Repository navigation
vnext: demand-driven support routing (#61) - #66
Conversation
An attributing failure on a target task now routes a scoped substrate probe before the mission continues — evaluated missingFunctions ∩ providesFunctions mints a SUPPORT_DEMAND planner intent, served by a support-purpose task, bounded per (target, function) pair and self-cancelling when the target recovers on its own. Support evidence is remediation context only: support_attempt is a registered event type outside the milestone-bearing ATTEMPT_TYPES, so probes mint nothing on either the substrate or the target capability. - evaluators: contracts declare attributesFunctions; choice misses attribute declared requiredFunctions, free-text misses stay empty - bind: missingFunctions stamped ⊆ task.requiredFunctions (forged provenance throws); planner re-filters + requires observed, verified, attributing evidence - planner: deriveSupportDemands replays the canonical log — issue / consume / cancel / bounded re-issue — support caps excluded from all normal intents (no free-run) - runner: support_demand maps only to support tasks; unservable demands skip non-fatally - contracts: 'support' purpose + support_attempt emission validated; probes must elicit a response in a practiced family - curriculum gate: support declarations must cover a mission-required function, own a probe, carry no claim-bearing tasks, hold one role - fixtures: meet_at_a_time activates the route — the number-catch substrate (identify_spoken_number) probes through one support task - ui: honest 'Luyện phần nền' frame; support caps excluded from progress lines; commit stamps evaluator attribution Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Independent adversarial audit of PR #66 found five HIGH defects in the Mission 005 support-routing layer, all rooted in capability-granular lifecycle bookkeeping instead of (cap, function, episode): - lifetime support ban: the per-pair cycle bound accumulated across the whole event history — a recovered-then-forgotten substrate could never re-route. Now demonstrated recovery (verified success on a task that requires the function) closes the episode and re-arms the budget. - provider-wide consume: one support_attempt cleared every pending demand on the cap. Now a probe consumes only demands whose function its own requiredFunctions test. - capability-scoped probe pick: the runner served any support task on the cap. Now candidates are filtered to probes covering the demand's missingFunction; uncovered demands skip non-fatally. - capability-wide cancel: any success on the target cap retired all its demands. Now only a success that exercises the missing function cancels it. - gate holes: provided-but-uncovered functions and probes testing non-provided functions both passed. The gate now proves per-function servability and probe provenance. Also: event-id dedup in deriveSupportDemands for replay parity. tests/vnext-audit-kernel.test.mjs (25 checks) encodes the desired semantics — it stood red on every defect pre-fix and is the permanent regression gate. verify:full green. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Mission 006 — Independent adversarial audit (control-room review)Self-review could not certify this PR — an independent audit pass attacked the kernel before merge. Result: 5 HIGH defects confirmed in the support-routing layer, all fixed on this branch. Confirmed (reproduced in
|
| # | Defect | Root |
|---|---|---|
| A | Lifetime support ban — cycles accumulated per cap|fn over the full log; a recovered-then-forgotten substrate could never re-route |
bound now resets on demonstrated recovery |
| B | Provider-wide consume — one support_attempt cleared ALL pending demands on the cap |
consume requires the probe's requiredFunctions to cover the demand's missingFunction |
| C | Capability-scoped probe pick — demand for fn_b was served probeA(fn_a) | runner filters candidates by demand.missingFunction; uncovered demands skip non-fatally |
| D | Capability-wide cancel — a success on delayed.hear (no identify_spoken_number) cancelled the number demand |
cancel only when the succeeding task requires the missing function |
| I | Gate holes — provided-but-uncovered functions and ghost-function probes passed | gate now proves per-function servability + probe provenance |
Disproved / verified safe
Carrier-origin demands are INTENDED AND SAFE (task-scoped attribution, mission-declared providers only). No mastery laundering path found: support_attempt mints zero milestones on any cap; stale revisions, forged/malformed missingFunctions, duplicate delivery, cross-learner evidence, and attemptId-reuse all fail closed. Due retrieval outranks pending demands; multi-demand ordering is canonical.
F (choice attribution attributes all declared functions) is a documented MEDIUM assumption — bounded to declared functions and mission-declared providers.
npm run verify:full green at 8762f23 — typecheck, all unit suites, build, 26 browser groups (both viewports, support route re-verified), both Firestore emulator suites.
Full audit report: missions/006-kernel-audit/REPORT.md
Summary
Implements issue #61 — demand-driven support routing in the vNext kernel:
target miss → missingFunctions ∩ providesFunctions → SUPPORT_DEMAND → scoped probe → return to targetattributesFunctions; a choice miss reports its declaredrequiredFunctionsas missing, free-text misses stay empty (unknown cause never routes).missingFunctionsbounded torequiredFunctions; the planner re-derives demands from the canonical log — verified + observed + attributing only.SUPPORT_DEMAND(with target/task/event provenance), deterministic provider pick, per-pair cycle bound (policy.supportDemand.maxCyclesPerPair), self-cancelling on target recovery, support caps excluded from every normal intent — no free-running.support_attemptis a real event type outside the milestone-bearingATTEMPT_TYPES— probes mint zero claims on the substrate or the target.meet_at_a_timeactivates the documented route (identify_spoken_numberprobe off the clock-time comprehension tasks).Test plan
tests/vnext-support-demand.test.mjs— 13 checks (free-run, forged/unobserved evidence, consume/cancel/bound, replay determinism, learner isolation, unservable-demand non-fatality, gate rejections, UI end-to-end)/vnext/?mission=mission.meet_at_a_time: wrong choice → probe interposes once → mission resumesnpm run verify:fullPASS — typecheck 123 files, all suites, build, 26 browser groups, both Firestore emulator suitesswe:verifyPASS @1c9ed40, mission DONE —missions/005-demand-support-routing/REPORT.mdMission report with the full adversarial matrix and known risks:
missions/005-demand-support-routing/REPORT.md.Generated with Devin