[EPIC] Portable semantic intents, multi-turn slot dialogue, and capability/service routing #150
Open
opened 2026-08-22 21:49:52 +00:00 by lost-rob0t
·
2 comments
No Branch/Tag specified
master
agent/pi-coder-plugin-2026-09-17
fix/android-remote-listener
ui/chat-message-bubbles
release/v0.1.1-alpha-20260908
fix/default-daemon-endpoint-20260908
ui/650-outrun-shell
fix/400-plugin-capability-composition
fix/tts-idle-cpu-spin
design/android-canonical-reference-2026-09-07
fixtures/voice-recordings
rage/core/388-tool-cancellation-r18
rage/core/388-tool-cancellation-r1
release/v0.1.0-alpha
rage/android/175-terminal-transcript-fence-r4
rage/core/324-expanded-history-sidebar-r2
rage/android/175-terminal-transcript-fence-r3
rage/android/175-focus-release-retry-r2
rage/android/175-focus-release-retry
ci/desktop-idle-cpu-budget
rage/android/175-terminal-transcript-fence-r2
rage/android/175-route-stop-retry-r3
rage/575-transient-send-backpressure-r3
rage/575-transient-send-backpressure-r2
rage/android/175-terminal-transcript-fence
rage/android/175-route-stop-retry-r2
rage/android/175-sink-self-close-r2
rage/android/175-route-stop-retry
rage/android/175-sink-self-close
rage/android/175-audio-focus-sync-loss-r2
rage/android/175-stock-voice-interop-r3
rage/android/175-stock-voice-interop-r2
rage/android/175-audio-focus-sync-loss
rage/android/175-recover-stack-current-4
rage/android/175-stock-voice-interop-r1
rage/android/175-recover-stack-current-2
rage/587-vulkan-current-master-r2
rage/587-dictation-vulkan-current2
rage/575-transient-send-backpressure-r1
tmp-do-not-use-587
tmp-do-not-use-587-2
tmp-do-not-use-587-3
tmp-do-not-use-587-4
rage/587-dictation-vulkan-current2-tree
fix/dictation-ggml-vulkan-rage587
rage/android-campaign-batch-20260906
rage/587-dictation-ggml-vulkan-current
rage/388-toolnode-forwarding-r17-current2
rage/587-dictation-ggml-vulkan-r1
rage/388-toolnode-forwarding-r17-current
rage/575-gateway-send-diagnostics-current
rage/178-device-action-json-depth-r7
rage/175-recorder-failure-precedence-r8
rage/175-terminal-capture-cleanup-r8
rage/175-playback-write-failure-cleanup-r8
rage/575-gateway-send-diagnostics
rage/388-toolnode-forwarding-r17
rage/575-stock-interop-diagnostics-r2
fix/dictate-whisper-cpp-vulkan
rage/575-stock-interop-diagnostics-r1
rage/324-expanded-history-sidebar-r1
rage/178-device-action-json-depth-r6
rage/388-plugin-cancellation-r16
rage/175-recorder-failure-precedence-r7
rage/175-terminal-capture-cleanup-r7
rage/175-playback-write-failure-cleanup-r7
rage/324-native-chrome-r1
rage/175-recorder-failure-precedence-r6
rage/175-terminal-capture-cleanup-r6
rage/175-playback-write-failure-cleanup-r6
rage/324-independent-geometry-r2
rage/175-close-resource-precedence
rage/178-device-action-json-depth-r5
rage/175-recorder-failure-precedence-r5
rage/175-terminal-capture-cleanup-r5
rage/175-playback-write-failure-cleanup-r5
rage/324-independent-geometry-r1
rage/324-screenshot-provenance-r1
rage/324-history-parity-r1
rage/178-device-action-json-depth-r4
rage/175-preserve-recorder-primary-failure-r2
rage/175-capture-terminal-failure-cleanup-r3
rage/175-playback-write-failure-cleanup-r4
rage/324-screenshot-ci-r1
rage/324-unified-copilot-r4
rage/175-capture-terminal-failure-cleanup-r2
rage/175-playback-write-failure-cleanup-r3
rage/324-unified-copilot-r3
rage/175-preserve-recorder-primary-failure
rage/175-capture-terminal-failure-cleanup
rage/178-device-action-json-depth-r3
rage/175-playback-write-failure-cleanup-r2
rage/178-voice-stream-json-depth-r5
rage/160-semantic-first-runtime-r2
rage/175-playback-write-failure-cleanup
rage/178-voice-stream-json-depth-r4
rage/324-unified-copilot-r2
rage/178-device-action-json-depth-r2
rage/178-voice-json-depth-r3
rage/178-voice-ack-json-depth-r3
rage/160-semantic-first-runtime
rage/492-device-action-replay-r6
rage/178-device-action-json-depth
rage/178-voice-json-depth-r2
rage/178-voice-ack-json-depth-r2
rage/178-voice-json-depth-bound
rage/178-voice-ack-json-depth
rage/178-voice-hello-json-depth
rage/178-device-json-depth-bound
rage/178-capability-json-depth-bound
rage/178-android-daemon-restart-stale-turn-r2
rage/492-device-action-replay-r5
rage/492-device-action-replay-r4
rage/178-android-daemon-restart-stale-turn-r1
rage/178-android-json-depth-bound-r2
rage/178-android-json-depth-bound-r1
rage/203-android-playback-session-invalidation-r3
rage/492-device-action-replay-r3
rage/178-android-audio-payload-bound-r4
rage/203-android-playback-session-invalidation-r2
rage/178-android-audio-payload-bound-r3
rage/492-device-action-replay-r2
rage/203-android-ui-close-runtime-ownership-r3
rage/203-android-playback-session-invalidation
rage/178-android-audio-payload-bound-r2
rage/203-android-ui-close-runtime-ownership-r2
rage/178-android-uri-intent-abuse-r4
rage/178-android-audio-payload-bound
rage/203-android-ui-close-runtime-ownership
rage/492-device-action-replay-r1
rage/178-android-uri-intent-abuse-r3
rage/178-android-no-raw-logging-r5
rage/492-device-action-replay-horizon
rage/218-normalizer-config-r4
rage/178-android-uri-intent-abuse-r2
rage/178-android-no-raw-logging-r4
rage/178-android-uri-intent-abuse-r1
rage/218-normalizer-config-r3
rage/178-android-no-raw-logging-r3
rage/178-android-prolog-lifecycle-r3
rage/178-android-no-raw-logging-r2
rage/178-android-prolog-lifecycle-r2
rage/178-android-principal-target-abuse-r2
rage/178-android-no-raw-logging-r1
rage/178-android-prolog-lifecycle-r1
rage/178-android-principal-target-abuse-r1
rage/178-android-device-action-replay-r4
rage/178-android-device-action-replay-r3
rage/178-android-capability-revocation-r3
rage/218-normalizer-config-r2
rage/178-android-trealla-result-overflow-r1
rage/178-android-device-action-replay-r2
rage/178-android-capability-revocation-r2
rage/178-android-auth-revocation-r2
rage/178-android-device-action-replay-r1
rage/178-android-capability-revocation-r1
rage/178-android-auth-revocation-r1
rage/178-android-reconnect-storm-r3
rage/218-normalizer-config-r1
rage/218-normalizer-config-status-r1
rage/324-unified-copilot-r1
rage/217-s1-mini-normalizer-r4
rage/178-android-reconnect-storm-r2
rage/178-reconnect-storm-red-proof
rage/217-s1-mini-normalizer-r3
rage/178-android-release-matrix-r1
rage/217-s1-mini-normalizer-r2
rage/203-android-recorder-failure-diagnostics-r3
rage/217-s1-mini-normalizer-r1
rage/203-android-assistant-role-loss-wiring-r3
rage/216-transcript-normalization-contract-r2
rage/203-android-recorder-failure-diagnostics-r2
rage/203-android-assistant-role-loss-wiring-r2
rage/216-transcript-normalization-contract-r1
rage/203-android-reconnect-scheduler-failure-r2
rage/388-plugin-tool-cancellation-r15
rage/203-android-reconnect-scheduler-failure
rage/203-android-voice-session-invalidation-r4
rage/203-android-voice-session-invalidation-r3
rage/203-android-ui-error-redaction-r3
rage/388-plugin-tool-cancellation-r14
rage/388-plugin-tool-cancellation-r13
rage/400-plugin-capability-composition-r1
rage/203-android-ui-error-redaction-r2
rage/388-plugin-tool-cancellation-r12
rage/203-android-audio-route-rollback-failure-r2
rage/325-atomic-durable-message-append
rage/203-android-state-store-temp-isolation-r2
rage/388-plugin-tool-cancellation-r11
rage/388-plugin-tool-cancellation-r10
rage/203-android-audio-route-rollback-failure
rage/203-android-recorder-failure-diagnostics
rage/203-android-voice-runtime-invalidation-r2
rage/203-android-assistant-role-loss-wiring
rage/203-android-voice-session-invalidation-r2
rage/203-android-ui-error-redaction
rage/388-plugin-tool-cancellation-r9
rage/203-android-state-store-temp-isolation
rage/203-android-connection-error-redaction
rage/203-android-assistant-role-loss-r3
rage/388-plugin-tool-cancellation-r8
rage/203-android-voice-runtime-invalidation-primitives
rage/203-android-assistant-role-loss-r2
rage/203-android-voice-diagnostic-redaction-r2
rage/388-plugin-tool-cancellation-r7
rage/203-android-assistant-role-loss
rage/203-android-voice-session-invalidation
rage/203-android-voice-diagnostic-redaction
rage/174-android-open-app-aliases
rage/388-plugin-tool-cancellation-r6
rage/203-android-assistant-shutdown-fence
rage/388-plugin-tool-cancellation-r5
rage/29-streaming-tts-provider-recovery-r10
rage/203-android-mic-permission-lifecycle
rage/203-android-audio-route-lifecycle
rage/175-android-audio-focus-lifecycle
rage/174-android-device-capabilities
rage/29-streaming-tts-provider-recovery-r9
rage/388-plugin-tool-cancellation-r4
rage/388-plugin-tool-cancellation-r3
rage/29-streaming-tts-provider-recovery-r8
rage/326-desktop-toggle
rage/388-plugin-tool-cancellation-r2
rage/388-plugin-tool-cancellation
rage/29-streaming-tts-current-r7
rage/29-streaming-tts-current-r6
rage/371-plugin-approval-current
rage/29-streaming-tts-current-r5
rage/371-plugin-approval-contract
rage/371-plugin-approval-red
rage/29-streaming-tts-current-r4
rage/196-ui-closed-runtime
rage/196-android-assistant-role
rage/29-streaming-tts-current-r3
rage/175-android-barge-in
rage/175-android-streamed-voice
rage/175-android-manual-voice
rage/29-streaming-tts-current-r2
rage/29-streaming-tts-current
rage/327-bounded-target-edit-distance-recovery-r2
rage/348-dash-prefixed-z85-cli-r2
rage/197-compose-first-usable
rage/348-dash-prefixed-z85-cli
rage/173-android-client-continuity
rage/327-bounded-target-edit-distance-recovery
rage/329-production-secure-listener
rage/329-merge-probe
rage/159-zara1-device-actions-current
docs/refresh-20260905
rage/159-zara1-device-actions-recovery
rage/324-unified-copilot
rage/173-android-auth
rage/327-bounded-target-edit-distance
research/unified-copilot-20260905
rage/133-desktop-daemon-default-regression
rage/133-daemon-default-regression
rage/13-open-app-allowlist-regression
rage/165-user-command-runtime
rage/315-route-backpressure-test-contract
rage/164-user-command-authoring
rage/163-user-command-compiler
rage/162-user-command-persistence
rage/309-prolog-config-recovery
docs/260-customization-wiki
rage/260-customization-diagnostics
rage/159-zara1-device-actions
rage/260-agent-loop-backend-registry
rage/260-backend-registry
rage/260-service-plugin-advice
backup/rage-260-service-plugin-advice-pre-android-merge-20260903
rage/android-172-cross-runtime-parity
rage/zara-004-config-durability
rage/260-prolog-command-advice
feature/long-horizon-tasks
rage/264-config-delta
rage/264-host-delta
rage/264-config-host-delta
rage/rebase-264-long-horizon-tasks
backup/rage-260-prolog-command-advice-pre-rebase-20260903
rage/android-172-resolver-parity
rage/260-python-user-hooks
rage/260-agent-loop-integration
rage/android-172-asset-staging
rage/android-172-native-adapter
rage/260-python-hooks-advice
rage/android-172-jni-bridge
rage/android-172-trealla-runtime
rage/260-hooks-prolog-config
rage/android-172-fixture-runner
fork/prolog-rlm-agentic-runtime
rage/android-172-normalized-results
rage/android-172-assets-v2
rage/core-246-todo-toggle-current
rage/android-172-assets
rage/core-246-todo-toggle-refresh
rage/android-172-portable-prolog-refresh
feature/agent-mode-core
rage/recover-259-run10
rage/android-172-portable-prolog
docs/244-merge-evidence
backup/feature-long-horizon-tasks-pre-rebase-20260902
feat/zara-031-context-management
docs/250-merge-evidence
rage/250-amd-stt-device-routing
rage/159-zara1-capability-advertisement
feat/unified-agent-tui
fix/discord-tools-bash
rage/158-api-service-providers
docs/249-merge-evidence
rage/249-latency-trace-checkpoint
fix/246-disable-todo-surface
codex/zara-discord-plugin-guidance
rage/157-execution-plans
rage/156-prolog-frames
rage/28-post-merge-evidence
perf/zara-027-streaming-llm-impl
rage/155-typed-slots
test/live-smoke-reasoning-budgets
feature/openrouter-rlm-directmode
rage/154-intentframe-contract
chore/backlog-import
rage/195-samsung-assistant-research
feat/android-app
research/aradr-local-tts-voice-cloning
feature/wake-words-edit-distance
perf/zara-027-streaming-llm
docs/134-reentry-assessment
rage/134-daemon-release-gate
rage/131-merge-closeout
docs/rage-130-merge-outcome
docs/rage-17-merge-outcome
fix/zara-016-llm-provider-contracts
build/flake-update-2026-08
rage/191-zara1-tool-approvals
rage/132-visible-stt-regression
codex/copilot-redesign
codex/default-daemon-cli
rage/132-transcript-events
rage/133-post-merge-evidence
rage/133-client-migration
rage/132-post-merge-evidence
rage/132-live-voice
rage/132-live-voice-zara1
rage/131-principal-isolation
rage/131-principal-scope
rage/130-curve-zap-security
rage/130-auth-security
docs/rage-129-merge-outcome
rage/129-zara1-protocol
rage/129-slice-e-lifecycle-red
rage/129-slice-e-endpoint-red
docs/rage-128-merge-outcome
rage/139-daemon
docs/full-feature-sweep
feature/mcp-client-support-current
remove-prolog-rlm
research/daemon-zeromq-voice-service
feature/autoresearch-bootstrap
agent/VAD-patch
agent/prolog-capability-reasoner
agent/whisper-cpp-vulkan-stt
agent/remove-pet-notification-spam
codex/service-plugin-runtime
agent/stt-backends
agent/fix-laptop-stt-quality
feature/prolog-rlm-integration
agent/fix-speaker-echo-loop
agent/stt-gpu-rocm-support
agent/fix-ubuntu-wayland-pets
feature/desktop-theme-contrast
fix/whisper-load-state
agent/mcp-client-support
fix/wake-model-readiness-debug
fix/wake-capture-failure-propagation
fix/wake-audio-health
agent/readme-current-zara
fix/desktop-conversation-migration-repair
agent/fix-voice-runtime-noise
feature/desktop-launch-surface
feature/quick-copilot
feature/conversation-full-chat
feature/desktop-shell
feature/runtime-host
feature/runtime-events
research/desktop-copilot
agent/overhaul-memory-forgetting
agent/fix-command-context-routing
agent/fix-streaming-vad-wake
agent/pets-post-merge-fixes
feature/pets
revert/wake-throughput
fix/wake-word-detection
fix/pulse-shared-mic-ci
fix/shared-mic-capture
feat/zara-timer-alarm-sounds
fix/zara-017-todo-correctness
fix/zara-015-prolog-engine-contract
fix/zara-018-ack-result-events
agent/readme-rewrite
fix/zara-014-wake-lifecycle
fix/zara-013-file-tool-sandbox
fix/zara-012-process-safety
fix/recover-zara-006-011-to-master
revert-36-fix/zara-005-dictation-lifecycle
revert-44-fix/zara-011-dictation-ordering
fix/zara-010-tts-contracts
fix/zara-011-dictation-ordering
fix/zara-007-intent-precedence
fix/zara-008-multi-tool-history
fix/zara-009-memory-fallback
fix/zara-006-timers
fix/zara-005-dictation-lifecycle
fix/zara-003-fail-closed-commands
fix/zara-004-prolog-config-overrides
agent/ci-test-gate
fix/zara-002-config-toml
fix/zara-001-wake-entrypoint
memory
cleanup
device-acceptance-661
v0.1.0-alpha
Labels
Clear labels
bug
Something isn't working
documentation
Improvements or additions to documentation
duplicate
This issue or pull request already exists
enhancement
New feature or request
good first issue
Good for newcomers
help wanted
Extra attention is needed
invalid
This doesn't seem right
question
Further information is requested
wontfix
This will not be worked on
No labels
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
nsaspy/zara#150
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal
Refactor Zara's command path after the daemon/client split so intent meaning, missing-argument dialogue, capability selection, and execution location are separate first-class contracts.
The target is one portable semantic core that can serve Linux desktop/CLI, the long-lived
zara-server, future Android clients, and future offline/device-local execution without duplicating intent vocabularies or turning the wire protocol into a remote shell.This epic is future implementation work. Do not begin implementation before #133 has completed the supported client split. Voice-specific integration additionally depends on #132. The daemon release decision remains owned by #134.
Code-review baseline
This epic is designed against PR #148 as though its intended principal-isolation architecture will merge, but does not pretend the current PR is merge-ready. Review on #148 identified pre-merge #131 integration blockers that must be closed first:
RuntimeSupervisor._build_default_host()currently discards itsPrincipalContext, so defaultAgentManagerconstruction still creates memory without an explicit authenticated principal;ConversationStoreintroduced by #148 is not yet the default daemon agent conversation path;AgentManagerstill owns an in-memoryConversationManagerhistory;RuntimeCommandinto aRuntimeEventBusthat correctly accepts onlyRuntimeEvent;The future architecture may assume the design outcome of #131 (principal-bound private state), but must not depend on those gaps remaining.
Current problems this epic owns
Parsing is conflated with execution
Current Prolog intent results are essentially
kind + name + args, and several execution paths still jump from a resolved verb directly toward command handling.Missing arguments are only partially modeled
modules/intent_resolver.plalready has a useful seed:pending(Intent)plus named missing slots for cases such as bareopenandtext. It is not general. A bare timer goes through the special timer parser and fails instead of yielding a typed request forduration.Provider location is implicit
Current
kb/config.plis heavily Linux/device shaped (xdg-open, GNOME utilities, desktop apps, shutdown commands). Those mappings must not become server policy just because Prolog moves behindzara-server.The LLM agent currently duplicates routing policy in prompt text
AgentManagercontains a command-verb list and tells the model to invokequery_prolog. Semantic command routing should become a runtime service contract rather than prompt-only policy duplicated beside Prolog.ZARA/1has no typed device capability/action plane yetProtocol v1 is closed and currently supports the daemon text/runtime vocabulary plus reserved voice messages. Future device capabilities must extend that closed schema explicitly rather than smuggling executable names or arbitrary shell through
body.Required architecture
1. Portable semantic
IntentFrameIntroduce one typed, transport-neutral semantic representation. Exact fields are research-owned, but it must represent at least:
Parsing an intent must not select an OS command or execute a tool.
2. First-class dialogue/slot completion
Generalize existing
pending(Intent)behavior into a state machine capable of:actually make that five minutes);never mind);pending_command;Example contract:
The second utterance must not be treated as an unrelated top-level command when an unambiguous active slot request owns it.
3. Capability/provider reasoning
After a complete semantic intent, resolve an abstract capability/provider independently from parsing.
Conceptual model:
Provider location must be explicit, for example:
server: API/service/tool/database/memory/search/server administration;device: desktop/Android actions such as open URI/app, clipboard, notification, screenshot, volume;Reuse and critically re-evaluate the ideas in draft PR #119 as prior art. Do not merge/revive it blindly; its provider reasoning must be reconciled with the authenticated daemon, typed protocol, and no-Prolog-RLM rule.
4. Server
api_serviceboundaryCreate a closed server-side service/capability layer behind
RuntimeHostfor actions that correctly belong to the daemon. Examples include search, memory, server timer/service operations, databases, MCP/tool-backed work, and explicitly authorized daemon administration.The ZeroMQ gateway must never call services, Prolog, tools, or AgentManager directly.
RuntimeHostremains the application-service boundary.5. Separate semantic and platform configuration
Do not copy current Linux
kb/config.plcommand mappings onto the server.Research and implement a clear split such as:
Exact filenames/predicates are research-owned. Prefer a normalized provider fact model internally when it makes reasoning easier, while preserving understandable user configuration.
6. Closed typed device actions over
ZARA/1Clients may advertise an allow-listed capability set such as
open_uri,open_app,clipboard,notification,speaker,microphone, or future Android actions.Server-to-client execution must use typed requests/results with:
Never send arbitrary shell, Python import/class names, executable paths, or eval-able code as a generic device action.
7. Existing subsystem integration
Required example-command corpus
Tests for every slice must use realistic commands, not only synthetic predicate calls. Minimum corpus includes:
set a timer for twenty minutes-> complete timer duration 1200s;set a timer-> missing duration ->How long?;twenty minutesfills the pending timer;actually make that five minutescorrects the pending/completed draft before execution where policy permits;never mindcancels pending work;open Firefox-> semantic open-app capability, device provider;open-> ask what to open;text Sarah-> missing message;text Sarah tell her I'm running late-> complete message frame;search for ZeroMQ CURVE authentication-> server search/service capability;take a screenshot-> initiating-device capability;what do you remember about X?-> server memory capability;Every new intent/capability added later must extend the corpus.
Adversarial requirements
Prove:
RAGE/TDD requirements
Each child issue must be consumed individually through the repository RAGE protocol. Before implementation its work log records exact immutable start SHA + issue. Research must be capable of changing this proposed design. Tests first, prove expected red, minimum production change, focused + full repo/Nix gates, changed-code coverage review, exact-head GitHub Actions, merge only exact green/mergeable head.
Ordered implementation slices
Create/consume child issues in this order unless RAGE research changes dependencies:
IntentFramespecification;ExecutionPlanand reconciliation of PR #119 prior art;api_serviceprovider boundary + server/device config split;ZARA/1capability advertisement and typed device action request/result plane;Completion rule
This epic is complete only when Zara can accept a realistic command, construct one portable semantic intent, clarify missing slots across turns, choose a policy-valid provider based on authenticated server/device capabilities, execute through the correct service/device boundary, and prove the same semantics across at least the Linux client and deterministic future-client fixtures without arbitrary remote execution.
Canonical child issue map
This epic is now fully issue-owned. Consume these children in order unless a RAGE research iteration changes a dependency:
IntentFramecontract (blocked by #133)ExecutionPlan; PR #119 is prior art onlyapi_serviceproviders + semantic/server/device config splitDo not invent implementation directly from the parent prose when one of these issues owns it.
IntentFramecontract #154IntentFrameand establish the canonical realistic command corpus #156ExecutionPlanwithout reviving draft architecture blindly #157api_serviceproviders and split semantic/server/device Prolog configuration #158IntentFrame/capability plans #163ZARA/1with bounded client capability advertisement and typed device action lifecycle #159Architecture reconciliation — 2026-09-07
Current
masterhas advanced beyond two assumptions in this epic body:do not begin before #133dependency gate is satisfied. Child-order/dependency gates still apply normally.This does not change this epic's authority model. #150 remains the semantic/typed-slot/capability/ExecutionPlan authority. #122 has been evolved in place to harden the current #233 rewrite adapter, and model/RLM output remains proposal-only: it cannot invent capabilities, bypass typed slot validation, or directly authorize/execute side effects.
Interpret the old
#124 remains ...and blanketno Prolog-RLM pathprose in this issue as superseded implementation-mechanism text, not as a reason to reopen #124 or fork a second model stack. The safety intent remains: no unbounded model/RLM agent path and no model/RLM side-effect authority.Do not close #150 as superseded by #624/#625/#628; those later cognitive-kernel epics build on this unfinished semantic contract.