Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
117 commits
Select commit Hold shift + click to select a range
95e9d20
docs(field-report): preserve the fic2 Gate-B cycle evidence
dsnger Aug 27, 2026
81c77b3
docs(intake): add review-loop-economics-pass-floor story
dsnger Aug 28, 2026
1773b32
chore: ignore docs/ideas/ and docs/research/ repo-wide
dsnger Aug 28, 2026
808d83e
docs(story): add the floor-demonstration criterion and route the econ…
dsnger Aug 28, 2026
9968252
docs(story): one floor predicate, and require the per-pass curve in c…
dsnger Aug 28, 2026
95040b8
docs(spec): design the review-loop economics change
dsnger Aug 28, 2026
057a924
docs(spec): correct the old-conditions count to match its own enumera…
dsnger Aug 28, 2026
27562ba
docs(story): re-aim criterion 8 at the floor this branch actually lic…
dsnger Aug 28, 2026
dc774b0
docs(spec): revision 2 — all 24 Gate-A pass-1 Blocker/Major findings
dsnger Aug 28, 2026
c4af714
docs(story): encode the settled severity test and fix two scope contr…
dsnger Aug 28, 2026
60f6b8c
docs(spec): revision 3 — Gate-A pass-2 findings, and the accounting m…
dsnger Aug 28, 2026
df4a78d
docs(story): align desired outcome 2 with the settled severity test
dsnger Aug 28, 2026
0edafeb
docs(spec): revision 4 — delete the marker mechanism; deepen the acco…
dsnger Aug 28, 2026
8b6f667
docs(story): propagate the deleted floor-file mechanism into three cr…
dsnger Aug 28, 2026
0c1927f
docs(story): criteria state observables, not mechanisms
dsnger Aug 28, 2026
a332514
docs(spec): revision 5 — untangle the hold from the resolve duty; pas…
dsnger Aug 28, 2026
facb636
docs(spec): revision 6 — correct two false claims I made about the hook
dsnger Aug 28, 2026
ed9629f
docs(story): cover four spec obligations no criterion observed
dsnger Aug 28, 2026
78ebfd6
docs(story): de-mechanize the last two criteria; cover unanimity and …
dsnger Aug 28, 2026
b8bfe15
docs(spec): revision 7 — the qualification is the hold rule, stated i…
dsnger Aug 28, 2026
93712ba
docs(spec): revision 8 — split the condition inventory out; fix five …
dsnger Aug 28, 2026
787dd3d
docs(spec): revision 9 — pass-8 Blockers; the split's price, stated
dsnger Aug 28, 2026
e8e5cfa
docs(spec): revision 10 — slim to contract level; detail descends to …
dsnger Aug 29, 2026
c513094
docs: revision 11 — repair what the restructuring compressed away
dsnger Aug 29, 2026
32bf49d
docs(field-report): record the fourth announce-then-idle occurrence
dsnger Aug 29, 2026
52611e8
docs: revision 12 — a closure deadlock, and the nonce the formats cou…
dsnger Aug 29, 2026
b885bfc
docs(story): narrow to parts 1+2; split the loop-rule consolidation out
dsnger Aug 29, 2026
8899bc9
docs(spec): revision 13 — reduce to parts 1+2; part 3 follows its sto…
dsnger Aug 29, 2026
46072fe
docs: revision 14 — the split's accounting errors, and the P8 handoff…
dsnger Aug 29, 2026
8bc04d6
docs(spec): revision 15 — rules only, 604 -> 332 lines
dsnger Aug 29, 2026
770ce63
docs: revision 16 — pass 14's twelve Majors; ZERO Blockers for the fi…
dsnger Aug 29, 2026
6491e9d
docs: revision 17 — pass 15's nine Majors; second consecutive zero-Bl…
dsnger Aug 29, 2026
e364fbc
docs: revision 18 — pass 16's four findings
dsnger Aug 29, 2026
8640302
docs: revision 19 — pass 17's six findings; the pre-rule cycle field …
dsnger Aug 29, 2026
df84dfa
docs: revision 20 — the pre-rule exception made semantic, not just gr…
dsnger Aug 29, 2026
9bda168
docs: revision 21 — the curve now measures what it is kept for
dsnger Aug 29, 2026
87583f3
docs: revision 22 — the baseline cannot bear the demotion comparison,…
dsnger Aug 29, 2026
7db381c
docs: revision 23 — comparable mixes are not measured demotion, and a…
dsnger Aug 29, 2026
68cca70
docs: revision 24 — propagate the demotion correction to every site t…
dsnger Aug 29, 2026
89fb693
docs: revision 25 — the same correction, this time everywhere it lives
dsnger Aug 29, 2026
93d5d8f
docs: revision 26 — a misstated commit, and a raw value a commit cann…
dsnger Aug 29, 2026
db39bce
docs: revision 27 — a requirement that breaks CI, and a retracted inf…
dsnger Aug 29, 2026
754fe97
docs: revision 28 — item 1 answered n/a with reason; the last open qu…
dsnger Aug 29, 2026
96b5ea2
docs: revision 29 — scope the n/a, and two grammar ambiguities
dsnger Aug 29, 2026
17d4037
docs: revision 30 — the floor replaces a number, not the rules around it
dsnger Aug 29, 2026
78dd825
docs: revision 31 — a checkpoint that names itself, and a scope I con…
dsnger Aug 29, 2026
e56fd28
docs: revision 32 — the skip is not a cycle owing a gate, and "any" b…
dsnger Aug 29, 2026
d5ee48c
docs: revision 33 — stop restating §5's skip rule
dsnger Aug 29, 2026
ef2125f
docs: revision 34 — remove the last two exit summaries
dsnger Aug 29, 2026
cb23ee7
docs: revision 35 — zero and unknown are different facts
dsnger Aug 29, 2026
6f6bc8e
docs: revision 36 — unknown is per series, and so is its exclusion
dsnger Aug 29, 2026
59cb7f0
docs(field-report): preserve the Gate-A rle cycle record before slot …
dsnger Aug 29, 2026
1470094
docs(plan): implementation plan for the review-loop economics change
dsnger Aug 29, 2026
5c00f8c
docs(plan): rewrite the review-loop-economics plan against revision 36
dsnger Aug 29, 2026
3b94dbf
docs(plan): Plan A — the rules edits, split from the single-plan attempt
dsnger Aug 29, 2026
cba0886
docs(todos): record the --no-edit Gate-B cycle reset as a hook defect
dsnger Aug 29, 2026
83b17e0
docs(plan): Plan A revision 2 — repair the fifteen in-set findings
dsnger Aug 29, 2026
3799ac9
docs(plan): Plan A revision 3 — every check executed, not predicted
dsnger Aug 30, 2026
e4509ad
docs(plan): Plan A revision 4 — strip the instrument
dsnger Aug 30, 2026
895a94d
docs(plan): Plan A revision 5 — fix the three rules findings
dsnger Aug 30, 2026
26e7885
docs(plan): Plan A revision 6 — repair three of four; one contract qu…
dsnger Aug 30, 2026
b3258d1
docs(plan): Plan A revision 7 — encode the between-cycle rule as curr…
dsnger Aug 30, 2026
1f1aa6f
docs(plan): Plan A revision 8 — give the cited set an authority and a…
dsnger Aug 30, 2026
385d6a2
docs(plan): Plan A revision 9 — bidirectional adoption rule; one Majo…
dsnger Aug 30, 2026
bdb9360
docs(plan): Plan A revision 10 — the Story header is the governing ci…
dsnger Aug 30, 2026
3b95e10
docs(plan): Plan A revision 11 — withdraw an out-of-scope change to t…
dsnger Aug 30, 2026
fbc63f1
docs(plan): Plan A revision 12 — Task 12 ships spec §3 and nothing else
dsnger Aug 30, 2026
7208756
docs(plan): Plan A revision 13 — the deferral must not ship a repo-lo…
dsnger Aug 30, 2026
89056e6
docs(plan): Plan A revision 14 — strip the declaration layer; fix all…
dsnger Aug 30, 2026
75a9a5b
docs(plan): Plan B — the records, written in the shape Plan A converg…
dsnger Aug 30, 2026
c05a86e
docs(plan): Plan B revision 2 — the grammars are the spec's block, no…
dsnger Aug 30, 2026
6f84ebc
docs(plan): Plan B revision 3 — close the preflight state space; drop…
dsnger Aug 30, 2026
8272674
docs(plan): Plan B revision 4 — collision-resistant, not collision-proof
dsnger Aug 30, 2026
c01ff6f
docs(plan): Plan B revision 5 — six absorbed; the cycle-cardinality q…
dsnger Aug 30, 2026
cf9e304
docs(plan): Plan B revision 6 — record the confirmed cycle-cardinalit…
dsnger Aug 30, 2026
bd5ca5b
docs(plan): Plan B revision 7 — the slot refusal gets an observable p…
dsnger Aug 30, 2026
f132c57
docs(plan): Plan B revision 8 — bind the slot rule to the deletion step
dsnger Aug 30, 2026
51840fd
docs(plan): Plan C — rollout, packaging, evidence, and the close
dsnger Aug 30, 2026
b280099
docs(plan): Plan C revision 2 — fifteen fixed, one contract question …
dsnger Aug 30, 2026
5b12030
docs(plan): Plan C revision 3 — strip the theater, settle the records…
dsnger Aug 30, 2026
83a61b6
docs(plan): Plan C revision 4 — the strip took two real things with it
dsnger Aug 30, 2026
bc40a11
docs(plan): Plan C revision 5 — the plan stops restating §5
dsnger Aug 30, 2026
5f1eddd
docs(field-report): the three Gate-A plan cycles for rle
dsnger Aug 30, 2026
ab8a8fe
docs(plan): Plan C revision 6 — reconstruction leaves the commit body
dsnger Aug 30, 2026
2badb57
docs(vision): dark-factory target vision and decomposition
dsnger Aug 30, 2026
bcd45dc
docs(plan): Plan C revision 7 — the claim sweep
dsnger Aug 30, 2026
4cec17c
docs(vision): parallelism and flow control decisions
dsnger Aug 30, 2026
b110a3a
docs(vision): prior-art review of godarkfactory, adoptions and non-ad…
dsnger Aug 30, 2026
bb358c2
docs(plan): Plan C1 — the user-facing floor description
dsnger Aug 30, 2026
6dad454
docs(vision): intake loop, Freigabe, and naming
dsnger Aug 30, 2026
476236b
docs(plan): Plan C1 revision 2 — eight sites, whole-line asserts, bot…
dsnger Aug 30, 2026
7e42947
docs(plan): Plan C1 revision 3 — every replacement line-complete, the…
dsnger Aug 30, 2026
52192d1
docs(plan): Plan C1 revision 4 — stops first, guards stop overclaiming
dsnger Aug 30, 2026
4e82957
docs(vision): Freigabe ladder on a rendered wave plan, plan-as-view, …
dsnger Aug 30, 2026
096dfa9
docs(vision): rename Intake-Loop to Klassifizierungs-Loop
dsnger Aug 30, 2026
0c0e476
Revert "docs(vision): rename Intake-Loop to Klassifizierungs-Loop"
dsnger Aug 30, 2026
2afe1d1
docs(vision): decision 8 — four-eyes principle with a scaling guard
dsnger Aug 30, 2026
56657bc
docs(vision): reviewers judge artifacts, the judge watches process
dsnger Aug 30, 2026
391ea0f
docs(vision): park three §11 topics for the 2026-08-31 session
dsnger Aug 30, 2026
6e37fda
docs(vision): three test layers and the merge-queue station
dsnger Aug 31, 2026
0b48976
docs(vision): dark-factory map as an Excalidraw file
dsnger Aug 31, 2026
23d8889
docs(vision): decision 9 (AC read-only in a lane), second prior-art s…
dsnger Aug 31, 2026
8aedc0b
docs(vision): Gate A pass 1 — bound the merge-queue claim, correct tw…
dsnger Aug 31, 2026
2121b25
docs(vision): Gate A pass 1 round 2 — close both blockers, split the …
dsnger Aug 31, 2026
d479e83
docs(vision): Gate A pass 2 — reviewer availability gates automatic m…
dsnger Aug 31, 2026
263be71
docs(vision): Gate A pass 3 — an outage makes work wait, fix permissi…
dsnger Aug 31, 2026
6f67645
docs(vision): Gate A pass 4 — fix where the outage rule applies, corr…
dsnger Aug 31, 2026
97bf0f4
docs(vision): Gate A closed — dark-factory decomposition, five passes
dsnger Aug 31, 2026
b9254f2
docs(vision): dashboard package and role-separation rules (Daniel, 20…
dsnger Aug 31, 2026
8bdb7cf
docs(vision): shortcuts and hooks (Daniel, 2026-08-31)
dsnger Aug 31, 2026
92b072a
docs(vision): map rebuilt as a road, synced to the gated doc
dsnger Aug 31, 2026
7e29cb4
docs(vision): map redrawn with the excalidraw-diagram skill
dsnger Aug 31, 2026
ab8ac98
docs(field-report): Plan C's closing figures and Plan C1's stopped curve
dsnger Sep 1, 2026
b3bcb18
feat(workflow): derive the pass floor from the cited story's profile
dsnger Sep 1, 2026
4760f4a
docs(field-report): the Gate-B cycle, and the failure shape that clos…
dsnger Sep 2, 2026
f387ac8
fix(review): six findings from PR #26's bot round
dsnger Sep 2, 2026
1b07c7b
docs(field-report): the seven decisions behind these cycles
dsnger Sep 2, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,3 +12,10 @@ _unrelated-seo-work/
# passCount hands every fresh clone a pre-counted Gate-B pass.
.context/*
!.context/codex-gate.on

# Local drafts and reading notes — working material, not repo content. `docs/field-reports/`
# is deliberately NOT here: field reports are tracked, because a field-intake round cites
# them as its evidence. These two replace a per-clone `.git/info/exclude`, so the policy
# travels with the repo instead of living in one checkout.
docs/ideas/
docs/research/
502 changes: 479 additions & 23 deletions CLAUDE.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -127,7 +127,7 @@ plugin is installed once per machine; every other repo you open hears nothing fr

Per-workspace knobs, all files under `.context/`:

| `codex-gate.floor` | a positive integer; moves the 3-passes-per-gate floor. |
| `codex-gate.floor` | a positive integer; moves the hook's reminder threshold. It does not change the floor §5 obliges, which is derived from the cited story's profile. |
| `codex-gate.off` | silences the reminders; classification and state tracking keep running, so re-enabling lands on counters carrying the same semantics as gate-on — which is not the same as evidence that a review happened. |
| `codex-gate.tools` | `execTool=<name>` and/or `reviewTool=<name>` — counts a Codex server whose tools aren't named `exec`/`review`, and only worth it if that server really does separate text-review from diff-review; aiming both gates at one general-purpose tool moves the counters while neither gate means what it says. Each mapped name must itself lie in `mcp__codex__*`: the hook's `hooks.json` matcher is `^(Bash\|Skill\|mcp__codex__.*)$`, so an out-of-namespace name is either never delivered (the mapping looks applied and does nothing) or, for the reserved names `Bash`/`Skill`, hijacks a lifecycle event; the hook refuses both — register the server as `codex` to place its tools there. Unparseable, out-of-namespace and reserved (`Bash`/`Skill`) lines are ignored, and the gate keeps its default `exec`/`review` name. A typo **inside** the namespace — `mcp__codex__exce` — is still honoured: the hook does not check that a mapped tool exists, so the gate now counts that name and nothing else. Whether it ever counts depends on whether a tool by that name is actually invoked; for a typo, normally never. |

Expand Down
15 changes: 9 additions & 6 deletions docs/coding-workflow.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,8 +76,9 @@ story that captures *what* and defers *how*: the problem, the desired outcome, t
acceptance criteria, which core invariants the change touches, the open questions,
a rough size, and a **profile** — risk and security relevance, confirmed by the human,
with a validation mode derived from the two. The two axes **add** review lenses at the
gates for a risky or security-relevant change (they never subtract any: Gate A's floor and
the baseline questions are the same at every level), while the derived mode calibrates
gates for a risky or security-relevant change (they never subtract a baseline question; the
floor itself derives from the profile, so it is not the same at every level), while the derived
mode calibrates
what evidence the author owes before Gate B. The design ("how") is deliberately left out —
it belongs to the next stage. The value here is a shared, reviewable definition of done before
anyone argues about approach.
Expand Down Expand Up @@ -127,8 +128,9 @@ prior review. Trivial changes may skip it, on terms that depend on the story: an
unprofiled one keeps the judgement call, while a profiled one qualifies only at
effective level 0 — trivial risk *and* no security relevance — so a trivial-looking
change on security-relevant surface is not eligible. A skip removes the review, never
the evidence: the battery still runs, the reason is recorded in the commit body, and
so is one evidence entry per cited profiled story. **Explanatory**
the evidence: the battery still runs, and the commit body carries the reason, the battery
result, the cycle's provenance line, a skip record in place of the curve, and one evidence
entry per cited profiled story. **Explanatory**
documentation carries no gate at all — a wrong sentence there costs a confused reader
rather than broken behaviour. Prompt artifacts are not explanatory prose: in a project
whose product is prompts, the text *is* the behaviour, so the review policy requires Gate
Expand Down Expand Up @@ -276,8 +278,9 @@ top-level field alone is the wrong answer precisely where the override documente
use, since `CODEX_DEV_REVIEW_MODEL` is stored at `tools.review.model`. If neither level names a
model the probe establishes nothing — the CLI then picks its own default, and the only honest
record is to set an explicit model or record the model as undetermined. Record the result beside
the finding count in the pass record: the commit body's evidence entry, or the slot's
dispositions file. This is
the finding count in **the cycle's per-pass curve**, which pins a field for it — not the
evidence entry and not the dispositions file, neither of which is keyed to a pass. The health
probe above is how the value is established; the curve is where it goes. This is
bookkeeping, not enforcement: nothing checks it, and a wrong entry looks exactly like a right
one.

Expand Down
66 changes: 66 additions & 0 deletions docs/field-reports/2026-08-16-canvas-a1-a5-dispositions.md
Original file line number Diff line number Diff line change
Expand Up @@ -310,3 +310,69 @@ established neither whether the hash was computable at any given pass nor whethe
failed to persist, and it did not read the hook at the site that computes it. Its one new lead — that the second
shape's STOP arrived at a `git reset --soft`, which reaches the reset path only via `is_commit` —
ties it to the item-2 row and is a lead, not a finding.

---

## Field note added 2026-08-28 — criteria that restate the design are a Blocker generator

Observed across Gate-A passes 1–4 of the review-loop-economics cycle
(`docs/superpowers/specs/2026-08-28-review-loop-economics-design.md`): **five Blocker-severity
occurrences of one defect**, where the spec was revised and the story's acceptance criteria
still described the superseded mechanism — criterion 8 demanding a floor a risk-`high` story
cannot license; criterion 5 describing artifact-kind severity after a consequence-keyed test was
settled; desired outcome 2 keeping a false-green-only carve-out; criterion 3 reversing the
settled meanings of derived floor and hook knob; and criterion 4 requiring both shipped copies to
describe a mechanism the design had deleted — where implementing the criterion would have
recreated the rejected design in order to satisfy a criterion about it.

The cause is structural rather than carelessness: those criteria embedded **mechanism detail**,
so each had to track a design still in motion. A criterion that restates the design is a second
copy of it, and this repo's ledger already records what a second copy does — "a restatement is a
second copy that can drift".

Remedy applied in that cycle: the criteria were rewritten to state **what must be observably
true** rather than **how**, with the bound that a criterion which cannot be made observable
without naming mechanism is one where the mechanism *is* the contract, and there it stays named.

**Captured, not acted on beyond that cycle.** This is field evidence for whoever next touches
`dev-workflow:intake`, whose story template says acceptance criteria "describe observable
outcomes or constraints, never implementation steps" — the rule exists; what this record adds is
five measured occurrences of the failure it is meant to prevent, and the observation that the
drift shows up as *Blockers in a later gate* rather than as a bad-looking criterion at intake
time.

**Also observed, 2026-08-28, same cycle:** three occurrences of an agent ending a turn on an
announcement — "writing the spec now", "running pass 6" — with the named tool call never issued.
A fourth followed on 2026-08-29 ("running pass 10"), spotted by Daniel watching the terminal. Each cost a round-trip and one cost ~90 minutes of wall clock before a peer session noticed. No
error, no timeout, nothing in flight: the announcement simply replaced the act. Remedy adopted for
the remainder of that cycle: during an active gate cycle a turn ends with the tool call actually
issued, a message sent, or an explicit statement that something is blocking — and noticing the
turn ending with the call not in flight *is* that statement.

**Prediction recorded 2026-08-28, before the pass that tests it.** Gate-A pass 7 of the
review-loop-economics cycle found that the spec's own nineteen-row condition-inventory table (§6.2)
had become the loop's largest finding source: **7 of 29 Blocker/Major, including 4 of 9 Blockers**,
every one a row contradicting the design it existed to account for. The table was split out —
method and passage list stay in the spec, the row-by-row dispositions move to an artifact produced
once against frozen text and gated before implementation.

Verbatim prediction, so it can be scored rather than remembered: **pass 8 should lose roughly 7 of
29 Blocker/Major and 4 of 9 Blockers to the §6.2 removal. If pass 8 does not fall materially, the
generator is elsewhere and the whole-artifact split becomes the live candidate.**

Worth keeping either way: this is the third site of one defect class in a single cycle — a
restatement that must track a moving original. It appeared in the story's acceptance criteria
(five Blocker occurrences), then inside the spec's own accounting table (four more). The lesson is
not "write the table more carefully"; it is that a second copy of a moving thing drifts, and the
remedy is to produce it once against something that has stopped moving.


**The loop's first wrong finding, 2026-08-29.** Gate-A pass 13 of the review-loop-economics cycle
returned a BLOCKER claiming a spec sentence was "syntactically incomplete at *every and the curve
duty treated as owed*". `grep 'every and'` on the reviewed file returns nothing — the break existed
in revision 13 and revision 14 had replaced the sentence. **Dismissed with that evidence.**

Worth recording because it is the **first outright wrong finding in thirteen passes** of that
loop — roughly 380 findings. That ratio is the argument for validating before applying rather than
against it: the discipline cost thirteen passes' worth of checking and caught one, and the one it
caught would otherwise have driven an edit to text that was already correct.
Loading