Repository navigation
Expand file tree
/
Copy pathsystem.bla
More file actions
225 lines (187 loc) · 14.7 KB
/
Copy pathsystem.bla
File metadata and controls
225 lines (187 loc) · 14.7 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
system "cli" {
purpose "Parse arguments, choose a command, and render every human and JSON surface."
paths ["src/main.rs", "src/cli/mod.rs", "src/cli/project.rs", "src/cli/guide.rs", "src/cli/init.rs", "src/cli/heartbeat.rs", "src/cli/task.rs", "src/cli/recovery.rs", "src/cli/expert.rs"]
}
system "project" {
purpose "Compose a manifest's contracts into one project, fingerprint the implementation, and decide staleness and completion."
paths ["src/project/mod.rs", "src/project/status.rs", "src/project/runstate.rs", "src/project/task.rs", "src/project/task/revision.rs", "src/project/task/store.rs", "src/project/ignore.rs", "src/project/expert.rs"]
knowledge ["testing"]
}
system "skeptic" {
purpose "Form one grounded challenge to the current account of the work, from evidence the project already holds."
paths ["src/skeptic.rs"]
knowledge ["reviewing", "engineering"]
}
system "behavior-contract" {
purpose "Turn behavior contract text into a typed, normalized IR, and reject what cannot be typed."
paths ["src/syntax/mod.rs", "src/semantics/mod.rs", "src/ir/mod.rs"]
}
system "behavior-verify" {
purpose "Search for a counterexample to the typed IR under a finite campaign, and shrink what it finds."
paths ["src/verify/mod.rs", "src/verify/campaign.rs", "src/verify/coverage.rs", "src/verify/corpus.rs", "src/verify/evaluator.rs", "src/verify/generator.rs"]
knowledge ["testing"]
}
system "adapter" {
purpose "Drive the application under test across the trust boundary: process, protocol, isolation and containment."
paths ["src/application.rs", "src/runtime/mod.rs", "src/runtime/primitives.rs", "src/runtime/process_tree.rs", "src/runtime/strict_json.rs"]
}
system "memory" {
purpose "Parse authored Mission, Knowledge, System, Process and Goal memory, validate it within project memory, and answer identity queries about it."
paths ["src/memory/mod.rs", "src/memory/syntax.rs", "src/memory/system.rs", "src/memory/process.rs", "src/memory/mission.rs", "src/memory/knowledge.rs", "src/memory/routing.rs", "src/memory/goal.rs"]
knowledge ["engineering"]
}
system "structure-eval" {
purpose "Parse structure contracts and decide each rule against an already-inspected fact map."
paths ["src/structure/mod.rs", "src/structure/syntax.rs", "src/structure/falsify.rs"]
knowledge ["testing"]
}
system "structure-providers" {
purpose "Turn one source file of one language into ModuleFacts, without executing it."
paths ["src/structure/python.rs", "src/structure/python_facts.py", "src/structure/rust.rs", "src/structure/typescript.rs", "src/structure/go.rs", "src/structure/java.rs", "src/structure/cfamily.rs"]
}
system "structure-harness" {
purpose "Read, parse and classify one source file identically for every tree-sitter grammar, and hold the one accumulator a language walk fills."
paths ["src/structure/treesitter.rs"]
knowledge ["engineering"]
}
system "voice" {
purpose "Render a contradiction in the wording the owner selected, over evidence and verdicts it never changes."
paths ["src/voice.rs"]
knowledge ["design"]
}
system "report" {
purpose "Define the single result value that every rendering reads, and the diagnostic shape beside it."
paths ["src/report.rs", "src/diagnostic.rs"]
knowledge ["engineering"]
}
system "expert" {
purpose "Validate fixed provider answers, apply deterministic advisory policy, and retain bounded current-revision replay and delivery state without deciding project completion."
paths ["src/expert/mod.rs", "src/expert/packet.rs", "src/expert/provider.rs", "src/expert/policy.rs", "src/expert/trace.rs", "adapters/systemone/provider.py"]
knowledge ["engineering", "testing", "expert-review"]
}
responsibility "expert-context-selection" {
owner "project"
statement "Resolve registered judgments and Process bindings into bounded selected packets using actual task evidence and the shared relevant revision. No unrestricted transcript or unselected file enters the packet."
}
responsibility "expert-advisory-runtime" {
owner "expert"
statement "Validate typed answers and provider identity, map pure policy, replay saved responses and recheck current revisions before any reservation. Own bounded runtime settings, selected traces and delivery/suppression records under .blabla/expert/. Unknown delivery remains unresolved across restart; acknowledgment is not observed correction. Provider failure leaves deterministic verification available."
}
responsibility "expert-command-surfaces" {
owner "cli"
statement "Expose opt-in expert inspection, checkpoint evaluation, saved-response replay and trace operations without adding an expert call to ordinary project verification. Repository bindings remain shadow-only; no live host is certified."
}
seam "selected-expert-packet" {
between ["project", "expert"]
value "ExpertPacket"
statement "Only resolved identities, bounded selected observations and the shared task revision cross into a fixed judgment. Missing, unknown, unavailable or truncated required context cannot yield actionable advice. The same selected-revision comparison is used by current-result and actual reservation guards."
moves_with ["src/project/expert.rs", "src/project/task/revision.rs", "src/expert/packet.rs", "src/expert/policy.rs", "src/expert/trace.rs", "bridge/expert.rs", "contracts/expert.bla", "contracts/expert-seams.bla", "docs/project.md"]
}
seam "expert-proposal" {
between ["expert", "cli"]
value "ExpertResult"
statement "A validated answer becomes silence, abstention, a proposed nudge or escalation through deterministic policy. Rendering resolves only packet references. The proposal never changes verifier outcomes, exit codes or OVERALL. Local SystemOne transport exists; live checkpoint observation, same-task advisory insertion and tied receipts remain unverified."
moves_with ["src/expert/provider.rs", "src/expert/policy.rs", "src/expert/trace.rs", "src/cli/expert.rs", "adapters/systemone/provider.py", "docs/expert.md", "docs/design/0.10-host-capabilities.md"]
}
responsibility "inspect-source" {
owner "structure-providers"
statement "Read a declared source file and produce ModuleFacts from it. No other system reads project source for structural facts, and no system executes it."
}
responsibility "hold-project-memory" {
owner "memory"
statement "Parse, validate and answer queries about authored project memory: Mission, Knowledge, System, Process and Goals. Validation covers project memory against itself, including the knowledge packs System and Process route to, never against the repository, and no result of it reaches completion."
}
responsibility "decide-structure-rule" {
owner "structure-eval"
statement "Decide GREEN, RED or ERROR for one structure rule. The decision reads the inspected fact map and nothing else, which is also what lets the same decision be taken a second time against a counterfactual fact map when an author asks whether a rule can fail."
}
responsibility "execute-the-application" {
owner "adapter"
statement "Start, drive, restart and contain the process under test, and isolate each case's working directory."
}
responsibility "generate-behavior-cases" {
owner "behavior-verify"
statement "Choose action sequences, replay the bounded corpus, derive coverage obligations and shrink a failure."
}
responsibility "type-check-intent" {
owner "behavior-contract"
statement "Compile contract units against one project environment and produce the typed IR."
}
responsibility "decide-completion" {
owner "project"
statement "Combine the layer results into OVERALL, and map that to the exit code. No rendering surface decides it."
}
responsibility "decide-staleness" {
owner "project"
statement "Fingerprint the implementation tree and the project, profile and verifier identities, and say when a record is no longer current."
}
responsibility "hold-persistent-state" {
owner "project"
statement "Write and read project status, in-flight run markers and bounded task records under .blabla/. The expert subsystem separately owns .blabla/expert/. These records are machine state rather than authored memory: written by BlaBla, never registered by the manifest and never validated for truth. Task and expert state do not determine OVERALL."
}
responsibility "form-a-challenge" {
owner "skeptic"
statement "Choose at most one challenge to the current account of the work, from the bounded task record, the working tree measured against the snapshot that record holds, the completion state and a falsification verdict. A class with no evidence behind it produces no challenge and states why instead, because a challenge that is not grounded is the overstatement this project treats as worse than silence. It reaches no verdict about correctness and takes no part in completion."
}
responsibility "hold-the-result-value" {
owner "report"
statement "Define the one value a finished run produces, so that no two surfaces can disagree about it."
}
responsibility "render" {
owner "cli"
statement "Turn a result value into the human and JSON surfaces. Rendering computes nothing that the value does not already carry."
}
seam "provider" {
between ["structure-eval", "structure-providers"]
value "ModuleFacts"
statement "Every language fact enters rule evaluation as ModuleFacts and nothing else crosses. Inspection runs once per provider per verification, before any rule is decided; deciding a rule is then a function of that materialised map. This is why a provider adds a language and never a fact, and why rule semantics cannot drift between languages."
moves_with ["src/structure/mod.rs", "src/structure/falsify.rs", "src/structure/python.rs", "src/structure/python_facts.py", "src/structure/rust.rs", "src/structure/typescript.rs", "src/structure/go.rs", "src/structure/java.rs", "src/structure/cfamily.rs", "contracts/rust.bla", "contracts/providers.bla", "docs/structure.md", "docs/architecture.md"]
}
seam "parse-harness" {
between ["structure-harness", "structure-providers"]
value "Facts"
statement "Every tree-sitter language enters through one read-parse-classify preamble and fills one accumulator. A missing file leaves exists false with no error, an unreadable file sets error, and a file that does not parse sets error with its line: those three answers are decided once, for every grammar, because they are the difference between absent and unreadable and a language walk must not be able to reinvent it. A language module supplies its extensions, its grammar and its own node kinds, and nothing else."
moves_with ["src/structure/treesitter.rs", "src/structure/typescript.rs", "src/structure/go.rs", "src/structure/java.rs", "src/structure/cfamily.rs", "contracts/providers.bla", "docs/structure.md"]
}
seam "bounded-unknown" {
between ["structure-providers", "structure-eval"]
value "UnreadableImport.covers"
statement "A provider that cannot decide a dependency says so, and says how far the doubt reaches: the one declared module the unknown could be hiding, or nothing when it is genuinely unbounded. The evaluator turns that into ERROR for exactly the targets the unknown could cover and leaves every other dependency on the module decidable. Silence in place of an unknown is a false GREEN on a forbid; an unbounded unknown in place of a bounded one poisons unrelated facts. Both are defects and the contract holds the evaluator to both."
moves_with ["src/structure/mod.rs", "src/structure/treesitter.rs", "src/structure/go.rs", "src/structure/java.rs", "src/structure/cfamily.rs", "contracts/evaluator.bla", "bridge/structure_adapter.rs", "docs/structure.md"]
}
seam "rendered-contradiction" {
between ["voice", "cli"]
value "Voice"
statement "The voice is resolved once, from the manifest, and reaches rendering only. Adjudication never sees it: the standing set, the exit code and the machine-readable report are identical under every voice, and a blunt rendering is appended to the neutral statement rather than replacing it, so no wording choice can drop evidence or a hedge. Only a contradiction has a blunt rendering; an honest failure or a reported blocker has none."
moves_with ["src/voice.rs", "src/cli/task.rs", "src/cli/project.rs", "src/project/mod.rs", "contracts/voice.bla", "bridge/voice.rs", "docs/project.md"]
}
seam "application" {
between ["behavior-verify", "adapter"]
value "Application"
statement "Everything above this boundary works in observations, so the verifier never knows whether a real process is behind them. An adapter that cannot provide trusted process restart reports that rather than faking it. The application's observations are trusted and BlaBla cannot prove they describe the real application."
moves_with ["src/application.rs", "src/runtime/mod.rs", "src/runtime/primitives.rs", "docs/language.md", "docs/architecture.md"]
}
seam "typed-ir" {
between ["behavior-contract", "behavior-verify"]
value "Contract"
statement "The verifier consumes the typed IR and never the syntax AST. Coverage obligations, failures, shrinking and rule identities are all defined over it, so a change to the IR reaches coverage derivation even when it compiles."
moves_with ["src/ir/mod.rs", "src/semantics/mod.rs", "src/verify/coverage.rs", "src/verify/mod.rs"]
}
seam "bounded-task" {
between ["project", "skeptic"]
value "Task"
statement "Everything the skeptic knows about a bounded change crosses as the recorded Task: its write scope, its deliverables, the findings raised against it and the tree snapshot taken when it opened. The skeptic reads no chat, no agent report and no diff of its own, so a challenge can only ever rest on what an orchestrator wrote down at assignment and what the tree says now. A class of challenge that would need anything else cannot be added here without first adding it to the record."
moves_with ["src/project/task.rs", "src/skeptic.rs", "src/cli/task.rs", "process.bla", "docs/agent-workflow.md"]
}
seam "run-report" {
between ["report", "cli"]
value "RunReport"
statement "The human rendering and the --json rendering are two views of one value. Neither computes anything the other does not see, so a field added for one surface is added to the value, never to a renderer."
moves_with ["src/report.rs", "src/cli/project.rs", "src/cli/mod.rs"]
}
seam "runtime-primitives" {
between ["adapter", "cli"]
value "primitives table"
statement "Every agent-facing surface renders runtime primitive semantics from one table. No surface carries its own prose copy, and a rule's dependency on a primitive is derived from the typed IR rather than annotated in a contract."
moves_with ["src/runtime/primitives.rs", "src/project/status.rs", "src/cli/project.rs", "src/cli/guide.rs", "src/cli/init.rs", "docs/architecture.md"]
}