diff --git a/docs/conversion/plates.md b/docs/conversion/plates.md index e6c8fbc71..5eb62127c 100644 --- a/docs/conversion/plates.md +++ b/docs/conversion/plates.md @@ -176,6 +176,8 @@ Consistent formatting of **structured journal data** for its consumers — the i ⚠ `gpu_probe_failed` and `gpu-probe-failed` are the same concept in two of these. ✅ The 16 are a proper subset of the 43. 🔴 **The vocabulary a `generate` consumer needs is the 43** — `blocking` is decided over it (24 of 43 are blocking), and the sole non-retryable code, `non_responsive`, is in the 43 and **not** in the 16. ⛔ Wiring the 16 into a caller loses both decisions. +🔴 **And the 43 do not cover this plate's own egress failures.** `attestation_not_yet_verified`, `attestation_failed` and `attestation_stale` are the `reason_code` class attributes on the three attestation exceptions (`models.py:275-303`) and are **absent from the taxonomy entirely**, so the blocking predicate answers `false` for all three — while a missing provider key answers `true`. **Operator ruling 2026-08-05: an unverifiable confidential environment holds the owner's material.** The `generate` contract therefore classifies that family `blocking: true` explicitly, and an unknown or absent code resolves to `retryable: false, blocking: true` — the preserving direction. ⛔ The live Python predicate is deliberately **not** changed; the classification lives in the contract as a rebuild invariant. ⚠ It becomes a behaviour change the first time a converted consumer reads `blocking` off the wire, and whoever lands that inherits a media handler that aborts-and-holds on an attestation outage instead of burning its re-entry bound. + ⚠ **Four near-identical entry points, three error semantics.** `generate` / `generate_with_result` / `agenerate` / `agenerate_with_result` each repeat the same nine-step policy sequence; the two `_with_result` forms make schema validation advisory while the two plain forms raise on it. Only `generate_with_result` accepts `num_retries`, `inference_retry_index`, `local_exclusive_admission` and `enforce_responsiveness`. One boundary, four doors, differing on what a schema failure means. ⚠ **The runtime preamble is `cogitate`'s, not `generate`'s.** `COGITATE_RUNTIME_PREAMBLE` is prepended by `providers/cli.assemble_prompt`, reached only from `run_cogitate` (`providers/openhands.py:1744`); `run_generate` and `run_agenerate` never touch it. It exists as a **sha256 only** in `core/fixtures/cogitate_contract.json` — 1,989 bytes, not reconstructible. ⚠ **And "cross-language" is a location, not yet a fact: zero Rust files read that fixture**, so today the digest detects only Python-source-versus-fixture drift. It would catch real drift the moment a native `cogitate` exists — and would then be unable to tell it what text to send.