From ead45915efcaf6dca1149d2b91e4a96734e27c1e Mon Sep 17 00:00:00 2001 From: John Morrissey <544926+tachyon-beep@users.noreply.github.com> Date: Sun, 9 Aug 2026 09:46:47 +1000 Subject: [PATCH 1/3] =?UTF-8?q?product:=20session=209=20checkpoint=20?= =?UTF-8?q?=E2=80=94=20static-content=20hardening=20merged=20(PDR-0018);?= =?UTF-8?q?=20design-system=20recovery=20gated=20on=20owner=20(PDR-0019);?= =?UTF-8?q?=20pacing=20warning=20fired?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Fable 5 --- docs/product/current-state.md | 80 ++++++++++--------- ...018-static-content-review-and-hardening.md | 55 +++++++++++++ .../0019-design-system-recovery-path.md | 48 +++++++++++ docs/product/metrics.md | 4 +- 4 files changed, 149 insertions(+), 38 deletions(-) create mode 100644 docs/product/decisions/0018-static-content-review-and-hardening.md create mode 100644 docs/product/decisions/0019-design-system-recovery-path.md diff --git a/docs/product/current-state.md b/docs/product/current-state.md index f3bdd03..180c4ae 100644 --- a/docs/product/current-state.md +++ b/docs/product/current-state.md @@ -1,47 +1,55 @@ -# Current State — Simic Checkpoint: 2026-08-09 (session 8) +# Current State — Simic Checkpoint: 2026-08-09 (session 9) ## The bet right now -Design hardening — the hld-review burn-down (38 → 0 by 2026-08-31, pacing -signal) — plus the ADR-0002 information-management regime -(simic-357c92664c), now three sessions unstarted against PDR-0010's -alongside-not-displacing intent. Public face live and current: -https://simic.foundryside.dev with the wiki at /design/ now carrying -staged ADRs, generated reference registries, and the linkified INV/ADR -citation spine (ADR-0007, PDR-0017). +Design hardening — the hld-review burn-down (38 → 0 by 2026-08-31, +pacing signal) — plus the ADR-0002 information-management regime +(simic-357c92664c), now four sessions unstarted. **The pacing warning has +fired**: two consecutive flat sessions (7 and 9 did wiki/site work, 8 was +checkpoint-only); ~1.7 closures per working day needed to make the date. +Public face live, hardened and now deploy-gated: https://simic.foundryside.dev +with the wiki at /design/ (PDR-0018, PR #2 merged 6df7e7a). ## In flight - Nothing claimed. Six wave:1 items remain; simic-d6ea02f9a9 (containment - owner) stays the natural next — ADR-0004/0005 both route seams to it. - Critical path: simic-0bf2c40dec → simic-38a07fad39. -- Commissioning: neither pack has landed — axiom-contract-engineering and - yzmir-training-state are both absent from the session skill roster - (verified 2026-08-09). The training-state applied prompt - (commissioning/yzmir-training-state-engineering-updated-prompt.md) - still awaits owner relay upstream. -- simic-357c92664c (implement ADR-0002) ready, unstarted. John is the - sole signing actor, so the plainweave seeding needs owner presence at - the gate regardless of who stages it. + owner) stays the natural next. Critical path: simic-0bf2c40dec → + simic-38a07fad39. +- simic-42e575b93c (NEW, blocked-on-owner): recover or reconstruct the 33 + missing simic-design design-system files — fork decided by whether the + claude.ai project survives (PDR-0019, proposed). +- Commissioning: both packs still absent from the session roster; the + training-state applied prompt still awaits owner relay upstream + (carried since session 6). +- simic-357c92664c (implement ADR-0002) ready, unstarted; plainweave + seeding needs owner presence at the gate. ## Open questions / blocked-on-owner -- Relay the training-state updated prompt to its upstream session - (owner-reachable only; carried since session 6). -- Nothing new escalated: session 8 was RESUME → ORIENT → CHECKPOINT - only; session 7's pushes were owner-directed (ADR-0007 deciders line, - PDR-0017). +- PDR-0019: does the SimicDesignSystem_5a908e project survive anywhere in + your claude.ai/design UI? (Decides re-export vs reconstruction.) +- Watch the first post-merge Pages deploy: it carries both the new deploy + gates (PDR-0018) AND the dependabot pymdown-extensions 10.21→11.0.1 + bump (PR #1, merged after PR #2, untested together). Gate failures are + loud, not silent; local wiki builds will fail the version-drift gate + until `pip install -U -r tools/wiki/requirements.txt`. +- Pacing warning fired (metrics.md): next DECIDE resumes wave:1 closures + or re-plans the 2026-08-31 date by PDR — silent drift is the one + disallowed outcome. +- Tooling, for upstream relay: `filigree issue-list --status open` exited + 144 and ignored the status filter (CLI path; MCP unaffected). Wardline's + taint gate is inert on this repo (0 declared trust boundaries — green + means "nothing to check" until boundaries are annotated). ## Last checkpoint did -- PDR-0017: reconciled the uncheckpointed 2026-08-09 session — ADR-0007 - wiki-projection regime, Structurizr model of the 14 domains, - simic-dd5a578332 closed verified. Process note recorded: ADR-tier - sessions should close with a checkpoint. -- Metrics: burn-down read flat at 38 (session 7 effort went to the - derivation programme, not the burn-down); one flat session, a second - consecutive one re-arms the pacing warning; 22 days to 2026-08-31. -- No bet changed horizon; roadmap untouched; tracker already true. +- PDR-0018 (accepted): recorded the owner-directed static-content review → + implementation → merge (5 commits, 2 review gates, 2 Criticals caught + pre-merge) and the durable deploy/build gates; public copy honesty fix. +- PDR-0019 (proposed): design-system recovery fork, owner-gated; tracker + item simic-42e575b93c created. +- Metrics: burn-down read flat at 38 — second consecutive flat session, + pacing warning FIRED. +- No bet changed horizon; roadmap untouched. ## Next session, start here -DECIDE was not run this session. Session 8's ORIENT proposal stands: -claim simic-d6ea02f9a9 (containment accountability) to resume wave:1 -closures — the burn-down needs ~1.7 closures per working day to make the -pacing date — and stage the simic-357c92664c plainweave seeding for -owner sign-off in the same session if capacity allows. +Answer the pacing warning first: claim simic-d6ea02f9a9 and resume wave:1 +closures, or re-plan the burn-down date by PDR. Check the post-merge +deploy status before any wiki/site work. PDR-0019's owner question can be +answered in passing and unblocks simic-42e575b93c. diff --git a/docs/product/decisions/0018-static-content-review-and-hardening.md b/docs/product/decisions/0018-static-content-review-and-hardening.md new file mode 100644 index 0000000..c19baf8 --- /dev/null +++ b/docs/product/decisions/0018-static-content-review-and-hardening.md @@ -0,0 +1,55 @@ +# PDR-0018 — Static-content review executed, implemented and merged; deploy now gated + +Date: 2026-08-09 Status: accepted Author: Claude (product-owner session) +Owner sign-off: not required — every outward-facing step was owner-directed +in-session ("review the static content including the wiki" → "implement +those changes" → "create a PR and merge it back to main remotely"). +Related: ADR-0007, PDR-0014, PDR-0017, PR #2 (merge 6df7e7a), commits +6435f07, 7a92b61, b847980, 02564bb, d60e743 + +## Context + +The owner requested a full design review of the static content (marketing +site + design-docs wiki), then implementation of the findings, then PR and +merge. Two independent review streams (site, wiki) produced 40+ findings +(1 Critical, 15 Major); implementation ran under a per-stream adversarial +review gate with browser verification and fix loops. The wiki gate caught +two shipped-broken Criticals the implementer's non-browser checks missed +(all 20 compiled diagrams 404ing; math dead after instant navigation) — +both fixed and browser-verified before merge. + +## The call + +Ship the full batch to main as one owner-directed merge, and make the +quality regime durable rather than one-shot: the deploy is now gated by +`html-validate@11` plus `tools/ci/linkcheck.py` (every internal link and +fragment of the assembled artifact), and the wiki build by +`tools/wiki/check_links.py` (every src/href/srcset in the built HTML — the +raw-HTML class `--strict` cannot see) and a diagram-palette check. Two +public-copy decisions ride along: the landing page no longer claims the +design is "complete" (now "locked … under active design review", dated), +and both surfaces are zero-third-party at runtime (wiki MathJax switched +to its SVG build so `material/privacy` vendors everything). + +Accepted deferrals, recorded not dropped: border non-text contrast (needs +a palette decision); the generated design-system manifest divergence (re- +sync checklist in the skill readme); three minor linkcheck residues (all +fail-closed, listed in the review reports). + +## Rationale + +The site's strongest asset is that a hostile reader cannot fault its +honesty; "complete" was the one sentence that undercut it. The gates exist +because both Criticals were exactly the class local verification missed — +converting silent breakage into blocked deploys is the same fail-loud +discipline the HLD demands of the training system (ADR-0006 lineage). +Gate failure modes are confined to blocking a deploy, never shipping +broken content. + +## Reversal trigger + +If the deploy gates falsely block two clean deploys (failures traced to +gate strictness rather than genuine breakage), re-evaluate gate scope in a +superseding PDR. First live signal to watch: the first post-merge Pages +deploy — which also carries the dependabot pymdown-extensions 10.21→11.0.1 +bump (PR #1, merged after PR #2, untested against the new staging code). diff --git a/docs/product/decisions/0019-design-system-recovery-path.md b/docs/product/decisions/0019-design-system-recovery-path.md new file mode 100644 index 0000000..0958549 --- /dev/null +++ b/docs/product/decisions/0019-design-system-recovery-path.md @@ -0,0 +1,48 @@ +# PDR-0019 — Design-system recovery path: re-export if it survives, else reconstruct — never fabricate + +Date: 2026-08-09 Status: proposed Author: Claude (product-owner session) +Owner sign-off: REQUIRED — the deciding fact (does the SimicDesignSystem +project survive in the owner's claude.ai/design UI?) is owner-visible only. +Related: simic-42e575b93c, commit 6e74997, PDR-0018 (the divergence table), +memory: simic-design-system-partial-export + +## Context + +`.claude/skills/simic-design/` turned out to be the compiled-export residue +of a claude.ai Design System project (`SimicDesignSystem_5a908e`): commit +6e74997 committed 8 of ~41 files; the 33 manifest-referenced source files +(tokens, components, guidelines, UI kits) were never committed and no +matching project exists in the owner's writable claude.ai project list +(verified via DesignSync 2026-08-09). The skill is `user-invocable` and its +own instructions send agents into the missing tree. + +## The call (proposed) + +1. Owner checks whether the project survives anywhere in claude.ai/design. +2. If yes: full re-export / DesignSync pull, then re-apply the site's token + corrections per the readme's divergence table. +3. If no: reconstruct from `_ds_bundle.js` (compiled components with source + hashes) + `_ds_manifest.json` (44 tokens, card metadata) + + `site/style.css` (token ground truth), clearly marked as reconstruction. +4. Standing constraints either way: never fabricate the missing files as if + original; never hand-trim the generated descriptors (readme Index, + github.md screen map) to match disk — they are the record of the gap. + +Interim mitigations already merged (PDR-0018): `styles.css` flattened from +the site tokens with a provenance comment; readme warning block naming the +33 missing files and the re-sync checklist. + +## Rationale + +The compiled bundle makes the export look self-sufficient until something +follows a source path; leaving the skill half-broken compounds with every +session that invokes it. Reconstruction is ~80% mechanical but writes +history it cannot verify (source hashes will not match), so re-export is +strictly better if available — hence the owner-gated fork rather than an +autonomous choice. + +## Reversal trigger + +If reconstruction is chosen and a later re-sync surfaces the original +project, the reconstruction is discarded wholesale in favour of the export +(the sourceHashes in the bundle adjudicate which files are original). diff --git a/docs/product/metrics.md b/docs/product/metrics.md index ed22b78..c9ad0bb 100644 --- a/docs/product/metrics.md +++ b/docs/product/metrics.md @@ -1,4 +1,4 @@ -# Metrics — Simic Last read: 2026-08-09 (session 8 checkpoint) +# Metrics — Simic Last read: 2026-08-09 (session 9 checkpoint) > Dates here are pacing signals for the owner's own use — this is a spare-time > moonshot (owner-stated 2026-08-08, PDR-0005). A fired date is a re-plan signal @@ -13,7 +13,7 @@ ## Input metrics (the levers that move the north-star) | Metric | Target | Current | Read on | |--------|--------|---------|---------| -| Design-debt burn-down: open `hld-review` tracker items | 0 by 2026-08-31 | 38 open / 12 closed — flat across session 7 (2026-08-09), whose effort went to the ADR-0007 wiki-projection work (outside the burn-down; simic-dd5a578332 closed but not hld-review-labelled). One flat session; second consecutive flat session re-arms the pacing warning. 22 days to the pacing date | 2026-08-09 (session 8 checkpoint) | +| Design-debt burn-down: open `hld-review` tracker items | 0 by 2026-08-31 | 38 open / 12 closed — flat across session 9 (2026-08-09), an owner-directed static-content quality session (PDR-0018, outside the burn-down). **Second consecutive flat session: the pacing warning session 8 armed now FIRES.** 22 days to the pacing date needs ~1.7 closures per working day; next DECIDE must either resume wave:1 closures or re-plan the date by PDR (PDR-0005: a fired signal must fire, never drift silently) | 2026-08-09 (session 9 checkpoint) | | Phase progression: HLD §25 phases with acceptance tests (§21) passing | Phase A complete by 2026-09-30 (provisional — revise by PDR if the gate reshapes §9 materially) | 0 of 11 (pre-code) | 2026-08-08 | ## Guardrails (must NOT degrade) From cef43a76f833beeefc7467c6611544260b996554 Mon Sep 17 00:00:00 2001 From: John Morrissey <544926+tachyon-beep@users.noreply.github.com> Date: Sun, 9 Aug 2026 10:09:04 +1000 Subject: [PATCH 2/3] =?UTF-8?q?design:=20adopt=20Namespec=202.0=20(ADR-000?= =?UTF-8?q?8)=20=E2=80=94=20full=20rename=20cascade?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sarpadia→Urborg, Tamiyo→Ugin, Narset→Aurelia, Tezzeret→Urabrask, Urabrask→Jin-Gitaxias, Augustin→Isperia, Kasmina→Wrenn, Oona→Tamiyo; mechanics, contracts and all 45 invariants unchanged. Constitution rewritten with the synthesis-core/governance-cage framing and the new canonical sentence; domain chapters renamed collision-safe; Urabrask dual compilation mode made explicit; appendices, root docs, product workspace (PDR-0020) cascaded; ADR-0001..0007 carry a namespec banner; Esper-era references in ops/migration.md kept era-correct names. model.dsl and mermaid sources renamed and re-rendered (dimension gate green); stage.py drift gate learns the underscore/hyphen convention; wiki builds strict (54 pages, 3888 links resolve) and the site linkcheck + html-validate gates pass. Open tracker issues retitled. Reconciled atop the concurrent session-9 checkpoint (ead4591): PDR renumbered 0018→0020, resume brief carries a dated namespec note. Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_012qVBdHQtjsNsUbfMHSdyeF --- .claude/skills/simic-design/_ds_bundle.js | 2 +- .claude/skills/simic-design/readme.md | 6 +- AGENTS.md | 63 +++--- ARCHITECTURE.md | 100 +++++---- README.md | 26 ++- docs/adr/0001-hld-decomposition-structure.md | 4 + .../adr/0002-information-management-regime.md | 4 + .../adr/0003-project-name-simic-clean-seam.md | 4 + docs/adr/0004-lexicographic-admission.md | 4 + ...05-retention-hysteresis-schmitt-trigger.md | 4 + ...-ban-silent-defaulting-telemetry-access.md | 4 + docs/adr/0007-wiki-projection-regime.md | 4 + docs/adr/0008-namespec-2.0.md | 150 +++++++++++++ docs/adr/README.md | 2 +- docs/design/00-INDEX.md | 8 +- docs/design/01-claim.md | 84 ++++---- docs/design/02-constitution.md | 200 ++++++++++-------- docs/design/03-principles.md | 100 ++++----- docs/design/04-architecture.md | 196 ++++++++--------- docs/design/05-leyline-contracts.md | 50 ++--- docs/design/06-growth-model.md | 72 +++---- docs/design/07-counterfactual-engine.md | 32 +-- docs/design/TEMPLATE-lld.md | 2 +- docs/design/appendices/caveman-mode.md | 16 +- docs/design/appendices/glossary.md | 16 +- docs/design/appendices/good-bad-sentences.md | 42 ++-- docs/design/appendices/newsroom.md | 52 ++--- docs/design/appendices/scaffold-pattern.md | 10 +- docs/design/assets/model.dsl | 170 +++++++-------- docs/design/domains/README.md | 10 +- docs/design/domains/{narset.md => aurelia.md} | 24 +-- docs/design/domains/elesh.md | 2 +- docs/design/domains/emrakul.md | 14 +- .../domains/{augustin.md => isperia.md} | 24 +-- docs/design/domains/jin-gitaxias.md | 39 ++++ docs/design/domains/leyline.md | 4 +- docs/design/domains/momir.md | 8 +- docs/design/domains/nissa.md | 6 +- docs/design/domains/oona.md | 40 ---- docs/design/domains/tamiyo.md | 51 +++-- docs/design/domains/tezzeret.md | 27 --- docs/design/domains/ugin.md | 43 ++++ docs/design/domains/urabrask.md | 58 ++--- .../design/domains/{sarpadia.md => urborg.md} | 44 ++-- docs/design/domains/{kasmina.md => wrenn.md} | 12 +- docs/design/ops/migration.md | 46 ++-- docs/design/ops/observability.md | 40 ++-- docs/design/ops/repo-structure.md | 60 +++--- docs/design/programme/curriculum.md | 54 ++--- docs/design/programme/evaluation.md | 68 +++--- docs/design/programme/learning.md | 42 ++-- docs/design/programme/phases.md | 50 ++--- .../programme/risks-and-open-decisions.md | 51 ++--- docs/product/commissioning/README.md | 2 +- docs/product/current-state.md | 10 + .../decisions/0020-namespec-2.0-adoption.md | 55 +++++ docs/product/metrics.md | 2 +- docs/product/roadmap.md | 10 +- docs/product/vision.md | 2 +- site/404.html | 2 +- site/architecture.html | 138 ++++++------ site/assets/diagrams/assurance-loop-dark.svg | 2 +- site/assets/diagrams/assurance-loop-light.svg | 2 +- site/assets/diagrams/core-loop-dark.svg | 2 +- site/assets/diagrams/core-loop-light.svg | 2 +- .../assets/diagrams/observation-loop-dark.svg | 2 +- .../diagrams/observation-loop-light.svg | 2 +- site/index.html | 30 +-- site/lineage.html | 10 +- tools/diagrams/assurance-loop.mmd | 8 +- tools/diagrams/core-loop.mmd | 36 ++-- tools/diagrams/observation-loop.mmd | 8 +- tools/wiki/stage.py | 32 ++- 73 files changed, 1448 insertions(+), 1153 deletions(-) create mode 100644 docs/adr/0008-namespec-2.0.md rename docs/design/domains/{narset.md => aurelia.md} (66%) rename docs/design/domains/{augustin.md => isperia.md} (78%) create mode 100644 docs/design/domains/jin-gitaxias.md delete mode 100644 docs/design/domains/oona.md delete mode 100644 docs/design/domains/tezzeret.md create mode 100644 docs/design/domains/ugin.md rename docs/design/domains/{sarpadia.md => urborg.md} (79%) rename docs/design/domains/{kasmina.md => wrenn.md} (65%) create mode 100644 docs/product/decisions/0020-namespec-2.0-adoption.md diff --git a/.claude/skills/simic-design/_ds_bundle.js b/.claude/skills/simic-design/_ds_bundle.js index 1d230a6..28f2daf 100644 --- a/.claude/skills/simic-design/_ds_bundle.js +++ b/.claude/skills/simic-design/_ds_bundle.js @@ -671,7 +671,7 @@ function OverviewScreen({ style: { margin: 0 } - }, "Nissa observes and reports. Tamiyo plans. Narset commissions and acts. Momir designs. Elesh conforms. Tezzeret compiles. Urabrask tests the compiled result in Tolaria. Augustin judges the resulting evidence under Leyline. Kasmina embodies the admitted growth. Emrakul destroys what no longer earns continued tenancy. Sarpadia retains every precedent. Oona reveals the account.")), /*#__PURE__*/React.createElement("h2", null, "Where the design lives"), /*#__PURE__*/React.createElement("p", null, "The canonical authority is the HLD chapter set in the repository, not this site.")), /*#__PURE__*/React.createElement(DataTable, { + }, "Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo reveals; every precedent is kept in Urborg.")), /*#__PURE__*/React.createElement("h2", null, "Where the design lives"), /*#__PURE__*/React.createElement("p", null, "The canonical authority is the HLD chapter set in the repository, not this site.")), /*#__PURE__*/React.createElement(DataTable, { caption: "Repository map", columns: ["Path", "Contents"], rows: [["docs/design/00-INDEX.md", "Entry point to the HLD chapter set, with reading paths"], ["docs/design/01-claim.md", "Executive summary, problem statement, goals, non-goals, the first defensible claim"], ["docs/design/02-constitution.md", "Naming constitution and the 45 blocking invariants"], ["docs/design/04-architecture.md", "System context, planes, and the control hierarchy"], ["src/simic/", "Target code layout: one package per domain (scaffold only, today)"]] diff --git a/.claude/skills/simic-design/readme.md b/.claude/skills/simic-design/readme.md index 7d63eb5..d4ddf29 100644 --- a/.claude/skills/simic-design/readme.md +++ b/.claude/skills/simic-design/readme.md @@ -1,6 +1,6 @@ # Simic Design System -Design system for **Simic — Counterfactual Generative Morphogenesis**, a research project by tachyon-beep (foundryside.dev). Simic is a lifecycle-driven neural training system: new structure is generated from the live state of a host network, then causally screened against doing nothing. Status: pre-implementation bootstrap — HLD v4.1, Namespec 1.0, locked. +Design system for **Simic — Counterfactual Generative Morphogenesis**, a research project by tachyon-beep (foundryside.dev). Simic is a lifecycle-driven neural training system: new structure is generated from the live state of a host network, then causally screened against doing nothing. Status: pre-implementation bootstrap — HLD v4.1, Namespec 2.0, locked. Two surfaces: 1. **Marketing/overview site** (https://simic.foundryside.dev/) — hand-written static HTML, vanilla CSS, **zero JavaScript**, zero external requests. Source: `site/` in the repo. @@ -17,7 +17,7 @@ Source repo: https://github.com/foundryside-dev/simic — explore it for the can **Person**: third person throughout. The system and its domains are the subjects ("Nissa observes and reports"). No "we", no "you". Direct imperatives appear only in obligations ("Do not strip armour to speed the forward motion"). **Signature devices**: -- Domain codenames as actors with one-verb authority: "Momir designs. Elesh conforms. Tezzeret compiles." +- Domain codenames as actors with one-verb authority: "Momir designs. Elesh conforms. Urabrask compiles." - Invariant citations inline: `INV-15`, `INV-38`, set in mono accent. - File paths as authority citations: `docs/design/01-claim.md` §4. - Bold for the load-bearing clause of a paragraph, em for contrastive stress (*what*, *whether*, *who*). @@ -27,7 +27,7 @@ Source repo: https://github.com/foundryside-dev/simic — explore it for the can **Examples** (verbatim): > "Doing nothing is a real competitor." > "Absent signal stays absent and is never a fabricated zero." -> "Nissa sends the photograph directly to the designer. Narset sends only the assignment brief." +> "Nissa sends the photograph directly to the designer. Aurelia sends only the assignment brief." ## VISUAL FOUNDATIONS diff --git a/AGENTS.md b/AGENTS.md index 0fe5af5..a7271d9 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -10,7 +10,7 @@ reversibly under warrant, and eventually retired. ## Canonical design authority -The HLD (v4.1, Namespec 1.0 — locked) is decomposed into standalone chapters +The HLD (v4.1, Namespec 2.0 — locked, ADR-0008) is decomposed into standalone chapters under **`docs/design/`** (ADR-0001). Entry point and §→file concordance: **`docs/design/00-INDEX.md`**. Load `docs/design/02-constitution.md` (naming constitution + the 45 INV-nn invariants) in every working session, plus the @@ -31,34 +31,37 @@ state, not free-edit documentation. Three infrastructure domains carry prepositions (Leyline = contracts and the deterministic request resolver; Tolaria = the single training/execution -substrate for mainline and branches; Sarpadia = append-only history, ancestry +substrate for mainline and branches; Urborg = append-only history, ancestry and retrieval). Eleven agent domains carry verbs — the canonical sentence (`docs/design/02-constitution.md`): -> Nissa observes and reports. Tamiyo plans. Narset commissions and acts. -> Momir designs. Elesh conforms. Tezzeret compiles. Urabrask tests the -> compiled result in Tolaria. Augustin judges the resulting evidence under -> Leyline. Kasmina embodies the admitted growth. Emrakul destroys what no -> longer earns continued tenancy. Sarpadia retains every precedent. Oona -> reveals the account. +> Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, +> Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in +> Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo +> reveals; every precedent is kept in Urborg. The codenames are behavioural mandates and act as an architecture linter: a subsystem acting contrary to its verb is exercising authority it must not have (`02-constitution.md`, `04-architecture.md`, `domains/README.md`, and the -smell catalogue in `03-principles.md`). The core loop: Tolaria trains +smell catalogue in `03-principles.md`). Namespec 2.0 (ADR-0008) adds a +faction layer: Momir → Elesh → Urabrask → Jin-Gitaxias form the Phyrexian +industrial synthesis core (bio-foundry → standardisation → manufacturing → +QA), and the remaining authorities are the governance cage that contains it — +a Phyrexian name on a governance lever, or a cage name inside the assembly +line, is an authority smell before it is a diff. The core loop: Tolaria trains the host → Nissa observes the ablated host and publishes the **same** -`TelemetryEnvelope` directly to Narset and Momir → Tamiyo grants a -`StrategicEnvelope` → Narset issues a narrow `GrowthIntent` (assignment brief; +`TelemetryEnvelope` directly to Aurelia and Momir → Ugin grants a +`StrategicEnvelope` → Aurelia issues a narrow `GrowthIntent` (assignment brief; diagnosis/topology/ancestry hints are schema-invalid) → Leyline's deterministic resolver produces the canonical `GrowthRequest` → Momir designs raw candidates -(optionally conditioned on Sarpadia bootstrap ancestry) → Elesh canonicalises -and verifies → Tezzeret compiles without changing semantics → Urabrask runs QA -in Tolaria's matched common-future branches and certifies evidence → Augustin -adjudicates provider-blind against no-op and issues warrants → Kasmina +(optionally conditioned on Urborg bootstrap ancestry) → Elesh canonicalises +and verifies → Urabrask compiles without changing semantics → Jin-Gitaxias runs QA +in Tolaria's matched common-future branches and certifies evidence → Isperia +adjudicates provider-blind against no-op and issues warrants → Wrenn germinates/blends/commits under an admission warrant → Emrakul later -sedates/decays/lyses under maintenance warrants → Sarpadia records everything → -Oona reveals it. The newsroom rule (`appendices/newsroom.md`): **Nissa sends -the photograph; Narset sends only the assignment brief.** +sedates/decays/lyses under maintenance warrants → Urborg records everything → +Tamiyo reveals it. The newsroom rule (`appendices/newsroom.md`): **Nissa sends +the photograph; Aurelia sends only the assignment brief.** ## Non-negotiable invariants (`02-constitution.md` has all 45; these are the spine) @@ -69,22 +72,22 @@ the photograph; Narset sends only the assignment brief.** - **Lexicographic admission:** the tail-risk veto is adjudicated before any utility comparison and cannot be traded against measured benefit; the assurance class owns the veto operating point. -- **QA/judgement split:** Urabrask certifies evidence but never issues - verdicts or warrants; Augustin judges but never executes or alters tests. -- **Dual provider blindness:** neither Urabrask nor Augustin sees candidate +- **QA/judgement split:** Jin-Gitaxias certifies evidence but never issues + verdicts or warrants; Isperia judges but never executes or alters tests. +- **Dual provider blindness:** neither Jin-Gitaxias nor Isperia sees candidate source; blinding is by construction (fields absent, not ignored). -- **Warrants:** Kasmina never raises influence without a valid Augustin +- **Warrants:** Wrenn never raises influence without a valid Isperia admission warrant; ordinary decay/lysis requires a maintenance warrant. - **Assignment-brief boundary:** `GrowthIntent` carries scope and operational constraints only; equivalent intents resolve to one canonical request, and - Momir never sees Narset hidden state. + Momir never sees Aurelia hidden state. - **Semantic identity:** artefact, QA report, decision and embodiment all - reference the same canonical hash; Tezzeret preserves semantics. -- **Authority separation:** Narset pre-commit only, Emrakul post-commit only, - Tamiyo never issues local transitions, Nissa never emits `should_grow`. -- **Complete history:** Sarpadia is append-only and retains failures, rejected + reference the same canonical hash; Urabrask preserves semantics. +- **Authority separation:** Aurelia pre-commit only, Emrakul post-commit only, + Ugin never issues local transitions, Nissa never emits `should_grow`. +- **Complete history:** Urborg is append-only and retains failures, rejected pools, no-op wins and abstentions — never winners-only. -- **Oona isolation:** disconnecting observability cannot change training. +- **Tamiyo isolation:** disconnecting observability cannot change training. - **Leyline dependency direction:** contracts import nothing from subsystems. - **Grouped statistics:** branches of one base trajectory never cross splits. - **Scaffold discipline:** every run declares its three-axis `ScaffoldState`; @@ -94,8 +97,8 @@ the photograph; Narset sends only the assignment brief.** ## Target layout and sequencing Code goes under `src/simic//` — one package per domain (`leyline/`, -`tolaria/`, `sarpadia/`, `tamiyo/`, `narset/`, `nissa/`, `momir/`, `elesh/`, -`tezzeret/`, `urabrask/`, `augustin/`, `kasmina/`, `emrakul/`, `oona/`) plus +`tolaria/`, `urborg/`, `ugin/`, `aurelia/`, `nissa/`, `momir/`, `elesh/`, +`urabrask/`, `jin_gitaxias/`, `isperia/`, `wrenn/`, `emrakul/`, `tamiyo/`) plus `controls/`, `curriculum/`, `benchmarks/`, `experiments/`, `analysis/`, `scripts/`, with `tests/{namespec,contracts,observation_routing,request_resolution,bootstrap_withdrawal,scaffold_withdrawal,unit,integration,training,determinism,counterfactual,authority,blinding,end_to_end}/` diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index c786725..24806bd 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -17,7 +17,7 @@ keep four questions separate: *what* to build, *whether* it is sound, Authority is split across fourteen bounded domains, grouped into planes. Three domains are infrastructure (named with prepositions: *under* Leyline, -*in* Tolaria, *from* Sarpadia); eleven are agents (named with verbs). A +*in* Tolaria, *from* Urborg); eleven are agents (named with verbs). A subsystem acting contrary to its verb is exercising authority it must not have — the names are an architecture linter. @@ -25,108 +25,106 @@ have — the names are an architecture linter. |---|---|---| | Constitutional infrastructure | Leyline | Contracts, grammar profiles, compatibility, the deterministic request resolver | | Training and execution infrastructure | Tolaria | Trains the live host; executes deterministic ordinary, replay and branch worlds | -| Historical infrastructure | Sarpadia | Append-only history: lineages, outcomes, failures, split-safe datasets | -| Strategic agency | Tamiyo | Allocates regional resources, permissions and risk over long horizons | -| Tactical commissioning | Narset | Decides whether and where to commission growth; pre-commit lifecycle actions | +| Historical infrastructure | Urborg | Append-only history: lineages, outcomes, failures, split-safe datasets | +| Strategic agency | Ugin | Allocates regional resources, permissions and risk over long horizons | +| Tactical commissioning | Aurelia | Decides whether and where to commission growth; pre-commit lifecycle actions | | Observation | Nissa | Publishes what the host is doing without prescribing what to build | -| Synthesis | Momir, Elesh, Tezzeret | Designs, canonicalises and compiles growth | -| Assurance and adjudication | Urabrask, Augustin | Establishes empirical evidence, then judges it independently | -| Embodiment and maintenance | Kasmina, Emrakul | Introduces growth safely; removes obsolete committed structure | -| Witness | Oona | Exposes an auditable account without steering anything | +| Synthesis | Momir, Elesh, Urabrask | Designs, canonicalises and compiles growth | +| Assurance and adjudication | Jin-Gitaxias, Isperia | Establishes empirical evidence, then judges it independently | +| Embodiment and maintenance | Wrenn, Emrakul | Introduces growth safely; removes obsolete committed structure | +| Witness | Tamiyo | Exposes an auditable account without steering anything | ## The pipeline ```mermaid flowchart TD - TOL["Tolaria: trains the host"] --> KAS["Kasmina: host + reversible growth physiology"] - KAS --> NIS["Nissa: canonical ablated observation"] - NIS -->|"TelemetryEnvelope"| NAR["Narset: commissions"] + TOL["Tolaria: trains the host"] --> WRE["Wrenn: host + reversible growth physiology"] + WRE --> NIS["Nissa: canonical ablated observation"] + NIS -->|"TelemetryEnvelope"| AUR["Aurelia: commissions"] NIS -->|"same TelemetryEnvelope"| MOM["Momir: designs candidates"] - TAM["Tamiyo: strategic controller"] -->|"StrategicEnvelope"| NAR - NAR -->|"GrowthIntent (assignment brief)"| RES["Leyline: deterministic request resolver"] + UGN["Ugin: strategic controller"] -->|"StrategicEnvelope"| AUR + AUR -->|"GrowthIntent (assignment brief)"| RES["Leyline: deterministic request resolver"] RES -->|"canonical GrowthRequest"| MOM MOM -->|"RawGrowthGraph"| ELE["Elesh: verifies + canonicalises"] - ELE -->|"CanonicalGrowthSpec"| TEZ["Tezzeret: compiles"] - TEZ -->|"ExecutableGrowthArtifact"| URA["Urabrask: QA in Tolaria branches"] - URA -->|"blinded QualityReport"| AUG["Augustin: judges vs mandatory no-op"] - AUG -->|"admission warrant"| KAS - KAS -->|"committed growth"| EMR["Emrakul: maintains, retires"] - AUG -->|"maintenance warrant"| EMR + ELE -->|"CanonicalGrowthSpec"| URB["Urabrask: compiles"] + URB -->|"ExecutableGrowthArtifact"| JIN["Jin-Gitaxias: QA in Tolaria branches"] + JIN -->|"blinded QualityReport"| ISP["Isperia: judges vs mandatory no-op"] + ISP -->|"admission warrant"| WRE + WRE -->|"committed growth"| EMR["Emrakul: maintains, retires"] + ISP -->|"maintenance warrant"| EMR ``` -Every stage also appends its records to Sarpadia and projects events to -Oona; those edges are omitted above for legibility. Two details in the +Every stage also appends its records to Urborg and projects events to +Tamiyo; those edges are omitted above for legibility. Two details in the diagram are load-bearing: -- **Nissa publishes the same observation identity independently to Narset - and Momir.** Narset is not a telemetry proxy; the newsroom formulation is - "Nissa sends the photograph; Narset sends only the assignment brief." A +- **Nissa publishes the same observation identity independently to Aurelia + and Momir.** Aurelia is not a telemetry proxy; the newsroom formulation is + "Nissa sends the photograph; Aurelia sends only the assignment brief." A `GrowthIntent` carries scope and operational constraints only — diagnosis, topology and ancestry hints are schema-invalid (INV-07, INV-09). - **The request resolver is not a fifteenth agent.** It is a pure Leyline - service that combines `GrowthIntent` + `StrategicEnvelope` + Kasmina's + service that combines `GrowthIntent` + `StrategicEnvelope` + Wrenn's `RegionContract` + the active `GrammarProfile` into one canonical `GrowthRequest`, can only narrow authority, and fails closed on incompatibility (INV-10, INV-11). -The assurance loop: Urabrask builds a blinded `TestPlan`; Tolaria restores a +The assurance loop: Jin-Gitaxias builds a blinded `TestPlan`; Tolaria restores a common snapshot and runs candidate branches, controls, and a **mandatory -no-op branch** over identical future data; Urabrask certifies the evidence -into a `QualityReport` without issuing a verdict; Augustin applies +no-op branch** over identical future data; Jin-Gitaxias certifies the evidence +into a `QualityReport` without issuing a verdict; Isperia applies eligibility, budget, risk and utility policy and returns one of `ADMIT / NO_OP / REJECT / DEFER / REQUIRE_RETEST`. Admitted growth germinates at zero influence, matures, blends in reversibly, and at commit -passes from Narset's ownership to Emrakul's, where it must keep earning its +passes from Aurelia's ownership to Emrakul's, where it must keep earning its tenancy through periodic counterfactual review (`RETAIN / RETEST / SEDATE / DECAY / LYSE`). ## The fourteen domains -The canonical sentence: *Nissa observes and reports. Tamiyo plans. Narset -commissions and acts. Momir designs. Elesh conforms. Tezzeret compiles. -Urabrask tests the compiled result in Tolaria. Augustin judges the resulting -evidence under Leyline. Kasmina embodies the admitted growth. Emrakul -destroys what no longer earns continued tenancy. Sarpadia retains every -precedent. Oona reveals the account.* +The canonical sentence: *Under Leyline, Ugin plans, Aurelia commissions and +acts, Nissa observes, Momir designs, Elesh conforms, Urabrask compiles, +Jin-Gitaxias tests in Tolaria, Isperia judges, Wrenn embodies, Emrakul +destroys, and Tamiyo reveals; every precedent is kept in Urborg.* | Domain | Key outputs | Explicitly does not own | |---|---|---| | **Leyline** | Versioned contracts, validators, resolved requests | Case-specific policy, diagnosis, execution | | **Tolaria** | `Snapshot`, `BranchResult`, execution manifests | Utility weights, candidate preference, verdicts | -| **Sarpadia** | `GrowthRecord`, retrieval sets, lineage graphs | Live-host mutation, self-approval | -| **Tamiyo** | `StrategicEnvelope` | Local action timing, candidate choice | -| **Narset** | `GrowthIntent`, `LifecycleCommand` | Diagnosis, topology hints, post-commit structure | +| **Urborg** | `GrowthRecord`, retrieval sets, lineage graphs | Live-host mutation, self-approval | +| **Ugin** | `StrategicEnvelope` | Local action timing, candidate choice | +| **Aurelia** | `GrowthIntent`, `LifecycleCommand` | Diagnosis, topology hints, post-commit structure | | **Nissa** | `TelemetryEnvelope` | `should_grow`, structural recommendations, verdicts | | **Momir** | `RawGrowthGraph` | Intervention timing, approval, testing | | **Elesh** | `CanonicalGrowthSpec`, structural reports | Runtime QA, task utility, lifecycle policy | -| **Tezzeret** | `ExecutableGrowthArtifact`, compilation manifest | Semantic topology changes, QA, admission | -| **Urabrask** | `TestPlan`, `QualityReport` | Verdicts, warrants, lifecycle commands | -| **Augustin** | `AdmissionDecision`, `MaintenanceDecision`, warrants | Test execution, compilation, host mutation | -| **Kasmina** | `RegionContract`, embodied state, lifecycle events | Whether a growth deserves admission | +| **Urabrask** | `ExecutableGrowthArtifact`, compilation manifest | Semantic topology changes, QA, admission | +| **Jin-Gitaxias** | `TestPlan`, `QualityReport` | Verdicts, warrants, lifecycle commands | +| **Isperia** | `AdmissionDecision`, `MaintenanceDecision`, warrants | Test execution, compilation, host mutation | +| **Wrenn** | `RegionContract`, embodied state, lifecycle events | Whether a growth deserves admission | | **Emrakul** | Maintenance requests, warranted lifecycle commands | Candidate construction, judgement | -| **Oona** | Operator views, flight recorder, audit bundles | Training control, source-of-truth schemas | +| **Tamiyo** | Operator views, flight recorder, audit bundles | Training control, source-of-truth schemas | ## Authority model -Control flows down a narrow hierarchy — Tamiyo sets the `StrategicEnvelope`; -Narset chooses local pre-commit actions inside it; after `COMMIT`, ordinary +Control flows down a narrow hierarchy — Ugin sets the `StrategicEnvelope`; +Aurelia chooses local pre-commit actions inside it; after `COMMIT`, ordinary ownership transfers to Emrakul for post-commit maintenance. Three authorities sit deliberately **outside** that hierarchy: -- **Urabrask and Augustin are independent** of the command chain: Urabrask - certifies evidence but never issues verdicts or warrants; Augustin judges +- **Jin-Gitaxias and Isperia are independent** of the command chain: Jin-Gitaxias + certifies evidence but never issues verdicts or warrants; Isperia judges but never executes or alters tests (INV-18). Neither ever sees candidate provenance — blinding is by construction, with source fields absent rather than ignored (INV-17, INV-37). - **Tolaria is beneath the hierarchy** as neutral execution infrastructure: it applies no utility weights and issues no verdicts (INV-03). -- **Oona and Sarpadia are outside the control path**: disconnecting Oona - cannot change training (INV-35), and Sarpadia's history is append-only and +- **Tamiyo and Urborg are outside the control path**: disconnecting Tamiyo + cannot change training (INV-35), and Urborg's history is append-only and retains failures, rejected pools, no-op wins and abstentions — never winners-only (INV-31, INV-36). -No influence without a warrant: Kasmina cannot raise a newborn growth above -zero influence without a valid Augustin admission warrant (INV-26), and +No influence without a warrant: Wrenn cannot raise a newborn growth above +zero influence without a valid Isperia admission warrant (INV-26), and ordinary post-commit decay or lysis requires a maintenance warrant (INV-27). Every artefact, QA report, decision and embodiment references the same canonical semantic hash (INV-20). diff --git a/README.md b/README.md index 5bdfc6f..be8b8c4 100644 --- a/README.md +++ b/README.md @@ -7,7 +7,7 @@ in matched counterfactual branches, adjudicated against doing nothing, embodied reversibly under warrant, and eventually retired. > **Status: pre-implementation bootstrap.** The design is complete — the -> HLD (v4.1, Namespec 1.0 — locked) is decomposed into standalone chapters +> HLD (v4.1, Namespec 2.0 — locked, ADR-0008) is decomposed into standalone chapters > under [`docs/design/`](docs/design/00-INDEX.md) (ADR-0001) — and the > Python scaffold is in place, but no functional code exists yet. First > engineering work is Phase A (Namespec, @@ -38,16 +38,14 @@ codenames (they act as an architecture linter — a subsystem acting contrary to its verb is exercising authority it must not have). Three are infrastructure: **Leyline** (contracts and the deterministic request resolver), **Tolaria** (the single training/execution substrate for mainline -and branches), and **Sarpadia** (append-only history, ancestry, retrieval). +and branches), and **Urborg** (append-only history, ancestry, retrieval). The other eleven are agents, summarised by the canonical sentence ([`docs/design/02-constitution.md`](docs/design/02-constitution.md)): -> Nissa observes and reports. Tamiyo plans. Narset commissions and acts. -> Momir designs. Elesh conforms. Tezzeret compiles. Urabrask tests the -> compiled result in Tolaria. Augustin judges the resulting evidence under -> Leyline. Kasmina embodies the admitted growth. Emrakul destroys what no -> longer earns continued tenancy. Sarpadia retains every precedent. Oona -> reveals the account. +> Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, +> Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in +> Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo +> reveals; every precedent is kept in Urborg. The architecture deliberately resembles a newsroom ([`docs/design/appendices/newsroom.md`](docs/design/appendices/newsroom.md)): @@ -71,16 +69,16 @@ defines 45 blocking invariants, cited as INV-nn. The spine: - **Tail risk cannot be bought (INV-45):** admission is lexicographic — a tail-risk veto precedes utility comparison, and no measured benefit can offset a veto. -- **Evidence and judgement never mix (INV-17, INV-18, INV-37):** Urabrask - (QA) certifies evidence but cannot issue verdicts; Augustin (judge) +- **Evidence and judgement never mix (INV-17, INV-18, INV-37):** Jin-Gitaxias + (QA) certifies evidence but cannot issue verdicts; Isperia (judge) decides but cannot touch tests — and neither ever sees candidate provenance (blinding by construction). -- **No influence without a warrant (INV-26, INV-27):** Kasmina cannot raise +- **No influence without a warrant (INV-26, INV-27):** Wrenn cannot raise a growth above zero influence, and Emrakul cannot retire committed - structure, without a valid Augustin warrant. -- **Complete history (INV-31, INV-36):** Sarpadia is append-only and keeps + structure, without a valid Isperia warrant. +- **Complete history (INV-31, INV-36):** Urborg is append-only and keeps failures and abstentions — never winners-only. -- **Observability is inert (INV-35):** disconnecting Oona cannot change +- **Observability is inert (INV-35):** disconnecting Tamiyo cannot change training. ## Repository map diff --git a/docs/adr/0001-hld-decomposition-structure.md b/docs/adr/0001-hld-decomposition-structure.md index a703d67..efec44d 100644 --- a/docs/adr/0001-hld-decomposition-structure.md +++ b/docs/adr/0001-hld-decomposition-structure.md @@ -3,6 +3,10 @@ Date: 2026-08-08 · Status: accepted Deciders: john (structure selected from four proposals in-session) · Tracker: simic-573b5b1c35, simic-80cc39ccfc +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). + ## Context The v4.1 HLD was one 4,720-line file. The predecessor programme (esper) failed diff --git a/docs/adr/0002-information-management-regime.md b/docs/adr/0002-information-management-regime.md index eac447f..15acc48 100644 --- a/docs/adr/0002-information-management-regime.md +++ b/docs/adr/0002-information-management-regime.md @@ -3,6 +3,10 @@ Date: 2026-08-08 · Status: accepted Deciders: john (approach A selected from three in-session) · Tracker: simic-357c92664c +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). + ## Context Esper and esper-lite had two systemic failures. Reward shaping is recorded diff --git a/docs/adr/0003-project-name-simic-clean-seam.md b/docs/adr/0003-project-name-simic-clean-seam.md index 5bce063..0a585ca 100644 --- a/docs/adr/0003-project-name-simic-clean-seam.md +++ b/docs/adr/0003-project-name-simic-clean-seam.md @@ -3,6 +3,10 @@ Date: 2026-08-08 · Status: accepted Deciders: John (owner; in-session rulings 2026-08-08) · Tracker: simic-a708c5b1b7, simic-3a17fe545d, PDR-0006 +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). + ## Context The HLD left the umbrella name open — remain `simic`, return to `esper`, or diff --git a/docs/adr/0004-lexicographic-admission.md b/docs/adr/0004-lexicographic-admission.md index 0a763f1..f3ce787 100644 --- a/docs/adr/0004-lexicographic-admission.md +++ b/docs/adr/0004-lexicographic-admission.md @@ -2,6 +2,10 @@ Date: 2026-08-08 · Status: accepted Deciders: John (gate adjudication PDR-0007; peer review §22 accepted into the + +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). wave programme) · Tracker: simic-ae3caf44f1 ## Context diff --git a/docs/adr/0005-retention-hysteresis-schmitt-trigger.md b/docs/adr/0005-retention-hysteresis-schmitt-trigger.md index 94764e8..95c910e 100644 --- a/docs/adr/0005-retention-hysteresis-schmitt-trigger.md +++ b/docs/adr/0005-retention-hysteresis-schmitt-trigger.md @@ -2,6 +2,10 @@ Date: 2026-08-08 · Status: accepted Deciders: John (gate adjudication PDR-0007; peer review §2 accepted into the + +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). wave programme) · Tracker: simic-ed2698fafd ## Context diff --git a/docs/adr/0006-ban-silent-defaulting-telemetry-access.md b/docs/adr/0006-ban-silent-defaulting-telemetry-access.md index a204c2d..279daef 100644 --- a/docs/adr/0006-ban-silent-defaulting-telemetry-access.md +++ b/docs/adr/0006-ban-silent-defaulting-telemetry-access.md @@ -2,6 +2,10 @@ Date: 2026-08-08 · Status: accepted Deciders: John (owner-directed rule and rationale, in-session 2026-08-08) · + +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). Tracker: simic-108cdb52bc ## Context diff --git a/docs/adr/0007-wiki-projection-regime.md b/docs/adr/0007-wiki-projection-regime.md index 2a80199..af83900 100644 --- a/docs/adr/0007-wiki-projection-regime.md +++ b/docs/adr/0007-wiki-projection-regime.md @@ -2,6 +2,10 @@ Date: 2026-08-09 · Status: accepted Deciders: John (owner-directed, in-session 2026-08-09) · + +> **Namespec note (ADR-0008):** this record predates Namespec 2.0 and uses +> Namespec 1.0 names; read it through the concordance in +> [`0008-namespec-2.0.md`](0008-namespec-2.0.md). Tracker: simic-dd5a578332 ## Context diff --git a/docs/adr/0008-namespec-2.0.md b/docs/adr/0008-namespec-2.0.md new file mode 100644 index 0000000..74de51d --- /dev/null +++ b/docs/adr/0008-namespec-2.0.md @@ -0,0 +1,150 @@ +# ADR-0008 — Adopt Namespec 2.0: the Phyrexian industrial compleation constitution + +Date: 2026-08-09 · Status: accepted +Deciders: John (owner; directive of 2026-08-09, prompts/namespec.md) · Tracker: simic-d8369760b9 + +## Context + +Namespec 1.0 was locked in `../design/02-constitution.md#57-change-control` and +reaffirmed unamended in ADR-0003 after the peer review challenged the +Tamiyo-as-strategist assignment (simic-3a17fe545d, ruled WONTFIX 2026-08-08). +On 2026-08-09 the owner directed a final consistency pass over the conceptual +design and issued a locked replacement naming constitution — **Namespec 2.0** +— superseding Namespec 1.0 in its entirety, with no legacy aliases. The +architecture remains HLD v4.1: every authority boundary, contract schema, +lifecycle rule, determinism policy, scaffold withdrawal gate, and the 45 +INV-nn invariants are unchanged in content. Only the subsystem codenames, +their narrative grammar, and the thematic framing change. + +The change also settles, on new terms, the ambiguity the peer review raised: +Tamiyo leaves the strategic role entirely. Strategy goes to a name with no +pre-pivot history (Ugin), and Tamiyo moves to the witness role — the one that +matches the character (the Moon Sage who records histories without steering +them) — replacing Oona, whose secret-hoarding Fae-queen character was always +a poor fit for an agent whose verb is *reveals*. + +## Decision + +Adopt Namespec 2.0 as the locked naming constitution. The concordance: + +| Role | Namespec 1.0 | Namespec 2.0 | Verb / context | +|---|---|---|---| +| Constitutional infrastructure | Leyline | **Leyline** (retained) | *under/through Leyline* | +| Training & execution substrate | Tolaria | **Tolaria** (retained) | *trained/executed/tested in Tolaria* | +| Historical infrastructure | Sarpadia | **Urborg** | *recorded in/retrieved from Urborg* | +| Strategic agency | Tamiyo | **Ugin** | *plans* | +| Tactical commissioning | Narset | **Aurelia** | *commissions and acts* | +| Observation | Nissa | **Nissa** (retained) | *observes and reports* | +| Synthesis — design | Momir | **Momir** (retained) | *designs* | +| Synthesis — conformance | Elesh | **Elesh** (retained) | *conforms* | +| Synthesis — compilation | Tezzeret | **Urabrask** | *compiles* | +| Assurance & evidence | Urabrask | **Jin-Gitaxias** | *tests* | +| Adjudication | Augustin | **Isperia** | *judges* | +| Embodiment & physiology | Kasmina | **Wrenn** | *embodies* | +| Maintenance & destruction | Emrakul | **Emrakul** (retained) | *destroys* | +| Witness & revelation | Oona | **Tamiyo** | *reveals* | + +The canonical sentence becomes: + +> **Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, +> Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in +> Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo +> reveals; every precedent is kept in Urborg.** + +The thematic framing is upgraded from decorative lore to a **warning system**: +the architecture is a Simic engine run under Phyrexian industrial discipline. +Momir (bio-foundry) → Elesh (standardisation) → Urabrask (manufacturing) → +Jin-Gitaxias (quality control) form the **Phyrexian industrial synthesis +core** — a single compleation assembly line inside the architecture — and +the non-Phyrexian authorities (Ugin, Aurelia, Isperia, Tamiyo, Nissa, Wrenn) +form the **governance cage** that contains it. The tension between core and +cage is the architecture's central narrative, and it makes authority +violations audible: a Phyrexian name showing up on a governance decision, or +a cage name inside the assembly line, is a sentence that sounds wrong before +it is a diff that reads wrong. + +Urabrask's chapter must state his **dual compilation mode** explicitly: +on-demand manufacturing (compile the canonical specification under deadline +and budget when Aurelia commissions a growth) and background industrial R&D +(idle-cycle compilation of canonical backlogs and discovery of production +optimisations, reported as versioned compiler improvements). Neither mode may +invent topology (Momir's domain) or alter semantic meaning (Elesh's +canonical identity; INV-21). This is framing made explicit, not new +authority. + +The agent/infrastructure grammar is preserved: agents carry verbs (Ugin, +Aurelia, Nissa, Momir, Elesh, Urabrask, Jin-Gitaxias, Isperia, Wrenn, +Emrakul, Tamiyo); infrastructure carries prepositions (Leyline, Tolaria, +Urborg). The Python package for Jin-Gitaxias is `jin_gitaxias`; document +files and anchors use `jin-gitaxias`. + +**Historical-interpretation rule.** Two names appear in both namespecs with +different referents: *Urabrask* (1.0: QA/testing → 2.0: compilation) and +*Tamiyo* (1.0: strategic planning → 2.0: witness/revelation). Any document +whose content predates this ADR — the archived v4.1 monolith, the +`docs/concept/reviews/` records, the bodies of ADR-0001..0007, and PDR +bodies through 0019 — uses Namespec 1.0 names where it names domains at all, +and is read through the +concordance above. Those records are not rewritten (Urborg discipline: +corrections create new records; INV-36). ADR-0001..0007 receive a one-line +namespec banner pointing here; nothing else in them changes. + +## Displaced constraints + +- **Namespec 1.0 lock** (`../design/02-constitution.md#57-change-control`): + displaced in its entirety by the Namespec 2.0 locked list above. This is + exactly the amendment path §5.7 prescribes — a codename change through an + ADR. +- **ADR-0003's Namespec 1.0 reaffirmation**: superseded in part. The + project-level name (Simic, clean seam) and everything else in ADR-0003 + stand; only the "Namespec 1.0 stands unamended" ruling is displaced. The + underlying gate ruling (Tamiyo does not return to the tactical role) is + still honoured: under 2.0 the tactical role is Aurelia, and Tamiyo is the + witness, not the tactician. +- **No INV-nn is amended in content.** All 45 invariants are re-worded only + where they name an agent (e.g. INV-17 dual provider blindness now names + Jin-Gitaxias and Isperia; INV-26/27 warrants now name Isperia and Wrenn; + INV-35 Oona isolation becomes Tamiyo isolation). The obligations, + thresholds and failure semantics are character-for-character equivalent + modulo the concordance. + +## Options considered + +- **Keep Namespec 1.0** — rejected by owner directive. Beyond preference: + 1.0's thematic layer was inert (names as mnemonics only), and two of its + castings fought their characters (Oona the secret-keeper as the revealer; + Tamiyo the recorder as the strategist). 2.0 makes the mythology + load-bearing — the synthesis-core/cage split encodes the QA/judgement and + designer/compiler separations the invariants enforce. +- **Rename only the contested pair (Tamiyo/Oona)** — rejected: a partial + amendment still breaks the lock and still needs the concordance machinery, + but buys no coherent frame; the industrial-core narrative requires the + Urabrask/Jin-Gitaxias and Tezzeret→Urabrask moves. +- **Choose 2.0 names with zero overlap against 1.0** (avoid reusing Urabrask + and Tamiyo) — rejected: it would trade permanent character-role mismatch + for a transitional reading hazard. The hazard is bounded — it lives only in + pre-pivot records, which are all behind the clean seam (ADR-0003) — and the + historical-interpretation rule plus banners pay it down once. + +## Consequences + +- **Cascade (this ADR's implementation):** `docs/design/02-constitution.md` + rewritten (Namespec 2.0, thematic constitution, INV renames, Appendix B); + all design chapters, `domains/` files (renamed, collision-safe), appendices + (newsroom, glossary, sentence tests, smells) updated; `AGENTS.md`, + `ARCHITECTURE.md`, `README.md` updated; `docs/design/assets/model.dsl` and + the mermaid sources renamed and re-rendered; product workspace updated + (PDR-0018); site pages and wiki rebuilt; open tracker issues retitled. +- **Phase A lands the 2.0 package layout:** `src/simic/{leyline, tolaria, + urborg, ugin, aurelia, nissa, momir, elesh, urabrask, jin_gitaxias, + isperia, wrenn, emrakul, tamiyo}` and the corresponding test directories. + No code exists yet, so the rename costs nothing on the code side — this is + the last cheap moment to make the change, which is why it happens now. +- **Future telemetry, test and audit names** use 2.0 names from birth. +- **Reading pre-pivot records now requires the concordance** for Urabrask + and Tamiyo; the banners on ADR-0001..0007 and the clean seam (ADR-0003) + bound the exposure. +- **Reversal trigger:** owner ruling only, before Phase A writes package + names to disk; after Phase A, a reversal is a new ADR with a migration + plan. Absent that, the decision stands unrevisited — naming churn is pure + cost (ADR-0003's discipline applies to this ADR too). diff --git a/docs/adr/README.md b/docs/adr/README.md index 8f7883e..ef6ea14 100644 --- a/docs/adr/README.md +++ b/docs/adr/README.md @@ -4,7 +4,7 @@ Design-doc tiering (PDR-0002, `docs/product/decisions/0002-design-doc-tiering.md - **Tier 0 — Constitution.** The HLD chapters under `docs/design/` (entry: `00-INDEX.md`; the locked core is `02-constitution.md`). Constitutional - constraints — Namespec 1.0, the INV-01..45 invariants, authority boundaries, + constraints — Namespec 2.0, the INV-01..45 invariants, authority boundaries, the newsroom rule, the no-op requirement, scaffold withdrawal — change only through an ADR that **names the displaced invariant** (`../design/ops/repo-structure.md#30-repository-handoff-and-custody` / repo diff --git a/docs/design/00-INDEX.md b/docs/design/00-INDEX.md index 8eeee50..6b5f315 100644 --- a/docs/design/00-INDEX.md +++ b/docs/design/00-INDEX.md @@ -24,7 +24,7 @@ load the chapters your task names; do not load the rest. | `06-growth-model.md` | Growth levels, candidate identity, lifecycle FSM and transition authority | | `07-counterfactual-engine.md` | Branch pools, Academy/Field QA, no-op anchoring, blindness, statistical unit | | `domains/README.md` | The §13 grouping preamble and navigation to the fourteen domain chapters | -| `domains/.md` | Per-domain specification (responsibilities, invariants, smells); `sarpadia.md` also carries the data model | +| `domains/.md` | Per-domain specification (responsibilities, invariants, smells); `urborg.md` also carries the data model | | `programme/curriculum.md` | Static-to-counterfactual curriculum, scaffold withdrawal stages | | `programme/learning.md` | Learning responsibilities per subsystem | | `programme/evaluation.md` | Testing strategy and evaluation framework | @@ -39,7 +39,7 @@ load the chapters your task names; do not load the rest. ## Reading paths - **Implementing a domain:** `02-constitution.md` + `domains/.md` + `05-leyline-contracts.md` (its contracts) + `programme/learning.md` (its entry). -- **Admission / adjudication work:** `02` + `domains/augustin.md` + `domains/urabrask.md` + `07-counterfactual-engine.md`. +- **Admission / adjudication work:** `02` + `domains/isperia.md` + `domains/jin-gitaxias.md` + `07-counterfactual-engine.md`. - **Contract / schema work:** `02` + `05-leyline-contracts.md` + `04-architecture.md` (flow). - **Experiment / curriculum design:** `02` + `01-claim.md` + `programme/*`. - **New here:** `01` → `04` → `02`, then `appendices/newsroom.md` for the authority model. @@ -50,7 +50,7 @@ In new text (issues, ADRs, LLDs, commit messages): - Invariants: **INV-nn** (numbering as listed in `02-constitution.md`, e.g. INV-05 Academy exact replay). - Contracts: by **name** (`GrowthIntent`), never by section number. -- Chapters: by **path#anchor** (`domains/augustin.md#admission-utility`). +- Chapters: by **path#anchor** (`domains/isperia.md#admission-utility`). - Legacy **§-numbers** (v4.1 monolith) remain resolvable via the concordance below — do not use them in new text. Rationale: v2.0→v4.1 renumbering broke every consumer that cited sections; @@ -70,7 +70,7 @@ names and file anchors survive restructuring, numbers do not. | §13 preamble | `domains/README.md` | | §13.1–§13.14 subsystem specs | `domains/.md` | | §14 counterfactual execution, QA, adjudication | `07-counterfactual-engine.md` | -| §15 Sarpadia data model | `domains/sarpadia.md` | +| §15 Urborg data model | `domains/urborg.md` | | §16 curriculum and scaffold withdrawal | `programme/curriculum.md` | | §17 learning responsibilities | `programme/learning.md` | | §18 constitutional invariants (INV-01..45) | `02-constitution.md` | diff --git a/docs/design/01-claim.md b/docs/design/01-claim.md index 35f5e4d..67e8025 100644 --- a/docs/design/01-claim.md +++ b/docs/design/01-claim.md @@ -23,68 +23,68 @@ The system is divided into fourteen bounded domains: - **Leyline** defines the contracts, schemas, grammar profiles, policy records, compatibility rules, and ordering invariants through which every other subsystem communicates. - **Tolaria** is the deterministic training and execution substrate in which the host, ordinary training runs, QA trials, flash clones, replays, and counterfactual worlds execute. -- **Sarpadia** is the persistent historical substrate in which candidate lineages, reference ancestry, counterfactual outcomes, failures, abstentions, and retrieval indices are retained. -- **Tamiyo** is the strategic controller. It allocates long-horizon developmental resources, permissions, risk, and capacity across regions. -- **Narset** is the tactical controller. It decides whether and where to commission local growth, and manages the pre-commit lifecycle inside Tamiyo's active strategic envelope. -- **Nissa** observes the host and publishes one canonical, typed diagnostic record directly to every authorised consumer, including Narset and Momir, without embedding policy or editorial interpretation. +- **Urborg** is the persistent historical substrate in which candidate lineages, reference ancestry, counterfactual outcomes, failures, abstentions, and retrieval indices are retained. +- **Ugin** is the strategic controller. It allocates long-horizon developmental resources, permissions, risk, and capacity across regions. +- **Aurelia** is the tactical controller. It decides whether and where to commission local growth, and manages the pre-commit lifecycle inside Ugin's active strategic envelope. +- **Nissa** observes the host and publishes one canonical, typed diagnostic record directly to every authorised consumer, including Aurelia and Momir, without embedding policy or editorial interpretation. - **Momir** designs raw candidate growth graphs, parameters, mutations, and recombinations from Nissa's diagnostic context and a separately resolved assignment contract. - **Elesh** verifies and canonicalises those designs into structurally legal, shape-safe, gradient-safe, semantically stable specifications. -- **Tezzeret** compiles canonical specifications into efficient executable artefacts without changing their meaning. -- **Urabrask** performs quality assurance. It designs test plans, requests execution in Tolaria, detects defects, measures behaviour, and produces certified evidence. -- **Augustin** is the judge. It applies admission and continued-tenancy policy to Urabrask's evidence, compares every candidate against no intervention, and issues decisions or warrants. -- **Kasmina** embodies admitted growth inside the host through reversible slots, isolated maturation, alpha blending, and lifecycle mechanics. -- **Emrakul** safely sedates, decays, consolidates, or lyses committed structure after Augustin has judged that continued tenancy is no longer justified. -- **Oona** reveals the system's account through event projections, flight recording, operator interfaces, audit bundles, and alerts. +- **Urabrask** compiles canonical specifications into efficient executable artefacts without changing their meaning. +- **Jin-Gitaxias** performs quality assurance. It designs test plans, requests execution in Tolaria, detects defects, measures behaviour, and produces certified evidence. +- **Isperia** is the judge. It applies admission and continued-tenancy policy to Jin-Gitaxias's evidence, compares every candidate against no intervention, and issues decisions or warrants. +- **Wrenn** embodies admitted growth inside the host through reversible slots, isolated maturation, alpha blending, and lifecycle mechanics. +- **Emrakul** safely sedates, decays, consolidates, or lyses committed structure after Isperia has judged that continued tenancy is no longer justified. +- **Tamiyo** reveals the system's account through event projections, flight recording, operator interfaces, audit bundles, and alerts. The ordinary host-training loop and the growth loop share one execution reality: ```text Task and data configuration ↓ -Tolaria trains the Kasmina host +Tolaria trains the Wrenn host ↓ Nissa publishes one canonical TelemetryEnvelope - ├──→ Narset decides whether and where to commission growth + ├──→ Aurelia decides whether and where to commission growth └──→ Momir receives the same uncaptioned diagnostic evidence directly ↓ -Tamiyo authorises strategic resources +Ugin authorises strategic resources ↓ -Narset emits a narrow GrowthIntent: the assignment brief +Aurelia emits a narrow GrowthIntent: the assignment brief ↓ -Leyline and Kasmina deterministically resolve the legal GrowthRequest +Leyline and Wrenn deterministically resolve the legal GrowthRequest ↓ -Sarpadia may supply temporary bootstrap ancestry or ordinary precedents +Urborg may supply temporary bootstrap ancestry or ordinary precedents ↓ -Momir designs → Elesh conforms → Tezzeret compiles +Momir designs → Elesh conforms → Urabrask compiles ↓ -Urabrask specifies QA; Tolaria executes the tests +Jin-Gitaxias specifies QA; Tolaria executes the tests ↓ -Urabrask certifies the evidence +Jin-Gitaxias certifies the evidence ↓ -Augustin judges candidate versus no-op +Isperia judges candidate versus no-op ↓ -Kasmina embodies an admitted growth +Wrenn embodies an admitted growth ↓ -Emrakul later removes what Augustin judges no longer earns its place +Emrakul later removes what Isperia judges no longer earns its place ↓ -Every success, failure, abstention, and lineage is retained in Sarpadia +Every success, failure, abstention, and lineage is retained in Urborg ↓ -Oona reveals the complete account +Tamiyo reveals the complete account ``` The locked narrative grammar is: -> **Under Leyline, Tamiyo plans, Narset commissions and acts, Nissa observes, Momir designs, Elesh conforms, Tezzeret compiles, Urabrask tests in Tolaria, Augustin judges, Kasmina embodies, Emrakul destroys, and Oona reveals; every precedent is kept in Sarpadia.** +> **Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo reveals; every precedent is kept in Urborg.** The deliberately goofy names are not decorative aliases. They encode which parts of the system are allowed to exercise agency, which parts must remain neutral infrastructure, and which sentences should sound architecturally wrong. The naming layer therefore acts as a lightweight responsibility and dependency lint. The architecture also resembles a newsroom for a non-coincidental reason: both systems must keep source observation, commissioning, authorship, standards review, production, fact-checking, publication judgement, integration, correction, archival memory, and presentation distinct. The central newsroom rule is load-bearing here: -> **Nissa sends the photograph directly. Narset sends only the assignment brief. Momir must never receive reality through Narset's caption.** +> **Nissa sends the photograph directly. Aurelia sends only the assignment brief. Momir must never receive reality through Aurelia's caption.** -The newsroom analogy is documented as an explanatory aid in §5.5 and Appendix E. The actual enforcement remains contractual: direct evidence publication, a narrow `GrowthIntent`, deterministic request resolution, immutable provenance, and tests that reject diagnostic or structural hints in Narset's channel. +The newsroom analogy is documented as an explanatory aid in §5.5 and Appendix E. The actual enforcement remains contractual: direct evidence publication, a narrow `GrowthIntent`, deterministic request resolution, immutable provenance, and tests that reject diagnostic or structural hints in Aurelia's channel. -A uniform **Scaffold Withdrawal Pattern** governs how the architecture learns under initially noisy, variable, or sparse conditions. Tolaria first establishes causal ground truth under an Academy profile with bitwise-exact replay, Narset first learns on repeated host trajectories, and Momir first learns near a viable Sarpadian reference population. Each scaffold then passes through controlled relaxation and an independent withdrawal gate. Withdrawal removes the scaffold as an ordinary production dependency while retaining it as a reference, calibration, regression, or escalation capability. Exact replay is therefore Tolaria's metrology laboratory—not a requirement that every future field execution remain bitwise identical. +A uniform **Scaffold Withdrawal Pattern** governs how the architecture learns under initially noisy, variable, or sparse conditions. Tolaria first establishes causal ground truth under an Academy profile with bitwise-exact replay, Aurelia first learns on repeated host trajectories, and Momir first learns near a viable Urborg reference population. Each scaffold then passes through controlled relaxation and an independent withdrawal gate. Withdrawal removes the scaffold as an ordinary production dependency while retaining it as a reference, calibration, regression, or escalation capability. Exact replay is therefore Tolaria's metrology laboratory—not a requirement that every future field execution remain bitwise identical. ## 2. Problem Statement @@ -215,10 +215,10 @@ is wrong. This design **replaces the reward function with measured counterfactuals**: paired branches from one snapshot over identical futures cancel ordinary-training variance, so the difference between branches *is* the intervention effect. That converts credit assignment into supervised -learning — Momir becomes ranking over measured pools, Narset becomes +learning — Momir becomes ranking over measured pools, Aurelia becomes per-step supervised classification against counterfactual labels, and -Augustin becomes explicit adjudication rules. The genuinely irreducible RL -shrinks to Tamiyo's allocation and Narset's timing. The counterfactual +Isperia becomes explicit adjudication rules. The genuinely irreducible RL +shrinks to Ugin's allocation and Aurelia's timing. The counterfactual apparatus is therefore not overhead wrapped around a policy learner; **it is the machine that manufactures the supervision signal RL could not extract**, and the programme's cost model is honestly read as the price of @@ -280,17 +280,17 @@ The first defensible claim is narrower: The architecture is successful at the first stage when it demonstrates that: -1. Tolaria trains the live Kasmina host reproducibly, passes one Academy-exact causal reference gate, and uses equivalent semantics for replay and counterfactual branches; +1. Tolaria trains the live Wrenn host reproducibly, passes one Academy-exact causal reference gate, and uses equivalent semantics for replay and counterfactual branches; 2. Momir candidate pools contain useful canonical growth at a materially higher rate than random search and at lower online cost than comparable iterative construction; -3. Elesh and Tezzeret transform raw designs into executable artefacts without silent structural or semantic drift; -4. Urabrask detects runtime defects, measures trajectories and certifies evidence with an acceptable accuracy–cost trade-off; -5. Augustin selects useful candidates with low regret, reliable no-op behaviour, stable policy and no source bias; +3. Elesh and Urabrask transform raw designs into executable artefacts without silent structural or semantic drift; +4. Jin-Gitaxias detects runtime defects, measures trajectories and certifies evidence with an acceptable accuracy–cost trade-off; +5. Isperia selects useful candidates with low regret, reliable no-op behaviour, stable policy and no source bias; 6. generated birth plus bounded maturation improves adaptation speed without unacceptable integration shock or harmful-intervention rate; -7. Narset learns reliable local lifecycle behaviour inside fixed strategic envelopes; -8. Emrakul safely reclaims obsolete committed capacity in accordance with Augustin tenancy decisions; -9. Sarpadia retrieval or lineage conditioning improves future design quality while preserving failures, blinding and split integrity; -10. Tamiyo allocates scarce developmental resources more effectively than uniform or heuristic allocation once multiple regions exist; -11. Oona reconstructs every case and surfaces constitutional smells without entering the control path; +7. Aurelia learns reliable local lifecycle behaviour inside fixed strategic envelopes; +8. Emrakul safely reclaims obsolete committed capacity in accordance with Isperia tenancy decisions; +9. Urborg retrieval or lineage conditioning improves future design quality while preserving failures, blinding and split integrity; +10. Ugin allocates scarce developmental resources more effectively than uniform or heuristic allocation once multiple regions exist; +11. Tamiyo reconstructs every case and surfaces constitutional smells without entering the control path; 12. performance transfers from repeated acquisition trajectories to held-out host seeds and controlled task variations; 13. the namespec remains semantically stable enough that code review and incident discussion use it as a reliable responsibility shorthand; 14. Field Tolaria achieves acceptable ranking and accept/no-op agreement against Academy with calibrated uncertainty and escalation; @@ -304,7 +304,7 @@ A negative generative result remains scientifically useful if the architecture c ## 29. Final Design Statement -> **Counterfactual Generative Morphogenesis is a hierarchical, lifecycle-driven neural adaptation architecture in which Tolaria trains the host; Nissa publishes the host's diagnostic evidence directly; Tamiyo allocates strategic developmental resources; Narset commissions and manages local work without prescribing its answer; Leyline and Kasmina resolve the legal assignment contract; Sarpadia may provide temporary ancestral precedent; Momir designs candidate growth; Elesh forces it into canonical legality; Tezzeret compiles it without changing meaning; Urabrask tests it in matched possible futures; Augustin publishes it only when the certified evidence beats doing nothing; Kasmina embodies it reversibly; Emrakul removes it when it no longer earns continued tenancy; Sarpadia preserves every accepted, rejected, failed and withdrawn lineage; and Oona reveals the complete account.** +> **Counterfactual Generative Morphogenesis is a hierarchical, lifecycle-driven neural adaptation architecture in which Tolaria trains the host; Nissa publishes the host's diagnostic evidence directly; Ugin allocates strategic developmental resources; Aurelia commissions and manages local work without prescribing its answer; Leyline and Wrenn resolve the legal assignment contract; Urborg may provide temporary ancestral precedent; Momir designs candidate growth; Elesh forces it into canonical legality; Urabrask compiles it without changing meaning; Jin-Gitaxias tests it in matched possible futures; Isperia publishes it only when the certified evidence beats doing nothing; Wrenn embodies it reversibly; Emrakul removes it when it no longer earns continued tenancy; Urborg preserves every accepted, rejected, failed and withdrawn lineage; and Tamiyo reveals the complete account.** The governing engineering principle is: @@ -312,7 +312,7 @@ The governing engineering principle is: The governing evidence principle is: -> **Nissa sends the photograph. Narset sends the assignment. Momir writes the answer.** +> **Nissa sends the photograph. Aurelia sends the assignment. Momir writes the answer.** The governing curriculum principle is: diff --git a/docs/design/02-constitution.md b/docs/design/02-constitution.md index ef3b70b..72768c4 100644 --- a/docs/design/02-constitution.md +++ b/docs/design/02-constitution.md @@ -1,26 +1,26 @@ [← HLD index](00-INDEX.md) - + ## 5. Locked Naming Constitution ### 5.1 Why the names are deliberately goofy The subsystem names are deliberately non-obvious to an outsider. This is useful for five reasons. -First, the names provide **cognitive compression**. “Urabrask tests; Augustin judges” is easier to retain and repeat than a long explanation of the distinction between evidence production and policy adjudication. +First, the names provide **cognitive compression**. “Jin-Gitaxias tests; Isperia judges” is easier to retain and repeat than a long explanation of the distinction between evidence production and policy adjudication. Second, the names create a **sentence test**. A sentence that sounds wrong in the project's narrative grammar often describes a real responsibility leak: - “Tolaria rejected the candidate” sounds wrong because a training substrate should not judge. -- “Augustin ran the CUDA probe” sounds wrong because a judge should not gather its own evidence. +- “Isperia ran the CUDA probe” sounds wrong because a judge should not gather its own evidence. - “Momir admitted its design” sounds wrong because a designer should not approve its own work. - “Nissa said `should_grow=True`” sounds wrong because observation should not conceal policy. -- “Narset told Momir to use attention” sounds wrong because an assignments editor should not pre-write the answer. -- “Sarpadia deployed the module” sounds wrong because history should not mutate the present. -- “Oona changed alpha” sounds wrong because a witness should not steer the process. +- “Aurelia told Momir to use attention” sounds wrong because an assignments editor should not pre-write the answer. +- “Urborg deployed the module” sounds wrong because history should not mutate the present. +- “Tamiyo changed alpha” sounds wrong because a witness should not steer the process. -Third, the names create a **neutral review vocabulary**. Engineers can say “this makes Elesh too political,” “Narset has added an editorial angle,” or “Tolaria has acquired opinions” without making the discussion personal. The metaphor points at the boundary violation rather than the author. +Third, the names create a **neutral review vocabulary**. Engineers can say “this makes Elesh too political,” “Aurelia has added an editorial angle,” or “Tolaria has acquired opinions” without making the discussion personal. The metaphor points at the boundary violation rather than the author. Fourth, the names define a small **architectural grammar**. People and entities exercise agency; infrastructure supplies contexts. The project can reason in verbs and prepositions rather than memorising an arbitrary package map. @@ -40,17 +40,17 @@ Places, systems, and phenomena represent infrastructure. They are the contexts * | Agent | Narrative verb | Architectural authority | Must not become | |---|---|---|---| -| **Tamiyo** | Plans | Strategic allocation, regional permissions, long-horizon budgets and risk | A local action selector | -| **Narset** | Commissions and acts | Tactical intervention timing, insertion-region choice, operational constraints, and pre-commit lifecycle control | A co-designer or source of unallocated authority | +| **Ugin** | Plans | Strategic allocation, regional permissions, long-horizon budgets and risk | A local action selector | +| **Aurelia** | Commissions and acts | Tactical intervention timing, insertion-region choice, operational constraints, and pre-commit lifecycle control | A co-designer or source of unallocated authority | | **Nissa** | Observes and reports | Typed host diagnostics, direct evidence publication, and provenance | A hidden controller or editorial intermediary | | **Momir** | Designs | Candidate topology, parameters, mutation and recombination | The approver of its own work | | **Elesh** | Conforms | Structural legality, canonicalisation and semantic identity | A utility predictor or task judge | -| **Tezzeret** | Compiles | Lowering and executable realisation | A semantic graph designer | -| **Urabrask** | Tests | Dynamic QA, regression, runtime conformance and evidence certification | The admission judge | -| **Augustin** | Judges | Admission, no-op comparison, policy utility and continued-tenancy rulings | A test runner or compiler | -| **Kasmina** | Embodies | Host topology, slots, maturation, blending and physical lifecycle | A candidate selector or blueprint catalogue | +| **Urabrask** | Compiles | Lowering and executable realisation | A semantic graph designer | +| **Jin-Gitaxias** | Tests | Dynamic QA, regression, runtime conformance and evidence certification | The admission judge | +| **Isperia** | Judges | Admission, no-op comparison, policy utility and continued-tenancy rulings | A test runner or compiler | +| **Wrenn** | Embodies | Host topology, slots, maturation, blending and physical lifecycle | A candidate selector or blueprint catalogue | | **Emrakul** | Destroys | Safe post-commit sedation, decay, consolidation and lysis | A constructor or newborn judge | -| **Oona** | Reveals | Flight recording, projections, operator surfaces and audit | A control-plane backchannel | +| **Tamiyo** | Reveals | Flight recording, projections, operator surfaces and audit | A control-plane backchannel | #### Infrastructure names @@ -58,49 +58,69 @@ Places, systems, and phenomena represent infrastructure. They are the contexts * |---|---|---|---| | **Leyline** | *under/through Leyline* | Contracts, schemas, grammar profiles, versions, invariants and policy record formats | Case-specific decisions or subsystem policy | | **Tolaria** | *trained/executed/tested in Tolaria* | Host training, data and optimiser execution, devices, snapshots, replay, branching and rollback | Preferences, utility weights or verdicts | -| **Sarpadia** | *recorded in/retrieved from Sarpadia* | History, lineage, bootstrap ancestry, counterfactual outcomes, retrieval and datasets | Live-host mutation or self-approval | +| **Urborg** | *recorded in/retrieved from Urborg* | History, lineage, bootstrap ancestry, counterfactual outcomes, retrieval and datasets | Live-host mutation or self-approval | Infrastructure can be highly active software. “Infrastructure” means it provides a neutral capability rather than exercising a preference about what ought to happen. +#### The synthesis core and the governance cage + +The names carry a second, deliberate layer: faction. Four agents form the **Phyrexian industrial synthesis core** — a single compleation assembly line running inside the architecture: + +- **Momir** (Simic genesis) designs the raw specimen in the bio-lab. +- **Elesh** (the Machine Orthodoxy) forces it into canonical, unified, structurally legal form. +- **Urabrask** (the Quiet Furnace) manufactures it into an executable artifact. He is the factory foreman: he may optimise the production line — kernel fusion, memory layout, device-specific lowering, cheaper compilation paths — but he cannot change the blueprint. If he changes semantic meaning, he has violated the Orthodoxy. +- **Jin-Gitaxias** (the Progress Engine) stress-tests the manufacture with ruthless, iterative empirical experimentation and certifies what the artifact actually does. + +Bio-foundry → standardisation → manufacturing → quality control: these four are one industrial organism. The remaining authorities are **the governance cage** that contains it: + +- **Ugin** plans long-horizon resource allocation from a distance. +- **Aurelia** commissions local tactical assignments within Ugin's envelope. +- **Isperia** judges whether the certified evidence justifies admission or lysis. +- **Nissa** observes and publishes direct evidence. +- **Wrenn** is the symbiotic host who physically embodies the growth and manages its lifecycle. +- **Tamiyo** reveals the complete account without steering it. + +Emrakul is claimed by neither side: post-commit destruction acts only under the cage's maintenance warrants. This framing is a **warning system**, not decoration. An authority violation reads as faction contamination — the factory issuing a verdict, the judge running the presses. “Jin-Gitaxias issued the admission token” is audibly a Phyrexian hand on a governance lever before it is ever a diff to review. The tension between the synthesis core and the cage is the central narrative of the architecture. + ### 5.3 The canonical sentence The architecture should remain intelligible as a sentence: -> **Nissa observes and reports. Tamiyo plans. Narset commissions and acts. Momir designs. Elesh conforms. Tezzeret compiles. Urabrask tests the compiled result in Tolaria. Augustin judges the resulting evidence under Leyline. Kasmina embodies the admitted growth. Emrakul destroys what no longer earns continued tenancy. Sarpadia retains every precedent. Oona reveals the account.** +> **Under Leyline, Ugin plans, Aurelia commissions and acts, Nissa observes, Momir designs, Elesh conforms, Urabrask compiles, Jin-Gitaxias tests in Tolaria, Isperia judges, Wrenn embodies, Emrakul destroys, and Tamiyo reveals; every precedent is kept in Urborg.** -This sentence is a compact authority map. +This sentence is a compact authority map, and it must remain intelligible as the architecture's creation myth. ### 5.4 The sentence test The following sentences are healthy: ```text -Nissa published the same TelemetryEnvelope to Narset and Momir. -Narset issued a GrowthIntent for Region A under Tamiyo's envelope. -Leyline resolved the legal GrowthRequest from the intent and Kasmina region contract. -Momir used compatible ancestors retrieved from Sarpadia during the bootstrap curriculum. -Urabrask requested a deterministic trial in Tolaria. +Nissa published the same TelemetryEnvelope to Aurelia and Momir. +Aurelia issued a GrowthIntent for Region A under Ugin's envelope. +Leyline resolved the legal GrowthRequest from the intent and Wrenn's region contract. +Momir used compatible ancestors retrieved from Urborg during the bootstrap curriculum. +Jin-Gitaxias requested a deterministic trial in Tolaria. Tolaria returned branch measurements. -Augustin selected no-op from the certified evidence. -Kasmina rejected a lifecycle command whose Augustin warrant was invalid. -Oona displayed the rejection without altering the run. +Isperia selected no-op from the certified evidence. +Wrenn rejected a lifecycle command whose Isperia warrant was invalid. +Tamiyo displayed the rejection without altering the run. ``` The following sentences should trigger review: ```text -Narset forwarded a captioned telemetry summary to Momir. -Narset requested an attention-like topology. +Aurelia forwarded a captioned telemetry summary to Momir. +Aurelia requested an attention-like topology. Nissa recommended a wide bottleneck. Tolaria rejected the candidate. -Urabrask issued the admission token. -Augustin reran the branch with a more favourable batch. +Jin-Gitaxias issued the admission token. +Isperia reran the branch with a more favourable batch. Momir filtered out designs that scored poorly in the current live trial. Elesh used future task reward to reject a legal graph. -Tezzeret inserted a new semantic node during optimisation. -Sarpadia installed the nearest historical candidate. -Oona changed the learning rate directly. -Leyline imported Narset to decide a default action. +Urabrask inserted a new semantic node during optimisation. +Urborg installed the nearest historical candidate. +Tamiyo changed the learning rate directly. +Leyline imported Aurelia to decide a default action. ``` The sentence test is not a proof, but it is an intentionally cheap architecture lint. @@ -114,23 +134,23 @@ The sentence test is not a proof, but it is an intentionally cheap architecture > In this architecture: > > - Nissa is the reporting, photography, and data desk: it publishes what was observed. -> - Tamiyo is the editor-in-chief or managing editor: it allocates desks, time, and strategic resources. -> - Narset is the assignments editor: it decides whether there is a story, which beat owns it, what scope and deadline apply, and what resources may be spent. +> - Ugin is the editor-in-chief or managing editor: it allocates desks, time, and strategic resources. +> - Aurelia is the assignments editor: it decides whether there is a story, which beat owns it, what scope and deadline apply, and what resources may be spent. > - Momir is the writer or investigative journalist: it determines the substantive answer from the evidence and commission. > - Elesh is the copy and standards desk: it enforces structural, typed, and house-form conformity without deciding whether the story is valuable. -> - Tezzeret is production: it turns canonical copy into an executable edition without changing meaning. -> - Urabrask is fact-checking and QA: it establishes what the finished artefact actually does. -> - Augustin is the publishing editor: it decides whether the evidence justifies running, returning, deferring, or spiking the story. -> - Kasmina integrates accepted material into the live edition. +> - Urabrask is production, layout, and manufacturing: the factory that prints the edition without changing meaning. +> - Jin-Gitaxias is fact-checking and QA: cold, empirical, perfectionist; it establishes what the finished artefact actually does. +> - Isperia is the publishing editor: it decides whether the evidence justifies running, returning, deferring, or spiking the story. +> - Wrenn is the live-edition integrator: the symbiote who hosts the accepted story in the running edition. > - Emrakul handles correction, withdrawal, and retirement after publication. -> - Sarpadia is the morgue and archive, including corrections, failed investigations, and abandoned drafts. -> - Oona is presentation: front page, broadcast desk, dashboards, and public account. +> - Urborg is the morgue and archive, including corrections, failed investigations, and abandoned drafts. +> - Tamiyo is presentation: front page, broadcast desk, dashboards, and public account. > - Leyline is the stylebook, editorial constitution, and record format. > - Tolaria is the newsroom production environment, CMS, presses, and test editions. > -> The load-bearing rule is: **Narset does not send the photograph. Nissa sends the photograph directly to Momir. Narset sends only the assignment brief.** +> The load-bearing rule is: **Aurelia does not send the photograph. Nissa sends the photograph directly to Momir. Aurelia sends only the assignment brief. Momir must never receive reality through Aurelia's caption.** > -> The code-review question is therefore: **does this field belong in an assignment brief, or does it impose an editorial angle?** Scope, region, resource class, deadline, maturity mode, and assurance class are assignment fields. A deficit diagnosis, topology preference, ancestor choice, expected mechanism, or proposed solution is an editorial angle and is prohibited from Narset's channel. +> The code-review question is therefore: **does this field belong in an assignment brief, or does it impose an editorial angle?** Scope, region, resource class, deadline, maturity mode, and assurance class are assignment fields. A deficit diagnosis, topology preference, ancestor choice, expected mechanism, or proposed solution is an editorial angle and is prohibited from Aurelia's channel. > > Appendix E develops the analogy, its smell tests, and its limits. The metaphor is never the enforcement mechanism; Leyline contracts and authority tests are. @@ -138,53 +158,57 @@ The sentence test is not a proof, but it is an intentionally cheap architecture The naming grammar implies two dependency rules: -1. Agents may consume neutral services from Leyline, Tolaria, and Sarpadia through typed interfaces. +1. Agents may consume neutral services from Leyline, Tolaria, and Urborg through typed interfaces. 2. Infrastructure must not import agent policy or encode agent-specific preferences. Examples: ```text -urabrask → tolaria protocol healthy -augustin → leyline contracts healthy -momir → sarpadia retrieval API healthy +jin_gitaxias → tolaria protocol healthy +isperia → leyline contracts healthy +momir → urborg retrieval API healthy nissa → leyline telemetry schema healthy -narset → leyline GrowthIntent schema healthy - -tolaria → augustin policy suspect -sarpadia → momir training code suspect -leyline → narset implementation prohibited -narset → momir graph grammar implementation prohibited -momir → narset hidden state prohibited +aurelia → leyline GrowthIntent schema healthy + +tolaria → isperia policy suspect +urborg → momir training code suspect +leyline → aurelia implementation prohibited +aurelia → momir graph grammar implementation prohibited +momir → aurelia hidden state prohibited +urabrask → elesh canonicalisation internals prohibited +tamiyo ← any training-critical code path prohibited ``` -Tolaria may execute a Kasmina host through a neutral host-runtime protocol. Sarpadia may store Momir records as opaque contract values. Neither requires ownership of the corresponding agent's policy. +Tolaria may execute a Wrenn host through a neutral host-runtime protocol. Urborg may store Momir records as opaque contract values. Neither requires ownership of the corresponding agent's policy. ### 5.7 Change control -Namespec 1.0 is considered locked for this design: +Namespec 2.0 is considered locked for this design (ADR-0008, superseding Namespec 1.0 in its entirety; no legacy aliases): ```text Leyline Tolaria -Sarpadia -Tamiyo -Narset +Urborg +Ugin +Aurelia Nissa Momir Elesh -Tezzeret Urabrask -Augustin -Kasmina +Jin-Gitaxias +Isperia +Wrenn Emrakul -Oona +Tamiyo ``` Changing a codename or moving an authority between names requires an architecture decision record because it changes the project's shared responsibility grammar, package paths, telemetry names, tests, and operational language. +**Reading historical records.** Two names appear in both namespecs with different referents: *Urabrask* (1.0: QA and testing → 2.0: compilation) and *Tamiyo* (1.0: strategic planning → 2.0: witness and revelation). Documents whose content predates ADR-0008 — the archived v4.1 monolith, `docs/concept/reviews/`, the bodies of ADR-0001..0007, and product decision records through PDR-0019 — use Namespec 1.0 names where they name domains at all, and are read through the concordance table in ADR-0008. Those records are never rewritten; corrections create new records (INV-36). + --- - + ## 18. Safety, Correctness and Constitutional Invariants The following are blocking invariants. @@ -195,38 +219,38 @@ The following are blocking invariants. 4. **Mainline–branch parity:** live and counterfactual host steps use the same execution semantics unless the difference is explicitly measured. 5. **Academy exact replay:** identical snapshot plus identical future data produces bitwise-identical traces under Tolaria's Academy-exact determinism contract; non-exact profiles carry measured uncertainty rather than pretending to satisfy this invariant. 6. **Common future:** paired branches receive identical future minibatches and equivalent random streams. -7. **Direct evidence publication:** Nissa publishes one canonical observation identity independently to Narset and Momir; Narset is not the designer's telemetry intermediary. +7. **Direct evidence publication:** Nissa publishes one canonical observation identity independently to Aurelia and Momir; Aurelia is not the designer's telemetry intermediary. 8. **Observation binding:** `TelemetryEnvelope`, `GrowthIntent`, `GrowthRequest`, Momir proposals and Tolaria trials reconcile to the same observation, host state, region and snapshot. 9. **Assignment-brief boundary:** `GrowthIntent` contains scope and operational constraints only; diagnosis, topology, ancestry and mechanism hints are schema-invalid. 10. **Deterministic request resolution:** `GrowthRequest` is reproducible from recorded intent, envelope, region contract and grammar profile and can only narrow authority. 11. **No covert request channel:** equivalent intents resolve to one canonical request; irrelevant serialisation, aliases, candidate count and field ordering cannot steer Momir. -12. **No hidden-state coupling:** Momir cannot access Narset recurrent state or implementation-specific features. -13. **Bootstrap provenance:** ancestry context is explicit, versioned and independently supplied from Sarpadia; null ancestry is supported. +12. **No hidden-state coupling:** Momir cannot access Aurelia recurrent state or implementation-specific features. +13. **Bootstrap provenance:** ancestry context is explicit, versioned and independently supplied from Urborg; null ancestry is supported. 14. **Scaffold-versus-control distinction:** removal of ancestry from Momir does not remove reference candidates from blinded evaluation controls. 15. **No-op availability:** every admission and continued-tenancy case includes a measured no-intervention alternative. -16. **No-op convention:** Augustin assigns no-op policy utility exactly zero. -17. **Dual provider blindness:** neither Urabrask nor Augustin accesses candidate source during QA interpretation or adjudication. -18. **Evidence–judgement separation:** Urabrask cannot issue admission or maintenance warrants; Augustin cannot execute or alter tests. +16. **No-op convention:** Isperia assigns no-op policy utility exactly zero. +17. **Dual provider blindness:** neither Jin-Gitaxias nor Isperia accesses candidate source during QA interpretation or adjudication. +18. **Evidence–judgement separation:** Jin-Gitaxias cannot issue admission or maintenance warrants; Isperia cannot execute or alter tests. 19. **Raw-to-canonical traceability:** every canonical growth links to the exact raw proposal and Elesh report. -20. **Canonical semantic identity:** every artefact, QA report, Augustin decision and Kasmina embodiment references the same canonical semantic hash. -21. **Compiler semantic preservation:** every Tezzeret artefact passes Urabrask runtime conformance against the canonical reference. +20. **Canonical semantic identity:** every artefact, QA report, Isperia decision and Wrenn embodiment references the same canonical semantic hash. +21. **Compiler semantic preservation:** every Urabrask artefact passes Jin-Gitaxias runtime conformance against the canonical reference. 22. **No branch transplant:** branch-matured growth is deployed only by branch adoption or exact replay. 23. **Budget enforcement:** every constructor, compiler, test plan, branch and maturation phase declares budget and reports spend. 24. **Typed compatibility:** incompatible schema, grammar, insertion, device, telemetry, QA or policy versions fail closed. 25. **Reversible influence:** every non-merged growth can be brought to zero influence without an uncontrolled discontinuity. -26. **Augustin admission warrant:** Kasmina cannot raise a newborn growth above zero influence without a valid warrant. -27. **Augustin maintenance warrant:** ordinary post-commit decay or lysis requires a valid maintenance decision. +26. **Isperia admission warrant:** Wrenn cannot raise a newborn growth above zero influence without a valid warrant. +27. **Isperia maintenance warrant:** ordinary post-commit decay or lysis requires a valid maintenance decision. 28. **Containment distinction:** emergency safety reduction is recorded as containment, not disguised as economic judgement. -29. **Authority enforcement:** Narset cannot manage post-commit structure; Emrakul cannot manage unborn structure; Tamiyo cannot issue local transitions. +29. **Authority enforcement:** Aurelia cannot manage post-commit structure; Emrakul cannot manage unborn structure; Ugin cannot issue local transitions. 30. **Grace-period protection:** contribution-based removal cannot fire before declared blend and holding windows complete. 31. **Complete negative retention:** structural rejects, compilation failures, QA failures, adjudication rejects, no-op decisions and abstentions are stored. 32. **Grouped statistics:** branches from one base trajectory never cross splits or inflate independent sample counts. 33. **Selection–retention consistency:** shared cost terms use shared weights unless a structural difference is documented; admission and retention thresholds are deliberately asymmetric — the admit threshold sits strictly above the retain threshold by a versioned hysteresis band sized against measured execution noise. (ADR-0005) 34. **Telemetry purity:** Nissa observation cannot perturb host training state. -35. **Oona isolation:** disconnecting Oona cannot alter training outcomes. -36. **Sarpadia append-only history:** corrections create new records rather than rewriting causal history. +35. **Tamiyo isolation:** disconnecting Tamiyo cannot alter training outcomes. +36. **Urborg append-only history:** corrections create new records rather than rewriting causal history. 37. **Blinding by construction:** source fields are absent from QA and adjudication views rather than merely ignored. -38. **Failure visibility:** invariant breaches fail loudly and are visible through Oona; no silent fallback fabricates valid-looking state. +38. **Failure visibility:** invariant breaches fail loudly and are visible through Tamiyo; no silent fallback fabricates valid-looking state. 39. **Declared scaffold state:** every curriculum, QA and confirmatory run records its execution, host-distribution and design-prior regimes. 40. **Independent withdrawal gates:** one scaffold cannot advance because a different scaffold passed its gate. 41. **One-axis confirmatory transition:** withdrawing multiple scaffolds at once requires a declared interaction experiment and completed single-axis controls. @@ -237,7 +261,7 @@ The following are blocking invariants. --- - + ## Appendix B — One-Line Namespec Invariants **Scaffolds:** constrain acquisition, relax under measurement, withdraw independently, and remain available as references. @@ -252,16 +276,16 @@ TOLARIA Is where the host is trained and where possible futures are executed. Must not prefer one future. -SARPADIA +URBORG Is where precedents, failures, reference ancestry and lineages are kept. May supply temporary ancestry and ordinary retrieval. Must not act on the live host. -TAMIYO +UGIN Plans long-horizon developmental authority. Must not micromanage local actions. -NARSET +AURELIA Commissions and acts locally inside granted authority. May specify scope and operational class. Must not caption evidence, choose ancestry, or prescribe phenotype. @@ -274,29 +298,29 @@ Must not hide decisions or structural recommendations inside observations. MOMIR Designs possibilities from evidence, constraints and optional precedent. May produce bad ideas. -Must not receive Narset's hidden interpretation or approve its own work. +Must not receive Aurelia's hidden interpretation or approve its own work. ELESH Makes designs structurally legal and canonical. May reject malformed structure. Must not judge task utility. -TEZZERET +URABRASK Compiles canonical designs into executable artefacts. May optimise implementation. Must not change meaning. -URABRASK +JIN-GITAXIAS Tests artefacts and certifies evidence. May report defects and uncertainty. Must not issue a verdict. -AUGUSTIN +ISPERIA Judges certified evidence under declared policy. May choose no-op. Must not gather or alter evidence, or trade tail risk against measured benefit. -KASMINA +WRENN Embodies legal, warranted growth and declares insertion-region contracts. Must not own a preferred blueprint catalogue or decide whether growth deserves to exist. @@ -304,7 +328,7 @@ EMRAKUL Safely removes committed structure that has outlived its value. Must not design or judge newborn growth. -OONA +TAMIYO Reveals the system's account. Must not steer the system through the act of observing it. ``` diff --git a/docs/design/03-principles.md b/docs/design/03-principles.md index 38fe5a3..7096702 100644 --- a/docs/design/03-principles.md +++ b/docs/design/03-principles.md @@ -6,26 +6,26 @@ ### 6.1 Strategy and tactics are separate -Tamiyo determines where developmental resources may be spent over a slow horizon. Narset decides what local action to take at a particular state. Tamiyo cannot choose a candidate or issue an alpha tick. Narset cannot create capacity that is absent from Tamiyo's envelope. +Ugin determines where developmental resources may be spent over a slow horizon. Aurelia decides what local action to take at a particular state. Ugin cannot choose a candidate or issue an alpha tick. Aurelia cannot create capacity that is absent from Ugin's envelope. -> **Tamiyo establishes what may be spent and where. Narset decides what to do with it now.** +> **Ugin establishes what may be spent and where. Aurelia decides what to do with it now.** ### 6.2 Observation, commissioning, and interpretation are separate -Nissa produces one canonical, typed, versioned `TelemetryEnvelope` for a particular host observation and publishes it independently to every authorised consumer. Narset and Momir receive the same evidence by identity, not a copy interpreted or rewritten by another agent. +Nissa produces one canonical, typed, versioned `TelemetryEnvelope` for a particular host observation and publishes it independently to every authorised consumer. Aurelia and Momir receive the same evidence by identity, not a copy interpreted or rewritten by another agent. -Narset may interpret the observation to decide whether and where to commission work. Momir independently interprets the same observation to decide what phenotype to design. Nissa must not smuggle a lifecycle decision or structural recommendation into telemetry. +Aurelia may interpret the observation to decide whether and where to commission work. Momir independently interprets the same observation to decide what phenotype to design. Nissa must not smuggle a lifecycle decision or structural recommendation into telemetry. -> **Nissa sends the photograph directly. Narset sends only the assignment brief.** +> **Nissa sends the photograph directly. Aurelia sends only the assignment brief.** -“Raw telemetry” means uncaptioned by Narset, not untyped or unconstrained. Nissa may perform neutral normalisation, alignment, missing-value masking, stable feature construction, and provenance attachment. It may not emit `deficit_type`, `recommended_structure`, or equivalent prescriptions. +“Raw telemetry” means uncaptioned by Aurelia, not untyped or unconstrained. Nissa may perform neutral normalisation, alignment, missing-value masking, stable feature construction, and provenance attachment. It may not emit `deficit_type`, `recommended_structure`, or equivalent prescriptions. ### 6.3 Developmental intent and phenotype are separate -Narset authors a narrow `GrowthIntent`. It may specify: +Aurelia authors a narrow `GrowthIntent`. It may specify: - the insertion region; -- a resource or urgency class inside Tamiyo's envelope; +- a resource or urgency class inside Ugin's envelope; - one-shot versus nursery maturation; - assurance class; - and tactical deadline or escalation context. @@ -39,41 +39,41 @@ It must not specify: - rank, width, gate, operator, or connectivity hints; - or any field whose practical purpose is to steer Momir toward a structural answer. -Leyline and Kasmina deterministically resolve the selected region and active capabilities into a `GrowthRequest`. This attaches the tensor contract, grammar profile, exact derived budgets, and compatibility information as system constraints rather than Narset-authored design hints. +Leyline and Wrenn deterministically resolve the selected region and active capabilities into a `GrowthRequest`. This attaches the tensor contract, grammar profile, exact derived budgets, and compatibility information as system constraints rather than Aurelia-authored design hints. -> **Narset constrains the feasible solution space. Momir chooses a point within it.** +> **Aurelia constrains the feasible solution space. Momir chooses a point within it.** -Coarse enumerated classes are preferred over arbitrary continuous request values. This reduces the opportunity for jointly trained Narset and Momir to invent a covert design code through harmless-looking budget, latency, ordering, or candidate-count fields. +Coarse enumerated classes are preferred over arbitrary continuous request values. This reduces the opportunity for jointly trained Aurelia and Momir to invent a covert design code through harmless-looking budget, latency, ordering, or candidate-count fields. ### 6.4 Design, conformance, and compilation are separate -Momir creates possibilities. Elesh establishes structural legality and canonical semantic identity. Tezzeret realises that identity efficiently for a target runtime. +Momir creates possibilities. Elesh establishes structural legality and canonical semantic identity. Urabrask realises that identity efficiently for a target runtime. -> **Momir establishes possibility. Elesh establishes identity. Tezzeret establishes execution.** +> **Momir establishes possibility. Elesh establishes identity. Urabrask establishes execution.** ### 6.5 QA and judgement are separate -Urabrask establishes the facts that can only be learned by executing a candidate: runtime conformance, numerical safety, gradients, cost, trajectory behaviour, shock, regression and uncertainty. +Jin-Gitaxias establishes the facts that can only be learned by executing a candidate: runtime conformance, numerical safety, gradients, cost, trajectory behaviour, shock, regression and uncertainty. -Augustin applies policy to those facts: eligibility, the tail-risk veto, budget, expected risk, utility weights, no-op anchoring, admission margins and continued tenancy. +Isperia applies policy to those facts: eligibility, the tail-risk veto, budget, expected risk, utility weights, no-op anchoring, admission margins and continued tenancy. -> **Leyline contains the law. Urabrask establishes the evidence. Augustin applies the law.** +> **Leyline contains the law. Jin-Gitaxias establishes the evidence. Isperia applies the law.** -Urabrask may report that a mandatory QA test failed. It must not decide which otherwise eligible candidate deserves admission. Augustin may reject every candidate. It must not alter the test plan, future data or measured result. +Jin-Gitaxias may report that a mandatory QA test failed. It must not decide which otherwise eligible candidate deserves admission. Isperia may reject every candidate. It must not alter the test plan, future data or measured result. -### 6.6 Kasmina and Tolaria are different substrates +### 6.6 Wrenn and Tolaria are different substrates -Kasmina is the **model physiology**: the host network, insertion regions, reversible slots, gradients, alpha and lifecycle state. +Wrenn is the **model physiology**: the host network, insertion regions, reversible slots, gradients, alpha and lifecycle state. Tolaria is the **training and execution reality**: data movement, optimiser stepping, devices, precision, distributed scheduling, checkpointing, snapshots, replay, branch execution and rollback. -> **Kasmina is what is trained. Tolaria is where and how it is trained.** +> **Wrenn is what is trained. Tolaria is where and how it is trained.** There must be one Tolaria execution path for the live host and counterfactual branches wherever practical. A special branch-only trainer would undermine paired comparisons. ### 6.7 Static validity and dynamic validity are separate -Elesh answers whether a design is legal in principle. Urabrask answers whether Tezzeret's artefact behaves correctly in practice. Static verification does not replace execution, and passing runtime tests does not excuse a structurally illegal graph. +Elesh answers whether a design is legal in principle. Jin-Gitaxias answers whether Urabrask's artefact behaves correctly in practice. Static verification does not replace execution, and passing runtime tests does not excuse a structurally illegal graph. ### 6.8 Every intervention is reversible @@ -89,7 +89,7 @@ Counterfactual branches begin from the same complete snapshot, receive the same ### 6.11 The tested object and embodied semantics are identical -The canonical semantic identity tested by Urabrask, selected by Augustin, and embodied by Kasmina must be the same. Compilation may change execution strategy but not meaning. +The canonical semantic identity tested by Jin-Gitaxias, selected by Isperia, and embodied by Wrenn must be the same. Compilation may change execution strategy but not meaning. ### 6.12 Costs are contractual @@ -97,7 +97,7 @@ Every constructor, compiler, QA plan, training run, branch, maturation process a ### 6.13 Experience includes failures -Every candidate, structural rejection, compilation failure, QA defect, adjudication rejection, no-op victory, stale integration, lifecycle reversal and lysis event is recorded in Sarpadia. +Every candidate, structural rejection, compilation failure, QA defect, adjudication rejection, no-op victory, stale integration, lifecycle reversal and lysis event is recorded in Urborg. ### 6.14 Generalisation follows acquisition @@ -105,15 +105,15 @@ Exact repetition and controlled one-axis variation precede composed variation, u ### 6.15 Observability is read-only -Oona may subscribe to, persist, aggregate and present events. It cannot create actions, mutate budgets or become a hidden dependency of the training path. +Tamiyo may subscribe to, persist, aggregate and present events. It cannot create actions, mutate budgets or become a hidden dependency of the training path. ### 6.16 Infrastructure remains neutral -Leyline defines records; Tolaria executes requests; Sarpadia retains history. None decides which candidate should live. +Leyline defines records; Tolaria executes requests; Urborg retains history. None decides which candidate should live. ### 6.17 Bootstrap ancestry is temporary; controls endure -Conventional Norm, Attention, Convolution, low-rank, and gated-residual seeds may be retained in Sarpadia as a **reference population** for Momir's initial curriculum. They are demonstrations, ancestral material, and counterfactual controls—not Kasmina-owned production blueprints and not Narset actions. +Conventional Norm, Attention, Convolution, low-rank, and gated-residual seeds may be retained in Urborg as a **reference population** for Momir's initial curriculum. They are demonstrations, ancestral material, and counterfactual controls—not Wrenn-owned production blueprints and not Aurelia actions. The ancestry context is progressively withdrawn from Momir's proposal input. The same reference seeds may remain permanently in the experimental harness as blinded competitors. Removing a scaffold is not the same as deleting a baseline. @@ -123,9 +123,9 @@ Momir receives three conceptually distinct inputs: 1. diagnostic evidence directly from Nissa; 2. operational constraints through the resolved `GrowthRequest`; -3. optional historical ancestry or retrieval context from Sarpadia. +3. optional historical ancestry or retrieval context from Urborg. -These channels preserve separate provenance and may be independently ablated. Narset's hidden state, commentary, and diagnostic interpretation are never Momir inputs. This permits failures to be attributed to observation, commissioning, design, conformance, compilation, QA, judgement, embodiment, or maintenance rather than to an inseparable controller-generator pair. +These channels preserve separate provenance and may be independently ablated. Aurelia's hidden state, commentary, and diagnostic interpretation are never Momir inputs. This permits failures to be attributed to observation, commissioning, design, conformance, compilation, QA, judgement, embodiment, or maintenance rather than to an inseparable controller-generator pair. ### 6.19 Scaffolds are explicit, independently gated and retained as references @@ -186,7 +186,7 @@ clean measurement substrate is proven to carry real topological signal — so the design pushes from a fixed blueprint menu to generated growth (Momir), from shaped reward to measured counterfactuals (the branching engine), and from single-region caution toward strategic allocation -(Tamiyo). The counterfactual engine is simultaneously both: armour against +(Ugin). The counterfactual engine is simultaneously both: armour against Goodhartable shaping, and the forward mechanism that makes generation adjudicable at all. @@ -213,38 +213,38 @@ Two standing obligations for future contributors: | A confirmatory run changes two scaffold axes without single-axis controls | The result is causally uninterpretable | | Leyline calculates a case-specific decision | Constitution became case management | | Leyline's resolver infers a deficit or topology | Contract assembly became design policy | -| Sarpadia deploys a retrieved candidate | History mutated the present | -| Tamiyo chooses blend ticks or candidate IDs | Strategy collapsed into micromanagement | -| Narset exceeds its envelope | Tactics escaped strategic governance | -| Narset forwards a modified telemetry object to Momir | Assignments desk rewrote the source material | -| `GrowthIntent` contains `preferred_topology_family` | Narset became a co-designer | +| Urborg deploys a retrieved candidate | History mutated the present | +| Ugin chooses blend ticks or candidate IDs | Strategy collapsed into micromanagement | +| Aurelia exceeds its envelope | Tactics escaped strategic governance | +| Aurelia forwards a modified telemetry object to Momir | Assignments desk rewrote the source material | +| `GrowthIntent` contains `preferred_topology_family` | Aurelia became a co-designer | | `GrowthIntent` contains `deficit_type=RANK_COLLAPSE` | A diagnosis was smuggled into the assignment brief | -| Narset selects a bootstrap ancestor | The legacy blueprint selector reappeared | -| Fine-grained budget values predict topology choice | Narset and Momir formed a covert design channel | +| Aurelia selects a bootstrap ancestor | The legacy blueprint selector reappeared | +| Fine-grained budget values predict topology choice | Aurelia and Momir formed a covert design channel | | Nissa emits `should_grow` | Policy hidden in telemetry | | Nissa emits `recommended_structure` | Source reporting became editorial prescription | -| Momir reads Narset hidden state | Design is coupled to controller implementation rather than contract | +| Momir reads Aurelia hidden state | Design is coupled to controller implementation rather than contract | | Momir approves or filters its live pool by admission outcome | Designer judging itself | | Momir fails when ancestry context is null | Bootstrap scaffold became a production dependency | | Elesh consumes future utility | Structural conformance contaminated by policy | | Elesh changes non-equivalent semantics | Canonicaliser became designer | -| Tezzeret invents topology | Compiler became Momir | -| Urabrask returns `ADMIT` or issues a warrant | QA became judge | -| Urabrask changes mandatory tests after seeing results | QA tailored the examination | -| Augustin calls Tolaria or runs a tensor probe | Judge gathered its own evidence | -| Augustin changes future data or requests a favourable branch | Evidentiary tampering | -| Augustin knows candidate source | Adjudication contamination | -| Kasmina owns a preferred stock blueprint library | Host physiology regained a design ontology | -| Kasmina calculates utility | Host physiology acquired opinions | -| Kasmina raises alpha without an Augustin warrant | Constitutional admission bypass | +| Urabrask invents topology | Compiler became Momir | +| Jin-Gitaxias returns `ADMIT` or issues a warrant | QA became judge | +| Jin-Gitaxias changes mandatory tests after seeing results | QA tailored the examination | +| Isperia calls Tolaria or runs a tensor probe | Judge gathered its own evidence | +| Isperia changes future data or requests a favourable branch | Evidentiary tampering | +| Isperia knows candidate source | Adjudication contamination | +| Wrenn owns a preferred stock blueprint library | Host physiology regained a design ontology | +| Wrenn calculates utility | Host physiology acquired opinions | +| Wrenn raises alpha without an Isperia warrant | Constitutional admission bypass | | Emrakul judges an unborn candidate | Maintenance leaked into admission | | Emrakul generates a replacement genotype | Destruction became design | -| Oona changes optimiser, alpha or budget | Witness became control plane | -| Sarpadia stores only accepted growth | Survivorship bias | +| Tamiyo changes optimiser, alpha or budget | Witness became control plane | +| Urborg stores only accepted growth | Survivorship bias | | Reference seeds disappear from evaluation when withdrawn from Momir | Scaffold removal was confused with baseline deletion | | Branch-trained growth is copied into a divergent live host | Co-adaptation transplant error | | Candidate hash changes between QA, judgement and embodiment | Test–judge–deploy identity failure | -| Narset retains authority after commitment | Development never handed off | -| Urabrask and Augustin share one mutable policy object | Evidence and judgement are not independent | +| Aurelia retains authority after commitment | Development never handed off | +| Jin-Gitaxias and Isperia share one mutable policy object | Evidence and judgement are not independent | | Candidate source is “hidden” only by convention | Blinding is not enforced by construction | | A package name no longer supports its canonical sentence | Namespec responsibility drift | diff --git a/docs/design/04-architecture.md b/docs/design/04-architecture.md index ad0df9e..49b6aeb 100644 --- a/docs/design/04-architecture.md +++ b/docs/design/04-architecture.md @@ -8,39 +8,39 @@ The system operates inside nested learning and execution loops: - Tolaria continuously runs ordinary host training against the task and data stream; - Nissa publishes canonical observations at defined decision points; -- Narset acts at local developmental decision points; -- Tamiyo updates strategic envelopes at a slower cadence; -- Momir, Elesh and Tezzeret construct candidate artefacts; -- Urabrask defines QA plans and requests candidate trials in Tolaria; -- Augustin adjudicates the certified reports; -- Kasmina embodies admitted growth; +- Aurelia acts at local developmental decision points; +- Ugin updates strategic envelopes at a slower cadence; +- Momir, Elesh and Urabrask construct candidate artefacts; +- Jin-Gitaxias defines QA plans and requests candidate trials in Tolaria; +- Isperia adjudicates the certified reports; +- Wrenn embodies admitted growth; - Emrakul manages committed structure under continued-tenancy warrants; -- Sarpadia accumulates the complete causal history; -- and Oona exposes the account without becoming part of the control path. +- Urborg accumulates the complete causal history; +- and Tamiyo exposes the account without becoming part of the control path. | Plane | Subsystems | Purpose | |---|---|---| | **Constitutional infrastructure** | Leyline | Defines contracts, grammar profiles, compatibility, policy records and invariants | | **Training and execution infrastructure** | Tolaria | Trains the live host and executes deterministic ordinary, replay and branch worlds | -| **Historical infrastructure** | Sarpadia | Retains lineages, reference ancestry, outcomes, failures and split-safe datasets | -| **Strategic agency** | Tamiyo | Allocates regional resources, permissions and risk over long horizons | -| **Tactical commissioning** | Narset | Decides whether and where to commission growth and manages pre-commit actions | +| **Historical infrastructure** | Urborg | Retains lineages, reference ancestry, outcomes, failures and split-safe datasets | +| **Strategic agency** | Ugin | Allocates regional resources, permissions and risk over long horizons | +| **Tactical commissioning** | Aurelia | Decides whether and where to commission growth and manages pre-commit actions | | **Observation** | Nissa | Publishes what the host is doing without prescribing what should be built | -| **Synthesis** | Momir, Elesh, Tezzeret | Designs, canonicalises and compiles growth | -| **Assurance and adjudication** | Urabrask, Augustin | Establishes empirical evidence, then judges it independently | -| **Embodiment and maintenance** | Kasmina, Emrakul | Introduces growth safely and removes obsolete committed structure | -| **Witness** | Oona | Exposes an auditable account without steering it | +| **Synthesis** | Momir, Elesh, Urabrask | Designs, canonicalises and compiles growth | +| **Assurance and adjudication** | Jin-Gitaxias, Isperia | Establishes empirical evidence, then judges it independently | +| **Embodiment and maintenance** | Wrenn, Emrakul | Introduces growth safely and removes obsolete committed structure | +| **Witness** | Tamiyo | Exposes an auditable account without steering it | ### 7.1 Logical architecture ```mermaid flowchart TD DATA[Task and data stream] --> TOL[Tolaria: training and execution substrate] - TOL --> K[Kasmina: host and reversible growth physiology] + TOL --> K[Wrenn: host and reversible growth physiology] K --> N[Nissa: canonical ablated diagnostic observation] - N -->|permitted coarse summary| TAM[Tamiyo: strategic controller] - N -->|same TelemetryEnvelope| NAR[Narset: tactical assignments controller] + N -->|permitted coarse summary| TAM[Ugin: strategic controller] + N -->|same TelemetryEnvelope| NAR[Aurelia: tactical assignments controller] N -->|same TelemetryEnvelope| MOM[Momir: candidate designer] TAM -->|StrategicEnvelope| NAR @@ -50,14 +50,14 @@ flowchart TD LEY[Leyline: contracts and GrammarProfile] --> RES RES -->|Resolved GrowthRequest| MOM - SAR[Sarpadia: history, lineage and bootstrap ancestry] -->|optional precedents / BootstrapAncestryContext| MOM + SAR[Urborg: history, lineage and bootstrap ancestry] -->|optional precedents / BootstrapAncestryContext| MOM MOM -->|RawGrowthGraph| EL[Elesh: verify and canonicalise] - EL -->|CanonicalGrowthSpec| TEZ[Tezzeret: compile] - TEZ -->|ExecutableGrowthArtifact| URA[Urabrask: QA] + EL -->|CanonicalGrowthSpec| TEZ[Urabrask: compile] + TEZ -->|ExecutableGrowthArtifact| URA[Jin-Gitaxias: QA] URA -->|TestPlan| TOL TOL -->|BranchResults and runtime evidence| URA - URA -->|QualityReport| AUG[Augustin: judge] + URA -->|QualityReport| AUG[Isperia: judge] TAM -->|strategic limits| AUG RES -->|request context| AUG @@ -81,7 +81,7 @@ flowchart TD K --> SAR EM --> SAR - N --> O[Oona: witness and operator surface] + N --> O[Tamiyo: witness and operator surface] TAM --> O NAR --> O MOM --> O @@ -95,7 +95,7 @@ flowchart TD EM --> O ``` -The two Nissa arrows to Narset and Momir are independent publications of the same observation identity. Narset is not a telemetry proxy. The request resolver is deterministic contract assembly, not a fifteenth agent: it applies Leyline compatibility rules to Narset's intent, Tamiyo's envelope, and Kasmina's region declaration. +The two Nissa arrows to Aurelia and Momir are independent publications of the same observation identity. Aurelia is not a telemetry proxy. The request resolver is deterministic contract assembly, not a fifteenth agent: it applies Leyline compatibility rules to Aurelia's intent, Ugin's envelope, and Wrenn's region declaration. ### 7.2 Ordinary training loop @@ -106,7 +106,7 @@ load or create TrainingRunSpec ↓ materialise data stream and device topology ↓ -execute Kasmina host forward pass +execute Wrenn host forward pass ↓ compute task loss ↓ @@ -121,7 +121,7 @@ invoke permitted strategic/tactical decision points checkpoint, snapshot or continue ``` -Tamiyo and Narset govern developmental actions around this loop. They do not perform SGD. Kasmina supplies the model and its growth mechanics. Tolaria performs the execution. +Ugin and Aurelia govern developmental actions around this loop. They do not perform SGD. Wrenn supplies the model and its growth mechanics. Tolaria performs the execution. ### 7.3 Observation and commissioning loop @@ -129,12 +129,12 @@ Tamiyo and Narset govern developmental actions around this loop. They do not per Nissa observes Snapshot S at decision point T ↓ Nissa publishes TelemetryEnvelope O - ├──→ Narset: should work be commissioned, where, and under what class? + ├──→ Aurelia: should work be commissioned, where, and under what class? └──→ Momir: what structure would address this observed state? -Tamiyo supplies StrategicEnvelope E -Narset emits GrowthIntent I referencing O and E -Kasmina supplies RegionContract R +Ugin supplies StrategicEnvelope E +Aurelia emits GrowthIntent I referencing O and E +Wrenn supplies RegionContract R Leyline supplies compatible GrammarProfile G ↓ pure request resolution: (O, E, I, R, G) → GrowthRequest Q @@ -147,18 +147,18 @@ Momir rejects a call where the observation, snapshot, region, or compatibility i ### 7.4 Candidate assurance and adjudication loop ```text -Tezzeret artefact +Urabrask artefact ↓ -Urabrask builds a blinded TestPlan +Jin-Gitaxias builds a blinded TestPlan ↓ Tolaria restores a common Snapshot and executes: candidate branches + controls + mandatory no-op ↓ -Urabrask verifies runtime conformance and certifies measurements +Jin-Gitaxias verifies runtime conformance and certifies measurements ↓ QualityReport ↓ -Augustin applies eligibility, then the tail-risk veto, then utility policy +Isperia applies eligibility, then the tail-risk veto, then utility policy ↓ ADMIT one / REJECT / DEFER / REQUIRE_RETEST / NO_OP ``` @@ -166,9 +166,9 @@ ADMIT one / REJECT / DEFER / REQUIRE_RETEST / NO_OP ### 7.5 Control hierarchy ```text -Tamiyo +Ugin └── establishes StrategicEnvelope - └── Narset chooses local actions + └── Aurelia chooses local actions ├── WAIT ├── COMMISSION_GROWTH → GrowthIntent ├── BEGIN_MATURATION @@ -180,7 +180,7 @@ Tamiyo └── COMMIT After COMMIT: - Narset relinquishes ordinary ownership + Aurelia relinquishes ordinary ownership └── Emrakul manages physical maintenance ├── REQUEST_REVIEW ├── HOLD @@ -189,9 +189,9 @@ After COMMIT: └── LYSE ``` -Urabrask and Augustin are independent of this command hierarchy. Urabrask certifies evidence. Augustin issues admission and maintenance warrants. Neither performs Kasmina state transitions. Tolaria is beneath the hierarchy as neutral execution infrastructure. +Jin-Gitaxias and Isperia are independent of this command hierarchy. Jin-Gitaxias certifies evidence. Isperia issues admission and maintenance warrants. Neither performs Wrenn state transitions. Tolaria is beneath the hierarchy as neutral execution infrastructure. -Emrakul's post-commit actions execute Augustin `MaintenanceDecision` verdicts; the vocabularies map one-to-one: `RETAIN` → `HOLD` (no physical transition), `RETEST` → `REQUEST_REVIEW` (schedule maintenance QA), and `SEDATE`/`DECAY`/`LYSE` execute directly under the maintenance warrant. Verdicts are Augustin records; actions are Emrakul executions of them. +Emrakul's post-commit actions execute Isperia `MaintenanceDecision` verdicts; the vocabularies map one-to-one: `RETAIN` → `HOLD` (no physical transition), `RETEST` → `REQUEST_REVIEW` (schedule maintenance QA), and `SEDATE`/`DECAY`/`LYSE` execute directly under the maintenance warrant. Verdicts are Isperia records; actions are Emrakul executions of them. ### 7.6 The newsroom authority model @@ -199,21 +199,21 @@ The newsroom analogy provides an explanatory overlay, not a second architecture: ```text Nissa reports source material -Tamiyo funds the desk -Narset commissions the assignment +Ugin funds the desk +Aurelia commissions the assignment Momir authors the candidate Elesh applies standards and canonical form -Tezzeret produces the executable edition -Urabrask fact-checks and proof-tests it in Tolaria -Augustin publishes, returns, defers, or spikes it -Kasmina integrates it into the live edition +Urabrask produces the executable edition +Jin-Gitaxias fact-checks and proof-tests it in Tolaria +Isperia publishes, returns, defers, or spikes it +Wrenn integrates it into the live edition Emrakul corrects, withdraws, or retires it later -Sarpadia preserves the complete archive -Oona presents the account +Urborg preserves the complete archive +Tamiyo presents the account Leyline supplies the editorial constitution ``` -The analogy is useful because it makes an authority leak audible. “The assignments editor rewrote the source notes before the writer saw them” is the same defect as Narset mediating Nissa's evidence. Appendix E provides the full mapping and review prompts. +The analogy is useful because it makes an authority leak audible. “The assignments editor rewrote the source notes before the writer saw them” is the same defect as Aurelia mediating Nissa's evidence. Appendix E provides the full mapping and review prompts. ## 8. Subsystem Map @@ -221,18 +221,18 @@ The analogy is useful because it makes an authority leak audible. “The assignm |---|---|---|---| | **Leyline** | Typed contracts, schema versions, grammar profiles, request resolution, compatibility, policy record formats and ordering invariants | Versioned records, validators, warrants, rule vocabularies and resolved constraints | Case-specific policy, diagnosis or execution | | **Tolaria** | Host training and deterministic execution: data, optimisers, devices, precision, distributed scheduling, snapshots, replay, branches and rollback | `TrainingRunState`, `Snapshot`, `BranchResult`, execution manifests | Utility weights, candidate preference or verdicts | -| **Sarpadia** | Append-only history, lineage, bootstrap reference population, outcomes, retrieval and split-safe datasets | `GrowthRecord`, `BootstrapAncestryContext`, retrieval sets, lineage graphs and blinded views | Live-host mutation or self-approval | -| **Tamiyo** | Strategic budgets, regional priorities, exploration quotas, cooldowns and long-horizon risk | `StrategicEnvelope` | Local action timing or candidate choice | -| **Narset** | Tactical commissioning and pre-commit lifecycle actions | `GrowthIntent`, `LifecycleCommand`, review requests and escalations | Diagnostic captions, ancestor choice, topology hints, unallocated budget or structural generation | +| **Urborg** | Append-only history, lineage, bootstrap reference population, outcomes, retrieval and split-safe datasets | `GrowthRecord`, `BootstrapAncestryContext`, retrieval sets, lineage graphs and blinded views | Live-host mutation or self-approval | +| **Ugin** | Strategic budgets, regional priorities, exploration quotas, cooldowns and long-horizon risk | `StrategicEnvelope` | Local action timing or candidate choice | +| **Aurelia** | Tactical commissioning and pre-commit lifecycle actions | `GrowthIntent`, `LifecycleCommand`, review requests and escalations | Diagnostic captions, ancestor choice, topology hints, unallocated budget or structural generation | | **Nissa** | Ablated host telemetry, direct evidence publication and diagnostic provenance | `TelemetryEnvelope` | `should_grow`, structural recommendations, reward or verdicts | | **Momir** | Raw candidate topology, parameters, mutation and recombination | `RawGrowthGraph` | Intervention timing, structural approval, testing or admission | | **Elesh** | Static verification, canonicalisation, semantic hashing and structural legality | `CanonicalGrowthSpec`, structural reports | Runtime QA, task utility or lifecycle policy | -| **Tezzeret** | Lowering, kernel selection, fusion, memory planning and compilation | `ExecutableGrowthArtifact`, compilation manifest | Semantic topology changes, QA or admission | -| **Urabrask** | Dynamic QA, runtime conformance, regression, branch measurement and evidence certification | `TestPlan`, `QualityReport` | Admission, no-op policy or lifecycle commands | -| **Augustin** | Provider-blind admission and continued-tenancy adjudication | `AdmissionDecision`, `MaintenanceDecision`, warrants | Test execution, compilation or host mutation | -| **Kasmina** | Host model, insertion-region declarations, slots, gradient routing, maturation, blending and physical lifecycle | `RegionContract`, embodied state and lifecycle events | Stock blueprint ontology or whether a growth deserves admission | +| **Urabrask** | Lowering, kernel selection, fusion, memory planning and compilation | `ExecutableGrowthArtifact`, compilation manifest | Semantic topology changes, QA or admission | +| **Jin-Gitaxias** | Dynamic QA, runtime conformance, regression, branch measurement and evidence certification | `TestPlan`, `QualityReport` | Admission, no-op policy or lifecycle commands | +| **Isperia** | Provider-blind admission and continued-tenancy adjudication | `AdmissionDecision`, `MaintenanceDecision`, warrants | Test execution, compilation or host mutation | +| **Wrenn** | Host model, insertion-region declarations, slots, gradient routing, maturation, blending and physical lifecycle | `RegionContract`, embodied state and lifecycle events | Stock blueprint ontology or whether a growth deserves admission | | **Emrakul** | Safe post-commit sedation, decay, consolidation and lysis | Maintenance requests and warranted lifecycle commands | Candidate construction or judgement | -| **Oona** | Event projections, flight recorder, TUI/dashboard adapters, audit bundles and alerts | Operator views and audit records | Training control or source-of-truth schemas | +| **Tamiyo** | Event projections, flight recorder, TUI/dashboard adapters, audit bundles and alerts | Operator views and audit records | Training control or source-of-truth schemas | The deterministic request resolver is a Leyline application service operating over immutable `GrowthIntent`, `StrategicEnvelope`, `RegionContract`, and `GrammarProfile` records. It performs no diagnosis and has no learned policy. @@ -243,7 +243,7 @@ The deterministic request resolver is a Leyline application service operating ov ### 10.1 Ordinary host training in Tolaria -Tolaria materialises the `TrainingRunSpec`, constructs the data and device environment, and advances the Kasmina host through ordinary optimisation. +Tolaria materialises the `TrainingRunSpec`, constructs the data and device environment, and advances the Wrenn host through ordinary optimisation. It owns: @@ -257,11 +257,11 @@ It owns: - callback and decision-point scheduling; - and measured execution spend. -Tamiyo is not “the trainer” in this sense. It is a strategic controller around a host that Tolaria trains. +Ugin is not “the trainer” in this sense. It is a strategic controller around a host that Tolaria trains. ### 10.2 Strategic allocation -At a slow cadence, Tamiyo consumes coarse host health, regional histories, current capacity, recent interventions and strategic objectives. It emits a `StrategicEnvelope` specifying: +At a slow cadence, Ugin consumes coarse host health, regional histories, current capacity, recent interventions and strategic objectives. It emits a `StrategicEnvelope` specifying: - which regions may grow; - how much parameter and compute capacity each may consume; @@ -271,7 +271,7 @@ At a slow cadence, Tamiyo consumes coarse host health, regional histories, curre - permitted grammar profiles; - and cooldowns or embargoes. -Tamiyo may reserve capacity for anticipated future pressure, but it cannot select an immediate candidate, choose an ancestor, or issue a blend command. +Ugin may reserve capacity for anticipated future pressure, but it cannot select an immediate candidate, choose an ancestor, or issue a blend command. ### 10.3 Local observation and direct publication @@ -281,18 +281,18 @@ Nissa constructs one canonical `TelemetryEnvelope` bound to the current Tolaria ```text Nissa - ├── TelemetryEnvelope O ──→ Narset + ├── TelemetryEnvelope O ──→ Aurelia ├── TelemetryEnvelope O ──→ Momir - ├── permitted summary ───→ Tamiyo - ├── append-only record ───→ Sarpadia - └── event projection ───→ Oona + ├── permitted summary ───→ Ugin + ├── append-only record ───→ Urborg + └── event projection ───→ Tamiyo ``` -Nissa emits measurements and provenance, not conclusions. Narset is not permitted to produce a second “designer telemetry” object. +Nissa emits measurements and provenance, not conclusions. Aurelia is not permitted to produce a second “designer telemetry” object. ### 10.4 Tactical commission -Narset receives Nissa's telemetry, the active `StrategicEnvelope`, Kasmina local lifecycle state, prior Augustin decisions, and compact operational history. It chooses among legal local actions: +Aurelia receives Nissa's telemetry, the active `StrategicEnvelope`, Wrenn local lifecycle state, prior Isperia decisions, and compact operational history. It chooses among legal local actions: ```text WAIT @@ -305,10 +305,10 @@ CONTINUE_BLEND HOLD ABORT COMMIT -ESCALATE_TO_TAMIYO +ESCALATE_TO_UGIN ``` -A `COMMISSION_GROWTH` action creates a narrow `GrowthIntent`. Narset chooses whether intervention is warranted, which permitted insertion region owns the assignment, and what operational class applies. It does not select a seed family, ancestor, rank, width, operator, or diagnosis for Momir. +A `COMMISSION_GROWTH` action creates a narrow `GrowthIntent`. Aurelia chooses whether intervention is warranted, which permitted insertion region owns the assignment, and what operational class applies. It does not select a seed family, ancestor, rank, width, operator, or diagnosis for Momir. ### 10.5 Deterministic request resolution @@ -317,16 +317,16 @@ A pure resolver operating under Leyline combines: ```text GrowthIntent + StrategicEnvelope -+ Kasmina RegionContract ++ Wrenn RegionContract + active GrammarProfile = GrowthRequest ``` The resolver: -- validates the intent against Tamiyo's active authority; -- obtains the region's tensor contract from Kasmina; -- selects only a grammar profile already permitted by the envelope and supported by Elesh and Tezzeret; +- validates the intent against Ugin's active authority; +- obtains the region's tensor contract from Wrenn; +- selects only a grammar profile already permitted by the envelope and supported by Elesh and Urabrask; - derives exact bounded budgets from the requested resource class; - binds observation, host state, snapshot, region and schema identities; - canonicalises representation and field ordering; @@ -342,8 +342,8 @@ Momir receives independent inputs with preserved provenance: TelemetryEnvelope from Nissa GrowthRequest from deterministic resolution under Leyline ProposalBatchRequest from orchestration -BootstrapAncestryContext | null from Sarpadia during the bootstrap curriculum -ordinary retrieval context from Sarpadia where enabled +BootstrapAncestryContext | null from Urborg during the bootstrap curriculum +ordinary retrieval context from Urborg where enabled ``` Momir may design: @@ -357,7 +357,7 @@ Momir may design: Research controls such as stock Norm, Attention, Convolution, random, analytic, retrieval, online-optimised or human-designed candidates enter through the same downstream contracts and remain blinded during QA and judgement. -Momir never reads Narset hidden state or a Narset-authored diagnostic summary. Its output must remain valid when bootstrap ancestry is absent. +Momir never reads Aurelia hidden state or a Aurelia-authored diagnostic summary. Its output must remain valid when bootstrap ancestry is absent. ### 10.7 Structural conformance @@ -378,13 +378,13 @@ Elesh performs: - equivalence-class detection; - and semantic hashing. -A failed candidate receives a structured rejection report and is stored in Sarpadia. A successful candidate becomes a `CanonicalGrowthSpec`. +A failed candidate receives a structured rejection report and is stored in Urborg. A successful candidate becomes a `CanonicalGrowthSpec`. Elesh may simplify only where semantic equivalence is established. Predicted usefulness is not structural equivalence. ### 10.8 Compilation -Tezzeret lowers each canonical specification for the target Tolaria runtime. +Urabrask lowers each canonical specification for the target Tolaria runtime. It may perform: @@ -402,7 +402,7 @@ Compilation success does not imply runtime validity or admission. ### 10.9 QA planning and execution -Urabrask creates a blinded `TestPlan` covering: +Jin-Gitaxias creates a blinded `TestPlan` covering: - canonical-to-artefact runtime equivalence; - finite outputs and gradients; @@ -418,13 +418,13 @@ Urabrask creates a blinded `TestPlan` covering: Tolaria restores the complete snapshot and executes the requested branches over identical future data. -Urabrask certifies the returned evidence into a `QualityReport`. It may mark hard defects, incomplete evidence and uncertainty. It does not issue a verdict. +Jin-Gitaxias certifies the returned evidence into a `QualityReport`. It may mark hard defects, incomplete evidence and uncertainty. It does not issue a verdict. ### 10.10 Independent adjudication -Augustin receives a blinded `QualityReport`, the resolved request, the active `StrategicEnvelope`, and the applicable policy version. +Isperia receives a blinded `QualityReport`, the resolved request, the active `StrategicEnvelope`, and the applicable policy version. Adjudication is lexicographic (ADR-0004): three ordered stages, no later stage reopening an earlier one. @@ -437,9 +437,9 @@ Adjudication is lexicographic (ADR-0004): three ordered stages, no later stage r - evidence complete enough for the assurance class; - and measured spend inside declared budget. -**Stage 2 — tail-risk veto:** per candidate, Augustin estimates the tail of the intervention-outcome distribution from certified evidence and vetoes any candidate whose estimate breaches the threshold. The veto is not tradeable against measured benefit (INV-45); the assurance class owns the operating point, priced against current snapshot distance. No-op never faces the veto. +**Stage 2 — tail-risk veto:** per candidate, Isperia estimates the tail of the intervention-outcome distribution from certified evidence and vetoes any candidate whose estimate breaches the threshold. The veto is not tradeable against measured benefit (INV-45); the assurance class owns the operating point, priced against current snapshot distance. No-op never faces the veto. -**Stage 3 — utility competition:** Augustin computes policy utility, expected-risk and uncertainty charges for the survivors relative to no-op. It may: +**Stage 3 — utility competition:** Isperia computes policy utility, expected-risk and uncertainty charges for the survivors relative to no-op. It may: ```text ADMIT @@ -449,15 +449,15 @@ DEFER REQUIRE_RETEST ``` -A growth is not entitled to publication merely because Narset commissioned it. +A growth is not entitled to publication merely because Aurelia commissioned it. ### 10.11 Germination and maturation -On admission, Narset issues a warranted command to Kasmina. +On admission, Aurelia issues a warranted command to Wrenn. -Kasmina: +Wrenn: -- verifies the Augustin warrant; +- verifies the Isperia warrant; - verifies the candidate semantic hash and artefact identity; - instantiates the growth at zero influence; - configures one-shot or nursery mode; @@ -469,17 +469,17 @@ Tolaria executes any maturation steps. Maturation spend is charged to the growth ### 10.12 Integration and commitment -Before blending, a nursery-matured growth is re-qualified against the current host state. If host drift has invalidated it, Narset aborts or requests fresh QA rather than integrating stale growth. +Before blending, a nursery-matured growth is re-qualified against the current host state. If host drift has invalidated it, Aurelia aborts or requests fresh QA rather than integrating stale growth. -Kasmina applies the authorised blend schedule. Narset may hold, continue, reverse, abort or commit within its pre-commit authority and the Augustin warrant. +Wrenn applies the authorised blend schedule. Aurelia may hold, continue, reverse, abort or commit within its pre-commit authority and the Isperia warrant. -At commitment, ordinary ownership transfers from Narset to Emrakul. +At commitment, ordinary ownership transfers from Aurelia to Emrakul. ### 10.13 Continued-tenancy review and maintenance Emrakul schedules periodic or event-driven maintenance review. -Urabrask requests counterfactual evidence in Tolaria, including separate no-growth or re-adaptation branches where required. Augustin issues a `MaintenanceDecision`: +Jin-Gitaxias requests counterfactual evidence in Tolaria, including separate no-growth or re-adaptation branches where required. Isperia issues a `MaintenanceDecision`: ```text RETAIN @@ -489,27 +489,27 @@ DECAY LYSE ``` -Emrakul executes the authorised safe physical transition through Kasmina. It cannot change the verdict or generate a replacement. +Emrakul executes the authorised safe physical transition through Wrenn. It cannot change the verdict or generate a replacement. ### 10.14 Memory and witness -Sarpadia stores: +Urborg stores: - direct Nissa observation identity; -- Tamiyo envelope; -- Narset intent; +- Ugin envelope; +- Aurelia intent; - resolved request; - proposal-batch metadata; - optional bootstrap ancestry; - raw candidates and lineages; - Elesh reports; -- Tezzeret manifests; +- Urabrask manifests; - Tolaria snapshots and branches; -- Urabrask plans and reports; -- Augustin decisions; +- Jin-Gitaxias plans and reports; +- Isperia decisions; - lifecycle traces; - spend and rent; - determinism manifests; - and terminal outcomes. -Oona presents the same causal chain to operators. It may show the newsroom view—source, assignment, draft, standards, production, fact check, publication decision, placement, correction and archive—but it remains read-only. +Tamiyo presents the same causal chain to operators. It may show the newsroom view—source, assignment, draft, standards, production, fact check, publication decision, placement, correction and archive—but it remains read-only. diff --git a/docs/design/05-leyline-contracts.md b/docs/design/05-leyline-contracts.md index a611ec5..0540fbc 100644 --- a/docs/design/05-leyline-contracts.md +++ b/docs/design/05-leyline-contracts.md @@ -8,7 +8,7 @@ Subsystem boundaries are enforced with typed, immutable or append-only records. ### 9.1 `StrategicEnvelope` -Issued by Tamiyo and consumed by Narset, the request resolver, Augustin, Kasmina and Emrakul. +Issued by Ugin and consumed by Aurelia, the request resolver, Isperia, Wrenn and Emrakul. ```text StrategicEnvelope @@ -39,11 +39,11 @@ StrategicEnvelope schema_version ``` -The envelope grants permission and constrains judgement. It does not instruct Narset to act or Augustin which candidate to select. +The envelope grants permission and constrains judgement. It does not instruct Aurelia to act or Isperia which candidate to select. ### 9.2 `TelemetryEnvelope` -Produced once by Nissa for a particular observation and published independently to Tamiyo, Narset, Momir, Sarpadia and Oona according to access policy. +Produced once by Nissa for a particular observation and published independently to Ugin, Aurelia, Momir, Urborg and Tamiyo according to access policy. ```text TelemetryEnvelope @@ -70,13 +70,13 @@ TelemetryEnvelope Any change in meaning, width, basis, normalisation or provenance creates a new schema version. Nissa may normalise and align measurements, but the record contains no `should_grow`, deficit diagnosis, topology suggestion, ancestor choice, or recommended mechanism. -The same `observation_id` must be referenced by Narset's intent, Momir's conditioning input, and the Tolaria snapshot later used for counterfactual evaluation. A mismatch fails closed. +The same `observation_id` must be referenced by Aurelia's intent, Momir's conditioning input, and the Tolaria snapshot later used for counterfactual evaluation. A mismatch fails closed. `observation_id` and `telemetry_id` are distinct on purpose: `observation_id` names the canonical observation identity that binds downstream records (INV-08); `telemetry_id` names this envelope record instance for storage and audit. Independent publications and permitted per-consumer projections of one observation share `observation_id` but carry distinct `telemetry_id`s. ### 9.3 `GrowthIntent` -Authored by Narset under an active `StrategicEnvelope`. This is the **assignment brief**, not the design brief. +Authored by Aurelia under an active `StrategicEnvelope`. This is the **assignment brief**, not the design brief. ```text GrowthIntent @@ -110,11 +110,11 @@ expected_internal_structure free_form_designer_message ``` -Narset does not copy, summarise, annotate or forward telemetry inside the intent. +Aurelia does not copy, summarise, annotate or forward telemetry inside the intent. ### 9.4 `GrowthRequest` -Resolved deterministically under Leyline from the `GrowthIntent`, active `StrategicEnvelope`, Kasmina `RegionContract`, and compatible `GrammarProfile`. Narset does not author the resolved fields. +Resolved deterministically under Leyline from the `GrowthIntent`, active `StrategicEnvelope`, Wrenn `RegionContract`, and compatible `GrammarProfile`. Aurelia does not author the resolved fields. ```text GrowthRequest @@ -165,7 +165,7 @@ Candidate count is not a design hint. Momir's candidate-generation function shou ### 9.6 `BootstrapAncestryContext` -An optional, temporary curriculum record assembled from Sarpadia by the curriculum harness. Narset never selects or transmits it. +An optional, temporary curriculum record assembled from Urborg by the curriculum harness. Aurelia never selects or transmits it. ```text BootstrapAncestryContext @@ -238,7 +238,7 @@ The canonical semantic hash identifies developmental meaning independently of co ### 9.9 `ExecutableGrowthArtifact` -Produced by Tezzeret. +Produced by Urabrask. ```text ExecutableGrowthArtifact @@ -257,7 +257,7 @@ ExecutableGrowthArtifact reproducibility_manifest ``` -The artefact is not trusted merely because compilation succeeded. Urabrask must dynamically verify it against the canonical specification. +The artefact is not trusted merely because compilation succeeded. Jin-Gitaxias must dynamically verify it against the canonical specification. ### 9.10 `TrainingRunSpec` @@ -300,8 +300,8 @@ Snapshot growth_slot_states lifecycle_state economy_state - narset_recurrent_state - tamiyo_state_reference + aurelia_recurrent_state + ugin_state_reference telemetry_history random_number_states dataloader_cursor @@ -318,7 +318,7 @@ A snapshot is complete only when it captures enough state to satisfy the Academy ### 9.12 `TestPlan` -Produced by Urabrask and consumed by Tolaria. +Produced by Jin-Gitaxias and consumed by Tolaria. ```text TestPlan @@ -345,7 +345,7 @@ TestPlan qa_policy_version ``` -Urabrask controls what evidence must be collected. It does not control the adjudication utility applied later. +Jin-Gitaxias controls what evidence must be collected. It does not control the adjudication utility applied later. ### 9.13 `BranchResult` @@ -385,7 +385,7 @@ Source provenance is held outside the blinded view and reattached only after QA ### 9.14 `QualityReport` -Produced by Urabrask and consumed by Augustin, Sarpadia, Narset and Emrakul. +Produced by Jin-Gitaxias and consumed by Isperia, Urborg, Aurelia and Emrakul. ```text QualityReport @@ -424,7 +424,7 @@ A `QualityReport` establishes facts and test status. It does not contain `ADMIT` ### 9.15 `AdmissionDecision` -Produced by Augustin. +Produced by Isperia. ```text AdmissionDecision @@ -447,11 +447,11 @@ AdmissionDecision adjudication_policy_version ``` -An admission warrant is required before Kasmina may raise a new growth above zero influence. +An admission warrant is required before Wrenn may raise a new growth above zero influence. ### 9.16 `MaintenanceDecision` -Produced by Augustin from a maintenance `QualityReport`. +Produced by Isperia from a maintenance `QualityReport`. ```text MaintenanceDecision @@ -471,12 +471,12 @@ Emrakul decides how to execute an authorised safe transition. It does not rewrit ### 9.17 `LifecycleCommand` -Issued by Narset before commitment or Emrakul after commitment. +Issued by Aurelia before commitment or Emrakul after commitment. ```text LifecycleCommand command_id - authority # NARSET or EMRAKUL + authority # AURELIA or EMRAKUL target_growth_id requested_transition admission_warrant | null @@ -487,11 +487,11 @@ LifecycleCommand reason ``` -Kasmina validates the command against authority, state, warrant, budget and transition rules. +Wrenn validates the command against authority, state, warrant, budget and transition rules. ### 9.18 `GrowthRecord` -Stored by Sarpadia. +Stored by Urborg. ```text GrowthRecord @@ -524,11 +524,11 @@ GrowthRecord split_membership ``` -The full candidate pool is stored, including stock-reference controls, structurally rejected candidates, scaffold-free de novo pools, and pools in which Augustin selects no-op. +The full candidate pool is stored, including stock-reference controls, structurally rejected candidates, scaffold-free de novo pools, and pools in which Isperia selects no-op. ### 9.19 `EventEnvelope` -Defined by Leyline and published by every subsystem for Oona. +Defined by Leyline and published by every subsystem for Tamiyo. ```text EventEnvelope @@ -544,7 +544,7 @@ EventEnvelope integrity_digest ``` -Oona consumes these events but does not define their source-of-truth semantics. +Tamiyo consumes these events but does not define their source-of-truth semantics. ### 9.20 `ScaffoldManifest` and `ScaffoldState` diff --git a/docs/design/06-growth-model.md b/docs/design/06-growth-model.md index 20adb3f..4765b88 100644 --- a/docs/design/06-growth-model.md +++ b/docs/design/06-growth-model.md @@ -42,7 +42,7 @@ Elesh canonicalises semantically equivalent graph forms into one identity. ### Level 3 — Generated typed graph -Momir emits a small directed acyclic graph over whitelisted operators. Elesh proves contract compliance and canonicalises it. Tezzeret compiles it. +Momir emits a small directed acyclic graph over whitelisted operators. Elesh proves contract compliance and canonicalises it. Urabrask compiles it. The grammar remains bounded by: @@ -61,14 +61,14 @@ Arbitrary code generation is not required. ### One-shot mode - Momir emits the complete final growth. -- Kasmina holds it frozen after admission. +- Wrenn holds it frozen after admission. - Only alpha and lifecycle state may change. - This is the cleanest test of generative construction as a final answer. ### Nursery mode - Momir emits structure, birth parameters, and a trainability mask. -- Kasmina grants bounded isolated maturation. +- Wrenn grants bounded isolated maturation. - Host and growth optimisation streams remain explicit and separately accounted. - The growth is re-qualified against the current host before blending. - Maturation spend is charged to the candidate. @@ -81,16 +81,16 @@ Three identities are distinct: 1. **Raw identity:** the exact graph Momir proposed. 2. **Canonical semantic identity:** the graph after Elesh’s semantics-preserving canonicalisation. -3. **Executable artefact identity:** Tezzeret’s device-specific implementation. +3. **Executable artefact identity:** Urabrask’s device-specific implementation. -Sarpadia stores all three. Urabrask tests canonical semantics through Tezzeret’s executable artefact in Tolaria. Augustin judges the resulting evidence. Kasmina embodies the same canonical semantic identity selected by Augustin. +Urborg stores all three. Jin-Gitaxias tests canonical semantics through Urabrask’s executable artefact in Tolaria. Isperia judges the resulting evidence. Wrenn embodies the same canonical semantic identity selected by Isperia. Two compiled artefacts may implement the same canonical growth. Two raw graphs may canonicalise to the same semantic identity. Candidate diversity is therefore measured primarily in canonical and functional space, not raw syntax or compiler artefact space. ### 11.4 Reference-seed bootstrap and scaffold withdrawal -Momir is not initially asked to invent useful neural machinery from an unrestricted grammar with no examples. The first curriculum supplies a small, versioned **reference population** of known mechanically viable microcells held in Sarpadia, such as: +Momir is not initially asked to invent useful neural machinery from an unrestricted grammar with no examples. The first curriculum supplies a small, versioned **reference population** of known mechanically viable microcells held in Urborg, such as: - normalisation-derived cells; - attention-derived cells; @@ -99,7 +99,7 @@ Momir is not initially asked to invent useful neural machinery from an unrestric - gated residual cells; - and synthetic known-repair cells. -These are represented as canonical graphs and outcome records, not permanent blueprint enums. Kasmina can embody them because it can embody any legal warranted growth, but it does not own them as an internal stock library. +These are represented as canonical graphs and outcome records, not permanent blueprint enums. Wrenn can embody them because it can embody any legal warranted growth, but it does not own them as an internal stock library. The reference population has three bootstrap roles: @@ -118,7 +118,7 @@ M4 ancestry-optional and explicitly de novo proposals M5 withdrawal of reference ancestry from Momir's production input ``` -At every stage, Urabrask tests the child, its parent, compatible reference seeds, retrieval and analytic controls where available, and mandatory no-op under identical Tolaria futures. Sarpadia retains the ordered neighbourhood, not only the winner: +At every stage, Jin-Gitaxias tests the child, its parent, compatible reference seeds, retrieval and analytic controls where available, and mandatory no-op under identical Tolaria futures. Urborg retains the ordered neighbourhood, not only the winner: ```text child A > parent > reference B > no-op > child C @@ -140,9 +140,9 @@ Momir may therefore learn three increasingly demanding margins: The scaffold is considered withdrawn when Momir is evaluated with `BootstrapAncestryContext = null`. Conventional reference seeds may remain permanently in sealed or routine experiments as blinded controls. This preserves the scientific question—whether Momir beats known alternatives—without making those alternatives an enduring production dependency. -Narset never chooses the ancestor. The curriculum harness assembles ancestry context from Sarpadia under a fixed manifest. Otherwise the old blueprint selector would simply reappear inside the tactical controller. +Aurelia never chooses the ancestor. The curriculum harness assembles ancestry context from Urborg under a fixed manifest. Otherwise the old blueprint selector would simply reappear inside the tactical controller. -The analogy to Narset's own curriculum is deliberate: both subsystems first learn a restricted causal language on repeated, interpretable examples, then face the broader CIFAR-scale distribution without the classroom scaffold. +The analogy to Aurelia's own curriculum is deliberate: both subsystems first learn a restricted causal language on repeated, interpretable examples, then face the broader CIFAR-scale distribution without the classroom scaffold. --- @@ -177,30 +177,30 @@ ACTIVE → DECAYING → DORMANT | State | Meaning | Ordinary authority | |---|---|---| -| **DORMANT** | Slot empty and available | Kasmina mechanics; Narset may request germination | -| **GERMINATED** | Augustin-admitted growth installed at zero influence | Narset | -| **MATURING** | Optional isolated optimisation executed in Tolaria | Narset within budget | -| **QUALIFYING** | Urabrask QA followed by Augustin adjudication or re-adjudication | Narset requests; Urabrask tests; Augustin judges | -| **BLENDING** | Alpha rises under a bounded schedule | Narset | -| **HOLDING** | Target alpha reached; grace and qualification window | Narset, constrained by current Augustin warrant | -| **ACTIVE** | Growth serves under local pre-commit lifecycle control | Narset | +| **DORMANT** | Slot empty and available | Wrenn mechanics; Aurelia may request germination | +| **GERMINATED** | Isperia-admitted growth installed at zero influence | Aurelia | +| **MATURING** | Optional isolated optimisation executed in Tolaria | Aurelia within budget | +| **QUALIFYING** | Jin-Gitaxias QA followed by Isperia adjudication or re-adjudication | Aurelia requests; Jin-Gitaxias tests; Isperia judges | +| **BLENDING** | Alpha rises under a bounded schedule | Aurelia | +| **HOLDING** | Target alpha reached; grace and qualification window | Aurelia, constrained by current Isperia warrant | +| **ACTIVE** | Growth serves under local pre-commit lifecycle control | Aurelia | | **COMMITTED** | Growth becomes maintained structure | Ownership transfers to Emrakul | | **SEDATED** | Influence reduced while dispensability or replacement is assessed | Emrakul under a maintenance warrant | -| **DECAYING** | Alpha ramps to zero before recycling | Emrakul, or Narset before commitment | -| **DORMANT** | Slot recycled; occupant-specific state reset | Kasmina | +| **DECAYING** | Alpha ramps to zero before recycling | Emrakul, or Aurelia before commitment | +| **DORMANT** | Slot recycled; occupant-specific state reset | Wrenn | ### 12.2 Transition authority -Kasmina is the sole executor of growth-state transitions and enforces these rules: +Wrenn is the sole executor of growth-state transitions and enforces these rules: -- Tamiyo never issues a lifecycle transition. -- Narset may issue only pre-commit transitions. +- Ugin never issues a lifecycle transition. +- Aurelia may issue only pre-commit transitions. - Emrakul may issue only post-commit maintenance transitions. -- Urabrask issues QA evidence, never lifecycle authority or admission tokens. -- Augustin issues admission and maintenance warrants, never physical transitions. +- Jin-Gitaxias issues QA evidence, never lifecycle authority or admission tokens. +- Isperia issues admission and maintenance warrants, never physical transitions. - Tolaria executes optimisation and tests, never lifecycle preferences. -- A transition that raises influence requires a valid Augustin warrant. -- A transition that removes influence for ordinary economic reasons requires the appropriate authority and, post-commit, an Augustin maintenance warrant. +- A transition that raises influence requires a valid Isperia warrant. +- A transition that removes influence for ordinary economic reasons requires the appropriate authority and, post-commit, an Isperia maintenance warrant. - Emergency containment may reduce influence without prior economic adjudication only when a declared safety invariant is breached; it must be logged as containment and reviewed. ### 12.3 Commitment handoff @@ -209,15 +209,15 @@ Commitment is an ownership boundary, not merely a label. Before commitment: -- Narset manages the growth as an intervention under evaluation. +- Aurelia manages the growth as an intervention under evaluation. After commitment: - Emrakul manages its physical maintenance as part of the host’s established structure; -- Augustin remains the authority for continued-tenancy judgements; -- Urabrask remains the authority for certified maintenance evidence. +- Isperia remains the authority for continued-tenancy judgements; +- Jin-Gitaxias remains the authority for certified maintenance evidence. -Narset may ask Emrakul to request review but may not directly lyse committed growth. Emrakul may identify replacement pressure but may not ask Momir for a specific replacement without a new Narset request under a valid Tamiyo envelope. +Aurelia may ask Emrakul to request review but may not directly lyse committed growth. Emrakul may identify replacement pressure but may not ask Momir for a specific replacement without a new Aurelia request under a valid Ugin envelope. ### 12.4 Grace-period protection @@ -230,18 +230,18 @@ A growth cannot be condemned merely because low early alpha yields low measured ### 12.5 QA and adjudication are not lifecycle states -Urabrask and Augustin can be invoked at several lifecycle points, but neither becomes the owner of the growth. +Jin-Gitaxias and Isperia can be invoked at several lifecycle points, but neither becomes the owner of the growth. ```text -Narset or Emrakul requests review +Aurelia or Emrakul requests review ↓ -Urabrask specifies and certifies tests +Jin-Gitaxias specifies and certifies tests ↓ -Augustin issues a verdict or warrant +Isperia issues a verdict or warrant ↓ -Narset or Emrakul requests a legal physical transition +Aurelia or Emrakul requests a legal physical transition ↓ -Kasmina executes it in Tolaria +Wrenn executes it in Tolaria ``` This prevents an evidence subsystem or judge from quietly becoming a lifecycle controller. diff --git a/docs/design/07-counterfactual-engine.md b/docs/design/07-counterfactual-engine.md index 28e56f6..3246df2 100644 --- a/docs/design/07-counterfactual-engine.md +++ b/docs/design/07-counterfactual-engine.md @@ -24,7 +24,7 @@ For each selected host state, the pool may include: During the bootstrap, reference seeds may appear both in Momir's ancestry context and as independent controls. After scaffold withdrawal they remain only as blinded controls unless an experiment explicitly restores ancestry. -Urabrask and Augustin receive blinded identifiers. Candidate source and ancestry are reattached only after QA and adjudication. +Jin-Gitaxias and Isperia receive blinded identifiers. Candidate source and ancestry are reattached only after QA and adjudication. ### 14.2 Data separation @@ -35,7 +35,7 @@ The target design separates four data roles: 3. **QA audit:** an independent partition used to verify the selected evidence and detect best-of-\(K\) overfit. 4. **Retention and report:** periodic maintenance and headline reporting, untouched by construction or admission. -Augustin consumes certified summaries and does not access raw batches. This protects the evidentiary boundary while keeping the decision reproducible. +Isperia consumes certified summaries and does not access raw batches. This protects the evidentiary boundary while keeping the decision reproducible. ### 14.3 Academy QA @@ -45,13 +45,13 @@ Academy QA is the high-assurance causal reference regime. It uses Tolaria's Acad - candidate construction comparisons; - field-QA surrogate calibration; - execution-noise measurement; -- Augustin threshold calibration; -- Narset imitation targets; -- Tamiyo allocation outcomes; +- Isperia threshold calibration; +- Aurelia imitation targets; +- Ugin allocation outcomes; - Emrakul maintenance cases; - disputed or low-margin Field decisions; - regression and divergence diagnosis; -- and Sarpadia dataset construction. +- and Urborg dataset construction. Its cost is measured as a product of snapshots, candidate families, candidates per family, horizons and rollout length. It is the system's metrology laboratory: narrow, expensive and trusted. Withdrawal from Academy as the default operating profile does not remove Academy as a reference capability. @@ -64,7 +64,7 @@ Field QA trades evidence quality against cost through a tiered process: 3. repeated or short statistical branches for close or high-cost cases; 4. Academy-exact QA when required by risk, uncertainty, calibration age or policy. -The field surrogate predicts measurements and uncertainty. It does not issue Augustin's verdict. Field calibration is judged not only by numerical prediction error but by: +The field surrogate predicts measurements and uncertainty. It does not issue Isperia's verdict. Field calibration is judged not only by numerical prediction error but by: - candidate-ranking agreement with Academy; - selection regret relative to Academy; @@ -75,7 +75,7 @@ The field surrogate predicts measurements and uncertainty. It does not issue Aug #### 14.4.1 Execution uncertainty and adjudication margins -Once Tolaria operates outside the Academy-exact regime, Augustin judges conservative evidence rather than point estimates that pretend execution is noiseless. A representative lower-confidence utility is: +Once Tolaria operates outside the Academy-exact regime, Isperia judges conservative evidence rather than point estimates that pretend execution is noiseless. A representative lower-confidence utility is: $$ U^{-}(c) = \widehat U(c) - \kappa\,\sigma_{\mathrm{exec}}(c), @@ -91,9 +91,9 @@ A numerically imperfect Field estimate may be operationally adequate when its ma The margin discipline above governs the **utility** stage. Before any utility comparison, every candidate faces the **tail-risk veto** (ADR-0004, -INV-45): Augustin estimates the tail of the intervention-outcome +INV-45): Isperia estimates the tail of the intervention-outcome distribution — the catastrophic case, not the expectation — from certified -Urabrask measurements (integration shock, instability, numerical events, +Jin-Gitaxias measurements (integration shock, instability, numerical events, trajectory behaviour), and removes from contention any candidate whose estimate breaches the veto threshold. No measured benefit can offset a veto. @@ -116,12 +116,12 @@ the distribution whose extreme events are, by design, rare. ### 14.5 No-op anchoring -Urabrask always measures a matched no-op branch. Augustin assigns no-op policy utility exactly zero. +Jin-Gitaxias always measures a matched no-op branch. Isperia assigns no-op policy utility exactly zero. This separation matters: -- Urabrask establishes what happened in the no-op world. -- Augustin establishes whether any candidate earns admission relative to it. +- Jin-Gitaxias establishes what happened in the no-op world. +- Isperia establishes whether any candidate earns admission relative to it. ### 14.6 Branch adoption invariant @@ -138,10 +138,10 @@ Copying only a co-adapted candidate into a divergent host is invalid. Candidate source is hidden from: -- Urabrask while constructing source-neutral tests and interpreting results; -- Augustin while applying eligibility and utility policy. +- Jin-Gitaxias while constructing source-neutral tests and interpreting results; +- Isperia while applying eligibility and utility policy. -Source provenance is reattached only after the decision for research analysis and Sarpadia storage. +Source provenance is reattached only after the decision for research analysis and Urborg storage. ### 14.8 Mainline–branch parity diff --git a/docs/design/TEMPLATE-lld.md b/docs/design/TEMPLATE-lld.md index 781470f..daf82ba 100644 --- a/docs/design/TEMPLATE-lld.md +++ b/docs/design/TEMPLATE-lld.md @@ -4,7 +4,7 @@ written just-in-time. Keep under ~600 lines; split by ADR if it outgrows. --> **Verb / mandate:** +sentence — e.g. "Isperia judges the resulting evidence under Leyline"> **Authority:** **Forbidden knowledge / authority:** diff --git a/docs/design/appendices/caveman-mode.md b/docs/design/appendices/caveman-mode.md index 3ee53e5..40b7e84 100644 --- a/docs/design/appendices/caveman-mode.md +++ b/docs/design/appendices/caveman-mode.md @@ -47,17 +47,17 @@ breaks. The old tribe is proof. - **The Proving Grounds (Tolaria).** Where we test rocks and train the Big Brain. The Grounds have no opinions. They run the hunt exactly the same way every time you ask for the same hunt. -- **The Memory Wall (Sarpadia).** We draw every good rock, every bad rock, +- **The Memory Wall (Urborg).** We draw every good rock, every bad rock, and every dead ape here. We never forget. We never erase. We learn from dead rocks just as much as living ones. ### The tribe -**The Chief (Tamiyo).** DO: decide how much food and time the tribe has; +**The Chief (Ugin).** DO: decide how much food and time the tribe has; pick which parts of the Big Brain get attention. DO NOT: tell anyone what kind of rock to make. -**The Caller (Narset).** DO: point at a hole in the Big Brain and say "we +**The Caller (Aurelia).** DO: point at a hole in the Big Brain and say "we need a rock here, right now!" DO NOT: tell the Maker what shape the rock should be. Do not pre-write the answer. @@ -76,21 +76,21 @@ its own work. Rules; make the edges legal. DO NOT: care whether the rock is useful. Only whether it is legal. -**The Sharpener (Tezzeret).** DO: bind the rock to a stick so it is ready +**The Sharpener (Urabrask).** DO: bind the rock to a stick so it is ready for the Proving Grounds. DO NOT: change the shape the Maker and Smoother agreed on. Same rock, better handle. -**The Hitter (Urabrask).** DO: smash the new rock in the Proving Grounds +**The Hitter (Jin-Gitaxias).** DO: smash the new rock in the Proving Grounds and record exactly what happens. DO NOT: say whether the rock is good enough to keep. The Hitter reports; the Hitter never rules. -**The Elder (Augustin).** DO: look at the smashed rock, compare it to the +**The Elder (Isperia).** DO: look at the smashed rock, compare it to the do-nothing timeline, and say YES or NO. DO NOT: swing a club. Judges do not gather their own evidence. And before comparing anything, the Elder first asks the tail question: *could this rock destroy the Big Brain?* No rock buys its way past that question, however hard it hits. -**The Healer (Kasmina).** DO: if the Elder said YES, carefully weave the +**The Healer (Wrenn).** DO: if the Elder said YES, carefully weave the new rock into the Big Brain — slowly, so the Brain does not go crazy. DO NOT: pick which rock is good. The Healer weaves only what the Elder approved, and never without the Elder's mark. @@ -100,7 +100,7 @@ that an old rock no longer earns its place, put it to sleep and rip it out safely so the Brain can grow elsewhere. DO NOT: make new rocks, judge newborn rocks, or reap without the Elder's ruling. -**The Painter (Oona).** DO: watch the entire hunt and paint every single +**The Painter (Tamiyo).** DO: watch the entire hunt and paint every single thing on the wall, so outsiders can see our story. DO NOT: touch the Big Brain. If the Painter goes to sleep, the tribe must keep hunting exactly the same way. diff --git a/docs/design/appendices/glossary.md b/docs/design/appendices/glossary.md index f50a32e..4149723 100644 --- a/docs/design/appendices/glossary.md +++ b/docs/design/appendices/glossary.md @@ -8,15 +8,15 @@ |---|---|---| | Leyline | Shared contracts, grammar profiles and invariants | Stylebook and editorial constitution | | Tolaria | Host-training and deterministic execution substrate | Production environment, CMS and test presses | -| Sarpadia | Historical archive, reference ancestry, lineage store and retrieval system | Morgue and archive | -| Tamiyo | Strategic allocator | Editor-in-chief / managing editor | -| Narset | Tactical commissioning and lifecycle controller | Assignments editor | +| Urborg | Historical archive, reference ancestry, lineage store and retrieval system | Morgue and archive | +| Ugin | Strategic allocator | Editor-in-chief / managing editor | +| Aurelia | Tactical commissioning and lifecycle controller | Assignments editor | | Nissa | Diagnostic observer and direct evidence publisher | Reporting, photography and data desk | | Momir | Candidate growth designer | Writer / investigative journalist | | Elesh | Structural verifier and canonicaliser | Copy and standards desk | -| Tezzeret | Compiler | Production and typesetting desk | -| Urabrask | Quality assurance | Fact-checking and proof desk | -| Augustin | Independent judge | Publishing editor | -| Kasmina | Host and reversible growth physiology | Live-edition integrator | +| Urabrask | Compiler and manufacturing pipeline | Production and manufacturing desk | +| Jin-Gitaxias | Quality assurance | Fact-checking and proof desk | +| Isperia | Independent judge | Publishing editor | +| Wrenn | Host and reversible growth physiology | Live-edition integrator | | Emrakul | Post-commit maintenance and lysis executor | Corrections, withdrawal and retirement desk | -| Oona | Observability, flight recorder and operator surface | Front page, broadcast and presentation | +| Tamiyo | Observability, flight recorder and operator surface | Front page, broadcast and presentation | diff --git a/docs/design/appendices/good-bad-sentences.md b/docs/design/appendices/good-bad-sentences.md index 5502405..63fd073 100644 --- a/docs/design/appendices/good-bad-sentences.md +++ b/docs/design/appendices/good-bad-sentences.md @@ -8,18 +8,18 @@ ```text The host trained in Tolaria. -Nissa published observation O-41 to Narset and Momir. -Tamiyo allocated a regional growth budget. -Narset commissioned growth in Region A under the conservative assurance class. -Leyline resolved the request from Narset's intent and Kasmina's region contract. -Sarpadia supplied bootstrap ancestry during curriculum stage M2. +Nissa published observation O-41 to Aurelia and Momir. +Ugin allocated a regional growth budget. +Aurelia commissioned growth in Region A under the conservative assurance class. +Leyline resolved the request from Aurelia's intent and Wrenn's region contract. +Urborg supplied bootstrap ancestry during curriculum stage M2. Momir designed twelve candidates and three explicitly ancestry-free candidates. Elesh canonicalised nine and rejected six as malformed or duplicate. -Tezzeret compiled the nine canonical designs. -Urabrask tested the artefacts, their parents, the stock controls and no-op in Tolaria. -Augustin selected no-op because every eligible candidate had negative policy utility. -Oona revealed the result. -Sarpadia retained the entire rejected pool and the no-op victory. +Urabrask compiled the nine canonical designs. +Jin-Gitaxias tested the artefacts, their parents, the stock controls and no-op in Tolaria. +Isperia selected no-op because every eligible candidate had negative policy utility. +Tamiyo revealed the result. +Urborg retained the entire rejected pool and the no-op victory. ``` ### Unhealthy @@ -27,20 +27,20 @@ Sarpadia retained the entire rejected pool and the no-op victory. ```text Tolaria decided not to grow. Nissa requested an attention module. -Narset sent Momir a summary saying rank had collapsed. -Narset chose the Attention ancestor. -Narset encoded “use convolution” by requesting 100,064 parameters. -Momir read Narset's LSTM state. +Aurelia sent Momir a summary saying rank had collapsed. +Aurelia chose the Attention ancestor. +Aurelia encoded “use convolution” by requesting 100,064 parameters. +Momir read Aurelia's LSTM state. Momir admitted its best candidate. Elesh rejected a legal graph because its predicted accuracy was low. -Tezzeret added a helpful residual path during compilation. -Urabrask issued an admission token. -Augustin reran the test on an easier batch. -Kasmina selected the cheapest candidate from its stock library. -Sarpadia installed last week's winner. +Urabrask added a helpful residual path during compilation. +Jin-Gitaxias issued an admission token. +Isperia reran the test on an easier batch. +Wrenn selected the cheapest candidate from its stock library. +Urborg installed last week's winner. Emrakul designed a replacement. -Oona adjusted alpha from the dashboard. -Leyline imported Narset to decide what WAIT means today. +Tamiyo adjusted alpha from the dashboard. +Leyline imported Aurelia to decide what WAIT means today. ``` ### Review prompt diff --git a/docs/design/appendices/newsroom.md b/docs/design/appendices/newsroom.md index 0b33bf8..f660204 100644 --- a/docs/design/appendices/newsroom.md +++ b/docs/design/appendices/newsroom.md @@ -16,19 +16,19 @@ The newsroom analogy therefore explains why the architecture contains more roles | System role | Newsroom analogue | Legitimate question | |---|---|---| -| Tamiyo | Editor-in-chief / managing editor | Which desks, beats and investigations receive resources? | -| Narset | Assignments editor | Is there a story here, which region owns it, by when, and under what scope and budget? | +| Ugin | Editor-in-chief / managing editor | Which desks, beats and investigations receive resources? | +| Aurelia | Assignments editor | Is there a story here, which region owns it, by when, and under what scope and budget? | | Nissa | Reporting, photography and data desk | What was actually observed? | | Momir | Writer / investigative journalist | What coherent candidate follows from the evidence and assignment? | | Elesh | Copy, standards and house-form desk | Is the submission structurally legitimate, coherent and conformant? | -| Tezzeret | Production, layout and publishing pipeline | Can canonical copy become an executable edition without changing meaning? | +| Urabrask | Production, layout and manufacturing desk — the factory that prints the edition | Can canonical copy become an executable edition without changing meaning? | | Tolaria | Newsroom production environment, CMS and test presses | Where are ordinary and experimental editions produced and replayed? | -| Urabrask | Fact-checking and QA | Are the claims and executable behaviour supported by evidence? | -| Augustin | Publishing editor | Does this run, get returned, deferred, retested, rejected, or spiked? | -| Kasmina | Live-edition integrator | How is accepted material placed into the running edition safely? | +| Jin-Gitaxias | Fact-checking and QA — cold, empirical, perfectionist | Are the claims and executable behaviour supported by evidence? | +| Isperia | Publishing editor | Does this run, get returned, deferred, retested, rejected, or spiked? | +| Wrenn | Live-edition integrator — the symbiote who hosts the story | How is accepted material placed into the running edition safely? | | Emrakul | Corrections, withdrawal and retirement | What published material should be sedated, corrected, deprecated or removed? | -| Sarpadia | Morgue and archive | What did we report, try, reject, retract and learn? | -| Oona | Front page, broadcast desk and presentation | What does the operator or reader see? | +| Urborg | Morgue and archive | What did we report, try, reject, retract and learn? | +| Tamiyo | Front page, broadcast desk and presentation | What does the operator or reader see? | | Leyline | Stylebook and editorial constitution | What language, records and procedures govern the newsroom? | ### E.3 Assignment brief versus editorial angle @@ -70,30 +70,30 @@ attention-like / convolution-like / norm-like recommendation free-form message to the designer ``` -Narset may see Nissa's evidence because it must decide whether to commission work. It must not become the channel through which Momir sees that evidence. The assignments desk is allowed to say “investigate Region A under this scope.” It is not allowed to say “write a story proving rank collapse and conclude that attention is the answer.” +Aurelia may see Nissa's evidence because it must decide whether to commission work. It must not become the channel through which Momir sees that evidence. The assignments desk is allowed to say “investigate Region A under this scope.” It is not allowed to say “write a story proving rank collapse and conclude that attention is the answer.” ### E.4 The source-routing rule ```text Nissa observes host state S - ├──→ TelemetryEnvelope O ──→ Narset + ├──→ TelemetryEnvelope O ──→ Aurelia └──→ TelemetryEnvelope O ──→ Momir -Narset emits GrowthIntent I +Aurelia emits GrowthIntent I Leyline resolves GrowthRequest Q -Sarpadia optionally emits ancestry A +Urborg optionally emits ancestry A Momir designs from O + Q + optional A ``` The following are constitutional failures: -- Narset forwards a rewritten observation to Momir; +- Aurelia forwards a rewritten observation to Momir; - Nissa emits a recommended solution; -- Momir reads Narset hidden state; +- Momir reads Aurelia hidden state; - the request resolver infers a diagnosis; -- an ancestor is selected by Narset rather than the curriculum or retrieval policy; -- or the observation referenced by Momir differs from the one that triggered Narset's commission. +- an ancestor is selected by Aurelia rather than the curriculum or retrieval policy; +- or the observation referenced by Momir differs from the one that triggered Aurelia's commission. ### E.5 The right to spike the story @@ -101,32 +101,32 @@ A commissioned story does not have to run. Likewise, a `GrowthIntent` does not i The chain contains multiple legitimate stopping points: -- Narset may choose `WAIT` and issue no assignment. +- Aurelia may choose `WAIT` and issue no assignment. - Momir may produce no structurally viable proposal. - Elesh may reject malformed designs. -- Tezzeret may fail to compile faithfully. -- Urabrask may find runtime defects or inadequate evidence. -- Augustin may select no-op, reject, defer or require retest. -- Narset may abort stale growth before integration. +- Urabrask may fail to compile faithfully. +- Jin-Gitaxias may find runtime defects or inadequate evidence. +- Isperia may select no-op, reject, defer or require retest. +- Aurelia may abort stale growth before integration. - Emrakul may later withdraw committed growth under a maintenance warrant. This is the editorial equivalent of spiking a story, returning copy, publishing a correction, or withdrawing an obsolete article. The architecture is intentionally not a content mill that must publish something every time an assignment is raised. ### E.6 Archive discipline -A credible newsroom archive contains accepted stories, abandoned drafts, corrections, retractions, failed investigations and source notes. Sarpadia must likewise retain: +A credible newsroom archive contains accepted stories, abandoned drafts, corrections, retractions, failed investigations and source notes. Urborg must likewise retain: - stock reference seeds and their outcomes; - Momir children and parents; - structural rejects; - compilation failures; - QA defects; -- Augustin rejections and no-op decisions; +- Isperia rejections and no-op decisions; - stale integrations; - maintenance withdrawals; - and scaffold-withdrawal status. -A winners-only Sarpadia is not institutional memory. It is mythology. +A winners-only Urborg is not institutional memory. It is mythology. ### E.7 Where the analogy stops @@ -135,7 +135,7 @@ The newsroom model is not a literal organisational chart and should not determin - Nissa may be automated and highly mathematical; it is not a human reporter. - Elesh's structural proofs are stronger than ordinary copy editing. - Tolaria is both the ordinary training substrate and the counterfactual production environment. -- Augustin's utility policy is formal and versioned, not editorial taste. -- Kasmina and Emrakul operate on a neural host, not a publication. +- Isperia's utility policy is formal and versioned, not editorial taste. +- Wrenn and Emrakul operate on a neural host, not a publication. The analogy is used to explain and lint authority boundaries. Leyline schemas, dependency rules, tests, blinding and deterministic provenance remain the source of architectural truth. diff --git a/docs/design/appendices/scaffold-pattern.md b/docs/design/appendices/scaffold-pattern.md index 95926ae..25e9499 100644 --- a/docs/design/appendices/scaffold-pattern.md +++ b/docs/design/appendices/scaffold-pattern.md @@ -9,7 +9,7 @@ The architecture repeatedly faces problems whose unrestricted form is initially too noisy or sparse to teach anything reliable: - Tolaria cannot attribute branch differences while execution noise is unknown; -- Narset cannot learn intervention timing when every host trajectory diverges for unrelated reasons; +- Aurelia cannot learn intervention timing when every host trajectory diverges for unrelated reasons; - Momir cannot learn useful design when almost every unconstrained graph proposal is invalid or useless. The response is not to pretend the unrestricted problem is easy. It is to establish a controlled classroom in which causal signal exceeds nuisance variation, calibrate the instruments there, and then remove the classroom constraints one at a time. @@ -22,7 +22,7 @@ This is a uniform theory of generalisation rather than three unrelated training |---|---|---|---|---|---| | Tolaria Academy exactness | Attribution error | Bitwise-exact paired worlds | Repeated stochastic worlds and surrogate calibration | Ranking, decision, uncertainty and tail criteria | Causal oracle, CI, regression and disputed-case retest | | Repeated host trajectories | Host variance | Fixed acquisition seeds and identical trajectories | Held-out in-family initialisations and one-axis variation | Stable tactical timing and lifecycle outcomes | Policy-language and regression fixtures | -| Sarpadian reference ancestry | Generator collapse | Reconstruction, imitation and bounded mutation | Ancestry dropout and partial de novo design | Structural validity and positive coverage with null ancestry | Blinded controls and historical precedent | +| Urborg reference ancestry | Generator collapse | Reconstruction, imitation and bounded mutation | Ancestry dropout and partial de novo design | Structural validity and positive coverage with null ancestry | Blinded controls and historical precedent | ### F.3 Tolaria's training wheels @@ -56,9 +56,9 @@ Academy exactness therefore remains available after withdrawal. It defines the u The primary gate owners are: -- **Urabrask** certifies Tolaria execution and Field-surrogate evidence against Academy results; -- **Augustin** authorises use of that evidence for a declared assurance class and applies uncertainty margins; -- **Narset curriculum evaluation** certifies host-distribution generalisation; +- **Jin-Gitaxias** certifies Tolaria execution and Field-surrogate evidence against Academy results; +- **Isperia** authorises use of that evidence for a declared assurance class and applies uncertainty margins; +- **Aurelia curriculum evaluation** certifies host-distribution generalisation; - **Momir curriculum evaluation** certifies null-ancestry design competence; - **Leyline** validates that the run's declared `ScaffoldState` matches the actual configuration. diff --git a/docs/design/assets/model.dsl b/docs/design/assets/model.dsl index c1449e8..7605f87 100644 --- a/docs/design/assets/model.dsl +++ b/docs/design/assets/model.dsl @@ -18,7 +18,7 @@ workspace "Simic" "Counterfactual Generative Morphogenesis — the fourteen-doma !impliedRelationships false model { - operator = person "Operator" "Reads the account through Oona; owns escalations. Never a control-path participant." + operator = person "Operator" "Reads the account through Tamiyo; owns escalations. Never a control-path participant." dataStream = softwareSystem "Task and Data Stream" "The host's training task: minibatches, splits and evaluation data." "External" @@ -29,151 +29,151 @@ workspace "Simic" "Counterfactual Generative Morphogenesis — the fourteen-doma resolver = component "Request Resolver" "Pure deterministic contract assembly: (GrowthIntent, StrategicEnvelope, RegionContract, GrammarProfile) -> one canonical GrowthRequest. Fails closed on incompatibility. Not a fifteenth agent: no diagnosis, no learned policy." } tolaria = container "Tolaria" "The single training/execution substrate: host training, snapshots, deterministic replay, matched common-future branches and rollback. Applies no candidate utility weights; issues no verdicts." "src/simic/tolaria/" "Infrastructure" - sarpadia = container "Sarpadia" "Append-only history: lineages, reference ancestry, outcomes, failures, rejected pools, no-op wins and split-safe datasets. Never winners-only." "src/simic/sarpadia/" "Infrastructure" + urborg = container "Urborg" "Append-only history: lineages, reference ancestry, outcomes, failures, rejected pools, no-op wins and split-safe datasets. Never winners-only." "src/simic/urborg/" "Infrastructure" // ---- Agents (verbs) ------------------------------------------- nissa = container "Nissa" "Observes and reports. Publishes one canonical ablated observation identity directly to its consumers. Never emits should_grow." "src/simic/nissa/" "Agent" - tamiyo = container "Tamiyo" "Plans. Strategic budgets, regional priorities, exploration quotas, cooldowns and long-horizon risk. Never issues local transitions." "src/simic/tamiyo/" "Agent" - narset = container "Narset" "Commissions and acts. Tactical commissioning and pre-commit lifecycle actions only. Sends the assignment brief, never the photograph." "src/simic/narset/" "Agent" + ugin = container "Ugin" "Plans. Strategic budgets, regional priorities, exploration quotas, cooldowns and long-horizon risk. Never issues local transitions." "src/simic/ugin/" "Agent" + aurelia = container "Aurelia" "Commissions and acts. Tactical commissioning and pre-commit lifecycle actions only. Sends the assignment brief, never the photograph." "src/simic/aurelia/" "Agent" momir = container "Momir" "Designs. Raw candidate topology, parameters, mutation and recombination. No timing, approval, testing or admission authority." "src/simic/momir/" "Agent" { momirEvidence = component "Evidence Intake" "Consumes Nissa's canonical diagnostic evidence (TelemetryEnvelope) directly, with preserved provenance." momirRequest = component "Request Intake" "Consumes the independently resolved GrowthRequest as operational constraints; rejects calls whose observation, snapshot, region or compatibility identifiers do not reconcile." - momirAncestry = component "Ancestry Channel" "Optional Sarpadian ancestry or retrieval context through a separate provenance-bearing channel. Output must remain valid when ancestry is null." + momirAncestry = component "Ancestry Channel" "Optional Urborg ancestry or retrieval context through a separate provenance-bearing channel. Output must remain valid when ancestry is null." momirGenerator = component "Candidate Generator" "Designs raw candidate graphs and birth parameters: reference reconstruction, bounded mutation, lineage recombination, de novo; deterministic or stochastic best-of-K." momirAssembler = component "Proposal Assembler" "Binds provenance, generation uncertainty and measured spend to every proposal in the batch." } elesh = container "Elesh" "Conforms. Static verification, canonicalisation, semantic hashing and structural legality. Simplifies only where semantic equivalence is established." "src/simic/elesh/" "Agent" - tezzeret = container "Tezzeret" "Compiles. Lowering, kernel selection, fusion, memory planning. Preserves semantics; compilation success implies neither runtime validity nor admission." "src/simic/tezzeret/" "Agent" - urabrask = container "Urabrask" "Tests the compiled result in Tolaria. Certifies evidence; never issues verdicts, warrants or lifecycle tokens." "src/simic/urabrask/" "Agent" { + urabrask = container "Urabrask" "Compiles. Lowering, kernel selection, fusion, memory planning. Preserves semantics; compilation success implies neither runtime validity nor admission." "src/simic/urabrask/" "Agent" + jin_gitaxias = container "Jin-Gitaxias" "Tests the compiled result in Tolaria. Certifies evidence; never issues verdicts, warrants or lifecycle tokens." "src/simic/jin_gitaxias/" "Agent" { uraPlanner = component "Test Planner" "Constructs blinded, versioned TestPlan records. Mandatory tests cannot be weakened after viewing a candidate's result." uraConformance = component "Conformance Verifier" "Verifies the compiled artefact against the canonical specification at runtime: reference outputs, gradient agreement, zero-influence behaviour, numerical stability." uraBranch = component "Branch Measurement" "Requests deterministic replay and matched common-future branches in Tolaria; measures immediate and multi-horizon trajectories, integration shock, latency and spend." uraCertifier = component "Evidence Certifier" "Quantifies uncertainty and evidence completeness, classifies hard defects and soft warnings, and signs the QualityReport — measurements, never a verdict." } - augustin = container "Augustin" "Judges the resulting evidence under Leyline. Provider-blind, lexicographic adjudication against mandatory no-op; issues warrants." "src/simic/augustin/" "Agent" { + isperia = container "Isperia" "Judges the resulting evidence under Leyline. Provider-blind, lexicographic adjudication against mandatory no-op; issues warrants." "src/simic/isperia/" "Agent" { augEligibility = component "Eligibility Gate" "Stage 1 — hard eligibility: identity, compilation conformance, runtime and gradient checks, determinism, evidence completeness for the assurance class, budget." augTailVeto = component "Tail-Risk Veto" "Stage 2 — vetoes any candidate whose intervention-outcome tail estimate breaches the threshold. Adjudicated before any utility comparison; never tradeable against measured benefit (INV-45). No-op never faces it." augUtility = component "Utility Competition" "Stage 3 — u_admit ranks survivors against mandatory no-op, whose policy utility is exactly zero. Returns ADMIT, NO_OP, REJECT, DEFER or REQUIRE_RETEST." augTenancy = component "Tenancy Adjudicator" "Continued-tenancy adjudication: u_retain under a versioned hysteresis band strictly below the admission threshold (ADR-0005, INV-33)." augWarrants = component "Warrant Issuer" "Issues admission and maintenance warrants, each bound to a specific evidence digest, semantic hash, envelope and policy version." } - kasmina = container "Kasmina" "Embodies the admitted growth. Host model, insertion regions, slots, gradient routing, maturation, blending and physical lifecycle — only under a valid warrant." "src/simic/kasmina/" "Agent" + wrenn = container "Wrenn" "Embodies the admitted growth. Host model, insertion regions, slots, gradient routing, maturation, blending and physical lifecycle — only under a valid warrant." "src/simic/wrenn/" "Agent" emrakul = container "Emrakul" "Destroys what no longer earns continued tenancy. Post-commit sedation, decay, consolidation and lysis under maintenance warrants. Post-commit only." "src/simic/emrakul/" "Agent" - oona = container "Oona" "Reveals the account. Event projections, flight recorder, operator surfaces and audit bundles. Read-only: disconnecting Oona cannot change training." "src/simic/oona/" "Agent" + tamiyo = container "Tamiyo" "Reveals the account. Event projections, flight recorder, operator surfaces and audit bundles. Read-only: disconnecting Tamiyo cannot change training." "src/simic/tamiyo/" "Agent" } // ==== System-level relationships (context view only) =============== // Implied relationships are off, so these must be stated explicitly; // they never render in container or component views. dataStream -> simic "Supplies the task and data stream" - operator -> simic "Reads the account through Oona; owns escalations" + operator -> simic "Reads the account through Tamiyo; owns escalations" // ==== Container-level relationships (transcribed from §7.1) ======== // Training substrate and observation dataStream -> tolaria "Supplies the task and data stream" - tolaria -> kasmina "Executes host forward/backward passes and optimiser steps" - kasmina -> nissa "Exposes host state for canonical ablated diagnostic observation" + tolaria -> wrenn "Executes host forward/backward passes and optimiser steps" + wrenn -> nissa "Exposes host state for canonical ablated diagnostic observation" // Direct evidence publication (the newsroom rule) - nissa -> tamiyo "Permitted coarse summary" - nissa -> narset "TelemetryEnvelope O (same observation identity)" + nissa -> ugin "Permitted coarse summary" + nissa -> aurelia "TelemetryEnvelope O (same observation identity)" nissa -> momir "TelemetryEnvelope O (same observation identity)" // Strategic loop and request resolution - tamiyo -> narset "StrategicEnvelope" - narset -> leyline "GrowthIntent — assignment brief only" - tamiyo -> leyline "Authorised StrategicEnvelope" - kasmina -> leyline "RegionContract" + ugin -> aurelia "StrategicEnvelope" + aurelia -> leyline "GrowthIntent — assignment brief only" + ugin -> leyline "Authorised StrategicEnvelope" + wrenn -> leyline "RegionContract" leyline -> momir "Resolved canonical GrowthRequest" // Core growth flow - sarpadia -> momir "Optional precedents / BootstrapAncestryContext (bootstrap curriculum)" + urborg -> momir "Optional precedents / BootstrapAncestryContext (bootstrap curriculum)" momir -> elesh "RawGrowthGraph" - elesh -> tezzeret "CanonicalGrowthSpec" - tezzeret -> urabrask "ExecutableGrowthArtifact" + elesh -> urabrask "CanonicalGrowthSpec" + urabrask -> jin_gitaxias "ExecutableGrowthArtifact" // QA and adjudication - urabrask -> tolaria "TestPlan: candidate branches + controls + mandatory no-op" - tolaria -> urabrask "BranchResults and runtime evidence" - urabrask -> augustin "QualityReport (blinded)" - tamiyo -> augustin "Strategic limits" - leyline -> augustin "Resolved request context" - augustin -> narset "AdmissionDecision or NO_OP" + jin_gitaxias -> tolaria "TestPlan: candidate branches + controls + mandatory no-op" + tolaria -> jin_gitaxias "BranchResults and runtime evidence" + jin_gitaxias -> isperia "QualityReport (blinded)" + ugin -> isperia "Strategic limits" + leyline -> isperia "Resolved request context" + isperia -> aurelia "AdmissionDecision or NO_OP" // Embodiment and maintenance - narset -> kasmina "LifecycleCommand plus admission warrant" - kasmina -> emrakul "Ownership of committed growth transfers at COMMIT" - emrakul -> urabrask "Maintenance QA request" - augustin -> emrakul "MaintenanceDecision plus maintenance warrant" - emrakul -> kasmina "Sedate / decay / lyse command under maintenance warrant" + aurelia -> wrenn "LifecycleCommand plus admission warrant" + wrenn -> emrakul "Ownership of committed growth transfers at COMMIT" + emrakul -> jin_gitaxias "Maintenance QA request" + isperia -> emrakul "MaintenanceDecision plus maintenance warrant" + emrakul -> wrenn "Sedate / decay / lyse command under maintenance warrant" // Archival ingestion (append-only, failures included) - nissa -> sarpadia "Append-only observation record" - leyline -> sarpadia "Resolved request record" - momir -> sarpadia "Raw candidates, lineages and rejected pools" - elesh -> sarpadia "Structural reports, including failures" - tezzeret -> sarpadia "Compilation manifests" - tolaria -> sarpadia "Snapshots and branch traces" - urabrask -> sarpadia "Test plans and quality reports" - augustin -> sarpadia "Decisions, including no-op wins and abstentions" - kasmina -> sarpadia "Lifecycle traces" - emrakul -> sarpadia "Maintenance actions" + nissa -> urborg "Append-only observation record" + leyline -> urborg "Resolved request record" + momir -> urborg "Raw candidates, lineages and rejected pools" + elesh -> urborg "Structural reports, including failures" + urabrask -> urborg "Compilation manifests" + tolaria -> urborg "Snapshots and branch traces" + jin_gitaxias -> urborg "Test plans and quality reports" + isperia -> urborg "Decisions, including no-op wins and abstentions" + wrenn -> urborg "Lifecycle traces" + emrakul -> urborg "Maintenance actions" // Witness projections (read-only surface) - nissa -> oona "Event projection" - tamiyo -> oona "Event projection" - narset -> oona "Event projection" - momir -> oona "Event projection" - elesh -> oona "Event projection" - tezzeret -> oona "Event projection" - tolaria -> oona "Event projection" - urabrask -> oona "Event projection" - augustin -> oona "Event projection" - kasmina -> oona "Event projection" - sarpadia -> oona "Event projection" - emrakul -> oona "Event projection" - operator -> oona "Reads the account" + nissa -> tamiyo "Event projection" + ugin -> tamiyo "Event projection" + aurelia -> tamiyo "Event projection" + momir -> tamiyo "Event projection" + elesh -> tamiyo "Event projection" + urabrask -> tamiyo "Event projection" + tolaria -> tamiyo "Event projection" + jin_gitaxias -> tamiyo "Event projection" + isperia -> tamiyo "Event projection" + wrenn -> tamiyo "Event projection" + urborg -> tamiyo "Event projection" + emrakul -> tamiyo "Event projection" + operator -> tamiyo "Reads the account" // ==== Component-level relationships ================================= // (implied relationships are OFF, so these never duplicate the // container-level edges above; each view renders only its own level) // Request resolution (Leyline) - narset -> resolver "GrowthIntent" - tamiyo -> resolver "StrategicEnvelope" - kasmina -> resolver "RegionContract" + aurelia -> resolver "GrowthIntent" + ugin -> resolver "StrategicEnvelope" + wrenn -> resolver "RegionContract" resolver -> momir "Canonical GrowthRequest" - resolver -> augustin "Resolved request context" + resolver -> isperia "Resolved request context" // Momir internals nissa -> momirEvidence "TelemetryEnvelope O" leyline -> momirRequest "Resolved GrowthRequest" - sarpadia -> momirAncestry "BootstrapAncestryContext | null; ordinary retrieval where enabled" + urborg -> momirAncestry "BootstrapAncestryContext | null; ordinary retrieval where enabled" momirEvidence -> momirGenerator "Diagnostic evidence" momirRequest -> momirGenerator "Operational constraints" momirAncestry -> momirGenerator "Ancestry / retrieval context" momirGenerator -> momirAssembler "Raw candidate graphs and birth parameters" momirAssembler -> elesh "RawGrowthGraph batch with provenance" - // Urabrask internals - tezzeret -> uraConformance "ExecutableGrowthArtifact" + // Jin-Gitaxias internals + urabrask -> uraConformance "ExecutableGrowthArtifact" uraPlanner -> tolaria "Blinded TestPlan" tolaria -> uraBranch "BranchResults and runtime evidence" uraConformance -> uraCertifier "Conformance measurements and defects" uraBranch -> uraCertifier "Branch measurements" uraPlanner -> uraCertifier "Test-plan version and evidence digest" - uraCertifier -> augustin "Signed QualityReport (blinded)" + uraCertifier -> isperia "Signed QualityReport (blinded)" - // Augustin internals - urabrask -> augEligibility "QualityReport (blinded)" - tamiyo -> augEligibility "Active StrategicEnvelope" + // Isperia internals + jin_gitaxias -> augEligibility "QualityReport (blinded)" + ugin -> augEligibility "Active StrategicEnvelope" leyline -> augEligibility "Resolved request context" augEligibility -> augTailVeto "Eligible candidates" augTailVeto -> augUtility "Veto survivors" augUtility -> augWarrants "ADMIT / NO_OP / REJECT / DEFER / REQUIRE_RETEST" - augWarrants -> narset "AdmissionDecision plus admission warrant" - urabrask -> augTenancy "Maintenance QualityReport (blinded)" + augWarrants -> aurelia "AdmissionDecision plus admission warrant" + jin_gitaxias -> augTenancy "Maintenance QualityReport (blinded)" augTenancy -> augWarrants "MaintenanceDecision" augWarrants -> emrakul "MaintenanceDecision plus maintenance warrant" } @@ -190,30 +190,30 @@ workspace "Simic" "Counterfactual Generative Morphogenesis — the fourteen-doma } container simic "CoreGrowthFlow" "Observation to embodiment: the core growth loop without archival and witness noise." { - include nissa tamiyo narset leyline momir elesh tezzeret urabrask augustin kasmina tolaria sarpadia - exclude "* -> sarpadia" + include nissa ugin aurelia leyline momir elesh urabrask jin_gitaxias isperia wrenn tolaria urborg + exclude "* -> urborg" autoLayout tb } - container simic "QaAdjudication" "QA and adjudication: Urabrask certifies evidence from matched branches; Augustin judges it provider-blind against no-op." { - include tezzeret urabrask tolaria augustin tamiyo leyline narset - exclude "tamiyo -> narset" - exclude "narset -> leyline" - exclude "tamiyo -> leyline" - exclude "* -> sarpadia" + container simic "QaAdjudication" "QA and adjudication: Jin-Gitaxias certifies evidence from matched branches; Isperia judges it provider-blind against no-op." { + include urabrask jin_gitaxias tolaria isperia ugin leyline aurelia + exclude "ugin -> aurelia" + exclude "aurelia -> leyline" + exclude "ugin -> leyline" + exclude "* -> urborg" autoLayout tb } - container simic "MaintenanceLoop" "Post-commit tenancy: Emrakul requests review, Urabrask certifies counterfactual evidence, Augustin decides, Emrakul executes through Kasmina." { - include emrakul urabrask augustin kasmina tolaria - exclude "* -> sarpadia" + container simic "MaintenanceLoop" "Post-commit tenancy: Emrakul requests review, Jin-Gitaxias certifies counterfactual evidence, Isperia decides, Emrakul executes through Wrenn." { + include emrakul jin_gitaxias isperia wrenn tolaria + exclude "* -> urborg" autoLayout tb } - container simic "ArchiveIngestion" "Sarpadia archival ingestion: every producer appends, failures and no-op wins included; nothing is winners-only." { - include nissa leyline momir elesh tezzeret tolaria urabrask augustin kasmina emrakul sarpadia + container simic "ArchiveIngestion" "Urborg archival ingestion: every producer appends, failures and no-op wins included; nothing is winners-only." { + include nissa leyline momir elesh urabrask tolaria jin_gitaxias isperia wrenn emrakul urborg exclude "* -> *" - include "* -> sarpadia" + include "* -> urborg" autoLayout tb } @@ -227,12 +227,12 @@ workspace "Simic" "Counterfactual Generative Morphogenesis — the fourteen-doma autoLayout tb } - component urabrask "UrabraskComponents" "Urabrask internals: blinded planning, runtime conformance, branch measurement, and certification without verdicts." { + component jin_gitaxias "Jin-GitaxiasComponents" "Jin-Gitaxias internals: blinded planning, runtime conformance, branch measurement, and certification without verdicts." { include * autoLayout tb } - component augustin "AugustinComponents" "Augustin internals: the lexicographic admission order (ADR-0004) — eligibility, then the untradeable tail-risk veto, then utility against no-op." { + component isperia "IsperiaComponents" "Isperia internals: the lexicographic admission order (ADR-0004) — eligibility, then the untradeable tail-risk veto, then utility against no-op." { include * autoLayout tb } diff --git a/docs/design/domains/README.md b/docs/design/domains/README.md index 07962e5..d237aca 100644 --- a/docs/design/domains/README.md +++ b/docs/design/domains/README.md @@ -9,12 +9,12 @@ The subsystem specifications are grouped according to the naming constitution: i --- Infrastructure (prepositions): [leyline](leyline.md) · [tolaria](tolaria.md) · -[sarpadia](sarpadia.md) (also carries the §15 data model) +[urborg](urborg.md) (also carries the §15 data model) -Agents (verbs): [tamiyo](tamiyo.md) · [narset](narset.md) · [nissa](nissa.md) · -[momir](momir.md) · [elesh](elesh.md) · [tezzeret](tezzeret.md) · -[urabrask](urabrask.md) · [augustin](augustin.md) · [kasmina](kasmina.md) · -[emrakul](emrakul.md) · [oona](oona.md) +Agents (verbs): [ugin](ugin.md) · [aurelia](aurelia.md) · [nissa](nissa.md) · +[momir](momir.md) · [elesh](elesh.md) · [urabrask](urabrask.md) · +[jin-gitaxias](jin-gitaxias.md) · [isperia](isperia.md) · [wrenn](wrenn.md) · +[emrakul](emrakul.md) · [tamiyo](tamiyo.md) Each chapter carries its domain's responsibilities, invariants, forbidden authority and smell. Contract shapes live in diff --git a/docs/design/domains/narset.md b/docs/design/domains/aurelia.md similarity index 66% rename from docs/design/domains/narset.md rename to docs/design/domains/aurelia.md index bd805e2..2b47f64 100644 --- a/docs/design/domains/narset.md +++ b/docs/design/domains/aurelia.md @@ -2,25 +2,25 @@ [← HLD index](../00-INDEX.md) -### 13.5 Narset — Tactical Controller +### 13.5 Aurelia — Tactical Controller #### Responsibilities - interpret local telemetry only to decide whether work should be commissioned, where it belongs, and what operational class applies; - choose among wait, commission, maturation, QA, adjudication, blend, hold, abort, commit and escalation actions; -- choose an insertion region permitted by Tamiyo; +- choose an insertion region permitted by Ugin; - author a narrow `GrowthIntent` inside the strategic envelope; - manage pre-commit lifecycle timing; -- request Urabrask QA and Augustin adjudication; -- and escalate strategic shortages or conflicts to Tamiyo. +- request Jin-Gitaxias QA and Isperia adjudication; +- and escalate strategic shortages or conflicts to Ugin. #### Inputs - Nissa's canonical `TelemetryEnvelope`; -- active Tamiyo envelope; -- Kasmina local lifecycle state and region identifiers; -- Urabrask evidence; -- Augustin decisions; +- active Ugin envelope; +- Wrenn local lifecycle state and region identifiers; +- Jin-Gitaxias evidence; +- Isperia decisions; - aggregate operational history without candidate-family or ancestor instructions; - and Emrakul notifications where committed structure affects local capacity. @@ -34,14 +34,14 @@ #### Invariants -- Narset cannot exceed Tamiyo's budget. +- Aurelia cannot exceed Ugin's budget. - It does not send, copy, caption or rewrite Nissa telemetry for Momir. - It cannot include a diagnosis, topology family, ancestor choice, rank, width, operator or mechanism hint in `GrowthIntent`. -- It cannot choose a structure that bypasses Momir, Elesh and Tezzeret. -- It cannot override Augustin's no-op or rejection. +- It cannot choose a structure that bypasses Momir, Elesh and Urabrask. +- It cannot override Isperia's no-op or rejection. - It relinquishes ordinary ownership at commitment. - It never exposes hidden recurrent state to Momir. #### Smell -> If Narset tells Momir what the problem “really is” or what kind of answer to produce, the assignments editor has become a co-author. +> If Aurelia tells Momir what the problem “really is” or what kind of answer to produce, the assignments editor has become a co-author. diff --git a/docs/design/domains/elesh.md b/docs/design/domains/elesh.md index 276a095..b957ceb 100644 --- a/docs/design/domains/elesh.md +++ b/docs/design/domains/elesh.md @@ -28,7 +28,7 @@ Every Elesh transformation must be semantics-preserving under the declared numer - Elesh does not consume task reward or future utility. - It does not use candidate source as a structural decision feature. - Canonicalisation occurs before compilation. -- It does not certify dynamic runtime behaviour; that belongs to Urabrask. +- It does not certify dynamic runtime behaviour; that belongs to Jin-Gitaxias. #### Smell diff --git a/docs/design/domains/emrakul.md b/docs/design/domains/emrakul.md index e945368..d490434 100644 --- a/docs/design/domains/emrakul.md +++ b/docs/design/domains/emrakul.md @@ -13,24 +13,24 @@ - initiate safe gradual decay; - lyse obsolete structures; - consolidate capacity where separately authorised; -- and return recycled capacity to Tamiyo’s strategic view. +- and return recycled capacity to Ugin’s strategic view. #### Inputs -- Urabrask maintenance `QualityReport`; -- Augustin `MaintenanceDecision`; +- Jin-Gitaxias maintenance `QualityReport`; +- Isperia `MaintenanceDecision`; - Tolaria maintenance execution; -- Kasmina lifecycle and alpha state; +- Wrenn lifecycle and alpha state; - Nissa long-horizon telemetry; -- Tamiyo strategic budgets; -- and Sarpadia lineage and historical outcomes. +- Ugin strategic budgets; +- and Urborg lineage and historical outcomes. #### Invariants - Emrakul acts only on committed or explicitly handed-off growth. - It does not construct replacements. - It does not decide continued-tenancy utility. -- It does not alter Urabrask test policy or Augustin adjudication policy. +- It does not alter Jin-Gitaxias test policy or Isperia adjudication policy. - Sedation precedes lysis where safety permits. - A lysis event is emitted once on a real transition. diff --git a/docs/design/domains/augustin.md b/docs/design/domains/isperia.md similarity index 78% rename from docs/design/domains/augustin.md rename to docs/design/domains/isperia.md index 1fa0822..dd1dee1 100644 --- a/docs/design/domains/augustin.md +++ b/docs/design/domains/isperia.md @@ -2,14 +2,14 @@ [← HLD index](../00-INDEX.md) -### 13.11 Augustin — Independent Judge +### 13.11 Isperia — Independent Judge #### Responsibilities -- consume blinded Urabrask `QualityReport` records; +- consume blinded Jin-Gitaxias `QualityReport` records; - apply hard eligibility requirements; - apply the tail-risk veto before any utility comparison; -- enforce Tamiyo’s active strategic envelope; +- enforce Ugin’s active strategic envelope; - calculate adjudicated utility, risk and uncertainty charges; - compare surviving candidates against mandatory no-op; - apply independent admission-audit rules; @@ -22,14 +22,14 @@ #### Lexicographic admission order (ADR-0004) -Admission is a risk judgement before it is a quality judgement. Augustin +Admission is a risk judgement before it is a quality judgement. Isperia adjudicates in three ordered stages, and no later stage can reopen an earlier one: 1. **Hard eligibility.** Conformance facts from the blinded `QualityReport`: identity, compilation, runtime and gradient checks, determinism, evidence completeness for the assurance class, budget. -2. **Tail-risk veto.** Augustin estimates, per candidate, the tail of the +2. **Tail-risk veto.** Isperia estimates, per candidate, the tail of the intervention-outcome distribution — the catastrophic case, not the expectation — from certified evidence (integration shock, instability, numerical events, trajectory behaviour). A candidate whose tail estimate @@ -46,9 +46,9 @@ risk — so it survives every stage by construction. A pool whose every candidate is vetoed resolves to `NO_OP` (or `DEFER`/`REQUIRE_RETEST` under policy), never to a least-bad survivor. -This order is what justifies the Momir/Augustin split: **Momir optimises +This order is what justifies the Momir/Isperia split: **Momir optimises expected value** and can afford to be wrong often, because its errors cost -compute; **Augustin bounds worst case** and must be conservative, because +compute; **Isperia bounds worst case** and must be conservative, because its errors cost the host. They optimise different functionals of the same distribution. @@ -110,14 +110,14 @@ Installation shock is omitted because a resident growth is no longer integrating Admission and retention thresholds form a Schmitt trigger: admission requires the conservative margin over no-op to exceed \(\theta_{\mathrm{admit}}\); continued tenancy requires only \(u_{\mathrm{retain}} \ge \theta_{\mathrm{retain}}\), with \(\theta_{\mathrm{retain}} = \theta_{\mathrm{admit}} - \Delta\) and \(\Delta > 0\) strictly (INV-33). A resident growth that drifts modestly below the admission bar is not thereby lysed. -The hysteresis band \(\Delta\) is an explicit, versioned Augustin policy parameter, carried by `adjudication_policy_version`, and its width is measured against observed execution noise \(\sigma_{\mathrm{exec}}\) — sized so noise-driven estimate movement cannot cross both thresholds — never picked by feel. Cooldowns are a frequency limiter for pathological cases, not the stability mechanism: they are a time-domain patch and do not remove a threshold-domain instability. +The hysteresis band \(\Delta\) is an explicit, versioned Isperia policy parameter, carried by `adjudication_policy_version`, and its width is measured against observed execution noise \(\sigma_{\mathrm{exec}}\) — sized so noise-driven estimate movement cannot cross both thresholds — never picked by feel. Cooldowns are a frequency limiter for pathological cases, not the stability mechanism: they are a time-domain patch and do not remove a threshold-domain instability. #### Invariants -- Augustin does not execute tests, alter data, call kernels or rerun a branch. +- Isperia does not execute tests, alter data, call kernels or rerun a branch. - It cannot see candidate source during adjudication. -- It can select no-op even when Tamiyo allocated budget and Narset commissioned growth. -- Hard Urabrask defects make a candidate ineligible according to the applicable Leyline policy. +- It can select no-op even when Ugin allocated budget and Aurelia commissioned growth. +- Hard Jin-Gitaxias defects make a candidate ineligible according to the applicable Leyline policy. - The tail-risk veto is adjudicated before any utility comparison and cannot be traded against measured benefit (INV-45). - Every veto, and every thin-margin pass, is recorded per candidate in `tail_veto_results` (INV-31). - Decision thresholds are frozen before confirmatory runs. @@ -125,6 +125,6 @@ The hysteresis band \(\Delta\) is an explicit, versioned Augustin policy paramet #### Smell -> If Augustin asks for a more favourable minibatch after seeing the evidence, the judge has tampered with the case. +> If Isperia asks for a more favourable minibatch after seeing the evidence, the judge has tampered with the case. > If a candidate's measured benefit is cited as a reason to soften the veto, the judge has repriced catastrophe. diff --git a/docs/design/domains/jin-gitaxias.md b/docs/design/domains/jin-gitaxias.md new file mode 100644 index 0000000..e0ee6e2 --- /dev/null +++ b/docs/design/domains/jin-gitaxias.md @@ -0,0 +1,39 @@ + +[← HLD index](../00-INDEX.md) + + +### 13.10 Jin-Gitaxias — Quality Assurance + +#### Responsibilities + +- construct blinded, versioned `TestPlan` records; +- verify the compiled artefact against the canonical specification at runtime; +- test reference-output and gradient agreement; +- test zero-influence behaviour; +- test numerical stability and finite gradients; +- request deterministic replay in Tolaria; +- run regression and stress suites; +- measure immediate and multi-horizon task trajectories; +- measure integration shock, gradient shock, latency and spend; +- quantify uncertainty and evidence completeness; +- classify hard defects and soft warnings; +- and produce signed `QualityReport` records. + +#### QA modes + +**Academy QA** uses full or multi-horizon branch execution for research labels, regression, calibration and curriculum acquisition. + +**Field QA** uses a budgeted hierarchy of local checks, learned measurement surrogates and short rollouts, escalating when uncertainty or risk requires it. + +#### Invariants + +- Jin-Gitaxias cannot issue `ADMIT`, `REJECT`, `NO_OP` or lifecycle tokens. +- It cannot see candidate source where source could affect testing or interpretation. +- It cannot change the candidate, canonical graph or compiled artefact. +- It reports measurements, defects and uncertainty separately from policy utility. +- A test-plan version and evidence digest accompany every report. +- Mandatory tests cannot be weakened after viewing a candidate’s result. + +#### Smell + +> If Jin-Gitaxias issues an admission token, QA has put on the judge’s robes. diff --git a/docs/design/domains/leyline.md b/docs/design/domains/leyline.md index ce0ffed..55cdcda 100644 --- a/docs/design/domains/leyline.md +++ b/docs/design/domains/leyline.md @@ -11,7 +11,7 @@ - define canonical ordering and enum stability; - define `GrowthIntent`, `GrowthRequest`, `RegionContract` and `GrammarProfile` vocabularies; - provide the pure deterministic request resolver; -- validate that resolved requests remain inside Tamiyo's envelope and Kasmina's region contract; +- validate that resolved requests remain inside Ugin's envelope and Wrenn's region contract; - define lifecycle state and transition vocabulary; - define budget, spend and cost units; - define determinism, numerical tolerance and evidence-completeness contracts; @@ -43,4 +43,4 @@ Leyline must not: #### Smell -> If Leyline imports Narset, Augustin, Momir or Kasmina—or if its resolver starts diagnosing the case—the constitution has started governing individual cases. +> If Leyline imports Aurelia, Isperia, Momir or Wrenn—or if its resolver starts diagnosing the case—the constitution has started governing individual cases. diff --git a/docs/design/domains/momir.md b/docs/design/domains/momir.md index affe57c..eb6e040 100644 --- a/docs/design/domains/momir.md +++ b/docs/design/domains/momir.md @@ -8,11 +8,11 @@ - consume Nissa's canonical diagnostic evidence directly; - consume the independently resolved `GrowthRequest` as operational constraints; -- consume optional Sarpadian ancestry or retrieval context through a separate provenance-bearing channel; +- consume optional Urborg ancestry or retrieval context through a separate provenance-bearing channel; - design raw candidate graphs and birth parameters; - model a distribution over useful growths; - provide latent or mixture diversity; -- reconstruct, mutate and recombine Sarpadian lineages during bootstrap; +- reconstruct, mutate and recombine Urborg lineages during bootstrap; - generate ancestry-free candidates after scaffold withdrawal; - report generation uncertainty and measured spend; - and preserve provenance for every proposal. @@ -32,7 +32,7 @@ - Momir outputs raw proposals, not executable modules. - It cannot approve, test or deploy its own work. -- It does not receive Narset hidden state, captions, diagnoses or topology hints. +- It does not receive Aurelia hidden state, captions, diagnoses or topology hints. - Candidate count and orchestration metadata do not become covert semantic conditioning unless explicitly studied. - Candidate diversity is evaluated in canonical and functional space. - A generator version is bound to compatible telemetry, request and grammar versions. @@ -40,6 +40,6 @@ #### Smell -> If Momir is merely colouring in an answer Narset already wrote, the designer has become an executor. If Momir removes candidates because it dislikes their live test results, the author is grading its own examination. +> If Momir is merely colouring in an answer Aurelia already wrote, the designer has become an executor. If Momir removes candidates because it dislikes their live test results, the author is grading its own examination. Momir may learn from historical failures offline. It must not own the live admission boundary. diff --git a/docs/design/domains/nissa.md b/docs/design/domains/nissa.md index d9a768e..631fb72 100644 --- a/docs/design/domains/nissa.md +++ b/docs/design/domains/nissa.md @@ -12,15 +12,15 @@ - perform neutral normalisation, alignment, validity masking and stable feature construction; - bind every observation to the exact host state and Tolaria snapshot; - attach provenance and normalisation manifests; -- publish the same canonical observation independently to Narset and Momir; -- provide only permitted coarse summaries to Tamiyo; +- publish the same canonical observation independently to Aurelia and Momir; +- provide only permitted coarse summaries to Ugin; - and emit stable, versioned `TelemetryEnvelope` records. #### Invariants - Nissa observations do not mutate host gradients or training state. - Germination context is measured without the contribution being diagnosed or replaced. -- Narset and Momir receive the same `observation_id`, not separately interpreted records. +- Aurelia and Momir receive the same `observation_id`, not separately interpreted records. - Every derived signal includes provenance and normalisation semantics. - Task-specific information is included only when the experiment permits it. - Nissa does not infer an editorial conclusion for either consumer. diff --git a/docs/design/domains/oona.md b/docs/design/domains/oona.md deleted file mode 100644 index e72c2af..0000000 --- a/docs/design/domains/oona.md +++ /dev/null @@ -1,40 +0,0 @@ - -[← HLD index](../00-INDEX.md) - - -### 13.14 Oona — Witness and Operator Surface - -#### Responsibilities - -- consume `EventEnvelope` streams; -- maintain append-only flight-recorder storage; -- build materialised views and projections; -- power operator terminal consoles and mission-control-style dashboards; -- expose training runs, branch trees, lineages, budgets, QA and adjudication; -- generate audit bundles; -- alert on invariant breaches; -- and support replay navigation. - -#### Internal separation - -Oona may contain distinct internal packages for: - -- event transport adapters; -- durable flight-recorder storage; -- projection builders; -- TUI adapters; -- dashboard adapters; -- and report generation. - -Leyline owns event schemas. Producers own the truth of their events. Oona owns presentation and projection. - -#### Invariants - -- Training behaviour is unchanged when Oona is disconnected. -- Operator commands, if later introduced, pass through explicit APIs owned by the relevant authority. -- Missing UI data fails visibly rather than silently fabricating a default. -- Oona cannot mutate Tolaria, Kasmina, Narset, Tamiyo or Augustin state through a presentation backchannel. - -#### Smell - -> If changing a dashboard changes the training trace, the witness has become a participant. diff --git a/docs/design/domains/tamiyo.md b/docs/design/domains/tamiyo.md index b96744f..55070f4 100644 --- a/docs/design/domains/tamiyo.md +++ b/docs/design/domains/tamiyo.md @@ -1,43 +1,40 @@ [← HLD index](../00-INDEX.md) - -### 13.4 Tamiyo — Strategic Controller + +### 13.14 Tamiyo — Witness and Operator Surface #### Responsibilities -- allocate parameter, compute, latency and churn budgets across regions; -- set maximum concurrent growth; -- establish global and regional cooldowns; -- balance exploitation and exploration allowances; -- set long-horizon priorities and risk ceilings; -- coordinate multiple Narset-controlled regions or cells; -- react to persistent trends rather than individual noisy steps; -- and emit versioned `StrategicEnvelope` records. +- consume `EventEnvelope` streams; +- maintain append-only flight-recorder storage; +- build materialised views and projections; +- power operator terminal consoles and mission-control-style dashboards; +- expose training runs, branch trees, lineages, budgets, QA and adjudication; +- generate audit bundles; +- alert on invariant breaches; +- and support replay navigation. -#### Inputs +#### Internal separation -- coarse Nissa summaries; -- Sarpadia history and regional performance; -- current host capacity and committed growth; -- aggregate Augustin and Emrakul outcomes; -- strategic task objectives; -- and global resource availability. +Tamiyo may contain distinct internal packages for: -#### Outputs +- event transport adapters; +- durable flight-recorder storage; +- projection builders; +- TUI adapters; +- dashboard adapters; +- and report generation. -- `StrategicEnvelope`; -- allocation updates; -- embargoes or emergency restrictions; -- and strategic-review requests. +Leyline owns event schemas. Producers own the truth of their events. Tamiyo owns presentation and projection. #### Invariants -- Tamiyo operates on a slower cadence than Narset. -- It cannot name a candidate, graph node, kernel or blend tick. -- It cannot directly mutate alpha or issue a local lifecycle transition. -- All local resource use is traceable to an active envelope. +- Training behaviour is unchanged when Tamiyo is disconnected. +- Operator commands, if later introduced, pass through explicit APIs owned by the relevant authority. +- Missing UI data fails visibly rather than silently fabricating a default. +- Tamiyo cannot mutate Tolaria, Wrenn, Aurelia, Ugin or Isperia state through a presentation backchannel. #### Smell -> If Tamiyo chooses the next candidate or alpha increment, strategy has collapsed into micromanagement. +> If changing a dashboard changes the training trace, the witness has become a participant. diff --git a/docs/design/domains/tezzeret.md b/docs/design/domains/tezzeret.md deleted file mode 100644 index dd12276..0000000 --- a/docs/design/domains/tezzeret.md +++ /dev/null @@ -1,27 +0,0 @@ - -[← HLD index](../00-INDEX.md) - - -### 13.9 Tezzeret — Compiler - -#### Responsibilities - -- lower canonical graphs into executable tensor operations; -- select kernels and layouts; -- fuse compatible operations; -- plan memory; -- compile for target hardware and dtype; -- estimate runtime cost; -- report measured compilation spend; -- and emit reproducibility manifests. - -#### Invariants - -- Tezzeret cannot change canonical semantic identity. -- Every optimisation is traceable in the compilation manifest. -- Compiled artefacts must pass Urabrask runtime QA. -- Compilation failure remains distinct from structural rejection and adjudication rejection. - -#### Smell - -> If Tezzeret invents a semantic node to improve predicted performance, the compiler has become Momir. diff --git a/docs/design/domains/ugin.md b/docs/design/domains/ugin.md new file mode 100644 index 0000000..61a9b2f --- /dev/null +++ b/docs/design/domains/ugin.md @@ -0,0 +1,43 @@ + +[← HLD index](../00-INDEX.md) + + +### 13.4 Ugin — Strategic Controller + +#### Responsibilities + +- allocate parameter, compute, latency and churn budgets across regions; +- set maximum concurrent growth; +- establish global and regional cooldowns; +- balance exploitation and exploration allowances; +- set long-horizon priorities and risk ceilings; +- coordinate multiple Aurelia-controlled regions or cells; +- react to persistent trends rather than individual noisy steps; +- and emit versioned `StrategicEnvelope` records. + +#### Inputs + +- coarse Nissa summaries; +- Urborg history and regional performance; +- current host capacity and committed growth; +- aggregate Isperia and Emrakul outcomes; +- strategic task objectives; +- and global resource availability. + +#### Outputs + +- `StrategicEnvelope`; +- allocation updates; +- embargoes or emergency restrictions; +- and strategic-review requests. + +#### Invariants + +- Ugin operates on a slower cadence than Aurelia. +- It cannot name a candidate, graph node, kernel or blend tick. +- It cannot directly mutate alpha or issue a local lifecycle transition. +- All local resource use is traceable to an active envelope. + +#### Smell + +> If Ugin chooses the next candidate or alpha increment, strategy has collapsed into micromanagement. diff --git a/docs/design/domains/urabrask.md b/docs/design/domains/urabrask.md index 5eae91e..2a07963 100644 --- a/docs/design/domains/urabrask.md +++ b/docs/design/domains/urabrask.md @@ -1,39 +1,43 @@ [← HLD index](../00-INDEX.md) - -### 13.10 Urabrask — Quality Assurance + +### 13.9 Urabrask — Compiler #### Responsibilities -- construct blinded, versioned `TestPlan` records; -- verify the compiled artefact against the canonical specification at runtime; -- test reference-output and gradient agreement; -- test zero-influence behaviour; -- test numerical stability and finite gradients; -- request deterministic replay in Tolaria; -- run regression and stress suites; -- measure immediate and multi-horizon task trajectories; -- measure integration shock, gradient shock, latency and spend; -- quantify uncertainty and evidence completeness; -- classify hard defects and soft warnings; -- and produce signed `QualityReport` records. - -#### QA modes - -**Academy QA** uses full or multi-horizon branch execution for research labels, regression, calibration and curriculum acquisition. - -**Field QA** uses a budgeted hierarchy of local checks, learned measurement surrogates and short rollouts, escalating when uncertainty or risk requires it. +- lower canonical graphs into executable tensor operations; +- select kernels and layouts; +- fuse compatible operations; +- plan memory; +- compile for target hardware and dtype; +- estimate runtime cost; +- report measured compilation spend; +- and emit reproducibility manifests. + +#### Operating modes + +Urabrask runs in two modes; both are bound by the same invariants. + +1. **On-demand manufacturing.** When Aurelia commissions a growth, Urabrask + compiles the canonical specification under the declared deadline and + budget, emitting an `ExecutableGrowthArtifact` and a compilation manifest + bound to the canonical semantic hash. +2. **Background industrial R&D.** During idle cycles, Urabrask may compile + canonical backlogs and experiment with kernel fusions, layout plans, and + device-specific optimisations, reporting production discoveries as + versioned compiler improvements. It cannot invent new topologies (that is + Momir's domain) and cannot alter semantic meaning (that is fixed by + Elesh's canonical identity). It may only discover that *adjusting the + alloy generates the same screws faster*. #### Invariants -- Urabrask cannot issue `ADMIT`, `REJECT`, `NO_OP` or lifecycle tokens. -- It cannot see candidate source where source could affect testing or interpretation. -- It cannot change the candidate, canonical graph or compiled artefact. -- It reports measurements, defects and uncertainty separately from policy utility. -- A test-plan version and evidence digest accompany every report. -- Mandatory tests cannot be weakened after viewing a candidate’s result. +- Urabrask cannot change canonical semantic identity. +- Every optimisation is traceable in the compilation manifest. +- Compiled artefacts must pass Jin-Gitaxias runtime QA. +- Compilation failure remains distinct from structural rejection and adjudication rejection. #### Smell -> If Urabrask issues an admission token, QA has put on the judge’s robes. +> If Urabrask invents a semantic node to improve predicted performance, the compiler has become Momir. diff --git a/docs/design/domains/sarpadia.md b/docs/design/domains/urborg.md similarity index 79% rename from docs/design/domains/sarpadia.md rename to docs/design/domains/urborg.md index d5bf5e4..05fe9cd 100644 --- a/docs/design/domains/sarpadia.md +++ b/docs/design/domains/urborg.md @@ -2,7 +2,7 @@ [← HLD index](../00-INDEX.md) -### 13.3 Sarpadia — Historical Infrastructure +### 13.3 Urborg — Historical Infrastructure #### Responsibilities @@ -13,7 +13,7 @@ - provide ordinary retrieval and similarity indices without deploying results; - preserve structural rejects, compilation failures, QA defects, no-op victories and withdrawals; - enforce base-trajectory grouped splits; -- and expose blinded, provenance-safe views to Momir, Urabrask, Augustin and analysis. +- and expose blinded, provenance-safe views to Momir, Jin-Gitaxias, Isperia and analysis. #### Retrieval modes @@ -27,46 +27,46 @@ #### Invariants -- Sarpadia never mutates the live host. +- Urborg never mutates the live host. - A retrieval result is precedent, not a verdict. - Failed and withdrawn records are first-class history. - Bootstrap ancestry is versioned and removable from production inference. -- Narset cannot select an ancestor through Sarpadia. +- Aurelia cannot select an ancestor through Urborg. - Branches from one base trajectory remain in one statistical split. #### Smell -> If Sarpadia forgets the dead, history has become propaganda. If it installs a precedent, history has started governing the present. +> If Urborg forgets the dead, history has become propaganda. If it installs a precedent, history has started governing the present. --- -### 15. Sarpadia Data Model and Learning Use +### 15. Urborg Data Model and Learning Use -Sarpadia is both an operational archive and a research data factory. +Urborg is both an operational archive and a research data factory. #### 15.1 Required records For every case it stores: - complete Tolaria run and snapshot provenance; -- Tamiyo envelope; -- Narset request and action context; +- Ugin envelope; +- Aurelia request and action context; - Nissa telemetry; - every raw Momir graph; - every Elesh rejection and canonicalisation report; -- every Tezzeret artefact manifest; -- every Urabrask test plan and quality report; +- every Urabrask artefact manifest; +- every Jin-Gitaxias test plan and quality report; - every Tolaria branch trace; -- every Augustin admission or maintenance decision; -- Kasmina embodiment state; +- every Isperia admission or maintenance decision; +- Wrenn embodiment state; - maturation and blend history; - Emrakul maintenance history; - and final outcome. #### 15.2 Blinded views -Sarpadia maintains a privileged provenance map and produces separate blinded views: +Urborg maintains a privileged provenance map and produces separate blinded views: ```text qa_view @@ -147,9 +147,9 @@ Retrieval returns evidence and candidate material, not an automatic deployment d - satisfy current Leyline versions; - pass Elesh compatibility and canonicalisation; -- compile through Tezzeret; -- pass Urabrask QA; -- and compete under Augustin against no-op and fresh candidates. +- compile through Urabrask; +- pass Jin-Gitaxias QA; +- and compete under Isperia against no-op and fresh candidates. ##### Future direction (non-binding): contextual retrieval over the precedent store @@ -163,17 +163,17 @@ fewer retrieval failures with the hybrid form and ~67% with reranking (["Introducing Contextual Retrieval"](https://www.anthropic.com/news/contextual-retrieval), Sep 2024), measured on codebase-like corpora — close in character to canonical genotypes and QA evidence. This is an implementation note for -Sarpadia's index layer only. It binds nothing: it changes no contract, no +Urborg's index layer only. It binds nothing: it changes no contract, no blinded view, no invariant, and no retrieval-mode semantics — a retrieval result remains precedent, not a verdict, however the index is built. #### 15.6 Training consumers - **Momir** consumes successful, failed and contrasting candidate sets. -- **Narset** consumes action trajectories and regret labels. -- **Tamiyo** consumes regional allocation outcomes over long horizons. -- **Urabrask’s field surrogate** consumes Academy measurements and evidence-completeness labels. -- **Augustin** may be calibrated or later trained from adjudication cases, but the initial policy is explicit and rule-driven. +- **Aurelia** consumes action trajectories and regret labels. +- **Ugin** consumes regional allocation outcomes over long horizons. +- **Jin-Gitaxias’s field surrogate** consumes Academy measurements and evidence-completeness labels. +- **Isperia** may be calibrated or later trained from adjudication cases, but the initial policy is explicit and rule-driven. - **Emrakul** consumes maintenance, re-adaptation and safe-decay outcomes. No consumer treats multiple branches from one base trajectory as independent validation or test examples. diff --git a/docs/design/domains/kasmina.md b/docs/design/domains/wrenn.md similarity index 65% rename from docs/design/domains/kasmina.md rename to docs/design/domains/wrenn.md index e809e0a..d0cde12 100644 --- a/docs/design/domains/kasmina.md +++ b/docs/design/domains/wrenn.md @@ -2,7 +2,7 @@ [← HLD index](../00-INDEX.md) -### 13.12 Kasmina — Host and Growth Physiology +### 13.12 Wrenn — Host and Growth Physiology #### Responsibilities @@ -20,14 +20,14 @@ #### Invariants -- Kasmina does not decide whether a growth is good. -- Kasmina owns no preferred stock blueprint or reference-seed catalogue. +- Wrenn does not decide whether a growth is good. +- Wrenn owns no preferred stock blueprint or reference-seed catalogue. - Region contracts describe attachment legality and tensor shape, not a suggested phenotype. -- It will not raise influence without a valid Augustin admission warrant. -- The embodied canonical semantic hash matches Augustin’s selected hash and Urabrask’s tested hash. +- It will not raise influence without a valid Isperia admission warrant. +- The embodied canonical semantic hash matches Isperia’s selected hash and Jin-Gitaxias’s tested hash. - Removal uses gradual blend-out except for declared emergency containment. - Occupant-specific economy state resets on slot recycling. #### Smell -> If Kasmina ranks candidates, calculates admission utility, or regains an internal Norm/Attention/Conv catalogue, physiology has acquired opinions and design authority. +> If Wrenn ranks candidates, calculates admission utility, or regains an internal Norm/Attention/Conv catalogue, physiology has acquired opinions and design authority. diff --git a/docs/design/ops/migration.md b/docs/design/ops/migration.md index 3d7298a..5acd376 100644 --- a/docs/design/ops/migration.md +++ b/docs/design/ops/migration.md @@ -23,55 +23,55 @@ The target is not bitwise validation on every future production configuration. T ### 23.2 Controller rename and split -- The existing local/tactical policy responsibility moves to **Narset**. -- **Tamiyo** becomes the strategic controller over regions, budgets, capacity and long horizons. -- Transitional code may use an explicit name such as `LegacyTamiyoController`, but the final API does not use `Tamiyo` for the local controller. -- Any prior allocator implementation migrates to Tamiyo’s target `StrategicEnvelope` interface. +- The existing local/tactical policy responsibility moves to **Aurelia**. +- **Ugin** becomes the strategic controller over regions, budgets, capacity and long horizons. +- Transitional code may use an explicit name such as `LegacyTamiyoController` (the predecessor's tactical controller carried the name Tamiyo under Namespec 1.0), but the final API does not use `Tamiyo` for the local controller — under Namespec 2.0 that name belongs to the witness. +- Any prior allocator implementation migrates to Ugin’s target `StrategicEnvelope` interface. ### 23.3 Observation, commissioning and candidate design -- Nissa becomes the canonical source of Momir's diagnostic input and publishes the same observation identity directly to Narset and Momir. -- Narset emits `GrowthIntent`, not a complete design-bearing `GrowthRequest`. -- Leyline and Kasmina deterministically resolve tensor, grammar and budget constraints. -- Fixed blueprint selection is removed from Narset's production action space. +- Nissa becomes the canonical source of Momir's diagnostic input and publishes the same observation identity directly to Aurelia and Momir. +- Aurelia emits `GrowthIntent`, not a complete design-bearing `GrowthRequest`. +- Leyline and Wrenn deterministically resolve tensor, grammar and budget constraints. +- Fixed blueprint selection is removed from Aurelia's production action space. - **Momir** becomes the generated candidate designer. -- Legacy Norm, Attention, Convolution and related seeds migrate from Kasmina's internal blueprint library into a versioned Sarpadian reference population and research-control package. +- Legacy Norm, Attention, Convolution and related seeds migrate from the legacy embodiment layer's internal blueprint library (Kasmina's, in the predecessor's naming) into a versioned Urborg reference population and research-control package. - Those reference seeds serve as temporary Momir ancestry and permanent experimental controls, not the production ontology. - Compatibility aliases are permitted only during migration and must not reintroduce topology fields into `GrowthIntent`. ### 23.4 Structural and compilation pipeline - **Elesh** is inserted after design and before compilation. -- **Tezzeret** becomes the explicit compiler. +- **Urabrask** becomes the explicit compiler. - Candidate identity is split into raw design, canonical semantic identity and executable artefact identity. ### 23.5 QA and adjudication split Any existing combined screening/economy component is decomposed: -- **Urabrask** owns test planning, runtime checks, branch measurement, regression, uncertainty and `QualityReport`. -- **Augustin** owns hard eligibility, no-op anchoring, policy utility, admission, continued tenancy and warrants. +- **Jin-Gitaxias** owns test planning, runtime checks, branch measurement, regression, uncertainty and `QualityReport`. +- **Isperia** owns hard eligibility, no-op anchoring, policy utility, admission, continued tenancy and warrants. -This split is mandatory. Renaming the old judge to Urabrask while leaving admission logic inside it does not satisfy the target design. +This split is mandatory. Renaming the old judge to Jin-Gitaxias while leaving admission logic inside it does not satisfy the target design. -### 23.6 Kasmina and lifecycle +### 23.6 Wrenn and lifecycle -Kasmina retains host topology, reversible slots, gradient isolation, maturation, blending, commitment, decay mechanics and state serialization. +Wrenn retains host topology, reversible slots, gradient isolation, maturation, blending, commitment, decay mechanics and state serialization. The change is constitutional: -- influence-increasing transitions require Augustin warrants; +- influence-increasing transitions require Isperia warrants; - post-commit ordinary removal requires maintenance warrants; -- Narset and Emrakul have disjoint authority windows. +- Aurelia and Emrakul have disjoint authority windows. ### 23.7 Memory and observability -- The static seed catalogue becomes a versioned **Sarpadian reference population** plus an episodic lineage-aware archive. -- Sarpadia records whether ancestry was supplied, withdrawn, or used only as a blinded control. +- The static seed catalogue becomes a versioned **Urborg reference population** plus an episodic lineage-aware archive. +- Urborg records whether ancestry was supplied, withdrawn, or used only as a blinded control. - Existing telemetry backends remain **Nissa**, with direct publication to Momir added as a locked route. -- Existing operator surfaces migrate under **Oona**. -- Oona gains a newsroom projection showing source observation, assignment, draft, standards, production, QA, judgement, placement, correction and archive. -- Event schemas remain in Leyline and training remains independent of Oona availability. +- Existing operator surfaces migrate under **Tamiyo**. +- Tamiyo gains a newsroom projection showing source observation, assignment, draft, standards, production, QA, judgement, placement, correction and archive. +- Event schemas remain in Leyline and training remains independent of Tamiyo availability. ### 23.8 Namespec migration @@ -79,7 +79,7 @@ Package moves and telemetry names are versioned. Compatibility aliases are time- The migration should include: -- an ADR locking Namespec 1.0; +- an ADR locking the namespec (Namespec 2.0 — ADR-0008); - package-owner READMEs; - import-linter rules; - telemetry producer-name migration; diff --git a/docs/design/ops/observability.md b/docs/design/ops/observability.md index fb91d2c..7d42ffa 100644 --- a/docs/design/ops/observability.md +++ b/docs/design/ops/observability.md @@ -4,26 +4,26 @@ ## 19. Observability and Auditability -Oona exposes the system at three levels. +Tamiyo exposes the system at three levels. ### 19.1 Live operational view - current Tolaria training run, device, precision and execution regime; - current three-axis `ScaffoldState` and gate evidence; - host loss, optimiser progress and data cursor; -- current Tamiyo strategic envelope; +- current Ugin strategic envelope; - current Nissa observation identity and publication recipients; -- current Narset GrowthIntent and resolved GrowthRequest; +- current Aurelia GrowthIntent and resolved GrowthRequest; - bootstrap ancestry status: supplied, withdrawn or control-only; -- Narset’s last action and legal action mask; +- Aurelia’s last action and legal action mask; - Nissa health summaries; - active requests and candidate pools; - Elesh rejection counts and reasons; -- Tezzeret compilation state and spend; -- Urabrask test-plan progress and QA status; +- Urabrask compilation state and spend; +- Jin-Gitaxias test-plan progress and QA status; - Tolaria branch progress and determinism state; -- Augustin no-op margins, verdicts and policy versions; -- Kasmina lifecycle and alpha; +- Isperia no-op margins, verdicts and policy versions; +- Wrenn lifecycle and alpha; - Emrakul maintenance state; - and current global resource use. @@ -36,14 +36,14 @@ Oona exposes the system at three levels. - compilation manifests; - QA tests, defects, warnings and evidence completeness; - measured versus surrogate-predicted trajectories; -- Augustin eligibility and utility decomposition; +- Isperia eligibility and utility decomposition; - lineage and retrieval paths; - lifecycle transitions; - and divergence-localisation traces. ### 19.3 Audit bundle -For any intervention, Oona can export: +For any intervention, Tamiyo can export: ```text TrainingRunSpec and Tolaria execution manifest @@ -55,23 +55,23 @@ ProposalBatchRequest BootstrapAncestryContext or explicit null Raw candidate pool Elesh reports -Tezzeret manifests +Urabrask manifests Snapshot and determinism manifest -Urabrask TestPlan +Jin-Gitaxias TestPlan Tolaria BranchResults -Urabrask QualityReport -Augustin AdmissionDecision -Kasmina lifecycle events -Urabrask maintenance QualityReports -Augustin MaintenanceDecisions +Jin-Gitaxias QualityReport +Isperia AdmissionDecision +Wrenn lifecycle events +Jin-Gitaxias maintenance QualityReports +Isperia MaintenanceDecisions Emrakul maintenance events -Sarpadia record references +Urborg record references ``` The bundle is sufficient to reconstruct: - which observation was published; -- why Narset commissioned work; +- why Aurelia commissioned work; - how the legal request was resolved; - whether ancestry was supplied or withdrawn; - what alternatives existed; @@ -84,7 +84,7 @@ The bundle is sufficient to reconstruct: ### 19.4 Naming-smell view -Oona should surface architecture-smell events such as: +Tamiyo should surface architecture-smell events such as: ```text FORBIDDEN_IMPORT_DETECTED diff --git a/docs/design/ops/repo-structure.md b/docs/design/ops/repo-structure.md index 59168c1..ea7f2ea 100644 --- a/docs/design/ops/repo-structure.md +++ b/docs/design/ops/repo-structure.md @@ -41,7 +41,7 @@ src/simic/ │ ├── profiles.py │ ├── calibration.py │ └── determinism.py -├── sarpadia/ # Append-only history, lineage, bootstrap ancestry, retrieval and datasets +├── urborg/ # Append-only history, lineage, bootstrap ancestry, retrieval and datasets │ ├── records.py │ ├── store.py │ ├── lineage.py @@ -53,13 +53,13 @@ src/simic/ │ ├── withdrawal.py │ ├── splits.py │ └── datasets.py -├── tamiyo/ # Strategic controller and long-horizon allocation +├── ugin/ # Strategic controller and long-horizon allocation │ ├── allocator.py │ ├── envelopes.py │ ├── regional_state.py │ ├── constraints.py │ └── training.py -├── narset/ # Tactical commissioning and pre-commit lifecycle policy +├── aurelia/ # Tactical commissioning and pre-commit lifecycle policy │ ├── controller.py │ ├── actions.py │ ├── masks.py @@ -92,14 +92,14 @@ src/simic/ │ ├── canonicalizer.py │ ├── equivalence.py │ └── reports.py -├── tezzeret/ # Lowering, fusion, compilation and artefact manifests +├── urabrask/ # Lowering, fusion, compilation and artefact manifests │ ├── lowering.py │ ├── fusion.py │ ├── layouts.py │ ├── compiler.py │ ├── costs.py │ └── manifests.py -├── urabrask/ # Dynamic QA and evidence certification +├── jin_gitaxias/ # Dynamic QA and evidence certification │ ├── plans.py │ ├── runtime_conformance.py │ ├── numerical.py @@ -109,7 +109,7 @@ src/simic/ │ ├── uncertainty.py │ ├── reports.py │ └── surrogate.py -├── augustin/ # Independent adjudication and warrants +├── isperia/ # Independent adjudication and warrants │ ├── policy.py │ ├── eligibility.py │ ├── utility.py @@ -118,7 +118,7 @@ src/simic/ │ ├── maintenance.py │ ├── calibration.py │ └── warrants.py -├── kasmina/ # Host model, insertion regions, slots and lifecycle +├── wrenn/ # Host model, insertion regions, slots and lifecycle │ ├── host.py │ ├── regions.py │ ├── region_contracts.py @@ -133,7 +133,7 @@ src/simic/ │ ├── decay.py │ ├── lysis.py │ └── training.py -├── oona/ # Event projections, flight recorder and UI adapters +├── tamiyo/ # Event projections, flight recorder and UI adapters │ ├── bus.py │ ├── recorder.py │ ├── projections.py @@ -155,7 +155,7 @@ src/simic/ │ └── oracle.py ├── curriculum/ │ ├── momir_bootstrap/ -│ ├── narset_acquisition/ +│ ├── aurelia_acquisition/ │ ├── scaffold_withdrawal/ │ └── manifests/ ├── benchmarks/ @@ -203,20 +203,20 @@ This preserves discoverability while retaining the deliberately opaque internal The preferred authority and evidence flow is: ```text - tamiyo + ugin │ StrategicEnvelope ▼ -nissa ──────────► narset ─────► GrowthIntent +nissa ──────────► aurelia ─────► GrowthIntent │ │ │ same TelemetryEnvelope ▼ └────────────► momir ◄──── resolved GrowthRequest ▲ ▲ │ │ optional ancestry leyline resolver - from sarpadia + kasmina RegionContract + from urborg + wrenn RegionContract │ ▼ - elesh ──► tezzeret ──► urabrask + elesh ──► urabrask ──► jin_gitaxias │ TestPlan ▼ @@ -224,16 +224,16 @@ nissa ──────────► narset ─────► GrowthIntent │ BranchResults ▼ - urabrask + jin_gitaxias │ QualityReport ▼ - augustin + isperia │ decision / warrant ┌────────┴────────┐ ▼ ▼ - kasmina emrakul + wrenn emrakul ``` Neutral infrastructure is available across this flow: @@ -241,23 +241,23 @@ Neutral infrastructure is available across this flow: ```text all domains → Leyline contracts agents → Tolaria execution protocols where required -agents → Sarpadia storage/retrieval protocols where required -all domains → Oona events only; decision-critical code never imports Oona +agents → Urborg storage/retrieval protocols where required +all domains → Tamiyo events only; decision-critical code never imports Tamiyo ``` ### 20.3 Prohibited dependency examples ```text -tolaria importing augustin.policy prohibited -urabrask importing augustin.admission prohibited -augustin importing tolaria.engine prohibited -sarpadia importing momir.training prohibited +tolaria importing isperia.policy prohibited +jin_gitaxias importing isperia.admission prohibited +isperia importing tolaria.engine prohibited +urborg importing momir.training prohibited leyline importing any agent implementation prohibited -oona imported by training-critical code prohibited -narset importing momir grammar or generator prohibited -momir importing narset controller or hidden state prohibited -narset constructing TelemetryEnvelope for Momir prohibited -kasmina importing reference blueprint catalogue prohibited +tamiyo imported by training-critical code prohibited +aurelia importing momir grammar or generator prohibited +momir importing aurelia controller or hidden state prohibited +aurelia constructing TelemetryEnvelope for Momir prohibited +wrenn importing reference blueprint catalogue prohibited ``` Integration occurs through Leyline records and protocols, not circular implementation imports. @@ -267,18 +267,18 @@ Integration occurs through Leyline records and protocols, not circular implement ## 30. Repository Handoff and Custody -This document is the authoritative target HLD for repository implementation. Namespec 1.0, the authority boundaries, the newsroom routing rule, the no-op requirement, and the Scaffold Withdrawal Principle are constitutional constraints. They may be changed only through an architecture decision record that names the displaced invariant and its replacement. +This document is the authoritative target HLD for repository implementation. Namespec 2.0 (ADR-0008), the authority boundaries, the newsroom routing rule, the no-op requirement, and the Scaffold Withdrawal Principle are constitutional constraints. They may be changed only through an architecture decision record that names the displaced invariant and its replacement. Codex or any other implementation agent may stage, simplify or defer unbuilt capabilities, but it must not represent a target capability as implemented, collapse two named authorities for convenience without an explicit adapter boundary, or silently turn an Academy scaffold into a permanent production assumption. The first repository milestones should: -1. commit this HLD and an ADR locking Namespec 1.0; +1. commit this HLD and the namespec ADR (Namespec 2.0 — ADR-0008); 2. create the package skeleton and forbidden-import checks; 3. define Leyline contracts, including `ScaffoldManifest` and `ScaffoldState`; 4. place ordinary host training behind Tolaria's Academy profile; 5. establish the exact replay and divergence-localisation harness; -6. preserve legacy stock blueprints only as Sarpadian bootstrap references and research controls; +6. preserve legacy stock blueprints only as Urborg bootstrap references and research controls; 7. implement each subsequent phase against explicit acceptance tests in §21; 8. record every deviation, approximation and unimplemented target in the repository status map. diff --git a/docs/design/programme/curriculum.md b/docs/design/programme/curriculum.md index e45227a..6f9abf5 100644 --- a/docs/design/programme/curriculum.md +++ b/docs/design/programme/curriculum.md @@ -11,8 +11,8 @@ The curriculum teaches causal intervention grammar before broad exploration. It | Dimension | Failure mode protected against | Learn the Land | Controlled relaxation | Operational generalisation | Retained reference capability | |---|---|---|---|---|---| | **Execution — Tolaria** | Attribution error caused by runtime noise | Academy-exact bitwise replay and noiseless paired counterfactuals | Repeated stochastic branches and Field surrogate calibration against Academy | Full validated Field execution with uncertainty, margins and escalation | Academy-exact replay remains the causal oracle, CI profile and divergence laboratory | -| **Host trajectories — Narset curriculum** | Host trajectory variance obscuring intervention timing and lifecycle learning | Fixed, repeated host seeds and identical trajectories | Held-out initialisations from the same family and controlled one-axis changes | Unseen geometries, scales, data orders and task distributions | Acquisition trajectories remain regression and policy-language fixtures | -| **Design prior — Momir** | Generator collapse in a sparse graph search space | Reference reconstruction, imitation and bounded mutation | Ancestry dropout, recombination and partial de novo generation | Null ancestry and the full permitted grammar | Reference seeds remain blinded controls and Sarpadian precedent | +| **Host trajectories — Aurelia curriculum** | Host trajectory variance obscuring intervention timing and lifecycle learning | Fixed, repeated host seeds and identical trajectories | Held-out initialisations from the same family and controlled one-axis changes | Unseen geometries, scales, data orders and task distributions | Acquisition trajectories remain regression and policy-language fixtures | +| **Design prior — Momir** | Generator collapse in a sparse graph search space | Reference reconstruction, imitation and bounded mutation | Ancestry dropout, recombination and partial de novo generation | Null ancestry and the full permitted grammar | Reference seeds remain blinded controls and Urborg precedent | The common progression is: @@ -26,14 +26,14 @@ $$ \text{verify retained invariants}. $$ -Each scaffold protects a different failure mode and has an independent gate. Tolaria may be ready for calibrated Field execution while Momir still needs ancestry; Momir may pass null-ancestry generation while Narset still needs repeated host trajectories. The architecture therefore records a three-axis `ScaffoldState` rather than one global `curriculum_stage` flag. +Each scaffold protects a different failure mode and has an independent gate. Tolaria may be ready for calibrated Field execution while Momir still needs ancestry; Momir may pass null-ancestry generation while Aurelia still needs repeated host trajectories. The architecture therefore records a three-axis `ScaffoldState` rather than one global `curriculum_stage` flag. A confirmatory transition withdraws one scaffold at a time. Two or more may change together only when their interaction is the declared experiment and the corresponding single-axis controls have already been measured. This rule prevents a failed run from becoming uninterpretable. The first withdrawal gates are: - **Tolaria:** Field-to-Academy ranking regret, accept/no-op disagreement, uncertainty coverage and tail-failure rate remain inside declared limits; ambiguous cases can still escalate to Academy. -- **Host distribution:** Narset's intervention timing, harmful-action rate and lifecycle completion remain stable on held-out in-family initialisations before task-family expansion. +- **Host distribution:** Aurelia's intervention timing, harmful-action rate and lifecycle completion remain stable on held-out in-family initialisations before task-family expansion. - **Momir:** structural validity, positive-candidate coverage and reference-relative utility remain acceptable with `BootstrapAncestryContext = null`. Hidden correlations between scaffolds are tested explicitly. Fixed host seeds may be unusually deterministic, and stock reference seeds may cover only the viable repairs for those seeds. The final programme therefore measures selected interaction cells before claiming full scaffold-free operation. @@ -46,7 +46,7 @@ Validate: - Namespec package ownership and forbidden imports; - Leyline schema round trips; -- direct Nissa publication of one observation identity to Narset and Momir; +- direct Nissa publication of one observation identity to Aurelia and Momir; - rejection of diagnostic or topology fields in `GrowthIntent`; - deterministic `GrowthIntent` to `GrowthRequest` resolution; - Tolaria ordinary host training; @@ -55,7 +55,7 @@ Validate: - bit-identical common-future execution under Tolaria's Academy-exact profile; - `ScaffoldManifest` and `ScaffoldState` validation; - rejection of multi-axis withdrawal without an interaction experiment identifier; -- Kasmina isolated maturation; +- Wrenn isolated maturation; - smooth blend-in and blend-out; - lifecycle authority enforcement; - rollback; @@ -65,7 +65,7 @@ No learned controller or generator is required. ### Stage 1 — Momir reference-seed bootstrap -Freeze the host at selected snapshots. Fix the insertion site, request and budget. Build a versioned Sarpadian reference population of conventional and synthetic known-good canonical cells. +Freeze the host at selected snapshots. Fix the insertion site, request and budget. Build a versioned Urborg reference population of conventional and synthetic known-good canonical cells. #### Stage 1A — Structural literacy @@ -79,7 +79,7 @@ Show Momir the same Nissa context used to evaluate each reference. Train it to p host diagnostic context → viable known structure ``` -without granting Narset a blueprint action. +without granting Aurelia a blueprint action. #### Stage 1C — Local mutation @@ -97,7 +97,7 @@ Train on the ordered neighbourhood rather than only the winner. #### Stage 1D — Recombination -Permit composition of compatible substructures from multiple ancestors. Elesh must identify malformed, redundant and equivalent combinations. Tezzeret must compile canonical meaning rather than raw syntax. +Permit composition of compatible substructures from multiple ancestors. Elesh must identify malformed, redundant and equivalent combinations. Urabrask must compile canonical meaning rather than raw syntax. #### Stage 1E — Ancestry-optional generation @@ -109,7 +109,7 @@ Evaluate with `BootstrapAncestryContext = null` on held-out host states. Momir m ### Stage 2 — Structural conformance and compilation school -Stress Momir, Elesh and Tezzeret independently with: +Stress Momir, Elesh and Urabrask independently with: - malformed graphs; - shape edge cases; @@ -123,11 +123,11 @@ Stress Momir, Elesh and Tezzeret independently with: The goal is reliable canonical identity and compilation before task utility is involved. -### Stage 3 — Urabrask QA school +### Stage 3 — Jin-Gitaxias QA school Use known canonical specifications and artefacts with injected defects. -Teach and test Urabrask to detect: +Teach and test Jin-Gitaxias to detect: - semantic drift; - wrong gradients; @@ -141,17 +141,17 @@ Teach and test Urabrask to detect: The expected output is a reliable `QualityReport`, not an admission decision. -### Stage 4 — Augustin adjudication school +### Stage 4 — Isperia adjudication school -Hold Urabrask reports fixed and vary policy cases. +Hold Jin-Gitaxias reports fixed and vary policy cases. -Teach or calibrate Augustin to: +Teach or calibrate Isperia to: - reject hard-defect candidates; - choose no-op when all candidates are net harmful; - prefer lower-cost candidates at equal benefit; - request retest when uncertainty is excessive; -- obey Tamiyo's envelope; +- obey Ugin's envelope; - and produce stable, explicit reasons. This isolates judgement from QA quality. @@ -170,13 +170,13 @@ Teach the system to distinguish: - admission value versus continued-tenancy value; - and intervention signal versus execution noise. -This stage creates the Academy evidence used to validate Field QA and Augustin's policy. It then repeats selected candidate pools under the calibrated-stochastic profile to estimate execution variance, ranking stability and accept/no-op decision disagreement. Field execution cannot advance merely because mean loss traces look similar; its operational decisions and uncertainty coverage must meet the declared Tolaria withdrawal gate. +This stage creates the Academy evidence used to validate Field QA and Isperia's policy. It then repeats selected candidate pools under the calibrated-stochastic profile to estimate execution variance, ranking stability and accept/no-op decision disagreement. Field execution cannot advance merely because mean loss traces look similar; its operational decisions and uncertainty coverage must meet the declared Tolaria withdrawal gate. -### Stage 6 — Narset tactical language acquisition +### Stage 6 — Aurelia tactical language acquisition -Use a known-good candidate source and reliable QA/adjudication so tactical failure cannot be blamed on Momir, Urabrask or Augustin. +Use a known-good candidate source and reliable QA/adjudication so tactical failure cannot be blamed on Momir, Jin-Gitaxias or Isperia. -Nissa continues to publish source evidence directly. Narset is trained only to commission and manage work: +Nissa continues to publish source evidence directly. Aurelia is trained only to commission and manage work: ```text WAIT @@ -195,7 +195,7 @@ Use short action-sequence search or counterfactual enumeration to create imitati ### Stage 7 — Emrakul maintenance school -Use committed structures with known utility trajectories and fixed Augustin maintenance policy. +Use committed structures with known utility trajectories and fixed Isperia maintenance policy. Calibrate: @@ -209,11 +209,11 @@ LYSE Include useful structures, host-dependent but replaceable structures, redundant structures, long-term regressors and regime-specific structures that become obsolete. -### Stage 8 — Tamiyo strategic allocation school +### Stage 8 — Ugin strategic allocation school -Introduce multiple regions or multiple Narset-controlled cells with constrained global resources. +Introduce multiple regions or multiple Aurelia-controlled cells with constrained global resources. -Teach Tamiyo to allocate: +Teach Ugin to allocate: - capacity; - intervention quotas; @@ -223,7 +223,7 @@ Teach Tamiyo to allocate: - adjudication risk; - and maintenance pressure. -Local Narset, Urabrask, Augustin and Emrakul behaviour is held fixed initially so strategic failure is attributable. +Local Aurelia, Jin-Gitaxias, Isperia and Emrakul behaviour is held fixed initially so strategic failure is attributable. ### Stage 9 — Joint few-trajectory, many-variation training @@ -254,7 +254,7 @@ Begin with exact repetition, then vary one ordinary experimental axis at a time: Add request-channel ablations: - same telemetry and effective constraints, different irrelevant serialisation; -- same resolved request, different Narset implementation; +- same resolved request, different Aurelia implementation; - candidate count varied outside Momir's semantic condition; - and equivalent resource-class encodings canonicalised by the resolver. @@ -299,4 +299,4 @@ Evaluate on: - small image tasks; - and larger benchmarks. -The broad environment is the examination, not the initial classroom. Narset's repeated host-seed curriculum and Momir's reference-ancestry curriculum are both successful only if the scaffolds can be removed. Tolaria's execution curriculum is successful when Field operation remains decision-calibrated against Academy rather than when Academy is deleted. Final reporting names the exact `ScaffoldState` of every result and distinguishes scaffold-free operation from reference-assisted escalation. +The broad environment is the examination, not the initial classroom. Aurelia's repeated host-seed curriculum and Momir's reference-ancestry curriculum are both successful only if the scaffolds can be removed. Tolaria's execution curriculum is successful when Field operation remains decision-calibrated against Academy rather than when Academy is deleted. Final reporting names the exact `ScaffoldState` of every result and distinguishes scaffold-free operation from reference-assisted escalation. diff --git a/docs/design/programme/evaluation.md b/docs/design/programme/evaluation.md index d7ec4fc..a2c756a 100644 --- a/docs/design/programme/evaluation.md +++ b/docs/design/programme/evaluation.md @@ -9,11 +9,11 @@ - package ownership manifest is complete; - every package declares its verb or infrastructure context; - forbidden imports fail CI; -- Urabrask cannot import Augustin policy; -- Augustin cannot import Tolaria execution; +- Jin-Gitaxias cannot import Isperia policy; +- Isperia cannot import Tolaria execution; - Leyline imports no agent package; -- Sarpadia storage imports no agent policy; -- Oona is absent from training-critical dependency paths; +- Urborg storage imports no agent policy; +- Tamiyo is absent from training-critical dependency paths; - and public cross-boundary types use plain-English names. ### 21.2 Leyline contract tests @@ -30,14 +30,14 @@ ### 21.3 Observation routing and assignment-brief tests -- Nissa publishes one `observation_id` to Narset and Momir. -- Narset cannot construct or substitute a second Momir-facing telemetry record. +- Nissa publishes one `observation_id` to Aurelia and Momir. +- Aurelia cannot construct or substitute a second Momir-facing telemetry record. - `GrowthIntent` rejects every forbidden diagnostic, topology, ancestry and free-form design field. - Equivalent intent representations canonicalise identically. - Request resolution is deterministic and cannot exceed the active envelope. -- Region contracts and grammar profiles are system-derived rather than Narset-authored. +- Region contracts and grammar profiles are system-derived rather than Aurelia-authored. - Observation, intent, request and Tolaria snapshot mismatches fail closed. -- Replacing Narset with another controller that emits the same canonical intent does not change Momir's output distribution. +- Replacing Aurelia with another controller that emits the same canonical intent does not change Momir's output distribution. - Changing candidate count outside Momir's semantic condition does not change single-candidate semantics. ### 21.4 Tolaria training, determinism and Field-calibration gates @@ -76,7 +76,7 @@ - parent-relative and reference-frontier improvement; - ancestry-dropout and scaffold-free generation; - output invariance to irrelevant request serialisation and orchestration metadata; -- no dependency on Narset hidden state or captioned telemetry; +- no dependency on Aurelia hidden state or captioned telemetry; - and valid production inference with `BootstrapAncestryContext = null`. ### 21.6 Elesh tests @@ -90,7 +90,7 @@ - non-equivalent-graph hash separation; - and semantics-preserving pruning. -### 21.7 Tezzeret tests +### 21.7 Urabrask tests - deterministic compilation manifests; - canonical-hash preservation; @@ -99,9 +99,9 @@ - measured cost reporting; - and reproducible artefact identity. -Reference-versus-compiled behaviour is certified by Urabrask integration tests rather than trusted as a compiler self-test. +Reference-versus-compiled behaviour is certified by Jin-Gitaxias integration tests rather than trusted as a compiler self-test. -### 21.8 Urabrask QA tests +### 21.8 Jin-Gitaxias QA tests - `QualityReport` contains no admission verdict; - candidate source is absent from the QA view; @@ -115,7 +115,7 @@ Reference-versus-compiled behaviour is certified by Urabrask integration tests r - evidence digests bind to the exact plan and results; - and field-surrogate error is measured against Academy QA. -### 21.9 Augustin adjudication tests +### 21.9 Isperia adjudication tests - no-op is always available and exactly zero; - source labels are absent from the adjudication view; @@ -123,15 +123,15 @@ Reference-versus-compiled behaviour is certified by Urabrask integration tests r - all-net-harmful pools select no-op; - equal-benefit cases prefer lower declared cost according to policy; - excessive uncertainty produces retest or defer; -- Tamiyo envelope limits are enforced; +- Ugin envelope limits are enforced; - thresholds remain frozen in confirmatory mode; - warrants bind to the selected semantic hash and evidence digest; - and repeated identical evidence produces identical decisions. -### 21.10 Kasmina tests +### 21.10 Wrenn tests - admitted hash equals embodied hash; -- no influence before an Augustin warrant; +- no influence before an Isperia warrant; - gradient isolation; - blend monotonicity where required; - smooth decay; @@ -140,7 +140,7 @@ Reference-versus-compiled behaviour is certified by Urabrask integration tests r - invalid-warrant rejection; - and occupant-state reset on recycling. -### 21.11 Sarpadia tests +### 21.11 Urborg tests - full-pool retention; - structural-reject retention; @@ -153,21 +153,21 @@ Reference-versus-compiled behaviour is certified by Urabrask integration tests r - retrieval compatibility filtering; - explicit ancestry-present versus ancestry-null provenance; - reference controls remain available after scaffold withdrawal; -- Narset cannot select or mutate ancestry context; +- Aurelia cannot select or mutate ancestry context; - and raw/canonical/artifact/evidence/decision identity linkage. -### 21.12 Tamiyo and Narset authority tests +### 21.12 Ugin and Aurelia authority tests -- Tamiyo cannot issue a lifecycle command; -- Narset cannot exceed an envelope; -- Narset cannot name a raw graph implementation; -- Narset cannot include diagnosis, topology, rank, width, operator, ancestor or mechanism fields in `GrowthIntent`; -- Narset cannot construct a Momir-facing telemetry record; -- Narset cannot select bootstrap ancestors; +- Ugin cannot issue a lifecycle command; +- Aurelia cannot exceed an envelope; +- Aurelia cannot name a raw graph implementation; +- Aurelia cannot include diagnosis, topology, rank, width, operator, ancestor or mechanism fields in `GrowthIntent`; +- Aurelia cannot construct a Momir-facing telemetry record; +- Aurelia cannot select bootstrap ancestors; - canonical-equivalent intents produce identical resolved requests; - request values cannot exceed the bandwidth allowed by declared coarse classes; -- Narset cannot bypass Urabrask or Augustin; -- and commitment removes Narset's ordinary authority. +- Aurelia cannot bypass Jin-Gitaxias or Isperia; +- and commitment removes Aurelia's ordinary authority. ### 21.13 Emrakul tests @@ -180,9 +180,9 @@ Reference-versus-compiled behaviour is certified by Urabrask integration tests r - real lysis counted once; - and capacity return after recycling. -### 21.14 Oona isolation tests +### 21.14 Tamiyo isolation tests -- training trace is identical with Oona enabled and disabled; +- training trace is identical with Tamiyo enabled and disabled; - missing projection data fails visibly; - audit bundle completeness; - no direct state mutation path from UI adapters; @@ -258,11 +258,11 @@ The system is evaluated as a quality–cost–stability frontier rather than by - equivalence-detection precision; - compile latency; - runtime cost-estimation error; -- Urabrask semantic-conformance failure rate; +- Jin-Gitaxias semantic-conformance failure rate; - gradient-conformance failure rate; - and cross-device semantic agreement. -### 22.5 Urabrask QA quality +### 22.5 Jin-Gitaxias QA quality - defect-detection sensitivity and specificity; - evidence reproducibility; @@ -273,7 +273,7 @@ The system is evaluated as a quality–cost–stability frontier rather than by - false-pass and false-fail rates; - and QA cost–coverage Pareto frontier. -### 22.6 Augustin adjudication quality +### 22.6 Isperia adjudication quality - best-candidate selection regret; - no-op precision and recall; @@ -285,7 +285,7 @@ The system is evaluated as a quality–cost–stability frontier rather than by - provider-blindness audit results; - and reason-code completeness. -### 22.7 Narset tactical quality +### 22.7 Aurelia tactical quality - intervention timing regret; - unnecessary-intervention rate; @@ -300,7 +300,7 @@ The system is evaluated as a quality–cost–stability frontier rather than by - abort-too-late rate; - and lifecycle completion rate. -### 22.8 Tamiyo strategic quality +### 22.8 Ugin strategic quality - budget utilisation; - regional starvation rate; diff --git a/docs/design/programme/learning.md b/docs/design/programme/learning.md index fa97de0..df6bd6a 100644 --- a/docs/design/programme/learning.md +++ b/docs/design/programme/learning.md @@ -27,9 +27,9 @@ Candidate-design objectives may include: The first generator should be a small deterministic or latent-conditioned network. Flow or diffusion models are introduced only if simpler models fail to provide useful candidate coverage. -Momir is trained to consume Nissa telemetry and the resolved request as separate inputs. During bootstrap it may additionally consume `BootstrapAncestryContext`; ancestry dropout progressively replaces this with null context. A training-only utility head does not grant Momir live admission authority. At inference, Momir proposes a pool that still passes through Elesh, Tezzeret, Urabrask and Augustin. +Momir is trained to consume Nissa telemetry and the resolved request as separate inputs. During bootstrap it may additionally consume `BootstrapAncestryContext`; ancestry dropout progressively replaces this with null context. A training-only utility head does not grant Momir live admission authority. At inference, Momir proposes a pool that still passes through Elesh, Urabrask, Jin-Gitaxias and Isperia. -### 17.2 Narset +### 17.2 Aurelia Recommended training sequence: @@ -40,13 +40,13 @@ Recommended training sequence: 5. reinforcement-learning refinement; 6. held-out generalisation. -Narset's objective must not pay it for outcomes caused solely by Tamiyo granting a larger budget. It is evaluated on action quality inside the envelope it received. +Aurelia's objective must not pay it for outcomes caused solely by Ugin granting a larger budget. It is evaluated on action quality inside the envelope it received. -The `GrowthIntent` action channel is deliberately coarse and canonical. Narset is never rewarded for selecting a topology family, ancestor, diagnosis, rank, width or operator. Joint training with Momir must include anti-collusion tests so the pair cannot encode structural hints in nominally irrelevant continuous values, field ordering, candidate count or aliases. Early training should hold Momir fixed or use a known-good provider so Narset learns commissioning rather than co-design. +The `GrowthIntent` action channel is deliberately coarse and canonical. Aurelia is never rewarded for selecting a topology family, ancestor, diagnosis, rank, width or operator. Joint training with Momir must include anti-collusion tests so the pair cannot encode structural hints in nominally irrelevant continuous values, field ordering, candidate count or aliases. Early training should hold Momir fixed or use a known-good provider so Aurelia learns commissioning rather than co-design. -### 17.3 Tamiyo +### 17.3 Ugin -Tamiyo learns on a slower horizon and initially consumes aggregate regional outcomes rather than raw local telemetry. +Ugin learns on a slower horizon and initially consumes aggregate regional outcomes rather than raw local telemetry. Training may use: @@ -56,9 +56,9 @@ Training may use: - constrained optimisation; - or delayed long-horizon utility. -Tamiyo is introduced only after Narset’s local behaviour, Augustin’s adjudication and Emrakul’s maintenance are stable enough that strategic outcomes are interpretable. +Ugin is introduced only after Aurelia’s local behaviour, Isperia’s adjudication and Emrakul’s maintenance are stable enough that strategic outcomes are interpretable. -### 17.4 Urabrask field surrogate +### 17.4 Jin-Gitaxias field surrogate A field-QA surrogate may be trained against Academy-exact `BranchResult` and `QualityReport` labels. It predicts: @@ -70,7 +70,7 @@ A field-QA surrogate may be trained against Academy-exact `BranchResult` and `Qu - evidence incompleteness; - and escalation need. -It does **not** predict `ADMIT` as an authoritative output. Its result is part of Urabrask's evidence process and remains auditable against Academy QA. +It does **not** predict `ADMIT` as an authoritative output. Its result is part of Jin-Gitaxias's evidence process and remains auditable against Academy QA. The surrogate's withdrawal gate is decision-aware. It must demonstrate acceptable: @@ -82,9 +82,9 @@ The surrogate's withdrawal gate is decision-aware. It must demonstrate acceptabl Calibration expires when the host family, grammar level, compiler backend, execution profile or evidence distribution moves outside the certified envelope. Expired or low-margin cases escalate to Academy rather than silently extending the surrogate's authority. -### 17.5 Augustin +### 17.5 Isperia -The initial Augustin is explicit, rule-driven and pre-registered. It applies: +The initial Isperia is explicit, rule-driven and pre-registered. It applies: - hard eligibility; - no-op anchoring; @@ -95,34 +95,34 @@ The initial Augustin is explicit, rule-driven and pre-registered. It applies: Later learned adjudication is possible, but only after: -- Urabrask evidence is trustworthy; +- Jin-Gitaxias evidence is trustworthy; - validation and test partitions are sealed; - decision calibration is measurable; - reasons and policy versions remain inspectable; - and a fixed-rule baseline is understood. -A learned Augustin still cannot inspect candidate source or collect its own evidence. +A learned Isperia still cannot inspect candidate source or collect its own evidence. ### 17.6 Emrakul -The first maintenance behaviour is fixed and pre-registered. Learned maintenance begins only after Augustin continued-tenancy decisions and Urabrask re-adaptation measurements are reliable. +The first maintenance behaviour is fixed and pre-registered. Learned maintenance begins only after Isperia continued-tenancy decisions and Jin-Gitaxias re-adaptation measurements are reliable. Emrakul may learn *how* to execute safe sedation and decay efficiently. It does not learn to override the tenancy verdict. -### 17.7 Elesh and Tezzeret +### 17.7 Elesh and Urabrask Elesh is primarily rule-driven. Learned structural analyses may be added only where they cannot replace hard safety and type checks. -Tezzeret may use learned compilation heuristics, but semantic equivalence remains verified by Urabrask runtime QA against the Elesh canonical reference. +Urabrask may use learned compilation heuristics, but semantic equivalence remains verified by Jin-Gitaxias runtime QA against the Elesh canonical reference. ### 17.8 Nissa -Nissa may learn feature extractors or diagnostic embeddings only under a separately defined observation objective. It is not trained end to end through Narset's action reward or Momir's preferred output in a way that would turn the observation into an undocumented policy message. +Nissa may learn feature extractors or diagnostic embeddings only under a separately defined observation objective. It is not trained end to end through Aurelia's action reward or Momir's preferred output in a way that would turn the observation into an undocumented policy message. Any learned telemetry must retain: - stable schema and basis semantics; -- direct publication to Narset and Momir; +- direct publication to Aurelia and Momir; - observation and snapshot identity; - provenance; - information ablations; @@ -130,14 +130,14 @@ Any learned telemetry must retain: The existence of useful latent information is not itself a violation; the violation is allowing one agent to rewrite or selectively expose the evidence another agent receives. -### 17.9 Tolaria, Leyline and Sarpadia +### 17.9 Tolaria, Leyline and Urborg These infrastructure domains are not policy learners. - Tolaria may autotune execution or compilation-independent scheduling, but it may not optimise for candidate preference. - Leyline may generate code from schemas and deterministically resolve requests, but it does not learn case-specific rules or infer diagnoses. -- Sarpadia may learn retrieval indices, but retrieval remains precedent selection rather than deployment policy. -- Sarpadia's bootstrap reference population is curated and versioned by curriculum manifests; it does not become a hidden production ontology. +- Urborg may learn retrieval indices, but retrieval remains precedent selection rather than deployment policy. +- Urborg's bootstrap reference population is curated and versioned by curriculum manifests; it does not become a hidden production ontology. - Request resolution must remain a pure, reproducible transformation whose output can be recomputed from recorded inputs. - Tolaria may learn or autotune Field execution only inside a profile calibrated against Academy-exact evidence; exact replay remains available as a non-learned reference path. - `ScaffoldState` is declarative experiment metadata, not a policy output inferred by infrastructure. diff --git a/docs/design/programme/phases.md b/docs/design/programme/phases.md index 22ed991..6f1f405 100644 --- a/docs/design/programme/phases.md +++ b/docs/design/programme/phases.md @@ -14,27 +14,27 @@ The first coherent implementation contains: - exact Tolaria snapshot, restore, branch and common-future replay under one Academy reference profile; - one explicit three-axis `ScaffoldState` and scaffold manifest registry; - a calibrated-stochastic harness capable of measuring Field-to-Academy disagreement, even if full Field operation remains disabled; -- one fixed Tamiyo strategic envelope; -- one heuristic Narset tactical controller; -- one Nissa telemetry schema published directly to Narset and Momir; -- one narrow Narset GrowthIntent and deterministic request resolver; -- one versioned Sarpadian stock-reference bootstrap corpus; +- one fixed Ugin strategic envelope; +- one heuristic Aurelia tactical controller; +- one Nissa telemetry schema published directly to Aurelia and Momir; +- one narrow Aurelia GrowthIntent and deterministic request resolver; +- one versioned Urborg stock-reference bootstrap corpus; - one small deterministic or latent-conditioned Momir designer that also runs with ancestry absent; - one rule-driven Elesh verifier and canonicaliser; -- one eager-mode Tezzeret compiler with explicit manifests; -- one rule-driven Urabrask QA suite with mandatory no-op measurement; -- one fixed, provider-blind Augustin judge; -- fixed Kasmina maturation and blend schedules; +- one eager-mode Urabrask compiler with explicit manifests; +- one rule-driven Jin-Gitaxias QA suite with mandatory no-op measurement; +- one fixed, provider-blind Isperia judge; +- fixed Wrenn maturation and blend schedules; - fixed Emrakul safe-maintenance rules; -- Sarpadia retention of complete candidate pools, evidence and decisions; -- Oona flight recording and branch inspection; +- Urborg retention of complete candidate pools, evidence and decisions; +- Tamiyo flight recording and branch inspection; - reference-seed bootstrap, scaffold-withdrawal, static and short-horizon counterfactual curricula; - and random, analytic, retrieval, online-optimised and no-op controls. The MVP does **not** require: -- learned Tamiyo; -- learned Augustin; +- learned Ugin; +- learned Isperia; - learned Emrakul; - arbitrary graph generation; - asynchronous CUDA code generation; @@ -48,7 +48,7 @@ The MVP does **not** require: ### Phase A — Namespec, Leyline and dependency boundaries -- record Namespec 1.0 in an ADR; +- record the namespec in an ADR (Namespec 2.0 — ADR-0008); - define package ownership and forbidden authority; - define all core contracts; - encode lifecycle and warrant rules; @@ -63,9 +63,9 @@ The MVP does **not** require: - define the Academy-exact runtime profile; - establish deterministic mainline traces; - implement `ScaffoldManifest` and `ScaffoldState` recording; -- and ensure Kasmina exposes a neutral host-runtime protocol. +- and ensure Wrenn exposes a neutral host-runtime protocol. -### Phase C — Kasmina, Elesh and Tezzeret mechanics +### Phase C — Wrenn, Elesh and Urabrask mechanics - implement the universal growth envelope; - define raw and canonical graph IRs; @@ -83,7 +83,7 @@ The MVP does **not** require: - measure ranking, decision and tail disagreement against Academy; - and keep Field profiles disabled until the declared gate passes. -### Phase E — Urabrask QA +### Phase E — Jin-Gitaxias QA - implement `TestPlan`; - implement runtime semantic and gradient conformance; @@ -93,7 +93,7 @@ The MVP does **not** require: - establish Academy versus Field QA; - and implement escalation from uncertain Field evidence to Academy-exact retest. -### Phase F — Augustin adjudication and controls +### Phase F — Isperia adjudication and controls - implement hard eligibility; - implement mandatory no-op policy; @@ -103,9 +103,9 @@ The MVP does **not** require: - add random, analytic, retrieval and bounded online controls; - and produce the QA-cost and adjudication-regret curves. -### Phase G — Sarpadia and Momir bootstrap curriculum +### Phase G — Urborg and Momir bootstrap curriculum -- migrate legacy stock blueprints into a versioned reference population outside Kasmina; +- migrate legacy stock blueprints into a versioned reference population outside Wrenn; - store complete pools, reports, decisions and no-op cases; - implement blinded views, lineage, equivalence and ancestry records; - collect frozen-state teachers, parents, mutations and failures; @@ -115,9 +115,9 @@ The MVP does **not** require: - retain stock seeds as blinded controls after ancestry withdrawal; - and consume losers through ranking or utility objectives. -### Phase H — Nissa routing and Narset lifecycle integration +### Phase H — Nissa routing and Aurelia lifecycle integration -- publish one Nissa observation directly to Narset and Momir; +- publish one Nissa observation directly to Aurelia and Momir; - replace blueprint actions with `GrowthIntent`; - implement deterministic `GrowthRequest` resolution; - train local commissioning and lifecycle behaviour with known-good candidates; @@ -128,17 +128,17 @@ The MVP does **not** require: ### Phase I — Emrakul maintenance - implement continued-tenancy QA; -- implement Augustin maintenance decisions; +- implement Isperia maintenance decisions; - calibrate sedation, decay and lysis execution; - and separate host dependence from intrinsic value. -### Phase J — Tamiyo strategic allocation +### Phase J — Ugin strategic allocation - introduce multiple regions or cells; - allocate global resources; - and train or search strategic policies after local behaviour is stable. -### Phase K — Oona and scale +### Phase K — Tamiyo and scale - complete event projections and audit bundles; - expose architecture-smell events; diff --git a/docs/design/programme/risks-and-open-decisions.md b/docs/design/programme/risks-and-open-decisions.md index 4fee310..d1e00cc 100644 --- a/docs/design/programme/risks-and-open-decisions.md +++ b/docs/design/programme/risks-and-open-decisions.md @@ -10,12 +10,12 @@ | **Mainline–branch divergence** | Counterfactual results do not describe live training | One step engine; parity tests; explicit approximation error | | **Momir mode collapse** | Best-of-\(K\) candidates are functionally identical | Explicit latent, winner-take-all objective, functional diversity metrics | | **Elesh overreach** | Structural gate pre-judges utility and biases the pool | Deny reward/future-utility inputs; rule-driven hard checks | -| **Tezzeret semantic drift** | Compiled artefact differs from canonical design | Canonical hash, manifests and Urabrask runtime conformance | -| **Urabrask judicial creep** | QA begins issuing admission recommendations or tokens | `QualityReport` schema excludes verdicts; forbidden imports; tests | -| **Augustin evidentiary creep** | Judge alters tests or gathers favourable evidence | Augustin consumes immutable reports only; no Tolaria dependency | +| **Urabrask semantic drift** | Compiled artefact differs from canonical design | Canonical hash, manifests and Jin-Gitaxias runtime conformance | +| **Jin-Gitaxias judicial creep** | QA begins issuing admission recommendations or tokens | `QualityReport` schema excludes verdicts; forbidden imports; tests | +| **Isperia evidentiary creep** | Judge alters tests or gathers favourable evidence | Isperia consumes immutable reports only; no Tolaria dependency | | **QA overfitting** | Test plans are tuned to known candidate families | Pre-versioned plans, source blindness, sealed regression fixtures | | **Adjudication overfitting** | Thresholds are tuned after seeing confirmatory results | Validation-only calibration and frozen policy versions | -| **Provider leakage** | Candidate origin influences tests or judgement | Blinded Sarpadia views and source-absence tests | +| **Provider leakage** | Candidate origin influences tests or judgement | Blinded Urborg views and source-absence tests | | **Telemetry underspecification** | Different deficits appear identical | Orientation-bearing gradients, temporal context and information ablations | | **Moving target** | Candidate becomes stale before integration | Latency budgets, staleness curves and re-qualification | | **Counterfactual nondeterminism** | Branch differences reflect runtime noise | Academy-exact causal reference, divergence localisation, measured Field uncertainty and escalation | @@ -23,11 +23,11 @@ | **Survivorship bias** | System cannot learn refusal or failure modes | Retain structural rejects, QA failures, no-op and long-term regressors | | **Host co-adaptation** | Same-host ablation exaggerates value | Separate no-op and re-adaptation branches | | **Install–lyse oscillation** | Boundary growths churn as execution noise moves the estimate | Threshold hysteresis (INV-33, ADR-0005): admit strictly above retain by a versioned band sized against measured σ_exec; churn metrics; cooldowns as frequency limiter only; pre-registration | -| **Tamiyo micromanagement** | Strategic controller becomes local policy | Slow cadence, aggregate inputs and interface prohibition | -| **Narset budget escape** | Tactical controller creates ungoverned capacity | Envelope validation in Leyline, Augustin and Kasmina | -| **Narset co-design / editorial angle** | Tactical policy encodes diagnosis, topology or ancestry into the assignment | Narrow `GrowthIntent`; schema-forbidden fields; direct Nissa-to-Momir route | -| **Telemetry mediation** | Momir sees Narset's interpretation rather than the host observation | One canonical Nissa publication with shared observation identity | -| **Covert request channel** | Narset and Momir encode designs through continuous budgets, aliases or candidate count | Coarse enums, deterministic canonical resolution, invariance and anti-collusion tests | +| **Ugin micromanagement** | Strategic controller becomes local policy | Slow cadence, aggregate inputs and interface prohibition | +| **Aurelia budget escape** | Tactical controller creates ungoverned capacity | Envelope validation in Leyline, Isperia and Wrenn | +| **Aurelia co-design / editorial angle** | Tactical policy encodes diagnosis, topology or ancestry into the assignment | Narrow `GrowthIntent`; schema-forbidden fields; direct Nissa-to-Momir route | +| **Telemetry mediation** | Momir sees Aurelia's interpretation rather than the host observation | One canonical Nissa publication with shared observation identity | +| **Covert request channel** | Aurelia and Momir encode designs through continuous budgets, aliases or candidate count | Coarse enums, deterministic canonical resolution, invariance and anti-collusion tests | | **Bootstrap ceiling** | Momir becomes a blueprint selector or mutation table | Parent-relative and reference-frontier objectives; ancestry dropout; de novo gate | | **Permanent scaffold dependence** | Production generation fails without stock reference seeds | Explicit null ancestry, withdrawal schedule, held-out scaffold-free evaluation | | **Permanent bitwise burden** | Exactness requirements prevent realistic kernels, scale or hardware evolution | Treat Academy exactness as a retained metrology profile; calibrate Field execution rather than requiring universal bitwise identity | @@ -35,32 +35,33 @@ | **Lockstep scaffold withdrawal** | One subsystem loses support because another subsystem is ready | Independent three-axis `ScaffoldState` and separate gate ownership | | **Multi-scaffold confounding** | A failure after simultaneous withdrawal cannot be attributed | One-axis confirmatory transitions and declared interaction experiments | | **Hidden scaffold correlation** | Fixed seeds, exact execution and stock ancestry make one another look stronger than they are | Selected scaffold interaction matrix and final fully withdrawn corner | -| **Kasmina legacy blueprint creep** | Host physiology quietly regains a preferred design catalogue | Reference population lives in Sarpadia/controls; Kasmina imports no blueprint library | -| **Sarpadia leakage** | Related branches cross train/test boundaries | Group split by base host trajectory | -| **Oona control coupling** | UI or logging changes training behaviour | Read-only events and isolation tests | +| **Wrenn legacy blueprint creep** | Host physiology quietly regains a preferred design catalogue | Reference population lives in Urborg/controls; Wrenn imports no blueprint library | +| **Urborg leakage** | Related branches cross train/test boundaries | Group split by base host trajectory | +| **Tamiyo control coupling** | UI or logging changes training behaviour | Read-only events and isolation tests | | **Codename opacity** | New contributors cannot find responsibilities | Plain-English README header, glossary, typed record names and diagrams | | **Namespec drift** | One codename accumulates multiple meanings | ADR, package ownership manifest and compatibility sunset dates | | **Toy-task non-separability** | Methods appear equal because the space is too small | Sweep width and grammar complexity before broad conclusions | | **Graph grammar explosion** | Design and verification become intractable | Staged grammar levels and explicit ceilings | -| **Asynchronous compilation staleness** | Candidate is obsolete before Tezzeret finishes | Compilation budget, caching and re-qualification | +| **Asynchronous compilation staleness** | Candidate is obsolete before Urabrask finishes | Compilation budget, caching and re-qualification | --- ## 27. Open Design Decisions -The subsystem names and their principal authorities are **not** open decisions. Namespec 1.0 is locked. The following implementation choices remain open. +The subsystem names and their principal authorities are **not** open decisions. Namespec 2.0 is locked (ADR-0008). The following implementation choices remain open. ### 27.1 Project-level name — decided **Decided 2026-08-08 (ADR-0003, PDR-0006): the name is locked as Simic** — repository, package (`src/simic/`), and presumptive publication name. The predecessors (ESPER, ESPER LITE) present as lineage history behind a clean -seam. This decision never affected the subsystem names, which are locked -with Namespec 1.0 and reaffirmed unamended in ADR-0003. +seam. This decision never affected the subsystem names, which were locked +as Namespec 1.0 at the time (reaffirmed in ADR-0003) and are now locked as +Namespec 2.0 (ADR-0008). ### 27.2 Default maturation mode -Should the ecological default be one-shot generation, isolated nursery training, or a mixed Narset policy after both modes are characterised? +Should the ecological default be one-shot generation, isolated nursery training, or a mixed Aurelia policy after both modes are characterised? ### 27.3 Winning-branch deployment @@ -76,7 +77,7 @@ What is the smallest safe grammar materially more expressive than a residual mic What horizon captures trajectory value before branch-divergence noise overwhelms the intervention signal? What evidence-completeness threshold should force retest? -### 27.6 Urabrask–Augustin contract +### 27.6 Jin-Gitaxias–Isperia contract Which measurements are raw, which are certified derived facts, and which hard QA statuses make a candidate ineligible by policy? The separation is locked; the exact report surface is not. @@ -86,19 +87,19 @@ Does commitment retain a named removable growth indefinitely, or may a later aut ### 27.8 Retrieval similarity -Should Sarpadia retrieve by telemetry distance, learned state embeddings, gradient alignment, functional effect, task context, lineage history or a calibrated mixture? +Should Urborg retrieve by telemetry distance, learned state embeddings, gradient alignment, functional effect, task context, lineage history or a calibrated mixture? -### 27.9 Augustin–Emrakul maintenance boundary +### 27.9 Isperia–Emrakul maintenance boundary -Should Augustin issue only a tenancy verdict, or also a bounded class of permitted maintenance actions? The preferred direction is verdict plus constraints, with Emrakul selecting the safe physical schedule. +Should Isperia issue only a tenancy verdict, or also a bounded class of permitted maintenance actions? The preferred direction is verdict plus constraints, with Emrakul selecting the safe physical schedule. -### 27.10 Oona transport boundary +### 27.10 Tamiyo transport boundary -Should Oona own the event bus implementation or only durable projections and operator adapters? In either case, Leyline owns schemas and training remains independent of Oona availability. +Should Tamiyo own the event bus implementation or only durable projections and operator adapters? In either case, Leyline owns schemas and training remains independent of Tamiyo availability. ### 27.11 Request-channel granularity -Fix the smallest set of coarse `GrowthIntent` classes that gives Narset useful tactical authority without creating a high-bandwidth covert design channel to Momir. +Fix the smallest set of coarse `GrowthIntent` classes that gives Aurelia useful tactical authority without creating a high-bandwidth covert design channel to Momir. ### 27.12 Bootstrap reference population @@ -106,7 +107,7 @@ Fix the initial reference families, canonical graph forms, mutation radii, ances ### 27.13 Tolaria integration boundary -Should Tolaria call a generic Kasmina host protocol, or should a thin integration adapter live outside both domains? The result must preserve infrastructure neutrality and one execution path. +Should Tolaria call a generic Wrenn host protocol, or should a thin integration adapter live outside both domains? The result must preserve infrastructure neutrality and one execution path. ### 27.14 Tolaria Field-withdrawal gate diff --git a/docs/product/commissioning/README.md b/docs/product/commissioning/README.md index 1dd59b2..b59fcd9 100644 --- a/docs/product/commissioning/README.md +++ b/docs/product/commissioning/README.md @@ -39,7 +39,7 @@ pointer stub. Prompts must ground in the decomposed chapters: |---|---| | Snapshot §9.7 | `Snapshot` contract — `docs/design/05-leyline-contracts.md#911-snapshot` | | Contract tests §21.1 | `docs/design/programme/evaluation.md#212-leyline-contract-tests` | -| Tezzeret tests §21.4 | `docs/design/programme/evaluation.md#217-tezzeret-tests` | +| Urabrask tests §21.4 | `docs/design/programme/evaluation.md#217-urabrask-tests` | | Statistical unit §14.7 | `docs/design/07-counterfactual-engine.md#149-statistical-unit` | | Tolaria spec §13.2 | `docs/design/domains/tolaria.md` (execution regimes) | | Execution-uncertainty margins §14.4.1 | `docs/design/07-counterfactual-engine.md#1441-execution-uncertainty-and-adjudication-margins` | diff --git a/docs/product/current-state.md b/docs/product/current-state.md index 180c4ae..0ceac79 100644 --- a/docs/product/current-state.md +++ b/docs/product/current-state.md @@ -9,6 +9,16 @@ checkpoint-only); ~1.7 closures per working day needed to make the date. Public face live, hardened and now deploy-gated: https://simic.foundryside.dev with the wiki at /design/ (PDR-0018, PR #2 merged 6df7e7a). +**Namespec 2.0 landed post-checkpoint, same day (ADR-0008, PDR-0020, +branch namespec-2.0):** eight domains renamed (Sarpadia→Urborg, Tamiyo→Ugin, +Narset→Aurelia, Tezzeret→Urabrask, Urabrask→Jin-Gitaxias, Augustin→Isperia, +Kasmina→Wrenn, Oona→Tamiyo), full cascade through the constitution, every +design chapter, appendices, root docs, model.dsl + diagrams (re-rendered), +site, wiki (strict build green) and the open tracker titles; mechanics and +all 45 invariants unchanged. Pre-2.0 records read through the ADR-0008 +concordance — beware the two reused names (Urabrask, Tamiyo). Publishing +the renamed site/wiki needs the owner-gated merge + push of namespec-2.0. + ## In flight - Nothing claimed. Six wave:1 items remain; simic-d6ea02f9a9 (containment owner) stays the natural next. Critical path: simic-0bf2c40dec → diff --git a/docs/product/decisions/0020-namespec-2.0-adoption.md b/docs/product/decisions/0020-namespec-2.0-adoption.md new file mode 100644 index 0000000..0c154a9 --- /dev/null +++ b/docs/product/decisions/0020-namespec-2.0-adoption.md @@ -0,0 +1,55 @@ +# PDR-0020 — Record the Namespec 2.0 adoption and its cascade + +Date: 2026-08-09 Status: accepted Author: Claude (product-owner session) +Owner sign-off: the underlying decision is owner-authored — John directed the +Namespec 2.0 plan (prompts/namespec.md) as the session goal on 2026-08-09; +this PDR records its product-tier consequences. +Related: ADR-0008 (the architecture-tier decision), ADR-0003 (partially +superseded), simic-d8369760b9 (tracker), PDR-0006 (clean seam) + +## Context + +The owner directed a final consistency pass over the conceptual design and a +locked replacement naming constitution: Namespec 2.0 supersedes Namespec 1.0 +in its entirety. Eight of fourteen codenames change (Sarpadia→Urborg, +Tamiyo→Ugin, Narset→Aurelia, Tezzeret→Urabrask, Urabrask→Jin-Gitaxias, +Augustin→Isperia, Kasmina→Wrenn, Oona→Tamiyo), and the thematic framing +becomes load-bearing: a Phyrexian industrial synthesis core +(Momir→Elesh→Urabrask→Jin-Gitaxias) inside a governance cage. Mechanics, +invariants, contracts and authority boundaries are unchanged. The cascade +was executed in the same session: ADR-0008, the constitution rewrite, every +design chapter and domain file, the appendices, root docs, the Structurizr +model and mermaid diagrams (re-rendered), the site, the wiki build inputs, +the product workspace, and the open tracker titles. + +## The call + +Record the adoption at product tier; no bet changes horizon. The Now bet +(design hardening, hld-review burn-down) continues under the new names. +Two product artifacts changed beyond mechanical renaming: + +- `roadmap.md`'s Phase A bullet now marks the namespec-ADR work item as done + (ADR-0008) — the remaining Phase A scope is unchanged. +- `vision.md`'s repo-discipline line now cites Namespec 2.0. This is a + factual-reference update inside the restated HLD discipline, not a change + to the authority grant, whose scope and reserved actions are untouched. + +Timing note: with no code on disk (Phase A ahead), this was the last point +at which a total rename cost only documentation effort. The same change +after Phase A would have carried package, telemetry and test migration. + +## Rationale + +The rename resolves on new terms the naming ambiguity the peer review +flagged (simic-3a17fe545d): Tamiyo leaves the strategic role entirely, and +the two names that would otherwise have collided with the predecessor's +vocabulary (Urabrask, Tamiyo) are bounded by the clean seam (PDR-0006, +ADR-0003) plus the historical-interpretation rule and banners in ADR-0008. +The product scoreboard (metrics.md) is unaffected: the burn-down counts the +same items under new titles. + +## Reversal trigger + +Per ADR-0008: owner ruling only, before Phase A writes package names to +disk; after Phase A, reversal requires a new ADR with a migration plan. +Naming churn is pure cost — absent an owner ruling this stands unrevisited. diff --git a/docs/product/metrics.md b/docs/product/metrics.md index c9ad0bb..a0592de 100644 --- a/docs/product/metrics.md +++ b/docs/product/metrics.md @@ -20,5 +20,5 @@ | Metric | Floor / ceiling | Current | Read on | |--------|-----------------|---------|---------| | Academy exact-replay gate: identical snapshot + identical future data ⇒ bitwise-identical traces (HLD §18, invariant 5) | Floor: 100% pass, from Phase D onward | N/A — pre-code | 2026-08-08 | -| History completeness: candidate pools, failures, rejections, no-op wins and abstentions retained in Sarpadia (never winners-only) | Floor: 100% of cases | N/A — pre-code | 2026-08-08 | +| History completeness: candidate pools, failures, rejections, no-op wins and abstentions retained in Urborg (never winners-only) | Floor: 100% of cases | N/A — pre-code | 2026-08-08 | | Harmful-intervention rate under admitted growth (HLD §28.6) | Ceiling: the tail-risk veto's declared operating point per assurance class — shape fixed by ADR-0004 (INV-45: veto precedes utility, non-tradeable, priced against snapshot distance); numbers land with the Phase-A adjudication-policy LLD | N/A — pre-code | 2026-08-08 (session 6: shape bound) | diff --git a/docs/product/roadmap.md b/docs/product/roadmap.md index 771efb3..4d640f5 100644 --- a/docs/product/roadmap.md +++ b/docs/product/roadmap.md @@ -11,7 +11,7 @@ (PDR-0007); the HLD is decomposed into docs/design/ chapters (PDR-0009, ADR-0001); remaining work runs as six region-based waves stamped as `wave:*` labels (PDR-0008) · tracker: wave:0 cleared and the wave:1 - Augustin pair landed (ADR-0004, ADR-0005); dependency-critical path now + Isperia pair landed (ADR-0004, ADR-0005); dependency-critical path now simic-0bf2c40dec → simic-38a07fad39, six wave:1 items remain · metric: design-debt burn-down (metrics.md) - **Information-management regime (ADR-0002)** — why: data management was the @@ -24,7 +24,7 @@ ## Next (shaped, decreasing certainty) - **Phase A — Namespec, Leyline contracts, dependency boundaries** (HLD §25.A; - §30 milestones 1–3) — ADR locking Namespec 1.0, package skeleton with + §30 milestones 1–3) — namespec ADR (Namespec 2.0 — done, ADR-0008), package skeleton with forbidden-import checks, core contracts, lifecycle/warrant rules, budgets, import-lint and authority tests. (not yet sequenced) - **Phase B — Tolaria host-training baseline and Academy profile** (HLD §25.B) — @@ -33,9 +33,9 @@ ## Later (directional bets, no order, no dates) - **Phases C–K toward the §24 Minimum Viable System** — growth mechanics, replay - and branching, Urabrask QA, Augustin adjudication and controls, Sarpadia/Momir - bootstrap curriculum, Nissa/Narset routing, Emrakul maintenance, Tamiyo - allocation, Oona and scale. + and branching, Jin-Gitaxias QA, Isperia adjudication and controls, Urborg/Momir + bootstrap curriculum, Nissa/Aurelia routing, Emrakul maintenance, Ugin + allocation, Tamiyo and scale. - **Esper-derived controls** — the working blueprint selector and the degenerate-architecture fixtures (~10%→~40% headroom) as sharp, cheap baselines for the generation hypothesis · adjudicated at the gate (PDR-0007): accepted diff --git a/docs/product/vision.md b/docs/product/vision.md index 08edb09..37cba32 100644 --- a/docs/product/vision.md +++ b/docs/product/vision.md @@ -84,7 +84,7 @@ Escalate BEFORE acting — the agent MUST get owner sign-off for: without explicit say-so); **never push without an explicit ask**; no destructive git without permission. Repo discipline (restates HLD §30; owner-confirmed 2026-08-08): HLD - constitutional constraints (Namespec 1.0, the §18 invariants, the + constitutional constraints (Namespec 2.0, the §18 invariants, the authority boundaries, the newsroom rule, the no-op requirement, scaffold withdrawal) change only through an ADR naming the displaced invariant. (Taxonomy + rationale: product-ownership-operating-model.md.) diff --git a/site/404.html b/site/404.html index 07e68d4..fd8ada5 100644 --- a/site/404.html +++ b/site/404.html @@ -82,7 +82,7 @@

Design docs →

Simic — a research project by tachyon-beep. Licensed Apache-2.0.

diff --git a/site/architecture.html b/site/architecture.html index 5ee74d6..804336f 100644 --- a/site/architecture.html +++ b/site/architecture.html @@ -109,8 +109,8 @@

Actors have verbs. Infrastructure has prepositions.Sarpadia - recorded in / retrieved from Sarpadia + Urborg + recorded in / retrieved from Urborg History, lineage, bootstrap ancestry, counterfactual outcomes, retrieval and datasets Live-host mutation or self-approval @@ -130,28 +130,28 @@

Actors have verbs. Infrastructure has prepositions.TamiyoPlansStrategic allocation, regional permissions, long-horizon budgets and riskA local action selector - NarsetCommissions and actsTactical intervention timing, insertion-region choice, operational constraints, pre-commit lifecycle controlA co-designer or source of unallocated authority + UginPlansStrategic allocation, regional permissions, long-horizon budgets and riskA local action selector + AureliaCommissions and actsTactical intervention timing, insertion-region choice, operational constraints, pre-commit lifecycle controlA co-designer or source of unallocated authority NissaObserves and reportsTyped host diagnostics, direct evidence publication, and provenanceA hidden controller or editorial intermediary MomirDesignsCandidate topology, parameters, mutation and recombinationThe approver of its own work EleshConformsStructural legality, canonicalisation and semantic identityA utility predictor or task judge - TezzeretCompilesLowering and executable realisationA semantic graph designer - UrabraskTestsDynamic QA, regression, runtime conformance and evidence certificationThe admission judge - AugustinJudgesAdmission, no-op comparison, policy utility and continued-tenancy rulingsA test runner or compiler - KasminaEmbodiesHost topology, slots, maturation, blending and physical lifecycleA candidate selector or blueprint catalogue + UrabraskCompilesLowering and executable realisationA semantic graph designer + Jin-GitaxiasTestsDynamic QA, regression, runtime conformance and evidence certificationThe admission judge + IsperiaJudgesAdmission, no-op comparison, policy utility and continued-tenancy rulingsA test runner or compiler + WrennEmbodiesHost topology, slots, maturation, blending and physical lifecycleA candidate selector or blueprint catalogue EmrakulDestroysSafe post-commit sedation, decay, consolidation and lysisA constructor or newborn judge - OonaRevealsFlight recording, projections, operator surfaces and auditA control-plane backchannel + TamiyoRevealsFlight recording, projections, operator surfaces and auditA control-plane backchannel

- Nissa observes and reports. Tamiyo plans. Narset commissions and acts. - Momir designs. Elesh conforms. Tezzeret compiles. Urabrask tests the - compiled result in Tolaria. Augustin judges the resulting evidence under - Leyline. Kasmina embodies the admitted growth. Emrakul destroys what no - longer earns continued tenancy. Sarpadia retains every precedent. Oona + Nissa observes and reports. Ugin plans. Aurelia commissions and acts. + Momir designs. Elesh conforms. Urabrask compiles. Jin-Gitaxias tests the + compiled result in Tolaria. Isperia judges the resulting evidence under + Leyline. Wrenn embodies the admitted growth. Emrakul destroys what no + longer earns continued tenancy. Urborg retains every precedent. Tamiyo reveals the account.

The canonical sentence — a compact authority map. @@ -170,14 +170,14 @@

Architectural planesLeylineContracts, grammar profiles, compatibility, policy records, invariants Training and executionTolariaTrains the live host; executes deterministic ordinary, replay and branch worlds - Historical infrastructureSarpadiaLineages, reference ancestry, outcomes, failures and split-safe datasets - Strategic agencyTamiyoAllocates regional resources, permissions and risk over long horizons - Tactical commissioningNarsetDecides whether and where to commission growth; manages pre-commit actions + Historical infrastructureUrborgLineages, reference ancestry, outcomes, failures and split-safe datasets + Strategic agencyUginAllocates regional resources, permissions and risk over long horizons + Tactical commissioningAureliaDecides whether and where to commission growth; manages pre-commit actions ObservationNissaPublishes what the host is doing without prescribing what should be built - SynthesisMomir, Elesh, TezzeretDesigns, canonicalises and compiles growth - Assurance and adjudicationUrabrask, AugustinEstablishes empirical evidence, then judges it independently - Embodiment and maintenanceKasmina, EmrakulIntroduces growth safely; removes obsolete committed structure - WitnessOonaExposes an auditable account without steering it + SynthesisMomir, Elesh, UrabraskDesigns, canonicalises and compiles growth + Assurance and adjudicationJin-Gitaxias, IsperiaEstablishes empirical evidence, then judges it independently + Embodiment and maintenanceWrenn, EmrakulIntroduces growth safely; removes obsolete committed structure + WitnessTamiyoExposes an auditable account without steering it @@ -200,17 +200,17 @@

The newsroom principle NissaReporting, photography and data — publishes what was observed - TamiyoEditor-in-chief — allocates desks, time and strategic resources - NarsetAssignments editor — is there a story, which beat, what scope and deadline + UginEditor-in-chief — allocates desks, time and strategic resources + AureliaAssignments editor — is there a story, which beat, what scope and deadline MomirWriter — determines the substantive answer from evidence and commission EleshCopy and standards desk — house form, without deciding whether the story is valuable - TezzeretProduction — turns canonical copy into an executable edition without changing meaning - UrabraskFact-checking and QA — establishes what the finished artefact actually does - AugustinPublishing editor — run, return, defer, or spike - KasminaIntegrates accepted material into the live edition + UrabraskProduction — turns canonical copy into an executable edition without changing meaning + Jin-GitaxiasFact-checking and QA — establishes what the finished artefact actually does + IsperiaPublishing editor — run, return, defer, or spike + WrennIntegrates accepted material into the live edition EmrakulCorrection, withdrawal and retirement after publication - SarpadiaMorgue and archive — including corrections, failed investigations, abandoned drafts - OonaPresentation — front page, dashboards, the public account + UrborgMorgue and archive — including corrections, failed investigations, abandoned drafts + TamiyoPresentation — front page, dashboards, the public account LeylineStylebook, editorial constitution and record format TolariaProduction environment, CMS, presses and test editions @@ -219,8 +219,8 @@

The newsroom principle

- Narset does not send the photograph. Nissa sends the photograph - directly to Momir. Narset sends only the assignment brief. + Aurelia does not send the photograph. Nissa sends the photograph + directly to Momir. Aurelia sends only the assignment brief.

@@ -230,14 +230,14 @@

The newsroom principle

The metaphor is never the enforcement mechanism. Enforcement is contractual: direct evidence publication, a narrow GrowthIntent, deterministic request resolution, immutable provenance, and tests that - reject diagnostic or structural hints in Narset's channel. + reject diagnostic or structural hints in Aurelia's channel.

The loops#

@@ -245,17 +245,17 @@

The loopsObservation and commissioning#

- diff --git a/site/assets/diagrams/assurance-loop-dark.svg b/site/assets/diagrams/assurance-loop-dark.svg index 0c15a18..992562e 100644 --- a/site/assets/diagrams/assurance-loop-dark.svg +++ b/site/assets/diagrams/assurance-loop-dark.svg @@ -1 +1 @@ -Tezzeret artefactUrabrask buildsa blinded TestPlanTolaria restoresone common SnapshotCandidate branchesControlsMandatory no-opUrabrask verifies conformanceand certifies the measurementsQualityReportAugustin applies eligibility,then the tail-risk veto,then utility policyADMIT one · REJECTDEFER · REQUIRE_RETEST · NO_OP \ No newline at end of file +Urabrask artefactJin-Gitaxias buildsa blinded TestPlanTolaria restoresone common SnapshotCandidate branchesControlsMandatory no-opJin-Gitaxias verifies conformanceand certifies the measurementsQualityReportIsperia applies eligibility,then the tail-risk veto,then utility policyADMIT one · REJECTDEFER · REQUIRE_RETEST · NO_OP \ No newline at end of file diff --git a/site/assets/diagrams/assurance-loop-light.svg b/site/assets/diagrams/assurance-loop-light.svg index 96416dc..d3267f9 100644 --- a/site/assets/diagrams/assurance-loop-light.svg +++ b/site/assets/diagrams/assurance-loop-light.svg @@ -1 +1 @@ -Tezzeret artefactUrabrask buildsa blinded TestPlanTolaria restoresone common SnapshotCandidate branchesControlsMandatory no-opUrabrask verifies conformanceand certifies the measurementsQualityReportAugustin applies eligibility,then the tail-risk veto,then utility policyADMIT one · REJECTDEFER · REQUIRE_RETEST · NO_OP \ No newline at end of file +Urabrask artefactJin-Gitaxias buildsa blinded TestPlanTolaria restoresone common SnapshotCandidate branchesControlsMandatory no-opJin-Gitaxias verifies conformanceand certifies the measurementsQualityReportIsperia applies eligibility,then the tail-risk veto,then utility policyADMIT one · REJECTDEFER · REQUIRE_RETEST · NO_OP \ No newline at end of file diff --git a/site/assets/diagrams/core-loop-dark.svg b/site/assets/diagrams/core-loop-dark.svg index 40e9447..89a0c85 100644 --- a/site/assets/diagrams/core-loop-dark.svg +++ b/site/assets/diagrams/core-loop-dark.svg @@ -1 +1 @@ -same envelope, publisheddirectlysame envelope, publisheddirectlyGrowthIntentthe assignment briefadmitno-op winsmaintenance warrantTask and data streamTolariatrains the Kasmina hostNissa publishes thecanonical TelemetryEnvelopeNarsetwhether and whereto commission growthMomirdesigns candidate growthTamiyoauthorises strategic resourcesLeyline and Kasmina resolvethe legal GrowthRequestSarpadiaoptional bootstrap ancestryElesh conformsTezzeret compilesUrabrask specifies QATolaria executes the testsUrabrask certifiesthe evidenceAugustin judgescandidate versus no-opKasmina embodiesthe admitted growthNo interventionpolicy utility exactly zeroEmrakul removes what Augustinjudges no longer earns its placeSarpadia retains everysuccess, failure, abstentionOona revealsthe complete account \ No newline at end of file +same envelope, publisheddirectlysame envelope, publisheddirectlyGrowthIntentthe assignment briefadmitno-op winsmaintenance warrantTask and data streamTolariatrains the Wrenn hostNissa publishes thecanonical TelemetryEnvelopeAureliawhether and whereto commission growthMomirdesigns candidate growthUginauthorises strategic resourcesLeyline and Wrenn resolvethe legal GrowthRequestUrborgoptional bootstrap ancestryElesh conformsUrabrask compilesJin-Gitaxias specifies QATolaria executes the testsJin-Gitaxias certifiesthe evidenceIsperia judgescandidate versus no-opWrenn embodiesthe admitted growthNo interventionpolicy utility exactly zeroEmrakul removes what Isperiajudges no longer earns its placeUrborg retains everysuccess, failure, abstentionTamiyo revealsthe complete account \ No newline at end of file diff --git a/site/assets/diagrams/core-loop-light.svg b/site/assets/diagrams/core-loop-light.svg index 2d226cb..991a4cf 100644 --- a/site/assets/diagrams/core-loop-light.svg +++ b/site/assets/diagrams/core-loop-light.svg @@ -1 +1 @@ -same envelope, publisheddirectlysame envelope, publisheddirectlyGrowthIntentthe assignment briefadmitno-op winsmaintenance warrantTask and data streamTolariatrains the Kasmina hostNissa publishes thecanonical TelemetryEnvelopeNarsetwhether and whereto commission growthMomirdesigns candidate growthTamiyoauthorises strategic resourcesLeyline and Kasmina resolvethe legal GrowthRequestSarpadiaoptional bootstrap ancestryElesh conformsTezzeret compilesUrabrask specifies QATolaria executes the testsUrabrask certifiesthe evidenceAugustin judgescandidate versus no-opKasmina embodiesthe admitted growthNo interventionpolicy utility exactly zeroEmrakul removes what Augustinjudges no longer earns its placeSarpadia retains everysuccess, failure, abstentionOona revealsthe complete account \ No newline at end of file +same envelope, publisheddirectlysame envelope, publisheddirectlyGrowthIntentthe assignment briefadmitno-op winsmaintenance warrantTask and data streamTolariatrains the Wrenn hostNissa publishes thecanonical TelemetryEnvelopeAureliawhether and whereto commission growthMomirdesigns candidate growthUginauthorises strategic resourcesLeyline and Wrenn resolvethe legal GrowthRequestUrborgoptional bootstrap ancestryElesh conformsUrabrask compilesJin-Gitaxias specifies QATolaria executes the testsJin-Gitaxias certifiesthe evidenceIsperia judgescandidate versus no-opWrenn embodiesthe admitted growthNo interventionpolicy utility exactly zeroEmrakul removes what Isperiajudges no longer earns its placeUrborg retains everysuccess, failure, abstentionTamiyo revealsthe complete account \ No newline at end of file diff --git a/site/assets/diagrams/observation-loop-dark.svg b/site/assets/diagrams/observation-loop-dark.svg index 805b72f..a6ae1d1 100644 --- a/site/assets/diagrams/observation-loop-dark.svg +++ b/site/assets/diagrams/observation-loop-dark.svg @@ -1 +1 @@ -published directlypublished directlyStrategicEnvelope EGrowthIntent IRegionContract RGrammarProfile Gobservation identityGrowthRequest QNissa observes Snapshot Sat decision point TTelemetryEnvelope ONarsetcommission work? where?under what class?Momirwhat structure would addressthis observed state?TamiyoPure request resolutionO, E, I, R, G QKasminaLeyline \ No newline at end of file +published directlypublished directlyStrategicEnvelope EGrowthIntent IRegionContract RGrammarProfile Gobservation identityGrowthRequest QNissa observes Snapshot Sat decision point TTelemetryEnvelope OAureliacommission work? where?under what class?Momirwhat structure would addressthis observed state?UginPure request resolutionO, E, I, R, G QWrennLeyline \ No newline at end of file diff --git a/site/assets/diagrams/observation-loop-light.svg b/site/assets/diagrams/observation-loop-light.svg index e0c2706..6a25917 100644 --- a/site/assets/diagrams/observation-loop-light.svg +++ b/site/assets/diagrams/observation-loop-light.svg @@ -1 +1 @@ -published directlypublished directlyStrategicEnvelope EGrowthIntent IRegionContract RGrammarProfile Gobservation identityGrowthRequest QNissa observes Snapshot Sat decision point TTelemetryEnvelope ONarsetcommission work? where?under what class?Momirwhat structure would addressthis observed state?TamiyoPure request resolutionO, E, I, R, G QKasminaLeyline \ No newline at end of file +published directlypublished directlyStrategicEnvelope EGrowthIntent IRegionContract RGrammarProfile Gobservation identityGrowthRequest QNissa observes Snapshot Sat decision point TTelemetryEnvelope OAureliacommission work? where?under what class?Momirwhat structure would addressthis observed state?UginPure request resolutionO, E, I, R, G QWrennLeyline \ No newline at end of file diff --git a/site/index.html b/site/index.html index af5afef..974d31e 100644 --- a/site/index.html +++ b/site/index.html @@ -59,7 +59,7 @@

Simic

Project status — as of 9 August 2026

Pre-implementation bootstrap. The design is locked — HLD - v4.1, Namespec 1.0 — and under active design review, with + v4.1, Namespec 2.0 — and under active design review, with findings still open against it, including unresolved contract shapes. A Python scaffold exists, but there is no functional code yet. First @@ -97,12 +97,12 @@

The ideaThe loop, end to end#

- diff --git a/site/lineage.html b/site/lineage.html index 5235469..049a233 100644 --- a/site/lineage.html +++ b/site/lineage.html @@ -198,10 +198,10 @@

The pivot, stated plainly. Paired branches from one snapshot over identical futures cancel ordinary-training variance, so the difference between branches is the intervention effect. That converts credit assignment into - supervised learning: Momir becomes ranking over measured pools, Narset + supervised learning: Momir becomes ranking over measured pools, Aurelia becomes per-step supervised classification against counterfactual labels, and - Augustin becomes explicit adjudication rules. The genuinely irreducible - reinforcement learning shrinks to Tamiyo's allocation and Narset's timing. + Isperia becomes explicit adjudication rules. The genuinely irreducible + reinforcement learning shrinks to Ugin's allocation and Aurelia's timing.

@@ -272,7 +272,7 @@

The forward motion

So the design pushes from a fixed blueprint menu to generated growth (Momir); from shaped reward to measured counterfactuals (the branching engine); and from single-region caution toward strategic allocation - (Tamiyo).

+ (Ugin).

The counterfactual engine is simultaneously both: armour against Goodhartable shaping, and the forward mechanism that makes generation adjudicable at all.

@@ -319,7 +319,7 @@

The guarantees →

Simic — a research project by tachyon-beep. Licensed Apache-2.0.

diff --git a/tools/diagrams/assurance-loop.mmd b/tools/diagrams/assurance-loop.mmd index e8228fd..45992ec 100644 --- a/tools/diagrams/assurance-loop.mmd +++ b/tools/diagrams/assurance-loop.mmd @@ -2,7 +2,7 @@ %% Source: docs/design/04-architecture.md §7.4. %% Rendered by build.sh; do not hand-edit the generated SVGs. flowchart TD - ART["Tezzeret artefact"] --> PLAN["Urabrask builds
a blinded TestPlan"] + ART["Urabrask artefact"] --> PLAN["Jin-Gitaxias builds
a blinded TestPlan"] PLAN --> TOL["Tolaria restores
one common Snapshot"] %% One rank of matched branches over an identical future. Deliberately not @@ -16,8 +16,8 @@ flowchart TD BK --> CERT BN --> CERT - CERT["Urabrask verifies conformance
and certifies the measurements"] --> QR["QualityReport"] - QR --> AUG["Augustin applies eligibility,
then the tail-risk veto,
then utility policy"] - AUG --> VERD["ADMIT one · REJECT
DEFER · REQUIRE_RETEST · NO_OP"] + CERT["Jin-Gitaxias verifies conformance
and certifies the measurements"] --> QR["QualityReport"] + QR --> ISP["Isperia applies eligibility,
then the tail-risk veto,
then utility policy"] + ISP --> VERD["ADMIT one · REJECT
DEFER · REQUIRE_RETEST · NO_OP"] class BN accent diff --git a/tools/diagrams/core-loop.mmd b/tools/diagrams/core-loop.mmd index 0d2dc26..c762afd 100644 --- a/tools/diagrams/core-loop.mmd +++ b/tools/diagrams/core-loop.mmd @@ -2,35 +2,35 @@ %% Source: docs/design/01-claim.md §1 (the shared execution reality). %% Rendered by build.sh; do not hand-edit the generated SVGs. flowchart TD - DATA["Task and data stream"] --> TOL["Tolaria
trains the Kasmina host"] + DATA["Task and data stream"] --> TOL["Tolaria
trains the Wrenn host"] TOL --> NIS["Nissa publishes the
canonical TelemetryEnvelope"] - NIS -->|"same envelope, published directly"| NAR["Narset
whether and where
to commission growth"] + NIS -->|"same envelope, published directly"| AUR["Aurelia
whether and where
to commission growth"] NIS -->|"same envelope, published directly"| MOM["Momir
designs candidate growth"] - TAM["Tamiyo
authorises strategic resources"] --> NAR - NAR -->|"GrowthIntent
the assignment brief"| RES["Leyline and Kasmina resolve
the legal GrowthRequest"] + UGN["Ugin
authorises strategic resources"] --> AUR + AUR -->|"GrowthIntent
the assignment brief"| RES["Leyline and Wrenn resolve
the legal GrowthRequest"] RES --> MOM - SARB["Sarpadia
optional bootstrap ancestry"] -.-> MOM + URGB["Urborg
optional bootstrap ancestry"] -.-> MOM MOM --> ELE["Elesh conforms"] - ELE --> TEZ["Tezzeret compiles"] - TEZ --> URA["Urabrask specifies QA
Tolaria executes the tests"] - URA --> CERT["Urabrask certifies
the evidence"] - CERT --> AUG{"Augustin judges
candidate versus no-op"} + ELE --> URA["Urabrask compiles"] + URA --> JIN["Jin-Gitaxias specifies QA
Tolaria executes the tests"] + JIN --> CERT["Jin-Gitaxias certifies
the evidence"] + CERT --> ISP{"Isperia judges
candidate versus no-op"} - AUG -->|"admit"| KAS["Kasmina embodies
the admitted growth"] - AUG -->|"no-op wins"| NOOP["No intervention
policy utility exactly zero"] + ISP -->|"admit"| WRE["Wrenn embodies
the admitted growth"] + ISP -->|"no-op wins"| NOOP["No intervention
policy utility exactly zero"] - %% INV-27: Emrakul acts only on an Augustin maintenance warrant. Do not + %% INV-27: Emrakul acts only on an Isperia maintenance warrant. Do not %% shorten this label to "Emrakul removes ..." — that draws Emrakul %% retiring committed structure on its own authority, which it cannot. - KAS --> EMR["Emrakul removes what Augustin
judges no longer earns its place"] - AUG -.->|"maintenance warrant"| EMR + WRE --> EMR["Emrakul removes what Isperia
judges no longer earns its place"] + ISP -.->|"maintenance warrant"| EMR - KAS --> SAR["Sarpadia retains every
success, failure, abstention"] - NOOP --> SAR - EMR --> SAR - SAR --> OON["Oona reveals
the complete account"] + WRE --> URG["Urborg retains every
success, failure, abstention"] + NOOP --> URG + EMR --> URG + URG --> TAM["Tamiyo reveals
the complete account"] class NOOP accent diff --git a/tools/diagrams/observation-loop.mmd b/tools/diagrams/observation-loop.mmd index c409496..8f43df5 100644 --- a/tools/diagrams/observation-loop.mmd +++ b/tools/diagrams/observation-loop.mmd @@ -4,12 +4,12 @@ flowchart TD OBS["Nissa observes Snapshot S
at decision point T"] --> ENV["TelemetryEnvelope O"] - ENV -->|"published directly"| NAR["Narset
commission work? where?
under what class?"] + ENV -->|"published directly"| AUR["Aurelia
commission work? where?
under what class?"] ENV -->|"published directly"| MOM["Momir
what structure would address
this observed state?"] - TAM["Tamiyo"] -->|"StrategicEnvelope E"| NAR - NAR -->|"GrowthIntent I"| RES - KAS["Kasmina"] -->|"RegionContract R"| RES + UGN["Ugin"] -->|"StrategicEnvelope E"| AUR + AUR -->|"GrowthIntent I"| RES + WRE["Wrenn"] -->|"RegionContract R"| RES LEY["Leyline"] -->|"GrammarProfile G"| RES ENV -.->|"observation identity"| RES diff --git a/tools/wiki/stage.py b/tools/wiki/stage.py index eb29896..8772268 100755 --- a/tools/wiki/stage.py +++ b/tools/wiki/stage.py @@ -69,7 +69,7 @@ H1 (the theme's title) straight to H3, a WCAG 1.3.1 heading-order break on all fourteen, under a synthesised title duplicating the chapter's own. They now shift up so the chapter heading IS the page H1 and the theme - injects nothing; `sarpadia.md`, which carries two headings at that level + injects nothing; `urborg.md`, which carries two headings at that level (§13.3 and the §15 data model), shifts to H2 instead so the page still has exactly one H1. Chapters already opening at `##` are untouched. The shift is anchor-neutral: python-markdown slugs come from heading TEXT and never @@ -157,13 +157,19 @@ "ArchiveIngestion", "RequestResolution", "MomirComponents", - "UrabraskComponents", - "AugustinComponents", + "Jin-GitaxiasComponents", + "IsperiaComponents", ] # Hyphenated filename fragments that stand for a slashed term in prose. SLASH_PAIRS = (("good", "bad"),) +# Hyphenated proper names: filename stems whose hyphen is part of the name +# itself, not a word separator. Without this, `domains/jin-gitaxias.md` +# would read "Jin gitaxias" in the nav. Closed and mechanical — the namespec +# (Namespec 2.0, ADR-0008) is the only source of such names. +HYPHEN_NAMES = {"jin-gitaxias": "Jin-Gitaxias"} + # Staged paths of pages this script GENERATES (no counterpart in docs/design/ # or docs/adr/). hooks.py suppresses the "edit this page" pencil for these: # mkdocs' own File.edit_uri docstring says generated files should have none, @@ -191,7 +197,7 @@ def derive_title(rel: Path) -> str: `04-architecture.md` -> "Architecture" `programme/risks-and-open-decisions.md` -> "Risks and open decisions" - `domains/augustin.md` -> "Augustin" + `domains/isperia.md` -> "Isperia" The numeric prefix is dropped from the *label* only; mkdocs still orders the nav by filename, so 01..07 stay in sequence. @@ -203,6 +209,8 @@ def derive_title(rel: Path) -> str: # admission", matching how the chapters cite them. adr = re.match(r"^(\d{4})[-_]", stem) if rel.parts[0] == ADR_STAGED_DIR else None stem = re.sub(r"^\d+[-_]", "", stem) + if stem in HYPHEN_NAMES: + return HYPHEN_NAMES[stem] # Vocabulary pairs the project writes with a slash. A filename cannot carry # `/`, so "good-bad-sentences" has to be re-joined or it reads "Good bad # sentences" instead of "Good/Bad sentences". Closed and mechanical, in the @@ -421,12 +429,12 @@ def normalise_heading_levels(text: str) -> str: monolith, where §13 was a third-level section, and wrong once the page has its own H1: the theme renders the derived title as H1 and the page then jumped straight to H3, a WCAG 1.3.1 heading-order break on all fourteen, - with the chapter's real title ("13.11 Augustin — Independent Judge") sitting - redundantly under a synthesised one ("Augustin"). + with the chapter's real title ("13.11 Isperia — Independent Judge") sitting + redundantly under a synthesised one ("Isperia"). Shifting to H1 fixes both at once: the chapter's own heading becomes the page H1, so the theme stops injecting a duplicate. The nav label still comes - from the front-matter title, so the sidebar keeps reading "Augustin". + from the front-matter title, so the sidebar keeps reading "Isperia". Chapters that already open at `##` (01-07) are left exactly as they are — there the synthesised H1 is a genuinely better page title than "5. Locked @@ -434,7 +442,7 @@ def normalise_heading_levels(text: str) -> str: A chapter with SEVERAL headings at its shallowest level shifts to H2, not H1, keeping the synthesised title as the one H1 that describes the page. - `domains/sarpadia.md` is the case: it carries both §13.3 and the §15 data + `domains/urborg.md` is the case: it carries both §13.3 and the §15 data model at the same level, and promoting both would give the page two H1s. Anchors are unaffected: python-markdown's toc slugify derives an id from @@ -465,7 +473,11 @@ def check_model_matches_domains() -> list[str]: dsl = SOURCE / "assets" / "model.dsl" if not dsl.is_file(): return [f"model.dsl missing: {dsl}"] - modelled = set(re.findall(r"^\s*(\w+)\s*=\s*container\s", dsl.read_text(encoding="utf-8"), re.M)) + # DSL identifiers cannot carry hyphens, so Jin-Gitaxias is `jin_gitaxias` + # there while its chapter file is `jin-gitaxias.md` (ADR-0008: underscores + # in identifiers/packages, hyphens in document paths). Normalise to the + # chapter convention before comparing. + modelled = {m.replace("_", "-") for m in re.findall(r"^\s*(\w+)\s*=\s*container\s", dsl.read_text(encoding="utf-8"), re.M)} canonical = {p.stem for p in (SOURCE / "domains").glob("*.md") if p.stem != "README"} errors = [] for name in sorted(canonical - modelled): @@ -481,7 +493,7 @@ def parse_view_descriptions() -> dict[str, str]: dsl = SOURCE / "assets" / "model.dsl" if not dsl.is_file(): return {} - pattern = r'^\s*(?:systemContext|container|component)\s+\w+\s+"(\w+)"\s+"([^"]*)"' + pattern = r'^\s*(?:systemContext|container|component)\s+\w+\s+"([\w-]+)"\s+"([^"]*)"' return dict(re.findall(pattern, dsl.read_text(encoding="utf-8"), re.M)) From deeab3848f9bcf7258099e8ed6172513d551c247 Mon Sep 17 00:00:00 2001 From: John Morrissey <544926+tachyon-beep@users.noreply.github.com> Date: Sun, 9 Aug 2026 10:11:50 +1000 Subject: [PATCH 3/3] =?UTF-8?q?product:=20session=2010=20checkpoint=20?= =?UTF-8?q?=E2=80=94=20Namespec=202.0=20recorded=20(ADR-0008,=20PDR-0020);?= =?UTF-8?q?=20burn-down=20flat=20at=2038,=20pacing=20warning=20stands;=20p?= =?UTF-8?q?ublish=20gated=20on=20owner?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-Authored-By: Claude Fable 5 Claude-Session: https://claude.ai/code/session_012qVBdHQtjsNsUbfMHSdyeF --- docs/product/current-state.md | 101 +++++++++++++++++----------------- docs/product/metrics.md | 4 +- docs/product/roadmap.md | 2 +- 3 files changed, 52 insertions(+), 55 deletions(-) diff --git a/docs/product/current-state.md b/docs/product/current-state.md index 0ceac79..0db756d 100644 --- a/docs/product/current-state.md +++ b/docs/product/current-state.md @@ -1,65 +1,62 @@ -# Current State — Simic Checkpoint: 2026-08-09 (session 9) +# Current State — Simic Checkpoint: 2026-08-09 (session 10) ## The bet right now -Design hardening — the hld-review burn-down (38 → 0 by 2026-08-31, -pacing signal) — plus the ADR-0002 information-management regime -(simic-357c92664c), now four sessions unstarted. **The pacing warning has -fired**: two consecutive flat sessions (7 and 9 did wiki/site work, 8 was -checkpoint-only); ~1.7 closures per working day needed to make the date. -Public face live, hardened and now deploy-gated: https://simic.foundryside.dev -with the wiki at /design/ (PDR-0018, PR #2 merged 6df7e7a). - -**Namespec 2.0 landed post-checkpoint, same day (ADR-0008, PDR-0020, -branch namespec-2.0):** eight domains renamed (Sarpadia→Urborg, Tamiyo→Ugin, -Narset→Aurelia, Tezzeret→Urabrask, Urabrask→Jin-Gitaxias, Augustin→Isperia, -Kasmina→Wrenn, Oona→Tamiyo), full cascade through the constitution, every -design chapter, appendices, root docs, model.dsl + diagrams (re-rendered), -site, wiki (strict build green) and the open tracker titles; mechanics and -all 45 invariants unchanged. Pre-2.0 records read through the ADR-0008 -concordance — beware the two reused names (Urabrask, Tamiyo). Publishing -the renamed site/wiki needs the owner-gated merge + push of namespec-2.0. +Design hardening — the hld-review burn-down (38 → 0 by 2026-08-31, pacing +signal) — plus the ADR-0002 information-management regime +(simic-357c92664c), still unstarted. **The pacing warning fired at session +9 and stands unanswered**: three working sessions (7, 9, 10) went to +owner-directed quality/consistency work outside the burn-down; ~1.7 +closures per working day needed to make the date. All design authority now +speaks **Namespec 2.0** (ADR-0008, PDR-0020): Urborg, Ugin, Aurelia, +Urabrask (compiler), Jin-Gitaxias (QA), Isperia, Wrenn, Tamiyo (witness); +pre-2.0 records read through the ADR-0008 concordance — beware the two +reused names (Urabrask, Tamiyo). ## In flight - Nothing claimed. Six wave:1 items remain; simic-d6ea02f9a9 (containment - owner) stays the natural next. Critical path: simic-0bf2c40dec → - simic-38a07fad39. -- simic-42e575b93c (NEW, blocked-on-owner): recover or reconstruct the 33 - missing simic-design design-system files — fork decided by whether the - claude.ai project survives (PDR-0019, proposed). -- Commissioning: both packs still absent from the session roster; the - training-state applied prompt still awaits owner relay upstream + owner — now "rollbacks are Isperia's accountability") stays the natural + next. Critical path: simic-0bf2c40dec → simic-38a07fad39. +- **Branch namespec-2.0 (commit cef43a7) is unmerged.** It carries the + whole Namespec 2.0 cascade: constitution, all chapters/domains renamed, + wiki strict build green (54 pages), site gates green, diagrams + re-rendered, 27 open issues retitled. The live site shows Namespec 1.0 + names until the owner merges and pushes. +- simic-42e575b93c (blocked-on-owner): design-system recovery fork + (PDR-0019, proposed) — decided by whether the claude.ai project survives. +- Commissioning: axiom-contract-engineering pack HAS landed in the session + roster (verified session 10's own-product run); yzmir-training-state + still absent, its applied prompt still awaiting owner relay upstream (carried since session 6). - simic-357c92664c (implement ADR-0002) ready, unstarted; plainweave - seeding needs owner presence at the gate. + seeding needs owner presence at the gate. Store confirmed still unseeded + (no baselines), so the Namespec rename touched no locked definitions. ## Open questions / blocked-on-owner -- PDR-0019: does the SimicDesignSystem_5a908e project survive anywhere in - your claude.ai/design UI? (Decides re-export vs reconstruction.) -- Watch the first post-merge Pages deploy: it carries both the new deploy - gates (PDR-0018) AND the dependabot pymdown-extensions 10.21→11.0.1 - bump (PR #1, merged after PR #2, untested together). Gate failures are - loud, not silent; local wiki builds will fail the version-drift gate - until `pip install -U -r tools/wiki/requirements.txt`. -- Pacing warning fired (metrics.md): next DECIDE resumes wave:1 closures - or re-plans the 2026-08-31 date by PDR — silent drift is the one - disallowed outcome. -- Tooling, for upstream relay: `filigree issue-list --status open` exited - 144 and ignored the status filter (CLI path; MCP unaffected). Wardline's - taint gate is inert on this repo (0 declared trust boundaries — green - means "nothing to check" until boundaries are annotated). +- **Merge + push namespec-2.0** to publish the renamed site/wiki (push is + owner-gated). Until then the public face contradicts the repo. +- vision.md's repo-discipline line now cites Namespec 2.0 (mechanical + reference update, recorded in PDR-0020 — the grant's scope is untouched); + confirm or revert at next grant review. +- Pacing warning (metrics.md): next DECIDE resumes wave:1 closures or + re-plans the 2026-08-31 date by PDR — silent drift is the one disallowed + outcome. +- Carried from session 9: PDR-0019's owner question (does the + SimicDesignSystem_5a908e claude.ai project survive?); watch the first + post-merge Pages deploy (new gates + pymdown bump untested together). ## Last checkpoint did -- PDR-0018 (accepted): recorded the owner-directed static-content review → - implementation → merge (5 commits, 2 review gates, 2 Criticals caught - pre-merge) and the durable deploy/build gates; public copy honesty fix. -- PDR-0019 (proposed): design-system recovery fork, owner-gated; tracker - item simic-42e575b93c created. -- Metrics: burn-down read flat at 38 — second consecutive flat session, - pacing warning FIRED. -- No bet changed horizon; roadmap untouched. +- Recorded the owner-directed Namespec 2.0 adoption: ADR-0008 + (architecture tier) + PDR-0020 (product tier), executed as a same-session + full cascade on branch namespec-2.0 (commit cef43a7), reconciled on top + of the concurrent session-9 checkpoint (PDR renumbered 0018→0020). +- Metrics: burn-down read still flat at 38 (namespec issue netted zero); + pacing warning stands; roadmap stamp updated, no bet changed horizon. +- Tracker reconciled: 27 open issues retitled to 2.0 names; + simic-d8369760b9 closed verified. ## Next session, start here -Answer the pacing warning first: claim simic-d6ea02f9a9 and resume wave:1 -closures, or re-plan the burn-down date by PDR. Check the post-merge -deploy status before any wiki/site work. PDR-0019's owner question can be -answered in passing and unblocks simic-42e575b93c. +Answer the standing pacing warning: claim simic-d6ea02f9a9 and resume +wave:1 closures — the contract-engineering pack landing makes +simic-0bf2c40dec (§9 contract shapes, critical path) the highest-leverage +alternative — or re-plan the burn-down date by PDR. Ask the owner for the +namespec-2.0 merge decision in passing. diff --git a/docs/product/metrics.md b/docs/product/metrics.md index a0592de..86186fb 100644 --- a/docs/product/metrics.md +++ b/docs/product/metrics.md @@ -1,4 +1,4 @@ -# Metrics — Simic Last read: 2026-08-09 (session 9 checkpoint) +# Metrics — Simic Last read: 2026-08-09 (session 10 checkpoint) > Dates here are pacing signals for the owner's own use — this is a spare-time > moonshot (owner-stated 2026-08-08, PDR-0005). A fired date is a re-plan signal @@ -13,7 +13,7 @@ ## Input metrics (the levers that move the north-star) | Metric | Target | Current | Read on | |--------|--------|---------|---------| -| Design-debt burn-down: open `hld-review` tracker items | 0 by 2026-08-31 | 38 open / 12 closed — flat across session 9 (2026-08-09), an owner-directed static-content quality session (PDR-0018, outside the burn-down). **Second consecutive flat session: the pacing warning session 8 armed now FIRES.** 22 days to the pacing date needs ~1.7 closures per working day; next DECIDE must either resume wave:1 closures or re-plan the date by PDR (PDR-0005: a fired signal must fire, never drift silently) | 2026-08-09 (session 9 checkpoint) | +| Design-debt burn-down: open `hld-review` tracker items | 0 by 2026-08-31 | 38 open / 13 closed — still flat through session 10 (2026-08-09), the owner-directed Namespec 2.0 cascade (ADR-0008, PDR-0020; the namespec issue itself opened and closed same-day, netting zero; 27 open items retitled, counts unaffected). **The pacing warning fired at session 9 and STANDS unanswered** — three working sessions without a wave:1 closure; 22 days to the pacing date needs ~1.7 closures per working day; next DECIDE must either resume wave:1 closures or re-plan the date by PDR (PDR-0005: a fired signal must fire, never drift silently) | 2026-08-09 (session 10 checkpoint) | | Phase progression: HLD §25 phases with acceptance tests (§21) passing | Phase A complete by 2026-09-30 (provisional — revise by PDR if the gate reshapes §9 materially) | 0 of 11 (pre-code) | 2026-08-08 | ## Guardrails (must NOT degrade) diff --git a/docs/product/roadmap.md b/docs/product/roadmap.md index 4d640f5..087fb6f 100644 --- a/docs/product/roadmap.md +++ b/docs/product/roadmap.md @@ -1,4 +1,4 @@ -# Roadmap — Simic Updated: 2026-08-08 (session 6 reconciliation; PDR-0012, ADR-0003) +# Roadmap — Simic Updated: 2026-08-09 (session 10; PDR-0020, ADR-0008 — Namespec 2.0 renames applied; no bet changed horizon) > Sequencing, WSJF / cost-of-delay, and dated forecasts are produced by > /axiom-program-management. This file records bets as INTENT, not a delivery