# Modular Runtime — Goal-to-Graph Production Entry 01

Date: 2026-08-01

Status: accepted; one unattended production-entry run admitted and completed a direct task, a parallel backend graph, and a dependency-ordered visual UI graph. Legacy remains the production authority.

## Claim

The `/vnext` production boundary no longer stops at direct work. One typed Sol proposal is deterministically admitted as either a direct lane or one of the existing bounded graph recipes. The admitted plan is persisted before execution, then consumed by the same tested direct controller, graph coordinator, resource broker, recipe modules, acceptance adapters, integration queue, and long-horizon machinery used by the earlier canaries. No second scheduler, workflow DSL, graph database, or model-owned state writer was added.

This audit proves the production-entry seam. It does **not** authorize or claim the final `legacy -> modular` production-authority transition.

## Production seam

The accepted path is:

```text
ProjectRequest
  -> read-only Sol goal proposal
  -> schema + semantic validation
  -> deterministic lane / recipe admission
  -> durable AdmittedProjectPlan
  -> direct executor | graph project executor
  -> existing acceptance + integration authority
  -> queryable terminal evidence
```

The proposal contract binds the exact workspace base, product contract, decisions, work ownership, dependency edges, model-call floor, acceptance commands, and recipe choice. Admission rejects unknown recipes, invalid graph structure, incompatible versions, invented authority, shell-bearing acceptance commands, and worker-owned Git mutations. Product vocabulary such as a CSS reset remains legal; only actual Git reset, merge, rebase, stage, commit, or worktree authority is forbidden in a Luna packet.

## Current-revision live run

The gated production-entry canary ran through the real HTTP runtime with no intermediate operator checkpoint:

```sh
RUN_LIVE_PRODUCTION_ENTRY=1 \
NYX_PRODUCTION_ENTRY_EVIDENCE_DIR=.nyx/evidence/production-entry-vnext-01 \
pnpm exec vitest run --workspace vitest.nyx-core.config.ts --project nyx-core \
  apps/moderator/src/modular/__tests__/live-production-entry.test.ts
```

Result: 1/1 accepted in 783.879 seconds.

| Project | Admitted lane | Bounded work | Terminal result | Authoritative head |
|---|---|---|---|---|
| `entry-direct-01` | direct | one exact greeting implementation surface | completed | `23696d91100dd5b3e37bc1bdd261e055b5c45206` |
| `entry-backend-graph-01` | graph | one accepted contract root plus two compatible backend nodes | completed | `ac8ccd083e1c148972a6fd186375add5c699bb91` |
| `entry-ui-graph-01` | graph | accepted contract root, Helios foundation, then caregiver home | completed | `807071817012fa034b8bc7f520b0d50e066a8072` |

The direct repository contains exactly one accepted commit. The backend repository contains three commits, and the UI repository contains two. Every repository ended clean. Both final graphs contain one accepted terminal compacted summary, their integration head equals Git authority, and their lease lists are empty. No runtime fault, orphan, unresolved retry, or operator checkpoint was recorded.

The sealed plan hashes are:

- direct: `d4679619a3ea32f0af9b0fe3b3970df11cc5936b5a065bb2038d5de25f11c2b9`;
- backend graph: `da155b6a25d8566180d1d4b07f49bef6c7d99980851bc78afc568dfe66496aa5`;
- UI graph: `015867225be772f0d30e09421e8dba7bd0409bb9ebc7c8ed4f8d974275149c58`.

## Running-product proof

UI acceptance used the real localhost product, not detached HTML or a model self-report. The trusted host supplied the loopback host and allocated port, started the declared preview command directly, waited for readiness, captured exact selectors with Chrome at 402 x 874, checked fonts, console health, and horizontal overflow, and then reaped the entire process family. A fresh read-only Sol reviewer judged the immutable captures against the product and visual contracts.

| Work item | Capture | SHA-256 | Result |
|---|---|---|---|
| `helios-foundation` | `foundation-mobile.png` | `1e1e073bfc75bcef51a16dd56316f9d52b455a3c85534085497fbe27392ad281` | accepted; zero console errors, no overflow |
| `robert-caregiver-home` | `pending-home.png` | `ec4eec910020c04e2410ab22da3da92674006863740caafa5a9e9ec594064ef7` | accepted; stable Helios/Robert shell and navigation |
| `robert-caregiver-home` | `completed-home.png` | `0d0d69f93eaa97a7b3db28217f3d19085725bb13916ceb746735f19e36e876c7` | accepted; only the next-action region changes |

The accepted UI is light-only and product-specific: true white canvas, near-black neutral sans typography, soft sun yellow, precise outlines, purposeful radii, and no beige canvas, dark mode, decorative live pulse, glass, gradient, glossy AI ornament, or fancy serif typography.

## Diagnostic history retained

The accepted run was reached by tightening the real contracts rather than weakening them:

1. An unsupported `uniqueItems` shape in the model schema was removed in favor of host-side uniqueness validation.
2. A model-proposed `env NAME=value command` preview was deterministically rejected and replanned as a direct command; trusted host code owns `PORT` and `HOST` injection.
3. An earlier cream/pastel visual result was rejected. Its retry adopted the binding true-white, restrained-yellow Helios contract and passed fresh Sol review.
4. The canary initially counted all historical visual-review rows rather than the latest attempt per work item. The assertion was corrected to preserve rejected history while judging terminal truth.
5. A semantic guard initially confused product phrases such as “CSS reset” with Git reset authority. The guard was narrowed to explicit Git context while retaining deterministic rejection of commit, stage, rebase, merge, reset, and worktree mutation.

These failures remain useful evidence: proposal repair is bounded, visual rejection prevents promotion, historical rows remain immutable, and deterministic policy can become more precise without granting Luna Git authority.

## Evidence integrity

The preserved bundle lives at [`evidence/MODULAR_RUNTIME_GOAL_GRAPH_INTAKE_01`](./evidence/MODULAR_RUNTIME_GOAL_GRAPH_INTAKE_01/).

`run-summary.json` SHA-256:

```text
29fcf15e7a7380d13218888695de0b16626b73b81f1c27bd5cce26f2871f6db7
```

Running `shasum -a 256 -c evidence.sha256` inside the evidence directory succeeds. The stored PNG bytes match every hash embedded in the corresponding fresh Sol review.

## Regression boundary

After the live run:

- 268 modular-package tests passed across 57 active files; 20 gated live tests were skipped in the deterministic lane;
- 239 moderator and production-boundary tests passed across 42 active files; the live entry test remained gated in that lane;
- both TypeScript builds passed without diagnostics;
- 93 modular and moderator-entry source files average 180 logical lines, p50 144, p90 361, with a 494-line maximum and no local import cycle.

The authority-bearing kernel now measures 6,592 logical lines when deterministic admission is included. This is 592 lines above the initial 6,000-line target. The required responsibility-by-responsibility review accepted a temporary bounded exception with explicit expiry and removal triggers; it found no duplicate authority mechanism safe to remove before transition. See [`MODULAR_RUNTIME_KERNEL_BUDGET_REVIEW_01.md`](./MODULAR_RUNTIME_KERNEL_BUDGET_REVIEW_01.md).

## Remaining boundary

The production selector still defaults to `legacy`. The isolated modular entry proof and kernel-budget review now exist, but changing authority requires a separately authorized, reversible transition: pin the legacy rollback target, switch only the atomic selector, repeat direct and graph smokes through the normal selected entry, automatically restore legacy on failure, and retain legacy source and evidence read-only.

## Studio publication

The architecture/control-plane Studio was rebuilt from this current evidence and published to `https://modular-builder-lab.pages.dev/`. The publication candidate is preserved at `https://e4b45f86.modular-builder-lab.pages.dev/`.

- all 70 served files matched the exact local `dist` bytes at both canonical and immutable origins;
- the production CSP permits same-origin and HTTPS runtime reads plus loopback HTTP on `localhost`, `127.0.0.1`, and `[::1]` while rejecting insecure non-loopback origins in client code;
- desktop and 402 x 874 browser checks showed the current 13-node Phase 5 scenario, three production-entry evidence images, zero document overflow, internal graph scrolling, and zero console warnings or errors;
- live mode consumed revision 9 of the accepted UI graph shape, displayed three accepted nodes, disabled reset/advance/run and both connection inputs, and exposed no write or control authority.
