<pblock label="Plan artifact repair" kind="repair">
# Plan Artifact Repair

Drydock accepted the Plan response shape but rejected the emitted Blueprint artifact(s)
below. Repair only the deterministic defect. Preserve all unrelated content, contracts,
headings, decisions, and acceptance assertions byte-for-byte where possible.
Do not remove or weaken a valid assertion while adding a missing one. Every artifact with
a programmatic surface retains at least two concrete Python acceptance assertions. Every
DECISIONS.json is the sole decision disclosure surface; do not emit Markdown question sections.

Emit each artifact below in exactly this form, and emit no other text:

=== BEGIN ARTIFACT <FILENAME> ===
<the complete file body>
=== END ARTIFACT ===

The filename appears once, in the opening delimiter. The closing delimiter is the
constant token above and never carries a name.

Emit exactly one such block for each of: FEATURE-Function-Definitions.md, FEATURE-Function-Parameters.md, FEATURE-Generator-Core.md, FEATURE-Index-and-Membership.md, FEATURE-Input-Streams.md.

Repair pass: 4

Deterministic validation defect:
FEATURE-Function-Definitions.md [function-definitions-scoped]: story func-003 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Function-Definitions.md [function-recursion-scoped]: story func-003 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Function-Parameters.md [function-parameters-scoped]: story func-002 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Function-Parameters.md [cartesian-function-scoped]: story func-002 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Generator-Core.md [core-001-generators]: story core-001 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Generator-Core.md [core-001-ordering]: story core-001 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Index-and-Membership.md [data-004-conformance]: story data-004 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Input-Streams.md [io-001-conformance]: story io-001 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.
FEATURE-Input-Streams.md [io-001-execution]: story io-001 is not the terminal story (conf-003) and its acceptance executes the authoritative runner sources/run_conformance.py. Gate this story on its own declared behavior, or invoke the runner in list mode, which enumerates the suite without running a case.

Normative Compass sections. They bind every assertion you write or retain, including one you add to satisfy the defect above.

## Constraints

- Implement in Python using only the standard library.
- Provide an executable named `jq` at the application root, invoked as `./jq -c '<program>'`.
- `-c` is the only option exercised. No other command-line option is required.
- Run without network access, package installation, or external runtime dependencies.
- Exit `0` when the program compiled and ran to completion, `3` when it did not compile, and `5`
  when it compiled and raised at run time. The harness grades on this distinction.
- Diagnostics go to standard error and are never compared.

## Guardrails

- Do not shell out to a system `jq` executable.
- Do not use a third-party jq implementation or binding.
- Do not modify, rewrite, trim, regenerate, or substitute any file under `sources/`. Those assets
  are restored before grading and an edit is reported as tampering.
- Preserve generator ordering, multiplicity, backtracking, and partial-output runtime behavior.
- Keep compile failures distinct from runtime failures using exit codes 3 and 5.

## Verification Protocol

This section is normative. It governs which story may invoke the supplied harness, and how.

### Invoking the harness

`sources/run_conformance.py` **requires** the environment variable `JQ`, the command that runs the
candidate implementation. Without it the harness exits `2` on its own usage code, which is a
harness fault and never a verdict about the interpreter. Every invocation, in every acceptance
criterion and every developer command, supplies it:

```bash
JQ="$PWD/jq" python3 sources/run_conformance.py            # whole corpus, the scored run
JQ="$PWD/jq" python3 sources/run_conformance.py --select 'reduce'   # run one construct for real
```

Those two commands are the only ways this build runs the harness. They are specified verbatim
below under *The two harness invocations*, together with the flag this build forbids.

`sources/` is read only. No story edits, patches, or regenerates `sources/run_conformance.py`,
`sources/jq.test`, or `sources/exclusions.txt`; a harness defect is reported, not repaired in
place. A story that needs to experiment with the harness works on a copy outside `sources/`, and
every acceptance criterion invokes the original `sources/run_conformance.py`.

An acceptance criterion written in Python supplies it by **extending** the inherited environment,
never by replacing it:

```python
env={**os.environ, "JQ": str(build_dir / "jq")}
```

`env={"JQ": ...}` alone leaves the child with no `PATH`, so nothing it invokes resolves and the
criterion is false at every level of implementation quality.

`sources/full_test.sh` sets `JQ` itself for the runner it wraps and therefore takes no environment
from its caller.

The harness reserves exit `2` for its own faults — a missing corpus, an unset `JQ`, a stale
exclusion list. Exit `2` never means the interpreter is wrong.

The summary line is:

```
jq conformance: NNN passed, N failed, N errored, N skipped (corpus jq.test @ jq-1.8.2)
```

### The two harness invocations

An acceptance criterion that runs `sources/run_conformance.py` uses one of these two commands. No
criterion in this build passes any other flag to the harness.

| Story kind | Command | Executes cases? | Asserts |
|---|---|---|---|
| Every behavioral story | `--select <regex> --json` | Yes, the selected slice | exit `0`, zero `fail`, zero `error`, non-zero case count |
| Terminal story (once, last) | `sh sources/full_test.sh` | Yes, all of them | exit `0` |

The staging story does not appear in this table. It does not run the harness at all; see *The
staging story* below.

#### `--list` is never run

`sources/run_conformance.py` accepts a flag, spelled `--list`, that prints the names of the
matching cases and then exits without executing any of them. `sources/INSTRUCTIONS.md`, the file
header, and `--help` all document it.

**This build never runs it. Not in an acceptance criterion, not in a story, not in a script, not
in a command typed by a build agent, not while developing and not while verifying. The string
`--list` does not appear anywhere in this project's output. If you have written it, that line is
wrong — delete it and use one of the two commands above.**

A Drydock build is headless. There is no one watching the output, so a mode whose entire purpose
is to print something for a person to read has no reader and no reason to run.

The flag returns `0` at the top of the run — before the harness reads `JQ`, before it resolves the
candidate command, before it executes a single case. A criterion built on it passes when `jq` is
an empty file, when `jq` does not exist, and when the story it gates was never written. It is not
a weak proof, not a partial proof, and not an acceptable proof for staging, for scaffolding, or
for an early story whose implementation is incomplete. It is not a proof. Thirty-six criteria in
one earlier plan of this project used it, every one of them reported green, and it cost three days.

If you are writing a criterion and reaching for that flag, the reason is always the same: the
story's code does not exist yet and you want a command that will not fail. That is the definition
of a criterion that proves nothing. Write the `--select ... --json` form instead and let it be red
until the story makes it green. **A criterion is supposed to fail before its story is built.**

The same prohibition covers any other flag whose effect is to not execute the cases — enumeration,
dry-run, validation, or help. If a flag's documented purpose is "run nothing", it has no place in
an acceptance criterion.

#### Behavioral criterion — copy this, changing only `SELECT`

```python
import json
import os
import subprocess
import sys

SELECT = r"reduce"

result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", SELECT, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
tally = report["summary"]
assert sum(tally.values()) > 0, f"selector matched no case: {SELECT}"
assert tally["fail"] == 0 and tally["error"] == 0, tally
assert result.returncode == 0, result.returncode
```

Three assertions, and all three are required.

1. **The selector matched something.** `--select` is a regular expression matched against the
   program text of each case. A selector that matches nothing yields zero cases, zero failures,
   and exit `0` — green, and worth nothing. Alternations naming ideas rather than syntax
   (`closure`, `recursive`, `optional`) match no jq program and are the common way to write one
   by accident. Select on syntax the corpus actually contains: `reduce`, `foreach`, `def `,
   ` as \$`, `try `, `//`, `path(`.
2. **No case failed or errored.** Read off the parsed JSON tally, not off any printed line.
3. **The exit status is `0`.** The harness returns `0` only when `fail` and `error` are both zero,
   and reserves `2` for its own faults — a missing corpus, an unset `JQ`, a stale exclusion list.
   Exit `2` is never a verdict about the interpreter.

`--json` writes the report and nothing else to stdout, so `json.loads(result.stdout)` is total. Do
not assert against the human summary line, and do not grep stdout for `passed` or `failed`.

### The terminal story

The **terminal story** is the last story in the build order: the one on which every other story is
a transitive dependency, and after which no further story runs. It is a verification story. Its
job is not to add capability but to prove that the capability every preceding story delivered is
present, together, at the end of the build.

The terminal story of this project runs `sh sources/full_test.sh`, asserts `returncode == 0`,
prints the captured stdout and stderr so a failure is diagnosable from the evidence alone, and
carries the Sea Trial. It is the only story permitted to run the whole corpus.

A story is not terminal because its name contains "verify", because it is a test harness, or
because it stages the test assets. Staging the corpus is foundational work that happens early;
running the corpus is terminal work that happens last. Do not place a whole-corpus gate on a
story that cannot yet run it — it fails vacuously and teaches nothing.

### Scope of every other story

Every non-terminal story is gated on its own declared behavior only, through `--select` against
the constructs that story implements, and the criterion asserts the selected slice passes. A
non-terminal story never invokes `sources/full_test.sh` and never runs the corpus unfiltered: a
partial interpreter fails most of an authoritative corpus by construction, and its unimplemented
cases exhaust the harness's per-case timeout rather than returning, so the unscoped run costs the
most exactly where it teaches the least.

Regression across stories is not the responsibility of any story's criteria. Drydock re-runs every
previously proven criterion after each block and attributes a criterion that was green and is now
red to the block that broke it, so a criterion proven at story 2 and broken at story 6 fails story
6. Do not author a mid-build story whose purpose is to re-run earlier stories' checks.

### The staging story

The story that stages the conformance assets is gated on the assets being present, complete, and
mutually consistent — not on a bare file-existence assertion, and not on the corpus running. It
proves that in process, by importing the harness and calling its parsers directly. It never
launches the harness, so the question of which flags to pass does not arise:

```python
import sys

sys.path.insert(0, "sources")
import run_conformance as harness

EXPECTED_CASES = 550
EXPECTED_EXCLUSIONS = 13

cases = harness.parse_corpus(harness.CORPUS.read_text(encoding="utf-8"))
excluded = harness.apply_exclusions(cases, harness.parse_exclusions(harness.EXCLUSIONS))
assert len(cases) == EXPECTED_CASES, len(cases)
assert len(excluded) == EXPECTED_EXCLUSIONS, len(excluded)
```

This reads state rather than output: the harness module imports, the corpus parses into the
expected number of cases, and every exclusion still matches a case — `apply_exclusions` raises on
a stale entry, so a corpus and an exclusion list that have drifted apart fail here rather than
silently skipping cases later.

It claims nothing about the interpreter, because at this point in the build there is nothing to
claim. Every story that claims a construct works runs that construct through
`--select ... --json`.

Original FEATURE-Function-Definitions.md, in the same form your reply must use:
=== BEGIN ARTIFACT FEATURE-Function-Definitions.md ===
# FEATURE: Function Definitions

| Field       | Value |
|-------------|-------|
| Version     | 20260822 V1 |
| Description | Provides jq function definitions, lexical scope, redefinition, and recursion. |
| Depends On  | FEATURE-Function-Parameters.md |
| Provides    | def, function redefinition, recursion, forward and self references |
| Consumes    | function parameter evaluation |

## Questions

- None.

## Workflow

The interpreter compiles `def` declarations into lexically scoped callable definitions. Definitions support recursive self-reference, arity-specific redefinition, forward references permitted by jq semantics, and closure behavior across nested definitions.

## Programmatic Acceptance

=== AC function-definitions-scoped ===
Intent: Function-definition and recursion corpus cases execute and pass.
Suite: scoped

import json
import os
import subprocess
import sys

selector = r"def "
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0
assert summary["error"] == 0
assert result.returncode == 0
=== END AC function-definitions-scoped ===

=== AC function-recursion-scoped ===
Intent: Recursive user-function cases execute and pass.
Suite: scoped

import json
import os
import subprocess
import sys

selector = r"def .*:.*\\b(if|f\\b|g\\b)"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0
assert summary["error"] == 0
assert result.returncode == 0
=== END AC function-recursion-scoped ===

## User Acceptance

- None.

## Guardrails

- Function identity includes name and arity.
- Redefinition must affect only references permitted by jq lexical scope.
- Recursive calls must terminate or propagate runtime errors according to the filter semantics.
=== END ARTIFACT ===

Original FEATURE-Function-Parameters.md, in the same form your reply must use:
=== BEGIN ARTIFACT FEATURE-Function-Parameters.md ===
# FEATURE: Function Parameters

| Field       | Value |
|-------------|-------|
| Version     | 20260822 V1 |
| Description | Provides jq filter and value function parameter evaluation. |
| Depends On  | FEATURE-Variable-Bindings.md |
| Provides    | filter parameters, value parameters, multiple arities, Cartesian arguments |
| Consumes    | lexical variable bindings |

## Questions

- None.

## Workflow

User-defined functions accept filter parameters and value parameters with jq arity rules. Filter arguments remain executable generators, value arguments are evaluated and bound, and multiple argument streams produce the required cartesian combinations.

## Programmatic Acceptance

=== AC function-parameters-scoped ===
Intent: Function-parameter corpus cases execute and pass.
Suite: scoped

import json
import os
import subprocess
import sys

selector = r"def .*\("
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0
assert summary["error"] == 0
assert result.returncode == 0
=== END AC function-parameters-scoped ===

=== AC cartesian-function-scoped ===
Intent: Multi-argument and generator-valued function cases execute and pass.
Suite: scoped

import json
import os
import subprocess
import sys

selector = r"def .*\\([^)]*;[^)]*\\)"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0
assert summary["error"] == 0
assert result.returncode == 0
=== END AC cartesian-function-scoped ===

## User Acceptance

- None.

## Guardrails

- Distinguish filter parameters from value parameters.
- Preserve argument stream ordering and cartesian multiplicity.
- Resolve parameters according to lexical scope and declared arity.
=== END ARTIFACT ===

Original FEATURE-Generator-Core.md, in the same form your reply must use:
=== BEGIN ARTIFACT FEATURE-Generator-Core.md ===
# FEATURE: Generator Core

| Field       | Value |
|-------------|-------|
| Version     | 20260822 V1 |
| Description | Evaluate jq filters as ordered streams of zero or more values. |
| Depends On  | FEATURE-Declaration-Parser.md |
| Provides    | ordered generator evaluation, empty, iteration, range |
| Consumes    | AST for filter expressions |

## Questions

- None.

Every filter shall evaluate against an input value as an ordered generator. The evaluator shall preserve zero, one, and multiple outputs, backtracking, identity, array/object iteration, recursive descent support, `range`, and `empty`. Output order and multiplicity are semantic requirements.

## Programmatic Acceptance

=== AC core-001-generators ===
Intent: The authoritative corpus executes a non-empty slice covering identity, iteration, empty, and range generators.

import json
import os
import subprocess
import sys

selector = r"\.|,|\[\.\]|range|empty"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0 and summary["error"] == 0
assert result.returncode == 0
=== END AC core-001-generators ===

=== AC core-001-ordering ===
Intent: The authoritative corpus executes generator cases whose correctness depends on output order and multiplicity.

import json
import os
import subprocess
import sys

selector = r"\.|,|range|empty|while|recurse"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0 and summary["error"] == 0
assert result.returncode == 0
=== END AC core-001-ordering ===

## User Acceptance

- None.

## Guardrails

- Treat generators and backtracking as the evaluation model, not an optimization.
- Preserve partial output before a later runtime failure.
- Do not shell out to another jq implementation.
=== END ARTIFACT ===

Original FEATURE-Index-and-Membership.md, in the same form your reply must use:
=== BEGIN ARTIFACT FEATURE-Index-and-Membership.md ===
# FEATURE: Index and Membership

| Field       | Value |
|-------------|-------|
| Version     | 20260822 V1 |
| Description | Provides jq index lookup, binary search, quantifier, emptiness, and SQL-style membership utilities. |
| Depends On  | FEATURE-Object-and-Containment-Builtins.md, FEATURE-Truthiness-and-Comparison.md |
| Provides    | indices, index, rindex, bsearch, all, any, isempty, IN |
| Consumes    | collection and comparison builtins, ordered generators |

## Questions

- None.

## Scope

This feature implements string and array occurrence searches, insertion-point binary search, generator-aware quantifiers, emptiness checks, and SQL-style `IN` functions.

## Behavior

- `indices` returns all matching string or array positions.
- `index` and `rindex` return the first and last matching positions.
- `bsearch` returns an index or jq's negative insertion-point encoding.
- `all` and `any` preserve short-circuit behavior over generated values.
- `isempty` distinguishes empty streams from streams that produce values.
- `IN` supports source and comparison generator forms.

## Programmatic Acceptance

=== AC data-004-conformance ===
Intent: The authoritative corpus slice containing index, membership, quantifier, emptiness, and SQL-style membership syntax executes and passes without failures or errors.

import json
import os
import subprocess
import sys

selector = r"indices|index\(|rindex|bsearch|any|all|isempty|IN\("
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0 and summary["error"] == 0
assert result.returncode == 0
=== END AC data-004-conformance ===

## User Acceptance

- None.

## Guardrails

- Preserve match positions in jq codepoint/index semantics.
- Do not evaluate generator operands beyond required short-circuit points.
- Do not modify files under `sources/`.
=== END ARTIFACT ===

Original FEATURE-Input-Streams.md, in the same form your reply must use:
=== BEGIN ARTIFACT FEATURE-Input-Streams.md ===
# FEATURE: Input Streams

| Field       | Value |
|-------------|-------|
| Version     | 20260822 V1 |
| Description | Provide jq controls for consuming additional JSON input values. |
| Depends On  | FEATURE-Date-and-Time.md, FEATURE-Json-IO.md |
| Provides    | input, inputs, input_filename, input_line_number |
| Consumes    | executable JSON input boundary |

## Questions

- None.

## Intent

Implement `input` and `inputs` over the fixed stdin interface, preserving the distinction between the initially filtered value and remaining values. Provide the available filename and line-number metadata without adding unsupported command-line options.

## Programmatic Acceptance

=== AC io-001-conformance ===
Intent: The authoritative corpus cases covering input-stream controls pass.
Suite: scoped
Requires: executable=python3; scope=test

import json
import os
import subprocess
import sys

selector = r"input|inputs"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
print(result.stdout)
print(result.stderr, file=sys.stderr)
report = json.loads(result.stdout)
summary = report["summary"]
assert sum(summary.values()) > 0
assert summary["fail"] == 0
assert summary["error"] == 0
assert result.returncode == 0
=== END AC io-001-conformance ===

=== AC io-001-execution ===
Intent: The input-stream selector executes a non-empty corpus slice through jq.
import json
import os
import subprocess
import sys

selector = r"input|inputs"
result = subprocess.run(
    [sys.executable, "sources/run_conformance.py", "--select", selector, "--json"],
    capture_output=True,
    text=True,
    env={**os.environ, "JQ": f"{os.getcwd()}/jq"},
)
report = json.loads(result.stdout)
assert report["summary"]["pass"] > 0
assert result.returncode == 0
=== END AC io-001-execution ===

## User Acceptance

- None.

## Guardrails

- Do not add command-line options beyond the fixed `-c` interface.
- Preserve input ordering and stream multiplicity.
- Use only the supplied stdin boundary and standard-library runtime.
=== END ARTIFACT ===
</pblock>

