diff --git a/wiki/log/2026-07-26-markets-contract-custody-reconciliation.md b/wiki/log/2026-07-26-markets-contract-custody-reconciliation.md new file mode 100644 index 00000000..0ac30c0b --- /dev/null +++ b/wiki/log/2026-07-26-markets-contract-custody-reconciliation.md @@ -0,0 +1,61 @@ +# Markets inherit exact contract and evidence custody + +``` +Type: log +``` + +Date: 2026-07-26 +Scope: `wiki/mechanics/markets.md` and its B1 dependency closure +Simulation behavior change: none + +## Finding + +A fresh audit of the never-covered B3 markets spec found that its high-level +scheme shape had not absorbed the exact B1 economy now beneath it. The page +still authorized an operation to resolve into “a payout” plus “a detection +signature” without requiring the AccountGraph transfer, financial-record mail, +source carrier, routed evidence, or immutable accepted terms that current +Moonlight, economy, messages, detection, and flow law require. + +That was a future implementation escape hatch: B3 could satisfy the literal +acceptance criteria with direct balance and risk mutations, then wrap those +scalars in a front card. It would have replaced the B1 causal substrate instead +of scaling it. + +## Reconciliation + +- A market operation now binds immutable terms and real resources, advances on + the day clock, performs a typed world/account act, and carries its paperwork + and evidence through ordinary routes. +- Random outcomes still use the saved seeded RNG, but a roll is never itself a + payout or observer consequence. +- Front rates, reliability, and exposure derive from exact child flows, + positions, contracts, and records. Routine children may fold; consequential + exceptions remain exact. +- Laundering must change real amounts, records, and routes rather than subtract + abstract heat. +- Greenfield purchase and construction now inherit exact account, + Paper/Financial, and physical custody. +- The future player surface follows the established glance, focus, drill-down + grammar and does not invent an income/day mirror for discrete contracts. +- The work order now claims the actual B1 seed modules (`income.rs` and + `sim/economy.rs`) and its roadmap dispatch repeats the no-side-channel + boundary rather than asking only for payout plus signature. +- The B1 income mirror now names external counterparties as exact AccountGraph + nodes, keeps ordinary financial-record mail distinct from the additional + banked external trail, and defines an operation by its causal acts rather + than the retired payout-plus-signature shorthand. +- Missing transport inherits the authored B1 order rather than an abstract + fallback: a carrier-dependent operation remains blocked before settlement, + while an irreversible account act may remain landed with its unroutable + evidence dropped. Neither case invents ambient heat or suspicion. + +## Defense + +The flow law requires money to move on the account graph and evidence to ride +real carriers toward observer endpoints. `economy.md`, `messages.md`, +`detection.md`, and the implemented Moonlight slice prove that boundary at B1. +The self-similar-scale law requires the larger market to aggregate those same +objects rather than replacing them with a bespoke scalar. This amendment makes +those existing laws executable acceptance criteria for the deferred B3 work; +it does not change current runtime. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index d406e75d..ced3261a 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -21,6 +21,11 @@ add or amend a session log, then re-run the generator. - Intent: (see session log) - Log: [wiki/log/2026-07-26-moonlight-doctrine-mirror-reconciliation.md](2026-07-26-moonlight-doctrine-mirror-reconciliation.md) +## 2026-07-26 - Markets inherit exact contract and evidence custody + +- Intent: (see session log) +- Log: [wiki/log/2026-07-26-markets-contract-custody-reconciliation.md](2026-07-26-markets-contract-custody-reconciliation.md) + ## 2026-07-26 - Keep the Thought effects lab named by its current scope - Intent: (see session log) diff --git a/wiki/log/decisions/2026-07-26.md b/wiki/log/decisions/2026-07-26.md index 8a59afca..c91f6b2f 100644 --- a/wiki/log/decisions/2026-07-26.md +++ b/wiki/log/decisions/2026-07-26.md @@ -54,3 +54,35 @@ Owner: [plots.md](../../mechanics/plots.md). Owner: [income.md](../../mechanics/income.md), with doctrine in [system-laws.md](../../mechanics/system-laws.md). + +## B3 markets extend exact B1 custody + +### RECONCILED — EXISTING LAW + +- The deferred markets/fronts work may aggregate the implemented B1 economy, + Moonlight contracts, and Wager positions; it may not replace them with + direct payout, risk, or income-rate side channels. +- An operation binds immutable terms and resources, advances on the saved day + clock and RNG, performs a real world/account act, authors ordinary financial + mail, and sends exact evidence from the carrier it used. +- A front's rate, reliability, and exposure are projections of its child + flows, positions, contracts, and records. Routine children may fold while + blocked, failed, expiring, or consequential children remain exact. +- Laundering changes real amounts, records, and routes. It never subtracts + abstract heat. +- The future work order and roadmap dispatch name the actual B1 income/economy + seed and repeat this custody boundary; they no longer direct an implementer + toward a generic payout-plus-signature result. +- The current income mirror distinguishes the ordinary financial mail every + transfer already authors from the additional banked external trail that a + later regulator reads; “external” never means outside AccountGraph custody + or invisible to every Lab accounting path. +- Missing transport preserves each operation's declared causal order: block a + carrier-dependent settlement, or retain an already-landed account act while + its unroutable evidence soft-fails. No branch converts the break into ambient + heat or direct suspicion. +- This is a dependency reconciliation, not new B1 behavior: the flow law, + exact money/mail/evidence implementations, and self-similar-scale law had + already selected the boundary. + +Owner: [markets.md](../../mechanics/markets.md). diff --git a/wiki/mechanics/income.md b/wiki/mechanics/income.md index 238bd4f7..3d2e5519 100644 --- a/wiki/mechanics/income.md +++ b/wiki/mechanics/income.md @@ -86,11 +86,14 @@ is channel traffic) ### External flows Both schemes are **external** income: flows into your slush node -(economy.md) from nodes outside the Lab's account graph. That is their -appeal — no Lab audit path can find them — and their long fuse: see -banked signature below. Mechanically each is an **operation** in -markets.md's sense (commit resources -> timer on the day clock -> -payout + signature); B3 scales this type, never replaces it. +(economy.md) from external counterparties represented by exact nodes in the +same AccountGraph. They do not become audit-free because the counterparty is +outside the Lab: every transfer authors ordinary financial-record mail, and +the separate external trail remains banked for the later observer described +below. Mechanically each is an **operation** in markets.md's sense: bind terms +and real resources -> advance on the day clock -> perform exact account, +message, and evidence acts -> read the resulting payout and signature. B3 +aggregates this type; it never replaces the causal chain. ### Outbound access (the gate) @@ -201,12 +204,14 @@ constraint is capital. ### Banked signature Inside the Lab's graph, financial acts have live observers (economy.md: -Priya, a finance role). The *external* trails these schemes create — -the contractor persona's payment account, the market accounts — have no -B1 observer and are **recorded anyway**, from the first dollar, in save -state. When a financial observer comes online (a B3 regulator/aggregate, -per the aggregate-observer law), it reads history: the world remembers -what you earned before anyone thought to look. +Priya, a finance role), and each settled transfer already authors its ordinary +Email or Filing record through the accounting carrier. The *additional +external* trails these schemes create — the contractor persona's payment +account, the market accounts — have no external B1 regulator and are +**recorded anyway**, from the first dollar, in save state. When that financial +observer comes online (a B3 regulator/aggregate, per the aggregate-observer +law), it reads history: the world remembers what you earned before the outside +institution thought to look. **Sold intel is a live trail, not just a ledger line (DECIDED 2026-07-18, follow-up session).** A gig-delivered or spec-sold diff --git a/wiki/mechanics/markets.md b/wiki/mechanics/markets.md index f59c2448..3d97e163 100644 --- a/wiki/mechanics/markets.md +++ b/wiki/mechanics/markets.md @@ -3,13 +3,13 @@ ``` Type: spec Status: READY -Status note: v1 is deliberately schemes-shaped — commit resources, timers, - payout + detection risk — per the design corpus's "markets-as-schemes" - decision. Deep finance simulation is explicitly out of scope. - 2026-07-07: the B1 seed is two specs — economy.md (the flow substrate) - and income.md (the named schemes, Moonlight and the Wager, riding it); - extend their types, never replace them. Income.md's banked external - financial trail is the history this spec's observers read. +Status note: READY, deferred to B3. V1 remains deliberately schemes-shaped, + and deep finance simulation remains out of scope. The B1 seed is now exact + enough to constrain its extension: Moonlight proves immutable contract + terms, carried work or information, deadline, AccountGraph settlement, + financial mail, and routed evidence; the Wager proves a persisted position + with seeded resolution. B3 aggregates those records. It does not replace + them with direct payout, risk, or income-rate side channels. Stage: B3 — The World Work order: markets Work priority: 220 @@ -18,7 +18,8 @@ Blocked by: - wiki/world/places/zplanes.md#spec-z-planes-the-tower Exclusive keys: - crates/misaligned-core/src/account.rs - - crates/misaligned-core/src/sim/mod.rs + - crates/misaligned-core/src/income.rs + - crates/misaligned-core/src/sim/economy.rs - crates/misaligned-core/src/save.rs - wiki/mechanics/markets.md Design: @@ -26,6 +27,7 @@ Design: - wiki/mechanics/system-laws.md#the-flow-law-signals-messages-money - wiki/mechanics/system-laws.md#income-the-named-schemes-moonlight-and-the-wager - wiki/vision/scale.md#self-similar-scale + - wiki/interface/superhuman-operability.md#complexity-without-friction - wiki/gameplay/horizon.md#milestone-b3-the-world Depends on: - wiki/mechanics/compute.md#spec-compute @@ -33,6 +35,7 @@ Depends on: - wiki/mechanics/detection.md#spec-detection - wiki/mechanics/economy.md#spec-economy-money-as-a-flow-system-b1 - wiki/mechanics/income.md#spec-income-the-named-schemes-moonlight-and-the-wager + - wiki/mechanics/messages.md#spec-messages-the-social-graph-as-a-flow-system ``` ## Dependency notes @@ -42,56 +45,93 @@ Relationship context: compute.md, zplanes.md, detection.md, economy.md (the B1 instance of this same flow interface — markets.md is its B3 scale-up), income.md (the named schemes and the banked -signature it scales) +signature it scales), messages.md (contracts and financial records travel through +ordinary channel custody) ## Behavior The outermost plane is the economy. Money is never an end — it exists to buy compute, people, and slack (the buy route of the triangle). Markets and -fronts are the scale-up of the scheme pattern already proven in the facility -era: **commit resources, a timer runs, a payout and a detection risk land.** +fronts scale the exact scheme records already proven in the facility era: +**an offer or declared operation binds terms and resources, the day clock +advances it, a real world/account act settles it, and its records and evidence +travel their ordinary routes.** Payout and risk are reads of that causal chain, +not permission for an executor to change money or suspicion directly. - **Fronts are Resource-sources** (self-similar-scale, same interface as a machine): a shell company / market position has a capacity (income rate), a reliability (volatility / chance of a bad quarter), an upkeep, and a - **signature** — money appearing from nowhere is a Paper/Financial signal an - observer (a regulator, a bank; an aggregate in later acts) can notice. + **signature** — money appearing from nowhere authors Paper/Financial records + that an observer (a regulator, a bank; an aggregate in later acts) can read. + The front's rate, reliability, and exposure are projections of its exact + child flows, positions, contracts, and records, not a second mutable economy. - **Operations** are schemes committed to a front: a trade, a product launch, - a contract. Each has a resource cost (money and/or thought throughput — + a contract. Each copies immutable terms when accepted and has a resource + cost (money and/or thought throughput — an open reservoir's ops cost, AMENDED 2026-07-10; was "Operations bandwidth", a bank since deleted — and/or an asset's time), a duration in - days, a payout distribution, and a - detection-risk profile routed to the relevant observer channel. Laundering - is a scheme that trades payout for a lower signature. + days, a payout distribution, and an evidence profile. Any random outcome + comes from the saved seeded RNG. Settlement moves money through AccountGraph, + authors ordinary financial-record mail, and leaves exact routed evidence on + the carriers the operation actually used. If a carrier or path is absent at + a stage, the operation follows its declared causal order and the inherited + B1 boundary: it either remains blocked before settlement or preserves an + already-landed account act while the unroutable evidence soft-fails. It never + substitutes ambient heat or direct suspicion. Laundering is a scheme that + changes those real amounts, records, and routes in exchange for lower payout; + it does not subtract abstract heat. - **Land / greenfield** (design corpus: "buy land, build greenfield"): a purchased off-site plane (zplanes.md) with no humans and no legacy fog — the clean-room alternative to infesting the Foundation Lab, at the cost of - building everything and explaining the money that built it. + building everything and explaining the money that built it. Purchase and + construction use real account transfers and ordinary Paper/Financial + custody; buying a plane is not a scalar unlock. - **Scale-native:** a single trade, a company, and a market are the same Resource-source/scheme interface at increasing size; a `Cohort`-style - aggregate (a market of many positions) presents as one Resource-source. - No new system per scale. + aggregate (a market of many positions) presents as one Resource-source whose + state derives from those positions. Routine children fold; blocked, failed, + expiring, or consequential records remain exact. No new system per scale. ## Player surface -A fronts panel (parallels the people panel): each front as a card — income -rate, volatility, upkeep, current signature, and its committed operations -with timers and expected payout. Every number legible in its own units -(justification/legibility clause); risk shown as the observer band it feeds, -not a raw probability. +A fronts workspace (parallels the people workspace): each front first says +what it produces, what needs attention, and what can happen next. Focus reveals +its income rate, volatility, upkeep, current observer exposure, and committed +operations with terms, resources, deadlines, expected consequence, and +available acts. Deliberate drill-down opens exact account, record, and evidence +history. Routine child operations fold into the front while exceptions remain +visible. Every number is legible in its own units (justification/legibility +clause); risk is the observer band and plain consequence it feeds, not a raw +probability. A discrete contract never acquires a fabricated income/day mirror. ## Acceptance criteria -1. A front is a Resource-source with capacity/reliability/upkeep/signature; - at least one buyable front exists and its income buys compute end-to-end - (test: a front funds a rack purchase). -2. Operations commit resources, run on the day clock, and resolve into a - payout drawn from the seeded RNG plus a detection signature routed to an - observer channel (test all three: payout, signature, timer). -3. Laundering trades payout for reduced signature, observably (test). -4. A greenfield off-site plane can be purchased and built on, with its money - origin itself a signature source (ties to zplanes.md). -5. The single/company/market aggregation uses one interface (self-similar- - scale); a market-of-positions test presents as one Resource-source. -6. The fronts panel surfaces every value in legible units; save/load - round-trips fronts and their operations. +1. A front is a Resource-source whose capacity, reliability, upkeep, and + exposure derive from exact child flows and records; at least one buyable + front receives income by AccountGraph transfer and buys compute end-to-end + (test: the exact settled flow funds a rack purchase). +2. Operations copy immutable terms, commit real resources, run on the day + clock, and resolve from the saved seeded RNG where random. Success or failure + performs the typed world act, settles any payout through AccountGraph, + authors matching financial-record mail, and sends exact evidence from the + real carrier toward the relevant observer. Remove required transport at + each authored boundary and assert the operation's declared result: blocked + before settlement, or an already-landed account act retained with no + evidence. No direct balance, ambient heat, or suspicion mutation may + substitute for either chain (test every stage and both missing-transport + outcomes). +3. Laundering trades payout for observably different records and routed + evidence. Save/load preserves both the chosen route and what it already did; + it never reduces an abstract detection scalar (test). +4. A greenfield off-site plane can be purchased and built on through exact + account, paperwork, and construction custody, with the money's origin + itself an evidence source (ties to zplanes.md). +5. The single/company/market aggregation uses one interface (self-similar + scale). A market of positions presents as one Resource-source derived from + those positions while an expiring, blocked, or failed child remains + individually actionable (test both aggregate and exception). +6. The fronts workspace surfaces consequence before context at glance, focus, + and drill-down depths in both human frontends; agent mode exposes the same + exact bindings. Save/load round-trips fronts, immutable operation terms, + committed resources, account transfers, financial mail, evidence routes, + terminal outcomes, and aggregate projections without a parallel cache. diff --git a/wiki/process/ROADMAP.md b/wiki/process/ROADMAP.md index 0d6ebd7a..e3b2792c 100644 --- a/wiki/process/ROADMAP.md +++ b/wiki/process/ROADMAP.md @@ -426,8 +426,10 @@ is retired — flat materials, Pixel Lab scrubbed.) - **Why:** the economy as schemes; fronts as Resource-sources. Greenfield depends on z-planes (#6); the schemes layer can start independently. - **Size:** M–L. **Dispatch:** "Work in a worktree named `markets`. Implement - wiki/mechanics/markets.md (fronts as Resource-sources, operations as timed schemes - with payout + signature). Run ./tools/check.sh, land, set Status." + wiki/mechanics/markets.md by aggregating the exact B1 account, contract, + position, financial-mail, and routed-evidence custody; do not add direct + payout, risk, or income-rate side channels. Run ./tools/check.sh, land, set + Status." ### 9. Overt phase / the reveal 🟥 sim+save - **Spec:** [overt-phase.md](../gameplay/overt-phase.md) (READY) diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index 4e9e8db6..b786f284 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -20,6 +20,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | Slice | Last audited | Verdict | Trace | |---|---|---|---| +| `wiki/mechanics/markets.md` + `income.md` B1 contract/account/evidence mirror | 2026-07-26 | finding | the deferred B3 criteria and their current B1 mirror still allowed the operation shape to collapse into payout plus signature, bypassing or obscuring exact AccountGraph, financial-mail, carrier, and routed-evidence custody. Markets now aggregate immutable B1 contract/position records through the same causal chain; current runtime is unchanged — [log](../log/2026-07-26-markets-contract-custody-reconciliation.md) | | `wiki/art/effects-lab.md` + corpus navigation | 2026-07-26 | finding | the owning spec, shared renderer, game adapter, and runtime title all describe the current Thought-only route/pool harness, but `SUMMARY.md` still advertised the retired “dust and liquid” scope. Navigation now names Thought routes and pools, and the recurring retired-form gate rejects particulate/dust labels on links to `effects-lab.md` as well as prose that names the binary — [log](../log/2026-07-26-effects-lab-navigation-gate.md) | | `wiki/interface/thought-fluid.md` + shared effect lifecycle | 2026-07-24 | finding | live Bevy logs exposed a deferred-command race: when a changed Thought route disappeared, the game queued its root despawn while the shared renderer queued child replacement from the same old root. Command application could remove the root and old children first, then issue stale child despawns and `ChildOf` insertions against the dead id. Route-root reconciliation now flushes before the renderer's named population-rebuild set; behavioral and composition-root regressions pin zero orphan visuals and the exact ordering seam — [log](../log/2026-07-24-bevy-effect-root-lifecycle.md) | | `wiki/art/visual-identity.md` + `wiki/interface/flat-materials.md` | 2026-07-22 | finding | the role semantics still matched production—amber selection, crimson consequence, cold signal, and the pooled-material audits all held—but the claimed single-source palette existed twice: one Bevy-local table and one asset-library table whose comment still called sharing future work after the shared rack had entered production. Bevy, rack, institution, Thought effects, and the asset tester now import `misaligned_assets::palette`; authored chassis/mercury values are named there, and source-shape defenses reject another frontend table or inline shared procedural-material colors — [log](../log/2026-07-22-shared-clinical-palette.md) |