Read one saved check beside an authored objective

Author a disposable plan, run a finite saved check, and inspect its retained result beside the exact criterion you defined. See what changes when the evidence expires or the requested record is missing.

What happens

Maude new/save/lock → objective-read → exact authored condition IDs
Nightshift finite schedule → Monitor acquisition → NQ saved evaluation
exact condition ID + retained NQ evaluation → application-owned reader
                                          → Phosphor objective-detail/v2
                                          → fresh, stale and missing-ID reads

The caller explicitly maps the first Maude criterion to one NQ saved-check definition and requires factual outcome passed. The disposable queue contains work, so the actual retained outcome is failed. Phosphor preserves that outcome, currentness and maintenance annotation separately. It does not parse criterion prose into a rule.

The script identifies its Maude submitter metadata as synthetic_agent and agent_generated. That describes this deterministic example input; it is not an external reviewer, provider call, Standing, authorization or execution identity.

Capabilities and boundaries

This use case requires Maude objective authoring/read, Nightshift finite scheduling, Monitor acquisition, NQ saved-check evaluation and retained condition reads, the application-owned reader, and Phosphor objective assembly. Other owners such as AG campaign history or Docket attempt custody are optional inputs to the wider objective view and are not needed here. The example supplies an empty real campaign directory; it does not replace an owner response with a fixture.

The reader's mapping and single prerequisite declaration are caller-owned application facts. NQ owns the retained evaluation, not the meaning of the Maude criterion. No result here establishes objective completion, application health, human review, permission, Standing, AG/Docket action, or a new effect.

Additive occurrence check: current public AG source includes a read-only exact-occurrence checker for a response that also has owner-minted Maude, Nightshift, AG and Docket links. It keeps objective state, currentness, custody and future authority separate. This site also includes a bounded capture wrapper: it reads one exact loopback objective endpoint, retains the response create-only, and runs digest-bound checker bytes from a sealed local descriptor. The wrapper does not assemble those owner records. These helpers are newer than immutable alpha.3; their publication does not mean the multi-owner consumer journey has run.

Exact public sources

Use Linux x86-64, Git, curl, a C compiler/linker, Rust/Cargo 1.94.0, and Python 3.12 with venv and SQLite. The runtime and example kit have distinct pins:

The example script is deliberately downloaded from the kit pin; it is not assumed to exist in the runtime checkout.

The source guide records development status at its frozen commit. This release records the subsequent public-only qualification; its manifest pins the runtime, kit and public Python wheels separately.

SETUP=$(mktemp -d /tmp/objective-saved-check-setup.XXXXXX)
git clone https://github.com/unpingable/constellation-ag.git "$SETUP/ag"
git -C "$SETUP/ag" checkout --detach deac918c2ad95b8205f293393874adb8eb12fe26
git clone https://github.com/unpingable/maude.git "$SETUP/maude"
git -C "$SETUP/maude" checkout --detach abaac51003b29ba8cefddc41ffbdcd018b732212
git clone https://github.com/unpingable/constellation-nq.git "$SETUP/nq"
git -C "$SETUP/nq" checkout --detach e259852ed58b8c0bf65a629b3c494afba28d9ce9
git clone https://github.com/unpingable/constellation-nightshift.git "$SETUP/nightshift"
git -C "$SETUP/nightshift" checkout --detach 019e6837565ebf5b0ac244cbd7c3edde28e25aea

curl --fail --location --proto '=https' --proto-redir '=https' \
  https://raw.githubusercontent.com/unpingable/constellation-ag/24792116bfba06f17700a57dc96153c4b40c37f6/examples/objective-owner-composed.py \
  --output "$SETUP/objective-owner-composed.py"
curl --fail --location --proto '=https' --proto-redir '=https' \
  https://raw.githubusercontent.com/unpingable/constellation-ag/24792116bfba06f17700a57dc96153c4b40c37f6/examples/objective-owner-composed.md \
  --output "$SETUP/objective-owner-composed.md"
printf '%s  %s\n' e7a02a589e4a9ab4af0a328b7901aa0d3e0ebcb0d8576158e64a20000d7f8098 \
  "$SETUP/objective-owner-composed.py" | sha256sum -c -
printf '%s  %s\n' cd07d9359424266ab3e0028351a4cb3116150974ee561883bcfc364d181a1cf9 \
  "$SETUP/objective-owner-composed.md" | sha256sum -c -
chmod 700 "$SETUP/objective-owner-composed.py"

python3 -m venv "$SETUP/maude-venv"
curl --fail --location --proto '=https' --proto-redir '=https' \
  https://unpingable.com/constellation/releases/0.1.0-alpha.3/python-requirements.txt \
  --output "$SETUP/python-requirements.txt"
printf '%s  %s\n' b431381b9e0f3b258d82680f5c92940996fc4af9902c5d4325dd04a537ee657d \
  "$SETUP/python-requirements.txt" | sha256sum -c -
"$SETUP/maude-venv/bin/pip" install --require-hashes --only-binary=:all: -r "$SETUP/python-requirements.txt"
"$SETUP/maude-venv/bin/pip" install --no-deps --no-build-isolation "$SETUP/maude"
"$SETUP/maude-venv/bin/pip" check
export CARGO_BUILD_JOBS=2 CARGO_INCREMENTAL=0 CARGO_PROFILE_DEV_DEBUG=0
CARGO_TARGET_DIR="$SETUP/ag-target" cargo +1.94.0 build --locked --manifest-path "$SETUP/ag/Cargo.toml" -p ag-operator-ui -p ag-app --bin ag-operator-ui --bin ag-loopctl
CARGO_TARGET_DIR="$SETUP/nq-target" cargo +1.94.0 build --locked --manifest-path "$SETUP/nq/Cargo.toml" -p nq-app --bin nq
CARGO_TARGET_DIR="$SETUP/nightshift-target" cargo +1.94.0 build --locked --manifest-path "$SETUP/nightshift/runtime/Cargo.toml" -p nightshiftd --bin nightshift
CARGO_TARGET_DIR="$SETUP/monitor-target" cargo +1.94.0 build --locked --manifest-path "$SETUP/nightshift/integrations/monitor-predicate-support/Cargo.toml" --bin monitor-concerns

Builds need public dependency access; the finite run needs no external network, provider credential, webhook, pre-existing service or container. The caller starts a temporary loopback Phosphor server for each read, then terminates and reaps it. Confirm both Python paths can import SQLite as shown in the alpha.2 guide. Keep the selected executable pathnames quiescent through the run and record their hashes.

Plan build capacity before allocating targets. Recent public debug targets occupied approximately 532 MiB for AG, 570 MiB for NQ, 282 MiB for Nightshift and 376 MiB for Monitor—about 1.8 GiB together, before source trees, registry/toolchain caches and retained run data. Those observations are estimates, not allocation enforcement or a promise about a fresh host. Check free blocks and inodes on the actual destination, account for other active work and preserve the host's required reserve before building.

Start the finite example

Choose an absent absolute root whose final name begins objective-owner-composed-, and an unused loopback port. The caller is create-only. This read-only probe checks whether the proposed port can be bound, then closes it without touching an existing process:

python3 -c 'import socket; s=socket.socket(); s.bind(("127.0.0.1", 28456)); s.close()'

A successful probe is not a reservation: another process can bind the port before the caller does. If the caller reports the port unavailable, inspect the process you own and choose another unused port; do not terminate or replace an unrelated listener.

"$SETUP/objective-owner-composed.py" \
  --root "$SETUP/objective-owner-composed-demo" \
  --maude "$SETUP/maude-venv/bin/maude-plan" \
  --nq "$SETUP/nq-target/debug/nq" \
  --nightshift "$SETUP/nightshift-target/debug/nightshift" \
  --monitor "$SETUP/monitor-target/debug/monitor-concerns" \
  --saved-check-example "$SETUP/nightshift/runtime/examples/saved-check-recurring.py" \
  --project-example "$SETUP/nightshift/integrations/monitor-predicate-support/examples/local-queue-attention.py" \
  --reader "$SETUP/ag/examples/phosphor-objective-owner-reader" \
  --operator-ui "$SETUP/ag-target/debug/ag-operator-ui" \
  --ag-loopctl "$SETUP/ag-target/debug/ag-loopctl" \
  --reader-revision deac918c2ad95b8205f293393874adb8eb12fe26 \
  --port 28456

The caller can approach six minutes because it waits through the actual 120-second NQ currentness interval. It bounds product streams and HTTP bodies, uses no automatic retry, terminates and reaps its temporary Phosphor server, and checks measured retained files at the end. Run it attended, or use a durable supervisor and checkpoint that survive loss of the terminal.

Expected reads

ROOT="$SETUP/objective-owner-composed-demo"
python3 -m json.tool "$ROOT/maude-objective.json"
python3 -m json.tool "$ROOT/fresh-objective.json"
python3 -m json.tool "$ROOT/stale-objective.json"
python3 -m json.tool "$ROOT/missing-evaluation-objective.json"
python3 -m json.tool "$ROOT/result.json"

Retain, stop and recover

Keep the exact root, commands.jsonl, plan/store, reader configurations, server identity and terminal records, and the complete saved-check directory. Each Phosphor read also retains <label>-server-stdout.log and <label>-server-stderr.log. Each stream is bounded to 1 MiB; when a server emits more, the retained file is explicitly a prefix and the terminal diagnostic marks it truncated. The matching terminal record reports per-stream byte counts, truncation and completeness plus any bounded error. An incomplete capture refuses rather than becoming a successful objective read. These records improve reconciliation but do not guarantee survival of supervisor loss.

Read the transcript as a sequence of labels and lifecycle events. A planned entry proves only that the caller intended a command. A matching started entry adds its process identity. Only the matching terminal entry supplies captured exit status and bounded output. If a started label lacks a terminal entry, first reconcile that exact process and its owner records. Preserve the root as uncertain if neither process nor owner outcome can be established; do not infer failure or rerun the create-only caller.

For a completed saved-check producer, extract the exact later evaluation ID from its retained nested transcript, then perform these wrapper-specific read-only inspections:

ROOT="$SETUP/objective-owner-composed-demo"
STATE="$ROOT/nightshift-saved-check-run-objective"
EVALUATION_ID=$(python3 -c 'import json,sys
for line in open(sys.argv[1], encoding="utf-8"):
    record=json.loads(line)
    if record.get("label")=="nightshift-next-slot" and record.get("exit_code")==0:
        print(json.loads(record["stdout"])["evaluation_id"]); break
else: raise SystemExit("no terminal nightshift-next-slot evaluation")' "$STATE/commands.jsonl")

"$SETUP/nightshift-target/debug/nightshift" --store "$STATE/nightshift.sqlite" \
  saved-check inspect --evaluation-id "$EVALUATION_ID"
"$SETUP/nightshift-target/debug/nightshift" --store "$STATE/nightshift.sqlite" \
  saved-check attention-status --policy "$STATE/attention-policy.json" \
  --evaluation-id "$EVALUATION_ID"
AT=$(date -u +%Y-%m-%dT%H:%M:%SZ)
"$SETUP/nq-target/debug/nq" --config "$STATE/nq.toml" --json \
  saved-check condition --evaluation-id "$EVALUATION_ID" \
  --component disposable-queue --kind saved-check --subject queue --at "$AT"

# List retained notification custody when the final notification ID was omitted.
"$SETUP/nq-target/debug/nq" --config "$STATE/nq.toml" --json \
  notification inspect

The --at value is the actual present read coordinate; never choose an earlier time to make retained evidence appear fresh. These commands inspect existing custody and do not repeat acquisition, evaluation or delivery. If the expected terminal label or evaluation ID is absent, preserve the state and stop instead of inventing an ID.

If output is lost, reconcile existing process identity and retained owner records before doing anything new. The missing-ID control does not erase the actual evaluation: inspect the original ID and NQ custody rather than rerunning the producer. Do not rerun this create-only caller over an existing or uncertain root. This guide does not validate supervisor-loss recovery, uncertain execution, interrupted delivery, migration, restoration or retention rollover.

After all processes have stopped, and only when no evidence, diagnosis, replay or recovery dependency remains, visually verify and remove the one exact disposable root. Do not use a variable, glob, setup parent or repository path:

rm -rf -- /tmp/objective-saved-check-setup.EXACT/objective-owner-composed-demo

A successful run can log operator UI request failed: empty request from the caller's TCP readiness probe. Check the subsequent objective JSON and complete capture record before classifying that line as a failed read. The server's -15 terminal return code here records its deliberate stop after capture, not the saved-check outcome.

For support, report suite 0.1.0-alpha.3, profile objective-saved-check-read/v1, the four runtime repository revisions, the separate kit revision and both kit hashes, tool versions, the exact command and a minimal redacted diagnostic excerpt through Troubleshooting. Do not send credentials, operator-only plan prose, full databases or unrelated retained records. Experimental support is best effort, with no guaranteed response time.