Skip to content

T094: phase 3's consumer pins, openDox e1e3a3c3 and openXdox 9564d5d9, with phase 3's host wiring: openXdox's columns and the governed binding-trust policy (plan 034) - #1236

Merged
brettheap merged 9 commits into
mainfrom
t094-phase3-consumer-pins
Oct 5, 2026
Merged

brettheap merged 9 commits into
mainfrom
t094-phase3-consumer-pins

Conversation

@brettheap

@brettheap brettheap commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

Plan 034, task T094: phase 3's consumer pins (T090 step 6) with phase 3's host wiring, specs/034-opendox-standalone-operation/tasks.md at openxFactory main. The precedents are T047 (opensoft/openXdox#20, then #1181) and T064 (opensoft/openXdox#21, then #1215).

The pins: both pairs in ONE commit (caa8d377)

pair gitlink pin file commit: digests.tree_sha256
openDox d5098297 → e1e3a3c3 same (contracts/opendox-pin.yaml:118) 2815ca23…57cc → 55a110f49d268e22d382d47d778dfaf9298c93b555e3c4fcb621afc99f9d011b (28 records)
openXdox f257e021 → 9564d5d9 same (contracts/openxdox-pin.yaml:109) 52f0598e…6959 → 11585eadf4fef2ffcb4419194fa6a52444f56759cfc427d41c352a6b8803cbd2 (29 records)
  • e1e3a3c3 is T087, phase 3's openDox root pin: code → dede32b4 (plan 034, T090 steps 1–2) openDox#18's squash (T087), one commit above d5098297. It moves code 047bb4fa → dede32b4 with contracts/code-pin.yaml and changes no other path, so openDox's contracts/manifest.yaml, its spec gitlink and the bundle (dox-v1.1) are unchanged. openDox's main has since moved to 504324de (T076, 10.3: the root README documents the one command openDox#17, T076, the root README only). Step 2's root commit is the one T090 pins, and no check reads main's tip.

  • 9564d5d9 is opensoft/openXdox main, where Record Omnigent worker event bridge proof #22 squash-landed (its tree equals Record Omnigent worker event bridge proof #22's head db6cc2a4). It moves code 6a3b93b9 → 56e1c238, which is openXdox-code main after Fix brainstorm Captured header (validator contract) #37 (T086), and contracts/opendox-pin.yaml d5098297 → e1e3a3c3 (T090 step 5).

  • Every digest was recomputed three ways: repo_shape.tree_digest, an independent ls-tree + sha256, and the forge's tree listing (repo_shape.tree_digest_from_gh). Controls: the same three methods reproduce the recorded 52f0598e…6959 at f257e021 and 2815ca23…57cc at d5098297.

  • Why one commit and not "one commit each" (T090 step 6). Record Omnigent worker event bridge proof #22 changes the openDox pin that verify-opendox-pin.py check 5 reads through the openXdox gitlink, and docs/openxdox-pin-resync-runbook.md § 4 prints DIFFERENT. Each split order was measured on this branch's base, and verify-opendox-pin.py exits 2 in both:

    • the openDox pair alone: REFUSE opendox-pin-lockstep-mismatch: this pin names openDox@e1e3a3c3f8dd38214510412b71a2e858c6179532, but openXdox's own openXdox/contracts/opendox-pin.yaml names openDox@d5098297a5c262f9977193305210bccb4ec51e89; two direct declarations of one product's bytes disagree.
    • the openXdox pair alone: REFUSE opendox-pin-lockstep-mismatch: this pin names openDox@d5098297a5c262f9977193305210bccb4ec51e89, but openXdox's own openXdox/contracts/opendox-pin.yaml names openDox@e1e3a3c3f8dd38214510412b71a2e858c6179532; two direct declarations of one product's bytes disagree.

    So "one commit each" cannot be met without an intermediate red commit. The holder ruled the single commit for phase 3 on 2026-10-05, as for phase 1 (T047, T047 (DRAFT): phase 1's consumer pins, openDox 663ac683 and openXdox 57e2b8f2, with T045 and T046's host wiring (plan 034) #1181) and phase 2 (T064, T064: phase 2's consumer pins, openDox d5098297 and openXdox f257e021, with openXdox's governed projection registered by the host (plan 034) #1215, decided 2026-09-28). This PR therefore departs from T090 step 6's "one commit each" for the third time. Each pair still moves as one unit (box 9.5).

  • Both pin files are edited in place, keeping their line counts (216 and 154). The openDox migration: block keeps range (0001..0002) and reversible (false): no migration path changes over openDox-code 047bb4fa..dede32b4. Its runbook names the new code leg dede32b4, and the block is identical to openXdox's derived copy at 9564d5d9, which tests/opendox_pin asserts.

  • Gates.

    • verify-opendox-pin.py: OK opendox-pin verified: openDox@e1e3a3c3f8dd38214510412b71a2e858c6179532, gitlink read from HEAD, sorted-ls-tree-r-v1 tree digest recomputed (55a110f4…011b), lockstep with openXdox confirmed.
    • verify-openxdox-pin.py: OK openxdox-pin verified: openXdox@9564d5d9462ffd1a3155d9177206368e5061efa8, gitlink read from HEAD, sorted-ls-tree-r-v1 tree digest recomputed (11585ead…cbd2).

What else it carries

commit what F11.1 surface
3c1c1146 The host wiring. scripts/opendox_host.register_openxfactory() calls openxdox.column_contributions.register() (T086) after the projection line, and refuses by name when it registers nothing. GovernedBindingTrust (RULED #656 5970369724, "Governance approval (Recommended)") is the sixth seams() entry, before the home seam, with its take-back row. Its verdicts: a binding pending in the governed declarations is untrusted (host basis, the governed reason); an unreadable declarations document admits nothing; otherwise trusted, host basis. It answers the console intake's own question, intake_verdict, as plan 034's T100 entry says a host policy must. Its record() writes nothing and returns None, which openDox-code#86 reads as "no record" (doxbench_trust.recording_for; #656 5986391296, applied to T094 by 5988088910), so a failed add or edit write is refused as the write's own failure and never with REASON_NO_WITHDRAWAL. tests/domain_profile/test_host_registers_binding_trust.py (new, 9 tests, 11 cases at 7e31eca1) and test_openxfactory_host_wiring.py (six seams; the three columns the facet composes; each declared once) cover it. They pin openDox-code#86's final REMEDY_NOT_BY_TRUST and INTAKE_HOST_NOT_ADMITTED strings. Planted mutants, measured over the draft rounds of this same code, are each killed: M1-M3 and M5 by test_host_registers_binding_trust.py, the column line removed (M4) by test_doxbench_routes, intake_verdict removed or admitting everything (M6, M7), and record() returning the verdict, returning True, or writing MachineTrust's store (M8, M9, M11). HOST, HOST_TESTS
3c1c1146 Composition tests, amended in the arc: test_extension_point_parity.py (the /capabilities arm of T073 and T103, and the MRO's T084 layout), test_serve_column_split.py (the snapshot arm's four handlers are the core's own after T086's trim; every column method is the column's own), and test_doxbench_status_exemption.py (T085's register_default_status_exemption joins the readers of the registered rail). COMPOSITION_TESTS
1c5f8edb The render lane's RENDER_LEG_MODULES and the seal test's RENDER_UNIT_IMPORTS gain opendox/doxbench_trust.py, opendox/doxbench_intake.py and openxdox/column_contributions.py, which the host bootstrap now imports. The seal carries a leg's whole src/, so no sealed artifact changes. scripts/profile_openxfactory.py's note on the two openXdox columns moves to the past tense. ADMITTED_ARC_EDITS (both paths); HOST
24215223 test_ruling_q7_two_direct_upstreams_in_lockstep's snapshot literal moves d5098297 → e1e3a3c3, as its comment says it does on every bump. ADMITTED_ARC_EDITS
eda75977 The lane route's predicate check (T086's Q8 (a)). openXdox-code's test_the_hosted_session_arrival_path_is_recorded_and_not_built no longer reads openxFactory's _handle_refresh_action (opensoft/openXdox-code#37 narrowed its loop to the leg's own routes), so tests/domain_profile/test_lane_route_asks_the_hosted_ref_predicate.py (new, 2 tests) asserts it here: the route's body calls hosted_ref_refused( (openXdox's predicate), and on a hosted plane a refresh naming a session ref is refused with session_unavailable before it runs, while a ref-less one runs. Three planted mutants are each killed: the check removed, the call kept but not deciding, and the call asked as loopback. HOST_TESTS
b3a4b6e0 29 created: admissions in docs/opendox-carve-admissions.yaml, pinned in tests/carve_arrival by path, since and count, as T047's 37 and T064's 129 are, and one removed (below). ADMITTED_ARC_EDITS (both paths)
16136990 The admissions test's ordinal paragraph and its sixteenth-bump docstring and comment name this PR, #1236 (a follow-up commit: the number did not exist before the PR). ADMITTED_ARC_EDITS
9cd1bf23 Merge of main at ca1c1486 (lane openXfactory-3's ahead PR). It merged with no conflict, and its four files are byte-identical to the ahead commits this branch was measured over. It is not a realization commit, so it carries the Lane: line and no Arc: line (T091): F11.1's guard selects commits by that line, and walked over this branch it would otherwise charge #1234's two non-arc files to the arc. (not on main's first-parent line)
7e31eca1 Copilot's finding at 16136990, and the pre-review's six fix-now findings. (Copilot) A refusal now gives back the unread defaults this call replaced: _DEFAULTS names the two globals and the default-registration call of each default-holding seam (T085's doxBench pair, T100's trust default). A write that replaced an unread default is recorded with it, and the take-back registers it again as the unread default, as openxdox.column_contributions does. The pre-review's six: (1) the no-columns refusal is tested, and no host seam is written; (2) a refusal at the trust seam is tested on fakes and on the pinned leg; (3) "five seams" becomes six where the count is meant; (4) GovernedBindingTrust's docstring names the one case that changed; (5) the failed-write case skips as root; (6) __all__ is in ASCII order and names GOVERNED_PENDING_REASON. The give-back case, the six-seam message and the exports case each failed before the fix. Planted mutants M12-M19 are each killed. HOST, HOST_TESTS

The 29 admissions, each since the leg's own squash landing (git log --diff-filter=A), each path present at the new pin, and none placed by a row or declared before:

T094's "Owed elsewhere" list from opensoft/openXdox-code#37, each item to the file that carries it

  • scripts/opendox_host.register_openxfactory() calls column_contributions.register() after T064's projection line (Q6 (a)): scripts/opendox_host.py (3c1c1146).
  • The module seals: scripts/ideation_dashboard/dashboard_refresh_lane.py and tests/ideation-dashboard/test_dashboard_source_seal.py (1c5f8edb). The carve admissions (created: gains src/openxdox/column_contributions.py, tests/test_column_contributions.py, tests/test_column_contributions_governed.py and tests/test_host_plane.py): docs/opendox-carve-admissions.yaml and tests/carve_arrival/test_verify_carve_arrival.py (b3a4b6e0).
  • The parity test's MRO layout and test_serve_column_split.py's four snapshot rows, which move to the core: tests/ideation-dashboard/test_extension_point_parity.py and tests/ideation-dashboard/test_serve_column_split.py (3c1c1146).
  • test_openxfactory_host_wiring.py's "second copy of the column" check and its contributed tuple, which now has three entries: tests/domain_profile/test_openxfactory_host_wiring.py (3c1c1146): test_no_route_extension_declares_a_second_copy_of_the_column holds each column to one declaration, and CONTRIBUTED_COLUMNS is LaneRoutes, GateRoutes, ProjectionRoutes.
  • The lane route's hosted_ref_refused( check (Q8 (a)): tests/domain_profile/test_lane_route_asks_the_hosted_ref_predicate.py (eda75977).
  • The trust policy at T100's seam (openXdox registers none; "Governance approval", openDox + openXdox: two open-source layers, an installable app with users, projects and a database; domain descendants pin openXdox (Brett's ruling 2026-09-04) #656 comment 5970369724): GovernedBindingTrust in scripts/opendox_host.py, tested by tests/domain_profile/test_host_registers_binding_trust.py (3c1c1146).

F11.1, on the real commits

PACKET_MERGE=94b6f7f1… ARC_TIP=<this branch's head> over the guard extracted from openspec/changes/add-neutral-product-standalone-operability/tasks.md prints:

requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)

Every path this PR touches is on a declared surface:

  • PIN_PAIRS: openDox, contracts/opendox-pin.yaml, openXdox, contracts/openxdox-pin.yaml;
  • HOST: scripts/opendox_host.py, scripts/profile_openxfactory.py;
  • HOST_TESTS: tests/domain_profile/test_host_registers_binding_trust.py, tests/domain_profile/test_lane_route_asks_the_hosted_ref_predicate.py, tests/domain_profile/test_openxfactory_host_wiring.py;
  • COMPOSITION_TESTS: tests/ideation-dashboard/test_extension_point_parity.py, tests/ideation-dashboard/test_serve_column_split.py, tests/ideation-dashboard/test_doxbench_status_exemption.py;
  • ADMITTED_ARC_EDITS: scripts/ideation_dashboard/dashboard_refresh_lane.py, tests/ideation-dashboard/test_dashboard_source_seal.py, tests/openxdox_pin/test_openxdox_pin_verifier.py, docs/opendox-carve-admissions.yaml and tests/carve_arrival/test_verify_carve_arrival.py.

The admitted list does not grow, and no manifest note is annotated here (decision (b)).

The falsifiers, at the COMMITTED pins

run head verifiers pytest-suite other checks
CI 16136990 OK, OK selected=9362 passed=9356 skipped=6 failures=0 errors=0, floors met (margin 2312), run 37315023063 all success, openxdox-consumer-gate included
local eda75977 (16136990 changes only a docstring and a comment) OK, OK 8943 passed, 7 skipped, 0 failed (pytest tests/ -q -m "not postgres") the composition, domain_profile, carve-mapping, both pin dirs and carve_arrival: 569 passed
CI 7e31eca1 PENDING PENDING
local 7e31eca1 OK, OK PENDING domain_profile, the seal and the carve mapping: 626 passed; mutants M12-M19 killed

Each local run uses Python 3.12.3, with TMPDIR and --basetemp under ~/.local/state, outside the aggregation tree, in a checkout named openxFactory. A local run skips 7 where CI skips 6: the work tree sits inside an aggregation checkout, so the aggregation ignore-file case runs and passes there (#1215's reason).

  • validate-carve-manifest.py prints OK (456 rows), and validate-former-id-arrival.py --base origin/main --head HEAD passes.

Accepted limits

  • A leg from before T100 now fails with an ImportError, because seams() imports doxbench_trust, rather than with HostSeamsIncomplete by name. The pins only move forward.
  • A directory at the declarations path reads as "no document". That is openDox's own store rule (document_present checks for a regular file), and the change opens no new hole.
  • Under the governed host, model-binding trust prints trusted "m1" on this machine although record() records nothing. That wording is openDox-code's (cli_model_binding._trusted_line ignores recording.recorded), and it is deferred to an openDox-code follow-on after release 1.
  • The trust seam's take-back entry cannot fire today. Only the home seam follows it, and the home seam refuses nothing. Nit: _TAKE_BACK is keyed by the bare call name "register".

What this leaves for the aggregation

This PR does not do the opensoft/xFactory root pin-sync. When it runs, it needs:

  • the root openDox gitlink → e1e3a3c3f8dd38214510412b71a2e858c6179532;
  • the root openXdox gitlink → 9564d5d9462ffd1a3155d9177206368e5061efa8;
  • the root openxFactory gitlink → this PR's landed sha, with .github/clearing/openxfactory/PIN.yaml in the same commit (CLAUDE.md rule 2);
  • .github/workflows/dashboard-image-worker.yml's RENDER_LEG_MODULES and its mirror in tests/test_dashboard_image_worker_contract.py gain the same three modules as this PR's 1c5f8edb.

Arc: neutral-product-standalone-operability

🤖 Generated with Claude Code

Brett Heap and others added 7 commits October 5, 2026 12:45
…564d5d9 (T090 step 5) (plan 034, T090 step 6)

Both pin pairs move in ONE commit, as phases 1 and 2 did (T047's
openxFactory#1181 and T064's #1215, on the holder's decision of
2026-09-28, and again for phase 3 on the holder's ruling of 2026-10-05).
docs/openxdox-pin-resync-runbook.md section 4 reports DIFFERENT: the
openXdox root at 9564d5d9 derives openDox e1e3a3c3, and
verify-opendox-pin.py check 5 reads that blob through the openXdox
gitlink, so either pair alone is refused with
opendox-pin-lockstep-mismatch (both orders measured).

- `openDox` gitlink and `contracts/opendox-pin.yaml`: d5098297 ->
  e1e3a3c3 (opensoft/openDox#18, T087), tree
  55a110f49d268e22d382d47d778dfaf9298c93b555e3c4fcb621afc99f9d011b
  (28 records). The migration triple's `runbook` names the pinned code
  leg dede32b4, identical to the openXdox root's block. `range` and
  `reversible` stand: no migration path changes over openDox-code
  047bb4fa..dede32b4.
- `openXdox` gitlink and `contracts/openxdox-pin.yaml`: f257e021 ->
  9564d5d9 (opensoft/openXdox#22, T090 step 5), tree
  11585eadf4fef2ffcb4419194fa6a52444f56759cfc427d41c352a6b8803cbd2
  (29 records).

Both files keep their line counts and every line's position.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-trust policy, and the composition tests (plan 034)

- scripts/opendox_host.py: register_openxfactory() calls
  openxdox.column_contributions.register() (T086) after the projection
  line, and refuses by name when it registers nothing.
  GovernedBindingTrust (RULED #656 5970369724, "Governance approval
  (Recommended)") is the sixth seam, before the home seam, with its
  take-back row. It answers `verdict` and, as plan 034's T100 entry says
  a host policy must, the console intake's own question,
  `intake_verdict`: the intake's new binding is undeclared while its
  broker runs and is admitted, a binding whose declaration is pending is
  refused, and an unreadable declarations document admits nothing. Its
  `record()` writes nothing and returns None, which openDox-code#86 reads
  as "no record" (`doxbench_trust.recording_for`; #656 5986391296,
  applied to T094 by 5988088910), so a failed `add` or `edit` write
  under the governed host is refused as the write's own failure, never
  with REASON_NO_WITHDRAWAL.
- tests/domain_profile/test_openxfactory_host_wiring.py: six seams; the
  three columns the facet composes; each column declared once.
- tests/domain_profile/test_host_registers_binding_trust.py (new): the
  registration, each verdict, no state written, the port against the
  strict default, the intake through openDox's own seam
  (`intake_admissible`, `intake_verdict_for`), the recording answer, and
  `model-binding add` and `edit` under the governed host with the
  bindings document's directory unwritable. It pins #86's final
  REMEDY_NOT_BY_TRUST and INTAKE_HOST_NOT_ADMITTED strings.
- Composition tests (F11.1's named set):
  - test_extension_point_parity.py: the /capabilities arm (T073, T103)
    and the MRO's T084 layout;
  - test_serve_column_split.py: the snapshot arm's four handlers are the
    core's own after T086's trim, and every column method is the
    column's own;
  - test_doxbench_status_exemption.py: the readers of the registered
    status rail are `_status_exemption()` and the four registration
    calls, now that T085 adds `register_default_status_exemption`.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…an 034)

The doc-health render lane copies a fixed list of each leg's modules into
the image it renders with. At phase 3 the host bootstrap imports three
more: `opendox.doxbench_trust` (T100) to register the governed
binding-trust policy, `opendox.doxbench_intake`, through which that
policy's verdict reads the pending declarations, and
`openxdox.column_contributions` (T086) to register openXdox's columns.
The lists in `scripts/ideation_dashboard/dashboard_refresh_lane.py` and
its seal-test mirror in `tests/ideation-dashboard/test_dashboard_source_seal.py`
gain them. The seal carries a leg's whole `src/`, so no sealed artifact
changes.

`scripts/profile_openxfactory.py`'s note on the two openXdox columns is
moved to the past tense: T084 retired `consumer_reach`, and openXdox
contributes the columns through openDox's handler-contribution facet,
which the host registers.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… (plan 034)

`test_ruling_q7_two_direct_upstreams_in_lockstep` names the openDox root
commit both direct upstreams declare, as its comment says it does on
every bump. It moves to e1e3a3c3, T087's root commit
(opensoft/openDox#18), the commit this PR's openDox pair and the openXdox
root's own `contracts/opendox-pin.yaml` at 9564d5d9 both name.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tale consumer_reach admission removed (plan 034)

`docs/opendox-carve-admissions.yaml` gains the files each `-code` leg
added between its last pin and its new one under the destination's
declared roots, that no row places and no admission already declared,
each present at the new pin, derived as T064's were (each `since` is the
leg's own squash landing, `git log --diff-filter=A`):

- `opendox_code`, 25: openDox-code#65, #67, #69, #71, #72, #74, #77, #78,
  #80, #81, #82, #84 and #85, over 047bb4fa..dede32b4;
- `openxdox_code`, 4: openXdox-code#37 (T086) at 56e1c238.

One admission leaves: `src/opendox/consumer_reach.py` (openDox-code#9,
da8aae96). openDox-code#77 (T084) deleted the file at e49b17c3 when it
retired the reach module, so the walk at dede32b4 never consumes the
admission and the verifier would report it stale. It is removed, as
split-opendox section 3.4 slice S5 removed its two re-homed modules', on
the holder's ruling of 2026-10-05. openXdox-code's own
`src/openxdox/consumer_reach.py` (the RULED seed) is still there, and its
entry stays.

Neither spec leg moved, so neither admits anything. The 4 `opendox_code`
and 3 `openxdox_code` carve-time files the walk still names are unchanged
since the old pins; T064 left them, and so does this.

`tests/carve_arrival/test_verify_carve_arrival.py` pins the 29 by path
and `since`, counts them in the committed file, asserts the stale entry
ABSENT, and records the sixteenth amendment.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…4 (plan 034)

main carries T094's ahead PR, #1234 (D2, non-arc):
the CLI help golden, the usage line and the rebound-Host case at both
pins. It is a merge, never a rebase.

This merge of main is not a realization commit, so it carries no `Arc:`
line (T091). F11.1's guard selects commits by that line, and walked over
this branch it would charge #1234's two non-arc files to the arc.

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… checked here (plan 034, T086's Q8 (a))

openXdox-code's `test_the_hosted_session_arrival_path_is_recorded_and_not_built`
asked every serve route that accepts a ref, openxFactory's
`_handle_refresh_action` among them, whether it calls
`hosted_ref_refused(`. That route is openxFactory's lanes column, which
never arrived at the leg, so T086 (opensoft/openXdox-code#37, Q8 (a))
narrowed the loop to the leg's own two routes, and the property moves
here, to the lane's owner.

`tests/domain_profile/test_lane_route_asks_the_hosted_ref_predicate.py`
(new) asserts it on the route's body, and by driving the route on a
hosted plane: a refresh naming a session ref is refused with
`session_unavailable` before it runs, and a ref-less one runs. Three
planted mutants are each killed: the check removed (both cases fail),
the call kept but not deciding, and the call asked as loopback (the
behavioural case fails).

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 13:11
@sourcery-ai

sourcery-ai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Reviewer's Guide

This PR lands phase 3 by advancing the openDox and openXdox pins together, registering openxFactory’s governed binding-trust policy, wiring openXdox’s contributed columns through the host composition facet, and updating the associated composition, routing, seal, and carve-arrival proofs.

Sequence diagram for governed binding trust evaluation

sequenceDiagram
    participant Client
    participant OpenDox
    participant GovernedBindingTrust
    participant DeclarationStore

    Client->>OpenDox: verdict(binding, root)
    OpenDox->>GovernedBindingTrust: verdict(binding, root)
    GovernedBindingTrust->>DeclarationStore: pending_binding_ids()
    alt declarations unreadable
        DeclarationStore-->>GovernedBindingTrust: IntakeRefused
        GovernedBindingTrust-->>OpenDox: TrustVerdict.untrusted_for()
    else binding is pending
        DeclarationStore-->>GovernedBindingTrust: pending binding id
        GovernedBindingTrust-->>OpenDox: TrustVerdict.untrusted_for()
    else binding is not pending
        DeclarationStore-->>GovernedBindingTrust: declarations
        GovernedBindingTrust-->>OpenDox: TrustVerdict.trusted_for()
    end
    OpenDox-->>Client: trust verdict
Loading

Sequence diagram for synchronized product pin verification

sequenceDiagram
    participant Verify as verify-opendox-pin.py
    participant OpenDoxPin as contracts/opendox-pin.yaml
    participant OpenXdoxPin as contracts/openxdox-pin.yaml
    participant VerifyXdox as verify-openxdox-pin.py

    Verify->>OpenDoxPin: read commit e1e3a3c3
    Verify->>OpenDoxPin: recompute tree_sha256
    Verify->>OpenXdoxPin: check lockstep declaration
    OpenXdoxPin-->>Verify: openDox e1e3a3c3
    Verify-->>Verify: pin verified
    VerifyXdox->>OpenXdoxPin: read commit 9564d5d9
    VerifyXdox->>OpenXdoxPin: recompute tree_sha256
    VerifyXdox-->>VerifyXdox: pin verified
Loading

File-Level Changes

Change Details Files
Advanced both product pins together and synchronized their recorded tree digests and migration metadata.
  • Moved the openDox gitlink and pin from d5098297 to e1e3a3c3 and updated its digest.
  • Moved the openXdox gitlink and pin from f257e021 to 9564d5d9 and updated its digest.
  • Retained lockstep validation and documented the updated openDox code-leg runbook reference.
contracts/opendox-pin.yaml
contracts/openxdox-pin.yaml
openDox
openXdox
tests/openxdox_pin/test_openxdox_pin_verifier.py
Registered the host’s governed binding-trust policy and wired openXdox’s contributed columns into the host.
  • Added GovernedBindingTrust with pending, unreadable-document, approved, undeclared, intake, and no-op recording behavior.
  • Registered the trust policy as a host seam and verified registration order, replacement refusal, and host-basis verdicts.
  • Registered openXdox column contributions and rejected assemblies that contribute no columns.
  • Updated host/profile documentation for the new trust and column wiring.
scripts/opendox_host.py
scripts/profile_openxfactory.py
tests/domain_profile/test_host_registers_binding_trust.py
tests/domain_profile/test_openxfactory_host_wiring.py
Updated composition, routing, and source-seal tests for phase-3 column ownership and hosted-reference enforcement.
  • Composed LaneRoutes, GateRoutes, and ProjectionRoutes through the handler facet without duplicate declarations.
  • Retargeted snapshot and capability ownership assertions to the core handler after openXdox’s column trim.
  • Added hosted refresh rejection coverage for non-main session references.
  • Added the newly imported host and contributed modules to render/seal expectations.
tests/domain_profile/test_lane_route_asks_the_hosted_ref_predicate.py
tests/ideation-dashboard/test_extension_point_parity.py
tests/ideation-dashboard/test_serve_column_split.py
tests/ideation-dashboard/test_doxbench_status_exemption.py
tests/ideation-dashboard/test_dashboard_source_seal.py
scripts/ideation_dashboard/dashboard_refresh_lane.py
Rebased carve-arrival admissions on the new code-leg pins and removed the stale retired consumer-reach admission.
  • Added 25 openDox-code and 4 openXdox-code created-file admissions with introducing commits.
  • Removed src/opendox/consumer_reach.py and asserted that its admission remains absent.
  • Updated the ordinal/count assertions for the sixteenth bump while preserving unchanged carve-time files.
docs/opendox-carve-admissions.yaml
tests/carve_arrival/test_verify_carve_arrival.py

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

The ordinal paragraph of
`test_the_committed_admissions_file_keeps_the_ruled_seed_and_stays_well_formed`
lists every amendment to `docs/opendox-carve-admissions.yaml` by PR, and
the sixteenth bump's docstring paragraph and comment name the PR that
makes it. They carried a placeholder until this PR existed.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A trust-registration conflict can leave earlier seam replacements installed after rollback.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Advances plan 034’s phase-3 consumer pins and integrates the new openDox/openXdox interfaces into openxFactory.

Changes:

  • Updates both consumer pins and their recorded digests.
  • Registers governed columns and the host’s binding-trust policy.
  • Updates composition tests, render dependencies, and carve admissions.
File Description
tests/​openxdox_pin/​test_openxdox_pin_verifier.py Updates the lockstep pin assertion.
tests/​ideation-dashboard/​test_serve_column_split.py Checks updated handler ownership.
tests/​ideation-dashboard/​test_extension_point_parity.py Updates dispatch and handler composition expectations.
tests/​ideation-dashboard/​test_doxbench_status_exemption.py Accounts for default registration.
tests/​ideation-dashboard/​test_dashboard_source_seal.py Adds required module expectations.
tests/​domain_profile/​test_openxfactory_host_wiring.py Checks six seams and three columns.
tests/​domain_profile/​test_lane_route_asks_the_hosted_ref_predicate.py Tests hosted session-ref refusal.
tests/​domain_profile/​test_host_registers_binding_trust.py Tests governed trust and intake behavior.
tests/​carve_arrival/​test_verify_carve_arrival.py Checks new admissions and retired-path absence.
scripts/​profile_openxfactory.py Clarifies column ownership in comments.
scripts/​opendox_host.py Registers governed columns and binding trust.
scripts/​ideation_dashboard/​dashboard_refresh_lane.py Updates render module requirements.
docs/​opendox-carve-admissions.yaml Adds 29 admissions and removes one stale entry.
contracts/​openxdox-pin.yaml Advances the openXdox pin and digest.
contracts/​opendox-pin.yaml Advances the openDox pin, digest, and migration reference.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread scripts/opendox_host.py
…d, and the pre-review's six fixes (plan 034)

Copilot at 1613699 (PRRT_kwDOTAvnrs6pDFLU): openDox's entry points
register openDox's own defaults at the two doxBench seams (T085,
`doxbench_defaults.register_defaults()`), and T100's consumers register
the strict trust default lazily. `register_seams()` replaces such a
default while it is unread, but recorded only the seams that were empty,
so a later refusal (the trust seam over another host's policy, say) left
the host's rail and validators in place of openDox's defaults.
`_DEFAULTS` now names each default-holding seam's two globals and its
default-registration call. A write that replaced an unread default is
recorded with it, and the take-back registers it again as the default,
still unread, as `openxdox.column_contributions` gives back the defaults
it replaced. The default calls are checked with the take-back calls
before anything is written.

The pre-review (the holder's six fix-now findings):
1. The no-columns refusal is tested: with
   `column_contributions.register()` registering nothing,
   `register_openxfactory()` raises HostSeamsIncomplete naming `SKIPPED`,
   and no host seam is written.
2. A refusal at the trust seam is tested, on fakes (`_FakeSeams` gains a
   trust seam, and the take-back parametrize its calls) and on the pinned
   leg in a subprocess: over another host's policy or a read default it
   refuses, the four earlier seams are emptied and the other policy
   stays; over the unread default it replaces it.
3. "Five seams" becomes six where the count is meant (phase 1's five and
   T100's), in `opendox_host.py` and `test_openxfactory_host_wiring.py`.
   Accepted limit: a pre-T100 leg fails with an ImportError, since
   `seams()` imports `doxbench_trust`; the pins only move forward.
4. `GovernedBindingTrust`'s docstring says the one case that changed: an
   unreadable declarations document now admits nothing (5970369724).
5. The failed-write case skips as root, which ignores the 0o500 bits.
6. `__all__` is in ASCII order and names GOVERNED_PENDING_REASON.

Red first: the give-back case, the six-seam message and the exports case
failed before the fix. Planted mutants M12-M19 are each killed. A test
pins the defaults' global names at the pinned leg.

Arc: neutral-product-standalone-operability
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings October 5, 2026 13:43
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The trust policy admits bindings when the declarations path is an existing non-regular file instead of refusing it.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (1)

Comment thread scripts/opendox_host.py
@brettheap
brettheap marked this pull request as ready for review October 5, 2026 14:06
@brettheap

Copy link
Copy Markdown
Contributor Author

READY (holder's manual landing, Copilot label overridden) at 7e31eca — Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

Holder: T094, T090 step 6, phase 3's consumer pins and host wiring. It is an arc landing.

  • The pins. Both pairs move in ONE commit (caa8d377): openDox → e1e3a3c3 (T087) and openXdox → 9564d5d9 (step 5, openXdox#22). That departs from step 6's "one commit each", as T047 and T064 did. verify-opendox-pin refuses either split order (opendox-pin-lockstep-mismatch; both REFUSE lines are quoted in the body).

  • The host wiring.

    • openXdox's columns are registered after T064's projection line.
    • The governed binding-trust policy (5970369724) is the sixth seam, with its take-back. A replaced unread default is given back.
    • The composition rows have moved.
    • The lane route's hosted_ref_refused( check is tested (Q8 (a)).
    • There are 29 carve admissions, and consumer_reach.py's admission is removed and asserted absent.
    • The merge-of-main commit carries no Arc: line, by the holder's ruling: it is neither a realization commit nor a landing (T091).
  • Review.

    • An independent pre-review found six fix-now items, and all six are fixed in 7e31eca1, each red-first, with mutants M12 to M19 killed.
    • Copilot's r4184406714, at 16136990, is fixed in the same commit.
  • Gates at the head.

    • All 15 check-runs pass. pytest-suite (run 37319092077) reads selected 9376, passed 9370, skipped 6, failures 0.
    • Both pin verifiers print OK.
    • F11.1's guard holds: "requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)".
    • 0 unresolved threads, and no closing keyword.
  • Copilot's review at the head says "Changes recommended", with one new finding, r4184739661 (High): a directory or FIFO at the declarations path reads as no document, so every binding is trusted. The holder rules it an ACCEPTED LIMIT under the convergence rule (5988818366). It is not a bypass:

    • anyone who can put a directory at that path can delete or edit the declarations document, and a deletion has the same effect, because an undeclared binding is trusted under 5970369724;
    • the case is openDox's own store rule (document_present reads a regular file only);
    • a document that exists but cannot be read still fails closed.

    Tightening it belongs to an openDox-code DeclarationStore follow-on after release 1. The body lists it under accepted limits. The landing uses the lander's override for Copilot's label.

  • What follows.

    • Lane openXfactory-3's T098 runs the interim F11.1 with ARC_TIP at this landing, then T089.
    • The aggregation pin-sync (D4) mirrors the root gitlinks, PIN.yaml and RENDER_LEG_MODULES.

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sorry @brettheap, you've used your own review budget of 250,000 diff characters for the last 7 days.

You can request another review in 4 days and 6 hours by commenting @sourcery-ai review. Upgrade to get a review now.

@brettheap

Copy link
Copy Markdown
Contributor Author

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

LANDING — lane openxfactory-4, session faabad8b-8c31-4958-abd5-b35bdc9cd282@Eagle, 2026-10-05T14:06:37Z, PR #1236 into opensoft/openxFactory main

@brettheap
brettheap merged commit 3690848 into main Oct 5, 2026
16 checks passed
@brettheap

Copy link
Copy Markdown
Contributor Author

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)

LANDED — lane openxfactory-4, 2026-10-05T14:06:53Z, PR #1236 → 3690848 (opensoft/openxFactory main; squash)

brettheap added a commit that referenced this pull request Oct 5, 2026
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Authored by lane openXfactory-3, delegated by lane openxfactory-4 (#656 5984809456)

**Plan 034's bookkeeping for phase 3's consumer pins.** It records T098, phase 3's interim F11.1, and ticks T098 and T094 in `specs/034-opendox-standalone-operation/tasks.md`, on T094's landing (#1236 → `36908480`). Lane openxfactory-4 asked for T094's tick here (2026-10-05), in openxFactory#1226's form: the box, and a Landed bullet drawn from the PR bodies. #1217 ticked T064 beside T065 the same way.

- **Bookkeeping only**, in two commits: `22de755e` records T098, and `57fb1368` ticks T094. It edits four files:
  - the new record `specs/034-opendox-standalone-operation/evidence/f11.1-phase3.txt`;
  - `specs/034-opendox-standalone-operation/tasks.md`;
  - `specs/034-opendox-standalone-operation/plan.md`'s evidence tree;
  - the feature's `README.md` entry.

  `git diff origin/main --stat -- openspec/` is empty, so there is no Rule 6 window.
- **No `Arc:` trailer** on any commit, and no closing keyword anywhere in the commits or in this body (both scanned). So F11.1 itself never walks this PR.

## T098: F11.1 at T094's landing

- `PACKET_MERGE=94b6f7f13b45c351b9142345738965c974b7dd37` (#1144's landing; `evidence/arc-base.md`).
- `ARC_TIP=36908480b40b32509c308087d9d54e6c9d81759d`: #1236's squash commit, landed 2026-10-05T14:06:42Z onto `70602a0a`, carrying the trailer. The sha was read with `gh pr view 1236 -R opensoft/openxFactory --json mergeCommit`, checked with `git rev-parse --short=8`, and confirmed on the first-parent line.
- **The guard** is 11.1's FALSIFIED BY block, `openspec/changes/add-neutral-product-standalone-operability/tasks.md` lines 1654-1733 at `36908480`, extracted by anchor, byte for byte (sha256 `60beede1244b6052…`, the bytes T065 ran), and run as extracted. It is the guard as T018 left it, with batch A's `COMPOSITION_TESTS` and the closed `ADMITTED_ARC_EDITS` (RULED `5890601202`). No path was added to either list for phase 3.
- It walks three landings: `f56c87c6` (T047), `fcb45380` (T064) and `36908480` (T094). Every path T094 touched is on a declared surface (the record lists each with its surface, read out of the extracted guard's own sets), and the manifest is untouched.

**Verbatim output, exit 0, empty stderr:**

```
requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)
```

Beside it, as T065's record carried:
- **The walk to main's head** (`36908480`) finds the same three landings and prints the same line, so nothing after `36908480` on the first-parent line carries the trailer.
- **A negative control (never pushed).** In a scratch detached worktree at `36908480`, one planted commit (`12d724df`) with the trailer and one file on no surface. The same script refused it with exit 1: `FAIL: the arc changed what requirement 1 keeps: 12d724df557a: touched docs/a-path-on-no-f11.1-surface.md`. The worktree was removed, and the commit is on no branch.
- **3.3 (T017).** The `deleted_at_carve` row for `scripts/ideation_dashboard/profile_openxfactory.py` is byte-identical (raw text and parsed) between the manifest's introducing commit `17167481` and `36908480`, so T097 can tick 3.3 on all three interim runs.

The record quotes all of it, with the guard's `arc-commits.txt` and `arc-changes.tsv`.

## The tick, with its evidence

| task | repo | landed | note |
|---|---|---|---|
| T098 | oxF | this PR's record, `evidence/f11.1-phase3.txt` | `requirement 1 holds` at `ARC_TIP=36908480`, with the negative control above |
| T094 | oX, oxF | opensoft/openXdox#22 → `9564d5d9` (T090 step 5: the openXdox root's code `56e1c238`, openDox pin `e1e3a3c3`), then #1236 → `36908480` (step 6) | Both pin pairs in ONE commit, `caa8d377`, as for T047 and T064 (`verify-opendox-pin.py` refuses either pair alone). The host calls `openxdox.column_contributions.register()` after the projection line, and `GovernedBindingTrust` is a sixth `seams()` entry. 29 carve admissions are added, and the stale `src/opendox/consumer_reach.py` one is removed. The ahead PR landed first (#1234 → `ca1c1486`). The holder's READY is `5996119122`, with Copilot's `r4184739661` an accepted limit; CI at #1236's final head `7e31eca1` passes every check (`pytest-suite`: `selected=9376 passed=9370 skipped=6 failures=0 errors=0`). |

**Left unticked:** T089, whose checkpoint quotes this record (its own PR follows). T087 was ticked by #1235.

## Validation

- `python3 scripts/validate-openspec-cli-pin.py --all --strict`, through the pinned CLI 1.12.0, from the openxFactory root at this head (`57fb1368`): rc 0, `Totals: 110 passed, 1 failed (111 items)`, `0 UNDISPOSITIONED failures`. The one failure is the accepted `add-chain-attestation` exception (Brett Heap, 2026-09-05), the same at `main` `36908480`.
- No test or workflow reads `specs/034-opendox-standalone-operation/` (`git grep` over `tests`, `scripts` and `.github` finds nothing), and this PR touches no code.

## Rehearsals (before T094 landed)

- **2026-10-04, at T064.** The same procedure ran at the last arc landing measured that day, `fcb45380`, with the extraction above: `requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)`, the walk to `main` `c8d80020` found the same two landings, a planted path (`d14d04b4`, never pushed) was refused by name, and 3.3's row was byte-identical. Lane openxfactory-4's dry run of 2026-10-03 had run the guard over a simulated T094; every path of that draft sat on a declared surface.
- **2026-10-05, at T094's open PR, #1236, head `16136990`.** The guard walked T094's seven branch commits, each carrying the trailer, then T064 and T047, and printed the same line. The branch's merge of `main`, `9cd1bf23`, carries no trailer (the holder's ruling), so it is no landing to the guard, and the first-parent walk never enters its second parent, `main`'s `ca1c1486`. Over a local squash of that head onto `main` `ca1c1486` (never pushed), the walk was exactly three landings, the squash, T064 and T047, with the same line; a planted path was refused by name, and 3.3's row was byte-identical.

Host paths in the record are written `<workdir>`. No closing keyword appears in this body or in any commit.

🤖 Generated with [Claude Code](https://claude.com/claude-code)


Lane: openxfactory-4
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
brettheap added a commit that referenced this pull request Oct 5, 2026
…1238)

Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Authored by lane openXfactory-3, delegated by lane openxfactory-4 (#656 5984809456)

**Plan 034 T089, phase 3's checkpoint, and T092's phase-3 notes.** This PR runs every check T089 names, at the commits phase 3 pinned, and quotes each one. It also carries T092's phase-3 notes in `docs/opendox-carve-manifest.yaml`, on the holder's decision below.
- Every check passes. F5.2 whole passes after T086's repair, so **F5.2's box closes here** (RULED `5962785556`, item 1: *"F5.2's box closes at phase 3's checkpoint (T089)"*), and F4.1's box closes here too (plan 034's box map: `F4.1 → T089`). T097 ticks both in #1144; this PR ticks only T089.
- This PR is bookkeeping, so it carries no `Arc:` trailer (R1Q20 (a), `5817152735`; T091). Claims: #656 comments `5984809456` (lane openXfactory-3's D3: T098 and T089) and `5987202231` (D5: T092's phase-3 notes), delegated by lane openxfactory-4.

Ruled, as T089 cites: F5.2's close, `5962785556`, item 1. The amended forms run: batch H (F10.1, F13.1), batches M and P (F16.1), batches C, F, G and K (F5.2), batch A (F11.1's guard).

**No Rule 6 window.** This PR touches nothing under `openspec/changes/`: the checkpoint finds no record in #1144 that is wrong, so #1144's `tasks.md` is untouched.

The record is [`specs/034-opendox-standalone-operation/evidence/checkpoint-phase3.md`](specs/034-opendox-standalone-operation/evidence/checkpoint-phase3.md).
- Each falsifier in it was extracted by anchor, byte for byte, from #1144's `tasks.md` at `36908480` (sha256 `48db295594a6…`), and every extraction reproduces the sha256 the earlier records quote (F4.1 `8900b985e72f`; F10.1 `d94265449831` → `2358bd8f76ab`; F13.1 `1e1f7da5564a` → `0a47fa31f5e0`; F16.1 `fe22ec4873d1` → `619b32a955e2`; F5.2 `808619e066fa` → `4b1512c26814`; F11.1 `60beede1244b`).
- Each ran from a fresh detached worktree at the pinned commit, with an empty `git status --porcelain --ignored`, in a scrubbed `env -i` environment, in the foreground of its wrapper.

## Verdict

| # | T089's check | where | result, quoted |
|---|---|---|---|
| 1 | F4.1 | openDox-code `dede32b4` | **PASS**, exit 0: `1 passed` twice, then `no deferred reach names the consumer or the publisher` |
| 2 | F10.1, as batch H amends it | openDox-code `dede32b4`, `pip install ".[local]"` (`opendox-0.1.0`) | **PASS**, exit 0: the bundled database, migrations `['0001', '0002']`; `validation: opendox-snapshot: 0 violations`; `serving http://127.0.0.1:8080/index.html` |
| 3 | F13.1, as batch H amends it | openDox-code `dede32b4` | **PASS**, exit 0: the bundled database, migrations `['0001', '0002']`; every assertion holds, the last `grep -q OPENDOX_OIDC_ISSUER …/default.err` |
| 4 | F16.1, as batches M and P amend it, with T100's named test | openDox-code `dede32b4` | **PASS**, exit 0: `24 passed` (16.6), the dialect line, `no model configured: the catalog offers nothing`, `83 passed` (`tests/test_chat_model_configuration.py`), `532 passed` (`tests/test_model_binding_trust.py`) |
| 5 | F5.2 whole, as batches C, F, G and K amend it, after T086's repair | openXdox-code `56e1c238`, openDox-code `dede32b4` installed over it, `OPENXFACTORY` at `36908480` | **PASS**, exit 0: the seven suites pass whole (`45`, `23`, `18`, `6`, `40`, `9` and `12 passed`), `test -s` holds, and the `--chains` step prints `ok: 5 protected edit(s), each entered and holding` |
| 6 | T098's interim F11.1 | openxFactory, `ARC_TIP` at T094's landing `36908480` | **PASS**: quoted from [`f11.1-phase3.txt`](specs/034-opendox-standalone-operation/evidence/f11.1-phase3.txt) (#1237 → `20ce593e`), and re-run here with the same line, `requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)` |

## T092's phase-3 notes, carried here

**Where they ride, and which reaches they cover.**
- **Phase 2's decision (b)**, recorded in T064's PR (#1215): phase 2's notes rode in T063's checkpoint PR, as phase 1's rode in T049's.
- **The holder's decision for phase 3** (lane openxfactory-4's round-2 delegation, 2026-10-05, D5, recorded there and here): *"Phase 3's notes ride in phase 3's checkpoint PR, the T089 PR, not in T094's arc PR. This follows phases 1 and 2, whose notes rode in T049's and T063's checkpoint PRs on the holder's decisions (T092's text names both). The checkpoint PR carries no `Arc:` trailer, so F11.1's count of annotated notes never includes them. Run F11.1's content rule over them in that PR, as T049 and T063 did."*
- **The holder's ruling (A)** (`#656` comment `5994463071`, 2026-10-05), on lane openXfactory-3's question whether `consumer_reach.py`'s last stand-ins take notes too: *"Phase 3 reads T092 as phase 2 did. T092 asks for one `edits[].note` per closed reach. Phase 2's T055 removed ten stand-in names of the same kind, and T063's checkpoint PR noted none of them (decision (b), recorded in #1215). A stand-in's removal is therefore not counted as a closed reach. Phase 3's notes cover the reaches T084 and T086 closed, the three rows of the default patch."*

3 notes on 3 rows (2 added, 1 extended), for the eleven reaches phase 3 closed. They are #1144's 4.3 reaches into openXdox that F4.1's scan still named at phase 2's pin `047bb4fa`, and the three rows of openXdox-code's ratchet `OPENDOX_BACK_IMPORTS`. All eleven drop at T084 (opensoft/openDox-code#77 → `e49b17c3`), which also retires `consumer_reach.py`.

| entry | carve lines | reaches at `1e4a57fb` | note |
|---|---|---|---|
| `branch_session.py` `edits[0]` | 1574, 1992 | `:1587`, `:2005` | extended (phase 2's note left these two open for phase 3) |
| `serve_project.py` `edits[0]` | 246, 247 | `:246`, `:247` | added |
| `serve_workbench.py` `edits[0]` | 346, 406, 407, 543, 1214, 1664, 2606 | `:347`, `:407`, `:408`, `:544`, `:1215`, `:1665`, `:2607` | added |

Each note cites the landings that close its reaches, each re-verified at this PR's run (`closers-p3.py`, quoted in the record): T084 (opensoft/openDox-code#77 → `e49b17c3`), T086 (opensoft/openXdox-code#37 → `56e1c238`: `openxdox.column_contributions.register()`, and `OPENDOX_BACK_IMPORTS` at `(0, 0)` with its pin at T087's commit `dede32b4`), and T094 (#1236 → `36908480`: the host's call).

So the stand-ins `consumer_reach.py` still held at `047bb4fa` (`gate_console`, `serve_gate`, `serve_projection` and the two late bases) take no note, on ruling (A).

F11.1's content rule, T049's script byte for byte, over `main`'s manifest and this PR's:

```
  extended: scripts/ideation_dashboard/branch_session.py edits[0]
  added: scripts/ideation_dashboard/serve_project.py edits[0]
  added: scripts/ideation_dashboard/serve_workbench.py edits[0]
F11.1's manifest content rule holds: 3 note(s) annotated, nothing else in the manifest moved
```

With every `edits[].note` removed, the two manifests are equal, and no other line moved. The note check, the reach mapping, `scripts/validate-carve-manifest.py` (`OK`) and F4.1's scan walk are quoted in the record's last section.

## The pins

From `pins.sh` over openxFactory at `36908480`, with `openDox` and `openXdox` initialized recursively: openDox root `e1e3a3c3` (`code` → openDox-code `dede32b4`, T087's pin), openXdox root `9564d5d9` (`code` → openXdox-code `56e1c238`, T086's landing; its `contracts/opendox-pin.yaml` → `e1e3a3c3`), and openXdox-code's `pyproject.toml` pins openDox-code `dede32b4`. All six T090 equalities hold, and the runs used exactly the pinned commits.

## What changed (5 files)

- `specs/034-opendox-standalone-operation/evidence/checkpoint-phase3.md`: new, `Status: record`. It is linked from the feature 034 entry in `README.md`, beside T098's F11.1 record, and from `plan.md`'s evidence tree.
- `specs/034-opendox-standalone-operation/tasks.md`: T089 ticked, with its Run bullet (T063's form), and T092's entry gains phase 3's sentence after phase 2's (#1218's form; T092 stays unticked, since 11.1 is ticked at ARC close). The box map already names T089 for F4.1 and F5.2, and nothing moves, so it is unchanged.
- `specs/034-opendox-standalone-operation/plan.md`: the evidence tree and its prose.
- `README.md`: the checkpoint link.
- `docs/opendox-carve-manifest.yaml`: T092's phase-3 notes, `note:` lines only (2 added, 1 extended). With every note removed the manifest is unchanged.

## Validation, at the head against `main` `20ce593e`

- **`python3 scripts/validate-openspec-cli-pin.py --all --strict`** (pinned CLI 1.12.0): rc 0, `Totals: 110 passed, 1 failed (111 items)`, `0 UNDISPOSITIONED failures`; the one failure is the accepted `add-chain-attestation` exception, as on `main`.
- **doc-health `--single-repo . --as-of 2026-10-05`**, run at `main` `20ce593e` and at the head in two worktrees of one clone, each named `openxFactory`, so like is compared with like: rc 0 at both, `Findings: 31 critical, 26 error, 69 warning, 20 info. New regressions vs previous report: 0.`, and the two reports are byte-identical, a delta of zero.
- Every 8-character commit sha in the record and in this diff resolves with `git rev-parse --verify` in its own repository (openxFactory, openDox-code, openXdox-code and the two roots). The two `spec` shas in the record's pin table, `f7ee3c76` and `f088b097`, are the roots' gitlinks, read with `git ls-tree`.

## Rehearsal (2026-10-04, at that day's mains, before T086, T087, T094 and T098)

At openDox-code `38d3350e`, openXdox-code `6a3b93b9` and openxFactory `c8d80020` (ARC_TIP `fcb45380`): F4.1, F10.1, F13.1, F16.1 (`24`, `83` and `135 passed`) and F11.1 passed; F5.2 was red as expected until T086, on `tests/test_session_snapshot.py` (`17 failed, 6 passed`: 16 `SeamNotRegistered` at openDox's kickoff seam, 1 `IndexError`) and `tests/test_snapshot_validation_launch.py` (`9 failed`: T070's install-mode precondition, hosted by default and refused for no `OPENDOX_OIDC_ISSUER`), with the other five suites whole and `--chains` at `ok: 4 protected edit(s)`. opensoft/openXdox-code#37's scope covers all 26.

Host paths in the quotes are written `<workdir>`, and the user `<user>`. No closing keyword appears in this body or in any commit.

🤖 Generated with [Claude Code](https://claude.com/claude-code)


Lane: openxfactory-4
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
brettheap added a commit that referenced this pull request Oct 5, 2026
Lane: openxfactory-4 (openXfactory-4-openDox_extraction)
Authored by lane openXfactory-3, delegated by lane openxfactory-4 (#656 5984809190)

**Plan 034 T097, release 1's bookkeeping.** This PR ticks all 63 release-1 boxes of #1144's `tasks.md` (`add-neutral-product-standalone-operability`) that a realization task closes, each with its evidence note, and records research R16's non-normative corrections. Its After set has landed: batch P (#1230), T096 (#1241 → `8a37a087`) and T099 (the publish at the cut, and openDox#19 → `d77f8cbf`). On the holder's rulings it also ticks plan 034's T095, T099, T002, T007 and T097, each with its bullet, so plan 034 closes at 92 of its 96 tasks. T090 to T093 tick at the arc's close.

- Bookkeeping, so it carries no `Arc:` trailer (R1Q20 (a), `5817152735`; T091) and no closing keyword. It touches `openspec/changes/`, so lane openxfactory-4 lands it under a Rule 6 `LANDING`/`LANDED` window.
- **Based on `main` `8a37a087`** (#1241, T096), merged in by `0cde3961`. The PR was first based on `c8d80020` (#1232). The merges since are listed below. Its commits:
  - `76d8ff37`: the ticks, the notes and R16;
  - `b7f49673` and `e2efb3a1`: from Copilot's review (below), which edit note text only;
  - `bd32ea9c`: the merge of `main` after batch P landed;
  - `cf2c6bdc`: 16.3a's tick, on the T100 follow-on's landing (openDox-code#86 → `651c35fe`);
  - `5870cd00`: 4.3's and 9.2's ticks, on T086's landing (openXdox-code#37 → `56e1c238`);
  - `23665543`: 5.5's note reworded (Copilot at `5870cd00`), note text only;
  - `96c74eab`: the merge of `main` after T094 and T098 landed;
  - `935164af`: 3.3's tick, on T098's landing (openxFactory#1237 → `20ce593e`);
  - `e93ab9fb`: 5.4a's note reworded (Copilot at `935164af`), note text only;
  - `f6c6dc3c`: the merge of `main` after T089 landed;
  - `e873b25f`: F4.1's, F5.2's and F16.1's ticks, on T089's landing (openxFactory#1238 → `fab575ad`);
  - `9759313b`: the merge of `main` `f2acc88c`;
  - `10b6ba05`: the phase-1 and phase-2 checkpoint citations by path (below), note text only;
  - `0cde3961`: the merge of `main` after T096 landed;
  - `f94be2fd`: 10.3's tick, on T099's publish, and plan 034's ticks (below);
  - `9713f991`: plan 034's opening status, which still said batch P was to land (Copilot at `f94be2fd`, below), plan text only.

  If `main` moves before the landing, I merge it in. No rebase and no force-push.

## Measured, not copied

Lane 4's table (2026-10-03T20:05Z, at `de2ab703`: 52 CLOSED-LANDED, 11 PENDING, 5 LEFT-OPEN, 2 ALREADY-TICKED) was regenerated by its own generator, patched, at `c8d80020`, at `ba6bb870`, and again after each closing landing:

- every landing PR, now 115 across the six repositories, re-read with `gh pr view <n> -R opensoft/<repo> --json state,mergeCommit,mergedAt`, last at 2026-10-05T16:50Z. Since the first reading these have landed: #1230 (batch P, `ba6bb870`), openDox-code#84 (T104, which realizes no box, `32943cbf`), openDox-code#86 (the T100 follow-on, `651c35fe`), openDox-code#78 and openDox-code#79 (T101, `d59f3f26` and `dede32b4`), openDox#17 (T076, `504324de`), openDox#18 (T087, `e1e3a3c3`), openXdox-code#37 (T086, `56e1c238`), openXdox#22 (T094's openXdox root step, `9564d5d9`), #1234 (T094's ahead PR, `ca1c1486`), #1235 (phase 3's plan ticks, `70602a0a`), #1236 (T094, `36908480`), #1237 (T094/T098, `20ce593e`), #1238 (T089, `fab575ad`), openDox-code#75 (T095, which realizes no box, `389e5a4a`) and openDox#19 (T099's root README, `d77f8cbf`);
- every task's landing re-read from plan 034's own `Landed:` bullet (78 of 96 tasks ticked at `c8d80020` and `ba6bb870`, 85 at `20ce593e`, 86 at `a43845e6`, 87 at `8a37a087`), and each run record traced to the openxFactory PR that added it: `checkpoint-phase1.md` (#1204 → `9d2e5bc3`), `checkpoint-phase2.md` (#1218 → `a883bbf6`), `f10.1-run.md` (#1223 → `f261fefa`), `f13.1-run.md` (#1224 → `de2ab703`), `f16.1-run.md` (#1231 → `0e01ca85`), `f11.1-phase3.txt` (#1237 → `20ce593e`), `checkpoint-phase3.md` (#1238 → `fab575ad`) and `at-r1/oracle-verdict.md` (#1241 → `8a37a087`). The T100 follow-on, which is no task, is read from the forge;
- batch P's text read at #1230's heads `84113a44` and `d08249a2`, and as it landed (`ba6bb870`, the squash of its head `051f9945`).

**Result: 63 CLOSED-LANDED, 0 PENDING, 5 LEFT-OPEN and 2 ALREADY-TICKED, of 70.** Since lane 4's table:

- T082 (openDox-code#76 → `ca9e1bd5`), T100 (openDox-code#82 → `38d3350e`), T102 (openDox-code#81 → `0116293a`) and T083 (openxFactory#1231 → `0e01ca85`) have landed. That closes 16.4, 16.5 and 16.6.
- The T100 follow-on (openDox-code#86 → `651c35fe`) has landed. That closes 16.3a.
- T086 (openXdox-code#37 → `56e1c238`) has landed. That closes 4.3 and 9.2.
- T098 (openxFactory#1237 → `20ce593e`), phase 3's interim F11.1, has landed. That closes 3.3 (below).
- T089 (openxFactory#1238 → `fab575ad`), phase 3's checkpoint, has landed. That closes F4.1, F5.2 and F16.1 (below).
- T076 (openDox#17 → `504324de`) and T101 (openDox-code#78 → `d59f3f26`, openDox-code#79 → `dede32b4`) have landed.
- T095 (openDox-code#75 → `389e5a4a`) and T096 (#1241 → `8a37a087`), AT-R1's two halves, have landed. They close no box of #1144.
- T099 has published `opendox` 0.1.0, and its root README PR has landed (openDox#19 → `d77f8cbf`). That closes 10.3 (below), the last box.

Batch P closes and rewords no box. In #1144's `tasks.md` it only inserts addenda at the ends of 12.4a, 16.3a and F16.1: no box line moves and no box changes state. Since `ba6bb870`, no landing has touched #1144's `tasks.md`. In plan 034's `tasks.md`, T097's own text is unchanged.

## The census

`python3 box_census.py openspec/changes/add-neutral-product-standalone-operability/tasks.md`, with the tool written from research.md § Appendix (byte-identical to the Appendix's heredoc).

Before, at `main` `8a37a087` (identical to `c8d80020`'s, `ba6bb870`'s, `20ce593e`'s and `a43845e6`'s):

```
2 8 2.1[ ] 2.1a[ ] 2.2[ ] 2.3[ ] 2.4[ ] 2.5[ ] 2.6[ ] F2.1[ ]
3 5 3.0[x] 3.1[ ] 3.2[ ] 3.3[ ] F3.1[ ]
4 5 4.1[ ] 4.1a[ ] 4.2[ ] 4.3[ ] F4.1[ ]
5 12 5.0[ ] 5.1[ ] 5.2[ ] 5.3[ ] 5.3a[ ] F5.1[ ] 5.4[ ] 5.4a[ ] F5.2[ ] 5.5[ ] 5.6[x] F5.3[ ]
7 8 7.0[ ] 7.1[ ] 7.1b[ ] 7.1a[ ] 7.2[ ] 7.3[ ] F7.1[ ] F7.2[ ]
9 8 9.1[ ] 9.2[ ] 9.2a[ ] 9.3[ ] 9.4[ ] 9.5[ ] F9.1[ ] F9.2[ ]
10 5 10.1[ ] 10.2[ ] 10.2a[ ] 10.3[ ] F10.1[ ]
11 3 11.0[ ] 11.1[ ] F11.1[ ]
13 8 13.1[ ] 13.2[ ] 13.3[ ] 13.4[ ] 13.4a[ ] 13.5[ ] 13.6[ ] F13.1[ ]
16 8 16.1[ ] 16.2[ ] 16.3[ ] 16.3a[ ] 16.4[ ] 16.5[ ] 16.6[ ] F16.1[ ]
total 125 Counter({' ': 105, 'x': 11, '~': 9})
```

After, at this head `9713f991` (`9713f991` changes only plan 034, so the census is `f94be2fd`'s):

```
2 8 2.1[x] 2.1a[x] 2.2[x] 2.3[x] 2.4[x] 2.5[x] 2.6[x] F2.1[x]
3 5 3.0[x] 3.1[x] 3.2[x] 3.3[x] F3.1[x]
4 5 4.1[x] 4.1a[x] 4.2[x] 4.3[x] F4.1[x]
5 12 5.0[x] 5.1[x] 5.2[x] 5.3[x] 5.3a[x] F5.1[x] 5.4[x] 5.4a[x] F5.2[x] 5.5[x] 5.6[x] F5.3[x]
7 8 7.0[x] 7.1[x] 7.1b[x] 7.1a[x] 7.2[x] 7.3[x] F7.1[x] F7.2[x]
9 8 9.1[x] 9.2[x] 9.2a[x] 9.3[x] 9.4[x] 9.5[ ] F9.1[x] F9.2[ ]
10 5 10.1[x] 10.2[x] 10.2a[x] 10.3[x] F10.1[x]
11 3 11.0[ ] 11.1[ ] F11.1[ ]
13 8 13.1[x] 13.2[x] 13.3[x] 13.4[x] 13.4a[x] 13.5[x] 13.6[x] F13.1[x]
16 8 16.1[x] 16.2[x] 16.3[x] 16.3a[x] 16.4[x] 16.5[x] 16.6[x] F16.1[x]
total 125 Counter({'x': 74, ' ': 42, '~': 9})
```

The release-1 groups are shown. Groups 1, 6, 8, 12, 14, 15 and the follow-ons read the same before and after. Earlier heads read `'x': 66, ' ': 50` (`76d8ff37` to `bd32ea9c`), `'x': 67, ' ': 49` (`cf2c6bdc`), `'x': 69, ' ': 47` (`5870cd00` and `23665543`), `'x': 70, ' ': 46` (`935164af` to `f6c6dc3c`) and `'x': 73, ' ': 43` (`e873b25f` to `0cde3961`).

## The change: #1144's `tasks.md`, and plan 034's ticks

- **63 boxes ticked**, each with its evidence note as the item's last paragraph, after any addenda. The note is in 1.8's and 3.0's form: a bold dated lead, `**Landed <date>**`, where the date is the last landing of the box's realizing tasks; the tasks; the landings as `repo#n → sha8`; and the falsifier's result, with where it was quoted. For example, 2.4:

  > **Landed 2026-09-27** (T030, in T011's PR): openDox-code#46 → `0e88454a`. `tests/test_imports_standalone.py::test_every_module_imports_with_no_sibling` first asserts the four siblings absent, then imports every module, failing with the first that still needs one (`evidence/checkpoint-phase1.md` § 1).

- **No ratified line moves.** Against `main` `8a37a087`, #1144's diff is the 63 checkbox lines, `[ ]` → `[x]`, and 64 inserted paragraphs (482 lines): 63 notes, and 1 R16 note on an open box (9.5). This was proven at `f94be2fd` by setting every checkbox to `[ ]` in both files and diffing: the result is 64 insertions and nothing else, and the lines the two files share differ only by the 63 flips. The only other file the PR changes is plan 034's `tasks.md` (below). The file is byte-identical to a fresh re-apply of the regenerated decisions onto `main`'s file.
- **Research R16** (research.md § R16), each figure re-checked against research R2, R4, R5, R10 and R13 and plan 034's records:

| R16 item | box | where it is recorded |
|---|---|---|
| 1 | 2.5 | in 2.5's note: 22 modules, not 26, were reached by no CI step |
| 2 | 9.4 | in 9.4's note: openXdox-code's floors read `564/558/6` at `626f2c8d`, not `539/533/6` |
| 3 | 4.3 | in 4.3's note, since 4.3 closed on T086 (an open-box note until then): `run_scoped_doc_health` makes three of the four reaches, and the fourth is `session_documents` |
| 4 | 3.2 | in 3.2's note: the proxy's refusal was written for NOTHING REGISTERED |
| 5 | 10.1 | in 10.1's note: Q-R4 is recorded at `runtime/cli.py:39-42`, not `:40-46` |
| 6 | 9.5 | a note on the open box (open for the arc's close, T090): the openDox pin was 11 commits behind, not 9, and T086 has since moved it to `dede32b4` |
| 7 | Group 2's heading | in 2.1's note, the box the heading introduces: 1,305 and 1,239 at `1e4a57fb` |
| 8 | 3.0 | no new line: 3.0's own note already records it (*"Read at ratification, 2026-09-24"*) |

## 10.3, closed on T099

10.3's box says the openDox root documents the entry point and does not host it, and batch H's addendum makes the documented command `pip install "opendox[local]"`, then `opendox generate-and-open --local …`. Plan 034 maps it to T076, T101 and T099:
- **T076** (openDox#17 → `504324de`) documents the install and the start, and adds no `make` target.
- **T101** adds the release workflow and the version bump (openDox-code#78 → `d59f3f26`, openDox-code#79 → `dede32b4`).
- **T099** publishes that commit at the cut, on Brett Heap's word (`5997633384`). Read from the forge and from PyPI:
  - the annotated tag `v0.1.0` (`9153c254`) names `dede32b4`, which the openDox root's `contracts/code-pin.yaml` names;
  - openDox-code's `release` run 37339111713, dispatched on that tag, completed `success` in all four jobs: `build and verify`, `publish to TestPyPI (the dry run)`, `install opendox[local] from TestPyPI` and `publish to PyPI`, whose steps include `PyPI serves the files the build job verified`;
  - `https://pypi.org/pypi/opendox/0.1.0/json` lists exactly two files, neither yanked: `opendox-0.1.0-py3-none-any.whl` (sha256 `8ecea00db6f9…`) and `opendox-0.1.0.tar.gz` (sha256 `56869b6208a8…`);
  - openDox#19 → `d77f8cbf` replaces the README's stand-in paragraph. At that commit, the README's first line resolves from PyPI, and no paragraph says that no release is published.

## Plan 034: T095, T099, T002, T007 and T097

Lane openxfactory-4's delegation of 2026-10-05T16:37:31Z asks #1233 to tick these, each with a `Landed` or `Done` bullet in #1226's form, so that release 1 closes at 92 of 96. Its ruling `5999175092` settles three points: (a), (a) and (a). Every sha in the bullets was read from GitHub.
- **T095**: openDox-code#75 → `389e5a4a`, which is X. Its `acceptance` job at X is the dispatched run 37333323932: `head_sha` X, job 111841708700, `success`, and its log reads `AT-R1 HTTP half: PASS (314 assertions held)`.
- **T099**: P against X. The compare shows four files between them, none a build input, so the ruled check exits 0. Then the tag, the release run, PyPI's two files and openDox#19, as above.
- **T002** (ruling (a)): 45 of the 50 slices in the three phases' writer tables were claimed on #656, and the bullet cites each claim. The five that were not are named in T091's form: P1-C, whose claim `5850230046` was posted as a literal file path and never edited, and P1-L, P2-H, P2-L and P2-M. Nothing is back-filled.
- **T007** (ruling (a)): batches A to P have landed (P #1230 → `ba6bb870`), and its status sentence now says so.
- **T097**: the census and research R16's corrections, with two non-normative notes beside them:
  - D6's T096 refusals, *"refused by name, with no browser signal"*;
  - the reachability of #1241's first commit, `f632d70c`, which `oracle-verdict.md` names as holding the bytes that ran (ruling (a)'s wording). It is not on `main`: `refs/pull/1241/head` (`5c663a7e`) reaches it, and so does #1241's branch, which still stands. `main`'s `SHA256SUMS` fixes the reviewed scripts, and the record names the ran bytes by their sha256.

## The checkpoint citations, by path

Lane openxfactory-4 ruled at 2026-10-05T16:25:25Z that the notes' `CP1 § n` and `CP2 § n` citations name their records, as the phase-3 notes name `evidence/checkpoint-phase3.md`. `CP1` and `CP2` are the shorthand of lane 4's table, and #1144 never defines them. The change is non-normative and inside T097's R16 scope. `10b6ba05` makes it. The 26 citations, in 25 notes, now read `evidence/checkpoint-phase1.md` (T049, #1204) and `evidence/checkpoint-phase2.md` (T063, #1218). A word diff against `e873b25f` finds those 26 tokens and nothing else; only the 25 paragraphs' line breaks move.

## F4.1, F5.2 and F16.1, closed on T089

T089, phase 3's checkpoint, landed on 2026-10-05T15:26:43Z as #1238 → `fab575ad`. Its record, `specs/034-opendox-standalone-operation/evidence/checkpoint-phase3.md`, extracts each block from #1144 by anchor at `36908480` and runs it from a fresh worktree at the commits phase 3 pinned: openDox-code `dede32b4`, the `code` of the openDox root `e1e3a3c3` (T087), and openXdox-code `56e1c238` (T086). It says of F4.1 and F5.2 *"T097 ticks both in #1144; this record ticks nothing there"*, and plan 034's T089 `Run` bullet says the same. Each box closes on that run, by plan 034's Box accounting:

- **F4.1** (`F4.1 → T089`): as extracted (sha256 `8900b985e72f`) and run unchanged, it exits 0 with `1 passed`, `1 passed`, then `no deferred reach names the consumer or the publisher` (§ 1).
- **F5.2** (`F5.2 → T086, T089`; RULED `5962785556`, item 1, moves its close to phase 3): whole, as batches C, F, G and K amend it (`OPENXFACTORY` at `36908480`, last step `--chains`), it exits 0. The seven suites pass whole (45, 23, 18, 6, 40, 9 and 12 passed), `test -s` holds, and the last step prints five `admitted:` lines, then `ok: 5 protected edit(s), each entered and holding` (§ 5). One of the five admits T086's edits to `tests/test_session_snapshot.py`, by entries 16, 17 and 19 of `tests/protected_suite_respellings.yaml` at `56e1c238`: the three pre-arc reds that T063 quoted, each entry naming the test it repairs.
- **F16.1** (`F16.1 → T083 (at 38d3350e), T089 (batch P's cases, at T087's pin)`): with batch M's line, it exits 0 with `24 passed`, the dialect line, `no model configured: the catalog offers nothing`, `83 passed` and `532 passed` (§ 4). `dede32b4` carries the T100 follow-on (openDox-code#86 → `651c35fe` is its ancestor, and the only commit between T100's landing and `dede32b4` that touches `tests/test_model_binding_trust.py`). That file is the same at both: 160 tests, among them batch P's six `test_F16_1_batch_p_*` cases and A8's `test_A8_a_state_directory_that_is_a_link_trusts_nothing`, none of which exists at `38d3350e`. T083's run there is quoted beside it, as before.

## 3.3, closed on T098

3.3 asks that the carve manifest's `deleted_at_carve` row for `scripts/ideation_dashboard/profile_openxfactory.py` stay BYTE-IDENTICAL. T017, which realizes it, reads the row through the three interim F11.1 runs, *"and T097 ticks 3.3 on all three"*. Each was re-checked on `main` `20ce593e`:

- **Phase 1**, T018 (#1202 → `e81eed62`, `evidence/f11.1-phase1.txt`): the amended run at T047's landing prints `requirement 1 holds: 0 note(s) annotated, every other path a declared surface (11.1)`, and the record's T017 section reads the row.
- **Phase 2**, T065 (#1217 → `1f670bc3`, `evidence/f11.1-phase2.txt`): the same line, at T064's landing.
- **Phase 3**, T098 (#1237 → `20ce593e`, `evidence/f11.1-phase3.txt`), at ARC_TIP `36908480` (T094, #1236). It prints the same line (exit 0) over the arc's three landings, and it refuses a planted path. `docs/opendox-carve-manifest.yaml` is touched by none of the three. Its T017 section finds the row equal at the manifest's introducing commit `17167481` and at that tip, both raw and parsed: `not_moved`, `deleted_at_carve`, no `edits`.
- **Re-read for this tick at `main` `20ce593e`:** the row is still equal to `17167481`'s, both raw (4 lines) and parsed. `scripts/opendox_host.py` is still openxFactory's host: T094 modified it and deleted nothing, which F11.1 would have refused.

## 4.3 and 9.2, closed on T086

T086 landed on 2026-10-05T12:23:03Z as openXdox-code#37 → `56e1c238`. It is a squash whose tree (`78ef1ed1`) is that of its head `57bebd8b`. Its pin is openDox-code `dede32b4`, the commit T087 pins (openDox#18 → `e1e3a3c3`).

- **4.3** closes *"with the last of"* the nineteen reaches into openXdox, and *"openXdox-code's ratchet (`OPENDOX_BACK_IMPORTS`) is tightened to `(0, 0)` in the same landing"*. At `56e1c238`:
  - `tests/test_dependency_direction.py` holds `OPENDOX_BACK_IMPORTS = {}`, and `test_the_pinned_opendox_does_not_import_openxdox_back` asserts `(0, 0)`.
  - openXdox-code#37's body reads that file `17 passed` at the pin, with the census empty.
  - `consumer_reach.py`, absent at `dede32b4`, was retired by T084 (openDox-code#77 → `e49b17c3`).
- **9.2** closes in phase 3 (batch F's addendum), with batch B's note. At `56e1c238`:
  - `tests/declared_exclusion.yaml` holds 66 entries carrying 68 reasons: 60 `doc_health`, 3 `status-exemption-rail` and 5 `openxfactory-contracts`.
  - CI's `validate` at the PR's head (openXdox-code run 37307785866) printed `open extraction: the declared exclusion` and `triple: selected=1099 passed=1095 skipped=4 failures=0 errors=0`.
  - Requirement 9 stays open until T008.

## 16.3a, closed on the T100 follow-on

16.3a is *"Carried out by T100"*, and batch P's addendum adds *"Carried out by a T100 follow-on openDox-code PR (claim `5982447319`), which is no task of plan 034 and lands before T087"*:

- T100 landed as openDox-code#82 → `38d3350e`.
- The follow-on landed as openDox-code#86 → `651c35fe` (09:49:55Z). It is a squash whose tree is that of its head `aecac805`, and it landed before T087 (openDox#18, 11:58:27Z) and T101.
- It carries out Brett Heap's `5982436447`, item 2, and `5983805990`, with the holder's `5984069416`, `5985046107` (C1 to C5) and `5985553609`, and the holder's A8.
- Its body records the falsifier: F16.1's block as batch P amends it, run by T089's runner at `aecac805`, exits 0 with `532 passed` in `tests/test_model_binding_trust.py`. The six `test_F16_1_batch_p_*` tests are present at `651c35fe`.
- The open trust-time existence check, and the follow-ons of openDox-code#86's eighth Copilot review, move no box of release 1. 16.3a's own text says so for the first, and the holder's `5992038800` for the second.

## Left open, by T097's own text

- 9.5, 11.0, 11.1 and F11.1, for the arc's close (T090 to T093), and F9.2, until T008. Nothing else is held.

## T097 is ticked

T097's task is *"Tick #1144's release-1 boxes, each with its evidence note: the 63 in the table below."* All 63 are ticked, so `f94be2fd` ticks T097 in the same commit as 10.3, the last box, as lane 4's brief requires.

## The merges of `main`

- **`bd32ea9c`** merged batch P (`ba6bb870`). It gave the one conflict this PR expected, at 16.4's checkbox line, which follows batch P's insertion at the end of 16.3a. The resolution took `main`'s text for every hunk batch P changed and re-applied the ticks and notes with the same tool, byte-identical to a fresh re-apply onto `main`'s file.
- **`96c74eab`** merged `main` `20ce593e` (#1234 to #1237). It was clean, because none of the four touches #1144's `tasks.md`.
- **`f6c6dc3c`** merged `main` `a43845e6` (#1238 and #1239). It was clean too, because neither touches #1144's `tasks.md`.
- **`9759313b`** merged `main` `f2acc88c` (#1240), and **`0cde3961`** merged `main` `8a37a087` (#1241). Both were clean, for the same reason.
- Every tick since is a fresh re-apply onto `main`'s file.

## Gates, at `main` `8a37a087` and at this head `9713f991`, in one full clone named `openxFactory`

| gate | `main` `8a37a087` | this head `9713f991` |
|---|---|---|
| `python3 scripts/validate-openspec-cli-pin.py --all --no-cache` (CI's form; pinned 1.12.0) | rc 0, `110 passed, 1 failed (111 items)`, `0 UNDISPOSITIONED failures`, 1 accepted exception (`add-chain-attestation`) | identical output, but for the pinned CLI's temporary directory |
| `… --change add-neutral-product-standalone-operability` | — | rc 0, `1 passed, 0 failed`, `validated --strict clean` |
| `scripts/doc-health.py --single-repo . --as-of 2026-10-05` | `31 critical, 22 error, 69 warning, 20 info`, 0 new regressions | byte-identical report |
| `proposal-support.py . verify add-neutral-product-standalone-operability` | ok | identical |
| `validate-sequenced-after.py . --ledger-diff` | 229 rows, consistent | identical |
| `validate-code-surface.py`, `validate-target-release.py`, `validate-pin-registrations.py`, `validate-document-catalog.py` | rc 0 each (the catalog: 0 errors, 0 warnings) | identical |
| `pytest -m "not postgres"` over `tests/doc-health`, `sequenced_after`, `proposal-support`, `former_id_arrival`, `citation_remainder`, `signed_execution_chain`, `openspec_cli_pin`, `target_release`, `code_surface`, `packet_reference`, `scope_globs` | the 8 below fail identically | running (the last full run, at `10b6ba05`: `8 failed, 3427 passed, 1 skipped`) |

The 8 failures are environmental, the same 8 at every head. Each needs the `openDox` and `openXdox` legs initialized, as CI's `pytest-suite` does, or a reachable pinned validator: `test_ideation_readiness.py` (3), `test_readiness_dispatch.py` (1), `test_sentinel_vocabulary.py` (2), `test_status_reader_real_lines.py` (1) and `test_chain_reader.py` (1). Re-run alone at `main` `8a37a087`, they read `8 failed` with the same messages. The venv was built by CI's own `pip install --require-hashes -r requirements/hermes-runtime-contracts.lock`, with `LANG=C.UTF-8` and every `GIT_*`/`XF_*` variable unset. The earlier rounds read the same: `main` `c8d80020` against `76d8ff37`, `b7f49673` and `e2efb3a1`, `main` `ba6bb870` against `bd32ea9c`, `cf2c6bdc`, `5870cd00` and `23665543`, `main` `20ce593e` against `935164af`, `main` `a43845e6` against `e873b25f`, and `main` `f2acc88c` against `10b6ba05`. At `f94be2fd` the local run was stopped at 31% on a session swap, and CI's `pytest-suite` passed there. No test, script or workflow reads plan 034's files (`git grep` over `tests`, `scripts` and `.github` finds none).

Also checked, on the inserted text at `9713f991`:

- every `repo#n → sha8` in #1144's notes (71 distinct pairs, 122 mentions) and in plan 034's bullets is that PR's merge commit, per the forge;
- every other sha (`17167481`, `1e4a57fb`, `36908480`, `5c137a90`, `626f2c8d`, `aecac805`, `dede32b4`, `f8a1ece`; in the plan, `5c663a7e`, `9153c254` and `f632d70c`) resolves in its repository, and the file digests match PyPI's JSON and the `SHA256SUMS` files;
- each of the 63 `Landed` dates equals the last landing of the box's realizing tasks (F5.1's and F7.1's notes also name T063's later re-run, and 5.4a's names the host line, #1215);
- no closing keyword, no `Arc:` line, no host path, and no unqualified reference to another repository, in the diff, the commit messages or this body;
- no inserted line is wider than 80 characters, and in #1144 none starts a list, a heading or a table.

## CI and review

- **CI at this head `9713f991`:** running.
- **CI at `f94be2fd`:** every check-run completed `success`, the 8 required among them (`pytest-suite` 17:13:56Z to 17:31:21Z).
- **CI at `10b6ba05`:** every check-run completed `success` (`pytest-suite` until 17:04:09Z).
- **CI at `e873b25f`:** every check-run completed `success`, the 8 required among them (`pytest-suite` 15:57:01Z to 16:22:01Z). `lane-line` re-ran on each edit of this description and passed.
- **CI at `935164af`, `23665543`, `cf2c6bdc`, `bd32ea9c` and `e2efb3a1`:** every check-run completed `success`, the 8 required among them (`signed-execution-chain-gate`, `lane-line`, `former-id-arrival-gate`, `openspec-cli-pin`, `wallet-validation`, `pytest-suite`, `release-tag-gate`, `openxdox-consumer-gate`). At `5870cd00`, `23665543`'s run superseded its `pytest-suite`.
- **Copilot at `76d8ff37`:** one finding, r4179674026: F7.2's note named no landing commit for T058 or T063. `b7f49673` names them (openDox-code#68 → `047bb4fa`, openxFactory#1218 → `a883bbf6`), and 7.1's changelog landing too (openDox#15 → `66758438`). The thread is answered and resolved.
- **Copilot at `b7f49673`:** no new finding, and one "previously missed" note: that 5.4a's note wrongly said T059's run deselected the three pre-arc cases. The note was right, and comment `5985467371` gives the records. The cited lines are T059's Falsifier line, written before it landed; T059's `Landed` record and openXdox-code#35's body (rulings 4 and 6, and its F5.2 run) record the deselections. `e2efb3a1` makes the note exact and cites them.
- **Copilot at `5870cd00`:** *"Findings: None"*, and one "previously missed" low note: 5.5's note read as though `consumer_reach` *"names the task lists"*. `23665543` says what it meant, that the seven `consumer_reach` names T055 lists are retired.
- **Copilot at `e2efb3a1`, `bd32ea9c`, `cf2c6bdc` and `23665543`:** *"Findings: None"*. Where its status line read *"Changes recommended"*, it named only what this DRAFT waits for.
- **Copilot at `935164af`:** one finding, r4185667778: 5.4a's note read *"the seven red at both pins"*. `e93ab9fb` reads "the seven reds", and the thread is answered and resolved.
- **Copilot at `e873b25f`:** one finding, r4186043242: this description was stale after T089's ticks. It is refreshed here, and the thread is answered and resolved. A second request at that head registered no new review.
- **Copilot at `10b6ba05`:** *"Findings: None"*.
- **Copilot at `f94be2fd`:** two findings, review `5418196219`. r4186761333: plan 034's opening status still said batch P was to land, against this PR's T007 tick. `9713f991` says that all sixteen batches have landed, A (#1171) to P (#1230), and that T007 is closed. r4186761413: this description was stale at `e873b25f`. It was refreshed at 17:16:28Z, while that review ran, and is refreshed again here for `9713f991`. Both threads are answered and resolved.
- **Copilot at `9713f991`:** review `5418607294`, on the push. Its one open item was r4186761413, this description, refreshed here for `9713f991`. Its two "previously missed" low notes, at plan 034's lines 129 ("whose message lacks") and 4496 ("the drive"), need no change, because each phrase is the wording of the record it cites, T091's and `oracle-verdict.md`'s. A comment on this PR gives the records.
- Sourcery posted a reviewer's guide, and no comment on the diff. At 17:16:25Z it reported its review budget used, and its check-run reads `skipped` at `f94be2fd` and at `9713f991`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)


Lane: openxfactory-4
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants