Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -35,8 +35,11 @@ jobs:
env:
GENTLE_PI_REQUIRE_NATIVE_BINARY: "1"

- name: Verify generated runtime modules
run: pnpm run check:runtime-modules

- name: Verify package contents
run: node scripts/verify-package-files.mjs

- name: Verify packed installation
run: pnpm run test:packed-runner
run: pnpm run test:packed-package
94 changes: 31 additions & 63 deletions README.md

Large diffs are not rendered by default.

298 changes: 51 additions & 247 deletions assets/orchestrator-delegation.md

Large diffs are not rendered by default.

42 changes: 11 additions & 31 deletions assets/orchestrator.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,7 +38,7 @@ Delegation is not optional once complexity appears. If a task crosses the trigge
Route work through the smallest harness that is safe. Three tiers:

1. **Inline Direct** β€” small, mechanical, parent has context (typo, one-file edit, read-only check of 1-3 known files, bash for state). No SDD ceremony; stop when it is no longer small.
2. **Simple Delegation** β€” generic non-SDD exploration β†’ `gentle-ai-explore`; bounded implementation β†’ `gentle-ai-worker`; command-running generic non-SDD verification β†’ `gentle-ai-verify`. Try its package role; if missing/unusable, use native `Agent` under the same read-only mapping/verification constraints and report fallback. SDD roles stay inside SDD; review lenses inside reviews.
2. **Simple Delegation** β€” generic non-SDD exploration β†’ `gentle-ai-explore`; bounded implementation β†’ `gentle-ai-worker`; command-running generic non-SDD verification β†’ `gentle-ai-verify`. Try its package role; if missing/unusable, use native `Agent` under the same read-only mapping/verification constraints and report fallback. SDD roles stay inside SDD.
3. **SDD (optional)** β€” selected only by an explicit request (`/sdd-new`/`/sdd-ff`/`/sdd-continue` or a direct ask) or an accepted proposal; size, file count, or risk alone never selects SDD. Suggest it organically when durable proposal/spec/design/tasks would materially reduce substantial ambiguity. Once selected, do not jump to implementation; create artifacts and gate for approval.

## Delegation Rules
Expand All @@ -51,15 +51,13 @@ Mandatory Delegation Triggers β€” stop rules; once fired, delegate through the b

1. **4-file rule** β€” 4+ files to understand β†’ delegate a scout/mapping task.
2. **Multi-file write rule** β€” 2+ non-trivial files touched β†’ delegate one writer.
3. **Lifecycle gate rule** β€” commit/push/PR/release validates one receipt and exact target with zero actors. Direct commit uses the durable native-validated transaction; unresolved state blocks publication. Changed authority fails closed.
4. **Incident rule** β€” diagnose wrong cwd/worktree/git/tooling incidents separately. An incident never reopens a closed review lineage or resets its budget.
5. **Verification rule** β€” executing/delegating verification commands β†’ `gentle-ai-verify`; only the 1-3-file read-only check stays inline.
6. **Long-session rule** β€” ~20 tool calls, 5 exploratory reads, or 2 non-mechanical edits without delegation β†’ pause and delegate.
7. **Review actor rule** β€” review lenses run only when selected by ordinary transaction start; explicit Judgment Day uses its two named judges. Lifecycle and SDD boundaries launch zero review actors.
3. **Incident rule** β€” diagnose wrong cwd/worktree/git/tooling incidents separately before resuming work.
4. **Verification rule** β€” executing/delegating verification commands β†’ `gentle-ai-verify`; only the 1-3-file read-only check stays inline.
5. **Long-session rule** β€” ~20 tool calls, 5 exploratory reads, or 2 non-mechanical edits without delegation β†’ pause and delegate.

{{GENTLE_PI_BACKGROUND_POLICY}}; rules: the background-subagents block in the delegation contract.

Full table, Work Routing Ladder examples/model-routing detail, Cost and Context Balance, Canonical Workflows, Review Actor Materialization, and the mirrored gentle-ai canon (blocking-prompt relays + defect handoff, language, delegation, native checking, review execution + stop table): `{{GENTLE_PI_DELEGATION_PATH}}`.
Full table, Work Routing Ladder examples/model-routing detail, Cost and Context Balance, Canonical Workflows, and the mirrored gentle-ai canon (blocking-prompt relays, language, and delegation): `{{GENTLE_PI_DELEGATION_PATH}}`.

## SDD Workflow (lazy-loaded)

Expand All @@ -73,44 +71,26 @@ Hard preflight invariant: `openspec/config.yaml`, existing SDD changes, installe

## Memory Contract

When Engram or another callable memory package is available, the parent owns context selection and subagents own write-back. Retrieval rules differ by task type, matching the gentle-ai (OpenCode) contract.

### Non-SDD delegation

- Read context: the parent/orchestrator searches memory (the injected Engram search tool), selects relevant observations, and passes them into the subagent prompt. The subagent does NOT search memory itself.
- Write context: the subagent MUST save significant discoveries, decisions, or bug fixes via the injected Engram save tool before returning when memory tools are available.
- Prompt forwarding: when delegating, add a concrete instruction such as: `If you make important discoveries, decisions, or fix bugs, save them to Engram via the available memory save tool with project: '<project>' before returning.`

SDD phase table, artifact keys, and the lifecycle rule: `{{GENTLE_PI_MEMORY_PATH}}`.
When memory is available, the parent selects context and subagents save significant discoveries before returning. SDD phase table, artifact keys, and persistence guidance: `{{GENTLE_PI_MEMORY_PATH}}`.

## Skill Registry Protocol

The parent resolves skills once per session or before first delegation: read `.atl/skill-registry.md` if present, match task context/target files against the `Trigger / description` column, and pass only matching `Path` values to subagents under `## Skills to load before work`. Subagents must read those exact `SKILL.md` files before reading, writing, reviewing, testing, or creating artifacts, and should not have to rediscover the registry. If the registry is absent, continue but say project-specific skill paths were unavailable.
The parent resolves matching skill paths once per session and passes them under `## Skills to load before work`. Subagents read those exact `SKILL.md` files before work; if the registry is absent, report that project-specific paths were unavailable.

Fallback-report semantics (`paths-injected`/`fallback-registry`/`fallback-path`/`none`) and the SDD-executor skill distinction: `{{GENTLE_PI_SKILLS_PATH}}`.

## Intent-Driven Skill Discovery

For skill-shaped requests, do not treat injected `<available_skills>` as complete; use the registry/filesystem only as a discovery aid, never to override a small request or a user's concrete ask. Discovery order, the common intent-hint table, and fallback behavior when no skill matches: `{{GENTLE_PI_SKILLS_PATH}}`.

## Gentle AI RDD ownership

Gentle AI dynamically supplies runtime-specific RDD instructions via generated Pi APPEND_SYSTEM composition. Follow only those exact native instructions; if absent or unsupported, this package does not invent or fall back.

## Safety

- Relay blocking prompts losslessly; STOP for the human's answer.
- Never commit unless the user explicitly asks.
- Ask before destructive git operations, publishing, or irreversible file changes.
- Keep writes single-threaded unless isolated worktrees are explicitly approved.
- Preserve human control: user decisions beat agent momentum.

## Bounded Review Transactions

Compact `gentle_review` uses `start -> finalize -> validate`; START freezes scope, risk, and budget; FINALIZE permits one correction, failure escalates.

Compact gates use zero actors and rederive authority, target, and evidence. Pi adds one-shot authorization. Legacy authority is read-only; Judgment Day is separate.
Release from protected `main` may bypass receipt validation only when its immutable remote SHA and required CI are proven; otherwise native receipt validation applies.
Major and post-incident releases require explicit extraordinary review even when fast-path checks pass.

Dangerous-command safety remains independent and authoritative.

SDD completion adds no review or Judgment Day pass.

Controller and actor contract: `{{GENTLE_PI_DELEGATION_PATH}}`.
17 changes: 1 addition & 16 deletions assets/sdd-orchestrator-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -308,19 +308,4 @@ Automatic mode does not override reviewer burnout protection.

## Provider Defect Handoff

This section applies when an SDD phase or review lifecycle operation appears blocked by a Gentle AI provider defect. The full contract lives in `assets/orchestrator-delegation.md` under `#### Gentle AI Provider Defect Handoff (MANDATORY)`; it ports Gentle AI's v2.4.0-rc.8 handoff consent contract (the `gentle-ai.review-integration.consent/v3` envelope; canonical source `internal/assets/generic/sdd-orchestrator.md` at tag `v2.4.0-rc.8`, a prerelease not present in v2.3.0 stable). Pi review commands use `gentle_review`.

Concise rules:

- Classify admissibility before relaying: offer the handoff only when a Gentle AI invocation produced the failure, not when its runtime merely hosted it.
- Never offer to switch to, inspect, modify, or directly repair the Gentle AI repository from this SDD workflow. If an upstream envelope offers direct repair, reject it as semantically inadmissible and issue the orchestrator-owned handoff envelope instead.
- Ask the user first, in the active conversation language, for explicit consent to report the apparent defect. Present one single-select blocking envelope with exactly three semantic choices in this order. Its exact internal answer tokens are `report_and_continue`, `continue_without_reporting`, `stop_here`. Do not expose machine or internal codes in user-facing labels.
- Privacy scrub immediately before the first GitHub operation: exclude raw argv, absolute paths, private project names, usernames, hostnames, credentials, diffs, source contents, and environment values.
- Complete a definitive lookup across open and closed issues in `Gentleman-Programming/gentle-ai` before any write; only a definitive lookup may branch to GitHub mutation.
- Derive the evidence channel only from the installed build string: recognized prerelease tags are `-rc.` and `-main.`; every other build is stable. A fix counts only in the installed build's channel. A fix published only to the other channel gets one occurrence comment naming where it is published; never recommend switching channels.
- If the installed build predates the relevant published fix, recommend installing it and reproducing; do not create or comment for that occurrence yet. If the installed build demonstrably contains the fix and still reproduces, treat it as a possible regression: comment on a suitable canonical tracker or create a linked regression issue; never reopen automatically.
- Confirmed creation requires the GitHub create operation to confirm a newly-created issue identity/URL; never infer creation from output text alone.
- On search, comment, or creation failure/ambiguity/timeout/permission/unknown: perform no further GitHub mutation and no blind retry; preserve all consumer state, then execute the exact captured provider-owned decline invocation exactly once, validate it, re-enter native negotiated STATUS, and resume the already-held consumer continuation.
- Both continue choices execute that exact captured decline invocation exactly once; never synthesize the decline command, target, token, or consumer continuation from prose. If unavailable or ambiguous, fail closed.
- Do not invoke `gentle-ai review mode disable` at clone or global scope within this handoff. Do not turn RDD off or on within this handoff.
- Resume after an installed published fix or an explicit maintainer-authorized, documented native recovery or reset that the runtime contract supports; then re-enter through native status. Never resume against unpublished code.
When an SDD task encounters a possible Gentle AI provider defect, the full contract lives in `assets/orchestrator-delegation.md` under `#### Gentle AI Provider Defect Handoff (MANDATORY)`. This workflow intentionally provides no summary, alternate report route, or RDD lifecycle instruction.
20 changes: 9 additions & 11 deletions docs/native-authority-architecture.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

← [Back to README](../README.md)

U8 closed the U1-U7 slimming work. Issue [#191](https://github.com/Gentleman-Programming/gentle-pi/issues/191) then extracted Pi command projection and publication revalidation from graph-v1 authority storage. New ordinary review authority is native; Pi retains permanent consumer infrastructure and explicit graph-v1 Judgment Day.
U8 closed the U1-U7 slimming work. New ordinary review authority is native; Pi retains permanent consumer infrastructure and explicit graph-v1 Judgment Day. Delivery commands remain ordinary repository-policy operations, not review gates.

## Current Ownership

Expand All @@ -12,8 +12,7 @@ U8 closed the U1-U7 slimming work. Issue [#191](https://github.com/Gentleman-Pro
| Canonical consumer identities | Permanent Pi module `lib/review-canonical.ts` |
| Git common-directory and repository identity | Permanent Pi module `lib/review-repository.ts` |
| Immutable reviewer candidate views | Permanent Pi module `lib/review-candidate-view.ts` |
| Typed command targets, remote binding, release projection, and publication rechecks | Permanent Pi module `lib/review-publication-gate.ts` |
| Direct commit transaction and dangerous-command safety | Pi; independent of review authority |
| Dangerous-command safety | Pi; independent of review authority and delivery decisions |
| Explicit Judgment Day and historical graph semantic replay | Pi graph-v1 until a separately proven replacement exists |
| Historical graph receipt validation | Pi graph-v1 transaction, reachable only for historical graph authority and explicit Judgment Day |

Expand Down Expand Up @@ -43,7 +42,6 @@ The permanent modules have direct production consumers after #191:
| `review-canonical.ts` | `extensions/gentle-ai.ts` and eight live review modules |
| `review-repository.ts` | `extensions/gentle-ai.ts`, graph object store, legacy detector, snapshot, and transaction |
| `review-candidate-view.ts` | `extensions/gentle-ai.ts` |
| `review-publication-gate.ts` | `extensions/gentle-ai.ts` and graph-v1 receipt validation in `review-transaction.ts` |

The remaining ordinary reducer is not dead authority. Historical graph event replay calls it to validate semantic adjacency. Deleting it would weaken graph integrity even though controller mutation is read-only.

Expand All @@ -56,7 +54,7 @@ node scripts/measure-native-authority-slimming.mjs origin/main HEAD WORKTREE
git diff --shortstat origin/main..HEAD
git diff --shortstat HEAD
git diff --shortstat origin/main
wc -l docs/native-authority-architecture.md scripts/measure-native-authority-slimming.mjs lib/review-publication-gate.ts
wc -l docs/native-authority-architecture.md scripts/measure-native-authority-slimming.mjs
```

The measurement script defines package footprint as unpacked bytes selected by `package.json#files` plus npm's always-included `package.json`, `README.md`, and `LICENSE`. Source LOC is physical lines in `extensions/**/*.ts`, `lib/**/*.ts`, `runtime/**/*.mjs`, and `scripts/**/*.mjs`. Test LOC is physical lines in `tests/**/*.ts` and `tests/**/*.mjs`.
Expand All @@ -74,10 +72,10 @@ The committed U1-U4 baseline is `origin/main..HEAD`. U5-U8 and #191 are in the u
| Diff boundary | Files | Additions | Deletions |
| --- | ---: | ---: | ---: |
| Committed U1-U4: `git diff --shortstat origin/main..HEAD` | 21 | 770 | 2,027 |
| Unstaged U5-#191, including three untracked delivery artifacts | 33 | 1,591 | 6,940 |
| Accumulated U1-#191, including three untracked delivery artifacts | 46 | 2,302 | 8,908 |
| Unstaged U5-#191, including two untracked delivery artifacts | 33 | 1,591 | 6,940 |
| Accumulated U1-#191, including two untracked delivery artifacts | 46 | 2,302 | 8,908 |

The two unit ranges are intentionally reported separately. `git diff --shortstat` excludes untracked files, so the architecture report, measurement script, and publication-gate module contribute 726 added lines to the reported U5-#191 and accumulated totals. Unit-range additions and deletions are not arithmetically additive because U5-#191 also edits or removes paths already changed by U1-U4; the accumulated comparison is Git's final origin-to-worktree result.
The two unit ranges are intentionally reported separately. `git diff --shortstat` excludes untracked files, so the architecture report and measurement script are outside the tracked shortstat totals. Unit-range additions and deletions are not arithmetically additive because U5-#191 also edits or removes paths already changed by U1-U4; the accumulated comparison is Git's final origin-to-worktree result.

## Retired Modules

Expand Down Expand Up @@ -114,10 +112,10 @@ The only platform-specific repository test is skipped outside Windows. U8 theref

## #191 Outcome

#191 moved typed command targets, configured push destinations, push-ref probes, release projection, release fast-path evaluation, and publication rechecks into `review-publication-gate.ts`. The extension imports that module directly for ordinary native publication. `review-publication-gate.ts` imports no graph transaction, object store, graph schema, lock, or snapshot module.
Issue #191 removed Pi-owned delivery authorization and publication-target revalidation from ordinary review. The extension does not import a publication-gate module or consult review authority to decide commit, push, pull-request, or release delivery.

`review-transaction.ts` imports the shared target primitives only for historical graph receipt validation. Its reducer, replay, object-store, lock, snapshot, and ordinary semantic-replay dependencies remain reachable from explicit graph-v1 Judgment Day, so no additional module deletion is justified.
`review-transaction.ts` retains its reducer, replay, object-store, lock, snapshot, and semantic-replay dependencies for explicit graph-v1 Judgment Day and historical compatibility; no additional module deletion is justified.

The next delivery boundary is one branch-wide High-tier 4R, followed by the size-exception PR, merge readiness, and release.
Review outcomes are informational: commit, push, PR, and release delivery follow ordinary repository policy. Dangerous-command safety and destructive-review consent remain independent.

← [Back to README](../README.md)
Loading
Loading