Construction Log · Ruling A: Build, Don't Retreat
A white-box, LLM-guided engine for architectural generation. Every step is an auditable decision; every unresolved responsibility remains visible on the ledger. The work shown here is a live construction record, not a polished claim of completion.
Tradition packs, canon ratios, type masks and structural capability tables define what may be written as law.
Law narrows each real menu before deterministic, LLM or human policy selects an action.
Premise, plan, tradition, massing, structure, composition, validation and evaluation form one replayable trajectory.
A minimal sufficient state carries premises, slot reads and writes, and current commitments.
Obligations are created and discharged across decisions. Anything unresolved remains as debt and produces an honest refusal.
to_voxels() is the only projection from physical geometry into the discrete space where the artifact is judged.
Plans, sections, elevations, isometrics, transcripts and provenance remain bound to the same building run.
Regression, system health and frozen goldens guard the executable path.
Adversarial building cases search for “validation passed, architecture wrong.” The repair changes the law, then replays the derivation.
Construction Log · 判决 A — 加速建造 · Ruling A: Build, Don't Retreat
白盒 LLM 引导体素建筑生成引擎:每一步都是可审计的决策,每一份责任都在账上。摘要 v6 投稿候选的每一句,都是 2026-10-26 全文截止前的建造义务。
Modify M0–M3 is now the sole numbering system for repairs to the live path. P0–P4 remains historical evidence of how V3 was constructed; R0–R3 retires superseded mechanisms after their replacements take ownership; M0–M3 removes false greens, connects canon and citations, separates building-specific facts, and adjudicates orphan constants.
A colonnade no longer passes because its centre-lines merely appear collision-free. TectonicEnvelopeIR@0 compiles full column envelopes, explicit lintel edge-sets and three classes of placed interfaces before structure and detail. Envelope overlap, missing hosts, broken junctions or stale state all fail closed. D2/D4 evidence confirms clear spacing, a shared-volume entrance and dome-to-drum support; the clean baseline is 1651 passed · 47 skipped · 131 subtests.
D no longer doubles as both architectural module and voxel resolution. Each building receives an AdaptiveModuleFrame@0 that separates physical module D_phys from representational density rho. Placement, grids and porticoes read only the physical frame; convert is the single rho projection channel. Scaling D2→D4 doubles physical bounds and multiplies volume by eight without changing component IDs, obligations or topology.
Declared use is now separated from causal use. Building-level fields require producer→consumer→artifact remove/perturb evidence, registry coverage, archive eligibility and a named repair stop. Fields that are merely registered, logged or read remain declared_but_inert.
The critic observes a detached, read-only snapshot and fails open with receipts. The scheduler survives ordinary critic exceptions without allowing critic mutation into production state. Evidence: 20 targeted tests + 3 subtests, 16 readiness tests, Doctor 0 and selfcheck 16 + ruin.
Retrieved facts and obligations can now enter a bounded, building-scoped memory path. RAD corpus facts archive through the per-building router; compact memory materialises only declared reads and dependency closure. Evidence: RAD 4 targeted; compact memory 71 targeted; obligation bridge 7 targeted.
Retirement is now measured by production ownership, not file deletion. The read-only audit records composer calls 4 (legacy 2 / decision 2), keyword-route surfaces 12 (production entry 3 / fixture 2 / learning 6 / proposer 1), and legacy adapters 3. Audit cards passed 2 + 3 + 3 targeted tests; the counters remain debt, not completion.
Selective Repair is now a sealed, child-only run. Old and new semantic read/write sets expand the affected dependency closure; unaffected answers are reused byte-for-byte, affected rounds are recomputed, and the parent proof stays immutable. The evidence manifest is the sole publication point.
The critic can no longer cite an in-training score as readiness. Held-out readiness is recomputed from frozen models, evaluators, feedback and blind-screen manifests. The current state is honestly blind=0; the prior 0.878 remains an in-training reconstruction and cannot justify reinforcement learning.
Modify M0–M3 已成为现役路径修正的唯一执行编号:P0–P4 只保留为 V3 架构怎样建成的历史证据;R0–R3 负责旧机制在替代者接管后退出生产;M0–M3 负责止假绿、接 canon 与补引注、清实例污染、收编无主数。R 与 M 可以并行,但同一卡只归一条线;本周仍以 Retirement 为主攻,Modify 先 M0 再 M1,M2/M3 不抢跑未判数字。
files ▾活消费者不再停在“被读取”:逐楼字段必须交 producer→consumer→artifact 的 remove/perturb 双证,进入登记、归档准入与具名修复停止;只登记、记录或读取但不改变工件者继续判 declared_but_inert。
critic 只读且普通失败 fail-open:观察从生产黑板脱离冻结,异常逐决策上账但不中断 scheduler,也不能借嵌套可变对象写回状态。证据为 20 定向 + 3 subtests、readiness 16、Doctor 0、selfcheck 16+ruin。
检索事实与义务已进入逐建筑有界记忆路径:RAD 语料经 ArtifactRouter 归档;紧凑记忆只展开 declared reads 与依赖闭包,不从 payload 脑补建筑语义。证据分别为 RAD 4、memory 71、obligation bridge 7 项定向。
退役改用生产所有权计量,不以删文件冒充完成:composer 调用 4(legacy 2 / decision 2)、关键词路由 12(真实生产入口 3 / fixture 2 / learning 6 / proposer 1)、legacy adapter 3。审计卡 2+3+3 项定向通过;计数仍是债,不是完成率。
柱列不再以中心线“看起来没撞”就算成立:TectonicEnvelopeIR@0 在结构与细节前编译完整柱包络、显式楣梁 edge-set 与三类 placed interface;包络重叠、host 缺席、接头不连贯或状态陈旧都 fail-closed。D11 不再删环柱凑入口,也不在缺 host 时先落 facade、coffer、pediment 或 aedicula。D2/D4 八图确认柱列净距、共享体积入口与穹—鼓承托;全量 1651 passed · 47 skipped · 131 subtests。
D 不再同时冒充建筑模数与体素分辨率:逐楼 AdaptiveModuleFrame@0 将物理模数 D_phys 与表现密度 rho 分开;placement、柱网与门廊只读物理 frame,convert 是唯一 rho 投影门。同一物理建筑 D2→D4 三维 bounds 精确×2、体积×8,145 个构件、ID、义务与拓扑不变;非万神殿 stoa 复用同一编译器。默认路径、Pipeline.run 与 Gold 零变化。
critic 不再凭训练内高分自称就绪:CriticHeldOutEvidence@0 从冻结模型、评估器、反馈、盲屏 manifest 与逐条 holdout 观察重算 tie-aware Spearman 和同屏 pairwise。训练/留出家族交叠、坏指纹、重复记录、非正相关或缺盲评都具名 NOT_READY。当前实况是 blind=0;既有 0.878 只是训练内回算,不能进入 RL。全量 1624 passed · 47 skipped · 131 subtests。
外部席的“一次”从进程纪律升级为跨进程持久许可:external_attempt sidecar 经 ArtifactRouter 的锁、WAL 与 manifest 在 transport 前公开提交;同一 building run + adapter + request 指纹只能赢得一次授权。准确承诺是 durable at-most-once dial authorization,不是 provider exactly-once;许可后、拨号前死亡可以零次,但绝不允许第二次。落盘不含 prompt、key、response 或预算私账。
Selective Repair 已从内存语义内核闭合为只写 child 的 sealed run:实际语义读写生成 old/new 依赖闭包,无关轮原回答字节复用,受影响轮显式重算,父 proof 永久只读;source/base/child checkpoint、plan、result、proof supersession 与 lineage 经 R0.2 Router/WAL 归档。最终 evidence manifest 是唯一公开点,未封印、半写、追加或漂移全部拒绝。默认 scheduler、几何与 Gold 未改变。
files ▾真实检索/LLM 席已接入现役公式,但默认仍零注册、零联网:wire body/response 字节硬界、进程级防重、预算 escrow、累计与单次费用门、raw 结构秘密门和 backend 身份→拨号同源均已闭合;provider 失败不重试、不回退。对抗探针覆盖 39,832 字符零秘密命中;当轮全量 1570,随后由 R1.8B、R1.9 与 P2.3A 继续抬升。
files ▾多步重放不再是“把单步 API 套进循环”:ReplayChain@0 逐轮绑定父链、完整知识前态、typed delta、后态与 validator 指纹;整链先在隔离 Blackboard 上验证,全部通过后才一次交换 live state。两步“检索→拓扑”重放与原 derivation 哈希相同;任一步漂移都让真实板、Ledger 与 derivation 零漂移。当前只完成 exact replay 底座,尚未宣称 Selective Uncommit。
第一条计算问句全链已经接到真实结构消费者:逐楼 ColumnGridIR 经具名义务、独立公式轮与 placement-bound bundle 进入 portico;consumer 每个 node 只发一柱,只沿显式 rank/alignment 发梁。scope、重放、承托或跨限任一不实即零发射、零清债;两种建筑复用同一编译/求解法,默认几何与 Gold 零漂移。最后一次无并列中间态的全量基线为 1458 passed · 47 skipped · 60 subtests。
files ▾逐楼事实账从“同进程原子”推进到可恢复的跨进程提交:ArtifactRouter 以 workspace 文件锁串行写入,正式文件变更前先落 WAL 与旧 artifact 备份;manifest replace 是唯一提交点。进程在 artifact 后硬退出会回旧代,在 manifest 后硬退出会保留新代;错楼 scope、坏 journal 与身份漂移全部 fail-closed,但不冒称介质损坏或分布式文件系统安全。
files ▾M0 与 M1 已从待施工推进为四张完成卡:fluted 内容闸门、checkpoint 一致性锁、portico order/D canon 通路与字段级证据契约均已接通。52 个驱动叶数值哈希保持不变;现状分为 cited 5、derived 8、conflicted 14、unresolved 26,approved_by 仍为空,因此“有引注”不会冒充“数值已批准”。M2/M3 继续等待逐概念判决,不批量合理化。
门廊与圆鼓不再靠“看起来接触”成立:D2.5 新增 join:portico_drum 子义务,D11 发射具名 SolidOp;union 必须在交付空间真实共体积,subtract 只扣点名 targets。入口 passage 从门廊贯穿鼓墙,冲突轴柱按拓扑退役。最终 B 路径为 12170 blocks · 五法 0 findings · 16/16 义务清偿。
门廊从“16根柱就算建成”升级为完整子装配:实心台基→柱列→三边楣梁→木屋盖→独立山花依次清偿;父义务只有在四项子义务全部完成后才由 portico_assembly 清偿。由此钉死“账清但拓扑未成”的历史假绿。
坐标从启发式猜测改为关系编译:落位求解器以唯一 primary、circulation entry、承托、毗邻、顶心与轴关系生成 semantic seed;SiteContext 的 front/left 交换会让圆鼓、门廊、柱列和入口留位整体旋转。局部只读父节点,非局部冲突继续交给全局门。
files ▾类型事实开始约束室内程序而非只塑造外轮廓:S7 权威事实纠偏为七礼拜堂之间穿插八龛庙;龛庙按圆鼓切向落座,藻井由 canon 的 5环×28经线写入穹承诺,台阶谱同步场地 approach、共同基座与通行义务。决策路径的语义家族覆盖由 2/8 推进到 8/8。
files ▾决策路径万神殿 v0:compose_mode 旋钮让 D11 composer 让位;盖谱席把 dome 纳入菜单;环律归位编译器负责结构环,但仍会拒绝稀疏环声明,因此铁律6保持不变。结果生成 32m hall 穹顶与 60 根环柱,10 项义务全部清偿,并通过坐标门的块级验收;视觉席随后发现闸E存在「天空被回答两次」的问题。
files ▾天空只答一次:逐一消除三个重复回答者——自适应屋顶对已经回答的 cover 让位(answered_covers);roof_truss 不再包裹接地壳;穹顶通过渲染方言桥,将 roof_form 元数据直接传给体素器。四视图均符合预期:穹顶显形、穹下无柱、剖面剪影成立;三门结果为 1143/0/16。
files ▾E2 落地:Ledger.entropy_trace() 直接从上账菜单计算 H(A_t|S_t)=Σlog₂|options|。熵预算因此从概念性主张变成可测指标,并可与 token-per-building 绘制在同一张图中。
理论确实改变了生成结果,并且可以导出对照:同一 prompt 在旋钮全关的 V2 路径中只生成 20 个构件、一个平顶盒和零结构件;开启义务模式后,结果变为 97 个构件 · 44 柱 · 22 梁 · 12 板,天花高度分为 5/7/10,16 项义务全部清偿。
files ▾Kevin 论点得到实证:「第一步就应该确定体块如何搭配、各自多高」。本地 qwen3:30b 给出 鼓高 16m = 内半径(依据 Pantheon),并通过效度门。由此确认昨日闸F的鼓座过矮并非体量算法错误,而是头部问句从未被提出。实验同时列出五个缺口:D2.5 问句、状态槽、SolidRegion 形状、commitment 义务与 RAD 注入点。
files ▾三模型 × 三类型 × 4 维基准:qwen3 是体块席主力,热身后约 5 秒完成一问,并能稳定给出鼓高 16m;deepseek 掌握相关知识,但承诺值会在 16 与 32 之间反复变化,因此只保留在批判席;glm 的词汇与依据均不稳定,退出承诺席。在巴西利卡层级题中,qwen 与 deepseek 都能判断「中厅必须高于侧廊」,说明模型进行了类型推理,而非简单背诵。
files ▾Claude 负责调度,本地模型分别执行子项:qwen 回答体块构成;glm 的回复被效度门拒收后,系统采用确定性结果,并把回退过程写入账本;deepseek 批判席准确指出柱列缺失与 oculus 4m 偏离史实 8.9m 两项问题。修复环只重答 oculus 这一问,用 11.7 秒将 4m 修订为 8.9m,构成 Selective Uncommit 的小型实例。实验形成三点结论:多个席位能够提供纵深防御;调度席的校验规则本身也要接受审查;采样漂移需要门与批判席双重保险。
files ▾先查资料建立标准答案,再让三个模型盲考:标准包含 43.3/21.65/8.9/11.9 四组数值、中介体块和五类拓扑关系。三个模型都遗漏中介块,形成 0/3 的明信片偏差:文本语料普遍缺少图纸层级知识,成为采用 RAD 的直接依据。glm 的数字达到 5/5,但连续三次违反 schema,因此退出承诺席、保留为知识源;qwen 则产生「86.6m 穹顶承托在 43.3m 鼓座上」的几何矛盾,因此跨体量一致性校验被列入待办。判卷器 v1 还出现评分偏低的问题,构成第三个「校验规则有误导致静默误判」的案例。
files ▾盲考、朴素 RAD 与结构化 RAD 的三方对照完成:把整段资料直接灌入 prompt 后,整体表现反而下降——例如「壁厚 6.4」被误造为 6.4m 高的板;即使引用来源完整,内容仍然崩坏,说明引用不等于理解。结构化 RAD 按「逐源掩码单问 → 带单位事实账本 → 律层推导 → 一致门」运行,三轮依次拒绝、拒绝、通过,并将 oculus 8.9m 与 30 罗马尺的换算结果互证合并。结论是:检索结果进入事实账本,不直接灌入 prompt;LLM 回答知识问句,结果性问题全部交给律层。这条边界正是白盒机制的核心原则。
files ▾视觉轮铁则(Kevin 指示):凡是产出或改变几何的轮次,收口前都必须完整检查四视图(iso+双剖+立面),不能只看轴测图与账本。万神殿 v0 虽然账本全部清偿,剖面却仍像矮棚;32ef7ae 试点也因此降格为「账对、楼错」。
files ▾为什么所有校验都通过了,内容仍然可能出错:存在三种机制——命题缺失,即现有规则尚未覆盖新现象;空间错位,即验证空间与交付空间不同;局部成立并不保证整体成立。因此新增三项待建校验:天空唯一性、全楼重叠与方言统一。
files ▾Kevin 判词:「原点只存在于实现层——柱子的位置只与台基大小有关,推算时只读取这一部分」。这把局部马尔可夫性从决策序列推广到空间:关系图是一张依赖 DAG,落位按拓扑序前向推算,每一步只读取父节点集合;重叠与越界等非局部约束不纳入父节点集合,而由全局门处理。由此得到三项推论:编译态越小,漂移面越小;父节点不变时子树保持不动,为 Selective Uncommit 提供理论依据;父节点越少,菜单越小,条件熵也越低。落位求解器已立项,坐标始终由确定性规则计算,不交给 LLM 回答。
files ▾The local R1 loop is closed. R2 is a production-ownership transfer, not a rewrite. A provider smoke test remains pending; without provider idempotency or a query protocol the claim stays at durable at-most-once dial authorization.
M1.4A proves a pre-detail tectonic condition, not blind-review eligibility of the final visible artifact. M2/M3 will not replace unresolved values with a new layer of hard-coded defaults.
Completed modules move here with date, commit, tests and evidence. Archive is a settled state, not a future phase, and is excluded from Planning percentages.
R1 本地闭环已经成立,下一阶段是 R2 生产交权。真实 provider 尚未 smoke;无幂等或查询协议时不承诺 exactly-once。每次退役仍须替代者、跨建筑证据与回滚参照齐备。
M1.4A 只证明构造/细节前的成立门,不等于最终工件已具盲评资格;M1.5 后续提交只有各卡定向证据,仍不回写 1651 的历史干净全量。M2、M3 不把未判数字换成另一批硬编码。
完成项的日期、commit、测试与证据真源统一见动态地图「Archive / ✅ 已清账」;Archive 是清账状态,不是下一阶段,也不参与 Planning 百分比。
small house (timber_trabeated) — 16 created, 16 discharged, 0 unresolved. The behaviour chain D05→D09 and structural chain cover→bear both close.
courthouse (trabeated_stone) — 11 created, 7 discharged, 4 unresolved. Stone post-and-lintel cannot span the 20 m hall; the refusal is recorded instead of hidden behind plausible geometry. Honest refusal is a feature.
This baseline excludes the uncommitted M1.5A intermediate state. It is evidence for a79b405, not a claim that every current working-tree change is green.
small house(timber_trabeated)— 创建 16 · 清偿 16 · 未清 0:行为义务(D05→D09)+ 结构义务(cover→bear)全链走通。
courthouse(trabeated_stone)— 创建 11 · 清偿 7 · 未清 4:石梁柱盖不了 20m 厅,拒绝被记录、债留账上——诚实拒绝是特性,不是缺陷。
最后一次不含 M1.5A 中间态的全量为 1651 passed / 47 skipped / 131 subtests;doctor 0 · selfcheck 16/16 + ruin。M1.3 与 M1.4A 默认路径、Pipeline.run 与 Gold 零变化;当前 dirty tree 不冒称全仓绿。
The machine can now prove that a revision refreshes only the affected domain; it still cannot prove that it knows what is better. P2.3A prevents an in-training 0.878 from masquerading as held-out evidence, honestly exposing blind=0. The next question is not how to tune another ranker number, but how to build an anonymous, cross-family, leakage-free blind-review set from artifacts that pass both final visibility and causal-consumer gates.
机器现在能证明一次修订只刷新受影响域,但仍不能证明它知道什么是“更好”。P2.3A 已阻止训练内 0.878 冒充 held-out 成绩,代价是诚实暴露 blind=0。下一步不应继续调 ranker 数字,而应回答:如何从 M1.4 最终可见且 M1.5 活消费者成立的方案中,建立与 catch/train 隔离、跨建筑家族无泄漏的匿名盲评集?
D_phys and rho · Kevin approves the R2 default flip · no credentials, no network calldeclared_but_inert。blind=0. The in-training 0.878 is not a held-out result. Failed catches and inert traces cannot enter taste Spearman or reinforcement learning.a79b405. Later M1.5/P2/R2/R3 cards have separate targeted evidence and must not be arithmetically merged into a fictitious full-suite total.The project models architectural composition as a decision trajectory p(τ)=p(a₀…a_T|s₀), with the building as its terminal artifact B=f(τ). Rather than sampling a finished image conditioned on C, ArchFlow constructs a state system that bounds combinatorics, records commitments and supports local revision. Architecture is not sampled into existence; it is committed into being.
Design contains latent intentions. A column exclusion may encode an unspoken sightline, ritual sequence or future façade. ArchFlow does not ask the model to guess these indefinitely; it progressively compiles them into explicit state.
ArchFlow does not claim that design is naturally Markovian. It makes the process operationally Markovian by compiling hidden intent into explicit premises such as parti, function_intent and tradition. Each decision must read those premises, so the next lawful action can be chosen from the current compiled state.
History, proposals and validation are compiled into a minimal sufficient state S_t=(G,C,L,O,U), including the obligation ledger 𝒪_t. Unlike a full chain-of-thought history, compiled state retains only information that can change future lawful actions.
The mask reduces the action menu to the lawful set A_valid; policy chooses only within it. The target is to keep H(A_t|S_t)≈log₂|A_valid| inside a useful interval, preventing both combinatorial explosion and a falsely deterministic process.
D⁺(X)={Y|X⤳Y} is the full downstream closure of decision X. Revision cost follows C_revision ∝ |D⁺(X)|: the cost of changing a decision depends on its causal reach, not on the total size of the finished artifact.
invalidate(D⁺(X)) re-answers a target inside a detached child run. Old/new semantic differences expand the affected closure; unrelated rounds are reused byte-for-byte, affected rounds are recomputed, the parent proof remains read-only and the child proof is resealed.
Retrieved material does not flow directly into token generation. It first becomes sourced, building-level facts, then compiles into commitments, relations and verifiable design deltas. LLMs handle questions, extraction and proposals within lawful menus; formulas and solvers retain ownership of arithmetic, coordinates, boolean operations and support consequences.
An obligation is forward debt: created → discharged. It may be created in one decision and discharged in another; unresolved items remain visible on the ledger. Discharge is checked as a multiset difference, analogous to a proof obligation.
The agenda is an explicit question list. Every decision carries a question; transcript() renders the derivation as a question/answer record. Repair means asking a question again, not painting over geometry.
Every decision uses the same internal form: observe → menu → mask → policy → apply → gate. The mask establishes legality, policy selects an option, and the gate records validity without inventing the answer.
A decision with a real MenuSpec is a true menu. Its policy seat can be deterministic, LLM or human; the answering identity is written to seat and posted to the ledger. Deterministic policy remains the default.
Every constant must first be classified as law or choice. Reusable vocabulary, masks and canon relations may become law; a judgement specific to one design must pass through a policy seat. Otherwise the system collapses into another parameterised recipe engine.
pytest, doctor and selfcheck (16 goldens plus the ruin gate) form the regression boundary. A change to default bytes must declare its effect on the goldens.
With all feature knobs off, output must remain byte-equivalent to V2 Pipeline.run. The frozen golden detects drift. Anti-cheating rules prohibit both result-side special cases and silent regeneration of the test oracle.
Adversarial building cases search for false negatives: validation passed, architecture wrong. Repairs must change law, mask, canon or obligation logic, never the generated artifact directly; the same case is then replayed for A/B evidence.
convert is the sole entry from the floating-point bbox world into discrete voxel delivery space. to_voxels() and conversion_findings() judge existence, bearing and related rules in the same space that is delivered.
When system capacity is insufficient, generation is refused and debt remains on the ledger. A stone post-and-lintel system that cannot span a 20 m hall must not hide the failure behind plausible geometry. Unresolved obligations never enter ValidationResult.
全项目的理论底座:建筑构成是一条决策轨迹 p(τ)=p(a₀…a_T|s₀),建筑只是这条轨迹的终点 B=f(τ)。与其只学习「在条件 C 下采样成品 B」,不如构造一个能够稳定推进、限制组合爆炸、记录承诺并支持局部修订的设计状态系统。「建筑不是被采样出来的,而是在连续承诺中成为现实。」 理论卷 §0
真实设计天然包含隐藏意图。例如,「这里不能放柱子」背后的原因可能是尚未表达的视线要求、仪式序列或未来立面构想,因此设计过程天然是部分可观测的。ArchFlow 的对策不是要求模型自行猜测,而是把这些意图逐步显式化,见「构造马尔可夫性」。 理论卷 §3.3
这不是发现设计过程天然符合马尔可夫性,而是主动把它构造成可操作的马尔可夫过程:将隐藏意图编译为显式状态变量,包括前提 premises:parti / function_intent / tradition;铁律11要求每个决策都必须读取这些前提,从而让「只看当前状态就能走下一步」成为工程事实。 premises.py · 理论卷 §3
将历史、提案与验证结果编译成最小充分状态 S_t=(G,C,L,O,U),并纳入义务账本 𝒪_t。完整思考历史容易重新激活噪声与过期假设,编译态则只保留会影响未来合法动作的信息。代码中的对应实体是黑板,包含槽位读写集与前提。 blackboard/ · 谱系:Hayes-Roth 1985 · Hearsay-II
将每一步的条件熵 H(A_t|S_t)≈log₂|A_valid| 控制在预算区间 [H_min,H_max] 内:掩码先把菜单缩到合法集 A_valid,策略再从合法项中选择。代码中的对应实体是 MenuSpec;目前已有三个真菜单接入流程。 policy.py · 谱系:SPRING(AIJ 2024) · shielded RL
决策 X 的全部下游 D⁺(X)={Y|X⤳Y};修订成本 C_revision ∝ |D⁺(X)|——改一个决策的代价由依赖闭包决定,不由结果规模决定(repair locality 的测量面)。代码 = 读写集 + downstream_of()。 谱系:TMS(Doyle 1979) · de Kleer 1986
invalidate(D⁺(X)) → 在 detached child 中重答目标并按 old/new 语义写差扩张依赖闭包;无关轮字节复用,受影响轮显式刷新,父 proof 只读,child proof 重签。R1.8B2 已将 source/base/child checkpoint、lineage 与最终 seal 归档为可 fail-closed reload 的逐楼 child run;生产默认接线仍归 R2。 selective_repair.py · repair_archive.py · 理论卷 §5–6
这里使用 RAD 而非普通 RAG:检索结果不是只用于生成 token,而是先成为带来源的逐楼事实,再编译为承诺、关系与可验证设计增量。LLM 负责问句、抽取与合法菜单内提议;精确算术、坐标、布尔和承托后果仍由公式、求解器与闸口决定。R1.7 已提供默认关闭的有界外部席,R1.8B 使受影响推导可修复并封印。 理论_RAD与建筑状态编译 · external_seat.py · selective_repair.py
义务是一种前向债:created → discharged,未清部分以 debt 留账。义务可以跨决策创建与清偿,例如 D05 创建隐私义务,D09 通过楼板检查清偿;cover→bear 则形成级联召唤。清偿按多重集差逐项对账,对应形式方法中的 proof obligation。 ledger · ⊕=比理论卷多出的增补件
议程就是问题清单:每个决策都带有 question 字段,transcript() 将推导渲染成「问/答」笔录;repair 表示重新询问一个问题,而不是直接重画一块几何。 decision/ · blackboard/
每个决策单元都采用同一内部结构:observe 观察 → menu 菜单 → mask 掩码 → policy 策略 → apply 应用 → gate 门。掩码先把菜单缩到合法集,策略只回答「选哪个」,门只记录、不裁决。 decision/ · 地图 §P0.1
拥有真实选择集(MenuSpec)的决策称为真菜单。策略席可以在确定性 / LLM / 人之间插拔;谁作答,就把相应身份写入 seat 字段并上账。当前三个席位分别是 D05 行为、D07 传统与 D10 结构;确定性策略仍为默认值,因此字节锚保持不变。 policy.py · v2_stages.py
面对一个常量,先判断它属于法还是选择:法,例如词汇、掩码和 canon 比例锁,可以写死;选择,即针对单个设计的判断,必须经过策略席,否则系统会退化为另一个参数化 CityEngine。进一步说,可复用的内容可以进入 pack,而具体配方必须经过推导流。 铁律15候选(判决 2026-07-16)
pytest · doctor · selfcheck(16 金样+废墟门)共同组成三门。任何提交都必须三门全绿;如果修复会改变默认路径的字节结果,必须明确说明它对金样的影响。 CLAUDE.md 工作协议
旋钮全关时,结果必须与 V2 Pipeline.run 字节等价,参照系本体保持不动。金样是冻结的基准产物,任何字节漂移都会触发报警。双向防作弊同时禁止「凑金样」——在结果侧加入特判,以及「自改考卷」——悄悄重生成金样;金样换代必须由 Kevin 拍板。 CLAUDE.md · selfcheck
主动构造对抗性建筑案例,寻找「验证通过,但建筑错误」的假阴性;幽灵柱就是「账对、图不对」的判例。第一原理是修法不修果:修复必须落在律法、掩码、canon 或义务链上,而不是直接修改生成结果;随后用同一案例进行 A/B 重跑取证。 CLAUDE.md 鹈鹕协议(判决 2026-07-16)
convert 唯一通道是浮点 bbox 世界进入离散体素交付空间的统一转换入口,由 to_voxels() 与 conversion_findings() 组成。existence / bearing 两条规则都在交付空间执行校验,使承托判定从 bbox 层升级到体素层,也让「离散可判定」这一主张在系统内部得到兑现。 archflow/convert/ · 铁律16候选
当系统能力不足时,它会拒绝生成并把债留在账上。例如,法院的石梁柱体系无法覆盖 20m 大厅,因此留下 4 项债务,而不是用表面漂亮的几何强行遮盖问题;未清义务绝不进入 ValidationResult。拒绝是特性,不是缺陷,失败分类学也由此建立。 ledger · 地图 §1.4