Core Panda consultation is not obsolete. This migration applies only to strict Loop execution
authority: old inputs remain readable, but Loop v2 requires fresh workspace evidence before approval or resume.
Strict boundary
Keep readable history. Rebuild execution authority.
Loop v2 keeps compatibility at the parser and inspection layers while refusing to infer trust from old
approvals, partial evidence, or ambiguous side effects.
Task files Legacy and unspecified schemas
Still parsed, with strict normalization max_iterations aliases verification cycles; conflicting values and
verification_passes: false are rejected.
Approval panda_preflight.v1.json
Inspect only; regenerate Loop v2 preflight
Preflight v2 binds the exact task, reviewers, privacy mode, canonical workspace, initial
fingerprint, artifacts, repair policy, and mutation limits.
Summary review Advisory prose
Pin structured evidence advisory-summary needs a valid implementation summary and raw-file SHA-256.
Full-context review needs inspected files unless the candidate explicitly made no change.
Reviewer policy Best-effort reviewer gate
Every frozen reviewer is mandatory
There is no quorum fallback. Missing, malformed, abstaining, timed-out, incomplete, or
workspace-mutating review escalates.
Repair Broad feedback input
Verifier-backed by default
Review-only repair is opt-in. Automatic and typed repairs produce reports; mutation defaults to
20 files, 1,000 lines, and no binary or symlink changes.
Run history Schema-v1 event logs
Inspectable, never auto-resumed
New runs record phase input digests and idempotency keys. Resume continues only from safe
boundaries; ambiguous interrupted repair escalates.
Defaults: without repair, one verification cycle and zero repairs; with repair, two cycles and one repair.
Hard ceilings are three cycles, two repairs, and 3,600 seconds. Allowed mutation paths derive from the
validated implementation summary unless the task explicitly narrows or broadens them.