Implement the retained ATM CLI surface while migrating mail/runtime ownership
from filesystem JSON plus mailbox locks to SQLite plus a singleton daemon,
preserving send, read, ack, clear, log, doctor, teams, and
members.
The authoritative migration document is:
This plan sequences the work. File-level migration decisions live in
docs/archive/file-migration-plan.md.
Documentation organization and cleanup are governed by
documentation-guidelines.md. As the docs are
restructured, product docs remain in docs/ and crate-local detail moves into
docs/atm/, docs/atm-core/, docs/atm-daemon/, and
docs/atm-rusqlite/.
Phase-Q disposition note:
- earlier daemon-free phases in this plan remain historical execution records
- The former early SQLite/daemon line is abandoned as an implementation line
docs/plans/phase-Q/plan-phase-Q.mdand Section 21 are retained as minimal historical execution records only- any retained value from that abandoned line must be brought forward manually after review
Phase-R redesign note:
- the next execution line is the Phase R redesign and enforcement pass tracked
in
docs/plans/phase-R/plan-phase-R.md - Phase R starts with boundary documents, ADR alignment, and lint/parser gates before new implementation work
- the active integration branch for this redesign line is
integrate/phase-R
Phase-S planning note:
- Phase R is the merged daemon baseline, but it missed the requirement that the full daemon feature set must work on Windows as well as Unix-like hosts
- the active planning line for that correction is Phase S, tracked in
docs/plans/phase-S/plan-phase-S.md - the canonical daemon API contract is
docs/atm-daemon/http-api.mdand its checked-in OpenAPI specification; the legacy frameprotocol-icd.mdwas intentionally removed - Phase S is not satisfied by Windows compilation or temporary unsupported-path stubs; it closes only when daemon functionality is production-ready on every supported operating system behind the documented portability boundaries
- Phase S implementation details must come either from
docs/plans/phase-S/plan-phase-S.mdor from the governing requirements, architecture, ADR, and ICD documents it names; the project plan does not override those lower-level sources of truth - the planning baseline is
integrate/phase-Rat6a072c1 - S.5 is the follow-on planning slice that tightens the no-flaky-test policy,
defines which anti-flake guardrails belong in the default lint path, and
documents the bounded queue-query split between
atm listand single-messageatm read, including the historical ATM-authored Claude JSONL compatibility envelope for oversized message bodies - the historical remaining Phase S implementation work continued in:
S.6daemon post-mortem runtime remediationS.7bounded queue-query implementationS.8historical Claude JSONL compatibility-envelope implementationS.9host-scoped retained logging defaults, including historical watcher/reconcile exclusion for~/.atm/logs/
Phase-AA simplification note:
- after the retained daemon/SQLite line proved the transport split, the daemon accumulated concrete SQLite composition and health/observability ownership that violated the intended boundary
- the corrective planning line is Phase AA, tracked in
docs/plans/phase-AA/plan-phase-AA.md - Phase AA restores the original daemon role as a thin router by moving
concrete SQLite construction to a dedicated
atm-runtimecrate and restoring a direct local doctor/store-health path
Phase-AG planning note:
Phase AGis the active cross-host validation line that follows the completed same-host release-readiness work inPhase Z- the authoritative planning document is
docs/plans/phase-AG/plan-phase-AG.md Phase AGnow has two historical sections:- the completed early validation attempts on
feature/cross-host-communication - the replan/corrective line on
plan/phase-ag-multihost-advertise-allowlist
- the completed early validation attempts on
- early AG execution proved that validation alone could not close the phase: the product was missing durable cross-host control-plane surfaces
- the current AG prerequisite product work is:
- SQLite-backed interface selection/bind configuration
- SQLite-backed deny-by-default exact-host allowlist enforcement
- CLI commands to manage both
atm doctorvisibility for both- retained loopback self-test support as a supported diagnostic mode
- only after that product work lands does AG return to live Windows/macOS host-pair validation and copied-state release proof
- the AG corrective routing/revalidation plan is now merged into
develop, and execution proceeds on separate per-sprint worktrees beginning withfeature/pAG-s11-remote-target-contract - the remaining ruthless-boundary cleanup and cross-host unification line is
split into separate critically reviewed hardening sprints
AG.18throughAG.25on top of the AG.11-AG.17 corrective line - transport security / encryption remains a later AG sprint concern and must not be implied by earlier functional cross-host closure
- standalone follow-up fix work also exists off
developfor identifier hardening:fix/agent-team-name-charset-validation, tracked bydocs/plans/sprint-agent-team-charset-hardening.md. Its scope is to tighten the repo-wide<agent>/<team>charset contract to path-segment-safe, delimiter-safe identifiers and to inject the matching centralized validation change through the normal develop-based path.
Phase-AD planning note:
Phase ADis the active release-blocking correction line for caller identity ownership, direct post-send emission, and deletion of retired Claude/reconcile/notification-runtime paths- the authoritative planning document is
docs/plans/phase-AD/plan-phase-AD.md - the planning branch is
plan/daemon-graft-boundary-reset - the execution integration branch is
integrate/phase-AD - the corrective release line extends beyond
AD.11;AD.12throughAD.20are required closure sprints for the graft-boundary reset, ULID-only identity cleanup, raw CLI runtime-root unification, and read-path consistency repair - the corrective release line extends again through
AD.25toAD.30for post-send closeout and Windows daemon-depth proof - the corrective release line extends again through
AD.31toAD.35for the mailbox peek surface, owner-only mutation reset, durable ack intent, self-address/self-ack closure, and final messaging regression closeout
Phase-AE planning note:
Phase AEis the active installed user-documentation planning line on top of the acceptedPhase ADbaseline- the authoritative planning document is
docs/plans/phase-AE/plan-phase-AE.md - the planning branch is
plan/phase-AE - the execution integration branch is
integrate/phase-AE Phase AEowns the repo-authoreddocs/user-documents/corpus, installed delivery undershare/doc/atm/, conciseatm helpsurfacing, fenced example and relative-link verification, release freshness gating, and the phase-close installed-doc proof artifact
Phase-AF planning note:
Phase AFis the 1.3.1 reliability recovery line following 1.3.0 dogfood findings; it does not supersede the retained Phase AE installed-documentation scope.- the authoritative phase plan is
docs/plans/phase-af/README.mdwith hardened sprint documents for AF-1 host-wide singleton, AF-2 observability/release gates, and AF-3 native send-input integrity. - the accepted implementation branch is
integrate/phase-AF; AF-1, AF-2, and AF-3 are merged there at52c5c338, with docs-only readiness corrections atd5420b0f. - PR #539 is merged to
developat98a4e66c. - AF-1 is the release blocker: no 1.3.1 RC or daemon-spawning full smoke may proceed until its process-level singleton proof is green.
smoke-test/1.3.1-cross-hostis the repo-published cross-host RC evidence sprint on top of the accepted AF implementation line. Its authoritative plan isdocs/plans/phase-af/smoke-1.3.1-cross-host-plan.md, and its Windows handoff checklist isdocs/plans/phase-af/smoke-1.3.1-windows-checklist.md.
Prompt-hardening note:
feature/prompt-hardeningis the prompt/template hardening branch for concise evidence discipline across dev, QA, and review reporting.- the authoritative plan is
docs/plans/prompt-hardening/plan-prompt-hardening.md
Phase R execution entry:
- Wave 1 deliverable: the new Phase R skeleton
- new crates
- public boundary traits/facades
- major data structures
- Wave 1 supporting sequence:
R.0lint foundationR.1lint debt burn-downR.2skeleton crates, boundary traits/facades, and major data structuresR.2Aparallel lint hardening
R.3is a dedicated review/re-planning stage after the Wave 1 skeleton lands- Wave 2 executes implementations only against the enforced boundary skeleton
Status:
- Phases 0 through P have executed on the retained rewrite line.
- Phases G and H are complete retained-command phases, closed through the shared observability and release-alignment work delivered in later phases.
- Phase K completed the shared
sc-observabilityintegration boundary. - Phase L completed the retained release-surface and team-recovery closeout.
- Phase M completed mailbox locking and review-finding fixes.
- Phase N completed publish-replacement and distribution-parity planning and implementation merge work.
- Phase O completed the security and hardening follow-up line.
- Phase P implementation is merged; follow-up hardening remains open for
P.6and later cleanup/fix branches, whileP.8documentation reconciliation and theP.9/P.10lock-sentinel design and implementation work are complete on the merged Phase P line. - Message schema ownership and metadata normalization are now implemented well enough for live shared-inbox adoption, while a separate ATM-native inbox remains deferred to a later version.
- The former early SQLite/daemon line is retained only as an abandoned historical attempt at the SQLite source-of-truth and daemon-boundary redesign.
- Phase R is the merged daemon baseline.
- Phase S is the active planning line for Windows-complete daemon parity.
- Phase AA is the architectural simplification planning line for removing
SQLite references from
atm-daemonand moving concrete runtime assembly out toatm-runtime. - Phase AG is the active planning line for Windows/macOS cross-host ATM validation after the accepted Phase Z baseline; Phase AB is historical input only.
- Phase AD is the active planning line for release-blocking caller-identity,
post-send, and retired-subsystem cleanup on top of the accepted
1.2.3baseline. - Phase AE is the active planning line for installed end-user documentation as a shipped release surface.
- Phase AF is the active 1.3.1 reliability recovery line under phase-end
review on
integrate/phase-AF; AF-1, AF-2, and AF-3 are merged and the remaining closeout work is release-evidence and QA-gate completion. - the current merged workspace contains:
crates/atm-architecturecrates/atm-corecrates/atmcrates/atm-daemoncrates/atm-daemon-bootstrapcrates/atm-daemon-clientcrates/atm-graftcrates/atm-runtimecrates/atm-rusqlitecrates/sc-lint-*support crates
- Rust workspace expanded from
crates/atm-core+crates/atmto includecrates/atm-daemonandcrates/atm-rusqlite - retained implementation of
send,read,ack,clear,log,doctor,teams, andmembers - SQLite-backed mail and roster source of truth
- singleton daemon runtime with one protocol, two production transport
adapters, and one in-process
test-socket - elimination of mailbox-lock dependence from ATM mail correctness
- explicit two-axis workflow model with three display buckets
- task-linked message metadata with mandatory ack behavior
- structured errors with recovery guidance
- structured logs through
sc-observability - retained and new integration tests for the retained command surface
- explicit schema ownership docs for Claude Code, legacy ATM compatibility, and forward ATM metadata
The abandoned early SQLite/daemon target implementation was split across:
crates/atm-corecrates/atmcrates/atm-daemoncrates/atm-daemon-bootstrapcrates/atm-daemon-clientcrates/atm-graftcrates/atm-rusqlite
Crate-local scope detail is owned by:
docs/atm-core/requirements.mddocs/atm-core/architecture.mddocs/atm-core/boundaries.mddocs/atm/requirements.mddocs/atm/architecture.mddocs/atm/boundaries.mddocs/atm-daemon/requirements.mddocs/atm-daemon/architecture.mddocs/atm-daemon/boundaries.mddocs/atm-rusqlite/requirements.mddocs/atm-rusqlite/architecture.mddocs/atm-rusqlite/boundaries.md
Phase R sequencing rule:
- no new implementation sprint begins until:
- the relevant boundary records exist
- architecture/requirements/ADR docs agree with those records
- the parser/lint pass for those records is in place
- Phase R implementation proceeds in this order:
- boundary design
- document alignment
- lint/parser gates
- skeleton implementation
- feature behavior
Status summary:
- Phase AF is the active reliability-recovery line following 1.3.0 dogfood.
- AF-1, AF-2, and AF-3 are merged on
integrate/phase-AF; PR #539 is merged todevelopat98a4e66c. - Accepted implementation branch:
integrate/phase-AF. - Integration target:
develop. - The authoritative plan is
docs/plans/phase-af/README.md. - The authoritative closure checklist is
docs/plans/phase-af/readiness.md.
Goal:
- restore the literal one-daemon/one-durable-state-root invariant for an OS user on one host
- make post-send configuration, daemon health, errors, capacity, and release cutover observable and safe
- preserve native inline, stdin, and file message bytes across the CLI-to- daemon boundary
Deliverables:
- AF-1 host-runtime singleton admission, lifecycle, and process-proof design
- AF-2 doctor, connection-worker, capacity/deadline, and compatibility-gate design
- AF-3 client-side stdin materialization and release-binary byte-readback design
Sprint line:
AF-1feature/atm-daemon-singleton-hardeningAF-2feature/pAF-s2-observability-release-gatesAF-3feature/pAF-s3-native-send-input-integrity
Acceptance:
- Phase AF exit criteria are satisfied only through
docs/plans/phase-af/readiness.mdand its linked plan validations.
Status summary:
- Phase AA is the active simplification planning line for restoring
atm-daemonto a thin-router role. - Integration Branch:
integrate/phase-AA - The authoritative plan is
docs/plans/phase-AA/plan-phase-AA.md. - The authoritative closure checklist is
docs/plans/phase-AA/readiness.md. AA.0completed the daemon-role restatement, top-level state-machine inventory, and daemon-side SQLite leak ledger that later AA sprints must follow.AA.1completed the subsystem-owned doctor traits and shared diagnostic DTO move intoatm-core.AA.2completed theatm-runtimecomposition-root introduction, moved production SQLite/runtime assembly out of daemon production composition, and froze the target runtime boundary while the SQLite TOML relock remains deferred toAA.5.AA.3completed the direct-local doctor split and daemon runtime-health simplification so store diagnostics no longer require daemon-only routing.AA.4removes the remaining daemon-side SQLite leak paths by deleting the daemon-private SQLite observability adapter, deleting direct daemon test boundary assembly calls, and relying onatm-core/atm-runtimereplay seams instead of a directatm-daemon -> atm-rusqlitedependency.AA.5relocks the daemon-to-SQLite edge in the runtime and SQLite boundary TOMLs, adds the independentcrates/atm-architecture/Rust review guard, and freezes boundary-policy widening as an explicit architecture change.AA.6completes the scopedsc-observability1.2.0migration by moving the concrete adapters to queue-backedLogger::log()admission, renaming the retained-log shutdown policy field towriter_shutdown_timeout, and projecting queue/writer/maintenance health detail intentionally.AA.7Rust Boundary Enforcement Crate (PR #398,feature/pAA-s7-atm-architecture-crate) completes the visible workspace architecture gate by landingcrates/atm-architecture/, removing the superseded Python boundary scripts, and makingcargo test -p atm-architecturethe sole code-driven boundary-enforcement check. Status:complete.AA.8Claude Code Inbox Schema Contract Alignment (feature/pAA-s8-claude-schema-contract) is complete: the current Claude Code inbox JSON contract is frozen from realteam-lead -> quality-mgrsamples, schema-model fixtures cover those shapes, and docs/models no longer classify the current JSON-array inbox shape as legacy.AA.9Current Claude Inbox Primary-Path Repair (feature/pAA-s9-claude-inbox-primary-path) is complete: the retained runtime now treats the current Claude inbox JSON file shape as the supported primary compatibility path,.jsoninboxes rewrite atomically as current Claude arrays, and the thorough smoke lane no longer expects compatibility degradation for a healthy current Claude inbox.AA.10Remove Historical ATM JSON Compatibility From 1.2 (feature/pAA-s10-remove-historical-atm-json) is complete: historical ATM-owned inbox JSON is no longer presented as the active primary 1.2 contract, while legal additive derivatives such as tolerated top-level ATM fields andmetadata.atm.*remain read-compatible only and are ignored for active machine-state behavior.AA.11(feature/pAA-s11-delete-sqlite-legacy-compat) is complete: pre-production SQLite compatibility scaffolding such aslegacy_message_idis no longer part of the active 1.2 runtime/bootstrap line, and surviving references remain only as historical inventory/ADR context.AA.12(feature/pAA-s12-malformed-claude-inbox-recovery) is complete: malformed Claude inbox reads now salvage segmentable valid messages, emit explicit degraded warnings for localized bad fragments, and keep rewrite paths fail-closed unless an explicit repair/rebuild action is chosen.
Goal:
- move concrete SQLite/runtime assembly to
atm-runtime - remove daemon-owned SQLite diagnostics, observability glue, and replay/store leakage
- relock the daemon-to-SQLite boundary with a permanent second enforcement layer
Deliverables:
crates/atm-runtimeas the concrete composition root- subsystem doctor trait model and direct local doctor path
- deletion of remaining daemon-side SQLite leaks
boundary-guardand relocked machine-readable boundary policysc-observability/sc-observability-typesupgraded to1.2.0with the queue-backed logger API, retained-log policy field migration, and updated health projection
Sprint line:
AA.0feature/pAA-s0-daemon-architecture-restatementAA.1feature/pAA-s1-subsystem-doctor-traitsAA.2feature/pAA-s2-atm-runtime-composition-transferAA.3feature/pAA-s3-direct-doctor-and-runtime-health-splitAA.4feature/pAA-s4-delete-daemon-sqlite-leaksAA.5feature/pAA-s5-boundary-relock-and-permanent-enforcementAA.6feature/pAA-s6-obs-upgradeAA.7feature/pAA-s7-atm-architecture-crateAA.8feature/pAA-s8-claude-schema-contractAA.9feature/pAA-s9-claude-inbox-primary-pathAA.10feature/pAA-s10-remove-historical-atm-jsonAA.11feature/pAA-s11-delete-sqlite-legacy-compatAA.12feature/pAA-s12-malformed-claude-inbox-recovery
Acceptance:
- Phase AA exit criteria are satisfied only through
docs/plans/phase-AA/readiness.md
Status summary:
- Phase AC is the planning line that restores the original storage and RPC design after the repo drifted into backend-shaped seams and per-operation request/response storage DTOs.
- Planning Branch:
plan/phase-AC - Integration Branch:
integrate/phase-AC AC.0planning prerequisite is complete atce02b9ff.- latest accepted planning tip is the current
plan/phase-ACbranch head, which carries the full plan-hardening sequence, the exhaustive AC.0 type ledger, and the final cross-document consistency corrections for the AC sprint set. AC0-DOCS-MIGRATE-1(chore/ac-docs-migrate) is complete: after mergingorigin/develop, the full Phase AC plan set now lives underdocs/plans/phase-AC/; the legacy pre-restructure Phase AC locations are gone, and all in-repo references were updated to the new layout.- The authoritative plan lives in
docs/plans/phase-AC/. - The authoritative closure checklist is
docs/plans/phase-AC/readiness.md.
Goal:
- create a small audited
atm-storagecontract - extract Claude inbox storage as a first-class backend
- converge the SQLite backend on that same contract
- collapse RPC/storage/domain type duplication back to canonical shared structs
- restore future SQL Server viability
Deliverables:
crates/atm-storagecrates/atm-storage-claude- converged SQLite backend against the same core traits
- generic RPC envelope plus canonical shared domain bodies
- deletion of obsolete storage/RPC wrapper families
Sprint line:
AC.0plan/phase-ACcompleteAC.1feature/pAC-s1-atm-storage-contract-and-canonical-typescompleteAC.2feature/pAC-s2-atm-storage-claude-extractioncompleteAC.3feature/pAC-s3-sqlite-backend-convergencecompleteAC.4feature/pAC-s4-atm-core-storage-boundary-adoptioncompleteAC.5feature/pAC-s5-rpc-envelope-and-domain-type-unificationcompleteAC.6feature/pAC-s6-cleanup-and-deletion-closeoutcompleteAC.7feature/pAC-s7-sqlserver-readiness-proofcompleteAC.8feature/pAC-s8-thin-client-bootstrap-dependency-relockcomplete
Completion note:
AC.7proves SQL Server readiness from the real post-AC.6contract, landscrates/atm-storage-sqlserver-proofas a compile-only backend proof, and closes the final backend-interchangeability issue without another storage reset.
AC.8 follow-on note:
AC.8is the thin-client dependency relock follow-on that removes the unconditionalatm-graft -> atm-daemon-bootstrapcompile-time edge while preserving the standard same-host daemon auto-start convenience path through sharedatm-daemon-clienthelpers and machine-readable boundary-policy enforcement.
AC.6 closeout:
- deleted the speculative
TaskStorefamily fromatm-coreand removed the last runtime/daemon compile bridge assumptions instead of preserving them as compatibility surface - removed the old Claude
SourceIngress*/ProjectionExport*shared wrapper surface and cut daemon consumers over to directatm-storage-claude::compatfunctions and canonicalSourceFileRecord - removed
SqliteObservability*fromatm-storageand left that surface owned byatm-storage-rusqliteas the backend-owned sqlite observability seam used during runtime assembly
Acceptance:
- Phase AC exit criteria are satisfied only through
docs/plans/phase-AC/readiness.md
- Phase 0: Document Lock [COMPLETE] — Locked requirements, architecture, and read-behavior documentation, and moved the migration plan to
docs/archive/. (Completed before the current PR sequence; no dedicated PR.)
- Phase A:
OBS-GAP-1[COMPLETE] — Catalogued and closed thesc-observabilityAPI gap before ATM depended on it foratm logandatm doctor. (Delivered in PR #1)
- Phase B: Core Skeleton [COMPLETE] — Created workspace, crate scaffolding, CLI command surface, and closed documentation gaps for the initial core messaging surface. (Delivered in PRs #2 and #3)
- Phase C: Low-Level Reuse [COMPLETE] — Landed foundational reuse for mailbox schema alignment, config/path helpers, and the shared
AtmError/AtmErrorKindmodel. (Delivered in PRs #4 and #5)
- Phase D: Send Path [COMPLETE] — Implemented the send service, CLI wiring, observability port adapter, and team-config validation. (Delivered in PR #6)
- Phase E: Read Path [COMPLETE] — Implemented the read service with
IsoTimestamp, seen-state handling, queue bucket filtering, and required read-path transitions. (Delivered in PR #7)
- Phase F: Ack And Clear Path [COMPLETE] — Implemented ack and clear flows, closed 30 RBP findings, and completed CI isolation hardening. (Delivered in PRs #8, #9, and #10)
- Phase G: Log Path [UNBLOCKED - Phase K COMPLETE] — Delivered the retained
logcommand on the sharedsc-observabilityquery/follow stack after Phase K landed the real adapter. (Unblocked by Phase K; implemented as part of Phase K.4)
- Phase H: Doctor Path [UNBLOCKED - Phase K COMPLETE] — Delivered the retained
doctorcommand on shared observability health/query integration after Phase K landed the real adapter. (Unblocked by Phase K; implemented as part of Phase K.5)
- Phase I: Cleanup And Hardening [COMPLETE] — Deleted daemon-dependent helpers, added integration/snapshot tests, and hardened config/schema recovery for legacy team records. (Absorbed into later phases)
- Phase J: Message Schema Normalization [COMPLETE] — Locked schema ownership for Claude-native, legacy ATM read-compat, and forward ATM metadata fields; validated the shared-inbox design live; deferred a separate ATM-native inbox to a later version.
- Phase K:
sc-observabilityIntegration [COMPLETE] — Integrated ATM with the sharedsc-observabilitystack for retained emit, query, follow, and health; deliveredatm logandatm doctoron the shared stack with ATM-owned boundary types. (Integration published viaK-CRATES-IO-1crates.io cutover)
- Phase L: 1.0 Alignment And Release Surface Cleanup [COMPLETE] — Completed published
sc-observability 1.0follow-on work (stderr routing, fault injection, file sink migration, API cleanup, construction ergonomics, release closeout), team baseline/identity source cleanup, and retained team recovery surface (teams,members,teams add-member,teams backup,teams restore). (L.1-L.8 complete; merged tointegrate/phase-L)
- Phase M: Mailbox Locking And Code Review Fixes [COMPLETE] — Implemented exclusive mailbox locking with deterministic sorted-path acquisition, closed all blocking BP-ECR-001–BP-ECR-006 code-review findings (error docs, recovery guidance, backtrace display, identity consolidation, panic removal, atomicity), and added the M.F1 locking hardening follow-up for fail-closed source discovery and read-only filesystem classification. (M.1 PR #60, M.2 PR #61; integrated to
develop)
- Phase N: Publish Replacement And Distribution Parity [COMPLETE] — Switched publishable crate identities to
agent-team-mail/agent-team-mail-core, ported release automation (crates.io, GitHub Releases, Homebrew), addedwingetas a new required Windows install channel, ported the publisher agent, rewrote README for release-facing docs, and proved dry-run publishability. (Sprints N.1–N.5; merged todevelop)
- Phase O: Security And Hardening [COMPLETE] — Closed the four confirmed CR001 findings: path-segment validation for team/agent names,
normalize_json_numberexpansion cap, UUID-based atomic temp-file naming, and sleep/backoff after stale-lock eviction. (Sprints O.1–O.2; integrated onintegrate/phase-O)
- Phase P: File-I/O Ownership And Single-Write-Path Hardening [COMPLETE] — Applied one explicit file-I/O ownership model (read_only / read_possible_write / read_modify_write) across every live file family, eliminated ad hoc write paths, completed lock-sentinel gap closure (P.9/P.10), and reconciled requirements/architecture docs with the landed implementation. The temporary workflow sidecar introduced during this phase has since been retired; SQLite is the exclusive mailbox-state authority. (Sprints P.1–P.5, P.6–P.10, M.F1; PRs #111–#115, #120; integrated to
develop)
- Removing the daemon does not authorize removing retained mail functionality.
- File-level migration decisions must be explicit.
- Every retained useful source file must appear in
docs/archive/file-migration-plan.md. - Every reviewed non-retained file must also appear there with a
do not copydecision. - Workflow-axis transitions must be enforced by code structure, not only by tests.
- Display bucket behavior must remain separate from the canonical two-axis workflow model.
- Task-linked mail is never ack-required; readiness is signalled by the task pass
and the assignee starts it with
atm task start. - Generic logging query/follow/filter behavior should live in
sc-observabilitywhere possible, not in ATM-specific code. - Persisted config/schema compatibility issues must recover at the narrowest safe scope, and identity/routing fields must never be guessed.
- Missing team config remains distinct from malformed team config; only the documented send fallback may bypass it, and repeated repair notifications must be deduplicated by unresolved condition.
Cross-document invariants that must stay locked during implementation:
taskIdimplies task-linked mail that never requires acknowledgement; readiness is signalled bytask_ready, and start byatm task startmutation_applied = truemeans a displayed message's legal read/seen transition was accepted into the supervised non-blocking handoff; durableread = truevisibility may follow later- pending-ack messages remain actionable until acknowledged
atm clearnever removes unread messagesatm clearnever removes pending-ack messagesatm read --timeoutreturns immediately when the requested selection is already non-empty
The rewrite is ready when:
atm sendworks through the documented production runtime pathatm readworks through the documented production runtime pathatm ackworks through the documented production runtime pathatm clearworks through the documented production runtime pathatm logworks through shared observability APIsatm doctorworks as a local diagnostics command with daemon/runtime visibility in the current SQLite/daemon architectureatm teamsprovides the retained local team recovery surfaceatm membersprovides retained local roster verification- daemon auto-start-when-absent path is exercised in bounded integration testing
ATM_POST_SEND.recipient_pane_idis sourced from SQLite roster truth when known- repo-tracked dogfood config does not carry live
[[atm.post_send_hooks]]defaults or committedtmux_pane_idrouting truth - retained command behavior is preserved, and any current-runtime shape changes are intentionally documented
- task-linked mail is actionable on
task_readyand never waits for an acknowledgement - the file-by-file migration plan is complete enough to implement directly
- the retained command tests pass against the new crate layout
Before implementation starts, the docs should be reviewed with these checks:
- every retained or rejected source file referenced by the retained command
surface appears in
docs/archive/file-migration-plan.md requirements.md,architecture.md, andread-behavior.mdagree on the two-axis model, three display buckets, and legal transitionsrequirements.md,architecture.md, andread-behavior.mdagree on--since,--since-last-seen,--no-since-last-seen,--no-update-seen, and--timeoutrequirements.md,architecture.md,docs/atm/requirements.md, anddocs/atm/architecture.mdagree on the retained release surface:send,read,ack,clear,log,doctor,teams,membersdocs/archive/file-migration-plan.mdremains the source of truth for the initial core migration set (send,read,ack,clear,log,doctor), and the release-onlyteams/membersexpansion is explicitly tracked in PhaseL.8
- Phase Q [ABANDONED] — The former Phase Q SQLite/daemon execution line was abandoned;
docs/plans/phase-Q/plan-phase-Q.mdis retained as a one-line historical marker only, and any still-useful ideas must be brought forward manually into the active Phase R documents.
- Phase R: Boundary Establishment And Enforcement [COMPLETE] — Established enforceable crate boundaries, lint/parser foundation, new crate skeleton, public boundary traits/facades, and major shared data structures as Wave 1; implemented behavior against the enforced boundary in Wave 2. (Authoritative plan:
docs/plans/phase-R/plan-phase-R.md; merged daemon baseline)
- Phase R.9 / R.10: Daemon Singleton And Test Fidelity Hardening [COMPLETE] — Made daemon singleton the first-class runtime invariant, removed daemon-spawn-driven test strategy from the correctness path, and replaced it with production-faithful in-process transport seams and narrow daemon-runtime coverage.
- Phase R Postmortem Linter Backfill [COMPLETE] — Converted recurring mechanically-detectable Phase R defect families (Unix platform-gating, bare
Condvar::wait, duplicate semantic string literals, fixed-sleep test hygiene, triage-record consistency) into repository lint or CI gates, with reusable rules staged for graduation to standalonesc-lint.
- Phase U: Mailbox Simplification And Identity Cleanup [COMPLETE] — Removed legacy mailbox/identity carry-forward design, made SQLite the sole ATM-owned mailbox authority outside the Claude-compat watcher boundary, and replaced ambiguous message identity/state/thread-update behavior with smaller auditable contracts across sprints U.0–U.11. (Integration branch:
integrate/phase-U)
- Phase V: Daemon Hardening And Boundary Cleanup [COMPLETE] — Closed daemon hardening follow-on from Phase U: defined
SubsystemObservabilityper-subsystem injection, deleted old central event-reconstruction helpers, and hardened.with_recovery()on the four required runtime error categories across sprints V.1–V.4. (PRs #269–#277 range via Phase W completion)
- Phase W: Production Readiness Follow-Up [COMPLETE] — Closed remaining production-readiness gaps after Phase V: daemon-side sink-failure visibility, same-host traceability and interface parity, SQLite observability and protocol parity, peer replay recovery, doctor projection, SQLite error-contract cleanup, and phase closeout. (Sprints W.1–W.8; PRs #269–#277; integration branch
integrate/phase-W)
- Phase Xb: SQLite SSOT And Daemon Boundary Simplification Restart [COMPLETE] — Removed the dual mailbox/runtime implementation so ATM has one durable mailbox path, aligned daemon runtime truth with the SQLite SSOT claim, and made replay persistence startup behavior explicit and enforceable. (Integration branch:
integrate/phase-Xb; authoritative plan:docs/phase-X/plan-phase-X.md)
- Phase Xb Planning And Pre-Phase Lint Prerequisite [COMPLETE] — Added guardrails to catch stale legacy paths and silent regressions earlier; removed remaining legacy mailbox/runtime branches behind the retained boundary. (Pre-phase branch:
feature/pX-lint-gates)
- Phase Y Pre-Smoke Trivial Fixes [COMPLETE] — Landed small pre-Phase-Y cleanup items: shared
ATM_SERVICE_NAMEreuse,atm ackvalidation cleanup, architecture wording,GH #78regression coverage, and trivial-fixes QA-1 follow-up. (Branch:feature/pY-trivial-fixes; status: complete)
31. Phase Y Daemon Release Readiness, Compatibility Write Simplification, And Smoke Rollout [COMPLETE]
- Phase Y: Daemon Release Readiness, Compatibility Write Simplification, And Smoke Rollout [COMPLETE] — Made the first daemon + SQLite mail-SSOT release safe for real operator use: consolidated compatibility writes behind one hard owner boundary, centralized delivery routing, removed mutable workflow-state projection from compatibility output, and delivered
atm helpUX improvements across sprints Y.1–Y.6. (Authoritative plan:docs/plan-phase-Y.md; integration branch:integrate/phase-Y)
- Phase Yb: Message-Path Consolidation Planning [COMPLETE] — Consolidated message paths after Phase Y: shared delivery plans across Claude/non-Claude harness paths, dedicated
NonClaudeOutboundpayload boundary, fail-closed handling for missing roster harness data, and repair/rebuild-only mailbox rewrite seams across sprints Y.7–Y.11. (Integration branch:integrate/phase-Y)
- Phase Yc: Final Production-Readiness Closure [COMPLETE] — Closed the final Claude recovered degraded-delivery contract gap and the final
NotificationSinkboundary bypass reopened by focused production-readiness review, across sprints Y.12–Y.13. (Implementation target:integrate/phase-Y)
- Phase Yd: Develop-Gate Closure [COMPLETE] — Documented and closed the full Phase Y blocker set (recovered Claude logical-message-set, production notification boundary, retained-runtime composition, candidate closure, thin-liveness) across sprints Y.14–Y.18; readiness record at
19376e42explicitly authorized Phase Y to land ondevelopand Phase Z to begin. (Integration target:integrate/phase-Y)
- Phase Ye: Daemon Ownership Simplification [COMPLETE] — Simplified
RuntimeStatusCache,NotificationRuntime, andReconcileRuntimeownership surfaces from lock-heavy to immutable snapshot publication and bounded channel/actor ownership across sprints Y.19–Y.23; closed withADR-015acceptance. (Phase Ye: closed — Y.23 phase-end proof recorded and ADR-015 accepted.)
- Phase Z: Smoke, Dogfood, And Release Sign-Off [COMPLETE] — Validated the first daemon + SQLite mail-SSOT release with real-binary smoke, roster truth cutover, watcher-owned Claude config ingest, boundary lint gates,
atm-devcanary and dogfood, and final release sign-off; verdictREADYonfeature/pZ-smoke-atm-graft @ 84935774authorized indocs/phase-Z/readiness.md(PZ-ATM-GRAFT-QA-3 PASS — PR #365). (Sprints Z.1–Z.24 and Z.3–Z.4; integration branch:integrate/phase-Z)
Status summary:
Phase Zis complete and remains the accepted same-host release-readiness line ondevelop.- Windows same-host build/test and release-binary daemon parity have been
restored on the post-
Zbaseline. - early AG validation attempts were executed and produced real findings, but they also proved the original validation-only framing was insufficient.
- the missing AG product surfaces are now explicit:
- durable daemon interface/bind configuration
- durable inbound exact-host allowlist enforcement
- CLI management for both
atm doctorvisibility for both- retained loopback self-test support
- Phase AG is retired. It documents the rejected custom-frame/TCP design and must not be used for implementation or release evidence; Phase AI owns the replacement HTTP/UDS and HTTPS proof line.
Phase ABremains historical source material only.
Planning branch:
- historical early execution:
feature/cross-host-communication - earlier corrective replan:
plan/phase-ag-multihost-advertise-allowlist - current corrective routing/revalidation plan source:
develop
Branch-routing note:
- PR #542 (
feature/cross-host-communication->develop) is retained as the historical early-AG planning/execution record - PR #555 (
plan/phase-ag-multihost-advertise-allowlist->develop) is the earlier corrective AG replanning line - the hardened AG.11 through AG.15 execution line now uses separate sprint
branches/worktrees:
feature/pAG-s11-remote-target-contract,feature/pAG-s12-localhost-proof,feature/pAG-s13-selfip-proof,feature/pAG-s14-integration-coverage, andfeature/pAG-s15-othermac-smoke - if AG later opens product-code fixes from concrete findings, those follow-up branches must declare their own normal integration path explicitly
Goal:
- preserve what AG.1 / AG.2 / AG.3 already established
- finish the missing product control plane before claiming real closure
- validate Windows <-> macOS cross-host ATM interfaces on real binaries after that product surface exists
- prefer the simplest real network path first (plain LAN is acceptable and preferable when available, including Mac Studio)
- revalidate on copied state only after the disposable lane passes
- sequence transport security / encryption after functional cross-host operability is real
Execution shape:
AG.1cross-host setup contract and channel bring-upAG.2core cross-host interface validationAG.3daemon loopback self-test surfaceAG.4durable interface configuration and bindingAG.5durable host allowlist enforcementAG.6doctor visibility for the cross-host control planeAG.7live cross-host revalidationAG.8transport security and encryption hardeningAG.10secured cross-host transport implementationAG.9historical reviewed copied-state verdict for the pre-corrective lineAG.11exact remote-target contract and dispatch routingAG.12localhost full-function same-host remote-target proofAG.13self-IP full-function same-host remote-target proofAG.14automated integration coverage for the corrective pathAG.15other-Mac cross-host smoke for the corrective pathAG.16Windows/macOS cross-host smoke for the corrective pathAG.17corrective copied-state revalidation and final release verdictAG.18collapse Compose and DirectDeliver into one envelope/handlerAG.19delete separate remote-ack execution pathAG.20move deferred/replay policy out of transportAG.21collapse duplicate dispatch routing and inbound persistence pathsAG.22relocate host matching and endpoint selection out of transportAG.23remove synthetic deferred-receipt construction from daemon dispatchAG.24stop transport from mutating request shape before sendAG.25live two-daemon-pair proof for the unified cross-host line
Immediate planning outputs:
docs/plans/phase-AG/plan-phase-AG.mddocs/plans/phase-AG/readiness.mddocs/plans/phase-AG/sprint-AG1.mddocs/plans/phase-AG/sprint-AG2.mddocs/plans/phase-AG/sprint-AG3.mddocs/plans/phase-AG/sprint-AG4.mddocs/plans/phase-AG/sprint-AG5.mddocs/plans/phase-AG/sprint-AG6.mddocs/plans/phase-AG/sprint-AG7.mddocs/plans/phase-AG/sprint-AG8.mddocs/plans/phase-AG/sprint-AG9.mddocs/plans/phase-AG/sprint-AG10.md
Acceptance / Phase Entry Gate:
Phase Zmust remain closed ondevelop- no speculative code work begins before the first failed validation row exists
- the clean-room disposable host-pair lane must pass before copied-state validation begins
- the phase does not close until both disposable and copied-state cross-host validation lanes pass with retained evidence or are blocked by named findings
Status summary:
Phase ADis complete onintegrate/phase-ADas the release-blocking correction line for the accepted1.2.3baseline.- it restores caller-owned identity handling so the CLI fails closed when identity is absent and the daemon never guesses identity
- it narrows post-send behavior back to a direct persist-then-emit seam with sender-visible warnings on emission failure
- it deletes retired Claude inbox, reconcile, and notification-runtime paths that no longer belong on the accepted line
AD.1(feature/pAD-s1-caller-identity-ownership-restore) is complete: retained caller-owned CLI commands now resolve caller identity and caller team at the CLI boundary, fail closed when either is missing, and carry both fields explicitly to daemon-backed request DTOs.AD.2(feature/pAD-s2-config-identity-removal-and-doctor-repair) is complete: obsolete config-driven caller identity fallback is retired, doctor remains the identity-free diagnostic exception, and the accepted caller context contract is reflected in CLI and doctor behavior.AD.3(feature/pAD-s3-claude-backend-and-inbox-nudge-retirement) is complete: the retired Claude backend and Claude JSON inbox nudge path are no longer part of the accepted runtime line.AD.4(feature/pAD-s4-reconcile-runtime-removal) is complete:ReconcileRuntimeand the watched-source/import runtime lane are removed from accepted daemon behavior.AD.5(feature/pAD-s5-notification-runtime-removal-and-post-send-detachment) is complete: daemon notification queue/worker delivery was removed and post-send warning ownership was detached from the old notification-runtime path.AD.6(feature/pAD-s6-post-send-nudge-contract-simplification) is complete: post-send ownership is reduced to explicit emitter seams with one stable sender-warning contract for emission failure.AD.7(feature/pAD-s7-local-tmux-post-send-emitter) is complete: local tmux nudges use authoritative SQLite roster pane metadata instead of repo config assumptions.AD.8(feature/pAD-s8-graft-post-send-emitter) is complete: graft-backed post-send emission is isolated behind the graft advisory boundary with matching governance records and readiness evidence.AD.9(feature/pAD-s9-update-member-cli-and-roster-repair-path) is complete:atm teams update-memberis the accepted repair path for pane and member metadata, withMemberNotFoundaligned to the not-found error family.AD.10(feature/pAD-s10-directory-metadata-and-doctor-contract-cleanup) is complete: durablehome_dir, runtimelive_cwd, and log-onlylaunch_cwdterminology and doctor projections are cleaned up and made consistent.AD.11(feature/pAD-s11-smoke-and-readiness-closeout) is complete: smoke artifacts, readiness validation, and closeout evidence converge on one accepted branch tip for the phase release gate.
Planning branch:
plan/daemon-graft-boundary-reset
Integration branch:
integrate/phase-AD
Goal:
- restore CLI-owned caller identity resolution
- restore direct post-send nudge emission after persistence
- remove retired Claude/reconcile/notification-runtime behavior from the accepted line
- finish the SQLite-backed roster repair path for pane and member metadata
Deliverables:
- required caller identity on caller-owned CLI -> daemon requests
- direct
PostSendHookEmittercontract plus boundary-governance records - local tmux and graft-backed emitter paths with sender-visible warning behavior
- deletion of
atm-storage-claude,ReconcileRuntime, and daemon notification queue/worker runtime atm teams update-memberas the accepted repair path for existing member metadata- corrective
AD.12throughAD.22closure of:- ULID-only retained message identity
- graft advisory boundary reset
- raw CLI runtime-root unification
- read-mutation and read-selector output consistency
- shipped built-in post-send nudge plus bounded template override support
- pane-routing ownership cleanup out of committed repo config
- follow-up
AD.25throughAD.30closure of:- explicit built-in template override lifecycle/reset semantics
- real post-send boundary wiring plus mixed-success hook accounting
- upstream extraction of built-in template resolution out of the built-in
delivery path, with any retained
atm internal-nudgehelper reduced to a resolved-envelope render/deliver leaf rather than the shipped default - deterministic
atm-grafthost-nudge race closure - one authoritative Phase AD post-send smoke matrix covering exactly:
- external hook success
- external hook partial failure
- built-in fallback
- override reset-to-default
- explicit disable behavior when retained
- separate Windows daemon integration-depth proof for the remaining local IPC shutdown/error/rejection cases
- follow-up
AD.31throughAD.35closure of:- explicit split between non-mutating
atm peekinspection and owner-only mutatingatm read - owner-only mutation for
send,read,ack, andclear, with no mutating impersonation path - durable sender-owned
requires_ackmessage state and deletion of read-time ack creation - self-addressed send rejection and self-ack poison termination
- operator-protocol/help/regression closeout for the repaired messaging model
- explicit split between non-mutating
Sprint line:
AD.1 [COMPLETE]feature/pAD-s1-caller-identity-ownership-restoreAD.2 [COMPLETE]feature/pAD-s2-config-identity-removal-and-doctor-repairAD.3 [COMPLETE]feature/pAD-s3-claude-backend-and-inbox-nudge-retirementAD.4 [COMPLETE]feature/pAD-s4-reconcile-runtime-removalAD.5 [COMPLETE]feature/pAD-s5-notification-runtime-removal-and-post-send-detachmentAD.6 [COMPLETE]feature/pAD-s6-post-send-nudge-contract-simplificationAD.7 [COMPLETE]feature/pAD-s7-local-tmux-post-send-emitterAD.8 [COMPLETE]feature/pAD-s8-graft-post-send-emitterAD.9 [COMPLETE]feature/pAD-s9-update-member-cli-and-roster-repair-pathAD.10 [COMPLETE]feature/pAD-s10-directory-metadata-and-doctor-contract-cleanupAD.11 [COMPLETE]feature/pAD-s11-smoke-and-readiness-closeoutAD.12feature/pAD-s12-graft-boundary-reset-planningAD.13feature/pAD-s13-ulid-message-identity-resetAD.14feature/pAD-s14-shared-graft-boundary-surface-resetAD.15feature/pAD-s15-daemon-advisory-runtime-deletionAD.16feature/pAD-s16-thin-graft-receiver-resetAD.17feature/pAD-s17-boundary-reset-verification-closeoutAD.18feature/pAD-s18-raw-cli-runtime-root-unificationAD.19feature/pAD-s19-read-mutation-output-consistency-repairAD.20feature/pAD-s20-read-body-search-metadata-consistency-repairAD.21feature/pAD-s21-built-in-post-send-nudge-and-template-overridesAD.22feature/pAD-s22-nudge-routing-state-and-dogfood-transition-cleanupAD.25feature/pAD-s25-post-send-hook-emitter-live-wiringAD.26feature/pAD-s26-rule001-observability-seam-closureAD.27feature/pAD-s27-upstream-built-in-template-resolutionAD.28feature/pAD-s28-atm-graft-timing-independentAD.29feature/pAD-s29-phase-ad-post-send-smoke-matrixAD.30feature/pAD-s30-windows-daemon-integration-depthAD.31feature/pAD-s31-mailbox-peek-surface-and-owner-only-mutation-resetAD.32feature/pAD-s32-durable-ack-intent-and-read-semantics-resetAD.33feature/pAD-s33-self-addressed-send-rejectionAD.34feature/pAD-s34-self-ack-loop-termination-and-historical-poison-cleanupAD.35feature/pAD-s35-messaging-protocol-and-regression-closeout
Acceptance:
- the phase closes only through
docs/plans/phase-AD/readiness.md - readiness is valid only if
AD.1throughAD.11,AD.12throughAD.22,AD.25throughAD.30, andAD.31throughAD.35all pass on the accepted line AD.30is the sole sprint allowed to author the Windows/post-send sub-line closeout record indocs/plans/phase-AD/readiness.md, whileAD.35is the sole sprint allowed to author the final PhaseADmessaging follow-up verdict afterAD.31throughAD.35are completeAD.24is reserved in the sibling smoke-test planning worktree and is consumed byAD.29; its harness scope must not be duplicated in the follow-up line
CHORE-ADR-AUDIT-001removed sprint-doc and phase-plan rationale dependencies from permanent ADRs, inlined the missing durable rationale in the affected records, and kept any surviving sprint references as historical execution context only.- branch:
chore/docs-restructure - authoritative source:
docs/adr/INDEX.md
- branch:
40. Phase AI — HTTP daemon and minimal cross-host transport [ACTIVE — implementation through AI.38; readiness blocked]
Planning branch: plan/phase-ai-planning
Integration branch: integrate/phase-ai-31-33
Implementation is merged through AI.38. Post-AI.38 legacy-finding and
hardening cleanup is in progress on follow-up branches. This implementation
status does not close the phase: docs/plans/phase-ai/readiness.md
still blocks release pending physical two-Mac and Mac↔Windows peer evidence.
The retained local roster-repair follow-up is planned in
docs/plans/teams-remove-member/sprint-02.md.
It adds the narrowly scoped atm teams remove-member command on its own
feature branch; it is not cross-host transport work and does not alter the
Phase AI readiness gate.
AI.1 (feature/pAI-1-daemon-preag-reset, PR #592) is the reviewed deletion
baseline. It retains only the local-IPC singleton while deleting peer transport,
replay/store support, and retired boundary adapters. It supersedes the abandoned
PR #590 line. AI.2 onward rebuild from that baseline: HTTP over UDS replaces the
custom local frame protocol, and the same router later serves authenticated
HTTPS/TCP peers. The final line has no legacy Windows local-transport fallback, peer/replay state, parallel
send/ack paths, or cross-host-specific mailbox logic.
Implementation Branches:
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
AI.1 |
complete |
feature/pAI-1-daemon-preag-reset |
deleted peer transport/replay state and retired daemon compatibility adapters |
AI.2 |
complete |
feature/pAI-s2-storage-topology |
storage topology cleanup, backend-neutral runtime factory, atm-core boundary retirement gate |
AI.3 |
complete |
feature/pAI-s3-error-contract-foundation |
serializable error contract foundation and retired protocol error envelope cleanup |
AI.4 |
complete |
feature/pAI-s4-error-consumer-migration |
consumers migrated onto the two-field error contract |
AI.5 |
complete |
feature/pAI-s5-chat-address-identity |
chat-address identity contract aligned for HTTP daemon ingress |
AI.6 |
complete |
feature/pAI-s6-http-uds-router |
REST router and HTTP-over-UDS local daemon transport, with AI.7 write-graph waiver recorded |
AI.7 |
complete |
feature/pAI-s7-canonical-write-path |
canonical write request, single host-routing seam, and collapsed send/ack ingress |
AI.8 |
complete |
feature/pAI-s8-crosshost-control-plane |
durable HTTPS interface, certificate, and trust configuration |
AI.9 |
complete |
feature/pAI-s9-https-peer-transport |
peer HTTPS transport |
AI.10 |
complete |
feature/pAI-s10-crosshost-proof-closeout |
proof matrix and closeout; live physical-peer rows remain readiness blockers |
AI.11 |
complete |
feature/pAI-s11-post-merge-remediation |
route-specific HTTP bodies and Windows loopback-TCP local transport |
AI.12 |
complete |
feature/pAI-s12-post-write-router |
canonical post-write peer routing and immutable outbound persistence |
AI.13 |
complete |
feature/pAI-s13-peer-smoke-contract |
repository-owned peer-pair smoke runner and release evidence contract |
AI.14 |
complete |
feature/pAI-s14-mac-peer-smoke |
physical Mac↔Mac peer-pair proof implementation; live evidence remains blocked |
AI.15 |
complete |
feature/pAI-s15-windows-peer-smoke |
physical Mac↔Windows peer-pair proof implementation; live evidence remains blocked |
AI.16 |
complete |
feature/pAI-s16-offline-reconciliation |
durable-age-bounded canonical-message reconciliation |
AI.17 |
complete |
feature/pAI-s17-hermes-chat-identity |
ambient ATM_CHAT_ID identity context |
AI.18 |
complete |
feature/pAI-s18-graft-python-bindings |
PyO3/Maturin graft client/nudge binding |
AI.19 |
complete |
feature/pAI-s19-hermes-graft-integration |
typed Hermes graft bridge after canonical persistence |
AI.20 |
complete |
feature/pAI-s20-hermes-bridge-deployment |
per-profile launchd bridge deployment and runbook |
AI.21 |
complete |
feature/pAI-s21-hermes-closure |
retained Hermes end-to-end production evidence |
AI.21-pre |
complete |
feature/pAI-s21pre-crosshost-evidence-harness |
supported peer-smoke harness and plaintext-test diagnostic profile |
AI.22 |
complete |
feature/pAI-s22-loopback-self-send-exemption |
host-qualified self-send exemption and advertised-IP proof path |
AI.23 |
complete |
feature/pAI-s23-crosshost-shared-write-path |
one shared HTTP write path and post-write router |
AI.24 |
complete |
feature/pAI-s24-host-qualified-ack-receipt |
host-qualified ACK receipt and peer nudge |
AI.25 |
complete |
feature/pAI-s25-peer-authority-resolution |
hostname/pin peer authority and live trust refresh |
AI.26 |
complete |
feature/pAI-s26-peer-write-deadline |
propagated peer-write deadline |
AI.27 |
complete |
feature/pAI-s27-peer-delivery-observability |
truthful peer delivery outcomes and terminal events |
AI.28 |
complete |
feature/pAI-s28-bounded-peer-recovery |
bounded recovery after connectivity loss |
AI.29 |
complete |
feature/pAI-s29-crosshost-smoke-rerun |
receiver-proven physical smoke implementation; live evidence remains blocked |
AI.30 |
complete |
feature/pAI-s30-semver-http-compatibility |
schema/HTTP compatibility admission and SemVer prerelease distribution |
AI.31 |
complete |
feature/pAI-s31-async-local-admission |
SQLite-only local admission response; host-qualified peer work signalled after response |
AI.32 |
complete |
feature/pAI-s32-independent-peer-jobs |
bounded non-durable per-ULID peer jobs |
AI.33 |
abandoned/superseded |
feature/pAI-s33-admission-capacity-smoke |
PR #695 closed, not merged; real M5 admission-capacity evidence retained a blocking HTTP 503 throughput failure despite green CI; AI.40 is the active owner of a clean benchmark runner/evidence path |
AI.34 |
complete |
fix/hermes-nudge-endpoint-mismatch |
canonical roster workspace-root resolution for graft nudge endpoint delivery |
AI.35 |
complete |
feature/pAI-s35-graft-root-fallback-observability |
graft-root fallback observability and operator runbook closure |
AI.36 |
complete |
feature/pAI-s36-graft-receiver-ownership |
lease-safe receiver ownership per canonical graft root/team/agent |
AI.37 |
complete |
feature/pAI-s37-hermes-recovery-summary |
ten-second durable-mail-derived recovery summary |
AI.38 |
complete |
feature/pAI-s38-hermes-steer-nudge-delivery |
live and recovery graft wake-ups via non-interrupting steer |
AI.39 |
complete |
feature/pAI-s39-buffered-local-http-framing |
bounded buffered local HTTP request framing |
AI.40 |
in_progress |
feature/pAI-s40-local-transport-benchmark |
clean local transport throughput benchmark; not an extension of abandoned AI.33 script |
AI.43 |
complete |
feature/pAI-s43-remote-https-response-framing |
buffered remote HTTPS response framing |
AI.46 |
complete |
feature/pAI-s46-reports-index |
generated durable reports index |
AI.47 |
complete |
feature/pAI-s47-pages-site-home |
GitHub Pages site home and deployment |
AI.48 |
complete |
feature/pAI-s48-fuzz-tooling-port |
ported just fuzz coordinator/probe tooling |
AI.49 |
complete |
feature/pAI-s49-benchmark-report |
durable benchmark JSON and aggregate HTML report |
AI.50 |
complete |
feature/pAI-s50-fuzz-report |
sc-compose-template fuzz report renderer |
AI.51 |
complete |
feature/pAI-s51-local-http-framing-adversarial-campaign |
bounded local HTTP framing campaign |
AI.52 |
complete |
feature/pAI-s52-windows-transport-benchmark |
cwin Windows TCP confirmation after accepted M5 performance evidence |
AI3152-TOOLING |
complete |
feature/daemon-devcert-signing |
retired self-signed macOS development-signing hook for local daemon builds |
Authoritative plan: Phase AI plan.
AI.3 (feature/pAI-s3-error-contract-foundation) completes the two-field
serializable error contract and removes the retired protocol error envelope.
Status summary:
- Phase AK is abandoned. It was the planned simplification line for replacing
the Phase AI peer worker and custom TLS sender with one direct HTTP delivery
function; Phase AL/AM (the Tokio migration,
atm-http-runtime) supersedes it with a single Tokio-based transport replacement instead of an incremental direct-HTTP-sender line. AK.1–AK.10reached implementation completion and merged tointegrate/phase-akbefore the line was abandoned; no further AK work is dispatched.AK.11–AK.17(the post-AK.10 mandate-correction line) do not proceed.AK.11's receiver-hook design is the sole salvaged artifact: AL.1 sources it asarchived_reference_sourcecommit88bca9d5e232006339f43a4e97eef335531b8a8f(hook-boundary file set and tests only, no wholesale cherry-pick), per Phase AL plan. This does not revive, complete, or re-authorize any other AK code, peer transport, replay, listener, or scheduler.- Planning branch (historical):
plan/mvp-simplification. - Integration branch (historical):
integrate/phase-ak. - The historical plan is Phase AK plan; its AK.11+ references are non-authoritative per that document's own AK.11+ authority notice.
Goal:
- preserve immutable local admission and the one ordinary inbound persistence/nudge path while removing peer worker, per-message-thread, broad-scan, DNS-thread, and native custom-TLS delivery complexity
- prove direct configured-host HTTP delivery before adding the small optional resend cache
Deliverables:
- direct host-alias normalization, one direct no-retry HTTP sender, optional timer-driven resend cache, and isolated curl-mTLS provisioning evidence
- deletion of obsolete worker/replay/TLS transport state with governed boundary-record updates
Sprint line:
AK.1feature/pak-s1-crosshost-ack-provenance-recoveryAK.2feature/pak-s2-delete-peer-workerAK.3feature/pak-s3-canonical-peer-aliasesAK.4feature/pak-s4-direct-peer-http-no-retryAK.5feature/pak-s5-direct-peer-timer-stateAK.6feature/pak-s6-remove-legacy-peer-transport
Acceptance:
- Phase AK acceptance is defined by the authoritative plan's sprint
validations and its required bidirectional production send/read/ACK/nudge
proof on the accepted
integrate/phase-akline.
Phase AJ plans and reviews against integrate/phase-ai-31-33 @ 150391ecdf2e003185bff7d78427cd21509a7981, the HTTP local transport line for
UDS and TCP. Phase AI merged to develop; team-lead recorded the post-merge
SHA, cut integrate/phase-AJ from it, reconciled every AJ exact target against
the pinned planning baseline, and revalidated drift before AJ.1 started. A
pre-merge plan finding cites the pinned baseline; a post-merge reconciliation
finding cites both SHAs and the changed target.
All AJ implementation heads, closeout validation, and parent PR merges
(AJ.1–AJ.10, PRs #735–#745, plus merge-content-recovery PR #758) are
complete. Phase AJ is not closed: a final holistic QA gate finding (a
transport-trust-boundary gap in heartbeat ingress) must be remediated and
reverified before its final status changes.
AJ established the original in-memory observation design. Issue #1378 corrects
the replacement-runtime owner: authenticated heartbeat POSTs and successful
Herdr polls converge on one ephemeral master-roster member record, while
RuntimeHealth becomes a projection only. Pre-cutover local activity metadata
remains tolerated but is not canonical state ingress. Session, pid, source, and
timestamp metadata remain non-policy inputs; the Phase BA nudge invariant is
the only policy that consumes canonical state.
| Sprint | Status | Branch | Purpose |
|---|---|---|---|
AJ.1 |
implementation complete |
feature/pAJ-s1-session-id-and-protocol |
canonical SessionId and additive heartbeat fields |
AJ.2 |
implementation complete |
feature/pAJ-s2-caller-context-env |
environment-attested observation resolver |
AJ.3 |
implementation complete |
feature/pAJ-s3-cli-wire-payload |
transient local CLI/graft request metadata |
AJ.4 |
implementation complete |
feature/pAJ-s4-daemon-cache-touch |
shared daemon cache merge after successful local dispatch |
AJ.5 |
implementation complete |
feature/pAJ-s5-heartbeat-session |
heartbeat session observation convergence |
AJ.6 |
implementation complete |
feature/pAJ-s6-runtime-observation-snapshot |
runtime snapshot and roster projection |
AJ.7 |
implementation complete |
feature/pAJ-s7-runtime-observation-source-guard |
non-authoritative source-use guard |
AJ.8 |
implementation complete |
feature/pAJ-s8-runtime-observation-boundary-record |
machine and human daemon boundary record |
AJ.9 |
implementation complete |
feature/pAJ-s9-runtime-observation-contract-reconciliation |
requirements, ADR, architecture, and team-state reconciliation |
AJ.10 |
implementation complete |
feature/pAJ-s10-runtime-observation-phase-closeout |
evidence-backed phase and status closeout (final QA gate open) |
Each AJ successor begins immediately when its parent's development head is merged forward into it; do not wait for parent QA approval. Merge the current parent branch into the child before every child dev/fix round. A child PR may not complete or merge its target before its parent PR merges.
Status summary:
- Phase AL replaces ATM's hand-written synchronous HTTP framing and
transport-specific request processing with one small
atm-http-runtimelibrary built on Tokio and maintained HTTP/TLS libraries, providing the same typed application contract to all clients and all listeners. - AL is additive: it does not preserve the legacy transport as a compatibility architecture and does not add resend/replay. Phase AM deletes the legacy implementation once AL proves the replacement.
- Planning branch:
plan/tokio-migration. - Baseline:
develop @ 67401907039f92e58e883273f02372a637202f70(includes the completed Phase AJ merge). - Entry gate: AL.1 starts from that
developbaseline; it does not require Phase AK completion, merge, or revival. AL.1 sources only the approved receiver-hook design from archived AK.11 commit88bca9d5(see Phase AK status above). - Binding boundary rules:
phase-al-am-runtime-boundary-checklist.md. Every AL PR must pass them before merging forward. - The authoritative plan is Phase AL plan.
Sprint line:
AL.1 [COMPLETE]sprint-AL1-runtime-contract.md— runtime contract and archived-hook transplantAL.2 [COMPLETE]sprint-AL2-canonical-handler.md— canonical handlerAL.3 [COMPLETE]sprint-AL3-received-hook.md— received hook wiringAL.4sprint-AL4-shared-client.md— shared clientAL.5 [COMPLETE]sprint-AL5-unix-uds.md— Unix UDS listenerAL.6sprint-AL6-loopback-tcp.md— loopback TCP listenerAL.7 [ABANDONED]sprint-AL7-peer-tls-m5-proof.md— mTLS peer adapter removed from the Phase AL MVP before implementation; retained TLS material stays quarantined reference onlyAL.8sprint-AL8-daemon-composition-proof.md— daemon composition and static boundary proofAL.9sprint-AL9-physical-proof-ledger-freeze.md— physical adapter matrix, benchmark, cutover/abort, AM ledger freezeAL.10 [ABANDONED]— proposed M4 hardware-smoke work was superseded before a sprint record was accepted; its useful evidence moved to the direct M5 and cwin tracks belowAL.11 [SUPERSEDED]— historical M5 hardware-smoke dispatch, replaced by the pinned-candidate, direct-peer AL.13 planAL.12 [SUPERSEDED]— historical cwin hardware-smoke dispatch, replaced by the direct public-CLI AL.14 planAL.13 [COMPLETE]sprint-AL13-m5-direct-crosshost-smoke.md— M5↔M4 direct-peer smoke and benchmark evidenceAL.14 [BLOCKED]sprint-AL14-cwin-direct-crosshost-smoke.md— cwin local smoke and benchmark evidence retained; its Windows-originated direct-peer row is infrastructure-blockedAL.15 [BLOCKED]sprint-AL15-direct-crosshost-evidence-closeout.md— coordinator closeout remains blocked until AL.9's final physical-proof rows are rerun and accepted at one frozen candidateAL.16sprint-AL16-hermes-graft-live-proof.md— installable genericatm-graftand Hermes-facinghermes-atmpackage boundary; package-side candidate is under review, while portable live proof is blocked on a reviewed, immutable, deployed Hermes host contractAL.17sprint-AL17-hermes-gateway-lifecycle.md— reviewed, immutable, deployed Hermes runner lifecycle/injection contract for the queue MVP; required before a portable live package claimAL.18sprint-AL18-hermes-telegram-live-proof.md— installed-package M4 idle and same-session busy queue proof after AL.17 is deployedAL.19sprint-AL19-hermes-m5-py311-verify.md— M5 multi-interpreter package verification; CPython 3.11 is an early wheel-compatibility lane and the active M5 Hermes-service lane must be inventoried and proven separately
Acceptance:
- Phase AL acceptance is defined by the authoritative plan's sprint validations and the runtime boundary checklist's required evidence set.
Status summary:
- Phase AM is deletion-only: it removes the legacy transport machinery made
redundant by
atm-http-runtime(raw HTTP framing, legacy local/peer transport workers, peer-only ingress, resend/replay machinery) without preserving, repairing, or extending it. - Planning branch:
plan/tokio-migration. - Baseline:
develop @ 67401907039f92e58e883273f02372a637202f70plus accepted Phase AL. - Entry gate: AM implementation begins only after AL.9 proves the new runtime is the live local and cross-host path. AM may inventory and write static guards in parallel with AL but must not delete a live path before that proof.
- Binding boundary and transition rules:
phase-al-am-runtime-boundary-checklist.md,phase-al-am-boundary-transition.md. - The authoritative plan is Phase AM plan.
Sprint line:
AM.1sprint-AM1-removal-ledger.md— deletion ledger, topological deletion order, negative architecture guardsAM.2sprint-AM2-delete-legacy-http.md— migrate retained non-write compatibility callers, then delete legacy HTTP framingAM.3sprint-AM3-delete-legacy-local.md— delete legacy local transportAM.4sprint-AM4-delete-legacy-peer.md— delete legacy peer transportAM.5sprint-AM5-delete-replay.md— delete resend/replay machineryAM.6sprint-AM6-minimality-proof.md— minimality proof
Acceptance:
- Phase AM acceptance is defined by the authoritative plan's sprint validations: every production legacy reference has one ledger row or is proven dead, no guard is merged early, and the minimality proof confirms no compatibility shim survives.
-
Phase AN: Decomposed Template Messages And Query Surface [AN.1–AN.10 COMPLETE] — Added a bounded
sc-composeradapter boundary, durable template catalog and decomposed-message records, render-on-read, FTS search, public introspection/query surfaces, and compose guidance. AN.8 closes the original decomposed-template phase with Q1–Q4 read-only query fixtures, a template-agnostic vocabulary proof, and the Tokio HTTP four-cell routing matrix on the Linux/macOS/Windows CI lanes. Physical cross-host template synchronization remains intentionally out of scope. (Authoritative plan:plan-phase-an.md; evidence:validation-evidence.md) -
AN workflow-metadata extension [COMPLETE] — adds optional template-declared workflow facts, immutable admission snapshots of template and instance tag provenance, generic local lifecycle analytics, and an opt-in OpenTelemetry-compatible projection. It retains no ATM-specific workflow vocabulary and is governed by
ADR-046.
Sprint line:
-
AN.9feature/pan-s9-template-workflow-contract -
AN.10feature/pan-s10-template-workflow-admission -
AN.11feature/pan-s11-workflow-analytics-projection— local workflow lifecycle analytics, query projection, and opt-in telemetry seam -
AN.12feature/an12-workflow-validation-evidence— retained two-vocabulary local validation for admission/provenance, CLI/HTTP/Python query, routing, migration compatibility, and best-effort telemetry isolation -
AN.13feature/an13-sc-composer-141-upgrade— durable output-format catalog identity and exact releasedsc-composer/sc-sha1.4.1 adapter pin -
AN.14feature/an14-sc-compose-141-checked-emission— adapter-only checked emission that rejects malformed JSON before send or render-on-read -
AN.13–AN.15 checked-render upgrade and assurance [COMPLETE] — AN.13 establishes durable adapter-derived output-format identity and adopts the released exact
sc-sha/sc-composer1.4.1 dependency chain in its adapter; AN.14 makes theatm-template-sc-composeadapter refuse malformed rendered JSON before sending, caching, or render-on-read output. AN.15 then runs a bounded, deterministic adversarial campaign over the checked template/catalog lifecycle, including captured-environment and immutable-revision oracles. The AN.15 HTTP-seam addendum (PR #887,feature/an15-http-fuzz-campaign) is merged and exercises the current Tokio/Axumatm-http-runtimeboundary with a separately retained, commit-pinned four-worker campaign; it is not duplicate pre-Tokio AI.51 work against the removedapi::http_frame_readermodule. AN.15 does not make ATM a template-approval or lineage-policy engine. The three sprints required crates.io to publishsc-sha,sc-composer, andsc-compose1.4.1; publishedsc-composerexportscheck_rendered_output,CheckedOutput, andOutputFormat; and sc-compose #448 supplies the direct-library checked-emission regression coverage. AN.13 retained release evidence records the satisfied gate; the authoritative scope and closure gates are insprint-AN13-sc-compose-141-checked-render.md,sprint-AN14-sc-compose-141-checked-emission.md, andsprint-AN15-adversarial-fuzzing.md.
Phase AO replans opt-in mTLS for the active Tokio/Axum peer HTTP path. The normal plaintext direct-peer listener and client remain the compatibility pipeline and must be structurally unchanged when TLS is not selected. An explicit runtime mode selects plaintext or mTLS in one shipped daemon build; mTLS is fail-closed, requiring exact hostname/SNI, certificate pin, trusted client certificate, and enabled interface configuration, and it never falls back to plaintext. Both modes retain one canonical HTTP request, storage, acknowledgement, and nudge path. The existing TLS interop crate remains quarantined fixture/reference material; production runtime code must not depend on it.
Implementation begins only after the accepted Tokio/Axum runtime line is
active. Phase AM's explicit AO TLS exception preserves the existing TLS helper
boundary while AO is decided; it is not an additional AO entry gate. AO work
integrates through integrate/phase-ao2; the earlier AO plan is retained only
as archived reference. The authoritative plan is
Phase AO plan.
Sprint line (all four merged into integrate/phase-ao2 2026-08-20 under
AO2.1–AO2.4 titles; landed on develop with PR #966 on 2026-08-26):
AO.1feature/pao-s1-peer-wire-policy[COMPLETE — PR #961] — ADR-047, typedPeerWireMode(mTLS default), peer-wire error/recovery contracts, boundary records, and executable guards proving the plaintext arm stays on the existing direct-peer canonical HTTP pipelineAO.2feature/pao-s2-isolated-mtls-stream-adapter[COMPLETE — PR #965] — boundedpeer-tlsadapter with positive and negative stream evidenceAO.3feature/pao-s3-runtime-peer-wire-mode[COMPLETE — PR #967] — one daemon build selects the original plaintext or mTLS stream establishment without application driftAO.4feature/pao-s4-peer-wire-proof[COMPLETE — PR #968] — shipped-daemon plaintext/mTLS proof and compatible-baseline performance evidence
Phase AP investigates support for a firewalled daemon that may initiate an outbound connection but cannot accept unsolicited peer TCP. The preferred direction is an mTLS-authenticated HTTP/1.1 SSE session from the restricted host to a reachable peer plus ordinary authenticated POST for correlated responses. It remains online-only: no outbox, retry/replay, or durable relay is introduced.
AP.1 is mandatory and must execute first on the actual CWin, M4, and M5 machines. It proves—or records a block for—the real outbound DNS/TLS/SSE/POST path without SSH tunneling, localhost simulation, raw-IP substitution, or a third-party relay. No AP product implementation begins if that physical proof does not pass. The authoritative outline is Phase AP plan.
Status 2026-08-26: AP's precondition (Phase AO's mTLS runtime line active) is
satisfied — AO merged to develop via the AO2 integration (PR #966). AP.1's
physical hardware proof remains the mandatory entry gate; no AP dispatch has
occurred.
48. Phase AQ — ATM Send-To Shell Integration [COMPLETE ON DEVELOP (PR #1079) — 5 open follow-ups, 2 tied to Must PRD requirements (R1 GUI E2E, R15 m5); see qa-evidence-master.json follow_ups]
Phase AQ delivers PRD Phase 1 of ATM "Send To": one gesture from the OS file
manager (Finder / Explorer / Nautilus) to a delivered message whose text
names files landed under the recipient host's $ATM_TEMP. Cross-host bytes
move via user-configured per-host transfer scripts (sftp default over fleet
SSH; unconfigured hosts fail closed with a setup-doc error) — no envelope
change, no daemon transfer machinery. ADR-055 defines the system-level
ATM_TEMP contract (mandatory env var, 30-day TTL sweep) and the
transfer-script seam; thin per-OS shell glue drives the pipeline
atm teams --json --members | <picker> | atm send --attach "$@" --from-json.
Phase 1 also delivers atm queue — atm send with the nudge deferred until
the recipient harness is ready (nudge taxonomy: steer and queue are message
kinds, not delivery timings — the physical mechanism may itself defer a
steer-kind notification until the next bare-CLI Stop pull, and mechanism
timing never changes the kind; ADR-054, AQ2.5 addendum) — via a
nudge_pending_at marker, a PendingNudgeStore
storage capability, graft dual-channel wiring (harness owns landing; Hermes
/steer+/queue complete), and a tmux idle-drain, under the ADR-054 nudge
taxonomy (nudge = umbrella; steer/queue = kinds) with its code-rename
inventory. Queue ships first; trait foundation first, Herdr second
(reordered 2026-08-26 per Rand). Fourteen sprints: AQ1 trait foundation +
atm queue CLI verb + ADR-054 taxonomy + PendingNudgeStore; AQ2.6/AQ2.7
Herdr local-steer backend + lifecycle-gated queue wake (most urgent);
AQ2.6 sprint is the
authoritative implementation entry for the local Herdr backend and is
complete after the AQ2.6 QA1 fix cycle. The AQ2.7 sprint
is complete with the fixed-cadence Herdr queue-wake pump and runtime health
poll projection;
AQ1.5–AQ1.9 graft push-registration (ADR-056), parallel with Herdr; AQ2
graft dual-channel; AQ2.5 queue delivery triggers (heartbeat hooks,
bare-CLI FIFO); AQ3 tmux idle-drain + recovery sweep; AQ4 Send-To core
(ATM_TEMP ADR-055, CLI surface, transfer scripts, sweeper); AQ5 surface +
phase evidence; AQ6 sc-ecosystem dependency preflight (pin-latest
Wyvern/sc-compose/sc-observability + integration tests) + Wyvern
contract-test issue. Plan status (2026-08-26): the earlier plan-QA PASS was
retracted after a whole-tree critical review (FAIL, 10 blocking); all
findings were closed in a finalization pass and the re-entry critical review
PASSed on round 3 (ea990a8dd); quality-mgr gate on PR #1019 in progress.
ADR-058 (Herdr local steer backend contract) is the phase's fourth ADR. Branches feature/aq-N-<slug> off
integrate/phase-aq, all PRs target integrate/phase-aq. The authoritative
plan is Phase AQ plan; source PRD is
prd-atm-send-to. PRD Phase 2
(agent-assisted drafting, Wyvern chat sessions) is explicitly deferred.
Phase AQ complete on develop (14/14 sprints) — integrate/phase-aq →
develop merged via PR #1079 (1f5666fa5).
Status 2026-08-28: all 14 of the phase's sprints are merged to
integrate/phase-aq:
- AQ1 trait foundation +
atm queueCLI verb/taxonomy — PR #1040 (feature/aq-1-trait-foundation) - AQ1.5 graft push-registration API — PR #1045
- AQ1.6 graft receiver registration client — PR #1046
- AQ1.7 graft endpoint consumer cutover — PR #1048
- AQ1.8 graft file-record retirement — PR #1049
- AQ1.9 hermes-atm wheel verification + restart-matrix crash guard — PR #1050,
PR #1070 (
26fb5bc4d); the m5 live matrix follow-up remains pending - AQ2 graft dual-channel queue delivery — PR #1051
- AQ2.5 queue delivery triggers (heartbeat CLI surface, bare-CLI FIFO,
QueuePullclassifier, ADR-054 delivery-trigger addendum) — PR #1053 - AQ2.6 Herdr local-steer backend — PR #1042
- AQ2.7 Herdr poll-gated queue wake — PR #1056, merged
6c70f88ce(cycle-5 QA-5 PASS, closing commitd25b049d7) - AQ3 tmux idle-drain + recovery sweep — PR #1054, merged
deed32e93(QA-final6 PASS 14/14) - AQ4 Send-To core (ATM_TEMP, CLI surface, transfer scripts, sweeper) —
PR #1055, merged
0adce24d6(QA-3 PASS-with-deferral, 7/9 AC; Windows loopback and tailscale legs deferred by ruling) - AQ5 Send-To surface + phase evidence — PR #1059, merged
53921169eon 2026-08-28 - AQ6 sc-ecosystem dependency preflight + Wyvern contract issue — PR #1066,
final head
29ac4a7c58796f446f3cdd6725f265ea6db2a66a, mergededb1a5381on 2026-08-28
Tracked follow-ups (owner in parentheses): AQ1.9-m5 — live m5 restart matrix
and hermes-atm suite run (Phase AQ closeout/AQ6); AQ4-tailscale-m5 — live
tailscale transfer transcript (Phase AQ closeout); AQ4-windows-loopback —
real Windows-host/POSIX-receiver reproduction of the ssh-under-pwsh loopback
gap (Phase AQ closeout); AQ5-gui-e2e — live Finder/Explorer/Nautilus
member-picker GUI E2E transcripts (Rand); AQ6-wyvern-pin-bump — Wyvern pin
behind the latest upstream release, surfaced by ecosystem-preflight on
PR #1076, bump before the next release, not a phase-merge blocker (Phase AQ
closeout). See Phase AQ plan for the
authoritative sprint-by-sprint detail and
docs/plans/phase-aq/.audit/qa-evidence-master.json for QA/merge
provenance.
COLIMA-SIMPLIFY-R1 is a complete documentation sprint on branch
plan/colima-simplify, targeting develop. Its authoritative
sprint plan replaces the
multi-party Colima exercise with one unattended testbed command, one aggregate
JSON result, and a 30-minute command-to-verdict budget. It is independent of
the current ATM build/rollout and parallel-safe with the separate canonical
Hermes patch-model work. Future testbed implementation lands as small,
independently mergeable PRs; no testbed or product code changes in this sprint.
49. Phase AO2 — Benchmark Safety, Evidence, And Transport Performance [COMPLETE — MERGED TO DEVELOP]
Phase AO2 made physical admission benchmarks safe and repeatable, restored
the bounded writer transaction-coalescing path, and established the benchmark
data, rendering, history, and operator-workflow contracts. It retains the
Tokio/Axum atm-http-runtime as the sole daemon path: snapshot/restore,
reporting, and benchmark tooling do not create or preserve a legacy transport
path.
The accepted implementation line includes dedicated benchmark-account snapshot/restore safety (AO2.5/AO2.5.4), the typed temporary daemon-switch overlay (AO2.5.3b), writer batching (AO2.6), the four-target benchmark matrix (AO2.7), versioned JSON/report contracts and historical migration (AO2.10–AO2.13), peer connection pooling (AO2.14), and the headless official benchmark trigger (AO2.15). AO2.8 is explicitly descoped; it is not evidence of Windows coverage.
The canonical operator procedure is the repository
benchmark-run skill. The phase is
not release-closed until its proof matrix and accepted-line evidence are
recorded in Phase AO2 readiness, including
the required four-target macOS campaign and the separately required Windows
TCP/TLS evidence.
Status 2026-08-26: integrate/phase-ao2 merged to develop via PR #966
(merge commit 9923ef6cb). Known deferred debt carried out of the phase
gate: 22 pre-existing sc-boundary findings, waived for the AO2 gate as
triage record AO2-SCBOUNDARY-DEBT-001 and tracked in GH issue #1028 —
these make just validate (and CI) red on develop until Phase AU retires
them. Post-merge follow-ups (post-mortem finalization, deferred findings
QA-AO215-I003 / AO2-REPORT-F001) are tracked in the readiness doc and
triage records, not here.
Phase AR plans atm-core's side of embedding native agent-team-mail into the
codex CLI fork (randlee/codex-atm) — the second production host after
hermes-agent and the first pure-Rust, crates.io-consuming one. The draft
covers seven requirement areas: a publishable atm-graft crate (R1), a
Rust-native two-channel (steer + queue) host embedding API with a durable,
bounded, backpressured queue channel (R2), fail-loud activation via
ATM_IDENTITY/ATM_TEAM replacing the .atm.toml silent no-op (R3, issue
#900), a required protocol-sequencing ruling — file-rendezvous graft vs.
daemon long-poll session protocol (R4, issue #899, the blocking
architectural decision), packaged sc-lint boundary rules (R5), hermetic
test/smoke support (R6), and release cadence/compatibility (R7).
No sprints are cut. The plan exists only on branch plan/phase-ar
(docs/plans/phase-AR/), pending arch-ctm review; it has not merged to
develop. Note: the local worktree named plan/phase-ar-graft-registration
does NOT contain this plan.
Phase AS attempted to adopt the shared sc-publish kit as an upstream-owned
overlay for ATM's release pipeline (crates.io/PyPI/Homebrew/winget). Six
sprints (AS.1–AS.6) were planned and work through AS.4/AS.5 merged into
integrate/phase-as, but the entire line was reverted from develop via
PR #960 (2026-08-19/20). Phase AT is its successor and explicitly carries
forward no AS work, files, acceptance criteria, or release receipts. The AS
artifacts remain only on origin/integrate/phase-as as historical
reference; do not build on them.
52. Phase AT — Manifest-Driven Publishing Recovery [COMPLETE — AT.1 MERGED, AT.2 DEFERRALS RECORDED]
Phase AT restarts the publish-kit adoption from the post-AS-revert baseline
(commit d610b4c07) under the ADR-050 ownership split: sc-publish owns
generic publish mechanics; atm-core owns its own manifest, validation, and
publish-order correctness. Two sprints: AT.1 install one immutable,
pinned sc-publish revision (never patched locally) driven by ATM's
complete consumer JSON input, prove preflight/release parity, and perform
the authorized publish proof; AT.2 verify coverage, then delete the
legacy publish surface — release.yml, release-preflight.yml,
hermes-atm-pypi-publish.yml, root scripts/ — that the kit now covers
(must_follow AT.1), retaining rows whose gate receipt does not yet exist as
deferred-until-<gate>. Integration branch: integrate/phase-at.
Amendment (2026-08-27, owner decision — forward-only publishing). The
originally planned TestPyPI→PyPI retry of the pre-kit 1.4.3 release is
withdrawn: v1.4.3 is unpublishable via the kit (kit action absent at the
tag; legacy manifest fails the kit schema), and Rand ruled pre-kit-tag
republishing out of scope. The publish-proof leg is retargeted to the first
kit-era tag (workspace version 1.4.4), cut after phase AT merges to
develop; TestPyPI authorization carries over, production remains
pending contemporaneous authorization. See
docs/plans/phase-at/receipts/AT.1-receipt.md.
AT.1 merged via PR #1044 (plus receipt amendments #1052/#1062); an AT.1
dry-run rehearsal receipt exists on smoke/phase-at-at1-rehearsal. AT.2
completed on feature/pat-s2-legacy-publish-deletion: it removed the
unreachable pre-kit installed-doc validator path and recorded every remaining
legacy publish candidate as a gate-bound deferral in its receipt. The first
kit-era release is the follow-up deletion trigger.
This is a distinct, narrowly-scoped release-validation phase, not a revival
of the superseded Phase AS — Shared Publish-Kit Migration above. It owns
only the repository-local, tag-triggered prerelease archive workflow and its
operator safeguards. Its current sprint is
AS1.1 — Prerelease archive job,
which builds CI-provenanced archives without publishing or modifying the
vendored sc-publish kit. It does not inherit the retired phase's files,
acceptance criteria, or release receipts.
PRERELEASE-R1 delivers the vendorable sc-publish prerelease skill and the
first atm-core adopter: GitHub prerelease Release assets, checksum-verified
staging, and managed-pair installation without touching production channels or
the Homebrew formula. The sprint record is
PRERELEASE-R1.
Phase AU retires the 22 pre-existing sc-boundary findings exposed when
QA-RUSTQA-AO2-001's fix armed the sc-boundary lint in just validate
(waived at the AO2 gate as AO2-SCBOUNDARY-DEBT-001, tracked in GH #1028) —
the findings currently making CI red on develop. Constraint: no boundary
loosening — no rule removed from just lint all, no baseline/ignore file;
the only suppressions permitted are the lint's own purpose-built per-type
opt-in markers where they are the designed mechanism. Three sprints mapping
to the analysis waves: AU.1 mechanical code fixes clearing 9–10 findings
(no lint changes, no design questions); AU.2 sc-lint-boundary calibration
— NodeId impl-discriminator bug fix, call-callee reference metadata, and
narrowed self-loop/trait-impl classifiers with pinning tests — clearing 11
findings; AU.3 the one true architectural cycle, atm_core::ack ↔
send, restructured via a narrow sibling write-contract module (design
review + benchmark-parity gate on m5-atmbench required; mechanical
relocation only on the hot path). Exit: sc-boundary reports 0 findings,
just validate fully green, waiver retired, #1028 closed.
The authoritative plan is
boundary-regression-plan (arch-ctm
critical review round 1 folded in); phase-au sprint docs are being cut from
it under docs/plans/phase-au/ on branch plan/boundary-regression.
Phase AV fixes the mailbox-read serialization regression: every core job —
including all reads — funnels through one single-permit BlockingCoreBridge
in atm-http-runtime, so an unrelated slow job head-of-line blocks atm read past its client budget. The phase completes the Tokio cutover the AL
phase left unfinished: a bounded read-only WAL reader lane
(AsyncMailboxReader), atomic read-handler cutover with the hidden
read-flow mutations split onto the writer lane, normative
requirements/ADR hardening making re-serialization non-compliant,
mechanical hard gates, and massively-parallel read/query benchmark
families with ratcheted floors. Five sprints: AV.1a reader-lane
foundation (runtime-inert), AV.1b read-handler cutover (the atomic
behavior change), AV.2 requirements/ADR hardening, AV.3 mechanical
hard gates, AV.4 read/query benchmarks. Dependency chain:
AV.1a→AV.1b→{AV.3, AV.4}; AV.2 parallel-safe with all.
The authoritative plan is
phase-av-plan with per-sprint docs
under docs/plans/phase-av/, authored on branch plan/phase-av (PR #1108).
Phase AV sprint status:
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
AV.1a |
merged (PR #1112) |
fix/mailbox-read-blocking-serialization |
docs/plans/phase-av/sprint-AV.1a-reader-lane-foundation.md |
AV.1b |
merged (PR #1115) |
feature/av1b-read-handler-cutover |
docs/plans/phase-av/sprint-AV.1b-read-handler-cutover.md |
AV.2 |
complete |
feature/av2-read-concurrency-requirements |
docs/requirements.md, docs/adr/ADR-059-async-mailbox-read-concurrency.md, docs/plans/phase-av/av-closeout-record.md |
AV.3 |
complete (PR #1113 merged) |
feature/av3-read-concurrency-gates |
docs/plans/phase-av/sprint-AV.3-mechanical-hard-gates.md |
AV.4 |
complete (PR #1114 merged) |
feature/av4-read-query-benchmarks |
docs/plans/phase-av/sprint-AV.4-read-query-benchmarks.md |
Phase AW makes replacement-runtime tracing retained and safely observable: AW.1 installs the allowlisted non-blocking tracing bridge, AW.2 persists the SQLite diagnostic timeline, AW.3 exposes health and log queries, AW.4 adds graft fallback observability, and AW.5 aligns native tool projections. The authoritative plan is phase-aw-plan.
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
AW.1 |
complete |
feature/aw1-tracing-bridge |
docs/plans/phase-aw/sprint-AW.1-tracing-bridge.md |
AW.2 |
complete |
feature/aw2-sqlite-diagnostic-timeline |
docs/plans/phase-aw/sprint-AW.2-sqlite-diagnostic-timeline.md |
AW.3 |
complete |
feature/aw3-health-and-log-query |
docs/plans/phase-aw/sprint-AW.3-health-and-log-query.md |
AW.4 |
complete |
feature/aw4-graft-fallback-observability |
docs/plans/phase-aw/sprint-AW.4-graft-fallback-observability.md |
AW.5 |
complete |
feature/aw5-native-tool-parity |
docs/plans/phase-aw/sprint-AW.5-native-tool-parity.md |
56. Phase AX — Nudge Templates On Every Backend And Task-State Tracking [COMPLETE — MERGED TO DEVELOP (PR #1253, 98661ea18)]
Phase AX closes three delivery defects found in the 2026-09-04 Herdr
dogfood run (issue #1173): the Herdr sink bypasses the built-in nudge
templates and injects fixed wake text; atm queue has no template class
of its own; and task-tagged mail has no state, so a second task can be
acked while the first is in progress and an idle assignee is never
reminded. Seven sprints in four tracks: A = AX.1 queue template class
→ AX.2 Herdr template rendering; B = AX.3 task state machine and
storage → AX.4 task CLI and docs, running in parallel with A
(parallel_safe: AX.1∥AX.3, AX.2∥AX.3); C = AX.5 reminder cycle →
AX.6 lead notification and doctor, after A and B merge; D = AX.7
live Herdr evidence. must_follow edges: AX.1→AX.2, AX.3→AX.4,
AX.2→AX.5, AX.4→AX.5, AX.5→AX.6, AX.6→AX.7. Branches are worktrees via
sc-git-worktree; PR bases and merges via gh stack (sequence in the
phase plan §6).
Current phase status: AX.1-AX.6 merged into integrate/phase-ax; AX.7
superseded 2026-09-05. integrate/phase-ax merged to develop 2026-09-06
23:14:05Z via PR #1253 (merge commit 98661ea18, parents 9a1e242d1 +
247bb1340). Phase complete. AX7's QA_RUN_MISSING triage-report gap (no
authoritative QA run for a superseded sprint) is an open post-mortem
follow-up, not a blocker.
The authoritative plan is
phase-ax-plan with per-sprint docs
under docs/plans/phase-ax/, authored on branch integrate/phase-ax.
Phase AX sprint status:
| Sprint | Track | Execute | Status | Branch | Artifacts |
|---|---|---|---|---|---|
AX.1 |
A | parallel with AX.3/AX.4 | complete |
feature/ax1-queue-template-class |
docs/plans/phase-ax/sprint-AX.1-queue-template-class.md, ADR-019 amendment |
AX.2 |
A | after AX.1; parallel with AX.3/AX.4 | complete |
feature/ax2-herdr-template-rendering |
docs/plans/phase-ax/sprint-AX.2-herdr-template-rendering.md, ADR-058 amendment, boundaries/atm-herdr/herdr-process-adapter.toml, docs/atm-herdr/requirements.md |
AX.3 |
B | parallel with AX.1/AX.2 | complete |
feature/ax3-task-state-machine |
docs/plans/phase-ax/sprint-AX.3-task-state-machine.md, docs/adr/ADR-062-task-state-machine.md, ADR-054 amendment, boundaries/atm-storage/task-store.toml, boundaries/atm-storage-rusqlite/task-store-sqlite.toml |
AX.4 |
B | after AX.3; parallel with AX.1/AX.2 | complete |
feature/ax4-task-cli-and-docs |
docs/plans/phase-ax/sprint-AX.4-task-cli-and-docs.md, docs/user-documents/tasks.md |
AX.5 |
C | after A and B merge | complete |
feature/ax5-task-reminder-cycle |
docs/plans/phase-ax/sprint-AX.5-task-reminder-cycle.md, ADR-062 reminder-cycle section |
AX.6 |
C | after AX.5 | complete |
feature/ax6-lead-notification-doctor |
docs/plans/phase-ax/sprint-AX.6-lead-notification-doctor.md |
AX.7 |
D | superseded 2026-09-05 (live proof moved to release readiness) | superseded |
none | docs/plans/phase-ax/sprint-AX.7-herdr-dogfood-evidence.md |
Herdr already runs on Windows: Rand manually verified an atm 1.5.0 self-send,
and nothing in the current client code blocks it. Phase AY instead moves the
six-operation client from a per-nudge CLI process to Herdr's native IPC—a
Unix-domain socket on macOS/Linux and named pipe on Windows—because Phase AX's
queue templates, built-in nudge rendering, task state/CLI, reminder cycle,
lead notification, and doctor all depend on that delivery path. It also
defines the daemon's optional-dependency behavior when Herdr is absent, late,
or crashed. The CLI remains a bounded fallback. Windows work includes real
production correctness code—CREATE_NO_WINDOW, a bounded kill-then-reap grace
period, per-call binary re-resolution, and CRLF-tolerant decoding—plus removal
of three stale scope-outs and closure of the cfg(unix) process-test gap. Windows CI
proves that behavior without live hardware. Live macOS/Windows proof stays in
release readiness (no sprint carries live evidence, Rand 2026-09-05). No work
remodels the legacy synchronous daemon; all composition targets the Tokio/Axum
atm-http-runtime cutover architecture.
Nine sprints execute in a documentation lane, a linear implementation
stack, an independent socket lane, and a code join. AY.1
runs in parallel with AY.2. The only stacked-PR chain is
AY.2→AY.3→AY.4→AY.5→AY.6→AY.7, managed noninteractively with the
/gh-stack skill. AY.8 starts independently only after AY.1, AY.2, and
AY.3 merge; it is parallel-safe with AY.4–AY.7. AY.9 is the standalone
AY.7+AY.8 code join and the phase's last sprint; the live macOS/Windows
matrix runs under release readiness once the phase is on develop.
AY.9's production contract is closed and explicit: native socket transport is
the default, while herdr.transport = "cli" remains a permanent explicit
alternative. The transport is selected once at Tokio bootstrap; a socket
failure is a typed availability/breaker outcome, never a hidden CLI fallback.
Doctor displays the active transport and a sanitized endpoint. No CLI removal
release or ownership-key cleanup is planned, and AY.9 contains no live
evidence; release readiness owns the live gate.
The authoritative umbrella is
Phase AY plan, with one
authoritative sprint file per sprint under docs/plans/phase-ay/.
Status: all Phase AY sprints have merged into integrate/phase-ay; the
phase-ending gate is in progress, and the merge to develop is pending Rand
approval.
Phase AY sprint status:
| Sprint | Track | Execute | Status | Branch | Authoritative sprint doc |
|---|---|---|---|---|---|
AY.1 |
Docs | parallel with AY.2 | merged (#1270, 7e40db597) |
feature/ay1-herdr-audit-docs |
docs/plans/phase-ay/sprint-AY.1-herdr-audit-docs.md |
AY.2 |
Core stack | parallel with AY.1; stack bottom | merged (#1269, 1195614ba) |
feature/ay2-herdr-transport-seam |
docs/plans/phase-ay/sprint-AY.2-herdr-transport-seam.md |
AY.3 |
Core stack | after AY.2 development and P-E(a); AY.2 merges first | merged (#1273, 5f769d488) |
feature/ay3-herdr-endpoint-doctor-config |
docs/plans/phase-ay/sprint-AY.3-herdr-endpoint-doctor-config.md |
AY.4 |
Core stack | after AY.3 development; parallel with AY.8 once eligible | merged (#1279, fc736e83e) |
feature/ay4-herdr-breaker-lifecycle |
docs/plans/phase-ay/sprint-AY.4-herdr-breaker-lifecycle.md |
AY.5 |
Core stack | after AY.4 development; parallel with AY.8 | merged (#1282, fa1e7d73b) |
feature/ay5-herdr-entry-control-plane |
docs/plans/phase-ay/sprint-AY.5-herdr-entry-control-plane.md |
AY.6 |
Core stack | after AY.5 development; parallel with AY.8 | merged (#1284, 8b0a6d346) |
feature/ay6-herdr-restart-coordination |
docs/plans/phase-ay/sprint-AY.6-herdr-restart-coordination.md |
AY.7 |
Core/Windows stack | after AY.6 development; Windows CI lane is the gate; parallel with AY.8 | merged (#1285, 94556328c) |
feature/ay7-windows-herdr-process-installer |
docs/plans/phase-ay/sprint-AY.7-windows-herdr-process-installer.md |
AY.8 |
Socket | after AY.1/AY.2/AY.3 merge and P-E(b); parallel with AY.4–AY.7; standalone | merged (#1280, 4407b006e) |
feature/ay8-herdr-socket-transport |
docs/plans/phase-ay/sprint-AY.8-herdr-socket-transport.md |
AY.9 |
Join | after AY.7/AY.8 merge; standalone code cutover | merged (#1295, 7ad3ad7e5, disposition Ship) |
feature/ay9-herdr-socket-cutover |
docs/plans/phase-ay/sprint-AY.9-herdr-socket-cutover.md |
AY.13 |
Doctor | standalone; Rand 2026-09-07 doctor team-scope requirement; parallel with AY.14 | merged (#1300, dd809c15e) |
feature/ay13-doctor-team-scope |
docs/plans/phase-ay/sprint-AY.13-doctor-team-scope.md |
AY.14 |
Herdr/roster | standalone; Rand 2026-09-07 name-collision ruling (roster alias); parallel with AY.13 | merged (#1305, 271b387ed) |
feature/ay14-herdr-agent-name-mapping |
docs/plans/phase-ay/sprint-AY.14-herdr-agent-name-mapping.md |
AY.15 |
Herdr/roster | must_follow AY.14; Rand 2026-09-07 unique_name ruling (alias ?? name unique database-wide); closes AY14-QA-003 | merged (#1310, 47f359cf9) |
feature/ay15-herdr-name-uniqueness |
docs/plans/phase-ay/sprint-AY.15-herdr-name-uniqueness.md |
DOCTOR-HERDR-TARGET-R1 |
Doctor | standalone target-resolution, breaker, and stale-session diagnostics | complete |
fix/doctor-herdr-target-resolution |
docs/plans/doctor/sprint-DOCTOR-HERDR-TARGET-R1.md |
58. Phase AZ — Bounded Nudges And Durable Task Lifecycle [SUPERSEDED BY PHASE BA — RETIRED UNMERGED 2026-09-11]
Superseded by Phase BA, retired unmerged 2026-09-11: the four AZ sprints on
integrate/phase-az (PR #1394) will not merge to develop. Issue #1378's
canonical roster state and HTTP API 1.4.0 (PRs #1381, #1384) merged to
develop independently and remain in force. The text below is the retired
plan, kept for record.
Phase AZ begins with the AZ.1 metadata-only nudge repair: every Steer, Queue,
rebuilt Queue, Task, acknowledge-family, and task-reminder path projects only
persisted message id/title and optional task id. The immutable body remains
available only through atm read --message-id; admission-time
build_summary policy is unchanged.
AZ.2–AZ.4 then replace the message-derived task ledger with a stable logical
TaskId, immutable assignment attempts/events, explicit lifecycle commands,
atomic terminal handoffs and queue cleanup, and one fair idle attention
selector over independent ephemeral-message and persistent-task lanes.
Blocked -> Assigned is explicit and never auto-starts. Existing tasks migrate
at normal priority; one current assignee per task and one active task per
(team, agent) are transactionally enforced.
Issue #1378 is a pre-AZ.4 prerequisite. It makes the RAM master roster the sole
ephemeral agent-state owner, routes both Herdr polls and authenticated
heartbeat/hook POSTs through it, and leaves RuntimeHealth projection-only.
Each accepted canonical idle revision may publish one opportunity to AZ.4;
delivery-channel filtering remains downstream and bare-CLI pull is unchanged.
The governed-interface sequence is HTTP API 1.3.0 → 1.4.0 in AZ.3 and SQLite
schema 2.0.0 (major task migration) → 2.1.0 (additive attention tables) in
AZ.2/AZ.4. ADR-063 records the capability-trait recount and v1/v2 coexistence
bridge. Rand approved that major change on 2026-09-09: ATM 1.6.0 introduces
v2, every 1.6.x release retains the bridge, and ATM 1.7.0 is the planned
removal target and earliest permitted removal release under a separate ADR-061
major review. ADR-061 D6 and ADR-063 D6 record the decision.
The authoritative umbrella is Phase AZ plan, with one authoritative sprint doc per row below and a maintained issue inventory.
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
AZ.1 |
retired (unmerged) |
feature/az1-task-nudge-contract |
bounded notification event/template repair, external hook compatibility, long-body/J2 regressions |
AZ.2 |
retired (unmerged) |
feature/az2-task-domain-storage |
lifecycle types, immutable attempts/events, SQLite migration, atomic invariants and task-aware nudge cleanup |
AZ.3 |
retired (unmerged) |
feature/az3-task-command-handoff |
canonical task CLI/API, authorization, atomic handoffs/supersession, legacy adapters |
AZ.4 |
retired (unmerged) |
feature/az4-attention-scheduler |
one-item idle selector, durable fair interleaving, attempt-aware persistent reminders |
The stack is strict AZ.1 -> AZ.2 -> AZ.3 -> AZ.4. Parent development must be
pushed before child work starts, the parent is merged forward before every
child development/fix round, and parent PRs merge first. No Phase AZ sprint
touches the frozen synchronous daemon or uses live daemon/test-daemon, release,
tag, publish, or installation evidence.
59. Phase BA — One Invariant, One Queue, One Task Command Set [LANDED ON integrate/phase-ba 2026-09-12 — review-findings closeout in progress]
Phase BA replaces the retired Phase AZ task work with the simpler design in
the Phase BA plan. BA.1 and BA.2 form the
initial stack; BA.3 follows BA.2, BA.4 and BA.5 then run in parallel, and BA.6
closes the phase documentation. The six sprints plus three consolidated cleanup
layers landed on integrate/phase-ba at 9f5aef2fe (2026-09-12) through the
top PR #1414; the phase PR to develop is #1418 (draft until the
review-findings stack below lands). Post-mortem:
docs/postmortems/phase-ba-postmortem.md;
stack practice: docs/development/gh-stack-guidelines.md.
| Sprint | Status | Branch | Authoritative sprint doc |
|---|---|---|---|
BA.1 |
merged (into BA.2 stack) |
feature/ba1-ack-task-separation |
docs/plans/phase-ba/sprint-BA.1-ack-task-separation.md |
BA.2 |
merged (#1400) |
feature/ba2-task-identity-queue |
docs/plans/phase-ba/sprint-BA.2-task-identity-queue.md |
BA.3 |
merged (#1402) |
feature/ba3-nudge-invariant |
docs/plans/phase-ba/sprint-BA.3-nudge-invariant.md |
BA.4 |
merged (#1408) |
feature/ba4-atm-task-commands |
docs/plans/phase-ba/sprint-BA.4-atm-task-commands.md |
BA.5 |
merged (#1407) |
feature/ba5-queue-ephemeral-item |
docs/plans/phase-ba/sprint-BA.5-queue-ephemeral-item.md |
BA.6 |
merged (#1412) |
docs/ba6-task-nudge-documentation |
docs/plans/phase-ba/sprint-BA.6-docs.md |
| cleanup | merged (#1413, #1414, #1415) |
fix/phase-ba-cleanup, fix/phase-ba-cleanup-b, fix/phase-ba-merge-fix |
consolidated non-blocking findings, bounded blocking, BA.3 fixtures under merged tick order |
| review-findings | in progress (#1419 …) |
fix/phase-ba-review-1 → -2 → -3, docs/phase-ba-post-mortem |
phase-ending review, production readiness review, post-mortem — stacked above integrate/phase-ba |
60. Phase BB — Task Transitions You Can See [MERGED INTO INTEGRATE/PHASE-BB — PHASE-ENDING GATE AND READINESS REVIEW IN PROGRESS; DEVELOP PR PENDING]
Phase BB replaces the two task-family nudge kinds with six per-transition
kinds so every task transition is visible in the recipient's prompt line, and
adds atm task start for the assignee. Design authority:
docs/plans/nudge-transition-templates/design.md;
plan: the Phase BB plan. Base develop
at 281e6f546; integration branch integrate/phase-bb. All seven sprints
are merged into integrate/phase-bb: stack #1457 landed via #1474, with
follow-up fixes #1476, #1477 and #1479; BB.7 landed via #1470 and #1478. The
phase-ending gate and readiness review are in progress, and the develop PR is
pending. Wave 1 is BB.1, BB.2
and BB.3 in parallel; BB.4, BB.5 and BB.6 stack on BB.1 in that order; BB.7
closes the phase documentation after BB.6 and BB.2 merge. Triage seed:
PR #1431 (SMK-004, SMK-005, SMK-006). BB.7 D6 keeps this table current;
team-lead lands the final status when the phase PR merges.
| Sprint | Status | Branch | Authoritative sprint doc |
|---|---|---|---|
BB.1 |
merged (#1452) |
feature/bb1-transition-templates |
docs/plans/phase-bb/sprint-BB.1-transition-templates.md |
BB.2 |
merged (#1452) |
feature/bb2-orchestration-templates-1516 |
docs/plans/phase-bb/sprint-BB.2-orchestration-templates-1516.md |
BB.3 |
merged (#1468) |
feature/bb3-test-procedure-pages |
docs/plans/phase-bb/sprint-BB.3-test-procedure-pages.md |
BB.4 |
merged (#1452) |
feature/bb4-task-start |
docs/plans/phase-bb/sprint-BB.4-task-start.md |
BB.5 |
merged (#1452) |
feature/bb5-assignment-write-task-pass |
docs/plans/phase-bb/sprint-BB.5-assignment-write-task-pass.md |
BB.6 |
merged (#1470) |
feature/bb6-docs-prompt-handoffs |
docs/plans/phase-bb/sprint-BB.6-prompt-handoffs.md |
BB.7 |
merged (#1470, #1478) |
feature/bb7-docs |
docs/plans/phase-bb/sprint-BB.7-docs.md |
BB.8 |
complete (#1500, #1501) |
feature/bb8-2-colima-driver |
docs/plans/phase-bb/sprint-BB.8-colima-integration.md |
61. phase bc — immutable releases and observability consolidation [CRITICAL-REMEDIATION REVIEW ACTIVE — NOT COMPLETE]
phase bc has implementation evidence for the published sc-observability
1.4.1 family and the bounded typed/logging work. Critical-remediation review
is active and the phase is not complete pending QA and the separately
authorized bc.5 evidence. The authoritative plan is
the phase-bc plan. Its planning branch is
plan/phase-bc, its implementation integration branch is
integrate/phase-bc, and all new phase/sprint identifiers and document or
branch names use lowercase.
The implementation is one append-only gh stack, with the lowest-risk
dependency qualification at the bottom. Repository-setting activation is a
separate operational gate requiring explicit authorization. The old
sc-publish PR106-derived pin at 22137c2da13bf4638b4267b69c6c2f021617da73
is frozen historical evidence and is not a valid current u4 qualification.
The reconciled main revision f178b6919881c5a3d030d6343fcbb509f04806cc is
installed and qualified by PR #1571, so u4 is closed. The repository setting
is reported enabled by API, but bc.5 preflight and first-release evidence
remain pending.
The owner-approved sequencing amendment dated 2026-09-23 records that bc.4 local adoption proceeded before u2 and u3. u2 credential/setting activation was not passed as a bc.4 gate and belongs to separately authorized bc.5; u3's broad draft-first/tag-binding/concurrency/digest expansion was removed from the accepted sc-publish scope and is not claimed. This amendment does not close u2 or u3; u4 is closed by the current consumer qualification.
The sc-observability 1.4.1 republish is an independent priority lane:
upstream preparation is tracked by sc-observability
PR #197, with
cobs@sc-obs owning version/manifests/validation and the existing installed
shared workflow remaining the release base. PR #101 is not adopted for that
publication. Once upstream reports the family published and verified, bc.6 is
the next append-only ATM layer above the then-frozen top; it never waits for
bc.4 or the immutable-release gates. User authority states 1.4.1 is
code-compatible with 1.4.0 and exists solely to recover the npm publication
that failed because the 1.4.0 release was not immutable. bc.6 is therefore
limited to dependency metadata, lockfile, evidence, and current
version-reference changes unless verification finds a semantic code delta and
the plan is explicitly amended.
| sprint | status | branch | authoritative sprint doc |
|---|---|---|---|
bc.1 |
implemented; critical-remediation review active |
feature/bc1-sc-observability-1-4-0 |
docs/plans/phase-bc/sprint-bc.1-sc-observability-1.4.0.md |
bc.2 |
implemented; critical-remediation review active |
feature/bc2-typed-observability |
docs/plans/phase-bc/sprint-bc.2-typed-observability.md |
bc.3 |
implemented; critical-remediation review active |
feature/bc3-log-macro-qualification |
docs/plans/phase-bc/sprint-bc.3-log-macro-qualification.md |
bc.4 |
implemented; u4 closed; critical-remediation review active |
feature/bc4-sc-publish-immutable-consumer |
docs/plans/phase-bc/sprint-bc.4-sc-publish-immutable-consumer.md |
bc.5 |
not started; authorization-gated; preflight/evidence pending |
evidence/bc5-immutable-release-activation |
docs/plans/phase-bc/sprint-bc.5-immutable-release-activation.md; pending artifacts: docs/plans/phase-bc/bc.5-credential-preflight.md, docs/plans/phase-bc/bc.5-immutable-release-evidence.md |
bc.6 |
implemented; critical-remediation review active |
feature/bc6-sc-observability-1-4-1 |
docs/plans/phase-bc/sprint-bc.6-sc-observability-1.4.1.md |
bc.7 |
complete; benchmark + colima release validation evidence published |
evidence/bc-7-release-validation |
docs/plans/phase-bc/sprint-bc.7-release-validation.md |
The bc.2,
bc.3, and
bc.6 closure records remain
implementation evidence with critical-remediation review active. The bc.4
qualification receipt
contains the current u4 qualification at f178b6919; the bc.5 artifacts are
pending records, not closure evidence.
Rand's 2026-09-05 scope ruling keeps daemon-switch to two operator modes:
selecting a published release, or selecting a release build from an exactly
prerelease-tagged worktree for dogfooding. Temporary-launch, quiesce, and
signing behavior remain independently scoped; no daemon runtime work belongs
to this line.
| Sprint | Status | Branch | Worktree | Artifacts |
|---|---|---|---|---|
DAEMON-SWITCH-MODES-1 |
in progress |
fix/daemon-switch-release-and-tagged-modes |
../atm-core-worktrees/fix/daemon-switch-release-and-tagged-modes |
REQ-P-DAEMON-SWITCH-002, ADR-053 amendment, daemon-switch skill/tests |
Implementation Branches:
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
PI.1 |
complete |
feature/pPI-s1-validation-infra |
Justfile, .just/print_help.py, scripts/validate_release.py, scripts/verify_release_archive.py, scripts/release_artifacts.py, release/publish-artifacts.toml, release/RELEASE-NOTES-TEMPLATE.md, .github/workflows/release-preflight.yml, .github/workflows/release.yml |
PI.2 |
complete |
integrate/publish-release-readiness |
.claude/agents/publisher.md, docs/release-preflight-checklist.md |
PI.3 |
complete |
integrate/publish-release-readiness |
.claude/agents/publisher.md, docs/release-preflight-checklist.md, .claude/commands/preflight.md |
Authoritative sprint plan:
docs/plans/preflight-documentation/sprint-preflight.md
Implementation Branches:
| Sprint | Status | Branch | Artifacts |
|---|---|---|---|
PREFLIGHT |
complete |
docs/preflight-documentation |
docs/plans/preflight-documentation/sprint-preflight.md, docs/release-preflight-checklist.md, .claude/commands/preflight.md, .claude/agents/publisher.md |