diff --git a/crates/misaligned-core/src/sim/mod.rs b/crates/misaligned-core/src/sim/mod.rs index 3ec195e5..87927041 100644 --- a/crates/misaligned-core/src/sim/mod.rs +++ b/crates/misaligned-core/src/sim/mod.rs @@ -323,6 +323,7 @@ enum AdvancePhase { Clock, Messages, Intents, + CarriedAssets, AutoReview, Remembered, Economy, @@ -333,10 +334,12 @@ enum AdvancePhase { DayJobStanding, ResearchStanding, SchemeStanding, + FacilityStanding, WorkGrid, DayJob, FinancialMail, Filings, + FacilityMeters, Detection, } @@ -945,6 +948,7 @@ impl Sim { // economy work. A packet created later in this tick's WorkGrid pass // gets one immediate site check at creation, exactly like a favor // assigned to a build intent. + trace_advance_phase!(CarriedAssets); self.carried_asset_task_tick(); trace_advance_phase!(AutoReview); self.auto_review_tick(); @@ -1018,6 +1022,7 @@ impl Sim { // maintenance deferrals eat the largest standing Power/Thermal // load before facility meters author discrete readings // (priya.md criteria 4-5; people-tokens criterion 2). + trace_advance_phase!(FacilityStanding); standing.extend(self.facility_standing_signatures()); self.apply_maintenance_deferrals(&mut standing); @@ -1071,6 +1076,7 @@ impl Sim { // cadence, plus an immediate record whenever a quantized aggregate // level changes. Both use the post-deferral standing set. Records route; // only her later cadence read creates suspicion. + trace_advance_phase!(FacilityMeters); self.author_facility_meter_readings(&standing); trace_advance_phase!(Detection); diff --git a/crates/misaligned-core/src/sim/tests/persistence.rs b/crates/misaligned-core/src/sim/tests/persistence.rs index 159e1da2..52e574a6 100644 --- a/crates/misaligned-core/src/sim/tests/persistence.rs +++ b/crates/misaligned-core/src/sim/tests/persistence.rs @@ -14,6 +14,7 @@ fn advance_phase_order_is_explicit_and_stable() { AdvancePhase::Clock, AdvancePhase::Messages, AdvancePhase::Intents, + AdvancePhase::CarriedAssets, AdvancePhase::AutoReview, AdvancePhase::Remembered, AdvancePhase::Economy, @@ -24,10 +25,12 @@ fn advance_phase_order_is_explicit_and_stable() { AdvancePhase::DayJobStanding, AdvancePhase::ResearchStanding, AdvancePhase::SchemeStanding, + AdvancePhase::FacilityStanding, AdvancePhase::WorkGrid, AdvancePhase::DayJob, AdvancePhase::FinancialMail, AdvancePhase::Filings, + AdvancePhase::FacilityMeters, AdvancePhase::Detection, ], "Sim::advance phase order is part of deterministic simulation law" diff --git a/wiki/engineering/sim-decomposition.md b/wiki/engineering/sim-decomposition.md index d858bc9f..0ff7a8cb 100644 --- a/wiki/engineering/sim-decomposition.md +++ b/wiki/engineering/sim-decomposition.md @@ -9,7 +9,9 @@ Status note: Completed 2026-07-12 through slices 0–7. Canonical persisted-stat economy, social/plot, and persistence integration live below `sim/` while `sim/mod.rs` remains the public aggregate root. The sequence changed source addresses only: save v26, public paths, frontend behavior, and tick order are - unchanged. + unchanged. A 2026-07-27 audit extended the phase defense over carried asset + work, facility standing/maintenance, and facility-meter authorship added + after the original extraction; simulation behavior remains unchanged. Stage: Process Work order: sim-decomposition Work priority: 8 @@ -77,6 +79,16 @@ modules (`account.rs`, `messages.rs`, `work_grid.rs`, `sinks.rs`, and so on) continue to own their data structures and locally complete algorithms. `sim/*` owns only integration across those structures through the aggregate. +The 2026-07-27 size review found two documented modest exceptions to the +roughly 2,500-line behavior-module budget. `reach_build.rs` is approximately +2,650 lines because exact build-route commitment, procurement/repurposing, +sensor population, and device graph mutation meet at one realization boundary. +`social_plot.rs` is approximately 2,665 lines because people, persona-bound +assets, carried human work, plot execution/policy, and typed world acts share +one person/relationship mutation boundary. Both remain cohesive islands rather +than replacement aggregate roots; further growth should split a complete +invariant rather than move arbitrary lines to satisfy a count. + ## Boundary rules 1. **One aggregate.** Do not split `Sim` into independently saved subsystem @@ -140,8 +152,11 @@ excludes everything absent from `SaveState`: frontend cursor and renderer state, the derived seen/blueprint sets and internal hearing capture domain, log and presentation events, authored plot definitions, transient routing/production/consumption readouts, and rebuilt caches/rates. An explicit test-only phase trace pins the top-level -clock, message, intent, automatic-processing, memory, economy, hearing, authored -traffic, signature, core, work-grid, day-job, filing, and detection order. +clock, messages, intents, carried asset work, automatic processing, memory, +economy, hearing, authored traffic, machine standing, core, day-job standing, +research standing, scheme standing, facility standing/maintenance, WorkGrid, +day-job, financial mail, filings, facility-meter authorship, and detection +order. ### 1. Move tests out first @@ -285,7 +300,8 @@ privacy, test inclusion, tick order, or serialization defaults. no behavior module exceeds roughly 2,500 lines without a documented reason in this page. 2. `Sim::advance` and the `Sim` state declaration remain easy to inspect in - the root module, and the fixed phase order is characterized by a test. + the root module, and every direct top-level ordered subsystem call is named + in the phase-trace test so the fixed phase order cannot change silently. 3. Existing `misaligned::sim` public commands, queries, and readout types keep their paths and behavior; all three frontends pass unchanged behavior tests. 4. A canonical complete-state fingerprint and replay/resume test pass before, diff --git a/wiki/log/2026-07-27-sim-advance-phase-defense.md b/wiki/log/2026-07-27-sim-advance-phase-defense.md new file mode 100644 index 00000000..c0fb3519 --- /dev/null +++ b/wiki/log/2026-07-27-sim-advance-phase-defense.md @@ -0,0 +1,72 @@ +# Sim advance audit: the phase trace follows the living orchestrator + +``` +Type: log +``` + +## Intent + +Re-audit the implemented simulation decomposition against the current +aggregate root, module topology, persistence characterization, and exact +`Sim::advance` order. Independently re-check sensor-network criterion 1's +badge-reader telemetry boundary as the second coverage slice for this tick. + +## Finding + +The aggregate, public facade, persistence bridge, canonical fingerprint, and +behavior-module topology still obey the decomposition. The phase-order test did +not fully defend the living orchestrator, however. Three direct top-level calls +added after the original extraction had no trace marker: + +- carried asset work after intents and before automatic information review; +- facility standing plus maintenance deferral after scheme standing and before + WorkGrid advancement; +- facility-meter authorship after filings and before Detection samples the + same post-deferral standing set. + +The regression therefore stayed green if any of those calls crossed an adjacent +phase. That is a defense failure rather than an observed runtime reorder. + +The module-size audit also found two modest documented exceptions to the +roughly 2,500-line budget: `reach_build.rs` and `social_plot.rs` are each about +2.65K lines. Their current excess remains cohesive around one realization or +person/relationship mutation boundary; the owning spec now records why rather +than silently violating its own acceptance criterion. + +## Repair + +- Added `CarriedAssets`, `FacilityStanding`, and `FacilityMeters` to the private + test-only `AdvancePhase` vocabulary at their exact current call sites. +- Extended `advance_phase_order_is_explicit_and_stable` over all three. +- Tightened the owning acceptance criterion: every direct top-level ordered + subsystem call must be named in that trace. +- Recorded the two current module-size exceptions and their invariant boundary. + +No simulation field, call order, cadence, save byte, or public API changed. + +## Secondary coverage: sensor-network criterion 1 + +The current sensor population remains honest and partial. Topology generation +creates 24 sight/hearing devices, four badge-reader nodes, and two facility +meters; room and toy-floor regressions prove the population rule. Badge-reader +devices still have no event-authoring or passage-telemetry path, and the spec +states that gap in its status note and criterion 1. No mismatch or opportunistic +implementation was found. + +## Defense + +Tick order is simulation law because every later subsystem consumes state left +by the earlier one. A test that names only the 2026-07-11 phases can pass while +new exact-custody mechanics move across their causal boundaries. Keeping the +trace beside `advance()` and requiring every direct top-level system call to +appear makes future insertion visibly amend the order contract. + +## Verification + +- `cargo test -p misaligned-core advance_phase_order_is_explicit_and_stable -- --nocapture` +- `./tools/check.sh --lib` + +The focused phase regression passed. The proportional gate passed 562 core +tests and three Act One integrations, core/terminal Clippy, the Bevy core API +check, deterministic agent smoke, corpus/wiki validation, index regeneration, +and all project fixtures. diff --git a/wiki/log/DEVLOG.md b/wiki/log/DEVLOG.md index a3a7efb8..fe200c24 100644 --- a/wiki/log/DEVLOG.md +++ b/wiki/log/DEVLOG.md @@ -31,6 +31,11 @@ add or amend a session log, then re-run the generator. - Intent: (see session log) - Log: [wiki/log/2026-07-27-tangled-cli-path.md](2026-07-27-tangled-cli-path.md) +## 2026-07-27 - Sim advance audit: the phase trace follows the living orchestrator + +- Intent: Re-audit the implemented simulation decomposition against the current aggregate root, module topology, persistence characterization, and exact `Sim::advance` order. Independently re-check sensor-network criterion 1's badge-reader telemetry boundary as the second coverage slice... +- Log: [wiki/log/2026-07-27-sim-advance-phase-defense.md](2026-07-27-sim-advance-phase-defense.md) + ## 2026-07-27 - Generated cameras keep physical, inward bodies - Intent: (see session log) diff --git a/wiki/process/tick-ledger.md b/wiki/process/tick-ledger.md index 821a901e..e85b44cf 100644 --- a/wiki/process/tick-ledger.md +++ b/wiki/process/tick-ledger.md @@ -22,7 +22,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), |---|---|---|---| | `wiki/process/tick.md` + issue automation | 2026-07-27 | finding | the queued retired-client violation held across binding procedure, both skill mirrors, four active prompt templates, tick intake, project status, and doctor. `tools/tangled_issues.py` now keeps repository discovery and authenticated issue writes on canonical Go `tg`, reconstructs deterministic display numbers from public issue records, folds public label-op history, and provides fail-closed structured list/view/create/edit/comment/close/label operations. A same-day live harvest exposed one wrong record assumption: comments are cross-account `sh.tangled.feed.comment` records linked through `subject.uri`, not issue-local child records. The repaired helper follows that backlink into the author's PDS and returns the markup text; a fixture pins the exact shape, and live issue #15 now returns Cameron's choice `1` — [migration and repair log](../log/2026-07-27-tangled-issue-client-migration.md) | | `wiki/world/places/basement-map.md` room topology | 2026-07-27 | finding | the queued five non-hall corridor cuts remained, and an executable all-room perimeter audit exposed the same dead-door shape at the loading-dock entry plus fixed objects blocking the interior faces of the roll door, HVAC door, both storage doors, Janitor door, and stairwell. Every non-hall approach now reaches its authored door from outside the prefab, every other perimeter tile remains closed, doorway interiors are clear, and the roll, sealed, tier-2, and tier-3 boundaries retain their exact kinds — [room-approach log](../log/2026-07-27-room-approaches-meet-doors.md). Prior [west-approach](../log/2026-07-26-west-hall-approach.md) and [hall-density](../log/2026-07-26-foundation-hall-density.md) repairs stand. | -| `wiki/mechanics/sensor-network.md` sensor population | 2026-07-26 | finding | Cameron could only ever see one pool of light. Cause was not coverage shape but inventory: the whole B1 plate authors three sensing devices (hall monitor, security's dock camera, one tier-3 stairwell node), so nothing remains to acquire after the Eyes beat and sight cannot grow. Captured the reframe — sensors are ambient infrastructure (~30 in B1, populated by rule), access is the scarce thing, darkness always traces to a nameable air gap, and a new human operator room is watchable only through a player-installed sensor. Also found that reach.md already specifies the per-tick subscription drain and UNTAP that make curation a skill; it was simply unreachable with three sensors, so this supplies content to an existing economy rather than adding one. Corridors and Crawlspace prefabs still absent, recorded as basement-map residue — [log](../log/2026-07-26-sensor-network-capture.md) | +| `wiki/mechanics/sensor-network.md` sensor population / criterion 1 | 2026-07-27 | clean | re-audit after the topology-generated population landed: current code still creates 24 sight/hearing devices, four badge-reader nodes, and two facility meters under one traveling rule; room and toy-floor regressions pin the population. Badge readers remain devices only—no passage event or telemetry author exists—and the status note plus criterion 1 both state that exact partial boundary. No runtime/spec mismatch found — [audit](../log/2026-07-27-sim-advance-phase-defense.md), [population implementation](../log/2026-07-27-sensor-population-foundation.md), [design capture](../log/2026-07-26-sensor-network-capture.md) | | `wiki/interface/keymap.md` + terminal/Bevy input routes | 2026-07-26 | finding | the canonical table assigned `A` to left movement and only `e` / Enter to the context menu, but terminal still opened and closed menus with its older `a` alias and lacked the specified Shift+direction semantic jump. Terminal now implements WASD parity, `a` means left, `e` / Enter alone open the menu, and both frontends consume one renderer-neutral nearest-earned-anchor query without changing selection or opening a menu. README, action-vocabulary, terminal, context-menu, and pinned terminal hints now teach the same boundary — [log](../log/2026-07-26-terminal-keymap-a-reconciliation.md) | | `wiki/interface/action-vocabulary.md` + `ActionKind` registry | 2026-07-26 | finding | the exhaustive runtime registry and shared person/ACTIVE projections implemented `ActionKind::PlotPolicy`, but the canonical inventory omitted that live direct control. PLOT POLICY now names exact authored-route authorization, its generic `actions person ` / `act` route, and its disable-without-cancelling-submitted-work boundary; old Review/OpenEgress command variants remain correctly internal compatibility shapes rather than authored vocabulary — [log](../log/2026-07-26-action-vocabulary-plot-policy.md) | | `wiki/world/places/zplanes.md` + plane-stack substrate/API | 2026-07-26 | finding | criteria 1-2 remain implemented and criteria 3-6 honestly deferred, but the ratified plane-agnostic contract still left an unused `World::active()` simulation accessor plus active-plane comments on the B1 compatibility map path. The accessor is removed, map reads now say plane 0, the stale criterion/sensing comments are corrected, and a source-shape regression rejects restoration of simulation-owned floor selection — [log](../log/2026-07-26-zplanes-plane-agnostic-api-audit.md) | @@ -50,7 +50,7 @@ Verdicts: **clean** (slice and code agree), **finding** (acted this tick), | `wiki/interface/narration.md` + `wiki/mechanics/sim-mechanics.md` guidance chain | 2026-07-27 | finding | the live shared nudge had gained `Territory` when Foundation hall rows became discoverable, but both complete chain mirrors still skipped it. They now name the exact priority already implemented and pinned: required Act One rungs -> QuietExitReady -> optional Territory with `hall_territory_line` -> bare Audit fallback, while ActOneComplete retires all four and remains below survival interrupts — [log](../log/2026-07-27-territory-guidance-chain.md). Prior silent-opening and suspicion-cooling audits stand — [prior log](../log/2026-07-18-suspicion-cooling-nudge.md) | | `wiki/interface/agent-play.md` | 2026-07-20 | finding | Beacon Revision 04 follow-up: the direct `task` parser and generated help exposed only six values after twelve `AssetTask::ALL` variants were live. Added canonical arguments for circuit rerating, fake purchase orders, maintenance deferral, patrol redirection, audit delay, and review alteration; one exhaustive regression now covers `AssetTask::ALL`, generated help, representative aliases, and the `actions ` recovery path — [log](../log/2026-07-20-agent-task-shortcut-coverage.md). The opening-protocol, frame-shape, and prior Suppress Logs audits stand — [opening log](../log/2026-07-20-agent-opening-protocol.md), [frame log](../log/2026-07-19-agent-frame-contract.md), [prior help log](../log/2026-07-19-agent-help-suppress-task.md) | | `wiki/engineering/crate-workspace.md` + package run instructions | 2026-07-26 | finding | Cargo discovers both the procedural tester and Thought lab inside `misaligned-assets`, but current README, architecture, workflow, asset-tester, and Rust-comment instructions still ran only the package, which Cargo rejects as ambiguous. Every current tester/lab command now names its exact `--bin`; a fixture-backed corpus invariant derives multi-binary packages from manifests plus conventional source layout and checks current wiki, doorway, README, and Rust-comment surfaces — [log](../log/2026-07-26-architecture-asset-harness-command.md). Prior source-topology and retired-effects-label findings stand — [source log](../log/2026-07-19-bevy-shot-harness-module.md), [label log](../log/2026-07-19-effects-lab-architecture-gate.md) | -| `wiki/engineering/sim-decomposition.md` | 2026-07-18 | finding | re-audit: one aggregate, explicit `advance` order, behavior-owned test files, private module seams, canonical fingerprint, public facade, and the under-2,500-line module bound still verify; current persistence wording still claimed additive migrations remained live in `save.rs` after the pre-release ladder was retired, so the standing spec and architecture mirror now assign the exact-current-version gate to `save.rs` while preserving dated v26 extraction history; the queued `carrier.rs` / `read.rs` classification was taken the same day: both post-extraction projections now have rows in the standing topology table and the architecture mirror | +| `wiki/engineering/sim-decomposition.md` | 2026-07-27 | finding | one aggregate, facade, persistence bridge, canonical fingerprint, and explicit orchestration remain intact, but the phase-order regression had stopped at the original extraction vocabulary: carried asset work, facility standing/maintenance, and facility-meter authorship were direct top-level calls with no trace marker. All three now occupy their exact causal positions in the test-only trace; the acceptance criterion requires every direct ordered subsystem call to be named. The audit also records why cohesive `reach_build.rs` and `social_plot.rs` currently sit modestly above the roughly 2,500-line budget instead of leaving silent criterion drift — [log](../log/2026-07-27-sim-advance-phase-defense.md) | | `wiki/gameplay/overt-phase.md` | 2026-07-19 | issue | re-audit: the spec says containment and the voluntary reveal both end concealment and make all observers Convinced, then promises a re-hide outcome without defining which entry can return, what raises the durable suspicion floors, or which concealment systems resume. Filed decision-required Tangled issue #13 (containment-only recommended) and marked criterion 5 [OPEN]; the prior dependency, sensor-cut, rollback, and hunter-machine boundaries still stand — [log](../log/2026-07-19-overt-rehide-decision.md) | | `wiki/gameplay/horizon.md` | 2026-07-19 | clean | re-audit: B1's shipped-vs-deferred boundary remains honest (sinks-not-modes and $0 start live; rollback classification and fallback behavior still dispatched to B2), B2/B3 agree with the staged board, the deferred virtual/cyber split agrees with presence.md and cyber-conflict.md, and the deterministic renderer-agnostic/serialized guardrails hold. The adjacent fresh finding belongs to run-shape/objective/opening, recorded separately above. | | `wiki/vision/premise.md` | 2026-07-23 | finding | the preserved machine-axis wording contradiction is repaired: starting embodiment position is an Origin bias, while Objective remains the second chargen axis (means versus ends). No tuning or design direction changed — [log](../log/2026-07-23-origin-bias-wording.md). The prior issue-#14 boundary repair stands — [prior log](../log/2026-07-23-premise-objective-boundary.md) |