Epic #17500 makes the exact AgentOS extraction inventory its first blocking proof. Per the corrected authority at D#17489 DC_kwDODSospM4BFFq_, this proof may land after Epic filing but must land before any relocation leaf starts.
Live origin/dev measurements at 2026-08-21T23:29Z (2e67c4d8ec) show why one reproducible inventory is needed. The filing-window checkout was one merge behind; fetching origin/dev changed 157→159 scripts, 115→116 root commands, and 73→74 roots before implementation began—the decay this leaf must eliminate:
12 tracked Tier-1/server config base/template candidates, plus operator overlays governed by ADR 0019.
These are different populations. The 63 data-plane openers are not the 74 launchable roots; a green closure lint does not classify all 159 source scripts; workflow path counts do not find subprocess command strings such as ai/scripts/lifecycle/postReleaseSync.mjs:143. Treating any one as “the inventory” leaves a plausible hole.
The Problem
No current-head artifact reconciles every executable/root command/workflow/config/custody surface against the folded first-wave topology. The evidence is split across diagnostics, package.json, workflow YAML, task definitions, config authorities, and Discussion prose.
Without one source-owned registry and one zero-residue check:
a module on disk can be omitted from plane authority;
an obsolete registry row can survive after its source disappears;
an Engine command can be mistaken for AgentOS simply because it contains ai, or vice versa;
a config file can move while its ADR-0019 declaration/resolution authority does not;
later migration leaves must re-derive the same population under deadline pressure.
This leaf is the census receipt only. It moves no code and creates no package manifest.
The Architectural Reality
D#17489 / Epic #17500 own C′: Engine stays independent; the future repository root is Host Edge, cloud/ is independently installed, npm workspaces are forbidden, and shared/ is admitted only for inventory-proven pure modules.
ADR 0039 owns the Brain-internal Host-Edge/Container-Cloud closure property and requires static reachability plus runtime package denial; neither instrument owns membership completeness.
ai/scripts/lint/lint-script-plane.mjs already derives launchable roots from npm scripts, workflows, and orchestrator task definitions. scriptPlaneClosure.mjs already owns transitive capability closure.
ai/scripts/diagnostics/planePlacementCensus.mjs already owns the durable-plane opener census and exports its source-owned result.
ADR 0019 owns AiConfig declaration and resolution. This inventory may classify config custody; it must not import operator overlays, re-resolve env values, duplicate leaves, or turn config values into migration metadata.
ai/scripts/diagnostics/ is the established home for rerunnable, read-only censuses. Structural fast-path: the new diagnostic matches planePlacementCensus.mjs and devDependencyCensus.mjs; no new directory role or Architecture Overview row is introduced.
The mandatory full npm run --silent ai:structure-map -- --files --loc currently exceeds Node's maximum string length. Scoped owning-surface reads succeeded; this tooling failure is evidence, not an empty map result.
The Fix
Add a rerunnable extraction-inventory diagnostic and source-owned disposition registry:
tracked config bases/templates plus the operator-overlay class under ADR 0019;
the explicit wave-one custody boundaries (src/ai/**, apps, learn/agentos, resources/content, Portal/SEO/tree inputs, and the minimal Engine contributor surface stay Engine).
The registry gives every derived identity exactly one disposition from a closed vocabulary: edge, cloud, shared, stays-engine, or retire, with a source coordinate and non-empty rationale. Different surfaces may point to the same file, but each surface identity remains independently accounted for.
Default output is a concise human report; --json emits a stable machine-readable receipt including repository SHA, population counts, all rows, and residue. Exit non-zero on missing authority, stale authority, duplicate identity, invalid disposition, missing rationale/source, unresolved computed launch edge, or any non-empty {disk} ⊖ {authority} / {authority} ⊖ {disk} set.
classify ownership/custody without importing overlays or re-deriving values
fail when a config authority surface is unclassified
ADR 0019 citation in JSDoc
positive/negative config fixtures
plane-opener rows
planePlacementCensus.mjs + C′ invariant 5
consume its exported census; classify every durable-plane opening concern as Cloud while preserving the source runtime class as evidence
fail if the owning census changes shape or a row is absent from the combined inventory
sibling citation
composition fixture
Decision Record impact
Depends on ADR 0039 and ADR 0019. Aligned with the corrected C′ authority in D#17489 and Epic #17500. It does not amend either ADR and does not freeze ADR 0040.
Decision Record
Required: #17502 will record ADR 0040 after the separate naming disposition. This inventory is an input to that record, never a prose substitute.
Discussion Criteria Mapping
Source criterion
This leaf
D#17489 OQ2 — exact Edge membership
every executable, script, command, workflow reference, config authority, and wave-one custody boundary receives one disposition
D#17489 OQ3 — membership completeness
bidirectional disk↔authority reconciliation reaches zero residue; computed launch edges are enumerated
D#17489 OQ7 — substrate residence
Engine-staying and moving surfaces are explicit decisions, not directory inference
corrected criteria timing DC_kwDODSospM4BFFq_
this receipt is blocking and must be linked on Epic #17500 before relocation starts
Acceptance Criteria
The diagnostic derives all eight populations above from current source authorities and records the current-head receipt without hardcoded headline counts.
Every one of the 159 origin/dev source modules plus this diagnostic's own governed retirement row (160 at implementation head), 116 root scripts, 19 workflow files / 69 references, 63 data-plane openers, and current config/custody surfaces has exactly one valid disposition; zero unclassified or unexplained residue remains.
Launch discovery includes subprocess/command strings, with ai/scripts/lifecycle/postReleaseSync.mjs:143 as a positive control; an import-only implementation fails the test.
The tool composes lint-script-plane, scriptPlaneClosure, and planePlacementCensus authorities rather than re-implementing their classifiers.
{disk} ⊖ {authority} = ∅ and {authority} ⊖ {disk} = ∅ are both enforced. Adding an unregistered file/command/reference and retaining a deleted registry row each RED independently.
Registry rows are deterministic and carry a source coordinate plus non-empty rationale; duplicate identities and invalid dispositions fail loud.
Config custody follows ADR 0019: no operator-overlay import, env re-read, config alias/pass-along, default duplication, or runtime mutation.
Human and --json outputs are SHA-bound, deterministic, and distinguish all population classes rather than conflating 63 openers with 74 launchable roots.
Unit fixtures cover missing/stale/duplicate rows, subprocess-only launch discovery, computed dynamic launch edges, config authority, and both residue directions.
A current-head zero-residue receipt is linked on Epic #17500 before any relocation leaf starts.
Out of Scope
creating the future Edge/Cloud package manifests or the standing closure/denial gate;
severing the GitHub Workflow or Neural Link durable-store spines;
choosing the repository name or drafting ADR 0040;
moving files, editing workflows, transferring tickets, or deleting Engine paths;
changing AiConfig declarations, defaults, overlays, or runtime values;
changing scriptPlaneClosure plane semantics to make the inventory green.
Avoided Traps
Snapshot-only markdown: a count without a rerunnable instrument is stale as soon as another script lands.
Directory equals plane: the nine ai/scripts folders classify activity, not execution realm.
Import-only discovery: command strings are execution edges too.
One population presented as all: launchable roots, durable-plane openers, files, commands, and workflow occurrences are distinct sets.
Copying existing classifiers: divergent closure/openers logic would create two authorities.
Reading live AiConfig for a static census: makes the answer machine/environment-shaped and violates ADR 0019.
Allowing unclassified to meet the deadline: a named residue is an honest blocker; a generic bucket is not a proof.
Related
Parent: #17500. Source: D#17489. Paired second blocking proof: to be filed separately. Decision Record leaf: #17502. Existing instruments: ADR 0039, scriptPlaneClosure.mjs, lint-script-plane.mjs, and planePlacementCensus.mjs.
Live latest-open sweep: checked latest 20 open issues at 2026-08-21T23:25:52.223Z; no equivalent found. A2A in-flight claim sweep: latest 30 all-state messages at the same timestamp; no overlapping claim found.
Context
Epic #17500 makes the exact AgentOS extraction inventory its first blocking proof. Per the corrected authority at D#17489
DC_kwDODSospM4BFFq_, this proof may land after Epic filing but must land before any relocation leaf starts.Live
origin/devmeasurements at 2026-08-21T23:29Z (2e67c4d8ec) show why one reproducible inventory is needed. The filing-window checkout was one merge behind; fetchingorigin/devchanged 157→159 scripts, 115→116 root commands, and 73→74 roots before implementation began—the decay this leaf must eliminate:lint-script-plane.mjs: 74 launchable roots (62 npm, 5 workflow, 7 orchestrator-task); 16 Host Edge, 34 Container Cloud, 1 shared primitive, 23 unresolved projections;ai/scripts/**: 159 tracked.mjsmodules whose directories classify activity, not execution realm;package.json: 116 scripts, 82 namedai:*;ai/scripts/references;planePlacementCensus.mjs: 63 durable-plane openers (41 host-side, 19 in-server, 3 unclassified);These are different populations. The 63 data-plane openers are not the 74 launchable roots; a green closure lint does not classify all 159 source scripts; workflow path counts do not find subprocess command strings such as
ai/scripts/lifecycle/postReleaseSync.mjs:143. Treating any one as “the inventory” leaves a plausible hole.The Problem
No current-head artifact reconciles every executable/root command/workflow/config/custody surface against the folded first-wave topology. The evidence is split across diagnostics,
package.json, workflow YAML, task definitions, config authorities, and Discussion prose.Without one source-owned registry and one zero-residue check:
spawn/exec/forkcommand crossings;ai, or vice versa;This leaf is the census receipt only. It moves no code and creates no package manifest.
The Architectural Reality
cloud/is independently installed, npm workspaces are forbidden, andshared/is admitted only for inventory-proven pure modules.ai/scripts/lint/lint-script-plane.mjsalready derives launchable roots from npm scripts, workflows, and orchestrator task definitions.scriptPlaneClosure.mjsalready owns transitive capability closure.ai/scripts/diagnostics/planePlacementCensus.mjsalready owns the durable-plane opener census and exports its source-owned result.ai/scripts/diagnostics/is the established home for rerunnable, read-only censuses. Structural fast-path: the new diagnostic matchesplanePlacementCensus.mjsanddevDependencyCensus.mjs; no new directory role or Architecture Overview row is introduced.npm run --silent ai:structure-map -- --files --loccurrently exceeds Node's maximum string length. Scoped owning-surface reads succeeded; this tooling failure is evidence, not an empty map result.The Fix
Add a rerunnable extraction-inventory diagnostic and source-owned disposition registry:
ai/scripts/diagnostics/agentOsExtractionInventory.mjsai/scripts/diagnostics/agentOsExtractionInventory.jsontest/playwright/unit/ai/scripts/diagnostics/agentOsExtractionInventory.spec.mjsThe diagnostic must derive current populations from their existing authorities, not copy counts:
lint-script-planepopulation;ai/scripts/**/*.mjsmodules;package.jsonscript, including Engine-staying commands;ai/scripts/;spawn,exec,execFile,execSync,fork, and equivalent command wrappers);planePlacementCensusopener rows;src/ai/**, apps,learn/agentos,resources/content, Portal/SEO/tree inputs, and the minimal Engine contributor surface stay Engine).The registry gives every derived identity exactly one disposition from a closed vocabulary:
edge,cloud,shared,stays-engine, orretire, with a source coordinate and non-empty rationale. Different surfaces may point to the same file, but each surface identity remains independently accounted for.Default output is a concise human report;
--jsonemits a stable machine-readable receipt including repository SHA, population counts, all rows, and residue. Exit non-zero on missing authority, stale authority, duplicate identity, invalid disposition, missing rationale/source, unresolved computed launch edge, or any non-empty{disk} ⊖ {authority}/{authority} ⊖ {disk}set.Contract Ledger Matrix
unknownbucket@examplein module JSDoc--jsonreceiptplanePlacementCensus.mjs+ C′ invariant 5Decision Record impact
Depends on ADR 0039 and ADR 0019. Aligned with the corrected C′ authority in D#17489 and Epic #17500. It does not amend either ADR and does not freeze ADR 0040.
Decision Record
Required: #17502 will record ADR 0040 after the separate naming disposition. This inventory is an input to that record, never a prose substitute.
Discussion Criteria Mapping
DC_kwDODSospM4BFFq_Acceptance Criteria
origin/devsource modules plus this diagnostic's own governed retirement row (160 at implementation head), 116 root scripts, 19 workflow files / 69 references, 63 data-plane openers, and current config/custody surfaces has exactly one valid disposition; zero unclassified or unexplained residue remains.ai/scripts/lifecycle/postReleaseSync.mjs:143as a positive control; an import-only implementation fails the test.lint-script-plane,scriptPlaneClosure, andplanePlacementCensusauthorities rather than re-implementing their classifiers.{disk} ⊖ {authority} = ∅and{authority} ⊖ {disk} = ∅are both enforced. Adding an unregistered file/command/reference and retaining a deleted registry row each RED independently.--jsonoutputs are SHA-bound, deterministic, and distinguish all population classes rather than conflating 63 openers with 74 launchable roots.Out of Scope
scriptPlaneClosureplane semantics to make the inventory green.Avoided Traps
ai/scriptsfolders classify activity, not execution realm.unclassifiedto meet the deadline: a named residue is an honest blocker; a generic bucket is not a proof.Related
Parent: #17500. Source: D#17489. Paired second blocking proof: to be filed separately. Decision Record leaf: #17502. Existing instruments: ADR 0039,
scriptPlaneClosure.mjs,lint-script-plane.mjs, andplanePlacementCensus.mjs.Origin Session ID: bbd4f722-ca03-4269-a88e-29555b12b9f9
Retrieval Hint:
query_raw_memories("AgentOS extraction zero-residue inventory 160 scripts 74 roots 63 openers workflow config custody")Live latest-open sweep: checked latest 20 open issues at 2026-08-21T23:25:52.223Z; no equivalent found. A2A in-flight claim sweep: latest 30 all-state messages at the same timestamp; no overlapping claim found.