Skip to content

Latest commit

 

History

History
980 lines (914 loc) · 95.3 KB

File metadata and controls

980 lines (914 loc) · 95.3 KB

Observer v1 実装計画

Status: Active — Claude/Codex両host対応と実Throughline CLI統合を進行中

作成日: 2026-07-14

製品契約: 00_product-contract.md

この文書は作業の現在地だけを管理する。製品仕様、非目標、廃案、恒久規約は製品契約またはAGENTS.mdを正とする。


未確定事項

completed-turn境界の初期未確定事項は解消済み。Claude側の完了証拠、Stop hook、60秒超wait、continuation、停止方法はP0-6で実測し、Codexの挙動から推測しない。Codex native childのread-only不成立はP2-5 blockerとしてADR 0008で分離する。


Throughline変更裁定

  • 当初のThroughline変更holdは、オーナーの続行指示により解除済み。
  • Throughline側は自身のdocs/14_observer_completed_turn_feed_plan.md、独立Control、独立gate、独立commitで進める。
  • Observerは公開observer-read/observer-wait CLIだけを利用し、ThroughlineのDB/WAL/libraryへ依存しない。

Control wave

  • foundation wave observer-independent-foundation-20260714はbounded worker budgetを使い切ったため、 ADR 0016の受入表でarchiveし、Codex host adapter以降を observer-codex-host-runtime-20260715へ継続する。これはObserver全体またはPhase 2の完了宣言ではない。
  • Control finalizationのdigest証拠には可変な本planを使わず、immutable ADRを使う。
  • queue 19eの訂正Control observer-p5-1b5-dual-host-live-20260716は、process-group cleanup、 pre-ready recovery、修理後HEADの回帰、独立重監査を ADR 0144で受け入れてfinalizeする。

Phase 0: 調査と設計裁定

  • P0-1 Observerのベースラインを確定する。

    • 成果物: repo状態、runtime候補、package / test / CI候補を記録した設計メモ。
    • 完了条件: 初期化操作、標準検証コマンド、H操作が分離されている。
  • P0-2 Throughlineの現行契約を実コードで特定する。

    • 成果物: read入口、turn schema、cursor、project path、Done保存経路のファイル・呼出経路一覧。
    • 完了条件: fixtureまたは実データで、task_complete済みturnと現行DB projectionの差を再現し、完了証拠を裁定できる。
  • P0-3 Codex親Stop hookを実測する。

    • 成果物: 正式event名、payload、session / cwd情報、stdout / stderr / exit codeの観測記録。
    • 完了条件: boundedなJSON reasonを同じ親turnのcontinuation promptとして注入できるか、できないかを再現手順付きで裁定できる。
  • P0-4 Observer継続turnを実測する。

    • 成果物: timeout後、同じObserver turnをStop continuationで再開する候補比較と、MCP wait transport実測。
    • 完了条件: project-local Stop continuationとMCP tool callの60秒超live waitを再現し、失敗、再開、停止方法を説明できる。
    • 実測: 65秒timerのMCP呼出しがCodex上で正常完了した。サーバー計測は時計境界により64,999msだったが、60秒超のhost保持という検証目的を満たす。途中取消はtimeoutでなくMCP承認要求が原因で、read-only注釈と対象tool限定の明示許可が必要。
  • P0-5 v1実装契約と安全網を固定する。

    • 成果物: 採用API、state path、runtime、検証コマンド、characterization test一覧。
    • 完了条件: 未確定事項3件が解消または明示的blockedになり、反対仮説の検証を一回通過する。
    • 裁定: Throughline JSON CLI + Observer MCP adapter、macOS owner-only state、emitted_unacked receiptを採用。DB直接監視、Throughline本体のMCP所有、cross-platform見せかけ、Host ack見せかけを棄却した。
  • P0-6 Claude親/Claude Observerのhost境界を実測する。

    • 成果物: Claudeの完了turn証拠、正式Stop event/payload、project/session identity、60秒超wait、同じturnへのcontinuation、明示停止の再現記録。
    • 完了条件: Claude Observerと親Claudeへの配送を、Codex wireの流用や推測なしで実装できる。
    • 部分実測: Claude Code 2.1.207でheadless result/end_turn、同じsession IDのresume、SessionStart:resumeを確認した。2.1.210ではbackground jobが75秒までworkingを維持し、90秒timer中の実行中stop、子process消滅、project fingerprint不変を確認した(ADR 0011)。daemon/adapter crash後の結果回収は未検証。完了turnはfinal assistantやprocess exitでなく、Throughline所有のStop receiptへ束縛する。/rewindはforkなので同一session rollbackを新設しない。
    • 上記は旧background job候補の基礎characterizationである。後続の隔離liveではjob sessionId/Stop session_id相関と Stop hook発火までconfirmedとなったが、canonical resultは拒否され、既存background jobへの 公開非対話requestとterminal exact result readはunsupportedと確定した (ADR 0114)。 ただしClaude Observer全体をblockedとはせず、永続PTY上のAiterm claude_agentを新しい公開transport 候補とする(ADR 0115)。
  • P0-7 Observerのprovider配置と役割を固定する。

    • 成果物: Codex親→Codex Observer、Claude親→Claude Observerという同provider契約と、継続的反証ではない伴走者契約。
    • 完了条件: 一般Workerのrate-aware配置、異社相談役、Phase反証とObserverを文書上で分離する。
  • P0-8 Observerの起動責任とlifecycleを固定する。

    • 成果物: ユーザー明示指示、親launcher、同provider、二重起動拒否、明示停止、fault停止の契約。
    • 完了条件: 暗黙起動と自動再起動を禁止し、一target一watchの所有境界を固定する。
    • 裁定: ADR 0002。親session単位の論理Observerとcontext generationへの 更新はADR 0025を正とする。
  • P0-9 Observer repoへCodegraph project indexを導入する。

    • 発見経路: provider binding計画の構造調査で、CLI/MCP登録は済んでいる一方、Observer固有の .codegraph/が未初期化だったため構造queryを利用できなかった。
    • 成果物: upstream正規入口codegraph initが生成する、共有可能な設定と端末local index。
    • 完了条件: codegraph status --jsonがinitialized=true、対象projectがObserver root、 pendingChangesが空、SQLite journalがwalを返し、生成された設定だけが追跡候補になる。
    • rollback: codegraph uninitでObserver固有の.codegraph/だけを除去する。
    • 実測: Codegraph 1.4.1で60 files、1,339 nodes、5,603 edgesをindex化した。statusは initialized=true、journalMode=wal、pendingChanges=0、reindexRecommended=false。 provider bindingの構造探索も実sourceとblast radiusを返した。DBは.codegraph/.gitignoreにより 端末local、生成されたignore metadataだけを追跡候補にする。

Gate: Aiterm claude_agentの非H契約・operation相関付き結果回収・timeout recoveryは dd43c40/3842ff2、related 122/122、full 262/262、独立反証P0/P1/P2残存なしで完了した。 P5-1b4の非H caller coreは完了した。次はP5-1b5 dual-host live Hであり、実Claude初回/follow-upは 同H gateまで成功扱いしない。


Phase 1: Throughline wait依存

  • P1-1 Throughline側に独立した正本プランを作る。

    • 成果物: Throughline repoのdocs/に置かれたcompleted-only read / wait API計画/TODO。
    • 完了条件: opaque cursor、最新thread解決、delta / switch / resync、競合窓、timeout、cancel、再接続、test、rollbackがThroughlineの所有契約として定義される。
    • 正本: /Users/kite/Developer/Throughline/docs/14_observer_completed_turn_feed_plan.md
  • P1-2 Throughline側の計画完遂を確認する。

    • 成果物: observer-wait、observer-readとThroughline側test。詳細TODOはThroughline側正本で管理する。
    • 完了条件: Claude/Codex両hostでin-flight除外、即時changed、待機changed、timeout、呼出競合、thread/host switch、rollback、再起動のgateがThroughline repoでgreenになる。
  • P1-3 Observerからblack-box検証する。

    • 成果物: Observer MCP adapterからThroughline公開CLIだけを使うcontract test。
    • 完了条件: 短縮timeout fixtureでchanged / timeout / missed-wakeup防止を再現し、Throughline実CLIを通した65秒超live callと3600秒設定が受理される。
    • test/throughline-black-box.integration.mjsから実Throughline CLIだけを起動し、待機中changed、 1秒timeout、呼出前completionの即時changed、DB未projection時のprojection_pendingを2.27秒で固定した。 Throughline側の隔離HOME black-boxで65秒超live changedと3600秒設定は確認済み。Control revision 49で親受入済み。
    • Observer MCP adapterを実装し、同じblack-box境界をMCP tool wireから通す。
      • MCP 2025-11-25/2025-06-18のinitialize、固定observer_read/observer_wait、active watch identity、 structured/text result、cancel/stdin shutdown、stdout衛生をADR 0013へ固定した。 node --test test/mcp-server.test.mjs test/throughline-client.test.mjsは10/10 PASS。
  • P1-4 標準testと実Throughline統合testの実行境界を分離する。

    • 成果物: 外部CLIなしでgreenになる標準npm testと、実CLI pathを明示してfail loudに実行する統合test script。
    • 完了条件: 標準gateが統合testをskip扱いで隠さず除外し、明示統合gateでは既存black-box 1件が実Throughline CLIでPASSする。

Gate: ObserverがThroughlineのDB / WALへ依存せず、新規turnを失わず待てる。


Phase 2: 最小Observer loop

  • P2-1 Observerプロジェクトを初期化する。

    • 成果物: runtime、package、lint、unit test、CIの最小構成。
    • 完了条件: 空実装のbaseline gateがgreenで、rollback可能な独立単位になる。
    • 実装: Node ESM / Node 22.13以上、runtime dependencyなし、Node test runner、構文検査、GitHub Actionsを追加。標準gateはnpm test && npm run check。
    • Control証跡: observer-scaffold-runは、初回baselineを親が同じworkspaceで確立したためWORKSPACE_DRIFTで失敗した。このRunを成功・acceptedへ変更しない。P2-1の完了根拠は親が独立に検証した16 test greenとroot commit 7b699c8であり、Task observer-scaffoldだけを本項参照でfinalizeする。
  • P2-2 project target登録を実装する。

    • 成果物: canonical project resolver、observer target register <absolute-project-root>、Observer所有state。
    • 完了条件: 同じprojectを安定したtargetへ解決し、別projectと混同せず、working treeを汚さない。
    • 実装: canonical pathのSHA-256からtarget IDを生成し、macOSの中央stateへ0700/0600でatomic登録する。相対path、symlink state、不正permission、非macOS defaultをfail closedで拒否する。
  • P2-3 最新親スレッド解決を実装する。

    • 成果物: Throughlineのhost-bound確定turn時刻から現在親とhostを選ぶresolver。
    • 完了条件: 親AからBへのthread切替と、Claude/Codex間のhost切替fixtureで、Bの最初の確定turn後にだけ追跡先がBへ切り替わる。複数活動親はfail closedにする。
    • v1境界: ADR 0001。一般的なactive leaseをmtime/PID/TTLで 推測せず、一project一活動親を前提にする。Throughlineが返すambiguous_parentはfail closedにする。
    • 実装: hash-only parent state、snapshot/delta/thread/host切替、cursor連結、pagination transaction、 projection_pending/ambiguous_parent/resync_requiredのfail-closed境界を実装した。
    • 検証: node --test test/parent-resolver.test.mjs 5/5 PASS。commit 91e51bd、Control revision 8。
  • P2-4 一時間wait loopとcursor回復を実装する。

    • 成果物: host-neutralなobserver watch <absolute-project-root>、active watch transaction、親別launcherと、Claude/Codex adapterでchanged / timeout / restartを処理する監視loop。
    • 完了条件: ユーザー明示指示を受けた親だけが同provider Observerを一体起動する。外部Supervisorが一target一processで wait/read/cursor/model operation/applyを所有し、timeoutではAIを起動せず同じcursorから次のbounded wait stepへ戻る。 二重起動、transport / schema / state failureではfail closedまたはfaultedになり、takeover、自動再起動、provider request再送を行わない。
    • Throughline公開CLI clientと、cursorをまだ保存しない一監視cycleを実装する(ADR 0003)。
      • bounded JSON、UTF-8 byte収集、strict schema、Abort時のSIGTERM→SIGKILL terminal cleanup、 orientation/timeout/fixed-through pagination/projection pendingを実装した。
      • 検証: node --test test/throughline-client.test.mjs test/watch-cycle.test.mjs 9/9 PASS。 commit f3bfef1、Control packet e4cf0531…2cc8、revision 17。
    • projection_pending bounded retry、監査後のcursor atomic commit、crash recoveryを実装する(ADR 0005)。
      • prepared → processed → cursor commit → cleanupのjournal store、full-state CAS、crash recoveryを実装した。 検証: node --test test/cycle-store.test.mjs 5/5 PASS。commit 845c002、Control revision 19。
      • watch cycle、bounded retry、監査callback、journal recoveryをSupervisorへ配線した。 通常changedとprepared recoveryのどちらも最初のfixed-through cursorから範囲を拡張せず、 durable callback結果の検証後だけprocessed保存とcursor commitを行う。 検証: node --test test/watch-cycle.test.mjs test/supervisor-cycle.test.mjs 12/12 PASS。 commit 181a54e、Control packet b29a9761…65fe、revision 26。
    • 一target一active watch transactionと明示stopを実装する(ADR 0004)。
      • provider child前のstarting予約、二重起動拒否、watch ID CAS、private handle非公開、 active → stopping → stopped、fault、明示nonce lock回復を実装した。
      • 検証: node --test test/watch-store.test.mjs 7/7 PASS。commit e0a1843、Control revision 14。
    • 公開observer watch/watch start|status|stopを両provider共通の非H lifecycle handlerへ接続する (ADR 0095)。
      • 利用者入力をabsolute project pathだけに保ち、現在親のprovider/runtime/authorizationとhost actionを argv外のexact contextへ分離する。
      • startのreserve→spawn receipt耐久化→ready、sanitized status、terminal receipt後だけのstop完了を、 Claude/Codex共通result schemaとfake host actionで固定する。
      • 実装a4195a3、focused 13/13、関連37/37、static greenを ADR 0096で受け入れた。
    • dotagents/installerから実host actionを注入し、live spawn/stop、session相関をP5-1bのH gateで受け入れる。
    • Codex/Claude親launcherと同provider child lifecycleを実装する(ADR 0006、起動順序の訂正=ADR 0007)。
      • explicit authorization、starting → launching → active、private provider handle、相関付きstop/fault transactionを実装した。 検証: node --test test/parent-launch.test.mjs test/watch-store.test.mjs 16/16 PASS、cycle-store fixture 5/5 PASS。 commits 1ed545c、ed4f077、Control revision 32。
      • unrestricted Codex親ではcustom agentのread-onlyが実効sandboxにならないことを実測し、native Observerを禁止した(ADR 0008)。
      • Codex persistent app-server thread候補/Claude backgroundの親host adapter、同provider Observer role、routing検証を実装する。
        • 全hostのcwdをcanonicalなObserver rootへ固定し、target project_rootをhost cwdや擬似projectへ使わない製品identityを固定した(ADR 0017)。
          • AGENTS.mdを両host共通の静的Observer契約、CLAUDE.mdをClaude固有差分の入口にする。
          • watchごとにthread/jobは分けても、監視対象ごとのtemporary repo/アプリprojectを生成しない。
          • 実行時契約は検証済みchild start envelopeの時だけ発火し、Observer開発AIの権限と分離する。
          • Codex app/Claude UI表示と既存の不要project cleanupは未検証のH gateとして残す。 Claude backgroundはexact tool allowlistでproject readとwrite拒否、job handleのworking → done、同handle stopを実証した。 argvの可変長flag順序とterminal後のlogs回収不能をADR 0010でadapter契約へ固定した。
        • Claude adapterの純粋coreとして、絶対CLI path、固定prompt位置、Observer MCPのruntime-root字句境界、公開/無人許可の分離、 job相関、terminal先行stop、raw出力非保持を実装した(ADR 0012)。 検証: node --test test/claude-host-adapter.test.mjs test/parent-launch.test.mjs 14/14 PASS。
        • 実行層でClaude CLI/Observer MCP executableのrealpath・version・所有を検証し、spawn/observe/stopをparent-launchへ配線する。 src/claude-host-runtime.mjsでmanifest固定path、file identity/digest、Claude 2.1.210、MCP 0.0.0、 exact tool surfaceを検証し、handle先行耐久化を守る分離runtimeを実装した(ADR 0015)。
          • Claude --bgのshort IDをspawn直後に耐久化し、observe/readyを同じ関数へ畳み込まない。
          • MCP tool surfaceは実装済みのobserver_read/observer_waitだけへexact固定し、wildcardを許さない。
          • ADR 0060の所有権訂正によりproduction Observer AIの tool allowlistを空へ変更した。MCP server自体は削除せず、compatibility/diagnostics裁定を後続Taskへ残した。
            • claude-host-runtimeの旧MCP allowlist期待を空surface契約へ揃えた。commit d34b119、 失敗scopeのfocused 1/1がgreen。直前関連gateの他65件は同じproduct filesでgreenだったため再利用し、66/66へ収束した。
          • spawn結果不明時はwatch固有nameとcwdから回収し、同じwatchを再spawnしない。
          • 検証: focused 23件、parent-launch接続7件、npm run check、実binary read-only diagnosticsがgreen。
        • Codex app-serverの純粋adapterとsession runtimeをparent-launchへ配線した(ADR 0018)。
          • thread/start結果不明は同一cwdの候補へattachせずthread_start_unknown、turn/start結果不明は turn_start_unknownとして耐久化し、同じwatch/cycleの再実行を拒否する。
          • thread IDをwatch handle、turn IDを別operation journalへ保存し、親stateへthread handleを耐久化してからだけ turn/startする。thread/readとthread/resumeをterminal照合/継続購読に分離する。
          • interrupt ACKではwatchを閉じず、同じthread/turnのterminal receiptをparent-launchで必須化した。 interrupt結果不明でも送信前にstoppingを耐久化し、同じturnへ再送しない。
          • focused gate: node --test test/codex-host-adapter.test.mjs test/codex-host-runtime.test.mjs test/parent-launch.test.mjs — 23/23 PASS。
          • app-server process transport、実model turn、UI、65秒超wait、crash後のunknown reconciliation、Observer MCP限定writeは 未検証のH/後続gateであり、production採用済みとはしない。
        • Codex app-serverのbounded JSONL process transportを実装した(ADR 0019)。
          • Codex executable identityとversionをObserver rootで確認し、codex app-serverをshellなし・環境allowlistで生成する。
          • request IDとresponseをexact相関し、未知/重複ID、oversize/不正JSONL、stderr/process終了をfail closedにする。
          • pending requestの切断は成功や自動retryへ丸めずunknownとして返し、同じlogical operationの再実行判断は codex-host-runtimeのdurable journalへ委ねる。
          • fake child processのfocused testだけをこのTODOのgateとし、実Codex process/model turnは起動しない。
          • focused gate: node --test test/codex-process-transport.test.mjs test/codex-host-runtime.test.mjs — 15/15 PASS。
        • parent session epochごとに一論理Observerを束縛し、同epoch内のcontext budget到達では 一つの物理host generationだけをterminal確認付きで世代交代する。
          • watch authorizationは維持し、新しいwatchやtarget別projectを生成しない。
          • generation counter、completed cycle count、累積bounded input bytesを独立durable stateに持ち、 8 completed cycle/262,144 model-visible UTF-8 bytesのhard thresholdとmodel前reservationを固定した (ADR 0034、ADR 0035)。
          • cycle pending v2、input reservation、cursor/generation commitをexact-once接続し、各write間の crash recoveryと非永続inputを固定した(ADR 0036、 ADR 0037)。
          • cursor、dedupe/cooldown receipt、boundedな未解決仮説だけを引き継ぎ、raw会話/tool logは保存しない。
          • watch継続の短命host journal、旧terminal確認、旧→新handle CAS、ready後activation、 Codex generation namespace、Claude live候補限定をfake fixtureで実装した (ADR 0038、 ADR 0040)。
          • 上記record-first coreをClaude/Codex固有のterminal stop/次generation start commandへ接続する。
            • raw handleを出さないrecovery contextと、watchを再遷移させないCodex generation runtimeを先行実装した (ADR 0042、 ADR 0043)。
            • recovery contextを使うClaude/Codex provider bindingを、一command一stepで実装する (ADR 0044)。
              • Codexの再送なしterminal観測APIを実装する。
                • commit b06a847。同一generationのdurable thread/turnだけをread-only照合し、 terminal/pending/unknownとraw-free receiptを返す。
              • host-neutral provider binding step machineを実装する。
                • commit 02329ad。一call一provider mutation、stop再送なし、provider ready後の core spawn/ready適用、unknown fail-closedを固定した。
              • 隔離した2 Workerの成果を本線へ統合し、focused gateを通す。
                • 関連gate 46/46、npm run check、git diff --check成功。両TaskはControl revision 29までに ADR 0046でfinalizeした。
            • model request送信結果不明をhost lifecycleと別journalで回収する (ADR 0047)。
              • generation reservationより先にhost-neutral model operationをpreparedで耐久化し、 prepared -> reserved -> dispatching -> accepted -> completed -> appliedの一方向遷移と identity conflictを実装する。
                • commit 4c3cc03。exact cycle result、UTC時刻非後退、private path/lock、status限定cleanupまで focused 8/8で固定し、ADR 0049で受け入れた。
                • Supervisor統合前の独立反証で見つかったlock残留、completed result locator、planned rollover、 processed前cleanupの4件をADR 0051どおりcorrective実装する。
                  • commit 8afebca。same/next generationのprepared回収を含むfocused+related 27/27、 npm run check、scoped diff-checkを通し、 ADR 0053で受け入れた。
              • Supervisorをissue_once/recover_only/idempotent applyへ分け、dispatchingからmodel requestを 再送せず、strict parse済みcanonical AI outputだけをcycle processedへ移管する (ADR 0050)。
                • commit c226cc9。focused 15/15、関連gate 47/47、npm run check、scoped diff-checkを通し、 ADR 0054で受け入れた。
              • prepared/reservation/provider handle/canonical result/apply/processed/cleanup間の crash matrixをfocused fixtureで固定する。
              • Claude/Codexのexact operation result readをprovider固有journalへ実装し、handle欠損を 別operationへの再送で隠さない(ADR 0055)。
                • Codexは保存済みthread/cycle turnのthread/readだけからexact agentMessage itemを再読する。 Claudeはjob/sessionを 束縛したStop.last_assistant_messageをhook中にcanonical保存する。
                • logs/transcript/private provider state/別turn/別job/新規requestへのfallbackを禁止する。
                • provider journal coreとfake public-surface fixtureを先に受け入れるが、この時点では本TODOを閉じない。 現行profileへObserver所有hookだけを注入するhost adapter接続、Codex item baseline、 両host session/turn相関、Supervisorのcomplete -> provider cleanup -> applyを続けて実装する。
                  • provider journal coreをcommit 4443ff9で追加し、両host合計focused 10/10を通して ADR 0056で受け入れた。
                  • SupervisorをcompleteModelOperation -> cleanupProviderOperation -> applyCycleへ接続し、 generic completed recoveryとcleanup fail-closedをcommit 3600876、focused 26/26、 ADR 0057で固定した。
                • Claude job sessionId/Stop session_idの一致、Codex hook trustとin-progress item再読はlive H gateで version固定し、未実証をproduction対応済みにしない。
                • SUPERSEDED: host-neutral canonical cycle requestとCodexの thread/read baseline -> turn/steer -> ACK -> accepted journal fixtureをcommit 1bb7b07、 focused 22/22、Supervisor関連16/16、ADR 0059で 受け入れたが、AI wait loopとSupervisorの二重所有およびStop idle問題が判明したため、 ADR 0060でturn/steer/Stop continuation部分をsupersedeした。 canonical requestとprovider journal欠損補正は維持する。
                • 外部Supervisor単一所有とCodexの thread/read context -> cycle turn/start -> ACK -> accepted journalをcommit 3f35dbbでcorrective実装した。 focused 38/38、Supervisor関連16/16、static gateを通し、 ADR 0061で受け入れた。
                • Codex production Supervisor callerを接続し、cycleごとのsession/turn/exact result順序をlive H gateで固定する。
                  • applyCycle/finalizeAppliedCycleのproduction callbackをcommit fc51157で実装し、durable operation時刻とcanonical cycle inputからadvisory messageを決定的に再構成してMailbox exact replay/ cleanupへ接続した。focused 4/4、関連40/40、static gateを通し、 ADR 0063で受け入れた。
                  • 一target一process lock、evidence input、Codex provider callback、sanitized production receiptを 束ねる一step callerをcommit 0ca7abeで実装した。focused 4/4、関連44/44、static gateを通し、 ADR 0065で受け入れた。
                  • verified Throughline clientとpre-initialized Codex app-server sessionを所有する外部process/CLIへ 一step coreを配線し、timeout/cancel/fault/explicit stop loopを固定する。
                    • target固有process lease、active watch停止監視、timeout/model pendingのbounded反復を host-neutral process loopとして実装する。 model_result_unknownは回収不能なterminal faultとしてpollせず停止する(ADR 0067)。
                    • Throughline executableとCodex app-serverを一process内で検証・初期化し、終了時にCodex childの terminal確認を必須化する。子process残存や終了不明を成功へ丸めない。 app-server faultは進行中Throughline waitへ即時伝播する(ADR 0068)。
                    • observer supervisor run CLIをabsolute command/watch identity/Observer rootへ束縛し、 signal cancel、explicit stop、faultのJSON/exit contractをfocused fixtureで固定する。
                    • focused/related gateを通し、ADR 0069と 独立commitへ固定する。corrective変更後の最終関連gateは70/70、static gateはgreen。
                    • repo正典に残っていた旧AI-owned wait/Stop continuation/Observer MCP公開の記述を、 ADR 0060の外部Supervisor単一所有とproduction AI exact-empty tool surfaceへ補正する。
                • 旧Claude background job経路のblockedを維持し、Aiterm公開対話transportをClaude callerへ接続する。
                  • P5-1b3の非H準備、live H、production callerを分離し、親Mailbox hookを result captureへ流用しない契約をADR 0109で固定した。
                  • characterization専用の隔離Stop capture、sanitized receipt、 prepare/verify/cleanup harnessをfixtureで閉じた(ADR 0110)。
                  • 専用runbookに従い、 一つのClaude jobでlive H characterizationを実施した。jobはdone、cleanupと project/host settings不変はconfirmedだが、Stop capture欠損、reply/terminal exact result非公開により接続はblockedとした(ADR 0111)。
                  • Stop未発火とpayload/result不正を区別するraw-free diagnostic receiptを 非Hで実装し、focused 9/9、related 29/29で受け入れた (ADR 0113)。
                  • diagnostic receipt受入後、別H承認で一つのjobだけを再characterizeした。 hook invocation、job/session、Stop payloadはconfirmed、canonical resultは E_CLAUDE_CHARACTERIZATION_RESULT_INVALID、公開reply/terminal exact resultは unsupportedであり、接続はblockedのままとする (ADR 0114)。
                  • Aitermの永続PTY claude_agentへ置き換え、operation相関付きexact resultと timeout後無送信回収を非H gateで閉じた。次はP5-1b4でproduction callerへ接続する。
              • Mailbox publishをdeterministic message IDの同内容replayだけ冪等成功にし、異内容をconflictにする (ADR 0048)。
                • 既存publishMessageのduplicate拒否は維持し、model operation専用publishOperationMessageと raw-freeなpublish-receipts/を追加する。
                • receiptをpreparedでrecord-first作成し、inbox/processing/consumer receiptからexact digestを回収する。
                • model journalのapplied後だけpublish receiptをcleanupし、それまでは対応するconsumer receiptをretention対象外にする。
                • commit 0e7a005。focused 15/15、npm run check、scoped diff-checkを通し、 ADR 0052で受け入れた。
          • parent rebind、planned rollover、fault recoveryを別transition/receiptにして統合する。
            • planned rolloverを既存generation host journal/provider bindingから Supervisor processへ接続し、同じverified runtimeで一stepずつ回収して 新generation activation後にprepared cycleへ戻る (ADR 0070)。
              • 実装commit 2bfc09c。focused 43/43、関連gate 103/103、npm run check、 git diff --checkを通し、ADR 0071で受け入れた。 実provider commandのH受入はPhase O2 gateへ残す。
              • Codex terminal観測時にraw-free receiptをhost terminalへ再構成せず、 already-terminal stop経路のexact receiptだけをcoreへ渡す (ADR 0080)。
                • 補正前focused 4/5でE_PARENT_HOST_RECEIPTを再現し、commit fe4f743で修正した。 focused 6/6、npm run check、git diff --checkを通し、 ADR 0081で受け入れた。
            • parent epoch切替を旧generationへのmodel requestなしで明示 rebind_required transition/receiptへ記録し、parent authorizationと terminal確認後だけ新epochを開始する(ADR 0072)。
              • host-neutral rebind transaction、new epoch generation、watch provider/handle CASを実装する。
                • commit 426f8b9。focused 21/21、関連gate 83/83、npm run check、 git diff --checkを通し、ADR 0073で受け入れた。
              • Claude/Codex provider bindingを一command一stepで接続した (ADR 0075)。
                • provider recovery contextをauthorization/launch request digestへ再束縛し、 Codex turn-start unknown再送と不完全terminal receiptを補正する (ADR 0074)。 core correction d7ebdbb、provider binding 3a737ad。focused 6/6、関連66/66、 npm run check、git diff --cached --checkがgreen。
              • Supervisor processへ接続し、new epoch activation後にprepared cycleへ戻る (ADR 0076、 ADR 0077)。 実装commit 107d2ca。focused 33/33、関連122/122、npm run check、git diff --checkがgreen。
              • 実thread/host switchとcrash recoveryをPhase O2 H gateで受け入れる。
            • watch/provider faultをterminal確認済みのfault transition/receiptへ記録し、 unknown outcomeを自動restart、takeover、別handle探索で隠さない (ADR 0078)。
              • host-neutral generation fault journal/専用transitionを実装する。
              • Claude/Codexの一command一step terminal bindingを実装する。
              • Supervisorへrecord-first faultとfault-first restart gateを接続する。
              • focused/関連gateと静的検査を一度ずつ通し、受入ADRへ証拠を固定する。
                • design e83970c、implementation 22cf33a。focused 22/22、関連107/107、 current HEADのnpm run check、git diff --checkがgreen。 ADR 0082で受け入れ、 実host fault/terminal/crash recoveryはPhase O2 H gateへ残す。 P2-5のread-only強制がgreenになるまでlive childは起動しない。
  • P2-5 read-only境界を強制する。

    • 成果物: production AIのtool surfaceを空にし、project観測とObserver state/Mailbox writeを 外部Supervisorだけが所有する実行profileと拒否test(ADR 0083)。
    • 完了条件: host別live gateでproject writeが拒否され、Supervisor監視とMailbox publishは成功する。 非H fixtureのproject fingerprint不変をlive拒否証拠へ読み替えない。
    • ADR 0060によりproduction AIのThroughline/Observer MCP/Mailbox tool surfaceを空にし、 Observer MCP observer_read/observer_waitはread-only diagnostics/compatibilityへ分離した。 Mailbox writeは外部Supervisorの固定callbackだけが所有する。
    • Observer MCPをread-only compatibility/diagnosticsとして維持する裁定を実装する (ADR 0097)。
      • --diagnosticsの決定的なsanitized JSON、package bin、既存stdio/version互換を固定する。
      • active watch exact照合、write API不在、cancel、stdout hygieneをfocused/関連gateで再確認する。
      • production AIのtool surface空を維持し、MCP greenをlive provider成功へ読み替えない。
      • 実装1d85039、focused 5/5、関連24/24、static greenを ADR 0098で受け入れた。
    • Codex native custom agentのTOML指定だけではunrestricted親のoverrideを防げないことを実測した。
    • app-server persistent threadのper-thread read-only、project write拒否、別processからのthread/read/thread/list回収をcharacterizationした(ADR 0009)。
    • 非H: Claude exact-empty tool surface/既存隔離flagとCodex runtime-root read-only envelopeを固定し、 同じSupervisor cycleでHEAD/index/tracked・untracked/modeを含むproject fingerprint不変と Observer state root配下のMailbox publish成功をfixture化する。 commit 2168199。focused 3/3、関連60/60、npm run checkを通し、 ADR 0084で非H部分だけを受け入れた。
    • Codex live H: アプリ内表示、65秒超turn、adapter crash後のturn resume、明示interrupt/停止、 project write拒否をcharacterizationする。
    • Claude backgroundをRead,Grep,Globだけで起動し、組込みtool surface上のproject read成功、Write tool不在による一回のwrite拒否、公開job lifecycleをcharacterizationした(ADR 0010)。
    • 空のsetting sources、skills/Chrome無効、strict MCPの一試行で、HEAD、index、tracked/untracked、modeを含むproject fingerprint不変をcharacterizationした(ADR 0011)。
    • Claude backgroundの65秒超継続、実行中stop、子process消滅をcharacterizationした。MCPは--toolsによる公開と--allowedToolsによる無人許可を分離する。
    • Claude adapter coreをADR 0060でexact-empty tool surfaceへ補正し、raw agent list/stop stderrを 構造化receiptへ保持しないことを固定した。ADR 0012のRead,Grep,Glob/mcp__observer__* allowlistはsuperseded。
    • Claude live H: --safe-modeと公開background agent定義、認証維持、隔離--settings Stop hook、 project write拒否、再stop receipt、daemon/adapter crash後のterminal result回収をcharacterizationする。 --bareはOAuth/keychainを無効化するため隔離fallbackにしない。 即時完了、terminal直前crash、実行中restart、daemon消失、失敗terminalを独立fixtureにし、doneを結果回収済みへ丸めない。 再stopは成功receiptを返さない実測のため、terminal stateを先に確認し、実行中stop receiptとterminal観測を分離する。

Gate: 手紙を生成しない最小Observerが、親の再作成と一時間timeoutを含めて継続監視できる。


Phase 3: Mailboxと親Stop hook

  • P3-1 中央Mailboxの保存・publish契約を実装する。

    • 成果物: project別inbox、message schema、atomic publish、permission / size / digest検査。
    • 完了条件: 不正messageを拒否し、正常messageを部分書込なしで公開できる。
    • 実装: strict schema、canonical digest、byte上限、secret pattern拒否、同一message ID拒否、同一filesystem上の完全書込み後publishを実装した。
    • dedupe_keyが既存secret pattern検査から漏れている欠陥を ADR 0085で独立補正した。 修正前focused 6/7で再現し、commit ae7e336、focused 7/7、関連30/30、static gateを ADR 0086で受け入れた。
  • P3-2 consume transactionを実装する。

    • 成果物: atomic claim、本文削除、digest-only receipt、delivery_unknown、retention。
    • 完了条件: concurrent consumerとfault injectionで同一本文を二重配送しない。
    • consumer lock、inbox→processingのatomic claim、claimed→emitted_unacked receipt、本文削除を実装する。
    • claim後crashを明示的にdelivery_unknownへ回収し、再配送しない。
    • malformed messageを注入せず、本文なしinvalid receiptへ変える。
    • 完了receiptを30日・最大1000件へbounded化し、claimedは自動削除しない。
    • lock owner nonceの観測と一致確認を必須にする明示recoveryを実装する。
    • claim後crash、malformed本文、重複publish、concurrent consumerの代表faultをtestで再現する。
  • P3-3 誤配送防止を実装した(ADR 0020)。

    • 成果物: project target、観測host、thread IDによるrouting、旧thread/旧host手紙の失効処理。
    • 完了条件: 別project、旧thread、target不明ではclaimせず、現在project / threadだけが取得できる。
    • projectごとの物理inbox分離と、target / thread完全一致時だけのclaimを実装する。
    • 親Stop payloadからのcurrent target解決、旧thread messageの失効receiptを実装した。
      • Mailbox message/receiptへraw thread IDを保存せずthread_sha256へ統一する。
      • Stop payloadのraw thread IDはその場でhash化し、registered target、active watch provider、committed parentの host/thread hashが全一致したauthoritative current hookだけをclaim可能にする。
      • authoritative current hookだけが同targetの旧thread messageを本文なしstale_thread receiptへ失効させる。 target不明、watch inactive、旧host/旧thread hookはinboxを変更しない。
      • focused gate: node --test test/mailbox-store.test.mjs test/mailbox-consumer.test.mjs test/mailbox-routing.test.mjs — 14/14 PASS。
  • P3-4 親Stop hook adapterを実装する。

    • 成果物: Claude/Codex別のMailbox fast path、bounded advisory render、installer / verify / rollback。
    • 完了条件: 両hostでMailboxなしなら短時間で終了し、一件の手紙を同じ親turnへ一度だけ正式なcontinuation promptとして注入できる。
    • P3-4a Observer所有のparent Stop hook coreを実装した(ADR 0021)。
      • Claudeは正式なStopのhookSpecificOutput.additionalContext、Codexは正式な decision:"block" + reasonだけを使う。
      • raw session_idはroute照合中だけ使い、receiptにはprovider/turn相関のdigestだけを残す。
      • stop_hook_active=trueでは新しい手紙をclaimせず、一つの親turnへObserver助言を最大一件にする。
      • claim後のrender、stdout、finalize失敗は本文を再配送せずdelivery_unknownへ回収する。
      • focused gate: node --test test/parent-stop-hook.test.mjs test/mailbox-consumer.test.mjs test/mailbox-routing.test.mjs — 18/18 PASS。
      • npm run check PASS。continued turnの実CLI fast pathはexit 0/stdoutなしを確認した。
    • P3-4b installer / verify / rollbackを実装する。
      • Observer側がhook commandと設定fragment生成/検証を所有し、dotagentsは工場配布adapterだけを所有する。
      • 既存hookを上書きせず合成し、Codexではasync:trueを使わず同期fast pathとして配線する。
      • P3-4b1 Observer hook-config契約を実装した(ADR 0022/ADR 0023)。
        • provider別canonical Stop entryのJSON生成と、candidate configの missing / duplicate / noncanonical / canonical判定だけを行う。
        • macOS v1では、実在するabsolute executable pathを明示入力し、空白、制御文字、引用符を含むcommandを拒否する。
        • Host設定を変更せず、fragment/診断のstdout以外へstateを書かない。
        • focused gate: node --test test/parent-stop-hook-config.test.mjs — 7/7 PASS。npm run check PASS。
        • 実装者ReportはControl revision 28でstrict import、revision 29で親受入した。
      • P3-4b2 dotagents transactional applierを実装した(ADR 0024)。
        • Observerのcanonical fragmentをconsumeし、Claude settings.jsonとCodex hooks.jsonへstandalone Stop entryを各一件に正規化する。
        • dry-runを既定にし、apply時は二設定をbackup/prepare/atomic replaceし、途中失敗は両方rollbackする。
        • 既存hook、matcher group、trust、model、effort、permission、credentialを変更しない。
        • dotagents commit 2fb48cb、Worker Report strict import revision 45、parent accept revision 46。
        • focused gate bash tests/install/observer-hook-config.shとmake lint-py PASS。実HOME applyとhost実火は未実施。
    • P3-4c live host gateを実証する(H)。
      • Claude/Codex各一回で、Mailboxなしのfast exitと一件の同一turn continuationを確認する。
      • Host ackが無いv1ではreceiptをdeliveredへ格上げしない。

Gate: 手動publishした手紙が正しい親へ最大一回だけ届き、本文が残らない。


Phase 4: Observer AIとノイズ抑制

  • P4-1 Observer起動契約と出力schemaを実装する。

    • 成果物: 親と同じproviderを選ぶhost resolver、read-only伴走者役割、禁止事項、no_advisory / advisory proposalの固定契約。
    • 完了条件: 異provider Observer、継続的反証、通常会話、実装、自由形式出力へ逸脱した結果をSupervisorが拒否する。
    • 同provider resolverと両host共通runtime prompt、observer.ai_output.v1のstrict parser/canonical digestを 実装した(ADR 0026)。
      • 静的人格はObserver rootのAGENTS.md/CLAUDE.md、wire protocolは生成promptを正本とする。
      • no_advisoryへの理由追加、複数proposal、未知field、自由文、Markdown、過大出力をfail closedにする。
      • focused gate: node --test test/observer-ai-contract.test.mjs test/parent-launch.test.mjs test/claude-host-adapter.test.mjs test/codex-host-adapter.test.mjs — 29/29 PASS。
    • P4-2の信頼済みcycle contextとP4-3のsemantic gateを通した後、Mailbox publishより前に Supervisorが本parserを必須実行し、provider/target/watch/cycleをAI自己申告なしで束縛した (ADR 0089)。
  • P4-2 bounded evidence収集を実装する。

    • 成果物: 新規turn、plan、diff、git、test evidenceの最小snapshot。
    • 完了条件: prompt全文、secret、巨大logを保存せず、手紙のclaimを検証できる参照を作れる。
    • observer.evidence_snapshot.v1の32 KiB全体上限、section別上限、redaction/truncation、 digest-only receiptを固定した(ADR 0027)。
      • generation hard ceilingは最大8 completed cycleまたはObserver所有model-visible payload累積256 KiBとし、 次cycleの開始前にplanned rolloverする。
    • host-neutral snapshot builderとstrict validatorを実装する(ADR 0031)。
      • Throughline turn itemをexact検証し、最新側から最大12 KiBへboundする。
      • plan最大4 refs/6 KiB、git最大8 KiB、test receipt最大16件/4 KiB、全体32 KiBを強制する。
      • raw snapshotを保存せず、digest、bytes、件数、truncation/redaction flagsだけのreceiptを生成する。
      • Control Run 1は契約不足でreject、Run 2はnative無応答をcancelledへ閉じた。未受入成果を成功扱いせず、 ADR 0028によりsuccessor Controlへ移送して継続する。
      • successorの再実装は、別会社Composerの認証H、sidecar config不足、native二失敗を明示した上で、 execution-verifiedなaiterm Codex一件へ親review配置する(ADR 0030)。
      • strict Worker Reportを手補正せずimportし、親のfocused 15/15、npm run check、対象2 pathの git diff --checkを再確認してControl revision 8でacceptした。実装はcommit 0536d07へ独立固定した。
    • read-only collectorを実装し、承認済みplan ref、git HEAD/status/diff evidence、既存test receiptを snapshot builderへ渡す。collector unavailableを空の成功へ丸めず、利用不能refとして明示する。
      • path containment、1 MiB取得上限、固定git argv、domain-separated source digest、test receipt投影を ADR 0032へ固定した。live repoとSupervisor配線は別gateとする。
      • strict Worker Reportを手補正せずimportし、親のfocused 22/22、npm run check、対象2 pathの git diff --checkを再確認してControl revision 17でacceptした。実装はcommit 4276615、受入証拠は ADR 0033へ独立固定した。
    • generation stateへcycle数とmodel-visible byte数を耐久化し、8 cycle/256 KiB到達前の terminal確認付きplanned rolloverへ接続する。
      • 一parent session epochへ一論理Observer、一watch内で一active generationを維持する。
      • model呼出し前のexact reservation、8 completed cycle、262,144 UTF-8 bytes、fresh generationでも 一入力が超過する場合のfail-closedをADR 0034へ固定した。
      • generation state/budget reservation、cycle transaction接続、host terminal/次generation起動を 独立gateに分け、旧generationのterminal不明時は新世代を起動しない。
      • generation stateとmodel呼出し前のexact reservationを実装した。strict Worker Reportを手補正せず importし、親のfocused 24/24、npm run check、対象2 pathのgit diff --checkを一度再確認して Control revision 25でacceptした。実装はcommit 9a2b899、受入証拠は ADR 0035へ独立固定した。
      • cycle cursor commitとgeneration completionを同一target transactionへ接続した。
        • Supervisorをinput構築とmodel処理へ分離し、予約成功後だけmodel callbackを呼ぶ。
        • pending cycle v2へinput digest/bytesを保存し、cursor/generation/cleanupを同じlockで crash-recoverableに適用した(ADR 0036、 ADR 0037)。
      • provider別host terminal確認と次generation activationを接続する。
        • host-neutral journal/watch handle CAS/provider recovery補助をfake fixtureで実装した (ADR 0040)。
        • Supervisor processから既存provider bindingを同じverified runtimeで回収する非live統合を実装した (ADR 0071)。
        • coreが返すauthorization/receiptを実Claude/Codex commandへ結ぶbindingとH受入を完了する。
  • P4-3 過剰指摘抑制を実装する。

    • 成果物: materiality、evidence、novelty、actionability、timing gateとdedupe / cooldown。
    • 完了条件: 好み、一般論、証拠不足、対処中、同一指摘のfixtureで手紙を出さない。
    • P4-3a runtime deterministic gate: evidence ref一意性/適格性、record-first current decision、 60分cooldown、severity escalation、bounded historyをhost-neutral coreへ実装する (ADR 0087、 ADR 0088)。
    • P4-3b cycle application integration: acceptedだけをMailboxへexact publishし、suppressed専用result、 crash replay、finalization/retentionを既存model operation順序へ接続した (ADR 0089)。
    • P4-3c semantic behavioral eval: materiality、actionability、semantic timing、親が対処中かを 文字列heuristicへ落とさず、好み/一般論/対処中をno_advisoryにするstrict eval fixtureを固定する。 実provider採否はP4-4 H gateへ残し、runtime機械gateだけでP4-3を完了扱いしない (ADR 0090、 ADR 0091)。
  • P4-4 severityと最小dogfoodを完了する。

    • 成果物: info、warning、review_requiredの実例と採否記録。
    • 完了条件: 正常進行では沈黙し、有益な助言とソフトストップを各一回だけ配送できる。

Gate: Observerが親の仕事を奪わず、ノイズより価値の高い助言だけを送る。


Phase 5: 統合、監査、還流

  • P5-1 E2Eとfault injectionを完了する。

    • 成果物: Codex task_complete/Claude実証済み完了証拠 → Throughline → 同provider Observer → Mailbox → 親Stop continuationの両host統合test。
    • 完了条件: timeout、thread切替、crash、重複通知、誤配送、claim失敗を含む受け入れ条件がgreenになる。
    • P5-1a 非H core E2E: 実Observer state/transactionとversioned Throughline/Codex公開境界fixtureで、 Codexのcompleted cycleからsemantic decision、Mailbox、parent Stopまでを貫通する。silence、suppression、 crash replay、重複、誤配送、claim失敗をexact-once契約へ収束させ、Claudeはstate変更前の provider_unavailableだけを受け入れる(ADR 0092)。
      • provider journal cleanup後・generic applied前のcrash replayで、production callbackが generic completedのprovider receipt/output digestをcleanup evidenceへ渡さず永久停止する欠陥を ADR 0093どおり補正する。
      • 実装 ddd768a/e203190/f6b296b、focused 6/6、関連178/178、npm run check greenを ADR 0094で受け入れた。
    • P5-1b-preflight 非H: dual-host live H campaignのread-only prerequisite、 必須証拠、停止条件、rollback、収集禁止情報をversioned receiptとrunbookへ固定する (ADR 0103)。実装 bbe407d、focused 13/13、related 40/40、actual read-only preflight h_required、npm run check greenを ADR 0104で受け入れた。
    • P5-1b1 Codex caller core 非H: current parent、watch、host receipt、initial generation、 同一app-server transport、Supervisor loop、terminal stopを一processへ接続する (ADR 0105)。実装 286a6db、focused 9/9、related 77/77、npm run check greenを ADR 0106で受け入れた。
    • P5-1b2 Codex parent entry/dotagents配布 非H: 現在Codex親からexact contextを注入し、 isolated HOMEでinstall/verify/rollbackする。live providerは起動しない (ADR 0107)。Observer 659924c/0690ee0、dotagents 21bc352、focused 12/12、related 25/25、isolated install/verify/rollback、npm run check/make lint greenを ADR 0108で受け入れた。
    • P5-1b3 Claude public surface characterization/代替transport確定: 公開非対話reply ACK、exact result read、 job/session/Stop相関の実在または不在を、ADR 0109の 順序で確定する。private protocolやheadless resumeへfallbackしない。
      • P5-1b3a 非H harness: characterization専用の隔離Stop capture、sanitized receipt、 prepare/verify/cleanupをfixtureで閉じた。親Mailbox hookをresult captureへ流用しない。 Observer f40b672、dotagents 78c358b、focused 10/10、related 26/26、 package/isolated install gateをADR 0110で受け入れた。
      • P5-1b3b live H: 専用runbookで 一つのbackground jobだけを起動した。job_session_correlation=blocked、 stop_capture=blocked、reply/terminal exact resultはunsupported、cleanupとfingerprint不変は confirmedである(ADR 0111)。 旧background job経路は必要な公開契約が揃わない限りblockedのまま維持する。
      • P5-1b3c 非H diagnostic receipt: Stop未発火とstdin/payload/result不正をraw-freeに 分離し、direct shebang CLI、verify、cleanupをfocused/related gateで閉じる (実装 f239a07、focused 9/9、related 29/29、npm run check green、 ADR 0113)。
      • P5-1b3d live H再characterization: 別H承認で一つのbackground job/Haiku requestだけを 起動した。hook invocation、job/session、Stop payload、terminal、cleanup、project/host settings 不変はconfirmed、canonical resultはE_CLAUDE_CHARACTERIZATION_RESULT_INVALID、公開reply/ terminal exact resultはunsupportedである (ADR 0114)。 旧background job経路は必要な公開delivery/result contractが現れるまでblockedとする。
    • P5-1b3e Aiterm Claude対話transport 非H: Aitermの永続PTYへ対話型claude_agentを追加し、 promptなし起動、初回/follow-up、Stop完了、operation相関付きexact result、timeout後回収、interrupt/closeを Aiterm側の独立plan・gate・commitで閉じる。claude -p反復は代替にしない (Aiterm dd43c40/3842ff2/ceb75e8/28b7438/f0fcf10。相関gate focused 1/1、 related 122/122、full 262/262、独立反証後green、構造化caller gate focused 5/5、related 126/126、 launcher receipt gate focused 4/4、related 94/94、 ADR 0115)。
    • P5-1b3f live順序整理: Aiterm単体live smokeをP5-1b4より前に反復せず、P5-1b5の一回の dual-host live Hへ統合する。これはlive成功ではなくqueue統合の完了である。
    • P5-1b4 Claude caller core 非H: P5-1b3eで固定したAiterm公開面だけをissue/recover/cleanup、 initial generation、同じ永続Claude sessionを所有するSupervisor loopへ接続する (ADR 0116)。
      • P5-1b4a: Aiterm stdio MCPをversion/tool schemaまで検証するtransportと、claude_turnの structured statusをgeneric model callbackへ変換するClaude provider operationを実装した。 focused 8/8、related 58/58、npm run check green。受入証拠は ADR 0117。
      • P5-1b4b: 新規production routeのprivate host handleをclaude.sessionへ分離し、promptless managed claude_agent launch、structured receipt、watch activation、initial generationを接続した。 明示launch拒否とtransport unknownをjournalで分離し、unknown時だけrecover-onlyを許す。旧claude.job background routeはblocked履歴互換だけに限定した。focused 27/27、related 35/35、npm run check green。 受入証拠はADR 0118。
      • P5-1b4c: Claude provider runtimeをproduction step、Supervisor process、親caller、CLIへ接続し、 通常completed cycle間で同じsession handleを再利用する。通常終了はpty_close成功後にMCP processを閉じ、 未対応rollover/parent rebindはfail loudを維持した。focused 27/27、related 91/91、npm run check green。 受入証拠はADR 0119。
      • P5-1b4d: rollback/parent rebindのstop/relaunch/recoveryをAiterm公開toolだけへ接続し、 focused/related gate、親反証、独立commitで19dを閉じる (設計訂正はADR 0120)。
        • Aiterm側の欠落契約を所有repoへ割り込み登録し、pty_closeのidempotent closed | already_closed structured receiptと0.14.0 versionを独立gate/独立commitで閉じた (Aiterm 056e0a4、focused 4/4、related 174/174、Aiterm ADR 0012)。
        • Aiterm launch response loss時に、session存在証拠ではないclaude_turn(operation_not_found)を spawn証拠へ誤用しているP1を修正する。Aiterm側の相関済みclaude_agent exact replayだけへ置換し、 同じsession名でもlaunch相関ID/引数identityが違うsessionを採用しない (Aiterm affc2df、Aiterm focused 6/6・related 96/96・full 269/269、Observer focused 11/11、 訂正設計はADR 0122)。
        • ObserverのAiterm検証を0.14.0/pty_close output schema/launch_operation_id input schemaへ上げ、 text解析を禁止する。
        • 同一generation内だけ同じsession IDを再利用し、planned rolloverとsame-provider parent rebindでは parent epoch+generation sequenceから決定した別session instanceを使う。watch固定session/launch receiptを 新generationへ再利用しない。
        • 旧session close receipt→terminal durable記録→新session spawn/recovery→watch handle CAS→ready→ generation activationを既存host-neutral transactionへ接続する。response loss後は同じclose/launch operationだけを 回収し、prompt再送、旧background Claude、Codexへのfallbackを行わない。
          • parent受入で、planned rolloverだけがstructured close command receiptをjournalへ保存し、parent rebind adapterは同receiptを破棄している非対称を検出した。修正前0/2、補正後2/2。旧v1 journalの stop_command_receipt_digest欠落はnull読取→次transitionで書戻し、異なるretry receiptは fail loudとする(ADR 0121)。
        • Supervisor runtimeのactive claude.session所有権をactivation後だけ新handleへ移し、通常cycle、 parent rebind、process cleanupが常に現在generationのsessionを参照することをfixtureで固定する。
        • 独立反証で検出したinitial caller recovery/parent rebind再authorizationのP1を補正する (ADR 0123)。
          • 明示expected_previous_watch_id=current watchを伴う同じwatchのstarting | launching | activeだけを Aiterm Claude初期callerが同一requestへ再束縛し、launching journalではexact claude_agent replayを呼ぶ。 通常の二重start、別provider/project/terminal watchは再利用しない。
          • parent rebind journal作成後は、generationがstopping以降でも同じcycle/proposed parentから 同一authorizationを回収し、authorizationを新規発行しない。
          • caller response-lossとrebind multi-step再開のfocused fixtureを先に17/20 redで固定し、 補正後20/20 greenへ戻した。
        • related 50/50、npm run check green、Phase full 393/393 green。独立重監査でP1実装欠陥2件を 採用・補正し、証拠再束縛指摘も補正後gateで閉じた。受入証拠は ADR 0124。
    • P5-1b5 dual-host live H: Aiterm実Claude初回/follow-up、Stop、exact result、session closeと、 Claude/Codexの実completed証拠、production model request、session相関、hook trust、65秒超wait、 通常停止を一回の両host campaignで受け入れる。Claude成功をfixtureで代用しない。timeout、crash、 通信断などのintentional fault trancheは通常campaignへ混ぜず、実行ごとに別の明示承認を要する。
      • P5-1b5a preflight/runbook production route補正: P5-1b4完了後も残った旧 claude --version/Observer MCP probe/background job前提を除去し、実production callerと同じ Throughline 0.6.3 observer-read実疎通、Aiterm 0.14.0 stdio initialize、 claude_agent/claude_turn/pty_close exact schema、Codex app-server、 Stop hook候補を read-only preflightで確認する。live手順は observer parent claude run ... --aiterm-command ...と observer parent codex run ...、同じ persistent Claude sessionの初回/follow-up、terminal回収、dotagentsの検証済み--restoreによる config rollbackへ固定する(ADR 0125)。 focused 20/20、product 4/4、related 46/46、isolated package gate、actual read-only status=h_requiredをADR 0126で受け入れた。
      • P5-1b5b 通常系dual-host live H: 承認済み通常campaignだけを各host一回実行し、preflight receiptの全証拠、両host terminal、project fingerprint不変、hook config rollbackを確認する。 intentional faultは未実施と明記する。通常campaignのH操作は2026-07-16にオーナーが 「queue 19e dual-host live Hを承認する」と明示承認した。
        • P5-1b5b-r1 state root束縛修理: 最初のClaude live attemptでmodel応答後に parent Stop hookが既定state rootを参照してE_PERMISSION_INVALID、Throughline completed feedが 0件のままになった。hook fragment/verifier、preflight、dotagents adapter、runbookへ同じ explicit state rootを束縛し、旧state rootのtarget entryを一件へ正規化する (ADR 0127)。失敗attemptは成功へ含めず、 session terminal確認後に修理gateを独立commitで閉じてからliveを再開する。 focused 28/28、related 48/48、npm run check、対象docs lint、dotagents isolated package gateが greenとなり、ADR 0128で受け入れた。
        • P5-1b5b-r2 Throughline capture実行物束縛: state root修理後のClaude attemptで hook errorは消えたが、Aiterm parentがglobal PATHの旧throughline process-turnを実行し、 DB sessionだけ増えてcompleted receipt fileが作られなかった。read側だけでなくcapture側も campaign candidateへ束縛するため、Aiterm controllerのPATH先頭をcampaign prefixへ固定する (ADR 0129)。手動transcript投入やglobal更新へ fallbackせず、失敗sessionを公開closeしてからliveを再開する。
          • P5-1b5b-r3 Aiterm runtime隔離: controller processのPATHを補正してもglobal tmux server作成時のstale環境が新sessionへ継承されreceiptは0件だった。campaign専用0700 TMPDIRでAiterm socket/log/stateを隔離し、candidate PATHを持つfresh serverだけを使う (ADR 0130)。
          • P5-1b5b-r4 socket長境界: campaign root配下のaiterm-runtimeでは最終tmux socketが 105 bytesとなり、macOSの104-byte sun_pathへ収まらずsession生成前に失敗した。短い0700 r2を使い、実物<TMPDIR>/claude-tmux-sockets/claude.sockを94 bytesとlaunch前に実測した。 ADR 0131の予測名/92 bytesはADR 0132で 訂正する。
          • P5-1b5b-r5 Throughline Stop flush barrier: 短い専用runtimeではAiterm session、 candidate-first PATH、実Claude end_turn、Stop hook error 0まで成立したが、async Stopがfinal assistant行のtranscript可視化より先に一回だけbackfillし、DB本文/receiptが0件になった。 Throughlineがlast_assistant_messageを本文でなくlatest logical groupのbounded barrierに使う修理を commit a46b915で独立確定し、focused 14/14、subprocess 2/2、related 78/78を通した。 失敗attemptはlive成功へ含めず、candidate再梱包後に通常campaignを再開する (ADR 0132)。
          • P5-1b5b-r6 installed package runtime root canonical化: 修理済みcandidateでClaude parent receiptを1件確定後、実observer parent claude runがprovider launch前に E_THROUGHLINE_RUNTIME_ROOT_INVALIDとなった。CLIだけがimport.meta.urlから末尾/付きの package rootを作り、preflightの末尾なしrootと分岐していた。runtime rootを実packageのcanonical directoryへ一意化し、Claude/Codex親callerの両dispatch testとisolated package gateで固定する。 失敗attemptはObserver live成功へ含めない (ADR 0133)。 focused 15/15、related 35/35、npm run check、対象docs lint、package verify、installed module smoke providers=2 root_count=1 canonical=trueがgreen。
          • P5-1b5b-r7 Throughline completed timestamp adapter: r6修理後の実callerはprovider launch前に E_EVIDENCE_SNAPSHOT_INVALIDとなった。Throughline observer_read.v1はcompleted_atをepoch milliseconds整数で公開し、Observer evidence schemaはcanonical .sssZを要求するため、evidence collector境界で整数msをexact ISOへ一度だけ変換する。文字列、負数、範囲外値、非canonical結果は fail closedにし、Throughline wireやevidence schema自体を変更しない。失敗attemptはlive成功へ 含めない(ADR 0134)。 focused 9/9、関連42/42、npm run check、対象docs lint、package verify、実feedを使う installed smoke feed_turns=1 snapshot_turns=1 canonical=trueがgreen。
          • P5-1b5b-r8 Aiterm初回ready安定化: 実managed Claudeで単発ready直後の初回promptが startup再描画へ消えるraceを再現した。Aiterm commit 4d3befdで4 vendor共通の初回readyを 500ms×11回連続へ固定し、非readyでstreakをリセットした。pure 21/21、focused agent 4/4、 related 113/113、build、新規ADR lint、diff checkがgreen。再pack候補の実managed Claudeで request/output可視、初回cycle commit、model operation残留なしを確認した。
          • P5-1b5b-r9 SIGINT時のAiterm子process signal隔離: r8候補の正常停止で、foreground Observerと同じprocess groupのAiterm MCP childがSIGINTを先に受け、session closeより前にtransportが terminalとなった。callerはE_AITERM_TRANSPORT_CLOSEDで非0終了しmanaged sessionが1件残留したため、 別processの公開pty_closeで回収した。Aiterm childを親terminal signalから隔離し、Observerの AbortSignalだけでSupervisorをcancelしてpty_close→MCP closeの既存順序を完遂する。 detached child修理はcommit 396cf05、focused 9/9、related 43/43でgreen。再pack候補の実正常停止は caller cancelled/exit 130、managed session残留0、親session公開close closedを確認して閉じた (ADR 0135)。
          • P5-1b5b-r10 cycleごとのexact output contract: r9修理後のfresh Claude candidateで managed request/Stop/exact result回収までは成立したが、実Claude出力がJSON object一件でなく E_OBSERVER_AI_OUTPUT_INVALIDとなった。strict parserをMarkdown/前後説明許容へ緩めず、各 observer.cycle_request.v1へhost-neutralなresponse contractを同梱する。default no_advisory、 exact二outcome、proposal field、許可enum、single JSON object、Markdown/code fence/前後説明/ unknown field禁止を毎cycleのmodel-visible bytesとinput digestへ含める。focused 12/12、 related 52/52はgreen。commit ebd8ae6の再pack候補でstrict parse、初回cycle commit、pending/ model operation残留なしを確認して閉じた (ADR 0136)。
          • P5-1b5b-r11 Codex app-server child signal隔離: Claude正常停止で根治した同じprocess group 問題がCodex app-server transportにも残っている。foreground callerのSIGINTがapp-server childへ 直接届くと、Observerのcancel処理より先にtransport terminalとなり、turn interrupt/terminal回収を 完遂できない。Codex childもdetached process group、stdio所有、unrefなし、既存 closeAndWait terminal確認へ固定する。focused 13/13、related 69/69はgreen。独立commit後、 実Codex正常停止で閉じる (ADR 0137)。 修理済みcandidate r11のSIGINTでcaller cancelled/exit 130、managed app-server terminal、 local app-server残留0、親app-server公開close closedを確認した。
          • P5-1b5b-r12 Codex bootstrap terminal ready gate: 実Codex parentのseed task_complete後、 Observer bootstrap turnがまだinProgressなのにwatch/generationをreadyへ進め、最初のcycleが E_CODEX_CYCLE_TURN_ACTIVEで停止した。turn/start ACKをAI readyにせず、同じdurable thread/turnのthread/readでbootstrap completedを確認してからready receiptとwatch activationへ 進む。failed | interrupted | timeoutは別turnを再送せずfail loudにする。initial/generation activationとready recoveryを同じ契約へ揃え、focused/related gate、独立commit、実Codex再Hで閉じる (ADR 0138)。
            • 実装gate: completed前のreadyを禁止し、failed/interrupted/timeout/別turnをfail closedに 固定した。focused 17/17、related 111/111、npm run check、新規ADR lint、diff checkがgreen。
            • 実Codex candidate r11で初回cycle commit、65秒超継続、follow-up後の第2cycle、正常停止を 確認した。親feed 2件、同じgenerationのcompleted cycle 2件、pending reservation/cycle/ model operation残留なし、project fingerprint不変。
          • P5-1b5b-r13 Throughline concurrent writer gate: r10で親2turn目とfeed書込みは成功したが、 Observer production callerの同時observer-readが一時SQLite lockでE_THROUGHLINE_EXEC終了した。 Throughline commit 95a3233でcompleted projectionのread-only接続だけに1秒のbounded busy waitを 追加し、Spotter auditorと上限超過hard failureを維持した。focused 16/16、related 78/78。 candidate再梱包後のr11で同時readを含む2 cycleを通し、commit 0366bb8でlive受入れを固定した。
          • P5-1b5b-r14 campaign closure: Claude r12とCodex r11はいずれも親feed 2件、同じ generationのcompleted cycle 2件、初回cycle後65秒超、pending stateなし、caller cancel、host terminalを満たした。最初のconfig archiveからClaude/Codex設定をexact digest・mode 0600・ uid 501・gid 20で復元し、candidate dry-runが両provider changed=yesとなることを確認した。 両projectは空のまま。intentional fault、push、publish、deploy、loginは未実施。 不変受入証拠はADR 0139。
          • P5-1b5b-r15 Codex process-group cleanup訂正: campaign cleanupで、終了済みCodex app-server二attemptが起動したMCP process群16件がcampaign rootをcwdにしたまま残留していた。 app-server leaderだけのterminal確認をprocess残留0へ読み替えたADR 0139の該当証拠を失効させる。 detached app-serverの終了は、固有process group全体へSIGTERM→SIGKILLを配送し、leader closeと process group消滅の両方をboundedに確認して初めて成功とする。既存孤児は所有PIDへの通常SIGTERMで 16/16終了しcampaign rootを削除した。実装、focused/related gate、fresh subprocess実証を独立commitで 閉じる(ADR 0140)。実装は commit c936cfdへ独立固定し、focused 16/16、Codex caller/Supervisor related 13/13、 npm run checkがgreen。 実OS fixtureではleader終了後もSIGTERMを無視する子を同じgroupに残し、bounded SIGKILL後に group/子PIDとも不在を確認した。受入証拠は ADR 0141。独立重監査で検出したPGID欠損時の error code不一致はcommit 8056405でE_CODEX_PROCESS_TERMINATION_UNKNOWNへ統一した。 full suite並列時のfixture起動待ちraceは、成功assertionを変えず5秒のbounded待ちへ拡張する commit 2b94392で閉じた。
          • P5-1b5b-r16 post-spawn/pre-ready recovery訂正: 独立監査候補を親が実コードで 再確認し、handle耐久化後のready失敗でprovider transport/sessionだけを閉じ、watchを launchingへ残す欠陥を採用した。validated spawned receiptの同じwatch identity/handleだけで launch failure cleanupを要求し、Codex bootstrap failed/interrupted/timeoutとClaude ready前失敗を provider terminal→watch faultedまで閉じる。別watch/別provider、handle推測、暗黙restartへ fallbackしない。intentional live faultを使わずfocused fixture、独立gate、独立commitで閉じる (ADR 0142)。実装はcommit 4bde91cへ 独立固定し、focused 19/19、parent-launch/watch-store/両Supervisor related 33/33、 npm run checkがgreen。受入証拠は ADR 0143。
  • P5-2 性能、導入、rollbackを確定する。

    • 成果物: latency実測、installer、verify、runbook、cleanup、rollback。
    • 完了条件: 空Mailboxと通常waitが開発体験を阻害せず、clean環境で導入・撤去を再現できる。
    • P5-2a clean環境installer/verify/rollback契約を閉じる (ADR 0099)。
      • versioned製品manifest、runtime package files、sanitized observer diagnosticsを実装した。
      • 4 binをexecutableへ揃え、package tamper、platform、Node、MCP/hook binary契約をfocused testで固定した。
      • dotagentsの隔離HOME/npm prefixでinstall→reinstall→verify→rollbackとhook adapter dry-runを通した。
      • actual HOME apply、hook trust、live host、credential、publish/pushは未実施のH/後続gateへ残した。
      • 実装 630c5ff/b45c07a(Observer)、894799b(dotagents)を ADR 0100で受け入れた。
    • P5-2b performance/retention cleanup契約を閉じる (ADR 0101)。
      • hook process、空Mailbox core、bounded wait overheadの分布と閾値を固定fixtureで計測した。
      • default retentionが完了receiptだけを削除し、claimed、prepared publish、active cooldownを保護した。
      • cleanup途中失敗をsanitized errorにし、無関係stateを変えず再実行で同じ最終状態へ収束させた。
      • 実装 1d045df/8b49493を ADR 0102で受け入れた。
    • project-ownedな.codex-sidecar.ymlを追加し、read-only presetと隔離worktree writer、 Observer製品面だけのpath allowlist、明示model policyを正規dry-runで検証した。
      • codex-sidecar diagnostics --project .: status=ok。
      • codex-sidecar review --project . --preset review --dry-run ...: status=dry-run、App Server未呼出。
      • codex-sidecar factory-diagnostics --project . --preset review: 0.3.7三package一致、overall=ready。
  • P5-3 最終監査とknowledge returnを完了する。

    • 成果物: Find → Dedup → 反証 → Critic → 親裁定、RAG / caveat / docsへの還流記録。
    • 完了条件: P0/P1問題が残らず、全受け入れ条件を親が裁定し、本プランをarchiveできる。
    • 修理後最終HEAD 2b94392でfocused 16/16、related 68/68、full 412/412、fail 0、skip 0。
    • 新規独立重監査はPGID欠損時のerror code不一致をP1一件として採用した。commit 8056405と 2b94392後の同一refuterによる限定再確認でP0/P1残存0、fixtureのgroup/子PID不在assertion維持を確認した。
    • knowledge returnとimmutable acceptance matrixは ADR 0144。intentional fault、追加model request、network、 credential、push、publish、deploy、loginは実施していない。
  • P5-4 Throughline上位互換version gateを補正する。

    • 成果物: 最低対応版以上の安定版SemVerを受理し、実versionをverificationへ束縛するruntime、 preflight、diagnostics、focused test、production watch smoke。
    • 完了条件: Throughline 0.8.7とそれより新しい安定版を受理し、旧版・不正SemVer・prereleaseを拒否する。 version受理後もobserver-read/observer-waitのstrict wire検証を維持し、互換性をversion文字列だけで 成功扱いしない。
    • version range契約とverification schemaをADR 0145へ固定する。
    • runtime、preflight、diagnostics、focused testを補正する。
    • Codex CLIも最低対応版以上+actual version束縛へ揃え、 ADR 0147どおり現行CLIを直接使う。
    • 実watchで露出したtruncated completed-turnの元全文digest境界を ADR 0146どおり補正する。
    • Supervisor hard failure後にfault provider bindingを同じruntimeでterminalまで進め、 fault_requiredを残して通常stopだけを完了する欠陥を ADR 0148どおり補正する。
    • source package検証、full suite、実Throughline 0.8.7/Codex CLI 0.144.6のversion gate通過を確認する。
    • default state rootの旧fault generation/journal/pending cycleをbackup付きで可逆隔離し、 production watch w_25fa83ce-ceb7-4494-bd62-474d8fd1cdbaがactive継続することを確認した。 旧fault再発防止はcommit 6c510b0、上位版受入れはcommit 85326c3。focused 49/49、 full 416/416、npm run check、Throughline 0.8.7/Codex CLI 0.144.6の実経路がgreen。
  • P5-5 Observer 0.1.1を公開し、installed runtimeへ切り替える。

    • 成果物: 現行live文書、CHANGELOG、0.1.1 package identity、release commit/tag、GitHub push、 npm公開、global install、installed packageからのproduction watch。
    • 完了条件: ADR 0149の順序で、全gate green、 publish対象commitがorigin/mainの祖先、npm registryとglobal installが0.1.1、 bingoのwatchがinstalled binaryからactive継続する。
    • live文書とpackage identityを0.1.1/Throughline >=0.8.7へ同期する。
    • package tarball、full suite、static check、package install smokeをgreenにする。
    • commitをmainへpushし、tag v0.1.1をpushした。
    • @quolu/observer@0.1.1をnpmへ公開し、registry metadataを確認した。
    • global installを0.1.1へ更新し、installed diagnostics/MCP diagnosticsを確認した。
    • installed binaryでbingo監視を再開したが、親AI向けhook/pluginを継承したbootstrapが 外部interruptを受け、active継続の受入はP5-6へ引き継いだ。
  • P5-6 Observer 0.1.2でCodex子の実行プロファイルを隔離し、installed watchをactiveにする。

    • 成果物: ADR 0150、hook/plugin無効化、 0.1.2 package identity、release commit/tag、npm公開、global install、production watch。
    • 完了条件: focused/full/package gateがgreen、installed 0.1.2のbingo watchがbootstrapを完了し、 foreground callerとwatchがactiveを維持する。
    • app-serverを--disable hooks --disable pluginsで起動し、process transport testで固定した。
    • 実Codex app-server characterizationでhook/plugin event 0、bootstrap completedを確認した。
    • 0.1.2のfull/package gateを通した。full 416/416、npm run check、 package install smoke、64-file tarballがgreen。
    • commit/push/tag/npm publish/global installを完了した。
    • installed 0.1.2でbootstrap完了を確認した。旧generation stateとの衝突で停止したため、 active継続の受入はP5-7へ引き継いだ。
  • P5-7 Observer 0.1.3でterminal watchから新watchへのgeneration切替を完結する。

    • 成果物: ADR 0151、新watch generation置換transaction、 0.1.3 package identity、release commit/tag、npm公開、global install、production watch。
    • 完了条件: pendingのない旧generationだけが新watchへatomic置換され、未解決stateは保持される。 installed 0.1.3のbingo watchがactiveを維持する。
    • 新watch active CASと旧generation状態を照合する置換transaction/focused testを実装した。
    • full/package gateを通した。full 418/418、npm run check、package install smoke、 64-file tarballがgreen。
    • commit/push/tag/npm publish/global installを完了した。
    • installed 0.1.3でgeneration切替は完了したが、turn/start直後の empty rolloutに対するthread/readがerrorとなり、active受入はP5-8へ引き継いだ。
  • P5-8 Observer 0.1.4でCodex bootstrapのflush競合とglobal tool surface継承を解消する。

    • 成果物: ADR 0152、 terminal notification gate、isolated CODEX_HOME、認証connector、0.1.4 release/installed watch。
    • 完了条件: turn/completed前にthread/readを発行せず、isolated homeがglobal config/MCPを継承しない。 installed 0.1.4のforeground callerとbingo watchがactiveを維持する。
    • turn/completed exact相関後のdurable readとtransport testを実装した。
    • isolated CODEX_HOME、0600認証元symlink、不要feature無効化、残存MCP fail-loudを実装した。
    • source runtimeでMCP startupなし、Observer AGENTSだけのinstruction source、read-only policy、 bingo watch activeを確認した。
    • full/package gateを通した。full 422/422、npm run check、 isolated package install smokeがgreen。
    • commit 71e66cfをmainへpushし、tag v0.1.4、npm publish、 registry shasum a1c083c653516175aaf3bff974de284752223658、global installを確認した。
    • installed 0.1.4でbingo監視 w_194bceab-d266-492a-943c-aefa8692cdceを foreground起動し、watch/callerがactiveを維持して作業を再開した。

v1受け入れ条件

  1. projectの絶対パスだけで監視を開始でき、Claude/Codexの親スレッド再作成へ自動追従する。
  2. Codexのtask_completeまたはClaudeの実証済み完了証拠だけでhost-bound completed cursorが進み、外部Supervisorの最大一時間Throughline waitを起こす。
  3. timeout時はAIやMailboxへ報告せず、外部Supervisorが同じcursorから次のbounded wait stepを開始する。
  4. crash、timeout境界、重複通知があっても確定turnを失わず、同じturnを二重監査しない。
  5. ObserverはprojectとThroughlineをread-onlyで扱い、実装、停止、Task変更を行えない。
  6. Observerは親と同じprovider familyで動き、正常進行では沈黙し、証拠、重要性、行動可能性のある助言だけを送る。継続的な反証役にならない。
  7. 別project、旧thread、不正messageを配送せず、正しい手紙を親へ最大一回だけ注入する。
  8. 配送後は本文を削除し、boundedなdigest-only receiptだけを残す。
  9. Claude/Codexの親Stop hook adapterはMailboxなしで高速に終了し、外部LLM、network、long-pollへ同期依存しない。
  10. E2E、fault injection、installer、verify、rollback、full CI、最終監査、knowledge returnが完了する。
  11. 利用者の明示指示を受けた親だけが同provider Observerを起動し、一targetで二重起動しない。
  12. Claude/Codex ObserverはcanonicalなObserver rootを実行cwdとし、監視対象ごとの擬似projectやtemporary repoを作らない。
  13. 一つの親session epochには一つの論理Observerだけが伴走し、同時にactiveな物理host generationを一つへ制限する。 active generation内は同じprovider sessionへcompleted turnを継続投入してObserver自身の理解を維持する。 context rollover後もcursorとbounded stateを引き継ぎ、Throughline L2をObserver cognitionの代替にしない。
  14. SupervisorはAIではなくtransport/exact-once/recovery制御だけを担い、completed turnごとのfresh evaluatorを Observerとして起動しない。利用者は永続Observer sessionを通常の対話sessionとして閲覧できる。