Make <Evaluate> evaluate complete XMD programs #713

Description

@taras

Story

As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
program at an explicit composition site, so producing a program and running it
remain separate choices.

Common paths

Evaluate a planned program directly while privately capturing the source that
<Plan> produces:

<Evaluate>
<Plan>
Inspect the release inputs, recommend a version, and ask me to approve it.
</Plan>
</Evaluate>

Or preserve the program first and evaluate it later:

<Planas="plan">
Inspect the release inputs, recommend a version, and ask me to approve it.
</Plan>
The approved program is ready. Carry it out here.
<Evaluateprogram={plan} />

The paired and program forms evaluate a complete root in the current XMD
execution. They do not start a child document, process, host profile, root
lifecycle, or independent journal.

Three disjoint forms

<Evaluate> has three mutually exclusive inputs:

  1. paired content produces complete-program source in a private buffer;
  2. program={value} supplies complete-program source directly; and
  3. source={fragment} retains the restricted generated-XMD meaning delivered
    by Evaluate Agent-generated XMD through a constrained allowlist #369.

source, program, and paired content cannot be combined. allow is valid
only with source. props={object} is valid only with a complete-program form.
Every ambiguous or misplaced combination refuses before program content or a
program effect runs.

The paired form suppresses its source-producing output from the surrounding
document, removes only indentation contributed by the <Evaluate> wrapper, and
admits the resulting complete root. Bytes emitted by a producer are otherwise
unchanged. With a sole <Plan> producer, paired evaluation and
program={plan} admit the same approved bytes and content digest.

Another source-producing text component may be used in paired content when its
rendered result is a complete admissible root. Paired content is not quotation:
an executable component written literally there executes under ordinary XMD
semantics while producing the text sent to admission.

Complete-program behavior

The complete root's frontmatter, imports, metadata, props schema, returns, and
<Output> selection apply.

  • props={object} is the complete root's props input. It defaults to {};
    ambient root props are never silently adopted.
  • Root props are schema-validated before the first program effect.
  • Ordinary non-props caller bindings are visible read-only. Program-local
    bindings do not escape the evaluation.
  • Relative imports resolve from the source origin of the authored <Evaluate>
    site.
  • A text root executes and renders its selected output without as; with as,
    it still executes, binds that selected text as a string, and emits none of it.
  • A value root requires as before its first effect and binds its
    schema-validated JSON result. Without as, it refuses before program effects.

The ordinary run profile exposes the complete-program forms. A workflow run's
<Evaluate> exposes those forms plus its existing restricted source form.
The author-facing description is:

Evaluate XMD source in the current execution. <Evaluate program={plan} />
evaluates a complete program. Use
<Evaluate source={fragment} allow={["read"]} /> for a restricted generated
fragment.

Structured syntax fields own the form, prop, capture, return, and origin details.

Current-site authority

Complete-program evaluation uses the current execution's lifecycle, journal,
cancellation scope, contextual providers, working directory or Workspace, and
authority at the authored <Evaluate> site. Program source requests behavior;
it grants none.

The producer's temporary authority is not inherited. In particular, <Plan>'s
authorship profile and private components have torn down before evaluation, and
a private component belonging to an enclosing declaration is available only to
elements authored by that declaration's exact bytes. Source returned by a
producer cannot invoke either closure. Ordinary imports and capabilities that
are genuinely present at the evaluation site remain available.

Separate admission and replay

Complete programs use a distinct complete-program admission and durable event;
do not widen or reuse generated_xmd. Before the first program effect, retain
and hostile-parse the exact source and digest, explicit props, evaluation-site
source origin, root mode, resolved component identities and forms, and every
compatibility term needed to prove the same current-site environment.

A partial continuation expands the retained source, restores completed nested
effects, and repeats no planning. Changed source at the same evaluation
occurrence is stale input and refuses before either current or retained source
can run. Neither source silently wins.

The source digest identifies the program artifact. The authored <Evaluate>
site and loop iteration identify one execution occurrence. Deliberately
evaluating the same artifact at two sites or iterations creates independent
nested effect identities; the digest never deduplicates those executions.

Restricted-fragment compatibility

<Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
contract exactly:

  • the closed generated-XMD grammar and selected read/write ceilings;
  • caller-binding isolation;
  • the generated_xmd admission and retained-source replay;
  • pinned component identities and forms; and
  • the exact { observations, output } result.

Complete-program support cannot be selected through source or allow.
Representative Agent, Elicitation, import, binding, executable-block, and
unadmitted-component cases still refuse through source before effects.

Acceptance ownership

This story exclusively owns these Quest cases:

  • Direct composition: paired Plan source evaluates once and is not emitted
    separately.
  • Deferred composition:program={plan} evaluates the same digest without
    repeating planning.
  • Program forms: text and value roots follow their output and return rules;
    ambiguous forms refuse before effects.
  • Root props: explicit props validate before effects and ambient props are
    not adopted.
  • Fragment compatibility: the delivered result and ceilings remain exact;
    Agent and Elicitation remain refused through source.
  • Authority: only evaluation-site authority is usable; producer-private and
    otherwise unavailable capabilities never run.
  • Evaluation replay: retained source resumes nested effects without
    replanning or repeating a completed effect.
  • Changed evaluation source: stale input refuses and neither source runs.
  • Repeated evaluation: two explicit occurrences execute independently and
    are not deduplicated by digest.

Structural preflight cases place a negative-control effect before a later
malformed construct and prove the earlier effect did not run.

Documentation and focused evidence

Update architecture.md, the component/root/return/execution sections of
specs/executable-mdx-spec.md, and the generated-XMD section of
specs/workflow-workspace-spec.md. The documentation names complete-program
admission separately and leaves #369's vocabulary intact. Update xmd syntax
and the component inventory for every host profile that exposes <Evaluate>.

Update the homepage delivered by PR #719 with the direct and deferred
<Plan>/<Evaluate> compositions and this public model:

Plan produces a program.
Evaluate evaluates a program in the current XMD execution.
Composition decides whether and when a planned program runs.

#724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
remains historical and unchanged.

Add focused canonical evidence in
packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
compatibility evidence in
packages/workflow/tests/generated-agent-component.test.ts. Keep
packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
control.

Focused feedback evidence:

deno task test \
packages/core/tests/program-evaluation.test.ts \
packages/cli/tests/evaluate-program-component.test.ts \
packages/workflow/tests/generated-agent-component.test.ts \
packages/core/tests/generated-xmd.test.ts \
packages/cli/tests/syntax-cli.test.ts

After a feedback commit, run deno task test --changed. Delivery proves npm and
compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
packaged-document probes, the build, and required CI checks.

Dependencies

There is no dependency on superseded #711 or PR #720.

Out of scope

  • Implicit execution by <Plan> or any other source-producing component.
  • Widening the restricted generated-XMD evaluator.
  • A <Run> component, process isolation, or a child document lifecycle.
  • Granting authority from source or inheriting producer-private closures.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
       blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
      }
      } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
      })();
      (function(){
      try {
      var __m = "github.com";
      var __re = new RegExp('^' + "github\\.com" + '
      
      Skip to content

      Make <Evaluate> evaluate complete XMD programs #713

      Description

      @taras

      Story

      As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
      program at an explicit composition site, so producing a program and running it
      remain separate choices.

      Common paths

      Evaluate a planned program directly while privately capturing the source that
      <Plan> produces:

      <Evaluate>
      <Plan>
      Inspect the release inputs, recommend a version, and ask me to approve it.
      </Plan>
      </Evaluate>

      Or preserve the program first and evaluate it later:

      <Planas="plan">
      Inspect the release inputs, recommend a version, and ask me to approve it.
      </Plan>
      The approved program is ready. Carry it out here.
      <Evaluateprogram={plan} />

      The paired and program forms evaluate a complete root in the current XMD
      execution. They do not start a child document, process, host profile, root
      lifecycle, or independent journal.

      Three disjoint forms

      <Evaluate> has three mutually exclusive inputs:

      1. paired content produces complete-program source in a private buffer;
      2. program={value} supplies complete-program source directly; and
      3. source={fragment} retains the restricted generated-XMD meaning delivered
        by Evaluate Agent-generated XMD through a constrained allowlist #369.

      source, program, and paired content cannot be combined. allow is valid
      only with source. props={object} is valid only with a complete-program form.
      Every ambiguous or misplaced combination refuses before program content or a
      program effect runs.

      The paired form suppresses its source-producing output from the surrounding
      document, removes only indentation contributed by the <Evaluate> wrapper, and
      admits the resulting complete root. Bytes emitted by a producer are otherwise
      unchanged. With a sole <Plan> producer, paired evaluation and
      program={plan} admit the same approved bytes and content digest.

      Another source-producing text component may be used in paired content when its
      rendered result is a complete admissible root. Paired content is not quotation:
      an executable component written literally there executes under ordinary XMD
      semantics while producing the text sent to admission.

      Complete-program behavior

      The complete root's frontmatter, imports, metadata, props schema, returns, and
      <Output> selection apply.

      • props={object} is the complete root's props input. It defaults to {};
        ambient root props are never silently adopted.
      • Root props are schema-validated before the first program effect.
      • Ordinary non-props caller bindings are visible read-only. Program-local
        bindings do not escape the evaluation.
      • Relative imports resolve from the source origin of the authored <Evaluate>
        site.
      • A text root executes and renders its selected output without as; with as,
        it still executes, binds that selected text as a string, and emits none of it.
      • A value root requires as before its first effect and binds its
        schema-validated JSON result. Without as, it refuses before program effects.

      The ordinary run profile exposes the complete-program forms. A workflow run's
      <Evaluate> exposes those forms plus its existing restricted source form.
      The author-facing description is:

      Evaluate XMD source in the current execution. <Evaluate program={plan} />
      evaluates a complete program. Use
      <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
      fragment.

      Structured syntax fields own the form, prop, capture, return, and origin details.

      Current-site authority

      Complete-program evaluation uses the current execution's lifecycle, journal,
      cancellation scope, contextual providers, working directory or Workspace, and
      authority at the authored <Evaluate> site. Program source requests behavior;
      it grants none.

      The producer's temporary authority is not inherited. In particular, <Plan>'s
      authorship profile and private components have torn down before evaluation, and
      a private component belonging to an enclosing declaration is available only to
      elements authored by that declaration's exact bytes. Source returned by a
      producer cannot invoke either closure. Ordinary imports and capabilities that
      are genuinely present at the evaluation site remain available.

      Separate admission and replay

      Complete programs use a distinct complete-program admission and durable event;
      do not widen or reuse generated_xmd. Before the first program effect, retain
      and hostile-parse the exact source and digest, explicit props, evaluation-site
      source origin, root mode, resolved component identities and forms, and every
      compatibility term needed to prove the same current-site environment.

      A partial continuation expands the retained source, restores completed nested
      effects, and repeats no planning. Changed source at the same evaluation
      occurrence is stale input and refuses before either current or retained source
      can run. Neither source silently wins.

      The source digest identifies the program artifact. The authored <Evaluate>
      site and loop iteration identify one execution occurrence. Deliberately
      evaluating the same artifact at two sites or iterations creates independent
      nested effect identities; the digest never deduplicates those executions.

      Restricted-fragment compatibility

      <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
      contract exactly:

      • the closed generated-XMD grammar and selected read/write ceilings;
      • caller-binding isolation;
      • the generated_xmd admission and retained-source replay;
      • pinned component identities and forms; and
      • the exact { observations, output } result.

      Complete-program support cannot be selected through source or allow.
      Representative Agent, Elicitation, import, binding, executable-block, and
      unadmitted-component cases still refuse through source before effects.

      Acceptance ownership

      This story exclusively owns these Quest cases:

      • Direct composition: paired Plan source evaluates once and is not emitted
        separately.
      • Deferred composition:program={plan} evaluates the same digest without
        repeating planning.
      • Program forms: text and value roots follow their output and return rules;
        ambiguous forms refuse before effects.
      • Root props: explicit props validate before effects and ambient props are
        not adopted.
      • Fragment compatibility: the delivered result and ceilings remain exact;
        Agent and Elicitation remain refused through source.
      • Authority: only evaluation-site authority is usable; producer-private and
        otherwise unavailable capabilities never run.
      • Evaluation replay: retained source resumes nested effects without
        replanning or repeating a completed effect.
      • Changed evaluation source: stale input refuses and neither source runs.
      • Repeated evaluation: two explicit occurrences execute independently and
        are not deduplicated by digest.

      Structural preflight cases place a negative-control effect before a later
      malformed construct and prove the earlier effect did not run.

      Documentation and focused evidence

      Update architecture.md, the component/root/return/execution sections of
      specs/executable-mdx-spec.md, and the generated-XMD section of
      specs/workflow-workspace-spec.md. The documentation names complete-program
      admission separately and leaves #369's vocabulary intact. Update xmd syntax
      and the component inventory for every host profile that exposes <Evaluate>.

      Update the homepage delivered by PR #719 with the direct and deferred
      <Plan>/<Evaluate> compositions and this public model:

      Plan produces a program.
      Evaluate evaluates a program in the current XMD execution.
      Composition decides whether and when a planned program runs.
      

      #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
      remains historical and unchanged.

      Add focused canonical evidence in
      packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
      packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
      compatibility evidence in
      packages/workflow/tests/generated-agent-component.test.ts. Keep
      packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
      control.

      Focused feedback evidence:

      deno task test \
      packages/core/tests/program-evaluation.test.ts \
      packages/cli/tests/evaluate-program-component.test.ts \
      packages/workflow/tests/generated-agent-component.test.ts \
      packages/core/tests/generated-xmd.test.ts \
      packages/cli/tests/syntax-cli.test.ts

      After a feedback commit, run deno task test --changed. Delivery proves npm and
      compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
      packaged-document probes, the build, and required CI checks.

      Dependencies

      There is no dependency on superseded #711 or PR #720.

      Out of scope

      • Implicit execution by <Plan> or any other source-producing component.
      • Widening the restricted generated-XMD evaluator.
      • A <Run> component, process isolation, or a child document lifecycle.
      • Granting authority from source or inheriting producer-private closures.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        enhancementNew feature or request

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Make <Evaluate> evaluate complete XMD programs #713

          Description

          @taras

          Story

          As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
          program at an explicit composition site, so producing a program and running it
          remain separate choices.

          Common paths

          Evaluate a planned program directly while privately capturing the source that
          <Plan> produces:

          <Evaluate>
          <Plan>
          Inspect the release inputs, recommend a version, and ask me to approve it.
          </Plan>
          </Evaluate>

          Or preserve the program first and evaluate it later:

          <Planas="plan">
          Inspect the release inputs, recommend a version, and ask me to approve it.
          </Plan>
          The approved program is ready. Carry it out here.
          <Evaluateprogram={plan} />

          The paired and program forms evaluate a complete root in the current XMD
          execution. They do not start a child document, process, host profile, root
          lifecycle, or independent journal.

          Three disjoint forms

          <Evaluate> has three mutually exclusive inputs:

          1. paired content produces complete-program source in a private buffer;
          2. program={value} supplies complete-program source directly; and
          3. source={fragment} retains the restricted generated-XMD meaning delivered
            by Evaluate Agent-generated XMD through a constrained allowlist #369.

          source, program, and paired content cannot be combined. allow is valid
          only with source. props={object} is valid only with a complete-program form.
          Every ambiguous or misplaced combination refuses before program content or a
          program effect runs.

          The paired form suppresses its source-producing output from the surrounding
          document, removes only indentation contributed by the <Evaluate> wrapper, and
          admits the resulting complete root. Bytes emitted by a producer are otherwise
          unchanged. With a sole <Plan> producer, paired evaluation and
          program={plan} admit the same approved bytes and content digest.

          Another source-producing text component may be used in paired content when its
          rendered result is a complete admissible root. Paired content is not quotation:
          an executable component written literally there executes under ordinary XMD
          semantics while producing the text sent to admission.

          Complete-program behavior

          The complete root's frontmatter, imports, metadata, props schema, returns, and
          <Output> selection apply.

          • props={object} is the complete root's props input. It defaults to {};
            ambient root props are never silently adopted.
          • Root props are schema-validated before the first program effect.
          • Ordinary non-props caller bindings are visible read-only. Program-local
            bindings do not escape the evaluation.
          • Relative imports resolve from the source origin of the authored <Evaluate>
            site.
          • A text root executes and renders its selected output without as; with as,
            it still executes, binds that selected text as a string, and emits none of it.
          • A value root requires as before its first effect and binds its
            schema-validated JSON result. Without as, it refuses before program effects.

          The ordinary run profile exposes the complete-program forms. A workflow run's
          <Evaluate> exposes those forms plus its existing restricted source form.
          The author-facing description is:

          Evaluate XMD source in the current execution. <Evaluate program={plan} />
          evaluates a complete program. Use
          <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
          fragment.

          Structured syntax fields own the form, prop, capture, return, and origin details.

          Current-site authority

          Complete-program evaluation uses the current execution's lifecycle, journal,
          cancellation scope, contextual providers, working directory or Workspace, and
          authority at the authored <Evaluate> site. Program source requests behavior;
          it grants none.

          The producer's temporary authority is not inherited. In particular, <Plan>'s
          authorship profile and private components have torn down before evaluation, and
          a private component belonging to an enclosing declaration is available only to
          elements authored by that declaration's exact bytes. Source returned by a
          producer cannot invoke either closure. Ordinary imports and capabilities that
          are genuinely present at the evaluation site remain available.

          Separate admission and replay

          Complete programs use a distinct complete-program admission and durable event;
          do not widen or reuse generated_xmd. Before the first program effect, retain
          and hostile-parse the exact source and digest, explicit props, evaluation-site
          source origin, root mode, resolved component identities and forms, and every
          compatibility term needed to prove the same current-site environment.

          A partial continuation expands the retained source, restores completed nested
          effects, and repeats no planning. Changed source at the same evaluation
          occurrence is stale input and refuses before either current or retained source
          can run. Neither source silently wins.

          The source digest identifies the program artifact. The authored <Evaluate>
          site and loop iteration identify one execution occurrence. Deliberately
          evaluating the same artifact at two sites or iterations creates independent
          nested effect identities; the digest never deduplicates those executions.

          Restricted-fragment compatibility

          <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
          contract exactly:

          • the closed generated-XMD grammar and selected read/write ceilings;
          • caller-binding isolation;
          • the generated_xmd admission and retained-source replay;
          • pinned component identities and forms; and
          • the exact { observations, output } result.

          Complete-program support cannot be selected through source or allow.
          Representative Agent, Elicitation, import, binding, executable-block, and
          unadmitted-component cases still refuse through source before effects.

          Acceptance ownership

          This story exclusively owns these Quest cases:

          • Direct composition: paired Plan source evaluates once and is not emitted
            separately.
          • Deferred composition:program={plan} evaluates the same digest without
            repeating planning.
          • Program forms: text and value roots follow their output and return rules;
            ambiguous forms refuse before effects.
          • Root props: explicit props validate before effects and ambient props are
            not adopted.
          • Fragment compatibility: the delivered result and ceilings remain exact;
            Agent and Elicitation remain refused through source.
          • Authority: only evaluation-site authority is usable; producer-private and
            otherwise unavailable capabilities never run.
          • Evaluation replay: retained source resumes nested effects without
            replanning or repeating a completed effect.
          • Changed evaluation source: stale input refuses and neither source runs.
          • Repeated evaluation: two explicit occurrences execute independently and
            are not deduplicated by digest.

          Structural preflight cases place a negative-control effect before a later
          malformed construct and prove the earlier effect did not run.

          Documentation and focused evidence

          Update architecture.md, the component/root/return/execution sections of
          specs/executable-mdx-spec.md, and the generated-XMD section of
          specs/workflow-workspace-spec.md. The documentation names complete-program
          admission separately and leaves #369's vocabulary intact. Update xmd syntax
          and the component inventory for every host profile that exposes <Evaluate>.

          Update the homepage delivered by PR #719 with the direct and deferred
          <Plan>/<Evaluate> compositions and this public model:

          Plan produces a program.
          Evaluate evaluates a program in the current XMD execution.
          Composition decides whether and when a planned program runs.
          

          #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
          remains historical and unchanged.

          Add focused canonical evidence in
          packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
          packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
          compatibility evidence in
          packages/workflow/tests/generated-agent-component.test.ts. Keep
          packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
          control.

          Focused feedback evidence:

          deno task test \
          packages/core/tests/program-evaluation.test.ts \
          packages/cli/tests/evaluate-program-component.test.ts \
          packages/workflow/tests/generated-agent-component.test.ts \
          packages/core/tests/generated-xmd.test.ts \
          packages/cli/tests/syntax-cli.test.ts

          After a feedback commit, run deno task test --changed. Delivery proves npm and
          compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
          packaged-document probes, the build, and required CI checks.

          Dependencies

          There is no dependency on superseded #711 or PR #720.

          Out of scope

          • Implicit execution by <Plan> or any other source-producing component.
          • Widening the restricted generated-XMD evaluator.
          • A <Run> component, process isolation, or a child document lifecycle.
          • Granting authority from source or inheriting producer-private closures.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            enhancementNew feature or request

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Make <Evaluate> evaluate complete XMD programs #713

              Description

              @taras

              Story

              As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
              program at an explicit composition site, so producing a program and running it
              remain separate choices.

              Common paths

              Evaluate a planned program directly while privately capturing the source that
              <Plan> produces:

              <Evaluate>
              <Plan>
              Inspect the release inputs, recommend a version, and ask me to approve it.
              </Plan>
              </Evaluate>

              Or preserve the program first and evaluate it later:

              <Planas="plan">
              Inspect the release inputs, recommend a version, and ask me to approve it.
              </Plan>
              The approved program is ready. Carry it out here.
              <Evaluateprogram={plan} />

              The paired and program forms evaluate a complete root in the current XMD
              execution. They do not start a child document, process, host profile, root
              lifecycle, or independent journal.

              Three disjoint forms

              <Evaluate> has three mutually exclusive inputs:

              1. paired content produces complete-program source in a private buffer;
              2. program={value} supplies complete-program source directly; and
              3. source={fragment} retains the restricted generated-XMD meaning delivered
                by Evaluate Agent-generated XMD through a constrained allowlist #369.

              source, program, and paired content cannot be combined. allow is valid
              only with source. props={object} is valid only with a complete-program form.
              Every ambiguous or misplaced combination refuses before program content or a
              program effect runs.

              The paired form suppresses its source-producing output from the surrounding
              document, removes only indentation contributed by the <Evaluate> wrapper, and
              admits the resulting complete root. Bytes emitted by a producer are otherwise
              unchanged. With a sole <Plan> producer, paired evaluation and
              program={plan} admit the same approved bytes and content digest.

              Another source-producing text component may be used in paired content when its
              rendered result is a complete admissible root. Paired content is not quotation:
              an executable component written literally there executes under ordinary XMD
              semantics while producing the text sent to admission.

              Complete-program behavior

              The complete root's frontmatter, imports, metadata, props schema, returns, and
              <Output> selection apply.

              • props={object} is the complete root's props input. It defaults to {};
                ambient root props are never silently adopted.
              • Root props are schema-validated before the first program effect.
              • Ordinary non-props caller bindings are visible read-only. Program-local
                bindings do not escape the evaluation.
              • Relative imports resolve from the source origin of the authored <Evaluate>
                site.
              • A text root executes and renders its selected output without as; with as,
                it still executes, binds that selected text as a string, and emits none of it.
              • A value root requires as before its first effect and binds its
                schema-validated JSON result. Without as, it refuses before program effects.

              The ordinary run profile exposes the complete-program forms. A workflow run's
              <Evaluate> exposes those forms plus its existing restricted source form.
              The author-facing description is:

              Evaluate XMD source in the current execution. <Evaluate program={plan} />
              evaluates a complete program. Use
              <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
              fragment.

              Structured syntax fields own the form, prop, capture, return, and origin details.

              Current-site authority

              Complete-program evaluation uses the current execution's lifecycle, journal,
              cancellation scope, contextual providers, working directory or Workspace, and
              authority at the authored <Evaluate> site. Program source requests behavior;
              it grants none.

              The producer's temporary authority is not inherited. In particular, <Plan>'s
              authorship profile and private components have torn down before evaluation, and
              a private component belonging to an enclosing declaration is available only to
              elements authored by that declaration's exact bytes. Source returned by a
              producer cannot invoke either closure. Ordinary imports and capabilities that
              are genuinely present at the evaluation site remain available.

              Separate admission and replay

              Complete programs use a distinct complete-program admission and durable event;
              do not widen or reuse generated_xmd. Before the first program effect, retain
              and hostile-parse the exact source and digest, explicit props, evaluation-site
              source origin, root mode, resolved component identities and forms, and every
              compatibility term needed to prove the same current-site environment.

              A partial continuation expands the retained source, restores completed nested
              effects, and repeats no planning. Changed source at the same evaluation
              occurrence is stale input and refuses before either current or retained source
              can run. Neither source silently wins.

              The source digest identifies the program artifact. The authored <Evaluate>
              site and loop iteration identify one execution occurrence. Deliberately
              evaluating the same artifact at two sites or iterations creates independent
              nested effect identities; the digest never deduplicates those executions.

              Restricted-fragment compatibility

              <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
              contract exactly:

              • the closed generated-XMD grammar and selected read/write ceilings;
              • caller-binding isolation;
              • the generated_xmd admission and retained-source replay;
              • pinned component identities and forms; and
              • the exact { observations, output } result.

              Complete-program support cannot be selected through source or allow.
              Representative Agent, Elicitation, import, binding, executable-block, and
              unadmitted-component cases still refuse through source before effects.

              Acceptance ownership

              This story exclusively owns these Quest cases:

              • Direct composition: paired Plan source evaluates once and is not emitted
                separately.
              • Deferred composition:program={plan} evaluates the same digest without
                repeating planning.
              • Program forms: text and value roots follow their output and return rules;
                ambiguous forms refuse before effects.
              • Root props: explicit props validate before effects and ambient props are
                not adopted.
              • Fragment compatibility: the delivered result and ceilings remain exact;
                Agent and Elicitation remain refused through source.
              • Authority: only evaluation-site authority is usable; producer-private and
                otherwise unavailable capabilities never run.
              • Evaluation replay: retained source resumes nested effects without
                replanning or repeating a completed effect.
              • Changed evaluation source: stale input refuses and neither source runs.
              • Repeated evaluation: two explicit occurrences execute independently and
                are not deduplicated by digest.

              Structural preflight cases place a negative-control effect before a later
              malformed construct and prove the earlier effect did not run.

              Documentation and focused evidence

              Update architecture.md, the component/root/return/execution sections of
              specs/executable-mdx-spec.md, and the generated-XMD section of
              specs/workflow-workspace-spec.md. The documentation names complete-program
              admission separately and leaves #369's vocabulary intact. Update xmd syntax
              and the component inventory for every host profile that exposes <Evaluate>.

              Update the homepage delivered by PR #719 with the direct and deferred
              <Plan>/<Evaluate> compositions and this public model:

              Plan produces a program.
              Evaluate evaluates a program in the current XMD execution.
              Composition decides whether and when a planned program runs.
              

              #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
              remains historical and unchanged.

              Add focused canonical evidence in
              packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
              packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
              compatibility evidence in
              packages/workflow/tests/generated-agent-component.test.ts. Keep
              packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
              control.

              Focused feedback evidence:

              deno task test \
              packages/core/tests/program-evaluation.test.ts \
              packages/cli/tests/evaluate-program-component.test.ts \
              packages/workflow/tests/generated-agent-component.test.ts \
              packages/core/tests/generated-xmd.test.ts \
              packages/cli/tests/syntax-cli.test.ts

              After a feedback commit, run deno task test --changed. Delivery proves npm and
              compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
              packaged-document probes, the build, and required CI checks.

              Dependencies

              There is no dependency on superseded #711 or PR #720.

              Out of scope

              • Implicit execution by <Plan> or any other source-producing component.
              • Widening the restricted generated-XMD evaluator.
              • A <Run> component, process isolation, or a child document lifecycle.
              • Granting authority from source or inheriting producer-private closures.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                enhancementNew feature or request

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Make <Evaluate> evaluate complete XMD programs #713

                  Description

                  @taras

                  Story

                  As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
                  program at an explicit composition site, so producing a program and running it
                  remain separate choices.

                  Common paths

                  Evaluate a planned program directly while privately capturing the source that
                  <Plan> produces:

                  <Evaluate>
                  <Plan>
                  Inspect the release inputs, recommend a version, and ask me to approve it.
                  </Plan>
                  </Evaluate>

                  Or preserve the program first and evaluate it later:

                  <Planas="plan">
                  Inspect the release inputs, recommend a version, and ask me to approve it.
                  </Plan>
                  The approved program is ready. Carry it out here.
                  <Evaluateprogram={plan} />

                  The paired and program forms evaluate a complete root in the current XMD
                  execution. They do not start a child document, process, host profile, root
                  lifecycle, or independent journal.

                  Three disjoint forms

                  <Evaluate> has three mutually exclusive inputs:

                  1. paired content produces complete-program source in a private buffer;
                  2. program={value} supplies complete-program source directly; and
                  3. source={fragment} retains the restricted generated-XMD meaning delivered
                    by Evaluate Agent-generated XMD through a constrained allowlist #369.

                  source, program, and paired content cannot be combined. allow is valid
                  only with source. props={object} is valid only with a complete-program form.
                  Every ambiguous or misplaced combination refuses before program content or a
                  program effect runs.

                  The paired form suppresses its source-producing output from the surrounding
                  document, removes only indentation contributed by the <Evaluate> wrapper, and
                  admits the resulting complete root. Bytes emitted by a producer are otherwise
                  unchanged. With a sole <Plan> producer, paired evaluation and
                  program={plan} admit the same approved bytes and content digest.

                  Another source-producing text component may be used in paired content when its
                  rendered result is a complete admissible root. Paired content is not quotation:
                  an executable component written literally there executes under ordinary XMD
                  semantics while producing the text sent to admission.

                  Complete-program behavior

                  The complete root's frontmatter, imports, metadata, props schema, returns, and
                  <Output> selection apply.

                  • props={object} is the complete root's props input. It defaults to {};
                    ambient root props are never silently adopted.
                  • Root props are schema-validated before the first program effect.
                  • Ordinary non-props caller bindings are visible read-only. Program-local
                    bindings do not escape the evaluation.
                  • Relative imports resolve from the source origin of the authored <Evaluate>
                    site.
                  • A text root executes and renders its selected output without as; with as,
                    it still executes, binds that selected text as a string, and emits none of it.
                  • A value root requires as before its first effect and binds its
                    schema-validated JSON result. Without as, it refuses before program effects.

                  The ordinary run profile exposes the complete-program forms. A workflow run's
                  <Evaluate> exposes those forms plus its existing restricted source form.
                  The author-facing description is:

                  Evaluate XMD source in the current execution. <Evaluate program={plan} />
                  evaluates a complete program. Use
                  <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
                  fragment.

                  Structured syntax fields own the form, prop, capture, return, and origin details.

                  Current-site authority

                  Complete-program evaluation uses the current execution's lifecycle, journal,
                  cancellation scope, contextual providers, working directory or Workspace, and
                  authority at the authored <Evaluate> site. Program source requests behavior;
                  it grants none.

                  The producer's temporary authority is not inherited. In particular, <Plan>'s
                  authorship profile and private components have torn down before evaluation, and
                  a private component belonging to an enclosing declaration is available only to
                  elements authored by that declaration's exact bytes. Source returned by a
                  producer cannot invoke either closure. Ordinary imports and capabilities that
                  are genuinely present at the evaluation site remain available.

                  Separate admission and replay

                  Complete programs use a distinct complete-program admission and durable event;
                  do not widen or reuse generated_xmd. Before the first program effect, retain
                  and hostile-parse the exact source and digest, explicit props, evaluation-site
                  source origin, root mode, resolved component identities and forms, and every
                  compatibility term needed to prove the same current-site environment.

                  A partial continuation expands the retained source, restores completed nested
                  effects, and repeats no planning. Changed source at the same evaluation
                  occurrence is stale input and refuses before either current or retained source
                  can run. Neither source silently wins.

                  The source digest identifies the program artifact. The authored <Evaluate>
                  site and loop iteration identify one execution occurrence. Deliberately
                  evaluating the same artifact at two sites or iterations creates independent
                  nested effect identities; the digest never deduplicates those executions.

                  Restricted-fragment compatibility

                  <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
                  contract exactly:

                  • the closed generated-XMD grammar and selected read/write ceilings;
                  • caller-binding isolation;
                  • the generated_xmd admission and retained-source replay;
                  • pinned component identities and forms; and
                  • the exact { observations, output } result.

                  Complete-program support cannot be selected through source or allow.
                  Representative Agent, Elicitation, import, binding, executable-block, and
                  unadmitted-component cases still refuse through source before effects.

                  Acceptance ownership

                  This story exclusively owns these Quest cases:

                  • Direct composition: paired Plan source evaluates once and is not emitted
                    separately.
                  • Deferred composition:program={plan} evaluates the same digest without
                    repeating planning.
                  • Program forms: text and value roots follow their output and return rules;
                    ambiguous forms refuse before effects.
                  • Root props: explicit props validate before effects and ambient props are
                    not adopted.
                  • Fragment compatibility: the delivered result and ceilings remain exact;
                    Agent and Elicitation remain refused through source.
                  • Authority: only evaluation-site authority is usable; producer-private and
                    otherwise unavailable capabilities never run.
                  • Evaluation replay: retained source resumes nested effects without
                    replanning or repeating a completed effect.
                  • Changed evaluation source: stale input refuses and neither source runs.
                  • Repeated evaluation: two explicit occurrences execute independently and
                    are not deduplicated by digest.

                  Structural preflight cases place a negative-control effect before a later
                  malformed construct and prove the earlier effect did not run.

                  Documentation and focused evidence

                  Update architecture.md, the component/root/return/execution sections of
                  specs/executable-mdx-spec.md, and the generated-XMD section of
                  specs/workflow-workspace-spec.md. The documentation names complete-program
                  admission separately and leaves #369's vocabulary intact. Update xmd syntax
                  and the component inventory for every host profile that exposes <Evaluate>.

                  Update the homepage delivered by PR #719 with the direct and deferred
                  <Plan>/<Evaluate> compositions and this public model:

                  Plan produces a program.
                  Evaluate evaluates a program in the current XMD execution.
                  Composition decides whether and when a planned program runs.
                  

                  #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
                  remains historical and unchanged.

                  Add focused canonical evidence in
                  packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
                  packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
                  compatibility evidence in
                  packages/workflow/tests/generated-agent-component.test.ts. Keep
                  packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
                  control.

                  Focused feedback evidence:

                  deno task test \
                  packages/core/tests/program-evaluation.test.ts \
                  packages/cli/tests/evaluate-program-component.test.ts \
                  packages/workflow/tests/generated-agent-component.test.ts \
                  packages/core/tests/generated-xmd.test.ts \
                  packages/cli/tests/syntax-cli.test.ts

                  After a feedback commit, run deno task test --changed. Delivery proves npm and
                  compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
                  packaged-document probes, the build, and required CI checks.

                  Dependencies

                  There is no dependency on superseded #711 or PR #720.

                  Out of scope

                  • Implicit execution by <Plan> or any other source-producing component.
                  • Widening the restricted generated-XMD evaluator.
                  • A <Run> component, process isolation, or a child document lifecycle.
                  • Granting authority from source or inheriting producer-private closures.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    enhancementNew feature or request

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Make <Evaluate> evaluate complete XMD programs #713

                      Description

                      @taras

                      Story

                      As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
                      program at an explicit composition site, so producing a program and running it
                      remain separate choices.

                      Common paths

                      Evaluate a planned program directly while privately capturing the source that
                      <Plan> produces:

                      <Evaluate>
                      <Plan>
                      Inspect the release inputs, recommend a version, and ask me to approve it.
                      </Plan>
                      </Evaluate>

                      Or preserve the program first and evaluate it later:

                      <Planas="plan">
                      Inspect the release inputs, recommend a version, and ask me to approve it.
                      </Plan>
                      The approved program is ready. Carry it out here.
                      <Evaluateprogram={plan} />

                      The paired and program forms evaluate a complete root in the current XMD
                      execution. They do not start a child document, process, host profile, root
                      lifecycle, or independent journal.

                      Three disjoint forms

                      <Evaluate> has three mutually exclusive inputs:

                      1. paired content produces complete-program source in a private buffer;
                      2. program={value} supplies complete-program source directly; and
                      3. source={fragment} retains the restricted generated-XMD meaning delivered
                        by Evaluate Agent-generated XMD through a constrained allowlist #369.

                      source, program, and paired content cannot be combined. allow is valid
                      only with source. props={object} is valid only with a complete-program form.
                      Every ambiguous or misplaced combination refuses before program content or a
                      program effect runs.

                      The paired form suppresses its source-producing output from the surrounding
                      document, removes only indentation contributed by the <Evaluate> wrapper, and
                      admits the resulting complete root. Bytes emitted by a producer are otherwise
                      unchanged. With a sole <Plan> producer, paired evaluation and
                      program={plan} admit the same approved bytes and content digest.

                      Another source-producing text component may be used in paired content when its
                      rendered result is a complete admissible root. Paired content is not quotation:
                      an executable component written literally there executes under ordinary XMD
                      semantics while producing the text sent to admission.

                      Complete-program behavior

                      The complete root's frontmatter, imports, metadata, props schema, returns, and
                      <Output> selection apply.

                      • props={object} is the complete root's props input. It defaults to {};
                        ambient root props are never silently adopted.
                      • Root props are schema-validated before the first program effect.
                      • Ordinary non-props caller bindings are visible read-only. Program-local
                        bindings do not escape the evaluation.
                      • Relative imports resolve from the source origin of the authored <Evaluate>
                        site.
                      • A text root executes and renders its selected output without as; with as,
                        it still executes, binds that selected text as a string, and emits none of it.
                      • A value root requires as before its first effect and binds its
                        schema-validated JSON result. Without as, it refuses before program effects.

                      The ordinary run profile exposes the complete-program forms. A workflow run's
                      <Evaluate> exposes those forms plus its existing restricted source form.
                      The author-facing description is:

                      Evaluate XMD source in the current execution. <Evaluate program={plan} />
                      evaluates a complete program. Use
                      <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
                      fragment.

                      Structured syntax fields own the form, prop, capture, return, and origin details.

                      Current-site authority

                      Complete-program evaluation uses the current execution's lifecycle, journal,
                      cancellation scope, contextual providers, working directory or Workspace, and
                      authority at the authored <Evaluate> site. Program source requests behavior;
                      it grants none.

                      The producer's temporary authority is not inherited. In particular, <Plan>'s
                      authorship profile and private components have torn down before evaluation, and
                      a private component belonging to an enclosing declaration is available only to
                      elements authored by that declaration's exact bytes. Source returned by a
                      producer cannot invoke either closure. Ordinary imports and capabilities that
                      are genuinely present at the evaluation site remain available.

                      Separate admission and replay

                      Complete programs use a distinct complete-program admission and durable event;
                      do not widen or reuse generated_xmd. Before the first program effect, retain
                      and hostile-parse the exact source and digest, explicit props, evaluation-site
                      source origin, root mode, resolved component identities and forms, and every
                      compatibility term needed to prove the same current-site environment.

                      A partial continuation expands the retained source, restores completed nested
                      effects, and repeats no planning. Changed source at the same evaluation
                      occurrence is stale input and refuses before either current or retained source
                      can run. Neither source silently wins.

                      The source digest identifies the program artifact. The authored <Evaluate>
                      site and loop iteration identify one execution occurrence. Deliberately
                      evaluating the same artifact at two sites or iterations creates independent
                      nested effect identities; the digest never deduplicates those executions.

                      Restricted-fragment compatibility

                      <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
                      contract exactly:

                      • the closed generated-XMD grammar and selected read/write ceilings;
                      • caller-binding isolation;
                      • the generated_xmd admission and retained-source replay;
                      • pinned component identities and forms; and
                      • the exact { observations, output } result.

                      Complete-program support cannot be selected through source or allow.
                      Representative Agent, Elicitation, import, binding, executable-block, and
                      unadmitted-component cases still refuse through source before effects.

                      Acceptance ownership

                      This story exclusively owns these Quest cases:

                      • Direct composition: paired Plan source evaluates once and is not emitted
                        separately.
                      • Deferred composition:program={plan} evaluates the same digest without
                        repeating planning.
                      • Program forms: text and value roots follow their output and return rules;
                        ambiguous forms refuse before effects.
                      • Root props: explicit props validate before effects and ambient props are
                        not adopted.
                      • Fragment compatibility: the delivered result and ceilings remain exact;
                        Agent and Elicitation remain refused through source.
                      • Authority: only evaluation-site authority is usable; producer-private and
                        otherwise unavailable capabilities never run.
                      • Evaluation replay: retained source resumes nested effects without
                        replanning or repeating a completed effect.
                      • Changed evaluation source: stale input refuses and neither source runs.
                      • Repeated evaluation: two explicit occurrences execute independently and
                        are not deduplicated by digest.

                      Structural preflight cases place a negative-control effect before a later
                      malformed construct and prove the earlier effect did not run.

                      Documentation and focused evidence

                      Update architecture.md, the component/root/return/execution sections of
                      specs/executable-mdx-spec.md, and the generated-XMD section of
                      specs/workflow-workspace-spec.md. The documentation names complete-program
                      admission separately and leaves #369's vocabulary intact. Update xmd syntax
                      and the component inventory for every host profile that exposes <Evaluate>.

                      Update the homepage delivered by PR #719 with the direct and deferred
                      <Plan>/<Evaluate> compositions and this public model:

                      Plan produces a program.
                      Evaluate evaluates a program in the current XMD execution.
                      Composition decides whether and when a planned program runs.
                      

                      #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
                      remains historical and unchanged.

                      Add focused canonical evidence in
                      packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
                      packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
                      compatibility evidence in
                      packages/workflow/tests/generated-agent-component.test.ts. Keep
                      packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
                      control.

                      Focused feedback evidence:

                      deno task test \
                      packages/core/tests/program-evaluation.test.ts \
                      packages/cli/tests/evaluate-program-component.test.ts \
                      packages/workflow/tests/generated-agent-component.test.ts \
                      packages/core/tests/generated-xmd.test.ts \
                      packages/cli/tests/syntax-cli.test.ts

                      After a feedback commit, run deno task test --changed. Delivery proves npm and
                      compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
                      packaged-document probes, the build, and required CI checks.

                      Dependencies

                      There is no dependency on superseded #711 or PR #720.

                      Out of scope

                      • Implicit execution by <Plan> or any other source-producing component.
                      • Widening the restricted generated-XMD evaluator.
                      • A <Run> component, process isolation, or a child document lifecycle.
                      • Granting authority from source or inheriting producer-private closures.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        enhancementNew feature or request

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Make <Evaluate> evaluate complete XMD programs #713

                          Description

                          @taras

                          Story

                          As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
                          program at an explicit composition site, so producing a program and running it
                          remain separate choices.

                          Common paths

                          Evaluate a planned program directly while privately capturing the source that
                          <Plan> produces:

                          <Evaluate>
                          <Plan>
                          Inspect the release inputs, recommend a version, and ask me to approve it.
                          </Plan>
                          </Evaluate>

                          Or preserve the program first and evaluate it later:

                          <Planas="plan">
                          Inspect the release inputs, recommend a version, and ask me to approve it.
                          </Plan>
                          The approved program is ready. Carry it out here.
                          <Evaluateprogram={plan} />

                          The paired and program forms evaluate a complete root in the current XMD
                          execution. They do not start a child document, process, host profile, root
                          lifecycle, or independent journal.

                          Three disjoint forms

                          <Evaluate> has three mutually exclusive inputs:

                          1. paired content produces complete-program source in a private buffer;
                          2. program={value} supplies complete-program source directly; and
                          3. source={fragment} retains the restricted generated-XMD meaning delivered
                            by Evaluate Agent-generated XMD through a constrained allowlist #369.

                          source, program, and paired content cannot be combined. allow is valid
                          only with source. props={object} is valid only with a complete-program form.
                          Every ambiguous or misplaced combination refuses before program content or a
                          program effect runs.

                          The paired form suppresses its source-producing output from the surrounding
                          document, removes only indentation contributed by the <Evaluate> wrapper, and
                          admits the resulting complete root. Bytes emitted by a producer are otherwise
                          unchanged. With a sole <Plan> producer, paired evaluation and
                          program={plan} admit the same approved bytes and content digest.

                          Another source-producing text component may be used in paired content when its
                          rendered result is a complete admissible root. Paired content is not quotation:
                          an executable component written literally there executes under ordinary XMD
                          semantics while producing the text sent to admission.

                          Complete-program behavior

                          The complete root's frontmatter, imports, metadata, props schema, returns, and
                          <Output> selection apply.

                          • props={object} is the complete root's props input. It defaults to {};
                            ambient root props are never silently adopted.
                          • Root props are schema-validated before the first program effect.
                          • Ordinary non-props caller bindings are visible read-only. Program-local
                            bindings do not escape the evaluation.
                          • Relative imports resolve from the source origin of the authored <Evaluate>
                            site.
                          • A text root executes and renders its selected output without as; with as,
                            it still executes, binds that selected text as a string, and emits none of it.
                          • A value root requires as before its first effect and binds its
                            schema-validated JSON result. Without as, it refuses before program effects.

                          The ordinary run profile exposes the complete-program forms. A workflow run's
                          <Evaluate> exposes those forms plus its existing restricted source form.
                          The author-facing description is:

                          Evaluate XMD source in the current execution. <Evaluate program={plan} />
                          evaluates a complete program. Use
                          <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
                          fragment.

                          Structured syntax fields own the form, prop, capture, return, and origin details.

                          Current-site authority

                          Complete-program evaluation uses the current execution's lifecycle, journal,
                          cancellation scope, contextual providers, working directory or Workspace, and
                          authority at the authored <Evaluate> site. Program source requests behavior;
                          it grants none.

                          The producer's temporary authority is not inherited. In particular, <Plan>'s
                          authorship profile and private components have torn down before evaluation, and
                          a private component belonging to an enclosing declaration is available only to
                          elements authored by that declaration's exact bytes. Source returned by a
                          producer cannot invoke either closure. Ordinary imports and capabilities that
                          are genuinely present at the evaluation site remain available.

                          Separate admission and replay

                          Complete programs use a distinct complete-program admission and durable event;
                          do not widen or reuse generated_xmd. Before the first program effect, retain
                          and hostile-parse the exact source and digest, explicit props, evaluation-site
                          source origin, root mode, resolved component identities and forms, and every
                          compatibility term needed to prove the same current-site environment.

                          A partial continuation expands the retained source, restores completed nested
                          effects, and repeats no planning. Changed source at the same evaluation
                          occurrence is stale input and refuses before either current or retained source
                          can run. Neither source silently wins.

                          The source digest identifies the program artifact. The authored <Evaluate>
                          site and loop iteration identify one execution occurrence. Deliberately
                          evaluating the same artifact at two sites or iterations creates independent
                          nested effect identities; the digest never deduplicates those executions.

                          Restricted-fragment compatibility

                          <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
                          contract exactly:

                          • the closed generated-XMD grammar and selected read/write ceilings;
                          • caller-binding isolation;
                          • the generated_xmd admission and retained-source replay;
                          • pinned component identities and forms; and
                          • the exact { observations, output } result.

                          Complete-program support cannot be selected through source or allow.
                          Representative Agent, Elicitation, import, binding, executable-block, and
                          unadmitted-component cases still refuse through source before effects.

                          Acceptance ownership

                          This story exclusively owns these Quest cases:

                          • Direct composition: paired Plan source evaluates once and is not emitted
                            separately.
                          • Deferred composition:program={plan} evaluates the same digest without
                            repeating planning.
                          • Program forms: text and value roots follow their output and return rules;
                            ambiguous forms refuse before effects.
                          • Root props: explicit props validate before effects and ambient props are
                            not adopted.
                          • Fragment compatibility: the delivered result and ceilings remain exact;
                            Agent and Elicitation remain refused through source.
                          • Authority: only evaluation-site authority is usable; producer-private and
                            otherwise unavailable capabilities never run.
                          • Evaluation replay: retained source resumes nested effects without
                            replanning or repeating a completed effect.
                          • Changed evaluation source: stale input refuses and neither source runs.
                          • Repeated evaluation: two explicit occurrences execute independently and
                            are not deduplicated by digest.

                          Structural preflight cases place a negative-control effect before a later
                          malformed construct and prove the earlier effect did not run.

                          Documentation and focused evidence

                          Update architecture.md, the component/root/return/execution sections of
                          specs/executable-mdx-spec.md, and the generated-XMD section of
                          specs/workflow-workspace-spec.md. The documentation names complete-program
                          admission separately and leaves #369's vocabulary intact. Update xmd syntax
                          and the component inventory for every host profile that exposes <Evaluate>.

                          Update the homepage delivered by PR #719 with the direct and deferred
                          <Plan>/<Evaluate> compositions and this public model:

                          Plan produces a program.
                          Evaluate evaluates a program in the current XMD execution.
                          Composition decides whether and when a planned program runs.
                          

                          #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
                          remains historical and unchanged.

                          Add focused canonical evidence in
                          packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
                          packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
                          compatibility evidence in
                          packages/workflow/tests/generated-agent-component.test.ts. Keep
                          packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
                          control.

                          Focused feedback evidence:

                          deno task test \
                          packages/core/tests/program-evaluation.test.ts \
                          packages/cli/tests/evaluate-program-component.test.ts \
                          packages/workflow/tests/generated-agent-component.test.ts \
                          packages/core/tests/generated-xmd.test.ts \
                          packages/cli/tests/syntax-cli.test.ts

                          After a feedback commit, run deno task test --changed. Delivery proves npm and
                          compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
                          packaged-document probes, the build, and required CI checks.

                          Dependencies

                          There is no dependency on superseded #711 or PR #720.

                          Out of scope

                          • Implicit execution by <Plan> or any other source-producing component.
                          • Widening the restricted generated-XMD evaluator.
                          • A <Run> component, process isolation, or a child document lifecycle.
                          • Granting authority from source or inheriting producer-private closures.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            enhancementNew feature or request

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Make <Evaluate> evaluate complete XMD programs #713

                              Description

                              @taras

                              Story

                              As an Executable Markdown author, I want <Evaluate> to evaluate a complete XMD
                              program at an explicit composition site, so producing a program and running it
                              remain separate choices.

                              Common paths

                              Evaluate a planned program directly while privately capturing the source that
                              <Plan> produces:

                              <Evaluate>
                              <Plan>
                              Inspect the release inputs, recommend a version, and ask me to approve it.
                              </Plan>
                              </Evaluate>

                              Or preserve the program first and evaluate it later:

                              <Planas="plan">
                              Inspect the release inputs, recommend a version, and ask me to approve it.
                              </Plan>
                              The approved program is ready. Carry it out here.
                              <Evaluateprogram={plan} />

                              The paired and program forms evaluate a complete root in the current XMD
                              execution. They do not start a child document, process, host profile, root
                              lifecycle, or independent journal.

                              Three disjoint forms

                              <Evaluate> has three mutually exclusive inputs:

                              1. paired content produces complete-program source in a private buffer;
                              2. program={value} supplies complete-program source directly; and
                              3. source={fragment} retains the restricted generated-XMD meaning delivered
                                by Evaluate Agent-generated XMD through a constrained allowlist #369.

                              source, program, and paired content cannot be combined. allow is valid
                              only with source. props={object} is valid only with a complete-program form.
                              Every ambiguous or misplaced combination refuses before program content or a
                              program effect runs.

                              The paired form suppresses its source-producing output from the surrounding
                              document, removes only indentation contributed by the <Evaluate> wrapper, and
                              admits the resulting complete root. Bytes emitted by a producer are otherwise
                              unchanged. With a sole <Plan> producer, paired evaluation and
                              program={plan} admit the same approved bytes and content digest.

                              Another source-producing text component may be used in paired content when its
                              rendered result is a complete admissible root. Paired content is not quotation:
                              an executable component written literally there executes under ordinary XMD
                              semantics while producing the text sent to admission.

                              Complete-program behavior

                              The complete root's frontmatter, imports, metadata, props schema, returns, and
                              <Output> selection apply.

                              • props={object} is the complete root's props input. It defaults to {};
                                ambient root props are never silently adopted.
                              • Root props are schema-validated before the first program effect.
                              • Ordinary non-props caller bindings are visible read-only. Program-local
                                bindings do not escape the evaluation.
                              • Relative imports resolve from the source origin of the authored <Evaluate>
                                site.
                              • A text root executes and renders its selected output without as; with as,
                                it still executes, binds that selected text as a string, and emits none of it.
                              • A value root requires as before its first effect and binds its
                                schema-validated JSON result. Without as, it refuses before program effects.

                              The ordinary run profile exposes the complete-program forms. A workflow run's
                              <Evaluate> exposes those forms plus its existing restricted source form.
                              The author-facing description is:

                              Evaluate XMD source in the current execution. <Evaluate program={plan} />
                              evaluates a complete program. Use
                              <Evaluate source={fragment} allow={["read"]} /> for a restricted generated
                              fragment.

                              Structured syntax fields own the form, prop, capture, return, and origin details.

                              Current-site authority

                              Complete-program evaluation uses the current execution's lifecycle, journal,
                              cancellation scope, contextual providers, working directory or Workspace, and
                              authority at the authored <Evaluate> site. Program source requests behavior;
                              it grants none.

                              The producer's temporary authority is not inherited. In particular, <Plan>'s
                              authorship profile and private components have torn down before evaluation, and
                              a private component belonging to an enclosing declaration is available only to
                              elements authored by that declaration's exact bytes. Source returned by a
                              producer cannot invoke either closure. Ordinary imports and capabilities that
                              are genuinely present at the evaluation site remain available.

                              Separate admission and replay

                              Complete programs use a distinct complete-program admission and durable event;
                              do not widen or reuse generated_xmd. Before the first program effect, retain
                              and hostile-parse the exact source and digest, explicit props, evaluation-site
                              source origin, root mode, resolved component identities and forms, and every
                              compatibility term needed to prove the same current-site environment.

                              A partial continuation expands the retained source, restores completed nested
                              effects, and repeats no planning. Changed source at the same evaluation
                              occurrence is stale input and refuses before either current or retained source
                              can run. Neither source silently wins.

                              The source digest identifies the program artifact. The authored <Evaluate>
                              site and loop iteration identify one execution occurrence. Deliberately
                              evaluating the same artifact at two sites or iterations creates independent
                              nested effect identities; the digest never deduplicates those executions.

                              Restricted-fragment compatibility

                              <Evaluate source={fragment} allow={...} as="observation" /> keeps #369's
                              contract exactly:

                              • the closed generated-XMD grammar and selected read/write ceilings;
                              • caller-binding isolation;
                              • the generated_xmd admission and retained-source replay;
                              • pinned component identities and forms; and
                              • the exact { observations, output } result.

                              Complete-program support cannot be selected through source or allow.
                              Representative Agent, Elicitation, import, binding, executable-block, and
                              unadmitted-component cases still refuse through source before effects.

                              Acceptance ownership

                              This story exclusively owns these Quest cases:

                              • Direct composition: paired Plan source evaluates once and is not emitted
                                separately.
                              • Deferred composition:program={plan} evaluates the same digest without
                                repeating planning.
                              • Program forms: text and value roots follow their output and return rules;
                                ambiguous forms refuse before effects.
                              • Root props: explicit props validate before effects and ambient props are
                                not adopted.
                              • Fragment compatibility: the delivered result and ceilings remain exact;
                                Agent and Elicitation remain refused through source.
                              • Authority: only evaluation-site authority is usable; producer-private and
                                otherwise unavailable capabilities never run.
                              • Evaluation replay: retained source resumes nested effects without
                                replanning or repeating a completed effect.
                              • Changed evaluation source: stale input refuses and neither source runs.
                              • Repeated evaluation: two explicit occurrences execute independently and
                                are not deduplicated by digest.

                              Structural preflight cases place a negative-control effect before a later
                              malformed construct and prove the earlier effect did not run.

                              Documentation and focused evidence

                              Update architecture.md, the component/root/return/execution sections of
                              specs/executable-mdx-spec.md, and the generated-XMD section of
                              specs/workflow-workspace-spec.md. The documentation names complete-program
                              admission separately and leaves #369's vocabulary intact. Update xmd syntax
                              and the component inventory for every host profile that exposes <Evaluate>.

                              Update the homepage delivered by PR #719 with the direct and deferred
                              <Plan>/<Evaluate> compositions and this public model:

                              Plan produces a program.
                              Evaluate evaluates a program in the current XMD execution.
                              Composition decides whether and when a planned program runs.
                              

                              #724 separately owns the homepage's xmd plan | xmd run - composition. PR #719
                              remains historical and unchanged.

                              Add focused canonical evidence in
                              packages/core/tests/program-evaluation.test.ts; public run-profile evidence in
                              packages/cli/tests/evaluate-program-component.test.ts; and workflow-profile
                              compatibility evidence in
                              packages/workflow/tests/generated-agent-component.test.ts. Keep
                              packages/core/tests/generated-xmd.test.ts as the restricted-fragment negative
                              control.

                              Focused feedback evidence:

                              deno task test \
                              packages/core/tests/program-evaluation.test.ts \
                              packages/cli/tests/evaluate-program-component.test.ts \
                              packages/workflow/tests/generated-agent-component.test.ts \
                              packages/core/tests/generated-xmd.test.ts \
                              packages/cli/tests/syntax-cli.test.ts

                              After a feedback commit, run deno task test --changed. Delivery proves npm and
                              compiled distribution through scripts/tests/cli-npm-bin.test.ts, the ordinary
                              packaged-document probes, the build, and required CI checks.

                              Dependencies

                              There is no dependency on superseded #711 or PR #720.

                              Out of scope

                              • Implicit execution by <Plan> or any other source-producing component.
                              • Widening the restricted generated-XMD evaluator.
                              • A <Run> component, process isolation, or a child document lifecycle.
                              • Granting authority from source or inheriting producer-private closures.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                enhancementNew feature or request

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions