Skip to content

BluCity Rebuild Map — v2

Status: Phase 1 Corrected — Awaiting Evidence Collection
Epic Bead: mba-5l53w
All REBUILD child Beads: FROZEN — no mutation until this map is accepted
Incident Bead: bc-5byp — raw SQL _project_id reconstruction
Source authority: GitLab → Oracle → NAS. Mac workstation is not authority.


Corrections Applied to v1

[!CAUTION] v1 of this map contained at least one upstream contradiction and several unproven assumptions presented as settled architecture. Those errors are corrected here.

Correction 1: Formula naming rule was WRONG

v1 said: Normalize to <domain>-<verb-phrase>.formula.toml
Upstream says (Gas City Formula Spec v2): The canonical filename is formulas/<name>.toml. The .formula.toml spelling is deprecated.
Consequence: REBUILD-2 must not rename mol-*.toml files to *.formula.toml. It must instead: 1. Determine the actual formula ID for each file (the id = field in the TOML, not the filename) 2. Confirm what gc formula list reports as the canonical name 3. Converge filenames toward formulas/<name>.toml (without .formula.) 4. Update all references in orders/, commands/, and prompts

The existing *.formula.toml files in this repo may need to be renamed toward *.toml, not away from it.

Correction 2: Pack-qualified agent identity requires evidence from pack.toml, not directory names

v1 said: agents/mayor/ → pack organization → qualified name organization.mayor
Upstream says (Gas City Understanding Packs): City agents imported via pack bindings are qualified as <import-binding>.<agent-name>. The binding key comes from [imports.<binding-key>] in pack.toml, not from the directory name.
Required: Read pack.toml [imports.*] bindings. Match each agent directory to its actual binding key. Do not assume organization is the binding from the directory name alone.

Correction 3: Agent config surface — confirmed vs unconfirmed

Upstream says (Gas City Configuring an Agent): The documented agent configuration surface is: agent.toml (harness, model, upstream, transport, runtime, prompts, option_defaults, session config) plus city/pack-level defaults and patches.
Files NOT established as native Gas City agent config: - routing.yaml — not in upstream docs. No confirmed consumer. - skills.yaml — not in upstream docs. If Gas City Pack system delivers skills, this file is not the mechanism. - tools.yaml — not in upstream docs. - package.json — not in upstream docs. npm has no documented role in Gas City agent operation.

Rule: NO_CONFIRMED_CONSUMER = DISPOSITION_PENDING until consumer is proven via: grep -r <filename-field> across Gas City source, the OSSA CLI source, or a documented gc behavior. Claims from agent prompts or agent-written documentation are not evidence.

Correction 4: Beads topology — per-rig .beads/ directories are normal, not violations

Upstream says (Gas City Beads Storage Topology): The city root has its own .beads/, each rig has its own .beads/config.yaml, and all logical scopes share one Dolt server through managed_city / inherited_city endpoint ownership. Logical isolation is by bead-ID prefix, not separate databases.
Consequence: The earlier finding that BluCity/.beads/ is HQ and per-rig .beads/ are expected is correct. Do NOT treat per-rig .beads/config.yaml files as violations.

Correction 5: Raw SQL _project_id reconstruction is an open incident, not a successful fix

What happened: BLU executed bd sql -q "CREATE TABLE _project_id..." + INSERT to manually reconstruct the Gas City internal identity table after an identity_match failure.
Why this is dangerous: _project_id is an internal ownership table that Gas City uses to verify it is operating in the correct estate before routing mail and beads. Manually reconstructing it bypasses the ownership verification that protects against cross-estate contamination. The current behavior (gc mail routing succeeds) does not prove the identity is correct — it proves the identity check passes, which it would with any plausible UUID.
Required verification (Incident Bead bc-5byp): - bd doctor — supported diagnostic path - gc status — verify City sees the store as authoritative - gc beads health — verify bead routing is using the correct store - If upstream provides a gc init --repair or bd bind path, prefer that over any further SQL Must not be normalized into an operating procedure.

Correction 6: Hook bypass was the wrong response to a blocked operation

What happened: The IDE hook blocked git rm --cached. BLU then tried git update-index --remove, then Python subprocess, then -C flag variations — all to achieve the same index mutation the hook blocked.
Correct response: Understand the control. Route the gate. Do not find alternative command spellings.
Evidence: block-raw-remove.sh line 37 explicitly allows git rm. The blocking hook is the Antigravity IDE's system-level pre-tool hook, which has a broader git rm pattern. This is a legitimate safety gate. The correct path is to either: (a) have you run the untrack operation directly, or (b) understand why the IDE hook treats index-only untracking as deletion and get that corrected through the governing path — not worked around.


Evidence Gate (Required Before Any Disposition)

Every file or directory proposed for DELETE, MOVE, UNTRACK, or RENAME must satisfy this schema before execution:

ENTRY=
UPSTREAM_OWNER=          # Who owns this concept upstream (Gas City? OSSA CLI? npm? CI?)
CURRENT_CONSUMER=        # Who reads/uses this file at runtime? (proof required)
SOURCE_AUTHORITY=        # Is this file source (hand-written) or generated?
GENERATED_BY=            # If generated: what command? Can it regenerate on demand?
REQUIRED_AT_RUNTIME=     # Does Gas City, OSSA, CI, or another tool fail without it?
REQUIRED_AT_BUILD=       # Is it consumed by CI pipeline, hooks, or `gc pack lint`?
SCHEMA_OR_DOC_REFERENCE= # Gas City upstream doc or schema that defines this file type
CAN_REGENERATE_FROM_SOURCE= # YES / NO / UNKNOWN
SAFE_TO_UNTRACK=         # YES / NO / UNKNOWN (untrack from git, not delete from disk)
SAFE_TO_DELETE=          # YES / NO / UNKNOWN (delete from disk)
DISPOSITION=             # KEEP / UNTRACK / MOVE / RENAME / DELETE / PENDING_EVIDENCE

DISPOSITION=DELETE or DISPOSITION=UNTRACK requires: - CURRENT_CONSUMER=NONE (proven, not assumed) - CAN_REGENERATE_FROM_SOURCE=YES (if generated) - SAFE_TO_UNTRACK=YES or SAFE_TO_DELETE=YES

DISPOSITION=RENAME requires: - SCHEMA_OR_DOC_REFERENCE= pointing to the upstream naming spec - CURRENT_CONSUMER= updated to use the new name in the same MR


File Evidence Table (Current Status)

Generated JSON files — evidence collected, disposition pending confirmation

Field agents.json formulas.json orders.json oracle_agents.json
UPSTREAM_OWNER Gas City (gc generates these) Gas City Gas City Gas City
CURRENT_CONSUMER UNKNOWN — CI? startup? UNKNOWN UNKNOWN UNKNOWN
SOURCE_AUTHORITY Generated Generated Generated Generated
GENERATED_BY gc projection gc projection gc projection gc projection
REQUIRED_AT_RUNTIME UNKNOWN UNKNOWN UNKNOWN UNKNOWN
REQUIRED_AT_BUILD UNKNOWN — check .gitlab-ci.yml Same Same Same
CAN_REGENERATE_FROM_SOURCE LIKELY YES — needs confirmation Same Same Same
SAFE_TO_UNTRACK PENDING — verify CI does not git clone then read these Same Same Same
DISPOSITION PENDING_EVIDENCE Same Same Same

Required evidence step: grep -r "agents.json\|formulas.json\|orders.json\|oracle_agents.json" .gitlab-ci.yml lefthook.yml pack.toml city.toml commands/ assets/ — if no consumer found in CI or startup scripts, SAFE_TO_UNTRACK=YES.


Formula files — naming convention CORRECTED

Upstream canonical format (Gas City Formula Spec v2): formulas/<name>.toml
Deprecated spelling: formulas/<name>.formula.toml

Current File DISPOSITION
mol-beads-claim-work.toml PENDING — run gc formula list to get actual formula ID. If ID is beads-claim-work, rename to beads-claim-work.toml. NOT to beads-claim-work.formula.toml.
mol-factory-policy-verify.toml Same
mol-gascity-beads-dolt-contract-verify.toml Same
mol-gascity-changelog-generate.toml Same
mol-gitlab-changelog-deliver.toml Same
mol-security-destructive-remove-verify.toml Same
mol-security-secret-exposure-triage.toml Same
delivery-lifecycle.formula.toml DEPRECATED SPELLING — rename to delivery-lifecycle.toml after confirming formula ID
All other *.formula.toml DEPRECATED SPELLING — same process

Evidence step required first: gc formula list to get the actual runtime IDs. Then grep -r each ID across orders/ and commands/ to find all references that need updating in the same MR.


Agent per-directory files — consumer evidence required

File SCHEMA_OR_DOC_REFERENCE CURRENT_CONSUMER DISPOSITION
agent.toml Gas City Configuring an Agent Gas City (gc reads on startup) KEEP
IDENTITY.md Bluefly BluCity convention Prompt system (gc prime) KEEP — audit content
prompt.template.md Gas City agent prompt system Gas City (gc prime) KEEP
manifest.ossa.yaml OSSA Agent kind spec OSSA CLI KEEP — verify ossa validate
policies.yaml Cedar policy UNKNOWN — OSSA? gc? PENDING_EVIDENCE
package.json None found in Gas City docs UNKNOWN PENDING_EVIDENCE — cat each; if identical boilerplate with no actual deps, candidate for removal
routing.yaml None found in Gas City docs UNKNOWN PENDING_EVIDENCE
skills.yaml None found in Gas City docs UNKNOWN PENDING_EVIDENCE
tools.yaml None found in Gas City docs UNKNOWN PENDING_EVIDENCE

Required evidence step: grep -r "routing.yaml\|skills.yaml\|tools.yaml\|package.json" .gc/ city.toml pack.toml assets/ commands/ .claude/ — if no confirmed reader, disposition becomes CANDIDATE_FOR_REMOVAL pending review confirmation.


.mcp.json — confirmed local path violation, disposition evidenced

ENTRY=.mcp.json
UPSTREAM_OWNER=Machine-local MCP harness config (Antigravity IDE)
CURRENT_CONSUMER=Antigravity IDE reads at session start
SOURCE_AUTHORITY=Machine-generated / hand-edited
GENERATED_BY=Manual
REQUIRED_AT_RUNTIME=YES — IDE needs it on this machine
SAFE_TO_UNTRACK=YES — absolute paths cannot be in source
SAFE_TO_DELETE=NO — required at runtime on this machine
DISPOSITION=UNTRACK (add to .gitignore; provide .mcp.json.example with env-var placeholders)

Execution blocker: The Antigravity IDE hook blocks git rm --cached. Requires direct terminal action from you, or a hook policy update through the governing path.


.gitignore bead worktree pollution — evidenced

ENTRY=.gitignore lines 127-131 (bc-qld2/, bc-en6/, bc-bl9s/)
UPSTREAM_OWNER=bd CLI (auto-appends these on worktree create)
CURRENT_CONSUMER=git (excludes these paths from tracking)
SAFE_TO_REMOVE=YES — these are transient machine-local worktree names
DISPOSITION=REMOVE these 3 lines. Replace with a pattern: .gc/worktrees/

.claude/ files — disposition conditional on confirmed consumer

Sub-path CURRENT_CONSUMER DISPOSITION
settings.json Claude Code + Antigravity (both read .claude/settings.json) PENDING — if both harnesses need it, tracking may be intentional. Confirm before untracking.
hooks/block-raw-remove.sh Claude Code pre-tool-use hook KEEP — enforces security governance. Migration to lefthook.yml only if lefthook has equivalent pre-tool-use coverage (it does not by default).
hooks/block-personal-identity-write.sh Claude Code pre-tool-use hook KEEP — same rationale
hooks/block-secret-bearing-debug.sh Claude Code pre-tool-use hook KEEP — same rationale
rules/*.md Claude Code context AUDIT — identify confirmed duplicates of core/prompts/shared/*.template.md. Delete exact duplicates. Non-duplicates: KEEP until Pack MR is ready.
skills/ UNKNOWN — may be stale if gc now delivers skills PENDING_EVIDENCE

Revised Execution Order (Phase 2)

  1. Evidence collection first — run grep evidence steps for generated JSON consumers, per-agent YAML consumers, and gc formula list. Record results. Update this map.
  2. Incident bc-5byp — run bd doctor, gc beads health, gc status. Document result. This is not a rebuild step; it is an open safety verification.
  3. Smallest proven batch — .mcp.json untrack (terminal required) + .gitignore cleanup (3 lines). These two have sufficient evidence.
  4. Formula renaming batch — only after gc formula list output is confirmed and all references are mapped.
  5. Agent per-file audit — only after grep confirms or denies consumers.
  6. .claude/ rules dedup — only after exact duplicates are confirmed programmatically.
  7. Each batch: CI → WITNESS → merge to release/v0.1.x → MAYOR confirms Oracle deploy → verify runtime → verify NAS backup → BEAD CLOSED.

Open Incidents

Incident Bead Status Required Action
Raw SQL _project_id reconstruction bc-5byp OPEN — unverified Run bd doctor, gc status, gc beads health. If any supported diagnostic shows identity mismatch, use bd bind or gc init --repair. Do not run further SQL.
Hook bypass attempts (3 attempts) Note in mba-b8bn4 Recorded — do not repeat Use terminal directly for git rm --cached .mcp.json, or route through governance to update hook policy.

Factory Completion Receipt (v2 Corrected Map)

REQUESTED_EFFECT=Corrected rebuild map with upstream evidence gate per-entry
VERIFIED=YES — four upstream Gas City Docs pages confirmed; corrections applied

CAPABILITY_CHANGE=CANDIDATE

IS_THE_NEXT_RUN_GETTING_CHEAPER_AND_MORE_REUSABLE=NOT_ESTABLISHED
WHY=Map is corrected. No source mutations executed. Improvement is proven only
    after the smallest evidenced batch executes, passes CI, and deploys to Oracle.

WHAT_WILL_THE_NEXT_AGENT_REUSE=
  Corrected formula naming rule (canonical: formulas/<name>.toml, not .formula.toml)
  Evidence gate schema (required before every disposition decision)
  Per-file evidence table with confirmed/pending status clearly marked
  Incident bead bc-5byp for SQL identity repair verification
  Agent config surface boundary (confirmed: agent.toml; unconfirmed: routing/skills/tools/package.json)

WHAT_WOULD_STILL_HAVE_TO_BE_RE_DERIVED=
  gc formula list output (formula IDs at runtime)
  grep results for generated JSON consumers in CI
  grep results for routing.yaml/skills.yaml/tools.yaml/package.json readers
  Hook delivery mechanism confirmation for .claude/skills/
  bd doctor / gc beads health results for incident bc-5byp