Specs

September 15, 2026 · View on GitHub

Specs define externally meaningful behavior for ripr. They are the source of truth for the spec-test-code traceability loop.

Use specs for behavior that users, integrations, or future agents need to rely on. Keep implementation details in architecture docs or ADRs unless they affect observable behavior.

A spec status records normative disposition only. It does not establish implementation, proof, support, or live-work state; those are represented by implementation claims and PR-local slices, traceability and evidence, support authorities, and GitHub/worktree state. A spec remains valid until it is explicitly corrected, rejected, superseded, or deprecated.

Index

SpecStatusTopic
RIPR-SPEC-0001acceptedStatic exposure loop
RIPR-SPEC-0002acceptedFixture laboratory
RIPR-SPEC-0003plannedAgent context packet
RIPR-SPEC-0004plannedTest efficiency and vacuity signals
RIPR-SPEC-0005proposedRepo seam inventory and test grip
RIPR-SPEC-0006proposedMutation calibration reports
RIPR-SPEC-0007proposedRepository configuration
RIPR-SPEC-0008proposedSARIF and CI policy
RIPR-SPEC-0009proposedDefaults-first adoption
RIPR-SPEC-0010proposedAgent working-set brief
RIPR-SPEC-0011proposedLLM work loop
RIPR-SPEC-0012proposedPR test guidance annotations
RIPR-SPEC-0013proposedRecommendation calibration report
RIPR-SPEC-0014proposedCalibrated gate policy
RIPR-SPEC-0015proposedEvidence health baseline
RIPR-SPEC-0016proposedBaseline debt delta
RIPR-SPEC-0017proposedRIPR Zero reporting
RIPR-SPEC-0018proposedPR evidence ledger
RIPR-SPEC-0019proposedTest-oracle assistant loop
RIPR-SPEC-0020proposedFirst useful action report
RIPR-SPEC-0021proposedEvidence record
RIPR-SPEC-0022proposedAssistant loop health report
RIPR-SPEC-0023proposedPR review front panel report
RIPR-SPEC-0024proposedReport packet index
RIPR-SPEC-0025proposedPR inline comment publisher
RIPR-SPEC-0026acceptedLanguage adapter contract
RIPR-SPEC-0027acceptedTypeScript preview static facts
RIPR-SPEC-0028proposedPython preview static facts
RIPR-SPEC-0029proposedPolicy readiness report
RIPR-SPEC-0030proposedPreview evidence policy boundary
RIPR-SPEC-0031proposedLane 1 evidence quality audit
RIPR-SPEC-0032proposedLane 1 evidence quality failure fixtures
RIPR-SPEC-0033proposedMatch-arm canonical gap discriminators
RIPR-SPEC-0034proposedEvidence quality scorecard
RIPR-SPEC-0035proposedEvidence quality benchmark corpus
RIPR-SPEC-0036proposedEditor preview routing
RIPR-SPEC-0037proposedEditor preview static-limit projection
RIPR-SPEC-0038proposedGenerated PR CI review workflow
RIPR-SPEC-0039proposedPolicy operations report
RIPR-SPEC-0040proposedStatic/runtime confidence expansion
RIPR-SPEC-0041proposedPolicy history ledger
RIPR-SPEC-0042proposedPolicy promotion packets
RIPR-SPEC-0043proposedPresentation text evidence
RIPR-SPEC-0044proposedPreview evidence promotion packet
RIPR-SPEC-0045proposedFinding-to-gap alignment
RIPR-SPEC-0046proposedGap decision ledger
RIPR-SPEC-0047acceptedEditor gap projection
RIPR-SPEC-0048proposedConfig and policy constant evidence
RIPR-SPEC-0049acceptedEditor setup status
RIPR-SPEC-0050acceptedEditor first repair loop
RIPR-SPEC-0051acceptedFirst successful PR UX
RIPR-SPEC-0052acceptedEditor first-pr packet projection
RIPR-SPEC-0053acceptedStart-here surface convergence
RIPR-SPEC-0054acceptedEditor adoption assurance
RIPR-SPEC-0055acceptedEditor actionable gap queue
RIPR-SPEC-0056acceptedPublic actionable projection
RIPR-SPEC-0057acceptedRIPR swarm repair loop
RIPR-SPEC-0058acceptedRIPR swarm external agent handoff
RIPR-SPEC-0059acceptedActionable surface translation
RIPR-SPEC-0060acceptedSource-of-truth stack
RIPR-SPEC-0061proposedLane 1 canonical actionability contract
RIPR-SPEC-0062proposedCross-language oracle graph
RIPR-SPEC-0063proposedCross-language evidence router UX
RIPR-SPEC-0064proposedPerl fact packet contract
RIPR-SPEC-0065proposedEvidence-to-repair use-case roadmap
RIPR-SPEC-0066proposedRepo badge use case
RIPR-SPEC-0067proposedPR gate use case
RIPR-SPEC-0068acceptedPR review-card use case
RIPR-SPEC-0069proposedLSP agent feedback use case
RIPR-SPEC-0070proposedDownstream review consumer use case
RIPR-SPEC-0071proposedTypeScript/Bun evidence use case
RIPR-SPEC-0072proposedLarge-repo diff-first use case
RIPR-SPEC-0073proposedReceipts, outcomes, and route quality use case
RIPR-SPEC-0074proposedRepo exposure run status
RIPR-SPEC-0075proposedPR evidence summary
RIPR-SPEC-0076acceptedLSP diagnostics severity policy
RIPR-SPEC-0077proposedLSP repair packet command
RIPR-SPEC-0078proposedLSP top-limitation command
RIPR-SPEC-0079proposedCanonical receipt command contract
RIPR-SPEC-0080proposedRoute-quality standalone report
RIPR-SPEC-0081proposedLSP receipt-status command
RIPR-SPEC-0082proposedPreview-language disclosure
RIPR-SPEC-0083proposedCheck no-scope disclosure
RIPR-SPEC-0084proposedDefault base resolution
RIPR-SPEC-0085proposedTypeScript evidence adapter contract
RIPR-SPEC-0086acceptedPython Tier A eval sweep
RIPR-SPEC-0087proposedTypeScript preview→actionable repair-packet contract (0085 §PR7)
RIPR-SPEC-0088proposedTypeScript repair-packet surface projection (0085 §PR8)
RIPR-SPEC-0089proposedTypeScript full-repo scan guidance disclosure
RIPR-SPEC-0090acceptedAll-no-path aggregate disclosure: human output adds an aggregate no-static-path note only when every finding is no-path/unknown, now including analyzed scope counts for changed Rust files, changed expressions, and statically linked related tests; JSON unchanged, no schema bump
RIPR-SPEC-0091proposedPilot artifact size bound (DEFAULT_PILOT_SEAM_BUDGET=2000)
RIPR-SPEC-0092proposedPython Tier B judged-diff panel schema
RIPR-SPEC-0093proposedMatch-arm blind-reach downgrade (arm_observation_unverified)
RIPR-SPEC-0094proposedobservation_unverified guard generalization to ReturnValue/FieldConstruction/SideEffect/CallDeletion + MatchArm variant-scope fix
RIPR-SPEC-0095acceptedTypeScript single-hop re-export test discovery
RIPR-SPEC-0096proposedINFECT/PROPAGATE fail-closed: wildcard discard, swallowed tails, stdout macros (parts A/B/C of #1219)
RIPR-SPEC-0097acceptedTypeScript toThrow exact-payload oracle upgrade: string/object/class → ExactErrorVariant/strong; bare toThrow stays weak
RIPR-SPEC-0098acceptedTypeScript exposed observation guard: downgrade exposed→weakly_exposed when no strong assertion's observed_expression flows from the changed sub-expression (console.log repro fix)
RIPR-SPEC-0099acceptedTypeScript tsconfig.json path-alias resolution: opt-in resolve_tsconfig_paths credits aliased imports; always-on typescript_path_alias_unresolved disclosure when name-matched non-relative import not credited
RIPR-SPEC-0100acceptedLSP advisory codeLens above changed symbols citing the cached related-test count; display-only, never a gate; honesty rules: snapshot==None→empty, N==0→"no related tests found", preview prefix for TS/Python
RIPR-SPEC-0101acceptedTypeScript honesty-clarity fix: reword misleading typescript_runner_hint_unresolved to typescript_package_manager_unresolved when framework is known and a verify command IS derivable; preserve strong fail-closed limitation for genuinely-unactionable case (no framework AND no runner)
RIPR-SPEC-0102acceptedTypeScript under-emit fix (gap 1): alias-rename import (import { X as local }) + verified body call upgraded from import_path_affinity/Medium to direct_owner_call/High; shadow guard prevents over-claim
RIPR-SPEC-0103acceptedError-seam exemplar kind-gate: withdraw wrong-kind nominations, emit null when no ExactErrorVariant Strong test found for ErrorVariant seam; fail-closed, credits nothing, grip unchanged
RIPR-SPEC-0104acceptedTypeScript honesty fix: assertion-level family↔oracle-kind filter so cross-family Strong oracle (e.g. ExactErrorVariant) cannot promote a ReturnValue/Predicate seam to Exposed; 4 controls including single-test-both-assertions over-correction guard
RIPR-SPEC-0105acceptedLSP seam-inventory deferral: defer expensive 336s full-repo walk off interactive did_open/did_save; diff findings (33ms–11s) always complete; seams run on explicit ripr.refreshDiagnostics; disclose via seams_deferred run_status + limited policy
RIPR-SPEC-0106acceptedError-seam unwrap_err/expect_err variant binding: recognize unwrap_err()-bound variables and upgrade exact-variant assertions to ExactErrorVariant/strong; sibling-variant guard prevents over-credit (fail-closed)
RIPR-SPEC-0107acceptedErrorPath requires a variant-observing oracle: add ErrorPath to needs_token_confirmation so sibling/broad oracles no longer promote error_path seams to exposed; genuine variant-pinning oracle (ExactErrorVariant with matching token) still clears guard
RIPR-SPEC-0108acceptedEvidence-promotion honesty meta-gate: cross-language pinned adversarial corpus + xtask gate that reads byte-pinned pure goldens, optionally executes pinned external real-repo cases such as semver, and writes a typed corpus-summary envelope; asserts non-promoted charter members stay non-promoted; catches dishonest re-bless that would bypass goldens check; enforces witnessed limitation detail, exact limitation edges, exact analyzer routes, command honesty for Rust named limitations, and repair-packet detail for the TypeScript complete packet; shares invariant+corpus, not per-language matchers
RIPR-SPEC-0109acceptedConfidence min-cap by weakest stage: cap headline confidence_score by the weakest contributing stage's per-stage Confidence ceiling (Low=0.66, Unknown=0.50); can only lower, never raise; classify untouched; seven fixture goldens re-blessed (confidence numbers only, classification unchanged); closes #1219 part D
RIPR-SPEC-0110acceptedReceipt-gap cross-reference: ripr receipt check --ledger cross-references receipt's canonical_gap_id against the live gap set; orphan_receipt/receipt_gap_mismatch exit non-zero; ledger-absent → not_available (never receipt_ok, fail-closed); real producer for #1130-deferred labels; closes #1123 PR 4
RIPR-SPEC-0111acceptedGate new_unsuppressed receipt field: additive top-level object in gate-decision.json for downstream thresholding (max_new_unsuppressed=0); count = policy-eligible blocking+advisory decisions (NOT just blocking); basis=diff/baseline/null; null+reason = fail-closed when config_errors non-empty; schema_version stays 0.1; closes #1038
RIPR-SPEC-0112acceptedDisclose unanalyzed working tree when using --base: emit unanalyzed_working_tree: true in JSON and advisory Note in human output when --base excludes uncommitted tracked-source changes; fail-closed (no disclosure when worktree is clean or git unavailable); closes #1291
RIPR-SPEC-0113acceptedHonest no_static_path messaging: replace "add a test" wording (implies no test exists) with "A test may already exercise it through macros, helper-call chains, or integration tests that ripr's static model does not yet trace"; message-only change, no classification change; P2 of first-run-trust campaign
RIPR-SPEC-0114acceptedRust transitive-reach limitation (P3 slice-a): when no_static_path has no related tests but a bounded BFS walk (depth<=5) finds a candidate path test->...->owner, name the limitation as static_limit_kind=rust_transitive_reach_unresolved and surface last edge, unresolved edge, route, and non-claim; fail-closed (no promotion, 'may' language, stops at macros/externals/depth>5)
RIPR-SPEC-0115acceptedRust transitive-reach witness (P3.1, visibility before inference): the 0114 walk now names the witnessing test (file:line) and entry public-API symbol; human output surfaces it under a "Where to look" section, JSON evidence single-sourced via a shared prefix const; fail-closed (class stays no_static_path, witness not in related_tests, 'may lead here' language); evidence-only, no schema/version bump
RIPR-SPEC-0116acceptedcheck --worktree mode: analyze staged and unstaged tracked working-tree edits with git diff <base> while keeping committed-history --base and file-based --diff behavior unchanged; dirty doctor guidance recommends ripr check --base HEAD --worktree; the #3183 amendment routes saved LSP refreshes through the same tracked-worktree authority while preserving dirty-buffer quarantine and excluding/disclosing untracked files; closes #1296 and #3183
RIPR-SPEC-0117acceptedRust macro-reach limitation: when no_static_path has no related tests and no 0114 lexical path, name a same-repo macro boundary as static_limit_kind=rust_macro_reach_unresolved only when the macro definition lexically mentions the changed owner; fail-closed (no promotion, no related_tests, no macro expansion, witness and limitation detail are evidence-only); closes #1292 macro-boundary slice
RIPR-SPEC-0118acceptedRust integration public-API path limitation: when a 0114/0115 transitive witness starts in an integration test path, emit static_limit_kind=rust_integration_public_api_path_unresolved instead of the generic transitive limitation; fail-closed (classification stays no_static_path, witness not in related_tests, no public-API proof, no repair packet)
RIPR-SPEC-0119acceptedRust direct test macro-call limitation: when a 0117 macro witness comes from the test body itself, emit static_limit_kind=rust_macro_wrapped_test_call_unresolved instead of the generic macro-reach limitation; fail-closed (classification stays no_static_path, witness not in related_tests, no macro expansion, no repair packet)
RIPR-SPEC-0120acceptedRust macro-wrapped assertion limitation: when a reachable related test has no recognized oracle but invokes an assertion-like custom macro, emit static_limit_kind=rust_macro_wrapped_assertion_unresolved; fail-closed (classification stays reachable_unrevealed, no macro expansion, no generic assert_* semantics, no repair packet)
RIPR-SPEC-0166proposedRust integration tests that invoke Cargo-built binaries receive a named rust_subprocess_binary_reach_unresolved limitation when the binary-to-owner map is unavailable; classification stays no_static_path and no reach, receipt, coverage, or repair claim is made
RIPR-SPEC-0121proposedperl-lsp-swarm CI scratch-GC orphan-reaper path mismatch: the per-run dirs nest under /mnt/ci-scratch/perl-lsp-swarm/ripr-* and /mnt/ci-scratch/tmp/ripr-* but the reaper scans the parent at depth 1, so killed/OOM/cancelled runs leak multi-GB Cargo target trees; spec-only (fix lands in perl-lsp-swarm, mirroring ripr-swarm scratch-gc.yml which sweeps inside each subdir at -maxdepth 1)
RIPR-SPEC-0122acceptedBounded human check output: --format human renders one start-here triage state, --format human-full preserves exhaustive evidence, repo-scoped formats warn when paired with --base/--diff, and first-pr --check explains validate-only missing-packet recovery
RIPR-SPEC-0123acceptedTargeted Rust rerun: explicit --gap or --changed-test selection, content-keyed fact reuse, named invalidation and cold fallback, canonical identity/receipt continuity, and a reproducible cold-versus-warm benchmark receipt
RIPR-SPEC-0124acceptedLSP diagnostic canonicalization, root-independent identities, unchanged URI suppression, and publication telemetry
RIPR-SPEC-0125proposedRust governed pilot missing-discriminator evidence fixtures
RIPR-SPEC-0126acceptedPure deterministic finite LSP delivery budget over producer-owned canonical actionable items; explicit selected/omitted identities, byte limits, and overflow reasons
RIPR-SPEC-0127acceptedGoverned catalog of every emitted RIPR LSP diagnostic code (finding, seam, gap); single-source constructors, fail-closed gap emission, and resolution validation; byte-identical wire output for known kinds (#1662 slice A)
RIPR-SPEC-0128deprecatedReserved historical identifier for the removed active-goal-authority-audit framework (#1701)
RIPR-SPEC-0129acceptedThree-layer editor integration contract, support matrix, and bounded VS Code pre-activation compatibility admission
RIPR-SPEC-0130proposedRIPR source-of-truth authority map: canonical paths for every artifact category, plus a legacy-dialect conformance fixture
RIPR-SPEC-0131proposedVersioned, capability-only riprAgent protocol, DTO envelopes, closed vocabularies, schemas, and recovery rules
RIPR-SPEC-0132proposedFirst RIPR-SPEC v2 requirement and spec/governance runtime-promotion boundary
RIPR-SPEC-0133acceptedAssertion-shaped owner guidance: when the changed owner is an assert*/expect-dominated helper with no non-test callers, reframe recommended_next_step for oracles (class unchanged) plus an owner_shape evidence disclosure line (#2131)
RIPR-SPEC-0134acceptedProducer-owned repo-exposure artifact identity, repository revision/currentness, and bounded raw-JSON content commitment for agent verify (#1977)
RIPR-SPEC-0135acceptedSeparate static movement, explicit command execution, receipt issuance, and external runtime mutation evidence into closed assurance axes (#1978)
RIPR-SPEC-0136acceptedLSP configuration pull: capability-negotiated workspace/configuration pull of the bounded ripr section with per-key precedence over initialization options, epoch-guarded coalesced re-pulls, startup-window honesty, and a documented push/initialization fallback (#2031)
RIPR-SPEC-0137acceptedLSP protocol tracing: session-local off/messages/verbose trace state with a manually validated $/setTrace lifecycle and structurally redacted $/logTrace emission (method/direction/class; bounded numeric metadata at verbose) that never touches snapshot, input-identity, diagnostic, action, or status state (#2035)
RIPR-SPEC-0138acceptedLSP CodeLens refresh lifecycle: negotiated workspace.codeLens.refreshSupport with a deterministic semantic lens-view identity (wall-clock excluded) so one workspace/codeLens/refresh is sent per changed visible lens view and none for byte-identical re-commits (#2032)
RIPR-SPEC-0139acceptedLSP workspace-folder set authority: one stored canonical folder set with validate-before-mutate delta application, typed bounded rejections, an epoch-bound reconciliation confirmation step, and no epoch bump for byte-identical transitions (#2036)
RIPR-SPEC-0150acceptedRust bounded value-propagation limitation: name find/rfind or len_utf8 plus map_or changed-let values that cannot reach a same-owner equality predicate; keep static_unknown, fail closed, and emit no repair route (#3215)
RIPR-SPEC-0151proposedFinding source currentness: producer-owned per-finding disposition (candidate_current, base_deleted, moved_or_renamed, unresolved_subject) resolving which revision owns the actionable source; removed-only Rust probes keep their recorded coordinate in this slice, ids stay content-addressed, and no gate, count, or actionability policy changes (#3280)
RIPR-SPEC-0152proposedCandidate-actionable projection authority: one Finding::is_candidate_actionable predicate gates every count, gap record, diagnostic, annotation, and agent obligation; TS/JS/Python producers resolve candidate_current from head-side delta evidence, Perl stays the explicit unknown, base-side evidence stays visible with revision labels, and denominators keep every finding (#3281)
RIPR-SPEC-0153acceptedRust producer-owned source role: typed per-file role (production, test/bench/example/fixture evidence, production-like opt-in, reserved unknown) plus typed item roles (Production, TestAttribute, CfgTestModule, HarnessHelper, RegisteredTestAttribute), declared Cargo targets confirming evidence outside default layouts, the governed [analysis.test_harnesses] registry (#3532), filename conventions never classifying alone, diff seeding plus repo seam inventory routed through one authority, a retained conformance corpus, and the check-rust-source-role-authority gate (#3283, ratified by #3534/#3618)
RIPR-SPEC-0154proposedAssertion-form parity: terminal Err-return guards in test bodies credit the same oracle as their structural assert! twins via the single classifier; repo-mode probe seeding filters evidence-role owners; cfg(all(test, ..)) members carry the evidence role; opaque conditions never guessed (#3284)
RIPR-SPEC-0155proposedCross-surface source-role projection: the LSP scope partition consumes the producer role model (opted-in targets keep their editor projection); the retired path predicate is deleted with its contract pinned in the role model; harness plumbing vocabulary creates zero production obligations (#3285)
RIPR-SPEC-0156proposedCurrentness editor projection and qualification corpus: code lenses gate on candidate actionability so base-deleted evidence is never pinned at its projected coordinate; a four-fixture corpus pins deleted-tail, reused-coordinate identity, movement-without-evidence, and whole-file-delete dispositions end to end (#3282)
RIPR-SPEC-0157proposedChanged-binding to predicate-operand relation: a changed simple let initializer retargets its probe to the same-function predicate use it feeds, keeping the initializers as causal evidence and naming the earliest unresolved initializer operation; shadowing, reassignment, closure, macro, sibling, comment/string, and destructuring shapes fail closed (#3294)
RIPR-SPEC-0158proposedBounded value transfer from exact test inputs: one typed evaluator resolves single-line let initializers over related-test call literals for the enumerated std families (find/rfind, len, starts_with/ends_with/contains, strip_prefix/strip_suffix, chars().next/next_back, len_utf8, identity map_or, checked_add/checked_sub, bounded slicing), with per-step provenance, named unsupported edges, and UTF-8 boundary validation; exact operands observe the #3294 predicate boundary (#3295)
RIPR-SPEC-0159proposedBounded helper-call transfer: one typed authority resolves the bounded (≤3-hop) unique-callee chain above a helper-owned probe with positional literal/parameter argument binding, relating tests through resolved hops (reach, oracles, and #3295 inputs cross the helper edge) and evaluating direct helper-call comparison operands through simple binding-tail returns; every unsupported edge stops by name (#3296)
RIPR-SPEC-0160proposedImmutable Git candidate CLI and output surface: --candidate-tree/--candidate-base bind the typed subject, execution routes through the R2 object producer, and the check JSON identity block gains an additive git_candidate_subject object (subject_kind, base_tree, candidate_tree, sha256 diff_identity) bound to resolved producer state only (#3278)
RIPR-SPEC-0161proposedImmutable candidate isolation and parity qualification: a bound subject configures itself from the candidate tree's own ripr.toml (worktree config cannot change a subject run), finding paths name the repository root instead of the ephemeral materialization directory, and a 7-test falsifier corpus proves post-bind mutation irrelevance, same-tree committed parity, exact identity echo, delete/rename resolution from objects, fail-closed invalid inputs, a worktree-substitution removal experiment, and temp-state cleanup (#3279)
RIPR-SPEC-0162proposedHonest propagation_unknown human wording: the why-hint stops asserting the propagation the class marks unknown, and unknown-class limitation prose renders under an Analyzer limit label while the Missing discriminator label is reserved for findings where a discriminator is actually missing (renderer-owned; #3317 review follow-up)
RIPR-SPEC-0163proposedBounded scanner-state transitions: a local whose initializer is a direct unique-helper call jumps to the helper authority, and a strict scanner shape (let mut state / for symbol in <exact>.chars() / literal match arms / state tail) unrolls at most 32 transitions over the row's exact inputs with string-literal or path-qualified state tokens (bare identifiers refused everywhere — token-coincidence guard); beyond-bound, computed-argument, computed-arm, and unrecognized-line edges keep the operand unknown (#3296)
RIPR-SPEC-0164proposedBounded literal match-arm transfer: one authority evaluates a helper whose whole body is a string match tail expression over the row's exact inputs — plain string-literal patterns and values, _ wildcard, first-match source order — and returns the arm's value as an exact typed value through the #3295 operand jump; guards, alternatives, bare bindings, escapes, computed values, non-string scrutinees, and non-tail bodies refuse the whole helper (#3296)
RIPR-SPEC-0165proposedBounded recursive helper evaluation: one shared context gates every helper-return evaluation — distinct (helper, bound inputs) states unroll within the existing MAX_HELPER_HOPS bound while a repeated state (a true cycle) or the bound itself refuses — and a match arm value may be one nested direct call resolved through the shared direct-call authority with strict literal/bound-parameter binding (#3296)
RIPR-SPEC-0167acceptedHexagonal source-to-swarm convergence architecture with adapter-neutral types/domain, bounded capability ports, infrastructure adapters, thin commands, and mechanical dependency-direction enforcement (#3323)
RIPR-SPEC-0168proposedParser-backed unsafe execution boundary probes: one static_unknown unsafe_boundary probe at a changed line inside an unsafe boundary (#3536)
RIPR-SPEC-0169proposedContextual source-role composition across include and module edges: evidence-only CfgTestModule grants, fail-closed unresolved chains with provenance reasons and disclosure, crate-root-anchored default module resolution (#3533)
RIPR-SPEC-0170proposedStable textual path identity escapes literal percent signs consistently across platforms while preserving Unix invalid-byte %XX handling (#3609)
RIPR-SPEC-0140acceptedCheck-artifact reuse: explicit check --write-artifact / explain|context --from pair with a full-fidelity CheckArtifactV1 envelope, atomic writes, a fail-closed identity gate (diff bytes, root, mode, languages, analysis options, versioned config identity, analyzer version), and byte-identical reused rendering (#2107)
RIPR-SPEC-0141acceptedLSP typed component-outcome degradation model: bounded per-component outcomes on the snapshot, one shared run-status aggregation, deduplicated window/logMessage warnings with recovery routes, and no hidden-stderr degradation reporting (#1997)
RIPR-SPEC-0142acceptedLSP Git input authority: one typed request-local ResolvedGitInputs resolution per accepted refresh shared by input identity, dedup, snapshot, and status, with episode-bounded reuse, explicit invalidation, and fail-closed unresolved/loader-default states (#2000)
RIPR-SPEC-0143acceptedLSP client feature profile: one immutable typed ClientFeatureProfile parsed once at initialize as the capability authority for standard and RIPR experimental blocks, fail-closed on malformed experimental fields, with a bounded status/receipt projection and no client-name inference (#1987)
RIPR-SPEC-0144acceptedLive-head 0.11.0 release authority: exact transaction-boundary swarm SHA, immutable pin, and historical C/T lens retained only for read-only disposition evidence (#2379/#2766)
RIPR-SPEC-0145accepted (historical)Former candidate-only 0.11 execution-surface disposition retained as audit evidence; it is not the active live-head publication rule (#2767)
RIPR-SPEC-0146accepted (historical)Former supplemental C/T denominator ledger retained for audit; final 0.11.0 counts and SHA digest are regenerated from pinned heads (#2768)
RIPR-SPEC-0147proposedTyped parser-to-pipeline completeness and limitation projection for human and JSON/status output; zero findings with unsupported input stays visibly incomplete while SARIF, badge, gate, and secondary projections remain PR-B follow-up (#2829)
RIPR-SPEC-0148acceptedExact source/swarm parent identity, ancestry denominator, ordered digest, and disposable dry-merge receipt for history-preserving promotion (#1492)
RIPR-SPEC-0179acceptedExact ordered-parent K, reviewed tree, current-head guard, and policy/release evidence for read-only source-to-swarm back-sync (#3100; renumbered from RIPR-SPEC-0152 on the 0.11 J join)
RIPR-SPEC-0178acceptedBounded literal allowlisted subprocess adapters with argument, timeout, captured-output, and cleanup evidence use the existing side_effect probe family; dynamic, shell, and unbounded commands retain strict exposure behavior; closes #1454
RIPR-SPEC-0149proposedExact source-promotion graph and resolution verifier
RIPR-SPEC-0177proposedExact PR-head verification plus read-only trusted admission workflow, normalized retained evidence, constructor dry-run guard, and post-merge reachability (renumbered from RIPR-SPEC-0150 on the 0.11 J join)
RIPR-SPEC-0171proposedReverse-dependency diff-scope expansion: Draft/Fast package scope grows by the package roots that reach a changed package through the path-dependency adjacency; expansion only adds, limited/unavailable graphs disclose the boundary, non-narrowing selections are unchanged, and the scope cap stays fail-closed (#2665-C/#2970)
RIPR-SPEC-0172proposedCross-crate test relation through dependency edges: an ambiguous-name cross-crate call is admitted as related evidence only through one captured forward callable dependency declaration (normal/dev) to the owner's nearest-manifest package, with parser-backed call identity (comments and strings never fabricate calls) attributable to the declared dependency name via qualified call or use import, and every other boundary failing closed (#2972)
RIPR-SPEC-0173proposedHarness trial subject evidence parity: a named-invocation trial subject keeps its registration-invocation span while its calls/oracles/literals widen over exactly the code it exercises — one level of a provably-unshadowed top-level helper-callback body, and method-position .unwrap()/.expect() smoke oracles with receiver-ful text and real lines — with every ambiguous binding (local shadow, import, nested-module fn) failing closed (#3603); named_invocation stays a syntactic claim bounded by the registered target — dead construction (unused helper, if false branch, collection never passed to the run entry point) still claims and still enters the executable-test denominator, with the over-credit boundary named on the claim (#3604)
RIPR-SPEC-0174proposedTarget support closure rule for Rust scope selection: any future target-aware narrowing must resolve all target shapes through one ownership authority, retain integration/subprocess/module-parent/#[path]/include!/cfg support edges, fail closed on unknown relationships, preserve reverse dependents, and bind completeness language to graph coverage — with the falsifying selection matrix pinning the current conservative baseline (#3705)
RIPR-SPEC-0175proposedGuarded Result match observations: a test-body match <direct-call> { Ok(..) => .., Err(..) => guard } whose scrutinee directly calls the changed owner produces a guarded_result_match oracle bound to that callee — strong for an exact error-variant pin in the guard, medium for a concrete downcast pin — with wildcard/no-op arms, message-only diagnostics, non-direct scrutinees, and shadowed callees failing closed (#3709); #3727 Slice A adds parser-backed shadow facts (nested_fn_names/let_bindings) with a flag-law shadow authority whose fact path is scanner-equivalent and whose lexical fallback runs the byte scanners byte-identically
RIPR-SPEC-0176proposedPython repair-trust selection and attempt semantics: one immutable pre-outcome selection denominator with per-row canonical digests and one typed attempt lifecycle (progress ordering, discard terminals, supersedes-based refresh appends) over separate static-movement and verification-execution axes that cannot imply one another, transition-required identities, forbidden production/generated/vendor/environment edit surfaces, row-derived aggregates with honest diversity floors, and an offline python-repair-trust check whose valid/incomplete/not_run verdict is never a support-tier or repair-correctness claim (#3568)