Owners of the Workspace Boundary
chant provides the repository specification, which now takes in the domain record kinds and the factory’s rules, and nothing that faces a person. hud renders what chant reads and acts on it for the person in front of it, and behold reads a workspace the same way for the infra plane. studio orchestrates and hosts, which covers running builders with their prompts and publishing a box’s work. A plugin owns only the record kinds a workspace pins from a third party, with their joins. The decision is ws-086 (#3161), which supersedes ws-052 (#2657).
The boundary
Section titled “The boundary”| chant | hud | studio | behold | plugin |
|---|---|---|---|---|
declaration, kinds, members, links, lineage, migrations, init --from, upgrade | rendering | agent prompts, context bundles, how a builder is run | reading a workspace for the infra plane | record kinds a workspace pins from a third party, and their commitJoins |
| records: schemas, states, seals, pins, supersession, attestation, provenance | review actions as UI (agree, dissent, propose, quorum meter, live sessions) | hosting and provisioning: boxes, the lobby, the door, the planter and beds | ||
the read contract: versioned JSON of ls, graph, check, records, status, graph --intent, graph --composites, points, work history, signers, evidence verify, closed reason codes | identity, sessions, who is looking | publishing a box’s work: the merge, the push and the pull request | ||
commit trailers: Chant-Agent, Chant-Lease, Chant-Run, Chant-Record, Chant-Applied-By, Chant-Applied-At, Chant-Applied-Commit | the agent chat, the dev proxy, comment mode | |||
the agent run record: workspace runs, runs start, end and record, the run ledger on chant/lifecycle | the question put to the person at each finding | |||
| reader conformance: a reader reads only through the read contract and writes nothing | ||||
the publish call: chant workspace box publish, the publisher protocol, and the apply record every publish leaves | ||||
| writer conformance: a writer writes only through the write contract, and keeps no fact outside the repo | ||||
| work in progress that survives the box: snapshots under refs/chant/wip/<branch>, kept attempts, work branches and their replication | ||||
the writing and verifying commands: approve, records pin, verify, check, gates, ledgers | ||||
| findings as data | ||||
| who a person-attributed record or gate approval names: forge identities, signer principals, identity.attribution, signed gates | ||||
| domain record kinds (contract, evidence, review session, driver, proposal, notes) | ||||
decision-point standards: the understand point and the slice-tier inputs | ||||
| the factory’s rules: readiness, attempts, outcomes, done | ||||
| the broker protocol: what a broker of box capabilities answers for inference, decide, egress, feedback and fountain, its refusals, and the broker conformance suite |
- chant never listens on a port, never authenticates a person and never renders.
test/no-listener.test.tsholdspackages/coreto the first and to importing no UI or agent-runtime package. - hud never parses a record file, never runs git for provenance and never computes drift. It reads only through the read contract and writes only through chant commands. The suite a reader runs to show it ships in
@intentius/chantas@intentius/chant/workspace/conformance, for any test runner. - The repo is the database (ws-074, #3158). Every durable fact about a workspace, anything a person or agent decided, answered, reviewed, approved, wrote or was attributed with and any configuration of a box or member, is a file in the repo. A tool writes it only through chant’s write commands. Outside the repo a tool keeps only secrets in a broker or vault, telemetry, caches and indexes it can rebuild from the repo, and the substrate’s own runtime state.
- studio defines no record field and keeps no fact outside the repo (ws-074). Its CI runs the reader and writer conformance suites, the same proof asked of hud (#3159, arugula-salad/studio#338). behold is held to hud’s rules.
- chant reads a pinned kind’s
commitJoins, and the intent graph reports what they join asunit,contractandevidencenodes. chant’s own kinds need no join, because the commit trailers tie a commit to them (ws-075).
The roster
Section titled “The roster”This page is generated from docs/data/boundary.yaml, which has one row for each concept. test/boundary-roster.test.ts compares the roster with the closed lists in the code. It fails the build when something in one of those lists has no row, or when a row names something that is not there. A row for a cell of the table above uses the cell’s text as #2657 or #3161 words it. Each hud, studio or behold row names its owner’s repository as the carrier: alecraso/hud, arugula-salad/studio or INTENTIUS/behold.
| Category | Where the code keeps it | chant | hud | studio | behold | plugin |
|---|---|---|---|---|---|---|
| boundary cell | the table of #2657, one row per cell | 16 | 5 | 3 | 1 | 1 |
| workspace command | commandRegistry in cli/main.ts, and each sub-verb its help names | 63 | 0 | 0 | 0 | 0 |
| member kind | BUILTIN_KIND_NAMES in kinds.ts | 5 | 0 | 0 | 0 | 0 |
| record kind | none in core; the reference workspace’s and this repository’s kind files, or a kind a workspace pins from a third party | 7 | 0 | 0 | 0 | 1 |
| member link kind | LINK_KINDS in links.ts | 2 | 0 | 0 | 0 | 0 |
| record link kind | RECORD_LINK_KINDS in record-assets.ts | 2 | 0 | 0 | 0 | 0 |
| intent node kind | the node kinds of intent.schema.json | 10 | 0 | 0 | 0 | 3 |
| intent edge kind | the edge kinds of intent.schema.json | 12 | 0 | 0 | 0 | 3 |
| reason code | REASONS in reason-codes.ts, less the finding codes | 215 | 0 | 0 | 0 | 0 |
| finding code | the finding codes of intent.schema.json | 18 | 0 | 0 | 0 | 0 |
| WSP check | WORKSPACE_CHECKS in checks.ts and checks/*.ts | 50 | 0 | 0 | 0 | 0 |
| hud view | the hud reader requirements H1 to H11 of #2650 | 0 | 11 | 0 | 0 | 0 |
Each row follows, in the order of the table above.
| Category | Concept | Owner | Carried by | What |
|---|---|---|---|---|
| boundary cell | declaration, kinds, members, links, lineage, migrations, init --from, upgrade | chant | declaration.schema.json, workspace-kinds.schema.json, workspace-principals.schema.json, .chant/workspace.lock.json | The repository specification itself: what a workspace declares, how each member is read, how members join, and where the files came from. |
| boundary cell | records: schemas, states, seals, pins, supersession, attestation, provenance | chant | records.schema.json | How a record file is validated, sealed, pinned to the files it rests on, superseded and traced to a signed commit. |
| boundary cell | the read contract: versioned JSON of ls, graph, check, records, status, graph --intent, graph --composites, points, work history, signers, evidence verify, closed reason codes | chant | ls.schema.json, graph.schema.json, check.schema.json, records.schema.json, status.schema.json, intent.schema.json, composites.schema.json, points.schema.json, work-history.schema.json, signers.schema.json, evidence.schema.json | The only way a reader sees a workspace: one JSON Schema per document, a contract version and a chant floor. |
| boundary cell | commit trailers: Chant-Agent, Chant-Lease, Chant-Run, Chant-Record, Chant-Applied-By, Chant-Applied-At, Chant-Applied-Commit | chant | intent.schema.json, intent-record.schema.json | The names a commit uses to point at its agent session, work lease, agent run, records and apply; whoever makes the commit writes them, and chant reads them back (#3149, ws-075). |
| boundary cell | the agent run record: workspace runs, runs start, end and record, the run ledger on chant/lifecycle | chant | runs.schema.json, runs-write.schema.json, run-statement.schema.json | What each agent run cost and which commits it made, written by whatever ran the agent and read with totals per work item, decision and principal; chant records runs and never starts one (#3033, ws-076). A runner or steward key can sign a statement over a run, kept in the same ledger (#3192, ws-090). |
| boundary cell | reader conformance: a reader reads only through the read contract and writes nothing | chant | @intentius/chant/workspace/conformance, @intentius/chant/workspace/conformance/vitest | The suite a reader such as hud runs in its own CI, with any test runner, on a workspace it generates from the fixture that @intentius/chant ships. |
| boundary cell | the publish call: chant workspace box publish, the publisher protocol, and the apply record every publish leaves | chant | box-publish.schema.json, status.schema.json | A surface asks for a box’s work to be published with one chant call; chant runs the publisher the box block names and checks the commit it made for the Chant-Applied-* trailers, while the merge, push and pull request stay the orchestrator’s (#3165, ws-088). |
| boundary cell | writer conformance: a writer writes only through the write contract, and keeps no fact outside the repo | chant | @intentius/chant/workspace/conformance, @intentius/chant/workspace/conformance/vitest | The suite a writer such as hud or studio’s factory runs in its own CI: scripted writes through the writer, each one chant command whose changes chant reports, and the amnesia test, which deletes the writer’s private state and expects the same facts back (#3159, ws-074). |
| boundary cell | work in progress that survives the box: snapshots under refs/chant/wip/<branch>, kept attempts, work branches and their replication | chant | wip.schema.json, wip-write.schema.json, declaration.schema.json | One ref namespace for checkpoints of a branch’s working tree, which hud’s turn checkpoints and studio’s checkpoints use, replicated with the work branches, kept attempts and ledger to the remote the box block’s replicate names (#3172, ws-085). |
| boundary cell | the writing and verifying commands: approve, records pin, verify, check, gates, ledgers | chant | chant approve, chant workspace records pin, chant workspace records new, amend, review and close, chant workspace verify, chant workspace check | Every change to the repository that carries weight is made or checked by a chant command, so a UI writes only by calling one. |
| boundary cell | findings as data | chant | check.schema.json, intent.schema.json | A finding is a node or a row with a closed code, so a reader can draw it and a test can assert it. |
| boundary cell | rendering | hud | alecraso/hud | Drawing the documents of the read contract for a person. |
| boundary cell | review actions as UI (agree, dissent, propose, quorum meter, live sessions) | hud | alecraso/hud | The buttons and meters a reviewer uses; each verdict lands as a pull request that chant then reads. |
| boundary cell | identity, sessions, who is looking | hud | alecraso/hud | Signing a person in, knowing who is present, and mapping the session to the forge identity or signer principal it passes to chant’s write commands as —by or —actor (#3163); chant never authenticates a person. |
| boundary cell | who a person-attributed record or gate approval names: forge identities, signer principals, identity.attribution, signed gates | chant | declaration.schema.json, status.schema.json | The forms a person is named by, the declaration’s identity block read at base, and the seal that attests an approval against the signers at base (#3163, ws-080). |
| boundary cell | the agent chat, the dev proxy, comment mode | hud | alecraso/hud | The interactive surfaces around a workspace, none of which chant serves. |
| boundary cell | the question put to the person at each finding | hud | alecraso/hud | hud asks and never answers; the finding it asks about comes from chant as data. |
| boundary cell | domain record kinds (contract, evidence, review session, driver, proposal, notes) | chant | the reference workspace’s kind files and schemas, named in chant.workspace.json records | The record kinds a development model works in, shipped by chant as data and upgraded through lineage; core still ships no kind of its own, and the declaration names the ones a workspace holds (#3148, ws-082, ws-086). |
| boundary cell | decision-point standards: the understand point and the slice-tier inputs | chant | the reference workspace’s decisions/points.json, points.schema.json | The points every factory asks and the inputs each reads, declared once so two orchestrators ask the same question (#3150, ws-086). |
| boundary cell | the factory’s rules: readiness, attempts, outcomes, done | chant | factoryOp in @intentius/chant/op, workspace/factory-rules.ts (#3406) | Which work items are ready, which lease outcomes count as attempts, what done means and what happens to an unfinished attempt, as declared and tested behaviour; an orchestrator supplies only execution (#3162, ws-087). |
| boundary cell | record kinds a workspace pins from a third party, and their commitJoins | plugin | a pinned package’s record kind file, its schema and its commitJoins export (intent-joins.ts reads it) | A kind chant does not ship, and how a commit is tied to its records; core calls the join and never parses the package’s own trailers, while chant’s trailers join a commit to chant’s kinds (ws-075). |
| boundary cell | agent prompts, context bundles, how a builder is run | studio | arugula-salad/studio | What an agent is told and given, and the builder’s harness (Claude Code in the box, fountainRun); chant hands out data and no prompts (ws-086). |
| boundary cell | hosting and provisioning: boxes, the lobby, the door, the planter and beds | studio | arugula-salad/studio | Where a box runs and how it is reached and credentialed; the box’s configuration it reads from the declaration through the read contract (ws-074, ws-086). |
| boundary cell | the broker protocol: what a broker of box capabilities answers for inference, decide, egress, feedback and fountain, its refusals, and the broker conformance suite | chant | broker-protocol.schema.json | The routes, scope words and bodies a broker serves a box on, and the suite a broker such as studio’s lobby or fountain’s runs to show it; chant specifies and checks a broker and runs none (#3164, ws-097). |
| boundary cell | publishing a box’s work: the merge, the push and the pull request | studio | arugula-salad/studio | The work behind a publish, run as the publisher a box block names; chant runs no push and calls no forge (#3165, ws-086). |
| boundary cell | reading a workspace for the infra plane | behold | INTENTIUS/behold | behold reads a workspace only through the read contract and writes only through chant, under hud’s rules (ws-086). |
| workspace command | workspace init | chant | declaration.schema.json | Proposes a chant.workspace.json from the projects under a directory. |
| workspace command | workspace ls | chant | ls.schema.json | Lists the declaration’s members, the record kinds it names and its example groups, with a reason code for each one that can’t be read. |
| workspace command | workspace graph | chant | graph.schema.json | Prints the composed IR of every member, with member links and, given —kind, the records and their links. A member whose stamp, toolchain, command line and environment are unchanged is served from the per-member cache in the user’s cache directory, never written into the workspace (ws-059). |
| workspace command | workspace graph --intent | chant | intent.schema.json | Prints the intent graph over one region, through the kinds given with —kind or else every kind the declaration names: its commits, the decisions that constrain it, the artifacts they pin, and findings as nodes. |
| workspace command | workspace graph --composites | chant | composites.schema.json | Prints each composite instance with the components that can deploy it, how each match was made and whether it crossed a member link; an instance with no component is listed with none, and the choice is never made here. |
| workspace command | workspace patch | chant | patch.schema.json | Prints the hunks of a range, a work branch or one commit, file by file, cut to a size limit, for a reader that runs no git. |
| workspace command | workspace check | chant | check.schema.json | Checks the declaration with WSP ids and the lineage lock with reason codes, and prints the result as a read-contract document. |
| workspace command | workspace status | chant | status.schema.json | Shows each member’s releases in one environment from the lifecycle ledgers, read-only. |
| workspace command | workspace records | chant | records.schema.json, records-since.schema.json | Reads the records a record kind locates, or every kind the declaration names, validated against its schema, with provenance and reason codes; with —since, what changed in them between two revisions. |
| workspace command | workspace work | chant | work-lease.schema.json | Claims, renews and releases the lease on a work item: a compare-and-set ref with a fencing token and an expiry, pushed to the remote so separate clones coordinate, with each change appended to _leases/<id>.jsonl on chant/lifecycle (#2732, ws-055). |
| workspace command | workspace work history | chant | work-history.schema.json | Reads one work item’s lease history from _leases/<id>.jsonl in the ledger of the member that owns its work kind, as claims with their token, holder and how each ended, so a runner counts failed attempts without reading git (#2785). |
| workspace command | workspace work evidence | chant | work-evidence.schema.json | Attaches one piece of evidence for an acceptance criterion under the lease the caller holds, through records amend: the workEvidence activity as a command, so a writer that is not an Op, such as hud, writes it through chant (#3159). |
| workspace command | workspace runs | chant | runs.schema.json | Reads the agent runs in _agent-runs/<id>.jsonl on chant/lifecycle with the commits each made, joined by the run’s own list and its Chant-Run trailer, and totals tokens and cost per work item, decision and principal, listing a run with no cost as unpriced rather than zero (#3033, ws-076). |
| workspace command | workspace runs start | chant | runs-write.schema.json | Appends an agent run’s start to the run ledger: who it worked for, its session, harness, model, work item and lease. chant records runs and never starts one (#3033). |
| workspace command | workspace runs end | chant | runs-write.schema.json | Appends a started run’s end: its outcome, tokens, cost with currency and price source, the transcript pinned by hash, and the commits it made with their patch-ids (#3033). |
| workspace command | workspace runs record | chant | runs-write.schema.json | Appends a finished run’s start and end in one write, for a caller that reports a run only once it is over (#3033). |
| workspace command | workspace runs sign | chant | runs-write.schema.json | Appends a statement over an ended run to its ledger file: a DSSE envelope over the run record’s hash, its work item, harness, model and commits, signed with a runner or steward key .chant/trust.json lists at base, or signed elsewhere and checked before it is stored (#3192, ws-090). |
| workspace command | workspace runs statement | chant | run-statement.schema.json | Prints the agent-run statement and the payload to sign, for a signer whose key is kept elsewhere, such as a lobby, which signs it and hands the envelope back for runs sign (#3192). |
| workspace command | workspace runs verify | chant | run-statement.schema.json | Judges each run’s stored statements offline against the runner keys at base and reports which runs are signed; it fails only with —require signed (#3192, studio-035). |
| workspace command | workspace box | chant | box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json | A member’s box block through chant: box listing set writes the listing and box factory set the factory, so a tool never edits the declaration itself (#3308, #3600, ws-074), and box publish runs the box’s declared publisher (#3165, ws-088). |
| workspace command | workspace box factory | chant | box-factory-write.schema.json | box factory set <member> changes only the top-level properties of members[i].box.factory in the declaration, in place, keeping its formatting and comments, so whoever plants a box sets where it publishes (factory.publish); honours the write scope and identity rule at base, and never commits (#3600). |
| workspace command | workspace box listing | chant | box-listing-write.schema.json | box listing set <member> changes only members[i].box.listing in the declaration, in place, keeping its formatting and comments, copies a —cover picture into the repository, honours the write scope and identity rule at base, and never commits (#3308). |
| workspace command | workspace member | chant | member-write.schema.json | A declaration’s members through chant, so a lobby keeps its boxes without editing the declaration itself (#3596, ws-074): member add and member remove. |
| workspace command | workspace member add | chant | member-write.schema.json | member add <name> —from <file|-> appends the member’s entry to members in the declaration, in place, keeping its formatting and comments; refuses a name taken, a declaration that would not read, and a collision or literal path between boxes; honours the write scope and identity rule at base, and never commits (#3596). |
| workspace command | workspace member remove | chant | member-write.schema.json | member remove <name> removes the member’s entry from members in the declaration, in place, refusing when the declaration would no longer read, and never commits (#3596). |
| workspace command | workspace host | chant | member-write.schema.json | A declaration’s hosts through chant (#3596, ws-074): host set. |
| workspace command | workspace host set | chant | member-write.schema.json | host set <name> —from <file|-> adds the host’s entry to hosts, or replaces the one of that name, in place, refusing a declaration that would not read and a collision or literal path between boxes, and never commits (#3596). |
| workspace command | workspace box publish | chant | box-publish.schema.json | box publish <member> <item> or —records runs the publisher the box block names, with a JSON request on stdin, checks its answer and holds the commit it made to the apply record of ws-075; chant itself never commits, pushes or calls a forge (#3165, ws-088). |
| workspace command | workspace lock | chant | write-lock.schema.json | Says who holds the working tree’s write lock, and takes and releases it for a batch of writes across chant calls run with CHANT_WRITE_LOCK=<token> (#3173, ws-089). |
| workspace command | workspace wip | chant | wip.schema.json | Lists the work-in-progress snapshots under refs/chant/wip/<branch>, newest first, and how far each ref the box’s replicate policy names is from its remote, read locally (#3172, ws-085). hud and studio list checkpoints through it. |
| workspace command | workspace wip save | chant | wip-write.schema.json | Snapshots the whole working tree, uncommitted records included, onto refs/chant/wip/<branch> through a temporary index, so the index, HEAD and branch never move; pushes when the policy’s on includes save (#3172). hud’s turn checkpoints and studio’s checkpoints are these. |
| workspace command | workspace wip restore | chant | wip-write.schema.json | Puts the working tree back as a snapshot holds it, after a pre-restore snapshot of how it is, and resets the index to HEAD; the branch never moves (#3172). |
| workspace command | workspace wip push | chant | wip-write.schema.json | Pushes the work branches, kept attempts, snapshots and ledger branch the box’s replicate policy names to its remote under their own names, never forced, for the host’s schedule (#3172). |
| workspace command | workspace wip fetch | chant | wip-write.schema.json | On a replacement box, mirrors the remote’s replicated refs into refs/chant/replica/<remote>/ and creates or fast-forwards the local ones, leaving a checked-out, ahead or forked ref as it is (#3172). |
| workspace command | workspace records pin | chant | chant workspace records pin <path> | Prints a file’s path from the workspace root and its sha256, for a decision’s evidence pin. |
| workspace command | workspace records new | chant | records-new.schema.json | Writes one new record in a kind’s directory from validated JSON fields, allocating the next id, and never commits; with —sign, sealed by its author. |
| workspace command | workspace records amend | chant | records-amend.schema.json | Sets fields of one record under its schema and the approval rule, refusing a change to an approved record that only a superseding record can make; with —sign it seals the author again, and without it a change removes the author seal. |
| workspace command | workspace records review | chant | records-review.schema.json | Appends a dated review verdict to one record, bound to the digest of the record text, with a note required for a dissent, and with —sign an ssh seal by the reviewer. With —session, the session must exist and be open, and the verdict goes on its verdicts list in the same command. |
| workspace command | workspace records close | chant | records-close.schema.json | Closes an open review session in one write: its state, close time and closing commit, and the seal computed by chant’s rule (#2693). |
| workspace command | workspace points | chant | points.schema.json | Lists the decision points each declared answer kind’s points file declares, and the questions asked of them, with the open ones and any model’s answer and confidence (ws-058, #2739). |
| workspace command | workspace points ask | chant | points-write.schema.json | Asks a point’s table, model and quorum deciders for one set of inputs and records the answer, proposed when a model gave it; chant calls no model, and a backend’s response is handed in with —response. An ad-hoc point’s question and candidates come with the ask, with —candidates, and the record keeps them as asked (#3403). |
| workspace command | workspace points answer | chant | points-write.schema.json | Records people’s answer to an open question, or their confirmation of a model’s proposal, once the point’s quorum is met, with their note (#3351). |
| workspace command | workspace points retract | chant | points-write.schema.json | Takes people’s answer back once the point’s quorum is met: the question is escalated to people again, and the answer, its note, and who retracted it, when and why stay in the record’s retractions (#3351, ws-084). |
| workspace command | workspace agent | chant | agent.schema.json | Prints an agent session from the declaration at base: the members it is bound to, the record kinds and verbs its write scope allows, and the spec records —current prints, so a session that resumes rebuilds its context from the repository alone (#2548, ws-067, ws-101). |
| workspace command | workspace verify | chant | chant workspace verify | Checks the commits in base..head against the signers and roles read from base. |
| workspace command | workspace signers | chant | signers.schema.json | Shows the signer set’s versions along the base’s first-parent line, each signed by a threshold of the one before, and writes and signs the rotation file for the next version. |
| workspace command | workspace evidence | chant | chant workspace evidence | Runner evidence: an in-toto statement over record hashes in a DSSE envelope, signed by a runner or service key the policy at base lists. |
| workspace command | workspace evidence sign | chant | chant workspace evidence sign | Signs runner evidence over the records a kind locates at a commit, with a runner key, never a signer’s. |
| workspace command | workspace evidence verify | chant | evidence.schema.json | Verifies runner evidence offline against the runner keys at base, and says whether the records still hash as signed. |
| workspace command | workspace pin | chant | chant workspace pin —json | Prints the integrity value that pins a plugin loaded by path, and says whether the declared pin matches it. |
| workspace command | workspace lineage | chant | chant workspace lineage —json | Shows each scope in the lineage lock with its template, pin, edited files and open manual steps. |
| workspace command | workspace lineage resolve | chant | chant workspace lineage resolve <path> | Closes a manual step once the file has been merged by hand. |
| workspace command | workspace upgrade | chant | chant workspace upgrade | Brings a lineage scope to a newer template version in a worktree and gates the patch on its digest. |
| workspace command | workspace adopt-lineage | chant | chant workspace adopt-lineage —json | Gives a scope with no lineage one matched against the template’s versions, or moves a directory lineage onto git. |
| workspace command | workspace hash-index | chant | chant workspace hash-index | Computes the per-version file hashes adopt-lineage matches a scope against, for a template’s CI to publish. |
| workspace command | workspace versions | chant | chant workspace versions —json | Reports the template, chant and lexicon versions of every lineage lock under a directory, by template family. |
| workspace command | workspace export | chant | chant workspace export —json | Writes the members that travel, with their lineage and records, into the export member as a workspace of their own, switching host-bound values. |
| workspace command | workspace import | chant | chant workspace import —json | Brings an export back per file against its recorded hashes, switches host values back, and records the return with the commits the files were made in. |
| workspace command | workspace admit | chant | chant workspace admit —json | Adds a return’s signers to .chant/trust.json under admitted, so the returned work reads as attested once an admin merges it. |
| workspace command | workspace build | chant | chant workspace build | Builds every chant member and example project, each under its own chant. |
| workspace command | workspace lint | chant | chant workspace lint | Runs each member’s own lint, with one SARIF run per member. |
| workspace command | workspace audit | chant | chant workspace audit | Audits each member’s files on disk with its own audit config, adding a member field to each finding. |
| workspace command | workspace member-run | chant | chant workspace member-run | The internal entry one member’s process runs under when a per-member command fans out; not for readers. |
| member kind | chant | chant | declaration.schema.json, workspace-kinds.schema.json | A chant project, with a chant.config.ts or chant.config.json in its directory. |
| member kind | workspace | chant | declaration.schema.json, workspace-kinds.schema.json | A nested workspace with its own declaration, read by the outer one only through its own chant workspace graph and never written. |
| member kind | other | chant | declaration.schema.json, workspace-kinds.schema.json | A directory chant does not read; the entry says why in because. |
| member kind | design | chant | declaration.schema.json, workspace-kinds.schema.json | A data member holding the design artifacts the workspace owns; chant reads its files for record pins and builds nothing. |
| member kind | examples | chant | declaration.schema.json, workspace-kinds.schema.json | An example group: every chant project its glob matches is built and linted. |
| record kind | decision | chant | docs/design/decisions/decision.kind.mjs, decision.schema.json | The decision record chant’s own design and the reference workspace use; the intent graph reads decisions as core nodes. reference/decision-kind specifies it, and a plugin carries a copy (ws-064). |
| record kind | work | chant | reference-workspace/work/work.kind.mjs, work.schema.json | A work item: a record with needs and implements links that people and agents share as one queue with no server. records gives each one ready and blockedBy, and the intent graph reads work items as core nodes (#2683). jhgaylor/chud#78 makes units work items. |
| record kind | answer | chant | reference-workspace/answers/answer.kind.mjs, answer.schema.json | An answer to a decision point: proposed when a model gave it, answered by a table or a quorum, escalated when people must; one per point, declaration and inputs (ws-058, #2739). |
| record kind | contract | chant | reference-workspace/design/contracts/contract.kind.mjs, contract.schema.json | An acceptance criterion made formal: its criteria, and its check pinned by hash. Drafted, approved by its reviewers, retired; a work item names the contract it builds, and the commits that serve it cite it as Chant-Record: contract:<id> (#3148, ws-082). |
| record kind | unit | plugin | a record kind file and its schema that a workspace pins from a third party, passed with —kind | A unit of work, joined to the commits it produced. |
| record kind | evidence | chant | reference-workspace/design/evidence/evidence.kind.mjs, evidence.schema.json | The result of one run of a contract’s check on a tree, named for the SHA-256 of its bytes and written by records new; a work item cites it as evidence for a criterion (#3148, ws-082). |
| record kind | driver | chant | reference-workspace/design/drivers/driver.kind.mjs, driver.schema.json | A record that groups contracts under one intent, with its design notes in the body (#3148, ws-082). |
| record kind | session | chant | reference-workspace/design/sessions/session.kind.mjs, session.schema.json | A review session with its agenda, attendance and the verdicts it produced on decisions, contracts and drivers, sealed on close; chud’s numbered session files, such as sessions/S-0001.json, are the shape it started from (#2673), and studio’s design sessions converge on it (#3148, ws-082). |
| member link kind | output | chant | graph.schema.json, check.schema.json | A consumer names a producer’s output, matched exactly; the default member link kind. |
| member link kind | telemetry | chant | graph.schema.json, check.schema.json | A consumer sends its telemetry to a pipeline or exporter of the producer’s collector, with the protocol it states checked against the target (#2558). |
| record link kind | asset | chant | graph.schema.json | A current record pins a file by hash. |
| record link kind | constrains | chant | graph.schema.json | A current record governs a member or a workspace path. |
| intent node kind | region | chant | intent.schema.json | The path, and optional line range, the intent graph is over. |
| intent node kind | file | chant | intent.schema.json | A file under a directory region, marked when it is a declared generated file. |
| intent node kind | member | chant | intent.schema.json | The member a region, file or link belongs to. |
| intent node kind | commit | chant | intent.schema.json | A commit that touched the region, with its trailers and provenance level. |
| intent node kind | unit | plugin | intent.schema.json | A unit of work a plugin’s commitJoins tied to a commit. |
| intent node kind | contract | plugin | intent.schema.json | A contract a plugin’s commitJoins tied to a unit or commit. |
| intent node kind | evidence | plugin | intent.schema.json | Evidence a plugin’s commitJoins tied to a contract or unit. |
| intent node kind | decision | chant | intent.schema.json | A decision record that constrains the region, with its state, provenance and reviews. |
| intent node kind | work | chant | intent.schema.json | A work item that constrains the region, or that one there implements, needs or addresses, with its state, ready and blockedBy (#2683). |
| intent node kind | artifact | chant | intent.schema.json | A file a decision pins, with its pin state. |
| intent node kind | link | chant | intent.schema.json | A member link touching the region’s member. |
| intent node kind | finding | chant | intent.schema.json | A finding with a closed code and the nodes it concerns. |
| intent node kind | run | chant | intent.schema.json | An agent run that made a commit in the walk, from the run ledger: its harness, model, principal, work item, tokens and cost, or recorded false when only a trailer names it (#3033). |
| intent edge kind | constrains | chant | intent.schema.json | A decision or work item governs a region, file, member, contract or issue, at a named granularity. |
| intent edge kind | pins | chant | intent.schema.json | A decision pins an artifact, with the pin’s state. |
| intent edge kind | touched-by | chant | intent.schema.json | A region was changed by a commit, with the lines touched. |
| intent edge kind | produced-by | plugin | intent.schema.json | A commit was produced by a unit, as a plugin’s commitJoins says. |
| intent edge kind | serves | plugin | intent.schema.json | A unit serves a contract, as a plugin’s commitJoins says. |
| intent edge kind | supersedes | chant | intent.schema.json | A newer decision replaces an older one, derived as records derives it. |
| intent edge kind | within | chant | intent.schema.json | A commit falls inside a decision’s window, with the state decided when the decision’s own unit made it and decided-by-window when it only falls there; shown for judgment, never a finding. A commit inside a work item’s window has the state worked (#2683). |
| intent edge kind | cites-evidence | plugin | intent.schema.json | A unit, contract or decision cites evidence, contributed by a plugin’s commitJoins. |
| intent edge kind | links | chant | intent.schema.json | A consumer member links to a producer member. |
| intent edge kind | implements | chant | intent.schema.json | A work item carries out a decision (#2683). |
| intent edge kind | needs | chant | intent.schema.json | A work item waits on another work item (#2683). |
| intent edge kind | addressed-by | chant | intent.schema.json | A finding is being closed by a work item that came from it or implements the decision it concerns (#2683). |
| intent edge kind | carries | chant | intent.schema.json | A commit carries a decision or work item its Chant-Record trailer names, or the work item its Chant-Lease was taken on (#3149). |
| intent edge kind | made-by | chant | intent.schema.json | A commit was made by an agent run, joined by its Chant-Run trailer or the run’s own list of commits (#3033). |
| intent edge kind | worked-on | chant | intent.schema.json | An agent run worked on a work item, or on a record it names, as its run record says; the commits it made carry them (#3034). |
| reason code | declaration-missing | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | No chant.workspace.json or .jsonc between the directory and the git root. |
| reason code | declaration-ambiguous | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | Both chant.workspace.json and chant.workspace.jsonc exist. |
| reason code | declaration-unparseable | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | The declaration is not valid JSON, or not valid JSONC for .jsonc. |
| reason code | declaration-invalid | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | The declaration does not match its schema, repeats a name, or —member names no entry. |
| reason code | placement-invalid | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | A member or group match breaks a placement rule. |
| reason code | reader-too-old | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | The declaration’s minReader is newer than the chant reading it. |
| reason code | root-chant-required | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json | The declaration pins a chant version other than the reader’s, and that chant is not installed at the workspace root. |
| reason code | not-a-git-repository | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, evidence.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, records-since.schema.json, records.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, signers.schema.json, status.schema.json, wip-write.schema.json, wip.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.json | —at, or a ledger read, needs a git repository and there is none. |
| reason code | revision-unknown | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, changes.schema.json, check.schema.json, ci-last-green.schema.json, composites.schema.json, evidence.schema.json, graph.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, member-write.schema.json, patch.schema.json, points.schema.json, records-since.schema.json, records.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json, signers.schema.json, wip-write.schema.json, wip.schema.json | —at names no commit. |
| reason code | live-at-revision | chant | graph.schema.json | graph was given —live and —at: a live read is of the account now, not of a revision. |
| reason code | environment-invalid | chant | status.schema.json | An environment name that can’t name a ledger directory. |
| reason code | dir-missing | chant | composites.schema.json, graph.schema.json, ls.schema.json | The member’s directory does not exist. |
| reason code | unknown-kind | chant | composites.schema.json, graph.schema.json, ls.schema.json | No built-in kind or pinned package supplies the member’s kind. |
| reason code | kind-probe-failed | chant | composites.schema.json, graph.schema.json, ls.schema.json | The member’s directory is not what its kind reads. |
| reason code | no-matches | chant | ls.schema.json | An example group matches no directory holding a chant project. |
| reason code | kind-not-run | chant | composites.schema.json, graph.schema.json | The member’s kind is one the per-member commands don’t run, such as other. |
| reason code | command-failed | chant | composites.schema.json, graph.schema.json | The member’s own command exited with a failure. |
| reason code | output-unreadable | chant | composites.schema.json, graph.schema.json | The member’s command printed something that isn’t the document asked for. |
| reason code | ir-version-unsupported | chant | composites.schema.json, graph.schema.json | The member’s IR has a version this chant can’t read. |
| reason code | ledger-unreadable | chant | status.schema.json | Reading the ledger failed, so nothing from it is listed. |
| reason code | ledger-malformed | chant | status.schema.json | Some lines of the ledger aren’t release records; the rest are listed. |
| reason code | gates-no-ledger | chant | status.schema.json | The checkout has no chant/lifecycle branch, so there is no gate ledger to read. |
| reason code | gates-no-gate-ledger | chant | status.schema.json | The branch has no gate ledger for the member: no run of it has reached a gate. |
| reason code | gates-ledger-unreadable | chant | status.schema.json | Reading the member’s gate ledger failed, so no gate is listed. |
| reason code | stewards-unreadable | chant | status.schema.json | An *.op.ts file could not be imported, so a steward it declares may be missing. |
| reason code | stewards-conflict | chant | status.schema.json | A steward was dropped: its name, or an Op it lists, belongs to another steward. |
| reason code | steward-runs-unreadable | chant | status.schema.json | Reading an Op’s run ledger failed, so its last run is null. |
| reason code | record-unparseable | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | No front matter, a YAML error or a value outside the JSON subset of YAML, or for a JSON kind a file that is not one object or repeats a member name. |
| reason code | record-schema-invalid | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | The record’s front matter, or its JSON object, does not match the kind’s schema. |
| reason code | record-id-duplicate | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | Another record earlier in path order has the same id. |
| reason code | record-supersedes-unknown | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | A supersedes link names an id no record has. |
| reason code | record-supersedes-conflict | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | A second closed record supersedes a record another one already superseded. |
| reason code | record-remediates-unknown | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A remediates link names an id no record has. |
| reason code | record-remediates-not-closed | chant | intent.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A remediates link names a record that isn’t closed; a record still open is amended instead. |
| reason code | record-seal-mismatch | chant | points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | A closed record’s seal is not the whole-file seal of its text now: the record changed after it closed. |
| reason code | session-seal-mismatch | chant | points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | A closed session’s seal is not the whole-file seal of its text now: the session changed after it closed, or was sealed by the rule before #2546. |
| reason code | session-verdict-unknown-record | chant | points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json, work-evidence.schema.json | A session’s verdict names a record that none of the session kind’s subject records has. |
| reason code | asset-drift | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A file the record pins by hash has changed: its bytes no longer hash to the pinned sha256. |
| reason code | asset-missing | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A file the record pins by hash does not exist in the tree read. |
| reason code | asset-stale | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A file the record pins is unchanged at the hash a record it supersedes pinned: the decision changed and the artifact did not follow. |
| reason code | record-no-evidence | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | The record’s evidence list is empty: it cites nothing and pins no file. Information for a reviewer, never an error. |
| reason code | review-undigested | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A verdict names no digest of the text it judged. It still counts, and an amendment does not stop it counting. |
| reason code | source-transcript-drift | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | The record’s source block pins a transcript by hash, the file it names can be read here, and its bytes hash to something else: it is not the transcript the record means. |
| reason code | work-needs-unknown | chant | intent.schema.json, records.schema.json | A work record’s needs list names a work id no record has, so the item stays blocked. |
| reason code | work-implements-unknown | chant | intent.schema.json, records.schema.json | A work record’s implements list names a decision id no decision has. |
| reason code | work-needs-cycle | chant | intent.schema.json, records.schema.json | A work record needs itself through its needs links, so it can never be ready. |
| reason code | work-implements-undecided | chant | intent.schema.json, records.schema.json | A work record implements a decision whose state is not approved, such as proposed. |
| reason code | work-done-unpinned | chant | intent.schema.json, records.schema.json | A work record is done and its evidence list is empty: nothing shows the work was done. |
| reason code | work-closed-without-date | chant | intent.schema.json, records.schema.json | A work record is done or dropped and has no closing date. |
| reason code | work-done-gap-open | chant | intent.schema.json, records.schema.json | A work record is done, and the finding it came from still fires on its region. graph —intent raises it, and records does by walking that region. |
| reason code | work-acceptance-unmet | chant | check.schema.json, intent.schema.json, records.schema.json | A work record is done, and one of its acceptance criteria has no passing evidence of the verification it expects. check fails on it (WSP117). |
| reason code | work-acceptance-self-verified | chant | intent.schema.json, records.schema.json, work-evidence.schema.json | A passing manual verdict on a work record’s criterion names the record’s implementer, so it does not count: a manual verdict comes from someone else. |
| reason code | work-contract-unknown | chant | intent.schema.json, records.schema.json | A work record names a contract that no record of its kind’s contract kind has. |
| reason code | work-contract-undecided | chant | intent.schema.json, records.schema.json | A work record names a contract whose state is not approved, such as a draft. |
| reason code | work-tier-unknown | chant | intent.schema.json, records.schema.json | A work record names a builder tier that its kind’s work.tier.tiers does not list. |
| reason code | review-decider | chant | records.schema.json | The verdict is the decider’s own, and the quorum counts verdicts besides the decider’s. |
| reason code | review-agent | chant | records.schema.json | The reviewer holds the agent role in the trust policy at base. |
| reason code | review-duplicate | chant | records.schema.json | A later verdict by the same principal replaces this one. Names are compared after NFKC, trimming and lower-casing. |
| reason code | review-older-digest | chant | records.schema.json | The verdict names a digest other than the record’s text now: the record changed after the verdict. |
| reason code | review-unattested | chant | records.schema.json | An attestation policy is active at base, and the verdict carries no seal that verifies for its reviewer. |
| reason code | seal-missing | chant | records.schema.json | The verdict, or the record, carries no seal. |
| reason code | seal-signer-unlisted | chant | records.schema.json | The reviewer, or the record’s author, has no key in the signers file at base, so the seal can’t count. |
| reason code | seal-signature-invalid | chant | records.schema.json | The seal is malformed, names a signer other than the reviewer or author, or its signature does not verify over the verdict or record. |
| reason code | seal-unverifiable | chant | records.schema.json | Nothing here can say whose seal it is: there is no signers file at base, or ssh-keygen is not installed. |
| reason code | record-unattested | chant | points-write.schema.json, points.schema.json, records.schema.json | A signers file is active at base, and the record names an author whose seal does not verify: it has none, the author has no key in the file, or the signature fails. |
| reason code | change-uncovered | chant | changes.schema.json | A path the diff changes is covered by no current decided record and no open work item, by path or by its member. |
| reason code | change-out-of-scope | chant | changes.schema.json | A record in hand for the change, such as the work item it is for or a decision that item implements, lists a path the diff changes in its out_of_scope. |
| reason code | composites-no-chant-member | chant | composites.schema.json | No member of kind chant was read, so nothing declares a composite instance or a component. |
| reason code | composites-none-declared | chant | composites.schema.json | The members read declare no composite instance. |
| reason code | composites-no-component | chant | composites.schema.json | The members read declare no component, so no composite instance has one. |
| reason code | runtimes-config-unreadable | chant | composites.schema.json | The member’s chant.config.ts could not be read, so only the built-in local runtime is listed, and no environment from the config. |
| reason code | runtimes-lexicon-unreadable | chant | composites.schema.json | A lexicon the member’s config lists could not be loaded, so it is not listed as a runtime. |
| reason code | environments-none-declared | chant | composites.schema.json | The member’s chant.config.ts declares no environments, so only local and the environments in its ledger are listed. |
| reason code | environments-ledger-undeclared | chant | composites.schema.json | The member’s ledger has releases in an environment its config’s environments don’t cover, so chant run —env would refuse it and it is not listed. |
| reason code | environments-component-undeclared | chant | composites.schema.json | A component declares an environment its member’s chant.config.ts environments don’t cover, so chant run —env would refuse it and it is not listed (#3153). |
| reason code | environments-ledger-unreadable | chant | composites.schema.json | The chant/lifecycle branch exists and the member’s ledger environments could not be listed. |
| reason code | record-supersedes-pending | chant | points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records.schema.json | A supersedes link from a record whose state is weaker than the record it names, so the link has no effect yet. |
| reason code | kind-unreadable | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, runs.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.json | The record kind file is missing or could not be imported. |
| reason code | kind-invalid | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.json | The record kind file exports no recordKind, or its shape is wrong. |
| reason code | schema-unreadable | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.json | The schema file the record kind names is missing or is not JSON. |
| reason code | schema-id-mismatch | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, ls.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.json | The schema’s $id differs from the id the record kind names. |
| reason code | schema-invalid | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.json | The record schema itself does not compile. |
| reason code | location-missing | chant | changes.schema.json, evidence.schema.json, intent-record.schema.json, intent.schema.json, points-write.schema.json, points.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, records-since.schema.json, records.schema.json, work-evidence.schema.json | The records directory does not exist, in the tree or at the revision. |
| reason code | write-usage-invalid | chant | box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, run-statement.schema.json, runs-write.schema.json, wip-write.schema.json, work-evidence.schema.json, work-lease.schema.json, write-lock.schema.json | The command line lacks a value the write needs, or gives one it does not take. |
| reason code | write-input-invalid | chant | box-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-new.schema.json, runs-write.schema.json, work-evidence.schema.json | The fields given with —from or —set can’t be read, are not JSON, or are not a JSON object. |
| reason code | record-not-found | chant | points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.json | No record of the kind has the id given. |
| reason code | record-id-taken | chant | points-write.schema.json, records-new.schema.json | The id given for a new record is already used, by a record or a file name. |
| reason code | record-id-unallocatable | chant | records-new.schema.json | No id was given and none can be allocated: the records share no single prefix and —prefix names none. |
| reason code | record-path-unmatched | chant | records-new.schema.json | The file name made from the record’s id and title does not match the kind’s location. |
| reason code | record-closed | chant | points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.json | The record is in a closed state, so nothing in it changes; a new record supersedes it instead. |
| reason code | amend-id-immutable | chant | records-amend.schema.json, work-evidence.schema.json | An amendment changes the record’s id, and ids are never renumbered. |
| reason code | amend-supersede-instead | chant | records-amend.schema.json, work-evidence.schema.json | The record is approved, and the amendment changes a field the approval rule does not let change in place; a new record supersedes it instead. |
| reason code | review-unsupported | chant | records-review.schema.json | The kind’s schema has no reviews field, so its records take no review. |
| reason code | review-note-required | chant | records-review.schema.json | A dissent was given with no note: a dissent needs a reason. |
| reason code | review-sign-failed | chant | records-review.schema.json | —sign was given and no seal could be made: the key can’t be read or used, git names no ssh signing key, or ssh-keygen is not installed. |
| reason code | record-sign-failed | chant | records-amend.schema.json, records-new.schema.json, work-evidence.schema.json | —sign was given and no author seal could be made: the record names no author, the key can’t be read or used, git names no ssh signing key, or ssh-keygen is not installed. |
| reason code | record-state-not-initial | chant | records-new.schema.json | A record written through chant serve mcp gives a state other than the kind’s first: a new record opens proposed, and a person moves it on. |
| reason code | ratify-quorum-not-met | chant | records-amend.schema.json, records-new.schema.json, work-evidence.schema.json | The write puts a record in its kind’s ratified state (reviews.ratified), and the record’s quorum is not met: too few agreeing verdicts count. |
| reason code | record-conflict | chant | records-amend.schema.json, records-close.schema.json, records-review.schema.json, work-evidence.schema.json | —expect named a digest the record no longer has: another write changed it after the caller read it (#3173). |
| reason code | write-lock-timeout | chant | box-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json, write-lock.schema.json | Another write held the working tree’s write lock for longer than the write waits; the refusal names the holder (#3173). |
| reason code | write-lock-not-held | chant | box-factory-write.schema.json, box-listing-write.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json, write-lock.schema.json | CHANT_WRITE_LOCK names a batch’s lock token that no longer holds the working tree’s write lock (#3173). |
| reason code | source-harvest-not-proposed | chant | records-new.schema.json | A harvested record (source.via harvest) was written in a state other than the kind’s first: a harvest proposes, and a person decides. |
| reason code | write-scope-member | chant | box-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json | The write is to a file, or to a record kind, of a member outside the writer’s scope: an agent session writes only the members it is bound to, and writeScope.<class>.members leaves the member out. |
| reason code | write-scope-kind | chant | changes.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json | The write is to a record kind writeScope.<class>.records does not list, with a verb it does not list for the kind, or deletes a record. |
| reason code | write-scope-protected | chant | box-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json | The write is to a file writeScope.<class>.protected lists, or one under a directory it lists, outside the top-level keys or JSON Pointers the entry’s except allows (#3146, #3308). |
| reason code | principal-unidentified | chant | box-factory-write.schema.json, box-listing-write.schema.json, box-publish.schema.json, member-write.schema.json, points-write.schema.json, records-amend.schema.json, records-new.schema.json, records-review.schema.json, wip-write.schema.json, work-evidence.schema.json | chant.workspace.json at base sets identity.attribution to identified, and the write names a person by a bare name rather than a forge identity, a signer at base, or an agent, runner or service principal (#3163). |
| reason code | write-scope-class-unknown | chant | box-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json | The declaration’s writeScope at base names a principal class no pinned package supplies, and the writer is judged human, so it may be in that class; the write is refused until the package is installed at the pinned version or the entry removed (#3080). |
| reason code | agent-unknown | chant | agent.schema.json, box-factory-write.schema.json, box-listing-write.schema.json, changes.schema.json, member-write.schema.json, records-amend.schema.json, records-close.schema.json, records-new.schema.json, records-review.schema.json, work-evidence.schema.json | CHANT_AGENT, or a commit’s Chant-Agent trailer, names an agent session the declaration at base does not declare. |
| reason code | session-unknown | chant | records-review.schema.json | —session names no session of a session kind whose subjects are the record’s kind. |
| reason code | session-not-open | chant | records-review.schema.json | —session names a session in a closed state, which takes no more verdicts. |
| reason code | since-rev-unknown | chant | records-since.schema.json | —since names no commit, or a session with no opening revision and no commit that added it. |
| reason code | since-session-unknown | chant | records-since.schema.json | —since has the shape of a session id and names no commit, and no session the kind or the declaration reads has that id. |
| reason code | since-session-open | chant | records-since.schema.json | —since names a session that is still open, so the comparison runs to the working tree. |
| reason code | intent-record-unknown | chant | intent-record.schema.json, intent.schema.json | graph —intent —record names an id that no record of a decision kind read has. |
| reason code | intent-symbol-unsupported | chant | intent.schema.json | The region names a symbol, path#symbol, in a file no symbol resolver reads; a line range still works (#3034). |
| reason code | intent-symbol-unknown | chant | intent.schema.json | The region names a symbol the file does not declare in the tree read (#3034). |
| reason code | intent-symbol-ambiguous | chant | intent.schema.json | The region names a symbol that matches more than one declaration in the file; its qualified name picks one (#3034). |
| reason code | intent-why-no-decision | chant | intent.schema.json | No current decision governs the region or is carried out by what made its current lines, so why.explained is false and hud offers to record one (#3034). |
| reason code | intent-why-no-run | chant | intent.schema.json | No agent run is joined to the commits that made the region’s current lines (#3034). |
| reason code | intent-why-uncommitted | chant | intent.schema.json | Some of the region’s lines are not committed yet (#3034). |
| reason code | intent-why-run-ambiguous | chant | intent.schema.json | Some lines come from a commit several agent runs made, and no run’s recorded hunks say which wrote them (#3034). |
| reason code | patch-path-invalid | chant | patch.schema.json | workspace patch —path names a path that is not relative and inside the workspace. |
| reason code | intent-region-invalid | chant | intent.schema.json | The region’s path, or its line range, does not exist in the tree read. |
| reason code | intent-history-shallow | chant | intent-record.schema.json, intent.schema.json | The repository is a shallow clone, so the region’s history stops at the clone’s boundary. |
| reason code | intent-plugin-failed | chant | intent-record.schema.json, intent.schema.json | A kind file’s commitJoins, which joins commits to units, contracts and evidence, failed for a commit. |
| reason code | squash-unfollowed | chant | intent-record.schema.json, intent.schema.json, runs.schema.json | With —follow-squash, a squash commit’s pull request ref is not in the clone and could not be fetched from origin, so its original commits are not followed; the read keeps its answer (#3035). |
| reason code | box-credential-declared | chant | check.schema.json | A file in a box member’s directory carries a literal secret: a credential’s shape, or a literal where a credential goes. A variable or secret-manager reference is not one. |
| reason code | box-capability-unbrokered | chant | check.schema.json | A capability in a member’s box block names no broker, so the box would hold its credential. |
| reason code | box-isolation-collision | chant | check.schema.json, member-write.schema.json | Two boxes on one host resolve to the same port, state path or cookie name, or two ports in one box share an offset. |
| reason code | box-isolation-literal | chant | check.schema.json, member-write.schema.json | A host’s stateRoot or a box’s state entry is a literal machine path instead of one derived from an environment reference and the box’s name. |
| reason code | diagram-source-missing | chant | check.schema.json | A declared diagram names a source, and it does not exist in the tree read. |
| reason code | diagram-render-missing | chant | check.schema.json | A declared diagram’s render does not exist in the tree read. |
| reason code | diagram-render-drift | chant | check.schema.json | A declared diagram records a sourceHash, and the source’s bytes now hash to something else: the render is stale for its source. |
| reason code | box-fountain-callback-undeclared | chant | check.schema.json | A box member builds a fountain Box, whose persistent sandbox fountain gives a callback token scoped to its owner, and the member’s box block does not declare the fountain-callback capability brokered by fountain with scope owner. |
| reason code | box-intent-unknown | chant | check.schema.json | A box block names an intent, and no record of a declared kind named decision has that id. |
| reason code | box-intent-unconstrained | chant | check.schema.json | The decision record a box names as its intent constrains no member or path of this workspace: no member: entry for a declared member and no path: entry at, above or inside one’s directory. |
| reason code | box-none | chant | graph.schema.json, status.schema.json | No member’s box block declares services, so the workspace has no box for a host to plant. |
| reason code | box-several | chant | graph.schema.json, status.schema.json | More than one member’s box block declares services, and a planted workspace runs one box. |
| reason code | rotation-unparseable | chant | signers.schema.json | The rotation file beside the signers file is not JSON. |
| reason code | rotation-invalid | chant | signers.schema.json | The rotation file does not match its shape: schema 1, a version, the previous set’s digest, a threshold and signatures. |
| reason code | rotation-previous-mismatch | chant | signers.schema.json | The rotation names a previous digest other than the set it replaces, as a rollback to an older set does. |
| reason code | rotation-threshold-unsatisfiable | chant | signers.schema.json | The new threshold is more than the number of distinct signers in the new set, so no later rotation could meet it. |
| reason code | rotation-missing | chant | signers.schema.json | The signer set or its threshold changed and no rotation file signed by the set before it came with the change. |
| reason code | signers-removed | chant | signers.schema.json | The signers file was removed. Commits merged before the removal keep the set they were judged by; nothing after it verifies. |
| reason code | rotation-first-version | chant | signers.schema.json | The first signer set’s rotation file names a version other than 1, or a previous digest. |
| reason code | rotation-version-skew | chant | signers.schema.json | The rotation names a version other than the one after the set it replaces, as a replayed or skipped rotation does. |
| reason code | signers-file-missing | chant | signers.schema.json | There is no signers file at the base revision, so there is no signer history to read. |
| reason code | rotation-threshold-not-met | chant | signers.schema.json | Fewer distinct signers of the set before signed the rotation, in the chant-signers namespace, than that set’s threshold. |
| reason code | trust-policy-unreadable | chant | evidence.schema.json, runs-write.schema.json | The trust policy at base can’t be read, or its signer history is broken, so no runner key is trusted. |
| reason code | evidence-statement-invalid | chant | evidence.schema.json | The payload is not an in-toto Statement v1 with chant’s runner-evidence predicate, or has a field the predicate does not define. |
| reason code | envelope-invalid | chant | evidence.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json | The file is not a DSSE envelope: payloadType, payload in canonical base64, and signatures with keyid and sig. |
| reason code | envelope-untrusted | chant | evidence.schema.json, run-statement.schema.json, runs-write.schema.json, runs.schema.json | No signature in the envelope verifies against a runner key the policy at base lists. |
| reason code | envelope-unreadable | chant | evidence.schema.json, runs-write.schema.json | The —envelope file can’t be read, or is not JSON. |
| reason code | evidence-runner-mismatch | chant | evidence.schema.json | The statement names a runner other than the one whose key signed it. |
| reason code | evidence-payload-type | chant | evidence.schema.json | The envelope’s payload type is not application/vnd.in-toto+json. |
| reason code | runner-key-unlisted | chant | evidence.schema.json, runs-write.schema.json | The policy at base lists no runner with the key given to evidence sign or runs sign. |
| reason code | runner-key-invalid | chant | evidence.schema.json, runs-write.schema.json | The key given to evidence sign or runs sign is not an Ed25519 private key in PEM. |
| reason code | runner-key-is-signer | chant | evidence.schema.json, runs-write.schema.json | The key given to evidence sign or runs sign is a person’s key in the signers file. Evidence and run statements are signed by a service or CI identity. |
| reason code | lock-invalid | chant | check.schema.json | The lineage lock can’t be read. |
| reason code | manual-step-open | chant | check.schema.json | A scope in the lineage lock has an open manual step. |
| reason code | work-kind-missing | chant | work-evidence.schema.json, work-history.schema.json, work-lease.schema.json | No work kind to find the item in: —kind names a kind with no work block, or the declaration names no work kind. |
| reason code | work-kind-ambiguous | chant | work-evidence.schema.json, work-history.schema.json, work-lease.schema.json | More than one declared work kind has a record with the id, so —kind must name one. |
| reason code | work-item-unknown | chant | changes.schema.json, work-evidence.schema.json, work-history.schema.json, work-lease.schema.json | No work record has the id, so there is nothing to lease. |
| reason code | work-item-closed | chant | work-evidence.schema.json, work-lease.schema.json | A claim on a work item in a closed state, such as done or dropped: there is no work left to claim. |
| reason code | work-criterion-unknown | chant | work-evidence.schema.json | The work record lists no acceptance criterion with the id the evidence names, or its kind has no acceptance criteria. |
| reason code | lease-held | chant | work-evidence.schema.json, work-lease.schema.json | Someone holds a live lease on the work item: another worker, or, for a claim, the same one. |
| reason code | lease-not-held | chant | work-evidence.schema.json, work-lease.schema.json | Nobody holds a live lease on the work item: it expired, was released or was never claimed. |
| reason code | lease-token-mismatch | chant | work-evidence.schema.json, work-lease.schema.json | The live lease on the work item carries another fencing token than the one given. |
| reason code | lease-race | chant | work-lease.schema.json | Another writer changed the lease between this command’s read and its write. |
| reason code | lease-push-rejected | chant | work-lease.schema.json | The remote refused the lease push: another clone claimed the item first, or the remote could not be reached. |
| reason code | run-exists | chant | runs-write.schema.json | runs start or runs record was given a run id the ledger already has. |
| reason code | run-unknown | chant | run-statement.schema.json, runs-write.schema.json | runs end names a run the ledger has no start for. |
| reason code | run-ended | chant | runs-write.schema.json | runs end names a run whose end is already recorded. |
| reason code | run-not-ended | chant | run-statement.schema.json, runs-write.schema.json | runs sign or runs statement names a run with no end recorded. A statement is signed over the run’s whole record. |
| reason code | run-statement-invalid | chant | run-statement.schema.json, runs-write.schema.json, runs.schema.json | The envelope’s payload is not an in-toto Statement v1 with chant’s agent-run predicate, or has a field the predicate does not define. |
| reason code | run-statement-signer-mismatch | chant | run-statement.schema.json, runs-write.schema.json, runs.schema.json | The statement names a signer other than the runner whose key signed it. |
| reason code | run-statement-mismatch | chant | run-statement.schema.json, runs-write.schema.json, runs.schema.json | A listed runner key signed the statement, and it does not match the run’s record: another run, a record that hashes differently, or another unit, harness, model, provider or principal. |
| reason code | member-exists | chant | member-write.schema.json | member add names a member the declaration already has, with an entry other than the one given. |
| reason code | member-unknown | chant | member-write.schema.json | member remove names a member the declaration does not declare. |
| reason code | factory-member-unknown | chant | box-factory-write.schema.json | box factory set names a member the declaration does not declare. |
| reason code | factory-box-missing | chant | box-factory-write.schema.json | box factory set names a member whose entry declares no box block, so it has no factory. |
| reason code | listing-member-unknown | chant | box-listing-write.schema.json | box listing set names a member the declaration does not declare. |
| reason code | listing-box-missing | chant | box-listing-write.schema.json | box listing set names a member whose entry declares no box block, so it has no listing. |
| reason code | listing-cover-invalid | chant | box-listing-write.schema.json | The cover can’t be read, is not a PNG, JPEG or WebP picture, is larger than 5 MiB, has a path outside the workspace, or has an extension other than its picture format’s. |
| reason code | publish-member-unknown | chant | box-publish.schema.json | box publish names a member the declaration does not declare. |
| reason code | publish-none | chant | box-publish.schema.json | box publish names a member whose box block names no publisher, or which declares no box block. |
| reason code | publish-refused | chant | box-publish.schema.json | The box’s publisher refused (it exited 2): nothing was published, and its message says why. |
| reason code | publish-failed | chant | box-publish.schema.json | The box’s publisher could not be run, failed (a nonzero exit other than 2) or ran out of time; its message says what it had done. |
| reason code | publish-answer-invalid | chant | box-publish.schema.json | The box’s publisher exited 0 and printed no JSON object, or one box-publish.schema.json does not allow. |
| reason code | publish-unrecorded | chant | box-publish.schema.json | The commit the publisher named is not in the repository, or lacks the apply record of ws-075. |
| reason code | wip-no-branch | chant | wip-write.schema.json | HEAD is detached, or names a branch with no commit yet, so there is no branch to keep work in progress for. |
| reason code | wip-none | chant | wip-write.schema.json | wip restore was given no snapshot, and the branch has none under refs/chant/wip/<branch>. |
| reason code | wip-snapshot-unknown | chant | wip-write.schema.json | wip restore names something that is not a work-in-progress snapshot chant took. |
| reason code | wip-branch-other | chant | wip-write.schema.json | wip restore names a snapshot taken on another branch than the one checked out. |
| reason code | wip-race | chant | wip-write.schema.json | Another writer moved refs/chant/wip/<branch> between this command’s read and its write. |
| reason code | wip-policy-none | chant | wip-write.schema.json | wip push or wip fetch was run, and no box block declares replicate, so there is no remote. |
| reason code | wip-remote-unknown | chant | wip-write.schema.json | The replicate policy names a git remote the checkout does not have; the host adds it, with its credential, before chant pushes. |
| reason code | ci-green-undeclared | chant | ci-last-green.schema.json | The declaration has no ci.green block, so chant does not know which check runs make a commit green. |
| reason code | ci-branch-unknown | chant | ci-last-green.schema.json | The checkout has no ref for the branch ci.green names: neither the remote-tracking branch nor a local one. |
| reason code | runs-no-ledger | chant | runs.schema.json | The checkout has no chant/lifecycle branch, so there are no agent runs to read. |
| reason code | runs-ledger-malformed | chant | runs.schema.json | Some lines of the agent run ledger aren’t run events; the rest are read. |
| reason code | answer-points-unreadable | chant | intent.schema.json, points-write.schema.json, points.schema.json, records.schema.json | The points file the answer kind names can’t be read, or is not valid. |
| reason code | answer-point-unknown | chant | intent.schema.json, points-write.schema.json, points.schema.json, records.schema.json | The answer’s point is not declared in the points file the answer kind names. |
| reason code | answer-point-changed | chant | intent.schema.json, points-write.schema.json, points.schema.json, records.schema.json | The point’s declaration changed since the question was asked, so the answer is to an older version of the question. |
| reason code | points-undeclared | chant | points-write.schema.json | No record kind with an answers block is declared, or given with —kind, so there is no points file to ask. |
| reason code | points-invalid | chant | points-write.schema.json, points.schema.json | The points file an answer kind names can’t be read, or does not match decision-points.schema.json and the rules checked in code. |
| reason code | point-unknown | chant | points-write.schema.json | No points file declares the point asked, or the one an answer names. |
| reason code | point-inputs-invalid | chant | points-write.schema.json | The inputs given to an ask are not a JSON object of the point’s declared inputs. |
| reason code | point-candidates-invalid | chant | points-write.schema.json | An ad-hoc point was asked without —candidates, a declared point with them, or they are not a question and criteria of the point’s question type (#3403). |
| reason code | point-decider-failed | chant | points-write.schema.json | A model decider that fails closed (unreachable: fail) could not answer, so the ask wrote nothing. |
| reason code | answer-not-candidate | chant | points-write.schema.json | The people’s answer is not one of the question’s candidates. |
| reason code | quorum-not-met | chant | points-write.schema.json | Too few of the people who answered count toward the point’s quorum: distinct, not holding the agent role, not the steward that asked, and holding one of its roles when it names any. |
| reason code | answer-in-steward-turn | chant | points-write.schema.json | The answer was given during a steward’s turn, or by a process it started: a steward never answers a decision point, and a person answers it through hud or at a shell. |
| reason code | answer-not-answered | chant | points-write.schema.json | points retract names a question that has no answer to retract: it is escalated or proposed, and people answer it instead (#3351). |
| reason code | answer-field-unsupported | chant | points-write.schema.json | The answer kind’s copy of point-answer.schema.json predates a field the write needs, a note, a retraction or an ad-hoc question’s asked, and chant refuses rather than drop it (#3351, #3403). |
| finding code | intent-commit-undecided | chant | intent.schema.json | A commit changed the region when no decision constrained it at path granularity. |
| finding code | intent-commit-bare | chant | intent.schema.json | A commit names no unit, carries no record through its Chant-Record or Chant-Lease trailer, and has no pull request and no decision covering the region at its time. |
| finding code | intent-pin-drifted | chant | intent.schema.json | A decision’s pinned artifact no longer hashes to the pin. |
| finding code | intent-pin-missing | chant | intent.schema.json | A decision’s pinned artifact does not exist in the tree read. |
| finding code | intent-pin-stale | chant | intent.schema.json | A current decision pins an artifact at the hash a record it supersedes pinned, and the artifact has not changed since: the decision moved on and the artifact did not. |
| finding code | intent-artifact-unpinned | chant | intent.schema.json | An artifact decisions in the graph pinned, which no current decision pins. |
| finding code | intent-decision-superseded-live | chant | intent.schema.json | Every decision constraining the region is superseded. |
| finding code | intent-decision-provisional | chant | intent.schema.json | The current decisions constraining the region are all in states their kind does not close, such as decided. |
| finding code | intent-decision-contested | chant | intent.schema.json | A current decision constraining the region has an open concern: a dissent neither addressed nor withdrawn. |
| finding code | intent-constraint-coarse | chant | intent.schema.json | The region is constrained only through its member, not by path. |
| finding code | intent-constraint-lost | chant | intent.schema.json | A decision’s path constraint names a path that does not exist in the tree read. |
| finding code | intent-evidence-unpinned | chant | intent.schema.json | A decision’s evidence has no hash: a URL, or a path with no sha256. |
| finding code | intent-trailer-unverified | chant | intent.schema.json | A commit carries a trailer a plugin says claims authorship, and the commit is not attested. |
| finding code | intent-region-unconstrained | chant | intent.schema.json | No decision constrains the region at any granularity. |
| finding code | intent-decision-unimplemented | chant | intent.schema.json | A decided decision constrains the region, no work item that is not dropped implements it, and no commit falls in its window. |
| finding code | intent-work-blocked | chant | intent.schema.json | A work item constraining the region has commits in its window while a work item it needs is not done. |
| finding code | intent-work-open-decided-code | chant | intent.schema.json | Commits in the region are a decision’s own work while the work item implementing that decision is still open. |
| finding code | intent-commit-join-conflict | chant | intent.schema.json | A commit joined to an agent run by its Chant-Run trailer or the run’s record has the patch-id of a commit another run recorded, so it is not joined to that run by content (#3036). |
| WSP check | WSP001 declaration-unreadable | chant | check.schema.json | The declaration can be read: it parses, matches the schema and keeps the placement rules. |
| WSP check | WSP002 kinds-unreadable | chant | check.schema.json | Every pinned package’s kinds and principal classes can be read: it is installed at the pinned version, its ./workspace-kinds file is valid kind data, and its ./workspace-principals file is valid class data. |
| WSP check | WSP003 kind-unknown | chant | check.schema.json | Every member’s kind is built in or supplied by a pinned package, and so is every principal class writeScope names (#3080). Unknown kinds and classes fail closed. |
| WSP check | WSP004 member-dir-missing | chant | check.schema.json | Every member’s directory exists. |
| WSP check | WSP005 kind-probe-failed | chant | check.schema.json | Every member’s directory is what its kind reads, such as a chant config for a chant member, and its fields are ones its kind declares, of the declared types (#3151). |
| WSP check | WSP006 kind-probe-tie | chant | check.schema.json | No directory is claimed by two kinds of the same highest precedence. Ties fail. |
| WSP check | WSP007 kind-outranked | chant | check.schema.json | When several kinds claim a member’s directory, the declared kind is the one the precedence order picks. |
| WSP check | WSP008 other-claimed | chant | check.schema.json | No other member’s directory is claimed by a registered kind’s probe. |
| WSP check | WSP009 other-member | chant | check.schema.json | A member of kind other is one chant does not read. It is reported so that it stays a decision. |
| WSP check | WSP010 group-empty | chant | check.schema.json | Every example group matches at least one chant project. |
| WSP check | WSP011 check-settings-invalid | chant | check.schema.json | The declaration’s checks and suppress settings name known, configurable WSP ids. |
| WSP check | WSP071 ownership-stack-shared | chant | check.schema.json | No two chant members set the same ownership.stack. Ownership markers carry no member name, so the stack tells members’ resources and receipts apart. |
| WSP check | WSP072 flat-ledger-environment-shared | chant | check.schema.json | No two members that write the flat ledger layout (the root member, and members on a chant older than 0.81.0) share an environment name. |
| WSP check | WSP073 ledger-settings-unread | chant | check.schema.json | A chant member’s ownership and environments could not be read from its config without running it, so WSP071 and WSP072 could not compare it. |
| WSP check | WSP081 generated-declared-twice | chant | check.schema.json | No two members record the same generated file, so no member’s regeneration overwrites another’s pipeline. |
| WSP check | WSP082 generated-outside-member | chant | check.schema.json | A member’s recorded generated files sit in its own directory, or are forge CI files at the fixed paths forges read. |
| WSP check | WSP083 linked-environments-disjoint | chant | check.schema.json | Linked members share at least one environment name, matched exactly, when both name any. |
| WSP check | WSP091 link-target-unknown | chant | check.schema.json | Every member link names another member of the workspace. A link to an unknown name, an example group or the consumer itself fails closed. |
| WSP check | WSP092 link-kind-unknown | chant | check.schema.json | Every member link’s kind is one chant knows. Unknown link kinds fail closed; output is the default, and telemetry is the other. |
| WSP check | WSP093 link-output-missing | chant | check.schema.json | Every member link names an output its producer exposes, matched exactly. A producer that renames an output fails this for every consumer that links to the old name. |
| WSP check | WSP094 link-unresolved | chant | check.schema.json | A member link whose producer’s outputs can’t be read in source is kept, unresolved, and reported. |
| WSP check | WSP095 join-ambiguous | chant | check.schema.json | No inferred join is ambiguous: a parameter that matches outputs of two producers (or two outputs of one) needs a declared link saying which. |
| WSP check | WSP096 link-duplicate | chant | check.schema.json | A link is stated once: no consumer lists the same member and output twice. |
| WSP check | WSP097 outputs-not-listable | chant | check.schema.json | An entry lists outputs only when its kind takes them from the entry: other, or a kind from a package. A chant member’s outputs are read from its source, and a nested workspace exposes none. |
| WSP check | WSP098 link-protocol-misplaced | chant | check.schema.json | A link states a protocol only when it is a telemetry link: protocol is the OTLP protocol the consumer sends to the producer’s collector, and no other link kind has one. |
| WSP check | WSP101 generated-drift | chant | check.schema.json | A generated file is what its generator writes. Declared generators run only with —generated. |
| WSP check | WSP102 generated-missing | chant | check.schema.json | Every declared generated file exists. |
| WSP check | WSP103 generator-failed | chant | check.schema.json | A declared generator runs, exits 0 and writes the file. |
| WSP check | WSP104 generated-hand-written | chant | check.schema.json | An entry kept by hand is reported with its reason, and its generator is not run. |
| WSP check | WSP105 generated-not-compared | chant | check.schema.json | An entry not compared with its generator’s output is reported with the reason. |
| WSP check | WSP106 generated-source-missing | chant | check.schema.json | Every source a generated entry names exists. |
| WSP check | WSP111 record-asset-drift | chant | check.schema.json | Every file a current record pins by hash still hashes to the pinned sha256. A changed file asks for the record to be revisited. |
| WSP check | WSP112 record-asset-missing | chant | check.schema.json | Every file a current record pins by hash exists. |
| WSP check | WSP113 record-asset-stale | chant | check.schema.json | No current record pins a file at the same hash as a record it supersedes while the file is unchanged since: when a decision changes, the artifacts it rests on follow. |
| WSP check | WSP114 records-unreadable | chant | check.schema.json | The records of the kind named with —kind can be read. |
| WSP check | WSP115 record-kind-unloadable | chant | check.schema.json | Every record kind the declaration names is a file that exports a valid recordKind, with the schema it names. |
| WSP check | WSP116 decision-points-invalid | chant | check.schema.json | Every answer kind the declaration names has a decision points file that matches decision-points.schema.json, with each input naming a read-contract output, pinned model ids and a chain ending in its one quorum (ws-058). |
| WSP check | WSP117 work-acceptance-unmet | chant | check.schema.json | Every done work item meets its acceptance criteria: each has evidence that names it, passed, and has the verification the criterion expects, and a manual verdict is from someone other than the implementer (#2772). |
| WSP check | WSP121 box-credential-declared | chant | check.schema.json | A box holds no credential: no file in a box member’s directory carries a literal secret, in its declarations, an env or a vault’s defaults. Variable references and secret-manager references (op://, bws://, infisical://) are not secrets. |
| WSP check | WSP122 box-capability-unbrokered | chant | check.schema.json | Every capability a box declares names the broker that holds its credential and enforces its scope. |
| WSP check | WSP123 box-isolation-collision | chant | check.schema.json | No two boxes on one host resolve to the same port, state path or cookie name, and no two ports in one box share an offset. |
| WSP check | WSP124 box-isolation-literal | chant | check.schema.json | No host’s state root and no box’s state entry is a literal machine path: state paths derive from an environment reference and the member’s name. |
| WSP check | WSP131 diagram-source-missing | chant | check.schema.json | A diagram’s source file, when it names one, exists in the tree read. |
| WSP check | WSP132 diagram-render-missing | chant | check.schema.json | A diagram’s render, when it names one, exists in the tree read. Only a mermaid or excalidraw diagram may name none. |
| WSP check | WSP133 diagram-render-drift | chant | check.schema.json | A diagram that records a sourceHash is unchanged since its render was made: the source’s bytes still hash to it. Runs no renderer. |
| WSP check | WSP125 box-fountain-callback-undeclared | chant | check.schema.json | A box member that builds a fountain Box declares the callback token fountain gives its persistent sandbox: the fountain-callback capability, brokered by fountain, with scope owner. |
| WSP check | WSP126 box-intent-unknown | chant | check.schema.json | The intent a box block names is the id of a record of a declared kind named decision, the record that says what the box is for. |
| WSP check | WSP127 box-intent-unconstrained | chant | check.schema.json | The decision record a box names as its intent constrains a member or path of this workspace, with member: and a declared member’s name or a path: entry at, above or inside one’s directory; not necessarily the box’s own member. |
| WSP check | WSP141 link-live-missing | chant | check.schema.json | With —live, a declared member link names an output its producer’s estate publishes now, matched exactly. |
| WSP check | WSP142 link-live-unresolved | chant | check.schema.json | With —live, a declared member link that could not be resolved against a live read is kept, unresolved, and reported. |
| hud view | H1 | hud | alecraso/hud | Review queue: decided records grouped by area, oldest first, each as a decision card. It reads records —current —json. |
| hud view | H2 | hud | alecraso/hud | Decision page: options side by side with rejected options kept, the supersession chain, amendment history and provenance. It reads records —json, records —at. |
| hud view | H3 | hud | alecraso/hud | Review actions: agree, dissent with a required reason, abstain and propose, each verdict a pull request under the signed-in principal. It reads records, and writes through records review and records new in a pull request. |
| hud view | H4 | hud | alecraso/hud | Quorum meter: counted and not-counted principals with reasons and open concerns. It reads the quorum in records. |
| hud view | H5 | hud | alecraso/hud | Review session: agenda, attendance, presence and follow mode, live meters and a summary of what changed at close. It reads session records, records —since <session id>; writes records new, review —session and close (#2693). |
| hud view | H6 | hud | alecraso/hud | Impact: constrained targets with their live state, and provisional dependants flagged. It reads the constrains lists in records —json, graph —kind, ls, the forge. |
| hud view | H7 | hud | alecraso/hud | Evidence drift: pin states, with the pinned and current artifact side by side. It reads the pins in records. |
| hud view | H8 | hud | alecraso/hud | Intent graph: the region at the centre, with artifacts, decisions and commits in bands and findings drawn as nodes. It reads graph —intent. |
| hud view | H9 | hud | alecraso/hud | Anchor states for constraint paths and pins, and re-anchor as an action that drafts a record. It reads graph —intent, records —constrains. |
| hud view | H10 | hud | alecraso/hud | Text from records, commits and comments goes to any agent fenced as data. It reads every document it passes on. |
| hud view | H11 | hud | alecraso/hud | Every walk answer is kept as a disposition list, so a group can review a walk without redoing it. It reads hud-side state, with the resulting records in git. |