9c7f60b269d86b3cdff83a42f4c4882342fe9774
156 Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
9c7f60b269 |
docs(ledger): C29 self-description contract -- INDEX entry + domain invariant 13
The cycle's design principle enters the ledger: every closed-vocabulary entry the binary exposes carries a one-line meaning behind one shared deterministic shape gate (doc_gate) at three seams -- compile/unit for engine-shipped entries, load for native node crates, register for the content-addressed store (documents: an additive-optional gated description). Forbids the engine evaluating description text (C17 / invariant 10), any influence on execution/identity/determinism (C1), retroactive invalidation of registered artifacts, and machine-invented meaning lines. Why: the audience is headless LLM agents (#319); field evidence #314 showed schema knowledge being recovered by CAS forensics from the release binary -- the removed failure class. All spec acceptance criteria are now met across the four iterations of this cycle (core carrier + std texts; domain threading; load seam; register seam + op-script doc slot + document description). closes #316 |
||
|
|
8688a60ded |
docs(ledger): split the design ledger into an INDEX map, per-contract live files, and history sidecars
The single-file ledger had grown to 2968 lines / ~42k tokens, mixing current design law with accreted history: 59 cycle-stamped realization blocks, 18 [HISTORY] passages, 22 supersession markers, and the C10 / C22 / C24 reframe sagas layered several supersessions deep. A code-grounding audit (31 agents, adversarially verified) confirmed 11 defects stated as current truth: stale crate homes from the C28 #288 roster split (cost nodes, PositionManagement, PositionEvent, Session), the renamed InputSpec->PortSpec, the pre-#241 project model in C16 and the open-threads section, a stale HarnessKind retirement deferral in C24, and three C28-internal inconsistencies. New shape, per the ailang precedent: - INDEX.md stays the sole addressable entry point: foundation, external components, a C-id-keyed contract map (one line per contract), and only the genuinely open architectural threads. - contracts/cNN-<slug>.md carries each contract's current truth only: Guarantee / Forbids / Why with ratified refinements integrated, plus a code-anchored Current state. All confirmed defects are fixed here; crate anchors were re-verified against the tree. - contracts/cNN-<slug>.history.md (18 sidecars) and INDEX.history.md preserve every superseded block verbatim, stamps and issue refs intact, under a frozen-record banner. Nothing was deleted: superseded design intent remains an addressable working-tree artifact, off the per-cycle audit walk. - Ledger discipline is now stated in INDEX.md: live files are edited in place at cycle close, superseded text moves verbatim to the sidecar, and a supersession marker in a live file is itself an audit finding. Every contract file was verified against its old text by an independent zero-loss pass (statement-by-statement) plus a code-accuracy spot check; C-ids and contract titles are unchanged, so existing C-id citations in code, tests, and issues resolve as before. |
||
|
|
757e3ac1bd |
feat: the document-first surface closes — show read-back, typed stops, bare plateau
The #300 keystone cycle: the residual run-quintet flags were already document vocabulary on the --real arm (#210/#220); this closes the loop and ratifies the surface. - `aura process|campaign show <content-id>` prints a registered document's canonical bytes (print!, no framing — #164), so generate -> retrieve -> hand-extend -> re-register needs no direct store filesystem access. Refusals reuse the store-hint prose, exit 1. - walkforward/mc --stop-length/--stop-k become clap-typed i64/f64 (generalize's form); stop_knob_or and its parse_csv_list helper are deleted (multi-value/invalid input is now clap's exit-2 rejection — the two dissolved-verb refusal tests retarget, the type-dead unit test is deleted). - --select accepts bare `plateau` as the documented default plateau:mean (#227 carry); document schema untouched — the two spellings generate content-id-identical campaigns (test-pinned). - family.rs's quadruplicated demo stop literal collapses onto one DEFAULT_STOP const (maintainer-lens drift finding). - Ledger: C25's "which projection next" line resolved (document-first delivered, per-verb identity re-ratified — F8; host/MCP stay demand-driven); C18 records the read-back. Design triage, fork decisions F1-F8, and the auto-signed spec live on the reference issue. Verification: full workspace suite 1482 passed / 0 failed with the real GER40 archive exercised (the byte-identity round-trips ran, not skipped); clippy -D warnings clean. closes #300 |
||
|
|
4ed6455b64 |
fix: load_family resolves the enumerated family name, refusing ambiguity (#298)
GREEN for 78e68e6's RED. aura_runner::reproduce::load_family resolved
only the derived C18 handle '{family}-{run}' while the registry's
enumeration exposes the bare name factor — the natural
list-then-reproduce library workflow dead-ended (found by the #295
fieldtest; predates the extraction byte-identically). Resolution now:
exact-handle match keeps first precedence; a bare name naming exactly
one stored run resolves as fallback; an ambiguous name (several runs,
or a name/handle collision) refuses without guessing, listing the
candidate handles. Two additional tests pin the ambiguity refusal and
the handle-precedence-on-collision semantics.
Ledger record-reality rider: the C18 #158 paragraph claimed reproduce
refuses an unknown id with exit 2; the code has always exited 1 —
correct per C14's partition (the id names missing recorded state, a
runtime failure, not a usage error). The paragraph now records the
actual behaviour and the new name-fallback semantics.
Verification: cargo test --workspace green (1477 passed, 0 failed);
clippy --workspace --all-targets -D warnings clean.
closes #298
|
||
|
|
5006766579 |
audit: shell-boundary cycle close — drift resolved in-commit
Cycle-close audit (architect: drift_found; design core clean). What holds, architect-confirmed with the guard run and the diff read in full: the shell boundary is real and enforced (full-workspace c28_layering incl. completeness + shell-content checks, acceptance grep clean — no member-run symbol left under crates/aura-cli/src); aura-campaign keeps zero production dependency on the runner; the IC move is verbatim against the anchor; the new library-only E2E pins C1 (two independent runners, byte-identical RunReport). Drift items, all resolved as fixes in this commit: - design ledger: the C28 status sentence "No crate exists yet for measurement" contradicted this cycle's own phase-3 done line — now records aura-measurement as seeded (#295), execution still unbuilt. - the #147 registry-dispatch acceptance tests (IC deflation null, seeded determinism, cross-vocabulary refusal) were pure library properties stranded in the shell's test module — relocated to aura-measurement/tests/registry_dispatch.rs (engine/registry as dev-only, layering-exempt edges), per the cycle's own tests-move- with-their-module rule. - aura-runner's direct production edge on the external data-server tree was structurally invisible (the direction table checks aura-* keys only) and unrecorded — the C28 assembly prose now names it, and a new c28_layering test pins the external tree's entry points to exactly {aura-ingest, aura-runner, aura-cli}. - the C28 shell prose named three buckets that did not cover two real shell residents — it now names the op-script construction front-end (translation) and the `aura new` scaffolder (authoring-tooling, shell-resident like rendering until a second consumer wants it). Deliberately deferred, tracker homes exist (not drift): #297 (process::exit sites in aura-runner's single-run verb paths), #294 (IC duplicate-timestamp semantics), #288-era rustdoc unresolved-link warnings in aura-std/aura-backtest (pre-existing byte-identically at the anchor). No regression scripts are configured (the bench is report-only); the architect review is the gate. Verification: cargo test --workspace green (1474 passed, 0 failed) incl. the relocated registry-dispatch tests and the new data-server guard; clippy --workspace --all-targets -D warnings clean. refs #295 |
||
|
|
170c6c82dc |
feat: full-workspace C28 guard — the shell boundary is structural (#295 part 2)
Completes the shell-boundary cycle (tasks 10-13): - c28_layering now enumerates the FULL workspace: every crate row is reconciled against its real production [dependencies], a completeness assertion pins the table to the on-disk crates/ set (a new crate can no longer escape the guard silently), the shell/assembly imported-by- nothing rule is asserted, and a shell-content check pins aura-cli to no-[lib] plus a closed allow-list of argv/translation/presentation modules. A new domain module in the shell now fails the suite. - Ledger amendments: C28 gains the assembly position (aura-runner) and the corrected import-rule prose (the ratified aura-campaign -> aura-backtest production edge, #291/#292); phase 3 is marked done with the #297 process::exit residual named; a provenance note records this as structural-debt closure, not a demonstrated downstream blocker. C25 records the control-surface decision: the text artifact vocabulary is canonical, every control surface (CLI executor verbs, a future host, an MCP face, a World program) is a projection/executor over it — the which-projection-next ranking deliberately open on #295. C14 gets the executor-face amendment, C26 the binding-module relocation. - aura_campaign::MemberRunner's doc names the shipped default implementor (aura-runner::DefaultMemberRunner) while the column keeps zero dependency on it. - New library-only E2E fixture (aura-runner/tests/world_member_run_e2e): runs the canonical member recipe over a tiny synthetic archive with no aura-cli in the link graph, and pins C1 determinism (two independently constructed runners produce a byte-identical RunReport). - campaign_run.rs module doc: intra-doc MemberRunner link re-anchored to aura_campaign::MemberRunner (the impl moved out with part 1). Verification: cargo test --workspace green (1473 passed, 0 failed); clippy --workspace --all-targets -D warnings clean; cargo doc clean of NEW warnings (the five unresolved-link warnings in aura-std/aura-backtest predate this cycle byte-identically at the anchor — #288-era doc drift, left for the cycle audit). refs #295 |
||
|
|
2cf4574e33 |
audit: cycle metric-vocabulary tidy — ledger records the retired #147 deferral
Cycle-close audit (architect: drift_found, design core clean). What holds, architect-confirmed: C18 bit-identity for RunMetrics (prose derived byte-identically, rng order preserved, registry suite unchanged); the C10 wall (monomorphic R-gates, r_based in the R vocabulary, cross-vocabulary refusal tested both ways — no leak); C28 direction (trait in aura-analysis, vocabulary supplied from the outer rungs, zero Cargo edge changes); C1 determinism pinned through the generic path. Drift items, all resolved as fixes in this commit: - design ledger: the C28 #147 disposition now records item 2 SHIPPED (the A1 cut) with A2 still deliberately deferred; the #136 one-implementor clause carries a supersession note (the IC is the second implementor). - seven stale doc comments describing the pre-#147 or mid-cycle state (analysis trait + estimator docs, registry check_r_metric C9 claim, engine re-export note, campaign PER_MEMBER_METRICS roster note, member-seam guard comment, research vocabulary note) updated to the shipped state. - R_BASED_METRICS is now oracle-pinned against RunMetricKey::r_based() in the vocabulary test (it feeds the NonRMetric refusal prose; a divergence would have misreported the R-gate silently). Noted, not amended (history stays): commit 6744f67's body says 'three syntax-only edits' where the test module actually took five. No regression scripts are configured (the bench is report-only); the architect review is the gate. Verification: extended vocabulary test, campaign suites, analysis/research suites green; clippy --workspace -D warnings clean. refs #147 |
||
|
|
a56ab7859d |
refactor: cut the engine's backtest-metrics edge via RunReport<M>
C28 phase 2 (Stratification); realizes item 1 of the deferred #147. The engine's production surface no longer names a backtest-metric type: - RunReport becomes generic over its metric payload M; sweep/mc/walkforward/ blueprint thread the parameter (SweepPoint<M>, SweepFamily<M>, WindowRun<M>, WalkForwardResult<M>). RunManifest stays concrete and engine-owned (its selection: Option<FamilySelection> embeds the foundation-grade analysis type). - summarize and the MC assembly (McDraw/McFamily/McAggregate/RBootstrap/ r_bootstrap/monte_carlo) move to aura-backtest - McAggregate::from_draws reads RunMetrics fields by name, so generifying it is the phase-6 metric-vocabulary abstraction (#147 item 2), still deferred; wholesale relocation is the honest cut. The concrete instantiation lives in aura-backtest as `type RunReport = aura_engine::RunReport<RunMetrics>` + sibling aliases. - the statistics kernel (MetricStats/quantile/resample_block/SplitMix64) moves to the aura-analysis foundation; the engine re-imports it (inner->foundation, legal) and re-exports it so existing consumers stay source-compatible. Dependency inversion in one commit: aura-engine drops aura-backtest from [dependencies] (back to dev-deps for its SimBroker/RunMetrics test fixtures); aura-backtest gains aura-engine. Cycle-free for lib targets - the cycle closes only through the engine's dev-dep edge, the pattern aura-vocabulary already uses. aura-backtest reaches the kernel transitively through the engine re-export, so no aura-backtest -> aura-analysis edge exists (the C28 ladder permits backtest -> {core, engine} only). run_indexed / SplitMix64::next_f64 widened pub(crate) -> pub for cross-crate use. Consumers (registry/campaign/cli/composites/ingest/bench) rewired by import path only, no call-site logic changed. The c28_layering structural test extends to the full ladder: aura-analysis (no aura-* deps), aura-engine ⊆ {core, analysis}, aura-backtest ⊆ {core, engine}. Behaviour-preserving: 1448/0 tests, clippy -D warnings clean, serde shapes byte-identical (C18 - RunReport<M> keeps field order manifest,metrics; the CLI pre-serialized-splice contract unchanged), moved code traceable via git rename detection. Cycle-introduced broken intra-doc links fixed. closes #292 |
||
|
|
94aaa4cde8 |
refactor: split aura-analysis into statistics and backtest metrics
C28 phase 5 (Stratification): the backtest reductions - RunMetrics, RMetrics, summarize_r, r_metrics_from_rs, and the position-event table - move verbatim into aura-backtest::metrics, beside the position_management producer whose record layout they read (the r_col/cost_col lockstep contract is now intra-crate; its stale "aura-std" comment corrected). aura-analysis is reduced to the domain-free half: the multiple-comparison hurdle math (inv_norm_cdf, expected_max_of_normals) and the selection-provenance types (FamilySelection/SelectionMode - kept beside the statistics so RunManifest.selection embeds a foundation-grade type), [dependencies] = serde only. The engine re-export surface is name-unchanged (report.rs re-imports from both crates), so no indirect consumer needed a source edit; aura-backtest moves from aura-engine's dev-dependencies into [dependencies] as a commented TRANSIENT widening of the C28 violation, removed by the phase-2 edge cut on this branch. The campaign drift guard imports its pinned types from their new source crates. Behaviour-preserving: 1448/0 tests, clippy -D warnings clean, serde shapes byte-identical (C18), moved code traceable via git copy detection. closes #291 |
||
|
|
b39fd63396 |
refactor: split the aura-std roster into C28 layer crates
Phase 4 of the Stratification milestone. aura-std held four C28 ladder layers in one roster; this cuts them into layer-aligned, aura-core-only node crates so the import direction is enforced by the crate graph: - aura-std — engine nodes only (arithmetic/logic/rolling + sinks) - aura-market — session, resample - aura-strategy — bias, stops, sizer, cost-model machinery - aura-backtest — sim_broker, position_management - aura-vocabulary — the relocated closed std_vocabulary roster Node modules move verbatim (byte-identical renames); consumers are rewired by import path only. A new structural test (aura-vocabulary/tests/c28_layering.rs) asserts each node crate's [dependencies] stay within its C28-permitted inner set, catching the acyclic-but-outward violation the compiler misses. Behaviour byte-identical: full workspace suite green (1448 tests), no golden edited, clippy -D warnings clean. C28 Status block updated. closes #288 |
||
|
|
1c49d5dce2 |
design: ratify C28 — internal stratification (ladder, process column, shell)
Codify the layer model settled with the user: an inner-to-outer ladder
engine -> market -> {measurement | strategy} -> backtest -> execution,
the research-process column beside the ladder, the shell outside. States
the import rule (inner never imports outer; measurement/strategy
siblings; column imported by no ladder crate; shell imports all;
dev-deps exempt), the six seams (five already ratified contracts —
C8/C24/C27/C18/C10-C13 — only the metric interface new), and an honest
Status recording the one hard production violation (engine -> analysis
via report.rs re-exports + the R-typed mc.rs fields) and its coupling to
the deferred #147.
Also restore the "### C19" header, deleted as collateral of
|
||
|
|
a5e02ff541 |
docs: SessionFrankfurt output semantics + declared-tap authoring (#285)
Surfaced by the measurement-milestone fieldtest: a downstream author reaching for session anchoring or declared taps had no public statement of either — the semantics lived only in node source / the design ledger. SessionFrankfurt / Session output semantics: - glossary `session node`: corrected — it claimed three streams (`bars_since_open`, `in_session`, `session_open_ts`), but the shipped node emits ONE `i64` field `bars_since_open`. Now states the real contract: the count of completed bar-periods since the local (tz-aware, DST-correct) session open, close-instant indexed (09:15->1, 09:45->3; pre-open <=0), with the Frankfurt 09:00 Europe/Berlin open + `period_minutes` knob + the value-ignored `trigger`. - authoring-guide: a "Session anchoring: the SessionFrankfurt preset" subsection — schema (trigger / period_minutes / bars_since_open), the close-instant multiples, the EqConst gating pattern, DST handling, and the add-snippet. Verified against `aura graph introspect --node SessionFrankfurt`. Declared-tap authoring (C27 / the #284 tap op): - authoring-guide: the `tap` op-table row (seven ops -> eight) + a worked "declaring a measurement tap" example. The example is verified: piping it through `aura graph build` emits `taps:[{"name":"spread","from":{"node":2,"field":0}}]`. - design ledger op-list (INDEX.md): a `tap` bullet (seven verbs -> eight); also corrected the `expose` "only verb that keeps `as`" claim — `tap` keeps it too. - README op-kind enumeration: adds `tap`. Docs only; no code change. Both worked examples were run through the built `aura` binary; the SessionFrankfurt schema was checked against introspect. closes #285 |
||
|
|
7a4e5eb99d |
docs(ledger): C27 — declared taps contract (#282)
Records the tap/binding contract: taps are the output-side twin of input_roles (C26), resolved and hoisted at compile, bound run-mode-aware via a caller-built sink (engine stays aura-core-only), recorded on the single run and inert in a sweep. Documents the deliberate DCE-deferral — build-time elision now, chain-pruning when DCE (C23) lands — and the unbound-is-inert non-error asymmetry vs a mandatory input role. refs #282 |
||
|
|
07c94433f3 |
audit: cycle-close tidy for #191 — C18 realization note for the identity index
Cycle #191 (identity-ref index) closes drift-resolved. Architect review
held: results stay scan-identical via verify-on-hit (the same-identity-
twin choice was order-unspecified before and stays unspecified in kind);
zero caller/write-path/engine changes; the #276 append-lock discipline
correctly extended to the fourth JSONL path. No regression scripts are
configured; the architect review is the gate.
Drift items and resolution:
- C18 lacked a realization note for the new persistent sidecar store and
its index-first/verify-on-hit/repair-walk mechanism, and the "identity
refs by store scan" line was stale -> this commit adds the #191
realization note and dates the scan wording (fix, ledger-only).
- The repair pass grew the sidecar without bound while same-identity
twins coexisted (per-entry comparison against a mid-walk-stale
snapshot) -> fixed in-cycle via RED pin
|
||
|
|
69bb2fc978 |
audit: cycle-close tidy for #277 — preflight duplicate refusal, zero-bound pin, C1 realization note
Resolutions for the architect's four drift items (all fix/document, none ratified away): - [medium] execute enforced family-name uniqueness only via the CLI's validate tier: preflight now refuses duplicate campaign instruments itself (defense in depth for direct callers), RED-first (execute_refuses_duplicate_instruments). - [medium] the parallel cell loop's C1 relationship lived only in the git-ignored spec: C1 gains a realization note (docs/design/INDEX.md) recording the chunked instrument-major schedule, the structural residency bound, and the two scheduling-dependent fatal-path carve-outs (fault attribution among completed cells; already-written family lines) — both inert and outside the success-path bit-identity. - [low] the fatal-path orphan-line honesty is part of that note. - [low] the --parallel-instruments zero-reject acceptance criterion had no protecting test: campaign_run_rejects_a_zero_parallel_instruments_bound pins clap's NonZeroUsize usage error (exit 2). Gates re-verified: workspace suite green, clippy -D warnings clean. refs #277 |
||
|
|
9e30805fcc |
feat(cli,ledger): supply CLI run sources by role key; ledger note
closes #275 The CLI half of by-name source binding, plus the ledger record. Every production run site that carries a ResolvedBinding — `run_signal_r`, `run_blueprint_member` (sweep / reproduction), and the campaign re-run/trace path — now keys its opened sources by role name via `key_supply(binding, sources)` and drives the harness through `Harness::run_bound` instead of the positional `run(sources)`. `key_supply` pairs each opened column with its declared role from `binding.entries()` — the one place open-order and role-order meet, made explicit so `bind_sources` verifies the wiring↔supply role match by name rather than by a maintained canonical-order convention. Because the current single-binding CLI derives both the `SourceSpec` roles (via `wrap_r`) and the supply roles (via `key_supply`) from the same `binding.entries()`, the bind cannot fail on this path — so the call site asserts the invariant with `.expect`, matching the adjacent `close_handle.expect("ResolvedBinding guarantees a close entry")` idiom. The named `SourceBindError` refusal path lives in `bind_sources` for future decoupled-supply callers (independently-built multi-feed / recorded sources, #124), where a mismatch becomes reachable. Ledger: a C4 realization note (supply resolved by name into declaration order, so supply order is no longer load-bearing; the tie-break guarantee is unchanged) and a scoped C23 refinement (a `SourceSpec.role` is load-bearing for source binding; every other flat-graph name stays a non-load-bearing raw-index symbol). The fieldtest-corpus `SourceSpec` sweep (planned Task 5) was reverted: the fieldtest packages already fail to build against the current engine API for reasons unrelated to `SourceSpec` (bootstrap arity, removed `InputSpec`, drifted `Recorder`/`SimBroker`/`RMetrics`, renamed `Scalar` helpers) — pre-existing bit-rot from earlier cycles. A partial `SourceSpec` migration neither revives nor further breaks them, so the scope decision to touch them (premised on their being otherwise-buildable) was withdrawn; reviving the corpus is separate from #275. Verification: `cargo test --workspace` green (0 failed; the real-data OHLC channel e2e exercises the migrated `run_bound` path byte-identically); `cargo build --workspace --all-targets` clean; `cargo clippy --workspace --all-targets -D warnings` clean. |
||
|
|
f0aadb54f8 |
audit: cycle-close tidy for the #256/#272 latecomer block
Drift review (architect) over a55e4cf..HEAD found the cycle substantially clean — C25 closed vocabulary, C1 determinism/behaviour-preservation, the additive-serde widening, exhaustive StageBlock matches, and the uniform exit-3 convention all hold. Two drift items resolved: - RATIFY: the `SilencedPanic` member-boundary panic-hook silencer (added by the #272 implementer, not named in the spec) is a legitimate mechanism — it keeps "recorded, campaign continues" observably true on stderr by suppressing the default crash backtrace around each contained `catch_unwind`. Its mutex serialises only the ref-count/hook-swap (O(1)), never member computation, so C1 disjoint-parallel determinism is preserved. Documented in the ledger's #272 realization paragraph rather than left as undocumented global state. - FIX: `cell_fault_kind_label` hand-wrote the snake_case strings that must match `CellFaultKind`'s serde `rename_all` (two sources of truth an aggregate over campaign_runs.jsonl could silently diverge from). Pinned with a test asserting each label equals the serialized form; the efficient `&'static str` stays. (The #272 commit's own concern-driven doc fixes and the wf panic-containment test landed in d3b1a1a; this commit carries only the two audit-phase items.) Suite: cargo test --workspace green (1311 tests, 0 failed); clippy clean. |
||
|
|
d3b1a1aead |
feat(campaign,registry,cli): per-cell fault isolation — a failed cell is recorded, never a global abort
closes #272 A member fault (no-data, bind, run, or a caught panic) is now a recorded per-cell outcome instead of aborting the whole campaign and discarding every already-computed cell. The incident that motivated this (a 22-instrument campaign lost ~36 healthy cells ~6.7 min in because Copper had an archive gap) now completes: the healthy cells persist, the gap cell is recorded as failed, and the run exits 3. Direction (owner decision 2026-07-14): run to completion and report compromised results; no coverage preflight, no window synthesis. Containment granularity: - The CELL for a sweep-stage member fault (a grid hole structurally compromises winner selection, so the whole cell fails). - The FOLD for a walk_forward member fault (independent time windows): the surviving folds pool into the family, failed folds are recorded as StageRealization.window_faults, and the summary names the ratio. - aura-registry: additive CellFault / CellFaultKind (closed: no_data|bind|run|panic|window) / WindowFault / CellCoverage, plus fault/coverage fields on CellRealization and window_faults on StageRealization — all serde-default-skipped, so pre-#272 campaign_runs lines parse and round-trip byte-identical. - aura-campaign: run_cell returns a fault-annotated CellRealization instead of Err (execute's accumulate-then-append-once tail is unchanged and now persists every healthy cell + the one run record); a `contain` split keeps ExecFault::Registry and doc-shape preflight faults global while Member/Window become per-cell/per-fold. Member panics are caught with catch_unwind(AssertUnwindSafe) at all three member-run sites (sweep IS/OOS) and recorded as MemberFault::Panic — a member panic no longer aborts the process. The wf stage partitions Registry faults (global) from Member/Window (per-fold) and filters faulted-fold placeholders (the "faulted-member-placeholder" broker sentinel) out of the persisted family. - aura-cli: exec_fault_prose gains the Panic arm; CliMemberRunner::window_coverage derives effective bounds + interior gap months from the #264 archive primitives; present_campaign prints per-cell failure notes + a completion summary and threads the failed-cell count; a run with >=1 failed cell exits 3 ("completed with failed cells") uniformly across `aura campaign run` and the dissolved sweep/walkforward/mc/generalize verbs (exit_on_campaign_result). Usage stays 2, refused-before-running stays 1, clean stays 0. Tests: the global-abort pins flip to containment (execute + the two wf fault tests → fold-containment + all-folds-fail-the-cell); new panic-containment tests on both the sweep path (PanicRunner) and the wf path (this commit adds the wf mirror the loop left uncovered); a new gapped-archive e2e (one covered cell + one gap cell → exit 3); the ~14 CLI exit-1 pins move to the exit-3 register; a pre-#272-line byte-identical round-trip guard. Suite: cargo test --workspace green (1309 tests, 0 failed); clippy clean. Decision log: #272 comments (fork rationale, the fold Registry/Member split, the placeholder sentinel, uniform exit-3). Follow-up (minor, not blocking): the plan under-scoped Task 1 to aura-registry though the additive fields also touch aura-campaign's exec.rs literals — the loop absorbed it mechanically; a future plan for a cross-crate additive-field change should scope every crate's construction sites in the first task. |
||
|
|
ea4e79d73f |
feat(research,campaign,cli): std::grid — the enumerate-only leading stage
closes #256
Fork B (owner decision 2026-07-14): the dissolved walkforward/mc
translations' leading sweep executed the full grid over the whole campaign
window and persisted a Sweep family, yet only the enumerated parameter
points ever crossed the stage seam (the wf stage re-sweeps them per IS
window itself). The leading stage is now the fieldless vocabulary block
std::grid: it enumerates, executes nothing, persists nothing.
- aura-research: StageBlock::Grid ({"block":"std::grid"}), schema-strict
parse arm (empty slot list: every key but "block" is refused by the
generic unknown-slot check), PROCESS_BLOCKS entry, intrinsic-tier no-op
arm; the vocabulary test's non-empty-slots guard carries a pinned
std::grid-only exception (a nominal slot would misdescribe the
vocabulary to describe_block consumers).
- aura-campaign: the inter-stage seam is a typed two-armed StageFlow
(points-only vs executed members); gate / mc-per-survivor fence the
points-only arm with defensive PipelineShape faults; preflight admits
std::grid only as the first stage and only immediately before
std::walk_forward (every other neighbor consumes executed reports).
- aura-cli: translate_walkforward / translate_mc lead with
StageBlock::Grid; the two family-shape E2E pins flip to zero Sweep
families; translate_generalize keeps its executed sweep(argmax) — its
generalize stage consumes the argmax winner report as the cell nominee.
- docs: dated #256 amendment in the ledger's verb-dissolution narrative;
the authoring-guide vocabulary transcript gains the std::grid line.
Behaviour preservation: the exact-grade real-data pins
(walkforward_real_e2e_pins_the_exact_current_grade,
mc_r_bootstrap_real_e2e_pins_the_exact_current_grade) pass unmodified —
survivor points reach the wf stage in the same odometer order as before.
Measured (the #256 acceptance measurement; debug build, real GER40 2025,
2x2 grid, `aura walkforward --real`, 3 runs each):
before (
|
||
|
|
d1b3a3dd31 |
feat(research,composites,cli,docs): vol_tf — the timescale-matched stop regime
The second risk-regime variant vol_tf{period_minutes, length, k}
computes the vol estimator over completed time buckets: an H1 signal
gets an H1-matched stop in the research matrix instead of a hand-scaled
minute stop (the issue's k-inflation workaround retires). Additive
externally-tagged serde (stored Vol documents keep their content ids);
the executor arm wires the VolTfStop primitive via the builder+bind
chain; validate checks period_minutes/length/k positivity per regime.
The member-manifest round-trip holds for both variants (C1): vol_tf
members stamp stop_period_minutes/stop_length/stop_k and the reproduce
path re-derives the VolTf stop whenever stop_period_minutes is present
— never a silent default-Vol fallback. The Regimes slot label and the
unit notes name the new variant (period_minutes IS the stop's
timescale); glossary, authoring guide, and design ledger record the
second variant. Default regime and sugar paths byte-untouched.
Coverage: node units (rollover-only emission, bucket-delta math, the
constant-|delta| correspondence with the per-cycle regime), executor
fold, serde/validate units, the manifest round-trip unit, and a
hostless two-regime e2e (distinct ordinals; vol_tf members stamp their
timescale, vol members do not).
closes #262
|
||
|
|
bb0b0aeac2 |
feat(analysis,campaign,registry,cli): bootstrap net R through the process pipeline
The OOS bootstrap conduit RMetrics.trade_rs becomes net_trade_rs and carries the COST-NETTED per-trade R (r − cost_in_r, trade order). Every conduit consumer is thereby net-when-costed: the monte-carlo pooled-OOS and per-survivor bootstraps, the walk-forward oos_r pooling, and the deflation null-max — which previously compared a net observed statistic against a gross-resampled null whenever a costed campaign selected on net_expectancy_r. An uncosted run is bit-identical (empty cost stream ⇒ cost 0.0 per trade), so every existing golden pin stays green. Design: one conduit, no knob — an explicit net: knob would let a costed campaign silently produce a gross headline again (the exact misreading of the issue's evidence). Per-member RMetrics scalar fields stay gross; net_expectancy_r keeps its meaning. Wire shape unchanged (serde(skip)). The net series is materialized as a separate expression in summarize_r; the pinned-float expressions (net_sum, the SQN pair, the lockstep r_metrics_from_rs copies) keep their tokens verbatim. Fork decisions and rationales: issue #259 comments. New coverage, both hostless over the synthetic SYMA archive: a costed campaign twin shifts the pooled-OOS bootstrap (sweep→gate→wf→mc) and every per-survivor bootstrap (sweep→mc) below its gross sibling, with the trade population unchanged; a unit test pins the conduit as the cost-netted series with the empty-stream degeneracy. Existing conduit tests renamed with the field. Verified: full workspace suite green (71 result blocks), clippy clean, zero bare trade_rs tokens remain, ledger conduit prose updated in place. closes #259 |
||
|
|
1ebb94c1b8 |
feat(engine,cli): run manifests stamp untouched bound defaults (closes #249)
RunManifest gains defaults: Vec<(String, Scalar)> — the wrap-prefixed bound_param_space() of the signal, read after axis reopening, so a bound param an axis overrode has already left the space and flows through params instead (disjoint by construction; verified end to end: a sweep member's overridden fast.length sits in params while slow.length/bias.scale sit in defaults). params keeps its "what varied" semantics and stays the reproduce input. One-directional serde widening (#[serde(default)]) per the selection/instrument/topology_hash idiom — old records deserialize with an empty defaults; unlike the Option fields it always serializes, mirroring params. ~20 struct-literal sites across five crates gained the field (compile-mandated breadth, no behaviour change at those sites). The C14 ledger records the underlying decision (2026-07-13): generated outcome records spend redundancy on direct readability (single writer, cannot drift); authored intent artifacts admit none (every redundancy is a drift site) — so the fix lands in the manifest, never the blueprint. Verification: RED test run_manifest_stamps_untouched_bound_defaults green; cargo build --workspace; cargo test --workspace green; clippy -D warnings on the touched crates; binary-level sweep exclusivity check. |
||
|
|
487431d97d |
test(cli): migrate the _open references — closed twins for sweeps, fixtures for open semantics (closes #248)
The references to the relocated _open blueprints follow the plan's two-way split: tests that only need a sweepable blueprint sweep the closed twins via bound-override axes (#246) with their axis strings byte-unchanged (the wrap prefix is the blueprint's internal name, identical across twins); the 12 tests that genuinely exercise open-param semantics (run/mc closed-guard refusals, subset-axes MissingKnob, --list-axes open/bound line mix, gang dissolution and campaign paths) read the fixtures under tests/fixtures/. The research_docs/project_load store seeds sweep the closed twin (campaign axis references resolve via the #246 reopen path); the INDEX.md history note records the relocation. Two deviations from the plan, both verified against the tree: doc comments referencing the bare filename (no examples/ prefix) escaped the global path swap and were reworded to stay truthful; the seed variable open_bp was renamed closed_bp (the plan kept it, but the rename touches only the binding and its uses and removes a misdescription). Verification: cargo test -p aura-cli --test cli_run (140 passed, 0 failed, real data exercised); --test research_docs; --test project_load; the four byte-pinned exact grades unchanged; grep-clean for examples/r_*_open.json across crates+docs; full workspace suite green. |
||
|
|
e4fb64d7c6 |
docs: bound params are overridable defaults — C12 amendment, glossary, guide
Task 7 of the bound-override cycle: the design ledger's C12 records the bound-as-default semantics (axis 1 may name a bound param; identity reads the authored document; the retired axes-bind-only-open-knobs restriction was an implementation consequence, not a recorded decision), the glossary's blueprint entry carries the same sentence, and the authoring-guide's data-only starter section explains the one-file run+sweep quickstart. closes #246 |
||
|
|
0170ec277f |
docs: two-tier project model — layout, guide, glossary, ledger, invariant 9 (#241 T7)
- CLAUDE.md invariant 9 amended end to end: a project is a directory anchored by a static Aura.toml, data-only by default; native node logic lives in attached node crates (the nodes/ antecedent removed — user decision 2026-07-12, re-opened by the role model's diagnosis). - docs/project-layout.md reworked to the two tiers (data-only default tree + sibling node crate, workspace note under the crate half); the day-in-the-life walkthrough now attaches the project's node crate once and wires the namespace the shown command actually produces. - docs/authoring-guide.md: data-only quickstart (closed run target, open sweep target) + `aura nodes new` as the native entry; section cross-reference updated. - docs/glossary.md: new "data-only project" and "node crate" entries; Aura.toml and manifest entries carry the tier split. - docs/design/INDEX.md: realization note (wiring-only tier, #241) in the project-environment section. - rustdoc: `[nodes]` intra-doc-link escapes in project.rs/main.rs. Full gates green: workspace suite (all binaries), clippy -D warnings, doc build without new warnings. closes #241 |
||
|
|
43a427bfed |
audit: run-tail close — ledger and glossary reconciled to the shipped state
The tail audit over d1e01ef..62f6592 found no code drift against the contracts (C18 name-resolution read-only, C23 doc identity-blind and inline-dissolved, C1 fit deterministic) but four lagging records, fixed here: the #106 real-roller amendment gains the #239 fit-to-window note (fixed sizes are a ceiling on the sugar path); a #125 realization note records the composite doc as a C23 debug symbol with its serde/identity/ viewer treatment; the glossary identity-id and composite entries name the doc; GraphSession::finish states the deliberate absence of a doc-carrying op-script surface (refs #125) instead of leaving the authoring asymmetry silent. |
||
|
|
d1e01efebf |
audit: fieldtest-tail close — C22 --trace ledger notes reconciled
Tail audit (aaca18c..f591164) over #213, the milestone-fieldtest fixtures, and the B1 chart fix: #213's intersection semantics conflict with no ledger contract, the depth-2 trace resolution preserves C1 ordering read-side with the layout unchanged, and the new §0/§3/ glossary docs match the code vocabularies. One HIGH drift item resolved: the two C22 --trace amendment notes still described the #168 refusal surface and deferred per-member trace-writing to #224 — both now carry a delivered-2026-07-11 annotation (real-data --trace writes the depth-2 fan-out, chart resolves it; synthetic still refuses). Accepted LOW debt, recorded in-code: the disjoint-archive generalize refusal has no e2e fixture (unreachable on this host's archives), the pure helper is unit-tested. |
||
|
|
aaca18c6f6 |
audit: net-r cycle close — ledger reconciled, drift items resolved
Architect review over dd23ea3..HEAD (the #234/#152 cycle, 6 commits). What holds (architect-confirmed): CostSpec is a closed, deny-unknown- fields vocabulary with typed slots mirroring RiskRegime, field names conforming to the builders' ParamSpec names; cost-less docs hash byte-identically (C18); cost threads through the single MemberRunner seam so every campaign stage nets uniformly; costed families reproduce bit-identically incl. Carry; the #221-deleted leg is rebuilt optional (net = gross under the empty model); both cost_graph leaks replaced by the interned single source (#152). Resolved this close: [high] the C10 realization notes contradicted shipped reality — the two 'wired on the run path via --cost-*' claims carry superseded-annotations, the 0084 carried-debt note a discharged- annotation, and a new cycle-net-r realization documents the campaign cost block, the net-by-default decision, the manifest/reproduce round-trip, and the returned net_r_equity tap; [medium] two dangling persist_traces_r docstring references reworded to what exists; [medium] the one-knob-per-cost-node invariant behind the manifest round-trip is now unit-pinned (exactly one distinctly-named knob per shipped builder). Cycle spec and plan (git-ignored working files) discarded per convention. refs #234 |
||
|
|
7748b53a10 |
feat(cli,docs): the r_channel OHLC example + ledger amendment C26 (#231 tasks 6-7)
The acceptance proof: hl_channel — a causal Donchian channel (Delay(1) excludes the current bar, C2) consuming high/low/close roles, built from rostered vocabulary, shipped as the r_channel/r_channel_open example pair (builder + regenerator + serialize pins, the r_* pattern). Proven at three layers: a non-gated loaded-vs-carve equivalence over inline sources (non-zero-bias hardened per review), the unconditional synthetic multi-column refusal, and archive-gated CLI e2e — aura run on GER40 end-to-end plus a sweep whose members run and reproduce 2/2 bit-identically. Ledger: new C26 entry (the binding vocabulary — closed column set + price alias, name-driven default + campaign data.bindings override, canonical order = the C4 tie-break, Blockly-litmus argument, the #71 extension point for recorded non-price sources) and the C20/C24 scaffolding-clause annotations: the single-price data weld is retired, wrap_r's remaining R-scaffolding retirement stays #159. Verified: all proof tests green, full workspace suite green, clippy -D warnings clean; independent quality review approved. closes #231 |
||
|
|
fc9cf23b87 |
feat(cli,docs): ship the ganged open examples + document the gang construct (#61 tasks 7-8)
The two open examples now expose their author-intended single knobs — the closed builders always bound these pairs to one value by hand; the open forms falsely offered them as independent axes: - r_breakout_open: channel_hi.length + channel_lo.length -> channel_length (the Donchian channel is structurally ONE parameter) - r_meanrev_open: mean_window.length + var_window.length -> window; the band factor stays an independent axis Regenerated via the emitters (never hand-edited); the closed examples are byte-unchanged. The carve builders gang in the open branch only. Test migration: the two axis-namespace pins, five --real e2e invocations (single gang axis, the 10,20 diagonal for the campaign pair — the mismatched 20,40/10,20 grid was exactly the configuration space the gang retires), and the param_stability row counts (4 -> 3). The r-sma walkforward golden anchor is untouched (it never swept a ganged pair). Docs: authoring-guide gains the seventh op + the third param state (open/bound/ganged) + the gang wrap note; README op list + Axis concept; glossary gang entry; ledger C24 records the gang verb and the pre-ship Tier-2 dormancy (no format-version bump while no out-of-repo reader exists). Verified: full workspace suite 1104/0 (--real e2e included, local data present), clippy -D warnings clean, cargo doc clean; live acceptance: introspect --params prints channel_length:I64 alone / window:I64 + band.factor:F64. closes #61 |
||
|
|
35b996e3bf |
docs(ledger,research): note the metric-vocabulary drift guard (#190 close)
The #190 cycle-close audit found two now-stale claims that predate this cycle's guard test: the ledger's known-debt note listed the metric-roster triplication as tracked by #190 (the issue that just added the guard, closing on push), and metric_vocabulary()'s doc comment told a hand-editor to keep the list in sync by hand without mentioning that a red test now catches a desync. Reconcile both to the honest state: the triplication remains (still a hand-list) but drift from the shipped aura-analysis types is now caught by the cross-crate guard `aura-campaign/tests/metric_vocabulary_e2e.rs`; the single-source removal that would delete the hand-list is tracked under #147 (where the metric vocabulary's home is decided). refs #190, #147 |
||
|
|
f2526b1720 |
docs(cli,ledger): #168 cycle-close audit — reconcile the --trace surfaces (closes #168)
The #168 refusal left sibling --trace surfaces still lying and the design ledger still describing CLI --trace as a live persist path (surfaced by the cycle-close architect drift review). Reconcile them to record reality: - the chart NotFound hint no longer points at `aura run --trace` (itself refused); it names the live trace-writer (a campaign document's persist_taps presentation). - RunCmd/McCmd --trace help stop promising persistence (both flags already refuse). - README drops --trace from the live naming flags. - the ledger records the CLI --trace retirement: per-member --trace was never wired to the blueprint sweep (`let _ = persist`) and was silently dropped at #159/#220 — it never migrated as the old HISTORY note claimed; the single live TraceStore::write is the campaign persist_taps; restoration is deferred to #224. Workspace suite green (62 groups / 0 failed), clippy -D warnings clean. closes #168 |
||
|
|
68317ec95d |
chore(cli,ledger): #217 cycle-close audit — coverage backfill + stop-knob helper
Cycle-close audit for the stop-default cycle ( |
||
|
|
4acea45519 |
chore(cli,docs): #220 cycle-close audit — doc reconcile + dispatch dedup
Cycle-close audit for the verb-axis-generalization cycle ( |
||
|
|
07a73fb66e |
docs(cli,ledger): sweep #159 demo-retirement drift — stale comments + ledger notes
Cycle-close audit tidy for the #159 demo-retirement arc: behaviour-free reword of prose/comments/docs left pointing at symbols the arc deleted. Adversarially verified by the audit workflow; cargo build --workspace --all-targets green. - README: drop the removed `--harness` token; restrict the legacy built-in form claim to walkforward/mc/generalize (run/sweep no longer resolve one). - glossary: the built-in `--strategy` sweep surface is retired (#159), not a live inline path. - INDEX.md ledger: append [HISTORY] supersession markers (house style) to the dated realization notes advertising the retired `--harness` / built-in `--strategy` CLI forms (cost-flag #153, cycles 0065/0066/0067, name-res, #210 status); historical text preserved. - aura-engine test-fixture docs: drop dead cross-crate refs to the deleted aura-cli fns sample_harness / build_sample and the deleted `macd` composite. - cli_run.rs: reword the #159-cut-2 pin doc to the current clap generic-usage reality (no strategy_from / Strategy::RBreakout); r_sma_sweep_family -> blueprint_sweep_family. - verb_sugar.rs: fix the pre-existing `E[R]` unresolved-doc-link warning. Remaining tidy — the main.rs comment cluster plus its rustdoc link at :1546 (the second cargo-doc warning) — held for a follow-up issue. The dead cost-graph branch is tracked in #221. refs #159 |
||
|
|
b761b3c9c2 |
docs: close the verb-dissolution milestone — ledger status 4/4 + glossary sugar note
The verb-dissolution STATUS paragraph read "cycle 0110 dissolved the first verb … Remaining: generalize, walkforward, and mc's R-bootstrap path" — stale at HEAD, where all four verbs are dissolved. The per-cycle audits were each scoped to their own commit range, so the cumulative status line lagged; the milestone close fieldtest (#210, 2026-07-07) surfaced the drift. Refresh the paragraph to the completed state, and record the per-verb dissolved-form asymmetry as intended scope (ratify): for sweep the dissolved form is the blueprint file (`<bp.json> --real`) while `aura sweep --strategy r-sma --real` stays the inline built-in path — the built-in `--strategy` demo surface is #159's hard-wired-harness retirement target, not the dissolution's; for generalize/walkforward/mc the dissolved form is `--strategy r-sma --real`. Glossary: note in the sweep and walk-forward entries that the CLI verbs are now thin sugar over the campaign path. Milestone closed 2026-07-07 on a green end-to-end fieldtest (0 bugs). Forward findings filed: #216 (risk-axis discoverability), #217 (verb knob asymmetry), #218 (no-project store litter). refs #210 |
||
|
|
d96af7e1a2 |
audit: cycle close risk-regime axis — drift-clean after the C20 ledger fix (#210)
Architect drift review (c9d962f..HEAD). What holds: the nominee key is the 3-tuple (strategy, window, regime) and no argmax over regime_ordinal exists, so the ledger's kept-separate / compared-not-selected semantics is what the code does; the C18 manifest stamp is honest (the characterization pin flipped from asserting absence to requiring the exact resolved 3/2.0, a strengthening, and a real two-regime e2e catches per-cell mis-resolution); no dead code (cell.regime and regime_ordinal are both read after the runtime-binding slice), absent/empty risk keeps content-id parity, and CampaignGeneralization.regime_ordinal is serde-default so pre-feature records still parse. Resolution: - FIX (inline, this commit): the spec promised a C10 AND a C20 note; only C10 landed. C20's enumerated structural-axis list (strategy/instrument/broker/ window) was left silently incomplete — the risk regime is added as the fourth matrix axis, with a dated realization pointer to the C10 semantics. - carry (documented descope): no std::risk descriptor in CAMPAIGN_SECTIONS — risk is a top-level array, not a slot-bearing section; no invariant broken. - carry (filed #212): the persist re-run + campaign_cell_key omit the regime because CellRealization gained none; the architect verified this is a LOUD C1 drift-alarm refusal for a non-default regime + persist_taps, not silent wrong data (#212 corrected accordingly). - trivial: validate_campaign's regime-check comment corrected (it catches NaN, not all non-finite; +inf is unreachable via JSON). Regression gate: full workspace suite green, clippy clean (no dedicated regression script; the suite + lint are the gate). Spec and plan removed (git rm) at cycle close per the project convention. No baseline moved. refs #210 |
||
|
|
50d3db7028 |
feat(cli): finalize the risk-regime axis — ledger note + clippy-clean regime check (#210 T5)
The last slice of the risk-regime structural axis. The sugar parity (`translate_sweep` emitting `risk: vec![]`, absent-serializing) and the real-data two-regime e2e landed in the earlier slices (the loop's self-correction and its e2e phase), so this closes the remaining pieces: - design-ledger note: the risk regime realizes the StopRule structural axis at the campaign-document level — kept-separate keying, compared-not-selected (the R-unit argument), the C18 stamp, absent-parity, and the deferred trace gap (#212). - clippy: `validate_campaign`'s regime check reads `k <= 0.0 || k.is_nan()` instead of `!(k > 0.0)` (neg_cmp_op_on_partial_ord), behaviour-identical. Full workspace suite green; clippy clean. refs #210 |
||
|
|
2c729965db |
audit: cycle 0110 tidy — verb-dissolution cycle 1 closed drift-clean
Architect review (scope e7c7bde..b7aaa0b) found three items; resolutions: - fix: docs/authoring-guide.md + glossary aligned with the shipped vocabulary (std::sweep selection group optional/all-or-nothing, selection-free = terminal-only, worked example verified against the live binary). - fix: the #203 wrapped/raw axis-name convention is now single-sourced in campaign_run.rs (wrapped_to_raw_axis + raw_matches_wrapped, a cross-documented inverse pair; dispatch_sweep and both bind sites call through it; inverse-property unit test). Ratify note: this unifies two previously different algorithms onto the documented first-segment semantics — the old loose ends_with suffix-match also accepted sub-segment shorthands (e.g. axis "length" against "sma_signal.fast.length") that no stored document or test used; such shorthands now refuse loudly (unbound/unknown axis) instead of matching, the refuse-don't-guess reading of #203. - carry: run_blueprint_sweep/blueprint_sweep_family remain generically real-capable though the dispatch no longer routes real data to them; the residual capability is shared DataSource machinery, its removal falls out with the built-in/synthetic branch retirement (#159), and the synthetic-only status is documented at the fn. What holds: C24 canonical form (flatten group leaves every stored content id unchanged, golden pin untouched), C18 lineage (topology_hash IS content_id_of, single store write resolves the strategy ref; selection-free arm still persists the full family), C25 closed- vocabulary discipline (all-or-nothing group, Blockly-clean), C3 (ms/ns conversion through the ingest seam's own named fn). Ledger: #109 open-thread status lifted to cycles 0107-0110 reality (executor shipped, amendment package landed, verb dissolution running as milestone #210 with sweep dissolved). Regression gates: cargo test --workspace 1056/0; clippy -D warnings clean; cargo doc clean. Cycle spec+plan removed at close per convention. refs #210 |
||
|
|
179c2f8bf0 |
audit: cycle 0109 tidy (drift resolved by ledger/glossary lift + tap-channel cross-pin)
Architect verdict: drift_found — the code holds (C1 honored not assumed: the nominee re-run's metrics-equality hard refusal; C22/C14 clean: existing TraceStore + unchanged viewer, serde-default widening round-trips, name composition single-sourced in derive_trace_name). Resolved here: - C18: the 0107 paragraph's 'persist_taps is deferred' points forward; new cycle-0109 realization paragraph records the closed tap vocabulary + UnknownTap tier, the nominee-only non-reduce re-run with the C1 metrics guard, the campaign trace family layout, the trace_name claim contract, the loud-skip lines, and the noted chart-over-family-root debt. - Glossary: tap entry names the closed vocabulary + escalation rule; campaign document's presentation clause references it; campaign run gains the trace_name pointer. - Debt fixed inline (architect med): tap_channel gains the emit_vocabulary-twin debug_assert cross-pin so a fifth vocabulary tap fails loudly instead of silently skipping. The consumed 0108 fieldtest spec is removed with the cycle's spec+plan (all its dispositions shipped: F6 #205, F8 #207, F11 #206, F7/F9/F10 doc-tightens). Regression: cargo test --workspace 1041/0; clippy -D warnings clean; cargo doc 0 warnings. refs #201 |
||
|
|
ae2fac3212 |
audit: cycle 0108 tidy (drift resolved by ledger/glossary lift)
Architect verdict: drift_found — the expected pre-audit doc lag; the code holds (C1: doc-seeded bootstrap + BTreeMap-ordered generalize; C14/C23 sparse widening pinned by the pre-0108-line parse test; terminal-annotator dataflow confirmed — nothing flows out, no new emit kind, no content-id movement). All items resolved here: - C18: 0107's 'refuse loudly at preflight' points forward; new cycle-0108 realization paragraph records the v2 shape, the dual-input stage bootstrap, campaign-scope generalize, the tier boundary (test-pinned on both sides), the record widenings, and the stringly wf-detection debt. - Glossary: campaign document -> v2 shape; bootstrap and Monte-Carlo entries disambiguate the three senses (construction vs statistical r_bootstrap vs seed axis — the std::monte_carlo stage IS the trade-sequence bootstrap, named for r_bootstrap's arguments); generalize gains the campaign-scope realization. Regression: cargo test --workspace 1025/0; clippy -D warnings clean; cargo doc 0 warnings. Spec + plan removed at close per convention. closes #200 |
||
|
|
428f83c542 |
audit: cycle 0107 tidy (drift resolved by ledger/glossary lift)
Architect verdict: drift_found — the code holds its contracts (C1 determinism incl. lowest-index fault attribution and doc-seeded deflation; C16 seam: aura-campaign excludes ingest/std/composites, MemberRunner isolates the condemned CLI scaffolding; the walk_forward lockstep set moved together), the docs lagged the tree. All six drift items resolved in this commit: - C18: 'no executor exists' retired (0106 text now points forward); new cycle-0107 realization records the executor, the aura-campaign home, ListSpace, the campaign_runs.jsonl sibling store, zero-survivor exit-0 semantics, emit/persist_taps split, the #196 on-ramp, and the machinery-true std::walk_forward correction. - C16: aura-campaign added to the non-node crate enumeration (cycle-0107 realization; explicitly not C21's World). - Glossary: campaign document entry corrected (run verb, execution prose); new 'campaign run' entry; blueprint entry gains the on-ramp verbs. Carry-on debt (self-noted in code, tracked): metric-roster triplication #190, deflation-constant duplication #199; cross-cell fault orphans + nested-parallelism oversubscription noted in the tasks-6-7 commit body. Follow-ups filed on the milestone: #200 (mc/generalize stage execution), #201 (persist_taps wiring). Regression: cargo test --workspace 987/0; clippy -D warnings clean; cargo doc 0 warnings. Spec + plan removed at close per convention (durable rationale lives in the ledger; the canonical record is the git history). closes #198 |
||
|
|
e73aadae1e |
docs(ledger): #188 amendment package — C25 role model, C20/C22 refinements, invariant-10 clarification
C25 (new): the nine authoring roles cut by artifact + surface + iteration cost, the recognizability test, the 6a/6b split on invariant 12's tier boundary with the id machinery as interface, the text-first/headless-first invariant (visual surfaces = stateless projections, viewers over editors), and the Blockly litmus test as every vocabulary's acceptance criterion. C20: the 'plain Rust loops, not a config schema' clause and the mini-DSL forbid are scoped — they forbid an open logic-bearing language, not the closed-vocabulary campaign document that now carries experiment intent under the P1 construct tier; generators may stay Rust, what they yield is data. C22: stateless-projection refinement generalized to all artifact classes; the shipped face recorded as the web-from-disk front. Glossary playground entry aligned (the egui-native wording was stale against the 2026-06 revision). CLAUDE.md invariant 10: clarified that closed-vocabulary data artifacts (op-scripts, blueprints, process/campaign documents) are not the forbidden DSL — RustAst failed as an open logic-bearing language; new logic escalates to a Rust block, never a freetext hole. All content ratified on #188 (body + addenda + resolution comments); this commit is production of the durable record, no new design. closes #192 |
||
|
|
ebe85683c9 |
audit: cycle 0106 tidy — ledger/glossary lift, unwired-hint fix, spec/plan retired
Architect drift review (holds: C14 headless authoring, C16/C17 no-DSL with aura-research a true leaf, content-id move behaviour-preserving per the untouched id goldens). Resolution per item: - fix (docs): C18 gains the cycle-0106 realization note (processes/ + campaigns/ stores, document canonical form, the content-id primitive's library home, the referential tier, no-executor status); the #109 analysis-meta-level open thread records the artifact half shipped v1 and what stays open (executor question, verb dissolution 'once it carries', the remaining #188 amendment package). Glossary: new campaign document + process document entries; content id generalized to all three artifact classes; experiment marked superseded by the campaign document (#188 re-cut of the builder-API thread). - fix (code): the --unwired guide advertised an identity_id process ref that validate_campaign refuses — the process.ref open-slot hint now says content-id-only (strategy refs keep both); lib + seam pins updated. - filed forward: #190 (metric-vocabulary single-sourcing, the 0105 roster drift class), #191 (identity-ref store scan is O(store), performance only). - carry-on: regression gates green by hand — cargo test --workspace 916/0, clippy -D warnings clean, cargo doc --no-deps 0 warnings; no baseline to ratify (project has no metric baseline scripts). Cycle 0106 spec and plan retired per convention (git rm); durable record is the ledger notes above plus #188/#189. refs #189 |
||
|
|
81ac6fd654 |
docs(ledger): declare the canonical project shape — templates canon, fixture frozen twin
Resolves the #181 design pass (option c: ledger declaration, no lockstep mechanism). The aura-new templates (scaffold.rs) are the canonical authoring shape and evolve with the engine; the cycle-0102 demo-project fixture is an intentionally frozen known-good twin for the load-boundary tests. Deliberately NOT lockstep-guarded: no consumer requires the copies to match (skeptic-verified — nothing treats the fixture as what aura new emits), each is e2e-guarded on its fitness for purpose (build/load/ charter/deterministic run; blueprint wiring is pinned in neither, stated honestly after an adversarial skeptic pass refuted the stronger claim), and an equality guard would convert deliberate template improvements into forced churn of the frozen fixture — the same cross-purpose coupling that rules out regenerating the fixture from the scaffolder. closes #181, refs #180 |
||
|
|
bd32c4fcb3 |
audit: cycle 0105 tidy (drift-clean after two doc-mirror alignments)
Architect drift review (range 7b429f9..57f401f): drift_found (low/medium only), resolved inline as close-fixes: - crates/aura-std/src/vocabulary.rs — the roster-site doc now names BOTH count pins a node addition trips (the in-crate shape test and aura-cli's cross-boundary --vocabulary count e2e); the singular phrasing understated the cross-crate lockstep the extra e2e introduced. - docs/design/INDEX.md — the C24 enforcement-shift passage gains the 0105 delivery note: resolver-vs-list drift closed by construction via the roster macro; the un-rostered-node residual stays fail-safe. Noted, no action: spec/plan predicted 884 (no new test) but delivery added one e2e (885) — consciously superseded, disclosed in the iter commit body; the artifacts are ephemeral and removed below. What holds (architect): byte-preserving refactor confirmed against the diff (22 keys/order exact, signatures and module doc untouched, every consumer unchanged); invariant 9 / C24 preserved (compile-time expansion, no registry); the new e2e count pin is genuinely roster-tied. Regression gates (all green): cargo build clean; cargo test --workspace 885 passed / 0 failed (884 baseline + 1 new e2e); clippy --all-targets -D warnings clean; cargo doc --no-deps 0 warnings. Ephemeral cycle artifacts removed per project convention (git rm): docs/specs/0105-std-vocabulary-roster-macro.md, docs/plans/0105-std-vocabulary-roster-macro.md. refs #180 |
||
|
|
7b429f931a |
audit: cycle 0104 tidy (drift-clean after three doc-mirror alignments)
Architect drift review (range d5c4361..45fb06d): drift_found, three items, all doc-mirror — resolved inline as close-fixes: - docs/design/INDEX.md — the two #171 deferral passages (C18 #158 realization + C24 status) now record the shipped identity id (additive sibling; content id keeps the store/reproduce roles; introspection-only until a dedup consumer exists). Whole-harness / structural-axis content-addressing stays deferred. - README.md — introspect table gains the --identity-id row incl. the combinable id-flag behaviour. - docs/glossary.md — three record-reality entries: content id, identity id (Avoid: identity hash, topology-identity hash), topology hash; the README row aligned to the canonical term. What holds (architect): additive-sibling discipline intact (no store code touched, every content-id/topology_hash pin green); C23 honoured precisely (each strip arm has a protecting property test; factoring byte-preserving via the canonical golden); the two extra engine tests are genuinely distinct coverage (recursion arm, role/output arms), no redundancy. Regression gates (all green): cargo build clean; cargo test --workspace 884 passed / 0 failed (873 baseline + 11 new); clippy --all-targets -D warnings clean; cargo doc --no-deps 0 warnings. Ephemeral cycle artifacts removed per project convention (git rm): docs/specs/0104-topology-identity-hash.md, docs/plans/0104-topology-identity-hash.md. refs #180 |
||
|
|
d5c4361a97 |
audit: cycle 0103 tidy (drift-clean after three doc-mirror alignments)
Architect review of b672a37..HEAD. What holds: emitted templates match the settled contracts (Aura.toml paths-only per C17, cdylib + empty [workspace] per C16, ::-namespaced ids per the charter, the C14 exit partition in dispatch_new); the load-bypass guard is narrow and sound (only the new-project verb exempted, the load arm byte-unchanged for every other verb); e2e coverage is real (scaffold -> build -> run twice byte-identical, namespace stamped, introspection, four refusals, the unbuilt-tree bypass, plus the additive namespace-override test). Regression: cargo build --workspace rc=0; cargo test --workspace 873 passed / 0 failed (project_new 6/6); clippy --workspace --all-targets -D warnings rc=0; cargo doc --workspace --no-deps 0 warnings. No baselines exist to move, so nothing to ratify. Drift resolved in this commit: three doc mirrors still framing the scaffolder as future — project-layout.md's 'the future aura new scaffolder will emit this line; until then, add it by hand', the C24 status paragraph's 'what remains open is the aura new scaffolder (the milestone's next cycle)', and the #109 open-thread bullet's 'the aura new scaffolder and the experiment-builder API remain open' — all rewritten to the landed reading (only the experiment-builder API stays open in that layer). Carried debt, filed forward: the scaffold templates and the demo-project fixture encode one project shape twice with no lockstep guard and deliberate cosmetic divergences (#181, idea — needs a design pass, not a mechanical edit). Process note: one mid-cycle plan-fix commit (derive(Debug) on a plan-prescribed struct whose own test code required it) — the implement loop's spec gate correctly blocked the necessary deviation; resolution followed the fix-plan/commit-subset/re-run path. Ephemeral cycle artifacts removed per convention: spec 0103, plan 0103. refs #180 |
||
|
|
b672a37903 |
audit: cycle 0102 tidy (drift-clean after two ledger-mirror alignments)
Architect review of d7c935d..HEAD. What holds: C13/C16 separation verified by diff (descriptor in aura-core::project, loader entirely in aura-cli::project, aura-engine gains only the additive provenance field); the C-tier-before-Rust-tier discipline is enforced in load() (magic -> version -> stamps, fn pointers touched only after Ok); C17/C24/invariant-9 hold (paths-only Aura.toml, injected merged resolver, charter at the one seam); outside-a-project byte-identity confirmed by the full green suite incl. every golden-bearing test. Regression: cargo build --workspace rc=0; cargo test --workspace 862 passed / 0 failed (cli_run 133, project_load 7 e2e); clippy --workspace --all-targets -D warnings rc=0; cargo doc --workspace --no-deps 0 warnings. No baselines exist to move, so nothing to ratify. Drift resolved in this commit: two stale project-as-crate ledger mirrors — the C24 status paragraph still calling the layer sequencing-coupled/unbuilt, and the #109 open-thread bullet naming it an unbuilt half — rewritten to record the landed load boundary (the aura new scaffolder and the experiment-builder API stay open). Carried holds (plan-prescribed bytes, cosmetic): the unreachable rsplit fallback in node_name, the unreachable! build closure in one aura-core test. Ephemeral cycle artifacts removed per convention: spec 0102, plan 0102. refs #180 |
||
|
|
4928e289f7 |
feat(project): the project-as-crate load boundary (cycle 0102)
A research project is now a loadable external cdylib crate. Inside a directory whose ancestry holds an Aura.toml, aura discovers the project root cargo-style, locates the compiled dylib via cargo metadata (debug default, --release opt-in), loads it load-and-hold, and refuses mismatches before trusting anything: the AURA_PROJECT descriptor (aura-core::project, #[repr(C)]) carries a C-ABI stamp prefix (rustc + aura-core version, baked per consuming build by the new aura-core build.rs) validated before any Rust-ABI field is read. The vocabulary charter gates the merged resolution: project type ids are ::-namespaced (std stays bare), duplicates refuse, and the enumerable type-id list must agree with the resolver, so introspection can never silently omit a project type. All blueprint verbs resolve through the merged project + std vocabulary via a per-invocation Env threaded through the dispatch chains; registry, trace-store, and data paths anchor at the project runs root (Aura.toml [paths], paths-only by design — instrument geometry stays the recorded sidecar, C15). RunManifest gains the Tier-1 project provenance field (namespace + dylib sha256 + best-effort commit), stamped beside topology_hash on the blueprint-run paths; pre-0102 registry lines load unchanged. Default node names strip the namespace, so :: never reaches the param-path address space. Proven by the demo-project fixture (built by the e2e via cargo, path-dep on this workspace): run twice bit-identical, provenance recorded, introspection lists demo::* beside std, registry anchors at the discovered root from a subdirectory; the badcharter fixture proves the charter refusal through the real libloading path; a never-built project refuses with a cargo-build hint. Outside a project every path collapses to the previous literals — goldens and manifest pins byte-identical. Verification: cargo build --workspace clean; cargo test --workspace 862 passed / 0 failed (incl. 7 project_load e2e); clippy -D warnings clean (one precedent-matching allow(too_many_arguments) on run_oos_blueprint, whose arity the Env threading raised to 8); doc build unchanged. Docs/ledger aligned: Aura.toml field lists are paths-only in project-layout.md, glossary, C16/C17; new C13 realization note records the per-invocation-reload reading and the load-and-hold one-shot scope boundary. New deps, per-case review (aura-cli leaf binary only, never the frozen artifact): libloading, toml. refs #180 |