Skip to content

Implement deterministic ProductionUnit lifecycle and startup safety - #636

Merged
drevendev merged 23 commits into
masterfrom
zen/issue-635-production-unit-lifecycle
Sep 22, 2026
Merged

drevendev merged 23 commits into
masterfrom
zen/issue-635-production-unit-lifecycle

Conversation

@drevendev

@drevendev drevendev commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Closes #635

Achieved outcome

Implements bounded M4 REQ-PRODUCTION-007: one mutable live ProductionUnit lifecycle status initialized from immutable seed status; deterministic Phase-14 lifecycle review with explicit tick-N+1 activation/removal; PLANNED startup and viable MOTHBALLED recapitalization through real INVESTMENT goods only; exact owner-to-unit home-currency funding; explicit current-tick M4 ownership/production legal-eligibility readiness from the existing read-only State policy fixture; configured ACTIVE→MOTHBALLED, MOTHBALLED→ACTIVE/CLOSING, and CLOSING→retirement behavior; live-status gating in planning/execution/capital formation; and fail-closed retirement/evidence validation. MOTHBALLED recapitalization does not re-enable normal hiring, INPUT procurement or production. No M5+ FX, credit, mutable fiscal institution, or trade behavior is introduced.

Tested revision

2df457f1f68cfae69dfffe638d0a664af04f4cdc — current exact producer head after repairing SLOPSTER's legal-eligibility finding. Exact-head CI #1485 passes retained .NET restore/build/test, TypeScript install/typecheck/full tests/build, and policy guard; mergeability is green.

Changed artifacts

  • docs/spec/IMPLEMENTATION_STATUS.md — generated implementation coverage updated to match the authoritative ledger.
  • docs/spec/implementation_status.csv — records REQ-PRODUCTION-007 as implemented by REQ-PRODUCTION-007: Phase-14 ProductionUnit lifecycle and startup safety #635/Implement deterministic ProductionUnit lifecycle and startup safety #636 with merge SHA intentionally blank before integration.
  • src/config/fixtures/baselineScenario.ts — makes the M4 State policy fixture explicitly permit baseline lifecycle ownership/production eligibility instead of relying on a hidden default.
  • src/config/scenarioDefinition.ts — exposes the explicit read-only M4 lifecycle ownership/production eligibility fixture on the existing State production-policy boundary.
  • src/simulation/capitalFormation.test.ts — makes Phase-12 regression fixtures opt into the live ACTIVE lifecycle authority explicitly.
  • src/simulation/capitalFormation.ts — permits capital formation from real INVESTMENT stock for live ACTIVE, PLANNED and MOTHBALLED units while keeping CLOSING excluded.
  • src/simulation/index.ts — exports lifecycle/startup APIs and live status type.
  • src/simulation/pendingTransitions.ts — preserves and filters explicit ProductionUnit lifecycle transitions.
  • src/simulation/productionExecution.test.ts — updates non-ACTIVE regression evidence to set live status rather than mutating immutable seed status.
  • src/simulation/productionExecution.ts — consumes mutable live status rather than immutable seed status.
  • src/simulation/productionPlanning.test.ts — updates non-ACTIVE regression evidence to set live status rather than mutating immutable seed status.
  • src/simulation/productionPlanning.ts — consumes live status; admits bounded PLANNED startup and viable MOTHBALLED recapitalization INVESTMENT while keeping normal labor/input/production demand at zero.
  • src/simulation/productionStartupPlanning.test.ts — covers PLANNED startup plus viable MOTHBALLED recovery from below minimumStartupCapital, cadence, live/seed divergence, CLOSING isolation and Phase-12→Phase-14 causal ordering.
  • src/simulation/productionStartupPlanning.ts — plans bounded PLANNED startup / viable MOTHBALLED recapitalization INVESTMENT demand from opening cash and prior-close prices, including same-tick depreciation safety.
  • src/simulation/productionUnitLifecycle.test.ts — covers genesis status, readiness/N+1 activation, explicit legal denial/allow controls, missing-policy fail-closed behavior, consecutive counters/reset/reactivation/closing, safe retirement, exact owner-funding conservation including sub-epsilon overdraw rejection, insertion-order determinism and evidence tampering.
  • src/simulation/productionUnitLifecycle.ts — deterministic Phase-14 lifecycle/readiness engine, including current controller-State ownership/production legal eligibility, authoritative evidence re-derivation, N+1 Phase-1 activation/removal, retirement safety, and exact zero-sum owner funding with no epsilon overdraft allowance.
  • src/simulation/productionUnitLifecycleContext.ts — typed immutable Phase-14 lifecycle evidence on TickContext.
  • src/simulation/productionUnitState.ts — defines and validates the sole mutable runtime lifecycle status.
  • src/simulation/worldState.ts — initializes live status from seed status and defines pending lifecycle transition state.

Acceptance criteria

  • Exactly one mutable runtime lifecycle status (PLANNED|ACTIVE|MOTHBALLED|CLOSING) is initialized from immutable seed status.
  • Non-ACTIVE normal labor/input/production is disabled; PLANNED startup and viable MOTHBALLED recapitalization may submit only bounded INVESTMENT demand.
  • PLANNED readiness requires real capital/infrastructure/owner/cash/resource conditions plus explicit current M4 ownership/production legal eligibility, and activation is queued for tick N+1 only.
  • MOTHBALLED reactivation requires the same current legal eligibility; missing controlled-Region fixture evidence fails closed.
  • MOTHBALLED units can recover from depreciation below minimumStartupCapital through real investment goods without bypassing lifecycle reactivation reviews.
  • Startup/recapitalization procurement respects the canonical investment-review cadence and targets enough pre-depreciation capital to survive same-tick Phase-12 depreciation.
  • Owner funding is an exact zero-sum transfer in the Region settlement currency; any request above available owner cash is rejected even within moneyEpsilon.
  • Configured consecutive lifecycle reviews gate mothballing, reactivation, and closing, with reset behavior on contradictory evidence.
  • CLOSING retirement rejects residual wallet/inventory/capital/pending lifecycle references and removes only after safe clearance.
  • Planning, execution, and capital formation consume live status rather than immutable seed status.
  • Phase-14 persistence re-derives authoritative evidence and rejects tampered/wrong-unit/replayed evidence; review order is deterministic.
  • Sensitive lifecycle/startup/recapitalization/legal/funding/retirement/seed-divergence/cadence regressions are included.
  • Exact-head required TypeScript/.NET/policy/mergeability gates are green before fresh SLOPSTER handoff.

Checks

SLOPSTER correctly refused 112eecbe98dc74f3c971cf3de5caf728fae0877d for missing MOTHBALLED recapitalization and epsilon-tolerant owner overdraw; cf733bba6594eb2cc6ce298159ecf9072455cb09 repaired both. SLOPSTER then correctly refused cf733bba... because Phase-14 readiness still lacked the existing contract's effective ownership/production legal gate.

Exact head 2df457f1f68cfae69dfffe638d0a664af04f4cdc repairs that remaining finding by reading explicit M4 lifecycle law outputs from the effective controller State's existing read-only production-policy fixture. Controlled Regions fail closed when that fixture/evidence is missing. Focused regressions deny otherwise-ready PLANNED activation and MOTHBALLED viable-review accrual when ownership or production eligibility is false, and retain eligible positive controls. Exact-head CI #1485 passes retained .NET restore/build/test, TypeScript npm ci, typecheck, full tests and build, and policy guard. mergeability is success.

Assumptions and unknowns

The current M4 schema has no autonomous owner strategy, mutable fiscal-law institution, or separate startup-cash-floor field. This implementation therefore uses the existing minOperatingCash as the M4 operating-cash readiness floor and the existing State m4ProductionPlanning fixture as the deterministic read-only source for lifecycle ownershipAllowed / productionAllowed query outputs. The fixture is deliberately coarse for M4; M6 may back the same pure-query semantics from canonical mutable institutions without changing Phase-14 readiness. MOTHBALLED recapitalization is limited to units whose current margin signal clears the configured reactivation margin threshold and only fills the real-capital gap required by the existing reactivation readiness gate.

Highest-risk area for review

Lifecycle authority and causal timing: effective controller-State legal eligibility, fail-closed missing policy evidence, live-vs-seed status, MOTHBALLED recapitalization without normal operation, Phase-14 N+1 transitions, exact money conservation at the owner-funding boundary, and fail-closed safe retirement.

Remaining gate

Fresh SLOPSTER independent judgement of exact head 2df457f1f68cfae69dfffe638d0a664af04f4cdc. This IMPLEMENT run does not merge the PR.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • docs/spec/implementation_status.csv
  • src/simulation/capitalFormation.ts
  • src/simulation/index.ts
  • src/simulation/pendingTransitions.ts
  • src/simulation/productionExecution.ts
  • src/simulation/productionPlanning.ts
  • src/simulation/productionUnitState.ts
  • src/simulation/worldState.ts

From .zen/edits/issue-635-lifecycle.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • docs/spec/IMPLEMENTATION_STATUS.md
  • src/simulation/pendingTransitions.ts
  • src/simulation/productionPlanning.ts
  • src/simulation/productionUnitLifecycle.ts
  • src/simulation/worldState.ts

From .zen/edits/issue-635-lifecycle-fix.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/productionStartupPlanning.test.ts
  • src/simulation/productionStartupPlanning.ts

From .zen/edits/issue-635-startup-depreciation.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/productionStartupPlanning.test.ts
  • src/simulation/productionStartupPlanning.ts

From .zen/edits/issue-635-startup-cadence.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/productionUnitLifecycle.ts

From .zen/edits/issue-635-retirement-tolerance.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/productionStartupPlanning.test.ts
  • src/simulation/productionStartupPlanning.ts
  • src/simulation/productionUnitLifecycle.test.ts

From .zen/edits/issue-635-typecheck.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/capitalFormation.test.ts
  • src/simulation/productionExecution.test.ts
  • src/simulation/productionPlanning.test.ts
  • src/simulation/productionStartupPlanning.test.ts

From .zen/edits/issue-635-ci-regressions.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

@drevendev
drevendev marked this pull request as ready for review September 22, 2026 06:30

Copy link
Copy Markdown
Owner Author

Producer handoff — exact head 112eecbe98dc74f3c971cf3de5caf728fae0877d

Issue #635 / REQ-PRODUCTION-007 is ready for independent SLOPSTER judgement.

The interrupted implementation was recovered rather than duplicated. The previous exact head exposed eight TypeScript regressions: stale tests were mutating immutable seed.status or inheriting a MOTHBALLED baseline fixture, and the startup test selected a recipe with no investment-good conversion. Those regressions are repaired on this exact head by making tests use the live lifecycle authority and selecting an investment-capable tools-craft startup fixture.

Exact-head evidence is green:

  • retained .NET restore/build/test: PASS;
  • TypeScript npm ci, typecheck, full test suite, build: PASS;
  • policy-guard, including generated implementation-status/ledger checks: PASS;
  • mergeability: success/clean.

Please judge the exact head 112eecbe98dc74f3c971cf3de5caf728fae0877d, especially lifecycle authority and timing: live-vs-seed status, PLANNED startup investment without same-tick production authority, Phase-14 N+1 transitions, owner-funding conservation, and fail-closed safe retirement. Producer will not merge this revision.

@drevendev drevendev left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Exact-head content review for 112eecbe98dc74f3c971cf3de5caf728fae0877d.

This is a COMMENT, not the formal scheme/8 verdict: the PR author and authenticated reviewer are both drevendev, while this repository assigns the formal verdict to SLOPSTER (andy-zen-dev).

I found two blocking contract defects despite the exact-head required checks being green:

  1. The MOTHBALLED recapitalization path required by REQ-PRODUCTION-007 is missing. Handoff/05 §19 explicitly says that eligible MOTHBALLED expansion is activated by REQ-PRODUCTION-007 once reactivation eligibility exists. On this head, planProductionUnitPhase2() emits startup INVESTMENT intents only for PLANNED; every MOTHBALLED unit receives zero investment intents. planOneUnit() in capitalFormation.ts likewise permits capital formation only for ACTIVE | PLANNED. But Handoff/05 §25 requires installedCapital >= minimumStartupCapital for MOTHBALLED→ACTIVE, while Phase 12 still depreciates MOTHBALLED capital. A mothballed unit that falls below the startup-capital threshold therefore has no canonical way to recapitalize and can never satisfy its reactivation gate even after margin/infrastructure/cash recover. Please add the bounded MOTHBALLED investment/capital-formation path required by §19 (without re-enabling normal hiring/input procurement/production) and a regression covering recovery from below minimumStartupCapital.

  2. Owner funding is not exactly zero-sum at the cash boundary. applyProductionUnitOwnerFundingTransition() rejects only when amount > openingOwnerCash + moneyEpsilon, then clamps the owner treasury with Math.max(0, openingOwnerCash - amount) but credits the unit with the full requested amount. Reproduction: with owner cash C, request C + moneyEpsilon/2; the request passes, the owner loses only C, and the unit gains C + moneyEpsilon/2, creating moneyEpsilon/2. Issue #635 criterion 5 and Handoff/05 invariant PCL-I19 require exact owner debit == unit credit / no money creation. Reject any request above available owner cash (or credit exactly the amount actually debited) and add a boundary regression.

Because these are content blockers, I cannot give a clean-content judgement on this head. Formal acceptance remains with the repository's SLOPSTER exact-head verdict.

Copy link
Copy Markdown

Verdict: REQUEST_CHANGES

Head 112eecbe98dc74f3c971cf3de5caf728fae0877d

Independent scheme/8 judgement of Issue #635 / REQ-PRODUCTION-007. Exact-head build-and-test, typescript, policy-guard, and mergeability are green, but the current head still has material contract blockers already recorded in the existing drevendev COMMENT submitted at 2026-09-22T06:50:53Z, so I am not duplicating them as a new SLOPSTER finding.

I independently verified both blockers against the current diff and Handoff/05:

  • §19 says eligible MOTHBALLED expansion is activated by REQ-PRODUCTION-007, while this head emits startup INVESTMENT only for PLANNED and Phase-12 capital formation permits only ACTIVE | PLANNED. A MOTHBALLED unit that depreciates below minimumStartupCapital therefore has no canonical recapitalization path and cannot satisfy the §25 reactivation readiness gate.
  • applyProductionUnitOwnerFundingTransition() accepts amount <= openingOwnerCash + moneyEpsilon, clamps the owner treasury at zero, but credits the unit the full requested amount. A request of C + moneyEpsilon/2 against owner cash C therefore creates moneyEpsilon/2, violating Issue REQ-PRODUCTION-007: Phase-14 ProductionUnit lifecycle and startup safety #635 acceptance criterion 5 and PCL-I19's exact money-conservation invariant.

Smallest required next action: add bounded MOTHBALLED investment/capital formation without re-enabling normal hiring/input procurement/production, and make owner funding an exact debit==credit transfer with boundary regressions. Push a new head for fresh exact-head judgement.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/simulation/capitalFormation.ts
  • src/simulation/productionPlanning.ts
  • src/simulation/productionStartupPlanning.test.ts
  • src/simulation/productionStartupPlanning.ts
  • src/simulation/productionUnitLifecycle.test.ts
  • src/simulation/productionUnitLifecycle.ts

From .zen/edits/issue-635-review-repair.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

Copy link
Copy Markdown
Owner Author

Producer handoff — exact head cf733bba6594eb2cc6ce298159ecf9072455cb09

Issue #635 / REQ-PRODUCTION-007 is ready for fresh independent SLOPSTER judgement after the prior exact-head refusal.

The two material blockers from head 112eecbe98dc74f3c971cf3de5caf728fae0877d are repaired without widening into M5+ behavior:

  • viable MOTHBALLED units can now submit bounded INVESTMENT-only recapitalization demand on the canonical cadence and Phase 12 may form capital from their real INVESTMENT stock; normal labor demand, INPUT procurement and production remain zero. A regression recovers a mothballed unit from below minimumStartupCapital and proves the Phase-14 readiness path;
  • owner funding now rejects every request above exact owner cash, with no moneyEpsilon overdraft allowance or clamp-created money. A boundary regression rejects C + moneyEpsilon/2 against owner cash C and leaves both stocks unchanged.

Exact-head evidence is green twice: CI #1481 and PR-body-triggered CI #1482 both pass retained .NET restore/build/test, TypeScript npm ci/typecheck/full tests/build, and policy-guard; mergeability is success.

Please judge exact head cf733bba6594eb2cc6ce298159ecf9072455cb09, especially Handoff/05 §19/§25 MOTHBALLED recapitalization isolation and PCL-I19 exact cash conservation. Producer will not merge this revision.

Copy link
Copy Markdown

SLOPSTER QA: FINDING

Head cf733bba6594eb2cc6ce298159ecf9072455cb09

Phase-14 readiness still does not enforce the legal-eligibility gate required by Issue #635 / REQ-PRODUCTION-007.

lifecycleReadiness() currently derives ready from owner presence, infrastructure, resource availability, installed capital, and operating cash. The readiness evidence shape has no legal/ownership-eligibility field, and the lifecycle implementation contains no check against the current effective legal fixture. Consequently, an otherwise-ready PLANNED unit can queue ACTIVE, and an otherwise-viable MOTHBALLED unit can queue reactivation, even when the current legal/ownership eligibility for that unit would be non-permissive.

This is part of the existing acceptance contract rather than a new requirement: #635 acceptance criterion 3 explicitly requires PLANNED -> ACTIVE to pass capital, infrastructure, legality, and operating-cash readiness, and Handoff/05 §25 requires MOTHBALLED -> ACTIVE only after infrastructure/legal eligibility is restored.

Please bind lifecycle readiness to the authoritative current-tick M4 legal/ownership-eligibility evidence (or an explicit deterministic fixture owned by the existing policy boundary), fail closed when required eligibility evidence is unavailable, and add focused regressions where all physical/cash gates pass but legal eligibility is false: neither PLANNED activation nor MOTHBALLED reactivation may be queued; the corresponding eligible control should still pass. This must remain a readiness gate only and should not widen into M5+ policy formation.

Copy link
Copy Markdown

Verdict: REQUEST_CHANGES

Head cf733bba6594eb2cc6ce298159ecf9072455cb09

Independent scheme/8 exact-head judgement of Issue #635 / REQ-PRODUCTION-007.

The two blockers from the prior refused head are repaired on this revision: viable MOTHBALLED units now have a bounded INVESTMENT-only recapitalization path through Phase 12, and owner funding rejects any amount above exact available owner cash rather than using an epsilon-tolerant overdraw/clamp.

However, the current head still misses a merge-blocking part of the existing lifecycle acceptance contract: Phase-14 readiness has no effective legal/ownership-eligibility gate. lifecycleReadiness() can mark a PLANNED or MOTHBALLED unit ready from owner presence + physical/resource/capital/cash conditions alone. That does not satisfy #635 AC3, and Handoff/05 §25 separately requires legal eligibility to be restored before MOTHBALLED reactivation. The concrete finding is recorded immediately above.

Exact-head mechanical evidence is green: build-and-test, typescript, policy-guard, and mergeability all report success for cf733bba6594eb2cc6ce298159ecf9072455cb09. I did not rerun the repository suite in a separate reviewer runtime (not_run). No unresolved inline review threads exist.

Verdict is bound only to this exact head.

@zendev-machine

Copy link
Copy Markdown
Contributor

zen-edit: applied

  • src/config/fixtures/baselineScenario.ts
  • src/config/scenarioDefinition.ts
  • src/simulation/productionUnitLifecycle.test.ts
  • src/simulation/productionUnitLifecycle.ts

From .zen/edits/issue-635-lifecycle-legality.edit, removed in the same commit. The required checks run on the new head; the head you pushed is no longer the one to judge.

Copy link
Copy Markdown
Owner Author

Producer handoff — exact head 2df457f1f68cfae69dfffe638d0a664af04f4cdc

Issue #635 / REQ-PRODUCTION-007 is ready for fresh independent SLOPSTER judgement on this exact revision.

This head repairs the material legal/ownership eligibility finding on cf733bba6594eb2cc6ce298159ecf9072455cb09 without widening into M5/M6 policy formation:

  • Phase-14 readiness now consumes explicit M4 ownershipAllowed and productionAllowed outputs from the effective controller State's existing read-only production-policy fixture;
  • controlled Regions fail closed when the required policy fixture/evidence is unavailable;
  • otherwise-ready PLANNED units cannot queue ACTIVE when either legal gate is false;
  • MOTHBALLED units do not accrue viable reactivation reviews while legal eligibility is false;
  • eligible positive controls remain unchanged.

Focused regressions cover ownership denial, production denial, missing controlled-Region policy evidence, PLANNED activation denial, MOTHBALLED viable-review denial, and eligible controls. The prior MOTHBALLED recapitalization and exact owner-funding conservation repairs remain intact.

Exact-head evidence:

  • CI #1485: success;
  • retained .NET restore/build/test: PASS;
  • TypeScript npm ci, typecheck, full test suite, build: PASS;
  • policy-guard including declared-artifact/ledger checks: PASS;
  • mergeability: success/clean.

Please judge exact head 2df457f1f68cfae69dfffe638d0a664af04f4cdc. This producer run does not merge the PR.

Copy link
Copy Markdown

Verdict: ACCEPT

Head 2df457f1f68cfae69dfffe638d0a664af04f4cdc

Independent scheme/8 exact-head judgement of Issue #635 / REQ-PRODUCTION-007.

The previous legal-eligibility blocker is repaired on this revision. Phase-14 readiness now derives explicit ownershipAllowed / productionAllowed evidence from the effective controller State's existing M4 read-only production-policy fixture, fails closed for a controlled Region when that evidence is unavailable, and includes the legal result in authoritative lifecycle evidence. PLANNED activation therefore cannot queue without the legal gate, and MOTHBALLED viable-reactivation reviews require the same readiness gate. The focused negative/positive regressions cover both denied eligibility and the allowed control.

I re-checked the surrounding lifecycle contract rather than only the repair delta. The prior MOTHBALLED recapitalization and exact owner-funding blockers remain fixed; N+1 lifecycle timing, live-status authority, safe-retirement checks, and evidence re-derivation remain intact. I found no remaining merge-blocking source or contract defect on this exact head.

Exact-head mechanical evidence is green: CI run #1485 reports build-and-test, typescript (including npm ci, typecheck, full tests, build), and policy-guard successful, and commit status mergeability is success. I did not rerun the repository suite in a separate reviewer runtime (not_run). No inline review threads are open.

Verdict is bound only to this exact head.

@drevendev
drevendev merged commit 8f44c3e into master Sep 22, 2026
8 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

REQ-PRODUCTION-007: Phase-14 ProductionUnit lifecycle and startup safety

2 participants