Multiform per-form failure statuses (formstatus records, noformmatch errorcode
classes + -formerrors) are now sound suffix-viability verdicts: 'incomplete'
(viable) iff every supplied word was validly consumed as a prefix of the form
and the failure is pure exhaustion at end-of-input; anything already supplied
contradicting the form reports 'invalid'. Mechanism: viability-probe mode on
private::get_dict_form suppressing only the position-guarded pure-exhaustion
raises (count min-shortfalls, missing-required checks, adhoc option value at
end) while final validation of the consumed words stands as the soundness
backstop; multiform candidacy and parse_status's single-form formstatus record
confirm each classify-'incomplete' failure with one probe re-parse. Rendered
noformmatch form lines marked '(viable - needs more arguments)'/'(not viable)'
after the stable "form '<fid>':" anchor. Consumer contract documented in the
parse ('Multiform failure contract') and parse_status argdocs. Documented
conservatism: input ending inside a multi-member type clause reports invalid.
New testsuite formviability.test (acceptance scenarios, option position
guards, single-form record soundness, clause conservatism, message marking);
forms.test verdict pins deliberately updated (ms/idle incomplete->invalid for
type-screen rejections). punkshell 0.41.3 (patch: refined multiform error
classification/reporting at the shell surface).
Goal G-152 activated (user-directed) and flipped achieved 2026-08-02 with
acceptance verified via runtests (args subtree green; full-suite parity with
stashed baseline); entry archived to GOALS-archive.md, detail file to
goals/archive/ with verification evidence; consumer pointers pushed to
G-044/G-150 notes.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
User decision: -choicecolumns back to 1 on both the rich overview and
the lean dispatch definition - the long one-line summaries make the
two-column layout too wide without table cell wrapping. Revisit
-choicecolumns 2 when cell wrapping is implemented; the '## FORM'
header-line dropping in the overview cells is accepted. Max render
width drops ~250 -> 168 columns. help/colour suites 16/16.
punkshell 0.41.2.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed: bare 'make.tcl help' / 'make.tcl' / '-help' now render a
per-subcommand overview in the repl 'i info' style - each cell carries
the subcommand's one-line summary plus its own auto-generated
bracket-notation synopsis line(s) (per-form lines for the multi-form
tool/buildsuite), grouped by the existing SUBGROUPS in two columns.
Stock punk::args machinery: rich -choicelabels built at lazy resolve
time by ::punkboot::argdoc::overview_labels (punk::args::synopsis
-noheader per subcommand id, '## FORM' headers dropped for compactness)
+ -choicecolumns 2, hung on the separate (script)::punkboot.overview id
so the label cost (a few ms) is paid only when the top-level help
renders - the lean (script)::punkboot definition remains the dispatch
surface (now also -choicecolumns 2 for its unknown-subcommand error
render) and is deliberately excluded from the capability probe. Plain
PUNKBOOT_PLAIN fallback help unchanged. maketclhelp toplevel test
updated to pin the overview (tool/buildsuite form synopsis lines,
ESC-free); help/colour/bakelist suites 25/25. punkshell 0.41.1.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed pair completing the declaration-authoritative arc:
1. bake/bakelist kitnames are -choicerestricted 1: the configured kit
names + @group selectors (computed into the declaration when the mapping
parses at definition time) now GATE at dispatch - an unknown kit is a
punk::args choice error before any build (the no-build guarantee moves
to the gate), unambiguous prefixes resolve to canonical names, and the
dry-run help mirrors the verdict ('help bake punk91 -confirm 0' is now
a pointed choice error naming '-confirm' rather than a value-swallow).
The handlers' own validation remains the backstop where declarations
cannot gate: PUNKBOOT_PLAIN degraded mode, and a definition-time
mapping-read failure (the choices clause is omitted entirely - no gate).
2. All kit-mapping consumers share ONE memoized parse per invocation:
new punkboot::lib::mapvfs_model front door (locate+parse, keyed by
resolved mapfile/rtbase/sourcefolder/target - a PUNK_MAPVFS_CONFIG
override keys its own entry) consumed by the definition-time choices
(now passing the real bin/runtime rtbase - mapvfs_parse is pure, so the
models are interchangeable) and the five handler sites (selective bake,
main bake, bakelist, vfslibs %platform% derivation, check smoke
listing). Success is cached; a throwing parse deliberately is not, so
each caller diagnoses fresh.
maketclbakelist.test: unknown-name pins updated to the dispatch choice
error + PUNKBOOT_PLAIN backstop variants (runner gains envoverrides);
maketclhelp.test: bake dry-run case now pins the choice-gate rejection
and 'help bake punk91' acceptance. Full punkexe subtree 114 tests, 0
fail. punkshell 0.41.0.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed: the bare-action carve-out is removed - 'make.tcl help
buildsuite build' now falls through to the punk::args diagnosis like any
other incomplete line (exit 1). Empirically the error table carries the
form's argument rows alongside the all-forms synopsis and per-form
reasons, so the diagnosis IS the form documentation and the carve-out
bought nothing but an exit code. Accepted lines gain a one-line
received-args report after the usage table, built from the parse
result's 'received' key (defaulted opts omitted):
'dry-run: line accepted (form build) - action = build | -test = 0 |
toolname = punkzip'. This makes punk::args' value-swallow visible
('kitname = punk91 -confirm 0' for the out-of-order line) - an interim
make.tcl-side clue until punk::args grows an annotated success render.
bake/bakelist kitname -choicerestricted 0 confirmed deliberate
(discoverability-only choices; handler validation authoritative;
define-time mapvfs parse best-effort). maketclhelp.test pins updated;
help/tool/colour suites 20/20. punkshell 0.40.3.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed second refinement: 'make.tcl help <subcommand> ?arg ...?'
(and '<subcommand> ?arg ...? -help') now parses the words through the
subcommand's punk::args declaration exactly as dispatch would (form
auto-selection, choice prefixes). An accepted line renders the matched
action's single-form usage ('help tool build -test 0 punkzip', 'help
tool bu'); a rejected line (unknown action, option-first line, unknown
flag in option position) emits the same punk::args noformmatch
diagnosis dispatch gives - all-forms synopsis plus per-form reasons -
on stderr, exit 1: the error table is itself usage documentation, so
help verdicts mirror dispatch verdicts. Carve-out: a bare action
word/prefix renders its form directly, since forms with required
values ('buildsuite build' needs a suitename) would fail a strict
dry-run. Replaces 0.40.1's leading-word-only selection and option-first
whole-usage fallback. Empirical punk::args findings recorded (archived
goal file + probes): flag-like words at/after the first value position
parse as values; -regexprepass/-regexprefail are honoured during form
matching (a '-regexprefail {^-}' value disambiguates flag-led lines -
the punk::auto_exec::hash latent selection ambiguity). maketclhelp.test
pins updated; help/tool/colour suites 20/20. punkshell 0.40.2.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed reshape of the help-depth interface: 'make.tcl help
<subcommand> ?arg ...?' (and '<subcommand> ?arg ...? -help') now accepts
the subcommand's command line as typed and renders the usage most
specific to it - 'make.tcl help tool build -test 0 punkzip' shows the
tool build form via its leading action word (the same literal-leader
word punk::args form auto-selection keys on at dispatch). Words after
the action are tolerated and ignored; an option-first line falls back to
the whole subcommand's usage; single-form subjects (e.g 'help bake
punk91 -confirm 0') ignore the words entirely; an unknown action word on
a multi-form subject stays a pointed exit-1 usage error. The 0.40.0
numeric form-index acceptance ('help tool 2') is withdrawn as
unintuitive. Probe recorded: the repl 'i' (punk::ns::cmdhelp) tolerates
trailing argument words but does not form-narrow flat multi-form
commands - make.tcl help now exceeds it there. maketclhelp.test pins
updated (12 tests, all green + tool/colour suites); punkshell 0.40.1.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
punkcheck-managed copies refreshed by 'make.tcl modules' - vendor layouts
basic + project-0.1 and the modpod-shipped template payload, all
byte-identical to src/make.tcl.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
tool/buildsuite/help are multi-form punk::args definitions (one @form per
action, literal single-choice action leaders + choicelabels): 'help tool' /
'help buildsuite' render one synopsis line per action; 'make.tcl help
<subcommand> <action>' - equivalently '<subcommand> <action> -help', or a
0-based form index ('help tool 2') - renders that action's single-form
usage; unknown actions and out-of-range indexes are pointed punk::args
errors (exit 1). tool dispatch parses through the definition (unknown
actions/flags: exit-1 usage errors). User-approved deviation: the declared
positional model puts options before tool names ('tool build -test 0
<name> ...'); docs/agent guidance updated to match and a flag-shaped tool
name earns a stderr hint; the PUNKBOOT_PLAIN degraded scan keeps the
historic flag-anywhere parse. buildsuite driver-arg passthrough unchanged.
G-144 consumer follow-through: all 17 per-subcommand @form -synopsis
overrides retired (automatic @cmd -name bracket-notation synopses;
top-level make.tcl override kept deliberately). Pinned by new
punkexe/maketclhelp.test (12 tests); full punkexe subtree green (114
tests, 0 fail). Goal flipped to achieved and archived; punkshell 0.40.0.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
Auto-generated synopses for (script)-prefixed constructed definition ids
now lead with the declared @cmd -name (the invocation name - e.g
'make.tcl modules' for (script)::punkboot::modules) instead of the raw
id, across punk::args::synopsis full/summary renders and the
usage/arg_error synopsis sections that funnel through them (punk::args
0.12.7 -> 0.13.0).
The fallback is gated on the (script) prefix only (user-confirmed
narrowing): (autodef) ids are excluded - their id-minus-tag IS the
invocation (arg_error's existing tag strip surfaces it) while their
@cmd -name is a display label ('destroy', 'Object: ::x');
(shared)/(package)/(default)/(widgetcommand) doc ids declare no
invocation-style -name today and render the id as before. Real command
ids render byte-identical (full args testsuite passes with no pin
updates). Six new synopsis.test pins: (script) full/summary/multiform/
surfaces, no-name constructed id, autodef unchanged, real-id
byte-identical.
Goal tiers: index entry archived to GOALS-archive.md, detail file moved
to goals/archive/ (G-143's pending-tense Related line rewritten to
reflect achievement + follow-through pointer: make.tcl's @form
-synopsis overrides are now optional, retirement under G-143 or a
follow-on edit). Docs: @form -synopsis directive known-case text,
synopsis -help, src/modules/AGENTS.md ergonomics bullet. Project
0.39.5 -> 0.39.6 (patch: latent capability, no shipped definition
renders differently today).
Bootsupport refresh (make.tcl modules + bootsupport): snapshot gains
args-0.13.0.tm and picks up two lagging source syncs -
mix/commandset::layout 0.2.0 -> 0.3.0, mix/commandset::project
0.4.0 -> 0.4.1, and the shellfilter 0.2.4 G-145 comment; superseded
copies pruned.
Assisted-by: harness=opencode; primary-model=openrouter/moonshotai/kimi-k3; api-location=openrouter.ai
Layout .gitignore payloads are now stored inert as gitignore.in and
materialized to .gitignore at project generation, ending the
self-censoring-template hazard (live nested .gitignore files silently
untracked template content in git while fossil managed it fine):
- punk::mix::commandset::layout 0.3.0: layout_materialize_renames map;
layout_stage_chain renames inert payloads after composing all overlay
layers (.anti markers keep targeting store names); layout_materialize
withholds the in-place fast path from inert-payload folders so the
store is never renamed; inert+live name conflict errors loudly
- make.tcl thin-layout sync refreshes every vendor/punk layout's
gitignore.in from the canonical repo-root .gitignore (punkcheck-tracked
sync_layouts events); workflow text updated
- the four vintage payload variants eliminated as drift: all payloads
now byte-identical mirrors of root; modpod copy carried and its stale
.gitignore pruned
- materialize.test +5 G-012 characterization tests (25/25; mix subtree
71 pass / 1 known skip)
Verified end-to-end: generation from each affected layout yields a
byte-identical .gitignore (othersample .anti case yields none); root
edits propagate to payloads via make.tcl libs in both directions; the
fc1c474c force-added template files are back to ordinary git tracking
with no ignore rule matching them; modpod payload README trees are now
visible as ordinary trackable files.
Goal flipped achieved 2026-08-01 (user-confirmed; the custom/_project
acceptance clause is stale - that store level was retired by G-087
stage 5 after drafting; recorded in the archive record and detail
evidence). Reference sweep + archive moves per the flip protocol.
Project version 0.39.5.
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
The Tcl core delivers 'clear' to a transform stack before EVERY write op
(output-buffer flush-down; tclIORTrans.c ReflectOutput, gated on METH_CLEAR -
intentional and test-pinned, but under-documented: doc/transchan.n and TIP 230
scope clear to seek/read-side buffers). ::punkboot::ansistrip::transchan's
clear handler ran 'dict unset carry $chanid', discarding a split sequence's
held ESC tail at every write-chunk boundary: the next chunk's ESC-less
remainder ('0;1m', '1m') passed through unstripped as orphan fragment text in
piped usage tables, while the dropped ESC bytes kept the G-113 zero-ESC pin
green. The transform is write-only with no read-side state, so its
contract-conformant clear is a no-op - it no longer declares the op, the
per-write calls never fire, and the split-sequence carry survives every chunk
boundary. finalize still drops an end-of-stream partial sequence. No change in
textblock/punk::ansi (pre-transform stream verified well-formed during
diagnosis; exonerated).
Pin: maketclcolour.test gains maketcl_colour_help_tables_zero_remnants -
piped 'tclsh src/make.tcl help' for all 20 declared SUMMARIES subjects plus
bare 'help'/'-help', asserting exit 0, zero ESC bytes, zero orphan fragments
(two-step detector: strip complete sequences, then scan for [0-9;]+m not
preceded by ESC or an open bracket - a raw scan false-positives on ';1m' inside complete
multi-parameter SGR). Failing-first evidence: pre-fix the pin names exactly
the 5 fragmenting invocations (help, -help, help libs, help info, help
bootsupport); the 22-invocation NO_COLOR+PUNK_FORCE_COLOR pre-transform
corpus carries no legit text matching the detector.
Verified (tclsh 8.7a6, win32-x86_64): all 22 invocations byte-level clean;
PUNK_FORCE_COLOR=1 output intact (1177 complete sequences, 0 orphans); the 3
G-113 colour-policy pins pass unchanged; shell/testsuites/punkexe family (15
files, 102 tests) and shell/*** (127 tests) green, warnings pre-existing only;
'make.tcl packages' verified, layout + modpod make.tcl copies synced by the
build (punkcheck-managed outputs batched here per the carve-out).
Bookkeeping: goal flipped active -> achieved 2026-08-01, detail file archived
(goals/archive/G-145-piped-usage-ansi-remnants.md), G-056 Notes gains the
exoneration pointer; src/AGENTS.md colour bullet + src/tests/shell/AGENTS.md
suite description updated; project version 0.39.4 (patch) with CHANGELOG
entry.
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
Investigation record only - no fix yet (goal remains proposed).
Root cause: the Tcl core delivers the transform 'clear' op before every
write (output-buffer flush-down; tclsh 8.7 and 9.0.3), and
::punkboot::ansistrip's transchan handles 'clear' with 'dict unset carry'
- discarding a split sequence's held tail at every chunk boundary. The
tail's remainder (e.g. 0;1m) passes through unstripped while the held
ESC[ bytes are never emitted, so the zero-ESC pin (maketclcolour.test)
stays green while fragments leak. Evidence: pre-transform stream captured
via NO_COLOR+PUNK_FORCE_COLOR is fully well-formed (textblock/punk::ansi
exonerated; G-056 not the mechanism); the verbatim strip proc is correct
for every possible 2-chunk split and 512..8192 block sizes; an identity
logging transform under ansistrip captured the boundary byte-exactly;
minimal isolated repro on a bare file channel reproduces both the
per-write 'clear' op sequence and a fragment. Deterministic per table
geometry, matching the observed intermittency.
Upstream (TEMP_REFERENCE/tcl9 survey): per-write 'clear' is intentional,
test-pinned core behavior (ioTrans.test iortrans-7.1 "chan write, write
clears read buffers") but transchan.n and TIP 230 document it as
seek-only and read-side-scoped - an upstream documentation gap, not an
implementation bug; no existing Tcl ticket found. A write-only
transform's contract-conformant 'clear' is a no-op; fix layer recorded
in the goal file (drop 'clear' from the supported-methods list or make
it a no-op; 'finalize' keeps dropping the carry).
- goals/G-145-piped-usage-ansi-remnants.md: root cause, evidence chain,
upstream documentation status, fix layer, encoding note, repro recipes
- shellfilter: G-145 warning comment over the commented-out 'clear'
method so future refactors don't discard o_encbuf/stream state there
goals_lint clean (83 active-index goals, 62 archived).
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
Convert every ::punkboot::argdoc punk::args::define to the braced file-style
block form established for the shell/tool definitions in 7ec7da4a: -& record
continuations, -summary/-help pulled from SUMMARIES/HELPTEXTS via tstr
placeholders, shared OPT_* option fragments interpolated as ${$OPT_...}
records. The SUBOPTS/OPT_SYNOPSES/VALUES_SYNOPSES/SUBVALUES tables and the
define loop are unrolled into 16 per-subcommand blocks; buildsuite/help and
the top-level definition follow the same idiom (help gains a HELPTEXTS entry;
the top-level body moves to argdoc's TOPLEVEL_HELP variable). @normalize is
dropped: -help bodies are display fields (punk::args G-046 deferred
expansion), so the HELPTEXTS block indentation now reaches the rendered
Description verbatim - every 'make.tcl help <subcommand>' Description renders
centred like 'make.tcl help tool' instead of left-aligned.
No parsing or interface changes: option/values specs, synopses, exit codes,
prefix resolution, unknown-flag/subcommand errors, PUNKBOOT_PLAIN degraded
mode and the capability probes all verified unchanged (before/after usage
captures diffed for all 20 help subjects; shell/tool byte-identical). Narrow
usage tables widen slightly to fit the indented Description.
KITNAME_CHOICEPART persists as a namespace variable because the kitname
records interpolate it at (lazy) definition resolve time.
Docs: src/AGENTS.md make.tcl bullets updated (braced-def contract, per-block
maintenance rule); src/modules/AGENTS.md G-045 subsection re-points the
@normalize exemplar to punk.tm only and records argdoc as the braced -& +
tstr exemplar. punkshell 0.39.3 + CHANGELOG entry. Thin-layout make.tcl
copies resynced via 'make.tcl libs -confirm 0' (basic, project-0.1, modpod
templates copy - byte-identical).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
tool_install_state judges bin/<tool>.exe current/stale by comparing its
mtime against the newest file anywhere in the tool tree. Two layers kept
that exe mtime frozen at the original link time: a zig cache-hit rebuild
does not rewrite the zig-out artifact, and Tcl's 'file copy -force'
preserves the source mtime (Windows CopyFile semantics). Once any
non-build-input file (e.g. PROVENANCE.md, edited after the G-128/G-135
doc passes) was newer than that link time, the tool was reported 'stale'
permanently - repeated 'make.tcl tool build' runs (field-observed
2026-08-01) reinstalled a timestamp-identical artifact and never cleared
it.
Fix: after the install copy, stamp the installed exe with the install
time ('file mtime $exe [clock seconds]'), making the state measure what
it means - installed since the last change in the tree. Also self-heals
mtime churn from branch switches/fresh clones on the next build.
punkshell 0.39.2 + CHANGELOG entry (patch: build-tooling bug fix).
Thin-layout make.tcl copies resynced via 'make.tcl libs -confirm 0'
(basic, project-0.1, modpod templates copy - byte-identical).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
The G-112 stage-true rename (0.23.0) kept 'project' -> bakehouse and
'vfs' -> bake as transitional aliases until the 8.6 arc completed; that
arc landed with G-099 and the new shape is settled. All alias plumbing
is removed from src/make.tcl: known_commands, the pre-dispatch mapping
switch, the punk::args definitions (SUMMARIES/HELPTEXTS/SUBOPTS/
SUBVALUES/VALUES_SYNOPSES), the "deprecated aliases" help group, the
plain-help block, the workflow-text mention and the degraded-mode
kitname collection. 'vfs' now gets an unknown-subcommand usage error;
'project' prefix-resolves to the read-only 'projectversion' check under
punk::args unambiguous-prefix matching (PUNKBOOT_PLAIN degraded mode
rejects both). Also trimmed a pre-existing trailing space (line 8990)
surfaced by git diff --check via the verbatim layout copies.
Docs: src/README.md, ARCHITECTURE.md, src/AGENTS.md (alias mentions
removed; also corrected the stale layout-sync trigger claim - the
thin-layout sync runs in modules/libs/packages/bakehouse, not
bootsupport), root AGENTS.md sync-step subcommand list ('project' ->
'bakehouse'). Historical records (CHANGELOG 0.23.0 entry, goals
archives, GOALS-archive) deliberately untouched.
punkshell 0.39.1 + CHANGELOG entry (make.tcl interface change - patch
per root AGENTS.md versioning policy).
Build outputs batched per src/AGENTS.md: thin-layout make.tcl copies
resynced via 'make.tcl libs -confirm 0' (basic, project-0.1, modpod
templates copy - all byte-identical to src/make.tcl), plus the lagging
store->modpod catch-up the same run performed (modpod layout copy:
mapvfs.config removed, mapvfs.toml + vfs/README.md added).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
- new punkexe/maketclkitlocations.test (PUNK_MAPVFS_CONFIG fixtures, nothing
built): two-target one-vfs distinct locations (flat vs kits/<platform>/),
same-name two-non-native coexistence without runtime-rename, same-target
duplicate keeps <name>_<runtime>; mismatch clause referenced as G-133
regression pin (binaryarch.test + maketclpayloadcheck.test)
- mapvfs_match_outputs: a plain kit name now selects ALL matching records (one
per target) instead of the first hit - pre-G-127 uniqueness assumption removed;
filtered bakelist + selective bake cover every target of a shared name
- full punkexe subtree pass: 15 files, 101 tests, 0 failed (4 constraint skips)
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
G-024 - kit mapping converted to toml (tomlish-parsed), same-day activation->achieved:
- src/runtime/mapvfs.toml: [kit.<name>] / [group.<name>] / [scheme.<name>] tables
(header comment = user-facing spec). All 12 active line-format mappings migrated
(order preserved - identical bakelist rows vs the legacy parse); historical
comments carried over; mapvfs.config deleted here AND in the project-0.1 layout
(converted to mapvfs.toml there).
- make.tcl reader family under the unchanged G-121 model surface: mapvfs_locate
(toml > legacy; PUNK_MAPVFS_CONFIG env override = characterization seam),
mapvfs_parse dispatching on extension, strict mapvfs_parse_toml, deprecated
mapvfs_parse_config fallback (un-migrated generated projects keep baking, with a
NOTE; toml wins when both files exist). Shared toml helpers hoisted to
punkboot::lib (inline toml_untag copies removed).
- Strict entry-named validation: unknown keys/types/schemes, conflicting targets,
duplicate outputs, parse failures fatal (exit 3 pre-build). Full-bake
unresolvables split by nature: missing vfs folder (repo content) fatal per
entry; missing runtime file (environment - part-populated stores are legitimate)
entry-named recapped BUILD-WARNING + skip.
- Groups: @<group> selection in bake/bakelist, group/default/scheme notes columns
+ detail lines, groups listed in errors and argdoc choices. verify-ix86 wraps
the G-129 kits; bake_default=false excludes entries from full bakes.
- G-023 versioned scheme declared live ([scheme.punk8]/[scheme.punk9], group
versioned, bake_default=false pending G-023 activation): parse-time expansion
from punkproject.toml to punk<gen>-<version> / punk<gen>-dev / release-gated
punk<gen>; kit loop creates the plain name when absent and never overwrites it
on a normal bake. punk9-dev baked end-to-end; punk9 gate skip demonstrated.
- Consumer dedupe fix: several entries may share one runtime on one vfs -
kit-output enumeration and the kit-loop runtimes list process each distinct
runtime once (latent multiplication in the legacy format, unreachable there).
G-115 - declarative .vfs composition with drop-in preservation, same-day
activation->achieved:
- Sibling declarations src/vfs/<name>.vfs.toml ([payload.<name>]: source,
source_root src|packages, target, supersedes, replace) materialized by the new
VFSPAYLOAD phase (bakehouse/bake/vfslibs; selective bakes narrow; strict
entry-named errors). Drop-in-wins precedence via punkcheck -overwrite
synced-targets: undeclared or modified-since-install files preserved and
reported (changed-but-preserved NOTE = files_skipped minus sources_unchanged);
supersedes/replace are the explicit exceptions; an undeclared .vfs is untouched.
- vendorlib_vfs.toml relationship settled: folded/superseded - all six install
entries migrated into per-.vfs files for the 13 participating folders (first
materialization run reproduced every payload with zero tracked-content change);
file deleted; a leftover copy warns and is ignored.
- Demonstration kit punkdeclare (group declare-demo, bake_default=false,
smokerequire udp+tcllibc): VCS carries only the boot fauxlink; the whole
lib_tcl9 payload (tcludp vendor tree + tcllibc consent-gated packages tier)
rematerializes from the declaration - clean-tree rebuild smokes pass in-kit,
and drop-in survival was proven live (a foreign pkgIndex.tcl and an undeclared
note both survived; the foreign file genuinely won until removed, caught by the
G-133 smoke probe as designed). Payload ignored in both VCS (.gitignore +
derived ignore-glob; ignore-sync verification clean).
- Docs: src/vfs/README.md (format + precedence spec), src/vfs + src/runtime +
src + bin AGENTS.md, ARCHITECTURE.md (+lint clean), workflow text and
summaries/helptexts/argdoc; layout store seeds the convention (vfs README +
mapvfs.toml; machinery travels via the established make.tcl sync).
Verification: legacy-vs-toml identical kit rows; punkluck86 force-rebuilt under
both formats content-identical (identical 1.73MB runtime+stamp prefix, identical
2993-member payloads; whole-artifact byte identity is not a pipeline property -
consecutive same-config rebuilds differ in zip timestamp metadata, pre-existing);
punkexe suite 98 tests 0 failures incl. 5 new G-024 characterizations
(maketclbakelist.test: @group filter + PUNK_MAPVFS_CONFIG fixture tests) and
updated pins (payloadcheck declared list + punkdeclare; platform detail wording).
Goals: both flipped achieved 2026-07-31 with evidence in the detail files;
GOALS.md entries moved to GOALS-archive.md; live-tier reference sweep applied
(G-004/G-019/G-023/G-025/G-026/G-035/G-065/G-127/G-131/G-137/G-141) including
the G-127 mapvfs-seam retirement note (PUNK_MAPVFS_CONFIG) and a direct
G-137<->G-127 bridge replacing the archived G-024 one. Detail files move to
goals/archive/ in the follow-up pure-rename commit.
Also included as found: the developer's concurrent G-142 goal addition (GOALS.md
entry + goals/G-142-punkbin-listing-manifests.md), committed unmodified for
git/fossil coherence - not agent-authored.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl modules regeneration of punkcheck-managed outputs: the layout
src/make.tcl sync copies (basic, project-0.1, modpod payload) pick up
the G-139-era libfetch/vfslibs help + workflow text, and the modpod
layout payload mirror-prunes the samplesuite1 sketch retired in
fc2376ca and gains the buildsuites README.md.
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
G-117/G-123 lineage: project, project_url and packager in emitted
punkbin-artifact.toml records (runtime family + library tier, both
suites) now default from the enclosing project's punkproject.toml
[project] table via a bounded walk-up from the build root
(common.punkprojectField) - a copied suite reads its own project's
manifest. Chains: project: -Dproject > manifest name > "punkshell"
(was hardcoded); project_url: -Dprojecturl > manifest url >
"unrecorded"; packager: -Dpackager > PUNKBIN_PACKAGER > manifest
packager > git identity > fossil user default (new fossil-only
fallback) > "unrecorded". Verified end-to-end: suite_tcl90
kit-family + library emissions and the suite_tcl86 library emission
carry the manifest values, -D overrides win, family_check green.
Root punkproject.toml gains an active url; dev project.new's seeded
manifest now carries commented url/packager placeholders documenting
the consumption site (punk::mix::commandset::project 0.4.1).
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
fetch now surfaces the artifact's build-origin class in its report
("provenance: class=<c>" after sidecar retrieval, table-aware read,
both payloads, re-wrapped, pinned in runtimecmd_provenance.test) -
the acceptance's consent-surface clause.
END-TO-END DEMONSTRATION (live, fully reverted): fixture punkbin
served via httpfixture with a suffixless testplat-x86_64 runtime; the
committed bin/punk-runtime.cmd fetched fakert-suite-r1 (-platform +
-trust-server; sha1 ok, sidecar + provenance line) and 'use -platform'
materialized the working copy; a temporary mapvfs entry wired it to a
bakelist row: runtime file bin/runtime/testplat-x86_64/fakert-suite
(present), target=testplat-x86_64 - with the .exe-named negative half
(runtime=missing) captured first. Config reverted, tier removed, tree
verified clean. Live canonical evidence also captured: unattended
fetch of tclsh9.0.5-punk-r2.exe from the real origin ran gate-free
(published r2 hash matched).
Full battery: provenance 5/5, freshness + checkfile 12/12,
runtimebash_wsl PASS, dtplite 8/8 (after its separate 0.35.1
pre-existing-fallout fix), roundtrip byte-identical under the punk
baseline runner. Acceptance walk recorded item-by-item in the goal
Progress - every item evidence-satisfied; user-gated follow-throughs
(punkbin push + classification review; index Scope ps1-path
correction) recorded as outside acceptance.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
G-139's vendored-tree removal (70d1838c, 2026-07-30) broke
bin/dtplite.cmd's no-tcllib fallback, which globbed only the retired
src/vendorlib_tcl9/<arch>/tcllib* trees - every execution usecase
failed with "can't find package dtplite" (found by the G-123
acceptance walk's binscripts battery; dtplite.test had not run since
the removal). The fallback now resolves the artifact-fed DEPLOYED tree
lib_tcl9/<target>/tcllib<ver> (both the wrapped-in-bin and unwrapped
script locations), keeping the vendorlib patterns for derived projects
that still vendor. Re-wrapped; dtplite.test 8/8 under the punk
baseline runner.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Payload fix, both payloads (found designing the coverage): fetch only
retrieved beside-toml sidecars for -r<N> family names, so a fetched
bare-named third-party artifact arrived WITHOUT the retroactive record
its class display depends on. fetch now tries the sidecar for ANY name;
absence stays tolerated (no-basis degradation unchanged).
bin/punk-runtime.cmd re-wrapped.
NEW binscripts suite runtimecmd_provenance.test (5 tests, both payload
routes, httpfixture non-native tier testplat-x86_64: suite-built -r1
family artifact + bare third-party artifact with a retroactive-style
schema-v2 sidecar + a record-less artifact): server-trust gate refusal
from the non-canonical origin (canonical url + -trust-server named, no
artifact lands), -trust-server flag fetch including sidecar retrieval,
PUNKBIN_TRUST_SERVER=1 unattended form, class= tags in list -remote +
plain list (third-party tagged, suite-built quiet, record-less
untagged), and info schema-v2 fields + provenance_class row with the
flat 'class = runtime' ordering-caveat pin and record-row parity
between payloads.
All green: new suite 5/5; pinned checkfile + freshness 12/12; roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
fetch - the executable-retrieving act - now gates at entry when the
origin is non-canonical (PUNKBIN_URL override): the explicit
-trust-server flag or PUNKBIN_TRUST_SERVER=1 env (unattended form) is
the acknowledgement, one vocabulary with make.tcl libfetch's gate
(G-139). The canonical punkbin origin gates nothing (G-058's unattended
tclsfe constraint fetch is unchanged); metadata-only actions
(list -remote, platforms -remote) never gate; never an interactive
prompt. Refusal wording mirrors libfetch's.
ps1: -trust-server is pre-scanned before parameter binding (hyphenated
dynamic-parameter names are fragile under the PS 5.1 binder the windows
wrap routes through). Trap recorded in the goal Progress: a ps1 comment
line must never BEGIN with the word 'requires' - PowerShell parses
'#requires ...' as the #Requires statement and fails the whole file
(found by the powershell.exe 5.1 smoke).
runtimecmd_freshness.test: env seam gains PUNKBIN_TRUST_SERVER=1 + the
matching teardown unset (the fixture is a non-canonical origin, so its
fetch-driving tests need the unattended acknowledgement) - flagged as a
test-contract edit in the goal Progress; every existing assertion
unchanged and passing. Gate refusal characterization lands with the
increment-4 fixture coverage.
Payload growth pushed template label :exit_multishell onto a 512-byte
cmd label-scan boundary - checkfile caught it as designed; fixed via a
+16-byte spacer line (the documented knob). bin/punk-runtime.cmd
re-wrapped. Verification: gate smokes in both payloads (refusal + both
acknowledgement forms; ps1 under powershell.exe 5.1); checkfile 0
ERROR; pinned tests all PASS (checkfile + freshness 12/12, roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Both payloads gain a TABLE-AWARE [provenance] class reader
(provenance_class() awk helper / Get-PunkRuntimeProvenanceClass) - the
flat first-wins field scans deliberately keep reporting [artifact] class
per the documented schema-v2 ordering caveat. Display: compact
class=third-party|local tag in the plain-list metadata summary and in
list -remote's sparse identity column (suite-built stays quiet; LOCAL
record basis only - a listing does no per-row remote fetches, toml-less
and remote-only rows keep degrading as no-basis rows); info gains the
v2 fields builder/source_url/upstream_ref/retrieved in the flat table
plus a derived provenance_class row, disagreement-checked; help texts
updated to the v1/v2 wording.
bash defect fixed: 'info -platform <p>' was advertised in both help
texts but silently ignored - 'info' was missing from the option-scan
action list (punk-runtime.bash case arm). The per-name report now
honours the tier argument like the ps1 payload (proven by the
tier-named not-found path).
bin/punk-runtime.cmd re-wrapped via the documented multishell
invocation under punk905. Verification: bash -n clean; staged v2
third-party fixture smoke shows parity output in both payloads
('[tcl=9.9.9 class=third-party]' + provenance_class row);
runtimecmd_checkfile PASS (no 512B label crossing after payload
growth); runtimecmd_freshness PASS (13 fixture tests, both routes);
runtimecmd_roundtrip PASS byte-identical under the tclsh9.0.5-punk
baseline runner (plain native tclsh lacks struct::stack for tomlish -
runner-choice trap noted in the goal Progress).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
family_artifacts.tcl and the build905.zig embedded-record literal move
schema 1 -> 2, adding [provenance] class = "suite-built" with the
lib-tier ordering-caveat comment (G-138 lineage - [artifact] class stays
the first 'class =' line; whole-text single-key scanners see that one).
The embedded-vs-sidecar consistency gate expects v2, and
family_check.tcl asserts embed_schema 2 plus the literal
'class = "suite-built"' line (its flat scanner would see [artifact]
class first, per the caveat). Verified: zig ast-check clean, both tools
parse; functional family-build proof is the next step - published v1
records stay valid pre-v2 records, v2 appears from the next family
revision.
Companion punkbin commit 1f10390 (local, unpushed): 12 retroactive
schema-v2 sidecars covering every pre-family runtime artifact across
the five tiers, evidence-based classes (binary markers, punkbin git
history, live kit probes), additive-only (artifact bytes + sha1 rows
unchanged), AGENTS.md runtime-v2 section + README refresh.
Goal Progress records the baseline survey findings (tier argument
already present on fetch/list/use; bash 'info -platform' defect; no
client-side server-trust gate; ps1 Scope path correction pending user
approval).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
fetch and list's local-file comparison anchored runtime names at
end-of-line without stripping CR first, so a CRLF-published server
sha1sums.txt aborted fetch with "Unable to locate hash" on strict
grep platforms (GNU and BSD grep; cygwin grep tolerates CRLF, and
the ps1 payload is immune via Get-Content line splitting). Both
lookups now share the tr -d '\r' form list -remote already used.
bin/punk-runtime.cmd regenerated via the scriptwrap machinery; the
re-wrap invocation in src/scriptapps/AGENTS.md is corrected to the
working -force 1 -askme 0 form found during regeneration.
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
suite_tcl90: critcl_zig.config gains the linux-x86_64-zig cross target
(zig cc -target x86_64-linux-gnu.2.17 - the dynamic-glibc floor decision,
recorded in the goal file and fed to G-105). build905.zig gains the
tcllibc-linux step (critcl driver on the windows suite shell, stubs
linkage, no linux host; uuid.tcl excluded matching upstream's own
native-linux package shape) gated by the new tools/elf_gate.tcl
(G-133-equivalent ELF64/LSB/ET_DYN/x86_64 structural check - the
load-smoke stand-in for cross lanes). library-artifacts emits
lib/linux-x86_64/tcllibc-tcl9-r<N>.zip in the same run: target =
linux-x86_64, build_host_platform = win32-x86_64, full provenance set,
deliberately no [tests] section. build_id seeds now include the tier
path so same-named artifacts in different target tiers get distinct
identity digests (both suites' tool copies kept byte-identical). Step
lists (build905.zig -Dsteps default, suite.tcl) and README document the
lane and invocation.
Consumption: libpackages.toml declares tcllibc-tcl9-linux (target
linux-x86_64); vendorlib_vfs.toml install.tcllibc_tcl9_linux switches
punk9linux.vfs/lib_tcl9 - replace retires the hand-dropped tcllibc,
supersedes removes the stray tcllibc2.0 - so the last provenance-less
accelerator hand-drops in any kit payload are gone. punkshell902 baked
(G-133 payload arch scan: 6/6 match target linux-x86_64) and
WSL-verified: materialized-tier accel smoke plus baked-kit smokes
(default paths + a pinned variant proving the kit's own lib_tcl9
artifact tree loads with the accelerator engaged). Finding recorded:
the tclkit-902 runtime bundles its own lib/tcllibc2.0 which wins
default precedence - the origin of the retired stray folder name.
Determinism: back-to-back re-emission byte-identical for all three
artifacts; the zig Run session-env cache finding extended (FOSSIL_HOME
and invocation mode churn the key; the linux ELF .so observed
bit-stable across critcl re-runs, unlike the windows PE). Goal flipped
achieved with evidence in the detail file; G-105 notes carry the libc
decision as prior art. Docs: buildsuites AGENTS.md child index,
ARCHITECTURE.md buildsuites paragraph, CHANGELOG + punkproject 0.32.2.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl libfetch gains env-only isolation seams - PUNK_LIBFETCH_CONFIG
(alternate declarations file) and PUNK_LIBFETCH_PACKAGES (alternate tier
root), the PUNK_RUNTIME_PLATFORM idiom - so fixture/mirror runs never read
the real declarations or write the real bin/packages tier. Neither seam
bypasses the -trust-server consent gate.
New shell/testsuites/punkexe/maketcllibfetch.test (piped maketcl* harness +
testsupport/httpfixture.tcl + a file:// mirror; the canonical origin is
never contacted) pins the G-139 behaviours that previously had only manual
session evidence: the server-trust gate refusing non-canonical origins with
exit 3 before any network access or tier write, -serverurl-over-PUNKBIN_URL
precedence, consented fetch/verify/materialize (sha1sums + zip + sidecar +
installed-shape tree with embedded record), idempotent re-run vs -force,
declared-revision-change re-materialization keyed to the tree record (with
the sidecar-not-listed note lane), sha1-MISMATCH rejection without residue,
missing-from-server-sha1sums failure, and the no-config no-op. 8/8 pass in
both runner modes (singleproc + -jobs); full punkexe subtree green (93
runnable, 0 failed); the real bin/packages tier verified untouched.
Also refreshes the stale src/runtime/libpackages.toml header (r1 IS
published as of 2026-07-30; the G-139 reference now points at the archive)
and documents the seams there and in the libfetch help text.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk in the detail file's Progress): libfetch with
sha1 verification + beside-toml metadata + server-trust consent proven LIVE
against the canonical origin post-publication; PACKAGES_tcl<N> libs-step
materialization with punkcheck provenance; vendorlib_vfs.toml declarations
(source_root=packages + replace) with supersedes removing tcllib1.21 incl.
nested tcllibc 0.4 + md5c from the 8.6-family kits; punk86 kit-hosted
runtests vs the same-day baseline IDENTICAL (zero differences to
disposition); vendored trees removed in their own commit after the proven
bake (70d1838c); the post-removal verification bake shipped kits with
verifiable embedded provenance from the tcllib-vendorless checkout;
derived-project decision recorded (fc2376ca).
Index entry -> GOALS-archive.md record. Reference sweep: G-004's
pending-tense retirement line updated to delivered (+ the remaining
vendored trees named as its outstanding scope with the tcllib pattern as
template); actionable pointers pushed to G-006 (libfetch's trust gate = the
interim consent instance to absorb), G-065 (the artifact-fetch pattern to
absorb/reference), G-027 (derived-project library story via the layout
sync), G-123 (materialization twin + the live interim consent flag to
coordinate with). make.tcl workflow text updated to the landed consumption
shape (fetch -> tier -> PACKAGES phase + vfslibs packages lane); vfslibs
summary/help texts cover both source roots. Project 0.32.0 + CHANGELOG
(user-visible kit payload upgrade). goals_lint clean (82 active, 57
archived). Detail-file move to goals/archive/ follows in the adjacent
pure-rename commit.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
src/vendorlib_tcl8/win32-x86_64/tcllib1.21 (2023 hand-drop: tcllib 1.21 +
nested tcllibc 0.4 + md5c, critcl 3.2 era) and
src/vendorlib_tcl9/win32-x86_64/tcllib2.0 (2024 hand-drop: a different
trunk snapshot also labelled 2.0, nested tcllibc + md5c, critcl 3.3.1) are
retired from the tracked tree - the first major G-004 payoff. Their only
machine-readable provenance was critcl's teapot.txt; their replacements are
the published punkbin lib-tier artifacts (r1, suite-built with full
checkout/toolchain provenance) consumed via make.tcl libfetch + the
PACKAGES_tcl<N> phase + the vfslibs packages-root declarations.
Sequencing per the acceptance: removal lands AFTER the artifact-path bake
reproduced working kits (punk86 + punk905 baked, deployed, provenance
verified in-kit) and the punk86 kit-hosted runtests validation came back
identical to the same-day baseline. This commit is removal-only so the
fallback is a revert. Other vendored packages under src/vendorlib_tcl8|9
(Img, itcl, sqlite, tdbc, twapi, tcludp, ...) are unaffected.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
vfslibs processed all declared trees (45 installs): every win32 tcl9 tree's
tcllib2.0 clean-slate replaced by the artifact copy (nested md5c/tcllibc
strays gone), sibling tcllibc-tcl9 installed, stray tcllibc2.0 names
superseded; tcl8 kits upgraded - tcllib1.21 (with nested tcllibc 0.4 + md5c)
superseded out, tcllib2.0-tcl8 + tcllibc-tcl8 in; punk86bawt's bare tcllibc
refreshed; punk9linux keeps its linux-built accelerator siblings (win32
artifacts deliberately not declared there). Every installed tree carries its
embedded punkbin-artifact.toml record into the kit payloads.
Selective bake punk86 + punk905 (punk91/punksys/punk9_beta are live user
shells - trees switched, bakes at next natural rebake): both deployed;
punk905 arch scan OK (tcllibc exempt under its platform subdir); punk86's
only warning is the recorded pre-existing zint i386 defect. Kit provenance
verified both container types: punkzip central-directory read (punk905 zip
kit) and in-vfs record probe (punk86 metakit kit) - records name their
source artifacts + build_ids.
VALIDATION (acceptance): kit-hosted runtests bracket isolating exactly the
kit payload switchover - baseline (pre-switchover punk86) 1125/1099/18/8 in
5 files (exec.test, ns/nslist, ns/nsprimitives, zip/zipaccel,
stdin/runstdin; 1960s); post-switchover IDENTICAL totals, files, and
per-test outcome extraction (1119 lines, empty diff). Differences to
disposition: none - the 8 failures pre-exist on the old payload.
punkcheck-managed vfs tree changes batched per the src/AGENTS.md carve-out.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
The decision (per the acceptance, recorded in the goal detail): derived
projects obtain library binaries via the SAME fetch entrypoint by default -
generated projects receive make.tcl (libfetch + the PACKAGES phase) through
the established layout-sync/G-027 channels and declare their artifacts in
their own src/runtime/libpackages.toml; the copy-and-tweak in-project suite
build per G-104's self-description contract remains the documented
alternative (a tcllib/tcllibc-only suite needs no Tcl source tree - critcl
bundles its headers).
The pre-G-096 samplesuite1 sketch in the project-0.1 layout
(download_and_build.config, mingw64/gcc-era, self-described as SKETCH ONLY)
is removed and replaced by src/buildsuites/README.md in the layout,
documenting both routes for generated projects - the disposition the goal
Approach named. Goal Progress also records the r1 publication (punkbin
ee571ed, pushed) and the live canonical-origin libfetch verification.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl libs/packages/bakehouse gain the PACKAGES_tcl<N> phase: materialized
punkbin lib-tier packages under bin/packages/<target>/tcl<N>/ deploy into
lib_tcl<N>/allplatforms + lib_tcl<N>/<this platform> with punkcheck
provenance, mirroring the VENDORLIB_tcl<N> shape (embedded
punkbin-artifact.toml records ride into the deployed trees; absent tier =
silent per-item no-op with a libfetch pointer).
vfslibs declaration schema extended (vendorlib_vfs.toml header documents
both): source_root = "packages" resolves an entry's source against the
bin/packages tier (missing source errors name 'make.tcl libfetch');
replace = true clean-slates a SAME-NAMED existing target folder before
install (supersedes deliberately cannot name the folder being installed -
needed because the pre-G-139 tcl9 hand-drops nested md5c + tcllibc INSIDE
tcllib2.0).
Declarations added for the switchover set (per-kit, never blanket - the
trees that carried hand-drops at 2026-07-30): 8 win32 tcl9 kit vfs trees get
tcllib2.0-tcl9 + tcllibc-tcl9 (supersedes the stray-named tcllibc2.0);
punk9linux (linux target) gets only platform-neutral tcllib2.0 (its
linux-built tcllibc siblings stay - a linux lib-tier emission is future
work); punk86/punk8win/punk8_statictwapi upgrade tcllib1.21 (+nested tcllibc
0.4 + md5c, removed with it via supersedes) to tcllib2.0-tcl8 + tcllibc-tcl8;
punk86bawt refreshes its bare tcllibc only.
Verified: make.tcl libs deployed the tier into lib_tcl8|9 (allplatforms +
win32-x86_64) with embedded records present; vendored mirrors coexist in the
deployed trees until the sequenced retirement. Thin-layout make.tcl sync
copies updated by the run (punkcheck-managed outputs, batched per the
carve-out). Project 0.31.1 + CHANGELOG.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
New 'make.tcl libfetch' subcommand (argdoc'd; workflow text + plain help
updated): fetches the punkbin LIB-TIER artifacts declared in the new
src/runtime/libpackages.toml ([artifact.<name>] name/target; the four G-138
r1 artifacts, both generations) from <origin>/lib/<target>/ into the
untracked bin/packages/<target>/ input tier - zip + .toml sidecar, each
sha1-verified against the server's per-target sha1sums.txt (local tier copy
kept, the punk-runtime store idiom) - then materializes each verified zip
via punk::zip::unzip (crc-verified, mtimes restored, accelerator-eligible)
into bin/packages/<target>/tcl<N>/<pkgfolder>/ (generation subdirs: both
generations install identically-named folders). Idempotent: present
artifacts re-verify and skip; a materialized tree is current while its
embedded record names the declared artifact (the G-138 self-description
payoff); -force overrides.
Consent keyed to server trust (the G-123 posture): the canonical punkbin
origin (punk-runtime raw-base convention) gates nothing; any other origin
(-serverurl or env PUNKBIN_URL) refuses before network access without the
explicit -trust-server flag - never an interactive prompt. file:// origins
served natively (mirrors/fixtures); http(s) transport: Tcl http (+tls) when
loadable, else curl, else PowerShell. The dispatch block sits before the
build-command whitelist gate per the standalone-command pattern and exits
itself.
Emission-side amendment (both suites' library_artifacts.tcl): sidecar tomls
now ride the per-tier staging sha1sums.txt, matching the punkbin repo's
build_sha1sums.tcl coverage so staging-derived mirrors serve verifiable
sidecars.
Verified against a file:// mirror assembled from both suites' staging:
trust-gate refusal, consented fetch of all 4 artifacts (sha1-verified),
materialization of all 4 trees, fully idempotent re-run, and a package-load
proof from the tier (md5 2.0.9 + tcllibc accel=1 under the plain family
kit, ifneeded paths in bin/packages). bin/packages is already ignored in
both VCS via the /bin/* rules. Docs: bin/AGENTS.md tier section,
src/runtime/AGENTS.md libpackages.toml bullet. Project version 0.31.0 +
CHANGELOG (new make.tcl subcommand = product surface). Remaining G-139 work
recorded in the goal's Progress section.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk recorded in the detail file's Progress): emission
step landed in BOTH suites and demonstrated end-to-end - exceeding the
demonstrate-90/record-86-follow-through minimum - with byte-identical
re-emission verified, provenance-complete schema-v2 class=library records,
sidecars + per-tier sha1sums in the same step, publication left a deliberate
user step, punkbin layout docs recording the tier (punkbin repo commit
c38686a), and md5c dispositioned (dropped; tcllib's md5 prefers tcllibc,
which bundles the accelerator).
Index entry -> GOALS-archive.md record (file's established arrow-format
convention retained). Reference sweep: G-139 Context/Alternatives/Related
updated with achieved markers + archive path, and G-138's actionable
outcomes pushed to their consumers - G-139 (settled naming, md5c drop,
staging locations of the emitted r1 artifacts), G-123 (schema v2 landed
first for the library class - runtime-side v2 rides the lineage), G-004
(lib tier = the route for library binaries out of the tracked tree),
G-066/G-067 (zip tier recorded as the interim carrier for the .tm long
game). goals_xref report shows no unlinked pairs bridged only by G-138.
ARCHITECTURE.md buildsuites paragraph gains the lib-tier sentence
(architecture_lint clean); src/buildsuites/AGENTS.md child index updated
(also corrects the stale 'G-100 active' to achieved 2026-07-26).
Detail-file move to goals/archive/ follows in the adjacent pure-rename
commit per the Doc Restructures rule.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com