Skip to content

Self-hosting phase 3: the executable-specs rewrite — 27 bound points, 51 Specs ready, and the first concept-doc dissolutions - #12

Merged
darko-mijic merged 23 commits into
mainfrom
feature/protocol-self-application-phase-3
Jul 26, 2026
Merged

Self-hosting phase 3: the executable-specs rewrite — 27 bound points, 51 Specs ready, and the first concept-doc dissolutions#12
darko-mijic merged 23 commits into
mainfrom
feature/protocol-self-application-phase-3

Conversation

@darko-mijic

@darko-mijic darko-mijic commented Jul 26, 2026

Copy link
Copy Markdown
Contributor

What this is

Phase 2 ended with a named backlog: the tests-to-executable-specs rewrite ("the big one"), readiness maturation of a corpus sitting honestly at 51 defined, and the first per-doc concept deletions under the dissolution decision. This phase is that backlog executed. The Protocol's own laws now verify themselves the way the product says laws should be verified: authored example Specs binding points in their parents' example spaces, generated contracts, and test handlers earning has-verifier in the graph — not a green runner merely claiming it. On that verification layer, readiness matured from 7 ready / 51 defined to 51 ready / 36 defined with zero decorative promotions, and the first two concept docs — 02 — Core Model and 03 — The One Graph — were deleted, their semantic contracts fully carried by the Specs that dissolved them.

The phase ran as six sequential sessions (S1–S6) on plan 20 (plans/20-self-hosting-phase-3.md, now ✅ EXECUTED), each closing on a fully green twelve-leg npm run check. It was closed by an archived adversarial review (reviews/09) whose central method was mutation testing rather than code reading, and — because this branch ran autonomously — a second, independent four-dimension review before this PR, whose accepted findings are already fixed on the branch.

What landed

Fifteen laws became bound executable points — 27 new example Specs. Three conversion tranches (the whole validation family in S1; the extraction, model, and carrier cheap wins in S2; three previously uncovered engine areas in S3) plus two more laws the readiness sweep converted on law-shape in S4. Each point is an immediate gwt example bound through a generated step contract to a specTest anchor, so spec-side drift is a compile error and the verifies edge carries the anchored claim. The corpus now holds 29 bound points (these 27 plus the two phase-2 tracers) across five bound suites. Worlds are built to the phase's own discipline — construct the state so the law under test is the only thing that can refuse — and they run real seams: validateGraph, parseSlots, discoverFiles, generateContracts, planExample/runExamplePlan, and full temp-dir extractions with symlinked builder modules.

Two new Specs and three enrichments carried laws nothing held. spec:extraction.example-runner (the runner core: authored step order, one handler per repeated step, the red step that names itself in the Spec's own words) and spec:carrier.slot-notation (the four slot forms and the refused guess) are new, each bound by its own impl: anchor. spec:extraction.executable-contracts, spec:carrier.envelope-contract, and spec:carrier.prose-ownership-rule were enriched from stubs into acceptance-grade Specs before any promotion touched them. The corpus grew 58 → 87 Specs.

Readiness matured only where a verifier honestly landed. The distribution moved in four steps, each riding its own wave's verifiers (24/45 → 34/41 → 44/40 → 51/36), and every one of the 51 ready Specs carries has-verifier in the graph. Just as deliberate: the S4 sweep dispositioned all 40 then-defined Specs per-Spec and recorded 36 honest refusals with named reasons — the epic, all 21 decision Specs, and every Spec whose only available verifier would have been decorative (whole-pipeline worlds, measured-evidence claims, the clean-room rebuild that is the close's own proof). implemented ∧ ¬ready stays a drift alarm precisely because nobody inflated ready.

Two concept docs deleted, three kept — on per-doc audits, not a purge. Five audits to the plan's template, judged over the regenerated Design Review under the dissolution decision's criterion (one uncarried law blocks deletion). 02-core-model.md and 03-the-one-graph.md were fully carried and deleted, with the D1/D2 registry rows re-pointed at their carrying Specs and a two-form reference sweep (backticked and bare citation spellings) re-run to zero hits. 05, 06, and 07 stay, with twelve precise gaps recorded as future corpus work instead of papered over — notably 07, whose "superseded" docket row turned out on honest reading to be a doc-repair note, not a deletion warrant. The per-doc audit beat the bulk prediction in both directions: the doc predicted easiest to delete survived, and 03 — predicted blocked — turned out fully carried.

The adversarial close mutation-tested the phase's central claim. reviews/09 broke a sandbox copy of the engine one law at a time — 37 mutations — and re-ran the new points after each: 26 of 27 went red for the law they name, and the 27th (the concreteness point, P-1) was restructured so the law under test is the only gate that can fire, then re-probed both ways. Four majors, no blockers, all fifteen findings dispositioned in the archived table. Two majors closed the honest way — by making the graded verdicts true: the ready-rung floor clauses and the reserved-namespace set (with the doc: deferral stated as a deferral) now live in the Specs that were credited with carrying them.

The clean-clone proof caught a real gate hole. The close includes a git clone --no-localnpm ci → full npm run check run at the close SHA. Its first run failed at the lint leg and exposed something no developed checkout could: the clean-room contract lint exemption had never been extended past the two bound suites that existed when it was written. Fixed, re-committed, re-cloned green — the clone reproduced the same graph numbers, test counts, and a clean preflight, which is the determinism claim proved rather than asserted.

Nothing weakened along the way. No test file was deleted, no residual suite lost a case, no exact matcher was loosened; the golden oracle grew by transcription only (one non-discriminating bound Then step was removed at S6, on the record). All five syntax watch items closed unfired with reasons — no table sugar, no single-literal vocabulary form, no multi-entry constraint form was ever forced by real material. All eight docket rows carried forward, each with a stated reason instead of rolling silently; two gained substance (the temporal-guard row now names the decision it waits on, and the oracle-granularity row carries the 3,888-line measurement that will justify the session that splits it).

The pre-PR review, closed on the branch

Because the phase ran autonomously, a second independent review preceded this PR — four parallel passes over the full branch: a records-honesty audit that recomputed every headline number from scratch, a repo-wide dangling-reference sweep after the deletions, a spec-quality pass comparing all 27 children word-for-word against their parents' vocabularies and the implementation, and an engine/test diff review.

Verdict: no blockers, no majors. Every claimed figure survived independent recomputation — including the intermediate readiness distribution at each session's commit. The sweep found zero dangling references from the deletions; the only broken links in the repo are two pre-existing clusters already on main (archived plan-18a evidence links and fixture-relative Design Review links). The accepted minors are fixed in the branch's final commit: the split-report example's Intent now names the readiness-floor error its own probe co-trips; the stable-ids law states that path segments admit mixed case (the clause the case-colliding example already depended on); the schema-version literal's second authored home is pinned in the prose-schema audit so a bump names both surfaces; the never-bound builder-trust branch names its regression home; the checkout-v1 README rows for the dissolved docs are re-pointed at the carrying Specs instead of dropped; and a spelling drift is repaired. One naming nit (lookalike-refusal describing silent non-minting) is declined — renaming a landed stable ID for a naming nit works against the stable-ids law itself. One minor (the red-step example's failureLabel binding a when-step text its Givens don't pin) is deferred with its reason recorded: the fix is a vocabulary change that thrashes the golden oracle, which the successor guidance explicitly orders behind the oracle-split session; the point's mutation-sensitivity is already proven.

Verification

  • npm run check green on the full twelve-leg chain — in the working checkout throughout all six sessions, and again on a fresh git clone --no-local clone (npm ci, the whole chain) at the close SHA, reproducing identical numbers.
  • The self-hosting graph at close: 87 Specs · 1 Pack · 65 anchors → 153 nodes · 294 edges, 0 errors · 0 warnings. Kind mix: 29 example · 21 decision · 14 rule · 12 behavior · 8 model · 1 contract · 1 workflow · 1 constraint.
  • Readiness: 51 ready / 36 defined (zero idea/scoped), every ready Spec backed by a resolving verifier in the graph, zero honesty/gaps warnings.
  • The suite: 559 tests across 41 files (505 in the parallel pool, 54 in the dedicated CLI process), zero skipped on this platform. The pre-PR audit verified "no assertion deleted" at the diff level: the only removed expect lines are count-literal updates in the golden oracle (58→87, 95→153, 180→294), and modified residual tests changed comments only or got stricter.
  • The adversarial review is archived at reviews/09-self-hosting-phase-3-pre-close-review.md with all 15 findings dispositioned; the mutation matrix covered 37 engine mutations against the 27 new points.
  • A post-close records amendment (external review feedback) is folded into plan 20 — the example-Spec count precisely stated, ruling 7 narrowed to the guard's enforced law, the tests claim made exact, and the glossary widened on the record where the landed corpus outran it.

A note on ratification, per the plan's own honesty rule: this phase ran autonomously — no live owner gate occurred during execution. The plan's gate ledger records that owner ratification happens at this PR review. Two items deserve a conscious yes: the S5/S6 deletions of 02 and 03 (the audits and reference sweeps are in the plan's §7), and the two lean glossary entries added at the pre-PR review — world and probe — which name vocabulary the 27 bound points and the plan's own rulings already lean on but which had no ratified standing.

What remains for full self-hosting

The thesis has now been applied to the cheap half of itself; what remains is ordered and recorded in plan 20's successor guidance:

  1. Split the golden oracle first. test/self-hosting-graph.test.ts stands at 3,888 lines in a single it() with frozen absolute counts — the first failure masks the rest. The recorded ruling: a single-purpose split session (by family or histogram bucket, never one mega-assert) before any new conversion wave thrashes it again. The deferred red-step vocabulary refinement from the pre-PR review rides behind this.
  2. The next corpus wave, in gap order. Twelve recorded gaps from the S5 audits, ordered for maximum dissolution pressure: (a) the lower readiness-floor rungs and the per-kind evidence table — the biggest single gap holding 05 in place; (b) the derived-readiness banner law, one gap shared by 05/06/07; (c) the already-implemented-but-uncarried view rules (the implemented view label, the one diagnostic rendering rule, Design Review's wholesale page rewrite). Each Spec authored there is a step toward the remaining three concept docs dissolving on their own audits.
  3. The conversion playbook inherits the P-1 lesson. Build worlds where only the named law can refuse; mutation-probe before recording "exercises clause X"; never use absence-of-a-finding-id as the sole discriminator. And one structural hardening: derive the clean-room lint exemption list and vitest-test.mjs's dependency table from one shared constant, or the seventh bound suite will repeat the clean-clone lint surprise.
  4. The readiness tail is honest, not lazy. The 36 defined Specs refused promotion for named reasons — mostly whole-pipeline worlds (the CLI pipeline, the reader over a full graph fixture, projection rendering) and the 21 decisions. They mature as the verification layer grows the machinery to make their verifiers non-decorative, not by fiat.
  5. The deferred docket tail, each row with its reason on file: the Markdown Pack syntax ruling (the pack manifest absorbed 29 new members as TS with no friction — no caller has forced it); the gen-1 .feature import adapter; the no-reparse read seam; the temporal-guard token assembly; the editor-association gap; control-character latitude; and the separate example-id namespace (29 example Specs authored under the existing convention with zero collisions — a watch, not a want).

https://claude.ai/code/session_01F2XoLBFBJoCBdb4zvoP5X1

Greptile Summary

The PR rewrites self-hosting verification around generated executable-spec contracts.

  • Adds 27 bound example Specs and five self-hosting test suites covering validation, extraction, model, carrier, and runner laws.
  • Promotes verified Specs to ready, expands the self-hosting pack, and updates generated-contract scheduling and lint configuration.
  • Deletes the dissolved core-model and one-graph concept documents and redirects operative references to their carrying Specs.

Confidence Score: 5/5

The PR appears safe to merge; no concrete changed-code defect or security-boundary failure was identified.

The changes cover generated-contract imports, executable-spec scheduling, lint configuration, and concept-document reference redirects.

Files Needing Attention: Generated-contract imports are covered by the updated scheduling and lint configuration, deleted concept-document references are cleanly redirected, and the scanner-reported dynamic test lookup is limited to maintainer-authored closed-union values.

T-Rex T-Rex Logs

What T-Rex did

  • Reviewed the general contract validation, confirming the full captured command output and associated preflight results, including the run directory, exit status, regeneration output, test summaries, graph validation summaries, and a clean semantic diff.

View all artifacts

T-Rex Ran code and verified through T-Rex

Important Files Changed

Filename Overview
specs/self-hosting.pack.sdp.ts Adds the new executable example Specs to the self-hosting aggregate.
test/self-hosting-carrier.test.ts Adds bound carrier-parity and slot-notation executable examples.
test/self-hosting-extraction.test.ts Adds bound extraction, contract-generation, schema-version, and runner examples.
test/self-hosting-model.test.ts Adds bound stable-ID and anchor-trust examples; its dynamic setup selection is constrained to authored closed-union contract values.
test/self-hosting-validators.test.ts Adds probe-graph executable examples for the validation laws.
vitest-test.mjs Registers every newly generated-contract-dependent suite in the test preflight and scheduling table.
eslint.config.js Extends clean-checkout lint handling to all suites whose generated contracts do not yet exist at lint time.
check-carrier-rule.mjs Repoints the carrier consistency gate from the deleted concept document to the carrying envelope Spec.
check-prose-schema.mjs Repoints prose and schema consistency checks to the Specs that now carry the dissolved documents' contracts.
docs/concept/02-core-model.md Deletes the concept document after its operative contracts and references move to authored Specs.
docs/concept/03-the-one-graph.md Deletes the concept document after graph contracts and operative references move to authored Specs.

Flowchart

%%{init: {'theme': 'neutral'}}%%
flowchart LR
A[Authored parent and example Specs] --> B[Extract one graph]
B --> C[Generate typed step contracts]
C --> D[Bound self-hosting test suites]
D --> E[Run handlers against probe worlds]
E --> F[Verifier anchors in graph]
F --> G[Ready Specs with has-verifier]
B --> H[Validation and projections]
Loading

Reviews (1): Last reviewed commit: "docs(specs,tests): land the pre-PR revie..." | Re-trigger Greptile

The executable-specs rewrite waves, the readiness promotion law, and the
first per-doc concept-dissolution audits, with rulings, ledgers, and
acceptance criteria drawn from the phase-2 close.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…oints

The orphan and gap signals now carry an authored `## Example space` on the
rule parent plus two `example`-kind children binding one fully-typed point
each: a disconnected spec (orphan warning, zero errors) and a connected
ready spec no verifier resolves (gap warning, zero errors).

The bound handlers live in a dedicated `test/self-hosting-validators.test.ts`
rather than inside `test/validators.test.ts`: importing the package specifier
into the existing suite turns on anchor scanning for the whole file, and its
inline fixture `specTest(...)` calls then raise `extract/misplaced-authoring`
warnings the corpus must not carry. The plain-vitest suite stays untouched as
regression evidence.

Both children and the promoted parent earn `has-verifier` through the
executable path; the parent clears the ready floor with a resolving verifier,
so the promotion introduces no `honesty/gaps` warning.

The wrapper's contract-dependency table becomes one row per generated tree
with a list of dependent test files, so a second self-hosting suite cannot
duplicate the recovery command the missing-tree message states.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…aws to bound points

Referential integrity gains an example space over one spec and one dependsOn
target, with two points: an unrelated missing target (a bare conformance
error) and a unique near miss (the did-you-mean suggestion). The suggestion
law was implicit in the validator and is now stated as a rule on the spec.

Authored honesty gains an example space over the two smuggling routes its
entrypoints police: a delivery fact hand-authored into a behavior section
carrier (authoring-shape) and a stated fact no binding earns (delivery-facts).

Both parents clear the ready floor and earn `has-verifier` through the
executable path, so both promotions introduce no `honesty/gaps` warning. The
plain-vitest suites and the graph-validator fixture corpus stay untouched as
regression evidence.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…pack laws

Claim separation gains an example space over the off-contract shapes a foreign
graph producer can hand the seam, with two points: a satisfies edge borrowing
the declared claim (the taxonomy never collapses) and an unratified specKind
(the descriptor error stands and no readiness floor is evaluated over it).

Verification linkage gains an example space over the two non-resolving traces
its entrypoints police: a declared verifier no test anchor binds, and an
oracle whose modelled spec owns no example space. Both points assert that the
parent earns no `has-verifier`, so "confers nothing" is executable truth.

Pack coherence gains its first real probe — one aggregate that repeats a
member and names a non-model modelRef, so both halves of the law fire on the
same graph. The validator's behavior matched the spec's stated law; each
parent gains the mechanism sentence its bound point needs to be readable.

All five parents clear the ready floor with a resolving verifier.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…lings

Flips the six S1 conversion-ledger rows to done with their bound point
counts, closes the S1 session-ledger row, and logs the five rulings the wave
made under fire: the dedicated bound-example suite forced by the anchor
scanner's file-level gate, the per-tree wrapper dependency table, the
exercised rule-kind Example space, the three unstated laws promoted into spec
text from ratified concept material, and the readiness promotions.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…s to bound points

Author `## Example space` vocabularies on `spec:extraction.excludes`,
`spec:extraction.schema-versioning`, `spec:model.stable-ids`, and
`spec:carrier.markdown-parser`, and bind six example children through
`bindExample` in three dedicated self-hosting suites. Each parent gains one
mechanism line naming its realizing entrypoint so the vocabulary reads against
stated intent.

The four parents and their six children promote to `ready`: every floor clears,
each child carries a resolving verifier through its `specTest` anchor, each
parent earns `has-verifier` from its enabled example, and the corpus introduces
no `honesty/gaps` warning (0 errors, 0 warnings over 75 specs).

The plain-vitest suites (`exclude-diagnostics`, `graph-schema`, `ids`,
`extract-parity`) stay whole as regression evidence — a law is converted, never
a table row.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
Flip the four S2 conversion-ledger rows to done with their actual point counts,
append the S2 rulings-under-fire entries (three dedicated suites, a behavior
parent owning an Example space beside its verification section, partial points
for refusal-versus-success siblings, the no-drift finding, and the readiness
promotions), and close the S2 session-ledger row.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…ound points

Grow the self-hosting corpus for three engine areas no spec covered, and bind
each law's points through the executable path:

- new `spec:extraction.example-runner` (behavior/feature) over the
  framework-neutral runner core, anchored at `planExample`/`runExamplePlan`,
  with the step-order and red-step-naming points;
- new `spec:carrier.slot-notation` (rule/story) over the owned slot
  micro-notation, anchored at `parseSlots`/`stepSkeleton`, with the
  typed-declaration and refused-guess points;
- `spec:extraction.executable-contracts` enriched with the concreteness law,
  the one-point law, the loud-degradation and withholding posture, and an
  Example space carrying the concreteness-refusal, multi-entry-example, and
  case-colliding-path points.

The bound handlers join the existing per-family suites; the plain-vitest
suites (`test/codegen.test.ts`, `test/runner.test.ts`, `test/notation.test.ts`)
survive whole as regression evidence. The corpus stands at 84 specs, 0 errors
and 0 warnings, `defined: 40 / ready: 44`.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…e-3 plan

Flip the three S3 conversion-ledger rows to done with their confirmed spec IDs
and point counts, append the S3 rulings-under-fire entries (suite placement,
the two new source anchors, the silent inline authoring builders, the two
notation-bounded vocabulary shapes, the no-drift finding, and the promotion
sweep), and close the S3 session-ledger row.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…ns it

The tranche-2 readiness sweep. Every remaining `defined` spec was judged
against the promotion law — the `ready` floor clears, a resolving verifier
exists so the promotion adds no `honesty/gaps` warning, and the content is
honestly acceptance-grade. Promotion is per-spec judgment, never a quota:
most decision and expository specs stay `defined`, honestly.

Two carrier specs already carried anchored verifiers and were promoted only
after enrichment in place, because the one-line stubs they were could not
honestly carry `ready`:

- `spec:carrier.envelope-contract` gains the closed-key-set law, the explicit
  `relations: {}` carrier rule, the derived-name refusal, and the owned
  grammar's bounded-refusal posture — every clause from ratified intent.
- `spec:carrier.prose-ownership-rule` gains the singular-section description
  owner, the constraints-array exception, and the graph-content-not-file-
  pointer rule.

Two laws were converted under the four-artifact template so their promotions
are earned through the executable path rather than asserted:

- `spec:model.anchors` — builder trust is physical module identity. Points
  `lookalike-refusal` (a consumer-local lookalike mints nothing and says
  nothing) and `physical-identity` (a deep relative import resolving to this
  package's builder modules is trusted), bound in
  `test/self-hosting-model.test.ts`.
- `spec:validation.two-check-families` — the family split. Point
  `split-report` runs one probe graph that trips a conformance error and an
  informative honesty signal at once, and pins the aggregate report claiming
  neither family as its own; bound in `test/self-hosting-validators.test.ts`.

`test/anchor-trust.test.ts` and `test/validators.test.ts` stay whole as
regression evidence — a law is converted, never a table row. No drift was
found: every clause the points exercise held as authored, no code moved, and
no claim was widened.

The corpus closes at 87 specs, `defined: 36 / ready: 51`, 0 errors and
0 warnings; the frozen carrier fixtures and the golden oracle move with the
enrichment.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…t row

Appends the S4 entry to plan 20's rulings-under-fire running log — enrichment
precedes promotion or the promotion does not happen; a `model`-kind parent may
own an Example space (ruling 2 on a fourth kind); the second-tier model
candidates refused on ruling 1 rather than on budget; the epic and all 21
decision specs recorded as honest `defined` — and carries the full per-spec
disposition ledger for every spec that stood at `defined` when the session
opened. Repoints §2 at the ledger's actual home and closes the §10 S4 row.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
The structural-decision shorthand still named `02` §2/§3 as canonical for
"readiness is separate from delivery facts" and "sections are typed to their
evidence role". Both laws are carried by executable Specs — the core-model
spec and the spec-sections spec — so the registry now reads by name to the
carrying Spec, exactly as D3, D5, and D6 already do.

This is the pre-repair the per-doc dissolution audit of `02` requires: the
lean registry must not point at a doc the audit may delete.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
Audit basis (plan 20 §7, the per-doc dissolution audit table): every section
of `03` maps to a carrying Spec or registry, judged over the regenerated
Design Review.

- §1 derivation + the edge contract → `spec:extraction.derive-graph` (one
  seam · flat typed arrays · Primitive-to-Primitive declared relations ·
  anchor-derived `satisfies`/`verifies` · computed delivery facts · advisory
  inferred edges), with the endpoint contracts on
  `spec:validation.claim-separation` and the per-edge severities on the
  validation family.
- §2 determinism → `spec:extraction.determinism` (sort order · excluded
  wall-clock/hash metadata · `--check-clean` · the two static-reification
  tiers and the per-carrier asymmetry).
- §3 the claim taxonomy → `spec:extraction.claim-taxonomy` (declared ·
  anchored · inferred · claim inheritance · delivery fact) with
  `spec:validation.claim-separation` and `spec:validation.duplicate-ids`.
- §4 regenerability and the no-second-store rule →
  `spec:extraction.regenerability`, clause for clause.
- §5 git is the event log → the `spec:extraction.derive-graph` narrative
  (current projection · removed means gone · `supersedes` the one forward
  pointer) plus `spec:model.stable-ids` and founding principle 5 in `01`.
- §6 schema versioning → `spec:extraction.schema-versioning`.

The graph JSON payload sample, the derivation diagram, and the graph-diff
paragraph are expository representations of `src/graph/schema.ts` and of the
determinism law; they carried no law of their own.

Reference sweep in the same commit: `CONTEXT.md` glossary pointers, `AGENTS.md`,
`docs/concept/README.md`, `01`, `05`, `06`, `07`, the JTBD stories, the checkout
walkthrough, `src/` and `test/` comments, and the audit maps in
`check-carrier-truth.mjs` (3 claims + 5 classification rules retired with the
doc) and `check-prose-schema.mjs` (the constraint-omission pin re-pointed to
`spec:carrier.prose-ownership-rule`; the schema-version pin re-pointed to
`spec:extraction.schema-versioning` beside the existing `src/graph/schema.ts`
literal pin).

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
Audit basis (plan 20 §7, the per-doc dissolution audit table): all six
sections of `02` map to carrying Specs and the ratified glossary, judged over
the regenerated Design Review.

- §1 the `Spec` primitive → `spec:model.core-model` (Spec · envelope · kind ·
  altitude · readiness · delivery fact) with `spec:decisions.one-primitive`;
  the carrier note is `spec:carrier.envelope-contract`'s explicit
  `relations: {}` clause; the TS type block is a representation of
  `src/model/spec.ts`.
- §2 the three descriptors → `spec:model.core-model` plus the glossary's
  locked descriptor values and delivery-fact table (with the payoff queries);
  the liveness ladder is `spec:decisions.binding-not-liveness`, and fact
  derivation is `spec:extraction.derive-graph`.
- §3 sections → `spec:model.spec-sections`, `spec:decisions.typing-law`,
  `spec:decisions.content-only-sections`, `spec:carrier.prose-ownership-rule`
  (narrative · the singular-section description owner · the constraints
  exception) and the typed shapes in `src/model/sections.ts`; the rejected
  `decision.status` field is in the glossary's term ledger; the verifier
  semantics are `spec:model.spec-sections`'s `verifies` and enabled-verifier
  terms.
- §4 `Pack` → `spec:model.pack-aggregate`, `spec:decisions.pack-reified`,
  `spec:validation.pack-coherence`.
- §5 stable IDs → `spec:model.stable-ids` (ready, two bound points) with the
  namespace set in `src/ids.ts`.
- §6 relations → `spec:model.relations` and the glossary's relations table
  (directions · UML anchors · derived-never-authored · the dropped
  `exemplifies`); the `doc:`-target deferral is
  `spec:decisions.carried-evidence`; the kind-typed endpoints are
  `spec:validation.claim-separation`.

The worked enrich-in-place examples are expository narrative; the law they
narrate is carried above.

Reference sweep in the same commit: the glossary's five section pointers and
the MD-16 note, `AGENTS.md`, `docs/concept/README.md`, `01`, `04`, `05`, `06`,
every JTBD reference line, the checkout walkthrough, `src/` and `test/`
comments (including two validator diagnostics that named the doc), and the
audit maps in `check-prose-schema.mjs` (narrative ownership re-pointed to
`spec:carrier.prose-ownership-rule`) and `check-carrier-rule.mjs` (the
logical/physical relations distinction re-pointed to
`spec:carrier.envelope-contract`, which states the same law in its own
authored words while JS-A1 keeps the verbatim sentence).

The registry pre-repair this deletion required landed first: D1 and D2 now
point at `spec:model.core-model` and `spec:model.spec-sections`.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
Plan 20 §7 now carries one audit table per candidate doc, built to the §4
template and judged over the regenerated Design Review: `02` and `03` are
fully carried and were deleted; `05`, `06`, and `07` carry gaps and stay.

Also recorded: the eleven gaps carried out of S5 as future corpus work (the
readiness-floor clause tables, the derived-readiness banner rule, the
`implemented` view-label rule, the diagnostic rendering rule, validator
self-testing, Design Review's wholesale rewrite, the discipline mapping, the
impact-graph assist roles and `bySymbol` shape, the per-PR preview, two open
questions, and the measure-what-hurts heuristic); the per-deletion reference
sweep inventories; five §6 rulings under fire (audit-map re-pointing, the
expository-against-a-surviving-doc rule, the reconciled `03` §5 prediction,
why `07` is not deletable on supersession, and the no-drift/no-Spec-edit
record); and the §10 S5 row.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…riers the audits named

The pre-close adversarial review found one bound point that stayed green with the
law it names deleted, and three dissolution-record defects. This change repairs the
corpus side of all four.

- The concreteness point ran under a parent that owns an example space, so both the
  concreteness law and vocabulary resolution withheld the step contract and the point
  could not tell them apart. Its parent now offers a second Given — a parent that
  declares no shared vocabulary — and the point uses it, so the vocabulary gate is
  structurally absent and only the concreteness law can withhold. Re-probed: deleting
  the unbound-slot refusal turns the point red (and only that point); disabling the
  vocabulary gate leaves it green, which is honest, because it does not name that law.
- `spec:extraction.executable-contracts` states the concreteness law's scope: it reads
  the example's own form, so it refuses with or without a parent vocabulary.
- The schema-version point drops its second Then step: comparing the serialized payload
  against the engine's own exported constant moves both sides together under every
  mutation, so it read as coverage it never provided. The authored `"0.4.0"` literal
  catches the same failure strictly harder.
- `spec:validation.readiness-floor` gains the `ready` floor's three clauses and the
  vacuous-anchor reading, so the edge contract's readiness-effect law rests on a Spec
  rather than on a surviving concept doc plus validator source.
- `spec:validation.verification-linkage` gains the one-oracle-per-space clause.
- `spec:model.stable-ids` gains the reserved-namespace set per binding direction and the
  `doc:` reservation with its actual status — a named deferral no builder mints.
- `spec:decisions.concept-docs-dissolve` restates its consequence in timeless language.
- `docs/concept/04` repairs the last bare `02 §3` citation; the wider sweep (bare and
  fenced forms across every tracked non-exempt file) now returns nothing.
- The runner anchor no longer orphans `planExample`'s doc comment, and two
  `check-carrier-rule.mjs` comments stop naming a dissolved doc and stop claiming
  verbatim sameness where the check proves co-presence.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…the falsified records

Fills the review's disposition column — four majors fixed, eleven minors fixed,
record-corrected, accepted, or carried with a stated reason — and adds the remediation
addendum in the reviews/07-08 convention.

The plan's own record is corrected where the review falsified it: §6 S3 ruling 5 no
longer lists the concreteness refusal among the clauses its points exercised; §6 S1
ruling 4 separates the ratified did-you-mean suggestion from the tie rule this phase
derived; §6 S5 ruling 3 and the `03` §5 audit row attribute the narrative carriage to
phase 2 on `main`. Four audit-row citations now name surfaces that carry what the row
says, the `06` §1 row is re-verdicted from `carried` to a partial gap, the carried-gap
list gains item 12 and narrows item 1 to the three lower floor rungs, and the reference
sweep is restated as it must be run — both citation forms, re-run with zero hits.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
… executed status

Writes the terminal records the close owes and flips the plan's status header from
DRAFTED to EXECUTED, keeping the mandated reading rule.

- §5 gains a terminal-state column: no watch item fired in six sessions, and each of
  the five now records why rather than merely that.
- §6 gains the S6 rulings log — the point made honest by removing the competing gate
  from its world rather than asserting around it, the tautological Then step removed
  rather than ratified, the two audit rows made true by enrichment rather than
  retraction, and ruling 7 enforced on the one Spec that carried a session handle.
- §7 gains the executed-delivery record, the three ledgers' terminal states, the
  amended gap list, the review-and-remediation summary, the docket-close table with a
  reason on every one of the eight carried rows, and the close evidence.
- §9 grades all seven acceptance criteria: 1, 2, 3, 6 PASS; 4, 5, 7 PASS after
  remediation, with what changed named against the review's PARTIAL grades.
- §10 closes S6.
- The handbook's status sentence records the phase-3 executed state and what remains.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…lf-hosting suite

The close's clean-clone proof failed at the lint leg with 27 no-unsafe-* errors: lint
runs before generate:self-hosting, so in a room with no generated/ the bound suites'
contract imports resolve to nothing and every bindExample call reads as an unsafe
call. The exemption for exactly this case already existed, scoped by an explicit
two-file list written when only two bound suites existed; the five suites added this
phase were never added to it, and no developed checkout could reveal the omission
because generated/ is always present there.

The list now names all six suites that import generated/contracts/ — the bound-suite
half of the wrapper's root contract-dependency row — and stays an explicit list rather
than a glob, so the corpus oracle and the contracts self-check, which derive in
memory, keep full lint strength. Recorded as an S6 ruling.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
The clean clone at the close commit reproduces the whole gate: same graph counts, same
zero-finding corpus, same test totals, clean preflight, empty status. The first clone
run is recorded too, because it is the reason the leg exists — it failed at lint and
exposed a clean-room hole no developed checkout could show.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…l review

The example-spec count (27 new / 29 corpus), the S5-vs-S6 gap-count
alignment, the tip-inventory line, and the precise tests claim. The
example-space glossary entry widens on the record to match ruling 2 and
the landed corpus; ruling 7 narrows to the guard's enforced token list
with the widen-vs-narrow choice decided on the docket row. Successor-plan
guidance recorded: oracle split first, the P-1 conversion playbook, one
source of truth for contract-dependent suite lists, and the gap order
that buys the most dissolution.

Claude-Session: https://claude.ai/code/session_01SoBtqnPU6EQrd1tgrUdxcw
…close

An independent four-dimension review of the closed branch (records honesty,
reference sweep, spec quality, engine/test diff) found no blockers or majors;
these are its accepted minors and nits, each paired with its oracle
transcription line where the prose is pinned:

- the split-report example's Intent now names the readiness-floor error its
  own probe necessarily co-trips, so the containment reading is stated
- the stable-ids grammar law now states that path segments admit mixed case
  (case binds only on the namespace) — the clause the case-colliding
  example already depended on
- the schema-version literal's second authored home (the declared-version
  example's bound slot) is pinned in check-prose-schema.mjs so a version
  bump names both surfaces
- the never-bound "published Protocol package" world branch carries the
  comment naming its regression home (test/anchor-trust.test.ts)
- the checkout-v1 README's where-to-look rows for the dissolved docs are
  re-pointed at the carrying Specs instead of silently dropped
- "modelled" → "modeled" per the glossary's spelling
- CONTEXT.md gains lean "world" and "probe" entries — both terms carry load
  across the 27 new bound points and plan 20's own rulings but had no
  glossary standing; flagged for ratification at the phase PR review

Claude-Session: https://claude.ai/code/session_01F2XoLBFBJoCBdb4zvoP5X1
@darko-mijic
darko-mijic merged commit 3474658 into main Jul 26, 2026
3 checks passed
@darko-mijic
darko-mijic deleted the feature/protocol-self-application-phase-3 branch July 26, 2026 16:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant