Payload fix, both payloads (found designing the coverage): fetch only
retrieved beside-toml sidecars for -r<N> family names, so a fetched
bare-named third-party artifact arrived WITHOUT the retroactive record
its class display depends on. fetch now tries the sidecar for ANY name;
absence stays tolerated (no-basis degradation unchanged).
bin/punk-runtime.cmd re-wrapped.
NEW binscripts suite runtimecmd_provenance.test (5 tests, both payload
routes, httpfixture non-native tier testplat-x86_64: suite-built -r1
family artifact + bare third-party artifact with a retroactive-style
schema-v2 sidecar + a record-less artifact): server-trust gate refusal
from the non-canonical origin (canonical url + -trust-server named, no
artifact lands), -trust-server flag fetch including sidecar retrieval,
PUNKBIN_TRUST_SERVER=1 unattended form, class= tags in list -remote +
plain list (third-party tagged, suite-built quiet, record-less
untagged), and info schema-v2 fields + provenance_class row with the
flat 'class = runtime' ordering-caveat pin and record-row parity
between payloads.
All green: new suite 5/5; pinned checkfile + freshness 12/12; roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
fetch - the executable-retrieving act - now gates at entry when the
origin is non-canonical (PUNKBIN_URL override): the explicit
-trust-server flag or PUNKBIN_TRUST_SERVER=1 env (unattended form) is
the acknowledgement, one vocabulary with make.tcl libfetch's gate
(G-139). The canonical punkbin origin gates nothing (G-058's unattended
tclsfe constraint fetch is unchanged); metadata-only actions
(list -remote, platforms -remote) never gate; never an interactive
prompt. Refusal wording mirrors libfetch's.
ps1: -trust-server is pre-scanned before parameter binding (hyphenated
dynamic-parameter names are fragile under the PS 5.1 binder the windows
wrap routes through). Trap recorded in the goal Progress: a ps1 comment
line must never BEGIN with the word 'requires' - PowerShell parses
'#requires ...' as the #Requires statement and fails the whole file
(found by the powershell.exe 5.1 smoke).
runtimecmd_freshness.test: env seam gains PUNKBIN_TRUST_SERVER=1 + the
matching teardown unset (the fixture is a non-canonical origin, so its
fetch-driving tests need the unattended acknowledgement) - flagged as a
test-contract edit in the goal Progress; every existing assertion
unchanged and passing. Gate refusal characterization lands with the
increment-4 fixture coverage.
Payload growth pushed template label :exit_multishell onto a 512-byte
cmd label-scan boundary - checkfile caught it as designed; fixed via a
+16-byte spacer line (the documented knob). bin/punk-runtime.cmd
re-wrapped. Verification: gate smokes in both payloads (refusal + both
acknowledgement forms; ps1 under powershell.exe 5.1); checkfile 0
ERROR; pinned tests all PASS (checkfile + freshness 12/12, roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Both payloads gain a TABLE-AWARE [provenance] class reader
(provenance_class() awk helper / Get-PunkRuntimeProvenanceClass) - the
flat first-wins field scans deliberately keep reporting [artifact] class
per the documented schema-v2 ordering caveat. Display: compact
class=third-party|local tag in the plain-list metadata summary and in
list -remote's sparse identity column (suite-built stays quiet; LOCAL
record basis only - a listing does no per-row remote fetches, toml-less
and remote-only rows keep degrading as no-basis rows); info gains the
v2 fields builder/source_url/upstream_ref/retrieved in the flat table
plus a derived provenance_class row, disagreement-checked; help texts
updated to the v1/v2 wording.
bash defect fixed: 'info -platform <p>' was advertised in both help
texts but silently ignored - 'info' was missing from the option-scan
action list (punk-runtime.bash case arm). The per-name report now
honours the tier argument like the ps1 payload (proven by the
tier-named not-found path).
bin/punk-runtime.cmd re-wrapped via the documented multishell
invocation under punk905. Verification: bash -n clean; staged v2
third-party fixture smoke shows parity output in both payloads
('[tcl=9.9.9 class=third-party]' + provenance_class row);
runtimecmd_checkfile PASS (no 512B label crossing after payload
growth); runtimecmd_freshness PASS (13 fixture tests, both routes);
runtimecmd_roundtrip PASS byte-identical under the tclsh9.0.5-punk
baseline runner (plain native tclsh lacks struct::stack for tomlish -
runner-choice trap noted in the goal Progress).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
family_artifacts.tcl and the build905.zig embedded-record literal move
schema 1 -> 2, adding [provenance] class = "suite-built" with the
lib-tier ordering-caveat comment (G-138 lineage - [artifact] class stays
the first 'class =' line; whole-text single-key scanners see that one).
The embedded-vs-sidecar consistency gate expects v2, and
family_check.tcl asserts embed_schema 2 plus the literal
'class = "suite-built"' line (its flat scanner would see [artifact]
class first, per the caveat). Verified: zig ast-check clean, both tools
parse; functional family-build proof is the next step - published v1
records stay valid pre-v2 records, v2 appears from the next family
revision.
Companion punkbin commit 1f10390 (local, unpushed): 12 retroactive
schema-v2 sidecars covering every pre-family runtime artifact across
the five tiers, evidence-based classes (binary markers, punkbin git
history, live kit probes), additive-only (artifact bytes + sha1 rows
unchanged), AGENTS.md runtime-v2 section + README refresh.
Goal Progress records the baseline survey findings (tier argument
already present on fetch/list/use; bash 'info -platform' defect; no
client-side server-trust gate; ps1 Scope path correction pending user
approval).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
proposed -> active in both tiers. Activation-freshness survey re-run
(goals_xref score G-123) per the maintenance rules: strongest pairs
G-127 and interval-drafted G-141; back-pointer Related lines recorded
in the detail file for G-141 (lib-tier selectivity sibling sharing the
server-trust consent surface), G-127 (cross-target kit bakes consume
served tiers), G-130 (32-bit runtimes publish through the per-target
layout) and G-131 (win32-ix86 zipfs specimens are third-party tclkits
the provenance backfill covers).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk in the detail file's Progress): libfetch with
sha1 verification + beside-toml metadata + server-trust consent proven LIVE
against the canonical origin post-publication; PACKAGES_tcl<N> libs-step
materialization with punkcheck provenance; vendorlib_vfs.toml declarations
(source_root=packages + replace) with supersedes removing tcllib1.21 incl.
nested tcllibc 0.4 + md5c from the 8.6-family kits; punk86 kit-hosted
runtests vs the same-day baseline IDENTICAL (zero differences to
disposition); vendored trees removed in their own commit after the proven
bake (70d1838c); the post-removal verification bake shipped kits with
verifiable embedded provenance from the tcllib-vendorless checkout;
derived-project decision recorded (fc2376ca).
Index entry -> GOALS-archive.md record. Reference sweep: G-004's
pending-tense retirement line updated to delivered (+ the remaining
vendored trees named as its outstanding scope with the tcllib pattern as
template); actionable pointers pushed to G-006 (libfetch's trust gate = the
interim consent instance to absorb), G-065 (the artifact-fetch pattern to
absorb/reference), G-027 (derived-project library story via the layout
sync), G-123 (materialization twin + the live interim consent flag to
coordinate with). make.tcl workflow text updated to the landed consumption
shape (fetch -> tier -> PACKAGES phase + vfslibs packages lane); vfslibs
summary/help texts cover both source roots. Project 0.32.0 + CHANGELOG
(user-visible kit payload upgrade). goals_lint clean (82 active, 57
archived). Detail-file move to goals/archive/ follows in the adjacent
pure-rename commit.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk recorded in the detail file's Progress): emission
step landed in BOTH suites and demonstrated end-to-end - exceeding the
demonstrate-90/record-86-follow-through minimum - with byte-identical
re-emission verified, provenance-complete schema-v2 class=library records,
sidecars + per-tier sha1sums in the same step, publication left a deliberate
user step, punkbin layout docs recording the tier (punkbin repo commit
c38686a), and md5c dispositioned (dropped; tcllib's md5 prefers tcllibc,
which bundles the accelerator).
Index entry -> GOALS-archive.md record (file's established arrow-format
convention retained). Reference sweep: G-139 Context/Alternatives/Related
updated with achieved markers + archive path, and G-138's actionable
outcomes pushed to their consumers - G-139 (settled naming, md5c drop,
staging locations of the emitted r1 artifacts), G-123 (schema v2 landed
first for the library class - runtime-side v2 rides the lineage), G-004
(lib tier = the route for library binaries out of the tracked tree),
G-066/G-067 (zip tier recorded as the interim carrier for the .tm long
game). goals_xref report shows no unlinked pairs bridged only by G-138.
ARCHITECTURE.md buildsuites paragraph gains the lib-tier sentence
(architecture_lint clean); src/buildsuites/AGENTS.md child index updated
(also corrects the stale 'G-100 active' to achieved 2026-07-26).
Detail-file move to goals/archive/ follows in the adjacent pure-rename
commit per the Doc Restructures rule.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Activation (user-directed this session) through achieved flip in one lifecycle
change-set: index entry moved to GOALS-archive.md (Scope relocated verbatim;
title preserved with the [achieved] status transform; Detail: line becomes the
archive detail pointer - the standard flip transformations), detail file gains
the activation survey Related: notes (G-114 prevention-side sibling, G-128
sibling PE surface), the advisory-as-drafted open-decision resolution, and the
full Progress/verification records (live bake evidence on
punkluck86/punk91ix86/punk86/punkshell902, the zint real finding, 92.6ms avg
scan cost, suite results). Reference sweep pushes the archived file's
actionable notes to G-024 (toml schema home), G-131 (one-vocabulary +
runtime_caps), G-127 (target-addressing adoption), G-130 (subdir exemption for
32-bit growth), G-123 (publication citation), G-114 (detection-side sibling).
Detail file moves to goals/archive/ in the following pure-rename commit.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Detail file: Status flipped, Context table corrected (the LUCK backport HAS a
::zipfs ensemble - just no root subcommand), Progress + verification records
added (both 32-bit kits boot and resolve from their mounts, four 64-bit kits
byte-identical before/after, unattributable-mount stderr report demonstrated,
both zip offset conventions verified on the backport, kitmountpoint.test 4/4,
full suite at the exec-14.3-only baseline). Index entry moved to GOALS-archive.
Reference sweep: achieved/archive markers added at the G-129 mentions in G-101,
G-024, G-130 and G-131 (pending-tense Approach line rewritten); forward-pointing
notes pushed to their targets - G-131 gets the factored-derivation shape,
measured mount tables, app/main.tcl hook and the LUCK both-capability probe row;
G-123 gets the bin/AGENTS.md kit-wrappable requirements as its publication
criterion pointer.
Claude-Session: https://claude.ai/code/session_01UEgomWq6kA6c4A8GswqqGW
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Everything a bake EMITS is now keyed by the artifact's TARGET platform rather than the
driving tclsh's personality: the bin/runtime/<tier> store a runtime is read from, .exe
suffixing of runtime files and kit outputs, presence checks, and whether the pre-deploy
process sweep uses tasklist/taskkill or ps/kill. Host semantics - copy commands, path
handling, filesystem case rules, prompts - stay keyed to the host.
The default target is the host's platform canon EXCEPT for a cygwin-family host (an
msys2/cygwin-runtime tclsh, which reports tcl_platform(platform) unix on windows), which
targets win32-x86_64. Such a host now drives the identical kit set, names and store
addressing as a native tclsh; before, it reported every kit runtime=missing against a
nonexistent mingw64-x86_64 store.
mapvfs.config entries take an optional 4th element naming the kit's target platform, so a
runtime kept in another platform's tier is a first-class mapping entry. The linux tclkit
entry now declares linux-x86_64 and bakes to a suffixless bin/punkshell902.
Zip-type kits assemble without zipfs in the driving tcl: when tcl::zipfs::mkimg is absent
(any 8.6) the image is built by raw-runtime split + punk::zip::mkzip + concatenation - the
same helper the zipcat type uses. Both mount identically (archive-start-relative offsets).
Fixes exposed by the above: the runtime capability probe looked for a suffixless filename
and so reported find-fail for every runtime on windows; with real capabilities arriving,
the extraction try-list was found to test capability presence rather than value, which
would send a plain zipfs runtime down the kit path where a failed sdx mksplit replaces
raw_runtime with the un-split original; BUILDCOPY names now follow the runtime's own
filename; runtime map keys strip only .exe (file rootname would eat the last dotted
segment of tclsh9.0.5); and native windows command lines run through a guard suppressing
msys2's posix-path argument rewriting - without it taskkill /PID <n> reached taskkill as
taskkill C:/<msysroot>/PID <n>, so the sweep could find a running kit but never replace it.
punk::platform folds the msys2 family (mingw64/mingw32/ucrt64/clang*) onto one stable
'msys' tag and CYGWIN_NT onto 'cygwin' - msys2's uname renders that token from MSYSTEM,
so one binary otherwise canonizes differently per launching shell. New normalize_os;
cygwin-x86_64 added to the platform table; 'help platforms' documents the fold.
make.tcl check reports the derivation on one line; bakelist rows carry target=<platform>
for non-default targets and the detail block names the tier; workflow text gains key note
[K9]. New characterization suite maketclplatform.test (5 tests, two self-gating on
discovering and probing a real msys/cygwin tclsh). Full suite 1112 tests: 1093 passed,
18 skipped, 1 failed = the documented exec-14.3 baseline.
Verified: msys2 tclsh8.6 bakelist output identical to native Tcl 9; a changed punk91
baked and deployed from that host with the sweep killing a running instance msys ps
cannot see; a real cross-target linux kit baked from windows to a 24MB ELF; a zipfs-less
8.6 bake producing a bootable zip kit.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
Index entry + detail file with the two user-directed amendments over the
presented draft: consent keyed to SERVER TRUST (trusted set defaults to the
canonical punkbin origin - no new prompts in existing flows incl. the
unattended tclsfe-x64 constraint fetch; untrusted/alternative servers gate
with a G-006-pattern acknowledgement surfacing the provenance class), and
retroactive schema-v2 provenance sidecars for the existing punkbin
third-party artifacts (additive only - bytes, bare pre-family names,
sha1sums.txt authority unchanged). Signing deliberately deferred per user
("down the track") with the minisign anticipation noted. Depends on G-122;
Related G-006/G-067/G-105/G-101; extends archived G-103/G-119 machinery under
a G-117 schema-v1 -> v2 bump. G-122's follow-on note now cites G-123 by id.
Claude-Session: https://claude.ai/code/session_01Jz7wkUsknJzyuJ3tgMaL2t
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com