Q-124 asked whether the 123-file Python tooling should be retooled into a
Rust CLI. The answer is no, and it is a costing rather than a preference.
All three frictions it names — per-script permission prompts, the venv/PATH
split between interactive and non-interactive shells, and interpreter
startup paid four times per push — are packaging problems, and one bare
command on PATH with lazy subcommand loading fixes all three. Rust would
additionally owe a numerical-equivalence proof on the planet-gen path,
whose heightmaps are committed build artefacts with goldens standing on
them: a large one-time cost to avoid a small recurring one, paid in the
currency the project can least afford to spend.
D-263 fixes the shape. tooling/ becomes an installable package behind the
`reach` command: a routing-only main.py, every domain under domains/<name>/
split router/service/schemas/helpers, a core/ bounded on day one to what
has no domain, logging and error handling attached as decorators rather
than call-site discipline, and pydantic confined to domain schemas —
measured at 87 ms against a whole gate check of 20-46 ms, which is why it
must never reach the push path. Failures carry the command that fixes them
and keep their exit code; a tool that explains itself and exits 0 silently
disables its own gate.
R-014 records the Rust option as costed down, not argued down, with the
condition under which it is worth reopening. T-1247 files the work as
eight dependency-ordered epics; only the skeleton is unblocked.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Jeroen's shape for the tooling CLI: move the Python into a package with a
proper domain split, one door that answers everything with help, and errors
that hand back instructions rather than a status.
The domain split turns out to be discoverable rather than invented. tooling/ is
85 top-level entries — 37 loose .py, ~36 extensionless executables, 11 dirs of
which only 6 hold anything — across four coexisting naming conventions. But the
domains are already encoded as filename prefixes: blender x14, atlas x8,
generate x7, check x7, then visual/validate/test x3 and
godot/garment/pql/install x2. Those prefixes are the subcommand groups, which
is what makes the consolidation mechanical enough to be safe.
Two constraints recorded against "a new prompt not an error code", because
taken literally each would break something:
- Exit codes stay. Four of these run in the pre-push hook, which fails a push
ONLY by non-zero exit; a tool that explains itself and exits 0 silently
disables its own gate. That exact failure was observed in clide today, where
unsupported-format, no-such-file and unknown-subsystem all returned 0.
So: code AND message, never either/or.
- It must not become literally interactive. Agents and git hooks have no TTY,
and the tea scar is already written down — its prompts "crash in Claude Code
(no TTY)", which is why every tea call passes all flags explicitly. Any
prompt must be TTY-gated and suppressible.
pql was cited as the precedent and measured rather than assumed. The principle
holds there for unknown subcommands (full usage dump) and not for invalid
values: `ticket status <id> nonsense` says invalid without naming the six legal
values it knows, `ticket new` says "accepts 2 arg(s)" without naming which two.
The gap is the closed sets, and it is the more common failure. Logged upstream
as pql T-112 rather than worked around here — the bar for our CLI is the
stronger one: whenever the accepted set is known, print it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Jeroen raised Typer as the Python-CLI option. Costing it changed what the
question is actually about.
The repo is already most of the way there: pyproject.toml exists, `make
setup-venv` already does `pip install -e ".[dev]"`, and 22 tooling files
already use argparse. What is missing is a single line — there is no
[project.scripts] entry at all, so no console entrypoint exists. This is
consolidation, not authorship, and it resolves the largest friction (per-script
permission prompts) for one allowlist entry.
But the framework is the second decision, not the first. A [project.scripts]
entrypoint lands in .venv/bin/, which is on PATH only when the venv is
activated — and agents and git hooks never activate it. That is the same split
VENV_PY already papers over in the Makefile, and precisely the failure recorded
for tea: an absolute path breaks the Bash(tea *) rule and prompts every time,
fixed only by a bare name on PATH. So the deliverable is "one bare command
reliably on PATH" (uv tool / pipx into ~/.local/bin, or a symlink), and a Typer
app behind an absolute venv path would solve nothing.
Two honest costs recorded against it: Typer and Click are further venv
dependencies, so it does not help the venv friction at all; and a single
entrypoint importing every subcommand eagerly would pay all 123 modules'
import cost on every invocation, four times per push. Lazy subcommand
registration is therefore mandatory rather than an optimisation, and must be
measured before and after.
Net: this looks like the answer for the check/gate family and the day-to-day
scripts, and it leaves the numpy/scipy/PIL planet-gen path alone — the part a
Rust port would have had to prove numerical equivalence for. T-1246 updated to
start here.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The relationship between wiki/, the generators, systems.db and the runtime is
a directed graph with two edges running opposite to the obvious direction and
one running backwards into its own producer. Prose renders that badly: every
document that has described it states a single ownership direction and is
therefore wrong about part of the tree. D-262 makes the diagram the source of
truth and points CLAUDE.md, Skill(wiki), project-structure.md and
wiki/GOVERNANCE.md at it.
The correction that matters most: body pages were described everywhere as
machine-owned and reverted on sync. They are not. scaffold_bodies.py writes
one once and never overwrites it, and import_economics then reads that
frontmatter directly as input — so a hand-edit is not reverted, it is obeyed,
and silently changes world generation. Worse than being overwritten, and the
actual reason GOVERNANCE.md forbids the edit.
New: tooling/check-dataflow-graph.py, wired into the Makefile and the pre-push
hook. It asserts every repo path named in a hand-authored diagram still
resolves — and its docstring states plainly what it cannot do: verify that an
edge still MEANS what it says. If wiki_sync.py stopped writing body pages
tomorrow, every path would still exist and the check would still pass. Edge
semantics stay a human check against the tool's source, so nobody reads a green
gate as a verified map.
Verified by breaking it: pointing one label at a moved path fails with exit 1
naming that path; restoring it passes. Building the checker also caught two
real vaguenesses in the diagram — "GJ-*/index.md" and "bodies/{id}/index.md"
were written without their wiki/star-systems/ prefix, which is precisely the
ambiguity this map exists to remove. Generated star-map .d2 files are excluded
by name; their correctness belongs to their generator under D-223.
Also files Q-124 + T-1246 (tooling): whether the 123 Python files under
tooling/ should become one Rust CLI of pql's calibre. The friction is real and
mostly not about the language — the permission gate prefix-matches whole
command strings and a blanket Bash(python3 *) grant is forbidden, so each tool
prompts near-individually, while a single binary is one allowlist entry. The
record requires pricing the cheap alternative (a Python dispatcher entrypoint)
before recommending Rust, and flags the hard constraint: import_economics is
stamped by source SHA, so any port must keep that contract intact through the
transition rather than disabled during it.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Jeroen's gap catch: T-750 never stated that the seed-to-tile cascade is
also what determines the world where the player walks. Now connected in
one statement across three homes: D-012 amendment (the founding 'chunks
load/unload around the player' driver now concretely = the D-227/D-239
cascade; 3x3 chunk neighborhood minimum, coarser context self-provided by
D-255(f) function composition, Atlas interaction never a precondition,
byte-identical either way), the matching T-750 deliverable note (in
changelog), and a one-truth consumer note on Q-093 for the Phase-5 insert
minimap (design deferred, no independent map pipeline expected).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
D-248 (architecture): per-leg constant-velocity interpolation keyed to the
stance throttle; cadence-synced gaits; one smoothing layer per channel;
annotates D-054 (its 100-150ms tween scoped to the 2D renderer).
D-249 (architecture): 'server feet, client eyes' facing split with the
verified octant-to-yaw table and the set_facing() trap note.
D-250 (perception): wall cutaway is client camera presentation, decoupled
from fog-of-perception; fog-memory-for-geometry nuance parked for Phase 5.
D-251 (content): Quaternius rig reconfirmed after full 2026 re-evaluation;
Synty intake technically proven then product-rejected; in-house wardrobe
routes; UAL paid tiers close the animation gap; revisit tripwires recorded.
Annotations: D-148 editorial note (preset list authoritative; stepped camera
yaw needs a record), Q-020/Q-063/Q-079/Q-084 updates.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The push gate's integration tests (not in cargo test --lib) caught two regressions
from the relief change:
- derivation_harness::cross_district_elevation_blend_reduces_seam_step — the relief's
large per-position term (span 300 → ±200 m, far above the compressed elev_q/2 base)
swamped the T-1042 seam measurement and clamped heavily at sea level. Fixes:
(1) shift the voxel-relief octave band to 0.13–1 km (all sub-district, dropping the
2 km octave that competed with elev_q's district role); (2) reduce VOXEL_RELIEF_SPAN_M
300 → 100 so relief stays mostly below the base (fewer sea-level clamp artifacts,
proportional hills); (3) rewrite the seam test's avg_elev to average over an 8 km
multi-wavelength y-transect so the zero-mean relief cancels, isolating the base seam.
- derivation_harness::golden_seed_determinism_regression — legitimate golden refresh
(determinism still holds; elevation values changed intentionally).
Believability relief now ≈22 m mean (was 5 m flat; 59 m at the over-aggressive span 300)
— navigable hills without clamp artifacts, 7/8 criteria. Both goldens regenerated; full
cargo test (38 binaries) + clippy --all-targets -D warnings green. D-239 amendment +
Q-123 item 4 updated to the final span/octave/numbers.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
T-1081 review (Hoshe + Tyre): the seed_domain_discriminants_are_pinned test (the
D-224 guard that fails CI if a variant is renumbered — which would silently re-roll
every world's relief field) did not pin the new VoxelRelief = 11. Add the assertion.
Also fold Tyre's two Q-123 calibration notes into item 4: (i) sanity-check the
slope_q*3 + elev_q envelope on a synthetic high-slope body (both terms cap at 100);
(ii) the relief transect is a single diagonal slice (fine for isotropic fBm, revisit
if an anisotropic ridge field is added).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The voxel tier read flat (the D-245 "0–3 m, no hills to navigate by" bug):
family generators set elevation from elev_q at a compressed scale plus only ±4 m
micro-scatter, and detail-scatter's mid-scale relief (D-243 §2) only ever reached
the district tier (elev_q), never per-voxel elevation_m.
- detail_scatter.rs: extract the enveloped-fBm core; add `voxel_relief` at the
0.25–2 km octave band (vs the district 4–40 km band).
- voxel.rs: add the mid-scale relief post-dispatch in derive_voxel_column, body-global
SeedDomain::VoxelRelief seed (position-keyed), f64 truncated to integer metres (D-010).
Envelope = slope_q*3 + elev_q — the coarse heightmap gives slope_q ≈ 0 even on high
ground (Arbour max 13), so elevation must drive ruggedness. Flat families only
(Alluvial/Lava/BraidedDelta/Dune/Meander); the dramatic families already carry strong
internal relief and WaterBody stays at sea level.
- seed.rs: SeedDomain::VoxelRelief (D-224 domain separation).
- believability.rs: new `contrast.voxel_relief_m` metric — mean within-district elevation
range over a 2 km transect (a single 64 m sample chunk is narrower than the relief
band) + a "voxel relief" criterion.
Arbour @ yolo: voxel relief 5 m → 59 m, 6/8 → 7/8 criteria (remaining fail = the
Q-123 vegetation-denominator item). Edict 59 m. Golden regenerated; 1586 lib tests +
believability harness (determinism) pass; clippy -D warnings clean.
D-239 amended (T-1081); Q-123 item 4 updated. Deferred to Q-123/follow-up: the
provisional span + threshold, and a per-body hypsometric absolute-elevation model.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Stack review (Hoshe + Tyre) of T-1083+T-1082+T-1080. Every finding fixed or disposed:
- believability.rs sample_indices: replace the rejection-sampling loop (could stall
when n ≈ take) with deterministic partial Fisher-Yates — O(n), guaranteed
termination, distinct, sorted (Hoshe+Tyre).
- believability.rs drainage proxy: exclude water-body districts (all elev 0, no banks)
and require both wet + dry voxels — they were passing vacuously and inflating the
metric (Hoshe).
- believability.rs read_cities: log skipped malformed rows instead of dropping silently
(Hoshe).
- voxel.rs: add the 3 WaterBody zones to all_families_no_panic_at_extreme_positions +
fix the "7 families" comment (Hoshe).
- climate_constants.toml: bold warning that [moisture_gradient] is not loaded until
T-1032 — tune ClimateConstants::default() (Tyre).
- Q-123: record the per-zone "water renders wet" threshold + the land-relative
vegetation-present denominator as calibration items (Tyre + the open 7th criterion).
- T-1083 ticket: note the sampling-fix attribution (landed in the T-1082 commit).
Believability golden regenerated (sampler + drainage fixes moved the metrics).
clippy --all-targets -D warnings clean; 1580 lib tests + harness pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Lock the cascade's nature-half deliverable to "reads alive anywhere", not
"implemented" — the holy-grail objective surfaced by probing the generation
cascade.
- D-245 (architecture): the nature layers are accepted only when the
believability litmus passes at randomly-sampled locations across all
habitable bodies/seeds — multi-scale + never-repeating (macro identity,
meso non-stationarity, micro mosaic), coherence + non-stationarity +
intra-class variety + relief + climate-appropriateness, automated screen
under a human sign-off, budgeted -> strict. Q-123: threshold calibration.
- T-1079 (epic, north-star, DoD=D-245) + findings T-1080 (uniform climate
fields), T-1081 (near-zero relief), T-1082 (no water-body generator),
T-1084 (intra-class micro-habitat mosaic), and T-1083 (the repeatable
believability test protocol / D-245 enforcer).
- aliveness_probe bin: the exploratory probe that found these (runs the
deterministic cascade for a body+seed, reports per-district nature +
verdict). Seed for T-1083.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Resolves Q-110 (region/chunk physical-scale anchoring), which had three
contradictory metres-per-scale assumptions in the cascade and no record
fixing metres-per-heightmap-pixel.
D-243 establishes a nested absolute-metre containment ladder with a single
elastic seam at planetary scale:
voxel 1m -> chunk 64m -> block 128m -> quarter 512m -> district 2km
-> region ~205km (100x100 districts) -> (elastic) -> planet
A body holds round(2*pi*R/204.8km) regions (the only per-body-floating
quantity); everything below is fixed integer math, so ChunkPos->RegionPos
is body-independent. The region is the largest hard block: the climate/
weather/season lockdown scale (the Q-105 cheap-dynamism source) and the
sane planetary grid. Sub-heightmap detail is invented deterministically
(interpolation + domain warp + detail-scatter, never stored, D-227); climate
is edge-fuzzed so the grid never shows ('climate does not change on a line').
Vocabulary locked and recorded in CLAUDE.md: 'region' = the 205km metric
cell only; the old 1km RegionProfile is dropped onto the 2km district; D-201
tier-4 'Region' renamed Province (the watershed/political overlay), amended
here. Refines D-239 §2 (district temperature now modulates a region baseline).
Implementation tickets: T-1077 (re-scale the code to the ladder + elastic-seam
resampling; blocks T-1046) and T-1078 (region climate stack + edge fuzz).
T-1046 is un-gated on Q-110 and now blocked only by T-1077.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Adopts the T-NNN convention (T-N == old #N == pql ticket id) across the active
operational layer: governance/ decision records, .claude/{rules,agents,skills},
CLAUDE.md, DECISIONS.md. 283 references rewritten.
Guarded against false positives (17 correctly skipped, each logged):
- PR references kept (PR #136/#138/... — PRs are a separate #-namespace)
- non-ticket numbers kept (#4122; the "#1 process failure" idiom; "task #3")
- only #N where N is an actual ticket id is rewritten; the 1-4 digit word-bounded
match also excludes 6-digit hex colours in the visual decision records
Git history is NOT rewritten (a commit's #N already equals T-N numerically), and
historical archives (docs/sprints, docs/discussions, docs/workshops) keep their
point-in-time #N. The /pr-process ticket-ID extraction logic moves to T-NNN in the
Phase 4 consumer cutover.
Verified: pql decisions validate ok; sync 357 records / 1057 refs / broken 0 (the
prose edits don't affect decision parsing or the tickets.decision_ref linkage).
Transform committed at tooling/pql-migrate/retag_ticket_refs.py.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Phase 1 of the pql migration. Moves the flat decisions/*.md layout into
governance/{decisions,questions,rejected}/<domain>.md — the tree pql's
`decisions sync` parses natively (record type from subdir, domain from
filename stem). Proven against pql 1.6.2: sync reports 357 records
(237 D / 108 Q / 12 R), 1057 refs, broken: 0; validate ok.
- 6 D-domain files -> governance/decisions/ (git renames)
- 5 questions-<domain>.md -> governance/questions/<domain>.md (prefix dropped)
- rejected.md split by domain -> governance/rejected/{architecture(R-001..010),
economics(R-011),perception(R-012)}.md
- decisions/README.md + questions.md index folded into governance/README.md;
pql's `decisions sync` now auto-maintains the record index appended below
the hand-written domain guidance (no more manual ID-list table upkeep).
- .pql/config.yaml: canonical vault config (tracked, not ignored).
Link rewrites are token-preserving: only the relative `foo.md` path portion
changes (e.g. `rejected.md#r-011` -> `../rejected/economics.md#r-011`); every
`[D-NNN]` bracket text and `#anchor` stays byte-identical, so pql's reference
extraction is unaffected. The one-shot transform is committed at
tooling/pql-migrate/restructure_decisions.py for provenance.
Codebase path references to decisions/ (CLAUDE.md, rules, skills, docs) are
updated in a follow-up commit.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>