You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
program(conformance): evidence rules and differential oracle harness — one Electron pin per corpus, shared corpus-manifest owner, red-until-implemented cells, pinned Electron recorder, Keld replayer, comparator, lanes #493
Generated by an AI agent (Claude Code) on behalf of @0monish during Wayfinder charting of the Electron compatibility program; rewritten 2026-10-07 by the doctrine-audit repair pass (change log at the end). Planning only — no implementation is authorized by this issue.
X01 owns the evidence machinery that every Electron-compat claim passes through. It works in two layers with different milestones.
First-proof evidence rules (X01-T3 spec, X01-T4 shared owner; milestone first-proof). These are: one Electron oracle pin per corpus, with the v44.4.5 tag commit 694f45852a0f1726cd23bfd379854de489cccb65 as the default for every new corpus; a per-cell citation of the pinned doc; red-until-implemented cells; the rule that observed-only means unknown; the meaning of artifact.sha256; the authority-profile label; and one shared corpus-manifest and exact-bytes owner in keld-compat. Every new corpus reuses that owner. The first-proof consumers are the conformance entries (F01-T1, F03-T1, F04-T1), the X02-T5 product cell contract (consumes X01-T3), the X02-T4 product corpus manifest (consumes X01-T3 and X01-T4), and the X02-T6 scoring run, which runs the corpus under the X01-T4 validator. None of these first-proof consumers gates on X01-T1: they need the rules and the helpers, not the two-arm recorder.
Differential oracle harness (X01-T1 spec and X01-T2 lifecycle tracer at milestone next; X01-T5 scheduled lane parked). Arm A records Keld-owned fixtures under the SHA-256-verified Electron 44.4.5 binary. Arm B replays the same unmodified fixtures under @keld/electron. A comparator in keld-compat emits one KEL-74 record per cell. INFERENCE (from their ticket text; edges owned by those units): the next-milestone conformance tickets F03-T6 (recorded undocumented behaviour) and F08-T3 (an UNKNOWN destroy-time render-process-gone oracle cell) genuinely need recorded Electron observations, so they stay on X01-T1.
The oracle is the pinned doc sentence. A golden transcript is only evidence-of-record (decision X01-A1; it survived both refuters).
FACT: X01 owns no Electron API member. The compat matrix assigns all 2,128 members of the 180 entities in the v44.4.5 API model to F01–F09. X01 records evidence for the cells those families define. It never claims coverage itself.
Corpus demand
FACT: the first proof is drawio-desktop on macOS under the explicit legacy profile. It consumes two things from X01: conformance entries that cite v44.4.5 sentences (F01-T1, F03-T1 and F04-T1 are first-proof conformance tickets), and a second corpus (electron-apps-v0, panel product: X02-T5 cell contract, X02-T4 manifest, X02-T6 scoring run that flips the cells). Neither needs recorded Electron goldens, because product cells reuse the KEL-237 runner pattern. So no edge from X02-T4, X02-T5 or X02-T6 to X01-T1 or X01-T2 is a real gate; their real X01 edges are X01-T3 (rules) and X01-T4 (helpers and validator).
FACT (package manifests of the pinned corpus clones): the declared Electron ranges are draw.io ^44.2.0, electron-quick-start ^44.4.3 and Zettlr ^43.6.0. Zettlr's range excludes 44.4.5, so the Zettlr proof needs either a second pin or a recorded out-of-range run. That question is parked until Zettlr work starts.
FACT (recount on the pinned clones, 2026-10-07): literal app.exit( call sites are draw.io 3 (export-mode and error paths, not on the four-step workflow) and Zettlr 2. draw.io has no <webview> demand: every hit is webviewTag: false or a will-attach-webview preventDefault. No recorder cell is motivated by either.
INFERENCE: the token-scan usage files credit a generic event name to every entity that declares it. Deduplicate by receiver type before letting event counts drive cell priority.
Maturity ladder
The ladder rungs are report vocabulary over the four KEL-74 verdicts. They are never a second verdict set. FACT: the evidence parser accepts only pass|fail|unknown|waived, and records reject unknown fields.
BEHAVIOR_MATCH: the Keld transcript equals the golden under declared normalisers on at least one OS. A cell with no doc citation (observed-only) is recorded unknown, with its oracle id naming the unspecified path. It is never pass.
CONFORMANCE_PASS: a cited pinned sentence, a Keld-owned test independent of any transcript diff, and a named negative control. The cell is pass per OS lane. An unrun lane stays unknown or carries an explicit ▲.
CORPUS_VERIFIED: the same observable is matched in a committed corpus app through migrate + dev smoke. It goes on panel product only after that corpus id is documented as committed (X02-T6 adds it in the same reviewed change that flips the cells).
Correction: the published epic called this "the ladder every family uses". That contradicted the family epics, which own L0–L3 maturity targets. X01-T3 records the mapping: a family L2 exit requires CONFORMANCE_PASS cells, and a family L3 exit requires CORPUS_VERIFIED rows.
Tracker of record and Linear owners consumed (Linear and GitHub, fetched 2026-10-07, read-only)
Owner rule consumed as text, not as a blocker: X06-D7 (#517) is CLOSED (closed 2026-10-06T20:32:52Z) with the owner decision recorded by @0monish: align each repo-writing ticket to the nearest live Linear issue whose scope covers it and claim there; otherwise the GitHub issue is the tracker of record (claim, status, handoffs and evidence on GitHub, earliest claim comment wins) and no Linear issue is created; every GitHub ticket is referenced by a link on the nearest live Linear issue for its surface, falling back to KEL-127. The map orchestrator is the single Linear writer for those reference links.
KEL-74, Done (GYLDLAB): evidence schema, parser and score(). Consumed unchanged, as landed on origin/main 8678c0d. The documented committed-product list is empty.
KEL-237, In Progress, unassigned: the lifecycle corpus, landed in b36b0ad (PR test(compat): commit bounded lifecycle corpus #242). It provides the manifest, the exact-bytes digest assertion with its one-byte mutation control, and the execution-admission checks. Its non-goals exclude new Electron API implementation and compatibility-surface expansion. Under X06-D7 it is the aligned tracker of record for X01-T3 and X01-T4. INFERENCE: that work falls inside the manifest contract KEL-237 already owns. If the KEL-237 owner contests this, those two tickets fall back to their GitHub issues as tracker of record, linked from KEL-237. KEL-237 is also the nearest live surface carrying the Linear reference links for X01-T1 and X01-T2 (INFERENCE).
KEL-77, In Progress, unassigned: the VS Code extension-host differential harness. Its spec supplies the shape X01-T1 consumes (§4.1 three-state rule and mirror-oracle rejection, §4.3 fixture-set digest, §4.5 field table). It is not X01's owner.
KEL-78, In Progress (GYLDLAB): profile states unverified | legacy | strict. Legacy requires an explicit Keld declaration. unverified has no KEL-74 authority value.
KEL-81, Done, unassigned: changed-path CI routing. It is not live, so it cannot be the tracker of record for a new scheduled lane.
KEL-127, Todo, unassigned: the program fallback for Linear reference links under X06-D7 (used by X01-T5).
GitHub tracker of record (no covering live Linear issue): X01-T1, X01-T2 and X01-T5. Each is claimed on its own GitHub issue per X06-D7. Who can act: any agent may post the ## Agent claim comment on the GitHub issue; the orchestrator posts the Linear reference link.
Design facts (labelled)
FACT: the corpus manifest contract is test-local today and has no shared owner. The lifecycle validator:
parses a deny-unknown-fields manifest whose corpus-level upstream block carries only an app doc URL;
hard-asserts the pin 44.3.0 @07e46071;
admits exactly two test targets;
allows expected_verdict only as pass, or as fail with an intentional divergence.
No red-until-implemented state exists.
FACT: the KEL-77 §4.3 fixture-set digest is a private helper inside the keld-runtime test target. In keld-compat, sha2 is a dev-dependency only, and the crate manifest records that a production sha2 dependency was rejected.
FACT: artifact.sha256 has two live meanings. KEL-237 records carry the manifest digest; KEL-77 §4.5 uses the fixture-directory digest.
FACT: the published lifecycle records are bound per OS to hosted-CI receipts of PR test(compat): commit bounded lifecycle corpus #242. Re-pinning that corpus therefore needs fresh receipts on all three OS. It is not a text edit.
FACT: diffing the app doc between Electron commit 07e46071 (44.3.0) and the v44.4.5 tag finds one prose change, in the getPath sessionData description. The other hunks are example formatting. The lifecycle sentences the three live cells cite are unchanged.
FACT: @keld/electron exports only app plus isCallError/KeldCallError. keld-cli has no --headless flag or verb. No window registry exists. So the Keld arm has no BrowserWindow, preload or renderer, and the first harness cells must be main-process only.
FACT (pinned ESM tutorial, byte-identical at the v44.4.5 tag, fetched 2026-10-07):
an ESM main entry is supported when the nearest package manifest has "type": "module";
"Preload scripts will ignore type: module fields";
sandboxed preloads run without an ESM context;
"your app may be ready before your code executes".
FACT (npm registry and the release SHASUMS256, fetched 2026-10-07): electron@44.4.5 has dist.shasum 0be094f8e783febba75d591106f5c61c1e511b70 and no install scripts, so the binary downloads lazily on first run. Zip SHA-256 values: darwin-arm64 a212eee63ba2f45fd83bd28f77a3e3313a336ad17a4c25adf617942eef5e0e2c, linux-x64 04586a0ec46c3283fbdaef85530f561f71f0b5e136ad0cb9ef63683615609780, win32-x64 11c395820a5aaa8ebcc0686b476d0ac98a730274ebfbdc8cf5538a7c2815cb5d.
FACT (refuter receipt from Electron's pinned test workflow, retrieved 2026-10-06, not re-fetched): Electron reruns its own tests up to three times on every non-ASAN lane. Its macOS lane sets ApplePersistenceIgnoreState, because repeated abnormal exits make AppKit's reopen alert hang app.whenReady() (electron#51462).
FACT: the Keld repository has two workflows and neither is scheduled. CI required aggregates PR and push jobs only.
FACT: the live lifecycle test waits on stdout markers with an 8-second kill-switch timeout, then panics without killing the spawned Bun child. A std child process is not killed on drop.
UNKNOWN: whether renderer rows interleave stably with main rows (X01-A5 arm D, a lead for X01-T1).
UNKNOWN: the recorder's runner cost and display needs on hosted Windows and Linux.
Platform lanes
PR lane: the existing three-OS matrix, running manifest validation and Keld-arm replay only, offline and deterministic. Each OS is scored separately. The Electron arm never runs here.
Recorder: a macOS arm64 developer command first (X01-T2), using the verified zip.
Parked (X01-T5): a Linux recorder under a virtual display, a Windows recorder, and the scheduled drift lane with its failure sink.
Running or mechanically translating Electron's spec tree (Mocha runner) under Bun
Fetching Electron latest or main, or recording from an unpinned or unverified binary, including a lazy npx download at record time
Committing the Electron binary, or running the Electron arm in the PR lane
Re-recording goldens from the Keld arm, or auto-updating goldens on a diff
Retries, reruns (Electron's own rerun setting is not copied), todoIf(isCI), bare skips or sleeps in harness cells
Any percentage or 'compatible' claim without a committed denominator; a product-panel row before the corpus id is documented as committed
Labelling the test-process harness or an unverified-profile run strict_bun, or inventing an authority_profile value
Scoring an observed-only (uncited) cell pass, or writing ladder rungs as evidence-record verdicts
Normalising event name, kind, order, Error.message or exit code
Comparing wall-clock timing as a conformance verdict (timing metrics belong to X05's registered metrics)
Adding fake @keld/electron named exports so that an unrelated fixture links
Fixtures using nodeIntegration:true, remote, child_process, custom-scheme privileges or network
A second manifest struct, digest helper, verdict vocabulary or per-family Electron pin
Out of scope
Electron API entities: none are owned by X01. The compat matrix assigns all 2,128 members of the 180 v44.4.5 entities to F01–F09; X01 records evidence for the cells those families define and claims no coverage
The electron-apps-v0 product corpus: cell contract (X02-T5), manifest (X02-T4), and the scoring run that flips cells and adds the corpus id to the committed product list (X02-T6)
Window-all-closed emitted during a host-initiated quit (no quit-in-progress state in the host lifecycle): owned by the F01 quit slice (F01-T3), the keld-core lifecycle owner
Per-family deferred/never rows (F04-T5 keeps those; the pin moved to X01-T3)
Performance and timing metrics (X05 registered metrics)
The live lifecycle test's orphan-child leak on timeout and the CLAUDECODE Bun reporter trap: KEL-237 (comment 6964244b)
Not yet specified (fog)
Zettlr pin: Zettlr declares ^43.6.0, outside 44.4.5. Decide between a second pin and a recorded out-of-range run when the Zettlr proof starts
KEL-78 unverified state versus the closed KEL-74 authority vocabulary: reconciliation belongs to the KEL-78 owner (In Progress, GYLDLAB); X01-T3 only refuses to invent a value
Renderer/preload cross-process ordering rule: X01-A5 arm D is a lead for X01-T1
Whether the separate corpus repository and the Keld repository share one manifest format or the corpus repository ships only goldens and receipts
Windows/Linux recorder runner cost and display requirements (unverified until a first X01-T5 run)
Decisions that govern this unit (closed decision tickets)
none
Change log (doctrine-audit repair, 2026-10-07)
Scope split into first-proof evidence rules (X01-T3 spec, X01-T4 shared owner) and the next/parked differential harness (X01-T1, X01-T2, X01-T5) (critic yagni X01-T1/X01-T2; rule 2; F01 frontier on red-entry mechanism).
States that X01 owns no Electron API member and enumerates that every matrix member is family-owned (rule 9 accounting; critic coverage-gap context).
Maturity ladder restated as report vocabulary over the KEL-74 verdicts, with observed-only = unknown. Corrected the false claim that every family uses this ladder; X01-T3 now maps the rungs to the family L2/L3 exits (refuter A1 corrections from both lenses; ladder-mapping extra finding).
Design facts relabelled. The weekly lane is now TARGET, not an existing home. Added the Electron binary identity (zip SHA-256, no install scripts), the ESM preload and ready-timing sentences, the macOS recorder hazard, reruns on every non-ASAN lane, the reaping gap, the two artifact.sha256 meanings, the test-local manifest and digest helpers, and the receipt-bound lifecycle records (refuter A2/A3/A4/A5/A6 corrections and extra findings).
Corpus demand corrected: Zettlr's ^43.6.0 pin consequence, no webview demand in draw.io, the app.exit recount, and the usage-scan over-attribution caveat (refuter version-coherence, stale-webview and over-attribution extra findings; app.exit counts recounted).
Replaced the inaccurate 'no headless in crates' wording with 'keld-cli has no --headless flag or verb' (refuter minor factual slip finding).
The program-wide Electron pin moved from F04-T5 into X01-T3 (critic duplicate F04-T5/X01-T1).
never_list, out_of_scope and not_yet_specified now enumerate every unowned atom, including the product corpus id owner, KEL-78 vocabulary reconciliation, the Zettlr pin and the keld-core quit-in-progress owner (F01-T3) (rule 9; refuter extra findings).
X06-D7 is no longer treated as open: Linear owner for repo-writing Electron-compat slices (owner decision: align to nearest Linear issue, else GitHub is the tracker of record) #517 is CLOSED (gh, fetched 2026-10-07; closed 2026-10-06T20:32:52Z) with the @0monish owner decision. The Linear owners section is now 'Tracker of record and Linear owners consumed': it states the adopted resolution as text, makes KEL-237 the aligned tracker for X01-T3/X01-T4, makes GitHub the tracker of record for X01-T1/X01-T2/X01-T5, and adds KEL-127 (Todo, unassigned; Linear fetched 2026-10-07) as the reference fallback. X06-D7 is removed from every X01 blocked_by_keys (cross-checker finding: blocked_by names a closed decision).
Scope and Corpus demand now state that the first-proof consumers F04-T1, X02-T5, X02-T4 and X02-T6 take X01-T3 (rules) and X01-T4 (helpers and validator), never X01-T1. F03-T6 and F08-T3 stay on X01-T1 as an INFERENCE from their text. The edge, AC and title edits in F04/X02 are left to those repairs and listed in unapplied_findings (cross-checker finding: first-proof slices gated on a next-milestone spec).
Every 'X02-T4' reference that meant the run which flips the product cells now names X02-T6. X01-T4 is named as a validator edge X02-T6 must have upstream. The rest of X02-T6's missing gate set is handed to the X02 repair in unapplied_findings (cross-checker finding: X02-T6 gate set incomplete).
Audit findings not applied (with the evidence-backed reason)
Critic coverage gap: F06 structures (ActivationArguments, ClipboardBookmark, DesktopCapturerSource, NotificationResponse, PaymentDiscount, ProductDiscount, ProductSubscriptionPeriod, Product, SharingItem, ShortcutDetails, Transaction, UserDefaultTypes) are covered only by a blanket promise. — These are not X01 entities. The compat matrix assigns them to F06, and the only link to X01 is the word 'Product' in the old epic. The F06 repair owner enumerates them (critic fix: F06-T6 or F06-EPIC out-of-scope).
Critic edge finding X02-T4: add edges from F01-T2, F01-T4, F02-T2, F02-T3, F03-T2, F03-T5, F04-T3, F04-T4, F05-T4, F06-T2, F06-T4, F06-T5, F07-T1, F09-T1, X03-T1, PANEL-P1 and PANEL-P3 to X02-T4. — Those edges now belong to X02-T6, the scoring run that flips the product cells; the X02 repair already carries them there. The X01 side is applied: X01-T2 records that it is not a gate for X02-T4 or X02-T6, and X01-T4 names X02-T4 and X02-T6 as edges to take.
Cross-checker (high): replace X01-T1 with X01-T3 (+ X01-T4) in F04-T1, X02-T4 and X02-T5 blocked_by_keys, reword F04-T1 AC3 and the X02-T4 title; leave F03-T6 and F08-T3 on X01-T1 if they need the recorder. — Applied on the X01 side only (epic Scope and Corpus demand, X01-T1/X01-T3/X01-T4 notes, X01-T4 key_interfaces). The edge, acceptance-criterion and title edits are in tickets owned by the F04 and X02 repairs, not in this unit. Evidence for those owners: F04-T1 is blocked by X01-T1 and its AC says 'the single Electron oracle pin recorded by X01-T1', but X01-T3 AC2 owns the pin rule; X02-T4's what_to_build says the helpers are 'the shared keld-compat owner that X01-T1 specifies', but X01-T4 implements them under X01-T3 AC6. X02-T5 consumes the X01-T3 rules. INFERENCE from their text: F03-T6 (recorded undocumented behaviour) and F08-T3 (UNKNOWN destroy-time render-process-gone oracle cell) need recorded Electron observations, so they stay on X01-T1.
Cross-checker (high): add F02-T4, F04-T12, F05-T7, F06-T7 (conditionally on PANEL-P1 arm B), F06-T8, X03-T4, X03-T7 and X01-T4 to X02-T6.blocked_by_keys. — X02-T6 is owned by the X02 repair, so the edge list cannot be edited here. The X01 part is applied: X01-T4 now names X02-T6 as a consumer that must have the validator upstream (directly or through X02-T4). The 'X02-T4 consumes' wording in X01 is renamed to X02-T6 wherever it meant the flipping run (X01-T1/T2/T3/T5 out_of_scope and notes, epic out_of_scope, Maturity ladder, the critic-edge reason above).
Refuter (semantics lens) extra finding: 'drawio app.exit 7 sites, Zettlr 14', plus other per-member demand counts and 'grep corpus deps for versions.electron'. — A recount on the pinned clones (2026-10-07) contradicts the app.exit counts: literal app.exit( calls are 3 in draw.io (error/export paths) and 2 in Zettlr. The other counts are F01–F04 family demand owned by those epics, and the versions.electron dependency scan belongs to X03. The X01 epic cites only the corrected app.exit recount.
X06-D6 (semantics): 'the three existing lifecycle cells can be re-pinned to v44.4.5 mechanically, since their oracle text is unchanged'. — Partly wrong. The oracle text is indeed unchanged (verified: the app doc diff from 07e46071 to v44.4.5 changes only getPath sessionData prose plus example formatting). But the published records are bound per OS to the PR test(compat): commit bounded lifecycle corpus #242 hosted-CI receipts, so a re-pin needs fresh receipts on three OS and is not mechanical. X01-T3 therefore keeps electron-lifecycle-v0 frozen at 44.3.0, puts new v44.4.5 cells in a new corpus id, and leaves the re-record decision to KEL-237. The rest of X06-D6 (claim rule, SHA-based predecessors) is applied.
X06-D1 (both lenses): the KEL-127 entry-condition reading, the KEL-143 hard edge, and preload-injection ownership moving from KEL-79. — None of these is an X01 surface. X01 consumes no spine artifact beyond the KEL-74/KEL-237 evidence owners. X06-D8 (closed) records the resolution.
X06-D4 (both lenses): reshape and park the agent-instruction skill ticket. — This is an agent-instruction surface owned by X06 and is not an X01 surface.
X06-D5 (both lenses): add gate:wire-protocol, gate:permission-model and gate:public-api labels where ticket bodies name those gates; GitHub milestone structure. — No change needed in X01. No X01 ticket names the wire-protocol, permission-model or public-API gates. X01-T4 explicitly avoids a public API, and the label and milestone structure is program-owned. The milestone labels first-proof, next and parked are applied per ticket.
X06-D3 (both lenses): the residual decision set (KEL-127 packet, Linear-owner packet, claim arbiter, conformance landing shape, T4 parking) and the P1, P3, R2 and P2 prototype fixes. — Program and prototype items owned by X06 and the PANEL tickets. The one X01-relevant item, 'repoint R1 at KEL-237, which owns that fixture pin', is applied in X01-T3.
changed the title [-]program(conformance): differential oracle harness — pinned Electron recorder, Keld replayer, comparator, canonical bytes, CI lanes, maturity ladder[/-][+]program(conformance): evidence rules and differential oracle harness — one Electron pin per corpus, shared corpus-manifest owner, red-until-implemented cells, pinned Electron recorder, Keld replayer, comparator, lanes[/+]on Oct 6, 2026
Parent map: #391 · Unit: X01
docs/agents/workflow.md§ Tracker issue (rule lands with docs(agents): record the #517 tracker-of-record rule in root AGENTS.md and the workflow claim protocol #520). Linear reference: KEL-237 (In Progress) carries a link to this issue.Scope
X01 owns the evidence machinery that every Electron-compat claim passes through. It works in two layers with different milestones.
unknown; the meaning ofartifact.sha256; the authority-profile label; and one shared corpus-manifest and exact-bytes owner in keld-compat. Every new corpus reuses that owner. The first-proof consumers are the conformance entries (F01-T1, F03-T1, F04-T1), the X02-T5 product cell contract (consumes X01-T3), the X02-T4 product corpus manifest (consumes X01-T3 and X01-T4), and the X02-T6 scoring run, which runs the corpus under the X01-T4 validator. None of these first-proof consumers gates on X01-T1: they need the rules and the helpers, not the two-arm recorder.@keld/electron. A comparator in keld-compat emits one KEL-74 record per cell. INFERENCE (from their ticket text; edges owned by those units): the next-milestone conformance tickets F03-T6 (recorded undocumented behaviour) and F08-T3 (an UNKNOWN destroy-time render-process-gone oracle cell) genuinely need recorded Electron observations, so they stay on X01-T1.The oracle is the pinned doc sentence. A golden transcript is only evidence-of-record (decision X01-A1; it survived both refuters).
FACT: X01 owns no Electron API member. The compat matrix assigns all 2,128 members of the 180 entities in the v44.4.5 API model to F01–F09. X01 records evidence for the cells those families define. It never claims coverage itself.
Corpus demand
electron-apps-v0, panel product: X02-T5 cell contract, X02-T4 manifest, X02-T6 scoring run that flips the cells). Neither needs recorded Electron goldens, because product cells reuse the KEL-237 runner pattern. So no edge from X02-T4, X02-T5 or X02-T6 to X01-T1 or X01-T2 is a real gate; their real X01 edges are X01-T3 (rules) and X01-T4 (helpers and validator).app.exit(call sites are draw.io 3 (export-mode and error paths, not on the four-step workflow) and Zettlr 2. draw.io has no<webview>demand: every hit iswebviewTag: falseor awill-attach-webviewpreventDefault. No recorder cell is motivated by either.Maturity ladder
The ladder rungs are report vocabulary over the four KEL-74 verdicts. They are never a second verdict set. FACT: the evidence parser accepts only
pass|fail|unknown|waived, and records reject unknown fields.unknown, with its oracle id naming the unspecified path. It is neverpass.passper OS lane. An unrun lane staysunknownor carries an explicit ▲.Correction: the published epic called this "the ladder every family uses". That contradicted the family epics, which own L0–L3 maturity targets. X01-T3 records the mapping: a family L2 exit requires CONFORMANCE_PASS cells, and a family L3 exit requires CORPUS_VERIFIED rows.
Tracker of record and Linear owners consumed (Linear and GitHub, fetched 2026-10-07, read-only)
Owner rule consumed as text, not as a blocker: X06-D7 (#517) is CLOSED (closed 2026-10-06T20:32:52Z) with the owner decision recorded by @0monish: align each repo-writing ticket to the nearest live Linear issue whose scope covers it and claim there; otherwise the GitHub issue is the tracker of record (claim, status, handoffs and evidence on GitHub, earliest claim comment wins) and no Linear issue is created; every GitHub ticket is referenced by a link on the nearest live Linear issue for its surface, falling back to KEL-127. The map orchestrator is the single Linear writer for those reference links.
score(). Consumed unchanged, as landed on origin/main 8678c0d. The documented committed-product list is empty.unverified | legacy | strict. Legacy requires an explicit Keld declaration.unverifiedhas no KEL-74 authority value.## Agent claimcomment on the GitHub issue; the orchestrator posts the Linear reference link.Design facts (labelled)
appdoc URL;expected_verdictonly aspass, or asfailwith an intentional divergence.No red-until-implemented state exists.
artifact.sha256has two live meanings. KEL-237 records carry the manifest digest; KEL-77 §4.5 uses the fixture-directory digest.appdoc between Electron commit 07e46071 (44.3.0) and the v44.4.5 tag finds one prose change, in thegetPathsessionData description. The other hunks are example formatting. The lifecycle sentences the three live cells cite are unchanged.@keld/electronexports onlyappplusisCallError/KeldCallError. keld-cli has no--headlessflag or verb. No window registry exists. So the Keld arm has no BrowserWindow, preload or renderer, and the first harness cells must be main-process only."type": "module";type: modulefields";readybefore your code executes".app.whenReady()(electron#51462).CI requiredaggregates PR and push jobs only.Platform lanes
Tracer-bullet tickets (sub-issues)
X01-T1X01-T2X01-T3X01-T4X01-T5Never list (documented ✘)
Out of scope
Not yet specified (fog)
unverifiedstate versus the closed KEL-74 authority vocabulary: reconciliation belongs to the KEL-78 owner (In Progress, GYLDLAB); X01-T3 only refuses to invent a valueDecisions that govern this unit (closed decision tickets)
Change log (doctrine-audit repair, 2026-10-07)
Audit findings not applied (with the evidence-backed reason)