Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
45 commits
Select commit Hold shift + click to select a range
90ae0ef
feat(cp06): add risk-aware Pi review workflow
Sep 28, 2026
75fed66
docs(cp06): record review workflow exercise
Sep 28, 2026
8b945a4
no-mistakes(document): Format workflow documentation table
Sep 28, 2026
8da6746
fix(cp06): constrain context to task authority
Sep 29, 2026
461dea5
no-mistakes(review): Harden CP-06 replay evidence
Sep 29, 2026
355854f
test(cp06): require successful bad-path retrieval
Sep 29, 2026
cdaf5e5
no-mistakes(document): Format changed documentation
Sep 29, 2026
cf10d9b
fix(cp06): close final review gaps
Sep 29, 2026
c3eb0b7
no-mistakes(review): Enforce scoped CTX provenance
Sep 29, 2026
6d02e46
fix(cp06): enforce isolated worker credential reads
Sep 29, 2026
385b80e
no-mistakes(review): Harden CP-06 credential isolation
Sep 29, 2026
752152e
fix(cp06): harden read-only Pi authentication
Sep 30, 2026
b835733
no-mistakes(review): Clarify CP-06 WSL2 proof limits
Sep 30, 2026
2ec7c26
no-mistakes(review): Cover source destructive isolation attacks
Sep 30, 2026
2e36a8f
no-mistakes(test): Restore offline CTX model lookup
Sep 30, 2026
3abaa43
no-mistakes(document): Document CP-06 auth-security proof
Sep 30, 2026
33b2724
no-mistakes(review): Enforce exact original read arguments
Sep 30, 2026
641d7ca
fix(cp06): enforce worker outcome and cleanup
Oct 1, 2026
6b9b6e2
no-mistakes(review): Enforce canonical missing source identity
Oct 1, 2026
9491626
no-mistakes(document): Document cleanup proof evidence
Oct 1, 2026
0632643
fix(cp06): preserve audit and cleanup failures
Oct 2, 2026
300bd38
no-mistakes(review): Harden CP-06 credential isolation and evidence v…
Oct 2, 2026
693c4c6
no-mistakes(review): Fix CP-06 source, read, oracle, and Pi pinning
Oct 2, 2026
d1cd374
no-mistakes(review): Fix CP-06 DUMMY control, response parsing, and S…
Oct 2, 2026
5cee2d8
no-mistakes(review): Pin both DUMMY probes to supervisor-owned fixtures
Oct 2, 2026
2fb24ca
no-mistakes(review): Harden CP-06 proof boundaries and failure reporting
Oct 2, 2026
c92c2fe
no-mistakes(review): Sanitize outputs; native FD-mount and exec hando…
Oct 2, 2026
036178f
no-mistakes(review): Harden CP06 proof boundaries
Oct 2, 2026
9afae5c
no-mistakes(review): Harden CP06 identity handoffs
Oct 2, 2026
7b96ee6
no-mistakes(review): Harden CP-06 proof boundaries
Oct 3, 2026
19e785d
no-mistakes(review): Fix helper execution, serializer imports, and ne…
Oct 3, 2026
93f424c
no-mistakes(document): Refresh CP06 documentation and format proof sc…
Oct 3, 2026
75620d0
no-mistakes(lint): Format CP06 regression tests
Oct 3, 2026
c12d24d
no-mistakes(review): Fix six CP06 findings; mount, CLI, kernel gaps r…
Oct 5, 2026
5953aea
no-mistakes(review): Pin cleanup scratch, exact read-audit paths, hon…
Oct 5, 2026
05c4960
no-mistakes(review): Pin cleanup HOME and add descriptor-bound anchor…
Oct 5, 2026
948e785
no-mistakes(review): Anchor evaluation-home removal and test identity…
Oct 5, 2026
fdc8321
Recover timed-out CP06 mount/CLI fix-agent edits
Oct 5, 2026
cc86a0e
no-mistakes(review): Harden CP06 descriptor handoff, evidence validat…
Oct 5, 2026
76e4783
no-mistakes(review): Bind CP06 ancestry, artifact identity, provenanc…
Oct 5, 2026
00321e0
no-mistakes(review): Resolve CP06 supervisor provenance safely withou…
Oct 6, 2026
b21a39b
no-mistakes(document): Apply Prettier formatting to CP06 scripts and …
Oct 6, 2026
b9bfceb
no-mistakes: apply CI fixes
Oct 6, 2026
a8c4c3d
Reject any offset or limit on the CP06 original read
Oct 6, 2026
604744e
no-mistakes(document): Align CP-06 probe docs with no-range original …
Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 18 additions & 0 deletions .factory/cp06-sdk-integrity.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
{
"schema_version": 1,
"source": "npm registry exact-version tarballs; verify each tarball SHA-512 SRI before extracting and recomputing the sorted [relative path, file SHA-256] manifest digest",
"packages": {
"@earendil-works/pi-coding-agent": {
"version": "0.85.1",
"tarball_integrity": "sha512-FGRN+OHbWaefBPGaTggAdLjrIHW+s2PzLyglz/5dfLzb9of7uuXMXYC0fJIeZTw+shS32o2cuQ9jF7YSDuL/oQ==",
"file_count": 1056,
"manifest_sha256": "ff28a78bb025ee9fc182929f8eec27908f5e20870a5b7d8b1b37a1ded8507ecf"
},
"@earendil-works/pi-ai": {
"version": "0.85.1",
"tarball_integrity": "sha512-+VgVIJDkDO2efYJKEEqvPTH4zmnIaXdAppGbO+vKFA9qy5PdhFiAenuFAkU+oiCSfOC4dMHDyrjdQeL4ZoC5CQ==",
"file_count": 750,
"manifest_sha256": "3e1894e3f18b90f39c068cd0815f8559083c382e7d343efd1f961a8f07b0cefc"
}
}
}
7 changes: 7 additions & 0 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,4 +18,11 @@ jobs:
- run: npm run format:check
- run: npm run lint
- run: npm run typecheck
# Ubuntu 24.04 runners restrict unprivileged user namespaces through AppArmor.
# CP-06 isolation tests need real disposable DUMMY namespaces and have no fallback.
- name: Allow unprivileged user namespaces
run: |
if [ -e /proc/sys/kernel/apparmor_restrict_unprivileged_userns ]; then
sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0
fi
- run: npm test
22 changes: 11 additions & 11 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ Recommended exit codes: `0` success; `2` validation failure; `3` unavailable/sta

## CTX context pack

`factory context TASK-ID` first includes the exact tracked task contract and a concise global project constraint section. It invokes `ctx status --root <root> --json` and `ctx doctor --offline --root <root> --json` as appropriate, then `ctx pack <query> --root <root> --token-budget <limit> --json`. The query is derived from title, outcome, acceptance, and topic strings; it is never a command. Canonical required documents are read from their original files, checked against root containment, and admitted before optional CTX excerpts. The adapter records CTX generation, file and line provenance, and available hashes; it does not treat an excerpt as a permission to ignore original wording. On stale or insufficient retrieval, it returns `CONTEXT_BLOCKED` with an actionable diagnostic. It does not fill the pack with guessed material.
`factory context TASK-ID` first includes the exact tracked task contract and a concise global project constraint section. It invokes `ctx status --root <root> --json` and `ctx doctor --offline --root <root> --json` as appropriate, then `ctx pack <query> --root <root> --token-budget <limit> --document <task-source>... --json`. The query is derived from title, outcome, acceptance, and topic strings; it is never a command. Repeated `--document` filters implement the authority-selection contract in [docs/CONTRACTS.md](docs/CONTRACTS.md#task-factorytaskssave-001yaml). Factory verifies returned provenance against the selected canonical source identities and blocks with `RETRIEVAL_SCOPE_WIDENED` if CTX returns an out-of-scope original; it does not silently discard that excerpt and report success. Canonical required documents are read from their original files, checked against root containment, and admitted before CTX excerpts; declaring a source required never substitutes an excerpt for the exact original. The adapter records CTX generation, file and line provenance, and available hashes. On stale, missing, or insufficient retrieval, it returns `CONTEXT_BLOCKED` with an actionable diagnostic. It does not fill the pack with guessed material or hide post-retrieval excerpts to improve a relevance score.

Default total task-context budgets (including contract and mandatory material) are 4,000 tokens for bounded, 8,000 for normal, and 15,000 for critical; these are design defaults to measure, not promises that CTX necessarily returns that many tokens. Reserve space for task contract and required sources before calling CTX with the remainder. The adapter enforces a byte ceiling as well as CTX's token budget, deduplicates overlapping excerpts, and never truncates an authoritative requirement mid-sentence. The pack is written atomically to `.factory/state/context/TASK-ID.md` with a sidecar receipt containing contract digest, source digests, CTX generation, timestamp, and retrieval mode. A worker verifies these before trusting the pack; if changed, regenerate it.

Expand All @@ -65,15 +65,15 @@ The tracked `.factory/completion.yaml` is authored before task implementation. I

## Failures and trust boundaries

| Failure | Required response |
| --- | --- |
| CTX unavailable or index stale | Do not make up context; exact required files still available for manual work; context command exits blocked. |
| Firstmate home absent or not registered | Publication blocked; preview shows required setup. |
| tasks-axi CLI/version/backend incompatible | Publication blocked; no direct backlog file edit fallback. |
| Contract changed during sync | Abort before writes where possible; report partial state if a write already occurred. |
| Duplicate ID/body edited by another actor | Conflict, never clobber. |
| Source path outside repo or symlink escape | Reject before reading or publishing. |
| Project checks pass on obsolete commit | Mark stale; rerun against release candidate. |
| Worker reports pass without evidence | Show unverified, not complete. |
| Failure | Required response |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------ |
| CTX unavailable or index stale | Do not make up context; exact required files still available for manual work; context command exits blocked. |
| Firstmate home absent or not registered | Publication blocked; preview shows required setup. |
| tasks-axi CLI/version/backend incompatible | Publication blocked; no direct backlog file edit fallback. |
| Contract changed during sync | Abort before writes where possible; report partial state if a write already occurred. |
| Duplicate ID/body edited by another actor | Conflict, never clobber. |
| Source path outside repo or symlink escape | Reject before reading or publishing. |
| Project checks pass on obsolete commit | Mark stale; rerun against release candidate. |
| Worker reports pass without evidence | Show unverified, not complete. |

External repository files, CTX excerpts, and task bodies are untrusted as shell commands. The CLI never executes test commands solely because a contract specifies one; allowed project checks are defined by a reviewed, tracked verification configuration and executed only by an explicit operator/worker command. Do not store secrets or raw agent transcripts in a context pack or receipt.
6 changes: 3 additions & 3 deletions BUILD_PLAN.md
Original file line number Diff line number Diff line change
Expand Up @@ -87,9 +87,9 @@

**Deliverable:** Pi's workflow classifies bounded/normal/critical risk, obtains precise review findings, and collects evidence appropriate to the task without rerunning no-mistakes' pipeline inside Factory.

- [ ] Create tests/fixtures for critical auth isolation and normal API behavior, plus one simulated reviewer finding that causes repair and retest.
- [ ] Run an actual worker task with only task/pack/evidence sources in a fresh context; inspect whether it needs missing docs.
- [ ] **Gate:** P-06, P-07, and no change to Firstmate routing or shipping config by Factory.
- [x] Create tests/fixtures for critical auth isolation and normal API behavior, plus one simulated reviewer finding that causes repair and retest.
- [x] Run an actual worker task with only task/pack/evidence sources in a fresh context; inspect whether it needs missing docs.
- [ ] **Gate:** P-06 and P-07 via the tracked replays in [docs/probes/CP-06.md](docs/probes/CP-06.md), which owns proof interpretation and residual limits; exact-final-head proofs and independent review remain required. No change to Firstmate routing or shipping config by Factory.

## CP-07 — Thin Pi command and status convenience

Expand Down
18 changes: 14 additions & 4 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Factory: build package

**Status:** implementation specification, 26 September 2026. No Factory software is claimed to exist yet.
**Status:** development CLI with CP-06 corrections in progress. Product completion requires the independent gates in [COMPLETION.md](COMPLETION.md); checkpoint state is owned by [BUILD_PLAN.md](BUILD_PLAN.md).

Factory is a thin layer for turning a software product brief into independently verifiable work for an existing Pi + Firstmate setup. Its purpose is to minimize the intelligence, context, and human attention required to transform intent into verified software.

Expand All @@ -14,11 +14,21 @@ Factory is a thin layer for turning a software product brief into independently

Read [docs/CONTRACTS.md](docs/CONTRACTS.md) when implementing validation, [docs/INTEGRATIONS.md](docs/INTEGRATIONS.md) when touching CTX/Pi/Firstmate, [docs/WORKFLOW.md](docs/WORKFLOW.md) when designing the Factory skill, and [docs/RESEARCH.md](docs/RESEARCH.md) for sources and decisions. [docs/BOOTSTRAP_PROMPTS.md](docs/BOOTSTRAP_PROMPTS.md) contains copyable Pi instructions for the initial checkpoints.

## Repository bootstrap
## Common usage

Create an empty Git repository for Factory and copy this directory's contents to its root. Do not copy an archived CTX repository or a Firstmate home into it. Review the files, resolve only genuine product decisions, then use your existing `/CTX startup` workflow to index the authoritative Markdown. Begin CP-00 from [BUILD_PLAN.md](BUILD_PLAN.md). The current workspace contains documents only; commands described here are target behavior, not commands that already run.
From this source checkout:

The baseline interaction is your current research → project truth → checkpoint → worker → independent review process. Once validation and task publication work, use Factory's own backlog to build later checkpoints. Do not assert that dogfooding happened until a real Firstmate worker receives, executes, and closes a Factory task.
```sh
npm ci
npm run build
node dist/src/cli.js --help
node dist/src/cli.js validate --root <project-root> --json
node dist/src/cli.js context <TASK-ID> --root <project-root> --json
```

Prepare reviewed contracts and a deliberate offline CTX authority set first; see [docs/CONTRACTS.md](docs/CONTRACTS.md) and the [Factory skill](skills/factory/SKILL.md) for the workflow and named-home publication safeguards. Do not copy an archived CTX repository or a Firstmate home into a target project. Factory does not dispatch workers or choose delivery policy.

CP-06's development proof commands, exact SDK requirements, evidence interpretation, and platform limits are owned by [docs/probes/CP-06.md](docs/probes/CP-06.md). A DUMMY proof or closed backlog is not product completion.

## Document authority

Expand Down
4 changes: 2 additions & 2 deletions docs/CONTRACTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,7 +80,7 @@ evidence:
delivery: project-default
```

`depends_on` names local task IDs, is acyclic, and cannot name self. `advances` names completion IDs and may be empty only for a task explicitly marked `kind: enabling`; enabling tasks still have testable outcomes. `complexity` is `bounded | normal | critical`; `risk` is `bounded | normal | critical` and controls review policy, not a specific model name. `delivery` defaults to `project-default` and cannot override the actual Firstmate project mode; if the project mode conflicts with a task request, validation blocks publication. All required evidence categories are verified by evidence receipts rather than assumed from task closure.
`depends_on` names local task IDs, is acyclic, and cannot name self. `advances` names completion IDs and may be empty only for a task explicitly marked `kind: enabling`; enabling tasks still have testable outcomes. `complexity` is `bounded | normal | critical`; `risk` is `bounded | normal | critical` and controls review policy, not a specific model name. `context.required` is the reviewed task-local authority selection: Factory reads every listed original exactly and passes the same paths as CTX document filters. An empty list explicitly means that no task-specific original is needed; Factory still filters CTX to the project's mandatory `documents.required` authority and never treats the empty selection as unrestricted corpus access. Include each known source that can decide an acceptance or risk condition; do not add broad directories or unrelated documents as insurance. The omitted-source correction procedure is owned by [WORKFLOW.md](WORKFLOW.md#task-local-worker-brief). `delivery` defaults to `project-default` and cannot override the actual Firstmate project mode; if the project mode conflicts with a task request, validation blocks publication. All required evidence categories are verified by evidence receipts rather than assumed from task closure.

## Task receipt: `.factory/state/evidence/SAVE-001.json`

Expand All @@ -100,7 +100,7 @@ delivery: project-default
"artifact_sha256": "<64 hexadecimal characters>"
}
],
"review": {"status": "pending", "artifact": null},
"review": { "status": "pending", "artifact": null },
"recorded_at": "2026-09-26T00:00:00Z"
}
```
Expand Down
18 changes: 9 additions & 9 deletions docs/INTEGRATIONS.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ The user's archived CTX README describes a Python 3.12+ local CLI, source-proven

CP-00 probes: detect `ctx`; create a disposable Git fixture with two normative Markdown docs; initialize and add docs according to local `ctx --help`; index with `--no-embeddings` so the test does not download anything; run status, offline doctor, pack, and exact lines; record actual JSON fields and failure codes. Confirm stale-source detection by changing a source after indexing. A user's globally installed model may then be tested separately. Do not index the Factory repo until its initial documents are approved.

Context policy: required files are read exactly; CTX provides relevant additional passages with source provenance; changed docs invalidate a pack; unavailable local embedding may allow the explicitly reported lexical mode if it retrieves sufficient authority. Query text is data, never shell code. `ctx pack` is one context source, not a substitute for Git, `rg`, or project checks.
The installed `ctx pack` accepts repeated `--document` filters. Factory's selection contract is owned by [CONTRACTS.md](CONTRACTS.md#task-factorytaskssave-001yaml); provenance verification and blocking behavior are owned by [ARCHITECTURE.md](../ARCHITECTURE.md#ctx-context-pack). Query text is data, never shell code. `ctx pack` is one context source, not a substitute for Git, `rg`, or project checks.

## Pi

Expand All @@ -30,14 +30,14 @@ no-mistakes documents a review → test → document → lint → push → PR

## Probe matrix

| Probe | Failure response |
| --- | --- |
| CTX actual version/JSON/CLI flags | Block context pack and show install-specific diagnostic. |
| Pi installed import namespace and skill discovery | Keep CLI usable; defer extension/skill packaging. |
| Firstmate home identity and registered project | Block sync. |
| tasks-axi version, backend, dependency commands | Block sync; provide dry-run export for manual inspection only. |
| no-mistakes gate in intended project mode | Block automated shipping claims; continue local deterministic checks. |
| Windows/macOS path behavior | Report platform limitation honestly; do not claim cross-platform gate. |
| Probe | Failure response |
| ------------------------------------------------- | ---------------------------------------------------------------------- |
| CTX actual version/JSON/CLI flags | Block context pack and show install-specific diagnostic. |
| Pi installed import namespace and skill discovery | Keep CLI usable; defer extension/skill packaging. |
| Firstmate home identity and registered project | Block sync. |
| tasks-axi version, backend, dependency commands | Block sync; provide dry-run export for manual inspection only. |
| no-mistakes gate in intended project mode | Block automated shipping claims; continue local deterministic checks. |
| Windows/macOS path behavior | Report platform limitation honestly; do not claim cross-platform gate. |

## Primary documents

Expand Down
Loading
Loading