Imported from giodl73-repo/FERRIS (
AGENTS.md). Install upstream withnpx skills add giodl73-repo/FERRIS. Copyright stays with the author.
Ferris Agent Instructions
Read CONTEXT.md first. It is the canonical operating context for this
repository.
Working rules
- Use
docs/plans/FERRIS_PROGRAM.mdfor product authority and sequence. - Use
docs/specs/README.mdfor normative specification status and dependencies. - Read the applicable
.rolesfiles before claiming a role review. - Preserve Cargo and every external owner's authority; do not create parallel resolvers, hidden manifests, or synthetic owner truth.
- Keep Typebook/RUNE product-neutral and independently usable.
- Keep observation, planning, approval, and execution as separate records and authorities.
- Treat unknown, unsupported, unavailable, stale, failed, and not-observed as distinct states.
- Never place credentials or reusable secrets in plans, prompts, roots, refs, logs, fixtures, or evidence.
- Preserve ordinary Cargo and owner-native workflows and define removal and rollback for every adoption.
Change authority
The closed bounded pulses in
context/waves/2026-08-11-read-only-planning/pulses/
authorize only local read-only plan, explain, declared-workspace graph,
passive local doctor, and the Pulse 14 two-file experimental
profile-diff product code over explicit local inputs and development
fixtures. Pulse 15 authorizes only the nine-family development fixture matrix
and conformance tests for that existing command; it adds no product behavior.
Pulse 16 authorizes only the public held-out contract, custody protocol, and
review. It does not authorize hidden fixture construction by implementation
authors, scoring, or oracle access. Pulse 17 authorizes only Windows and Unix
development validation evidence for the existing implementation and fixtures.
Pulse 18 authorizes only the public-CLI filesystem immutability test and its
bounded evidence. Pulse 19 authorizes only the representative ordinary-Cargo
consumer fixture, before-and-after conformance test, and evidence. Do not
implement profile generation, affected-only scope, query, go, mutation,
active probes, connectors, MCP, AI narrowing, approval, deployment, remote
evidence, or held-out oracle access. Any later product capability requires
another separately approved pulse.
The
context/waves/2026-08-30-owner-validation-domains/ wave records explicit
owner approval for one bounded, non-executable owner-validation-domain pulse.
Pulse 01 authorizes only the optional closed prefix contract, opaque owner
entrypoint selection, conservative Cargo composition, and explicit lexical
classification of missing workspace-root-relative paths. Missing paths must
never narrow Cargo package scope without filesystem evidence. The pulse is
complete after a clean read-only implementation review, targeted core, CLI,
and schema proof, and eleven-role closeout. Its implementation and corrective
budgets are exhausted. External adopter migration, Git discovery, revision
evidence, command interpretation, and owner action execution require separate
pulses.
The
context/waves/2026-08-30-revision-bound-validation-evidence/ wave records
explicit owner approval for one bounded, read-only revision-evidence pulse.
Pulse 01 authorizes only optional local Git revision resolution for
validation-plan, exact merge-base-to-head path classification, binding the
resulting plan to the resolved base, merge base, head, and tested revisions,
and deterministic stale or invalid diagnostics. The caller chooses the
revisions and the repository owner retains entrypoint commands, execution,
artifacts, success semantics, and required-check policy. Do not add remote
fetch, checkout mutation, signing, workflow parsing, execution-result
attestation, cache reuse, or CI narrowing.
The
context/waves/2026-09-11-owner-native-focused-validation/ wave records
explicit owner approval for one bounded, read-only validation-planning pulse.
Pulse 01 is complete and adds an optional
ferris.owner-validation-domains/v2 contract that
preserves opaque owner entrypoint IDs while declaring only validation breadth,
an opaque preparation ID, and a normalized workspace-relative working
directory. V1 and no-contract behavior must remain unchanged. Do not parse or
execute commands, recipes, workflows, toolchains, preparation steps, or
environment values; infer sufficiency or CI equivalence; benchmark savings; or
alter an adopter.
The
context/waves/2026-09-10-enterprise-corpus-qualification/ wave records
explicit owner approval for one bounded qualification of current Ferris
against five existing private enterprise-shape synthetic repositories. Pulse
01 may freeze exact private revisions, execute only their already-declared
scenarios on local Windows and hosted Ubuntu, and retain public-safe aggregate
evidence. It may create one temporary validation branch per private repository
only to run the existing scenario harness in hosted CI; those branches must not
merge and must be removed after evidence custody. It adds no product behavior,
does not alter a corpus scenario, and does not authorize affected-only gating,
support, production representativeness, or savings claims. Private repository
names, revisions, paths, raw output, and identifiable timings must not enter
this public repository.
The completed incomplete
context/waves/2026-09-11-enterprise-onboarding-proof/ Pulse 02 authorizes only
removable Ferris-owned onboarding in the two custody-bound private consumers at
public Ferris revision
b347dc34d62810f043122d0d279def316b890cf0, unchanged owner-command baselines,
approved local plan, go, and verify evidence on Windows and local WSL 2
Ubuntu, complete removal, and unchanged post-removal validation. This is local
two-platform evidence only. Its WSL preflight found Rust 1.95 and Git but no
Linux pwsh, so the pulse stopped before either consumer changed, any tag or
baseline was created, or Ferris ran in a consumer. The authority is exhausted
and grants no retry, dependency installation, translated command, hosted-CI,
support, production, affected-only, savings, workflow-replacement, or
external-adopter authority.
Pulse 03 was one explicitly approved corrective successor. It authorized one checksum-verified PowerShell 7.6.6 Linux x64 archive installation in local WSL 2 Ubuntu, the unchanged two-consumer Windows/WSL baseline and removable onboarding protocol, and complete removal of both consumer onboarding files and the WSL prerequisite. It grants no APT or Snap setup, owner-command translation, consumer prerequisite accommodation, product change, hosted-CI, official Ubuntu support, production, support, affected-only, performance, savings, workflow-replacement, or external-adopter authority.
The archive matched its published digest, launched natively, and was removed
completely. Both Windows owner commands then stopped at Get-Command cargo
because Cargo was absent from the inherited PATH. No changed-input retry was
authorized, so no WSL baseline, tag, consumer mutation, Ferris execution, or
removal test occurred. Pulse 03 is exhausted and grants no retry or successor
authority.
Pulse 04 is explicitly owner-approved as one fresh environment-bound attempt.
It may prepend the existing Windows Cargo directory only to invoking processes,
preserve the existing WSL Cargo directory, require tool-resolution preflights,
repeat the exact removable PowerShell archive pathway, and run the unchanged
two-consumer onboarding/removal protocol. It grants no persistent PATH
change, owner-script translation, consumer accommodation, product change,
hosted-CI, official Ubuntu support, production, support, affected-only,
performance, savings, workflow-replacement, or external-adopter authority.
Both platform preflights and both Windows owner baselines passed. Both WSL
baselines stopped when ancestor user Cargo configuration selected unavailable
kache as rustc-wrapper. Pulse 04 did not override that owner configuration
or retry; it removed the PowerShell prerequisite and stopped before tags,
consumer mutation, Ferris execution, or removal testing. The authority is
exhausted and grants no wrapper override, retry, or successor.
Pulse 05 is explicitly owner-approved as one fresh configuration-isolated
attempt. It may use a temporary empty WSL CARGO_HOME while preserving the
installed rustup toolchain and user Cargo configuration, repeat the removable
PowerShell prerequisite, and run the unchanged onboarding/removal protocol.
It grants no configuration edit or override, dependency installation,
consumer accommodation, product change, hosted-CI, official Ubuntu support,
production, support, affected-only, performance, savings,
workflow-replacement, or external-adopter authority.
The empty Cargo home and both platform preflights passed, as did both Windows
owner baselines. Both WSL baselines still found the user Cargo configuration
because Cargo searches .cargo ancestors of the invocation directory. Pulse
05 did not change cwd, override configuration, or retry; it removed all
temporary state and stopped before tags, consumer mutation, Ferris execution,
or removal testing. The authority is exhausted and grants no retry or
successor.
The active
context/waves/2026-09-14-enterprise-value-validation/ wave orders the
remaining product gaps as repeatable onboarding, measured real-adopter value,
advisory CI reconciliation, and compatibility/support readiness. Pulse 01
authorizes only unchanged Windows owner baselines and temporary native-WSL
clones of the two custody-bound private consumers, plus exact cleanup and
public-safe evidence. It adds no Ferris product behavior, consumer mutation,
tag, Action Plan, execution, savings, CI-replacement, production, or support
claim.
Pulse 01 is complete: exact temporary native-WSL clones matched both custody sources, all four unchanged Windows/Linux owner baselines passed, invalid WSL timing measurements were discarded, and all clones and prerequisites were removed. This establishes cross-platform owner baselines only and grants no Pulse 02 or product claim automatically.
Pulse 02 is explicitly authorized for disposable Windows and native-Linux
clones only. It may build exact public Ferris revision
b347dc34d62810f043122d0d279def316b890cf0, stage removable .ferris/
planning and execution material, invoke each unchanged owner validation script
through a staged platform-native PowerShell runtime, verify receipts, remove all
Ferris material, and rerun owner validation. It grants no source-consumer
mutation, tag, remote push, workflow change, CI narrowing, savings, production,
or support authority.
Pulse 02 stopped invalid before execution because its federated request paths were not relative to the request file and Windows PowerShell staging copied no runtime files. No valid Action Plan, owner command, receipt, or source mutation occurred, and all disposable state was removed. Any retry requires a separate pulse with both preparation invariants preflighted.
Enterprise Value Validation Pulse 03 is explicitly authorized for one fresh
disposable attempt at the same pinned Ferris and consumer revisions. It may
correct only request-relative federated manifest paths and enumerated Windows
PowerShell staging, must preflight every manifest and both native executables,
and may then perform the unchanged planning, Action Plan, go, verification,
complete removal, and post-removal owner-command protocol. Any failed
preflight, planning, execution, verification, removal, or owner gate stops the
pulse without retry.
Pulse 03 stopped invalid at federated planning. Existing manifests passed the
preflight, but federated-plan correctly rejected their .. path components
with FERRIS-FEDERATED-PLAN-MANIFEST-TRAVERSAL. No Action Plan, execution,
receipt, owner command, Linux materialization, or source mutation followed, and
all disposable state was removed. Pulse 03 is exhausted.
Enterprise Value Validation Pulse 04 authorizes one fresh disposable attempt
with a single temporary root ferris-onboarding-request.json for EO-02.
That file and .ferris/ must both be absent before post-removal owner commands.
All other Pulse 03 revisions, commands, preflights, stop conditions, cleanup,
and exclusions remain unchanged.
Pulse 04 stopped invalid during disposable generator compilation because its
manifest omitted the direct serde dependency. No onboarding or owner command
ran, all disposable state was removed, and the pulse is exhausted.
Enterprise Value Validation Pulse 05 authorizes one fresh Pulse 04 attempt
after adding only the disposable generator's direct serde dependency. The
generator MUST build before either consumer is materialized. It otherwise
inherits the exact inputs, root-request boundary, preflights, commands, stop
conditions, removal invariant, cleanup, and exclusions from Pulse 04.
Pulse 05 stopped invalid before execution because go was invoked from the
public Ferris worktree rather than the disposable consumer root. Ferris failed
closed with FERRIS-EXECUTION-FILE-UNAVAILABLE; no owner lane or receipt
resulted. All disposable state was removed and Pulse 05 is exhausted.
Enterprise Value Validation Pulse 06 authorizes one fresh Pulse 05 attempt
with only go and verify process working directories explicitly bound to
their disposable consumer roots. It inherits every frozen input, preflight,
root request, owner command, stop condition, removal invariant, cleanup, and
exclusion from Pulse 05.
Pulse 06 reached owner execution. EO-01 PowerShell failed during Windows
system-policy initialization because the Action Plan inherited only PATH.
Ferris emitted a failed receipt with complete cleanup. No later lane or
platform ran, all disposable state was removed, and Pulse 06 is exhausted.
Enterprise Value Validation Pulse 07 authorizes one fresh Pulse 06 attempt
whose Windows declarations may inherit only PATH, SystemRoot, and WINDIR;
Linux remains PATH only. Each staged runtime MUST launch under the exact
declared environment before planning. All other inputs, commands, gates,
cleanup, and exclusions remain unchanged.
Pulse 07 stopped before owner launch because SystemRoot was not the uppercase
canonical environment name required by Ferris. The exact-environment runtime
preflight passed, but Ferris rejected the declaration. No receipt or owner lane
followed, cleanup completed, and Pulse 07 is exhausted.
Enterprise Value Validation Pulse 08 authorizes one fresh Pulse 07 attempt
using the sorted uppercase Windows names PATH, SYSTEMROOT, and WINDIR.
Their values and the Linux PATH-only declaration remain unchanged. Every
other input, preflight, command, gate, cleanup, and exclusion remains fixed.
Pulse 08 launched the first Windows owner lane under the canonical environment.
PowerShell initialized, but Get-Command cargo failed because Cargo was absent
from the child-visible PATH. Ferris retained a failed receipt with complete
cleanup. No later execution followed, cleanup completed, and Pulse 08 is
exhausted.
Enterprise Value Validation Pulse 09 authorizes one fresh Pulse 08 attempt
adding only PATHEXT to the sorted Windows environment declaration. Before
planning, staged PowerShell MUST resolve the exact Cargo executable under that
environment. Linux remains PATH only; every other boundary is unchanged.
Pulse 09 resolved Cargo and reached fresh cargo test, which failed because
the cleared lane could not resolve installed link.exe. Ferris retained a
failed receipt with complete cleanup. No later execution followed, all
disposable state was removed, and Pulse 09 is exhausted.
Enterprise Value Validation Pulse 10 authorizes one fresh Pulse 09 attempt
after importing the installed Visual Studio 2022 Build Tools x64 developer
environment into only the invoking process. Windows declarations add only
LIB, producing sorted LIB, PATH, PATHEXT, SYSTEMROOT, and WINDIR.
Cargo and link.exe discovery are required preflights. No persistent
environment change or prerequisite installation is authorized.
Pulse 10 stopped before consumer materialization because its cmd.exe quoting
for the process-local VsDevCmd.bat import was invalid. No onboarding command
ran, the tool-only root was removed, and Pulse 10 is exhausted.
Enterprise Value Validation Pulse 11 authorizes one fresh Pulse 10 attempt
using the proven single-string cmd /c invocation. The installed Visual Studio
Installer directory may be prepended only to the import process so
vswhere.exe resolves. No persistent environment change is authorized; every
other Pulse 10 boundary remains fixed.
Pulse 11 resolved Cargo and link.exe but the first owner lane lacked
TEMP/TMP, so the linker could not create its response file. Ferris
classified the bound-value diagnostic as leaked_secret, retained a failed
receipt with complete cleanup, and the pulse stopped. Pulse 11 is exhausted.
Enterprise Value Validation Pulse 12 authorizes one fresh Pulse 11 attempt
adding only TEMP and TMP to the sorted Windows declaration. Before either
consumer is materialized, a disposable Rust source MUST compile and link under
the exact cleared environment. Linux and every other Pulse 11 boundary remain
unchanged.
Pulse 12 passed both Windows Ferris executions and receipt verifications. Its Linux harness had CRLF endings and stopped before materialization, so the cross-platform gate remained incomplete. Windows aggregate evidence was retained privately, all disposable state was removed, and Pulse 12 is exhausted.
Enterprise Value Validation Pulse 13 authorizes one fresh complete Pulse 12 attempt after a byte-level preflight proves the Linux harness contains no CR bytes. Both platforms must rerun; Pulse 12 results are not reused as Pulse 13 success evidence. Every product, consumer, environment, removal, cleanup, and claim boundary remains unchanged.
Pulse 13 passed its LF gate but stopped during Linux tool setup because
non-login WSL omitted /root/.cargo/bin from launcher PATH. No consumer or
Windows materialization followed, cleanup completed, and Pulse 13 is
exhausted.
Enterprise Value Validation Pulse 14 authorizes one fresh Pulse 13 attempt
with existing /root/.cargo/bin prepended only inside the native Linux
harness. Linux MUST complete before Windows materializes. Every other input,
gate, removal invariant, cleanup requirement, and exclusion remains unchanged.
Pulse 14 passed both Linux executions and receipt verification, removed all
onboarding, and proved clean tracked trees. Post-removal owner validation then
could not find global pwsh; Windows did not materialize. Linux aggregate
evidence was retained privately, cleanup completed, and Pulse 14 is exhausted.
Enterprise Value Validation Pulse 15 authorizes one fresh Pulse 14 attempt with one checksum-bound native PowerShell runtime under the disposable Linux root, outside both consumers. Consumer runtimes may be copied from it; after onboarding removal it may run unchanged owner commands, then MUST be deleted with the root. Every other boundary remains unchanged.
Pulse 15 is complete. Both private consumers passed planning, owner-approved execution, and receipt verification on Windows and native Linux. Complete onboarding removal and all four unchanged post-removal owner commands passed; exact tracked trees remained clean and all disposable state was removed. This closes only the repeatable onboarding gate and grants no value, CI, production, support, or external-adopter claim.
Enterprise Value Validation Pulse 16 authorizes one local Windows value cohort
at BISECT revision 2b90f9265997a042133262144ec81f8024ef5c45 against parent
d3dd4c6ef6a66ffea490bca21a6ad2853ccaf257. It may use a disposable owner
domain declaration covering that committed change set, run the three
repository-owned vault unit tests as selected work, and run the complete
repository-owned unit suite as the full reference. It must perform eight
selected/full pairs with alternating order and explicit cold/warm state, count
Ferris planning overhead against selected time, require both lanes to pass in
every pair, zero selected-pass/full-fail divergence, and at least 10% positive
median value. No workflow, adopter, product, dependency, or environment
mutation is authorized.
Pulse 16 stopped before planning because the fresh invoking shell omitted the
installed Cargo directory from PATH. No owner lane or timing ran, all
disposable checkouts were removed, and Pulse 16 is exhausted.
Enterprise Value Validation Pulse 17 is complete and invalid. Process-local
Cargo resolution passed, exact Ferris built, and all eight revision-bound plans
succeeded without fallback over 29 focused owner entrypoints. Python 3.13.15
lacked pytest, so all sixteen frozen owner lanes exited before collection and
zero timings are admissible. Cleanup completed. Pulses 16 and 17 are
consecutive invalid attempts, the real-adopter value gate remains unresolved,
and no corrective successor, advisory CI reconciliation, or support-readiness
pulse is authorized.
After explicit user direction to continue across BISECT, ICELINES, and REEL,
Enterprise Value Validation Pulse 18 authorizes one fresh preflight-gated
ICELINES pure-Cargo value cohort. It freezes head
935136020140bd5b408d26cbb0777dd6f0fb5ef9, base
41fec3dab0dd0d28e55a3b5d5f98c2ac650f108f, the repository-owned
icelines-core --lib and icelines-fetch selected test commands, and the
repository-owned workspace full reference. Eight pairs preserve strict
correctness, alternating order, cold/warm state, planning overhead, and the 10%
threshold. Preflight failure ends the pulse. No adopter, REEL, dependency,
workflow, product, CI, support, or production change is authorized.
Pulse 18 is complete and invalid before measurement. The exact ICELINES
selected/full preflight passed and eight focused plans succeeded without
fallback. Its PowerShell wrapper bound the command array to reserved automatic
variable $args, so 24 intended owner invocations ran bare Cargo help and
zero owner lanes or admissible timings resulted. Cleanup completed. Pulse 18 is
exhausted and grants no retry, advisory CI, or support-readiness authority.
The user's fresh continue direction authorizes Enterprise Value Validation
Pulse 19 only. It corrects the PowerShell command-array parameter from reserved
$args to commandArgs, adds semantic proof that successful lanes actually
ran tests and not bare Cargo help, and reruns Pulse 18's otherwise unchanged
preflight, revisions, owner commands, eight pairs, threshold, cleanup, and
exclusions. No adopter, workflow, dependency, product, CI, support, or
production change is authorized.
Pulse 19 is complete and incomplete at resource exhaustion. The corrected
wrapper, semantic command-output checks, fresh exact preflight, and focused
planning passed. Pair 1's selected lane passed both owner commands; its full
lane failed during compilation with Cargo exit 101 and rustc no space on device. Zero complete pairs or admissible timings resulted. Disposable roots
were removed without changing the shared compiler cache, and no retry,
advisory CI, or support-readiness authority follows.
The user's next fresh continue authorizes Enterprise Value Validation Pulse
20 only. It sets CARGO_INCREMENTAL=0 process-locally and identically for
selected and full commands, requires independent passing preflight target trees
to coexist with at least 10 GiB free, and leaves the 19.44 GiB shared kache
untouched. If that gate passes, it reruns Pulse 19's otherwise unchanged
revisions, commands, planning, eight pairs, semantic checks, threshold,
cleanup, and exclusions. No persistent environment, adopter, dependency,
workflow, product, CI, support, or production change is authorized.
Pulse 20 is complete and invalid at capacity preflight. The selected
nonincremental target passed and measured 7.757 GiB; the independent full
target reached 16.548 GiB before Cargo exit 101 and linker/PDB resource
errors. Both trees left 3.544 GiB free, below the 10 GiB reserve, so
measurement did not start. Cleanup restored 30.798 GiB without changing the
shared cache or adopter clones. This was the final capacity-profile attempt and
grants no retry, advisory CI, or support-readiness authority.
The user's next fresh continue authorizes Enterprise Value Validation Pulse
21 against REEL. It freezes head
5c896f5a9d3fb7bd4a709ace66dfe119c6a568bb, base
9719aacc4d4554ad8d38502ae33135803836fd3c, the documented
cargo test --test scene_delivery selected command, and CI-owned
cargo test --all-targets --all-features full reference. Exact preflight,
focused revision planning, eight pairs, semantic logs, and the 10% threshold
remain mandatory. FFmpeg and ignored tests are excluded. No adopter,
dependency, workflow, product, CI, support, or production change is authorized.
Pulse 21 is complete and invalid at owner preflight. The exact focused command
passed, but the exact full command exited 101 because two non-ignored VFX
tests attempted to launch unavailable FFmpeg and panicked with program not found. Planning and measurement did not start, cleanup completed, and all
adopter research clones remained clean. Pulse 21 grants no FFmpeg installation,
retry, advisory CI, or support-readiness authority.
The active
context/waves/2026-09-16-environment-readiness/ wave has completed Pulse 01
research only. It selects an owner-declared, product-neutral readiness contract
on the existing doctor surface and preserves Cargo, rustup, environment
managers, container formats, Devfile, and repository-owner authority. The first
candidate slice may later cover only explicit platform, executable,
environment-name, and repository-relative path observations with no retained
values. No contract, product implementation, adapter, installation, repair,
shell evaluation, lifecycle execution, network access, secrets, resource
probe, inference, or adopter change is currently authorized.
The user's next fresh continue authorized Environment Readiness Pulse 02
contract work only. READINESS-001 is Draft with frozen requirements, report,
and command-result schemas; ready, state, and pre-report vectors; negative
controls; exact passive observation semantics; privacy exclusions; and
removal. V1 accepts only an explicit owner declaration, interprets no
owner-native source, retains no environment value or resolved path, and
performs no command or version execution. Pulse 02 is complete and grants no
implementation, adapter, repair, resource probe, adopter change, or Pulse 03
authority.
The user's next fresh continue authorizes Environment Readiness Pulse 03
only: one optional doctor --requirements <JSON> implementation of the frozen
V1 contract and targeted conformance proof. Existing doctor behavior without
that input must remain unchanged. The pulse may parse only the explicit Ferris
file and passively observe platform, executable-name resolution,
environment-name presence, and repository-relative path kind. It must retain
no values or resolved paths. No owner-native source adapter, version or owner
command execution, installation, repair, shell or lifecycle evaluation,
network, service, credential, capacity probe, Action Plan eligibility, adopter
change, CI replacement, support, production, or savings claim is authorized.
Environment Readiness Pulse 03 is complete. The optional requirements path
implements strict bounded V1 parsing, four passive observation kinds,
deterministic privacy-safe identities, stale-input detection, typed
report-bearing non-success outcomes, and targeted frozen-control, schema,
Windows, cfg-specific Unix, privacy, failure, and legacy-mode tests. It
requires an explicit manifest and never invokes Cargo for discovery. Legacy
doctor remains unchanged without requirements. Pulse 03 authority is
exhausted; source adapters, active probes, repair, owner execution, adopter
work, support, production, performance, savings, and Pulse 04 remain
unauthorized.
The user's next fresh continue authorizes Environment Readiness Pulse 04
only: evaluate asdf .tool-versions against frozen public fixtures and
READINESS-001 V1 with one dependency-free test-only lexical harness. Do not add
a product adapter or schema change; discover parent or user configuration;
invoke asdf or plugins; install or resolve versions; mutate an adopter; make a
support claim; or begin Pulse 05.
Environment Readiness Pulse 04 is complete with a no-go result. The frozen
asdf evidence shows that .tool-versions plugin IDs do not determine
executable leaves and that version, fallback, system, path:, and ref:
selection cannot be represented by READINESS-001 V1. The test-only evaluator
passed over public fixtures; no product code, schema, dependency, adopter, or
owner environment changed. Pulse 04 is exhausted and grants no owner-mapping
contract, adapter, or Pulse 05 authority.
The user's next fresh continue authorizes Environment Readiness Pulse 05
only: one local Windows, read-only readiness shadow over the two custody-bound
private enterprise consumers. Temporary requirements and raw reports must stay
outside both repositories and public records must use only EO-01 and
EO-02. The pulse may compare inherited missing-Cargo evidence with
process-local visibility of the existing Cargo directory, verify determinism,
privacy, source immutability, and cleanup, then stop. Do not run owner commands,
invoke asdf or plugins, install or repair anything, persist environment
changes, mutate a consumer, change product code or schemas, make performance or
support claims, or begin Pulse 06.
Environment Readiness Pulse 05 is complete. Both private enterprise consumers
reported blocked, exit 7, with exactly Cargo missing under the inherited
Windows environment before owner work. Process-local visibility of the
existing Cargo directory changed both to success, exit 0; repeated outputs
were byte-identical, privacy checks passed, source trees stayed clean, and all
temporary inputs and raw results were removed. V1 remains scoped to one
selected Cargo manifest and does not establish application-root readiness.
Pulse 05 is exhausted and grants no Linux shadow, application composition,
adoption, support, production, or Pulse 06 authority.
The user's next fresh continue authorizes Environment Readiness Pulse 06
only: one documentation/schema/fixture-only contract for passively composing
existing READINESS-001 workspace reports across an explicit
ferris.application/v0 definition. It may bind two to sixteen independent
workspace roots, preserve every child result, define fail-closed aggregate and
stale semantics, freeze controls, and record eleven-role review. Do not
implement product behavior, invoke Cargo or owner commands, add
application-root requirements, modify an adopter, or begin a successor.
Environment Readiness Pulse 06 is complete. APP-READINESS-001 is Draft with strict request and aggregate-report schemas, exact-byte public fixtures, blocked and stale precedence vectors, and negative controls. It rejects member-package manifests, duplicate or nested workspace roots, definition drift, and child binding mismatch while preserving each workspace report. Application-root path requirements remain deferred rather than reusing workspace V1 semantics. Pulse 06 is exhausted and grants no implementation, adopter, support, or successor authority.
The user's next fresh go authorizes Environment Readiness Pulse 07 only: one
optional doctor --application-readiness <REQUEST_JSON> implementation of the
frozen APP-READINESS-001 contract and targeted conformance proof. It may
strictly and passively load the explicit request, Application Definition,
workspace manifests, and READINESS-001 declarations; preserve each child
report; compose exact stale/blocked/incomplete/unsupported/ready precedence;
and emit deterministic privacy-safe output. Do not invoke Cargo or owner
commands, add application-root requirements, change dependencies or adopters,
make support or performance claims, or begin a successor.
Environment Readiness Pulse 07 is complete. The optional
doctor --application-readiness <REQUEST_JSON> path strictly and passively
binds an explicit Application Definition, two to sixteen workspace-root
manifests, and exact READINESS-001 declarations. It preserves independent child
result references, applies fail-closed worst-state precedence, rejects
filesystem aliases and links, and makes exact input replacement stale. Targeted
core, CLI, frozen-control, privacy, non-execution, identity, and legacy tests
passed, and the final independent review was clean. Pulse 07 is exhausted and
grants no application-root requirements, source adapter, adopter, execution,
support, production, performance, savings, or successor authority.
The user's next fresh go authorizes Environment Readiness Pulse 08 only: one
local Windows, disposable APP-READINESS-001 shadow over the custody-bound
private multi-workspace consumer identified publicly only as EO-02. It may
bind exact revisions, derive workspace IDs and manifests from the existing
owner topology, compare inherited missing-Cargo aggregation with process-local
Cargo visibility, and verify determinism, privacy, non-execution, source
immutability, and complete cleanup. Do not change product code, schemas,
dependencies, the source consumer, owner commands, persistent environment,
adoption, support, production, performance, savings, or begin a successor.
Environment Readiness Pulse 08 is complete. The exact APP-READINESS-001
implementation ran in one disposable local Windows clone of private EO-02.
Two ready children did not hide one missing-Cargo child: the aggregate returned
blocked, exit 7. Process-local Cargo visibility made all three children and
the aggregate ready, exit 0, and the repeat was byte-identical. Privacy,
identity, source immutability, and cleanup checks passed; no owner command ran
and no raw private output or disposable clone remains. Pulse 08 is exhausted
and grants no Linux rerun, adoption, support, production, performance, savings,
or successor authority.
The active
context/waves/2026-09-21-application-readiness-onboarding/ wave has one
research-only Pulse 01 authorized by the user's fresh go. It may inventory
current installation and explicit-input authoring, measure duplication in the
public APP-READINESS-001 fixture, and decide between documentation, a narrow
deterministic request binder, broad generation, or no product change. It may
correct directly related command documentation. It must not change product
behavior or schemas, infer requirements or workspaces, combine readiness with
Action Plan preparation or execution, modify a private consumer, or authorize a
successor.
Application Readiness Onboarding Pulse 01 is complete. The frozen
three-workspace fixture requires ten cross-record equality bindings, four exact
digest bindings, and three explicit requirements associations. Research selects
only a future narrow deterministic binder over explicit owner files, an
explicit output request path, and the existing schema. Broad init, inferred
requirements, Cargo discovery, environment observation, and Action Plan
coupling are rejected. Pulse 01 is exhausted and grants no implementation,
adopter, installation, execution, support, production, performance, savings,
or successor authority.
The completed
context/waves/2026-09-22-contract-catalog/ Pulse 01 authorizes only the
read-only contracts command and its deterministic
ferris.contract-catalog/v1 output. It reports exact schema identifiers that
one installed binary accepts or emits, including legacy-read-only behavior.
It does not negotiate or migrate versions, inspect repositories or remote
state, authorize execution, or establish a production-support commitment.
The completed
context/waves/2026-09-22-contract-requirements/ Pulse 01 authorizes only
strict, bounded evaluation of explicit adopter schema-handling requirements
against the local contract catalog. It does not compare record semantics,
infer requirements from repositories, negotiate or migrate versions, or claim
a multi-release support window. The synthetic fixture is controlled evidence,
not natural adoption.
The
context/waves/2026-09-10-private-corpus-generator-portability/ wave records
separate explicit owner approval for one bounded correction of the private
EC-04 deterministic generated-topology integrity failure found by the
enterprise-corpus qualification. Pulse 01 proved platform-native CRLF output
caused the mismatch, changed only the private generator to emit explicit
UTF-8/no-BOM/LF bytes, and passed the unchanged corpus on Windows and hosted
Ubuntu. The private pull request was merged only after separate explicit user
direction. The pulse is complete and
does not authorize Ferris product changes, scenario changes,
generated-topology semantic changes, or rerunning the exhausted qualification.
The
context/waves/2026-09-10-corrected-enterprise-corpus-qualification/ wave
records separate explicit owner approval for one fresh qualification over the
merged corrected private corpus cutoff. Pulse 01 is complete and incomplete:
all five Windows owner preflights passed, 17 small and scale scenarios produced
durable matched evidence, and the federated runner then exceeded the Windows
process command-line limit before launching its maximum-input case. Its earlier
in-memory cases were not durably emitted and remain not observed. No hosted
Ubuntu branch or job ran. The pulse adds no product or scenario behavior and
does not authorize a runner fix, retry, workflow narrowing, production
representativeness, support, savings claims, or any successor run.
The
context/waves/2026-09-10-private-federated-runner-portability/ wave records
separate explicit owner approval for one bounded correction of the private
EC-05 federated runner. Pulse 01 is complete: only its Ferris process launch
changed to use the application root as the working directory and relative
in-application arguments, preserving the absolute outside-path negative
control and all 256 maximum inputs. The complete Windows owner and federated
suites passed, and the private pull request's hosted Ubuntu owner workflow
passed. The runner itself was not executed on hosted Ubuntu. The private pull
request was merged only after separate explicit user direction. The pulse does
not authorize a Ferris product change, scenario change, qualification retry,
support, production representativeness, or savings claim.
The
context/waves/2026-09-10-post-portability-enterprise-corpus-qualification/
wave records explicit user approval for one fresh evidence-only qualification
after both private owner-tooling corrections merged. Pulse 01 may freeze one
unchanged public Ferris product revision and five exact corrected private
default-branch revisions, then run every existing owner gate and declared
scenario on local Windows and hosted Ubuntu. It may create one temporary
hosted-validation branch per private repository only to invoke those unchanged
scenarios; those branches must not merge and must be removed after custody. It
does not reuse prior attempts as qualification evidence. Pulse 01 is complete:
all five owner gates passed on Windows and hosted Ubuntu; all 26 scenarios on
each platform matched their contracts with stable identities, including two
declared matched failures, seven conservative fallbacks, both 256-input
boundaries, and three typed rejections with no owner execution. No
selected/full divergence occurred. All temporary pull requests closed without
merge and all temporary branches were removed. This qualifies the corpus as a
deterministic regression and demonstration suite only; it authorizes no
product, scenario, owner-command, support, production, affected-only,
performance, or savings change or claim.
The
context/waves/2026-09-09-real-history-validation-shadow/ wave records
explicit user approval for one bounded local evaluation pulse after PR #26.
Pulse 01 evaluated exactly 40 first-parent revisions from BISECT and
ICELINES, repeated revision-bound planning, and executed only owner commands and
required non-secret environments present at the historical revisions for the
three non-fallback cases. It retains bounded public evidence but adds no product
behavior and does not authorize adopter mutation, CI narrowing,
prevented-iteration, support, or realized-savings claims. The pulse is complete
and its planning and execution authority is exhausted; any new cohort, rerun,
or implementation requires separate approval.
The
context/waves/2026-09-11-enterprise-onboarding-proof/ wave records explicit
user direction to create additional purpose-built private enterprise consumers.
Pulse 01 authorizes only two private owner-native baselines, identified publicly
as EO-01 and EO-02: one ordinary Cargo workspace and one explicit
multi-workspace application shape. They must establish ordinary owner commands,
hosted Ubuntu CI, deterministic topology and scenario contracts, removal
invariants, and private custody before any Ferris adoption. Pulse 01 is complete
and incomplete: both repositories passed their Windows owner gates, but the
enterprise host kept repository Actions disabled, so zero hosted jobs ran and
no owner-baseline tag was frozen. The pulse stopped without alternate CI,
credentials, a third repository, or Ferris onboarding. It grants no Ferris
product change, consumer Ferris dependency, onboarding adapter, Action Plan,
execution, workflow replacement, production, support, performance, or savings
authority. Pulse 02 remains not authorized.
The active
context/waves/2026-08-12-platform-profile-conformance/ wave currently
authorizes Pulse 01 documentation and governance plus Pulse 02's frozen
ferris.platform-profile/v1 schema documents, incomplete exemplar, exact
negative-control mutations, and review. Pulse 03 additionally authorizes one
dependency-free test-only Rust harness that executes those controls. Do not
add production schema types. Pulse 04 authorizes only the pure-data family,
its two zero-dependency consumer revisions, isolated locked/offline owner
commands, source snapshots, and test-only profile materialization. Do not
add external dependencies or generate a product profile. Pulse 05 additionally
authorizes only the CLI/configuration family and reusable integration-test
support for later controlled families. Do not complete another family,
construct hidden held-out material, score an oracle, or change PLATFORM-001
status until the corresponding later pulse and role review grant that exact
authority.
Pulse 06 additionally authorizes only the in-process hosted-service family. Do not add sockets, network, databases, TLS, credentials, deployment, or production service behavior.
Pulse 32 is now permanently closed invalid at cutoff-build-freeze.
Checkout and package gates passed, but custody could not freeze the Ubuntu
executable; zero preflight, public-input validation, cases, or candidates ran,
and the conclusion is null. Pulse 33 authorizes only the public external
build-freeze release, root-cause record, governance, review, and test-only
validation. It records a WSL non-login PATH omission, explicit rustup Cargo
discovery, Cargo JSON artifact output, and deterministic Windows/Ubuntu
build hashes without executing a diagnostic or changing product code.
Pulse 34 authorized one independent diagnostic at an immutable cutoff that
contains the complete Pulse 33 release and predates the authority. Public
checkout, binding, package, build-freeze, adapter-preflight, and input gates
passed, but isolated corpus materialization did not complete. Pulse 34 is
permanently closed invalid with zero candidate launches, a null conclusion,
and no retry or reuse authority.
Pulses 69 through 82 are sealed successor infrastructure only. The latest callable chain terminates at Pulse 82 over the Pulse 78 staging/bootstrap hardening and Pulse 81 exact Pulse 35 release-tree binding. These releases grant no diagnostic authority and perform no real FERRIS execution. Any successor authority requires a separate approved pulse with an immutable pre-authority cutoff.
Pulse 83 is governance/test-only readiness evidence at merged cutoff
dfc889b. It grants no authority and invokes no Pulse 82 callable. A future
authority must use a later self-excluding cutoff containing the complete Pulse
83 review.
Pulse 84 authorizes exactly one later independent invocation attempt of the
exact Pulse 82 callable at self-excluding cutoff f874ebf. This pulse records
authority only and performs no custody or execution. Failed pre-call gates do
not consume authority; the sole callable attempt does, and no retry, resume,
alternate callable, score, fix, support, or PLATFORM-001 authority follows.
Pulse 85 permanently closes Pulse 84 after its sole consumed invocation
stopped not-attempted at Ubuntu capability build custody with
P57-WSL-BUNDLE. Windows custody passed, no seed or candidate ran, no terminal
publication or transfer occurred, cleanup completed, and all conclusions
remain null. Pulse 84 cannot be retried or resumed.
Pulse 86 is sealed prospective capability infrastructure only. It byte-binds
exact Pulse 78, derives the WSL operational username from the native runtime
parent's owner through one explicit-root read-only lookup, and binds every
staging, revalidation, worker, and cleanup spawn with --user. It filters no
stderr, grants no authority, and does not retry or reinterpret Pulse 84.
Pulse 87 is the sealed ordered successor over exact Pulse 86. It preserves
Pulse 81's exact Pulse 35 release-tree binding and Pulse 70/Pulse 58 ordering,
carries the parent-owner WSL identity into the ordered layer, and preserves
P86-INDETERMINATE-STAGE-CLEANUP before seed creation. It grants no
publication, witness, or authority.
Pulse 88 is the sealed witness-preserving successor over exact Pulse 87. It
retains Pulse 82/Pulse 59 terminal publication and cleanup semantics, proves
P86-INDETERMINATE-STAGE-CLEANUP remains publication-not-attempted, and
grants no diagnostic authority or real execution.
Research and specifications
- Inventory local evidence before using external sources.
- Cite actionable research claims with files, line ranges, URLs, or measured commands.
- Give findings stable
FERRIS-*identifiers; retain historicalFERRIUM-*identifiers unchanged. - Use MUST, MUST NOT, SHOULD, SHOULD NOT, and MAY according to
docs/specs/README.md. - Keep specification dependencies acyclic and owner-aligned.
- Do not mark a specification Proposed or Adopted without its stated fixtures, measurements, and role approvals.
- A review must record all nine role dispositions, completed revisions, remaining gates, and implementation authority.
Validation and commits
- Validate Markdown links and code fences for changed documentation.
- Run
git diff --check. - Review staged paths and the specification dependency graph before committing.
- Keep logical changes in focused commits.
- Include the required Copilot co-author trailer when applicable.
- Do not push unless requested.
- Keep Ferris child-repo commits separate from TRACKER submodule-pointer updates.
