GRILL stage for v0.7. ci-griller red-teamed the plan across 9 axes + 7
specific probes. Overall verdict: CONDITIONAL PASS (confidence 0.72).
5 binding decisions applied to PLANS.md + ARCHITECTURE.md + oy-state + PROJECT.md:
- D-086: P1 Factory functional for Phase-2 categories ONLY (FactoryAllowedPhases
= [Phase2] in P1; P2 extends to [Phase2,Phase3,Phase4]); P1 simtest adds
out-of-phase rejection negative case
- D-087: PierCarriesVoice=false added as 12th locked const (was 11; now 12)
in x/guild/types (FR-VOICE-6 mission-locked invariant)
- D-088: lexicon_meta_cover uses new lexicon.CoverBannedTerms() helper
(insurance/premium/claim/policy scoped to Cover surface, NOT project-wide);
x/cover/firewall pinned to allow-list of routing destinations (string-
equality check); optional x/pact insurance-like -> Cover-like doc-fix
- D-089: StillKeeper satisfied by simtest-local stub (x/still NOT extended
this milestone; x/still/keeper/ verified empty); x/bond -> x/cover
CoverKeeper reverse edge added to dependency map (MsgDebitMABProceeds
queries CoverKeeper.GetPoolReserveAccount; no import cycle, interface only)
- D-090: Bill of Rights temporal-gap fix (RightID + 13 Waivable* consts +
RightIsWaivable() + ValidateBasic gate land in P2, NOT P5 — closes the
P2->P5 window where rights were waivable); Voucher cold-start fix
(bond = max(10x avg, MinimumVoucherBond) — no zero-bond bypass); Standing-
gate dual check (floor enforced at BOTH launch handler AND Params-amendment
ValidateBasic); D-085 escalation window tightened to before P2
3 escalations to PO: D-085 (13th right identity, confidence 0.55),
lexicon banned-term scope (griller recommends Cover-scoped helper),
pen-test third party (this grill IS the self-administered review per
oy-state §7 item 4).
This grill IS the self-administered adversarial review (pen-test) per
oy-state §7 remaining-open item 4. High/critical findings (D-090(1)
temporal gap, D-088 lexicon paper tiger, D-090(2) Voucher cold-start)
are remediated in P0 via binding decisions D-086..D-090.
---ci---
project: oy
phase: 0
milestone: v0.7
status: grill
---/ci---
Ingest oy-spec v3 (net-new-only diff against spec-v2):
- 52 new REQs REQ-046..REQ-097 (v0.7 REQ-046..066, v0.8+ REQ-067..097)
- §5: 4 new constraints (no subsidies, Anchor no-Voice, Sovereign Anchors
separate SPEC, Pier-Routed Legal Wrapper OPTIONAL)
- §7: v0.7 Fraternal Groups Foundation + v0.8 Risk Mitigations plan
- §8: 8 open questions with PO recommendations
- Trimmed restated baseline/Principles/Lexicon/invariants (locked, in force)
Per PO ruling 2026-08-18. ciagent acknowledges; P0 will regenerate oy-state v2.
OY-specific template the PO copies to .ciagent/oy/oy-spec (no .md) when
starting a fresh milestone cycle. Pre-fills the locked baseline that does not
change between milestones (Six Principles §3, Constraints §5, Lexicon §6,
REQ-001..REQ-021 locked-vision rows in §4, Rules + Commit convention blocks).
Clears the per-milestone content the PO must fill (§1 Objective, §2 Vision
source locked-sections, §4 acceptance criteria, §4 new REQ-022+ rows, §7
Milestone intent, §8 Open questions, §9 Changelog).
Each placeholder is a <!-- TODO --> comment so the PO can grep for unfilled
slots. The header comment block explains what is pre-filled vs what the PO
fills, and points to oy-state §2 for the current max REQ-ID before adding new
rows.
Lives at .ciagent/oy/oy-spec-template.md (.md extension because it is a
reference file the PO reads in an editor, not ingested by the ciagent — the
working oy-spec / oy-state keep the bare-stem convention for ingestion).
---ci---
phase: 0
milestone: v0.6
status: execute
project: oy
---/ci---
Establishes the two-doc contract between the product owner and the ciagent:
- oy-spec (PO-authored, ciagent ingests): authoritative product input
- oy-state (ciagent-authored, PO ingests): current shipped state
Both live in .ciagent/oy/ with no .md extension (PO ingestion keys on the
bare stem oy-spec / oy-state). The 10 existing .ciagent/oy/*.md files remain
ciagent-internal working memory. PROJECT/REQUIREMENTS/ARCHITECTURE gain a
one-line header note pointing to oy-spec as the source and oy-state as the
shipped-state mirror.
oy-spec holds the schema the PO fills (Objective, Vision source, Principles
[locked], Requirements table with acceptance criteria, Constraints, Lexicon
[locked], Milestone intent, Open questions, Changelog) + the mandatory
docs(spec): Conventional Commit convention for spec edits.
oy-state is backfilled from shipped v0.6 state: 45-REQ coverage table, 24
locked constants, 18 deferred items, firewall status (G-003 GREEN, G-006
controlled exception cosmos-sdk v0.50.8, REQ-012 GREEN x3, Mission Lock
GREEN, coverage >=80% GREEN), and 5 open PO decisions for v0.7 scoping.
Closes the loop: PO reads oy-state -> edits oy-spec (docs(spec): commit) ->
ciagent regenerates PROJECT/REQUIREMENTS/ARCHITECTURE at next P0 -> flags
drift in oy-state §5. Prevents re-proposing shipped or explicitly-deferred
REQs.
---ci---
phase: 0
milestone: v0.6
status: execute
project: oy
---/ci---
---ci---
phase: 0
milestone: v0.6
status: research
decisions:
- id: D-074
decision: HTMX 2.0.10 vendored as web/static/htmx.min.js (single JS file, no build step, no go get — G-006 preserved)
rationale: htmx.org docs confirm dependency-free single-file install; 2.0.10 is current stable (v4 in beta, Summer 26 target)
confidence: 0.95
alternatives: [htmx 1.x (IE support, unnecessary), pin a newer beta (instability risk)]
- id: D-075
decision: lexicon_meta_web_test.go scans web/**/*.{html,js,go} as a new sibling firewall (package lexicon_meta_web, subdir lexicon_meta_web/)
rationale: web/ is a new top-level dir NOT under x/ — the existing lexicon_meta_test.go (x/**/*.go) does not cover it; mirror the lexicon_meta_docs/ subdir pattern with G-013 walk-coverage + G-009 self-test + G-014 shared SyntheticBannedStrings()
confidence: 0.85
alternatives: [extend lexicon_meta_test.go to also walk web/ (mixes x/ and web/ concerns), separate .go and .html/.js tests (more files)]
- id: D-076
decision: Go 1.22 net/http.ServeMux is the sole router for web/ (method+path patterns, r.PathValue); gorilla/mux NOT used by web/ despite being a transitive cosmos-sdk dep
rationale: go.mod:3 confirms go 1.22; enhanced ServeMux covers GET/POST + path params for all 5 screens; G-006 zero-dep preserved (no third-party router)
confidence: 0.95
alternatives: [gorilla/mux (breaks G-006 for web/, unnecessary), chi/router (new dep)]
- id: D-077
decision: frontend-engineer activated for v0.6 with territory web/** (templates, static, handlers, store, main.go, lexicon_meta_web_test.go); backend-engineer co-owns the mock store x/*/types integration
rationale: first UI milestone — frontend-engineer was deactivated since v0.3 (no UI work); Go html/template + HTMX stack (no node/React) aligns with frameworks; constraints bind G-006 (vendored HTMX), G-003 (app-layer type import), REQ-012 (lexicon), D-073 (bread-scale code constants)
confidence: 0.90
alternatives: [keep frontend-engineer deactivated and have backend-engineer own templates (wrong skill fit), activate docs-writer instead (no docs-content work in v0.6)]
---ci---
v0.6 §1: Go html/template + HTMX architecture — server layout (web/main.go,
handlers/, store/, templates/, static/), base template pattern, HTMX 2.0.10
vendoring (single JS file, no build step, G-006 preserved), progressive
enhancement via HX-Request header (fragment vs full-page dispatch), html/template
contextual auto-escaping (XSS prevention).
v0.6 §2: Mock server data model — exact struct shapes verified from source for
all 6 modules (identity Reach, stash Stash+StashActivity+IsMature, window
Window+Scope+RateLimit+Activate/Revoke/Expire, standing Rating/Vouch/Slash/
FreeholderSignals+helpers, bread GrainsPerBread=10000+BreadScaleAll 11 tiers,
bloom BloomRecord+TargetBloomRateBasisPoints=450). Import paths use module
github.com/oy/openyield. Bread-scale code constants are the source of truth
(D-073) — docs/shared/bread-scale.md is outdated (claims 1000x ratios; code
uses 100x).
v0.6 §3: Lexicon firewall extension — pattern to mirror from
lexicon_meta_test.go (x/**/*.go) and lexicon_meta_docs/ (docs/**/*.md); new
lexicon_meta_web/ subdir + package lexicon_meta_web scanning
web/**/*.{html,js,go}; 10 banned terms verified from lexicon.go:30-41 (bank,
deposit, interest, yield, currency, dollar, euro, account, savings, depositor);
G-013 walk-coverage + G-009 self-test + G-014 shared helper.
v0.6 §4: HTTP routing — Go 1.22 net/http.ServeMux method+path patterns
confirmed (go.mod:3); r.PathValue() for path params; gorilla/mux (go.mod:75
transitive) NOT used by web/ per G-006.
v0.6 §5: PERSONAS.md update — frontend-engineer activation (YAML frontmatter
format documented); territory web/**, frameworks Go 1.22+html/template+HTMX+
ServeMux (NO node/React), constraints G-006/G-003/REQ-012/D-073; backend-engineer
co-owns mock store type integration; security/cosmos/mesh/data-engineers
deactivate for v0.6 (UI-only, no runtime).
v0.6 §6: ARCHITECTURE.md update — proposed section outline appended after
line 514 (v0.5 section end); 7 subsections mirroring v0.5 density.
User-validated stack: Go html/template + HTMX, Go mock API server,
new web/ dir, all 5 screens. Lexicon firewall extended to web/.
Bread-scale source of truth = x/bread/types code constants.
---ci---
project: oy
phase: 0
milestone: v0.6
status: clarify
---/ci---
Audit (ci-audit workflow) found PROJECT.md line 64 said 'v0.5 — Bearers
Runtime (in progress...)' but the milestone is COMPLETE (ROADMAP.md
COMPLETE, checkpoint milestone_complete=true, release v0.4.8 shipped).
Fixed to 'complete' to match reconstruction state.
---ci---
project: oy
phase: 8
milestone: v0.5
status: audit
requirements:
covered: []
partial: []
---/ci---
Add ARCHITECTURE.md §"Council Voice/Council Interface — Lifecycle Type
Divergence Decisions (v0.4)": documents P1-1 (Proposal/VoteOption absent,
deferred to v0.5+ governance runtime — feat: rejected by D-001), P1-2
(SignalKind 4-vs-5: the 4-source shape is intentional per AUDIT rationale;
Freeholder is eligibility, Guild is council tier, Capital is committed-
capital per vision §9.1), P2 (bearers ValidateGenesis no-op correct per spec).
test(council): TestSignalKindShapeIntentional regression guard (REQ-031)
Add intent-assertion test locking the 4-source SignalKind shape with the
AUDIT §193 P1-2 rationale in the doc comment. A future agent changing
SignalKindCount 4→5 must update this test, surfacing the rationale. No
locked-const change, no production .go files modified (D-050).
Verification: go test ./... green; only types_test.go modified in x/**.
---ci---
project: oy
phase: 2
milestone: v0.4
status: execute
tag_base: v0.3.x
milestone_type: nfr
reqs: [REQ-031]
---/ci---
---ci---
project: oy
phase: 5
milestone: v0.2
status: complete
phase_role: final
milestone_complete: true
---/ci---
Checkpoint: v0.2 milestone complete. Merged to main, tagged v0.1.5 (milestone release,
release id 732 on Gitea). All milestone branches deleted. Per run.md, checkpoint cleared
for next run (v0.3 The Bearers per ROADMAP Phase 3).