Part of #963, stabilization epic #979, and roadmap #900. Stage 1 before #991 trusted publication and #992 atomic consumer activation.
Revised approach after contract review
Unaccepted prototypes #989 and #993 remain preserved and unmerged. The complete #993 review confirmed surviving falsey-history convenience paths, unnormalized stored episode lanes, and renderer chains lacking one immutable target. Stop further revisions of #993; rebuild a deliberately small pure core from accepted main in a fresh Codex-source PR, independently reviewed by qualified Claude.
Reuse schema fixtures and confirmed regressions, not prototype helpers or serial repair commits. Remove optional-context, generic evidence-composer, REST-history selector and environment-loading convenience APIs. Live accepted consumer behavior remains unchanged until #992.
Small explicit contract
- Target: immutable validated repo, positive non-boolean integer PR number, nonempty valid branch, full canonical SHA. Exact resolution never falls back. Identity-only resolution is a separate explicit API with no evidence argument.
- Episode: direct construction and mapping ingestion share validation/canonical stored values. Metadata-only target, lane/head binding and verified handoff/continuation shapes.
- Identity: one immutable canonical normalization of account/branch aliases, insertion-order-independent conflict refusal, longest prefix, declared policy-field preservation and canonical own-reviewer floor. No environment input or arbitrary opaque mutable configuration. Immutable branch binding preserves exact case separately from prefix-signal normalization.
- History and Authorities: explicit validated raw comments/pages; malformed present shapes/fields reject before normalization/trust. Genuine [], supported user:null and omitted optional body remain valid. Unavailable history is distinct from successful empty history. Marker authority is a separate explicit immutable account set, never inferred from identity authors.
- Chain: exact Target-bound empty or ordered nonempty chain from at most560 raw arrivals before deduplication, at most32 distinct contiguous episodes, one immutable repo/PR/branch, verified continuity and writer states. Parsing retains raw cumulative arrivals until one owning chain validator deduplicates; no composer resets the budget. Stale head waits and cannot admit.
- Resolve/parse/render/admit: one Chain factory owns raw-arrival validation/budget/deduplication; exact resolution uses that Chain's own Target with no raw-evidence overload or competing Target argument. One canonical full decision includes branch conflicts with zero episodes; strict announced complete unique-key/nonempty marker grammar; unrelated/untrusted comments confer no authority; rendering accepts only a validated nonempty Chain and never truncates; admission compares canonical reviewer/contributors and resolved decision.
One owning pure module plus standalone mirror is preferred. No store, environment, filesystem, network, provider, publisher or mutation dependencies. No legacy facade unless its explicit-input invariants exactly match. Keep the live tools/decisions.py adapter unchanged for #992.
Reviewable delivery and convergence
One fresh isolated Code Mower Codex writer from accepted main and one draft PR closing #990, Refs #963. Independent contributor-excluded Claude review must demonstrably read the entire exact diff/source. Target <=10 changed files and <=180,000 base-to-head diff bytes including tests, enforced before push; no automatic cap increase. A spec contradiction or scope overage stops before push for a decomposition decision. Use finite supervised source duration/output controls; Codex CLI has no native USD cap, so do not claim dollar enforcement. No hosted Devin create allowance.
Owning tests are unittest-native with isolated fixtures. Cover constructor/factory canonical equality, strict target versus explicit identity-only, aliases in both orders, zero-episode branch conflicts, valid recorded takeover/stale head, malformed and nullable raw history/pages, strict marker grammar/trust, common-target chain, full528+32 cumulative replay,561duplicate refusal before dedup and bounded consumption, renderer roundtrip/refusal, pure/transitive import boundary, mirror parity, and actual isolated init-materialized import/parse/resolve with package/repo source unavailable.
After clean Code Mower delivery: deterministic pure matrix, exact Ruff/privacy/package guard/readiness, canonical manifest regeneration equality, one exact CI-style full unittest discovery, one complete independent exact-head audit, full CI and authoritative gate, source quiescence/lease closeout. New broad design findings stop for assessment; no automatic repair loop. #990 accepts only the core; #963 remains open through #991/#992 and final consumer matrix. #915 still owns published-package pin/artifact qualification.
Part of #963, stabilization epic #979, and roadmap #900. Stage 1 before #991 trusted publication and #992 atomic consumer activation.
Revised approach after contract review
Unaccepted prototypes #989 and #993 remain preserved and unmerged. The complete #993 review confirmed surviving falsey-history convenience paths, unnormalized stored episode lanes, and renderer chains lacking one immutable target. Stop further revisions of #993; rebuild a deliberately small pure core from accepted main in a fresh Codex-source PR, independently reviewed by qualified Claude.
Reuse schema fixtures and confirmed regressions, not prototype helpers or serial repair commits. Remove optional-context, generic evidence-composer, REST-history selector and environment-loading convenience APIs. Live accepted consumer behavior remains unchanged until #992.
Small explicit contract
One owning pure module plus standalone mirror is preferred. No store, environment, filesystem, network, provider, publisher or mutation dependencies. No legacy facade unless its explicit-input invariants exactly match. Keep the live
tools/decisions.pyadapter unchanged for #992.Reviewable delivery and convergence
One fresh isolated Code Mower Codex writer from accepted main and one draft PR closing #990, Refs #963. Independent contributor-excluded Claude review must demonstrably read the entire exact diff/source. Target <=10 changed files and <=180,000 base-to-head diff bytes including tests, enforced before push; no automatic cap increase. A spec contradiction or scope overage stops before push for a decomposition decision. Use finite supervised source duration/output controls; Codex CLI has no native USD cap, so do not claim dollar enforcement. No hosted Devin create allowance.
Owning tests are unittest-native with isolated fixtures. Cover constructor/factory canonical equality, strict target versus explicit identity-only, aliases in both orders, zero-episode branch conflicts, valid recorded takeover/stale head, malformed and nullable raw history/pages, strict marker grammar/trust, common-target chain, full528+32 cumulative replay,561duplicate refusal before dedup and bounded consumption, renderer roundtrip/refusal, pure/transitive import boundary, mirror parity, and actual isolated init-materialized import/parse/resolve with package/repo source unavailable.
After clean Code Mower delivery: deterministic pure matrix, exact Ruff/privacy/package guard/readiness, canonical manifest regeneration equality, one exact CI-style full unittest discovery, one complete independent exact-head audit, full CI and authoritative gate, source quiescence/lease closeout. New broad design findings stop for assessment; no automatic repair loop. #990 accepts only the core; #963 remains open through #991/#992 and final consumer matrix. #915 still owns published-package pin/artifact qualification.