Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion .github/workflows/tests.yml
Original file line number Diff line number Diff line change
Expand Up @@ -85,7 +85,7 @@ jobs:
python -m pytest `
tests/test_mediated_executor.py `
tests/test_privacy_invariants.py `
tests/test_governed_decision_integration_absence.py `
tests/test_governed_consumption_parity.py `
-m "not windows_optional" -q `
-o junit_family=legacy --junit-xml=$xml
if ($LASTEXITCODE -ne 0) { exit $LASTEXITCODE }
Expand Down
25 changes: 14 additions & 11 deletions docs/architecture/daily_driver_orchestrator_spec.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,11 +34,14 @@ implementation is withheld. **CR-DD-012A is complete and merged through PR #107
`bccaaad`.** It distinguishes optional provenance source bytes, normalized component
bytes under current UTF-8/text semantics, and authoritative assembled worker-execution
bytes, but grants no integration authority; no public command consumes it. CR-DD-012B's
CR-YK-002 atomic-claiming prerequisite is satisfied through PR #117 as `5155bbb`, and a
documentation-only proposal now exists at
`docs/change/requests/CR-DD-012B-shared-preview-execution-consumption.md`; implementation
remains blocked on its own explicit approval and bounded file allowlist, and the proposal
is not that approval. **CR-DD-013 is implemented and merged through PR #116 as
CR-YK-002 atomic-claiming prerequisite is satisfied through PR #117 as `5155bbb`, and the
slice specified at
`docs/change/requests/CR-DD-012B-shared-preview-execution-consumption.md` is now
**implemented on an unmerged branch and accepted at exact head `bbe5336`**. The original
implementation instruction named no bounded file allowlist; that authority defect is
preserved in the CR and was handled by a one-time corrective ratification rather than
erased. Merge, release, and closeout authority are withheld, so nothing in this spec's
description of current `main` behavior changes until that slice is merged. **CR-DD-013 is implemented and merged through PR #116 as
`98df9c1`.** `tc run` now resolves recorded capability evidence and binds that resolution
into route selection; configured route declarations and observed reachability remain
separate inputs. Its documentation-only closeout merged through PR #132 at `6d585268` and
Expand Down Expand Up @@ -91,9 +94,10 @@ after M0 (below) produces daily-use evidence. See **Evidence Requirements**.
artifact review linkage. Execution still does not consume that artifact or the same
immutable decision. CR-DD-012A's bounded internal, non-integrated foundation and focused
tests are complete and merged through PR #107 as `bccaaad`; no public command consumes
them. CR-DD-012B has a documentation-only proposal and still has no implementation
authority. The future shared path must use one immutable input snapshot
so execution does not reopen or reconstruct governed inputs. Confirmed-artifact
them. CR-DD-012B is accepted at exact head `bbe5336` on an unmerged branch; merge
authority is withheld, so on `main` the two paths still diverge. The shared path that branch builds
uses one immutable input snapshot, read once at a seam before the preview branch, so
execution does not reopen or reconstruct governed inputs. Confirmed-artifact
execution remains a later, separately gated CR; `triagecore run-pipeline` also remains
local-only and bypasses the router.
- **G2 — Cloud is Qwen, not frontier.** No live Claude/GPT/Gemini backends, no provider
Expand Down Expand Up @@ -137,9 +141,8 @@ backwards.
`NormalizedComponentBytes`, and authoritative `AssembledExecutionBytes`, plus the
canonical decision, pure normalizer/builder, identity, and focused tests with no CLI,
ledger, worker, route, or plan-v2 change; then **M0.3b / CR-DD-012B**, whose
CR-YK-002 prerequisite is now satisfied and whose documentation-only proposal is
recorded, but which remains blocked until it receives its own separate approval and
bounded file allowlist. It owns shared preview/execution consumption, envelope
CR-YK-002 prerequisite is satisfied and which is now accepted at exact head `bbe5336`
on an unmerged branch, blocked until it receives merge authority. It owns shared preview/execution consumption, envelope
enforcement, bounded decision-ID linkage, and parity/fail-closed tests. A recorded
decision settles that CR-DD-013 capability evidence constrains **execution binding
only** and never governed-decision formation, so stable inputs produce the decision,
Expand Down
43 changes: 28 additions & 15 deletions docs/change/requests/CR-DD-012-shared-governed-run-decision.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,32 +10,45 @@ bounded implementation approval and is complete and merged through PR #107 as
`bccaaad` as an internal, non-integrated foundation. Current CR-DD-009 through
CR-DD-011 behavior remains unchanged.

**CR-DD-012B status update.** Its sequencing prerequisite is now satisfied:
CR-YK-002's atomic-claiming foundation is complete and merged through PR #117 as
`5155bbb`. A documentation-only proposal for the slice now exists at
`CR-DD-012B-shared-preview-execution-consumption.md`, settling the consumption
questions this document deferred. **Neither the satisfied prerequisite nor the
proposal is implementation approval.** CR-DD-012B still requires its own
explicit human implementation approval and its own bounded file allowlist before
any code is written. The proposal's three previously open questions are now
settled by recorded decision, most importantly that CR-DD-013 capability evidence
**CR-DD-012B status update.** Its sequencing prerequisite was satisfied by
CR-YK-002's atomic-claiming foundation, complete and merged through PR #117 as
`5155bbb`. `CR-DD-012B-shared-preview-execution-consumption.md` settled the
consumption questions this document deferred, and the slice has since been
**implemented** on `claude/cr-dd-012b-shared-preview-execution-35b467` under a
direct implementation instruction that granted intent but named no bounded file
allowlist; work proceeded under that document's provisional list as an *inferred*
scope, which was not a grant, and the gap was closed afterwards by a one-time
corrective ratification. Implementation authority is spent, an acceptance review at
`909838f` withheld acceptance pending three repairs, all were implemented, and
**implementation acceptance is now granted for exact head `bbe5336`. Merge,
release, and closeout authority are withheld.** The original authority defect —
the implementation instruction granted intent but named no bounded file allowlist
— is preserved rather than erased, and was handled by a one-time corrective
ratification pinned to `bbe5336`. That defect, the ratification, the two paths
taken beyond the inferred allowlist, the behavioral changes acceptance approved,
the one remaining place the built code is narrower than the recommendation, and
an open discovery on the high-risk terminal exit class are all recorded in that
document rather than absorbed. CR-DD-012A through CR-DD-011 behavior on `main` is unchanged until
that slice is accepted and merged. The proposal's three previously open questions
were settled by recorded decision, most importantly that CR-DD-013 capability evidence
constrains **execution binding only** and never governed-decision formation: a
volatile observation may execute, bind an already-authorized fallback, or fail
closed, but may never invent a route the decision did not authorize. That is a
deliberate correction to current `tc run` route selection and is recorded as
such. The proposal also records five approval gates binding at two stages: two
proposal-stage preconditions, already satisfied, and three test obligations that
any bounded implementation approval must bind and that must pass before
implementation acceptance, merge, or closeout.
proposal-stage preconditions, satisfied before implementation, and three test
obligations that were bound as implementation obligations and pass. Gates passing
was evidence for the acceptance decision, not the decision; the decision is
recorded separately and pinned to an exact head.

The CR-DD-012A foundation is specified in
`CR-DD-012A-governed-decision-foundation.md`. It resolves “exact bytes” as the
established normalized worker-facing execution representation, not raw
filesystem or backend transport bytes. CR-DD-012A implementation authority
is limited to its exact internal module, focused test, and documentation
allowlist. 012A has landed. The CR-YK-002 prerequisite has since been satisfied,
so CR-DD-012B is now blocked solely on its own separate explicit approval and
bounded file allowlist; its proposal is documentation-only and grants nothing.
allowlist. 012A has landed, and CR-DD-012B has been implemented against it and
accepted at exact head `bbe5336` on an unmerged branch; that branch is now
blocked on merge authority, which is a gate this document does not grant.

## Decision

Expand Down
Loading
Loading