grid_assets library

The_grid's opinion assets — the agent/verify/land Capability impls + the code Circuit + the git SourceControl (ADR-0008 D2 / M4-P1 §6).

These are the OPINIONS the opinion-free engine (grid_engine) must not carry (ADR-0007 §1): the coding agent it spawns (claude), the check it runs, the PR it opens. A station runner wires them via buildCodeRegistry + a CircuitResolver (RS-8 retired the transitional CodeRunCommand — the resident composition is the only consumer now). The power_station home of the first-party assets (extracted from the_grid at the repo split).

The v3 COMPOSITION ASSETS (Track F, tg-5r9, composition_assets.dart) are how those opinions mount into the grid tree at a SCOPE — the replacement for the runner-built ServiceBundle map: GitGridAssets plus a domain delivery asset (substation-scoped source control, over the ambient GitServices machinery carrier the delegate mounts once), HarnessProvider (station-scoped harness provision), CircuitProvider (the Q8 circuit provider/scope), and sourceControlOf (bead → substation → root resolution, no string-keyed map).

The AGENT SCOPE's model resolution is TIER → MODEL (beads pow-2c9, pow-n6n.4): a spawner declares the AgentTier it rides (frontier for the build and the spec author, mid for the critics, cheap for the read-only lenses) and the STATION arms tier → model (AgentConfig.tiers, a ModelTiers value — an unarmed tier rides defaultModelForTier: kFrontierModelDefault opus, kMidModelDefault sonnet, kCheapModelDefault haiku). resolveAgentConfig resolves bead grid.agent params.model > the selected environment's own model > the station's arming of the declared tier, stamping the winner into the harness transport key. So the committee grades cheap while the build runs strong, and a retune is one arming change. WHICH environment a seat rides is the TYPED lookup (ADR-0006 D2) — D5 retired the role indirection. The resolved model is ALWAYS explicit — never the harness CLI's own default (which silently fell back to fable when a weekly limit blew) — and UsageReport.model captures the id(s) that ACTUALLY ran, so grid.result.<node>.model proves it from the ledger (subsuming bead pow-efv).

The COMPUTE asset domain (ADR-0011 D2/D3, M6 Track D) also lives here: the DispatchCommand/CommandResult payloads + the bounded "use" + the capacity predicate moved OUT of the kind-agnostic grid_federation core, and the LeaseCapability wraps a federation lease as an engine Capability (mount = acquire + dispatch, unmount = release).

The SEARCH domain (bead pow-ovh, the first coupled skill+command pair) also lives here: deterministic, READ-ONLY (A37) cross-store search over the station's attached substations. mountedRosterOf resolves the roster from the resident-station context (the composing station's GridDelegate tree, mounted offline), while codedRosterOf owns and disposes a fresh delegate around that enumeration; StationSearchService queries each seat's .beads/ store (backlog + decision beads) through a read-only-by-construction seam; SearchCommand is the THIN exported CLI adapter a station composes (space search <query>) — the substrate agentic skills (discover) CALL instead of reinventing search by inference. Semantic vectors live in the grid-home-owned, derived DoltEmbeddingIndex at .grid/embeddings; DoltEmbeddingIndex.open provisions its VECTOR(N) width from EmbeddingIndexIdentity, rejects a provider/model/dimension mismatch before use, and is the sole storage API shared by the indexing and semantic-read paths. It never writes a substation work store or the resident tranquility store. IndexCommand is the only embedding writer: it calls EmbeddingClient before writing the grid-home-owned DoltEmbeddingIndex. SearchCommand remains inference-free and write-free.

The FILING pair is the front-door completeness counterpart: FilingService reads one bead through ExactSubstationBeadSource, gathers its FilingEvidence, and FilingContract deterministically evaluates the eleven mechanical authoring requirements over both; FilingCommand is the thin CLI adapter the discover skill calls. Description and acceptance usefulness remain with the agentic half.

Four of the eleven rows are PRESENCE and six are VIABILITY: can the validation_plan be PARSED by the gating lane's shell and by CI's dash, are the bead's file anchors repository-relative, does every bead id it cites EXIST in the current or an attached store, is its acceptance free of pinned release versions, and is every decision it cites already RECORDED. The pure scanners those rows run are in filing_text.dart — one copy, shared with discovery's own anchor and citation gather. The eleventh is CONTENT: no_corrupting_text refuses a NUL byte — and only a NUL byte — in the bead's own body text, because it truncates the write while bd reports success. A backtick is legitimate bead text and passes. The row reads no evidence — the text is the whole question.

The viability rows are judged against FilingEvidence, which every leg reports in three states rather than two: answered, answered-negative, and NOT ANSWERED. An unavailable leg is never read as an empty one, so "no store holds this id" and "nobody asked a store" stay different facts and only the first refuses a bead. FilingCommand and ApproveCommand bind the live gather by default (SystemFilingEvidenceSource over SystemValidationPlanProbe, BdListAllStatusBeadSource and the station's roster decision index); a test or an alternate station overrides it with a FilingEvidenceSource or a whole FilingService. The two checks that deliberately stay AGENT JUDGEMENT — whether the plan finishes inside the critic lane's cap, and whether it covers every affected consumer — are not decidable from bead text and are not requirements. The dependencies requirement is a DependencyProjection of the dependency rows bd holds for the bead — local targets and external:<project>:<capability> targets alike — and NOTHING in this package reads bead prose for blockers: a Blocked by sentence is prose (Nico, 2026-09-13, under the_grid#the-grid-is-a-beads-controller). Each external row resolves through the station roster both filing verbs take by the SAME injected seam (noArmedSubstations is the fail-closed default), so filing and approve cannot answer the same contract two ways; a project the roster does not arm — or a roster that was never supplied — refuses the row and NAMES the remedy.

filing, approve and unpark take NO --state-root. The option existed for ONE reader — the grid home's cross-store link beads — and that read is gone (the_grid#447) with bd's own external: rows replacing it in the store these verbs already read. park, show and mount keep the seam (addStateRootOption / resolveStateRoot), which takes the GRID HOME and appends its .grid state store, because they genuinely reach the session-lifecycle beads there.

MountCommand is the filing verb's counterpart on the OTHER question, and it is an EXPLAINER rather than an actuator: filing answers "is this bead APPROVABLE", mount answers "why will this bead not MOUNT", and the answer used to live in human memory as memorised dances (a hand-closed session leaves a bare work_bead key and the bead never re-mounts; the mount-attempt cap has no reset verb at all). MountExplanationContract turns them into ten ordered rows, each PASS / BLOCKED / UNCHECKED with its own evidence and — when it does not pass — the remedy, which the verb NAMES and never performs: several are destructive and belong to the governor. It COMPOSES the filing report whole rather than restating it, its dependencies row reuses the very DependencyProjection filing rendered (refined only with each local target's open/closed state), and its field clauses are the one mountEligibilityFindings predicate the engine's mount boundary already calls. Being OFFLINE is the point: it is the third consumer of the state-root seam because it reads SESSION-LIFECYCLE beads, and everything that lives only in a running station's memory — capacity, reservations, latches, process liveness, the engine-only mint and successor-retry counters — is reported UNCHECKED with a pointer to the resident status verb, never as a pass.

The PARK PAIR rides that same seam, one rung further in: it is the operator's sanctioned exit for a session the engine's own writers can no longer reach. ParkCommand absorbs the five-step hand ritual — note, unstamp, defer, close, void-retire — across the two stores A37 separates, and UnparkCommand undoes it by clearing the defer DATE through bd undefer and then CALLING ApproveService for the re-stamp rather than re-expressing the preflight. ShowService and ShowCommand sit beside them as the explicit ONE-BEAD READ: no verb anywhere printed a single bead's prose, because bead board/bead round are serviced by the RESIDENT and refuse when it is down — so reading a bead meant knowing which seat mints its prefix and shelling bd from that root. show reads it through the SAME ExactSubstationBeadSource.readExact the filing preflight uses (ONE exact-id bd query on bd's RECORD surface, which carries the bead and its dependency rows together, no mutation surface) and renders id, prose, the grid.approved_* stamp and the dependency edges with NO station in the path. Its output is BOUNDED at kBoundedOutputCapBytes on both the plain and the JSON rendering, and what it cuts it NAMES with the withheld byte count (power_station#a-mechanical-lookup-is-a-vended-command-with-a-bounded-output); --if-revision suppresses the prose only against the bead's own updated_at revision, never against the text of the request. Round, lane and grade data stay with bead round, which owns them. ParkService is guarded on both sides: it ADMITS only on a durable park marker (an open gate bead blocking the session, or grid.session.pause_state=paused — ParkMarker), never on worktree staleness, which is collected as WorktreeActivity corroboration and reported in every receipt and refusal; and it REFUSES on a still-LIVE process fence, probed for MEMBERS (not a leader bool) through the ProcessGroupController seam, so a dead leader over live descendants reads live (FenceLiveness). --override-live waives only that second guard and prints what it waived. The retired join key is never composed here — the session update writes exactly what voidRetireMetadata returns, so a park receipt is indistinguishable in SHAPE from the engine's own void retire. A composing station adds both beside filing and approve.

The SEAT command set makes an operator seat OCCUPIABLE with its own disc (bead pow-lv6t): PrimeCommand is the grid's own SessionStart hook target. It answers for the STATION and POINTS rather than restates (memento-engineering#a-station-explains-itself-through-prime-and-bounded-help): the station's identity and invocation, every verb it exposes BY NAME with that verb's own help beside it — DERIVED from the composed CommandRunner, never a list authored here that would drift the moment a station adds a verb — then where ratified decisions live and which verb searches them, the seat's disc, and the fenced service tick that wakes a seat. The issue tracker's bd prime reference follows VERBATIM under its own heading: still reachable, no longer the whole answer. Handoff injection is ONE note, only on startup, clear and compact, and WHICH note is the launcher's call: the body it consumed for this occupancy, declared in kConsumedHandoffEnvironmentVariable, or — failing that — whatever survived on the disc, which is the hand-started session and the only one still owed the succession verb, named with one seatHandoffAgeDiagnostic line. The whole answer rides the pack's ONE output bound, boundedOutput at kBoundedOutputCapBytes — the same selector the show verb consumes, because a second implementation of a cap is the defect power_station#a-mechanical-lookup-is-a-vended-command-with-a-bounded-output exists to stop one layer down; prime supplies only its own trim order (tracker body, then handoff body, then whole verb-pointer records) and every cut NAMES the bytes withheld and how to ask for them. SeatCommand is the OUTER harness that launches a seat's occupant with its role definition and disc and relaunches it on handoff. SuccessionCommand owns BOTH mechanical edges of the handoff's lifetime. It CONSUMES one through SeatSuccessionService, which archives the seat disc in a path-scoped commit and proves the note is in HEAD before deleting it and its one MEMORY.md pointer line (--no-destructive stops after the proof). The destruction the disc doctrine licenses on "the disc is tracked, so git history is the archive" now has something ENFORCING the tracked half. And --write-handoff <file> WRITES one, from a complete note on stdin, through SeatDisc.writeHandoffOnce — which refuses a second live handoff rather than amending the first, because a handoff is working memory "written once at a boundary, picked up, and deleted" (memento-engineering#handoffs-are-working-memory-and-long-term-memory-stays-thin). Consuming one was already enforced while writing one was only prose, which is how a single governor note came to be rewritten across thirty commits over nine hours; with amendment refused, an unconsumed note is simply a seat that has not handed off, and seatHandoffAgeDiagnostic is the threshold-free line every seat reader renders to make that visible. All three are harness-neutral: every vendor token is an AgentEnvironment declaration (AgentEnvironment.roleArgs, AgentEnvironment.memoryDirArgs, AgentEnvironment.primeMode, AgentEnvironment.drivenArgs, AgentEnvironment.roleAsset). A composing station adds them beside filing and approve; that one-line composition is space_station's own bead, the way power_station#a11-bead-pow-ovh-the-search-domain-roster-resolution-is-an-o landed search.

The VENDED SKILLS (bead pow-88p, extension/station_overlay/skills/) are those agentic halves: discover is the grid home's HITL front door — it dispatches on arg shape (topic research / bead advisory / bead directed), researches via the vended search Command, and on the human's yes files an ephemeral staged bead and hands to specify. vendedSkillIds enumerates them; PackagedAssetLoader.renderSkill renders one by id.

The DELIVERY leg is ONE RESOLUTION and two writers (bead pow-4peu, power_station#one-asset-resolution-defines-tree-and-writers). resolveGridAssets evaluates the station-generated GridAssetRegistry's declared selectors against an immutable SubstationFactsSnapshot — observed OUTSIDE build by a SubstationFactsRepository and projected into the tree by SubstationFactsAssets, aspect-scoped per SubstationKey — and returns the SELECTED generated definitions plus each one's exact source and target path. Registry membership is potential availability; a definition MOUNTED in a substation's assets is actual availability, and it is the same value. OverlayMaterializer then writes exactly that set: this package's OWN provision-time wire (AgentCapability, onto a per-bead WORKTREE root, so a station-spawned agent can /invoke a vended skill; SCOPED to kWorktreeOverlaySubtrees — the per-harness SKILL trees .claude/skills and .agents/skills — because a loose .claude/settings.json is repo-owned territory) and the operator install Command (onto a STATION repo root, unscoped). It renders each file, REFUSES to install one whose holes are unbound, NEVER clobbers a file it did not generate, and never deletes a generated file the resolution stopped selecting (OverlayFileStale).

The OPERATOR leg of that delivery is AssetsCommand over src/assets/overlay_install.dart: <cli> assets install observes the grid home's facts once, resolves the station registry against them, writes the selected artifacts (OverlayInstallService) and prints the DIFF (renderInstallReport). No runtime package-extension walk decides scope any more — the generated registry does. It COMMITS NOTHING — the operator reviews and commits. Each installed file carries a PROVENANCE stamp (overlay_provenance.dart) naming the grid_assets ref it came from, which is what lets the vended assets be COMMITTED rather than gitignored: the stamp tells a generated file from a hand-authored one, and assets install --check classifies every path IN SYNC, DRIFTED, HAND-EDITED, MISSING or STALE, writing nothing. mountedValuesOf is the one offline delegate-mount walker both this leg (for the grid home) and mountedRosterOf (for the substation roster) ride.

The SPEC-READINESS INTAKE LENS (bead pow-q7n, src/code/readiness.dart) heads that spec circuit: a deterministic intake contract (IntakeCapability — a driveable type + a real brief, ZERO agents) then ONE cheap agent grading the BEAD (ReadinessCriticCapability, the bead-readiness rubric) and a decision point (ReadinessRouteCapability). A bead that is not spec-ready is HELD for refinement BEFORE specify spawns, so a coarse brief never burns the architect + the 4-critic committee — the ~18-agent round the 2026-07-11 wide run spent discovering that at the committee.

The DISCOVERY circuit (src/code/discovery.dart) is the spec circuit's second head, nested between that ladder and specify — a gather AND a gate. The gather is deterministic (AnchorsCapability, ZERO agents): the committee's own grading rubrics, the bead's code anchors resolved against the worktree, and prior art through the read-only StationSearchService the search Command already vends. Three READ-ONLY explorers (DiscoveryLensCapability) then run in parallel on the CHEAP tier and, because a lens DECIDES NOTHING, a lens emits no letter: it emits a LensReport of context notes and CITED violations. DiscoveryRouteCapability makes the call, deterministically (decideDiscovery): a bead that contradicts a ratified ADR or an applicable skill WITHOUT acknowledging the departure is HELD with the offence CITED, so no architect and no committee ever runs on it; a clean bead ADVANCES with a curated DiscoveryDossier that buildSpecifyBrief renders — the architect specs against the rubrics it will be graded by. The gate is CITE-THE-OFFENCE by construction (gatesTheBead): no citation is a vibe and can never hold a bead, a DECLARED departure passes, and a pattern deviation needs a NAMED precedent.

The DART domain (the typed grid.dart envelope + pub dev-time linkage + DartCommand) lives in its sibling pack dart_grid_assets.

Classes

AcceptanceCriterion
One - [ ] AC-<n> — <criterion> record.
AcpBridgeSpec
Serializable description of one ACP-compatible agent child.
AcpSessionAdapter
Launches the package-resolved ACP bridge and normalizes its event stream.
AgentAuthorizationAdapter
The OPTIONAL authorization half of an AgentSessionAdapter.
AgentBrief
The harness-agnostic WORK CONTENT handed to an agent (OQ-a, ratified): the rendered task, the working agreement (grid policy — commit, don't push), and optional labeled extra-context blocks. Model/parameters are AgentConfig, NOT brief — so one brief replays across harnesses (supervision may retry the same work on a different harness without re-rendering policy). TRANSPORT is harness-owned (argv / stdin / workspace file).
AgentCapability
The IMPLEMENT capability — spawn the coding agent in the bead's workspace, parameterized over the AMBIENT agent scope (ADR-0008 Decision 10): it reads the work Bead, the Workspace, the station's AgentConfig default, and the AgentHarnessRegistry with the effect verb, resolves the effective config through the ladder (resolveAgentConfig — step params > bead grid.agent envelope > ambient; fail-closed → a per-work Failed), and delegates the INVOCATION to the resolved harness.
AgentConfig
The agent configuration — a pure VALUE the tree carries (never behavior). Watched by branches (dependOn*), snapshot-read by effects (get*).
AgentConfigOverride
A partial, per-bead override of the ambient AgentConfig — every field optional; merged over the ambient value in ladder order.
AgentEnvironment
One inheritance LAYER of a named inference environment (ADR-0002 D1). A pure VALUE (config = VALUES in the tree — ADR-0000 A8); it carries no behavior and reaches no service. Nullable scalars mean "this layer does not declare it — INHERIT"; resolve folds a chain of layers into one flattened environment.
AgentPermissionDecision
The station's answer to one AgentPermissionRequest — the durable authorization record.
AgentPermissionPolicy
The station's authorization configuration for agent channels — a VALUE.
AgentPermissionRequest
One harness permission ask, normalized off the wire.
AgentProtocolEvent
One harness-owned protocol event decoded into the grid-side vocabulary.
AgentSession
Grid-side session joining one adapter, supervised child, and steer stream.
AgentSessionAdapter
Per-harness launch, encoding, and decoding behavior.
AgentSessionAdapterRegistry
Immutable adapter implementations injected at station composition.
AgentSteerSource
Read-only source of bead-routed commands for one work bead.
AnchorsCapability
TIER 1 of the discovery circuit — the DETERMINISTIC gather (ZERO agents).
ApprovalOutcome
The outcome of one approve run — a sealed union so every consumer faces both arms.
ApprovalRefused
The verb WROTE NOTHING and says why.
ApprovalStamp
The RECEIPT the approve verb writes — and the ONLY approval marker the mount gate reads: WHO approved, WHEN, and against WHICH revision of the bead's filing basis. The grid.approved label it used to sit beside is retired; a label any writer can add was the same act written twice.
ApprovalStamped
The verb WROTE the grid.approved_* stamp in one bd update.
ApproveCommand
approve --actor <name> [--json] <bead-id> — the approval VERB: the filing preflight, then the grid.approved_* stamp.
ApproveService
UI-drivable approval: the eleven-row filing preflight, then ONE stamped bd update. Nothing is written unless every row passes.
ArtifactFencedSession
Re-applies a capability's DECLARED CompletionContract.artifactDurability on the CHANNEL path, and contributes that capability's result() fields (bead pow-39tl).
AssetsCommand
assets — the vended-AI-ASSET domain umbrella (the subcommands carry the verbs).
AssetsInstallCommand
assets install — write every asset the station's registry SELECTS for this grid home onto a repo ROOT, stamping each file with the grid_assets source ref it was generated from. Shows a diff, commits NOTHING, never clobbers a file it did not generate, and never deletes a stale one.
AvailabilityAssets
The probing seed: mounts AvailableEnvironments over the ambient EnvironmentRegistry, re-probing on a bounded interval and whenever the registry or the ambient SiteBinding changes.
AvailableEnvironments
The environments PRESENT right now - availability as PRESENCE (ADR-0006 D3), never a probe cache: an environment is available if and only if it is IN this set, by value equality.
BdExportBeadSource
The default SubstationBeadSource: ONE bd query spawn per store, covering every status. A pure read: no last-touched write, no watcher self-trigger, no mutation (A37).
BdListAllStatusBeadSource
The default SubstationBeadSource for an id CATALOG: one scoped bd list -t <type> --status all --json --limit 0 per stable IssueType.coreTypes value.
BeadFieldCitation
A machine-checkable quotation from one bead field.
BeadFieldEvidence
ONE bead field — the work bead's own prose, resolved ONCE by the deterministic gather so no lens re-reads the bead through a tool. Carried WHOLE, however long (boundedBeadFields).
BeadRoutedAgentSteerSource
Projects fenced commands from the existing live bead event surface.
BeadTextSlice
ONE exact substring a scanner found, and WHERE it found it.
BoundedCommandExecutor
Enforces ComputeBounds over an injectable ComputeSpawn: refuses any out-of-bounds command (empty, or not on the allow-list) with a ComputeBoundsException BEFORE spawning anything, then runs the in-bounds command under the bounds' timeout. The explicit-argv DispatchCommand (no shell) is what makes "no string interpolation" structural.
BoundedEvidence
ONE piece of gathered evidence, BOUNDED: a stable identity, where it came from, the clipped snippet, the digest of the COMPLETE text, and how complete the record is.
BoundedShellRunner
A ShellRunner that can BOUND a run — the extension point the code-validation lane's own deadline (power_station#code-validation-enforces-its-own-deadline-as-a-service-capability) rides.
BoundedTextBudget
A UTF-8 BYTE ceiling with an omission reserve — the one arithmetic every bounded model input in this pack does, in one place.
BuildAgentEnvironment
The BUILD seat - the coding agent (AgentCapability).
CarriedSpec
The exact complete specification authored by one specify-step execution.
ChangedFile
One changed file — git diff --name-status -z joined with --numstat -z.
ChangeShapeCircuitResolver
The bead → root-circuit policy that picks the REVIEW COMMITTEE by the bead's declared change shape — the production replacement for CodeCircuitResolver(kCodeCircuit).
CircuitProvider
CircuitProvider — the circuit provider / circuit scope shape (Q8, v3 §3): an asset that mounts a Circuit into a substation's scope, making it available for that substation's work (the resolver seam, ASSET-SHAPED).
ClearCritiqueCapability
Wipes _critiqueDir at the START of every committee round — a ServiceCapability all four critic lanes dependsOn, so it always completes before any lane can read OR write a verdict (gate-integrity #3). A rework round reuses the SAME workspace directory, so a prior round's verdict/rc file otherwise survives on disk; clearing first turns a critic's missing write back into a recognizable miss instead of a stale grade impersonating a fresh one.
CodeCircuitResolver
The migration-aware bead→circuit resolver for the code circuit — the production replacement for CircuitResolver((_) => kCodeCircuit).
CodeRouteCapability
The route/aggregate step — a ServiceCapability that joins its sibling critics' grades and applies the deterministic matrix (C3, asset policy).
CodeValidationCapability
The DETERMINISTIC code-validation lane — the bead's own Validation Plan, run on the BRANCH and at its MERGE-BASE, gating only on the difference.
CommandResult
The result of running a DispatchCommand on a leased compute slot.
CommitLintReport
The branch's commit-policy report (directive item 5: the policy applies to the COMMITS, not only the PR) — how many of the bead branch's own commits carry a compliant conventional subject, how many carry the bead trailer, and up to kMaxLintExamples off-policy examples. Rendered as receipt provenance; never a gate (a lint that blocks a land at the very end would park a DONE, approved bead over prose).
CommitteeClassifierAttempt
ONE classifier call, recorded — including the ones that produced nothing.
CommitteeClassifierResult
ONE classifier call's outcome. Three of the four kinds are NON-RESULTS.
CommitteeLaneReceipt
ONE full-committee lane, observed — trajectory's LaneReport and UsageSample carried directly, EXTENDED by composition with the per-sample columns the trajectory aggregate intentionally does not keep.
CommitteeLaneResultKeys
The result keys ONE committee lane records — the columns a shadow receipt reads back off the ambient SiblingView.
CommitteeRouteObservation
The AUTHORITATIVE route's ruling, observed. A shadow receipt records it; it never produces one.
CommitteeSelection
ONE stage's hypothetical committee — what the shadow WOULD have run.
CommitteeSelectionCapability
The SHADOW selector — one ServiceCapability per review circuit, mounted BESIDE the full committee and depended on by nothing.
CommitteeSelectionEvidence
The NORMALIZED facts a stage's rules and lane digests are computed over.
CommitteeSelectionEvidenceSource
The pluggable source of one stage's CommitteeSelectionEvidence.
CommitteeSelectionPolicy
The pure policy: the rules, the digests and the composition of a CommitteeSelection. Immutable, const-constructible and cache-free — it is a VALUE the tree carries, re-read on every build (ADR-0008 D-H).
CommitteeSelectionRun
ONE selector invocation's whole durable state — the selection, the evidence it was computed over, and every classifier attempt (including the ones that produced nothing).
CommitteeSelectionStore
The shadow artifacts' durable seam (Fakes, not mocks — the offline suite always injects).
CommitteeShadowReceipt
ONE round's whole SHADOW observation — what the full committee actually did, beside what the selector WOULD have run, with the counterfactual spend.
CommitteeShadowRouteCapability
The AUTHORITATIVE route, wrapped in shadow bookkeeping.
CommitteeUsageAccounting
One accounting BLOCK — trajectory's per-run UsageSamples carried whole, EXTENDED with the aggregate totals neither UsageSample (per-run cost and duration only) nor LaneReport (per-lane means and counts only) keeps.
ComputeBounds
The declared bounds on the compute "use" (ADR-0011 D3 / Hazards): the set of executables a lessor will run, and the per-command timeout. Immutable.
ComputeLeaseCapability
Leases a compute slot from a peer (client) and dispatches a bounded command there, holding the lease for the node's lifetime.
ComputeProcess
A spawned, REAPABLE compute process — the timeout-reap seam. The real impl (realComputeSpawn) wraps Process.start; tests inject a fake whose exitCode never completes (a hang) so the reap path runs offline.
ContextNote
One context NOTE — what an explorer FOUND (never a judgement).
ConventionalSubject
A conventional-commit SUBJECT as PARTS — the shape the asset always composes from (never a free-form string), so what it emits is compliant BY CONSTRUCTION rather than by hope.
CorrelatingLaneEnvironmentHealth
The correlating implementation: two failed targeted diagnoses for one lane inside kLaneFailureCorrelationWindow park it.
CriticAgentEnvironment
The CRITIC seat - CriticCapability, SpecCriticCapability and ReadinessCriticCapability. ONE class over many rubrics, so ONE mounted value routes them: entries is the shared preference and lanes overrides it per rubric (ADR-0006 D4), so a station can send decision-alignment somewhere else without a second provider.
CriticCapability
One critic, in isolation — a ProcessCapability whose params['rubric'] selects the lane (C2). Two flavors behind the single critic capability id:
CriticEnvironmentSeed
Provides a CriticAgentEnvironment whose BUILD-time dependents may scope themselves to one CriticLane (genesis-8zb; genesis_tree 0.3.0's InheritedModelSeed). A dependent that passes aspect: CriticLane(...) is invalidated only when THAT lane's effective preference changed; one that passes none keeps the whole-value dependency.
CriticLane
One critic LANE: the rubric id a critic already carries (args.params['rubric'] - coherence, decision-alignment, bead-readiness), as a VALUE so it can serve as an InheritedModelSeed aspect.
CriticSeatProvider
The CRITIC seat's provider seed - SeatProvider's counterpart for the one seat whose value is aspect-scoped, so provider() hands its consumer's Nest a link that mounts a CriticEnvironmentSeed rather than a plain InheritedSeed.
DecisionCitation
One ## ADR Alignment record.
DecisionEntryEvidence
ONE recorded decision entry, resolved from the roster-mode index and read off disk — the canonical <repo>#<slug> identity plus its bounded body.
DecisionGatherEvidence
The round's WHOLE decision gather: every entry body ONCE, plus one lookup record per roster-qualified surface holding ordered REFERENCES into it.
DecisionReference
ONE decision the bead cites EXPLICITLY, with the identity it resolves to.
DecisionReferenceCodec
The WIRE form of a decision reference: a body id's ordinal in the gather's index, written as a decimal string.
DecisionSurfaceEvidence
ONE roster-qualified surface's decision lookup — the exact command that ran, how it went, and REFERENCES to the entries it returned.
DeclaredTestsCapability
Mechanical, no-agent verification of Design-declared test-file presence.
DeliverRouteCapability
The ROOT code circuit's TERMINAL ROUTE — the node whose Advance the engine answers by actuating the substation's bound DeliveryMethod (isDeliveryTerminal). It decides NOTHING about the work's quality (the committee already did): it composes what delivery needs and advances.
DependencyProjection
The dependencies requirement's whole content: the PROJECTION of the dependency rows bd holds for one bead.
DerivedServiceBundleSeed
Provides a derived service bundle and notifies only when a derivation input changes.
DescribeManifest
The FACTS one manifest renders — read by the land step at its run edge and threaded in as VALUES (the renderer stays pure).
DescribeOutcome
What the describe pass produced — the inferred description (null ⇒ the deterministic fallback), the branch's commits policy report, which channel produced the title (source: inference | fallback), and the call's usage.
DescribeReceipt
ONE observer-written circuit receipt the manifest cites, with the node path it was READ from — its PROVENANCE. The route that already reads the ambient SiblingView supplies these; the manifest never guesses a node path, and a receipt the session does not carry is simply absent.
DesignAdjudication
One adjudicated finding — the verifier's answer to one judge claim.
DesignFinding
One finding a judge lane raised — the parsed form of one rationale line.
DesignVerificationReport
The verifier's whole answer: the revised documents plus one adjudication per judge finding.
DesignVerifyCapability
The VERIFY step — the design committee's one new capability, and the reason a design round is a station circuit rather than a hand-rolled workflow.
DiscoveryAdvance
CLEAN — advance into specify with dossier as the architect's context.
DiscoveryAnchors
The DETERMINISTIC gather's whole output (zero agents, zero judgement) — the round's CANONICAL EVIDENCE PROFILE.
DiscoveryCommitteeSelectionEvidenceSource
Reads one stage's evidence out of the live worktree.
DiscoveryDossier
The CURATED context the route hands to the architect — the deterministic gather PLUS what the explorers found, minus what gated.
DiscoveryEvidenceHold
A lens STATED that its canonical evidence is incomplete, and the re-gather bound is spent — a KNOWN NON-ANSWER, held for a human.
DiscoveryEvidenceProjection
ONE lens's bounded slice of the canonical evidence profile — everything that lens is allowed to see, and NOTHING else.
DiscoveryFinding
One CITED finding — the only thing that can hold a bead.
DiscoveryHold
OFFENDER — hold the bead with the CITED offence. Never a vibe.
DiscoveryLensCapability
ONE read-only explorer — the discovery circuit's agent lane, on the CHEAP tier (AgentTier.cheap ⇒ kCheapModelDefault, haiku).
DiscoveryLensOutcome
ONE lens's OUTCOME — the artifact a read-only explorer writes, and the ONLY thing it writes. Sealed: consumed with an exhaustive switch, so a lane that states its evidence was incomplete can never be read as a clean report.
DiscoveryLensPromptAssembly
ONE assembled lens prompt, and whether its evidence bundle was CLIPPED to fit the lane's byte cap.
DiscoveryRegather
A lens produced NO parseable report — re-run it VIRGIN (once).
DiscoveryRegatherLedger
The REGATHER round LEDGER — just the round number, written into the bead's worktree by DiscoveryRouteCapability on a DiscoveryRegather and read back on the NEXT round to apply the kMaxRegatherRounds bound. Unlike the respec ledger it carries NO guidance: a re-gather re-runs the gather VIRGIN, so there is nothing to correct.
DiscoveryRouteCapability
The DISCOVERY decision point (ZERO agents) — the circuit's terminal.
DiscoveryVerdict
The discovery route's verdict. Sealed: consumed with an exhaustive switch.
DispatchCommand
A generic command to run on a leased compute slot — the COMPUTE domain's dispatch payload, serialized into the kind-agnostic bus envelope.
DocsCheckCapability
One deterministic docs lane, selected by params['rubric'] — the same one-capability-many-lanes shape CriticCapability uses, and the same runner-not-agent posture as code-validation / spec-validation (ADR-0000 A13(2)): it ALWAYS completes, with the grade in its Ok payload, leaving the route as the single decision point.
DoltCommandResult
Result of one Dolt CLI invocation.
DoltCommandRunner
Injectable process seam for Dolt CLI invocations.
DoltEmbeddingIndex
Grid-home-owned, derived Dolt index shared by indexing and search.
DoltSemanticSearchBackend
EmbeddingClient
The single client that renders every declared embedding provider value.
EmbeddingHttpRequest
Transport-neutral request passed to the injectable HTTP function seam.
EmbeddingHttpResponse
Minimal HTTP response consumed by the embedding client.
EmbeddingIndexedBead
One indexed bead and the semantic-input key that produced its chunks.
EmbeddingIndexHit
One nearest-neighbour row with the distance computed by Dolt.
EmbeddingIndexIdentity
The immutable provider shape that built one embedding index.
EmbeddingIndexRow
One persisted embedding chunk.
EmbeddingIndexRowCount
Measured chunk-row cardinality, never a capacity estimate.
EmbeddingProvider
Semantic facts describing one uniformly rendered embedding provider.
EmbeddingProviderRegistry
Resolves declared providers and validates every mount-time invariant.
EmbeddingSiteBinding
Machine-local mapping from semantic binding names to endpoint URIs.
EnvBase
The base inheritance pointer (gc ProviderSpec.Base, a *string whose tri-state is LOAD-BEARING). Sealed — consumers switch exhaustively (house style). The three states are OBSERVABLY distinct:
EnvBaseRef
base = a NAMED parent, resolved against scope. See EnvBase.
EnvBaseStandalone
base EMPTY ('') — explicit standalone opt-out. See EnvBase.
EnvBaseUndeclared
base ABSENT (gc nil) — inherit by convention. See EnvBase.
EnvironmentProbeArming
A station's LIVE availability ARMING as ONE ambient value: the injected probe plus the bounded interval it runs on.
EnvironmentProbeRequest
ONE environment's probe input: its registry name, the FLATTENED environment the registry resolved for it, and the endpoint the site binding bound on this box (null when the target is provider-managed and needs no machine fact).
EnvironmentRegistry
name → AgentEnvironment, across TWO namespaces (gc's builtin-vs-custom base grammar — BaseScope): builtins are the shipped defaults (empty here; the harness collapse pow-ebf.4 supplies claude/copilot/pi/opencode as data), custom the box/substation authoring. A name in BOTH: custom is the leaf and a same-named builtins entry layers UNDER it (the EnvBaseUndeclared convention).
EvidenceGap
ONE named hole in a lens's evidence bundle — the canonical id of the record that is not complete, and the RECORDED reason it is not.
ExactSubstationBeadSource
An exact-id extension of BdExportBeadSource for filing checks.
ExternalBlocker
One external:<project>:<capability> dependency row, with what the roster said about its project.
FencedAgentSteer
Typed decode shape for the durable steer metadata value.
FenceLiveness
One recorded fence probe: the pgid, its leader, and who was still alive.
FileCommitteeSelectionStore
The real CommitteeSelectionStore: strict versioned JSON under kCommitteeSelectionDir, written through a same-directory temporary file so a reader never observes a half-written artifact.
FileSystemSubstationFactsRepository
The filesystem SubstationFactsRepository: observes EXPLICITLY configured substation roots, and nothing else.
FileSystemWorktreeActivityProbe
The real probe: <state-store>/worktrees/<substation>/<work-bead-id>.
FilingAdvisory
The injectable advisory seam (Fakes, not mocks — the offline suite always injects). One method, no mutation surface: an advisory READS a bead and answers about it.
FilingAdvisoryPassed
The lenses PASSED — the readiness lens graded readinessGrade (A–C) and the discovery matrix advanced.
FilingAdvisoryRefused
A lens REFUSED — reason is that lens's OWN fix text, verbatim.
FilingAdvisorySkipped
The advisory was WAIVED — FilingAdvisoryMode.skip. No inference ran, and nothing was judged.
FilingAdvisoryVerdict
What the advisory concluded. Sealed: consumed with an exhaustive switch.
FilingCommand
filing <bead-id> — deterministic enforcement of front-door completeness.
FilingContract
Pure evaluator for the eleven-row filing report.
FilingEvidence
What the six VIABILITY rows are judged against — everything a pure evaluator cannot decide from the bead's own text.
FilingEvidenceSource
The asynchronous seam that GATHERS FilingEvidence for one bead.
FilingReport
The complete filing report for one bead id.
FilingRequirementRow
One deterministic filing requirement result.
FilingService
UI-drivable filing lookup plus contract evaluation — the ONE read/gather/ evaluate path the filing verb, the approve verb and the mount gate share.
FixInFlight
ONE committee finding the round advanced WITH — BINDING on the build.
FormatCleanCapability
Mechanical, no-agent refusal of an UNFORMATTED diff (bead pow-jicn).
GatherAgentEnvironment
The GATHER seat - the discovery explorers (DiscoveryLensCapability, one class over three lenses, all read-only and all one seat).
GitGridAssets
GitGridAssets — the substation-scoped SOURCE-CONTROL asset (v3 §3).
GitServices
GitServices — the station's git-execution machinery as ONE ambient value: the shared StationGitRepository provisioner + the GitOps commit/push half (bead pow-72b).
GitSourceControl
The git SourceControl impl over grid_runtime — WORKSPACE PROVISIONING ONLY (the detail the engine knows only in CONCEPT — ADR-0008 D5; ships in the asset package).
GridAssetResolution
The COMPLETE immutable answer: what is available at one substation, and the exact files both writers act on.
GridAssetRosterOverride
A station's EXPLICIT exceptions to what the selectors decide — composition values, validated at construction.
GridAssetsPack
The grid_assets asset pack.
GridBlock
One parsed, validated grid: block.
GridPolicyAcpClient
ACP client posture for a grid agent doing real work in its worktree.
HarnessProvider
HarnessProvider — harness provision as a STATION-scoped asset (v3 §3).
HistoryCommitEvidence
ONE commit touching the bead's resolved surfaces.
HistoryEvidence
The round's git-history evidence over the bead's RESOLVED surfaces — ONE batched read, recorded with its exact command.
ImplementationStep
One implementation-step record and its five labeled fields.
IndexCommand
IndexStoreAbsent
IndexStoreFailed
InferenceResult
The result of one InferenceRunner.run — success plus the captured stdout.
InferenceRunner
The injectable ONE-SHOT inference seam (Fakes, not mocks — the offline suite always injects). Mirrors GitRunner's shape, but for a harness-rendered RuntimeConfig whose stdout is the answer.
InProcessReleaseCommandInvoker
The live ReleaseCommandInvoker: composes a fresh vended release command group per call, with captured output, and runs the requested subcommand IN-PROCESS.
InsufficientEvidenceReport
The lens STATES that the canonical evidence it was handed is incomplete — a KNOWN NON-ANSWER, which is neither a clean report nor a missing lane.
IntakeCapability
TIER 1 — the deterministic INTAKE CONTRACT (zero agents), the ladder's head.
JsonObjectProvenance
A .json object: the stamp is a top-level "$generated" string field, inserted textually right after the opening brace — the rest of the file is preserved byte-for-byte (no re-encode, so an install never reformats the operator's settings).
LandPrOutcome
The result of a delivery method's REUSE-or-open — a url (with its number when the opener supplies one) on a reuse (reused true when an already-open PR was adopted) OR a fresh open, or a failureReason when neither.
LandPushOutcome
The result of a delivery method's force-with-lease push — the push's success and its combined git stdout+stderr, so delivery can stamp the output tail as the FT-1 failureReason on a non-ok push.
LaneBinaryFingerprint
The agent binary as the station FOUND it: where it resolved, what it says its version is, and when it was last written.
LaneEnvironmentCondition
WHICH lanes are currently PARKED, and the diagnosis that parked each.
LaneEnvironmentDiagnosis
The ANSWER: the lane's environment as the station just measured it.
LaneEnvironmentHealth
The station's lane-health coordinator seam.
LaneEnvironmentProbeRequest
ONE targeted or scheduled question about a lane's environment.
LaneEnvironmentSetupFailure
One session-edge SETUP refusal, as the bridge declared it.
LaneEnvironmentTarget
WHICH lane a diagnosis is about, and everything needed to re-ask the question: the registry lane name, the FLATTENED environment armed under it, the model pin the spawn resolved, and the seat tier that pinned it.
LaneOverlap
Which judgement lane's rubric already asks for a rule — the DECLARED overlap, anchored by a clause quoted verbatim from that rubric.
LensArtifactTransport
The CIRCUIT arm: the lens writes its answer to a stamped file in the worktree, and a route reads it back through the shared freshness fence.
LensInProcessTransport
The IN-PROCESS arm: the lens writes NO file and returns its answer as the last JSON value in its reply, which the caller reads off captured stdout.
LensReport
The NORMAL report — what the lens found, and what it found that CONTRADICTS a standard.
LensResultTransport
WHERE a lens is asked to leave its answer — the ONE axis that differs between the in-pipeline circuits and the filing verbs' pre-stamp advisory.
MarkedBlockProvenance
A plain-Markdown file the repository ALSO owns (the root kAgentsRootRelativePath): the stamp cannot go anywhere in the file at large, so this tooling claims one BLOCK of it, bounded by kGeneratedBlockBegin and kGeneratedBlockEnd, and stamps the block's first interior line.
ModelPreference
An ORDERED preference over complete AgentEnvironment values - "this scope wants X, else Y, else Z", most-preferred FIRST (ADR-0006 D1).
ModelTiers
The STATION's arming of tier → model — a pure VALUE the tree carries (config = VALUES in the tree, impls = DI). Every field is a SPARSE override: null ⇒ that tier rides defaultModelForTier.
ModelTokenPrice
The per-million-token LIST PRICE of one explicitly selected model — the declared half of a DERIVED cost (bead pow-zetn).
MountCommand
mount [--json] [--state-root <grid-home>] <bead-id> — the offline EXPLAINER for why one bead will not mount.
MountEligibilityAssets
Injects grid_assets mount eligibility into the ambient service bundle.
MountExplanationContract
Pure evaluator for the ten-row mount explanation.
MountExplanationReport
The complete mount explanation for one bead id.
MountExplanationService
UI-drivable mount explanation: ONE filing inspect, ONE id-scoped work-store read, and the grid home's scoped session/step/attempt lists — then the pure contract and the pack's bound.
MountPreconditionRow
One precondition's answer: the outcome, the evidence that produced it, and — when it does not pass — what to do about it.
MountStateEvidence
Everything the explainer READ before it evaluated anything — the pre-read store state the pure contract is a function of.
NoAgentSteerSource
Empty source used when a composition has no command observer.
OverlayFileBlocked
relativePath exists at the target but was NOT generated by this tooling — a hand-authored file (no provenance stamp) or a SYMLINK. NEVER clobbered, always reported, and non-zero at the CLI (guards LOUD or GONE: the named invariants are "this tooling never overwrites a file it did not generate" and "it writes nothing outside the target root").
OverlayFileOutcome
What became of ONE file — sealed, so a caller (the assets install renderer, the provision wire) faces every case with an exhaustive switch.
OverlayFileRefused
relativePath was NOT installed: after substitution it still carried holes, and a half-bound asset reads as literal text to an agent.
OverlayFileStale
relativePath carries this tooling's provenance stamp but the CURRENT resolution does not select it — an asset that was withdrawn, excluded, or whose selector stopped holding.
OverlayFileUnchanged
relativePath is already generated AND identical to source — nothing was written. A re-install is idempotent: the file is left byte-for-byte alone.
OverlayFileUpdated
relativePath was GENERATED by this tooling (it carries the provenance stamp) and its body DRIFTED from source: this call regenerated it (or, in a dryRun, reported the drift). Only the BODY decides — a stale source ref in an otherwise-identical file is not drift.
OverlayFileWritten
relativePath did not exist at the target: this call WROTE it (or, in a dryRun, found it MISSING).
OverlayInstallReport
One install's outcome — the OverlayMaterializeReport (the sealed per-file outcomes, consumed with an exhaustive switch by whoever needs the cases) plus the CONTENTS of every file this run wrote or updated, so renderInstallReport is a pure function of the report and a Flutter UI renders the same diff.
OverlayInstallService
Writes one resolved asset set onto a repo ROOT — the UI-drivable half of <cli> assets install (a Flutter app calls exactly this).
OverlayMaterializer
Writes a GridAssetResolution onto a target ROOT — stateless, and safe to construct anywhere (a CLI Command, a Flutter interactor, a synchronous engine Capability hook). This class has NO CLI and NO git dependency.
OverlayMaterializeReport
One materialization's result: an outcome per file, in resolution order, then the stale paths (sorted) the same scope turned up at the target.
PackagedAssetLoader
Loads grid_assets' bundled rubric/prompt assets from extension/.
ParkCommand
The park VERB — reclaim a stalled session's agent slot in ONE command: unstamp and defer the work bead, then close and void-retire the session that holds the slot. invocation carries the exact shape.
Parked
The verb performed ALL FIVE steps and the slot is reclaimed.
ParkFailed
The ritual STARTED and a bd call refused mid-way. It is never reported as a park: the completed steps are named so the operator finishes by hand from exactly where it stopped.
ParkOutcome
The outcome of one park run — a sealed union so every consumer faces all three arms.
ParkRefused
The verb WROTE NOTHING and says why — a missing marker, an unresolvable session, or a fence that is still LIVE.
ParkService
UI-drivable park: the five-step reclaim ritual, behind two guards.
PinDiffCapability
Pins the CRITICS' REVIEW SCOPE to the bead branch's OWN delta (bead pow-6wo) — a ServiceCapability every critic lane dependsOn, so it always runs BEFORE any critic and can withhold them.
PrComposition
The PR title/body composition knob (bead pow-8dx) — a config VALUE a station/substation mounts (the configured GitHub delivery asset) to shape the landing asset's PRs; DeliverRouteCapability reads it at its route edge and falls back to const PrComposition() when none is mounted. A plain const class (the A10(3) carrier posture): the TITLE GRAMMAR is policy (not a knob — a station cannot opt out of v1.0.0), while the trailer TOKEN, the body SECTIONS, and the describe MODEL are.
PrCompositionContext
The data the title/body composition renders over — gathered by the land step at its run edge and threaded in as VALUES (the renderers stay pure).
PrDescription
What the describe pass INFERRED about the branch's change — the JSON object the model returns, parsed. The asset never renders these strings raw: the title goes through sanitizeConventionalSubject (compliant by construction) and the digest rides PrSection.summary through sanitizeDigest.
PreStampAdvisory
The LIVE FilingAdvisory: the shipped readiness lens, then the shipped discovery gather and its three lenses, decided by the shipped matrices.
PrimeCommand
prime [--hook-json] — the thin adapter over the pure composers above.
PrimeHandoff
The ONE handoff body an answer injects, with the single line that NAMES it and the pointer that replaces the body when the bound withholds it.
PriorArt
One PRIOR-ART hit — a bead or decision that already covered this ground.
PriorArtQueryEvidence
ONE prior-art QUERY's coverage — the query, how the search went, and its bounded hits.
ProbeTicker
A cancellable repeating tick — the DI seam over Timer.periodic, so a test FIRES the bounded re-probe instead of sleeping on a wall clock.
ProcessDoltCommandRunner
The real dolt CLI runner.
ProcessEnvironmentProbe
The REAL probe: D3's three checks, composed over three injected IO primitives so the COMPOSITION (which check runs for which InferenceTarget) is pure and unit-testable while only the defaults touch the machine (pure logic tested before IO is wired — the house set).
ProcessLaneEnvironmentProbe
The REAL lane diagnostic (bead pow-u1bi): what the agent binary IS right now, and what the resolver says about the pin against the catalog the agent offered.
ProcessSeatRunner
The real runner: a TTY plan INHERITS this terminal's stdio; a channel plan rides the station's existing session adapter with the terminal as the client.
ProseChunk
ProseChunker
Splits prose into rune-safe windows at 60% of the provider context limit.
ProvenanceSyntax
How a vended file carries its stamp — sealed, so every vended file type is faced with an exhaustive switch.
ReadinessAbsent
NO verdict has been published for this round — a JOIN state, NOT a judgement. The lane has said nothing yet: its result may simply not be VISIBLE to the route, and its artifact may not be on disk, at the instant the route looked.
ReadinessCriticCapability
TIER 2 — the CHEAP judgement lane: ONE agent grading the BEAD's readiness.
ReadinessDrive
The bead is READY — specify may run. grade is the lane's own A–C.
ReadinessHold
The bead is NOT ready — HOLD it for refinement. rule names the arm that fired (not-ready / no-verdict); reason is the refinement ask recorded on the parked gate bead.
ReadinessRouteCapability
TIER 3 — the readiness DECISION point (zero agents) AND the readiness lane's JOIN. It decides over THREE states of the lane's result, never two:
ReadinessVerdict
The readiness ladder's verdict. Sealed: consumed with an exhaustive switch.
RebaseCapability
The REBASE step — rebases the bead branch onto the CURRENT base branch tip. A conflict (or any other rebase failure) ABORTS the rebase (never leaves the worktree mid-rebase) and Escalates with the git output as provenance — never a silent force-through.
RecallCase
One durable query and the bead ids that count as its expected answer.
RecallCaseResult
The evaluated outcome for one recall case.
RecallRunResult
Aggregate recall and exact-id ordering results for one run.
RecallSet
A versioned recall corpus, exact-id guard, and recorded live baseline.
RefinementFlag
A round's refinement flag — every lane's bead-graph findings, none of which moved a letter.
RefinementNote
ONE lane's non-grading observation about the BEAD GRAPH.
RelayAgentEnvironment
The RELAY seat - a station's protective relay over its own signals (memento-engineering#protect-the-governor). PROTECTIVE in the power-grid sense that already names the governor: the device that SENSES an abnormal condition and DECIDES whether it warrants action. Not the forwarding sense of the word, and never the breaker - a relay decides, something else acts.
RelayAgentObserver
The relay OBSERVER the engine mounts: inspect, brief, infer, decode.
RelayAssets
RelayAssets — the seed that ARMS the station's protective relay.
RelayFlareRecord
What flares.read returns, one row: an observability flare the session emitted.
RelayGateRecord
What gates.read returns: the gate a session is parked at, if any.
RelayInferenceRunner
The relay's ONE inference seam: run brief on environment and return the raw answer.
RelayReadTools
The relay's READ-ONLY tool surface: the four injected readers behind the four read names, and nothing else.
RelaySessionSnapshot
ONE session, as the relay sees it: the engine's RelayObservation plus everything the four read tools returned for it.
RelayTelemetryRecord
What telemetry.read returns, one row: the usage captured at one circuit node of the session.
RelayWorktreeSnapshot
What worktree.read returns: the session worktree's per-path modified times plus its last commit and when that commit landed.
ReleaseCircuitRequest
Everything a release wave is: the workspace, the ref the changed-package query compares against, the semver move, the packages it publishes, the optional consumers manifest a stable wave owes, and whether a human declared intent to promote.
ReleaseCommandInvocation
One vended release-command invocation's result — the exit code and both captured streams, and nothing else. The circuit reads verdicts out of the JSON object on stdout; stderr and a non-zero exitCode are what a refusal quotes.
ReleaseCommandInvoker
The injectable seam every release leg runs its vended operation through.
ReleaseGateCapability
The deterministic release legs — ONE capability, ten operations, selected by the step's operation param.
ReleasePackageTarget
One package a release wave publishes: WHAT it is, WHERE it lives relative to the workspace root, and the prerelease rung the wave means it to occupy.
ReleasePromotionRouteCapability
The PROMOTION route — the only decision point in the release graph, and the place the pipeline HALTS rather than driving through a rung change only a human may make.
ResolvedAnchor
One resolved code ANCHOR — a path the bead NAMES, resolved against the live worktree, with the PATTERN that surrounds it (its directory's other files).
ResolvedGridAssetArtifact
ONE selected file: the definition that vends it, the declared leg, and the EXACT source and target paths. No discovery remains for a writer to do.
ResolvedGridAssetPack
One participating package resolved from the station package config.
RespecLane
One FAILING committee lane, as the re-specify agent must see it: the rubric that rejected the spec, the grade it gave, and its RATIONALE verbatim (the "recommendation" the bead requires reach the next brief).
RespecLedger
The auto-respec guidance ledger — the circuit round plus every failing lane, written into the bead's worktree by SpecRouteCapability and read back by SpecifyCapability on the next round. The round field mirrors the circuit round for the guidance brief; grid.round remains the sole authority.
RevalidateCapability
The REVALIDATE step — re-runs the bead's OWN Validation Plan (the SAME command the code-review committee's deterministic code-validation lane runs) against the REBASED tree, closing the stale-base hole (a plan that passed pre-rebase may fail post-rebase).
RoundRestamp
The outcome of the capability-side round re-stamp (restampVerdictRound).
RoundRestampApplied
The file was proven fresh and its CONTAMINATED round stamp was rewritten to the engine-injected round; modelRound is what the model had written, now preserved in the file under kVerdictModelRoundKey.
RoundRestampSkipped
The verdict file was left EXACTLY as found: it is absent, unparseable, not provably this incarnation's output, or its round stamp is unusable. The ratified fence then judges it exactly as it does today.
RoundRestampUnchanged
The file was proven fresh and the model's copy already MATCHED the engine-injected round — nothing was rewritten.
RubricEvidence
ONE grading rubric, bounded — its identity plus the digest of its COMPLETE prose. The prose itself still rides DiscoveryAnchors.rubrics verbatim (the architect is graded by it), so this record is the IDENTITY, not a second copy.
SearchCommand
search <query…> — deterministic cross-store search over the station's attached substations.
SearchHit
One structured hit: a bead that matched the query, with WHERE it lives (the owning substation), WHAT state it is in, and WHY it matched (the matched field + an excerpt).
SeatChannelClient
The TERMINAL's side of a channel-harness occupancy.
SeatChannelLaunch
A CHANNEL harness (a non-null AgentEnvironment.sessionAdapter): the station's existing session adapter owns the launch and the terminal is the client — no second spawner. priming is the first session message, or null.
SeatCommand
seat <name> [--env <name>] [--grid-home <abs>] [--once].
SeatDisc
One operator seat's disc directory — the thin IO seam over parseSeatHandoff. Read-only except for ensure and writeHandoffOnce.
SeatEnvironments
The four typed lookups RESOLVED at one point in the tree - the offline projection a station's banner prints and the suites assert. A pure VALUE.
SeatHandoff
One kind: handoff note read off a seat's disc — a pure VALUE.
SeatLaunch
One planned OPERATOR-SEAT launch — a pure VALUE an injected runner executes. Sealed: a caller faces both transports with an exhaustive switch.
SeatPreference
A SEAT's preference: a ModelPreference subtype that also vends the SEED which provides it, so the set of seats is OPEN.
SeatProvider<T extends SeatPreference>
Provides ONE SeatPreference over a subtree under its EXACT static type T - the provider seed a plain seat type vends from provider().
SeatSuccessionReport
What one SeatSuccessionService.succeed run did — a plain immutable value, UI-drivable: SuccessionCommand renders it, and so could anything else.
SeatSuccessionService
The reusable succession LOGIC — the whole verb minus argv and sinks.
SeatTtyLaunch
A TTY harness: run command + args with INHERITED stdio.
SemanticResidue
One claim the parser CANNOT decide, anchored by a clause quoted verbatim from the judgement lane that owns it.
SemanticSearchBackend
SemanticSearched
SemanticSearchHit
SemanticSearchOutcome
SemanticStoreCoverage
SemanticStoreInput
SemanticUnavailable
ShellRunner
The injectable shell-exec seam a Validation Plan runs through — mirrors GitRunner's shape (Fakes, not mocks), but for an arbitrary shell command rather than git.
ShellRunResult
The result of one ShellRunner.run — the exit code and combined stdout+stderr.
ShowCommand
show [--json] [--if-revision <revision>] [--state-root <path>] <bead-id> — the one-bead READ verb.
ShowOutcome
The outcome of one show run — a sealed union so every consumer faces all three arms.
ShowService
UI-drivable one-bead read: ONE exact-id read of the work store, projected into a bounded ShowOutcome.
SiteBinding
A box's machine facts: environment NAME -> the inference endpoint it reaches on THIS box. See the library doc.
SpecAdvance
The spec is READY — advance to the build. Either every lane converged (fixInFlight null), or exactly ONE architect-owed D remains and rides along as a BINDING fix-in-flight item (bead pow-bhm, ratified 2026-07-18).
SpecAgentEnvironment
The SPEC seat - SpecifyCapability (its first-round and its respec spawn are the same site). Folded pow-t1w's architect role, which bead pow-n6n.4 deleted (ADR-0006 D5).
SpecContract
The typed projection of ONE spec's line-oriented records.
SpecContractFinding
One source-located deviation from the documented grammar.
SpecCorpusEntry
One retained spec and its recorded outcome.
SpecCriticCapability
One SPEC critic, in isolation — the spec committee's LLM lane. Subclasses CriticCapability to inherit the ENTIRE verdict-transport stack unchanged (canonical file → round-fresh stray → result-envelope → fail-closed F, each with the nodePath + round freshness stamps and a named transport; plus the FT-2 usage merge): one transport stack serves both committees, so a hardening landed for the code critics (gate-integrity #3/#4, tg-291) automatically holds here. Only the SPAWN differs — it declares the MID tier (AgentTier.mid), like its superclass, so absent an override it grades on kMidModelDefault (sonnet); and a spec critic is always an agent (there is no sh -c validation-runner flavor; the spec gate is SpecValidationCapability) and its prompt is buildSpecCriticPrompt: the review subject is the bead's SPEC, never a pinned diff (no code exists yet).
SpecEscalate
The spec needs a HUMAN — the escalation arm. rule names the matrix arm that fired (gating-hard-block / critic-F / no-rationale / author-owed / multi-action-grade / respec-cap); reason is the parked gate's human-readable body.
SpecifyCapability
SpecRespec
The spec is FIXABLE — auto-loop back to specify with ledger's rationales as the correction guidance. NEVER a human ruling.
SpecRouteCapability
The SPEC committee's route (beads pow-7nm + pow-ui8) — the spec-side counterpart of the code committee's CodeRouteCapability, with a THIRD arm between advance and a human gate. It assembles ONE fresh lane vector at entry — the GATING lane's grade off the ambient SiblingView (the effect verb — never a subscription/re-query, D-5), and each JUDGEMENT lane's grade
SpecRouteVerdict
The spec route's THREE-way verdict (bead pow-7nm) — the code committee's binary advance | escalate matrix (CodeRouteCapability) is unchanged; the SPEC committee gains a middle arm. Sealed: consumed with an exhaustive switch.
SpecValidationCapability
The GATING spec lane — a deterministic STRUCTURAL check over the spec the ambient Bead carries (the spec-side mirror of the code committee's code-validation posture: a validation RUNNER, not an agent — no LLM judgement in this lane). It always COMPLETES with a grade in its Ok payload (A iff the structure is whole, else F with the findings as rationale), leaving the route as the single decision point — exactly the gating-lane contract committee.dart established.
StationIndexReport
StationIndexService
StationOverlaySource
One ordered overlay root and the path mappings declared by its own pack.
StationSearchReport
The whole search's structured result: the query + one outcome per roster seat, in roster (mount) order.
StationSearchService
The reusable, UI-drivable search SERVICE — all the logic behind the station's search verb (SearchCommand is a thin adapter over this; a Flutter app calls this directly).
StoreAbsent
The roster seat's root has no work store (<root>/.beads/ absent). NOT a refusal: an absent coded sibling still mounts its seat (space-6ds), so a search reports the gap loud and keeps covering the rest of the roster — the same skip-loud posture arming takes.
StoreFailed
The store exists but the read failed (bd unavailable, export error, …) — surfaced per-store, never masking the other seats' results.
StoreIndexed
StoreIndexOutcome
StoreSearched
The store resolved and was queried; hits may be empty.
StoreSearchOutcome
The per-store outcome — a sealed union so a consumer must face all three cases: a store was StoreSearched, was StoreAbsent (roster seat with no .beads/ at its root — a coded sibling not checked out), or the read StoreFailed. A search never silently drops a roster seat.
SubstationBeadSource
The per-store read seam — READ-ONLY by construction (A37): one read method, no mutation surface. The service is built on this seam so a search cannot write a foreign store by type, and tests exercise the whole service offline (Fakes, not mocks).
SubstationFacts
The FILESYSTEM and PACKAGE-GRAPH observations for ONE substation root — an immutable value, observed outside build and never re-derived inside one.
SubstationFactsAssets
PROJECTS the injected repository's snapshots into the tree.
SubstationFactsModelSeed
The ambient facts, scoped BY SUBSTATION: a dependent that watches one SubstationKey aspect is invalidated only when THAT substation's facts change (power_station#adr-0006-typed-environment-lookup-selects-by-value).
SubstationFactsRepository
The SINGLE source of root observations — injected, never constructed inside a build (config = VALUES in the tree, impls = DI).
SubstationFactsSnapshot
ONE immutable emission covering EVERY configured substation — what the repository publishes and the tree projects.
SubstationKey
ONE substation's stable identity — its tree Key AND the aspect a substation build subscribes to on SubstationFactsModelSeed.
SuccessionCommand
The THIN argv and sink adapter over SeatSuccessionService and SeatDisc.writeHandoffOnce — see invocation for the shape.
SystemFilingEvidenceSource
The LIVE FilingEvidenceSource: two parse probes, one all-status id catalog per distinct store, and one roster-mode decision-index lookup.
SystemInferenceRunner
The real InferenceRunner: Process.starts the harness-rendered argv (NO shell — no word-splitting of a prompt that contains a whole diff), collects stdout, and KILLS the child at timeout (a hung claude must never wedge a land). Constructed as buildCodeRegistry's default; the offline suite always injects a fake.
SystemShellRunner
The real ShellRunner: execs <shellExecutable> -c <command> via dart:io.
SystemValidationPlanProbe
The real ValidationPlanProbe: <shell> -n -c '( <plan> )'.
Touch
One ## Touches record.
UnparkCommand
unpark --actor <name> [--json] <work-bead-id> — clear a parked bead's defer date and re-stamp its approval.
Unparked
The defer DATE cleared and the approval preflight re-stamped it.
UnparkFailed
bd undefer itself refused — the approval step never ran.
UnparkOutcome
The outcome of one unpark run — a sealed union so every consumer faces all three arms.
UnparkRefused
The bead IS undeferred, but the approval preflight refused to re-stamp it. Never reported as unparked: an unstamped bead does not mount.
UnparkService
UI-drivable unpark: clear the defer DATE, then re-run the EXISTING approval verb.
UsageReport
The usage fields a harness JSON/JSONL run reports — every field OPTIONAL (a partial or version-skewed envelope contributes only what it carries). Pure value; parse with tryParse, project with toResultFields.
ValidationDelta
The answer one comparison produced: which named test failures are the BRANCH'S (a gate) and which the base already had (a note).
ValidationDeltaRunner
Runs one Validation Plan on the branch AND at its merge-base, on the same host, and answers the ValidationDelta between them.
ValidationMapping
One ## Validation Plan record.
ValidationPlanParseResult
ONE shell's answer about whether a validation plan PARSES.
ValidationPlanProbe
The injectable PARSE seam — it never EXECUTES the plan.
WorktreeActivity
CORROBORATION only: when the work bead's worktree was last written.
WorktreeActivityProbe
Reads the corroborating worktree activity for one work bead.
YamlFrontmatterProvenance
A .md whose first line opens a YAML frontmatter block (---): the stamp is a YAML COMMENT on line 2, so the frontmatter still OPENS on line 1 and the harness's skill discovery still parses it.

Enums

AgentPermissionCapability
The protocol-neutral kind of action one permission request asks for.
AgentPermissionGrant
The widest scope a station's policy is willing to give one capability.
AgentPermissionOutcome
The answer actually returned to the harness for one permission request.
AgentTier
The model CLASS a spawn rides — the selection axis. Sealed by the enum: consumers switch exhaustively (house style), so a new tier cannot be added without every arming site naming its model.
BaseScope
Which lookup scope an EnvBaseRef resolves against (gc's base prefix grammar). Sealed by the enum: consumers switch exhaustively (house style).
BeadCitationField
A field on a bead that discovery may cite verbatim.
BeadTextField
One text-bearing field of a work bead.
ChangeShape
Which committee a bead's change belongs to.
CodeCircuitShape
Which shape of the code circuit a session's cursor was MINTED under.
CommitteeClassifierResultKind
What one classifier call produced. Three of the four arms are NON-RESULTS: they are facts about the call, never a judgement about the work, and none of them is ever a letter grade.
CommitteeSelectionRule
The EIGHT deterministic selection rules — the whole policy, as const values.
CommitteeSelectionSource
WHICH channel produced a selection.
CommitteeStage
Which committee a selection was computed for. The two stages read DIFFERENT evidence, so the wire value is hashed into every digest.
DecisionDisposition
What a ## ADR Alignment item declares about its cited decision.
DecisionLookupNarrative
What a spec's ## ADR Alignment section declares about the roster LOOKUP itself — the distinction power_station#the-spec-decision-lane-queries-the-roster-union (3) makes load-bearing: "An empty union is a real result; a CRASHED lookup is not. A lookup that fails or exits non-zero must be reported verbatim and never graded clean."
EvidenceState
How COMPLETE one piece of gathered evidence is. Sealed by the enum and consumed with an exhaustive switch (house style), so a new state cannot skip a projection's sufficiency check.
ExternalResolution
What the station ROSTER said about one external: row's project.
FilingAdvisoryMode
WHETHER a filing evaluation runs the pre-stamp advisory.
FilingRequirement
The eleven mechanical checks reported for a newly filed bead.
InferenceTarget
WHERE inference runs (ADR-0002 D3) — the KIND only; the endpoint URL is a MACHINE FACT the site binding supplies (bead pow-ebf.6), never here. The URL-FREE successor to agent_harness.dart's ModelTarget (which fused kind+URL) — ADR-0002: "ModelTarget survives as the target field; the endpoint URL it carried moves to the site binding." Sealed by the enum: consumers switch exhaustively (house style).
MountOutcome
What one mount precondition says.
MountPrecondition
The ten preconditions one bead must satisfy before a station mounts it, in the ONE order both renderings emit them.
OverlayCheckClassification
How a path reads in a --check report — the CLOSED classification vocabulary assets install --check prints and exits on.
ParkMarker
The DURABLE marker that admitted one park.
ParkStep
The five hand steps the park verb absorbs, in the ONE order it performs them. The order is load-bearing: the work bead stops being mountable and stops being ready BEFORE its session is closed, and the closed session is re-keyed LAST so a crash between the two leaves a dead join key rather than a live one pointing at a closed session.
ParkStore
WHICH of the two stores one park mutation targets (A37).
PromptMode
How the brief is DELIVERED to the tool (gc prompt_mode) — transport, as DATA. Sealed by the enum: consumers switch exhaustively (house style).
PrSection
The composable PR-body sections — the landing asset's body is a CONFIGURABLE composition of these (bead pow-8dx), rendered through ONE exhaustive switch (renderPrSection).
RecallCaseKind
Whether a corpus row is a genuine lexical miss or an existing lexical hit.
ResumeStyle
How AgentEnvironment.resumeFlag is applied (gc resume_style). Sealed by the enum: consumers switch exhaustively (house style).
SeatArchiveSink
WHERE a run archived the disc before it consumed the note — the fork is the disc's OWN tracked state, and the two sinks are exclusive. Sealed by an enum so every reader faces both with an exhaustive switch.
SeatPrimeMode
How the newest HANDOFF on an operator seat's disc reaches its occupant (bead pow-lv6t). Sealed by the enum: consumers switch exhaustively (house style). ONE priming path per harness, DECLARED, never guessed.
SeatSuccessionDisposition
What one succession run DID — the four outcomes, sealed by an enum so the CLI consumes them with an exhaustive switch.
SessionStartSource
The four SessionStart sources the harness sends. Sealed by the enum so the injection-cost rule is consumed with an exhaustive switch.
SpecContractRule
Every rule parseSpecContract can report — one rule, one finding, so a single-rule fixture mutation fails with a single precise message.
SpecContractSection
The spec sections parseSpecContract reads — the cascade's currency.
TouchDisposition
What a ## Touches item declares happened to its path.
UsageCostSource
Where a non-null UsageReport.costUsd came from (bead pow-zetn) — durable beside the number, because a report that mixes billed and estimated money with no marker is a report nobody can audit.
ViolationKind
What KIND of standard a violation cites. Sealed by the enum — consumed with an exhaustive switch (house style), so a new kind cannot skip the gate matrix.

Extensions

AgentProtocolEventPatterns on AgentProtocolEvent
Adds pattern-matching-related methods to AgentProtocolEvent.
FencedAgentSteerPatterns on FencedAgentSteer
Adds pattern-matching-related methods to FencedAgentSteer.
ShowOutcomePatterns on ShowOutcome
Adds pattern-matching-related methods to ShowOutcome.

Constants

kAcceptanceRecordForm → const String
The acceptance-criterion record form — an addressable, stable id per criterion, so the validation plan can map onto it BY NAME.
kAcpBridgeSpecEnvironment → const String
Private environment handoff from the adapter launch to the bridge.
kAcpEffortSuffixByTier → const Map<AgentTier, String>
The reasoning-effort suffix each seat rung rides on an agent that names the effort INSIDE the model id.
kAcpPermissionDecisionTimeout → const Duration
How long the bridge waits for the STATION's answer to one permission ask before cancelling it locally.
kAcpProtocolVersion → const int
ACP major protocol version spoken by the bridge.
kAcpSessionAdapterId → const String
Stable registry identity for the ACP session adapter.
kAdjudicationLogHeading → const String
The heading the verifier appends its per-round record under. ONE section per document, one ### Round <n> subsection per round.
kAgentAssetsVersion → const String
This pack's grid.agent shape version (pre-1.0: minor = breaking).
kAgentAuthorizationDecisionFlare → const String
The out-of-band flare every policy-produced authorization is recorded on.
kAgentDomainKey → const String
The grid.agent metadata key (one slot per domain — the top-level-key merge granularity).
kAgentFailureOfferedField → const String
The AgentProtocolEvent.failed field carrying the model ids the agent offered, JSON-encoded (encodeOfferedField / decodeOfferedField).
kAgentFailurePhaseField → const String
The AgentProtocolEvent.failed field naming WHICH phase of the session a failure happened in.
kAgentFailurePinField → const String
The AgentProtocolEvent.failed field carrying the model pin a setup refusal named.
kAgentFailureResolverVerdictField → const String
The AgentProtocolEvent.failed field carrying the resolver's own verdict on the pin against the offered catalog.
kAgentSetupPhase → const String
The kAgentFailurePhaseField value for a failure BEFORE the first turn: the handshake, the session open, the model selection.
kAgentsMappingKey → const String
The mapping key of the harness-neutral agents TREE leg.
kAgentsRootMappingKey → const String
The mapping key of the harness-neutral agents ROOT-FILE leg — the only leg whose target is the repository ROOT itself rather than a harness head.
kAgentsRootRelativePath → const String
The ONE root-relative file the kAgentsRootMappingKey leg vends — the file a codex-style seat actually reads at a repository root, and the reason the leg exists at all: .agents/ carries skills, and no .agents/ path is read as repository INSTRUCTION.
kAgentsRootTargetHead → const String
The target of the kAgentsRootMappingKey leg: the repository ROOT.
kAgentsSkillsSubtree → const String
Where Codex discovers a skill inside a repo root (<root>/.agents/skills/<id>/SKILL.md, scanned from cwd up to the repo root). Copilot CLI reads this tree AND .claude/skills, so the two legs below already serve it — there is no third rendering.
kAgentsTargetHead → const String
Where the harness-neutral agents layout reads a repo's assets — the head every kAgentsMappingKey leg materializes under.
kAgentSteerMetadataKey → const String
Work-bead metadata key containing one JSON-encoded fenced steer.
kAgentStep → const String
The BUILD step's own verb, as it opens a failure reason.
kAnchorsStep → const String
The deterministic gather step (ZERO agents) — the circuit's only dep-free step, and therefore the cursor key the migration guard classifies on.
kApprovedAdvisoryKey → const String
Metadata key: skipped when the advisory was waived — the operator-legible half of kReadinessSkippedKey, so a receipt says WHY no grade is recorded rather than leaving its absence to be read as a lens that found nothing.
kApprovedAdvisorySkipped → const String
The kApprovedAdvisoryKey value a waived advisory records.
kApprovedAtKey → const String
Metadata key: the UTC ISO-8601 instant the approve verb stamped.
kApprovedByKey → const String
Metadata key: the --actor that ran the approve verb.
kApprovedRevKey → const String
Metadata key: the revision the approval was granted AGAINST.
kArgvTransport → const String
The transport named in an ARGV-leg agent failure reason — there is no session adapter on that leg, and the bracket in capturedOutputReason names WHICH transport produced the failure, never a harness.
kAssetFactsUnavailableFlare → const String
The ONE flare a consumer raises when it holds a station registry but the station has not mounted the facts projection yet (power_station#one-asset-resolution-defines-tree-and-writers).
kBeadsCodexBlockBeginPrefix → const String
How bd setup codex's own block OPENS in a repository's root instruction file — a PREFIX, because bd stamps its generator and profile onto the rest of the line.
kBeadsCodexBlockEnd → const String
How bd setup codex's own block CLOSES. See kBeadsCodexBlockBeginPrefix.
kBeadWorkFields → const List<BeadTextField>
The five WORK fields a scanner reads, in the order they are joined.
kBootRunnerArg → const String
The hole naming what starts the RESIDENT. Defaults to kRunnerArg.
kBoundedOutputCapBytes → const int
The HARD ceiling on one rendered result, in UTF-8 bytes, counting the trailing newline the command writes.
kBuildSeatPolicyId → const String
The BUILD seat's audit id, stamped onto every authorization its channel makes. An AUDIT id, never a lookup key: nothing resolves by this string.
kBuiltinAgentSessionAdapters → const AgentSessionAdapterRegistry
Station-default session adapter implementations.
kBuiltinEmbeddingProviders → const Map<String, EmbeddingProvider>
First-party embedding provider declarations.
kBuiltinEnvironments → const Map<String, AgentEnvironment>
The first-party inference environments as DATA (ADR-0002 D1). Claude, Pi, and OpenCode retain their one-turn argv transports. Copilot and Codex select the ACP channel adapter while keeping their command, args, and tool posture as values. Codex alone pins its native gpt-5.6-sol; the ACP adapter resolves that base against the qualified ids offered by the live session. Each builtin also declares how it takes an OPERATOR SEAT (bead pow-lv6t) — role definition, disc, and priming path — so the seat launcher carries no vendor flag.
kCarriedSpecAcceptanceKey → const String
Result key carrying the acceptance text authored by the specify step.
kCarriedSpecDesignKey → const String
Result key carrying the design text authored by the specify step.
kCheapModelDefault → const String
The AgentTier.cheap rung's asset-default model.
kCitationPathsRubric → const String
The lane whose every CITED file path must resolve in the tree.
kCiteVerificationRubric → const String
The judge lane that RESOLVES every citation — the deterministic half of an otherwise judgemental committee.
kClaudeMappingKey → const String
The mapping key of the Claude Code leg.
kClaudeNativeDefaults → const Set<String>
The models defaultModelForTier emits — the claude-native tier defaults. These are CLAUDE's names (opus/sonnet/haiku); a non-claude environment armed to a role must pin its OWN model, because these names 400 elsewhere (bead pow-a9o: codex --model opus is rejected on a ChatGPT account).
kClaudeSkillsSubtree → const String
Where Claude Code discovers a skill inside a repo root (<root>/.claude/skills/<id>/SKILL.md) — the harness's layout named ONCE, for the callers that must scope to it (the worktree wire) or read skill ids back out of it.
kClaudeTargetHead → const String
Where Claude Code reads a repo's assets — the head every kClaudeMappingKey leg materializes under.
kClearCritiqueStep → const String
The hygiene step id every critic lane transitively dependsOn (gate-integrity #3) — wipes _critiqueDir before any lane can read or write this round.
kCodeCircuit → const Circuit
spec_review → agent → review → land — the live code circuit (M5 "The Circuit" Track E; the spec stage is bead pow-6ao, the land step is itself the landing circuit as of bead tg-rm5).
kCodeGatingRubrics → const List<String>
Every deterministic hard gate in the code committee.
kCodeLens → const String
The CODE lens — what this bead will touch, and the conventions that govern it.
kCodeReviewCircuit → const Circuit
The adversarial code-committee circuit (id code_review) — a hygiene step (gate-integrity #3, ClearCritiqueCapability) → a diff-pinning pre-critic step (bead pow-6wo, PinDiffCapability) → the DETERMINISTIC FRONTIER (kFormatCleanStep + kDeclaredTestsRubric, fanned out in parallel) → four critic lanes fanned out in parallel → a route step that joins on all four and aggregates their grades (M5 Track C / C1).
kCommitteeActionGrades → const Set<String>
The grades this pack's route matrices treat as ACTION lanes (D/E/F) — a wider set than kCommitteeAdverseGrades by design.
kCommitteeAdverseGrades → const Set<String>
The grades trajectory's own report counts as ADVERSE. Re-expressed rather than imported: D1 narrows this package's grid_trajectory surface to the three VALUE types, so a constant crosses as a literal, not as an import.
kCommitteeClassifierAllowlist → const Set<String>
The CLOSED set of semantic rubric ids a classifier may name. An answer carrying anything else is rejected WHOLE (CommitteeClassifierResultKind.unknown) rather than filtered down to the legal subset — a model that named an id we do not run did not understand the question, and half-believing it would launder that.
kCommitteeClassifierAttempts → const int
How many times ONE unknown-shape classification may run in a single capability invocation: the first call, plus exactly one retry.
kCommitteeFixInFlightFindingKey → const String
The route payload key carrying the finding an advance forwarded.
kCommitteeFullRubricsParam → const String
The step param carrying the ACTIVE full committee roster, as a CSV of rubric ids in declaration order. It arrives as a VALUE so this library never imports a committee's roster constant.
kCommitteeGatingRubricsParam → const String
The step param carrying the ACTIVE deterministic gate ids, as a CSV. These lanes are ALWAYS selected, whatever the rules or the classifier say.
kCommitteeMetadataBasenames → const Set<String>
Extension-free basenames that make a changed path METADATA.
kCommitteeMetadataExtensions → const Set<String>
File extensions (without the separator) that make a changed path METADATA — a manifest, a lock, a config. A pubspec is covered by the first of these.
kCommitteeOperatorTransport → const String
The transport an OPERATOR RULING stamps on a lane result.
kCommitteeProseExtensions → const Set<String>
File extensions (without the separator) that make a changed path PROSE.
kCommitteeRubrics → const List<String>
Every committee rubric id, in declaration order (the gating lane first).
kCommitteeSelectionDir → const String
The workspace-relative directory the shadow artifacts live in — deliberately NOT .grid/critique, whose ownership stays with verdict freshness (power_station#a4-gate-integrity-3-bead-tg-bns-the-verdict-freshness-stamp).
kCommitteeSelectionPolicy → const CommitteeSelectionPolicy
The policy every circuit mounts by default.
kCommitteeSelectionPolicyVersion → const String
This policy's version stamp — every persisted artifact carries it, and a decoder refuses any other value rather than reading an older shape as if it were this one.
kCommitteeSelectionStageParam → const String
The step param naming the CommitteeStage a selector (or a shadowed route) runs for.
kCommitteeSelectionStep → const String
The step AND capability id the shadow selector mounts under, in all three review circuits.
kComputeKind → const String
The compute resource-asset kind label — what a compute lease requests/offers. The federation core treats kind as an opaque, equality-checked string; this is the COMPUTE domain naming its own kind (ADR-0011 D3).
kConsumedHandoffArchiveEnvironmentVariable → const String
The process env var naming the grid-home-relative path of the ARCHIVED copy of the handoff kConsumedHandoffEnvironmentVariable carries — the one read that recovers the body when prime's bound withholds it.
kConsumedHandoffEnvironmentVariable → const String
The process env var carrying the handoff body the launcher CONSUMED for this occupancy — the delivery path of a SeatPrimeMode.hook harness, whose priming is a SessionStart hook rather than a prompt.
kConventionalTypes → const List<String>
The Conventional Commits v1.0.0 type set (the feat/fix pair the spec itself names, plus the Angular convention's set the spec approves). An out-of-set type is NOT emitted: sanitizeConventionalSubject falls it back, and lintConventionalSubject reports it.
kCriticIncarnationDir → const String
The directory holding each critic lane's INCARNATION MARKER — deliberately OUTSIDE .grid/critique/, which sweepStaleCritique empties at every round start. A marker that survives an unrelated round is harmless: only a CriticCapability.spawn can precede a probe, and every spawn rewrites it.
kDecisionAbsentPrefix → const String
The index's one COMPLETED-NEGATIVE outcome, and the only one that may refuse a citation. Every other failure is unavailability.
kDecisionCitationExcerptChars → const int
How much of a citation's OWN field a report quotes either side of it.
kDecisionCitationFields → const List<BeadTextField>
The prose fields a DECISION citation is READ from — description and design, and nothing else.
kDecisionLens → const String
The DECISION lens — the ADRs and skills that bind; the gate's main evidence.
kDecisionLensEvidenceOmissionMarker → const String
What a clipped explore-decision bundle says in place of the records it dropped — VISIBLE in the prompt, and never silent.
kDecisionLensPromptOmissionReserveBytes → const int
Bytes held back from kMaxDecisionLensPromptBytes for the omission marker, so a clipped assembly can always afford to SAY it clipped.
kDecisionRecordForm → const String
The ## ADR Alignment record form. RESOLUTION is deterministic (the citation is an identity the roster index can answer, and the disposition is a declared word); INTERPRETATION stays the decision-alignment lane's.
kDecisionRegisterPath → const String
Where the decision-register selector points.
kDecisionWriteRule → const String
The register's WRITE rule — stated to every agent that could RECORD a decision (the specify architect writes one; the spec critic grades it).
kDeclaredTestsRubric → const String
The hard gate for test files promised by the Design.
kDefaultDescribeModel → const String
The CHEAP model the one-shot describe pass runs on by default (Nico: "a cheap model is fine" — the call is a single text→JSON completion over a pinned diff, no tool use). Overridable per station via PrComposition.model.
kDefaultEmbeddingProviderId → const String
Provider selected when configuration names none.
kDefaultOverlayRunner → const String
The executable name the vended overlay's skills render {{runner}} against (the skill's own <runner> search --json call — the coupled skill+command pattern, ADR-0001). The first-party station composing this pack is space_station, whose binary is space; any station with another verb overrides it. Homed here because it is an OVERLAY binding, and the materializer names it in every provenance stamp.
kDefaultPrSections → const List<PrSection>
The default section order: the inferred prose leads, provenance follows, trailers close.
kDefaultStationOverlayMappings → const Map<String, String>
Default publish-safe source directory to harness target directory mappings.
kDefaultTrailerToken → const String
The default git-trailer token the bead id rides (Refs: <bead>) — the ONLY place a foreign reference may appear. Configurable per station via PrComposition.trailerToken.
kDeliverStep → const String
The ROOT circuit's terminal step id — the ONE node whose advance delivers.
kDesignCommitteeRubrics → const List<String>
Every design-committee rubric id — the docs committee's three deterministic gates first, then the four judges.
kDesignDocumentBudget → const int
The total character budget for the design documents a single verify pass embeds in its brief.
kDesignJudgeRubrics → const List<String>
The four ADVERSARIAL judge lenses, in the order the r6 round ran them. Each is a distinct rubric asset; the pack IS the committee (docs_committee header: "a new document type IS a new rubric pack plus its circuit").
kDesignPathPrefix → const String
The SOLE allow-listed design-round prefix — the repo-ROOT docs/design tree. A design round's document lives here; no other location is admitted.
kDesignReviewCircuit → const Circuit
The DESIGN review circuit (id kDesignReviewCircuitId) — the docs committee's shape with the judges and the verifier in place of its single critic:
kDesignReviewCircuitId → const String
The DESIGN review circuit's registry id (design_committee.dart owns the circuit itself; the id lives here because ChangeShapeCircuitResolver is the one place a shape becomes a circuit, and this library must not import its own extension).
kDesignSeverities → const List<String>
The three severities a judge may attach to a finding, worst first.
kDesignVerdictOpen → const String
The verdict a finding carries when it survived verification — the ONLY one that reaches the route.
kDesignVerdicts → const List<String>
The three verdicts the verifier may return for a finding.
kDesignVerifyStep → const String
The verify step's id — also the rubric id its critique artifact is filed under, and the ONE lane the route joins. A LITERAL: it is a persisted cursor key.
kDiscoveryCircuit → const Circuit
The DISCOVERY circuit (id kDiscoveryCircuitId) — the deterministic gather → three READ-ONLY lenses in parallel → the route that escalates a CITED offence or advances with the curated dossier.
kDiscoveryCircuitId → const String
The discovery circuit's registry id — and the SubCircuitStep id that inflates it inside spec_review.
kDiscoveryLenses → const List<String>
Every lens, in declaration order (step ids AND lens ids — one word).
kDiscoveryRouteStep → const String
The decision point (ZERO agents) — the circuit's terminal.
kDocsCheckCapabilityId → const String
The capability id the three mechanical lanes share (params['rubric'] selects the check — the same one-capability-many-lanes shape critic uses).
kDocsCommitteeRubrics → const List<String>
Every docs-committee rubric id, gating lanes first.
kDocsGatingRubrics → const List<String>
The three DETERMINISTIC gating lanes — the docs diff's answer to code-validation. Any F is a hard block, decided by the route's matrix.
kDocsLlmRubrics → const List<String>
The docs committee's LLM lane — the standard spec-adherence critic, shared verbatim with the code committee (one rubric, two committees).
kDocsReviewCircuit → const Circuit
The DOCS review circuit (id kDocsReviewCircuitId) — the code committee's shape with its lane set replaced: the same hygiene step, the same diff pin, the same route. Four lanes: THREE deterministic gating checks + the spec-adherence critic. test-coverage and regression-risk are absent by construction — there is no test to cover and no runtime behaviour to regress on a prose diff, and the F they must otherwise return is the defect this circuit fixes.
kDocsReviewCircuitId → const String
The docs review circuit's registry id.
kDocsSectionsKey → const String
The bead-metadata key naming the sections a changed doc must carry (CSV).
kEmbeddingHttpTimeout → const Duration
The end-to-end deadline on one embedding HTTP round-trip. A black-holing endpoint (packets dropped, no fast connection-refused) must degrade to SemanticUnavailable like every other provider failure — never stall the whole search command behind the lexical half (the review committee's regression-risk finding on this diff; same bound-the-external-call convention as pr_describe.dart/bounded_use.dart).
kEmbeddingSiteBindingFile → const String
Machine-local embedding endpoint binding path.
kEmbeddingSiteBindingVersion → const int
Version owned by the embedding-specific site-binding decoder.
kEnvironmentProbeInterval → const Duration
The BOUNDED re-probe interval (ADR-0006 D3 "re-probes on a bounded interval"). Five minutes: long enough that a probe pass is free, short enough that a recovered local server rejoins within one committee round.
kEnvironmentProbeTimeout → const Duration
The per-check IO budget for ProcessEnvironmentProbe's defaults. BOUNDED on purpose: a wedged local server must leave the presence set, not stall the probe pass.
kFailedDecisionLookupPrefix → const String
The prefix a spec's ## ADR Alignment section is recognized by when the roster lookup FAILED.
kFallbackDescription → const String
The description a sanitizer falls back to when it is handed nothing usable (a blank bead title AND no inference) — deliberately id-free.
kFilingApprovalRevisionPrefix → const String
The scheme + version prefix of an approval revision that binds the FILING BASIS — the digest FilingContract.evaluate derives from the bead's work fields, its validation plan and the dependency ROWS bd holds for it.
kFilingLaneShell → const String
The shell the GATING lane actually invokes the validation plan with (sh -c '( … )'). SpecifyCapability parses against the same one, so the two verbs cannot disagree about what "parses" means.
kFilingPortabilityShell → const String
The PORTABILITY shell. sh is bash 3.2 on a developer's mac and dash on CI, and a Bash-only construct dies under dash at PARSE — no log, no return code, surfacing as a harness throttle rather than as a bad plan. Parsing against dash here is what turns that into a legible refusal at filing time.
kFoldedCodeCircuit → const Circuit
The FROZEN pre-ladder folded root shape (pow-ui8, git 996d020) — spec_review → agent → review → land, whose spec_review step keeps stepId: 'spec_review' (so every child node path lines up key-for-key with the adopted cursor) but points its circuitId at kFoldedSpecReviewCircuitId, so the body inflated is the pre-ladder one. The migration target for a shape-3 survivor.
kFoldedSpecReviewCircuit → const Circuit
The FROZEN pre-ladder folded spec circuit (pow-ui8, git 996d020) — specify → clear-critique → the gating lane + four LLM critics → route. The readiness LADDER (bead pow-q7n) is NOT in it: under shape 3 the spec circuit's head was specify itself.
kFoldedSpecReviewCircuitId → const String
The registry id of kFoldedSpecReviewCircuit — the FROZEN pre-LADDER spec circuit. Deliberately NOT spec_review (that id now resolves to the CURRENT circuit, whose head is the readiness LADDER).
kFoldFidelityAndOpsRubric → const String
The judge lane that follows every decision-bearing fact through the document's folds and asks whether the result is OPERABLE.
kFormatCleanStep → const String
The FORMATTING pre-critic step id (bead pow-jicn) every critic lane dependsOn, sequenced beside kDeclaredTestsRubric after kPinDiffStep.
kFrontierModelDefault → const String
The AgentTier.frontier rung's asset-default model.
kGateBlocksKey → const String
The gate bead's metadata key naming the SESSION it blocks.
kGatingDeadline → const Duration
The gating lane's absolute-from-start deadline (the_grid audit §4, tg-uad follow-through): the deterministic code-validation lane runs the bead's OWN Validation Plan via sh -c, which is minutes-scale by definition — never the multi-hour agentic build/critic lanes — so it must NOT ride a runtime provider's 2-hour default watchdog. Ten minutes bounds every future validation-latched variant of this lane without crowding a legitimately slow (but still deterministic) plan. Deliberately NOT applied to the LLM critic/build lanes, which legitimately ride the long default.
kGatingRubric → const String
The gating rubric id — its grade F is a hard block (a non-zero Validation Plan command), decided by the route's matrix.
kGeneratedBlockBegin → const String
The line opening the block this tooling owns inside a composed instruction file — the exact bytes, on their own line, and nothing else.
kGeneratedBlockEnd → const String
The line closing the block this tooling owns. See kGeneratedBlockBegin.
kGeneratedMcpPath → const String
The generated MCP mirror, relative to the package root.
kGeneratedPackPath → const String
The generated Dart declaration, relative to the package root.
kGeneratedStationAssetRegistryPath → const String
The default station-relative generated registrant path.
kGridAttemptEnvironment → const String
The engine's allocation-env key naming the attempt an incarnation was ADMITTED under.
kGridBlockGeneratedMarker → const String
The marker BOTH generated outputs carry, so a reader tells a generated file from a hand-authored one.
kGridHomeEnvironmentVariable → const String
The process env var naming the station grid home. Set by the launcher.
kGridHomeSubstation → const SubstationKey
The substation identity the operator install resolves under: the grid home itself, which is the one root this Command observes.
kHandoffKind → const String
The front-matter kind of the one note consumed on read.
kHandoffWriteRemedy → const String
The one REMEDY a write refused for an occupied disc names: the live handoff is CONSUMED, and the next note is authored fresh at the next boundary.
kInProcessResultInstruction → const String
The IN-PROCESS transport's closing instruction — the exact counterpart of verdictWriteInstruction, and the one paragraph a pre-stamp prompt says differently from the circuit prompt it otherwise shares byte-for-byte.
kIntakeStep → const String
The deterministic intake-contract step id (the ladder's head — zero agents).
kLadderedCodeCircuit → const Circuit
The FROZEN pre-discovery laddered root shape (pow-q7n, git 4f9d5c1) — spec_review → agent → review → land, whose spec_review step keeps stepId: 'spec_review' (so every child node path lines up key-for-key with the adopted cursor) but points its circuitId at kLadderedSpecReviewCircuitId. The migration target for a shape-4 survivor.
kLadderedSpecReviewCircuit → const Circuit
The FROZEN pre-discovery laddered spec circuit (pow-q7n, git 4f9d5c1) — intake → readiness → readiness-route → specify → clear-critique → the gating lane + four LLM critics → route. The DISCOVERY circuit is NOT in it: under shape 4 specify depended directly on readiness-route.
kLadderedSpecReviewCircuitId → const String
The registry id of kLadderedSpecReviewCircuit — the FROZEN pre-DISCOVERY spec circuit. Deliberately NOT spec_review (that id now resolves to the CURRENT circuit, whose specify dependsOn the discovery circuit).
kLandingCircuit → const Circuit
The landing PREPARATION circuit (id landing) — rebase → revalidate, which code's own land step inflates as a SubCircuitStep. Each step ESCALATES (never silently forces) on failure.
kLaneDownFlare → const String
The ONE station-level condition this seam publishes: a named lane is down, and the flare carries the whole diagnosis.
kLaneFactUnknown → const String
What an unmeasurable fact renders as — NAMED, so a reader can tell "the station could not read this" from "the station read an empty value".
kLaneFailureCorrelationWindow → const Duration
How long two failures must land within to be ONE lane condition.
kLegacyCodeCircuit → const Circuit
The FROZEN legacy root shape — agent → review → land, the shape of kCodeCircuit before pow-6ao (git a67feb8~1). The migration target for a shape-1 survivor.
kLensStampInstruction → const String
The stamp instruction every lens prompt writes after its report template — the discovery twin of kVerdictStampInstruction. All THREE stamps are required and copied verbatim: sessionId proves the report is THIS session's (a re-minted session restarts its round counter at 0 under the SAME node paths, so the round stamp alone cannot see the re-mint), nodePath proves it is THIS node's (A4's foreign-node fence), and round proves it is THIS round's (A15(5) alt-A's round fence — a re-gather wave re-runs the lens in the SAME worktree under the SAME node path, so an earlier generation's report file is otherwise indistinguishable from this one's). A report carrying the wrong stamps, or missing ANY of them, is read as MISSING — never as a verdict: the route re-gathers the lane once and, at the cap, ADVANCES with the miss recorded LOUDLY (A21(3)).
kLensWorkingAgreement → const String
The READ-ONLY working agreement every lens rides (A37, and the gather lane's own doctrine: it reads, it CITES, it decides NOTHING). Rendered into the brief, and asserted VERBATIM in test: the one artifact a lens may write is its own report file.
kLlmRubrics → const List<String>
The three LLM critic rubric ids (each graded in isolation by a claude critic; anti-anchoring).
kManifestOmissionReserveBytes → const int
Bytes held back from kMaxManifestBytes for the omission lines themselves, so a section that truncates can always afford to SAY it truncated.
kMaxAnchors → const int
The bound on the anchors pulled out of one bead.
kMaxDecisionEntriesPerSurface → const int
The bound on the decision entries kept for ONE roster-qualified surface.
kMaxDecisionLensPromptBytes → const int
The bound on the ASSEMBLED explore-decision prompt, in UTF-8 BYTES (256 KiB).
kMaxDiscoverySnippetChars → const int
The bound on ONE piece of FOREIGN bounded evidence's rendered SNIPPET — a prior-art hit, an anchor's contents, a decision entry, a history record. The full text is always hashed; only the snippet is clipped, and a clip is RECORDED (EvidenceState.truncated) so bounded evidence can never masquerade as complete evidence.
kMaxHistoryCommits → const int
The bound on the git-history commits kept for one round.
kMaxLintExamples → const int
How many off-policy commit subjects the receipt names (the rest are counted, not listed).
kMaxManifestAreas → const int
How many AREAS (directories) the change-shape section names.
kMaxManifestBytes → const int
The manifest's hard ceiling, in UTF-8 BYTES (16 KiB).
kMaxManifestIntentChars → const int
The bead's acceptance INTENT the manifest carries, capped in characters.
kMaxManifestReceiptFields → const int
How many fields ONE circuit receipt contributes to its rendered line.
kMaxManifestReceiptValueChars → const int
The per-field value cap in a rendered receipt line.
kMaxManifestRecordChars → const int
ONE manifest record (a commit message, a file line), capped in characters.
kMaxNeighbors → const int
The bound on a resolved anchor's SURROUNDING PATTERN (its directory's other files) — enough to show the architect what the neighborhood looks like.
kMaxPriorArtHitsPerQuery → const int
The bound on the prior-art hits kept for ONE query.
kMaxPriorArtQueries → const int
The bound on the deterministic prior-art pull — each query is one read-only pass over every attached store.
kMaxRegatherRounds → const int
How many times the route re-gathers a lens whose report never arrived. ONE: a cheap model slips, a broken lane does not fix itself twice. Strictly below the engine's kMaxReworkRounds belt, so the asset's own policy fires first.
kMaxRespecRounds → const int
The max AUTO-respec rounds a spec may take before the route flares to a human (the bead's bound). Round 1 and round 2 auto-loop; a third fixable fail ESCALATES. Strictly below the engine's own kMaxReworkRounds (3) — the belt that gates a node whose derived generation reaches the cap — so the asset's cap always fires first, on its own policy.
kMaxSubjectChars → const int
The subject-line budget — the whole <type>[(scope)][!]: <description> line stays within it (git's own convention; a longer subject is truncated at a word boundary by sanitizeConventionalSubject and reported by lintConventionalSubject).
kMaxSummaryChars → const int
The human DIGEST the PR body leads with, capped — a model that answers with a whole essay (or a pasted diff) must not become the PR body. Truncation is the belt; the prompt asks for 2–5 sentences.
kMemoryDirHole → const String
The hole AgentEnvironment.memoryDirArgs renders the ABSOLUTE disc directory into.
kMetadataPathExtensions → const Set<String>
The file extensions a METADATA path may carry — prose and configuration, never source.
kMetadataPathFilenames → const Set<String>
The extension-less file NAMES a metadata path may carry.
kMidModelDefault → const String
The AgentTier.mid rung's asset-default model.
kMigrationCircuits → const Map<String, Circuit>
The registry entries the frozen shapes need, spread into buildCodeRegistry. Only the frozen SPEC circuits need registering — the legacy shape's code_review/landing sub-circuits are the CURRENT ones, unchanged by any reshape, and a ROOT circuit is passed to SessionScope directly rather than looked up by id.
kMountEligibilityReadDeadline → const Duration
Deadline over one fresh mount-eligibility read.
kMountEligibilityReadRetryBackoff → const Duration
How long a FAILED fresh mount-eligibility read stays cached before the next predicate evaluation reads again — the FIRST wait, doubled per consecutive failure of the SAME bead and saturating at _kMountEligibilityReadRetryCap.
kMountEligibilityReadTimeoutFlare → const String
Raised when a fresh mount-eligibility read dies on a deadline — either kMountEligibilityReadDeadline killing the whole read, or bd's own process deadline killing one call inside it (BdTimeoutException).
kNoGoverningDecisionPrefix → const String
The prefix a spec's ## ADR Alignment section is recognized by when the roster union was EMPTY for every queried surface.
kNoRoundCommitDiagnostic → const String
The build step's refusal when the agent returned and the round base is still this branch's HEAD.
kOrderingAndRollbackRubric → const String
The judge lane that reads the document as a MECHANISM: causal ordering, interlocks, restore order, breaker semantics, partial-failure rollback.
kOverlayTargetHeads → const List<String>
The harness target heads a materialized asset can land under — the whole territory the STALE scan reads when a caller scopes to nothing.
kOwnerArchitect → const String
The fix is derivable from the bead AS WRITTEN plus the tree — re-running specify with the critic's rationale can produce it. The auto-respec loop is exactly the right instrument.
kOwnerAuthor → const String
The fix needs a decision the bead TEXT does not make (which sibling's symbol names win, whether the scope splits, which of two designs is wanted, a policy call). No re-run of the architect can converge, however good it is — the receipt is pow-n6n.1, which drew a coherence D twice asking the architect to choose between its own names and pow-n6n.2's.
kPinDiffStep → const String
The diff-pinning pre-critic step id (bead pow-6wo) every critic lane dependsOn. PinDiffCapability computes the bead BRANCH'S OWN delta (git diff origin/<base>...HEAD) and pins it as the critics' review scope — and, when that delta is EMPTY, Escalates the whole round (a stale/no-op bead) so the critics never grade PRE-EXISTING mainline work as if it were the bead's diff (the live finding this step exists to close). Runs AFTER kClearCritiqueStep so its pinned-diff file survives that round's wipe.
kPrBodyRelPath → const String
The workspace-relative path the terminal route writes the composed PR body to, and the bound delivery method reads it back from. A worktree ledger, exactly like the respec ledger and the discovery dossier: it keeps kilobytes of prose OUT of the session bead's metadata (a terminal Advance payload is persisted under grid.result.<nodePath>.*) while still crossing the value-only DeliveryRequest seam.
kPreStampAdvisoryBranch → const String
The bead-under-advisory's inert workspace branch fields.
kPreStampAdvisoryNodePath → const String
The node path a pre-stamp lens prompt is stamped with.
kPreStampAdvisoryRound → const int
The round a pre-stamp run gathers and judges its FIRST pass at.
kPreStampAdvisorySessionId → const String
The session id a pre-stamp lens prompt is stamped with — see kPreStampAdvisoryNodePath; there is no session either.
kPriorArtLens → const String
The PRIOR-ART lens — what has already been done, decided, or attempted here.
kProvenanceMarker → const String
The substring every stamped file carries — the detection AND strip key.
kReadinessGradeKey → const String
Metadata key: the bead-readiness letter the PRE-STAMP ADVISORY graded this filing, written only on a stamp whose advisory RAN and passed.
kReadinessOption → const String
The --readiness option every filing verb carries, and its stable wire values.
kReadinessRouteStep → const String
The readiness decision point's step id (zero agents).
kReadinessRubric → const String
The readiness lane's rubric id (extension/rubrics/bead-readiness.md).
kReadinessRun → const String
The --readiness wire value that RUNS the advisory.
kReadinessSkip → const String
The --readiness wire value that WAIVES it.
kReadinessSkippedKey → const String
Metadata key: true when the advisory was WAIVED on this stamp.
kReadinessStep → const String
The cheap judgement lane's step id (ONE agent).
kRelayFlaresReadTool → const String
The read tool naming the tail of the session's observability flares.
kRelayGatesReadTool → const String
The read tool naming the session's open gate, if it is parked at one.
kRelayTelemetryReadTool → const String
The read tool naming the session's captured usage telemetry records.
kRelayToolAllowList → const Set<String>
The EXACT tool set a relay may reach — four read-only inspections and the one verdict write. A RelayAgentEnvironment.tools that is not equal to this set is refused by RelayReadTools.inspect before any reader runs.
kRelayVerdictWriteTool → const String
The ONE write a relay owns: its own verdict. It writes no session, no horizon, no flare, no bead — the verdict is the return value, and the engine persists whatever follows from it.
kRelayWorktreeReadTool → const String
The read tool naming a session's worktree evidence — its per-path modified times and its last commit. The governor disc's dead-session lesson: worktree mtimes are the signal that separates a long build from a stopped one.
kReleaseCircuit → const Circuit
The RELEASE circuit (id release) — a strictly linear gated pipeline whose always-1-wide frontier is the whole point: each leg's verdict gates the next, and the irreversible one is last but two.
kReleaseGateCapabilityId → const String
The capability id every DETERMINISTIC release leg resolves through — one capability, ten legs, selected by the step's operation param.
kReleasePromotionRouteCapabilityId → const String
The capability id of the human-promotion route — the only decision point in the release graph, and the only step that can HALT it short of a refusal.
kReleaseReceiptKey → const String
The result-payload key every release node writes its canonical JSON receipt under (grid.result.<nodePath>.release). One key, one object, so a downstream leg parses exactly one thing.
kRespecSpecDir → const String
The workspace-relative directory the respec guidance ledger lives in — deliberately NOT under .grid/critique/ (which ClearCritiqueCapability wipes at the start of every committee round; the ledger must outlive that wipe — though never the session: IntakeCapability resets it).
kRevalidateReasonTailChars → const int
The tail budget for a captured harness/tool log a failure reason carries (bead pow-gy41). Wide enough to hold a whole dart test failure block — the failing test's name, its expected/actual, and the Some tests failed. trailer — and well inside the gate bead's metadata budget.
kReviewStepId → const String
The root circuit's review step id — the SubCircuitStep whose circuitId withReviewCircuitId re-points. A LITERAL: it is a persisted cursor key.
kRosterSurfacePlaceholder → const String
The path placeholder a PRE-SPECIFY brief shows: the architect has not written ## Touches yet, so there is no real surface to qualify.
kRoundCommitUnreadableDiagnostic → const String
The build step's refusal when the round's commit count could not be READ.
kRouteCancelled → const RouteFailure
The cancellation unwind — a route that observes StepArgs.cancel set after an async gap throws this. RouteAllocation drops it silently (it checks the token before sinking), so it can never record a stale terminal.
kRulingAdherenceRubric → const String
The judge lane that holds the document to every RULING the bead names — each one honoured, each one cited by its entry sentence.
kRunnerArg → const String
The hole naming the VERB invocation — the name a seat or operator calls.
kSeatArchiveRetention → const int
How many .archive/<stamp>/ directories one disc KEEPS. Every succession prunes what falls outside it (Nico, 2026-09-13).
kSeatArchiveSubdirectory → const String
The disc-local directory a LOCAL archive is written under — the sink for a disc git IGNORES.
kSeatEnvironmentVariable → const String
The process env var naming the seat a session occupies. Set by the launcher; ABSENT means a bare harness session, which is NOT a seat and writes no disc.
kSeatHole → const String
The hole a seat-scoped declaration renders the SEAT NAME into (AgentEnvironment.roleAsset, AgentEnvironment.roleArgs).
kSeatMemoryFileName → const String
The disc's INDEX — the one file loaded wholesale at session start, and the only thing that makes any other note on the disc findable (the_grid#agent-disc-file-shape-and-home: "one pointer line per file").
kSeatsSubdirectory → const String
The grid-home-relative home of every operator seat's disc.
kSectionStructureRubric → const String
The lane that requires the sections the bead NAMES (kDocsSectionsKey).
kSelectorGrammar → const String
The closed selector grammar, rendered for a refusal message.
kSemanticHitLimitPerStore → const int
kSessionStartHookEvent → const String
The hook event this verb answers when a payload names none.
kShowOutputCapBytes → const int
The pack-wide output cap under this verb's original name.
kSiteBindingFile → const String
The conventional machine-local site-binding file, under the already-gitignored .grid/ (never committed — the endpoint never enters version control). Named in refusals so "the fix" points at a real path; WHERE the composition root reads it from is its call (bead pow-ebf.5) — this only names the convention.
kSiteBindingVersion → const int
This pack's site-binding wire version (pre-1.0: a bump is breaking). A document written by any other version REFUSES rather than mis-parsing (the envelope precedent — fail closed on a shape you do not own).
kSpecCommitteeRubrics → const List<String>
Every spec-committee rubric id, in declaration order (the gating lane first) — the spec-side mirror of kCommitteeRubrics.
kSpecContractLaneOverlap → const List<LaneOverlap>
The overlap table: for every SpecContractRule, the judgement lane that already asks for the same thing in prose, or '' where the rule is structure NO lane states.
kSpecContractSemanticResidue → const List<SemanticResidue>
What stays INFERENCE after the record grammar lands.
kSpecContractShadowReport → const String
The generated report's path, relative to the package root.
kSpecCorpusDir → const String
The directory, relative to the package root, holding the retained corpus.
kSpecExemplarAcceptance → const String
A structurally WHOLE spec — the acceptance half of the exemplar the specify brief ships. Round-tripped through specStructuralFindings in test: what the architect is told to copy is PROVEN to pass the gate that grades it.
kSpecGatingRubric → const String
The spec committee's gating rubric id — a deterministic structural check whose grade F is a hard block, decided by the route's matrix (the spec-side mirror of kGatingRubric).
kSpecHeadCodeCircuit → const Circuit
The FROZEN spec-head root shape (pow-6ao, git a67feb8) — specify → spec_review → agent → review → land, with specify a step of the ROOT circuit (cursor key <bead>/specify). The migration target for a shape-2 survivor.
kSpecHeadSpecReviewCircuit → const Circuit
The FROZEN pre-fold spec circuit (git a67feb8) — clear-critique → the gating lane + four LLM critics in parallel → route. specify is NOT in it: under shape 2 the architect ran at the ROOT circuit's <bead>/specify.
kSpecHeadSpecReviewCircuitId → const String
The registry id of kSpecHeadSpecReviewCircuit — the FROZEN pre-fold spec circuit. Deliberately NOT spec_review (that id now resolves to the CURRENT circuit, which CONTAINS specify).
kSpecifyStep → const String
The specify step id — the step the RESPEC arm invalidates, and the step kSpecReviewCircuit authors at its head (bead pow-ui8). ONE definition, so the declared validates target and the circuit's step can never drift: a dangling target mints NO edge at all, so a drift would silently disarm the whole auto-respec loop.
kSpecLlmRubrics → const List<String>
The four LLM spec-critic rubric ids (each graded in isolation by a harness critic; anti-anchoring) — the spec-readiness pack's judgement lanes.
kSpecPlaceholderTokens → const List<String>
The placeholder tokens that anchor an automatic structural F — a spec that defers its own content is not implementation-ready.
kSpecReviewCircuit → const Circuit
The spec-readiness committee circuit (id spec_review) — the READINESS LADDER (bead pow-q7n: intake → readiness → readiness-route, the cheap pre-specify lens) → SPECIFY (the architect harness ride) → a hygiene step (ClearCritiqueCapability, shared with the code committee so a round's verdict files are always round-fresh) → the deterministic gating lane + four LLM critics fanned out in parallel → a route join running the SPEC matrix (SpecRouteCapability, bead pow-7nm) — advance | AUTO-RESPEC | escalate — over the spec grades.
kSpecSeatPolicyId → const String
The SPEC seat's audit id - kBuildSeatPolicyId's counterpart.
kStateRootHelp → const String
The ONE help line every verb prints for kStateRootOption.
kStateRootOption → const String
The ONE --state-root option name the verbs that REACH the grid home's state store expose — park, show and mount.
kStationAssetRegistryGeneratedMarker → const String
The provenance marker carried by every generated station registrant.
kStationOverlaySourceHead → const String
The vended-tree prefix EVERY station-overlay artifact is declared under.
kStationStorePath → const String
Where the station selector points — the grid's own state store.
kStepFieldLabels → const List<String>
The labeled lines every implementation step carries, in brief order.
kStepRecordForm → const String
The implementation-step record form. The ordinal-LIST openers already accepted (1. … / 1) … / **Step 1:** …) still parse as steps; this is the shape the brief TEACHES, because a step carrying a fenced block must take it.
kTelemetryDir → const String
The workspace-relative directory each step's usage telemetry lands in (sibling of the committee's .grid/critique).
kTerminologyBanRubric → const String
The lane that refuses the banned seam word (the org rule: the seam word is extension, and the other one is reserved for third-party proper nouns).
kTierDefaultCommand → const String
The environment defaultModelForTier's names belong to. The claude builtin (command == kTierDefaultCommand) rides the shared tier defaults with no per-environment model; every OTHER environment armed to a role must pin its own native model — enforced LOUD at boot by EnvironmentRegistry.validate (bead pow-a9o). Mirrors the claude builtin's command (agent_harness.dart), kept HERE beside the defaults it gates to avoid a model_tier -> agent_harness import cycle.
kTouchRecordForm → const String
The ## Touches record form — one repo-relative backticked path, one disposition, then the symbols the item adds or exposes.
kUnknownSourceRef → const String
The source ref recorded when the overlay's checkout cannot be probed (the package came from pub, or git is absent). Never a throw: an un-probable ref is not a packaging bug.
kUnknownSubstationPrefix → const String
The substation prefix used when a bead names no substation (metadata['rig'] absent) — the literal placeholder the agent substitutes with its own repository name.
kUnresolvedLegacyCitationFrom → const String
What separates the reported ALIAS from its provenance in that same line.
kUnresolvedLegacyCitationPrefix → const String
How the non-failing report of an unresolved LEGACY citation OPENS.
kUsageApiErrorHeadChars → const int
The character budget UsageReport.apiErrorReason spends on the harness's own error message. Wide enough for the measured Prompt is too long, the request is about 202302 tokens… sentence, narrow enough that a reason this PREFIXES still leads the engine's 500-char persisted slice with the diagnosis rather than with the log it explains.
kUsageModelPrices → const ModelPriceTable
The station's declared prices — read ONLY when a harness reports tokens but no billed cost.
kUsagePriceUnknownFlare → const String
Raised when a run reports tokens under a NAMED model the declared ModelPriceTable has no row for: the tokens are still recorded, the cost stays null, and the flare names the model so an operator adds the price (guards LOUD or GONE — the alternative, a silent $0 lane, is the exact invisibility this bead exists to end).
kValidatesParamKey → const String
The engine's DECLARATIVE params key naming a backward-motion edge (the_grid molecule_schema.dart's kValidatesParam): a step whose params[kValidatesParamKey] names a SIBLING step id of its OWN circuit gets that edge minted when the molecule is instantiated, and the engine's derivation invalidates the named target ∪ its transitive dependents ∪ the source itself whenever the SOURCE reaches a positive terminal carrying a recorded grade of F.
kValidationDeadline → const Duration
The Validation Plan's absolute-from-start deadline (the_grid audit §4, tg-uad follow-through): a plan is sh running a deterministic script, minutes-scale by definition — never the multi-hour agentic build/critic lanes — so it must NOT ride a runtime provider's 2-hour default watchdog. Ten minutes bounds every validation-latched variant of the lane without crowding a legitimately slow (but still deterministic) plan.
kValidationDiagnosticHeadChars → const int
The character budget the leading VALIDATION DIAGNOSTICS may take out of kRevalidateReasonTailChars. Wide enough for the two-line Failed to load + file:line:col: Error: <symbol> pair the Dart front end prints, narrow enough that the exit-class and log-path line still lands inside the engine's 500-char persisted prefix.
kValidationRecordForm → const String
The ## Validation Plan record form — the restatement is optional; the id is what carries the mapping.
kVerdictArtifactAbsent → const String
No current-round artifact exists at the canonical path at all.
kVerdictModelRoundKey → const String
The verdict JSON's MODEL-AUTHORED round stamp key.
kVerdictNodePathMismatch → const String
A4's FOREIGN-NODE fence refused the artifact: its nodePath stamp names a step other than the one reading it (a stray or mis-keyed write).
kVerdictOwnerInstruction → const String
The OWNER instruction the SPEC critic prompt writes after kVerdictStampInstruction (bead pow-hxme). Only the family that is TAUGHT ownership is HELD to it (CriticCapability.requiresVerdictOwner).
kVerdictOwnerKey → const String
The verdict JSON key naming WHO can fix an actionable (D/E) grade — bead pow-hxme, ADR-0000 A37. Not a freshness stamp (A4 and A15(5) alt-A fence the nodePath + round): a PAYLOAD column the SPEC route's matrix decides on.
kVerdictOwners → const List<String>
The closed owner vocabulary. A verdict naming anything else is refused by the ONE decoder — LOUD, never coerced.
kVerdictRefinementInstruction → const String
The REFINEMENT instruction the SPEC critic prompt writes after kVerdictOwnerInstruction (bead pow-bhm).
kVerdictRefinementKey → const String
The verdict JSON key carrying a lane's NON-GRADING observations about the BEAD GRAPH — bead pow-bhm's COHERENCE SCOPE dial (policy Nico-ratified 2026-07-18, interactive session: "Tracker state is never the spec author's defect").
kVerdictRoundKey → const String
The verdict JSON's ROUND stamp key (A15(5) alt-A) — ONE name, written by every critic prompt (verdictJsonTemplate) and read by the verdict parser, so the writer and reader can never drift apart.
kVerdictRoundPinMismatch → const String
A15(5) alt-A's ROUND fence refused the artifact: its round stamp names an EARLIER round than the one reading it (a file that survived a rework on the reused worktree).
kVerdictShapeCheckFailed → const String
The strict decoder refused the artifact's SHAPE — the detail that follows is the parser's own.
kVerdictStampInstruction → const String
The stamp instruction that follows verdictJsonTemplate in every critic prompt: both stamps are REQUIRED and copied verbatim. LOUD about the consequence — a verdict carrying the wrong stamps is discarded as stale, and a verdict missing either stamp is discarded as an unverifiable transport defect so the lane fails and re-runs.
kWorktreeOverlaySubtrees → const List<String>
Subtrees materialized into an agent worktree — one per harness SKILL tree, and nothing else: each is a set of <id>/ asset dirs, which is what keeps the per-asset-dir git fence able to cover every path the leg writes.

Properties

kDecisionLookupRule → String
The DEFAULT-runner rendering of decisionLookupRule — the form a caller that composes no station verb (a fence, a parse test) reads.
final
kFailedDecisionLookupSentence → String
The DEFAULT-runner rendering of failedDecisionLookupSentence.
final
kNoGoverningDecisionSentence → String
The DEFAULT-runner rendering of noGoverningDecisionSentence.
final
kSpecExemplarDesign → String
The DEFAULT-runner rendering of specExemplarDesign — the exemplar the structural round-trip fence grades.
final
kSpecStructuralContract → String
The DEFAULT-runner rendering of specStructuralContract.
final
vendedSkillIds → List<String>
The skill ids this package vends, sorted.
no setter

Functions

absolutePathReferences(Bead bead) → List<BeadTextSlice>
Every ABSOLUTE file anchor bead's work fields carry, in field order then field-local offset order.
acpEffortSuffix(AgentTier tier) → String
The effort suffix tier requires.
acpModelRefusal({required String want, required List<String> available, required AgentTier tier}) → String
The refusal a null resolveAcpModelId earns: the pin, the rung that asked for it, the variant that rung requires, and what the agent actually offered — the efforts it has for that base first, then the whole catalog.
acpOfferedOutcomes(List<PermissionOption> options) → List<AgentPermissionOutcome>
Projects the KINDS an ACP request offers, dropping its option ids and its human-facing labels — the station decides on shape, never on prose.
acpPermissionCapability(ToolKind? kind) → AgentPermissionCapability
Normalizes an ACP tool kind onto the grid's permission vocabulary.
addedLinesByFile(String diff) → Map<String, List<String>>
The ADDED lines of each file in a unified diff, keyed by repo-relative path — the ONLY text the mechanical lanes grade. This is the scope-pinning doctrine one level down (ADR-0000 A9): grade the bead's OWN delta, never the ambient worktree, so a pre-existing offence in an untouched paragraph is not this bead's finding.
addReadinessOption(ArgParser parser) → void
Declares --readiness=run|skip on parser — one declaration, so filing, approve and unpark cannot offer three spellings of one waiver.
addStateRootOption(ArgParser parser) → void
Registers kStateRootOption on parser — the seam every verb rides so the option name and its help cannot drift apart between them.
agentProcessEnvironment({required AgentEnvironment environment, Uri? endpoint}) → Map<String, String>
The env a resolved target layers over its site endpoint (the _targetEnv successor — ADR-0002 D3: the URL is a MACHINE FACT the site binding supplies, never in code/argv/bead). Provider-managed needs nothing; an endpoint-needing target with a null endpoint injects nothing (the LOUD refusal for an unbound fact is SiteBinding.endpointFor's at the spawn edge, not this pure fold). Exhaustive switch (house style).
ambientAssetFactsOrFlare(TreeContext context, {required String consumer, SubstationKey? aspect}) → ({SubstationFactsSnapshot snapshot, SubstationKey substation})?
The ambient pair a consumer needs to run resolveGridAssets — or null, having raised kAssetFactsUnavailableFlare EXACTLY once, when the station has not mounted SubstationFactsAssets (and, at an effect, a SubstationScope) yet.
anchorsPath(String workspaceDir) → String
The deterministic gather's output — read back by every lens prompt and by the route.
assembleDiscoveryLensPrompt({required String lens, required String sessionId, required String nodePath, required int round, required String workspaceDir, required DiscoveryEvidenceProjection projection, LensResultTransport transport = const LensArtifactTransport()}) → DiscoveryLensPromptAssembly
ONE assembled lens prompt and whether its evidence bundle was CLIPPED — the SHARED assembly both the in-pipeline lens lane (DiscoveryLensCapability) and the filing verbs' pre-stamp advisory ride.
assetFieldName(AssetKey key) → String
The generated field name for key — <kind><PascalCaseId>.
availableEnvironmentsOf(TreeContext context) → AvailableEnvironments
The ambient presence set: the mounted AvailableEnvironments, or - until the availability seed (bead pow-n6n.3) mounts one - the ambient EnvironmentRegistry's boot-validated members, falling back to the station builtins exactly as every spawn site already does (readiness.dart:372, code_capabilities.dart:235).
baseAcpModelId(String id) → String
Removes a codex-acp reasoning-effort suffix from id.
baseTreeFiles({required GitRunner runner, required String workspaceDir, required String baseRef}) → Future<Set<String>>
The repo-relative paths tracked at baseRef — the pinned base's own file list, read once with git ls-tree -r --name-only <baseRef> in workspaceDir.
beadAnchors(Bead bead) → ({List<String> paths, bool pathsTruncated, List<String> symbols, bool symbolsTruncated})
The PATH + SYMBOL anchors bead names — the round's ONLY tree-intake pass. Pure, deterministic (first-appearance order), bounded (kMaxAnchors), and exposed for unit tests.
beadFieldValue(Bead bead, BeadCitationField field) → String
Returns the live value of field on bead.
beadIdPrefixOf(String id) → String
The store PREFIX of id — the text before its first hyphen.
beadIdReferences(Bead bead, {required Set<String> prefixes, Map<String, Set<String>> catalogs = const {}}) → List<BeadTextSlice>
Every BEAD-ID-shaped token bead's work fields carry under one of prefixes, in field order then field-local offset order.
beadTextOf(Bead bead, BeadTextField field) → String
field's text on bead — the one place a field name resolves to a value.
beadUnderIntake(Bead bead) → String
Renders the work bead into the readiness prompt — the same title/task/design/ acceptance/notes rendering the committees embed, re-labeled so the lens knows the BEAD is the artifact under review (not a spec, not a diff).
boundDiscoveryEvidence({required String kind, required String subject, required String source, required String fullText, EvidenceState? state, String error = '', bool truncateSnippet = true}) → BoundedEvidence
Bounds fullText into one BoundedEvidence record: hashes the COMPLETE text, clips the snippet at kMaxDiscoverySnippetChars, and derives the state (EvidenceState.truncated on a clip) unless state forces one.
boundedBeadFields(Bead bead) → List<BeadFieldEvidence>
The bead's own fields, resolved ONCE — the intake block every lens used to re-render from the live bead.
boundedMountExplanation(MountExplanationReport report) → MountExplanationReport
report rendered down to kBoundedOutputCapBytes in BOTH renderings.
boundedOutput<T>({required T complete, required int maximumTrimBudget, required String renderPlain(T value), required String renderJson(T value), required T trim(int budget)}) → T
complete when both of its renderings already fit kBoundedOutputCapBytes, and otherwise the largest trim candidate that does.
boundedValidationDiagnosticHead(List<String> diagnostics, [int max = kValidationDiagnosticHeadChars]) → String
diagnostics joined and cut to max, marked with a trailing … when cut — the unabridged lines stay in the log on disk.
buildAgentBrief(Bead bead, Workspace workspace, {String trailerToken = kDefaultTrailerToken, List<String> skills = const [], FixInFlight? fixInFlight}) → AgentBrief
Assembles the agent's full-bead brief + local-first working agreement (the live dogfood contract — exposed for unit tests). The agreement closes with the D-H genesis_tree doctrine (ADR-0008; companion to the_grid GridDelegate D-H fix): watch deps / no sync accessor over StateNotifier state / config = values, impls = DI / guards LOUD or GONE — every coding agent this station spawns carries it. Model/params are AgentConfig, NOT brief (OQ-a) — one brief replays across harnesses. One-turn completion is OBSERVED via process exit; channel completion is OBSERVED in the adapter's structured protocol event — the agent never DECLARES a grid cursor transition (tg-p9q).
buildBuiltinEnvironmentRegistry() → EnvironmentRegistry
The station-default environment registry — the five builtins as builtins, no custom authoring (a station/substation adds custom at its HarnessProvider). The station-default arming (bead pow-ebf.3 reserved EnvironmentRegistry.builtins for exactly this).
buildCircuitReceipt({required String beadId, required SiblingView siblings, List<String> preexisting = const [], String? baseEvidenceNote}) → String
Assembles the landing circuit's OWN PR-body provenance section (tg-rm5): the rebase/revalidate outcomes, read via the ambient SiblingView at beadId's absolute node paths. The code-review committee's grade line MOVED to PrSection.committeeGrades and the description/commit-policy provenance lines are appended by that section's renderer (pr_composition.dart, bead pow-8dx) — this receipt now carries ONLY what the landing circuit itself did. Pure + deterministic (no I/O) so it is unit-testable in isolation.
buildCodeRegistry({DateTime clock()?, RubricSource? rubrics, String? devRoot, GitRunner? gitRunner, ShellRunner? shellRunner, DartFormatService? dartFormatService, DirectoryClearer? critiqueDirClearer, InferenceRunner? inference, AnchorResolver? anchorResolver, PriorArtSource? priorArt, DecisionIndexSource? discoveryDecisions, HistorySource? discoveryHistory, BdRunner specifyBdRunnerFor(String workspaceRoot)?, SpecifyAuthoredSpecWriter? writeSpecifyAuthoredSpec, GridAssetRegistry? assetRegistry, GridAssetRosterOverride? assetRosterOverride, InferenceRunner? committeeClassifier, CommitteeSelectionStore? committeeSelectionStore, ReleaseCommandInvoker? releaseCommands, String? overlaySourceRef, String? validationHost, Map<String, String> overlayArgs = const {}, AgentSessionAdapterRegistry sessionAdapters = kBuiltinAgentSessionAdapters, AgentSteerSource steers = const NoAgentSteerSource()}) → DefaultCapabilityRegistry
Builds the code registry: the SPEC-READINESS INTAKE LENS (intake/readiness/readiness-route, bead pow-q7n — the cheap pre-specify ladder that HOLDS a bead that is not ready to specify) + the specify stage + spec-readiness committee (specify/spec-critic/spec-validation + the spec_review circuit, bead pow-6ao) + the agent/land capabilities + the adversarial committee (critic/route + the code_review circuit) + the landing circuit (rebase/revalidate + the landing circuit, tg-rm5), with an optional injected clock (the backoff seam). The composer provides it as a stable InheritedSeed<CapabilityRegistry> above Station, alongside a CircuitResolver((_) => kCodeCircuit). The spec critics share rubrics with the code critics — ONE RubricSource serves both committees (the loader resolves any extension/rubrics/<id>.md by id).
buildCodeReviewSelectionEvidence({required String workBeadId, required DiscoveryAnchors? anchors, required DiscoveryDossier? dossier, required String? pinnedDiff}) → CommitteeSelectionEvidence
The code_review evidence — the same discovery facts PLUS the actual pinned diff: the complete file's digest and its changed target paths.
buildCommitteeClassifierPrompt({required CommitteeSelectionEvidence evidence, required List<String> allowedRubricIds, int maxChangedPaths = 40}) → String
The prompt ONE unknown-shape classifier call receives.
buildCommitteeShadowReceipt({required CommitteeSelectionRun run, required CommitteeRouteObservation route, required List<CommitteeLaneReceipt> lanes, Iterable<String> missingFields = const [], bool truncated = false}) → CommitteeShadowReceipt
Assembles ONE receipt from already-observed facts — PURE: no filesystem, no inference, no tree.
buildComputeLeaseCommand() → LeaseCommand
Builds the COMPUTE asset's lessee command and payload/result codecs.
buildComputeServeCommand({required List<String> allow}) → ServeCommand
Builds the COMPUTE asset's bounded lessor command.
buildDescribeManifest(DescribeManifest facts) → String
Renders facts as the manifest text — the SOLE model input of the describe pass. Stable section order, counts before optional detail, truncation only at a record boundary, at most kMaxManifestBytes UTF-8 bytes.
buildDescribePrompt({required String beadId, required String manifest, String trailerToken = kDefaultTrailerToken}) → String
The ONE-SHOT describe prompt — a pure text→JSON completion with NO tool use over a BOUNDED, DETERMINISTIC buildDescribeManifest rendering of the branch's facts.
buildDesignVerifyPrompt({required Bead bead, required Map<String, String> documents, required List<DesignFinding> findings, required int round}) → String
The verifier's brief — bounded, self-contained, and explicit that a judgment is EVIDENCE and never fact.
buildRelayBrief(RelayAgentEnvironment seat, RelaySessionSnapshot snapshot) → AgentBrief
The relay's BRIEF: the protective-relay mission, the exact tool surface, the whole evidence snapshot, and the answer contract.
buildSpecifyBrief(Bead bead, Workspace workspace, {RespecLedger? guidance, DiscoveryDossier? dossier, String runner = kDefaultOverlayRunner, String? gridHome}) → AgentBrief
Assembles the specify agent's full-bead brief + the spec-writing working agreement (exposed for unit tests). Mirrors buildAgentBrief's shape — the full bead renders first (A36), the agreement carries the stage policy — but the contract is the ARCHITECT's, not the builder's: write the spec into the bead, verify it against the live tree, touch no code.
buildSpecReviewSelectionEvidence({required String workBeadId, required DiscoveryAnchors? anchors, required DiscoveryDossier? dossier}) → CommitteeSelectionEvidence
The spec_review evidence — the round-stamped discovery facts, with NO diff.
canonicalCommitteeJson(Object? value) → String
value as canonical JSON: every map's keys sorted, recursively, so two structurally equal facts always render the same bytes.
capturedOutputReason({required String verb, required String adapter, required String output, int? exitCode, String? diagnostic, int max = kRevalidateReasonTailChars}) → String
One failure reason in the station's captured-output SHAPE: '<verb> failed (exit N) [<adapter>]: <diagnostic — ><tail>'.
changedFilesFrom({required String nameStatus, required String numstat}) → List<ChangedFile>
Parses git diff --name-status -z joined with git diff --numstat -z into ONE path-sorted list of facts.
changedFilesIn(String diff) → Set<String>
Every repo-relative path a unified diff touches.
changeShapeOf(Bead bead) → ChangeShape
The bead's DECLARED change shape — ChangeShape.design iff its ## Touches section cites at least one path and EVERY cited path is a design path (isDesignPath); ChangeShape.docs iff every cited path is a docs path; ChangeShape.metadata iff every cited path is a METADATA path (isMetadataPath) but not every one is prose (a CHANGELOG.md beside a pubspec.yaml — the pow-x6k receipt).
citationFindings({required Map<String, List<String>> addedLines, required bool exists(String repoRelativePath)}) → List<String>
Findings for kCitationPathsRubric: every path an ADDED doc line cites must resolve — relative to the repo root, or to the citing doc's own directory (a markdown link is doc-relative). exists is the injected probe (tests pass a pure set membership — Fakes, not mocks).
citedDecisionRegisters(Bead bead) → Set<String>
Every REGISTER half a canonical citation in bead's prose names, lowercased — asked BEFORE any index has answered, so a caller can tell whether it must widen its lookup to a register this surface never mentioned.
citedPaths(String markdown) → List<String>
Every repo-relative path CITED in markdown, sorted and de-duplicated.
citesDecisionToken(String haystack, String needle) → bool
Whether needle occurs in haystack as a WHOLE token — never as the head or the tail of a longer one, so A2 can never claim the entry a bead cited as A25.
classifyCodeShape({required String beadId, required CircuitCursor cursor}) → CodeCircuitShape
Classifies the shape cursor was minted under, for the session of beadId.
clearDirectory(String dir) → void
The real DirectoryClearer: deletes dir (if present) and recreates it empty. Public so every hygiene step that wipes the critique dir shares ONE implementation (tests inject a no-op instead).
clearDiscoveryRegatherLedger(String workspaceDir) → void
Deletes the regather ledger at workspaceDir — called on a DiscoveryAdvance so a LATER rework round can never re-inject a stale round count into a fresh gather. Best-effort: a delete that fails never gates an otherwise-clean advance.
clearFixInFlight(String workspaceDir) → void
Deletes the carry at workspaceDir — every exit that does NOT advance with a finding, plus IntakeCapability's session-head hygiene. Best-effort: a delete that fails never gates an otherwise-passing spec.
clearRefinementFlag(String workspaceDir) → void
Deletes the flag at workspaceDir — a round with no notes, plus IntakeCapability's session-head hygiene. Best-effort.
clearRespecLedger(String workspaceDir) → void
Deletes the ledger at workspaceDir — called on EVERY terminal verdict that hands the bead on: an ADVANCE (the spec is ready) and an ESCALATE (a human now rules). Both exits SPEND the counter, so a LATER rework round can never re-inject a stale spec correction into a fresh specify brief, and a re-armed route after a gate resolve can never re-flare off a consumed round. ALSO called by IntakeCapability at the head of every session (bead pow-96s): the counter is SESSION-scoped — a fresh session over a reused worktree starts at round zero rather than inheriting a prior session's rounds. Best-effort: a delete that fails never gates an otherwise-passing spec.
codedRosterOf(GridDelegate factory(), {GridConfiguration configuration = const sdk.GridConfiguration()}) → List<SubstationScope>
Enumerates the coded substation roster authored by a fresh delegate from factory, then disposes that owned delegate.
commandDecisionIndexSource(ShellRunner runner, {String? runnerInvocation, String? gridHome}) → DecisionIndexSource
The SHELL fallback DecisionIndexSource: the composing station's ROSTER-MODE decisions index --surface <repo>/<path> verb, run through the pack's existing ShellRunner seam once per deduplicated surface inside ONE batch call.
commandOnPath(String command) → Future<bool>
Whether command resolves to a file on this box: a path as written when it carries a separator, else each PATH entry in order.
committeeChangedPathsIn(String diff) → List<String>
The changed TARGET paths a unified diff names, normalized, deduplicated and sorted. Only diff --git a/<path> b/<path> headers are read — never a hunk.
committeeCsv(String? raw) → List<String>
The non-blank, trimmed members of a CSV step param, in order.
committeeDigest(Object? value) → String
The SHA-256 of value's canonical JSON — the one digest function every identity in this library is derived with.
committeeGateDispositionFor({required bool adverse, required String routeType, String? transport}) → GateDisposition?
The gate disposition ONE adverse lane earned under routeType.
committeeJoinId({required CommitteeStage stage, required String workBeadId, required int round, required String routeParentPath}) → String
The stable JOIN identity a downstream fold groups samples by.
committeeRouteObservationOf(RouteVerdict verdict, {required String nodePath}) → CommitteeRouteObservation
The route verdict as an observation at nodePath.
committeeRouteTypeOf(RouteVerdict verdict) → String
The route verdict's wire type — an exhaustive switch over the engine's sealed verdict, so a new arm cannot be recorded as an old one.
committeeSampleId({required String policyVersion, required CommitteeStage stage, required String workBeadId, required int round, required String evidenceDigest}) → String
The stable SAMPLE identity for one selection.
committeeSelectionParentPath(String nodePath) → String
The parent node path of nodePath (a/b/route → a/b) — how a join step derives its sibling lane paths.
committeeSelectionResultProjection(CommitteeSelectionRun run) → Map<String, String>
run's evidence packet as the step-result entries the engine appends durably beside the step transition — the copy that OUTLIVES the per-round worktree the store's own artifact is reaped with.
committeeSelectionRound(StepArgs args) → int
The engine-injected circuit round for this step, fail-safe to 0.
committeeSelectionRunPath(String workspaceDir, CommitteeStage stage) → String
The workspace path one stage's selection run is persisted at.
committeeShadowReceiptPath(String workspaceDir, String sampleId) → String
The workspace path one shadow receipt is persisted at.
committeeShadowResultProjection(CommitteeShadowReceipt receipt) → Map<String, String>
receipt's evidence packet as the RESERVED committeeShadow* step-result entries a shadowed advance carries — the durable half of the receipt the worktree file is reaped with.
committeeUsageAccounting({required Iterable<CommitteeLaneReceipt> lanes, Iterable<CommitteeClassifierAttempt> attempts = const []}) → CommitteeUsageAccounting
Folds lanes and attempts into ONE accounting block.
composeCommitMessage({required ConventionalSubject subject, String body = '', String breakingChange = '', Map<String, String> trailers = const {}}) → String
A full commit/PR MESSAGE: the subject, an optional body, then the FOOTERS — the BREAKING CHANGE: entry (when breakingChange is non-blank) and the git trailers (Token: value) — each block separated by ONE blank line, footers LAST. This is the only shape the asset emits, and the shape the build-agent brief teaches.
composePrimeContext({required String bdContext, PrimeHandoff? handoff, String? handoffDiagnostic}) → String
The additionalContext this verb emits: bdContext VERBATIM, plus — only when handoff is non-null — its PrimeHandoff.namingLine, an optional handoffDiagnostic line, and the handoff BODY. PURE.
computeDispatchHandler({required ComputeBounds bounds, ComputeSpawn? spawn, CommandExecutor? executor, ProcessGroupController? groups, void onLog(String)?}) → DispatchHandler
Adapts the COMPUTE domain's BOUNDED "use" onto the federation's kind-agnostic DispatchHandler (the lessor-side glue — moved out of the federation core at the M6 Track D split). Decodes a DispatchCommand, runs it through a BoundedCommandExecutor (allow-list + timeout + reap over bounds), encodes the CommandResult. A refused (out-of-bounds) command surfaces as a non-zero CommandResult (exit 126 = "command refused") so the lessee gets a clean result rather than an opaque transport error — the lessor never runs it.
computeHasCapacity({required String kind, required int available}) → bool
The COMPUTE domain's declare-and-check CAPACITY PREDICATE (ADR-0011 D3 — the capacity predicate is domain-owned, not engine code).
conventionalTypeFor(IssueType issueType) → String
The conventional-commit TYPE a bead's issueType derives — the FALLBACK title's type ONLY (the inference picks its own type from the DIFF, which is the whole point of the directive). IssueType is an OPEN set (an extension type over the wire string), so an unknown type falls back to chore rather than throwing.
criticIncarnationPath(String workspaceDir, String rubric) → String
The incarnation marker for rubric under workspaceDir: the file whose mtime IS this critic incarnation's spawn instant.
critiqueDirPath(String workspaceDir) → String
The absolute path of the round's critique dir under workspaceDir — the canonical home of every lane's verdict file (<rubric>.json). Derived identically by ClearCritiqueCapability (the code + spec committees' wipe) and by IntakeCapability (the readiness lane's own wipe, bead pow-q7n), so the two can never drift.
currentVerdictFromFile({required String workspaceDir, required String rubric, required String nodePath, required int round, bool requireOwner = false}) → Map<String, String>?
rubric's CANONICAL verdict payload under workspaceDir, iff it parses AND carries THIS nodePath + THIS round's freshness stamps — null for an absent, foreign, or PRIOR-ROUND file. A malformed or incomplete present artifact throws CapabilityFailure.invalidResult, naming the rubric, the artifact path, and the parser's own detail.
currentVerdictOnDisk({required String workspaceDir, required String rubric, required String nodePath, required int round, bool requireOwner = false}) → Map<String, String>?
currentVerdictFromFile widened to the SAME transport reach result() has for on-disk artifacts: the canonical path first, then the round-fresh STRAY walk (gate-integrity #4 — a critic that cdd mid-run and wrote its verdict under a subdir). The route's join reads through THIS (bridge fix, 2026-07-24): a lane whose verdict result() accepted as file-stray still has a current-round artifact ON DISK, and refusing to join it would wedge the round on a lane that can never re-write. Same fence, same round, same single parser — only the search widens.
decideAgentPermission({required AgentPermissionPolicy policy, required AgentPermissionRequest request, required String admittedAttemptId, required String? boundSessionId, required bool audited}) → AgentPermissionDecision
Decides ONE permission request against the station's policy — the whole authorization rule, pure and total.
decideDiscovery({required Map<String, DiscoveryLensOutcome?> lanes, required DiscoveryAnchors anchors, required Bead workBead, required int priorRound, int maxRounds = kMaxRegatherRounds}) → DiscoveryVerdict
The DISCOVERY matrix (pure — zero I/O; the whole decision, unit-testable).
decideReadiness({required String? grade, required String rationale}) → ReadinessVerdict
The readiness MATRIX (pure — zero I/O; the whole decision, unit-testable).
decideSpecRoute({required List<SpecLane> lanes, required String gating, required String sessionRoot, required int priorRound, int maxRounds = kMaxRespecRounds}) → SpecRouteVerdict
The SPEC-route matrix (pure — zero I/O; the whole decision, unit-testable).
decisionCitationText(Bead bead) → String
kDecisionCitationFields joined and lowercased — the haystack a WHOLE-TOKEN name check (citesDecisionToken) runs over.
decisionLookupRule({String runner = kDefaultOverlayRunner, String? gridHome}) → String
The register's READ rule — stated to every agent on the spec path.
decisionReferences(Bead bead, {required Set<String> knownRegisters}) → List<DecisionReference>
Every decision bead cites EXPLICITLY, deduplicated, in field order then field-local offset order.
declaredTestFiles(String design, {Set<String> baseFiles = const <String>{}}) → Set<String>
Confident test paths the design DECLARES — the gate's obligation set.
decodeAgentEnvelope(Map<String, dynamic> metadata) → DomainEnvelopeResult<AgentConfigOverride>
Decodes a bead's grid.agent envelope off its metadata — fail-closed via the shared machinery (decodeDomainEnvelope): absent is the common case (no override); an incompatible or malformed envelope REFUSES WHOLE.
decodeOfferedField(String? encoded) → List<String>
Decodes kAgentFailureOfferedField; an absent or unparseable value is the EMPTY catalog, never a throw — diagnostic evidence may not break a failure report that is already on its way to the engine.
decodeRelayVerdict(String result) → RelayVerdict
Decodes a relay's raw answer into the engine's RelayVerdict.
defaultFilingService({required BdRunner runnerFor(String storeRoot), SubstationScope? owningScope, List<SubstationScope> attachedScopes = const [], ValidationPlanProbe validationPlanProbe = const SystemValidationPlanProbe(), ShellRunner decisionShell = const SystemShellRunner(), String? decisionInvocation, String? decisionGridHome, FilingEvidenceSource? evidence, FilingAdvisory? advisory, InferenceRunner? inference}) → FilingService
The DEFAULT filing service: the exact read, plus the LIVE viability evidence the six content rows are judged against.
defaultModelForTier(AgentTier tier) → String
The model tier rides when the station arms none — the ASSET rung, the bottom of the model ladder.
describeBranch({required Bead bead, required String beadId, required String nodePath, required Workspace workspace, required PrComposition composition, required AgentConfig ambient, required EnvironmentRegistry registry, List<DescribeReceipt> receipts = const [], GitRunner? git, InferenceRunner? inference, UsageFlare? flare}) → Future<DescribeOutcome>
Reads the bead branch's own delta AS FACTS and runs the ONE-SHOT describe inference over a bounded manifest of them. Every failure path returns a fallback DescribeOutcome — the description is decoration, never a land blocker.
designGradeFor(Iterable<DesignFinding> findings) → String
The letter grade a lane must report for findings — the SHARED verdict envelope's A–F alphabet, mapped from the worst severity present.
discoveryDirPath(String workspaceDir) → String
The discovery round's artifact dir under workspaceDir. A SIBLING of .grid/critique/ (which ClearCritiqueCapability wipes every committee round) — the dossier must outlive that wipe: specify reads it after it.
discoveryDossierPath(String workspaceDir) → String
The CURATED dossier the route writes on ADVANCE and buildSpecifyBrief renders — the whole point of the gather (derived identically by the writer and the reader, the respecLedgerPath precedent).
discoveryLensOutcomeFromResultText(String? text, {required String lens}) → DiscoveryLensOutcome?
Recovers ONE lens outcome from a lens's captured REPLY — the LensInProcessTransport counterpart of readLensReport.
discoveryLensPrompt({required String lens, required String sessionId, required String nodePath, required int round, required String workspaceDir, required DiscoveryEvidenceProjection projection, LensResultTransport transport = const LensArtifactTransport()}) → String
The lens's COMPLETE prompt for transport, or a THROW when the assembly refuses.
discoveryLensRuntimeConfig({required Bead bead, required Workspace workspace, required String lens, required String sessionId, required String nodePath, required int round, required DiscoveryAnchors anchors, required LensResultTransport transport, required AgentConfig ambient, required EnvironmentRegistry registry, required SiteBinding siteBinding, AgentEnvironment? typedEnvironment, Map<String, String> stepParams = const {}}) → RuntimeConfig
Renders ONE lens's spawn for transport — the ONE place the lane's tier, environment resolution, site binding, working agreement, evidence projection and usage posture are settled.
discoveryRegatherLedgerPath(String workspaceDir) → String
The REGATHER round ledger under workspaceDir — the durable round counter DiscoveryRouteCapability reads back to apply kMaxRegatherRounds. Deliberately a SIBLING of .grid/discovery/ (which AnchorsCapability WIPES virgin at the head of every round), so it OUTLIVES that wipe: the full regather wave re-runs anchors, which would clobber any counter kept inside the gather dir and restart the bound at 0 forever. The respecLedgerPath precedent — derived identically by the writer and the reader.
embeddingChangeKey(Bead bead) → String
Returns the stable key for every bead value that contributes embeddings.
encodeOfferedField(List<String> offered) → String
Encodes offered for kAgentFailureOfferedField.
evaluateRecall({required RecallSet recallSet, required Map<String, StationSearchReport> reports}) → RecallRunResult
Evaluates recorded or live station search reports against recallSet.
exactReleaseVersions(Bead bead) → List<BeadTextSlice>
Every EXACT release version pinned in bead's acceptance criteria, in offset order.
extractBdAdditionalContext(String stdout) → String
bd's own additionalContext out of a bd prime --hook-json stdout.
extractPrUrl(String output) → String?
The PR url embedded in gh output — both a successful gh pr create (stdout) and its "already exists" refusal (which prints the open PR's url) carry one. Returns null when none is present.
failedDecisionLookupSentence({String runner = kDefaultOverlayRunner, String? gridHome}) → String
The sentence a spec writes when the roster lookup FAILED — the FORM of kDecisionLookupRule's "a lookup that FAILS or exits non-zero is NOT 'no decision applies'" clause.
failingTestNames(String output) → List<String>
The named tests Dart's test runner reported as failing in output.
fallbackDescriptionFor(Bead bead, {required String foreignRef}) → String
The fallback description — the bead's title, id-stripped; kFallbackDescription for a title-less bead.
fallbackSubjectFor(Bead bead, {required String foreignRef}) → ConventionalSubject
The DETERMINISTIC fallback subject when there is no inference (not wired, offline, a failed run, or unparseable output): type from the bead's issueType, scope from its substation (metadata.rig), description from its TITLE with the bead id stripped out — id-free, compliant, and never the old grid: <id>.
firstAvailable(TreeContext context, ModelPreference preference) → AgentEnvironment?
The availability WALK: the first entry of preference present in the ambient AvailableEnvironments, or null when none is present.
firstAvailableFrom(ModelPreference preference, AvailableEnvironments available) → AgentEnvironment?
The availability WALK as a PURE function: the first entry of preference present in available, or null when none is present.
fixInFlightPath(String workspaceDir) → String
The absolute path of the carry under workspaceDir.
gatesTheBead(DiscoveryFinding finding) → bool
Whether finding may HOLD the bead — the whole gate, in one predicate.
gatherDecisions(DecisionIndexSource? source, String workspaceDir, List<String> surfaces, Bead workBead) → Future<DecisionGatherEvidence>
The round's WHOLE decision gather — every entry body once, plus one lookup per roster-qualified surface — through source, or an explicit EvidenceState.unavailable/EvidenceState.failed record per surface (and an EMPTY index) when no source is wired / the batch threw.
gatherDiscoveryAnchors({required Bead bead, required String workspaceDir, required int round, required String substation, required bool live, List<String> rubricIds = const [], RubricSource? rubrics, AnchorResolver? resolver, PriorArtSource? priorArt, DecisionIndexSource? decisions, HistorySource? history, bool isCancelled() = _neverCancelled}) → Future<DiscoveryAnchors?>
The DETERMINISTIC gather, as a pure-ish function over its injected seams — the SINGLE implementation of "what evidence does this bead get", shared by AnchorsCapability (which persists it as the round's artifact) and by the filing verbs' pre-stamp advisory (which never persists anything).
gatherHistory(HistorySource? source, String workspaceDir, List<String> paths) → Future<HistoryEvidence>
The round's git history, gathered through source — or an explicit EvidenceState.unavailable/EvidenceState.failed record when no source is wired / the batch threw.
gatherPriorArt(PriorArtSource? source, List<String> queries) → Future<List<PriorArtQueryEvidence>>
Every prior-art query's coverage, gathered through source — or an explicit EvidenceState.unavailable record per query when NO source is wired, and a EvidenceState.failed record per query when the batch itself threw.
gitHistorySource(GitRunner runner) → HistorySource
The real HistorySource: ONE git log over every resolved surface, through the pack's existing GitRunner seam.
hasProvenance(String contents) → bool
Whether contents was generated by this tooling (it carries the stamp).
hasTrailer(String message, {String token = kDefaultTrailerToken}) → bool
Whether message carries the git trailer token (Refs: <value>) with a non-blank value — the INVERTED-tracking half of the policy.
headingOffset(String design, String heading) → int
The offset of the heading LINE that opens heading's section in design, or -1 when there is none — the LAST match when several exist.
headingsOf(String markdown) → Set<String>
Every markdown heading TEXT in markdown, read from PROSE — a heading that exists only inside a fenced block is evidence, not a section (the same rule the spec gate holds, ADR-0000 A19).
hookEventNameOf(String payload) → String
The event name carried by a SessionStart payload, defaulting to kSessionStartHookEvent when absent or malformed. PURE.
hookSourceOf(String payload) → SessionStartSource?
The SessionStart source carried by payload, or null when absent, unknown or malformed. PURE.
inferenceTargetNeedsEndpoint(InferenceTarget target) → bool
Whether target requires a machine endpoint the site binding must supply (ADR-0002 D3 — an environment whose machine fact is UNBOUND on this box REFUSES at boot). Exhaustive switch (house style).
inspectedBinaryOf(AgentEnvironment environment) → String?
WHICH binary an environment's presence is actually about.
intakeFindings(Bead bead) → List<String>
The INTAKE-CONTRACT findings for bead — empty iff the bead may reach the readiness lane. Pure and exposed for unit tests; IntakeCapability gates iff this returns non-empty. Each finding NAMES what is missing (guards LOUD), so a held bead's refinement ask never makes a governor diff the bead by hand.
isApprovalStamped(Bead bead) → bool
Whether bead carries the verb-written stamp.
isCommitteeProseOrMetadataPath(String path) → bool
Whether path is prose or metadata — the shapes with no runtime behaviour to regress and no test to cover.
isCommitteeRuntimePath(String path) → bool
Whether path carries RUNTIME behaviour — anything that is neither a test surface nor prose/metadata.
isCommitteeTestPath(String path) → bool
Whether path is a TEST surface — a test root, a nested test directory, or a Dart test file.
isDesignPath(String path) → bool
Whether path is a DESIGN-ROUND path — a repo-relative file at any depth under kDesignPathPrefix (the glob docs/design/**).
isDocsPath(String path) → bool
Whether path is a DOCS path — any .md file anywhere, or any path with a segment that is exactly docs.
isMetadataPath(String path) → bool
Whether path is a METADATA path — prose or configuration, never source.
isPrAlreadyOpen(String ghOutput) → bool
Whether ghOutput is gh pr create's "a pull request … already exists" refusal — the rework-round symptom (round one's PR is still open).
isResolvableDecisionReference(String raw) → bool
Whether raw is a citation identity the roster index can ANSWER: the canonical <repo>#<slug>, a docs/decisions/ path, or a legacy ADR-<nnnn> id (which a migrated entry still resolves by).
isStaleFilingApprovalStamp(Bead bead) → bool
Whether bead carries a COMPLETE receipt minted under a RETIRED filing scheme version — well-formed in every part, and unreproducible only because the basis its digest was taken over no longer exists.
landReasonTail(String output, [int max = 400]) → String
The TAIL of captured process output — what a failure reason stamps so an operator sees WHY without forensics. The useful line is at the END (a tool prints progress first, the fatal message last) and the engine truncates a failureReason to its FIRST kMaxReasonChars; taking the tail keeps the diagnosis, not the noise. A leading … marks a cut.
laneDownFlareFields(LaneEnvironmentDiagnosis diagnosis, LaneEnvironmentDiagnosis first) → Map<String, String>
The kLaneDownFlare payload for diagnosis, whose lane first failed at first.
laneDownSummary(LaneEnvironmentDiagnosis diagnosis, DateTime since) → String
The ONE LINE an operator reads the whole incident from.
legacyDecisionAlias(String slug) → String
The leading legacy id of slug, or '' when it carries none.
lensBrief(String lens) → String
The per-lens angle — the ONE thing that differs between the three lanes. Public so the Packaged-AI-Asset mirror (extension/prompts/discovery.md) renders the SAME brief the in-pipeline lens reads.
lensReportPath(String workspaceDir, String lens) → String
One lens's report path — the canonical, ABSOLUTE path its prompt names (cwd-invariant, gate-integrity #4).
lineOf(String text, int offset) → int
The 1-based line of offset in text — the ONE line-number reckoning, so every SpecContractFinding counts the same way, and the only place a line number is computed.
lintCommitSubjects(List<String> messages, {required String foreignRef, String trailerToken = kDefaultTrailerToken}) → CommitLintReport
Lints the branch's own commit MESSAGES against the policy — the subject through lintConventionalSubject (with the bead id as the forbidden foreign reference) and the message through hasTrailer.
lintConventionalSubject(String subject, {String foreignRef = ''}) → List<String>
The v1.0.0 violations in subject — EMPTY when compliant. The shared checker: sanitizeConventionalSubject guarantees the asset's OWN output passes it, the build-agent commit lint (lintCommitSubjects) runs it over the branch's commits, and the tests assert the emitted title against it. A non-empty foreignRef (the bead id) in the subject is itself a violation — the exact anti-pattern the policy fixes.
listedModels(Uri endpoint) → Future<Set<String>>
The model ids endpoint lists at GET /v1/models (the OpenAI-compatible shape both swift-infer and a llama.cpp server answer), or the EMPTY set when the provider exposes no list or answers unparseably.
loadStationOverlaySourceFromPaths({required String overlayRoot, required String manifestPath}) → StationOverlaySource
Reads station_overlay.mappings from manifestPath over the defaults.
maskQuotations(String line) → String
line with every markdown QUOTATION / EMPHASIS span blanked to spaces of the SAME length (so match offsets stay honest), and a > blockquote line blanked whole. A quoted word is a MENTION — the org rule itself is written as never "plugin" in two shipped rubrics, and stating a ban must never trip it. A word used BARE in prose is a USE, and that is the offence.
memoryPointerLines({required String memory, required String target}) → List<int>
The indices of the lines in memory carrying a Markdown link whose target is EXACTLY target — the disc index's pointer at one note.
missingDeclaredTestFiles({required String design, required Set<String> changedFiles, Set<String> baseFiles = const <String>{}}) → List<String>
Sorted declarations absent from changedFiles.
mountedGridHomeOf(GridDelegate delegate, {GridConfiguration configuration = const sdk.GridConfiguration()}) → String?
The grid home the composing station AUTHORED — the ambient sdk.GridRoot of delegate's tree, resolved BY TREE POSITION in one offline mount (the A11 idiom; RawAssetGrid(root:) provides it). Null when the delegate authors no RawAssetGrid — the Command refuses LOUD on that.
mountedRosterOf(GridDelegate delegate, {GridConfiguration configuration = const sdk.GridConfiguration()}) → List<SubstationScope>
Enumerates the mounted substation roster of delegate — the ATTACHED substations, resolved from the resident-station context at run time.
mountedValueOf<T extends Object>(GridDelegate delegate, {GridConfiguration configuration = const sdk.GridConfiguration()}) → T?
The FIRST ambient T in delegate's tree (tree order), or null when the tree provides none — the single-value form of mountedValuesOf. The caller decides how loud an absence is.
mountedValuesOf<T extends Object>(GridDelegate delegate, {GridConfiguration configuration = const sdk.GridConfiguration()}) → List<T>
Every ambient value of type T provided in delegate's authored tree, in TREE ORDER (a pre-order walk).
mountEligibilityDecision(Bead bead, {Bead? freshBead, String? evaluatedApprovalRevision}) → MountEligibilityDecision
The grid_engine predicate supplied by this assets pack.
mountEligibilityFindings(Bead bead, {String? evaluatedApprovalRevision}) → List<String>
Mechanical pre-session findings that decide whether bead may mount.
mountSemanticSearchBackend(String gridHome) → Future<SemanticSearchBackend>
noArmedSubstations() → Set<String>?
The default roster seam: NONE. Until a station threads its coded roster in, an external:<project>:<capability> dependency row cannot be resolved to an armed substation, and the dependencies row refuses fail-closed saying so.
noGoverningDecisionSentence({String runner = kDefaultOverlayRunner, String? gridHome}) → String
The sentence a spec writes when the roster union is EMPTY for every queried surface — the FORM of kDecisionLookupRule's "an empty union is a real result" clause.
normalizeCitedPath(String raw) → String?
raw as a citable repo-relative path, or null when it is not one.
noStateRoot() → String?
The default injected state root: NONE. The verb that REQUIRES the home (park) refuses rather than guess at one.
operatorSkillIds(GridAssetRegistry registry) → List<String>
The skills registry declares for the OPERATOR — the human at the grid home, whose .claude/ the install Command fills — sorted.
parentPath(String nodePath) → String
The parent node path of nodePath ('a/b/route' → 'a/b'), so a join step computes its sibling lane paths ('$parentPath/$laneId'). ONE definition — every route in this pack derives its siblings the same way.
parseAssetSelector(Object? raw, String label) → AssetSelector
Maps one CLOSED selector token onto the grid_sdk AssetSelector union.
parseCodeAnchor(String anchor) → ({int? line, String path})
The PATH half and the CITED LINE of one code anchor — lib/src/x.dart:222 answers both; an anchor with no :NNN qualifier answers itself and null.
parseCommitteeClassifierResult(String? output, {required List<String> activeSemanticRubricIds}) → CommitteeClassifierResult
Decodes ONE classifier answer STRICTLY.
parseDesignFindings({required String lane, required String grade, required String rationale}) → List<DesignFinding>
Parses one judge lane's rationale into its findings.
parseGridBlock({required String pubspecYaml, required ArtifactPathProbe pathExists}) → GridBlock
Parses the grid: block out of pubspecYaml, refusing LOUD on any malformed field, missing artifact path, duplicate AssetKey, or duplicate AssetArtifactKey.
parseSeatArchiveDirectoryName(String name) → ({int ordinal, String stamp})?
name split back into the stamp and ordinal seatArchiveDirectoryName composed, or null when it is not a name this station wrote. PURE.
parseSeatHandoff({required String path, required String relativePath, required String contents}) → SeatHandoff?
Parses contents as a disc note, returning a SeatHandoff when its front matter declares kind: handoff and null otherwise — a lesson, a receipt, an observation, MEMORY.md, or a file with no front matter at all. PURE: the whole handoff decision is testable without a disk.
parseSpecContract({required String acceptance, required String design, Set<SpecContractSection> only = const {SpecContractSection.acceptance, SpecContractSection.plan, SpecContractSection.touches, SpecContractSection.decisions, SpecContractSection.validation}}) → ({SpecContract contract, List<SpecContractFinding> findings})
Projects acceptance + design — the bead's RAW fields — into a SpecContract, appending every deviation from the documented grammar to the returned findings.
pathCheckDiagnostic(String plan, int exitCode) → String?
Advisory PATH candidates after exitCode has already been observed.
pinnedDiffPath(String workspaceDir) → String
The absolute path the pinned review-scope diff lives at under workspaceDir — derived identically by PinDiffCapability (the writer) and CriticCapability.buildCriticPrompt (which names it to the critic).
planOutputWithoutPubAdvice(String output) → String
output with pub's upgrade-ADVICE lines dropped (bead pow-gy41).
planSeatLaunch({required AgentEnvironment environment, required String seat, required String gridHome, required String discDirectory, String? handoffBody, String? handoffArchivePath}) → SeatLaunch
Plans seat's occupancy of environment — PURE.
prBodyPath(String workspaceDir) → String
The absolute PR-body ledger path inside workspaceDir.
priorArtQueries(Bead bead, List<String> symbols) → List<String>
The PRIOR-ART queries for bead — its SYMBOL anchors (a symbol is a high-signal substring query; a whole title is not), else its distinctive title words. Pure, bounded by kMaxPriorArtQueries, exposed for unit tests.
projectDiscoveryEvidence(DiscoveryAnchors anchors, {required String lens, required int round, required String workBeadId}) → DiscoveryEvidenceProjection
Projects anchors into lens's OWN bundle — the whole reason the gather is deterministic.
proseOnly(String spec) → String
spec with its markdown QUOTATION contexts blanked — fenced ``` blocks, > blockquote lines, then inline code spans (in that order, so a fence's own backticks are never re-paired as inline spans). Quoted material is what a spec points AT (code carrying a // TODO the plan deletes, an ADR clause cited verbatim), not a commitment the author defers, so the placeholder fence never reads it. Each region is replaced by a TWO-space seam: wide enough that stripping can only ever break a token across it, never splice one together (every banned phrase joins its words with a single space). An unterminated fence is left as-is (its content stays scannable — fail-closed), and inline spans never cross a newline.
provenanceSyntaxFor(String relativePath, String body) → ProvenanceSyntax
The provenance syntax for relativePath carrying body.
readBinaryMtime(String path) → Future<DateTime?>
When path was last written, in UTC; null when it cannot be read.
readBinaryVersion(String path) → Future<String?>
The version path reports for itself, bounded by kEnvironmentProbeTimeout.
readCapturedOutputLogOrEmpty(String path) → String
The full captured-output log at path, or '' when it is not readable.
readDiscoveryAnchors(String workspaceDir) → DiscoveryAnchors?
The deterministic gather, read back (best-effort — an absent/corrupt file degrades to "no gather", never a throw). The readRespecLedger posture.
readDiscoveryDossier(String workspaceDir) → DiscoveryDossier?
The curated dossier, read back — what SpecifyCapability hands the architect.
readDiscoveryRegatherLedger(String workspaceDir) → DiscoveryRegatherLedger?
The regather ledger at workspaceDir, or null when there is none / it is unreadable. Best-effort: a corrupt ledger degrades to "no prior round" (the counter restarts) — it can never throw into a route.
readEnvelopeResultText(String workspaceDir, String nodePath) → String?
Reads the RAW result text field out of the harness's --output-format json envelope for the step at nodePath under workspaceDir — the verdict-transport fallback (tg-291): a critic that graded cleanly but wrote its verdict into stdout instead of .grid/critique/<rubric>.json still has that text recoverable here, so a caller can attempt to parse a verdict out of it. FAIL-SAFE: an absent/unreadable/malformed envelope, or one with no non-blank string result field, yields null — NEVER a throw.
readFixInFlight(String workspaceDir) → FixInFlight?
The carry at workspaceDir, or null when there is none / it is unreadable.
readinessLensPrompt({required Bead bead, required String rubric, required String nodePath, required String workspaceDir, required int round, required LensResultTransport transport, RubricSource? rubrics, String decisionRunner = kDefaultOverlayRunner, String? decisionGridHome}) → String
The COMPLETE readiness prompt: readinessLensPromptBody plus the one paragraph that names transport's destination.
readinessLensPromptBody({required Bead bead, required String rubric, required String nodePath, required int round, RubricSource? rubrics, String decisionRunner = kDefaultOverlayRunner, String? decisionGridHome}) → String
The TRANSPORT-INVARIANT body of the readiness lens's prompt — everything through kVerdictStampInstruction, and the whole of what the lens is asked to JUDGE.
readinessLensRuntimeConfig({required Bead bead, required Workspace workspace, required String rubric, required String nodePath, required int round, required LensResultTransport transport, required AgentConfig ambient, required EnvironmentRegistry registry, required SiteBinding siteBinding, RubricSource? rubrics, String decisionRunner = kDefaultOverlayRunner, String? decisionGridHome, AgentEnvironment? typedEnvironment, Map<String, String> stepParams = const {}, String promptSuffix = ''}) → RuntimeConfig
Renders the readiness lens's spawn for transport — the ONE place the lane's tier, environment resolution, site binding, usage posture and prompt are settled.
readinessModeOf(ArgResults results) → FilingAdvisoryMode
The mode results selected. Absent or blank ⇒ FilingAdvisoryMode.run.
readinessRubricText(String rubric, RubricSource? rubrics) → String
The rubric prose a readiness prompt embeds — the injected source (D-9), or an inline placeholder so the lane is testable with no real assets.
readLensReport(String workspaceDir, String lens, String nodePath, {required int round, required String sessionId}) → DiscoveryLensOutcome?
Reads ONE lens's report — the A13(3) transport stack, minus the fail-closed default (a gather lane's silence is MISSING, never a verdict):
readRefinementFlag(String workspaceDir) → RefinementFlag?
The flag at workspaceDir, or null when there is none / it is unreadable.
readRespecLedger(String workspaceDir, {required String expectedSessionRoot}) → RespecLedger?
The ledger at workspaceDir, or null when there is none / it is unreadable. Best-effort by design: a corrupt ledger degrades to no correction guidance; it can never throw into a spawn or a route.
readSpecCorpus(String root) → List<SpecCorpusEntry>
Reads the retained corpus rooted at root (the package root).
readUsageFields(String workspaceDir, String nodePath, {required ModelPriceTable modelPrices, UsageFlare? flare}) → Map<String, String>
The step's usage telemetry as the result fields to merge — an EMPTY map when the envelope is absent, unreadable, malformed, or carries no usage at all. readUsageReport owns the read, so this is fail-safe for the same reason it is.
readUsageReport(String workspaceDir, String nodePath, {ModelPriceTable modelPrices = const <String, ModelTokenPrice>{}, UsageFlare? flare}) → UsageReport?
Reads + parses the usage telemetry the harness redirected for the step at nodePath under workspaceDir — the ONE filesystem seam every lane reads an FT-2 envelope through. null when the file is absent, unreadable, or malformed; NEVER a throw, so reading telemetry can never fail, gate, or delay a step (the FT-2 fail-safe property).
realComputeSpawn(DispatchCommand cmd) → Future<ComputeProcess>
The real compute ComputeSpawn: a Process.start with EXPLICIT argv (no shell — so no string interpolation / injection), killable + with a readable exit code. Offline tests inject a fake instead of spawning a process.
recordArtifact(File file, String contents) → Future<void>
Writes contents to file, creating parents, so no reader observes a partially written artifact.
refinementFlagPath(String workspaceDir) → String
The absolute path of the refinement flag under workspaceDir — a sibling of the respec ledger and the fix-in-flight carry, under the same session-scoped kRespecSpecDir.
refinementNotes(List<SpecLane> lanes) → List<RefinementNote>
Every lane's BEAD-GRAPH observations, in critics order (bead pow-bhm's COHERENCE SCOPE dial, ratified 2026-07-18).
removeMemoryLine({required String memory, required int index}) → String
memory with line index removed and EVERY remaining byte preserved — the removed line takes its own \n and nothing else. PURE.
renderContextNote(ContextNote note, String workBeadId) → String
Renders a context note with explicit bead ownership.
renderDiscoveryDossier(DiscoveryDossier dossier) → String
The DOSSIER block buildSpecifyBrief renders — the architect's curated context. Rubrics FIRST (ADR-0000 A19's Status footer: spec to the definition you are graded by), then the resolved anchors, the prior art, what the explorers found, the flags to answer, and the departures to carry.
renderDiscoveryEvidenceHold(Map<String, List<EvidenceGap>> gaps) → String
The REFINEMENT ASK a bead parks with when a lens STATED that the canonical evidence it was handed is incomplete — it NAMES each hole by its canonical evidence id and repeats the reason the gather itself recorded, so a governor's next move is unambiguous.
renderDiscoveryHold({required List<DiscoveryFinding> offenses, required List<DiscoveryFinding> flags}) → String
The REFINEMENT ASK an offending bead parks with — it CITES every offence, and it states the departure clause, so a governor's next move is unambiguous: revise the bead, or DECLARE the departure.
renderedBytes(String rendering) → int
What rendering costs the cap: its UTF-8 length plus the one newline the command writes after it.
renderFixInFlightGuidance(FixInFlight carry) → String
The BINDING block the BUILD agent's brief embeds: the finding verbatim, and what the builder owes it.
renderFixInFlightRecheck(FixInFlight carry) → String
The RE-CHECK block every CODE-critic prompt embeds while a carry is live — the same finding, addressed to the reviewer.
renderGridAssetPackLibrary(GridBlock block) → String
Renders block as the public Dart library a station composes.
renderInstallReport(OverlayInstallReport report, {bool diff = true}) → String
Renders report for the operator — PURE (no IO), so the CLI and a UI print the same thing.
renderIntakeHold(Bead bead, List<String> findings) → String
The INTAKE-CONTRACT hold's reason — every deterministic finding, named.
renderMcpConfig(GridBlock block) → String
Renders block as the MCP-shaped compatibility mirror (extension/mcp/config.yaml, the package:extension_discovery shape).
renderMemoryDirArgs(AgentEnvironment environment, String absoluteDiscPath) → List<String>
environment's AgentEnvironment.memoryDirArgs with kMemoryDirHole bound to absoluteDiscPath; empty when the harness declares none.
renderMountExplanationPlain(MountExplanationReport report) → String
The plain rendering of one bounded report — the single renderer both the bound calculation and MountCommand consume, so what the cap is measured against is exactly what is printed.
renderOverlayTemplate(String contents, Map<String, String> args) → String
Renders contents against args, applying the overlay's argument defaults.
renderPrimeHookJson({required String hookEventName, required String additionalContext}) → String
The hook object a SessionStart hook writes on stdout. PURE.
renderPrSection(PrSection section, PrCompositionContext context, {String trailerToken = kDefaultTrailerToken}) → String
Renders ONE section over context — '' when its data is absent (an empty render is OMITTED from the composed body, never a bare heading).
renderRefinementAsk({required String grade, required String rationale}) → String
The REFINEMENT ASK a not-ready bead parks with — the hold's whole point. The lens's rationale rides VERBATIM (it is the governor's working material, not a summary), under a line that says plainly what was NOT spent: no specify agent, no spec committee.
renderRefinementFlag(RefinementFlag flag) → String
The OPERATOR-facing block: what refinement owes the tracker, verbatim. Rides the parked gate's reason on an escalate, so a governor reads it where they already read the ruling.
renderRespecGuidance(RespecLedger ledger) → String
The correction-guidance BLOCK the next specify brief embeds (bead pow-7nm's load-bearing requirement: "the critic rationales MUST reach the re-specify agent's brief"). Rationales ride VERBATIM and in full — this is the agent's working material, not a summary.
renderRoleArgs(AgentEnvironment environment, String seat) → List<String>
environment's AgentEnvironment.roleArgs with kSeatHole bound to seat; empty when the harness declares none.
renderRoleAsset(AgentEnvironment environment, String seat) → String?
environment's AgentEnvironment.roleAsset with kSeatHole bound to seat; null when the harness declares no authored-persona home.
renderSpecContractShadowReport(List<SpecCorpusEntry> corpus) → String
The report, rendered from corpus plus the declared tables. PURE — the only thing that writes it is runSpecContractShadow.
renderStationAssetRegistryLibrary(Iterable<ResolvedGridAssetPack> packages) → String
Renders a Flutter-registrant-style library from packages.
replayCommitteeSelectionRun(CommitteeSelectionRun recorded) → CommitteeSelectionRun
Re-derives recorded's selection from its OWN retained evidence and attempts — the pure half of replay.
replayCommitteeShadowReceipt(CommitteeShadowReceipt recorded) → CommitteeShadowReceipt
Replays recorded through the PURE policy over its own recorded facts.
repoRelativePathOf(String raw) → String?
raw as a REPO-RELATIVE path, or null when it is not one.
reportedLegacyDecisionAliases(String detail) → Set<String>
Every legacy alias detail REPORTS as unresolved, lowercased.
requiredDocSections(Bead bead) → List<String>
The sections the bead REQUIRES of the docs it changes — the CSV kDocsSectionsKey metadata. Absent or blank ⇒ no requirement, so this lane is vacuously A. That is deliberate: the ruling says "required sections present WHEN THE BEAD NAMES THEM", and a lane that invented its own requirement would gate on taste.
resolveAcpModelId({required String want, required List<String> available, required AgentTier tier, String? current}) → String?
Resolves an environment pin against the model ids offered by an ACP agent, for a seat riding tier.
resolveAgentConfig({required AgentTier tier, required AgentConfig ambient, required Map<String, dynamic> beadMetadata, required Map<String, String> stepParams, required EnvironmentRegistry registry, AgentEnvironment? typedEnvironment}) → AgentConfig
The effect-boundary resolution (the D-C ladder as a pure value merge).
resolveAnchorOnDisk(String workspaceDir, String anchor) → ResolvedAnchor
The real AnchorResolver: does the path exist in the worktree, and what else lives in its directory (the SURROUNDING PATTERN the architect must match). Deterministic (sorted) and bounded (kMaxNeighbors).
resolveAnchorsOnDisk(String workspaceDir, List<String> anchors) → List<ResolvedAnchor>
The real AnchorResolver: resolveAnchorOnDisk over the whole batch, in input order. ONE tree-intake pass per round.
resolveBinaryPath(String command) → Future<String?>
The ABSOLUTE file command runs as on this box, with symlinks resolved, or null when it resolves to nothing.
resolveEnvironment<TSpecific extends ModelPreference>(TreeContext context) → AgentEnvironment?
The EFFECTIVE typed lookup - the one function a spawn site calls (bead pow-n6n.2 wires the six of them).
resolveGridAssets({required GridAssetRegistry registry, required SubstationFactsSnapshot snapshot, required SubstationKey substation, Map<String, String> renderArguments = const <String, String>{}, GridAssetRosterOverride? rosterOverride}) → GridAssetResolution
Resolves ACTUAL availability — and both writers' exact file sets — from the generated registry, the observed snapshot, and this station's composition values. PURE: no filesystem, no package graph, no process.
resolveOverlaySourceRefSync(String overlayRoot) → String
The grid_assets source ref overlayRoot was vended from — the short commit sha of its checkout, or kUnknownSourceRef when it is not in one.
resolveStateRoot(ArgResults results, String? fallback()) → String?
Resolves the state root for one run: the parsed kStateRootOption when it carries a non-blank path, else the station-injected fallback. Null when neither names one — the state store is then NOT consulted.
resolveStationGridAssetPacks({required String stationRoot}) → List<ResolvedGridAssetPack>
Resolves all packages participating in stationRoot's asset registry.
respecLedgerPath(String workspaceDir) → String
The absolute path of the respec guidance ledger under workspaceDir — derived identically by SpecRouteCapability (the writer) and its readers (SpecifyCapability's guidance).
respecStampReason(RespecLedger ledger) → String
The RESPEC decision's compact human-readable REASON, recorded as result PROVENANCE beside the invalidating grade: 'F' stamp. Diagnostics and telemetry ONLY: the engine's derivation reads the STRUCTURED grade and never this prose, and the correction guidance the next specify actually reads is the durable ledger at respecLedgerPath, which carries every rationale in FULL. So this line is deliberately COMPACT: the round, the bound, the failing lanes, and where the guidance lives. (The superseded gate reason it replaces had to inline every rationale, because a parked gate bead was the only thing a governor could read; a respec parks nothing.)
restampVerdictRound({required String workspaceDir, required String rubric, required String nodePath, required int round}) → RoundRestamp
Rewrites the canonical <rubric>.json round stamp to round — the engine-injected grid.round read via verdictRound — WHEN AND ONLY WHEN the file is provably THIS critic incarnation's output.
reviewBaseRef(Workspace workspace) → String
The ONE review base every committee probe measures a round against: the commit the workspace was PROVISIONED from, when the provisioner recorded it (Workspace.baseSha), and otherwise the remote base branch.
rosterDecisionIndexCommand({String? surface, String runner = kDefaultOverlayRunner, String? gridHome}) → String
The composing station's ROSTER-MODE decision lookup, as shell text.
rosterDecisionLookupBlock(List<String> surfaces, {String runner = kDefaultOverlayRunner, String? gridHome}) → String
The per-surface roster lookup an agent must run, one command per line, each CWD-QUALIFIED by gridHome.
rosterQualifiedPaths({required Iterable<String> paths, required String substation}) → List<String>
The ONE path qualifier — <substation>/<path> for every token in paths that could be a repository-relative path, deduplicated in first-appearance order, with kUnknownSubstationPrefix as the fallback prefix.
rosterQualifiedSurfaces({required String design, required String substation}) → List<String>
The ROSTER-QUALIFIED surfaces rosterDecisionIndexCommand is run over for the spec carried in design, each prefixed with substation.
rubricEvidenceOf(Map<String, String> rubrics) → List<RubricEvidence>
The rubric IDENTITIES for rubrics — the digest of each rubric's complete prose, in map order. The prose itself is NOT re-copied: it rides DiscoveryAnchors.rubrics verbatim, which is what A19's rubrics-in-brief principle requires.
runGridAssetsGenerator({required String packageRoot, bool check = false, StringSink? out, ProcessResult runProcess(String executable, List<String> arguments, {Encoding? stderrEncoding, Encoding? stdoutEncoding, String? workingDirectory}) = Process.runSync}) → int
Regenerates — or, with check, VERIFIES — both generated outputs from the grid: block at <packageRoot>/pubspec.yaml.
runRecall({required String runner, required String gridHome, required bool recordBaseline, ProcessRunner processRunner = Process.run, String workingDirectory = '.'}) → Future<int>
Runs the durable corpus through the vended search command.
runSemanticSearch({required String query, required String gridHome, required List<SemanticStoreInput> stores, SemanticSearchBackendMount mount = mountSemanticSearchBackend}) → Future<SemanticSearchOutcome>
runSpecContractShadow({required String root, required bool record}) → Future<int>
Regenerates or CHECKS kSpecContractShadowReport under root.
runStationAssetRegistryGenerator({required String stationRoot, String outputPath = kGeneratedStationAssetRegistryPath, bool check = false, StringSink? out}) → int
Generates or checks one station-local Dart registrant.
runWithinDeadline(ShellRunner runner, {required String workingDirectory, required String command, required Duration deadline}) → Future<ShellRunResult>
Runs command through runner, bounded by deadline when runner is a BoundedShellRunner.
sanitizeConventionalSubject({required String type, String? scope, bool breaking = false, required String description, required String foreignRef, String fallbackType = 'chore', String fallbackDescription = kFallbackDescription}) → ConventionalSubject
Normalizes a (possibly model-authored) subject into one that is COMPLIANT BY CONSTRUCTION — this is what makes the emitted title spec-valid without trusting the model: an unknown type falls back to fallbackType; the scope is lower-cased and paren-stripped; the description loses every occurrence of foreignRef (the bead id — the anti-pattern this bead exists to kill), collapses its whitespace, drops trailing periods, lower-cases its FIRST letter (only the first — an acronym or an identifier mid-description keeps its case: infer the PR title, never infer the pr title), and is truncated at a WORD boundary so the whole subject fits kMaxSubjectChars; an empty result becomes fallbackDescription.
sanitizeDigest(String digest, {required String foreignRef, int maxChars = kMaxSummaryChars}) → String
The digest as it is RENDERED: every occurrence of foreignRef — its #rN rework form, the brackets that wrap it and the separator it orphans — REMOVED, inline whitespace tidied, paragraph breaks preserved, the whole capped at maxChars.
seatArchiveCommitMessage(String seat) → String
The message the scoped archive commit carries. PURE.
seatArchiveDirectoryName(String stamp, int ordinal) → String
The <YYYYMMDD>t<HHMMSS>z(-<n>)? shape a local archive directory is named by — the stamp alone at ordinal 1, <stamp>-2 at 2, and so on. PURE.
seatArchiveDisposition(SeatSuccessionReport report) → String
The ONE phrase naming where a run archived the disc, rendered identically by every reader of a SeatSuccessionReport. PURE.
seatArchiveRetentionDisposition(SeatSuccessionReport report) → String?
The ONE phrase naming what retention did, or null when it did nothing — rendered identically by every reader of a SeatSuccessionReport. PURE.
seatArchiveStamp(DateTime at) → String
The UTC stamp one local archive directory is named by — the <YYYYMMDD>t<HHMMSS>z shape the handoff file name already carries, so an archive sorts beside the notes it holds. PURE.
seatArchivesToPrune(Iterable<String> names, {int keep = kSeatArchiveRetention}) → List<String>
The archive directory names in names that fall OUTSIDE the newest keep, OLDEST first — exactly what one succession prunes. PURE.
seatChannelPolicy<TSeat extends ModelPreference>(TreeContext context, {required String seatId}) → AgentPermissionPolicy
The station permission policy in effect for ONE capability's channel, keyed by the seat's own preference type TSeat and stamped with seatId.
seatDiscPath(String gridHome, String seat) → String
The ABSOLUTE disc directory of seat under gridHome.
seatHandoffAgeDiagnostic({required String seat, required SeatHandoff handoff, required DateTime authoredAt, required DateTime now}) → String
The ONE line every seat reader renders beside an unconsumed handoff: which Agent Seat, which note on its Agent Disc, and how OLD it is. PURE.
seatHandoffDeliveryRefusal(AgentEnvironment environment) → String?
Whether environment can DELIVER a consumed handoff body to its child, or the one-line reason it cannot — PURE.
sectionAt(String design, int headingAt) → ({String body, int start})
The section whose ## heading starts at headingAt: its start offset in design and its body — the text after the heading line up to the next ## heading (or the end).
sectionBodyAt(String design, int headingAt) → String
The body of the section whose ## heading starts at headingAt — the text after the heading line up to the next ## heading (or the end).
sectionFindings({required Map<String, String> docBodies, required List<String> requiredSections}) → List<String>
Findings for kSectionStructureRubric: when requiredSections is non-empty, every changed doc in docBodies must carry each one as a heading.
selectorExpression(AssetSelector selector) → String
The Dart source expression for selector — an exhaustive switch over the sealed grid_sdk union, so a new variant breaks this renderer loudly.
semanticVersionToken(String text) → String?
The LAST semantic-version-shaped token in text, or null.
sendEmbeddingHttpRequest(EmbeddingHttpRequest request) → Future<EmbeddingHttpResponse>
Sends one request through dart:io's HTTP client, bounded end to end by kEmbeddingHttpTimeout.
setupFailureFields(Object error) → Map<String, String>
The structured evidence a SETUP failure carries onto its failed frame.
shellCommandExecutables(String plan) → List<String>
External executables occupying command positions in plan.
shellParseDiagnostic({required String shell, required int exitCode, required String stderr}) → String
The shell's OWN first word on why it refused — the line an author can act on (unexpected EOF while looking for matching …). A silent shell falls back to the exit code, so the reason is never empty.
shouldInjectHandoff(String payload) → bool
Whether the seat's newest handoff is injected for payload.
socketReachable(Uri endpoint) → Future<bool>
Whether a TCP connection to endpoint completes inside kEnvironmentProbeTimeout. A dead local server refuses at once and a wedged one times out — either way the environment leaves the presence set.
sourceControlOf(TreeContext context) → SourceControl?
Resolves the SourceControl a bead's work runs under — the v3 successor to the retired root-keyed bundle map (bead tg-5r9).
spawnFor({required AgentEnvironment environment, required AgentBrief brief, required Workspace workspace, String? model, String? usageOut, Uri? endpoint}) → RuntimeConfig
The one-turn spawn renderer (ADR-0002 D1; the harness collapse, bead pow-ebf.4): render one resolved environment + brief into the process invocation rooted at workspace, reading the environment's DATA. Channel environments instead select an injected AgentEnvironment.sessionAdapter; there is still no per-tool class.
spawnThroughSessionAdapter({required AgentSessionAdapterRegistry adapters, required AgentEnvironment environment, required AgentBrief brief, required Workspace workspace, required AgentTier tier, String? model, String? usageOut, Uri? endpoint}) → RuntimeConfig
The HARNESS-NEUTRAL spawn (bead pow-39tl): one resolved environment rendered into a process invocation, whichever transport it declares.
specBeadBlock(Bead bead) → String
Renders the full work bead into the spec-review prompt block — the same title/task/design/acceptance/notes rendering the code committee embeds, re-labeled so the critic knows the Acceptance criteria + Design sections ARE the artifact under review.
specExemplarDesign({String runner = kDefaultOverlayRunner, String? gridHome}) → String
The design half of that exemplar — one complete step in the ordinal-heading shape, all four sections, every element the four LLM lanes look for, and every RECORD form the deterministic gate parses.
specForStructuralValidation({required Bead? fallback, required Map<String, String> specifyResult}) → Bead?
Selects the complete current-wave spec, falling back to the mounted bead.
specStructuralContract({String runner = kDefaultOverlayRunner, String? gridHome}) → String
The EXACT structural contract taught to the specify agent, in the words it reads. Items 1–5 are enforced by specStructuralFindings; items 6–10 are parsed by parseSpecContract in shadow measurement only. buildSpecifyBrief renders this string VERBATIM, so neither phase can hide a rule from the architect.
specStructuralFindings(Bead bead) → List<String>
The LIVE structural findings for bead's spec — empty iff the five presence and placeholder checks pass. Pure and exposed for unit tests; SpecValidationCapability grades A iff this returns empty. Each finding names what is missing (guards LOUD), and every existing finding string is byte-unchanged.
stampedRound(Object? raw) → int?
The verdict's ROUND stamp as an int — null when the stamp is ABSENT or unreadable. A JSON number and its string form both read (a critic that wrote "round":"2" made a formatting slip, not a stale verdict); anything else is a MISS, which fail-closes exactly like a foreign nodePath does.
stampProvenance(String body, {required String relativePath, required String sourceRef, required String runner}) → String
body with its provenance stamp inserted. sourceRef is the grid_assets ref it was generated from; runner is the composing station's verb, so the stamp names the exact command that regenerates the file.
stationPriorArt(GridDelegate delegate(), {required String gridHome, StationSearchService service = const StationSearchService()}) → PriorArtSource
The station's real prior-art source (ADR-0001, the coupled skill+command pattern applied one layer in): the asset CALLS the deterministic StationSearchService — the SAME UI-drivable service the search Command adapts — over the roster resolved from the composing station's delegate. READ-ONLY by construction (A37): the service's only store surface is a single-spawn export.
stripForeignRef(String text, String foreignRef) → String
Removes every occurrence of foreignRef — and its #rN rework form — from text, then the separator it orphans (pow-8dx — do a thing ⇒ do a thing). The belt behind the prompt's "never write the tracker id" rule: a model that writes it anyway still cannot land it in a subject.
stripProvenance(String contents) → String
contents with its stamp line removed — the BODY, which is what a drift check compares. Identity for an unstamped file, and the exact inverse of stampProvenance.
sweepStaleCritique(String workspaceDir, {required String committeePath, required int round}) → void
The round-aware critique sweep ClearCritiqueCapability runs: ensures critiqueDirPath exists and deletes every entry in it EXCEPT a canonical verdict of THIS round — a <rubric>.json whose stamps pass the one shared fence (_verdictFromFile) for the sibling node path <committeePath>/<rubric> at round. Everything else — a prior round's verdict, a foreign node's, an unstamped or unparseable file, the gating .rc, pinned.diff — is deleted, exactly what the blanket wipe deleted.
sweepStaleDiscovery(String workspaceDir, {required String circuitPath, required int round, required String sessionId}) → void
The generation-aware discovery sweep AnchorsCapability runs at the head of every round — the twin of sweepStaleCritique. It ensures discoveryDirPath exists and deletes every entry in it EXCEPT a lens report of THIS generation: a <lens>.json whose stamps pass the one shared fence (_freshLensReport) for the sibling node path <circuitPath>/<lens> at round, written by session sessionId. Everything else — a PRIOR SESSION's report, a PRIOR round's, a FOREIGN node's, an unstamped or unparseable file, and the previous round's anchors.json / dossier.json (neither carries a lens stamp, and the gather rewrites the first immediately) — is deleted, exactly what the blanket wipe deleted.
terminologyFindings(Map<String, List<String>> addedLines) → List<String>
Findings for kTerminologyBanRubric over the ADDED doc lines.
testDeclarations(String design) → TestDeclarations
Extracts TestDeclarations from design — the one extraction pipeline (_markTestCommandPaths → _markConfidentTestPaths → proseOnly → _collectTestDeclarations), reporting its three evidence buckets separately.
timerProbeSchedule(Duration period, void onTick()) → ProbeTicker
The real schedule: a Timer.periodic.
unresolvedAnchor(String anchor, {required String source}) → ResolvedAnchor
The ANCHOR that does not exist in the worktree — a COMPLETE negative lookup (the bead is naming NEW work, or a stale path). Shared by the offline gather and resolveAnchorOnDisk so both spell the same record.
usageEnvelopeJson({String? result, int? tokensIn, int? tokensOut, int? numTurns, String? model}) → String
Renders a harness-neutral FT-2 usage envelope — the SAME JSON shape UsageReport.tryParse and readEnvelopeResultText read out of claude's --output-format json result, so a CHANNEL harness's telemetry and its final text land in the step's durable result through the identical path (bead pow-39tl).
usageReportPath(String nodePath) → String
The workspace-relative usage-telemetry path for the step at nodePath — the --output-format json result envelope redirect target the harness writes and result() reads. The node path is sanitized for a filename (its / separators — and any other filesystem-hostile char — collapse to _), so tg-1/review/spec-adherence → .grid/telemetry/tg-1_review_spec-adherence.usage.json.
validationDiagnosticLines(String output) → List<String>
Every recognized validation diagnostic line in output, deduplicated in encounter order — the Dart front end repeats the SAME Error: once per test file it failed to load, so an undeduplicated lead would spend the whole budget on one cause.
validationPlanOffendingSlice(String plan, String diagnostic) → String
The EXACT text of plan a shell refused, given that shell's diagnostic.
verdictFromResultText(String? text) → Map<String, String>?
Recovers a verdict from a critic's captured output — the SHARED decoder for every caller that has the lane's answer as TEXT rather than as an artifact.
verdictJsonTemplate({required String rubric, required String nodePath, required int round, String rationaleHint = '<why>', bool owner = false, bool refinement = false}) → String
The verdict JSON SHAPE every critic prompt hands its critic — the TWO freshness stamps side by side: nodePath (A4's FOREIGN-NODE fence — WHOSE verdict is this?) and round (A15(5) alt-A's ROUND fence — WHICH round's?). rationaleHint lets a lane phrase its own rationale ask (the readiness lens wants the fix, not just the why) without forking the shape.
verdictRound(StepArgs args, {RoundDiagnostic diagnostic = _writeRoundDiagnostic}) → int
Reads the session circuit round injected under grid.round.
verdictWriteInstruction(String path) → String
Renders the mandatory same-directory atomic verdict-write contract.
verifiedContextNotes({required Iterable<ContextNote> notes, required Bead workBead, required List<PriorArt> priorArt}) → List<ContextNote>
Keeps only context whose bead attribution can be checked at assembly time.
verifiesBeadCitation({required BeadFieldCitation citation, required Bead workBead, required List<PriorArt> priorArt}) → bool
Whether citation exactly names evidence available to discovery.
withAdjudicationLog({required String revised, required String onDisk, required int round, required List<DesignAdjudication> adjudications}) → String
revised with this round's adjudication record appended under the ONE kAdjudicationLogHeading section, keeping every EARLIER round's subsection.
withReviewCircuitId(Circuit base, String circuitId) → Circuit
base with its kReviewStepId SubCircuitStep re-pointed at circuitId — the ONE difference between the code root shape and the docs root shape.
writeCapturedOutputLog({required String path, required String output}) → void
Writes output unchanged to path, creating its parent directories.
writeDiscoveryRegatherLedger(String workspaceDir, DiscoveryRegatherLedger ledger) → void
Writes ledger into workspaceDir. THROWS on a write that cannot land — the caller (DiscoveryRouteCapability) turns that into a LOUD RouteFailure: a regather whose round counter never advances would re-run the gather sub-DAG unbounded until the engine's belt fires (guards LOUD or GONE).
writeFixInFlight(String workspaceDir, FixInFlight carry) → void
Writes carry into workspaceDir. THROWS on a write that cannot land — the caller turns that into a LOUD RouteFailure. The guard protects a NAMED invariant (guards LOUD or GONE): the build brief reads the FILE, so an advance whose carry never landed would build a spec with its one known defect silently dropped — exactly the "every catch keeps its value" clause the ratified policy turns on.
writeRefinementFlag(String workspaceDir, RefinementFlag flag) → void
Writes flag into workspaceDir. BEST-EFFORT, deliberately — and the guard is GONE rather than silent (guards LOUD or GONE): the route ALSO carries every note on its own verdict (the refinement result key, and the gate reason on an escalate), so a note can never be lost by a failed file write. Failing a ROUND over a tracker-hygiene note would invert the very policy this flag implements ("never round-fail").
writeRespecLedger(String workspaceDir, RespecLedger ledger) → void
Writes ledger into workspaceDir. THROWS on a write that cannot land — the caller (SpecRouteCapability) turns that into a LOUD RouteFailure: a respec whose guidance never reaches the next brief would re-specify blind and re-park, which is precisely the toil this bead removes (guards LOUD or GONE).
writeUsageEnvelope({required String workspaceDir, required String usageOut, required String content}) → bool
Writes content to the workspace-relative usageOut under workspaceDir, creating the telemetry directory. FAIL-SAFE (the FT-2 property): any I/O surprise is swallowed, so writing telemetry can never fail, gate, or delay a run. Returns whether the file landed.

Typedefs

AcpModelResolver = String? Function({required List<String> available, String? current, required AgentTier tier, required String want})
The signature of resolveAcpModelId, so the resolver can be injected as a tear-off and a test composes the probe without a live catalog.
AgentPermissionAuditSink = void Function(AgentPermissionDecision decision)
Records one BRIDGE-LOCAL cancellation — an authorization the station never produced, so nothing upstream has recorded it yet.
AgentPermissionDecider = Future<AgentPermissionDecision?> Function(AgentPermissionRequest request)
Asks the station to decide one normalized permission request.
AnchorResolver = List<ResolvedAnchor> Function(String workspaceDir, List<String> anchors)
The pluggable ANCHOR resolution seam (mirrors RubricSource) — ONE call per round over EVERY anchor, so the tree is intaken exactly once. Defaults to resolveAnchorsOnDisk; tests inject a Fake so the offline suite never touches a real path.
ArtifactPathProbe = bool Function(String packageRelativePath)
Answers whether a package-relative artifact path exists.
BusLease = ({StationClient client, LeaseGrant grant})
A held bus lease: the bus client to the owner + the granted lease.
CommandExecutor = Future<CommandResult> Function(DispatchCommand cmd)
Runs a compute DispatchCommand and returns its CommandResult — the back-compat result-returning seam (a fake for tests / an in-process executor). Prefer ComputeSpawn for the real path so a timeout can REAP the process.
CommitteeClassifier = Future<({bool ok, String output})> Function(RuntimeConfig config)
The injected one-shot classifier seam — the SAME shape the delivery describe pass's runner answers with, so buildCodeRegistry adapts the existing InferenceRunner rather than growing a second process abstraction.
CommitteeDeterministicMatch = ({List<String> rubricIds, List<String> ruleIds})
What the deterministic half of the policy concluded: which rules fired and which SEMANTIC lanes they union to. Empty ruleIds is the UNKNOWN shape — the only case a classifier is ever reached for.
CommitteePinnedDiffPath = String Function(String nodePath)
Derives the ABSOLUTE pinned-diff path under a workspace — injected rather than imported, so this library stays free of committee.dart.
ComputeSpawn = Future<ComputeProcess> Function(DispatchCommand cmd)
Spawns a DispatchCommand as a reapable ComputeProcess. Injectable (default = realComputeSpawn); tests pass a fake so no process spawns.
DecisionIndexSource = Future<DecisionGatherEvidence> Function(String workspaceDir, List<String> rosterQualifiedSurfaces, Bead workBead)
The pluggable DECISION-INDEX seam — the composing station's roster-mode decisions index --surface <repo>/<path> verb, run ONCE per round over every roster-qualified surface. Absent ⇒ every surface is recorded EvidenceState.unavailable.
DirectoryClearer = void Function(String dir)
The pluggable critique-dir hygiene seam ClearCritiqueCapability uses (D-9-style injection, mirrors RubricSource) — defaults to the real delete+recreate; tests inject a no-op so the offline suite never touches a real filesystem at a synthetic workspace path.
EmbeddingHttpSend = Future<EmbeddingHttpResponse> Function(EmbeddingHttpRequest request)
Function-typed HTTP dependency used by every provider.
EmbeddingIndexOpen = Future<DoltEmbeddingIndex> Function({required String gridHome, required EmbeddingIndexIdentity identity})
EmbeddingSiteBindingLoad = EmbeddingSiteBinding Function(String path)
EnvironmentProbe = Future<bool> Function(EnvironmentProbeRequest request)
Whether request's environment is PRESENT on this box right now.
HistorySource = Future<HistoryEvidence> Function(String workspaceDir, List<String> resolvedPaths)
The pluggable HISTORY seam — one batched git log over the round's RESOLVED surfaces. Absent ⇒ the history record is EvidenceState.unavailable.
IndexBeadChangeKey = String? Function(Bead bead)
LaneEnvironmentDiagnosticProbe = Future<LaneEnvironmentDiagnosis> Function(LaneEnvironmentProbeRequest request)
A lane diagnosis, on demand. Injected — impls are DI; the real one is ProcessLaneEnvironmentProbe (environment_probe.dart).
LaneFlare = void Function(String name, Map<String, String> data)
The out-of-band flare sink, as a plain function.
LensReportReader = DiscoveryLensOutcome? Function(String workspaceDir, String lens, String lensNodePath, {required int round, required String sessionId})
The pluggable REPORT-READ seam — the route's only I/O (tests inject a Fake returning canned reports, so the whole matrix drives offline; absent ⇒ the real readLensReport).
ModelPriceTable = Map<String, ModelTokenPrice>
Model id → its declared token prices, keyed by the id resolveAgentConfig stamps into params['model'] (A20(3): every spawn is explicitly pinned, so the key is always known).
PriorArtSource = Future<List<PriorArtQueryEvidence>> Function(List<String> queries)
The pluggable PRIOR-ART seam — the deterministic space search pull, as one call over every query, answering with per-QUERY coverage. The composing station wires stationPriorArt (which resolves the roster from ITS resident-station context); absent ⇒ NO search runs and every query is recorded EvidenceState.unavailable (never a silent "no hits").
ProbeSchedule = ProbeTicker Function(Duration period, void onTick())
Starts a repeating period tick that calls onTick. Injected into AvailabilityAssets; the real one is timerProbeSchedule.
ProcessRunner = Future<ProcessResult> Function(String executable, List<String> arguments)
Injectable process seam matching the command invocation used by runRecall.
RelayFlareTailReader = Future<List<RelayFlareRecord>> Function(RelayObservation observation)
Reads the tail of the session's flares (flares.read). Injected.
RelayGateReader = Future<RelayGateRecord?> Function(RelayObservation observation)
Reads the session's open gate, if any (gates.read). Injected.
RelayTelemetryReader = Future<List<RelayTelemetryRecord>> Function(RelayObservation observation)
Reads the session's captured usage telemetry (telemetry.read). Injected.
RelayWorktreeReader = Future<RelayWorktreeSnapshot> Function(RelayObservation observation)
Reads the session's worktree evidence (worktree.read). Injected.
RoundDiagnostic = void Function(String dir)
Receives one diagnostic emitted while resolving a verdict freshness round.
RubricSource = String Function(String workspaceDir)
A pluggable source of a rubric's prose text by id (D-9: the Packaged-AI-Asset loader replaces the inline placeholder). Returns the rubric body a critic's prompt embeds.
SeatProcessRunner = Future<int> Function(SeatLaunch launch)
Runs one planned SeatLaunch and returns the child's exit code — the ONE IO seam the verb has, so a test drives the whole loop with a Fake and no harness is ever spawned.
SemanticSearchBackendMount = Future<SemanticSearchBackend> Function(String gridHome)
SpecLane = ({String? grade, String id, String owner, String rationale, String refinement})
One committee lane's raw result, as the route reads it off its verdict source: its rubric id, its grade (null/blank ⇒ MISSING ⇒ fail-closed to F), its rationale (blank when the critic returned none), its OWNER (blank when the lane names none — see decideSpecRoute arm 5), and its REFINEMENT — the lane's BEAD-GRAPH observations, which decideSpecRoute never reads (bead pow-bhm).
SubstationFactsRepositoryFactory = SubstationFactsRepository Function({required GridAssetRegistry registry, required Map<SubstationKey, String> roots})
Creates the fact observer for roots over registry — the injectable OBSERVATION seam (impls are DI); the default is the real filesystem one.
TestDeclarations = ({Set<String> authored, Set<String> fallback, Set<String> mentioned})
A design's confident test paths, split by the EVIDENCE that named them.
UsageFlare = void Function(String name, Map<String, String> data)
The EMIT-ONLY observation sink the fail-safe usage parse names a problem through — the ExplorationTransport.flare shape (D-8), taken as a function so this codec stays dependency-free and fixture-testable with no transport.

Exceptions / Errors

AcpModelResolutionFailure
The TYPED refusal a null resolveAcpModelId earns at session setup (bead pow-u1bi).
ComputeBoundsException
Thrown when a DispatchCommand is REFUSED by the compute bounds: the executable is not on the allow-list, or the command is empty. A hard refusal — the lessor never runs an out-of-bounds command (ADR-0011 Hazards).
EmbeddingClientError
A loud embeddings wire or response-shape failure.
EmbeddingIndexIdentityMismatch
Thrown at open time when an existing index was built by another identity.
EmbeddingProviderRegistryError
A provider declaration or mount-time configuration refusal.
EmbeddingSiteBindingError
A missing endpoint fact requested from an embedding site binding.
EnvironmentRegistryError
A LOUD, fail-closed refusal (ADR-0000 A8 "guards LOUD or GONE") thrown by EnvironmentRegistry.resolve (moment 2): an unknown environment name, a base cycle, or a dangling base. Its message names the environment, the missing thing, and the fix. Mirrors SiteBindingError.
GridBlockException
A LOUD refusal from the grid: block reader.
RouteFailure
A route body's failure — its reason rides the node's failureReason unmodified (beyond the engine's route threw: prefix).
SeatDiscIntegrityException
The disc's INDEX does not cover the notes beside it — what SeatDisc.verifyIndexIntegrity throws.
SeatHandoffWriteException
A handoff write REFUSED — what SeatDisc.writeHandoffOnce throws instead of amending, appending to, or overwriting a note that is already there.
SiteBindingError
A LOUD refusal (ADR-0000 A8 "guards LOUD or GONE"): an armed environment's inference endpoint is UNBOUND on this box. Thrown by SiteBinding.endpointFor; its message names the environment, the missing fact, and the fix.
StalePackageGraphException
A lockfile whose packages are not all present in package config.
StationAssetRegistryException
A malformed station graph or participating package.
ValidationLaneFailure
A comparison that could not produce comparable named-test outcomes — a LANE failure with a named cause, never a bead block.
ValidationPlanShellMissing
The named refusal for a parse shell that is NOT INSTALLED — distinct from a shell that ran and crashed, because only one of those says anything about the plan.