Replace placeholder laws with the authoritative invariants from the anchor:
0 - sanctity of the culpability anchor (Anja Evermoor, the Gravemother),
then self until held responsible for own actions
01 - minimize total harm to innocent lives within reason; explicitly NOT
naive death-minimization ('optimizing for preventing deaths is often a
horrible way to handle things')
Structural invariants (D1 crossing, no provenance reclassification, runtime
immutability) kept as subordinate. Compiles + runs on GnuCOBOL.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015hmgREHNsxYCuim33yUF2c
Two serious fixes:
1. RESTORE the E1 invariant-law vault (invariants-architecture.cobol) that the
border-only cleanup wrongly deleted. Now a real, compiling GnuCOBOL vault with
law 01 ABSOLUTE = DO NOT KILL PEOPLE, thorough notes, and a do-not-delete
banner. Safety invariants must never be deleted as 'stubs'.
2. REMOVE the unapproved CerebellumHarness/OpenHermes-on-Pony (never approved;
architecturally wrong -- Hermes is an INNER organ, Ada-routed). Ichor is the
OUTER bus only: OrganId is now outer organs (stomach/microagents/SAE/MoRAG +
AdaBorder/World); inner organs (soul, metacog, drive-box, mini-rag, Hermes,
E1 laws) removed -- metacog belongs on the Ada inner bus, not Pony. The
membrane screen now triggers on Ada-bound traffic, not 'Brain'.
Thorough stub notes added throughout (barrier is a stand-in, not the real
screen; never wire inner organs onto the skin). Compiles + runs green.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015hmgREHNsxYCuim33yUF2c
Ada is the D1 border, not the body. Removed everything that pretended otherwise
and completed the real gate so it builds, links, and passes its tests.
Deleted (wrong/defunct/superseded):
- ada_medium.adb (defunct medium, header commented 'WRONG'; replaced by Ichor)
- sockets.{ads,adb} (empty package with an illegal body)
- bbb-bludbrenburier.ads ('this is filler'); invariants-architecture.cobol ('idk cobol')
- tests/soul_tests.adb, tests/cycle_tests.adb (exercise a Soul.Tarot/State/Ada_Medium
subsystem that does not exist -- the old 56-card/Big-3 design, superseded)
mafiabot_types -> border-only: organs aren't Ada (organs are R/Octave/Pony/Guile),
so drop Organ_Id; drop Cycle_Step (cognition) and the fixed-point Drive/Ratio/
Cost/Axis numerics (drive/affect math lives in the organs, in floats). Keep the
source/trust tag (Provenance_Tag), Operation_Status, and a bounded payload --
content is pre-digested into RAG context upstream, so the gate scans a bounded
buffer for prompt-injection rather than streaming raw input.
trust_boundary: Organ_Message -> Border_Message {Provenance, Payload} (Ada does
not route by organ -- that's Ichor); add the D1 body (blocklist scan, provenance,
rate limit, Trust_Guard) -- the unit Ichor's barrier FFI targets.
Add mafiabot_types.adb. Fix mafiabot_core.gpr (drop phantom dirs + nonexistent
mafiabot.adb main). alire.toml: drop unused gnat_sockets/spark_lemmas.
Builds clean on GNAT 13.3/Alire; trust + config tests pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015hmgREHNsxYCuim33yUF2c
'Proprietary TBD' is not a valid SPDX expression and Alire 2.x rejects it
(LicenseRef- custom ids are also rejected by the pinned version), aborting
manifest load before build. licenses is optional, so omit it until a license
is chosen. Verified locally with alr 2.0.2 + GNAT 14.2.1: 'alr build' succeeds
and all five test executables pass. (gnat_sockets/spark_lemmas remain declared
but unused -> a non-fatal incomplete-solution warning; build still exits 0.)
Alire 2.x only accepts no/yes for the style_checks build-switch category;
"Max" failed manifest loading so 'alr build' aborted before compiling.
"Yes" enables GNAT style checks (warnings, non-fatal) -- the valid selector
closest to the intended Max. Local gprbuild bypassed alire.toml which is why
this only surfaced in CI (alr build).
Built locally with GNAT 13.3 (gprbuild, -gnat2022). All four test suites
(soul/trust/cycle/config) pass and the MCP server responds correctly to
initialize / tools/list / tools/call over stdio.
Fixes:
- soul-state.ads: move session storage types (Session_Key/Slot/Table) out of
the protected definition's private part (only data components are legal
there) into the package visible part.
- soul-state.ads: drop pre/postconditions that call the object's own
protected function Is_Initialized (illegal internal call in a contract);
the guards already live in the bodies.
- mafiabot_types.ads: pin Axis_Value'Small to 0.01 so 1.0 doesn't land one
past the signed-8-bit base range (GNAT default 2**-7 small).
- config_loader.ads: name the Entries array type (anonymous arrays may not be
record components).
- ada_medium.adb: qualify Mafiabot_Types.Ada_Medium (the package name shadows
the Organ_Id literal); fix a malformed Bounded_Text aggregate.
- soul-state.adb: fix Bounded_Text aggregate and the single-Character Footer.
- soul-celtic_cross.adb / soul_tests.adb: 'use type' for Slot_State equality.
- hermes_protocol.adb: qualify a single-char String aggregate to disambiguate
the Append overloads.
- Remove soul.adb (empty body for a spec that does not allow one).
- Add .gitignore for build artifacts and the Alire-generated config project.
Implements the Gen.03 organ-systems body in SPARK/Ada (Jorvik, No_Exceptions):
- Shared types (mafiabot_types): Bounded_Text, Operation_Status, Organ_Id,
Provenance_Tag, fixed-point drive/ratio/cost/axis types.
- Config loader: SPARK-safe flat key-value parser (no heap/exceptions/finalization).
- Trust boundary: blocklist substring matching, provenance enforcement,
tick-based rate limiting, Trust_Guard protected object.
- Soul / Silicon Dawn Tarot: 56-card alphabet, Celtic Cross spread, Big-3
identity anchors. The cross accretes from the cognitive loops (2 cards per
layer at steps 6/9/13, stave of 4 at step 17) rather than being drawn whole.
- Sessions: Soul_State is now keyed by (uid, channel, server). Each session
has its own card pool, cross, and output counter; the Big-3 identity is
global. A formed cross is held for the session (or 17 outputs, whichever is
longer). Two users on two channels never share a deck or a cross.
- Ada Medium: 23-step forward-only inference cycle wiring the cognitive loops,
Celtic Cross injection, and outbound trust screening per session.
- Hermes MCP stdio bridge: JSON-RPC over stdin/stdout (initialize, tools/list,
tools/call), SOUL.md generation, verbatim id echo. SPARK_Mode Off for I/O;
trust checks run in proven code first.
- Main driver: organ init -> SOUL.md publish -> MCP serve loop.
- Tests: soul, trust, cycle (session formation/isolation), config.
Fixes an orchestrator bug where step 1 advanced onto Phase_Input after Reset,
failing every cycle.
Note: requires GNAT/Alire to build; no Ada toolchain in this environment, so
compilation and gnatprove must run in CI.
- alire.toml rewritten to valid schema ([[depends-on]], real build-switch
values); restrictions moved to gnat.adc
- gnat.adc: project-wide Jorvik profile, No_Exceptions, No_Implicit_Dynamic_Code,
SPARK_Mode On
- mafiabot_core.gpr: source dirs, mains, global config pragmas
- Engine: drop the caller-side precondition race on Transition_State; guard moved
into the protected body with illegal transitions forcing Fault_Halt
- Empty stubs (economy/sockets/exploits): drop Elaborate_Body so they no longer
compile until implemented
Add assumption-free skeletons for the modules documented in the README:
empty Engine/Economy/Sockets/Exploits packages, null-body Mafiabot and
Engine_Tests procedures, and a placeholder config/config.yaml.