Realign code with the 2026-07-31 findings-resolution rulings

The full bullet list from Implementation card bf080d9a — both ruling
batches, including the three appended mid-session by 16ef377:

- Restore subjects compose the inverse, never nest: crossing "Undo: S"
  emits "Redo: S" and vice versa; parity, not stack depth, reads a
  legacy double prefix (GitHistoryProvider.restoreSubject).
- Git-operation failures join the one-shot failure banner tier:
  BannerCenter.GitFailureBanner (undo/redo/branchSwitch/addGit), error
  tone at failure rank merged with write one-shots by recency; the
  postLoss compromise is retired at both AppModel wirings.
- order/schema optional below the board root: append-at-end reading
  (ordered siblings first, folder-name tie-break among the order-less),
  schema reads 1, both coerce-tier logged; the root keeps its
  requirements. Ranks.resolvedOrders materializes finite ranks so
  models and placement math stay untouched; first Writer rewrite
  stamps a real rank on touch, placement against an order-less sibling
  stamps that sibling inline in the same bracket. Agent guide v10
  teaches optional keys and zero-read filing. Hostile-YAML order
  shapes become coercion tests; Fixtures/Valid/optional-keys.kanban
  replaces the four retired Malformed boards.
- .gitignore is the relocation-heal noise gate: GitignoreRules pure
  matcher (standard semantics, board-root file only), loader consults
  it once per walk so matched loose files keep the stray posture;
  seeded (.DS_Store + .*.lanework-*) at board creation and template
  instantiation, healed in when missing at open — repo-nested
  included; empty file honored, existing files never edited; the
  committer's obedience via libgit2 status is pinned by test.
- Comments crash-residue sweep gates on step ownership: HistoryStep
  derives backing from its own undo expectations, backedContent unions
  both stacks, the sweep purges per-entry only what no live step owns.
- Skip-purge decoupled (16ef377): a stale-skipped coarse step strands
  whole in NativeHistoryProvider.strandedSteps — still backing, retired
  only at session end; clean exits purge as before.
- Coarse close step named "Changes to '<card>'"; the fine body-edit
  wording never leaks onto the board menu.
- Branch-switch settle clears every open card window's fine stack on
  Save All and Discard alike; the empty fold registers no coarse step.
- Close flush awaits its covering snapshot (quiesce + one generation
  bump, 1s bound), and an explicit flush now queues behind an
  in-flight one instead of skipping — the audit-caught interleaving
  could lose a close flush permanently when the debounce fired inside
  the close sequence; regression tests force both races.
- Commit comment bullets sort chronologically by created, not UUID.
- The production-unwired CardBodyEditSession.editSessionDidChange seam
  is deleted with its seam-only tests.
- Composition-root pins: beginSession composes the committer with the
  store's own EchoLedger and binds the announcer (the miswire class).
- Deliberate 06 conformance pass over every 2026-07-31-tagged
  sentence: fixed Change-custom-key subjects (the retired named
  generic was the only producer), the unbuilt Replace attachment
  vocabulary, heal commits now authored Lanework Integrity, the config
  reader scopes identity to plain [user] sections, add-git re-runs
  detection at create (a stale mode-none could initialize inside the
  user's repo), and add-git failures answer at the form or the banner.
  Structural residue filed on the Redesign board.

2554 tests / 439 suites green.

Claude-Session: https://claude.ai/code/session_01CqjXB7ASoWtbyoGod68k97
This commit is contained in:
2026-08-01 07:43:45 -04:00
parent 16ef3779e8
commit 274ccd9ff5
75 changed files with 5619 additions and 791 deletions
+53 -1
View File
@@ -370,7 +370,8 @@ public final class BoardStore: HealHost {
losses: banners.losses,
suspension: banners.historySuspension,
operations: banners.operations,
signposts: banners.signposts
signposts: banners.signposts,
gitFailures: banners.gitFailures
)
}
@@ -4055,10 +4056,60 @@ public final class BoardStore: HealHost {
}
}
// MARK: - The board's noise definition
/// Puts the seeded `.gitignore` on a board that has none, and does nothing at all to a board
/// that has one 06-history-undo.md Repository hygiene's whole scheduling ("a board missing
/// the file gains it by scheduled heal at open (the guide-refresh cadence)", re-ruled
/// 2026-07-31).
///
/// **`refreshAgentGuide()`'s twin, deliberately**, down to the shape of this method: the file is
/// a board-root courtesy the app owns, its defect is *presence* rather than anything a tree walk
/// could report, and the decision is one `lstat`. What differs is that there is no version to
/// compare and no displacement to make a name already held by anything at all is left exactly
/// as it stands (`BoardWriter.seedGitignoreIfAbsent`), including by a directory, because an
/// unreadable noise definition costs the board nothing but the exclusions it never had.
///
/// **Silent.** No banner row, on the guide's reasoning exactly: a courtesy file the user did not
/// create and may not know exists, whose absence changed nothing they can see. Only a genuine I/O
/// failure reaches the strip, through `performWrite`.
///
/// **The memo is armed before the attempt and cleared on success** (`HealScheduler`'s steps 4 and
/// 6), which is what makes a foreign deletion healable: the picture "missing" is restored by the
/// delete, and a standing memo would make that deletion the one thing this could not answer
/// while a failing write still gets exactly one attempt per changed picture rather than one per
/// reload. "Deletion is answered by re-seeding" is 06's own wording.
///
/// **It registers no undo step**, like every heal: nobody asked for it.
public func seedGitignore() {
let root = rootURL
// An empty signature is the engine's resting state and costs no bracket which matters here
// more than anywhere, because this heal runs at every open and reload tail of every board,
// and a bracket schedules a reload whether or not anything was written.
let signature: Set<String> = IntegrityRules
.node(at: root.appendingPathComponent(IntegrityRules.gitignoreFileName)) == nil
? ["gitignore:missing"]
: []
heals.run(.missingGitignore, signature: signature, on: self) { () throws(BoardWriteError) -> Void in
// The disk re-verify is the Writer's own: a file that appeared under us another window,
// an agent, a clone finishing makes this a no-op rather than an overwrite.
try BoardWriter.seedGitignoreIfAbsent(atBoardRoot: root)
}
}
/// **Every scheduled heal, in order** the engine's two seams call exactly this
/// (02-architecture.md Components HealScheduler: "fires uniformly at the reload tail and at
/// registry acquire, closing today's asymmetry where tombstone migration never fires at open").
///
/// **The `.gitignore` seed goes before the relocation, and that ordering is load-bearing in the
/// same way** (01-storage-format.md § Fractal layout Rules, ruled 2026-07-31): the seed *is*
/// the noise gate the relocation obeys, so a pass that relocated first would act, once, on a
/// board whose noise definition it was about to write. The window it closes is narrow by
/// construction the walk that produced this pass's work list ran before either heal, so the
/// seed's own patterns cannot filter it until the next load, and both of them name hidden files
/// the carve-out never touches anyway but the order costs nothing and states the dependency.
///
/// **The claimed-name displacement goes first, and that ordering is load-bearing**: a card's
/// migration mints `<root>/.trash/`, which cannot be created while a file or symlink holds that
/// name so a migration attempted ahead of the displacement fails *and arms its memo against an
@@ -4084,6 +4135,7 @@ public final class BoardStore: HealHost {
/// re-armed by the reload the others' writes produce, so none can see another's work half-done.
public func runScheduledHeals() {
displaceClaimedNames()
seedGitignore()
relocateLooseCardFiles()
migrateLegacyTombstones()
remintDuplicateIdentities()