Viewer AI implementation ledger¶
The full program remains the completion contract. Every package, including P15A and U01–U04, is in scope. A partial implementation below does not close its package. Validated layers are merged under the user’s authorization, including admin merges when the queue is unreliable. Closing an implementation issue does not establish full-program acceptance.
Delivery-stage evidence¶
The rows below describe evidence and limits when each layer was delivered. Later layers may supersede their implementation gaps; the package register below tracks current completion work.
| PR | Layer | Evidence and limits |
|---|---|---|
| #6811 | Provider-independent output budgets | API and transport refusal tests; existing defaults retained. Full root usage accounting remains open. |
| #6818 | Stack CI and branch-pattern diagnostics | 57 workflow/classification regressions. No review gate disabled. |
| #6816 | Full architecture/UI charter | Bounded Astra architecture review incorporated. No implementation acceptance implied. |
| #6819 | Contextual analysis assistant | Real ArchiCAD IDS oracle; bounded frozen evidence; cancellation/staleness; mounted source actions. The real-model discussion test passed in CI run 37197674333 on dcddfa61e; screenshot inspected. Hosted software-WebGPU loss limits that artifact to data/assistant evidence, not 3D correctness. Completion-visible captures are being hardened. |
| #6821 | Durable completed conversations | Actual IndexedDB reload, CAS conflicts, refused writes, backup/import and mounted Save/Open. Archived evidence does not become current. |
| #6828 | Reviewed native Flow graph patches | Native registry validation; approval-gated apply/undo; standard-registry math execution oracle; no automatic graph execution. Receipts are session-only; graph durability uses native Save. |
| #6832 | Reviewed native document drafts | Initial analysis answer/evidence conversion, citation existence, native document storage/PDF. Broader narrative schema and adapter coverage remain open. |
| #6835 | Native load diagnostics and adapter register | Unavailable/failure/federation/sample/replacement invariants; native panel action and portable reports. Missing provider refusal and completion-visible CI capture; full adapter charter #6833 remains open. |
| #6837 | Local HTTP BCF publication evidence | 50 connector/publication tests; parsed SketchUp identity and native archive roundtrip; permission/vocabulary rejection and committed-but-lost effects. Controlled peer is not vendor conformance or a durable outbox. |
| #6841 | Shared frozen evidence view | Mounted discussion/document/Flow integration, captured/historical/stale states, federation omissions and escaped source text. Canonical fingerprint guard; successful CI journey video retention. Broader U02 remains open. |
| #6843 | Native content registry/recovery | 92 native storage/assistant/comparison/validation tests. Later legacy assistant values are preserved without replay; kind/policy/codecs and native host mapping are shared. New durable artifact families remain open. |
| #6846 | Native clash taxonomy evidence | Eight native taxonomy/evidence tests, including committed SketchUp parsing. Selector overlap and unknown types remain explicit; side/model identity and native severity are retained. Reviewed durable grouping remains open. |
| #6850 | Typed clash group preview | 19 focused native/mounted/transport tests. Captured citations resolve canonical occurrences; full report findings partition into proposed or unclassified. Strict bounded, escaped, inert preview; durable approve/apply/undo remains open. |
| #6852 | Native grouping workspace storage | 94 focused tests, including mounted workspace choice/quota retry and real whole-partition CAS/migration/import recovery. Human grouping persists; AI approve/apply/undo remains open. |
| #6854 | Atomic native content CAS | 81 focused tests, including multi-participant conflicts, immutable-policy refusal, rollback after a scheduled put, tombstones and invocation-time snapshots. Action schemas and durable effect receipts remain open. |
| #6857 | Device recovery notifications | Mounted native reporters replace loss/failure/recovery messages; delayed notification imports cannot publish older states. This does not prove geometry rendering. |
| #6859 | Native source availability | 23 focused evidence/persistence/mounted tests distinguish unavailable, zero-row and older unknown snapshots. Source workflows remain native; rendering acceptance remains open. |
| #6861 | Assistant panel fit and Chrome walkthrough | Actual native Chrome/Metal inspection rendered the real ArchiCAD model and exercised missing, empty and sampled clash evidence. Refresh action fits the default panel; full provider and human UX acceptance remain open. |
| #6865 | Conversation-first assistant panel | Issue #6863. Compact evidence summary with caveats behind Evidence details; per-source suggested questions; typed clash/Flow answers as proposal cards; review steps only when actionable; clash preview stat grid and finding rows; Enter-to-send composer. Mounted keyboard/suggestion/proposal tests and the coordinator E2E pass in a short docked panel. No live provider quality claim; human UX acceptance remains open. |
| #6867 | Show proposed clash findings in the model | Issue #6866. Finding rows and group actions resolve occurrences against the live native report and use the native Clash focus path; stale previews are inert. Real-model check: E1 selected its 2 elements with pair colours, a 3-finding group selected 5 elements, review decisions unchanged. Report/Flow cards lead with narrative/target and fold evidence into Evidence details. |
| #6879 | Start in the Assistant; live free-model test drive | Issue #6873. Source picker with live native status, in-place clash run and source switching; shared Markdown parser for panel and documents; citation peek with native clash focus; reports as structured blocks with a readable appendix (live GLM answer: 43-page JSON PDF → 5 pages); refused proposals explained with a one-click correction request and an explicit, disclosed repeats-removed preview; readable free-model names; elapsed waiting time. Live hosted free models (GLM 5.3 Flash, Qwen3 Coder Next) exercised summary, grouping, timeout and repair; quality remains model-dependent. |
| (unopened, #6833) | Native evidence adapter coverage | Per-source adapter register replaces the hard-wired five-source capture without changing their payloads; 21 new sources and 8 explained boundaries; information-rule reports stamped. Per-adapter tests over committed real models and native engines, plus mounted header-action and picker tests; not merged, no PR yet. |
CI results are live measurements on each PR, not a permanent green claim in this document. Exhausted provider budgets are infrastructure failures, remain visible and do not replace evidence-based self-review. A successful “Review posted” job does not establish that a provider actually reviewed the code.
Publication acceptance uses a local test server, selected by the user. The passing coordinator journey in CI run 37205277397 has a retained video in artifact 11304279788, downloaded and supplied to the user for review. It covers native discussion/report/Flow/undo/load panel behavior with blank software-GPU geometry; final UX acceptance and the remaining acceptance journeys are still outstanding. Native HTTP publication and recovery boundaries are measured in the BCF evidence register.
The user selected native clash type/severity plus discipline pairs as the default classification/grouping taxonomy. BCF drafts leave assignees empty until one is chosen from the selected server project's user list.
Package coverage and remaining completion work¶
| Package | Status | Remaining completion work |
|---|---|---|
| P01 | Adapter inventory complete for analysis surfaces (#6833) | Every workspace panel is an adapter source or an explained boundary, enforced by registry.test.ts; see the adapter register. Existing source-picker Open/Discuss/Run descriptors and native input availability are shared with recipe source launch/evidence availability (#7160). Remaining: proposal-effect/action families and additional per-source producer hosts (P04), rendered-browser evidence per new source. |
| P02 | Partial: shared requests and typed Flow response schemas (#7132) | lib/llm/request-service.ts gives the Assistant one cancellable, time-limited streaming call with a typed outcome (completed/truncated/cancelled/timeout/error, or refused before dispatch when the root budget is exhausted or provider schema limits are exceeded), registry-derived capabilities (model-capabilities.ts: route output ceiling, BYOK context window, null where the registry has only a placeholder; direct routes implement JSON Schema request protocols), a session-only receipt per request and one RootBudget per evidence snapshot (16 requests, 40,960 output tokens). Token counts are recorded only when the stream carries them: Anthropic (message_start/message_delta usage, always), OpenAI direct (include_usage is now requested; Responses response.completed/response.incomplete), proxy only if the upstream sends a usage chunk (the proxy forwards chunks verbatim and does not request one). Otherwise receipts say usageReported: false. Covered by stubbed SSE frames in unit tests, not by live provider measurements. Scripting chat now uses the same viewer service (#7093): one session task per explicit prompt, Continue/automatic repairs sharing its root across panel remount, completion-only native script finalization/execution, rollback of partial edits and bounded refusal without another HTTP request. Mounted tests run actual proxy/OpenAI/Anthropic transports against supplied SSE frames, real QuickJS queries on the committed SketchUp IFC, Stop/deadline rollback, remount/Continue exhaustion and native preflight repair exhaustion, account-boundary rollback and no hidden transport retries. Flow and headless/MCP consumers use the shared @ifc-lite/ai core through their host transports (P19). Typed Flow classify/extract/summarize/propose calls now carry native object schemas through the shared request contract and viewer/CLI/MCP hosts (#7132): direct OpenAI chat/Responses and Anthropic use their provider format fields; explicitly configured compatible headless upstreams request strict JSON Schema; the hosted proxy and unconfigured compatible hosts remain honestly parser-only. Typed receipts record the outgoing protocol without retaining schemas or source identifiers. Native evidence/target/allowed-value validation and review checkpoints remain authoritative. Protocol and schema-validation tests are deterministic boundary tests, not live quality measurements. Remaining: conversational artifact response schemas and actual-provider capability/usage measurements. |
| P03 | Partial: 26 sources on one adapter contract (#6833) | Each source has readiness, reference identity, run stamps where results are stored (information rules, lists, script, Flow run and point-cloud deviation newly stamped), native totals, units, availability and real-model acceptance tests. Data validation IDS/rules/manual side changes cancel attached validation and manual-checklist requests through adapter subscriptions (#7098), retaining native reports and leaving other evidence sources active. Selection includes separate mutation-aware inherited type definitions with exact model/type provenance and bounds (#7104). Material assignments and generic material property sets now share the native Properties reader (#7119), including occurrence/type precedence, session associations, aliases, federation and source-free unknown markers. Selected classifications reuse the canonical effective reader (#7139/#7131) with bounded native references/paths, schema-exact codes, model isolation and explicit unknown totals. Selected relationships use native exact edges and alias merging (#7179), bounded model-local targets, explicit source-origin uncertainty and canonical suppression of unreadable superseded membership for authoring. The relationship layer passed exact-head native, root build/type/lint and bundle checks and merged in #7185. Remaining: population-wide classification beyond samples and rendered acceptance screenshots. |
| P04 | Model-data family implemented (#6899) | Typed bounded model.changes (property set/delete, quantity set, IfcRoot string attributes) addressed by GlobalId with expected values; pure preflight (resolution, ambiguity, native edit gate, conflicts); commit as one native undo batch per model via runTransaction, all-or-nothing across models; durable receipts as content kind modelChanges; undo via revertChangeOperation refusing newer conflicts; export/reparse proven in tests. Remaining families build on this contract: geometry/creation (P15A), content effects (P10 group apply), BCF effects (P11/P12 outbox), grants beyond the native edit gate. |
| P05 | Partial | Contextual shell and conversation controls exist; the panel is conversation-first with suggested questions, typed proposal cards and keyboard send. Complete task contexts, common artifact/proposal renderers, accessibility/locale coverage and script migration. |
| P06 | Partial | Conversations and whole-partition manual grouping workspaces reuse native content libraries; shared registry and native hosts cover migration, backup and recovery. BCF drafts and the BCF publication outbox are native content kinds with quarantined imports (#6896). Saved Assistant turns and AI reports now retain their own allowlisted canonical generation receipts (#7242), including actual reported usage/outcome/transport protocol through native Save/IDB/reload/backup/document export/import and native-only refresh. Legacy missing receipts stay unknown; global session history is not persisted. Canonical dispatched receipts now retain actual token grants/deadlines, safe finish reasons, explicitly declared producer versions and versioned logical-input/output-text SHA256 digests (#7246); native artifact digests remain a separate owner-level contract. Remaining: proposals/other receipt classes, grouping policies and cross-analysis review workspaces; full program import/corruption/concurrency acceptance. |
| P07 | Merged explanation and reviewed authoring (#6915, #6935, #6936) | Typed bounded ids.specifications (IDS 1.0 facets and constraints by their native names, cardinality, dataType, declared length/area/volume units converted to SI), rules.proposal (native RuleSetFile, anything the native parser would ignore refused) and document.outline (text, validation tables bound to the live report, native report snapshot, page breaks). IDS drafts go through the @ifc-lite/rules writer (now exported; round-trips 301 of 307 buildingSMART corpus pass/fail cases with identical verdicts, refuses the 6 length-bound cases) and the native parser, then the native audit. Dry runs use the panel's runIdsCheck/runInformationCheck per loaded model without publishing; counts equal the native validator directly on the committed sample, a two-model federation and AC20-FZK-Haus; failing samples select in the model. Saving needs a clean audit and a current dry run that checked at least one model, adds a new entry to the native IDS/rules library (without activating it, so the shown report survives) or Documents, and hands off to Data validation, the rule editor or Documents; .ids export. Unsupported requirements are listed in review and stored in the IDS description/instructions, rule-set/rule descriptions or a document section. Mounted IDS/rules/outline review tests. Open: requirement-document extraction with source spans, classifying statements as IDS/rule/geometry/manual, editing an existing library entry by revision, renamed-property suggestions against dictionaries, cross-check comparison, IDS cardinality across a federation, a real provider answer and screenshot. |
| P08 | Generic reports, checked claims, refresh and languages implemented (#6918); see the assistant guide | One source-independent draft path for every registered source except graph-only Flow. Proven over the whole ASSISTANT_SOURCES list with the common adapter row envelope, so sources added by the adapter register are covered without per-source code. Optional native tables: live validation results, an immutable comparison snapshot. Typed report.claims (text, cited rows, native field values with units) are checked against the captured rows: exact for JSON numbers, rounding only at the decimals a string value writes out, converting only between same-dimension units that the evidence declares. Each claim is supported, unverifiable or contradicted, and contradicted claims block saving until edited or removed. Generated text blocks carry aiProvenance (slot plus exact generated text), and the document embeds aiReport (evidence, claims, cited-row identities, revision and optional actual generation receipt under #7242). Native-only refresh retains the original generation receipt; legacy absence stays unknown. Actual granted limits/request digests remain a separate gap. Refresh refuses an out-of-date native result, warns when the loaded models differ from the original capture, re-finds rows (including narrative and claim-text citations) by native identity, tells rows outside a sampled capture from removed rows, re-checks claims, flags changed and missing values in the document, regenerates untouched blocks, keeps human edits unless replaced block by block, and never restores deleted blocks. Copies and templates detach provenance. The narrative language is chosen per draft. Text is made WinAnsi-printable, with a substitution notice, so preview and PDF agree; a mostly unprintable narrative is refused. Real jsPDF/pdf.js checks cover de/fr/pl/cs. Report-owned headings, provenance/coverage and claim captions, appendix/grouping wrappers and refresh notices use one complete catalogue for all 13 offered Latin-script report languages (#7302), independently of UI locale. Native facts, field names, diagnostics and citations stay verbatim; generic PDF footer/page decorations and source-native table labels retain their existing language. Unsupported imported report languages explicitly refuse regeneration rather than falling back to English. Native compose/Save/IDB/export/import/PDF/refresh controls are deterministic behavior evidence, not native-speaker approval. Remaining: generic exporter/source-table locale presentation; prose outside typed claims is not semantically checked; no live-provider measurement of claim-block compliance; adapters outside the current list are covered only when they use the common envelope; no embedded Unicode fonts for non-Latin scripts. |
| P09 | Merged graph creation, run-grounded debugging, tracked-branch review and preflight (#6919, #6976, #6984) | flow.create proposals checked against the native registry and saved as a new library graph (never run, never replacing); the flowRun evidence adapter carries the last run's native diagnostics (verdict, node status, lane errors, messages, tracking counts, outputs, warnings, artifacts; parameters only for the failing branch, without script source or credentials; failing nodes ordered first so the budget never cuts them) pinned to that run; debug patches must cite nodes that failed in the captured run and change their branch; tracked-node effects (removed, re-keyed, mode, branch, added) with owned-element counts from the tracking sidecar and a second acknowledgement; assistant preflight through the native preflightWorkflow lease. Tests: author → run → debug → rerun → tracked edit → delete → rerun on the committed building-architecture.ifc, mutation-checked, plus a browser journey through the real Flow panel Run. Open: script-to-node conversion, Player input exposure, headless (CLI/MCP) parity for created graphs and a real provider answer. |
| P10 | Reviewed grouping apply/undo and full-run classification (#6906) | Native detection type/severity and ambiguous discipline candidates stay authoritative. Reviewed taxonomy edits (rename, move, split, merge, unclassify) on a review-local draft with live full-population accounting. Apply into a new named workspace (default) or the active one, with every move out of an existing group disclosed and explicitly confirmed; one CAS transaction writes the workspace at the planned revision plus a durable receipt (content kind clashGroupApplications, backup/import/boot registered); undo restores the whole previous partition and refuses once the workspace revision moved. Full-run classification pages all native findings in chunks of up to 100 with chunk-local citations through the shared request service under one root budget (30 requests, 122,880 output tokens) with a pre-start estimate, progress, cancel, disclosed consented normalization, deterministic case/whitespace-folded name merge and grouped/unclassified/failed/not-run accounting. Rerun continuity lists unchanged, identity-matched, gone and new members via the native resolver. Covered by stubbed-provider and fake-IndexedDB tests, not live provider quality or real coordinator-labelled exports; project taxonomy editing, bulk decisions and "policy for the rest" remain open. |
| P11 | Drafts from clash groups/findings (#6896, merged #6911) | Native draft batches with exact finding membership, bridge viewpoints, split/merge/remove, explicit reconciliation proposals against a newer real clash run, and .bcfzip export/import carrying the mapping; 8 draft/archive tests plus 2 mounted dialog tests (evidence). Remaining: drafts from IDS/information/semantic validation, comparisons, the AI grouping preview and cross-analysis selections; language changes; snapshot images; human UX acceptance. |
| P12 | Durable outbox and connected publication UI against the controlled peer (#6896, merged #6911) | Per-effect outbox with CAS intents, receipts, uncertain blocking of entries and dependents, read-only server checks, reload recovery, quarantined backup imports, preflight of project permissions/vocabulary/users, remote-edit conflicts on update, and Flow write nodes routed through the same outbox; 11 loopback acceptance/recovery tests and 13 package tests. Remaining: real vendor server evidence (paging, field normalisation, snapshot upload, OAuth refresh), server revision headers, background resume, a durable outbox for headless Flow hosts, orphaned-topic UI and a recorded coordinator walkthrough. |
| P13 | Reviewed native artifact proposals (#6914; analysis chart sources #7106) | Strict filter.proposal, list.proposal, lens.proposal and chart.proposal carrying the native Rules groups, ListDefinition, Lens and native ChartSpec (element chart fields named by identity; reading taken from discovered bindings). A local revision-aware schema index counts exact property/quantity presence per model and discovers declared/referenced classification systems. Explicit system selectors resolve exactly across filters, lists, lenses and charts; unknown names wait for a user pick rather than broadening missing-classification populations (#7130). Omitted/empty selectors preserve native any-system semantics, including unnamed source references. Native filters, lists, lenses, charts and classification discovery share effective definition/reference/association/type reads, native export precedence and model-local revision caches (#7131). Relevant live classification edits on source-empty transports explicitly refuse an unavailable population; source-bearing edits remain reviewable. A bounded digest goes into guidance. Unresolved names wait for a user pick among ranked real candidates. Reviews run the native engines (evaluateFilterGroupsFederated, runListFederated + resolveListColumnUnits, evaluateLensGroups + evaluateLens/evaluateAutoColorLens, buildElementsDataset + resolveChartFilter + aggregate). They show per-model populations, units and measured/total denominators. "This model" is a native model rule whose names resolve to durable source fingerprints before any engine runs (unknown or duplicate names are refused); a filter, list or lens claiming a visible/selected scope is refused, and guidance asks for a prose explanation plus the closest supported proposal for unsupported joins. Saving goes into saved filters, Lists, Lenses and dashboards and opens the native panel. The index scan yields every 500 rows like the chart editor's field discovery (80 MB hospital model, 15,074 elements: about 1.1 s in total, longest main-thread block 79 ms) and an unreadable model degrades the guidance instead of failing the request. Tests: 7 parser, 10 engine-oracle (committed building-architecture.ifc with hello-wall.ifc federated, including model scope and type-inherited properties), 9 ambiguity/index/guidance, 5 save/reopen, 4 mounted review tests, and one Playwright journey (assistant-artifacts.e2e.spec.ts: Open/Add federation, keyboard ambiguity pick, list/chart/filter review, save, native editors). Analysis chart proposals now use the existing clash/BCF/schedule/IDS/compare datasets: exact native columns, units and recorded-row denominators, missing element links, source-bound preview/save and native dashboard reuse (#7106). Visible/basket analysis populations and analysis-source element filters explicitly refuse; they are not silently widened. Remaining: visible/selected populations for filters (chart scope covers visible/basket), a structured unsupported-join refusal beyond guidance, origin metadata (the native types have none), live provider quality measurements and human UX acceptance. |
| P14 | Partial: Assistant scene actions with restore (#6907) | Typed bounded scene.actions (lib/actions/scene-actions.ts: select/isolate/hide/frame, colour groups from an 8-colour palette, section plane or box, camera eye/target; targets by GlobalId (+ modelId) or evidence citation; units required) with an inert preview (scene-preview.ts) that resolves targets per model, counts missing/ambiguous/stale-citation targets and converts IFC-world coordinates through the shared render-frame rule, refusing positions outside loaded bounds. Apply (scene-apply.ts) re-previews, captures the prior view and writes native channels; restore (scene-restore.ts) is gated per channel: selection by selectionRevision, isolation by value ownership with the prior owner's record restored and the claim dropped on first replacement, hides by the ids added, colours by colorPresentationRevision (IDS colour claim handed back), section by the installed plane object; the camera always returns. Composer Attach selection (selection-grounding.ts, bounded GlobalId/type/Name) and Attach view (image only for supportsImages models; otherwise refused, never dropped; not persisted). Covered by store-level round-trip/ownership tests and a mounted panel flow, not by a browser run against a real model. Remaining: natural-language filter/list grounding (P13), "this area" geometric queries from tools, a selection evidence source in the adapter register, restore across model reload, keyboard/screen-reader review in a real browser and real-model demonstrations. |
| P15 | Partial: table, bulk and IDS corrections reviewed as model.changes (#6912) |
Converters in lib/actions/ (table-changes, bulk-changes, ids-changes) turn a CSV mapping, a Bulk editor action or an IDS correction into P04 batches with the effective value as expected value, keyed by GlobalId (Tag/Name keys resolved exactly; empty, duplicate, unmatched and ambiguous keys reported, never guessed), typed by the shared cell parser, unit-converted to the stored frame through the IDS unit resolver; split into numbered parts of 500, refused above 10,000. Data Connector, Bulk editor and IDS correction dialog make Review as changes primary; direct paths stay secondary for Express ID/property-value matching, one-row-to-many writes and oversized sets. Typed table.mapping with strict parse, validation and an editable card with live sample conversion; Data Connector Suggest mapping drafts it through the shared request service. Receipts record per-specification verdict counts at apply and after Re-run validation (IDS or open rule set), decoded compatibly. Tested on the committed SketchUp sample and its IDS (unit conversion mm, wall/type Name ambiguity, conflict after read, one undo, export/reparse, IDS failed 1 → 0). Remaining: dictionary/classification/whitespace mappings, a table evidence source for the Assistant, information requests for unknown values, coordinated partial commits across models with skip-conflict preview, redo of reviewed batches, rerun invalidation on undo, storage-refusal and multi-tab acceptance, real spreadsheet evidence from a delivery. |
| P15A | Native authoring layer implemented (#6902); see the operation matrix | Sibling contract model.authoring (declared units, storey-local frame, expected class/name/type/material/origin/angle, in-batch refs). Ops: create wall/slab/roof/plate/column/beam/member/space, hosted door/window/opening, wall join, type and material assignment, horizontal move, rotate, delete. Preview: resolution, edit gate, native builder dry run on an unpublished draft, 3D ghosts on a proposal overlay channel. Commit through runTransaction as one undo batch per model with re-mesh; shared receipts and undo. Tests on the committed SketchUp sample: refusals, one-batch commit, undo, export/reparse integrity (containment, void/fill, join, type, material, moved/turned placement, deletion), ghost-vs-commit geometry, mounted review card and assistant proposal. Reviewed copy/linear/polar arrays now use native planners/writers/ghosts, bounded output refs, target-storey and source-reload checks, per-root receipts and one undo batch. Native committed SketchUp mutation/export/undo/federation and Bonsai real WASM cut-volume/opening/ghost proofs are recorded under #7202; metre/millimetre polar/storey variants and mounted approval are covered. Open: split/trim/extend, resizes, storey/group/relationship edits, polygon/profile parameters, slab openings, multi-model run, real provider answer and viewport screenshot, storey evidence for proposals. |
| P16 | Native assistance implemented (issue #6920); see the linked-records notes | Linked records is an assistant source with attached texts cut into exact-offset passages. Typed proposals semantic.query, semantic.mapping, semantic.projection and semantic.requirements are reviewed natively: query lint (inspectReadOnlyQuery, outer LIMIT, declared columns) and run only with the endpoint grant the panel exercised (never in evidence or on screen as a credential), mappings counted per revision-associated model and saved with a revision pin to the semanticReviews library (backup/import), projections previewed and applied by the existing projection service, requirements saved with each span's verification. Spans verify only on exact offsets and quote equality. 24 tests (seeded span generator, recording transport, mounted cards, grant revocation, backup round trip) with eight mutation checks. Open: a real provider answer and live endpoint run, applying approved mappings to a profile, turning requirements into IDS/validation, multi-endpoint grants. |
| P17 | Impact and compatible-run reconciliation implemented (#6921) | Compare panel Impact on other analyses joins the loaded clash run, IDS/rules report, active list (numeric column sums) and BCF topics to changed elements by model + GlobalId only (BCF by GlobalId), with stale/not-loaded status and exact totals. Reconcile findings across revisions reconciles two captured clash or validation runs into new/resolved/persisting/changed/not evaluated, refusing with named reasons when rules, settings, scope, specification or rule content, model coverage or freshness differ (an unstamped run is refused); absence resolves only after a complete re-examination, a finding is new only when the base run was complete for it, cross-revision clash pairs and duplicated GlobalIds are excluded, and a saved result is withdrawn after later edits. The assistant's compare evidence carries both sections. Tests on the committed revision pair (building-architecture A and rev B) with native meshing, clash, IDS, list and a native property correction; reused GlobalIds, truncated and stale runs, refusals, mounted panel. Open: a second independent real revision pair (rev B is derived), quantity takeoff beyond list columns, impact rows that focus the 3D view, persisted captures, assistant evidence freshness when a joined analysis reruns without a new comparison. |
| P18 | Partial: Review workspace and coordination cards (#6922) | lib/review/: five finding sources (clash, validation, comparison, BCF, linked records) normalised to one shape and registered in sources/index.ts; coordination cards group findings that name exactly the same validated elements (identity via model name + GlobalId; ambiguous, missing or natively unresolved elements are never merged; cards are not transitive, related cards link by shared element); lifecycle keeps current and historical evidence apart and only a complete current run can produce a no-longer-observed resolution candidate (never a resolution); separate totals (unique elements, current, historical, cards, topics). Reviewer decisions are the reviewWorkspaces content kind (CAS save, backup, import, recovery). Actions: draft BCF topics (draft batch origin review; cards with a topic or without current evidence are excluded and reported) and add to report (new literal native document). The pinned card is the review evidence source. Open original selects the native clash/topic/element and opens its panel. Native P17 compatible run reconciliation also contributes exact captured occurrences, source states and resolution candidates. Review refreshes and clears pinned evidence when its source changes; Open original identifies the native run pair and focuses its row. Stale, partial, excluded or unavailable evidence cannot confirm resolution. Native P10 durable group application receipts also contribute historical coordination records with verbatim applied/undone status, saved membership and workspace revision, and native rerun continuity. Missing, partial or ambiguous source membership stays explicit; grouping never proves clash resolution. Receipt/workspace changes refresh Review and clear pins; Open original reaches the exact saved receipt, including an undone receipt, and repeated navigation restores focus. Saved IDS/information-validation snapshots now retain bounded portable failed/warning element facts through native Save, workflow retention, document copying and library import. Review projects those as historical not-evaluated findings; old count-only snapshots invent no rows. Native history requests select the exact immutable row without reusing historical scene identifiers. Saved source changes refresh Review and clear pins. Not yet: compatible re-examination of these saved element facts, review Flow/MCP surfaces. |
| P19 | Shared AI nodes and reviewed host continuation (#7079, #7083; completion tracked by #7070) | @ifc-lite/ai is the common request, receipt and persistable root-budget home. The lazy Flow AI entry registers ai.classify, ai.summarize, ai.extract and ai.propose; validated evidence, citations, coverage and native field constraints govern drafts. ai.propose currently supports only the portable model.changes artifact; other kinds explicitly refuse. Viewer, configured CLI and configured MCP share the native scheduler and checkpoint lifecycle: prepared → reviewed/rejected → applying → completed/partially-committed through exclusive CAS, binding graph/Player inputs, source and proposal digests. Restored outputs replay without another request; original budget consumption and usage receipts survive MCP continuation. Viewer uses IndexedDB and its native review card; CLI uses flow run --checkpoint, flow review --approve <digest> and flow resume; MCP uses durable pending artifacts from run_flow or read-only propose_flow and a separate current-authorized resume_flow. Real committed IFC regressions demonstrate downstream property application, export/reparse, single consumption, stale evidence, revoked authority, cancellation, credential-persistence refusal and exhaustion across a second pause. The constrained model-change artifact also traverses native viewer preview/commit/export/undo. Non-portable values explicitly refuse. MCP creation tracking remains per-call; this is not persistent creation reconciliation. Remaining: full charter parity audit and live-provider/human acceptance under #6928. |
| P20 | Implemented native reuse (#7055, #7067) | Fingerprint-scoped preferences, native prompt/Flow/review recipes and Ideas; completed conversation intent compiles into a reviewed native Flow graph with fresh evidence, the existing request pool and selected action kinds. Graph/recipe saves report independent refusal/retry states; exports bind imported graph references, and native preflight denies missing edit permission. Real committed IFC tests cover native column creation and tracked rerun without duplicates; approval, redraft, cancellation and stale-host races are mounted regressions. Remaining: live-provider usefulness and independent reuse/recovery acceptance under #6928. |
| P21 | Full journey replay coverage; external acceptance pending | Real ArchiCAD IDS and committed SketchUp parse/PDF fixtures started. Tooling: versioned corpus manifest with fingerprints and automated privacy scan, 27 recorded-response CI cases replayed through the real Assistant path, release invariants with proven detectors, an opt-in live runner with fixed settings, budget and usage receipts, and a labelling tool with agreement scoring. Every charter journey now has a native fixture task and offline release recording, enforced by the corpus gate. Classification pauses before writes; Review scope, missing quantities, source selection and file-reimport boundaries have native assertions. Remaining external evidence: independent labels, privacy/licence review, a real live evaluation and pilot UX thresholds. |
| U01 | Partial design contract; study tooling built | Recognizable incremental layout/style constraints captured. Study protocol with twelve registry-checked task scripts spanning all ten journeys (#7069), current/assisted variants, session schema and a summary that refuses to judge thresholds on too few participants. Open for people: actual existing-user sessions and ratified thresholds; complete navigation mapping. |
| U02 | Shared result chrome and activity tray (#6925) | components/viewer/result/: ResultView regions (source/models/population, coverage with status and every known gap, native summary, filters, a named actions group, rows, evidence), one StatusChip vocabulary with icon plus words (the charter's proposal states and run outcomes), ResultState (no applicable population, no findings, failed, unsupported, partial, filtered), ArtifactHeader, ScopeControl (selected/filtered/all, empty scopes unavailable, members pinned at open) and the lib/result/selection-model.ts reducer (selected vs in-batch, highlighted owned by the panel focus; page vs population "select all"; population actions enabled only on retrieved keys; stale answers dropped). Adopted by Compare (source, scope, geometry-gap coverage), IDS/rules validation (models, population, not-applicable/unevaluable/capped coverage, partial when no specification applied to anything; IDS document card as artifact header) and Clash (four empty states, select-all over filtered findings that only a membership change drops, not a re-sort or review decision, BCF archive scoped and pinned). Activity tray in the status bar: loads, clash/validation runs, exports (ExportDialogShell, plus the clash BCF, IDS BCF and Charts PDF report dialogs through recordActivity), assistant requests (request-service in-flight entries; Cancel aborts the request) and Flow runs from a per-tab session journal whose running jobs return as Interrupted after reload; a cancel is read from its source (loadCancelSeq, the Flow run's abort signal), so a job stopped from its own panel, the status bar or the loading card is Cancelled, not Completed or Failed; the 30-entry journal evicts finished jobs before running ones; one live region announces each job that finishes; BCF publication rows read from the durable outbox. Native clash detection (normal, duplicate and preset preparation) now exposes owned tray cancellation, keeps background work cancellable after panel close, separates superseded runs and removes terminal callbacks (#7110). IDS and information rules already had per-controller native tray cancellation; regression runs verify cancelled outcomes and registry cleanup. Native list execution, bulk-property operations and document PDF publication now enter the journal (#7128). List and bulk rows reuse their native per-invocation cancellation; cancelled/failed bulk work with applied edits is Partial and states that changes remain undoable. Document PDF publication records native success, partial coverage and failure without an invented Cancel. Native cloud-source download batches now enter Activity before model loading (#7134), keep exact per-batch cancellation, suppress late dispatch and report Partial when already dispatched files survive cancellation or later download failures. Native BCF panel and draft archive publication now records each writer/download invocation as Running, Completed or Failed, preserves background completion after panel close, and offers no Cancel because the native ZIP writer has no abort contract (#7140). Native zone geometry GLB and quantity CSV/Parquet exports now journal actual publication outcomes (#7142). Geometry preserves the exclusive native background lease, propagates per-element progress and classifies no-geometry as Failed and published geometry gaps as Partial; missing-binding, absent-zone and busy preflight create no job. Tables preserve no-members preflight and native reason columns; unmeasured rows produce Partial. Neither writer offers Cancel. Installed extension exports journal native handler execution through browser publication (#7170), identify the exporter owner, retain background jobs and native failure outcomes, and offer no Cancel because the host has no abort contract. Native toolbar model CSV exports (entities, properties, quantities and spatial hierarchy) now enter Activity through their shared ribbon/palette/mobile handler (#7162), preserve edited active-model-only output and independent background invocations, and record completion only after publication or failure without unsupported Cancel. Native Lists result composition now adopts captured source/model scope, native matched/visible coverage and honest empty/filtered states through ResultView (#7166); nested/schedule rows, units, grouping, selection and exports retain native behavior. Native selection quantities now use ResultView with actual selected model/population identity, native authored/proved-volume/mesh-area counts, all native coverage gaps and source inspection in the evidence region (#7184). Empty selection and unavailable measurements are distinct; finite zero measurements remain rows. Canonical units, occurrence/type fallback and independent measurement bases are retained. The native BCF topic workspace composes the shared source/coverage regions (#7198), counts current workspace topics separately from status-filtered topics and distinguishes a filter-empty view from no local topic population. It preserves native topic GUID selection and full-workspace archive publication; imported/server/check completeness remains explicitly unknown, and unrelated loaded IFC models are not claimed as topic source scope. Native BIM ↔ scan deviation now composes captured scan source identities, actual readback/finite/clipped coverage, native summaries, controls, CSV actions and GUID evidence through ResultView (#7197). Canonical renderer statistics and revision/placement/readback ownership are retained; unavailable identity, unmeasured points and unrecorded provenance remain explicit. Native Zones volume-apportionment results now use ResultView with actual cached processed/refused counts, captured per-row source identity and freshness, explicit incremental/unknown coverage and bounded GlobalId evidence (#7204). Older or unrecorded rows retain their own provenance through per-element cache merges; native clipping, cache revision/publication and authoring/writeback/export controls are preserved. Remaining: libraries composition, batch (included) adoption by P10/P04 reviewed batches, live-provider acceptance. Native sheet and vector PDF writes in useDrawingExport now record running/completed/failed journal outcomes (#7100); error toasts remain native, and no Cancel is offered because these PDF writers have no abort contract. Flow Activity callbacks retain only their captured native run authority; a retained callback cannot abort a subsequent workflow (#7122). Existing abortable native Cesium uploads and deviation CSV exports now expose owned tray cancellation, classify native aborts as Cancelled, suppress late publication and clean terminal callbacks (#7121). |
| U03 | Native workbench delivered (#7053) | Reviewed coordinator/author/explorer presets, stable Assistant return context and proposal target, reset recovery and language reconciliation. Mounted/native tests, root checks and unchanged bundle limits passed at delivery. Independent keyboard/screen-reader, locale and narrow-layout user acceptance remains part of #6928. |
| U04 | Migration/recovery delivered; follow-up merged (#7054, #7068) | Versioned layouts preserve known/unknown placements, exact rollback sources and older-writer edits; review is reachable in mobile/collapsed hosts. Native artifact links preserve unsaved conversation work and reject conflicting destinations. #6927 was reopened for rejected-write recovery: #7068 restores companion placements and addresses complete-panel import backup/refusal. Independent third-party extension and Session acceptance remains to be recorded. |
Completion rule¶
Do not close the program issue #6812 until every row is complete and all ten acceptance journeys in the charter have recorded independent evidence. Each next layer gets a scoped issue, claimed ownership, native implementation, tests, a self-review record and a linked PR with measured validation before merge. No package is deferred as “later.”
Coordinator screenshot follow-up¶
The initial coordinator recording exposed contradictory device-loss and recovery notifications. Issue #6855 replaces these messages within one notification lifecycle, retaining unrelated errors and suppressing delayed updates from older notification states. A successful native recovery restores GPU resources; its notification says the graphics device is restored and drawing is restarting. It does not claim a rendered frame was observed. This is notification correctness, not proof of geometry visibility. A successful rendered-model recording is still required for viewport acceptance. The complete program and remaining acceptance journeys remain open.
Issue #6856 separates unavailable native sources, available zero-row reports and older unknown availability in bounded snapshots and the shared evidence view. Sampling, freshness and archived scope remain unchanged. The coordinator test now checks the source availability in the actual outbound evidence envelope.
Rendered-model acceptance follow-up is tracked in #6858. CI run 37205277397 recorded panel/CPU behavior successfully, while the supplied screenshots show a blank viewport. Hosted software-WebGPU losses appear elsewhere in that job; the cause of this particular recording remains unproven. Neither passing panel assertions nor notification replacement resolves this acceptance requirement.
Standalone Chrome inspection (2026-10-04)¶
At the user’s request, session t3code-a14bee09 inspected the native viewer in a fresh standalone Chrome session on a secure localhost origin with Apple Metal WebGPU. The real AC20-FZK-Haus.ifc loaded 82 geometry elements and the house was visibly rendered. Native duplicate detection returned zero findings; native all-clash detection returned 155 findings grouped into 33 native issues. These are observed native outputs, not independent correctness labels or LLM classifications. The assistant distinguished absent results from the completed empty scan and disclosed a bounded 72/155 sample for the populated scan. No browser page or graphics errors were observed. A missing model produced the explicit configuration error; no live LLM generation was tested.
The inspection exposed an overflowing refresh action (issue #6860); wrapping it keeps it within the default panel. The coordinator E2E test now measures the action’s actual browser bounds. Screenshots and a recorded walkthrough are retained locally for the user’s review. This supplies successful rendering evidence for the ordinary coordinator flow; forced device-loss recovery and the cause of the earlier software-GPU recording failure remain unproven, and final human UX acceptance remains pending. All remaining packages stay in scope.
Shared-browser viewport evidence (2026-10-08)¶
A qualified production preview in the native T3 collaborative browser visibly rendered the committed SketchUp sample on an NVIDIA Blackwell WebGPU adapter. The recorded TOP camera and GPU roof pick selected source slab #425, GlobalId 12UVOn4wvAJPMUExKdZLb8, and exposed its native Properties panel. Asset fingerprints and scope accompany the screenshots and recording. This adds reproducible ordinary-render evidence; it does not establish forced-loss recovery or explain the original software-GPU failure.
P15A Trim/Extend class #7262 uses the canonical native reach planner/writer through reviewed element.trimExtend, with verbatim selected native expected snapshots, source/overlay freshness, wall or line boundaries and one native undo/remesh batch. Review discloses outer-body, adjoining-wall, fillet and dependent-boundary preview limits. Native both-end wall/beam/member, file/command units, federation, hosted refit/cut refusal, joins, shared-geometry refusal, source replay/reload and WASM section proofs are the bounded acceptance route. Full compilation/review is pending; the rest of P15A remains open.
P15A #7273: bounded reviewed canonical stair/railing lifecycle uses existing creation, strict dimension, assembly/generic removal and family replacement writers. Native IFC export/reparse, IFC2X3/IFC4/IFC4X3 m/mm, federation, real WASM, mounted review and controlled transport witnesses cover the family; 50 native family controls pass with no skips. Shared schema-exact Root uniqueness guards product/flight GlobalIds before prepared writes publish, including explicit old-GlobalId replacement and Undo. The pure reader correction is reused from #7270. The full 14-production-file oracle observes parser/mounted/native behavior and verifies source restoration; refusal and federation isolation compare independently reparsed native type/attribute graphs rather than export headers. Independent review and allocated root qualification remain pending; the complete native operation matrix and human acceptance remain open.
P15A #7313 (Draft #7316): explicit-pivot rotation and native Align are under bounded implementation. Both request routes publish canonical current placement pins; explicit Align preparation binds native remesh bounds to source/view revisions, owning meshes and the native workplane. Native host/filling carriers retain their canonical write policy. Current source-native/inverse controls exist; allocated root compilation, built acceptance and independent review remain pending. This does not complete the operation matrix or external human acceptance.
P15A supplied Structural graph follow-up (#7318): the bounded separate reviewed route consumes the nine existing native SDK creation/relationship factories, publishes complete effective native records and unit-provenance evidence on both selection request routes, and uses detached preparation plus current-source native grouped Apply/Undo. Literal model-measure acknowledgement is explicit; no engineering design/solver, automatic unit conversion, Structural deletion or fabricated geometry preview is added. Source-only storey frame limitations refuse current placement edits. Native/root qualification remains pending until the follow-up PR records completed proof; this does not mark P15A or external acceptance #6928 complete.
P15A supplied Cost graph class #7311 adds a separate bounded reviewed cost.graph route over the nine existing canonical SDK cost methods. Both selection evidence channels publish the same complete native snapshot (rich transport uses bounded JSON parts), with explicit source/unavailable status, declared units and full incoming native references. Preparation is detached, Apply uses compound native history, non-root receipts retain actual expressIds, and no price/currency/conversion is inferred. Native fixture/request/mounted/STEP/Undo witnesses qualify this class only; allocated full root qualification, independent review and external #6928 acceptance remain pending.
P15A Room AutoAll #7324 / Draft #7325 extends the CLOSED #7286 single-storey Room class with one explicit-model complete current-storey preparation. The canonical SDK source backend uses the existing native planner/writer, one detached graph and one recorded approval, with per-storey known/no-wall/occupied/no-face/unavailable coverage and no partial approval of unknown storeys. Source-native SDK controls include independent m/mm STEP readback, no live preparation writes, native grouped Undo, direct mutation/cancel/geometry leases and honest no-write outcomes. The coordinated root Turbo SDK build at c41 supplies the actual SDK binding. Current-main composed native Room controls pass 48/48 with zero skips, including the earlier 17 AutoAll fixtures; final 18/18 adds saved-source first-read purity and genuine grouped Undo: controlled OpenAI/Anthropic requests through both evidence channels, mounted m/mm approval, native STEP owners/dimensions/WASM and Undo, one-model federation ownership, unavailable/no-write coverage and current source/geometry/frame/cancel leases. Exact native view revision and current entity ownership invalidate stale footprint/triangle occupancy after direct space removal. The whole twelve-Viewer-runtime-path inverse gives 5 actual assertions, 12 native unsupported-admission errors and one native creation control; surgical current-occupancy reversion gives one actual assertion/17 controls. All source SHA values and compiled SDK bytes are restored, followed by 18/18 passing controls. This Viewer proof is separate from the retained SDK two-source-file inverse; final current-dependency root build/type/lint/API snapshot/docs/bundle and independent review remain pending. This checkpoint does not complete P15A or external #6928 human/privacy/licence/coordinator acceptance.
P15A standalone native scaffold #7326 adds bounded ifc.create review using the existing public CreateNamespace project/storey/export writer. Explicit supported schema, file units and storeys are required. Detached preparation parses actual native header/units/Root graph; Download publishes approved bytes. Empty Models context exposes capability with zero existing-model facts, and the primary File request uses the existing canonical loader event without asserting completion or Undo. Current-main composed native request/mounted/STEP/WASM, front-door, document metadata and recorded-response controls pass 91/91 with zero skips, and composed Structural/NewFile review, native and transport controls pass 106/106 on the current Structural main; the seven-runtime-path public-entry inverse yields six actual assertions and six native controls, followed by exact source-SHA restoration and 12/12 passing public-entry controls. Two recorded Models contexts were refreshed through the canonical capture tool with provider replies, prompts and all other fields unchanged. These controls qualify only this finite class; allocated full root qualification, actual browser loading and external #6928 acceptance remain pending.
Comparison impact native navigation (#7307 / #7309)¶
Four existing impact-row kinds now use native panel/selection setters with authentic source-table and mutation-view revision ownership captured at comparison preparation. List aggregates open their existing result without a freshness claim; BCF topics open without model-free component selection. Both revision-side chips resolve exact current native Root identity. Replaced sources before first mount, remounts, direct view edits, unavailable originals and held callbacks refuse. Native real SketchUp revision-pair parser/WASM/diff/clash/IDS/information validation/list/BCF and federation controls passed 36 tests without skips on the Room-composed main; whole-class inverse and compiler qualification are recorded separately. External coordinator/human acceptance remains unperformed by this layer. No new matching, navigation engine or analysis run.