voyage/docs
Kjell Tore Guttormsen d2b6a696bd fix(cap): fail closed when the ledger cannot be READ, in both modules
An unreadable ledger returned 0 from countTurns in BOTH the primitive and
the hook, so a run whose ledger existed but could not be read (EISDIR,
EACCES, EIO) was handed the full budget again on every call - unbounded.
research-loop-cap.mjs argues against exactly that three lines above the
code that did it, and its missing-DIRECTORY case already failed closed.
The unreadable-FILE case now agrees with it.

Only ENOENT still counts as zero turns spent: that is the legitimate
first-turn state, and the reason this cannot just throw on any read
failure.

The hook no longer carries its own countTurns. It imports the primitive's
exported readLedger(), the same way it already resolves the data root
through resolveDataRoot() - a reader and a writer with private copies of
the counting rule is how a hook ends up enforcing a different bound than
the gate it backs. In scope + cannot count now exits 2 with a message
that says counting failed, not that the budget is spent.

Fail-closed stays scoped to the loop: a test pins that an unreadable
ledger in an OUT-of-scope session still exits 0, because a PreToolUse
hook that over-blocks bricks every session on the box.

Also dropped the existsSync pre-check before the read - readFileSync's
own ENOENT carries the same information without a second syscall that
can disagree with the read that follows it.

Review finding 5e1c6230f48ead38fa77cd8f4b06bfdc2b5b7bbf (MINOR).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LuGhWAbWyRFBFeemfhxoVv
2026-08-12 22:49:08 +02:00
..
eval-corpus feat(eval): SKAL-1·4b offline gold-scored output eval 2026-06-30 09:00:33 +02:00
agent-description-token-trim-brief.md docs(voyage): track agent-description token-trim brief (M4 input) 2026-06-26 20:15:34 +02:00
architecture.md fix(cap): fail closed when the ledger cannot be READ, in both modules 2026-08-12 22:49:08 +02:00
balance-backlog-plan.md chore(voyage): S34 — V30 economy-profile self-declares experimental (uncalibrated Jaccard floor) 2026-06-20 10:18:38 +02:00
cc-upgrade-2.1.181-decision-matrix.md docs(voyage): S20 — CC-04/T3 verified clean (research-agent MCP degradation under --strict-mcp-config) 2026-06-19 14:08:51 +02:00
claudemd-token-trim-brief.md docs(claude-md): trim CLAUDE.md to invariants (always-loaded token trim, S53) 2026-06-29 14:49:32 +02:00
command-modes.md fix(research-loop-cap): floor the turn cap before the guard, not after 2026-08-12 22:46:35 +02:00
deep-research-engine-brief.md docs(research): resolve deep-research-engine topic-1 (/deep-research trigging) 2026-06-30 10:39:03 +02:00
deep-research-engine-research.md docs(research): remove literal keyword tripping verify SC1 2026-08-12 20:29:35 +02:00
devils-advocate-plan.md docs(voyage): plan S14 devil's-advocate audit via Dynamic Workflow 2026-06-18 18:30:05 +02:00
devils-advocate-results.md docs(voyage): S22 — happy-path dogfood results (blind spot #1/#4 measured) 2026-06-19 20:53:21 +02:00
HANDOVER-CONTRACTS.md docs(voyage): fable-aware allowlist prose in contracts, architecture, templates, CLAUDE.md 2026-07-02 17:14:35 +02:00
observability.md docs(observability): document token-usage schema + main-context v1 scope 2026-06-26 14:47:24 +02:00
operations.md docs(voyage): add fable profile row and correct model-allowlist prose 2026-07-02 17:13:15 +02:00
profiles.md docs(voyage): add fable profile row and correct model-allowlist prose 2026-07-02 17:13:15 +02:00
S22-happy-path-dogfood.md docs(voyage): S27 — close version-skew (S22 defect #4) as no-op 2026-06-19 22:11:25 +02:00
SLDC-AI.pdf fix(cap): fail closed when the ledger cannot be READ, in both modules 2026-08-12 22:49:08 +02:00
spike-pretooluse-subagent-reach.md feat(trekresearch): wire Phase 5 scope marker so the cap hook enforces 2026-08-12 20:55:55 +02:00
storm-measurement.md fix(storm-measure): restore the pre-registered OR decision rule 2026-08-12 22:15:07 +02:00
subagent-delegation-audit.md feat(voyage)!: bulk content rewrite ultra -> voyage/trek prose [skip-docs] 2026-05-05 15:08:20 +02:00
T1-cc26-delegated-orchestration.md docs(voyage): S7 (W1/CC-26 gate) — T1 feasibility probe + measurement design 2026-06-18 13:21:09 +02:00
T1-synthesis-poc-results.md feat(voyage): S12 — NW3 synthesis-agent built + measured → declined per measurement [skip-docs] 2026-06-18 17:58:39 +02:00
T2-bakeoff-results.md fix(voyage): S21 — close IPv4-mapped IPv6 SSRF bypass + security/safety audit (blind spot #2) 2026-06-19 20:02:56 +02:00
T2-cc27-workflow-substrate.md docs(voyage): S8 (W1/CC-27 gate) — T2 Workflow-substrate probe + measurement design 2026-06-18 13:34:05 +02:00
voyage-vs-cc-balance-analysis.md chore(voyage): S34 — V30 economy-profile self-declares experimental (uncalibrated Jaccard floor) 2026-06-20 10:18:38 +02:00
voyage-vs-cc-balance-charter.md docs(voyage): add Voyage-vs-CC balance-analysis charter (next-session launch spec) 2026-06-20 06:34:40 +02:00
W1-narrow-wins-plan.md docs(voyage): plan W1 narrow-wins implementation (NW1/NW2/NW3, S9->) 2026-06-18 13:41:20 +02:00