Skip to content

docs: define intent verification runtime - #174

Merged
joshcramer merged 9 commits into
mainfrom
docs/dd-078-intent-verification
Jul 30, 2026
Merged

docs: define intent verification runtime#174
joshcramer merged 9 commits into
mainfrom
docs/dd-078-intent-verification

Conversation

@larimonious

@larimonious larimonious commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add DD-078, defining a truthful Intent Verification Runtime, the pure-NTNT project-testing target, and the v0.6.0-and-later verification track
  • add a dependency-aware, test-first implementation plan covering the evidence ledger, project policy, runtime authority, typed .tnt cases, fixtures, stateful HTTP, managed resources, PostgreSQL, eventual/concurrent behavior, browser verification, project/provenance checks, typed project environments, and external evidence
  • add an immutable Larrimon audit appendix with repository/commit, path/range/line/blob inventory, canonical digests, retained-asset classifications, and regeneration gates
  • define incremental Larrimon parity/deletion gates through zero project-owned Bash/Python support and zero compensating browser/SQL test harnesses
  • mark the execution ordering in ial_vision_v2.md as superseded while preserving its historical term-rewriting and Studio direction

Key decisions

  • .intent states durable obligations but receives no execution authority
  • .tnt is the project-owned executable verification language
  • DD-078 is project-neutral: Tracks A–F and every public contract use generalized fixtures; Larrimon is a separate reference-adoption pressure corpus and cannot define runtime names, schemas, defaults, policies, or privileged modes
  • ntnt.toml requests resources and capabilities; an operator launcher outside repository-controlled execution grants/clamps privileged authority
  • authoring = "pure-ntnt" classifies files and executable declarations; inline workflow/package/Compose/Docker scripts, gitlinks/nested repositories, generated helpers, omissions, overlaps, and relabeled wrappers fail planning
  • host policy and protected contracts use separate closed PolicyTrustedInputV1/ProtectedContractTrustedInputV1 JCS envelopes over the same inherited-handle loader; each domain signs the exact raw-payload digest before parsing
  • planning, execution, and reporting consume one immutable content-addressed input snapshot
  • the Larrimon pressure audit is pinned to repository commit ceadfd992d1435ac27afb054968ff5569d697ce1 with canonical path/range/blob inventory digests
  • runtime authority is concrete and resource-scoped: semantic EffectKind metadata never substitutes for supervisor-minted VerificationGrants
  • DD-077 candidate f0132afcff984bb43305be39122d7e74a6850396 is explicitly unmerged/not ancestral; dependent slices use its real PR 0A, Design spike 0B, PRs 2C–2E, and PRs 1B–1C identifiers and cannot start until exact merge commits are recorded
  • the generalized prerequisite ledger also pins DD-047's design source and blocks 18B on its unimplemented Slice 1C/PR 2; production agent/tool execution is excluded because this baseline has no DD-065 design/owner artifact
  • DD-078 Slices 10P/10B own the missing internal runtime observation/clock seam; no temporary callback, provider, network, or migration fallback is allowed
  • one evidence ledger drives human, JSON, JUnit, coverage, and exit status
  • implementation, executability, and verified coverage remain separate
  • unsupported, skipped, stale, blocked, flaky, zero-evidence, and cleanup-failed work cannot masquerade as pass
  • no unrestricted shell or inline Intent SQL
  • executable resources are explicitly mediated, sandboxed, or trusted-uncontained; protected PR lanes require enforceable containment
  • strict cleanup uses a host-pinned durable reserve → create → finalize → expose broker protocol; unsupported crash windows are non-verifying, and reconciliation never falls back to broad labels/prefix/PID scans
  • strict/protected Redis uses that disposable brokered lifecycle and can claim zero residual state only after completed cleanup/reconciliation; attached ACL mode is non-verifying
  • typed ntnt project env plus root-bound CAS/locks/leases replaces dev/staging scripts; OCI ingress binds listener/container/endpoint/generation and authenticates the exact target before forwarding application bytes, rather than trusting names, aliases, cached IPs, placeholder sockets, or a user lock as a daemon mutex
  • golden update mode emits a snapshot-bound private candidate and patch only; ntnt never overwrites the committed target, and human/VCS apply plus fresh verification are mandatory
  • provider transport is frozen only after a cross-platform adversarial framing spike
  • migration scripts survive until the landed production runner and a complete legacy/upgrade/failure matrix pass
  • external browser/database/OCI/protocol systems remain typed, pinned, bounded providers
  • old-to-new deletion gates require semantic mutation/fault witnesses, not only case or line-count parity
  • DD-077 owns reusable callback, network-policy/transport, and migration primitives; DD-078 consumes rather than duplicates them
  • process, provider, browser, streaming, and HA/recovery APIs each wait for explicit adversarial feasibility spikes; future KMS, load, backup, and topology mechanisms have dependency-closed owners
  • every slice has one explicit owner with exact dependency-cell parity, independent files/RED-GREEN/gate scope, explicit Rust parent-module registration/creator dependency closure, generalized external/task-owner validation, and mechanically checked release closure including Larrimon/16M

Larrimon target

The plan maps the seven pinned Intent files and immutable replacement estate—14 shell files, 11 Python files, 2 JavaScript/MJS test programs, and 3 SQL-only test inputs totaling 4,549 lines—into explicit native destinations and dependency-closed ntnt slices. It then extends the proving surface for signup/egress/KMS, monitoring and streaming protocols, durable jobs, multi-node protocol fixtures, AI/provider behavior, alerting, retention, upgrades, restore, HA, and private/on-prem profiles. Production agent/tool effect transcripts remain outside DD-078 pending a real DD-065 contract.

The final project target is one canonical command:

ntnt intent check . --profile full

Scope

Documentation, immutable baseline evidence, and one mechanical plan-DAG test only. This PR changes no runtime behavior.

Validation

  • independently reviewed architecture/dependency baseline: 7ed409c68c17179c742a9edfab0ab860a958916b (patch SHA-256 9631ebe3ff3b4fddca83c102905c91469b90b5c79200eb43b693b3fa57636534)
  • latest follow-ups: 8bb722c453c84124761bf89d990ba92a1a3853b2 generalized the adoption model and repaired both Greptile inline findings; 9bc9c54971e3d5740dc7c54103c1c48a6e1da464 closed the multi-create-block maintenance note; eb87c589237465b4f9273d3e10a47ef62e28a3e7 moved all Larrimon Waves A–E, Slice 16M, deletion authority, release milestones, and completion criteria into a mechanically non-gating standalone consumer plan; 75bd032919e0a8e225b2c67f58b3995b6f740fd6 requires release groups to cover every core slice; 5692abb8df6db00e9ecedcc8dbaa71ad36e3b763 snapshot-locks high-risk scope and deletion sections; 92d35c952f07f7b401c53ce7bb6e6f246179665b normalizes and explicitly exercises snapshot checks across LF/CRLF checkouts; d689279ee63bd52f8831653efdab4db64620d0db SHA-256-locks all three complete normative document envelopes and rejects outside-section scope/deletion bypasses
  • independent architecture/security review — PASS, 0 blockers/majors
  • independent dependency/completeness review — PASS after repairing and regression-testing Slice 13B's transitive parent-module creator dependency
  • cargo nextest run — 1,962 passed, 0 skipped
  • cargo test --doc — passed (0 doctests)
  • cargo fmt --check — passed
  • cargo test --test dd078_plan_tests — 2 passed, including representative negative drift mutations
  • staged diff whitespace check — passed
  • local Markdown fence/link and embedded TOML parse checks — passed
  • immutable Larrimon extension, SQL-only test, and Intent path/line/blob inventory digests regenerated from ceadfd992d1435ac27afb054968ff5569d697ce1 — matched

cargo clippy --all-targets -- -D warnings is already red on unchanged build.rs under Rust 1.94: one collapsible_if and two manual_strip lints. The plan records this as a baseline preflight to repair separately or resolve through an explicit supported-toolchain pin before Task 1.

Comment thread tests/dd078_plan_tests.rs
Comment thread tests/dd078_plan_tests.rs
@greptile-apps

greptile-apps Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Greptile Summary

This PR adds the DD-078 Intent Verification Runtime design document, a dependency-closed implementation plan, a separate Larrimon consumer adoption plan, and the mechanical dd078_plan_tests.rs test suite that enforces DAG consistency, owner coverage, module-registration hygiene, spike constraints, release closure, and SHA-256 snapshot/envelope integrity. No runtime behavior changes.

  • Design + plans introduce the pure-NTNT project-testing target, typed .tnt cases, the evidence ledger, capability/resource model, and an immutable Larrimon audit appendix pinned to a specific repository commit.
  • Test harness (tests/dd078_plan_tests.rs) mechanically validates the implementation plan: slice-table parsing, cycle detection, owner uniqueness, creator-dependency closure, external-prerequisite ledger, release-group coverage, spike artifact-only constraints, and adoption-boundary isolation — all locked by SHA-256 digest fixtures that also survive CRLF checkouts.
  • Supersession note added to ial_vision_v2.md marks the legacy UI-first delivery order as historical while preserving glossary and Studio direction.

Confidence Score: 5/5

Documentation-only PR; no runtime behaviour changes. The mechanical test harness enforces all structural invariants and is itself covered by representative negative-drift mutations.

All changed files are documentation, plans, SHA-256 fixture locks, and the test harness that validates those documents. The two previous inline findings (reversed-range error, spike section boundary) are confirmed fixed in the current HEAD with regression coverage. The digest-locking scheme correctly normalises line endings before hashing, and the CRLF round-trip test exercises that path. No logic paths introduce data mutation or security-sensitive operations.

Files Needing Attention: No files require special attention.

Important Files Changed

Filename Overview
tests/dd078_plan_tests.rs 958-line mechanical validator: parses the slice DAG table, checks cycle-freeness, owner uniqueness, module-registration creator-dependency closure, external-prerequisite ledger, release-group exhaustiveness, spike artifact-only constraints, and SHA-256 snapshot/envelope integrity over both LF and CRLF checkouts. Previous findings are fixed with regression coverage.
plans/dd-078-intent-verification-implementation.md Core implementation plan locked by SHA-256 fixture; defines the full slice DAG, release groupings, external prerequisite ledger, and definition of done.
plans/dd-078-larrimon-adoption.md Standalone consumer adoption plan locked by SHA-256; kept explicitly outside the core DD-078 DAG, release sequence, and definition of done.
design-docs/dd-078-intent-verification-runtime.md Core design document locked by SHA-256; defines obligation truth model, evidence ledger, capability/resource model, provider model, acceptance criteria, and open questions.
tests/fixtures/dd078/core-plan.sha256 SHA-256 digest fixture locking the core implementation plan against unauthorized drift.
design-docs/README.md Adds dd-078 entry and updates ial_vision_v2.md status to Superseded in part.
design-docs/ial_vision_v2.md Adds supersession note pointing to DD-078 for execution roadmap; historical content preserved.

Reviews (9): Last reviewed commit: "test: lock complete DD-078 normative env..." | Re-trigger Greptile

@larimonious

Copy link
Copy Markdown
Contributor Author

Addressed the final Greptile maintenance note in 9bc9c54971e3d5740dc7c54103c1c48a6e1da464: module-registration validation now iterates every **Create** block in each owner section rather than stopping after the first. Added a regression that injects a second late create block after RED/GREEN and verifies the missing parent registration is rejected. cargo fmt --check, cargo test --test dd078_plan_tests, and git diff --check pass.

@larimonious

Copy link
Copy Markdown
Contributor Author

Addressed Greptile’s release-coverage finding in 75bd032919e0a8e225b2c67f58b3995b6f740fd6. After validating each release group’s dependency closure, the validator now requires the union of all groups to equal the complete core slice graph. A regression adds a fully owned synthetic Slice 21 to the authoritative table without assigning it to a release and verifies the exact unreleased-slice diagnostic. Focused plan tests, formatting, and diff checks pass.

@larimonious

Copy link
Copy Markdown
Contributor Author

Closed the independent adversarial-review major in 5692abb8df6db00e9ecedcc8dbaa71ad36e3b763. The validator now byte-locks four reviewed safety sections through explicit snapshot fixtures: core acceptance criteria, core definition of done, the complete Larrimon Slice 16M migration/deletion contract, and the complete Larrimon consumer definition of done. Section headings/terminators must also occur exactly once. Negative probes now reproduce the reviewer’s attacks—adding Larrimon Wave E to core completion, weakening the migration matrix to convenient examples, and collapsing consumer completion to a declaration—plus a core-acceptance leak; every mutation is rejected with the relevant snapshot diagnostic. Full local nextest remains 1,962/1,962 with doctests passing.

@larimonious

Copy link
Copy Markdown
Contributor Author

Closed the second adversarial-review major in d689279ee63bd52f8831653efdab4db64620d0db. In addition to the four exact high-risk section snapshots, the validator now SHA-256-locks the complete canonical-LF bytes of the core design, core implementation plan, and standalone Larrimon adoption plan. Equivalent scope or deletion-authority weakening anywhere in those normative envelopes therefore requires an explicit digest-fixture update in the same review. Negative probes reproduce both reported outside-section bypasses: a Wave E core-completion gate immediately before core DoD and premature owner-8 deletion authority immediately before Slice 16M; both are rejected. LF/CRLF normalization remains covered. Full local nextest: 1,962/1,962; doctests pass.

@larimonious

Copy link
Copy Markdown
Contributor Author

Fresh immutable cold review of d689279ee63bd52f8831653efdab4db64620d0db: PASS, 0 blockers/majors. The reviewer independently reproduced both prior outside-section bypasses under LF and CRLF representations; both were rejected. Complete canonical-LF SHA-256 locks cover all three normative documents, and focused plan tests passed 2/2. Worktree remained clean.

@joshcramer
joshcramer merged commit 851dbe7 into main Jul 30, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants