Skip to content

Latest commit

 

History

History
2988 lines (2850 loc) · 192 KB

File metadata and controls

2988 lines (2850 loc) · 192 KB

Changelog

Unreleased

Added

  • Strict filesystem WAL stores now persist a checksummed writer-epoch ledger containing the active epoch, its exact latest closed predecessor, and final LSN and commit-digest evidence. Bounded retention keeps ledger writes and reopen validation independent of lifetime restart count. An OS-backed writer lease—not the deterministic chain markers stored in the generic fencing, process, host, and lease fields—refuses overlapping processes before append. A recovered trusted host closes only an abandoned epoch under that lease and derives a fresh, monotonically linked successor. Duplicate, stale, skipped, regressed, or unfenced epoch chains fail closed. Independent-process witnesses carry an external-action request, claim, settlement, and effect-free replay across successive host processes.

  • Echo now consumes the exact independently verified Edict workspace.patch.applyValidated@1 request through a capability-rooted single-file patch adapter. The request binds the prior bounded-observation basis, replacement identity, exact writable aperture, immutable no-follow and CI-workflow-exclusion policy, and byte budgets before mutation. The adapter rejects stale bases, escaped or substituted paths, symlinks, special files, and oversized writes without mutation; synchronizes a same-directory atomic replacement; and settles the resulting basis and observed before/after content identities before resumption. Claimed attempts reconcile by observing only the exact postcondition or settling OutcomeUnknown, never by claiming an unobserved pre-state or reapplying the patch. Identical settlement retry and replay remain effect-free.

  • Bounded workspace claims can now settle as OutcomeUnknown after directory authority disappears. A rootless reconciliation handle retains only the exact runtime-owned profile, revalidates the durable grant's exact claim commit and compiler-admitted request, and constructs the schema-bound settlement inside Echo. It cannot observe files or construct success, while zero evidence and substituted profiles, grants, or requests fail before another WAL commit.

  • Settled external-action candidates can now be reconciled idempotently after acknowledgement loss without a WAL store, transition context, or claim grant. An exact retained candidate returns the original admitted settlement and commit digest without appending history or making adapter execution reachable. A different valid candidate conflicts, malformed candidates fail ordinary settlement validation, and duplicated settlement records remain a recovery obstruction.

  • Echo now independently admits compiler-produced Edict Core and Target IR for one non-callable external request, verifies its exact source, target profile, result, basis, and capability closure, independently corroborates the complete Target IR request against Core, and evaluates argument-rooted runtime fields under both compiler-declared and Echo-owned step, allocation, and output ceilings. Admission also requires enough capacity for every terminal settlement posture. The derived generic request invokes no provider. The first operation-specific adapter observes an explicit relative-path set through a capability-rooted directory after request and claim commits. It refuses traversal, duplicate or unauthorized paths, symlinks, special files, stale bases, malformed settlements, substituted success apertures, and aggregate byte-budget overruns; revalidates registry authority before settlement; retains canonical path/content bytes plus complete basis evidence; admits OutcomeUnknown explicitly; and replays settled bytes without reopening the workspace.

  • Echo now admits domain-neutral external actions through separate request-before-effect, bounded claim, and settlement-before-resumption WAL transactions (ADR 0026). Canonical requests bind worldline, operation, schemas, authority scope, basis, single-claim and retained-byte budgets, input digest, and reconciliation law. Runtime-owner adapter registration attenuates operation and scope policy into an exact request-, basis-, and registry-policy-bound authorization without granting Edict or the provider seam external authority. Succeeded, Rejected, Failed, and OutcomeUnknown settlements bind the exact request, attempt, adapter, basis, schema, canonical result bytes, admission evidence, and nonzero external evidence. Echo derives each lifecycle frontier from a canonical request-id-keyed sparse Merkle index; insertion order cannot move its root, one planned mutation advances its bounded path without replaying prior WAL payloads, and recovery rejects substituted roots. Raw WAL builders and commit flushes cannot mint the coordinator's opaque authority; causal transaction coordinates come from one checked local continuation. Arbitrary recovery reports are observation-only. A coordinator recovered from a fallible local-store snapshot reconstructs interrupted request tokens, claim grants, and resumable settlements; storage corruption cannot masquerade as genesis. Recovery reconstructs requested, claimed, and settled posture from committed WAL records, including strict filesystem reopen; duplicate, conflicting, stale, unauthorized, malformed, and over-budget evidence fails closed. Replay consumes retained settlement bytes and never invokes an adapter.

  • The generic Edict-operation runner now exposes complete fresh-host and WAL-recovered application-result records beside the applied result. Report construction fails closed unless all three schema-neutral projection identities, output types, canonical bytes, and result identities are exactly equal.

  • Executable-operation packages can now bind an exact compiler-owned edict.result-projection.artifact/v1. Projected invocations retain the exact canonical application input, scheduler-owned private evaluation emits the compiler-declared output type and canonical result bytes, and a domain-separated identity binds that evidence. Applied Action outcomes, Receipts, and decided-Tick WAL transactions retain the same projection, bytes, type, and identity; fresh-host recovery revalidates them against the installed package before publication. Rebound projections, mismatched application inputs, and substituted result evidence fail closed. Obstructed Actions carry no application result. The generic external runner reports and recovers this evidence without a native application callback or application-specific reconstruction. Runtime admission caps canonical application input at 65,536 bytes and the compiler-declared result ceiling at 65,536 before private scheduler evaluation. Both independent provider components reject result ceilings above that runtime maximum and ambiguous input bindings. Configuration-derived node-key and replacement field names share the projection path-segment text ceiling. Package admission preserves authored source kinds and paths, and optional result evidence carries an explicit presence tag. Evaluation preflights exact canonical output size before constructing the projected value, while recovery re-evaluates the projection over the retained invocation input and refuses substituted result bytes before publication.

  • The generic Edict-operation runner's duplicate witness now exposes canonical before/after application-state roots and typed target-value digests. The graph-only roots commit reachable application state without conflating WAL, Tick history, Receipts, or commit metadata; report emission fails closed if either the root or target value changes during an obstructed duplicate.

  • cargo xtask run-edict-operation now consumes an exact external compiler-produced executable-operation package, its structurally separate accepted verification report, the manifest-to-adapter-to-target-configuration closure, and typed JSON input. The generic runner durably installs the package, acknowledges one canonical Action only after accepted-submission WAL commit, drops that host, recovers the exact installed package and pending Action into a fresh host, then lets the scheduler privately evaluate the recovered work while constructing one singleton Tick. Publication follows only after the decided-Tick WAL commit. A second fresh filesystem host recovers the package, Action, Tick, state, typed outcome, and Receipt. Repeating creation yields the package-declared, lawpack-qualified typed obstruction with no hidden mutation, while a changed initial state produces the typed echo-operation-execution-mismatch/action-basis recovery refusal. Admission binds the accepted verification report's Target IR to the package semantic closure, selects target configuration only from the package-supported target intrinsic, and verifies both created node and attachment types. The machine-readable witness reports exact package, verification-report, and lawpack-manifest digests plus basis, node, submission, Tick-commit, typed Receipt, result-projection, output-type, canonical-result, and result identities. The checked external fixture and bounded failure/stress suite contain application vocabulary only under xtask/tests; the production runner is generic and contains no native application callback or handwritten package.

  • The former native hello-echo counter capsule is now explicitly named runtime-counter-diagnostic, including its command, artifact paths, and internal identities. It remains a low-level callback-based maintenance diagnostic and no longer claims to be the external application proof.

  • Echo's checked Edict provider now lowers arbitrary application-owned Core coordinates through one generic executable-operation route. Exact Edict source, Core, lawpack, exports, target adapter, target configuration, and Target IR artifacts produce a canonical echo.operation-package/v1 for the bounded anchored create-if-absent capability without application-specific dispatch or a native callback. A structurally separate verifier reconstructs the source-to-package relation and emits an exact accepted or rejected echo.operation-package-verifier-report/v1. Target IR validation consumes the adapter-lowered target obstruction coordinate while independently corroborating its source-failure mapping. The provider package exposes seven new closure domains through 31 total schema bindings. The generic route now binds source-local capability aliases to canonical lawpack exports through the exact digest-locked Edict import and corroborates lawpack-owned coordinate-framed exports and adapter references independently from their provider-envelope domains. Its lowerer and verifier components were independently reproduced in copy-only, mount-free designated linux/amd64 containers and promoted at 258,787 bytes / dfd14015705ff555a7efdb3787ddb0f8b4f304168a9a0ebf324fd25d430bf5cd and 277,836 bytes / 279738ffeea40027eb493c15e873b87cf3aa0677a57f9f03fb824698e532322f, respectively. The resulting 25-file package has provider identity sha256:6685b7c629ae6955515d69158feb1d7db06af2193de7e5d13e1095101670b977. This package build proves generic compiler/provider lowering and independent verification. The separate run-edict-operation witness now consumes that crossing through Echo-owned runtime execution.

  • Executable-operation application writes now enter Echo as canonical, WAL-acknowledged Actions and are evaluated only by the scheduler while constructing a Tick (ADR 0025). Accepted pre-Tick Actions recover as pending work. Runtime-owned admission uses a bounded pending index and cache; unavailable packages are quarantined without poisoning unrelated work. Durable-acceptance lookup and newly committed receipt correlations are indexed directly, so scheduler Ticks do not replay or diff retained history. A WAL-enabled app surface rejects executable Actions submitted outside the durable acknowledgement boundary before witnessed intake can mutate. Mixed executable and provider/native backlogs alternate by durable parent global-Tick parity. The scheduler-round coordinate advances once per pass, so every head switches categories even when several heads share one worldline, preventing caller-controlled ingress hashes from starving either category. Homogeneous unbounded admission moves the complete inbox map instead of rebuilding and removing its entries one by one. Positional receipt attribution is exclusive to executable Actions; ordinary correlations without an exact scope match fail closed. Scheduler selection admits at most 64 executable Actions per Tick, leaving excess work pending, and meters footprint comparisons, blocker evidence, and aggregate operations during composition. Two independent Actions can share one exact parent coordinate and contribute to one composite Tick while retaining candidate-specific application-basis propositions and per-Action typed outcomes. Footprint conflicts name earlier applied members; evaluator and composition-budget obstructions contribute no operations. Every noncommitted typed outcome carries its deciding writer head, worldline and global Tick coordinates, commit and Tick-receipt identities, and canonical member index. Tick construction pins that index to the corresponding receipt entry with an executable alignment invariant. One scheduler WAL transaction retains exactly one batched Tick decision record, then each Action's receipt correlation and typed outcome in canonical order, followed by exactly one replayable state delta. Recovery rejects every second transaction claiming the same state-transition coordinate, including a byte-identical delta, so a Tick cannot be reconstructed from split WAL fragments. The decided Tick is durable before state, frontier, receipt, or outcome publication. Recovery and same-host retry both preserve an accepted Action when Tick-WAL persistence fails; runtime rollback also rolls back the corresponding admission cache so the Action re-enters scheduler admission. Fresh-host recovery validates every outcome against its exact envelope, admission, invocation, installed operation, causal coordinate, evaluation basis, reconstructed preparation and actual footprint, Tick entry, composite consequence, exact reconstructed aggregate patch membership, and state root. Typed obstruction records retain their invocation-admission policy and budget ceiling; recovery reproduces bounded evaluation and the complete scheduler composition before accepting an obstruction kind. For a cross-worldline basis obstruction, recovery reconstructs the submitted basis on its named worldline but resolves the deciding transition on the target head's worldline. Recovery records one monotonic installation ordinal per package and one installation-count boundary per Action, avoiding per-outcome package-set snapshots while preserving exact installation-before-Tick validation. Activation caches each reconstructed causal state by worldline coordinate, so Actions sharing one scheduler basis do not replay that history repeatedly. Recovered Action outcomes resolve installed packages through one package-ID index instead of scanning the complete installation set per Action. Test instrumentation now counts the actual package-index and installation-order lookups rather than asserting constant zero-value proxies. Tick WAL staging borrows its read-only outcome index instead of deep-cloning every outcome. The v1 scheduler Action-candidate ceiling is exported as ACTION_BATCH_CANDIDATE_LIMIT_V1; its acceptance witness now proves the complete limit with independent, non-conflicting node targets. Admission applies that ceiling independently to each runnable head, so Actions retained for dormant or faulted heads cannot consume another head's Tick capacity. run_until_idle continues after a no-Step pass that advances bounded Action admission, so an obstructed prefix cannot hide later admissible work. When more than that ceiling is pending, runtime admission selects the bounded set by canonical ingress identity rather than submission identity. TrustedRuntimeHost::into_parts now returns an opaque TrustedRuntimeHostParts value consumed by from_parts, preserving WAL, authority, policy, pending admission, and every typed Action outcome across host decomposition and reconstruction. A composite receipt cannot validate outside its complete Action-batch context. Legacy operation recovery-index roots remain byte-compatible when no Action outcome exists. Direct operation prepare/commit remains a documentation-hidden public TrustedRuntimeHost compatibility/test seam, absent from TrustedRuntimeApp; removal is tracked by issue #689.

  • TrustedRuntimeHost now has the first hook-free executable-operation runtime slice. A runtime owner can admit exact canonical ExecutableOperationPackageV1 bytes under a separate package policy, install their data-only EchoOperationProgramV1, independently admit an exact-basis invocation under caller authority and delegated budget, evaluate privately, and either commit one parent-visible patch or return typed noncommit evidence. On that transitional direct seam, only committed operation consequences enter the operation-tick WAL. The initial generic program performs an anchored typed-node alpha-attachment compare-and-set; it contains no application matcher, executor, footprint callback, or prebuilt mutation plan. Package, installation, invocation, evaluation, actual-footprint, budget, patch, result, basis, and terminal identities are bound into a typed receipt. The parent patch and singleton tick evidence name the admitted installation rather than promoting the subordinate program digest into rule authority. Application-basis corroboration is bounded by the delegated read budget. A runtime-control installation record and distinct execution-kernel commit records retain the full admitted installation and committed state delta under exact frame and frontier shapes so a fresh host can re-admit and reconstruct them without callbacks. A program digest alone cannot install, invoke, or authorize an operation. This slice does not yet include Edict compiler emission, a structurally separate target verifier, Jedit's rope lawpack, ReplaceRange, or an independently implemented semantic oracle.

  • The executable-operation corridor now has a separate AnchoredNodeAttachmentCreateIfAbsent program (ADR 0024). The original compare-and-set program remains update-only with its canonical program, invocation, application-basis, target-profile, and result identities unchanged. Creation has distinct schema, footprint, basis, result, and target-profile identities; observes node and attachment occupancy independently; succeeds only when both are absent; emits one atomic UpsertNode plus SetAttachment consequence; charges the node type, attachment type, and payload; and refuses every occupied target with PreconditionMismatch. Filesystem-WAL recovery validates the exact installed-program consequence, including operation and slot shape, program-owned node and attachment types, the atom-only attachment algebra, replacement bounds, and operations scoped to descended WARP instances. Descended evaluation now validates the complete parent chain, retains every portal attachment as both a footprint read and replay input, and charges each portal-pointer read incrementally before dereferencing that portal, so out-of-budget ancestry cannot affect evaluation; activation recovery reconstructs each operation's exact parent state and rejects missing, duplicate, substituted, or otherwise non-chain portal inputs, and independently corroborates the creation receipt's total-absence proposition against both target locations before replay. This closes only the single anchored-node-plus-alpha-attachment creation gap. It does not establish Graft-style multi-record mutation or a real Edict application crossing.

  • TrustedRuntimeHost can now admit a previously witnessed mutation for an installed Edict provider package with admit_provider_contract_submission_v1(...). The shared installed-contract admission boundary requires the exact canonical EINT v1 outer kind and an installed provider operation before staging. Provider invocation evidence binds the installed package id, exact package reference, semantic operation, Target IR, and scheduler rule; Echo reports an applied provider outcome only when that exact rule appears in the tick receipt, so the same-scope system acknowledgement cannot masquerade as application execution. A distinct validated tag-2 WAL encoding retains the evidence without fabricating a legacy contract coordinate, while the tag-1 legacy bytes remain stable. A fresh filesystem-WAL host recovers the exact outcome after independently reinstalling the provider package, without callback execution or duplicate work. Unknown operations, malformed or relabeled EINT, structurally invalid retained evidence, and provider inverse requests fail closed through stable typed errors. This closure does not authenticate callers, authorize targets, validate codec-owned input against an operation schema, or implement provider-native reads.

  • echo-wesley-gen now owns the proof-consuming provider installation adapter: it consumes DigestCorroboratedProviderContractPackageV1 through warp-core's sealed runtime-owner installer port and delegates to a TrustedRuntimeHost lower primitive that explicitly does not authenticate package bytes itself. Installation creates a distinct owned provider record retaining the exact occurrence, provider reference, complete provider registry, and mutation-rule identity, then atomically installs provider-package, package-root, operation, and shared scheduler-rule indexes. It fabricates no legacy Wesley/GraphQL metadata or evidence, exposes no app installation surface, and invokes no callbacks. Installation alone remains distinct from the provider mutation admission, invocation, receipt, and WAL crossings described above; generated bounded-read observations remain subsequent work.

  • echo-wesley-gen can now consume a DigestAdmittedProviderPackageV1 and an independently Echo-admitted AdmittedProviderContractPackageV1, require the exact echo.edict-provider@1 coordinate and strict lowercase sha256: package-root agreement with the proposal occurrence, and return an opaque DigestCorroboratedProviderContractPackageV1. Stable structured failures distinguish coordinate, digest-rendering, and artifact-root disagreement. This pure crossing corroborates package occurrence only: it does not derive registry semantics from package bytes, install or mutate registry state, invoke callbacks, schedule or execute work, emit receipts, or grant runtime authority. The real-host witness extends the exact generator dependency closure, so generation evidence and the checked provider occurrence refresh to sha256:ee870c75ec08c8818b3f80ab6562ae62a5cf741cd709edcee0085d951c5d5a7b; the primary semantic and Target IR artifacts remain byte-identical.

  • TrustedRuntimeHost can now admit an opaque Edict provider proposal against an independently constructed ProviderContractAdmissionPolicyV1. The pure crossing compares the complete host-owned package occurrence claim and provider registry—including schema, target-bundle profile, semantic and release identities, ABI/helper versions, operations, codecs, Target IR, obstruction, profiles, and footprint claims—and returns stable typed mismatches. The resulting AdmittedProviderContractPackageV1 retains private proposal material for the proof-owned provider installation crossing but does not rehash package bytes, mutate the engine registry, install handlers, invoke callbacks, schedule work, or grant application authority.

  • The checked Echo Edict provider conformance corpus now declares twelve reviewed executable obligations: exactly six owned by the isolated host executor and six by the package executor, with one accepted, nine rejected, and two refused dispositions. Each declaration names its crossing, stimulus, required disposition, and outcome contract, but embeds no pass flag, result, evidence pointer, implementation command, or runtime authority. The two exact-set executors separately produce provider-conformance evidence for baseline package parity, admission and binding failures, typed semantic refusals, and verifier disagreements. Corpus declarations and their executed provider evidence remain distinct from Echo installation, execution, observation, and runtime receipts.

  • TrustedRuntimeHost can now admit a witnessed installed-contract submission without accepting caller-manufactured ticket authority. Echo derives a domain-separated admission digest from its witnessed submission record and verified installed-package identity, stages the operation through the same package-evidence boundary, and binds the resulting receipt to that evidence. The explicit ticketed staging API remains available for actual Optic admissions; application-facing handles still cannot admit, stage, or tick.

  • echo-wesley-gen now purely assembles and digest-admits the first complete Echo Edict provider distribution from the verified 22-file generated corpus and explicit lowerer/verifier bytes. The derived provider manifest carries ten exact routes and 31 schema bindings—nine compatibility invocation domains, the generated artifact profile, 14 generated-resource domains, and seven generic executable-operation closure domains—but never inventories itself. A versioned canonical-CBOR package root binds those semantics plus raw hashes of all 24 non-manifest members, while the exact 25-file inventory, deterministic JSON rendering, mixed raw/domain-framed digest laws, packaged Wesley provenance/review, component bounds, and an external expected provider pin all fail closed through structured errors. This is package-occurrence authentication only; Edict schema/component preflight and Echo runtime installation remain separate authority crossings. A dedicated publisher now checks that all 22 generated members exactly reproduce the current checked provider corpus introduced by #652 before writing the two components and derived manifest as a self-contained 25-file distribution. Its capability-oriented filesystem boundary refuses invalid expected inventories before resolving the root, bounds actual-tree enumeration and expected-byte reads, never opens an unexpected regular file, and makes --check report sorted drift without creating, deleting, or rewriting package material.

  • The checked provider package now passes an isolated Edict-native readiness boundary pinned to Edict merge c75c3f55. The exact manifest constructs its immutable 24-domain schema registry, all five canonical primaries and 14 generated resources satisfy their owning CDDL roots, resource references are bound field-by-field to independently recomputed domain-framed digests, both components pass frozen-WIT preflight, and both request kinds produce opaque validation proofs. Schema-valid byte replacement, digest mutation, semantic field swaps, authority-source disagreement, malformed schemas/components, and invalid requests all fail before guest execution. This proves package readiness only, never Echo installation, execution, or runtime authority.

  • echo-wesley-gen now carries a fixed 38-file package-local source and provider asset boundary, preserving original logical source labels while making its .crate archive independent of workspace-parent files. An explicit sync tool distinguishes authoritative generated/component owners from their checked package corroboration, supports staged regeneration without circularity, and checks exact Cargo archive selection. Fixed owner leaves are opened without following final symbolic links and read twice through one retained descriptor; file-type, length, or byte disagreement refuses a moving owner. The generator source identity now enumerates 20 files and includes the exact manifest and implementation bytes of its canonicalization, operation-id-law, and provider-registry dependencies. The extracted archive compiles when its still-unpublished Echo dependencies are supplied through local patches.

  • Echo now owns the versioned semantic operation-id law echo.semantic-operation-id.fnv1-32/v1. It derives a persisted u32 from the exact semantic coordinate and generic query/mutation kind, remains domain-separated from Wesley's GraphQL-field-name law, and reserves the top two ids for Echo protocol envelopes: u32::MAX for scheduler control and u32::MAX - 1 for witnessed suffix import. The canonical generated-artifact profile carries both the law coordinate and each derived id; generation refuses either reserved value and package-local collisions without salting, probing, or renaming. Its CDDL bounds operationId to the remaining numeric application range, but schema admission alone does not prove derivation or collision freedom: semantic generation recomputes the law and checks the complete operation set. This packages an exact operation-identity proposition but does not register, install, authorize, or execute the operation. Generated source now carries public expected constants for the profile-owned law and id, requires both as untrusted bundle claims, refuses disagreement, and exposes the matched claim through the resulting private-state registration descriptor.

  • Echo now provides the exact edict:target-provider/lowerer@1.0.0 Component Model implementation for the first checked provider closure. The pure lowerer accepts only explicit digest-bound Core, target-profile, authority, lawpack, lowerability, and output-role inputs; produces canonical echo.span-ir/v1 Target IR with byte-for-byte parity to Edict's built-in Echo wrapper; and returns typed refusals for unsupported ABI, profiles, semantics, reads, rebound operations, unresolved authored optics, changed type bindings, Core type definitions, evaluation budgets, out-of-scope locals, intrinsics, and undeclared or malformed output-role claims. Local admission distinguishes pre-effect, obstruction-arm, and post-effect scope from the exact input, effect-result, and obstruction declarations before cloning any expression into Target IR. The first closure also requires an empty input-constraint set and the exact zero-argument domain.WriteRejected obstruction constructor. Effect inputs and intent results admit no call-expression callee, refusing unreviewed calls until their own lowering laws exist. A deterministic build boundary pins the frozen WIT bytes, rejects ambient or callable imports, checks the exact decoded world type graph and contract attestation, and reproduces the checked component byte-for-byte across independently provisioned linux/amd64 containers from the immutable Rust image used by CI. The builder resolves and authenticates the exact Rust and Cargo executables, binds Cargo to that compiler, owns the inner Cargo home, removes ambient Cargo profile/build/target overrides, remaps its dependency source paths to /cargo, and atomically promotes only distinct candidates matching a reviewed repository digest. The promoted 225,428-byte component has SHA-256 3a0a1ce454f3083df814f60554997d26d0b539f7977a7aae6b00e7e09159e392. Other-host builds are structural and semantic witnesses rather than cross-host compiler-identity claims. The publication-enabled, archive-self-contained echo-edict-provider-lowerer source crate carries package-local copies of its four exact admitted resources, with a workspace witness binding them to the checked generated corpus. Its full package gate follows publication of echo-edict-canonical 0.1.0. These artifacts describe and translate provider semantics; they confer no Echo runtime authority.

  • The native Echo Edict lowerer model now accepts any exact, lexicographically sorted subset of the declared generated.echo-dpo generated artifact, review.echo-dpo review payload, and target-ir.echo-dpo Target IR roles. It emits canonical-CBOR generated and review envelopes at generated/echo_dpo.rs and review/echo_dpo.json, and refuses unknown, mismatched, duplicate, or out-of-order role claims with typed UnsupportedOutputRole. The generated Rust binds the semantic operation, Target IR, Echo ABI and helper API, provider and operation schemas, target and generated profiles, and abstract footprint obligation/algebra. It then performs only an explicit post-assembly equality and consistency comparison between an independent expected pin and untrusted Edict semantic/release bundle claims, with typed refusal for every identity class. Every domain-framed resource is compared as a complete coordinate/domain/digest proposition. The generated-artifact profile now owns le-binary-v1, and generated Rust implements distinct bounded Id, Input, and Output types with fail-closed decoding for malformed, over-bound, truncated, or trailing bytes. Descriptor methods round-trip the exact input/output types and pack typed input into canonical EINT v1; EINT vars remain codec-owned opaque bytes rather than a universal canonical-CBOR value. The matched descriptor exposes a borrowed, provider-generic registry and can bind its generated matcher to one explicitly identified host mutation implementation. It returns only an opaque, non-installing package proposal after checking the complete Target IR, semantic/release bundle, target/generated/operation profile, provider/value schema, codec, obstruction, operation-id, ABI, helper-API, rule-name, and footprint identities. Echo adds the mandatory ingress matcher reads to the host's effect footprint. Identity equality detects cross-binding but does not prove arbitrary callback semantics. The mutation proposal fails closed for a Query; authored reads remain a separate bounded observer/optic path. The isolated actual-host fixture is green for binding, typed codec refusal and round trips, EINT packing, the borrowed registry, and proposal preflight. The permanently non-authoritative review is bound to the exact generated artifact. Neither projection authenticates a pin, admits or installs a package, or grants Echo runtime authority; checked-component promotion and host-side CDDL admission remain separate crossings.

  • Echo now provides the exact edict:target-provider/verifier@1.0.0 Component Model implementation for the checked provider closure. The pure verifier independently compares explicit digest-bound Core and Target IR artifacts under the exact target profile and ordered semantic inputs. It emits a canonical accepted report for the reviewed relation, admits a well-formed intrinsic disagreement as a rejected report with an error diagnostic and host-authored output manifest, and preserves an unsupported output-role overclaim as a typed provider refusal with neither response nor manifest. Its bounded native preflight validates complete known expression, predicate, input-constraint, require-failure, and Core-value shapes before separating malformed artifacts from well-formed unsupported semantics, and one admitted diagnostic-ABI identity now binds both the target profile and every emitted report. The 242,350-byte checked component has SHA-256 660ad5ad875b844e30c027e2a861e7941b5905098311fe578ae7fed732cf322c and reproduces byte-for-byte across independently provisioned designated linux/amd64 builders. The isolated pinned Edict host preflights the exact request artifacts and declared output schema, invokes that checked component, then schema-admits each returned accepted or rejected report and authors its output manifest. It replays accepted, rejected, and refused completed outcomes identically in independent fresh stores and separate host processes. These witnesses prove provider verification and host replay only; they do not install, authorize, execute, or observe an operation in Echo.

  • echo-edict-canonical now owns the shared pure implementation of Edict's canonical CBOR and domain-framed digest contracts as a publishable 0.1.0 leaf. echo-wesley-gen retains its existing compatibility surface through a re-export, while executable provider components use the same codec without depending on generator or Wesley APIs. Its decoder now applies a 65,536-node host materialization ceiling, charging map keys and values separately. A matching cumulative reservation budget rejects both oversized direct containers and nested declarations that attempt to reuse the same capacity allowance before reserving their storage.

  • echo-wesley-gen now checks in the first exact 22-file Edict provider artifact corpus: five canonical-CBOR primaries, fourteen canonical-CBOR resources, the self-contained CDDL, Wesley provenance JSON, and non-authoritative review JSON. A dedicated generator binds an explicit, compile-time-enumerated source/dependency-lock bundle rather than executable, Git, path, or environment discovery. Its --check mode reports sorted missing, changed, and unexpected paths without creating, deleting, or rewriting files, while generation refuses observed unexpected entries before writing and retains no-follow directory capabilities through temporary-file replacement. The crate test suite checks the committed snapshot.

  • echo-wesley-gen now derives Wesley's canonical GenerationReviewV1 from verified provider provenance. The deterministic JSON copies the exact input, provenance, generator, projection-role, source, and emitted-output identities, is structurally unable to claim authority, and preserves typed Wesley failures when its input and provenance disagree. The semantic source now identifies both provenance and review contracts as Wesley #728 artifacts.

  • echo-wesley-gen now constructs canonical Wesley provider-generation provenance from explicit material only. The manifest binds the exact three authored source artifacts, checked settings digest, caller-supplied generator component bytes, and exactly six non-derived primary outputs, then immediately re-verifies all referenced bytes. Generated resources remain transitively bound through the primary artifacts, while provenance and review stay outside the emitted set to prevent circular digests. Typed Wesley failures are preserved without exposing Rust debug spelling as a stable diagnostic. The primary closure retains its producing input digest so outputs cannot be attributed to another invocation, and generator coordinates must remain disjoint from every exact source, declared artifact, resource, and package coordinate.

  • echo-wesley-gen now deterministically projects the validated Echo Edict source into a canonical lawpack, target profile, two source-partitioned authority-facts documents, generated operation profile, fourteen declarative resources, and a self-contained provider CDDL artifact. Every output passes its owning generated root, Edict-owned values also pass the independently admitted upstream roots, manifest edges use domain-framed digests, and Wesley references bind exact output bytes. The projection preserves direct adapters, operation-local obstructions, and optic contracts, and keeps read-class operations as bounded observers rather than mutation DPOs. These artifacts describe provider semantics and confer no Echo runtime authority.

  • echo-wesley-gen now admits the exact Apache-2.0 Edict provider contract pack introduced in Edict PR #162 and extended with the result-projection contract in Edict PR #174 as an explicit generator input. The pure boundary pins the CDDL and manifest publication, verifies strict contract and domain inventories plus every embedded resource byte, digest, and provenance record, rejects tampering with stable structured error kinds, and performs no filesystem, registry, environment, or network discovery.

  • echo-wesley-gen now implements the exact edict.canonical-cbor/v1 value, encoding, nesting, map-ordering, and domain-framed SHA-256 contracts. Named provider artifacts must both use those canonical bytes and satisfy their owning root in the admitted Edict CDDL; typed failures distinguish unknown contracts, invalid canonical encoding, and schema mismatch, and oversized declared lengths produce platform-stable truncation failures before host-width conversion. This validates a generation artifact and does not grant Echo runtime authority or admission.

  • echo-wesley-gen now constructs a canonical Wesley extension-generation input from exact Echo semantic-source bytes, the admitted Edict CDDL and manifest, and checked versioned settings. The first provider closure uses an explicitly empty GraphQL Shape/operation catalog, derives six primary output roles without circular provenance/review digests, preserves the normalized semantic model across set reordering, and moves the generation-input digest when exact authored source or settings bytes change.

  • warp-core now separates application-requested causal-anchor claims from Echo admission. CausalAnchorAdmissionRequest contains no admission receipt, CausalAnchorClaim is an opaque canonical value over only the caller's claim, and admitted fact construction is reserved for Echo's trusted admission path under ADR 0022.

  • The causal WAL now has stable causal-anchor admission transaction, fact, and receipt record kinds. Transaction validation requires exactly one fact frame followed by exactly one receipt frame before append, while recovery rejects uncommitted, malformed, coordinate-mismatched, basis-mismatched, frontier-root-mismatched, or cross-admission evidence. Public WAL builders and stores cannot originate causal-anchor admission transactions without Echo's crate-private admission capability. Writer-cursor and read-only recovery consume one shared causal-anchor traversal so basis and frontier validation cannot diverge between recovery modes. Self-contained and CAS-addressed WSC imports consume that same traversal before accepting anchor sidecars, so matching projection material cannot legitimize forged recovered basis or frontier evidence.

  • TrustedRuntimeApp now admits causal anchors only through an enabled runtime WAL at the current logical durable frontier. A host-owned exact root-support policy is validated and bound into receipt identity; successful admissions recover by anchor id after restart, while stale bases, unsupported roots, and failed storage commits publish no authority. Exact-retry lookup uses a disposable claim projection rebuilt from validated WAL history, replaced on writer recovery, and advanced only after a successful admission commit.

  • Causal-anchor request, fact, receipt, observation-only WAL evidence, and recovered admission evidence are now available from the warp-core crate root. Arbitrary recovery reports produce ObservedCausalAnchorAdmission; sealing RecoveredCausalAnchorAdmission is reserved for trusted local WAL recovery. A Jim-shaped external-consumer witness and standalone golden vector pin Echo-produced subject, basis, root, purpose, anchor, receipt, transaction, and commit identity so applications do not create a second anchor hash domain. Both evidence types expose coordinates through read-only accessors rather than caller-reconstructible public fields. External consumers can reconstruct an opaque anchor lookup key from persisted Echo-produced identifier bytes without gaining fact, receipt, or admission construction authority.

  • echo-wesley-gen now exposes a strict, versioned Echo Edict provider semantic-source model and pure validator. The checked first-operation source fixes target.replace authority, typed failure and obstruction schemas, exhaustive source mapping, full optic profile, budget, native capability, explicit semantic discharge, source-partitioned authority facts, complete lawpack/target-profile resources, generated artifact roles, package ABI and provider identity, and full invocation schema bindings. It deterministically rejects recursive types, Edict Core ownership violations, byte-counted string aliases, invalid failure identifiers, duplicate or dangling facts, missing or ambiguous effect implementations, duplicate target-profile adapter selectors, authority/profile/capability disagreement, self-referential manifests, and incorrect generated contracts, invocation domains, or schema roots while treating generated files and relocated SDL as non-authoritative. Authority-facts outputs are bound to Edict's canonical ABI work in flyingrobots/edict#157 rather than defining an Echo-owned wire contract.

  • warp-core installed contract packages can now provide read-only inverse laws for mutation operations. The trusted app surface resolves an exact retained causal receipt after restart, verifies the recovered witnessed submission and currently installed artifact, checks the caller's current frontier, resolves the receipt set for the current frontier commit, and WAL-acknowledges the contract-produced mutation with both the target receipt and current-basis receipts as causal parents. The retained ingress preserves a typed inverse-target role, and the app surface can recover the inverse target and admission basis directly from receipt history after restart. Missing receipts, non-applied target receipts, stale bases, unavailable inverse fragments, unmappable spans, absent handlers, and contract-version mismatches remain typed obstructions; inverse admission never deletes or rewrites the original transition. Ordinary app and runtime submission reject the reserved inverse-target parent role, preventing caller-authored intents from being projected as contract-defined inverses. Runtime recovery rejects a receipt correlation when its non-empty retained tick receipt contains only other submission ingresses.

  • warp-core now distinguishes repeatable TickReceipt content commitments from admitted receipt-event identity. CausalTickReceiptRef binds receipt content to worldline, worldline tick, global tick, commit, submission, and admission ticket coordinates; ingress, trusted-runtime WAL, recovery indexes, app-facing outcomes, and WSC causal history now retain and follow that exact coordinate. echo-cli wal submission-posture reports the canonical receipt reference bytes alongside the repeatable receipt-content digest. Versioned codecs reject malformed magic and empty-but-present, duplicated, or reordered parent sets as corruption and report structurally valid legacy digest-only parent evidence as an explicit ambiguity rather than aliasing it to an arbitrary event. Read-only runtime-WAL recovery also rejects any correlation parent set that disagrees with the independently retained ingress envelope. Retained tick-receipt reconstruction also rejects non-canonical blocker ordering, forward or non-applied blocker references, and blocker attribution incompatible with the candidate disposition before the receipt re-enters provenance history.

  • Trusted runtime scheduler commits now retain canonical local-commit provenance, the exact typed tick receipt, and installed-contract evidence in the same WAL transaction as receipt correlation. Filesystem reopen replays that evidence into a fresh runtime without invoking scheduler or contract callbacks and restores global tick, worldline frontier, materialized state, receipt indexes, causal parents, and app-facing outcome. Legacy digest-only runtime deltas remain explicit recovery obstructions. WAL activation also rejects live process-only authority that recovered durable history cannot reproduce. Recovery rejects duplicate singular acceptance, retained-envelope, tick-receipt, receipt-correlation, or state-delta frames instead of selecting one claim. WAL transaction construction rejects retained submission, correlation, or replayable state-delta material that does not bind the other evidence in the same atomic claim.

  • Trusted runtime submission intake now atomically retains a versioned canonical ingress envelope with each WAL-backed acceptance. Filesystem WAL reopen restores the witnessed submission ledger without ticking or dispatching, preserves duplicate posture, and reports legacy acceptances without envelope material as explicit recovery obstructions.

  • warp-core ingress can now cite typed causal parent tick receipts. Trusted runtime outcomes, WAL receipt correlations, read-only recovery indexes, and WSC causal-history envelopes retain both parent and reverse child lookup so contract-defined inverse intents remain attributable after host restart.

  • warp-core now exposes RetainedEvidenceBoundaryPosture with boundary layer, origin, proof strength, access, completeness, and obstruction axes so retained evidence refs can be projected without conflating citation, reveal permission, redaction, unsupported evidence kinds, or missing retention.

  • warp-core now exposes a recovered WAL evidence segment catalog derived from RecoveryScanReport, with a non-authoritative live cache in TrustedRuntimeWal that marks cache-update failures as rebuild posture without turning committed WAL transactions into failures.

  • warp-core now exposes a narrow Edict echo.span-ir/v1 Target IR fixture bridge that accepts strict lowercase digest-locked pre-step continueObstructed requirements, evaluates deterministic basis freshness facts, and emits versioned attempt receipt objects bound to the supplied Target IR digest. The bridge distinguishes accepted artifacts from executed receipts, obstructed attempts from invalid proposals, and obstruction from legal unselected counterfactuals without claiming bundle admission, Jim semantics, scheduler counterfactual exploration, canonical Echo receipt bytes, or receipt digests.

  • warp-core now exposes WAL projection fact records for WalRoot, WalWriterEpoch, WalSegmentRef, WalCommitAnchor, and RecoveryCertificateRef; WalSegmentRef::identity_digest() binds writer epoch, LSN range, commit chain, segment digest, commit anchors, and seal posture while excluding storage locators from causal projection identity.

  • warp-core can now project recovered WAL history into graph-ready WalRecoveryProjection records from explicit manifest, segment seal, segment locator, writer epoch, and recovery certificate evidence; missing manifests or unavailable locators produce typed projection obstructions instead of empty success.

  • warp-core now exposes WalRecoveryPlan records that bootstrap from a projected WAL root or storage manifest, record checkpoint posture, committed replay suffix, tail posture, recovered index roots, retained-material posture, and projected evidence posture without requiring graph WAL nodes as input.

  • warp-core now exposes RecoveredDurabilityIndexes and rebuild_durability_indexes_after_recovery(...), composing committed WAL recovery into submission, receipt, retained-material, materialization outbox, topology, and graph/WSC projection indexes without invoking scheduler, observer, wall-clock, network, or app code.

  • warp-core materialization outbox recovery now exposes typed MaterializationRecoveryPosture evidence for missing artifacts, artifact or metadata digest mismatches, committed observation mismatches, and retained material unavailability while preserving the coarse replay posture for existing callers.

  • echo-dind-tests now includes a process-kill WAL crashpoint witness that kills child processes after committed WAL material and before transaction commit, proving recovery preserves committed history and excludes uncommitted tails.

  • warp-core can now materialize WAL projection records into deterministic WARP graph facts with root, writer epoch, segment, commit-anchor, and recovery certificate nodes plus typed graph edges suitable for WSC serialization. The materialized graph omits raw WAL storage locator authority and rebuilds to identical WSC bytes from the same recovery evidence.

  • warp-core now exposes observation-only WAL projection graph WSC import evidence, keeping materialized projection bytes readable as schema/count facts while rejecting them as causal-history import material or WAL recovery authority without manifests and segment evidence.

  • warp-core now exposes a versioned WSC causal-history export profile model for ref-only, self-contained, and CAS-addressed profiles, including the evidence each profile must carry and an explicit CAS byte-retention posture that does not promote CAS hashes into causal authority.

  • warp-core now exports and validates a ref-only WAL WSC fixture that joins WAL projection graph material, accepted-submission evidence, and receipt correlation evidence while reporting external segment bytes as explicit dependencies and normalizing absolute locator paths out of causal identity.

  • warp-core now exports and validates a self-contained WAL WSC fixture that embeds WAL segment bytes as WSC material, replays those bytes through WAL recovery to validate segment digest and commit-chain evidence, rebuilds accepted-submission and receipt indexes without access to the original filesystem WAL root, and reports tampered embedded bytes as typed recovery obstruction evidence.

  • warp-core now exports and validates a CAS-addressed WAL WSC fixture that joins WAL projection graph facts with content-addressed segment and retained material references, verifies referenced blobs through CAS content hashes without making CAS semantic authority, reports missing blobs as typed import obstructions, and keeps equal bytes under different semantic coordinates as distinct retained material references.

  • warp-core WAL WSC exports now carry retained material and reading-reference envelopes through ref-only, self-contained, and CAS-addressed profiles. Self-contained exports can embed retained payload bytes and validate them against the WAL-retained material digest, while CAS-addressed imports require the referenced retained blobs to be present before reporting success.

  • WSC causal-history profile version 2 now carries explicit Echo causal-anchor fact, receipt, WAL transaction, LSN, and commit evidence through all three export profiles. Ref-only imports expose sidecar records as unverified until external WAL dependencies are resolved, but require every supplied sidecar to match a transaction and commit anchor in the projected WAL root; self-contained and CAS-addressed validation recovers retained WAL segments and requires the envelope to match the complete recovered anchor history before exposing observation evidence. CAS-addressed exports and imports also require retained CAS references to exactly match every retention record whose material posture is present; mismatch errors report missing and extra references independently. echo-cli bundle schema version 2 writes, inspects, and reports the dedicated causal-anchor envelope without treating Continuum transport as admission.

  • warp-core now includes a filesystem-backed WSC store adapter that persists envelope material separately from commit markers, hides staged material until marker publication, reopens committed envelopes in deterministic order, and reports torn envelope or marker files as typed WSC store obstructions.

  • echo-cli now exposes read-only wsc causal-history commands that export ref-only and self-contained WAL WSC bundles from filesystem WAL roots, inspect bundle envelope metadata including retained evidence envelopes, verify self-contained bundles without the original WAL root, and report unavailable ref-only segment bytes as typed material obstructions in JSON output.

  • echo-cas now exposes a fallible filesystem-backed DiskTier for durable retained blobs, preserving content-only BLAKE3 hash semantics across process reconstruction while keeping missing blobs as explicit absence.

  • cargo xtask test-slice durable-runtime-wal now runs the release-grade filesystem runtime WAL durability gate, joining filesystem ACK recovery, filesystem failure atomicity, CLI submission posture JSON, stale-claim, and generated man-page checks while leaving runtime-wal-ack as the fast semantic gate.

  • cargo xtask test-slice durability-release now includes the exact wsc_retained_evidence_export_modes witness, keeping retained-evidence WSC export coverage in the release gate without using Cargo's slow package-level name filter.

  • cargo xtask test-slice durability-release now includes the exact retained_reading_missing_payload_is_not_empty_success witness, locking the app-safe missing-retention posture for reading payloads, reading envelopes, and retained receipt support.

  • cargo xtask test-slice durability-release now includes the exact recovery_plan_bootstraps_from_wal_root witness, locking recovery plan bootstrap posture without using Cargo's slow package-level name filter.

  • cargo xtask test-slice durability-release now includes the exact wal_recovery_rebuilds_all_durability_indexes witness, locking committed-only rebuild coverage for durability indexes without using Cargo's slow package-level name filter.

  • cargo xtask test-slice durability-release now includes the exact materialization_outbox_recovery_returns_typed_posture witness, locking typed materialization outbox recovery posture into the release gate.

  • cargo xtask test-slice durability-release now includes the exact wal_process_crashpoints witness, promoting the process-kill WAL crashpoint runner from future descriptor to release-gate evidence.

  • cargo xtask dind now defaults to run mode and includes the exact dind_durability_convergence_gate witness, proving live WAL execution, read-only WAL recovery, WSC import, and retained-material reveal agree on the same app-facing receipt and bounded reading while missing or corrupt support material returns typed obstruction.

  • cargo xtask test-slice durability-release now includes the exact dind_durability_convergence_gate witness so the release slice also carries the DIND durability convergence proof.

  • warp-core trusted runtime hosts now configure runtime WAL through TrustedRuntimeWalConfig, including in-memory and filesystem-backed adapters. TrustedRuntimeWalStoreKind exposes the configured adapter kind as host-owned read-only evidence, filesystem roots recover pending and decided submissions after host reconstruction, reopened filesystem adapters continue the committed LSN/digest chain, filesystem commits are marked StrictFilesystem, read-only filesystem recovery preserves torn/corrupt tail posture, host-test-only filesystem fault plans inject append, flush, and manifest failures to prove submission/tick rollback, and TrustedRuntimeApp remains limited to submit and observe surfaces.

  • Added an Echo 1.0 release contract that records the four binary release gates, compatibility policy, evidence requirements, and GitHub Project boundary without carrying live roadmap state in the repository.

  • Recast the WAL/WSC packet as stable durability doctrine and added guards that reject live roadmap issue inventories while preserving WAL authority, graph projection, WSC export modes, storage locators, and bootstrap recovery language linked to issue #521.

  • warp-core now hardens the first braids/strands roadmap goalpost: Strand<P> fields are no longer publicly constructible, Strand::new(...) validates typestate/runtime-posture coherence before construction, public strand tests use fixture builders and accessors, ProofEnvelope::validate_shape(...) returns structured ProofError, and invalid braid lifecycle transitions report typed BraidTransitionKind instead of action strings.

  • warp-core now locks the second braids/strands roadmap goalpost with golden vectors for replay-trace proof-envelope identity, proofless and proof-bearing braid shell identity, revealed and sealed member identity, and sealed-member salt effects. The vector metadata marks these identities as E1 scaffolding identity, and API docs now state that deterministic member blinding defaults are reproducibility tools, not unlinkability boundaries.

  • warp-core now begins the third braids/strands roadmap goalpost with append-only braid membership history. BraidMembershipEntry and Braid::membership_history() expose accepted MemberWoven facts as a read-only projection over the braid event log, while frontier() remains the current membership projection.

  • warp-core now exposes historical braid membership views through BraidMembershipCursor, Braid::current_membership_cursor(), and Braid::membership_at(...). The cursor is a half-open event-log interval, so later woven members do not appear in earlier membership views.

  • warp-core now exposes BraidMembershipDiff through Braid::diff_membership(...), reporting deterministic added and ended membership projection facts between historical cursors while reserving revealed/concealed fact slots for future lawful disclosure evidence.

  • warp-core now exposes retained braid shell replay/audit facts through audit_braid_shell(...) and BraidShellAudit, including member verdicts, support/frontier digests, posture floor, proof binding, and explicit self-witness integrity-only posture.

  • The braids/strands hardening docs now define the Braid Flight Recorder and Causal X-Ray lower-mode output target over historical membership, diff, shell audit, proof-binding, and witness-posture facts.

  • warp-core now completes the fourth braids/strands roadmap goalpost with typed witness receipts, witness kinds, a verifier-shaped witness backend boundary, deterministic simulator fixtures, explicit witness compatibility rules, generic sealed membership presentations, disclosure budget labels, and braid shell audit receipts that keep E1 self-witnessing marked as integrity-only local evidence. The self-witness simulator rejects non-E1 compatibility requests with a typed UnsupportedCompatibility error instead of minting stable public identity for scaffolding evidence. Sealed membership presentations validate that their witness receipt subject and evidence digests bind the braid coordinate, purpose, authority domain, member commitment, and disclosure budget.

  • warp-core now completes the fifth braids/strands roadmap goalpost with a named plurality law registry, machine-readable Law Cards, typed law references and versions in braid shell replay/audit readings, adapter-provided law-family routing through authority domains, and typed law obstruction evidence for unsupported or unauthorized law execution. Law references and braid shell policy ids reject all-zero names before replay, collapse-derived shells report collapse policy ids as collapse laws, and law versions reject zero before registration. Law readings derive integrity-only posture from witness attestation strength, so non-self integrity-only receipts are not promoted to external witness evidence, and they reject witness receipts whose subject digest does not match the retained support digest. Collapse-derived shells also reject records whose shell policy id diverges from the nested collapse policy id.

  • The braids/strands hardening docs now define Goalpost 6 for topology intents and WAL recovery, making strand forks, braid event logs, retained braid shells, and replica suffix import explicit WAL/WSC hardening work rather than process-local topology state.

  • warp-core now enforces the v1 single-writer-head strand invariant through both Strand::new(...) and StrandRegistry::insert(...), and runtime strand forking constructs the registered relation through the same constructor boundary used by external callers.

  • warp-core casting a dynamically postured strand to statically shared now returns a semantically precise PostureObstruction::PostureMismatch instead of PostureObstruction::NarrowingRefused.

  • warp-core renamed ProofEnvelope::verify to validate_shape and updated error variants to ProofShapeValidationFailed to accurately reflect shape/input checks rather than full cryptographic proof verification.

  • warp-core strand creation now carries explicit RetentionPosture through ForkStrandRequest, ForkStrandReceipt, and Strand. Session-default and debugger fork constructors choose posture policy explicitly, session-default work always records PostureDerivation::SessionDefault, debugger forks never silently become Shared, and StrandRegistry rejects incoherent retained posture such as Shared without an admission scope.

  • warp-core import admission receipts now bind local source-shared import admission to an explicit imported artifact identity. A receipt minted for one imported artifact cannot admit another import into a local shared admission scope.

  • warp-core retained plural settlement artifacts now persist their causal posture in ProvenanceEventKind::PluralArtifact and include the posture tag in canonical provenance-event hashing.

  • warp-core now exposes a generic contract obstruction taxonomy for product-facing contract-host surfaces. ContractObstructionKind, ContractObstructionSubject, and ContractObstruction classify unsupported operations, unsupported queries, admission obstructions, runtime faults, missing retention, stale basis, residual readings, and budget limits without importing application-domain failure names into core or treating runtime faults as lawful domain rejections.

  • warp-core now exposes retained evidence references and missing-retention posture for contract-hosted evidence. RetainedEvidenceRef binds installed contract identity, retained role, semantic digest, content hash, and byte length; RetainedEvidencePosture returns either available evidence or typed MissingRetention obstruction. CAS hashes remain byte identities only and cannot stand in for semantic reading or evidence coordinates.

  • warp-core now exposes a local witnessed-submission persistence shell. WitnessedSubmissionPersistenceSnapshot pairs accepted submission records with canonical ingress envelopes so hosts can persist accepted-but-not-yet- ticked work and restore duplicate detection plus envelope material without staging scheduler-visible inbox work, ticking, dispatching handlers, or executing contracts.

  • warp-core now exposes a local product-facing intent outcome surface. submit_app_intent(...) returns an IntentSubmissionHandle without ticking or staging runtime ingress, and observe_app_intent_outcome(...) maps internal scheduler correlation into IntentOutcome::{Unknown, Pending, Applied, Rejected, Obstructed} with receipt evidence and typed contract obstruction posture.

  • echo-registry-api, echo-wesley-gen, and warp-core now enforce local contract/API compatibility at the installed package boundary. Generated registries carry Echo contract ABI, Wesley generator, and contract-host helper API versions; host verification policy rejects version drift before package install; and installed contract receipt/reading evidence cites the verified compatibility metadata without granting execution or query authority.

  • warp-core now exposes a reference trusted runtime host loop for the local contract-host path. TrustedRuntimeHost owns generated package installation, ticketed ingress staging, scheduler passes, until-idle policy, and read-only observation service access, while TrustedRuntimeApp exposes app-facing submit/observe/query methods without tick, package-install, ingress-staging, or fault-recovery authority.

  • warp-core now has an external contract proof fixture for the v0.1.0 local contract-host path. The fixture installs a generated-style package with a mutation, conflict-capable mutation, and QueryView query; submits non-trivial canonical vars; executes only through scheduler-owned ticks; observes a bounded contract reading; retains reading payload and receipt evidence through echo-cas semantic coordinates; and replays witnessed submission history to the same observed intent outcome. The fixture keeps application nouns inside the test package and generated payload shape, not in Echo core.

  • warp-core now has a serious external-consumer-shaped contract fixture for the local contract-host path. The fixture uses hot-text-style document edit names only in test code, installs through the generic package boundary, submits through the app-facing host handle, produces a footprint-conflict rejection for overlapping edits, observes a bounded QueryView reading, and retains both reading payload and receipt evidence through semantic coordinates.

  • xtask test-slice now includes contract-path-release, a narrow local v0.1 contract-host release witness. The slice runs the installed contract pipeline replay tests, reference trusted host loop test, and serious external consumer fixture without requiring developers to run the full DIND suite for normal local iteration.

  • xtask test-slice now includes runtime-wal-ack, a narrow runtime WAL ACK witness. The slice runs WAL-backed app-facing submission acceptance, scheduler tick receipt commit-before-publish, recovered runtime indexes, CLI submission-posture JSON for filesystem runtime WAL roots, stale-claim guard, and generated man-page checks.

  • The docs now include an executable local contract-host quickstart and a v0.1.0 authority-boundary audit. The quickstart points developers at cargo xtask test-slice contract-path-release, names the app-facing and trusted-host APIs, and documents compatibility and retention boundaries. The audit records current evidence that application code cannot tick, stage ingress, install packages, or recover scheduler faults through the app surface.

  • echo-cas semantic retention now supports bounded byte-range lookup through RetainedBlobIndex::load_range(...). Range lookup requires the exact semantic coordinate, enforces the caller's byte budget, and returns typed RetentionError variants for missing coordinates, missing content, over-budget requests, or out-of-bounds ranges. Content-hash lookup remains a byte lookup only; semantic success still requires coordinate match.

  • echo-cas semantic retention now fails closed when the same SemanticBlobCoordinate is retained with different bytes. Retaining the same coordinate with the same content is idempotent, while conflicting content returns RetentionError::SemanticCoordinateConflict. Bounded range lookup now proves the semantic coordinate exists before reporting range-budget errors.

  • echo-cas now provides a local semantic retention index above the content-only blob store. RetainedBlobIndex maps SemanticBlobCoordinate values to retained descriptors for contract artifacts, receipts, witnesses, reading payloads, reading envelopes, and observer artifacts while preserving the rule that BlobHash names bytes only. Retained blobs can be loaded by content hash or exact semantic coordinate, equal bytes under different semantic coordinates do not alias, and missing coordinates or missing bytes return typed RetentionError variants instead of fake successful reads.

  • warp-core QueryView readings now carry a QueryReadingIdentity in ReadingEnvelope. The identity binds query id, domain-separated vars digest, resolved basis digest, requested aperture digest, observer plan, and installed contract evidence when present, while keeping payload bytes in ObservationPayload::QueryBytes. Tests prove reading identity changes when query vars, query id, causal basis, schema/observer plan, or budget changes. Over-budget reads still obstruct with BudgetExceeded; residual readings remain explicit posture rather than fake complete payloads.

  • warp-core query reading identity now excludes observation freshness metadata from the basis digest. The same QueryView against the same resolved commit keeps a stable QueryReadingIdentity even if unrelated runtime-owned tick progress changes the observation freshness watermark.

  • warp-core now publishes observation artifacts under observation contract version 4 and echo:observation-artifact:v4 because contract evidence, query reading identity, and retained-evidence posture are now part of the canonical reading envelope hashed into observation artifacts.

  • echo-wasm-abi now reports ABI_VERSION 12 for the expanded ReadingEnvelope response shape. Legacy retained reading envelopes that omit the new optional contract, query identity, and retained-evidence fields decode those fields as None or empty vectors.

  • warp-core now attaches contract package evidence to installed contract readings and receipt correlations. Installed QueryView readings carry package id, package name/version, artifact hash, schema hash, codec identity, registry version, query op id, and operation kind in the ReadingEnvelope. Installed mutation receipt correlations copy the same package evidence from ticketed runtime ingress after scheduler-owned execution. Built-in reads and non-package observers can still leave this evidence empty. The evidence is metadata only: it does not grant tick authority, mutate state, replace semantic reading identity, or act as a CAS lookup key.

  • warp-core now connects the installed contract package boundary to the witnessed intent pipeline. Package-supported canonical EINT mutation ids can be staged through ticketed runtime ingress only after Echo has witnessed the submission and verified an installed package owns the op id; unsupported installed-contract mutation ids are rejected before they become runtime-visible scheduler work. The new installed-contract intent pipeline tests prove application submission does not tick or execute, ticketed ingress stages without executing, scheduler-owned ticks dispatch the installed mutation handler, conflict rejection is a final tick outcome with blocker attribution, duplicate submits do not create hidden retries, witnessed submissions can be replayed back into pending ingress history without staging inbox work, and the replayed pipeline converges to the same receipt correlation and observed outcome. Replayed witnessed submission records preserve generation continuity so the next live submission receives the next contiguous generation instead of skipping ahead.

  • warp-core now exposes an installed contract package registry boundary for runtime-owner host adapters. An installed package binds generated registry metadata, schema hash, codec identity, package artifact identity, supported mutation op ids, mutation handler rules, supported query op ids, and read-only query observers before the handlers or observers are installed into Engine. The boundary verifies the generated RegistryProvider with echo-registry-api, rejects unknown operation ids, rejects mutation/query kind mismatches, rejects mutation rules whose generated rule name does not bind the declared mutation op id, rejects duplicate package operation ids, and preflights package-internal rule name/id conflicts plus engine-level rule and observer conflicts before mutating engine state. This does not add dynamic plugin loading, application-controlled ticks, streaming subscriptions, or domain nouns to warp-core.

  • echo-wesley-gen --contract-host now emits std-only query observer host helpers against warp-core's ContractQueryObserver boundary. Generated query helpers include deterministic authored observer plan identity, typed context-vars decoders that return Result on malformed canonical vars, and typed observer constructors that install read-only host closures through Engine::register_contract_query_observer. The core observer function boundary now returns a typed Result, so decode failures and host observer failures are explicit observation errors. The generated smoke crate proves mutation host helpers and query observer helpers install together without giving query observers write authority, tick authority, or application nouns in core.

  • warp-core now routes QueryView/Query observations to installed contract query observers. Installed observers are keyed by generated query op id, receive canonical vars bytes plus the resolved causal basis, return ObservationPayload::QueryBytes, and stamp the emitted ReadingEnvelope with the authored observer plan identity. Unsupported query ids remain typed UnsupportedQuery errors, artifact identity changes when query vars, op id, schema/plan identity, or basis changes, and observer-reported residual posture participates in bounded reading evidence. This does not add streaming subscriptions, generated query observer helpers, dynamic plugin loading, or application-controlled execution.

  • echo-wesley-gen now supports --contract-host, an opt-in generated helper surface for installed warp-core mutation handlers. Generated mutation helpers now include stable contract command-rule names, op-id matchers, typed vars decoding from scheduler-materialized EINT runtime ingress events, base runtime-ingress read footprints, and rule constructors that accept host-supplied executor and footprint functions. A generated toy-counter smoke crate proves the emitted helpers install into warp-core and run only during scheduler-owned ticks. This flag is std-only and does not implement QueryView, dynamic plugin loading, or a generated application mutation body.

  • warp-core now exposes a scheduler-owned installed contract host seam for EINT-backed mutation handlers. Host/generated cmd/* rules can read a scheduler-materialized runtime ingress event, match its EINT operation id, borrow canonical vars bytes for generated decoding, and extend a standard runtime-ingress read footprint with handler-specific writes. Tests prove an installed toy contract handler does not run during application dispatch, runs only during SchedulerCoordinator::super_tick(...), and ignores nonmatching EINT operation ids. This does not generate Wesley handler rules, implement QueryView, add dynamic plugin loading, or allow application code to tick the runtime.

  • warp-core now records runtime-local scheduler fault quarantine posture after internal scheduler faults. Lawful receipt-level rejections remain normal tick outcomes and do not fault heads. Scoped internal head faults roll back the failed SuperTick attempt, record scheduler fault evidence, quarantine only the failing writer head, and allow unrelated heads to proceed on later ticks. Unscoped panic faults mark the runtime globally faulted until trusted runtime recovery resolves the fault. Generic head eligibility changes do not clear fault quarantine. Durable control-plane/provenance publication for scheduler fault evidence remains follow-up work. Trusted host adapters can enable warp-core/trusted_runtime to construct the recovery authority; the authority remains unavailable to ordinary application builds.

  • warp-core now exposes a zero-write observe_intent_outcome(...) polling surface over witnessed submission ids. The observation reports UnknownSubmission, Pending with optional ticketed-ingress identity, or Decided with the scheduler-owned receipt correlation and typed receipt decision once a ticketed submission reaches a tick receipt. The decision reports applied entries or rejected entries with deterministic rejection reason and blocker attribution. This does not stream updates, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry.

  • warp-core now records scheduler-owned receipt correlations for ticketed runtime ingress. After SchedulerCoordinator::super_tick(...) commits a ticketed ingress batch, Echo indexes the witnessed submission id, admission ticket digest, ticketed ingress id, ingress id, writer head, logical tick coordinates, receipt digest, and commit hash. Correlations are created only after scheduler-owned ticks and only for ticketed runtime ingress; legacy direct inbox ingress remains uncorrelated. This does not expose intent outcome observation, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry.

  • warp-core now exposes a ticketed runtime ingress boundary. WorldlineRuntime::submit_intent(...) records witnessed submission history without entering a head inbox, ticking, dispatching handlers, or mutating application state. WorldlineRuntime::ingest_ticketed_invocation(...) stages a witnessed submission into runtime ingress only when the caller holds the explicit TicketedRuntimeIngressAuthority runtime-owner token and supplies an OpticAdmissionTicket, records deterministic ticketed-ingress correlation material, rejects unknown or mismatched submissions, and treats duplicate staging of the same ticket/submission pair idempotently. This does not correlate tick receipts, expose intent outcome observation, dispatch installed handlers, execute contracts outside scheduler-owned ticks, or introduce automatic retry.

  • warp-core optic invocation admission now issues an OpticAdmissionTicket after BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, SchedulerAdmission, SchedulerWorkCandidate, and LawWitness all resolve. The ticket binds the registered artifact handle, artifact hash, operation id, requirements digest, canonical variables digest, request digests, law witness digest, and a deterministic ticket digest, and publishes an AdmissionTicketIssued graph fact with the same invocation-binding material. Echo-owned admission evidence fixture recorders now require an explicit OpticAdmissionEvidenceAuthority token, making the host/runtime-owner boundary explicit before test fixture evidence can be recorded; the runtime-owner constructor is only available behind warp-core's internal host_test feature. This does not enqueue scheduler work, enter runtime ingress, tick, dispatch handlers, execute contracts, correlate tick receipts, or observe intent outcomes.

  • warp-core now records a narrow WitnessedIntentSubmission ledger when WorldlineRuntime::ingest(...) accepts canonical application ingress. The runtime derives a deterministic submission_id from the resolved writer head and content-addressed ingress_id, assigns an Echo-owned submission_generation for intake/audit correlation, and returns the same submission identity for duplicate pending or committed ingress without appending duplicate semantic submission history. This ledger does not tick, mutate application state, dispatch handlers, enqueue scheduler work, issue law witnesses, issue admission tickets, or make submission order decide scheduler order. DispatchResponse now carries optional submission_id and submission_generation fields for application ingress, and the WASM ABI version is now 10.

  • warp-core optic invocation admission now has a narrow SchedulerWorkCandidate boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, and SchedulerAdmission all resolve, Echo checks runtime-owned scheduler work candidate facts for the registered artifact handle. Without that Echo-owned scheduler work candidate fact, the ladder obstructs at SchedulerWorkUnavailable; with the exact scheduler-work-candidate:resolved-fixture fixture, the ladder advances to LawWitnessUnavailable. Scheduler work candidate fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing scheduler work candidate evidence. This does not add law witnesses, admission tickets, scheduler enqueueing, handler dispatch, execution, or caller-supplied scheduler work testimony.

  • warp-core optic invocation admission now has a narrow LawWitness boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, InvocationAdmission, SchedulerAdmission, and SchedulerWorkCandidate all resolve, Echo checks runtime-owned law witness facts for the registered artifact handle. Without that Echo-owned law witness fact, the ladder obstructs at LawWitnessUnavailable; with the exact law-witness:resolved-fixture fixture, the ladder can issue an admission ticket. Law witness fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing law witness evidence. This does not enqueue scheduler work, dispatch handlers, execute contracts, or accept caller-supplied law witness testimony.

  • warp-core optic invocation admission now has a narrow SchedulerAdmission boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, capability identity coverage, and InvocationAdmission all resolve, Echo checks runtime-owned scheduler admission facts for the registered artifact handle. Without that Echo-owned scheduler admission fact, the ladder obstructs at SchedulerAdmissionUnavailable; with the exact scheduler-admission:resolved-fixture scheduler admission fixture, the ladder advances to SchedulerWorkUnavailable. Scheduler admission fixture recording is scoped through Echo-issued artifact handles, publishes idempotent graph facts, and rejects unknown handles without publishing scheduler admission evidence. This does not add admission tickets, law witnesses, scheduler work, scheduler enqueueing, handler dispatch, execution, or caller-supplied scheduler admission testimony.

  • warp-core optic invocation admission now has a narrow InvocationAdmission boundary. After BasisResolution, ApertureResolution, BudgetResolution, RuntimeSupport, and capability identity coverage all resolve, Echo checks runtime-owned admission facts for the registered artifact handle. Without that Echo-owned admission fact, the ladder obstructs at InvocationAdmissionUnavailable; with the exact invocation-admission:resolved-fixture admission fixture, the ladder advances to SchedulerAdmissionUnavailable. Invocation admission fixture recording is scoped through Echo-issued artifact handles, so caller-supplied invocation bytes and capability presentations cannot supply admission testimony. This does not add admission tickets, law witnesses, scheduler admission, scheduler work, handler dispatch, execution, or successful grant validation.

  • warp-core optic invocation admission now has a narrow RuntimeSupport boundary. After BasisResolution, ApertureResolution, and BudgetResolution all resolve, Echo checks runtime-owned support facts for the registered requirements digest. Without that Echo-owned support fact, admission still obstructs at RuntimeSupportUnavailable; with the exact runtime-support:resolved-fixture support fixture and no Echo-owned invocation admission fact, the ladder advances to InvocationAdmissionUnavailable. Runtime support fixture recording is scoped through Echo-issued artifact handles, so unknown handles cannot publish support facts, repeated recordings for the same requirements digest do not duplicate support facts, and registration rejects artifacts whose stored requirements digest does not match the artifact requirements digest. This does not add caller-supplied runtime support testimony, admission tickets, law witnesses, scheduler work, execution, budget reservation, or successful grant validation.

  • dispatch_optic_intent(...) and the default KernelPort optic dispatch path now reject EINT payloads that use Echo's reserved scheduler/control op id, closing the remaining application-facing control-intent ingress path.

  • warp-core optic invocation admission now has a narrow ApertureResolution boundary. Identity-covered invocations with exact fixture basis bytes basis-request:resolved-fixture and exact fixture aperture bytes aperture-request:resolved-fixture progress past aperture resolution and still obstruct at UnsupportedBudgetResolution; unsupported aperture shapes continue to obstruct at UnsupportedApertureResolution, and aperture resolution remains unreachable when basis resolution fails. This does not issue admission tickets, law witnesses, scheduler work, execution, budget evaluation, runtime support checks, or successful grant validation.

  • warp-core optic invocation admission now has a narrow BasisResolution boundary. Identity-covered invocations with exact fixture basis bytes basis-request:resolved-fixture progress past basis resolution and still obstruct at UnsupportedApertureResolution; all unsupported non-empty basis shapes continue to obstruct at UnsupportedBasisResolution. This does not issue admission tickets, law witnesses, scheduler work, execution, aperture resolution, budget evaluation, runtime support checks, or successful grant validation.

  • warp-core optic invocation admission now has a budget/runtime-support obstruction shell. Empty budget request bytes obstruct as MissingBudgetRequest; UnsupportedBudgetResolution and RuntimeSupportUnavailable are defined as future vocabulary but remain unreachable until basis and aperture resolution exist.

  • docs/design/budget-and-runtime-support-optic-admission.md defines budget as caller-supplied bounded-resource context and runtime support as Echo-owned capability checking against registered artifact requirements, not caller testimony.

  • warp-core optic invocation admission now has an aperture-bound obstruction shell. Empty aperture request bytes obstruct as MissingApertureRequest; UnsupportedApertureResolution is defined as future vocabulary but remains unreachable until basis resolution exists because aperture semantics are scoped inside a resolved causal basis.

  • docs/design/aperture-bound-optic-admission.md defines aperture as the visibility/effect window over a resolved basis and pins the rule that basis resolution gates aperture resolution.

  • warp-core optic invocation admission now has a basis-bound obstruction shell. Empty basis request bytes obstruct as MissingBasisRequest; identity covered capability presentations still obstruct as UnsupportedBasisResolution because Echo has not wired basis resolution, admission tickets, law witnesses, scheduler work, or execution into invocation admission.

  • docs/design/basis-bound-optic-admission.md defines the current basis boundary: basis selection is explicit admission context, and covered authority material still cannot authorize execution without basis resolution.

  • warp-core optic invocation admission can now route bound capability presentations through a narrow CapabilityPresentationValidator to publish sharper grant-validation obstruction facts while preserving conservative CapabilityValidationUnavailable invocation refusal. Identity coverage still does not issue an admission ticket, law witness, scheduler work, or execution.

  • docs/design/invocation-grant-validation-obstruction-routing.md defines the validator routing boundary: validation evidence refines refusal, but it does not create authority.

  • warp-core now publishes GraphFact::CapabilityGrantValidationObstructed when recorded capability grant material fails narrow identity coverage against a registered optic artifact. The validation checks artifact hash, operation id, requirements digest, and explicit expiry posture, and remains refusal-first: it does not issue successful admission tickets, law witnesses, scheduler work, execution, delegation policy, quorum governance, or Continuum protocol.

  • docs/design/capability-grant-validation-obstruction-facts.md defines grant validation obstruction as graph evidence rather than authority. A recorded grant can fail causally before any invocation can succeed.

  • warp-core now publishes GraphFact::OpticInvocationObstructed whenever the optic invocation admission skeleton refuses an invocation. The fact records the artifact handle id, operation id, canonical variables digest, basis and aperture request digests, and structured obstruction kind without creating a success admission ticket, law witness, execution, scheduler output, or counterfactual candidate.

  • docs/design/invocation-obstruction-graph-facts.md defines the invocation refusal publication boundary: registered handles are not authority, and invocation obstruction facts are causal refusal evidence rather than counterfactual worlds.

  • Local verification now maps warp-core optic artifact and causal fact source changes to the exact integration test targets they exercise, avoiding broad Cargo name-filter runs while preserving targeted smoke coverage.

  • warp-core now publishes in-memory causal graph facts from optic artifact registration. Successful registration emits GraphFact::ArtifactRegistered, computes a deterministic FactDigest, and links that digest from an ArtifactRegistrationReceipt; obstructed registration emits GraphFact::ArtifactRegistrationObstructed without issuing a handle or success receipt. Fact digests use explicit domain tags, field tags, present/absent markers, and length-prefixed bytes, not JSON.

  • docs/design/graph-fact-publication-skeleton.md defines the first substrate publication boundary: facts are world statements, receipts explain publication/refusal boundaries, and registration facts are the first in-memory proof that Echo can describe its own runtime decisions.

  • echo-wesley-gen now imports real wesley-core 0.0.4 runtime optic artifacts into warp-core registration structs, preserving Wesley artifact hashes, schema ids, operation ids, requirements digests, and registration descriptors while keeping warp-core free of a Wesley dependency. Echo still owns opaque runtime-local OpticArtifactHandle issuance. Imported admission requirements now preserve Wesley-owned canonical requirement bytes, codec id, and digest directly from OpticAdmissionRequirementsArtifact; downstream runtimes must not serialize Wesley structs to create admission truth.

  • docs/procedures/DIRECT-MAIN-EXCEPTION-LOG.md records the 2026-05-14 docs-only direct-main exception for the Echo graph model checkpoint, including authorization context, exact commits, validation, changed files, and the future rule to prefer PRs unless an emergency or docs-only fast path is explicitly authorized. Future exception records must also cite explicit authorizer identity and authorization evidence.

  • docs/design/built-in-echo-graph-data-model.md defines Echo's native graph ontology for future optic admission, authority, transaction atomicity, receipts, witnessed readings, footprint addressing, transaction-local object identity, worldlines, strands, attachments, provenance, materialization, import/export, and settlement.

  • docs/design/obstruction-receipt-boundary.md distinguishes causal obstruction receipts from counterfactual retention: refusal is a causal event but not admission, and counterfactuals begin only after a rewrite is legally admitted and then left unselected at the scheduler boundary.

  • warp-core now attaches an ObstructionReceipt to capability grant intent refusals. The receipt records causal refusal context and remains explicitly RewriteDisposition::Obstructed, not an admission ticket, law witness, or counterfactual candidate. It also carries the authority policy id/posture used to classify the refusal when that policy context is present. Receipt input bytes are rebuilt on demand for digest verification instead of being stored on every refusal receipt.

  • docs/design/transaction-optic-atomicity-model.md defines Echo's doctrine for atomic composite optics: one basis, one admission surface, transaction-local execution, one committed delta, and receipt-emitting refusal or admission. It also pins the rule that policy evaluation reading graph state is an atomic causal phase, not a detached preflight query.

  • warp-core now has an Echo-owned OpticArtifactRegistry registration proof for Wesley-compiled optic artifacts. The registry verifies artifact id, artifact hash, schema id, operation id, and requirements digest before storing admission requirements internally and returning an opaque OpticArtifactHandle.

  • warp-core now has an optic invocation admission skeleton that resolves registered artifact handles internally and obstructs unknown handles, operation mismatches, and registered-handle invocations without capability presentation. Admission outcomes are must-use, and placeholder capability presentations still obstruct until grant validation is wired into invocation admission. The registration and invocation regression fixtures avoid expect(...) so all-target Clippy remains clean.

  • Optic invocation obstruction now returns a ticket-shaped pre-admission posture carrying the invocation handle, operation id, canonical variables digest, basis request, aperture request, and structured obstruction reason. This is not a success ticket and does not authorize execution.

  • Optic invocation admission now classifies capability presentation obstruction without validating grants: missing, malformed, unbound, and placeholder presentations all remain obstructed until real bounded grant validation exists.

  • warp-core now has an Echo-owned capability grant intent obstruction skeleton. CapabilityGrantIntentGate records well-formed submitted authority intents deterministically, obstructs malformed, missing-issuer, invalid-delegation, scope-escalation, replay/duplicate, and unsupported-policy grant intents, and keeps all submissions from becoming authority until future witnessed grant admission exists.

  • Echo-owned WASM package boundary tooling: scripts/build-warp-wasm-package.sh now builds crates/warp-wasm/pkg with the bundler target and the package export smoke test imports crates/warp-wasm/pkg/rmg_wasm.js to verify the JavaScript byte ABI surface expected by consumers.

  • The WASM package export smoke test now runs through scripts/tests/warp_wasm_package_exports_test.sh, which rebuilds the package before importing it so the export witness cannot pass against a stale package.

  • Stack Witness 0001 drift lock — warp-wasm now mirrors Wesley's fixture vectors for the jedit-through-Echo walking skeleton and verifies Echo's fixture op ids, buffer-inclusive fixture vars bytes, the wesley-binary/v0 target codec marker, helper entrypoints, and expected QueryBytes("hello") payload bytes against that vector.

  • echo-registry-api::verify_contract_artifact(...) — generic load-time verification for Wesley-generated registries, including schema/codec/layout checks, expected footprint certificate hashes, optional generated artifact hashes, and a policy switch requiring all mutation operations to be backed by an expected certificate before the artifact is treated as compile-time-certified.

  • Cycle 0003 (dt policy) — ratify fixed timestep as default, variable-dt as opt-in admitted stream, braidability constraint for settlement.

  • KERNEL_strand-contract backlog item — strand as a first-class relation with exact fields, invariants, lifecycle, and TTD mapping.

  • KERNEL_strand-settlement backlog item — deterministic settlement semantics (compare → plan → import → conflict artifact).

  • crates/method/ — standalone METHOD library crate (cycle 0002). cargo xtask method status and cargo xtask method status --json for backlog lane counts, active cycles, and legend load.

  • Adopt METHOD: backlog lanes, legends, cycle loop, BEARING signpost.

  • docs/DOCS_AUDIT.md — full audit of every file in the docs corpus.

  • docs/BEARING.md — current direction and tensions signpost.

  • Four legends: KERNEL, MATH, PLATFORM, DOCS.

  • Seven asap backlog items (five xtask METHOD commands, docs cleanup, roadmap migration).

  • Three graveyard entries (BOAW naming, 5x Duty Model, unimplemented future specs).

Removed

  • Removed the provisional caller-authoritative causal-anchor API: CausalAnchorRequest, CausalAnchorFact::from_request, public admitted-fact fields, and raw admitted-identity constructors. Applications now submit a CausalAnchorAdmissionRequest and treat the returned Echo fact, receipt, and identities as opaque. This is an intentional breaking Rust API correction; preserving the old surface would let callers manufacture Echo authority.
  • Removed the abandoned Method system: its workspace crate and xtask commands, checked-in backlog, cycles, retrospectives, status ledgers, process manuals, and generated task graphs. Current architecture now lives in canonical topics/specs/invariants, durable decisions live in ADRs, and live work/status lives in GitHub.
  • Removed the superseded docs/design/ packet corpus and the retired TTD counterfactual-creation invariant after promoting current doctrine into canonical topics, ADRs, architecture documents, specifications, and tests.
  • Removed the remaining architecture drift/future packets and dated benchmark reports after preserving the retained-reading storage and proof boundary in ADR 0020. Benchmark instructions now keep methodology in source docs and measurements in generated artifacts and pull requests.
  • Deleted zombie crates with no consumers (recoverable from git history): echo-wasm-bindings (browser demo kernel), echo-ttd, ttd-protocol-rs, and echo-session-proto (the TTD stack now lives with warp-ttd), plus echo-config-fs (desktop app-shell fossil) and the packages/ttd-protocol-ts generated consumer.
  • Deleted echo-app-core (desktop app-shell fossil: toasts, prefs, config ports) and the echo-dry-tests in-memory config fake that existed only to test its trait; no other crate consumed either.
  • Removed the unused echo-wasm-abi::ttd module and its public PrivacyMask, SessionToken, and TtdError exports after the owning TTD/session stack was retired. This is a breaking Rust API removal for unknown external consumers.
  • Deleted cargo xtask wesley (existed only to sync the removed TTD protocol consumer artifacts).
  • Deleted stale point-in-time audit reports under docs/audit/ and docs/audits/.
  • Removed the deleted crates from workspace members, CI clippy lanes, det-policy.yaml, scripts/verify-local.sh, and the unordered-ABI allowlist.
  • Removed the VitePress docs-site toolchain from active repo tooling: npm scripts, Make targets, tracked docs-site config, the dead browser-open helper, and VitePress/Mermaid dependencies are gone.
  • Removed the broken warp-core/serde feature and the gated Serializable* wrapper exports. warp-core no longer declares direct serde, serde-value, or ciborium dependencies; authoritative core serialization must stay in explicit canonical boundary encoders rather than general serde derives.
  • Removed the legacy ttd-browser crate from Echo's active workspace. The release browser/runtime boundary now stays centered on warp-wasm and echo-wasm-abi; debugger session semantics and browser delivery adapters belong in warp-ttd.
  • docs/METHODOLOGY.md — 5x Duty Model (never practiced; see graveyard).
  • 17 unimplemented future spec files (see graveyard).
  • docs/march-16.plan.md — stale planning scratchpad.
  • docs/plans/parallel-merge-and-footprint-optimizations.md — superseded by design review.
  • Old plans, book (LaTeX), and research artifacts. All remain recoverable from Git history.
  • warp-ffi crate deleted: The C ABI integration path (crates/warp-ffi) has been removed. The C ABI approach was abandoned in favor of Rust plugin extension via RewriteRule trait registration and Rhai scripting. See TASKS-DAG.md #26 (Graveyard). This is a BREAKING CHANGE for any downstream code that depended on the C FFI surface.

Changed

  • Public installed-contract evidence fields on runtime ingress, receipt correlation, outcome, and WAL state-delta carriers now use Option<InstalledInvocationEvidence> instead of Option<ContractEvidenceIdentity>. This is an intentional pre-1.0 source compatibility change: legacy callers wrap with LegacyContract or .into() and inspect with legacy_contract(), while provider callers inspect provider_v1(). The enum is non-exhaustive to match the extensible wire-tag family, so direct downstream matches require a wildcard arm. The legacy tag-1 WAL encoding remains byte-identical.
  • The public RuntimeError enum now includes InstalledContractIntentKindMismatch and UnsupportedInstalledProviderContractMutation, and the public ContractInverseObstruction enum now includes ProviderTargetUnsupported. These are intentional pre-1.0 source-compatibility additions: downstream exhaustive matches must handle the new variants (or use an appropriate wildcard arm).
  • echo-wesley-gen now follows Wesley's operation-neutral adapter names: import_runtime_optic_artifact(...) accepts OperationArtifact, and import_registration_descriptor(...) accepts OperationRegistrationDescriptor. Source consumers using Wesley's former OpticArtifact or OpticRegistrationDescriptor names must update when they adopt the corresponding Wesley 0.3 prerelease; Echo's runtime-local optic artifact types and handles are unchanged.
  • Provider semantic-source, generation-input, and contract-pack Display diagnostics now render explicit kebab-case failure labels instead of Rust Debug variant spellings. Typed error enums remain the programmatic contract, while human/CLI diagnostics no longer move when Rust variants are refactored.
  • Restored the durable ADR 0001–0011 namespace and moved the post-Method decisions to ADR 0012–0019, preserving the meaning of existing source citations. CI now rejects missing, duplicate, non-contiguous, unindexed, or collided ADR identifiers.
  • Recorded the WSC, CAS, semantic reading identity, and optional proof boundary as ADR 0020 without carrying forward the source packet's implementation roadmap or application-specific checkpoint design.
  • Replaced the opaque numeric determinism claim-pack generator with an honest gate over upstream job results and exact artifact payload presence. The executable suites remain the authority for what passed.
  • Replaced the frozen root architecture and advanced guides with explicit supersession signposts to the living no-graph architecture, topics, specifications, invariants, and ADRs.
  • Echo 1.0 release eligibility now depends only on Continuum participant conformance, networked causal suffix exchange, and release integrity. Edict, jedit, and any particular generated package remain downstream compatibility work and no longer gate the Echo release.
  • Echo 1.0 planning references now point at the cross-repository Continuum Stack Convergence Project instead of the retired Echo-only Project.
  • Local scripts/verify-local.sh full now treats broad Cargo test lanes as GitHub Actions-owned by default, while keeping a maintainer opt-in through VERIFY_LOCAL_FULL_TESTS=1 for intentional local full-suite runs.
  • warp-core renamed the generated contract package host API from install_contract_package(...) to register_contract_package(...) so the trusted-runtime boundary reads as explicit runtime-owned registration instead of process-global installation.
  • warp-core sealed braid member lookup now requires authority-bound sealed query material, redacts non-public blinding material from debug output, and keeps hidden-member commitments stable across parent frontier movement.
  • warp-core settlement planning now rejects non-Shared strands before producing import candidates. Author-only/debugger strand suffixes can remain real causal work, but they cannot enter base shared history without an explicit shared admission posture. Settlement compare remains local revelation/inspection only: it can inspect a locally held strand suffix without promoting, planning, admitting, or settling it.
  • warp-core settlement plural artifacts and retained braid shells now carry the source strand posture instead of hard-coding author-only posture for shared settlement records.
  • Local determinism tooling now fails closed around scripts/check-warp-core-serialization-boundaries.sh. The serialization boundary guard is mandatory, runs through bash rather than executable mode, works without rg, rejects table-form serde/ciborium dependencies, and blocks direct, grouped, multiline, or aliased canonical ABI serialization imports outside explicit warp-core boundary modules.
  • The nondeterminism guard now shares the same rg/Perl fallback scanner, supports DETERMINISM_FORCE_NO_RG=1 regression coverage, catches namespace imports and alias calls for std::env, std::fs, and std::process, bans std::thread::available_parallelism, and replaces file-wide allowlists with rule-scoped waivers for build/native filesystem boundaries and test fixtures.
  • warp-core engine and scheduler state now use ordered BTreeMap/BTreeSet storage instead of HashMap, HashSet, or FxHashMap in deterministic core paths. WAL filesystem tests also recreate stale deterministic fixture roots before use so previous local residue cannot change the test outcome.
  • warp-core engine construction now defaults to deterministic serial execution instead of reading ECHO_WORKERS or host CPU availability. Callers can still opt into parallel execution explicitly with EngineBuilder::workers(...) or worker-count constructors.
  • echo-cli wal submission-posture now exposes generic read-only recovery JSON for one submission id and canonical envelope digest. The output reports retry posture, recovered submission posture, receipt digest, and ticket digest without importing any application nouns into Echo.
  • Runtime WAL-backed scheduler ticks now roll back all tick WAL evidence from a failed multi-head scheduler pass, treat missing or mismatched receipt correlation evidence as an invariant error instead of a normal obstruction, and bind runtime recovery certificates to rebuilt submission and receipt indexes.
  • warp-wasm no longer contains the legacy Stack Witness 0001 createBuffer/replaceRange/textWindow shortcut. QueryView requests now route through the generic installed contract observer boundary only; without an installed observer, WASM observe(...) returns UNSUPPORTED_QUERY instead of materializing hardcoded text bytes.
  • warp-core structured binding tests no longer use rope/text-shaped fixture names. The executable examples now exercise generic authored scopes, heads, segments, and markers so core test fixtures do not imply built-in editor semantics.
  • The canonical pre-push hook now runs the narrowest changed-file Rust witness instead of reusing the broader local PR gate. Rust module edits map to exact cargo test -p <crate> --lib <module>::tests slices, integration-test edits map to exact --test <target> invocations, and tooling edits stay on local shell smoke checks. Broader clippy, rustdoc, package, and workspace coverage remains available through make verify-pr, make verify-full, and CI. The selector now avoids fake zero-test module filters for source files without inline tests, maps src/bin/*.rs edits to exact binary targets, and preserves required features for gated integration tests.
  • Deterministic math now lives in a slim warp-math workspace crate. warp-core keeps the existing warp_core::math::* compatibility surface as a re-export, while warp-geom depends directly on warp-math instead of pulling in all of warp-core. Math-only integration tests, deterministic trig golden vectors, PRNG golden regression, and the LUT generator moved with the math crate.
  • CI and local verification now split broad clippy coverage into explicit library, binary, and selected integration-test lanes instead of invoking one monolithic cargo pass. The warp-core runtime inbox test target is now an explicit lint lane with the same native_rule_bootstrap,host_test features used by the ticketed-ingress regression suite.
  • Local verification now treats rustdoc warnings as CI-owned by default. scripts/verify-local.sh skips local rustdoc lanes unless VERIFY_LOCAL_RUSTDOC=1 is set, keeping pre-push and full local gates focused on faster edit-loop witnesses while preserving CI rustdoc coverage.
  • Tooling-only full verification now selects focused hook regression scripts by changed file family, so a scripts/verify-local.sh edit runs the verify-local hook regression without also running unrelated runtime-schema, PR-status, or timing hook tests.
  • Local hook regression tests are now CI-owned by default. The local full gate skips hook tests unless VERIFY_LOCAL_HOOK_TESTS=1 is set, and the opt-in hook-test lane clears verifier override variables before launching nested hook regressions.

Fixed

  • Generic executable-operation lowering and independent verification now resolve source-local obstruction constructor aliases through the exact digest-locked lawpack import before encoding or comparing the package. Runtime duplicate outcomes therefore retain the capability-owned obstruction coordinate instead of exposing an application-local alias or collapsing it into the generic precondition-mismatch class.
  • Provider-native installation now applies the same pure structural validation used to reconstruct retained invocation evidence before mutating any Echo engine index. Empty operation or Target IR coordinates, empty Target IR digest domains, and Target IR digests that are not exact lowercase sha256:<64-hex> values fail with stable typed installation errors, so Echo cannot originate receipt or WAL evidence that fresh-host recovery would reject. Existing valid tag-2 provider evidence and byte-stable tag-1 legacy evidence retain their encoding and recovery behavior.
  • Full local verification now enables the declared native_rule_bootstrap,trusted_runtime feature set when testing or linting provider_contract_admission_tests, matching the canonical pre-push route.
  • Direct GraphQL SDL lowering in echo-wesley-gen now binds the exact pinned wesley-core version into generated Rust artifact-hash provenance, with a regression test that refuses dependency/provenance version drift.
  • Generated-rule architecture now distinguishes Wesley's current raw RewriteRule fixture path, Edict's fixture-only Target IR bridge, and the still-target package-registration corridor. It also records native_rule_bootstrap as an opt-in Cargo policy boundary rather than an access-control seal.
  • Generated-rule documentation no longer implies that release footprint enforcement is already wired. Wesley and Edict packs remain unqualified until package emitters and positive and negative footprint_enforce_release witnesses exist.
  • warp-core recovered filesystem WAL ACK paths now rebuild the live evidence catalog before returning recovered success, live catalog-update failures record the last commit where the catalog was actually fresh, and committed evidence segments now populate coverings_by_range for their exact LSN range. Rebuilt evidence catalogs now reject malformed commit/frame evidence before admitting ExactCommittedWal segments.
  • Cargo.lock now pins crossbeam-epoch to 0.9.20, clearing RUSTSEC-2026-0204 for the benchmark-only rayon dependency path.
  • warp-core evolving braid logs now reject unchecked incremental mutations: Braid::apply returns typed lifecycle errors, rejects duplicate member weaving and mixed revealed/sealed membership, refuses empty-frontier settlement finalization, detects member sequence overflow with checked arithmetic, rejects empty collapse witnesses, and exposes folded state through read-only accessors instead of public mutable fields. Duplicate checks now use a deterministic member index instead of scanning the append-ordered frontier.
  • warp-core braid-shell digests now bind optional proof-shaped envelopes: proof-bearing shells have distinct content identity from proof-less shells, mutating proof bytes after assembly is caught by shell validation, and BRAID_SHELL_VERSION is now 2 for the proof-digest marker shape. Shape-only proof envelope admission is limited to replay-trace evidence; cryptographic proof kinds require a verifier backend before admission.
  • warp-core sealed braid members now require caller-supplied blinding material, preserve hidden shared source disclosure in settlement shells, mix a settlement-local MemberBlindingSalt into hidden settlement member commitments, reject mixed revealed/sealed shell member sets, and treat sealed member authority as part of duplicate-member identity.
  • warp-core retained braid shell queries now distinguish revealed member lookup from sealed member lookup: has_revealed_member_strand and BraidShellQuery::revealed_member_strand only match revealed references, while BraidShellMemberQuery carries blinding material for sealed matches.
  • warp-core crate-root braid exports now include BraidError, BraidStatus, and BraidMemberRef so external consumers can handle public braid results.
  • warp-core shared-strand settlement handles now re-enter the live registry path before planning or settling, and crate-internal settlement helpers reject stale handles that no longer match registered strand state. CausalPostureState is sealed to Echo's marker types so external crates cannot add typestate implementations outside the runtime posture gate.
  • warp-wasm settlement publication now maps non-Shared strand admission rejection to the stable INVALID_STRAND ABI error code instead of collapsing the lawful posture denial into ENGINE_ERROR.
  • echo-file-aperture now normalizes HostFileSnapshot material at the aperture boundary so caller-forged snapshot metadata or fingerprints cannot bind a basis, observation receipt, or materialization verification to bytes different from the observed host bytes.
  • scripts/verify-local.sh stamp storage now resolves the real gitdir via git rev-parse --git-dir, so pre-commit and pre-push hooks work in linked worktrees where .git is a file rather than a directory. Stamps are per-worktree as a result.
  • docs/spec/SPEC-0009-wasm-abi-v3.md is now a historical supersession signpost to the canonical current WASM ABI specification. The former v3 export table, wire contract, migration notes, and test checklist remain in Git history rather than presenting a second active ABI authority.
  • warp-core WSC retained-evidence recovery now rejects conflicting duplicate retained material digests and reading ids instead of letting recovery or the recovered retention index silently overwrite evidence identity collisions.
  • warp-core WSC causal-history and retained-evidence recovery now rejects envelopes whose recorded basis digest does not match the canonical digest of recovered records, returning typed BasisDigestMismatch obstruction evidence instead of admitting stale or forged envelope bindings.
  • echo-cli wal doctor now inspects a real filesystem WAL root through Echo's read-only filesystem WAL doctor instead of reporting a fresh empty in-memory store. The command accepts an optional WAL root path, defaults to the current directory, and the generated man pages cover the new wal subcommand.
  • warp-core witnessed-submission persistence snapshots now fail closed when a submission lacks retained canonical envelope material instead of silently dropping replayed submissions from the host-persistable image.
  • Local pre-push verification now includes the changed-file fingerprint in its cache key, skips nested integration-test helper modules instead of inventing fake --test mod targets, and only emits <module>::tests filters for source files that declare a real mod tests. The hook also preserves the delta_validate and trusted_runtime feature gates required by the corresponding warp-core integration tests.
  • warp-math is now explicitly covered by determinism classification plus the default global-state and nondeterminism guard scans, while warp-core/serde forwards the re-exported math serde feature.
  • SchedulerCoordinator::super_tick(...) now journals ticket-local receipt correlation writes instead of checkpointing whole historical correlation indexes, preserving failure-atomic rollback while keeping rollback bookkeeping proportional to the attempted tick's writes.
  • warp-core submit-only intake now enforces the same canonical IngressEnvelope content-address invariant as runtime inbox ingestion, so would_accept(...) cannot approve malformed ingress ids.
  • warp-core ticketed runtime ingress now rejects duplicate pending or already committed runtime ingress before recording ticketed correlation material, so an admission ticket cannot retroactively claim legacy direct inbox work.
  • Determinism Guards no longer runs apt-get install ripgrep; static guard scripts now fall back to Perl regex scanning when rg is unavailable, so mirror stalls cannot hang the determinism gate.
  • Stack Witness 0001 fixture observations now require the fixture createBuffer and replaceRange("hello") history to be admitted and materialized before textWindow can return QueryBytes("hello").
  • Stack Witness 0001 textWindow observations now fail closed when the bounded read budget is smaller than the returned payload and carry a deterministic BLAKE3 artifact hash instead of a dummy reading identity.
  • Strengthened Echo's Wesley fixture-vector drift lock to cover artifact family, schema, version, declared footprints, and generated helper field shapes.
  • Corrected Stack Witness 0001 terminology so the current semicolon-kv byte strings are fixture vars only, not Wesley's future runtime codec bytes.
  • Hardened Stack Witness 0001 fixture integrity by validating fixture vars before admission, requiring fixture intents to commit before textWindow materializes, and rejecting fixture QueryView reads for non-default worldlines.

Fixed (PR #326 follow-up)

  • Added regression coverage that rejects trailing whitespace in the committed echo-cli --help golden fixture, and cleaned the existing padded blank line.
  • Split generated contract artifact verification into MetadataVerified and CompileTimeCertified postures so weak or metadata-only host policies cannot accidentally enable the trusted footprint fast path.
  • Strengthened Wesley footprint certificate artifact hashes so they incorporate a generated Rust artifact manifest hash and operation argument shape instead of only the declared read/write footprint.
  • Changed GraphQL SDL operation id generation to fail closed on derived id collisions instead of silently incrementing persisted ABI ids.
  • Replaced generated query optic variable digests with Echo ABI's domain-separated BLAKE3 query_vars_digest_v1(...) helper.
  • Made built-in observation request helpers fail closed on invalid frame/projection pairs instead of silently falling back to QueryBytes.
  • Restored the CodeRabbit archive path filter and added a hook regression guard so frozen docs/archive/** files stay out of automated review.
  • Split the large warp-core optic module test body into optic/tests.rs and added a hook guard so production optic code is no longer buried under the test suite.
  • Verified imported witnessed causal suffix bundle digests before admission and reject forged retained-shell identities.
  • Validated exported witnessed suffix boundary witnesses against the source worldline and resolved base/target frontier range.
  • Fixed Wesley-generated helper output so helper-only vars and intent error types live in a generated namespace instead of colliding with user contract types, while preserving top-level helper function re-exports, and added no-std smoke coverage for op-bearing generated helpers.
  • Fixed contract-hosting docs to describe synchronous KernelPort dispatch accurately, treat ObservationRequest as the read boundary, keep artifact identity separate from trust posture, hash canonical submitted intent bytes, and require codec/hash metadata for future Continuum artifact interchange.

Fixed (PR #313 follow-up)

  • The adaptive parallel-policy experiment follow-ups so benchmark/report rows now describe the plan that actually executed, adaptive planning reuses the runtime shard-partitioning path instead of duplicating profiling logic, stale adaptive Criterion directories are selected deterministically, malformed adaptive benchmark directory names now fail loudly instead of disappearing from baked reports, conflicting truthful adaptive rows are rejected before export, and the experimental selector seam stays out of the public warp-core kernel surface while the benchmark-facing adaptive routing entrypoints remain concrete and deterministic.

Fixed (PR #312 follow-up)

  • The docs-surface reduction follow-ups so the collision tour no longer points at a deleted guide route, the architecture outline uses implementation-backed deterministic wording for the scene boundary, task-DAG tooling/docs use the new tasks-dag-source.md name consistently, and the backlog now tracks broader docs-validation cleanup beyond Markdown-only checks, including recursive docs/public/**/*.html coverage.

Fixed (PR #308 follow-up)

  • The PR workflow hardening follow-ups so pr-preflight skips deleted file-targeted inputs, pr-threads reply can target an explicit PR context instead of assuming the checkout repo, review-thread batch resolution reports partial progress before failure, GitHub auth-error detection avoids generic author-style false positives, and the workflow docs point at the tracked docs/archive/AGENTS.md path.

Fixed (PR #306 follow-up)

  • The Phase 8 runtime-schema/tooling follow-ups so workspace Prettier usage is declared and lockfile-pinned, runtime schema validation now fails clearly when node is unavailable, dependency DAG generation uses docs/archive/tasks/TASKS-DAG.md as the default task source with UTC-stable fallback labels, and the tracked Rust Analyzer workspace target dir is repo-local and cross-platform.
  • Shared Phase 8 type extraction so WorldlineId is actually opaque like HeadId, echo-wasm-abi forwards std/serde into echo-runtime-schema explicitly, echo-wasm-abi --no-default-features avoids a stray std dependency, and positive-only scheduler/inbox schema inputs are represented explicitly as PositiveInt.
  • Late Phase 8 review follow-ups so contributor docs use portable workspace links, the runtime-schema README matches the default serde contract, the schema audit/inventory docs reflect the typed-id migration, and dependency-DAG docs use the correct GitHub workflow wording.
  • Final Phase 8 review follow-ups so shared logical counters enforce their checked-arithmetic boundary, runtime-schema validation runs through the pinned pnpm schema:runtime:check entrypoint, worldline-id/schema nullability docs match the frozen 32-byte and scheduler-state contracts, and backlog follow-up tasks now require cargo xtask as the maintenance surface.

Fixed (PR #304 follow-up)

  • Fixed the session WebSocket gateway TLS stack to use the Rustls ring provider instead of AWS-LC, clearing the current cargo audit and cargo-deny blockers without weakening TLS coverage.
  • Fixed hook timing instrumentation to cache its clock source, serialize CSV header creation, and runtime-test the sequential and parallel pre-push hooks instead of only checking them statically.
  • Fixed ABI/runtime metadata surfaces so dormant heads are representable, playback cursor tick/state invariants stay encapsulated, and typed logical counter helpers have direct boundary coverage.
  • Fixed the browser adapter to reuse the canonical committed-tick helper and preserve large logical tick values end-to-end instead of clamping them.
  • Fixed final PR review follow-ups so browser-only large-tick DTOs no longer hand-edit generated protocol artifacts, forked provenance retains checkpoint state at the copied tip, verify-local records failing lane timings even when helpers exit, and the session gateway tolerates an already-installed Rustls crypto provider.
  • Fixed final replay/tooling follow-ups so checkpoints are validated before storage, suffix replay rebuilds metadata without a second provenance scan, hook timing reaps stale CSV locks, pr-status propagates paginated parse failures, and mixed timing logs prefer current run records over legacy rows.
  • Fixed final Rabbit review follow-ups so checkpoint fixtures carry honest replay metadata, playback rejects non-canonical tick-zero materializations, observation/spec docs spell out deterministic U0 hashes, and verifier timing appends stay serialized without hiding helper failures.

feat(warp-core): complete Phase 7 full-state replay

  • Changed playback, replay, snapshot, and fork materialization now rebuild full WorldlineState instead of a warp-local store-only approximation.
  • Added checkpoint-backed playback and provenance replay so historical materialization can restore from validated full-state checkpoints as an acceleration path before replaying the remaining suffix from authoritative provenance.
  • Changed replay, observation, and ABI metadata now carry typed WorldlineTick / GlobalTick coordinates consistently across the public Phase 7 boundary.

feat(tooling): harden the post-Phase-5 dev loop

  • Changed local verification success stamps now key off the actual checked tree instead of HEAD, so commit-only churn can reuse the same clean proof across manual and hook-triggered runs without ignoring unstaged or untracked changes.
  • Added per-lane and per-run timing records under .git/verify-local/timing.jsonl, keeping local timing artifacts off the tracked repo while making verifier cost visible.
  • Added scripts/pr-status.sh plus make pr-status as a one-shot GitHub summary for PR number, head SHA, unresolved thread count, review decision, merge state, and grouped checks.
  • Fixed cargo nextest targeted verification now respects crate target shape instead of hardcoding --lib --tests, which keeps bin-only crates from tripping the local fast path.
  • Changed the full local tooling lane now runs all hook regression scripts under tests/hooks/test_*.sh instead of one hardcoded verifier test.

feat(tooling): split local verification into parallel lanes

  • Changed the local full verifier now runs as curated parallel lanes with isolated CARGO_TARGET_DIRs for clippy, tests, rustdoc, and guard checks, which cuts local wall-clock time by avoiding one giant serialized cargo invocation.
  • Changed staged and reduced local Rust checks now use a narrower fast-path target surface, keeping the heaviest all-target clippy drag in CI instead of every local iteration loop.
  • Changed full local verification is now scope-aware: tooling-only full changes stay tooling-local, while critical Rust changes run local smoke lanes and defer exhaustive proof to CI.
  • Changed local warp-core smoke selection is now file-family aware: default source edits stay on --lib, runtime/inbox files pull inbox, playback files pull playback-smoke tests, and PRNG edits pull the golden regression.
  • Changed local warp-wasm and echo-wasm-abi smoke selection is now file-family aware too: warp-wasm/src/lib.rs stays on plain lib smoke, warp_kernel.rs pulls the engine-enabled lane, canonical ABI work pulls only canonical/floating-point vectors, and non-Rust crate docs no longer wake Rust lanes at all.
  • Added make verify-ultra-fast as the shortest local edit-loop lane: changed Rust crates get cargo check, critical runtime surfaces still pull targeted smoke tests, tooling-only changes stay on a syntax/smoke path, and clippy/rustdoc/guard scans stay on heavier local paths and CI.
  • Added make verify-full-sequential as an explicit fallback when the lane runner itself needs debugging.
  • Fixed ultra-fast tooling smoke now detects actual shell tooling files by extension or shebang, so extensionless hook entrypoints stay covered while non-shell files like hook docs or timing logs do not false-fail under bash -n.

feat(warp-core): close Phase 4 and pivot reads to observe

  • Added ADR-0011 documenting the explicit observation contract with worldline, coordinate, frame, and projection semantics.
  • Changed Phase 4 provenance/BTR work is now the documented substrate baseline: provenance is entry-based, parent refs are stored explicitly, and the standalone ProvenanceService owns authoritative worldline history.
  • Added ObservationService::observe(...) as the canonical internal read path with explicit worldline, coordinate, frame, and projection semantics.
  • Added deterministic observation artifacts and error mapping: INVALID_WORLDLINE, INVALID_TICK, UNSUPPORTED_FRAME_PROJECTION, UNSUPPORTED_QUERY, and OBSERVATION_UNAVAILABLE.
  • Changed WarpKernel and the WASM ABI now expose observe(...), while get_head, snapshot_at, and drain_view_ops are thin one-phase adapters over the observation contract. execute_query(...) currently lowers through observation semantics and returns deterministic UNSUPPORTED_QUERY until full query support is implemented.
  • Changed drain_view_ops() is now legacy adapter/debug behavior only: it reads recorded truth through observe(...) and tracks only adapter-local drain state instead of mutating runtime-owned materialization state.
  • Changed ttd-browser migrated to the entry-based provenance API after the Phase 4 hard cut removed the old provenance convenience methods.

docs(post-phase5): sync roadmap truth after the merge

  • Changed during the post-Phase-5 closeout, the ADR-0008 / ADR-0009 implementation plan was updated to mark Phases 0-5 implemented and record Phase 5 as shipped.
  • Changed ADR-0010 is now accepted, aligning the observational/admin split with the implemented observation contract rather than leaving it in a hypothetical state.
  • Added docs/march-16.plan.md as the post-merge execution bridge for dev-loop hardening, Phase 6 adapter deletion, explicit tick types, and the later replay / transport horizons.

fix(warp-core): close final Phase 3 PR review threads

  • Fixed Engine::commit_with_state() now restores both the engine-owned runtime metadata and the borrowed WorldlineState even if rule execution unwinds, and duplicate admitted ingress is deduplicated by ingress_id before command enqueue.
  • Fixed the canonical pre-commit hook now routes staged crate verification through scripts/verify-local.sh pre-commit, which uses index-scoped changed files plus an index-tree stamp instead of branch-HEAD reuse.
  • Clarified cumulative unpause(PlaybackMode::Paused) notes now describe the shipped deterministic all-build failure instead of mixing final behavior with the earlier debug-only guard.

fix(tooling): reduce duplicate local and feature-branch verification

  • Changed scripts/hooks/pre-commit and scripts/hooks/pre-push now delegate to the canonical .githooks/ implementations instead of enforcing a stale parallel local policy.
  • Added scripts/verify-local.sh plus make verify-fast, make verify-pr, and make verify-full so local verification can scale with the change set and reuse a same-HEAD success stamp.
  • Changed the canonical pre-push hook now classifies docs-only, reduced, and critical verification paths, escalating to a determinism/tooling-focused local gate only for determinism-critical, CI, hook, and build-system changes.
  • Fixed manual make verify-full runs and the canonical pre-push full gate now share the same success stamp, so an explicit clean full pass suppresses the identical hook rerun for the same HEAD.
  • Changed the curated local full test lane now runs library and integration targets only for the small non-core confidence crates, cutting doc-test-only churn while the script reports total elapsed time on completion or failure.
  • Changed the main CI workflow no longer runs on push for feat/** branches, leaving pull_request as the authoritative branch-validation lane while main retains push-time protection.
  • Changed the CI Tests gate now fans in from parallel workspace sans warp-core and warp-core shards, preserving the required Tests status while cutting PR wall-clock time spent waiting on one serialized workspace job.
  • Changed the warp-core CI shard now uses cargo nextest for the main test inventory and keeps cargo test --doc as a separate step so the heavy crate runs faster without dropping its doctest coverage.

fix(warp-core): resolve final Phase 3 review invariants

  • Fixed Engine now caches canonical cmd/* rule order at registration time instead of rebuilding and sorting that list for every admitted ingress envelope.
  • Fixed WorldlineRegistry::register(...) now preserves the restored frontier tick implied by WorldlineState.tick_history instead of rewinding restored worldlines to tick 0.
  • Fixed WorldlineState root validation is now fallible and explicit: callers must supply or derive the unique root instance with a backing store, and the old fabricated fallback root is gone.
  • Fixed WarpKernel::with_engine(...) now returns a typed KernelInitError for non-fresh or invalid caller-supplied engine state instead of panicking through the WASM host boundary.
  • Clarified ADR-0008 and the Phase 3 implementation plan now describe duplicate suppression as per-resolved-head, use full head_key values for per-head APIs, and keep WorldlineRuntime pseudocode encapsulated.

fix(warp-core): resolve late Phase 3 PR follow-ups

  • Fixed WorldlineRuntime no longer exposes raw public registries that can desynchronize the default-writer / named-inbox route tables; named inbox lookup is now allocation-free on the live ingress path.
  • Fixed SchedulerCoordinator::super_tick() now preflights global_tick/frontier_tick overflow before draining inboxes or mutating worldline state.
  • Fixed runtime ingress event materialization is now folded back into the recorded tick patch boundary, so replaying initial_state + tick_history matches the committed post-state.
  • Fixed WarpKernel::with_engine(...) now rejects non-fresh engines instead of silently dropping runtime history that it cannot preserve.

fix(warp-core): close remaining Phase 3 PR review threads

  • Fixed duplicate worldline registration now surfaces as a typed RuntimeError::DuplicateWorldline at the runtime boundary instead of being silently ignored at the call site.
  • Fixed golden-vector and proptest determinism harnesses now pin EngineBuilder to a single worker so hashes do not inherit ambient ECHO_WORKERS or host core-count entropy.
  • Fixed GV-004 now pins both engines to the expected state_root, patch_digest, and commit_hash artifacts rather than checking only one run against constants and the second run for self-consistency.
  • Clarified hook/docs governance: .githooks/ installed via make hooks is canonical, scripts/hooks/ are legacy shims, ADR-0008 now states seek is observational-only, and the ADR exceptions ledger no longer uses a sentinel pseudo-entry.

fix(warp-core): harden Phase 3 runtime review follow-ups

  • Fixed HeadId is now opaque with internal range bounds, so public callers cannot fabricate arbitrary head identities while heads_for_worldline() still keeps its BTreeMap range-query fast path.
  • Fixed WriterHead now derives pause state from mode, and unpause(PlaybackMode::Paused) now fails deterministically in all builds instead of only under debug_assert!.
  • Fixed PlaybackHeadRegistry and WorldlineRegistry no longer expose raw public mutable access to stored heads/frontiers; runtime code uses targeted internal inbox/frontier mutation instead.
  • Fixed IngressEnvelope fields are now private and HeadInbox::ingest() enforces the canonical content hash in release builds too, closing the debug-only invariant hole.
  • Fixed SchedulerCoordinator::peek_order() now derives runnable order from the head registry instead of trusting cached state, and tick counters now fail deterministically on overflow.
  • Fixed INV-002 now asserts exact head-key equality against the canonical expected order, not just length plus pairwise zip checks.
  • Fixed the ADR implementation plan now shows private-field pseudocode for worldline frontiers and the stronger verification matrix, including the rustdoc warnings gate (RUSTDOCFLAGS="-D warnings" cargo doc ... --no-deps).

fix(warp-core): address CodeRabbit round-3 PR feedback

  • Fixed WriterHead.key is now private with a key() getter, preventing mutation via PlaybackHeadRegistry::get_mut() which would break the BTreeMap key invariant.
  • Fixed INV-002 proptest now verifies exact key identity (sorted+deduped input vs output), catching bugs where rebuild substitutes one key for another.
  • Fixed plan doc pseudocode updated to reflect private fields with getters (WriterHead, WorldlineFrontier) and correct constructor name (IngressEnvelope::local_intent).

fix(warp-core): address CodeRabbit round-2 PR feedback

  • Fixed WriterHead.mode is now private with a mode() getter, preventing the mode/paused pair from diverging via direct field assignment.
  • Fixed SchedulerCoordinator::super_tick() now uses canonical runnable order derived from the head registry via peek_order() instead of trusting stale runnable-cache state.
  • Fixed HeadInbox::set_policy() now revalidates pending envelopes against the new policy, evicting any that no longer pass.
  • Fixed HeadInbox::admit() now uses mem::take + into_values() instead of clone() + clear() for zero-copy admission in AcceptAll/KindFilter.
  • Fixed HeadInbox::ingest() added envelope hash invariant checks; later hardening enforces the canonical ingress_id/payload-hash match in release builds as well.
  • Fixed WorldlineState.warp_state is now pub(crate) with a warp_state() getter, and WorldlineFrontier fields are pub(crate) with public getters.
  • Fixed INV-002 proptest now verifies set preservation (length check) in addition to canonical ordering.
  • Fixed removed redundant_clone clippy suppression from head.rs and coordinator.rs test modules.
  • Fixed ADR exceptions ledger sentinel row no longer mimics an active entry.
  • Fixed verification matrix in implementation plan now matches the hook-enforced gate used in that phase.

fix(warp-core): self-review fixes for Phases 0–3

  • Fixed HeadInbox::ingest() now rejects non-matching envelopes at ingest time under KindFilter policy, preventing unbounded memory growth.
  • Fixed GV-003 golden vector now covers all 6 fork entries (ticks 0..=5), closing a gap where the fork-tick itself was never verified.
  • Added INV-002 proptest for canonical head ordering (shuffled insertion always produces canonical (worldline_id, head_id) order).
  • Added duplicate-tick detection to INV-001 (append at existing tick fails).
  • Fixed heads_for_worldline() now uses BTreeMap range queries (O(log n + k) instead of O(n) full scan).
  • Fixed unpause() initially added a debug-only guard for Paused; later hardening made the failure deterministic in all build configurations.
  • Fixed pre-commit hook now passes --workspace to clippy.
  • Improved documentation: multi-writer frontier semantics, global_tick behavior on empty SuperTicks, compute_ingress_id length-prefix safety, InboxAddress as human-readable alias.

feat(warp-core): Phase 3 deterministic ingress and per-head inboxes

  • Added IntentKind — stable, content-addressed intent kind identifier using domain-separated BLAKE3 ("intent-kind:" || label).
  • Added IngressEnvelope — unified, content-addressed ingress model with deterministic routing and idempotent deduplication.
  • Added IngressTarget — routing discriminant: DefaultWriter, InboxAddress, or ExactHead (control/debug only).
  • Added IngressPayload — payload enum starting with LocalIntent, extensible for cross-worldline messages (Phase 10) and imports (Phase 11).
  • Added HeadInbox — per-head inbox with BTreeMap-keyed pending envelopes for deterministic admission order.
  • Added InboxPolicy — admission control: AcceptAll, KindFilter, or Budgeted { max_per_tick }.

feat(warp-core): Phase 2 SchedulerCoordinator for ADR-0008

  • Added SchedulerCoordinator — serial canonical scheduling loop that iterates runnable writer heads in (worldline_id, head_id) order and advances each worldline's frontier tick.
  • Added WorldlineRuntime — top-level runtime struct bundling worldline registry, head registry, runnable set, and global tick.
  • Added StepRecord — output record documenting which heads were stepped and in what order during a SuperTick.

feat(warp-core): Phase 1 runtime primitives for ADR-0008

  • Added HeadId, WriterHeadKey, WriterHead — first-class head types for worldline-aware scheduling. Heads are control objects (identity, mode, paused state), not private mutable stores.
  • Added PlaybackHeadRegistryBTreeMap-backed registry providing canonical (worldline_id, head_id) iteration order.
  • Added RunnableWriterSet — ordered live index of non-paused writer heads.
  • Added WorldlineState — broad wrapper around WarpState preventing API calcification around GraphStore.
  • Added WorldlineFrontier — the single mutable frontier state per worldline, owning WorldlineState and frontier_tick.
  • Added WorldlineRegistryBTreeMap-backed registry of worldline frontiers with deterministic iteration.
  • Added make_head_id() — domain-separated BLAKE3 identifier factory ("head:" || label).

test(warp-core): Phase 0 invariant harness for ADR-0008/0009

  • Added golden vector suite (golden_vectors_phase0.rs) pinning commit determinism, provenance replay integrity, fork reproducibility, and idempotent ingress hashes before the worldline runtime refactor.
  • Added invariant test suite (invariant_property_tests.rs) enforcing monotonic worldline ticks, idempotent ingress, cross-worldline isolation, commit determinism, and provenance immutability; INV-001/002/003/005 use proptest, while INV-004/006 are fixed regression tests.
  • Added ADR exceptions ledger (docs/adr/adr-exceptions.md) — operational from Phase 0 onward, every intentional model violation must be logged with owner and expiry.
  • Added ADR-0010: Observational Seek, Explicit Snapshots, and Administrative Rewind — companion ADR clarifying the seek/rewind split under the one-frontier-state-per-worldline design.
  • Added implementation plan for ADR-0008 and ADR-0009 (docs/plans/adr-0008-and-0009.md) — 14-phase roadmap with verification matrix and exit criteria.
  • Added git hooks (scripts/hooks/pre-commit, scripts/hooks/pre-push) for lint and test gating.

docs(adr): ADR-0009 Inter-Worldline Communication

  • Added ADR-0009: Inter-Worldline Communication, Frontier Transport, and Conflict Policy — formalizes message-passing-only communication between worldlines, frontier-relative patches, suffix transport as the replication primitive, four-dimensional footprint interference, explicit conflict surfacing over silent LWW, and the state-vs-history convergence separation.

docs(adr): ADR-0008 Worldline Runtime Model

  • Added ADR-0008: Worldline Runtime Model — formalizes writer/reader heads, SuperTick scheduling contract, three-domain boundaries (Echo Core, App, Janus), per-head seek/jump semantics, and the 8-step normative refactor plan.

feat(warp-core): Wire up TTD domain logic from ttd-spec branch

  • Exported compute_tick_commit_hash_v2, compute_op_emission_index_digest, and OpEmissionEntry from warp-core public API (previously dead_code).
  • Wired LocalProvenanceStore::append_with_writes() to actually store atom writes instead of discarding them.
  • Added LocalProvenanceStore::atom_writes(w, tick) — query atom writes for a specific tick (TTD "Show Me Why" provenance).
  • Added LocalProvenanceStore::atom_history(w, atom) — causal cone walk using out_slots (Paper III Out(μ)) to filter ticks that wrote to the atom, with early termination at creation. O(history) scan, no reverse index.
  • Fixed LocalProvenanceStore::fork() to copy atom_writes alongside patches, expected hashes, and outputs.
  • Added 12 tests covering atom write storage, queries, filtering, fork, causal-cone walk, skip behavior, early termination, within-tick ordering, and SlotId::Node(atom) provenance path.

test(echo-dind-harness): Golden-vector coverage for TTD digest surface

  • Added digest_golden_vectors.rs — DIND-level golden-hash tests that exercise compute_emissions_digest, compute_op_emission_index_digest, and compute_tick_commit_hash_v2 through warp-core's crate-root re-exports.
  • Pinned 3 golden vectors: individual emission/op-emission-index digests plus a full hash chain (emissions → op-index → tick-commit). Any wire format drift in the public digest surface is now caught outside module-local tests.

fix(warp-core): Preserve within-tick write order in atom_history

  • Fixed atom_history() within-tick write ordering: the backward tick walk collected per-tick writes in forward order, so the final reverse() flipped within-tick execution sequence. Iterate tick_writes.iter().rev() so the global reverse restores original order.
  • Fixed creation truncation: if a single tick had [create, mutate] for the same atom, forward iteration hit is_create() first and returned early, losing the subsequent mutation.
  • Updated fork() rustdoc to mention atom_writes in the copied fields.
  • Documented append_with_writes() invariant: atom writes must reference atoms declared in patch.out_slots for atom_history() visibility.

fix: Ban-globals regex for macro patterns

  • Fixed scripts/ban-globals.sh: the \bthread_local!\b and \blazy_static!\b patterns never matched because ! is not a word character in ripgrep regex, making the trailing \b impossible. Use escaped \! without trailing \b.
  • Added .ban-globals-allowlist to exempt warp-wasm/src/lib.rs (WASM boundary legitimately needs module-scoped thread_local + install_kernel).

fix(wasm): Address PR review feedback

  • Fixed init() now returns real 32-byte state_root and commit_id hashes from the freshly constructed kernel instead of empty vecs.
  • Fixed WarpKernel::with_engine() auto-registers sys/ack_pending if absent, silently ignoring duplicates. Prevents ENGINE_ERROR on first dispatched intent when callers forget to register it.
  • Removed unnecessary #[allow(dead_code)] on public WarpKernel::with_engine() method.
  • Removed redundant explicit type annotation on get_registry_info().
  • Fixed broken RegistryInfo rustdoc link after import removal.

fix: Resolve pre-existing clippy warnings across workspace

  • Fixed warp-core: cfg-gate footprint enforcement internals (FootprintGuard, OpTargets, op_write_targets, etc.) so they compile out cleanly under unsafe_graph without dead-code warnings.
  • Fixed warp-core: add #[allow(unused_mut)] on cfg-conditional mutation in engine_impl.rs.
  • Fixed echo-wasm-bindings: restructure TtdController WASM bindings to use per-method wasm_bindgen with JsValue/JsError wrappers instead of blanket wasm_bindgen on the impl block (fixes trait bound errors under --all-features).
  • Fixed echo-scene-codec: add clippy allow attributes to test module for expect_used, unwrap_used, and float_cmp.
  • Fixed warp-core tests: move enforcement-only imports into cfg-gated mod enforcement in parallel_footprints.rs.

fix(wasm): Validate intent envelopes, enforce envelope construction, add trait defaults

  • Fixed dispatch_intent now validates the EINT envelope before passing bytes to the engine, returning INVALID_INTENT (code 2) for malformed envelopes instead of forwarding garbage.
  • Added Display impl for EnvelopeError (no_std compatible).
  • Changed OkEnvelope and ErrEnvelope fields to private with ::new() constructors, enforcing correct ok field values at compile time.
  • Added default implementations for KernelPort::execute_query and KernelPort::render_snapshot returning NOT_SUPPORTED, making future trait evolution non-breaking.
  • Updated SPEC-0009 error code 2 description and versioning notes.

feat(wasm): Ship reusable app-kernel WASM boundary with real exports (ECO-001)

  • Added KernelPort trait to echo-wasm-abi — app-agnostic byte-level boundary contract for WASM host adapters. Includes ABI response DTOs (DispatchResponse, StepResponse, HeadInfo, DrainResponse, RegistryInfo), error codes, and CBOR wire envelope types.
  • Added WarpKernel to warp-wasm (behind engine feature) — wraps warp-core::Engine implementing KernelPort. Registers sys/ack_pending system rule, provides deterministic tick execution.
  • Replaced all placeholder WASM exports with real implementations: dispatch_intent, step, drain_view_ops, get_head, snapshot_at, get_registry_info, and handshake metadata getters now return live data.
  • Added init() export for kernel initialization; calling exports before init returns structured error (no panics).
  • Added CBOR success/error envelope protocol ({ ok: true/false, ... }) for all Uint8Array returns.
  • Added install_kernel() public API for app-agnostic kernel injection.
  • Added SPEC-0009 documenting ABI v1 contract, wire encoding, error codes, versioning strategy, and migration notes.
  • Added 14 conformance tests covering dispatch, step, drain, snapshot, determinism, error paths, and handshake metadata.
  • execute_query and render_snapshot honestly report NOT_SUPPORTED (error code 5) until the engine query dispatcher lands.

Refactor: Retire BOAW/JITOS/Continuum codenames

  • Renamed warp_core::boaw module to warp_core::parallel — all import paths, re-exports, and doc comments updated.
  • Renamed 14 boaw_* integration test files to parallel_*, updated test harness types (BoawScenarioParallelScenario, BoawTestHarnessParallelTestHarness, etc.) and string literals.
  • Renamed boaw_baseline benchmark to parallel_baseline, updated warp-benches/Cargo.toml target.
  • Annotated 5 ADR files with deprecation notice (filenames preserved as historical records).
  • Updated book/LaTeX sections, specs, guides, and source comments to replace BOAW references with parallel.
  • Replaced "Echo/JITOS" → "Echo" in echo-wasm-bindings, echo-wasm-abi, and spec-000-rewrite crate metadata and READMEs.
  • Replaced "JITOS Engineering Standard" → "Echo Engineering Standard" in METHODOLOGY.md.
  • Replaced "Echo / Continuum" → "Echo" in ADR-0007.

Chore: Archive ~90 stale docs, restructure docs-index

  • Archived 6 entire directories to docs/archive/: notes/, plans/, tasks/, rfc/, memorials/, jitos/ (session artifacts, completed work).
  • Archived docs/study/ (51 files: LaTeX papers, build artifacts, tour materials) to docs/archive/study/.
  • Archived 4 completed DIND mission docs from docs/determinism/ and the superseded ECHO_ROADMAP.md from docs/ROADMAP/.
  • Archived 18 stale loose docs from docs/ root: AGENTS.md, ISSUES_MATRIX.md, code-map.md, phase1-plan.md, roadmap-mwmr-mini-epic.md, branch-merge-playbook.md, testing-and-replay-plan.md, runtime-diagnostics-plan.md, telemetry-graph-replay.md, warp-demo-roadmap.md, warp-runtime-architecture.md, capability-ownership-matrix.md, ROLLBACK_TTD.md, aion-papers-bridge.md, rust-rhai-ts-division.md, hash-graph.md, two-lane-abi.md, diagrams.md.
  • Archived dead redirect guide/collision-tour.md (both targets missing).
  • Rewrote docs/meta/docs-index.md: curated golden-path index with clear separation of implemented specs, vision specs (unimplemented), ADRs, and archive. Removed broken links and stale entries.

Docs: Fix violations found during docs sweep

  • Fixed CONTRIBUTING.md: Rust version 1.71.1 → 1.90.0, AGENTS.md path to docs/AGENTS.md, reference/typescript/packages/ and apps/, commit message guidance aligned with conventional commits.
  • Fixed .devcontainer/post-create.sh: reads toolchain version from rust-toolchain.toml instead of hardcoding 1.71.1, removed stale rmg-core crate reference.
  • Fixed warp-wasm/README.md: corrected dependency claim from warp-core to echo-wasm-abi + echo-registry-api.
  • Fixed echo-session-proto/README.md: removed broken docs/tex/ paths, pointed to docs/js-cbor-mapping.md and book sections instead.
  • Fixed ttd-browser/README.md: removed broken docs/plans/ttd-app.md reference and nonexistent ttd-controller crate mention.
  • Fixed NOTICE: copyright year 2025 → 2025–2026, SPDX identifier aligned to LicenseRef-MIND-UCAL-1.0.
  • Fixed ROADMAP priority mismatch: 5 milestone READMEs aligned from P2 → P3 to match the parent index. Proof Core status downgraded from "Verified" to "In Progress" (Docs Polish feature still incomplete).
  • Fixed guide/cargo-features.md: removed nonexistent spec-000-rewrite crate section.
  • Fixed guide/course/glossary.md: corrected ViolationKind variant AdjacencyViolationOpWarpUnknown with full variant names.
  • Fixed BENCHMARK_GUIDE.md: updated "CI Integration (Future)" section to reflect existing G3 perf gate.
  • Fixed echo-session-client and echo-session-service Cargo.toml descriptions: removed stale "(skeleton)" qualifier.

Fix: Task list guard CI failure

  • Fixed scripts/check_task_lists.sh: accept file arguments for testability; fall back to built-in FILES array when none are given.
  • Fixed scripts/tests/check_task_lists_test.sh: updated tests to pass file arguments to the checker and match current output messages. Tests were broken after the FILES array was emptied when task lists were archived.

Chore: Clean up root directory

  • Removed stale root-level ADR duplicates (ADR-0003 through ADR-0006); canonical copies already exist in docs/adr/.
  • Removed completed one-shot plan MERGE_TTD_BRANCH_PLAN.md.
  • Moved determinism docs (DETERMINISM-AUDIT.md, DIND-MISSION*.md) to docs/determinism/.
  • Moved task trackers (TASKS.md, TASKS-DAG.md, WASM-TASKS.md) to docs/tasks/.
  • Moved ECHO_ROADMAP.md to docs/ROADMAP/, COMING_SOON.md to docs/plans/, AGENTS.md to docs/.
  • Deleted untracked junk files (paper-7eee.log, dind-report.json, .DS_Store).
  • Archived 14 superseded/completed docs: redirect stubs removed, canonical content already in docs/archive/. Updated cross-references in docs-index.md, code-map.md, DETERMINISTIC_MATH.md, and warp-geom/README.md.
  • Added docs/archive/README.md defining archive policy.

CI: G3 perf regression gate (#280)

  • CI: G3 perf regression gate now compares criterion benchmark output against a git-tracked perf-baseline.json and fails if any benchmark regresses beyond 15% (configurable via --threshold). Structured perf-report.json artifact uploaded alongside raw perf.log.
  • CI: New perf-baseline-update.yml workflow auto-generates baseline update PRs on main pushes that touch Rust sources.
  • Scripts: Added check_perf_regression.cjs (gate comparison) and generate_perf_baseline.cjs (baseline generation from bencher output).

Docs: Allowlist governance (#287)

  • Policy: Added "Determinism Allowlist Governance" section to docs/RELEASE_POLICY.md documenting acceptable exemption criteria, approval requirements, and audit cadence for .ban-nondeterminism-allowlist.
  • Scripts: Added cross-reference from ban-nondeterminism.sh header to the governance policy.

Docs Polish (#41)

  • License: Renamed SPDX identifier MIND-UCAL-1.0LicenseRef-MIND-UCAL-1.0 across 328 files to comply with SPDX Appendix IV (custom identifiers must use LicenseRef- prefix). Updated ensure_spdx.sh tooling and pre-commit hook accordingly.

  • Fix: Fixed radix sort scope pair index inversion in scheduler.rs bucket16(). LSD passes were processing scope bytes MSB-first instead of LSB-first, causing the radix-sort path (n > 1024) to produce a different ordering than the comparison-sort path (n ≤ 1024). Added 3 property tests: proptest_drain_matches_btreemap_reference (fuzzes both sort paths), proptest_insertion_order_independence, and threshold_boundary_determinism.

  • Spec: Replaced "Theorem A" in spec-mwmr-concurrency.md with the formal name from Paper II: "Skeleton-plane Tick Confluence theorem (§6, Thm. 6.1)".

  • Spec: Changed <i>Alea iacta est</i> to semantic HTML in memorials/2026-01-18-phase4-rubicon.md (foreign phrase italics).

  • Spec: Resolved 4 CRITICAL CodeRabbit items: normative frame ordering rule in spec-editor-and-inspector.md (stable sort by (tick, frameType), UTF-8 lexicographic, insertion-order tie-break); added getNode() to BridgeContext in spec-temporal-bridge.md with NodeId disambiguation note (timeline hash vs WARP graph u64); defined world:config capability in spec-capabilities-and-security.md and removed "not yet defined" warning from spec-runtime-config.md; verified SweepProxy rename in spec-knots-in-time.md. Also changed producer return type from object to unknown in spec-editor-and-inspector.md.

  • Spec: Rewrote spec-branch-tree.md to resolve all 10 CodeRabbit review items. Key changes: formal ReadKey/WriteKey/QualifiedKey type definitions with ECS-layer layering rationale; MergeStrategyId as extensible namespaced string registry; extracted TimelineNodeCore hashable subset and replaced broken hash formula; unified parents[] replacing parentId + mergeParents?; renamed entropy heuristic to "branch strain" (distinguished from Aion Boltzmann entropy); defined WorldView, GCPolicy, three explicit GC modes with transitive pin semantics, domain-separated seed derivation, layered causal-edge semantics, CapabilityAssertion with forward reference to capabilities spec, and StabilityObserver lifecycle.

  • Polish: Resolved remaining 13 Tier 2 CodeRabbit items (all 66 complete): session token format (HMAC-SHA256) and filter semantics in spec-editor-and-inspector.md; signing canonicalization subsection with 8-field byte layout in spec-warp-confluence.md; breaking-change criteria and deprecation timeline in spec-world-api.md; BlockManifest section encoding in spec-serialization-protocol.md; radix sort internals documentation in scheduler-optimization-followups.md; enum style unification in SPEC-0002; cargo metadata provenance command in cargo-features.md; expanded serde acceptance criteria in issue-canonical-f32.md.

  • Polish: Resolved 12 Tier 1 CodeRabbit items: remain disjointare non-conflicting in SPEC-0003, tightened subnormal definition in DETERMINISTIC_MATH.md, added Aion inline definition in branch-merge-playbook.md, converted numbered narrative to bullets in spec-time-streams-and-wormholes.md, verified 3 already-correct items (serialization link, admission MUST language, musings blank line), dismissed 3 prettier-enforced formatting items.

  • Spec: Resolved all 3 TODO comments in spec-scheduler.md: bidirectional dependency resolution rules, cleaner registerSystem pseudo-code, and a formal resource conflict detection model aligned with warp-core's Footprint. Replaced ComponentSignature with SystemFootprint (reads/writes/exclusiveTags).

  • Review: Addressed 69 CodeRabbit review comments across 37 files:

    • xtask: Cross-platform command_exists, annotated UTF-8 errors, warned on non-UTF-8 path drops, simplified has_extension, fixed doc comment.
    • Specs: Hardened 15 spec docs — added error handling for branch-tree commit conflicts, defined equality predicates, bounded parent counts in merkle-commit, specified canonical field ordering, fixed broken cross-refs and link styles, added validation rules and error codes to runtime-config, unified BranchId/KairosBranchId, clarified signing payloads.
    • Notes/Archive: Corrected O(n log n) cost attribution in scheduler notes, fixed stale code references and branch names, expanded commit hashes, added provenance blocks.
    • Docs: Fixed ADR-0004 placeholder, normalized titles, corrected dependency direction in ISSUES_MATRIX, fixed emphasis style, consolidated repetitive bullets, added cargo-features provenance note, fixed heading levels in warp-math-claims, fixed workflow artifacts in mat-bus-finish RFC.
  • Archive: Moved 6 superseded docs to docs/archive/ with redirect stubs (spec-deterministic-math.md, spec-geom-collision.md, notes/scheduler-radix-optimization.md, notes/xtask-wizard.md, plans/cross-warp-parallelism.md, plans/BOAW-tech-debt.md).

  • Consolidate: Added "Docs Map" callouts to SPEC_DETERMINISTIC_MATH.md and DETERMINISTIC_MATH.md linking all 5 docs in the deterministic math cluster. Updated scheduler.md Quick Map with status labels.

  • Fix: Repaired 13 broken cross-references (docs/specs/ -> docs/spec/, memorial.md -> memorials/..., streams-inspector-frame.md -> streams-inspector.md, docs/spec/SPEC-0004... prefix, archived file image paths, nonexistent README link).

  • New: cargo xtask lint-dead-refs — scans docs/ for broken markdown cross-references. Handles relative paths, root-relative docs links, and docs/public/ asset resolution. Use --all to also check non-markdown file references (images, HTML).

  • New: cargo xtask markdown-fix — auto-fixes common markdown lint violations: SPDX header repair, prettier formatting, and markdownlint --fix. Supports --no-prettier and --no-lint flags.

  • New: cargo xtask docs-lint — combined pipeline that runs markdown-fix followed by lint-dead-refs. Single command for full docs hygiene.

  • New: Configuration reference (docs/guide/configuration-reference.md) covering engine parameters, protocol constants, and environment variables.

  • New: Cargo feature flags reference (docs/guide/cargo-features.md) covering all 19 features across 11 crates.

  • Fix: cargo xtask lint-dead-refs now uses pulldown-cmark for link extraction (handles title text, balanced parens, angle-bracket URLs) and separates scan scope from the docs root. Includes 10 unit tests.

  • Fix: det_fixed correctly documented as a behavioral switch in cargo-features.md; worker_count default now shows NUM_SHARDS cap.

  • Fix: All file collection in xtask now uses git ls-files instead of filesystem walks so ignored build artifacts stay out of docs scans.

  • Update: Archival stubs enriched with date, reason, and PR metadata. Draft spec (spec-scheduler.md) marked with [!CAUTION] disclaimer and TODO markers for unspecified sections.

  • Update: Math code fences converted from text to math with proper LaTeX markup across THEORY.md, SPEC-0001, and scheduler notes.

  • Fix: Archived cross-warp-parallelism.md annotated with implementation traceability and WorkUnit struct deviation (no shard_id in actual code).

  • Fix: Archived BOAW-tech-debt.md checklists annotated as frozen with tracking-moved callout pointing to TECH-DEBT-BOAW.md.

  • Fix: Archived scheduler-radix-optimization.md canonical order clarified and code-reference staleness disclaimer made visible.

  • New: .coderabbit.yaml — excludes docs/archive/** from CodeRabbit reviews (frozen historical records generate low-value feedback).

  • Update: README determinism claims link, reference docs section, docs-index entries, docs-audit log.

Added — Proof Core (P1 Milestone)

  • Determinism Claims v0.1: New docs/determinism/DETERMINISM_CLAIMS_v0.1.md documenting five determinism claims (DET-001 through DET-005) covering static inspection, float parity, parallel execution, trig oracle golden vectors, and torture-rerun reproducibility.
  • Trig Golden Vectors (DET-004): New test crates/warp-core/tests/trig_golden_vectors.rs with a 2048-sample golden binary (testdata/trig_golden_2048.bin) that locks down dfix64 sin/cos/tan outputs across platforms. Runs on Linux and macOS in CI.
  • Torture Rerun Script (DET-005): scripts/torture-100-reruns.sh — turnkey repro script that runs 100 sequential simulations and asserts identical hashes.
  • CI Trig Oracle Gate: Added trig golden vector tests to .github/workflows/det-gates.yml for both Linux and macOS runners, with log artifacts uploaded alongside existing determinism artifacts.
  • CLAIM_MAP.yaml: Added DET-004 and DET-005 entries with required evidence pointers and owner roles.
  • Evidence Generator: Wired DET-004 and DET-005 into scripts/generate_evidence.cjs so the evidence policy cross-check passes.
  • Ban-Nondeterminism Allowlist: Added trig_golden_vectors.rs to .ban-nondeterminism-allowlist (test-only std::fs for reading golden vector binaries).

Changed — Roadmap

  • Updated docs/ROADMAP/proof-core/README.md: checked off P1 exit criteria, marked milestone as "In Progress".
  • Resequenced roadmap phases: P0 verified, P1→P2→P3 ordering clarified.

Fixed — Code Review (PR #291)

  • Bench Recursive Scanning: collect_criterion_results now walks directories recursively, correctly finding grouped (benchmark_group) and parameterised (BenchmarkId) benchmarks that Criterion stores in nested directories (e.g. group/bench/new/estimates.json).
  • Bench Regex Filter: Post-filter now uses regex::Regex to match Criterion's own regex semantics instead of substring contains. Filters with anchors or metacharacters (e.g. ^hotpath$) now work correctly.

Fixed — Self-Review (PP-1 Branch)

  • Stale warp-ffi References: Removed deleted crate from git hooks (pre-push-parallel, pre-push-sequential), warp-core/README.md, and AGENTS.md. Only historical references in CHANGELOG and TASKS-DAG remain.
  • Broken Spec Paths: Fixed docs/specs/docs/spec/ in two acceptance criteria in docs/ROADMAP/backlog/security.md.
  • emit() Error Propagation: Changed output::emit() to return Result<()> instead of silently printing to stderr on serialization failure. All call sites (bench.rs, verify.rs, inspect.rs) now propagate with ?.
  • SPEC-0005 Clarity: Bound loop index variable in BTR verification algorithm (H-3); documented missing-producer behavior in derive() (H-4); clarified multi-producer vs. most-recent-producer semantics between build_provenance_graph() and derive() (M-4); added canonical_state_hash() cross-reference (M-5); specified composition error semantics (M-6); added set semantics for Out(μ)/In(μ) (M-8); expanded ProvenanceNode constructor in pseudocode (L-10); documented empty derivation graph semantics (L-11); formalized identity composition (L-12); defined H(P) notation in example (L-13); added Paper III citation (L-14).
  • format_duration() Infinity: Added is_infinite() check alongside is_nan() so f64::INFINITY returns "N/A" instead of formatting as seconds.
  • Safe edge_ix Cast: Replaced as usize with usize::try_from() in inspect.rs tree builder to guard against truncation on 32-bit targets.
  • Bench Test Ordering: Added positional assertion ensuring -- precedes the filter pattern in build_bench_command.
  • Bench Empty Warning: Added stderr warning when no benchmark results found.
  • WSC Loader Warnings: Warning messages now include entity IDs (first 4 bytes hex) for easier debugging.
  • Inspect Docstring: Changed "Prints" to "Displays" in module docstring.
  • TREE_MAX_DEPTH Doc: Added doc comment explaining the depth limit's purpose.
  • Fragile len() - 1: Changed i == node.children.len() - 1 to i + 1 == node.children.len() to avoid underflow on empty children (though the loop guards against this, the pattern is safer).

Fixed — Developer CLI (echo-cli)

  • Bench Filter: echo-cli bench --filter <pattern> now passes the filter as a Criterion regex (-- <pattern>) instead of a --bench cargo target selector. Previous behavior would look for a bench target named after the pattern rather than filtering benchmarks by regex.
  • Verify Expected Hash: --expected now correctly reports "unchecked" for warps 1+ instead of silently claiming "pass". Emits a stderr warning when --expected is used with multi-warp snapshots. Text and JSON output now use consistent lowercase status values.
  • Unused Dependency: Removed colored = "2" from warp-cli (declared but never imported).
  • Output Hardening: emit() no longer panics on JSON serialization failure; falls back to stderr. Bench exit status now reports Unix signal numbers instead of a misleading -1.
  • Error Handling: collect_criterion_results now logs a warning on unparseable estimates.json instead of silently skipping. format_duration returns "N/A" for NaN/negative values. att_row_to_value warns on missing blob data instead of silent fallback.
  • Dead Code: Replaced blanket #![allow(dead_code)] on lib.rs with targeted #[allow(dead_code)] on the output module only.
  • Man Page Headers: Subcommand man pages now use prefixed names (echo-cli-bench, echo-cli-verify, echo-cli-inspect) in .TH headers instead of bare subcommand names.
  • Visibility: Narrowed all non-API structs and functions from pub to pub(crate) in bench, verify, inspect, and wsc_loader modules. Only cli.rs types remain pub (required by xtask man page generation).
  • cargo-deny: Fixed wildcard dependency error for warp-cli in xtask/Cargo.toml by adding explicit version = "0.1.0" alongside the path override.
  • Man Page Cleanup: cargo xtask man-pages now removes stale echo-cli*.1 files before regeneration so the output directory is an exact snapshot.

Fixed — Code Review (PR #289, Round 2)

  • Inspect Tree Warp Identity: Multi-warp snapshots now label each tree section with its warp index (Tree (warp 0):, Tree (warp 1):) instead of flattening all trees into a single unlabeled Tree: section.
  • WSC Loader Attachment Checks: Replaced debug_assert! with runtime warnings for attachment multiplicity violations. Previously, release builds silently dropped extra attachments; now emits a warning to stderr.
  • Test Naming: Renamed tampered_wsc_fails to tampered_wsc_does_not_panic to accurately reflect the test's behavior (no assertion, just no-panic guard).
  • Test Coverage: Added roundtrip_with_edge_attachments and roundtrip_with_descend_attachment tests to wsc_loader.rs, covering previously untested code paths.
  • SPEC-0005 global_tick Invariant: Reworded from patches[i].global_tick == i to correctly state contiguity relative to the payload's start tick, since payloads can begin at any absolute tick via from_store(store, wl, 5..10).
  • SPEC-0005 BTR Verification: Fixed step 5 of the verification algorithm to reference the actual hash formula from §5.4 instead of a nonexistent parents field.
  • SPEC-0005 Derivation Algorithm: Fixed backward-cone traversal that dropped transitive dependencies. The original filter checked the root query slot at every hop; now accepts all frontier nodes unconditionally (they are already known-causal) and traces all in_slots backward.
  • Stale warp-ffi References: Removed dead warp-ffi entry from det-policy.yaml, C ABI text from phase1-plan.md, and stale CLI names from rust-rhai-ts-division.md.

Fixed — Docs & CI

  • TASKS-DAG Spec Path: SPEC-PROVENANCE-PAYLOAD.mdSPEC-0005-provenance-payload.md in sub-task title and AC1 (two occurrences). Same stale path fixed in ROADMAP backlog security.md.
  • SPEC-0005 Byte Counts: Domain separation tag sizes corrected: echo:provenance_payload:v1\0 = 27 bytes (was 28), echo:provenance_edge:v1\0 = 24 bytes (was 25).
  • Project Tour: Updated warp-cli description from "Placeholder CLI home" to list actual subcommands (verify, bench, inspect).
  • CI Formatting: Removed stray blank line between warp-geom and warp-wasm rustdoc steps in ci.yml.

Added — Developer CLI (echo-cli)

  • CLI Scaffold (warp-cli): Replaced placeholder with full clap 4 derive subcommand dispatch. Three subcommands: verify, bench, inspect. Global --format text|json flag for machine-readable output.
  • Verify Subcommand: echo-cli verify <snapshot.wsc> loads a WSC snapshot, validates structural integrity via validate_wsc, reconstructs the in-memory GraphStore from columnar data, and computes the state root hash. Optional --expected <hex> flag compares against a known hash.
  • WSC Loader: New wsc_loader module bridges WSC columnar format to GraphStore — the inverse of warp_core::wsc::build_one_warp_input. Reconstructs nodes, edges, and attachments from WarpView.
  • Bench Subcommand: echo-cli bench [--filter <pattern>] shells out to cargo bench -p warp-benches, parses Criterion JSON from target/criterion/*/new/estimates.json, and renders an ASCII table via comfy-table. Supports --format json for CI integration.
  • Inspect Subcommand: echo-cli inspect <snapshot.wsc> [--tree] displays WSC metadata (tick, schema hash, warp count), graph statistics (node/edge counts, type breakdown, connected components via BFS), and optional ASCII tree rendering depth-limited to 5 levels.
  • Man Pages: Added clap_mangen-based man page generation to xtask. cargo xtask man-pages generates docs/man/echo-cli.1, echo-cli-verify.1, echo-cli-bench.1, echo-cli-inspect.1.

Added — Provenance Payload Spec (PP-1)

  • SPEC-0005: Published docs/spec/SPEC-0005-provenance-payload.md mapping Paper III (AION Foundations) formalism to concrete Echo types. Defines four new types (ProvenancePayload, BoundaryTransitionRecord, ProvenanceNode, DerivationGraph), wire format with CBOR encoding and domain separation tags, two worked examples (3-tick accumulator, branching fork), bridge to existing ProvenanceStore/PlaybackCursor APIs, and attestation envelope with SLSA alignment.

Fixed (CI)

  • Evidence Derivation: Replaced artifact-directory-presence check for DET-001 with structured parsing and validation of static-inspection.json; FAILED static inspections now correctly yield UNVERIFIED evidence instead of relying solely on artifact existence. Adds source_file, source_status, and optional error fields to DET-001 evidence.
  • Evidence Script Hardening: Added TypeError guard on generateEvidence input, try/catch with process.exit(1) in CLI mode, truncated log interpolations to 200 chars in checkStaticInspection, harmonized parameter naming, and tightened JSDoc return types to 'VERIFIED'|'UNVERIFIED' union.

Fixed (Docs)

  • Docs Build: Rewrote ADR-0007-impl.md from a 3185-line raw conversation transcript into a proper 13-section ADR document. The Vue template compiler was crashing on bare Rust generics (BTreeMap<NodeId, NodeRecord>, etc.) outside fenced code blocks. The new document preserves all architectural knowledge as a structured implementation companion to ADR-0007.
  • Stale Hash Domain: Updated three stale DIND_STATE_HASH_V2 references in graph.rs doc comment and ADR-0007-impl.md §2.1/§7 to match the actual domain prefix echo:state_root:v1 defined in domain.rs. Renamed the adjacent V2 Changes subsection to Layout Notes to remove versioning ambiguity.
  • Module Count: Fixed off-by-one module count in ADR-0007-impl.md metadata and §1 prose (36 → 37) and added qualifier noting tables cover key modules only.
  • Stale Design Doc: Deleted docs/WARP-GRAPH.md (1,219-line chat transcript fully superseded by ADR-0007-impl.md and crates/warp-core/src/wsc/). Extracted all-zero-key caveat into ADR §9.6 and save_wsc() convenience wrapper gap into TASKS-DAG.md backlog before removal.

[0.1.3] — 2026-02-21

Fixed (Sprint S1)

  • CI Security: Hardened det-gates workflow against script injection by using environment variables for all github.* interpolations (branch refs, SHA, run ID, event name).
  • WASM Reproducibility: Implemented bit-exact reproducibility checks (G4) for ttd-browser WASM using hash comparison of clean isolated rebuilds.
  • Static Inspection: Added automated CI guard for DET-001 covering all 14 DET_CRITICAL crate paths (expanded from echo-wasm-abi only). Report now conditional on check outcome (PASSED/FAILED).
  • Evidence Validation: Made artifact presence checks in validate-evidence conditional on classification tier; added det-macos-artifacts check; run_reduced and DET_NONCRITICAL paths no longer hard-fail.
  • Policy Classification: Promoted warp-benches from DET_NONCRITICAL to DET_IMPORTANT so benchmark crate changes trigger reduced gates.
  • Benchmark Correctness: Replaced let _ = with .unwrap() on all bus.emit() calls; migrated iter_with_setup to iter_batched.
  • CBOR Robustness: Expanded negative security tests for ProjectionKind and LabelAnchor enum tags and optimized MAX_OPS boundary check.
  • Evidence Integrity: Enhanced generate_evidence.cjs and validate_claims.cjs with stricter semantic validation (SHAs, run IDs) and artifact existence checks.
  • Script Quality: Replaced process.exit(1) with throw in classify_changes.cjs; removed dead import; exported functions for testing.
  • Governance: Moved sec-claim-map.json to docs/determinism/, formalized gate states in RELEASE_POLICY.md, tightened claim statements in CLAIM_MAP.yaml.
  • CI Permissions: Added permissions: contents: read to det-gates.yml for least-privilege workflow execution.
  • CI Robustness: Made ripgrep install idempotent; gated validate-evidence on classify-changes success; invoked CJS scripts via node for cross-platform portability.
  • Evidence Validation: Relaxed commit_sha check to accept local sentinel for local development; exported generateEvidence and validateClaims functions for unit testing (#286).
  • Claims Precision: Sharpened PRF-001 statement to reference specific Criterion benchmark rather than generic threshold language.
  • Backlog: Added five TASKS-DAG.md items: BLD-001 claim gap, macOS parity claim, CI concurrency controls, expanded script test coverage, and det-policy.yaml path simplification.
  • Evidence Completeness: Added REPRO-001 claim for G4 build reproducibility to CLAIM_MAP.yaml and wired into generate_evidence.cjs.
  • Script Hardening: Added Array.isArray guard for required_gates in validate_det_policy.cjs; used explicit null/undefined check in validate_claims.cjs instead of falsy coercion.
  • Test Robustness: Encoded all 5 CBOR fields in reject_invalid_version to prevent false passes from decoder field-read reordering.
  • Docs: Added G3 staging-optional rationale in RELEASE_POLICY.md; merge-commit revert guidance and evidence packet filing in ROLLBACK_TTD.md; documented tests/**/e2e/** classification rationale in det-policy.yaml.
  • Gate Coverage: Made G3 (perf-regression) run for all non-run_none paths, not just run_full. Ensures PRF-001 claim fires for DET_IMPORTANT changes (e.g., warp-benches). Moved perf-artifacts presence check to always-required.
  • Classification Precision: Carved tests/dind* and testdata/dind/** out of the DET_NONCRITICAL docs catch-all into a dedicated dind-tests-root entry at DET_IMPORTANT, preventing gate evasion for DIND test modifications.
  • Policy Simplification: Replaced 20+ explicit docs paths with ** catch-all in det-policy.yaml; max-class semantics ensure higher-priority patterns win.
  • CI Concurrency: Added concurrency block to det-gates.yml to cancel superseded runs on the same branch.
  • CI Robustness: Added push-event empty changelist guard (defaults to full run).
  • Dynamic DETERMINISM_PATHS: Replaced hardcoded crate list in static-inspection with yq/jq extraction from det-policy.yaml DET_CRITICAL entries, eliminating manual sync.
  • Evidence Sync Guardrails: Added CI cross-check step validating claim IDs in evidence.json match CLAIM_MAP.yaml exactly; added sec-claim-map.json test ID existence verification against source.
  • macOS Parity Claim: Added DET-003 to CLAIM_MAP.yaml and generate_evidence.cjs for macOS-specific determinism verification.
  • Claims Precision: Fixed REPRO-001 evidence type from static_inspection to hash_comparison; flattened verbose required_evidence syntax.
  • Test Assertions: Strengthened reject_invalid_enum_tags test to assert specific error messages instead of bare is_err() checks.
  • CI Timeouts: Added timeout-minutes to all det-gates.yml jobs to prevent hung jobs from burning the 6-hour GitHub default.
  • Classification Optimization: Added early-exit in classify_changes.cjs when maxClass reaches DET_CRITICAL (guarded by require_full_classification).
  • Build Repro Fix: Restored rustup target add wasm32-unknown-unknown in build-repro — required because rust-toolchain.toml pins a specific Rust version that overrides the dtolnay/rust-toolchain action's target.

[0.1.2] — 2026-02-14

Added — TTD Hardening Sprint S1 (Gates & Evidence)

  • Path-Aware CI Gates: Implemented det-policy.yaml and classify_changes.cjs to classify workspace crates (DET_CRITICAL/IMPORTANT/NONCRITICAL) and drive selective CI gate triggering (G1-G4).
  • Hardening Gates (G1-G4):
    • G1 (Determinism): Integrated float parity tests and the DIND (Deterministic Ironclad Nightmare Drills) suite on both Linux and macOS.
    • G2 (Security): Added negative security tests for the CBOR decoder (MAX_OPS, invalid versions/enums, truncated payloads).
    • G3 (Performance): Created materialization_hotpath Criterion benchmark in warp-benches to track materialization overhead.
    • G4 (Build): Added WASM build reproducibility checks verifying bit-exact artifacts across clean rebuilds.
  • Evidence Integrity: Added generate_evidence.cjs and validate_claims.cjs to ensure all VERIFIED claims are backed by immutable CI artifacts (run IDs, commit SHAs).
  • Static Inspection: Integrated DET-001 automated static inspection into CI to verify zero-HashMap usage in deterministic guest paths.
  • Governance: Published RELEASE_POLICY.md (staging/prod blockers) and ROLLBACK_TTD.md (commit-ordered rollback sequences).
  • Security Claim Mapping: Exported sec-claim-map.json mapping decoder controls to explicit negative test cases.

Added — Deterministic Scene Data (TTD)

  • Scene Rendering Port (echo-scene-port): Defined the core data model for deterministic scene updates, including nodes, edges, labels, and camera state.
  • Scene Codec (echo-scene-codec): Implemented a high-performance minicbor codec for SceneDelta serialization with strict validation.
  • Float Parity Proof: Integrated a cross-language verification suite ensuring canonicalize_f32 produces bit-identical results between Rust and JavaScript.
  • Scene Integrity Drills: Added stress tests for atomic state mutations and robustness against truncated CBOR payloads.

Added — TTD Protocol & Core Hardening

  • TTD Wire Protocols (v2): Implemented high-integrity codecs for intents and receipts.
    • Added EINT v2 (Intent Envelope) with Little-Endian fixed headers and BLAKE3 payload checksums.
    • Added TTDR v2 (Tick Receipt Record) supporting full provenance commitments including state roots and emission digests.
    • Integrated "Header Integrity Drills" and a decoder fuzzer to ensure protocol robustness.
  • Provenance & Merkle Hardening: Expanded core state model to support deterministic "Show Me Why" features.
    • Added AtomWrite records to track causal arrows from rules to state changes.
    • Implemented compute_tick_commit_hash_v2, binding schema identity, worldline history, and materialized emissions into a single Merkle root.
    • Added TruthSink::clear_session to ensure isolated and leak-free memory management for TTD sessions.

Added — Determinism & Verification

  • DIND Phase 5 (The Shuffle): Added robustness against insertion order and HashMap iteration leaks.
    • Implemented echo-dind converge command to verify that shuffles of commutative operations (e.g. disjoint put_kv) yield identical final state hashes.
    • Added randomized scenario generator (scripts/bootstrap_randomized_order.mjs) producing semantically equivalent transcripts via different orderings.
    • Added regression tests for Invariant A (Self-Consistency) and Invariant B (Convergence) in CI; see issue #22.
  • Domain-Separated Hash Contexts: Added unique domain-separation prefixes to all core commitment hashes to prevent cross-context structural collisions.
    • state_root (graph hash), patch_digest (tick patch), and commit_id (Merkle root) now use distinct BLAKE3 domain tags (e.g. echo:state_root:v1\0).
    • RenderGraph::compute_hash (echo-graph) now uses its own domain tag, ensuring renderable snapshots cannot collide with engine state roots.
    • Added warp_core::domain module containing public prefix constants.
    • Integrated cross-domain collision tests into CI.
  • Benchmarks CI Integration: The warp-benches package is now integrated into the CI compilation gate (cargo check --benches).

Changed — Roadmap & Governance

  • Roadmap Refactor ("Sharpened" structure): Migrated the flat roadmap into a 2-level hierarchy based on features and milestones.
    • Established a WIP Cap policy: maximum 2 active milestones and 3 active feature files per milestone to prevent context thrashing.
    • Added binary Exit Criteria to all milestone READMEs to ensure clear, objective completion signals.
    • Renamed milestones for clarity (e.g. lock-the-hashes, first-light, proof-core).
    • Audited and updated license headers (SPDX) and formatting (Prettier/MD028) across roadmap documents.

Changed — Gateway Resilience (echo-session-ws-gateway)

  • Typed HubConnectError enum replaces the opaque HubConnectError(String). Four variants (Timeout, Connect, Handshake, Subscribe) carry structured context, and a should_retry() predicate is wired into the ninelives retry policy so future non-transient variants can short-circuit retries.

  • Hub observer task exits are surfaced — the fire-and-forget tokio::spawn is wrapped in a watcher task that logs unexpected exits and panics at warn!/error! level, preventing silent observer disappearance.

  • connect_failures restored to per-attempt semantics — the metric now increments on every failed connection attempt (1:1 with connect_attempts), not once per exhausted retry burst. This preserves dashboard/alerting accuracy during prolonged hub outages.

  • Hub observer reconnect now uses ninelives retry policy with exponential backoff (250 ms → 3 s) and full jitter, replacing hand-rolled backoff state. Retries are grouped into bursts of 10 attempts; on exhaustion a 10 s cooldown separates bursts. This prevents synchronized retry storms across gateway instances and improves recovery behavior during prolonged hub outages.

  • Connection setup (connect + handshake + subscribe) extracted into hub_observer_try_connect, separating connection logic from retry orchestration.

  • Entire connection attempt (connect + handshake + subscribe) is now wrapped in a single 5 s timeout, preventing a stalled peer from hanging the retry loop.

  • Retry policy construction uses graceful error handling instead of .expect(), so a misconfiguration disables the observer with a log rather than panicking inside a fire-and-forget tokio::spawn.

  • Added 1 s cooldown after the read loop exits to prevent tight reconnect loops when the hub accepts connections but immediately closes them.

Fixed

  • Security: upgraded bytes 1.11.0 → 1.11.1 to fix RUSTSEC-2026-0007 (integer overflow in BytesMut::reserve).