From 23210405cfb5bd56991f6d37149c477c2d588170 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Sun, 27 Sep 2026 20:10:33 +0000 Subject: [PATCH 01/13] Add Factory Pi workflow skill --- skills/factory/SKILL.md | 60 +++++++++++++++++++++++++++++++++++++++++ 1 file changed, 60 insertions(+) create mode 100644 skills/factory/SKILL.md diff --git a/skills/factory/SKILL.md b/skills/factory/SKILL.md new file mode 100644 index 0000000..5222499 --- /dev/null +++ b/skills/factory/SKILL.md @@ -0,0 +1,60 @@ +--- +name: factory +description: Use Factory to turn reviewed project intent into validated task contracts, bounded source-attributed context, and a safe Firstmate backlog preview. Use when initializing or validating a Factory project, preparing worker context, or previewing and publishing tasks to a named Firstmate home. +compatibility: Requires the Factory CLI plus separately installed ctx and tasks-axi CLIs; Firstmate owns dispatch. +--- + +# Factory workflow + +Factory validates and packages work; Pi makes semantic judgments; CTX retrieves durable Markdown; tasks-axi owns the backlog; Firstmate alone dispatches workers. + +## Establish the boundary + +1. Identify the canonical Git project root and the exact, named Firstmate home. Never infer a home from a nearby checkout. +2. Find the real CLI: use `factory` only if `command -v factory` succeeds. In the Factory source checkout, run `npm run build` and use `node dist/src/cli.js` instead. Call that executable `` below. +3. Run the read-only probe: + +```sh + doctor --root --home --json +``` + +Stop on a mismatched home/project, stale CTX index, unsupported backend or tool version, contradictory authority, missing consequential product decision, sensitive access request, or publication conflict. Do not weaken the delivery mode. + +## Prepare reviewed contracts + +1. Before task decomposition, write concise product and architecture truth and independently author `.factory/completion.yaml` from observable behavior and risks. +2. Run ` init --root --json`. It creates scaffolding but does not invent product choices. +3. Author `.factory/project.yaml` and bounded task contracts under `.factory/tasks/`. Prefer vertical slices, explicit acceptance IDs and evidence, a serial backbone, and at most three genuinely independent ready tasks. +4. Run ` validate --root --json`; repair every schema, graph, path, coverage, and decision-block diagnostic. + +Use the exact contracts in [`../../docs/CONTRACTS.md`](../../docs/CONTRACTS.md). For methodology and decision format, read [`../../docs/WORKFLOW.md`](../../docs/WORKFLOW.md). Original project documents remain authoritative; CTX excerpts and generated summaries do not replace decisive exact reads. + +## Build bounded worker context + +For each ready task, run: + +```sh + context --root --json +``` + +Inspect the pack and receipt for the exact task contract, required original sources, source and contract digests, CTX generation/retrieval mode, relevance, and token/byte bounds. Regenerate after any source, contract, or index change. Never place secrets, credentials, source archives, or agent transcripts in a pack. + +## Preview, then publish + +Always run the read-only preview first: + +```sh + sync --dry-run --root --home --json +``` + +Require the reported backlog hash to be unchanged, review every `create`, `unchanged`, `blocked`, and `conflict` record, and obtain human review of this exact named-home preview. Only then may the operator explicitly run: + +```sh + sync --apply --root --home --json +``` + +Apply must repeat preflight and fail closed. Never edit a backlog file directly, overwrite an edited item, use a different home, or treat publication as dispatch. Firstmate chooses ready work and owns dispatch, worker lifecycle, and delivery approvals. + +## Current command limit + +At this checkpoint the implemented Factory CLI commands are only `doctor`, `init`, `validate`, `context`, and `sync --dry-run|--apply`. Do not invent `/factory`, `factory run`, `factory evidence`, `factory status`, or `factory inspect` invocations. Backlog closure alone never proves product completion. From 7178f565ecd7b30b393a450a5dc6e324c8a99d9c Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Sun, 27 Sep 2026 20:26:43 +0000 Subject: [PATCH 02/13] Document CP-04 proof and CP-05 proposal --- BUILD_PLAN.md | 4 +- docs/probes/CP-04.md | 234 ++++++++++++++++++++++++++++++++++++++ docs/proposals/CP-05.yaml | 23 ++++ 3 files changed, 259 insertions(+), 2 deletions(-) create mode 100644 docs/probes/CP-04.md create mode 100644 docs/proposals/CP-05.yaml diff --git a/BUILD_PLAN.md b/BUILD_PLAN.md index d925cee..1a07218 100644 --- a/BUILD_PLAN.md +++ b/BUILD_PLAN.md @@ -69,8 +69,8 @@ **Implementation files:** `skills/factory/SKILL.md`, optional `prompts/factory-start.md`, package manifest registration if Pi discovery requires it; validate exact installed Pi behavior. -- [ ] Write the skill using `docs/WORKFLOW.md`; explain what the CLI does, when to use it, and when to stop for a real decision. -- [ ] Load it in Pi, invoke it explicitly and automatically, and confirm it uses existing commands rather than narrating a fictional `/factory run`. +- [x] Write the skill using `docs/WORKFLOW.md`; explain what the CLI does, when to use it, and when to stop for a real decision. +- [x] Load it in Pi, invoke it explicitly and automatically, and confirm it uses existing commands rather than narrating a fictional `/factory run`. - [ ] Publish CP-05 as a testable task in Factory's own backlog, then observe real Firstmate dispatch and closure. **Gate:** F-09 and the first real task/worker trace. Dogfooding remains unproven if only task publication succeeds. ## CP-05 — Evidence and independent completion diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md new file mode 100644 index 0000000..1a910fd --- /dev/null +++ b/docs/probes/CP-04.md @@ -0,0 +1,234 @@ +# CP-04 probe report — Pi workflow packaging and initial dogfood + +Date: 2026-09-27. Branch: `fm/factory-cp04`, stacked on verified CP-03 +`b72da4508f6d845e2bea5545b7a627254dba12d6`. Skill implementation SHA tested: +`bff13871227a1edeb3cbd74ec252713c4ee9a1d1`. + +Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The +Pi skill and isolated blind-handoff proof pass, but CP-04's real dogfood milestone +remains open: CP-03 PR #4 is unmerged, no CP-05 item was published to the real +Firstmate home, and no Firstmate-dispatched CP-05 worker closed it. The tracked +`docs/proposals/CP-05.yaml` is a proposal, not a backlog record or CP-05 +implementation. + +## Isolation and upstream state + +The task started in the disposable worktree +`/home/ansh/.treehouse/Factory-86709f/3/Factory`; `pwd -P` and +`git rev-parse --show-toplevel` returned that same path. The first remote fetch +confirmed `origin/fm/factory-cp03` exactly matched the required SHA before +`fm/factory-cp04` was created. + +```text +$ git fetch origin fm/factory-cp03 +$ git rev-parse FETCH_HEAD +b72da4508f6d845e2bea5545b7a627254dba12d6 +exit=0 + +$ gh-axi pr view 4 -R 0xnotdev/Software_factory +state=open; merged=no; checks="2 passed, 0 failed, 2 total" +exit=0 + +$ gh-axi pr checks 4 -R 0xnotdev/Software_factory +checks=2 passed, 0 failed +exit=0 + +$ git ls-remote origin refs/heads/fm/factory-cp03 refs/heads/main +fm/factory-cp03=b72da4508f6d845e2bea5545b7a627254dba12d6 +main=bd053912a66b06dd8a63c98e91fe292ced75c65a +exit=0 +``` + +No CP-00–03 commit was rewritten or dropped. + +## Documentation and installed boundary + +The repository CTX state was absent in this isolated worktree. It was initialized +only from the deliberately selected authoritative Markdown and remains ignored. +`ctx status --json` reported `CLEAN`, generation 1, verified +`BAAI/bge-small-en-v1.5`, and `HYBRID_SEMANTIC`. A strict pack remained +`CONFLICTING` because its deterministic detector reported possible phrase-pair +conflicts and omitted normative sections even at a larger budget. It was not +accepted as authority; decisive requirements were read from the exact original +`PROJECT.md`, `ARCHITECTURE.md`, `COMPLETION.md` F-09, `BUILD_PLAN.md` CP-04, +`docs/WORKFLOW.md`, `docs/INTEGRATIONS.md`, and `docs/CONTRACTS.md`. + +Installed tools used for this checkpoint: + +- Pi `0.85.1`; installed package `@earendil-works/pi-coding-agent` `0.85.1`. +- Pi docs read completely: installed `docs/skills.md`; related + `docs/packages.md`, `examples/sdk/04-skills.ts`, and + `examples/extensions/dynamic-resources/SKILL.md` were also checked. +- CTX `1.0.0`, tasks-axi `0.2.5`, Node `v24.20.0`, npm `12.0.2`. +- no-mistakes `v1.57.0` (`0fcbbff`); daemon healthy. It was not updated or + restarted. + +Pi `0.85.1` discovered the conventional `skills/factory/SKILL.md` package layout, +so no `pi` manifest or package metadata was added. An isolated temporary +`PI_CODING_AGENT_DIR` install of the repository exited 0 and listed the local +package without changing the user's Pi settings. + +## Skill discovery and behavior + +The skill links to the deeper workflow and contract references, keeps context +bounded, requires the exact named-home preflight and a human-reviewed preview, +and leaves dispatch to Firstmate. It names only the implemented commands: +`doctor`, `init`, `validate`, `context`, and `sync --dry-run|--apply`. It does not +advertise `/factory`, `factory run`, `evidence`, `status`, or `inspect`. + +Deterministic discovery used Pi's documented RPC `get_commands` interface: + +```text +$ printf | PI_OFFLINE=1 pi --offline --approve \ + --no-session --no-context-files --no-extensions --no-prompt-templates \ + --no-themes --no-skills --skill skills/factory --mode rpc +exit=0 +command=skill:factory; source=skill +path=.../skills/factory/SKILL.md +``` + +Explicit invocation: + +```text +$ PI_OFFLINE=1 pi --offline --approve --no-context-files --no-session \ + --no-tools --no-skills --skill skills/factory/SKILL.md \ + --provider openai-codex --model gpt-5 -p \ + '/skill:factory Give only the ordered implemented Factory CLI command names ...' +exit=0 +result=doctor, init, validate, context, sync --dry-run, sync --apply; +dispatch owner=Firstmate +``` + +Automatic matching ran in another ephemeral, transcript-free Pi process with +only the Factory skill and read tool. Pi's JSON trace showed a `read` call for +`skills/factory/SKILL.md`; it returned the same command boundary and identified +Firstmate as dispatch owner. Command exit was 0. With unrelated global skills +also enabled, model selection is not deterministic (one probe first selected an +unrelated skill), so the acceptance proof isolates the package under test rather +than claiming global skill-priority behavior. + +## Fixture-only sync preview + +A fresh disposable Git project and named disposable Firstmate home were created +under ignored `.factory/state/`. No live home was used. + +```text +$ node dist/src/cli.js sync --dry-run \ + --root .factory/state/cp04-sync-proof/project-repo \ + --home .factory/state/cp04-sync-proof/named-firstmate-home --json +exit=0 +summary={create:1,unchanged:0,conflict:0,blocked:0} +created_ids=[] +backlog sha256 before=e9d9186469a1b96f87bb25a4474617bfe8224065c1b266d2055a8cfde27d4726 +backlog sha256 after =e9d9186469a1b96f87bb25a4474617bfe8224065c1b266d2055a8cfde27d4726 +``` + +This proves the packaged instruction's preview is executable and byte-preserving +against a fixture. `sync --apply` was not run against the real Firstmate home. + +## Blind F-09 handoff + +A fresh clone at the exact skill implementation SHA received only: + +- checkpoint `CP-04`; +- acceptance IDs `CP04-SKILL` and `F-09`; +- exact task-contract digest + `efbe4bc1cc7eff1a90848b2f3cc82ba476ef6516cf4e743c825349dc0e261087`; +- required pack `.factory/state/context/CP-04-BLIND.md`; +- expected executable Pi discovery/invocation and freshness proof; and +- branch SHA `bff13871227a1edeb3cbd74ec252713c4ee9a1d1`. + +The isolated fixture's actual commands returned: + +```text +$ ctx status --root . --json +exit=0; category=CLEAN; generation=1; retrieval=HYBRID_SEMANTIC + +$ ctx doctor --offline --root . --json +exit=0; model.verified=true; offline_ready=true; network_attempted=false + +$ node dist/src/cli.js validate --root . --json +exit=0; task_count=1; condition_count=1 + +$ node dist/src/cli.js context CP-04-BLIND --root . \ + --token-budget 15000 --json +exit=0; bytes=18432; estimated_tokens=6144; generation=1; +retrieval_mode=HYBRID_SEMANTIC +``` + +The first fixture attempt incorrectly made four full documents mandatory while +also asking CTX to retrieve the same corpus; after mandatory material consumed +the bounded budget, CTX correctly returned `PARTIAL`. Increasing total budgets +to 20,000 and 30,000 was a disconfirming case: it changed the result to +`CONFLICTING`, not `COMPLETE`, because the broad corpus triggered an unrelated +deterministic possible-conflict pair. The smallest counterfactual kept the +methodology (`docs/WORKFLOW.md`) as exact mandatory authority and deliberately +indexed only the relevant CP-04/F-09 supporting originals (`BUILD_PLAN.md`, +`COMPLETION.md`, `docs/INTEGRATIONS.md`). That produced the complete bounded +pack above. Accepted F-03/F-04 behavior was therefore working as designed; no +CP-02 adapter change was needed. + +A genuinely new Pi process then received only the six handoff fields. It exited +0, verified HEAD, contract digest, pack receipt, and every source digest, and +explicitly reported that it needed and retrieved the exact original +`docs/WORKFLOW.md`; it did not claim prior transcript knowledge. It ran explicit +and automatic Pi skill probes, both exit 0, and left the clone unchanged except +for the pre-existing untracked fixture contracts. Raw Pi conversations and +transcripts are not tracked. + +This is positive isolated evidence for F-09, but F-09/CP-04 dogfood remains +reported open until the authorized real Firstmate task trace exists; the +isolated exercise is not represented as Firstmate dispatch or task closure. + +## Deterministic gates + +Against `bff13871227a1edeb3cbd74ec252713c4ee9a1d1`: + +```text +$ npm run format:check +exit=0 +$ npm run lint +exit=0; lint ok +$ npm run typecheck +exit=0 +$ npm test +exit=0; 56 passed, 0 failed +$ npm run build && node --test \ + --test-name-pattern='dry-run previews create/unchanged/conflict without changing one backlog byte' \ + dist/test/sync.test.js +exit=0; 1 passed, 0 failed +``` + +## CP-05 and delivery hold + +`docs/proposals/CP-05.yaml` records the next checkpoint's proposed outcome, +acceptance, P-03/P-04 links, exact required authority, and expected evidence. It +is intentionally outside `.factory/tasks/`, cannot be picked up by sync, and +contains no CP-05 implementation. + +The real dependent milestone is held because PR #4 remains open. Before any +publication, CP-03 must land; main, tool versions, named-home registration, +backend, and project mode must be re-probed; and a human must review the exact +read-only preview for that named home. Firstmate alone may then dispatch the +independently scoped CP-05 worker. + +The installed no-mistakes `v1.57.0` home/status and `axi run --help` expose no +base-branch option. This branch tracks `origin/fm/factory-cp03`, while the gate's +recorded origin default is `main`; a full run could not explicitly preserve the +stacked PR base and its rebase step could drop unmerged CP-03 history. Per the +task safety gate, no no-mistakes run was started. This is a delivery hold, not a +skipped or passed gate. + +## Changed files and residual risks + +- `skills/factory/SKILL.md` +- `docs/proposals/CP-05.yaml` +- `docs/probes/CP-04.md` +- `BUILD_PLAN.md` (only the two proven CP-04 checklist items) + +Residual risks: CP-03 is unmerged; real named-home preview/publication, +Firstmate dispatch, CP-05 closure, and the first real task/worker trace are +unrun; no-mistakes cannot safely preserve this stacked base through its full +v1.57.0 gate; automatic model skill choice can be distracted by unrelated +global skills. No live backlog, Firstmate configuration, shared daemon, +credentials, Herdr lifecycle, merge, deployment, or default branch was changed. diff --git a/docs/proposals/CP-05.yaml b/docs/proposals/CP-05.yaml new file mode 100644 index 0000000..ecc24f7 --- /dev/null +++ b/docs/proposals/CP-05.yaml @@ -0,0 +1,23 @@ +# Tracked proposal only. Do not publish until CP-03 is merged, the named home is +# re-probed, and a human reviews the exact `factory sync --dry-run` preview. +schema_version: 1 +id: CP-05 +title: Bind evidence to task contracts and independent product completion +outcome: Factory reports task evidence separately from project completion and rejects failed or stale proof. +depends_on: [] +complexity: normal +risk: normal +acceptance: + - id: CP05-EVIDENCE + statement: Prose-only pass claims, failed exits, changed contracts, changed release SHAs, and missing artifacts cannot produce valid passing evidence. + - id: P-03 + statement: Task evidence is bound to the exact task contract and tested Git SHA, and becomes stale after either changes. + - id: P-04 + statement: Product completion remains NOT COMPLETE when a project-level check fails even after every task is closed. +advances: [P-03, P-04] +context: + topics: [evidence receipts, stale proof, release candidate, independent completion] + required: [PROJECT.md, ARCHITECTURE.md, COMPLETION.md, BUILD_PLAN.md, docs/CONTRACTS.md] +evidence: + required: [unit, integration] +delivery: project-default From 229443bd5503248ae62141b64ab390268d1732c8 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Sun, 27 Sep 2026 20:27:30 +0000 Subject: [PATCH 03/13] Record final CP-04 validation SHA --- docs/probes/CP-04.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index 1a910fd..be8e5bc 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -1,8 +1,9 @@ # CP-04 probe report — Pi workflow packaging and initial dogfood Date: 2026-09-27. Branch: `fm/factory-cp04`, stacked on verified CP-03 -`b72da4508f6d845e2bea5545b7a627254dba12d6`. Skill implementation SHA tested: -`bff13871227a1edeb3cbd74ec252713c4ee9a1d1`. +`b72da4508f6d845e2bea5545b7a627254dba12d6`. Skill implementation SHA: +`bff13871227a1edeb3cbd74ec252713c4ee9a1d1`. Full CP-04 candidate tested: +`c1c34a13a3448b29c1743b2800bc5937565bac7e`. Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The Pi skill and isolated blind-handoff proof pass, but CP-04's real dogfood milestone @@ -182,7 +183,7 @@ isolated exercise is not represented as Firstmate dispatch or task closure. ## Deterministic gates -Against `bff13871227a1edeb3cbd74ec252713c4ee9a1d1`: +Against `c1c34a13a3448b29c1743b2800bc5937565bac7e`: ```text $ npm run format:check From a33dad3aa662e2b9b28d01f8bccbdf7e30657ac9 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 09:35:47 +0000 Subject: [PATCH 04/13] Prepare reviewed CP-05 dogfood preview --- docs/probes/CP-04.md | 184 ++++++++++++++++++++++++++++++++------ docs/proposals/CP-05.yaml | 23 ----- 2 files changed, 157 insertions(+), 50 deletions(-) delete mode 100644 docs/proposals/CP-05.yaml diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index be8e5bc..692dda4 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -7,10 +7,10 @@ Date: 2026-09-27. Branch: `fm/factory-cp04`, stacked on verified CP-03 Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The Pi skill and isolated blind-handoff proof pass, but CP-04's real dogfood milestone -remains open: CP-03 PR #4 is unmerged, no CP-05 item was published to the real -Firstmate home, and no Firstmate-dispatched CP-05 worker closed it. The tracked -`docs/proposals/CP-05.yaml` is a proposal, not a backlog record or CP-05 -implementation. +remains open until the reviewed CP-05 item is published, dispatched by Firstmate, +and closed with its expected proof. The initial evidence below records the state +before CP-03 merged; the post-merge continuation records the current named-home +preview. No CP-05 implementation is included. ## Isolation and upstream state @@ -200,36 +200,166 @@ $ npm run build && node --test \ exit=0; 1 passed, 0 failed ``` -## CP-05 and delivery hold +## Post-merge continuation and CP-05 contracts + +On 2026-09-28, `origin/main` and the primary Factory source checkout both resolved +to CP-03 merge `c15605edd924b07f6e0eb98e6fd3de57a2e0f52b`; its tree +`84b410487fcdf81e4613a46c894b9930039f6696` equals verified CP-03 head +`b72da4508f6d845e2bea5545b7a627254dba12d6`'s tree. The CP-04 branch retains all +three CP-04 commits on that preserved CP-03 head, and CP-03 is an ancestor of +main. The earlier stacked-base no-mistakes hold is therefore superseded; the +full gate is still deferred until the dogfood milestone can truthfully complete. + +The former out-of-band proposal is now the minimal publishable contract set: +`.factory/project.yaml`, `.factory/completion.yaml`, and +`.factory/tasks/CP-05.yaml`. `factory validate --root . --json` exited 0 with one +task, two conditions, and order `CP-05`. The task advances exactly P-03 and P-04. +The completion contract metadata explicitly scopes this bootstrap contract to +those CP-05 conditions; `COMPLETION.md` remains authority for all Factory V0/V1 +gates, so this subset must never be presented as full product completion. No new +consequential product choice was needed: the original project, architecture, +completion, build-plan, and contract documents determine the behavior and leave +Firstmate as dispatch owner. + +After `ctx sync --root . --json`, generation 2 was `CLEAN` with verified +`BAAI/bge-small-en-v1.5` and `HYBRID_SEMANTIC`. A 15,000-token Factory context +attempt failed because the remaining CTX budget triggered CTX's serialized-budget +error; 20,000 was `PARTIAL`. The explicit 30,000-token ceiling succeeded while +the generated CP-05 pack actually used 12,888 estimated tokens / 38,663 bytes. +It includes all five required originals and one attributed integration excerpt; +its receipt records contract digest +`34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646`, pack digest +`86631975148915631fdb58fef3e6008e1832f9c6d7201db049250c0925534c55`, generation +2, and `HYBRID_SEMANTIC`. Generated packs and probe output remain ignored. + +## Exact real-home read-only preview + +The named Factory-only home was re-probed at +`/home/ansh/firstmate-factory`. Its registry has exactly +`Factory [no-mistakes-prod-only]`; `.tasks.toml` selects markdown +`data/backlog.md`; `config/backend` is `herdr`; no +`config/backlog-backend` override exists. The actual project source checkout was +clean at main `c15605edd924b07f6e0eb98e6fd3de57a2e0f52b`. Installed boundaries were +Factory's built output, tasks-axi `0.2.5`, Pi/package +`@earendil-works/pi-coding-agent` `0.85.1`, CTX `1.0.0`, Node `v24.20.0`, and +no-mistakes `v1.57.0`. `factory doctor` exited 0 and its tasks-axi probes preserved +the backlog hash. -`docs/proposals/CP-05.yaml` records the next checkpoint's proposed outcome, -acceptance, P-03/P-04 links, exact required authority, and expected evidence. It -is intentionally outside `.factory/tasks/`, cannot be picked up by sync, and -contains no CP-05 implementation. +```text +$ node dist/src/cli.js sync --dry-run --root . \ + --home /home/ansh/firstmate-factory --json +exit=0 +root=/home/ansh/.treehouse/Factory-86709f/3/Factory +home=/home/ansh/firstmate-factory +project={id:factory,repo:Factory,delivery_mode:no-mistakes-prod-only,yolo:false} +backend={tasks_axi:0.2.5,storage:markdown} +summary={create:1,unchanged:0,conflict:0,blocked:0} +record={task_id:CP-05,published_id:factory-factory-cp-05, + contract_sha256:34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646, + depends_on:[],action:create} +created_ids=[] +backlog sha256 before=029b14010f03f894b72853ed3442be2dcad55f438a205d46503103dd2a3e98a7 +backlog sha256 after =029b14010f03f894b72853ed3442be2dcad55f438a205d46503103dd2a3e98a7 +``` + +The exact proposed body is: -The real dependent milestone is held because PR #4 remains open. Before any -publication, CP-03 must land; main, tool versions, named-home registration, -backend, and project mode must be re-probed; and a human must review the exact -read-only preview for that named home. Firstmate alone may then dispatch the -independently scoped CP-05 worker. +```text + +Factory source: factory:factory:CP-05 +Project: factory +Repository: Factory +Contract SHA-256: 34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646 +Contract: .factory/tasks/CP-05.yaml +Complexity: normal +Risk: normal +Delivery request: project-default + +## Project intent +Turn a small, explicit software intent and independently written completion conditions into bounded task contracts that Pi can reason about, CTX can contextualize, and Firstmate can execute and ship through its existing controls. +Audience: One engineer building greenfield software with Pi, Firstmate, Herdr, Treehouse, tasks-axi, no-mistakes, and CTX. + +## Project constraints +- Original tracked project documents are authoritative; retrieved excerpts and generated summaries are not. +- Firstmate alone owns worker dispatch, lifecycle, and delivery controls. +- Backlog closure alone never proves product completion. +- Publication must fail closed on an unverified home, backend, tool version, contract, or conflict. + +## Outcome +Factory reports task evidence separately from project completion and rejects failed or stale proof. + +## Acceptance +- CP05-EVIDENCE: Prose-only pass claims, failed exits, changed contracts, changed release SHAs, and missing artifacts cannot produce valid passing evidence. +- CP05-STATUS: factory status --json reports backlog progress separately from passed, failed, stale, and unverified product conditions. +- P-03: Task evidence is bound to the exact task contract and tested Git SHA, and becomes stale after either changes. +- P-04: Product completion remains NOT COMPLETE when a project-level check fails even after every task is closed. + +## Dependencies +- none + +## Product completion advanced +- P-03 +- P-04 + +## Evidence expected +- unit +- integration + +## Authoritative context to read +- PROJECT.md +- ARCHITECTURE.md +- COMPLETION.md +- BUILD_PLAN.md +- docs/CONTRACTS.md + +## Worker brief +Implement only CP-05: Bind evidence to task contracts and independent product completion. +Deliver the outcome and every acceptance item above in repository Factory. +Read the tracked contract at .factory/tasks/CP-05.yaml and verify its SHA-256 before work. +Do not treat backlog closure as product completion; return exact command, exit code, artifact, and tested Git SHA evidence. +``` + +No apply occurred. Human review of this exact digest/body/home is required before +`sync --apply`; publication is not dispatch, and Firstmate alone may dispatch the +independently scoped CP-05 worker. CP-04/F-09 dogfood remains open until that real +worker closes with executable proof. + +## Post-merge deterministic validation + +The complete contract/preview candidate passed: + +```text +$ npm run format:check +exit=0 +$ npx prettier --check .factory/project.yaml .factory/completion.yaml \ + .factory/tasks/CP-05.yaml +exit=0 +$ npm run lint +exit=0; lint ok +$ npm run typecheck +exit=0 +$ npm test +exit=0; 56 passed, 0 failed +$ node dist/src/cli.js validate --root . --json +exit=0; task_count=1; condition_count=2; task_order=[CP-05] +$ git diff --check +exit=0 +``` -The installed no-mistakes `v1.57.0` home/status and `axi run --help` expose no -base-branch option. This branch tracks `origin/fm/factory-cp03`, while the gate's -recorded origin default is `main`; a full run could not explicitly preserve the -stacked PR base and its rebase step could drop unmerged CP-03 history. Per the -task safety gate, no no-mistakes run was started. This is a delivery hold, not a -skipped or passed gate. +The exact tested candidate SHA is recorded by the following proof-only commit. ## Changed files and residual risks - `skills/factory/SKILL.md` -- `docs/proposals/CP-05.yaml` +- `.factory/project.yaml` +- `.factory/completion.yaml` +- `.factory/tasks/CP-05.yaml` - `docs/probes/CP-04.md` - `BUILD_PLAN.md` (only the two proven CP-04 checklist items) -Residual risks: CP-03 is unmerged; real named-home preview/publication, -Firstmate dispatch, CP-05 closure, and the first real task/worker trace are -unrun; no-mistakes cannot safely preserve this stacked base through its full -v1.57.0 gate; automatic model skill choice can be distracted by unrelated -global skills. No live backlog, Firstmate configuration, shared daemon, -credentials, Herdr lifecycle, merge, deployment, or default branch was changed. +Residual risks: real publication, Firstmate dispatch, CP-05 closure, and the first +real task/worker trace remain unrun pending preview review; the 30,000-token pack +ceiling exceeds the normal default even though actual output was 12,888 tokens; +automatic model skill choice can be distracted by unrelated global skills. No +live backlog, Firstmate configuration, shared daemon, credentials, Herdr +lifecycle, merge, deployment, or default branch was changed. diff --git a/docs/proposals/CP-05.yaml b/docs/proposals/CP-05.yaml deleted file mode 100644 index ecc24f7..0000000 --- a/docs/proposals/CP-05.yaml +++ /dev/null @@ -1,23 +0,0 @@ -# Tracked proposal only. Do not publish until CP-03 is merged, the named home is -# re-probed, and a human reviews the exact `factory sync --dry-run` preview. -schema_version: 1 -id: CP-05 -title: Bind evidence to task contracts and independent product completion -outcome: Factory reports task evidence separately from project completion and rejects failed or stale proof. -depends_on: [] -complexity: normal -risk: normal -acceptance: - - id: CP05-EVIDENCE - statement: Prose-only pass claims, failed exits, changed contracts, changed release SHAs, and missing artifacts cannot produce valid passing evidence. - - id: P-03 - statement: Task evidence is bound to the exact task contract and tested Git SHA, and becomes stale after either changes. - - id: P-04 - statement: Product completion remains NOT COMPLETE when a project-level check fails even after every task is closed. -advances: [P-03, P-04] -context: - topics: [evidence receipts, stale proof, release candidate, independent completion] - required: [PROJECT.md, ARCHITECTURE.md, COMPLETION.md, BUILD_PLAN.md, docs/CONTRACTS.md] -evidence: - required: [unit, integration] -delivery: project-default From 4394a164561c3853b562d182c279db302ae5148f Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 09:35:57 +0000 Subject: [PATCH 05/13] Record CP-05 preview candidate SHA --- docs/probes/CP-04.md | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index 692dda4..c7b8774 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -346,7 +346,9 @@ $ git diff --check exit=0 ``` -The exact tested candidate SHA is recorded by the following proof-only commit. +These commands tested candidate SHA +`4d23606a8d1a496af4e851a844928ae3a8e0c95e`; the following commit changes only +this proof record. ## Changed files and residual risks From 93e5142688f93023cb3af90c6049e5e9c1caf9fc Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 09:45:18 +0000 Subject: [PATCH 06/13] Record authorized CP-05 publication --- docs/probes/CP-04.md | 52 +++++++++++++++++++++++++++++++++++--------- 1 file changed, 42 insertions(+), 10 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index c7b8774..c393fd1 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -319,10 +319,42 @@ Read the tracked contract at .factory/tasks/CP-05.yaml and verify its SHA-256 be Do not treat backlog closure as product completion; return exact command, exit code, artifact, and tested Git SHA evidence. ``` -No apply occurred. Human review of this exact digest/body/home is required before -`sync --apply`; publication is not dispatch, and Firstmate alone may dispatch the -independently scoped CP-05 worker. CP-04/F-09 dogfood remains open until that real -worker closes with executable proof. +The preview above did not apply. Captain approval subsequently named this exact +home, ID, digest, and body. Publication is not dispatch, and Firstmate alone may +dispatch the independently scoped CP-05 worker. CP-04/F-09 dogfood remains open +until that real worker closes with executable proof. + +## Authorized publication proof + +Before applying, the committed branch was clean at +`db6ed7ae50eac2f2afa5ecec789454f13f22f826`, the task contract still hashed to +`34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646`, and a new +`doctor` plus dry-run exited 0. Other Firstmate activity had changed the live +backlog since the earlier reviewed preview, so the fresh preflight used hash +`2c167bb2e41382e6a8640b80fcbc76c095c21797b088baf46c1ea61d210ca238`; it still +reported exactly one create, no unchanged/conflict/blocked records, the same +approved ID/digest/body/home, and no backlog mutation. + +Exactly one authorized apply then ran: + +```text +$ node dist/src/cli.js sync --apply --root . \ + --home /home/ansh/firstmate-factory --json +exit=0 +summary={create:1,unchanged:0,conflict:0,blocked:0} +record={task_id:CP-05,published_id:factory-factory-cp-05, + contract_sha256:34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646, + depends_on:[],action:create} +created_ids=[factory-factory-cp-05] +backlog sha256 before=2c167bb2e41382e6a8640b80fcbc76c095c21797b088baf46c1ea61d210ca238 +backlog sha256 after =4be6f927dc68d15621a85794a98440f9f52ae23a6e83907d6ba37a973a0caa24 +``` + +Installed `tasks-axi show factory-factory-cp-05 --full` then returned the exact +approved title/body, `state=queued`, `repo=Factory`, no blocker, no hold, and no +closure. `tasks-axi ready --repo Factory` returned this one item as ready. No +worker was dispatched by Factory or this CP-04 worker; Firstmate must perform and +own that transition. ## Post-merge deterministic validation @@ -359,9 +391,9 @@ this proof record. - `docs/probes/CP-04.md` - `BUILD_PLAN.md` (only the two proven CP-04 checklist items) -Residual risks: real publication, Firstmate dispatch, CP-05 closure, and the first -real task/worker trace remain unrun pending preview review; the 30,000-token pack -ceiling exceeds the normal default even though actual output was 12,888 tokens; -automatic model skill choice can be distracted by unrelated global skills. No -live backlog, Firstmate configuration, shared daemon, credentials, Herdr -lifecycle, merge, deployment, or default branch was changed. +Residual risks: publication passed, but Firstmate dispatch, CP-05 closure, and the +first real task/worker trace remain unrun; the 30,000-token pack ceiling exceeds +the normal default even though actual output was 12,888 tokens; automatic model +skill choice can be distracted by unrelated global skills. The single approved +backlog item was created, but no Firstmate configuration, shared daemon, +credentials, Herdr lifecycle, merge, deployment, or default branch was changed. From 89ce57e2e4724d1ae68ed78349dcce821d9f4c64 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 09:55:32 +0000 Subject: [PATCH 07/13] Record Firstmate CP-05 dispatch --- docs/probes/CP-04.md | 34 ++++++++++++++++++++++++++-------- 1 file changed, 26 insertions(+), 8 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index c393fd1..ad96384 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -353,8 +353,25 @@ backlog sha256 after =4be6f927dc68d15621a85794a98440f9f52ae23a6e83907d6ba37a973a Installed `tasks-axi show factory-factory-cp-05 --full` then returned the exact approved title/body, `state=queued`, `repo=Factory`, no blocker, no hold, and no closure. `tasks-axi ready --repo Factory` returned this one item as ready. No -worker was dispatched by Factory or this CP-04 worker; Firstmate must perform and -own that transition. +worker was dispatched by Factory or this CP-04 worker. + +## Firstmate dispatch observed + +Firstmate subsequently dispatched the item as a separate `kind=ship`, +`mode=no-mistakes`, `yolo=off` Pi worker in isolated worktree +`/home/ansh/.treehouse/Factory-86709f/4/Factory`. Its durable status reported: + +```text +working: isolated CP-05 branch created from c15605e; beginning contract import and implementation +``` + +A fresh installed `tasks-axi show factory-factory-cp-05 --full` exited 0 with +`state=in_flight`, the same exact body/digest, no blocker or hold, and no closure; +`tasks-axi ready --repo Factory` returned zero queued work. Firstmate attested +that the independent worker started from landed CP-03 main and received only the +exact contract files from CP-04 commit `135f21d`. This establishes real +publication and Firstmate-owned dispatch, not closure: CP-05 implementation, +executable evidence, delivery, and task closure remain pending. ## Post-merge deterministic validation @@ -391,9 +408,10 @@ this proof record. - `docs/probes/CP-04.md` - `BUILD_PLAN.md` (only the two proven CP-04 checklist items) -Residual risks: publication passed, but Firstmate dispatch, CP-05 closure, and the -first real task/worker trace remain unrun; the 30,000-token pack ceiling exceeds -the normal default even though actual output was 12,888 tokens; automatic model -skill choice can be distracted by unrelated global skills. The single approved -backlog item was created, but no Firstmate configuration, shared daemon, -credentials, Herdr lifecycle, merge, deployment, or default branch was changed. +Residual risks: publication and independent Firstmate dispatch passed, but CP-05 +executable evidence, delivery, closure, and the completed worker trace remain +pending; the 30,000-token pack ceiling exceeds the normal default even though +actual output was 12,888 tokens; automatic model skill choice can be distracted +by unrelated global skills. The single approved backlog item was created, but no +Firstmate configuration, shared daemon, credentials, merge, deployment, or +default branch was changed by this CP-04 worker. From d6db80f4e06d8d23745eed56c7af5a7f7f768d4e Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 11:01:43 +0000 Subject: [PATCH 08/13] Reconcile CP-04 onto landed CP-05 --- docs/probes/CP-04.md | 50 +++++++++++++++++++++++++++++++++----------- 1 file changed, 38 insertions(+), 12 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index ad96384..ddd9e6d 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -370,8 +370,34 @@ A fresh installed `tasks-axi show factory-factory-cp-05 --full` exited 0 with `tasks-axi ready --repo Factory` returned zero queued work. Firstmate attested that the independent worker started from landed CP-03 main and received only the exact contract files from CP-04 commit `135f21d`. This establishes real -publication and Firstmate-owned dispatch, not closure: CP-05 implementation, -executable evidence, delivery, and task closure remain pending. +publication and Firstmate-owned dispatch, not closure. + +## CP-05 delivery and guarded base reconciliation + +The independently dispatched worker's PR #5, `feat: add evidence-bound Factory +status`, merged at main `3bc6e46c6cfb0f78b33103eacb86d9ea0006c15f`. `gh-axi pr +view 5` reported merged at 2026-09-28T10:58:07Z with two checks passed and none +failed; `gh-axi pr checks 5` independently reported `2 passed, 0 failed`. The +merge tree `00b797a88c10efacc4868b737bb246f82ba85757` exactly equals validated +CP-05 head `4693dc7b0e43f31b5b701072b5242d821e347ec6`'s tree. + +This CP-04 branch was clean before a guarded local rebase from landed CP-03 onto +that main. Safety branch `fm/factory-cp04-pre-cp05-reconcile-29bd9a5` preserves +the pre-reconciliation tip. `git range-diff` maps all seven CP-04 commits in +order; the only absorbed changes are the three CP-05 contract files now already +identical on main. The resulting CP-04 diff contains only `BUILD_PLAN.md`, +`docs/probes/CP-04.md`, and `skills/factory/SKILL.md`. No nonredundant CP-04 +change was dropped, no conflict was inferred away, and no forced operation or +remote update occurred. + +The task is not administratively closed. Installed `tasks-axi show +factory-factory-cp-05 --full` still reports `state=in_flight`, `closed=-`, and no +blocker or hold. Firstmate reports that the original worker also has a distinct +local fix commit `ff23573` under safe reconciliation; the backlog body now has a +Firstmate captain-resolution prefix while preserving the Factory publication +marker and digest. Therefore landed code and passing CI are recorded as delivery +evidence, but CP-04/F-09 remains open until Firstmate resolves that work without +loss and closes the task. ## Post-merge deterministic validation @@ -401,17 +427,17 @@ this proof record. ## Changed files and residual risks +CP-04's current diff from landed main contains: + - `skills/factory/SKILL.md` -- `.factory/project.yaml` -- `.factory/completion.yaml` -- `.factory/tasks/CP-05.yaml` - `docs/probes/CP-04.md` - `BUILD_PLAN.md` (only the two proven CP-04 checklist items) -Residual risks: publication and independent Firstmate dispatch passed, but CP-05 -executable evidence, delivery, closure, and the completed worker trace remain -pending; the 30,000-token pack ceiling exceeds the normal default even though -actual output was 12,888 tokens; automatic model skill choice can be distracted -by unrelated global skills. The single approved backlog item was created, but no -Firstmate configuration, shared daemon, credentials, merge, deployment, or -default branch was changed by this CP-04 worker. +The CP-05 contracts remain tracked on main but are no longer duplicated in the +CP-04 diff. Residual risks: publication, independent Firstmate dispatch, CP-05 +PR delivery, and main CI passed, but administrative closure and safe +reconciliation of the worker's distinct local fix remain pending; the +30,000-token pack ceiling exceeds the normal default even though actual output +was 12,888 tokens; automatic model skill choice can be distracted by unrelated +global skills. No Firstmate configuration, shared daemon, credentials, merge, +deployment, or default branch was changed by this CP-04 worker. From 57785cf34d2044f9e9e82833f74ab0b84dcbc5b7 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 11:06:18 +0000 Subject: [PATCH 09/13] Complete CP-04 dogfood evidence --- BUILD_PLAN.md | 2 +- docs/probes/CP-04.md | 89 ++++++++++++++++++++++++++++++++++---------- 2 files changed, 70 insertions(+), 21 deletions(-) diff --git a/BUILD_PLAN.md b/BUILD_PLAN.md index 1a07218..f9a413f 100644 --- a/BUILD_PLAN.md +++ b/BUILD_PLAN.md @@ -71,7 +71,7 @@ - [x] Write the skill using `docs/WORKFLOW.md`; explain what the CLI does, when to use it, and when to stop for a real decision. - [x] Load it in Pi, invoke it explicitly and automatically, and confirm it uses existing commands rather than narrating a fictional `/factory run`. -- [ ] Publish CP-05 as a testable task in Factory's own backlog, then observe real Firstmate dispatch and closure. **Gate:** F-09 and the first real task/worker trace. Dogfooding remains unproven if only task publication succeeds. +- [x] Publish CP-05 as a testable task in Factory's own backlog, then observe real Firstmate dispatch and closure. **Gate:** F-09 and the first real task/worker trace. Dogfooding remains unproven if only task publication succeeds. ## CP-05 — Evidence and independent completion diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index ddd9e6d..b06a553 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -6,11 +6,12 @@ Date: 2026-09-27. Branch: `fm/factory-cp04`, stacked on verified CP-03 `c1c34a13a3448b29c1743b2800bc5937565bac7e`. Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The -Pi skill and isolated blind-handoff proof pass, but CP-04's real dogfood milestone -remains open until the reviewed CP-05 item is published, dispatched by Firstmate, -and closed with its expected proof. The initial evidence below records the state -before CP-03 merged; the post-merge continuation records the current named-home -preview. No CP-05 implementation is included. +Pi skill, transcript-free blind handoff, real CP-05 publication, Firstmate-owned +dispatch, executable worker proof, PR/main CI, and task closure now pass. The +report retains each earlier hold as chronological evidence and ends with the +verified closure trace. CP-05 implementation came only from its separate +Firstmate worker and landed main; this CP-04 branch contains no CP-05 +implementation diff. ## Isolation and upstream state @@ -390,14 +391,63 @@ identical on main. The resulting CP-04 diff contains only `BUILD_PLAN.md`, change was dropped, no conflict was inferred away, and no forced operation or remote update occurred. -The task is not administratively closed. Installed `tasks-axi show -factory-factory-cp-05 --full` still reports `state=in_flight`, `closed=-`, and no -blocker or hold. Firstmate reports that the original worker also has a distinct -local fix commit `ff23573` under safe reconciliation; the backlog body now has a -Firstmate captain-resolution prefix while preserving the Factory publication -marker and digest. Therefore landed code and passing CI are recorded as delivery -evidence, but CP-04/F-09 remains open until Firstmate resolves that work without -loss and closes the task. +At base-reconciliation time the task was not yet administratively closed. +Installed `tasks-axi show factory-factory-cp-05 --full` still reported +`state=in_flight`, `closed=-`, and no blocker or hold. Firstmate reported that the +original worker also had a distinct local draft `ff23573`; the backlog body gained +a Firstmate captain-resolution prefix while preserving the Factory publication +marker and digest. Landed code and passing CI were therefore recorded as delivery +evidence, not premature closure. + +## CP-05 executable evidence and closure + +Captain explicitly approved discarding only superseded local draft `ff23573` and +its isolated copy after Firstmate established that it was not landed work. +Firstmate then completed guarded cleanup and closed the published task. A final +read-only installed boundary check returned: + +```text +$ cd /home/ansh/firstmate-factory +$ tasks-axi show factory-factory-cp-05 --full +exit=0 +state=done +closed=2026-09-28 +repo=Factory +blocked=no +held=no +link=pr:https://github.com/0xnotdev/Software_factory/pull/5 +Factory contract SHA-256=34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646 +``` + +The merged PR records executable CP-05 worker proof at validated head +`4693dc7b0e43f31b5b701072b5242d821e347ec6`: + +```text +$ npm run build && node --test \ + dist/test/evidence.test.js dist/test/status.test.js +exit=0; 10 passed, 0 failed +$ node dist/src/cli.js evidence CP-05 --root . --json +exit=0; contract_sha256=34864d74...; missing receipt is unverified, not pass +$ node dist/src/cli.js status --root . --json +exit=0; task and product axes separate; product.status=NOT COMPLETE; +product.summary={passed:0,failed:0,stale:0,unverified:2} +``` + +PR #5's no-mistakes attestation records intent, rebase, review, test, document, +lint, push, PR, and CI workflow evidence. `gh-axi pr view 5 --full` reported +merged at 2026-09-28T10:58:07Z, and `gh-axi pr checks 5` returned exactly two +passed checks and no failures. Main +`3bc6e46c6cfb0f78b33103eacb86d9ea0006c15f` has tree +`00b797a88c10efacc4868b737bb246f82ba85757`, exactly matching validated CP-05 +head. The tracked CP-05 contract on this branch and main still has the authorized +digest `34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646`. + +This completes the real trace required by CP-04: reviewed Factory publication, +Firstmate dispatch in an isolated copy, independently executed proof, normal +no-mistakes PR/CI delivery, and Firstmate closure. Combined with the earlier +transcript-free blind exercise—which explicitly requested and verified exact +original documents rather than claiming prior conversation knowledge—this +satisfies F-09 without treating task closure as product completion. ## Post-merge deterministic validation @@ -434,10 +484,9 @@ CP-04's current diff from landed main contains: - `BUILD_PLAN.md` (only the two proven CP-04 checklist items) The CP-05 contracts remain tracked on main but are no longer duplicated in the -CP-04 diff. Residual risks: publication, independent Firstmate dispatch, CP-05 -PR delivery, and main CI passed, but administrative closure and safe -reconciliation of the worker's distinct local fix remain pending; the -30,000-token pack ceiling exceeds the normal default even though actual output -was 12,888 tokens; automatic model skill choice can be distracted by unrelated -global skills. No Firstmate configuration, shared daemon, credentials, merge, -deployment, or default branch was changed by this CP-04 worker. +CP-04 diff. Residual risks: the 30,000-token pack ceiling exceeds the normal +default even though actual output was 12,888 tokens; automatic model skill choice +can be distracted by unrelated global skills; native Windows and macOS remain +unverified as already recorded by earlier checkpoints. No Firstmate +configuration, shared daemon, credentials, merge, deployment, or default branch +was changed by this CP-04 worker. From fa701ec4993987fea2ec33c30459939b8266dffe Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 11:08:47 +0000 Subject: [PATCH 10/13] Record final CP-04 dogfood validation --- docs/probes/CP-04.md | 36 +++++++++++++++++++++--------------- 1 file changed, 21 insertions(+), 15 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index b06a553..8ed1041 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -1,9 +1,11 @@ # CP-04 probe report — Pi workflow packaging and initial dogfood -Date: 2026-09-27. Branch: `fm/factory-cp04`, stacked on verified CP-03 -`b72da4508f6d845e2bea5545b7a627254dba12d6`. Skill implementation SHA: -`bff13871227a1edeb3cbd74ec252713c4ee9a1d1`. Full CP-04 candidate tested: -`c1c34a13a3448b29c1743b2800bc5937565bac7e`. +Date: 2026-09-27 through 2026-09-28. Branch: `fm/factory-cp04`, initially +stacked on verified CP-03 `b72da4508f6d845e2bea5545b7a627254dba12d6` and later +guardedly rebased onto landed CP-05 main. Original skill implementation SHA: +`bff13871227a1edeb3cbd74ec252713c4ee9a1d1`; rebased equivalent: +`23210405cfb5bd56991f6d37149c477c2d588170`. Final dogfood candidate tested: +`57785cf34d2044f9e9e82833f74ab0b84dcbc5b7`. Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The Pi skill, transcript-free blind handoff, real CP-05 publication, Firstmate-owned @@ -449,31 +451,35 @@ transcript-free blind exercise—which explicitly requested and verified exact original documents rather than claiming prior conversation knowledge—this satisfies F-09 without treating task closure as product completion. -## Post-merge deterministic validation +## Final deterministic validation -The complete contract/preview candidate passed: +Against dogfood candidate `57785cf34d2044f9e9e82833f74ab0b84dcbc5b7`: ```text +$ npm ci +exit=0; 0 vulnerabilities $ npm run format:check exit=0 -$ npx prettier --check .factory/project.yaml .factory/completion.yaml \ - .factory/tasks/CP-05.yaml -exit=0 $ npm run lint exit=0; lint ok $ npm run typecheck exit=0 $ npm test -exit=0; 56 passed, 0 failed -$ node dist/src/cli.js validate --root . --json -exit=0; task_count=1; condition_count=2; task_order=[CP-05] +exit=0; 66 passed, 0 failed $ git diff --check exit=0 +$ sha256sum .factory/tasks/CP-05.yaml +34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646 ``` -These commands tested candidate SHA -`4d23606a8d1a496af4e851a844928ae3a8e0c95e`; the following commit changes only -this proof record. +Installed Pi `0.85.1` RPC discovery again exited 0 and returned +`skill:factory` from this checkout. An explicit `/skill:factory` invocation and +a separate automatic-matching invocation used only the Factory skill and read +tool in ephemeral no-session processes; both exited 0, named only `doctor`, +`init`, `validate`, `context`, and `sync --dry-run|--apply`, and identified +Firstmate as dispatch owner. The automatic JSON trace contains the actual read of +`skills/factory/SKILL.md`. Generated traces remain ignored and are not shipped. +The following commit changes only this proof record. ## Changed files and residual risks From b17159e93e1b11a778074c8aac5910da6c7cf478 Mon Sep 17 00:00:00 2001 From: Factory Crewmate Date: Mon, 28 Sep 2026 11:23:15 +0000 Subject: [PATCH 11/13] no-mistakes(document): Fix CP-04 proof wording --- docs/probes/CP-04.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index 8ed1041..f0113cb 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -487,7 +487,7 @@ CP-04's current diff from landed main contains: - `skills/factory/SKILL.md` - `docs/probes/CP-04.md` -- `BUILD_PLAN.md` (only the two proven CP-04 checklist items) +- `BUILD_PLAN.md` (only the three proven CP-04 checklist items) The CP-05 contracts remain tracked on main but are no longer duplicated in the CP-04 diff. Residual risks: the 30,000-token pack ceiling exceeds the normal From 13bd827c236cd7fa0cbcc73576ff1a4df97c4249 Mon Sep 17 00:00:00 2001 From: Factory Maintainer Date: Mon, 28 Sep 2026 17:01:27 +0000 Subject: [PATCH 12/13] docs(cp04): correct landed Factory command list --- docs/probes/CP-04.md | 25 ++++++++++++++++--------- skills/factory/SKILL.md | 2 +- 2 files changed, 17 insertions(+), 10 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index f0113cb..d90a9d5 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -76,9 +76,11 @@ package without changing the user's Pi settings. The skill links to the deeper workflow and contract references, keeps context bounded, requires the exact named-home preflight and a human-reviewed preview, -and leaves dispatch to Firstmate. It names only the implemented commands: -`doctor`, `init`, `validate`, `context`, and `sync --dry-run|--apply`. It does not -advertise `/factory`, `factory run`, `evidence`, `status`, or `inspect`. +and leaves dispatch to Firstmate. Against the final tree, it names the complete +implemented command set: `doctor`, `init`, `validate`, `context TASK-ID`, +`sync --dry-run|--apply`, `evidence TASK-ID`, and `status` (including +`status --json`). It continues to forbid absent `/factory`, `factory run`, and +`factory inspect` commands. Deterministic discovery used Pi's documented RPC `get_commands` interface: @@ -99,8 +101,8 @@ $ PI_OFFLINE=1 pi --offline --approve --no-context-files --no-session \ --provider openai-codex --model gpt-5 -p \ '/skill:factory Give only the ordered implemented Factory CLI command names ...' exit=0 -result=doctor, init, validate, context, sync --dry-run, sync --apply; -dispatch owner=Firstmate +result=doctor, init, validate, context TASK-ID, sync --dry-run, sync --apply, +evidence TASK-ID, status --json; dispatch owner=Firstmate ``` Automatic matching ran in another ephemeral, transcript-free Pi process with @@ -475,11 +477,16 @@ $ sha256sum .factory/tasks/CP-05.yaml Installed Pi `0.85.1` RPC discovery again exited 0 and returned `skill:factory` from this checkout. An explicit `/skill:factory` invocation and a separate automatic-matching invocation used only the Factory skill and read -tool in ephemeral no-session processes; both exited 0, named only `doctor`, -`init`, `validate`, `context`, and `sync --dry-run|--apply`, and identified -Firstmate as dispatch owner. The automatic JSON trace contains the actual read of +tool in ephemeral no-session processes; both exited 0, named the complete +implemented command list (`doctor`, `init`, `validate`, `context TASK-ID`, +`sync --dry-run|--apply`, `evidence TASK-ID`, and `status --json`), and +identified Firstmate as dispatch owner. The automatic JSON trace contains the actual read of `skills/factory/SKILL.md`. Generated traces remain ignored and are not shipped. -The following commit changes only this proof record. +The following commit changes only this proof record. The final skill command +list was checked against `node dist/src/cli.js --help`: `doctor`, `init`, +`validate`, `context TASK-ID`, `sync --dry-run|--apply`, `evidence TASK-ID`, +and `status`; `status --json` is the machine-readable form. The skill still +forbids `/factory`, `factory run`, and `factory inspect`, which are absent. ## Changed files and residual risks diff --git a/skills/factory/SKILL.md b/skills/factory/SKILL.md index 5222499..ae94486 100644 --- a/skills/factory/SKILL.md +++ b/skills/factory/SKILL.md @@ -57,4 +57,4 @@ Apply must repeat preflight and fail closed. Never edit a backlog file directly, ## Current command limit -At this checkpoint the implemented Factory CLI commands are only `doctor`, `init`, `validate`, `context`, and `sync --dry-run|--apply`. Do not invent `/factory`, `factory run`, `factory evidence`, `factory status`, or `factory inspect` invocations. Backlog closure alone never proves product completion. +The implemented Factory CLI commands are `doctor`, `init`, `validate`, `context TASK-ID`, `sync --dry-run|--apply`, `evidence TASK-ID`, and `status` (including `status --json`). Use the actual installed CLI help when syntax matters. Do not invent `/factory`, `factory run`, or `factory inspect` invocations. Backlog closure alone never proves product completion. From 7b49889aefc46f853091006632c41f1a63546102 Mon Sep 17 00:00:00 2001 From: Factory CP-04 no-mistakes Date: Mon, 28 Sep 2026 17:08:45 +0000 Subject: [PATCH 13/13] no-mistakes(review): Correct CP-04 validation provenance --- docs/probes/CP-04.md | 36 +++++++++++++++++++++++------------- 1 file changed, 23 insertions(+), 13 deletions(-) diff --git a/docs/probes/CP-04.md b/docs/probes/CP-04.md index d90a9d5..696504b 100644 --- a/docs/probes/CP-04.md +++ b/docs/probes/CP-04.md @@ -5,7 +5,8 @@ stacked on verified CP-03 `b72da4508f6d845e2bea5545b7a627254dba12d6` and later guardedly rebased onto landed CP-05 main. Original skill implementation SHA: `bff13871227a1edeb3cbd74ec252713c4ee9a1d1`; rebased equivalent: `23210405cfb5bd56991f6d37149c477c2d588170`. Final dogfood candidate tested: -`57785cf34d2044f9e9e82833f74ab0b84dcbc5b7`. +`57785cf34d2044f9e9e82833f74ab0b84dcbc5b7`. Later source-correction +starting SHA under review: `13bd827c236cd7fa0cbcc73576ff1a4df97c4249`. Active checkpoint: `BUILD_PLAN.md` CP-04 only. Acceptance exercised: F-09. The Pi skill, transcript-free blind handoff, real CP-05 publication, Firstmate-owned @@ -474,19 +475,28 @@ $ sha256sum .factory/tasks/CP-05.yaml 34864d74fd6a831ef57b9e85fea124bd93598a674201c680bab018ce5e6c7646 ``` -Installed Pi `0.85.1` RPC discovery again exited 0 and returned -`skill:factory` from this checkout. An explicit `/skill:factory` invocation and -a separate automatic-matching invocation used only the Factory skill and read -tool in ephemeral no-session processes; both exited 0, named the complete -implemented command list (`doctor`, `init`, `validate`, `context TASK-ID`, -`sync --dry-run|--apply`, `evidence TASK-ID`, and `status --json`), and -identified Firstmate as dispatch owner. The automatic JSON trace contains the actual read of +At that dogfood candidate, installed Pi `0.85.1` RPC discovery exited 0 and +returned `skill:factory`. The explicit and automatic Pi probes against that tree +validated the then-current skill boundary: `doctor`, `init`, `validate`, +`context TASK-ID`, and `sync --dry-run|--apply`; the same skill text still +forbade `/factory`, `factory run`, `factory evidence`, `factory status`, and +`factory inspect`. Those historical probes did not validate `evidence TASK-ID` or +`status --json` at `57785cf34d2044f9e9e82833f74ab0b84dcbc5b7`. + +The later source-correction worktree based on +`13bd827c236cd7fa0cbcc73576ff1a4df97c4249` checked the final skill command list +against `node dist/src/cli.js --help`: `doctor`, `init`, `validate`, +`context TASK-ID`, `sync --dry-run|--apply`, `evidence TASK-ID`, and `status`; +`status --json` is the machine-readable form. Installed Pi `0.85.1` RPC +discovery returned `skill:factory` from the corrected checkout. An explicit +`/skill:factory` invocation and a separate automatic-matching invocation used +only the Factory skill and read tool in ephemeral no-session processes; both +exited 0, named the corrected implemented command list including +`evidence TASK-ID` and `status --json`, and identified Firstmate as dispatch +owner. The automatic JSON trace contains the actual read of `skills/factory/SKILL.md`. Generated traces remain ignored and are not shipped. -The following commit changes only this proof record. The final skill command -list was checked against `node dist/src/cli.js --help`: `doctor`, `init`, -`validate`, `context TASK-ID`, `sync --dry-run|--apply`, `evidence TASK-ID`, -and `status`; `status --json` is the machine-readable form. The skill still -forbids `/factory`, `factory run`, and `factory inspect`, which are absent. +The skill still forbids `/factory`, `factory run`, and `factory inspect`, which +are absent. ## Changed files and residual risks