From e789bb99a361768ba80813f0f8012431b720ba8f Mon Sep 17 00:00:00 2001 From: kjgbot Date: Tue, 8 Sep 2026 09:43:48 +0200 Subject: [PATCH 1/6] =?UTF-8?q?docs(scoreboard):=20gate=207=20is=20AMBER?= =?UTF-8?q?=20=E2=80=94=20#227=20landed=20the=20darwin-arm64=20suite=20it?= =?UTF-8?q?=20waited=20on?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The row said RED because "regression suite needs darwin-arm64 placement". That suite merged last night as be3c95ed and is green: full kernel run is 205 passed / 0 failed on main at c9bf155, on darwin arm64. I merged the work and left the row that tracks it stale, which is the same staleness this lane spent four ticks correcting in other files. AMBER rather than GREEN, deliberately. RFC-0001 gate 7 requires the same flow YAML to run locally AND in cloud with no placement config, and only the local half is provable from this repo. Promoting it to GREEN on the strength of a passing kernel suite would repeat exactly what the gate 2 row already warns about: its bar is the real workload in production, not a test run. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- ops/SCOREBOARD.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ops/SCOREBOARD.md b/ops/SCOREBOARD.md index 9b0066bbb..54a161200 100644 --- a/ops/SCOREBOARD.md +++ b/ops/SCOREBOARD.md @@ -11,6 +11,6 @@ Every row starts RED and moves only on evidence. AMBER blocks nothing here | 4 — chief / harness | RED | not started | | 5 — memory | RED | scoped by harness directive 3 (relayfile + relayhistory per customer) | | 6 — integrations via relayfile | RED | **BLOCKED on gates 2-4** (Khaliq, 2026-08-28, option B — this repo has no example flows to convert; helper surface may be built now but does not make the gate green) — harness (design partner) needs slack/notion helpers; also unblocks its `REPLACE-WHEN: gate-2` shims | -| 7 — sandbox routing | RED | regression suite needs darwin-arm64 placement | +| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified: disabling the `covered` short-circuit fails it). The darwin-arm64 regression suite this row was waiting on is green — full kernel suite 205 passed / 0 failed on `main` at `c9bf155`. The kernel ranks nothing: it carries no provider names, and `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | | 8 — identity + credentials | RED | regression suite needs multi-principal runs | | 9 — self-improving agents | RED | depends on 5 + 8 | From 136d98de4dcdd92369ed13b82f4720d563a92e0a Mon Sep 17 00:00:00 2001 From: kjgbot Date: Tue, 8 Sep 2026 09:46:51 +0200 Subject: [PATCH 2/6] docs(gate5): record relayhistory's contract before writing a provider against it MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit RFC-0001 gate 5 says relayhistory is "consumed over its serialization contract, not rewritten", so this reads the contract from the repo (3e7df69) rather than proposing a design that ignores it. Retrieval is `ai-hist pack --json`, emitting { query, entries }. The `--tokens` budget is applied as chars = tokens * 4, an approximation and not a tokenizer, so a provider must not report it back as exact usage — decision 10's per-step accounting is only checkable if the number means something. The trap worth having in writing: pack_entries calls std::process::exit(1) when nothing matches, AFTER printing an empty entries array. Exit 1 means "no memory matched", not "the call failed". A provider treating nonzero as an error would report every cold-start step as a memory failure. Also records what #221 already landed — the MemoryProvider seam and itemized memory.injected accounting — versus what is still a stub, so nobody re-derives that gate 5's hard part is done and its retrieval is not. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- kernel/GATE5-MEMORY-CONTRACT.md | 58 +++++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 kernel/GATE5-MEMORY-CONTRACT.md diff --git a/kernel/GATE5-MEMORY-CONTRACT.md b/kernel/GATE5-MEMORY-CONTRACT.md new file mode 100644 index 000000000..3c3a34f86 --- /dev/null +++ b/kernel/GATE5-MEMORY-CONTRACT.md @@ -0,0 +1,58 @@ +# Gate 5 — what a relayhistory-backed MemoryProvider has to do + +Read of `AgentWorkforce/relayhistory` at `3e7df69`, 2026-09-08. RFC-0001 gate 5 +says relayhistory is "consumed over its serialization contract, not rewritten", +so this records that contract rather than proposing a design that ignores it. + +## What already exists on the flows side + +`#221` landed the seam, and it is the part that is hard to retrofit: +`MemoryProvider`, `MemoryPack`, and a `memory.injected` journal entry carrying +the consuming `step_id` and initial `attempt`. That is RFC decision 10 — memory +tokens charged to the consuming step, itemized, no shared pools. + +What is wired is `FixedMemoryProvider`, which returns +`{"text":"fixed memory pack","citations":[]}` with synthetic usage of 7 input +tokens and `"0.002"`. `kernel/MEMORY.md` says so plainly: "a substrate stub: +there is no retrieval, relayhistory call, or claim about memory quality." + +## The contract to consume + +Retrieval is `ai-hist pack`: + + ai-hist pack [--project P] [--tag T] [--source S] + [--limit N] [--tokens N] [--fts] [--json] + +- `--json` emits `{ "query": ..., "entries": [...] }`. +- `--tokens N` is the budget, applied as `chars_budget = tokens * 4` + (`crates/ai-hist/src/lib.rs:2369`) — a four-characters-per-token + approximation, not a tokenizer. A provider must not report that figure back + as exact usage; decision 10's accounting is only checkable if the number + means something. + +**The trap worth writing down before anyone implements this.** `pack_entries` +calls `std::process::exit(1)` when there are no results, after printing +`{"query": ..., "entries": []}`. Exit 1 here means *no memory matched*, not +*the call failed*. A provider that treats nonzero as an error will report every +cold-start step as a memory failure, and a provider that treats it as fatal +will fail closed on exactly the runs that have nothing to remember yet. + +The trajectory side is `ai-hist push`, which takes `--install-service` and an +interval. Gate 5's bar is "every relayflow run pushes trajectories to +relayhistory **without opt-in code**", so that is a service the cell runs, not +a call each flow makes. + +## What gate 5 still needs, in order + +1. A `RelayhistoryMemoryProvider` implementing the existing `MemoryProvider` + trait over `ai-hist pack --json`, mapping a step's declared + `memory: { scope, query, budget }` onto the pack arguments, and reporting + honest usage rather than the char-budget approximation. +2. Exit-1-means-empty handled explicitly, with a test that a step whose query + matches nothing still runs and journals an empty pack. +3. The push side wired as a service. + +None of this is the acceptance test. RFC gate 5 asks for "an agent avoiding a +mistake recorded in a previous run's trajectory, with the citation in its +output" — a behavioural bar, not a passing suite. The three items above are +what makes attempting it possible. From 98ddfbeaf0719893f036ac0a9b8cceaa30af60c3 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Tue, 8 Sep 2026 13:24:42 +0200 Subject: [PATCH 3/6] docs: correct a self-contradicting claim and a PR attribution MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Two cubic findings on #240, both mine. The gate 7 row said the kernel "carries no provider names" two sentences after naming `RoutingDecision (profile, provider, fallbacks_attempted, workspace)`, and `placement.rs` declares `pub provider: String`. I meant the kernel hardcodes no provider identities and contains no ranking; what I wrote reads as false against the struct on the same row. Rewritten to say the chosen provider is the journaled fact while the kernel holds no provider identities and no ranking. The gate 5 contract note credited the memory seam to #221. `kernel/MEMORY.md` is titled "Step memory, slice 1 (#220)"; #221 is a separate PR. Corrected. Neither changes a verdict — gate 7 stays AMBER and the gate 5 contract is unchanged — but a scoreboard that contradicts itself is worse than one that is merely out of date, because the contradiction is what a reader trusts least. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- kernel/GATE5-MEMORY-CONTRACT.md | 2 +- ops/SCOREBOARD.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/kernel/GATE5-MEMORY-CONTRACT.md b/kernel/GATE5-MEMORY-CONTRACT.md index 3c3a34f86..7b1b45f99 100644 --- a/kernel/GATE5-MEMORY-CONTRACT.md +++ b/kernel/GATE5-MEMORY-CONTRACT.md @@ -6,7 +6,7 @@ so this records that contract rather than proposing a design that ignores it. ## What already exists on the flows side -`#221` landed the seam, and it is the part that is hard to retrofit: +`#220` landed the seam, and it is the part that is hard to retrofit (`kernel/MEMORY.md` is titled "Step memory, slice 1 (#220)"; #221 is a separate PR): `MemoryProvider`, `MemoryPack`, and a `memory.injected` journal entry carrying the consuming `step_id` and initial `attempt`. That is RFC decision 10 — memory tokens charged to the consuming step, itemized, no shared pools. diff --git a/ops/SCOREBOARD.md b/ops/SCOREBOARD.md index 54a161200..bb4bca500 100644 --- a/ops/SCOREBOARD.md +++ b/ops/SCOREBOARD.md @@ -11,6 +11,6 @@ Every row starts RED and moves only on evidence. AMBER blocks nothing here | 4 — chief / harness | RED | not started | | 5 — memory | RED | scoped by harness directive 3 (relayfile + relayhistory per customer) | | 6 — integrations via relayfile | RED | **BLOCKED on gates 2-4** (Khaliq, 2026-08-28, option B — this repo has no example flows to convert; helper surface may be built now but does not make the gate green) — harness (design partner) needs slack/notion helpers; also unblocks its `REPLACE-WHEN: gate-2` shims | -| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified: disabling the `covered` short-circuit fails it). The darwin-arm64 regression suite this row was waiting on is green — full kernel suite 205 passed / 0 failed on `main` at `c9bf155`. The kernel ranks nothing: it carries no provider names, and `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | +| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified: disabling the `covered` short-circuit fails it). The darwin-arm64 regression suite this row was waiting on is green — full kernel suite 205 passed / 0 failed on `main` at `c9bf155`. The kernel ranks nothing: `RoutingDecision` carries a `provider` field because the chosen provider is the journaled fact, but the kernel hardcodes no provider *identities* and contains no ranking — `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | | 8 — identity + credentials | RED | regression suite needs multi-principal runs | | 9 — self-improving agents | RED | depends on 5 + 8 | From cb3ee527323a107a34c0aebc30d485f14f059af3 Mon Sep 17 00:00:00 2001 From: kjgbot Date: Wed, 9 Sep 2026 09:25:08 +0200 Subject: [PATCH 4/6] docs(gate5): place the relayhistory provider outside the kernel boundary The structure lens raised a P1 and it is right. Item 1 read "a RelayhistoryMemoryProvider implementing the existing MemoryProvider trait", and that trait lives in kernel/relayflowd/src/memory.rs -- so the wording naturally directs the implementation into relayflowd, where a subprocess/provider integration would violate RFC-0001 section 4 and settled decision #13. That is a structural defect in the contract, not a naming quibble: a contract that reads as an instruction to put ai-hist inside the Rust kernel will eventually be followed. The item now states where the adapter lives (SDK/control-plane edge, crossing the journal protocol boundary), keeps the kernel-side MemoryProvider an injected protocol seam only, and prohibits an ai-hist dependency, a subprocess call, or relayhistory-shaped vocabulary in relayflowd. Documentation only; no product code or tests are touched. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- kernel/GATE5-MEMORY-CONTRACT.md | 17 +++++++++++++---- 1 file changed, 13 insertions(+), 4 deletions(-) diff --git a/kernel/GATE5-MEMORY-CONTRACT.md b/kernel/GATE5-MEMORY-CONTRACT.md index 7b1b45f99..cea27ff62 100644 --- a/kernel/GATE5-MEMORY-CONTRACT.md +++ b/kernel/GATE5-MEMORY-CONTRACT.md @@ -44,10 +44,19 @@ a call each flow makes. ## What gate 5 still needs, in order -1. A `RelayhistoryMemoryProvider` implementing the existing `MemoryProvider` - trait over `ai-hist pack --json`, mapping a step's declared - `memory: { scope, query, budget }` onto the pack arguments, and reporting - honest usage rather than the char-budget approximation. +1. A `RelayhistoryMemoryProvider` over `ai-hist pack --json`, mapping a step's + declared `memory: { scope, query, budget }` onto the pack arguments and + reporting honest usage rather than the char-budget approximation. + + **It does not live in the kernel.** The adapter belongs at the + SDK/control-plane edge and reaches the kernel across the journal protocol + boundary. RFC-0001 §4 and settled decision #13 keep the Rust kernel small, + pure and closed-vocabulary, so `relayflowd` must not gain an `ai-hist` + dependency, a subprocess call, or any relayhistory-shaped vocabulary. + `MemoryProvider` in `kernel/relayflowd/src/memory.rs` stays an **injected + protocol seam** — the kernel declares the shape it will accept and never + learns who satisfies it. Reading item 1 as "implement this trait inside + relayflowd" is the failure mode this paragraph exists to prevent. 2. Exit-1-means-empty handled explicitly, with a test that a step whose query matches nothing still runs and journals an empty pack. 3. The push side wired as a service. From bb7c44b033127691fd3986872094cf36ae816e7c Mon Sep 17 00:00:00 2001 From: kjgbot Date: Wed, 9 Sep 2026 09:42:32 +0200 Subject: [PATCH 5/6] docs: fix a reversed PR attribution and two unsupported claims Both blockers the history lens raised are mine, and H1 is the worse kind: a commit that announced it was correcting an attribution and reversed it instead. H1 - GATE5-MEMORY-CONTRACT.md:9 said "#220 landed the seam ... #221 is a separate PR". #220 is the ISSUE; PR #221 implemented it and closed it. The line now reads "PR #221 (issue #220) landed the seam", and explains that kernel/MEMORY.md is titled with #220 because it names the issue. The historical commit stays; the current document is corrected here, as the lens asked. H2 - SCOREBOARD.md:14 asserted "full kernel suite 205 passed / 0 failed" and described a case as "mutation-verified" while supplying neither commands nor a transcript. That is the failure class AGENTS.md rules 1-2 prohibit -- evidence is captured, not narrated -- and a pass count drifts while a transcript does not. The row now cites the run rather than restating a number, and says how the mutation check was performed without claiming the sentence is the proof. Documentation only. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- kernel/GATE5-MEMORY-CONTRACT.md | 2 +- ops/SCOREBOARD.md | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/kernel/GATE5-MEMORY-CONTRACT.md b/kernel/GATE5-MEMORY-CONTRACT.md index cea27ff62..c94581c82 100644 --- a/kernel/GATE5-MEMORY-CONTRACT.md +++ b/kernel/GATE5-MEMORY-CONTRACT.md @@ -6,7 +6,7 @@ so this records that contract rather than proposing a design that ignores it. ## What already exists on the flows side -`#220` landed the seam, and it is the part that is hard to retrofit (`kernel/MEMORY.md` is titled "Step memory, slice 1 (#220)"; #221 is a separate PR): +PR `#221` (issue `#220`) landed the seam, and it is the part that is hard to retrofit (`kernel/MEMORY.md` is titled "Step memory, slice 1 (#220)" because it names the issue): `MemoryProvider`, `MemoryPack`, and a `memory.injected` journal entry carrying the consuming `step_id` and initial `attempt`. That is RFC decision 10 — memory tokens charged to the consuming step, itemized, no shared pools. diff --git a/ops/SCOREBOARD.md b/ops/SCOREBOARD.md index bb4bca500..f7727bb31 100644 --- a/ops/SCOREBOARD.md +++ b/ops/SCOREBOARD.md @@ -11,6 +11,6 @@ Every row starts RED and moves only on evidence. AMBER blocks nothing here | 4 — chief / harness | RED | not started | | 5 — memory | RED | scoped by harness directive 3 (relayfile + relayhistory per customer) | | 6 — integrations via relayfile | RED | **BLOCKED on gates 2-4** (Khaliq, 2026-08-28, option B — this repo has no example flows to convert; helper surface may be built now but does not make the gate green) — harness (design partner) needs slack/notion helpers; also unblocks its `REPLACE-WHEN: gate-2` shims | -| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified: disabling the `covered` short-circuit fails it). The darwin-arm64 regression suite this row was waiting on is green — full kernel suite 205 passed / 0 failed on `main` at `c9bf155`. The kernel ranks nothing: `RoutingDecision` carries a `provider` field because the chosen provider is the journaled fact, but the kernel hardcodes no provider *identities* and contains no ranking — `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | +| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified by disabling the `covered` short-circuit and observing that case fail; the transcript is the evidence, not this sentence). The darwin-arm64 regression suite this row was waiting on is green on `main` at `c9bf155`; the run is the evidence, and this row deliberately does not restate a pass count, which drifts while the transcript does not. The kernel ranks nothing: `RoutingDecision` carries a `provider` field because the chosen provider is the journaled fact, but the kernel hardcodes no provider *identities* and contains no ranking — `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | | 8 — identity + credentials | RED | regression suite needs multi-principal runs | | 9 — self-improving agents | RED | depends on 5 + 8 | From 3564fcb6d70161b875501597bad82721fc1749fa Mon Sep 17 00:00:00 2001 From: kjgbot Date: Wed, 9 Sep 2026 09:57:40 +0200 Subject: [PATCH 6/6] docs: move the gate-5 contract out of kernel/ and shrink the gate-7 row Both remaining structure blockers, and the first is sharper than the wording fix I made an hour ago. P1 - location, not phrasing. I had added a paragraph saying the relayhistory adapter must not live in relayflowd. Directionally right, but the FILE still sat at kernel/GATE5-MEMORY-CONTRACT.md, and a document under kernel/ reads as kernel design authority no matter what its text says. It specifies ai-hist CLI syntax, JSON output, exit-code behaviour and provider traps -- SDK/control-plane knowledge that RFC-0001 section 4 and settled decision 13 keep out of the provider-neutral Rust kernel. Moved to docs/ and added an explicit ownership header saying why, so location and text now agree. P2 - the gate-7 scoreboard cell had become a second design report: Rust symbols, test names, crash behaviour, a mutation claim, commit hashes and suite counts in one table cell. Reduced 1420 chars to 382: gate state, what is journaled, and the reason it is not GREEN. The implementation narrative and mutation transcript belong in the PR #227 review artifacts, which AGENTS.md already requires to carry the literal transcript -- a row asserting "mutation-verified" was never evidence. Documentation only. Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_01FtQSAcGDta5VH9xiZFT4sR --- {kernel => docs}/GATE5-MEMORY-CONTRACT.md | 11 +++++++++++ ops/SCOREBOARD.md | 2 +- 2 files changed, 12 insertions(+), 1 deletion(-) rename {kernel => docs}/GATE5-MEMORY-CONTRACT.md (84%) diff --git a/kernel/GATE5-MEMORY-CONTRACT.md b/docs/GATE5-MEMORY-CONTRACT.md similarity index 84% rename from kernel/GATE5-MEMORY-CONTRACT.md rename to docs/GATE5-MEMORY-CONTRACT.md index c94581c82..a89c9838e 100644 --- a/kernel/GATE5-MEMORY-CONTRACT.md +++ b/docs/GATE5-MEMORY-CONTRACT.md @@ -1,3 +1,14 @@ + + +> **Ownership.** This contract describes a `relayhistory` / `ai-hist` integration: +> provider CLI syntax, JSON output, exit-code behaviour and provider-specific +> traps. That is SDK/control-plane knowledge, not kernel design authority. +> RFC-0001 §4 and settled decision #13 keep the Rust kernel provider-neutral and +> closed-vocabulary, so this file lives under `docs/` — it previously sat under +> `kernel/`, where its location signalled kernel ownership regardless of what the +> text said, and a future implementer could reasonably have grown the kernel +> around `ai-hist` on that signal alone. + # Gate 5 — what a relayhistory-backed MemoryProvider has to do Read of `AgentWorkforce/relayhistory` at `3e7df69`, 2026-09-08. RFC-0001 gate 5 diff --git a/ops/SCOREBOARD.md b/ops/SCOREBOARD.md index f7727bb31..ccc8c4ad8 100644 --- a/ops/SCOREBOARD.md +++ b/ops/SCOREBOARD.md @@ -11,6 +11,6 @@ Every row starts RED and moves only on evidence. AMBER blocks nothing here | 4 — chief / harness | RED | not started | | 5 — memory | RED | scoped by harness directive 3 (relayfile + relayhistory per customer) | | 6 — integrations via relayfile | RED | **BLOCKED on gates 2-4** (Khaliq, 2026-08-28, option B — this repo has no example flows to convert; helper surface may be built now but does not make the gate green) — harness (design partner) needs slack/notion helpers; also unblocks its `REPLACE-WHEN: gate-2` shims | -| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 as `be3c95ed`. A step declares `requirements`, the engine journals a `RoutingDecision` (`profile`, `provider`, `fallbacks_attempted`, `workspace`) at `StepRouted`, and dispatch consumes that fact without choosing again — pinned by `worker_retry_consumes_the_original_routing_fact` and `crash_between_routing_and_start_does_not_redecide`. Kill-and-resume is covered by three `crash_resume::placement` cases including `sigkill_mid_step_keeps_the_route_and_source_tree`, and `a_resumed_attempt_keeps_the_original_pin_after_the_worktree_head_moves` pins the revision across a moving HEAD (mutation-verified by disabling the `covered` short-circuit and observing that case fail; the transcript is the evidence, not this sentence). The darwin-arm64 regression suite this row was waiting on is green on `main` at `c9bf155`; the run is the evidence, and this row deliberately does not restate a pass count, which drifts while the transcript does not. The kernel ranks nothing: `RoutingDecision` carries a `provider` field because the chosen provider is the journaled fact, but the kernel hardcodes no provider *identities* and contains no ranking — `placement.rs:58` states it must not rank providers again after the append. **Not GREEN**: RFC-0001 gate 7 requires the same flow YAML to run locally *and in cloud* with no placement config, and only the local half is provable in this repo. | +| 7 — sandbox routing | **AMBER** | in progress — #227 merged 2026-09-08 (`be3c95ed`). Routing is journaled as a `RoutingDecision` fact at `StepRouted` and dispatch consumes it without re-deciding. **Not GREEN**: gate 7 requires the same flow YAML to run locally and in cloud, and the cloud half is unproven. Design, test inventory and the mutation transcript live in the PR #227 review artifacts, not in this row. | | 8 — identity + credentials | RED | regression suite needs multi-principal runs | | 9 — self-improving agents | RED | depends on 5 + 8 |