import re
p = r'C:\Users\decid\Documents\projects\spt-core\.worktrees\351-w5\traceable-reqs.toml'
s = open(p, encoding='utf-8', newline='').read()
N = '\r\n' if '\r\n' in s else '\n'


def block(rid):
    i = s.index(f'id = "{rid}"{N}')
    j = s.index(f'[[requirements]]', i)
    return i, j


def sub_between(rid, start, end, new, include_end=False):
    """Replace text in REQ `rid` from `start` up to (not incl.) `end`."""
    global s
    i, j = block(rid)
    b = s[i:j]
    a = b.index(start)
    e = b.index(end, a)
    if include_end:
        e += len(end)
    b = b[:a] + new + b[e:]
    s = s[:i] + b + s[j:]


def rep_in(rid, old, new):
    global s
    i, j = block(rid)
    b = s[i:j]
    assert b.count(old) == 1, (rid, old[:60], b.count(old))
    s = s[:i] + b.replace(old, new) + s[j:]


# ---- REQ-TRUST-WARNING: carrier passages amended by replacement (releases#346)
rep_in('REQ-TRUST-WARNING', 'composes a system-authored TRUST WARNING and delivers it alongside the message.',
       'composes a system-authored TRUST WARNING and records it for the receiving instance\'s now-signal, beside the message.')
rep_in('REQ-TRUST-WARNING',
       'the warning is advisory text that rides alongside, is skipped for a duplicate',
       'the warning is advisory text recorded beside the message, is skipped for a duplicate')
rep_in('REQ-TRUST-WARNING',
       'when it cannot be delivered at all',
       'when it cannot be recorded at all')
sub_between('REQ-TRUST-WARNING', "THE CARRIER IS THE DELIVERED MESSAGE'S OWN ENVELOPE", 'THE DECISION CONSUMES',
            "THE CARRIER IS THE NOW-SIGNAL (REQ-TRUST-WARNING-NOW-SIGNAL, releases#346, which supersedes the envelope-attribute carrier of REQ-TRUST-WARNING-ENVELOPE and its standalone fail-safe, and leaves this rule untouched): the block is recorded by the RECEIVING node and surfaces as a TRUST_WARNINGS entry naming the sender and the msg-id it concerns, so the sender authors the text in no design. ")
rep_in('REQ-TRUST-WARNING',
       'the composer with its reserved author, and the delivery-alongside at the WAN edge ahead of the message legs',
       'the composer, and the record at the WAN edge beside the message (carrier: REQ-TRUST-WARNING-NOW-SIGNAL)')

# ---- REQ-TRUST-WARNING-CADENCE: the DELIVERED moment is now render time
sub_between('REQ-TRUST-WARNING-CADENCE', 'THE CLAIM IS MADE ONLY AFTER THE WARNING IS ACTUALLY DELIVERED', 'THE CADENCE APPLIES UNIFORMLY',
            "THE CLAIM IS MADE ONLY WHEN THE WARNING IS ACTUALLY SHOWN — the first now-signal poll that renders its TRUST_WARNINGS entry (REQ-TRUST-WARNING-NOW-SIGNAL, releases#346) — so the cadence can never eat the one warning a session gets: an entry that no poll rendered (cut by a line cap, or never polled) claims nothing and stays owed, and a warning that could not even be recorded (the loud unrecorded diagnostic) claims nothing either — a marker on disk must never assert a caution that no agent ever read. The render claims BOTH the polling session and the session bound at receipt, so a burst received while the agent was away surfaces once in the session that returns and does not resurface in a later one; burst suppression at receipt keys on (peer, not yet rendered), with no session in the key, because the receipt-time session is not the session that will read it. ")
rep_in('REQ-TRUST-WARNING-CADENCE',
       'and the claim-after-delivery wiring at the one surfacing site',
       'and the claim at the one surfacing site, the now-signal render')
rep_in('REQ-TRUST-WARNING-CADENCE',
       'and an undelivered warning (every delivery leg failed, the loud diagnostic printed) leaves the marker unclaimed so the next message warns again.',
       'an unrecorded warning (the loud diagnostic printed) leaves the marker unclaimed so the next message warns again, and an entry cut by the line cap stays owed and renders on the next poll.')

# ---- REQ-TRUST-WARNING-ENVELOPE: retired, with its reason
i, j = block('REQ-TRUST-WARNING-ENVELOPE')
b = s[i:j]
m = re.search(r'required_stages = \[[^\]]*\][^\r\n]*', b)
b = b[:m.start()] + ('required_stages = []  # RETIRED 2026-09-27 (releases#346, W5, doyle-ruled; todlando build): '
                    'the envelope `trust-warning` attribute AND its standalone system-authored fail-safe both retire in the same release, '
                    'superseded by REQ-TRUST-WARNING-NOW-SIGNAL (the caution rides a now-signal category, TRUST_WARNINGS). '
                    'Reason: the attribute needed special adapter treatment to surface, and the now-signal did not exist when it was built. '
                    'What survives is re-homed, not dropped: the receiver-composed class strip (an inbound forged attribute stays inert) '
                    'and the kept EVENT_ATTR_TRUST_WARNING const now carry REQ-TRUST-WARNING-NOW-SIGNAL evidence. '
                    'No evidence remains tagged here by design.') + b[m.end():]
s = s[:i] + b + s[j:]

# ---- REQ-TRUST-WARNING-NOW-SIGNAL: activated
i, j = block('REQ-TRUST-WARNING-NOW-SIGNAL')
b = s[i:j]
old = 'required_stages = []'
assert b.count(old) == 1
b = b.replace(old, 'required_stages = ["doc", "impl", "unit", "int"]  # ACTIVATED 2026-09-27 W5 (todlando build), doyle ruling .spt/preserved/346/w5-ruling-picks.md: '
              'record in the receiving perch (node-local), one line per peer per poll (newest msg-id + "(+N more)", body one-lined, override never cut), '
              'non-suppressible by an adapter spec, claim on render for the poll AND receipt sessions, burst suppression on (peer, unrendered). '
              'int = the single-node chain receive_wan -> record -> now-signal render -> claim. doc includes harness-contract api.md: polling now-signal is REQUIRED to receive trust warnings.')
s = s[:i] + b + s[j:]

open(p, 'w', encoding='utf-8', newline='').write(s)
print('ok')
