Skip to content

lynxtwo/anti-dark-code

v2026.10.4-unified.17FSL-1.1-MIT

Evidence-based architecture review, code audits, verification, and authorized improvements.

Changelog

2026.10.04-unified.17

  • Add a held-handle destination binding to references/assurance-preservation.md: when destination identity protects writes, bind them to a verified held directory handle or platform equivalent, prove the actual child retains that binding, and test replacement or unmount after validation, including tools that recreate missing paths on another filesystem. Baseline trials without the text missed this obligation in one of five runs.

  • Add a final-step lock denial check to references/assurance-native-execution.md: at the last protected step, prove a separate contender cannot acquire the lock with incidental holders absent, and test closed, reused and wrong-object descriptors and stale environment claims. Baseline trials missed this obligation in five of five runs; trials with the text met it in two of three.

  • Require behavioral trial evidence for promoted instruction text in references/15-dogfeeding-flowback.md: at least three fresh-context trials per case per skill state, an addition kept only when a baseline trial without it misses its obligation, baseline trials topped up to five before pruning, counts and quotes recorded without a compliance percentage, and pruned lessons kept queued as rejected naming the evidence so a new incident reopens them. CONTRIBUTING.md and the public site state the same rule.

  • Record the promotion review in design/lessons-unified-17-plan.md and the trials in design/evals/lessons-v17/: one Codex trial per case per state scored by the author, two further Claude trials per case per state scored blind, and baseline-only runs four and five. Sixteen proposed additions whose baseline never missed were pruned before commit and remain queued in their consumer repositories; held observations stay held. A later standard-tier check (three Sonnet 5.5 trials per case against the unified.17 text, blind-scored, evidence-2026-10-04-sonnet-baseline.json) missed no obligation. Local checks do not publish a release or update consumers.

  • Point the README at the public site instead of the raw page source.

  • Release surfaces for 2026.10.04-unified.17: version, catalog version, README, pinned-tag examples, website and brief headers. The brief carries a one-line promotion-evidence note and a tightened bindings paragraph on its Keep-knowledge-local page, keeping seven print pages; the PDF is re-rendered with design/render-brief-pdf.py (the Playwright recipe its provenance names) and the provenance refreshed. The six plugin metadata files are regenerated as 2026.10.4-unified.17.

  • Add the owner-selected Illuminated code artwork in GitHub-profile-inspired black and gold to Codex plugin and skill metadata, including a simplified composer icon. Keep editable SVG and PNG exports together; treat PNGs as binary across platforms and reject packages with missing or linked artwork. Preserve validation of the original unified.16 package without artwork. Published unified.16 assets remain unchanged.

  • Add the approved progressive frost to website and screen-brief navigation. Decorative inert snapshots blur only within the narrow navigation strip, with scroll/resize synchronization, opaque accessibility fallbacks and print exclusion. Published unified.16 release assets remain unchanged.

Reference and template inventory

  • references/15-dogfeeding-flowback.md
  • references/assurance-native-execution.md
  • references/assurance-preservation.md
  • assets/brand/README.md
  • assets/brand/illuminated-code-small.png
  • assets/brand/illuminated-code-small.svg
  • assets/brand/illuminated-code.png
  • assets/brand/illuminated-code.svg

2026.09.27-unified.16

  • Apply the approved glass visual direction to the website and screen brief: frosted navigation, rounded opaque reading surfaces, accessible fallbacks and visible workflow/PDF/support links. Keep the seven-page PDF crisp with matching rounded components and refreshed provenance.

  • Refresh the version, capability catalog, website and seven-page brief with current plugin installation guidance and source links; regenerate the PDF and its provenance. Surface optional one-time or monthly support through the existing GitHub Sponsors destination in the website and README.

  • Compare historical mutation test identities across the exact test_route.py packaging move while preserving their recorded paths. Test classes, names and parameter IDs must still match, and an unskipped survivor remains a failure.

  • Package the single universal core under skills/anti-dark-code/ for Agent Plugins 1.0, Codex, Claude Code and Gemini CLI; add host manifests and root-relative marketplaces without hooks or automatic collection. Preserve standalone installs and repository-owned calibration. Document the source-path migration in MIGRATION.md and installation in PLUGINS.md. Plugin versions normalize the canonical calendar version to strict SemVer; adc_packaging.py detects metadata drift and regenerates the six metadata files explicitly.

  • Validate new-layout manifests from the tagged release archive, retaining historical standalone release checks and distinguishing pure file moves from undocumented reference changes. Update CI, the active mutation matrix/test pointers and source authority probes for the new layout. Extend assets/templates/calibration/routing-policy.json for the plugin source scope marker while retaining legacy and installed paths. Add migration, stale-tag metadata and discovery regressions. Shorten the skill description to put triggering tasks first and declare license/runtime compatibility; activation-rate improvement remains unmeasured.

  • List review in adc.py usage --help. The routine task review commands (enable, disable, hook, submit, pending) were reachable only through argv dispatch and never appeared in the help that references/routine-task-review.md documents. Dispatch is unchanged; usage review --help still reaches the helper's own parser. Two tests assert both help outputs (tests/test_usage_review.py).

  • Repair stale references found in a documentation sweep. Correct the swapped capability labels in references/product-principles.md (contracts are V08, invariants V03). Add the Improve card to references/00-preflight.md. Replace the fixed V01 through V20 range in assets/templates/repo-slices.md with the catalog. Describe managed files in references/13-calibrated-local-mode.md as the whole core except calibration/, incoming/ and caches. Call the installed path canonical, not legacy, in references/specialist-exact-gate-contract.md; collapse its blank-line runs and those in references/assurance-claim-proof.md. Match the audit marker to the planted TODO(adc): marker in references/specialist-remediation-edges.md. Point references/specialist-verifier-falsifiability.md at the exact gate contract's cautions instead of 14-deterministic-verification.md, which has none. Replace "this section" with "this recipe" in references/assurance-hardware-recovery.md and references/assurance-preservation.md. Promote skipped heading levels in references/assurance-native-execution.md, references/assurance-release-closure.md and references/specialist-native-reachability.md. Repair the sentence "No failure signal needs no escalation." in references/orchestration-mode.md. No rule, status, identifier or capability changed.

  • Link the references nothing linked to from the place their trigger belongs: steering from references/tasks/document.md, shadow routing evidence and artifact cleanup from references/13-calibrated-local-mode.md, optional orchestration from references/host-adapters.md. Index the vocabularies that specialist references define from references/00-conventions.md, note that unknowns entries store the severity scale under Risk level, and distinguish flow-back ready from item status ready. Open references/assurance-claim-proof.md with its Trigger paragraph like every other recipe. List the mutation survivor classes once in references/specialist-mutation-restoration.md. Add two documentation-contract tests: every reference has an inbound link from the core (the compatibility entry 00-preflight.md excepted), and the thirteen recipes carry one identical authority sentence.

  • Give each rule that appeared in two references one canonical home and leave a pointer where the copy lived: commit bounds in references/11-remediation-loop.md (pointer from references/combined-03-06-loop.md); the widening-guard and gate-named-repair rules in the remediation loop (pointer from references/specialist-mutation-restoration.md); collection equality and child-context handoff in references/specialist-exact-gate-contract.md (pointer from references/specialist-verifier-falsifiability.md); detector thresholds in verifier falsifiability (pointer from references/specialist-gate-environment.md); the engagement record in the core's Authority section (references/tasks/improve.md defers to it); the alternative comparison in references/quality-tests.md (references/tasks/remediate.md and references/tasks/improve.md apply it); the Codex record contract in references/real-world-usage.md (references/host-codex.md no longer repeats the version). Remove the generated-binary sentence repeated inside references/specialist-native-reachability.md and the trigger sentence repeated inside references/assurance-hardware-recovery.md and references/assurance-preservation.md, folding hardware recovery's extra item (media state) into its Trigger line. No rule changed; the three catalog-screening pointers that all name 14-deterministic-verification.md stay as intentional entry points.

  • Add references/proportionality.md: a need trace (need, authority, worst case) recorded before a task card loads for assurance, campaign, harness, observer or guarantee requests; a consequence class on every guarantee claim with an assurance ceiling per class, where stock local development credentials in disposable resources are none; a boring-option comparison before any custom mechanism; and a reframe trigger that stops for the owner's decision when a proof ledger is still at zero after the attempt limit, the subject under test is itself a harness or evidence tool with no authority naming its need, or the verification inventory grows while product code does not. Retries and observer, allowlist, sampling-window or timeout changes count as attempts. No stop condition is waived.

  • Point to it from the core's selection, evidence and completion rules (SKILL.md), from references/tasks/investigate.md step 1 and from references/tasks/verify.md step 3. The core sentence "Neither requires repeating completed work." was removed to stay inside the per-file instruction budget.

  • Restore core headroom: SKILL.md drops from 1198 to 1139 words against its 1200-word budget. The product paragraph keeps its trigger and two guards and defers the rest to references/quality-tests.md and references/product-principles.md; the routine-feedback completion rule moves into references/routine-task-review.md with a pointer from the opt-in sentence; "Load only the matching task card" becomes "Load the matching task card first", since cards may name another card. Three further trials in design/evals/proportionality-v1/evidence-2026-09-26-headroom.json show no change in behavior.

  • Add design/evals/proportionality-v1/: two behavioral case prompts with a yes/no rubric, and the dated evidence file holding the baseline trials that failed without the reference and the trials that ran with it. Counts and quotes only; no compliance percentage.

Reference and template inventory

  • assets/templates/repo-slices.md
  • references/00-preflight.md
  • references/13-calibrated-local-mode.md
  • references/assurance-claim-proof.md
  • references/assurance-hardware-recovery.md
  • references/assurance-native-execution.md
  • references/assurance-preservation.md
  • references/assurance-release-closure.md
  • references/orchestration-mode.md
  • references/product-principles.md
  • references/specialist-exact-gate-contract.md
  • references/specialist-native-reachability.md
  • references/specialist-remediation-edges.md
  • references/specialist-verifier-falsifiability.md
  • references/00-conventions.md
  • references/13-calibrated-local-mode.md
  • references/host-adapters.md
  • references/specialist-mutation-restoration.md
  • references/tasks/document.md
  • references/combined-03-06-loop.md
  • references/host-codex.md
  • references/specialist-gate-environment.md
  • references/tasks/improve.md
  • references/tasks/remediate.md
  • references/proportionality.md
  • references/tasks/investigate.md
  • references/tasks/verify.md
  • references/routine-task-review.md

2026.09.15-unified.15

  • Add scoped quality tests, product principles, a product-contract template and the Improve task card. Preserve audit-only work, owner authority and stable capability/status IDs. Apply relevant user journeys without turning technical tests into usability or fairness claims.
  • Partition HTML scripts, handlers, controls, prose and inert data. Recognize framework-free browser apps and declared Python CLI entrypoints. Separate runtime family, source-file size and unknown maturity; distinguish fixtures, examples, catalogs and quoted Python strings from runtime evidence. Preserve representative locators for contributing evidence classes.
  • Refuse shared/wrong-owner usage-ledger paths before sensitive writes. Create private files and verify POSIX modes or Windows ACLs. Assign current-user ownership to new empty Windows files before writes, since the token's default group owner need not match the parent. Initialize under a private sibling and publish the completed directory; retry after interruption without deleting unrelated files. Existing ledgers retain their schema and require the documented private permissions.
  • Add private, exclusive summary export with explicit scope, feedback correction guidance and a manual history-removal workflow. Collection remains opt-in. No automatic purge or retention period, live-log collection, upload, release or installation is introduced.
  • Add opted-in routine Codex task reviews through reviewed native UserPromptSubmit and Stop hooks. Observe private hashed tickets independently of skill activation; reconcile delayed parent usage without borrowing another task or overwriting independent feedback. Retain missing labels, delivery gaps, failed-attempt reports and correction history. Split reported trigger results by reviewer class; Stop never grades a task or forces a model continuation. Other hosts retain manual feedback.
  • Isolate the Windows permission checker's module path to its own system modules. PowerShell 7 host environments otherwise can prevent Windows PowerShell 5.1 from loading Get-Acl. Keep the caller's environment, private-owner requirements and timeouts unchanged; test an incompatible inherited module path.
  • Give the Windows privacy helper a measured timeout. Windows PowerShell 5.1 slows sharply under CPU contention: draft PR #61's probe measured setup calls of 4.0 to 10.2 s on CI runners, and a local burst of 192 concurrent setup calls reproduced the intermittent "cannot create a private Windows staging directory" refusal only for calls that crossed the former 15 s ceiling, while calls without a ceiling always succeeded. The ceiling is now 60 s, more than a 2:1 margin over the slowest success observed, and each refusal names its reason (timed out, could not start, or did not confirm a private ACL) without child output or paths. No retry was added and no permission policy changed.
  • Clarify the brief's introduction and examples, add linked contents and page numbers, preserve page margins, and shorten the maintenance section. Regenerate the seven-page PDF and its source/artifact hashes.
  • Share pinned test dependencies across local setup and CI, with pytest-xdist only for parallel execution. Add contrasting regression fixtures and a versioned product evaluation set with browser observations; no agent-compliance percentage is claimed.
  • Integrate PR #56 at 050cc959c3207c5cadf58c0d21939628462f2edb: exact test selection, property case accounting, coherent source/artifact evidence and comparable performance recordings.
  • Adapt PR #57 at b6d756645bb0e839ca82330b1fa3dbf40a497253: observe the runtime target of cached/repository-bound tools and test two checkouts with one executable. The original private reproduction is contributor-reported; the new probe regression is independently executed on synthetic repositories. The incoming proposal is not copied into the distribution.
  • Adapt PR #55 at f678454d6a60a4cabe4719d9cb147d5acdf22025: separate server readiness, client endpoint acquisition and on-device candidate identity before a physical-client review handoff. Keep server-only scope and existing evidence statuses. The contributor's physical-device incident remains contributor-reported; a loopback transport counterexample is narrower evidence, not device or agent validation.
  • Count each model response once in work_receipt.py. Claude Code writes one transcript row per content block and repeats the response's usage on each row, so summing rows over-counted; one observed session read about 3.8 times its deduplicated output tokens. Usage is now keyed by message.id (largest snapshot kept), tool calls by tool_use id, and copied transcripts count once. Rows without ids still count individually, non-object JSON lines count as malformed, and the new usage_rows field shows the raw row count. Receipts produced earlier from such transcripts overstate usage.
  • Promote two profiler lessons queued by a consuming repository. A manifest the probe cannot parse is listed under scan.unparsed_manifests, noted in the profile and warned about by probe, plan and bootstrap, because silence read as a package with no scripts; a package.json that is valid JSON but not an object is recorded the same way instead of stopping the probe. The walk also skips mutation-tool sandboxes such as .stryker-tmp and any in-tree directory holding a byte-identical copy of a root project manifest, recorded under scan.skipped_repository_copies, so a tool's copy of the project no longer becomes proposed gates. Near-empty manifests and distinct workspace packages are not treated as copies. 14-deterministic-verification.md describes both fields.
  • Adapt PR #63 at 0aa8f2f4ce2d66485088e2e1041325678adc4cdd: inventory checkouts, worktree links, shared Git storage and unique files before consolidating a workspace, and check the generated consumers a move strands (specialist-remediation-edges.md); record an optional workspace boundary in the map (02-architecture-map.md); keep machine-local state separate when verification runs on another host (specialist-gate-environment.md). The contributor's evidence remains contributor-reported, and the incoming proposal is not copied into the distribution.
  • Promote a lesson queued by a consuming repository: a change whose effect is slower than any test window leaves the suite green without proving the change inert. Check the cause through the intermediate values it moves, and observe the effect once with a long-horizon probe where that is affordable (specialist-verifier-falsifiability.md).

Reference and template inventory

  • assets/templates/calibration/coverage-ledger.md
  • assets/templates/calibration/findings-ledger.md
  • assets/templates/calibration/system-map.md
  • assets/templates/coverage-ledger.md
  • assets/templates/codex-review-hooks.json
  • assets/templates/product-contract.md
  • assets/templates/system-map.md
  • assets/verification-capabilities.json
  • references/product-principles.md
  • references/assurance-contracts.md
  • references/quality-tests.md
  • references/real-world-usage.md
  • references/routine-task-review.md
  • references/host-codex.md
  • references/repo-verification-profiles.md
  • references/specialist-gate-environment.md
  • references/specialist-native-reachability.md
  • references/tasks/improve.md
  • references/tasks/investigate.md
  • references/tasks/remediate.md
  • references/tasks/understand.md
  • references/tasks/verify.md
  • references/verification-capabilities.md
  • references/02-architecture-map.md
  • references/14-deterministic-verification.md
  • references/specialist-remediation-edges.md
  • references/specialist-verifier-falsifiability.md

2026.09.07-unified.14

  • Add opt-in passive local usage collection in scripts/adc_usage.py and versioned Codex/Claude adapters in scripts/adc_usage_sources.py. Collect reported counters from ordinary work after opt-in, resume bounded reads and deduplicate observed requests without provider calls, task replay, transcript storage or uploads. Preserve missing counters, source diagnostics and attribution limits.
  • Add structured feedback for observed tasks: skill use, expectation, invocation, quality and task class. Report trigger feedback only for the eligible labeled implicit-use sample; natural usage does not establish causal savings, subscription spend, remaining quota or population accuracy.
  • Add the offline recommendation helper scripts/adc_model_policy.py, dated assets/model-policy.json and references/model-selection.md. Filter by caller-supplied live capabilities and an acceptance check before suggesting a tier. Apply changes only through an available, authorized host control; keep the current model when required evidence is unknown and retain failed work when taking one stronger route.
  • Document collection and feedback in references/real-world-usage.md; update references/host-codex.md, references/host-claude-code.md and references/16-community-feedback-and-efficiency.md while preserving the separate controlled-pair contract. Update README.md, OPERATIONS.md, the HTML overview and six-page PDF brief for the implemented behavior.
  • Reject common credential-shaped values in model, provider and effort metadata while retaining usage with unknown attribution (tests/test_usage_sources.py). This filter does not establish that arbitrary metadata is secret-free.
  • Disable detached automatic Git maintenance in the remaining disposable Git fixtures (tests/test_adc.py). Git 2.55 tracing reproduced 135 cleanup failures in 400 baseline runs; all 100 fixed runs passed without a maintenance process. Existing cleanup and behavior assertions remain intact.
  • On Windows, force termination of a timed-out gate's process tree before its parent exits. A descendant ignoring the console break signal previously survived the parent and retained the raw output handle. The regression in tests/test_adc.py checks timeout failure, raw-output removal and descendant survival; termination remains best effort and cannot earn a passing gate result.

2026.09.07-unified.13

  • Replace mandatory numbered routing with a compact SKILL.md and five references/tasks/ cards. Preserve numbered reference entry points and move specialist obligations to conditional recipes; every reference has a per-file word budget checked in tests/test_documentation_contract.py.

  • Canonicalize scope-bound authorization, evidence kinds, zero-execution limits, manual tool fallback and evidence reuse after interruption in SKILL.md, references/00-preflight.md and references/00-conventions.md. Keep existing calibration schemas and command meanings.

  • Split README and OPERATIONS; isolate host mechanics, explicit operator workflows and opt-in usage evidence. No published host-compatibility or token-savings claim.

  • Require literal boolean owner confirmation in scripts/adc.py and scripts/adc_shadow.py, including migration inspection. Regression tests exercise malformed values without granting authority.

  • Reuse cached profiles only when recorded and current worktrees are explicitly clean; matching Git status cannot prove unchanged dirty file bytes. Dirty and non-Git targets re-probe without dropping recorded exclusions.

  • Bind cached profiles to the probe source hash, version and Python runtime; changed or missing method provenance requires a new probe with the recorded exclusions. An assets/ directory alone no longer selects game verification; game manifests and dependencies remain recognized.

  • Preserve CLI dry-run defaults, execution reviews, approval drift checks, source binding and proposal-only flow-back. Qualification records distinguish permission-limited checks from executed coverage; no timeouts or assertions were weakened.

  • Update README.md, OPERATIONS.md, the HTML overview and regenerated PDF to describe the implemented workflow. Preserve the original ASCII banner, Sponsor text, palette, metrics script and PDF navigation.

  • Replace identifying consumer case-study names with explicitly qualified generic examples, preserve design decision IDs, and keep illustrative gates disabled/proposed. Real repositories retain their own calibration.

  • Disable automatic Git maintenance only in disposable efficiency-test repositories. Git 2.55 detached pack writers reproduced a cleanup race; the same 400-case stress passed after the fixture change, with assertions and cleanup checks unchanged (tests/test_efficiency.py).

  • Partition all mutation-matrix IDs across four required Linux jobs after the single job exceeded its 25-minute limit. Keep the existing replay, per-shard restoration checks, and stable required aggregate. Workflow contracts prove complete, disjoint coverage and failure propagation (.github/workflows/tests.yml, tests/test_route.py).

Reference and template migration inventory

The task cards and conditional specialist recipes hold the extracted obligations. Numbered entries remain compatible, with repeated rules delegated to the core; host mechanics and assurance contracts have their own references. The following references and templates changed in this release:

  • assets/templates/remediation-backlog.md
  • assets/verification-capabilities.json
  • references/00-conventions.md
  • references/00-preflight.md
  • references/01-steering.md
  • references/02-architecture-map.md
  • references/03-critical-path-comments.md
  • references/04-logging-audit.md
  • references/05-coverage-slicing.md
  • references/06-writing-hygiene.md
  • references/07-adversarial-review.md
  • references/08-scenario-stress-test.md
  • references/09-artifact-gc.md
  • references/10-maintenance-harness.md
  • references/11-remediation-loop.md
  • references/12-transcreation-boundary.md
  • references/13-calibrated-local-mode.md
  • references/14-deterministic-verification.md
  • references/15-dogfeeding-flowback.md
  • references/16-community-feedback-and-efficiency.md
  • references/assurance-claim-proof.md
  • references/assurance-contracts.md
  • references/assurance-hardware-recovery.md
  • references/assurance-native-execution.md
  • references/assurance-preservation.md
  • references/assurance-publication-integrity.md
  • references/assurance-release-closure.md
  • references/assurance-runtime-boundaries.md
  • references/combined-03-06-loop.md
  • references/example-stress-test-report.md
  • references/host-adapters.md
  • references/host-claude-code.md
  • references/host-codex.md
  • references/host-gemini-cli.md
  • references/host-generic.md
  • references/orchestration-mode.md
  • references/repo-verification-profiles.md
  • references/shadow-evidence.md
  • references/specialist-audited-producers.md
  • references/specialist-exact-gate-contract.md
  • references/specialist-gate-environment.md
  • references/specialist-hidden-control-planes.md
  • references/specialist-mutation-restoration.md
  • references/specialist-native-reachability.md
  • references/specialist-process-verdicts.md
  • references/specialist-remediation-edges.md
  • references/specialist-restricted-builds.md
  • references/specialist-verifier-falsifiability.md
  • references/tasks/document.md
  • references/tasks/investigate.md
  • references/tasks/remediate.md
  • references/tasks/understand.md
  • references/tasks/verify.md
  • references/verification-capabilities.md

2026.09.06-unified.12

Six Lessons Promoted

Staged from a consuming repository in proposal #50 and promoted here.

  • A claim that crossed a context boundary is a hypothesis again (references/00-conventions.md, confidence levels). A claim inherited across a summary, handoff, or session carries no label until re-measured in the current session, and a refuted inherited claim is recorded as refuted where it was going to be filed.
  • Enumerate the channels before reporting an absence (references/00-conventions.md, negative-search evidence). An availability absence names the channels searched; a mid-migration ecosystem makes a single-channel survey systematically negative.
  • A line-ending override plus a sweep commit rewrites the repository (references/00-conventions.md, new commit hygiene section, and SKILL.md bounded execution). Explicit staging, no sweep with an environment override, attributes decide line endings, and a diff stat against the base before every push.
  • An unaudited producer needs its own output root (references/10-maintenance-harness.md, 9b). A non-gate producer declares an output root outside any audited tree, with the reason commented at the path.
  • A required job at the edge of its timeout is a flake waiting for contention (references/10-maintenance-harness.md, harness safety rules). Keep a measured two-to-one margin or split the job; re-measure before opening several pull requests at once. This repository's own mutation-replay job is the example.
  • A refusal must name a repair that does not destroy something else (references/14-deterministic-verification.md, step 4, and scripts/adc.py). gates --rebind GATE --note TEXT recomputes one gate's source binding, keeps the previous digest, appends the note, and leaves the profile and plan untouched; it refuses without a note, for an unknown gate, and when nothing drifted. The runner's refusal now names it before the planner. Three tests cover the message order, the targeted rebind, and the three refusals.

2026.09.06-unified.11

Profiling Scope

  • Documentation is not evidence that code does a thing. Every signal now records evidence_classes (source, config, structure, prose) and a documentation_only flag. A content match in a steering file, a design note, or a user guide is recorded as prose; the planner holds a non-core capability whose matched signals are all documentation-only at candidate and names them in the reason, instead of selecting it. Found at a consuming repository where 23 of 30 signals were present and the citations for financial entitlement and simulation were all Markdown, so the automatic plan selected 21 of 22 capabilities against a reviewed 10. Two tests cover the flag and the planner's response; references/14-deterministic-verification.md documents both.

Documentation

  • The catalog has described 22 capabilities since unified.9, but eleven sentences across SKILL.md, references/10-maintenance-harness.md, references/13-calibrated-local-mode.md, references/14-deterministic-verification.md, and assets/templates/calibration/README.md still said twenty, and references/verification-capabilities.md had no entry for V21 or V22. The counts now say 22, the reference gains both entries in the shape of the others, and V21 joins the core list in its selection summary.

2026.09.05-unified.10

Shadow Evidence Campaign

  • assets/templates/shadow-job.yml uploads the two policy sidecars beside the record. The record step has always written policy-<digest>.json and gates-<digest>.json next to shadow-<head>-<attempt>.json, and ingest recomputes a record's class from them (D-133), but the upload step's glob was shadow-*.json, so every artifact carried the record alone and ingest fell back to recovering the policy from the calibration at the record's head. Found on the first consumer's first live record: the job log showed both sidecars written and "1 file uploaded". The glob is now the three patterns the step writes, not *.json, because the outcomes file lives in the same directory and ingest would read it as a record and refuse it. This repository's own workflow and the consumer proposal under design/routing/consumers/ carry the same fix. Records already uploaded without sidecars remain ingestible through the recovery path.

Profiling Scope

Two defects found by installing unified.9 into a consuming repository whose main language is Visual Basic .NET and whose agent harness keeps linked worktrees under .claude/worktrees/. The profile it produced counted 1383 files where the tree under audit holds 387, listed a second steering file from inside a worktree, bound its one discovered gate to solution files four of which lived in worktrees, and selected all 22 capabilities where the reviewed plan selects 10. It also reported no Visual Basic at all. Staged as a public proposal in incoming/ and promoted here.

  • The profiler stops at a nested checkout. Any directory below the root that carries its own .git entry, file or directory, is another repository: a vendored clone, a submodule, or a linked worktree. The walk no longer descends into it and lists what it skipped under scan.skipped_nested_repositories. Agent worktrees under .claude/worktrees/ are also excluded by name, listed under scan.ignored_worktree_trees, and left out of the source-identity status hash the same way skill trees are, so a checkout parked inside the repository no longer marks the profile stale.
  • probe, plan, and bootstrap accept --exclude <path-or-glob>, repeatable, for content no rule can recognize. The request is normalized, refused if it points outside the repository, recorded under scan.requested_exclusions, and reused when plan re-probes a stale profile, so a plan cannot silently widen a scan the owner narrowed. Naming different exclusions makes the stored profile stale by intent.
  • Visual Basic .NET is a recognized language. .vb counts as source, *.vbproj and *.fsproj count as .NET manifests, and the dotnet-test candidate binds to them alongside .sln and .csproj.
  • An unrecognized language is reported, not dropped. When an extension outside every table outnumbers the largest recognized language, and there are at least ten such files, the profile records it under counts.unrecognized_source_extensions and adds a note that language and repo-type classification are incomplete. An allow-list inventory now says what it declined to count.
  • A proposal pull request can pass the clean-distribution check. anti-dark-code/incoming/ is now export-ignore, so git archive and a source-archive download leave the inbox out, which is what CONTRIBUTING.md has always promised and what the clean-distribution job verifies. The first proposal opened under the test workflow failed that job because the archive carried the very file the proposal added; release-check was unaffected because it already excludes the inbox by pathspec.
  • references/13-calibrated-local-mode.md and references/14-deterministic-verification.md document the exclusion flag, the recorded scan fields, and how to read the residue note. SKILL.md names worktrees and nested checkouts beside skill trees in the profiling exclusions.

Eight tests cover the nested-checkout skip, the exclusion flag and its refusal of outside paths, the plan's reuse of recorded exclusions, the Visual Basic count and manifest binding, both sides of the residue threshold, and the identity hash ignoring a parked worktree.

2026.09.04-unified.9

Shadow Evidence Campaign

The routing policy's rules ship proposed, and a proposed rule never runs less than everything. This adds the measurement by which a rule earns an approval review, and documents it for a repository that installs it.

  • scripts/adc_shadow.py and the adc.py shadow subcommands: outcomes and record, which a non-required CI job runs on every pull request to record what the proposed rules would have skipped and whether anything skipped failed; backfill, which replays today's router over every pull request's own run history rather than the merges that survived them; ingest, which re-reads each record's outcomes from the run it names and recomputes its verdict before appending it to a committed ledger; and summary, which counts pull requests per route class and is byte-identical on a second run. A record is evidence and never a gate: the job is absent from every required check's dependencies.
  • references/shadow-evidence.md documents the campaign for a maintainer: what a record says, what a repository needs, the install steps, the commands, canaries, and the boundaries. It is listed in SKILL.md beside the other supporting references and is not a pass.
  • assets/templates/shadow-job.yml is the job, with three placeholders, and assets/templates/shadow-gate-map.json is the mapping from canonical gates to a repository's own CI jobs and steps, with one example of each shape.
  • assets/templates/calibration/gates.json gains a canonical_full_set block, empty and commented: what a full route runs is declared beside the gates and checked against the policy, because a policy able to define "full" could shrink it and still look complete. assets/templates/calibration/routing-policy.json gains the classifier and the proposed rules a generated calibration starts from, every rule proposed so it can only ever describe what a route would have been.
  • assets/verification-capabilities.json adds V21, affected-unit testing, and V22, input fuzz testing, so the catalog describes 22 capabilities rather than 20. The obligations a routing policy binds are drawn from this catalog, and the shadow campaign's own gates bind to it.
  • Ingest recomputes each record's class against the policy that built it, kept beside the ledger and named by its own digest, so a class is checked rather than believed. adc.py shadow dominance is the second path to approval for a class no gate reads: it breaks every path the class covers, twice, runs every gate, and records what each concluded. It runs gates, so it refuses without the same owner confirmation the gate runner requires.

Release and Install Provenance

Four guards, added after unified.7 shipped a tag that did not reproduce the core distributed from it and notes that did not describe everything the release carried. Both defects were found by an independent reviewer at a consuming repository, and neither was caught by anything in this repository, because nothing checked them.

  • The installer refuses a source that is not at a release tag. install and bootstrap classify the source as git-tag, git-untagged, git-dirty, or non-git and block the two moving kinds unless --allow-untagged-source is passed after review. A plain extract stays allowed: it cannot drift. This is the guard that would have stopped the original mistake.
  • --expect-core-digest binds an install to a published release. The installer refuses unless the source core hashes to the expected digest, and the recorded source_core_sha256 then lets a reviewer check the install against the release without rerunning anything.
  • release-check verifies a tag against itself. It extracts the tag, recomputes the core digest, optionally compares it to the digest the release publishes, runs distribution validation on that extract, and returns nonzero on failure. Verifying a release by reading the working tree that produced it proves nothing about the tag.
  • Release notes must describe what the release changed. release-check reports every file under references/ or assets/ that changed since the previous tag without being named in the new notes. Mechanical version-string churn is ignored so the check stays worth reading. Run against the historical tags, this reports the unified.7 digest mismatch and its undescribed template change, and passes unified.8.

The deterministic suite grows by source-provenance classification across all four source kinds, both installer refusals, tag-reproduction failure and success, an undescribed reference change, and the version-churn exclusion. Counting everything below, it now stands at 144 tests, of which 131 pass and 13 skip on a Windows workstation without symlink privilege; a host that can create links runs about a dozen more.

Mutation and Fuzz Coverage

  • Pilots mutation testing on the highest-stakes modules and records what survived in tools/MUTATION-FINDINGS.md, including the gaps it did not close.
  • Fuzzes validate_flowback_proposal_bytes, the one function here that parses a stranger's file, against 19,000 inputs across five strategies: bit-flips, uniform random bytes, truncation, filename attacks, and an adversarial set covering terminal escapes, bidirectional overrides, homoglyphs, credential shapes, invalid UTF-8, and inputs shaped to provoke catastrophic backtracking. Four invariants: never raises, never hangs, fails closed, and can still accept a valid proposal. The fourth exists because the other three are satisfied by a validator that rejects everything.
  • Fault-injects gate termination: a gate that never returns, one that spawns a background process and then hangs, and one that ignores SIGTERM. The orphan case is the one that separates process-tree termination from child termination, and it was proven to have teeth by swapping the tree kill for a direct one and watching it fail.

Cross-Platform Verification

  • Adds a test workflow. This repository previously had none: the two existing workflows trigger only on incoming/** and metrics/**, so an ordinary code change ran no checks at all, and three stacked pull requests reached review untested on any platform.
  • The suite now runs on Linux, macOS, and Windows, plus a second Python on Linux for forward drift, and validates a clean distribution archive rather than the working tree.
  • The matrix found real defects on its first runs. macOS had never passed: it places temporary directories under /var, a symlink to /private/var, and the managed-path guards correctly refuse to write through a link-like component, so 29 tests failed before exercising anything. Windows failed four more: a symlink call that raised instead of skipping, a filesystem chmod that Windows git cannot see, fixtures written as CRLF and compared against LF from a git archive, and a shell pipeline into tar with a backslashed drive path. All were test portability rather than product defects.
  • One was subtler. A marker path embedded two string levels deep, with the outer level not raw, reached the gate's parser as a truncated unicode escape whenever the temp directory sat under C:/Users, so the gate died of a SyntaxError instead of hanging and the test reported a termination failure that had not happened. Local Windows testing could not find it, because that workstation's temp directory contains no escape-forming sequence.
  • Branch protection requires one aggregating context rather than one name per matrix leg. Pinning every leg by name makes the settings page a second implementation of the workflow's matrix, which is the standing drift risk SKILL.md names, with a failure mode where a renamed job leaves pull requests waiting on a check that no longer exists. The aggregating job runs with if: always(), so it checks each dependency's result explicitly; without that it would report success no matter what happened upstream.

Locale Independence

  • Fixes a product defect. git_output decoded git's stdout with text=True alone, which uses the machine's locale encoding: cp1252 on a default Windows install, ASCII under LC_ALL=C. Git emits UTF-8. core.quotepath hides this for paths by escaping them, but not for a branch name, a tag name, the repository path from rev-parse --show-toplevel, or diff content, so a repository under a non-ASCII directory decoded wrong or not at all. On Windows the failure was especially quiet: the decode raised inside subprocess's reader thread, stdout came back None while returncode was 0, and the caller crashed on None.strip(). Both git wrappers now pin UTF-8 with surrogateescape, which round-trips rather than corrupting values that are compared and hashed.
  • Adds a regression test that runs in a child process with the locale forced, because the parent's encoding is fixed at interpreter start and every runner in the matrix defaults to UTF-8, where the unfixed code passes. Reverting the fix turns it red with raised-AttributeError for a non-ASCII commit subject and corrupted for a non-ASCII branch name.
  • Hashes a repository path with os.fsencode rather than a strict UTF-8 encode. Under an ASCII filesystem encoding a path outside that encoding decodes to surrogates, and encoding them back strictly raises, so compute_repository_binding could not run at all for a repository under a non-ASCII directory. For any path the platform can already represent the bytes are identical, so existing bindings keep their digests. Found by the hostile-environment job on its first run, against a fix that had only handled the decode half.
  • Adds a hostile-environment job to the required gate, as two environments rather than one. A C locale with ASCII paths, and a UTF-8 locale with a temp root containing a space and non-ASCII characters; both rewrite line endings on checkout with core.autocrlf. Each condition has already produced a real failure here, and none of the three OS legs exercises any of them, because every runner defaults to UTF-8. The first attempt combined an ASCII locale with non-ASCII paths, which is a system that cannot exist: a machine whose paths are non-ASCII has a locale that can represent them. All it proved was that fixtures needing non-ASCII I/O cannot run where the filesystem encoding forbids them, so those now skip on that ground, the same way the symlink tests already do.

Source Dirtiness Measures What Ships

  • assess_source_provenance now measures working-tree dirtiness with calibration/ and incoming/ excluded. Neither directory is part of the managed core, so a work-in-progress proposal or local calibration cannot change a single byte an install carries, yet either was enough to refuse an install from a clean release tag with a message claiming the tree was dirty. That is the shape of guard people learn to override, which costs more than the guard was ever worth. A genuine edit to a shipped file still reports git-dirty, and the provenance test asserts both directions: drafts in the excluded directories leave a tagged source tagged with its digest unchanged, and a shipped-file edit still trips the guard.

Consuming-Repository Review Lessons

Three additions distilled from dogfeeding the skill at a consuming repository during owner-gated integration work. Each one earned its place by catching or explaining a real event there.

  • Verify a publication against its approval, not its paperwork (references/07-adversarial-review.md). Tree identity between the integration commit and the approved head; every declared postimage recomputed from the published bytes; every "unchanged" claim treated as a computation to run. Added after a publication declared four postimage receipts and only three verified: the fourth was carried forward from a paused working state that publication had since adapted, while the same document handled a different file's history correctly. Current receipts are current, superseded receipts are history, and presenting history as the present is the same defect class as release notes that describe an artifact their tag does not reproduce.
  • Authorization documents drift; diff them against their authority before they become executable (references/07-adversarial-review.md). Parallel workstreams produce divergent copies of what is authorized, and the enabling act is the moment that matters. Added after a good-faith work order authorized a materially wider scope than the owner-approved contract developed in parallel; the pre-enabling comparison caught the drift as scope, not wording.
  • A byte receipt states its algorithm and its normalization (references/07-adversarial-review.md). Two honest people can hash the same approved file and record different values: line endings rewritten at checkout, a version-control object id against a file digest, or mixed normalization inside one document. Added after a published postimage disagreed with its recorded receipt and the explanation, a receipt computed on a line-ending-rewriting checkout while the published bytes were stored normalized, was only reachable because both artifacts still existed to compare. Every receipt now names its algorithm and its normalization, and where raw and normalized digests agree, saying so rules out the class in one line.
  • Cleanup that was supposed to run against cleanup that demonstrably did (references/14-deterministic-verification.md). The shell exit-code contract already required detaching teardown from the conjunction that can skip it; it now also requires asserting the working tree is clean before the artifact is created. Detached cleanup can still fail, and a scratch file or modified harness that survives into a commit reproduces only on the machine that made it, so local runs stay green while every shared lane goes red. Completes a standing local proposal whose first half shipped earlier.
  • A suite's verdict is defined by its configured runner (references/10-maintenance-harness.md, new 9c). An ad-hoc invocation from the wrong root manufactured four plausible failures on a suite that passes under its package runner. Canonical invocations recorded beside the suite, zero-discovery treated as failed invocation, and observed ghosts recorded with their explanations so nobody re-debugs an invocation artifact as a product defect.

Documentation

  • Names the Python floor. The README said "no dependencies beyond Python 3"; the real floor is 3.12, set by tarfile.extractall's filter argument.

2026.08.22-unified.8

A provenance release. It supersedes 2026.08.22-unified.7 for distribution and changes no reference text relative to the current core.

Two defects in the unified.7 release made that tag unusable as a distribution source, both found by an independent reviewer at a consuming repository:

  • The v2026.08.22-unified.7 tag does not reproduce the core that was distributed from it. Two commits landed on the release branch after the tag and both touch the distributed core (scripts/adc.py, tests/test_adc.py). A managed install taken from the branch tip therefore carried post-tag bytes while recording 2026.08.22-unified.7 as its source version. Extracting the tag yields core digest 511dfaf51f01b2ba677bb7f421c2f19a...; the distributed bytes hash to 575383c9383dbe13521c229ab15dd571.... A version string that does not bind to specific bytes is a claim, not evidence.
  • The unified.7 notes state "It adds no new lessons," which is inaccurate. That release also carried ADC-LOCAL-015, a separately promoted new lesson adding the new-producer checklist to references/14-deterministic-verification.md. It was promoted on its own branch before the release commit and was never described in the release section.

This release states the full contents of the current core plainly:

  • Recovered repairs (from unified.7). The fourteen lessons that unified.6 promoted from truncated proposals were re-staged from their source and their reconstructions repaired across 00-conventions.md, 07-adversarial-review.md, 10-maintenance-harness.md, 11-remediation-loop.md, 15-dogfeeding-flowback.md, and assurance-contracts.md. Unchanged here; see the unified.7 section for the itemized repairs.
  • Separately promoted lesson (from unified.7, previously undisclosed). ADC-LOCAL-015 adds the new-producer checklist to references/14-deterministic-verification.md: a gate added to an audited evidence family is not done when it passes, but when the audit validates its record inside the set, the producer invalidates any standing audit before writing, and the record obeys the family's evidence canon.
  • Tooling fixes (after the unified.7 tag). scripts/adc.py now names the remedy when a proposal comparison cannot reach a merge base, instead of returning an unexplained refusal, with regression coverage in tests/test_adc.py.

Release Integrity

  • The distributed core at tag v2026.08.22-unified.8 has core digest b554a5a481b6f58caa111546f3309759412d38dc7520b8c10534a391427130de, verified by extracting the tag into a clean directory and recomputing, not by reading the working tree.
  • Consumers should install from a tag, never from a branch tip, and may compare their .adc-managed.json source_core_sha256 against the digest published above.

2026.08.22-unified.7

Erratum, added in unified.8: two claims in this section are inaccurate and are corrected there rather than rewritten here. This release also carried ADC-LOCAL-015, a separately promoted new lesson, so "adds no new lessons" describes only the repair scope. The v2026.08.22-unified.7 tag also does not reproduce the core distributed from this release; use 2026.08.22-unified.8 or later as a distribution source.

A correctness release. 2026.08.20-unified.6 promoted fourteen lessons from proposals whose multi-line fields had been truncated in staging, so their reference text was reconstructed from titles and surviving fragments. The full proposals were re-staged afterwards. This release compares the reconstructions against the restored sources and repairs what the reconstruction lost. It adds no new lessons.

Two independent audit passes produced these findings, the second run specifically to falsify the first. The second pass refuted one claim outright and narrowed two others; those corrections are reflected below.

Repaired Promotions

  • 11-remediation-loop.md: the revert-mutation baseline rule described the wrong failure. Version control cannot restore a file it does not track, so on a new unit the restoring checkout fails with an unknown-pathspec error and the mutation stays in place. The text said the checkout destroys the unit instead. The danger is a mutation that survives the revert, and the closing green run is what exposes it.
  • 11-remediation-loop.md: the surviving-mutant rule offered "a missing test or untested behavior" as its two possibilities. Those are the same thing, which made the sentence an instance of the unfalsifiable-check class this skill defines. The alternatives are a missing test or an equivalent mutant, and the equivalent-mutant response was absent entirely: the mutated code was not load bearing, so the honest close is to delete the dead branch, name which mechanism really owns the behavior, and re-prove with a load-bearing mutation. The unit is not done until one goes red.
  • 11-remediation-loop.md: hang-as-third-outcome kept the bounding requirement but lost the reason and the remedy. A hang is worse evidence than a pass because it also blocks every later proof, and the fix is to bound cleanup waits downstream of a mutated safety action and surface expiry as a typed failure.
  • 11-remediation-loop.md: the guard-case rule lost its placement. A guard belongs in the finding's own smallest-safe-step rather than in follow-up work, must cover the form the change newly catches rather than one that already worked, and a probe an author ran once is not a guard because it does not run again.
  • 07-adversarial-review.md: three of the five field-observed shapes of the unfalsifiable-check class had been replaced by three plausible but unobserved ones. The observed shapes are restored. Two obligations were missing: naming the class requires sweeping the whole verification surface, because a remediation written after the class is named can introduce fresh instances of it, and a documentation restatement must cite the probe that proves it, which is the cheap discriminator between a restatement and an unverified claim hiding among verified ones.
  • assurance-contracts.md: the isolation-claim rule downgraded the claim to inferred when a probe cannot run but never required the gate to fail. A probe that tests nothing is indistinguishable from a passing probe, so silence must not score as success.
  • assurance-contracts.md: the self-certification rule kept the general defect and lost both practical traps: scope the scan to the whole document, because a live verdict often sits in a different section than the one a first replacement checks, and distinguish a live claim from accurate history so closing a check never requires deleting true history.
  • 00-conventions.md: audited-set evidence defined the claim but omitted its ordering. A producer record written after an audit attempt is unaudited however green its own run was, and a producer writing new evidence must invalidate any standing audit first.
  • 10-maintenance-harness.md: environment contention lost the requirement to name the holder before proposing a timing remedy, and to record a required tool exclusion beside the gate as an environmental prerequisite the repository cannot enforce from the inside.
  • 10-maintenance-harness.md: audited dependency state lost the rule that every restore goes through the reviewed path, leaving only the no-restore flag and the hash gate.
  • 15-dogfeeding-flowback.md and scripts/adc.py: the reference opened by telling readers to anchor identity to what a repository cannot casually change, while the rest of the same paragraph and the shipped code correctly do the opposite. Forks share root commits by design, so anchoring identity there would accept an upstream repository's calibration inside every fork of it. Both surfaces now state the same rule: the remote is the exclusivity signal and keys the binding, root commits explain a mismatch without overruling it, and a root-commit mismatch is the stop condition. Binding behavior is unchanged.

Deterministic-First Contract

  • 14-deterministic-verification.md: the shell exit-code contract covered pipelines and not conjunctions. The composition that collapses a gate to a one-line result is itself a trust boundary. A pipeline reports its last stage, so a verdict piped into a summarizer is discarded; a conjunction short-circuits, so cleanup and revert steps chained behind a failing gate never run. The two compose into a worse case, where masking a failure lets the chain proceed and report success with the safety step apparently confirmed. One idiom loses the verdict and the other loses the safety step, so no single fix covers both.

Release Evidence

  • Adds normalize_pdf_bytes and normalized_pdf_sha256 to scripts/adc.py, and normalized_pdf_sha256 to the brief's provenance. A print-to-PDF engine restamps /CreationDate and /ModDate on every render, so pdf_sha256 identifies one artifact and can never be reproduced. The normalized digest is the reproducibility claim, and two independent renders of this brief on different days now produce the same normalized digest. Both remain integrity checks over committed bytes: neither proves the PDF was regenerated from the current HTML, and only an actual re-render does. That gap is recorded rather than papered over with a check that cannot fail.
  • Fixes chip crowding in the evidence-language rows of the brief and the website. The verified, inferred, and unknown chips sit in a grid track sized for two-digit pass numbers, and a fixed track does not grow, so they overflowed into the body text. This fix was authored before 2026.08.20-unified.6 shipped but was merged into a branch that had already merged to main, so it never reached a release.
  • Removes both fully promoted proposals from the inbox. A clean distribution archive previously failed validate --mode distribution because the runtime-only inbox shipped inside it.

Hardening

  • Bounds the untrusted-fork history that the proposal-intake workflow downloads onto a privileged runner. It checked the candidate out with fetch-depth: 0, which lets a fork choose how much work the runner does. A bounded depth keeps the merge base present for the normal case. It does not degrade gracefully outside that case: validate-incoming compares with a three-dot diff and has no two-dot fallback, so a branch point older than the window leaves the candidate shallow with no merge base and validation fails closed. Like any workflow change, this is unverified until it runs on the default branch. The identical change to the efficiency-ledger workflow followed separately, because that workflow triggers on edits to itself and the ledger validator had to reach the default branch before it could accept a change combining that file with anything else.
  • Fixes that validator. validate-ledger-pr accepted a receipt-free change only when the changeset was exactly .github/workflows/efficiency-ledger.yml, so it refused every legitimate combined change, including one that also edits the sibling intake workflow. It now passes any change that adds no receipt and touches neither the ledger nor either generated summary, and still refuses ledger data or a summary that moves without a new receipt. --allow-workflow-maintenance is accepted for compatibility and no longer consulted, because a deployed workflow still passes it. Found by this release's own pull request failing CI.
  • Replaces the one non-ASCII character in the shipped skill, an arrow in the system-map template, against this skill's own ASCII-only writing rule.

Tests

  • 125 tests, of which 114 pass and 11 skip on this host. Adds a fixture-pair regression proving PDF normalization collapses timestamp differences while preserving content differences, which goes red if the normalization is reduced to an identity function, and extends the release-surface test to the normalized digest.

2026.08.20-unified.6

Promoted Lessons

  • Promotes the eight verification lessons from proposal flowback-0a6794d23314 and the six mutation-discipline lessons from proposal flowback-52ed79f5435b into the references: unfalsifiable checks as a named finding class with a falsifying-input test (07-adversarial-review.md), guard cases for widening fixes and gate-named fix sets plus a revert-mutation proof discipline covering committed baselines, hang-as-third-outcome, and surviving-mutant diagnosis (11-remediation-loop.md), isolation-property probes and the self-certification anti-pattern (assurance-contracts.md), harness environment contention and audited dependency-lock state (10-maintenance-harness.md), audited-set evidence as its own claim (00-conventions.md), record-equality and child-context handoff cautions in gate authoring (14-deterministic-verification.md), and per-component repository-identity reporting (15-dogfeeding-flowback.md plus adc.py, which now names whether the remote identity or the root commits failed a binding check while remaining fail-closed).
  • Both source proposals were staged with truncated multi-line fields (see the fix below), so the promoted text was reconstructed from titles, surviving fragments, and proposed targets. Source repositories should re-stage any lesson whose promoted form lost substance.
  • Promotes the determinism lesson queued by a calibrated repository: ordering keyed on a parsed value is not total over raw representations; canonical comparators tie-break on the raw representation and determinism suites include a fixture pair of distinct representations of one parsed value (14-deterministic-verification.md, 07-adversarial-review.md).
  • Merges five field-tested reference sections from the maintainer's working branch: exclusion and single-owner claims need live second-claimant probes and untested else branches fail closed (07-adversarial-review.md), history rewrites strand cited identifiers (09-artifact-gc.md), self-matching process selectors (10-maintenance-harness.md), characterizing components outside the repo and sweeping text references after moves (11-remediation-loop.md), and capability-restricting build flags (14-deterministic-verification.md).
  • Removes both fully promoted proposals from the pending inbox; Git history retains the review record.

Tooling

  • Fixes flow-back staging truncation: parse_candidates now preserves wrapped continuation lines in candidate fields instead of keeping only each field's first line, with a regression test. Previously staged public proposals carried first-line-only fields.
  • Adds scripts/work_receipt.py: a stdlib-only helper that sums token usage, tool calls, and the covered time window from agent-session transcripts and prints a measured WORK line for a pull-request body. Documented in 16-community-feedback-and-efficiency.md; measured numbers and human-equivalent estimates never blend.
  • Expands the deterministic suite to 122 tests, including the continuation-line regression, per-component binding detail, and four work-receipt cases.

Release Surfaces

  • Adds the README banner, updates every release surface to 2026.08.20-unified.6, and repairs the README version line that 2026.08.18-unified.5.1 failed to bump (its release predated running the release-surface test; the test caught it after the fact).

2026.08.18-unified.5.1

License Provenance

  • Ships the FSL-1.1-MIT license text inside the distributed core (anti-dark-code/LICENSE.md) so every managed install carries the license with the software, as the license's Redistribution clause requires. Root LICENSE.md remains the repository copy; the core copy is byte-identical.
  • No reference, template, script, or policy changes from 2026.08.09-unified.5.

2026.08.09-unified.5

Evidence and Assurance Contracts

  • Adds a repository-neutral assurance-contract reference for claim closure, finalization, branch activation, hardware capability measurement, nested recovery, transactions, concurrency, subprocesses, native ABI boundaries, lockfiles, provenance, releases, signing, compatibility, UI evidence, providers, and hot paths.
  • Requires terminal coverage labels and explicit dependency, shipping, and end-to-end reachability evidence instead of treating reference search or project inclusion as runtime proof.
  • Tightens negative-search evidence, cleanup safety, self-review of freshly shipped high-risk fixes, calibrated detectors, producer exit-code handling, and shared-worktree orchestration.

Deterministic Gate Identity

  • Adds bounded, reviewed, non-sensitive per-gate environment overlays and an optional sparse-environment mode.
  • Records only environment key names and an opaque execution fingerprint in dry runs, summaries, and failure packets; raw overlay values are omitted and scrubbed from retained child output.
  • Refuses secret-like overlay variable names and bounds variable count and value size.
  • Binds conventional gate proposals to the exact manifest files that produced them and invalidates approval when those files change.
  • Prevents punctuation-normalized package script names from colliding and refreshes stale repository profiles when writing a new plan.
  • Preserves approved repo-owned or auto-discovered gates across bounded profile refreshes when their exact source binding still verifies, while invalidating changed bindings and disappeared unbound auto-discovered gates.
  • Makes bootstrap dry runs preview bounded gate changes and any owner-confirmation reset without writing calibration.
  • Ships a subtree .gitattributes rule so checksummed managed installs retain LF bytes on Windows checkouts.

Mutation and Regression Guidance

  • Promotes the bounded mutation-pilot, absolute-count reporting, presentation-surface separation, stale-cache detection, and separate test-typechecking lessons from the incoming proposal inbox.
  • Expands the deterministic suite to 116 tests, including regressions for environment privacy and execution, exact-bound gate preservation and invalidation, bounded-profile omissions, canonical fresh/migrated bootstrap previews, package-runner replacements, linked-source and duplicate-gate rejection, managed-install LF stability under core.autocrlf=true, conventional-source staleness, gate-id collisions, profile refresh, public proposal intake, workflow-only contribution handling, proposal diagnostic escaping, proposal-local public ids, immutable quarantined proposals, qualified-pair controls, canonical summaries, release-surface/PDF provenance synchronization, wrapper help, adapter/counter-semantics separation, and opt-in efficiency receipts.

Public Proposal Intake

  • Adds an explicit fork-and-pull-request path plus a no-Git issue form for community lessons, while keeping the inbox an untrusted quarantine that is never executed, installed, shipped, or promoted automatically.
  • Requires shared-inbox staging to use public mode. The generator withholds the source commit, removes known repository-name/path variants, assigns proposal-local ordinal ids, permits only repo-agnostic or reviewed generic repo-shape scopes, redacts credential-like values and raw commit ids, and fails closed when the bounded public format is invalid.
  • Adds content-hash, canonical-structure, path, field, pre-read size, control-character, all-raw-HTML, URI, credential, link, terminal-safe diagnostic, and one-file-diff validation.
  • Adds read-only pull_request_target validation that executes workflow and validator logic from the trusted base revision, checks out fork content only as data, and never runs candidate scripts. The introducing pull request requires manual validation because a new workflow does not run until it exists on the default branch.
  • Removes the fully promoted proposal inbox from the pending branch so proving-repository names, commit ids, and local evidence paths do not remain in the live quarantine. Git history retains the review record.

Honest Efficiency Evidence

  • Adds an offline, standard-library receipt helper for explicit host-reported numeric usage, controlled same-provider/model/adapter/counter-semantics/task comparisons, privacy-stripped public export, strict validation, and deterministic aggregation.
  • Keeps actual usage separate from savings, requires matching adapter/counter semantics, reporting month, settings/tools/fixture/oracle digests, and fresh same-contract passing outcomes before computing a token delta, retains negative results, and never combines unlike provider/model/adapter/usage-semantics/task-class strata.
  • Forces LF for managed-core and content-hashed public data, compares generated summaries as canonical bytes, and ignores local run, receipt, and flow-back artifacts at their point of creation.
  • Adds a public JSON schema, empty ledger and honest initial summary, trusted-base receipt PR validation, exact mirrored website data, and an opt-in measurement reference. No prompts, responses, paths, repository/user ids, or raw host logs are collected.
  • Updates the README, contribution guide, migration guide, all sixteen field-brief passes, PDF, and GitHub Pages site to .5; adds PDF/source hash provenance and a release-surface synchronization test; historical exact savings remain explicitly unmeasured until controlled public pairs exist.

2026.08.06-unified.4

Real-Repo Write and Execution Hardening

  • Verifies and fixes repo-local symlink-blind writes. Install, calibration, adapter, run-artifact, and flow-back paths now fail closed on symbolic-link or Windows-junction components and nested link-like entries.
  • Keeps user-level host-discovery aliases compatible with a shared universal core while requiring real repo-local managed directories.
  • Uses atomic file replacement for managed-core copies, calibration-template copies, and staged flow-back proposals.
  • Treats invalid or link-contaminated calibration as repair-or-quarantine work instead of allowing --accept-unbound-calibration to override it.
  • Makes blocked gate plans return exit code 2 in dry-run mode as well as execution mode.
  • Launches each executed gate in a separate process group and makes a best-effort process-tree termination on timeout.
  • Records timeout termination details in bounded failure packets.
  • Makes auto validation treat the canonical repo-local path as installed state even when that path is an unsafe symlink, so the validation error cannot be hidden by resolving to the shared target.

Scan Isolation and Validation Modes

  • Excludes .agents/skills, .claude/skills, .gemini/skills, and .codex/skills from repository profiling, source identity, and changed-slice routing.
  • Detects legacy .codex/skills/anti-dark-code/calibration alongside the other supported legacy locations.
  • Adds explicit distribution, universal, installed, and auto validation modes.
  • Keeps distribution validation strict against incoming/, repo calibration, managed-install metadata, symbolic links or junctions, __pycache__, and .pyc artifacts.
  • Lets a deployed universal core validate and run its unit suite with staged flow-back proposals and without outer distribution documents.
  • Validates installed repo copies through .adc-managed.json, managed-core hashes, the core digest, source metadata, local calibration JSON, calibration link safety, and repository binding.
  • Allows ordinary live-core flow-back proposals while rejecting symlinked or junction-backed incoming/ inbox entries.
  • Excludes .codex/skills from Git worktree identity as well as content scans.

Migration and Regression Coverage

  • Updates repository-neutral migration guidance for symlinked legacy layouts, layered validation, blocked dry-run status, installed-copy integrity, and process-tree timeout behavior.
  • Preserves strict package-artifact checks without requiring python3 -B.
  • Adds regression tests for blocked dry runs, installed-copy validation, universal-core incoming/ isolation, distribution rejection of runtime inboxes, repo-local link refusal, linked flow-back destinations, sibling-skill isolation across profiling and change routing, and timeout process-tree termination.

2026.08.06-unified.3

Cross-Repo Calibration Isolation

  • Adds SOURCE-SCOPE.json so installers can identify a clean universal source core.
  • Adds calibration/repo-binding.json with a hashed one-repository identity.
  • Blocks unbound legacy calibration until --accept-unbound-calibration is explicit.
  • Blocks mismatched calibration until a reviewed --rebind-calibration is explicit.
  • Records prior hashed repository ids when a binding is deliberately changed.
  • Refuses deterministic gate execution and flow-back from unbound or foreign calibration.
  • Verifies that a flow-back parent is a clean universal core.
  • Reports legacy calibration locations without silently merging competing stores.
  • Resets migrated or rebound gates to disabled and proposed, and clears global execution confirmation.
  • Uses canonicalized Git remotes for stable binding across a first commit and ordinary SSH-to-HTTPS remote changes.

Installation Source Hardening

  • Blocks unmarked, repo-local, and repo-calibrated installation sources by default.
  • Adds --allow-unsafe-source for advanced reviewed recovery only.
  • Never copies top-level source calibration, even when the recovery override is used.
  • Excludes the shared incoming/ proposal inbox from repo-local managed copies.
  • Rejects contaminated calibration templates even under the source override.
  • Validates that template bindings are unbound and template gates are disabled and unapproved.
  • Preserves nested calibration templates in managed repo copies while still excluding top-level repo calibration and proposal inboxes.
  • Rejects a shared flow-back parent that carries a repo-local managed-install manifest.

Migration and Documentation

  • Rewrites MIGRATION.md for any old, partial, mixed, model-specific, or repo-customized installation.
  • Makes same-repo fact migration, gate conversion, host consolidation, rollback, and multi-repo safety explicit.
  • Removes project-specific migration guidance from operational references.
  • Clarifies that the universal core flows downward, repo calibration stays local, and only reviewed general proposals flow upward.
  • Generalizes personal-path validation beyond two hardcoded developer paths.

Test Harness Fix

  • Fixes the unit-suite packaging false positive caused by the suite's own runtime __pycache__ files.
  • The suite now validates a clean temporary package copy and runs with ordinary python3.
  • Strict package validation still rejects packaged __pycache__ directories and .pyc files.
  • Expands deterministic coverage for clean-source enforcement, source-calibration exclusion, binding creation, stable remote identity, unbound migration, migration gate resets, mismatch rejection, explicit rebind, template completeness, template contamination, foreign-gate refusal, managed-parent refusal, and neutral operational guidance.

2026.08.06-unified.2

Deterministic Gate Hardening

  • Detects npm, pnpm, Yarn, or Bun for package-script gates.
  • Creates generated gate suggestions disabled and marked proposed.
  • Requires each enabled gate to be marked approved before execution.
  • Resets global execution confirmation when generated gates are added, changed, or become stale.
  • Fingerprints package-script definitions and blocks a previously approved gate when the underlying script changes.
  • Includes committed, uncommitted, and untracked files in changed-slice routing.
  • Retains pattern-redacted gate logs and redacts command fields in failure packets.
  • Adds microsecond run ids and gate-definition hashes to avoid artifact collisions.

Calibration and Probe Hardening

  • Tracks commit and worktree status for profile freshness.
  • Migrates pre-install fallback calibration into the canonical repo-local skill.
  • Uses calibration templates from the selected source skill during installation.
  • Prunes installed skill trees during repo enumeration.
  • Reduces false generated-output and security signals from ordinary export and tokenizer code.
  • Adds stricter package, capability-catalog, path, and generated-artifact validation without creating __pycache__ files.
  • Expands the deterministic unit suite from 8 to 15 tests.

2026.08.06-unified.1

Unified

  • Replaced separate Claude and Codex core trees with one model-neutral skill.
  • Preserved optional OpenAI metadata under agents/openai.yaml.
  • Added host addenda for Claude Code, Codex, Gemini CLI, and generic harnesses.
  • Added a thin Claude repo adapter that points to the canonical .agents/skills copy.

Added

  • Pass 13: calibrated local mode.
  • Pass 14: deterministic verification planner.
  • Pass 15: dogfeeding and proposal-only flow-back.
  • Machine-readable catalog for all 20 verification capabilities.
  • Repo-type adaptations for service/web, frontend, monorepo, library/SDK, game/simulation, mobile/native, infrastructure, AI/data, CLI/desktop, small/new, and mixed repos.
  • Repo-owned calibration templates.
  • Managed-core installer with checksums and conflict detection.
  • Bounded deterministic repo probe.
  • 20-capability planner and confidence ladder.
  • Exact gate schema, dry-run runner, owner-confirmation gate, real exit-code capture, local logs, and bounded failure packets.
  • Content-hashed flow-back proposals and parent inbox staging.
  • Skill validator and unit tests.

Incorporated from Repo-Local Dogfeeding

  • calibration-first operation
  • fresh-surface re-audit avoidance
  • finding-class verification effort
  • exact gate reuse and machine constraints
  • canonical-rule delegation across projections and adapters
  • aggregate canaries for emergent behavior
  • output-count probes and configuration unwiring
  • aggregation-semantics review
  • chunking metamorphic tests
  • dependency graph enforcement
  • observational diagnostics and replayable UI monkey failures

Changed

  • Updated preflight, steering, architecture, slicing, adversarial review, scenario stress, maintenance, remediation, and orchestration references to use deterministic planning and calibration.
  • Updated templates with capability ids, confidence levels, exact gates, failure packets, replay memory, rule authority, and freshness triggers.

Safety

  • No automatic dependency installation.
  • No repo-code execution during install, bootstrap, or probe.
  • Gate execution requires both --allow-exec and recorded owner confirmation.
  • Repo-local flow-back cannot directly mutate shared core files.