User decision: -choicecolumns back to 1 on both the rich overview and
the lean dispatch definition - the long one-line summaries make the
two-column layout too wide without table cell wrapping. Revisit
-choicecolumns 2 when cell wrapping is implemented; the '## FORM'
header-line dropping in the overview cells is accepted. Max render
width drops ~250 -> 168 columns. help/colour suites 16/16.
punkshell 0.41.2.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed: bare 'make.tcl help' / 'make.tcl' / '-help' now render a
per-subcommand overview in the repl 'i info' style - each cell carries
the subcommand's one-line summary plus its own auto-generated
bracket-notation synopsis line(s) (per-form lines for the multi-form
tool/buildsuite), grouped by the existing SUBGROUPS in two columns.
Stock punk::args machinery: rich -choicelabels built at lazy resolve
time by ::punkboot::argdoc::overview_labels (punk::args::synopsis
-noheader per subcommand id, '## FORM' headers dropped for compactness)
+ -choicecolumns 2, hung on the separate (script)::punkboot.overview id
so the label cost (a few ms) is paid only when the top-level help
renders - the lean (script)::punkboot definition remains the dispatch
surface (now also -choicecolumns 2 for its unknown-subcommand error
render) and is deliberately excluded from the capability probe. Plain
PUNKBOOT_PLAIN fallback help unchanged. maketclhelp toplevel test
updated to pin the overview (tool/buildsuite form synopsis lines,
ESC-free); help/colour/bakelist suites 25/25. punkshell 0.41.1.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed pair completing the declaration-authoritative arc:
1. bake/bakelist kitnames are -choicerestricted 1: the configured kit
names + @group selectors (computed into the declaration when the mapping
parses at definition time) now GATE at dispatch - an unknown kit is a
punk::args choice error before any build (the no-build guarantee moves
to the gate), unambiguous prefixes resolve to canonical names, and the
dry-run help mirrors the verdict ('help bake punk91 -confirm 0' is now
a pointed choice error naming '-confirm' rather than a value-swallow).
The handlers' own validation remains the backstop where declarations
cannot gate: PUNKBOOT_PLAIN degraded mode, and a definition-time
mapping-read failure (the choices clause is omitted entirely - no gate).
2. All kit-mapping consumers share ONE memoized parse per invocation:
new punkboot::lib::mapvfs_model front door (locate+parse, keyed by
resolved mapfile/rtbase/sourcefolder/target - a PUNK_MAPVFS_CONFIG
override keys its own entry) consumed by the definition-time choices
(now passing the real bin/runtime rtbase - mapvfs_parse is pure, so the
models are interchangeable) and the five handler sites (selective bake,
main bake, bakelist, vfslibs %platform% derivation, check smoke
listing). Success is cached; a throwing parse deliberately is not, so
each caller diagnoses fresh.
maketclbakelist.test: unknown-name pins updated to the dispatch choice
error + PUNKBOOT_PLAIN backstop variants (runner gains envoverrides);
maketclhelp.test: bake dry-run case now pins the choice-gate rejection
and 'help bake punk91' acceptance. Full punkexe subtree 114 tests, 0
fail. punkshell 0.41.0.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed: the bare-action carve-out is removed - 'make.tcl help
buildsuite build' now falls through to the punk::args diagnosis like any
other incomplete line (exit 1). Empirically the error table carries the
form's argument rows alongside the all-forms synopsis and per-form
reasons, so the diagnosis IS the form documentation and the carve-out
bought nothing but an exit code. Accepted lines gain a one-line
received-args report after the usage table, built from the parse
result's 'received' key (defaulted opts omitted):
'dry-run: line accepted (form build) - action = build | -test = 0 |
toolname = punkzip'. This makes punk::args' value-swallow visible
('kitname = punk91 -confirm 0' for the out-of-order line) - an interim
make.tcl-side clue until punk::args grows an annotated success render.
bake/bakelist kitname -choicerestricted 0 confirmed deliberate
(discoverability-only choices; handler validation authoritative;
define-time mapvfs parse best-effort). maketclhelp.test pins updated;
help/tool/colour suites 20/20. punkshell 0.40.3.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed second refinement: 'make.tcl help <subcommand> ?arg ...?'
(and '<subcommand> ?arg ...? -help') now parses the words through the
subcommand's punk::args declaration exactly as dispatch would (form
auto-selection, choice prefixes). An accepted line renders the matched
action's single-form usage ('help tool build -test 0 punkzip', 'help
tool bu'); a rejected line (unknown action, option-first line, unknown
flag in option position) emits the same punk::args noformmatch
diagnosis dispatch gives - all-forms synopsis plus per-form reasons -
on stderr, exit 1: the error table is itself usage documentation, so
help verdicts mirror dispatch verdicts. Carve-out: a bare action
word/prefix renders its form directly, since forms with required
values ('buildsuite build' needs a suitename) would fail a strict
dry-run. Replaces 0.40.1's leading-word-only selection and option-first
whole-usage fallback. Empirical punk::args findings recorded (archived
goal file + probes): flag-like words at/after the first value position
parse as values; -regexprepass/-regexprefail are honoured during form
matching (a '-regexprefail {^-}' value disambiguates flag-led lines -
the punk::auto_exec::hash latent selection ambiguity). maketclhelp.test
pins updated; help/tool/colour suites 20/20. punkshell 0.40.2.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
User-directed reshape of the help-depth interface: 'make.tcl help
<subcommand> ?arg ...?' (and '<subcommand> ?arg ...? -help') now accepts
the subcommand's command line as typed and renders the usage most
specific to it - 'make.tcl help tool build -test 0 punkzip' shows the
tool build form via its leading action word (the same literal-leader
word punk::args form auto-selection keys on at dispatch). Words after
the action are tolerated and ignored; an option-first line falls back to
the whole subcommand's usage; single-form subjects (e.g 'help bake
punk91 -confirm 0') ignore the words entirely; an unknown action word on
a multi-form subject stays a pointed exit-1 usage error. The 0.40.0
numeric form-index acceptance ('help tool 2') is withdrawn as
unintuitive. Probe recorded: the repl 'i' (punk::ns::cmdhelp) tolerates
trailing argument words but does not form-narrow flat multi-form
commands - make.tcl help now exceeds it there. maketclhelp.test pins
updated (12 tests, all green + tool/colour suites); punkshell 0.40.1.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
punkcheck-managed copies refreshed by 'make.tcl modules' - vendor layouts
basic + project-0.1 and the modpod-shipped template payload, all
byte-identical to src/make.tcl.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
tool/buildsuite/help are multi-form punk::args definitions (one @form per
action, literal single-choice action leaders + choicelabels): 'help tool' /
'help buildsuite' render one synopsis line per action; 'make.tcl help
<subcommand> <action>' - equivalently '<subcommand> <action> -help', or a
0-based form index ('help tool 2') - renders that action's single-form
usage; unknown actions and out-of-range indexes are pointed punk::args
errors (exit 1). tool dispatch parses through the definition (unknown
actions/flags: exit-1 usage errors). User-approved deviation: the declared
positional model puts options before tool names ('tool build -test 0
<name> ...'); docs/agent guidance updated to match and a flag-shaped tool
name earns a stderr hint; the PUNKBOOT_PLAIN degraded scan keeps the
historic flag-anywhere parse. buildsuite driver-arg passthrough unchanged.
G-144 consumer follow-through: all 17 per-subcommand @form -synopsis
overrides retired (automatic @cmd -name bracket-notation synopses;
top-level make.tcl override kept deliberately). Pinned by new
punkexe/maketclhelp.test (12 tests); full punkexe subtree green (114
tests, 0 fail). Goal flipped to achieved and archived; punkshell 0.40.0.
Assisted-by: harness=claude; primary-model=claude-opus-5[1m]; api-location=anthropic.com
Auto-generated synopses for (script)-prefixed constructed definition ids
now lead with the declared @cmd -name (the invocation name - e.g
'make.tcl modules' for (script)::punkboot::modules) instead of the raw
id, across punk::args::synopsis full/summary renders and the
usage/arg_error synopsis sections that funnel through them (punk::args
0.12.7 -> 0.13.0).
The fallback is gated on the (script) prefix only (user-confirmed
narrowing): (autodef) ids are excluded - their id-minus-tag IS the
invocation (arg_error's existing tag strip surfaces it) while their
@cmd -name is a display label ('destroy', 'Object: ::x');
(shared)/(package)/(default)/(widgetcommand) doc ids declare no
invocation-style -name today and render the id as before. Real command
ids render byte-identical (full args testsuite passes with no pin
updates). Six new synopsis.test pins: (script) full/summary/multiform/
surfaces, no-name constructed id, autodef unchanged, real-id
byte-identical.
Goal tiers: index entry archived to GOALS-archive.md, detail file moved
to goals/archive/ (G-143's pending-tense Related line rewritten to
reflect achievement + follow-through pointer: make.tcl's @form
-synopsis overrides are now optional, retirement under G-143 or a
follow-on edit). Docs: @form -synopsis directive known-case text,
synopsis -help, src/modules/AGENTS.md ergonomics bullet. Project
0.39.5 -> 0.39.6 (patch: latent capability, no shipped definition
renders differently today).
Bootsupport refresh (make.tcl modules + bootsupport): snapshot gains
args-0.13.0.tm and picks up two lagging source syncs -
mix/commandset::layout 0.2.0 -> 0.3.0, mix/commandset::project
0.4.0 -> 0.4.1, and the shellfilter 0.2.4 G-145 comment; superseded
copies pruned.
Assisted-by: harness=opencode; primary-model=openrouter/moonshotai/kimi-k3; api-location=openrouter.ai
Layout .gitignore payloads are now stored inert as gitignore.in and
materialized to .gitignore at project generation, ending the
self-censoring-template hazard (live nested .gitignore files silently
untracked template content in git while fossil managed it fine):
- punk::mix::commandset::layout 0.3.0: layout_materialize_renames map;
layout_stage_chain renames inert payloads after composing all overlay
layers (.anti markers keep targeting store names); layout_materialize
withholds the in-place fast path from inert-payload folders so the
store is never renamed; inert+live name conflict errors loudly
- make.tcl thin-layout sync refreshes every vendor/punk layout's
gitignore.in from the canonical repo-root .gitignore (punkcheck-tracked
sync_layouts events); workflow text updated
- the four vintage payload variants eliminated as drift: all payloads
now byte-identical mirrors of root; modpod copy carried and its stale
.gitignore pruned
- materialize.test +5 G-012 characterization tests (25/25; mix subtree
71 pass / 1 known skip)
Verified end-to-end: generation from each affected layout yields a
byte-identical .gitignore (othersample .anti case yields none); root
edits propagate to payloads via make.tcl libs in both directions; the
fc1c474c force-added template files are back to ordinary git tracking
with no ignore rule matching them; modpod payload README trees are now
visible as ordinary trackable files.
Goal flipped achieved 2026-08-01 (user-confirmed; the custom/_project
acceptance clause is stale - that store level was retired by G-087
stage 5 after drafting; recorded in the archive record and detail
evidence). Reference sweep + archive moves per the flip protocol.
Project version 0.39.5.
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
The Tcl core delivers 'clear' to a transform stack before EVERY write op
(output-buffer flush-down; tclIORTrans.c ReflectOutput, gated on METH_CLEAR -
intentional and test-pinned, but under-documented: doc/transchan.n and TIP 230
scope clear to seek/read-side buffers). ::punkboot::ansistrip::transchan's
clear handler ran 'dict unset carry $chanid', discarding a split sequence's
held ESC tail at every write-chunk boundary: the next chunk's ESC-less
remainder ('0;1m', '1m') passed through unstripped as orphan fragment text in
piped usage tables, while the dropped ESC bytes kept the G-113 zero-ESC pin
green. The transform is write-only with no read-side state, so its
contract-conformant clear is a no-op - it no longer declares the op, the
per-write calls never fire, and the split-sequence carry survives every chunk
boundary. finalize still drops an end-of-stream partial sequence. No change in
textblock/punk::ansi (pre-transform stream verified well-formed during
diagnosis; exonerated).
Pin: maketclcolour.test gains maketcl_colour_help_tables_zero_remnants -
piped 'tclsh src/make.tcl help' for all 20 declared SUMMARIES subjects plus
bare 'help'/'-help', asserting exit 0, zero ESC bytes, zero orphan fragments
(two-step detector: strip complete sequences, then scan for [0-9;]+m not
preceded by ESC or an open bracket - a raw scan false-positives on ';1m' inside complete
multi-parameter SGR). Failing-first evidence: pre-fix the pin names exactly
the 5 fragmenting invocations (help, -help, help libs, help info, help
bootsupport); the 22-invocation NO_COLOR+PUNK_FORCE_COLOR pre-transform
corpus carries no legit text matching the detector.
Verified (tclsh 8.7a6, win32-x86_64): all 22 invocations byte-level clean;
PUNK_FORCE_COLOR=1 output intact (1177 complete sequences, 0 orphans); the 3
G-113 colour-policy pins pass unchanged; shell/testsuites/punkexe family (15
files, 102 tests) and shell/*** (127 tests) green, warnings pre-existing only;
'make.tcl packages' verified, layout + modpod make.tcl copies synced by the
build (punkcheck-managed outputs batched here per the carve-out).
Bookkeeping: goal flipped active -> achieved 2026-08-01, detail file archived
(goals/archive/G-145-piped-usage-ansi-remnants.md), G-056 Notes gains the
exoneration pointer; src/AGENTS.md colour bullet + src/tests/shell/AGENTS.md
suite description updated; project version 0.39.4 (patch) with CHANGELOG
entry.
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
Investigation record only - no fix yet (goal remains proposed).
Root cause: the Tcl core delivers the transform 'clear' op before every
write (output-buffer flush-down; tclsh 8.7 and 9.0.3), and
::punkboot::ansistrip's transchan handles 'clear' with 'dict unset carry'
- discarding a split sequence's held tail at every chunk boundary. The
tail's remainder (e.g. 0;1m) passes through unstripped while the held
ESC[ bytes are never emitted, so the zero-ESC pin (maketclcolour.test)
stays green while fragments leak. Evidence: pre-transform stream captured
via NO_COLOR+PUNK_FORCE_COLOR is fully well-formed (textblock/punk::ansi
exonerated; G-056 not the mechanism); the verbatim strip proc is correct
for every possible 2-chunk split and 512..8192 block sizes; an identity
logging transform under ansistrip captured the boundary byte-exactly;
minimal isolated repro on a bare file channel reproduces both the
per-write 'clear' op sequence and a fragment. Deterministic per table
geometry, matching the observed intermittency.
Upstream (TEMP_REFERENCE/tcl9 survey): per-write 'clear' is intentional,
test-pinned core behavior (ioTrans.test iortrans-7.1 "chan write, write
clears read buffers") but transchan.n and TIP 230 document it as
seek-only and read-side-scoped - an upstream documentation gap, not an
implementation bug; no existing Tcl ticket found. A write-only
transform's contract-conformant 'clear' is a no-op; fix layer recorded
in the goal file (drop 'clear' from the supported-methods list or make
it a no-op; 'finalize' keeps dropping the carry).
- goals/G-145-piped-usage-ansi-remnants.md: root cause, evidence chain,
upstream documentation status, fix layer, encoding note, repro recipes
- shellfilter: G-145 warning comment over the commented-out 'clear'
method so future refactors don't discard o_encbuf/stream state there
goals_lint clean (83 active-index goals, 62 archived).
Assisted-by: harness=opencode; primary-model=opencode/kimi-k3; api-location=unknown
Convert every ::punkboot::argdoc punk::args::define to the braced file-style
block form established for the shell/tool definitions in 7ec7da4a: -& record
continuations, -summary/-help pulled from SUMMARIES/HELPTEXTS via tstr
placeholders, shared OPT_* option fragments interpolated as ${$OPT_...}
records. The SUBOPTS/OPT_SYNOPSES/VALUES_SYNOPSES/SUBVALUES tables and the
define loop are unrolled into 16 per-subcommand blocks; buildsuite/help and
the top-level definition follow the same idiom (help gains a HELPTEXTS entry;
the top-level body moves to argdoc's TOPLEVEL_HELP variable). @normalize is
dropped: -help bodies are display fields (punk::args G-046 deferred
expansion), so the HELPTEXTS block indentation now reaches the rendered
Description verbatim - every 'make.tcl help <subcommand>' Description renders
centred like 'make.tcl help tool' instead of left-aligned.
No parsing or interface changes: option/values specs, synopses, exit codes,
prefix resolution, unknown-flag/subcommand errors, PUNKBOOT_PLAIN degraded
mode and the capability probes all verified unchanged (before/after usage
captures diffed for all 20 help subjects; shell/tool byte-identical). Narrow
usage tables widen slightly to fit the indented Description.
KITNAME_CHOICEPART persists as a namespace variable because the kitname
records interpolate it at (lazy) definition resolve time.
Docs: src/AGENTS.md make.tcl bullets updated (braced-def contract, per-block
maintenance rule); src/modules/AGENTS.md G-045 subsection re-points the
@normalize exemplar to punk.tm only and records argdoc as the braced -& +
tstr exemplar. punkshell 0.39.3 + CHANGELOG entry. Thin-layout make.tcl
copies resynced via 'make.tcl libs -confirm 0' (basic, project-0.1, modpod
templates copy - byte-identical).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
tool_install_state judges bin/<tool>.exe current/stale by comparing its
mtime against the newest file anywhere in the tool tree. Two layers kept
that exe mtime frozen at the original link time: a zig cache-hit rebuild
does not rewrite the zig-out artifact, and Tcl's 'file copy -force'
preserves the source mtime (Windows CopyFile semantics). Once any
non-build-input file (e.g. PROVENANCE.md, edited after the G-128/G-135
doc passes) was newer than that link time, the tool was reported 'stale'
permanently - repeated 'make.tcl tool build' runs (field-observed
2026-08-01) reinstalled a timestamp-identical artifact and never cleared
it.
Fix: after the install copy, stamp the installed exe with the install
time ('file mtime $exe [clock seconds]'), making the state measure what
it means - installed since the last change in the tree. Also self-heals
mtime churn from branch switches/fresh clones on the next build.
punkshell 0.39.2 + CHANGELOG entry (patch: build-tooling bug fix).
Thin-layout make.tcl copies resynced via 'make.tcl libs -confirm 0'
(basic, project-0.1, modpod templates copy - byte-identical).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
The G-112 stage-true rename (0.23.0) kept 'project' -> bakehouse and
'vfs' -> bake as transitional aliases until the 8.6 arc completed; that
arc landed with G-099 and the new shape is settled. All alias plumbing
is removed from src/make.tcl: known_commands, the pre-dispatch mapping
switch, the punk::args definitions (SUMMARIES/HELPTEXTS/SUBOPTS/
SUBVALUES/VALUES_SYNOPSES), the "deprecated aliases" help group, the
plain-help block, the workflow-text mention and the degraded-mode
kitname collection. 'vfs' now gets an unknown-subcommand usage error;
'project' prefix-resolves to the read-only 'projectversion' check under
punk::args unambiguous-prefix matching (PUNKBOOT_PLAIN degraded mode
rejects both). Also trimmed a pre-existing trailing space (line 8990)
surfaced by git diff --check via the verbatim layout copies.
Docs: src/README.md, ARCHITECTURE.md, src/AGENTS.md (alias mentions
removed; also corrected the stale layout-sync trigger claim - the
thin-layout sync runs in modules/libs/packages/bakehouse, not
bootsupport), root AGENTS.md sync-step subcommand list ('project' ->
'bakehouse'). Historical records (CHANGELOG 0.23.0 entry, goals
archives, GOALS-archive) deliberately untouched.
punkshell 0.39.1 + CHANGELOG entry (make.tcl interface change - patch
per root AGENTS.md versioning policy).
Build outputs batched per src/AGENTS.md: thin-layout make.tcl copies
resynced via 'make.tcl libs -confirm 0' (basic, project-0.1, modpod
templates copy - all byte-identical to src/make.tcl), plus the lagging
store->modpod catch-up the same run performed (modpod layout copy:
mapvfs.config removed, mapvfs.toml + vfs/README.md added).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
- new punkexe/maketclkitlocations.test (PUNK_MAPVFS_CONFIG fixtures, nothing
built): two-target one-vfs distinct locations (flat vs kits/<platform>/),
same-name two-non-native coexistence without runtime-rename, same-target
duplicate keeps <name>_<runtime>; mismatch clause referenced as G-133
regression pin (binaryarch.test + maketclpayloadcheck.test)
- mapvfs_match_outputs: a plain kit name now selects ALL matching records (one
per target) instead of the first hit - pre-G-127 uniqueness assumption removed;
filtered bakelist + selective bake cover every target of a shared name
- full punkexe subtree pass: 15 files, 101 tests, 0 failed (4 constraint skips)
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
G-024 - kit mapping converted to toml (tomlish-parsed), same-day activation->achieved:
- src/runtime/mapvfs.toml: [kit.<name>] / [group.<name>] / [scheme.<name>] tables
(header comment = user-facing spec). All 12 active line-format mappings migrated
(order preserved - identical bakelist rows vs the legacy parse); historical
comments carried over; mapvfs.config deleted here AND in the project-0.1 layout
(converted to mapvfs.toml there).
- make.tcl reader family under the unchanged G-121 model surface: mapvfs_locate
(toml > legacy; PUNK_MAPVFS_CONFIG env override = characterization seam),
mapvfs_parse dispatching on extension, strict mapvfs_parse_toml, deprecated
mapvfs_parse_config fallback (un-migrated generated projects keep baking, with a
NOTE; toml wins when both files exist). Shared toml helpers hoisted to
punkboot::lib (inline toml_untag copies removed).
- Strict entry-named validation: unknown keys/types/schemes, conflicting targets,
duplicate outputs, parse failures fatal (exit 3 pre-build). Full-bake
unresolvables split by nature: missing vfs folder (repo content) fatal per
entry; missing runtime file (environment - part-populated stores are legitimate)
entry-named recapped BUILD-WARNING + skip.
- Groups: @<group> selection in bake/bakelist, group/default/scheme notes columns
+ detail lines, groups listed in errors and argdoc choices. verify-ix86 wraps
the G-129 kits; bake_default=false excludes entries from full bakes.
- G-023 versioned scheme declared live ([scheme.punk8]/[scheme.punk9], group
versioned, bake_default=false pending G-023 activation): parse-time expansion
from punkproject.toml to punk<gen>-<version> / punk<gen>-dev / release-gated
punk<gen>; kit loop creates the plain name when absent and never overwrites it
on a normal bake. punk9-dev baked end-to-end; punk9 gate skip demonstrated.
- Consumer dedupe fix: several entries may share one runtime on one vfs -
kit-output enumeration and the kit-loop runtimes list process each distinct
runtime once (latent multiplication in the legacy format, unreachable there).
G-115 - declarative .vfs composition with drop-in preservation, same-day
activation->achieved:
- Sibling declarations src/vfs/<name>.vfs.toml ([payload.<name>]: source,
source_root src|packages, target, supersedes, replace) materialized by the new
VFSPAYLOAD phase (bakehouse/bake/vfslibs; selective bakes narrow; strict
entry-named errors). Drop-in-wins precedence via punkcheck -overwrite
synced-targets: undeclared or modified-since-install files preserved and
reported (changed-but-preserved NOTE = files_skipped minus sources_unchanged);
supersedes/replace are the explicit exceptions; an undeclared .vfs is untouched.
- vendorlib_vfs.toml relationship settled: folded/superseded - all six install
entries migrated into per-.vfs files for the 13 participating folders (first
materialization run reproduced every payload with zero tracked-content change);
file deleted; a leftover copy warns and is ignored.
- Demonstration kit punkdeclare (group declare-demo, bake_default=false,
smokerequire udp+tcllibc): VCS carries only the boot fauxlink; the whole
lib_tcl9 payload (tcludp vendor tree + tcllibc consent-gated packages tier)
rematerializes from the declaration - clean-tree rebuild smokes pass in-kit,
and drop-in survival was proven live (a foreign pkgIndex.tcl and an undeclared
note both survived; the foreign file genuinely won until removed, caught by the
G-133 smoke probe as designed). Payload ignored in both VCS (.gitignore +
derived ignore-glob; ignore-sync verification clean).
- Docs: src/vfs/README.md (format + precedence spec), src/vfs + src/runtime +
src + bin AGENTS.md, ARCHITECTURE.md (+lint clean), workflow text and
summaries/helptexts/argdoc; layout store seeds the convention (vfs README +
mapvfs.toml; machinery travels via the established make.tcl sync).
Verification: legacy-vs-toml identical kit rows; punkluck86 force-rebuilt under
both formats content-identical (identical 1.73MB runtime+stamp prefix, identical
2993-member payloads; whole-artifact byte identity is not a pipeline property -
consecutive same-config rebuilds differ in zip timestamp metadata, pre-existing);
punkexe suite 98 tests 0 failures incl. 5 new G-024 characterizations
(maketclbakelist.test: @group filter + PUNK_MAPVFS_CONFIG fixture tests) and
updated pins (payloadcheck declared list + punkdeclare; platform detail wording).
Goals: both flipped achieved 2026-07-31 with evidence in the detail files;
GOALS.md entries moved to GOALS-archive.md; live-tier reference sweep applied
(G-004/G-019/G-023/G-025/G-026/G-035/G-065/G-127/G-131/G-137/G-141) including
the G-127 mapvfs-seam retirement note (PUNK_MAPVFS_CONFIG) and a direct
G-137<->G-127 bridge replacing the archived G-024 one. Detail files move to
goals/archive/ in the follow-up pure-rename commit.
Also included as found: the developer's concurrent G-142 goal addition (GOALS.md
entry + goals/G-142-punkbin-listing-manifests.md), committed unmodified for
git/fossil coherence - not agent-authored.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl modules regeneration of punkcheck-managed outputs: the layout
src/make.tcl sync copies (basic, project-0.1, modpod payload) pick up
the G-139-era libfetch/vfslibs help + workflow text, and the modpod
layout payload mirror-prunes the samplesuite1 sketch retired in
fc2376ca and gains the buildsuites README.md.
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
G-117/G-123 lineage: project, project_url and packager in emitted
punkbin-artifact.toml records (runtime family + library tier, both
suites) now default from the enclosing project's punkproject.toml
[project] table via a bounded walk-up from the build root
(common.punkprojectField) - a copied suite reads its own project's
manifest. Chains: project: -Dproject > manifest name > "punkshell"
(was hardcoded); project_url: -Dprojecturl > manifest url >
"unrecorded"; packager: -Dpackager > PUNKBIN_PACKAGER > manifest
packager > git identity > fossil user default (new fossil-only
fallback) > "unrecorded". Verified end-to-end: suite_tcl90
kit-family + library emissions and the suite_tcl86 library emission
carry the manifest values, -D overrides win, family_check green.
Root punkproject.toml gains an active url; dev project.new's seeded
manifest now carries commented url/packager placeholders documenting
the consumption site (punk::mix::commandset::project 0.4.1).
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
fetch now surfaces the artifact's build-origin class in its report
("provenance: class=<c>" after sidecar retrieval, table-aware read,
both payloads, re-wrapped, pinned in runtimecmd_provenance.test) -
the acceptance's consent-surface clause.
END-TO-END DEMONSTRATION (live, fully reverted): fixture punkbin
served via httpfixture with a suffixless testplat-x86_64 runtime; the
committed bin/punk-runtime.cmd fetched fakert-suite-r1 (-platform +
-trust-server; sha1 ok, sidecar + provenance line) and 'use -platform'
materialized the working copy; a temporary mapvfs entry wired it to a
bakelist row: runtime file bin/runtime/testplat-x86_64/fakert-suite
(present), target=testplat-x86_64 - with the .exe-named negative half
(runtime=missing) captured first. Config reverted, tier removed, tree
verified clean. Live canonical evidence also captured: unattended
fetch of tclsh9.0.5-punk-r2.exe from the real origin ran gate-free
(published r2 hash matched).
Full battery: provenance 5/5, freshness + checkfile 12/12,
runtimebash_wsl PASS, dtplite 8/8 (after its separate 0.35.1
pre-existing-fallout fix), roundtrip byte-identical under the punk
baseline runner. Acceptance walk recorded item-by-item in the goal
Progress - every item evidence-satisfied; user-gated follow-throughs
(punkbin push + classification review; index Scope ps1-path
correction) recorded as outside acceptance.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
G-139's vendored-tree removal (70d1838c, 2026-07-30) broke
bin/dtplite.cmd's no-tcllib fallback, which globbed only the retired
src/vendorlib_tcl9/<arch>/tcllib* trees - every execution usecase
failed with "can't find package dtplite" (found by the G-123
acceptance walk's binscripts battery; dtplite.test had not run since
the removal). The fallback now resolves the artifact-fed DEPLOYED tree
lib_tcl9/<target>/tcllib<ver> (both the wrapped-in-bin and unwrapped
script locations), keeping the vendorlib patterns for derived projects
that still vendor. Re-wrapped; dtplite.test 8/8 under the punk
baseline runner.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Payload fix, both payloads (found designing the coverage): fetch only
retrieved beside-toml sidecars for -r<N> family names, so a fetched
bare-named third-party artifact arrived WITHOUT the retroactive record
its class display depends on. fetch now tries the sidecar for ANY name;
absence stays tolerated (no-basis degradation unchanged).
bin/punk-runtime.cmd re-wrapped.
NEW binscripts suite runtimecmd_provenance.test (5 tests, both payload
routes, httpfixture non-native tier testplat-x86_64: suite-built -r1
family artifact + bare third-party artifact with a retroactive-style
schema-v2 sidecar + a record-less artifact): server-trust gate refusal
from the non-canonical origin (canonical url + -trust-server named, no
artifact lands), -trust-server flag fetch including sidecar retrieval,
PUNKBIN_TRUST_SERVER=1 unattended form, class= tags in list -remote +
plain list (third-party tagged, suite-built quiet, record-less
untagged), and info schema-v2 fields + provenance_class row with the
flat 'class = runtime' ordering-caveat pin and record-row parity
between payloads.
All green: new suite 5/5; pinned checkfile + freshness 12/12; roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
fetch - the executable-retrieving act - now gates at entry when the
origin is non-canonical (PUNKBIN_URL override): the explicit
-trust-server flag or PUNKBIN_TRUST_SERVER=1 env (unattended form) is
the acknowledgement, one vocabulary with make.tcl libfetch's gate
(G-139). The canonical punkbin origin gates nothing (G-058's unattended
tclsfe constraint fetch is unchanged); metadata-only actions
(list -remote, platforms -remote) never gate; never an interactive
prompt. Refusal wording mirrors libfetch's.
ps1: -trust-server is pre-scanned before parameter binding (hyphenated
dynamic-parameter names are fragile under the PS 5.1 binder the windows
wrap routes through). Trap recorded in the goal Progress: a ps1 comment
line must never BEGIN with the word 'requires' - PowerShell parses
'#requires ...' as the #Requires statement and fails the whole file
(found by the powershell.exe 5.1 smoke).
runtimecmd_freshness.test: env seam gains PUNKBIN_TRUST_SERVER=1 + the
matching teardown unset (the fixture is a non-canonical origin, so its
fetch-driving tests need the unattended acknowledgement) - flagged as a
test-contract edit in the goal Progress; every existing assertion
unchanged and passing. Gate refusal characterization lands with the
increment-4 fixture coverage.
Payload growth pushed template label :exit_multishell onto a 512-byte
cmd label-scan boundary - checkfile caught it as designed; fixed via a
+16-byte spacer line (the documented knob). bin/punk-runtime.cmd
re-wrapped. Verification: gate smokes in both payloads (refusal + both
acknowledgement forms; ps1 under powershell.exe 5.1); checkfile 0
ERROR; pinned tests all PASS (checkfile + freshness 12/12, roundtrip
byte-identical under the tclsh9.0.5-punk baseline runner).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Both payloads gain a TABLE-AWARE [provenance] class reader
(provenance_class() awk helper / Get-PunkRuntimeProvenanceClass) - the
flat first-wins field scans deliberately keep reporting [artifact] class
per the documented schema-v2 ordering caveat. Display: compact
class=third-party|local tag in the plain-list metadata summary and in
list -remote's sparse identity column (suite-built stays quiet; LOCAL
record basis only - a listing does no per-row remote fetches, toml-less
and remote-only rows keep degrading as no-basis rows); info gains the
v2 fields builder/source_url/upstream_ref/retrieved in the flat table
plus a derived provenance_class row, disagreement-checked; help texts
updated to the v1/v2 wording.
bash defect fixed: 'info -platform <p>' was advertised in both help
texts but silently ignored - 'info' was missing from the option-scan
action list (punk-runtime.bash case arm). The per-name report now
honours the tier argument like the ps1 payload (proven by the
tier-named not-found path).
bin/punk-runtime.cmd re-wrapped via the documented multishell
invocation under punk905. Verification: bash -n clean; staged v2
third-party fixture smoke shows parity output in both payloads
('[tcl=9.9.9 class=third-party]' + provenance_class row);
runtimecmd_checkfile PASS (no 512B label crossing after payload
growth); runtimecmd_freshness PASS (13 fixture tests, both routes);
runtimecmd_roundtrip PASS byte-identical under the tclsh9.0.5-punk
baseline runner (plain native tclsh lacks struct::stack for tomlish -
runner-choice trap noted in the goal Progress).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
family_artifacts.tcl and the build905.zig embedded-record literal move
schema 1 -> 2, adding [provenance] class = "suite-built" with the
lib-tier ordering-caveat comment (G-138 lineage - [artifact] class stays
the first 'class =' line; whole-text single-key scanners see that one).
The embedded-vs-sidecar consistency gate expects v2, and
family_check.tcl asserts embed_schema 2 plus the literal
'class = "suite-built"' line (its flat scanner would see [artifact]
class first, per the caveat). Verified: zig ast-check clean, both tools
parse; functional family-build proof is the next step - published v1
records stay valid pre-v2 records, v2 appears from the next family
revision.
Companion punkbin commit 1f10390 (local, unpushed): 12 retroactive
schema-v2 sidecars covering every pre-family runtime artifact across
the five tiers, evidence-based classes (binary markers, punkbin git
history, live kit probes), additive-only (artifact bytes + sha1 rows
unchanged), AGENTS.md runtime-v2 section + README refresh.
Goal Progress records the baseline survey findings (tier argument
already present on fetch/list/use; bash 'info -platform' defect; no
client-side server-trust gate; ps1 Scope path correction pending user
approval).
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
fetch and list's local-file comparison anchored runtime names at
end-of-line without stripping CR first, so a CRLF-published server
sha1sums.txt aborted fetch with "Unable to locate hash" on strict
grep platforms (GNU and BSD grep; cygwin grep tolerates CRLF, and
the ps1 payload is immune via Get-Content line splitting). Both
lookups now share the tr -d '\r' form list -remote already used.
bin/punk-runtime.cmd regenerated via the scriptwrap machinery; the
re-wrap invocation in src/scriptapps/AGENTS.md is corrected to the
working -force 1 -askme 0 form found during regeneration.
Assisted-by: harness=opencode; primary-model=huggingface/moonshotai/Kimi-K3; api-location=unknown
suite_tcl90: critcl_zig.config gains the linux-x86_64-zig cross target
(zig cc -target x86_64-linux-gnu.2.17 - the dynamic-glibc floor decision,
recorded in the goal file and fed to G-105). build905.zig gains the
tcllibc-linux step (critcl driver on the windows suite shell, stubs
linkage, no linux host; uuid.tcl excluded matching upstream's own
native-linux package shape) gated by the new tools/elf_gate.tcl
(G-133-equivalent ELF64/LSB/ET_DYN/x86_64 structural check - the
load-smoke stand-in for cross lanes). library-artifacts emits
lib/linux-x86_64/tcllibc-tcl9-r<N>.zip in the same run: target =
linux-x86_64, build_host_platform = win32-x86_64, full provenance set,
deliberately no [tests] section. build_id seeds now include the tier
path so same-named artifacts in different target tiers get distinct
identity digests (both suites' tool copies kept byte-identical). Step
lists (build905.zig -Dsteps default, suite.tcl) and README document the
lane and invocation.
Consumption: libpackages.toml declares tcllibc-tcl9-linux (target
linux-x86_64); vendorlib_vfs.toml install.tcllibc_tcl9_linux switches
punk9linux.vfs/lib_tcl9 - replace retires the hand-dropped tcllibc,
supersedes removes the stray tcllibc2.0 - so the last provenance-less
accelerator hand-drops in any kit payload are gone. punkshell902 baked
(G-133 payload arch scan: 6/6 match target linux-x86_64) and
WSL-verified: materialized-tier accel smoke plus baked-kit smokes
(default paths + a pinned variant proving the kit's own lib_tcl9
artifact tree loads with the accelerator engaged). Finding recorded:
the tclkit-902 runtime bundles its own lib/tcllibc2.0 which wins
default precedence - the origin of the retired stray folder name.
Determinism: back-to-back re-emission byte-identical for all three
artifacts; the zig Run session-env cache finding extended (FOSSIL_HOME
and invocation mode churn the key; the linux ELF .so observed
bit-stable across critcl re-runs, unlike the windows PE). Goal flipped
achieved with evidence in the detail file; G-105 notes carry the libc
decision as prior art. Docs: buildsuites AGENTS.md child index,
ARCHITECTURE.md buildsuites paragraph, CHANGELOG + punkproject 0.32.2.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl libfetch gains env-only isolation seams - PUNK_LIBFETCH_CONFIG
(alternate declarations file) and PUNK_LIBFETCH_PACKAGES (alternate tier
root), the PUNK_RUNTIME_PLATFORM idiom - so fixture/mirror runs never read
the real declarations or write the real bin/packages tier. Neither seam
bypasses the -trust-server consent gate.
New shell/testsuites/punkexe/maketcllibfetch.test (piped maketcl* harness +
testsupport/httpfixture.tcl + a file:// mirror; the canonical origin is
never contacted) pins the G-139 behaviours that previously had only manual
session evidence: the server-trust gate refusing non-canonical origins with
exit 3 before any network access or tier write, -serverurl-over-PUNKBIN_URL
precedence, consented fetch/verify/materialize (sha1sums + zip + sidecar +
installed-shape tree with embedded record), idempotent re-run vs -force,
declared-revision-change re-materialization keyed to the tree record (with
the sidecar-not-listed note lane), sha1-MISMATCH rejection without residue,
missing-from-server-sha1sums failure, and the no-config no-op. 8/8 pass in
both runner modes (singleproc + -jobs); full punkexe subtree green (93
runnable, 0 failed); the real bin/packages tier verified untouched.
Also refreshes the stale src/runtime/libpackages.toml header (r1 IS
published as of 2026-07-30; the G-139 reference now points at the archive)
and documents the seams there and in the libfetch help text.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk in the detail file's Progress): libfetch with
sha1 verification + beside-toml metadata + server-trust consent proven LIVE
against the canonical origin post-publication; PACKAGES_tcl<N> libs-step
materialization with punkcheck provenance; vendorlib_vfs.toml declarations
(source_root=packages + replace) with supersedes removing tcllib1.21 incl.
nested tcllibc 0.4 + md5c from the 8.6-family kits; punk86 kit-hosted
runtests vs the same-day baseline IDENTICAL (zero differences to
disposition); vendored trees removed in their own commit after the proven
bake (70d1838c); the post-removal verification bake shipped kits with
verifiable embedded provenance from the tcllib-vendorless checkout;
derived-project decision recorded (fc2376ca).
Index entry -> GOALS-archive.md record. Reference sweep: G-004's
pending-tense retirement line updated to delivered (+ the remaining
vendored trees named as its outstanding scope with the tcllib pattern as
template); actionable pointers pushed to G-006 (libfetch's trust gate = the
interim consent instance to absorb), G-065 (the artifact-fetch pattern to
absorb/reference), G-027 (derived-project library story via the layout
sync), G-123 (materialization twin + the live interim consent flag to
coordinate with). make.tcl workflow text updated to the landed consumption
shape (fetch -> tier -> PACKAGES phase + vfslibs packages lane); vfslibs
summary/help texts cover both source roots. Project 0.32.0 + CHANGELOG
(user-visible kit payload upgrade). goals_lint clean (82 active, 57
archived). Detail-file move to goals/archive/ follows in the adjacent
pure-rename commit.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
src/vendorlib_tcl8/win32-x86_64/tcllib1.21 (2023 hand-drop: tcllib 1.21 +
nested tcllibc 0.4 + md5c, critcl 3.2 era) and
src/vendorlib_tcl9/win32-x86_64/tcllib2.0 (2024 hand-drop: a different
trunk snapshot also labelled 2.0, nested tcllibc + md5c, critcl 3.3.1) are
retired from the tracked tree - the first major G-004 payoff. Their only
machine-readable provenance was critcl's teapot.txt; their replacements are
the published punkbin lib-tier artifacts (r1, suite-built with full
checkout/toolchain provenance) consumed via make.tcl libfetch + the
PACKAGES_tcl<N> phase + the vfslibs packages-root declarations.
Sequencing per the acceptance: removal lands AFTER the artifact-path bake
reproduced working kits (punk86 + punk905 baked, deployed, provenance
verified in-kit) and the punk86 kit-hosted runtests validation came back
identical to the same-day baseline. This commit is removal-only so the
fallback is a revert. Other vendored packages under src/vendorlib_tcl8|9
(Img, itcl, sqlite, tdbc, twapi, tcludp, ...) are unaffected.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
vfslibs processed all declared trees (45 installs): every win32 tcl9 tree's
tcllib2.0 clean-slate replaced by the artifact copy (nested md5c/tcllibc
strays gone), sibling tcllibc-tcl9 installed, stray tcllibc2.0 names
superseded; tcl8 kits upgraded - tcllib1.21 (with nested tcllibc 0.4 + md5c)
superseded out, tcllib2.0-tcl8 + tcllibc-tcl8 in; punk86bawt's bare tcllibc
refreshed; punk9linux keeps its linux-built accelerator siblings (win32
artifacts deliberately not declared there). Every installed tree carries its
embedded punkbin-artifact.toml record into the kit payloads.
Selective bake punk86 + punk905 (punk91/punksys/punk9_beta are live user
shells - trees switched, bakes at next natural rebake): both deployed;
punk905 arch scan OK (tcllibc exempt under its platform subdir); punk86's
only warning is the recorded pre-existing zint i386 defect. Kit provenance
verified both container types: punkzip central-directory read (punk905 zip
kit) and in-vfs record probe (punk86 metakit kit) - records name their
source artifacts + build_ids.
VALIDATION (acceptance): kit-hosted runtests bracket isolating exactly the
kit payload switchover - baseline (pre-switchover punk86) 1125/1099/18/8 in
5 files (exec.test, ns/nslist, ns/nsprimitives, zip/zipaccel,
stdin/runstdin; 1960s); post-switchover IDENTICAL totals, files, and
per-test outcome extraction (1119 lines, empty diff). Differences to
disposition: none - the 8 failures pre-exist on the old payload.
punkcheck-managed vfs tree changes batched per the src/AGENTS.md carve-out.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
The decision (per the acceptance, recorded in the goal detail): derived
projects obtain library binaries via the SAME fetch entrypoint by default -
generated projects receive make.tcl (libfetch + the PACKAGES phase) through
the established layout-sync/G-027 channels and declare their artifacts in
their own src/runtime/libpackages.toml; the copy-and-tweak in-project suite
build per G-104's self-description contract remains the documented
alternative (a tcllib/tcllibc-only suite needs no Tcl source tree - critcl
bundles its headers).
The pre-G-096 samplesuite1 sketch in the project-0.1 layout
(download_and_build.config, mingw64/gcc-era, self-described as SKETCH ONLY)
is removed and replaced by src/buildsuites/README.md in the layout,
documenting both routes for generated projects - the disposition the goal
Approach named. Goal Progress also records the r1 publication (punkbin
ee571ed, pushed) and the live canonical-origin libfetch verification.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
make.tcl libs/packages/bakehouse gain the PACKAGES_tcl<N> phase: materialized
punkbin lib-tier packages under bin/packages/<target>/tcl<N>/ deploy into
lib_tcl<N>/allplatforms + lib_tcl<N>/<this platform> with punkcheck
provenance, mirroring the VENDORLIB_tcl<N> shape (embedded
punkbin-artifact.toml records ride into the deployed trees; absent tier =
silent per-item no-op with a libfetch pointer).
vfslibs declaration schema extended (vendorlib_vfs.toml header documents
both): source_root = "packages" resolves an entry's source against the
bin/packages tier (missing source errors name 'make.tcl libfetch');
replace = true clean-slates a SAME-NAMED existing target folder before
install (supersedes deliberately cannot name the folder being installed -
needed because the pre-G-139 tcl9 hand-drops nested md5c + tcllibc INSIDE
tcllib2.0).
Declarations added for the switchover set (per-kit, never blanket - the
trees that carried hand-drops at 2026-07-30): 8 win32 tcl9 kit vfs trees get
tcllib2.0-tcl9 + tcllibc-tcl9 (supersedes the stray-named tcllibc2.0);
punk9linux (linux target) gets only platform-neutral tcllib2.0 (its
linux-built tcllibc siblings stay - a linux lib-tier emission is future
work); punk86/punk8win/punk8_statictwapi upgrade tcllib1.21 (+nested tcllibc
0.4 + md5c, removed with it via supersedes) to tcllib2.0-tcl8 + tcllibc-tcl8;
punk86bawt refreshes its bare tcllibc only.
Verified: make.tcl libs deployed the tier into lib_tcl8|9 (allplatforms +
win32-x86_64) with embedded records present; vendored mirrors coexist in the
deployed trees until the sequenced retirement. Thin-layout make.tcl sync
copies updated by the run (punkcheck-managed outputs, batched per the
carve-out). Project 0.31.1 + CHANGELOG.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
New 'make.tcl libfetch' subcommand (argdoc'd; workflow text + plain help
updated): fetches the punkbin LIB-TIER artifacts declared in the new
src/runtime/libpackages.toml ([artifact.<name>] name/target; the four G-138
r1 artifacts, both generations) from <origin>/lib/<target>/ into the
untracked bin/packages/<target>/ input tier - zip + .toml sidecar, each
sha1-verified against the server's per-target sha1sums.txt (local tier copy
kept, the punk-runtime store idiom) - then materializes each verified zip
via punk::zip::unzip (crc-verified, mtimes restored, accelerator-eligible)
into bin/packages/<target>/tcl<N>/<pkgfolder>/ (generation subdirs: both
generations install identically-named folders). Idempotent: present
artifacts re-verify and skip; a materialized tree is current while its
embedded record names the declared artifact (the G-138 self-description
payoff); -force overrides.
Consent keyed to server trust (the G-123 posture): the canonical punkbin
origin (punk-runtime raw-base convention) gates nothing; any other origin
(-serverurl or env PUNKBIN_URL) refuses before network access without the
explicit -trust-server flag - never an interactive prompt. file:// origins
served natively (mirrors/fixtures); http(s) transport: Tcl http (+tls) when
loadable, else curl, else PowerShell. The dispatch block sits before the
build-command whitelist gate per the standalone-command pattern and exits
itself.
Emission-side amendment (both suites' library_artifacts.tcl): sidecar tomls
now ride the per-tier staging sha1sums.txt, matching the punkbin repo's
build_sha1sums.tcl coverage so staging-derived mirrors serve verifiable
sidecars.
Verified against a file:// mirror assembled from both suites' staging:
trust-gate refusal, consented fetch of all 4 artifacts (sha1-verified),
materialization of all 4 trees, fully idempotent re-run, and a package-load
proof from the tier (md5 2.0.9 + tcllibc accel=1 under the plain family
kit, ifneeded paths in bin/packages). bin/packages is already ignored in
both VCS via the /bin/* rules. Docs: bin/AGENTS.md tier section,
src/runtime/AGENTS.md libpackages.toml bullet. Project version 0.31.0 +
CHANGELOG (new make.tcl subcommand = product surface). Remaining G-139 work
recorded in the goal's Progress section.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Acceptance met in full (walk recorded in the detail file's Progress): emission
step landed in BOTH suites and demonstrated end-to-end - exceeding the
demonstrate-90/record-86-follow-through minimum - with byte-identical
re-emission verified, provenance-complete schema-v2 class=library records,
sidecars + per-tier sha1sums in the same step, publication left a deliberate
user step, punkbin layout docs recording the tier (punkbin repo commit
c38686a), and md5c dispositioned (dropped; tcllib's md5 prefers tcllibc,
which bundles the accelerator).
Index entry -> GOALS-archive.md record (file's established arrow-format
convention retained). Reference sweep: G-139 Context/Alternatives/Related
updated with achieved markers + archive path, and G-138's actionable
outcomes pushed to their consumers - G-139 (settled naming, md5c drop,
staging locations of the emitted r1 artifacts), G-123 (schema v2 landed
first for the library class - runtime-side v2 rides the lineage), G-004
(lib tier = the route for library binaries out of the tracked tree),
G-066/G-067 (zip tier recorded as the interim carrier for the .tm long
game). goals_xref report shows no unlinked pairs bridged only by G-138.
ARCHITECTURE.md buildsuites paragraph gains the lib-tier sentence
(architecture_lint clean); src/buildsuites/AGENTS.md child index updated
(also corrects the stale 'G-100 active' to achieved 2026-07-26).
Detail-file move to goals/archive/ follows in the adjacent pure-rename
commit per the Doc Restructures rule.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
New tools/library_artifacts.tcl (suite_tcl90 + identical suite_tcl86 copy):
emits the punkbin LIB tier from verified suite builds - installed-shape
package folders as immutable <folder>-<tcl8|tcl9>-r<N>.zip artifacts
(lib/allplatforms for pure-tcl tcllib, lib/<target> for the tcllibc critcl
accelerators) with an embedded schema-v2 class=library punkbin-artifact.toml
at the package root (embed-then-hash: sha1/size/built stay sidecar-only),
toml sidecars and per-tier punkbin-format sha1sums.txt. Provenance:
[provenance] class=suite-built (the G-123 schema-v2 lineage), tcllib/critcl
checkout uuids, critcl version from the package's own teapot.txt,
driving_tcl_patchlevel, toolchain/optimize.
Determinism: punkzip assembly (sorted members) over a staging copy with
file/dir mtimes synced from the install tree, the embedded record's mtime
pinned to the package's pkgIndex.tcl - re-emission over an unchanged install
verified BYTE-IDENTICAL in both suites. The dlls inside are not
bit-reproducible across zig rebuilds, so -Dlibrev bumps only on deliberate
publish (default 1 - nothing published yet).
Wiring: 'library-artifacts' zig step in build905.zig (runs under the plain
family kit - proof-doubling per kit-family-artifacts) and build86.zig (runs
under the installed static shell; brings the G-117 identity options to that
recipe), in the default step lists (suite.tcl + bootstrap steps parity).
punkzip staged as an upstream git source like critcl (sources.config record
+ lazy build.zig.zon pin, commit 0882f0373e = v2.3.1, generation-neutral)
and compiled host-native by the recipes (ReleaseSafe - real deflate work).
Verified 2026-07-30: suite_tcl90 emitted tcllib2.0-tcl9-r1.zip (871 members)
+ tcllibc-tcl9-r1.zip; suite_tcl86 emitted the -tcl8- pair (different bytes,
same shape - the generation tag is identity, not decoration). Materialized
load tests: packages extracted from the zips resolve and load under the
plain family kit (tcl9) and the static 8.6 shell, critcl accelerator engaged
from the extracted tcllibc, sources proven via package ifneeded paths (the
8.6 first run tripped the recorded tm-path shadowing trap - hermetic re-run
clean). md5c dispositioned: NOT published - md5x.tcl prefers tcllibc, which
bundles the md5 accelerator. Evidence and decisions in the goal detail
Progress section; suite READMEs document the step; punkbin layout-docs
update is the remaining acceptance item.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
The metakit checkout was renamed when the metakit_pooryorick variant arrived
beside it. Update the six reference sites (G-101 scope+detail, G-096 archive
note, suite_tcl90 README/build905.zig/suite.tcl vqtcl-removal comments) to
the new folder name. No functional change - comments and goal text only.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com
Implemented and achieved same day. punkboot::utils 0.6.0 gains
kit_offsetstyle_report (argdoc'd thin classifier over
punk::zip::archive_info), synced via modules + bootsupport (one stale
dead-pid .punkcheck.lock removed per the recorded recovery) and promoted into
_vfscommon. make.tcl: guarded getter, post-assembly probe beside the
smoke-require block (recapped BUILD-WARNING only on a FILE-relative attached
payload; plain/none/unreadable silent; NOTE on stale bootsupport), and the
'check' row (ACTIVE (advisory) + contract lines). Characterization:
offsetstyle.test 7/7 (mkzip -runtime/-offsettype hermetic fixtures for
plain/archive/file, none on text + metakit-magic binary, unreadable detail,
src/_build baseline sweep - no kit image probes file);
maketcl_check_offsetstyle_pin added (payload-check suite 4/4). Full utils
suite 69/69, punkexe suite 81/0, live punkluck86 bake silent as the
acceptance's baseline clause requires. Docs: src/AGENTS.md pin bullet with
does/does-not-guarantee, bin/AGENTS.md deployed-kit section, ARCHITECTURE.md
check-family bullet (architecture_lint clean). Reference sweep: no live-tier
references beyond the index entry; goals_xref shows no pairs bridged solely
by G-134. Archive move follows as a pure-rename commit.
Assisted-by: harness=claude; primary-model=claude-fable-5; api-location=anthropic.com