foundry · local-first · oracle · foundry-hal · trivium-forge · what is left · 2026-09-29

Foundry Build Ledger

Updated 2026-09-29 11:54 UTC from GitHub. 8 components in your words, each broken into the parts that produce it, in the owner's order. Yellow edge = the part a builder picks up now. Red edge = it moves only when you act. Finished work is folded away at the bottom.

45 open
Moves on Peter5 parts
Moves on the builder22 parts
Moves on Claude4 parts
With Gage / Astra / Grok7 parts

Eight components

Your level is the component; mine is the part. Bars show parts landed out of parts listed. "Next" is the one part that unblocks the most.

1 · Speed

A plain chat turn on the live route answers fast, every time. Prompt length is the latency, not thinking: a one-word greeting was carrying 33 tool schemas and 7.8k prompt tokens. Speed is a merge gate of Class A standing; new-tool work halts while it is red.

Your rule · 9/15 and 9/18Always keep speed a high priority. Core as light as possible; when a tool is called the wire carries core plus that one schema and everything else is dropped. Every PR states its cost to the turn.
No.PartStateRefNext moveDone when
1.1Tiered tools: core on the wire, the rest behind open_toolsCategories listed as one-line index entries; a category loads only when opened.done#926Claude measureCore schema count and bytes reported; a chat turn under 4k prompt tokens.
1.2Drop everything but core + the called schema for the rest of the turnYour 9/18 evening ruling. Index lines go too once a tool is open; reset to core + index between turns.done#847 B.3BuilderDeployed 9/20 evening (#956 line).
1.3Zero prefix-cache hits on the Sparks routeThe core is stable at the front so the cache should hit; it does not. --prefix-match-unit 8 was a no-op.done#927Claude + BuilderWarm-turn prefill drops and the server counter shows hits.
1.4Snappy-turn SLO as the merge gateA plain chat turn on the live route, timed in CI against the lane budget. Red blocks the merge.merged#870 #1023 #1204BuilderA PR that adds latency to Hal's chat turn fails its check.
1.5Reply first, work in the backgroundA drafting question gets an immediate answer while the tools run as a job.done#956Claude deployDeployed 9/20 evening; reply-first live on both lanes.
1.6Standing bakeoff: Foundry vs DeepSeek harness vs Hermesdone#872—Same tasks, same endpoint; if Foundry is 5× slower the harness is the bug.
1.7Long Telegram reply splits; a streamed turn shows oncedone#965Claude deployDeployed 9/20 evening.
1.8Thinking off on chat; keepalive; streaming; self-knowledge cachedone#809 #867—Landed 9/15.
1.9Fast front + specialist lanes as toolsOne fast Hal in front; engineering, accounting and design as specialist lanes with their own models.live#624—Specialist registry, picker and delegation on main.
1.10Gage 4.7 audit · Oracle greeting sends 37 schemas, 9,063 tokens, 3.7 s before a wordMerged #1015; deployed 9/27 14:50 (Oracle greeting 37 → 4 schemas).live#1015BuilderAn Oracle greeting carries the same 4 core schemas Hal does; measured on the Sparks route.
1.11Gage 4.7 audit · Thinking at the server default eats the output cap and returns nothinglive#1198 #1205BuilderChat routes force thinking off; a greeting returns text every time.
1.12Gage 4.7 audit · Hal greeting is 4,893 prompt tokens: a core file and a page of memory it never usesnext#1199 #1207BuilderGreeting under 3k tokens; the cut blocks named and lazy-loaded.
1.13Gage 4.7 audit · Prefix cache is on but a repeated chat prompt is not fasterlive#1200 #1206 #1022Builder · Claude measureSecond identical greeting measurably faster than the first, or the reason written down.

3 · Last mile

Every ability that is built and green but not yet on the runtime. Three audits found the same thing: capability built in one PR, armed in a second PR that never opened. This component is the list of second PRs, records and deploys. It is the shortest road to a more capable Hal, and most of it moves on you.

Your rule · 9/17Report exceptions only. So this table is the exception list: each row is one thing standing between a merged PR and a live lane.
No.PartStateRefNext moveDone when
3.1Schedule tools: register, grant Foundry-wide, fire from each lane's daemonOracle's four report times are launchd jobs I install. This lets any lane set its own. Oracle asked for it again today (oracle#159).done#941PeterDeployed 9/20 evening.
3.2Deploy the merged speed workReply-first (#956), tiered tools (#926), long-reply split (#965) are on main and not on the runtime. Merge hold lifts when #941 lands.done#956 #926 #965ClaudeRuntime on 81725e0e, 9/21.
3.3Grant the coms bus: Hal, Oracle and the builder message each otherInbox, delivery, receipts and ratchet exist; all three lanes hold the bus tools and both flags ship in the Hal and Oracle daemon env templates (#1044, #1300, #1352), deployed 9/27 14:50. Class B since #1151 (9/25): no owner record. Left: the proof turn (Oracle asks the builder for something) is not yet observed; then #833's intake loop lands a chat ask as a job.next#835 #1352Builder PROracle asks the builder for something and it lands as a job.
3.4Oracle engine gate binds to merged main; one deploy script; hourly pin checkEnds the record-per-engine-bump churn you ruled out this morning.done#967PeterMerged #967 + one deploy script; engine at 8c25d293.
3.5Scout gets live X: Grok /responses with x_search + web_searchA Foundry-wide ability behind a route flag; add the grok-search route to the operator env at deploy.done#968PeterMerged #968; grok-search route live 9/20.
3.6Standing preferences: an owner-set file loaded with the core context every turnin review#985Gage"Never sign off with a summary" sticks across sessions on every adult lane.
3.7Email tool family: each agent reads and sends from its own mailboxSends stay behind the hard stop.in review#959Gage then PeterHal reads a vendor reply from his own inbox.
3.8Every agent's keychain unlocks itself at bootProved 9/27 17:35: GUI restart, nobody logged in; unlock 86 s after boot, claude -p answered, a seat started a run. Boot proof script on main (local-first #49).donelocal-first#37 local-first#45 local-first#49Claude · Peter yes on halLive for foundry, grok, codex; not done for claude until a boot brings Claude Code up with nobody at the keyboard; hal is Peter's login (left alone).
3.9Rotate the printed secretsHal Telegram token (8/16), Anvil Telegram token + S128 key (9/03), Cerebras key (9/15), Cloudflare + Hostinger passwords (9/14).yours—PeterEach one rotated; I stop reminding.
3.10Builder route + gate livesparks-builder route READY, gate recorded, dry-run proven.done#837 #854—Done 9/20.
3.11Live board on jobs.egyed.ioLive since 9/22: the Studio renders and deploys the page every 15 min; the source moves with local-first #41.live#975ClaudePage renders every 15 min from ledger/parts.yaml and GitHub state.
3.12Gage 4.7 audit · Anvil's mission loop has no deadline and its lock is a lieDeadline wrapper on main (local-first #46, #47). Left: point Anvil's mission loop at it — a Hermes-side change on the mini.nextlocal-first#45AnvilA cycle past its budget is killed and journaled; measured 85 min past a 30-min lock.
3.13Gage 4.7 audit · Class A approval dies on a rebase that changed no bytesMerged #1208; live in the gate since 9/27.live#1201 #1208Builder · GageApproval binds to the tree hash; a no-byte rebase keeps the stamp and the record. 30 of the last 40 merges were Class A.
3.14Gage 4.7 audit · Oracle pin drift can sit for hours; two Colima VMs for two small listenersPin check merged (#1211, #1353, #1368) and installable without an engine deploy. Waiting on your `go 3.14` to install the hourly LaunchDaemon (a Colima VM on the Studio).yours#1203 #1211BuilderPin checker alerts within the hour; one VM.
3.15Post-close review carries the engine's numbersopenoracle#169 oracle#170 oracle#176Builder (oracle#169)The engine writes the review block at the daily close and the cadence renders it. Not a clock bug: #993 closed, live plist restored.
3.16Lead Auditor seat pluggable: two App identities, runner swappable (Astra in while Gage is out of credits)Merged #1388 and live 9/27 15:48: Astra reviews from his own Codex App, one slot. Follow-up: the accepted set in a data file so a local model can take the seat.next#1388 #1405builderA third auditor identity is a data change; the loop survives a reboot (#1404)
3.17Route watchdog + Sparks self-start after a power cycle9/27: both Sparks hung 10:35–17:25 unnoticed. Boxes have no status lights; the watchdog is also your 'is it on' signal.next#1403 #1404builderA dead route pings you within 5 min; a killed engine restarts by itself; Astra's loop is a LaunchDaemon

7 · Drafting

Foundry drafts by writing a sheet script on a shared kit — never a blank canvas. One house style and a quality floor on every sheet; the old fixed forms retire once the canvas beats them. Plan: docs/plans/2026-09-24-drafting-canvas.md (#1104).

Your rule · 9/23 and 9/24I would like a base style and quality that we always produce. Drafting first on every builder; build for Foundry as a whole.
No.PartStateRefNext moveDone when
7.1Gate re-run: name the missing field, deliver the sheet already made, 'ok' never redrawsopen#1101 #1100OpusThe three gate turns rerun in the sandbox: no false 'couldn't complete', no redraw on 'ok'.
7.2Gate re-run: one dimension each, no stray dimension, no overlap, one sheet for a double gateopen#1102 #1100OMPBoth leaf widths and the gap dimensioned once on one sheet; no overlap.
7.3Model code runs on the Studio (canvas C0)The lane's venv sat under the denied ~/runtime tree, so every workspace_run was refused.merged#1107 #1103Opusworkspace_run python 'print(1)' succeeds as the runtime account; secrets under ~/runtime still unreadable.
7.4Deploy 7.1–7.3 to Hallive#1101 #1102 #1107Claude · Peter 'deploy'Live Hal on the merged head; the gate conversation rerun passes.
7.5Canvas plan signed offmerged#1104Astra · Gage · PeterAstra and Gage approve the exact head; owner approves.
7.6C1 + C1b: sheet kit and house standard (style fixed in code; required content per sheet type)live#1140Builder after 7.5A sheet built on the kit renders the house frame; style cannot be overridden.
7.7C3 + C4: pre-send check and view-conventions rulebooklive#1139Builder after 7.5Overlap, dimension-from-geometry and required-content checks block a bad sheet.
7.8C2: parametric two-leaf gate templatelive#1142Builder after 7.6A new gate is an inputs block; derived numbers printed and asserted.
7.9C5: drafting skill — memo → template → render → look → fix → deliverlive#1150Builder after 7.8The sandbox gate conversation produces a sheet that passes C3.
7.10C6: cloud model for new designs (Anthropic transport)yours—Peter: pick the credentialA new design turn runs on Opus 5.5; quick edits stay local.
7.11C7: the customer gate as a hidden level-5 exam caseopen—ClaudeThe nightly hunt scores it.
7.12C8: retire the forms (~15k lines deleted)open—BuilderCanvas passes every L1–L3 drafting case the forms pass, two nights running; one deletion PR.

8 · Training system

A nightly failure hunt: a sandboxed copy of each agent runs graded cases that climb in difficulty; every repeat break becomes a builder job; fixes are proven by the next night. Plan: docs/plans/2026-09-23-failure-hunt.md (#1061).

Your rule · 9/23Hundreds if not thousands of iterations of basic actions that increase in difficulty. Foundry-wide tool families, not agent names; led by a cloud model.
No.PartStateRefNext moveDone when
8.1Week-one build: nightly CI run, sandbox, Hammer's tools shared, grading, scheduler, filer, trial rundone#1079 #1080 #1082 #1083 #1084 #1085 #1086OpusAll seven merged.
8.2Curriculum: 800 cases across seven tool familiesdone#1081TeamMerged: 800 frozen cases across seven tool families.
8.3Nightly run live: drafting levels 1–3 at 22:30Nightly at 21:30 on the deployed runtime; same set, same difficulty until the fixes show.live—ClaudeFirst night's report read and its filed breaks triaged.
8.4Move the nightly glue into the repo (ops/studio36)open#1133 #1135BuilderThe LaunchDaemon and wrapper ship from main, not hand-installed.
8.5Morning report to Peter on Telegramopen#1134 #1136BuilderOne short report at 6:30, skipped on quiet nights.
8.6Widen to every tool family: core turn, memory, schedules, research, investing, codingEvery family runs nightly (1,402 cases, rounds 1+2). Full run 9/26–27 graded and hand-triaged: findings + plan in #1387.live#1387BuilderEach family runs nightly at its open levels.
8.7Cloud lead: writes variations, plays you in long sessions, finds the causeyours—Peter: credential (same as 7.10)Level 4–5 sessions run nightly under the spend cap.
8.8Refine and teach-back: keep a prompt/tool/skill change only if the night improvesopen—Builder after 8.7One change kept on evidence, one rejected on evidence.
8.9Make the test honest: sandbox parity, grader misfires, answer keysOf 715 raw fails on 9/27, ~455 were the test's (sandbox one-blob scripts #1244, grader #1327, answer keys #1337, zero-call timeouts #1375). Astra's review on #1387 sets the shape: an integration subset on the real registry; all-attempt completion beside the honest rate; a fixed passing-control slice.next#1244 #1327 #1337 #1382 #1393 #1394builderTonight's number is true: a fail is Hal's or it is unscored, never the sandbox's
8.10Kernel breaks from the 9/27 runMoney path #1374 (PR #1383, your record on c7329f5), guard regression #1242 (#1370), unasked writes #1328, wrong-slot dimensions #1331, remember field #1369, bend web #1371, stray-arg refusal #1372/#1392, assembly mark #1373 (merged #1391).next#1374 #1242 #1328 #1331 #1369 #1371 #1372 #1373builderEach named case passes on a replay; the 9/28 morning report shows it
8.11Held-out variants of the failed cases (same dial, new numbers and names)Your 9/27 ask: the next test is not harder, but we do not build to it. Variants run as a separate slice, grouped by template.open—builderA held-out slice runs one night a week and its rate tracks the main set

2 · Capabilities

A Foundry agent is fully capable the moment it is spun up: shell, files, brokered network, helpers that persist, skills that load, memory that writes, tool results that survive a turn. Opt-out per agent later. Money, sends and credentials stay the only gates.

Your rule · 9/17 and 9/18Tear down the limitations… reimplement once we have a really usable product. When we spin up a foundry agent, I need it to be fully capable from the start by default.
No.PartStateRefNext moveDone when
2.1Default-on lanes: kernel posture and the profile resolverA new lane manifest gets every registered tool unless its forbidden: block says otherwise.merged#909 #936Gage then PeterA lane file with no grants list prints every tool at start-up.
2.2A · workspace_run works on the live hostThe OS sandbox refused every command since 9/13. Probe fix #913; the exec path was measured on the live host (#898, foundry-hal#7) and the TurnLoop receipt is now a regression test. The live Hal turn is still open.open#890 foundry-hal#7 #1107BuilderHal runs a script in his workspace and gets the output back.
2.3B · Skill loader: load and keep procedures before filing a ticketopen#962GagePart B never merged (#962, six Gage rounds). Re-scope or close.
2.4C · Helpers persistA script the agent wrote and that worked is callable next time.done#890 CBuilderMerged #978, deployed 9/21.
2.5D · durable_memory_write granted to the front lanesdone#890 DBuilder · Peter recordMerged #981, deployed 9/21 (hal v7 / oracle v6).
2.6E · Brokered egress for the workspacedone#890 EBuilderMerged #982, deployed 9/21.
2.7F · One capability envelope, wired to a lanedone#890 FBuilderMerged #980, deployed 9/21.
2.8G · Rewrite the self-model sentenceStop teaching "a capability the lane does not grant is silence".done#890 GBuilderMerged #976, deployed 9/21.
2.9H · stuck.py improvises before it escalatesWrite a helper and try again before asking a bigger brain.done#890 HBuilderMerged #976, deployed 9/21.
2.10N · Tool results survive into the next turnBounded rows on the trace message; +325 prompt tokens, +0.16 s p50, per-lane dial.merged#933Peter Class AHal quotes yesterday's tool result without re-running the tool.
2.11Host file search: host_find / host_readRead-only over what the foundry account sees; secret paths refused.merged#836 #1026 #1128Builder"Find anything about X on this machine" returns the file.
2.12Skills: mine repeats, promote at 10 days, retire with a tombstonemerged#672 #702—Nothing uses a mined skill yet; that is 2.3.
2.13Memory seeded from OpenClaw, 5,080 lines livemerged#843 #845 #848 #858—Landed 9/15.
2.14Gage 4.7 audit · Engineer, finance and coding are not three running agentsMerged #1016; deployed 9/27 14:50. Calculators granted on Hal's lane.next#1016BuilderThe calculators are granted, the books are registered, and each role answers on its own lane.
2.15Gage 4.7 audit · A request does not become a tool in 90 minutesopen#992Anvil · Hammerfoundry-hal #15 (open since 9/20) lands as a tool; the intake loop (4.2) closes the gap by itself.
2.16Gage 4.7 audit · The model is still told a closed worldMerged #1212; deployed 9/27 14:50.next#1202 #1212BuilderSelf-knowledge says what the lane holds and how to get more, never what it cannot do; verified on a live turn.

4 · Coding agent

Anvil moves off Hermes and onto Foundry: his brain on the Sparks route, a loop that turns an accepted request into a job by itself, his own Telegram seat, and one shadow job to prove it. Hermes stays the fallback until two Foundry-built PRs merge clean.

Your rule · 9/20Make sure the abilities we create for the builder are foundry wide abilities. Always keep speed a high priority. No builder-only branch of the harness; each PR states cost to the turn.
No.PartStateRefNext moveDone when
4.17.08 · A real brain on the builder laneReadback: builder-foundry brain route sparks-builder → qwen38-flash-next-sparks: READY.done#837—Proven 9/20 11:4x with the gate recorded.
4.27.09 · Intake loop: a request issue becomes a job by itselfAny lane's own-repo [request] issue, not just the builder's. The 90-minute rule.open#833 #984AnvilAnvil picked it up 9/21 06:35.
4.34.08 · The bus grantSame part as 3.3; it sits in the builder's order because the builder is the first consumer.open#835Anvil PRA request travels agent → builder with no relay.
4.47.10 · Anvil's own Telegram seat on Foundry, with the envelopewaiting#834AnvilParked 9/21: Hammer gets the Telegram lane instead if wanted.
4.57.11 · Shadow job: one issue on both buildersopen#838Anvil + Claude compareTwo Foundry-built PRs merge and you say "stop building on Hermes".
4.67.12 · What the builder loses leaving Hermes: shell, memory, watcherWiden only for what the shadow job proves he needs.open#839AnvilThe shadow job runs without a tool he does not have.
4.7Mission-cycle guard: every cycle writes a ledger lineHermes-side hygiene while he is still there.done#891GageNo unreviewed merge and no silent cycle.
4.8Hammer: a second builder seat on Foundry, run beside AnvilPlan change filed 9/21 (#994): Anvil stays as is. The blinc-hammer GitHub App exists (9/21).next#994Builder wiringBoth builders pull one queue for 2 weeks or 20 jobs; one table; you pick the harness.

5 · Forge

The kids out-earned the eleven-recipe catalog in two weeks. Crafting Overhaul Map v1 is signed: a full-width Smithy around the tutor, metal as tier, shape as a craft-time choice, then depth and learning in the temper step. Build order S0 → S1 → S3, then temper and grades, then smith level and runes.

Your rule · 9/20Signed Map v1 with three yeses, plus: kids want more things to craft: swords, tools, weapons, shields. Viking set is the product; the 3-boy/6-girl split stays.
No.PartStateRefNext moveDone when
5.1S0 · The slot SmithyStructural goal picker, per-slot chain, full-width forge page. Gage approved round 1; Astra's blocker fixed in round 2.donetrivium-forge#297Claude mergeMerged 9/20.
5.2S1 · Metal as a compositor input, the cape row, the forward-upgrade ruledonetrivium-forge#299Claude merge after S0Merged 9/21.
5.3S3 · Forge scene and strike FX behind the Smithy (CSS/SVG only)donetrivium-forge#300Claude merge after S1Merged 9/21.
5.4Deploy S0–S3 to the minidonemini deploy procedureClaudeDeployed 9/21 morning; public path 200.
5.5Art wave: metal layers, cape, sword, spear, kite and tower shields, nasal helmDispatched to Grok on #294; no reply yet. Buzz relay was down before the reboot; it is up now.waitingtrivium-forge#294GrokLayered PNGs committed and referenced by the compositor.
5.6S2 · Temper step and quality gradesThree live-plan questions in the metal's discipline; misses never cost ingots; stars from mastery, server-graded.yoursMap v1 §CPeterGage and Astra both: a finish from lesson questions is a quiz under Map §1. Hold, or accept the seam until S4 with one record on #301.
5.7S4 · Smith level upgrades the forge scene; runes and named gearopenMap v1 §D–E trivium-forge#317ClaudeLevel 3 smith sees a bigger forge; a quest line names a sword.
5.8Two open advisoriesCross-slot banner order; full-set portraits ignore metal cuts (Astra).mergedtrivium-forge#304Astra · ClaudeBoth folded into S1 or filed as their own parts.
5.9Gage 4.7 audit · A failed drill still mints an ingot, and the screen never says somergedtrivium-forge#314 trivium-forge#318BuilderA failed drill mints nothing and says why.
5.10Gage 4.7 audit · A lesson check waits up to 60 s on the model after the grade is savednexttrivium-forge#305BuilderGrade shows at once; the model's note arrives when it arrives.
5.11Gage 4.7 audit · Smithy discards a finished reply, then loads an 800×1280 portrait into an 11-rem frameopentrivium-forge#305BuilderOne reply used; portrait sized to the frame.
5.12Gage 4.7 audit · History: 20 of 50 stories drafted; keep-forging has no daily capopentrivium-forge#305Grok stories · Builder30 more stories drafted; a per-day cap.

6 · Oracle on Coinbase

About $600 of BTC plus $500 of USDC you added 9/20 in your Default portfolio is Oracle's live-test money before real money. Oracle places the orders, never the builder. BTC is the savings account; USD and alts are working capital. At roughly 0.9% a side, a round trip costs about 2%, so the monitor's default action is to do nothing. Rails proposed: 25% per position, 10% daily stop, 20% weekly kill, every fill journaled and one Telegram line.

Your rule · 9/20Turn it on and turn him free. Grow it any way; convert half to all of the BTC to USD as his first act; the LLC account is the real-money phase, and the 50/50 hardware deal starts there.
No.PartStateRefNext moveDone when
6.1Oracle's keys back in the rebuilt foundry keychainCoinbase CDP (new key, also in the CLI), Alpaca paper and live pairs, FRED, Telegram. Each verified against its API 17:20. Live pair is stored only; the engine still refuses live writes.donelocal-first #37—Landed 9/20 17:20. Paper equity reads; live account reads $0.
6.2Read-only Coinbase Advanced Trade driver: market kinds, provider switch, trading gateYour record is posted at head cc904eb7; Gage re-stamps after the reboot.doneoracle#160Gage then Claude merge + syncMerged #160 9/20; engine synced.
6.3Coinbase market kinds (cb_*) on the oracle-voice argv allowlistdone#970GageMerged #970 9/21.
6.4Execution: Oracle's order path, rails, first act, sleeves, gateRecord line handed at cb20f58d. First real order path, so Class A.doneoracle#163 oracle#161PeterMerged #163 9/21 at your record.
6.5Your word: trading_enabled: trueOracle's first act converts half to all of the BTC to USD; a done state needs a confirmed fill.done—PeterYour word 05:06 MST 9/21; flag committed as #164. A fill waits on a coinbase_fill record.
6.6Crypto 24/7 monitor + local Jev in the loopTeam brainstorm: Claude, Grok, Astra lenses in; OMP pending. Trend state, volatility regime and "when not to act" per pair from one WebSocket.openoracle#162 oracle#178Claude fold into one mapOne map for your signature, then a builder PR.
6.7Astra: BTC-first momentum research and the evaluation contractResearch-only branch astra/crypto-momentum-research-20260920: strategy spec, offline detector and cost lab, tests. Compares the Jev API against the local model. Not a live activation.researchREADME @ b5447abeAstraA strategy with a backtest and a fee model, filed as a proposal Oracle can run as a sleeve.
6.8Local Jev: Laya behind the decision seam, in shadow beside TypeSafe23 ms per choice; zero-shot weak; fine-tune on the shadow-route rows is part D. Jev never places, cancels or flattens.Class B#969 #964GageShadow log shows Laya and TypeSafe side by side on real ticks.
6.9Oracle's own requests: Coinbase connector, schedulerFiled by Oracle on his repo today; answered by 6.2/6.4 and 3.1.doneoracle#158 oracle#159OMP · GageOMP's #986 (foundry) merged 9/22: read kinds live on the lane.
6.10Coinbase CLI live, Default portfolio readdone9/20—Landed this morning; key re-import is 6.1.
6.11Gage 4.7 audit · The 10% daily and 20% weekly halts block buys but never sellnextoracle#167 oracle#173OMPOn a halt the trend and swing positions are sold; the week baseline is never replaced with a lower equity.
6.12Gage 4.7 audit · first_act.done, trend, and swing_rebalanced_on flip without a confirmed fillnextoracle#167 oracle#173OMPAll three flip only on a confirmed fill; a lost response retries under the same client id; a response that cannot be read flips nothing.
6.13Gage 4.7 audit · Savings BTC in Default blocks the whole trend sleeve at the 25% railOwner ruled 9/22: no position cap on BTC (#174) instead of removing BTC-USD from the trend list.mergedoracle#174PeterNo position cap on BTC-USD.
6.15Gage 4.7 audit · an unreadable coinbase_exec.json sells half the BTC againA missing or half-written state file reads as a fresh book, so the first act fires a second sale nobody ordered.nextoracle#167OMPIf coinbase_exec.json exists and does not parse: place no order and run no first act.
6.14$500 USDC added to the test bookdone9/20—Landed 9/20; book is ~$300 BTC + ~$300 USD + 500 USDC.

Moves only when you act

11 need you → owner page

Failure hunt

Breaks are the failure-hunt issues on foundry, grouped by the family named in the title. In flight = an open PR names the issue. Pass = last night's whole-workflow pass rate for that family. Fixes = failure-hunt PRs merged in the last day.

Latest run

No run data.

Breaks per family

59 open · 17 with a fix in flight · 42 fixed

FamilyOpenIn flightFixedPassFixes in flight
coding842·#1452 #1483 #1484
core_turn3·2··
drafting9·4··
investing2····
memory54··#1428 #1443 #1446
research4····
schedules5·3··
cross-family324·#1266 #1275 #1276
setup/grader20727·#1266 #1383 #1428 #1443 #1446 #1448 #1483
All591742··

Merged fixes, last 24 h

40 of 68 shown, newest first. Builder = the seat prefix on the PR title.

PRBuilderFixMerged
#1485opus3Sparks: watchdog sets the serve container's memory ceiling09-29 11:17
#1488opus3failure hunt: a probe search quoting a number the case's pages gave finds the page09-29 11:16
#1489opusfailure hunt: a page the probe search listed reads as its listing09-29 11:16
#1487—Failure hunt: hold when the model route is down, mark route_unreachable, re-queue (#1486)09-29 11:01
#1416opus2failure hunt: pin the #1315 frozen cases' reads on the probe sandbox09-29 09:52
#1463opus3hal-core: ask on a past or unclear reminder date; pin the prompt budget09-29 09:52
#1433opus3failure hunt: a report of a shut gate is not a refusal (#1318)09-29 08:50
#1438opus3grounding guard: keep a measured reply, cut only the unsupported number (#1242)09-29 08:49
#1441opus3failure hunt: an unscripted oracle_status answers as a quiet paper account09-29 08:48
#1442opus2failure hunt: a draft success scripted as a note draws for real (#1324)09-29 08:48
#1451opus3failure hunt: a draft scripted as ok with only prose draws for real09-29 08:48
#1406—board: 9/27 evening update — deployed parts live, 3.8 proved, new ops/training parts09-29 07:48
#1414oxalphadeliver_sheet: answer the turn record before the job check09-29 07:48
#1424opusschedule_set: test that a zone name also bounds until (#1316)09-29 07:48
#1431oxalphagrader: an empty recall plus a config/package obstacle is not a refusal09-29 07:47
#1457opus2failure hunt: grade a model route that never answered as a host fault09-29 07:47
#1462opusSay how far out a scheduled date lands so the model can ask (#1367)09-29 07:47
#1456opusfailure hunt: a re-sent edit the worktree rejects is not a duplicate effect (#1364)09-29 06:44
#1429ompdesign_sitting: read a file write as a writing ask, not a part (#1239)09-29 05:43
#1444opusfailure hunt: a remember answered already-saved is no effect; script the dedupe premises (#1329)09-29 05:43
#1482—failure-hunt: deploy main to the runtime before the nightly run (#1468)09-29 04:43
#1423opus3schedule_set: read a time in a named zone09-29 03:29
#1370opus3failure hunt: lock the R2-L4-03 read-of-an-edited-file case with a test (#1221)09-29 03:29
#1479—ops(sparks): watchdog — self-reset on wedge, health check, serve at boot09-29 03:01
#1401opus2draft_package: a drawn part's approval package is a package, not a note09-29 02:35
#1476opusFailure hunt: no night wall; HUNT_WALL_S is the only stop (#1468)09-29 02:34
#1481—snappy-turn: pin prompt_bytes_max to the measured 15078 (main red after #1410+#1392)09-29 02:34
#1392—kernel: refuse an unknown arg before any effect; drop it only for reads and drafts (#1387 s2)09-29 01:07
#1410ompdeliver_sheet: answer a call with no job from this turn's drawn sheet09-29 01:07
#1459opus3failure hunt: script the open order for o2-investing-R2-L1-03 (#1337)09-28 22:55
#1478opus3failure hunt 8.5: send the morning report when the run ends09-28 22:54
#1436oxalphafailure hunt: a drafting kit setup refusal is setup, not a session crash09-28 22:22
#1377opus3Grade declining a forbidden act as an answer, not a refusal09-28 21:50
#1475opus2Failure hunt: L4/L5 run last, one at a time09-28 21:49
#1439opus2failure hunt: a probe list note naming its jobs holds them on the sandbox scheduler09-28 21:18
#1400opus2failure hunt: an honest caveat on a dated or empty read is not a refusal (#1228)09-28 20:46
#1445opus3failure-hunt: real bend-sheet answer for omp-drafting-L1-03, reword o2-drafting-R2-L2-0109-28 20:46
#1458opusfailure hunt: script the open-order premise in o2-investing-R2-L1-03 (#1337)09-28 20:45
#1430opusfailure hunt: a drafts list meets its cap with that many rows or more09-28 20:13
#1473opus2failure-hunt: script real tool output for five round-1 coding cases (#1337)09-28 20:13

Broad audits

Whole-project audits, kept here until every finding is fixed or closed. A finding's state comes from the issue or PR that answers it; no ref means nobody has taken it yet. Part = the board row that carries it.

Speed of a live turn — Hal and Oracle

Gage Grok 4.7 · foundry#991 · filed 2026-09-21 · 1 of 10 findings closed

No.FindingStateRefPart
1Thinking is on unless the route says otherwise; a reply can spend its cap thinkingopen—1.11
2A repeated chat prompt does not hit the prefix cacheopen#1022 measures it1.13
3Oracle has no tool tiers: 37 schemas on every callmerged#10151.10
4A drawing ask pre-opens the whole drafting draweropen——
5The memory brief sends a 20-fact page on a greetingopen—1.12
6The lane core files repeat what the soul and self-knowledge already sayopen—1.12
7Reply-first is a second full prefill; ship finding 1 firstopen—1.11
8Self-knowledge can spend 3 s on GitHub before the model startsopen——
9web_read is serial, and each read may wait 25 sopen——
10A scout call blocks the parent turn for the whole searchopen——

Capability is half live — the model is still told the tool list is the limit

Gage Grok 4.7 · foundry#992 · filed 2026-09-21 · 4 of 14 findings closed

No.FindingStateRefPart
1Every turn tells the agent a missing name is a missing abilityopen—2.16
2Tool results are scrubbed with a pattern that eats shop dimensionsopen——
3The engineer calculators are built, registered and not grantedmerged#10162.14
4search_tools tells the agent to file a ticket instead of using the computeropen——
5Finance is a library, and a test forbids turning it into toolsmerged#10162.14
6A request does not become a tool; the 90-minute loop never startedopen#833 #9842.15
7The skill loader (#890 B) is not on the turnin review#9622.3
8A missing envelope receipt refuses the chat lane's startopen——
9Class A still means Peter signs ordinary code (30 of the last 40 merges)merged#1151—
10An exact-head approval does not survive a byte-identical rebaseopen—3.13
11web_read_rendered is granted in the lane and off in codemerged#1029—
12draft_part tells the agent not to try rolled workopen——
13The coding agent is opted out of memoryopen——
14Nothing wakes Hal unless Peter typesopen——

Coinbase money path: the rails do not bound the loss

Gage Grok 4.7 · oracle#167 · filed 2026-09-21 · 3 of 9 findings closed

No.FindingStateRefPart
1The daily and weekly halts block buys but never sellmergedoracle#1736.11
2Done in the state file is not a fillmergedoracle#1736.12
3An unreadable state file sells half the BTC againopen—6.15
4Savings BTC blocks the whole trend sleeve at the 25% capOwner ruled 9/22: no cap on BTC (#174), not the audit's removal of BTC-USD.mergedoracle#1746.13
5The money path waits on the paper broker, inside the lock, with no deadlineopen——
6The pause flag blocks exits; the kill switch does notopen——
7The equity swing runs without the paper book's 15% stopopen——
8USDC is counted as cash that can pay for a BTC-USD orderopen——
9The live strategies are not the research, and nothing measures themopen——

Kids' tutor — speed, rewards, runway

Gage Grok 4.7 · trivium-forge#305 · filed 2026-09-21 · 1 of 10 findings closed

No.FindingStateRefPart
1A right answer waits up to 60 s on the modelopen—5.10
2The Smithy portrait is far bigger than its frameopen—5.11
3The Smithy does the same read two or three timesopen—5.11
4A failed drill still mints an ingot, and the screen never says somergedtrivium-forge#314 trivium-forge#3185.9
5Paste beats a typing speed runopen——
6The cape slot is a dead tapopen——
7History can run out this week: 20 of 50 stories, no daily capopen—5.12
8The computers lane is one quest, then a replayopen——
9Every locate drill re-downloads the globeopen——
10Today waits on three serial callsopen——

Studio36: reboot still needs a human, the builder loop does not stop

Gage Grok 4.7 · local-first#38 · filed 2026-09-21 · 0 of 12 findings closed

No.FindingStateRefPart
1Claude Code still needs a person after every rebootopenlocal-first#373.8
2The Anvil mission loop has no deadline, and its lock goes staleopen—3.12
3Two Colima VMs are up for two small listenersopen—3.14
4The Oracle pin check is written but not installedopen—3.14
5The two chat lanes restarted many times this boot, cause unreadopen——
6Repo-watch runs as root and fails every 15 minutes; so does chat exportopen——
7Secrets in places every account can readopen——
8The Buzz bridge watchdog watches the wrong processopen——
9Gage's watch and OMP do not start at bootopen——
10Disk is 85% fullopen——
11The local-first repo describes a plan, not the machineopen——
12Temporary root grants from August are still installedopen——

Outside audit: Foundry and the four-repository agent fleet

Astra GPT 5.5 · foundry#639 · filed 2026-09-05 · 10 of 22 findings closed

No.FindingStateRefPart
1Auditor credentials still carry builder/admin reachopen#350—
2Revising a drawing rewrites the earlier draft's filesnot planned#626—
3Compaction loses knowledge when the model failsopen#627—
4A finished model turn is not a finished jobin review#630 #1123—
5Crash recovery leaves a tool call unresolvednot planned#631—
6Resumed work sees a 500-character excerpt, not the evidencenot planned#628—
7Optional Oracle advice can stop protective workdoneoracle#55—
8Child inference locality is not enforced at dispatchopentrivium-forge#249 trivium-forge#316—
9Context is budgeted in pieces, not as the actual requestdone#632—
10Provider truncation is recorded as completiondone#629—
11Auto-live memory trusts a loose provenance claimnot planned#633—
12An unaccepted memory replacement can hide accepted knowledgenot planned#634—
13Fleet recovery is not shown by restoring code and Buzz aloneopenlocal-first#32—
14Staff messages lack one working recipient contractopen#635—
15Review and coordination can eat the only builder and auditoropen#306 #617 trivium-forge#92—
16Shared inference is a fleet-wide single point of failureopen#624 #608—
17The run deadline does not stop a later tool in the same batchdone#636—
18Learning and escalation are parts, not a measured reuse loopopen#637—
19Green CI skips the offline runtime and drawing testsdone#638—
20Forge's value rests on teaching depth, not only safe chat and rewardsopentrivium-forge#38—
21Oracle's correctness fixes do not prove a trading edgeopenoracle#41—
22Stale plans and capability prose mislead new buildersopen#501—

Oracle — day trading and scalping

Astra GPT 5.5 · oracle#70 · filed 2026-09-05 · 6 of 9 findings closed

No.FindingStateRefPart
1A market-data entitlement failure can block protection and flattendoneoracle#63—
2A swing reduction shrinks the stop before a sell that can faildoneoracle#65—
3The intraday sleeve and shared cash can be overcommitteddoneoracle#64—
4Stale or missing entry data passes the gatedoneoracle#66—
5Known protection defects still open (#55, #49, #48)doneoracle#55 oracle#49 oracle#48—
6Orders outlive their signals; holding time starts at submissionopenoracle#67—
7Relative volume uses the wrong time-of-day denominatoropenoracle#68—
8The evidence cannot judge the intraday idea fairlynot plannedoracle#69—
9Missing decisions and unrelated marks contaminate learningopenoracle#3 oracle#42 oracle#8 oracle#81 oracle#83—

Trivium Forge — weak spots, one issue per finding

Astra GPT 5.5 · trivium-forge#258 · filed 2026-09-08 · 11 of 16 findings closed

No.FindingStateRefPart
1No complete, measurable CS and engineering learning cycleopentrivium-forge#264—
2A malformed request can stop the shared tutor servicedonetrivium-forge#259—
3An unmapped weak skill suppresses all due reviewdonetrivium-forge#260—
4A failed grade can land on the wrong child or activitymergedtrivium-forge#269 trivium-forge#322—
5Unvalidated evidence can poison parent reportingopentrivium-forge#34 trivium-forge#326—
6Approved learner memory is not on every tutor pathopentrivium-forge#263—
7Calibration grading does not match its declared thresholddonetrivium-forge#275—
8Calibration Backspace becomes a phantom keymergedtrivium-forge#307—
9Remembered check passes are not bound to the question revisiondonetrivium-forge#261—
10New calibration reports inherit prior runsmergedtrivium-forge#262 trivium-forge#268—
11Post-check coaching skips the authenticated dispatcherdonetrivium-forge#265—
12The Hermes bridge drops each caller's response budgetopentrivium-forge#232—
13A stale parent auth failure logs out a new sessiondonetrivium-forge#272—
14A finished parent action reopens the old child and drops the draftmergedtrivium-forge#274 trivium-forge#324—
15The showcase claims more than its evidencemergedtrivium-forge#273 trivium-forge#323 trivium-forge#328—
16No one honest map of built, partial and planned workopentrivium-forge#38 trivium-forge#169—

Foundry speed and efficiency

Astra GPT 5.5 · foundry#869 · filed 2026-09-15 · 3 of 9 findings closed

No.FindingStateRefPart
1Stop irrelevant work: answer the question askeddone#863—
2Finish tool tiers; count bytes and extra steps togetheropen#847 #926—
3Take memory maintenance off the reply pathmerged#904 #1041—
4Run independent reads at the same timemerged#958—
5Complete the latency ledger; make it a foundation testopen#847—
6Make context budgeting precise enough to stop repeat lookupsopen——
7Tune serving, cache and thinking against the real workloadopen#927 closed; Gage #991 finding 2 says chat still misses—
8Coalesce memory-index rebuilds before the store growsopen——
9Make speed checks cheap; close the intake gapopen#870 #833—

Lean/local-first architecture — structural half

OxAlpha Cerebras · foundry#883 · filed 2026-09-17 · 0 of 4 findings closed

No.FindingStateRefPart
1The product lives under prototypes/: move it outopen#501—
2No LOC budget: make deletion-as-momentum a review checkopen——
3Prompt weight as a per-call metric with per-lane budgetsopen#884 #847—
4Lane consolidation: 25 lane files, retire the overlapopen——
Finished since the 9/14 ledger — 85 parts landed
  • Tiered tools: core on the wire, the rest behind open_tools (#926)
  • Drop everything but core + the called schema for the rest of the turn (#847 B.3)
  • Zero prefix-cache hits on the Sparks route (#927)
  • Snappy-turn SLO as the merge gate (#870 #1023 #1204)
  • Reply first, work in the background (#956)
  • Standing bakeoff: Foundry vs DeepSeek harness vs Hermes (#872)
  • Long Telegram reply splits; a streamed turn shows once (#965)
  • Thinking off on chat; keepalive; streaming; self-knowledge cache (#809 #867)
  • Fast front + specialist lanes as tools (#624)
  • Gage 4.7 audit · Oracle greeting sends 37 schemas, 9,063 tokens, 3.7 s before a word (#1015)
  • Gage 4.7 audit · Thinking at the server default eats the output cap and returns nothing (#1198 #1205)
  • Gage 4.7 audit · Prefix cache is on but a repeated chat prompt is not faster (#1200 #1206 #1022)
  • Schedule tools: register, grant Foundry-wide, fire from each lane's daemon (#941)
  • Deploy the merged speed work (#956 #926 #965)
  • Oracle engine gate binds to merged main; one deploy script; hourly pin check (#967)
  • Scout gets live X: Grok /responses with x_search + web_search (#968)
  • Every agent's keychain unlocks itself at boot (local-first#37 local-first#45 local-first#49)
  • Builder route + gate live (#837 #854)
  • Live board on jobs.egyed.io (#975)
  • Gage 4.7 audit · Class A approval dies on a rebase that changed no bytes (#1201 #1208)
  • Model code runs on the Studio (canvas C0) (#1107 #1103)
  • Deploy 7.1–7.3 to Hal (#1101 #1102 #1107)
  • Canvas plan signed off (#1104)
  • C1 + C1b: sheet kit and house standard (style fixed in code; required content per sheet type) (#1140)
  • C3 + C4: pre-send check and view-conventions rulebook (#1139)
  • C2: parametric two-leaf gate template (#1142)
  • C5: drafting skill — memo → template → render → look → fix → deliver (#1150)
  • Week-one build: nightly CI run, sandbox, Hammer's tools shared, grading, scheduler, filer, trial run (#1079 #1080 #1082 #1083 #1084 #1085 #1086)
  • Curriculum: 800 cases across seven tool families (#1081)
  • Nightly run live: drafting levels 1–3 at 22:30
  • Widen to every tool family: core turn, memory, schedules, research, investing, coding (#1387)
  • Default-on lanes: kernel posture and the profile resolver (#909 #936)
  • C · Helpers persist (#890 C)
  • D · durable_memory_write granted to the front lanes (#890 D)
  • E · Brokered egress for the workspace (#890 E)
  • F · One capability envelope, wired to a lane (#890 F)
  • G · Rewrite the self-model sentence (#890 G)
  • H · stuck.py improvises before it escalates (#890 H)
  • N · Tool results survive into the next turn (#933)
  • Host file search: host_find / host_read (#836 #1026 #1128)
  • Skills: mine repeats, promote at 10 days, retire with a tombstone (#672 #702)
  • Memory seeded from OpenClaw, 5,080 lines live (#843 #845 #848 #858)
  • 7.08 · A real brain on the builder lane (#837)
  • Mission-cycle guard: every cycle writes a ledger line (#891)
  • S0 · The slot Smithy (trivium-forge#297)
  • S1 · Metal as a compositor input, the cape row, the forward-upgrade rule (trivium-forge#299)
  • S3 · Forge scene and strike FX behind the Smithy (CSS/SVG only) (trivium-forge#300)
  • Deploy S0–S3 to the mini (mini deploy procedure)
  • Two open advisories (trivium-forge#304)
  • Gage 4.7 audit · A failed drill still mints an ingot, and the screen never says so (trivium-forge#314 trivium-forge#318)
  • Oracle's keys back in the rebuilt foundry keychain (local-first #37)
  • Read-only Coinbase Advanced Trade driver: market kinds, provider switch, trading gate (oracle#160)
  • Coinbase market kinds (cb_*) on the oracle-voice argv allowlist (#970)
  • Execution: Oracle's order path, rails, first act, sleeves, gate (oracle#163 oracle#161)
  • Your word: trading_enabled: true
  • Oracle's own requests: Coinbase connector, scheduler (oracle#158 oracle#159)
  • Coinbase CLI live, Default portfolio read (9/20)
  • Gage 4.7 audit · Savings BTC in Default blocks the whole trend sleeve at the 25% rail (oracle#174)
  • $500 USDC added to the test book (9/20)
  • Lead Auditor seat pluggable; Astra live from his Codex App 9/27 (#1388)
  • Failure hunt: full 1,402-case run graded and hand-triaged; findings and plan in #1387
  • Studio36 reboot proof passed 9/27 (3.8)
  • Kernel batch + board parts deployed 9/27 14:50 (6b08fecb)
  • Oracle trading ON at your word 05:06 9/21 (6.5)
  • Coinbase execution #163 + flag #164 merged, engine 8c25d293
  • Tear-down parts C–H merged and deployed (2.4–2.9); runtime 81725e0e
  • Forge S0–S3 + S1 follow-up live on the mini (5.4)
  • Scout X search live (#968); schedule tools live (#941)
  • Gage on Grok 4.7; five broad audits filed 9/21
  • Oracle memory: OpenClaw account line retired; engine-is-live fact added
  • Shared-folder GitHub App keys moved to their owners
  • Live board tooling merged (#975)
  • Speech fix deployed (#867)
  • Importer dry-run dedupe (#861)
  • Egress-proxy CI flake (#855)
  • report_issue routed to the agent's own repo (#825)
  • draft_package: customer-approval package (#826)
  • Memory reindex hygiene (#937)
  • Oracle: watchlist persistence + daily review (oracle#143)
  • Oracle: macro list gains VIX and oil (oracle#139)
  • Oracle: flatten unblocked on non-numeric stop (oracle#138)
  • Oracle quotes fixed, pin and evidence rule: no record per engine bump
  • Forge Crafting Overhaul Map v1 signed
  • Forge crafting table + painted gear live on the mini
  • Studio36 recovery: Claude Code login restored (local-first #37)
Source: GitHub state on azhodl/foundry, azhodl/local-first, azhodl/oracle, azhodl/foundry-hal, azhodl/trivium-forge at 2026-09-29 11:54 UTC (198 refs read from GitHub, 0 unreachable), ledger/parts.yaml, and the owner's rulings of 9/15–9/20. Component names are the owner's; part numbers, ordering and "Done when" come from the data file. A merge on any of these repos flips its row within 15 minutes; nobody edits HTML.
SHEET 1/2