ticket-054 — restore skills-agent
discovery, prove a todo2code → Repair PR → independent Validator hand-off,
then add three bounded todo2code-grounded skills. Current state:
IN_PROGRESS / PUBLICATION; executable changes remain in target repositories.ticket-058 — synchronize release,
runtime, SDK and generated-provenance version identity and add a deterministic
drift gate. Plan and owner-ticket creation are approved; current state:
BLOCKED / WAIT_FOR_DEPENDENCIES while ticket-054 reserves integration.ticket-051 — wire
scripts/github-event-log.mjs into CI with explicit flags only. Current
state: PLAN / WAIT_FOR_APPROVAL; ticket-048 is now merged.ticket-052 — promote the Validator
autonomy operator checklist into agent-facing governance (AGENTS.md).
Current state: PLAN / WAIT_FOR_APPROVAL.ticket-076 — publishes independently
callable code2dsl, docs2dsl and config2dsl facades that emit strictly
validated, source-limited t2c.intent/v1 records. Full host/Docker checks,
Koru, Validator App and protected plan-first governance passed on exact head
944288f; PR #92 merged as main@24ca3a1 and its branch was deleted. Current
state: DONE / DONE.ticket-074 — routes Subactor-owned
semantic calls through central SubLLM with direct Z.AI GLM 5.2, OpenRouter
fallback ordering and provider-visible identity. Koru, independent GLM-5.2
review and protected checks passed; PR #88 merged as main@ceae696.
Current state: DONE / DONE.ticket-073 — defines canonical
t2c.analysis-policy/v1 selection, exact-evidence caching and nested
request/token/time ceilings while requiring LLM for selected semantic stages.
Koru, independent GLM-5.2 review and protected checks passed; PR #86 merged
as main@f0df52c. Current state: DONE / DONE.ticket-072 — redacts credentials,
contextual credential identifiers and provider management URLs once at the
OpenRouter boundary while preserving actionable diagnostics and fail-closed
require-llm. Koru, independent GLM-5.2 review and protected checks passed;
PR #84 merged as main@790b867. Current state: DONE / DONE.ticket-062 — adopted immutable
new-project v0.14.0 at exact SHA a22eb47, preserved all eight target
workstreams, assigned test/python-runtime.test.ts to sdk, aligned the
reusable workflow caller and passed protected PR #77. Current state:
DONE / DONE; merge main@a762580.ticket-055 — identifies OpenRouter
usage with explicit OPENROUTER_APP_NAME, falling back to the analysed
project’s folder name. Koru, Validator App and protected checks approved
exact head 7aae643; PR #74 merged as main@d0659ca. Current state: DONE.ticket-056 — restored both Docker E2E
profiles by supplying make and respecting the unlocked Rust library
contract. Koru, Validator App and protected checks approved exact head
1752f3d; PR #72 merged as main@5f8e831. Current state: DONE.ticket-050 — adopted immutable
new-project v0.13.2, assigned CHANGELOG.md and .env.example to the
governance workstream, and made governance checks recoverable while retaining
fail-closed exact-head approval. Koru, Validator and protected checks passed;
PR #70 merged as main@f60d3cc. Current state: DONE.ticket-049 — Validator autonomy audit,
operator guide and refactor plan accepted by the user on 2026-08-08. Sibling
tickets 050–052 retain independent approval and ownership gates. Current
state: DONE. See
AUTONOMY_AND_REFACTOR_PLAN.md.ticket-053 — documents the existing
CI-form governance check as a blocking pre-push gate. Koru and Validator
approved exact head 079de29; protected PR #67 merged as main@100a7d2
and its implementation branch was deleted. Current state: DONE.ticket-048 — republished ticket-047’s
GitHub acquisition adapter with explicit-only inputs and no ambient
process.env fallback. Validator approval and all protected checks passed on
exact head 92f99dc; PR #66 merged as main@f1b3d5d. Current state: DONE
for publication purposes; the ticket-local historical status remains part of
the merged audit record.ticket-047 — built the first GitHub
acquisition adapter for the t2c.event-log/v1 codec, mapping one bounded
push, pull_request, pull_request_review or completed workflow_run
payload onto the closed event vocabulary. Host, governance, Docker and
focused checks passed locally, but the work never reached protected main:
it carries no Koru or Validator approval, and its squashed commits are
rejected by CI governance. Republication is tracked as ticket-048. Current
state: DONE.ticket-046 — generates a canonical,
atomic logs.dsl.txt beside every succeeded, degraded and failed pipeline
manifest. Koru and Validator approved exact head 1180e45 with
openrouter/z-ai/glm-5.2; protected PR #62 merged as main@c1decdb and its
implementation branch was deleted. Current state: DONE.ticket-045 — defined the canonical,
tamper-evident t2c.event-log/v1 contract and validated its 17-event
logs.dsl.txt fixture. Koru and Validator approved exact head 46210e1
with openrouter/z-ai/glm-5.2; protected PR #60 merged as main@a66eb40
and its implementation branch was deleted. Current state: DONE.ticket-044 — adopted immutable
new-project 0.11.0 and its canonical work-classification package through
local Goal. Koru and Validator approved exact head 80f860c with
openrouter/z-ai/glm-5.2; protected PR #58 merged as main@aae9ec5 and its
implementation branch was deleted. Current state: DONE.ticket-043 — exposed ticket-040’s
deterministic read-only observer through make preflight, with canonical
stdout, stable exit codes and complete Git-state non-mutation tests. Koru and
Validator approved exact head 87ce55c with openrouter/z-ai/glm-5.2;
protected PR #56 merged as main@4a7445a. Current state: DONE.ticket-042 — bounded the aggregate
semantic deadline of compare-workspace across both pipelines and all
document chunks with 2x scaling and a 40-minute ceiling. Koru and Validator
approved exact head 5b51880 with openrouter/z-ai/glm-5.2; protected PR
#52 merged as main@2c16449. Current state: DONE.ticket-040 — bounded, read-only
workspace preflight binding exact local Git state, managed governance and the
active ticket before governed edits. Ten focused tests plus host, Docker,
governance and complexity gates passed; Koru and Validator approved exact
head 567424b with openrouter/z-ai/glm-5.2; protected PR #49 merged as
main@008bee5. Current state: DONE.ticket-041 — strict immutable Git
materialization validation and exact-tree graph/truth-map evidence assembly
into the existing t2c.branch/v1 projector. Focused, host, Docker,
governance and complexity gates passed; Koru and Validator approved exact
head 3779613 with openrouter/z-ai/glm-5.2; protected PR #48 merged as
main@f188025. Current state: DONE.ticket-021 — assigned root-level
generated analysis formats to the integration workstream without changing
ticket-directory ownership or the managed wrapper. Koru and Validator
approved exact head 9e2feff with openrouter/z-ai/glm-5.2; PR #33 merged
as main@8ebeb66. Current state: DONE.ticket-039 — bounded, read-only local
Git materializer for exact branch/tree/merge-base/ahead-behind, stable patch
identity and textual collision evidence. Focused, full host/Docker,
governance, complexity and live branch checks passed; Koru and Validator
approved exact head 29df450 with openrouter/z-ai/glm-5.2; PR #44 merged
as main@2948f4a. Current state: DONE.ticket-037 — deterministic,
fail-closed t2c.branch/v1 projection over immutable branch evidence.
Fourteen focused tests, full host/Docker verification, Koru and Validator
approved exact head 50d6dba with openrouter/z-ai/glm-5.2; PR #42 merged
as main@b5d2417. Current state: DONE.ticket-038 — reconciled ticket-036’s
stale pending-review narrative with protected completion evidence. Koru and
Validator approved exact head 670894d using
openrouter/z-ai/glm-5.2; PR #40 merged as main@ed35d3f. Current state:
DONE.ticket-036 — deterministic,
provenance-preserving t2c.truth-map/v1 core projection. Koru and Validator
approved exact head 65b4bc1 with openrouter/z-ai/glm-5.2; PR #35 merged
as main@15d2b26. Current state: DONE.ticket-034 — scales each OpenRouter
request timeout from bounded input, output and structural-complexity pressure,
retaining the configured default at baseline and increasing by 2x steps up
to 8x and 600 seconds. Exact-head Validator approval used
openrouter/z-ai/glm-5.2; implementation merged in PR #31 as
main@6116961. Current state: DONE.ticket-019 — published the
dependency-free Python SDK from one root pyproject.toml, passed package,
application, SDK, Docker and protected exact-head validation, and merged PR
#28 as main@e333ace. Current state: DONE.ticket-035 — declared the five atomic
Python publication paths as integration-owned shared contracts, preserved the
immutable standard provenance and passed exact-head Validator review plus all
protected checks. Implementation merged as main@a2441f8; current state:
DONE.ticket-020 — role-bound trusted intake
with persistent manager/user/dev assignments, CQRS/event sourcing, strict
schemas, dependency-free Protobuf codecs and Python/TypeScript CLI, MCP and
A2A parity. Implementation commit 06a2faa is contained in protected main;
current focused validation passes 9/9, full verification has 0 failures and
policy 0.10.0 governance passes.ticket-018 — adopted hardened
wellmanifest/new-project 0.10.0 at immutable merge 9706e63, moved trusted
App authority outside PR control, switched Koru to z-ai/glm-5.2, passed
exact-head App review and protected checks, and merged as main@6ad85bd.ticket-017 — repaired mutating command
help, Polish prohibition polarity and repository-bound path resolution;
independently audited the concurrent path/action-planning baseline and added
isolated Docker E2E core and full-toolchain gates. Current state: DONE.ticket-009 — canonical structured
response contracts. All seven production OpenRouter boundaries now generate
their provider schema and runtime parser from one typed source, retain
rejected-response metadata and fail closed without semantic coercion.
Published as d0fc143; current state: DONE.ticket-008 — upstream governance
hardening. wellmanifest/new-project 0.6.0 now uses role-typed participant
templates, explicit unresolved ownership, active-ticket reuse and a separate
project/TICKETS.md index that cannot overwrite generated analysis. Current
state: DONE.ticket-007 — explicit unresolved
response routing. Every communication issue now names a known participant or
the role sentinel unresolved:human / unresolved:agent; no participant is
guessed or created. Current state: DONE.ticket-006 — canonical structured-output
conformance. Retained exact fail-closed diagnostics and a schema drift gate;
rejected both tested Qwen routes before graph mutation. Current state:
DONE.ticket-005 — audited communication and
cross-language reranking. Retained section-aware user-*/ai-* Intent DSL
plus explicit response ownership; rejected the live semantic candidate after
three fail-closed provider contract violations and zero demonstrated coverage
improvement. Current state: DONE.ticket-004 — language-independent topic
matching benchmark. Rejected unsafe raw embeddings and added a separately
reported 6-positive/6-negative cross-language gold cohort. Current state:
DONE.ticket-003 — deterministic audit of
residual changelog diagnostics and one evidence-gated correction. Removed
547 false review findings with stable graphs. Current state: DONE.ticket-002 — cross-repository semantic
benchmark and iterative todo2code quality improvements. Current state:
DONE.user-* and ai-* sections to typed Intent DSL
without ingesting ticket evidence/logs, reject unstructured migration
silently losing content, and attach the required role plus participant IDs
to every communication divergence.responseRequiredRole=human but an
empty responseRequiredFrom because the agent refused to fabricate a
human-owned user-* file. Ticket-007 now emits the explicit role sentinel
unresolved:human or unresolved:agent, never a guessed identity.document records exist.statement.object remain symbols rather than false paths.document
records.nie wolno scored unknown, nie może scored optional because the
permissive rule matched the może inside the ban, and \bmuszą\b could never
match at all: JavaScript’s \b treats ą as a non-word character.topicKeywords, guarded against ss/us/
is/as/os endings and folding -ies to -y. On its own this added
relations without moving coverage, because aligned never read the graph;
the topic-anchor change below is what converted relations into the metric.t2c.conclusion/v1 before rendering Markdown, rather than accepting free-form
narrative as the primary result.deterministic|prefer-llm|require-llm, consistent with NL and Markdown
extraction modes.markdown.ts against
the repository tree before linking, while preserving the current rejection
of prose fragments and refusing ambiguous basename matches. The linker indexes
basenames owned by exactly one full path; validation.ts, types.ts and
git.ts name several files here and keep requiring a directory.PLANNED_NOT_IMPLEMENTED: once the deterministic
converter emitted document records the count went to 579, of which 574 came
from documentation and 555 had modality: unknown. Scoping the rule to
required/recommended brought it back to 22..github/workflows/, so the advertised CI conversion is exercised in real
repositories, not only in an isolated fixture.project.sh correct and validate generated README metadata against
package.json; external code2docs fallback values (0.1.0, MIT and a
TypeScript runtime badge) can no longer be published silently.project.sh generators in a detached tracked-only snapshot,
reject references to untracked inputs, temporary paths and unavailable
parser downloads, and make source-changing prefact -a explicitly opt-in.project/ namespace: root-level
code2llm/redup output is analysis, while communication requires a recognised
ticket directory, participant registry or explicit front matter. This keeps
project/analysis.toon.yaml stable without creating agent_log noise.code2llm, domd, pactfix) and fix Python ignore-scope
overflow plus false-positive project/ communication discovery.code2logic, code2docs, redup): all succeeded with deterministic
code-change planning; fix configuration ??/|| SyntaxError that blocked
the batch.src/extractors/ast.ts into independently
testable TypeScript/JavaScript, Python, Go, Java and Rust modules behind the
existing common adapter envelope.token_get_all(..., TOKEN_PARSE), preserves the shared fact envelope and
fails open when PHP is absent; A/B on redsl converted 40 tracked files into
2,127 unique records and removed 18 warning diagnostics.require-llm pipeline run instead of calling selected stages
itself, which is how it drifted to two: a bespoke caller cannot go out of date
against a pipeline it does not run. History is reported and never gates —
t2c.live-contract-check/v2, 50 runs, restored from CI cache and published as
an artifact.make demollm execute and verify all six semantic LLM stages
end-to-end, with no deterministic fallback and a manifest-based PASS gate.make demollm runs
completed, with LLM_RESPONSE_INVALID sinking three of them on well-formed
but non-existent record IDs. The retry quotes the validation error back and
keeps both attempts in the audit; a second fabrication still fails the run.make demollm flakiness without accepting invented
evidence: derive conclusion recordIds only from the cited diagnostics,
continue to reject unknown diagnosticIds. The historical runtime assigned
blank response-local proposal keys; ticket-009 now rejects them and relies on
the corrective retry because inventing a key changes provider intent. Live
contract and full six-stage run 20260730T185205Z-312a0535 passed with
generator version 2 before that hardening.compactSynthesisPayload
collected record IDs from diagnostics and then truncated records to 500, so a
large repository could ship a diagnostic citing a record the model never saw.
Diagnostics whose evidence did not survive the record budget are now dropped
from the payload instead of inviting a fabricated citation.subactor/platform repository (144 Markdown files, 43 configs, .mjs
sources) and fix what it exposed: an absolute host path aborted code-change
planning, HTTP routes and hostnames were extracted as repository paths and
code symbols, and configuration declarations formed a quadratic subgraph.module_fact for AST. configuration_file_fact carries a bounded inventory
of declared keys, but links as file evidence only through an explicit path.
A capability-topic prototype created 288 cross-source links from five files
on code2llm and was rejected; the hardened run keeps exactly 2 explicit
path links and 0 system~system relations.system record is a fact with lifecycle
implemented, and for infrastructure repositories the implementation can be
the configuration. Semantic impact must be measured again after the
capability-topic hardening rather than inferred from the rejected noisy run.system lane in the Intent-vs-Reality SVG. The lane was
added to LANE_ORDER, but the eight-lane table is now wide enough that the
topic column truncates earlier; check whether a combined “evidence” column or
a wider viewBox reads better.HEAD: 16 of 46 aligned
topics on subactor/platform rest on configuration alone against 4 of 89 here,
so an undifferentiated headline reads the same for a repository whose evidence
is a third weaker. RealityRow.evidence and totals.alignedByEvidence now
report the split; neither changes what counts as aligned, because a
behaviour whose implementation is configuration is implemented.detectPolarity so “without / bez + dopełnienie” does not negate
the governing intent (for example “Document X without inventing files”);
covered by the offline gold set and a focused unit test.path.resolve.
Missing root, sourcePath or text now produces a named option error at
the public deterministic and audited NL boundaries..github/workflows/ci.yml against duplicate top-level keys. Two
concurrent edits produced a second schedule: block, which YAML silently
resolves to the last one — verify:workflows now rejects that state before
a workflow can silently lose a trigger.Cel: domknąć pętlę od intencji w języku naturalnym, przez Intent Evidence DSL, do planowanej zmiany kodu i weryfikacji po re-analizie. System pozostaje guardem intencji: LLM może proponować, runtime waliduje, człowiek zatwierdza.
markdown.ts);
niejednoznaczne nazwy (validation.ts, types.ts) wymagają katalogu.required/recommended; opisowe prose nie podnosi
PLANNED_NOT_IMPLEMENTED.evaluation/gold/v2/dataset.json z kanałem
documentation-deterministic (prescriptive vs descriptive w ekstrakcji),
zakresem diagnostics (false DONE bez dowodu vs DONE z dowodem, partial
implementation jednego ticketu), ośmioma pozytywami capability-topic,
czternastoma parami zabronionymi oraz osobnym kohortem cross-language
(6 oczekiwanych, 6 zabronionych). npm run evaluate:gold liczy teraz v2; v1
pozostaje pod evaluate:gold:v1.capability-topic na tyle, by zmiana progu trzech
tematów dawała mierzalny spadek w obie strony. Siedem pozytywów wykrywa
regresję progu, ale nie pozwala go stroić.ticketu,
foundera), odfiltrowanie polskich słów funkcyjnych (nie 175, jest 110 i
jako 54 były jednymi z najczęstszych „tematów” korpusu platformy) oraz
kotwiczenie deklaracji bez własnego celu w powiązanym module. A/B na tej samej
treści: aligned 25 → 43 i coverage 5,9% → 10,0% na subactor/platform,
74 → 82 i 22,0% → 24,4% tutaj.subactor/platform; wzajemny top-1
usunął błędy kosztem zerowego wzrostu pokrycia. Ticket-005 dodał osobno
mierzone, ugruntowane kontrakty rerankera i osiągnął 6/6 na przejrzanych
fixture’ach, lecz trzy rzeczywiste odpowiedzi Qwen/OpenRouter złamały
wymagany kształt lub typ danych. Żadna relacja nie powstała, a eksperyment
nie został wyeksportowany produkcyjnie. Następny kandydat musi najpierw
dowieść stabilności provider/schema na śledzonym repozytorium, a dopiero
potem wzrostu pokrycia.subactor/platform, które dotykają kilku modułów i
dlatego celowo nie dostają kotwicy. Rozstrzygnięcie ich wymaga dowodu
mocniejszego niż wspólne tematy — bez niego wybór modułu byłby zgadywaniem.isModuleTopicSource. Na subactor/platform ze 111 diagnostyk
CHANGELOG_WITHOUT_IMPLEMENTATION dopasowanie tematyczne sięgnęłoby dokładnie
jednego modułu w 8 przypadkach (7%) przy 15 niejednoznacznych; w tym repo ze
121 diagnostyk — 7 (6%) przy 105 niejednoznacznych (87%). Wpis wydania
opisuje zwykle zmianę w kilku modułach naraz, więc dopuszczenie go do
dopasowania tematycznego kupiłoby kilka procent mniej diagnostyk za setkę
arbitralnych relacji.indexModuleAnchors) objąć wpis changelogu, gdy trafia
w dokładnie jeden moduł. To 8 i 7 przypadków wyżej, bez wpuszczania
niejednoznacznych do grafu — ale zmienia znaczenie
CHANGELOG_WITHOUT_IMPLEMENTATION, więc wymaga decyzji, nie samego pomiaru.missingFields / AMBIGUOUS_REQUIREMENT wskazują
konkretne pole i kandydujące ścieżki (ticket-011).weekly 218,741→53,362 ms,
a nlp2uri przeszedł 619 rekordów / 20 żądań w 194,750 ms.npm run live:models na 267 rekordach tego repo pokazał, że
mistralai/codestral-2508 i google/gemini-3-flash-preview zgadzają się co
do action/modality/polarity/lifecycle tylko w 169 z 267 rekordów (63,3%) —
tańszy model nie odpowiada tak samo, a porównanie nie mówi, który ma rację.
Potrzebne są przypadki gold nad polami wzbogacenia, nie kolejny przebieg live.ticket-014 — nie uznawać nowej
możliwości za zaimplementowaną wyłącznie dlatego, że wskazany plik istnieje;
wymagany dodatkowy dowód symbolu/tematu albo jawna abstencja. Gold ma parę
negatyw/pozytyw, a Koru PLF-003 przeszedł wykrycie, patch, pytest i re-analizę.ticket-015 — zachować złożoną intencję
implement ... and verify ... w tytule code-change; klasyfikacja czasownika
pomocniczego nie może tworzyć Implement Implement ... and it ....implemented obok AST+Git.t2c.code-change-plan/v1: paths/symbols, evidence
(recordIds/diagnosticIds/conclusionIds/proposalIds), acceptance criteria,
risk, rollback, status proposed, content-bound ID/hash i runtime provenance.PLANNED_NOT_IMPLEMENTED /
CHANGELOG_WITHOUT_IMPLEMENTATION i powiązanych propozycji TODO
(bez auto-apply, bez udawania codegen).project/ i artefaktów runu todo2code; SVG, lockfile i zwykła dokumentacja
pozostają dozwolone. Audyt własnego repo zmniejszył szum z 9 do 3 planów.t2c.code-change-acceptance/v1: re-diagnose po zmianie,
cleared vs remaining diagnostics, fail gdy pojawią się nowe blocking.propose_code_change / evaluate_code_change na grafie
before/after; SDK TypeScript convenience methods.code-change-plans.json w każdym udanym runie
(etap deterministyczny codeChangePlanning w manifeście).CODE_CHANGE.review.md + audit
t2c.code-change-review/v1 (hash-bound, bez apply źródeł); CLI
render-code-change, MCP/A2A/SDK i zapis w pipeline... oraz
hostnames jako fałszywych symboli (gold + unit).t2c.code-change-source-patch/v1: instrukcje
per path, opcjonalny unified diff z walidacją path/sekretów, content-bound
hash; CLI propose-source-patch, MCP/A2A/SDK i zapis w pipeline; propozycja
sama nigdy nie wykonuje apply.apply-source-patch / MCP): tylko
gdy każdy edit ma unifiedDiff; instruction-only jest odrzucany; receipt
idempotentny, ma runtime provenance i weryfikuje stan plików przy powtórzeniu;
pełny preflight, ochrona symlink/root i rollback chronią przed częściowym
zapisem. LLM wypełniający diff — nadal opcjonalna przyszła gałąź.detectPolarity nie traktuje „without / bez + dopełnienie” jako
negacji całego zdania (gold + unit).t2c close-code-change (plan lub plan-set +
before/after graph) → t2c.code-change-close-result/v1 bez auto-DONE.detectModality nie traktuje nagłówków „(recommended)” / gołych
przymiotników jako deontycznych (mniej fałszywych PLANNED_NOT_IMPLEMENTED
na code2logic).