From 3284dc778af2620146145880988680ca7f29a76b Mon Sep 17 00:00:00 2001 From: Lu Nelson Date: Wed, 5 Aug 2026 11:33:52 +0200 Subject: [PATCH 1/3] FE-1316: Charter current-system reorientation audit --- memory/PLAN.md | 22 +++ ...system-reorientation-audit--lane-ledger.md | 126 ++++++++++++++++++ 2 files changed, 148 insertions(+) create mode 100644 memory/cards/system-reorientation-audit--lane-ledger.md diff --git a/memory/PLAN.md b/memory/PLAN.md index 8813cc45f..b492c3c1c 100644 --- a/memory/PLAN.md +++ b/memory/PLAN.md @@ -18,6 +18,7 @@ - **Comparison lanes:** the repo keeps two distinct evaluation doors: seed-based intra-product testing and mission-driven cross-product comparison. FE-1241 closed the brownfield comparison cases; FE-1215 landed the approachable operator workflow; the remaining operator residue is the structural mission-isolation hardening plus the later real Brunch+Claude saved-mission witness. - **Executor / Execute evidence queue:** several KA fronts are implementation-merged but still carry explicit outer evidence: `host-landing`, `executor-plan-synthesis`, `execution-comparison-tracer`, `executor-plan-coherence`, `executor-slice-verification-repair`, and `greenfield-secure-drop-demo`. - **Current seams and discipline:** Brunch ships on `1.0.0-alpha.x`. D125-L's live ask registry is the structured-exchange headless surface; the transcript-backed pending projection remains compatibility-only. Sweep classification remains fail-closed on exchange-schema terminal names (D117-L); the larger capture-conditional watermark question remains A40-L. Co-located `src/**/TOPOLOGY.md` files own current topology; scratch evidence is not durable until promoted to `.fixtures/runs/`. +- **Current-state reorientation:** FE-1316 freezes the post-cleanup drift/overlap concerns into one temporary disposition ledger. It may route work to existing or new frontiers but implements none of them and must not become a second queue beside PLAN. ## Initiatives @@ -60,6 +61,7 @@ Older completion history and archived completed frontier definitions live in [`d ### Next +- `system-reorientation-audit` ([FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift)) — prepared evidence/disposition pass over the frozen cleanup, handover, documentation, legibility, presentation, and comparison/PTY concerns. FE-1311 closure is satisfied; current execution pointer: [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). **Retires:** uncertainty about which current seams are canonical versus implemented-but-unwitnessed, intentionally distinct, superseded, or genuinely divergent. - `saved-mission-comparison-witness` — later operator-owned frontier: FE-1215 is landed, so the remaining work is scheduling the real Brunch + Claude `/compare-specs` witness, then revising/rerunning the saved mission to prove historical snapshots remain immutable. Definition below. - `comparison-mission-isolation-hardening` — admitted from FE-1215 smoke (`TESTING_FINDINGS.md` CS2): move the private mission outside the target-reachable tree (or equivalently jail the target's file tools) so the D134-L/I67-L mission boundary is structural, not conduct-dependent. Definition below. - `shared-session-host-tracer` — prove the one-host TUI attachment seam that FE-1200 deliberately left open. Definition below. @@ -92,6 +94,22 @@ Legacy link target; see Horizon. +### system-reorientation-audit + +- **Name:** Current-system authority and drift audit +- **Linear:** [FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift) +- **Branch:** `ln/fe-1316-system-authority-audit`, stacked after FE-1311 because its closure state is an audit input. +- **Kind:** structural evidence/disposition frontier; not an implementation umbrella or alternate planning store. +- **Certainty:** proving. +- **Status:** prepared; FE-1311 dependency satisfied, so lane review may begin. +- **Objective:** give every concern in the frozen post-cleanup inventory one evidence-backed current-state disposition and canonical owner. +- **Acceptance:** each row in the lane ledger reaches `closed` or `promoted`; alleged overlaps are classified as intentional, accidental, superseded, or unknown; factual handover drift is source-backed; promoted work has exactly one PLAN owner and no mirrored progress state remains in the ledger. +- **Verification:** structural census against the user-provided concern set and both flyovers; targeted code/test/build/package/provenance checks only where they discriminate a row; final user review of the disposition map. +- **Depends on:** FE-1311 closure is satisfied; reuse the existing KA evidence queue, `capture-ledger-tracer`, `walkthrough-remediation-2`, and shared-session-host arc rather than duplicating them. +- **Current execution pointer:** [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). +- **Promotion / disposal:** row-sized no-boundary corrections may close here; all implementation, witness, architecture, or independent doc cleanup promotes through `ln-plan`. Delete the ledger after every row is closed or promoted. +- **Traceability:** D140-L, A47-L; `docs/planning/planning-record-substrate-assessment.md`; `TESTING_FINDINGS.md`; current subtree topology homes. + ### walkthrough-remediation-2 - **Name:** Walkthrough chapter closure — remediation, evidence, and design follow-through (absorbs FE-1167) @@ -202,6 +220,10 @@ active: -[stack]-> cli-mode-entry next: + system-reorientation-audit (FE-1316) + dependency_satisfied: integrity-cleanup closure + disposes: frozen drift/overlap inventory -> closed | promoted to one PLAN owner + ledger: memory/cards/system-reorientation-audit--lane-ledger.md saved-mission-comparison-witness gated_by: operator availability depends_on: landed FE-1215 workflow diff --git a/memory/cards/system-reorientation-audit--lane-ledger.md b/memory/cards/system-reorientation-audit--lane-ledger.md new file mode 100644 index 000000000..618eea251 --- /dev/null +++ b/memory/cards/system-reorientation-audit--lane-ledger.md @@ -0,0 +1,126 @@ +# Current-system reorientation audit + +Frontier: system-reorientation-audit +Status: active +Mode: single +Created: 2026-08-04 + +## Orientation + +- Containing seam: Brunch's current-state authority after FE-1311 and the July executor/comparison delivery burst. +- Frontier: `system-reorientation-audit` (FE-1316), stacked after `integrity-cleanup`; this card inventories and disposes concerns but implements no promoted fix. +- Posture: **proving** (inherited from `system-reorientation-audit`); the useful result is a trusted map of which concerns are live, already owned, obsolete, or worthy of promotion. +- Main risk: this ledger becoming a sixth planning store. It owns only the frozen concern inventory and evidence-backed disposition; `memory/PLAN.md` owns work and sequencing, while SPEC/topology own durable truth. + +## Target behavior + +Every concern in the frozen post-cleanup inventory has one evidence-backed current-state disposition and canonical owner. + +## Cold-start reads + +- `memory/PLAN.md` — frontier `system-reorientation-audit`, existing frontiers, KA evidence queue, and dependencies +- `memory/SPEC.md` — D140-L, A47-L, live tracing/evaluation decisions, and acknowledged blind spots +- `memory/POSTURE.md` — proving, free-rewrite, high-stakes boundary behavior +- `memory/cards/integrity-cleanup--closure-walkthrough.md` — preceding closed inventory and explicit exclusions +- `TESTING_FINDINGS.md` — Secure Drop SD1–SD9 and current walkthrough evidence +- `docs/planning/planning-record-substrate-assessment.md` — existing planning-substrate measurements and recommendation +- `docs/design/AGENT_TRACING.md` and `docs/design/WEB_UI_ARCHITECTURE.md` — tracing and shared-host current claims +- `src/dev/TOPOLOGY.md`, `src/executor/TOPOLOGY.md`, and relevant subtree topology files — materialized current state + +## Boundary + +In scope is the concern inventory below: cleanup safety, handover/evidence truth, planning/document authority, agent legibility, presentation/runtime authority, and comparison/PTY ownership. + +Out of scope: + +- implementing a finding; +- rerunning provider, Secure Drop, comparison, or human outer witnesses; +- rewriting Notion documents without an available Notion connection; +- changing the PTY driver merely to avoid oracle-pack identity churn; +- reopening FE-1311's closed inventory or adding inferred cleanup rows to it; +- replacing `memory/PLAN.md`, SPEC, topology files, Linear, or existing findings ledgers. + +A newly discovered concern may enter only when it is a missing member of one of the six frozen lanes and includes a one-line omission justification. More than one new concern stops the audit and routes back through `ln-plan`. + +## Lane charter + +| Lane | Question | Existing authority | Output | +| --- | --- | --- | --- | +| L0 · cleanup safety | Did FE-1311 remove or strand a required behavior? | FE-1311 commits, closure card, D140-L, tests/build/package checks | bounded keep/fix verdict; no new cleanup sweep by analogy | +| L1 · evidence and handover | Which merged mechanisms have current valid witnesses? | PLAN KA evidence queue, TESTING findings, comparison provenance, fixture sources | implementation/evidence split and corrected handover status | +| L2 · canonical truth | Which planning and design surfaces still duplicate or contradict current topology? | PLAN, SPEC, topology files, planning-substrate assessment | keep/thin/archive/promote disposition by canonical owner | +| L3 · agent legibility | What observation loop can judge prompt, skill, and context interventions? | capture-ledger frontier, trajectory tools, product prompts/skills | smallest usable feedback loop; bounded prompt defects routed separately | +| L4 · presentation authority | What remains implementation work versus outer evidence across TUI, themes, web, and session hosting? | FE-1187, shared-host arc, web/TUI topology | existing-frontier routing; no second GUI proof | +| L5 · comparison and PTY | Which comparison doors and terminal-control seams are canonical for each study shape? | comparison prompts/skills/runbooks, end-to-end contracts, `tui-driver` consumers | authority map and only behavior-justified follow-ups | + +Lanes may be investigated independently, but they do not become branches by default. A finding gets a Linear issue and Graphite branch only when `ln-plan` promotes it to a frontier. + +## Disposition ledger + +Status vocabulary: `new` → not yet evidenced; `partial` → evidence gathered, disposition not closed; `closed` → no follow-up; `promoted` → PLAN owns the follow-up. A promoted row carries no duplicate progress state here. + +| ID | Lane | Concern | Initial evidence | Canonical owner / likely route | Closure oracle | Status | +| --- | --- | --- | --- | --- | --- | --- | +| R01 | L0 | FE-1311's five-row closure remains the only admitted cleanup work | FE-1311 closeout in `docs/archive/PLAN_HISTORY.md`; current PLAN exclusion list | `integrity-cleanup` | every required row built and aggregate package/check/build oracles satisfied | closed | +| R02 | L0 | Required behavior may have been removed through an out-of-graph consumer blind spot | D140-L; FE-1311 falsified-deletion commits; package/build/test surfaces | close if evidence stays negative; promote only a concrete broken behavior | named consumer failure or clean current full-gate lanes plus deletion provenance | partial | +| R03 | L1 | Notion handover status and fixture counts drift from current repository truth | Alpha 13 tag; Wisp 88/212; NullWire 61/143; SD9 | correction report for the document owner; no local product frontier by default | each disputed claim mapped to current file/tag/test evidence | partial | +| R04 | L1 | KA implementation claims are ahead of current valid outer witnesses | PLAN KA evidence queue; Secure Drop witness card; comparison report state | reuse named KA evidence frontiers; do not create an umbrella executor frontier | every claimed outcome labeled implemented, witnessed-current, failed, or unknown | partial | +| R05 | L1 | "Current test scenarios" spans several ledgers and mixes prepared scenarios with current evidence | `TESTING_PLAN.md`; `TESTING_FINDINGS.md`; comparison case trees; fixture READMEs | testing documentation owner or promoted consolidation finding | one inventory distinguishes scenario availability, implementation coverage, and current valid witness | partial | +| R06 | L2 | Mutable queue coordination and durable repository truth are carried by overlapping planning surfaces | planning-record substrate assessment; PLAN/SPEC measurements; Linear mapping | disposition through `ln-plan`/`ln-sync`; Linear remains mutable coordination, not product canon | explicit owner matrix with no second live queue | partial | +| R07 | L2 | SPEC, topology, design, praxis, cards, and findings duplicate or preserve superseded claims | current file census; topology ownership rule; retired FE-1208 text | likely `ln-sync` promotion after exact contradiction inventory | each named contradiction has one surviving canonical home and obsolete copies are thinned/archived | new | +| R08 | L3 | Existing trajectory capture does not yet form an operational agent-direction feedback loop | `trajectory.ndjson`; trajectory report; capture-ledger frontier; retired FE-1208 actor | reuse `capture-ledger-tracer`; promote child-span tracing only on a named attribution gap | one controlled intervention loop links conduct evidence to a discriminating outcome judgment | partial | +| R09 | L3 | Prompt/context guidance is repeated, overweight, and demonstrably capable of drift | product prompts/skills/extensions; stale `present_digest` continuation guidance | bounded defects may be direct fixes; optimization follows R08 evidence | authority map plus at least one current contradiction disposed without broad prompt rewrite | partial | +| R10 | L4 | TUI and web retain duplicate writable runtime authority | shared-session-host arc; A47-L; web/TUI/session topology | existing `shared-session-host-tracer` then cutover | one host owns runtime/JSONL/driver while both real presentations attach | promoted | +| R11 | L4 | Theme and TUI refinement appears active although implementation is largely complete | shipped themes; preview harness; FE-1187 consolidated outer checkpoint | existing `walkthrough-remediation-2` evidence route | implementation/evidence distinction recorded; no new theme frontier absent a visual failure | partial | +| R12 | L5 | Elicitation, execution, and end-to-end comparison use several trees, prompts, adapters, and runbooks | comparison guide/runbooks; `/compare-specs`; `/compare-execution`; E2E contracts | retain distinct study shapes; promote only accidental orchestration/document duplication | every entry point has one named purpose, authority, evidence contract, and supersession relation | partial | +| R13 | L5 | `tui-driver` is fallback transport, automated oracle actuation, and part of immutable oracle identity | `tui-driver`; host-landing runner; comparison operator hash inputs | keep current seam until a named behavior requires change; do not split to hide recalibration | each consumer class and recalibration consequence documented; any proposed edit names the behavior it buys | partial | + +## Risks and assumptions + +- RISK: broad reading generates an unbounded issue list → MITIGATION: frozen lanes, one-new-row tripwire, and promotion rather than implementation. +- RISK: a row repeats status already owned by PLAN or a findings ledger → MITIGATION: link the owner, mark `promoted`, and stop mirroring progress. +- RISK: historical prose is treated as current authority → MITIGATION: current production topology and executable evidence outrank summaries; SPEC retains decision events only. +- ASSUMPTION: the user-provided concerns plus the two independent flyovers form a sufficient frozen audit input. + → IMPACT IF FALSE: the card is not a bounded audit and must be replanned rather than expanded indefinitely. + → VALIDATE: the one-new-row tripwire during lane review. + +## Posture check + +This proving frontier retires uncertainty about current authority and overlap. It lights no new runtime path and must not pretend to: its value is a falsifiable disposition map that prevents later build frontiers from preserving or reintroducing superseded paths. + +## Acceptance criteria + +- ✓ **Frozen inventory check** — every original user concern maps to at least one R-row, and no row is a miscellaneous catch-all. +- ✓ **Evidence check** — every row reaches `closed` or `promoted` with repository paths, executable output, provenance, or an explicitly named unavailable outer oracle. +- ✓ **Authority check** — every promoted row names one PLAN frontier; no row creates a parallel queue or mirrors that frontier's progress. +- ✓ **Drift check** — all factual disagreements between the pasted Notion handover and current repository evidence are listed with their current source. +- ✓ **Overlap check** — each alleged duplicate receives `intentional`, `accidental`, `superseded`, or `unknown`, with the discriminating reason. +- ✓ **Disposal check** — once all rows are `closed` or `promoted`, `ln-sync` deletes this card after reconciling its promoted frontier references into PLAN. + +## Verification approach + +- Inner: structural row census and repository searches — prove completeness against the frozen input and bind claims to sources. +- Middle: targeted tests, builds, package inspection, semantic dependency analysis, and git provenance only where they discriminate a row. +- Outer: user review of the final disposition map; unavailable Notion edits and model/browser witnesses remain with their existing named owners and re-entry triggers. + +## Cross-cutting obligations + +- FE-1311's closed-inventory rule remains intact. +- Current topology lives in `src/**/TOPOLOGY.md`; SPEC owns decisions/events, not a duplicate current-state copy. +- Implementation evidence and outer outcome evidence remain separate statuses. +- Comparison evidence stays target-neutral; Brunch-only traces are diagnostic. +- Oracle-pack identity changes when oracle behavior changes; architecture must not be split merely to conceal that change. + +## Expected touched paths (tentative) + +```text +memory/ +├── PLAN.md ~ +└── cards/system-reorientation-audit--lane-ledger.md ~ +``` + +## Promotion and disposal + +A row-sized correction may close in place only when it changes no durable boundary and belongs on this frontier branch. Any implementation, witness campaign, architecture decision, or independent documentation cleanup is promoted through `ln-plan` to an existing or new frontier. `promoted` is terminal here: PLAN owns all later status. + +Delete this card in the first `ln-sync` after every row is `closed` or `promoted`; do not archive its live-status table or preserve it as a permanent handover document. From 9b0381d25b0c879838168e934b348b73144d3242 Mon Sep 17 00:00:00 2001 From: Lu Nelson Date: Wed, 5 Aug 2026 12:05:17 +0200 Subject: [PATCH 2/3] FE-1316: Reconcile system audit dispositions --- memory/PLAN.md | 46 +++++++++++++++++-- ...system-reorientation-audit--lane-ledger.md | 35 +++++++++----- .../__tests__/exchanges-extension.test.ts | 8 ++-- .../extensions/exchanges/present-digest.ts | 6 +-- 4 files changed, 74 insertions(+), 21 deletions(-) diff --git a/memory/PLAN.md b/memory/PLAN.md index b492c3c1c..4eaf2247e 100644 --- a/memory/PLAN.md +++ b/memory/PLAN.md @@ -61,7 +61,9 @@ Older completion history and archived completed frontier definitions live in [`d ### Next -- `system-reorientation-audit` ([FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift)) — prepared evidence/disposition pass over the frozen cleanup, handover, documentation, legibility, presentation, and comparison/PTY concerns. FE-1311 closure is satisfied; current execution pointer: [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). **Retires:** uncertainty about which current seams are canonical versus implemented-but-unwitnessed, intentionally distinct, superseded, or genuinely divergent. +- `system-reorientation-audit` ([FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift)) — evidence/disposition pass over the frozen cleanup, handover, documentation, legibility, presentation, and comparison/PTY concerns. Twelve rows are closed or promoted; the bounded `present_digest` guidance correction remains. Current execution pointer: [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). **Retires:** uncertainty about which current seams are canonical versus implemented-but-unwitnessed, intentionally distinct, superseded, or genuinely divergent. +- `canonical-document-reconciliation` — earned closure over the exact normative-looking drift promoted by FE-1316: demote the unadopted PLAN-replacement prescription, archive/thin the enumerated superseded design notes, and correct comparison case/profile prose. Definition below. +- `host-landing-oracle-identity` — close the immutable host-landing oracle pack over every behavior-bearing PTY input before its next comparison use. Definition below. - `saved-mission-comparison-witness` — later operator-owned frontier: FE-1215 is landed, so the remaining work is scheduling the real Brunch + Claude `/compare-specs` witness, then revising/rerunning the saved mission to prove historical snapshots remain immutable. Definition below. - `comparison-mission-isolation-hardening` — admitted from FE-1215 smoke (`TESTING_FINDINGS.md` CS2): move the private mission outside the target-reachable tree (or equivalently jail the target's file tools) so the D134-L/I67-L mission boundary is structural, not conduct-dependent. Definition below. - `shared-session-host-tracer` — prove the one-host TUI attachment seam that FE-1200 deliberately left open. Definition below. @@ -101,15 +103,44 @@ Legacy link target; see Horizon. - **Branch:** `ln/fe-1316-system-authority-audit`, stacked after FE-1311 because its closure state is an audit input. - **Kind:** structural evidence/disposition frontier; not an implementation umbrella or alternate planning store. - **Certainty:** proving. -- **Status:** prepared; FE-1311 dependency satisfied, so lane review may begin. +- **Status:** audit complete; twelve rows are closed or promoted, with only the row-sized `present_digest` provider-guidance correction still partial. - **Objective:** give every concern in the frozen post-cleanup inventory one evidence-backed current-state disposition and canonical owner. -- **Acceptance:** each row in the lane ledger reaches `closed` or `promoted`; alleged overlaps are classified as intentional, accidental, superseded, or unknown; factual handover drift is source-backed; promoted work has exactly one PLAN owner and no mirrored progress state remains in the ledger. +- **Acceptance:** each row in the lane ledger reaches `closed` or `promoted`; alleged overlaps are classified as intentional, accidental, superseded, or unknown; factual handover drift is source-backed; promoted work has exactly one PLAN owner and no mirrored progress state remains in the ledger. Current close condition: correct and pin the stale `present_digest` provider guidance, then dispose the ledger. - **Verification:** structural census against the user-provided concern set and both flyovers; targeted code/test/build/package/provenance checks only where they discriminate a row; final user review of the disposition map. - **Depends on:** FE-1311 closure is satisfied; reuse the existing KA evidence queue, `capture-ledger-tracer`, `walkthrough-remediation-2`, and shared-session-host arc rather than duplicating them. - **Current execution pointer:** [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). - **Promotion / disposal:** row-sized no-boundary corrections may close here; all implementation, witness, architecture, or independent doc cleanup promotes through `ln-plan`. Delete the ledger after every row is closed or promoted. - **Traceability:** D140-L, A47-L; `docs/planning/planning-record-substrate-assessment.md`; `TESTING_FINDINGS.md`; current subtree topology homes. +### canonical-document-reconciliation + +- **Name:** Reconcile canonical documentation with current topology +- **Linear:** unassigned — create at pickup in Frontend / brunch. +- **Branch:** tbd at pickup; stack after FE-1316. +- **Kind / classification:** coverage-shaped documentation closure · buildable-now. +- **Certainty:** earned. +- **Objective:** make every retained active planning/design/comparison document in the FE-1316 inventory point at current authority without preserving normative-looking superseded architecture. +- **Boundary:** the planning-substrate assessment; `ELICITATION_QUESTIONS.md`; `ELICITATION_LENSES.md`; `STRUCTURED_EXCHANGE_COLLAPSE.md`; `SESSION_HOST_DECISION_CANDIDATE.md`; `MULTI_SESSION_DAEMON_ARCHITECTURE.md`; stale `REVIEW_SETS.md` future-work text; and comparison guide/runbook case/profile drift. No SPEC rewrite, product implementation, or new aggregate status document. +- **Closes:** FE-1316 R06, R07, and R12. +- **Acceptance:** the planning assessment labels its PLAN-replacement proposal unadopted; each enumerated historical design note is archived or thinned to history plus a current pointer; active comparison prose lists four execution cases, distinguishes three configured E2E contracts from retained witnesses, and does not imply an E2E operator command; Markdown links pass. +- **Verification:** exact retired-vocabulary/current-authority searches, archive/link census, `npm run check:markdown-links`, and final diff review against the frozen inventory. +- **Depends on:** FE-1316 disposition audit. +- **Traceability:** AGENTS.md §topology files; `docs/praxis/ln-skills.md` canonical-state ownership; D98-L, D110-L, D116-L, D132-L–D134-L. + +### host-landing-oracle-identity + +- **Name:** Close host-landing oracle identity over PTY behavior +- **Linear:** unassigned — create at pickup in Frontend / brunch. +- **Branch:** tbd at pickup; stack after FE-1316 independently of the docs closure. +- **Kind:** bounded verification hardening. +- **Certainty:** earned. +- **Objective:** make the immutable host-landing oracle-pack hash change for every behavior-bearing `tui-driver` input. +- **Closes:** FE-1316 R13's concrete identity gap; it does not redesign or split the PTY driver. +- **Acceptance:** the compiled host-landing implementation set includes `tui-driver.ts`, `session.ts`, `screen.ts`, `keys.ts`, and `driver.exp`; changing any one changes `oraclePackSha256`; identical inputs produce a stable hash. +- **Verification:** focused oracle-pack identity regression plus current host-landing oracle contract tests. +- **Depends on:** FE-1316 disposition audit; must land before the next retained host-landing comparison attempt or any claim that its current oracle identity covers PTY behavior. +- **Traceability:** FE-1230 execution-comparison oracle boundary; `src/dev/TOPOLOGY.md`; `src/dev/execution-comparison-operator.ts`. + ### walkthrough-remediation-2 - **Name:** Walkthrough chapter closure — remediation, evidence, and design follow-through (absorbs FE-1167) @@ -222,8 +253,17 @@ active: next: system-reorientation-audit (FE-1316) dependency_satisfied: integrity-cleanup closure + closes_next: bounded present_digest provider-guidance correction disposes: frozen drift/overlap inventory -> closed | promoted to one PLAN owner ledger: memory/cards/system-reorientation-audit--lane-ledger.md + -[hard]-> canonical-document-reconciliation + -[hard]-> host-landing-oracle-identity + canonical-document-reconciliation + closes: FE-1316 R06 | R07 | R12 + classification: buildable-now earned docs closure + host-landing-oracle-identity + closes: FE-1316 R13 + blocks: next retained host-landing comparison attempt saved-mission-comparison-witness gated_by: operator availability depends_on: landed FE-1215 workflow diff --git a/memory/cards/system-reorientation-audit--lane-ledger.md b/memory/cards/system-reorientation-audit--lane-ledger.md index 618eea251..1608aa220 100644 --- a/memory/cards/system-reorientation-audit--lane-ledger.md +++ b/memory/cards/system-reorientation-audit--lane-ledger.md @@ -62,18 +62,29 @@ Status vocabulary: `new` → not yet evidenced; `partial` → evidence gathered, | ID | Lane | Concern | Initial evidence | Canonical owner / likely route | Closure oracle | Status | | --- | --- | --- | --- | --- | --- | --- | | R01 | L0 | FE-1311's five-row closure remains the only admitted cleanup work | FE-1311 closeout in `docs/archive/PLAN_HISTORY.md`; current PLAN exclusion list | `integrity-cleanup` | every required row built and aggregate package/check/build oracles satisfied | closed | -| R02 | L0 | Required behavior may have been removed through an out-of-graph consumer blind spot | D140-L; FE-1311 falsified-deletion commits; package/build/test surfaces | close if evidence stays negative; promote only a concrete broken behavior | named consumer failure or clean current full-gate lanes plus deletion provenance | partial | -| R03 | L1 | Notion handover status and fixture counts drift from current repository truth | Alpha 13 tag; Wisp 88/212; NullWire 61/143; SD9 | correction report for the document owner; no local product frontier by default | each disputed claim mapped to current file/tag/test evidence | partial | -| R04 | L1 | KA implementation claims are ahead of current valid outer witnesses | PLAN KA evidence queue; Secure Drop witness card; comparison report state | reuse named KA evidence frontiers; do not create an umbrella executor frontier | every claimed outcome labeled implemented, witnessed-current, failed, or unknown | partial | -| R05 | L1 | "Current test scenarios" spans several ledgers and mixes prepared scenarios with current evidence | `TESTING_PLAN.md`; `TESTING_FINDINGS.md`; comparison case trees; fixture READMEs | testing documentation owner or promoted consolidation finding | one inventory distinguishes scenario availability, implementation coverage, and current valid witness | partial | -| R06 | L2 | Mutable queue coordination and durable repository truth are carried by overlapping planning surfaces | planning-record substrate assessment; PLAN/SPEC measurements; Linear mapping | disposition through `ln-plan`/`ln-sync`; Linear remains mutable coordination, not product canon | explicit owner matrix with no second live queue | partial | -| R07 | L2 | SPEC, topology, design, praxis, cards, and findings duplicate or preserve superseded claims | current file census; topology ownership rule; retired FE-1208 text | likely `ln-sync` promotion after exact contradiction inventory | each named contradiction has one surviving canonical home and obsolete copies are thinned/archived | new | -| R08 | L3 | Existing trajectory capture does not yet form an operational agent-direction feedback loop | `trajectory.ndjson`; trajectory report; capture-ledger frontier; retired FE-1208 actor | reuse `capture-ledger-tracer`; promote child-span tracing only on a named attribution gap | one controlled intervention loop links conduct evidence to a discriminating outcome judgment | partial | -| R09 | L3 | Prompt/context guidance is repeated, overweight, and demonstrably capable of drift | product prompts/skills/extensions; stale `present_digest` continuation guidance | bounded defects may be direct fixes; optimization follows R08 evidence | authority map plus at least one current contradiction disposed without broad prompt rewrite | partial | -| R10 | L4 | TUI and web retain duplicate writable runtime authority | shared-session-host arc; A47-L; web/TUI/session topology | existing `shared-session-host-tracer` then cutover | one host owns runtime/JSONL/driver while both real presentations attach | promoted | -| R11 | L4 | Theme and TUI refinement appears active although implementation is largely complete | shipped themes; preview harness; FE-1187 consolidated outer checkpoint | existing `walkthrough-remediation-2` evidence route | implementation/evidence distinction recorded; no new theme frontier absent a visual failure | partial | -| R12 | L5 | Elicitation, execution, and end-to-end comparison use several trees, prompts, adapters, and runbooks | comparison guide/runbooks; `/compare-specs`; `/compare-execution`; E2E contracts | retain distinct study shapes; promote only accidental orchestration/document duplication | every entry point has one named purpose, authority, evidence contract, and supersession relation | partial | -| R13 | L5 | `tui-driver` is fallback transport, automated oracle actuation, and part of immutable oracle identity | `tui-driver`; host-landing runner; comparison operator hash inputs | keep current seam until a named behavior requires change; do not split to hide recalibration | each consumer class and recalibration consequence documented; any proposed edit names the behavior it buys | partial | +| R02 | L0 | Required behavior may have been removed through an out-of-graph consumer blind spot | D140-L; FE-1311 deletion provenance; 123 focused tests; unchanged production tree since closeout | closed — no concrete broken or stranded behavior found | named consumer failure or clean current gates plus negative deletion provenance | closed | +| R03 | L1 | Notion handover status and fixture counts drift from current repository truth | Alpha 13 tag; Wisp 88/212; NullWire 61/143; SD9 | closed by source-backed correction report to the user; external Notion edit remains with its document owner | each disputed claim mapped to current file/tag/test evidence | closed | +| R04 | L1 | KA implementation claims are ahead of current valid outer witnesses | PLAN KA evidence queue; Secure Drop witness card; comparison report state | existing KA evidence queue; no umbrella executor frontier | every claimed outcome labeled implemented, witnessed-current, failed, or unknown | promoted | +| R05 | L1 | "Current test scenarios" spans several ledgers and mixes prepared scenarios with current evidence | walkthrough plan/findings; five missions; four execution cases; three E2E contracts; fixture READMEs | closed by role-specific inventory; do not create another status document | scenario availability, implementation coverage, and current valid witness are distinguished | closed | +| R06 | L2 | Mutable queue coordination and durable repository truth are carried by overlapping planning surfaces | planning assessment versus current PLAN/Linear/Graphite authority rules | `canonical-document-reconciliation` — demote the unadopted PLAN-replacement prescription | explicit owner matrix with no second live queue | promoted | +| R07 | L2 | SPEC, topology, design, praxis, cards, and findings duplicate or preserve superseded claims | exact stale/superseded design-note inventory; topology ownership rule | `canonical-document-reconciliation` — thin/archive only the enumerated documents | each named contradiction has one surviving canonical home and obsolete copies are thinned/archived | promoted | +| R08 | L3 | Existing trajectory capture does not yet form an operational agent-direction feedback loop | trajectory recorder/report/evaluator; prepared capture-ledger campaign; retired FE-1208 actor | existing `capture-ledger-tracer`; child spans remain trigger-gated | one controlled intervention loop links conduct evidence to a discriminating outcome judgment | promoted | +| R09 | L3 | Prompt/context guidance is repeated, overweight, and demonstrably capable of drift | provider-visible `present_digest` contradiction versus D110-L/runtime continuation | closed by bounded guidance correction and focused contract/runtime tests; broad optimization follows R08 evidence | tool guidance matches conversational feedback and later `acceptsDigest` capture authority | closed | +| R10 | L4 | TUI and web retain duplicate writable runtime authority | production composition roots; shared-session-host arc; A47-L | existing `shared-session-host-tracer` then cutover | one host owns runtime/JSONL/driver while both real presentations attach | promoted | +| R11 | L4 | Theme and TUI refinement appears active although implementation is largely complete | shipped themes; preview harness; FE-1187 consolidated outer checkpoint | existing `walkthrough-remediation-2` evidence route; no new theme frontier | implementation/evidence distinction recorded; outer checkpoint yields pass or a specific bounded failure | promoted | +| R12 | L5 | Elicitation, execution, and end-to-end comparison use several trees, prompts, adapters, and runbooks | authority matrix plus exact comparison-guide/case-count drift | `canonical-document-reconciliation`; retain the distinct study shapes | every entry point has one named purpose, authority, evidence contract, and supersession relation | promoted | +| R13 | L5 | `tui-driver` is fallback transport, automated oracle actuation, and part of immutable oracle identity | consumer census; host-landing pack omits behavior-bearing `keys.ts` and `driver.exp` | `host-landing-oracle-identity`; do not split PTY to hide recalibration | every behavior-bearing PTY input changes the oracle-pack hash; identical inputs remain stable | promoted | + +## Audit findings + +- **Cleanup safety:** no required runtime behavior was found removed or stranded. FE-1311's deleted tool, query-helper, schema-snapshot, renderer-dependency, and deterministic-minting paths all have negative consumer provenance or replacement coverage; current focused closure suites pass. R02 reopens only on a named behavior failure. +- **Evidence truth:** Alpha 13 is released, not being prepared. Wisp is 88 nodes / 212 edges and NullWire is 61 / 143. Secure Drop reached landing but remains failed outcome evidence under SD9. All six KA queue items are implementation-merged and outer-evidence-open. +- **Scenario roles:** walkthrough concerns, saved missions, execution cases, end-to-end contracts, seed fixtures, and retained runs are intentionally different strata. Their existence does not imply a current valid witness, so no new aggregate status store is warranted. +- **Canonical documents:** the planning-substrate assessment's PLAN-replacement recommendation is unadopted. `ELICITATION_QUESTIONS.md`, `ELICITATION_LENSES.md`, `STRUCTURED_EXCHANGE_COLLAPSE.md`, the superseded host notes, and parts of `REVIEW_SETS.md` preserve normative-looking retired language. The exact inventory routes to one bounded docs reconciliation, not a wholesale rewrite. +- **Legibility:** current trajectory machinery proves exposure/read/correlation, not causality. The prepared `capture-ledger-tracer` is the smallest controlled outcome loop. Child-span tracing remains gated on a concrete attribution failure. +- **Prompt authority:** one current provider-visible contradiction is proven: `src/.pi/extensions/exchanges/present-digest.ts` still prescribes approve/request-changes/reject and capture echoing, contrary to D110-L's conversational free-text continuation and later `acceptsDigest` carrier. R09 remains the one row-sized correction on this branch; no broad prompt rewrite is admitted. +- **Presentation:** duplicate TUI/web runtime authority is real at the two production composition roots and already belongs to the shared-host tracer/cutover. Theme implementation is materially present; its remaining work is FE-1187-owned outer evidence. +- **Comparison and PTY:** approachable elicitation, rigorous elicitation, execution comparison, and end-to-end composition are intentional study shapes. Documentation case counts have drifted. `tui-driver` is both fallback transport and automated oracle actuation; the host-landing hash currently omits behavior-bearing `keys.ts` and `driver.exp`, which requires identity closure rather than PTY decomposition. ## Risks and assumptions diff --git a/src/.pi/extensions/__tests__/exchanges-extension.test.ts b/src/.pi/extensions/__tests__/exchanges-extension.test.ts index 25fc5bfed..3d689ff9c 100644 --- a/src/.pi/extensions/__tests__/exchanges-extension.test.ts +++ b/src/.pi/extensions/__tests__/exchanges-extension.test.ts @@ -69,9 +69,11 @@ describe('structured exchange tool guidance', () => { expect(guidance).toContain('Never author a listed option that duplicates the built-in Other affordance'); expect(guidance).toContain("Do not restate a present_* offer's large pretext or digest body"); - expect(guidance).toContain( - 'For the declared review continuation, ask only for approve / request changes / reject', - ); + expect(guidance).toContain('Collect conversational free-text corrections or clarifications'); + expect(guidance).toContain('A continued ask does not accept the digest for capture'); + expect(guidance).toContain('acceptsDigest'); + expect(guidance).not.toContain('approve / request changes / reject'); + expect(guidance).not.toContain('accepted terminal echoes the abstract'); }); }); diff --git a/src/.pi/extensions/exchanges/present-digest.ts b/src/.pi/extensions/exchanges/present-digest.ts index 42abfd7db..2c0c81406 100644 --- a/src/.pi/extensions/exchanges/present-digest.ts +++ b/src/.pi/extensions/exchanges/present-digest.ts @@ -21,13 +21,13 @@ export const presentDigestTool = defineTool Date: Wed, 5 Aug 2026 12:07:26 +0200 Subject: [PATCH 3/3] FE-1316: Close system reorientation audit --- docs/archive/PLAN_HISTORY.md | 6 + memory/PLAN.md | 29 +--- ...system-reorientation-audit--lane-ledger.md | 137 ------------------ 3 files changed, 9 insertions(+), 163 deletions(-) delete mode 100644 memory/cards/system-reorientation-audit--lane-ledger.md diff --git a/docs/archive/PLAN_HISTORY.md b/docs/archive/PLAN_HISTORY.md index eae92bae7..180ce7266 100644 --- a/docs/archive/PLAN_HISTORY.md +++ b/docs/archive/PLAN_HISTORY.md @@ -3,6 +3,12 @@ This file is the active POC-line plan archive for `memory/PLAN.md`. Legacy pre-`next` history was moved out of the live docs tree with the old archived implementation. +## 2026-08-06 FE-1316 system reorientation audit closeout + +`system-reorientation-audit` closed a bounded six-lane review of thirteen post-cleanup concerns. It found no deleted or stranded required behavior, separated merged executor mechanisms from their still-open outer witnesses, confirmed the comparison scenario layers are distinct, and routed tracing, dual-host, theme, and KA evidence work to their existing owners. + +The audit fixed one row-sized defect: stale `present_digest` provider guidance that contradicted the conversational correction flow. It admitted exactly two new frontiers: `canonical-document-reconciliation` for enumerated normative-document drift and `host-landing-oracle-identity` for omitted behavior-bearing PTY inputs. The temporary ledger was deleted after every row reached `closed` or `promoted`; no parallel audit queue remains. + ## 2026-08-05 FE-1311 integrity cleanup closeout `integrity-cleanup` completed its verified deletion/consolidation sweep and final five-row closure on `ln/fe-1311-integrity-cleanup`. The closing pass made `dist-web` the sole published browser artifact, kept locally built probes out of the package while documenting their topology, routed external end-to-end comparison consumers through the public root, removed the final byte-identical `fileExists` clone, and renamed DB column round-trip coverage for what it proves. diff --git a/memory/PLAN.md b/memory/PLAN.md index 4eaf2247e..9865b97bd 100644 --- a/memory/PLAN.md +++ b/memory/PLAN.md @@ -18,7 +18,6 @@ - **Comparison lanes:** the repo keeps two distinct evaluation doors: seed-based intra-product testing and mission-driven cross-product comparison. FE-1241 closed the brownfield comparison cases; FE-1215 landed the approachable operator workflow; the remaining operator residue is the structural mission-isolation hardening plus the later real Brunch+Claude saved-mission witness. - **Executor / Execute evidence queue:** several KA fronts are implementation-merged but still carry explicit outer evidence: `host-landing`, `executor-plan-synthesis`, `execution-comparison-tracer`, `executor-plan-coherence`, `executor-slice-verification-repair`, and `greenfield-secure-drop-demo`. - **Current seams and discipline:** Brunch ships on `1.0.0-alpha.x`. D125-L's live ask registry is the structured-exchange headless surface; the transcript-backed pending projection remains compatibility-only. Sweep classification remains fail-closed on exchange-schema terminal names (D117-L); the larger capture-conditional watermark question remains A40-L. Co-located `src/**/TOPOLOGY.md` files own current topology; scratch evidence is not durable until promoted to `.fixtures/runs/`. -- **Current-state reorientation:** FE-1316 freezes the post-cleanup drift/overlap concerns into one temporary disposition ledger. It may route work to existing or new frontiers but implements none of them and must not become a second queue beside PLAN. ## Initiatives @@ -53,15 +52,14 @@ ### Recently Completed +- 2026-08-06 `system-reorientation-audit` (FE-1316) — **✓ complete:** thirteen post-cleanup concerns received evidence-backed dispositions; one stale exchange-guidance defect was fixed, two bounded frontiers were admitted, and existing owners absorbed the remaining promoted work without creating a parallel queue. - 2026-08-05 `integrity-cleanup` (FE-1311) — **✓ complete:** the verified deletion/consolidation sweep and final five-row closure aligned the published package, probe topology, comparison public root, path-existence ownership, DB test naming, and portable repo-root Pi extension discovery without reopening falsified deletion targets. - 2026-07-22 `brownfield-comparison-cases` (FE-1241) — **✓ complete, learning-first:** frozen Brunch and Petrinaut packets, pinned-source preparation, deterministic oracles, publication-compatible attempt evidence, and portable CI are built. -- 2026-07-22 `comparison-publication-workflow` (FE-1251) — **✓ complete:** PR #364 landed immutable comparison provenance plus guarded, idempotent Comparison Reports publication and schema reconciliation. Older completion history and archived completed frontier definitions live in [`docs/archive/PLAN_HISTORY.md`](../docs/archive/PLAN_HISTORY.md). ### Next -- `system-reorientation-audit` ([FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift)) — evidence/disposition pass over the frozen cleanup, handover, documentation, legibility, presentation, and comparison/PTY concerns. Twelve rows are closed or promoted; the bounded `present_digest` guidance correction remains. Current execution pointer: [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). **Retires:** uncertainty about which current seams are canonical versus implemented-but-unwitnessed, intentionally distinct, superseded, or genuinely divergent. - `canonical-document-reconciliation` — earned closure over the exact normative-looking drift promoted by FE-1316: demote the unadopted PLAN-replacement prescription, archive/thin the enumerated superseded design notes, and correct comparison case/profile prose. Definition below. - `host-landing-oracle-identity` — close the immutable host-landing oracle pack over every behavior-bearing PTY input before its next comparison use. Definition below. - `saved-mission-comparison-witness` — later operator-owned frontier: FE-1215 is landed, so the remaining work is scheduling the real Brunch + Claude `/compare-specs` witness, then revising/rerunning the saved mission to prove historical snapshots remain immutable. Definition below. @@ -96,22 +94,6 @@ Legacy link target; see Horizon. -### system-reorientation-audit - -- **Name:** Current-system authority and drift audit -- **Linear:** [FE-1316](https://linear.app/hash/issue/FE-1316/audit-current-system-authority-and-drift) -- **Branch:** `ln/fe-1316-system-authority-audit`, stacked after FE-1311 because its closure state is an audit input. -- **Kind:** structural evidence/disposition frontier; not an implementation umbrella or alternate planning store. -- **Certainty:** proving. -- **Status:** audit complete; twelve rows are closed or promoted, with only the row-sized `present_digest` provider-guidance correction still partial. -- **Objective:** give every concern in the frozen post-cleanup inventory one evidence-backed current-state disposition and canonical owner. -- **Acceptance:** each row in the lane ledger reaches `closed` or `promoted`; alleged overlaps are classified as intentional, accidental, superseded, or unknown; factual handover drift is source-backed; promoted work has exactly one PLAN owner and no mirrored progress state remains in the ledger. Current close condition: correct and pin the stale `present_digest` provider guidance, then dispose the ledger. -- **Verification:** structural census against the user-provided concern set and both flyovers; targeted code/test/build/package/provenance checks only where they discriminate a row; final user review of the disposition map. -- **Depends on:** FE-1311 closure is satisfied; reuse the existing KA evidence queue, `capture-ledger-tracer`, `walkthrough-remediation-2`, and shared-session-host arc rather than duplicating them. -- **Current execution pointer:** [`memory/cards/system-reorientation-audit--lane-ledger.md`](cards/system-reorientation-audit--lane-ledger.md). -- **Promotion / disposal:** row-sized no-boundary corrections may close here; all implementation, witness, architecture, or independent doc cleanup promotes through `ln-plan`. Delete the ledger after every row is closed or promoted. -- **Traceability:** D140-L, A47-L; `docs/planning/planning-record-substrate-assessment.md`; `TESTING_FINDINGS.md`; current subtree topology homes. - ### canonical-document-reconciliation - **Name:** Reconcile canonical documentation with current topology @@ -251,17 +233,12 @@ active: -[stack]-> cli-mode-entry next: - system-reorientation-audit (FE-1316) - dependency_satisfied: integrity-cleanup closure - closes_next: bounded present_digest provider-guidance correction - disposes: frozen drift/overlap inventory -> closed | promoted to one PLAN owner - ledger: memory/cards/system-reorientation-audit--lane-ledger.md - -[hard]-> canonical-document-reconciliation - -[hard]-> host-landing-oracle-identity canonical-document-reconciliation + dependency_satisfied: FE-1316 disposition audit closes: FE-1316 R06 | R07 | R12 classification: buildable-now earned docs closure host-landing-oracle-identity + dependency_satisfied: FE-1316 disposition audit closes: FE-1316 R13 blocks: next retained host-landing comparison attempt saved-mission-comparison-witness diff --git a/memory/cards/system-reorientation-audit--lane-ledger.md b/memory/cards/system-reorientation-audit--lane-ledger.md deleted file mode 100644 index 1608aa220..000000000 --- a/memory/cards/system-reorientation-audit--lane-ledger.md +++ /dev/null @@ -1,137 +0,0 @@ -# Current-system reorientation audit - -Frontier: system-reorientation-audit -Status: active -Mode: single -Created: 2026-08-04 - -## Orientation - -- Containing seam: Brunch's current-state authority after FE-1311 and the July executor/comparison delivery burst. -- Frontier: `system-reorientation-audit` (FE-1316), stacked after `integrity-cleanup`; this card inventories and disposes concerns but implements no promoted fix. -- Posture: **proving** (inherited from `system-reorientation-audit`); the useful result is a trusted map of which concerns are live, already owned, obsolete, or worthy of promotion. -- Main risk: this ledger becoming a sixth planning store. It owns only the frozen concern inventory and evidence-backed disposition; `memory/PLAN.md` owns work and sequencing, while SPEC/topology own durable truth. - -## Target behavior - -Every concern in the frozen post-cleanup inventory has one evidence-backed current-state disposition and canonical owner. - -## Cold-start reads - -- `memory/PLAN.md` — frontier `system-reorientation-audit`, existing frontiers, KA evidence queue, and dependencies -- `memory/SPEC.md` — D140-L, A47-L, live tracing/evaluation decisions, and acknowledged blind spots -- `memory/POSTURE.md` — proving, free-rewrite, high-stakes boundary behavior -- `memory/cards/integrity-cleanup--closure-walkthrough.md` — preceding closed inventory and explicit exclusions -- `TESTING_FINDINGS.md` — Secure Drop SD1–SD9 and current walkthrough evidence -- `docs/planning/planning-record-substrate-assessment.md` — existing planning-substrate measurements and recommendation -- `docs/design/AGENT_TRACING.md` and `docs/design/WEB_UI_ARCHITECTURE.md` — tracing and shared-host current claims -- `src/dev/TOPOLOGY.md`, `src/executor/TOPOLOGY.md`, and relevant subtree topology files — materialized current state - -## Boundary - -In scope is the concern inventory below: cleanup safety, handover/evidence truth, planning/document authority, agent legibility, presentation/runtime authority, and comparison/PTY ownership. - -Out of scope: - -- implementing a finding; -- rerunning provider, Secure Drop, comparison, or human outer witnesses; -- rewriting Notion documents without an available Notion connection; -- changing the PTY driver merely to avoid oracle-pack identity churn; -- reopening FE-1311's closed inventory or adding inferred cleanup rows to it; -- replacing `memory/PLAN.md`, SPEC, topology files, Linear, or existing findings ledgers. - -A newly discovered concern may enter only when it is a missing member of one of the six frozen lanes and includes a one-line omission justification. More than one new concern stops the audit and routes back through `ln-plan`. - -## Lane charter - -| Lane | Question | Existing authority | Output | -| --- | --- | --- | --- | -| L0 · cleanup safety | Did FE-1311 remove or strand a required behavior? | FE-1311 commits, closure card, D140-L, tests/build/package checks | bounded keep/fix verdict; no new cleanup sweep by analogy | -| L1 · evidence and handover | Which merged mechanisms have current valid witnesses? | PLAN KA evidence queue, TESTING findings, comparison provenance, fixture sources | implementation/evidence split and corrected handover status | -| L2 · canonical truth | Which planning and design surfaces still duplicate or contradict current topology? | PLAN, SPEC, topology files, planning-substrate assessment | keep/thin/archive/promote disposition by canonical owner | -| L3 · agent legibility | What observation loop can judge prompt, skill, and context interventions? | capture-ledger frontier, trajectory tools, product prompts/skills | smallest usable feedback loop; bounded prompt defects routed separately | -| L4 · presentation authority | What remains implementation work versus outer evidence across TUI, themes, web, and session hosting? | FE-1187, shared-host arc, web/TUI topology | existing-frontier routing; no second GUI proof | -| L5 · comparison and PTY | Which comparison doors and terminal-control seams are canonical for each study shape? | comparison prompts/skills/runbooks, end-to-end contracts, `tui-driver` consumers | authority map and only behavior-justified follow-ups | - -Lanes may be investigated independently, but they do not become branches by default. A finding gets a Linear issue and Graphite branch only when `ln-plan` promotes it to a frontier. - -## Disposition ledger - -Status vocabulary: `new` → not yet evidenced; `partial` → evidence gathered, disposition not closed; `closed` → no follow-up; `promoted` → PLAN owns the follow-up. A promoted row carries no duplicate progress state here. - -| ID | Lane | Concern | Initial evidence | Canonical owner / likely route | Closure oracle | Status | -| --- | --- | --- | --- | --- | --- | --- | -| R01 | L0 | FE-1311's five-row closure remains the only admitted cleanup work | FE-1311 closeout in `docs/archive/PLAN_HISTORY.md`; current PLAN exclusion list | `integrity-cleanup` | every required row built and aggregate package/check/build oracles satisfied | closed | -| R02 | L0 | Required behavior may have been removed through an out-of-graph consumer blind spot | D140-L; FE-1311 deletion provenance; 123 focused tests; unchanged production tree since closeout | closed — no concrete broken or stranded behavior found | named consumer failure or clean current gates plus negative deletion provenance | closed | -| R03 | L1 | Notion handover status and fixture counts drift from current repository truth | Alpha 13 tag; Wisp 88/212; NullWire 61/143; SD9 | closed by source-backed correction report to the user; external Notion edit remains with its document owner | each disputed claim mapped to current file/tag/test evidence | closed | -| R04 | L1 | KA implementation claims are ahead of current valid outer witnesses | PLAN KA evidence queue; Secure Drop witness card; comparison report state | existing KA evidence queue; no umbrella executor frontier | every claimed outcome labeled implemented, witnessed-current, failed, or unknown | promoted | -| R05 | L1 | "Current test scenarios" spans several ledgers and mixes prepared scenarios with current evidence | walkthrough plan/findings; five missions; four execution cases; three E2E contracts; fixture READMEs | closed by role-specific inventory; do not create another status document | scenario availability, implementation coverage, and current valid witness are distinguished | closed | -| R06 | L2 | Mutable queue coordination and durable repository truth are carried by overlapping planning surfaces | planning assessment versus current PLAN/Linear/Graphite authority rules | `canonical-document-reconciliation` — demote the unadopted PLAN-replacement prescription | explicit owner matrix with no second live queue | promoted | -| R07 | L2 | SPEC, topology, design, praxis, cards, and findings duplicate or preserve superseded claims | exact stale/superseded design-note inventory; topology ownership rule | `canonical-document-reconciliation` — thin/archive only the enumerated documents | each named contradiction has one surviving canonical home and obsolete copies are thinned/archived | promoted | -| R08 | L3 | Existing trajectory capture does not yet form an operational agent-direction feedback loop | trajectory recorder/report/evaluator; prepared capture-ledger campaign; retired FE-1208 actor | existing `capture-ledger-tracer`; child spans remain trigger-gated | one controlled intervention loop links conduct evidence to a discriminating outcome judgment | promoted | -| R09 | L3 | Prompt/context guidance is repeated, overweight, and demonstrably capable of drift | provider-visible `present_digest` contradiction versus D110-L/runtime continuation | closed by bounded guidance correction and focused contract/runtime tests; broad optimization follows R08 evidence | tool guidance matches conversational feedback and later `acceptsDigest` capture authority | closed | -| R10 | L4 | TUI and web retain duplicate writable runtime authority | production composition roots; shared-session-host arc; A47-L | existing `shared-session-host-tracer` then cutover | one host owns runtime/JSONL/driver while both real presentations attach | promoted | -| R11 | L4 | Theme and TUI refinement appears active although implementation is largely complete | shipped themes; preview harness; FE-1187 consolidated outer checkpoint | existing `walkthrough-remediation-2` evidence route; no new theme frontier | implementation/evidence distinction recorded; outer checkpoint yields pass or a specific bounded failure | promoted | -| R12 | L5 | Elicitation, execution, and end-to-end comparison use several trees, prompts, adapters, and runbooks | authority matrix plus exact comparison-guide/case-count drift | `canonical-document-reconciliation`; retain the distinct study shapes | every entry point has one named purpose, authority, evidence contract, and supersession relation | promoted | -| R13 | L5 | `tui-driver` is fallback transport, automated oracle actuation, and part of immutable oracle identity | consumer census; host-landing pack omits behavior-bearing `keys.ts` and `driver.exp` | `host-landing-oracle-identity`; do not split PTY to hide recalibration | every behavior-bearing PTY input changes the oracle-pack hash; identical inputs remain stable | promoted | - -## Audit findings - -- **Cleanup safety:** no required runtime behavior was found removed or stranded. FE-1311's deleted tool, query-helper, schema-snapshot, renderer-dependency, and deterministic-minting paths all have negative consumer provenance or replacement coverage; current focused closure suites pass. R02 reopens only on a named behavior failure. -- **Evidence truth:** Alpha 13 is released, not being prepared. Wisp is 88 nodes / 212 edges and NullWire is 61 / 143. Secure Drop reached landing but remains failed outcome evidence under SD9. All six KA queue items are implementation-merged and outer-evidence-open. -- **Scenario roles:** walkthrough concerns, saved missions, execution cases, end-to-end contracts, seed fixtures, and retained runs are intentionally different strata. Their existence does not imply a current valid witness, so no new aggregate status store is warranted. -- **Canonical documents:** the planning-substrate assessment's PLAN-replacement recommendation is unadopted. `ELICITATION_QUESTIONS.md`, `ELICITATION_LENSES.md`, `STRUCTURED_EXCHANGE_COLLAPSE.md`, the superseded host notes, and parts of `REVIEW_SETS.md` preserve normative-looking retired language. The exact inventory routes to one bounded docs reconciliation, not a wholesale rewrite. -- **Legibility:** current trajectory machinery proves exposure/read/correlation, not causality. The prepared `capture-ledger-tracer` is the smallest controlled outcome loop. Child-span tracing remains gated on a concrete attribution failure. -- **Prompt authority:** one current provider-visible contradiction is proven: `src/.pi/extensions/exchanges/present-digest.ts` still prescribes approve/request-changes/reject and capture echoing, contrary to D110-L's conversational free-text continuation and later `acceptsDigest` carrier. R09 remains the one row-sized correction on this branch; no broad prompt rewrite is admitted. -- **Presentation:** duplicate TUI/web runtime authority is real at the two production composition roots and already belongs to the shared-host tracer/cutover. Theme implementation is materially present; its remaining work is FE-1187-owned outer evidence. -- **Comparison and PTY:** approachable elicitation, rigorous elicitation, execution comparison, and end-to-end composition are intentional study shapes. Documentation case counts have drifted. `tui-driver` is both fallback transport and automated oracle actuation; the host-landing hash currently omits behavior-bearing `keys.ts` and `driver.exp`, which requires identity closure rather than PTY decomposition. - -## Risks and assumptions - -- RISK: broad reading generates an unbounded issue list → MITIGATION: frozen lanes, one-new-row tripwire, and promotion rather than implementation. -- RISK: a row repeats status already owned by PLAN or a findings ledger → MITIGATION: link the owner, mark `promoted`, and stop mirroring progress. -- RISK: historical prose is treated as current authority → MITIGATION: current production topology and executable evidence outrank summaries; SPEC retains decision events only. -- ASSUMPTION: the user-provided concerns plus the two independent flyovers form a sufficient frozen audit input. - → IMPACT IF FALSE: the card is not a bounded audit and must be replanned rather than expanded indefinitely. - → VALIDATE: the one-new-row tripwire during lane review. - -## Posture check - -This proving frontier retires uncertainty about current authority and overlap. It lights no new runtime path and must not pretend to: its value is a falsifiable disposition map that prevents later build frontiers from preserving or reintroducing superseded paths. - -## Acceptance criteria - -- ✓ **Frozen inventory check** — every original user concern maps to at least one R-row, and no row is a miscellaneous catch-all. -- ✓ **Evidence check** — every row reaches `closed` or `promoted` with repository paths, executable output, provenance, or an explicitly named unavailable outer oracle. -- ✓ **Authority check** — every promoted row names one PLAN frontier; no row creates a parallel queue or mirrors that frontier's progress. -- ✓ **Drift check** — all factual disagreements between the pasted Notion handover and current repository evidence are listed with their current source. -- ✓ **Overlap check** — each alleged duplicate receives `intentional`, `accidental`, `superseded`, or `unknown`, with the discriminating reason. -- ✓ **Disposal check** — once all rows are `closed` or `promoted`, `ln-sync` deletes this card after reconciling its promoted frontier references into PLAN. - -## Verification approach - -- Inner: structural row census and repository searches — prove completeness against the frozen input and bind claims to sources. -- Middle: targeted tests, builds, package inspection, semantic dependency analysis, and git provenance only where they discriminate a row. -- Outer: user review of the final disposition map; unavailable Notion edits and model/browser witnesses remain with their existing named owners and re-entry triggers. - -## Cross-cutting obligations - -- FE-1311's closed-inventory rule remains intact. -- Current topology lives in `src/**/TOPOLOGY.md`; SPEC owns decisions/events, not a duplicate current-state copy. -- Implementation evidence and outer outcome evidence remain separate statuses. -- Comparison evidence stays target-neutral; Brunch-only traces are diagnostic. -- Oracle-pack identity changes when oracle behavior changes; architecture must not be split merely to conceal that change. - -## Expected touched paths (tentative) - -```text -memory/ -├── PLAN.md ~ -└── cards/system-reorientation-audit--lane-ledger.md ~ -``` - -## Promotion and disposal - -A row-sized correction may close in place only when it changes no durable boundary and belongs on this frontier branch. Any implementation, witness campaign, architecture decision, or independent documentation cleanup is promoted through `ln-plan` to an existing or new frontier. `promoted` is terminal here: PLAN owns all later status. - -Delete this card in the first `ln-sync` after every row is `closed` or `promoted`; do not archive its live-status table or preserve it as a permanent handover document.