x64base verifies behavior three ways: a curated regression launcher inside the shell, a hash-bound proof-transcript discipline for durable evidence, and build-integrated CTests. The disposable Pinocchio lane adds scale and fault-injection runs on top.
The REGRESSION launcher
REGRESSION is a curated launcher, not a separate test executor — it runs
reviewed DotScript smoke/regression files through the normal
DotScript runner. Subcommands:
REGRESSION LIST— show the curated stable entrypoints (not every historical script on disk).REGRESSION SHOW NONDESTRUCTIVE— show what a named suite will run.REGRESSION RUN INDEX_X64— run one curated suite by name.REGRESSION ALL— run the curated default suite in declared order.
Each suite bootstraps its own environment. Because scripts may mutate data and
session state, REGRESSION is a read-and-execute surface with no built-in
transaction or rollback — suites are expected to be self-contained.
The curated suite -- viewable and categorized
The full REGRESSION registry is shown below, grouped by domain, with each script linked
so you can view it. This block is auto-generated from the engine source
(src/cli/cmd_regression.cpp, the kRegressionSpecs table) and regenerated rather than
hand-edited, so it cannot drift from what REGRESSION ALL actually runs. Runtime .dts
scripts that are not in the public tree are listed by path without a link. Regenerate with
python tools/reports/regression_index.py --write-mdx <this-file>.
{/* regression-index:begin -- generated by tools/reports/regression_index.py; do not edit between markers */}
The list below is generated from the engine's own registry -- the kRegressionSpecs table in src/cli/cmd_regression.cpp, the same set REGRESSION LIST / REGRESSION ALL drive (42 entries, 8 in the default suite), grouped by domain. It cannot drift from what the engine runs, because it is parsed from that source. Regenerate with python tools/reports/regression_index.py --md.
bbs (1; 0 default)
- BBS_LANE
[explicit]-- AI-BBS command-surface smoke (AIF-052/054/055): BBS BOARDS tops up + lists the seeded rooms (governance/afb.chat/notice/lounge/guestbook/worklog), BBS READ board.governance renders the SYSGRANT projection, and a POST/READ round-trip on board.afb.chat self-asserts. Read-mostly (first BBS BOARDS tops up the board store, idempotent after; no fixture touched). The guest-scoping SECURITY regression lives in the socket smoke bbs_smoke.ps1 (server-side permission denial needs the listener). Out of the default suite (explicit run).bbs/bbs_lane_regression.dts
calc (1; 0 default)
- CALC
[explicit]-- CALC output-routing regression: every ValueKind path (Bool/Number/String/Date/empty/Error) via cli::cmdout::print_line (AIF-031); read-only, but leaves ECHO ON so it stays out of the default suite (explicit run)calc/calc_output_regression.dts(runtime script -- not in the public tree)
canaries (2; 2 default)
- LANGUAGE
[default]-- Messaging-normalization locale proof: es/fr/de/it USAGE render across the localized command surfacecanaries/language_shakedown_canary.dts(runtime script -- not in the public tree) - X64_METRICS
[default]-- x64 structural boundary proof above legacy 16-bit record/header limitscanaries/x64_matrix_metrics_boundary_canary.dts(runtime script -- not in the public tree)
core (20; 3 default)
- INDEX_X32
[default]-- x32 INX/CNX order and attachment smokeindex_x32_inx_cnx_smoke.dts(runtime script -- not in the public tree) - INDEX_X64
[default]-- v64 CDX/LMDB order and attachment smokeindex_v64_cdx_lmdb_smoke.dts(runtime script -- not in the public tree) - NONDESTRUCTIVE
[default]-- Broad non-destructive shell smoke over stable command surfacedottalkpp_non_destructive_smoke.dts(runtime script -- not in the public tree) - CASCADE_ENV
[explicit]-- Cascade system-bundle environment proof (AIF-105, promoted final test per the promote-final-tests rule, runtime-proven 2026-08-10): bundle slots stand up, USE auto-attaches the built CDX orders, SET ORDER TAG + ordered traversal follow the tag, SEEK reaches PDU-100 through the SKU unique tag, and ERP CASCADE opens the SQLite carrier at the bundle path (ERP CHECK scorecard as transcript evidence). C_T1/T2 deliberately encode the MEASURED lexicographic ordering of the N-type ITEM_ID key (1,10,11..) -- a recorded behavioral-parity difference vs SQLite's numeric order for the lane's parity oracle; if numeric key encoding lands, repoint them (IDXSTALE precedent). Section 2 (proven 2026-08-10): WORKSPACE LOAD cascade_all restores 43 areas + 58 relations (logical-name plane -- REL resolves x64 LONG names, CDX resolves descriptors), then SET RELATION traversal is asserted BY FIELD VALUE: parent TOP/BOTTOM + REL REFRESH drives the child to SO 1 / SO 6 (child recno measured 1 -> 11). House semantic recorded: slaving is REFRESH-driven, not implicit per movement. Requires workspaces/cascade_all.dtschema. Read-only; no fixture mutation. Explicit-run until soaked, then promote to default.cascade_env_regression.dts - CNXLIVE
[explicit]-- Realtime CNX index maintenance (XIDX-TXN-02 M1, session 2026-07-31): a REPLACE that moves an indexed value re-places that record in the CNX ordering IMMEDIATELY, with no REBUILD between the edit and the ordered read, and the staleness warning is correctly ABSENT (trace 'staleBefore=no leftStale=no'). The positive counterpart to IDXSTALE, which asserts the opposite contract for a backend that cannot maintain; the two are kept separate so the inversion that happened when M1 landed reads as a deliberate split rather than a silently retuned regression. A CNX RUN1 payload stores 4 bytes per recno and NO keys (cnx_document.cpp:81 -> InxEntry{"", rn}), so upsert cannot binary-search stored keys: it searches the PERMUTATION, comparing the edited record's live field value against the live value at each probe (~log2 n record reads). The table is the ordering authority, the same authority REBUILD uses, and both share derive_sort_entry_/sort_entry_less_ so they cannot drift -- L_T6 asserts exactly that by re-checking the order after a REBUILD that must be a no-op. L_G0/L_G1 guard the fixture, L_T2 is the marker that inverted (top is AAAAA with no rebuild), L_T3/L_T4 catch an insert that appends instead of placing, L_T5 confirms lookup and order agree. Markers are FIELD comparisons for the same reason as IDXSTALE. Self-bootstrapping v32 table, self-erasing; explicit-run until soaked.cnx_realtime_index_proof.dts - CURSOR
[explicit]-- Navigation/cursor family regression on classic ordered traversalCURSOR_FAMILY_REGRESSION_001.DTS(runtime script -- not in the public tree) - EVALDIFF
[explicit]-- SQLSEL evaluator differential harness (AIF-074 P4.0a): self-bootstraps a mixed-type X64 fixture in SANDBOX, compares classic DbArea and TupleRow-bound predicate outcomes over the same physical records, reports verdict/failure parity and known differences, restores the cursor, and self-erases. Observer only; explicit-run while findings are being classified.evaldiff_regression.dts - IDXDIFF
[explicit]-- Index replace-diff benchmark (item A, session 2026-07-30): apply_replace_snapshot now emits only the tags whose (tag,key) actually moved instead of deleting and re-inserting every tag, turning a single-field REPLACE on an N-tag table from 2N committed LMDB write transactions into 2. Builds a throwaway 4-tag x64 table, replaces one indexed field then one non-indexed field, and carries two correctness markers (moved key reachable, skipped tag intact). MEASUREMENT is external: run with DOTTALK_INDEX_TRACE=1 and read the '[INDEX TRACE] apply_replace ... emitted_del/emitted_ins/skipped' lines; a .dts cannot count engine trace output. Expect 1/1 skipped=3 for the indexed edit and 0/0 skipped=4 for the unindexed one. Explicit-run: benchmark, not a pass/fail gate.index_replace_diff_bench.dts - IDXSTALE
[explicit]-- Index-staleness REPORTING on a backend that cannot maintain incrementally (item E, session 2026-07-31): apply_replace_snapshot compares wasStale() across the apply and reports a false->true transition, so such a backend is no longer silent; wasStale() had seven overrides and ZERO call sites (AIF-079 instance 1). SUBJECT REPOINTED 2026-07-31: this ran against CNX/v32 until XIDX-TXN-02 M1 gave CNX realtime maintenance, at which point CNX stopped qualifying and E_T2 correctly inverted to .F. The test was not wrong -- its subject moved -- so it now targets native CDX-V64, whose upsert/erase are STILL no-op stubs that set stale_ and return normally (cdx_native_backend.cpp:507-519). That is the RAM/vdisk x64 path, so this now covers the in-memory lane; the realtime CNX behaviour that replaced it is proven separately by CNXLIVE. Scored on ORDER, not key lookup -- a native SEEK compares LIVE field values through a stale recno ordering, so a key probe proves nothing either way (measured on CNX: after moving MILLER->AAAAA, SEEK MILLER misses and SEEK AAAAA still hits). E_G0/E_G1 guard the fixture, E_T2 shows the stale order still starting at ANDERSON, E_T4 shows REINDEX fixing it. If E_T2 ever reads .F. the backend has GAINED realtime maintenance and this proof needs repointing again. Every marker is a FIELD comparison: RECNO() and FOUND() render EMPTY in a '?' marker and STR() does not rescue them. Builds a throwaway x64 table entirely in the RAM VFS and unmounts on teardown, so it writes nothing to disk; explicit-run until re-proven against the new subject.index_maintenance_failure_proof.dts - INDEX_X64_CNX
[explicit]-- CNX-on-x64 policy proof (owner ruling 2026-08-09): explicit .cnx attaches on a v64 table with an advisory instead of the old hard refusal; SET ORDER honors the .cnx both as an explicit container and via the bare-tag fallback when no .cdx exists; bare REINDEX routes to the CNX engine when the active order is CNX; and the CDX/LMDB default is proven UNCHANGED when no .cnx is requested. Self-bootstrapping disposable copy in SANDBOX (students_cnx64_smoke), self-erasing. This is the lane's final test promoted to a regression per the promote-final-tests rule. Explicit-run until soaked, then promote to the default suite.index_x64_cnx_smoke.dts - MEM
[explicit]-- AIF-043 in-memory indexed table end-to-end proof: DO mem mounts the in-process RAM VFS (xbase::ramfs), then an x64 table AND its native CDX-V64 index are built, indexed, and traversed entirely in RAM (RUN8, no LMDB, zero files on disk). Self-contained (leads with DO mem, clean-slate remount) and self-asserting: ordered read-back must yield ADAMS/MILLER/ZEBRA (MEM_T1/T2/T3 = .T.); teardown unmounts and restores the x64 disk env. Mutates the RAM VFS only (no disk table), but kept out of the default suite (explicit run) until soaked. (AIF-043)mem_proof.dts - MEMO_RAM_HELLO
[explicit]-- x64 memo field lifecycle in RAM (promoted final test, runtime-proven 2026-08-11): CREATE X64 with NOTES M in the RAM VFS, write a memo string, close/reopen, read it back as TEXT, and update after reopen -- H_T1/H_T2/H_T3 all field-value markers. H_T2/H_T3 are exactly the two KNOWN-RED cases MEMO_X64_REOPEN_CANARY_20260513 recorded (memo reading back as its reference token after reopen; REPLACE reporting 'memo backend not attached') -- both measured GREEN on the RAM path 2026-08-11, so that canary's expectations are stale and it is due a disk-path rerun and repoint (IDXSTALE precedent). Born as an owner tiny-favor ('append a memo field to students, copy to RAM, say hello') that re-measured a three-month-old defect by accident. Students-shaped structure built fresh because no ALTER-add-field verb exists yet (named gap: sql_ref ALTER-TABLE-ADD). CORRECTED 2026-08-11 (measured by the hydration leak check): the original 'zero disk writes' claim was FALSE -- the DBF lives in ramfs but the DTX memo sidecar does its own file I/O, bypasses the VFS, and lands as a REAL file (data/ram/STUDMEMO.dtx, 4624 B, survived unmount). This solved the named VDISK census gap: 'RAM files = 1 despite (+ memo)' was the census telling the truth. Lifecycle markers stand; the memo RESIDENCY claim does not. Ramfs coverage for the memo store layer is the chartered prerequisite for true RAM memos. Explicit-run until soaked.memo_ram_hello.dts - SQLSEL_BUFFER_VIS
[explicit]-- SQLSEL/TUPLE TABLE BUFFER visibility split (AIF-074 follow-up): TUPLE remains buffer-preview, while SQLSEL SELECT projects the same committed table truth its WHERE predicate scans. Self-bootstrapping throwaway SQLBUFVIS table in SANDBOX; explicit-run because it mutates the filesystem.sqlsel_buffer_visibility_regression.dts(runtime script -- not in the public tree) - SQLSEL_SELECT_V1
[explicit]-- SQLSEL statement surface, gate G3 (AIF-074 P3): SELECT <cols|> FROM <table> with WHERE, ORDER BY [ASC|DESC], LIMIT and COUNT(), each row set compared against an in-process SQLite oracle over identical data in the same run. Asserts cursor neutrality by data (the cursor is parked on a known record before and after), corrective errors for an unopened table / expression select-item / bad LIMIT / unknown ORDER BY field / ORDER BY on COUNT(*), and that ORDER BY sorts the full match set BEFORE LIMIT applies. Legacy predicate form preserved. Self-bootstrapping throwaway SQLSTU table in SANDBOX; explicit-run because it mutates the filesystem.sqlsel_select_v1_regression.dts - VUREPAIR
[explicit]-- VALIDATE UNIQUE ... REPAIR maintains the active index (item C1, session 2026-07-30): builds a throwaway x64 table with a duplicated key, indexes the uniqueness-candidate field via CDX, repairs the duplicate, then asserts the repaired record is reachable at its NEW key with NO REINDEX between (VUR_T2) and that the surviving legitimate duplicate is still correct (VUR_T3). Runtime-proven 2026-07-30 on the wsl-lean build. REPAIR previously used set()+writeCurrent(), which carry no index hook, and left the tag pointing at the old value with nothing marked stale. Proven on x64/CDX. It was ALSO restricted to x64/CDX because CnxBackend upsert/erase were stubs, so x32/CNX would have failed for an unrelated reason -- that restriction LAPSED 2026-07-31 when XIDX-TXN-02 M1 gave CNX realtime maintenance (see CNXLIVE). Whether VUREPAIR now passes on x32/CNX is UNMEASURED; the blocker is gone, the run has not been done. Self-bootstrapping and self-erasing; explicit-run until proven green.validate_unique_repair_index_proof.dts - WORKSPACE_MEMO
[explicit]-- Workspace-in-memo proof (AIF-070 M2/M3, promoted final test per the promote-final-tests rule, runtime-proven 2026-08-11): a whole database posture (43 areas + 58 relations) is saved INTO a memo field of the self-creating WORKSPACES catalog (WORKSPACE SAVE <name> MEMO -- x64 table, FLOCK per append, attributed via current_member, append-history with SUPERSEDED per owner ruling D4, SET PATH roots recorded because .dtschema payloads are root-relative) and restored FROM INSIDE THE TABLE (WORKSPACE LOAD <name> MEMO), then proven live: refresh-driven SET RELATION traversal drives the child to SO 1 / SO 6 / record 11, and SQLSEL agrees cursor-neutrally (WM_T1..WM_T4). The save's oracle byte-compares the payload against the token read back FROM THE FIELD -- a len=10 truncation of the canonical 16-hex x64 memo token slipped past a memory-ref oracle once (2026-08-11) and cannot again. One format, two carriers; the .dtschema text is byte-identical in file or memo. Writes catalog rows by design (append-history, reruns supersede). Requires workspaces/cascade_all.dtschema + the cascade_erp bundle. Explicit-run until soaked, then promote to default.workspace_memo_regression.dts - WORKSPACE_MINIDB
[explicit]-- Memo-resident mini-database (AIF-070's chartered destination LANDED, owner 'do it' 2026-08-11; promoted final test, runtime-proven same day build 18:35:35 FIRST TRY): WORKSPACE SAVE <name> MEMO MINIDB writes a MINIDB 1 container -- the self-locating v3 posture PLUS every open table's bytes and every attached native index's bytes, length-prefixed and binary-safe (the memo store's payload-agnosticism, zoo-proven on embedded NULs, is what makes DBF/CDX bytes legal cargo). WORKSPACE LOAD <name> MEMO RAM detects the container and hydrates FROM THE PAYLOAD: memo -> RAM VFS, ZERO disk reads; the carried posture then stands areas up re-pointed at RAM. Reads are residence-aware (RAM-resident sources come from ramfs), so a RAM session can save its whole working set into a memo -- the owner's save-the-state vision. Plain MEMO load refuses a MINIDB payload with the hydration instruction rather than half-loading. First measure: mcc_db = 94200 B container (92139 B tables+indexes, 1443 B posture), oracle byte-compare OK on the WHOLE container; hydration onto a clean RAM disk 65.5 ms -- FASTER than disk-sourced hydration (71-94 ms) because it is memory to memory; STUDENTS row read and ENROLL CDX attached from memo-carried bytes (DB_T1/DB_T2). The catalog row records FMT='MINIDB 1'. What this makes true: a whole small database -- data, indexes, posture, session state -- lives inside one memo field of another database, versioned by the supersede chain, attributed, oracle-verified. The writeback cycle (RAM -> disk commit) LANDED and is runtime-proven on both toolchains as of 2026-08-21 -- see WORKSPACE_WRITEBACK. Still chartered: LMDB carriage (out of ramfs scope by contract), memo-sidecar carriage (Part B coupling). Writes catalog rows; mutates only the RAM VFS, self-erasing. Requires workspaces/mcc_x64.dtschema + the x64 MCC tables. Explicit-run until soaked.workspace_minidb.dts(runtime script -- not in the public tree) - WORKSPACE_RAM
[explicit]-- Memo -> RAM hydration (owner lane step 2, promoted final test, runtime-proven 2026-08-11 build 14:59:07): WORKSPACE LOAD <name> MEMO RAM copies the posture's tables + native CDX files from their DISK homes into the mounted RAM VFS and loads with roots re-pointed at RAM (the DTSHEMA 3 self-location mechanism reused as the hydration vehicle). The copy goes through xbase::ramfs streams, NEVER std::filesystem -- the VFS is in-process and an OS copy would land on real disk while claiming RAM (a false hydration). LMDB is not hydrated: owner rule 'lmdb only for disks', grounded in ramfs.hpp's own contract (LMDB must mmap a real OS file). First measure: 24 file(s), 92139 B in 94.2 ms for the 13-table MCC posture, VDISK census agreeing byte-for-byte (92139 B / 24 files) -- an independent cross-check of the hydration counter. HYD_T1 asserts a STUDENTS row reads from the RAM-resident copy. Index attach in RAM, measured 2026-08-11 (ENROLL, hydrated .cdx): the LMDB-backed route fails ('SET ORDER: failed.' -- no LMDB in RAM, by design) and the native-CDX fallback then attaches (SET ORDER: CDX TAG 'SID'); attach is proven, ordered-traversal-by-value assertion is a chartered follow-up. Environment note: the source-authoring leg MUST run under DO x64 -- without the LMDB slot, LOAD attaches zero CDX orders and the posture records index=none (measured: the 13-vs-24 hydrated-file variance). VDISK UNMOUNT at the end IS the dismiss exit of the chartered two-exit close (save-state or dismiss); the save-state exit is the lane's next step. Memo-sidecar hydration chartered with the Part B MCC regeneration (no MCC table carries a memo field yet). Self-contained: authors its own v3 source posture (ram_hydrate_src) from mcc_x64. Writes catalog rows + mutates only the RAM VFS (self-erasing on unmount). Requires workspaces/mcc_x64.dtschema + the x64 MCC tables. Explicit-run until soaked.workspace_ram_hydrate.dts - WORKSPACE_SESSION
[explicit]-- v3 session-state capture (owner requirement 2026-08-11 'we need the cursor states and refresh relations'; promoted final test, runtime-proven same day, build 15:22:32, FIRST TRY): a v3 save emits CURSOR <area> <physical-recno> per open area plus CURRENT <area>; the v3 loader applies them after AREA/REL restoration, the saved selection outranks normalization, and the final refresh slaves children to the RESTORED parents -- so a workspace save is now a complete session snapshot: shape, index attachments, keys, cursors, selection, and refresh state. PHYSICAL recno is the recorded anchor per the GPS prior art (owner pointer: see cmd_gps.cpp -- logical row is derived from physical under the active order, so physical is what restores exactly); GPS is the post-restore verifier. Old loaders skip the lines (tolerate-unknown, the KEY precedent) -- v2 coexistence preserved. Proof: Sales_Orders driven to BOTTOM (SO 6) with child slaved, session saved (9792 B = posture + 43 CURSOR lines + CURRENT), full teardown, reload -- '(+ 43 cursor(s))', GPS Area 21 Physical Recno 6 / Logical Row 6, SS_T1 parent at SO 6 not row 1, SS_T2 child re-slaved to Recno 11 through the load's own refresh. Writes catalog rows (append-history; reruns supersede). Requires workspaces/cascade_all.dtschema + the cascade_erp bundle. Explicit-run until soaked.workspace_session_state.dts - WORKSPACE_V3
[explicit]-- DTSHEMA 3 step 1 (owner-chartered 2026-08-11, promoted final test, runtime-proven same day, build 14:47:06): version 3 is v2 plus declarative lines -- FLAVOR (measured from the open areas at save time, never declared: versionByte 0x64/V128=X64, 0x30-32=VFP, V32=X32, disagreement=MIXED) and DBFROOT/IDXROOT/LMDBROOT (owner suggestion: the posture stores its own dbf/index/lmdb locations; LMDBROOT is recorded-not-applied, disk-only application chartered). v3 is opt-in per save (trailing V3 keyword, combinable with MEMO in either order); v2 remains the default so every proven producer and consumer is untouched -- the owner's no-blowing-up-2 rule, enforced by pairing this with WORKSPACE_MEMO green on the same build. The proof deliberately BREAKS the environment (SETPATH to the default roots) before the v3 load; restoration of all 13 MCC areas plus a readable STUDENTS row (V3_T1) proves the payload's roots -- not the environment -- resolved the tables, because the loader re-points its resolution roots at the payload's DBFROOT/IDXROOT lines for that load only (global SETPATH never mutated). Self-locating postures end the env-first fragility that made every workspace script SETPATH before LOAD. Writes catalog rows by design (append-history; reruns supersede). Requires workspaces/mcc_x64.dtschema + the x64 MCC tables. Explicit-run until soaked.workspace_v3_selflocate.dts
ddl (1; 0 default)
- DDL_SCHEMA
[explicit]-- DDL schema flavor smoke (AIF-063): creates classic MSDOS/DBASE and X64 throwaway tables from JSON schema fixtures, writes seed blanks through the DBF backend, reopens them from TMP, and self-asserts classic fields plus X64 long logical names. Emits sidecars and documents index declarations as metadata-only in this milestone. Mutates TMP only, so it stays out of the default suite (explicit run).ddl/ddl_schema_flavor_regression.dts(runtime script -- not in the public tree)
dotscript (8; 2 default)
- DOTSCRIPT_EXPR
[default]-- DotScript memvars (VAR/$name) + arrays ({}/$a[n], nested/chained) via the house expression path, with an IF literal baseline (AIF-041 M1)dotscript/dotscript_expr_regression.dts - DOTSCRIPT_PARITY
[default]-- Predicate parity target: $name/$a[n] in IF/WHILE/WHERE -- now GREEN via the shared house-evaluator bridge (AIF-041, landed 2026-07-21). Fixture-free, self-asserting; safe for the default suitedotscript/predicate_memvar_parity_regression.dts - BUILD_VECTORS
[explicit]-- Build-vector runtime report (AIF-044 M4): BUILDVECTORS prints the compiled capacity authority; GATE #1 proof (areas=512, fields=256, rows=int64max). Read-only, no fixture/mutation. Explicit-run until proven, then promote.dotscript/build_vectors_regression.dts - DEF_FAMILY
[explicit]-- Runtime DEF-family testbed: DEFCMD/DEFFN/EXAMPLE define-invoke-arg-compose-list-remove, session-only, no rebuild (RUNTIME_DEF_FAMILY lane). Self-bootstrapping; opens/mutates no table or file (only the session command/function registries, which it cleans up). Permanent worked example of the AI-friendly dev-tools. Explicit-run until proven green in-suite, then promote to default.dotscript/def_family_regression.dts - HELP_DIDYOUMEAN
[explicit]-- HELP unknown-topic feedback + did-you-mean (AIF-047 M1-M3): HELP GAINT -> 'No help found for: GAINT' + 'Did you mean: GIANT, ...' (soundex phonetic), HELP SELCT -> SELECT, HELP GIANT <unknown> shares the not-found terminal, and SOUNDEX("GIANT") still returns G530 after sharing its implementation with the suggester. Read-only, no mutation. Explicit-run until proven, then promote.dotscript/help_didyoumean_regression.dts - IDENTITY_ACCEPT
[explicit]-- AI-agent local-security accept cycle (AIF-045 2c): admits a throwaway AI member, proves the resolver DENIES git.commit, owner USER GRANT flips it to ALLOW, USER UNGRANT flips it back to DENY, then USER DELETE removes it. Repeatable + self-cleaning (deletes any leftover up front and at the end). Mutates only data/metadata/identity (adds+removes a throwaway member); seeded rows intact. Explicit-run until proven, then promote.dotscript/identity_accept_regression.dts - IDENTITY_PERSIST
[explicit]-- Identity/RBAC DBF persistence round-trip (AIF-045 2b-ii, APH-5): USER SAVE writes the nine SYS* identity tables, USER VERIFY reloads and confirms counts, user id/key/profile, and every member x permission authorize() verdict are preserved. Writes DBF under data/metadata/identity only; no fixture mutation. Explicit-run until proven, then promote.dotscript/identity_persistence_regression.dts - SCAN_PARITY
[explicit]-- Scan-path parity: $name resolves in a FOR/scan predicate (eval_bool: LOCATE/COUNT/SCAN/LIST FOR + SET FILTER) via the shared bridge. GREEN since the AIF-041 scan convergence landed (2026-07-21). Self-bootstrapping throwaway SCANREGR in SANDBOX; stays out of the default suite because it mutates the filesystem (explicit run) (AIF-041)dotscript/scan_memvar_parity_regression.dts
errorstop (1; 0 default)
- ERRORSTOP
[explicit]-- stop_on_error threshold: OFF continues past a recorded error, ERROR aborts at the failing line; self-contained, but Phase-2 aborts leaving STOP_ON_ERROR ON so it stays out of the default suite (explicit run) (AIF-036)errorstop/stop_on_error_regression.dts
export (1; 0 default)
- EXPORT_SDF
[explicit]-- EXPORT SDF smoke: creates a throwaway table in SANDBOX and exports fixed-width, space-padded records with TUPTALK PUSH ROW-compatible alignment. Explicit-run because it writes an output text file.export/export_sdf_regression.dts(runtime script -- not in the public tree)
lexing (1; 1 default)
- LEXING
[default]-- Canonical comment vocabulary on the script path after the AIF-037 lexer consolidation (full-line * REM # //, inline && #, single & macro survives); read-only, fixture-freelexing/comment_handling_regression.dts
limits (1; 0 default)
- LIMITS
[explicit]-- Engine limit guardrails: MAX_AREA=512, x64 name ceilings 256, record-size advisory, CLOSE ALL over every open arealimits/limits_all_shakedown.dts(runtime script -- not in the public tree)
main (2; 0 default)
- HARVEST
[explicit]-- Top-layer harvest proof across regression launcher, security roles, holiday demos, and curated runtime shakedownsmain/harvest_top_shakedown.dts(runtime script -- not in the public tree) - RELJOIN
[explicit]-- Relation join/enum projection regressionmain/rel_join_enum_regression.dts(runtime script -- not in the public tree)
migrated (1; 0 default)
- INDEX_TXN
[explicit]-- SET INDEXTXN transactional in-COMMIT index maintenance: buffered REPLACE/DELETE + COMMIT maintains the live CDX/LMDB index with NO BUILDLMDB. Self-asserting and fixture-free (builds + erases its own throwaway x64 IDXTXN table; never touches students). Scored on ORDERED position = index-truth (T1 commit-maintains, T2 dup-survivor): OFF => .F. (RED), ON => .T. (GREEN). Mode is env-driven (DOTTALK_INDEX_TXN) or runtime SET INDEXTXN; the script does not force the flag. Out of the default suite (mutates the filesystem; explicit run) (AIF-027/023; feeds AIF-041 M1)migrated/index_txn_lmdb_maintenance.dts(runtime script -- not in the public tree)
pinocchio (2; 0 default)
- PHASE0_DECODE_COST
[explicit]-- Scan-evaluator baseline benchmark (scan-evaluator optimization lane M0): self-times SUM GPA / COUNT FOR (1 term) / COUNT FOR (3 terms) over the 1,000,000-row pinocchio STUDENTS fixture via SET TIMER (now script-aware) cross-checked by fractional SECONDS(). Read-only, no mutation. Baseline floor (Alienware m16 R2 / Core Ultra 9 185H): SUM ~19.5s, DEC1 ~38.5s, DEC3 ~70.5s. NOT a pass/fail regression and long-running (~2+ min); requires the 1M-row pinocchio fixture. EXEMPT from REGRESSION ALL by design -- explicit run only, as the M1-M4 speedup floor. (scan-evaluator lane, origin AIF-043 Ticket B Phase-0 KILL)pinocchio/ticketb_phase0_decode_cost.dts - WAL_COMMIT_ROLLBACK
[explicit]-- WAL durability: COMMIT applies a buffered+logged REPLACE, ROLLBACK discards one; self-bootstrapping (creates+erases a throwaway WALREGR table, never touches the students fixture), self-asserting W0/W1/W2 markers. Mutates the filesystem so it stays out of the default suite (explicit run) (AIF-017/023)pinocchio/wal_commit_rollback_regression.dts
Python test scripts (60; tracked, CI-style)
bindings/pydottalk/src/test_table.pylabtalk/ai_portal/tests/test_audit_trail.pylabtalk/lms/tests/test_lms_pipe.pylabtalk/portal/tests/test_ai_report_audit.pylabtalk/portal/tests/test_output_acceptance.pylabtalk/portal/tests/test_runtime_paths.pytest_lmdb.pytools/cascade_erp/tests/test_generate_dual_schema_contract.pytools/comments/tests/test_reharvest_source_comment_catalog.pytools/coordination/test_session_coordinator.pytools/database_ecology/tests/test_database_ecology.pytools/dbf/tests/test_crud_logic.pytools/dbf/tests/test_schema_registry.pytools/fullstack_docs/test_analyze_manualgen_parity_delta.pytools/fullstack_docs/test_compare_help_meta_harvest.pytools/fullstack_docs/tests/test_apply_newline_reconciliation.pytools/fullstack_docs/tests/test_audit_manual_documentation_pointers.pytools/fullstack_docs/tests/test_audit_manual_publication_readiness.pytools/fullstack_docs/tests/test_build_current_work_feed.pytools/fullstack_docs/tests/test_build_historical_source_museum.pytools/fullstack_docs/tests/test_build_reference_identity_inventory.pytools/fullstack_docs/tests/test_build_website_feed_packet.pytools/fullstack_docs/tests/test_comments_help_promotion_preflight.pytools/fullstack_docs/tests/test_help_contract_continuation.pytools/fullstack_docs/tests/test_reference_authority_crosswalk.pytools/fullstack_docs/tests/test_supported_command_publication_coverage.pytools/fullstack_docs/tests/test_validate_pinocchio_benchmarks.pytools/fullstack_docs/tests/test_validate_syscmd_candidate.pytools/fullstack_docs/tests/test_validate_website_feed_packet.pytools/fullstack_docs/tests/test_validate_website_integration_plan.pytools/gui_preview/test_gui_backend.pytools/manualgen/tests/test_assembly_workspace_selection.pytools/manualgen/tests/test_command_reference_candidate.pytools/manualgen/tests/test_controlled_acceptance.pytools/manualgen/tests/test_controlled_acceptance_apply.pytools/manualgen/tests/test_gate4_acceptance_apply.pytools/manualgen/tests/test_gate5_development_apply.pytools/manualgen/tests/test_gate5_development_plan.pytools/manualgen/tests/test_gate5_source_gap.pytools/manualgen/tests/test_manual_catalog_cli.pytools/manualgen/tests/test_prose_review.pytools/manualgen/tests/test_reference_candidate.pytools/manualgen/tests/test_selective_merge.pytools/memory/test_consolidate.pytools/memory/test_promote.pytools/reports/test_bbs_auth_relay.pytools/reports/tests/test_build_reports_closed_lanes.pytools/reports/tests/test_serve_dynamic_reports.pytools/selfdoc/tests/test_documentation_lineages.pytools/selfdoc/tests/test_maint_documentation_parity.pytools/selfdoc/tests/test_metadata_system_registry.pytools/selfdoc/tests/test_reference_identity_authority.pytools/selfdoc/tests/test_source_contract_vocabulary.pytools/source_objects/tests/test_source_objects.pytools/staging/test_create_public_baseline_escrow.pytools/staging/test_execute_gate5_staging_rebuild.pytools/staging/test_plan_gate5_staging_overlay.pytools/staging/test_preserve_staging_worktree.pytools/staging/test_repository_role_guard.pytools/tracking/tests/test_seed_tracking.py
{/* regression-index:end */}
Proof transcripts
Correctness-critical changes are bound to a hash-verified teed transcript: the
run's full output is captured to a log and its SHA-256 recorded, so a result is a
durable artifact rather than a recollection. Recent examples include the
table-buffer WAL durability phases and the Pinocchio scale-verb fixes; the
repository retains dozens of these run logs under labtalk/proofs/runs/.
This is the same discipline the documentation pipeline uses: a claim is
runtime-proven only when a captured, hash-bound transcript backs it.
Build-integrated tests
The CMake build registers CTests (via include(CTest) / add_test) that run
as part of the build — for example the xBase physical-order proof matrix and the
pydottalk contract smoke — so structural regressions surface at build time, not
only through the shell launcher.
Scale and fault injection — Pinocchio
The Pinocchio lane is the disposable stress-test surface: million-row datasets, ordered-navigation and scale-verb benchmarks, and the Phase 2 fault-injection work (the buffered-lane durability WAL is the first delivered slice). Its data, tables, and indexes stay isolated from protected project data.