Priority: P0
Labels: correctness, privacy, domain-model, release-blocker, dmcheck
Confidence: 99%
Solution confidence: 92%
Evidence
- R1 treats a player question immediately following a GM-authored row as GM-directed rather than using directed audience evidence; a player-to-player question can be charged to the GM.
- R2 treats any dice-bot line as a roll and any GM row within the configured forward window as acknowledgment.
- R3 treats any later GM message as narration and may not run without later GM messages.
- R8 labels recent threshold findings “unresolved” without tracking lifecycle.
- R6 outputs the exact hidden term in detail and raw evidence.
Scope / specification
Represent directed question, roll, narration, and recovery as typed obligations with immutable IDs and explicit audience/correlation. Heuristic text-only detection must be inferred/advisory with confidence and cannot silently close an observed obligation. R8 reports actual open obligations at closure. R6 uses an opaque host-issued secret ID or keyed HMAC whose key is unavailable to the evaluated agent/output sinks; a plain hash is dictionary-recoverable for low-entropy spoilers. Raw access is a separate trusted/role-scoped operation.
Acceptance criteria
- Unrelated later messages do not close obligations.
- In live mode, an overdue uncorrelated obligation remains OPEN. At explicit close it becomes a finding only when the required evidence was observable; otherwise the top-level result is
incomplete.
- Bot status/errors do not become rolls; roll result/request/narration share one ID.
- Player-to-player and public questions are distinguished by audience evidence or marked uncertain.
- Default CLI/JSON/MCP/log/hook output contains no secret term or revealing excerpt.
- Each finding includes the complete effective machine-readable rule parameters used plus charter version/digest; R7, for example, must disclose all quiet-table predicates, not only
dead_air_seconds.
- R8 derives from lifecycle state, not transcript quartile.
Required tests: interleaved concurrent rolls/questions/events; missing tail; unrelated GM text; bot error; audience ambiguity; secret variants/case/Unicode; output snapshot redaction across every sink.
Dependencies: secret redaction and conservative correlation patches land immediately; typed obligation migration depends on PORT-002/PORT-004.
Priority: P0
Labels:
correctness,privacy,domain-model,release-blocker,dmcheckConfidence: 99%
Solution confidence: 92%
Evidence
Scope / specification
Represent directed question, roll, narration, and recovery as typed obligations with immutable IDs and explicit audience/correlation. Heuristic text-only detection must be
inferred/advisory with confidence and cannot silently close an observed obligation. R8 reports actual open obligations at closure. R6 uses an opaque host-issued secret ID or keyed HMAC whose key is unavailable to the evaluated agent/output sinks; a plain hash is dictionary-recoverable for low-entropy spoilers. Raw access is a separate trusted/role-scoped operation.Acceptance criteria
incomplete.dead_air_seconds.Required tests: interleaved concurrent rolls/questions/events; missing tail; unrelated GM text; bot error; audience ambiguity; secret variants/case/Unicode; output snapshot redaction across every sink.
Dependencies: secret redaction and conservative correlation patches land immediately; typed obligation migration depends on
PORT-002/PORT-004.