Status: Active — Claude/Codex両host対応と実Throughline CLI統合を進行中
作成日: 2026-07-14
製品契約: 00_product-contract.md
この文書は作業の現在地だけを管理する。製品仕様、非目標、廃案、恒久規約は製品契約またはAGENTS.mdを正とする。
completed-turn境界の初期未確定事項は解消済み。Claude側の完了証拠、Stop hook、60秒超wait、continuation、停止方法はP0-6で実測し、Codexの挙動から推測しない。Codex native childのread-only不成立はP2-5 blockerとしてADR 0008で分離する。
- 当初のThroughline変更holdは、オーナーの続行指示により解除済み。
- Throughline側は自身の
docs/14_observer_completed_turn_feed_plan.md、独立Control、独立gate、独立commitで進める。 - Observerは公開
observer-read/observer-waitCLIだけを利用し、ThroughlineのDB/WAL/libraryへ依存しない。
- foundation wave
observer-independent-foundation-20260714はbounded worker budgetを使い切ったため、 ADR 0016の受入表でarchiveし、Codex host adapter以降をobserver-codex-host-runtime-20260715へ継続する。これはObserver全体またはPhase 2の完了宣言ではない。 - Control finalizationのdigest証拠には可変な本planを使わず、immutable ADRを使う。
- queue 19eの訂正Control
observer-p5-1b5-dual-host-live-20260716は、process-group cleanup、 pre-ready recovery、修理後HEADの回帰、独立重監査を ADR 0144で受け入れてfinalizeする。
-
P0-1 Observerのベースラインを確定する。
- 成果物: repo状態、runtime候補、package / test / CI候補を記録した設計メモ。
- 完了条件: 初期化操作、標準検証コマンド、H操作が分離されている。
-
P0-2 Throughlineの現行契約を実コードで特定する。
- 成果物: read入口、turn schema、cursor、project path、Done保存経路のファイル・呼出経路一覧。
- 完了条件: fixtureまたは実データで、
task_complete済みturnと現行DB projectionの差を再現し、完了証拠を裁定できる。
-
P0-3 Codex親Stop hookを実測する。
- 成果物: 正式event名、payload、session / cwd情報、stdout / stderr / exit codeの観測記録。
- 完了条件: boundedなJSON reasonを同じ親turnのcontinuation promptとして注入できるか、できないかを再現手順付きで裁定できる。
-
P0-4 Observer継続turnを実測する。
- 成果物: timeout後、同じObserver turnをStop continuationで再開する候補比較と、MCP wait transport実測。
- 完了条件: project-local Stop continuationとMCP tool callの60秒超live waitを再現し、失敗、再開、停止方法を説明できる。
- 実測: 65秒timerのMCP呼出しがCodex上で正常完了した。サーバー計測は時計境界により64,999msだったが、60秒超のhost保持という検証目的を満たす。途中取消はtimeoutでなくMCP承認要求が原因で、read-only注釈と対象tool限定の明示許可が必要。
-
P0-5 v1実装契約と安全網を固定する。
- 成果物: 採用API、state path、runtime、検証コマンド、characterization test一覧。
- 完了条件: 未確定事項3件が解消または明示的blockedになり、反対仮説の検証を一回通過する。
- 裁定: Throughline JSON CLI + Observer MCP adapter、macOS owner-only state、
emitted_unackedreceiptを採用。DB直接監視、Throughline本体のMCP所有、cross-platform見せかけ、Host ack見せかけを棄却した。
-
P0-6 Claude親/Claude Observerのhost境界を実測する。
- 成果物: Claudeの完了turn証拠、正式Stop event/payload、project/session identity、60秒超wait、同じturnへのcontinuation、明示停止の再現記録。
- 完了条件: Claude Observerと親Claudeへの配送を、Codex wireの流用や推測なしで実装できる。
- 部分実測: Claude Code 2.1.207でheadless
result/end_turn、同じsession IDのresume、SessionStart:resumeを確認した。2.1.210ではbackground jobが75秒までworkingを維持し、90秒timer中の実行中stop、子process消滅、project fingerprint不変を確認した(ADR 0011)。daemon/adapter crash後の結果回収は未検証。完了turnはfinal assistantやprocess exitでなく、Throughline所有のStop receiptへ束縛する。/rewindはforkなので同一session rollbackを新設しない。 - 上記は旧background job候補の基礎characterizationである。後続の隔離liveではjob
sessionId/Stopsession_id相関と Stop hook発火までconfirmedとなったが、canonical resultは拒否され、既存background jobへの 公開非対話requestとterminal exact result readはunsupportedと確定した (ADR 0114)。 ただしClaude Observer全体をblockedとはせず、永続PTY上のAitermclaude_agentを新しい公開transport 候補とする(ADR 0115)。
-
P0-7 Observerのprovider配置と役割を固定する。
- 成果物: Codex親→Codex Observer、Claude親→Claude Observerという同provider契約と、継続的反証ではない伴走者契約。
- 完了条件: 一般Workerのrate-aware配置、異社相談役、Phase反証とObserverを文書上で分離する。
-
P0-8 Observerの起動責任とlifecycleを固定する。
-
P0-9 Observer repoへCodegraph project indexを導入する。
- 発見経路: provider binding計画の構造調査で、CLI/MCP登録は済んでいる一方、Observer固有の
.codegraph/が未初期化だったため構造queryを利用できなかった。 - 成果物: upstream正規入口
codegraph initが生成する、共有可能な設定と端末local index。 - 完了条件:
codegraph status --jsonがinitialized=true、対象projectがObserver root、pendingChangesが空、SQLite journalがwalを返し、生成された設定だけが追跡候補になる。 - rollback:
codegraph uninitでObserver固有の.codegraph/だけを除去する。 - 実測: Codegraph 1.4.1で60 files、1,339 nodes、5,603 edgesをindex化した。statusは
initialized=true、journalMode=wal、pendingChanges=0、reindexRecommended=false。 provider bindingの構造探索も実sourceとblast radiusを返した。DBは.codegraph/.gitignoreにより 端末local、生成されたignore metadataだけを追跡候補にする。
- 発見経路: provider binding計画の構造調査で、CLI/MCP登録は済んでいる一方、Observer固有の
Gate: Aiterm claude_agentの非H契約・operation相関付き結果回収・timeout recoveryは
dd43c40/3842ff2、related 122/122、full 262/262、独立反証P0/P1/P2残存なしで完了した。
P5-1b4の非H caller coreは完了した。次はP5-1b5 dual-host live Hであり、実Claude初回/follow-upは
同H gateまで成功扱いしない。
-
P1-1 Throughline側に独立した正本プランを作る。
- 成果物: Throughline repoの
docs/に置かれたcompleted-only read / wait API計画/TODO。 - 完了条件: opaque cursor、最新thread解決、delta / switch / resync、競合窓、timeout、cancel、再接続、test、rollbackがThroughlineの所有契約として定義される。
- 正本:
/Users/kite/Developer/Throughline/docs/14_observer_completed_turn_feed_plan.md
- 成果物: Throughline repoの
-
P1-2 Throughline側の計画完遂を確認する。
- 成果物:
observer-wait、observer-readとThroughline側test。詳細TODOはThroughline側正本で管理する。 - 完了条件: Claude/Codex両hostでin-flight除外、即時changed、待機changed、timeout、呼出競合、thread/host switch、rollback、再起動のgateがThroughline repoでgreenになる。
- 成果物:
-
P1-3 Observerからblack-box検証する。
- 成果物: Observer MCP adapterからThroughline公開CLIだけを使うcontract test。
- 完了条件: 短縮timeout fixtureでchanged / timeout / missed-wakeup防止を再現し、Throughline実CLIを通した65秒超live callと3600秒設定が受理される。
-
test/throughline-black-box.integration.mjsから実Throughline CLIだけを起動し、待機中changed、 1秒timeout、呼出前completionの即時changed、DB未projection時のprojection_pendingを2.27秒で固定した。 Throughline側の隔離HOME black-boxで65秒超live changedと3600秒設定は確認済み。Control revision 49で親受入済み。 - Observer MCP adapterを実装し、同じblack-box境界をMCP tool wireから通す。
- MCP 2025-11-25/2025-06-18のinitialize、固定
observer_read/observer_wait、active watch identity、 structured/text result、cancel/stdin shutdown、stdout衛生をADR 0013へ固定した。node --test test/mcp-server.test.mjs test/throughline-client.test.mjsは10/10 PASS。
- MCP 2025-11-25/2025-06-18のinitialize、固定
-
P1-4 標準testと実Throughline統合testの実行境界を分離する。
- 成果物: 外部CLIなしでgreenになる標準
npm testと、実CLI pathを明示してfail loudに実行する統合test script。 - 完了条件: 標準gateが統合testをskip扱いで隠さず除外し、明示統合gateでは既存black-box 1件が実Throughline CLIでPASSする。
- 成果物: 外部CLIなしでgreenになる標準
Gate: ObserverがThroughlineのDB / WALへ依存せず、新規turnを失わず待てる。
-
P2-1 Observerプロジェクトを初期化する。
- 成果物: runtime、package、lint、unit test、CIの最小構成。
- 完了条件: 空実装のbaseline gateがgreenで、rollback可能な独立単位になる。
- 実装: Node ESM / Node 22.13以上、runtime dependencyなし、Node test runner、構文検査、GitHub Actionsを追加。標準gateは
npm test && npm run check。 - Control証跡:
observer-scaffold-runは、初回baselineを親が同じworkspaceで確立したためWORKSPACE_DRIFTで失敗した。このRunを成功・acceptedへ変更しない。P2-1の完了根拠は親が独立に検証した16 test greenとroot commit7b699c8であり、Taskobserver-scaffoldだけを本項参照でfinalizeする。
-
P2-2 project target登録を実装する。
- 成果物: canonical project resolver、
observer target register <absolute-project-root>、Observer所有state。 - 完了条件: 同じprojectを安定したtargetへ解決し、別projectと混同せず、working treeを汚さない。
- 実装: canonical pathのSHA-256からtarget IDを生成し、macOSの中央stateへ0700/0600でatomic登録する。相対path、symlink state、不正permission、非macOS defaultをfail closedで拒否する。
- 成果物: canonical project resolver、
-
P2-3 最新親スレッド解決を実装する。
- 成果物: Throughlineのhost-bound確定turn時刻から現在親とhostを選ぶresolver。
- 完了条件: 親AからBへのthread切替と、Claude/Codex間のhost切替fixtureで、Bの最初の確定turn後にだけ追跡先がBへ切り替わる。複数活動親はfail closedにする。
- v1境界: ADR 0001。一般的なactive leaseをmtime/PID/TTLで
推測せず、一project一活動親を前提にする。Throughlineが返す
ambiguous_parentはfail closedにする。 - 実装: hash-only parent state、snapshot/delta/thread/host切替、cursor連結、pagination transaction、
projection_pending/ambiguous_parent/resync_requiredのfail-closed境界を実装した。 - 検証:
node --test test/parent-resolver.test.mjs5/5 PASS。commit91e51bd、Control revision 8。
-
P2-4 一時間wait loopとcursor回復を実装する。
- 成果物: host-neutralな
observer watch <absolute-project-root>、active watch transaction、親別launcherと、Claude/Codex adapterでchanged / timeout / restartを処理する監視loop。 - 完了条件: ユーザー明示指示を受けた親だけが同provider Observerを一体起動する。外部Supervisorが一target一processで wait/read/cursor/model operation/applyを所有し、timeoutではAIを起動せず同じcursorから次のbounded wait stepへ戻る。 二重起動、transport / schema / state failureではfail closedまたはfaultedになり、takeover、自動再起動、provider request再送を行わない。
- Throughline公開CLI clientと、cursorをまだ保存しない一監視cycleを実装する(ADR 0003)。
- bounded JSON、UTF-8 byte収集、strict schema、Abort時のSIGTERM→SIGKILL terminal cleanup、 orientation/timeout/fixed-through pagination/projection pendingを実装した。
- 検証:
node --test test/throughline-client.test.mjs test/watch-cycle.test.mjs9/9 PASS。 commitf3bfef1、Control packete4cf0531…2cc8、revision 17。
-
projection_pendingbounded retry、監査後のcursor atomic commit、crash recoveryを実装する(ADR 0005)。-
prepared → processed → cursor commit → cleanupのjournal store、full-state CAS、crash recoveryを実装した。 検証:node --test test/cycle-store.test.mjs5/5 PASS。commit845c002、Control revision 19。 - watch cycle、bounded retry、監査callback、journal recoveryをSupervisorへ配線した。
通常changedとprepared recoveryのどちらも最初のfixed-through cursorから範囲を拡張せず、
durable callback結果の検証後だけ
processed保存とcursor commitを行う。 検証:node --test test/watch-cycle.test.mjs test/supervisor-cycle.test.mjs12/12 PASS。 commit181a54e、Control packetb29a9761…65fe、revision 26。
-
- 一target一active watch transactionと明示stopを実装する(ADR 0004)。
- provider child前の
starting予約、二重起動拒否、watch ID CAS、private handle非公開、active → stopping → stopped、fault、明示nonce lock回復を実装した。 - 検証:
node --test test/watch-store.test.mjs7/7 PASS。commite0a1843、Control revision 14。
- provider child前の
- 公開
observer watch/watch start|status|stopを両provider共通の非H lifecycle handlerへ接続する (ADR 0095)。- 利用者入力をabsolute project pathだけに保ち、現在親のprovider/runtime/authorizationとhost actionを argv外のexact contextへ分離する。
- startのreserve→spawn receipt耐久化→ready、sanitized status、terminal receipt後だけのstop完了を、 Claude/Codex共通result schemaとfake host actionで固定する。
- 実装
a4195a3、focused 13/13、関連37/37、static greenを ADR 0096で受け入れた。
- dotagents/installerから実host actionを注入し、live spawn/stop、session相関をP5-1bのH gateで受け入れる。
- Codex/Claude親launcherと同provider child lifecycleを実装する(ADR 0006、起動順序の訂正=ADR 0007)。
- explicit authorization、
starting → launching → active、private provider handle、相関付きstop/fault transactionを実装した。 検証:node --test test/parent-launch.test.mjs test/watch-store.test.mjs16/16 PASS、cycle-store fixture 5/5 PASS。 commits1ed545c、ed4f077、Control revision 32。 - unrestricted Codex親ではcustom agentの
read-onlyが実効sandboxにならないことを実測し、native Observerを禁止した(ADR 0008)。 - Codex persistent app-server thread候補/Claude backgroundの親host adapter、同provider Observer role、routing検証を実装する。
- 全hostの
cwdをcanonicalなObserver rootへ固定し、targetproject_rootをhost cwdや擬似projectへ使わない製品identityを固定した(ADR 0017)。AGENTS.mdを両host共通の静的Observer契約、CLAUDE.mdをClaude固有差分の入口にする。- watchごとにthread/jobは分けても、監視対象ごとのtemporary repo/アプリprojectを生成しない。
- 実行時契約は検証済みchild start envelopeの時だけ発火し、Observer開発AIの権限と分離する。
- Codex app/Claude UI表示と既存の不要project cleanupは未検証のH gateとして残す。
Claude backgroundはexact tool allowlistでproject readとwrite拒否、job handleの
working → done、同handle stopを実証した。 argvの可変長flag順序とterminal後のlogs回収不能をADR 0010でadapter契約へ固定した。
- Claude adapterの純粋coreとして、絶対CLI path、固定prompt位置、Observer MCPのruntime-root字句境界、公開/無人許可の分離、
job相関、terminal先行stop、raw出力非保持を実装した(ADR 0012)。
検証:
node --test test/claude-host-adapter.test.mjs test/parent-launch.test.mjs14/14 PASS。 - 実行層でClaude CLI/Observer MCP executableのrealpath・version・所有を検証し、spawn/observe/stopをparent-launchへ配線する。
src/claude-host-runtime.mjsでmanifest固定path、file identity/digest、Claude 2.1.210、MCP 0.0.0、 exact tool surfaceを検証し、handle先行耐久化を守る分離runtimeを実装した(ADR 0015)。- Claude
--bgのshort IDをspawn直後に耐久化し、observe/readyを同じ関数へ畳み込まない。 - MCP tool surfaceは実装済みの
observer_read/observer_waitだけへexact固定し、wildcardを許さない。 - ADR 0060の所有権訂正によりproduction Observer AIの
tool allowlistを空へ変更した。MCP server自体は削除せず、compatibility/diagnostics裁定を後続Taskへ残した。
-
claude-host-runtimeの旧MCP allowlist期待を空surface契約へ揃えた。commitd34b119、 失敗scopeのfocused 1/1がgreen。直前関連gateの他65件は同じproduct filesでgreenだったため再利用し、66/66へ収束した。
-
- spawn結果不明時はwatch固有nameとcwdから回収し、同じwatchを再spawnしない。
- 検証: focused 23件、parent-launch接続7件、
npm run check、実binary read-only diagnosticsがgreen。
- Claude
- Codex app-serverの純粋adapterとsession runtimeをparent-launchへ配線した(ADR 0018)。
thread/start結果不明は同一cwdの候補へattachせずthread_start_unknown、turn/start結果不明はturn_start_unknownとして耐久化し、同じwatch/cycleの再実行を拒否する。- thread IDをwatch handle、turn IDを別operation journalへ保存し、親stateへthread handleを耐久化してからだけ
turn/startする。thread/readとthread/resumeをterminal照合/継続購読に分離する。 - interrupt ACKではwatchを閉じず、同じthread/turnのterminal receiptをparent-launchで必須化した。
interrupt結果不明でも送信前に
stoppingを耐久化し、同じturnへ再送しない。 - focused gate:
node --test test/codex-host-adapter.test.mjs test/codex-host-runtime.test.mjs test/parent-launch.test.mjs— 23/23 PASS。 - app-server process transport、実model turn、UI、65秒超wait、crash後のunknown reconciliation、Observer MCP限定writeは 未検証のH/後続gateであり、production採用済みとはしない。
- Codex app-serverのbounded JSONL process transportを実装した(ADR 0019)。
- Codex executable identityとversionをObserver rootで確認し、
codex app-serverをshellなし・環境allowlistで生成する。 - request IDとresponseをexact相関し、未知/重複ID、oversize/不正JSONL、stderr/process終了をfail closedにする。
- pending requestの切断は成功や自動retryへ丸めずunknownとして返し、同じlogical operationの再実行判断は
codex-host-runtimeのdurable journalへ委ねる。 - fake child processのfocused testだけをこのTODOのgateとし、実Codex process/model turnは起動しない。
- focused gate:
node --test test/codex-process-transport.test.mjs test/codex-host-runtime.test.mjs— 15/15 PASS。
- Codex executable identityとversionをObserver rootで確認し、
- parent session epochごとに一論理Observerを束縛し、同epoch内のcontext budget到達では
一つの物理host generationだけをterminal確認付きで世代交代する。
- watch authorizationは維持し、新しいwatchやtarget別projectを生成しない。
- generation counter、completed cycle count、累積bounded input bytesを独立durable stateに持ち、 8 completed cycle/262,144 model-visible UTF-8 bytesのhard thresholdとmodel前reservationを固定した (ADR 0034、ADR 0035)。
- cycle pending v2、input reservation、cursor/generation commitをexact-once接続し、各write間の crash recoveryと非永続inputを固定した(ADR 0036、 ADR 0037)。
- cursor、dedupe/cooldown receipt、boundedな未解決仮説だけを引き継ぎ、raw会話/tool logは保存しない。
- watch継続の短命host journal、旧terminal確認、旧→新handle CAS、ready後activation、 Codex generation namespace、Claude live候補限定をfake fixtureで実装した (ADR 0038、 ADR 0040)。
- 上記record-first coreをClaude/Codex固有のterminal stop/次generation start commandへ接続する。
- raw handleを出さないrecovery contextと、watchを再遷移させないCodex generation runtimeを先行実装した (ADR 0042、 ADR 0043)。
- recovery contextを使うClaude/Codex provider bindingを、一command一stepで実装する
(ADR 0044)。
- Codexの再送なしterminal観測APIを実装する。
- commit
b06a847。同一generationのdurable thread/turnだけをread-only照合し、 terminal/pending/unknownとraw-free receiptを返す。
- commit
- host-neutral provider binding step machineを実装する。
- commit
02329ad。一call一provider mutation、stop再送なし、provider ready後の core spawn/ready適用、unknown fail-closedを固定した。
- commit
- 隔離した2 Workerの成果を本線へ統合し、focused gateを通す。
- 関連gate 46/46、
npm run check、git diff --check成功。両TaskはControl revision 29までに ADR 0046でfinalizeした。
- 関連gate 46/46、
- Codexの再送なしterminal観測APIを実装する。
- model request送信結果不明をhost lifecycleと別journalで回収する
(ADR 0047)。
- generation reservationより先にhost-neutral model operationを
preparedで耐久化し、prepared -> reserved -> dispatching -> accepted -> completed -> appliedの一方向遷移と identity conflictを実装する。- commit
4c3cc03。exact cycle result、UTC時刻非後退、private path/lock、status限定cleanupまで focused 8/8で固定し、ADR 0049で受け入れた。 - Supervisor統合前の独立反証で見つかったlock残留、completed result locator、planned rollover、
processed前cleanupの4件をADR 0051どおりcorrective実装する。
- commit
8afebca。same/next generationのprepared回収を含むfocused+related 27/27、npm run check、scoped diff-checkを通し、 ADR 0053で受け入れた。
- commit
- commit
- Supervisorを
issue_once/recover_only/idempotent applyへ分け、dispatchingからmodel requestを 再送せず、strict parse済みcanonical AI outputだけをcycle processedへ移管する (ADR 0050)。- commit
c226cc9。focused 15/15、関連gate 47/47、npm run check、scoped diff-checkを通し、 ADR 0054で受け入れた。
- commit
- prepared/reservation/provider handle/canonical result/apply/processed/cleanup間の crash matrixをfocused fixtureで固定する。
- Claude/Codexのexact operation result readをprovider固有journalへ実装し、handle欠損を
別operationへの再送で隠さない(ADR 0055)。
- Codexは保存済みthread/cycle turnの
thread/readだけからexactagentMessageitemを再読する。 Claudeはjob/sessionを 束縛したStop.last_assistant_messageをhook中にcanonical保存する。 logs/transcript/private provider state/別turn/別job/新規requestへのfallbackを禁止する。- provider journal coreとfake public-surface fixtureを先に受け入れるが、この時点では本TODOを閉じない。
現行profileへObserver所有hookだけを注入するhost adapter接続、Codex item baseline、
両host session/turn相関、Supervisorの
complete -> provider cleanup -> applyを続けて実装する。 - Claude job
sessionId/Stopsession_idの一致、Codex hook trustとin-progress item再読はlive H gateで version固定し、未実証をproduction対応済みにしない。 - SUPERSEDED: host-neutral canonical cycle requestとCodexの
thread/read baseline -> turn/steer -> ACK -> accepted journalfixtureをcommit1bb7b07、 focused 22/22、Supervisor関連16/16、ADR 0059で 受け入れたが、AI wait loopとSupervisorの二重所有およびStop idle問題が判明したため、 ADR 0060でturn/steer/Stop continuation部分をsupersedeした。 canonical requestとprovider journal欠損補正は維持する。 - 外部Supervisor単一所有とCodexの
thread/read context -> cycle turn/start -> ACK -> accepted journalをcommit3f35dbbでcorrective実装した。 focused 38/38、Supervisor関連16/16、static gateを通し、 ADR 0061で受け入れた。 - Codex production Supervisor callerを接続し、cycleごとのsession/turn/exact result順序をlive H gateで固定する。
-
applyCycle/finalizeAppliedCycleのproduction callbackをcommitfc51157で実装し、durable operation時刻とcanonical cycle inputからadvisory messageを決定的に再構成してMailbox exact replay/ cleanupへ接続した。focused 4/4、関連40/40、static gateを通し、 ADR 0063で受け入れた。 - 一target一process lock、evidence input、Codex provider callback、sanitized production receiptを
束ねる一step callerをcommit
0ca7abeで実装した。focused 4/4、関連44/44、static gateを通し、 ADR 0065で受け入れた。 - verified Throughline clientとpre-initialized Codex app-server sessionを所有する外部process/CLIへ
一step coreを配線し、timeout/cancel/fault/explicit stop loopを固定する。
- target固有process lease、active watch停止監視、timeout/model pendingのbounded反復を
host-neutral process loopとして実装する。
model_result_unknownは回収不能なterminal faultとしてpollせず停止する(ADR 0067)。 - Throughline executableとCodex app-serverを一process内で検証・初期化し、終了時にCodex childの terminal確認を必須化する。子process残存や終了不明を成功へ丸めない。 app-server faultは進行中Throughline waitへ即時伝播する(ADR 0068)。
-
observer supervisor runCLIをabsolute command/watch identity/Observer rootへ束縛し、 signal cancel、explicit stop、faultのJSON/exit contractをfocused fixtureで固定する。 - focused/related gateを通し、ADR 0069と 独立commitへ固定する。corrective変更後の最終関連gateは70/70、static gateはgreen。
- repo正典に残っていた旧AI-owned wait/Stop continuation/Observer MCP公開の記述を、 ADR 0060の外部Supervisor単一所有とproduction AI exact-empty tool surfaceへ補正する。
- target固有process lease、active watch停止監視、timeout/model pendingのbounded反復を
host-neutral process loopとして実装する。
-
- 旧Claude background job経路のblockedを維持し、Aiterm公開対話transportをClaude callerへ接続する。
- P5-1b3の非H準備、live H、production callerを分離し、親Mailbox hookを result captureへ流用しない契約をADR 0109で固定した。
- characterization専用の隔離Stop capture、sanitized receipt、 prepare/verify/cleanup harnessをfixtureで閉じた(ADR 0110)。
- 専用runbookに従い、
一つのClaude jobでlive H characterizationを実施した。jobは
done、cleanupと project/host settings不変はconfirmedだが、Stop capture欠損、reply/terminal exact result非公開により接続はblockedとした(ADR 0111)。 - Stop未発火とpayload/result不正を区別するraw-free diagnostic receiptを 非Hで実装し、focused 9/9、related 29/29で受け入れた (ADR 0113)。
- diagnostic receipt受入後、別H承認で一つのjobだけを再characterizeした。
hook invocation、job/session、Stop payloadはconfirmed、canonical resultは
E_CLAUDE_CHARACTERIZATION_RESULT_INVALID、公開reply/terminal exact resultは unsupportedであり、接続はblockedのままとする (ADR 0114)。 - Aitermの永続PTY
claude_agentへ置き換え、operation相関付きexact resultと timeout後無送信回収を非H gateで閉じた。次はP5-1b4でproduction callerへ接続する。
- Codexは保存済みthread/cycle turnの
- Mailbox publishをdeterministic message IDの同内容replayだけ冪等成功にし、異内容をconflictにする
(ADR 0048)。
- 既存
publishMessageのduplicate拒否は維持し、model operation専用publishOperationMessageと raw-freeなpublish-receipts/を追加する。 - receiptを
preparedでrecord-first作成し、inbox/processing/consumer receiptからexact digestを回収する。 - model journalの
applied後だけpublish receiptをcleanupし、それまでは対応するconsumer receiptをretention対象外にする。 - commit
0e7a005。focused 15/15、npm run check、scoped diff-checkを通し、 ADR 0052で受け入れた。
- 既存
- generation reservationより先にhost-neutral model operationを
- parent rebind、planned rollover、fault recoveryを別transition/receiptにして統合する。
- planned rolloverを既存generation host journal/provider bindingから
Supervisor processへ接続し、同じverified runtimeで一stepずつ回収して
新generation activation後にprepared cycleへ戻る
(ADR 0070)。
- 実装commit
2bfc09c。focused 43/43、関連gate 103/103、npm run check、git diff --checkを通し、ADR 0071で受け入れた。 実provider commandのH受入はPhase O2 gateへ残す。 - Codex terminal観測時にraw-free receiptをhost terminalへ再構成せず、
already-terminal stop経路のexact receiptだけをcoreへ渡す
(ADR 0080)。
- 補正前focused 4/5で
E_PARENT_HOST_RECEIPTを再現し、commitfe4f743で修正した。 focused 6/6、npm run check、git diff --checkを通し、 ADR 0081で受け入れた。
- 補正前focused 4/5で
- 実装commit
- parent epoch切替を旧generationへのmodel requestなしで明示
rebind_requiredtransition/receiptへ記録し、parent authorizationと terminal確認後だけ新epochを開始する(ADR 0072)。- host-neutral rebind transaction、new epoch generation、watch provider/handle CASを実装する。
- commit
426f8b9。focused 21/21、関連gate 83/83、npm run check、git diff --checkを通し、ADR 0073で受け入れた。
- commit
- Claude/Codex provider bindingを一command一stepで接続した
(ADR 0075)。
- provider recovery contextをauthorization/launch request digestへ再束縛し、
Codex turn-start unknown再送と不完全terminal receiptを補正する
(ADR 0074)。
core correction
d7ebdbb、provider binding3a737ad。focused 6/6、関連66/66、npm run check、git diff --cached --checkがgreen。
- provider recovery contextをauthorization/launch request digestへ再束縛し、
Codex turn-start unknown再送と不完全terminal receiptを補正する
(ADR 0074)。
core correction
- Supervisor processへ接続し、new epoch activation後にprepared cycleへ戻る
(ADR 0076、
ADR 0077)。
実装commit
107d2ca。focused 33/33、関連122/122、npm run check、git diff --checkがgreen。 - 実thread/host switchとcrash recoveryをPhase O2 H gateで受け入れる。
- host-neutral rebind transaction、new epoch generation、watch provider/handle CASを実装する。
- watch/provider faultをterminal確認済みのfault transition/receiptへ記録し、
unknown outcomeを自動restart、takeover、別handle探索で隠さない
(ADR 0078)。
- host-neutral generation fault journal/専用transitionを実装する。
- Claude/Codexの一command一step terminal bindingを実装する。
- Supervisorへrecord-first faultとfault-first restart gateを接続する。
- focused/関連gateと静的検査を一度ずつ通し、受入ADRへ証拠を固定する。
- design
e83970c、implementation22cf33a。focused 22/22、関連107/107、 current HEADのnpm run check、git diff --checkがgreen。 ADR 0082で受け入れ、 実host fault/terminal/crash recoveryはPhase O2 H gateへ残す。 P2-5のread-only強制がgreenになるまでlive childは起動しない。
- design
- planned rolloverを既存generation host journal/provider bindingから
Supervisor processへ接続し、同じverified runtimeで一stepずつ回収して
新generation activation後にprepared cycleへ戻る
(ADR 0070)。
- 全hostの
- explicit authorization、
- 成果物: host-neutralな
-
P2-5 read-only境界を強制する。
- 成果物: production AIのtool surfaceを空にし、project観測とObserver state/Mailbox writeを 外部Supervisorだけが所有する実行profileと拒否test(ADR 0083)。
- 完了条件: host別live gateでproject writeが拒否され、Supervisor監視とMailbox publishは成功する。 非H fixtureのproject fingerprint不変をlive拒否証拠へ読み替えない。
- ADR 0060によりproduction AIのThroughline/Observer MCP/Mailbox tool surfaceを空にし、
Observer MCP
observer_read/observer_waitはread-only diagnostics/compatibilityへ分離した。 Mailbox writeは外部Supervisorの固定callbackだけが所有する。 - Observer MCPをread-only compatibility/diagnosticsとして維持する裁定を実装する
(ADR 0097)。
-
--diagnosticsの決定的なsanitized JSON、package bin、既存stdio/version互換を固定する。 - active watch exact照合、write API不在、cancel、stdout hygieneをfocused/関連gateで再確認する。
- production AIのtool surface空を維持し、MCP greenをlive provider成功へ読み替えない。
- 実装
1d85039、focused 5/5、関連24/24、static greenを ADR 0098で受け入れた。
-
- Codex native custom agentのTOML指定だけではunrestricted親のoverrideを防げないことを実測した。
- app-server persistent threadのper-thread read-only、project write拒否、別processからの
thread/read/thread/list回収をcharacterizationした(ADR 0009)。 - 非H: Claude exact-empty tool surface/既存隔離flagとCodex runtime-root read-only envelopeを固定し、
同じSupervisor cycleでHEAD/index/tracked・untracked/modeを含むproject fingerprint不変と
Observer state root配下のMailbox publish成功をfixture化する。
commit
2168199。focused 3/3、関連60/60、npm run checkを通し、 ADR 0084で非H部分だけを受け入れた。 - Codex live H: アプリ内表示、65秒超turn、adapter crash後のturn resume、明示interrupt/停止、 project write拒否をcharacterizationする。
- Claude backgroundを
Read,Grep,Globだけで起動し、組込みtool surface上のproject read成功、Write tool不在による一回のwrite拒否、公開job lifecycleをcharacterizationした(ADR 0010)。 - 空のsetting sources、skills/Chrome無効、strict MCPの一試行で、HEAD、index、tracked/untracked、modeを含むproject fingerprint不変をcharacterizationした(ADR 0011)。
- Claude backgroundの65秒超継続、実行中stop、子process消滅をcharacterizationした。MCPは
--toolsによる公開と--allowedToolsによる無人許可を分離する。 - Claude adapter coreをADR 0060でexact-empty tool surfaceへ補正し、raw agent list/stop stderrを
構造化receiptへ保持しないことを固定した。ADR 0012の
Read,Grep,Glob/mcp__observer__*allowlistはsuperseded。 - Claude live H:
--safe-modeと公開background agent定義、認証維持、隔離--settingsStop hook、 project write拒否、再stop receipt、daemon/adapter crash後のterminal result回収をcharacterizationする。--bareはOAuth/keychainを無効化するため隔離fallbackにしない。 即時完了、terminal直前crash、実行中restart、daemon消失、失敗terminalを独立fixtureにし、doneを結果回収済みへ丸めない。 再stopは成功receiptを返さない実測のため、terminal stateを先に確認し、実行中stop receiptとterminal観測を分離する。
Gate: 手紙を生成しない最小Observerが、親の再作成と一時間timeoutを含めて継続監視できる。
-
P3-1 中央Mailboxの保存・publish契約を実装する。
- 成果物: project別inbox、message schema、atomic publish、permission / size / digest検査。
- 完了条件: 不正messageを拒否し、正常messageを部分書込なしで公開できる。
- 実装: strict schema、canonical digest、byte上限、secret pattern拒否、同一message ID拒否、同一filesystem上の完全書込み後publishを実装した。
-
dedupe_keyが既存secret pattern検査から漏れている欠陥を ADR 0085で独立補正した。 修正前focused 6/7で再現し、commitae7e336、focused 7/7、関連30/30、static gateを ADR 0086で受け入れた。
-
P3-2 consume transactionを実装する。
- 成果物: atomic claim、本文削除、digest-only receipt、
delivery_unknown、retention。 - 完了条件: concurrent consumerとfault injectionで同一本文を二重配送しない。
- consumer lock、inbox→processingのatomic claim、
claimed→emitted_unackedreceipt、本文削除を実装する。 - claim後crashを明示的に
delivery_unknownへ回収し、再配送しない。 - malformed messageを注入せず、本文なし
invalidreceiptへ変える。 - 完了receiptを30日・最大1000件へbounded化し、
claimedは自動削除しない。 - lock owner nonceの観測と一致確認を必須にする明示recoveryを実装する。
- claim後crash、malformed本文、重複publish、concurrent consumerの代表faultをtestで再現する。
- 成果物: atomic claim、本文削除、digest-only receipt、
-
P3-3 誤配送防止を実装した(ADR 0020)。
- 成果物: project target、観測host、thread IDによるrouting、旧thread/旧host手紙の失効処理。
- 完了条件: 別project、旧thread、target不明ではclaimせず、現在project / threadだけが取得できる。
- projectごとの物理inbox分離と、target / thread完全一致時だけのclaimを実装する。
- 親Stop payloadからのcurrent target解決、旧thread messageの失効receiptを実装した。
- Mailbox message/receiptへraw thread IDを保存せず
thread_sha256へ統一する。 - Stop payloadのraw thread IDはその場でhash化し、registered target、active watch provider、committed parentの host/thread hashが全一致したauthoritative current hookだけをclaim可能にする。
- authoritative current hookだけが同targetの旧thread messageを本文なし
stale_threadreceiptへ失効させる。 target不明、watch inactive、旧host/旧thread hookはinboxを変更しない。 - focused gate:
node --test test/mailbox-store.test.mjs test/mailbox-consumer.test.mjs test/mailbox-routing.test.mjs— 14/14 PASS。
- Mailbox message/receiptへraw thread IDを保存せず
-
P3-4 親Stop hook adapterを実装する。
- 成果物: Claude/Codex別のMailbox fast path、bounded advisory render、installer / verify / rollback。
- 完了条件: 両hostでMailboxなしなら短時間で終了し、一件の手紙を同じ親turnへ一度だけ正式なcontinuation promptとして注入できる。
- P3-4a Observer所有のparent Stop hook coreを実装した(ADR 0021)。
- Claudeは正式な
StopのhookSpecificOutput.additionalContext、Codexは正式なdecision:"block" + reasonだけを使う。 - raw
session_idはroute照合中だけ使い、receiptにはprovider/turn相関のdigestだけを残す。 stop_hook_active=trueでは新しい手紙をclaimせず、一つの親turnへObserver助言を最大一件にする。- claim後のrender、stdout、finalize失敗は本文を再配送せず
delivery_unknownへ回収する。 - focused gate:
node --test test/parent-stop-hook.test.mjs test/mailbox-consumer.test.mjs test/mailbox-routing.test.mjs— 18/18 PASS。 npm run checkPASS。continued turnの実CLI fast pathはexit 0/stdoutなしを確認した。
- Claudeは正式な
- P3-4b installer / verify / rollbackを実装する。
- Observer側がhook commandと設定fragment生成/検証を所有し、dotagentsは工場配布adapterだけを所有する。
- 既存hookを上書きせず合成し、Codexでは
async:trueを使わず同期fast pathとして配線する。 - P3-4b1 Observer
hook-config契約を実装した(ADR 0022/ADR 0023)。- provider別canonical
StopentryのJSON生成と、candidate configのmissing/duplicate/noncanonical/canonical判定だけを行う。 - macOS v1では、実在するabsolute executable pathを明示入力し、空白、制御文字、引用符を含むcommandを拒否する。
- Host設定を変更せず、fragment/診断のstdout以外へstateを書かない。
- focused gate:
node --test test/parent-stop-hook-config.test.mjs— 7/7 PASS。npm run checkPASS。 - 実装者ReportはControl revision 28でstrict import、revision 29で親受入した。
- provider別canonical
- P3-4b2 dotagents transactional applierを実装した(ADR 0024)。
- Observerのcanonical fragmentをconsumeし、Claude
settings.jsonとCodexhooks.jsonへstandalone Stop entryを各一件に正規化する。 - dry-runを既定にし、apply時は二設定をbackup/prepare/atomic replaceし、途中失敗は両方rollbackする。
- 既存hook、matcher group、trust、model、effort、permission、credentialを変更しない。
- dotagents commit
2fb48cb、Worker Report strict import revision 45、parent accept revision 46。 - focused gate
bash tests/install/observer-hook-config.shとmake lint-pyPASS。実HOME applyとhost実火は未実施。
- Observerのcanonical fragmentをconsumeし、Claude
- P3-4c live host gateを実証する(H)。
- Claude/Codex各一回で、Mailboxなしのfast exitと一件の同一turn continuationを確認する。
- Host ackが無いv1ではreceiptを
deliveredへ格上げしない。
Gate: 手動publishした手紙が正しい親へ最大一回だけ届き、本文が残らない。
-
P4-1 Observer起動契約と出力schemaを実装する。
- 成果物: 親と同じproviderを選ぶhost resolver、read-only伴走者役割、禁止事項、
no_advisory/ advisory proposalの固定契約。 - 完了条件: 異provider Observer、継続的反証、通常会話、実装、自由形式出力へ逸脱した結果をSupervisorが拒否する。
- 同provider resolverと両host共通runtime prompt、
observer.ai_output.v1のstrict parser/canonical digestを 実装した(ADR 0026)。- 静的人格はObserver rootの
AGENTS.md/CLAUDE.md、wire protocolは生成promptを正本とする。 no_advisoryへの理由追加、複数proposal、未知field、自由文、Markdown、過大出力をfail closedにする。- focused gate:
node --test test/observer-ai-contract.test.mjs test/parent-launch.test.mjs test/claude-host-adapter.test.mjs test/codex-host-adapter.test.mjs— 29/29 PASS。
- 静的人格はObserver rootの
- P4-2の信頼済みcycle contextとP4-3のsemantic gateを通した後、Mailbox publishより前に Supervisorが本parserを必須実行し、provider/target/watch/cycleをAI自己申告なしで束縛した (ADR 0089)。
- 成果物: 親と同じproviderを選ぶhost resolver、read-only伴走者役割、禁止事項、
-
P4-2 bounded evidence収集を実装する。
- 成果物: 新規turn、plan、diff、git、test evidenceの最小snapshot。
- 完了条件: prompt全文、secret、巨大logを保存せず、手紙のclaimを検証できる参照を作れる。
-
observer.evidence_snapshot.v1の32 KiB全体上限、section別上限、redaction/truncation、 digest-only receiptを固定した(ADR 0027)。- generation hard ceilingは最大8 completed cycleまたはObserver所有model-visible payload累積256 KiBとし、 次cycleの開始前にplanned rolloverする。
- host-neutral snapshot builderとstrict validatorを実装する(ADR 0031)。
- Throughline turn itemをexact検証し、最新側から最大12 KiBへboundする。
- plan最大4 refs/6 KiB、git最大8 KiB、test receipt最大16件/4 KiB、全体32 KiBを強制する。
- raw snapshotを保存せず、digest、bytes、件数、truncation/redaction flagsだけのreceiptを生成する。
- Control Run 1は契約不足でreject、Run 2はnative無応答をcancelledへ閉じた。未受入成果を成功扱いせず、 ADR 0028によりsuccessor Controlへ移送して継続する。
- successorの再実装は、別会社Composerの認証H、sidecar config不足、native二失敗を明示した上で、 execution-verifiedなaiterm Codex一件へ親review配置する(ADR 0030)。
- strict Worker Reportを手補正せずimportし、親のfocused 15/15、
npm run check、対象2 pathのgit diff --checkを再確認してControl revision 8でacceptした。実装はcommit0536d07へ独立固定した。
- read-only collectorを実装し、承認済みplan ref、git HEAD/status/diff evidence、既存test receiptを snapshot builderへ渡す。collector unavailableを空の成功へ丸めず、利用不能refとして明示する。
- generation stateへcycle数とmodel-visible byte数を耐久化し、8 cycle/256 KiB到達前の
terminal確認付きplanned rolloverへ接続する。
- 一parent session epochへ一論理Observer、一watch内で一active generationを維持する。
- model呼出し前のexact reservation、8 completed cycle、262,144 UTF-8 bytes、fresh generationでも 一入力が超過する場合のfail-closedをADR 0034へ固定した。
- generation state/budget reservation、cycle transaction接続、host terminal/次generation起動を 独立gateに分け、旧generationのterminal不明時は新世代を起動しない。
- generation stateとmodel呼出し前のexact reservationを実装した。strict Worker Reportを手補正せず
importし、親のfocused 24/24、
npm run check、対象2 pathのgit diff --checkを一度再確認して Control revision 25でacceptした。実装はcommit9a2b899、受入証拠は ADR 0035へ独立固定した。 - cycle cursor commitとgeneration completionを同一target transactionへ接続した。
- provider別host terminal確認と次generation activationを接続する。
-
P4-3 過剰指摘抑制を実装する。
- 成果物: materiality、evidence、novelty、actionability、timing gateとdedupe / cooldown。
- 完了条件: 好み、一般論、証拠不足、対処中、同一指摘のfixtureで手紙を出さない。
- P4-3a runtime deterministic gate: evidence ref一意性/適格性、record-first current decision、 60分cooldown、severity escalation、bounded historyをhost-neutral coreへ実装する (ADR 0087、 ADR 0088)。
- P4-3b cycle application integration: acceptedだけをMailboxへexact publishし、suppressed専用result、 crash replay、finalization/retentionを既存model operation順序へ接続した (ADR 0089)。
- P4-3c semantic behavioral eval: materiality、actionability、semantic timing、親が対処中かを
文字列heuristicへ落とさず、好み/一般論/対処中を
no_advisoryにするstrict eval fixtureを固定する。 実provider採否はP4-4 H gateへ残し、runtime機械gateだけでP4-3を完了扱いしない (ADR 0090、 ADR 0091)。
-
P4-4 severityと最小dogfoodを完了する。
- 成果物:
info、warning、review_requiredの実例と採否記録。 - 完了条件: 正常進行では沈黙し、有益な助言とソフトストップを各一回だけ配送できる。
- 成果物:
Gate: Observerが親の仕事を奪わず、ノイズより価値の高い助言だけを送る。
-
P5-1 E2Eとfault injectionを完了する。
- 成果物: Codex
task_complete/Claude実証済み完了証拠 → Throughline → 同provider Observer → Mailbox → 親Stop continuationの両host統合test。 - 完了条件: timeout、thread切替、crash、重複通知、誤配送、claim失敗を含む受け入れ条件がgreenになる。
- P5-1a 非H core E2E: 実Observer state/transactionとversioned Throughline/Codex公開境界fixtureで、
Codexのcompleted cycleからsemantic decision、Mailbox、parent Stopまでを貫通する。silence、suppression、
crash replay、重複、誤配送、claim失敗をexact-once契約へ収束させ、Claudeはstate変更前の
provider_unavailableだけを受け入れる(ADR 0092)。 - P5-1b-preflight 非H: dual-host live H campaignのread-only prerequisite、
必須証拠、停止条件、rollback、収集禁止情報をversioned receiptとrunbookへ固定する
(ADR 0103)。実装
bbe407d、focused 13/13、related 40/40、actual read-only preflighth_required、npm run checkgreenを ADR 0104で受け入れた。 - P5-1b1 Codex caller core 非H: current parent、watch、host receipt、initial generation、
同一app-server transport、Supervisor loop、terminal stopを一processへ接続する
(ADR 0105)。実装
286a6db、focused 9/9、related 77/77、npm run checkgreenを ADR 0106で受け入れた。 - P5-1b2 Codex parent entry/dotagents配布 非H: 現在Codex親からexact contextを注入し、
isolated HOMEでinstall/verify/rollbackする。live providerは起動しない
(ADR 0107)。Observer
659924c/0690ee0、dotagents21bc352、focused 12/12、related 25/25、isolated install/verify/rollback、npm run check/make lintgreenを ADR 0108で受け入れた。 - P5-1b3 Claude public surface characterization/代替transport確定: 公開非対話reply ACK、exact result read、
job/session/Stop相関の実在または不在を、ADR 0109の
順序で確定する。private protocolやheadless resumeへfallbackしない。
- P5-1b3a 非H harness: characterization専用の隔離Stop capture、sanitized receipt、
prepare/verify/cleanupをfixtureで閉じた。親Mailbox hookをresult captureへ流用しない。
Observer
f40b672、dotagents78c358b、focused 10/10、related 26/26、 package/isolated install gateをADR 0110で受け入れた。 - P5-1b3b live H: 専用runbookで
一つのbackground jobだけを起動した。
job_session_correlation=blocked、stop_capture=blocked、reply/terminal exact resultはunsupported、cleanupとfingerprint不変は confirmedである(ADR 0111)。 旧background job経路は必要な公開契約が揃わない限りblockedのまま維持する。 - P5-1b3c 非H diagnostic receipt: Stop未発火とstdin/payload/result不正をraw-freeに
分離し、direct shebang CLI、verify、cleanupをfocused/related gateで閉じる
(実装
f239a07、focused 9/9、related 29/29、npm run checkgreen、 ADR 0113)。 - P5-1b3d live H再characterization: 別H承認で一つのbackground job/Haiku requestだけを
起動した。hook invocation、job/session、Stop payload、terminal、cleanup、project/host settings
不変はconfirmed、canonical resultは
E_CLAUDE_CHARACTERIZATION_RESULT_INVALID、公開reply/ terminal exact resultはunsupportedである (ADR 0114)。 旧background job経路は必要な公開delivery/result contractが現れるまでblockedとする。
- P5-1b3a 非H harness: characterization専用の隔離Stop capture、sanitized receipt、
prepare/verify/cleanupをfixtureで閉じた。親Mailbox hookをresult captureへ流用しない。
Observer
- P5-1b3e Aiterm Claude対話transport 非H: Aitermの永続PTYへ対話型
claude_agentを追加し、 promptなし起動、初回/follow-up、Stop完了、operation相関付きexact result、timeout後回収、interrupt/closeを Aiterm側の独立plan・gate・commitで閉じる。claude -p反復は代替にしない (Aitermdd43c40/3842ff2/ceb75e8/28b7438/f0fcf10。相関gate focused 1/1、 related 122/122、full 262/262、独立反証後green、構造化caller gate focused 5/5、related 126/126、 launcher receipt gate focused 4/4、related 94/94、 ADR 0115)。 - P5-1b3f live順序整理: Aiterm単体live smokeをP5-1b4より前に反復せず、P5-1b5の一回の dual-host live Hへ統合する。これはlive成功ではなくqueue統合の完了である。
- P5-1b4 Claude caller core 非H: P5-1b3eで固定したAiterm公開面だけをissue/recover/cleanup、
initial generation、同じ永続Claude sessionを所有するSupervisor loopへ接続する
(ADR 0116)。
- P5-1b4a: Aiterm stdio MCPをversion/tool schemaまで検証するtransportと、
claude_turnの structured statusをgeneric model callbackへ変換するClaude provider operationを実装した。 focused 8/8、related 58/58、npm run checkgreen。受入証拠は ADR 0117。 - P5-1b4b: 新規production routeのprivate host handleを
claude.sessionへ分離し、promptless managedclaude_agentlaunch、structured receipt、watch activation、initial generationを接続した。 明示launch拒否とtransport unknownをjournalで分離し、unknown時だけrecover-onlyを許す。旧claude.jobbackground routeはblocked履歴互換だけに限定した。focused 27/27、related 35/35、npm run checkgreen。 受入証拠はADR 0118。 - P5-1b4c: Claude provider runtimeをproduction step、Supervisor process、親caller、CLIへ接続し、
通常completed cycle間で同じsession handleを再利用する。通常終了は
pty_close成功後にMCP processを閉じ、 未対応rollover/parent rebindはfail loudを維持した。focused 27/27、related 91/91、npm run checkgreen。 受入証拠はADR 0119。 - P5-1b4d: rollback/parent rebindのstop/relaunch/recoveryをAiterm公開toolだけへ接続し、
focused/related gate、親反証、独立commitで19dを閉じる
(設計訂正はADR 0120)。
- Aiterm側の欠落契約を所有repoへ割り込み登録し、
pty_closeのidempotentclosed | already_closedstructured receiptと0.14.0 versionを独立gate/独立commitで閉じた (Aiterm056e0a4、focused 4/4、related 174/174、Aiterm ADR 0012)。 - Aiterm launch response loss時に、session存在証拠ではない
claude_turn(operation_not_found)を spawn証拠へ誤用しているP1を修正する。Aiterm側の相関済みclaude_agentexact replayだけへ置換し、 同じsession名でもlaunch相関ID/引数identityが違うsessionを採用しない (Aitermaffc2df、Aiterm focused 6/6・related 96/96・full 269/269、Observer focused 11/11、 訂正設計はADR 0122)。 - ObserverのAiterm検証を0.14.0/
pty_closeoutput schema/launch_operation_idinput schemaへ上げ、 text解析を禁止する。 - 同一generation内だけ同じsession IDを再利用し、planned rolloverとsame-provider parent rebindでは parent epoch+generation sequenceから決定した別session instanceを使う。watch固定session/launch receiptを 新generationへ再利用しない。
- 旧session close receipt→terminal durable記録→新session spawn/recovery→watch handle CAS→ready→
generation activationを既存host-neutral transactionへ接続する。response loss後は同じclose/launch operationだけを
回収し、prompt再送、旧background Claude、Codexへのfallbackを行わない。
- parent受入で、planned rolloverだけがstructured close command receiptをjournalへ保存し、parent rebind
adapterは同receiptを破棄している非対称を検出した。修正前0/2、補正後2/2。旧v1 journalの
stop_command_receipt_digest欠落はnull読取→次transitionで書戻し、異なるretry receiptは fail loudとする(ADR 0121)。
- parent受入で、planned rolloverだけがstructured close command receiptをjournalへ保存し、parent rebind
adapterは同receiptを破棄している非対称を検出した。修正前0/2、補正後2/2。旧v1 journalの
- Supervisor runtimeのactive
claude.session所有権をactivation後だけ新handleへ移し、通常cycle、 parent rebind、process cleanupが常に現在generationのsessionを参照することをfixtureで固定する。 - 独立反証で検出したinitial caller recovery/parent rebind再authorizationのP1を補正する
(ADR 0123)。
- 明示
expected_previous_watch_id=current watchを伴う同じwatchのstarting | launching | activeだけを Aiterm Claude初期callerが同一requestへ再束縛し、launchingjournalではexactclaude_agentreplayを呼ぶ。 通常の二重start、別provider/project/terminal watchは再利用しない。 - parent rebind journal作成後は、generationが
stopping以降でも同じcycle/proposed parentから 同一authorizationを回収し、authorizationを新規発行しない。 - caller response-lossとrebind multi-step再開のfocused fixtureを先に17/20 redで固定し、 補正後20/20 greenへ戻した。
- 明示
- related 50/50、
npm run checkgreen、Phase full 393/393 green。独立重監査でP1実装欠陥2件を 採用・補正し、証拠再束縛指摘も補正後gateで閉じた。受入証拠は ADR 0124。
- Aiterm側の欠落契約を所有repoへ割り込み登録し、
- P5-1b4a: Aiterm stdio MCPをversion/tool schemaまで検証するtransportと、
- P5-1b5 dual-host live H: Aiterm実Claude初回/follow-up、Stop、exact
result、session closeと、
Claude/Codexの実completed証拠、production model request、session相関、hook trust、65秒超wait、
通常停止を一回の両host campaignで受け入れる。Claude成功をfixtureで代用しない。timeout、crash、
通信断などのintentional fault trancheは通常campaignへ混ぜず、実行ごとに別の明示承認を要する。
- P5-1b5a preflight/runbook production route補正: P5-1b4完了後も残った旧
claude --version/Observer MCP probe/background job前提を除去し、実production callerと同じ Throughline 0.6.3observer-read実疎通、Aiterm 0.14.0 stdio initialize、claude_agent/claude_turn/pty_closeexact schema、Codex app-server、 Stop hook候補を read-only preflightで確認する。live手順はobserver parent claude run ... --aiterm-command ...とobserver parent codex run ...、同じ persistent Claude sessionの初回/follow-up、terminal回収、dotagentsの検証済み--restoreによる config rollbackへ固定する(ADR 0125)。 focused 20/20、product 4/4、related 46/46、isolated package gate、actual read-onlystatus=h_requiredをADR 0126で受け入れた。 - P5-1b5b 通常系dual-host live H: 承認済み通常campaignだけを各host一回実行し、preflight
receiptの全証拠、両host terminal、project fingerprint不変、hook config rollbackを確認する。
intentional faultは未実施と明記する。通常campaignのH操作は2026-07-16にオーナーが
「queue 19e dual-host live Hを承認する」と明示承認した。
- P5-1b5b-r1 state root束縛修理: 最初のClaude live attemptでmodel応答後に
parent Stop hookが既定state rootを参照して
E_PERMISSION_INVALID、Throughline completed feedが 0件のままになった。hook fragment/verifier、preflight、dotagents adapter、runbookへ同じ explicit state rootを束縛し、旧state rootのtarget entryを一件へ正規化する (ADR 0127)。失敗attemptは成功へ含めず、 session terminal確認後に修理gateを独立commitで閉じてからliveを再開する。 focused 28/28、related 48/48、npm run check、対象docs lint、dotagents isolated package gateが greenとなり、ADR 0128で受け入れた。 - P5-1b5b-r2 Throughline capture実行物束縛: state root修理後のClaude attemptで
hook errorは消えたが、Aiterm parentがglobal PATHの旧
throughline process-turnを実行し、 DB sessionだけ増えてcompleted receipt fileが作られなかった。read側だけでなくcapture側も campaign candidateへ束縛するため、Aiterm controllerのPATH先頭をcampaign prefixへ固定する (ADR 0129)。手動transcript投入やglobal更新へ fallbackせず、失敗sessionを公開closeしてからliveを再開する。- P5-1b5b-r3 Aiterm runtime隔離: controller processのPATHを補正してもglobal tmux
server作成時のstale環境が新sessionへ継承されreceiptは0件だった。campaign専用0700
TMPDIRでAiterm socket/log/stateを隔離し、candidate PATHを持つfresh serverだけを使う (ADR 0130)。 - P5-1b5b-r4 socket長境界: campaign root配下の
aiterm-runtimeでは最終tmux socketが 105 bytesとなり、macOSの104-bytesun_pathへ収まらずsession生成前に失敗した。短い0700r2を使い、実物<TMPDIR>/claude-tmux-sockets/claude.sockを94 bytesとlaunch前に実測した。 ADR 0131の予測名/92 bytesはADR 0132で 訂正する。 - P5-1b5b-r5 Throughline Stop flush barrier: 短い専用runtimeではAiterm session、
candidate-first PATH、実Claude
end_turn、Stop hook error 0まで成立したが、async Stopがfinal assistant行のtranscript可視化より先に一回だけbackfillし、DB本文/receiptが0件になった。 Throughlineがlast_assistant_messageを本文でなくlatest logical groupのbounded barrierに使う修理を commita46b915で独立確定し、focused 14/14、subprocess 2/2、related 78/78を通した。 失敗attemptはlive成功へ含めず、candidate再梱包後に通常campaignを再開する (ADR 0132)。 - P5-1b5b-r6 installed package runtime root canonical化: 修理済みcandidateでClaude parent
receiptを1件確定後、実
observer parent claude runがprovider launch前にE_THROUGHLINE_RUNTIME_ROOT_INVALIDとなった。CLIだけがimport.meta.urlから末尾/付きの package rootを作り、preflightの末尾なしrootと分岐していた。runtime rootを実packageのcanonical directoryへ一意化し、Claude/Codex親callerの両dispatch testとisolated package gateで固定する。 失敗attemptはObserver live成功へ含めない (ADR 0133)。 focused 15/15、related 35/35、npm run check、対象docs lint、package verify、installed module smokeproviders=2 root_count=1 canonical=trueがgreen。 - P5-1b5b-r7 Throughline completed timestamp adapter: r6修理後の実callerはprovider launch前に
E_EVIDENCE_SNAPSHOT_INVALIDとなった。Throughlineobserver_read.v1はcompleted_atをepoch milliseconds整数で公開し、Observer evidence schemaはcanonical.sssZを要求するため、evidence collector境界で整数msをexact ISOへ一度だけ変換する。文字列、負数、範囲外値、非canonical結果は fail closedにし、Throughline wireやevidence schema自体を変更しない。失敗attemptはlive成功へ 含めない(ADR 0134)。 focused 9/9、関連42/42、npm run check、対象docs lint、package verify、実feedを使う installed smokefeed_turns=1 snapshot_turns=1 canonical=trueがgreen。 - P5-1b5b-r8 Aiterm初回ready安定化: 実managed Claudeで単発ready直後の初回promptが
startup再描画へ消えるraceを再現した。Aiterm commit
4d3befdで4 vendor共通の初回readyを 500ms×11回連続へ固定し、非readyでstreakをリセットした。pure 21/21、focused agent 4/4、 related 113/113、build、新規ADR lint、diff checkがgreen。再pack候補の実managed Claudeで request/output可視、初回cycle commit、model operation残留なしを確認した。 - P5-1b5b-r9 SIGINT時のAiterm子process signal隔離: r8候補の正常停止で、foreground
Observerと同じprocess groupのAiterm MCP childがSIGINTを先に受け、session closeより前にtransportが
terminalとなった。callerは
E_AITERM_TRANSPORT_CLOSEDで非0終了しmanaged sessionが1件残留したため、 別processの公開pty_closeで回収した。Aiterm childを親terminal signalから隔離し、Observerの AbortSignalだけでSupervisorをcancelしてpty_close→MCP closeの既存順序を完遂する。 detached child修理はcommit396cf05、focused 9/9、related 43/43でgreen。再pack候補の実正常停止は callercancelled/exit 130、managed session残留0、親session公開closeclosedを確認して閉じた (ADR 0135)。 - P5-1b5b-r10 cycleごとのexact output contract: r9修理後のfresh Claude candidateで
managed request/Stop/exact result回収までは成立したが、実Claude出力がJSON object一件でなく
E_OBSERVER_AI_OUTPUT_INVALIDとなった。strict parserをMarkdown/前後説明許容へ緩めず、各observer.cycle_request.v1へhost-neutralなresponse contractを同梱する。default no_advisory、 exact二outcome、proposal field、許可enum、single JSON object、Markdown/code fence/前後説明/ unknown field禁止を毎cycleのmodel-visible bytesとinput digestへ含める。focused 12/12、 related 52/52はgreen。commitebd8ae6の再pack候補でstrict parse、初回cycle commit、pending/ model operation残留なしを確認して閉じた (ADR 0136)。 - P5-1b5b-r11 Codex app-server child signal隔離: Claude正常停止で根治した同じprocess group
問題がCodex app-server transportにも残っている。foreground callerのSIGINTがapp-server childへ
直接届くと、Observerのcancel処理より先にtransport terminalとなり、turn interrupt/terminal回収を
完遂できない。Codex childもdetached process group、stdio所有、unrefなし、既存
closeAndWait terminal確認へ固定する。focused 13/13、related 69/69はgreen。独立commit後、
実Codex正常停止で閉じる
(ADR 0137)。
修理済みcandidate r11のSIGINTでcaller
cancelled/exit 130、managed app-server terminal、 local app-server残留0、親app-server公開closeclosedを確認した。 - P5-1b5b-r12 Codex bootstrap terminal ready gate: 実Codex parentのseed
task_complete後、 Observer bootstrap turnがまだinProgressなのにwatch/generationをreadyへ進め、最初のcycleがE_CODEX_CYCLE_TURN_ACTIVEで停止した。turn/startACKをAI readyにせず、同じdurable thread/turnのthread/readでbootstrapcompletedを確認してからready receiptとwatch activationへ 進む。failed | interrupted | timeoutは別turnを再送せずfail loudにする。initial/generation activationとready recoveryを同じ契約へ揃え、focused/related gate、独立commit、実Codex再Hで閉じる (ADR 0138)。- 実装gate:
completed前のreadyを禁止し、failed/interrupted/timeout/別turnをfail closedに 固定した。focused 17/17、related 111/111、npm run check、新規ADR lint、diff checkがgreen。 - 実Codex candidate r11で初回cycle commit、65秒超継続、follow-up後の第2cycle、正常停止を 確認した。親feed 2件、同じgenerationのcompleted cycle 2件、pending reservation/cycle/ model operation残留なし、project fingerprint不変。
- 実装gate:
- P5-1b5b-r13 Throughline concurrent writer gate: r10で親2turn目とfeed書込みは成功したが、
Observer production callerの同時
observer-readが一時SQLite lockでE_THROUGHLINE_EXEC終了した。 Throughline commit95a3233でcompleted projectionのread-only接続だけに1秒のbounded busy waitを 追加し、Spotter auditorと上限超過hard failureを維持した。focused 16/16、related 78/78。 candidate再梱包後のr11で同時readを含む2 cycleを通し、commit0366bb8でlive受入れを固定した。 - P5-1b5b-r14 campaign closure: Claude r12とCodex r11はいずれも親feed 2件、同じ
generationのcompleted cycle 2件、初回cycle後65秒超、pending stateなし、caller cancel、host
terminalを満たした。最初のconfig archiveからClaude/Codex設定をexact digest・mode 0600・
uid 501・gid 20で復元し、candidate dry-runが両provider
changed=yesとなることを確認した。 両projectは空のまま。intentional fault、push、publish、deploy、loginは未実施。 不変受入証拠はADR 0139。 - P5-1b5b-r15 Codex process-group cleanup訂正: campaign cleanupで、終了済みCodex
app-server二attemptが起動したMCP process群16件がcampaign rootを
cwdにしたまま残留していた。 app-server leaderだけのterminal確認をprocess残留0へ読み替えたADR 0139の該当証拠を失効させる。 detached app-serverの終了は、固有process group全体へSIGTERM→SIGKILLを配送し、leader closeと process group消滅の両方をboundedに確認して初めて成功とする。既存孤児は所有PIDへの通常SIGTERMで 16/16終了しcampaign rootを削除した。実装、focused/related gate、fresh subprocess実証を独立commitで 閉じる(ADR 0140)。実装は commitc936cfdへ独立固定し、focused 16/16、Codex caller/Supervisor related 13/13、npm run checkがgreen。 実OS fixtureではleader終了後もSIGTERMを無視する子を同じgroupに残し、bounded SIGKILL後に group/子PIDとも不在を確認した。受入証拠は ADR 0141。独立重監査で検出したPGID欠損時の error code不一致はcommit8056405でE_CODEX_PROCESS_TERMINATION_UNKNOWNへ統一した。 full suite並列時のfixture起動待ちraceは、成功assertionを変えず5秒のbounded待ちへ拡張する commit2b94392で閉じた。 - P5-1b5b-r16 post-spawn/pre-ready recovery訂正: 独立監査候補を親が実コードで
再確認し、handle耐久化後のready失敗でprovider transport/sessionだけを閉じ、watchを
launchingへ残す欠陥を採用した。validated spawned receiptの同じwatch identity/handleだけで launch failure cleanupを要求し、Codex bootstrap failed/interrupted/timeoutとClaude ready前失敗を provider terminal→watchfaultedまで閉じる。別watch/別provider、handle推測、暗黙restartへ fallbackしない。intentional live faultを使わずfocused fixture、独立gate、独立commitで閉じる (ADR 0142)。実装はcommit4bde91cへ 独立固定し、focused 19/19、parent-launch/watch-store/両Supervisor related 33/33、npm run checkがgreen。受入証拠は ADR 0143。
- P5-1b5b-r3 Aiterm runtime隔離: controller processのPATHを補正してもglobal tmux
server作成時のstale環境が新sessionへ継承されreceiptは0件だった。campaign専用0700
- P5-1b5b-r1 state root束縛修理: 最初のClaude live attemptでmodel応答後に
parent Stop hookが既定state rootを参照して
- P5-1b5a preflight/runbook production route補正: P5-1b4完了後も残った旧
- 成果物: Codex
-
P5-2 性能、導入、rollbackを確定する。
- 成果物: latency実測、installer、verify、runbook、cleanup、rollback。
- 完了条件: 空Mailboxと通常waitが開発体験を阻害せず、clean環境で導入・撤去を再現できる。
- P5-2a clean環境installer/verify/rollback契約を閉じる
(ADR 0099)。
- versioned製品manifest、runtime package files、sanitized
observer diagnosticsを実装した。 - 4 binをexecutableへ揃え、package tamper、platform、Node、MCP/hook binary契約をfocused testで固定した。
- dotagentsの隔離HOME/npm prefixでinstall→reinstall→verify→rollbackとhook adapter dry-runを通した。
- actual HOME apply、hook trust、live host、credential、publish/pushは未実施のH/後続gateへ残した。
- 実装
630c5ff/b45c07a(Observer)、894799b(dotagents)を ADR 0100で受け入れた。
- versioned製品manifest、runtime package files、sanitized
- P5-2b performance/retention cleanup契約を閉じる
(ADR 0101)。
- hook process、空Mailbox core、bounded wait overheadの分布と閾値を固定fixtureで計測した。
- default retentionが完了receiptだけを削除し、claimed、prepared publish、active cooldownを保護した。
- cleanup途中失敗をsanitized errorにし、無関係stateを変えず再実行で同じ最終状態へ収束させた。
- 実装
1d045df/8b49493を ADR 0102で受け入れた。
- project-ownedな
.codex-sidecar.ymlを追加し、read-only presetと隔離worktree writer、 Observer製品面だけのpath allowlist、明示model policyを正規dry-runで検証した。codex-sidecar diagnostics --project .:status=ok。codex-sidecar review --project . --preset review --dry-run ...:status=dry-run、App Server未呼出。codex-sidecar factory-diagnostics --project . --preset review: 0.3.7三package一致、overall=ready。
-
P5-3 最終監査とknowledge returnを完了する。
- 成果物: Find → Dedup → 反証 → Critic → 親裁定、RAG / caveat / docsへの還流記録。
- 完了条件: P0/P1問題が残らず、全受け入れ条件を親が裁定し、本プランをarchiveできる。
- 修理後最終HEAD
2b94392でfocused 16/16、related 68/68、full 412/412、fail 0、skip 0。 - 新規独立重監査はPGID欠損時のerror code不一致をP1一件として採用した。commit
8056405と2b94392後の同一refuterによる限定再確認でP0/P1残存0、fixtureのgroup/子PID不在assertion維持を確認した。 - knowledge returnとimmutable acceptance matrixは ADR 0144。intentional fault、追加model request、network、 credential、push、publish、deploy、loginは実施していない。
-
P5-4 Throughline上位互換version gateを補正する。
- 成果物: 最低対応版以上の安定版SemVerを受理し、実versionをverificationへ束縛するruntime、 preflight、diagnostics、focused test、production watch smoke。
- 完了条件: Throughline
0.8.7とそれより新しい安定版を受理し、旧版・不正SemVer・prereleaseを拒否する。 version受理後もobserver-read/observer-waitのstrict wire検証を維持し、互換性をversion文字列だけで 成功扱いしない。 - version range契約とverification schemaをADR 0145へ固定する。
- runtime、preflight、diagnostics、focused testを補正する。
- Codex CLIも最低対応版以上+actual version束縛へ揃え、 ADR 0147どおり現行CLIを直接使う。
- 実watchで露出したtruncated completed-turnの元全文digest境界を ADR 0146どおり補正する。
- Supervisor hard failure後にfault provider bindingを同じruntimeでterminalまで進め、
fault_requiredを残して通常stopだけを完了する欠陥を ADR 0148どおり補正する。 - source package検証、full suite、実Throughline
0.8.7/Codex CLI0.144.6のversion gate通過を確認する。 - default state rootの旧fault generation/journal/pending cycleをbackup付きで可逆隔離し、
production watch
w_25fa83ce-ceb7-4494-bd62-474d8fd1cdbaがactive継続することを確認した。 旧fault再発防止はcommit6c510b0、上位版受入れはcommit85326c3。focused 49/49、 full 416/416、npm run check、Throughline0.8.7/Codex CLI0.144.6の実経路がgreen。
-
P5-5 Observer 0.1.1を公開し、installed runtimeへ切り替える。
- 成果物: 現行live文書、CHANGELOG、0.1.1 package identity、release commit/tag、GitHub push、 npm公開、global install、installed packageからのproduction watch。
- 完了条件: ADR 0149の順序で、全gate green、
publish対象commitが
origin/mainの祖先、npm registryとglobal installが0.1.1、 bingoのwatchがinstalled binaryからactive継続する。 - live文書とpackage identityを0.1.1/Throughline
>=0.8.7へ同期する。 - package tarball、full suite、static check、package install smokeをgreenにする。
- commitをmainへpushし、tag
v0.1.1をpushした。 -
@quolu/observer@0.1.1をnpmへ公開し、registry metadataを確認した。 - global installを0.1.1へ更新し、installed diagnostics/MCP diagnosticsを確認した。
- installed binaryでbingo監視を再開したが、親AI向けhook/pluginを継承したbootstrapが
外部interruptを受け、
active継続の受入はP5-6へ引き継いだ。
-
P5-6 Observer 0.1.2でCodex子の実行プロファイルを隔離し、installed watchをactiveにする。
- 成果物: ADR 0150、hook/plugin無効化、 0.1.2 package identity、release commit/tag、npm公開、global install、production watch。
- 完了条件: focused/full/package gateがgreen、installed 0.1.2のbingo watchがbootstrapを完了し、
foreground callerとwatchが
activeを維持する。 - app-serverを
--disable hooks --disable pluginsで起動し、process transport testで固定した。 - 実Codex app-server characterizationでhook/plugin event 0、bootstrap
completedを確認した。 - 0.1.2のfull/package gateを通した。full 416/416、
npm run check、 package install smoke、64-file tarballがgreen。 - commit/push/tag/npm publish/global installを完了した。
- installed 0.1.2でbootstrap完了を確認した。旧generation stateとの衝突で停止したため、
active継続の受入はP5-7へ引き継いだ。
-
P5-7 Observer 0.1.3でterminal watchから新watchへのgeneration切替を完結する。
- 成果物: ADR 0151、新watch generation置換transaction、 0.1.3 package identity、release commit/tag、npm公開、global install、production watch。
- 完了条件: pendingのない旧generationだけが新watchへatomic置換され、未解決stateは保持される。
installed 0.1.3のbingo watchが
activeを維持する。 - 新watch active CASと旧generation状態を照合する置換transaction/focused testを実装した。
- full/package gateを通した。full 418/418、
npm run check、package install smoke、 64-file tarballがgreen。 - commit/push/tag/npm publish/global installを完了した。
- installed 0.1.3でgeneration切替は完了したが、
turn/start直後の empty rolloutに対するthread/readがerrorとなり、active受入はP5-8へ引き継いだ。
-
P5-8 Observer 0.1.4でCodex bootstrapのflush競合とglobal tool surface継承を解消する。
- 成果物: ADR 0152、
terminal notification gate、isolated
CODEX_HOME、認証connector、0.1.4 release/installed watch。 - 完了条件:
turn/completed前にthread/readを発行せず、isolated homeがglobal config/MCPを継承しない。 installed 0.1.4のforeground callerとbingo watchがactiveを維持する。 -
turn/completedexact相関後のdurable readとtransport testを実装した。 - isolated
CODEX_HOME、0600認証元symlink、不要feature無効化、残存MCP fail-loudを実装した。 - source runtimeでMCP startupなし、Observer AGENTSだけのinstruction source、read-only policy、
bingo watch
activeを確認した。 - full/package gateを通した。full 422/422、
npm run check、 isolated package install smokeがgreen。 - commit
71e66cfをmainへpushし、tagv0.1.4、npm publish、 registry shasuma1c083c653516175aaf3bff974de284752223658、global installを確認した。 - installed 0.1.4でbingo監視
w_194bceab-d266-492a-943c-aefa8692cdceを foreground起動し、watch/callerがactiveを維持して作業を再開した。
- 成果物: ADR 0152、
terminal notification gate、isolated
- projectの絶対パスだけで監視を開始でき、Claude/Codexの親スレッド再作成へ自動追従する。
- Codexの
task_completeまたはClaudeの実証済み完了証拠だけでhost-bound completed cursorが進み、外部Supervisorの最大一時間Throughline waitを起こす。 - timeout時はAIやMailboxへ報告せず、外部Supervisorが同じcursorから次のbounded wait stepを開始する。
- crash、timeout境界、重複通知があっても確定turnを失わず、同じturnを二重監査しない。
- ObserverはprojectとThroughlineをread-onlyで扱い、実装、停止、Task変更を行えない。
- Observerは親と同じprovider familyで動き、正常進行では沈黙し、証拠、重要性、行動可能性のある助言だけを送る。継続的な反証役にならない。
- 別project、旧thread、不正messageを配送せず、正しい手紙を親へ最大一回だけ注入する。
- 配送後は本文を削除し、boundedなdigest-only receiptだけを残す。
- Claude/Codexの親Stop hook adapterはMailboxなしで高速に終了し、外部LLM、network、long-pollへ同期依存しない。
- E2E、fault injection、installer、verify、rollback、full CI、最終監査、knowledge returnが完了する。
- 利用者の明示指示を受けた親だけが同provider Observerを起動し、一targetで二重起動しない。
- Claude/Codex ObserverはcanonicalなObserver rootを実行
cwdとし、監視対象ごとの擬似projectやtemporary repoを作らない。 - 一つの親session epochには一つの論理Observerだけが伴走し、同時にactiveな物理host generationを一つへ制限する。 active generation内は同じprovider sessionへcompleted turnを継続投入してObserver自身の理解を維持する。 context rollover後もcursorとbounded stateを引き継ぎ、Throughline L2をObserver cognitionの代替にしない。
- SupervisorはAIではなくtransport/exact-once/recovery制御だけを担い、completed turnごとのfresh evaluatorを Observerとして起動しない。利用者は永続Observer sessionを通常の対話sessionとして閲覧できる。