# Native two-phase orientation contract
Native owns lifecycle and binding/verification artifacts; children consume them.
## Pre-Critic artifacts
`shepherd run orientation pre <run>` derives fixed `phase0.md` and every stopped Auditor/Discovery `result_artifact` from native dispatch. Critic-before-pre, active/stale children, substitutions, symlinks, and noncanonical/wrong-project/run paths fail. Each hashed file is read through one no-follow descriptor.
It refuses to clobber exactly:
- `.shepherd/runs/<run>/orientation-manifest.json`
- `.shepherd/runs/<run>/orientation-pre.json`
Manifest `shepherd.orientation-manifest/2` has phase `pre`, canonical run/run_dir/project_root,
and ordered sources with id/kind/role/dispatch_path/dispatch_sha256/path/sha256/read_scope.
First source: id/kind `phase0`, role `engineer`, path `phase0.md`, empty scope; its opened
UTF-8 Markdown has required headings and exact run/seed/planted lines, never child JSON.
`orientation-pre.json`, schema `shepherd.orientation-pre/1`, binds the same roots/sources,
opened manifest hash, and accepted true: exactly one phase0, at least one Auditor and Discovery, and no Critic. Its hash is passed to the Critic brief.
## Child result contract
Auditor/Discovery/Critic results are regular no-follow `shepherd.orientation-report/1` JSON:
exact run/result id/kind/role/read scope, complete status, nonempty summary, assumptions, claims, evidence, and caveats. Claim/assumption IDs are globally unique; claims/evidence cannot be empty.
Evidence is exactly path/sha256/line, scoped path, lowercase SHA-256, and in-range opened-byte
line. Empty files have zero lines; line 1 fails.
## Post-Critic artifact
After Critic stop, Native derives its current dispatch record; caller manifest paths/order fail.
Report `orientation_pre_sha256` equals accepted pre hash. Verdict fields: decision, findings,
corrections, blockers, citations. A source citation has exactly source id/path/hash/line with an
in-range opened-byte line; a claim citation only has globally bound claim_id. No self-citations.
Duplicate, stale, aliased, reversed, wrong-run/role/scope, missing, or unresolved citations fail. RED is valid; only GREEN is accepted.
`shepherd run orientation post <run>` replaces exactly `orientation-post.json` with `shepherd.orientation-post/1`, pre/manifest hashes, current sources, accepted, and verdict. Post-before-pre fails.
Native `run transition --to planned <run>` recomputes and checks post, dispatch/result hashes,
containment, identity, GREEN, and full planning readiness from `plan-contract.md`.
Native alone owns checkpoint incarnation/epoch/creation fields, planning binding, and registry digest.
Opening authenticates those bindings and reruns probes. Enumeration borrows the held run
lock, never reacquiring it. Missing, stale, copied, or caller-authored proof fails.
`services/eval/evals/validate_orientation_manifest.py` is a historical fixture utility;
it cannot validate current native checkpoints or authorize current planning acceptance.
