design: SPEC/PLAN authority architecture and executable design gate #379
Closed
nsaspy
wants to merge 28 commits from
docs/spec-seeded-symbolic-plans into main
pull from: docs/spec-seeded-symbolic-plans
merge into: nsaspy:main
nsaspy:main
nsaspy:feat/prolog-rlm-language
nsaspy:codex/claude-api-provider
nsaspy:codex/symbolic-experts
nsaspy:codex/openai-api-provider
nsaspy:feat/zai-provider-protocols
nsaspy:hardening/project-semantic-20260911
nsaspy:hardening/ws7-nix-ci-pinning
nsaspy:chore/track-prolog
nsaspy:rage/98-semantic-project-knowledge
nsaspy:fix/339-agent-zero-skill-graph
nsaspy:ci/tree-sitter-runner-labels
nsaspy:issue-293
nsaspy:research/text-streaming
nsaspy:docs/agent-editor-handoff
nsaspy:icon-add
nsaspy:hydra/fleet-jobs-20260904
nsaspy:rage/355-d6-11-plan-native-dispatch
nsaspy:cd/nix-installer-action-url
nsaspy:issue-355
nsaspy:rage/97-query-capture-apis
nsaspy:research/expert-direct-tool-projection
nsaspy:rage/96-versioned-syntax-facts
nsaspy:fix/direct-deadline-typing
nsaspy:dogfood/auto-dig-native-tools
nsaspy:feature/rage-feature-freeze
nsaspy:fix/323-native-batch-cardinality
nsaspy:fix/328-direct-user-namespace-text-string
nsaspy:fix/transient-provider-retry-2026-09-01
nsaspy:fix/openrouter-dotted-tool-result-name
nsaspy:rage/325-native-call-isolation
nsaspy:fix/316-original-batch-effect-isolation
nsaspy:fix/313-per-call-preflight
nsaspy:fix/312-peek-schema-contract
nsaspy:docs/agents-worktree-rule
nsaspy:fix/child-native-capability-narrowing
nsaspy:test/paid-lane-glm-53-flash
nsaspy:rage/290-spec-plan-authority
nsaspy:fix/304-context-peek-selector-contract
nsaspy:fix/298-native-any-json-schema
nsaspy:rage/288-spec-plan-graph-executor
nsaspy:feat/spec-plan-flow-api
nsaspy:prolog-rlm-v1
nsaspy:gpt-5-6-sol-high/questions-for-rlm-prolog-and-lambda-rlm
nsaspy:rage/277-planner-protocol-context
nsaspy:research-approval/rlm-research-026-task-deadlines-20260827135838
nsaspy:research-approval/rlm-research-025-lem-ui-20260827135751
nsaspy:rage/183-live-operator-behavior
nsaspy:agent/127-agentprolog-config
nsaspy:recovery/132-agentprolog-monorepo
nsaspy:rage/223-durable-context-mount-recovery
nsaspy:rage/223-constraint-benchmark-recovery
nsaspy:research-approval/rlm-research-011-managed-context-tool-discovery-20260827054019
nsaspy:feat/research-approval-schema
nsaspy:agent/rrlm-control-plane-research
nsaspy:docs/219-adrrd-review
nsaspy:salvage/231-runtime-status
nsaspy:salvage/231-runtime-status-run
nsaspy:tmp
nsaspy:tmp2
nsaspy:tmp3
nsaspy:rage/245-planner-structural-retry
nsaspy:rage/168-skill-selection-eval
nsaspy:rage/250-skill-catalog-graph
nsaspy:rage/56-result-acceptance
nsaspy:rage/172-parent-resume-replan
nsaspy:rage/175-deadline-policy-recovery
nsaspy:rage/257-provider-tool-choice-normalization
nsaspy:agent/tool-result-projection-presets
nsaspy:fix/234-numeric-schema-bounds
nsaspy:feature/231-rlm-cli-reference-harness
nsaspy:feature/223-durable-context-mounts
nsaspy:feature/223-real-constraint-benchmark
nsaspy:feature/223-real-constraint-benchmark-clean
nsaspy:feature/223-real-constraint-benchmark-final
nsaspy:feature/223-real-constraint-benchmark-impl
nsaspy:feature/223-real-constraint-benchmark-now
nsaspy:feature/223-real-constraint-benchmark-tdd
nsaspy:feature/223-real-constraint-benchmark-work
nsaspy:rage/176-root-planner-tool-projection
nsaspy:rage/172-typed-delegation-policy
nsaspy:rage/175-subagent-deadline-policy
nsaspy:rage/206-prompt-command-runtime
nsaspy:rage/203-subagent-skill-role-provenance
nsaspy:rage/200-permanent-rlm-context
nsaspy:fix/190-cli-help-success
nsaspy:archive/pr-132-agentprolog-config-20260827
nsaspy:feature/117-prolog-skill-activation-linear
nsaspy:feature/117-prolog-skill-activation
nsaspy:fix/194-completion-budget-usage
nsaspy:fix/191-capability-filtered-tool-schemas
nsaspy:fix/185-reasoning-effort
nsaspy:ci/report-workflow-failures-20260825
nsaspy:cleanup/186-remove-legacy-harnesses
nsaspy:fix/185-reasoning-routing
nsaspy:agent/evolution-async-evaluator
nsaspy:rage/181-binding-replay-race
nsaspy:agent/124-deepseek-harness-prolog
nsaspy:rage/144-fallback-closure
nsaspy:rage/164-conversation-metadata
nsaspy:agent/subagent-supervised-call-conformance
nsaspy:fix/160-context-adapter-closed-data
nsaspy:codex/move-agent-zero-adaptor
nsaspy:codex/sol-high-integration
nsaspy:fix/151-plunit-gate
nsaspy:fix/165-evolution-closed-data
nsaspy:fix/162-async-control-exceptions
nsaspy:fix/158-prompt-compiler-closed-dicts
nsaspy:fix/151-plunit-main-ownership
nsaspy:fix/156-registry-destroy-hooks
nsaspy:fix/154-anonymous-dict-canonicalization
nsaspy:fix/flake-lock-reproducibility
nsaspy:agent/issue-142-evolution-kernel
nsaspy:agent/141-flake-runtime-package
nsaspy:agent/rlm-subagent-runtime
nsaspy:agent/144-subagent-fallback-a
nsaspy:agent/107-bound-adapter-metadata
nsaspy:validation/clean-pack-install
nsaspy:fix/45-authoritative-nested-model-events
nsaspy:fix/46-router-safe-live-streaming
nsaspy:agent/prompt-context-compiler
nsaspy:agent/42-canonical-recursive-fingerprints
nsaspy:agent/136-static-load-errors-fail-ci
nsaspy:agent/44-completion-error-usage
nsaspy:fix/67-loader-registry-cleanup
nsaspy:agent/opentui-solid-reference-client-current
nsaspy:agent/95-project-source-registry
nsaspy:feature/issue-117-prolog-skill-compiler
nsaspy:backlog/roadmap-86-merged
nsaspy:agent/opentui-solid-reference-client
nsaspy:79-tool-effect-boundary
nsaspy:agent/prolog-agent-ui-research
nsaspy:agent/conversation-cold-context
nsaspy:agent/94-tree-sitter-ffi
nsaspy:agent/conversation-warm-context
nsaspy:111-opentui-solid-reference-client
nsaspy:109-prolog-agent-ui-v1
nsaspy:agent/conversation-runtime
nsaspy:agent/spec-mode-language
nsaspy:agent/spec-verify-foundation
nsaspy:agent/prompt-compiler-research
nsaspy:reconcile-backlog-postmerge
nsaspy:reconcile-backlog-issues
nsaspy:agent/prolog-agent-roadmap
nsaspy:feature/issue-84-effect-store-migration
nsaspy:fix/issue-80-effect-substrate-adversarial-hardening
nsaspy:feature/issue-57-effect-identity
nsaspy:agent/mcp-declaration-security
nsaspy:agent/external-tool-category-boundary
nsaspy:feature/issue-53-authority-pending-async
nsaspy:feature/issue-54-agent-graph-canonical-async
nsaspy:feature/issue-54-tools-mcp-canonical-async
nsaspy:feature/issue-54-async-canonical-runtime
nsaspy:agent/dual-sync-async-runtime
nsaspy:agent/reconcile-todo-status
nsaspy:feature/issue-20-deep-recursion-experiments
nsaspy:feature/issue-19-cli-demo-trace
nsaspy:feature/issue-18-benchmark-conformance
nsaspy:feature/issue-17-adaptive-recursion
nsaspy:feature/issue-16-durable-artifacts
nsaspy:feature/issue-15-mcp-2026-dual-version
nsaspy:feature/issue-14-mcp-2025-11-25
nsaspy:hotfix/live-tool-native-openrouter
nsaspy:feature/issue-13-chain-runtime
nsaspy:fix/stable-live-repair-gate
nsaspy:fix/live-repair-strategy-parser
nsaspy:feature/issue-12-durable-graph
nsaspy:feature/issue-11-agent-supervision
nsaspy:feature/issue-10-structured-outcomes-repair
nsaspy:feature/issue-9-rlm-completion
nsaspy:feature/issue-8-capability-tools
nsaspy:feature/issue-7-typed-plan-runtime
nsaspy:feature/issue-6-context-store
nsaspy:fix/openrouter-reasoning-response
nsaspy:fix/live-openrouter-smoke-stability
nsaspy:feature/issue-5-openrouter-provider
nsaspy:feature/issue-4-swi-bootstrap
nsaspy:agent/agentic-harness-research
nsaspy:agent/prolog-rlm-foundation
No reviewers
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/prolog-rlm!379
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/spec-seeded-symbolic-plans"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Replaces the failed PR #290 design with a rewritten, executable design record
for the SPEC / VALIDATE / PLAN authority architecture, plus the design gate
that validates it through real merged code. This is no longer a docs-only PR:
it changes CI, an executable gate script, research KB state, deterministic
corpus, and two live tests.
docs/research/spec-plan-authority.md— full design record: canonical SPEClanguage (merged
rlm_spec_langgrammar unchanged), BASE adoption ofrage/288-spec-plan-graph-executorwith explicitly declared D6 deltas(D6-1..D6-10), expert contracts and inner capabilities, TDD RED/GREEN
evidence contract, HTTP/network assertion model, PLAN→SPEC compatibility and
replan safety, durability (forward projection, never compaction), S0–S11
implementation DAG.
scripts/design_gate.pl— executable design gate (deterministic; no modelor network calls) validating the normative design through real merged
parsers, the adopted BASE module, and gate-local normative checkers:
59 checks in 13 groups, all green.
research/spec-plan-refinement-kb.pl+-state.pl— hardened research KBwith machine-checked evidence refs (
kb_evidence_refs_resolve)..github/workflows/ci.yml— design-gate step with non-fatal BASE fetch;the BASE object is pinned by commit id
(
71a10ae…,rage/288-spec-plan-graph-executornow pushed to this remote).test/deterministic_corpus.pl— manifest entries for two tests added onmain without corpus entries (main's own unit lane was red for this;
b654831/eb2411a).test/live_conversation_scale_openrouter_test.pl,test/live_completion_openrouter_test.pl— assertions corrected to pin theruntime retrieval contract rather than one model-authored plan shape; child
session token headroom + reasoning-effort pinned. No test was skipped,
xfailed, or weakened into accepting a wrong answer.
Runtime invariant implemented (design level): model output is inert data —
SPEC compilation grants nothing (closed metadata schema, no capability field),
planning cannot widen authority, plans seed only from a fingerprint-verified
frozen spec, dropped obligations are unrecoverable, and patches re-run the
full validation chain against the same frozen ref.
Non-goals
KB, or
plan_validate_against_spec/4(slices S0–S11 in §13).rlm_direct/rlm_spec_strategysubstrates (S10).Evidence
--no-localGitHub clones of the PR head (thin-clone BASE-missing casehalts 1 with the candidate list; after the CI fetch step the pinned id
resolves).
check_runtime,load_all, PlUnit gate-report mode1066/1066 in 92 suites,
benchmark/run.pl -- deterministic16/16,CLI demo/trace smoke.
OPENROUTER_TEST_MODEL=z-ai/glm-5.3-flash: 11/11.This does not prove the required CI lane (which pins
openai/gpt-oss-120bvia the repo variable).Known separate issue (pre-existing on main, not introduced here)
live_planner_context_openrouter_testfails with the pinnedopenai/gpt-oss-120b. Characterized across consecutive runs: the failuresmove between stages (one-hop
tool_result_envelope_fieldreferences;ungranted
parallelop; malformed step) — stochastic plan-authoringfragility under this harness rather than one deterministic defect. This
predates the PR: main's own paid lane fails identically (run 33254062233 at
b654831), and this branch's lane failed the same way before this slice(runs at
5bb2817,7c9e007).14b6ec7improves the runtime's planner repair loop for every model (withdeterministic test coverage):
tool_result_envelope_fieldretries now teachthe corrected two-hop envelope form,
capability_deniedretries name thedenied capability plus the granted list, and the rlm-operate skill body
states the one-hop rejection rule up front. This does not make the 120b lane
green and is not claimed to. A dedicated follow-up slice should own it with
120B-specific live evidence; the
z-ai/glm-5.3-flash11/11 run is notoffered as evidence for that lane.
Follow-up scope after merge
evidence on that model.
§8.1 gains the required inner_capabilities:[capability] field D6-8 and §8.2 already reference: expert inner-loop grants (e.g. model(P)), distinct from the op's own required capabilities, validated against environment grants at preflight. expert_contract_ok/2 now shape-checks model_policy{provider:atom, max_iterations:>0} instead of accepting any dict, closes budget_policy to shared_step_budget, closes completion to applied_and_observed and failure to blocked|failed, requires non-empty effects, and validates every capability element against the merged rlm_tool capability model. New expert_contract_shape check (red-first under the lax checker): missing inner_capabilities, inner widening, bad model_policy, unknown budget/completion/failure atoms are all rejected; widening check now covers inner capabilities too. Doc §8.1 updated.path_template_name/2 now succeeds when {Name} occurs anywhere in the path (embedded "/users/{id}" or whole "/{id}"), with a non-empty alphanumeric name; a declared path_param without a matching template still fails. New http_path_param_ok check (red-first under the whole-template-only matcher) compiles a positive GET /users/{id} endpoint contract with path_params {id:integer} and a derivable missing_resource 404 scenario.Refinement pushed (
88bca2e)Branch reconciled against current
main(a89175b, PR #286 runtime consolidation merged in; PR content preserved). The refined design is now defined indocs/research/spec-plan-authority.md— a design-only pass, no runtime changes.Primary correction implemented in the design: the flow now runs INTENT → SPEC → VALIDATE SPEC (first-class hard gate) → Frozen Spec → PLAN COMPILER → plan KB → expert loop → observe → spec verification → replan/continue → FINAL. Gate invariants G1–G5: seeding accepts only a fingerprint-checked
frozen_spec{}; invalid specs yield structuredspec_fault/1diagnostics and spec-source repair (never a plan); model text is inert until validated; spec repair and verification-time repair stay distinct; FINAL requiresverification_report{status:passed}. Direct mode remains first-class (direct/symbolic/recursive_symbolic, host-selected, caller-pinnable).Key reconciliations with merged reality (the PR's original sketch predated #286):
rlm_spec_lang's closed symbols already cover most seed constructs; the delta is minimal —input/2,artifact/2,3,forbidden/1,ordering/2,conflicts/2, spec-levelevidence_policy/1.goal/validate/success/constraintmap onto existingsubject/require+assertion/output_contract/invariantrather than duplicating names.validateSpec/3extends the existingspec_validate/3to be environment-aware with a diagnostics vocabulary (missing capability, contradictions, impossible requirements, dangling references, missing inputs, invalid output contracts, incompatible constraints, forbidden-effect conflicts, ordering cycles, no validation mechanism).rlm_planclosed AST stays the execution IR; the 12-op project vocabulary (rage/288 slice) desugars onto it; newplan_validate_against_spec+ typedplan_patchkeep model proposals candidate-only.recursive_symbolicis not a new runtime — it is symbolic mode over the existingrlm_recursion_policyroutes; λ-RLM split/map/filter/reduce/thresholds/termination map onto existing context ops, plan combinators, policy guards, and one new closedfilterreducer.symbolRef/sourceSpan/revision grammar with the write engine routed through the durable effect boundary (#79); tree-sitter stays internal to the index layer (#96–#99).Managed by Prolog:
research/spec-plan-refinement-kb.pl(+ persisted state) drove this refinement — 23 tasks, dependency graph, decisions, evidence; alldone.scripts/spec_plan_authority_check.{pl,sh}is a deterministic design gate (schema shapes, example spec/plan, diagnostics vocabulary, slice graph, KB state): ALL CHECKS PASSED.Evidence at this head: full deterministic suite 1061/1061 (90 suites), benchmark deterministic 16/16, check_runtime/load_all/CLI demo/
make research-approval/git diff --checkgreen.Non-goals honored: no runtime/API changes in this PR; implementation is deferred to slices S1–S10 (dependency graph in §23 of the design record). The roadmap now points at the refinement record as the TaskIR/Phase-2/3 design input.
Pull request closed