First R3 (Theater) piece. Reworks the stale artifact-keyed ReplayRoute into
the turn-keyed hero over the #716 sealed-replay backend, and fully retires
the dead W-026 artifact-keyed machinery on both sides (the NOT_YET_MIRRORED
comment anticipated this).
The hero makes determinism *felt*: pick a journaled turn, CORE re-executes
its prompt in a sealed fresh runtime, and the result renders as a hash
verdict (≡ equivalent / ≠ diverged) + the original/replay DigestBadges + a
leaf diff (critical weighted above informational, each with a ≠ glyph). The
'What this proves' card surfaces comparison_basis + origin_state and states
the honest limit: a divergence means nondeterminism OR origin-state
influence, never rendered on its own as a determinism failure.
Retirement (verified zero serving uses):
- Python schemas.py: removed ReplayComparison/ReplayDivergence/ReplayStatus/
ReplayDivergenceSeverity; scripts/dump-enums.py drops the two replay enums;
both snapshots regenerated (deterministic: dump == committed)
- TS: removed ReplayComparison/ReplayDivergence/ReplayDivergenceSeverity;
added TurnReplayComparison/TurnReplayDivergence (+ basis/origin/severity
unions); NOT_YET_MIRRORED now empty (every engine schema mirrored)
- badges: removed ReplayStatusBadge + ReplayDivergenceSeverityBadge +
meta/enums + their enumCoverage cases (hero renders severity inline)
- api: fetchReplayComparison/useReplayComparison -> fetchTurnReplay/
useTurnReplay (/replay/<turnId>)
- deleted ArtifactList, ReplayComparisonPanel, ReplayDiffViewer,
ReplayMetadataTable, old replay.test.tsx
- App route /replay/:artifactId? -> /replay/:turnId?; conformance row
turn-keyed (loading 'Loading turns...', empty 'No turns recorded yet.')
Tests: ReplayRoute.test.tsx (equivalence hero + honesty card, diverged
critical leaf, informational-only label, replace-mode select, j/k spine).
Full vitest 358 green; workbench Python 34 green; both snapshots deterministic.
Follow-up flagged (not in this PR to keep it focused): the artifact query
hooks (useArtifacts/useArtifactDetail/fetchArtifacts*) are now orphaned but
entangled with the still-live artifact EvidenceSubject kind — a separate
cleanup once an Artifacts route or that subject's fate is decided.
Brief: docs/handoff/wave-R3-briefs-2026-06-13.md (all four R3 pieces).
Replaces SettingsRoutePlaceholder, completing all six placeholder routes.
- workbenchPrefs.ts: typed localStorage prefs with safe parse + live
same-tab sync (useWorkbenchPrefs). Every pref has a real consumer — no
toggle that does nothing:
* landingRoute -> consumed by the App index redirect (Navigate)
* inspectorDefaultOpen -> consumed by EvidenceProvider initial state
(EvidenceUrlSync still force-opens on a ?inspect= deep link)
- SettingsRoute: two panels. Preferences (landing route select + inspector
default switch, applied on next load, survive reload). Runtime (read-only
/runtime/status: backend, git_revision DigestBadge, engine_state_present,
checkpoint_revision, revision_warning with warning token, active_session_id,
mutation_mode) under the standing statement 'Engine configuration is
CLI-only. This page mutates nothing on the server.'
- no backend change, no new schema/subject, no NOT_YET_MIRRORED change, no
engine mutation of any kind
- bespoke conformance block (Settings has no empty state — the prefs panel
always renders); asserts the loading label + CLI-only statement + the
error contract over the status fetch
- tests: workbenchPrefs (defaults / persist+reload / invalid+malformed
fallback / partial merge) + SettingsRoute (both panels, landing-route
persistence, inspector toggle, error-without-mutation)
DEFERRED (flagged, not shipped as theater): list-density pref — honest
wiring requires threading a density token through every list row, a
separate change; shipping a control that does nothing would violate
ADR-0160 (audit-native, not analytics theater). Token-only styling
(hexScan green); full vitest 363 green.
Replaces VaultRoutePlaceholder with the real route over the R2-B
/vault read substrate (#712).
- TS mirrors VaultSummary/VaultEntry; both removed from NOT_YET_MIRRORED.
Also fixes a latent ErrorCode drift: adds 'evidence_unavailable' to the
TS union (present in Python schemas, missing in TS) — the route branches
on it.
- fail-closed is the design: a missing/unpersisted vault (the 501
evidence_unavailable signal, or persisted=false / entry_count=0) renders
the honest absence card as the PRIMARY state, naming the opt-in
RuntimeConfig.persist_session_state pointer — not a generic error, no
skeleton theater
- with data: summary strip (entry_count, store_count, reproject_interval,
max_entries, source_path) + VirtualizedList of entries with
epistemic_status / epistemic_state pills and versor_digest DigestBadge
- exact-recall doctrine: renders only backend fields; never computes or
displays a similarity/relevance proxy (runtime recall is exact cga_inner)
- selection publishes the vault_entry subject (inspect-param only, via
setSubject + setInspectorOpen; EvidenceUrlSync writes ?inspect=vault:N);
a URL-restored identity-only subject is hydrated once entries load
- Vault row added to routeConformance MOUNT_ROUTES — the fail-closed
absence asserted as the primary contract
- tests: fail-closed card (not error), summary+entries, no-similarity-score
doctrine, vault_entry subject publication, j/k spine
Token-only styling (hexScan green).
Replaces PacksRoutePlaceholder with the real triad route over the R2-B
/packs read substrate (#712).
- TS mirrors PackSource/PackSummary/PackDetail; PackSummary/PackDetail
removed from NOT_YET_MIRRORED (drift gate now enforces them)
- new design primitive TreeView (src/design/components/TreeView): a
deterministic, keyboard-driven JSON tree — object keys sorted, array
indices in order, no animation; ←/→ collapse/expand, ↑/↓ + j/k move,
Home/End jump, Enter toggles; registers its shortcuts only while focused
(KeyboardHelp never advertises tree controls when no tree is on screen)
- list pane: VirtualizedList + useListNavigation (j/k) + SearchInput; rows
show pack_id, source, version, language/modality, determinism_class pill
- detail pane: Panel + TabBar (Manifest / Checksums / Raw); Manifest renders
via TreeView; Checksums is the verify affordance — manifest_digest and
declared checksum as DigestBadges plus the per-field manifest checksums
table (the checksum-hashes-the-bytes-on-disk doctrine made visible); Raw
collapsed by default
- selection publishes the pack subject (R2-S), records /packs/<packId>
(replace), pushRecentItem on visit
- Packs row added to routeConformance MOUNT_ROUTES (loading 'Loading
packs...', error 'No packs mutation occurred.', empty 'No packs
discovered.' + core pack validate <path>)
- tests: TreeView (sorted/collapsed/expand/collapse/focus/click/empty) +
PacksRoute (list, replace-mode select + manifest tree, checksum verify
affordance, j/k spine)
Token-only styling (hexScan green).
Replaces the RunsRoutePlaceholder with the real triad route over the
R2-B /runs read substrate (#712).
- TS mirrors RunSource/RunSummary/RunTurnRef/RunDetail; all three classes
removed from NOT_YET_MIRRORED (drift gate now enforces them)
- list pane: VirtualizedList + useListNavigation (j/k) + SearchInput;
rows show source, session_id, turn_count, relative timestamp, a
checkpoint badge (present + revision vs 'no checkpoint'), and any
evidence_gap rendered honestly in-row (never hidden)
- detail pane: Panel + TabBar (Turns / Manifest / Raw); every turn row
is an anchor to /trace/<turn_id> (backend-provided trace_path) with the
trace_hash as a DigestBadge — the cross-link is the point of this route;
turn list pages via turn_limit ('Load more turns')
- selection publishes the run subject (R2-S) and records /runs/<sessionId>
in the URL (replace), pushRecentItem on visit
- Runs row added to routeConformance MOUNT_ROUTES (loading 'Loading
runs...', error 'No runs mutation occurred.', empty 'No runs recorded
yet.' + core chat)
- RunsRoute.test.tsx: list evidence, in-row gap, replace-mode URL select,
trace cross-link hrefs, manifest tab, j/k keyboard spine
Token-only styling (hexScan green); full vitest 339 green.
URL = subject: one codec (evidenceAddress.ts) owns the address grammar for
every EvidenceSubject kind, including kinds whose routes are placeholders.
urlToSubject is a total inverse — malformed input yields null, never throws.
- Route params: /trace/:turnId?, /proposals/:proposalId?, /evals/:laneId?,
/replay/:artifactId? (placeholders keep flat paths)
- ?inspect= carries inspector subject + open state; EvidenceUrlSync restores
deep links and write-through syncs with replace (selection churn never
pollutes history); malformed values are dropped from the URL
- Proposals/Evals/Replay restore selection from their param on load, write it
on selection change (replace), and publish the selected subject to the
evidence context (identity at once, detail when the query resolves)
- EvidenceSubject.data now optional; inspectors render an honest
'detail not loaded' state for identity-only subjects
- Cmd+Shift+C copies origin + subjectToUrl(subject); no-op without subject;
input-focus guard; transient inline 'Copied' on the inspector header
- Fix pre-existing unbounded re-render loop in RightInspector.test.tsx
(render-phase setSubject); subjects now set from effects