Specs
September 15, 2026 · View on GitHub
Specs define externally meaningful behavior for ripr. They are the source of
truth for the spec-test-code traceability loop.
Use specs for behavior that users, integrations, or future agents need to rely on. Keep implementation details in architecture docs or ADRs unless they affect observable behavior.
A spec status records normative disposition only. It does not establish implementation, proof, support, or live-work state; those are represented by implementation claims and PR-local slices, traceability and evidence, support authorities, and GitHub/worktree state. A spec remains valid until it is explicitly corrected, rejected, superseded, or deprecated.
Index
| Spec | Status | Topic |
|---|---|---|
| RIPR-SPEC-0001 | accepted | Static exposure loop |
| RIPR-SPEC-0002 | accepted | Fixture laboratory |
| RIPR-SPEC-0003 | planned | Agent context packet |
| RIPR-SPEC-0004 | planned | Test efficiency and vacuity signals |
| RIPR-SPEC-0005 | proposed | Repo seam inventory and test grip |
| RIPR-SPEC-0006 | proposed | Mutation calibration reports |
| RIPR-SPEC-0007 | proposed | Repository configuration |
| RIPR-SPEC-0008 | proposed | SARIF and CI policy |
| RIPR-SPEC-0009 | proposed | Defaults-first adoption |
| RIPR-SPEC-0010 | proposed | Agent working-set brief |
| RIPR-SPEC-0011 | proposed | LLM work loop |
| RIPR-SPEC-0012 | proposed | PR test guidance annotations |
| RIPR-SPEC-0013 | proposed | Recommendation calibration report |
| RIPR-SPEC-0014 | proposed | Calibrated gate policy |
| RIPR-SPEC-0015 | proposed | Evidence health baseline |
| RIPR-SPEC-0016 | proposed | Baseline debt delta |
| RIPR-SPEC-0017 | proposed | RIPR Zero reporting |
| RIPR-SPEC-0018 | proposed | PR evidence ledger |
| RIPR-SPEC-0019 | proposed | Test-oracle assistant loop |
| RIPR-SPEC-0020 | proposed | First useful action report |
| RIPR-SPEC-0021 | proposed | Evidence record |
| RIPR-SPEC-0022 | proposed | Assistant loop health report |
| RIPR-SPEC-0023 | proposed | PR review front panel report |
| RIPR-SPEC-0024 | proposed | Report packet index |
| RIPR-SPEC-0025 | proposed | PR inline comment publisher |
| RIPR-SPEC-0026 | accepted | Language adapter contract |
| RIPR-SPEC-0027 | accepted | TypeScript preview static facts |
| RIPR-SPEC-0028 | proposed | Python preview static facts |
| RIPR-SPEC-0029 | proposed | Policy readiness report |
| RIPR-SPEC-0030 | proposed | Preview evidence policy boundary |
| RIPR-SPEC-0031 | proposed | Lane 1 evidence quality audit |
| RIPR-SPEC-0032 | proposed | Lane 1 evidence quality failure fixtures |
| RIPR-SPEC-0033 | proposed | Match-arm canonical gap discriminators |
| RIPR-SPEC-0034 | proposed | Evidence quality scorecard |
| RIPR-SPEC-0035 | proposed | Evidence quality benchmark corpus |
| RIPR-SPEC-0036 | proposed | Editor preview routing |
| RIPR-SPEC-0037 | proposed | Editor preview static-limit projection |
| RIPR-SPEC-0038 | proposed | Generated PR CI review workflow |
| RIPR-SPEC-0039 | proposed | Policy operations report |
| RIPR-SPEC-0040 | proposed | Static/runtime confidence expansion |
| RIPR-SPEC-0041 | proposed | Policy history ledger |
| RIPR-SPEC-0042 | proposed | Policy promotion packets |
| RIPR-SPEC-0043 | proposed | Presentation text evidence |
| RIPR-SPEC-0044 | proposed | Preview evidence promotion packet |
| RIPR-SPEC-0045 | proposed | Finding-to-gap alignment |
| RIPR-SPEC-0046 | proposed | Gap decision ledger |
| RIPR-SPEC-0047 | accepted | Editor gap projection |
| RIPR-SPEC-0048 | proposed | Config and policy constant evidence |
| RIPR-SPEC-0049 | accepted | Editor setup status |
| RIPR-SPEC-0050 | accepted | Editor first repair loop |
| RIPR-SPEC-0051 | accepted | First successful PR UX |
| RIPR-SPEC-0052 | accepted | Editor first-pr packet projection |
| RIPR-SPEC-0053 | accepted | Start-here surface convergence |
| RIPR-SPEC-0054 | accepted | Editor adoption assurance |
| RIPR-SPEC-0055 | accepted | Editor actionable gap queue |
| RIPR-SPEC-0056 | accepted | Public actionable projection |
| RIPR-SPEC-0057 | accepted | RIPR swarm repair loop |
| RIPR-SPEC-0058 | accepted | RIPR swarm external agent handoff |
| RIPR-SPEC-0059 | accepted | Actionable surface translation |
| RIPR-SPEC-0060 | accepted | Source-of-truth stack |
| RIPR-SPEC-0061 | proposed | Lane 1 canonical actionability contract |
| RIPR-SPEC-0062 | proposed | Cross-language oracle graph |
| RIPR-SPEC-0063 | proposed | Cross-language evidence router UX |
| RIPR-SPEC-0064 | proposed | Perl fact packet contract |
| RIPR-SPEC-0065 | proposed | Evidence-to-repair use-case roadmap |
| RIPR-SPEC-0066 | proposed | Repo badge use case |
| RIPR-SPEC-0067 | proposed | PR gate use case |
| RIPR-SPEC-0068 | accepted | PR review-card use case |
| RIPR-SPEC-0069 | proposed | LSP agent feedback use case |
| RIPR-SPEC-0070 | proposed | Downstream review consumer use case |
| RIPR-SPEC-0071 | proposed | TypeScript/Bun evidence use case |
| RIPR-SPEC-0072 | proposed | Large-repo diff-first use case |
| RIPR-SPEC-0073 | proposed | Receipts, outcomes, and route quality use case |
| RIPR-SPEC-0074 | proposed | Repo exposure run status |
| RIPR-SPEC-0075 | proposed | PR evidence summary |
| RIPR-SPEC-0076 | accepted | LSP diagnostics severity policy |
| RIPR-SPEC-0077 | proposed | LSP repair packet command |
| RIPR-SPEC-0078 | proposed | LSP top-limitation command |
| RIPR-SPEC-0079 | proposed | Canonical receipt command contract |
| RIPR-SPEC-0080 | proposed | Route-quality standalone report |
| RIPR-SPEC-0081 | proposed | LSP receipt-status command |
| RIPR-SPEC-0082 | proposed | Preview-language disclosure |
| RIPR-SPEC-0083 | proposed | Check no-scope disclosure |
| RIPR-SPEC-0084 | proposed | Default base resolution |
| RIPR-SPEC-0085 | proposed | TypeScript evidence adapter contract |
| RIPR-SPEC-0086 | accepted | Python Tier A eval sweep |
| RIPR-SPEC-0087 | proposed | TypeScript preview→actionable repair-packet contract (0085 §PR7) |
| RIPR-SPEC-0088 | proposed | TypeScript repair-packet surface projection (0085 §PR8) |
| RIPR-SPEC-0089 | proposed | TypeScript full-repo scan guidance disclosure |
| RIPR-SPEC-0090 | accepted | All-no-path aggregate disclosure: human output adds an aggregate no-static-path note only when every finding is no-path/unknown, now including analyzed scope counts for changed Rust files, changed expressions, and statically linked related tests; JSON unchanged, no schema bump |
| RIPR-SPEC-0091 | proposed | Pilot artifact size bound (DEFAULT_PILOT_SEAM_BUDGET=2000) |
| RIPR-SPEC-0092 | proposed | Python Tier B judged-diff panel schema |
| RIPR-SPEC-0093 | proposed | Match-arm blind-reach downgrade (arm_observation_unverified) |
| RIPR-SPEC-0094 | proposed | observation_unverified guard generalization to ReturnValue/FieldConstruction/SideEffect/CallDeletion + MatchArm variant-scope fix |
| RIPR-SPEC-0095 | accepted | TypeScript single-hop re-export test discovery |
| RIPR-SPEC-0096 | proposed | INFECT/PROPAGATE fail-closed: wildcard discard, swallowed tails, stdout macros (parts A/B/C of #1219) |
| RIPR-SPEC-0097 | accepted | TypeScript toThrow exact-payload oracle upgrade: string/object/class → ExactErrorVariant/strong; bare toThrow stays weak |
| RIPR-SPEC-0098 | accepted | TypeScript exposed observation guard: downgrade exposed→weakly_exposed when no strong assertion's observed_expression flows from the changed sub-expression (console.log repro fix) |
| RIPR-SPEC-0099 | accepted | TypeScript tsconfig.json path-alias resolution: opt-in resolve_tsconfig_paths credits aliased imports; always-on typescript_path_alias_unresolved disclosure when name-matched non-relative import not credited |
| RIPR-SPEC-0100 | accepted | LSP advisory codeLens above changed symbols citing the cached related-test count; display-only, never a gate; honesty rules: snapshot==None→empty, N==0→"no related tests found", preview prefix for TS/Python |
| RIPR-SPEC-0101 | accepted | TypeScript honesty-clarity fix: reword misleading typescript_runner_hint_unresolved to typescript_package_manager_unresolved when framework is known and a verify command IS derivable; preserve strong fail-closed limitation for genuinely-unactionable case (no framework AND no runner) |
| RIPR-SPEC-0102 | accepted | TypeScript under-emit fix (gap 1): alias-rename import (import { X as local }) + verified body call upgraded from import_path_affinity/Medium to direct_owner_call/High; shadow guard prevents over-claim |
| RIPR-SPEC-0103 | accepted | Error-seam exemplar kind-gate: withdraw wrong-kind nominations, emit null when no ExactErrorVariant Strong test found for ErrorVariant seam; fail-closed, credits nothing, grip unchanged |
| RIPR-SPEC-0104 | accepted | TypeScript honesty fix: assertion-level family↔oracle-kind filter so cross-family Strong oracle (e.g. ExactErrorVariant) cannot promote a ReturnValue/Predicate seam to Exposed; 4 controls including single-test-both-assertions over-correction guard |
| RIPR-SPEC-0105 | accepted | LSP seam-inventory deferral: defer expensive 336s full-repo walk off interactive did_open/did_save; diff findings (33ms–11s) always complete; seams run on explicit ripr.refreshDiagnostics; disclose via seams_deferred run_status + limited policy |
| RIPR-SPEC-0106 | accepted | Error-seam unwrap_err/expect_err variant binding: recognize unwrap_err()-bound variables and upgrade exact-variant assertions to ExactErrorVariant/strong; sibling-variant guard prevents over-credit (fail-closed) |
| RIPR-SPEC-0107 | accepted | ErrorPath requires a variant-observing oracle: add ErrorPath to needs_token_confirmation so sibling/broad oracles no longer promote error_path seams to exposed; genuine variant-pinning oracle (ExactErrorVariant with matching token) still clears guard |
| RIPR-SPEC-0108 | accepted | Evidence-promotion honesty meta-gate: cross-language pinned adversarial corpus + xtask gate that reads byte-pinned pure goldens, optionally executes pinned external real-repo cases such as semver, and writes a typed corpus-summary envelope; asserts non-promoted charter members stay non-promoted; catches dishonest re-bless that would bypass goldens check; enforces witnessed limitation detail, exact limitation edges, exact analyzer routes, command honesty for Rust named limitations, and repair-packet detail for the TypeScript complete packet; shares invariant+corpus, not per-language matchers |
| RIPR-SPEC-0109 | accepted | Confidence min-cap by weakest stage: cap headline confidence_score by the weakest contributing stage's per-stage Confidence ceiling (Low=0.66, Unknown=0.50); can only lower, never raise; classify untouched; seven fixture goldens re-blessed (confidence numbers only, classification unchanged); closes #1219 part D |
| RIPR-SPEC-0110 | accepted | Receipt-gap cross-reference: ripr receipt check --ledger cross-references receipt's canonical_gap_id against the live gap set; orphan_receipt/receipt_gap_mismatch exit non-zero; ledger-absent → not_available (never receipt_ok, fail-closed); real producer for #1130-deferred labels; closes #1123 PR 4 |
| RIPR-SPEC-0111 | accepted | Gate new_unsuppressed receipt field: additive top-level object in gate-decision.json for downstream thresholding (max_new_unsuppressed=0); count = policy-eligible blocking+advisory decisions (NOT just blocking); basis=diff/baseline/null; null+reason = fail-closed when config_errors non-empty; schema_version stays 0.1; closes #1038 |
| RIPR-SPEC-0112 | accepted | Disclose unanalyzed working tree when using --base: emit unanalyzed_working_tree: true in JSON and advisory Note in human output when --base excludes uncommitted tracked-source changes; fail-closed (no disclosure when worktree is clean or git unavailable); closes #1291 |
| RIPR-SPEC-0113 | accepted | Honest no_static_path messaging: replace "add a test" wording (implies no test exists) with "A test may already exercise it through macros, helper-call chains, or integration tests that ripr's static model does not yet trace"; message-only change, no classification change; P2 of first-run-trust campaign |
| RIPR-SPEC-0114 | accepted | Rust transitive-reach limitation (P3 slice-a): when no_static_path has no related tests but a bounded BFS walk (depth<=5) finds a candidate path test->...->owner, name the limitation as static_limit_kind=rust_transitive_reach_unresolved and surface last edge, unresolved edge, route, and non-claim; fail-closed (no promotion, 'may' language, stops at macros/externals/depth>5) |
| RIPR-SPEC-0115 | accepted | Rust transitive-reach witness (P3.1, visibility before inference): the 0114 walk now names the witnessing test (file:line) and entry public-API symbol; human output surfaces it under a "Where to look" section, JSON evidence single-sourced via a shared prefix const; fail-closed (class stays no_static_path, witness not in related_tests, 'may lead here' language); evidence-only, no schema/version bump |
| RIPR-SPEC-0116 | accepted | check --worktree mode: analyze staged and unstaged tracked working-tree edits with git diff <base> while keeping committed-history --base and file-based --diff behavior unchanged; dirty doctor guidance recommends ripr check --base HEAD --worktree; the #3183 amendment routes saved LSP refreshes through the same tracked-worktree authority while preserving dirty-buffer quarantine and excluding/disclosing untracked files; closes #1296 and #3183 |
| RIPR-SPEC-0117 | accepted | Rust macro-reach limitation: when no_static_path has no related tests and no 0114 lexical path, name a same-repo macro boundary as static_limit_kind=rust_macro_reach_unresolved only when the macro definition lexically mentions the changed owner; fail-closed (no promotion, no related_tests, no macro expansion, witness and limitation detail are evidence-only); closes #1292 macro-boundary slice |
| RIPR-SPEC-0118 | accepted | Rust integration public-API path limitation: when a 0114/0115 transitive witness starts in an integration test path, emit static_limit_kind=rust_integration_public_api_path_unresolved instead of the generic transitive limitation; fail-closed (classification stays no_static_path, witness not in related_tests, no public-API proof, no repair packet) |
| RIPR-SPEC-0119 | accepted | Rust direct test macro-call limitation: when a 0117 macro witness comes from the test body itself, emit static_limit_kind=rust_macro_wrapped_test_call_unresolved instead of the generic macro-reach limitation; fail-closed (classification stays no_static_path, witness not in related_tests, no macro expansion, no repair packet) |
| RIPR-SPEC-0120 | accepted | Rust macro-wrapped assertion limitation: when a reachable related test has no recognized oracle but invokes an assertion-like custom macro, emit static_limit_kind=rust_macro_wrapped_assertion_unresolved; fail-closed (classification stays reachable_unrevealed, no macro expansion, no generic assert_* semantics, no repair packet) |
| RIPR-SPEC-0166 | proposed | Rust integration tests that invoke Cargo-built binaries receive a named rust_subprocess_binary_reach_unresolved limitation when the binary-to-owner map is unavailable; classification stays no_static_path and no reach, receipt, coverage, or repair claim is made |
| RIPR-SPEC-0121 | proposed | perl-lsp-swarm CI scratch-GC orphan-reaper path mismatch: the per-run dirs nest under /mnt/ci-scratch/perl-lsp-swarm/ripr-* and /mnt/ci-scratch/tmp/ripr-* but the reaper scans the parent at depth 1, so killed/OOM/cancelled runs leak multi-GB Cargo target trees; spec-only (fix lands in perl-lsp-swarm, mirroring ripr-swarm scratch-gc.yml which sweeps inside each subdir at -maxdepth 1) |
| RIPR-SPEC-0122 | accepted | Bounded human check output: --format human renders one start-here triage state, --format human-full preserves exhaustive evidence, repo-scoped formats warn when paired with --base/--diff, and first-pr --check explains validate-only missing-packet recovery |
| RIPR-SPEC-0123 | accepted | Targeted Rust rerun: explicit --gap or --changed-test selection, content-keyed fact reuse, named invalidation and cold fallback, canonical identity/receipt continuity, and a reproducible cold-versus-warm benchmark receipt |
| RIPR-SPEC-0124 | accepted | LSP diagnostic canonicalization, root-independent identities, unchanged URI suppression, and publication telemetry |
| RIPR-SPEC-0125 | proposed | Rust governed pilot missing-discriminator evidence fixtures |
| RIPR-SPEC-0126 | accepted | Pure deterministic finite LSP delivery budget over producer-owned canonical actionable items; explicit selected/omitted identities, byte limits, and overflow reasons |
| RIPR-SPEC-0127 | accepted | Governed catalog of every emitted RIPR LSP diagnostic code (finding, seam, gap); single-source constructors, fail-closed gap emission, and resolution validation; byte-identical wire output for known kinds (#1662 slice A) |
| RIPR-SPEC-0128 | deprecated | Reserved historical identifier for the removed active-goal-authority-audit framework (#1701) |
| RIPR-SPEC-0129 | accepted | Three-layer editor integration contract, support matrix, and bounded VS Code pre-activation compatibility admission |
| RIPR-SPEC-0130 | proposed | RIPR source-of-truth authority map: canonical paths for every artifact category, plus a legacy-dialect conformance fixture |
| RIPR-SPEC-0131 | proposed | Versioned, capability-only riprAgent protocol, DTO envelopes, closed vocabularies, schemas, and recovery rules |
| RIPR-SPEC-0132 | proposed | First RIPR-SPEC v2 requirement and spec/governance runtime-promotion boundary |
| RIPR-SPEC-0133 | accepted | Assertion-shaped owner guidance: when the changed owner is an assert*/expect-dominated helper with no non-test callers, reframe recommended_next_step for oracles (class unchanged) plus an owner_shape evidence disclosure line (#2131) |
| RIPR-SPEC-0134 | accepted | Producer-owned repo-exposure artifact identity, repository revision/currentness, and bounded raw-JSON content commitment for agent verify (#1977) |
| RIPR-SPEC-0135 | accepted | Separate static movement, explicit command execution, receipt issuance, and external runtime mutation evidence into closed assurance axes (#1978) |
| RIPR-SPEC-0136 | accepted | LSP configuration pull: capability-negotiated workspace/configuration pull of the bounded ripr section with per-key precedence over initialization options, epoch-guarded coalesced re-pulls, startup-window honesty, and a documented push/initialization fallback (#2031) |
| RIPR-SPEC-0137 | accepted | LSP protocol tracing: session-local off/messages/verbose trace state with a manually validated $/setTrace lifecycle and structurally redacted $/logTrace emission (method/direction/class; bounded numeric metadata at verbose) that never touches snapshot, input-identity, diagnostic, action, or status state (#2035) |
| RIPR-SPEC-0138 | accepted | LSP CodeLens refresh lifecycle: negotiated workspace.codeLens.refreshSupport with a deterministic semantic lens-view identity (wall-clock excluded) so one workspace/codeLens/refresh is sent per changed visible lens view and none for byte-identical re-commits (#2032) |
| RIPR-SPEC-0139 | accepted | LSP workspace-folder set authority: one stored canonical folder set with validate-before-mutate delta application, typed bounded rejections, an epoch-bound reconciliation confirmation step, and no epoch bump for byte-identical transitions (#2036) |
| RIPR-SPEC-0150 | accepted | Rust bounded value-propagation limitation: name find/rfind or len_utf8 plus map_or changed-let values that cannot reach a same-owner equality predicate; keep static_unknown, fail closed, and emit no repair route (#3215) |
| RIPR-SPEC-0151 | proposed | Finding source currentness: producer-owned per-finding disposition (candidate_current, base_deleted, moved_or_renamed, unresolved_subject) resolving which revision owns the actionable source; removed-only Rust probes keep their recorded coordinate in this slice, ids stay content-addressed, and no gate, count, or actionability policy changes (#3280) |
| RIPR-SPEC-0152 | proposed | Candidate-actionable projection authority: one Finding::is_candidate_actionable predicate gates every count, gap record, diagnostic, annotation, and agent obligation; TS/JS/Python producers resolve candidate_current from head-side delta evidence, Perl stays the explicit unknown, base-side evidence stays visible with revision labels, and denominators keep every finding (#3281) |
| RIPR-SPEC-0153 | accepted | Rust producer-owned source role: typed per-file role (production, test/bench/example/fixture evidence, production-like opt-in, reserved unknown) plus typed item roles (Production, TestAttribute, CfgTestModule, HarnessHelper, RegisteredTestAttribute), declared Cargo targets confirming evidence outside default layouts, the governed [analysis.test_harnesses] registry (#3532), filename conventions never classifying alone, diff seeding plus repo seam inventory routed through one authority, a retained conformance corpus, and the check-rust-source-role-authority gate (#3283, ratified by #3534/#3618) |
| RIPR-SPEC-0154 | proposed | Assertion-form parity: terminal Err-return guards in test bodies credit the same oracle as their structural assert! twins via the single classifier; repo-mode probe seeding filters evidence-role owners; cfg(all(test, ..)) members carry the evidence role; opaque conditions never guessed (#3284) |
| RIPR-SPEC-0155 | proposed | Cross-surface source-role projection: the LSP scope partition consumes the producer role model (opted-in targets keep their editor projection); the retired path predicate is deleted with its contract pinned in the role model; harness plumbing vocabulary creates zero production obligations (#3285) |
| RIPR-SPEC-0156 | proposed | Currentness editor projection and qualification corpus: code lenses gate on candidate actionability so base-deleted evidence is never pinned at its projected coordinate; a four-fixture corpus pins deleted-tail, reused-coordinate identity, movement-without-evidence, and whole-file-delete dispositions end to end (#3282) |
| RIPR-SPEC-0157 | proposed | Changed-binding to predicate-operand relation: a changed simple let initializer retargets its probe to the same-function predicate use it feeds, keeping the initializers as causal evidence and naming the earliest unresolved initializer operation; shadowing, reassignment, closure, macro, sibling, comment/string, and destructuring shapes fail closed (#3294) |
| RIPR-SPEC-0158 | proposed | Bounded value transfer from exact test inputs: one typed evaluator resolves single-line let initializers over related-test call literals for the enumerated std families (find/rfind, len, starts_with/ends_with/contains, strip_prefix/strip_suffix, chars().next/next_back, len_utf8, identity map_or, checked_add/checked_sub, bounded slicing), with per-step provenance, named unsupported edges, and UTF-8 boundary validation; exact operands observe the #3294 predicate boundary (#3295) |
| RIPR-SPEC-0159 | proposed | Bounded helper-call transfer: one typed authority resolves the bounded (≤3-hop) unique-callee chain above a helper-owned probe with positional literal/parameter argument binding, relating tests through resolved hops (reach, oracles, and #3295 inputs cross the helper edge) and evaluating direct helper-call comparison operands through simple binding-tail returns; every unsupported edge stops by name (#3296) |
| RIPR-SPEC-0160 | proposed | Immutable Git candidate CLI and output surface: --candidate-tree/--candidate-base bind the typed subject, execution routes through the R2 object producer, and the check JSON identity block gains an additive git_candidate_subject object (subject_kind, base_tree, candidate_tree, sha256 diff_identity) bound to resolved producer state only (#3278) |
| RIPR-SPEC-0161 | proposed | Immutable candidate isolation and parity qualification: a bound subject configures itself from the candidate tree's own ripr.toml (worktree config cannot change a subject run), finding paths name the repository root instead of the ephemeral materialization directory, and a 7-test falsifier corpus proves post-bind mutation irrelevance, same-tree committed parity, exact identity echo, delete/rename resolution from objects, fail-closed invalid inputs, a worktree-substitution removal experiment, and temp-state cleanup (#3279) |
| RIPR-SPEC-0162 | proposed | Honest propagation_unknown human wording: the why-hint stops asserting the propagation the class marks unknown, and unknown-class limitation prose renders under an Analyzer limit label while the Missing discriminator label is reserved for findings where a discriminator is actually missing (renderer-owned; #3317 review follow-up) |
| RIPR-SPEC-0163 | proposed | Bounded scanner-state transitions: a local whose initializer is a direct unique-helper call jumps to the helper authority, and a strict scanner shape (let mut state / for symbol in <exact>.chars() / literal match arms / state tail) unrolls at most 32 transitions over the row's exact inputs with string-literal or path-qualified state tokens (bare identifiers refused everywhere — token-coincidence guard); beyond-bound, computed-argument, computed-arm, and unrecognized-line edges keep the operand unknown (#3296) |
| RIPR-SPEC-0164 | proposed | Bounded literal match-arm transfer: one authority evaluates a helper whose whole body is a string match tail expression over the row's exact inputs — plain string-literal patterns and values, _ wildcard, first-match source order — and returns the arm's value as an exact typed value through the #3295 operand jump; guards, alternatives, bare bindings, escapes, computed values, non-string scrutinees, and non-tail bodies refuse the whole helper (#3296) |
| RIPR-SPEC-0165 | proposed | Bounded recursive helper evaluation: one shared context gates every helper-return evaluation — distinct (helper, bound inputs) states unroll within the existing MAX_HELPER_HOPS bound while a repeated state (a true cycle) or the bound itself refuses — and a match arm value may be one nested direct call resolved through the shared direct-call authority with strict literal/bound-parameter binding (#3296) |
| RIPR-SPEC-0167 | accepted | Hexagonal source-to-swarm convergence architecture with adapter-neutral types/domain, bounded capability ports, infrastructure adapters, thin commands, and mechanical dependency-direction enforcement (#3323) |
| RIPR-SPEC-0168 | proposed | Parser-backed unsafe execution boundary probes: one static_unknown unsafe_boundary probe at a changed line inside an unsafe boundary (#3536) |
| RIPR-SPEC-0169 | proposed | Contextual source-role composition across include and module edges: evidence-only CfgTestModule grants, fail-closed unresolved chains with provenance reasons and disclosure, crate-root-anchored default module resolution (#3533) |
| RIPR-SPEC-0170 | proposed | Stable textual path identity escapes literal percent signs consistently across platforms while preserving Unix invalid-byte %XX handling (#3609) |
| RIPR-SPEC-0140 | accepted | Check-artifact reuse: explicit check --write-artifact / explain|context --from pair with a full-fidelity CheckArtifactV1 envelope, atomic writes, a fail-closed identity gate (diff bytes, root, mode, languages, analysis options, versioned config identity, analyzer version), and byte-identical reused rendering (#2107) |
| RIPR-SPEC-0141 | accepted | LSP typed component-outcome degradation model: bounded per-component outcomes on the snapshot, one shared run-status aggregation, deduplicated window/logMessage warnings with recovery routes, and no hidden-stderr degradation reporting (#1997) |
| RIPR-SPEC-0142 | accepted | LSP Git input authority: one typed request-local ResolvedGitInputs resolution per accepted refresh shared by input identity, dedup, snapshot, and status, with episode-bounded reuse, explicit invalidation, and fail-closed unresolved/loader-default states (#2000) |
| RIPR-SPEC-0143 | accepted | LSP client feature profile: one immutable typed ClientFeatureProfile parsed once at initialize as the capability authority for standard and RIPR experimental blocks, fail-closed on malformed experimental fields, with a bounded status/receipt projection and no client-name inference (#1987) |
| RIPR-SPEC-0144 | accepted | Live-head 0.11.0 release authority: exact transaction-boundary swarm SHA, immutable pin, and historical C/T lens retained only for read-only disposition evidence (#2379/#2766) |
| RIPR-SPEC-0145 | accepted (historical) | Former candidate-only 0.11 execution-surface disposition retained as audit evidence; it is not the active live-head publication rule (#2767) |
| RIPR-SPEC-0146 | accepted (historical) | Former supplemental C/T denominator ledger retained for audit; final 0.11.0 counts and SHA digest are regenerated from pinned heads (#2768) |
| RIPR-SPEC-0147 | proposed | Typed parser-to-pipeline completeness and limitation projection for human and JSON/status output; zero findings with unsupported input stays visibly incomplete while SARIF, badge, gate, and secondary projections remain PR-B follow-up (#2829) |
| RIPR-SPEC-0148 | accepted | Exact source/swarm parent identity, ancestry denominator, ordered digest, and disposable dry-merge receipt for history-preserving promotion (#1492) |
| RIPR-SPEC-0179 | accepted | Exact ordered-parent K, reviewed tree, current-head guard, and policy/release evidence for read-only source-to-swarm back-sync (#3100; renumbered from RIPR-SPEC-0152 on the 0.11 J join) |
| RIPR-SPEC-0178 | accepted | Bounded literal allowlisted subprocess adapters with argument, timeout, captured-output, and cleanup evidence use the existing side_effect probe family; dynamic, shell, and unbounded commands retain strict exposure behavior; closes #1454 |
| RIPR-SPEC-0149 | proposed | Exact source-promotion graph and resolution verifier |
| RIPR-SPEC-0177 | proposed | Exact PR-head verification plus read-only trusted admission workflow, normalized retained evidence, constructor dry-run guard, and post-merge reachability (renumbered from RIPR-SPEC-0150 on the 0.11 J join) |
| RIPR-SPEC-0171 | proposed | Reverse-dependency diff-scope expansion: Draft/Fast package scope grows by the package roots that reach a changed package through the path-dependency adjacency; expansion only adds, limited/unavailable graphs disclose the boundary, non-narrowing selections are unchanged, and the scope cap stays fail-closed (#2665-C/#2970) |
| RIPR-SPEC-0172 | proposed | Cross-crate test relation through dependency edges: an ambiguous-name cross-crate call is admitted as related evidence only through one captured forward callable dependency declaration (normal/dev) to the owner's nearest-manifest package, with parser-backed call identity (comments and strings never fabricate calls) attributable to the declared dependency name via qualified call or use import, and every other boundary failing closed (#2972) |
| RIPR-SPEC-0173 | proposed | Harness trial subject evidence parity: a named-invocation trial subject keeps its registration-invocation span while its calls/oracles/literals widen over exactly the code it exercises — one level of a provably-unshadowed top-level helper-callback body, and method-position .unwrap()/.expect() smoke oracles with receiver-ful text and real lines — with every ambiguous binding (local shadow, import, nested-module fn) failing closed (#3603); named_invocation stays a syntactic claim bounded by the registered target — dead construction (unused helper, if false branch, collection never passed to the run entry point) still claims and still enters the executable-test denominator, with the over-credit boundary named on the claim (#3604) |
| RIPR-SPEC-0174 | proposed | Target support closure rule for Rust scope selection: any future target-aware narrowing must resolve all target shapes through one ownership authority, retain integration/subprocess/module-parent/#[path]/include!/cfg support edges, fail closed on unknown relationships, preserve reverse dependents, and bind completeness language to graph coverage — with the falsifying selection matrix pinning the current conservative baseline (#3705) |
| RIPR-SPEC-0175 | proposed | Guarded Result match observations: a test-body match <direct-call> { Ok(..) => .., Err(..) => guard } whose scrutinee directly calls the changed owner produces a guarded_result_match oracle bound to that callee — strong for an exact error-variant pin in the guard, medium for a concrete downcast pin — with wildcard/no-op arms, message-only diagnostics, non-direct scrutinees, and shadowed callees failing closed (#3709); #3727 Slice A adds parser-backed shadow facts (nested_fn_names/let_bindings) with a flag-law shadow authority whose fact path is scanner-equivalent and whose lexical fallback runs the byte scanners byte-identically |
| RIPR-SPEC-0176 | proposed | Python repair-trust selection and attempt semantics: one immutable pre-outcome selection denominator with per-row canonical digests and one typed attempt lifecycle (progress ordering, discard terminals, supersedes-based refresh appends) over separate static-movement and verification-execution axes that cannot imply one another, transition-required identities, forbidden production/generated/vendor/environment edit surfaces, row-derived aggregates with honest diversity floors, and an offline python-repair-trust check whose valid/incomplete/not_run verdict is never a support-tier or repair-correctness claim (#3568) |