# CartoonOS — Prove the Loop Execution Plan v0.1 Status: active P0 execution plan Date: 2026-09-08 Owner model: shared CartoonOS capabilities; no new executive agents/services. Current runtime snapshot: [`CURRENT_RUNTIME_STATUS_2026-09-08.md`](CURRENT_RUNTIME_STATUS_2026-09-08.md) ## Objective Move CartoonOS from strong architecture/composability to production-verified evidence by proving one complete loop: `plan → produce → publish → measure → learn → improve → produce again` First proof uses Luminautas Project #1, a **story-selected cast**, one controlled recurring environment, Golden Shot → Golden Sequence → 45–90 second Golden Short, then real D1/D3/D7 learning before flagship production. No fixed duo is a global prerequisite. All seven mascots maintain baseline identity/voice/reference readiness; package-specific deep readiness follows the approved story. ## Non-negotiable rules - make the brain deeper, not the architecture bigger; - underneath specialized responsibilities: skills, tools and deterministic workflows, not more agents; - no parallel RAG/analytics/character/publishing pipeline; - every production fact is project-scoped, versioned and reconstructable; - provider syntax stays behind adapters/compilers; - generation consumes exact approved ShotSpecs/frozen compiled requests; - quality/safety/factual/IP gates are non-compensating; - optimize accepted output and downstream value, not API-call volume; - no production-ready claim without target-environment evidence. ## Current composed baseline Implemented/composed: - 13-activity production workflow with explicit `compile_shots_for_generation`; - ScenePlan / BeatMap / ShotSpec / ContinuityLedger / AssetReusePlan / DirectorSpec / RenderPlan; - RoughCutArtifact / AudioPlan / EditPlan + hard gate; - PromptIR, shot-family routing, reference budgeting, parameter allowlists and safe coercions; - deterministic checksummed `CompiledVideoRequest` objects; - exact ShotSpec coverage + provider/model/checksum validation; - generation attempt IDs/provider job IDs/failure taxonomy/repair provenance; - generation acceptance separated from `RoughCutShot.selected_attempt_id` editorial selection; - selected-attempt validation against the actual workflow run set; - durable compiled request + attempt + accepted output asset/checksum/URI schema path through migration 016; - shot-level attempts/generated seconds/accepted seconds/first-pass/cost-per-accepted-second observations; - Environment OS binding contracts; - Observation / Eval / Experiment / DARL / checkpoint / economics spine; - omnichannel distribution contract/fan-out doctrine. Not production-verified: - trusted green GitHub Actions on exact production revision; - protected `main` requiring trusted checks; - PostgreSQL migration proof through head 016; - live 13-activity Temporal worker with production dependencies; - fresh live provider capability ingestion/hashes; - real provider/Higgsfield Golden Shot with immutable media storage; - real social publishing adapters + reconciliation; - real D1/D3/D7 learning closure. ## P0-A — Engineering trust Done only when: 1. Actions executes repository steps successfully; 2. `main` requires trusted checks; 3. Alembic `001 → 016` upgrades on clean PostgreSQL, downgrades/re-upgrades safely and resolves one head; 4. 13-activity Temporal worker boots with validated dependencies; 5. object/media storage passes SHA-256 round-trip; 6. replay/recovery proves no duplicate external mutation. ## P0-B — Scene-to-Screen Already composed: scene/beat/shot/continuity/reuse/directing/render contracts, compiled-shot generation, rough-cut/audio/edit gate, selected-attempt validation and shot-level economics. Remaining: - make RenderPlan hard budget + accepted-second economics an execution veto; - persist approved ScenePlan/ContinuityLedger/RenderPlan/RoughCut graphs durably; - supply real SceneToScreenPlanner + RoughCutBuilderReviewer adapters; - prove full target-environment execution. ## P0-C — Prompt/model compilation Canonical sequence: `ShotSpec → PromptIR → ModelCapabilitySnapshot → ReferenceBudget/ParameterPolicy/CostPreflight → ProviderAdapter → CompiledVideoRequest → durable request → GenerationAttempt → durable output → RoughCut selection` Remaining: - live/fresh capability registry ingestion; - RenderPlan budget/economics integration; - deterministic failure-directed repair + negative enrichment; - explicit native-audio vs controlled-stems routing; - routing by expected quality × first-pass yield × cost/accepted-second × latency; - telemetry-based prompt/reference/negative-budget calibration. ## P0-D — Environment/provider proof Canonical environment chain: `EnvironmentPack → SceneGeographyBinding → ShotEnvironmentBinding → EnvironmentReferenceBundle → ShotSpec → CompiledVideoRequest` First recurring pack: **Luminautas HQ/Lab**. Live proof must preserve exact environment/cast/prop refs, capability hash, provider/model/version, compiled request checksum, cost preflight, provider job ID, attempt/failure/repair evidence, output asset/checksum/URI, latency/cost and QA decision. ## P0-E — Golden evidence ladder ### 1. Golden Character baseline All seven mascots maintain independent visual/voice/reference/provider/Golden readiness. ### 2. Golden Shot One story-selected shot passes exact compiled-request/provider/output/economics provenance and hard QA. ### 3. Golden Sequence 3–5 dependent shots pass identity, environment geography/scale, anchors, camera, lighting/props/audio and rough-cut continuity. ### 4. Golden Short 45–90 second approved canonical Short produced from the proven pipeline. ### 5. Golden Publication Publish through deterministic independent platform queues with rendition checksums, idempotency and reconciliation. ### 6. Golden Learning Cycle Real D1/D3/D7 observations cause one reviewed persisted Decision → Action → Result → Learning change in the next package. ### 7. Flagship Only after the Short proves runtime/distribution/learning boundaries should flagship production scale. ## P0-F — Measurement/economics Primary North Star: **90-day quality watch hours / production dollar** Track per project/format/platform/mascot/cast/shot/model/provider: - first-pass acceptance; - attempts / accepted shot; - accepted / generated seconds; - cost / accepted second; - p50/p95 latency; - continuity/failure/repair rates; - reuse ratio/avoided cost; - retention/completion/rewatch/saves/shares; - returning-viewer contribution; - contribution margin; - character/IP affinity; - explicit delayed recall/transfer when actually measured. Engagement does not prove learning. ## Exit criteria — PRODUCTION_VERIFIED_LOOP All must be true on the exact production revision: - trusted green CI; - protected merge path; - PostgreSQL/Temporal proof; - Golden Shot and Golden Sequence pass with real provider evidence; - Golden Short published through real adapter(s); - reconciliation proves no duplicate mutation; - real metrics enter project-scoped observations; - economics derive from actual production/performance evidence; - one measured learning changes the next package; - no fixture/planning metric is presented as live. ## What not to build now - no new executive agents; - no Kafka/NATS without measured need; - no broad microservice split; - no second analytics/RAG/learning store; - no autonomous commercial/financial commitment; - no mass episode production before Golden Short; - no mass environment modeling before reuse ROI evidence. ## Execution order 1. restore trusted GitHub Actions + protect `main`; 2. prove PostgreSQL Alembic `001 → 016`; 3. boot live 13-activity Temporal worker; 4. resolve provider access + fresh capability ingestion; 5. complete HQ/Lab EnvironmentReferenceBundle/CameraAnchors; 6. stabilize all-seven mascot baseline readiness; 7. promote story-selected cast only; 8. bind hard RenderPlan budget + deterministic repair routing; 9. persist remaining planning/rough-cut artifacts; 10. Golden Shot; 11. Golden Sequence; 12. Golden Short; 13. deterministic publication/reconciliation; 14. D1/D3/D7 + actual economics; 15. measured learning changes next package; 16. flagship/scaling only after repeatability evidence.