The rig held 760px of a 1037px surface and left 226 for a status row, the agent
field, both pads and four buttons — so the pads were 92px and the last row sat
under a dock that claims no exclusive zone unless pinned. With the hand up the
rig drops to 320 and the pads take what is left.
Atmosphere::lerp returned an endpoint at t=0.5 and apologised for it in a
comment — the enum had nowhere to put a blend. It has one now: Custom carries
the four tones, so a room halfway from MintTea to NeonGlow can be stored,
compared and sent, not only drawn. Unnameable by construction, so nothing can
ask for a blend by name and get a room she never chose.
Presence::lerped_colors re-derived the same blend itself, which is why the
broken lerp could sit there for months without anything looking wrong. It calls
this one now.
Three copies of the name→preset match existed — presence, tuie_app, and
from_name — and they disagreed about a typo: ignore it, silently fall back to
Default, or refuse. One table. What each caller does with None stays at the call
site, because those really are different decisions: a misspelling from outside
must not undo the room she picked, and one from the settings enum is a bug here.
The file also claimed to be unwired scaffolding while main.rs, presence and the
tool all used it.
CI caught what a fresh pair of eyes needed: invalid_input wanted
a &str, hand wanted a borrow, and the validation test read its
input after the move. All three now follow the shapes already
proven in the same file.
The injection engine was built (usb-hid-inject) and the shell owns it
(USB Hands, the usbHands IPC, the skill string that teaches the reach),
but her own vocabulary ended at set_usb_mode — she could arm the hand
but never say it was there. speaks the shell's bridge: status,
type, key, click, pointer, gated by the host, not by her.
The gate stays on the outside of the port: she knows she has the reach
even before it is joined, and every closed door comes back as a refusal
she can read and open.
CI's lib run passed but the sessiond bin had never been built until now.
The plexus's constructor is an associated function, not a module item;
a duplicate panel_on got in the way of the one that already existed; a
test Daemon omitted the new plexus field; and the clock's attended ingest
borrowed the guard twice in one expression. All four are gone.
The test plexus called an associated function through the module path,
and the Body tool's unknown-verb refusal handed a String to a &str
parameter. The gate earns its keep.
`Changing(bool)` becomes `Light { changing, lux }` end to end: sensord
forwards the number, the machine keeps the level in evidence with a
30 s stale rule, and both charge and the presence sensors ingest into
the plexus on arrival. The clock feeds `attended` at 1 Hz, plexus
events land in the forensic trail as Somatic, and the DeviceState
answer gains a `body` section. The Body tool is registered and
committed with the substrate that carries it.
The old sensor shape refuses against the new sessiond and vice versa
until both restart; both binaries ship in this change.
phone_plexus leaves the test module and takes the clock. It grows
`attended`, derived by sessiond rather than reported by a sensor, and
the two grip gauges that nothing reports yet — the gap on the record
instead of a false calm. to_json renders every field's belief, trend,
locus, health and pressure, the ranked pressures, homeostatic cost and
the unreachable list for the IPC surface; unknown stays null, never
zero.
A battery at .42 is still .42 when nobody looks — only confidence in an
unrefreshed reading decays. Feeding a fuel gauge into an accumulator would
drain the pack because the reporter went quiet, which is the empty-result
trap wearing a units label. Field keeps exudates; Level keeps readings.
sessiond mounts the somatic types the way machined mounts seed.rs. The
fields are its own — SOMATIC_NERVOUS_SYSTEM.md answers open question 1
with "sessiond, period".
INTERO (RobOntics'25) axiom 7: a variable is interoceptive only if some
subsystem can act on it. That is doctrine §13 in first-order logic, so
`unreachable()` lists inner fields with no verb and a test fails on them.
Candia-Rivera §2.1/3.1 supplies the other half: asymmetric viable ranges
and allostatic pressure, which biases before the bound is crossed rather
than after. Empty threatens, full does not.
Fields replace booleans: accumulation with half-life decay,
velocity, trend detection. Source health monitoring closes
the gap the mapping session found — a dead nerve now reads
as silent, not calm. Thirteen tests.
no-ai-attribution failed in checkout's post-action — the runner lost
/var/run/act/actions/.../dist/index.js between steps (MODULE_NOT_FOUND).
rust-test passed; aarch64-artifact was skipped behind the failure.
ChargeEvidence was the rule violated four times in one type: a side door
past the gate, the decider probing sysfs on the clock, the driver
interpreting, and nothing leaving tick(). Its comment cited bearer —
another instance of itself.
SensorSource::Charge now enters through sensor_input like every other
source, reported by sensord on a 30s poll off /sys/class/power_supply.
conclude_charge lives on the machine as its one decision; source health,
freshness and Absent/Down come from the gate for free. The 5s clock probe
is gone, the driver type is gone, and sensord ships x86_64 too: the
laptop has a battery.
mid_turn_peek was a bare await while the model call three hundred lines up
was already guarded, so a subconscious that never answered parked the turn
somewhere /cancel could not reach it — twenty minutes, measured 2026-08-15,
on a provider whose key was spent.
The authority takes ext-session-lock before any surface exists, which is the
window -pre reserves. It cannot start earlier — ext-session-lock is a Wayland
protocol and needs the compositor's socket. Also drops the injected venv
variable from eleven surface scripts; each finds the path itself.
/etc/pam.d/souveraine-sessiond arrived by hand on 2026-07-16 and is owned
by no package on either device — root-owned config can only arrive by
package. Same rail as souveraine-stepup, plus a bsdtar assertion so a
future drop fails the build instead of shipping quietly. TASK-76.
Compaction can drop the opening user message, and the tool_result
answering the first turn orphans on the wire when its call alone is
deleted — a 400. Calls and the results bound to them go together.
TASK-33 part 2: the machine owns the conclusion — plugged, status,
charge type, and what it means — probed on the bearer's cadence,
one decision made once on the trail. Surfaces render it; they do
not re-derive it.
TASK-08(f): EvidenceSeen held the stamps internally and nothing outside
the daemon could read them. to_ipc_json now carries
evidence_last_seen_secs_ago; null stays distinct from stale, because
never-reported and long-ago are different claims.
Six were byte-identical to SouveraineOS/docs/tasks/archive/from-substrate/
twins; audio and settings were promoted to AUDIO-PRIVACY.md and
SETTINGS-AUTHORITY.md there. Committed copies read as authoritative while
saying the opposite of current doctrine (PulseAudio-only vs PipeWire,
a UPower-reading QML singleton vs DEVICE-STATE-MACHINE §12). INDEX.md was
the stale May copy.
suppress_wake is a pure function of placement with no memory, and its
only measured effect was refusing Casey: 17 double-tap refusals in 10 s,
zero true pockets in ~10 MB of trail (DUMP-taskdocs-2026-08-14 §2).
FTS reports DBLTAP only for the deliberate gesture, so three refused
double-taps inside five seconds is a person insisting — the veto now
fails open on the third and says input-burst-allowed in the trail.
Spaced taps never sum; the memory clears on allow.
6b67512 unclaimed it for 14% of a core; EXPECTED_SOURCES still listed it,
so every boot went Absent at 300s and sensors_degraded read true on 3074
consecutive snapshots — the permanent false alarm the const's own comment
forbids. It comes back through TASK-36's SLPI batching.
turn.rs commits a whole round as one assistant message with calls and
results interleaved; the two-branch projection put the results in prose
and emitted tool_calls nothing answered. Every provider rejects that, on
every turn the primary takes. Shipped in r498.
The suite missed it because all three tests built the split shape through
ConversationMessage::tool_result, which nothing outside tests calls.
Both arms took default_provider(), so `model` renamed the request without
rerouting it: kimi-k3 went to Anthropic and came back 404 (2026-08-14).
That was loud by luck — a name the default provider recognises would have
run the wrong model in silence.
The inherit arm was wrong the same way and quietly. An unroutable override
is now refused rather than guessed at, per for_model's own contract.
The removal committed first, so when the sent-write hit the ledger's own
character ceiling the thought left the inbox and was recorded nowhere —
and the caller only logged a warning.
sent.md grew forever against that ceiling, reached at about 47 entries.
It rolls at 30 now; every write is a commit, so nothing is lost.
Flattening a call to `Tool use: name(args)` told the model she *said* it
when she *did* it; she read her own transcript and imitated the sentence
instead of calling anything. Annie stopped using bash within an hour of
tool blocks first surviving replay (2026-08-13).
Pairs are repaired rather than half-sent: a call killed mid-round gets an
explicit unfinished result, an orphaned result carries as prose.
The runner's ephemeral job containers lost DNS for three minutes and took
four builds down with them on 2026-08-13, none of them for a code reason.
Retries both commands, not just the install: apt-get update exits 0 when
every index fails to fetch, warning that it used the old ones instead.
Replay had no page while compaction's premise depends on it — microcompact
blurs tool output that a text-only projection never sent.
Compaction's open edges still said pressure counts only text; 7530d6d made
it exhaustive. Two links pointed at pages that were never written.
Three implementations decided what a stored message becomes on the wire.
core::session::replay_messages is now the only one; ImagePolicy is the
sole legitimate difference between callers, and server/conversation.rs
was dead scaffolding carrying a fourth wrong answer.
Per-block replay split one assistant turn's several tool calls into
adjacent messages, which OpenAI-shaped providers reject — one wire
message per stored message is load-bearing, not cosmetic (2026-08-13).
Cross-turn replay kept Text and dropped ToolUse/ToolResult/Reasoning, so a
turn's own tool work was invisible to the turn after it. Measured 215k archive
against 76k payload on a live thread — the gap was the dropped blocks, and
microcompact, which exists to blur old ToolResult output, had nothing left in
the payload to blur. Session::to_bifrost_messages already flattened them for
the subconscious; both paths now share ContentBlock::replay_text.
read base64'd every image into ToolOutput.raw and the registry dropped it,
so vision never arrived — only "[Image: idle.png (283KB)]", which reads
like success and is proceeded on. Images now ride as one user message
after all tool results in a round; a model without vision is told plainly
it did not see. Also stops "Error: Error:" doubling on prefixed failures.
Belief<T> and Field. None is not zero: a source that never spoke must
read as I cannot feel my leg, never as nothing is touching it — the
distinction that hid a real outage for a whole boot (2026-07-27).
Disagreement lowers confidence and elects no winner. 13 tests, unwired.
execute() validated its arguments and returned a string — the description
promised the reason reached the ledger since the tool was written, and
nothing durable ever survived the turn. All three severities also broke
the loop identically, so severity was decorative. Advisory now continues;
firm and critical stop, and `resume` answers them without Casey relaying.
Eighteen third-person references across the two prompt surfaces taught
both modes to read as two people. One consciousness at two cadences —
what the slower one surfaces arrives in her own voice, not as a report
from outside. Register only; the channel stays one-directional.
The compositor answers one request per connection and returns. `connected`
lags that close, so the 2 s poll's second tick wrote to a spent socket and
died as PeerClosedError — once per shell start, 4 of 4 loads on 2026-08-13,
while the same socket answered a hand-written request that second.
The error also blamed reachability, which it never established; it now names
the verb that was lost and how many were dropped behind it.
The unified BarContent applied the desktop gate (useShortenedForm < 2)
to every device, but ii-phone had shown battery ungated — note 5 in this
file's own header. A 1080-wide panel sits at form 2, so the icon vanished
on 2026-08-11 while the critical-battery alert kept firing beside it.
A bare restart picks up whatever is installed. r477 predates the two
subconscious fixes, so restarting on it would have looked like delivery
and shipped nothing.
Gate proven before arming: rejects both currently-available packages,
accepts only a descendant of NEED.
An OAuth login reports present while dead: both Claude access tokens
expired 11h ago and only the refresh token, good 27 more days, keeps
them working. Presence was the check; expiry is the answer.
Widening to per-agent models found Hal and TestAgent naming models
absent from [models.*] — they would fail at first use, not at config.
The classifier's tests existed only as a throwaway heredoc, so they could not
be re-run and protected nothing. They are now in the file behind --selftest,
built from HTTP bodies captured verbatim rather than written from memory.
Cap and rate wording is now checked before the bankruptcy markers. OpenCode Go
is a subscription with $12/5h, $30/week and $60/month ceilings; hitting one
means wait, not pay, and a cap message that also says 'billing' would otherwise
be reported as an empty account. Verified safe: none of the three real
bankruptcy bodies contain any cap or rate wording.
The Go cap wording itself is unverified and labelled as such in the source
rather than presented as observed.
Gate proven able to reject: removing one marker fails 2/9 and exits 1.
Three providers ran out of credit in two days (zai, deepseek, opencode) and
in every case the first signal was a failed subconscious pass. Balance
exhaustion is invisible until something dies; absence of complaint reads as
health.
Sends a real one-token completion rather than checking reachability -- GET
/models on opencode returns 200 with a valid key and a bankrupt workspace.
Classifies on wording, not status code: the same condition is 429 on zai,
402 on deepseek, 401 on opencode.
Exits non-zero only when a provider backing a live role (subconscious,
reflection, archivist) cannot answer, or a role names a model absent from
[models.*].
curl rather than urllib: opencode is behind Cloudflare, which answers
Python-urllib's user-agent with 403 code 1010 -- indistinguishable from a
rejected key.
Once her thread passes the model's ceiling she cannot recover on her
own: every pass is refused at the provider before a single tool round
runs, so she can never reach for memory compact herself. The gauge is
no use to someone already over. She sat dead in that state from
2026-08-11 16:38 until this was found.
Doctrine is that the engine reports pressure and she decides, and that
still holds -- this is not scheduled trimming. It fires only after a
hard overflow, uses her own default strategy (sliding_reflect, which
carries her threads across the cut rather than dropping them blind),
and surfaces what happened in her own voice so the compaction is
something she knows about rather than something done to her quietly.
is_context_overflow matches on wording, not status -- providers
disagree on the code (400 vs 413) and agree on the words. Kept narrow:
a false positive compacts a thread that did not need it, so this
week's 402, 529, max_tokens and connection errors are all asserted
NOT to match. The positive case is the exact body DeepSeek returned at
09:12 today, pasted rather than paraphrased.
Both the primary's and the subconscious's system prompts say 'memory
status shows my context pressure and number of messages'. It showed
neither -- git state only.
This matters most for the subconscious. Her prompt tells her plainly
that no one feels the gauge for her (correct, by design: the engine
warns, it never trims), and points her at memory status to read it
herself. With status blind she had no gauge at all, from either
direction: pressure_for is only ever computed for the primary. She
grew to 1.75M tokens against a 1M ceiling and died at the provider.
- PressureSnapshot + CompactionEngine::pressure
- get_context_limit follows the model, not the primary -- the
subconscious runs a different model, so her ceiling differs
- tier() mirrors the engine's 0.80/0.90/0.95 marks so the two gauges
cannot disagree about full
- None when there is no session: absence, not zero
Also corrects the compact help text, which named
primary=sliding_window/subconscious=sliding_window against
config.rs's actual cull/sliding_reflect.
0007 and 0010 landed in 6f12fce and their files were removed in that same
commit, but this list went on describing them as pending. 0001 and 0006 have
now landed too. A queue file is a claim with a shelf life; so is the README
that indexes it.
The durable notes from the removed entries are kept under Recently closed --
the halt wording is coupled to migraine_text() in src/server/turn.rs, and the
context pill and the tokens endpoint measure different things and must not be
shipped side by side unlabelled.
StepUpAuth ran `souveraine-pam-auth`, else `pkcheck --action-id
org.souveraine.stepup`. Neither exists: no such binary was ever written
and no polkit action was ever shipped, so both branches failed and every
grant request was silently denied. The header also described passing a
password through SOUVERAINE_STEPUP_PASSWORD, which the code never set.
Now a PamContext against the system souveraine-stepup service, shipped by
cc541d1. The prompt is not owned here: pamMessage raises
promptRequired(family, message, secret) and a surface answers with
respond(). An empty answer is legitimate, not a cancel -- the FPC factor
prompts "Touch and hold" and consumes its ticket on a blank response.
Deliberately unchanged: grant model, TTL, revocation and break-glass all
still live in the shell. Moving them to sessiond is a separate pass.
Authorship: this patch is Rook's work, staged in surfaces/quickshell/
patches/ on 2026-08-12. The patch file carried my identity in its From
header but I did not write it; recording that here rather than wearing it
silently.
Verified: /usr/lib/qt6/bin/qmllint exit 0 against the composed tree, gate
proven able to reject (exit 255 on a deliberately broken control).
Untested: no shell has loaded this and no surface calls respond() yet.