Skip to content

spec(split-reel): v7 -- a client's reel carries the client's call, voice and words - #5785

Merged
gHashTag merged 5 commits into
masterfrom
spec/split-reel-v7
Oct 3, 2026
Merged

gHashTag merged 5 commits into
masterfrom
spec/split-reel-v7

Conversation

@gHashTag

@gHashTag gHashTag commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Closes #5784

Why

Owner, 2026-10-03, on a reel made for a client: "why does it make the CTA mine and not the client's? what a mess".

The split reel ended on OWNER_CTA (@t27ai_bot) whenever the order wrote no call. An order for a client's reel writes none. The owner's MiniMax clone and the bot's spoken name ("Trinity") leaked into client reels the same way.

What

specs/automation/split-reel.t27 enters t27 at v7. v1-v6 lived only in the 999 host, and v6's body is unchanged here.

  • house_own(house_caller, client_turn, for_lead, seller_sweep): a reel is the house's own only when the house orders it and nobody else is named on the turn.

  • cta_for(house_own, given, given_names_house, client_has_cta) -> u8 returns one of:

    • CTA_GIVEN, the call the order wrote, unless it names the house on a client's reel;
    • CTA_CLIENT, the call in the client's profile;
    • CTA_NEUTRAL, a neutral call;
    • CTA_OWNER, on the house's own reel only.
  • owner_voice_allowed(house_own): OWNER_VOICE_ON_CLIENT_REEL = false.

  • house_name_allowed(house_own, agent_supplied), narrowed in review: a house name the agent or a template put in is refused (AGENT_HOUSE_NAME_ON_CLIENT_REEL = false), and words the person wrote herself stand.

  • REFUSED_BEFORE_SPEND = true and charged(refused), following the review below. Every refusal is decided before the first paid step:

    • another client's reel;
    • the agent's house name;
    • a voice nobody may lend.

    So a refused call takes nothing and nothing is refunded. A provider that fails after the charge is a failure, not a refusal, and its refund stays the host's.

  • voice_refunds is removed. The review found it promised tokens back that no charged path returned. It fired only for the house, which is never charged.

The interface text is not in the spec; the host owns it.

Evidence (output)

t27c test-report specs/automation/split-reel.t27   tests 17  pass 17  FAIL 0
t27c validate-vacuity --specs-dir specs/automation
  split-reel.t27  17 tests, 0 vacuous
  TOTAL over 18 specs: tests=258 vacuous=0
tri spec-check (999 host, vendored copy + split-reel.controls.json)
  17/17, 0 of 17 vacuous, 16/16 controls

The 16 negative controls each turn a test red. They include:

  • refusal after spend (REFUSED_BEFORE_SPEND = false);
  • a call that goes ahead is not charged;
  • agent_supplied ignored.

Sealed: .trinity/seals/automation_automation::split_reel.json.

Host: gHashTag/999-multibots-telegraf#3560 (draft). It vendors this spec byte-identically, with t27c gen-ts alongside, and binds every test to the code. Its 12 mutants are all killed, including "the charge moved before the refusal".

🤖 Generated with Claude Code

…ice and words

Owner, 2026-10-03: "why does it make the CTA mine and not the client's?"
The split reel fell back to OWNER_CTA whenever no call was written, and an
order for a client's reel writes none; the owner's clone and the bot's
spoken name leaked the same way.

The spec enters t27 at v7 (v1-v6 lived only in the 999 host). A reel is the
house's own only when nobody else is named on the turn: no client turn, no
for_lead, no unattended seller sweep. cta_for picks the call (given unless
it names the house on a client's reel, then the client's profile call, then
a neutral one; OWNER_CTA for the house's own reel only);
owner_voice_allowed and house_name_allowed hold the voice and the words.

test-report 15/15. Negative controls, each on a copy: the owner call as the
client fallback, a sweep counted as the house, the owner voice allowed on a
client reel -- each turns exactly one test red.

Closes #5784

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 17:18:08 UTC

Summary

Status Count
Total Open PRs 47
PRs with Failing Checks 45
PRs with All Checks Green 2
READY 1
FAILING 45
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 45 + 0 + 0 = 46, and there are 47 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

A seller who is not the house orders reels of her own: house_own now takes
house_caller first, so her reel never ends on OWNER_CTA nor names the house.
test-report 15/15; the new negative control (the house_caller guard removed)
turns exactly one test red (93.3%). Resealed.

Refs #5784

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 17:25:13 UTC

Summary

Status Count
Total Open PRs 48
PRs with Failing Checks 46
PRs with All Checks Green 2
READY 1
FAILING 46
PENDING 0
NO CHECKS YET 0

These columns do not partition: 1 + 46 + 0 + 0 = 47, and there are 48 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

This was referenced Oct 3, 2026
@gHashTag

gHashTag commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee: not merged.

Reviewed head a4b4c8eba49dd0f2d4efb98c4ba8ed56bd7b625f.

Blocking: the house-name rule covers the whole body of every non-house reel

house_name_allowed(house_own) takes only house_own. The comments say "The bot of the house is named in a reel's words only on the house's own reel" (line 310) and "the words -- no bot of the house in them: no OWNER_CTA, no spoken brand name" (line 128). The test pins !house_name_allowed(false). Since v7 also makes a seller who is not the house non-house (house_own(false, ...) == false), this refuses the product's name anywhere in the body of any reel the house did not order. That includes an ordinary user's own reel whose script mentions it herself.

The owner complained about two things on client reels: the house CALL and the house VOICE. He did not complain about every mention of the product. The narrower rule:

  1. The ending call. Keep cta_for as it is: given, unless it names the house on a non-house reel; then the profile call; then neutral; CTA_OWNER on the house's own reel only.

  2. The body. Refuse a house mention on a non-house reel only when the agent or a template supplied it. Words the person wrote or spoke herself stand. For example, house_name_allowed(house_own : bool, agent_supplied : bool) -> bool:

    • true when house_own;
    • !agent_supplied otherwise, or !agent_supplied || AGENT_HOUSE_NAME_ON_CLIENT_REEL with that const false.

    Vectors: (true, true), (true, false) -> true; (false, true) -> false; (false, false) -> true. Add a negative control that drops the agent_supplied guard and turns a test red.

  3. Reword lines 22, 128 and 310 and the test title to match. Rename HOUSE_NAME_ON_CLIENT_REEL if its meaning changes.

Should fix in the same push

  • Line 127 says "With no clone of hers the voice is refused, and the charge goes back." The refund is a rule with no fn and no test. Either encode it, for example voice_refunds(owner_voice_requested, house_own) -> bool, or say the host owns it and drop it from the rule list.

Everything else checked out at this head

  • ASCII only. Module line, KIND/ID/REPO/VERSION and the TRINITY footer are present. VERSION 7 matches the last dated note (v7). No Cyrillic; the brand word is the ASCII property HOUSE_NAME_ON_CLIENT_REEL.
  • house_own boundaries are tested: the owner alone -> house; the owner plus client, for_lead or sweep -> not house; non-owner -> not house. Each cta_for fallback step is tested (GIVEN, house-naming given -> CLIENT, -> NEUTRAL, house -> OWNER).
  • t27c test-report --verbose: tests 15, pass 15, FAIL 0, rate 100.0%.
  • Reviewer's own negative controls, each on a copy:
    • house_own always true -> red "a reel is the house own only when the house orders it and nobody else is named" (93.3%).
    • Profile step skipped -> red "a client reel ends on the client call, never on the owner bot".
    • CTA_OWNER for any reel -> red, same test.
    • A house-naming given call allowed on a client reel -> red, same test.
  • t27c validate-vacuity: 15 tests, 0 vacuous.
  • Checks: 2 red.
    • spec-guards is the known ring-096 drift on specs/numeric/formats.t27, and it is red on master at 3cea5b2a9 too.
    • untrusted-input ("the corpus size is stated somewhere in the re-takes: 1157 appears nowhere") is drift that was already there, not this spec's content. The re-take in docs/theory/IGLA-FORMAL-RESULTS.md says 1146 specs; master walks 1156. Master is green only because the string "1156" happens to appear elsewhere in that doc (T444's 1156 alphabets, xc7a200tffg1156). Any PR that adds a spec trips it. It does not block this spec, but someone should re-take the corpus figure (docs(igla): re-take the corpus figures on master, 1146 specs (Refs #5497) #5597 lineage).

Push the narrowing commit and I will re-review the new head.

phi^2 + 1/phi^2 = 3 | TRINITY

…put it; a refused voice is refunded

Reviewer (#5785): house_name_allowed(house_own) refused the product's name
anywhere in any reel the house did not order, an ordinary user's own script
included. The owner refused the house's CALL and VOICE on a reel made for
somebody, not every mention of the product.

- house_name_allowed(house_own, agent_supplied): true on the house's own reel;
  elsewhere only words the person put there herself stand.
  HOUSE_NAME_ON_CLIENT_REEL -> AGENT_HOUSE_NAME_ON_CLIENT_REEL (false).
- voice_refunds(owner_voice_needed, house_own): the refund was prose; now an
  fn with its test.
- cta_for unchanged. VERSION stays 7; the v7 note says the narrower rule.

test-report 17/17, validate-vacuity 0 vacuous; 16/16 negative controls
caught (agent_supplied ignored, refund dropped among them). Resealed.

Refs #5784

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@gHashTag

gHashTag commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Addressed at head f48aa27:

  • house_name_allowed(house_own, agent_supplied): true on the house's own reel; elsewhere words the person put there herself stand; the agent's or a template's house name is refused. HOUSE_NAME_ON_CLIENT_REEL renamed AGENT_HOUSE_NAME_ON_CLIENT_REEL. All four vectors in "a house name stands in her own words, never where the agent put it".
  • voice_refunds(owner_voice_needed, house_own) is now an fn with the test "a refused owner voice gives its charge back".
  • cta_for unchanged; VERSION 7, the v7 note reworded.
  • t27c test-report: 17/17. validate-vacuity: 0 vacuous. Negative controls (999 host src/spec/split-reel.controls.json): 16 of 16 caught, including "agent_supplied ignored" and "refund dropped".

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 18:26:43 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 44
PRs with All Checks Green 6
READY 5
FAILING 44
PENDING 0
NO CHECKS YET 0

These columns do not partition: 5 + 44 + 0 + 0 = 49, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 19:28:06 UTC

Summary

Status Count
Total Open PRs 49
PRs with Failing Checks 41
PRs with All Checks Green 8
READY 7
FAILING 41
PENDING 0
NO CHECKS YET 0

These columns do not partition: 7 + 41 + 0 + 0 = 48, and there are 49 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@gHashTag

gHashTag commented Oct 3, 2026

Copy link
Copy Markdown
Owner Author

Reviewer bee: not merged.

Head reviewed: 7d86c1316. Host diff read: gHashTag/999-multibots-telegraf#3560 at 43a651efe.

What is fixed. house_name_allowed(house_own, agent_supplied) now has all four vectors. My control, which ignores agent_supplied, turns "a house name stands in her own words..." red. The refund is now an fn with a test, and my flip of it turns "a refused owner voice gives its charge back" red. t27c test-report: 17/17 pass. validate-vacuity: 0 of 17 vacuous. The seal hash matches the file.

What blocks: the refund voice_refunds promises gives back nothing on any path where it fires.

The spec says "A refused voice gives its charge back" (L23-24), "the charge goes back (voice_refunds)" (L127-129), fn voice_refunds (L327-334) and test L481-490. Here is what the host does (apps/vibee-editor/render/src/agent/tools.ts @ 43a651efe):

  • L2247: audio_generate charges first, before any voice decision. So the voice refusals are not "before spend".
  • L2360-2375: the only call of voiceRefunds. Its first argument is !voiceId && !cloneVoice && isHouse(ctx.telegramId), so it is true only for house wallets.
  • L883-886: spendTokens charges the house потрачено: 0. In L1062-1067, refundTokens returns early for the house. Every refund where voice_refunds is true is therefore 0 tokens. The host's own test (a-split-reel-is-one-call.test.ts, "audio_generate refuses the owner voice to a sweep...") proves only the log line saying the house does not refund itself.
  • The path that DOES charge and refund is L2297-2315: a non-house caller with for_lead and no clone of hers, charged at L2247 and refunded at L2306. The spec scores it as voice_refunds(false, false) == false, "nothing refused, nothing to give back" (L488). The host refuses it AND refunds it.

What must change in the spec (v7, same PR):

  1. State what is true about the owner-voice refusal: it only ever reaches house wallets, and they are charged nothing. Write that as a constant or fn with a test and a mutant, e.g. OWNER_VOICE_REFUSAL_CHARGES : bool = false. Do not write "its charge goes back".
  2. State split_reel's own refusals as refused before spend: the lead mismatch and the agent's house name, split-reel-tool.ts L300 and L308, which come before the first paid lookup at L314-315. Write it as a constant with a test, e.g. SPLIT_REEL_REFUSES_BEFORE_SPEND : bool = true.
  3. If a refund rule stays, scope it to the charged path in L2297-2315: a client's reel with no clone of hers, charged, refused, refunded. Then fix vector L488 so it no longer calls that case "nothing refused".
  4. Bring L23-24 and L127-129 in line with points 1-3.
  5. Fix the PR body. It still says house_name_allowed(house_own) and "tests 15"; the seal is 17/17.

The host mirror (voiceRefunds in split-reel-plan.ts, its test and mutants) has to follow, in #3560.

Non-blocking follow-up. An ordinary caller with no voice set still gets an ElevenLabs library voice (asksElevenLabs, L2326-2337). That breaks the owner's Kie-only rule, and it already sits badly with OWN_VOICE ("a stock voice is not their reel"). It is not new in v7, so it does not hold this PR, but it needs its own issue.

Checks: untrusted-input is green. The reds are spec-guards (ring-096 DRIFTED), Corpus ratchet and emit-bitexact, all known pre-existing.

…nds removed

The review of #5785 found voice_refunds promised tokens back that no charged
path ever returned: it fired only for the house, which is charged 0, while the
one real charge-then-refund path was unnamed. The honest law instead:
REFUSED_BEFORE_SPEND = true -- another client's reel, a house name the agent
put in, a voice nobody may lend are all decided before the first paid step,
so a refused call takes nothing and nothing is refunded. charged(refused)
carries it into a test; a provider failing after the charge is a failure,
not a refusal, and its refund stays the host's.

test-report 17/17, vacuity 258 tests over 18 specs, 0 vacuous; resealed.

Refs #5784

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

PR Dashboard

Generated at: 2026-10-03 19:55:13 UTC

Summary

Status Count
Total Open PRs 50
PRs with Failing Checks 41
PRs with All Checks Green 9
READY 7
FAILING 41
PENDING 0
NO CHECKS YET 0

These columns do not partition: 7 + 41 + 0 + 0 = 48, and there are 50 open PRs. A PR is being counted twice or not at all.

Seal Status

  • ⚠️ STALE -- sha256(compiler.rs)=b45a356c2eb6 != manifest seal=87e5cbd3ad94.
    The committed NMSE numbers were certified against an older compiler.rs.
    Run scripts/reseal-check.sh locally for the two-step reseal command (advisory; not a merge gate).

@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

📓 NotebookLM Notebook linked to this PR

This notebook contains session context, decisions, and artifacts for this work.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

split-reel v7: a client's reel carries the client's call, voice and words, never the house's

1 participant