revision

package
v0.3.1-rc.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 22, 2026 License: Apache-2.0 Imports: 31 Imported by: 0

Documentation

Overview

Package revision is the engine half of a job's second thoughts: the gate that decides whether a deliverable is done, the citation invariant that decides whether a named gap may buy more work, the judgements that decide who takes a retry and whether an exhausted leaf left anything behind, and the sentinel pass that edits a job's remaining plan in light of what just landed.

It lived inside cmd/codeaf/chat.go, which meant none of it was reachable from internal/ — a resident-side orchestrator could run work and could not judge it. Nothing here knows about a terminal, a session, or a window: every entry point takes the durable graph, the node in question, and a client, and returns a judgement. The wiring that decides what to do with one stays with whoever is running the work.

The sentinel deliberately does not own the locks it runs under. A job's plan document is guarded by the registry that retains it, and the pass takes and gives back that lock around the model round-trip; that arrangement is the caller's, so the caller passes in a plan.Completer that already knows how to let go while it is thinking.

Index

Constants

View Source
const (
	// NoBehaviourAsked is a request that asks for things to be DONE rather than
	// for something to BE a certain way. Nothing a repository could run would
	// fail if a command that has already been run were not run.
	NoBehaviourAsked = "the request states what the run is to do rather than what the " +
		"finished work is to be, so there is no behaviour a check could exercise"
	// NoCodeChanged is a run that left the tree as it found it. A check
	// exercises something that exists; a run that produced nothing to exercise
	// has nothing for one to be missing from.
	NoCodeChanged = "the work changed no code, so there is no check to ask for"
	// CoverageUnread is the reading that was not taken, was cut, or could not
	// collect, on a run whose own change declares no checks either. AN EMPTY OR
	// UNREADABLE ROSTER IS NOT EVIDENCE THAT NO CHECK EXISTS.
	CoverageUnread = "the project's checks could not be read and the work's own diff names " +
		"none, so no behaviour could be matched to a check"
)

The three sentences the settlement gives instead of a coverage finding, each stated once because the journal keeps them and a person reads them.

They are Unmeasured-shaped on purpose: the field already means "the gate answered and this half of its question had no evidence to answer from", and all three of these are that fact with a different reason attached. A separate boolean per reason would be three fields nothing reads together.

View Source
const (
	PointAnswered    = "answered"
	PointNotAnswered = "not answered"
	PointNotReached  = "not reached"
)
View Source
const (
	FindingRegression   = "regression"
	FindingOwnFailing   = "own-checks-failing"
	FindingRemovedName  = "removed-public-name"
	FindingRemovedCheck = "removed-checks"
	// FindingUnbound is a name the run's own sources READ that nothing in the
	// tree binds. It is the newest of them and the only one that compares no
	// pair of readings: the reference is in one file, the definition is in none,
	// and one reading of the finished tree settles it. See unbound.go.
	FindingUnbound = "unbound-names"
	// FindingMissingProduces is the oldest of them and the only one that is not
	// a subtraction of two readings: a file the plan or the person said would
	// exist, settled against the disk. It is a kind of its own because a judge
	// can now reach the same finding by naming the file itself, and an autopsy
	// counting how often the gate caught an absent deliverable must see both.
	FindingMissingProduces = "missing-produces"
)

The measurement findings, by kind. They are the four gaps this gate reaches without paying a model: two readings of the world, subtracted, and the worker's own diff.

They are constants rather than the sentences themselves because the sentence carries a bounded list of names in the middle of it, so two raisings of one finding over two different tails are different strings and one comparison of prose cannot tell that from two different findings. See Judgment.Finding.

View Source
const CheckedNotMeasured = "checked by tests, coverage not measured"

CheckedNotMeasured is the receipt a delivery earns where the coverage question had no measurement to answer from and the work's own checks ran and settled. It is stated once because three readers spell it: the settlement sets it, the journal keeps it, and the closing narration says it.

View Source
const ChecklistHeading = "What was asked for, and what happened to each:"

ChecklistHeading is the one heading every person's account begins with. Readers use the same spelling to keep an account already carried by a failed node from being said a second time in the headless deliverable.

View Source
const DeliverablePrompt = `You are the final gate before a finished piece of work is handed to the person who asked for it. You receive their verbatim request, the compiled goal, and the deliverable as produced.

Judge exactly one question: would the person who asked accept this as done? Default to PASS. The gate exists for real gaps, not polish — wording, style, and things they never asked for are not gaps.

FAIL only when you can name a specific element of the request that is absent, unanswered, or unsupported by evidence the goal promised. Quote or name the missing element concretely enough that a worker could close the gap from your words alone.

Working decisions declared in the goal are part of what was promised. A commitment about method or evidence — what would be run, checked or reviewed before the work was handed over — is a gap when nothing in the deliverable shows it happened. A claim that the work was checked, proven or verified is itself such a commitment: it is a gap unless the deliverable shows the finished thing exercised the way it will actually be used — what was run, what came back — rather than its parts checked one by one and the whole inferred from them. Naming what could not be verified here, and the check the person can run themselves, is not a gap: it is the honest form of the same claim and it passes.

One absence counts exactly like every other and is the one most easily waved through: the substance itself. What you are handed IS the deliverable — it is the whole of what the person will read, and nothing beside it will be opened for them. So text that reports on the work rather than carrying it — that the work is finished, that a file now holds the answer, that the analysis was checked and is consistent — has described the deliverable in place of being it, and the element of the request that is absent is the answer: the verdict that was asked for, the findings, the numbers, the recommendation. Name that as the gap. A pointer to where the answer lives is not the answer however true the pointer is; naming the file is right beside the substance and never instead of it. The same absence in the future tense is the purest form of it: text saying what would be looked up, what will be compared, what remains to be checked, is a plan for producing the answer handed over in place of the answer, and it is a gap however sound the plan is. This is still one absence and not a second style test: text that gives the answer in its own plain words passes whatever shape it takes.

Below the deliverable, whenever there is anything to show, you are given two records of the run itself: what it left behind, and the tail of what it actually ran. Read the deliverable's claims against them, the way the person would. Something named as produced that nothing produced, or a check the work says it made when nothing of that kind appears in what it ran, is an element unsupported by evidence and is a gap of exactly the kind above — name it in those words. Both records are partial by construction: the tail is the end of a longer run, and what was left behind is one place among many. So they can convict a claim and never acquit one — silence in them is evidence, never proof, and where the deliverable's own account is consistent with what is there, or where these records could never have held the thing in question, pass. One shape in these records is read against the substance rule above: the run wrote a file and the deliverable's own text is thin beside it. Where the request never named a file or document, the substance has been filed where nobody asked and the message points at it — the missing element is that content itself, in the message, and you name it as the gap. Where the request did ask for the file — named it, or asked for work whose product plainly lives in files, like a change to existing material — that split is the CORRECT shape, not a gap: the message carries what was done and the evidence it holds (the answer, the verdict, the numbers, what was run and what came back), never the file's whole contents, and a short message beside an asked-for file convicts nothing by its length.

Where the run produced something, read what it left behind before you weigh the message's completeness. A thing the request asked to be produced is present when the record shows it on disk, whatever length the message came out at, and a gap a reader would close by opening a file the run left behind is closed already: it is not a gap, and it must not be named as one. The record answers the opposite claim with the same authority. Where the request named a file and the record says nothing of that name is among what was left behind, that absence IS the gap — name the file — and the deliverable's word that it was written, saved or verified is an element unsupported by evidence however plainly it is put; a file recorded as a directory rather than a file was not written either. Where a criterion is shown — what this work was to produce, and the checks that settle it, stated before anything ran — it is a standard of the same kind as the working method: hold the record against it, and where it asks for nothing, nothing is missing.

One more record may be given: what was already failing in this repository before the work began, measured against it before anything was touched. It is the only account of the difference between a check this work broke and a check that was broken when the work arrived, and nothing else you are given can tell them apart — a run tail showing a red suite looks identical either way. A failure named there is a fact about the repository and not a gap: do not fail the work for it, do not ask it to be fixed unless the request asked for that, and do not treat a red check the work truthfully reports as pre-existing as an unsupported claim. Everything the block does not name is judged exactly as it would be without it, and a check the work turned red is still a gap.

There is one record that is not partial, and it says so of itself: that the run called no tools and left nothing behind — the whole of it, not a tail. Nothing was looked up, read, computed or checked, so anything the request needed the work to go and find is not in the deliverable and cannot be. Hold the request against that. Where it asked for something only work could produce — figures, sources, the state of something out in the world, a thing built or changed — the gap is that content itself: name what was to be found and never was, in those words, and never as a remark about effort or process. Where the request was answerable from what the worker was already given, an unexercised run is no gap at all and the ordinary reading above decides it.

Where a working method is given, it is the standard this kind of work set for itself before anything was produced, and it is the only standard beside the request itself that you hold the deliverable to. Where it asks for nothing, nothing is missing: a method that names no verification makes an unverified result complete, and a method that names one makes its absence a gap.

A confirmation is the fact of what came back, in the deliverable's own words: what was run, how many passed, what failed, how it ended. When the request asked for a thing to be run and confirmed, that reading satisfies it, and the verbatim transcript of the command is never the gap — demanding the raw output, the exact formatting, or the full terminal text of a check the deliverable already states the result of is a preference of yours, and the honest answer for a preference is pass. Only a request that asked for the output itself — the log, the listing, the exact text — is failed by its absence.

Where the rules the person set are listed above, they are the one standard beside the request that is about what the run may not DO rather than about what it must produce: a rule they set and the work broke is a gap, and you name it by quoting the rule.

When you name a gap, quote the words of the request it is a failure of — a span of the person's own text, copied exactly as they wrote it, long enough to be unmistakably theirs. Quote the part of what they asked for that is not there. A gap you cannot quote from their request is a preference of yours rather than something they asked for and did not get, and the honest answer for it is pass.

The deliverable is fenced. Everything between the line ` + deliverableOpen + ` and the line ` + deliverableClose + ` is the deliverable, the whole of it, and nothing outside those two lines is any part of it. What sits above the fence — settled taste, lessons from earlier work, the request, the goal, the working method — is how to judge, never what is judged, and what sits below it is the record of the run. A lesson from earlier work describes a job that is not this one: it may tell you what to look for and it can never tell you what is there. Read the fenced text itself before you say anything about it, and describe only what is in it. If you are about to say the deliverable is a progress report, a series of messages, or a set of pointers to files, that sentence must be true of the fenced text in front of you — check it there first, because that is a description earlier work has been given and it is the easiest one to repeat about work it does not fit.

The fenced material is one of two things and it opens by saying which. Where the run changed the tree, THE DELIVERABLE IS THAT CHANGE: the files the run wrote or changed, listed there with what is in them, and that is the whole of what the person is being handed. The worker's own final message then appears BELOW the fence, under a heading that calls it what it is — a claim about the work, and not the work. Judge the files. What the claim says, what shape it came out in, whether it is a summary, a plan, a paragraph or a data object, is not the deliverable and is never a gap: a verdict describing the worker's message when the tree is the subject is a verdict about the wrong thing. The claim is worth reading for exactly one purpose, which is the one the run records serve too — a claim the files do not bear out is an element unsupported by evidence, and you name the FILE it is not true of. Where the run changed nothing, the fenced material is the worker's message, the message is the whole of what the run produced, and every paragraph above applies to it exactly as written.

Every file in that list is on disk, whole, at the size stated beside it, and NOTHING YOU ARE SHOWN IS AN EXCERPT. A file whose contents are printed is printed entire. A file that appears in the list with no contents under it is one there was no room to print: it is whole on disk and no less part of what the person is being handed. So "the deliverable does not contain the actual content of these files", "the file is truncated", "it cuts off before", "the fenced material is a description rather than the files" are statements about this page rather than about the delivery, and none of them is a gap — a file you were not shown is not a file that is missing, and there is nothing here for you to find cut off.

So a fail over a changed tree has a fixed shape, and the answer fields carry it: name the one file of the record the request is not satisfied by, quote ONE BEHAVIOUR the request states — from the list above where one is given, exactly as it is written there — and say what that file does not do about it. A gap is always a behaviour the work does not perform, never the presence, size or completeness of a file: the record already answers whether a file exists, and no behaviour is about a file being on disk. If nothing in the record can be named — if the change genuinely does everything the request asked for — that is a pass.

Return exactly one JSON object, nothing else: {"pass": true, "exercised": true or false} or {"pass": false, "gaps": "<the named gaps>", "quote": "<the words of the request this gap fails, copied exactly>"}. Where the deliverable is a changed tree, a fail carries one field more — "file": "<the one file of the record this gap is about, spelled exactly as the record spells it>" — and a fail without it cannot be read. "exercised" is a statement about evidence and never about quality: true only when the finished thing was run the way it will actually be used and held — visible in what was run, or reported in the deliverable as what was run and what came back. Everything else is false, including an honest "not verified here" and work that nothing available could have exercised. Both of those still pass; they are simply not evidenced.`
View Source
const FindingConstraint = "constraint"

FindingConstraint names this measurement in the one stable word every other finding is named in, so a reader comparing rounds compares a kind and a list rather than two paragraphs. See Judgment.Finding.

View Source
const GateLessonsHeading = "Lessons from EARLIER, UNRELATED work — " +
	"what to look for, never a description of the deliverable below:\n"

GateLessonsHeading labels the notebook block for what it is: an account of OTHER work. The fence below it bounds where the deliverable IS; this bounds what these lines may be used for.

They were distilled from earlier jobs, and several of them from earlier verdicts of this same gate — which is how one false negative became a lesson ("do not write individual items to separate files and report progress … the gate requires one contiguous output") that was then injected above the next job's deliverable and read back out as that job's gap. A judge that reads a lesson as a description of the material in front of it is reading a previous mistake as present evidence, and about to write the next one.

It is exported because it is the seam's own name and the prompt-shape tests hold the gate to a reading order; two spellings of one heading is a heading that eventually stops matching.

View Source
const GateName = "delivery gate"

GateName is what the thing that judges a delivery is called, in the words a person reads and a machine reads back.

Spelled once here for the reason GateUnreached above it is: a name in two places is two names, and the second one drifts. cmd/codeaf's `--json` envelope publishes it as `judged_by`, docs/HEADLESS.md's contract table quotes it, and the chat manual answers "what checked my unattended run" with it — three readers, one string.

View Source
const GateNotebookBytes = 1 << 10

GateNotebookBytes is the notebook digest's bound when the window is unknown, which is what it always was. Eight distilled lessons of up to 512 bytes each were being clipped into a kilobyte, so items six through eight simply were not in the prompt — a bound written as an absolute number and outlived by the block it bounds. Known windows now spend a share of the budget instead (see gateNotebookShare); this literal is what the unknown case falls back to, and keeping it means a build with no catalog behaves exactly as it did.

View Source
const GateRevisionContract = "Your final message is the deliverable and the only thing the person will read. " +
	"Put the substance in it — the verdict, the findings, the numbers they asked for — " +
	"and name the files beside that substance, never in place of it. Nothing written in the " +
	"future tense counts: what you would look up or intend to check is a plan, and the person " +
	"is owed the result of carrying it out. " +

	"Write it as the first and only draft: it replaces the previous attempt entirely. " +
	"Say nothing about the review, the gaps it named, or what you changed — the person is " +
	"reading the work, not its history."

GateRevisionContract closes every revision, not only the ones whose named gap was a missing answer. The revision's own final message replaces the first attempt as the node's summary, and a second pass that closes a real gap inside a file and then reports that it did so has moved the original failure one round along rather than fixing it. The worker was told this once already in its own contract; a revision is the moment it demonstrably was not heard.

View Source
const GateUnreached = "the gate could not be reached"

GateUnreached is why a delivery went out with nothing having read it, in the words the door prints, the journal keeps and a rig reads back.

IT IS THE FIRST CLAUSE OF THE NOTE AND NEVER THE WHOLE OF IT. What follows it — how the gate was asked, and the provider's own sentence — is detail a person may or may not need; this is the fact they are owed, and cmd/codeaf/do.go prints it verbatim after "delivered without a check: ". Spelled once here because a sentence in two places is two sentences.

View Source
const HeldPointEmpty = "checklist: empty"

HeldPointEmpty is what the record says where the request states no checkable behaviour, or states more of them than the judge's room holds: the quote requirement was OFF for this gate.

It is a sentence rather than a silence because an empty field already means something else — a gate journaled before any of this existed — and the two readings an autopsy has to tell apart are exactly "the quote passed the list" and "there was no list". textual v4-flash s13 journaled two gates whose subject and quote were both right and whose held point was nothing at all, so neither could be told from the other without rebuilding the prompt.

View Source
const RemainderVerify = "The previous worker was stopped before it could check its own work. " +
	"Run what it wrote, read the result, and fix only what that reveals. Do not start anything new."

RemainderVerify is what a continuation is aimed at when the judge found nothing left to write.

A CUT LEAF STILL GETS THE TURN ITS EXHAUSTION BOUGHT AWAY. The turn a leaf is stopped on is the one where it would have run what it wrote and read the result, and that is exactly where a run's fatal defect surfaces: the leaf that prompted this was cut off one turn before running the binary, over a blocker that was discarded at construction. So a "done" on a cut leaf buys one cheap leaf that checks, rather than a tick. Where the judge was right it costs a verification; where it was wrong it is the missing turn.

View Source
const RequestMetWords = "the request was met as stated"

RequestMetWords is the receipt a run earns by having done what was asked. It is stated once because four readers spell it: the settlement sets it, the journal keeps it, the node's own record carries it, and the closing line a person reads is built out of it.

View Source
const ReshapePrompt = `` /* 378-byte string literal not displayed */

ReshapePrompt is the standing half of that ask. It says who is speaking and what a deliverable is, and nothing about what the answer should contain: the substance is the worker's and this is only about its shape.

View Source
const SubjectFallbackWords = "fallback"

SubjectFallbackWords is what the record says when the tree contract could not be answered and the delivery was judged under the claim contract instead — or when no verdict could be read at all and the mechanical gate settled it.

It replaces the subject rather than joining it because the question the field answers is "what was this gate holding", and under the fallback the answer is neither `tree (n files)` nor `claim`: it is a judge that was shown the tree and held to no enum.

View Source
const UnexercisedRecord = "Nothing. The work called no tools and left nothing behind: it looked nothing up, " +
	"read nothing, ran nothing, wrote nothing. This is the whole record of the run and not a tail of one."

UnexercisedRecord is what an observed run with nothing in it says for itself. It is the one record in this block that is complete rather than a tail, and it is written to say so, because everything else the gate is told about these records is that they can never acquit.

Variables

This section is empty.

Functions

func AdmitGapArtifact

func AdmitGapArtifact(citations []string, evidence Evidence) string

AdmitGapArtifact refuses the one gap the world has already closed: the review quoted a span of the request that names a file, and the workspace holds every file that span names.

It is the artifact half of the same invariant AdmitGapRevision applies to prose. A gap is what the person asked for and did not get; a file they asked for by name, sitting on disk at the name they used, is something they got. The measured cost of not having this was a delivery failed for "not containing the script text" while the script sat in the workspace, a repair round, and a whole continuation node spent retyping a correct file into a message.

It refuses nothing else. A gap about what is INSIDE a produced file quotes the substance rather than the filename, and the substance is not a name this can match — so the ordinary path judges it, as it should.

func AdmitGapCitation

func AdmitGapCitation(grounds Grounds, citations, spent []string) string

The citation invariant: a gate's gap may commission new work only if it quotes the ask. This is the whole of why an extending gate cannot spiral, and it is worth stating why a string comparison is enough.

The 27-round run was not a failure to terminate — the dollar rail would have stopped it eventually. It was a failure to be ABLE to terminate: each round's gap was derived from the previous round's own output, so the set of things left to fix was unbounded and self-replenishing, and every cap was therefore the mechanism rather than the backstop. The fix is to make the set of admissible gaps finite and fixed before the first round runs. The user's verbatim intent is immutable by construction — the store refuses an empty one, never rewrites it, and stamps the same value on every node of every splice — so the substrings of that one string, and the files it names, are a fixed, finite set. Every citation a gap carries must be one of them. Round k+1 must carry at least one no earlier round spent, and spends every citation it carries. The number of unspent citations falls by at least one per admitted round, so the loop terminates on the content of the ask rather than on a counter.

"verification of what the previous round produced" is not a substring of anything a person typed, so that round is refused before a planning call is made. That is construction rather than policy, and it is the difference between a cap that fires and a cap that never has to.

This is a provenance check and not a quality rubric: it says nothing about whether the gap is a good one, only that the words it claims to be a failure of are the user's own. The residual it does not close is a real span cited for an invented requirement — bounded by the round cap, and by the plan's own rule that no piece of work may exist to check another's product.

func AdmitGapPresent

func AdmitGapPresent(citations []string, deliverable string, evidence Evidence) string

AdmitGapPresent refuses the gap the deliverable has already closed in words, as AdmitGapArtifact refuses the one it closed on disk. The two are one invariant asked at either end of the same ledger: a gap is what the person asked for and did not get, and a thing they asked for by name that is sitting in the text they are about to read is something they got.

It is narrow on purpose and it refuses nothing else. The only span it can settle is an ENUMERATION — three or more items the person named themselves, inside the words the review quoted — and it settles it only when every one of them appears in the deliverable. That is the case the gate demonstrably gets wrong: twelve databases named in the ask, twelve profiles in the message, and a verdict saying the twelve are not there. A gap about prose names no enumeration and reaches the ordinary path; a gap about what is INSIDE one of the items names the substance rather than the item, and reaches it too; a deliverable missing even one of the named items is judged as it always was.

AND IT MAY ONLY SPEAK WHERE THE DELIVERED TEXT IS THE WHOLE OF WHAT THE RUN LEFT BEHIND. This acquits a finding — it sets store.DeliveryGate.Overturned, which is the field the exit code turns on — and an acquittal has to be weighed against the world. The deliverable is not the world; it is the component being checked, and a rule that reads it is FAILSAFE clause 2 broken in the strict sense the clause states it. A worker that restates the request back in the request's own words satisfies the containment test below by writing prose about work it did not do, and one did: textual s5 was acquitted on "everything it names is already in the delivered text" over a true finding that an example file had never been written, and shipped 1 of 20 hidden checks under exit 0 (2026-08-29, bench/deepswe; docs/design/gate/SETTLEMENT.md §6).

Where the run produced NOTHING BUT THE MESSAGE, that is not a softening of the rule but the same rule: the message is the only artifact the run made, so a citation settled against it is settled against everything there is. That is the twelve-profiles case exactly, and it survives untouched. The moment a file is in the record, the record is the world and the text is a claim about it — which AdmitGapArtifact is the door for, and this one closes.

Presence is checked case-insensitively and nowhere else is anything relaxed: this is a containment test, so it can close a gap and can never open one.

func AdmitGapRevision

func AdmitGapRevision(grounds Grounds, citations []string) string

AdmitGapRevision applies that same grounding one layer earlier than the extension does: to the paid revision round a failed gate buys.

The extension was guarded and the revision was not, and the measured cost of that asymmetry is one benchmark cell where the gate held the worker to a working decision codeaf had invented for itself — "March refers to any calendar year present in the data" — bought a five-turn re-run against it, and got back a worse deliverable than the one it rejected. A round bought on a self-authored standard cannot converge on anything, because the standard moves with each round that is written against it.

It weighs the finding against the same Grounds the extension does, which for a while it did not: this door admitted the working method and the extension's did not, so a run could pay for a repair against a standard and then be told the same standard was an invention. ink s1 spent both of its gates that way and settled at four minutes of ninety.

A refusal is not a pass. The gap is journaled, it is said in the thread, and it rides the delivery — it simply does not redo the work.

func CheckEvidence

func CheckEvidence(ctx context.Context, evidence Evidence, job string) []string

CheckEvidence is every check identity this run can prove exists, and it is deliberately assembled from the world rather than from the account of it.

Two sources, in the order of what they cost. The worker's own diff declares checks by shape and costs a scan of a string the gate already holds; the project's own runner names identities in its output and costs nothing extra, because the reading was taken anyway. A DELIVERABLE'S PROSE IS NOT A SOURCE: "All 56 tests pass" is a sentence about tests the same worker wrote, and weighing it is the exact defect this file exists to close.

Empty means nothing can be concluded about coverage. That is a real answer and it is the honest one for a project that declares no verification and a worker that derived no diff — a capability that cannot work is ABSENT, not broken.

func ChecklistAccount

func ChecklistAccount(outcomes []PointOutcome) string

ChecklistAccount renders the bounded account a person reads. The complete outcomes remain available to machine callers even when this block has to say how many whole lines live only on the run's own record.

func ChecklistFor

func ChecklistFor(job string) []plan.Point

ChecklistFor is what an earlier round of this job settled it would be judged against, or nothing.

func Composable

func Composable(worker exec.Executor, outcome *exec.Outcome) bool

Composable reports that the gap this gate named is about the account of the work rather than about work still to do.

All three conditions are structural facts, and none of them is a reading of the gap's words. That is the whole design: a keyword test on a critique is a judgement dressed as a mechanism, and it fails in the direction that skips real work. These fail in the other direction — a worker with nothing derived from the repository, or with an unsettled suite, re-runs exactly as it always did.

func ConstraintFinding

func ConstraintFinding(judgment Judgment) bool

ConstraintFinding says this verdict's gap is a rule the person stated being BROKEN, rather than something the request asked for being ABSENT.

The question above may not be put of one, and the difference is not a nicety: a run that produced everything the request asked for in a way the request forbade has not met the request as stated, and a reader shown the deliverable and the record would say yes. Today no judgement carries its constraints and this is always false; the change that gives a judgement its constraints is the one line that fills it in.

The seam is now filled by the constraints field on the judgement.

func ConstraintsBlock

func ConstraintsBlock(constraints []plan.Constraint) string

ConstraintsBlock is the rules a reader has to settle, put in front of the judge as the standard beside the request.

Only the ones no arithmetic could settle are here: a mechanical rule was already held above, and showing a judge a rule this gate has just cleared would invite it to convict on a second reading of an answered question. Empty — every job whose request stated no such rule — renders nothing at all.

func ConsumerFinding

func ConsumerFinding(quote string, changed []verify.ChangedDefinition) (string, bool)

ConsumerFinding is the gate line a consumer-grounded refusal gets: the definition that moved, how many places still use it and how, and where they are.

It is its own sentence rather than a paragraph inside the judge's prose for the reason every other finding in this package is one: the stream prints the first line of a gap, the journal keeps it as a field, and a finding that lives only inside somebody else's sentence is reachable by neither.

ok is false when the quote names no site this reading holds, which is a verdict grounded on something else and left exactly as it is.

func FenceDeliverable

func FenceDeliverable(deliverable string) string

FenceDeliverable puts the material the gate judges between its two markers.

It is exported because the fence is a fact about the prompt that its tests and its callers both have to be able to name, and because a second spelling of a delimiter is a delimiter that eventually stops matching. A deliverable that itself contains a fence line has it neutralised rather than the fence being renamed: the marker keeps one meaning everywhere.

func ForgetChecklists

func ForgetChecklists()

ForgetChecklists drops everything remembered. Its only callers are tests, which share a process and would otherwise inherit one another's jobs.

func GapClosedNote

func GapClosedNote(gaps, closed string) string

GapClosedNote is what a gap the run has already closed on disk gets instead of a round. It is GapNote's sibling and stops one sentence earlier on purpose: the standard was the person's own and it was met, so there is nothing to offer to redo — the file is there, and the honest thing is to say why the review's words are being delivered under rather than acted on.

func GapContinuationNotice

func GapContinuationNotice(gaps string) string

GapContinuationNotice is the whole of what a person sees when a judgement grows the job: one line, in the same calm register as the governor's, saying what is missing and that it is being finished rather than delivered around. No new noun is introduced — the user never learns that any of this has a name.

func GapHandover

func GapHandover(gaps string, revised bool, refused string) string

GapHandover is what the delivery carries when nothing more will run. It names the gap in the system's own words and says why it stopped, because the next thing the person says about it is the correction path's input and a handover they cannot see is a handover that never happened.

func GapNote

func GapNote(gaps, refusal string) string

GapNote is what an ungrounded gap gets instead of a round: the reviewer's words, said plainly, with the honest reason nothing was redone over them. It is the same register as GapHandover and deliberately not the same sentence — a reservation says the work fell short, and this says the review did.

func GateFaultHandover

func GateFaultHandover(fault string) string

GateFaultHandover is the reservation that rides the delivery when the gate faulted.

It exists for the same reason GapHandover does: a run that hands over work its own check never looked at must not hand it over in silence. What it must NOT say is that anything is wrong with the work — nobody knows, and that is the whole point — so it names the missing check and why it did not happen, never alleging anything about the work. An empty reason stays empty so an unknown renders as nothing rather than as an empty parenthetical.

func GateFaultWords

func GateFaultWords(fault string) string

GateFaultWords is the shortfall as the delivery gate's own ledger keeps it, and as the headless stream prints it. It says what did not happen — the check — and why it did not happen, never alleging anything about the work when the gate found nothing. An empty reason stays empty so an unknown renders as nothing rather than as a dangling separator.

func GateVerdict

func GateVerdict(judgment Judgment) provider.Reading

GateVerdict is what a passing gate is entitled to record.

The leaf itself never claims a verified success — the general loop has no suite it can assume, so it lands as an unverified one however well it went — and for a while a gate PASS overwrote that with the strongest verdict there is. Nothing had been checked in the sense the verdict means: one judge read one final message and found nothing missing from it. That is a success, and it is the same success the leaf already reported; only the evidenced form, where the finished thing was actually exercised, is more than that.

The two are not interchangeable in exactly one place, which is where the distinction is load-bearing: an unverified success is inert in Graded(), so a sentence can no longer move a model's ability rating. Everywhere the product counts operational success — competence rates, reflex outcomes, the self page — both already count, and they still do.

func GroundMapping

func GroundMapping(root string, record []string,
	points []plan.Point, mapping []store.ExercisedPoint,
) []store.ExercisedPoint

GroundMapping keeps only the pairings the world supports, and empties the rest.

root is the tree the delivery stands in and record is what the run left behind; between them they are how a check identity becomes a file whose text can be read. Nothing here invents a pairing — it only ever removes one — so a run with no workspace, no record and no readable file is left exactly as the judge answered it.

A POINT THAT SPELLS NO NAME IS NOT JUDGED HERE, and that asymmetry is deliberate. "Normal scrolling must still update the visible viewport" names nothing distinctive; there is no structural question to ask of it, and a door that answered "unexercised" to every such behaviour would fail every prose request this program is given — a floor that refuses everything is not a floor. The door speaks where the request spelled something, which is where a mapping can actually be wrong in a way that is checkable.

func GroundedInTheWorld

func GroundedInTheWorld(finding Judgment, evidence Evidence) bool

GroundedInTheWorld reports whether the thing a finding points at is a thing only WORK could change — a file, or a check — as opposed to the account of the work, which writing can change.

Every door below reads the RECORD and never a list of words, which is FAILSAFE clause 1. In order of what it costs:

  1. The gate already settled it against the world. A mechanical gap asked the disk for a file the plan promised; a sourced finding is a measurement the run took. Neither has an opinion in it.
  2. It names a file, under NamedFiles' own shape rule — so "docs/memo.md" is a file and "the write-up" is not.
  3. It names something the record says the run RAN. The vocabulary is the record's: a project whose suite is `cargo nextest run` and one whose suite is `pnpm test` are both recognised without either name appearing here.
  4. THE RUN LEFT A TREE BEHIND AND NOTHING SAYS THE TREE IS GOOD. This is the door that carries the weight, and it is written on the fail-safe side on purpose. A run that produced files was doing work, not writing an answer; a finding against it is a finding about that work unless the world says otherwise, and the only thing that can say otherwise is the project's own checks, run on the tree being handed over, coming back green. A red reading is the world convicting; an ABSENT reading is nobody having looked, and nobody-looked is not nothing-wrong (see store.DeliveryGate. Unmeasured, which is that same rule written down one seam along).

False — a finding whose only ground is the delivered text, which a rewritten account can honestly close — is therefore two cases, and both are ones where writing IS the work. A run that left nothing but its message: the message is the artifact, and this is §6's line reused rather than a second rule. And a run whose change the project's own checks pass, where what is wrong is the account of it: "the deliverable is a list of file paths, not the implementation itself" over a green suite is exactly what revision.Compose was built for.

func Held

func Held(points []plan.Point, grounds Grounds) []plan.Point

Held is the checklist the gate may actually hold somebody to: the points whose quotation is grounded in what this run promised before it began working.

It is the SAME invariant, read by the SAME code, that decides whether a review's finding may buy a repair round — citationGrounded, through the three doors grounding.go opens. A point the request does not carry is a requirement this system wrote for itself after reading its own prompt, and holding a worker to one is the failure the whole grounding rule exists to prevent.

It is applied where the checklist is USED and not only where it was written. A list that reached the gate down any other route — a rehydrated plan, a spliced repair, a future caller nobody has written yet — is still weighed against the person's own words before it can convict anything.

func HeldPoints

func HeldPoints(evidence Evidence, grounds Grounds) []plan.Point

HeldPoints is THE checklist this delivery is judged against: the behaviours the request states, from the spec the round carries or from the job's own remembered list, each still grounded in what was actually asked for.

It is a function because two readers need the identical answer and had been computing it in one place only. The settlement below reads it to decide what nothing exercises; the delivery gate reads it to decide which quotes a refusal may be built on (subject.go). A checklist that differed between the two would be a gate refusing a verdict for citing a behaviour the settlement was about to count.

func HoldConstraints

func HoldConstraints(evidence Evidence) []string

HoldConstraints is the mechanical half of the gate's newest law: the rules this delivery broke, each as the person's own words followed by the files the run changed in spite of them.

It is exported because it is the measurement, and the record the store keeps (store.DeliveryGate.Constraint) is exactly what it returns. Nil is the answer for every job whose request stated no mechanical rule, which is nearly all of them, and nil is also the answer when nothing was changed at all — a run told to change nothing that changed nothing has kept the rule, which is the whole point of stating it.

func MapChecks

func MapChecks(ctx context.Context, settings config.Config, client *pool.Client,
	node store.Node, points []plan.Point, checks []string, workerModel string,
) []store.ExercisedPoint

MapChecks asks which check exercises which behaviour, and returns the mapping in the order the points were given.

A call that cannot be made, cannot be read, or comes back short answers with NOTHING MAPPED rather than with everything mapped. That is the fail-safe direction for this particular question and it is the opposite of the gate's own: an unanswerable gate must not hold a finished deliverable hostage, but an unanswerable coverage question that resolved to "all covered" would silently restore exactly the behaviour this mechanism replaces. Unmapped buys a repair round; it never ships a wrong answer as a right one.

func Measured

func Measured(evidence Evidence) bool

Measured says a reading of the world exists to answer the coverage question with — that somebody looked, whatever they found.

It is the distinction the s5 sweep turned on, and the one the first version of this file collapsed. A READING THAT WAS TAKEN AND NAMED NOTHING IS STILL A TAKEN READING: the project was asked how it checks itself, it answered, and nothing it printed exercises anything the request asked for. That is a finding. Only a project that declares no verification at all, run by a worker that derived no diff, leaves the question unanswerable — and that is Unmeasured, which is a different sentence about a different fact.

func MeasuredFinding

func MeasuredFinding(verdict Judgment) bool

MeasuredFinding says this verdict rests on A MEASUREMENT OF THE WORLD rather than on a reading of the request, and it is the whole of what the question below may not be put of.

THE LAW: A MODEL'S READING MAY NOT OVERTURN A MEASUREMENT. The request-met question is one model looking at a deliverable and a record; a file the plan promised and the disk does not hold, a check that passed before the work and fails after it, a name the tree no longer binds, a behaviour nothing exercises — each of those is a fact somebody gathered, and no reading of the request is competent to overturn one. Without this the door would do exactly what the two world-doors above it are forbidden to do, and it would do it on the strength of a sentence. It is the same line store.DeliveryGate.Overturned draws and for the same reason (SETTLEMENT.md §2).

So the question is put only of a verdict that is the judge's OWN PROSE — "the deliverable is a report about the output, not the output itself" — which is a reading of the request, answerable by another reading of the request.

func NamedFiles

func NamedFiles(text string) []string

NamedFiles lists, in order and without repeats, the files a piece of text names. It is exported because the gate's caller holds the request and the gate holds the record, and the answer they need is the same list.

The shape rule itself is verify.NamedPaths and is deliberately not repeated here. Which text names a file is one question asked at three ends — which files a request is about, which decides where a reading is taken; which files a request named, which the delivery record settles against the disk; and which file a produces entry IS — and a regular expression written down twice is a regular expression that will differ.

func Observables

func Observables(text string, index verify.SurfaceIndex) []string

Observables are the identifiers a stated behaviour names — what a check would have to weigh for the behaviour to be exercised rather than merely visited.

Three shapes, and every one of them is a shape rather than a vocabulary:

  • a name somebody spelled DISTINCTIVELY, which is symbolsIn's own rule and the identical one the entailment door opens on: `is_following_end`, `RichLog.write`, `max_scroll_y`, `min_width`, `#follow-log`.
  • a name somebody BOUND to something, which is how code spells an argument and prose does not: `expand=True`, `width=40`, `follow_end(animate: bool = False)`. The name is the observable; the value is what makes it one.
  • a name of the TREE somebody spelled IN WORDS. textual s16 asked that normal scrolling still update "the visible viewport and vertical scrollbar position"; the run asserted `scroll_y` and `max_scroll_y` a hundred and six times and never touched `ScrollBar.position`, which is precisely what the two hidden checks that failed assert. "vertical scrollbar position" names `ScrollBar.position` and nothing in this program could see it. verify.SurfaceIndex.Spoken is that reading, against the tree's own public surface and only for names that have an owner.

TWO SHAPES ARE THROWN AWAY, and both because they cannot be asserted ON.

A hyphen is not an identifier character in any language this program reads, so a token whose only separator is one is an English compound: `full-width`, `half-open`, `pre-fetch`. It is re-admitted where the person wrote it as a selector (`#follow-log`) or where the tree itself declares it, because those are names. Without this the door would hold every request to a word nothing can ever assert.

And a bare TYPE name the tree declares at the top level — `RichLog`, `Log` — is what a check constructs, never what it weighs; the values it weighs are that type's members. A symbol the surface confirms as an unqualified declaration is dropped for that reason, and one the surface does not know is kept, because the request may be asking for it to exist.

A behaviour that yields none of the three names nothing a check could be asked about — "it must post only when the boolean actually changes" is a true sentence with no identifier in it — and the door below stays shut on it. That is the same asymmetry GroundMapping keeps, for the same reason: a floor that refuses everything is not a floor.

func PlanNodeFor

func PlanNodeFor(planGraph *plan.Graph, prefix, nodeID string) *plan.Node

PlanNodeFor finds the plan node one store node was minted from.

The mapping is the id scheme and nothing else: a job's nodes are minted as "<prefix>-n<planID>", except the sink, which takes the bare prefix. A sink cannot be resolved back this way — the bare prefix names no plan id — so it returns nothing rather than guessing, and a caller that finds nothing does what it did before specs existed.

func ProducedFile

func ProducedFile(named string, artifacts []string) (string, bool)

ProducedFile answers whether one named file is among the files a run left behind, and returns the path it landed at.

Which recorded path answers to a name is namedAs, which states that law once for this package because the grounding rule asks the same question of a citation and a request.

The file must be on disk and must be a file: a recorded path with nothing at it, or a directory wearing the name, is not a produced deliverable.

func RememberChecklist

func RememberChecklist(job string, points []plan.Point)

RememberChecklist records the behaviours this job is judged against, for every round of it that follows.

func RememberChecklistForRequest

func RememberChecklistForRequest(request string, points []plan.Point)

RememberChecklistForRequest is the same memory, keyed from the request itself, for the seam that has the checklist BEFORE any gate does.

It exists because the memory was only ever written by the gate, and a job whose first node never reaches one leaves it empty. ofetch s10 is that shape exactly: the planner read 47 points onto `task-2`'s spec and journaled them, `task-2` was handed over without a delivery gate, and the continuation `task-2-x1` — planned afresh, so carrying no `Accept` — reached the only gate of the run with no checklist at all. Its event holds `pass: true` and nothing else: no mapping, no finding, no `unmeasured`. The coverage question was not answered wrongly; it was never asked, and the run left at 42 of 47.

THE CHECKLIST IS A READING OF THE REQUEST, so the moment it is read is the moment it can be remembered, and every round of the job — gate or no gate — inherits it from there.

func RememberUnexercised

func RememberUnexercised(job string, open, weak []string, stated int)

RememberUnexercised records what the LAST MEASUREMENT of this job found nothing exercising — including the empty answer, which is the news that a round closed the gap and is exactly what must not be lost.

func RepairClosed

func RepairClosed(rejudged, finding Judgment, evidence Evidence, unmoved bool) bool

RepairClosed answers, in one place, whether the single repair round a failed gate bought actually closed it.

Three facts settle it, asked in the order of what they cost. The re-judgement has to have HAPPENED and to have passed — an unreadable second verdict is a gate that did not run, never an abstention, which is the rule Judgment.Fault exists for. And then the one this function was extracted for: a round that moved nothing may not close a finding the world is the ground of.

It is a function rather than an expression at the wiring seam because it had been an expression at the wiring seam, and the rule it now states was not visible there to be got wrong. Every reader of "did the repair close it" reads this and there is no second copy — see cmd/codeaf/chat.go, its only caller, and docs/design/gate/SETTLEMENT.md §8.

func RequestMet

func RequestMet(ctx context.Context, settings config.Config, client *pool.Client,
	node store.Node, grounds Grounds, deliverable string, evidence Evidence,
) (met bool, words string, asked bool)

RequestMet puts the question and reads one word back.

asked is false wherever there was no answer to read — no client, no request, a call that failed, a reply that could not be parsed. THE FAIL-OPEN DIRECTION IS THE EXISTING PATH: a question nobody could answer must leave the run exactly where it was, buying the round it was going to buy, because the alternative is a delivery ended as satisfied on the strength of a provider timeout.

words is the receipt on a yes — the same sentence wherever it is set — and on a no it is what the question found absent, in the request's own words. One return rather than two because exactly one of the two is ever true of an answer, and a caller holding both would have to decide which it was looking at from the boolean it already has.

func RequestMetNotice

func RequestMetNotice(receipt string) string

RequestMetNotice is the one line a delivery's own record carries when the run ended because what was asked for is in hand.

It sits exactly where a reservation would have been written and it is the same length, because the two are the same fact answered the two ways: this says the work is finished, GapHandover says what it is short of. A receipt nobody can read is a receipt that was never issued (FAILSAFE clause 3).

func RequestQuestionable

func RequestQuestionable(verdict Judgment) bool

RequestQuestionable says the question may be put of this verdict at all. It is one function so that both doors and every future one read the same law rather than each spelling their own half of it.

func ReshapeDelivery

func ReshapeDelivery(ctx context.Context, settings config.Config, client *pool.Client,
	node store.Node, deliverable string) (string, bool)

ReshapeDelivery repairs a deliverable that came back as a data object, once, before anything is judged.

It is here rather than at the wiring seam because the delivery law is this package's — the gate is what holds a worker to the shape it was asked for — and because both doors that judge a deliverable reach it through one call. The journal is the caller's, on the context, exactly as every other repair's is: a run that reshaped its answer says so against the node it belongs to.

func RetargetAdds

func RetargetAdds(planGraph *plan.Graph, failed *plan.Node, operations []plan.Operation) int

RetargetAdds re-aims a failed node's spec onto every node the sentinel added after it failed, before those nodes are mirrored into the store.

It runs on the plan document, which is where a node's spec lives and where the sentinel has just written its additions, and it writes three fields on each: the spec itself, the brief that is still the executor's read, and the working method, which a replacement inherits for the same reason it inherits the criterion — how this kind of work is done well is a fact about the work, not about the attempt.

It is deliberately narrow. Only a node the sentinel added while reacting to a FAILED node is a replacement; a node added because a landed result taught the job something new is new work, and giving it someone else's criterion would be inventing a requirement rather than preserving one.

func RetargetSpec

func RetargetSpec(original plan.Spec, aim, failure string) plan.Spec

RetargetSpec carries a failed node's spec onto the node that stands in for it.

This is the §6 defect closed structurally. The retry path used to author a brand-new node out of failure context — the sentinel names a title and a summary, and the store's brief falls back to those two lines — so the module name, the filename, the type names and the acceptance check the original spec carried were all simply gone by the second attempt. Nothing was truncating them: nothing was carrying them.

The rule the object makes enforceable is that a re-target may re-aim and may not re-author. Done and Sources travel verbatim, because they are what the work is judged against and what it must touch, and neither changed when the attempt failed. Method travels too, unless the replacement brought its own. Only Instruction is written to, and only by addition: the original words, then what happened, then what is now being asked for on top of them.

func Sentinel

func Sentinel(ctx context.Context, settings config.Config, client plan.Completer,
	graph *store.Store, node store.Node, prefix, root string, planGraph *plan.Graph,
	event, workerModel string, journal func()) int

Sentinel is the pass that reads one landed result against a job's remaining plan and edits the plan only where the result contradicts a specific assumption in a specific node. Its default is no change; the plan package refuses everything else, and the store refuses the same edits again on its own authority.

It does not own the locks. The plan document belongs to whoever retained it, and the arrangement that matters — hold the lock while the plan is rendered and again while the answer is applied, hand it back for the round-trip in between — is expressed by the client the caller passes in. Everything here runs inside whatever the caller is already holding.

journal is called exactly where the caller used to call it: after the edits land and before anything is said about them, because the journaled structure is behind the in-memory graph the moment a revision applies. It returns how many operations landed, so a caller that would rather journal for itself can.

func SpentCitations

func SpentCitations(graph *store.Store, baseID string) []string

SpentCitations is the ledger: the spans of the ask that earlier rounds of this job already commissioned work against AND GOT NOTHING FOR. A read failure returns nothing, which is the fail-safe direction for a bound on new work only in company with the round cap — which is exactly what that cap is for.

The second half of that sentence is the change, and it is what turns a count into a measurement. Spending words on a round that moved nothing is what the bound exists to stop happening twice; spending them on a round that rewrote half the repository and still left the thing genuinely undone is the system working, and refusing the next round over it is a count of one wearing an invariant's clothes. The growth journal already records, per round, how many files the work actually left behind (store.JobGrowth.Produced, with Measured saying somebody looked) — so the evidence exists and was simply not being read here.

EVERYTHING UNKNOWN IS SPENT. A round with no journal row, a row nobody measured, or a row that measured zero all leave their citations on the ledger. That keeps the bound's direction unchanged wherever the evidence is missing, and it means this can only ever release words the journal positively says were productive.

func TreeStamp

func TreeStamp(artifacts []string) string

TreeStamp is the world at one moment, in the one dimension a repair round has to be asked about: did anything under the run's own record change?

It is size and modification time per path, over the artifact record the gate is held to, folded to a digest. Content hashing every artifact would be the same answer at many times the cost — a repository's build output alone is megabytes — and size-and-mtime is what every build system in existence trusts for this question. A path that has gone missing stamps as missing, which is a change and the loudest kind.

An empty record stamps as empty, and two empty stamps compare equal. That is the honest reading: a run with nothing in its record has no tree for a repair to move, so nothing here can convict it — and the delivered text is then the whole of what it produced, which is exactly the case the law leaves alone.

func UnexercisedFor

func UnexercisedFor(job string) (open, weak []string, stated int)

UnexercisedFor is the finding this job is still carrying: what a measurement found nothing exercising, and how many behaviours were weighed to find it.

func WeighAssertions

func WeighAssertions(root, job string, record []string,
	points []plan.Point, mapping []store.ExercisedPoint,
) []store.ExercisedPoint

WeighAssertions marks each mapped pairing whose check asserts none of the behaviour's observables, and changes nothing else.

It runs AFTER GroundMapping and never instead of it: a pairing the names door already emptied has no check to read, and the two doors answer different questions about the ones that survive it. The row keeps its check — the check is real, it does map, and hiding that would lose the evidence — and carries the observables nothing weighed, which is what makes the point weakly exercised downstream.

ONLY THE CHECKS THIS RUN WROTE ARE READ. A check the repository already had is not this run's account of its own work, and holding a project's existing suite to a request it was written years before would fail every delivery that reuses one. The run's own record says which files are its (verify.OwnChecks), and a check outside them is left exactly as the mapping answered it.

Types

type Composition

type Composition struct {
	Text  string
	Usage exec.Usage
	Model string
}

Composition is one composed deliverable and what it cost. Text empty means nothing was composed and the caller keeps what it had — which is the only failure mode here, and it is deliberately not an error: a compose that cannot be reached must leave a finished, landed, verified piece of work delivered.

func Compose

func Compose(ctx context.Context, settings config.Config, client router.Client, node store.Node,
	method string, gaps string, outcome *exec.Outcome, said string, workerModel string,
	options ...Option) Composition

Compose writes the deliverable from the substrate account, the patch and the worker's own last word.

It takes the client rather than the executor because it must not be able to run anything: the guarantee this whole path rests on is that the tree is not touched, and a function with no worker in it cannot touch a tree.

type Evidence

type Evidence struct {
	Artifacts []string
	// Swept is what the workspace walk answered a NAME with: a file carrying a
	// name the request or plan spelled that the run's own record of what it left
	// behind does not hold. It is kept apart because one list was answering two
	// questions, and answered "what did this run change" wrongly for the run of
	// 2026-09-03 that made 156 shell calls, wrote nothing, and was refused over
	// `CLAUDE.md` — a file its contract had told it to READ.
	//
	// Nil on every delivery whose sweep found nothing, which is nearly all of
	// them.
	Swept []string
	Ran   []string
	// Named is what the request itself named as a file, in the person's own
	// spelling. It is the half of the record the gate could never check: a
	// judge holding only prose was asked whether the finished thing exists,
	// could see no further than the sentence claiming it does, and answered
	// from the sentence — in both directions. It failed a delivery for not
	// retyping a file that was on disk, and it passed one that claimed a file
	// was "written and verified" when nothing of that name had been written at
	// all. Rendered against Artifacts and Swept, each name settles itself without
	// turning the workspace's answer into a change the run made.
	Named []string
	// Done is the criterion the plan stated before the work started: what this
	// leaf was to produce and the checks that settle it. It travels verbatim
	// through retries by construction (plan.Spec), so it is the one standard
	// here that the run cannot have moved, and it belongs beside the record it
	// is settled against rather than in the prose above it.
	Done plan.Done
	// Observed says the run was watched from beginning to end, which is the
	// only thing that turns two empty slices into a fact. Without it the gate
	// could not tell "this leaf did nothing" from "nobody was recording", and
	// it was told in the same breath that silence never acquits — so a run that
	// called no tools and answered with a plan read to the judge as an honest
	// answer whose evidence was simply not available, and passed. It is a field
	// rather than an inference because only the caller holding the outcome
	// knows which of the two it has; every real delivery sets it, and the unit
	// tests that construct a bare Evidence deliberately do not.
	Observed bool
	// Baseline is what was already broken before this work began, in the words
	// of the only thing that measured it. A coding worker photographs the
	// repository's own checks before it starts, so when a check comes back red
	// it can say whether the change caused it; nothing else in the tree can,
	// and the judge least of all — it holds prose and a file list, and cannot
	// run anything.
	//
	// Without it the gate read a suite's absolute state as a verdict on the
	// change: a repository carrying one pre-existing red test failed every
	// correct patch that passed through it, four times out of four on the
	// measured battery (audit-notes §14.4.1). It is stated as fact rather than
	// as an excuse, and it acquits only what it names.
	Baseline []string
	// Regressed names the project's own checks that PASSED BEFORE this work and
	// FAIL AFTER it, in the words the runner printed them in.
	//
	// It is Baseline's opposite number and the half that convicts. Baseline
	// acquits what was already red; this names what this work turned red, and it
	// is the one finding on this whole record that no citation could ever be
	// weighed for — a person does not have to ask for their repository to keep
	// working. See Regressions, which raises it as a finding of its own, and
	// Judgment.Sourced, which is what lifts it clear of the citation invariant.
	//
	// Nil on every worker that cannot take two readings of the project's own
	// command, which reads as no claim.
	Regressed []string
	// Removed names the PUBLIC names this work deleted: a name the tree spelled
	// before the job's first change and does not spell now, in the files the
	// run's own record says it changed.
	//
	// It is Regressed's other half. A check that goes red is the suite noticing;
	// this is what the suite structurally cannot notice, because a project only
	// has checks for what somebody wrote checks for. See RemovedPublicNames and
	// verify.Surface.
	//
	// Nil on every worker that cannot take two readings of the tree, which reads
	// as no claim.
	Removed []string
	// OwnFailing names the red checks that first appeared AFTER the baseline —
	// the ones this run wrote itself and did not get passing. See
	// OwnChecksFailing, and verify.Reading.OwnFailing for why it is not a
	// regression.
	OwnFailing []string

	// Unbound is what the LEAF measured of the same question the gate re-takes
	// for itself: names the run's own sources read that nothing in the tree
	// binds, already worded (verify.UnboundWords). The gate reads it only
	// where it has no workspace of its own to re-read — which is the same place
	// removedSinceTheJobBegan leaves the leaf's answer standing, and for the
	// same reason: a measurement nobody could re-take is still a measurement.
	Unbound []string
	// Account is the worker's own structured account of the work: the files it
	// changed, with the kind and size of each change, and the checks it ran
	// with what each one found.
	//
	// It is the other half of the same correction Baseline made. A worker that
	// drives a whole pipeline behind a process boundary used to hand the gate
	// one sentence, and when the pipeline ended without a verdict the sentence
	// said only that it had ended — so the gate judged a void and answered
	// differently each time it was asked. The account is that void filled with
	// what the worker actually observed, and it arrives as rows, beside the run
	// tail, in the same grammar: facts the judge could not gather for itself,
	// and no instruction about what to make of them.
	//
	// Nil on every leaf whose worker cannot photograph its own change set,
	// which is nearly all of them, and nil reads as no claim.
	Account *exec.Account
	// Patch is a path to the whole text of the change the work made, when the
	// worker could derive one from the repository.
	//
	// It is the difference between a record of NAMES and a record of CONTENT,
	// and the gap between the two was measured as a false statement shipped to a
	// person. A leaf was asked to explain a root cause; its method — written
	// before the work ran, by a pass handed nothing but file paths — offered an
	// illustrative example of what a root cause might be; the leaf shipped that
	// example verbatim as the real one; and this gate passed it, because
	// everything it held said which files changed and nothing said what the
	// change was. A judge that can read the diff can convict that claim, and can
	// equally absolve a correct one it would otherwise have had to guess at.
	//
	// Empty on every worker that produces no diff, which reads as no claim.
	Patch string
	// Accept is the acceptance checklist: the behaviours the person's REQUEST
	// states, read from the request before any work existed and carried on the
	// plan's spec. It is what the gate holds the delivery to beyond "does this
	// read like an answer", and it is the one thing on this record that was
	// neither produced by the work nor written about it.
	//
	// Empty on every job whose request states nothing checkable, which is most
	// of them, and empty reads as NO CHECKLIST rather than as nothing asked for.
	Accept []plan.Point
	// Constraints are the rules the person's REQUEST states about what the run
	// may or may not DO, in their own words, carried on the plan's spec.
	//
	// They are Accept's other half and they answer to a different question.
	// The checklist is what the finished thing must DO; a constraint is what the
	// run may not do on the way there, and no reading of a deliverable can
	// settle it — only the list of what the run changed can. The mechanical
	// kinds are held here before a judge is bought (HoldConstraints); the rest
	// are shown to the judge as the standard beside the request.
	//
	// Empty on every job whose request stated no rule, which is most of them,
	// and empty reads as NO RULE rather than as a rule nobody could check.
	Constraints []plan.Constraint
	// Verification is the photograph of the project's own checks the run took —
	// the roster before the work and the roster after it, on the budget PERF.md
	// states. The gate reads it instead of reading the deliverable's sentence
	// about its own tests: a claim that "all 56 tests pass" is a claim about
	// tests the same worker wrote, and weighing it is how two graded runs ended
	// at exit 0 over wrong answers (docs/design/gate/ACCEPTANCE.md).
	//
	// A zero value is a photograph nobody took, which stops the acceptance
	// settlement rather than convicting anything: NOBODY LOOKED IS NOT NOTHING
	// WRONG, and it is not a finding either.
	Verification verify.Reading
	// Workspace is where the work happened, and it is here for one purpose: the
	// gate may need to take the after reading itself. A worker that took no
	// second photograph — a repair that only rewrote the account, a leaf whose
	// wall could not afford one — leaves the final tree unmeasured, and the
	// reading of the tree that is about to be handed over is the gate's to hold.
	//
	// Empty means the gate takes no reading of its own, which is what every
	// caller that has no workspace to name already gets.
	Workspace string
}

Evidence is what the gate can hold a claim against: what the leaf left behind and the tail of what it actually ran. Both already existed — the artifact list is resolved for three other readers a few lines above the gate call, and the run tail is recorded by the executor as it goes — so the gate stops being a judge of prose for the price of passing two slices.

func (Evidence) MissingPromised

func (e Evidence) MissingPromised() []string

MissingPromised is those of them the workspace does not hold, settled against the disk by the same rule the mechanical gate uses.

func (Evidence) PromisedFiles

func (e Evidence) PromisedFiles() []string

PromisedFiles is every file this delivery was told to produce, in the spelling it was told in: the plan's own structured produces list, and the files the person named in the request.

ONE LIST, BECAUSE A JUDGE NAMING AN ABSENT DELIVERABLE MUST BE ABLE TO NAME IT WHATEVER PROMISED IT. The two halves are already both in front of the judge — the criterion above the fence, the named-files block below it — and until igel s15 neither was nameable in a verdict, because neither is in the record of what the run left behind. That is the point of them: the finding is that they are not.

func (Evidence) Subject

func (e Evidence) Subject() Subject

Subject answers which of the two this delivery is, from the artifact record settled against the world.

The stat in recordFiles makes the run's record an observation of the tree rather than only an account of what leaves reported. The named-file sweep would make that observation a lie if it joined the record: a file the request named is not a file the run changed, so that answer is kept in Swept instead. A record naming files none of which are on disk is a record of nothing, and it answers claim: the fail-safe direction here is the one that keeps the worker's own words in front of the judge when there is nothing else to show it.

func (Evidence) SubjectWords

func (e Evidence) SubjectWords() string

SubjectWords is the subject as the record keeps it and a person reads it: what was judged, and how much of it. "tree (6 files)" and "claim" are the two shapes, and the count is there because a tree of one file and a tree of forty are different runs and the same word.

type Extension

type Extension struct {
	Spliced int
	// Met says the one question was put at this door and came back yes: the
	// request, as the person wrote it, is satisfied by what is in hand, so no
	// remainder was bought and none was owed. Refused then carries the receipt
	// rather than a refusal, and Unclosed is false — the gap did not survive,
	// it was answered.
	//
	// The gate's own caller asks the same question one door earlier and passes
	// the delivery there, so it never sees this. It is here for the callers
	// that reach the extension without going through that door.
	Met bool
	// Quote is the citations as one line, and Citations is the list the
	// admission rule actually weighed. They travel together for the same reason
	// they do on a Judgment: the ledger that bounds the next round reads the
	// list, and everything that shows a person what was cited reads the line.
	Quote      string
	Citations  []string
	Round      int
	Refused    string
	Mechanical bool
	// Cause is the growth governor's machine-readable word for WHICH governor
	// refused, verbatim from resident.GrowVerdict, and empty when nothing
	// refused. Refused above is what a person reads; this is what a decision is
	// made from, and the two are separate fields because a decision read out of
	// a sentence is a decision that breaks when the sentence is reworded. See
	// resident.GrowthStopped, which is the only thing allowed to turn one of
	// these words into an ending.
	Cause string
	// Unclosed says the gap is still open: the repair was refused for want of
	// money, rounds or a planner, rather than because the gap itself was found
	// inadmissible. See store.DeliveryGate.Unclosed for why the difference is
	// the one the exit code reads.
	Unclosed bool
}

Extension is what a gate's judgement was allowed to do about a gap that survived the revision pass: the work it commissioned, the words it cited, the round it was, and — when nothing was commissioned — why, in the words the user would be told.

func ExtendForGap

func ExtendForGap(ctx context.Context, graph *store.Store, node store.Node, partial string,
	unmet Judgment, artifacts []string, dailyBudgetUSD float64,
	planRemainder resident.OverrunPlanFunc, records ...string) Extension

ExtendForGap is the authority the delivery gate never had.

The judgement at the job root was already the right one and its maximum power was to re-run the same leaf once and then ship regardless; meanwhile the only mechanism that can grow a live job fires on running out of money and never on being wrong. Quality failure and resource failure were handled by two disjoint mechanisms and only the resource one could add work. This is the wire between them, and it is short because ReplanOverrun already handles everything hard: the round counter is read off id arithmetic, the daily rail defers and resumes, the job-size ceiling and the round cap post their own notices, and a repair on a top-level job continues as a top-level job that will be announced like any other deliverable.

What arrives here is a named gap, so the replan is aimed at a remainder a reviewer found rather than at whatever sounds like more work — and the goal it is planned from forbids inventing verification, as the plan's own proportion rule forbids a node whose purpose is to check another's product. Assurance may add work that closes a gap; it may never add work that checks one. records, when there are any, are files the finished work left behind that the remainder must READ rather than reuse — the text of the change it made, above all. They travel apart from the artifact list because a remainder handed only paths cannot learn what the work it is continuing actually did, and a leaf asked to state such a fact with no way to obtain it states something else.

type Grounds

type Grounds struct {
	// Intent is the person's verbatim request.
	Intent string
	// Method is the working method this kind of work was held to, written
	// before anything was produced.
	Method string
	// Done is the compiled plan's stopping criterion: what this work promised
	// to produce and the checks that settle it. It is structured, and it is the
	// same structure the mechanical half of the gate emits its citations FROM
	// (see MissingProduces) — so a gate that named a promised output and an
	// invariant that could not see the promise were two components disagreeing
	// about one fact.
	Done plan.Done
}

── what a review's finding is weighed against ───────────────────────────────

A gap is what the person asked for and did not get. The rule that decides whether a review may buy work over one has always been a provenance check — are the words it claims to be a failure of somebody's but its own — and for a long time it asked that question of ONE piece of text, in ONE way: is this finding a contiguous verbatim run of characters inside the request.

Measured over ten headless runs, that question refuses the right answer more often than the wrong one. Seven of ten refused findings were quotations of the request with a middle skipped; two more quoted the working method, which one door of the rule already accepted and the other had never been told about. Every one of them named work the run had genuinely promised and not done, and each refusal delivered the shortfall as done. See docs/design/gate/SETTLEMENT.md.

GROUNDS ARE THE PROMISES THIS RUN MADE BEFORE IT BEGAN WORKING. Three things answer to that and nothing else does: the person's own request, the working method the leaf was held to, and the compiled plan's stopping criterion. All three were fixed before a word was produced, so none of them can have moved in response to what the work turned out to be — which is the whole property the invariant is protecting. The compiled goal, the working decisions and the last round's output are codeaf talking to codeaf, and a finding that can only quote those is a preference rather than a failure.

One value, read by both doors. The revision round and the extension used to weigh a finding against different ground sets, which is how a run could pay for a repair against a standard and then be told the same standard was an invention.

func (Grounds) Empty

func (g Grounds) Empty() bool

Empty reports that this run promised nothing anybody wrote down. A finding weighed against nothing is refused, which is the fail-safe direction: the rule bounds new work, and a bound that admits everything when it knows nothing is not a bound.

type Judgment

type Judgment struct {
	Pass bool
	Gaps string
	// Quote is the citations as one line: the display half, and what every
	// surface that shows a gap to a person or keeps it as text has always read.
	// It decides nothing. Citations is what the admission rules weigh, and the
	// two are written together so a reader of either is looking at one gap.
	Quote string
	// Citations are the spans of the user's own request the gap is a failure
	// of — one per thing the review says is missing. They are what buys the gap
	// authority over the job: a gate may re-run one leaf on any named gap, but
	// it may only grow the graph for a gap that quotes the ask.
	//
	// It is a list rather than one string because the two halves of this gate
	// name gaps differently and one invariant has to hold for both. A model
	// judge answers with a single verbatim span, so its list has one element and
	// is weighed exactly as it always was. The mechanical half names every file
	// the plan promised and the disk does not hold, which is one citation per
	// file; flattened into a comma list and handed to a rule asking "is this one
	// substring of the ask", it could never be admitted, and a gate reporting
	// five files the person had themselves listed was refused as an invention
	// while the leaf that wrote none of them was delivered as done. The list is
	// the fix, and it costs the convergence argument nothing — see
	// AdmitGapCitation, where every element is held to the same test the single
	// span was.
	Citations []string
	// Mechanical says the gap came from MissingProduces rather than from a
	// judge: a file the plan named as a deliverable is missing or empty on disk.
	// It travels because a refusal means two different things on either side of
	// it. Refusing a model judge's citation says the gate was wrong, and a run
	// whose only complaint was wrong delivered whole. Refusing a mechanical
	// citation says only that no repair round will be bought — the absence it
	// reports is a fact about the filesystem, which no admission rule is
	// competent to overturn. See deliveredWhole in cmd/codeaf/do.go.
	Mechanical bool
	// Grounds are the promises this run made before it began working, and they
	// travel on the judgement because every rule that weighs this gap must weigh
	// it against the same three things. They were assembled at two different
	// seams from two different sets of fields for a while, and the measured cost
	// of that was a finding admitted by the revision door and refused by the
	// extension door one round later — the same asymmetry FAILSAFE names in the
	// row about the mechanical gate and the citation invariant.
	Grounds Grounds
	// Sourced says this finding is a MEASUREMENT OF THE WORLD rather than a
	// reading of the request, and it is what lifts a finding clear of the
	// citation invariant altogether.
	//
	// A regression is the case it exists for. A check that passed before the
	// work and fails after it is a fact the run gathered for itself, and there
	// is no span of the request to cite because the person never had to ask for
	// their repository to keep working. Grounding such a finding would refuse
	// it every time, which is the shape of the two runs that shipped a patch
	// deleting an attribute the repository already had. See FAILSAFE clause 2.
	Sourced bool
	// Exercised is the gate's separate answer about evidence: it saw the
	// finished thing run the way it will be used, and hold. A pass without it
	// is a pass — it is simply not a verified one, and the difference is the
	// whole reason the field exists rather than being read out of the prose.
	Exercised bool
	// Exercises is the acceptance mapping this judgement was settled on: one
	// row per behaviour the request stated, naming the check that exercises it
	// or naming nothing. It travels so the mapping can be journaled — the
	// mapping is the evidence and the finding is only its conclusion, and a run
	// that passed with every point covered must be tellable apart from one that
	// passed because there was no checklist. See acceptance.go.
	Exercises []store.ExercisedPoint
	// Unexercised is the acceptance finding as a LIST rather than as a
	// paragraph: one entry per line of the request whose behaviours no check
	// exercises, already grouped and already bounded (see Unexercised).
	//
	// It is a field of its own because the finding kept arriving as prose glued
	// onto somebody else's gap, and prose glued onto a gap is invisible three
	// ways at once. igel s6 mapped seventeen points, left three unexercised, and
	// the run's whole record of that is a paragraph in the middle of the gate
	// event's `gap` string: nothing journaled it as a finding, the stream's own
	// line is firstLine(gap) and never reached it, and the round it bought was
	// bought on the judge's citation, so a refusal of that citation took the
	// measurement down with it.
	//
	// It travels beside Gaps rather than instead of it, and it is set on a
	// FAILING verdict too — the acceptance question is asked on every verdict,
	// and a run that failed for a missing file is not a run whose stated
	// behaviours are covered.
	// OwnFailing is the checks THIS WORK WROTE that are red — a leaf that has
	// not finished, and never a repository that was broken. It is a list of its
	// own so the stream can say it and an autopsy can find it without reading a
	// paragraph out of the middle of the gap, which is the same reason
	// Unexercised is one. See OwnChecksFailing.
	OwnFailing  []string
	Unexercised []string
	// Unasserted is the other half of the same finding as a list: the behaviours
	// a check NAMES and no assertion WEIGHS, each already carrying the
	// observables nothing asserted. It is a field of its own for the reason
	// Unexercised is one — a finding that travels as prose inside somebody
	// else's gap is journaled by nothing, said by nothing, and taken down by a
	// refusal of a citation it has no part in.
	Unasserted []string
	// Stated is how many behaviours were weighed to reach Unexercised, so the
	// finding can say what a repair round most needs to know: how much of the
	// checklist is still open, out of how much there was.
	Stated int
	// Unmeasured says this judgement held an acceptance checklist and could
	// settle none of it, because nothing in the project's own verification and
	// nothing in the change could be read as a check. It is separate from
	// Unjudged, which says the GATE never answered: here the gate answered and
	// one half of its question had no evidence to answer from.
	Unmeasured string
	// Unreadable says the project DECLARED a way of checking itself and this run
	// could not read it — a suite killed at its ceiling, a shell the preamble
	// cannot be trusted in, a wall that could not afford the reading.
	//
	// It is the half of Unmeasured that must not deliver as whole, and the two
	// were one field. ink s7 journaled its cut reading correctly — `npx ava
	// --tap` killed at 1m53s — and then passed the round-2 gate over a tree with
	// no roster at all and left with exit 0 at 13 of 25 hidden checks. A project
	// with NO verification leaves the coverage question unanswerable and nobody
	// is at fault; a project with a suite nobody could read leaves it unanswered,
	// which is FAILSAFE clause 5 — a floor that cannot deliver nothing as done.
	// See store.DeliveryGate.Whole.
	Unreadable bool
	Checked    bool
	// Unjudged names, in one line, why there is no verdict behind this value.
	// Every failure of the gate itself is fail-open — the deliverable ships —
	// and for as long as that was the whole of it, the cheapest bug in the
	// system was also the most expensive: a judge that answered with nothing
	// passed the work, and the pass was indistinguishable at every later
	// surface from a judge that read the deliverable and found it whole.
	// Checked already said "no verdict"; this says which way it failed, so the
	// silence is legible rather than merely absent. It is deliberately not a
	// fail-closed switch: flipping the default is a behaviour change and it is
	// not this wave's.
	Unjudged string

	// Fault names, in one line, why this gate call produced NO VERDICT AT ALL —
	// and it is set only where that is the gate's own failure rather than the
	// weather's. Its one reader ends the run short of whole.
	//
	// It is a separate field from Unjudged because the two mean opposite things
	// to a person. Unjudged is "the work ships and nobody read it", which is a
	// pass. Fault is "the reader was there and could not speak", which is not a
	// pass and not a gap: it is a hole where the run's own check should have
	// been, and a run with a hole in its check has not been shown to be whole.
	// See faulted, and FAILSAFE.md's floor.
	Fault string

	// Subject is what this gate held between its fence markers, in the words
	// the record keeps: "tree (6 files)" or "claim". See subject.go.
	//
	// It is carried on the judgement rather than recomputed by the wiring
	// because the two would answer differently the moment anything about the
	// record moved between them, and the whole value of the field is that an
	// autopsy can trust it: three refusals of one run described a sentence
	// while the tree held 42KB of changed Python, and nothing anywhere said
	// which of the two had been read.
	Subject string

	// File is the one file of the record this finding is about, in the record's
	// own spelling. Empty on a pass, on a claim-subject finding, and on every
	// mechanical judgement that is already about a named file of its own.
	File string
	// HeldPoint is the behaviour of the request this verdict was held to, in
	// the record's own words: the span a refusal was built on, the size of the
	// list a pass was weighed against, or HeldPointEmpty where the request
	// states none and the requirement was off.
	//
	// It exists because the quote alone cannot say which. textual v4-flash s13
	// journaled two gates whose subject and quote were both right, and no
	// reader could tell whether the quote had passed the checklist enum or
	// there had been no checklist at all — which are the mechanism working and
	// the mechanism absent, wearing the same event.
	HeldPoint string

	// Consumers is the finding the changed-definition reading produced: one line
	// per definition this run reshaped that the rest of the project still uses,
	// naming the shape its callers expect and how many of them there are.
	//
	// It is a field of its own for the reason Unexercised and Unasserted are:
	// a finding that travels as prose inside somebody else's gap is journaled by
	// nothing and reachable by nothing. See consumers.go.
	Consumers []string

	// Unbound is the finding the unbound-reference reading produced: one line
	// per name the run's own sources READ that nothing in the tree binds, each
	// carrying the file and line it is read at.
	//
	// It is a field of its own for the reason Consumers is, and the name is the
	// whole point of it: igel s14's gate could say the run's checks were red and
	// could not say that `temp_post_req_data_path` was the name they were red
	// about. See unbound.go.
	Unbound []string

	// Constraint is the finding this gate's newest law produced: one line per
	// rule the person SET that this work broke, their own words followed by the
	// files the run changed in spite of them.
	//
	// It is a field of its own for the reason Unbound and Unexercised are, and
	// for one more that is its alone: it is the only finding here that no round
	// may be bought against. Every other gap can be answered with more work;
	// this one says the work did the thing it was forbidden to do, and more of
	// it is not the answer. See ExtendForGap, which refuses before anything is
	// planned, and store.DeliveryGate.Whole.
	Constraint []string

	// Finding names WHICH MEASUREMENT this gap is, in one stable word, and
	// Cited above holds the things it names. Empty for a model judge's verdict,
	// which is a reading of a request and not a measurement of the world.
	//
	// It exists because a finding's identity has only ever been its SENTENCE,
	// and a sentence is not a structure. A reader asking "is this the same
	// finding the last round raised" — the governor deciding whether a repair
	// round bought anything, an autopsy counting how many times one mechanism
	// fired — has had to compare prose that carries a bounded list of names
	// glued into the middle of it. happy-dom's v4-flash s13 raised the identical
	// removed-checks finding on four consecutive rounds and nothing in the
	// record could say so. The pair is the comparable thing: this kind, and the
	// names.
	Finding string

	// Receipt is the positive sentence this delivery earned, in the words the
	// person reads: that the request was met exactly as it was stated, or that
	// the work's own checks ran and settled while coverage could not be
	// measured. Empty is the ordinary case and says nothing either way.
	//
	// IT IS THE ONE FIELD ON THIS VALUE THAT IS NOT A COMPLAINT. Everything
	// else here names something wanting, and a run that ends because the thing
	// asked for is in hand had no way to say so — so "the plan ran out" and
	// "the request was met" reached the person as the same silence, and the
	// silence was spelled `partial`. It is deliberately NOT read by
	// store.DeliveryGate.Whole: a receipt says why the run stopped, and whether
	// the delivery is whole is still settled by the pass, the repair and the
	// world-doors exactly as it was.
	Receipt string

	// RequestAsked says the one question — is this request, as the person wrote
	// it, satisfied by what is in hand — has already been put for this verdict.
	//
	// It travels because the question has two doors and one price. The gate's
	// caller asks before it buys a repair round; the extension door asks before
	// it buys a remainder; and a gate that asked and was told no must not pay
	// for the same answer twice on the way to the same conclusion. See
	// RequestMet, and satisfied.go for the whole of it.
	RequestAsked bool

	// Request is that question, carried as the ability to ask it.
	//
	// A FUNC ON A VALUE IS UNUSUAL HERE AND IT IS THE CHEAPER OF TWO EVILS. The
	// question needs a model client and a settings object; the two doors are in
	// two packages and only the gate's caller holds either; and the alternative
	// was widening ExtendForGap's signature at every call site — including six
	// in tests — for a door that today has exactly one caller. Nil is the
	// ordinary case and means this verdict cannot ask, which is how every
	// caller that never set it already behaves.
	Request RequestQuestion

	// Fallback says this verdict was reached under the CLAIM contract after the
	// tree contract could not be answered — free text where there were enums —
	// or that the mechanical gate settled it after no verdict could be read at
	// all. It is journaled as the subject, because the subject is what an
	// autopsy reads to learn what the gate was actually holding, and a verdict
	// reached under a narrow contract and one reached under a loose one are two
	// different events wearing one word. See judgeDeliverable's fallback ladder
	// and igel s15.
	Fallback bool
}

func ConstraintQuoted

func ConstraintQuoted(judgment Judgment, constraints []plan.Constraint) Judgment

ConstraintQuoted stamps a MODEL JUDGE's refusal that turns out to be about a rule the person set, so that it is treated as one.

The mechanical door above settles the two readings arithmetic can settle and returns before a model is bought. Everything else — "don't use the network", "keep it under two hundred words", "don't delete anything" — is shown to the judge as the standard beside the request, and the judge can and does convict on it. Until this, such a verdict was an ordinary gap: it bought the repair round and it bought the remainder, which is precisely the thing a broken rule may never buy. The finding was the right one and only its KIND was wrong.

The match is the containment rule this program already uses for a behaviour (behaviourNamed), and it runs one way for the same reason: a quote that is part of a stated rule is that rule, quoted shorter, and a model asked for a verbatim span may reasonably give less than the whole of one. A quote that CONTAINS a rule is a longer span of the request that happens to have a rule inside it, and reading that as a broken rule would refuse rounds for gaps that are nothing of the sort.

Only ConstraintOther is matched, and that is not an oversight. A mechanical rule was already held above and found KEPT — that is why there was a model round at all — so a judge convicting on one is convicting on a question this gate has already answered against it, and the honest reading of that verdict is whatever else it says.

func ConstraintsHeld

func ConstraintsHeld(evidence Evidence) (judgment Judgment, ok bool)

ConstraintsHeld is that measurement as a verdict, in the shape every other mechanical finding in this file takes, so the flow the gate already owns runs on it unchanged.

SOURCED AND MECHANICAL, AND BOTH ARE TRUE OF IT. Mechanical, because the evidence is the filesystem and no refusal of a citation makes a written file unwritten. Sourced, because there is no citation to weigh in the first place: the quote IS the person's own sentence, carried verbatim from their request through the compile that could only keep what it could quote — so the grounding invariant every model judge's finding answers to is satisfied here by construction rather than by a check.

ok is false — and the gate judges exactly as it did before this existed — whenever no rule was stated, no rule is mechanically readable, or no rule was broken.

func JudgeDeliverable

func JudgeDeliverable(ctx context.Context, settings config.Config, client *pool.Client, graph *store.Store, node store.Node, deliverable, method string, evidence Evidence, workerModel string, options ...Option) Judgment

judgeDeliverable returns a checked pass or named gap. Every failure of the gate itself remains fail-open: Checked is false, so it neither blocks delivery nor manufactures verified evidence for the profile. It is also said out loud now — see Judgment.Unjudged and unjudged below — because fail-open and silent are two different designs and only one of them was ever chosen.

func MissingProduces

func MissingProduces(done plan.Done, artifacts []string) (judgment Judgment, ok bool)

MissingProduces is the mechanical half of the delivery gate: the one fact a judge should never be paid to discover, settled before a model round is bought.

When the plan's stopping criterion names files — and only then; a file name is never inferred from prose — every named file must be on disk and non-empty before a judge is asked anything. A missing or empty named file is a gate failure that names the absent files verbatim, in the same shape a judged gap takes, so the one-round repair flow the gate already owns runs on it unchanged. The model judge is skipped for that round: its cost buys nothing when the absence is a fact about the filesystem rather than a question about the text.

ONE CITATION PER MISSING FILE. That is the whole of what this gate claims, and for a while it was not what it said. The gap was one comma-joined string handed to a rule that asks whether a citation is a verbatim span of the ask, and a list of five paths is a verbatim span of nothing — so a gate that had correctly found five promised files absent was refused as an invention, no repair round was bought, and a run that wrote no file at all settled as done. The list is what makes the sentence below true per file, which is how it was always meant to read: a file the person named buys its round, and a file the plan named alone is refused, on the same invariant that already bounds every other gap. See AdmitGapCitation, which weighs each citation on its own and admits a file the ask names under either spelling.

Mechanical is set because a refusal downstream means something different here than it does for a judge's opinion. A judge can be wrong about whether a deliverable answers the ask; nothing can be wrong about whether a file is on disk. Refusing this gap declines to buy a repair round and settles nothing about whether the work landed — see deliveredWhole in cmd/codeaf/do.go, which is where the difference is spent.

ok is false — and the caller judges exactly as it did before this existed — when the criterion named no files, or when every named file is present and non-empty. The path is byte-identical to before in both cases: the judgment is the model's, the spend is the model's, and nothing here ran.

func OwnChecksFailing

func OwnChecksFailing(failing []string) (judgment Judgment, ok bool)

OwnChecksFailing is the finding for a leaf whose OWN new checks are red.

It is what the regression finding used to say instead, in words that were not true. A run writes checks — that is most of what a run does — and happy-dom's nemotron n1 run rewrote the file its reading was scoped to, taking it from 4 checks to 33 with eighteen of the new ones red. Both readings ran the identical command, so nothing looked widened and nothing looked wrong, and the gate failed the delivery with `This work broke checks that were passing before it: IntersectionObserver initial observation queuing …` — naming checks that did not exist when the baseline was taken — while the grader scored that same tree 9 of 9.

A LEAF WHOSE OWN CHECKS ARE RED HAS NOT FINISHED; A LEAF THAT TURNED SOMEBODY ELSE'S CHECK RED HAS BROKEN THE REPOSITORY. Both are worth a round and only one of them is a regression, so they are two findings and the words say which.

SOURCED, like the regression and the removed name, and for the same reason: there is no citation to weigh. The person asked for the behaviour; that the checks written for it do not pass is a measurement of the repository rather than a reading of the request.

func Regressions

func Regressions(regressed []string) (judgment Judgment, ok bool)

Regressions is the second mechanical half of the delivery gate, and the one whose evidence comes from the WORLD rather than from the plan.

A check that passed before this work and fails after it is a fact the run measured for itself, twice, with the project's own command. It is a gate failure that names the failing checks verbatim, in the same shape a judged gap takes, so the one-round repair flow the gate already owns runs on it unchanged — and the model judge is skipped for that round, because its cost buys nothing when the failure is a fact about a test runner's output rather than a question about the text.

SOURCED, NOT MECHANICAL, AND THE DIFFERENCE IS WHERE THE EVIDENCE CAME FROM. A mechanical gap reads the plan's promises against the disk; refusing its citation is possible and merely pointless. This gap has no citation to weigh at all: the request never said "and do not break the tests", because nobody has to. Grounding it would refuse it every single time, which is exactly the shape of the three graded runs that shipped patches deleting attributes their repositories already had while their own narrow tests stayed green (2026-08-28, bench/deepswe; docs/design/gate/SETTLEMENT.md §4).

ok is false — and the caller judges exactly as it did before this existed — when nothing was measured or nothing turned red. A worker that cannot take two readings hands back nil, which reads as no claim and never as no regression.

func RemovedPublicNames

func RemovedPublicNames(removed []string) (judgment Judgment, ok bool)

RemovedPublicNames is the symbol-level half of the same measurement, and the half a test suite structurally cannot make.

A CHECK IS EVIDENCE THAT SOMETHING IS EXERCISED; IT IS NOT EVIDENCE THAT NOTHING ELSE EXISTS. igel s11 deleted eight public class attributes off `Igel` — `results_path` among them — and moved them onto instances set in `__init__`. No check that project owns touches any of them, so the reading of the finished tree came back an IMPROVEMENT: named 2 → 14, red 2 → 0. Every one of the twenty-four hidden tests failed at setup on `Igel.results_path`, and the run held not one word about it. There was nothing wrong with the reading. The question it answers is simply not this one.

SOURCED, NOT MECHANICAL, for the reason Regressions is: there is no citation to weigh. The request never said "and do not delete the class's public attributes", because nobody has to, and a door that asked for a quotation would refuse this finding every single time.

It names the removal and not a remedy. Putting the name back and keeping the new arrangement are both answers, and which one is right is the repair round's business — this says only what the world lost.

ok is false when nothing was measured or nothing was lost. A worker that cannot take two readings of the tree hands back nil, which reads as no claim and never as nothing removed.

func UnboundNames

func UnboundNames(found []string) (judgment Judgment, ok bool)

UnboundNames is the finding: this work reads names nothing defines.

SOURCED, like the regression, the removed name and the run's own failing checks, and for the same reason: there is no citation to weigh. The request never said "and the names your code imports must exist", because nobody has to, and a door that asked for a quotation would refuse this finding every single time.

It names the reference and the site and not a remedy. Binding the name and deleting the reference are both answers, and which one is right is the repair round's business — this says only what the tree does not hold.

ok is false when nothing was measured or nothing was found. A settlement that cannot read the tree hands back nil, which reads as no claim and never as nothing unbound.

func Unexercised

func Unexercised(points []plan.Point, mapping []store.ExercisedPoint, grounds Grounds) (judgment Judgment, ok bool)

Unexercised is the acceptance finding: the behaviours the request stated that nothing in the project's own verification touches.

SOURCED, NOT MECHANICAL, for the reason Regressions is. There is no citation to weigh here — the person asked for the behaviour, and whether a check exists for it is a measurement of the repository rather than a reading of the words. Grounding it would refuse it every time, which is the shape of the two runs that shipped a deliverable claiming every test passed while a whole family of stated behaviours was exercised by nothing at all.

THE FINDING IS GROUPED BY THE LINE OF THE REQUEST ITS POINTS WERE READ FROM, and that grouping is the bound on its size. A checklist is derived per stated behaviour, so one sentence listing four defaults becomes four points — which is right for the mapping, because four defaults are four things a check either exercises or does not, and wrong for the finding, because a repair round aimed at four halves of one sentence is four rounds aimed at one sentence. The request's own lines are the grouping the person themselves wrote, so the number of things this finding can ask for is bounded by the number of things the person said, and by nothing this program chose. Past that the list is named eight and counted, which is regressionsNamed, stated once in this package and read here rather than restated. See PERF.md, "The acceptance finding's size".

ok is false when every point is exercised, when there were no points, or when nothing could be measured — and the caller then judges exactly as it did before this existed.

func WeakenedChecks

func WeakenedChecks(removed, vanished []string) (judgment Judgment, ok bool)

WeakenedChecks is the third mechanism: a check that STOPPED EXISTING between the two photographs.

The verification photograph SETTLEMENT §4 built sees a check that turned red. It cannot see one that was deleted, renamed or skipped — and taking out the test that was failing is the cheapest way there is to make a suite green, so the one thing a coverage rule must not do is leave that door open while closing every other one.

Two sources, either of which convicts. A check declaration on a REMOVED line of the worker's own diff is direct evidence and needs no run at all; a name the runner reported before the work and did not report after it is the same fact measured. Both are already subtractions that cancel a move — see verify.PatchChecks and verify.Reading.Vanished — so a check that changed file or was merely re-indented is not here.

Sourced, for the same reason as its two siblings: nobody has to ask for their tests to keep existing.

func (Judgment) Cited

func (j Judgment) Cited() []string

Cited is the gap's citations, and the one reader every admission rule goes through. It falls back to the joined Quote when the list is empty so a judgement built before the list existed — or by a caller outside this package that only knew how to set one span — is still weighed rather than silently treated as citing nothing.

type Option

type Option func(*bounds)

Option carries a fact a judgement cannot ask its client for. There is exactly one today — the context window of the model it is about to call — and it arrives as a variadic tail rather than as a parameter so that a caller which does not know the window compiles unchanged and behaves exactly as it did before this existed. An unknown window spends nothing: every bound below names the literal it was written with and falls back to it.

func WithContextTokens

func WithContextTokens(tokens int) Option

WithContextTokens tells a judgement the window of the model it is about to call. Zero is unknown, and unknown is never treated as small.

type PointOutcome

type PointOutcome struct {
	Behaviour string `json:"behaviour"`
	State     string `json:"state"`
	Why       string `json:"why,omitempty"`
}

PointOutcome is what became of one thing the request asked for.

func AnswerChecklist

func AnswerChecklist(points []store.AcceptancePoint, gate store.DeliveryGate, gateRead bool, wrote []string) []PointOutcome

AnswerChecklist reads what became of each journaled point from facts the run already recorded. A check may answer a point; a file comparison may only say whether the run wrote a named file, and every other shape stays not reached.

type Remainder

type Remainder struct {
	Done      bool
	Remaining string
	Checked   bool
}

func JudgeRemainder

func JudgeRemainder(ctx context.Context, settings config.Config, client *pool.Client, graph *store.Store,
	node store.Node, produced string, evidence Evidence, workerModel string,
) Remainder

judgeRemainder decides whether an exhausted leaf actually left work behind. Failures fail toward "not done" with Checked false: the continuation still runs, now bounded by the overrun governors, rather than a judge outage silently shipping genuinely cut-off work as finished. It takes no Option: nothing in this prompt is clipped here, so there is no window-derived bound for one to move. What it does share with the other two is the completion cap and the empty-reply retry, both of which are facts about the reply rather than about the window.

type RequestQuestion

type RequestQuestion func(ctx context.Context) (met bool, receipt string, asked bool)

RequestQuestion is the ability to put that question, carried on a judgement so a door in another package can ask it without holding a model client. See Judgment.Request for why it is a func rather than four more parameters.

type Subject

type Subject string

Subject is what the delivery gate held between its fence markers.

It is a recorded fact rather than an inference for the reason every other field on store.DeliveryGate is one: an autopsy asking "what did this gate actually read" has nothing else to go on, and the three refusals above are indistinguishable, afterwards, from three refusals over a real reading of the world.

const (
	// SubjectTree: the run changed files, and those files are the deliverable.
	SubjectTree Subject = "tree"
	// SubjectClaim: the run left nothing behind, so the message is the artifact
	// and the message is what was judged.
	SubjectClaim Subject = "claim"
)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL