Skip to content

Durable project investigation and challenged development proposals

This extends compositional read cognition. Luna is the interface. Rubick owns reviewed source operations, Oracle owns evidence interpretation, governed continuations preserve explicit investigation state, Legion Commander challenges proposed development, the existing development delegation service owns immutable plans, and Lich owns operator approval.

General evidence reach

app/documentation/inspection.py reads configured repository text without ingestion, indexing, retrieval-count writes, or a second memory store. Its reviewed contract admits Markdown/reStructuredText in docs, Markdown in knowledge and cognition, and Python in app and tests. It rejects hidden/generated paths, nonregular files, symlink components, absolute paths and traversal. The repository root comes from runtime configuration, never model arguments. Corpus reads require the configured canonical operator and matching live Rubick registration.

Discovery returns bounded source openings, hashes, sizes, pagination and first/last Unicode match offsets for up to three query terms, plus a matching Python definition offset when present. Discovery may be restricted to one reviewed tree, such as app for implementation evidence; the filter cannot admit another filesystem root. Range reads return Unicode offsets, complete bounded segments, source SHA-256 and an explicit continuation offset. Redaction precedes slicing, preventing credentials split across ranges from leaking. Changed source hashes refuse continuation. Corpus redaction reuses Spectre with an explicit one-megabyte line budget matching the already validated source bound; terminal/screen defaults remain 4,096 characters. Ordinary long paragraphs therefore survive segmentation, while late credentials are still inspected before slicing. Redacted ranges are flagged in the durable ledger and answer-coverage review because omissions may matter. Search ranks topic words above generic request/navigation wording. Retained findings require current project-read permission before disclosure, independently of Lich's separate approval ownership and authority contracts. Source hashes identify bytes; they do not prove authority, truth or authorship. A redaction flag alone does not establish a material evidence gap. Remaining ranges stay retrievable; synthesis must investigate visible evidence and state limitations without requesting credential values. Design documents retain their own statuses and cannot establish implementation.

The same contract works for any project in the reviewed trees. The Rote corpus is an acceptance specimen, not a route, reader, index, capability or memory type. Its existing DOCX reading derivative is ordinary project text; original binary formats are not silently interpreted by this reader.

Existing reviewed service readers remain available during investigation. No new arbitrary shell, HTTP, filesystem, private connector, external repository, host configuration or unrestricted LifeVault read is exposed. Those sources need reviewed read contracts and principal authorization before this path can use them. Process access and repository links never grant disclosure authority.

Iteration, durability and uncertainty

app/runtime/deep_investigation.py admits at most two reads per reasoning step (discovery and larger metadata contexts use one-read batches to stay within synthesis input bounds), reauthorizing each. A governed model can discover sources, inspect ranges and choose additional reads based on new evidence. Repeated identical selections within one run stop. Whole-document completion requires contiguous hash-bound ranges for every selected documentation source; a model cannot waive missing ranges. Related source and test files may be inspected in relevant ranges. The coverage review can require a complete source file when the question or a material gap needs it. New corpus inquiries start with bounded discovery, including when source-selection inference is unavailable. Search results schedule up to five distinct source versions fairly across requested evidence facets, consumed in the existing one/two-read batches without a separate source-selection model call. Explicit paths prioritize their own evidence role without excluding other requested facets. Discovery snippets alone cannot complete an investigation or become final findings. After range coverage is satisfied, a separate governed inference pass challenges whether the findings answer every part of the original question. Gaps return to reviewed reads; an unavailable review preserves a resumable read and blocks completion. This checks answer coverage only. Local claim assessment runs on each candidate before global completion and cannot be overridden by the coverage model. The reviewer receives the literal supporting passages, observed citations, hashes and ranges. Selection, investigation and coverage review share a model-output schema derived from Rubick's scalar parameter contracts; runtime validation and authorization remain mandatory even when the provider claims schema conformance. Model-facing evidence separates file hashes from observation-envelope digests. Its source bindings merge the entire retained range ledger and expose the first unread offset, so recent-context limits do not erase prior read coverage. Range-selection schemas reference that observed-source table with exact path/hash pairs; it records read coverage, not a second claim-support representation. Exact duplicate ranges share citation bindings on continuation; changed hashes remain separate and redaction qualifications are preserved. Discovery candidates retain only path/hash/size metadata in that ledger. Coverage contexts expose the latest candidate page alongside every inspected source. Continuation compacts obsolete candidate lists while retaining their discovery digests; older unused navigation does not accumulate in provider prompts. Coverage review names required primary sources, and deterministic range checks reject a positive verdict when those sources remain unread. Current-implementation questions additionally require directly inspected application source. These are minimum evidence checks, not proof of semantic correctness. Range-selection schemas enumerate observed path/hash pairs and valid starting offsets; unknown sources require discovery. These constraints improve selection quality without replacing the reader's current-source drift check. Completion is constrained by validated state: requested reads retain an investigating status, and unresolved evidence without a read remains blocked, independently of model completion language; the synthesis schema has no status field. Named function gaps can trigger a local symbol search. When that search exposes a reachable definition, a bounded range read precedes accepting a model's claim that the implementation is inaccessible. Findings are provisional; this recovery does not waive redaction, material uncertainty or current source authorization.

Explicit state lives in the existing governed continuation record: objective, evidence references and hashes, attributed findings, unresolved evidence, next read selections and status. The store checkpoints reads before inference and findings afterward using principal and version guards. It does not retain hidden chain-of-thought. A process interruption may repeat a safe read, never invent a completed interpretation. continue investigation resumes one unambiguous unfinished principal-owned investigation. Stop/cancel contracts stop further reads at the next admission boundary and preserve useful evidence. When several are unfinished, continue investigation: <original question> selects an exact principal-owned objective. Ambiguous matches leave all records unchanged. Explicit exact selection can also reopen a completed investigation for review. Recovery from a blocked answer and explicit review of a completed answer retain provisional findings and their exact citation map, clear stale blockers from the fresh assessment prompt, and require reassessment against selected evidence. Stored findings remain intact until a validated update; recovery does not erase the conclusions needed to reason across previously inspected documents. Up to twelve concise attributed findings can cover distinct question facets. plan from investigation: <original question> requests advisory planning from that same objective and retained evidence, including a completed investigation. It preserves the investigation's provider-authorization lineage and performs current source-scope checks; it does not approve the resulting plan.

Current limits include a one-megabyte source, 4,000 searched files, approximately 20 MB searched source bytes, 6,000 characters per range, 96 evidence entries by default, and the continuation's existing 32,768-byte JSON boundary. The configured LUNA_INVESTIGATION_MAX_ROUNDS defaults to 16 and is clamped to 1–40; admission also honors LUNA_INVESTIGATION_MAX_EVIDENCE, clamped to 1–128 without raising the checkpoint-size bound. The default accommodates the verified 85-entry mixed-source investigation previously admitted under a temporary 96-entry setting, with bounded room for continuation reads. Explicit smaller overrides still stop admission; retained history never automatically raises the cap. These are resource limits, not source or effect grants. Admission also stops after 240 seconds. Budget exhaustion is incomplete work, not a factual conclusion. A stopped/incomplete investigation remains inspectable and resumable.

Inference receives explicit findings and recent evidence rather than private reasoning. Its opt-in local profile requests a 32,768-token context with bounded output. The complete UTF-8 prompt plus framing/output reserve must fit a conservative context bound; it is never silently clipped. Existing callers retain their prior defaults. Configured providers and cost policy remain authoritative. Backend output-budget exhaustion is failure, not a completed answer. The xAI adapter requests medium reasoning for explicitly output-bounded heavy calls to configured grok-4.3, using the provider's supported reasoning control. Other model/tier/default calls retain their previous behavior. The request's existing output ceiling still applies; hidden provider reasoning is not returned or checkpointed. This does not change frontier eligibility or authority. An operator may temporarily authorize frontier synthesis for exact investigation records using LUNA_INVESTIGATION_FRONTIER_REFS (space-separated references) and LUNA_INVESTIGATION_FRONTIER_UNTIL (Unix expiry). The configured canonical operator must own the record. Its immediate independent-review child shares that grant; unrelated requests retain their configured model mode. This is an explicit deployment setting, never a model-written permission or mutation authority. While admitted under this grant, collection remains local and only the reviewed corpus reader contracts are exposed. Selected redacted ranges, compact findings and source metadata reach the configured frontier provider. No service logs, environment files or generic host readers are added. Existing durable Kernel Record inference audits retain model and mode attribution for each request. Remove the temporary deployment override after the authorized investigation. Paid bounded reasoning additionally requires LUNA_INVESTIGATION_FRONTIER_APPROVAL to name an approved, unexpired, operator-owned Lich record for the exact source lineage, configured xAI model and read-only investigation operation. Its declared cost-policy bound supplies the existing Underlord approval metadata; missing, pending or mismatched approval remains blocked. Default cost classes are unchanged. The grant is reread immediately before external dispatch, including after local collection. An invalid grant prevents dispatch independently of provider pricing policy; it cannot fall back to an unapproved frontier request. The existing arbitration bound is eligibility metadata, not a measured billing ledger; token and request bounds still apply. No separate budget store is added. Investigation and independent challenge use the existing heavy bounded-reasoning tier, with a 480-second client deadline covering the configured 420-second heavy backend deadline when the lane is available. Source selection uses a smaller 16,384-token context and 512-token output. Queued contention can still exhaust a deadline and leaves the investigation incomplete; it never grants authority.

Conflicting sources remain attributed. Missing material evidence requires more investigation; legitimately operator-resolvable product choices may be returned as bounded clarification. Unavailable sources or inference fail closed. Citation and coverage validation establish provenance and read coverage, not proof that every inference is correct.

Recommendation, challenge and Gate 1

A completed development inquiry may prepare one relevant bounded slice. Legion Commander independently retrieves evidence and receives only locally established source-bound findings (including established unresolved states). It generates one advisory plan with explicit scope, exclusions, effects, rollback, mandatory/advisory acceptance and source-attributed technical tasks. There is no separate synthesis call to turn a recommendation into an established finding. Ordinary investigation findings retain the fixed 400-character limit.

Commander review_comments are advisory observations, not reconciled established findings. They retain independent source citations for inspection and possible fresh review, with 600 characters each and a 4,800-character aggregate limit. The technical plan separates observed premises, inferred conclusions and recommended tasks. Observed premises must exactly match locally established input findings and their actual source paths; model-written reasoning belongs in inferred conclusions. No part of the plan becomes independent evidence. The investigator never imports the plan or its review comments into retained findings. Accepting an advisory plan does not invalidate or overwrite established findings.

A rejection can request one bounded fresh investigation of independently cited source observations. Only observation references cross that checkpoint; advisory wording remains explicitly labelled review feedback. Local establishment must run again before any new claim becomes knowledge. Investigation next reads and coverage gaps are procedural state, never support. Corpus readers exclude the operational data/planning_artifacts and data/codex_reports trees.

The independent review separately reads the original investigation's selected documents and implementation sources. A summary cannot substitute for an omitted primary source. Planning checks both current investigation records, including cancellation, expiry and changed findings. Before publication it rechecks source hashes supporting the independent plan through the reviewed reader, bound to the repository snapshot. Missing or changed premises cannot be attached to a new current-repository approval. Uncited historical reads remain prior inspection; they do not become premises merely because they were previously read.

Planning uses the canonical bound-excerpt projection over fresh hash-verified reads. Its payload remains capped at 50,000 UTF-8 bytes without truncation, with the existing stricter context/output admission checks. Read-only recommendations cannot publish implementation authority; persisted documentation changes must be declared as mutating tasks. Luna separately reviews proposed premise, ordering, scope and acceptance against exact source quotations. This review returns an advisory rationale; its supported decision endorses a proposal, never establishes a claim. Invented quotations fail closed. A contradicted proposal gets at most one bounded reconsideration. Persistent disagreement or necessary operator choices remain unapproved. The immutable plan retains this review and provider provenance.

The existing DevelopmentDelegationService binds the challenge and acceptance contract into its content-addressed canonical JSON and readable Markdown plan. Repository snapshot, task set, interpretation and lifecycle bindings remain verified. Final proposal publication is serialized per repository. An overlapping pending development Gate 1 or nonterminal governed development job blocks another proposal. Historical objective labels without an execution job do not establish active execution; they remain unchanged. Unknown job states fail closed. This check uses the canonical runtime job store, not the legacy jobs table in session storage. The registered executor's enforced read-only planning lane may continue concurrently. Planning and lifecycle writes are explicit coordination effects, not source or runtime implementation authority.

The resulting Lich request asks whether to implement the exact plan. It has no implicit timeout. Details exposes the complete immutable plan. Questions carry the approval control forward, and the ordinary summary includes declared risks. Questions do not consume it. Short decisions including yes, do it and go ahead resolve only when the authenticated principal has exactly one plausible pending approval. Other approvals retain their existing contracts. Cross-transport identity and high-risk device-verification requirements remain Lich policy; neither model text nor an opaque ID bypasses them.

Immediately before Gate 1 approval, Lich requires the registered development validator, current principal, current immutable plan/reference, exact authority envelope and unchanged repository premise. Failure invalidates the request using Lich's terminal expired state with explicit invalidation attribution. The same check contracts stale approvals before Details, question carry-forward or replacement planning, without waiting for an attempted approval. A fresh plan and approval are required. Ordinary source drift conservatively invalidates pending authority even when it might ultimately prove immaterial.

Gate 1 grants authority; it does not currently release an implementation job automatically. The existing explicit governed implementation dispatcher consumes the exact approved plan. Plans retain mandatory validation/deployed acceptance and the separate Gate 2 commit/push boundary. This extension does not perform commit, push, roadmap adoption, finalization, migration or automatic rollback.

Preserved owners and boundaries

READ_ONLY remains affirmative reviewed read/no-mutation semantics. Unknown effects fail closed. No command/function name determines safety. Diagnostic, mutating, approval, scheduling and execution APIs are absent from the cognition reader map. The opt-in inference budget serves both general investigation and independent development review; the continuation checkpoint extension addresses process-loss correctness without introducing a workflow engine or alternative memory owner.

Canonical roadmap state remains unchanged during investigation and implementation. Findings in active investigations are observations, not adopted priorities or architecture. Automatic Future Consideration reconciliation, standing-authority evolution, anomaly triggers, execution revocation of an already-running external worker, independent Gate 2 acceptance automation and automatic deploy rollback are not newly implemented here. Their existing owners and approval boundaries must be reused in subsequent separately bounded capabilities. No automatic Rote creation, attestation, publication, transfer or activation is introduced.

Validation

Focused suites cover general source retrieval, redaction before ranges, traversal and symlinks, source drift, principal denial/revocation, durable restart and interruption, fabricated citations/effects, inference budgets, independent-plan binding, portable natural decisions, pending Details, overlapping proposals and stale Gate 1 invalidation. Repository-wide validation and actual deployed Rote and non-Rote inquiries remain required acceptance evidence for this change.

A retained claim can be rechecked with verify finding <number> in investigation: <original question>. This selects an existing owned finding, not a new objective or authority grant. Its actual citation ranges seed the existing read loop; unsupported implications and source-section labels must be investigated again. The original objective and principal/provider scope remain bound.

Claim support and optional interpretation

Findings carry a classification (direct, reconciled, inference, or unresolved) and bounded literal supporting passages with source references. The model selects identifiers from a local table of bounded source passages; AncientOS binds their exact text and source references. It does not ask the model to transcribe quotations or choose provenance independently. The table preserves paragraph boundaries where possible. A valid reference alone cannot establish a claim. One bound excerpt carries its source reference, citation (path/hash/read range), exact quote/span and governing context. A deterministic handle derives from that same bound identity, independently of observation aliases. Repeated words in different sections retain their different spans and governing context; ambiguous legacy occurrences fail closed. There is no separate evidence-set owner.

An inquiry can request design/concept, implementation, operational, decision and historical facets together. Deterministic recognition and source roles guide navigation and minimum evidence-kind checks; they do not assign truth or resolve arbitrary natural-language meaning. Each claim still requires its own applicable source status, subject, scope and qualifications. Explicit open operator decisions can complete a decisions facet without resolving the underlying product choice. No findings, missing requested evidence kinds, or invalid context block completion even when the model says coverage is complete.

Unique source character spans, including governing-context spans, cost at most 4,800 characters across the investigation's selected support; new support costs at most 3,600 per step. Overlapping spans and byte-identical source aliases cost once. Independently versioned content retains separate costs; equal wording does not establish independent corroboration. Legacy context without offsets costs conservatively by exact contextual text. Disclosure and continuation byte limits remain separate hard bounds. An excerpt can support several distinct findings; there is no global allocation mutex and no combining claims just to share cost. Derived summaries do not become independent evidence; an explicit derivative without a source parent cannot supply primary facet evidence. Each candidate binds explicitly to one requested facet and is assessed locally. The same excerpt may support several legitimate claims, but it never acquires additional evidential independence through reuse. The canonical finding assessment has five outcomes:

  • established: a complete contextual source proposition supports this facet.
  • established_unresolved: the source establishes an open, deferred or unknown state.
  • contradicted: the support explicitly states the opposite proposition.
  • insufficient: context or locally provable support is missing.
  • invalid: the support relationship, provenance, facet or contextual scope is unsafe.

These are source-relative epistemic results, not permission or implementation readiness. An unresolved product decision can complete a decisions facet. An unresolved evidence relationship cannot. The display preserves that distinction.

The general corpus reader derives bounded structural context from the same redacted, hash-bound source as the range: heading ancestry, explicit document status/authority labels, and paragraph fragments or a following qualification needed to interpret a selected passage. These labels are source assertions, not grants of authority. Heading offsets preserve which section governs each passage; a heading from another section cannot relabel a table. Supplemental context does not count as full-file read coverage. No unrelated surrounding body is attached. Fenced examples retain their limited source role across ranges; example status lines and headings do not become governing document metadata. Oversized, ambiguous or redacted context is marked incomplete rather than silently truncated into apparently sufficient evidence. Legacy bare quotations require a fresh contextual read before establishment.

claim_assessment owns local establishment. claim_context_issues supplies its necessary context checks; quote binding and fresh range revalidation own text identity. The positive proof boundary is deliberately conservative: the claim must preserve a whole bound excerpt (with optional explicit source attribution) and its material qualifications. Whitespace and outer quotation marks may vary; arbitrary paraphrases and inferences remain insufficient. Selecting one sentence from a conditional excerpt is not a proof. A table can be quoted in full and its governing open-decision heading supplies the unresolved status; another section's heading cannot relabel it. Exact whole-proposition polarity opposition is classified as contradicted; more complex unsupported wording stays insufficient. This does not attempt general natural-language entailment or infer execution from source statements. Evidence-kind, historical scope, example-role and decision category checks remain mandatory even for matching quotations.

Local assessment runs after every valid synthesis response and on revalidated retained support, including while further reads keep an investigation open. Synthesis no longer declares global status, and coverage models no longer return claim verdicts or dimension scores. Model coverage can identify omitted topics and request authorized reads only after local checks pass. It cannot convert a locally invalid claim into an established one. An unavailable coverage model can block global completion while already established source findings remain visible. Facet coverage requires an explicit locally established finding for each requested evidence role. Role recognition is conservative, not a general semantic parser; question-specific completeness remains an advisory review with deterministic source-range requirements. Design and implementation statements keep their separate facet bindings rather than competing for one global evidence owner.

The structured request also exposes the finding text limit and a shorter writing target. Provider schema conformance is never assumed: overlong findings are rejected without truncation and identified separately from unknown passage IDs. Rejected output leaves a bounded validator reason/count record in the existing continuation. Resume exposes that feedback for correction without retaining the invalid claims or treating a validation failure as source truth.

Model input shares canonical bound excerpts through deterministic handles, including support retained by earlier findings. Durable findings keep their literal quotations; unmatched support remains explicit. This removes repeated serialization without increasing the input budget or dropping evidence. A selected partial excerpt cannot disprove a retained quotation outside that excerpt; a fresh observation of the full cited range can still withdraw it.

Discovery metadata and duplicate ranges are compacted after each read batch, not only at resume. Source hashes and discovery digests remain retained. Reaching a resource bound is explicitly incomplete; it does not manufacture completeness. When optional interpretation fails, inspected source passages and the bounded continuation remain visible. Semantic conclusions requiring unavailable inference are not fabricated. Approval Details with no pending development plan is answered directly from the principal-scoped Lich query and does not call inference.

The governed inference request now transmits its existing timeout to the gateway. For local inference, queue admission and backend work share that deadline with a small response margin. Queue waiting cannot silently add a minimum minute or thirty-second extension. An expired request cannot dispatch a model, and a bounded heavy request cannot start an implicit fast fallback after failure. Timeouts return an explicit deadline result; optional interpretation still leaves deterministic evidence intact. Model readiness remains the existing inventory's live observation, not the tier's configured name or process health.

Discovery ranking selects sources before definition offsets select a range within those sources. An incidental function match cannot displace a more relevant document. When the registered corpus reader is already selected, local discovery precedes optional model selection. No corpus-specific query rules are used.

Synthesis receives a locally ranked selection of whole passages, at most 3,600 new source and contextual characters per step, plus the existing bounded support. Facet eligibility and question-term specificity rank new passages; retained disagreement and support are not evicted by that ranking. The prompt declares available, selected and omitted counts. Unselected content is not claim support and remains reachable through authorized ranges. Full read coverage is still recorded independently; it never proves that a selected passage entails a conclusion. This reduces unnecessary semantic input without raising context/output limits.

Sanitization preserves segment-ending newlines, so reassembly cannot concatenate words across source boundaries. A fresh range also rejects a retained passage that no longer matches that exact text. Explicit reviewed paths in a discovery query outrank incidental vocabulary; those matches constrain the initial batch without turning other search results into mandatory reads. Commander disagreement preserves prior support, marks conclusions unresolved and returns to source verification instead of declaring revised claims complete.

Source-context encoding

Provider requests use one shared project_evidence projection for investigation, coverage, Commander challenge and reconciliation. It replaces the separate flat excerpt and inspected-source payloads. Sources use their existing path@hash identity. Their original read-coverage metadata and identical contextual fields are encoded once. Each existing excerpt handle retains its quote, observation reference, exact span, observed read range and any differing context fields. Shared context applies only to the listed excerpts, not unread source contents. Overlay excerpt context on source context to recover the complete bound context; the source key and read range recover the original citation. No context field is truncated or interpreted by this projection. Different headings, status, qualifiers, completeness and provenance remain distinct whenever they differ.

Findings refer to the same excerpt handles and carry no duplicate source text. The old project_findings helper and flat provider tables are removed. No new source ID, context ID, selector, persistent evidence store or budget is added. The existing full bound objects remain the authority for local establishment and durable fresh-read revalidation; provider output cannot replace those objects. The projection is a transport encoding, not a second evidence authority or a compatibility acceptance path. Test-only reconstruction checks every bound field and unique-support cost against the originals.

Unique support cost and serialized byte admission remain independent safeguards. Normalization removes repeated encoding cost without changing what is selected, what source ranges were read, or what a claim can establish. The investigation's 26,000-byte packet limit and other consumer limits remain unchanged. Advisory recommendations use the separate advisory planning contract; the encoding change does not promote proposed actions into established factual findings.