From 6cc21bf05b96724c94aba5190dd195208c4b210f Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 08:52:31 -0400 Subject: [PATCH 01/20] Relocate manual verification docs under world reference --- .../branch-map.json | 35 ------- .../contract-freeze.json | 55 ----------- .../durable-state-freeze.json | 27 ----- .../final-summary.md | 15 --- .../gates/G0-run-freeze/PASSED | 1 - .../gates/G0-run-freeze/evidence.md | 16 --- .../gates/G0-run-freeze/gate.json | 6 -- .../gates/G1-contract-foundation/PASSED | 1 - .../gates/G1-contract-foundation/evidence.md | 34 ------- .../gates/G1-contract-foundation/gate.json | 6 -- .../gates/G2-durable-attach/PASSED | 1 - .../gates/G2-durable-attach/evidence.md | 40 -------- .../gates/G2-durable-attach/gate.json | 6 -- .../lane-ownership.json | 99 ------------------- .../merge-order.json | 27 ----- .../run-state.json | 12 --- .../sentinels/RUN_COMPLETE | 1 - .../session-log.md | 34 ------- .../source-lock.json | 14 --- .../tasks.json | 54 ---------- .../G1-contract-foundation-accept/ACCEPTED | 1 - .../HEAD_SHA.txt | 1 - .../changed-files.txt | 11 --- .../commands.txt | 8 -- .../deliverable.txt | 1 - .../dependencies.json | 8 -- .../exit-codes.json | 14 --- .../gitnexus-detect-changes.txt | 10 -- .../handoff-notes.md | 11 --- .../impact-analysis-summary.md | 5 - .../G1-contract-foundation-accept/owner.txt | 1 - .../G1-contract-foundation-accept/scope.txt | 1 - .../G1-contract-foundation-accept/status.txt | 1 - .../G1-contract-foundation-accept/summary.md | 1 - .../G1-contract-foundation-accept/task.json | 8 -- .../tasks/G2-durable-attach-accept/ACCEPTED | 1 - .../G2-durable-attach-accept/HEAD_SHA.txt | 1 - .../changed-files.txt | 3 - .../G2-durable-attach-accept/commands.txt | 14 --- .../G2-durable-attach-accept/deliverable.txt | 1 - .../dependencies.json | 9 -- .../G2-durable-attach-accept/exit-codes.json | 16 --- .../gitnexus-detect-changes.txt | 33 ------- .../G2-durable-attach-accept/handoff-notes.md | 14 --- .../impact-analysis-summary.md | 5 - .../tasks/G2-durable-attach-accept/owner.txt | 1 - .../tasks/G2-durable-attach-accept/scope.txt | 1 - .../tasks/G2-durable-attach-accept/status.txt | 1 - .../tasks/G2-durable-attach-accept/summary.md | 1 - .../tasks/G2-durable-attach-accept/task.json | 8 -- .../tasks/G3-parallel-window-accept/ACCEPTED | 1 - .../G3-parallel-window-accept/HEAD_SHA.txt | 1 - .../G3-parallel-window-accept/status.txt | 1 - .../G3-parallel-window-accept/summary.md | 1 - .../tasks/G3-parallel-window-accept/task.json | 8 -- .../tasks/G4-docs-accept/ACCEPTED | 1 - .../tasks/G4-docs-accept/HEAD_SHA.txt | 1 - .../tasks/G4-docs-accept/status.txt | 1 - .../tasks/G4-docs-accept/summary.md | 1 - .../tasks/G4-docs-accept/task.json | 8 -- .../tasks/G5-final-acceptance/ACCEPTED | 1 - .../tasks/G5-final-acceptance/HEAD_SHA.txt | 1 - .../tasks/G5-final-acceptance/status.txt | 1 - .../tasks/G5-final-acceptance/summary.md | 1 - .../tasks/G5-final-acceptance/task.json | 8 -- .../L0-a1-a2-contract-foundation/ACCEPTED | 1 - .../L0-a1-a2-contract-foundation/HEAD_SHA.txt | 1 - .../changed-files.txt | 4 - .../L0-a1-a2-contract-foundation/commands.txt | 12 --- .../deliverable.txt | 1 - .../dependencies.json | 8 -- .../exit-codes.json | 14 --- .../gitnexus-detect-changes.txt | 6 -- .../handoff-notes.md | 9 -- .../impact-analysis-summary.md | 8 -- .../L0-a1-a2-contract-foundation/owner.txt | 1 - .../L0-a1-a2-contract-foundation/scope.txt | 1 - .../L0-a1-a2-contract-foundation/status.txt | 1 - .../L0-a1-a2-contract-foundation/summary.md | 1 - .../L0-a1-a2-contract-foundation/task.json | 10 -- .../L1-a3-durable-attach-freeze/ACCEPTED | 1 - .../L1-a3-durable-attach-freeze/HEAD_SHA.txt | 1 - .../changed-files.txt | 3 - .../L1-a3-durable-attach-freeze/commands.txt | 19 ---- .../deliverable.txt | 1 - .../dependencies.json | 8 -- .../exit-codes.json | 21 ---- .../gitnexus-detect-changes.txt | 35 ------- .../handoff-notes.md | 10 -- .../impact-analysis-summary.md | 10 -- .../L1-a3-durable-attach-freeze/owner.txt | 1 - .../L1-a3-durable-attach-freeze/scope.txt | 1 - .../L1-a3-durable-attach-freeze/status.txt | 1 - .../L1-a3-durable-attach-freeze/summary.md | 1 - .../L1-a3-durable-attach-freeze/task.json | 10 -- .../L2-a4-human-caller-adoption/commands.txt | 8 -- .../deliverable.txt | 1 - .../dependencies.json | 8 -- .../exit-codes.json | 10 -- .../L2-a4-human-caller-adoption/owner.txt | 1 - .../L2-a4-human-caller-adoption/scope.txt | 1 - .../L2-a4-human-caller-adoption/status.txt | 1 - .../L2-a4-human-caller-adoption/summary.md | 5 - .../L2-a4-human-caller-adoption/task.json | 12 --- .../deliverable.txt | 1 - .../dependencies.json | 8 -- .../L3-a5-repl-dispatch-adoption/owner.txt | 1 - .../L3-a5-repl-dispatch-adoption/scope.txt | 1 - .../L3-a5-repl-dispatch-adoption/status.txt | 1 - .../L3-a5-repl-dispatch-adoption/summary.md | 5 - .../L3-a5-repl-dispatch-adoption/task.json | 12 --- .../tasks/L4-a6-docs-truth-sync/status.txt | 1 - .../tasks/L4-a6-docs-truth-sync/summary.md | 1 - .../tasks/L4-a6-docs-truth-sync/task.json | 8 -- .../tasks/P0-parent-freeze/ACCEPTED | 1 - .../tasks/P0-parent-freeze/HEAD_SHA.txt | 1 - .../tasks/P0-parent-freeze/changed-files.txt | 14 --- .../tasks/P0-parent-freeze/commands.txt | 6 -- .../tasks/P0-parent-freeze/deliverable.txt | 1 - .../tasks/P0-parent-freeze/dependencies.json | 6 -- .../tasks/P0-parent-freeze/exit-codes.json | 8 -- .../gitnexus-detect-changes.txt | 1 - .../tasks/P0-parent-freeze/handoff-notes.md | 1 - .../impact-analysis-summary.md | 7 -- .../tasks/P0-parent-freeze/owner.txt | 1 - .../tasks/P0-parent-freeze/scope.txt | 1 - .../tasks/P0-parent-freeze/status.txt | 1 - .../tasks/P0-parent-freeze/summary.md | 1 - .../tasks/P0-parent-freeze/task.json | 7 -- .../gitnexus-detect-changes.txt | 21 ---- .../tasks/P1-a7-validation-wall/status.txt | 1 - .../tasks/P1-a7-validation-wall/summary.md | 1 - .../tasks/P1-a7-validation-wall/task.json | 8 -- .../tasks/P2-parent-closeout/status.txt | 1 - .../tasks/P2-parent-closeout/summary.md | 1 - .../tasks/P2-parent-closeout/task.json | 7 -- .../validation-wall.md | 45 --------- ...ARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md | 0 .../UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md | 0 docs/WORLD.md | 2 +- docs/cross-platform/mac_world_setup.md | 2 +- .../concrete-remediation-decisions.md | 57 ----------- .../next/linux_guest_rootfs_backend/tasks.md | 2 +- .../p0-platform-stability/session_log.md | 2 +- .../governance/seam-5-closeout.md | 6 +- ...am-5-verification-and-smoke-conformance.md | 2 +- .../seam.md | 2 +- ...-privileged-and-macos-smoke-conformance.md | 4 +- docs/reference/world/README.md | 5 + docs/reference/world/verification/README.md | 8 ++ .../world/verification}/linux_world_socket.md | 0 .../verification}/netfilter_enforcement.md | 4 +- ...-member-runtime-world-placement-gap-sow.md | 2 +- .../27-uaa-boundary-and-naming-cleanup.md | 4 +- 154 files changed, 29 insertions(+), 1213 deletions(-) delete mode 100644 .runs/slice-29-shared-dispatch-contract/branch-map.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/contract-freeze.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/durable-state-freeze.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/final-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/PASSED delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/evidence.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/gate.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/PASSED delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/evidence.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/gate.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/PASSED delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/evidence.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/gate.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/lane-ownership.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/merge-order.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/run-state.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/sentinels/RUN_COMPLETE delete mode 100644 .runs/slice-29-shared-dispatch-contract/session-log.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/source-lock.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/changed-files.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/handoff-notes.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/impact-analysis-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/changed-files.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/handoff-notes.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/impact-analysis-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/changed-files.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/handoff-notes.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/impact-analysis-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/changed-files.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/handoff-notes.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/impact-analysis-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/ACCEPTED delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/HEAD_SHA.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/changed-files.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/commands.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/deliverable.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/dependencies.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/exit-codes.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/handoff-notes.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/impact-analysis-summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/owner.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/scope.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/gitnexus-detect-changes.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/status.txt delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/summary.md delete mode 100644 .runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/task.json delete mode 100644 .runs/slice-29-shared-dispatch-contract/validation-wall.md rename SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md => archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md (100%) rename UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md => archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md (100%) delete mode 100644 docs/decisions/concrete-remediation-decisions.md create mode 100644 docs/reference/world/verification/README.md rename docs/{manual_verification => reference/world/verification}/linux_world_socket.md (100%) rename docs/{manual_verification => reference/world/verification}/netfilter_enforcement.md (98%) diff --git a/.runs/slice-29-shared-dispatch-contract/branch-map.json b/.runs/slice-29-shared-dispatch-contract/branch-map.json deleted file mode 100644 index 52cd76e6b..000000000 --- a/.runs/slice-29-shared-dispatch-contract/branch-map.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "authoritative_branch": "feat/gateway-mediated-llm-fulfillment", - "authoritative_head_at_P0": "4c61ab779752a9185c6b7558275d7fdb5880893c", - "accepted_tip_after_G1": "50a450a05f374e46c736f79f9b5c7fec5c0e54d9", - "accepted_tip_after_G2": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "accepted_tip_after_G3": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "lane_branches": { - "L0": "codex/feat-gateway-mediated-llm-fulfillment-s29-a1-a2-contract-foundation", - "L1": "codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze", - "L2": "codex/feat-gateway-mediated-llm-fulfillment-s29-a4-human-caller-adoption", - "L3": "codex/feat-gateway-mediated-llm-fulfillment-s29-a5-repl-dispatch-adoption", - "L4": "codex/feat-gateway-mediated-llm-fulfillment-s29-a6-docs-truth-sync" - }, - "lane_worktrees": { - "root": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract", - "L0": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a1-a2-contract-foundation", - "L1": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze", - "L2": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a4-human-caller-adoption", - "L3": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a5-repl-dispatch-adoption", - "L4": "/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a6-docs-truth-sync" - }, - "lane_base_shas": { - "L0": "4c61ab779752a9185c6b7558275d7fdb5880893c", - "L1": "50a450a05f374e46c736f79f9b5c7fec5c0e54d9", - "L2": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "L3": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "L4": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72" - }, - "replay_target_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "notes": [ - "ORCH_PLAN.md declares equivalent worktree names under a different absolute workstation root; this run maps them to the live workspace root in this environment.", - "accepted_tip_after_G2 is the authoritative post-L1 integration commit from which both L2 and L3 were created.", - "accepted_tip_after_G3 is the authoritative slice-29 implementation/docs/test tree that passed the locked validation wall; the follow-up closeout commit only updates parent-owned .runs artifacts." - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/contract-freeze.json b/.runs/slice-29-shared-dispatch-contract/contract-freeze.json deleted file mode 100644 index faf11e365..000000000 --- a/.runs/slice-29-shared-dispatch-contract/contract-freeze.json +++ /dev/null @@ -1,55 +0,0 @@ -{ - "module_owner": "crates/shell/src/execution/agent_runtime/dispatch_contract.rs", - "frozen_vocabulary": { - "dispatch_request_envelope": "DispatchRequestEnvelope", - "dispatch_capability_override_set": "DispatchCapabilityOverrideSet", - "attach_launch_knobs": "AttachLaunchKnobs", - "resolved_launch_contract": "ResolvedLaunchContract", - "field_provenance": "FieldProvenance", - "dispatch_resolution_error": "DispatchResolutionError" - }, - "baseline_kinds": [ - "inventory_backed", - "persisted_attach_backed" - ], - "caller_kinds": [ - "human_start", - "human_reattach", - "human_fork", - "human_detached_turn_attach", - "orchestrator_member_dispatch" - ], - "capability_families": [ - "backend_identity", - "scope", - "cli_mode", - "capability_profile", - "policy_overlay" - ], - "attach_knob_vocabulary": [ - "attach_mode", - "continuity_selector", - "resume_contract_required" - ], - "merge_precedence": [ - "baseline_truth", - "explicit_supported_dispatch_overrides", - "effective_policy_narrowing", - "runtime_realizability_validation" - ], - "fail_closed_categories": [ - "unknown_override_family", - "unsupported_override", - "baseline_broadening", - "invalid_policy_overlay", - "policy_denial", - "runtime_unrealizable", - "missing_required_continuity" - ], - "frozen_invariants": [ - "One shared internal dispatch contract owner exists under crates/shell/src/execution/agent_runtime/.", - "Inventory-backed and persisted-attach-backed baseline domains remain explicit.", - "Policy remains narrowing-only and fail-closed.", - "Human callers and orchestrator-controlled dispatch must resolve through the same contract semantics." - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/durable-state-freeze.json b/.runs/slice-29-shared-dispatch-contract/durable-state-freeze.json deleted file mode 100644 index 37e414896..000000000 --- a/.runs/slice-29-shared-dispatch-contract/durable-state-freeze.json +++ /dev/null @@ -1,27 +0,0 @@ -{ - "durable_owner": "HostAttachContract", - "owner_module": "crates/shell/src/execution/agent_runtime/orchestration_session.rs", - "required_persisted_fields": [ - "backend identity derived from resolved contract", - "scope truth derived from resolved contract", - "cli mode truth derived from resolved contract", - "capability truth derived from resolved contract", - "attach continuity selector state", - "resume-contract continuity requirements" - ], - "continuity_successor_copy_rule": [ - "Preserve resolved launch truth needed for successor attach.", - "Clear only continuity-specific state on successor copy.", - "Do not persist a second durable attach object.", - "Do not persist full provenance trees." - ], - "compatibility_constraints": [ - "Persisted JSON changes must remain additive or migration-safe through OrchestrationSessionRecord::validate_persisted_invariants(...).", - "Detached attach planning must consume persisted attach truth instead of ambient participant state." - ], - "prohibitions": [ - "No second durable attach object.", - "No caller-specific reconstruction of host launch truth.", - "No non-additive persisted-state break." - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/final-summary.md b/.runs/slice-29-shared-dispatch-contract/final-summary.md deleted file mode 100644 index a3d2dfd25..000000000 --- a/.runs/slice-29-shared-dispatch-contract/final-summary.md +++ /dev/null @@ -1,15 +0,0 @@ -# Final Summary - -Accepted implementation/docs/test tip: `0d15fb2fe8902a9201c891eccd3d7a20325f9d72` - -- Landed one shared internal dispatch contract in `dispatch_contract.rs`, with explicit inventory-backed and persisted-attach-backed baseline domains. -- Kept `HostAttachContract` as the only durable host-attach truth and generalized it to persist resolved launch semantics without inventing a second durable attach object. -- Brought the human caller plane and orchestrator-controlled dispatch back onto the same contract semantics, including same-session parked-turn reattach/stop continuity. -- Aligned the allowed docs and llm-last-mile truth surfaces to the merged runtime behavior. - -Validation: - -- The locked shell selectors passed, including `resolve_public_control_target`, `public_turn_prompt_requests_require_exact_session_and_backend_contract`, `new_session_starts_active_attached`, and `detached_postures_enforce_pending_inbox_truth`. -- `cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture` and `cargo test -p shell --test repl_world_first_routing_v1 -- --nocapture` passed on the accepted tree. -- `cargo fmt --all -- --check`, `cargo clippy --workspace --all-targets -- -D warnings`, and `cargo test --workspace -- --nocapture` passed. -- `npx gitnexus detect-changes --repo substrate --scope staged` reported `7 files`, `37 symbols`, `0 affected processes`, `risk level: low`. diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/PASSED b/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/PASSED deleted file mode 100644 index b0aad4deb..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/PASSED +++ /dev/null @@ -1 +0,0 @@ -passed diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/evidence.md b/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/evidence.md deleted file mode 100644 index 0a2090a76..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/evidence.md +++ /dev/null @@ -1,16 +0,0 @@ -# G0 Evidence - -`G0` passes because all frozen preconditions in `ORCH_PLAN.md` are satisfied: - -1. The authoritative branch is `feat/gateway-mediated-llm-fulfillment`. -2. `PLAN.md` working-tree bytes were hashed and source-locked in `source-lock.json`. -3. `contract-freeze.json` and `durable-state-freeze.json` were written by the parent. -4. `branch-map.json`, `lane-ownership.json`, and `merge-order.json` were written by the parent. -5. The slice-29 worktree root exists, but no slice-29 worker worktree exists yet. - -Supporting command evidence: - -- `git rev-parse HEAD` => `4c61ab779752a9185c6b7558275d7fdb5880893c` -- `sha256sum PLAN.md` => `9389b48a1d20f93c8411a7670f11e25ed0929b0cddce7dc4deeb5c5adb5182cc` -- `git status --short --branch -- PLAN.md ORCH_PLAN.md` => `## feat/gateway-mediated-llm-fulfillment...origin/feat/gateway-mediated-llm-fulfillment` -- `git worktree list --porcelain` => only the authoritative checkout plus `/tmp/substrate-origin-main-check`; no slice-29 worker worktree exists at `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/` diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/gate.json b/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/gate.json deleted file mode 100644 index 89bb852c9..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/gate.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "gate_id": "G0-run-freeze", - "status": "passed", - "opened_at": "2026-05-24T18:13:37Z", - "passed_at": "2026-05-24T18:13:37Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/PASSED b/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/PASSED deleted file mode 100644 index b0aad4deb..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/PASSED +++ /dev/null @@ -1 +0,0 @@ -passed diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/evidence.md b/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/evidence.md deleted file mode 100644 index 33828ddb2..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/evidence.md +++ /dev/null @@ -1,34 +0,0 @@ -# G1 Evidence - -`G1` passes because the integrated authoritative tree satisfies the contract-foundation acceptance criteria in `ORCH_PLAN.md`. - -1. `dispatch_contract.rs` exists and is exported from `agent_runtime/mod.rs`. - - [`crates/shell/src/execution/agent_runtime/dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:1) - - [`crates/shell/src/execution/agent_runtime/mod.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/mod.rs:2) -2. Inventory-backed and persisted-attach-backed baseline domains are explicit, with per-field provenance tracked inside the shared contract owner. - - Inventory projection/origin helpers: [`agent_inventory.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_inventory.rs:105), [`agent_inventory.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_inventory.rs:196) - - Inventory and persisted-attach resolvers: [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:210), [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:313), [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:389), [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:470) -3. Policy remains narrowing-only and fail-closed, and the contract produces runtime materialization inputs instead of a second merge owner. - - Override/policy rejection layers and provenance: [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:156), [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:442) - - Runtime materialization from `ResolvedLaunchContract`: [`validator.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/validator.rs:124), [`validator.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/validator.rs:173), [`validator.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/validator.rs:231) -4. `control.rs` consumes downstream descriptor/state-store results rather than owning top-level merge semantics, so no `L0` control edit was required. - - Public prompt dispatch resolves through exact participant/session targeting only: [`control.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/control.rs:1601), [`control.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/control.rs:2272) - - The focused contract-semantic control test passes: [`control.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/control.rs:2733) -5. The accepted authoritative diff stayed inside the authorized `L0` hotspot set. - - `git diff --name-only HEAD^ HEAD` => `agent_inventory.rs`, `dispatch_contract.rs`, `mod.rs`, `validator.rs` - - No durable-state, public CLI, REPL, docs, or `.runs/**` worker edits were merged from the lane. -6. Focused authoritative validation passed. - - `cargo fmt --all -- --check` - - `cargo test -p shell dispatch_contract -- --nocapture` - - `cargo test -p shell validate_member_selection_returns_descriptor_for_unique_world_member -- --nocapture` - - `cargo test -p shell validate_exact_backend_selection_bypasses_world_ambiguity_when_backend_matches_exactly -- --nocapture` - - `cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture` -7. The accepted authoritative tip is recorded and `L1` branches from it exactly. - - `accepted_tip_after_G1 = 50a450a05f374e46c736f79f9b5c7fec5c0e54d9` - - `L1` worktree was created from that SHA at `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze` - -Ancillary evidence: - -- A broader `cargo test -p shell validate_ -- --nocapture` attempt earlier hit unrelated linker bus errors from integration targets matched by the broad filter; the focused selectors above are the authoritative `G1` evidence. -- An authoritative `cargo clippy -p shell --lib --tests -- -D warnings` attempt was blocked by disk exhaustion before cleanup. This is an environment incident, not a code regression, and is recorded in the task artifacts. -- `npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^` now returns `Changes: 6 files, 16 symbols`, `Affected processes: 0`, `Risk level: low`, but the stale index still misclassifies some symbols and includes unrelated `AGENTS.md`/`CLAUDE.md` drift. diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/gate.json b/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/gate.json deleted file mode 100644 index 5b153eb3e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/gate.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "gate_id": "G1-contract-foundation", - "status": "passed", - "opened_at": "2026-05-24T18:13:37Z", - "passed_at": "2026-05-24T18:35:32Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/PASSED b/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/PASSED deleted file mode 100644 index 53cdf1e93..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/PASSED +++ /dev/null @@ -1 +0,0 @@ -PASSED diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/evidence.md b/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/evidence.md deleted file mode 100644 index 8f7ef5201..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/evidence.md +++ /dev/null @@ -1,40 +0,0 @@ -# G2 Evidence - -`G2` passes because the integrated authoritative tree satisfies the durable attach freeze acceptance criteria in `ORCH_PLAN.md`. - -1. Session birth persists generalized host attach truth derived from the resolved host launch contract. - - `HostAttachContract` now persists launch descriptor, capabilities, attach knobs, and continuity selector with additive serde defaults: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:75), [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:88), [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:127) - - Session creation derives that persisted truth from the resolved host launch manifest via `from_manifest(...)`: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:145), [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:159) - - Birth invariants are covered by `new_session_starts_active_attached`: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:595) -2. Successor copy preserves launch truth while clearing only continuity-specific state. - - `fork_successor_attach_contract(...)` clones the persisted attach contract and clears only `continuity_uaa_session_id`: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:335) - - The exact behavior is proven by `successor_attach_contract_clears_continuity_and_preserves_launch_truth`: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:664) -3. `state_store.rs` uses persisted attach truth rather than ambient participant state for detached attach planning. - - Public control targeting carries the persisted contract, gates resume/fork/stop off persisted capabilities, and requires continuity from the durable selector rather than the live participant: [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:779) - - Public turn targeting now returns the persisted host attach contract on the resolved target: [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:901), [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:968) - - Detached posture reconciliation and stale-attachment recovery both depend on persisted capability and continuity truth: [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:2360), [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:2399) - - Coverage exists for persisted continuity control/turn routing and legacy-json backfill: [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:3554), [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:3609), [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:3807) -4. Persisted-state validation remains additive and fail-closed. - - The generalized fields are migration-safe through serde defaults, and `validate_persisted_invariants(...)` fail-closes on descriptor, scope, protocol, and attach-knob drift: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:80), [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:128), [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:396) - - The drift guard is covered by `host_attach_contract_knob_drift_fails_closed`: [`orchestration_session.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:691) - - Legacy session JSON without the new fields backfills defaults and still loads cleanly: [`state_store.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/state_store.rs:3807) -5. The durable-state schema freeze finalized without reopening `L0` semantics. - - The accepted authoritative diff from `50a450a05f374e46c736f79f9b5c7fec5c0e54d9` to `42636f8eb68fe2e817d973a4896f5c35cfc5b12b` is limited to `orchestration_session.rs`, `state_store.rs`, and one compile-only fixture update in `dispatch_contract.rs`. - - The only `dispatch_contract.rs` change is the test fixture expansion needed to instantiate the generalized `HostAttachContract`; persisted attach baseline semantics stay frozen: [`dispatch_contract.rs`](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:828) - - Focused authoritative validation passed on the merged tree: - - `cargo fmt --all -- --check` - - `cargo clippy -p shell --lib --tests -- -D warnings` - - `cargo test -p shell resolve_public_control_target -- --nocapture` - - `cargo test -p shell new_session_starts_active_attached -- --nocapture` - - `cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture` - - `cargo test -p shell successor_attach_contract_clears_continuity_and_preserves_launch_truth -- --nocapture` - - `cargo test -p shell host_attach_contract_knob_drift_fails_closed -- --nocapture` - - `cargo test -p shell resolve_public_turn_target_uses_persisted_continuity_truth -- --nocapture` - - `cargo test -p shell load_session_backfills_generalized_attach_contract_defaults_for_legacy_json -- --nocapture` - - `cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture` - -Ancillary evidence: - -- `accepted_tip_after_G2 = 42636f8eb68fe2e817d973a4896f5c35cfc5b12b` -- `L2` and `L3` were both created from that exact accepted authoritative SHA. -- GitNexus `detect-changes` compare remains stale and medium-risk because the index refresh crashes, but the output was preserved in the task artifacts rather than ignored. diff --git a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/gate.json b/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/gate.json deleted file mode 100644 index 77bb17c4b..000000000 --- a/.runs/slice-29-shared-dispatch-contract/gates/G2-durable-attach/gate.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "gate_id": "G2-durable-attach", - "status": "passed", - "opened_at": "2026-05-24T18:35:32Z", - "passed_at": "2026-05-24T18:57:05Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/lane-ownership.json b/.runs/slice-29-shared-dispatch-contract/lane-ownership.json deleted file mode 100644 index 6c0e984af..000000000 --- a/.runs/slice-29-shared-dispatch-contract/lane-ownership.json +++ /dev/null @@ -1,99 +0,0 @@ -{ - "parent": { - "owns": [ - ".runs/**", - "PLAN.md", - "ORCH_PLAN.md", - "gate transitions", - "merge decisions", - "blocked-run decisions", - "validation wall", - "final acceptance" - ] - }, - "L0": { - "owned_files": [ - "crates/shell/src/execution/agent_runtime/dispatch_contract.rs", - "crates/shell/src/execution/agent_runtime/mod.rs", - "crates/shell/src/execution/agent_inventory.rs", - "crates/shell/src/execution/agent_runtime/validator.rs", - "crates/shell/src/execution/agent_runtime/control.rs" - ], - "forbidden_files": [ - "crates/shell/src/execution/agent_runtime/orchestration_session.rs", - "crates/shell/src/execution/agent_runtime/state_store.rs", - "crates/shell/src/execution/agents_cmd.rs", - "crates/shell/src/repl/async_repl.rs", - "crates/shell/src/execution/routing/dispatch/world_ops.rs", - "docs/**", - "llm-last-mile/**", - ".runs/**" - ] - }, - "L1": { - "owned_files": [ - "crates/shell/src/execution/agent_runtime/orchestration_session.rs", - "crates/shell/src/execution/agent_runtime/state_store.rs" - ], - "forbidden_files": [ - "crates/shell/src/execution/agent_runtime/dispatch_contract.rs", - "crates/shell/src/execution/agent_inventory.rs", - "crates/shell/src/execution/agent_runtime/validator.rs", - "crates/shell/src/execution/agent_runtime/control.rs", - "crates/shell/src/execution/agents_cmd.rs", - "crates/shell/src/repl/async_repl.rs", - "crates/shell/src/execution/routing/dispatch/world_ops.rs", - "docs/**", - "llm-last-mile/**", - ".runs/**" - ] - }, - "L2": { - "owned_files": [ - "crates/shell/src/execution/agents_cmd.rs", - "crates/shell/src/execution/agent_runtime/control.rs", - "crates/shell/src/execution/prompt_fulfillment.rs", - "crates/shell/tests/agent_public_control_surface_v1.rs" - ], - "forbidden_files": [ - "crates/shell/src/execution/agent_runtime/dispatch_contract.rs", - "crates/shell/src/execution/agent_inventory.rs", - "crates/shell/src/execution/agent_runtime/validator.rs", - "crates/shell/src/execution/agent_runtime/orchestration_session.rs", - "crates/shell/src/execution/agent_runtime/state_store.rs", - "crates/shell/src/repl/async_repl.rs", - "crates/shell/src/execution/routing/dispatch/world_ops.rs", - "docs/**", - "llm-last-mile/**", - ".runs/**" - ] - }, - "L3": { - "owned_files": [ - "crates/shell/src/repl/async_repl.rs", - "crates/shell/src/execution/routing/dispatch/world_ops.rs" - ], - "forbidden_files": [ - "crates/shell/src/execution/agent_runtime/dispatch_contract.rs", - "crates/shell/src/execution/agent_inventory.rs", - "crates/shell/src/execution/agent_runtime/validator.rs", - "crates/shell/src/execution/agent_runtime/control.rs", - "crates/shell/src/execution/agent_runtime/orchestration_session.rs", - "crates/shell/src/execution/agent_runtime/state_store.rs", - "crates/shell/src/execution/agents_cmd.rs", - "docs/**", - "llm-last-mile/**", - ".runs/**" - ] - }, - "L4": { - "owned_files": [ - "docs/**", - "llm-last-mile/**" - ], - "forbidden_files": [ - "crates/**", - ".runs/**" - ] - } -} diff --git a/.runs/slice-29-shared-dispatch-contract/merge-order.json b/.runs/slice-29-shared-dispatch-contract/merge-order.json deleted file mode 100644 index c6b450735..000000000 --- a/.runs/slice-29-shared-dispatch-contract/merge-order.json +++ /dev/null @@ -1,27 +0,0 @@ -{ - "default_order": [ - "P0", - "L0", - "G1", - "L1", - "G2", - "L2", - "L3", - "G3", - "L4", - "G4", - "P1", - "G5", - "P2" - ], - "parallel_window": [ - "L2", - "L3" - ], - "parallel_window_precondition": "G2 must pass and freeze both contract vocabulary and durable-state schema before L2 and L3 branch from the same accepted SHA.", - "merge_constraints": [ - "Parent merges L2 before L3.", - "L3 is replayed onto the accepted L2 tree if required.", - "L4 does not open until both runtime lanes are accepted." - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/run-state.json b/.runs/slice-29-shared-dispatch-contract/run-state.json deleted file mode 100644 index 91d085d3a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/run-state.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "run_id": "slice-29-shared-dispatch-contract", - "status": "complete", - "authoritative_branch": "feat/gateway-mediated-llm-fulfillment", - "head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "current_task_id": "P2-parent-closeout", - "current_gate_id": "G5-final-acceptance", - "worker_cap_initial": 0, - "worker_cap_peak": 2, - "updated_at": "2026-05-24T20:47:10Z", - "note": "Run completed. The authoritative slice-29 implementation/docs/test tree is accepted at 0d15fb2fe8902a9201c891eccd3d7a20325f9d72, the same-session parked-turn regression was resolved through the LOW-risk can_park_host_runtime_after_detach seam without editing the previously escalated HIGH-risk dispatch_targeted_follow_up_turn seam, and the locked validation wall passed on that accepted tree." -} diff --git a/.runs/slice-29-shared-dispatch-contract/sentinels/RUN_COMPLETE b/.runs/slice-29-shared-dispatch-contract/sentinels/RUN_COMPLETE deleted file mode 100644 index 3e8cd4118..000000000 --- a/.runs/slice-29-shared-dispatch-contract/sentinels/RUN_COMPLETE +++ /dev/null @@ -1 +0,0 @@ -2026-05-24T20:47:10Z diff --git a/.runs/slice-29-shared-dispatch-contract/session-log.md b/.runs/slice-29-shared-dispatch-contract/session-log.md deleted file mode 100644 index a063dcac2..000000000 --- a/.runs/slice-29-shared-dispatch-contract/session-log.md +++ /dev/null @@ -1,34 +0,0 @@ -# Session Log - -- `2026-05-24T18:13:37Z` Parent entered `P0`, confirmed branch `feat/gateway-mediated-llm-fulfillment`, locked `PLAN.md` SHA `9389b48a1d20f93c8411a7670f11e25ed0929b0cddce7dc4deeb5c5adb5182cc`, and initialized the slice-29 run-state tree. -- `2026-05-24T18:13:37Z` GitNexus status reported the local index as stale (`Indexed commit a628e41`, `Current commit 4c61ab7`). -- `2026-05-24T18:13:37Z` Parent attempted `npx gitnexus analyze` to refresh the index before any symbol edits; the CLI failed during rebuild with `free(): invalid pointer`. The failure is recorded here and in `P0` artifacts; impact and detect-changes will still be run from the available index as a best-effort control unless the tool becomes unusable. -- `2026-05-24T18:13:37Z` Inspection confirmed the authoritative tree is pre-slice-29 in code: `crates/shell/src/execution/agent_runtime/dispatch_contract.rs` does not exist and current launch semantics remain distributed across `agents_cmd.rs`, `control.rs`, `state_store.rs`, and `async_repl.rs`. -- `2026-05-24T18:13:37Z` `G0` passed: source lock, contract freeze, durable-state freeze, lane ownership, merge order, and worktree root initialization are complete; no slice-29 worker worktree exists yet. -- `2026-05-24T18:29:42Z` The `L0` worker lane committed `6be348293ad140690385fbde5463992e084f5470` on `codex/feat-gateway-mediated-llm-fulfillment-s29-a1-a2-contract-foundation`, adding `dispatch_contract.rs`, inventory projection helpers, and validator materialization through the shared contract. -- `2026-05-24T18:30:02Z` The parent integrated `L0` by cherry-picking the worker tip onto the authoritative branch, producing accepted commit `50a450a05f374e46c736f79f9b5c7fec5c0e54d9`. -- `2026-05-24T18:34:55Z` Authoritative validation was briefly blocked by disk exhaustion (`/dev/root` at 100%); the parent removed reproducible build artifacts from the `L0` worktree target and `target/tests-tmp`, restoring 26G free space without touching source state. -- `2026-05-24T18:35:32Z` Focused authoritative checks passed for `dispatch_contract`, validator exact/unique selection, `public_turn_prompt_requests_require_exact_session_and_backend_contract`, and `cargo fmt --all -- --check`. -- `2026-05-24T18:35:32Z` `npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^` now returns a low-risk compare summary for the integrated commit, but the stale index still misclassifies `dispatch_contract.rs` and unrelated `AGENTS.md`/`CLAUDE.md` drift as `undefined`; that limitation is preserved as evidence rather than ignored. -- `2026-05-24T18:35:32Z` `G1` passed. The parent recorded `accepted_tip_after_G1=50a450a05f374e46c736f79f9b5c7fec5c0e54d9`, created the `L1` worktree at `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze`, and moved the run to `L1 -> G2`. -- `2026-05-24T18:38:35Z` `L1` impact triage completed before any durable-state edits. `sync_host_attach_contract` returned `MEDIUM`, `fork_successor_attach_contract` returned `LOW`, and `resolve_public_control_target` returned `HIGH` (`19` impacted symbols, `2` affected processes, including `handle_agent_command`). Per the run contract, the parent stopped before editing and wrote `blocked.json` pending explicit user direction to continue through the HIGH-risk seam. -- `2026-05-24T18:50:21Z` `L1` resumed under explicit user direction to proceed through the previously escalated HIGH-risk `resolve_public_control_target` seam while staying inside the frozen `A3` boundary. The worker lane committed `aa656181aa53c92cefbec1264145c5b071e5e803`, generalizing `HostAttachContract`, preserving successor launch truth, and moving detached posture checks onto persisted attach truth. -- `2026-05-24T18:50:46Z` The parent integrated `L1` by cherry-picking `aa656181aa53c92cefbec1264145c5b071e5e803` onto the authoritative branch, producing accepted commit `42636f8eb68fe2e817d973a4896f5c35cfc5b12b`. The integrated diff touched `dispatch_contract.rs` only for a compile-only unit-test fixture update required by the expanded `HostAttachContract` fields; shared contract semantics remained closed. -- `2026-05-24T18:57:05Z` Focused authoritative `G2` validation passed: `cargo fmt --all -- --check`, `cargo clippy -p shell --lib --tests -- -D warnings`, `resolve_public_control_target`, `new_session_starts_active_attached`, `detached_postures_enforce_pending_inbox_truth`, `successor_attach_contract_clears_continuity_and_preserves_launch_truth`, `host_attach_contract_knob_drift_fails_closed`, `resolve_public_turn_target_uses_persisted_continuity_truth`, `load_session_backfills_generalized_attach_contract_defaults_for_legacy_json`, and `persisted_attach_contract_is_explicit_baseline_domain`. -- `2026-05-24T18:57:05Z` `G2` passed. The parent recorded `accepted_tip_after_G2=42636f8eb68fe2e817d973a4896f5c35cfc5b12b`, removed the stale blocked state, and opened the only safe parallel window with `L2` at `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a4-human-caller-adoption` and `L3` at `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a5-repl-dispatch-adoption`. -- `2026-05-24T18:57:05Z` Parent dispatched the live parallel workers: `Popper` owns `L2` human caller adoption and `Lovelace` owns `L3` REPL dispatch adoption. Both were instructed to run GitNexus impact before symbol edits, stop on any new `HIGH` or `CRITICAL` result, respect the frozen ownership boundaries, and return detect-changes plus validation evidence. -- `2026-05-24T19:03:41Z` `L3` halted at its impact gate with no code changes. `build_member_dispatch_transport_request` returned `LOW`, but `dispatch_targeted_follow_up_turn` returned `HIGH` with affected processes `main`, `run_shell_with_cli`, and `run_async_repl`, so the lane is parked pending explicit escalation. -- `2026-05-24T19:12:43Z` `L2` reported no `HIGH` or `CRITICAL` impact results. The lane hit an environment issue instead: the worktree-local `target/` ran out of space, but the required `public_turn_prompt_requests_require_exact_session_and_backend_contract` selector passed once the worker switched to `TMPDIR=/mnt/localssd/tmp` and `CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-s29-a4-target`. The parent resumed Popper to finish the remaining required validation and final handoff. -- `2026-05-24T19:46:12Z` The parent took over `L2`, closed the stalled worker, and reran the locked human-caller checks from the `a4-human-caller-adoption` worktree with `TMPDIR=/mnt/localssd/tmp` and `CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target`. Targeted selectors for exact session/backend control, detached continuity recovery, and slow-start prompt normalization passed, but `cargo test -p shell --test agent_public_control_surface_v1 public_same_session_parked_status_turn_reattach_and_stop_stay_on_one_orchestration_session_id -- --nocapture` failed deterministically after emitting a successful `completed` turn envelope because `sess_turn_reattach_stop` became terminal before the resumed participant reparked. -- `2026-05-24T19:46:12Z` Code inspection narrowed the remaining fault to the fast-exit auto-park handoff in `crates/shell/src/repl/async_repl.rs`: the hidden owner-helper completion can win before the queued `park_after_turn` request is consumed, leaving the resumed turn to invalidate instead of parking. That file is owned exclusively by `L3` under the controller, and `L3` is already stopped on a `HIGH` GitNexus impact result for `dispatch_targeted_follow_up_turn`, so the parent wrote `blocked.json`, added `RUN_BLOCKED`, and stopped the run at `G3` with no legal in-scope fix path remaining. -- `2026-05-24T19:56:36Z` The parent made one last `L2`-owned attempt to recover terminalized fast-exit resumed turns without reopening `async_repl.rs`: a narrow `control.rs` reconciliation for success-exit terminal fingerprints plus a stricter post-reconciliation stability check in `agents_cmd.rs`. The attempt did not clear the blocker. The latest same-session turn failure still ended at `owner_unreachable`, and the enriched obstruction message showed the persisted late-write pair: `session_state=Invalidated`, `session_reason='attached control turn exited with status 0'`, with the participant flipping between `Invalidated('attached control turn exited with status 0')` and `Failed('shell-owned orchestrator cancel did not produce authoritative terminal completion')`. This confirmed the remaining defect lives in the helper/REPL closeout path, not the human caller surface. -- `2026-05-24T20:10:54Z` The parent cleaned the dead-end `L2` terminal-revival experiment out of `control.rs`, staged only the owned lane files, and cut two lane commits: `7ec35e3d` (`feat: adopt shared dispatch contract`) for `L2` and `7b560e2e` (`fix: preserve auto-parked host continuity`) for the low-risk `L3` helper-closeout fix. `gitnexus detect-changes --scope staged` returned `No changes detected` in both worktrees despite the staged code diff; the limitation is preserved as evidence rather than treated as a clean detect-changes result. -- `2026-05-24T20:11:24Z` The parent integrated the lane commits onto the authoritative branch in plan order, producing `d5323945` for `L2` and `c2721ed5` for the low-risk `L3` fix. The authoritative checkout target directory was moved onto `/mnt/localssd/tmp/substrate-authoritative-target` to avoid root-disk exhaustion during acceptance runs. -- `2026-05-24T20:14:06Z` Focused merged-tree selectors passed on authoritative head `c2721ed5ec0bdb4d764c26f033d47fbe4f648c06`: `resolve_public_control_target`, `public_turn_prompt_requests_require_exact_session_and_backend_contract`, `new_session_starts_active_attached`, and `detached_postures_enforce_pending_inbox_truth`. -- `2026-05-24T20:15:53Z` `cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture` on authoritative head `c2721ed5` failed at only one case: `public_same_session_parked_status_turn_reattach_and_stop_stay_on_one_orchestration_session_id`. Earlier control-surface cases, including detached pending-inbox normalization and persisted reattach continuity, passed. -- `2026-05-24T20:16:58Z` The parent traced the remaining same-session failure to the targeted follow-up host launch path in `crates/shell/src/repl/async_repl.rs`, where `dispatch_targeted_follow_up_turn` calls `start_host_orchestrator_runtime_with_prepared_prompt(..., false /* auto_park_after_public_turn */ , ...)`. That seam is the same `HIGH` GitNexus impact area that previously halted `L3`. -- `2026-05-24T20:17:15Z` The parent tested and reverted one last low-risk experiment by widening `LOCAL_RETAINED_AUTO_PARK_GRACE_TIMEOUT` from `250ms` to `2s` and rerunning only the failing same-session selector. The failure reproduced unchanged with `session_state=Invalidated`, `session_reason='attached control turn exited with status 0'`, `participant_state=Failed`, and `participant_reason='shell-owned orchestrator cancel did not produce authoritative terminal completion'`. The run remains blocked at `G3` pending explicit authorization to cross the `HIGH` targeted follow-up seam. -- `2026-05-24T20:31:18Z` The parent resumed from the accepted authoritative tree without touching the HIGH-risk targeted follow-up seam. Fresh impact checks kept `can_park_host_runtime_after_detach` in the LOW-risk bucket, and the parent used that seam to reconcile the persisted-store lag that was still invalidating same-session parked turns after successful one-turn completion. -- `2026-05-24T20:35:44Z` The new low-risk `async_repl.rs` handoff predicate and regression test cleared the last runtime failure. `public_same_session_parked_status_turn_reattach_and_stop_stay_on_one_orchestration_session_id`, the full `agent_public_control_surface_v1`, the full `repl_world_first_routing_v1`, and the full `agent_successor_contract_ahcsitc0` suite all passed on the authoritative tree. -- `2026-05-24T20:45:31Z` The parent aligned the allowed docs truth surfaces (`ADR-0027`, `llm-last-mile/29`, `/30`, `/31`, and `README.md`) to the merged runtime behavior and committed the authoritative implementation/docs/test tree as `0d15fb2fe8902a9201c891eccd3d7a20325f9d72` (`feat: complete slice-29 shared dispatch contract`). -- `2026-05-24T20:47:10Z` `G3`, `L4`, `G4`, `P1`, and `G5` all passed against accepted tip `0d15fb2fe8902a9201c891eccd3d7a20325f9d72`. The locked commands from `ORCH_PLAN.md` passed, and `npx gitnexus detect-changes --repo substrate --scope staged` reported `7 files`, `37 symbols`, `0 affected processes`, `risk level: low`. The parent then entered `P2` to write final closeout artifacts and mark the run complete. diff --git a/.runs/slice-29-shared-dispatch-contract/source-lock.json b/.runs/slice-29-shared-dispatch-contract/source-lock.json deleted file mode 100644 index 204bd235e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/source-lock.json +++ /dev/null @@ -1,14 +0,0 @@ -{ - "authoritative_branch": "feat/gateway-mediated-llm-fulfillment", - "authoritative_head_sha": "4c61ab779752a9185c6b7558275d7fdb5880893c", - "repo_root": "/home/azureuser/__Active_Code/atomize-hq/substrate", - "plan_path": "/home/azureuser/__Active_Code/atomize-hq/substrate/PLAN.md", - "orch_path": "/home/azureuser/__Active_Code/atomize-hq/substrate/ORCH_PLAN.md", - "plan_sha256": "9389b48a1d20f93c8411a7670f11e25ed0929b0cddce7dc4deeb5c5adb5182cc", - "git_status_short_plan_orch": "## feat/gateway-mediated-llm-fulfillment...origin/feat/gateway-mediated-llm-fulfillment", - "timestamp": "2026-05-24T18:13:37Z", - "notes": [ - "ORCH_PLAN.md hard guard 4 expected PLAN.md to be dirty in the authoritative checkout, but the live checkout is clean for PLAN.md and ORCH_PLAN.md at source-lock time.", - "The parent locked the live working-tree PLAN.md bytes exactly as found and will stop the run if they change materially." - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks.json b/.runs/slice-29-shared-dispatch-contract/tasks.json deleted file mode 100644 index cec8733c2..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks.json +++ /dev/null @@ -1,54 +0,0 @@ -{ - "P0-parent-freeze": { - "status": "completed", - "note": "Source lock, contract freeze, durable-state freeze, lane ownership, merge order, and G0 evidence were written by the parent." - }, - "L0-a1-a2-contract-foundation": { - "status": "completed", - "note": "Worker landed the shared dispatch contract foundation on its lane branch and the parent integrated it at 50a450a05f374e46c736f79f9b5c7fec5c0e54d9." - }, - "G1-contract-foundation-accept": { - "status": "completed", - "note": "Parent accepted the contract foundation, recorded accepted_tip_after_G1, and opened L1 from the accepted authoritative tip." - }, - "L1-a3-durable-attach-freeze": { - "status": "completed", - "note": "Worker landed generalized persisted attach truth and detached-planning consumption on branch codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze; the parent accepted it at 42636f8eb68fe2e817d973a4896f5c35cfc5b12b." - }, - "G2-durable-attach-accept": { - "status": "completed", - "note": "Parent accepted the durable attach freeze, recorded accepted_tip_after_G2, and opened the L2/L3 worktrees from the same authoritative SHA." - }, - "L2-a4-human-caller-adoption": { - "status": "completed", - "note": "Parent took over L2 after the worker stalled, landed the caller-surface adoption as authoritative commit d5323945, and preserved the shared contract semantics through final acceptance. The final same-session parked-turn repair did not require further L2-owned edits." - }, - "L3-a5-repl-dispatch-adoption": { - "status": "completed", - "note": "Parent first landed the low-risk helper-closeout fix as authoritative commit c2721ed5, then resolved the remaining same-session parked-turn race on the LOW-risk can_park_host_runtime_after_detach seam in authoritative commit 0d15fb2fe8902a9201c891eccd3d7a20325f9d72. The previously escalated HIGH-risk dispatch_targeted_follow_up_turn seam remained untouched." - }, - "G3-parallel-window-accept": { - "status": "completed", - "note": "G3 passed on authoritative commit 0d15fb2fe8902a9201c891eccd3d7a20325f9d72. Both runtime lanes now satisfy the shared dispatch contract semantics, including same-session parked-turn reattach/stop continuity." - }, - "L4-a6-docs-truth-sync": { - "status": "completed", - "note": "Parent aligned ADR-0027 and the llm-last-mile slice-29/30/31 truth surfaces to the merged runtime behavior on authoritative commit 0d15fb2fe8902a9201c891eccd3d7a20325f9d72." - }, - "G4-docs-accept": { - "status": "completed", - "note": "G4 passed. The allowed docs truth surfaces now match the merged runtime: one shared dispatch-contract owner, explicit inventory/persisted-attach baseline domains, persisted HostAttachContract launch truth, caller parity, and no second durable attach object." - }, - "P1-a7-validation-wall": { - "status": "completed", - "note": "The locked validation wall passed on authoritative commit 0d15fb2fe8902a9201c891eccd3d7a20325f9d72: the four named shell selectors, agent_public_control_surface_v1, repl_world_first_routing_v1, cargo fmt --all -- --check, cargo clippy --workspace --all-targets -- -D warnings, and cargo test --workspace -- --nocapture." - }, - "G5-final-acceptance": { - "status": "completed", - "note": "G5 passed on authoritative commit 0d15fb2fe8902a9201c891eccd3d7a20325f9d72. GitNexus detect-changes on the staged implementation tree reported 7 files, 37 symbols, 0 affected processes, and overall risk level low." - }, - "P2-parent-closeout": { - "status": "completed", - "note": "Parent wrote the final summary, validation evidence, task/gate closeout records, and RUN_COMPLETE sentinel." - } -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/ACCEPTED deleted file mode 100644 index 377cefa1a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ -accepted diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/HEAD_SHA.txt deleted file mode 100644 index c61b0a7d3..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -50a450a05f374e46c736f79f9b5c7fec5c0e54d9 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/changed-files.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/changed-files.txt deleted file mode 100644 index 180aa7815..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/changed-files.txt +++ /dev/null @@ -1,11 +0,0 @@ -crates/shell/src/execution/agent_inventory.rs -crates/shell/src/execution/agent_runtime/dispatch_contract.rs -crates/shell/src/execution/agent_runtime/mod.rs -crates/shell/src/execution/agent_runtime/validator.rs -.runs/slice-29-shared-dispatch-contract/branch-map.json -.runs/slice-29-shared-dispatch-contract/run-state.json -.runs/slice-29-shared-dispatch-contract/tasks.json -.runs/slice-29-shared-dispatch-contract/session-log.md -.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/* -.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/* -.runs/slice-29-shared-dispatch-contract/gates/G1-contract-foundation/* diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/commands.txt deleted file mode 100644 index e653aafa4..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/commands.txt +++ /dev/null @@ -1,8 +0,0 @@ -git cherry-pick 6be348293ad140690385fbde5463992e084f5470 -cargo fmt --all -- --check -cargo test -p shell dispatch_contract -- --nocapture -cargo test -p shell validate_member_selection_returns_descriptor_for_unique_world_member -- --nocapture -cargo test -p shell validate_exact_backend_selection_bypasses_world_ambiguity_when_backend_matches_exactly -- --nocapture -cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture -npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^ -git worktree add -b codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze 50a450a05f374e46c736f79f9b5c7fec5c0e54d9 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/deliverable.txt deleted file mode 100644 index eb93a7c05..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Accepted L0 on the authoritative branch, recorded `accepted_tip_after_G1`, wrote contract-foundation evidence, and opened the serialized L1 worktree from the accepted tip. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/dependencies.json deleted file mode 100644 index a13bd97cf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/dependencies.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "depends_on": [ - "L0-a1-a2-contract-foundation" - ], - "unblocks": [ - "L1-a3-durable-attach-freeze" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/exit-codes.json deleted file mode 100644 index 9cdfcffc5..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/exit-codes.json +++ /dev/null @@ -1,14 +0,0 @@ -{ - "git cherry-pick 6be348293ad140690385fbde5463992e084f5470": 0, - "cargo fmt --all -- --check": 0, - "cargo test -p shell dispatch_contract -- --nocapture": 0, - "cargo test -p shell validate_member_selection_returns_descriptor_for_unique_world_member -- --nocapture": 0, - "cargo test -p shell validate_exact_backend_selection_bypasses_world_ambiguity_when_backend_matches_exactly -- --nocapture": 0, - "cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture": 0, - "npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^": 0, - "git worktree add -b codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze 50a450a05f374e46c736f79f9b5c7fec5c0e54d9": 0, - "cargo test -p shell validate_ -- --nocapture": 101, - "cargo clippy -p shell --lib --tests -- -D warnings": 101, - "rm -rf /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a1-a2-contract-foundation/target": 0, - "rm -rf /home/azureuser/__Active_Code/atomize-hq/substrate/target/tests-tmp": 0 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/gitnexus-detect-changes.txt deleted file mode 100644 index f7ff5e264..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/gitnexus-detect-changes.txt +++ /dev/null @@ -1,10 +0,0 @@ -Authoritative compare result: - -- `npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^` -- Exit code: `0` -- Summary: `Changes: 6 files, 16 symbols`, `Affected processes: 0`, `Risk level: low` - -Limitations retained as evidence: - -- The compare output still lists unrelated `AGENTS.md` / `CLAUDE.md` drift because those files changed earlier outside this slice and are present in `HEAD^..HEAD`. -- The stale index labels several entries as `undefined` and does not expose `dispatch_contract.rs` directly, so detect-changes is helpful but not authoritative for per-symbol coverage in this run. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/handoff-notes.md b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/handoff-notes.md deleted file mode 100644 index 4d5c649a0..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/handoff-notes.md +++ /dev/null @@ -1,11 +0,0 @@ -Parent acceptance notes: - -- Accepted authoritative commit: `50a450a05f374e46c736f79f9b5c7fec5c0e54d9` -- Recorded in `branch-map.json` as `accepted_tip_after_G1` -- Opened `L1` branch `codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze` -- `L1` worktree path: `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze` - -Important carry-forward constraints: - -- `dispatch_contract.rs`, `agent_inventory.rs`, and `validator.rs` are now frozen after `G1`. -- `L1` may touch only `orchestration_session.rs`, `state_store.rs`, and directly related tests. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/impact-analysis-summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/impact-analysis-summary.md deleted file mode 100644 index 68657531e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/impact-analysis-summary.md +++ /dev/null @@ -1,5 +0,0 @@ -G1 reviewed the pre-edit impact evidence already captured under `L0` and confirmed the integrated tree stayed within the frozen hotspot set: - -- Modified authoritative code files: `agent_inventory.rs`, `dispatch_contract.rs`, `mod.rs`, `validator.rs` -- No `control.rs`, `orchestration_session.rs`, `state_store.rs`, `agents_cmd.rs`, `async_repl.rs`, or docs edits landed in `L0` -- The accepted tree therefore remained inside the authorized `A1+A2` boundary despite the HIGH-risk validator blast radius diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/owner.txt deleted file mode 100644 index 9676f5bfe..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/owner.txt +++ /dev/null @@ -1 +0,0 @@ -parent diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/scope.txt deleted file mode 100644 index 7dcedc364..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Review L0 against the frozen slice-29 contract criteria, integrate only the accepted lane tip, record accepted_tip_after_G1, and open L1 from that exact authoritative SHA. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/summary.md deleted file mode 100644 index 06cdd9666..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/summary.md +++ /dev/null @@ -1 +0,0 @@ -G1 passed. The authoritative tree now contains the shared dispatch contract foundation at `50a450a05f374e46c736f79f9b5c7fec5c0e54d9`, focused contract/validator/control evidence is green, and L1 has been opened from the recorded accepted tip. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/task.json deleted file mode 100644 index 57b2d0809..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G1-contract-foundation-accept/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "G1-contract-foundation-accept", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "50a450a05f374e46c736f79f9b5c7fec5c0e54d9", - "started_at": "2026-05-24T18:29:42Z", - "completed_at": "2026-05-24T18:35:32Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/ACCEPTED deleted file mode 100644 index a6413548e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ -ACCEPTED diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/HEAD_SHA.txt deleted file mode 100644 index ebdbcfc31..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -42636f8eb68fe2e817d973a4896f5c35cfc5b12b diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/changed-files.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/changed-files.txt deleted file mode 100644 index 08f0ae98f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/changed-files.txt +++ /dev/null @@ -1,3 +0,0 @@ -crates/shell/src/execution/agent_runtime/dispatch_contract.rs -crates/shell/src/execution/agent_runtime/orchestration_session.rs -crates/shell/src/execution/agent_runtime/state_store.rs diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/commands.txt deleted file mode 100644 index 570103cb2..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/commands.txt +++ /dev/null @@ -1,14 +0,0 @@ -git cherry-pick aa656181aa53c92cefbec1264145c5b071e5e803 -cargo fmt --all -- --check -cargo clippy -p shell --lib --tests -- -D warnings -cargo test -p shell resolve_public_control_target -- --nocapture -cargo test -p shell new_session_starts_active_attached -- --nocapture -cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture -cargo test -p shell successor_attach_contract_clears_continuity_and_preserves_launch_truth -- --nocapture -cargo test -p shell host_attach_contract_knob_drift_fails_closed -- --nocapture -cargo test -p shell resolve_public_turn_target_uses_persisted_continuity_truth -- --nocapture -cargo test -p shell load_session_backfills_generalized_attach_contract_defaults_for_legacy_json -- --nocapture -cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture -npx gitnexus detect-changes --repo substrate --scope compare --base-ref 50a450a05f374e46c736f79f9b5c7fec5c0e54d9 -git worktree add /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a4-human-caller-adoption -b codex/feat-gateway-mediated-llm-fulfillment-s29-a4-human-caller-adoption 42636f8eb68fe2e817d973a4896f5c35cfc5b12b -git worktree add /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a5-repl-dispatch-adoption -b codex/feat-gateway-mediated-llm-fulfillment-s29-a5-repl-dispatch-adoption 42636f8eb68fe2e817d973a4896f5c35cfc5b12b diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/deliverable.txt deleted file mode 100644 index 90253aaba..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -The parent accepted the authoritative L1 integration at 42636f8eb68fe2e817d973a4896f5c35cfc5b12b, finalized the durable-state schema freeze, recorded accepted_tip_after_G2, and opened the only safe parallel window with L2 and L3 branched from that exact accepted SHA. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/dependencies.json deleted file mode 100644 index b20d0ad3f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/dependencies.json +++ /dev/null @@ -1,9 +0,0 @@ -{ - "depends_on": [ - "L1-a3-durable-attach-freeze" - ], - "unblocks": [ - "L2-a4-human-caller-adoption", - "L3-a5-repl-dispatch-adoption" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/exit-codes.json deleted file mode 100644 index f663a4b94..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/exit-codes.json +++ /dev/null @@ -1,16 +0,0 @@ -{ - "git cherry-pick aa656181aa53c92cefbec1264145c5b071e5e803": 0, - "cargo fmt --all -- --check": 0, - "cargo clippy -p shell --lib --tests -- -D warnings": 0, - "cargo test -p shell resolve_public_control_target -- --nocapture": 0, - "cargo test -p shell new_session_starts_active_attached -- --nocapture": 0, - "cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture": 0, - "cargo test -p shell successor_attach_contract_clears_continuity_and_preserves_launch_truth -- --nocapture": 0, - "cargo test -p shell host_attach_contract_knob_drift_fails_closed -- --nocapture": 0, - "cargo test -p shell resolve_public_turn_target_uses_persisted_continuity_truth -- --nocapture": 0, - "cargo test -p shell load_session_backfills_generalized_attach_contract_defaults_for_legacy_json -- --nocapture": 0, - "cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture": 0, - "npx gitnexus detect-changes --repo substrate --scope compare --base-ref 50a450a05f374e46c736f79f9b5c7fec5c0e54d9": 0, - "git worktree add /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a4-human-caller-adoption -b codex/feat-gateway-mediated-llm-fulfillment-s29-a4-human-caller-adoption 42636f8eb68fe2e817d973a4896f5c35cfc5b12b": 0, - "git worktree add /home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a5-repl-dispatch-adoption -b codex/feat-gateway-mediated-llm-fulfillment-s29-a5-repl-dispatch-adoption 42636f8eb68fe2e817d973a4896f5c35cfc5b12b": 0 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/gitnexus-detect-changes.txt deleted file mode 100644 index 65e2463f1..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/gitnexus-detect-changes.txt +++ /dev/null @@ -1,33 +0,0 @@ -`npx gitnexus detect-changes --repo substrate --scope compare --base-ref 50a450a05f374e46c736f79f9b5c7fec5c0e54d9` output: - -```text -Changes: 5 files, 47 symbols -Affected processes: 4 -Risk level: medium - -Changed symbols: - undefined GitNexus — Code Intelligence → AGENTS.md - undefined GitNexus — Code Intelligence → CLAUDE.md - undefined from_manifest → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined new → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined transition_state → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined mark_startup_prompt_completed → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined HostAttachContract → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined OrchestrationSessionRecord → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined continuity_uaa_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined orchestration_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined shell_trace_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined workspace_root → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined shell_owner_pid → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined state → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined opened_at → crates/shell/src/execution/agent_runtime/orchestration_session.rs - ... and 32 more - -Affected execution flows: - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → RuntimeSelectionDescriptor (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → New (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → Transition_state (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → Bind_active_session_handle (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session -``` - -The compare output remains constrained by the stale index and still misattributes unrelated `AGENTS.md` / `CLAUDE.md` drift. It is preserved as required evidence rather than treated as authoritative scope proof. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/handoff-notes.md b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/handoff-notes.md deleted file mode 100644 index 821c2563f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/handoff-notes.md +++ /dev/null @@ -1,14 +0,0 @@ -Parent acceptance notes: - -- Accepted authoritative commit: `42636f8eb68fe2e817d973a4896f5c35cfc5b12b` -- Recorded in `branch-map.json` as `accepted_tip_after_G2` -- Opened `L2` branch `codex/feat-gateway-mediated-llm-fulfillment-s29-a4-human-caller-adoption` -- Opened `L3` branch `codex/feat-gateway-mediated-llm-fulfillment-s29-a5-repl-dispatch-adoption` -- `L2` worktree path: `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a4-human-caller-adoption` -- `L3` worktree path: `/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a5-repl-dispatch-adoption` - -Important carry-forward constraints: - -- `dispatch_contract.rs`, `agent_inventory.rs`, `validator.rs`, `orchestration_session.rs`, and `state_store.rs` are now frozen after `G2`. -- `L2` may touch only `agents_cmd.rs`, `control.rs`, `prompt_fulfillment.rs`, `crates/shell/tests/agent_public_control_surface_v1.rs`, and minimal supporting tests in its owned surface. -- `L3` may touch only `repl/async_repl.rs`, `crates/shell/tests/repl_world_first_routing_v1.rs`, and `world_ops.rs` only if a concrete additive transport field is proven necessary. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/impact-analysis-summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/impact-analysis-summary.md deleted file mode 100644 index 16c60d576..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/impact-analysis-summary.md +++ /dev/null @@ -1,5 +0,0 @@ -G2 acceptance preserved the L1 GitNexus impact evidence rather than rerunning new symbol edits on the parent branch. - -- The highest-risk L1 seam remained `AgentRuntimeStateStore.resolve_public_control_target` with `HIGH` risk and `19` impacted symbols. -- The run stayed blocked until that result was escalated and explicit user direction authorized continuation within the frozen `A3` ownership boundary. -- The merged authoritative diff still centered on durable-state files; the only out-of-band path was a compile-only unit-test fixture update in `dispatch_contract.rs`, which did not reopen the shared dispatch semantics frozen at `G1`. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/owner.txt deleted file mode 100644 index 9676f5bfe..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/owner.txt +++ /dev/null @@ -1 +0,0 @@ -parent diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/scope.txt deleted file mode 100644 index e7c36813b..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Review L1 against the frozen durable-state criteria, integrate only the accepted lane tip, record accepted_tip_after_G2, and open the one allowed L2/L3 parallel window from that exact authoritative SHA without reopening the shared contract or durable-state owners. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/summary.md deleted file mode 100644 index 86eff4e83..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/summary.md +++ /dev/null @@ -1 +0,0 @@ -G2 passed. The authoritative tree at `42636f8eb68fe2e817d973a4896f5c35cfc5b12b` satisfies the durable attach freeze criteria, `accepted_tip_after_G2` is recorded, and the only safe parallel window is open with both runtime lanes branched from the same accepted tree. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/task.json deleted file mode 100644 index 5cb5b2f58..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G2-durable-attach-accept/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "G2-durable-attach-accept", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "started_at": "2026-05-24T18:35:32Z", - "completed_at": "2026-05-24T18:57:05Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/ACCEPTED deleted file mode 100644 index 8b1378917..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ - diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/HEAD_SHA.txt deleted file mode 100644 index 487582b54..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -0d15fb2fe8902a9201c891eccd3d7a20325f9d72 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/summary.md deleted file mode 100644 index 621e42fdf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/summary.md +++ /dev/null @@ -1 +0,0 @@ -G3 passed on `0d15fb2fe8902a9201c891eccd3d7a20325f9d72`. The runtime lanes now satisfy the shared dispatch contract together, including the same-session parked-turn reattach/stop case that previously blocked acceptance. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/task.json deleted file mode 100644 index 807e2fb67..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G3-parallel-window-accept/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "G3-parallel-window-accept", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "started_at": "2026-05-24T18:57:05Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/ACCEPTED deleted file mode 100644 index 8b1378917..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ - diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/HEAD_SHA.txt deleted file mode 100644 index 487582b54..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -0d15fb2fe8902a9201c891eccd3d7a20325f9d72 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/summary.md deleted file mode 100644 index 09700c259..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/summary.md +++ /dev/null @@ -1 +0,0 @@ -G4 passed. The merged docs truth now matches the accepted runtime behavior and does not reassign contract ownership or durable attach truth outside the shared slice-29 contract surface. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/task.json deleted file mode 100644 index c9f33649f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G4-docs-accept/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "G4-docs-accept", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "started_at": "2026-05-24T20:35:44Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/ACCEPTED deleted file mode 100644 index 8b1378917..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ - diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/HEAD_SHA.txt deleted file mode 100644 index 487582b54..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -0d15fb2fe8902a9201c891eccd3d7a20325f9d72 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/summary.md deleted file mode 100644 index 7afba54c0..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/summary.md +++ /dev/null @@ -1 +0,0 @@ -G5 passed. The accepted tree satisfies the slice-29 implementation contract from `PLAN.md` and `ORCH_PLAN.md`, the validation wall is green, and the recorded detect-changes scope is low risk. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/task.json deleted file mode 100644 index 4266ae704..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/G5-final-acceptance/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "G5-final-acceptance", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "started_at": "2026-05-24T20:45:31Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/ACCEPTED deleted file mode 100644 index 377cefa1a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ -accepted diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/HEAD_SHA.txt deleted file mode 100644 index 0d20a4812..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -6be348293ad140690385fbde5463992e084f5470 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/changed-files.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/changed-files.txt deleted file mode 100644 index 61af962a7..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/changed-files.txt +++ /dev/null @@ -1,4 +0,0 @@ -crates/shell/src/execution/agent_inventory.rs -crates/shell/src/execution/agent_runtime/dispatch_contract.rs -crates/shell/src/execution/agent_runtime/mod.rs -crates/shell/src/execution/agent_runtime/validator.rs diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/commands.txt deleted file mode 100644 index a5dbd97f0..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/commands.txt +++ /dev/null @@ -1,12 +0,0 @@ -npx gitnexus impact resolve_gateway_backend_inventory_entry --repo substrate --direction upstream -npx gitnexus impact validate_runtime_realizability --repo substrate --direction upstream -npx gitnexus impact validate_member_selection --repo substrate --direction upstream -npx gitnexus impact validate_exact_backend_selection --repo substrate --direction upstream -cargo test -p shell inventory_contract_tracks_workspace_origin_and_config_defaults -- --nocapture -cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture -cargo test -p shell validate_exact_backend_selection_bypasses_world_ambiguity_when_backend_matches_exactly -- --nocapture -cargo test -p shell validate_member_selection_returns_descriptor_for_unique_world_member -- --nocapture -cargo test -p shell dispatch_contract -- --nocapture -cargo test -p shell validate_ -- --nocapture -cargo fmt --all -cargo clippy -p shell --lib --tests -- -D warnings diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/deliverable.txt deleted file mode 100644 index ef85e5f8d..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Shared dispatch-contract foundation landed on the L0 worker branch with explicit inventory and persisted-attach baseline domains, runtime materialization through the contract boundary, and no second contract owner or durable attach object. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/dependencies.json deleted file mode 100644 index 46dd2fba5..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/dependencies.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "depends_on": [ - "P0-parent-freeze" - ], - "unblocks": [ - "G1-contract-foundation-accept" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/exit-codes.json deleted file mode 100644 index 0efddab39..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/exit-codes.json +++ /dev/null @@ -1,14 +0,0 @@ -{ - "npx gitnexus impact resolve_gateway_backend_inventory_entry --repo substrate --direction upstream": 0, - "npx gitnexus impact validate_runtime_realizability --repo substrate --direction upstream": 0, - "npx gitnexus impact validate_member_selection --repo substrate --direction upstream": 0, - "npx gitnexus impact validate_exact_backend_selection --repo substrate --direction upstream": 0, - "cargo test -p shell inventory_contract_tracks_workspace_origin_and_config_defaults -- --nocapture": 0, - "cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture": 0, - "cargo test -p shell validate_exact_backend_selection_bypasses_world_ambiguity_when_backend_matches_exactly -- --nocapture": 0, - "cargo test -p shell validate_member_selection_returns_descriptor_for_unique_world_member -- --nocapture": 0, - "cargo test -p shell dispatch_contract -- --nocapture": 0, - "cargo test -p shell validate_ -- --nocapture": 0, - "cargo fmt --all": 0, - "cargo clippy -p shell --lib --tests -- -D warnings": 0 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/gitnexus-detect-changes.txt deleted file mode 100644 index 7a37584e6..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/gitnexus-detect-changes.txt +++ /dev/null @@ -1,6 +0,0 @@ -Worker-side detect-changes evidence before commit was limited by the stale index and the inability to refresh it (`npx gitnexus analyze` crashed with `free(): invalid pointer`). - -Observed behavior before parent integration: - -- `npx gitnexus detect-changes --repo substrate --scope unstaged` and `--scope staged` returned either `No changes detected` or symbol output polluted by unrelated `AGENTS.md` / `CLAUDE.md` drift. -- After integration, `npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^` produced a usable low-risk compare summary, but it still failed to classify `dispatch_contract.rs` directly because the index was stale. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/handoff-notes.md b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/handoff-notes.md deleted file mode 100644 index efc7163ef..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/handoff-notes.md +++ /dev/null @@ -1,9 +0,0 @@ -Worker branch: `codex/feat-gateway-mediated-llm-fulfillment-s29-a1-a2-contract-foundation` - -Worker tip: `6be348293ad140690385fbde5463992e084f5470` - -Parent integration: - -- Cherry-picked onto the authoritative branch as `50a450a05f374e46c736f79f9b5c7fec5c0e54d9`. -- No merge conflicts. -- `control.rs` remained unchanged because it already consumed `RuntimeSelectionDescriptor`/state-store outputs rather than owning top-level launch merging. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/impact-analysis-summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/impact-analysis-summary.md deleted file mode 100644 index 6ad934136..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/impact-analysis-summary.md +++ /dev/null @@ -1,8 +0,0 @@ -GitNexus impact was run before editing the affected symbols. - -- `validate_runtime_realizability`: `HIGH`, 29 impacted symbols, 4 affected processes (`handle_agent_command`, `run_async_repl`, `run_shell_with_cli`, `main`). -- `validate_member_selection`: `HIGH`, 11 impacted symbols, 1 affected process (`handle_agent_command`). -- `validate_exact_backend_selection`: `HIGH`, 10 impacted symbols, 1 affected process (`handle_agent_command`). -- `resolve_gateway_backend_inventory_entry`: `LOW`, 4 impacted symbols, 0 affected processes. - -These HIGH-risk seams were reported before edits. The L0 change was then kept inside the frozen hotspot set and validated with focused unit coverage before parent integration. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/owner.txt deleted file mode 100644 index ff0d03824..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/owner.txt +++ /dev/null @@ -1 +0,0 @@ -worker diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/scope.txt deleted file mode 100644 index e187de20c..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Own the shared dispatch-contract module and immediate inventory/validator consumers only: create the contract vocabulary, make baseline domains explicit, keep policy narrowing fail-closed, and stop before durable-state, public CLI, REPL, docs, or .runs ownership. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/summary.md deleted file mode 100644 index 532169d4c..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/summary.md +++ /dev/null @@ -1 +0,0 @@ -L0 completed on the worker lane. The slice added `dispatch_contract.rs` as the single internal dispatch owner, projected inventory entries into explicit baseline/value origins, resolved persisted host attach truth without inventing a second durable attach object, and moved validator runtime selection through `ResolvedLaunchContract` materialization. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/task.json deleted file mode 100644 index 07c198ff3..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L0-a1-a2-contract-foundation/task.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "task_id": "L0-a1-a2-contract-foundation", - "status": "completed", - "owner": "worker", - "worker_branch": "codex/feat-gateway-mediated-llm-fulfillment-s29-a1-a2-contract-foundation", - "worker_head_sha": "6be348293ad140690385fbde5463992e084f5470", - "accepted_head_sha": "50a450a05f374e46c736f79f9b5c7fec5c0e54d9", - "started_at": "2026-05-24T18:13:37Z", - "completed_at": "2026-05-24T18:29:42Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/ACCEPTED deleted file mode 100644 index a6413548e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ -ACCEPTED diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/HEAD_SHA.txt deleted file mode 100644 index 6402ae14a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -aa656181aa53c92cefbec1264145c5b071e5e803 diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/changed-files.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/changed-files.txt deleted file mode 100644 index 08f0ae98f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/changed-files.txt +++ /dev/null @@ -1,3 +0,0 @@ -crates/shell/src/execution/agent_runtime/dispatch_contract.rs -crates/shell/src/execution/agent_runtime/orchestration_session.rs -crates/shell/src/execution/agent_runtime/state_store.rs diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/commands.txt deleted file mode 100644 index 83c8c527f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/commands.txt +++ /dev/null @@ -1,19 +0,0 @@ -npx gitnexus impact OrchestrationSessionRecord.sync_host_attach_contract --repo substrate --direction upstream -npx gitnexus impact OrchestrationSessionRecord.fork_successor_attach_contract --repo substrate --direction upstream -npx gitnexus impact AgentRuntimeStateStore.resolve_public_control_target --repo substrate --direction upstream -npx gitnexus impact OrchestrationSessionRecord.validate_persisted_invariants --repo substrate --direction upstream -npx gitnexus impact valid_detached_host_continuity_posture --repo substrate --direction upstream -npx gitnexus impact recoverable_stale_host_attachment --repo substrate --direction upstream -cargo fmt --all -cargo fmt --all -- --check -cargo clippy -p shell --lib --tests -- -D warnings -cargo test -p shell new_session_starts_active_attached -- --nocapture -cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture -cargo test -p shell resolve_public_control_target -- --nocapture -cargo test -p shell successor_attach_contract_clears_continuity_and_preserves_launch_truth -- --nocapture -cargo test -p shell host_attach_contract_knob_drift_fails_closed -- --nocapture -cargo test -p shell resolve_public_turn_target_uses_persisted_continuity_truth -- --nocapture -cargo test -p shell load_session_backfills_generalized_attach_contract_defaults_for_legacy_json -- --nocapture -cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture -git diff --check -npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^ diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/deliverable.txt deleted file mode 100644 index 7b70c5b3d..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Generalized persisted host attach truth landed on the L1 worker branch: session birth now stores launch descriptor, capabilities, and attach knobs inside HostAttachContract; successor copy clears only continuity-specific state; and detached planning consumes persisted attach truth instead of ambient participant truth. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/dependencies.json deleted file mode 100644 index 946e89275..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/dependencies.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "depends_on": [ - "G1-contract-foundation-accept" - ], - "unblocks": [ - "G2-durable-attach-accept" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/exit-codes.json deleted file mode 100644 index 1527f8775..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/exit-codes.json +++ /dev/null @@ -1,21 +0,0 @@ -{ - "npx gitnexus impact OrchestrationSessionRecord.sync_host_attach_contract --repo substrate --direction upstream": 0, - "npx gitnexus impact OrchestrationSessionRecord.fork_successor_attach_contract --repo substrate --direction upstream": 0, - "npx gitnexus impact AgentRuntimeStateStore.resolve_public_control_target --repo substrate --direction upstream": 0, - "npx gitnexus impact OrchestrationSessionRecord.validate_persisted_invariants --repo substrate --direction upstream": 0, - "npx gitnexus impact valid_detached_host_continuity_posture --repo substrate --direction upstream": 0, - "npx gitnexus impact recoverable_stale_host_attachment --repo substrate --direction upstream": 0, - "cargo fmt --all": 0, - "cargo fmt --all -- --check": 0, - "cargo clippy -p shell --lib --tests -- -D warnings": 0, - "cargo test -p shell new_session_starts_active_attached -- --nocapture": 0, - "cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture": 0, - "cargo test -p shell resolve_public_control_target -- --nocapture": 0, - "cargo test -p shell successor_attach_contract_clears_continuity_and_preserves_launch_truth -- --nocapture": 0, - "cargo test -p shell host_attach_contract_knob_drift_fails_closed -- --nocapture": 0, - "cargo test -p shell resolve_public_turn_target_uses_persisted_continuity_truth -- --nocapture": 0, - "cargo test -p shell load_session_backfills_generalized_attach_contract_defaults_for_legacy_json -- --nocapture": 0, - "cargo test -p shell persisted_attach_contract_is_explicit_baseline_domain -- --nocapture": 0, - "git diff --check": 0, - "npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^": 0 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/gitnexus-detect-changes.txt deleted file mode 100644 index 4764aba28..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/gitnexus-detect-changes.txt +++ /dev/null @@ -1,35 +0,0 @@ -GitNexus warning: - -- `Index for "substrate" was built at /home/azureuser/__Active_Code/atomize-hq/substrate; your cwd (/home/azureuser/__Active_Code/atomize-hq/.worktrees/substrate-s29-shared-dispatch-contract/a3-durable-attach-freeze) is a sibling clone that is 2 commits ahead of the indexed commit. Results may be stale or incorrect — re-run gitnexus analyze to refresh the index.` - -`npx gitnexus detect-changes --repo substrate --scope compare --base-ref HEAD^` output: - -```text -Changes: 5 files, 47 symbols -Affected processes: 4 -Risk level: medium - -Changed symbols: - undefined GitNexus — Code Intelligence → AGENTS.md - undefined GitNexus — Code Intelligence → CLAUDE.md - undefined from_manifest → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined new → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined transition_state → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined mark_startup_prompt_completed → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined continuity_uaa_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined orchestration_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined shell_trace_session_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined workspace_root → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined shell_owner_pid → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined state → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined opened_at → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined last_active_at → crates/shell/src/execution/agent_runtime/orchestration_session.rs - undefined orchestrator_agent_id → crates/shell/src/execution/agent_runtime/orchestration_session.rs - ... and 32 more - -Affected execution flows: - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → RuntimeSelectionDescriptor (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → New (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → Transition_state (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session - • Hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session → Bind_active_session_handle (4 steps) — changed: hidden_owner_helper_launch_classifier_accepts_detached_attention_needed_session -``` diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/handoff-notes.md b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/handoff-notes.md deleted file mode 100644 index a8de20000..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/handoff-notes.md +++ /dev/null @@ -1,10 +0,0 @@ -Worker branch: `codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze` - -Worker tip: `aa656181aa53c92cefbec1264145c5b071e5e803` - -Parent integration: - -- Cherry-picked onto the authoritative branch as `42636f8eb68fe2e817d973a4896f5c35cfc5b12b`. -- No merge conflicts. -- `dispatch_contract.rs` changed only to update the co-located `persisted_attach_contract_is_explicit_baseline_domain` unit-test fixture for the new persisted `HostAttachContract` fields; the shared contract owner and dispatch semantics remained frozen after `G1`. -- The durable-state changes stayed centered on `orchestration_session.rs` and `state_store.rs`, with successor attach truth and detached-posture checks now keyed off persisted contract truth. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/impact-analysis-summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/impact-analysis-summary.md deleted file mode 100644 index bde53b3ee..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/impact-analysis-summary.md +++ /dev/null @@ -1,10 +0,0 @@ -GitNexus impact was run before the L1 edits. - -- `OrchestrationSessionRecord.sync_host_attach_contract`: `MEDIUM`, `35` impacted symbols, affected processes `start_remote_member_runtime_with_prepared`, `run_async_repl`. -- `OrchestrationSessionRecord.fork_successor_attach_contract`: `LOW`, `3` impacted symbols, affected process `handle_agent_command`. -- `AgentRuntimeStateStore.resolve_public_control_target`: `HIGH`, `19` impacted symbols, affected processes `handle_agent_command`, `resolve_public_control_target_enforces_linux_first_world_posture`. -- `OrchestrationSessionRecord.validate_persisted_invariants`: `LOW`, `3` impacted symbols. -- `valid_detached_host_continuity_posture`: `LOW`, `12` impacted symbols. -- `recoverable_stale_host_attachment`: `LOW`, `3` impacted symbols. - -The `HIGH` result on `resolve_public_control_target` was escalated and recorded in `blocked.json` before edits proceeded. Work resumed only after explicit user direction to continue within the frozen `A3` ownership boundary. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/owner.txt deleted file mode 100644 index ff0d03824..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/owner.txt +++ /dev/null @@ -1 +0,0 @@ -worker diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/scope.txt deleted file mode 100644 index 52c43bfb0..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Own persisted host attach truth and detached-planning state consumption only: generalize HostAttachContract in orchestration_session.rs, move detached continuity checks in state_store.rs onto persisted contract truth, keep migration additive and fail-closed, and do not reopen the L0 shared contract owner or public caller surfaces. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/summary.md deleted file mode 100644 index e24168ecc..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/summary.md +++ /dev/null @@ -1 +0,0 @@ -L1 completed on the worker lane. HostAttachContract now persists generalized launch truth, capabilities, and attach knobs; successor copies preserve launch truth while clearing only the continuity selector; and state-store detached attach planning now consumes persisted contract truth instead of ambient participant truth. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/task.json deleted file mode 100644 index 617b21310..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L1-a3-durable-attach-freeze/task.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "task_id": "L1-a3-durable-attach-freeze", - "status": "completed", - "owner": "worker", - "worker_branch": "codex/feat-gateway-mediated-llm-fulfillment-s29-a3-durable-attach-freeze", - "worker_head_sha": "aa656181aa53c92cefbec1264145c5b071e5e803", - "accepted_head_sha": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "started_at": "2026-05-24T18:35:32Z", - "completed_at": "2026-05-24T18:50:21Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/commands.txt deleted file mode 100644 index cf1c419ac..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/commands.txt +++ /dev/null @@ -1,8 +0,0 @@ -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell public_turn_resumes_parked_host_session_and_preserves_exact_session_selector_contracts --test agent_public_control_surface_v1 -- --nocapture -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell public_turn_uses_persisted_attach_continuity_selector_when_recovering_detached_host_turns --test agent_public_control_surface_v1 -- --nocapture -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell public_start_survives_slow_startup_prompt_completion_after_bootstrap_readiness --test agent_public_control_surface_v1 -- --nocapture -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell public_same_session_parked_status_turn_reattach_and_stop_stay_on_one_orchestration_session_id --test agent_public_control_surface_v1 -- --nocapture -TMPDIR=/mnt/localssd/tmp CARGO_TARGET_DIR=/mnt/localssd/tmp/substrate-parent-a4-target cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture -cargo fmt --all -cargo fmt --all -- --check diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/deliverable.txt deleted file mode 100644 index db4684dba..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Adopt the frozen shared dispatch semantics in the human caller surfaces so start/reattach/fork flows resolve through inventory-backed or persisted-attach-backed truth without reopening the contract or durable-state owners. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/dependencies.json deleted file mode 100644 index 471103531..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/dependencies.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "depends_on": [ - "G2-durable-attach-accept" - ], - "unblocks": [ - "G3-parallel-window-accept" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/exit-codes.json deleted file mode 100644 index 7a7d065bb..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/exit-codes.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "public_turn_prompt_requests_require_exact_session_and_backend_contract": 0, - "public_turn_resumes_parked_host_session_and_preserves_exact_session_selector_contracts": 0, - "public_turn_uses_persisted_attach_continuity_selector_when_recovering_detached_host_turns": 0, - "public_start_survives_slow_startup_prompt_completion_after_bootstrap_readiness": 0, - "public_same_session_parked_status_turn_reattach_and_stop_stay_on_one_orchestration_session_id": 101, - "agent_public_control_surface_v1_full_suite": 101, - "cargo_fmt_all": 0, - "cargo_fmt_all_check": 0 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/owner.txt deleted file mode 100644 index ff0d03824..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/owner.txt +++ /dev/null @@ -1 +0,0 @@ -worker diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/scope.txt deleted file mode 100644 index 4cc923a9b..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Own agents_cmd.rs, agent_runtime/control.rs, prompt_fulfillment.rs, agent_public_control_surface_v1.rs, and minimal directly related supporting tests only. Do not reopen dispatch_contract.rs, inventory/validator ownership, durable-state files, REPL files, docs, or .runs. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/summary.md deleted file mode 100644 index df447ef25..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/summary.md +++ /dev/null @@ -1,5 +0,0 @@ -# L2 Summary - -- `agents_cmd.rs`, `control.rs`, and `agent_public_control_surface_v1.rs` adoption changes were integrated on the authoritative branch as `d5323945`. -- The final same-session parked-turn repair landed later through the LOW-risk `async_repl.rs` continuity seam, not through any additional L2-owned caller-surface change. -- The final accepted tree at `0d15fb2fe8902a9201c891eccd3d7a20325f9d72` preserves the exact shared contract semantics on the public/human caller plane. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/task.json deleted file mode 100644 index 45e00e064..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L2-a4-human-caller-adoption/task.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "task_id": "L2-a4-human-caller-adoption", - "status": "completed", - "owner": "parent", - "worker_branch": "codex/feat-gateway-mediated-llm-fulfillment-s29-a4-human-caller-adoption", - "worker_agent_id": null, - "worker_nickname": null, - "base_head_sha": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "started_at": "2026-05-24T18:57:05Z", - "completed_at": "2026-05-24T20:47:10Z", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/deliverable.txt deleted file mode 100644 index 32cc743cf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Adopt the frozen shared dispatch semantics in orchestrator-controlled REPL routing without reopening the contract or durable-state owners, and touch world_ops.rs only if a concrete additive transport field is proven necessary. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/dependencies.json deleted file mode 100644 index 471103531..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/dependencies.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "depends_on": [ - "G2-durable-attach-accept" - ], - "unblocks": [ - "G3-parallel-window-accept" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/owner.txt deleted file mode 100644 index ff0d03824..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/owner.txt +++ /dev/null @@ -1 +0,0 @@ -worker diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/scope.txt deleted file mode 100644 index e8c02ad6e..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Own repl/async_repl.rs, repl_world_first_routing_v1.rs, and world_ops.rs only if an additive transport field is concretely required. Do not reopen dispatch_contract.rs, control.rs, agents_cmd.rs, durable-state files, docs, or .runs. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/summary.md deleted file mode 100644 index 5da2884bf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/summary.md +++ /dev/null @@ -1,5 +0,0 @@ -# L3 Summary - -- The first low-risk `async_repl.rs` helper-closeout changes were integrated as `c2721ed5`, which cleared detached-turn continuity failures. -- The remaining same-session parked-turn race was then resolved through the LOW-risk `can_park_host_runtime_after_detach` seam and committed in the final accepted implementation tree `0d15fb2fe8902a9201c891eccd3d7a20325f9d72`. -- The previously escalated HIGH-risk `dispatch_targeted_follow_up_turn` seam remained untouched; the final repair came from recognizing completed one-turn handoff truth even when the persisted session row lags. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/task.json deleted file mode 100644 index 578c0a6c4..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L3-a5-repl-dispatch-adoption/task.json +++ /dev/null @@ -1,12 +0,0 @@ -{ - "task_id": "L3-a5-repl-dispatch-adoption", - "status": "completed", - "owner": "parent", - "worker_branch": "codex/feat-gateway-mediated-llm-fulfillment-s29-a5-repl-dispatch-adoption", - "worker_agent_id": "019e5b5c-5f2c-7e71-95ba-953a8ccb58de", - "worker_nickname": "Lovelace", - "base_head_sha": "42636f8eb68fe2e817d973a4896f5c35cfc5b12b", - "started_at": "2026-05-24T18:57:05Z", - "completed_at": "2026-05-24T20:47:10Z", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/summary.md deleted file mode 100644 index 4618e1007..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/summary.md +++ /dev/null @@ -1 +0,0 @@ -Parent updated the allowed truth surfaces in `ADR-0027` and `llm-last-mile/{29,30,31,README}.md` so they match the merged slice-29 runtime: one shared dispatch-contract owner, explicit baseline domains, persisted `HostAttachContract` launch truth, and caller parity. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/task.json deleted file mode 100644 index a55bc81ce..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/L4-a6-docs-truth-sync/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "L4-a6-docs-truth-sync", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "started_at": "2026-05-24T20:35:44Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/ACCEPTED b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/ACCEPTED deleted file mode 100644 index 377cefa1a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/ACCEPTED +++ /dev/null @@ -1 +0,0 @@ -accepted diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/HEAD_SHA.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/HEAD_SHA.txt deleted file mode 100644 index 07a212251..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/HEAD_SHA.txt +++ /dev/null @@ -1 +0,0 @@ -4c61ab779752a9185c6b7558275d7fdb5880893c diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/changed-files.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/changed-files.txt deleted file mode 100644 index ac64da6cd..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/changed-files.txt +++ /dev/null @@ -1,14 +0,0 @@ -.runs/slice-29-shared-dispatch-contract/run-state.json -.runs/slice-29-shared-dispatch-contract/tasks.json -.runs/slice-29-shared-dispatch-contract/source-lock.json -.runs/slice-29-shared-dispatch-contract/contract-freeze.json -.runs/slice-29-shared-dispatch-contract/durable-state-freeze.json -.runs/slice-29-shared-dispatch-contract/branch-map.json -.runs/slice-29-shared-dispatch-contract/lane-ownership.json -.runs/slice-29-shared-dispatch-contract/merge-order.json -.runs/slice-29-shared-dispatch-contract/validation-wall.md -.runs/slice-29-shared-dispatch-contract/session-log.md -.runs/slice-29-shared-dispatch-contract/final-summary.md -.runs/slice-29-shared-dispatch-contract/sentinels/RUN_OPEN -.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/* -.runs/slice-29-shared-dispatch-contract/gates/G0-run-freeze/* diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/commands.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/commands.txt deleted file mode 100644 index 1b0ea17a3..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/commands.txt +++ /dev/null @@ -1,6 +0,0 @@ -git status --short --branch -- PLAN.md ORCH_PLAN.md -git rev-parse HEAD -sha256sum PLAN.md -git worktree list --porcelain -npx gitnexus status -npx gitnexus analyze diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/deliverable.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/deliverable.txt deleted file mode 100644 index ada794bca..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/deliverable.txt +++ /dev/null @@ -1 +0,0 @@ -Written P0 run-state artifacts, passed G0 evidence, and a clean authorization boundary for opening the L0 worktree. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/dependencies.json b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/dependencies.json deleted file mode 100644 index 9eb629f37..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/dependencies.json +++ /dev/null @@ -1,6 +0,0 @@ -{ - "depends_on": [], - "unblocks": [ - "L0-a1-a2-contract-foundation" - ] -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/exit-codes.json b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/exit-codes.json deleted file mode 100644 index ce5ab0021..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/exit-codes.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "git status --short --branch -- PLAN.md ORCH_PLAN.md": 0, - "git rev-parse HEAD": 0, - "sha256sum PLAN.md": 0, - "git worktree list --porcelain": 0, - "npx gitnexus status": 0, - "npx gitnexus analyze": 1 -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/gitnexus-detect-changes.txt deleted file mode 100644 index ca1784e18..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/gitnexus-detect-changes.txt +++ /dev/null @@ -1 +0,0 @@ -Not run in P0. This task did not edit code symbols and has no worker handoff. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/handoff-notes.md b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/handoff-notes.md deleted file mode 100644 index 467220282..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/handoff-notes.md +++ /dev/null @@ -1 +0,0 @@ -Parent-only task. No worker branch or merge was involved. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/impact-analysis-summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/impact-analysis-summary.md deleted file mode 100644 index c4ee9bfda..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/impact-analysis-summary.md +++ /dev/null @@ -1,7 +0,0 @@ -No code symbols were edited during `P0`; this task only initialized parent-owned `.runs/**` artifacts. - -GitNexus refresh attempt note: - -- `npx gitnexus status` reported the index as stale. -- `npx gitnexus analyze` was attempted before any future symbol edits and failed with `free(): invalid pointer`. -- The failure is recorded as environment evidence, not ignored. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/owner.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/owner.txt deleted file mode 100644 index 9676f5bfe..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/owner.txt +++ /dev/null @@ -1 +0,0 @@ -parent diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/scope.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/scope.txt deleted file mode 100644 index af56ee2e2..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/scope.txt +++ /dev/null @@ -1 +0,0 @@ -Source-lock the live PLAN.md, freeze the slice-29 contract and durable-state vocabulary, initialize parent-owned .runs state, and authorize only L0. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/summary.md deleted file mode 100644 index b139ab22d..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/summary.md +++ /dev/null @@ -1 +0,0 @@ -P0 completed successfully. The parent locked the live PLAN.md bytes, froze the contract vocabulary and durable-state rules, initialized the slice-29 run-state tree, recorded the GitNexus refresh failure, and passed G0 without opening any slice-29 worker worktree. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/task.json deleted file mode 100644 index 201c1e16f..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P0-parent-freeze/task.json +++ /dev/null @@ -1,7 +0,0 @@ -{ - "task_id": "P0-parent-freeze", - "status": "completed", - "owner": "parent", - "started_at": "2026-05-24T18:13:37Z", - "completed_at": "2026-05-24T18:13:37Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/gitnexus-detect-changes.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/gitnexus-detect-changes.txt deleted file mode 100644 index 5c66612ee..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/gitnexus-detect-changes.txt +++ /dev/null @@ -1,21 +0,0 @@ -Changes: 7 files, 37 symbols -Affected processes: 0 -Risk level: low - -Changed symbols: - undefined apply_parked_host_runtime_snapshots → crates/shell/src/repl/async_repl.rs - undefined shell_owner_pid_is_alive → crates/shell/src/repl/async_repl.rs - undefined start_member_runtime_reuses_parent_session_and_persists_world_binding → crates/shell/src/repl/async_repl.rs - undefined prepare_member_replacement_runtime_preserves_resumed_from_lineage → crates/shell/src/repl/async_repl.rs - undefined tests → crates/shell/src/repl/async_repl.rs - undefined orchestration_session_manifest_with_options → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined write_json_file → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined repo_root → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined read_repo_file → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined read_production_shell_source_without_inline_tests → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined agent_status_json_surfaces_parked_resumable_fields_from_parent_session_truth → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined agent_status_json_surfaces_awaiting_attention_fields_from_parent_session_truth → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined agent_doctor_does_not_treat_trace_records_as_control_plane_authorization → crates/shell/tests/agent_successor_contract_ahcsitc0.rs - undefined ADR-0027 — LLM + Agent Config/Policy Surface (Existing Files, New Keys) → docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md - undefined User Contract (Authoritative) → docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md - ... and 22 more diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/summary.md deleted file mode 100644 index e9b97ee2c..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/summary.md +++ /dev/null @@ -1 +0,0 @@ -P1 passed on accepted tip `0d15fb2fe8902a9201c891eccd3d7a20325f9d72`. All locked commands from `ORCH_PLAN.md` passed, and GitNexus `detect-changes` reported a low-risk staged implementation scope with no affected processes. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/task.json deleted file mode 100644 index 5ac232508..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P1-a7-validation-wall/task.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "task_id": "P1-a7-validation-wall", - "status": "completed", - "owner": "parent", - "accepted_head_sha": "0d15fb2fe8902a9201c891eccd3d7a20325f9d72", - "started_at": "2026-05-24T20:35:44Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/status.txt b/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/status.txt deleted file mode 100644 index 6ab9fedbf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/status.txt +++ /dev/null @@ -1 +0,0 @@ -completed diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/summary.md b/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/summary.md deleted file mode 100644 index e7f3cd2bf..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/summary.md +++ /dev/null @@ -1 +0,0 @@ -Parent-only closeout completed: final summary, validation wall, task/gate state, accepted-tip records, and `RUN_COMPLETE` were written under `.runs/slice-29-shared-dispatch-contract/`. diff --git a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/task.json b/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/task.json deleted file mode 100644 index 26cf7237a..000000000 --- a/.runs/slice-29-shared-dispatch-contract/tasks/P2-parent-closeout/task.json +++ /dev/null @@ -1,7 +0,0 @@ -{ - "task_id": "P2-parent-closeout", - "status": "completed", - "owner": "parent", - "started_at": "2026-05-24T20:47:10Z", - "completed_at": "2026-05-24T20:47:10Z" -} diff --git a/.runs/slice-29-shared-dispatch-contract/validation-wall.md b/.runs/slice-29-shared-dispatch-contract/validation-wall.md deleted file mode 100644 index 5d98bbfc0..000000000 --- a/.runs/slice-29-shared-dispatch-contract/validation-wall.md +++ /dev/null @@ -1,45 +0,0 @@ -# Validation Wall - -Locked merged-tree commands from `ORCH_PLAN.md`: - -```bash -cargo test -p shell resolve_public_control_target -- --nocapture -cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture -cargo test -p shell new_session_starts_active_attached -- --nocapture -cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture -cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture -cargo test -p shell --test repl_world_first_routing_v1 -- --nocapture -cargo fmt --all -- --check -cargo clippy --workspace --all-targets -- -D warnings -cargo test --workspace -- --nocapture -``` - -Additional parent proof obligations: - -- final merged-tree GitNexus `detect-changes` transcription -- contract/domain parity audit against `PLAN.md` -- docs and `llm-last-mile/` truth-sync audit against merged runtime behavior - -## Result - -Accepted authoritative implementation/docs/test tip: - -- `0d15fb2fe8902a9201c891eccd3d7a20325f9d72` - -Locked command results on that accepted tree: - -- `cargo test -p shell resolve_public_control_target -- --nocapture` passed -- `cargo test -p shell public_turn_prompt_requests_require_exact_session_and_backend_contract -- --nocapture` passed -- `cargo test -p shell new_session_starts_active_attached -- --nocapture` passed -- `cargo test -p shell detached_postures_enforce_pending_inbox_truth -- --nocapture` passed -- `cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture` passed -- `cargo test -p shell --test repl_world_first_routing_v1 -- --nocapture` passed -- `cargo fmt --all -- --check` passed -- `cargo clippy --workspace --all-targets -- -D warnings` passed -- `cargo test --workspace -- --nocapture` passed - -Additional proof obligations: - -- GitNexus `detect-changes` on the staged implementation tree reported `7 files`, `37 symbols`, `0 affected processes`, `risk level: low` -- Contract/domain parity audit passed: the merged runtime keeps `dispatch_contract.rs` as the sole internal contract owner, makes both baseline domains explicit (`InventoryLaunch`, `PersistedHostAttach`), preserves generalized launch truth in `HostAttachContract`, and keeps human/public + orchestrator-controlled dispatch on the same semantics -- Docs truth-sync audit passed for the allowed surfaces in `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` and `llm-last-mile/{29,30,31,README}.md` diff --git a/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md b/archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md similarity index 100% rename from SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md rename to archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md diff --git a/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md b/archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md similarity index 100% rename from UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md rename to archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md diff --git a/docs/WORLD.md b/docs/WORLD.md index 6538f7437..4a014f4b8 100644 --- a/docs/WORLD.md +++ b/docs/WORLD.md @@ -171,7 +171,7 @@ Deliberate boundary for later lanes: confirm `cap_chown` is present in the service's `CapabilityBoundingSet`/`AmbientCapabilities` (overlayfs copy-up may require it to preserve ownership/metadata). - Need to hand off a reproducible verification run? Execute `scripts/linux/world-socket-verify.sh` - (see `docs/manual_verification/linux_world_socket.md`) to provision the socket, capture + (see `docs/reference/world/verification/linux_world_socket.md`) to provision the socket, capture doctor/shim-status JSON, and optionally uninstall the units afterward. - Provisioning is idempotent; rerun the helper whenever the agent binary changes or the units need to be repaired. Set `SUBSTRATE_WORLD_SOCKET` to diff --git a/docs/cross-platform/mac_world_setup.md b/docs/cross-platform/mac_world_setup.md index 83f18b09b..4b9eebcac 100644 --- a/docs/cross-platform/mac_world_setup.md +++ b/docs/cross-platform/mac_world_setup.md @@ -180,7 +180,7 @@ This conformance mode creates a temporary no-workspace fixture, sets Use `--log-dir ` if you want the doctor JSON and command transcripts written to a specific artifact directory. For the full operator playbook, including Linux privileged verification and the -optional named-allowlist walkthrough, see `docs/manual_verification/netfilter_enforcement.md`. +optional named-allowlist walkthrough, see `docs/reference/world/verification/netfilter_enforcement.md`. ### Using `substrate host doctor` and `substrate world doctor` diff --git a/docs/decisions/concrete-remediation-decisions.md b/docs/decisions/concrete-remediation-decisions.md deleted file mode 100644 index d5fae6db4..000000000 --- a/docs/decisions/concrete-remediation-decisions.md +++ /dev/null @@ -1,57 +0,0 @@ -# Concrete Remediation Decisions - -This file records any **decision-last** choices introduced while remediating concreteness gaps. - -If a decision in this file conflicts with `WORKSTREAM_TRIAGE_AND_LIFT_DECISIONS.md`, the decision log wins. - -## CRD-0001 — Work Lift strict pack mode forbids directory/prefix Touch Set entries - -Date: 2026-02-22 - -### Context - -Work Lift v1 allows directory/prefix entries in Impact Map Touch Sets (they degrade confidence and can be expanded deterministically for advisory lift estimation). However, the strict-mode onramp requires at least one concrete, pack-eligible invariant that is: - -- deterministic, -- measurable from existing contracts, and -- safe to enforce without relying on non-deterministic repo state beyond `HEAD`. - -### Decision - -In **strict pack** checks (SEAM-5 S3), the pack MUST have **no** directory/prefix entries: - -- `validate_impact_map.py --emit-json` MUST report `dir_prefixes == []`. - -### Rationale - -Directory/prefix entries inherently depend on `HEAD` for deterministic expansion and are explicitly treated as lower-confidence signals. Strict pack mode needs an invariant that reduces this uncertainty rather than masking it. - -### Implications - -- Packs that rely on directory/prefix entries can still compute advisory lift, but strict pack checks fail until the Touch Set is made explicit. -- This does not change the validator’s strict-vs-legacy gating; it only affects the opt-in strict lift wrapper. - -## CRD-0002 — Promotion criteria for enabling strict checks by default - -Date: 2026-02-22 - -### Context - -The strict-mode onramp plan previously contained placeholders (“N calibration runs”, “acceptable false positive rate”). These values are required for a concrete rollout plan. - -### Decision - -Promotion to “enabled-by-default” strict checks requires: - -- >= 20 calibration runs -- across >= 10 distinct eligible packs (`tasks.json.meta.slice_spec_version >= 2`) -- with strict failure false-positive rate <= 5% -- with any exceptions documented as explicit allowlist entries (path + rationale) in the strict-mode standard doc. - -### Rationale - -These thresholds are large enough to exercise variability across packs while remaining small enough to execute during a bounded rollout. - -### Implications - -Strict checks remain opt-in until these criteria are met and a separate PR explicitly flips defaults. diff --git a/docs/project_management/_archived/next/linux_guest_rootfs_backend/tasks.md b/docs/project_management/_archived/next/linux_guest_rootfs_backend/tasks.md index 87eaa02e2..9c5127ed5 100644 --- a/docs/project_management/_archived/next/linux_guest_rootfs_backend/tasks.md +++ b/docs/project_management/_archived/next/linux_guest_rootfs_backend/tasks.md @@ -65,7 +65,7 @@ Phase 1 `spec.md` and Phase 2 `plan.md` were loaded and accepted as the authorit - [ ] Task: Add Linux regression, smoke, and manual verification coverage for guest-rootfs. - Acceptance: Coverage proves image verification, overlay reuse/separation, readiness consistency, guest execution, full isolation, provisioning persistence, and host-native rejection; manual validation lives in normal doc/smoke surfaces rather than planning-pack artifacts. - Verify: `cargo test -p world -- --nocapture`; `cargo test -p world-service -- --nocapture`; `cargo test -p shell -- --nocapture`; `bash docs/project_management/_archived/next/linux_guest_rootfs_backend/smoke/linux-smoke.sh` - - Files: new `crates/world/tests/guest_rootfs_integration.rs`, new `crates/world-service/tests/guest_rootfs_execution.rs`, new `crates/shell/tests/world_enable_provision_deps_guest_rootfs.rs`, new `docs/project_management/_archived/next/linux_guest_rootfs_backend/smoke/linux-smoke.sh`, new `docs/manual_verification/linux_guest_rootfs.md` + - Files: new `crates/world/tests/guest_rootfs_integration.rs`, new `crates/world-service/tests/guest_rootfs_execution.rs`, new `crates/shell/tests/world_enable_provision_deps_guest_rootfs.rs`, new `docs/project_management/_archived/next/linux_guest_rootfs_backend/smoke/linux-smoke.sh`, new `docs/reference/world/verification/linux_guest_rootfs.md` Assumptions carried into this breakdown: - I assumed the implementation will introduce a dedicated `crates/world/src/guest_rootfs/` module; if the code lands in a different existing Linux-world seam, the ordering still holds. diff --git a/docs/project_management/_archived/p0-platform-stability/session_log.md b/docs/project_management/_archived/p0-platform-stability/session_log.md index b2ed2884c..191556087 100644 --- a/docs/project_management/_archived/p0-platform-stability/session_log.md +++ b/docs/project_management/_archived/p0-platform-stability/session_log.md @@ -373,7 +373,7 @@ Template: ## [2025-12-02 18:47 UTC] Integration Agent – S1c-integ – Linux socket harness - Added `scripts/linux/world-socket-verify.sh`, a sudo-enabled helper that provisions the world-agent socket, captures `world doctor` + `shim-status` JSON, logs `systemctl` state, and optionally runs the uninstall script so operators can document real socket-activation runs. -- Authored `docs/manual_verification/linux_world_socket.md` with requirements, usage, and artifact descriptions; `docs/WORLD.md` now references the helper near the existing manual verification steps. +- Authored `docs/reference/world/verification/linux_world_socket.md` with requirements, usage, and artifact descriptions; `docs/WORLD.md` now references the helper near the existing manual verification steps. - Harness defaults to storing logs under `artifacts/linux/world-socket-verify-` so future session log entries or PRs can attach the raw JSON for the `world_socket` block. ## [2025-12-02 18:46 UTC] Integration Agent – R1b-integ – START diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md index 144a60185..18d1206ff 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md @@ -41,8 +41,8 @@ open_remediations: [] - `cargo test -p shell --test world_request_net_allowed_snapshot -- --nocapture` passed with `1 passed; 0 failed`; `nonpty_world_request_obeys_net_allowed_routing_matrix` keeps allow-all (`["*"]`), deny-all (`[]`), and restrictive routing semantics aligned with the effective `world.net.filter` host gate. - `cargo test -p shell --test doctor_scopes_ds0 -- --nocapture` passed with `3 passed; 0 failed`, preserving the world-doctor JSON envelope for the published `requested`, `enabled`, `world_netfilter_enable_present`, and `last_failure_reason` fields. - `cargo test -p shell --test shim_doctor -- --nocapture` passed with `11 passed; 0 failed`, including `shim_doctor_json_preserves_world_netfilter_default_details`, `shim_doctor_json_preserves_world_netfilter_enabled_details`, and `shim_doctor_json_preserves_world_netfilter_failure_reason_details`, proving downstream shim surfaces preserve the same doctor contract. - - `docs/manual_verification/netfilter_enforcement.md` now publishes the privileged Linux verification path around `cargo test -p world -- --ignored --nocapture`, including prerequisites, expected pass/skip/failure evidence, and the exact closeout capture requirements for the ignored `crates/world/src/netfilter.rs` nftables coverage. - - `scripts/mac/smoke.sh` now includes `--netfilter-conformance`, which warms Lima with `SUBSTRATE_WORLD_NETFILTER_ENABLE=1`, exercises allow-all and deny-all postures, and writes the doctor JSON plus probe transcripts expected by closeout; `docs/cross-platform/mac_world_setup.md` and `docs/manual_verification/netfilter_enforcement.md` publish the same warm/smoke commands, expected doctor states, and artifact names (`allow-all-world-doctor.json`, `deny-all-world-doctor.json`). + - `docs/reference/world/verification/netfilter_enforcement.md` now publishes the privileged Linux verification path around `cargo test -p world -- --ignored --nocapture`, including prerequisites, expected pass/skip/failure evidence, and the exact closeout capture requirements for the ignored `crates/world/src/netfilter.rs` nftables coverage. + - `scripts/mac/smoke.sh` now includes `--netfilter-conformance`, which warms Lima with `SUBSTRATE_WORLD_NETFILTER_ENABLE=1`, exercises allow-all and deny-all postures, and writes the doctor JSON plus probe transcripts expected by closeout; `docs/cross-platform/mac_world_setup.md` and `docs/reference/world/verification/netfilter_enforcement.md` publish the same warm/smoke commands, expected doctor states, and artifact names (`allow-all-world-doctor.json`, `deny-all-world-doctor.json`). - **Contracts published or changed**: - none; `SEAM-5` consumes `C-01` through `C-07` and turns them into conformance evidence without publishing a new contract. - **Threads published / advanced**: @@ -54,7 +54,7 @@ open_remediations: [] - Operators and maintainers can now verify allow-all versus deny-all behavior against the same doctor fields and runtime expectations that the regression suites pin in code. - **Planned-vs-landed delta**: - No contract drift was found; the landed regression suites and operator-facing conformance surfaces match the planned `SEAM-5` scope. - - Local execution on this Darwin host could not produce privileged Linux nftables evidence: `cargo test -p world -- --ignored --nocapture` completed with `0 tests` because the ignored privileged coverage is Linux-gated. The landed closeout therefore cites the published Linux verification command and capture requirements from `docs/manual_verification/netfilter_enforcement.md` rather than a local Linux transcript. + - Local execution on this Darwin host could not produce privileged Linux nftables evidence: `cargo test -p world -- --ignored --nocapture` completed with `0 tests` because the ignored privileged coverage is Linux-gated. The landed closeout therefore cites the published Linux verification command and capture requirements from `docs/reference/world/verification/netfilter_enforcement.md` rather than a local Linux transcript. - **Downstream stale triggers raised**: - none inside this pack; future drift against the recorded basis triggers reopens conformance work outside the terminal seam rather than creating a downstream carry here. - **Remediation disposition**: diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-5-verification-and-smoke-conformance.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-5-verification-and-smoke-conformance.md index dd7b7adc9..fcbac7bbe 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-5-verification-and-smoke-conformance.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-5-verification-and-smoke-conformance.md @@ -70,7 +70,7 @@ open_remediations: [] - `transport-api-types` tests - `crates/shell` tests around snapshot builder and routing decisions - `crates/world` tests around rule generation - - `docs/manual_verification` or related smoke areas + - `docs/reference/world/verification` or related smoke areas - **Verification**: - This seam is itself the verification surface and is now concrete enough to execute. - **Risks / unknowns**: diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md index 53493e92b..adf527c17 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md @@ -62,7 +62,7 @@ open_remediations: [] - `scripts/mac/smoke.sh` - `docs/reference/config/world.md` - `docs/cross-platform/mac_world_setup.md` - - `docs/manual_verification/netfilter_enforcement.md` + - `docs/reference/world/verification/netfilter_enforcement.md` - **Verification**: - cross-seam regression coverage for config/routing/doctor invariants - ignored privileged Linux validation for requested isolation and deny-all behavior diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md index 352f76459..03aa43234 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md @@ -62,7 +62,7 @@ candidate_subslices: [] - **Outcome**: the seam closeout can cite one concrete privileged verification surface instead of relying on source-only ignored tests. - **Files**: - `crates/world/src/netfilter.rs` - - `docs/manual_verification/netfilter_enforcement.md` + - `docs/reference/world/verification/netfilter_enforcement.md` - **Thread/contract refs**: - `THR-04` - `C-02` @@ -84,7 +84,7 @@ Checklist: - `scripts/mac/lima-warm.sh` - `scripts/mac/smoke.sh` - `docs/cross-platform/mac_world_setup.md` - - `docs/manual_verification/netfilter_enforcement.md` + - `docs/reference/world/verification/netfilter_enforcement.md` - **Thread/contract refs**: - `THR-03` - `THR-05` diff --git a/docs/reference/world/README.md b/docs/reference/world/README.md index 9bac79550..488e84ac8 100644 --- a/docs/reference/world/README.md +++ b/docs/reference/world/README.md @@ -12,3 +12,8 @@ Existing related docs (top-level): Operator documentation for `substrate world deps` lives under: - `docs/reference/world/deps/README.md` + +## World Verification + +Operator verification playbooks for stable world behavior live under: +- `docs/reference/world/verification/README.md` diff --git a/docs/reference/world/verification/README.md b/docs/reference/world/verification/README.md new file mode 100644 index 000000000..a05fa3348 --- /dev/null +++ b/docs/reference/world/verification/README.md @@ -0,0 +1,8 @@ +# World Verification + +Operator-facing verification playbooks for published world behavior live here. + +## Documents + +- `linux_world_socket.md`: Linux socket-activation and doctor/shim-status evidence capture. +- `netfilter_enforcement.md`: privileged Linux and macOS Lima verification for world netfilter enforcement. diff --git a/docs/manual_verification/linux_world_socket.md b/docs/reference/world/verification/linux_world_socket.md similarity index 100% rename from docs/manual_verification/linux_world_socket.md rename to docs/reference/world/verification/linux_world_socket.md diff --git a/docs/manual_verification/netfilter_enforcement.md b/docs/reference/world/verification/netfilter_enforcement.md similarity index 98% rename from docs/manual_verification/netfilter_enforcement.md rename to docs/reference/world/verification/netfilter_enforcement.md index 1e83486b5..a0c39406c 100644 --- a/docs/manual_verification/netfilter_enforcement.md +++ b/docs/reference/world/verification/netfilter_enforcement.md @@ -2,7 +2,7 @@ Use this playbook to verify the opt-in world netfilter contract on Linux and macOS. It is the operator-facing companion to the three-way gate published in -[`world.net.filter`](../reference/config/world.md): +[`world.net.filter`](../../config/world.md): - `world.net.filter` decides whether the host may request enforcement. - policy `net_allowed` decides whether the posture is allow-all, deny-all, or a restrictive allowlist. @@ -119,7 +119,7 @@ it does not mutate repository or user configuration. - inspect `.world.netfilter_status.last_failure_reason` - if `world_netfilter_enable_present` is `false`, rerun the Lima warm step with `SUBSTRATE_WORLD_NETFILTER_ENABLE=1` - if `requested` is not what you expected, re-check the host gate and policy posture against the three-way gate contract in - [`world.md`](../reference/config/world.md) + [`world.md`](../../config/world.md) ## Optional manual restrictive allowlist walkthrough diff --git a/llm-last-mile/13-member-runtime-world-placement-gap-sow.md b/llm-last-mile/13-member-runtime-world-placement-gap-sow.md index ae18cd3d1..313bed617 100644 --- a/llm-last-mile/13-member-runtime-world-placement-gap-sow.md +++ b/llm-last-mile/13-member-runtime-world-placement-gap-sow.md @@ -334,7 +334,7 @@ Relevant reference docs: - [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:105) - [docs/INSTALLATION.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/INSTALLATION.md:79) -- [docs/manual_verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/manual_verification/linux_world_socket.md:1) +- [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md:1) - [docs/cross-platform/wsl_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_setup.md:1) - [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md:1) diff --git a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md index 807b8c04c..862ca25fa 100644 --- a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md +++ b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md @@ -326,7 +326,7 @@ Primary anchors: - [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md:169) - [docs/REPLAY.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/REPLAY.md:82) - [docs/reference/env/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/env/contract.md:63) -- [docs/manual_verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/manual_verification/linux_world_socket.md:12) +- [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md:12) - [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md:108) - [docs/cross-platform/wsl_world_troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_troubleshooting.md:163) - [ADR-0042](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md:127) @@ -533,7 +533,7 @@ When this slice lands, the following must be updated together: - [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md), - [docs/REPLAY.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/REPLAY.md), - [docs/reference/env/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/env/contract.md), -- [docs/manual_verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/manual_verification/linux_world_socket.md), +- [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md), - [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md), - [docs/cross-platform/wsl_world_troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_troubleshooting.md), - [dist-workspace.toml](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/dist-workspace.toml), From b25ce0a097248eae3b053c9e43c11d18c1912181 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 09:14:50 -0400 Subject: [PATCH 02/20] Reorganize gateway contracts under docs/contracts/gateway --- docs/WORLD.md | 2 +- docs/contracts/README.md | 7 ++++ docs/contracts/gateway/README.md | 13 +++++++ .../backend-adapter-protocol.md} | 4 +-- .../backend-adapter-schema.md} | 2 +- .../backend-adapter-selection.md} | 4 +-- .../operator-contract.md} | 4 +-- .../policy-evaluation.md} | 0 .../runtime-parity.md} | 6 ++-- .../status-schema.md} | 0 .../next/llm_gateway_in_world/contract.md | 2 +- .../llm_gateway_in_world/decision_register.md | 2 +- .../next/llm_gateway_in_world/impact_map.md | 2 +- .../manual_testing_playbook.md | 2 +- .../next/llm_gateway_in_world/plan.md | 2 +- .../llm_gateway_in_world/spec_manifest.md | 2 +- .../specs/env_injection.md | 2 +- .../specs/http_surface.md | 2 +- ...kend-contract-and-capability-divergence.md | 6 ++-- ...-gateway-boundary-and-runtime-ownership.md | 4 +-- ...y-backend-selection-runtime-integration.md | 10 +++--- .../manual_testing_playbook.md | 2 +- .../policy-spec.md | 2 +- .../pre-planning/impact_map.md | 2 +- .../slices/ITPS1/ITPS1-spec.md | 2 +- .../slices/ITPS2/ITPS2-spec.md | 2 +- .../telemetry-spec.md | 2 +- .../policy-spec.md | 4 +-- .../pre-planning/impact_map.md | 4 +-- .../pre-planning/spec_manifest.md | 14 ++++---- .../compatibility-spec.md | 4 +-- .../governance/remediation-log.md | 14 ++++---- .../governance/seam-2-closeout.md | 4 +-- .../governance/seam-3-closeout.md | 2 +- .../platform-parity-spec.md | 2 +- .../scope_brief.md | 14 ++++---- ...-1-backend-selection-and-policy-surface.md | 12 +++---- ...eam-2-runtime-realization-and-artifacts.md | 20 +++++------ .../seam-3-parity-validation-and-rollout.md | 16 ++++----- .../seam_map.md | 6 ++-- .../review.md | 4 +-- .../seam.md | 12 +++---- .../slice-00-c-01-c-02-contract-definition.md | 6 ++-- ...e-1-selection-order-and-inventory-truth.md | 2 +- ...icy-precedence-and-fail-closed-boundary.md | 2 +- .../review.md | 2 +- .../seam.md | 12 +++---- ...e-1-binding-lookup-and-capability-gates.md | 2 +- ...ce-2-request-auth-and-runtime-artifacts.md | 2 +- .../review.md | 6 ++-- .../seam.md | 12 +++---- .../threading.md | 20 +++++------ .../pre-planning/impact_map.md | 28 +++++++-------- .../pre-planning/minimal_spec_draft.md | 14 ++++---- .../pre-planning/spec_manifest.md | 36 +++++++++---------- .../compatibility-spec.md | 2 +- .../contract.md | 6 ++-- .../manual_testing_playbook.md | 10 +++--- .../platform-parity-spec.md | 24 ++++++------- .../policy-spec.md | 4 +-- .../pre-planning/impact_map.md | 16 ++++----- .../pre-planning/minimal_spec_draft.md | 18 +++++----- .../pre-planning/spec_manifest.md | 16 ++++----- .../pre-planning/workstream_triage.md | 4 +-- .../slices/LAITDP1/LAITDP1-spec.md | 4 +-- .../slices/LAITDP2/LAITDP2-spec.md | 2 +- .../telemetry-spec.md | 6 ++-- .../compatibility-spec.md | 6 ++-- .../contract.md | 14 ++++---- .../gateway-backend-adapter-protocol-spec.md | 4 +-- .../gateway-backend-adapter-schema-spec.md | 4 +-- .../governance/remediation-log.md | 20 +++++------ .../governance/seam-1-closeout.md | 4 +-- .../governance/seam-2-closeout.md | 4 +-- .../manual_testing_playbook.md | 8 ++--- .../platform-parity-spec.md | 14 ++++---- .../policy-spec.md | 6 ++-- .../pre-planning/impact_map.md | 6 ++-- .../pre-planning/minimal_spec_draft.md | 16 ++++----- .../pre-planning/spec_manifest.md | 24 ++++++------- .../scope_brief.md | 8 ++--- .../seam-1-adapter-selection-boundary.md | 14 ++++---- .../seam-2-adapter-protocol-and-schema.md | 10 +++--- .../seam-3-parity-and-validation.md | 12 +++---- .../seam_map.md | 2 +- .../review.md | 10 +++--- .../seam-1-adapter-selection-boundary/seam.md | 2 +- .../slice-00-c-01-c-02-contract-definition.md | 8 ++--- ...us-owner-line-and-adr-authority-cleanup.md | 8 ++--- .../slice-99-seam-exit-gate.md | 2 +- .../review.md | 4 +-- .../seam.md | 4 +-- .../slice-00-c-03-c-04-contract-definition.md | 8 ++--- ...ice-1-dispatch-lifecycle-and-owner-line.md | 2 +- ...subset-and-fail-closed-capability-rules.md | 2 +- .../slice-99-seam-exit-gate.md | 2 +- .../seam-3-parity-and-validation/review.md | 2 +- .../seam-3-parity-and-validation/seam.md | 4 +-- ...-1-platform-parity-and-runtime-boundary.md | 4 +-- .../threading.md | 8 ++--- .../governance/remediation-log.md | 2 +- .../governance/seam-1-closeout.md | 2 +- .../governance/seam-2-closeout.md | 6 ++-- .../governance/seam-3-closeout.md | 2 +- ...-operator-boundary-and-command-contract.md | 2 +- ...us-schema-and-policy-evaluation-surface.md | 4 +-- ...eam-3-typed-runtime-and-platform-parity.md | 10 +++--- ...seam-4-validation-and-cross-doc-lock-in.md | 8 ++--- .../seam.md | 4 +-- .../slice-00-operator-contract-definition.md | 2 +- .../slice-99-seam-exit-gate.md | 2 +- .../slice-99-seam-exit-gate.md | 4 +-- .../review.md | 2 +- .../seam.md | 4 +-- ...e-00-runtime-parity-contract-definition.md | 6 ++-- ...e-1-typed-lifecycle-status-api-boundary.md | 4 +-- ...onsumption-and-platform-parity-evidence.md | 4 +-- .../slice-99-seam-exit-gate.md | 2 +- ...nual-validation-and-owner-surface-audit.md | 8 ++--- ...ice-2-operator-docs-and-trace-alignment.md | 8 ++--- .../threading.md | 10 +++--- .../contract.md | 12 +++---- .../gateway-status-schema-spec.md | 2 +- .../manual_testing_playbook.md | 16 ++++----- .../platform-parity-spec.md | 8 ++--- .../policy-spec.md | 2 +- .../pre-planning/impact_map.md | 2 +- .../pre-planning/minimal_spec_draft.md | 2 +- .../pre-planning/spec_manifest.md | 2 +- ...4-secret-handoff-into-the-world-gateway.md | 8 ++--- .../27-uaa-boundary-and-naming-cleanup.md | 12 +++---- ...ulfillment-without-lifecycle-regression.md | 20 +++++------ llm-last-mile/ORCH_PLAN-14.md | 2 +- llm-last-mile/PLAN-14.md | 8 ++--- 134 files changed, 468 insertions(+), 448 deletions(-) create mode 100644 docs/contracts/README.md create mode 100644 docs/contracts/gateway/README.md rename docs/contracts/{substrate-gateway-backend-adapter-protocol.md => gateway/backend-adapter-protocol.md} (97%) rename docs/contracts/{substrate-gateway-backend-adapter-schema.md => gateway/backend-adapter-schema.md} (99%) rename docs/contracts/{substrate-gateway-backend-adapter-selection.md => gateway/backend-adapter-selection.md} (97%) rename docs/contracts/{substrate-gateway-operator-contract.md => gateway/operator-contract.md} (94%) rename docs/contracts/{substrate-gateway-policy-evaluation.md => gateway/policy-evaluation.md} (100%) rename docs/contracts/{substrate-gateway-runtime-parity.md => gateway/runtime-parity.md} (94%) rename docs/contracts/{substrate-gateway-status-schema.md => gateway/status-schema.md} (100%) diff --git a/docs/WORLD.md b/docs/WORLD.md index 4a014f4b8..581aad806 100644 --- a/docs/WORLD.md +++ b/docs/WORLD.md @@ -1,6 +1,6 @@ # Substrate World: Architecture, Behavior, and Operations (Linux & macOS) -This document describes the world execution model, transport topology, and validation evidence used by Substrate. It is descriptive context for `docs/contracts/substrate-gateway-runtime-parity.md`, `docs/contracts/substrate-gateway-operator-contract.md`, and `docs/contracts/substrate-gateway-status-schema.md`; it does not redefine those operator contracts. +This document describes the world execution model, transport topology, and validation evidence used by Substrate. It is descriptive context for `docs/contracts/gateway/runtime-parity.md`, `docs/contracts/gateway/operator-contract.md`, and `docs/contracts/gateway/status-schema.md`; it does not redefine those operator contracts. Status: Linux host-native and macOS Lima-backed worlds are the supported provisioning paths in this slice. Windows/WSL helper scripts are intentionally fail-closed until their placement contract matches the Linux-first runtime contract. diff --git a/docs/contracts/README.md b/docs/contracts/README.md new file mode 100644 index 000000000..e6cc80657 --- /dev/null +++ b/docs/contracts/README.md @@ -0,0 +1,7 @@ +# Contracts + +Stable contract documents live here, grouped by subsystem. + +## Subsystems + +- `gateway/`: Substrate gateway operator, status, policy, runtime, and backend-adapter contract surfaces. diff --git a/docs/contracts/gateway/README.md b/docs/contracts/gateway/README.md new file mode 100644 index 000000000..93253791e --- /dev/null +++ b/docs/contracts/gateway/README.md @@ -0,0 +1,13 @@ +# Gateway Contracts + +These documents are the stable contract surfaces for the Substrate gateway boundary. + +## Documents + +- `operator-contract.md`: operator command family, stable wiring exports, and exit taxonomy. +- `status-schema.md`: machine-readable `substrate world gateway status --json` surface. +- `policy-evaluation.md`: fail-closed policy evaluation and secret-sourcing boundary. +- `runtime-parity.md`: typed runtime lifecycle/status authority and platform parity guarantees. +- `backend-adapter-selection.md`: backend-id selection, allowlisting, and failure taxonomy before dispatch. +- `backend-adapter-protocol.md`: adapter dispatch lifecycle, validation order, and bounded handoff rules. +- `backend-adapter-schema.md`: adopted capability/extension subset and bounded request/event/completion schema. diff --git a/docs/contracts/substrate-gateway-backend-adapter-protocol.md b/docs/contracts/gateway/backend-adapter-protocol.md similarity index 97% rename from docs/contracts/substrate-gateway-backend-adapter-protocol.md rename to docs/contracts/gateway/backend-adapter-protocol.md index 6d2bdef41..e0a20ca5b 100644 --- a/docs/contracts/substrate-gateway-backend-adapter-protocol.md +++ b/docs/contracts/gateway/backend-adapter-protocol.md @@ -72,11 +72,11 @@ The local-to-external handoff is explicit: ## Boundaries - This contract does not redefine the stable backend-id grammar or allowlist order. That remains - owned by `docs/contracts/substrate-gateway-backend-adapter-selection.md`. + owned by `docs/contracts/gateway/backend-adapter-selection.md`. - This contract consumes the upstream invalid-selection, dependency-unavailable, and policy-denial buckets; adapter lookup must not reinterpret backend-id grammar or allowlist policy locally. - This contract does not widen the machine-readable status boundary. That remains owned by - `docs/contracts/substrate-gateway-status-schema.md`. + `docs/contracts/gateway/status-schema.md`. - This contract does not define provider-specific routing strategy, planner/executor role splits, raw SSE framing, or provider error payloads as public contract truth. - Repository topology is not part of the protocol contract. Moving the gateway into the Substrate diff --git a/docs/contracts/substrate-gateway-backend-adapter-schema.md b/docs/contracts/gateway/backend-adapter-schema.md similarity index 99% rename from docs/contracts/substrate-gateway-backend-adapter-schema.md rename to docs/contracts/gateway/backend-adapter-schema.md index deb977945..9baa9a23b 100644 --- a/docs/contracts/substrate-gateway-backend-adapter-schema.md +++ b/docs/contracts/gateway/backend-adapter-schema.md @@ -174,7 +174,7 @@ Rules: schema as long as the published policy precedence and bounded request validation rules stay unchanged. - This schema does not redefine machine-readable gateway status output. That remains owned by - `docs/contracts/substrate-gateway-status-schema.md`. + `docs/contracts/gateway/status-schema.md`. - This schema does not make backend-specific capability ids, provider quirks, or raw transport details part of the stable Substrate-facing contract. diff --git a/docs/contracts/substrate-gateway-backend-adapter-selection.md b/docs/contracts/gateway/backend-adapter-selection.md similarity index 97% rename from docs/contracts/substrate-gateway-backend-adapter-selection.md rename to docs/contracts/gateway/backend-adapter-selection.md index f7090e1f5..356d065ed 100644 --- a/docs/contracts/substrate-gateway-backend-adapter-selection.md +++ b/docs/contracts/gateway/backend-adapter-selection.md @@ -56,10 +56,10 @@ Concrete rules: ## Boundaries - This contract does not define `status --json` fields. That remains owned by - `docs/contracts/substrate-gateway-status-schema.md`. + `docs/contracts/gateway/status-schema.md`. - This contract does not define policy decision tables or trust-boundary mechanics beyond the published selection boundary. That remains owned by - `docs/contracts/substrate-gateway-policy-evaluation.md`. + `docs/contracts/gateway/policy-evaluation.md`. - This contract does not define adapter request/response payloads, capabilities, extension keys, session handles, event envelopes, or trace vocabulary. - This contract does not widen operator command ownership beyond the existing gateway command family. diff --git a/docs/contracts/substrate-gateway-operator-contract.md b/docs/contracts/gateway/operator-contract.md similarity index 94% rename from docs/contracts/substrate-gateway-operator-contract.md rename to docs/contracts/gateway/operator-contract.md index 8d3c24e28..ca6ae0db4 100644 --- a/docs/contracts/substrate-gateway-operator-contract.md +++ b/docs/contracts/gateway/operator-contract.md @@ -44,8 +44,8 @@ Ownership split: ## Boundaries -- This document does not define the `status --json` field list; that contract is owned by `docs/contracts/substrate-gateway-status-schema.md`. -- This document does not define policy decision tables or trust-boundary logic; that contract is owned by `docs/contracts/substrate-gateway-policy-evaluation.md`. +- This document does not define the `status --json` field list; that contract is owned by `docs/contracts/gateway/status-schema.md`. +- This document does not define policy decision tables or trust-boundary logic; that contract is owned by `docs/contracts/gateway/policy-evaluation.md`. - This document does not define runtime transport, endpoint shapes, or parity details. - The later-slice proof surfaces for this contract are: - `crates/shell/src/execution/cli.rs` diff --git a/docs/contracts/substrate-gateway-policy-evaluation.md b/docs/contracts/gateway/policy-evaluation.md similarity index 100% rename from docs/contracts/substrate-gateway-policy-evaluation.md rename to docs/contracts/gateway/policy-evaluation.md diff --git a/docs/contracts/substrate-gateway-runtime-parity.md b/docs/contracts/gateway/runtime-parity.md similarity index 94% rename from docs/contracts/substrate-gateway-runtime-parity.md rename to docs/contracts/gateway/runtime-parity.md index 82dc25a53..78e7c3f28 100644 --- a/docs/contracts/substrate-gateway-runtime-parity.md +++ b/docs/contracts/gateway/runtime-parity.md @@ -23,9 +23,9 @@ Concrete rules: - Prompt-bearing shell/world orchestration paths that consume integrated gateway bindings must enter the gateway-owned runtime seam (`crates/gateway/src/adapter_runtime.rs`) through their bridge layers, not through duplicated shell-local or world-local backend-registration tables. - Non-isolated gateway lifecycle/status flows must not depend on reusable session-world creation or recovery when no world-backed isolation is required for the gateway runtime. In that posture, the typed runtime surface may use a stable synthetic runtime identity derived from the effective lifecycle binding inputs. - Isolated gateway lifecycle/status flows must continue to require a real compatible world/session identity and any required world-backed attachment primitives. -- `substrate world gateway status --json` remains governed by `docs/contracts/substrate-gateway-status-schema.md`; this contract may not widen the JSON field list or redefine `client_wiring.*`. -- Policy placement, fail-closed routing, secret delivery, and trust-boundary rules remain governed by `docs/contracts/substrate-gateway-policy-evaluation.md`. -- The operator command family and exit taxonomy remain governed by `docs/contracts/substrate-gateway-operator-contract.md`, including exit `4` for the required gateway/world component unavailable posture. +- `substrate world gateway status --json` remains governed by `docs/contracts/gateway/status-schema.md`; this contract may not widen the JSON field list or redefine `client_wiring.*`. +- Policy placement, fail-closed routing, secret delivery, and trust-boundary rules remain governed by `docs/contracts/gateway/policy-evaluation.md`. +- The operator command family and exit taxonomy remain governed by `docs/contracts/gateway/operator-contract.md`, including exit `4` for the required gateway/world component unavailable posture. - Linux, macOS, and Windows must present one operator-facing lifecycle/status contract even when the underlying world transport differs. - This contract governs lifecycle/status semantics for whichever integrated backends the implementation and compatibility surfaces currently support; it does not itself promote a diff --git a/docs/contracts/substrate-gateway-status-schema.md b/docs/contracts/gateway/status-schema.md similarity index 100% rename from docs/contracts/substrate-gateway-status-schema.md rename to docs/contracts/gateway/status-schema.md diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/contract.md b/docs/project_management/_archived/next/llm_gateway_in_world/contract.md index f553dde01..38b7b7f23 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/contract.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/contract.md @@ -1,7 +1,7 @@ # contract — llm_gateway_in_world Historical evidence only. This document preserves the ADR-0023-era operator contract and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Historical inputs: - ADR: `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md b/docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md index 6adb016a5..0f4fbcf71 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md @@ -7,7 +7,7 @@ Standard: Scope: - Historical evidence only. This decision register supported `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` and does not define the current operator boundary. -- The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +- The live operator contract is `docs/contracts/gateway/operator-contract.md`. - Each decision is recorded as exactly two viable options (A/B) with explicit tradeoffs and a single selection. --- diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/impact_map.md b/docs/project_management/_archived/next/llm_gateway_in_world/impact_map.md index 22b387449..fa2f3881e 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/impact_map.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/impact_map.md @@ -1,7 +1,7 @@ # impact_map — llm_gateway_in_world Historical evidence only. This placeholder impact map preserves ADR-0023-era planning and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Primary components (anticipated): - `crates/world-agent` (supervision/transport to in-world gateway) diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/manual_testing_playbook.md b/docs/project_management/_archived/next/llm_gateway_in_world/manual_testing_playbook.md index 8a9a70039..a4eaf51f1 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/manual_testing_playbook.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/manual_testing_playbook.md @@ -1,7 +1,7 @@ # Manual testing playbook — llm_gateway_in_world Historical evidence only. This placeholder manual playbook preserves ADR-0023-era checks and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Intended checks (v1): - Fail-closed behavior when `llm.fail_closed.routing=true` and world is unavailable. diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/plan.md b/docs/project_management/_archived/next/llm_gateway_in_world/plan.md index 793b134c8..249a6285c 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/plan.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/plan.md @@ -1,7 +1,7 @@ # plan — llm_gateway_in_world Historical evidence only. This plan captures ADR-0023-era implementation intent and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Goal: Make ADR-0023 execution-ready by defining the minimal, explicit contracts required to implement an in-world LLM gateway without reshaping config/policy surfaces beyond ADR-0027. diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md b/docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md index bd7c02515..2073d3a1b 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md @@ -1,7 +1,7 @@ # spec_manifest — llm_gateway_in_world Historical evidence only. This is a lightweight placeholder manifest for ADR-0023 planning outputs and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Required (v1): - `contract.md` (operator-facing) diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/specs/env_injection.md b/docs/project_management/_archived/next/llm_gateway_in_world/specs/env_injection.md index 5b458d471..9992d3815 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/specs/env_injection.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/specs/env_injection.md @@ -1,7 +1,7 @@ # spec — llm_gateway_in_world: secret delivery (v1 legacy env injection + v1.1 FD/pipe auth bundle) Historical evidence only. This spec preserves ADR-0023-era secret delivery planning and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Phase 8 additive upgrade: v1.1 introduces a preferred secret-channel payload + in-world FD/pipe delivery path so secret values do not live in in-world process environments by default (see DR-0018). diff --git a/docs/project_management/_archived/next/llm_gateway_in_world/specs/http_surface.md b/docs/project_management/_archived/next/llm_gateway_in_world/specs/http_surface.md index e2d1cdebd..4e20faa49 100644 --- a/docs/project_management/_archived/next/llm_gateway_in_world/specs/http_surface.md +++ b/docs/project_management/_archived/next/llm_gateway_in_world/specs/http_surface.md @@ -1,7 +1,7 @@ # spec — llm_gateway_in_world: HTTP surface (subset) Historical evidence only. This spec preserves ADR-0023-era HTTP surface planning and does not define the current operator boundary. -The live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. +The live operator contract is `docs/contracts/gateway/operator-contract.md`. Historical ADR: `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` diff --git a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md index 3a604281a..13f83d051 100644 --- a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md +++ b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md @@ -19,9 +19,9 @@ - LLM + agent config/policy surface: `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - Gateway boundary and runtime ownership: `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - Gateway backend adapter contract: `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` -- Gateway operator contract: `docs/contracts/substrate-gateway-operator-contract.md` -- Gateway policy evaluation contract: `docs/contracts/substrate-gateway-policy-evaluation.md` -- Gateway runtime and platform parity contract: `docs/contracts/substrate-gateway-runtime-parity.md` +- Gateway operator contract: `docs/contracts/gateway/operator-contract.md` +- Gateway policy evaluation contract: `docs/contracts/gateway/policy-evaluation.md` +- Gateway runtime and platform parity contract: `docs/contracts/gateway/runtime-parity.md` - Phase 8 cross-cutting secret/auth registry: `docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` ## Executive Summary (Operator) diff --git a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md index 3e352330c..d7363e97e 100644 --- a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md @@ -17,7 +17,7 @@ This ADR is a successor to ADR-0023 and should be read as an ownership clarification, not a rewrite of the underlying gateway capability. The committed operator contract that downstream slices should treat as live source of truth is -`docs/contracts/substrate-gateway-operator-contract.md`. +`docs/contracts/gateway/operator-contract.md`. - Superseded intent: - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` @@ -26,7 +26,7 @@ The committed operator contract that downstream slices should treat as live sour - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - Committed operator contract: - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` - Foundational output/routing and trace contracts: - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` diff --git a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md index b0c5ed446..cdbe406ff 100644 --- a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md +++ b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md @@ -23,11 +23,11 @@ This ADR is a thin implementation follow-on to ADR-0041. It keeps the ADR-0041 b - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - Existing contract docs this ADR realizes: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` - Explicitly deferred follow-ons: - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md index 51883f621..388387875 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md @@ -11,7 +11,7 @@ This pack is documentation-driven. Validation is a deterministic contract and wo - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/compatibility-spec.md` - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `crates/broker/src/tests.rs` - `crates/shell/src/builtins/world_gateway.rs` - `crates/shell/tests/world_gateway.rs` diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md index 0cdfe1a6e..55d2e4d3a 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md @@ -19,7 +19,7 @@ Canonical references: - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/contract.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tuple-policy-schema-spec.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/decision_register.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md index 97be4b1da..0efb0b2b3 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md @@ -51,7 +51,7 @@ Strict packs (`tasks.json` → `meta.slice_spec_version >= 2`) requirements: - `docs/CONFIGURATION.md` - `docs/USAGE.md` - `docs/TRACE.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/README.md` - `crates/shell/src/execution/policy_cmd.rs` diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-spec.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-spec.md index 45852e185..81667a34d 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-spec.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-spec.md @@ -18,7 +18,7 @@ - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/spec_manifest.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/workstream_triage.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-spec.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-spec.md index ca24c9902..14bec9b65 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-spec.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-spec.md @@ -23,7 +23,7 @@ - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/workstream_triage.md` - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` -- `docs/contracts/substrate-gateway-status-schema.md` +- `docs/contracts/gateway/status-schema.md` - `docs/TRACE.md` ## Behavior (authoritative) diff --git a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/telemetry-spec.md b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/telemetry-spec.md index 92bb5eeed..eb489e9b3 100644 --- a/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/telemetry-spec.md +++ b/docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/telemetry-spec.md @@ -16,7 +16,7 @@ Canonical references: - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/compatibility-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` -- `docs/contracts/substrate-gateway-status-schema.md` +- `docs/contracts/gateway/status-schema.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/TRACE.md` diff --git a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/policy-spec.md b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/policy-spec.md index 97005409a..38ea8ce18 100644 --- a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/policy-spec.md +++ b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/policy-spec.md @@ -18,7 +18,7 @@ Canonical references: - `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/agent-hub-session-protocol-spec.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` @@ -99,7 +99,7 @@ Agent-hub control-plane policy evaluation follows this fixed order: - when drift is absent, reuse the current shared world - when drift is present and `agents.hub.world_restart.on_drift = auto_restart`, restart is permitted and replacement handles must be allocated before more work is dispatched - when drift is present and `agents.hub.world_restart.on_drift = fail_closed`, the control plane denies further world-scoped work until an explicit restart path succeeds -12. If an agent explicitly triggers nested LLM work, stop agent-hub control-plane evaluation and hand the nested request to the gateway policy surface governed by ADR-0043 and `docs/contracts/substrate-gateway-policy-evaluation.md`. +12. If an agent explicitly triggers nested LLM work, stop agent-hub control-plane evaluation and hand the nested request to the gateway policy surface governed by ADR-0043 and `docs/contracts/gateway/policy-evaluation.md`. ## Deny taxonomy diff --git a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/impact_map.md b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/impact_map.md index 2578b7d69..0a78032eb 100644 --- a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/impact_map.md @@ -26,7 +26,7 @@ Authoring standards: - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/policy-evaluation.md` ## Touch set (explicit) @@ -66,7 +66,7 @@ Strict packs (`tasks.json` → `meta.slice_spec_version >= 2`) requirements: - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/CONFIGURATION.md` - `docs/USAGE.md` - `docs/TRACE.md` diff --git a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/spec_manifest.md b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/spec_manifest.md index 34aa26920..3b8ba3d9d 100644 --- a/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/spec_manifest.md +++ b/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/spec_manifest.md @@ -22,13 +22,13 @@ Authoring standards: - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/status-schema.md` ## Slice IDs (canonical) diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md index 8da1c6d14..19c3165f7 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md @@ -23,7 +23,7 @@ Not owned here: ## Compatibility posture -- Existing operator workflows remain compatible with `docs/contracts/substrate-gateway-runtime-parity.md`. +- Existing operator workflows remain compatible with `docs/contracts/gateway/runtime-parity.md`. - `cli:codex` remains the regression floor. - `api:openai` is the first additional backend proof target reflected in rollout framing. - Unsupported integrated backends are explicit negative cases and do not silently fall back to `cli:codex`. @@ -35,7 +35,7 @@ This document consumes, but does not redefine, the following upstream evidence: - automated parity evidence from the runtime and shell test suites - platform validation evidence from the Linux, macOS, and Windows proof surfaces -- the canonical runtime-parity contract in `docs/contracts/substrate-gateway-runtime-parity.md` +- the canonical runtime-parity contract in `docs/contracts/gateway/runtime-parity.md` ## Invariants diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/remediation-log.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/remediation-log.md index 13cf438b7..11a77f605 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/remediation-log.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/remediation-log.md @@ -42,7 +42,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S00 related_thread: THR-01 related_contract: C-02 - related_artifact: docs/contracts/substrate-gateway-policy-evaluation.md + related_artifact: docs/contracts/gateway/policy-evaluation.md severity: medium status: resolved owner_seam: SEAM-1 @@ -63,7 +63,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S00 related_thread: THR-01 related_contract: C-01 - related_artifact: docs/contracts/substrate-gateway-backend-adapter-selection.md + related_artifact: docs/contracts/gateway/backend-adapter-selection.md severity: medium status: resolved owner_seam: SEAM-1 @@ -84,7 +84,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S01 related_thread: THR-02 related_contract: C-03 - related_artifact: docs/contracts/substrate-gateway-backend-adapter-protocol.md + related_artifact: docs/contracts/gateway/backend-adapter-protocol.md severity: medium status: resolved owner_seam: SEAM-2 @@ -104,7 +104,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S01 related_thread: THR-02 related_contract: C-04 - related_artifact: docs/contracts/substrate-gateway-backend-adapter-schema.md + related_artifact: docs/contracts/gateway/backend-adapter-schema.md severity: medium status: resolved owner_seam: SEAM-2 @@ -125,7 +125,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S01 related_thread: THR-03 related_contract: C-05 - related_artifact: docs/contracts/substrate-gateway-runtime-parity.md + related_artifact: docs/contracts/gateway/runtime-parity.md severity: medium status: resolved owner_seam: SEAM-3 @@ -151,7 +151,7 @@ Future remediation entries must use the canonical fields from the extractor gove related_slice: S00 related_thread: THR-02 related_contract: C-04 - related_artifact: docs/contracts/substrate-gateway-policy-evaluation.md + related_artifact: docs/contracts/gateway/policy-evaluation.md severity: none status: retired owner_seam: SEAM-2 @@ -159,5 +159,5 @@ Future remediation entries must use the canonical fields from the extractor gove summary: auth-source precedence is already fixed while carrier choice is explicitly deferred by the policy contract, so choosing env-only, file-only, or a stronger secret-channel carrier is not a current pack blocker required_fix: none inside the current execution target resolution_evidence: - - docs/contracts/substrate-gateway-policy-evaluation.md states that auth-source precedence governs handoff content while carrier choice remains separate and current env delivery remains compatible + - docs/contracts/gateway/policy-evaluation.md states that auth-source precedence governs handoff content while carrier choice remains separate and current env delivery remains compatible ``` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-2-closeout.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-2-closeout.md index 68a5373f2..c326e99ad 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-2-closeout.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-2-closeout.md @@ -34,8 +34,8 @@ unsupported and unbound backends explicit with no fallback. - **Source artifact**: `../threaded-seams/seam-2-runtime-realization-and-artifacts/slice-99-seam-exit-gate.md` - **Landed evidence**: - canonical contract truth remains the primary baseline for `C-03` and `C-04`: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - landed runtime and shell evidence on the current tree: - `crates/transport-api-types/src/lib.rs` now defines a closed backend-neutral `api_env` auth facet beside `cli_codex`, hardens `GatewayLifecycleRequestV1` with `deny_unknown_fields`, and validates backend/facet coherence before runtime execution. - `crates/world-service/src/service.rs` now uses the shared request/auth validator, preserves selected-backend continuity, and exposes the Linux-only runtime inspection helpers that the parity suite exercises as a real integration test. diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-3-closeout.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-3-closeout.md index 711a270fd..25b0b7420 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-3-closeout.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-3-closeout.md @@ -36,7 +36,7 @@ unsupported-backend behavior remaining explicit and no-fallback. - **Source artifact**: `../threaded-seams/seam-3-parity-validation-and-rollout/slice-99-seam-exit-gate.md` - **Landed evidence**: - canonical contract baseline: - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - landed automated parity evidence: - `crates/world-service/tests/gateway_runtime_parity.rs` - `gateway_openai_sync_makes_status_available_and_is_idempotent` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md index 08c64d1bc..e95f07c14 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md @@ -22,7 +22,7 @@ Not owned here: The evidence surfaces in this slice consume, rather than redefine: -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/runtime-parity.md` - the automated parity matrix established in slice 1 That upstream proof already covers the `cli:codex` regression floor and the landed `api:openai` parity path. diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/scope_brief.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/scope_brief.md index 477841d43..b2a907f95 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/scope_brief.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/scope_brief.md @@ -51,13 +51,13 @@ execution_horizon: - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` + - `docs/contracts/gateway/status-schema.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `crates/shell/src/builtins/world_gateway.rs` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-1-backend-selection-and-policy-surface.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-1-backend-selection-and-policy-surface.md index 9604badca..44eeec8bd 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-1-backend-selection-and-policy-surface.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-1-backend-selection-and-policy-surface.md @@ -52,8 +52,8 @@ open_remediations: [] - **Primary interfaces** - Inputs: - ADR-0046 goals and non-goals - - canonical `C-01` in `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - canonical `C-02` in `docs/contracts/substrate-gateway-policy-evaluation.md` + - canonical `C-01` in `docs/contracts/gateway/backend-adapter-selection.md` + - canonical `C-02` in `docs/contracts/gateway/policy-evaluation.md` - shell request construction and validation in `crates/shell/src/builtins/world_gateway.rs` - shell lifecycle tests in `crates/shell/tests/world_gateway.rs` - Outputs: @@ -82,8 +82,8 @@ open_remediations: [] - **Touch surface**: - `crates/shell/src/builtins/world_gateway.rs` - `crates/shell/tests/world_gateway.rs` - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` - future subordinate ADR-0046 support docs under `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/`, if created later - **Verification**: - `C-01` and `C-02` are already published; this seam verifies shell adoption, not fresh contract publication. @@ -99,8 +99,8 @@ open_remediations: [] - `crates/shell/tests/world_gateway.rs` proves the distinction between invalid integration, policy denial, component unavailable, and transient runtime failure where the shell owns that distinction - any later subordinate ADR-0046 support docs remain descriptive implementation notes and do not compete with canonical `docs/contracts/` ownership - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Risks / unknowns**: - Risk: - current shell behavior still special-cases `cli:codex` and does not yet realize generic inventory-backed backend validation diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-2-runtime-realization-and-artifacts.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-2-runtime-realization-and-artifacts.md index 25b177608..16db3be7a 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-2-runtime-realization-and-artifacts.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-2-runtime-realization-and-artifacts.md @@ -57,8 +57,8 @@ open_remediations: [] - Inputs: - `C-01` - `C-02` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - current world-service runtime manager behavior in `crates/world-service/src/gateway_runtime.rs` - current shell-side integrated auth construction in `crates/shell/src/builtins/world_gateway.rs` - current lifecycle request shape in `crates/transport-api-types/src/lib.rs` @@ -70,7 +70,7 @@ open_remediations: [] - **Key invariants / rules**: - one selected backend resolves to one integrated adapter binding - capability gating, auth validation, config render, launch, and readiness must have one fixed order - - auth precedence is already owned by `docs/contracts/substrate-gateway-policy-evaluation.md`: complete allowlisted env auth is primary, host credential files are fallback-only when env auth is absent, and partial env auth fails closed + - auth precedence is already owned by `docs/contracts/gateway/policy-evaluation.md`: complete allowlisted env auth is primary, host credential files are fallback-only when env auth is absent, and partial env auth fails closed - current env-compatible delivery remains acceptable for this seam; execution must not block on a secret-channel redesign - runtime artifact semantics must be explicit implementation behavior rather than side effects of the current Codex-specific launch path - this seam must consume, not redefine, `SEAM-1` selection/policy truth @@ -93,13 +93,13 @@ open_remediations: [] - `crates/world-service/src/gateway_runtime.rs` - `crates/world-service/src/service.rs` - `crates/transport-api-types/src/lib.rs` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - **Verification**: - This seam consumes canonical contracts `C-01`, `C-02`, `C-03`, and `C-04`. The repo already has durable contract truth for adapter lookup ordering, capability/error taxonomy, and auth-source precedence; this seam should execute against that truth instead of reopening it. - Current pre-exec gate posture is: - `review: passed` because seam-local execution planning and review now live under `threaded-seams/seam-2-runtime-realization-and-artifacts/`. - - `contract: passed` because `docs/contracts/substrate-gateway-backend-adapter-protocol.md`, `docs/contracts/substrate-gateway-backend-adapter-schema.md`, and `docs/contracts/substrate-gateway-policy-evaluation.md` already cover lookup order, capability gating, bounded error kinds, and env-primary/file-fallback auth precedence. + - `contract: passed` because `docs/contracts/gateway/backend-adapter-protocol.md`, `docs/contracts/gateway/backend-adapter-schema.md`, and `docs/contracts/gateway/policy-evaluation.md` already cover lookup order, capability gating, bounded error kinds, and env-primary/file-fallback auth precedence. - `revalidation: passed` because `SEAM-1` published `THR-01`, the new seam-local review rechecked the active basis against that closeout, and current repo evidence still shows the exact Codex-only runtime gaps this seam is planned to land. - Later seam-local verification should prove: - selected non-Codex backends no longer disappear behind the current `cli:codex` checks in `crates/shell/src/builtins/world_gateway.rs` and `crates/world-service/src/gateway_runtime.rs` @@ -109,10 +109,10 @@ open_remediations: [] - managed artifacts have fixed roots, names, permissions, and inspectability rules - restart preserves the selected backend contract instead of re-deriving behavior ad hoc - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - **Risks / unknowns**: - Risk: - the current request and runtime types only expose `cli_codex`, so widening the integrated path can accidentally entrench one-off variants instead of one adapter-owned shape diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-3-parity-validation-and-rollout.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-3-parity-validation-and-rollout.md index 894a4b745..1462b5bb9 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-3-parity-validation-and-rollout.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-3-parity-validation-and-rollout.md @@ -60,7 +60,7 @@ open_remediations: [] - `C-02` - `C-03` - `C-04` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - current parity tests in `crates/world-service/tests/gateway_runtime_parity.rs` - current shell command-path tests in `crates/shell/tests/world_gateway.rs` - Outputs: @@ -97,10 +97,10 @@ open_remediations: [] - `crates/world-service/tests/gateway_runtime_parity.rs` - `crates/shell/tests/world_gateway.rs` - **Verification**: - - This seam consumes upstream contracts `C-01`, `C-02`, `C-03`, and `C-04` plus the existing lifecycle/status parity contract in `docs/contracts/substrate-gateway-runtime-parity.md`. + - This seam consumes upstream contracts `C-01`, `C-02`, `C-03`, and `C-04` plus the existing lifecycle/status parity contract in `docs/contracts/gateway/runtime-parity.md`. - Current pre-exec gate posture is: - `review: passed` because seam-local proof planning, falsification questions, and the parity/rollout review bundle now exist under `threaded-seams/seam-3-parity-validation-and-rollout/`. - - `contract: passed` because the operator/runtime parity surface is already owned by `docs/contracts/substrate-gateway-runtime-parity.md`, and unsupported-backend/no-fallback behavior is already implied by the existing selection/runtime contracts. This seam should validate those truths in code and smoke evidence rather than wait for a new compatibility contract. + - `contract: passed` because the operator/runtime parity surface is already owned by `docs/contracts/gateway/runtime-parity.md`, and unsupported-backend/no-fallback behavior is already implied by the existing selection/runtime contracts. This seam should validate those truths in code and smoke evidence rather than wait for a new compatibility contract. - `revalidation: passed` because `governance/seam-2-closeout.md` publishes `THR-02`, names `api:openai` as the first landed non-Codex proof target, and the live runtime/test surfaces still expose `api_env`, `api:openai`, and explicit unsupported-backend behavior exactly where this seam expects to verify them. - Later seam-local verification should prove: - `cli:codex` remains non-regressed @@ -109,11 +109,11 @@ open_remediations: [] - rollout posture does not rely on widened status or tuple surfaces - smoke/manual evidence matches the existing operator/runtime parity contracts rather than an invented seam-local compatibility taxonomy - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/runtime-parity.md` - **Risks / unknowns**: - Risk: - parity work can overfit to one `api:openai` proof path and stop exercising the explicit unsupported-backend posture that must remain visible diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam_map.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam_map.md index 47d16c3f5..cb96a810e 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam_map.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam_map.md @@ -4,9 +4,9 @@ ADR-0046 and the pre-planning pack already imply a three-part implementation spi | Seam | Horizon | Type | Core value | Direct blockers | Main touch surface | Source-pack anchors | | --- | --- | --- | --- | --- | --- | --- | -| `SEAM-1` | `landed` | `integration` | Finish the narrow selection/policy contract alignment that is still needed in-repo, then land consumer alignment and proof so one selected backend id flows through config, policy, inventory, and auth precedence without Codex-specific shortcuts. | none; `THR-01` is published and revalidated by the active seam | Canonical refs: `docs/contracts/substrate-gateway-backend-adapter-selection.md`, `docs/contracts/substrate-gateway-policy-evaluation.md`; implementation surfaces: `crates/shell/src/execution/config_model.rs`, `crates/shell/src/execution/policy_model.rs`, `crates/broker/src/policy.rs`, `crates/shell/src/builtins/world_gateway.rs` | ADR-0046, `pre-planning/spec_manifest.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-01` | -| `SEAM-2` | `landed` | `integration` | Realize one adapter-driven integrated runtime from the upstream handoff: binding lookup, capability gating, auth handoff validation, config rendering, managed artifacts, launch, readiness, and restart behavior. | none; `THR-01` was revalidated and `THR-02` is now published in closeout | Canonical refs: `docs/contracts/substrate-gateway-backend-adapter-protocol.md`, `docs/contracts/substrate-gateway-backend-adapter-schema.md`, `docs/contracts/substrate-gateway-runtime-parity.md`; implementation surfaces: `crates/world-service/src/gateway_runtime.rs`, `crates/world-service/src/service.rs`, `crates/transport-api-types/src/lib.rs`, `crates/shell/src/builtins/world_gateway.rs` | ADR-0046, `pre-planning/spec_manifest.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-02` | -| `SEAM-3` | `active / exec-ready` | `conformance` | Prove parity, validation, and rollout behavior from the revalidated runtime handoff: `cli:codex` regression floor, explicit unsupported-backend behavior, and the named `api:openai` proof target across Linux/macOS/Windows. | none inside the pack; consumes the revalidated `THR-02` handoff from `SEAM-2` | Canonical ref: `docs/contracts/substrate-gateway-runtime-parity.md`; supporting execution surfaces: `platform-parity-spec.md`, `compatibility-spec.md`, `manual_testing_playbook.md`; evidence: smoke scripts, `crates/world-service/tests/gateway_runtime_parity.rs`, `crates/shell/tests/world_gateway.rs` | ADR-0046, `pre-planning/impact_map.md`, `pre-planning/ci_checkpoint_plan.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-03` | +| `SEAM-1` | `landed` | `integration` | Finish the narrow selection/policy contract alignment that is still needed in-repo, then land consumer alignment and proof so one selected backend id flows through config, policy, inventory, and auth precedence without Codex-specific shortcuts. | none; `THR-01` is published and revalidated by the active seam | Canonical refs: `docs/contracts/gateway/backend-adapter-selection.md`, `docs/contracts/gateway/policy-evaluation.md`; implementation surfaces: `crates/shell/src/execution/config_model.rs`, `crates/shell/src/execution/policy_model.rs`, `crates/broker/src/policy.rs`, `crates/shell/src/builtins/world_gateway.rs` | ADR-0046, `pre-planning/spec_manifest.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-01` | +| `SEAM-2` | `landed` | `integration` | Realize one adapter-driven integrated runtime from the upstream handoff: binding lookup, capability gating, auth handoff validation, config rendering, managed artifacts, launch, readiness, and restart behavior. | none; `THR-01` was revalidated and `THR-02` is now published in closeout | Canonical refs: `docs/contracts/gateway/backend-adapter-protocol.md`, `docs/contracts/gateway/backend-adapter-schema.md`, `docs/contracts/gateway/runtime-parity.md`; implementation surfaces: `crates/world-service/src/gateway_runtime.rs`, `crates/world-service/src/service.rs`, `crates/transport-api-types/src/lib.rs`, `crates/shell/src/builtins/world_gateway.rs` | ADR-0046, `pre-planning/spec_manifest.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-02` | +| `SEAM-3` | `active / exec-ready` | `conformance` | Prove parity, validation, and rollout behavior from the revalidated runtime handoff: `cli:codex` regression floor, explicit unsupported-backend behavior, and the named `api:openai` proof target across Linux/macOS/Windows. | none inside the pack; consumes the revalidated `THR-02` handoff from `SEAM-2` | Canonical ref: `docs/contracts/gateway/runtime-parity.md`; supporting execution surfaces: `platform-parity-spec.md`, `compatibility-spec.md`, `manual_testing_playbook.md`; evidence: smoke scripts, `crates/world-service/tests/gateway_runtime_parity.rs`, `crates/shell/tests/world_gateway.rs` | ADR-0046, `pre-planning/impact_map.md`, `pre-planning/ci_checkpoint_plan.md`, `pre-planning/workstream_triage.md` lineage `GBSRI-03` | Why this split is the right seam map: diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/review.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/review.md index 1c3feb3dd..344781fa2 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/review.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/review.md @@ -43,8 +43,8 @@ flowchart TB ## Likely mismatch hotspots -- `docs/contracts/substrate-gateway-backend-adapter-selection.md` already publishes inventory roots, filename/id invariants, and selection order, and the landed shell evidence for that rule is now split across `world_gateway_missing_inventory_uses_exit_code_2_before_socket_dispatch`, `world_gateway_inventory_filename_id_mismatch_uses_exit_code_2`, and `world_gateway_allowlist_denial_uses_exit_code_5`. -- `docs/contracts/substrate-gateway-policy-evaluation.md` already publishes env-primary precedence, and the landed shell evidence for that rule is now split across `world_gateway_sync_builds_integrated_auth_payload_from_host_auth_file`, `world_gateway_status_prefers_allowed_env_auth_over_host_auth_file`, `world_gateway_status_builds_integrated_auth_payload_from_allowed_env_override`, `world_gateway_host_credential_policy_denials_use_exit_code_5`, and `world_gateway_incomplete_env_override_uses_exit_code_2`. +- `docs/contracts/gateway/backend-adapter-selection.md` already publishes inventory roots, filename/id invariants, and selection order, and the landed shell evidence for that rule is now split across `world_gateway_missing_inventory_uses_exit_code_2_before_socket_dispatch`, `world_gateway_inventory_filename_id_mismatch_uses_exit_code_2`, and `world_gateway_allowlist_denial_uses_exit_code_5`. +- `docs/contracts/gateway/policy-evaluation.md` already publishes env-primary precedence, and the landed shell evidence for that rule is now split across `world_gateway_sync_builds_integrated_auth_payload_from_host_auth_file`, `world_gateway_status_prefers_allowed_env_auth_over_host_auth_file`, `world_gateway_status_builds_integrated_auth_payload_from_allowed_env_override`, `world_gateway_host_credential_policy_denials_use_exit_code_5`, and `world_gateway_incomplete_env_override_uses_exit_code_2`. - `crates/shell/src/builtins/world_gateway.rs` now proves inventory-backed shell validation at the boundary, and any remaining runtime-owned cases are limited to adapter binding, capability, or availability questions outside this seam. - Any future ADR-0046 support docs under `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/` must remain subordinate implementation notes, not current canonical surfaces. diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/seam.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/seam.md index 80db7c203..46ed5dcd1 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/seam.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/seam.md @@ -53,8 +53,8 @@ open_remediations: [] - **Touch surface**: - `crates/shell/src/builtins/world_gateway.rs` - `crates/shell/tests/world_gateway.rs` - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` - any future ADR-0046 support docs created under `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/`, which must remain subordinate to canonical `docs/contracts/` truth - **Verification**: - This seam **consumes** published `C-01` and `C-02` and turns them into shell behavior plus evidence. @@ -65,8 +65,8 @@ open_remediations: [] - `resolve_integrated_auth_payload` plus `resolve_cli_codex_integrated_auth` enforce env-primary/file-fallback/no-mixed-source auth precedence - shell-side tests prove the distinction between invalid integration, policy denial, transient runtime failure, and component unavailable where the shell owns that classification - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Basis posture**: - Currentness: - `current` because `SEAM-1` has no inbound closeout dependency and the seam plan still matches the latest extracted pack state plus the current shell implementation evidence. @@ -88,8 +88,8 @@ open_remediations: [] - Contracts consumed: - no pack-owned consumed contracts; ADR-0040, ADR-0041, and existing config-policy docs are basis authorities only - Canonical contract refs: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` ## Review bundle diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-00-c-01-c-02-contract-definition.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-00-c-01-c-02-contract-definition.md index 83189c1a3..d332627a9 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-00-c-01-c-02-contract-definition.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-00-c-01-c-02-contract-definition.md @@ -43,7 +43,7 @@ open_remediations: - **Dependencies**: - none inbound; this is the first producer seam in the pack - **Verification**: - - compare the seam plan against `docs/contracts/substrate-gateway-backend-adapter-selection.md`, `docs/contracts/substrate-gateway-policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, and `crates/shell/tests/world_gateway.rs` + - compare the seam plan against `docs/contracts/gateway/backend-adapter-selection.md`, `docs/contracts/gateway/policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, and `crates/shell/tests/world_gateway.rs` - treat the missing non-fse ADR-0046 support-doc files as future subordinate material, not as current evidence required to validate the baseline - **Rollout/safety**: - preserves fail-closed behavior by preventing the seam from broadening scope into runtime ownership @@ -56,7 +56,7 @@ open_remediations: - **Outcome**: - The seam records that `C-01` already fixes selection order, inventory roots, and filename/id invariants, and that SEAM-1 now only needs shell-side adoption and tests. - **Inputs/outputs**: - - Inputs: `../../threading.md`, `docs/contracts/substrate-gateway-backend-adapter-selection.md`, `crates/shell/src/builtins/world_gateway.rs` + - Inputs: `../../threading.md`, `docs/contracts/gateway/backend-adapter-selection.md`, `crates/shell/src/builtins/world_gateway.rs` - Outputs: a narrowed SEAM-1 implementation plan and explicit code/test ownership - **Thread/contract refs**: - `THR-01` @@ -88,7 +88,7 @@ Checklist: - **Outcome**: - The seam records that `C-02` already fixes precedence and fail-closed posture, and that SEAM-1 now owns adoption plus evidence. - **Inputs/outputs**: - - Inputs: `../../threading.md`, `docs/contracts/substrate-gateway-policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, `crates/shell/tests/world_gateway.rs` + - Inputs: `../../threading.md`, `docs/contracts/gateway/policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, `crates/shell/tests/world_gateway.rs` - Outputs: a narrowed SEAM-1 plan for precedence/fail-closed adoption and tests - **Thread/contract refs**: - `THR-01` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-1-selection-order-and-inventory-truth.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-1-selection-order-and-inventory-truth.md index 423946434..76db583d0 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-1-selection-order-and-inventory-truth.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-1-selection-order-and-inventory-truth.md @@ -55,7 +55,7 @@ open_remediations: - **Outcome**: - `crates/shell/src/builtins/world_gateway.rs` uses the same ordered decision path as `C-01` from selected backend id through allowlist enforcement before runtime dispatch. - **Inputs/outputs**: - - Inputs: `S00`, `docs/contracts/substrate-gateway-backend-adapter-selection.md`, `crates/shell/src/builtins/world_gateway.rs` + - Inputs: `S00`, `docs/contracts/gateway/backend-adapter-selection.md`, `crates/shell/src/builtins/world_gateway.rs` - Outputs: aligned shell selection flow, targeted test updates, and supporting ADR-0046 doc notes - **Thread/contract refs**: - `THR-01` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-2-policy-precedence-and-fail-closed-boundary.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-2-policy-precedence-and-fail-closed-boundary.md index b82bd95b3..deffaa42e 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-2-policy-precedence-and-fail-closed-boundary.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-2-policy-precedence-and-fail-closed-boundary.md @@ -55,7 +55,7 @@ open_remediations: - **Outcome**: - shell auth-resolution logic and tests match the published precedence rule exactly. - **Inputs/outputs**: - - Inputs: `docs/contracts/substrate-gateway-policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, supporting ADR-0046 policy/env-var docs + - Inputs: `docs/contracts/gateway/policy-evaluation.md`, `crates/shell/src/builtins/world_gateway.rs`, supporting ADR-0046 policy/env-var docs - Outputs: aligned policy text and shell-side auth-source handling - **Thread/contract refs**: - `THR-01` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/review.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/review.md index 1896717d1..835c98124 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/review.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/review.md @@ -48,7 +48,7 @@ flowchart TB - `crates/shell/src/builtins/world_gateway.rs` now validates backend selection pre-dispatch, but request construction still emits `GatewayIntegratedAuthPayloadV1 { cli_codex: ... }`, so the active seam must widen the runtime-owned payload shape without reintroducing shell-owned selection logic. - `crates/world-service/src/service.rs` currently narrows `integrated_auth` to `payload.cli_codex.clone()` inside request preparation, which makes the world-service behave as if only one integrated backend can exist. - `crates/world-service/src/gateway_runtime.rs` still hard-rejects any default backend other than `cli:codex` and resolves auth handoff only through the Codex-specific path, so adapter lookup and capability gating are not yet implemented as the protocol contract requires. -- `docs/contracts/substrate-gateway-backend-adapter-protocol.md` and `docs/contracts/substrate-gateway-backend-adapter-schema.md` already publish the owned contract baseline for this seam, so the remaining work is landing behavior and tests, not inventing a new contract phase. +- `docs/contracts/gateway/backend-adapter-protocol.md` and `docs/contracts/gateway/backend-adapter-schema.md` already publish the owned contract baseline for this seam, so the remaining work is landing behavior and tests, not inventing a new contract phase. ## Pre-exec findings diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/seam.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/seam.md index 937f8b443..31a3bcea6 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/seam.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/seam.md @@ -64,8 +64,8 @@ open_remediations: [] - **Verification**: - This seam **consumes** published `C-01` and `C-02` from `THR-01`. - This seam **owns and realizes** `C-03` and `C-04`, whose canonical baselines already exist under: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - Readiness means execution may start without inventing new upstream contract truth: - selected backend id already arrives from shell as a fixed input - auth precedence is already pinned by canonical policy docs @@ -97,10 +97,10 @@ open_remediations: [] - `C-01` - `C-02` - Canonical contract refs: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` ## Review bundle diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-1-binding-lookup-and-capability-gates.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-1-binding-lookup-and-capability-gates.md index b3e032fba..7b659ab65 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-1-binding-lookup-and-capability-gates.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-1-binding-lookup-and-capability-gates.md @@ -57,7 +57,7 @@ open_remediations: - **Outcome**: - runtime request preparation and binding resolution consume the selected backend id directly rather than treating `cli:codex` as the only integrated binding. - **Inputs/outputs**: - - Inputs: `THR-01`, `docs/contracts/substrate-gateway-backend-adapter-protocol.md`, `crates/world-service/src/service.rs`, `crates/world-service/src/gateway_runtime.rs` + - Inputs: `THR-01`, `docs/contracts/gateway/backend-adapter-protocol.md`, `crates/world-service/src/service.rs`, `crates/world-service/src/gateway_runtime.rs` - Outputs: binding-resolution implementation, failure-class updates, targeted tests - **Thread/contract refs**: - `THR-01` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-2-request-auth-and-runtime-artifacts.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-2-request-auth-and-runtime-artifacts.md index dd21c9a92..87c6843d9 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-2-request-auth-and-runtime-artifacts.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-2-request-auth-and-runtime-artifacts.md @@ -59,7 +59,7 @@ open_remediations: - **Outcome**: - request preparation supports more than `cli_codex` while preserving the policy-owned precedence boundary from `THR-01`. - **Inputs/outputs**: - - Inputs: `docs/contracts/substrate-gateway-backend-adapter-schema.md`, `docs/contracts/substrate-gateway-policy-evaluation.md`, `crates/transport-api-types/src/lib.rs`, `crates/shell/src/builtins/world_gateway.rs`, `crates/world-service/src/service.rs` + - Inputs: `docs/contracts/gateway/backend-adapter-schema.md`, `docs/contracts/gateway/policy-evaluation.md`, `crates/transport-api-types/src/lib.rs`, `crates/shell/src/builtins/world_gateway.rs`, `crates/world-service/src/service.rs` - Outputs: widened shared types, backend-aware request construction, bounded auth validation, test coverage - **Thread/contract refs**: - `THR-01` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/review.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/review.md index 40a86e90c..e78cb71a0 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/review.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/review.md @@ -13,7 +13,7 @@ This artifact feeds `gates.pre_exec.review`. - Can parity proof still silently route unsupported integrated backends through the old `cli:codex` path even after `SEAM-2` published explicit no-fallback runtime behavior? - Can `api:openai` be named as the first additional-backend proof target in closeout and live tests, yet remain absent from the platform validation and rollout surfaces this seam is supposed to land? -- Can Linux/macOS/Windows evidence drift into platform-specific exceptions that contradict the single operator-facing lifecycle/status contract in `docs/contracts/substrate-gateway-runtime-parity.md`? +- Can Linux/macOS/Windows evidence drift into platform-specific exceptions that contradict the single operator-facing lifecycle/status contract in `docs/contracts/gateway/runtime-parity.md`? ## R1 - Regression floor and additional-backend matrix that must land @@ -43,13 +43,13 @@ flowchart LR - `crates/world-service/tests/gateway_runtime_parity.rs` already names `api:openai` and explicit unsupported-backend cases, but the seam still has to make the proof matrix readable and durable enough that closeout can publish `THR-03` without re-reading test internals. - `crates/shell/tests/world_gateway.rs` already proves bounded `api_env` emission and explicit unsupported-integrated-backend failures, but this seam still has to align those assertions with rollout and platform evidence rather than treating them as isolated test trivia. -- `docs/contracts/substrate-gateway-runtime-parity.md` owns lifecycle/status parity semantics already, so rollout proof must attach evidence to that canonical contract instead of inventing a seam-local compatibility taxonomy. +- `docs/contracts/gateway/runtime-parity.md` owns lifecycle/status parity semantics already, so rollout proof must attach evidence to that canonical contract instead of inventing a seam-local compatibility taxonomy. - The active seam references pack-local parity, compatibility, manual-testing, and smoke surfaces that do not yet exist in this pack directory, so execution must create only the minimum evidence surfaces needed to make platform proof and closeout deterministic. ## Pre-exec findings - The review gate passes. The seam-local diagrams expose the exact matrix and platform evidence flows that must land before closeout can publish `THR-03`. -- The contract gate passes. Canonical `C-05` already exists under `docs/contracts/substrate-gateway-runtime-parity.md`, while upstream `C-01` through `C-04` were published and revalidated through `SEAM-1` and `SEAM-2`. +- The contract gate passes. Canonical `C-05` already exists under `docs/contracts/gateway/runtime-parity.md`, while upstream `C-01` through `C-04` were published and revalidated through `SEAM-1` and `SEAM-2`. - Revalidation passes against current repo evidence: - `governance/seam-2-closeout.md` publishes `THR-02` and names `api:openai` as the first landed non-`cli:codex` proof target. - `crates/transport-api-types/src/lib.rs` still exposes the bounded `api_env` auth facet for `api:openai`. diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/seam.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/seam.md index c6fda2c9a..0ebcceb75 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/seam.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/seam.md @@ -65,7 +65,7 @@ open_remediations: [] - **Verification**: - This seam **consumes** published `C-01`, `C-02`, `C-03`, and `C-04` from `THR-01` and `THR-02`. - This seam **owns and realizes** `C-05`, whose canonical baseline already exists under: - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - Readiness means execution may start without inventing new upstream truth: - `SEAM-2` closeout already names `api:openai` as the first landed non-`cli:codex` proof target - live shell, world-service, and shared request/auth surfaces still expose `api:openai`, `api_env`, and explicit unsupported-backend behavior @@ -100,11 +100,11 @@ open_remediations: [] - `C-03` - `C-04` - Canonical contract refs: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/runtime-parity.md` ## Review bundle diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threading.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threading.md index bb5d5cc0c..c97526856 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threading.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threading.md @@ -23,10 +23,10 @@ Horizon policy for this pack: - **Derived consumers**: shell gateway entrypoints, broker/config readers, runtime tests - **Thread IDs**: `THR-01` - **Definition**: the integrated lifecycle selection boundary over existing config, policy, and inventory inputs: stable backend id selection, backend-id grammar, one-file-per-backend posture, filename/id consistency, deny-by-default allowlisting, and the trusted-input boundary that excludes gateway-local persistence and mutation from authorization. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-selection.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-selection.md` - **Supporting feature-local surfaces**: - future subordinate ADR-0046 support docs under `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/`, if created later - - **Versioning / compat**: canonical publication stays in `docs/contracts/substrate-gateway-backend-adapter-selection.md`; this pack only aligns implementation and any later subordinate ADR-0046 support docs to it. + - **Versioning / compat**: canonical publication stays in `docs/contracts/gateway/backend-adapter-selection.md`; this pack only aligns implementation and any later subordinate ADR-0046 support docs to it. - **Contract ID**: `C-02` - **Type**: `permission` @@ -35,7 +35,7 @@ Horizon policy for this pack: - **Derived consumers**: auth material sourcing logic, failure taxonomy, security review - **Thread IDs**: `THR-01` - **Definition**: the integrated lifecycle policy-evaluation and auth-sourcing boundary: fail-closed posture, host env-read gating, host-credential-read gating, no-host-fallback rules when in-world execution is required, and the precedence rules for authorized auth material. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-policy-evaluation.md` + - **Canonical contract ref**: `docs/contracts/gateway/policy-evaluation.md` - **Supporting feature-local surfaces**: - future subordinate ADR-0046 support docs under `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/`, if created later - **Versioning / compat**: reused ADR-0027 keys stay externally owned; this pack aligns implementation and any later subordinate ADR-0046 support docs to the published policy contract rather than reopening it. @@ -47,10 +47,10 @@ Horizon policy for this pack: - **Derived consumers**: world-service service, runtime launch path, lifecycle restart handling - **Thread IDs**: `THR-02` - **Definition**: the integrated adapter realization protocol after selection succeeds: one binding lookup, required capability gate, auth handoff validation order, adapter-driven config render, launch, readiness, and restart semantics. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-protocol.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-protocol.md` - **Supporting feature-local surfaces**: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/gateway-runtime-adapter-protocol-spec.md` - - **Versioning / compat**: canonical publication stays in `docs/contracts/substrate-gateway-backend-adapter-protocol.md`; `SEAM-2` must implement it without widening `status --json` or operator commands. + - **Versioning / compat**: canonical publication stays in `docs/contracts/gateway/backend-adapter-protocol.md`; `SEAM-2` must implement it without widening `status --json` or operator commands. - **Contract ID**: `C-04` - **Type**: `schema` @@ -59,7 +59,7 @@ Horizon policy for this pack: - **Derived consumers**: shared request types, integrated auth payloads, runtime artifact handling, failure reporting - **Thread IDs**: `THR-02` - **Definition**: the runtime-owned realization data surfaces needed to support more than `cli:codex`: integrated auth payload shapes, runtime config payloads, managed runtime artifact naming/permission rules, and any shared types required for adapter-driven lifecycle behavior. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-schema.md` - **Supporting feature-local surfaces**: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/gateway-runtime-adapter-schema-spec.md` - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/filesystem-semantics-spec.md` @@ -72,14 +72,14 @@ Horizon policy for this pack: - **Derived consumers**: validation artifacts, compatibility notes, smoke scripts, downstream rollout review - **Thread IDs**: `THR-03` - **Definition**: parity and rollout proof for the selected-backend lifecycle: Linux/macOS/Windows validation expectations, `cli:codex` regression floor, explicit unsupported-backend behavior, and later first-additional-backend proof. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-runtime-parity.md` + - **Canonical contract ref**: `docs/contracts/gateway/runtime-parity.md` - **Supporting feature-local surfaces**: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md` - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md` - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/manual_testing_playbook.md` - **Consumed external authorities**: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Versioning / compat**: the runtime-parity contract owns lifecycle/status parity; future additional-backend compatibility publication is deferred until that rollout work actually begins. ## Thread registry @@ -91,7 +91,7 @@ Horizon policy for this pack: - **Purpose**: make the existing selection and policy contracts executable in repo consumers so runtime realization does not infer truth from the older Codex-only path. - **State**: `revalidated` - **Revalidation trigger**: selection order, backend inventory rules, allowlist semantics, auth precedence, or policy failure taxonomy changes. - - **Satisfied by**: `governance/seam-1-closeout.md` plus evidence that shell, broker, config/policy surfaces, and any later subordinate ADR-0046 support docs align to `docs/contracts/substrate-gateway-backend-adapter-selection.md` and `docs/contracts/substrate-gateway-policy-evaluation.md`. + - **Satisfied by**: `governance/seam-1-closeout.md` plus evidence that shell, broker, config/policy surfaces, and any later subordinate ADR-0046 support docs align to `docs/contracts/gateway/backend-adapter-selection.md` and `docs/contracts/gateway/policy-evaluation.md`. - **Notes**: the canonical contracts were published by `SEAM-1`, and the thread is now `revalidated` because active `SEAM-2` rechecked its basis against `governance/seam-1-closeout.md` and the new seam-local `review.md`. - **Thread ID**: `THR-02` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md index f2b63e07d..bdeb986e5 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md @@ -11,13 +11,13 @@ Authoring standards: - Spec manifest: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md` - External contract docs scanned: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/runtime-parity.md` - Adjacent ADRs and packs scanned: - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` @@ -58,9 +58,9 @@ Authoring standards: ### Edit - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` -- `docs/contracts/substrate-gateway-operator-contract.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` - `docs/CONFIGURATION.md` - `docs/USAGE.md` - `crates/transport-api-types/src/lib.rs` @@ -92,8 +92,8 @@ Authoring standards: - `crates/shell/tests/world_gateway.rs` cases that treat `api:openai` as a generic available status path must move to the new classification matrix: supported backend, blocked backend, invalid backend, missing inventory, missing adapter, and missing auth. - Contradiction risks: - Silent collapse back to the Codex template would violate ADR-0046 and ADR-0041. - - A backend-specific command fork would violate the operator contract in `docs/contracts/substrate-gateway-operator-contract.md`. - - Any additive `status --json` field family without a schema-owner update would violate `docs/contracts/substrate-gateway-status-schema.md`. + - A backend-specific command fork would violate the operator contract in `docs/contracts/gateway/operator-contract.md`. + - Any additive `status --json` field family without a schema-owner update would violate `docs/contracts/gateway/status-schema.md`. ### Inventory-backed selection creates a new filesystem and discoverability dependency - Direct impact: @@ -105,7 +105,7 @@ Authoring standards: - `crates/world-service/src/service.rs` and `crates/world-service/src/gateway_runtime.rs` must agree on where inventory lookup happens so `status`, `sync`, and `restart` share one resolution order. - Contradiction risks: - The current repo documents agent inventory roots and deps inventory roots, but it does not publish backend inventory roots. Leaving that gap open would make the ADR claim inventory-backed realization without an operator discoverability path. - - Treating gateway-local config files as the inventory source would violate `docs/contracts/substrate-gateway-policy-evaluation.md`. + - Treating gateway-local config files as the inventory source would violate `docs/contracts/gateway/policy-evaluation.md`. ### Auth handoff stops being Codex-only and becomes backend-aware - Direct impact: @@ -230,5 +230,5 @@ Authoring standards: ## Follow-ups - Pin the first supported non-`cli:codex` integrated backend id. That decision tightens `crates/gateway/src/auth/`, `crates/gateway/src/providers/`, and `crates/gateway/tests/` from directory-prefix entries to exact files. - Define the exact backend inventory roots and filename rules in `filesystem-semantics-spec.md`, then mirror that wording in `docs/CONFIGURATION.md`. -- Keep `status --json` unchanged unless the status-schema owner explicitly widens `docs/contracts/substrate-gateway-status-schema.md`. +- Keep `status --json` unchanged unless the status-schema owner explicitly widens `docs/contracts/gateway/status-schema.md`. - Keep tuple metadata and tuple-axis policy keys out of this feature-local doc set. Route those surfaces through ADR-0042 and ADR-0043 only. diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/minimal_spec_draft.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/minimal_spec_draft.md index e46731ebb..4ccd1603a 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/minimal_spec_draft.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/minimal_spec_draft.md @@ -26,13 +26,13 @@ Authoritative upstream sources for this draft: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md` External source-of-truth docs reused by this feature: -- `docs/contracts/substrate-gateway-operator-contract.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` -- `docs/contracts/substrate-gateway-backend-adapter-selection.md` -- `docs/contracts/substrate-gateway-backend-adapter-protocol.md` -- `docs/contracts/substrate-gateway-backend-adapter-schema.md` +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` +- `docs/contracts/gateway/backend-adapter-selection.md` +- `docs/contracts/gateway/backend-adapter-protocol.md` +- `docs/contracts/gateway/backend-adapter-schema.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` diff --git a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md index dfc2bcea4..689bf1b33 100644 --- a/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md +++ b/docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md @@ -13,13 +13,13 @@ Authoring standards: - ADRs: - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` - External authoritative docs reused by this feature: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` @@ -234,14 +234,14 @@ This manifest does not require `plan.md`, `tasks.json`, kickoff prompts, executi | Surface | Authoritative doc | What must be explicitly defined | | --- | --- | --- | -| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as the stable operator command family | `docs/contracts/substrate-gateway-operator-contract.md` | command names, baseline operator meaning, stable entrypoint set, and stable absent-state semantics | -| `status --json` envelope and `client_wiring.*` field family | `docs/contracts/substrate-gateway-status-schema.md` | field names, field types, and absence semantics | -| Stable non-secret wiring env outputs `SUBSTRATE_LLM_OPENAI_BASE_URL` and `SUBSTRATE_LLM_ANTHROPIC_BASE_URL` | `docs/contracts/substrate-gateway-operator-contract.md` | env names, non-secret posture, and ownership boundary | -| Gateway policy-evaluation rules for `llm.gateway.mode`, `llm.fail_closed.routing`, host-to-world secret delivery, and no-host-fallback posture | `docs/contracts/substrate-gateway-policy-evaluation.md` | evaluation meaning, fail-closed posture, and trust boundary | -| Typed runtime authority, readiness truth, operator-facing parity contract, and hidden transport divergence | `docs/contracts/substrate-gateway-runtime-parity.md` | typed runtime ownership, readiness contract, and transport-divergence boundary | -| Stable `:` backend-id grammar and the ordered selection boundary before adapter dispatch | `docs/contracts/substrate-gateway-backend-adapter-selection.md` | backend-id format, selection order, invalid-versus-denied distinction, and trusted-input boundary | -| General gateway adapter dispatch lifecycle after a backend id has been selected | `docs/contracts/substrate-gateway-backend-adapter-protocol.md` | general lookup, validation, dispatch, and event-translation rules reused by this feature | -| General gateway adapter capability subset, extension subset, request shape, bounded event/completion shape, and bounded adapter error shape | `docs/contracts/substrate-gateway-backend-adapter-schema.md` | adopted capability ids, extension keys, request envelope, bounded event/completion payloads, and bounded adapter error vocabulary | +| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as the stable operator command family | `docs/contracts/gateway/operator-contract.md` | command names, baseline operator meaning, stable entrypoint set, and stable absent-state semantics | +| `status --json` envelope and `client_wiring.*` field family | `docs/contracts/gateway/status-schema.md` | field names, field types, and absence semantics | +| Stable non-secret wiring env outputs `SUBSTRATE_LLM_OPENAI_BASE_URL` and `SUBSTRATE_LLM_ANTHROPIC_BASE_URL` | `docs/contracts/gateway/operator-contract.md` | env names, non-secret posture, and ownership boundary | +| Gateway policy-evaluation rules for `llm.gateway.mode`, `llm.fail_closed.routing`, host-to-world secret delivery, and no-host-fallback posture | `docs/contracts/gateway/policy-evaluation.md` | evaluation meaning, fail-closed posture, and trust boundary | +| Typed runtime authority, readiness truth, operator-facing parity contract, and hidden transport divergence | `docs/contracts/gateway/runtime-parity.md` | typed runtime ownership, readiness contract, and transport-divergence boundary | +| Stable `:` backend-id grammar and the ordered selection boundary before adapter dispatch | `docs/contracts/gateway/backend-adapter-selection.md` | backend-id format, selection order, invalid-versus-denied distinction, and trusted-input boundary | +| General gateway adapter dispatch lifecycle after a backend id has been selected | `docs/contracts/gateway/backend-adapter-protocol.md` | general lookup, validation, dispatch, and event-translation rules reused by this feature | +| General gateway adapter capability subset, extension subset, request shape, bounded event/completion shape, and bounded adapter error shape | `docs/contracts/gateway/backend-adapter-schema.md` | adopted capability ids, extension keys, request envelope, bounded event/completion payloads, and bounded adapter error vocabulary | | Config file families and precedence for global and workspace config and policy files | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` | file locations, precedence order, and overlay rules | | Inventory file family and filename-to-id match rule | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | file locations, filename rules, and schema-backed identity consistency | | `llm.routing.default_backend` key path, type, and default behavior | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | key path, type, default, and schema constraints | @@ -290,11 +290,11 @@ These artifacts are required by ADR-0046 validation, but they are not selected a No feature-local doc is selected for these classes: - Gateway operator contract doc - - Existing operator command-family semantics already have one owner in `docs/contracts/substrate-gateway-operator-contract.md`. + - Existing operator command-family semantics already have one owner in `docs/contracts/gateway/operator-contract.md`. - Status-schema spec - - Existing machine-readable gateway status surfaces already have one owner in `docs/contracts/substrate-gateway-status-schema.md`. + - Existing machine-readable gateway status surfaces already have one owner in `docs/contracts/gateway/status-schema.md`. - Standalone gateway policy-evaluation contract - - Existing gateway policy-evaluation semantics already have one owner in `docs/contracts/substrate-gateway-policy-evaluation.md`. + - Existing gateway policy-evaluation semantics already have one owner in `docs/contracts/gateway/policy-evaluation.md`. - Telemetry spec - ADR-0046 does not add a new trace field, log field, or structured-event envelope field. Existing trace vocabulary and envelope ownership remain external. - Decision register diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md index ca67a27a3..d29ad8e53 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md @@ -16,7 +16,7 @@ Canonical references: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` -- `docs/contracts/substrate-gateway-status-schema.md` +- `docs/contracts/gateway/status-schema.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md index 38b35e752..b4e772487 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md @@ -104,9 +104,9 @@ Rendering rules: - `identity-tuple-schema-spec.md` owns the machine-readable object names `identity_tuple` and `placement_posture`, their field lists, token grammar, and omission rules. - `telemetry-spec.md` owns placement and projection of `identity_tuple` and `placement_posture` onto status, diagnostics, and trace surfaces. -- `docs/contracts/substrate-gateway-status-schema.md` remains the owner of the top-level `status --json` envelope and the `client_wiring.*` field family. -- `docs/contracts/substrate-gateway-operator-contract.md` remains the owner of the gateway command family and exit-code taxonomy reuse. -- `docs/contracts/substrate-gateway-policy-evaluation.md` remains the owner of policy evaluation over existing ADR-0027 keys. +- `docs/contracts/gateway/status-schema.md` remains the owner of the top-level `status --json` envelope and the `client_wiring.*` field family. +- `docs/contracts/gateway/operator-contract.md` remains the owner of the gateway command family and exit-code taxonomy reuse. +- `docs/contracts/gateway/policy-evaluation.md` remains the owner of policy evaluation over existing ADR-0027 keys. - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` and `SCHEMA.md` remain the owners of config roots, policy roots, precedence, and backend-id grammar. - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` remains the owner of tuple-axis policy keys under `llm.constraints.*`. - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` remains the owner of canonical correlation vocabulary and join keys. diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md index df3f7890f..1a87b726f 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md @@ -11,9 +11,9 @@ This pack is semantic and planning-only. Validation is a deterministic cross-doc - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` @@ -64,7 +64,7 @@ Check: - `policy-spec.md` owns routing-hint evaluation, direct-provider gating, and bridge transport-only policy rules. - ADR-0043 owns tuple-axis policy keys under `llm.constraints.*` and does not restate tuple meanings as a competing owner. - `telemetry-spec.md` owns additive placement of `identity_tuple` and `placement_posture` on status, diagnostics, and trace surfaces. -- `docs/contracts/substrate-gateway-status-schema.md` remains the owner of the top-level `status --json` envelope and `client_wiring.*`. +- `docs/contracts/gateway/status-schema.md` remains the owner of the top-level `status --json` envelope and `client_wiring.*`. - ADR-0028 remains the owner of canonical trace correlation keys and tuple publication remains additive relative to those keys. Pass condition: @@ -177,7 +177,7 @@ rg -n 'host_to_world_bridge|second control plane|second gateway|host gateway' \ ```bash rg -n 'client_wiring|identity_tuple|placement_posture' \ docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture \ - docs/contracts/substrate-gateway-status-schema.md + docs/contracts/gateway/status-schema.md ``` 4. Search for stale active or backup references presented as current owners: diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md index 50f479102..3c0d6833f 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md @@ -14,9 +14,9 @@ Canonical references: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` @@ -34,9 +34,9 @@ Owned here: Not owned here: -- the operator command family or exit taxonomy from `docs/contracts/substrate-gateway-operator-contract.md` -- the `status --json` envelope or `client_wiring.*` field family from `docs/contracts/substrate-gateway-status-schema.md` -- routing-hint evaluation, tuple-axis constraint semantics, or host credential-read gates from `policy-spec.md`, `docs/contracts/substrate-gateway-policy-evaluation.md`, and ADR-0043 +- the operator command family or exit taxonomy from `docs/contracts/gateway/operator-contract.md` +- the `status --json` envelope or `client_wiring.*` field family from `docs/contracts/gateway/status-schema.md` +- routing-hint evaluation, tuple-axis constraint semantics, or host credential-read gates from `policy-spec.md`, `docs/contracts/gateway/policy-evaluation.md`, and ADR-0043 - the object names, field grammar, and omission rules from `identity-tuple-schema-spec.md` - backend-id grammar or backend-selection realization from ADR-0027, ADR-0041, or ADR-0046 @@ -51,9 +51,9 @@ Not owned here: | Platform | Tuple and posture guarantee | Allowed hidden divergence | Verification anchor | | --- | --- | --- | --- | -| Linux | `identity_tuple` and `placement_posture` keep the ADR-0042 meanings, token grammar, omission rules, and router/posture invariants unchanged. | Direct Unix socket transport, cgroup or namespace wiring, and Linux provisioning mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/substrate-gateway-runtime-parity.md` | -| macOS | `identity_tuple` and `placement_posture` keep the same meanings, token grammar, omission rules, and router/posture invariants as Linux. | Lima-backed guest transport, forwarding, and warm-flow mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/substrate-gateway-runtime-parity.md` | -| Windows | `identity_tuple` and `placement_posture` keep the same meanings, token grammar, omission rules, and router/posture invariants as Linux. | WSL-backed transport, named-pipe or TCP bridge mechanics, and Windows warm-flow mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/substrate-gateway-runtime-parity.md` | +| Linux | `identity_tuple` and `placement_posture` keep the ADR-0042 meanings, token grammar, omission rules, and router/posture invariants unchanged. | Direct Unix socket transport, cgroup or namespace wiring, and Linux provisioning mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/gateway/runtime-parity.md` | +| macOS | `identity_tuple` and `placement_posture` keep the same meanings, token grammar, omission rules, and router/posture invariants as Linux. | Lima-backed guest transport, forwarding, and warm-flow mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/gateway/runtime-parity.md` | +| Windows | `identity_tuple` and `placement_posture` keep the same meanings, token grammar, omission rules, and router/posture invariants as Linux. | WSL-backed transport, named-pipe or TCP bridge mechanics, and Windows warm-flow mechanics may differ under the hood. | `contract.md`, `identity-tuple-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `docs/contracts/gateway/runtime-parity.md` | ## Shared invariants @@ -90,9 +90,9 @@ Parity review for this pack consumes these surfaces: - `policy-spec.md` - `telemetry-spec.md` - durable external authorities: - - `docs/contracts/substrate-gateway-runtime-parity.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md index 6d4f0d91f..ca1763f5e 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md @@ -12,7 +12,7 @@ Owner standard: Canonical references: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` @@ -127,7 +127,7 @@ Policy evaluation for tuple-aware routing follows this order: - Invalid integration state, dependency unavailability, and policy denial remain separate outcomes. - This spec fixes the tuple-aware decision points that feed those existing buckets. -- `docs/contracts/substrate-gateway-policy-evaluation.md` remains the owner of the final bucket taxonomy and operator explanation boundary. +- `docs/contracts/gateway/policy-evaluation.md` remains the owner of the final bucket taxonomy and operator explanation boundary. ## Acceptance criteria diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/impact_map.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/impact_map.md index 2e70f982c..cda8503c9 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/impact_map.md @@ -11,10 +11,10 @@ Authoring standards: - Spec manifest: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md` - External contract docs scanned: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - Adjacent ADRs and packs scanned: @@ -83,10 +83,10 @@ Canonical slice ids selected for this feature: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ-windows.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ.md` - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` -- `docs/contracts/substrate-gateway-operator-contract.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/CONFIGURATION.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/minimal_spec_draft.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/minimal_spec_draft.md index 1c26e3a46..830b76f95 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/minimal_spec_draft.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/minimal_spec_draft.md @@ -28,10 +28,10 @@ Authority boundaries for this feature: - `platform-parity-spec.md` owns Linux, macOS, and Windows parity guarantees and the rule that `host_to_world_bridge` does not change in-world `net_allowed` governance. - `compatibility-spec.md` owns overloaded-backend-label retirement posture and rollout proof for new docs and diagnostics. - `manual_testing_playbook.md` owns deterministic doc-alignment validation and example-based review. -- `docs/contracts/substrate-gateway-operator-contract.md` remains the owner for the existing gateway command family. -- `docs/contracts/substrate-gateway-status-schema.md` remains the owner for the published `status --json` envelope and `client_wiring.*` field family. -- `docs/contracts/substrate-gateway-policy-evaluation.md` remains the owner for gateway placement evaluation, fail-closed routing semantics, and host-to-world secret-delivery posture. -- `docs/contracts/substrate-gateway-runtime-parity.md` remains the owner for general gateway lifecycle parity. +- `docs/contracts/gateway/operator-contract.md` remains the owner for the existing gateway command family. +- `docs/contracts/gateway/status-schema.md` remains the owner for the published `status --json` envelope and `client_wiring.*` field family. +- `docs/contracts/gateway/policy-evaluation.md` remains the owner for gateway placement evaluation, fail-closed routing semantics, and host-to-world secret-delivery posture. +- `docs/contracts/gateway/runtime-parity.md` remains the owner for general gateway lifecycle parity. - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` and `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` remain the owners for config roots, policy roots, key paths, precedence, and backend-id grammar. - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` remains the owner for canonical trace vocabulary and correlation keys. - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` remains the owner for tuple-axis policy keys under `llm.constraints.*`. @@ -147,8 +147,8 @@ Accepted draft slice count: `3` - likely owned or touched surfaces: - `contract.md` - `identity-tuple-schema-spec.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` @@ -158,10 +158,10 @@ Accepted draft slice count: `3` - likely owned or touched surfaces: - `policy-spec.md` - `telemetry-spec.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/status-schema.md` - `docs/TRACE.md` - slice_id: `LAITDP2` @@ -172,7 +172,7 @@ Accepted draft slice count: `3` - `compatibility-spec.md` - `manual_testing_playbook.md` - `pre-planning/ci_checkpoint_plan.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md index 495efa0f0..0fb8aa614 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md @@ -12,10 +12,10 @@ Authoring standards: - ADRs: - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - External authoritative docs reused by this feature: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` @@ -124,10 +124,10 @@ Full planning will create or refine these docs: | Surface | Authoritative doc | What must be explicitly defined | | --- | --- | --- | -| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as existing operator entrypoints | `docs/contracts/substrate-gateway-operator-contract.md` | command family, stable operator meaning, and baseline exit-code taxonomy for the gateway boundary | -| `status --json` top-level envelope and `client_wiring.*` field family | `docs/contracts/substrate-gateway-status-schema.md` | top-level JSON shape, `status`, `client_wiring.*`, and absence semantics for the published wiring surface | -| Gateway policy-evaluation flow over `llm.gateway.mode`, `llm.fail_closed.routing`, `llm.secrets.env_allowed`, and `agents.host_credentials.read.allowed_backends` | `docs/contracts/substrate-gateway-policy-evaluation.md` | fail-closed routing, secret-source precedence, trusted-input boundary, and policy outcome classes | -| Gateway runtime lifecycle parity and hidden transport divergence | `docs/contracts/substrate-gateway-runtime-parity.md` | typed runtime boundary, lifecycle/status parity, and hidden transport divergence list | +| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as existing operator entrypoints | `docs/contracts/gateway/operator-contract.md` | command family, stable operator meaning, and baseline exit-code taxonomy for the gateway boundary | +| `status --json` top-level envelope and `client_wiring.*` field family | `docs/contracts/gateway/status-schema.md` | top-level JSON shape, `status`, `client_wiring.*`, and absence semantics for the published wiring surface | +| Gateway policy-evaluation flow over `llm.gateway.mode`, `llm.fail_closed.routing`, `llm.secrets.env_allowed`, and `agents.host_credentials.read.allowed_backends` | `docs/contracts/gateway/policy-evaluation.md` | fail-closed routing, secret-source precedence, trusted-input boundary, and policy outcome classes | +| Gateway runtime lifecycle parity and hidden transport divergence | `docs/contracts/gateway/runtime-parity.md` | typed runtime boundary, lifecycle/status parity, and hidden transport divergence list | | Config and policy file families, patch locations, and precedence order | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` | file locations, precedence order, and the deny-by-default policy posture already in force | | Existing key-path definitions for `llm.gateway.mode`, `llm.fail_closed.routing`, `llm.secrets.env_allowed`, and `agents.host_credentials.read.allowed_backends` | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | key paths, types, defaults, and merge strategy | | Backend id format and the rule that backend ids stay adapter/runtime selectors rather than tuple substitutes | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | `:` format and the non-equivalence boundary against tuple semantics | diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/workstream_triage.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/workstream_triage.md index 91dfc14e9..6f32eb4c4 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/workstream_triage.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/workstream_triage.md @@ -226,11 +226,11 @@ - The host-only router identity conflict around `direct_provider_path` remains open. - The absence semantics for `provider` and `auth_authority` remain open for pre-provider-selection paths and for pure-agent follow-on flows. -- The exact status and diagnostics field family for tuple publication outside `client_wiring.*` remains open against `docs/contracts/substrate-gateway-status-schema.md`. +- The exact status and diagnostics field family for tuple publication outside `client_wiring.*` remains open against `docs/contracts/gateway/status-schema.md`. - The exact trace field family and field placement remains open against ADR-0028. - The boundary line with ADR-0044 and ADR-0045 for pure-agent and toolbox tuple publication remains open. - WSL scope remains a follow-up until downstream runtime review names the concrete surface set. -- High-churn boundary: additive tuple publication across `telemetry-spec.md`, `docs/contracts/substrate-gateway-status-schema.md`, ADR-0028, and the typed-model surface named in `impact_map.md`. +- High-churn boundary: additive tuple publication across `telemetry-spec.md`, `docs/contracts/gateway/status-schema.md`, ADR-0028, and the typed-model surface named in `impact_map.md`. - High-churn boundary: compatibility and rollout wording across `compatibility-spec.md`, ADR-0040, ADR-0041, and ADR-0046. ## Slice skeleton recommendations diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-spec.md index 6239a3492..dd37e06bd 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-spec.md @@ -18,8 +18,8 @@ - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/status-schema.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-spec.md index 3c53717fe..24b590cbf 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-spec.md @@ -20,7 +20,7 @@ - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` diff --git a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md index 94a8bb9d2..dff06d12f 100644 --- a/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md +++ b/docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md @@ -8,14 +8,14 @@ Owner standard: - This spec is authoritative for additive publication of `identity_tuple` and `placement_posture` on gateway status, diagnostics, and trace surfaces introduced by ADR-0042. - This spec owns field placement, emission rules, omission rules, and redaction posture for those two objects. - This spec does not redefine the object shapes from `identity-tuple-schema-spec.md`. -- This spec does not redefine the owned `status` or `client_wiring.*` fields from `docs/contracts/substrate-gateway-status-schema.md`. +- This spec does not redefine the owned `status` or `client_wiring.*` fields from `docs/contracts/gateway/status-schema.md`. - This spec does not redefine the canonical correlation keys from ADR-0028. Canonical references: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-operator-contract.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/operator-contract.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/TRACE.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md index b1d53e976..67343b3c4 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md @@ -10,7 +10,7 @@ Owned here: - the additive rollout and compatibility story for existing operator workflows - the historical-evidence-only treatment of ADR-0024 - the evidence-only treatment of ADR-0040 as consumed through ADR-0041 and - `docs/contracts/substrate-gateway-runtime-parity.md` + `docs/contracts/gateway/runtime-parity.md` - the explicit "no second control plane" invariant for this seam Not owned here: @@ -42,7 +42,7 @@ Not owned here: - ADR-0040 remains the prerequisite boundary evidence for runtime ownership. - This seam consumes ADR-0040 through ADR-0041 and - `docs/contracts/substrate-gateway-runtime-parity.md`, not by reopening ADR-0040 as a direct touch + `docs/contracts/gateway/runtime-parity.md`, not by reopening ADR-0040 as a direct touch surface. - Direct ADR-0040 edits remain out of scope unless landing evidence exposes a concrete owner-line mismatch that the current boundary no longer explains. @@ -58,4 +58,4 @@ Not owned here: ## Acceptance check This document is complete only if it can be read as a consumer of ADR-0024, ADR-0040, ADR-0041, and -`docs/contracts/substrate-gateway-runtime-parity.md` without becoming a shadow contract for any of them. +`docs/contracts/gateway/runtime-parity.md` without becoming a shadow contract for any of them. diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md index b6666e492..965d0089e 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md @@ -6,9 +6,9 @@ protocol, payload, or parity detail. Canonical references: -- `docs/contracts/substrate-gateway-backend-adapter-selection.md` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-operator-contract.md` +- `docs/contracts/gateway/backend-adapter-selection.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/operator-contract.md` ## Contract baseline @@ -27,9 +27,9 @@ Canonical references: Substrate authorization inputs or selection inputs. - No additive adapter-visible `status --json` field family is published by this seam in v1. The currently published machine-readable surface remains the existing `status` plus - `client_wiring.*` schema owned by `docs/contracts/substrate-gateway-status-schema.md`. + `client_wiring.*` schema owned by `docs/contracts/gateway/status-schema.md`. - Any future additive adapter-visible status metadata requires an explicit update to - `docs/contracts/substrate-gateway-status-schema.md` before code or tests widen + `docs/contracts/gateway/status-schema.md` before code or tests widen `GatewayLifecycleResponseV1`. ## Verification plan @@ -45,8 +45,8 @@ Evidence already present: Execution checklist for landing this seam: - Update docs: - - keep this file aligned with `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - keep the status-boundary statement aligned with `docs/contracts/substrate-gateway-status-schema.md` + - keep this file aligned with `docs/contracts/gateway/backend-adapter-selection.md` + - keep the status-boundary statement aligned with `docs/contracts/gateway/status-schema.md` - Add or update tests: - extend `crates/broker/src/policy/tests.rs` when backend-id grammar or invalid-selection rules change - extend `crates/shell/tests/world_gateway.rs` if gateway status output is widened after the schema owner is updated diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md index 11624f798..5dd2bd84f 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md @@ -1,7 +1,7 @@ # Gateway Backend Adapter Protocol Spec This spec is the seam-local execution baseline for `C-03`. The durable contract text for this -surface lives in `docs/contracts/substrate-gateway-backend-adapter-protocol.md`. +surface lives in `docs/contracts/gateway/backend-adapter-protocol.md`. ## Scope @@ -65,7 +65,7 @@ topology, not contract truth. ### Doc surfaces that define the landed protocol baseline -- `docs/contracts/substrate-gateway-backend-adapter-protocol.md` +- `docs/contracts/gateway/backend-adapter-protocol.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md index 308f8bb70..1403ef9eb 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md @@ -1,7 +1,7 @@ # Gateway Backend Adapter Schema Spec This spec is the seam-local execution baseline for `C-04`. The durable contract text for this -surface lives in `docs/contracts/substrate-gateway-backend-adapter-schema.md`. +surface lives in `docs/contracts/gateway/backend-adapter-schema.md`. ## Adopted Unified Agent API Subset @@ -165,7 +165,7 @@ Pinned rules: ### Doc surfaces that define the landed schema baseline -- `docs/contracts/substrate-gateway-backend-adapter-schema.md` +- `docs/contracts/gateway/backend-adapter-schema.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md` ### Runtime-adjacent adoption surfaces to verify against when implementation lands diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/remediation-log.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/remediation-log.md index 62ce23642..3cd65abb2 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/remediation-log.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/remediation-log.md @@ -16,9 +16,9 @@ status: resolved owner_seam: SEAM-1 blocked_targets: [] summary: v1 gateway status publication remains limited to the existing `status` plus `client_wiring.*` schema, and any future additive adapter-visible field family must be introduced by the status-schema owner before runtime models widen. -required_fix: keep `docs/contracts/substrate-gateway-status-schema.md` as the owner for the machine-readable status field list and require an explicit schema-owner update before any additive adapter-visible status field family ships. +required_fix: keep `docs/contracts/gateway/status-schema.md` as the owner for the machine-readable status field list and require an explicit schema-owner update before any additive adapter-visible status field family ships. resolution_evidence: - - docs/contracts/substrate-gateway-status-schema.md + - docs/contracts/gateway/status-schema.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md @@ -38,9 +38,9 @@ status: carried_forward owner_seam: SEAM-2 blocked_targets: [] summary: the adopted Unified Agent API subset is now pinned to a bounded cross-backend execution baseline, but landing and closeout still need to keep the capability set, extension-key subset, session-handle facet, and bounded adapter error detail aligned with that baseline. -required_fix: keep `docs/contracts/substrate-gateway-backend-adapter-schema.md` and `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md` aligned as implementation lands, and verify the unified-agent-api capability, session-handle, selector-validation, cancellation, and runtime-rejection suites still match the adopted subset before closeout publishes `THR-02`. +required_fix: keep `docs/contracts/gateway/backend-adapter-schema.md` and `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md` aligned as implementation lands, and verify the unified-agent-api capability, session-handle, selector-validation, cancellation, and runtime-rejection suites still match the adopted subset before closeout publishes `THR-02`. resolution_evidence: - - docs/contracts/substrate-gateway-backend-adapter-schema.md + - docs/contracts/gateway/backend-adapter-schema.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md - /Users/spensermcconnell/atomize-hq/unified-agent-api/docs/specs/unified-agent-api/capability-matrix.md @@ -65,9 +65,9 @@ status: carried_forward owner_seam: SEAM-2 blocked_targets: [] summary: the local-to-external owner line is now pinned: gateway-local adapter translation stops at bounded gateway-local event and completion shapes, while ADR-0017 and ADR-0028 remain the external owners of structured-event envelope and canonical trace semantics. -required_fix: keep `docs/contracts/substrate-gateway-backend-adapter-protocol.md` and `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md` aligned as implementation lands, and verify the unified-agent-api harness ownership tests plus the standalone gateway normalized-event surfaces still respect that owner line before closeout publishes `THR-02`. +required_fix: keep `docs/contracts/gateway/backend-adapter-protocol.md` and `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md` aligned as implementation lands, and verify the unified-agent-api harness ownership tests plus the standalone gateway normalized-event surfaces still respect that owner line before closeout publishes `THR-02`. resolution_evidence: - - docs/contracts/substrate-gateway-backend-adapter-protocol.md + - docs/contracts/gateway/backend-adapter-protocol.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md - /Users/spensermcconnell/atomize-hq/unified-agent-api/crates/agent_api/src/backends/codex/tests/backend_contract.rs @@ -95,7 +95,7 @@ required_fix: keep ADR-0040 as evidence-only basis for runtime ownership and reo resolution_evidence: - docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md - docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md - - docs/contracts/substrate-gateway-runtime-parity.md + - docs/contracts/gateway/runtime-parity.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-2-compatibility-proof-and-adr-0040-decision.md @@ -130,15 +130,15 @@ related_seam: SEAM-1 related_slice: S00 related_thread: THR-01 related_contract: C-01 -related_artifact: docs/contracts/substrate-gateway-backend-adapter-selection.md +related_artifact: docs/contracts/gateway/backend-adapter-selection.md severity: blocking status: resolved owner_seam: SEAM-1 blocked_targets: [] summary: the canonical backend-selection baseline now exists and the seam-local execution checklist points downstream work at that durable contract instead of at planning-pack-only prose. -required_fix: keep `docs/contracts/substrate-gateway-backend-adapter-selection.md` aligned with the pack-local `contract.md` and `policy-spec.md` as the implementation checklist executes. +required_fix: keep `docs/contracts/gateway/backend-adapter-selection.md` aligned with the pack-local `contract.md` and `policy-spec.md` as the implementation checklist executes. resolution_evidence: - - docs/contracts/substrate-gateway-backend-adapter-selection.md + - docs/contracts/gateway/backend-adapter-selection.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md - docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-1-closeout.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-1-closeout.md index 128e379e9..b38d2eadc 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-1-closeout.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-1-closeout.md @@ -31,8 +31,8 @@ This closeout records the landed `SEAM-1` exit gate after the dedicated `S99` se - **Source artifact**: `../threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md` - **Landed evidence**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/status-schema.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md` - **Contracts published or changed**: `C-01`, `C-02` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-2-closeout.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-2-closeout.md index 6156d00e0..bcb7cbd29 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-2-closeout.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-2-closeout.md @@ -33,8 +33,8 @@ This closeout records the realized `SEAM-2` handoff and publishes `THR-02` for d - **Source artifact**: `../threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md` - **Landed evidence**: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md index 25a0214bc..f0d0eaaec 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md @@ -5,12 +5,12 @@ It consumes the landed contracts below and does not redefine them. ## Contracts consumed -- `docs/contracts/substrate-gateway-operator-contract.md` - operator command family and exit taxonomy -- `docs/contracts/substrate-gateway-status-schema.md` - machine-readable gateway status wiring surface -- `docs/contracts/substrate-gateway-policy-evaluation.md` - policy evaluation and trust boundary +- `docs/contracts/gateway/operator-contract.md` - operator command family and exit taxonomy +- `docs/contracts/gateway/status-schema.md` - machine-readable gateway status wiring surface +- `docs/contracts/gateway/policy-evaluation.md` - policy evaluation and trust boundary - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - event-envelope owner line - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - canonical trace vocabulary owner line -- `docs/contracts/substrate-gateway-runtime-parity.md` - typed runtime boundary and platform parity +- `docs/contracts/gateway/runtime-parity.md` - typed runtime boundary and platform parity ## One-owner-per-surface audit diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/platform-parity-spec.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/platform-parity-spec.md index dd35df654..f44c1b0ca 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/platform-parity-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/platform-parity-spec.md @@ -1,9 +1,9 @@ # substrate-gateway-backend-adapter-contract - platform parity spec This document defines the feature-local proof surface for cross-platform parity and runtime-boundary verification. -It is a consumer of `docs/contracts/substrate-gateway-runtime-parity.md`, not a second owner of that contract. +It is a consumer of `docs/contracts/gateway/runtime-parity.md`, not a second owner of that contract. For this slice, the canonical runtime-parity contract remains read-only. -S1 does not require any edits to `docs/contracts/substrate-gateway-runtime-parity.md`. +S1 does not require any edits to `docs/contracts/gateway/runtime-parity.md`. ## Contract boundary @@ -34,9 +34,9 @@ WSL is not a separate operator-facing contract surface in this feature. | Platform | Guarantee | Allowed hidden divergence | Verification anchor | | --- | --- | --- | --- | -| Linux | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | Direct Unix socket transport to `/run/substrate.sock`, socket activation, and provisioning mechanics may differ under the hood. | `docs/contracts/substrate-gateway-runtime-parity.md` and this pack-local parity spec. | -| macOS | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | Lima-backed forwarding, guest transport, and warm-up mechanics may differ under the hood. | `docs/contracts/substrate-gateway-runtime-parity.md` and this pack-local parity spec. | -| Windows | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | WSL-backed transport, named-pipe or TCP bridge mechanics, and warm-up details may differ under the hood. | `docs/contracts/substrate-gateway-runtime-parity.md` and this pack-local parity spec. | +| Linux | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | Direct Unix socket transport to `/run/substrate.sock`, socket activation, and provisioning mechanics may differ under the hood. | `docs/contracts/gateway/runtime-parity.md` and this pack-local parity spec. | +| macOS | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | Lima-backed forwarding, guest transport, and warm-up mechanics may differ under the hood. | `docs/contracts/gateway/runtime-parity.md` and this pack-local parity spec. | +| Windows | Adapter-backed execution stays inside the world boundary when world execution is required, and the stable backend-id / allowlist semantics remain unchanged. | WSL-backed transport, named-pipe or TCP bridge mechanics, and warm-up details may differ under the hood. | `docs/contracts/gateway/runtime-parity.md` and this pack-local parity spec. | ## Runtime-boundary proof @@ -44,7 +44,7 @@ The proof obligation for this slice is to show that the pack-local parity surfac Rules: -- `docs/contracts/substrate-gateway-runtime-parity.md` remains the canonical runtime-boundary reference for this slice. +- `docs/contracts/gateway/runtime-parity.md` remains the canonical runtime-boundary reference for this slice. - This pack-local spec may narrow or restate the canonical boundary, but it must not widen it. - Hidden transport and bootstrap differences stay evidence-only unless the canonical contract is explicitly changed upstream. - No second Substrate control plane may be introduced through parity wording, validation wording, or platform-specific notes. @@ -65,6 +65,6 @@ This spec does not define code behavior, but it does define the proof shape that - The Linux/macOS/Windows guarantee matrix is explicit and bounded. - Windows parity is framed as hidden WSL-backed runtime mechanics, not a separate operator contract. -- The pack-local spec clearly consumes `docs/contracts/substrate-gateway-runtime-parity.md` as read-only canonical basis. +- The pack-local spec clearly consumes `docs/contracts/gateway/runtime-parity.md` as read-only canonical basis. - The spec does not imply direct ADR-0040 edits. - The spec does not introduce a second control plane or any new contract surface. diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md index 04cf0165b..99ee8f073 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md @@ -6,8 +6,8 @@ keep the C-01 baseline internally consistent. Canonical references: -- `docs/contracts/substrate-gateway-backend-adapter-selection.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/backend-adapter-selection.md` +- `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` @@ -59,7 +59,7 @@ These outcomes must remain distinct in docs, code, and tests. Evidence already present: - `crates/broker/src/policy.rs` and `crates/broker/src/effective_policy.rs` enforce backend-id validation -- `docs/contracts/substrate-gateway-policy-evaluation.md` already separates invalid integration state, +- `docs/contracts/gateway/policy-evaluation.md` already separates invalid integration state, dependency unavailability, and policy denial - `crates/shell/tests/world_gateway.rs` and `crates/world-service/tests/gateway_runtime_parity.rs` already prove the current unavailable and available status posture diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/impact_map.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/impact_map.md index 38a2b9aa3..422ea5c40 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/impact_map.md @@ -36,9 +36,9 @@ Authoring standards: ### Edit - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` -- `docs/contracts/substrate-gateway-operator-contract.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` -- `docs/contracts/substrate-gateway-runtime-parity.md` +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/policy-evaluation.md` +- `docs/contracts/gateway/runtime-parity.md` - `docs/WORLD.md` - `docs/USAGE.md` - `crates/transport-api-types/src/lib.rs` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/minimal_spec_draft.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/minimal_spec_draft.md index 90c4a59e5..3646a7f3f 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/minimal_spec_draft.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/minimal_spec_draft.md @@ -28,10 +28,10 @@ Authority boundaries for this feature: - `policy-spec.md` is the downstream single owner for adapter selection, allowlist gating, and trusted-input boundaries. - `gateway-backend-adapter-protocol-spec.md` and `gateway-backend-adapter-schema-spec.md` are the downstream single owners for adapter lifecycle, payload, capability, error, and session-handle boundary details. - `platform-parity-spec.md` and `compatibility-spec.md` are the downstream single owners for parity and rollout guarantees. -- `docs/contracts/substrate-gateway-operator-contract.md` remains the owner for the `substrate world gateway status`, `sync`, and `restart` command family. -- `docs/contracts/substrate-gateway-status-schema.md` remains the owner for the existing `status --json` envelope and existing `client_wiring.*` family. -- `docs/contracts/substrate-gateway-policy-evaluation.md` remains the owner for gateway/world placement evaluation and host-to-world secret delivery posture. -- `docs/contracts/substrate-gateway-runtime-parity.md` remains the owner for the general gateway lifecycle runtime-parity surface. +- `docs/contracts/gateway/operator-contract.md` remains the owner for the `substrate world gateway status`, `sync`, and `restart` command family. +- `docs/contracts/gateway/status-schema.md` remains the owner for the existing `status --json` envelope and existing `client_wiring.*` family. +- `docs/contracts/gateway/policy-evaluation.md` remains the owner for gateway/world placement evaluation and host-to-world secret delivery posture. +- `docs/contracts/gateway/runtime-parity.md` remains the owner for the general gateway lifecycle runtime-parity surface. - ADR-0027 and the implemented `llm_and_agent_config_policy_surface` pack remain the owners for backend-id grammar, inventory locations, config roots, policy roots, and allowlist storage. - ADR-0017 remains the owner for structured event envelope semantics. - ADR-0028 remains the owner for canonical trace vocabulary and correlation semantics. @@ -159,8 +159,8 @@ Baseline seam count from `spec_manifest.md`: 3 draft seams. This draft keeps tha - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/policy-evaluation.md` ### Seam 2 @@ -173,7 +173,7 @@ Baseline seam count from `spec_manifest.md`: 3 draft seams. This draft keeps tha - `contract.md` - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/status-schema.md` ### Seam 3 @@ -185,5 +185,5 @@ Baseline seam count from `spec_manifest.md`: 3 draft seams. This draft keeps tha - `compatibility-spec.md` - `manual_testing_playbook.md` - `pre-planning/ci_checkpoint_plan.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/spec_manifest.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/spec_manifest.md index 92f2f46d2..90cce3265 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/spec_manifest.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/spec_manifest.md @@ -15,10 +15,10 @@ Authoring standards: - ADRs: - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - External authoritative docs reused by this feature: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` @@ -212,11 +212,11 @@ This manifest does not require `plan.md`, `tasks.json`, kickoff prompts, executi | Surface | Authoritative doc | What must be explicitly defined | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as operator entrypoints | `docs/contracts/substrate-gateway-operator-contract.md` | command family, operator meaning, stable entrypoint status, and gateway lifecycle exit-code baseline | -| Human-readable gateway availability and wiring discovery posture | `docs/contracts/substrate-gateway-operator-contract.md` | operator-visible wording, stable wiring discovery posture, and absent-state contract | -| `status --json` top-level envelope and `client_wiring.*` field family | `docs/contracts/substrate-gateway-status-schema.md` | field names, field types, and absence semantics | -| Gateway/world placement evaluation and host-to-world secret delivery boundary | `docs/contracts/substrate-gateway-policy-evaluation.md` | gateway policy-evaluation rules that ADR-0041 reuses without redefining | -| Gateway lifecycle runtime parity and hidden transport divergence | `docs/contracts/substrate-gateway-runtime-parity.md` | typed runtime boundary and general gateway lifecycle parity | +| `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as operator entrypoints | `docs/contracts/gateway/operator-contract.md` | command family, operator meaning, stable entrypoint status, and gateway lifecycle exit-code baseline | +| Human-readable gateway availability and wiring discovery posture | `docs/contracts/gateway/operator-contract.md` | operator-visible wording, stable wiring discovery posture, and absent-state contract | +| `status --json` top-level envelope and `client_wiring.*` field family | `docs/contracts/gateway/status-schema.md` | field names, field types, and absence semantics | +| Gateway/world placement evaluation and host-to-world secret delivery boundary | `docs/contracts/gateway/policy-evaluation.md` | gateway policy-evaluation rules that ADR-0041 reuses without redefining | +| Gateway lifecycle runtime parity and hidden transport divergence | `docs/contracts/gateway/runtime-parity.md` | typed runtime boundary and general gateway lifecycle parity | | Config file families and precedence for config and policy patches | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` | file locations and precedence order | | Backend inventory file family and filename-to-id matching | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | inventory locations, filename/id matching rule, and strictness | | `llm.routing.default_backend` key path, type, default, and `:` syntax | `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` | schema rule and default | @@ -257,11 +257,11 @@ This manifest does not require `plan.md`, `tasks.json`, kickoff prompts, executi No feature-local doc is selected for these classes: - Gateway operator contract doc - - Existing gateway operator surfaces already have one owner in `docs/contracts/substrate-gateway-operator-contract.md`. + - Existing gateway operator surfaces already have one owner in `docs/contracts/gateway/operator-contract.md`. - Status-schema spec - - Existing machine-readable gateway status surfaces already have one owner in `docs/contracts/substrate-gateway-status-schema.md`. + - Existing machine-readable gateway status surfaces already have one owner in `docs/contracts/gateway/status-schema.md`. - Gateway runtime parity contract - - Existing lifecycle and hidden-transport parity surfaces already have one owner in `docs/contracts/substrate-gateway-runtime-parity.md`. + - Existing lifecycle and hidden-transport parity surfaces already have one owner in `docs/contracts/gateway/runtime-parity.md`. - Env-vars spec - ADR-0041 does not add a new env-var family. Existing stable wiring env vars remain owned by the gateway operator contract. - Telemetry spec diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/scope_brief.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/scope_brief.md index 392c9f4d6..b6b058da3 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/scope_brief.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/scope_brief.md @@ -42,10 +42,10 @@ execution_horizon: - **External systems / dependencies**: - `substrate-gateway` - ADR-0027, ADR-0040, ADR-0017, ADR-0028 - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - Unified Agent API evidence from `unified-agent-api` - gateway boundary evidence from `kimi-claude-adapter` - **Known unknowns / risks**: diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-1-adapter-selection-boundary.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-1-adapter-selection-boundary.md index fb5ffd88a..8e273a4c3 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-1-adapter-selection-boundary.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-1-adapter-selection-boundary.md @@ -58,9 +58,9 @@ open_remediations: [] - `pre-planning/spec_manifest.md` - `pre-planning/impact_map.md` - ADR-0027 and the implemented config/policy pack - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - Outputs: - `C-01` - `C-02` @@ -92,14 +92,14 @@ open_remediations: [] - **Verification**: - This seam produces owned contracts `C-01` and `C-02`. - At seam-brief depth, readiness means the stable backend-id semantics, ordered selection inputs, failure buckets, and `status --json` publication boundary are concrete enough for execution without inventing a second owner. - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` is now the canonical `C-01` baseline. + - `docs/contracts/gateway/backend-adapter-selection.md` is now the canonical `C-01` baseline. - `C-02` now resolves to a narrower v1 decision: no additive adapter-visible `status --json` field family is currently published beyond the existing `status` plus `client_wiring.*` schema, and any future additive family requires an explicit status-schema owner update before code changes. - With the seam exit now closed and `THR-01` published from closeout, this seam no longer sits in the forward planning window. - Downstream seam-local review should verify that one selected backend id maps to one adapter identity, that the failure buckets stay fail-closed, and that any adapter-visible status subset stays inside a single explicit owner line. - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/backend-adapter-selection.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Risks / unknowns**: - Risk: - a future attempt to publish adapter-visible `status --json` metadata could drift from the current v1 boundary if it widens the schema without an explicit status-schema owner update diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-2-adapter-protocol-and-schema.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-2-adapter-protocol-and-schema.md index 8dc5370ea..bbee2d8a7 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-2-adapter-protocol-and-schema.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-2-adapter-protocol-and-schema.md @@ -97,14 +97,14 @@ open_remediations: - This seam produces owned contracts `C-03` and `C-04`. - At seam-brief depth, readiness is that the dispatch lifecycle, field inventory, fail-closed capability rules, and ADR-0017 / ADR-0028 handoff lines are concrete enough for seam-local planning and implementation. - `SEAM-2` is closed because `THR-02` is now published and the seam-local contract baseline landed in: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - `gateway-backend-adapter-protocol-spec.md` - `gateway-backend-adapter-schema-spec.md` - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` + - `docs/contracts/gateway/status-schema.md` - **Risks / unknowns**: - Risk: - landing could drift away from the now-pinned adopted capability subset, extension-key subset, bounded error shape, or session-handle bounds diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-3-parity-and-validation.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-3-parity-and-validation.md index eb3942d49..cdfe7e232 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-3-parity-and-validation.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-3-parity-and-validation.md @@ -64,7 +64,7 @@ This seam is closed. Its authoritative exit-gate record lives in `./governance/s - `C-02` - `C-03` - `C-04` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - Outputs: @@ -92,19 +92,19 @@ This seam is closed. Its authoritative exit-gate record lives in `./governance/s - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/ci_checkpoint_plan.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Verification**: - This seam consumes upstream contracts `C-01` through `C-04`, so verification may depend on accepted upstream evidence for the landed selection, publication, protocol, and schema contracts. - At seam-brief depth, readiness is that the parity matrix, compatibility proof, and validation assertions are concrete enough for seam-local planning and implementation. - Downstream seam-local review should prove that cross-platform guarantees remain compatible with ADR-0040 and that the compatibility proof keeps ADR-0024 historical rather than active. - ADR-0040 is now explicitly confirmed as evidence-only basis for this seam: - ADR-0040 remains the owner of the Substrate versus `substrate-gateway` runtime boundary. - - ADR-0041 and `docs/contracts/substrate-gateway-runtime-parity.md` carry the downstream consequences this seam must prove. + - ADR-0041 and `docs/contracts/gateway/runtime-parity.md` carry the downstream consequences this seam must prove. - direct ADR-0040 edits stay out of scope unless landing evidence discovers a concrete runtime-ownership drift. - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-runtime-parity.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` + - `docs/contracts/gateway/runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` - **Risks / unknowns**: - Risk: - landing evidence could still expose a concrete runtime-ownership drift that ADR-0040 and the current runtime-parity contract no longer explain diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam_map.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam_map.md index e7c23ec69..bd17385a5 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam_map.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam_map.md @@ -94,7 +94,7 @@ That split is still cohesive. `SEAM-1` owns the prerequisite contract truth, `SE - `compatibility-spec.md` - `manual_testing_playbook.md` - `pre-planning/ci_checkpoint_plan.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - **Natural boundary**: - This seam is cross-seam proof and drift prevention. It does not own selection semantics or adapter payload shape. diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/review.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/review.md index 71867ae31..697dbaa05 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/review.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/review.md @@ -39,8 +39,8 @@ flowchart LR flowchart TB S["SEAM-1 contract surfaces"] --> C1["C-01 stable backend selection contract"] S --> C2["C-02 adapter-visible status subset boundary"] - C2 --> StatusSchema["docs/contracts/substrate-gateway-status-schema.md"] - C2 --> Operator["docs/contracts/substrate-gateway-operator-contract.md"] + C2 --> StatusSchema["docs/contracts/gateway/status-schema.md"] + C2 --> Operator["docs/contracts/gateway/operator-contract.md"] StatusSchema --> Bound["Existing envelope + client_wiring.* stay externally owned"] Operator --> Bound C2 --> Subset["Any additive adapter-visible fields require one explicit owner line"] @@ -56,7 +56,7 @@ flowchart TB - No inbound closeout or thread publication blocks this seam. `SEAM-1` remains the first contract-definition seam in the pack, so revalidation is against the current ADR + pre-planning basis rather than against upstream landed work. - The seam-local decomposition is now concrete enough to falsify the selection boundary and the downstream handoff. -- `C-01` now has a canonical baseline at `docs/contracts/substrate-gateway-backend-adapter-selection.md`. +- `C-01` now has a canonical baseline at `docs/contracts/gateway/backend-adapter-selection.md`. - `C-02` is now concrete enough for producer-seam readiness: v1 publishes no additive adapter-visible `status --json` field family beyond the existing `status` and `client_wiring.*` shape, and any future additive family must be introduced by the status-schema owner before runtime models widen. - `REM-005` remains material rather than blocking, but the stale ADR authority paths still need cleanup before the final handoff can be considered clean. - Readiness is not blocked: this seam has no inbound publication dependency, its owned-contract baseline is concrete in seam-local planning, and no open remediation currently blocks `status: exec-ready`. @@ -65,7 +65,7 @@ flowchart TB - **Review gate**: passed - **Contract gate**: passed - - `C-01` is anchored in `docs/contracts/substrate-gateway-backend-adapter-selection.md`. + - `C-01` is anchored in `docs/contracts/gateway/backend-adapter-selection.md`. - `C-02` is anchored in the current status-schema owner line: no additive adapter-visible field family is published in v1 beyond `status` and `client_wiring.*`. - **Revalidation gate**: passed - No inbound thread or closeout dependency exists for `SEAM-1`. @@ -80,7 +80,7 @@ flowchart TB ## Planned seam-exit gate focus - **What must be true before downstream promotion is legal**: - - `C-01` exists at `docs/contracts/substrate-gateway-backend-adapter-selection.md`. + - `C-01` exists at `docs/contracts/gateway/backend-adapter-selection.md`. - `C-02` keeps the v1 status boundary narrow: no additive adapter-visible field family ships until the status-schema owner explicitly publishes one. - `THR-01` is published from closeout with the final failure taxonomy and stale triggers recorded. - **Which outbound contracts/threads matter most**: diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/seam.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/seam.md index 4b0b5a228..f620807b4 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/seam.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/seam.md @@ -65,7 +65,7 @@ open_remediations: - **Verification**: - This seam **produces** `C-01` and `C-02`. - Readiness means the owned-contract baseline is concrete enough that downstream seams can execute against one backend-id truth, one failure taxonomy, and one status-publication boundary without reopening ADR-0027, the gateway operator contract, or the status schema owner line. - - The canonical `C-01` text now lives at `docs/contracts/substrate-gateway-backend-adapter-selection.md`. + - The canonical `C-01` text now lives at `docs/contracts/gateway/backend-adapter-selection.md`. - `C-02` is narrowed to the current v1 publication boundary: no additive adapter-visible `status --json` field family is published beyond `status` and `client_wiring.*`, and any future additive family requires an explicit status-schema update first. - **Basis posture**: - Currentness: diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md index 128f8140a..8b3da9594 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md @@ -46,9 +46,9 @@ Make the owned contract bundle concrete enough that downstream seams can cite on #### S00.T1 - Create the canonical `C-01` backend-selection baseline - **Outcome**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` exists and states the stable backend-id semantics, ordered evaluation inputs, one-id-to-one-adapter rule, and failure taxonomy before dispatch. + - `docs/contracts/gateway/backend-adapter-selection.md` exists and states the stable backend-id semantics, ordered evaluation inputs, one-id-to-one-adapter rule, and failure taxonomy before dispatch. - **Files**: - - `docs/contracts/substrate-gateway-backend-adapter-selection.md` + - `docs/contracts/gateway/backend-adapter-selection.md` - `../../contract.md` - `../../policy-spec.md` - **Thread/contract refs**: @@ -78,8 +78,8 @@ Checklist: - **Files**: - `../../contract.md` - `../../policy-spec.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/operator-contract.md` - **Thread/contract refs**: - `THR-01` - `C-02` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-2-status-owner-line-and-adr-authority-cleanup.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-2-status-owner-line-and-adr-authority-cleanup.md index 52c6bf0e8..ba0ed34c7 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-2-status-owner-line-and-adr-authority-cleanup.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-2-status-owner-line-and-adr-authority-cleanup.md @@ -37,8 +37,8 @@ Keep the now-recorded v1 status owner line aligned while repairing the stale ADR - `S00` defines the contract bundle and target owner surfaces - external authorities: - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/operator-contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` @@ -49,8 +49,8 @@ Keep the now-recorded v1 status owner line aligned while repairing the stale ADR - **Files**: - `../../contract.md` - `../../policy-spec.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/operator-contract.md` - **Thread/contract refs**: - `THR-01` - `C-02` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md index 74be560cd..7e62b0c0a 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md @@ -34,7 +34,7 @@ This slice plans the closeout-backed handoff that `SEAM-2` and `SEAM-3` must con - Update `../../governance/seam-1-closeout.md` with: - landed evidence for `C-01` and `C-02` - - the canonical `C-01` artifact path at `docs/contracts/substrate-gateway-backend-adapter-selection.md` + - the canonical `C-01` artifact path at `docs/contracts/gateway/backend-adapter-selection.md` - the explicit `C-02` owner line and bounded adapter-visible status field family - `THR-01` published-state evidence - any review-surface delta or stale triggers discovered during landing diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/review.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/review.md index e46b8c251..63829387c 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/review.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/review.md @@ -56,8 +56,8 @@ flowchart TB - The seam is safe to activate and decompose because the consumed upstream contract truth is now landed and current. - Review is concrete enough to falsify the intended lifecycle, schema, and owner-line shape. - The contract gate is now satisfied: - - `C-03` is pinned by `docs/contracts/substrate-gateway-backend-adapter-protocol.md` and `../../gateway-backend-adapter-protocol-spec.md`. - - `C-04` is pinned by `docs/contracts/substrate-gateway-backend-adapter-schema.md` and `../../gateway-backend-adapter-schema-spec.md`. + - `C-03` is pinned by `docs/contracts/gateway/backend-adapter-protocol.md` and `../../gateway-backend-adapter-protocol-spec.md`. + - `C-04` is pinned by `docs/contracts/gateway/backend-adapter-schema.md` and `../../gateway-backend-adapter-schema-spec.md`. - `REM-002` and `REM-003` remain open only as non-blocking execution and closeout tracking; they no longer block `status: exec-ready`. ## Pre-exec gate disposition diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md index f4d4fd057..01f849dd0 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md @@ -73,8 +73,8 @@ open_remediations: - This seam **produces** `C-03` and `C-04`. - The exact adopted Unified Agent API subset and the local-to-external ADR-0017 / ADR-0028 owner line are now concrete enough to execute without post-exec invention. - The durable contract baselines now live at: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - The seam-local execution baselines now live at: - `../../gateway-backend-adapter-protocol-spec.md` - `../../gateway-backend-adapter-schema-spec.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md index 8dfdd8b0c..a3d343099 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md @@ -54,7 +54,7 @@ Make the owned protocol/schema bundle concrete enough that downstream seams can - **Outcome**: - the seam-owned protocol surfaces state the deterministic adapter-dispatch lifecycle, fail-closed order, and the exact handoff boundary to ADR-0017 and ADR-0028. - **Files**: - - `docs/contracts/substrate-gateway-backend-adapter-protocol.md` + - `docs/contracts/gateway/backend-adapter-protocol.md` - `../../gateway-backend-adapter-protocol-spec.md` - `../../pre-planning/spec_manifest.md` - **Thread/contract refs**: @@ -71,7 +71,7 @@ Make the owned protocol/schema bundle concrete enough that downstream seams can Checklist: - Implement: - - author the deterministic dispatch-lifecycle baseline in `docs/contracts/substrate-gateway-backend-adapter-protocol.md` + - author the deterministic dispatch-lifecycle baseline in `docs/contracts/gateway/backend-adapter-protocol.md` - mirror the execution baseline and owner checklist in `../../gateway-backend-adapter-protocol-spec.md` - pin the exact owner-line handoff to ADR-0017 and ADR-0028 without widening those external owners - Test: @@ -87,7 +87,7 @@ Checklist: - **Outcome**: - the seam-owned schema surfaces state the exact adopted Unified Agent API subset for capability advertisement, extension keys, request/response payloads, bounded adapter errors, and session-handle facets. - **Files**: - - `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - `docs/contracts/gateway/backend-adapter-schema.md` - `../../gateway-backend-adapter-schema-spec.md` - `../../pre-planning/spec_manifest.md` - **Thread/contract refs**: @@ -104,7 +104,7 @@ Checklist: Checklist: - Implement: - - record the adopted schema subset and omission rules in `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - record the adopted schema subset and omission rules in `docs/contracts/gateway/backend-adapter-schema.md` - mirror the exact adopted capability ids, extension keys, bounded error shape, and session-handle facet in `../../gateway-backend-adapter-schema-spec.md` - Test: - compare the proposed subset against the Unified Agent API evidence set and current gateway docs diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-1-dispatch-lifecycle-and-owner-line.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-1-dispatch-lifecycle-and-owner-line.md index 850e7a6ed..a46bc81eb 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-1-dispatch-lifecycle-and-owner-line.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-1-dispatch-lifecycle-and-owner-line.md @@ -67,7 +67,7 @@ Checklist: - Implement: - document the ordered lifecycle and fail-closed checkpoints in `../../gateway-backend-adapter-protocol-spec.md` - - keep `docs/contracts/substrate-gateway-backend-adapter-protocol.md` as the durable owner of the lifecycle boundary + - keep `docs/contracts/gateway/backend-adapter-protocol.md` as the durable owner of the lifecycle boundary - document which upstream selection outputs are consumed as fixed inputs - Test: - compare the order against the seam review diagrams and pre-planning alignment notes diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-2-schema-subset-and-fail-closed-capability-rules.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-2-schema-subset-and-fail-closed-capability-rules.md index 916efc627..257da052c 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-2-schema-subset-and-fail-closed-capability-rules.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-2-schema-subset-and-fail-closed-capability-rules.md @@ -65,7 +65,7 @@ Checklist: - Implement: - record the supported capability and extension-key inventory in `../../gateway-backend-adapter-schema-spec.md` - - keep `docs/contracts/substrate-gateway-backend-adapter-schema.md` as the durable owner of the adopted subset + - keep `docs/contracts/gateway/backend-adapter-schema.md` as the durable owner of the adopted subset - record the fail-closed rules for unsupported requests - Test: - verify every supported item is named explicitly against: diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md index b50f522d8..29f0192da 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md @@ -36,7 +36,7 @@ This slice plans the closeout-backed handoff that `SEAM-3` must consume before p - Update `../../governance/seam-2-closeout.md` with: - landed evidence for `C-03` and `C-04` - - canonical artifact paths for `docs/contracts/substrate-gateway-backend-adapter-protocol.md` and `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - canonical artifact paths for `docs/contracts/gateway/backend-adapter-protocol.md` and `docs/contracts/gateway/backend-adapter-schema.md` - a `THR-02` publication-state entry captured at closeout time - the final local-to-external owner line for ADR-0017 and ADR-0028 - the adopted capability, extension-key, payload, error, and session-handle schema subset diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md index 6478d3872..2a5ed2a67 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md @@ -29,7 +29,7 @@ This artifact feeds `gates.pre_exec.review`. - Contract consumption is concrete enough to plan because the seam consumes accepted upstream truth rather than owning a new public contract baseline. - ADR-0040 posture is now explicit: - ADR-0040 remains the prerequisite boundary owner for Substrate versus `substrate-gateway` runtime ownership. - - `SEAM-3` consumes that owner line through ADR-0041 and `docs/contracts/substrate-gateway-runtime-parity.md` instead of reopening ADR-0040 as a direct touch surface. + - `SEAM-3` consumes that owner line through ADR-0041 and `docs/contracts/gateway/runtime-parity.md` instead of reopening ADR-0040 as a direct touch surface. - The seam should reopen ADR-0040 only if landing evidence uncovers a concrete ownership drift that the current owner line no longer explains. - `REM-004` is resolved by recording that evidence-only posture in seam-local planning, so it no longer blocks `status: exec-ready`. diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md index 7709842da..e79492b3d 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md @@ -65,13 +65,13 @@ This seam is closed. Its authoritative exit-gate record lives in `../../governan - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md` - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/ci_checkpoint_plan.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Verification**: - This seam consumes `C-01` through `C-04` from `../../governance/seam-1-closeout.md` and `../../governance/seam-2-closeout.md`. - `THR-01` and `THR-02` are now published inbound threads for this seam. - ADR-0040 now stays explicit evidence-only basis for this seam: - ADR-0040 remains the owner of the Substrate versus `substrate-gateway` runtime boundary. - - ADR-0041 and `docs/contracts/substrate-gateway-runtime-parity.md` carry the downstream consequences that this seam must prove. + - ADR-0041 and `docs/contracts/gateway/runtime-parity.md` carry the downstream consequences that this seam must prove. - direct ADR-0040 edits stay out of scope unless landing evidence uncovers a concrete owner-line mismatch. ## Review bundle diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-1-platform-parity-and-runtime-boundary.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-1-platform-parity-and-runtime-boundary.md index e5b10a479..2d539a8fe 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-1-platform-parity-and-runtime-boundary.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-1-platform-parity-and-runtime-boundary.md @@ -56,10 +56,10 @@ Define the Linux/macOS/Windows guarantee matrix and the runtime-boundary proof t #### S1.T2 - Lock the runtime-boundary proof - **Outcome**: - - parity proof names the runtime-boundary evidence that must align with `docs/contracts/substrate-gateway-runtime-parity.md`. + - parity proof names the runtime-boundary evidence that must align with `docs/contracts/gateway/runtime-parity.md`. - **Files**: - `../../platform-parity-spec.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Acceptance criteria**: - no second Substrate control plane is introduced - runtime-boundary validation cites upstream truth rather than restating it diff --git a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md index 0ed091b72..b4fd0cf44 100644 --- a/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md +++ b/docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md @@ -24,7 +24,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: gateway adapter docs, policy review, and any future backend inventory or allowlist validation surfaces - **Thread IDs**: `THR-01` - **Definition**: the stable `:` backend-id contract, ordered config/policy/inventory evaluation, and the invalid-selection versus dependency-unavailable versus policy-denied classification used before adapter dispatch. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-selection.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-selection.md` - **Versioning / compat**: the backend-id grammar, deny-by-default posture, one-backend-id-to-one-adapter-identity rule, and failure taxonomy must remain stable for future `cli:*` and `api:*` adapters. - **Contract ID**: `C-02` @@ -34,7 +34,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: `status --json` readers, operator docs, tests, and later gateway capability publication work - **Thread IDs**: `THR-01` - **Definition**: the publication boundary for any additive adapter-visible gateway status metadata while preserving the existing `status --json` envelope and `client_wiring.*` owner line. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-status-schema.md` + - **Canonical contract ref**: `docs/contracts/gateway/status-schema.md` - **Versioning / compat**: no new adapter-visible field family may ship without an explicit owner line; existing `status --json` semantics remain externally owned and must stay backward-compatible. - **Contract ID**: `C-03` @@ -44,7 +44,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: `substrate-gateway`, shared client helpers, event/trace review, and future adapter harness implementations - **Thread IDs**: `THR-02` - **Definition**: the selected-backend to adapter-dispatch lifecycle, capability-validation order, request normalization and response emission ordering, and the exact handoff boundary between local adapter translation and externally owned ADR-0017 / ADR-0028 semantics. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-protocol.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-protocol.md` - **Versioning / compat**: unsupported capabilities and extension keys must fail closed, and the protocol may evolve only through explicit versioned contract changes that preserve the stable backend-id boundary. - **Contract ID**: `C-04` @@ -54,7 +54,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: adapter implementations, validation artifacts, and any future durable schema publication - **Thread IDs**: `THR-02` - **Definition**: the adopted Unified Agent API subset for capability advertisement, versioned extension keys, request and response payloads, adapter error objects, and backend-defined session-handle facets. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-backend-adapter-schema.md` + - **Canonical contract ref**: `docs/contracts/gateway/backend-adapter-schema.md` - **Versioning / compat**: field names, defaults, omission rules, and bounded error detail must stay explicit and additive; session-handle facets remain gateway-contract data rather than Substrate policy input. ## Thread registry diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/remediation-log.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/remediation-log.md index 882e704d4..66902c8fa 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/remediation-log.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/remediation-log.md @@ -51,7 +51,7 @@ Additional remediation rules for this pack: resolution_evidence: - `8c0bd439` landed the S1 typed runtime boundary across `crates/transport-api-types/src/lib.rs`, `crates/transport-api-client/src/lib.rs`, `crates/world-service/src/handlers.rs`, `crates/world-service/src/service.rs`, `crates/shell/src/builtins/world_gateway.rs`, and the corresponding runtime parity and shell gateway tests - `4511b3a5` landed the S2 parity evidence update in `docs/WORLD.md` without widening the operator contract - - `docs/contracts/substrate-gateway-runtime-parity.md` remains the durable canonical `C-04` contract without planning IDs + - `docs/contracts/gateway/runtime-parity.md` remains the durable canonical `C-04` contract without planning IDs - `cargo test -p transport-api-client -- --nocapture` passed `13/13` tests plus `0` doc tests on the current tree - `cargo test -p world-service --test gateway_runtime_parity -- --nocapture` completed successfully on the current tree; the `3/3` target-local route-shape tests passed and the runtime-dependent service cases self-skipped on this host after `WorldService::new()` reported Linux/VM-only support - `cargo test -p shell --test world_gateway -- --nocapture` passed `8/8` tests on the current tree diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-1-closeout.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-1-closeout.md index 2b00d20d5..5bfb8cb00 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-1-closeout.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-1-closeout.md @@ -29,7 +29,7 @@ This is the seam-exit closeout for the committed operator boundary contract. The - **Source artifact**: `../threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md` - **Landed evidence**: - Feature-local contract publication: `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md` - - Durable operator contract publication: `docs/contracts/substrate-gateway-operator-contract.md` + - Durable operator contract publication: `docs/contracts/gateway/operator-contract.md` - Thread publication: `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md` (`THR-01`) - Runtime/readback surfaces confirming the landed contract: - `crates/shell/src/execution/cli.rs` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-2-closeout.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-2-closeout.md index 6b119b1c7..6b6f0eb26 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-2-closeout.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-2-closeout.md @@ -36,9 +36,9 @@ This closeout records the landed SEAM-2 exit state after the schema and policy s - `b1de7e51` - completed S00 contract-definition work for the seam boundary and durable contract mirrors - `407eacf9` - completed S1 status-schema boundary and `client_wiring.*` publication - `2dddf13d` - completed S2 policy-evaluation and trust-boundary publication - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md` - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md` - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-3-closeout.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-3-closeout.md index 470483dad..6f04d704f 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-3-closeout.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-3-closeout.md @@ -40,7 +40,7 @@ This closeout records the landed SEAM-3 exit state after the typed runtime bound - **Landed evidence**: - `8c0bd439` - completed S1 typed runtime boundary across shared API types, shared client helpers, world-service gateway routes, and shell gateway consumption/tests - `4511b3a5` - completed S2 parity evidence updates in `docs/WORLD.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `crates/transport-api-types/src/lib.rs` - `crates/transport-api-client/src/lib.rs` - `crates/world-service/src/handlers.rs` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-1-operator-boundary-and-command-contract.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-1-operator-boundary-and-command-contract.md index 4683ddb74..ffe199d29 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-1-operator-boundary-and-command-contract.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-1-operator-boundary-and-command-contract.md @@ -100,7 +100,7 @@ open_remediations: [] - exit `2`, `3`, `4`, and `5` are distinguished cleanly - the stable env names and `status --json` authority rule stay synchronized - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` - **Risks / unknowns**: - Risk: - archived planning still carries alternate command ordering and older ownership assumptions diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-2-status-schema-and-policy-evaluation-surface.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-2-status-schema-and-policy-evaluation-surface.md index 9fd7fca6f..164c489fd 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-2-status-schema-and-policy-evaluation-surface.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-2-status-schema-and-policy-evaluation-surface.md @@ -96,8 +96,8 @@ open_remediations: [] - ADR-0042 additive metadata stays out of the owned field family - invalid integration state, dependency unavailability, and policy denial are distinguished cleanly - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Risks / unknowns**: - Risk: - the machine-readable status shape can drift away from the operator contract or from later shared client types diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-3-typed-runtime-and-platform-parity.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-3-typed-runtime-and-platform-parity.md index 08d70a728..cee97db76 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-3-typed-runtime-and-platform-parity.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-3-typed-runtime-and-platform-parity.md @@ -93,17 +93,17 @@ open_remediations: [] - `docs/WORLD.md` - **Verification**: - This seam consumes upstream contracts `C-01`, `C-02`, and `C-03`; verification may depend on accepted upstream evidence for command behavior, status schema, and fail-closed policy rules. - - This seam produces owned contract `C-04`. The contract baseline and owner execution checklist now live in `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md`, `docs/contracts/substrate-gateway-runtime-parity.md`, and the threaded `S00` owner slice, so the remaining work is execution and publication rather than pre-exec contract discovery. + - This seam produces owned contract `C-04`. The contract baseline and owner execution checklist now live in `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md`, `docs/contracts/gateway/runtime-parity.md`, and the threaded `S00` owner slice, so the remaining work is execution and publication rather than pre-exec contract discovery. - Later seam-local verification should prove: - the typed world-service path is authoritative for lifecycle/status operations - shell and shared clients consume the same runtime contract - Linux, macOS, and Windows guarantees are explicit and testable - provisioning remains correctly deferred outside this pack - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - **Risks / unknowns**: - Risk: - typed runtime ownership can drift back toward shell-assembled probing diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-4-validation-and-cross-doc-lock-in.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-4-validation-and-cross-doc-lock-in.md index 74f8b9b30..147ce373e 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-4-validation-and-cross-doc-lock-in.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-4-validation-and-cross-doc-lock-in.md @@ -100,10 +100,10 @@ open_remediations: [] - docs/CONFIGURATION, docs/USAGE, docs/WORLD, and docs/TRACE reflect the same truth - `plan.md`, `tasks.json`, and checkpoint boundaries match the accepted planning spine and landed seam ordering - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - **Risks / unknowns**: - Risk: - docs and quality-gate artifacts can lag the landed contract wording even when implementation is correct diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/seam.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/seam.md index 2f51ac992..1416a089c 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/seam.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/seam.md @@ -64,7 +64,7 @@ open_remediations: [] - `C-01` is concrete enough for execution because `S00` names the exact command family, status entrypoint rule, stable env semantics, exit taxonomy, ownership table, and the verification surfaces that later slices must update together. - The producer seam does not require its own final accepted contract artifact as a pre-exec input; publication and accepted evidence are handled through `S99` and closeout. - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` - **Basis posture**: - Currentness: `current` - Upstream closeouts assumed: none @@ -75,7 +75,7 @@ open_remediations: [] - Downstream blocked seams: `SEAM-2`, `SEAM-3`, `SEAM-4` - Contracts produced: `C-01` - Contracts consumed: none - - Canonical contract refs: `docs/contracts/substrate-gateway-operator-contract.md` + - Canonical contract refs: `docs/contracts/gateway/operator-contract.md` ## Review bundle diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-00-operator-contract-definition.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-00-operator-contract-definition.md index b93236b64..f1c684f75 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-00-operator-contract-definition.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-00-operator-contract-definition.md @@ -76,7 +76,7 @@ open_remediations: [] - `crates/shell/src/execution/cli.rs`, `crates/shell/src/builtins/mod.rs`, and `crates/shell/src/builtins/world_gateway.rs` enforce one command family and one status entrypoint. - `crates/shell/tests/world_gateway.rs` protects command spelling, absent-state behavior, and exit taxonomy. - `docs/USAGE.md` matches the contract wording without redefining the machine-readable surface. - - the durable contract reference remains `docs/contracts/substrate-gateway-operator-contract.md`. + - the durable contract reference remains `docs/contracts/gateway/operator-contract.md`. #### S00.T1 - Record the concrete operator contract for `C-01` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md index a975d3739..82c620b94 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md @@ -43,7 +43,7 @@ open_remediations: [] - re-run the targeted CLI/docs/test checks cited by `S1` and `S2` - verify ADR and pack-root publication surfaces in `S3` match the landed operator contract - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` - **Review surface refs**: `../../review_surfaces.md` #### S99.T1 - Record `C-01` and `THR-01` publication in closeout diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-99-seam-exit-gate.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-99-seam-exit-gate.md index 7bd17def5..5f33b7b73 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-99-seam-exit-gate.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-99-seam-exit-gate.md @@ -43,6 +43,6 @@ open_remediations: [] - **Verification**: - rerun targeted schema, policy, docs, and test checks cited by the implementation slices - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Review surface refs**: `review.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/review.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/review.md index 8224e2385..d013d2d3b 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/review.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/review.md @@ -47,7 +47,7 @@ flowchart TB - `../../governance/seam-1-closeout.md` publishes the operator boundary consumed by this seam. - `../../governance/seam-2-closeout.md` publishes the status-schema and policy threads this seam depends on. -- The owned runtime/parity contract baseline is not yet concrete enough for execution because both `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md` and `docs/contracts/substrate-gateway-runtime-parity.md` are still missing. +- The owned runtime/parity contract baseline is not yet concrete enough for execution because both `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md` and `docs/contracts/gateway/runtime-parity.md` are still missing. ## Pre-exec gate disposition diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/seam.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/seam.md index e0f5f9dcc..cec57d3c0 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/seam.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/seam.md @@ -58,7 +58,7 @@ open_remediations: [] - cross-doc/manual-playbook lock-in and checkpoint wiring - **Touch surface**: - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - `crates/world-service/src/handlers.rs` - `crates/world-service/src/service.rs` - `crates/transport-api-types/src/lib.rs` @@ -67,7 +67,7 @@ open_remediations: [] - `docs/WORLD.md` - **Verification**: - This seam consumes upstream contracts `C-01`, `C-02`, and `C-03`; those inputs are now published by `../../governance/seam-1-closeout.md` and `../../governance/seam-2-closeout.md`. - - This seam produces owned contract `C-04`. The contract baseline and owner execution checklist now exist in `S00`, `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md`, and `docs/contracts/substrate-gateway-runtime-parity.md`, so the remaining work is runtime implementation and publication evidence rather than pre-exec contract definition. + - This seam produces owned contract `C-04`. The contract baseline and owner execution checklist now exist in `S00`, `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md`, and `docs/contracts/gateway/runtime-parity.md`, so the remaining work is runtime implementation and publication evidence rather than pre-exec contract definition. - Later seam-local verification should prove: - the typed world-service path is authoritative for lifecycle/status operations - shell and shared clients consume the same runtime contract diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-00-runtime-parity-contract-definition.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-00-runtime-parity-contract-definition.md index 40ee54a66..32e7f30c4 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-00-runtime-parity-contract-definition.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-00-runtime-parity-contract-definition.md @@ -52,7 +52,7 @@ open_remediations: - `../../governance/seam-1-closeout.md` - `../../governance/seam-2-closeout.md` - **Verification**: - - the contract-definition bundle must map directly to `platform-parity-spec.md`, `docs/contracts/substrate-gateway-runtime-parity.md`, seam-local review, and later runtime/parity implementation surfaces + - the contract-definition bundle must map directly to `platform-parity-spec.md`, `docs/contracts/gateway/runtime-parity.md`, seam-local review, and later runtime/parity implementation surfaces - **Rollout/safety**: - keep provisioning out of scope and keep raw exec probing out of the operator contract - **Review surface refs**: `review.md` R1 and R2 @@ -83,7 +83,7 @@ These are the binding contract statements this seam must implement and later pub - **Doc surfaces to publish and keep aligned**: - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Code surfaces that must land against this contract**: - `crates/world-service/src/lib.rs` - `crates/transport-api-types/src/lib.rs` @@ -109,7 +109,7 @@ These are the binding contract statements this seam must implement and later pub - **Outcome**: `C-04` is concrete in both the feature-local parity spec and the durable contract mirror. - **Inputs/outputs**: - Inputs: `../../threading.md`, `../../governance/seam-1-closeout.md`, `../../governance/seam-2-closeout.md`, `docs/WORLD.md`, `docs/INSTALLATION.md`, and the current shell/world-service transport surfaces - - Outputs: aligned `platform-parity-spec.md` and `docs/contracts/substrate-gateway-runtime-parity.md` + - Outputs: aligned `platform-parity-spec.md` and `docs/contracts/gateway/runtime-parity.md` - **Thread/contract refs**: `THR-04`, `C-04` - **Acceptance criteria**: - the typed runtime authority boundary is explicit diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-1-typed-lifecycle-status-api-boundary.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-1-typed-lifecycle-status-api-boundary.md index d3ff21747..568e03a1d 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-1-typed-lifecycle-status-api-boundary.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-1-typed-lifecycle-status-api-boundary.md @@ -48,8 +48,8 @@ candidate_subslices: [] - **Dependencies**: - `review.md` - `../../governance/seam-2-closeout.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` - **Verification**: - pass condition: runtime planning can name one authoritative lifecycle/status path without reopening schema or policy truth - **Rollout/safety**: diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-2-shell-consumption-and-platform-parity-evidence.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-2-shell-consumption-and-platform-parity-evidence.md index 395d9798c..125d8bb2a 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-2-shell-consumption-and-platform-parity-evidence.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-2-shell-consumption-and-platform-parity-evidence.md @@ -49,8 +49,8 @@ candidate_subslices: [] - `review.md` - `../../governance/seam-1-closeout.md` - `../../governance/seam-2-closeout.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/runtime-parity.md` - **Verification**: - pass condition: parity planning can describe one operator-facing runtime contract and one evidence model across Linux, macOS, and Windows - **Rollout/safety**: diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-99-seam-exit-gate.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-99-seam-exit-gate.md index 4168cfed0..182c5c727 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-99-seam-exit-gate.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-99-seam-exit-gate.md @@ -43,5 +43,5 @@ open_remediations: [] - **Verification**: - rerun targeted runtime, parity, docs, and test checks cited by the implementation slices - **Canonical contract refs**: - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Review surface refs**: `review.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-1-manual-validation-and-owner-surface-audit.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-1-manual-validation-and-owner-surface-audit.md index ba702d358..5c1528cb6 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-1-manual-validation-and-owner-surface-audit.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-1-manual-validation-and-owner-surface-audit.md @@ -51,10 +51,10 @@ open_remediations: [] - `../../governance/seam-1-closeout.md` - `../../governance/seam-2-closeout.md` - `../../governance/seam-3-closeout.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - **Verification**: - pass condition: the manual playbook can be read as a contract-consumption checklist without inventing new ownership language - **Rollout/safety**: diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-2-operator-docs-and-trace-alignment.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-2-operator-docs-and-trace-alignment.md index 9d48686eb..fef6c727e 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-2-operator-docs-and-trace-alignment.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-2-operator-docs-and-trace-alignment.md @@ -50,10 +50,10 @@ open_remediations: [] - trace documentation preserves Substrate-owned canonical tracing authority - **Dependencies**: - `review.md` - - `docs/contracts/substrate-gateway-operator-contract.md` - - `docs/contracts/substrate-gateway-status-schema.md` - - `docs/contracts/substrate-gateway-policy-evaluation.md` - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/operator-contract.md` + - `docs/contracts/gateway/status-schema.md` + - `docs/contracts/gateway/policy-evaluation.md` + - `docs/contracts/gateway/runtime-parity.md` - `../../governance/seam-1-closeout.md` - `../../governance/seam-2-closeout.md` - `../../governance/seam-3-closeout.md` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md index 7011c17d3..aad35746c 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md @@ -31,7 +31,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: operators, shell builtins, docs, and downstream validation artifacts - **Thread IDs**: `THR-01` - **Definition**: the Substrate-owned operator boundary for `substrate world gateway sync`, `status`, and `restart`, including absent-state behavior, stable wiring entrypoint rules, stable non-secret env outputs, exit-code boundaries, and the durable ownership split against `substrate-gateway`. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-operator-contract.md` + - **Canonical contract ref**: `docs/contracts/gateway/operator-contract.md` - **Versioning / compat**: command spelling, exit-code mapping, stable env names, and the rule that `status --json` is the machine-readable wiring authority must remain stable; additive operator prose must not redefine these semantics. - **Contract ID**: `C-02` @@ -41,7 +41,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: operator docs, tests, and any world-internal clients that consume the stable wiring surface - **Thread IDs**: `THR-02` - **Definition**: the structured output contract for `substrate world gateway status --json`, including the top-level object shape, `client_wiring.*` field family, non-secret posture, conditional presence rules, and the hard boundary against ADR-0042 additive metadata outside that family. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-status-schema.md` + - **Canonical contract ref**: `docs/contracts/gateway/status-schema.md` - **Versioning / compat**: field names, omission rules, and `client_wiring.*` semantics must remain compatible; additive fields require downstream revalidation when they touch operator-facing meaning. - **Contract ID**: `C-03` @@ -51,7 +51,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: policy explanations, platform parity docs, and manual validation artifacts - **Thread IDs**: `THR-03` - **Definition**: the gateway-integration decision flow over existing ADR-0027 inputs, including fail-closed in-world placement, host secret sourcing and host-to-world secret delivery boundaries, distinction between invalid integration state and dependency unavailability, and the ban on trusting gateway-local config/admin/persistence as policy inputs. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-policy-evaluation.md` + - **Canonical contract ref**: `docs/contracts/gateway/policy-evaluation.md` - **Versioning / compat**: reused key paths stay externally owned, but the decision taxonomy and no-host-fallback rule must remain stable; changes require runtime and docs revalidation. - **Contract ID**: `C-04` @@ -61,7 +61,7 @@ Horizon policy for this extracted pack: - **Derived consumers**: shell builtins, shared agent API clients, parity docs, and quality-gate evidence - **Thread IDs**: `THR-04` - **Definition**: the typed world-service lifecycle/status contract and the Linux/macOS/Windows parity guarantees that let CLI behavior stay stable without raw exec probing or platform-specific operator contracts. - - **Canonical contract ref**: `docs/contracts/substrate-gateway-runtime-parity.md` + - **Canonical contract ref**: `docs/contracts/gateway/runtime-parity.md` - **Versioning / compat**: endpoint ownership, lifecycle/status semantics, allowed divergence, and required validation evidence must stay synchronized across host and backend consumers. ## Thread registry @@ -103,7 +103,7 @@ Horizon policy for this extracted pack: - **Purpose**: publish the typed lifecycle/status transport and parity evidence contract that cross-doc validation and quality-gate work will lock in. - **State**: `revalidated` - **Revalidation trigger**: typed world-service endpoint shape, shell/client integration path, allowed divergence list, or Linux/macOS/Windows evidence requirements change. - - **Satisfied by**: `governance/seam-3-closeout.md` records the landed `C-04` publication, the S1 typed runtime boundary in `8c0bd439`, the S2 parity evidence update in `4511b3a5`, the durable contract mirror in `docs/contracts/substrate-gateway-runtime-parity.md`, and the targeted verification reruns for the shared client, the `gateway_runtime_parity` target-local route-shape tests, and the shell gateway tests; host-local runtime-dependent `world-service` cases self-skipped outside Linux/VM support. `threaded-seams/seam-4-validation-and-cross-doc-lock-in/review.md` revalidates that handoff for the active conformance seam. + - **Satisfied by**: `governance/seam-3-closeout.md` records the landed `C-04` publication, the S1 typed runtime boundary in `8c0bd439`, the S2 parity evidence update in `4511b3a5`, the durable contract mirror in `docs/contracts/gateway/runtime-parity.md`, and the targeted verification reruns for the shared client, the `gateway_runtime_parity` target-local route-shape tests, and the shell gateway tests; host-local runtime-dependent `world-service` cases self-skipped outside Linux/VM support. `threaded-seams/seam-4-validation-and-cross-doc-lock-in/review.md` revalidates that handoff for the active conformance seam. - **Notes**: this thread now carries the revalidated typed lifecycle/status and parity-evidence contract into `SEAM-4`. Provisioning changes remain out of scope for this pack and were not pulled into the published contract. ## Dependency graph diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md index 59c8c7e07..70065a7eb 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md @@ -1,6 +1,6 @@ # substrate-gateway-boundary-and-runtime-ownership — contract surface -This file mirrors the committed operator contract in `docs/contracts/substrate-gateway-operator-contract.md` +This file mirrors the committed operator contract in `docs/contracts/gateway/operator-contract.md` and keeps the feature-local publication surface aligned to the live source of truth for the operator boundary and the owned contract refs for `C-02` and `C-03`. @@ -45,22 +45,22 @@ Publication surfaces: - this feature-local contract file - the durable operator contract reference under `docs/contracts/` -- `docs/contracts/substrate-gateway-status-schema.md` -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/policy-evaluation.md` - later-slice publication and verification surfaces: - `crates/shell/src/execution/cli.rs` - `crates/shell/src/builtins/mod.rs` - `crates/shell/src/builtins/world_gateway.rs` - `crates/shell/tests/world_gateway.rs` - `docs/USAGE.md` - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` Verification surfaces: - the operator contract must stay aligned with ADR-0040 and the committed operator contract reference - downstream implementation work must preserve the command family, JSON authority rule, stable env semantics, exit taxonomy, and ownership split without widening this contract into schema or runtime details -- `C-02` is published through `docs/contracts/substrate-gateway-status-schema.md` -- `C-03` is published through `docs/contracts/substrate-gateway-policy-evaluation.md` +- `C-02` is published through `docs/contracts/gateway/status-schema.md` +- `C-03` is published through `docs/contracts/gateway/policy-evaluation.md` - the later-slice proof surfaces listed above are publication and verification targets for subsequent slices, not implementation targets for this slice ## Boundaries diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md index da53217e6..45d066af6 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md @@ -52,7 +52,7 @@ Rules: The schema boundary is published through: - this feature-local spec -- `docs/contracts/substrate-gateway-status-schema.md` +- `docs/contracts/gateway/status-schema.md` - later implementation and verification slices ## Required contract statements diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/manual_testing_playbook.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/manual_testing_playbook.md index 5fd0229eb..47fb6b9b9 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/manual_testing_playbook.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/manual_testing_playbook.md @@ -5,10 +5,10 @@ It is a consumer of the landed contracts below and does not redefine them. ## Contracts consumed -- `docs/contracts/substrate-gateway-operator-contract.md` - operator command family and exit taxonomy -- `docs/contracts/substrate-gateway-status-schema.md` - machine-readable gateway status wiring surface -- `docs/contracts/substrate-gateway-policy-evaluation.md` - policy evaluation and trust boundary -- `docs/contracts/substrate-gateway-runtime-parity.md` - typed runtime boundary and platform parity +- `docs/contracts/gateway/operator-contract.md` - operator command family and exit taxonomy +- `docs/contracts/gateway/status-schema.md` - machine-readable gateway status wiring surface +- `docs/contracts/gateway/policy-evaluation.md` - policy evaluation and trust boundary +- `docs/contracts/gateway/runtime-parity.md` - typed runtime boundary and platform parity ## One-owner-per-surface audit @@ -16,7 +16,7 @@ Use this checklist to confirm each operator-visible surface has one landed owner ### 1) Operator command family -Validate that the gateway command family is owned only by `docs/contracts/substrate-gateway-operator-contract.md`. +Validate that the gateway command family is owned only by `docs/contracts/gateway/operator-contract.md`. Check: - The playbook treats `substrate world gateway sync`, `substrate world gateway status`, `substrate world gateway restart`, and `substrate world gateway status --json` as one operator surface. @@ -31,7 +31,7 @@ Pass condition: ### 2) Machine-readable status wiring -Validate that the JSON wiring surface is owned only by `docs/contracts/substrate-gateway-status-schema.md`. +Validate that the JSON wiring surface is owned only by `docs/contracts/gateway/status-schema.md`. Check: - `substrate world gateway status --json` is treated as the authoritative machine-readable wiring discovery surface. @@ -44,7 +44,7 @@ Pass condition: ### 3) Policy evaluation and trust boundary -Validate that policy and trust boundary rules are owned only by `docs/contracts/substrate-gateway-policy-evaluation.md`. +Validate that policy and trust boundary rules are owned only by `docs/contracts/gateway/policy-evaluation.md`. Check: - The playbook keeps fail-closed behavior, host-to-world secret delivery, and trust-boundary rules under the policy contract. @@ -57,7 +57,7 @@ Pass condition: ### 4) Runtime and platform parity -Validate that typed lifecycle/status runtime behavior and platform parity are owned only by `docs/contracts/substrate-gateway-runtime-parity.md`. +Validate that typed lifecycle/status runtime behavior and platform parity are owned only by `docs/contracts/gateway/runtime-parity.md`. Check: - The playbook treats shell and world-service runtime interaction as a typed boundary, not raw probing or log scraping. diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md index 350283e41..e34acf0b0 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md @@ -16,9 +16,9 @@ Owned here: Not owned here: -- the operator command family or exit taxonomy already owned by `docs/contracts/substrate-gateway-operator-contract.md` -- the `status --json` envelope or `client_wiring.*` field family already owned by `docs/contracts/substrate-gateway-status-schema.md` -- fail-closed policy, secret delivery, or trust-boundary rules already owned by `docs/contracts/substrate-gateway-policy-evaluation.md` +- the operator command family or exit taxonomy already owned by `docs/contracts/gateway/operator-contract.md` +- the `status --json` envelope or `client_wiring.*` field family already owned by `docs/contracts/gateway/status-schema.md` +- fail-closed policy, secret delivery, or trust-boundary rules already owned by `docs/contracts/gateway/policy-evaluation.md` - provisioning changes, warm-flow orchestration, or gateway-internal provider/planner/executor behavior ## Required platforms @@ -53,7 +53,7 @@ Not owned here: - **Doc publication surfaces**: - this feature-local parity spec - - `docs/contracts/substrate-gateway-runtime-parity.md` + - `docs/contracts/gateway/runtime-parity.md` - **Code surfaces that later slices must implement against**: - `crates/world-service/src/lib.rs` - `crates/transport-api-types/src/lib.rs` diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md index 7cb2f4b08..d2808e641 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md @@ -41,7 +41,7 @@ Not owned here: The policy boundary is published through: - this feature-local spec -- `docs/contracts/substrate-gateway-policy-evaluation.md` +- `docs/contracts/gateway/policy-evaluation.md` - later implementation and verification slices ## Required contract statements diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/impact_map.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/impact_map.md index c3bc0cfec..a835f6c86 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/impact_map.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/impact_map.md @@ -241,7 +241,7 @@ List overlaps/conflicts with other in-flight work and resolve them deterministic - status JSON ownership - Conflict: yes - Resolution (explicit): - - Treat the archived pack as historical evidence only; the live operator contract is `docs/contracts/substrate-gateway-operator-contract.md`. + - Treat the archived pack as historical evidence only; the live operator contract is `docs/contracts/gateway/operator-contract.md`. - Carry forward only the stable wiring env names and the in-world gateway intent. - Do not carry forward Substrate-owned gateway runtime crates, archived command ordering, or archived transport details as current contract. diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/minimal_spec_draft.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/minimal_spec_draft.md index 28d04d8db..db686112e 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/minimal_spec_draft.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/minimal_spec_draft.md @@ -13,7 +13,7 @@ - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO0/SGBRO0-spec.md` - External source-of-truth ownership remains with: - ADR-0027 and `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/*` for config and policy schema ownership - - `docs/contracts/substrate-gateway-operator-contract.md` for the committed operator boundary wording + - `docs/contracts/gateway/operator-contract.md` for the committed operator boundary wording - ADR-0017 for structured event routing and output-class separation - ADR-0028 for canonical trace vocabulary and correlation semantics - ADR-0041 for gateway runtime internals and backend-adapter identity diff --git a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/spec_manifest.md b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/spec_manifest.md index 408a7925d..6c062d5a1 100644 --- a/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/spec_manifest.md +++ b/docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/spec_manifest.md @@ -15,7 +15,7 @@ Authoring standards: - Related authoritative contracts that remain external to this pack: - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - - `docs/contracts/substrate-gateway-operator-contract.md` + - `docs/contracts/gateway/operator-contract.md` - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/llm-last-mile/14-secret-handoff-into-the-world-gateway.md b/llm-last-mile/14-secret-handoff-into-the-world-gateway.md index a86849469..5ae5c99cb 100644 --- a/llm-last-mile/14-secret-handoff-into-the-world-gateway.md +++ b/llm-last-mile/14-secret-handoff-into-the-world-gateway.md @@ -38,7 +38,7 @@ That means the integrated path currently satisfies policy and lifecycle requirem - [ADR-0023](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md:72) records the additive upgrade from legacy env injection to FD/pipe auth-bundle delivery. - [ADR-0040](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md:82) keeps host-to-world secret delivery explicitly Substrate-owned. -- [Substrate Gateway Policy Evaluation](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md:33) already says the carrier should move away from env-based delivery by default. +- [Substrate Gateway Policy Evaluation](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md:33) already says the carrier should move away from env-based delivery by default. - [DR-0018](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md:683) explicitly selects the auth-bundle FD/pipe direction. - [Secrets Delivery Channel Rubric](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/standards/shared/SECRETS_DELIVERY_CHANNEL_RUBRIC.md:36) says FD/pipe is the default when Substrate spawns both endpoints. @@ -104,8 +104,8 @@ This is the exact seam that must change. ### Operator and policy contracts that must remain true -- [docs/contracts/substrate-gateway-operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-operator-contract.md:7) -- [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md:25) +- [docs/contracts/gateway/operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/operator-contract.md:7) +- [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md:25) This SOW must preserve those contracts while changing only the durable secret carrier between `world-agent` and the in-world gateway process. @@ -258,7 +258,7 @@ This slice should not move secret sourcing into the gateway or into gateway-loca ### 5. Preserve invalid-integration, dependency-unavailable, and policy-denial distinctions -The current gateway policy contract already requires those buckets to remain distinct in [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md:38). +The current gateway policy contract already requires those buckets to remain distinct in [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md:38). The auth-bundle work must preserve that separation for cases such as: diff --git a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md index 862ca25fa..5b8de6f98 100644 --- a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md +++ b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md @@ -43,7 +43,7 @@ The following keep their current upstream meaning and are not renamed here: - crates.io package `unified-agent-api` - Rust import name `agent_api` -- adopted capability/schema ids such as `agent_api.run`, `agent_api.session.resume.v1`, and `agent_api.session.handle.v1` documented in [docs/contracts/substrate-gateway-backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-schema.md:21) +- adopted capability/schema ids such as `agent_api.run`, `agent_api.session.resume.v1`, and `agent_api.session.handle.v1` documented in [docs/contracts/gateway/backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-schema.md:21) - surfaced internal correlation fields such as `internal.uaa_session_id` / `uaa_session_id`, which remain internal and correctly describe upstream session-handle identity in [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md:120) and [ADR-0047](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md:210) This slice does not rename upstream `agent_api` under any spelling. The rename target is only the pre-UAA local transport naming. @@ -90,7 +90,7 @@ This SOW assumes the following are already true and are not being redesigned her - `crates/shell` already depends on the real external Unified Agent API as `agent_api` in [crates/shell/Cargo.toml](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/Cargo.toml:61). - `crates/world-agent` also already depends on the real external Unified Agent API for member runtime launch/control. - `world-api` already owns the abstract world backend contract and is not part of this rename. -- The local typed host↔world transport remains a separate boundary documented today in [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:237) and [docs/contracts/substrate-gateway-runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-runtime-parity.md:21), even though those docs still use the old pre-cleanup names. +- The local typed host↔world transport remains a separate boundary documented today in [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:237) and [docs/contracts/gateway/runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/runtime-parity.md:21), even though those docs still use the old pre-cleanup names. - The public session/control contract is already frozen around `orchestration_session_id` plus exact `backend_id`; public callers do not target `participant_id`, `active_session_handle_id`, or `internal.uaa_session_id` as documented in [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md:116). - `backend_id` remains the adapter/allowlist identity only; this slice does not reopen provider/auth/protocol overloading questions already settled in [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md:147). @@ -121,7 +121,7 @@ That drift now costs more than it did earlier, because the codebase contains bot This repo already uses real upstream UAA semantics: - external crate import `agent_api` in [crates/shell/Cargo.toml](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/Cargo.toml:61), -- adopted `agent_api.*` capability/schema ids in [docs/contracts/substrate-gateway-backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-schema.md:21), +- adopted `agent_api.*` capability/schema ids in [docs/contracts/gateway/backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-schema.md:21), - and surfaced internal `uaa_session_id` semantics in [ADR-0047](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md:214). Those are not the things being renamed here. @@ -131,7 +131,7 @@ Those are not the things being renamed here. The local transport boundary is already explicit in implementation: - transport/client/schema crates under [Cargo.toml](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/Cargo.toml:55), -- typed transport ownership in [docs/contracts/substrate-gateway-runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-runtime-parity.md:21), +- typed transport ownership in [docs/contracts/gateway/runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/runtime-parity.md:21), - and the `world-agent` socket API boundary in [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:237). The ambiguity is naming, not architectural absence. The misleading names are specifically: @@ -187,7 +187,7 @@ Primary anchors: - [AGENT_ORCHESTRATION_GAP_MATRIX.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENT_ORCHESTRATION_GAP_MATRIX.md:67) - [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:237) - [docs/TRACE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/TRACE.md:184) -- [docs/contracts/substrate-gateway-backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-schema.md:21) +- [docs/contracts/gateway/backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-schema.md:21) Required outcome: @@ -348,7 +348,7 @@ Primary anchors: - [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md:120) - [ADR-0047](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md:214) -- [docs/contracts/substrate-gateway-backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-schema.md:21) +- [docs/contracts/gateway/backend-adapter-schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-schema.md:21) Required outcome: diff --git a/llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md b/llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md index a61945ada..eaadc0cae 100644 --- a/llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md +++ b/llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md @@ -64,12 +64,12 @@ This SOW assumes the following are already true and must be reused rather than r 1. The gateway ownership split is already fixed in repo truth: - Substrate owns policy evaluation, world placement, lifecycle control, host-to-world secret delivery, operator UX, and canonical tracing. - `substrate-gateway` owns the in-world front door, adapter dispatch, and backend/provider internals. - - Primary anchors: [docs/contracts/substrate-gateway-operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-operator-contract.md), [docs/contracts/substrate-gateway-runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-runtime-parity.md), and [ADR-0040](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md). + - Primary anchors: [docs/contracts/gateway/operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/operator-contract.md), [docs/contracts/gateway/runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/runtime-parity.md), and [ADR-0040](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md). 2. Stable backend selection is already a landed contract: - backend ids remain stable `:`, - allowlisting happens before adapter dispatch, - unsupported-but-well-formed backend ids remain a dependency/runtime-unavailable problem rather than an excuse to reuse another adapter. - - Primary anchors: [docs/contracts/substrate-gateway-backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-selection.md) and [docs/contracts/substrate-gateway-backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-protocol.md). + - Primary anchors: [docs/contracts/gateway/backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-selection.md) and [docs/contracts/gateway/backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-protocol.md). 3. Integrated auth already has a real secure carrier: - host-side auth payload synthesis already exists, - world-service already converts that payload into an inherited FD auth bundle, @@ -182,10 +182,10 @@ Required outcome: Primary anchors: -- [docs/contracts/substrate-gateway-backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-selection.md) -- [docs/contracts/substrate-gateway-backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-protocol.md) -- [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md) -- [docs/contracts/substrate-gateway-runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-runtime-parity.md) +- [docs/contracts/gateway/backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-selection.md) +- [docs/contracts/gateway/backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-protocol.md) +- [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md) +- [docs/contracts/gateway/runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/runtime-parity.md) Required outcome: @@ -292,14 +292,14 @@ When this slice closes, update the truth/docs that would otherwise keep describi 1. [llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/llm-last-mile/28-gateway-mediated-llm-fulfillment-without-lifecycle-regression.md) 2. [AGENT_ORCHESTRATION_GAP_MATRIX.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENT_ORCHESTRATION_GAP_MATRIX.md) -3. [docs/contracts/substrate-gateway-runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-runtime-parity.md) -4. [docs/contracts/substrate-gateway-backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-protocol.md) +3. [docs/contracts/gateway/runtime-parity.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/runtime-parity.md) +4. [docs/contracts/gateway/backend-adapter-protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-protocol.md) 5. [docs/USAGE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/USAGE.md) Review and update if needed, but do not reopen their core ownership/lifecycle rules: -1. [docs/contracts/substrate-gateway-backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-backend-adapter-selection.md) -2. [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md) +1. [docs/contracts/gateway/backend-adapter-selection.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/backend-adapter-selection.md) +2. [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md) 3. [ADR-0040](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md) 4. [ADR-0041](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md) diff --git a/llm-last-mile/ORCH_PLAN-14.md b/llm-last-mile/ORCH_PLAN-14.md index e808dc4f7..9d132bc4e 100644 --- a/llm-last-mile/ORCH_PLAN-14.md +++ b/llm-last-mile/ORCH_PLAN-14.md @@ -585,7 +585,7 @@ Owned files: - [crates/world-agent/tests/gateway_runtime_parity.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/world-agent/tests/gateway_runtime_parity.rs) - [crates/gateway/tests/openai_shared_parity.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/gateway/tests/openai_shared_parity.rs) - [crates/shell/tests/world_gateway.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/tests/world_gateway.rs) -- [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md) +- [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md) - [crates/gateway/docs/contracts/chatgpt-codex-auth-handoff-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/gateway/docs/contracts/chatgpt-codex-auth-handoff-contract.md) - [AGENT_ORCHESTRATION_GAP_MATRIX.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENT_ORCHESTRATION_GAP_MATRIX.md) diff --git a/llm-last-mile/PLAN-14.md b/llm-last-mile/PLAN-14.md index 900c2bf8b..375755a87 100644 --- a/llm-last-mile/PLAN-14.md +++ b/llm-last-mile/PLAN-14.md @@ -39,8 +39,8 @@ The following work is already landed and is not reopened here: - host-side auth sourcing and policy enforcement in [crates/shell/src/builtins/world_gateway.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_gateway.rs) - typed `integrated_auth` payload validation in [crates/agent-api-types/src/lib.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/agent-api-types/src/lib.rs) - backend selection and integrated gateway runtime binding in [crates/world-agent/src/gateway_runtime.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/world-agent/src/gateway_runtime.rs) -- operator command family and exit-code contract in [docs/contracts/substrate-gateway-operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-operator-contract.md) -- policy precedence and fail-closed auth sourcing rules in [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md) +- operator command family and exit-code contract in [docs/contracts/gateway/operator-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/operator-contract.md) +- policy precedence and fail-closed auth sourcing rules in [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md) ### Exact remaining gap @@ -210,7 +210,7 @@ Expected production surfaces: 11. `crates/gateway/src/providers/registry.rs` 12. `crates/gateway/tests/openai_shared_parity.rs` 13. `crates/shell/tests/world_gateway.rs` -14. `docs/contracts/substrate-gateway-policy-evaluation.md` +14. `docs/contracts/gateway/policy-evaluation.md` 15. `crates/gateway/docs/contracts/chatgpt-codex-auth-handoff-contract.md` 16. `AGENT_ORCHESTRATION_GAP_MATRIX.md` @@ -713,7 +713,7 @@ Files: - [crates/world-agent/tests/gateway_runtime_parity.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/world-agent/tests/gateway_runtime_parity.rs) - [crates/gateway/tests/openai_shared_parity.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/gateway/tests/openai_shared_parity.rs) - [crates/shell/tests/world_gateway.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/tests/world_gateway.rs) -- [docs/contracts/substrate-gateway-policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/substrate-gateway-policy-evaluation.md) +- [docs/contracts/gateway/policy-evaluation.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/gateway/policy-evaluation.md) - [crates/gateway/docs/contracts/chatgpt-codex-auth-handoff-contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/gateway/docs/contracts/chatgpt-codex-auth-handoff-contract.md) - [AGENT_ORCHESTRATION_GAP_MATRIX.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENT_ORCHESTRATION_GAP_MATRIX.md) From 464c4f83054ede8876a7c18642aa5a7fb3a1d33c Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 09:21:34 -0400 Subject: [PATCH 03/20] Moved the platform docs into `docs/reference/world/platforms/` and the D --- README.md | 6 +-- docs/WORLD.md | 2 +- .../release_notes_macos_always_world.md | 45 ------------------- docs/internals/world/README.md | 2 +- .../world/transport-parity.md} | 0 .../p0-platform-stability/tasks.json | 2 +- .../governance/seam-5-closeout.md | 2 +- .../seam.md | 2 +- ...-privileged-and-macos-smoke-conformance.md | 2 +- docs/reference/world/README.md | 5 +++ docs/reference/world/platforms/README.md | 9 ++++ .../world/platforms/macos-lima-setup.md} | 2 + .../world/platforms/windows-wsl-setup.md} | 0 .../platforms/windows-wsl-troubleshooting.md} | 0 ...-member-runtime-world-placement-gap-sow.md | 4 +- .../27-uaa-boundary-and-naming-cleanup.md | 8 ++-- llm-last-mile/ORCH_PLAN-13.md | 2 +- 17 files changed, 32 insertions(+), 61 deletions(-) delete mode 100644 docs/cross-platform/release_notes_macos_always_world.md rename docs/{cross-platform/transport_parity_design.md => internals/world/transport-parity.md} (100%) create mode 100644 docs/reference/world/platforms/README.md rename docs/{cross-platform/mac_world_setup.md => reference/world/platforms/macos-lima-setup.md} (98%) rename docs/{cross-platform/wsl_world_setup.md => reference/world/platforms/windows-wsl-setup.md} (100%) rename docs/{cross-platform/wsl_world_troubleshooting.md => reference/world/platforms/windows-wsl-troubleshooting.md} (100%) diff --git a/README.md b/README.md index 93be800b4..c0d20cb51 100644 --- a/README.md +++ b/README.md @@ -66,7 +66,7 @@ After the warm step, run `substrate` from the workspace (or your PATH) and it wi pwsh -File scripts\windows\wsl-smoke.ps1 ``` -Detailed setup guidance, doctor output, and troubleshooting live in [`docs/cross-platform/wsl_world_setup.md`](docs/cross-platform/wsl_world_setup.md). +Detailed setup guidance, doctor output, and troubleshooting live in [`docs/reference/world/platforms/windows-wsl-setup.md`](docs/reference/world/platforms/windows-wsl-setup.md). > Windows installers follow the same pass-through model—host shells keep their > PATH, and `substrate shim doctor` provides the canonical view of manager @@ -195,8 +195,8 @@ Additional capabilities planned for later phases: - **[Replay](docs/REPLAY.md)** - Replaying traced commands (with Linux isolation option) - **[Graph](docs/GRAPH.md)** - Graph architecture and CLI (mock backend) - **[Privileged Tests](docs/HOWTO_PRIVILEGED_TESTS.md)** - Running isolation/netfilter tests on Linux -- **[Windows World Setup](docs/cross-platform/wsl_world_setup.md)** - WSL2 provisioning, warm/doctor/smoke automation, and troubleshooting -- **[Transport Parity Design](docs/cross-platform/transport_parity_design.md)** - The cross-platform transport architecture that underpins Windows parity +- **[Windows World Setup](docs/reference/world/platforms/windows-wsl-setup.md)** - WSL2 provisioning, warm/doctor/smoke automation, and troubleshooting +- **[Transport Parity Design](docs/internals/world/transport-parity.md)** - The cross-platform transport architecture that underpins Windows parity ### World Doctor & Host Readiness diff --git a/docs/WORLD.md b/docs/WORLD.md index 581aad806..c54712d8f 100644 --- a/docs/WORLD.md +++ b/docs/WORLD.md @@ -304,7 +304,7 @@ Notes - The shell probes `/v1/capabilities`; if stale socket is found, it removes it. - If the agent isn’t running, the shell attempts to spawn it (Linux dev flow: `target/debug/world-service`). - macOS invokes the Lima backend ensure path to boot the VM and wire up its tunnel. - - Windows/WSL helper flows are intentionally fail-closed in this slice; see `docs/cross-platform/wsl_world_setup.md`. + - Windows/WSL helper flows are intentionally fail-closed in this slice; see `docs/reference/world/platforms/windows-wsl-setup.md`. - Fallback - With `world_fs.require_world=false`, exactly one warning is printed if the world cannot be reached; execution continues on the host in that situation. - With `world_fs.require_world=true`, world routing failures are treated as hard errors (no host fallback). diff --git a/docs/cross-platform/release_notes_macos_always_world.md b/docs/cross-platform/release_notes_macos_always_world.md deleted file mode 100644 index abed0c6c8..000000000 --- a/docs/cross-platform/release_notes_macos_always_world.md +++ /dev/null @@ -1,45 +0,0 @@ -# Release Notes — macOS Always-World Parity - -## Highlights - -- macOS now ships the same "Always World" experience as Linux by running Substrate commands inside a Lima-hosted Linux VM. -- Shell, PTY, replay, shim, and telemetry flows all route through the Lima backend automatically with transport fallbacks. -- Documentation and tooling cover provisioning, health checks, smoke validation, and troubleshooting for the new mac path. - -## Requirements - -- macOS 13.0+ with Virtualization.framework enabled (`sysctl kern.hv_support` → `1`). -- Homebrew packages: `lima jq openssh coreutils gnused gnu-tar gettext` (ensure `envsubst` and `vsock-proxy` are on `PATH`). -- Rust toolchain installed for building `substrate-world-service`. - -## Setup Flow - -1. From the repo root run `scripts/mac/lima-warm.sh` to create or start the `substrate` Lima VM. The helper script applies the default profile with writable mounts (`/src`, `/tmp`), installs required packages, and deploys the systemd unit. -2. Build the agent on the host (`cargo build -p world-service --release`) and copy it into the guest (`limactl copy ...`, `sudo mv /usr/local/bin/substrate-world-service`). -3. Enable the service: `limactl shell substrate sudo systemctl enable --now substrate-world-service`. -4. Validate with `scripts/mac/lima-doctor.sh`; all critical checks must return `[PASS]`. - -## Smoke & Diagnostics - -- End-to-end verification: `PATH="$(pwd)/target/debug:$PATH" scripts/mac/smoke.sh` (expects replay `fs_diff` to include `world-mac-smoke/file.txt`). -- Guest logs: `substrate sudo journalctl -u substrate-world-service -n 200` (the CLI shells into Lima automatically); manual fallback `limactl shell substrate sudo journalctl -u substrate-world-service -n 200`. -- Transport order and fallback: VSock → SSH UDS (`~/.substrate/sock/agent.sock`) → SSH TCP. The shell logs the chosen transport; on failure it emits a single warning and runs the command on the host. - -## Environment & Compatibility - -- `SUBSTRATE_WORLD` defaults to `enabled` on macOS; set `SUBSTRATE_WORLD=disabled` to bypass the Lima backend for troubleshooting. -- `SUBSTRATE_WORLD_ID` is exported once a session is established for telemetry correlation. -- No mac-only transport override flags; all behavior mirrors Linux defaults. - -## Troubleshooting Quick Hits - -- Re-run `scripts/mac/lima-doctor.sh` if the shell falls back every command—fix any `[FAIL]` entries before retrying. -- Ensure the agent binary matches the guest architecture (`Exec format error` → rebuild inside Lima). -- If VSock is unavailable, verify `vsock-proxy` exists and the Lima profile uses `vmType: "vz"`; otherwise expect SSH fallback with identical semantics. - -## References - -- Provisioning profile: `scripts/mac/lima/substrate.yaml` -- mac setup runbook: `docs/dev/mac_world_setup.md` -- World architecture (Linux & mac): `docs/WORLD.md` -- Installation overview with mac section: `docs/INSTALLATION.md` diff --git a/docs/internals/world/README.md b/docs/internals/world/README.md index 06d8b427f..e8256ec07 100644 --- a/docs/internals/world/README.md +++ b/docs/internals/world/README.md @@ -4,7 +4,7 @@ This directory is scaffolding: it is intended to hold developer-facing notes abo Existing related docs (top-level): - `docs/WORLD.md` -- `docs/cross-platform/transport_parity_design.md` +- `docs/internals/world/transport-parity.md` Additional internal docs: - `docs/internals/world/workspace_sync_filesystem_model.md` diff --git a/docs/cross-platform/transport_parity_design.md b/docs/internals/world/transport-parity.md similarity index 100% rename from docs/cross-platform/transport_parity_design.md rename to docs/internals/world/transport-parity.md diff --git a/docs/project_management/_archived/p0-platform-stability/tasks.json b/docs/project_management/_archived/p0-platform-stability/tasks.json index d1d0b72a6..888e26c44 100644 --- a/docs/project_management/_archived/p0-platform-stability/tasks.json +++ b/docs/project_management/_archived/p0-platform-stability/tasks.json @@ -391,7 +391,7 @@ "description": "Re-run `pwsh -File scripts/windows/wsl-warm.ps1 -WhatIf` on a Windows host with PowerShell 7 to capture the socket-activation provisioning dry-run that was skipped on Linux.", "references": [ "scripts/windows/wsl-warm.ps1", - "docs/cross-platform/wsl_world_setup.md", + "docs/reference/world/platforms/windows-wsl-setup.md", "docs/INSTALLATION.md#windows", "docs/project_management/_archived/next/p0-platform-stability/session_log.md" ], diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md index 18d1206ff..060905f11 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md @@ -42,7 +42,7 @@ open_remediations: [] - `cargo test -p shell --test doctor_scopes_ds0 -- --nocapture` passed with `3 passed; 0 failed`, preserving the world-doctor JSON envelope for the published `requested`, `enabled`, `world_netfilter_enable_present`, and `last_failure_reason` fields. - `cargo test -p shell --test shim_doctor -- --nocapture` passed with `11 passed; 0 failed`, including `shim_doctor_json_preserves_world_netfilter_default_details`, `shim_doctor_json_preserves_world_netfilter_enabled_details`, and `shim_doctor_json_preserves_world_netfilter_failure_reason_details`, proving downstream shim surfaces preserve the same doctor contract. - `docs/reference/world/verification/netfilter_enforcement.md` now publishes the privileged Linux verification path around `cargo test -p world -- --ignored --nocapture`, including prerequisites, expected pass/skip/failure evidence, and the exact closeout capture requirements for the ignored `crates/world/src/netfilter.rs` nftables coverage. - - `scripts/mac/smoke.sh` now includes `--netfilter-conformance`, which warms Lima with `SUBSTRATE_WORLD_NETFILTER_ENABLE=1`, exercises allow-all and deny-all postures, and writes the doctor JSON plus probe transcripts expected by closeout; `docs/cross-platform/mac_world_setup.md` and `docs/reference/world/verification/netfilter_enforcement.md` publish the same warm/smoke commands, expected doctor states, and artifact names (`allow-all-world-doctor.json`, `deny-all-world-doctor.json`). + - `scripts/mac/smoke.sh` now includes `--netfilter-conformance`, which warms Lima with `SUBSTRATE_WORLD_NETFILTER_ENABLE=1`, exercises allow-all and deny-all postures, and writes the doctor JSON plus probe transcripts expected by closeout; `docs/reference/world/platforms/macos-lima-setup.md` and `docs/reference/world/verification/netfilter_enforcement.md` publish the same warm/smoke commands, expected doctor states, and artifact names (`allow-all-world-doctor.json`, `deny-all-world-doctor.json`). - **Contracts published or changed**: - none; `SEAM-5` consumes `C-01` through `C-07` and turns them into conformance evidence without publishing a new contract. - **Threads published / advanced**: diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md index adf527c17..5a08cac95 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md @@ -61,7 +61,7 @@ open_remediations: [] - `scripts/mac/lima-warm.sh` - `scripts/mac/smoke.sh` - `docs/reference/config/world.md` - - `docs/cross-platform/mac_world_setup.md` + - `docs/reference/world/platforms/macos-lima-setup.md` - `docs/reference/world/verification/netfilter_enforcement.md` - **Verification**: - cross-seam regression coverage for config/routing/doctor invariants diff --git a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md index 03aa43234..c6351b755 100644 --- a/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md +++ b/docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md @@ -83,7 +83,7 @@ Checklist: - **Files**: - `scripts/mac/lima-warm.sh` - `scripts/mac/smoke.sh` - - `docs/cross-platform/mac_world_setup.md` + - `docs/reference/world/platforms/macos-lima-setup.md` - `docs/reference/world/verification/netfilter_enforcement.md` - **Thread/contract refs**: - `THR-03` diff --git a/docs/reference/world/README.md b/docs/reference/world/README.md index 488e84ac8..d95b785a2 100644 --- a/docs/reference/world/README.md +++ b/docs/reference/world/README.md @@ -17,3 +17,8 @@ Operator documentation for `substrate world deps` lives under: Operator verification playbooks for stable world behavior live under: - `docs/reference/world/verification/README.md` + +## World Platforms + +Operator-facing platform setup and troubleshooting guides live under: +- `docs/reference/world/platforms/README.md` diff --git a/docs/reference/world/platforms/README.md b/docs/reference/world/platforms/README.md new file mode 100644 index 000000000..2e5cb2f6a --- /dev/null +++ b/docs/reference/world/platforms/README.md @@ -0,0 +1,9 @@ +# World Platform Guides + +Operator-facing platform setup and troubleshooting guides for world-backed execution live here. + +## Documents + +- `macos-lima-setup.md`: macOS Lima provisioning, doctor flow, smoke checks, and troubleshooting. +- `windows-wsl-setup.md`: current Windows WSL setup posture and fail-closed helper behavior. +- `windows-wsl-troubleshooting.md`: Windows WSL troubleshooting catalogue for doctor and smoke failures. diff --git a/docs/cross-platform/mac_world_setup.md b/docs/reference/world/platforms/macos-lima-setup.md similarity index 98% rename from docs/cross-platform/mac_world_setup.md rename to docs/reference/world/platforms/macos-lima-setup.md index 4b9eebcac..b8b7dc64b 100644 --- a/docs/cross-platform/mac_world_setup.md +++ b/docs/reference/world/platforms/macos-lima-setup.md @@ -251,6 +251,8 @@ The shell manages transport detection automatically. The only knobs you should n - `SUBSTRATE_WORLD_NETFILTER_ENABLE=1`: Host-side input for `scripts/mac/lima-warm.sh`; writes `WORLD_NETFILTER_ENABLE=1` into the guest `substrate-world-service.service` unit so requested netfilter enforcement can be honored. +- There are no macOS-only transport override flags in the supported operator surface; transport + selection follows the built-in fallback chain automatically. For a quick guest-env check without reprovisioning, run: diff --git a/docs/cross-platform/wsl_world_setup.md b/docs/reference/world/platforms/windows-wsl-setup.md similarity index 100% rename from docs/cross-platform/wsl_world_setup.md rename to docs/reference/world/platforms/windows-wsl-setup.md diff --git a/docs/cross-platform/wsl_world_troubleshooting.md b/docs/reference/world/platforms/windows-wsl-troubleshooting.md similarity index 100% rename from docs/cross-platform/wsl_world_troubleshooting.md rename to docs/reference/world/platforms/windows-wsl-troubleshooting.md diff --git a/llm-last-mile/13-member-runtime-world-placement-gap-sow.md b/llm-last-mile/13-member-runtime-world-placement-gap-sow.md index 313bed617..05ecb9db7 100644 --- a/llm-last-mile/13-member-runtime-world-placement-gap-sow.md +++ b/llm-last-mile/13-member-runtime-world-placement-gap-sow.md @@ -335,8 +335,8 @@ Relevant reference docs: - [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md:105) - [docs/INSTALLATION.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/INSTALLATION.md:79) - [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md:1) -- [docs/cross-platform/wsl_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_setup.md:1) -- [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md:1) +- [docs/reference/world/platforms/windows-wsl-setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/windows-wsl-setup.md:1) +- [docs/reference/world/platforms/macos-lima-setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/macos-lima-setup.md:1) ## Acceptance Criteria diff --git a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md index 5b8de6f98..9e1d2a82c 100644 --- a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md +++ b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md @@ -327,8 +327,8 @@ Primary anchors: - [docs/REPLAY.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/REPLAY.md:82) - [docs/reference/env/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/env/contract.md:63) - [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md:12) -- [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md:108) -- [docs/cross-platform/wsl_world_troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_troubleshooting.md:163) +- [docs/reference/world/platforms/macos-lima-setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/macos-lima-setup.md:108) +- [docs/reference/world/platforms/windows-wsl-troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/windows-wsl-troubleshooting.md:163) - [ADR-0042](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md:127) - [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md:183) - [ADR-0045](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md:255) @@ -534,8 +534,8 @@ When this slice lands, the following must be updated together: - [docs/REPLAY.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/REPLAY.md), - [docs/reference/env/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/env/contract.md), - [docs/reference/world/verification/linux_world_socket.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/verification/linux_world_socket.md), -- [docs/cross-platform/mac_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/mac_world_setup.md), -- [docs/cross-platform/wsl_world_troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_troubleshooting.md), +- [docs/reference/world/platforms/macos-lima-setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/macos-lima-setup.md), +- [docs/reference/world/platforms/windows-wsl-troubleshooting.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/windows-wsl-troubleshooting.md), - [dist-workspace.toml](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/dist-workspace.toml), - [macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md), - [AGENTS.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENTS.md), diff --git a/llm-last-mile/ORCH_PLAN-13.md b/llm-last-mile/ORCH_PLAN-13.md index e5088b94a..12ce34106 100644 --- a/llm-last-mile/ORCH_PLAN-13.md +++ b/llm-last-mile/ORCH_PLAN-13.md @@ -507,7 +507,7 @@ Owned files: - [docs/WORLD.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md) - [docs/INSTALLATION.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/INSTALLATION.md) - [docs/CONFIGURATION.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/CONFIGURATION.md) -- [docs/cross-platform/wsl_world_setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/cross-platform/wsl_world_setup.md) +- [docs/reference/world/platforms/windows-wsl-setup.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/platforms/windows-wsl-setup.md) Forbidden files: From 49c52815eaebf7ee2a622656235e0ea664baf37b Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 09:28:17 -0400 Subject: [PATCH 04/20] Remove obsolete world FS policy quick reference --- docs/WORLD_FS_POLICY_V2_QUICK_REFERENCE.md | 224 --------------------- 1 file changed, 224 deletions(-) delete mode 100644 docs/WORLD_FS_POLICY_V2_QUICK_REFERENCE.md diff --git a/docs/WORLD_FS_POLICY_V2_QUICK_REFERENCE.md b/docs/WORLD_FS_POLICY_V2_QUICK_REFERENCE.md deleted file mode 100644 index b4360bdf5..000000000 --- a/docs/WORLD_FS_POLICY_V2_QUICK_REFERENCE.md +++ /dev/null @@ -1,224 +0,0 @@ -# World FS Policy V2 — Quick Reference (Granular Allow/Deny + Strict) - -This is a practical “what to set + what to try” guide for the newer `world_fs` policy shape (ADR-0018 / WFGAD*). - -## 0) Preconditions (so tests are meaningful) - -- The deny/strict behavior is a **Linux** implementation detail: - - Linux host: world-service runs on the host. - - macOS host: world-service runs inside a **Lima VM** (Linux in VM). -- Verify world backend health before testing: - - `substrate world doctor` - - If that fails, run `substrate world enable` (or on macOS: `scripts/mac/lima-warm.sh`). - -## 1) Policy shape (what exists now) - -At a high level: - -- `world_fs` is configured with: - - `mode`: `read_only` or `writable` - - `isolation`: `workspace` or `full` - - `require_world`: `true|false` (denies require `true`) - - `enforcement`: `strict` or `best_effort` (**only** when any `deny_list` is non-empty) -- Dimensions (optional objects): - - `world_fs.read` - - `world_fs.discover` (optional; defaults to `read` semantics when omitted) - - `world_fs.write` -- Each dimension has: - - `allow_list`: required, non-empty (when the dimension is present / implied by mode) - - `deny_list`: optional list of patterns - -### Hard rules that commonly bite people - -- **Deny lists require full isolation**: - - If any `deny_list` is non-empty, you must have: - - `world_fs.isolation=full` - - `world_fs.require_world=true` - - `world_fs.enforcement` present (`strict` or `best_effort`) -- `discover` is optional: - - If `world_fs.discover` is omitted, **discover behaves like read** (no “mystery default”). -- Allow-list patterns are intentionally conservative: - - `allow_list` rejects wildcards and unsupported metacharacters. -- Deny-list patterns support only `*` and `**` (no `?`, no character classes). -- Legacy keys are **hard errors**: - - e.g. `world_fs.read_allowlist`, `world_fs.write_allowlist` should fail fast. - -## 2) Minimal working examples (CLI) - -Create a clean workspace + policy, then apply one of the examples below: - -```bash -substrate workspace init --force -substrate policy init --force -``` - -### A) Read-only, full isolation (allow everything in project) - -```bash -substrate policy set \ - 'world_fs.mode=read_only' \ - 'world_fs.isolation=full' \ - 'world_fs.require_world=true' \ - 'world_fs.read.allow_list+=.' -``` - -### B) Read-only with deny masking (best_effort) - -```bash -substrate policy set \ - 'world_fs.mode=read_only' \ - 'world_fs.isolation=full' \ - 'world_fs.require_world=true' \ - 'world_fs.enforcement=best_effort' \ - 'world_fs.read.allow_list+=.' \ - 'world_fs.read.deny_list+=./secrets/**' -``` - -### C) Strict deny lockdown (security boundary) - -```bash -substrate policy set \ - 'world_fs.mode=read_only' \ - 'world_fs.isolation=full' \ - 'world_fs.require_world=true' \ - 'world_fs.enforcement=strict' \ - 'world_fs.read.allow_list+=.' \ - 'world_fs.read.deny_list+=./secrets/**' -``` - -### D) Discover vs read (visible-but-not-readable) - -```bash -substrate policy set \ - 'world_fs.mode=read_only' \ - 'world_fs.isolation=full' \ - 'world_fs.require_world=true' \ - 'world_fs.enforcement=best_effort' \ - 'world_fs.discover.allow_list+=.' \ - 'world_fs.read.allow_list+=.' \ - 'world_fs.read.deny_list+=./secrets/secret.txt' -``` - -### E) Writable with write-deny (EROFS) - -```bash -substrate policy set \ - 'world_fs.mode=writable' \ - 'world_fs.isolation=full' \ - 'world_fs.require_world=true' \ - 'world_fs.enforcement=best_effort' \ - 'world_fs.write.allow_list+=.' \ - 'world_fs.write.deny_list+=./outputs/private/**' -``` - -## 3) “Things to try” (behavior checklist) - -Use `--world` runs so you’re exercising the backend enforcement path: - -### 3.1 Schema / validation (fast fail) - -- Legacy keys should error: - - `substrate policy set 'world_fs.read_allowlist+=.'` - - `substrate policy set 'world_fs.write_allowlist+=.'` -- Invalid patterns should error: - - `substrate policy set 'world_fs.read.allow_list+=../x'` - - `substrate policy set 'world_fs.read.allow_list+=/abs'` - - `substrate policy set 'world_fs.read.allow_list+=src/**'` - - `substrate policy set 'world_fs.read.deny_list+=file?.txt'` - -### 3.2 Deny overrides allow (directory deny) - -Expected: `EACCES` / “Permission denied” for denied paths; allowed paths still work. - -```bash -substrate --world --command 'ls ./secrets' -substrate --world --command 'cat ./secrets/secret.txt' -substrate --world --command 'cat ./docs/public.txt' -``` - -### 3.3 Strict bypass prevention (mount/umount must not undo denies) - -Expected in strict: -- `umount`/`mount` attempts fail with `EPERM` / “Operation not permitted” -- denied reads remain denied - -```bash -substrate --world --command 'umount /project/secrets || true' -substrate --world --command 'cat ./secrets/secret.txt' -``` - -### 3.4 Discover vs read (“listable but not readable”) - -Expected: -- `ls` shows the file -- `cat` is denied - -```bash -substrate --world --command 'ls ./secrets | grep -qx secret.txt' -substrate --world --command 'cat ./secrets/secret.txt' -``` - -### 3.5 Wildcard deny snapshot semantics (deny matches at exec start) - -Expected: -- wildcard deny blocks matching files that exist at exec start - -```bash -substrate --world --command 'cat ./certs/a.pem' -``` - -### 3.6 Write deny returns EROFS (not EACCES) - -Expected: “Read-only file system” / `EROFS` when writing under a denied write subtree. - -```bash -substrate --world --command 'mkdir -p ./outputs/private/x' -``` - -### 3.7 Discover deny makes subtree “invisible” - -Expected: listing/reading in the denied discover subtree fails (typically “Permission denied”). - -```bash -substrate --world --command 'ls ./secrets' -``` - -## 4) One-command “known good” smoke (recommended) - -These run a curated suite of the above behaviors. - -### Linux (local) - -```bash -cargo build --bin substrate --bin substrate-shim -export PATH="$PWD/target/debug:$PATH" -SUBSTRATE_SMOKE_SLICE_ID=WFGAD5 bash docs/project_management/_archived/world-fs-granular-allow-deny/smoke/linux-smoke.sh -``` - -### macOS (local; Lima-backed Linux world) - -```bash -scripts/mac/lima-warm.sh "$PWD" -cargo build --bin substrate --bin substrate-shim -export PATH="$PWD/target/debug:$PATH" -SUBSTRATE_SMOKE_SLICE_ID=WFGAD5 bash docs/project_management/_archived/world-fs-granular-allow-deny/smoke/macos-smoke.sh -``` - -## 5) CI / runners (Planning Pack Feature Smoke) - -Feature smoke is dispatched via `.github/workflows/feature-smoke.yml`. - -- Linux (self-hosted runner with `/run/substrate.sock`): `make feature-smoke PLATFORM=linux RUNNER_KIND=self-hosted ...` -- macOS (self-hosted runner): `make feature-smoke PLATFORM=macos RUNNER_KIND=self-hosted ...` -- macOS **github-hosted runners cannot run Lima** (Virtualization.framework is unavailable), so full isolation smoke must run on self-hosted macOS. - -Example: - -```bash -FEATURE_DIR="docs/project_management/_archived/world-fs-granular-allow-deny" -CHECKOUT_SHA="$(git rev-parse HEAD)" - -make feature-smoke FEATURE_DIR="$FEATURE_DIR" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="$(git branch --show-current)" SMOKE_CHECKOUT_REF="$CHECKOUT_SHA" SMOKE_SLICE_ID=WFGAD5 -make feature-smoke FEATURE_DIR="$FEATURE_DIR" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="$(git branch --show-current)" SMOKE_CHECKOUT_REF="$CHECKOUT_SHA" SMOKE_SLICE_ID=WFGAD5 -``` - From a6447fcd4ebceb1572576c50852259a62fd83090 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 10:36:58 -0400 Subject: [PATCH 05/20] Extract world-deps and trace docs from planning packs --- crates/common/src/world_exec_guard.rs | 2 +- ...l_persistent_session_client_fail_closed.rs | 6 +- .../tests/world_deps_apt_fail_early_wdap1.rs | 50 +--- crates/world-service/src/world_exec_guard.rs | 2 +- crates/world/src/guard.rs | 4 +- docs/COMMANDS.md | 2 +- docs/CONFIGURATION.md | 2 +- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 230 ++++++++++++++++++ docs/TRACE.md | 5 +- docs/WORLD.md | 4 +- docs/internals/repl/persistent_session.md | 5 +- docs/internals/trace/README.md | 9 +- docs/internals/trace/protocol.md | 122 ++++++++++ docs/internals/trace/schema.md | 130 +++++++++- docs/internals/world/deps.md | 4 +- docs/reference/config/world.md | 2 +- docs/reference/world/deps/README.md | 2 +- docs/reference/world/deps/provisioning.md | 68 ++++++ 18 files changed, 581 insertions(+), 68 deletions(-) create mode 100644 docs/PROJECT_MANAGEMENT_RETIREMENT.md create mode 100644 docs/internals/trace/protocol.md create mode 100644 docs/reference/world/deps/provisioning.md diff --git a/crates/common/src/world_exec_guard.rs b/crates/common/src/world_exec_guard.rs index 8a0a24252..3a56591de 100644 --- a/crates/common/src/world_exec_guard.rs +++ b/crates/common/src/world_exec_guard.rs @@ -1,6 +1,6 @@ //! Exec-time guardrails for host-mounted toolchain binaries in host-visible worlds. //! -//! Spec: `docs/project_management/next/world-deps-host-visible-hardening/WDH2-spec.md` +//! Reference: `docs/reference/config/world.md` use std::collections::HashMap; use std::path::{Path, PathBuf}; diff --git a/crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs b/crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs index 39ebca81e..3c4ca0835 100644 --- a/crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs +++ b/crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs @@ -1,9 +1,7 @@ //! C2-test: fail-closed host-side persistent session client protocol handling. //! -//! Spec: -//! - docs/project_management/next/world-first-repl-persistent-pty/C2-spec.md -//! - docs/project_management/next/world-first-repl-persistent-pty/PROTOCOL.md -//! - docs/project_management/next/world-first-repl-persistent-pty/requirements_traceability.md +//! Reference: +//! - docs/internals/repl/persistent_session.md use serde_json::json; use world_api::{ diff --git a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs index bfcccc431..dc6cd88ce 100644 --- a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs +++ b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs @@ -48,9 +48,9 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { ); assert!( reference_readme.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" + "docs/reference/world/deps/provisioning.md" ), - "expected docs/reference/world/deps/README.md to link to the WDAP1 contract" + "expected docs/reference/world/deps/README.md to link to the stable provisioning contract" ); assert!( reference_readme.contains("substrate world enable --provision-deps"), @@ -68,37 +68,15 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { ); assert!( internals.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" + "docs/reference/world/deps/provisioning.md" ), - "expected docs/internals/world/deps.md to link to the WDAP1 contract" + "expected docs/internals/world/deps.md to link to the stable provisioning contract" ); assert!( internals.contains("substrate world enable --provision-deps"), "expected docs/internals/world/deps.md to mention the provisioning workflow" ); - let upstream_contract = read_repo_file( - "docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md", - ); - assert!( - upstream_contract.contains("#### substrate world deps current install "), - "expected upstream contract doc to include the install heading" - ); - assert!( - upstream_contract.contains("#### substrate world deps current sync [--dry-run] ..."), - "expected upstream contract doc to include the sync heading" - ); - assert!( - upstream_contract.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" - ), - "expected upstream contract doc to link to the WDAP1 contract" - ); - assert!( - upstream_contract.contains("substrate world enable --provision-deps"), - "expected upstream contract doc to mention the provisioning remediation" - ); - let world_doc = read_repo_file("docs/WORLD.md"); assert!( world_doc.contains("## 5) Agent API (over UDS)"), @@ -110,9 +88,9 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { ); assert!( world_doc.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" + "docs/reference/world/deps/provisioning.md" ), - "expected docs/WORLD.md to link to the WDAP1 contract" + "expected docs/WORLD.md to link to the stable provisioning contract" ); let configuration = read_repo_file("docs/CONFIGURATION.md"); @@ -122,9 +100,9 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { ); assert!( configuration.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" + "docs/reference/world/deps/provisioning.md" ), - "expected docs/CONFIGURATION.md to link to the WDAP1 contract" + "expected docs/CONFIGURATION.md to link to the stable provisioning contract" ); assert!( configuration.contains("substrate world enable --provision-deps"), @@ -142,21 +120,19 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { ); assert!( commands.contains( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md" + "docs/reference/world/deps/provisioning.md" ), - "expected docs/COMMANDS.md to link to the WDAP1 contract" + "expected docs/COMMANDS.md to link to the stable provisioning contract" ); - let wdap1_contract = read_repo_file( - "docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md", - ); + let wdap1_contract = read_repo_file("docs/reference/world/deps/provisioning.md"); assert!( wdap1_contract.contains("unsupported on Windows"), - "expected the WDAP1 contract to preserve the Windows runtime guidance" + "expected the stable provisioning contract to preserve the Windows runtime guidance" ); assert!( wdap1_contract.contains("Substrate will not mutate the host OS"), - "expected the WDAP1 contract to preserve the Linux host-native runtime guidance" + "expected the stable provisioning contract to preserve the Linux host-native runtime guidance" ); } diff --git a/crates/world-service/src/world_exec_guard.rs b/crates/world-service/src/world_exec_guard.rs index 0a684bc97..434241858 100644 --- a/crates/world-service/src/world_exec_guard.rs +++ b/crates/world-service/src/world_exec_guard.rs @@ -1,5 +1,5 @@ //! Exec-time guardrails for host-mounted toolchain binaries in host-visible worlds. //! -//! Spec: `docs/project_management/next/world-deps-host-visible-hardening/WDH2-spec.md` +//! Reference: `docs/reference/config/world.md` pub(crate) use substrate_common::world_exec_guard::{check_command, deny_message}; diff --git a/crates/world/src/guard.rs b/crates/world/src/guard.rs index 4391da660..75e3b2d08 100644 --- a/crates/world/src/guard.rs +++ b/crates/world/src/guard.rs @@ -53,8 +53,8 @@ pub fn wrap_with_anchor_guard(command: &str, anchor_root: &Path) -> String { /// Wrap a shell command with the deterministic world environment contract. /// /// This is defense-in-depth against shells or service environments that mutate PATH/HOME/XDG/TERM -/// despite the caller providing an explicit env map. The contract is owned by the WDH0 spec: -/// `docs/project_management/next/world-deps-host-visible-hardening/WDH0-spec.md`. +/// despite the caller providing an explicit env map. The stable contract reference is +/// `docs/reference/config/world.md`. pub fn wrap_with_world_env_contract(command: &str, env: &HashMap) -> String { const DEFAULT_WORLD_DEPS_BIN: &str = "/var/lib/substrate/world-deps/bin"; const BASELINE_PATH: &str = "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin"; diff --git a/docs/COMMANDS.md b/docs/COMMANDS.md index 1d8a8d4d6..613ecad95 100644 --- a/docs/COMMANDS.md +++ b/docs/COMMANDS.md @@ -79,7 +79,7 @@ Once you type `graph`, `host`, `world`, `config`, `policy`, `workspace`, `shim`, | Invocation | Positional Arguments | Subcommand Flags | Notes | | --- | --- | --- | --- | | `substrate world doctor` | — | `--json` | World-scoped readiness report (host + world-service facts). | -| `substrate world enable` | — | `--prefix`, `--profile`, `--provision-deps`, `--dry-run`, `--verbose`, `--force`, `--timeout` | Provisioning control per `cli.rs:197`; `--provision-deps` is the operator-facing APT workflow. See `docs/reference/world/deps/README.md` and `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md`. | +| `substrate world enable` | — | `--prefix`, `--profile`, `--provision-deps`, `--dry-run`, `--verbose`, `--force`, `--timeout` | Provisioning control per `cli.rs:197`; `--provision-deps` is the operator-facing APT workflow. See `docs/reference/world/deps/README.md` and `docs/reference/world/deps/provisioning.md`. | | `substrate world deps current list [VIEW]` | `view` (`available`, `enabled`, `applied`) | `--all`, `--json` | `available/enabled` are host-only; `applied` queries the world backend. | | `substrate world deps current show ` | `item` name | `--json`, `--explain` | `--explain` queries the world backend and prints remediation/manual instructions when blocked. | | `substrate world deps current install ` | One or more item names | `--dry-run`, `--verbose` | Applies immediately without modifying enabled list; APT-backed items are probe-only at runtime and remediate to `substrate world enable --provision-deps`. | diff --git a/docs/CONFIGURATION.md b/docs/CONFIGURATION.md index 5d21e7d42..50d6b5835 100644 --- a/docs/CONFIGURATION.md +++ b/docs/CONFIGURATION.md @@ -174,7 +174,7 @@ Other world-adjacent variables: | Variable | Purpose | Default | Example | |----------|---------|---------|---------| -| `SUBSTRATE_WORLD_REQUEST_PROFILE` | Sets the Agent API request `profile` for world-service executions (advanced/internal only). Built-in world-deps profiles such as `world-deps-provision` and `world-deps-probe` are reserved for Substrate’s own world-deps flows and are ignored when supplied through this env var; the operator-facing APT provisioning workflow remains `substrate world enable --provision-deps`. See `docs/reference/world/deps/README.md`, `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md`, and the historical draft-pack path `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md`. | *unset* | `wdap-smoke-profile` | +| `SUBSTRATE_WORLD_REQUEST_PROFILE` | Sets the Agent API request `profile` for world-service executions (advanced/internal only). Built-in world-deps profiles such as `world-deps-provision` and `world-deps-probe` are reserved for Substrate’s own world-deps flows and are ignored when supplied through this env var; the operator-facing APT provisioning workflow remains `substrate world enable --provision-deps`. See `docs/reference/world/deps/README.md` and `docs/reference/world/deps/provisioning.md`. | *unset* | `wdap-smoke-profile` | | `SUBSTRATE_SOCKET_ACTIVATION_OVERRIDE` | Force socket activation mode reporting (`socket_activation`, `manual`, or `unknown`) for diagnostics/tests | auto-detect via systemd | `socket_activation` | | `SUBSTRATE_SYSTEMCTL_TIMEOUT_MS` | Timeout (ms) for `systemctl show …` probes used by Linux socket-activation detection; prevents hangs when systemd/dbus is unhealthy | `2000` | `250` | diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md new file mode 100644 index 000000000..97e77a79e --- /dev/null +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -0,0 +1,230 @@ +# Project Management Retirement + +## Scope + +This plan retires the legacy top-level planning system under `docs/project_management/`. + +In scope: +- `docs/project_management/packs/**` +- `docs/project_management/system/**` +- `docs/project_management/intake/**` +- `docs/project_management/future/**` +- obsolete `_archived/**` planning material + +Out of scope for this cut: +- `crates/gateway/docs/project_management/**` +- the ADR registry under `docs/project_management/adrs/**` + +Current recommendation for ADRs: +- keep the full ADR registry in place during the pack retirement +- decide later whether to move or curate ADRs into a new stable `docs/adr/` tree + +## Constraints + +- `docs/project_management/packs/**` should be retired in one atomic cut, not wave-by-wave. +- Any pack document that is still treated as current source-of-truth must be extracted before the pack removal lands. +- CI, Make targets, smoke scripts, and Rust tests must stop depending on pack paths before the cut. +- Gateway-local planning docs are not being retired in this effort, but they currently link back into top-level packs and will need rewrites to avoid broken references. + +## Current Dependency Classes + +### 1. Tooling and automation that assume `packs/**` exists + +- `Makefile` + - planning scaffolding, validation, triad execution, archive helpers, and feature smoke dispatch all assume `docs/project_management/packs/...` +- `.github/workflows/feature-smoke.yml` + - workflow input model and smoke-script discovery depend on feature pack directories and `tasks.json` +- `scripts/e2e/triad_e2e_phase1.sh` +- `scripts/e2e/triad_e2e_phase2.sh` +- `scripts/e2e/triad_e2e_all.sh` +- `scripts/ci/dispatch_feature_smoke.sh` +- `scripts/ci-audit/ci_audit.sh` +- `scripts/ci-audit/ci_audit_record.sh` +- `scripts/mac/smoke.sh` + +Disposition: +- delete if triad/planning-pack orchestration is dead +- otherwise replace with non-pack infrastructure before the pack cut + +### 2. Rust tests and code that hard-read pack markdown + +- `crates/broker/src/tests.rs` + - contract tests for `adr-0027-identity-tuple-policy-surface` +- `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + - asserts world-deps provisioning references and contract wording +- `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` + - asserts successor compatibility, parity, and manual validation playbooks +- `crates/shell/tests/playbook_alignment.rs` + - recursively scans `docs/project_management/packs/**/manual_testing_playbook.md` +- `crates/transport-api-types/src/lib.rs` + - test reads a manual testing playbook under a draft pack + +Disposition: +- rewrite when the source-of-truth doc survives in a stable home +- delete when the test only protected planning-pack process mechanics + +### 3. Stable docs that still point at pack files + +These are the highest-priority extraction blockers because they treat pack docs as current truth: + +- `docs/TRACE.md` + - references `active/world_process_exec_tracing_parity/SCHEMA.md` + - references `active/world_process_exec_tracing_parity/PROTOCOL.md` + - references `packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` +- `docs/WORLD.md` + - references world-deps provisioning pack contracts +- `docs/CONFIGURATION.md` + - references world-deps provisioning pack contracts +- `docs/COMMANDS.md` + - references world-deps provisioning pack contracts +- `docs/reference/world/deps/README.md` + - references world-deps provisioning pack contracts +- `docs/internals/world/deps.md` + - references world-deps provisioning pack contracts +- `docs/reference/config/world.md` + - references `world-deps-host-visible-hardening/WDH0-spec.md` +- `docs/internals/world/workspace_sync_filesystem_model.md` + - references `world-sync` spec documents + +Disposition: +- extract the normative content into `docs/reference/**`, `docs/contracts/**`, or `docs/internals/**` +- then rewrite these references to the new stable locations + +### 4. Gateway docs that link to top-level packs + +Although `crates/gateway/docs/project_management/**` is out of scope for retirement, it currently depends on top-level pack closeouts, seam docs, and evidence paths. + +Notable dependency surfaces: +- `crates/gateway/docs/foundation/*.md` +- `crates/gateway/tests/fixtures/azure_kimi/*.json` +- `crates/gateway/docs/project_management/packs/active/**` + +Disposition: +- rewrite foundation docs and fixture provenance to stable gateway docs or stable top-level contracts before removing top-level packs +- do not leave `crates/gateway/**` pointing at deleted top-level pack paths + +## Extraction Targets Before The Atomic `packs/**` Cut + +### A. Trace schema and protocol + +Current pack sources: +- `docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md` +- `docs/project_management/packs/active/world_process_exec_tracing_parity/PROTOCOL.md` + +Recommended destination: +- merge schema ownership into `docs/internals/trace/schema.md` +- merge protocol ownership into `docs/internals/trace/README.md` or a new sibling under `docs/internals/trace/` + +Required follow-up: +- rewrite `docs/TRACE.md` +- rewrite `docs/internals/trace/README.md` +- remove any tests or comments that still name the pack path as authoritative + +### B. World-deps provisioning contract + +Current pack sources: +- `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md` +- `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md` +- `docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md` + +Recommended destination: +- move operator-facing contract material into `docs/reference/world/deps/README.md` +- move implementation/background material into `docs/internals/world/deps.md` +- if needed, add a dedicated stable doc under `docs/reference/world/deps/` + +Required follow-up: +- rewrite `docs/WORLD.md`, `docs/CONFIGURATION.md`, and `docs/COMMANDS.md` +- rewrite `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + +### C. ADR-0027 implemented policy contract/schema surfaces + +Current pack sources: +- `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` +- `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` +- draft pack docs under `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/` + +Recommended destination: +- absorb stable policy contract wording into `docs/reference/policy/contract.md` +- absorb stable schema ownership into a new or expanded doc under `docs/reference/policy/` +- keep the ADR itself in `docs/project_management/adrs/**` for historical record + +Required follow-up: +- rewrite `crates/broker/src/tests.rs` +- decide which draft-pack assertions remain valid as product contract tests versus planning-process checks to delete + +### D. Workspace sync filesystem semantics + +Current pack sources: +- `docs/project_management/packs/implemented/world-sync/filesystem-semantics-spec.md` +- `docs/project_management/packs/implemented/world-sync/WS2-spec.md` +- `docs/project_management/packs/implemented/world-sync/WS5-spec.md` + +Recommended destination: +- absorb normative filesystem semantics into `docs/internals/world/workspace_sync_filesystem_model.md` +- create stable reference docs only if the content is operator-facing + +Required follow-up: +- rewrite the internal world docs that currently cite those pack specs + +### E. Host-visible hardening references + +Current pack sources: +- `docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH0-spec.md` + +Current code comments still reference old `next/` paths: +- `crates/world/src/guard.rs` +- `crates/common/src/world_exec_guard.rs` +- `crates/world-service/src/world_exec_guard.rs` +- `crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs` + +Recommended destination: +- replace stale planning-path comments with stable doc anchors under `docs/reference/config/` or `docs/internals/world/` + +Required follow-up: +- update comments and any tests relying on those comments as documentation anchors + +## Delete Or Rewrite Checklist Before Pack Removal + +### Delete candidates + +- planning-pack scaffolding and triad automation in `Makefile` if the planning system is fully dead +- feature-smoke workflow and helper scripts if they only exist for planning packs +- `crates/shell/tests/playbook_alignment.rs` if no stable replacement playbook corpus is needed +- Python tests under `docs/project_management/system/scripts/planning/tests/` if the planning scripts are retired rather than relocated + +### Rewrite candidates + +- any Rust test that validates product behavior by asserting current docs mention the right contract +- any stable operator or internal doc that cites a pack path as canonical +- gateway docs and fixture provenance that would otherwise point at deleted top-level packs + +## Atomic `packs/**` Retirement Procedure + +1. Extract all surviving normative content out of `docs/project_management/packs/**`. +2. Rewrite all references in `docs/**`, `crates/**`, `scripts/**`, `.github/**`, and `Makefile`. +3. Remove or replace pack-based tests and automation. +4. Confirm `rg -n "docs/project_management/packs" .` returns only intentionally retained historical notes, if any. +5. Delete `docs/project_management/packs/**` in one cut. +6. Run formatting, clippy, tests, and a second reference scan. + +## Post-Pack Cleanup + +After `packs/**` is gone: +- remove `docs/project_management/system/**` +- remove `docs/project_management/intake/**` +- remove `docs/project_management/future/**` +- prune `_archived/**` to the minimum historical set worth keeping +- decide whether to keep the ADR registry where it is or move it into a non-project-management namespace + +## First Safe Implementation Slice + +The safest first execution slice is: + +1. extract the world-deps provisioning contract into stable docs +2. rewrite the stable docs and WDAP1 Rust test to those new locations +3. re-run tests + +Reason: +- it has a contained set of references +- it already has stable destination candidates +- it removes one of the largest live blockers before the atomic pack cut diff --git a/docs/TRACE.md b/docs/TRACE.md index 8070c3eee..826c76444 100644 --- a/docs/TRACE.md +++ b/docs/TRACE.md @@ -5,8 +5,7 @@ The Substrate Trace module (`crates/trace`) provides comprehensive span-based tracing for command execution across the Substrate ecosystem. It captures detailed execution context, policy decisions, and system state to enable command replay, security auditing, and graph-based analysis of command relationships. Canonical trace schema/correlation vocabulary (Phase 8 cross-cutting spines for LLM/agents/router/workflows): -- Source of truth: `docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md` for the pack-level schema and `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` for the ADR decision record. -- Phase 8 registry/progress: `docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` +- Source of truth: `docs/internals/trace/schema.md` for stable schema details and `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` for the ADR decision record. ### Key Features @@ -127,7 +126,7 @@ The current runtime already lands these fields on completion spans: ### World Process Telemetry (`world_process_*`) -`world_process_*` is the canonical subprocess exec/exit telemetry family introduced by ADR-0028. Linux-backed executions emit these records; on other platforms, the contract is degrade-only and is summarized through shell completion fields such as `process_events_status` and `process_events_reason` instead of `world_process_*` records. The authoritative schema and protocol live in [SCHEMA.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md) and [PROTOCOL.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/active/world_process_exec_tracing_parity/PROTOCOL.md). +`world_process_*` is the canonical subprocess exec/exit telemetry family introduced by ADR-0028. Linux-backed executions emit these records; on other platforms, the contract is degrade-only and is summarized through shell completion fields such as `process_events_status` and `process_events_reason` instead of `world_process_*` records. The authoritative schema and protocol now live in [schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/trace/schema.md) and [protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/trace/protocol.md). Event names: - `world_process_start` diff --git a/docs/WORLD.md b/docs/WORLD.md index c54712d8f..bf2bf37a8 100644 --- a/docs/WORLD.md +++ b/docs/WORLD.md @@ -282,9 +282,7 @@ Notes commands do not use the provisioning profile and never perform runtime APT mutation. - Provisioning-time APT and runtime fail-early details live in: `docs/reference/world/deps/README.md` - and `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md` - (historical draft-pack path: - `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md`) + and `docs/reference/world/deps/provisioning.md` --- diff --git a/docs/internals/repl/persistent_session.md b/docs/internals/repl/persistent_session.md index 53bd4cb81..e10f9d8b1 100644 --- a/docs/internals/repl/persistent_session.md +++ b/docs/internals/repl/persistent_session.md @@ -4,8 +4,9 @@ Substrate’s world-first REPL uses the world-service WebSocket `/v1/stream` “ protocol (v1) to execute interactive commands while persisting a small amount of state across commands (not a long-lived login shell). -This doc is intentionally implementation-focused. For the authoritative project plan/specs, see -`docs/project_management/_archived/world-first-repl-persistent-pty/`. +This doc is intentionally implementation-focused and is the stable internal reference for the +world-first persistent-session REPL behavior that was previously documented only in planning and +archived pack artifacts. ## Mental Model diff --git a/docs/internals/trace/README.md b/docs/internals/trace/README.md index 7f996da57..39e67654f 100644 --- a/docs/internals/trace/README.md +++ b/docs/internals/trace/README.md @@ -2,8 +2,9 @@ Trace internals are documented at the top level in [docs/TRACE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/TRACE.md). -This directory is intentionally small. Use it for internal notes or implementation references only when they add detail beyond the top-level trace schema docs. +This directory now holds the stable internal trace references that used to live in pack docs: +- [schema.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/trace/schema.md) +- [protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/trace/protocol.md) -Current authoritative surfaces: -- [docs/TRACE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/TRACE.md) -- [active pack SCHEMA.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md) +Use this directory for implementation-facing schema and protocol notes that add detail beyond the +operator-facing trace overview. diff --git a/docs/internals/trace/protocol.md b/docs/internals/trace/protocol.md new file mode 100644 index 000000000..6b5d0bd78 --- /dev/null +++ b/docs/internals/trace/protocol.md @@ -0,0 +1,122 @@ +# Trace Protocol (Internal) + +This document is the stable internal protocol reference for process-event payloads returned by +world-service and persisted by the host shell. + +## Scope + +- HTTP `POST /v1/execute` +- WebSocket `GET /v1/stream` + - v1 uses exit-frame batching only for process-event payloads + +Platform posture: +- Linux: supported when process capture is enabled +- macOS Lima: supported because world-service runs inside a Linux guest +- Windows: explicit degrade-only posture for this feature + +## 1. Process event payload + +`process_events` is a list of normalized process lifecycle records. + +### Base fields + +- `event_type`: `world_process_start` or `world_process_exit` +- `ts` +- `ts_unix_ns` +- `session_id` +- `world_id` +- `pid` +- `ppid` +- `cwd` +- `parent_span` +- `parent_cmd_id` when available + +### Argv capture + +Exactly one of the following must be present: +- `argv` +- `argv_omitted: true` + +### Start-only fields + +- `exe` may be present as best effort + +### Exit-only fields + +For `world_process_exit`, exactly one of the following must be present: +- `exit_code` +- `signal` + +`duration_ms` is also required on exit records. + +### Optional env capture + +- `env` is optional +- env keys are allowlist-only and may be redacted + +### Ordering + +`process_events` must be sorted by: +1. `ts_unix_ns` ascending +2. `pid` ascending +3. `event_type`, with `world_process_start` before `world_process_exit` + +## 2. Diagnostics and degrade posture + +Responses and frames that carry `process_events` must include: +- `process_events_status`: `ok | unavailable | truncated | error` +- `process_events_reason` when status is not `ok` + +Optional summaries: +- when status is `truncated`: + - `process_events_dropped` + - `process_events_max` +- when status is `unavailable`: + - `process_events_backend` +- when status is `error`: + - `process_events_error` + +Stable non-ok reason examples: +- `not_supported_platform` +- `backend_disabled` +- `ptrace_not_permitted` +- `capture_overflow` +- `internal_error` + +## 3. HTTP execute response additions + +`ExecuteResponse` must include: +- `process_events` +- `process_events_status` +- `process_events_reason` when status is not `ok` + +Rules: +- on Linux-backed supported backends, status must be `ok` or `truncated` +- on Windows for this feature, status must be `unavailable` with reason `not_supported_platform` +- `process_events` may be omitted only when status is `error` and no safe records can be emitted + +## 4. WebSocket stream exit-frame additions + +For the v1 stream protocol: +- `process_events*` fields appear only on the exit frame +- per-event streaming of process telemetry is not part of v1 + +Exit frames must include: +- `process_events` +- `process_events_status` +- `process_events_reason` when status is not `ok` + +## 5. Host persistence contract + +The host shell persists each process event as a canonical JSONL record with: +- `component: "world-service"` +- `event_type` copied from the process event payload +- required process-event fields preserved after host normalization + +The host must not synthesize raw argv or env values that were omitted or redacted by world-service. + +For each world execution, the host shell also persists protocol diagnostics on the corresponding +shell completion record: +- `process_events_status` +- `process_events_reason` when status is not `ok` +- `process_events_dropped` when status is `truncated` diff --git a/docs/internals/trace/schema.md b/docs/internals/trace/schema.md index c7b9f20c1..810306d58 100644 --- a/docs/internals/trace/schema.md +++ b/docs/internals/trace/schema.md @@ -1,9 +1,131 @@ # Trace Schema (Internal) -This page is a compact index, not the authoritative schema. +This document is the stable internal schema reference for canonical trace record families. -Authoritative schema surfaces: +Related sources: - [docs/TRACE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/TRACE.md) -- [active pack SCHEMA.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md) +- `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` -Use this file for short implementation notes, legacy field reminders, and pointers to the code that emits each record family. +## 1. Span records (`command_start` / `command_complete`) + +### Required invariants + +- `parent_span` on `command_complete` must equal the parent captured at span start. +- Deny completion spans must include `outcome: "denied"`. +- `duration_ms` must be present on completion spans. +- `policy_decision` must be present on completion spans whenever the command was policy-evaluated. +- `span_id` must be present on shell `command_start` and `command_complete` events when a span exists. +- `parent_cmd_id`, when present, must equal `SHIM_PARENT_CMD_ID` for the execution. + +### Shell command summary fields + +Shell `command_complete` events must include: +- `world_fs_strategy_primary` +- `world_fs_strategy_final` +- `world_fs_strategy_fallback_reason` + +For world-backed executions, shell completion events must also include: +- `process_events_status` +- `process_events_reason` when status is not `ok` +- `process_events_dropped` when status is `truncated` + +## 2. World process event family + +This family is the canonical subprocess exec/exit telemetry path. + +Event types: +- `world_process_start` +- `world_process_exit` + +### Required fields + +- `ts` +- `ts_unix_ns` +- `event_type` +- `component: "world-service"` +- `session_id` +- `world_id` +- `pid` +- `ppid` +- `cwd` +- exactly one of: + - `argv` + - `argv_omitted: true` +- `parent_span` +- `parent_cmd_id` when available + +### Exit-only fields + +- `exit_code` or `signal` +- `duration_ms` + +### Optional fields + +- `env` +- `exe` + +### Truncation caps + +- max events per execution: 10,000 by default +- max env value length: 4 KB per value by default + +Protocol-level truncation reporting is owned by +[protocol.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/trace/protocol.md). + +## 3. Builtin and preexec trace posture + +When `SUBSTRATE_ENABLE_PREEXEC=1`: +- `builtin_command` records in canonical trace must omit command bodies +- canonical records must include: + - `command_omitted: true` + - `parent_cmd_id` when available + +When `SUBSTRATE_PREEXEC_RAW_LOG` is set: +- raw debug-only records are written as `builtin_command_raw` +- raw records must include `may_contain_secrets: true` + +## 4. Router-derived and toolbox event families + +Phase 8 additive correlation extends canonical trace beyond shell and world-service spans. + +### Router-derived event examples + +- `workflow_router_rule_match` +- `workflow_router_request_enqueued` +- `workflow_router_request_denied` +- `workflow_router_request_pending_approval` +- `workflow_router_action_enqueued` +- `workflow_router_action_executed` +- `workflow_router_cursor_gap_detected` + +Required join keys for router-derived rows: +- `request_id` +- `idempotency_key` +- `workspace_id` +- one explicit cause reference: + - `source_span_id`, and/or + - `source_cmd_id` +- `rule_id` + +### Toolbox tool-call event examples + +- `toolbox_tool_call_start` +- `toolbox_tool_call_complete` + +Required fields: +- `component: "agent-toolbox"` +- `session_id` +- `orchestration_session_id` +- `run_id` +- `agent_id` +- `backend_id` +- `tool_call_id` +- `tool_name` + +Completion rows must also include: +- `outcome` +- `duration_ms` + +Safe-by-default payload rule: +- canonical toolbox records must not embed full request args or full tool response bodies +- use omission markers such as `args_omitted: true` and `result_omitted: true` diff --git a/docs/internals/world/deps.md b/docs/internals/world/deps.md index 2b3237753..bc9d1c91e 100644 --- a/docs/internals/world/deps.md +++ b/docs/internals/world/deps.md @@ -159,9 +159,7 @@ Those internal world-deps profiles are reserved for Substrate’s built-in world Contract source: - `docs/reference/world/deps/README.md` -- `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md` -- Historical draft-pack path: - `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md` +- `docs/reference/world/deps/provisioning.md` Implementation lives in: - runtime preflight/probe: `crates/shell/src/builtins/world_deps/surfaces.rs` diff --git a/docs/reference/config/world.md b/docs/reference/config/world.md index 01b720ab0..6354b7517 100644 --- a/docs/reference/config/world.md +++ b/docs/reference/config/world.md @@ -104,7 +104,7 @@ Controls whether Substrate forwards a small allowlist of host environment variab See: - Full configuration reference (including env forwarding contract): `docs/CONFIGURATION.md` -- Planning contract (host-visible hardening): `docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH0-spec.md` +- This page is the stable host-visible hardening reference. ### Hardened worlds: `$HOME` is scratch (ephemeral) diff --git a/docs/reference/world/deps/README.md b/docs/reference/world/deps/README.md index 897c514c5..ee15bf9a7 100644 --- a/docs/reference/world/deps/README.md +++ b/docs/reference/world/deps/README.md @@ -109,4 +109,4 @@ Behavior: Internal details and rationale: - `docs/internals/world/deps.md` - WDAP1 provisioning/remediation contract: - `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md` (compatibility shim only) + `docs/reference/world/deps/provisioning.md` diff --git a/docs/reference/world/deps/provisioning.md b/docs/reference/world/deps/provisioning.md new file mode 100644 index 000000000..bb84daed9 --- /dev/null +++ b/docs/reference/world/deps/provisioning.md @@ -0,0 +1,68 @@ +# World Deps Provisioning Contract + +This document is the stable operator-facing contract for system-package provisioning and runtime +fail-early behavior in `substrate world deps`. + +## Commands in scope + +- Provisioning: + - `substrate world enable --provision-deps [--dry-run] [--verbose]` +- Runtime world deps: + - `substrate world deps current sync [--dry-run] [--verbose] [--all]` + - `substrate world deps current install [--dry-run] [--verbose]` + +## Core invariants + +- Runtime `substrate world deps current sync` and `substrate world deps current install` never + invoke `apt`, `apt-get`, mutating `dpkg`, or `pacman`. +- Runtime system-package checks are probe-only and use read-only presence checks. +- `substrate world enable --provision-deps` is the only operator-facing Substrate workflow that + performs provisioning-time system-package mutation for world deps on supported guest backends. +- Linux host-native must not mutate the host OS. +- Missing-package remediation includes the exact command: + +```text +substrate world enable --provision-deps +``` + +## Platform and backend guarantees + +| Platform/backend | `substrate world enable --provision-deps` | Runtime `substrate world deps current sync/install` for system-package-backed items | +| --- | --- | --- | +| Linux host-native world backend | Unsupported (exit `4`); Substrate will not mutate the host OS | Probe-only; exits `4` when required system packages are missing | +| macOS Lima guest world backend | Supported | Probe-only; exits `4` when required system packages are missing | +| Windows | Unsupported (exit `4`); unsupported on Windows | Probe-only; exits `4` when required system packages are missing | + +## Provisioning contract + +`substrate world enable --provision-deps` derives requirements from the effective enabled +world-deps set for the current directory. + +Behavior: +- If the derived requirement set is empty, the command is a no-op and exits `0`. +- If all required system packages are already present, the command is a no-op and exits `0`. +- `--dry-run` prints the derived requirement set without mutating the world. +- `--verbose` additionally reports the provisioning request posture used for the world-service call. +- On Linux host-native, the command exits `4` and states that Substrate will not mutate the host OS. +- On Windows, the command exits `4` and remains unsupported on Windows. + +## Runtime fail-early contract + +For system-package-backed items, runtime application remains probe-only: +- `substrate world deps current sync` +- `substrate world deps current install ` + +Behavior: +- Requirements are derived from the in-scope item set. +- Requirements are probed read-only inside the world. +- If required system packages are missing, the command exits `4` with remediation. +- If required system packages are already present, system-package items are treated as satisfied and + Substrate continues with non-system-package work. +- `--dry-run` still enforces the fail-early rule and still exits `4` when required system packages + are missing. + +## Request profile note + +Built-in world-deps request profiles such as `world-deps-provision` and `world-deps-probe` are +reserved for Substrate’s own world-deps flows. `SUBSTRATE_WORLD_REQUEST_PROFILE` does not select +them. From e91da0b18b239b63ac6ce4b6302421e71b2e33e0 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 11:39:40 -0400 Subject: [PATCH 06/20] Extract policy docs and retire broker pack tests --- crates/broker/src/tests.rs | 322 +++--------------- .../docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md | 12 +- ...-foundry-c07-runtime-transport-contract.md | 8 +- ...ndry-c08-operator-verification-contract.md | 8 +- ...de-code-c09-operator-bootstrap-contract.md | 8 +- ...e-code-c10-live-session-smoke-procedure.md | 6 +- ...ive-session-smoke-verification-contract.md | 10 +- ...eshooting-and-support-boundary-contract.md | 12 +- ...nai-side-conformance-suite-c13-contract.md | 4 +- .../substrate-boundary-c05-contract.md | 5 +- ...xplicit-tool-calls-k2-thinking-stream.json | 2 +- .../hidden-markers-k2-thinking-nonstream.json | 2 +- .../hidden-markers-k2-thinking-stream.json | 2 +- ...-reasoning-and-tool-calls-k2-thinking.json | 2 +- .../no-tool-control-k2-5-stream.json | 2 +- .../tests/world_deps_apt_fail_early_wdap1.rs | 20 +- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 24 +- .../gateway/backend-adapter-selection.md | 4 +- docs/contracts/gateway/policy-evaluation.md | 3 + docs/reference/policy/README.md | 11 +- docs/reference/policy/contract.md | 90 ++++- docs/reference/policy/schema.md | 131 +++++++ docs/reference/policy/tuple_constraints.md | 142 ++++++++ 23 files changed, 469 insertions(+), 361 deletions(-) create mode 100644 docs/reference/policy/schema.md create mode 100644 docs/reference/policy/tuple_constraints.md diff --git a/crates/broker/src/tests.rs b/crates/broker/src/tests.rs index cdf268e8a..3fab52925 100644 --- a/crates/broker/src/tests.rs +++ b/crates/broker/src/tests.rs @@ -992,20 +992,6 @@ mod c0_policy_patch_only_broker_effective_resolution { .unwrap_or_else(|err| panic!("read {relative}: {err}")) } - fn read_repo_json(relative: &str) -> serde_json::Value { - serde_json::from_str(&read_repo_file(relative)) - .unwrap_or_else(|err| panic!("parse {relative} as JSON: {err}")) - } - - fn task_by_id<'a>(tasks_json: &'a serde_json::Value, id: &str) -> &'a serde_json::Value { - tasks_json["tasks"] - .as_array() - .unwrap_or_else(|| panic!("tasks.json missing tasks array: {tasks_json}")) - .iter() - .find(|task| task.get("id").and_then(|value| value.as_str()) == Some(id)) - .unwrap_or_else(|| panic!("tasks.json missing task {id}")) - } - struct Fixture { _temp: TempDir, home: PathBuf, @@ -1196,34 +1182,47 @@ world_fs: #[test] fn c0_itps0_contract_doc_locks_authoritative_surface_exit_codes_and_deny_patterns() { - let contract = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/contract.md", - ); + let contract = read_repo_file("docs/reference/policy/contract.md"); + let tuple_constraints = read_repo_file("docs/reference/policy/tuple_constraints.md"); for needle in [ - "`substrate policy current show --explain` is the authoritative merged inspection surface for `llm.constraints.*`.", - "tuple-policy publication reuses the existing `identity_tuple` and `placement_posture` field family", - "tuple-policy schema invalidity maps to `2`", - "tuple-axis mismatch denial maps to `5`", + "Substrate's LLM and agent surfaces stay on the existing layered config and policy files:", + "Backend ids remain adapter selectors only.", + "ADR-0043 extends the policy surface additively under `llm.constraints.*`.", + "`substrate policy current show --explain` is the authoritative merged inspection surface", + "Tuple-policy publication reuses the existing `identity_tuple` and `placement_posture` field", + "Tuple-axis mismatch denial maps to exit code `5`.", + ] { + assert!( + contract.contains(needle), + "expected policy contract to contain {needle:?}" + ); + } + + for needle in [ + "Tuple-policy schema invalidity maps to `2`.", "effective gateway routing authority 'substrate_gateway' is not allowlisted by llm.constraints.routers", "effective gateway protocol '' is not allowlisted by llm.constraints.protocols", "effective gateway provider '' is not allowlisted by llm.constraints.providers", "effective gateway auth authority '' is not allowlisted by llm.constraints.auth_authorities", ] { assert!( - contract.contains(needle), - "expected ITPS0 contract to contain {needle:?}" + tuple_constraints.contains(needle), + "expected tuple constraint reference to contain {needle:?}" ); } } #[test] fn c0_itps0_schema_doc_locks_owned_keys_defaults_replace_semantics_and_client_omission() { - let schema = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tuple-policy-schema-spec.md", - ); + let schema = read_repo_file("docs/reference/policy/schema.md"); + let tuple_constraints = read_repo_file("docs/reference/policy/tuple_constraints.md"); for needle in [ + "`llm.allowed_backends: [string]`", + "`agents.allowed_backends: [string]`", + "`workflow.router.allowed_workflow_ids: [string]`", + "ADR-0043 extends this policy family additively with tuple-axis narrowing constraints under", "`llm.constraints.routers`", "`llm.constraints.providers`", "`llm.constraints.protocols`", @@ -1234,13 +1233,13 @@ world_fs: "- `llm.constraints.clients`", ] { assert!( - schema.contains(needle), - "expected ITPS0 schema spec to contain {needle:?}" + schema.contains(needle) || tuple_constraints.contains(needle), + "expected stable policy references to contain {needle:?}" ); } assert!( - !schema.contains("| `llm.constraints.clients` |"), - "schema spec must not introduce llm.constraints.clients as a canonical key" + !tuple_constraints.contains("| `llm.constraints.clients` |"), + "tuple constraint reference must not introduce llm.constraints.clients as a canonical key" ); } @@ -1382,274 +1381,33 @@ world_fs: #[test] fn c1_itps1_policy_spec_locks_runtime_order_fail_early_rules_and_failure_buckets() { - let policy_spec = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md", - ); + let policy_spec = read_repo_file("docs/reference/policy/tuple_constraints.md"); for needle in [ - "1. Validate gateway lifecycle config:", - "2. Resolve the selected backend inventory entry and apply `llm.allowed_backends` before tuple derivation begins.", + "1. Validate gateway lifecycle config.", + "2. Resolve the selected backend inventory entry and apply `llm.allowed_backends` before tuple", "4. Apply tuple-axis narrowing in this exact order:", - "- `llm.constraints.routers`", - "- `llm.constraints.protocols`", - "- `llm.constraints.providers`", - "- `llm.constraints.auth_authorities`", + "5. Resolve integrated auth source material:", + "6. Apply world-boundary posture.", + "7. Apply downstream transport and egress gates.", "- blocked env auth is a policy denial", "- partial env auth is invalid integration", - "- If the selected backend id is absent from `llm.allowed_backends`, evaluation stops before tuple-axis narrowing.", + "If the selected backend id is absent from `llm.allowed_backends`, evaluation stops before", "\" is not allowlisted by effective policy llm.allowed_backends\"", - "\"effective gateway routing authority '' is not allowlisted by llm.constraints.routers\"", - "\"effective gateway protocol '' is not allowlisted by llm.constraints.protocols\"", - "\"effective gateway provider is unresolved while llm.constraints.providers is constrained\"", - "\"effective gateway provider '' is not allowlisted by llm.constraints.providers\"", - "\"effective gateway auth authority is unresolved while llm.constraints.auth_authorities is constrained\"", - "\"effective gateway auth authority '' is not allowlisted by llm.constraints.auth_authorities\"", + "effective gateway provider is unresolved while llm.constraints.providers is constrained", + "effective gateway auth authority is unresolved while llm.constraints.auth_authorities is constrained", "- the required world or gateway socket is missing", "- connection refused", "- timeout", - "- `substrate policy current show --explain` is the authoritative merged inspection surface for `llm.constraints.*`.", - "- Explain output for tuple-aware denials must identify the exact policy key that denied the route.", + "Explain output for tuple-aware denials must identify the exact policy key that denied the route.", ] { assert!( policy_spec.contains(needle), - "expected ITPS1 policy spec to contain {needle:?}" + "expected tuple constraint reference to contain {needle:?}" ); } } - #[test] - fn c1_itps1_decision_register_locks_tuple_family_reuse_and_explain_surface_ownership() { - let decision_register = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/decision_register.md", - ); - - for needle in [ - "### DR-ITPS-01 — Tuple-policy publication family (`identity_tuple` reuse vs trace-only tuple shape)", - "- **Selected:** Option A — Reuse `identity_tuple` and `placement_posture` across status, diagnostics, and trace.", - "One tuple vocabulary preserves semantic ownership and prevents schema drift across deny, status, and trace surfaces.", - "### DR-ITPS-02 — Authoritative inspection surface for `llm.constraints.*` (`policy current show --explain` vs config view)", - "- **Selected:** Option A — `substrate policy current show --explain` is the authoritative merged inspection surface.", - "Tuple-axis constraints are policy keys, and the policy effective view is already the merged explain surface that carries their provenance.", - ] { - assert!( - decision_register.contains(needle), - "expected ITPS1 decision register to contain {needle:?}" - ); - } - } - - #[test] - fn c3_itps3_manual_validation_closure_locks_cross_platform_review_and_stale_reference_audits() { - let spec = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/ITPS3-spec.md", - ); - let playbook = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md", - ); - let adr = read_repo_file( - "docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md", - ); - - for needle in [ - "- `ITPS3` closes the manual review matrix for the authoritative `substrate policy current show --explain` surface, schema-invalid tuple-policy input, tuple-aware gateway status publication, and the router, provider, protocol, and auth-authority deny families.", - "- Validation closure covers Linux, macOS, and Windows as one operator contract, even when the execution substrate differs across world backends.", - "- Validation examples that mention paths such as `~/.codex/auth.json` remain validation-only examples and do not become new Substrate-owned path contracts.", - "- Validation closure includes one-owner-per-surface review across `contract.md`, `tuple-policy-schema-spec.md`, `policy-spec.md`, `telemetry-spec.md`, `compatibility-spec.md`, and `manual_testing_playbook.md`.", - "- Validation closure includes stale-reference review for overloaded `backend_id` wording, config-versus-policy inspection drift, and any wording that implies telemetry owns tuple semantics.", - ] { - assert!( - spec.contains(needle), - "expected ITPS3 spec to contain {needle:?}" - ); - } - - for needle in [ - "Behavior-platform smoke coverage:", - "Windows smoke remains optional manual evidence for this pack and automates only the policy inspection plus schema-invalid checks because Windows is compile-parity only in `tasks.json`.", - "sections 6 through 8 remain the manual extension path for protocol mismatch, auth-authority mismatch, and validation-only auth-file review.", - "## One-owner-per-surface checklist", - "## Stale-reference checks", - "Accept only if `substrate policy current show --explain` is the authoritative merged view for `llm.constraints.*`.", - "rg -n '~/.codex/auth.json|codex_subscription|openai_api_key' \\", - "- `~/.codex/auth.json` appears only as illustrative validation input", - "- `tuple-policy-schema-spec.md` is the only owner of `llm.constraints.*` key grammar, defaults, and empty-list semantics.", - "- `policy-spec.md` is the only owner of tuple-axis evaluation ordering and deny taxonomy.", - "- `telemetry-spec.md` is the only owner of tuple-aware allow and deny publication rules.", - "- `compatibility-spec.md` is the only owner of additive rollout and promotion invariants.", - ] { - assert!( - playbook.contains(needle), - "expected ITPS3 manual playbook to contain {needle:?}" - ); - } - - for needle in [ - "- `substrate policy current show --explain` is the authoritative merged inspection surface for `llm.constraints.*`.", - "- Linux:", - "- macOS:", - "- Windows:", - "- Same policy semantics as Linux.", - "- Codex + Responses API + `~/.codex/auth.json`, with `auth_authority` expressed separately from `provider`.", - ] { - assert!( - adr.contains(needle), - "expected ADR-0043 to contain {needle:?}" - ); - } - } - - #[test] - fn c3_itps3_checkpoint_alignment_locks_single_post_itps3_boundary_and_task_wiring() { - let spec = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/ITPS3-spec.md", - ); - let checkpoint_plan = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/ci_checkpoint_plan.md", - ); - let tasks_json = read_repo_json( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tasks.json", - ); - - for needle in [ - "- `ITPS3` is the final slice before the only pre-planned CI checkpoint boundary for this feature.", - "- The accepted slice order remains `ITPS0`, `ITPS1`, `ITPS2`, `ITPS3`.", - "- `CP1-ci-checkpoint` is aligned to run after `ITPS3` and to validate the completed broker, shell, trace, and operator-contract seam together.", - "- `meta.checkpoint_boundaries = [\"ITPS3\"]` remains the required final-task wiring target once the single-writer planning lane materializes `tasks.json`.", - "- `ITPS3` does not create a second checkpoint or split the existing cross-platform gate into platform-local promotion paths.", - ] { - assert!( - spec.contains(needle), - "expected ITPS3 spec to contain {needle:?}" - ); - } - - for needle in [ - "\"task_id\": \"CP1-ci-checkpoint\"", - "\"slices\": [\"ITPS0\", \"ITPS1\", \"ITPS2\", \"ITPS3\"]", - "Cross-platform validation after ITPS3 covers Linux/macOS feature behavior plus Linux/macOS/Windows compile parity", - "- Set `tasks.json` `meta.checkpoint_boundaries = [\"ITPS3\"]`.", - ] { - assert!( - checkpoint_plan.contains(needle), - "expected checkpoint plan to contain {needle:?}" - ); - } - - assert_eq!( - tasks_json["meta"]["checkpoint_boundaries"], - serde_json::json!(["ITPS3"]), - "tasks.json must keep ITPS3 as the sole checkpoint boundary" - ); - - let expected_depends_on = [ - ("ITPS3-code", serde_json::json!(["ITPS2-integ"])), - ("ITPS3-test", serde_json::json!(["ITPS2-integ"])), - ( - "ITPS3-integ-core", - serde_json::json!(["ITPS3-code", "ITPS3-test"]), - ), - ("CP1-ci-checkpoint", serde_json::json!(["ITPS3-integ-core"])), - ("ITPS3-integ-linux", serde_json::json!(["ITPS3-integ-core"])), - ("ITPS3-integ-macos", serde_json::json!(["ITPS3-integ-core"])), - ( - "ITPS3-integ-windows", - serde_json::json!(["ITPS3-integ-core"]), - ), - ( - "ITPS3-integ", - serde_json::json!([ - "ITPS3-integ-core", - "ITPS3-integ-linux", - "ITPS3-integ-macos", - "ITPS3-integ-windows" - ]), - ), - ("FZ-feature-cleanup", serde_json::json!(["ITPS3-integ"])), - ]; - - for (task_id, expected) in expected_depends_on { - assert_eq!( - task_by_id(&tasks_json, task_id)["depends_on"], - expected, - "unexpected depends_on wiring for {task_id}" - ); - } - } - - #[test] - fn c3_itps3_promotion_packaging_extends_the_implemented_adr_0027_pack_without_reassigning_ownerships( - ) { - let spec = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/ITPS3-spec.md", - ); - let compatibility_spec = read_repo_file( - "docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/compatibility-spec.md", - ); - let implemented_contract = read_repo_file( - "docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md", - ); - let implemented_schema = read_repo_file( - "docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md", - ); - - for needle in [ - "- Promotion closes into the implemented ADR-0027 pack by extending its contract and schema surfaces with the tuple-axis policy additions locked by this feature.", - "- Promotion packaging requires the implemented ADR-0027 pack to absorb the authoritative policy inspection surface, tuple-axis schema tables, additive rollout wording, and validation-ready operator contract text.", - "- Promotion packaging does not move telemetry-field ownership out of `ITPS2`, does not move runtime-ordering ownership out of `ITPS1`, and does not create a second implemented pack for the same policy family.", - ] { - assert!( - spec.contains(needle), - "expected ITPS3 spec to contain {needle:?}" - ); - } - - for needle in [ - "Promotion is complete only when the implemented ADR-0027 pack absorbs these additive surfaces:", - "- tuple-policy contract wording for `substrate policy current show --explain`", - "- schema tables for the four `llm.constraints.*` keys", - "- additive rollout wording that keeps policy files and precedence unchanged", - "Promotion does not move tuple semantics out of ADR-0042 or trace-envelope ownership out of ADR-0028.", - "- Promotion into the implemented ADR-0027 pack extends the existing policy system instead of creating a second one.", - ] { - assert!( - compatibility_spec.contains(needle), - "expected compatibility spec to contain {needle:?}" - ); - } - - for needle in [ - "- `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md`", - "- ADR-0043 extends the policy surface additively with tuple-axis constraints under `llm.constraints.*`.", - ] { - assert!( - implemented_contract.contains(needle), - "expected implemented ADR-0027 contract to contain {needle:?}" - ); - } - - for needle in [ - "Phase 8 additive note:", - "- ADR-0043 extends this policy family with tuple-axis narrowing constraints under `llm.constraints`:", - "- `llm.constraints.routers`", - "- `llm.constraints.providers`", - "- `llm.constraints.protocols`", - "- `llm.constraints.auth_authorities`", - "- Those keys are additive follow-on policy surfaces. They are not implemented or fully specified by this pack, but they must be interpreted as narrowing constraints layered on top of backend/adapter allowlists.", - ] { - assert!( - implemented_schema.contains(needle), - "expected implemented ADR-0027 schema to contain {needle:?}" - ); - } - - assert!( - !repo_root() - .join("docs/project_management/packs/implemented/adr-0027-identity-tuple-policy-surface") - .exists(), - "promotion must extend the existing implemented ADR-0027 pack instead of creating a second implemented policy-pack directory" - ); - } - #[test] #[serial] fn c0_policy_global_set_rejects_unknown_and_invalid_lacp0_updates_with_exit_2() { diff --git a/crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md b/crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md index a4f010b15..07ad6c550 100644 --- a/crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md +++ b/crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md @@ -14,15 +14,17 @@ These constraints are mandatory design guardrails for early implementation: Authoritative repository-local decisions: -- [ADR 0005](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0005-present-a-single-backend-identity-to-substrate.md) -- [ADR 0006](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md) -- [ADR 0007](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0007-integrate-via-normalized-structured-events-not-raw-provider-streams.md) +- [ADR 0005](crates/gateway/docs/adr/0005-present-a-single-backend-identity-to-substrate.md) +- [ADR 0006](crates/gateway/docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md) +- [ADR 0007](crates/gateway/docs/adr/0007-integrate-via-normalized-structured-events-not-raw-provider-streams.md) External planning inputs reviewed: - LLM/policy surface pack: - [/Users/spensermcconnell/__Sandbox/actions-runner/_work/substrate/substrate/candidate/docs/project_management/packs/active/llm_and_agent_config_policy_surface](/Users/spensermcconnell/__Sandbox/actions-runner/_work/substrate/substrate/candidate/docs/project_management/packs/active/llm_and_agent_config_policy_surface) + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` + - `docs/reference/policy/tuple_constraints.md` - Agent-hub output routing pack: - [/Users/spensermcconnell/__Sandbox/actions-runner/_work/substrate/substrate/docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing](/Users/spensermcconnell/__Sandbox/actions-runner/_work/substrate/substrate/docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing) + - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` If an implementation choice conflicts with these constraints, stop and resolve the conflict in docs before proceeding. diff --git a/crates/gateway/docs/foundation/azure-foundry-c07-runtime-transport-contract.md b/crates/gateway/docs/foundation/azure-foundry-c07-runtime-transport-contract.md index 2689bea8a..1c6d9a0ce 100644 --- a/crates/gateway/docs/foundation/azure-foundry-c07-runtime-transport-contract.md +++ b/crates/gateway/docs/foundation/azure-foundry-c07-runtime-transport-contract.md @@ -25,10 +25,10 @@ This contract is grounded in the seam-local evidence and the landed upstream bas Repo-grounded anchors: -- `docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/review.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/threading.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/review.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threading.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md` - `docs/foundation/anthropic-messages-c03-contract.md` - `docs/foundation/planner-executor-c04-policy-contract.md` - `docs/foundation/substrate-boundary-c05-contract.md` diff --git a/crates/gateway/docs/foundation/azure-foundry-c08-operator-verification-contract.md b/crates/gateway/docs/foundation/azure-foundry-c08-operator-verification-contract.md index d64e3d16b..89d01f4c2 100644 --- a/crates/gateway/docs/foundation/azure-foundry-c08-operator-verification-contract.md +++ b/crates/gateway/docs/foundation/azure-foundry-c08-operator-verification-contract.md @@ -27,10 +27,10 @@ This contract is grounded in the landed basis and seam-local planning below: - `docs/foundation/anthropic-messages-c03-contract.md` - `docs/foundation/planner-executor-c04-policy-contract.md` - `docs/foundation/substrate-boundary-c05-contract.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/threading.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md` -- `docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/review.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threading.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md` +- `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/review.md` If this note and the landed basis disagree, this note must be revalidated before downstream operator work proceeds. diff --git a/crates/gateway/docs/foundation/claude-code-c09-operator-bootstrap-contract.md b/crates/gateway/docs/foundation/claude-code-c09-operator-bootstrap-contract.md index 70da178f3..9087759b2 100644 --- a/crates/gateway/docs/foundation/claude-code-c09-operator-bootstrap-contract.md +++ b/crates/gateway/docs/foundation/claude-code-c09-operator-bootstrap-contract.md @@ -23,10 +23,10 @@ It does not define: This contract is grounded in the landed basis and seam-local planning below: -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/review.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/review.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` - `docs/foundation/azure-foundry-c07-runtime-transport-contract.md` - `docs/foundation/azure-foundry-c08-operator-verification-contract.md` - `docs/foundation/anthropic-messages-c03-contract.md` diff --git a/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-procedure.md b/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-procedure.md index a5b2c9da0..5e583bf08 100644 --- a/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-procedure.md +++ b/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-procedure.md @@ -23,9 +23,9 @@ This note is grounded in: - `docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md` - `docs/foundation/claude-code-c09-operator-bootstrap-contract.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` - `gateway/README.md` - `gateway/src/router/mod.rs` - `gateway/src/server/mod.rs` diff --git a/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md b/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md index c8bcd175e..d7e19eb18 100644 --- a/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md +++ b/crates/gateway/docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md @@ -23,11 +23,11 @@ It does not define: This contract is grounded in the landed basis and seam-local planning below: -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/slice-1-freeze-live-session-smoke-contract-and-coverage.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/slice-1-freeze-live-session-smoke-contract-and-coverage.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` - `docs/foundation/claude-code-c09-operator-bootstrap-contract.md` - `docs/foundation/azure-foundry-c08-operator-verification-contract.md` - `docs/foundation/anthropic-messages-c03-contract.md` diff --git a/crates/gateway/docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md b/crates/gateway/docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md index 477d47631..d4536f3d9 100644 --- a/crates/gateway/docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md +++ b/crates/gateway/docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md @@ -23,12 +23,12 @@ It does not define: This contract is grounded in the landed basis and seam-local planning below: -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/slice-1-freeze-troubleshooting-boundary-contract-and-taxonomy.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` -- `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/slice-1-freeze-troubleshooting-boundary-contract-and-taxonomy.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` +- `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md` - `docs/foundation/claude-code-c09-operator-bootstrap-contract.md` - `docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md` - `docs/foundation/claude-code-c10-live-session-smoke-procedure.md` diff --git a/crates/gateway/docs/foundation/openai-side-conformance-suite-c13-contract.md b/crates/gateway/docs/foundation/openai-side-conformance-suite-c13-contract.md index 6ce30486f..03580747d 100644 --- a/crates/gateway/docs/foundation/openai-side-conformance-suite-c13-contract.md +++ b/crates/gateway/docs/foundation/openai-side-conformance-suite-c13-contract.md @@ -15,8 +15,8 @@ It defines the SEAM-3 / `THR-13` conformance and drift-guard contract for the ga ## Canonical Sources Of Truth -- SEAM-3 planning: `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md` -- SEAM-3 pre-exec review: `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/review.md` +- SEAM-3 planning: `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md` +- SEAM-3 pre-exec review: `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/review.md` - Chat Completions contract: `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/openai-side-chat-completions-c10-contract.md` - Responses contract: `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/openai-side-responses-c11-contract.md` - Shared adapter invariants: `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/openai-side-adapter-invariants-c12-contract.md` diff --git a/crates/gateway/docs/foundation/substrate-boundary-c05-contract.md b/crates/gateway/docs/foundation/substrate-boundary-c05-contract.md index 3355b73ad..00d63c69c 100644 --- a/crates/gateway/docs/foundation/substrate-boundary-c05-contract.md +++ b/crates/gateway/docs/foundation/substrate-boundary-c05-contract.md @@ -23,8 +23,8 @@ It does not define: This contract is grounded in the seam-local boundary note and upstream contracts: -- `docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/seam.md` -- `docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md` +- `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/seam.md` +- `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md` - `docs/foundation/claude-code-mux-extension-boundary.md` - `docs/foundation/anthropic-messages-c03-contract.md` - `docs/foundation/planner-executor-c04-policy-contract.md` @@ -81,4 +81,3 @@ Downstream revalidation is required if any of the following changes: - do public docs and config examples avoid planner/executor/provider identity leakage - are localhost and `127.0.0.1` clearly framed as development conveniences - do the drift guards make identity and deployment regressions explicit - diff --git a/crates/gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json b/crates/gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json index 3b6240fcc..499411150 100644 --- a/crates/gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json +++ b/crates/gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json @@ -1,7 +1,7 @@ { "case_id": "explicit-tool-calls-k2-thinking-stream", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "raw_artifact_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-response.json", + "raw_artifact_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-response.json", "normalized_events": [ { "event_kind": "action", diff --git a/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json b/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json index 1f6015abd..3e30d2f12 100644 --- a/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json +++ b/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json @@ -1,7 +1,7 @@ { "case_id": "hidden-markers-k2-thinking-nonstream", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "raw_artifact_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-response.json", + "raw_artifact_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-response.json", "normalized_events": [ { "event_kind": "action", diff --git a/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json b/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json index 731b05070..6a63cf18b 100644 --- a/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json +++ b/crates/gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json @@ -1,7 +1,7 @@ { "case_id": "hidden-markers-k2-thinking-stream", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "raw_artifact_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json", + "raw_artifact_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json", "normalized_events": [ { "event_kind": "action", diff --git a/crates/gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json b/crates/gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json index f8dc4bcbb..a78f914dd 100644 --- a/crates/gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json +++ b/crates/gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json @@ -1,7 +1,7 @@ { "case_id": "mixed-reasoning-and-tool-calls-k2-thinking", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "raw_artifact_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-response.json", + "raw_artifact_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-response.json", "normalized_events": [ { "event_kind": "action", diff --git a/crates/gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json b/crates/gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json index 4bc17056a..394259808 100644 --- a/crates/gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json +++ b/crates/gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json @@ -1,7 +1,7 @@ { "case_id": "no-tool-control-k2-5-stream", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "raw_artifact_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-response.json", + "raw_artifact_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-response.json", "normalized_events": [ { "event_kind": "final", diff --git a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs index dc6cd88ce..6c1ef716a 100644 --- a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs +++ b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs @@ -47,9 +47,7 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { "expected docs/reference/world/deps/README.md to include the commands heading" ); assert!( - reference_readme.contains( - "docs/reference/world/deps/provisioning.md" - ), + reference_readme.contains("docs/reference/world/deps/provisioning.md"), "expected docs/reference/world/deps/README.md to link to the stable provisioning contract" ); assert!( @@ -67,9 +65,7 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { "expected docs/internals/world/deps.md to include the runtime fail-early heading" ); assert!( - internals.contains( - "docs/reference/world/deps/provisioning.md" - ), + internals.contains("docs/reference/world/deps/provisioning.md"), "expected docs/internals/world/deps.md to link to the stable provisioning contract" ); assert!( @@ -87,9 +83,7 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { "expected docs/WORLD.md to mention the request profile field" ); assert!( - world_doc.contains( - "docs/reference/world/deps/provisioning.md" - ), + world_doc.contains("docs/reference/world/deps/provisioning.md"), "expected docs/WORLD.md to link to the stable provisioning contract" ); @@ -99,9 +93,7 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { "expected docs/CONFIGURATION.md to include SUBSTRATE_WORLD_REQUEST_PROFILE" ); assert!( - configuration.contains( - "docs/reference/world/deps/provisioning.md" - ), + configuration.contains("docs/reference/world/deps/provisioning.md"), "expected docs/CONFIGURATION.md to link to the stable provisioning contract" ); assert!( @@ -119,9 +111,7 @@ fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { "expected docs/COMMANDS.md to document the --provision-deps flag" ); assert!( - commands.contains( - "docs/reference/world/deps/provisioning.md" - ), + commands.contains("docs/reference/world/deps/provisioning.md"), "expected docs/COMMANDS.md to link to the stable provisioning contract" ); diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 97e77a79e..c469d4a1b 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -143,14 +143,18 @@ Current pack sources: - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` - draft pack docs under `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/` -Recommended destination: -- absorb stable policy contract wording into `docs/reference/policy/contract.md` -- absorb stable schema ownership into a new or expanded doc under `docs/reference/policy/` -- keep the ADR itself in `docs/project_management/adrs/**` for historical record +Stable destinations now in place: +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` +- `docs/reference/policy/tuple_constraints.md` -Required follow-up: -- rewrite `crates/broker/src/tests.rs` -- decide which draft-pack assertions remain valid as product contract tests versus planning-process checks to delete +Completed follow-up: +- rewrote `crates/broker/src/tests.rs` to lock stable policy references instead of pack docs +- deleted planning-only broker assertions that were validating slice specs, checkpoint wiring, and promotion packaging rather than product contract + +Remaining follow-up: +- keep the ADRs in `docs/project_management/adrs/**` for historical record until the broader ADR namespace move is addressed +- repoint downstream ADR and planning references as separate retirement slices rather than treating them as blockers for the stable policy reference itself ### D. Workspace sync filesystem semantics @@ -196,7 +200,11 @@ Required follow-up: - any Rust test that validates product behavior by asserting current docs mention the right contract - any stable operator or internal doc that cites a pack path as canonical -- gateway docs and fixture provenance that would otherwise point at deleted top-level packs +- remaining gateway-local docs and fixture provenance that still point at deleted top-level packs + after the completed rewrites in: + - `crates/gateway/docs/foundation/**` + - `crates/gateway/tests/fixtures/azure_kimi/**` + - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` ## Atomic `packs/**` Retirement Procedure diff --git a/docs/contracts/gateway/backend-adapter-selection.md b/docs/contracts/gateway/backend-adapter-selection.md index 356d065ed..6f8049d98 100644 --- a/docs/contracts/gateway/backend-adapter-selection.md +++ b/docs/contracts/gateway/backend-adapter-selection.md @@ -73,6 +73,6 @@ The implementation and verification surfaces for this contract are expected to s - `crates/broker/src/effective_policy.rs` - `crates/shell/src/execution/config_model.rs` - `crates/shell/src/execution/policy_model.rs` -- `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` -- `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/docs/contracts/gateway/policy-evaluation.md b/docs/contracts/gateway/policy-evaluation.md index 5ef46492a..f1067d19d 100644 --- a/docs/contracts/gateway/policy-evaluation.md +++ b/docs/contracts/gateway/policy-evaluation.md @@ -44,6 +44,9 @@ Not defined here: - config schema ownership already covered elsewhere - `client_wiring.*` status-schema detail +Tuple-axis key ownership, runtime ordering, and deny wording for `llm.constraints.*` live in +`docs/reference/policy/tuple_constraints.md`. + ## Boundary rules - fail closed when in-world execution is required and no world boundary is available diff --git a/docs/reference/policy/README.md b/docs/reference/policy/README.md index 8ab1d7b37..a82e1234a 100644 --- a/docs/reference/policy/README.md +++ b/docs/reference/policy/README.md @@ -1,8 +1,9 @@ # Policy Reference -This directory is scaffolding: it is intended to hold the stable operator contract for policy files and policy mode semantics. - -Existing related docs (top-level): -- `docs/BROKER.md` -- `docs/WORLD.md` +Stable policy reference docs live here. +- `contract.md`: operator-facing ADR-0027 contract for policy/config file families, precedence, + fail-closed posture, backend allowlists, and host credential-read gates. +- `schema.md`: authoritative ADR-0027 key-path, type, default, and merge-strategy reference. +- `tuple_constraints.md`: additive ADR-0043 policy reference for `llm.constraints.*`, including + grammar, evaluation order, deny wording, and explain-surface ownership. diff --git a/docs/reference/policy/contract.md b/docs/reference/policy/contract.md index 30ad17fb6..f234a9107 100644 --- a/docs/reference/policy/contract.md +++ b/docs/reference/policy/contract.md @@ -1,12 +1,86 @@ # Policy Contract -This file is scaffolding: it will define the stable policy contract: -- policy file locations (global vs workspace), -- policy mode semantics (disabled/observe/enforce), -- strict parsing expectations, -- and how policy interacts with world isolation and filesystem mode. +This document is the stable operator-facing contract for the ADR-0027 config and policy surface. -Existing related docs: -- `docs/BROKER.md` -- `docs/WORLD.md` +Related references: +- `docs/reference/policy/schema.md` +- `docs/reference/policy/tuple_constraints.md` +- `docs/contracts/gateway/policy-evaluation.md` +## Authoritative file families + +Substrate's LLM and agent surfaces stay on the existing layered config and policy files: + +- Config: + - Global: `$SUBSTRATE_HOME/config.yaml` (default `~/.substrate/config.yaml`) + - Workspace: `/.substrate/workspace.yaml` +- Policy: + - Global: `$SUBSTRATE_HOME/policy.yaml` (default `~/.substrate/policy.yaml`) + - Workspace: `/.substrate/policy.yaml` +- Agent inventory: + - Global: `$SUBSTRATE_HOME/agents/.yaml` (default `~/.substrate/agents/.yaml`) + - Workspace: `/.substrate/agents/.yaml` + +This contract does not introduce a second config system or new root file family. + +## Core invariants + +- Unknown config or policy keys are hard errors. +- Invalid values for known keys are hard errors. +- Config and policy schema invalidity maps to exit code `2`. +- LLM and agent routing remain fail-closed by default. +- Backend allowlists remain deny-by-default: + - `llm.allowed_backends=[]` denies LLM routing. + - `agents.allowed_backends=[]` denies agent routing. +- Backend ids remain adapter selectors only. They must not be overloaded with router, provider, + auth-authority, protocol, planner, executor, or wrapper identity. +- Per-agent `policy_overlay` remains restriction-only. +- Secrets must not be stored in Substrate YAML patches. +- Host credential reads remain explicitly policy-gated by + `agents.host_credentials.read.allowed_backends`. +- Router daemon indirect execution remains explicitly policy-gated by `workflow.router.*`. + +## Precedence + +Config precedence remains unchanged and applies per key: +1. CLI flags for keys that explicitly support them +2. Workspace config patch +3. `SUBSTRATE_OVERRIDE_*` environment overrides when no workspace is active +4. Global config patch +5. Built-in defaults + +Policy precedence remains unchanged and applies per key: +1. Workspace policy patch +2. Global policy patch +3. Built-in defaults + +## Tuple-policy additive alignment + +ADR-0027 remains the root contract for: + +- config and policy file families +- precedence +- fail-closed posture +- backend allowlists +- host-side secret and credential-read gates + +ADR-0042 remains the semantic owner of the operator-facing tuple fields: + +- `client` +- `router` +- `provider` +- `auth_authority` +- `protocol` +- `identity_tuple` +- `placement_posture` + +ADR-0043 extends the policy surface additively under `llm.constraints.*`. + +- `substrate policy current show --explain` is the authoritative merged inspection surface for + `llm.constraints.*`. +- Tuple-policy publication reuses the existing `identity_tuple` and `placement_posture` field + family. +- Tuple-axis mismatch denial maps to exit code `5`. + +The stable schema and runtime ownership for that additive surface lives in +`docs/reference/policy/tuple_constraints.md`. diff --git a/docs/reference/policy/schema.md b/docs/reference/policy/schema.md new file mode 100644 index 000000000..b6a6a7dad --- /dev/null +++ b/docs/reference/policy/schema.md @@ -0,0 +1,131 @@ +# Policy Schema + +This document defines the stable ADR-0027 config and policy key paths, defaults, and merge +strategies. + +Related references: +- `docs/reference/policy/contract.md` +- `docs/reference/policy/tuple_constraints.md` + +## General rules + +- Unknown config or policy keys MUST be rejected with exit code `2`. +- Invalid values for known keys MUST be rejected with exit code `2`. +- Merge remains per-key: + - Config: workspace overrides global; environment overrides apply only when no workspace exists. + - Policy: workspace overrides global. +- Keys defined here use replace semantics across layers unless noted otherwise. + +## Backend id format + +Applies to: +- `llm.routing.default_backend` +- `llm.allowed_backends[*]` +- `agents.allowed_backends[*]` +- `agents.host_credentials.read.allowed_backends[*]` + +Format: +- `:` + - ``: lowercase ASCII `[a-z0-9_]+` + - ``: lowercase ASCII `[a-z0-9_-]+` + +Backend ids are selector ids only. They are not substitutes for `client`, `router`, `provider`, +`auth_authority`, or `protocol`. + +## Agent inventory + +Agent definitions are stored as one file per agent: + +- Global: `$SUBSTRATE_HOME/agents/.yaml` +- Workspace: `/.substrate/agents/.yaml` + +Requirements: +- The filename-derived `` MUST match the YAML field `id`. +- Unknown keys in agent files MUST be rejected. +- Agent files MUST NOT contain secrets. + +Inventory precedence per `id`: +1. Workspace agent file +2. Global agent file +3. Built-in defaults, if any + +## Config schema additions + +### `llm` + +- `llm.enabled: bool` + - Default: `false` +- `llm.gateway.enabled: bool` + - Default: `false` +- `llm.gateway.mode: in_world|host_only` + - Default: `in_world` + - Constraint: `host_only` is only valid when effective policy has + `llm.fail_closed.routing=false` +- `llm.routing.default_backend: string` + - Default: empty string + +### `agents` + +- `agents.enabled: bool` + - Default: `false` +- `agents.defaults.execution.scope: host|world` + - Default: `world` +- `agents.defaults.cli.mode: persistent|per_request` + - Default: `persistent` +- `agents.hub.orchestrator_agent_id: string` + - Default: empty string +- `agents.hub.world_restart.on_drift: auto_restart|fail_closed` + - Default: `auto_restart` +- `agents.toolbox.enabled: bool` + - Default: `false` +- `agents.toolbox.bind.transport: uds|tcp` + - Default: `uds` + +## Policy schema additions + +### `llm` + +- `llm.fail_closed.routing: bool` + - Default: `true` +- `llm.require_approval: bool` + - Default: `false` +- `llm.allowed_backends: [string]` + - Default: `[]` +- `llm.secrets.env_allowed: [string]` + - Default: `[]` + +### `agents` + +- `agents.allowed_backends: [string]` + - Default: `[]` +- `agents.fail_closed.routing: bool` + - Default: `true` +- `agents.host_credentials.read.allowed_backends: [string]` + - Default: `[]` + +### `workflow.router` + +- `workflow.router.enabled: bool` + - Default: `false` +- `workflow.router.allow_cross_workspace: bool` + - Default: `false` +- `workflow.router.allowed_rule_ids: [string]` + - Default: `[]` +- `workflow.router.allowed_workflow_ids: [string]` + - Default: `[]` +- `workflow.router.allowed_target_workspace_ids: [string]` + - Default: `[]` + +## Additive tuple-policy note + +ADR-0043 extends this policy family additively with tuple-axis narrowing constraints under +`llm.constraints`: + +- `llm.constraints.routers` +- `llm.constraints.providers` +- `llm.constraints.protocols` +- `llm.constraints.auth_authorities` + +Those keys narrow an already-selected backend path. They do not replace backend allowlists or +introduce a standalone `client` policy key. The authoritative grammar, defaults, evaluation order, +and deny wording for that additive surface live in `docs/reference/policy/tuple_constraints.md`. diff --git a/docs/reference/policy/tuple_constraints.md b/docs/reference/policy/tuple_constraints.md new file mode 100644 index 000000000..1503c01f6 --- /dev/null +++ b/docs/reference/policy/tuple_constraints.md @@ -0,0 +1,142 @@ +# Tuple Constraint Policy Reference + +This document is the stable operator-facing reference for ADR-0043, the additive tuple-axis policy +surface under `llm.constraints.*`. + +Related references: +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` +- `docs/contracts/gateway/policy-evaluation.md` + +## Decision locks + +- `substrate policy current show --explain` is the authoritative merged inspection surface for + `llm.constraints.*`. +- Tuple-policy publication reuses the existing `identity_tuple` and `placement_posture` field + family. +- This additive surface does not introduce a standalone `client` policy key in v1. + +## Owned keys and defaults + +This document owns only the additive tuple-axis schema: + +| Key path | Type | Effective default | Valid token grammar | Meaning when non-empty | +| --- | --- | --- | --- | --- | +| `llm.constraints.routers` | `[string]` | `[]` | lowercase snake_case id | effective `router` must match one listed value | +| `llm.constraints.providers` | `[string]` | `[]` | lowercase snake_case id | effective `provider` must match one listed value | +| `llm.constraints.protocols` | `[string]` | `[]` | lowercase dotted id | effective `protocol` must match one listed value | +| `llm.constraints.auth_authorities` | `[string]` | `[]` | lowercase snake_case id | effective `auth_authority` must match one listed value | + +Merge rules: +- workspace patch replaces the same global key +- omitted key inherits the next lower layer +- each tuple-axis key resolves independently + +Effective meaning of `[]`: +- unconstrained on that axis + +`client` is not a standalone policy key in v1. + +The following key family is invalid for this feature: +- `llm.constraints.clients` + +## Exact grammar + +Snake-case ids apply to: +- `llm.constraints.routers[*]` +- `llm.constraints.providers[*]` +- `llm.constraints.auth_authorities[*]` + +Accepted examples: +- `substrate_gateway` +- `openai` +- `azure_openai` +- `codex_subscription` +- `openai_api_key` + +Rejected examples: +- `Substrate_Gateway` +- `openai-responses` +- `_openai` +- `openai__api` +- `openai_` + +Validation error family: +- `invalid entry ''; expected lowercase snake_case id` + +Dotted ids apply to: +- `llm.constraints.protocols[*]` + +Accepted examples: +- `openai.responses` +- `openai.chat_completions` +- `anthropic.messages` +- `uaa.agent_session` + +Rejected examples: +- `openai` +- `OpenAI.responses` +- `openai..responses` +- `openai.responses_v1.` +- `openai.responses-v1` + +Validation error family: +- `invalid llm.constraints.protocols entry ''; expected lowercase dotted id` + +## Ordered runtime evaluation + +Tuple-aware gateway policy evaluation follows this order: + +1. Validate gateway lifecycle config. +2. Resolve the selected backend inventory entry and apply `llm.allowed_backends` before tuple + derivation begins. +3. Derive the candidate identity tuple from the selected backend and integrated auth source. +4. Apply tuple-axis narrowing in this exact order: + - `llm.constraints.routers` + - `llm.constraints.protocols` + - `llm.constraints.providers` + - `llm.constraints.auth_authorities` +5. Resolve integrated auth source material: + - blocked env auth is a policy denial + - partial env auth is invalid integration +6. Apply world-boundary posture. +7. Apply downstream transport and egress gates. + +If the selected backend id is absent from `llm.allowed_backends`, evaluation stops before +tuple-axis narrowing. + +## Deny wording and failure buckets + +Tuple-policy schema invalidity maps to `2`. +Tuple-axis mismatch denial maps to `5`. + +Backend allowlist denial: +- `" is not allowlisted by effective policy llm.allowed_backends"` + +Tuple-axis mismatch denials: +- `effective gateway routing authority 'substrate_gateway' is not allowlisted by llm.constraints.routers` +- `effective gateway protocol '' is not allowlisted by llm.constraints.protocols` +- `effective gateway provider is unresolved while llm.constraints.providers is constrained` +- `effective gateway provider '' is not allowlisted by llm.constraints.providers` +- `effective gateway auth authority is unresolved while llm.constraints.auth_authorities is constrained` +- `effective gateway auth authority '' is not allowlisted by llm.constraints.auth_authorities` + +Component unavailable examples: +- the required world or gateway socket is missing + +Transient runtime failure examples: +- connection refused +- timeout + +Explain-surface rule: +- Explain output for tuple-aware denials must identify the exact policy key that denied the route. + +## Platform guarantee + +Linux, macOS, and Windows expose the same tuple-axis policy semantics: + +- the same four policy keys +- the same precedence posture +- the same authoritative inspection command +- the same exit-code mapping for schema invalidity and policy denial +- the same deny wording family for tuple-axis mismatch From a7ce1657e1bb1d8fbed604a0d76dea29d151b4c2 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 12:53:25 -0400 Subject: [PATCH 07/20] Update project management retirement tracker --- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 156 +++++++++++++++++++------- 1 file changed, 117 insertions(+), 39 deletions(-) diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index c469d4a1b..cd0fce71c 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -26,6 +26,45 @@ Current recommendation for ADRs: - CI, Make targets, smoke scripts, and Rust tests must stop depending on pack paths before the cut. - Gateway-local planning docs are not being retired in this effort, but they currently link back into top-level packs and will need rewrites to avoid broken references. +## Current State + +Completed extraction/rewrite slices: +- trace schema/protocol ownership moved into: + - `docs/internals/trace/schema.md` + - `docs/internals/trace/protocol.md` + - with stable trace docs repointed from pack-backed sources +- world-deps provisioning contract moved into: + - `docs/reference/world/deps/provisioning.md` + - with `docs/WORLD.md`, `docs/CONFIGURATION.md`, `docs/COMMANDS.md`, + `docs/reference/world/deps/README.md`, and `docs/internals/world/deps.md` repointed +- ADR-0027 / ADR-0043 stable policy references moved into: + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` + - `docs/reference/policy/tuple_constraints.md` + - with stable gateway contracts repointed and `crates/broker/src/tests.rs` rewritten to lock + stable docs instead of pack docs +- gateway backlink cleanup completed for: + - `crates/gateway/docs/foundation/**` + - `crates/gateway/tests/fixtures/azure_kimi/**` + - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` +- stale host-visible hardening and persistent-session planning anchors were already cleaned in + earlier slices + +Still remaining before the atomic top-level `packs/**` removal: +- workspace-sync filesystem semantics are still owned by pack docs and still referenced from + `docs/internals/world/workspace_sync_filesystem_model.md` +- planning automation and workflow machinery still assume `docs/project_management/packs/**` +- several tests outside `crates/broker/src/tests.rs` still read pack docs directly +- gateway-local planning docs under `crates/gateway/docs/project_management/**` remain out of + scope for deletion but still need their own backlink cleanup + +Validation already completed for the finished slices: +- `cargo test -p substrate-broker --lib -- --nocapture` +- targeted world-deps test rewrites are present in + `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` +- scoped reference scans over stable docs and non-`project_management` gateway docs no longer show + top-level pack backlinks for the completed ADR-0027 and gateway-foundation slices + ## Current Dependency Classes ### 1. Tooling and automation that assume `packs/**` exists @@ -48,10 +87,9 @@ Disposition: ### 2. Rust tests and code that hard-read pack markdown -- `crates/broker/src/tests.rs` - - contract tests for `adr-0027-identity-tuple-policy-surface` - `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` - - asserts world-deps provisioning references and contract wording + - rewritten to the stable world-deps provisioning docs; keep as an example of the desired end + state for other tests - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` - asserts successor compatibility, parity, and manual validation playbooks - `crates/shell/tests/playbook_alignment.rs` @@ -59,28 +97,26 @@ Disposition: - `crates/transport-api-types/src/lib.rs` - test reads a manual testing playbook under a draft pack +Completed: +- `crates/broker/src/tests.rs` + - ADR-0027 contract tests now lock stable policy docs under `docs/reference/policy/**` + - planning-only slice/checkpoint/promote-pack assertions were deleted rather than migrated + Disposition: - rewrite when the source-of-truth doc survives in a stable home - delete when the test only protected planning-pack process mechanics ### 3. Stable docs that still point at pack files -These are the highest-priority extraction blockers because they treat pack docs as current truth: - +Completed stable-doc rewrites: - `docs/TRACE.md` - - references `active/world_process_exec_tracing_parity/SCHEMA.md` - - references `active/world_process_exec_tracing_parity/PROTOCOL.md` - - references `packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` - `docs/WORLD.md` - - references world-deps provisioning pack contracts - `docs/CONFIGURATION.md` - - references world-deps provisioning pack contracts - `docs/COMMANDS.md` - - references world-deps provisioning pack contracts - `docs/reference/world/deps/README.md` - - references world-deps provisioning pack contracts - `docs/internals/world/deps.md` - - references world-deps provisioning pack contracts + +Remaining stable-doc blockers that still treat pack docs as current truth: - `docs/reference/config/world.md` - references `world-deps-host-visible-hardening/WDH0-spec.md` - `docs/internals/world/workspace_sync_filesystem_model.md` @@ -94,9 +130,12 @@ Disposition: Although `crates/gateway/docs/project_management/**` is out of scope for retirement, it currently depends on top-level pack closeouts, seam docs, and evidence paths. -Notable dependency surfaces: +Completed rewrites: - `crates/gateway/docs/foundation/*.md` - `crates/gateway/tests/fixtures/azure_kimi/*.json` +- `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` + +Remaining dependency surface: - `crates/gateway/docs/project_management/packs/active/**` Disposition: @@ -111,14 +150,18 @@ Current pack sources: - `docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md` - `docs/project_management/packs/active/world_process_exec_tracing_parity/PROTOCOL.md` -Recommended destination: -- merge schema ownership into `docs/internals/trace/schema.md` -- merge protocol ownership into `docs/internals/trace/README.md` or a new sibling under `docs/internals/trace/` +Stable destinations now in place: +- `docs/internals/trace/schema.md` +- `docs/internals/trace/protocol.md` -Required follow-up: -- rewrite `docs/TRACE.md` -- rewrite `docs/internals/trace/README.md` -- remove any tests or comments that still name the pack path as authoritative +Completed follow-up: +- rewrote `docs/TRACE.md` +- rewrote `docs/internals/trace/README.md` +- removed stable-doc dependency on pack-backed schema/protocol ownership + +Remaining follow-up: +- keep ADR-0028 in `docs/project_management/adrs/**` for historical record +- clean any downstream ADR/planning references separately from the stable trace surface itself ### B. World-deps provisioning contract @@ -127,14 +170,19 @@ Current pack sources: - `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md` - `docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md` -Recommended destination: -- move operator-facing contract material into `docs/reference/world/deps/README.md` -- move implementation/background material into `docs/internals/world/deps.md` -- if needed, add a dedicated stable doc under `docs/reference/world/deps/` +Stable destinations now in place: +- `docs/reference/world/deps/provisioning.md` +- `docs/reference/world/deps/README.md` +- `docs/internals/world/deps.md` -Required follow-up: -- rewrite `docs/WORLD.md`, `docs/CONFIGURATION.md`, and `docs/COMMANDS.md` -- rewrite `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` +Completed follow-up: +- rewrote `docs/WORLD.md`, `docs/CONFIGURATION.md`, and `docs/COMMANDS.md` +- rewrote `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + +Remaining follow-up: +- keep downstream ADR/planning references separate from the stable provisioning contract +- verify any still-dirty worktree state in `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + before using it as a resume point in a new session ### C. ADR-0027 implemented policy contract/schema surfaces @@ -170,6 +218,10 @@ Recommended destination: Required follow-up: - rewrite the internal world docs that currently cite those pack specs +Current recommendation: +- make this the next stable-doc extraction slice after the gateway-local backlink cleanup, because + it is now one of the clearest remaining product-doc blockers before pack deletion + ### E. Host-visible hardening references Current pack sources: @@ -206,6 +258,40 @@ Required follow-up: - `crates/gateway/tests/fixtures/azure_kimi/**` - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` +## Recommended Resume Order + +Use this order in the next session: + +1. Finish the remaining gateway-local backlink cleanup under + `crates/gateway/docs/project_management/**`. + - Goal: remove the remaining dependence on top-level `docs/project_management/packs/**` from + gateway-local planning docs without deleting the gateway-local planning tree itself. +2. Extract the world-sync filesystem semantics into + `docs/internals/world/workspace_sync_filesystem_model.md`. + - Goal: eliminate another stable-doc blocker that still names pack specs as canonical. +3. Triage the remaining pack-reading tests: + - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` + - `crates/shell/tests/playbook_alignment.rs` + - `crates/transport-api-types/src/lib.rs` + - Goal: rewrite to stable docs where appropriate; delete planning-process-only assertions. +4. Remove or replace planning automation and workflow dependencies: + - `Makefile` + - `.github/workflows/feature-smoke.yml` + - triad / smoke / CI helper scripts +5. Re-run a repo-wide reference scan. + - Goal: confirm what still points at `docs/project_management/packs/**` before attempting the + atomic cut. + +## Resume Notes + +- Do not start by deleting any pack directories. +- The next correct move is still extraction/rewrite work. +- The top-level `packs/**` tree must be removed in one cut only after: + - stable docs are repointed, + - pack-reading tests are rewritten or deleted, + - automation stops assuming pack directories exist, + - and gateway-local backlinks have been cleaned far enough to avoid broken references. + ## Atomic `packs/**` Retirement Procedure 1. Extract all surviving normative content out of `docs/project_management/packs/**`. @@ -224,15 +310,7 @@ After `packs/**` is gone: - prune `_archived/**` to the minimum historical set worth keeping - decide whether to keep the ADR registry where it is or move it into a non-project-management namespace -## First Safe Implementation Slice - -The safest first execution slice is: - -1. extract the world-deps provisioning contract into stable docs -2. rewrite the stable docs and WDAP1 Rust test to those new locations -3. re-run tests +## Historical Note -Reason: -- it has a contained set of references -- it already has stable destination candidates -- it removes one of the largest live blockers before the atomic pack cut +The original first safe implementation slice was the world-deps provisioning extraction. That +slice is now complete and should not be treated as the next step when resuming this work. From 4e0c5aff4cf1ea0c79703ddeff2576410bd2a5d6 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 12:59:38 -0400 Subject: [PATCH 08/20] Update gateway-local pack backlinks --- .../README.md | 2 +- .../governance/remediation-log.md | 6 ++-- .../governance/seam-1-closeout.md | 10 +++--- .../governance/seam-2-closeout.md | 4 +-- .../scope_brief.md | 2 +- .../seam-1-azure-foundry-runtime-transport.md | 8 ++--- ...m-2-azure-live-smoke-operator-readiness.md | 8 ++--- .../seam.md | 16 ++++----- .../seam.md | 12 +++---- .../governance/remediation-log.md | 22 ++++++------- .../governance/seam-1-closeout.md | 2 +- .../governance/seam-2-closeout.md | 6 ++-- .../governance/seam-3-closeout.md | 2 +- ...e-2-capture-azure-evidence-and-fixtures.md | 4 +-- .../review.md | 4 +-- .../governance/seam-1-closeout.md | 6 ++-- .../governance/seam-2-closeout.md | 2 +- .../governance/seam-3-closeout.md | 2 +- .../README.md | 2 +- .../governance/seam-1-closeout.md | 18 +++++----- .../governance/seam-2-closeout.md | 18 +++++----- .../governance/seam-3-closeout.md | 8 ++--- .../scope_brief.md | 2 +- .../seam-1-claude-code-operator-bootstrap.md | 10 +++--- .../seam-2-live-session-smoke-verification.md | 8 ++--- ...-3-troubleshooting-and-support-boundary.md | 10 +++--- .../seam.md | 20 +++++------ ...1-freeze-claude-code-bootstrap-contract.md | 2 +- .../review.md | 2 +- .../seam.md | 16 ++++----- .../review.md | 2 +- .../seam.md | 20 +++++------ .../governance/pack-closeout.md | 8 ++--- .../governance/seam-1-closeout.md | 6 ++-- .../governance/seam-2-closeout.md | 6 ++-- .../governance/seam-3-closeout.md | 8 ++--- .../seam-1-openai-chat-completions-surface.md | 4 +-- .../seam-2-openai-responses-surface.md | 2 +- .../review.md | 2 +- .../seam.md | 6 ++-- .../seam-2-openai-responses-surface/seam.md | 8 ++--- .../seam.md | 8 ++--- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 33 +++++++++---------- 43 files changed, 172 insertions(+), 175 deletions(-) diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/README.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/README.md index 38d018d20..accea71ff 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/README.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/README.md @@ -1,6 +1,6 @@ # Azure Foundry Provider Transport - seam extraction -Source: `docs/project_management/packs/active/azure-kimi-claude-gateway`, `docs/foundation/*.md`, `docs/adr/*.md`, and current gateway Azure transport anchors under `gateway/` +Source: `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway`, `docs/foundation/*.md`, `docs/adr/*.md`, and current gateway Azure transport anchors under `gateway/` This pack captures seam briefs, authoritative threading, pack-level review surfaces, seam-exit intent, and governance scaffolds for the remaining Azure Foundry runtime-provider work. It is intentionally one level above seam-local decomposition. diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/remediation-log.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/remediation-log.md index 3f49a45d2..0285680e3 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/remediation-log.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/remediation-log.md @@ -41,7 +41,7 @@ related_seam: SEAM-2 related_slice: null related_thread: THR-07 related_contract: C-08 -related_artifact: docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md +related_artifact: crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md severity: blocking status: resolved owner_seam: SEAM-2 @@ -52,6 +52,6 @@ blocked_targets: summary: SEAM-2 could not publish THR-07 until redacted live Azure smoke evidence existed for both Kimi routes. required_fix: Capture redacted live Azure `/v1/messages` evidence for both routes and publish THR-07. resolution_evidence: - - docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md ``` diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md index 0b81ec5b5..a5b12bd8f 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md @@ -3,16 +3,16 @@ seam_id: SEAM-1 status: landed closeout_version: v0 seam_exit_gate: - source_ref: docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/slice-4-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/slice-4-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-06 stale_triggers: diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md index 5f9ee2f67..01b9ded73 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-2 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/slice-3-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/slice-3-seam-exit-gate.md status: passed promotion_readiness: ready basis: @@ -32,7 +32,7 @@ open_remediations: [] - [gateway/config/default.example.toml](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/config/default.example.toml) - [gateway/config/models.example.toml](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/config/models.example.toml) - [gateway/src/server/mod.rs](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/src/server/mod.rs) - - [manifest.json](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json) + - [manifest.json](crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json) - `S1` commit `c9926ce` (`SEAM-2: complete slice-1-freeze-operator-verification-contract`) - `S2` commit `96f9a42` (`SEAM-2: complete slice-2-deliver-live-smoke-procedure-and-troubleshooting`) - **Contracts published or changed**: diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md index 4c2770314..1d366a2d4 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/scope_brief.md @@ -35,7 +35,7 @@ execution_horizon: - an operator can follow the eventual seam outputs to express Azure auth, deployment URL shape, `api-version`, provider mapping, and Kimi deployment selection without guessing - the gateway has an explicit planned path to prove real Azure traffic through `/v1/messages` using `Kimi-K2-Thinking` and `Kimi-K2.5` - **Constraints**: - - `docs/project_management/packs/active/azure-kimi-claude-gateway` is the upstream landed basis and should be consumed through closeout-backed truth, not re-planned as greenfield work + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway` is the upstream landed basis and should be consumed through closeout-backed truth, not re-planned as greenfield work - `docs/foundation/azure-kimi-c02-normalized-event-contract.md`, `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, `docs/foundation/substrate-boundary-c05-contract.md`, and `docs/foundation/substrate-structured-events-c06-contract.md` remain authoritative constraints - `docs/foundation/claude-code-mux-extension-boundary.md` and `docs/foundation/claude-code-mux-5a372fb-validation.md` still constrain where Azure-specific work may attach and what remained unresolved after the foundation seam - `docs/adr/0002-model-azure-kimi-as-a-first-class-provider-normalization-problem.md` and `docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md` prohibit collapsing Azure into a thin generic adapter or hard-coding localhost-only assumptions into the core diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-1-azure-foundry-runtime-transport.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-1-azure-foundry-runtime-transport.md index 2111d89fd..cfc29e879 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-1-azure-foundry-runtime-transport.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-1-azure-foundry-runtime-transport.md @@ -10,10 +10,10 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-06 stale_triggers: diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-2-azure-live-smoke-operator-readiness.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-2-azure-live-smoke-operator-readiness.md index 21c164f1f..713743b54 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-2-azure-live-smoke-operator-readiness.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/seam-2-azure-live-smoke-operator-readiness.md @@ -10,10 +10,10 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-06 - THR-07 diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md index 9a754a729..91566c4a8 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-1-azure-foundry-runtime-transport/seam.md @@ -9,10 +9,10 @@ basis: source_seam_brief: ../../seam-1-azure-foundry-runtime-transport.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-06 stale_triggers: @@ -67,10 +67,10 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` - **Required threads**: `THR-06` - **Stale triggers**: - Azure runtime truth changes the required auth header posture, deployment URL shape, or `api-version` semantics diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md index 5b6fb8c3e..1daa66b7c 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/seam.md @@ -10,9 +10,9 @@ basis: source_scope_ref: ../../scope_brief.md upstream_closeouts: - ../../governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-06 - THR-07 @@ -64,9 +64,9 @@ open_remediations: [] - **Currentness**: `current` - **Upstream closeouts assumed**: - `../../governance/seam-1-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` - **Required threads**: `THR-06`, `THR-07` - **Stale triggers**: - `C-07` changes Azure auth, base URL, deployment-selection, or request-body invariance in a way that invalidates the smoke path diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/remediation-log.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/remediation-log.md index 48eb9f6e7..c72a5de6d 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/remediation-log.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/remediation-log.md @@ -39,7 +39,7 @@ related_seam: SEAM-2 related_slice: null related_thread: THR-01 related_contract: C-01 -related_artifact: docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md +related_artifact: crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md severity: blocking status: resolved owner_seam: SEAM-2 @@ -50,12 +50,12 @@ blocked_targets: summary: SEAM-2 horizon promotion was unblocked by recording that THR-01 is already published and that Azure hidden-tool revalidation is owned by SEAM-2 active work instead of SEAM-1 promotion-readiness. required_fix: Keep the Azure hidden-tool validation gap explicit as SEAM-2 normalization work and preserve the published C-01 handoff from SEAM-1 without treating the carried gap as a foundation-horizon blocker. resolution_evidence: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/seam-2-azure-kimi-normalization.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/README.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/scope_brief.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/seam_map.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/seam-2-azure-kimi-normalization.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/README.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/scope_brief.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/seam_map.md ``` ```yaml @@ -66,7 +66,7 @@ related_seam: SEAM-2 related_slice: S4 related_thread: THR-02 related_contract: C-02 -related_artifact: docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md +related_artifact: crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md severity: blocking status: resolved owner_seam: SEAM-2 @@ -82,7 +82,7 @@ required_fix: Extend the SEAM-2 streaming provider boundary so hidden-marker-onl resolution_evidence: - gateway/src/providers/openai.rs - gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json - - docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md ``` diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md index f8c7e8dcb..0685eb14c 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-1-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-1 status: landed closeout_version: v0 seam_exit_gate: - source_ref: docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-1-mux-foundation-baseline/slice-4-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-1-mux-foundation-baseline/slice-4-seam-exit-gate.md status: passed promotion_readiness: blocked basis: diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md index f1f9b34ee..cf42ac2ab 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-2 status: landed closeout_version: v2 seam_exit_gate: - source_ref: docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-4-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-4-seam-exit-gate.md status: passed promotion_readiness: ready basis: @@ -31,8 +31,8 @@ This closeout records the seam-exit gate for `SEAM-2` and the publication-backed - **Source artifact**: [slice-4-seam-exit-gate.md](../threaded-seams/seam-2-azure-kimi-normalization/slice-4-seam-exit-gate.md) - **Landed evidence**: - [azure-kimi-c02-normalized-event-contract.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/azure-kimi-c02-normalized-event-contract.md) - - [manifest.json](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json) - - [variant-notes.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md) + - [manifest.json](crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json) + - [variant-notes.md](crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md) - five landed regression fixtures under `gateway/tests/fixtures/azure_kimi/` - Azure normalization boundary and regression coverage in `gateway/src/providers/openai.rs` - verification run: `cargo test openai -- --nocapture` diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md index 15f4f9201..3599cbc29 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-3 status: landed closeout_version: v0 seam_exit_gate: - source_ref: docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-3-anthropic-messages-gateway-surface/slice-3-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-3-anthropic-messages-gateway-surface/slice-3-seam-exit-gate.md status: passed promotion_readiness: ready basis: diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-2-capture-azure-evidence-and-fixtures.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-2-capture-azure-evidence-and-fixtures.md index b24a0c1cd..6e67ea2d0 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-2-capture-azure-evidence-and-fixtures.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/slice-2-capture-azure-evidence-and-fixtures.md @@ -36,9 +36,9 @@ candidate_subslices: [] - In: reproduce or refresh Azure Foundry probe cases, capture raw request/response artifacts, classify explicit and hidden tool-intent cases, and build a fixture corpus with expected normalized outputs. - Out: shipping public gateway behavior changes or embedding planner/executor policy into the probe process. - **Acceptance criteria**: - - `docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json` inventories one explicit `tool_calls` case, one hidden `reasoning_content` case, one mixed case, and one no-tool control case. + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json` inventories one explicit `tool_calls` case, one hidden `reasoning_content` case, one mixed case, and one no-tool control case. - `gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json`, `gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json`, `gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json`, and `gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json` each map raw Azure evidence to expected `C-02` normalized output. - - `docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md` records the current `Kimi-K2.5` hidden-marker observation and the streaming hidden-marker variant note for later revalidation. + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md` records the current `Kimi-K2.5` hidden-marker observation and the streaming hidden-marker variant note for later revalidation. - any divergence from the assumptions in `docs/foundation/claude-code-mux-5a372fb-validation.md` is recorded as a stale-trigger candidate for seam exit - **Landed outputs**: - evidence manifest: `evidence/manifest.json` diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md index 654b3c2eb..69c1934fa 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-5-substrate-compatible-boundary/review.md @@ -56,7 +56,7 @@ flowchart LR ## Likely mismatch hotspots -- `docs/project_management/packs/active/azure-kimi-claude-gateway/seam-5-substrate-compatible-boundary.md` can drift into a future-only posture if it keeps `SEAM-5` described as queued instead of active and exec-ready. +- `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/seam-5-substrate-compatible-boundary.md` can drift into a future-only posture if it keeps `SEAM-5` described as queued instead of active and exec-ready. - `gateway/src/server/mod.rs` and config docs can accidentally hard-code localhost-style assumptions even when the pack is trying to keep deployment replaceable. - Downstream schema or docs can reintroduce raw provider transport detail if `C-06` is not kept normalized and stable. @@ -70,7 +70,7 @@ flowchart LR - **Review gate**: `passed` - **Contract gate**: `passed`; `S1` freezes the owned public identity and deployment boundary, while `S2` freezes normalized downstream structured events and drift guards -- **Revalidation gate**: `passed`; the seam was rechecked against `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/azure-kimi-c02-normalized-event-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, and `docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md` +- **Revalidation gate**: `passed`; the seam was rechecked against `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/azure-kimi-c02-normalized-event-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, and `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threading.md` - **Opened remediations**: none ## Planned seam-exit gate focus diff --git a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-1-closeout.md b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-1-closeout.md index 53e4f7bfb..d64ae52ab 100644 --- a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-1-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-1-closeout.md @@ -3,14 +3,14 @@ seam_id: SEAM-1 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-1-chatgpt-codex-route-contract-and-stream-native-transport/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-1-chatgpt-codex-route-contract-and-stream-native-transport/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md required_threads: - THR-14 stale_triggers: diff --git a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-2-closeout.md b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-2-closeout.md index 85555c00d..8ab58268b 100644 --- a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-2-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-2-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-2 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-2-substrate-auth-handoff-and-account-id-provenance/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-2-substrate-auth-handoff-and-account-id-provenance/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: diff --git a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-3-closeout.md b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-3-closeout.md index 1c130a100..575312f86 100644 --- a/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-3-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/governance/seam-3-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-3 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-3-codex-route-conformance-and-drift-guards/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/chatgpt-codex-oauth-backend-api-responses/threaded-seams/seam-3-codex-route-conformance-and-drift-guards/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/README.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/README.md index c4b21f4c0..a9ab61e5d 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/README.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/README.md @@ -1,6 +1,6 @@ # Claude Code Live Integration Smoke - seam extraction -Source: `docs/project_management/packs/active/azure-kimi-claude-gateway`, `docs/project_management/packs/active/azure-foundry-provider-transport`, `docs/foundation/*.md`, `docs/adr/0001-0007`, and current Claude Code/gateway operator anchors under `gateway/` +Source: `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway`, `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport`, `docs/foundation/*.md`, `docs/adr/0001-0007`, and current Claude Code/gateway operator anchors under `gateway/` This pack captures seam briefs, authoritative threading, pack-level review surfaces, seam-exit intent, and governance scaffolds. It is intentionally one level above seam-local decomposition. diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md index 55c8107fe..b15543393 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md @@ -3,17 +3,17 @@ seam_id: SEAM-1 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-3-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-3-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: [] stale_triggers: - `docs/foundation/claude-code-c09-operator-bootstrap-contract.md` changes the canonical bootstrap sequence, evidence posture, or redaction rules in a way that affects downstream bootstrap consumption @@ -33,9 +33,9 @@ open_remediations: [] - **Source artifact**: [slice-3-seam-exit-gate.md](../threaded-seams/seam-1-claude-code-operator-bootstrap/slice-3-seam-exit-gate.md) - **Landed evidence**: - [claude-code-c09-operator-bootstrap-contract.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/claude-code-c09-operator-bootstrap-contract.md) - - [seam.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md) - - [review.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/review.md) - - [threading.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) + - [seam.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md) + - [review.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/review.md) + - [threading.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) - [gateway/README.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/README.md) - [gateway/config/default.example.toml](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/config/default.example.toml) - [gateway/config/models.example.toml](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/config/models.example.toml) diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md index 3904f62a8..fae2f2543 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md @@ -3,16 +3,16 @@ seam_id: SEAM-2 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/slice-3-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/slice-3-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md required_threads: - THR-08 - THR-09 @@ -36,10 +36,10 @@ open_remediations: [] - **Landed evidence**: - [claude-code-c10-live-session-smoke-verification-contract.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md) - [claude-code-c10-live-session-smoke-procedure.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/claude-code-c10-live-session-smoke-procedure.md) - - [manifest.json](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json) - - [seam.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md) - - [review.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md) - - [threading.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) + - [manifest.json](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json) + - [seam.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md) + - [review.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md) + - [threading.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) - [gateway/README.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/README.md) - [gateway/src/router/mod.rs](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/src/router/mod.rs) - [gateway/src/server/mod.rs](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/src/server/mod.rs) diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-3-closeout.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-3-closeout.md index b831b6fa7..4611338ab 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-3-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-3-closeout.md @@ -3,7 +3,7 @@ seam_id: SEAM-3 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/slice-3-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/slice-3-seam-exit-gate.md status: passed promotion_readiness: ready basis: @@ -35,9 +35,9 @@ open_remediations: [] - **Landed evidence**: - [claude-code-c11-troubleshooting-and-support-boundary-contract.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md) - [claude-code-c11-operator-troubleshooting-guide.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/foundation/claude-code-c11-operator-troubleshooting-guide.md) - - [seam.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md) - - [review.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md) - - [threading.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) + - [seam.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md) + - [review.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md) + - [threading.md](crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threading.md) - [gateway/README.md](/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/gateway/README.md) - **Contracts published or changed**: - `C-11` is published in `docs/foundation/claude-code-c11-troubleshooting-and-support-boundary-contract.md` diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/scope_brief.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/scope_brief.md index 2132d5f41..c0c2ca4ca 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/scope_brief.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/scope_brief.md @@ -36,7 +36,7 @@ execution_horizon: - a reviewer can explain which artifacts prove the live path works, which artifacts are only orientation, and which failures belong to Claude Code setup versus gateway runtime/config versus Azure transport - the pack leaves downstream seam planners with one clear path to make the live integration executable and supportable without inventing new threading rules - **Constraints**: - - `docs/project_management/packs/active/azure-kimi-claude-gateway` and `docs/project_management/packs/active/azure-foundry-provider-transport` are closeout-backed upstream basis and must be consumed rather than re-planned + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway` and `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport` are closeout-backed upstream basis and must be consumed rather than re-planned - `docs/foundation/azure-kimi-c02-normalized-event-contract.md`, `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, `docs/foundation/substrate-boundary-c05-contract.md`, `docs/foundation/substrate-structured-events-c06-contract.md`, `docs/foundation/azure-foundry-c07-runtime-transport-contract.md`, and `docs/foundation/azure-foundry-c08-operator-verification-contract.md` remain authoritative constraints - the live verification path must stay capability-oriented and preserve one logical backend identity, even when operators inspect internal routing evidence - the smoke path must use Claude Code through the landed Anthropic-compatible gateway route instead of provider-only bypasses diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-1-claude-code-operator-bootstrap.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-1-claude-code-operator-bootstrap.md index 1eb83a30d..fca92853c 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-1-claude-code-operator-bootstrap.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-1-claude-code-operator-bootstrap.md @@ -10,11 +10,11 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: [] stale_triggers: - `docs/foundation/azure-foundry-c07-runtime-transport-contract.md` changes the required Azure provider or model-mapping setup surfaces diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-2-live-session-smoke-verification.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-2-live-session-smoke-verification.md index c19b10f25..2b0a97855 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-2-live-session-smoke-verification.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-2-live-session-smoke-verification.md @@ -10,10 +10,10 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md required_threads: - THR-08 stale_triggers: diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-3-troubleshooting-and-support-boundary.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-3-troubleshooting-and-support-boundary.md index 6524e488f..f0ebc4b29 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-3-troubleshooting-and-support-boundary.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/seam-3-troubleshooting-and-support-boundary.md @@ -10,11 +10,11 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-08 - THR-09 diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md index c063e1dc3..1cd64c70b 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/seam.md @@ -9,11 +9,11 @@ basis: source_seam_brief: ../../seam-1-claude-code-operator-bootstrap.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: [] stale_triggers: - docs/foundation/azure-foundry-c07-runtime-transport-contract.md changes Azure provider setup, model-mapping, or startup assumptions that the bootstrap path depends on @@ -68,11 +68,11 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md` - - `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` - **Required threads**: none; this seam owns `THR-08` - **Stale triggers**: - `C-07` changes Azure setup or mapping semantics diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md index 93df047ac..7fdbda229 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-1-claude-code-operator-bootstrap/slice-1-freeze-claude-code-bootstrap-contract.md @@ -44,7 +44,7 @@ candidate_subslices: [] - the contract states the bootstrap order from Azure prerequisites through gateway config, startup validation, statusline or tracing enablement, and Claude Code launch - the contract keeps `Kimi-K2-Thinking`, `Kimi-K2.5`, and Azure deployment names in internal routing context rather than public product identity - the contract names the minimum pre-smoke evidence posture that `SEAM-2` can later assume without rereading runtime code -- **Dependencies**: `../../threading.md`, `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md`, `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md`, `docs/foundation/azure-foundry-c07-runtime-transport-contract.md`, `docs/foundation/azure-foundry-c08-operator-verification-contract.md`, `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, `docs/foundation/substrate-boundary-c05-contract.md` +- **Dependencies**: `../../threading.md`, `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-1-closeout.md`, `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md`, `docs/foundation/azure-foundry-c07-runtime-transport-contract.md`, `docs/foundation/azure-foundry-c08-operator-verification-contract.md`, `docs/foundation/anthropic-messages-c03-contract.md`, `docs/foundation/planner-executor-c04-policy-contract.md`, `docs/foundation/substrate-boundary-c05-contract.md` - **Verification**: - a reviewer can explain the canonical bootstrap path and minimum evidence posture by reading the contract alone - pass condition: `S2` can implement docs, examples, and helper surfaces without inventing any setup semantics diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md index b5a8132df..831525f6b 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/review.md @@ -59,7 +59,7 @@ flowchart LR - **Review gate**: `passed` - **Contract gate**: `passed` because the owned `C-10` baseline, scenario matrix, artifact path, and verification checklist are explicit across `seam.md`, `S1`, and `S2` -- **Revalidation gate**: `passed` after rechecking `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md`, `docs/foundation/claude-code-c09-operator-bootstrap-contract.md`, `gateway/README.md`, `gateway/src/router/mod.rs`, and `gateway/src/server/mod.rs` +- **Revalidation gate**: `passed` after rechecking `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md`, `docs/foundation/claude-code-c09-operator-bootstrap-contract.md`, `gateway/README.md`, `gateway/src/router/mod.rs`, and `gateway/src/server/mod.rs` - **Opened remediations**: none ## Planned seam-exit gate focus diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md index 04726bebd..c6d9d4551 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/seam.md @@ -9,10 +9,10 @@ basis: source_seam_brief: ../../seam-2-live-session-smoke-verification.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md required_threads: - THR-08 stale_triggers: @@ -63,10 +63,10 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` - - `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` + - `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` - **Required threads**: - `THR-08` - **Stale triggers**: diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md index ec32524ab..259b286ac 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/review.md @@ -58,7 +58,7 @@ flowchart LR - **Review gate**: `passed` - **Contract gate**: `passed` because the owned `C-11` baseline, ownership matrix, evidence review order, and verification checklist are explicit across `seam.md`, `S1`, and `S2` -- **Revalidation gate**: `passed` after rechecking `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md`, `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md`, `docs/foundation/claude-code-c09-operator-bootstrap-contract.md`, `docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md`, `docs/foundation/claude-code-c10-live-session-smoke-procedure.md`, `gateway/README.md`, `gateway/src/router/mod.rs`, and `gateway/src/server/mod.rs` +- **Revalidation gate**: `passed` after rechecking `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md`, `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md`, `docs/foundation/claude-code-c09-operator-bootstrap-contract.md`, `docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md`, `docs/foundation/claude-code-c10-live-session-smoke-procedure.md`, `gateway/README.md`, `gateway/src/router/mod.rs`, and `gateway/src/server/mod.rs` - **Opened remediations**: none ## Planned seam-exit gate focus diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md index e937a8b71..b955c8f8a 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-3-troubleshooting-and-support-boundary/seam.md @@ -9,11 +9,11 @@ basis: source_seam_brief: ../../seam-3-troubleshooting-and-support-boundary.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md - - docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md required_threads: - THR-08 - THR-09 @@ -65,11 +65,11 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` - - `docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md` - - `docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` + - `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-1-closeout.md` + - `crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-4-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-5-closeout.md` - **Required threads**: - `THR-08` - `THR-09` diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/pack-closeout.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/pack-closeout.md index e6bf281bf..be754733c 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/pack-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/pack-closeout.md @@ -10,10 +10,10 @@ The pack is closed out on the basis of the published seam closeouts and thread registry: -- `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` -- `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md` -- `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md` -- `docs/project_management/packs/active/openai-side-chat-completions-and-responses/threading.md` +- `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` +- `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md` +- `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md` +- `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threading.md` Landed contracts and maintenance basis: diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md index e3d70f742..cc89a2d95 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md @@ -3,14 +3,14 @@ seam_id: SEAM-1 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-11 diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md index d2fd368d2..0ec75fd0d 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md @@ -3,14 +3,14 @@ seam_id: SEAM-2 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-12 diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md index ccad1dcb5..9154a0564 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-3-closeout.md @@ -3,14 +3,14 @@ seam_id: SEAM-3 status: landed closeout_version: v1 seam_exit_gate: - source_ref: docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/slice-99-seam-exit-gate.md + source_ref: crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/slice-99-seam-exit-gate.md status: passed promotion_readiness: ready basis: currentness: current upstream_closeouts: - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md required_threads: - THR-10 - THR-11 @@ -33,7 +33,7 @@ This closeout records the landed evidence, contract publication, thread advancem ## Seam-exit gate record -- **Source artifact**: `docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/slice-99-seam-exit-gate.md` +- **Source artifact**: `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/slice-99-seam-exit-gate.md` - **Landed evidence**: - Canonical contract: - `docs/foundation/openai-side-conformance-suite-c13-contract.md` (`C-13`) diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-1-openai-chat-completions-surface.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-1-openai-chat-completions-surface.md index bb709eb09..1a85a334c 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-1-openai-chat-completions-surface.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-1-openai-chat-completions-surface.md @@ -10,8 +10,8 @@ basis: source_scope_ref: scope_brief.md source_scope_version: v1 upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-11 diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-2-openai-responses-surface.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-2-openai-responses-surface.md index 4f6858256..cb3d062e3 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-2-openai-responses-surface.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/seam-2-openai-responses-surface.md @@ -11,7 +11,7 @@ basis: source_scope_version: v1 upstream_closeouts: - governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-12 diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/review.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/review.md index 634754514..984a449b5 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/review.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/review.md @@ -61,7 +61,7 @@ flowchart LR - `C-10` canonical artifact: `docs/foundation/openai-side-chat-completions-c10-contract.md` - `C-12` canonical artifact: `docs/foundation/openai-side-adapter-invariants-c12-contract.md` - **Revalidation gate**: `passed` - - upstream basis: `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md`, `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - upstream basis: `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md`, `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - **Opened remediations**: none ## Planned seam-exit gate focus diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/seam.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/seam.md index eb266a502..fe425ce87 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/seam.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-1-openai-chat-completions-surface/seam.md @@ -9,8 +9,8 @@ basis: source_seam_brief: ../../seam-1-openai-chat-completions-surface.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-11 @@ -61,7 +61,7 @@ open_remediations: [] - publication of the final contract artifacts is seam-exit work; pre-exec readiness depends on seam-local concreteness, not on closeout-backed publication existing already - **Basis posture**: - **Currentness**: `current` - - **Upstream closeouts assumed**: `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md`, `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - **Upstream closeouts assumed**: `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-2-closeout.md`, `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - **Required threads**: `THR-10`, `THR-11` - **Stale triggers**: - ADR 0008 changes the supported Chat Completions subset or the reject/ignore posture diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/seam.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/seam.md index 04d871c84..e12415870 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/seam.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-2-openai-responses-surface/seam.md @@ -9,8 +9,8 @@ basis: source_seam_brief: ../../seam-2-openai-responses-surface.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md - - docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md required_threads: - THR-10 - THR-12 @@ -66,8 +66,8 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` (revalidated against `SEAM-1` closeout-backed `THR-10` publication) - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` - - `docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` + - `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` + - `crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/governance/seam-3-closeout.md` - **Required threads**: `THR-10`, `THR-12` - **Stale triggers**: - ADR 0008 changes the Responses subset or the minimum streaming event set diff --git a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md index 62059af15..7800fbb07 100644 --- a/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md +++ b/crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/threaded-seams/seam-3-openai-side-conformance-and-drift-guards/seam.md @@ -9,8 +9,8 @@ basis: source_seam_brief: ../../seam-3-openai-side-conformance-and-drift-guards.md source_scope_ref: ../../scope_brief.md upstream_closeouts: - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md - - docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md + - crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md required_threads: - THR-10 - THR-11 @@ -65,8 +65,8 @@ open_remediations: [] - **Basis posture**: - **Currentness**: `current` (revalidated against landed `SEAM-1` and `SEAM-2` closeout-backed `C-10`, `C-11`, and `C-12` truth) - **Upstream closeouts assumed**: - - `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` - - `docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md` + - `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-1-closeout.md` + - `crates/gateway/docs/project_management/packs/active/openai-side-chat-completions-and-responses/governance/seam-2-closeout.md` - **Required threads**: `THR-10`, `THR-11`, `THR-12`, `THR-13` - **Stale triggers**: - any change to `SEAM-1` or `SEAM-2` public response shapes, error envelope rules, or streaming semantics diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index cd0fce71c..fa844e8c7 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -47,6 +47,8 @@ Completed extraction/rewrite slices: - `crates/gateway/docs/foundation/**` - `crates/gateway/tests/fixtures/azure_kimi/**` - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` +- gateway-local planning backlink cleanup completed for: + - `crates/gateway/docs/project_management/packs/active/**` - stale host-visible hardening and persistent-session planning anchors were already cleaned in earlier slices @@ -55,8 +57,6 @@ Still remaining before the atomic top-level `packs/**` removal: `docs/internals/world/workspace_sync_filesystem_model.md` - planning automation and workflow machinery still assume `docs/project_management/packs/**` - several tests outside `crates/broker/src/tests.rs` still read pack docs directly -- gateway-local planning docs under `crates/gateway/docs/project_management/**` remain out of - scope for deletion but still need their own backlink cleanup Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` @@ -64,6 +64,8 @@ Validation already completed for the finished slices: `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` - scoped reference scans over stable docs and non-`project_management` gateway docs no longer show top-level pack backlinks for the completed ADR-0027 and gateway-foundation slices +- scoped reference scans over `crates/gateway/docs/project_management/**` no longer show + top-level `docs/project_management/packs/**` or old `kimi-claude-adapter` pack backlinks ## Current Dependency Classes @@ -134,13 +136,16 @@ Completed rewrites: - `crates/gateway/docs/foundation/*.md` - `crates/gateway/tests/fixtures/azure_kimi/*.json` - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` +- `crates/gateway/docs/project_management/packs/active/**` Remaining dependency surface: -- `crates/gateway/docs/project_management/packs/active/**` +- none found in the current gateway-local markdown scan; this tree remains out of scope for + deletion but is no longer a top-level pack backlink blocker Disposition: -- rewrite foundation docs and fixture provenance to stable gateway docs or stable top-level contracts before removing top-level packs -- do not leave `crates/gateway/**` pointing at deleted top-level pack paths +- keep gateway-local planning docs in place +- do not let future edits reintroduce `docs/project_management/packs/**` backlinks from + `crates/gateway/**` ## Extraction Targets Before The Atomic `packs/**` Cut @@ -252,33 +257,25 @@ Required follow-up: - any Rust test that validates product behavior by asserting current docs mention the right contract - any stable operator or internal doc that cites a pack path as canonical -- remaining gateway-local docs and fixture provenance that still point at deleted top-level packs - after the completed rewrites in: - - `crates/gateway/docs/foundation/**` - - `crates/gateway/tests/fixtures/azure_kimi/**` - - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` +- any future gateway-local planning edits that reintroduce links to deleted top-level pack paths ## Recommended Resume Order Use this order in the next session: -1. Finish the remaining gateway-local backlink cleanup under - `crates/gateway/docs/project_management/**`. - - Goal: remove the remaining dependence on top-level `docs/project_management/packs/**` from - gateway-local planning docs without deleting the gateway-local planning tree itself. -2. Extract the world-sync filesystem semantics into +1. Extract the world-sync filesystem semantics into `docs/internals/world/workspace_sync_filesystem_model.md`. - Goal: eliminate another stable-doc blocker that still names pack specs as canonical. -3. Triage the remaining pack-reading tests: +2. Triage the remaining pack-reading tests: - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` - `crates/shell/tests/playbook_alignment.rs` - `crates/transport-api-types/src/lib.rs` - Goal: rewrite to stable docs where appropriate; delete planning-process-only assertions. -4. Remove or replace planning automation and workflow dependencies: +3. Remove or replace planning automation and workflow dependencies: - `Makefile` - `.github/workflows/feature-smoke.yml` - triad / smoke / CI helper scripts -5. Re-run a repo-wide reference scan. +4. Re-run a repo-wide reference scan. - Goal: confirm what still points at `docs/project_management/packs/**` before attempting the atomic cut. From 59639144b224ac04b0ac75b2d5cd908ac2a0c34f Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 13:09:11 -0400 Subject: [PATCH 09/20] chore: update project management retirement tracker --- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 63 ++- .../world/workspace_sync_filesystem_model.md | 377 +++++++++++++----- 2 files changed, 294 insertions(+), 146 deletions(-) diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index fa844e8c7..39e1f53fd 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -49,12 +49,14 @@ Completed extraction/rewrite slices: - `crates/gateway/docs/IMPORTANT_SUBSTRATE_ALIGNMENT.md` - gateway-local planning backlink cleanup completed for: - `crates/gateway/docs/project_management/packs/active/**` +- workspace-sync filesystem semantics completed in: + - `docs/internals/world/workspace_sync_filesystem_model.md` + - with stable path, diff, direction, conflict, safety-rail, and clear semantics absorbed out of + the pack specs - stale host-visible hardening and persistent-session planning anchors were already cleaned in earlier slices Still remaining before the atomic top-level `packs/**` removal: -- workspace-sync filesystem semantics are still owned by pack docs and still referenced from - `docs/internals/world/workspace_sync_filesystem_model.md` - planning automation and workflow machinery still assume `docs/project_management/packs/**` - several tests outside `crates/broker/src/tests.rs` still read pack docs directly @@ -66,6 +68,8 @@ Validation already completed for the finished slices: top-level pack backlinks for the completed ADR-0027 and gateway-foundation slices - scoped reference scans over `crates/gateway/docs/project_management/**` no longer show top-level `docs/project_management/packs/**` or old `kimi-claude-adapter` pack backlinks +- scoped reference scans over `docs/reference/**` and `docs/internals/**` no longer show + top-level world-sync or host-visible hardening pack backlinks ## Current Dependency Classes @@ -117,16 +121,14 @@ Completed stable-doc rewrites: - `docs/COMMANDS.md` - `docs/reference/world/deps/README.md` - `docs/internals/world/deps.md` +- `docs/internals/world/workspace_sync_filesystem_model.md` Remaining stable-doc blockers that still treat pack docs as current truth: -- `docs/reference/config/world.md` - - references `world-deps-host-visible-hardening/WDH0-spec.md` -- `docs/internals/world/workspace_sync_filesystem_model.md` - - references `world-sync` spec documents +- none currently identified under `docs/reference/**` or `docs/internals/**` Disposition: -- extract the normative content into `docs/reference/**`, `docs/contracts/**`, or `docs/internals/**` -- then rewrite these references to the new stable locations +- keep stable-doc scans in the validation loop so pack backlinks are not reintroduced while the + remaining tests and automation are retired ### 4. Gateway docs that link to top-level packs @@ -216,33 +218,19 @@ Current pack sources: - `docs/project_management/packs/implemented/world-sync/WS2-spec.md` - `docs/project_management/packs/implemented/world-sync/WS5-spec.md` -Recommended destination: -- absorb normative filesystem semantics into `docs/internals/world/workspace_sync_filesystem_model.md` -- create stable reference docs only if the content is operator-facing - -Required follow-up: -- rewrite the internal world docs that currently cite those pack specs - -Current recommendation: -- make this the next stable-doc extraction slice after the gateway-local backlink cleanup, because - it is now one of the clearest remaining product-doc blockers before pack deletion - -### E. Host-visible hardening references - -Current pack sources: -- `docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH0-spec.md` - -Current code comments still reference old `next/` paths: -- `crates/world/src/guard.rs` -- `crates/common/src/world_exec_guard.rs` -- `crates/world-service/src/world_exec_guard.rs` -- `crates/shell/src/execution/routing/dispatch/tests/repl_persistent_session_client_fail_closed.rs` +Stable destination now in place: +- `docs/internals/world/workspace_sync_filesystem_model.md` -Recommended destination: -- replace stale planning-path comments with stable doc anchors under `docs/reference/config/` or `docs/internals/world/` +Completed follow-up: +- absorbed the stable Linux filesystem semantics into + `docs/internals/world/workspace_sync_filesystem_model.md` +- removed the internal-doc dependency on the world-sync pack specs +- kept the operator-facing surface in `docs/reference/cli/workspace_sync.md` rather than creating + another stable reference page -Required follow-up: -- update comments and any tests relying on those comments as documentation anchors +Remaining follow-up: +- none for the stable-doc dependency itself; the remaining blockers now sit in tests and + automation rather than `docs/reference/**` or `docs/internals/**` ## Delete Or Rewrite Checklist Before Pack Removal @@ -263,19 +251,16 @@ Required follow-up: Use this order in the next session: -1. Extract the world-sync filesystem semantics into - `docs/internals/world/workspace_sync_filesystem_model.md`. - - Goal: eliminate another stable-doc blocker that still names pack specs as canonical. -2. Triage the remaining pack-reading tests: +1. Triage the remaining pack-reading tests: - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` - `crates/shell/tests/playbook_alignment.rs` - `crates/transport-api-types/src/lib.rs` - Goal: rewrite to stable docs where appropriate; delete planning-process-only assertions. -3. Remove or replace planning automation and workflow dependencies: +2. Remove or replace planning automation and workflow dependencies: - `Makefile` - `.github/workflows/feature-smoke.yml` - triad / smoke / CI helper scripts -4. Re-run a repo-wide reference scan. +3. Re-run a repo-wide reference scan. - Goal: confirm what still points at `docs/project_management/packs/**` before attempting the atomic cut. diff --git a/docs/internals/world/workspace_sync_filesystem_model.md b/docs/internals/world/workspace_sync_filesystem_model.md index dfed56573..21ea70dff 100644 --- a/docs/internals/world/workspace_sync_filesystem_model.md +++ b/docs/internals/world/workspace_sync_filesystem_model.md @@ -1,170 +1,333 @@ -# Workspace Sync — Filesystem Model (Reality, Linux) +# Workspace Sync — Filesystem Model (Current Linux Reality) -Scope: this document explains how `substrate workspace sync` behaves **today** on Linux given the -current world implementation (overlay-based “world” sessions). This is developer-facing and is -grounded in the codebase, not an aspirational contract. +Scope: this document explains how `substrate workspace sync` behaves today on Linux given the +current overlay-based world implementation. It is developer-facing and grounded in the current +shell, world-service, and overlayfs code paths. -If you are looking for the *operator-facing* CLI contract, see `docs/reference/cli/workspace_sync.md`. +If you are looking for the operator-facing command contract, see +`docs/reference/cli/workspace_sync.md`. ## Mental model (one sentence) -On Linux, the “world filesystem” is the **live host workspace** (overlay lower layer) plus an -optional **world-only overlay upper layer** for pending changes; `workspace sync` controls when the -world-only layer is applied to the host and/or discarded. +On Linux, the world filesystem is the live host workspace as the overlay lower layer plus an +optional world-only overlay upper layer for pending changes; `workspace sync` controls when the +world-only layer is applied back to the host and when conflicting shadowed paths are discarded. ## Glossary -- **Host workspace**: the real directory on the developer machine (e.g. `/home//repo`). -- **World session**: a reusable isolated context created by `world-service` (one per compatible - `WorldSpec` in the daemon process). -- **Overlay lower**: the host workspace directory (bind-mounted for overlay mounting). -- **Overlay upper/work**: where world-only writes and deletes are materialized. -- **Overlay merged**: what world processes see when reading/writing the project directory. -- **Pending diff**: the set of workspace-relative paths currently represented in overlay upper/work - (writes/mods/deletes). +- Host workspace: the real directory on the developer machine (for example `/home//repo`). +- World session: a reusable isolated context created by `world-service` for a compatible + `WorldSpec`. +- Overlay lower: the live host workspace directory used as the overlay baseline. +- Overlay upper/work: where world-only writes and deletes are materialized. +- Overlay merged: what world processes see when reading or writing the project directory. +- Pending diff: the current workspace-relative set of writes, mods, and deletes represented by the + overlay upper/work layer. +- Shadowed path: a host path whose current host state is hidden by a pending world-side overlay + entry for the same relative path. + +## Stable surfaces for this behavior + +- Operator overview: `docs/reference/cli/workspace_sync.md` +- Current implementation details and code pointers: this document +- Auto-sync hook behavior: `crates/shell/src/execution/auto_sync.rs` ## Where the behavior lives (code pointers) -Shell (“workspace sync” CLI and apply logic): +Shell (`workspace sync` CLI, filtering, conflict policy, apply, and clear): - `crates/shell/src/execution/workspace_cmd.rs` - - Fetch pending diff, filter excludes, detect conflicts, apply, then clear by `diff_id`. - - Implements directions `from_world | from_host | both` and conflict policy. World agent (pending diff record, conditional clear, reconciliation): - `crates/world-service/src/service.rs` - - `pending_diff()` builds `PendingDiffRecordV1` (includes `session_started_at` + `diff_id`). - - `pending_diff_clear()` clears only if the `diff_id` still matches. - - `pending_diff_reconcile()` discards selected overlay paths (host-preferred reconciliation). + - `pending_diff()` builds the record and computes `diff_id` + - `pending_diff_clear()` conditionally clears by `diff_id` + - `pending_diff_reconcile()` discards selected overlay paths by `diff_id` World backend and overlay tracking: -- `crates/world/src/lib.rs`: `LinuxLocalBackend::{pending_diff, clear_pending_diff, discard_pending_paths}` -- `crates/world/src/session.rs`: `SessionWorld` owns a persistent `OverlayFs` per session. - - `SessionWorld::clear_pending_diff()` discards the overlay upper/work (resetting “world-only” state). -- `crates/world/src/overlayfs/mod.rs`: overlay mount/unmount + `discard_paths()`. -- `crates/world/src/overlayfs/utils.rs`: computes a pending diff by walking the overlay upper layer. +- `crates/world/src/lib.rs` + - `LinuxLocalBackend::{pending_diff, clear_pending_diff, discard_pending_paths}` +- `crates/world/src/session.rs` + - `SessionWorld::clear_pending_diff()` resets the overlay upper/work layer +- `crates/world/src/overlayfs/mod.rs` + - overlay mount/unmount and `discard_paths()` +- `crates/world/src/overlayfs/utils.rs` + - pending diff computation and whiteout interpretation + +## Stable rules enforced today + +### 1. All diff paths are workspace-root-relative + +`workspace sync` treats all diff and reconciliation paths as workspace-root-relative strings. + +Normalization rules enforced by the shell and world-service: +- normalize separators to forward slashes +- strip a leading `./` +- reject empty paths +- reject absolute paths +- reject Windows drive-prefixed absolute paths +- reject any path containing a `..` segment + +Behavior: +- an invalid pending diff path causes a fail-closed sync refusal +- an invalid `discard_paths` reconciliation request is rejected by the agent + +### 2. Protected paths are a hard fail-closed boundary + +Protected excludes are injected automatically: +- `.git/**` +- `.substrate/**` + +If the raw pending diff contains any protected path, `workspace sync` refuses before mutation. +The shell reports the offending paths and exits without applying or clearing anything. + +This same protection also prevents checkpoint and rollback from mutating those paths. + +### 3. Exclude patterns are applied after protected-path refusal + +Effective excludes come from: +- protected excludes injected by the shell +- config `sync.exclude` +- CLI `workspace sync --exclude ` + +Pattern behavior: +- `*` matches within a path segment +- `**` matches across `/` +- `?` matches a single non-`/` character +- patterns are case-sensitive +- patterns must not start with `/` + +The shell removes duplicate patterns while preserving order. Excluded paths are skipped from the +apply set and counted in sync output, but excluded paths do not override protected-path refusal. + +### 4. Pending diffs are bucketed and normalized before decisions + +The pending diff record returned by the agent contains: +- `session_started_at` +- `diff_id` +- a required `non_pty` bucket +- an optional `pty` bucket + +Each bucket contains disjoint normalized path lists: +- `writes` +- `mods` +- `deletes` + +The shell: +- normalizes and validates raw paths +- rejects protected paths +- applies exclude filtering +- sorts and de-duplicates bucket contents +- computes a combined apply set from non-PTY and PTY buckets + +Implementation note: +- `diff_id` is intentionally stable across harmless reclassification of a path between `writes` + and `mods` +- it changes when the effective updates or deletes set changes +- this prevents false clear failures after host apply changes the lower-layer existence check + +### 5. Host changes are usually visible in world immediately + +Because overlay lower is the live host workspace, host create, modify, and delete operations are +normally visible in world reads immediately. -Specs / planning-pack references (authoritative intent, but not the source of truth for this doc): -- `docs/project_management/packs/active/world-sync/filesystem-semantics-spec.md` -- `docs/project_management/packs/active/world-sync/WS2-spec.md` -- `docs/project_management/packs/active/world-sync/WS5-spec.md` +The main exception is a shadowed path: +- if the world has a pending upper-layer entry for a path, the merged overlay can continue showing + the world version instead of the host version until that upper-layer entry is discarded or the + pending diff is cleared -## Key invariants (current reality) +### 6. World changes accumulate as overlay upper entries -### 1) Host changes are generally visible in world immediately +World-side filesystem changes under the project root are represented in overlay upper/work until +they are cleared or selectively discarded: +- creates and modifications materialize as upper-layer files or directories +- deletes materialize as overlay whiteouts -Because the overlay lower is the **live host workspace**, any host create/modify/delete is visible -in world reads as soon as it happens *unless* the path is shadowed by an overlay upper entry. +Pending diff computation walks the overlay upper layer and interprets whiteouts accordingly. -Shadowing happens when the world has a pending change for the same path. In that case, the overlay -merged view can continue to show the world version until the upper entry is discarded/cleared. +### 7. Direction semantics are asymmetric -### 2) World changes accumulate as overlay upper entries (“pending diffs”) +`workspace sync` resolves an effective direction: -When a world command creates/modifies/deletes a path under the project root, it is represented in -overlay upper/work until cleared: +- `from_world` + - apply pending world diffs to the host + - host is mutated + - both non-PTY and PTY pending diffs are included when present -- Creates/mods: materialized as real files/dirs under the overlay upper directory. -- Deletes: materialized as overlayfs whiteouts (`.wh.` files) in the upper directory. +- `from_host` + - reconcile host-newer shadowed paths back into the world overlay + - host is never mutated + - this is not an upload or copy operation because the host is already the lower-layer baseline -Pending diff computation walks overlay upper and interprets whiteouts: -- `crates/world/src/overlayfs/utils.rs` (`compute_diff()` + `.wh.` handling). +- `both` + - run `from_host` reconciliation first + - re-fetch the pending diff snapshot + - then run `from_world` apply on the updated snapshot -### 3) `workspace sync` (from_world) applies pending world diffs to host, then clears the snapshot +Important nuance for `from_host`: +- the shell computes conflicts only for shadowed paths whose host mtime is newer than + `session_started_at` +- `prefer_host` discards the world overlay entry for those conflicting paths only +- `prefer_world` keeps the overlay entry +- `abort` refuses if any such conflict exists -The host apply path: -1) Fetch pending diff record from world-service (includes `diff_id`). -2) Apply deletes then writes/mods (after preflight validation). -3) Attempt to clear the pending diff snapshot using `pending_diff_clear(diff_id=...)`. +### 8. Conflict detection uses world session start time -If the clear step fails, Substrate must not clear “whatever is current”: -- `crates/shell/src/execution/workspace_cmd.rs` (clear refusal path). -- `docs/project_management/packs/active/world-sync/filesystem-semantics-spec.md` (“Clear/ack semantics”). +For reconciliation and apply, a host path is considered conflicting when: +- the host path exists, and +- its mtime is strictly greater than `session_started_at` -### 4) Clearing pending diffs resets the world-only overlay state +This is a coarse policy gate, not a three-way merge. -Clearing discards overlay upper/work (and unmounts the overlay) for that session: -- `crates/world/src/session.rs` (`clear_pending_diff()` → `OverlayFs::cleanup()`). +Conflict policy behavior: +- `prefer_host` + - `from_host`: discard conflicting overlay entries so the world observes the host version + - `from_world`: skip conflicting paths from apply +- `prefer_world` + - keep world pending changes and apply them to host when relevant +- `abort` + - refuse the operation if any conflict exists -After a clear, subsequent world commands see only the live host baseline until a new world change -recreates overlay upper entries again. +### 9. Apply preflight is fail-closed -### 5) `from_host` is reconciliation of shadowed paths, not “copy host into world” +Before any host mutation, the shell performs all-or-nothing validation: +- protected path refusal +- exclude filtering +- `max_paths = 10000` +- `max_bytes_to_copy = 104857600` across selected writes and mods +- abort-on-conflict when policy is `abort` +- backend capability checks for pending diff clear and world file reads -Because host is already the baseline, “host→world” sync is implemented as: -- identify paths shadowed by pending overlay entries (union of writes/mods/deletes), -- for conflicting paths, decide whether to discard (prefer host) or keep (prefer world), -- perform the decision by deleting overlay upper entries / whiteouts for selected paths. +If any preflight guard fails, no host mutations occur. -This is implemented by `pending_diff_reconcile_v1`: -- shell: `crates/shell/src/execution/workspace_cmd.rs` -- agent: `crates/world-service/src/service.rs` (`pending_diff_reconcile()`) -- backend: `crates/world/src/lib.rs` (`discard_pending_paths()`) -- overlay: `crates/world/src/overlayfs/mod.rs` (`discard_paths()`) +### 10. Only regular files and directories can be applied -### 6) Conflict detection uses `session_started_at` (world session start) +For selected writes and mods, the shell reads current world metadata first. -On apply/reconciliation, Substrate considers a host path “in conflict” if: -- host path exists, and -- host mtime is strictly greater than `session_started_at`. +Apply accepts: +- directories +- regular files -Implications: -- This is a coarse-grained “anything touched after the world session began” signal. -- It is not a 3-way merge; it is a policy gate for deciding whether to apply/discard world changes. +Apply refuses fail-closed for other file types, including: +- symlinks +- sockets +- device nodes +- FIFOs -## Common “surprise” scenarios (expected today) +This is why overlayfs symlink entries are still tracked in pending diffs: sync must see them and +refuse safely rather than silently dropping them. -### Scenario: “I synced a world file to host; deleting it on host also deletes it in world” +### 11. Apply ordering and content preservation are deterministic + +After validation passes, apply order is deterministic: +1. Deletes, sorted by path depth descending and then lexicographically descending +2. Writes and mods, sorted lexicographically ascending + +Apply behavior: +- deletes remove files directly and directories recursively +- directory writes create parent directories as needed +- file writes read current world bytes at apply time and write them atomically to host +- execute bits are preserved on Unix for directories and regular files + +Failure model: +- after preflight passes, apply is best-effort +- the shell stops at the first filesystem failure +- already-applied mutations are not rolled back + +### 12. Clearing pending diffs is conditional on `diff_id` + +After a successful `from_world` apply, the shell attempts to clear the applied snapshot by sending +the same `diff_id` back to `pending_diff_clear()`. + +Rules: +- `--dry-run` never clears +- the agent clears only if the current pending diff still hashes to the same `diff_id` +- a mismatch means new or changed pending overlay state arrived concurrently + +If clear fails: +- host mutations remain applied +- the command exits as a failure +- the shell prints `applied but pending diffs were not cleared` + +The shell never clears "whatever is current." + +## Dry-run and verbose behavior + +`workspace sync --dry-run` does not mutate host or overlay state. + +Current output shape: +- `from_host` dry-run prints a reconciliation plan summary +- `from_world` dry-run prints non-PTY, optional PTY, and combined pending diff summaries +- `--verbose` includes `session_started_at`, `diff_id`, and per-path decisions + +For apply: +- non-verbose output reports applied counts plus skipped-by-exclude and skipped-by-conflict totals +- verbose output includes per-path apply or skip decisions + +## Common "surprise" scenarios (expected today) + +### Scenario: "I synced a world file to host; deleting it on host also deletes it in world" This is expected. -Once a world-created file is applied to host and the pending diff is cleared, the file becomes part -of the shared baseline. Removing it on host removes it from what the world sees (overlay lower). +Once a world-created file is applied to host and the pending diff is cleared, that file becomes +part of the shared host lower layer. Deleting it on host deletes it from what the world sees. -### Scenario: “`from_host` doesn’t upload host-only new files to world” +### Scenario: "`from_host` doesn't upload host-only new files to world" Also expected. -Host-only files are already visible in world via the baseline. `from_host` exists for the case -where the world has a pending upper entry that is hiding the host’s current version. +Host-only files are already visible in world through the lower layer. `from_host` only exists to +resolve cases where a pending world overlay entry is hiding the host version of a shadowed path. + +### Scenario: "A host edit still loses to the world version until I reconcile or clear" + +Also expected. + +If the path is shadowed by a pending upper-layer entry, the world can keep seeing the world version +until `from_host` discards that upper entry or a later clear resets the overlay state. ## Auto-sync (`sync.auto_sync=true`) — current reality -When `sync.auto_sync=true`, the shell will opportunistically run a workspace sync automatically -after successful commands, using the same engine as `substrate workspace sync`: +When `sync.auto_sync=true`, the shell opportunistically runs the same sync engine after successful +commands: -- One-shot execution path (`substrate -c "..."`): - - Hook lives in `crates/shell/src/execution/routing/dispatch/exec.rs` (post-success hook). -- Async REPL path (`substrate` interactive session): - - Hook runs on REPL exit and lives in `crates/shell/src/repl/async_repl.rs`. +- one-shot execution path + - `crates/shell/src/execution/routing/dispatch/exec.rs` +- async REPL path + - `crates/shell/src/repl/async_repl.rs` -Implementation details: -- Auto-sync is wired through `crates/shell/src/execution/auto_sync.rs`. -- Effective direction handling: - - `sync.direction=from_host` → no-op (auto-sync does not run). - - `sync.direction=from_world|both` → calls the `workspace sync` engine with that direction. -- Failures are surfaced as `auto-sync failed: ...` and propagate a non-zero exit code. +Behavior: +- `sync.direction=from_host` results in no auto-sync apply +- `sync.direction=from_world` or `both` runs the sync engine automatically +- failures surface as `auto-sync failed: ...` and propagate a non-zero exit code ## Debugging workflows -### Inspect what sync would do +### Preview decisions safely - `substrate workspace sync --dry-run --verbose` - - shows pending diff counts and (with verbose) the `diff_id` and decisions. -### Inspect overlay storage on Linux +Useful details: +- `session_started_at` +- `diff_id` +- non-PTY and PTY counts +- excluded counts +- conflict decisions + +### Inspect Linux overlay storage -The overlay base directory is selected by uid/runtime dirs: -- `crates/world/src/overlayfs/layering.rs` (`choose_base_dir()`). +Overlay base directory selection: +- `crates/world/src/overlayfs/layering.rs` (`choose_base_dir()`) -Within that base directory, overlay state is stored per world id (`wld_`): -- `crates/world/src/session.rs` (world ids). +Per-session overlay directories: +- `crates/world/src/session.rs` (world ids and overlay ownership) -## Notes on future evolution (non-authoritative) +### Inspect why a clear or reconcile refused -The current model is intentionally “live host lower + world upper”. +Look for: +- `diff_id mismatch (concurrent changes detected)` +- protected path refusal output +- unsupported file type refusal output -If we want a UX where “host changes do not enter world until explicitly synced”, the world lower -cannot be the live host workspace. That would require introducing a snapshot baseline for the world -(e.g., a materialized snapshot dir) and explicit host→world apply semantics. Internal git -(`workspace checkpoint`/`rollback`) is a plausible building block for snapshot materialization, but -it is not currently wired into world mounts. +These messages map directly to the shell's fail-closed branches in +`crates/shell/src/execution/workspace_cmd.rs`. From 6a84f53512c604e5e10712d34d97036d60b55ed6 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 13:31:22 -0400 Subject: [PATCH 10/20] Remove markdown-coupled tests --- crates/broker/src/tests.rs | 104 ---------- .../agent_successor_contract_ahcsitc0.rs | 191 ------------------ crates/shell/tests/playbook_alignment.rs | 108 ---------- .../tests/world_deps_apt_fail_early_wdap1.rs | 103 ---------- crates/transport-api-types/src/lib.rs | 31 --- 5 files changed, 537 deletions(-) delete mode 100644 crates/shell/tests/playbook_alignment.rs diff --git a/crates/broker/src/tests.rs b/crates/broker/src/tests.rs index 3fab52925..994c7550a 100644 --- a/crates/broker/src/tests.rs +++ b/crates/broker/src/tests.rs @@ -980,18 +980,6 @@ mod c0_policy_patch_only_broker_effective_resolution { .expect("failed to allocate integration test temp dir") } - fn repo_root() -> PathBuf { - PathBuf::from(env!("CARGO_MANIFEST_DIR")) - .join("../..") - .canonicalize() - .expect("canonicalize repo root") - } - - fn read_repo_file(relative: &str) -> String { - std::fs::read_to_string(repo_root().join(relative)) - .unwrap_or_else(|err| panic!("read {relative}: {err}")) - } - struct Fixture { _temp: TempDir, home: PathBuf, @@ -1180,69 +1168,6 @@ world_fs: ); } - #[test] - fn c0_itps0_contract_doc_locks_authoritative_surface_exit_codes_and_deny_patterns() { - let contract = read_repo_file("docs/reference/policy/contract.md"); - let tuple_constraints = read_repo_file("docs/reference/policy/tuple_constraints.md"); - - for needle in [ - "Substrate's LLM and agent surfaces stay on the existing layered config and policy files:", - "Backend ids remain adapter selectors only.", - "ADR-0043 extends the policy surface additively under `llm.constraints.*`.", - "`substrate policy current show --explain` is the authoritative merged inspection surface", - "Tuple-policy publication reuses the existing `identity_tuple` and `placement_posture` field", - "Tuple-axis mismatch denial maps to exit code `5`.", - ] { - assert!( - contract.contains(needle), - "expected policy contract to contain {needle:?}" - ); - } - - for needle in [ - "Tuple-policy schema invalidity maps to `2`.", - "effective gateway routing authority 'substrate_gateway' is not allowlisted by llm.constraints.routers", - "effective gateway protocol '' is not allowlisted by llm.constraints.protocols", - "effective gateway provider '' is not allowlisted by llm.constraints.providers", - "effective gateway auth authority '' is not allowlisted by llm.constraints.auth_authorities", - ] { - assert!( - tuple_constraints.contains(needle), - "expected tuple constraint reference to contain {needle:?}" - ); - } - } - - #[test] - fn c0_itps0_schema_doc_locks_owned_keys_defaults_replace_semantics_and_client_omission() { - let schema = read_repo_file("docs/reference/policy/schema.md"); - let tuple_constraints = read_repo_file("docs/reference/policy/tuple_constraints.md"); - - for needle in [ - "`llm.allowed_backends: [string]`", - "`agents.allowed_backends: [string]`", - "`workflow.router.allowed_workflow_ids: [string]`", - "ADR-0043 extends this policy family additively with tuple-axis narrowing constraints under", - "`llm.constraints.routers`", - "`llm.constraints.providers`", - "`llm.constraints.protocols`", - "`llm.constraints.auth_authorities`", - "workspace patch replaces the same global key", - "Effective meaning of `[]`:\n- unconstrained on that axis", - "`client` is not a standalone policy key in v1.", - "- `llm.constraints.clients`", - ] { - assert!( - schema.contains(needle) || tuple_constraints.contains(needle), - "expected stable policy references to contain {needle:?}" - ); - } - assert!( - !tuple_constraints.contains("| `llm.constraints.clients` |"), - "tuple constraint reference must not introduce llm.constraints.clients as a canonical key" - ); - } - #[test] fn c0_itps0_schema_examples_match_snake_case_and_dotted_id_validators() { for value in [ @@ -1379,35 +1304,6 @@ world_fs: ); } - #[test] - fn c1_itps1_policy_spec_locks_runtime_order_fail_early_rules_and_failure_buckets() { - let policy_spec = read_repo_file("docs/reference/policy/tuple_constraints.md"); - - for needle in [ - "1. Validate gateway lifecycle config.", - "2. Resolve the selected backend inventory entry and apply `llm.allowed_backends` before tuple", - "4. Apply tuple-axis narrowing in this exact order:", - "5. Resolve integrated auth source material:", - "6. Apply world-boundary posture.", - "7. Apply downstream transport and egress gates.", - "- blocked env auth is a policy denial", - "- partial env auth is invalid integration", - "If the selected backend id is absent from `llm.allowed_backends`, evaluation stops before", - "\" is not allowlisted by effective policy llm.allowed_backends\"", - "effective gateway provider is unresolved while llm.constraints.providers is constrained", - "effective gateway auth authority is unresolved while llm.constraints.auth_authorities is constrained", - "- the required world or gateway socket is missing", - "- connection refused", - "- timeout", - "Explain output for tuple-aware denials must identify the exact policy key that denied the route.", - ] { - assert!( - policy_spec.contains(needle), - "expected tuple constraint reference to contain {needle:?}" - ); - } - } - #[test] #[serial] fn c0_policy_global_set_rejects_unknown_and_invalid_lacp0_updates_with_exit_2() { diff --git a/crates/shell/tests/agent_successor_contract_ahcsitc0.rs b/crates/shell/tests/agent_successor_contract_ahcsitc0.rs index 797623b65..f13db3b16 100644 --- a/crates/shell/tests/agent_successor_contract_ahcsitc0.rs +++ b/crates/shell/tests/agent_successor_contract_ahcsitc0.rs @@ -4764,197 +4764,6 @@ fn agent_doctor_fails_at_runtime_realizability_when_selected_cli_mode_is_per_req ); } -#[test] -fn docs_usage_and_repo_boundary_match_the_successor_contract() { - let usage = read_repo_file("docs/USAGE.md"); - assert!( - usage.contains("substrate agent list"), - "docs/USAGE.md must document the canonical singular list command" - ); - assert!( - usage.contains("substrate agent status"), - "docs/USAGE.md must document the canonical singular status command" - ); - assert!( - usage.contains("substrate agent doctor"), - "docs/USAGE.md must document the canonical singular doctor command" - ); - assert!( - usage.contains("substrate agent toolbox status"), - "docs/USAGE.md must document the canonical singular toolbox status command" - ); - assert!( - usage.contains("substrate agent toolbox env"), - "docs/USAGE.md must document the canonical singular toolbox env command" - ); - for forbidden in [ - "substrate agents list", - "substrate agents status", - "substrate agents doctor", - "live session discovery is backed by persisted manifests under `~/.substrate/run/agent-hub/handles/`", - ] { - assert!( - !usage.contains(forbidden), - "docs/USAGE.md must not advertise plural successor aliases: {forbidden}" - ); - } - for required in [ - "`~/.substrate/run/agent-hub/sessions//session.json`", - "`~/.substrate/run/agent-hub/sessions//participants/.json`", - "`~/.substrate/run/agent-hub/handles/*.json` remains compatibility input only", - ] { - assert!( - usage.contains(required), - "docs/USAGE.md must describe the session-root live-state authority boundary `{required}`" - ); - } - - assert!( - !repo_root().join("crates/agent-hub").exists(), - "AHCSITC0 must not introduce a new crates/agent-hub package" - ); -} - -#[test] -fn ahcsitc3_specs_lock_supersession_parity_and_validation_boundaries() { - let compatibility = read_repo_file( - "docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/compatibility-spec.md", - ); - for required in [ - "ADR-0025 is historical evidence only", - "ADR-0025 may be cited only as superseded historical evidence.", - "Existing `agents.allowed_backends` entries remain valid without rewriting because `backend_id` stays derived as `:`.", - "`substrate agents validate` remains supported as an additive compatibility leaf for inventory validation only.", - "`backend_id` remains the agent-side adapter identifier and allowlist token", - ] { - assert!( - compatibility.contains(required), - "compatibility-spec.md must lock AHCSITC3 closeout rule `{required}`" - ); - } - - let parity = read_repo_file( - "docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/platform-parity-spec.md", - ); - for required in [ - "| Linux |", - "| macOS |", - "| Windows |", - "`substrate agents validate` remains a compatibility leaf on every platform and never becomes an alias for list, status, or doctor.", - "Nested gateway-backed LLM records always omit `world_id` and `world_generation` on every platform.", - "If the effective command path requires a world-scoped member posture and the required world boundary is temporarily unavailable, `substrate agent doctor` returns exit `3`.", - "If the current build or platform cannot satisfy the required world posture at all, `substrate agent doctor` returns exit `4`.", - "`crates/shell/tests/agents_validate.rs`", - "`crates/shell/tests/agent_hub_trace_persistence.rs`", - "`crates/shell/tests/repl_world_first_routing_v1.rs`", - "`scripts/linux/world-provision.sh`", - "`scripts/mac/lima-warm.sh`", - "`scripts/mac/smoke.sh`", - "`scripts/windows/wsl-warm.ps1`", - "`scripts/windows/wsl-smoke.ps1`", - ] { - assert!( - parity.contains(required), - "platform-parity-spec.md must lock AHCSITC3 parity evidence `{required}`" - ); - } - - let playbook = read_repo_file( - "docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/manual_testing_playbook.md", - ); - for required in [ - "### Case 1 — `substrate agent list --json` keeps adapter identity and omission rules", - "### Case 2 — `substrate agent status --json` proves a host-scoped orchestrator", - "### Case 3 — world-scoped members publish `world_id` and `world_generation`", - "### Case 4 — nested gateway-backed records publish `run_id`, `provider`, and `auth_authority` on the nested record only", - "### Case 5 — canonical trace keeps the same pure-agent versus nested-record split", - "### Case 6 — `substrate agent doctor --json` proves healthy ordered checks", - "### Case 7 — `substrate agent doctor` fails closed for invalid orchestrator state", - "### Case 8 — `substrate agent doctor` fails closed for world-boundary loss", - "`crates/shell/tests/agents_validate.rs`", - "`crates/shell/tests/agent_hub_trace_persistence.rs`", - "`crates/shell/tests/repl_world_first_routing_v1.rs`", - ] { - assert!( - playbook.contains(required), - "manual_testing_playbook.md must keep AHCSITC3 validation coverage `{required}`" - ); - } -} - -#[test] -fn ahcsitc3_configuration_doc_locks_successor_config_surface() { - let configuration = read_repo_file("docs/CONFIGURATION.md"); - for required in [ - "agents.hub.orchestrator_agent_id", - "agents.allowed_backends", - ] { - assert!( - configuration.contains(required), - "docs/CONFIGURATION.md must document successor config surface `{required}`" - ); - } -} - -#[test] -fn closeout_docs_keep_session_and_participant_terms_aligned_to_runtime_truth() { - let matrix = read_repo_file("AGENT_ORCHESTRATION_GAP_MATRIX.md"); - for required in [ - "Status ambiguity handling", - "Trace-only participant-aware fallback", - "orchestration_session_id", - "participant_id", - ] { - assert!( - matrix.contains(required), - "gap matrix must retain closeout terminology `{required}`" - ); - } - - let packet = read_repo_file("llm-last-mile/README.md"); - for required in [ - "`~/.substrate/run/agent-hub/sessions//session.json`", - "`~/.substrate/run/agent-hub/sessions//participants/.json`", - "trace.jsonl` remains audit history, not live state authority", - "read-only status can degrade to warnings", - ] { - assert!( - packet.contains(required), - "llm-last-mile README must document the runtime truth `{required}`" - ); - } - assert!( - !packet.contains("`~/.substrate/run/agent-sessions/.json`"), - "llm-last-mile README must not keep the superseded agent-sessions path" - ); -} - -#[test] -fn ahcsitc3_trace_doc_locks_tuple_compatible_fields() { - let trace = read_repo_file("docs/TRACE.md"); - for required in [ - "`backend_id`", - "`client`", - "`router`", - "`protocol`", - "`provider`", - "`auth_authority`", - "`world_id`", - "`world_generation`", - "`~/.substrate/run/agent-hub/sessions//session.json`", - "`~/.substrate/run/agent-hub/sessions//participants/.json`", - "`~/.substrate/run/agent-hub/sessions/.json`", - "`~/.substrate/run/agent-hub/participants/*.json`", - "`~/.substrate/run/agent-hub/handles/*.json` remains legacy compatibility input only", - "Invalidated participant tombstones in canonical or flat compatibility participant records beat stale trace fallback rows", - ] { - assert!( - trace.contains(required), - "docs/TRACE.md must document tuple-compatible trace field `{required}`" - ); - } -} - #[test] fn production_runtime_snapshot_writes_remain_centralized_in_state_store() { let src_root = repo_root().join("crates/shell/src"); diff --git a/crates/shell/tests/playbook_alignment.rs b/crates/shell/tests/playbook_alignment.rs deleted file mode 100644 index d8e13b302..000000000 --- a/crates/shell/tests/playbook_alignment.rs +++ /dev/null @@ -1,108 +0,0 @@ -use std::path::{Path, PathBuf}; - -fn playbook_paths() -> Vec { - let packs_dir = - PathBuf::from(env!("CARGO_MANIFEST_DIR")).join("../../docs/project_management/packs"); - let mut out = Vec::new(); - collect_playbooks(&packs_dir, &mut out); - out -} - -fn collect_playbooks(dir: &Path, out: &mut Vec) { - let entries = match std::fs::read_dir(dir) { - Ok(entries) => entries, - Err(_) => return, - }; - - for entry in entries.flatten() { - let path = entry.path(); - if path.is_dir() { - collect_playbooks(&path, out); - continue; - } - if path - .file_name() - .is_some_and(|name| name == "manual_testing_playbook.md") - { - out.push(path); - } - } -} - -fn parse_heredoc_delimiter(line: &str) -> Option { - let prefix = "cat > .substrate-profile <<"; - let start = line.find(prefix)?; - let after = line[start + prefix.len()..].trim(); - let token = after.split_whitespace().next()?.trim_end_matches(';'); - let token = token - .strip_prefix('\'') - .and_then(|value| value.strip_suffix('\'')) - .or_else(|| { - token - .strip_prefix('\"') - .and_then(|value| value.strip_suffix('\"')) - }) - .unwrap_or(token); - if token.is_empty() { - None - } else { - Some(token.to_string()) - } -} - -#[test] -fn manual_testing_playbook_substrate_profile_snippets_include_required_id_and_name() { - let playbooks = playbook_paths(); - assert!( - !playbooks.is_empty(), - "expected at least one manual testing playbook under docs/project_management/packs/" - ); - - for playbook_path in playbooks { - let contents = std::fs::read_to_string(&playbook_path) - .unwrap_or_else(|err| panic!("failed to read {playbook_path:?}: {err}")); - - let mut snippets = Vec::new(); - let mut lines = contents.lines().enumerate().peekable(); - while let Some((line_no, line)) = lines.next() { - let Some(delimiter) = parse_heredoc_delimiter(line) else { - continue; - }; - - let mut snippet = Vec::new(); - for (_, body_line) in lines.by_ref() { - if body_line.trim_end() == delimiter { - break; - } - snippet.push(body_line); - } - - snippets.push((line_no + 1, snippet.join("\n"))); - } - - if snippets.is_empty() { - continue; - } - - for (start_line, snippet) in snippets { - let value: serde_yaml::Value = serde_yaml::from_str(&snippet).unwrap_or_else(|err| { - panic!( - "failed to parse `.substrate-profile` snippet from {playbook_path:?}:{start_line} as YAML: {err}\n---\n{snippet}\n---" - ) - }); - - let mapping = value.as_mapping().unwrap_or_else(|| { - panic!( - "expected YAML mapping at top-level for `.substrate-profile` snippet from {playbook_path:?}:{start_line}\n---\n{snippet}\n---" - ) - }); - - let has_id = mapping.contains_key(serde_yaml::Value::String("id".to_string())); - let has_name = mapping.contains_key(serde_yaml::Value::String("name".to_string())); - assert!( - has_id == has_name, - "expected `.substrate-profile` snippet from {playbook_path:?}:{start_line} to include either both top-level keys `id` and `name`, or neither\n---\n{snippet}\n---" - ); - } - } -} diff --git a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs index 6c1ef716a..ccf088bcb 100644 --- a/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs +++ b/crates/shell/tests/world_deps_apt_fail_early_wdap1.rs @@ -23,109 +23,6 @@ fn write_file(path: &Path, contents: &str) { fs::write(path, contents).expect("write file"); } -fn repo_root() -> PathBuf { - PathBuf::from(env!("CARGO_MANIFEST_DIR")) - .join("../..") - .canonicalize() - .expect("canonicalize repo root") -} - -fn read_repo_file(relative: &str) -> String { - fs::read_to_string(repo_root().join(relative)) - .unwrap_or_else(|err| panic!("read {relative}: {err}")) -} - -#[test] -fn wdap1_required_docs_reference_the_contract_and_provisioning_workflow() { - let reference_readme = read_repo_file("docs/reference/world/deps/README.md"); - assert!( - reference_readme.contains("## System-package runtime fail-early"), - "expected docs/reference/world/deps/README.md to include the runtime heading" - ); - assert!( - reference_readme.contains("## Commands you will use"), - "expected docs/reference/world/deps/README.md to include the commands heading" - ); - assert!( - reference_readme.contains("docs/reference/world/deps/provisioning.md"), - "expected docs/reference/world/deps/README.md to link to the stable provisioning contract" - ); - assert!( - reference_readme.contains("substrate world enable --provision-deps"), - "expected docs/reference/world/deps/README.md to mention the operator remediation" - ); - - let internals = read_repo_file("docs/internals/world/deps.md"); - assert!( - internals.contains("## High-level flow"), - "expected docs/internals/world/deps.md to include the high-level flow heading" - ); - assert!( - internals.contains("## System-package runtime fail-early"), - "expected docs/internals/world/deps.md to include the runtime fail-early heading" - ); - assert!( - internals.contains("docs/reference/world/deps/provisioning.md"), - "expected docs/internals/world/deps.md to link to the stable provisioning contract" - ); - assert!( - internals.contains("substrate world enable --provision-deps"), - "expected docs/internals/world/deps.md to mention the provisioning workflow" - ); - - let world_doc = read_repo_file("docs/WORLD.md"); - assert!( - world_doc.contains("## 5) Agent API (over UDS)"), - "expected docs/WORLD.md to include the Agent API heading" - ); - assert!( - world_doc.contains("profile"), - "expected docs/WORLD.md to mention the request profile field" - ); - assert!( - world_doc.contains("docs/reference/world/deps/provisioning.md"), - "expected docs/WORLD.md to link to the stable provisioning contract" - ); - - let configuration = read_repo_file("docs/CONFIGURATION.md"); - assert!( - configuration.contains("SUBSTRATE_WORLD_REQUEST_PROFILE"), - "expected docs/CONFIGURATION.md to include SUBSTRATE_WORLD_REQUEST_PROFILE" - ); - assert!( - configuration.contains("docs/reference/world/deps/provisioning.md"), - "expected docs/CONFIGURATION.md to link to the stable provisioning contract" - ); - assert!( - configuration.contains("substrate world enable --provision-deps"), - "expected docs/CONFIGURATION.md to mention the operator workflow" - ); - - let commands = read_repo_file("docs/COMMANDS.md"); - assert!( - commands.contains("### world Subcommand"), - "expected docs/COMMANDS.md to include the world subcommand section" - ); - assert!( - commands.contains("--provision-deps"), - "expected docs/COMMANDS.md to document the --provision-deps flag" - ); - assert!( - commands.contains("docs/reference/world/deps/provisioning.md"), - "expected docs/COMMANDS.md to link to the stable provisioning contract" - ); - - let wdap1_contract = read_repo_file("docs/reference/world/deps/provisioning.md"); - assert!( - wdap1_contract.contains("unsupported on Windows"), - "expected the stable provisioning contract to preserve the Windows runtime guidance" - ); - assert!( - wdap1_contract.contains("Substrate will not mutate the host OS"), - "expected the stable provisioning contract to preserve the Linux host-native runtime guidance" - ); -} - #[cfg(unix)] fn normalize_output(raw: &[u8]) -> String { String::from_utf8_lossy(raw).replace("\r\n", "\n") diff --git a/crates/transport-api-types/src/lib.rs b/crates/transport-api-types/src/lib.rs index c86935f2b..359ba5cdd 100644 --- a/crates/transport-api-types/src/lib.rs +++ b/crates/transport-api-types/src/lib.rs @@ -1630,8 +1630,6 @@ pub enum WorldDoctorWorldFsStrategyProbeResultV1 { #[cfg(test)] mod tests { use super::*; - use std::fs; - use std::path::Path; use serde_json::{json, Value}; @@ -2116,35 +2114,6 @@ mod tests { ); } - #[test] - fn laitdp2_manual_review_playbook_names_required_evidence() { - let playbook_path = Path::new(env!("CARGO_MANIFEST_DIR")).join( - "../../docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md", - ); - let playbook = - fs::read_to_string(&playbook_path).expect("manual testing playbook should be readable"); - - for required in [ - "One-owner-per-surface audit", - "Tuple meanings and wording", - "Machine-readable schema ownership", - "Policy and telemetry owner lines", - "Platform parity and compatibility", - "Claude Code pointed at `substrate_gateway`", - "Codex using Responses API and `~/.codex/auth.json`", - "Pre-provider-selection publication", - "Search for overloaded backend wording", - "Search for bridge wording that implies a second control plane", - "Search for status-schema drift", - "Search for stale active or backup references presented as current owners", - ] { - assert!( - playbook.contains(required), - "manual review playbook must include `{required}` as LAITDP2 validation evidence" - ); - } - } - #[test] fn gateway_integrated_auth_validation_rejects_unknown_facet_fields() { let err = serde_json::from_value::(json!({ From e2bd8ffb342d60e1bb120ef1254266679bf8bb57 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 13:49:42 -0400 Subject: [PATCH 11/20] Remove obsolete substrate world plumbing --- .github/workflows/feature-smoke.yml | 909 +------------------------- Makefile | 450 +------------ docs/PROJECT_MANAGEMENT_RETIREMENT.md | 84 ++- scripts/ci-audit/ci_audit.sh | 40 +- scripts/ci-audit/ci_audit_record.sh | 36 +- scripts/ci/dispatch_feature_smoke.sh | 614 +---------------- scripts/e2e/triad_e2e_all.sh | 60 +- scripts/e2e/triad_e2e_phase1.sh | 655 +------------------ scripts/e2e/triad_e2e_phase2.sh | 514 +-------------- scripts/mac/smoke.sh | 11 +- 10 files changed, 120 insertions(+), 3253 deletions(-) diff --git a/.github/workflows/feature-smoke.yml b/.github/workflows/feature-smoke.yml index 07d967525..af0edfd47 100644 --- a/.github/workflows/feature-smoke.yml +++ b/.github/workflows/feature-smoke.yml @@ -1,917 +1,18 @@ -name: Feature Smoke (Planning Pack) +name: Retired Feature Smoke on: workflow_dispatch: - inputs: - feature_dir: - description: "Feature Planning Pack directory (e.g., docs/project_management/_archived/next/world-sync)" - required: true - type: string - checkout_ref: - description: "Git ref to checkout for running the smoke scripts (defaults to the workflow ref)." - required: false - type: string - default: "" - runner_kind: - description: "Where to run the smoke job(s)" - required: true - type: choice - options: - - github-hosted - - self-hosted - default: github-hosted - macos_runner_kind: - description: "Override where macOS runs when runner_kind=self-hosted (hybrid fallback)." - required: false - type: choice - options: - - self-hosted - - github-hosted - default: self-hosted - platform: - description: "Which platform smoke to run" - required: true - type: choice - options: - - behavior - - linux - - macos - - windows - - wsl - - all - run_wsl: - description: "Also run WSL smoke (requires suitable runner)" - required: false - type: boolean - default: false - run_integ_checks: - description: "Also run full integration checks (fmt --check, clippy -D warnings, workspace tests) before smoke." - required: false - type: boolean - default: false - smoke_slice_id: - description: "Optional slice id (e.g., WCU1) passed to smoke scripts as SUBSTRATE_SMOKE_SLICE_ID." - required: false - type: string - default: "" - -env: - CARGO_TERM_COLOR: always - RUST_TOOLCHAIN: 1.89.0 - SUBSTRATE_SMOKE_SLICE_ID: ${{ inputs.smoke_slice_id }} permissions: contents: read jobs: - validate_inputs: - runs-on: ubuntu-24.04 - steps: - - name: Validate inputs - shell: bash - run: | - set -euo pipefail - platform="${{ inputs.platform }}" - runner_kind="${{ inputs.runner_kind }}" - run_wsl="${{ inputs.run_wsl }}" - - if [[ "${platform}" == "wsl" && "${runner_kind}" != "self-hosted" ]]; then - echo "ERROR: platform=wsl requires runner_kind=self-hosted" >&2 - exit 1 - fi - - if [[ "${run_wsl}" == "true" && "${runner_kind}" != "self-hosted" ]]; then - echo "ERROR: run_wsl=true requires runner_kind=self-hosted" >&2 - exit 1 - fi - - feature_meta: - needs: validate_inputs + retired: runs-on: ubuntu-24.04 - outputs: - run_linux: ${{ steps.meta.outputs.run_linux }} - run_macos: ${{ steps.meta.outputs.run_macos }} - run_windows: ${{ steps.meta.outputs.run_windows }} - steps: - - name: Checkout repository (override ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - - - name: Checkout repository - if: inputs.checkout_ref == '' - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Compute selected platforms - id: meta - shell: bash - run: | - set -euo pipefail - - selection="${{ inputs.platform }}" - feature_dir="${{ inputs.feature_dir }}" - tasks_json="${feature_dir}/tasks.json" - - run_linux=0 - run_macos=0 - run_windows=0 - - case "${selection}" in - all) - run_linux=1 - run_macos=1 - run_windows=1 - ;; - linux) run_linux=1 ;; - macos) run_macos=1 ;; - windows) run_windows=1 ;; - wsl) : ;; # WSL handled by dedicated job condition. - behavior) - if [[ ! -f "${tasks_json}" ]]; then - echo "ERROR: missing ${tasks_json} (required for platform=behavior)" >&2 - exit 1 - fi - if ! command -v jq >/dev/null 2>&1; then - sudo apt-get update - sudo apt-get install -y jq - fi - required="$(jq -r '.meta.behavior_platforms_required[]? // empty' "${tasks_json}")" - while IFS= read -r p; do - case "${p}" in - linux) run_linux=1 ;; - macos) run_macos=1 ;; - windows) run_windows=1 ;; - "" ) ;; - *) echo "WARN: ignoring unknown behavior platform in ${tasks_json}: ${p}" >&2 ;; - esac - done <<< "${required}" - ;; - *) - echo "ERROR: invalid platform selection: ${selection}" >&2 - exit 1 - ;; - esac - - echo "run_linux=${run_linux}" >> "$GITHUB_OUTPUT" - echo "run_macos=${run_macos}" >> "$GITHUB_OUTPUT" - echo "run_windows=${run_windows}" >> "$GITHUB_OUTPUT" - - linux_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_linux == '1' && inputs.runner_kind == 'github-hosted' - runs-on: ubuntu-24.04 - steps: - - name: Checkout repository (override ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - - - name: Checkout repository - if: inputs.checkout_ref == '' - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Install system dependencies - run: | - sudo apt-get update - sudo apt-get install -y jq ripgrep pkg-config libseccomp-dev - - - name: Enable unprivileged user namespaces - run: | - sudo sysctl -w kernel.unprivileged_userns_clone=1 - sudo sysctl -w user.max_user_namespaces=28633 || true - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Run integration checks (Linux) - if: inputs.run_integ_checks - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate + world-service (debug) - run: | - cargo build --bin substrate --bin substrate-shim - cargo build -p world-service --bin world-service - - - name: Add substrate to PATH - run: echo "$GITHUB_WORKSPACE/target/debug" >> "$GITHUB_PATH" - - - name: Run linux smoke - shell: bash - run: | - set -euo pipefail - export SUBSTRATE_BIN="$GITHUB_WORKSPACE/target/debug/substrate" - export SUBSTRATE_WORLD_REQUEST_PROFILE="world-deps-provision" - - manual_sock="" - manual_log="" - agent_pid="" - cleanup() { - if [[ -n "${agent_pid}" ]]; then - kill "${agent_pid}" >/dev/null 2>&1 || true - wait "${agent_pid}" >/dev/null 2>&1 || true - fi - if [[ -n "${manual_sock}" ]]; then - rm -f "${manual_sock}" >/dev/null 2>&1 || true - fi - } - trap cleanup EXIT - - if [[ -S /run/substrate.sock && -w /run/substrate.sock ]]; then - export SUBSTRATE_WORLD_SOCKET="/run/substrate.sock" - else - socket_activate="$(command -v systemd-socket-activate || true)" - if [[ -z "${socket_activate}" ]]; then - echo "ERROR: systemd-socket-activate is required when /run/substrate.sock is unavailable" >&2 - exit 1 - fi - - manual_sock="${RUNNER_TEMP:-/tmp}/substrate-world-service.sock" - manual_log="${RUNNER_TEMP:-/tmp}/substrate-world-service.log" - rm -f "${manual_sock}" "${manual_log}" - - "${socket_activate}" --listen="${manual_sock}" --fdname=substrate-world-service "$GITHUB_WORKSPACE/target/debug/world-service" >"${manual_log}" 2>&1 & - agent_pid=$! - - for _ in $(seq 1 50); do - if [[ -S "${manual_sock}" ]]; then - break - fi - sleep 0.2 - done - - if [[ ! -S "${manual_sock}" ]]; then - echo "ERROR: failed to start user-scoped world-service socket fallback" >&2 - [[ -f "${manual_log}" ]] && cat "${manual_log}" >&2 - exit 1 - fi - - export SUBSTRATE_WORLD_SOCKET="${manual_sock}" - echo "Using user-scoped world-service socket fallback: ${manual_sock}" - fi - - feature_dir="${{ inputs.feature_dir }}" - smoke_script="${feature_dir}/smoke/linux-smoke.sh" - if [[ ! -f "${smoke_script}" ]]; then - feature_slug="$(basename "${feature_dir}")" - smoke_script="scripts/ci/feature-smoke/${feature_slug}/linux-smoke.sh" - fi - - if [[ ! -f "${smoke_script}" ]]; then - echo "ERROR: Linux smoke script not found for ${feature_dir}" >&2 - exit 1 - fi - - if ! bash "${smoke_script}"; then - [[ -n "${manual_log}" && -f "${manual_log}" ]] && cat "${manual_log}" >&2 - exit 1 - fi - - linux_self_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_linux == '1' && inputs.runner_kind == 'self-hosted' - runs-on: [self-hosted, Linux, linux-host] - steps: - - name: Checkout repository (workflow ref) - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Checkout repository (candidate ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - path: candidate - - - name: Select build checkout - id: checkout_dir - shell: bash - run: | - set -euo pipefail - if [[ -d "$GITHUB_WORKSPACE/candidate" ]]; then - echo "dir=candidate" >> "$GITHUB_OUTPUT" - else - echo "dir=." >> "$GITHUB_OUTPUT" - fi - - - name: Provision world-service (Linux self-hosted; WAPS) - if: startsWith(inputs.feature_dir, 'docs/project_management/packs/draft/world-deps-apt-provisioning') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/next/world-sync') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/world-service-policy-snapshot') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/full-isolation-landlock-overlayfs-compat') - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - set -euo pipefail - if [[ -S /run/substrate.sock && -w /run/substrate.sock ]]; then - echo "Using existing system world-service socket" - elif sudo -n true >/dev/null 2>&1; then - cargo build -p world-service --release - scripts/linux/world-provision.sh --profile release --skip-build --sudo-noninteractive - else - echo "WARN: sudo -n unavailable on this runner; smoke will fall back to a user-scoped socket if needed" >&2 - fi - - - name: Preflight substrate world socket (Linux self-hosted) - shell: bash - run: | - set -euo pipefail - sock="/run/substrate.sock" - - if [[ -S "${sock}" && -w "${sock}" ]]; then - exit 0 - fi - - echo "WARN: system world-service socket unavailable; smoke will try a user-scoped socket fallback" >&2 - if [[ -e "${sock}" ]]; then - ls -l "${sock}" >&2 || true - stat "${sock}" >&2 || true - fi - echo " id: $(id -a || true)" >&2 - - - name: Ensure rustup is on PATH (Linux self-hosted) - shell: bash - run: | - set -euo pipefail - export PATH="$HOME/.cargo/bin:$PATH" - echo "$HOME/.cargo/bin" >> "$GITHUB_PATH" - - if command -v rustup >/dev/null 2>&1; then - rustup --version - exit 0 - fi - - echo "ERROR: rustup is required on self-hosted runners but was not found." >&2 - echo "Fix runner provisioning so the runner service PATH includes rustup (usually: $HOME/.cargo/bin)." >&2 - echo "If the runner is installed under /opt/actions-runner, update /opt/actions-runner/.path to prepend $HOME/.cargo/bin and restart the runner service." >&2 - echo "Current PATH: $PATH" >&2 - exit 1 - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Preflight native deps (Linux) - run: | - if ! command -v pkg-config >/dev/null 2>&1; then - echo "Missing pkg-config. Install it (e.g., pkgconf/pkg-config) on this runner." >&2 - exit 1 - fi - if ! pkg-config --exists libseccomp; then - echo "Missing libseccomp development package on this runner." >&2 - echo " - Ubuntu/Debian: sudo apt-get install -y libseccomp-dev pkg-config" >&2 - echo " - Manjaro/Arch: sudo pacman -Syu --needed libseccomp pkgconf" >&2 - exit 1 - fi - - - name: Run integration checks (Linux self-hosted) - if: inputs.run_integ_checks - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate + world-service (debug) - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - cargo build --bin substrate --bin substrate-shim - cargo build -p world-service --bin world-service - - - name: Add substrate to PATH - shell: bash - run: | - set -euo pipefail - dir="${{ steps.checkout_dir.outputs.dir }}" - if [[ "${dir}" == "candidate" ]]; then - echo "$GITHUB_WORKSPACE/candidate/target/debug" >> "$GITHUB_PATH" - else - echo "$GITHUB_WORKSPACE/target/debug" >> "$GITHUB_PATH" - fi - - - name: Run linux smoke - working-directory: ${{ steps.checkout_dir.outputs.dir }} - shell: bash - run: | - set -euo pipefail - export SUBSTRATE_BIN="$PWD/target/debug/substrate" - export SUBSTRATE_WORLD_REQUEST_PROFILE="world-deps-provision" - - manual_sock="" - manual_log="" - agent_pid="" - cleanup() { - if [[ -n "${agent_pid}" ]]; then - kill "${agent_pid}" >/dev/null 2>&1 || true - wait "${agent_pid}" >/dev/null 2>&1 || true - fi - if [[ -n "${manual_sock}" ]]; then - rm -f "${manual_sock}" >/dev/null 2>&1 || true - fi - } - trap cleanup EXIT - - if [[ -S /run/substrate.sock && -w /run/substrate.sock ]]; then - export SUBSTRATE_WORLD_SOCKET="/run/substrate.sock" - else - socket_activate="$(command -v systemd-socket-activate || true)" - if [[ -z "${socket_activate}" ]]; then - echo "ERROR: systemd-socket-activate is required when /run/substrate.sock is unavailable" >&2 - exit 1 - fi - - manual_sock="${RUNNER_TEMP:-/tmp}/substrate-world-service.sock" - manual_log="${RUNNER_TEMP:-/tmp}/substrate-world-service.log" - rm -f "${manual_sock}" "${manual_log}" - - "${socket_activate}" --listen="${manual_sock}" --fdname=substrate-world-service "$PWD/target/debug/world-service" >"${manual_log}" 2>&1 & - agent_pid=$! - - for _ in $(seq 1 50); do - if [[ -S "${manual_sock}" ]]; then - break - fi - sleep 0.2 - done - - if [[ ! -S "${manual_sock}" ]]; then - echo "ERROR: failed to start user-scoped world-service socket fallback" >&2 - [[ -f "${manual_log}" ]] && cat "${manual_log}" >&2 - exit 1 - fi - - export SUBSTRATE_WORLD_SOCKET="${manual_sock}" - echo "Using user-scoped world-service socket fallback: ${manual_sock}" - fi - - feature_dir="${{ inputs.feature_dir }}" - smoke_script="${feature_dir}/smoke/linux-smoke.sh" - if [[ ! -f "${smoke_script}" ]]; then - feature_slug="$(basename "${feature_dir}")" - smoke_script="scripts/ci/feature-smoke/${feature_slug}/linux-smoke.sh" - fi - - if [[ ! -f "${smoke_script}" ]]; then - echo "ERROR: Linux smoke script not found for ${feature_dir}" >&2 - exit 1 - fi - - if ! bash "${smoke_script}"; then - [[ -n "${manual_log}" && -f "${manual_log}" ]] && cat "${manual_log}" >&2 - exit 1 - fi - - macos_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_macos == '1' && (inputs.runner_kind == 'github-hosted' || (inputs.runner_kind == 'self-hosted' && inputs.macos_runner_kind == 'github-hosted')) - runs-on: macos-14 - steps: - - name: Checkout repository (override ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - - - name: Checkout repository - if: inputs.checkout_ref == '' - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Install system dependencies - run: | - brew update - if ! command -v jq >/dev/null 2>&1; then brew install jq; fi - if ! command -v rg >/dev/null 2>&1; then brew install ripgrep; fi - if ! command -v limactl >/dev/null 2>&1; then brew install lima; fi - if ! command -v envsubst >/dev/null 2>&1; then brew install gettext; fi - - # Prefer Homebrew gettext/envsubst and Lima on PATH for subsequent steps. - if command -v brew >/dev/null 2>&1; then - echo \"$(brew --prefix gettext)/bin\" >> \"$GITHUB_PATH\" || true - echo \"$(brew --prefix lima)/bin\" >> \"$GITHUB_PATH\" || true - fi - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Run integration checks (macOS) - if: inputs.run_integ_checks - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate (debug) - run: cargo build --bin substrate --bin substrate-shim - - - name: Add substrate to PATH - run: echo "$GITHUB_WORKSPACE/target/debug" >> "$GITHUB_PATH" - - - name: Run macOS smoke - shell: bash - run: | - set -euo pipefail - export SUBSTRATE_BIN="$GITHUB_WORKSPACE/target/debug/substrate" - - feature_dir="${{ inputs.feature_dir }}" - smoke_script="${feature_dir}/smoke/macos-smoke.sh" - if [[ ! -f "${smoke_script}" ]]; then - feature_slug="$(basename "${feature_dir}")" - smoke_script="scripts/ci/feature-smoke/${feature_slug}/macos-smoke.sh" - fi - - if [[ ! -f "${smoke_script}" ]]; then - echo "ERROR: macOS smoke script not found for ${feature_dir}" >&2 - exit 1 - fi - - bash "${smoke_script}" - - macos_self_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_macos == '1' && inputs.runner_kind == 'self-hosted' && inputs.macos_runner_kind != 'github-hosted' - runs-on: [self-hosted, macOS] - env: - CARGO_BUILD_JOBS: 2 - RUST_TEST_THREADS: 1 steps: - - name: Checkout repository (workflow ref) - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Checkout repository (candidate ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - path: candidate - - - name: Select build checkout - id: checkout_dir + - name: Report retirement shell: bash run: | - set -euo pipefail - if [[ -d "$GITHUB_WORKSPACE/candidate" ]]; then - echo "dir=candidate" >> "$GITHUB_OUTPUT" - else - echo "dir=." >> "$GITHUB_OUTPUT" - fi - - - name: Prevent sleep (macOS self-hosted) - run: caffeinate -dimsu & - - - name: Warm Lima world (macOS self-hosted; WAPS) - if: startsWith(inputs.feature_dir, 'docs/project_management/packs/draft/world-deps-apt-provisioning') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/next/world-sync') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/world-service-policy-snapshot') || startsWith(inputs.feature_dir, 'docs/project_management/_archived/full-isolation-landlock-overlayfs-compat') - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: bash scripts/mac/lima-warm.sh "$PWD" - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Run integration checks (macOS self-hosted) - if: inputs.run_integ_checks - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate (debug) - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: cargo build --bin substrate --bin substrate-shim - - - name: Add substrate to PATH - shell: bash - run: | - set -euo pipefail - dir="${{ steps.checkout_dir.outputs.dir }}" - if [[ "${dir}" == "candidate" ]]; then - echo "$GITHUB_WORKSPACE/candidate/target/debug" >> "$GITHUB_PATH" - else - echo "$GITHUB_WORKSPACE/target/debug" >> "$GITHUB_PATH" - fi - - - name: Run macOS smoke - working-directory: ${{ steps.checkout_dir.outputs.dir }} - shell: bash - run: | - set -euo pipefail - export SUBSTRATE_BIN="$PWD/target/debug/substrate" - - feature_dir="${{ inputs.feature_dir }}" - smoke_script="${feature_dir}/smoke/macos-smoke.sh" - if [[ ! -f "${smoke_script}" ]]; then - feature_slug="$(basename "${feature_dir}")" - smoke_script="scripts/ci/feature-smoke/${feature_slug}/macos-smoke.sh" - fi - - if [[ ! -f "${smoke_script}" ]]; then - echo "ERROR: macOS smoke script not found for ${feature_dir}" >&2 - exit 1 - fi - - bash "${smoke_script}" - - windows_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_windows == '1' && inputs.runner_kind == 'github-hosted' - runs-on: windows-2022 - steps: - - name: Enable Windows longpaths - run: git config --global core.longpaths true - - - name: Checkout repository (override ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - - - name: Checkout repository - if: inputs.checkout_ref == '' - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Run integration checks (Windows) - if: inputs.run_integ_checks - shell: pwsh - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate (debug) - run: cargo build --bin substrate --bin substrate-shim - - - name: Add substrate to PATH - shell: pwsh - run: Add-Content -LiteralPath $env:GITHUB_PATH -Value "$pwd\\target\\debug" - - - name: Run Windows smoke - shell: pwsh - env: - SUBSTRATE_NO_SHIMS: "1" - SUBSTRATE_EXE: ${{ github.workspace }}\target\debug\substrate.exe - run: pwsh -File "${{ inputs.feature_dir }}/smoke/windows-smoke.ps1" - - windows_self_hosted: - needs: feature_meta - if: needs.feature_meta.outputs.run_windows == '1' && inputs.runner_kind == 'self-hosted' - runs-on: [self-hosted, Windows] - steps: - - name: Enable Windows longpaths - run: git config --global core.longpaths true - - - name: Checkout repository (workflow ref) - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Checkout repository (candidate ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - path: candidate - - - name: Select build checkout - id: checkout_dir - shell: pwsh - run: | - if (Test-Path (Join-Path $env:GITHUB_WORKSPACE "candidate")) { - "dir=candidate" >> $env:GITHUB_OUTPUT - } else { - "dir=." >> $env:GITHUB_OUTPUT - } - - - name: Ensure Rust toolchain (self-hosted) - shell: pwsh - run: | - if (-not (Get-Command rustup -ErrorAction SilentlyContinue)) { - Write-Host "rustup not found; installing rustup for the runner user..." - $rustupInit = Join-Path $env:RUNNER_TEMP "rustup-init.exe" - Invoke-WebRequest -Uri "https://static.rust-lang.org/rustup/dist/x86_64-pc-windows-msvc/rustup-init.exe" -OutFile $rustupInit - & $rustupInit -y --profile minimal --default-toolchain $env:RUST_TOOLCHAIN - } - - $cargoBin = Join-Path $env:USERPROFILE ".cargo\\bin" - if (Test-Path $cargoBin) { - $env:Path = "$cargoBin;$env:Path" - Add-Content -LiteralPath $env:GITHUB_PATH -Value $cargoBin - } - - $rustupExe = Join-Path $cargoBin "rustup.exe" - if (-not (Test-Path $rustupExe)) { - throw "rustup.exe not found at expected path: $rustupExe" - } - - & $rustupExe toolchain install $env:RUST_TOOLCHAIN --profile minimal - & $rustupExe component add rustfmt clippy --toolchain $env:RUST_TOOLCHAIN - rustc --version - cargo --version - - - name: Run integration checks (Windows self-hosted) - if: inputs.run_integ_checks - shell: pwsh - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Warm WSL world (Windows self-hosted; WAPS) - if: startsWith(inputs.feature_dir, 'docs/project_management/_archived/world-service-policy-snapshot') - shell: pwsh - env: - # The Windows WSL backend is expected to use the named pipe forwarder; disable the TCP bridge - # even if the runner machine has SUBSTRATE_FORWARDER_TCP=1 set globally. - SUBSTRATE_FORWARDER_TCP: "0" - run: pwsh -File scripts/windows/wsl-warm.ps1 -DistroName substrate-wsl -ProjectPath (Resolve-Path .) - - - name: Build substrate (debug) - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: cargo build --bin substrate --bin substrate-shim - - - name: Add substrate to PATH - shell: pwsh - run: | - $dir = "${{ steps.checkout_dir.outputs.dir }}" - if ($dir -eq "candidate") { - Add-Content -LiteralPath $env:GITHUB_PATH -Value "$env:GITHUB_WORKSPACE\\candidate\\target\\debug" - } else { - Add-Content -LiteralPath $env:GITHUB_PATH -Value "$env:GITHUB_WORKSPACE\\target\\debug" - } - - - name: Run Windows smoke - shell: pwsh - working-directory: ${{ steps.checkout_dir.outputs.dir }} - env: - # Force pipe transport regardless of runner-global environment. - SUBSTRATE_FORWARDER_TCP: "0" - SUBSTRATE_NO_SHIMS: "1" - run: | - $cargoCmd = Get-Command cargo -ErrorAction Stop - $env:SUBSTRATE_WINDOWS_CARGO_EXE = $cargoCmd.Path - if ("${{ steps.checkout_dir.outputs.dir }}" -eq "candidate") { - $env:SUBSTRATE_EXE = "$env:GITHUB_WORKSPACE\\candidate\\target\\debug\\substrate.exe" - } else { - $env:SUBSTRATE_EXE = "$env:GITHUB_WORKSPACE\\target\\debug\\substrate.exe" - } - pwsh -File "$env:GITHUB_WORKSPACE\\${{ inputs.feature_dir }}\\smoke\\windows-smoke.ps1" - - wsl: - needs: validate_inputs - if: inputs.runner_kind == 'self-hosted' && (inputs.run_wsl || inputs.platform == 'wsl') - runs-on: [self-hosted, Linux, wsl] - steps: - - name: Checkout repository (workflow ref) - uses: actions/checkout@v5 - with: - submodules: recursive - - - name: Checkout repository (candidate ref) - if: inputs.checkout_ref != '' - uses: actions/checkout@v5 - with: - ref: ${{ inputs.checkout_ref }} - submodules: recursive - path: candidate - - - name: Select build checkout - id: checkout_dir - shell: bash - run: | - set -euo pipefail - if [[ -d "$GITHUB_WORKSPACE/candidate" ]]; then - echo "dir=candidate" >> "$GITHUB_OUTPUT" - else - echo "dir=." >> "$GITHUB_OUTPUT" - fi - - - name: Preflight substrate world socket (WSL runner) - shell: bash - run: | - set -euo pipefail - sock="/run/substrate.sock" - - if [[ ! -S "${sock}" ]]; then - echo "SUBSTRATE_RUNNER_MISPROVISIONED=1" - echo "SUBSTRATE_RUNNER_MISPROVISIONED_REASON=substrate_sock_missing" - echo "WSL runner is missing required world-service socket: ${sock}" >&2 - echo "Remediation: provision the world agent + ensure the runner user can access ${sock} (root:substrate 0660)." >&2 - echo "Diagnostics: id=$(id -a || true)" >&2 - exit 1 - fi - - if [[ ! -w "${sock}" ]]; then - echo "SUBSTRATE_RUNNER_MISPROVISIONED=1" - echo "SUBSTRATE_RUNNER_MISPROVISIONED_REASON=substrate_sock_permission_denied" - echo "WSL runner cannot access required world-service socket: ${sock} (need write permission to connect)" >&2 - echo "Remediation: ensure runner user is in substrate group + restart runner service; confirm ${sock} is root:substrate 0660." >&2 - ls -l "${sock}" >&2 || true - stat "${sock}" >&2 || true - echo "Diagnostics: id=$(id -a || true)" >&2 - exit 1 - fi - - - name: Ensure rustup is on PATH (WSL runner) - shell: bash - run: | - set -euo pipefail - export PATH="$HOME/.cargo/bin:$PATH" - echo "$HOME/.cargo/bin" >> "$GITHUB_PATH" - - if command -v rustup >/dev/null 2>&1; then - rustup --version - exit 0 - fi - - echo "ERROR: rustup is required on self-hosted runners but was not found." >&2 - echo "Fix runner provisioning so the runner service PATH includes rustup (usually: $HOME/.cargo/bin)." >&2 - echo "If the runner is installed under /opt/actions-runner, update /opt/actions-runner/.path to prepend $HOME/.cargo/bin and restart the runner service." >&2 - echo "Current PATH: $PATH" >&2 + echo "ERROR: feature-smoke automation was retired with project-management pack automation." >&2 + echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 exit 1 - - - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable - with: - toolchain: ${{ env.RUST_TOOLCHAIN }} - components: rustfmt, clippy - - - name: Preflight native deps (WSL runner) - run: | - if ! command -v pkg-config >/dev/null 2>&1; then - echo "Missing pkg-config. Install it on this runner." >&2 - exit 1 - fi - if ! pkg-config --exists libseccomp; then - echo "Missing libseccomp development package on this runner." >&2 - exit 1 - fi - - - name: Run integration checks (WSL runner) - if: inputs.run_integ_checks - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: | - cargo fmt --all -- --check - cargo clippy --workspace --all-targets -- -D warnings - cargo test --workspace --all-targets - - - name: Build substrate (debug) - working-directory: ${{ steps.checkout_dir.outputs.dir }} - run: cargo build --bin substrate --bin substrate-shim - - - name: Add substrate to PATH - shell: bash - run: | - set -euo pipefail - dir="${{ steps.checkout_dir.outputs.dir }}" - if [[ "${dir}" == "candidate" ]]; then - echo "$GITHUB_WORKSPACE/candidate/target/debug" >> "$GITHUB_PATH" - else - echo "$GITHUB_WORKSPACE/target/debug" >> "$GITHUB_PATH" - fi - - - name: Run WSL (Linux) smoke - shell: bash - run: | - set -euo pipefail - dir="${{ steps.checkout_dir.outputs.dir }}" - if [[ "${dir}" == "candidate" ]]; then - export SUBSTRATE_BIN="$GITHUB_WORKSPACE/candidate/target/debug/substrate" - else - export SUBSTRATE_BIN="$GITHUB_WORKSPACE/target/debug/substrate" - fi - export SUBSTRATE_WORLD_REQUEST_PROFILE="world-deps-provision" - bash "${{ inputs.feature_dir }}/smoke/linux-smoke.sh" diff --git a/Makefile b/Makefile index 6c85eb284..6b02c4a4d 100644 --- a/Makefile +++ b/Makefile @@ -140,10 +140,9 @@ pre-ci: PM_SYSTEM_SCRIPTS := docs/project_management/system/scripts FSE_SYSTEM_SCRIPTS := docs/project_management/system/fse/scripts -# Feature directory under docs/project_management/packs// +# Compatibility vars kept for retired planning automation entrypoints. FEATURE_DIR ?= -# Space-separated list of pack-relative paths to scan (scoped lint for planning agents) OWNED_PATHS ?= # Planning agent id for pm-run-planning-agent @@ -156,7 +155,6 @@ PWS_ID ?= START_AT ?= POLL_S ?= 60 -# ADR path under docs/project_management/adrs//... ADR ?= CODEX_PROFILE ?= @@ -167,138 +165,6 @@ PROVING_RUN_FACTS ?= PROVING_RUN_HUMAN_INPUTS ?= PROVING_RUN_CLOSEOUT_OUTPUT ?= proving-run-closeout.json -.PHONY: planning-validate -planning-validate: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - python3 $(PM_SYSTEM_SCRIPTS)/planning/validate_tasks_json.py --feature-dir "$(FEATURE_DIR)" - -.PHONY: planning-lint -planning-lint: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - $(PM_SYSTEM_SCRIPTS)/planning/lint.sh --feature-dir "$(FEATURE_DIR)" - -.PHONY: planning-micro-lint -planning-micro-lint: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(OWNED_PATHS)" ]; then echo "ERROR: set OWNED_PATHS=\"\""; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/micro_lint.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(AGENT)" ]; then cmd="$$cmd --agent \"$(AGENT)\""; fi; \ - cmd="$$cmd -- $(OWNED_PATHS)"; \ - eval "$$cmd" - -.PHONY: pm-pws-plan -pm-pws-plan: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @python3 $(PM_SYSTEM_SCRIPTS)/planning/pm_pws_plan.py --feature-dir "$(FEATURE_DIR)" - -.PHONY: pm-run-pws -pm-run-pws: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(PWS_ID)" ]; then echo "ERROR: set PWS_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/run_pws_agent.sh --feature-dir \"$(FEATURE_DIR)\" --pws-id \"$(PWS_ID)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-full-planning-orchestrate -pm-full-planning-orchestrate: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/full_planning_orchestrate.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-pre-full-planning-converge -pm-pre-full-planning-converge: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/pre_full_planning_converge.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-post-full-planning-converge -pm-post-full-planning-converge: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/post_full_planning_converge.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-planning-pipeline -pm-planning-pipeline: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/planning_pipeline_orchestrate.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(START_AT)" ]; then cmd="$$cmd --start-at \"$(START_AT)\""; fi; \ - if [ -n "$(POLL_S)" ]; then cmd="$$cmd --poll-s \"$(POLL_S)\""; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-run-planning-agent -pm-run-planning-agent: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(AGENT)" ]; then echo "ERROR: set AGENT=spec_manifest|impact_map|min_spec_draft|ci_checkpoint|workstream_triage"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/run_planning_agent.sh --feature-dir \"$(FEATURE_DIR)\" --agent \"$(AGENT)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - eval "$$cmd" - -.PHONY: pm-pre-planning-research -pm-pre-planning-research: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/pre_planning_research_orchestrate.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(START_AT)" ]; then cmd="$$cmd --start-at \"$(START_AT)\""; fi; \ - if [ -n "$(POLL_S)" ]; then cmd="$$cmd --poll-s \"$(POLL_S)\""; fi; \ - CODEX_PROFILE="$(CODEX_PROFILE)" CODEX_MODEL="$(CODEX_MODEL)" CODEX_JSONL="$(CODEX_JSONL)" eval "$$cmd" - -.PHONY: pm-pre-planning-from-adr -pm-pre-planning-from-adr: - @if [ -z "$(ADR)" ]; then echo "ERROR: set ADR=docs/project_management/adrs//ADR-XXXX-....md"; exit 2; fi - @set -euo pipefail; \ - if [ -n "$$(git status --porcelain=v1)" ]; then echo "ERROR: orchestration checkout is dirty; commit or stash before running"; exit 2; fi; \ - bucket="$(BUCKET)"; \ - if [ -z "$$bucket" ]; then bucket="$${PM_DEFAULT_PACK_BUCKET:-}"; fi; \ - if [ -z "$$bucket" ]; then bucket="draft"; fi; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/scaffold_pre_planning_pack.sh --adr \"$(ADR)\" --bucket \"$$bucket\""; \ - if [ -n "$(FEATURE)" ]; then cmd="$$cmd --feature \"$(FEATURE)\""; fi; \ - feature_dir="$$(eval "$$cmd")"; \ - if [ -z "$$feature_dir" ]; then echo "ERROR: scaffold_pre_planning_pack.sh returned empty feature dir"; exit 2; fi; \ - tasks_path="$$feature_dir/tasks.json"; \ - if [ -n "$$(git status --porcelain=v1 -- "$$tasks_path")" ]; then \ - git add -- "$$tasks_path"; \ - if ! git diff --cached --quiet; then git commit -m "docs: bootstrap pre-planning pack"; fi; \ - fi; \ - if [ "$(RUN_PIPELINE)" = "1" ]; then \ - $(MAKE) pm-planning-pipeline FEATURE_DIR="$$feature_dir" START_AT="$(START_AT)" POLL_S="$(POLL_S)" CODEX_PROFILE="$(CODEX_PROFILE)" CODEX_MODEL="$(CODEX_MODEL)" CODEX_JSONL="$(CODEX_JSONL)"; \ - else \ - $(MAKE) pm-pre-planning-research FEATURE_DIR="$$feature_dir" START_AT="$(START_AT)" POLL_S="$(POLL_S)" CODEX_PROFILE="$(CODEX_PROFILE)" CODEX_MODEL="$(CODEX_MODEL)" CODEX_JSONL="$(CODEX_JSONL)"; \ - fi - .PHONY: pm-prepare-proving-run-closeout pm-prepare-proving-run-closeout: @if [ -z "$(PROVING_RUN_FACTS)" ]; then echo "ERROR: set PROVING_RUN_FACTS="; exit 2; fi @@ -307,34 +173,10 @@ pm-prepare-proving-run-closeout: if [ -n "$(PROVING_RUN_HUMAN_INPUTS)" ]; then cmd="$$cmd --human-inputs \"$(PROVING_RUN_HUMAN_INPUTS)\""; fi; \ eval "$$cmd" -.PHONY: pm-fse-pre-planning-from-adr -pm-fse-pre-planning-from-adr: - @if [ -z "$(ADR)" ]; then echo "ERROR: set ADR=docs/project_management/adrs//ADR-XXXX-....md"; exit 2; fi - @set -euo pipefail; \ - if [ -n "$$(git status --porcelain=v1)" ]; then echo "ERROR: orchestration checkout is dirty; commit or stash before running"; exit 2; fi; \ - bucket="$(BUCKET)"; \ - if [ -z "$$bucket" ]; then bucket="$${PM_DEFAULT_PACK_BUCKET:-}"; fi; \ - if [ -z "$$bucket" ]; then bucket="draft"; fi; \ - cmd="$(FSE_SYSTEM_SCRIPTS)/planning/scaffold_pre_planning_pack.sh --adr \"$(ADR)\" --bucket \"$$bucket\""; \ - if [ -n "$(FEATURE)" ]; then cmd="$$cmd --feature \"$(FEATURE)\""; fi; \ - feature_dir="$$(eval "$$cmd")"; \ - if [ -z "$$feature_dir" ]; then echo "ERROR: scaffold_pre_planning_pack.sh returned empty feature dir"; exit 2; fi; \ - fse_metadata_path="$$feature_dir/fse_pre_planning.json"; \ - if [ -n "$$(git status --porcelain=v1 -- "$$fse_metadata_path")" ]; then \ - git add -- "$$fse_metadata_path"; \ - if ! git diff --cached --quiet; then git commit -m "docs: bootstrap fse pre-planning pack"; fi; \ - fi; \ - cmd="$(FSE_SYSTEM_SCRIPTS)/planning/pre_planning_research_orchestrate.sh --feature-dir \"$$feature_dir\""; \ - if [ -n "$(START_AT)" ]; then cmd="$$cmd --start-at \"$(START_AT)\""; fi; \ - if [ -n "$(POLL_S)" ]; then cmd="$$cmd --poll-s \"$(POLL_S)\""; fi; \ - CODEX_PROFILE="$(CODEX_PROFILE)" CODEX_MODEL="$(CODEX_MODEL)" CODEX_JSONL="$(CODEX_JSONL)" eval "$$cmd" - -.PHONY: planning-lint-ps -planning-lint-ps: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if ! command -v pwsh >/dev/null 2>&1; then echo "ERROR: pwsh not found on PATH"; exit 2; fi - pwsh -File $(PM_SYSTEM_SCRIPTS)/planning/lint.ps1 -FeatureDir "$(FEATURE_DIR)" +.PHONY: planning-validate planning-lint planning-micro-lint pm-pws-plan pm-run-pws pm-full-planning-orchestrate pm-pre-full-planning-converge pm-post-full-planning-converge pm-planning-pipeline pm-run-planning-agent pm-pre-planning-research pm-pre-planning-from-adr pm-fse-pre-planning-from-adr planning-lint-ps +planning-validate planning-lint planning-micro-lint pm-pws-plan pm-run-pws pm-full-planning-orchestrate pm-pre-full-planning-converge pm-post-full-planning-converge pm-planning-pipeline pm-run-planning-agent pm-pre-planning-research pm-pre-planning-from-adr pm-fse-pre-planning-from-adr planning-lint-ps: + @echo "ERROR: target '$@' was retired with project-management pack automation. See docs/PROJECT_MANAGEMENT_RETIREMENT.md." >&2 + @exit 2 .PHONY: adr-check adr-check: @@ -358,14 +200,8 @@ pm-lift-intake: .PHONY: pm-lift-pack pm-lift-pack: - @if [ -z "$(PACK)" ]; then echo "ERROR: set PACK=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(PACK)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: PACK must be under docs/project_management/packs//"; exit 2; fi - @set -euo pipefail; \ - if [ "$(EMIT_JSON)" = "1" ]; then \ - python3 $(PM_SYSTEM_SCRIPTS)/planning/pm_lift.py from-impact-map --feature-dir "$(PACK)" --emit-json; \ - else \ - python3 $(PM_SYSTEM_SCRIPTS)/planning/pm_lift.py from-impact-map --feature-dir "$(PACK)"; \ - fi + @echo "ERROR: target '$@' was retired with project-management pack automation. See docs/PROJECT_MANAGEMENT_RETIREMENT.md." >&2 + @exit 2 .PHONY: pm-lift-diff pm-lift-diff: @@ -379,15 +215,8 @@ pm-lift-diff: .PHONY: pm-lift-strict pm-lift-strict: - @if [ -n "$(FILE)" ] && [ -n "$(PACK)" ]; then echo "ERROR: set only one of FILE or PACK"; exit 2; fi - @if [ -z "$(FILE)" ] && [ -z "$(PACK)" ]; then echo "ERROR: set FILE= or PACK=docs/project_management/packs//"; exit 2; fi - @if [ -n "$(PACK)" ] && ! echo "$(PACK)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: PACK must be under docs/project_management/packs//"; exit 2; fi - @set -euo pipefail; \ - if [ -n "$(FILE)" ]; then \ - PM_LIFT_STRICT=1 python3 $(PM_SYSTEM_SCRIPTS)/planning/pm_lift_strict_check.py --intake "$(FILE)"; \ - else \ - PM_LIFT_STRICT=1 python3 $(PM_SYSTEM_SCRIPTS)/planning/pm_lift_strict_check.py --feature-dir "$(PACK)"; \ - fi + @echo "ERROR: target '$@' was retired with project-management pack automation. See docs/PROJECT_MANAGEMENT_RETIREMENT.md." >&2 + @exit 2 # ========================= # Cross-platform smoke (CI) @@ -422,53 +251,19 @@ ci-compile-parity: installers-container-smoke: @bash tests/installers/pkg_manager_container_smoke.sh -# Dispatch defaults (override as needed) +# Retired pack automation compatibility entrypoints. PLATFORM ?= linux - RUNNER_KIND ?= self-hosted - MACOS_RUNNER_KIND ?= - RUN_WSL ?= 0 - RUN_INTEG_CHECKS ?= 0 - SMOKE_SLICE_ID ?= - SMOKE_CHECKOUT_REF ?= - WORKFLOW ?= .github/workflows/feature-smoke.yml +RUNNER_KIND ?= self-hosted +MACOS_RUNNER_KIND ?= +RUN_WSL ?= 0 +RUN_INTEG_CHECKS ?= 0 +SMOKE_SLICE_ID ?= +SMOKE_CHECKOUT_REF ?= +WORKFLOW ?= WORKFLOW_REF ?= $(CURRENT_REF) REMOTE ?= origin CLEANUP ?= 1 -.PHONY: feature-smoke -feature-smoke: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(WORKFLOW_REF)" ]; then echo "ERROR: set WORKFLOW_REF= (ref must not be main/testing; use the orchestration/task ref)"; exit 2; fi - @if [ "$(PLATFORM)" = "wsl" ] && [ "$(RUNNER_KIND)" != "self-hosted" ]; then echo "ERROR: PLATFORM=wsl requires RUNNER_KIND=self-hosted"; exit 2; fi - @if [ "$(RUN_WSL)" = "1" ] && [ "$(RUNNER_KIND)" != "self-hosted" ]; then echo "ERROR: RUN_WSL=1 requires RUNNER_KIND=self-hosted"; exit 2; fi - @set -euo pipefail; \ - args="--feature-dir \"$(FEATURE_DIR)\" --runner-kind $(RUNNER_KIND) --platform $(PLATFORM) --workflow \"$(WORKFLOW)\" --workflow-ref \"$(WORKFLOW_REF)\" --remote \"$(REMOTE)\""; \ - if [ -n "$(MACOS_RUNNER_KIND)" ]; then args="$$args --macos-runner-kind $(MACOS_RUNNER_KIND)"; fi; \ - if [ "$(RUN_WSL)" = "1" ]; then args="$$args --run-wsl"; fi; \ - if [ "$(RUN_INTEG_CHECKS)" = "1" ]; then args="$$args --run-integ-checks"; fi; \ - if [ -n "$(SMOKE_CHECKOUT_REF)" ]; then args="$$args --checkout-ref \"$(SMOKE_CHECKOUT_REF)\""; fi; \ - if [ -n "$(SMOKE_SLICE_ID)" ]; then args="$$args --smoke-slice-id \"$(SMOKE_SLICE_ID)\""; fi; \ - if [ "$(CLEANUP)" = "1" ]; then args="$$args --cleanup"; fi; \ - eval "scripts/ci/dispatch_feature_smoke.sh $$args" - -.PHONY: feature-smoke-all -feature-smoke-all: - @$(MAKE) feature-smoke PLATFORM=all - -.PHONY: feature-smoke-behavior -feature-smoke-behavior: - @$(MAKE) feature-smoke PLATFORM=behavior - -.PHONY: feature-smoke-wsl -feature-smoke-wsl: - @$(MAKE) feature-smoke PLATFORM=wsl RUN_WSL=0 RUNNER_KIND=self-hosted - -# ========================= -# Planning pack scaffolding -# ========================= - -# New feature directory name under docs/project_management/packs// FEATURE ?= PACK_BUCKET ?= DECISION_HEAVY ?= 0 @@ -480,58 +275,6 @@ BEHAVIOR_PLATFORMS ?= CI_PARITY_PLATFORMS ?= SLICE_PREFIX ?= -.PHONY: planning-new-feature -planning-new-feature: - @if [ -z "$(FEATURE)" ]; then echo "ERROR: set FEATURE="; exit 2; fi - @set -euo pipefail; \ - bucket="$(PACK_BUCKET)"; \ - if [ -z "$$bucket" ]; then bucket="$${PM_DEFAULT_PACK_BUCKET:-}"; fi; \ - if [ -z "$$bucket" ]; then bucket="active"; fi; \ - cmd="$(PM_SYSTEM_SCRIPTS)/planning/new_feature.sh --feature \"$(FEATURE)\" --bucket \"$$bucket\""; \ - if [ -n "$(SLICE_PREFIX)" ]; then cmd="$$cmd --slice-prefix \"$(SLICE_PREFIX)\""; fi; \ - if [ "$(DECISION_HEAVY)" = "1" ]; then cmd="$$cmd --decision-heavy"; fi; \ - if [ "$(CROSS_PLATFORM)" = "1" ]; then cmd="$$cmd --cross-platform"; fi; \ - if [ -n "$(BEHAVIOR_PLATFORMS)" ]; then cmd="$$cmd --behavior-platforms \"$(BEHAVIOR_PLATFORMS)\""; fi; \ - if [ -n "$(CI_PARITY_PLATFORMS)" ]; then cmd="$$cmd --ci-parity-platforms \"$(CI_PARITY_PLATFORMS)\""; fi; \ - if [ "$(WSL_REQUIRED)" = "1" ]; then cmd="$$cmd --wsl-required"; fi; \ - if [ "$(WSL_SEPARATE)" = "1" ]; then cmd="$$cmd --wsl-separate"; fi; \ - if [ "$(AUTOMATION)" = "1" ]; then cmd="$$cmd --automation"; fi; \ - eval "$$cmd"; \ - $(MAKE) planning-validate FEATURE_DIR="docs/project_management/packs/$$bucket/$(FEATURE)" - -.PHONY: planning-new-feature-ps -planning-new-feature-ps: - @if [ -z "$(FEATURE)" ]; then echo "ERROR: set FEATURE="; exit 2; fi - @if ! command -v pwsh >/dev/null 2>&1; then echo "ERROR: pwsh not found on PATH"; exit 2; fi - @set -euo pipefail; \ - bucket="$(PACK_BUCKET)"; \ - if [ -z "$$bucket" ]; then bucket="$${PM_DEFAULT_PACK_BUCKET:-}"; fi; \ - if [ -z "$$bucket" ]; then bucket="active"; fi; \ - cmd="pwsh -File $(PM_SYSTEM_SCRIPTS)/planning/new_feature.ps1 -Feature \"$(FEATURE)\" -Bucket \"$$bucket\""; \ - if [ -n "$(SLICE_PREFIX)" ]; then cmd="$$cmd -SlicePrefix \"$(SLICE_PREFIX)\""; fi; \ - if [ "$(DECISION_HEAVY)" = "1" ]; then cmd="$$cmd -DecisionHeavy"; fi; \ - if [ "$(CROSS_PLATFORM)" = "1" ]; then cmd="$$cmd -CrossPlatform"; fi; \ - if [ -n "$(BEHAVIOR_PLATFORMS)" ]; then cmd="$$cmd -BehaviorPlatforms \"$(BEHAVIOR_PLATFORMS)\""; fi; \ - if [ -n "$(CI_PARITY_PLATFORMS)" ]; then cmd="$$cmd -CiParityPlatforms \"$(CI_PARITY_PLATFORMS)\""; fi; \ - if [ "$(WSL_REQUIRED)" = "1" ]; then cmd="$$cmd -WslRequired"; fi; \ - if [ "$(WSL_SEPARATE)" = "1" ]; then cmd="$$cmd -WslSeparate"; fi; \ - if [ "$(AUTOMATION)" = "1" ]; then cmd="$$cmd -Automation"; fi; \ - eval "$$cmd"; \ - $(MAKE) planning-validate FEATURE_DIR="docs/project_management/packs/$$bucket/$(FEATURE)" - -.PHONY: planning-archive -planning-archive: - @if [ -z "$(SRC)" ]; then echo "ERROR: set SRC=docs/project_management//"; exit 2; fi - @set -euo pipefail; \ - cmd="python3 $(PM_SYSTEM_SCRIPTS)/planning/archive_project_management_dir.py --src \"$(SRC)\""; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - if [ "$(ALLOW_DIRTY)" = "1" ]; then cmd="$$cmd --allow-dirty"; fi; \ - eval "$$cmd" - -# ========================= -# Triad execution automation -# ========================= - TASK_ID ?= TASK_PLATFORM ?= SLICE_ID ?= @@ -541,166 +284,25 @@ PLATFORMS ?= SMOKE_RUN_ID ?= LAUNCH_CODEX ?= 0 -CODEX_PROFILE ?= -CODEX_MODEL ?= -CODEX_JSONL ?= 0 - VERIFY_ONLY ?= 0 NO_COMMIT ?= 0 SMOKE ?= 0 - REMOVE_WORKTREES ?= 0 PRUNE_LOCAL ?= 0 PRUNE_REMOTE ?= FORCE ?= 0 DRY_RUN ?= 0 -.PHONY: triad-code-checks -triad-code-checks: - cargo fmt - cargo clippy --workspace --all-targets -- -D warnings - -.PHONY: triad-test-checks -triad-test-checks: - cargo fmt - -.PHONY: triad-task-start -triad-task-start: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(TASK_ID)" ]; then echo "ERROR: set TASK_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start.sh --feature-dir \"$(FEATURE_DIR)\" --task-id \"$(TASK_ID)\""; \ - if [ "$(LAUNCH_CODEX)" = "1" ]; then cmd="$$cmd --launch-codex"; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ -n "$(TASK_PLATFORM)" ]; then cmd="$$cmd --platform \"$(TASK_PLATFORM)\""; fi; \ - if [ "$(FORCE)" = "1" ]; then cmd="$$cmd --force"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-start-pair -triad-task-start-pair: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ] && ( [ -z "$(CODE_TASK_ID)" ] || [ -z "$(TEST_TASK_ID)" ] ); then \ - echo "ERROR: set SLICE_ID= OR set CODE_TASK_ID= TEST_TASK_ID="; exit 2; \ - fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start_pair.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(SLICE_ID)" ]; then cmd="$$cmd --slice-id \"$(SLICE_ID)\""; fi; \ - if [ -n "$(CODE_TASK_ID)" ]; then cmd="$$cmd --code-task-id \"$(CODE_TASK_ID)\""; fi; \ - if [ -n "$(TEST_TASK_ID)" ]; then cmd="$$cmd --test-task-id \"$(TEST_TASK_ID)\""; fi; \ - if [ "$(LAUNCH_CODEX)" = "1" ]; then cmd="$$cmd --launch-codex"; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ "$(FORCE)" = "1" ]; then cmd="$$cmd --force"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-start-complete -triad-task-start-complete: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ]; then echo "ERROR: set SLICE_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start_complete.sh --feature-dir \"$(FEATURE_DIR)\" --slice-id \"$(SLICE_ID)\""; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-orch-ensure -triad-orch-ensure: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/orch_ensure.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ -n "$(FROM_BRANCH)" ]; then cmd="$$cmd --from-branch \"$(FROM_BRANCH)\""; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-start-platform-fixes -triad-task-start-platform-fixes: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ]; then echo "ERROR: set SLICE_ID="; exit 2; fi - @if [ -z "$(PLATFORMS)" ]; then echo "ERROR: set PLATFORMS=linux,macos,windows[,wsl]"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start_platform_fixes.sh --feature-dir \"$(FEATURE_DIR)\" --slice-id \"$(SLICE_ID)\""; \ - IFS=',' read -r -a platforms <<<"$(PLATFORMS)"; \ - for p in "$${platforms[@]}"; do cmd="$$cmd --platform \"$$p\""; done; \ - if [ "$(LAUNCH_CODEX)" = "1" ]; then cmd="$$cmd --launch-codex"; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-start-platform-fixes-from-smoke -triad-task-start-platform-fixes-from-smoke: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ]; then echo "ERROR: set SLICE_ID="; exit 2; fi - @if [ -z "$(SMOKE_RUN_ID)" ]; then echo "ERROR: set SMOKE_RUN_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start_platform_fixes.sh --feature-dir \"$(FEATURE_DIR)\" --slice-id \"$(SLICE_ID)\" --from-smoke-run \"$(SMOKE_RUN_ID)\""; \ - if [ "$(LAUNCH_CODEX)" = "1" ]; then cmd="$$cmd --launch-codex"; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-start-integ-final -triad-task-start-integ-final: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ]; then echo "ERROR: set SLICE_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_start_integ_final.sh --feature-dir \"$(FEATURE_DIR)\" --slice-id \"$(SLICE_ID)\""; \ - if [ "$(LAUNCH_CODEX)" = "1" ]; then cmd="$$cmd --launch-codex"; fi; \ - if [ -n "$(CODEX_PROFILE)" ]; then cmd="$$cmd --codex-profile \"$(CODEX_PROFILE)\""; fi; \ - if [ -n "$(CODEX_MODEL)" ]; then cmd="$$cmd --codex-model \"$(CODEX_MODEL)\""; fi; \ - if [ "$(CODEX_JSONL)" = "1" ]; then cmd="$$cmd --codex-jsonl"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-mark-noop-platform-fixes-completed -triad-mark-noop-platform-fixes-completed: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @if [ -z "$(SLICE_ID)" ]; then echo "ERROR: set SLICE_ID="; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/mark_noop_platform_fixes_completed.sh --feature-dir \"$(FEATURE_DIR)\" --slice-id \"$(SLICE_ID)\""; \ - if [ -n "$(SMOKE_RUN_ID)" ]; then cmd="$$cmd --from-smoke-run \"$(SMOKE_RUN_ID)\""; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" - -.PHONY: triad-task-finish -triad-task-finish: - @if [ -z "$(TASK_ID)" ]; then echo "ERROR: set TASK_ID="; exit 2; fi +.PHONY: planning-archive +planning-archive: + @if [ -z "$(SRC)" ]; then echo "ERROR: set SRC=docs/project_management//"; exit 2; fi @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/task_finish.sh --task-id \"$(TASK_ID)\""; \ - if [ "$(VERIFY_ONLY)" = "1" ]; then cmd="$$cmd --verify-only"; fi; \ - if [ "$(NO_COMMIT)" = "1" ]; then cmd="$$cmd --no-commit"; fi; \ - if [ "$(SMOKE)" = "1" ]; then cmd="$$cmd --smoke"; fi; \ - if [ -n "$(TASK_PLATFORM)" ]; then cmd="$$cmd --platform \"$(TASK_PLATFORM)\""; fi; \ + cmd="python3 $(PM_SYSTEM_SCRIPTS)/planning/archive_project_management_dir.py --src \"$(SRC)\""; \ if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ + if [ "$(ALLOW_DIRTY)" = "1" ]; then cmd="$$cmd --allow-dirty"; fi; \ eval "$$cmd" -.PHONY: triad-feature-cleanup -triad-feature-cleanup: - @if [ -z "$(FEATURE_DIR)" ]; then echo "ERROR: set FEATURE_DIR=docs/project_management/packs//"; exit 2; fi - @if ! echo "$(FEATURE_DIR)" | grep -q '^docs/project_management/packs/'; then echo "ERROR: FEATURE_DIR must be under docs/project_management/packs// (legacy next/ is removed)"; exit 2; fi - @set -euo pipefail; \ - cmd="$(PM_SYSTEM_SCRIPTS)/triad/feature_cleanup.sh --feature-dir \"$(FEATURE_DIR)\""; \ - if [ "$(REMOVE_WORKTREES)" = "1" ]; then cmd="$$cmd --remove-worktrees"; fi; \ - if [ "$(PRUNE_LOCAL)" = "1" ]; then cmd="$$cmd --prune-local-branches"; fi; \ - if [ -n "$(PRUNE_REMOTE)" ]; then cmd="$$cmd --prune-remote-branches \"$(PRUNE_REMOTE)\""; fi; \ - if [ "$(FORCE)" = "1" ]; then cmd="$$cmd --force"; fi; \ - if [ "$(DRY_RUN)" = "1" ]; then cmd="$$cmd --dry-run"; fi; \ - eval "$$cmd" +.PHONY: feature-smoke feature-smoke-all feature-smoke-behavior feature-smoke-wsl planning-new-feature planning-new-feature-ps triad-code-checks triad-test-checks triad-task-start triad-task-start-pair triad-task-start-complete triad-orch-ensure triad-task-start-platform-fixes triad-task-start-platform-fixes-from-smoke triad-task-start-integ-final triad-mark-noop-platform-fixes-completed triad-task-finish triad-feature-cleanup +feature-smoke feature-smoke-all feature-smoke-behavior feature-smoke-wsl planning-new-feature planning-new-feature-ps triad-code-checks triad-test-checks triad-task-start triad-task-start-pair triad-task-start-complete triad-orch-ensure triad-task-start-platform-fixes triad-task-start-platform-fixes-from-smoke triad-task-start-integ-final triad-mark-noop-platform-fixes-completed triad-task-finish triad-feature-cleanup: + @echo "ERROR: target '$@' was retired with project-management pack automation. See docs/PROJECT_MANAGEMENT_RETIREMENT.md." >&2 + @exit 2 diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 39e1f53fd..20e405f47 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -57,28 +57,38 @@ Completed extraction/rewrite slices: earlier slices Still remaining before the atomic top-level `packs/**` removal: -- planning automation and workflow machinery still assume `docs/project_management/packs/**` -- several tests outside `crates/broker/src/tests.rs` still read pack docs directly +- repo-wide reference scan still finds non-pack-tree references to `docs/project_management/packs/**` +- the remaining refs are now concentrated in historical/root docs plus a small number of live + wrappers that still point at pack-owned artifacts Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` - targeted world-deps test rewrites are present in `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` +- `cargo test -p shell --test world_deps_apt_fail_early_wdap1 -- --nocapture` +- `cargo test -p shell --test agent_successor_contract_ahcsitc0 -- --nocapture` +- `cargo test -p transport-api-types --lib -- --nocapture` - scoped reference scans over stable docs and non-`project_management` gateway docs no longer show top-level pack backlinks for the completed ADR-0027 and gateway-foundation slices - scoped reference scans over `crates/gateway/docs/project_management/**` no longer show top-level `docs/project_management/packs/**` or old `kimi-claude-adapter` pack backlinks - scoped reference scans over `docs/reference/**` and `docs/internals/**` no longer show top-level world-sync or host-visible hardening pack backlinks +- scoped reference scans over `Makefile`, `.github/workflows/feature-smoke.yml`, and the targeted + triad / smoke / CI helper scripts no longer show `docs/project_management/packs/**` or + `tasks.json` assumptions ## Current Dependency Classes ### 1. Tooling and automation that assume `packs/**` exists +Completed retirements/replacements: - `Makefile` - - planning scaffolding, validation, triad execution, archive helpers, and feature smoke dispatch all assume `docs/project_management/packs/...` + - retired the pack-driven planning, feature-smoke, scaffolding, and triad entrypoints behind + explicit failure stubs instead of pack-path validation - `.github/workflows/feature-smoke.yml` - - workflow input model and smoke-script discovery depend on feature pack directories and `tasks.json` + - replaced with a retirement workflow that fails fast instead of discovering feature-pack smoke + scripts - `scripts/e2e/triad_e2e_phase1.sh` - `scripts/e2e/triad_e2e_phase2.sh` - `scripts/e2e/triad_e2e_all.sh` @@ -86,31 +96,37 @@ Validation already completed for the finished slices: - `scripts/ci-audit/ci_audit.sh` - `scripts/ci-audit/ci_audit_record.sh` - `scripts/mac/smoke.sh` + - BEDPM installer conformance mode is now retired instead of shelling through a pack-owned smoke + wrapper + +Remaining dependency surface after the repo-wide scan: +- `tests/installers/pkg_manager_detection_smoke.sh` + - still points at a pack-owned smoke wrapper +- root and historical docs outside `docs/project_management/packs/**` + - examples include `docs/BACKLOG.md`, `llm-last-mile/**`, `FSE_PRE_PLANNING_*`, and archived + planning notes that still cite pack paths Disposition: -- delete if triad/planning-pack orchestration is dead -- otherwise replace with non-pack infrastructure before the pack cut +- rewrite or retire any still-live scripts/tests +- classify root/historical docs as either intentional history or blockers that must be rewritten + before the atomic cut ### 2. Rust tests and code that hard-read pack markdown +Completed: +- `crates/broker/src/tests.rs` + - planning-only slice/checkpoint/promote-pack assertions were deleted - `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` - - rewritten to the stable world-deps provisioning docs; keep as an example of the desired end - state for other tests + - markdown-coupled doc-contract assertions were deleted - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` - - asserts successor compatibility, parity, and manual validation playbooks + - markdown-coupled successor doc assertions were deleted - `crates/shell/tests/playbook_alignment.rs` - - recursively scans `docs/project_management/packs/**/manual_testing_playbook.md` + - deleted - `crates/transport-api-types/src/lib.rs` - - test reads a manual testing playbook under a draft pack - -Completed: -- `crates/broker/src/tests.rs` - - ADR-0027 contract tests now lock stable policy docs under `docs/reference/policy/**` - - planning-only slice/checkpoint/promote-pack assertions were deleted rather than migrated + - manual playbook evidence assertion was deleted -Disposition: -- rewrite when the source-of-truth doc survives in a stable home -- delete when the test only protected planning-pack process mechanics +Remaining dependency surface: +- none currently identified in Rust tests under `crates/**` ### 3. Stable docs that still point at pack files @@ -236,14 +252,10 @@ Remaining follow-up: ### Delete candidates -- planning-pack scaffolding and triad automation in `Makefile` if the planning system is fully dead -- feature-smoke workflow and helper scripts if they only exist for planning packs -- `crates/shell/tests/playbook_alignment.rs` if no stable replacement playbook corpus is needed - Python tests under `docs/project_management/system/scripts/planning/tests/` if the planning scripts are retired rather than relocated ### Rewrite candidates -- any Rust test that validates product behavior by asserting current docs mention the right contract - any stable operator or internal doc that cites a pack path as canonical - any future gateway-local planning edits that reintroduce links to deleted top-level pack paths @@ -251,23 +263,23 @@ Remaining follow-up: Use this order in the next session: -1. Triage the remaining pack-reading tests: - - `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` - - `crates/shell/tests/playbook_alignment.rs` - - `crates/transport-api-types/src/lib.rs` - - Goal: rewrite to stable docs where appropriate; delete planning-process-only assertions. -2. Remove or replace planning automation and workflow dependencies: - - `Makefile` - - `.github/workflows/feature-smoke.yml` - - triad / smoke / CI helper scripts -3. Re-run a repo-wide reference scan. - - Goal: confirm what still points at `docs/project_management/packs/**` before attempting the - atomic cut. +1. Triage the remaining non-pack-tree references surfaced by the repo-wide scan. + - Start with `tests/installers/pkg_manager_detection_smoke.sh`. + - Then classify root-level docs such as `docs/BACKLOG.md`, `llm-last-mile/**`, and + `FSE_PRE_PLANNING_*` into: + - intentional historical notes + - blockers that still need rewrites +2. Re-run the repo-wide reference scan after those rewrites. + - Goal: confirm that only intentionally retained historical notes still mention + `docs/project_management/packs/**`. +3. Prepare the atomic `packs/**` deletion once the remaining refs are either rewritten or + explicitly accepted as historical holdouts. ## Resume Notes - Do not start by deleting any pack directories. -- The next correct move is still extraction/rewrite work. +- The next correct move is repo-wide residual-reference triage, not another stable-doc extraction + pass. - The top-level `packs/**` tree must be removed in one cut only after: - stable docs are repointed, - pack-reading tests are rewritten or deleted, diff --git a/scripts/ci-audit/ci_audit.sh b/scripts/ci-audit/ci_audit.sh index 1960df09a..4e08b87de 100755 --- a/scripts/ci-audit/ci_audit.sh +++ b/scripts/ci-audit/ci_audit.sh @@ -9,13 +9,12 @@ Purpose: Recommend whether to SKIP or RUN multi-OS CI based on: - required platforms for the audit kind - last successful GH Actions run coverage (platforms that actually passed) - - whether changes since that run are docs/planning-only + - whether changes since that run are docs-only Usage: scripts/ci-audit/ci_audit.sh \ - --kind \ + --kind ci-testing \ --orch-branch \ - [--feature-dir ] \ [--required-platforms ] \ [--head-sha ] \ [--baseline-sha ] \ @@ -25,11 +24,10 @@ Usage: Examples: scripts/ci-audit/ci_audit.sh --kind ci-testing --orch-branch feat/my-feature - scripts/ci-audit/ci_audit.sh --kind feature-smoke --orch-branch feat/my-feature --feature-dir docs/project_management/packs/active/my-feature Notes: - Advisory only: does not dispatch CI. - - Docs/planning-only changes (anything under docs/) are recommended to SKIP all CI per policy. + - Docs-only changes (anything under docs/) are recommended to SKIP all CI per policy. - If no last-green run exists, diff baseline falls back to merge-base with origin/testing (if available). USAGE } @@ -45,7 +43,6 @@ require_cmd() { KIND="" ORCH_BRANCH="" -FEATURE_DIR="" REQUIRED_PLATFORMS_OVERRIDE="" HEAD_SHA="" BASELINE_SHA_OVERRIDE="" @@ -59,8 +56,6 @@ while [[ $# -gt 0 ]]; do KIND="${2:-}"; shift 2 ;; --orch-branch) ORCH_BRANCH="${2:-}"; shift 2 ;; - --feature-dir) - FEATURE_DIR="${2:-}"; shift 2 ;; --required-platforms) REQUIRED_PLATFORMS_OVERRIDE="${2:-}"; shift 2 ;; --head-sha) @@ -84,8 +79,9 @@ done [[ -n "${ORCH_BRANCH}" ]] || die "Missing --orch-branch" case "${KIND}" in - ci-testing|feature-smoke) ;; - *) die "Invalid --kind: ${KIND} (expected ci-testing or feature-smoke)" ;; + ci-testing) ;; + feature-smoke) die "feature-smoke audit was retired with project-management pack automation" ;; + *) die "Invalid --kind: ${KIND} (expected ci-testing)" ;; esac require_cmd gh @@ -103,7 +99,6 @@ fi WORKFLOW_FILE="" case "${KIND}" in ci-testing) WORKFLOW_FILE=".github/workflows/ci-testing.yml" ;; - feature-smoke) WORKFLOW_FILE=".github/workflows/feature-smoke.yml" ;; esac git fetch -q "${REMOTE}" testing "${ORCH_BRANCH}" || true @@ -111,20 +106,8 @@ git fetch -q "${REMOTE}" testing "${ORCH_BRANCH}" || true required_platforms_csv="" if [[ -n "${REQUIRED_PLATFORMS_OVERRIDE}" ]]; then required_platforms_csv="${REQUIRED_PLATFORMS_OVERRIDE}" -elif [[ "${KIND}" == "ci-testing" ]]; then - required_platforms_csv="linux,macos,windows" else - if [[ -n "${FEATURE_DIR}" ]]; then - if [[ ! -f "${FEATURE_DIR}/tasks.json" ]]; then - die "Missing ${FEATURE_DIR}/tasks.json" - fi - required_platforms_csv="$(jq -r '.meta.behavior_platforms_required // [] | join(",")' "${FEATURE_DIR}/tasks.json")" - else - die "--feature-dir or --required-platforms is required for --kind feature-smoke" - fi - if [[ -z "${required_platforms_csv}" ]]; then - required_platforms_csv="linux,macos,windows" - fi + required_platforms_csv="linux,macos,windows" fi to_set_lines() { @@ -205,15 +188,6 @@ derive_passed_platforms_from_jobs() { "Lint & Test (windows-"*")") platforms+=("windows") ;; esac done < <(jq -r '.[] | select(.conclusion=="success") | .name' <<<"${jobs_json}") - else - while IFS= read -r job_name; do - case "${job_name}" in - linux_*) platforms+=("linux") ;; - macos_*) platforms+=("macos") ;; - windows_*) platforms+=("windows") ;; - wsl) platforms+=("wsl") ;; - esac - done < <(jq -r '.[] | select(.conclusion=="success") | .name' <<<"${jobs_json}") fi if [[ "${#platforms[@]}" -eq 0 ]]; then diff --git a/scripts/ci-audit/ci_audit_record.sh b/scripts/ci-audit/ci_audit_record.sh index 3c2b93e01..2db8b307b 100755 --- a/scripts/ci-audit/ci_audit_record.sh +++ b/scripts/ci-audit/ci_audit_record.sh @@ -13,11 +13,10 @@ Purpose: Usage: scripts/ci-audit/ci_audit_record.sh \ --ledger-path \ - --kind \ + --kind ci-testing \ --orch-branch \ --run-id \ --tested-sha \ - [--feature-dir ] \ [--required-platforms ] \ [--mode ] \ [--repo ] \ @@ -43,7 +42,6 @@ KIND="" ORCH_BRANCH="" RUN_ID="" TESTED_SHA="" -FEATURE_DIR="" REQUIRED_PLATFORMS_OVERRIDE="" MODE="" REPO="" @@ -56,7 +54,6 @@ while [[ $# -gt 0 ]]; do --orch-branch) ORCH_BRANCH="${2:-}"; shift 2 ;; --run-id) RUN_ID="${2:-}"; shift 2 ;; --tested-sha) TESTED_SHA="${2:-}"; shift 2 ;; - --feature-dir) FEATURE_DIR="${2:-}"; shift 2 ;; --required-platforms) REQUIRED_PLATFORMS_OVERRIDE="${2:-}"; shift 2 ;; --mode) MODE="${2:-}"; shift 2 ;; --repo) REPO="${2:-}"; shift 2 ;; @@ -73,8 +70,9 @@ done [[ -n "${TESTED_SHA}" ]] || die "Missing --tested-sha" case "${KIND}" in - ci-testing|feature-smoke) ;; - *) die "Invalid --kind: ${KIND} (expected ci-testing or feature-smoke)" ;; + ci-testing) ;; + feature-smoke) die "feature-smoke audit recording was retired with project-management pack automation" ;; + *) die "Invalid --kind: ${KIND} (expected ci-testing)" ;; esac require_cmd gh @@ -88,18 +86,8 @@ fi required_platforms_csv="" if [[ -n "${REQUIRED_PLATFORMS_OVERRIDE}" ]]; then required_platforms_csv="${REQUIRED_PLATFORMS_OVERRIDE}" -elif [[ "${KIND}" == "ci-testing" ]]; then - required_platforms_csv="linux,macos,windows" else - if [[ -n "${FEATURE_DIR}" ]]; then - [[ -f "${FEATURE_DIR}/tasks.json" ]] || die "Missing ${FEATURE_DIR}/tasks.json" - required_platforms_csv="$(jq -r '.meta.behavior_platforms_required // [] | join(",")' "${FEATURE_DIR}/tasks.json")" - if [[ -z "${required_platforms_csv}" ]]; then - required_platforms_csv="linux,macos,windows" - fi - else - required_platforms_csv="linux,macos,windows" - fi + required_platforms_csv="linux,macos,windows" fi to_set_json() { @@ -122,19 +110,6 @@ derive_passed_platforms() { "Lint & Test (windows-"*")") echo windows ;; esac done | sort -u - else - jq -r ' - .[] - | select(.conclusion=="success") - | .name - ' <<<"${jobs_json}" | while IFS= read -r name; do - case "${name}" in - linux_*) echo linux ;; - macos_*) echo macos ;; - windows_*) echo windows ;; - wsl) echo wsl ;; - esac - done | sort -u fi } @@ -202,4 +177,3 @@ echo "CONCLUSION=${conclusion}" echo "TESTED_SHA=${TESTED_SHA}" echo "REQUIRED_PLATFORMS=${required_platforms_csv}" echo "PASSED_PLATFORMS=$(jq -r '.passed_platforms | join(",")' <<<"${entry}")" - diff --git a/scripts/ci/dispatch_feature_smoke.sh b/scripts/ci/dispatch_feature_smoke.sh index 21d88aa53..dfa3e152e 100755 --- a/scripts/ci/dispatch_feature_smoke.sh +++ b/scripts/ci/dispatch_feature_smoke.sh @@ -1,606 +1,26 @@ #!/usr/bin/env bash set -euo pipefail -usage() { - cat <<'USAGE' -Usage: - scripts/ci/dispatch_feature_smoke.sh \ - --feature-dir docs/project_management/packs/active/ \ - [--runner-kind github-hosted|self-hosted] \ - [--macos-runner-kind github-hosted|self-hosted] \ - --platform behavior|linux|macos|windows|wsl|all \ - [--checkout-ref ] \ - [--smoke-slice-id ] \ - [--run-wsl] \ - [--run-integ-checks] \ - [--workflow .github/workflows/feature-smoke.yml] \ - [--workflow-ref ] \ - [--remote origin] \ - [--cleanup] - -What it does: - - Creates a throwaway remote branch at the target commit (default: HEAD) - - Dispatches the workflow against the workflow ref (default: current git branch), checking out the throwaway branch - - Optionally waits and deletes the throwaway branch - -Requirements: - - `gh` CLI installed and authenticated - - Push access to the configured remote - -Stdout contract (machine-parseable): - DISPATCH_OK=0|1 - HEAD= - TEMP_BRANCH= - RUN_ID= - RUN_URL= - CONCLUSION= - SMOKE_SLICE_ID= - SMOKE_PASSED_PLATFORMS= - SMOKE_FAILED_PLATFORMS= - RUNNER_MISPROVISIONED=0|1 - RUNNER_MISPROVISIONED_REASON= - ERROR_KIND= - ERROR_MESSAGE= -USAGE -} - emit_kv() { local key="$1" local val="$2" printf '%s=%s\n' "$key" "$val" } -die() { - echo "ERROR: $*" >&2 - ERROR_MESSAGE="$*" - exit 2 -} - -require_cmd() { - if ! command -v "$1" >/dev/null 2>&1; then - ERROR_KIND="dependency_missing" - die "Missing dependency: $1" - fi -} - -run_with_timeout() { - local timeout_secs="$1" - shift - - if command -v timeout >/dev/null 2>&1; then - timeout -k 10s "${timeout_secs}s" "$@" - return $? - fi - if command -v gtimeout >/dev/null 2>&1; then - gtimeout -k 10s "${timeout_secs}s" "$@" - return $? - fi - - python3 - "$timeout_secs" "$@" <<'PY' -import os -import signal -import subprocess -import sys - -timeout_secs = float(sys.argv[1]) -cmd = sys.argv[2:] - -proc = subprocess.Popen(cmd, start_new_session=True) -try: - raise SystemExit(proc.wait(timeout=timeout_secs)) -except subprocess.TimeoutExpired: - try: - os.killpg(proc.pid, signal.SIGTERM) - except ProcessLookupError: - raise SystemExit(124) - try: - proc.wait(timeout=10) - except subprocess.TimeoutExpired: - try: - os.killpg(proc.pid, signal.SIGKILL) - except ProcessLookupError: - pass - raise SystemExit(124) -PY -} - -FEATURE_DIR="" -PLATFORM="" -RUNNER_KIND="self-hosted" -MACOS_RUNNER_KIND="" -RUN_WSL=0 -RUN_INTEG_CHECKS=0 -CHECKOUT_REF="" -SMOKE_SLICE_ID="" -WORKFLOW=".github/workflows/feature-smoke.yml" -WORKFLOW_REF="" -REMOTE="origin" -CLEANUP=0 - -DISPATCH_OK=0 -HEAD="" -TEMP_BRANCH="" -RUN_ID="" -RUN_URL="" -CONCLUSION="" -SMOKE_PASSED_PLATFORMS="" -SMOKE_FAILED_PLATFORMS="" -RUNNER_MISPROVISIONED=0 -RUNNER_MISPROVISIONED_REASON="" -ERROR_KIND="" -ERROR_MESSAGE="" -_SUMMARY_EMITTED=0 - -emit_summary() { - if [[ "${_SUMMARY_EMITTED}" -eq 1 ]]; then - return 0 - fi - _SUMMARY_EMITTED=1 - - emit_kv "DISPATCH_OK" "${DISPATCH_OK}" - emit_kv "HEAD" "${HEAD}" - emit_kv "TEMP_BRANCH" "${TEMP_BRANCH}" - emit_kv "RUN_ID" "${RUN_ID}" - emit_kv "RUN_URL" "${RUN_URL}" - emit_kv "CONCLUSION" "${CONCLUSION}" - emit_kv "SMOKE_SLICE_ID" "${SMOKE_SLICE_ID}" - emit_kv "SMOKE_PASSED_PLATFORMS" "${SMOKE_PASSED_PLATFORMS}" - emit_kv "SMOKE_FAILED_PLATFORMS" "${SMOKE_FAILED_PLATFORMS}" - emit_kv "RUNNER_MISPROVISIONED" "${RUNNER_MISPROVISIONED}" - emit_kv "RUNNER_MISPROVISIONED_REASON" "${RUNNER_MISPROVISIONED_REASON}" - emit_kv "ERROR_KIND" "${ERROR_KIND}" - emit_kv "ERROR_MESSAGE" "${ERROR_MESSAGE}" -} - -on_exit() { - local exit_code="$?" - trap - EXIT - - if [[ -z "${CONCLUSION}" ]]; then - CONCLUSION="unknown" - fi - - emit_summary - - # Preserve the original exit code behavior; note that `make feature-smoke` will map any non-zero - # to a Make failure (typically exiting 2), so callers should rely on DISPATCH_OK + RUN_URL too. - exit "${exit_code}" -} -trap on_exit EXIT - -while [[ $# -gt 0 ]]; do - case "$1" in - --feature-dir) - FEATURE_DIR="${2:-}" - shift 2 - ;; - --runner-kind) - RUNNER_KIND="${2:-}" - shift 2 - ;; - --macos-runner-kind) - MACOS_RUNNER_KIND="${2:-}" - shift 2 - ;; - --platform) - PLATFORM="${2:-}" - shift 2 - ;; - --checkout-ref) - CHECKOUT_REF="${2:-}" - shift 2 - ;; - --smoke-slice-id) - SMOKE_SLICE_ID="${2:-}" - shift 2 - ;; - --run-wsl) - RUN_WSL=1 - shift 1 - ;; - --run-integ-checks) - RUN_INTEG_CHECKS=1 - shift 1 - ;; - --workflow) - WORKFLOW="${2:-}" - shift 2 - ;; - --workflow-ref) - WORKFLOW_REF="${2:-}" - shift 2 - ;; - --remote) - REMOTE="${2:-}" - shift 2 - ;; - --cleanup) - CLEANUP=1 - shift 1 - ;; - -h|--help) - usage - exit 0 - ;; - *) - echo "Unknown arg: $1" >&2 - usage >&2 - ERROR_KIND="usage" - exit 2 - ;; - esac -done - -if [[ -z "${FEATURE_DIR}" || -z "${PLATFORM}" ]]; then - usage >&2 - ERROR_KIND="usage" - die "Missing required args: --feature-dir and --platform" -fi - -case "${PLATFORM}" in - behavior|linux|macos|windows|wsl|all) ;; - *) - echo "Invalid --platform: ${PLATFORM}" >&2 - usage >&2 - ERROR_KIND="usage" - exit 2 - ;; -esac - -case "${RUNNER_KIND}" in - github-hosted|self-hosted) ;; - *) - echo "Invalid --runner-kind: ${RUNNER_KIND}" >&2 - usage >&2 - ERROR_KIND="usage" - exit 2 - ;; -esac - -if [[ -n "${MACOS_RUNNER_KIND}" ]]; then - case "${MACOS_RUNNER_KIND}" in - github-hosted|self-hosted) ;; - *) - echo "Invalid --macos-runner-kind: ${MACOS_RUNNER_KIND}" >&2 - usage >&2 - ERROR_KIND="usage" - exit 2 - ;; - esac -fi - -require_cmd git -require_cmd gh -require_cmd python3 - -if [[ -z "${WORKFLOW_REF}" ]]; then - WORKFLOW_REF="$(git branch --show-current 2>/dev/null || true)" - if [[ -z "${WORKFLOW_REF}" ]]; then - ERROR_KIND="usage" - die "Missing --workflow-ref (ref must not be main/testing; use the orchestration/task ref)" - fi -fi - -if ! gh api user >/dev/null 2>&1; then - ERROR_KIND="auth" - die "GitHub CLI auth is not usable (token invalid or missing). Fix with: gh auth login -h github.com (or set GH_TOKEN for non-interactive runs)." -fi - -if [[ -z "${WORKFLOW_REF}" ]]; then - usage >&2 - ERROR_KIND="usage" - die "Missing --workflow-ref" -fi - -GIT_PUSH_TIMEOUT_SECS="${FEATURE_SMOKE_GIT_PUSH_TIMEOUT_SECS:-300}" -GH_TIMEOUT_SECS="${FEATURE_SMOKE_GH_TIMEOUT_SECS:-120}" -WATCH_INTERVAL_SECS="${FEATURE_SMOKE_WATCH_INTERVAL_SECS:-15}" -WATCH_TIMEOUT_SECS="${FEATURE_SMOKE_WATCH_TIMEOUT_SECS:-7200}" # 2h -WATCH_MAX_CONSECUTIVE_ERRORS="${FEATURE_SMOKE_WATCH_MAX_CONSECUTIVE_ERRORS:-20}" -# Under heavy CI load, workflow runs can remain queued long enough that no job logs are available -# for matching. Allow a longer default to avoid spurious lookup timeouts. -RUN_LOOKUP_TIMEOUT_SECS="${FEATURE_SMOKE_RUN_LOOKUP_TIMEOUT_SECS:-600}" - -ts="$(date -u +%Y%m%dT%H%M%SZ)" -safe_feature="$(basename "${FEATURE_DIR}")" -TEMP_BRANCH="tmp/feature-smoke/${safe_feature}/${PLATFORM}/${ts}" - -if [[ -z "${CHECKOUT_REF}" ]]; then - CHECKOUT_REF="HEAD" -fi - -HEAD="$(git rev-parse "${CHECKOUT_REF}")" -echo "HEAD: ${HEAD}" >&2 -echo "Temp branch: ${TEMP_BRANCH}" >&2 - -git branch -f "${TEMP_BRANCH}" "${HEAD}" -if ! run_with_timeout "${GIT_PUSH_TIMEOUT_SECS}" git push -u "${REMOTE}" "${TEMP_BRANCH}:${TEMP_BRANCH}" >&2; then - ERROR_KIND="git_push_failed" - die "git push timed out or failed (branch=${TEMP_BRANCH})" -fi - -echo "Dispatching workflow: ${WORKFLOW}" >&2 -echo "Workflow ref: ${WORKFLOW_REF}" >&2 -dispatch_started="$(date -u +%Y-%m-%dT%H:%M:%SZ)" -run_wsl_flag="false" -run_integ_checks_flag="false" -macos_runner_kind_arg=() -if [[ "${RUN_WSL}" -eq 1 ]]; then - run_wsl_flag="true" -fi -if [[ "${RUN_INTEG_CHECKS}" -eq 1 ]]; then - run_integ_checks_flag="true" -fi -if [[ -n "${MACOS_RUNNER_KIND}" ]]; then - macos_runner_kind_arg=(-f "macos_runner_kind=${MACOS_RUNNER_KIND}") -fi -if ! run_with_timeout "${GH_TIMEOUT_SECS}" gh workflow run "${WORKFLOW}" --ref "${WORKFLOW_REF}" \ - -f feature_dir="${FEATURE_DIR}" \ - -f checkout_ref="${TEMP_BRANCH}" \ - -f runner_kind="${RUNNER_KIND}" \ - -f platform="${PLATFORM}" \ - -f smoke_slice_id="${SMOKE_SLICE_ID}" \ - -f run_wsl="${run_wsl_flag}" \ - -f run_integ_checks="${run_integ_checks_flag}" \ - "${macos_runner_kind_arg[@]}"; then - ERROR_KIND="dispatch_failed" - die "failed to dispatch workflow via gh (workflow=${WORKFLOW} ref=${WORKFLOW_REF})" -fi -DISPATCH_OK=1 - -echo "Waiting for run to start..." >&2 -started_lookup_at="$(date +%s)" -RUN_ID="" -checked_runs="" -fallback_run_id="" -while [[ -z "${RUN_ID}" ]]; do - # Do not rely on local time-based filtering; runner clocks can drift relative to GitHub's - # createdAt timestamps and cause false "run_lookup_timeout" failures. - candidates_json="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run list --workflow "${WORKFLOW}" --event workflow_dispatch --branch "${WORKFLOW_REF}" --limit 20 --json databaseId,createdAt -q '.' 2>/dev/null || true)" - - if [[ -n "${candidates_json}" ]]; then - # Best-effort fallback: prefer the newest run created after we dispatched, otherwise - # fall back to the newest run overall on the workflow ref. This avoids false negatives - # when job logs are temporarily unavailable for matching. - fallback_run_id="$( - python3 - "${candidates_json}" "${dispatch_started}" <<'PY' || true -import json -import sys -from datetime import datetime, timezone - -raw = sys.argv[1] -dispatch_started_raw = sys.argv[2] - -try: - data = json.loads(raw) -except Exception: - raise SystemExit(0) - -def parse_ts(s: str): - # GitHub timestamps are ISO8601 with Z. - return datetime.fromisoformat(s.replace("Z", "+00:00")) - -try: - dispatch_started = parse_ts(dispatch_started_raw) -except Exception: - dispatch_started = None - -for r in data: - rid = r.get("databaseId") - created_at = r.get("createdAt") - if rid is None or not created_at or dispatch_started is None: - continue - try: - if parse_ts(created_at) >= dispatch_started: - print(rid) - raise SystemExit(0) - except Exception: - continue - -if data and isinstance(data, list): - rid = data[0].get("databaseId") - if rid is not None: - print(rid) -PY - )" - - candidate_ids="$(python3 - "${candidates_json}" <<'PY' || true -import json -import sys - -raw = sys.argv[1] -try: - data = json.loads(raw) -except Exception: - raise SystemExit(0) - -for r in data: - rid = r.get("databaseId") - if rid is None: - continue - print(rid) -PY -)" - - while IFS= read -r rid; do - [[ -z "${rid}" ]] && continue - if printf '%s\n' "${checked_runs}" | grep -Fxq "${rid}"; then - continue - fi - - feature_meta_job_id="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${rid}" --json jobs -q '.jobs[] | select(.name == "feature_meta") | .databaseId' 2>/dev/null || true)" - [[ -z "${feature_meta_job_id}" ]] && continue - - feature_meta_log="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${rid}" --job "${feature_meta_job_id}" --log 2>/dev/null || true)" - if [[ -n "${feature_meta_log}" ]] && printf '%s\n' "${feature_meta_log}" | grep -Fq "ref: ${TEMP_BRANCH}"; then - RUN_ID="${rid}" - break - fi - - # Only mark a run as "checked" once we can definitively see it checked out some other temp branch. - # If the job hasn't reached checkout yet (or logs aren't ready), allow re-checking in later iterations. - if [[ -n "${feature_meta_log}" ]] && printf '%s\n' "${feature_meta_log}" | grep -Fq "ref: tmp/feature-smoke/"; then - checked_runs="$(printf '%s\n%s\n' "${checked_runs}" "${rid}")" - fi - done <<< "${candidate_ids}" - fi - - if [[ -n "${RUN_ID}" ]]; then - break - fi - - now="$(date +%s)" - if [[ $((now - started_lookup_at)) -ge "${RUN_LOOKUP_TIMEOUT_SECS}" ]]; then - if [[ -n "${fallback_run_id}" ]]; then - echo "WARN: Could not confirm run checkout ref via logs after ${RUN_LOOKUP_TIMEOUT_SECS}s; proceeding with newest candidate run id: ${fallback_run_id}" >&2 - RUN_ID="${fallback_run_id}" - break - fi - - ERROR_KIND="run_lookup_timeout" - die "Could not find a matching workflow run for ${TEMP_BRANCH} after ${RUN_LOOKUP_TIMEOUT_SECS}s" - fi - sleep 5 -done -if [[ -z "${RUN_ID}" ]]; then - ERROR_KIND="run_lookup_failed" - die "Could not find a matching workflow run for ${TEMP_BRANCH}" -fi - -echo "Run: ${RUN_ID}" >&2 -RUN_URL="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${RUN_ID}" --json url -q '.url' 2>/dev/null || true)" -started_watch_at="$(date +%s)" -next_heartbeat_at="$((started_watch_at + 60))" -consecutive_errors=0 - -echo "Watching run status (interval=${WATCH_INTERVAL_SECS}s timeout=${WATCH_TIMEOUT_SECS}s)..." >&2 -while true; do - now="$(date +%s)" - elapsed="$((now - started_watch_at))" - if [[ "${elapsed}" -ge "${WATCH_TIMEOUT_SECS}" ]]; then - ERROR_KIND="watch_timeout" - die "Timed out waiting for smoke run ${RUN_ID} to complete after ${elapsed}s" - fi - - status="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${RUN_ID}" --json status -q '.status' 2>/dev/null || true)" - if [[ -z "${status}" ]]; then - consecutive_errors="$((consecutive_errors + 1))" - if [[ "${consecutive_errors}" -ge "${WATCH_MAX_CONSECUTIVE_ERRORS}" ]]; then - ERROR_KIND="watch_query_failed" - die "Repeated failures querying GitHub run status (run=${RUN_ID})" - fi - status="unknown" - else - consecutive_errors=0 - fi - if [[ "${status}" == "completed" ]]; then - break - fi - - if [[ "${now}" -ge "${next_heartbeat_at}" ]]; then - echo " status=${status} elapsed_s=${elapsed} run=${RUN_ID}" >&2 - next_heartbeat_at="$((now + 60))" - fi - - sleep "${WATCH_INTERVAL_SECS}" -done -CONCLUSION="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${RUN_ID}" --json conclusion -q '.conclusion' 2>/dev/null || true)" - -platform_summary="$(run_with_timeout "${GH_TIMEOUT_SECS}" gh run view "${RUN_ID}" --json jobs 2>/dev/null || true)" -passed_csv="" -failed_csv="" -if [[ -n "${platform_summary}" ]]; then - parsed="$(python3 - "${platform_summary}" <<'PY' || true -import json -import sys - -raw = sys.argv[1] -try: - data = json.loads(raw) -except Exception: - raise SystemExit(0) - -jobs = data.get("jobs") or [] -failed = set() -passed = set() - -def job_platform(name): - if name.startswith("linux_"): - return "linux" - if name.startswith("macos_"): - return "macos" - if name.startswith("windows_"): - return "windows" - if name == "wsl": - return "wsl" - return None - -for j in jobs: - if not isinstance(j, dict): - continue - name = j.get("name") or "" - concl = j.get("conclusion") - if concl in (None, "skipped"): - continue - p = job_platform(str(name)) - if not p: - continue - if concl == "success": - passed.add(p) - else: - failed.add(p) - -def csv(xs): - return ",".join(sorted(xs)) - -print(f"SMOKE_PASSED_PLATFORMS={csv(passed)}") -print(f"SMOKE_FAILED_PLATFORMS={csv(failed)}") -PY -)" - passed_csv="$(printf '%s\n' "${parsed}" | awk -F= '$1=="SMOKE_PASSED_PLATFORMS"{sub($1"=","",$0); print $0}')" - failed_csv="$(printf '%s\n' "${parsed}" | awk -F= '$1=="SMOKE_FAILED_PLATFORMS"{sub($1"=","",$0); print $0}')" -fi - -SMOKE_PASSED_PLATFORMS="${passed_csv}" -SMOKE_FAILED_PLATFORMS="${failed_csv}" - -# If the run failed, check for known misprovisioning sentinels so callers don't thrash reruns. -if [[ "${DISPATCH_OK}" -eq 1 && -n "${RUN_ID}" && "${CONCLUSION}" != "success" ]]; then - LOG_SCAN_TIMEOUT_SECS="${FEATURE_SMOKE_LOG_SCAN_TIMEOUT_SECS:-300}" - failed_logs="$(run_with_timeout "${LOG_SCAN_TIMEOUT_SECS}" gh run view "${RUN_ID}" --log-failed 2>/dev/null || true)" - if [[ -n "${failed_logs}" ]] && printf '%s\n' "${failed_logs}" | grep -Fq "SUBSTRATE_RUNNER_MISPROVISIONED=1"; then - RUNNER_MISPROVISIONED=1 - RUNNER_MISPROVISIONED_REASON="$( - printf '%s\n' "${failed_logs}" \ - | grep -F "SUBSTRATE_RUNNER_MISPROVISIONED_REASON=" \ - | head -n 1 \ - | sed 's/.*SUBSTRATE_RUNNER_MISPROVISIONED_REASON=//' - )" - ERROR_KIND="runner_misprovisioned" - if [[ -z "${ERROR_MESSAGE}" ]]; then - if [[ -n "${RUNNER_MISPROVISIONED_REASON}" ]]; then - ERROR_MESSAGE="Runner misprovisioned (${RUNNER_MISPROVISIONED_REASON}); do not rerun; fix runner provisioning and retry" - else - ERROR_MESSAGE="Runner misprovisioned; do not rerun; fix runner provisioning and retry" - fi - fi - fi -fi - -if [[ "${CLEANUP}" -eq 1 ]]; then - echo "Cleaning up remote branch: ${TEMP_BRANCH}" >&2 - if ! run_with_timeout "${GIT_PUSH_TIMEOUT_SECS}" git push "${REMOTE}" ":${TEMP_BRANCH}" >&2; then - ERROR_KIND="${ERROR_KIND:-cleanup_failed}" - echo "WARN: failed to delete remote branch (continuing): ${TEMP_BRANCH}" >&2 - fi - git branch -D "${TEMP_BRANCH}" >/dev/null 2>&1 || true -fi - -if [[ "${CONCLUSION}" != "success" ]]; then - if [[ -z "${ERROR_KIND}" ]]; then - ERROR_KIND="run_failed" - fi - exit 1 -fi - -echo "OK: feature smoke passed" >&2 +emit_kv "DISPATCH_OK" "0" +emit_kv "HEAD" "" +emit_kv "TEMP_BRANCH" "" +emit_kv "RUN_ID" "" +emit_kv "RUN_URL" "" +emit_kv "CONCLUSION" "retired" +emit_kv "SMOKE_SLICE_ID" "" +emit_kv "SMOKE_PASSED_PLATFORMS" "" +emit_kv "SMOKE_FAILED_PLATFORMS" "" +emit_kv "RUNNER_MISPROVISIONED" "0" +emit_kv "RUNNER_MISPROVISIONED_REASON" "" +emit_kv "ERROR_KIND" "retired" +emit_kv "ERROR_MESSAGE" "feature-smoke automation was retired with project-management pack automation" + +echo "ERROR: feature-smoke automation was retired with project-management pack automation." >&2 +echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 +exit 2 diff --git a/scripts/e2e/triad_e2e_all.sh b/scripts/e2e/triad_e2e_all.sh index ee930c75b..a33c20e42 100755 --- a/scripts/e2e/triad_e2e_all.sh +++ b/scripts/e2e/triad_e2e_all.sh @@ -1,60 +1,6 @@ #!/usr/bin/env bash set -euo pipefail -usage() { - cat <<'USAGE' -Usage: - scripts/e2e/triad_e2e_all.sh [phase1 options] -- [phase2 options] - -Example: - scripts/e2e/triad_e2e_all.sh --feature e2e-demo --push-orch --codex-jsonl -- \ - --platform-fixes linux,macos,windows --push-orch --cleanup - -Notes: - - Everything before `--` is passed to Phase 1. - - Everything after `--` is passed to Phase 2. - - Phase 2 always receives `--feature-dir docs/project_management/packs/active/` based on Phase 1 output. -USAGE -} - -die() { - echo "ERROR: $*" >&2 - exit 2 -} - -require_cmd() { - if ! command -v "$1" >/dev/null 2>&1; then - die "Missing dependency: $1" - fi -} - -require_cmd awk -require_cmd bash - -phase1_args=() -phase2_args=() -split=0 - -while [[ $# -gt 0 ]]; do - if [[ "$1" == "--" ]]; then - split=1 - shift 1 - continue - fi - if [[ "${split}" -eq 0 ]]; then - phase1_args+=("$1") - else - phase2_args+=("$1") - fi - shift 1 -done - -out="$(scripts/e2e/triad_e2e_phase1.sh "${phase1_args[@]}")" -echo "${out}" - -feature_dir="$(printf '%s\n' "${out}" | awk -F= '$1=="FEATURE_DIR"{print $2}')" -if [[ -z "${feature_dir}" ]]; then - die "Could not parse FEATURE_DIR from phase1 output" -fi - -scripts/e2e/triad_e2e_phase2.sh --feature-dir "${feature_dir}" "${phase2_args[@]}" +echo "ERROR: triad_e2e_all.sh was retired with project-management pack automation." >&2 +echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 +exit 2 diff --git a/scripts/e2e/triad_e2e_phase1.sh b/scripts/e2e/triad_e2e_phase1.sh index 311d0a92e..e22f725c9 100755 --- a/scripts/e2e/triad_e2e_phase1.sh +++ b/scripts/e2e/triad_e2e_phase1.sh @@ -1,655 +1,6 @@ #!/usr/bin/env bash set -euo pipefail -usage() { - cat <<'USAGE' -Usage: - scripts/e2e/triad_e2e_phase1.sh [options] - -Purpose: - Phase 1 of the end-to-end triad automation smoke: - - scaffold an automation-enabled, cross-platform Planning Pack - - write minimal (lintable) docs + ADR + smoke scripts + deterministic kickoff prompts - - complete the feature start gate (F0-exec-preflight) on orchestration branch - - start first-slice code + test in parallel worktrees and launch Codex headless for both - - finish first-slice code + test (commit to their task branches; no merge to orchestration) - -Options: - --feature Feature dir name under docs/project_management/packs/active/ (default: e2e-triad-smoke-) - --remote Git remote for pushes/CI (default: origin) - --runner-kind github-hosted|self-hosted (default: self-hosted) - --run-wsl Include WSL coverage in smoke (requires self-hosted runners) - --wsl-separate Scaffold a separate WSL platform-fix task (requires --run-wsl) - - --codex-profile

Passed to Codex (`codex exec --profile`) - --codex-model Passed to Codex (`codex exec --model`) - --codex-jsonl Capture Codex JSONL events (uses `codex exec --json`) - --skip-codex Do not launch Codex (still creates worktrees; you must edit manually) - - --skip-planning-lint Skip `make planning-lint` (still runs JSON validation unless skipped) - --skip-planning-validate Skip `make planning-validate` - --skip-sequencing-update Do not add a temporary entry to the sequencing spine (packs; falls back to next) - - --push-orch Push orchestration branch to remote (recommended if you will run Phase 2 CI) - - --log-dir

Log directory (default: target/e2e//) - --dry-run Print actions; do not mutate git/worktrees - -Output: - Prints the feature directory and the log paths. -USAGE -} - -die() { - echo "ERROR: $*" >&2 - exit 2 -} - -require_cmd() { - if ! command -v "$1" >/dev/null 2>&1; then - die "Missing dependency: $1" - fi -} - -utc_now_compact() { - date -u +%Y%m%dT%H%M%SZ -} - -utc_now() { - date -u +%Y-%m-%dT%H:%M:%SZ -} - -python_abs_path() { - python3 - "$1" <<'PY' -import os -import sys - -p = sys.argv[1] -if os.path.isabs(p): - print(os.path.realpath(p)) -else: - print(os.path.realpath(os.path.join(os.getcwd(), p))) -PY -} - -log() { - echo "== $*" >&2 -} - -run() { - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ $*" >&2 - return 0 - fi - echo "+ $*" >&2 - "$@" -} - -append_session_log() { - local session_log="$1" - local line="$2" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ append ${session_log}: ${line}" >&2 - return 0 - fi - printf '%s\n' "${line}" >>"${session_log}" -} - -set_task_status() { - local tasks_json="$1" - local task_id="$2" - local status="$3" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ set ${tasks_json} ${task_id}.status=${status}" >&2 - return 0 - fi - python3 - "${tasks_json}" "${task_id}" "${status}" <<'PY' -import json -import sys - -path, task_id, status = sys.argv[1], sys.argv[2], sys.argv[3] -with open(path, "r", encoding="utf-8") as f: - data = json.load(f) - -tasks = data.get("tasks") -if not isinstance(tasks, list): - raise SystemExit("tasks.json: missing tasks[]") - -found = False -for t in tasks: - if isinstance(t, dict) and t.get("id") == task_id: - t["status"] = status - found = True - break -if not found: - raise SystemExit(f"tasks.json: task not found: {task_id}") - -tmp = path + ".tmp" -with open(tmp, "w", encoding="utf-8") as f: - json.dump(data, f, indent=2) - f.write("\n") -import os -os.replace(tmp, path) -PY -} - -FEATURE="e2e-triad-smoke-$(utc_now_compact)" -REMOTE="origin" -RUNNER_KIND="self-hosted" -RUN_WSL=0 -WSL_SEPARATE=0 - -CODEX_PROFILE="" -CODEX_MODEL="" -CODEX_JSONL=0 -SKIP_CODEX=0 - -SKIP_PLANNING_LINT=0 -SKIP_PLANNING_VALIDATE=0 -SKIP_SEQUENCING_UPDATE=0 -PUSH_ORCH=0 - -LOG_DIR="" -DRY_RUN=0 - -while [[ $# -gt 0 ]]; do - case "$1" in - --feature) - FEATURE="${2:-}" - shift 2 - ;; - --remote) - REMOTE="${2:-}" - shift 2 - ;; - --runner-kind) - RUNNER_KIND="${2:-}" - shift 2 - ;; - --run-wsl) - RUN_WSL=1 - shift 1 - ;; - --wsl-separate) - WSL_SEPARATE=1 - shift 1 - ;; - --codex-profile) - CODEX_PROFILE="${2:-}" - shift 2 - ;; - --codex-model) - CODEX_MODEL="${2:-}" - shift 2 - ;; - --codex-jsonl) - CODEX_JSONL=1 - shift 1 - ;; - --skip-codex) - SKIP_CODEX=1 - shift 1 - ;; - --skip-planning-lint) - SKIP_PLANNING_LINT=1 - shift 1 - ;; - --skip-planning-validate) - SKIP_PLANNING_VALIDATE=1 - shift 1 - ;; - --skip-sequencing-update) - SKIP_SEQUENCING_UPDATE=1 - shift 1 - ;; - --push-orch) - PUSH_ORCH=1 - shift 1 - ;; - --log-dir) - LOG_DIR="${2:-}" - shift 2 - ;; - --dry-run) - DRY_RUN=1 - shift 1 - ;; - -h|--help) - usage - exit 0 - ;; - *) - die "Unknown arg: $1" - ;; - esac -done - -if [[ "${RUN_WSL}" -eq 0 && "${WSL_SEPARATE}" -eq 1 ]]; then - die "--wsl-separate requires --run-wsl" -fi - -case "${RUNNER_KIND}" in - github-hosted|self-hosted) ;; - *) die "Invalid --runner-kind: ${RUNNER_KIND}" ;; -esac - -require_cmd git -require_cmd jq -require_cmd rg -require_cmd python3 -require_cmd make - -if [[ "${SKIP_CODEX}" -eq 0 ]]; then - require_cmd codex -fi - -REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || die "Not in a git repo" -cd "${REPO_ROOT}" - -ORCH_BRANCH="feat/${FEATURE}" -FEATURE_DIR="docs/project_management/packs/active/${FEATURE}" -FEATURE_DIR_ABS="$(python_abs_path "${FEATURE_DIR}")" -SEQUENCING_JSON="docs/project_management/packs/sequencing.json" -PM_SYSTEM_SCRIPTS="docs/project_management/system/scripts" - -SLICE_PREFIX="E2E" -SLICE_ID="${SLICE_PREFIX}0" -CODE_TASK_ID="${SLICE_ID}-code" -TEST_TASK_ID="${SLICE_ID}-test" -INTEG_CORE_TASK_ID="${SLICE_ID}-integ-core" -INTEG_TASK_ID="${SLICE_ID}-integ" - -if [[ -z "${LOG_DIR}" ]]; then - LOG_DIR="target/e2e/${FEATURE}" -fi -LOG_DIR_ABS="$(python_abs_path "${LOG_DIR}")" -mkdir -p "${LOG_DIR_ABS}" -LOG_PATH="${LOG_DIR_ABS}/phase1.log" - -exec > >(tee -a "${LOG_PATH}") 2>&1 - -log "Repo: ${REPO_ROOT}" -log "Feature: ${FEATURE_DIR}" -log "Orchestration branch: ${ORCH_BRANCH}" -log "Log: ${LOG_PATH}" - -if [[ "${DRY_RUN}" -ne 1 ]]; then - if ! git diff --quiet || ! git diff --cached --quiet; then - die "Working tree is not clean; commit/stash before running e2e" - fi -fi - -if [[ -e "${FEATURE_DIR}" ]]; then - die "Feature dir already exists: ${FEATURE_DIR} (choose a different --feature)" -fi - -if git show-ref --verify --quiet "refs/heads/${ORCH_BRANCH}"; then - die "Branch already exists: ${ORCH_BRANCH} (choose a different --feature)" -fi - -log "Creating orchestration branch: ${ORCH_BRANCH}" -run git checkout -b "${ORCH_BRANCH}" - -log "Scaffolding Planning Pack (cross-platform + automation)" -scaffold_make_args=(planning-new-feature FEATURE="${FEATURE}" SLICE_PREFIX="${SLICE_PREFIX}" CROSS_PLATFORM=1 AUTOMATION=1) -if [[ "${RUN_WSL}" -eq 1 ]]; then - scaffold_make_args+=(WSL_REQUIRED=1) - if [[ "${WSL_SEPARATE}" -eq 1 ]]; then - scaffold_make_args+=(WSL_SEPARATE=1) - fi -fi -run make "${scaffold_make_args[@]}" - -TASKS_JSON="${FEATURE_DIR_ABS}/tasks.json" -SESSION_LOG="${FEATURE_DIR_ABS}/session_log.md" - -log "Writing minimal ${SLICE_ID} spec" -if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ write ${FEATURE_DIR}/${SLICE_ID}-spec.md" >&2 -else - cat >"${FEATURE_DIR_ABS}/${SLICE_ID}-spec.md" <<'MD' -# ${SLICE_ID}-spec (E2E triad smoke) - -## Scope -- Add a new workspace member crate `crates/triad_e2e_smoke_demo/`. -- Expose `pub fn answer() -> u32` returning `42`. -- Add a minimal test proving `answer() == 42`. - -## Behavior -- The crate builds on Linux/macOS/Windows. -- `cargo test -p triad_e2e_smoke_demo` passes. - -## Acceptance criteria -- `crates/triad_e2e_smoke_demo/Cargo.toml` exists and is a valid Rust crate. -- `crates/triad_e2e_smoke_demo/src/lib.rs` defines `answer()` returning `42`. -- `crates/triad_e2e_smoke_demo/tests/answer.rs` asserts `answer() == 42`. -- `cargo fmt` and `cargo clippy --workspace --all-targets -- -D warnings` succeed. - -## Out of scope -- Any behavior changes to existing Substrate functionality. -MD -fi - -log "Writing minimal ADR (with Executive Summary hash)" -ADR_PATH="${FEATURE_DIR_ABS}/ADR-0001-e2e-triad-smoke.md" -if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ write ${ADR_PATH}" >&2 -else - cat >"${ADR_PATH}" <<'MD' -# ADR-0001: E2E triad automation smoke - -## Executive Summary (Operator) - -ADR_BODY_SHA256: placeholder - -- Existing: No single scripted end-to-end run proves planning + triad automation + CI smoke wiring works together. -- New: Add a temporary Planning Pack + triad execution run that exercises worktrees, Codex headless launch, CI smoke dispatch, and final FF merge-back. -- Why: Catch workflow/automation bugs early with a deterministic, repeatable smoke scenario. - -## Decision -- Use an automation-enabled Planning Pack (tasks.json schema v3 + meta.automation.enabled=true). -- Use the cross-platform integration model (integ-core + platform-fix + final aggregator). - -## Notes -- This feature is intended for workflow validation and can be removed after debugging. -MD - python3 "${PM_SYSTEM_SCRIPTS}/planning/check_adr_exec_summary.py" --adr "${ADR_PATH}" --fix -fi - -log "Writing quality gate report (ACCEPT) and execution preflight report (ACCEPT)" -if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ write ${FEATURE_DIR}/quality_gate_report.md" >&2 - echo "+ write ${FEATURE_DIR}/execution_preflight_report.md" >&2 -else - cat >"${FEATURE_DIR_ABS}/quality_gate_report.md" <"${FEATURE_DIR_ABS}/execution_preflight_report.md" <&2 -else - cat >"${FEATURE_DIR_ABS}/kickoff_prompts/${CODE_TASK_ID}.md" < u32 { 42 }\` in \`src/lib.rs\`. -- Add the crate to the workspace (root \`Cargo.toml\` members). - -Constraints: -- Production code only; do not add tests in this task. -- Keep changes minimal and deterministic. - -Required: -- Run \`cargo fmt\` -- Run \`cargo clippy --workspace --all-targets -- -D warnings\` - -Finish: -- From inside this worktree run: \`make triad-task-finish TASK_ID="${CODE_TASK_ID}"\` -MD - - cat >"${FEATURE_DIR_ABS}/kickoff_prompts/${TEST_TASK_ID}.md" <"${FEATURE_DIR_ABS}/kickoff_prompts/${INTEG_CORE_TASK_ID}.md" <"${FEATURE_DIR_ABS}/kickoff_prompts/${task_id}.md" </dev/null 2>&1; then - task_id="${SLICE_ID}-integ-wsl" - cat >"${FEATURE_DIR_ABS}/kickoff_prompts/${task_id}.md" <"${FEATURE_DIR_ABS}/kickoff_prompts/${INTEG_TASK_ID}.md" <&2 -else - cat >"${FEATURE_DIR_ABS}/smoke/linux-smoke.sh" <<'SH' -#!/usr/bin/env bash -set -euo pipefail -echo "== E2E smoke: cargo test -p triad_e2e_smoke_demo ==" -cargo test -p triad_e2e_smoke_demo -SH - chmod +x "${FEATURE_DIR_ABS}/smoke/linux-smoke.sh" - - cat >"${FEATURE_DIR_ABS}/smoke/macos-smoke.sh" <<'SH' -#!/usr/bin/env bash -set -euo pipefail -echo "== E2E smoke: cargo test -p triad_e2e_smoke_demo ==" -cargo test -p triad_e2e_smoke_demo -SH - chmod +x "${FEATURE_DIR_ABS}/smoke/macos-smoke.sh" - - cat >"${FEATURE_DIR_ABS}/smoke/windows-smoke.ps1" <<'PS1' -Set-StrictMode -Version Latest -$ErrorActionPreference = "Stop" - -Write-Host "== E2E smoke: cargo test -p triad_e2e_smoke_demo ==" -cargo test -p triad_e2e_smoke_demo -PS1 -fi - -if [[ "${SKIP_SEQUENCING_UPDATE}" -eq 0 ]]; then - if [[ ! -f "${SEQUENCING_JSON}" ]]; then - die "Missing canonical sequencing file: ${SEQUENCING_JSON}" - fi - - log "Adding temporary sequencing.json entry (required for planning-lint): ${SEQUENCING_JSON}" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ update ${SEQUENCING_JSON}" >&2 - else - python3 - "${SEQUENCING_JSON}" "${FEATURE_DIR}" "${FEATURE}" "${ORCH_BRANCH}" "${SLICE_ID}" <<'PY' -import json -import sys -from pathlib import Path - -path = Path(sys.argv[1]) -data = json.loads(path.read_text(encoding="utf-8")) -sprints = data.get("sprints", []) -feat_dir = sys.argv[2] -feat_id = f"e2e_{sys.argv[3]}" -branch = sys.argv[4] -slice_id = sys.argv[5] - -if any(s.get("directory") == feat_dir for s in sprints if isinstance(s, dict)): - raise SystemExit("sequencing.json already has an entry for this directory") - -order = max([s.get("order", 0) for s in sprints if isinstance(s, dict) and isinstance(s.get("order"), int)] + [0]) + 1 -sprints.append( - { - "order": order, - "id": feat_id, - "title": "E2E triad automation smoke", - "branch": branch, - "directory": feat_dir, - "plan": f"{feat_dir}/plan.md", - "status": "not_started", - "sequence": [{"id": slice_id, "name": "E2E smoke slice"}], - } -) -data["sprints"] = sprints -path.write_text(json.dumps(data, indent=2) + "\n", encoding="utf-8") -PY - fi -fi - -log "Planning validation/lint (optional via flags)" -if [[ "${SKIP_PLANNING_VALIDATE}" -eq 0 ]]; then - run make planning-validate FEATURE_DIR="${FEATURE_DIR}" -fi -if [[ "${SKIP_PLANNING_LINT}" -eq 0 ]]; then - run make planning-lint FEATURE_DIR="${FEATURE_DIR}" -fi - -log "Committing Planning Pack on orchestration branch" -add_paths=("${FEATURE_DIR}") -if [[ -f "${SEQUENCING_JSON}" ]]; then - add_paths+=("${SEQUENCING_JSON}") -fi -run git add "${add_paths[@]}" || true -run git commit -m "docs: scaffold e2e triad smoke (${FEATURE})" - -if [[ "${PUSH_ORCH}" -eq 1 ]]; then - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ git push -u ${REMOTE} ${ORCH_BRANCH}" >&2 - else - if ! git remote get-url "${REMOTE}" >/dev/null 2>&1; then - die "Remote not configured: ${REMOTE}" - fi - run git push -u "${REMOTE}" "${ORCH_BRANCH}" - fi -fi - -log "Completing feature start gate task (F0-exec-preflight) on orchestration branch" -set_task_status "${TASKS_JSON}" "F0-exec-preflight" "in_progress" -append_session_log "${SESSION_LOG}" "" -append_session_log "${SESSION_LOG}" "START $(utc_now) F0-exec-preflight" -set_task_status "${TASKS_JSON}" "F0-exec-preflight" "completed" -append_session_log "${SESSION_LOG}" "END $(utc_now) F0-exec-preflight (ACCEPT)" -run git add "${TASKS_JSON}" "${SESSION_LOG}" "${FEATURE_DIR_ABS}/execution_preflight_report.md" -run git commit -m "docs: complete F0-exec-preflight (${FEATURE})" - -log "Starting ${SLICE_ID} code+test in parallel (worktrees + optional Codex headless)" -pair_cmd=(make triad-task-start-pair FEATURE_DIR="${FEATURE_DIR}" SLICE_ID="${SLICE_ID}") -if [[ "${SKIP_CODEX}" -eq 0 ]]; then pair_cmd+=(LAUNCH_CODEX=1); fi -if [[ -n "${CODEX_PROFILE}" ]]; then pair_cmd+=(CODEX_PROFILE="${CODEX_PROFILE}"); fi -if [[ -n "${CODEX_MODEL}" ]]; then pair_cmd+=(CODEX_MODEL="${CODEX_MODEL}"); fi -if [[ "${CODEX_JSONL}" -eq 1 ]]; then pair_cmd+=(CODEX_JSONL=1); fi - -pair_out="$("${pair_cmd[@]}")" -echo "${pair_out}" - -parse_kv() { - local key="$1" - local text="$2" - printf '%s' "${text}" | awk -F= -v k="${key}" '$1==k {sub($1"=","",$0); print $0}' -} - -CODE_WORKTREE="$(parse_kv CODE_WORKTREE "${pair_out}")" -TEST_WORKTREE="$(parse_kv TEST_WORKTREE "${pair_out}")" - -if [[ -z "${CODE_WORKTREE}" || -z "${TEST_WORKTREE}" ]]; then - die "Could not parse worktree paths from triad-task-start-pair output" -fi - -log "Finishing ${CODE_TASK_ID} (commit only; no merge back)" -run bash -lc "cd \"${CODE_WORKTREE}\" && make triad-task-finish TASK_ID=\"${CODE_TASK_ID}\"" - -log "Finishing ${TEST_TASK_ID} (commit only; no merge back)" -run bash -lc "cd \"${TEST_WORKTREE}\" && make triad-task-finish TASK_ID=\"${TEST_TASK_ID}\"" - -log "Marking ${CODE_TASK_ID} and ${TEST_TASK_ID} completed in tasks.json (orchestration branch)" -run git checkout "${ORCH_BRANCH}" -set_task_status "${TASKS_JSON}" "${CODE_TASK_ID}" "completed" -set_task_status "${TASKS_JSON}" "${TEST_TASK_ID}" "completed" -append_session_log "${SESSION_LOG}" "" -append_session_log "${SESSION_LOG}" "END $(utc_now) ${CODE_TASK_ID} (e2e smoke)" -append_session_log "${SESSION_LOG}" "END $(utc_now) ${TEST_TASK_ID} (e2e smoke)" -run git add "${TASKS_JSON}" "${SESSION_LOG}" -run git commit -m "docs: complete ${SLICE_ID} code+test (${FEATURE})" - -echo "" -echo "PHASE1_OK=1" -echo "FEATURE_DIR=${FEATURE_DIR}" -echo "ORCH_BRANCH=${ORCH_BRANCH}" -echo "LOG=${LOG_PATH}" +echo "ERROR: triad_e2e_phase1.sh was retired with project-management pack automation." >&2 +echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 +exit 2 diff --git a/scripts/e2e/triad_e2e_phase2.sh b/scripts/e2e/triad_e2e_phase2.sh index aa8a79311..f37e383ae 100755 --- a/scripts/e2e/triad_e2e_phase2.sh +++ b/scripts/e2e/triad_e2e_phase2.sh @@ -1,514 +1,6 @@ #!/usr/bin/env bash set -euo pipefail -usage() { - cat <<'USAGE' -Usage: - scripts/e2e/triad_e2e_phase2.sh --feature-dir [options] - -Purpose: - Phase 2 of the end-to-end triad automation smoke: - - start and finish first-slice integ-core (merge code+test into integ-core; run integ-checks) - - dispatch cross-platform smoke via GitHub Actions (self-hosted runners by default) - - optionally start platform-fix integration tasks in parallel and run per-platform smoke - - start and finish the final aggregator, re-run smoke, and fast-forward merge back to orchestration - - optionally run feature cleanup (remove retained worktrees/prune branches) - -Required: - --feature-dir Feature Planning Pack dir (docs/project_management/packs/active/) - -Options: - --remote Git remote for CI temp branches and push (default: origin) - --runner-kind github-hosted|self-hosted (default: self-hosted) - --run-wsl Include WSL coverage in smoke (requires self-hosted runners) - --workflow-ref Ref containing the workflow definition (default: meta.automation.orchestration_branch) - - --platform-fixes Force-start platform-fix tasks for these platforms (e.g., linux,macos,windows[,wsl]) - If omitted, failing platforms are auto-detected from the PLATFORM=all smoke run. - - --codex-profile

Passed to Codex (`codex exec --profile`) - --codex-model Passed to Codex (`codex exec --model`) - --codex-jsonl Capture Codex JSONL events (uses `codex exec --json`) - --skip-codex Do not launch Codex - - --push-orch Push orchestration branch after final merge-back - --cleanup Run feature cleanup at the end (worktree retention model) - --force-cleanup Pass FORCE=1 to feature cleanup - - --log-dir

Log directory (default: target/e2e//) - --dry-run Print actions; do not mutate git/worktrees -USAGE -} - -die() { - echo "ERROR: $*" >&2 - exit 2 -} - -require_cmd() { - if ! command -v "$1" >/dev/null 2>&1; then - die "Missing dependency: $1" - fi -} - -utc_now() { - date -u +%Y-%m-%dT%H:%M:%SZ -} - -python_abs_path() { - python3 - "$1" <<'PY' -import os -import sys - -p = sys.argv[1] -if os.path.isabs(p): - print(os.path.realpath(p)) -else: - print(os.path.realpath(os.path.join(os.getcwd(), p))) -PY -} - -log() { - echo "== $*" >&2 -} - -run() { - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ $*" >&2 - return 0 - fi - echo "+ $*" >&2 - "$@" -} - -set_task_status() { - local tasks_json="$1" - local task_id="$2" - local status="$3" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ set ${tasks_json} ${task_id}.status=${status}" >&2 - return 0 - fi - python3 - "${tasks_json}" "${task_id}" "${status}" <<'PY' -import json -import sys - -path, task_id, status = sys.argv[1], sys.argv[2], sys.argv[3] -with open(path, "r", encoding="utf-8") as f: - data = json.load(f) -tasks = data.get("tasks") -if not isinstance(tasks, list): - raise SystemExit("tasks.json: missing tasks[]") -for t in tasks: - if isinstance(t, dict) and t.get("id") == task_id: - t["status"] = status - break -else: - raise SystemExit(f"tasks.json: task not found: {task_id}") -tmp = path + ".tmp" -with open(tmp, "w", encoding="utf-8") as f: - json.dump(data, f, indent=2) - f.write("\n") -import os -os.replace(tmp, path) -PY -} - -append_session_log() { - local session_log="$1" - local line="$2" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ append ${session_log}: ${line}" >&2 - return 0 - fi - printf '%s\n' "${line}" >>"${session_log}" -} - -parse_kv_text() { - local key="$1" - local text="$2" - printf '%s\n' "${text}" | awk -F= -v k="${key}" '$1==k { sub(/^[^=]*=/, "", $0); print $0; exit }' -} - -task_branch() { - local tasks_json="$1" - local task_id="$2" - jq -r --arg id "${task_id}" '.tasks[] | select(.id==$id) | .git_branch' "${tasks_json}" -} - -merge_if_needed() { - local repo_dir="$1" - local branch="$2" - if git -C "${repo_dir}" merge-base --is-ancestor "${branch}" HEAD >/dev/null 2>&1; then - log "Already contains ${branch}: ${repo_dir}" - return 0 - fi - log "Merging ${branch} into $(git -C "${repo_dir}" rev-parse --abbrev-ref HEAD) at ${repo_dir}" - if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ (cd ${repo_dir} && git merge --no-edit ${branch})" >&2 - return 0 - fi - git -C "${repo_dir}" merge --no-edit "${branch}" -} - -FEATURE_DIR="" -REMOTE="origin" -RUNNER_KIND="self-hosted" -RUN_WSL=0 -WORKFLOW_REF="" -PLATFORM_FIXES_CSV="" - -CODEX_PROFILE="" -CODEX_MODEL="" -CODEX_JSONL=0 -SKIP_CODEX=0 - -PUSH_ORCH=0 -CLEANUP=0 -FORCE_CLEANUP=0 - -LOG_DIR="" -DRY_RUN=0 - -while [[ $# -gt 0 ]]; do - case "$1" in - --feature-dir) - FEATURE_DIR="${2:-}" - shift 2 - ;; - --remote) - REMOTE="${2:-}" - shift 2 - ;; - --runner-kind) - RUNNER_KIND="${2:-}" - shift 2 - ;; - --run-wsl) - RUN_WSL=1 - shift 1 - ;; - --workflow-ref) - WORKFLOW_REF="${2:-}" - shift 2 - ;; - --platform-fixes) - PLATFORM_FIXES_CSV="${2:-}" - shift 2 - ;; - --codex-profile) - CODEX_PROFILE="${2:-}" - shift 2 - ;; - --codex-model) - CODEX_MODEL="${2:-}" - shift 2 - ;; - --codex-jsonl) - CODEX_JSONL=1 - shift 1 - ;; - --skip-codex) - SKIP_CODEX=1 - shift 1 - ;; - --push-orch) - PUSH_ORCH=1 - shift 1 - ;; - --cleanup) - CLEANUP=1 - shift 1 - ;; - --force-cleanup) - FORCE_CLEANUP=1 - shift 1 - ;; - --log-dir) - LOG_DIR="${2:-}" - shift 2 - ;; - --dry-run) - DRY_RUN=1 - shift 1 - ;; - -h|--help) - usage - exit 0 - ;; - *) - die "Unknown arg: $1" - ;; - esac -done - -if [[ -z "${FEATURE_DIR}" ]]; then - usage >&2 - die "Missing --feature-dir" -fi - -case "${RUNNER_KIND}" in - github-hosted|self-hosted) ;; - *) die "Invalid --runner-kind: ${RUNNER_KIND}" ;; -esac - -require_cmd git -require_cmd jq -require_cmd rg -require_cmd python3 -require_cmd make -require_cmd gh - -if [[ "${SKIP_CODEX}" -eq 0 ]]; then - require_cmd codex -fi - -if [[ "${DRY_RUN}" -ne 1 ]]; then - if ! gh api user >/dev/null 2>&1; then - die "GitHub CLI auth is not usable (token invalid or missing). Fix with: gh auth login -h github.com (or set GH_TOKEN for non-interactive runs)." - fi -fi - -REPO_ROOT="$(git rev-parse --show-toplevel 2>/dev/null)" || die "Not in a git repo" -cd "${REPO_ROOT}" - -FEATURE_DIR_ABS="$(python_abs_path "${FEATURE_DIR}")" -TASKS_JSON="${FEATURE_DIR_ABS}/tasks.json" -SESSION_LOG="${FEATURE_DIR_ABS}/session_log.md" -if [[ ! -f "${TASKS_JSON}" ]]; then - die "Missing tasks.json: ${TASKS_JSON}" -fi - -FEATURE_NAME="$(jq -r '.meta.feature // empty' "${TASKS_JSON}")" -ORCH_BRANCH="$(jq -r '.meta.automation.orchestration_branch // empty' "${TASKS_JSON}")" -if [[ -z "${FEATURE_NAME}" || -z "${ORCH_BRANCH}" ]]; then - die "tasks.json must include meta.feature and meta.automation.orchestration_branch" -fi - -if [[ -z "${WORKFLOW_REF}" ]]; then - WORKFLOW_REF="${ORCH_BRANCH}" -fi - -SLICE_ID="$(jq -r '.tasks[] | select(.type=="code") | .phase' "${TASKS_JSON}" | head -n 1)" -if [[ -z "${SLICE_ID}" || "${SLICE_ID}" == "null" ]]; then - die "Could not infer SLICE_ID from tasks.json (expected at least one code task with .phase set)" -fi -CODE_TASK_ID="${SLICE_ID}-code" -TEST_TASK_ID="${SLICE_ID}-test" -INTEG_CORE_TASK_ID="${SLICE_ID}-integ-core" -INTEG_TASK_ID="${SLICE_ID}-integ" - -if [[ -z "${LOG_DIR}" ]]; then - LOG_DIR="target/e2e/${FEATURE_NAME}" -fi -LOG_DIR_ABS="$(python_abs_path "${LOG_DIR}")" -mkdir -p "${LOG_DIR_ABS}" -LOG_PATH="${LOG_DIR_ABS}/phase2.log" - -exec > >(tee -a "${LOG_PATH}") 2>&1 - -log "Repo: ${REPO_ROOT}" -log "Feature: ${FEATURE_DIR_ABS}" -log "Orchestration branch: ${ORCH_BRANCH}" -log "Remote: ${REMOTE}" -log "Runner kind: ${RUNNER_KIND}" -log "Workflow ref: ${WORKFLOW_REF}" -log "Log: ${LOG_PATH}" - -log "Ensuring orchestration branch exists/checked out" -run make triad-orch-ensure FEATURE_DIR="${FEATURE_DIR}" - -log "Starting ${INTEG_CORE_TASK_ID} (worktree + optional Codex headless)" -start_core=(make triad-task-start FEATURE_DIR="${FEATURE_DIR}" TASK_ID="${INTEG_CORE_TASK_ID}") -if [[ "${SKIP_CODEX}" -eq 0 ]]; then start_core+=(LAUNCH_CODEX=1); fi -if [[ -n "${CODEX_PROFILE}" ]]; then start_core+=(CODEX_PROFILE="${CODEX_PROFILE}"); fi -if [[ -n "${CODEX_MODEL}" ]]; then start_core+=(CODEX_MODEL="${CODEX_MODEL}"); fi -if [[ "${CODEX_JSONL}" -eq 1 ]]; then start_core+=(CODEX_JSONL=1); fi -core_out="$("${start_core[@]}")" -echo "${core_out}" -core_wt="$(printf '%s' "${core_out}" | awk -F= '$1=="WORKTREE"{sub($1"=","",$0); print $0}')" -if [[ -z "${core_wt}" ]]; then - die "Could not parse WORKTREE from ${INTEG_CORE_TASK_ID} task_start output" -fi - -code_branch="$(task_branch "${TASKS_JSON}" "${CODE_TASK_ID}")" -test_branch="$(task_branch "${TASKS_JSON}" "${TEST_TASK_ID}")" -core_branch="$(task_branch "${TASKS_JSON}" "${INTEG_CORE_TASK_ID}")" - -log "Merging code/test into ${INTEG_CORE_TASK_ID} worktree" -merge_if_needed "${core_wt}" "${code_branch}" -merge_if_needed "${core_wt}" "${test_branch}" - -log "Finishing ${INTEG_CORE_TASK_ID} (runs integ-checks; no merge-back)" -run bash -lc "cd \"${core_wt}\" && make triad-task-finish TASK_ID=\"${INTEG_CORE_TASK_ID}\"" - -log "Marking ${INTEG_CORE_TASK_ID} completed in tasks.json (orchestration branch)" -run git checkout "${ORCH_BRANCH}" -set_task_status "${TASKS_JSON}" "${INTEG_CORE_TASK_ID}" "completed" -append_session_log "${SESSION_LOG}" "" -append_session_log "${SESSION_LOG}" "END $(utc_now) ${INTEG_CORE_TASK_ID} (e2e smoke)" -run git add "${TASKS_JSON}" "${SESSION_LOG}" -run git commit -m "docs: complete ${INTEG_CORE_TASK_ID} (${FEATURE_NAME})" - -log "Dispatching cross-platform smoke (PLATFORM=all)" -smoke_cmd=(make feature-smoke FEATURE_DIR="${FEATURE_DIR}" PLATFORM=all RUNNER_KIND="${RUNNER_KIND}" WORKFLOW_REF="${WORKFLOW_REF}" REMOTE="${REMOTE}" CLEANUP=1) -if [[ "${RUN_WSL}" -eq 1 ]]; then smoke_cmd+=(RUN_WSL=1); fi -smoke_all_rc=0 -smoke_all_out="" -smoke_run_id_all="" -PLATFORM_FIXES_STARTED=0 -set +e -if [[ "${DRY_RUN}" -eq 1 ]]; then - echo "+ (cd ${core_wt} && ${smoke_cmd[*]})" >&2 - smoke_all_rc=0 - else - smoke_all_out="$(bash -lc "cd \"${core_wt}\" && ${smoke_cmd[*]}")" - smoke_all_rc=$? - echo "${smoke_all_out}" - smoke_run_id_all="$(parse_kv_text RUN_ID "${smoke_all_out}")" - fi -set -e - -if [[ "${smoke_all_rc}" -ne 0 && -z "${PLATFORM_FIXES_CSV}" ]]; then - if [[ -z "${smoke_run_id_all}" ]]; then - die "Cross-platform smoke failed and RUN_ID could not be parsed; re-run with --platform-fixes linux,macos,windows[,wsl]" - fi - log "Cross-platform smoke failed; auto-starting only failing platform-fix tasks from run ${smoke_run_id_all}" - pf_cmd=(make triad-task-start-platform-fixes-from-smoke FEATURE_DIR="${FEATURE_DIR}" SLICE_ID="${SLICE_ID}" SMOKE_RUN_ID="${smoke_run_id_all}") - if [[ "${SKIP_CODEX}" -eq 0 ]]; then pf_cmd+=(LAUNCH_CODEX=1); fi - if [[ -n "${CODEX_PROFILE}" ]]; then pf_cmd+=(CODEX_PROFILE="${CODEX_PROFILE}"); fi - if [[ -n "${CODEX_MODEL}" ]]; then pf_cmd+=(CODEX_MODEL="${CODEX_MODEL}"); fi - if [[ "${CODEX_JSONL}" -eq 1 ]]; then pf_cmd+=(CODEX_JSONL=1); fi - pf_out="$("${pf_cmd[@]}")" - echo "${pf_out}" - PLATFORM_FIXES_CSV="$(parse_kv_text FAILED_PLATFORMS "${pf_out}")" - if [[ -z "${PLATFORM_FIXES_CSV}" ]]; then - die "Cross-platform smoke failed but no failing platforms could be inferred from run ${smoke_run_id_all}; set --platform-fixes manually" - fi - PLATFORM_FIXES_STARTED=1 -fi - -if [[ "${smoke_all_rc}" -eq 0 && -z "${PLATFORM_FIXES_CSV}" ]]; then - log "Smoke is green and --platform-fixes not provided; completing platform-fix tasks as no-op to unblock final aggregator" - platforms_required="$(jq -r '.meta.platforms_required // [] | join(\",\")' "${TASKS_JSON}")" - wsl_required="$(jq -r '.meta.wsl_required // false' "${TASKS_JSON}")" - wsl_mode="$(jq -r '.meta.wsl_task_mode // \"bundled\"' "${TASKS_JSON}")" - PLATFORM_FIXES_CSV="${platforms_required}" - if [[ "${wsl_required}" == "true" && "${wsl_mode}" == "separate" ]]; then - if [[ -n "${PLATFORM_FIXES_CSV}" ]]; then PLATFORM_FIXES_CSV="${PLATFORM_FIXES_CSV},wsl"; else PLATFORM_FIXES_CSV="wsl"; fi - fi - - IFS=',' read -r -a platforms <<<"${PLATFORM_FIXES_CSV}" - for p in "${platforms[@]}"; do - p="$(echo "${p}" | xargs)" - [[ -z "${p}" ]] && continue - task_id="${SLICE_ID}-integ-${p}" - run git checkout "${ORCH_BRANCH}" - set_task_status "${TASKS_JSON}" "${task_id}" "completed" - append_session_log "${SESSION_LOG}" "END $(utc_now) ${task_id} (no-op; smoke green)" - run git add "${TASKS_JSON}" "${SESSION_LOG}" - run git commit -m "docs: complete ${task_id} (no-op) (${FEATURE_NAME})" - done -fi - -if [[ -n "${PLATFORM_FIXES_CSV}" ]]; then - if [[ "${PLATFORM_FIXES_STARTED}" -eq 0 ]]; then - log "Starting platform-fix tasks in parallel: ${PLATFORM_FIXES_CSV}" - pf_cmd=(make triad-task-start-platform-fixes FEATURE_DIR="${FEATURE_DIR}" SLICE_ID="${SLICE_ID}" PLATFORMS="${PLATFORM_FIXES_CSV}") - if [[ "${SKIP_CODEX}" -eq 0 ]]; then pf_cmd+=(LAUNCH_CODEX=1); fi - if [[ -n "${CODEX_PROFILE}" ]]; then pf_cmd+=(CODEX_PROFILE="${CODEX_PROFILE}"); fi - if [[ -n "${CODEX_MODEL}" ]]; then pf_cmd+=(CODEX_MODEL="${CODEX_MODEL}"); fi - if [[ "${CODEX_JSONL}" -eq 1 ]]; then pf_cmd+=(CODEX_JSONL=1); fi - pf_out="$("${pf_cmd[@]}")" - echo "${pf_out}" - PLATFORM_FIXES_STARTED=1 - fi - - IFS=',' read -r -a platforms <<<"${PLATFORM_FIXES_CSV}" - for p in "${platforms[@]}"; do - p="$(echo "${p}" | xargs)" - [[ -z "${p}" ]] && continue - task_id="${SLICE_ID}-integ-${p}" - wt_rel="$(jq -r --arg id "${task_id}" '.tasks[] | select(.id==$id) | .worktree' "${TASKS_JSON}")" - wt_abs="$(python_abs_path "${wt_rel}")" - - log "Platform-fix ${task_id}: merging integ-core branch (${core_branch})" - merge_if_needed "${wt_abs}" "${core_branch}" - - log "Platform-fix ${task_id}: per-platform smoke via CI (repeat after fixes until green)" - smoke_one=(make feature-smoke FEATURE_DIR="${FEATURE_DIR}" PLATFORM="${p}" RUNNER_KIND="${RUNNER_KIND}" WORKFLOW_REF="${WORKFLOW_REF}" REMOTE="${REMOTE}" CLEANUP=1) - if [[ "${RUN_WSL}" -eq 1 && "${p}" == "linux" ]]; then smoke_one+=(RUN_WSL=1); fi - run bash -lc "cd \"${wt_abs}\" && ${smoke_one[*]}" - - log "Platform-fix ${task_id}: finishing (commit only; no extra smoke dispatch)" - run bash -lc "cd \"${wt_abs}\" && make triad-task-finish TASK_ID=\"${task_id}\"" - - run git checkout "${ORCH_BRANCH}" - set_task_status "${TASKS_JSON}" "${task_id}" "completed" - append_session_log "${SESSION_LOG}" "END $(utc_now) ${task_id} (e2e smoke)" - run git add "${TASKS_JSON}" "${SESSION_LOG}" - run git commit -m "docs: complete ${task_id} (${FEATURE_NAME})" - done -fi - -log "Starting final aggregator (${INTEG_TASK_ID}) via wrapper (requires deps completed)" -start_final=(make triad-task-start-integ-final FEATURE_DIR="${FEATURE_DIR}" SLICE_ID="${SLICE_ID}") -if [[ "${SKIP_CODEX}" -eq 0 ]]; then start_final+=(LAUNCH_CODEX=1); fi -if [[ -n "${CODEX_PROFILE}" ]]; then start_final+=(CODEX_PROFILE="${CODEX_PROFILE}"); fi -if [[ -n "${CODEX_MODEL}" ]]; then start_final+=(CODEX_MODEL="${CODEX_MODEL}"); fi -if [[ "${CODEX_JSONL}" -eq 1 ]]; then start_final+=(CODEX_JSONL=1); fi -final_out="$("${start_final[@]}")" -echo "${final_out}" -final_wt="$(printf '%s' "${final_out}" | awk -F= '$1=="WORKTREE"{sub($1"=","",$0); print $0}')" -if [[ -z "${final_wt}" ]]; then - die "Could not parse WORKTREE from final task_start output" -fi - -log "Final aggregator: merging integ-core branch (${core_branch})" -merge_if_needed "${final_wt}" "${core_branch}" - -if [[ -n "${PLATFORM_FIXES_CSV}" ]]; then - IFS=',' read -r -a platforms <<<"${PLATFORM_FIXES_CSV}" - for p in "${platforms[@]}"; do - p="$(echo "${p}" | xargs)" - [[ -z "${p}" ]] && continue - merge_if_needed "${final_wt}" "$(task_branch "${TASKS_JSON}" "${SLICE_ID}-integ-${p}")" - done -fi - -log "Final aggregator: dispatching cross-platform smoke (PLATFORM=all)" -run bash -lc "cd \"${final_wt}\" && ${smoke_cmd[*]}" - -log "Final aggregator: finishing (runs integ-checks; merges back FF-only)" -run bash -lc "cd \"${final_wt}\" && make triad-task-finish TASK_ID=\"${INTEG_TASK_ID}\"" - -log "Marking ${INTEG_TASK_ID} completed in tasks.json (orchestration branch)" -run git checkout "${ORCH_BRANCH}" -set_task_status "${TASKS_JSON}" "${INTEG_TASK_ID}" "completed" -append_session_log "${SESSION_LOG}" "END $(utc_now) ${INTEG_TASK_ID} (e2e smoke)" -run git add "${TASKS_JSON}" "${SESSION_LOG}" -run git commit -m "docs: complete ${INTEG_TASK_ID} (${FEATURE_NAME})" - -if [[ "${PUSH_ORCH}" -eq 1 ]]; then - log "Pushing orchestration branch: ${ORCH_BRANCH} -> ${REMOTE}" - run git push "${REMOTE}" "${ORCH_BRANCH}" -fi - -if [[ "${CLEANUP}" -eq 1 ]]; then - log "Running feature cleanup (retention model)" - cleanup_cmd=(make triad-feature-cleanup FEATURE_DIR="${FEATURE_DIR}" REMOVE_WORKTREES=1 PRUNE_LOCAL=1) - if [[ "${FORCE_CLEANUP}" -eq 1 ]]; then cleanup_cmd+=(FORCE=1); fi - run "${cleanup_cmd[@]}" DRY_RUN=1 - run "${cleanup_cmd[@]}" - run git checkout "${ORCH_BRANCH}" - set_task_status "${TASKS_JSON}" "FZ-feature-cleanup" "completed" - append_session_log "${SESSION_LOG}" "END $(utc_now) FZ-feature-cleanup" - run git add "${TASKS_JSON}" "${SESSION_LOG}" - run git commit -m "docs: complete FZ-feature-cleanup (${FEATURE_NAME})" -fi - -echo "" -echo "PHASE2_OK=1" -echo "FEATURE_DIR=${FEATURE_DIR}" -echo "ORCH_BRANCH=${ORCH_BRANCH}" -echo "LOG=${LOG_PATH}" +echo "ERROR: triad_e2e_phase2.sh was retired with project-management pack automation." >&2 +echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 +exit 2 diff --git a/scripts/mac/smoke.sh b/scripts/mac/smoke.sh index 9c2195c49..2d110b411 100755 --- a/scripts/mac/smoke.sh +++ b/scripts/mac/smoke.sh @@ -728,14 +728,9 @@ run_generic_smoke() { } run_bedpm_installer_conformance() { - local smoke_cmd - - smoke_cmd="(cd /src 2>/dev/null || cd \"${REPO_ROOT}\") && bash docs/project_management/packs/draft/best-effort-distro-package-manager/smoke/linux-smoke.sh" - - log "Running BEDPM Linux smoke through the Lima-backed guest path" - "${SCRIPTS_ROOT}/lima-warm.sh" - run_gateway_lifecycle_proof - "${SUBSTRATE_BIN}" -c "${smoke_cmd}" + echo "ERROR: --bedpm-installer-conformance was retired with project-management pack automation." >&2 + echo "See docs/PROJECT_MANAGEMENT_RETIREMENT.md for the replacement workflow." >&2 + exit 2 } run_orchestration_conformance() { From 4bef4e7e602d0bac4ddc373349431bef4151b419 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 14:08:45 -0400 Subject: [PATCH 12/20] Retire pack wrapper assertions and repoint contract docs --- docs/BACKLOG.md | 2 +- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 33 +++++++++++++------ .../gateway/backend-adapter-protocol.md | 1 - .../gateway/backend-adapter-schema.md | 2 +- docs/contracts/gateway/runtime-parity.md | 2 +- .../installers/pkg_manager_detection_smoke.sh | 26 --------------- 6 files changed, 26 insertions(+), 40 deletions(-) diff --git a/docs/BACKLOG.md b/docs/BACKLOG.md index 8cc5c34b1..766ad096c 100644 --- a/docs/BACKLOG.md +++ b/docs/BACKLOG.md @@ -65,7 +65,7 @@ Keep concise, actionable, and security-focused. - Acceptance: parity with `policy global show` UX; message is shown only when a workspace override applies; docs/help updated if needed. - **P1 – World-sync continuation (internal git v2: per-command history + compaction)** - - Context: `docs/project_management/packs/active/world-sync/` implements host-only `workspace checkpoint`/`workspace rollback` via `.substrate/git/repo.git/` and explicitly does not implement the richer internal history described in `docs/project_management/future/INTERNAL_GIT.md`. + - Context: the current workspace-sync implementation provides host-only `workspace checkpoint`/`workspace rollback` via `.substrate/git/repo.git/` and explicitly does not implement the richer internal history described in `docs/project_management/future/INTERNAL_GIT.md`. - Work: - Record per-command internal git commits for filesystem-mutating commands and persist a mapping (trace span / command id ↔ internal git commit) for review/debug. - Add session/checkpoint tagging semantics and user-facing UX for undo/rollback at multiple resolutions (command / checkpoint / session). diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 20e405f47..c6f8bceb1 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -58,8 +58,8 @@ Completed extraction/rewrite slices: Still remaining before the atomic top-level `packs/**` removal: - repo-wide reference scan still finds non-pack-tree references to `docs/project_management/packs/**` -- the remaining refs are now concentrated in historical/root docs plus a small number of live - wrappers that still point at pack-owned artifacts +- the remaining refs are now concentrated in historical/root docs and in-progress + `docs/project_management/**` material rather than live shell wrappers Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` @@ -77,6 +77,8 @@ Validation already completed for the finished slices: - scoped reference scans over `Makefile`, `.github/workflows/feature-smoke.yml`, and the targeted triad / smoke / CI helper scripts no longer show `docs/project_management/packs/**` or `tasks.json` assumptions +- scoped reference scans over `docs/contracts/gateway/*.md` and `docs/BACKLOG.md` no longer show + pack-path backlinks for the stable contract and backlog surfaces cleaned in this slice ## Current Dependency Classes @@ -98,18 +100,28 @@ Completed retirements/replacements: - `scripts/mac/smoke.sh` - BEDPM installer conformance mode is now retired instead of shelling through a pack-owned smoke wrapper +- `tests/installers/pkg_manager_detection_smoke.sh` + - removed the obsolete assertion that a pack-owned BEDPM smoke wrapper still exists +- `docs/contracts/gateway/backend-adapter-protocol.md` +- `docs/contracts/gateway/backend-adapter-schema.md` +- `docs/contracts/gateway/runtime-parity.md` + - removed pack-spec backlinks from stable gateway contract verification surfaces +- `docs/BACKLOG.md` + - removed the remaining direct pack-path context note from the world-sync backlog entry Remaining dependency surface after the repo-wide scan: -- `tests/installers/pkg_manager_detection_smoke.sh` - - still points at a pack-owned smoke wrapper - root and historical docs outside `docs/project_management/packs/**` - - examples include `docs/BACKLOG.md`, `llm-last-mile/**`, `FSE_PRE_PLANNING_*`, and archived - planning notes that still cite pack paths + - examples now concentrate in `llm-last-mile/**`, `FSE_PRE_PLANNING_*`, and archived planning + notes that still cite pack paths +- in-progress `docs/project_management/**` planning and ADR material + - these references still need explicit triage as either acceptable retained planning history or + blockers that must be repointed before the atomic cut Disposition: -- rewrite or retire any still-live scripts/tests - classify root/historical docs as either intentional history or blockers that must be rewritten before the atomic cut +- keep narrowing stable/root surfaces first so the remaining scan result is dominated by clearly + historical or intentionally retained planning material ### 2. Rust tests and code that hard-read pack markdown @@ -264,9 +276,10 @@ Remaining follow-up: Use this order in the next session: 1. Triage the remaining non-pack-tree references surfaced by the repo-wide scan. - - Start with `tests/installers/pkg_manager_detection_smoke.sh`. - - Then classify root-level docs such as `docs/BACKLOG.md`, `llm-last-mile/**`, and - `FSE_PRE_PLANNING_*` into: + - Start with root-level and historical docs such as `llm-last-mile/**` and + `FSE_PRE_PLANNING_*`. + - Also classify in-progress `docs/project_management/**` references that are outside + `packs/**` into: - intentional historical notes - blockers that still need rewrites 2. Re-run the repo-wide reference scan after those rewrites. diff --git a/docs/contracts/gateway/backend-adapter-protocol.md b/docs/contracts/gateway/backend-adapter-protocol.md index e0a20ca5b..44a6b381e 100644 --- a/docs/contracts/gateway/backend-adapter-protocol.md +++ b/docs/contracts/gateway/backend-adapter-protocol.md @@ -87,7 +87,6 @@ The local-to-external handoff is explicit: The implementation and verification surfaces for this contract are expected to stay aligned across: -- `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md` - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `crates/gateway/src/adapter_runtime.rs` - `crates/shell/src/execution/prompt_fulfillment.rs` diff --git a/docs/contracts/gateway/backend-adapter-schema.md b/docs/contracts/gateway/backend-adapter-schema.md index 9baa9a23b..ef2feeb11 100644 --- a/docs/contracts/gateway/backend-adapter-schema.md +++ b/docs/contracts/gateway/backend-adapter-schema.md @@ -182,7 +182,7 @@ Rules: The implementation and verification surfaces for this contract are expected to stay aligned across: -- `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md` +- `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - the Unified Agent API capability, extension, run-protocol, and event-envelope specs cited by ADR-0041 - the built-in backend capability and session-handle tests cited by the seam-local schema spec diff --git a/docs/contracts/gateway/runtime-parity.md b/docs/contracts/gateway/runtime-parity.md index 78e7c3f28..d9b60cfc0 100644 --- a/docs/contracts/gateway/runtime-parity.md +++ b/docs/contracts/gateway/runtime-parity.md @@ -67,5 +67,5 @@ The later execution slices must keep the runtime/parity contract aligned across - `crates/world-service/tests/socket_activation.rs` - `crates/transport-api-types/src/lib.rs` - `crates/transport-api-client/src/lib.rs` -- `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md` +- `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/WORLD.md` diff --git a/tests/installers/pkg_manager_detection_smoke.sh b/tests/installers/pkg_manager_detection_smoke.sh index 8ba5f268d..3350de9d0 100755 --- a/tests/installers/pkg_manager_detection_smoke.sh +++ b/tests/installers/pkg_manager_detection_smoke.sh @@ -70,17 +70,6 @@ assert_not_contains() { fi } -assert_file_contains() { - local path="$1" - local needle="$2" - local label="$3" - - if ! grep -Fq -- "${needle}" "${path}"; then - printf '[pkg-manager-detection-smoke] expected %s (%s) to contain %q\n' "${label}" "${path}" "${needle}" >&2 - exit 1 - fi -} - assert_contains_once() { local haystack="$1" local needle="$2" @@ -252,19 +241,6 @@ run_no_manager_without_sudo_case() { ensure_linux_packages_for_commands curl tar } -assert_smoke_wrapper_topology() { - local smoke_wrapper="${repo_root}/docs/project_management/packs/draft/best-effort-distro-package-manager/smoke/linux-smoke.sh" - - assert_file_contains \ - "${smoke_wrapper}" \ - 'HARNESS_PATH="${REPO_ROOT}/tests/installers/pkg_manager_detection_smoke.sh"' \ - "smoke wrapper harness path" - assert_file_contains \ - "${smoke_wrapper}" \ - 'exec bash "${HARNESS_PATH}" "$@"' \ - "smoke wrapper exec pass-through" -} - tmpdir="$(mktemp -d -t substrate-pkg-manager-detection.XXXXXX)" trap 'rm -rf "${tmpdir}"' EXIT @@ -362,8 +338,6 @@ BLA::start_loading_animation() { :; } BLA::stop_loading_animation() { :; } EOF -assert_smoke_wrapper_topology - unset SUBSTRATE_INSTALL_OS_RELEASE_PATH resolve_selected_os_release_input assert_selected "/etc/os-release" From 25f43549c95d75b54d974ecea1febdfa82ba80ff Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 15:06:25 -0400 Subject: [PATCH 13/20] Promote curated ADRs into stable docs --- .../evidence/manifest.json | 2 +- .../evidence/manifest.json | 32 ++--- .../evidence/manifest.json | 2 +- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 124 +++++++++++++++--- docs/adr/CURATION.md | 102 ++++++++++++++ docs/adr/README.md | 48 +++++++ docs/adr/draft/README.md | 7 + docs/adr/historical/README.md | 6 + ...027-llm-and-agent-config-policy-surface.md | 70 ++++++++++ ...-gateway-boundary-and-runtime-ownership.md | 69 ++++++++++ ...strate-gateway-backend-adapter-contract.md | 62 +++++++++ ...t-identity-tuple-and-deployment-posture.md | 72 ++++++++++ ...-adr-0027-identity-tuple-policy-surface.md | 64 +++++++++ ...y-backend-selection-runtime-integration.md | 66 ++++++++++ docs/adr/implemented/README.md | 15 +++ .../gateway/backend-adapter-protocol.md | 2 +- .../gateway/backend-adapter-schema.md | 2 +- .../gateway/backend-adapter-selection.md | 2 +- docs/contracts/gateway/runtime-parity.md | 2 +- .../PROVISIONING_SURFACE_RECONCILIATION.md | 17 +-- docs/project_management/adrs/README.md | 9 ++ ...DR-0023-in-world-llm-gateway-front-door.md | 8 +- .../ADR-0024-cli-backend-provider-engine.md | 4 +- .../ADR-0025-agent-hub-core-role-swappable.md | 2 +- .../ADR-0026-orchestration-toolbox-mcp.md | 2 +- ...027-llm-and-agent-config-policy-surface.md | 14 +- ...-gateway-boundary-and-runtime-ownership.md | 10 +- ...strate-gateway-backend-adapter-contract.md | 10 +- ...t-identity-tuple-and-deployment-posture.md | 10 +- ...-adr-0027-identity-tuple-policy-surface.md | 10 +- ...y-backend-selection-runtime-integration.md | 10 +- ...11-world-deps-packages-bundles-contract.md | 10 +- ...fig-schema-per-key-merge-and-provenance.md | 4 +- 33 files changed, 791 insertions(+), 78 deletions(-) create mode 100644 docs/adr/CURATION.md create mode 100644 docs/adr/README.md create mode 100644 docs/adr/draft/README.md create mode 100644 docs/adr/historical/README.md create mode 100644 docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md create mode 100644 docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md create mode 100644 docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md create mode 100644 docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md create mode 100644 docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md create mode 100644 docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md create mode 100644 docs/adr/implemented/README.md diff --git a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json index 34c7b4881..da1b348ec 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json +++ b/crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/manifest.json @@ -4,7 +4,7 @@ "contract_ref": "docs/foundation/azure-foundry-c08-operator-verification-contract.md", "runbook_ref": "gateway/README.md", "env_source_ref": "gateway/.env", - "smoke_config_ref": "docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/temp-config.redacted.example.toml", + "smoke_config_ref": "crates/gateway/docs/project_management/packs/active/azure-foundry-provider-transport/threaded-seams/seam-2-azure-live-smoke-operator-readiness/evidence/temp-config.redacted.example.toml", "gateway_base_url_shape": "https:///openai/v1", "config_notes": [ "the live run used a temporary config outside the repo", diff --git a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json index eb0de1bb7..9c87c922e 100644 --- a/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json +++ b/crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/manifest.json @@ -3,16 +3,16 @@ "slice_id": "S2", "generated_on": "2026-03-27", "contract_ref": "docs/foundation/azure-kimi-c02-normalized-event-contract.md", - "variant_notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md", + "variant_notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/variant-notes.md", "cases": [ { "case_id": "explicit-tool-calls-k2-thinking-stream", "classification": "explicit_tool_calls", "model": "Kimi-K2-Thinking", "stream": true, - "raw_request_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-request.json", - "raw_response_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-response.json", - "notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/notes.md", + "raw_request_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-request.json", + "raw_response_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/raw-response.json", + "notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/explicit-tool-calls-k2-thinking-stream/notes.md", "fixture_ref": "gateway/tests/fixtures/azure_kimi/explicit-tool-calls-k2-thinking-stream.json" }, { @@ -20,9 +20,9 @@ "classification": "hidden_marker_tool_calls", "model": "Kimi-K2-Thinking", "stream": true, - "raw_request_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-request.json", - "raw_response_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json", - "notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/notes.md", + "raw_request_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-request.json", + "raw_response_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/raw-response.json", + "notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-stream/notes.md", "fixture_ref": "gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-stream.json" }, { @@ -30,9 +30,9 @@ "classification": "hidden_marker_tool_calls", "model": "Kimi-K2-Thinking", "stream": false, - "raw_request_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-request.json", - "raw_response_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-response.json", - "notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/notes.md", + "raw_request_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-request.json", + "raw_response_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/raw-response.json", + "notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/hidden-markers-k2-thinking-nonstream/notes.md", "fixture_ref": "gateway/tests/fixtures/azure_kimi/hidden-markers-k2-thinking-nonstream.json" }, { @@ -40,9 +40,9 @@ "classification": "mixed_reasoning_and_tool_calls", "model": "Kimi-K2-Thinking", "stream": false, - "raw_request_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-request.json", - "raw_response_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-response.json", - "notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/notes.md", + "raw_request_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-request.json", + "raw_response_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/raw-response.json", + "notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/mixed-reasoning-and-tool-calls-k2-thinking/notes.md", "fixture_ref": "gateway/tests/fixtures/azure_kimi/mixed-reasoning-and-tool-calls-k2-thinking.json" }, { @@ -50,9 +50,9 @@ "classification": "no_tool_control", "model": "Kimi-K2.5", "stream": true, - "raw_request_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-request.json", - "raw_response_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-response.json", - "notes_ref": "docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/notes.md", + "raw_request_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-request.json", + "raw_response_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/raw-response.json", + "notes_ref": "crates/gateway/docs/project_management/packs/active/azure-kimi-claude-gateway/threaded-seams/seam-2-azure-kimi-normalization/evidence/cases/no-tool-control-k2-5-stream/notes.md", "fixture_ref": "gateway/tests/fixtures/azure_kimi/no-tool-control-k2-5-stream.json" } ] diff --git a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json index 92245bce0..2f7cc443b 100644 --- a/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json +++ b/crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/threaded-seams/seam-2-live-session-smoke-verification/evidence/manifest.json @@ -5,7 +5,7 @@ "evidence_kind": "repo_backed_and_operator_run_governance_proof", "contract_ref": "docs/foundation/claude-code-c10-live-session-smoke-verification-contract.md", "procedure_ref": "docs/foundation/claude-code-c10-live-session-smoke-procedure.md", - "closeout_ref": "docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md", + "closeout_ref": "crates/gateway/docs/project_management/packs/active/claude-code-live-integration-smoke/governance/seam-2-closeout.md", "runbook_ref": "gateway/README.md", "limitations": [ "The tracked trace file preserves the route evidence for the three-branch Claude Code smoke, but the matching last_routing.json from that run is not preserved as a tracked repo artifact.", diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index c6f8bceb1..2df2a01ac 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -13,11 +13,15 @@ In scope: Out of scope for this cut: - `crates/gateway/docs/project_management/**` -- the ADR registry under `docs/project_management/adrs/**` Current recommendation for ADRs: -- keep the full ADR registry in place during the pack retirement -- decide later whether to move or curate ADRs into a new stable `docs/adr/` tree +- treat ADR curation into a stable `docs/adr/` tree as the next strategic milestone +- do not blindly move every ADR; curate them first +- expect some ADRs still labeled `draft` to be effectively implemented and needing promotion or + restatement into the stable ADR tree +- the initial curation policy and first-cluster classification now live in: + - `docs/adr/README.md` + - `docs/adr/CURATION.md` ## Constraints @@ -60,6 +64,19 @@ Still remaining before the atomic top-level `packs/**` removal: - repo-wide reference scan still finds non-pack-tree references to `docs/project_management/packs/**` - the remaining refs are now concentrated in historical/root docs and in-progress `docs/project_management/**` material rather than live shell wrappers +- `llm-last-mile/**` and `FSE_PRE_PLANNING_*` are intentionally deferred for now and should not + drive the next slice ordering +- the highest-value next namespace decision is ADR curation, because repeated backlink cleanup + inside `docs/project_management/adrs/**` has diminishing returns while the long-term destination + is now known to be `docs/adr/` +- the curation-policy question is now resolved for the first slice: + - use `restate + supersede`, not a blind directory move + - promote first-cluster keepers into `docs/adr/implemented/` +- the first-cluster promotion slice is now complete: + - curated implemented ADRs exist for ADR-0027, ADR-0040, ADR-0041, ADR-0042, ADR-0043, and + ADR-0046 + - stable gateway contract docs now point at curated implemented ADRs instead of the old draft + project-management paths Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` @@ -79,6 +96,35 @@ Validation already completed for the finished slices: `tasks.json` assumptions - scoped reference scans over `docs/contracts/gateway/*.md` and `docs/BACKLOG.md` no longer show pack-path backlinks for the stable contract and backlog surfaces cleaned in this slice +- scoped rewrites under `docs/project_management/adrs/**` now point ADR-0027 foundation references + at `docs/reference/policy/{contract,schema}.md`, and the provisioning reconciliation note now + points at stable world-deps references instead of implemented pack contracts +- the remaining direct pack-contract citations under `docs/project_management/adrs/**` are now + concentrated in draft provisioning ADRs that still cite their own feature-pack contract surfaces + (`ADR-0030`, `ADR-0033`) +- initial gateway-local manifest normalization under + `crates/gateway/docs/project_management/**` now uses monorepo-correct + `crates/gateway/docs/project_management/packs/**` refs in evidence payloads that previously + looked like top-level `docs/project_management/packs/**` backlinks +- stable ADR scaffolding now exists under: + - `docs/adr/` + - `docs/adr/implemented/` + - `docs/adr/draft/` + - `docs/adr/historical/` +- the first ADR curation ledger now exists at `docs/adr/CURATION.md` +- the first promoted cluster has been classified as stable keepers: + - ADR-0027 + - ADR-0040 + - ADR-0041 + - ADR-0042 + - ADR-0043 + - ADR-0046 +- those first-cluster ADRs were classified as `draft_but_implemented` before promotion so their + stable curated ADRs could normalize status away from `Draft` +- curated implemented ADR files now exist for that cluster under `docs/adr/implemented/` +- stable gateway contract verification docs now reference curated implemented ADR paths for: + - ADR-0040 + - ADR-0041 ## Current Dependency Classes @@ -116,12 +162,18 @@ Remaining dependency surface after the repo-wide scan: - in-progress `docs/project_management/**` planning and ADR material - these references still need explicit triage as either acceptable retained planning history or blockers that must be repointed before the atomic cut +- `crates/gateway/docs/project_management/**` + - remaining hits are mostly gateway-local self-references and planning-pack internals; continue + normalizing any monorepo-incorrect `docs/project_management/packs/**` payload refs as they are + found Disposition: - classify root/historical docs as either intentional history or blockers that must be rewritten before the atomic cut - keep narrowing stable/root surfaces first so the remaining scan result is dominated by clearly historical or intentionally retained planning material +- for the current slice ordering, defer `llm-last-mile/**` and `FSE_PRE_PLANNING_*` and focus on + `docs/project_management/**` plus gateway-local `project_management/**` cleanup ### 2. Rust tests and code that hard-read pack markdown @@ -271,28 +323,66 @@ Remaining follow-up: - any stable operator or internal doc that cites a pack path as canonical - any future gateway-local planning edits that reintroduce links to deleted top-level pack paths +## ADR Curation Milestone + +Before the broader `docs/project_management/**` retirement can finish cleanly, curate the ADR set +that still matters into a stable `docs/adr/` home. + +Recommended order: + +1. Define ADR keep criteria. + - Keep ADRs that are still normative, implemented, referenced by stable docs/code, or still + define a current operator/runtime contract. +2. Classify the ADR set. + - Use buckets: + - keep as stable ADR + - keep as historical only + - superseded + - draft-but-implemented + - draft-and-actually-still-draft +3. Create the `docs/adr/` structure. + - Likely: + - `docs/adr/implemented` + - `docs/adr/draft` + - optional `docs/adr/historical` +4. Promote the real keepers. + - Move or restate the curated ADRs into `docs/adr/**`. + - Normalize statuses so “draft but actually implemented” is no longer ambiguous. +5. Repoint stable references to `docs/adr/**`. + - Once stable docs and current contracts point at `docs/adr/**`, the remaining + `docs/project_management/adrs/**` content becomes much easier to archive or delete. + +Completed in this slice: + +- defined keep criteria and migration policy in `docs/adr/README.md` +- created the stable `docs/adr/{implemented,draft,historical}/` structure +- classified the first contract-heavy ADR cluster in `docs/adr/CURATION.md` +- promoted the first contract-heavy ADR cluster into `docs/adr/implemented/` +- repointed stable gateway contract docs to the curated implemented ADR paths +- added relocation notes on the legacy project-management ADRs retained for compatibility + ## Recommended Resume Order Use this order in the next session: -1. Triage the remaining non-pack-tree references surfaced by the repo-wide scan. - - Start with root-level and historical docs such as `llm-last-mile/**` and - `FSE_PRE_PLANNING_*`. - - Also classify in-progress `docs/project_management/**` references that are outside - `packs/**` into: - - intentional historical notes - - blockers that still need rewrites -2. Re-run the repo-wide reference scan after those rewrites. - - Goal: confirm that only intentionally retained historical notes still mention - `docs/project_management/packs/**`. -3. Prepare the atomic `packs/**` deletion once the remaining refs are either rewritten or - explicitly accepted as historical holdouts. +1. Repoint live ADR-to-ADR prerequisite links to the curated implemented ADR paths. + - Focus on current, still-live consumers before touching broader planning-pack history. +2. Reclassify and promote the next ADR cluster. + - Keep the provisioning ADR decision around ADR-0030 and ADR-0033 as its own narrower slice. +3. Continue narrowing the remaining `docs/project_management/**` dependency surface after the + stable ADR consumers stop pointing at the retiring namespace. ## Resume Notes - Do not start by deleting any pack directories. -- The next correct move is repo-wide residual-reference triage, not another stable-doc extraction - pass. +- The first-cluster ADR promotion slice is complete. +- The next correct move is targeted repointing of live ADR-to-ADR prerequisites plus + classification of the next cluster, not another broad stable-doc extraction pass. +- Treat the repo-wide `docs/project_management/**` cleanup as subordinate to that ADR curation + milestone; otherwise you risk repeatedly repointing docs toward a namespace that is still meant + to be retired. +- The curation-policy and first-cluster-classification questions are no longer open; use the + recorded policy and ledger under `docs/adr/**` rather than re-deciding them in a later session. - The top-level `packs/**` tree must be removed in one cut only after: - stable docs are repointed, - pack-reading tests are rewritten or deleted, diff --git a/docs/adr/CURATION.md b/docs/adr/CURATION.md new file mode 100644 index 000000000..5fd29791d --- /dev/null +++ b/docs/adr/CURATION.md @@ -0,0 +1,102 @@ +# ADR Curation Ledger + +This ledger records the curation rules and the current classification state for ADRs that may move +from `docs/project_management/adrs/**` into the stable `docs/adr/**` tree. + +## Classification Axes + +Every ADR under review is classified on two axes: + +1. Curation disposition + - `stable_keeper`: belongs in `docs/adr/**` + - `historical_only`: keep only as history or audit trail + - `superseded`: retained only as a replaced decision record +2. Implementation posture + - `implemented` + - `draft_but_implemented` + - `still_draft` + +`draft_but_implemented` is the key normalization bucket for this repo because multiple ADRs still +say `Status: Draft` while stable docs, code, and tests already rely on their decisions. + +## Keep Criteria + +Promote an ADR into `docs/adr/**` when one or more of these conditions hold: + +- it defines a current operator-facing contract that stable docs already expose +- it defines a runtime boundary or data model that current code already implements +- stable docs, tests, or contract references still use the ADR number as an authority anchor +- later ADRs still depend on it as an active prerequisite rather than only historical context + +Do not promote an ADR yet when it is primarily: + +- a planning-pack wrapper around already-extracted stable docs +- a feature-local execution plan rather than a durable architectural decision +- a superseded proposal whose current value is only historical context + +## Migration Policy + +- Preferred strategy: `restate + supersede` +- Stable target tree: + - `docs/adr/implemented/` + - `docs/adr/draft/` + - `docs/adr/historical/` +- Promotion order: + 1. curate stable keepers with current operator/runtime contract weight + 2. repoint stable references to `docs/adr/**` + 3. leave compatibility stubs in `docs/project_management/adrs/**` only where older planning or + archive material still needs a breadcrumb + +## First Cluster: Policy and Gateway Contract ADRs + +This is the first high-value cluster called out by the retirement tracker. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0027 | `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` | `stable_keeper` | `draft_but_implemented` | Stable policy contract/schema docs already exist under `docs/reference/policy/**`, broker and shell config/policy models implement the surface, and multiple later ADRs still treat ADR-0027 as the root contract. | +| ADR-0040 | `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` | `stable_keeper` | `draft_but_implemented` | The gateway operator contract is already published under `docs/contracts/gateway/operator-contract.md`, and shell/world-service lifecycle code plus tests implement the named gateway command family and ownership boundary. | +| ADR-0041 | `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` | `stable_keeper` | `draft_but_implemented` | Stable gateway backend-selection docs exist, `llm.routing.default_backend` is implemented in config models, and gateway runtime code already carries adapter-style backend bindings beyond a planning-only statement. | +| ADR-0042 | `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` | `stable_keeper` | `draft_but_implemented` | The tuple and placement-posture surfaces are already reflected in gateway lifecycle/status code and tests, and later docs treat ADR-0042 as the semantic owner of tuple meaning. | +| ADR-0043 | `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` | `stable_keeper` | `draft_but_implemented` | Stable tuple-constraint docs exist under `docs/reference/policy/tuple_constraints.md`, and broker/shell policy models already parse and validate `llm.constraints.*`. | +| ADR-0046 | `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` | `stable_keeper` | `draft_but_implemented` | Although written as a thin implementation follow-on, the gateway runtime and shell lifecycle code already implement inventory-backed default-backend handling, integrated auth shaping, and multi-backend runtime wiring. | + +## First-Cluster Decision + +The first cluster belongs in `docs/adr/implemented/`, not in a long-lived draft bucket. + +Rationale: + +- Each ADR still defines active product/runtime truth. +- Each ADR already has stable downstream references, code touchpoints, or both. +- Leaving them under `docs/project_management/adrs/draft/**` preserves an inaccurate signal about + implementation maturity and keeps stable references pointed at a namespace scheduled for + retirement. + +## Promoted In This Slice + +The following curated ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` +- `docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md` + +## Explicit Non-Decisions In This Slice + +- This ledger does not yet classify the full ADR registry. +- The legacy project-management ADR files remain in place with relocation notes; this slice does + not yet archive or delete those historical source files. +- This ledger does not yet decide the final disposition of provisioning ADRs `ADR-0030` and + `ADR-0033`; they remain separate because their pack-owned contract references may still be + intentional until that narrower provisioning cluster is curated. + +## Next Resume Slice + +Next, continue with: + +1. repoint live ADR-to-ADR prerequisite links that should follow the curated implemented paths +2. classify and promote the next ADR cluster +3. keep provisioning ADRs `ADR-0030` and `ADR-0033` separate until that narrower cluster is + explicitly curated diff --git a/docs/adr/README.md b/docs/adr/README.md new file mode 100644 index 000000000..9c42422e9 --- /dev/null +++ b/docs/adr/README.md @@ -0,0 +1,48 @@ +# ADR Tree + +This directory is the stable home for curated Architecture Decision Records that still matter to +the current Substrate product, runtime, and operator contract. + +Use this tree for ADRs that should survive the retirement of `docs/project_management/**`. + +## Structure + +- `docs/adr/implemented/` + - Curated ADRs whose decisions are accepted and materially reflected in shipped code, stable + contract docs, or operator/runtime behavior. +- `docs/adr/draft/` + - Curated ADRs that are still active design inputs but are not implemented yet. +- `docs/adr/historical/` + - Curated ADRs kept only for historical reasoning, supersession context, or audit trail. + +## Curation Policy + +- Do not blindly move every ADR from `docs/project_management/adrs/**`. +- Curate first, then promote only the keepers. +- Keep an ADR in this tree only when at least one of these is true: + - it remains normative for the current product, runtime, or operator contract + - it is implemented and still explains current behavior + - stable docs or code still depend on it as a named decision anchor + - it records a still-relevant supersession boundary +- Leave planning-only or pack-coupled artifacts in `docs/project_management/**` until they are + either promoted here or intentionally archived. + +## Migration Rule + +Use `restate + supersede`, not a blind filesystem move, when curating ADRs out of +`docs/project_management/adrs/**`. + +That means: + +1. Create the curated ADR under `docs/adr/**`. +2. Rewrite it so links and status reflect the stable post-project-management world. +3. Leave a short compatibility stub or supersession note behind in + `docs/project_management/adrs/**` when existing planning/history docs still point there. +4. Repoint stable docs and current contracts to `docs/adr/**`. + +This avoids dragging planning-pack assumptions, feature-directory references, and stale status +labels into the stable ADR tree unchanged. + +## Current Ledger + +The active classification ledger lives in `docs/adr/CURATION.md`. diff --git a/docs/adr/draft/README.md b/docs/adr/draft/README.md new file mode 100644 index 000000000..f13879ef9 --- /dev/null +++ b/docs/adr/draft/README.md @@ -0,0 +1,7 @@ +# Draft ADRs + +This directory holds curated ADRs that remain active architectural input but are not implemented +yet. + +It is intentionally narrower than `docs/project_management/adrs/draft/`, which also contains +planning-heavy ADRs that may never be promoted here. diff --git a/docs/adr/historical/README.md b/docs/adr/historical/README.md new file mode 100644 index 000000000..6cde898f6 --- /dev/null +++ b/docs/adr/historical/README.md @@ -0,0 +1,6 @@ +# Historical ADRs + +This directory holds curated ADRs kept only for historical context, supersession boundaries, or +audit trail. + +Do not treat files here as current operator or runtime truth. diff --git a/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md b/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md new file mode 100644 index 000000000..92c642cd4 --- /dev/null +++ b/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md @@ -0,0 +1,70 @@ +# ADR-0027 — LLM and Agent Config/Policy Surface + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-03 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Substrate's LLM and agent surfaces must reuse the existing layered config and policy files rather +than introducing a second config system. + +The stable decision is: + +- config lives in `$SUBSTRATE_HOME/config.yaml` and `/.substrate/workspace.yaml` +- policy lives in `$SUBSTRATE_HOME/policy.yaml` and `/.substrate/policy.yaml` +- agent inventory lives in `$SUBSTRATE_HOME/agents/.yaml` and + `/.substrate/agents/.yaml` +- unknown keys are hard errors +- invalid values are hard errors +- routing remains fail-closed by default +- backend allowlists remain deny-by-default +- backend ids remain adapter selectors only, not overloaded identity labels +- secrets must not be stored in Substrate YAML patches + +## Stable Owned Surface + +The stable operator-facing and schema-facing references for this ADR are: + +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` +- `docs/reference/policy/tuple_constraints.md` for the additive ADR-0043 extension + +## Current Implementation Anchors + +The decision is materially implemented and enforced through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/policy_model.rs` +- `crates/broker/src/policy.rs` +- `crates/broker/src/effective_policy.rs` +- `crates/broker/src/tests.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` +- Historical predecessors kept for context: + - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` + - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` + - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` + - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + +## Historical Note + +The original ADR includes planning-pack scope, slice references, and feature-local execution +context that do not belong in the stable ADR tree. Keep using the curated references above for +current contract truth. diff --git a/docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md b/docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md new file mode 100644 index 000000000..2390e1fe1 --- /dev/null +++ b/docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md @@ -0,0 +1,69 @@ +# ADR-0040 — Substrate Gateway Boundary and Runtime Ownership + +## Status + +- Status: Implemented +- Original date (UTC): 2026-04-02 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Substrate owns the trusted boundary around integrated gateway operation, while +`substrate-gateway` owns the in-world runtime behind that boundary. + +Substrate owns: + +- policy evaluation +- world placement +- lifecycle control +- host-to-world secret delivery +- operator UX +- canonical tracing + +`substrate-gateway` owns: + +- the in-world front door +- provider, planner, and executor internals +- normalized event generation inside the runtime + +This split prevents gateway-local internals from silently becoming Substrate policy or operator +contract truth. + +## Stable Owned Surface + +The stable references for this ADR are: + +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/status-schema.md` +- `docs/contracts/gateway/runtime-parity.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/world_gateway.rs` +- `crates/world-service/src/gateway_runtime.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/world_gateway.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- Historical predecessor kept for context: + - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` + +## Historical Note + +The original ADR contains pack-local planning context and external evidence links that remain +useful historically, but the stable ownership boundary lives here and in the gateway contract docs. diff --git a/docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md b/docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md new file mode 100644 index 000000000..87f60dd76 --- /dev/null +++ b/docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md @@ -0,0 +1,62 @@ +# ADR-0041 — Substrate Gateway Backend Adapter Contract + +## Status + +- Status: Implemented +- Original date (UTC): 2026-04-02 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Substrate selects and allowlists one stable backend id in `:` form, then hands that +selection to a gateway-owned adapter boundary. + +The stable decision is: + +- backend ids are selector ids only +- one backend id maps to one adapter identity at the Substrate boundary +- selection uses the ADR-0027 config, policy, and inventory surfaces +- allowlisting happens before adapter dispatch +- gateway-local adapter internals remain implementation detail +- provider quirks, wrapper mechanics, and session details must not leak into the stable policy + surface + +## Stable Owned Surface + +The stable references for this ADR are: + +- `docs/contracts/gateway/backend-adapter-selection.md` +- `docs/contracts/gateway/backend-adapter-protocol.md` +- `docs/contracts/gateway/backend-adapter-schema.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/policy_model.rs` +- `crates/shell/src/builtins/world_gateway.rs` +- `crates/world-service/src/gateway_runtime.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md` +- Historical predecessor kept for context: + - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` + +## Historical Note + +The original ADR includes planning-pack and external evidence material that remains useful as +historical context, but stable backend-selection and adapter-contract truth now lives here and in +the gateway contract docs. diff --git a/docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md b/docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md new file mode 100644 index 000000000..4acfc34d5 --- /dev/null +++ b/docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md @@ -0,0 +1,72 @@ +# ADR-0042 — LLM and Agent Identity Tuple and Deployment Posture + +## Status + +- Status: Implemented +- Original date (UTC): 2026-04-02 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Operator-visible identity must be expressed as an explicit tuple rather than inferred from one +overloaded backend label. + +The stable tuple fields are: + +- `client` +- `router` +- `provider` +- `auth_authority` +- `protocol` + +The stable placement posture is: + +- `in_world` +- `host_only` +- `host_to_world_bridge` as a transport-only adjunct, not a second control plane + +This keeps operator, status, and trace semantics aligned with the actual runtime split between +Substrate and `substrate-gateway`. + +## Stable Owned Surface + +This ADR remains the semantic owner for: + +- `identity_tuple` +- `placement_posture` + +Current stable contract references that depend on this ownership include: + +- `docs/reference/policy/contract.md` +- `docs/reference/policy/tuple_constraints.md` +- `docs/contracts/gateway/status-schema.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/world_gateway.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/world_gateway.rs` +- `crates/shell/tests/agent_successor_contract_ahcsitc0.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + +## Historical Note + +The original ADR includes planning-pack references and larger example context. Keep using this +curated ADR as the stable semantic owner of tuple and placement-posture meaning. diff --git a/docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md b/docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md new file mode 100644 index 000000000..a2e973580 --- /dev/null +++ b/docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md @@ -0,0 +1,64 @@ +# ADR-0043 — ADR-0027 Identity Tuple Policy Surface + +## Status + +- Status: Implemented +- Original date (UTC): 2026-04-03 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +ADR-0027 remains the only config/policy root, and tuple-aware narrowing is added under +`llm.constraints.*` rather than through a second config system or overloaded backend ids. + +The stable additive keys are: + +- `llm.constraints.routers` +- `llm.constraints.providers` +- `llm.constraints.protocols` +- `llm.constraints.auth_authorities` + +The stable behavior is: + +- each axis narrows an already-selected backend path +- empty lists mean unconstrained on that axis +- tuple-axis mismatch is a policy denial +- tuple-policy inspection belongs on `substrate policy current show --explain` + +## Stable Owned Surface + +The stable references for this ADR are: + +- `docs/reference/policy/tuple_constraints.md` +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/broker/src/policy.rs` +- `crates/broker/src/effective_policy.rs` +- `crates/shell/src/execution/policy_model.rs` +- `crates/broker/src/tests.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + +## Historical Note + +The original ADR contains planning-pack references and broader local execution context. Keep using +this curated ADR and the stable policy reference docs for current tuple-policy truth. diff --git a/docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md b/docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md new file mode 100644 index 000000000..9cbbb2a3a --- /dev/null +++ b/docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md @@ -0,0 +1,66 @@ +# ADR-0046 — Gateway Backend Selection Runtime Integration + +## Status + +- Status: Implemented +- Original date (UTC): 2026-04-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +The integrated gateway lifecycle must realize ADR-0041 through runtime selection, adapter binding, +capability gating, and auth handoff for the supported integrated backend set. + +The stable decision is: + +- `llm.routing.default_backend` remains the selected backend surface +- allowlisting and auth-read policy gates apply before runtime realization +- integrated lifecycle resolves one adapter binding for the selected backend +- missing binding, unsupported capabilities, or unavailable auth material fail closed +- runtime config and auth handoff are adapter-driven rather than one-off operator glue + +The implemented scope can widen over time, but supported backends must continue to follow this +same realization contract. + +## Stable Owned Surface + +This ADR realizes the contract surfaces documented in: + +- `docs/contracts/gateway/backend-adapter-selection.md` +- `docs/contracts/gateway/backend-adapter-protocol.md` +- `docs/contracts/gateway/backend-adapter-schema.md` +- `docs/contracts/gateway/operator-contract.md` +- `docs/contracts/gateway/status-schema.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/world_gateway.rs` +- `crates/world-service/src/gateway_runtime.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/world_gateway.rs` +- `crates/world-service/tests/gateway_runtime_parity.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + +## Historical Note + +The original ADR captures the planning and rollout framing for this implementation seam. Keep using +this curated ADR for the stable realization contract and the project-management ADR only for +historical execution context. diff --git a/docs/adr/implemented/README.md b/docs/adr/implemented/README.md new file mode 100644 index 000000000..55bd8b81d --- /dev/null +++ b/docs/adr/implemented/README.md @@ -0,0 +1,15 @@ +# Implemented ADRs + +This directory holds curated ADRs that are accepted and materially implemented. + +Use it for ADRs that still explain current Substrate behavior after +`docs/project_management/**` retirement. + +Current curated set: + +- `ADR-0027-llm-and-agent-config-policy-surface.md` +- `ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `ADR-0043-adr-0027-identity-tuple-policy-surface.md` +- `ADR-0046-gateway-backend-selection-runtime-integration.md` diff --git a/docs/contracts/gateway/backend-adapter-protocol.md b/docs/contracts/gateway/backend-adapter-protocol.md index 44a6b381e..cd23006b4 100644 --- a/docs/contracts/gateway/backend-adapter-protocol.md +++ b/docs/contracts/gateway/backend-adapter-protocol.md @@ -87,7 +87,7 @@ The local-to-external handoff is explicit: The implementation and verification surfaces for this contract are expected to stay aligned across: -- `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `crates/gateway/src/adapter_runtime.rs` - `crates/shell/src/execution/prompt_fulfillment.rs` - `crates/world-service/src/prompt_fulfillment.rs` diff --git a/docs/contracts/gateway/backend-adapter-schema.md b/docs/contracts/gateway/backend-adapter-schema.md index ef2feeb11..dd19e3767 100644 --- a/docs/contracts/gateway/backend-adapter-schema.md +++ b/docs/contracts/gateway/backend-adapter-schema.md @@ -182,7 +182,7 @@ Rules: The implementation and verification surfaces for this contract are expected to stay aligned across: -- `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - the Unified Agent API capability, extension, run-protocol, and event-envelope specs cited by ADR-0041 - the built-in backend capability and session-handle tests cited by the seam-local schema spec diff --git a/docs/contracts/gateway/backend-adapter-selection.md b/docs/contracts/gateway/backend-adapter-selection.md index 6f8049d98..b8be2803c 100644 --- a/docs/contracts/gateway/backend-adapter-selection.md +++ b/docs/contracts/gateway/backend-adapter-selection.md @@ -75,4 +75,4 @@ The implementation and verification surfaces for this contract are expected to s - `crates/shell/src/execution/policy_model.rs` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` -- `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/docs/contracts/gateway/runtime-parity.md b/docs/contracts/gateway/runtime-parity.md index d9b60cfc0..605a364dc 100644 --- a/docs/contracts/gateway/runtime-parity.md +++ b/docs/contracts/gateway/runtime-parity.md @@ -67,5 +67,5 @@ The later execution slices must keep the runtime/parity contract aligned across - `crates/world-service/tests/socket_activation.rs` - `crates/transport-api-types/src/lib.rs` - `crates/transport-api-client/src/lib.rs` -- `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/WORLD.md` diff --git a/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md b/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md index 8fffb774c..21e695f30 100644 --- a/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md +++ b/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md @@ -19,12 +19,10 @@ The most authoritative current references are: - authoritative operator-facing summary - states that runtime `substrate world deps current sync|install` never mutates system packages - points missing-package remediation at `substrate world enable --provision-deps` -- [`docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md) - - authoritative contract for APT-backed system-package provisioning -- [`docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md) - - authoritative manager-aware contract for `apt` and `pacman` -- [`docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md) - - authoritative contract for inventory structure, enabled-set resolution, and runtime fail-early posture +- [`docs/reference/world/deps/provisioning.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/deps/provisioning.md) + - authoritative operator-facing contract for provisioning-time mutation, runtime fail-early behavior, and supported backend posture +- [`docs/internals/world/deps.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/world/deps.md) + - authoritative implementation-oriented reference for inventory structure, enabled-set resolution, wrapper behavior, and runtime probe-only posture - [`docs/WORLD.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md) - authoritative world/runtime architecture summary for provisioning request profiles @@ -98,7 +96,6 @@ To make the documentation chain consistent end to end, the next updates should b If someone wants the current truth quickly, they should read in this order: 1. [`docs/reference/world/deps/README.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/deps/README.md) -2. [`docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md) -3. [`docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md) -4. [`docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md) -5. The implementing code in [`crates/shell/src/builtins/world_enable/runner.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_enable/runner.rs), [`crates/shell/src/builtins/world_enable/runner/provision_deps.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_enable/runner/provision_deps.rs), and [`crates/shell/src/builtins/world_deps/surfaces.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_deps/surfaces.rs) +2. [`docs/reference/world/deps/provisioning.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/deps/provisioning.md) +3. [`docs/internals/world/deps.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/world/deps.md) +4. The implementing code in [`crates/shell/src/builtins/world_enable/runner.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_enable/runner.rs), [`crates/shell/src/builtins/world_enable/runner/provision_deps.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_enable/runner/provision_deps.rs), and [`crates/shell/src/builtins/world_deps/surfaces.rs`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/builtins/world_deps/surfaces.rs) diff --git a/docs/project_management/adrs/README.md b/docs/project_management/adrs/README.md index 144714a16..8ea11dcea 100644 --- a/docs/project_management/adrs/README.md +++ b/docs/project_management/adrs/README.md @@ -28,3 +28,12 @@ New ADRs should prefer `docs/project_management/adrs/` unless there is a strong Legacy ADR locations may still be referenced by older planning artifacts. Use the migration tooling to move them into this registry so repo-wide scans can be strict and deterministic. + +## Stable Curated ADRs + +Curated ADRs that survive the retirement of `docs/project_management/**` now live under: + +- `docs/adr/` + +Use that tree for stable operator/runtime decision records. Keep this registry for planning-rich, +historical, or not-yet-curated ADR material. diff --git a/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md b/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md index fc7fba304..68a7cb0dc 100644 --- a/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md +++ b/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md @@ -2,7 +2,7 @@ ## Status - Status: Draft -- Supersession note: Architectural intent is superseded by `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md`. Keep this ADR only as the original gateway-capability draft and historical context for the archived `llm_gateway_in_world` planning set. +- Supersession note: Architectural intent is superseded by `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md`. Keep this ADR only as the original gateway-capability draft and historical context for the archived `llm_gateway_in_world` planning set. - Date (UTC): 2026-02-03 - Owner(s): Spenser McConnell (Substrate) @@ -16,7 +16,7 @@ ## Related Docs - Successor ADR: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - Plan: `docs/project_management/_archived/next/llm_gateway_in_world/plan.md` - Tasks: `docs/project_management/_archived/next/llm_gateway_in_world/tasks.json` - Spec manifest: `docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md` @@ -31,7 +31,7 @@ ADR_BODY_SHA256: 3b15c76f976661655bac13323eb5c21a8e7a4c8230bb1907a0f96fe90339d621 Supersession note: -- Read `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` as the current architectural source of truth for Substrate versus `substrate-gateway` ownership. This ADR remains useful for the original gateway-capability shape and archived execution planning, but it no longer defines the runtime ownership boundary. +- Read `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` as the current architectural source of truth for Substrate versus `substrate-gateway` ownership. This ADR remains useful for the original gateway-capability shape and archived execution planning, but it no longer defines the runtime ownership boundary. ### Changes (operator-facing) - Substrate-owned LLM gateway runs inside the world boundary @@ -103,7 +103,7 @@ This ADR does not define new config file families or bespoke gateway config file - Source of truth (config/policy key paths + precedence + defaults): - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/_archived/next/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/schema.md` Files and locations (existing YAML layering model): - Global config patch: `$SUBSTRATE_HOME/config.yaml` (default: `~/.substrate/config.yaml`) diff --git a/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md b/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md index b4ad54ad4..ae5c4abd5 100644 --- a/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md +++ b/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md @@ -2,7 +2,7 @@ ## Status - Status: Draft -- Supersession note: The architectural intent of this ADR is superseded by `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md`, which preserves the stable backend-id / allowlisting contract while replacing the bespoke Substrate-local engine assumption with a gateway-hosted adapter contract. +- Supersession note: The architectural intent of this ADR is superseded by `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md`, which preserves the stable backend-id / allowlisting contract while replacing the bespoke Substrate-local engine assumption with a gateway-hosted adapter contract. - Date (UTC): 2026-02-03 - Owner(s): Spenser McConnell (Substrate) @@ -74,7 +74,7 @@ This ADR MUST use the Phase 3 surface defined by ADR-0027 for: Sources of truth: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` -- `docs/project_management/_archived/next/llm_and_agent_config_policy_surface/SCHEMA.md` +- `docs/reference/policy/schema.md` Config (selection surface; ADR-0027): - `llm.enabled: bool` diff --git a/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md b/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md index e2e94b05e..5178c113f 100644 --- a/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md +++ b/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md @@ -131,7 +131,7 @@ Control-plane enablement gates (v1; fail closed): - This ADR does not define new config file families. It MUST use the Phase 3 config/policy surface defined by ADR-0027. - Source of truth (key paths + precedence + defaults): - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/_archived/next/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/schema.md` - Agent backends are registered via the agent inventory directory (one file per backend), per ADR-0027: - Global: `$SUBSTRATE_HOME/agents/.yaml` (default `~/.substrate/agents/.yaml`) - Workspace: `/.substrate/agents/.yaml` diff --git a/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md b/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md index 740e71a0c..c4c83bd1b 100644 --- a/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md +++ b/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md @@ -92,7 +92,7 @@ ADR_BODY_SHA256: 24f8f422c1813381e2dc1245e483eb010d765d48d7915186aa94a6da9534bf9 - This ADR does not define new config file families. It MUST use the Phase 3 config/policy surface defined by ADR-0027. - Source of truth (key paths + precedence + defaults): - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/_archived/next/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/schema.md` - Additive config keys (authoritative): - `agents.toolbox.enabled: bool` diff --git a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md index 66e4d1533..23b4df68f 100644 --- a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-03 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -23,8 +29,8 @@ - CI checkpoints: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/ci_checkpoint_plan.md` - Spec manifest: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/spec_manifest.md` - Specs: - - Contract: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/contract.md` - - Schema: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/SCHEMA.md` + - Contract: `docs/reference/policy/contract.md` + - Schema: `docs/reference/policy/schema.md` - Phase 3a slice: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/LACP0-spec.md` - Phase 3b slice: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/LACP1-spec.md` - Decision Register: `docs/project_management/packs/active/llm_and_agent_config_policy_surface/decision_register.md` @@ -67,8 +73,8 @@ ADR_BODY_SHA256: 36c3baa794d0878fae02ffa4dfa7bb9dbeed355c4aa7e4a0a554df7dd116443 - Why: Keep Substrate’s enforcement/audit claims accurate and avoid a “second config system” as LLM + agent features land (gateway, CLI backends, agent hub, orchestration toolbox). - Links: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md#L1` - - `docs/project_management/packs/active/llm_and_agent_config_policy_surface/contract.md#L1` - - `docs/project_management/packs/active/llm_and_agent_config_policy_surface/SCHEMA.md#L1` + - `docs/reference/policy/contract.md#L1` + - `docs/reference/policy/schema.md#L1` - `docs/project_management/packs/active/llm_and_agent_config_policy_surface/decision_register.md#L1` - Phase 8 additive clarification: - This ADR remains the source of truth for config/policy file families, precedence, fail-closed posture, backend allowlists, and host-side secret-read gates. diff --git a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md index d7363e97e..4c4fb233b 100644 --- a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-04-02 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -23,8 +29,8 @@ The committed operator contract that downstream slices should treat as live sour - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - Foundational config/policy surface: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` - Committed operator contract: - `docs/contracts/gateway/operator-contract.md` - Foundational output/routing and trace contracts: diff --git a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md index de7fbdda2..19e68f7b3 100644 --- a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md +++ b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md @@ -7,6 +7,12 @@ - Date (UTC): 2026-04-02 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/` @@ -22,8 +28,8 @@ This ADR is a successor to ADR-0024 and should be read as a contract clarificati - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - Config / policy source of truth: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` - Output / event / trace foundations: - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` diff --git a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md index 1502091e2..56ab3da0e 100644 --- a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md +++ b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-04-02 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -18,8 +24,8 @@ clarification layer that precedes later Agent Hub updates and any additive confi - Foundational config/policy surface: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` - Semantic planning pack: - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md` diff --git a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md index b864ee92f..3f5c97ad0 100644 --- a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-04-03 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -21,8 +27,8 @@ This ADR is a minimal additive follow-on to ADR-0027. It keeps the existing file - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md` - Config/policy foundation: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` - Expected planning-pack outputs: - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/plan.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tasks.json` diff --git a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md index cdbe406ff..e924e917d 100644 --- a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md +++ b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-04-21 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -20,8 +26,8 @@ This ADR is a thin implementation follow-on to ADR-0041. It keeps the ADR-0041 b - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Config / policy source of truth: - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md` - - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md` + - `docs/reference/policy/contract.md` + - `docs/reference/policy/schema.md` - Existing contract docs this ADR realizes: - `docs/contracts/gateway/backend-adapter-selection.md` - `docs/contracts/gateway/backend-adapter-protocol.md` diff --git a/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md b/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md index bc7abeb81..19b47be2c 100644 --- a/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md +++ b/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md @@ -23,8 +23,8 @@ - `docs/project_management/system/standards/triad/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` (automation/worktree execution) ## Related Docs -- Source contract doc (must remain in parity with this ADR’s contract section): - - `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` +- Stable operator reference (must remain in parity with this ADR’s contract section): + - `docs/reference/world/deps/README.md` - Planning Pack (execution v4; this feature directory): - `docs/project_management/_archived/next/world-deps-packages-bundles-contract/plan.md` - `docs/project_management/_archived/next/world-deps-packages-bundles-contract/tasks.json` @@ -52,7 +52,7 @@ ADR_BODY_SHA256: d66ae560a90cdad0241a8e8fd0557c898d4f3e5596ca3f21a6828c5fda506d1 - New: `substrate world deps` is driven by an inventory directory model (`$SUBSTRATE_HOME/deps/`, `/.substrate/deps/`) plus enabled patch keys in YAML (`$SUBSTRATE_HOME/config.yaml`, `/.substrate/workspace.yaml`), with explicit `current|global|workspace` CLI scopes. - Why: makes “what exists / what you want / what is applied” explicit and scriptable; removes misleading “looks like a CLI but isn’t” cases. - Links: - - `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` + - `docs/reference/world/deps/README.md` - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` @@ -61,7 +61,7 @@ ADR_BODY_SHA256: d66ae560a90cdad0241a8e8fd0557c898d4f3e5596ca3f21a6828c5fda506d1 - New: `world deps` MUST NOT read (or be influenced by) any legacy world-deps paths; inventory/enabled sources are limited to the new directories/patch files plus built-in defaults. - Why: prevents silent drift, hidden overrides, and “it works on one machine” confusion; makes tests enforce the end state. - Links: - - `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` + - `docs/reference/world/deps/README.md` ## Problem / Context - `substrate world deps` needs a stable, predictable, scope-aware contract for declaring and applying in-world dependencies. @@ -83,7 +83,7 @@ ADR_BODY_SHA256: d66ae560a90cdad0241a8e8fd0557c898d4f3e5596ca3f21a6828c5fda506d1 ## User Contract (Authoritative) This section is a direct, parity-preserving conversion of: -- `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` +- `docs/reference/world/deps/README.md` It is authoritative; other sections in this ADR must not contradict it. diff --git a/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md b/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md index f9f66ff3c..d47c5b9ea 100644 --- a/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md +++ b/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md @@ -18,7 +18,7 @@ - Patch files + scope model: - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - World-deps consumer contract: - - `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` + - `docs/reference/world/deps/README.md` - World-deps ADR (consumer workstream; not modified by this ADR): - `docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md` @@ -32,7 +32,7 @@ ADR_BODY_SHA256: 9f5ad467af8c83056bf9e06e1f6f2b3f1e9be8a58a0f35fc56b832fa957e964 - Why: enables additive config keys (like `world.deps.enabled`) without creating a second parallel config system or confusing precedence. - Links: - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - - `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` + - `docs/reference/world/deps/README.md` - Schema defines merge behavior per key - Existing: patch files imply a single merge rule (“workspace overrides global”) for all keys. From 56307fdc2c728e750d52142986c6b1597ae317d1 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 16:22:52 -0400 Subject: [PATCH 14/20] Reclassify queued ADR-0026 and update retirement tracker --- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 34 ++++++++++--- docs/adr/CURATION.md | 37 ++++++++++++-- .../ADR-0026-orchestration-toolbox-mcp.md | 49 +++++++++++++++++++ docs/adr/draft/README.md | 4 ++ ...DR-0023-in-world-llm-gateway-front-door.md | 44 +++++++++++++++++ .../ADR-0024-cli-backend-provider-engine.md | 46 +++++++++++++++++ .../ADR-0025-agent-hub-core-role-swappable.md | 45 +++++++++++++++++ docs/adr/historical/README.md | 6 +++ ...kend-contract-and-capability-divergence.md | 6 +-- ...concurrent-execution-and-output-routing.md | 4 +- .../ADR-0021-substrate-workflow-engine.md | 2 +- ...-0022-forge-agent-loop-as-workflow-node.md | 2 +- ...DR-0023-in-world-llm-gateway-front-door.md | 6 +++ .../ADR-0024-cli-backend-provider-engine.md | 6 +++ .../ADR-0025-agent-hub-core-role-swappable.md | 6 +++ .../ADR-0026-orchestration-toolbox-mcp.md | 6 +++ ...027-llm-and-agent-config-policy-surface.md | 10 ++-- ...-gateway-boundary-and-runtime-ownership.md | 2 +- ...strate-gateway-backend-adapter-contract.md | 12 ++--- ...t-identity-tuple-and-deployment-posture.md | 18 +++---- ...-adr-0027-identity-tuple-policy-surface.md | 16 +++--- ...ore-successor-identity-tuple-compatible.md | 18 +++---- ...ox-internal-mcp-identity-trace-contract.md | 12 ++--- ...y-backend-selection-runtime-integration.md | 16 +++--- ...-session-and-parked-resumable-ownership.md | 4 +- 25 files changed, 340 insertions(+), 71 deletions(-) create mode 100644 docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md create mode 100644 docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md create mode 100644 docs/adr/historical/ADR-0024-cli-backend-provider-engine.md create mode 100644 docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 2df2a01ac..001ea4da7 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -77,6 +77,11 @@ Still remaining before the atomic top-level `packs/**` removal: ADR-0046 - stable gateway contract docs now point at curated implemented ADRs instead of the old draft project-management paths + - live ADR-to-ADR prerequisite repointing for non-superseded current consumers is now complete + - the remaining old first-cluster draft-path refs are confined to superseded predecessor ADRs + ADR-0023, ADR-0024, and ADR-0025, plus queued draft ADR-0026 + - ADR-0023, ADR-0024, and ADR-0025 are now curated into `docs/adr/historical/` + - ADR-0026 is now curated into `docs/adr/draft/` as queued work rather than historical-only Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` @@ -125,6 +130,13 @@ Validation already completed for the finished slices: - stable gateway contract verification docs now reference curated implemented ADR paths for: - ADR-0040 - ADR-0041 +- scoped scans over the current ADR consumer set no longer show old first-cluster draft ADR paths +- curated historical ADR files now exist for: + - ADR-0023 + - ADR-0024 + - ADR-0025 +- curated draft ADR files now exist for: + - ADR-0026 ## Current Dependency Classes @@ -360,24 +372,32 @@ Completed in this slice: - promoted the first contract-heavy ADR cluster into `docs/adr/implemented/` - repointed stable gateway contract docs to the curated implemented ADR paths - added relocation notes on the legacy project-management ADRs retained for compatibility +- repointed live ADR-to-ADR prerequisite links for the non-superseded current consumer set +- classified the superseded predecessor cluster (`ADR-0023` through `ADR-0025`) +- promoted that predecessor cluster into `docs/adr/historical/` +- reclassified ADR-0026 as queued and moved it into `docs/adr/draft/` +- added updated relocation notes on the retained predecessor and queued draft ADRs ## Recommended Resume Order Use this order in the next session: -1. Repoint live ADR-to-ADR prerequisite links to the curated implemented ADR paths. - - Focus on current, still-live consumers before touching broader planning-pack history. -2. Reclassify and promote the next ADR cluster. - - Keep the provisioning ADR decision around ADR-0030 and ADR-0033 as its own narrower slice. +1. Reclassify and promote the next current ADR cluster. + - The likely next slice is the orchestration / workflow cluster, including queued ADR-0026, + not the already-curated historical predecessor ADRs. +2. Keep the provisioning ADR decision around ADR-0030 and ADR-0033 as its own narrower slice. 3. Continue narrowing the remaining `docs/project_management/**` dependency surface after the - stable ADR consumers stop pointing at the retiring namespace. + current ADR cluster decisions stop pointing stable readers at the retiring namespace. ## Resume Notes - Do not start by deleting any pack directories. - The first-cluster ADR promotion slice is complete. -- The next correct move is targeted repointing of live ADR-to-ADR prerequisites plus - classification of the next cluster, not another broad stable-doc extraction pass. +- Live ADR-to-ADR prerequisite repointing is complete for the current consumer set, and the + superseded predecessor cluster has been moved into `docs/adr/historical/` except ADR-0026, + which is now treated as queued draft work under `docs/adr/draft/`. +- The next correct move is classification of the next current ADR cluster, not another broad + stable-doc extraction pass or a return to the predecessor cluster. - Treat the repo-wide `docs/project_management/**` cleanup as subordinate to that ADR curation milestone; otherwise you risk repeatedly repointing docs toward a namespace that is still meant to be retired. diff --git a/docs/adr/CURATION.md b/docs/adr/CURATION.md index 5fd29791d..7fcd09f91 100644 --- a/docs/adr/CURATION.md +++ b/docs/adr/CURATION.md @@ -92,11 +92,42 @@ The following curated ADRs now exist under `docs/adr/implemented/`: `ADR-0033`; they remain separate because their pack-owned contract references may still be intentional until that narrower provisioning cluster is curated. +## Second Cluster: Superseded Gateway and Agent-Hub Predecessors + +This is the next bounded cluster after live-consumer prerequisite repointing because these ADRs +still carry legacy backlinks but are no longer the active architectural truth. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0023 | `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` | `superseded` | `still_draft` | Its gateway-capability intent is preserved historically, but the current runtime ownership split now lives in ADR-0040 and the adapter boundary in ADR-0041. | +| ADR-0024 | `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` | `superseded` | `still_draft` | The stable backend-id and allowlisting goals survived, but the Substrate-local engine framing was replaced by the gateway-owned adapter contract in ADR-0041. | +| ADR-0025 | `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` | `superseded` | `still_draft` | The core Agent Hub direction remains relevant, but the newer successor ADRs changed the identity and backend semantics enough that this draft is historical, not current truth. | + +## Promoted In This Slice + +The following curated historical ADRs now exist under `docs/adr/historical/`: + +- `docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md` +- `docs/adr/historical/ADR-0024-cli-backend-provider-engine.md` +- `docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md` + +## Queued Draft: ADR-0026 + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0026 | `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` | `stable_keeper` | `still_draft` | The toolbox concept is still queued work rather than settled history. It has not been landed, and when implementation is ready it should be rewritten against the later orchestration, identity, and trace semantics rather than treated as an already-closed predecessor. | + +Curated queued draft ADR: + +- `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` + ## Next Resume Slice -Next, continue with: +Live-current prerequisite repointing for the first promoted cluster is now complete. Next, +continue with: -1. repoint live ADR-to-ADR prerequisite links that should follow the curated implemented paths -2. classify and promote the next ADR cluster +1. classify and promote the next current ADR cluster +2. treat the orchestration / workflow ADRs, including queued toolbox work around ADR-0026, as the + next likely cluster rather than returning to the superseded predecessor set 3. keep provisioning ADRs `ADR-0030` and `ADR-0033` separate until that narrower cluster is explicitly curated diff --git a/docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md b/docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md new file mode 100644 index 000000000..fe8af51a4 --- /dev/null +++ b/docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md @@ -0,0 +1,49 @@ +# ADR-0026 — Orchestration Toolbox (Internal; MCP Protocol) + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-02-09 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + +The project-management ADR remains as the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +This curated ADR remains active architectural input, but it is not implemented and should not be +treated as implementation-ready. + +## Queued Direction + +This draft proposes an internal MCP toolbox that exposes orchestration-only tools to the +orchestrator agent without requiring bespoke SDK coupling. + +The queued direction that still matters is: + +- orchestrator-only tool access +- MCP as the internal tool protocol +- a dedicated control-plane toolbox instead of ad hoc integration points + +## Why Queued + +The core intent remains needed, but the current draft is not the form that should land. + +It will require a rewrite when implementation is ready so it can align with: + +- `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + +Treat this curated draft as the queued placeholder for that future rewrite, not as current +operator/runtime truth and not as a closed historical-only artifact. + +## Draft Note + +Keep the project-management draft for planning-rich origin context, but resume from this curated +draft when the toolbox implementation slice is ready to be restated and landed. diff --git a/docs/adr/draft/README.md b/docs/adr/draft/README.md index f13879ef9..653a7f38c 100644 --- a/docs/adr/draft/README.md +++ b/docs/adr/draft/README.md @@ -5,3 +5,7 @@ yet. It is intentionally narrower than `docs/project_management/adrs/draft/`, which also contains planning-heavy ADRs that may never be promoted here. + +Current curated draft ADRs: + +- `ADR-0026-orchestration-toolbox-mcp.md` diff --git a/docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md b/docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md new file mode 100644 index 000000000..41ce07a97 --- /dev/null +++ b/docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md @@ -0,0 +1,44 @@ +# ADR-0023 — In-World Substrate LLM Gateway (Front Door + Engines) + +## Status + +- Status: Historical +- Original date (UTC): 2026-02-03 +- Curated into `docs/adr/historical/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` + +This curated ADR is kept only as historical context. The project-management ADR remains as the +planning-rich source retained for compatibility while `docs/project_management/**` is retired. + +## Historical Decision Snapshot + +This draft proposed an in-world Substrate-owned LLM gateway front door so model egress would stay +inside the world boundary when world mode is enabled. + +The historical shape matters because it established the original goals behind: + +- keeping gateway egress inside the boundary +- avoiding policy bypass through host-local routing +- making world placement part of the operator-facing contract + +## Why Historical + +This proposal is no longer the current architectural truth. + +Its runtime ownership assumptions were superseded by: + +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + +Those successor ADRs preserve the boundary goals while replacing the older single-ADR framing with +an explicit Substrate-versus-`substrate-gateway` ownership split and adapter contract. + +## Historical Note + +Keep the original draft for archived gateway-capability planning context, not as a live runtime or +operator contract. diff --git a/docs/adr/historical/ADR-0024-cli-backend-provider-engine.md b/docs/adr/historical/ADR-0024-cli-backend-provider-engine.md new file mode 100644 index 000000000..61940431e --- /dev/null +++ b/docs/adr/historical/ADR-0024-cli-backend-provider-engine.md @@ -0,0 +1,46 @@ +# ADR-0024 — CLI Backend Provider Engine (Subscription-First Cross-Routing) + +## Status + +- Status: Historical +- Original date (UTC): 2026-02-03 +- Curated into `docs/adr/historical/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` + +This curated ADR is kept only as historical context. The project-management ADR remains as the +planning-rich source retained for compatibility while `docs/project_management/**` is retired. + +## Historical Decision Snapshot + +This draft proposed treating subscription-authenticated CLIs as provider backends behind a +Substrate-local engine layer so cross-provider routing could work without forcing API keys. + +The historical shape matters because it captured the product goal of: + +- stable backend selection for CLI-backed fulfillment +- subscription-first usage +- controlled cross-routing inside the trusted boundary + +## Why Historical + +The product goal remains relevant, but the engine architecture did not stay authoritative. + +Its stable successor is: + +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + +The current architecture keeps the stable backend-id and allowlisting posture while replacing the +older Substrate-local engine assumption with a gateway-owned adapter contract under the ownership +split from: + +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + +## Historical Note + +Keep the original draft for early CLI-backend strategy context, not as the current adapter or +runtime contract. diff --git a/docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md b/docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md new file mode 100644 index 000000000..39c1d913b --- /dev/null +++ b/docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md @@ -0,0 +1,45 @@ +# ADR-0025 — Agent Hub Core (Role-Swappable Agent Backends) + +## Status + +- Status: Historical +- Original date (UTC): 2026-02-09 +- Curated into `docs/adr/historical/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` + +This curated ADR is kept only as historical context. The project-management ADR remains as the +planning-rich source retained for compatibility while `docs/project_management/**` is retired. + +## Historical Decision Snapshot + +This draft proposed an Agent Hub registry and routing layer where CLI or API backends could assume +orchestrator or member roles without hardcoding those roles into backend types. + +The historical shape matters because it established the original direction for: + +- deterministic agent registration and routing +- concurrent attribution for multi-agent execution +- role assignment as a control-plane concern instead of a backend-type distinction + +## Why Historical + +This framing was superseded before it became the durable semantic contract. + +The newer direction keeps the orchestration goals while clarifying identity and backend semantics +through: + +- `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + +In particular, the successor direction stops overloading `backend_id` with role, provider, or +protocol meaning. + +## Historical Note + +Keep the original draft for archived Agent Hub origin context, not as the current identity or +orchestration contract. diff --git a/docs/adr/historical/README.md b/docs/adr/historical/README.md index 6cde898f6..5dd546a04 100644 --- a/docs/adr/historical/README.md +++ b/docs/adr/historical/README.md @@ -4,3 +4,9 @@ This directory holds curated ADRs kept only for historical context, supersession audit trail. Do not treat files here as current operator or runtime truth. + +Current curated historical ADRs: + +- `ADR-0023-in-world-llm-gateway-front-door.md` +- `ADR-0024-cli-backend-provider-engine.md` +- `ADR-0025-agent-hub-core-role-swappable.md` diff --git a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md index 13f83d051..8ec9c7e88 100644 --- a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md +++ b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md @@ -16,9 +16,9 @@ - Exit code taxonomy: `docs/project_management/system/standards/shared/EXIT_CODE_TAXONOMY.md` - ADR standard/template: `docs/project_management/system/standards/adr/ADR_STANDARD_AND_TEMPLATE.md` - Secrets delivery channel rubric: `docs/project_management/system/standards/shared/SECRETS_DELIVERY_CHANNEL_RUBRIC.md` -- LLM + agent config/policy surface: `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` -- Gateway boundary and runtime ownership: `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` -- Gateway backend adapter contract: `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- LLM + agent config/policy surface: `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` +- Gateway boundary and runtime ownership: `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- Gateway backend adapter contract: `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Gateway operator contract: `docs/contracts/gateway/operator-contract.md` - Gateway policy evaluation contract: `docs/contracts/gateway/policy-evaluation.md` - Gateway runtime and platform parity contract: `docs/contracts/gateway/runtime-parity.md` diff --git a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md index f10ed196b..736494c28 100644 --- a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md +++ b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md @@ -42,8 +42,8 @@ - Related ADRs: - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical context: diff --git a/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md b/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md index 8ac9672d5..fea05660f 100644 --- a/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md +++ b/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md @@ -28,7 +28,7 @@ - Output routing + attribution: `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - Router daemon (workflow triggers, queues, cross-workspace): `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` - Host orchestration durable session and inbox contract: `docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` - - Config/policy surface (no new roots): `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - Config/policy surface (no new roots): `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` ## Executive Summary (Operator) diff --git a/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md b/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md index c8ec47258..f98c58f91 100644 --- a/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md +++ b/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md @@ -27,7 +27,7 @@ - LLM gateway front door: `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - Backend/provider engines: `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - Trace/event foundations: `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - Config/policy surface (no new roots): `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - Config/policy surface (no new roots): `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` ## Executive Summary (Operator) diff --git a/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md b/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md index 68a7cb0dc..f6e21c58c 100644 --- a/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md +++ b/docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-03 - Owner(s): Spenser McConnell (Substrate) +## Curated Historical ADR + +- Current curated historical ADR: `docs/adr/historical/ADR-0023-in-world-llm-gateway-front-door.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/llm_gateway_in_world/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md b/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md index ae5c4abd5..79f924c44 100644 --- a/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md +++ b/docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-03 - Owner(s): Spenser McConnell (Substrate) +## Curated Historical ADR + +- Current curated historical ADR: `docs/adr/historical/ADR-0024-cli-backend-provider-engine.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/llm_cli_backend_engine/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md b/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md index 5178c113f..ee8ba4ddd 100644 --- a/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md +++ b/docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md @@ -6,6 +6,12 @@ - Owner(s): Spenser McConnell (Substrate) - Superseded by: `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +## Curated Historical ADR + +- Current curated historical ADR: `docs/adr/historical/ADR-0025-agent-hub-core-role-swappable.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/agent_hub_core/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md b/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md index c4c83bd1b..c3b3de792 100644 --- a/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md +++ b/docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md @@ -6,6 +6,12 @@ - Owner(s): Spenser McConnell (Substrate) - Superseded by: `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/orchestration_mcp_toolbox/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md index 23b4df68f..3ddfbd98f 100644 --- a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md @@ -45,11 +45,11 @@ - Profiles (future; must remain compatible): - `docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md` - Identity / tuple follow-ons (additive; must remain compatible): - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Current successor ADRs that consume this surface: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical predecessor ADRs (superseded semantically; useful as origin context only): @@ -72,7 +72,7 @@ ADR_BODY_SHA256: 36c3baa794d0878fae02ffa4dfa7bb9dbeed355c4aa7e4a0a554df7dd116443 - with explicit schemas, precedence, and fail-closed behavior. - Why: Keep Substrate’s enforcement/audit claims accurate and avoid a “second config system” as LLM + agent features land (gateway, CLI backends, agent hub, orchestration toolbox). - Links: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md#L1` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md#L1` - `docs/reference/policy/contract.md#L1` - `docs/reference/policy/schema.md#L1` - `docs/project_management/packs/active/llm_and_agent_config_policy_surface/decision_register.md#L1` diff --git a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md index 4c4fb233b..388dd5e08 100644 --- a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md @@ -28,7 +28,7 @@ The committed operator contract that downstream slices should treat as live sour - Superseded intent: - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - Foundational config/policy surface: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Committed operator contract: diff --git a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md index 19e68f7b3..8e5874a8e 100644 --- a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md +++ b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md @@ -25,9 +25,9 @@ This ADR is a successor to ADR-0024 and should be read as a contract clarification for the gateway adapter layer, not as a redefinition of the gateway boundary itself. - Boundary / runtime ownership prerequisite: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - Config / policy source of truth: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Output / event / trace foundations: @@ -46,7 +46,7 @@ This ADR is a successor to ADR-0024 and should be read as a contract clarificati - Handoff evidence: - `.codex/handoffs/2026-04-02-144618-substrate-gateway-architecture-alignment.md` - Follow-on boundary ADR: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` ## Executive Summary (Operator) @@ -60,7 +60,7 @@ ADR_BODY_SHA256: 10d71a701199e24edda589d0bac6e8edcaf6c56de561e07c59b90aec3102f0d - Why: This keeps backend identity stable, avoids coupling policy to provider implementation details, and matches the runtime ownership split clarified in ADR-0040. - Links: - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `/Users/spensermcconnell/atomize-hq/unified-agent-api/docs/adr/0013-agent-api-backend-harness.md` - `/Users/spensermcconnell/atomize-hq/unified-agent-api/docs/adr/0015-unified-agent-api-session-extensions.md` - `/Users/spensermcconnell/atomize-hq/unified-agent-api/docs/adr/0017-unified-agent-api-session-thread-id-surfacing.md` @@ -245,8 +245,8 @@ ADR_BODY_SHA256: 10d71a701199e24edda589d0bac6e8edcaf6c56de561e07c59b90aec3102f0d ### Manual validation - Compare this ADR against: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - the unified-agent-api UAA ADRs - the gateway boundary evidence in `kimi-claude-adapter` - Confirm there is no remaining ambiguity about who owns: diff --git a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md index 56ab3da0e..d283a2509 100644 --- a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md +++ b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md @@ -23,7 +23,7 @@ This ADR is a semantic lock for operator-facing identity and deployment posture. clarification layer that precedes later Agent Hub updates and any additive config/policy updates. - Foundational config/policy surface: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Semantic planning pack: @@ -33,10 +33,10 @@ clarification layer that precedes later Agent Hub updates and any additive confi - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Additive policy follow-on: - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Follow-on agent orchestration ADRs: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` @@ -56,11 +56,11 @@ ADR_BODY_SHA256: 51fd84175744539955168c2a9aa657d1fc69c9923a9a84295c22d8697847df2 - New: Substrate treats these as distinct semantic fields: `client`, `router`, `provider`, `auth_authority`, and `protocol`. - Why: A single backend id is not enough to explain what is actually happening when a host client is pointed at `substrate_gateway`, when the gateway fans out to multiple providers, or when subscription-based auth and API-key auth both exist in the same ecosystem. - Links: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` ## Problem / Context - The current architecture has multiple, orthogonal choices that operators need to understand independently: @@ -176,9 +176,9 @@ Non-negotiable interpretation: ### Config - This ADR introduces no new config files and no new config keys. - Source of truth for config/policy files, precedence, and fail-closed semantics remains: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - Router/provider/protocol/auth-authority policy constraints are introduced additively by: - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Placement posture is expressed via existing config/policy: - `llm.gateway.mode: in_world|host_only` - `llm.fail_closed.routing` (no host fallback when true) diff --git a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md index 3f5c97ad0..835c39d10 100644 --- a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md @@ -22,11 +22,11 @@ This ADR is a minimal additive follow-on to ADR-0027. It keeps the existing file families and extends the policy surface so operators can express the ADR-0042 identity model clearly without overloading backend ids. - Semantic model: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md` - Config/policy foundation: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Expected planning-pack outputs: @@ -41,8 +41,8 @@ This ADR is a minimal additive follow-on to ADR-0027. It keeps the existing file - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Follow-on agent orchestration ADRs: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` @@ -56,10 +56,10 @@ ADR_BODY_SHA256: ab38102c3d0c2de20c9a6ae9236523c865e18cb9b3966725e2e4f93b9c42245 - New: Substrate adds tuple-axis narrowing constraints under `llm.constraints` so operators can separately constrain `router`, `provider`, `protocol`, and `auth_authority` while keeping backend ids as adapter/backend gates only. - Why: This removes the last ambiguity from the operator model without inventing new files or collapsing the router, client, provider, and auth authority into one label. - Links: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` ## Problem / Context - ADR-0042 establishes the semantic identity tuple: diff --git a/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md b/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md index 6ef601fca..d8e6536fc 100644 --- a/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md +++ b/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md @@ -19,17 +19,17 @@ This ADR supersedes the older backend-id-centric Agent Hub framing in ADR-0025 a - Superseded ADR: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - Identity tuple and deployment posture: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - Tuple-axis policy surface: - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Config/policy foundation: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - Event and trace foundations: - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Follow-on orchestration surface: - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical toolbox predecessor: @@ -45,16 +45,16 @@ ADR_BODY_SHA256: d9b8f16acf256bc582ac1cfaaa23cd75f48bc990f7ebe221ee6406763beaea5 - Why: operators need to know whether they are approving a runtime adapter, a routing authority, or an upstream model provider, and those are not the same thing. - Links: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Separate pure agent-run identity from nested gateway-backed LLM identity - Existing: backend ids and trace attribution can be read as if they imply provider, auth authority, and protocol all at once. - New: pure agent runs expose `client`, `router`, `protocol`, and `backend_id`; `provider` and `auth_authority` are absent unless the agent triggers a nested LLM request through `substrate_gateway`. - Why: this keeps operator approval and audit output readable when a host orchestrator dispatches a world-scoped member agent that later calls an LLM. - Links: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` ## Problem / Context diff --git a/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md b/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md index f9e085445..136040c97 100644 --- a/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md +++ b/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md @@ -19,19 +19,19 @@ This ADR supersedes the older orchestration-toolbox framing in ADR-0026 and shou - Superseded ADR: - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` - Identity tuple and deployment posture: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - Tuple-axis policy surface: - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Agent Hub successor: - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - Config/policy foundation: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - Event and trace foundations: - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` ## Executive Summary (Operator) @@ -43,7 +43,7 @@ ADR_BODY_SHA256: 41a4e1478057cd1a67695c503531f4fbcab3f4d08e2b3d896b7bfd8327f0e7d - Why: operators need a read-only toolbox that is easy to audit, fail closed, and impossible to confuse with a second execution plane. - Links: - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` ## Problem / Context diff --git a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md index e924e917d..09057aa7b 100644 --- a/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md +++ b/docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md @@ -22,10 +22,10 @@ This ADR is a thin implementation follow-on to ADR-0041. It keeps the ADR-0041 backend-id contract intact and defines how Substrate realizes that contract in the integrated gateway lifecycle for more than `cli:codex`. - Prerequisite boundary and contract ADRs: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Config / policy source of truth: - - `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Existing contract docs this ADR realizes: @@ -35,8 +35,8 @@ This ADR is a thin implementation follow-on to ADR-0041. It keeps the ADR-0041 b - `docs/contracts/gateway/operator-contract.md` - `docs/contracts/gateway/status-schema.md` - Explicitly deferred follow-ons: - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Expected planning-pack outputs: - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/plan.md` - `docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/tasks.json` @@ -66,9 +66,9 @@ ADR_BODY_SHA256: 0c49fe896ae4eebf17fad20a6079dffa13006612a50c40496f0edec500ad843 - New: this ADR limits itself to realizing ADR-0041 selection, adapter lookup, capability gating, and integrated runtime generation, while deferring tuple-axis policy, additive status-schema widening, and stronger secret transport redesign to their owning ADRs. - Why: this keeps the active implementation seam small enough to plan and land without reopening adjacent semantic surfaces. - Links: - - `docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md` - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - `crates/shell/src/execution/config_model.rs#L215` - `crates/shell/src/execution/policy_model.rs#L68` diff --git a/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md b/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md index 678b6f208..8c446565d 100644 --- a/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md @@ -16,8 +16,8 @@ This ADR is a lifecycle correction for host orchestration. It does not replace the existing public caller surfaces; it clarifies what those surfaces bind to and what runtime durability they require. - Foundational runtime / ownership ADRs: - - `docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - - `docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - Public caller-surface and execution-plan context: - `llm-last-mile/PLAN-22.md` - `llm-last-mile/ORCH_PLAN-22.md` From af42abc50218eeeba405f428f831a0c9c05b1246 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 18:10:41 -0400 Subject: [PATCH 15/20] Curate additional ADRs into implemented and draft docs --- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 43 ++++++++++-- docs/adr/CURATION.md | 69 +++++++++++++++++-- ...al-show-when-workspace-config-overrides.md | 43 ++++++++++++ ...R-0020-profiles-config-policy-snapshots.md | 44 ++++++++++++ .../ADR-0021-substrate-workflow-engine.md | 47 +++++++++++++ ...-0022-forge-agent-loop-as-workflow-node.md | 44 ++++++++++++ ...R-0029-host-event-bus-and-router-daemon.md | 45 ++++++++++++ ...ore-successor-identity-tuple-compatible.md | 45 ++++++++++++ ...ox-internal-mcp-identity-trace-contract.md | 47 +++++++++++++ docs/adr/draft/README.md | 7 ++ ...DR-0016-world-first-repl-persistent-pty.md | 59 ++++++++++++++++ ...concurrent-execution-and-output-routing.md | 59 ++++++++++++++++ ...027-llm-and-agent-config-policy-surface.md | 2 +- ...-world-process-execution-tracing-parity.md | 57 +++++++++++++++ ...-session-and-parked-resumable-ownership.md | 62 +++++++++++++++++ docs/adr/implemented/README.md | 4 ++ ...DR-0016-world-first-repl-persistent-pty.md | 6 ++ ...concurrent-execution-and-output-routing.md | 22 +++--- ...al-show-when-workspace-config-overrides.md | 6 ++ ...R-0020-profiles-config-policy-snapshots.md | 10 ++- .../ADR-0021-substrate-workflow-engine.md | 18 +++-- ...-0022-forge-agent-loop-as-workflow-node.md | 14 ++-- ...027-llm-and-agent-config-policy-surface.md | 8 +-- ...-world-process-execution-tracing-parity.md | 6 ++ ...R-0029-host-event-bus-and-router-daemon.md | 16 +++-- ...-gateway-boundary-and-runtime-ownership.md | 4 +- ...strate-gateway-backend-adapter-contract.md | 4 +- ...t-identity-tuple-and-deployment-posture.md | 10 +-- ...-adr-0027-identity-tuple-policy-surface.md | 6 +- ...ore-successor-identity-tuple-compatible.md | 16 +++-- ...ox-internal-mcp-identity-trace-contract.md | 18 +++-- ...-session-and-parked-resumable-ownership.md | 10 ++- 32 files changed, 782 insertions(+), 69 deletions(-) create mode 100644 docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md create mode 100644 docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md create mode 100644 docs/adr/draft/ADR-0021-substrate-workflow-engine.md create mode 100644 docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md create mode 100644 docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md create mode 100644 docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md create mode 100644 docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md create mode 100644 docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md create mode 100644 docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md create mode 100644 docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md create mode 100644 docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 001ea4da7..685d82eb5 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -82,6 +82,12 @@ Still remaining before the atomic top-level `packs/**` removal: ADR-0023, ADR-0024, and ADR-0025, plus queued draft ADR-0026 - ADR-0023, ADR-0024, and ADR-0025 are now curated into `docs/adr/historical/` - ADR-0026 is now curated into `docs/adr/draft/` as queued work rather than historical-only + - the orchestration/workflow batch is now curated: + - implemented ADRs: ADR-0017, ADR-0028, ADR-0047 + - queued draft ADRs: ADR-0021, ADR-0022, ADR-0026, ADR-0029, ADR-0044, ADR-0045 + - the remaining current ADR tail is now curated: + - implemented ADR: ADR-0016 + - queued draft ADRs: ADR-0019, ADR-0020 Validation already completed for the finished slices: - `cargo test -p substrate-broker --lib -- --nocapture` @@ -131,12 +137,24 @@ Validation already completed for the finished slices: - ADR-0040 - ADR-0041 - scoped scans over the current ADR consumer set no longer show old first-cluster draft ADR paths +- curated implemented ADR files now also exist for: + - ADR-0016 + - ADR-0017 + - ADR-0028 + - ADR-0047 - curated historical ADR files now exist for: - ADR-0023 - ADR-0024 - ADR-0025 - curated draft ADR files now exist for: + - ADR-0019 + - ADR-0020 - ADR-0026 + - ADR-0021 + - ADR-0022 + - ADR-0029 + - ADR-0044 + - ADR-0045 ## Current Dependency Classes @@ -377,17 +395,26 @@ Completed in this slice: - promoted that predecessor cluster into `docs/adr/historical/` - reclassified ADR-0026 as queued and moved it into `docs/adr/draft/` - added updated relocation notes on the retained predecessor and queued draft ADRs +- classified the orchestration/workflow ADR batch +- promoted implemented ADRs `ADR-0017`, `ADR-0028`, and `ADR-0047` into `docs/adr/implemented/` +- promoted queued ADRs `ADR-0021`, `ADR-0022`, `ADR-0026`, `ADR-0029`, `ADR-0044`, and + `ADR-0045` into `docs/adr/draft/` +- added relocation notes on the retained project-management copies for that batch +- classified the remaining current ADR tail +- promoted implemented ADR `ADR-0016` into `docs/adr/implemented/` +- promoted queued ADRs `ADR-0019` and `ADR-0020` into `docs/adr/draft/` +- repointed current ADR references from `ADR-0016` and `ADR-0020` toward the curated namespace ## Recommended Resume Order Use this order in the next session: 1. Reclassify and promote the next current ADR cluster. - - The likely next slice is the orchestration / workflow cluster, including queued ADR-0026, - not the already-curated historical predecessor ADRs. -2. Keep the provisioning ADR decision around ADR-0030 and ADR-0033 as its own narrower slice. -3. Continue narrowing the remaining `docs/project_management/**` dependency surface after the - current ADR cluster decisions stop pointing stable readers at the retiring namespace. + - The next explicit slice is the provisioning ADR pair `ADR-0030` and `ADR-0033`. +2. Continue narrowing the remaining `docs/project_management/**` dependency surface after the + ADR registry stops pointing stable readers at the retiring namespace. +3. Do not reopen the completed current ADR clusters unless a remaining stable consumer still points + at the old copies. ## Resume Notes @@ -396,8 +423,10 @@ Use this order in the next session: - Live ADR-to-ADR prerequisite repointing is complete for the current consumer set, and the superseded predecessor cluster has been moved into `docs/adr/historical/` except ADR-0026, which is now treated as queued draft work under `docs/adr/draft/`. -- The next correct move is classification of the next current ADR cluster, not another broad - stable-doc extraction pass or a return to the predecessor cluster. +- The orchestration/workflow batch is now classified and promoted. +- The remaining current ADR tail is now classified and promoted. +- The next correct move is the dedicated provisioning ADR slice (`ADR-0030` / `ADR-0033`), not + another broad stable-doc extraction pass or a return to already-curated clusters. - Treat the repo-wide `docs/project_management/**` cleanup as subordinate to that ADR curation milestone; otherwise you risk repeatedly repointing docs toward a namespace that is still meant to be retired. diff --git a/docs/adr/CURATION.md b/docs/adr/CURATION.md index 7fcd09f91..7564e7838 100644 --- a/docs/adr/CURATION.md +++ b/docs/adr/CURATION.md @@ -121,13 +121,68 @@ Curated queued draft ADR: - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` +## Third Cluster: Orchestration and Workflow ADRs + +This is the next current ADR cluster after the first contract-heavy promotion and predecessor +cleanup. It groups the accepted execution/trace contracts that are already implemented plus the +active queued orchestration/workflow follow-ons that still need restatement before landing. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0017 | `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` | `stable_keeper` | `implemented` | Accepted and materially implemented in REPL/output-routing behavior; still used as a live foundation for orchestration and trace-related work. | +| ADR-0028 | `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` | `stable_keeper` | `implemented` | Accepted and implemented through the canonical tracing stack and stable trace internals docs. | +| ADR-0047 | `docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` | `stable_keeper` | `draft_but_implemented` | Its durable host-session and terminal-delivery posture is already treated as current runtime truth and backed by runtime/test anchors. | +| ADR-0021 | `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md` | `stable_keeper` | `still_draft` | Still queued architectural input for a future workflow runtime; not implemented and should remain draft. | +| ADR-0022 | `docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md` | `stable_keeper` | `still_draft` | Still queued as a workflow-node derivative of the broader workflow-engine direction. | +| ADR-0026 | `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` | `stable_keeper` | `still_draft` | Queued toolbox work that still needs a rewrite before implementation; active draft, not history. | +| ADR-0029 | `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` | `stable_keeper` | `still_draft` | Queued host-router/service direction that remains active architectural input but not landed behavior. | +| ADR-0044 | `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` | `stable_keeper` | `still_draft` | Queued successor Agent Hub contract that should remain draft until the orchestration/session stack is restated and landed. | +| ADR-0045 | `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` | `stable_keeper` | `still_draft` | Queued toolbox successor contract that depends on the surrounding orchestration and identity work. | + +## Promoted In This Slice + +The following curated implemented ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` + +The following curated draft ADRs now exist under `docs/adr/draft/`: + +- `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` +- `docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md` +- `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` +- `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` +- `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + +## Fourth Cluster: Remaining Current ADR Tail + +This tail slice captures the remaining current non-provisioning ADRs that still matter after the +contract-heavy, predecessor, and orchestration/workflow clusters were promoted. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0016 | `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` | `stable_keeper` | `draft_but_implemented` | World-first REPL semantics are already implemented and still anchor later output-routing and tracing work, so this belongs in the implemented tree despite the legacy draft label. | +| ADR-0019 | `docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` | `stable_keeper` | `still_draft` | Still queued UX work around config visibility and scope messaging; active input, not landed behavior. | +| ADR-0020 | `docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md` | `stable_keeper` | `still_draft` | Still queued architecture for full profile snapshots and surface scoping; not implemented and should remain draft. | + +## Promoted In This Slice + +The following curated implemented ADR now exists under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` + +The following curated draft ADRs now exist under `docs/adr/draft/`: + +- `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` +- `docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md` + ## Next Resume Slice -Live-current prerequisite repointing for the first promoted cluster is now complete. Next, -continue with: +The remaining current ADR tail is now classified and promoted. Next, continue with: -1. classify and promote the next current ADR cluster -2. treat the orchestration / workflow ADRs, including queued toolbox work around ADR-0026, as the - next likely cluster rather than returning to the superseded predecessor set -3. keep provisioning ADRs `ADR-0030` and `ADR-0033` separate until that narrower cluster is - explicitly curated +1. keep provisioning ADRs `ADR-0030` and `ADR-0033` as the next explicit curation slice +2. after that, narrow any remaining `docs/project_management/**` dependency surface that still + points stable readers at retiring namespaces +3. do not reopen already-curated ADR clusters unless new stable references are discovered diff --git a/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md new file mode 100644 index 000000000..677a8ca81 --- /dev/null +++ b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md @@ -0,0 +1,43 @@ +# ADR-0019 — Warn on Config Global Show When Workspace Config Overrides + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-01-30 +- Owner(s): Substrate maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Substrate should emit a high-signal stderr note when `config global show` is likely to be +misread inside a workspace with active workspace overrides, while preserving stdout and exit-code +stability. + +The queued direction that still matters is: + +- warn only when workspace override conditions actually apply +- keep stdout patch-only and script-safe +- emit explicit scope/write-target guidance for implicit-scope `config set` + +## Why Queued + +This remains active UX/input-surface work, but it is not landed and should not be treated as a +stable contract yet. + +When implementation is ready, it should be restated against: + +- `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` + +## Draft Note + +Keep the project-management ADR for the original operator-contract detail, but treat this curated +draft as the queued warning-behavior placeholder. diff --git a/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md b/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md new file mode 100644 index 000000000..4e6ed1621 --- /dev/null +++ b/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md @@ -0,0 +1,44 @@ +# ADR-0020 — Profiles Config and Policy Snapshots + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-01-30 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Substrate may need explicit profiles that provide complete config and policy snapshots for specific +surfaces instead of relying entirely on layered defaults/global/workspace resolution. + +The queued direction that still matters is: + +- complete config and policy snapshots with no accidental layer leakage +- explicit surface scoping for profile application +- explainability about when profiles suppress workspace/global/default layers + +## Why Queued + +This remains active architectural input, but it is not landed and should not yet be treated as a +stable contract. + +When implementation is ready, it should be restated against: + +- `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` + +## Draft Note + +Keep the project-management ADR for the fuller profile model and validation detail, but treat this +curated draft as the queued profile-snapshot placeholder. diff --git a/docs/adr/draft/ADR-0021-substrate-workflow-engine.md b/docs/adr/draft/ADR-0021-substrate-workflow-engine.md new file mode 100644 index 000000000..592f3ae8d --- /dev/null +++ b/docs/adr/draft/ADR-0021-substrate-workflow-engine.md @@ -0,0 +1,47 @@ +# ADR-0021 — Substrate Workflow Engine + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-02-03 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Substrate maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Substrate needs a first-class workflow runtime that can execute DAG-shaped work under the existing +policy, trace, and isolation model rather than pushing multi-step orchestration outside the +product. + +The queued direction that still matters is: + +- a DAG workflow runtime with explicit node dependencies +- stable workflow-run and node-run tracing +- execution that continues to route tool/script work through existing policy and world boundaries +- extensibility through node executors rather than a one-off scheduler + +## Why Queued + +This is still active architectural input, but it is not landed and should not yet be treated as a +stable contract. + +When implementation is ready, it should be restated against: + +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` +- `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` + +## Draft Note + +Keep the project-management ADR for original planning detail, but treat this curated draft as the +queued workflow-runtime placeholder. diff --git a/docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md b/docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md new file mode 100644 index 000000000..2956d8b75 --- /dev/null +++ b/docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md @@ -0,0 +1,44 @@ +# ADR-0022 — Forge as a Workflow Node + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-02-03 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Substrate maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Forge remains a queued composite node concept that should live inside a broader Substrate workflow +runtime rather than becoming the workflow engine itself. + +The queued direction that still matters is: + +- a bounded iterative agent-loop node +- nested spans and traceability under the core workflow runtime +- reuse of stable config/policy and tracing contracts instead of bespoke execution plumbing + +## Why Queued + +This is active architectural input, but it is not landed and depends on the workflow/runtime +cluster being settled first. + +When implementation is ready, it should be restated against: + +- `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` + +## Draft Note + +Keep the project-management ADR for the original Forge framing, but treat this curated draft as a +queued derivative of the workflow-engine slice. diff --git a/docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md b/docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md new file mode 100644 index 000000000..15426d0f7 --- /dev/null +++ b/docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md @@ -0,0 +1,45 @@ +# ADR-0029 — Host Event Bus and Router Daemon + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-02-05 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate); Shell maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Substrate may need a host-scoped router service that consumes trace and event signals to drive +workflow triggers, requests, and cross-workspace routing. + +The queued direction that still matters is: + +- trace-driven or event-driven routing as a host-scoped service +- compatibility with durable host orchestration sessions +- reuse of existing trace and output attribution vocabulary + +## Why Queued + +This remains active input, but it is not landed and depends on the orchestration/session contract +and workflow direction being settled. + +When implementation is ready, it should be restated against: + +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` +- `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` + +## Draft Note + +Keep the project-management ADR for archived planning depth, but use this curated draft as the +queued router-service placeholder. diff --git a/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md b/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md new file mode 100644 index 000000000..71c0f3c0b --- /dev/null +++ b/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md @@ -0,0 +1,45 @@ +# ADR-0044 — Agent Hub Core Successor + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-04-03 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +The next Agent Hub contract should preserve backend-id safety while making orchestrator/member +semantics, session handles, and nested gateway-backed identity explicit. + +The queued direction that still matters is: + +- capability-driven agent backend semantics +- explicit host-scoped orchestrator and world-scoped member model +- identity that keeps `backend_id` separate from provider, auth authority, and protocol + +## Why Queued + +This is active architectural input, but it is not landed and still needs the queue of +orchestration/session/toolbox work around it. + +When implementation is ready, it should be restated against: + +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` +- `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` +- `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + +## Draft Note + +Keep the project-management ADR for detailed design reasoning, but treat this curated draft as the +queued Agent Hub successor anchor. diff --git a/docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md b/docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md new file mode 100644 index 000000000..ed448f708 --- /dev/null +++ b/docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md @@ -0,0 +1,47 @@ +# ADR-0045 — Orchestration Toolbox Internal MCP Identity and Trace Contract + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-04-03 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +The toolbox remains queued as an internal MCP control-plane surface with explicit identity and +trace semantics, layered on top of the newer Agent Hub and tuple model. + +The queued direction that still matters is: + +- orchestrator-only toolbox access +- introspection-only v1 toolbox posture +- MCP protocol as the internal toolbox wire contract +- explicit control-plane identity and trace joinability + +## Why Queued + +This is active architectural input, but it is not landed and depends on the surrounding +orchestration/session work being finalized. + +When implementation is ready, it should be restated against: + +- `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` +- `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` + +## Draft Note + +Keep the project-management ADR for detailed control-plane design, but use this curated draft as +the queued toolbox-contract placeholder. diff --git a/docs/adr/draft/README.md b/docs/adr/draft/README.md index 653a7f38c..014fd221b 100644 --- a/docs/adr/draft/README.md +++ b/docs/adr/draft/README.md @@ -8,4 +8,11 @@ planning-heavy ADRs that may never be promoted here. Current curated draft ADRs: +- `ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` +- `ADR-0020-profiles-config-policy-snapshots.md` +- `ADR-0021-substrate-workflow-engine.md` +- `ADR-0022-forge-agent-loop-as-workflow-node.md` - `ADR-0026-orchestration-toolbox-mcp.md` +- `ADR-0029-host-event-bus-and-router-daemon.md` +- `ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` diff --git a/docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md b/docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md new file mode 100644 index 000000000..ca39d30f8 --- /dev/null +++ b/docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md @@ -0,0 +1,59 @@ +# ADR-0016 — World-First REPL With Persistent World PTY + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Substrate maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +When world execution is enabled, the interactive REPL must behave like a world-first shell backed +by a persistent world PTY session rather than mixing world-backed command execution with host-only +builtin semantics. + +The stable decision is: + +- unprefixed interactive REPL commands run against a persistent in-world session +- `cd`, `pwd`, `export`, and `unset` follow in-world shell semantics when world mode is active +- `:host` remains an explicit gated escape hatch rather than an implicit fallback +- `-c/--command` must stay world-consistent when world mode is enabled +- PTY output handling and completion ordering must preserve traceability and operator clarity + +## Stable Owned Surface + +This ADR owns the stable world-first REPL behavior surfaced through: + +- interactive `substrate` REPL behavior when world execution is enabled +- `:host` and `:pty` interactive escape/forcing behavior +- world-consistent `-c/--command` semantics + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/invocation/runtime.rs` +- `crates/shell/src/execution/routing/dispatch/exec.rs` +- `crates/shell/src/execution/routing/builtin/utility.rs` +- `crates/shell/src/execution/routing/builtin/world_deps.rs` +- `crates/shell/src/execution/routing/dispatch/world_ops.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md` + +## Historical Note + +The original ADR captures detailed protocol, state-machine, and rollout context. The stable +world-first REPL contract now lives here. diff --git a/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md b/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md new file mode 100644 index 000000000..dc1b3e590 --- /dev/null +++ b/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md @@ -0,0 +1,59 @@ +# ADR-0017 — Agent Hub Concurrent Execution and Output Routing + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-25 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Substrate maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Substrate must keep PTY byte streams and structured concurrent agent events as distinct output +classes so concurrent execution remains attributable and does not corrupt interactive PTY flows. + +The stable decision is: + +- PTY streams are forwarded as raw bytes +- structured agent events use a separate structured rendering path +- structured events must not be injected into PTY passthrough +- concurrent attribution must remain explicit and joinable +- buffering and dropped-event summaries must preserve operator clarity under pressure + +## Stable Owned Surface + +This ADR owns the stable output-routing and event-envelope behavior surfaced through: + +- interactive REPL output behavior +- structured agent-event rendering and attribution +- trace correlation expectations for concurrent agent execution + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/agent_events.rs` +- `crates/shell/src/repl/async_repl.rs` +- `crates/world-service/src/pty.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + +## Historical Note + +The original ADR contains pack-local rollout, smoke, and evidence references that remain useful +for historical context, but the stable output-routing contract now lives here. diff --git a/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md b/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md index 92c642cd4..770ac8706 100644 --- a/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md +++ b/docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md @@ -61,7 +61,7 @@ The decision is materially implemented and enforced through: - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` ## Historical Note diff --git a/docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md b/docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md new file mode 100644 index 000000000..4283e8c91 --- /dev/null +++ b/docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md @@ -0,0 +1,57 @@ +# ADR-0028 — In-World Process Execution Tracing Parity + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-29 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell + World-Agent + World runtime + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +Substrate tracing must preserve parity between host and in-world process execution so operators and +downstream tooling can reason about execution trees, exec/exit events, and correlation without +guessing which runtime path produced the record. + +The stable decision is: + +- in-world execution must emit canonical process execution telemetry +- exec/exit semantics must remain joinable across shell, shim, and world-service paths +- trace fields must preserve stable correlation vocabulary for downstream consumers +- parity gaps are correctness issues, not optional observability enhancements + +## Stable Owned Surface + +The stable references for this ADR are: + +- `docs/internals/trace/schema.md` +- `docs/internals/trace/protocol.md` +- `docs/TRACE.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/trace` +- `crates/common/src/log_schema.rs` +- `crates/shim` +- `crates/world-service` + +## Related ADRs + +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` +- `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` + +## Historical Note + +The original ADR captures the phased rollout and pack-local execution planning. The stable tracing +parity contract now lives here and in the trace internals docs. diff --git a/docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md b/docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md new file mode 100644 index 000000000..864b4d87a --- /dev/null +++ b/docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md @@ -0,0 +1,62 @@ +# ADR-0047 — Host Orchestrator Durable Session and Parked-Resumable Ownership + +## Status + +- Status: Implemented +- Original date (UTC): 2026-05-09 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Spenser McConnell (Substrate) + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +The durable unit for host orchestration is the Substrate-owned orchestration session and its inbox +or task state, not the lifetime of any one attached backend client process. + +The stable decision is: + +- host orchestration sessions remain valid after clean client detachment +- parked and resumable posture is explicit persisted runtime truth +- follow-up, approval, and completion delivery must survive attached-client exit +- public prompt surfaces must terminate with explicit terminal envelopes after `Accepted` +- detached-world follow-up remains fail-closed until routed through a valid host owner path + +## Stable Owned Surface + +This ADR owns the durable host-orchestration posture surfaced through: + +- `substrate agent start` +- `substrate agent turn` +- `substrate agent reattach` +- `substrate agent stop` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/agents_cmd.rs` +- `crates/shell/src/execution/agent_runtime/control.rs` +- `crates/shell/src/execution/agent_runtime/session.rs` +- `crates/shell/src/execution/agent_runtime/state_store.rs` +- `crates/shell/src/repl/async_repl.rs` +- `crates/shell/tests/agent_public_control_surface_v1.rs` +- `crates/shell/tests/repl_world_first_routing_v1.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` +- `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` +- `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` + +## Historical Note + +The original ADR includes execution-plan framing and migration details. The stable host-session +durability contract now lives here. diff --git a/docs/adr/implemented/README.md b/docs/adr/implemented/README.md index 55bd8b81d..805f3d775 100644 --- a/docs/adr/implemented/README.md +++ b/docs/adr/implemented/README.md @@ -7,9 +7,13 @@ Use it for ADRs that still explain current Substrate behavior after Current curated set: +- `ADR-0016-world-first-repl-persistent-pty.md` +- `ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `ADR-0028-in-world-process-execution-tracing-parity.md` - `ADR-0027-llm-and-agent-config-policy-surface.md` - `ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `ADR-0041-substrate-gateway-backend-adapter-contract.md` - `ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `ADR-0043-adr-0027-identity-tuple-policy-surface.md` - `ADR-0046-gateway-backend-selection-runtime-integration.md` +- `ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` diff --git a/docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md b/docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md index 8993ce0a8..881f6f61b 100644 --- a/docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md +++ b/docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-21 - Owner(s): Substrate maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/world-first-repl-persistent-pty/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md index 736494c28..04da8f350 100644 --- a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md +++ b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-01-25 - Owner(s): Substrate maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/` @@ -40,12 +46,12 @@ - Phase 8 cross-cutting registry (sequencing umbrella): - `docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` - Related ADRs: - - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + - `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + - `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical context: - `docs/project_management/_archived/p0-agent-hub-isolation-hardening/` - Grounding code references: @@ -68,9 +74,9 @@ ADR_BODY_SHA256: f0d3b640100a78346549730cb1bb9a2051e2875038315f4f7e1b0ada4cd52ff - Structured agent events are rendered via a structured output path and are buffered during PTY passthrough to avoid corrupting TUIs. - Why: Agent hub orchestration will run multiple agent CLIs concurrently through adapter-backed, capability-driven execution paths. Without an output contract, concurrent outputs can corrupt terminal state or be mis-attributed, undermining usability and auditability. - Links: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md#L78` (this ADR: contract) + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md#L1` (this ADR: contract) - `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/decision_register.md#L12` (DR-0001: output classes) - - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md#L89` (PTY passthrough contract) + - `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md#L1` (PTY passthrough contract) - `docs/project_management/_archived/world-first-repl-persistent-pty/STATE_MACHINE.md` - `docs/project_management/_archived/world-first-repl-persistent-pty/PROTOCOL.md` - `crates/shell/src/repl/async_repl.rs` (concurrent structured printing today) @@ -167,7 +173,7 @@ Structured agent events are serialized as a top-level envelope with stable corre Authoritative shape and field requirements live in: - `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/decision_register.md` (DR-0003, DR-0008, DR-0009) -- Phase 8 correlation vocabulary (canonical field names): `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` +- Phase 8 correlation vocabulary (canonical field names): `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` Envelope fields (top-level; no nesting required for joinability): @@ -303,7 +309,7 @@ Fail-closed drift posture (`agents.hub.world_restart.on_drift=fail_closed`) - Prerequisite integration task IDs: none (ADR-0016 is already implemented; this ADR is self-contained). - Dependencies: - Depends on ADR-0016’s PTY passthrough and out-of-band PTY output rules for the REPL. - - Correlation vocabulary and field names must remain consistent with `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` (additive-only alignment). + - Correlation vocabulary and field names must remain consistent with `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` (additive-only alignment). ## Security / Safety Posture diff --git a/docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md b/docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md index 0aada82ed..9f7cc413f 100644 --- a/docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md +++ b/docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md @@ -6,6 +6,12 @@ Status: Proposed Owners: Substrate maintainers +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Executive Summary (Operator) ADR_BODY_SHA256: 5ba8ddfe1acc5eee1ce41582e50bac5f2501cfd3734f47aa5a40c02b9b0a9ca5 diff --git a/docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md b/docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md index 403a47373..3061fcc0f 100644 --- a/docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md +++ b/docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-30 - Owner(s): Shell maintainers +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directories (impacted): - `docs/project_management/_archived/next/` (this ADR; cross-cutting contract) @@ -19,7 +25,7 @@ - Env override taxonomy: - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - World-first REPL (motivation for surface scoping + drift messaging): - - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` + - `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` ## Executive Summary (Operator) @@ -31,7 +37,7 @@ ADR_BODY_SHA256: 954c6e25ffe2599ff28304e9a842cae35f5806b60450ee221e4f2fce4909e93 - Why: provides deterministic, intent-aligned behavior for humans vs agents without multiplying ad-hoc override knobs; improves debuggability by making “what is active?” explicit. - Links: - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - - `docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md` + - `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` ## Problem / Context - Substrate is used by both: diff --git a/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md b/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md index fea05660f..6ded525eb 100644 --- a/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md +++ b/docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-03 - Owner(s): Substrate maintainers +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/workflow-engine/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -24,10 +30,10 @@ - Impact Map: `docs/project_management/_archived/next/workflow-engine/impact_map.md` (not created; ADR draft phase) - Manual Playbook: `docs/project_management/_archived/next/workflow-engine/manual_testing_playbook.md` (not created; ADR draft phase) - Dependency foundations (must remain compatible): - - Trace + event foundations: `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - Output routing + attribution: `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - Router daemon (workflow triggers, queues, cross-workspace): `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` - - Host orchestration durable session and inbox contract: `docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` + - Trace + event foundations: `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` + - Output routing + attribution: `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - Router daemon (workflow triggers, queues, cross-workspace): `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` + - Host orchestration durable session and inbox contract: `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` - Config/policy surface (no new roots): `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` ## Executive Summary (Operator) @@ -39,9 +45,9 @@ ADR_BODY_SHA256: 0e7a75f2761d8bab7aa43ea95c05e6ab5eed4da516d7c1fdcce7c489a0e305f - New: Substrate can run a user-defined DAG workflow (YAML/JSON) made of heterogeneous nodes (command execution, sub-workflows, composite nodes like Forge) while emitting a single traceable workflow run with per-node spans and replay hooks. - Why: make multi-step automation observable/replayable under the same policy+trace model, and provide a stable substrate for “agentic workflows” without coupling to any specific agent framework. - Links: - - `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md#L1` + - `docs/adr/draft/ADR-0021-substrate-workflow-engine.md#L1` - `docs/project_management/_archived/next/workflow-engine/decision_register.md` - - `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md#L1` + - `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md#L1` ## Problem / Context - Substrate already provides secure execution, policy enforcement, and trace/replay, but it does not provide a native workflow graph runner. diff --git a/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md b/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md index f98c58f91..20889db2c 100644 --- a/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md +++ b/docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-03 - Owner(s): Substrate maintainers +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/forge/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -23,10 +29,10 @@ - Impact Map: `docs/project_management/_archived/next/forge/impact_map.md` (not created; ADR draft phase) - Manual Playbook: `docs/project_management/_archived/next/forge/manual_testing_playbook.md` (not created; ADR draft phase) - Dependency foundations (must remain compatible): - - Workflow engine (node executor hook): `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md` + - Workflow engine (node executor hook): `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` - LLM gateway front door: `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - Backend/provider engines: `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - - Trace/event foundations: `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - Trace/event foundations: `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Config/policy surface (no new roots): `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` ## Executive Summary (Operator) @@ -38,8 +44,8 @@ ADR_BODY_SHA256: 22f105ab816130a537072cd0fca3a75dec6c106edd965fc161ad57b34d1f22f - New: A workflow can include a `forge.run` node that performs bounded iterative refinement (execute → critique → refine → review with retries) under explicit budgets, emitting nested spans/events for observability. - Why: keep the general workflow engine simple (DAG scheduling) while enabling advanced looping/leadership behavior as a reusable composite node. - Links: - - `docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md#L1` - - `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md#L1` + - `docs/adr/draft/ADR-0022-forge-agent-loop-as-workflow-node.md#L1` + - `docs/adr/draft/ADR-0021-substrate-workflow-engine.md#L1` - `docs/project_management/_archived/next/forge/decision_register.md` ## Problem / Context diff --git a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md index 3ddfbd98f..8f1f0d242 100644 --- a/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md @@ -43,20 +43,20 @@ - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` - `docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` - Profiles (future; must remain compatible): - - `docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md` + - `docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md` - Identity / tuple follow-ons (additive; must remain compatible): - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Current successor ADRs that consume this surface: - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + - `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + - `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical predecessor ADRs (superseded semantically; useful as origin context only): - `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` - `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` - Global JSON mode plan (separate track; do not duplicate): - `docs/project_management/packs/draft/json-mode/json_mode_plan.md` diff --git a/docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md b/docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md index affbaef12..54e31a12c 100644 --- a/docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md +++ b/docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-29 - Owner(s): Shell + World-Agent + World runtime +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/active/world_process_exec_tracing_parity/` - Intended branch name(s): `feat/world-process-exec-tracing-parity` diff --git a/docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md b/docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md index 4450005ef..358a1dd7e 100644 --- a/docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md +++ b/docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-05 - Owner(s): Spenser McConnell (Substrate); Shell maintainers +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/host_event_bus_router_daemon/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -16,10 +22,10 @@ ## Related Docs - Decision Register: `docs/project_management/_archived/next/host_event_bus_router_daemon/decision_register.md` - Trace/event foundations: - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - Host orchestration session compatibility: - - `docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` + - `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` - FS path semantics & allow/deny matching: - `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` - Config/policy layering model: @@ -38,9 +44,9 @@ ADR_BODY_SHA256: af9cb004268a0a6cbf00a7981662d531b51f11c2afca77201becae5583feb9d - New: A host daemon tails the canonical trace stream and produces policy-gated requests/actions when routing rules match, including cross-workspace routing using an explicit workspace registry under `SUBSTRATE_HOME`. - Why: Enable reliable “when A completes, trigger B” workflows and selective file-change triggers without introducing an external broker or bypassing workspace policy boundaries. - Links: - - `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md#L1` + - `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md#L1` - `docs/project_management/_archived/next/host_event_bus_router_daemon/decision_register.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md#L1` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md#L1` - `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md#L1` ## Problem / Context diff --git a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md index 388dd5e08..3cfe156ae 100644 --- a/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md @@ -34,8 +34,8 @@ The committed operator contract that downstream slices should treat as live sour - Committed operator contract: - `docs/contracts/gateway/operator-contract.md` - Foundational output/routing and trace contracts: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Evidence from the adjacent gateway runtime: - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0005-present-a-single-backend-identity-to-substrate.md` - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md` diff --git a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md index 8e5874a8e..d01370221 100644 --- a/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md +++ b/docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md @@ -31,8 +31,8 @@ This ADR is a successor to ADR-0024 and should be read as a contract clarificati - `docs/reference/policy/contract.md` - `docs/reference/policy/schema.md` - Output / event / trace foundations: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway evidence: - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0005-present-a-single-backend-identity-to-substrate.md` - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md` diff --git a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md index d283a2509..17f7fc496 100644 --- a/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md +++ b/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md @@ -30,8 +30,8 @@ clarification layer that precedes later Agent Hub updates and any additive confi - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md` - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md` - Foundational output/event and trace contracts: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` @@ -39,7 +39,7 @@ clarification layer that precedes later Agent Hub updates and any additive confi - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Follow-on agent orchestration ADRs: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` - Supporting evidence: - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0005-present-a-single-backend-identity-to-substrate.md` - `/Users/spensermcconnell/__Active_Code/kimi-claude-adapter/docs/adr/0006-preserve-an-in-world-compatible-deployment-boundary.md` @@ -57,8 +57,8 @@ ADR_BODY_SHA256: 51fd84175744539955168c2a9aa657d1fc69c9923a9a84295c22d8697847df2 - Why: A single backend id is not enough to explain what is actually happening when a host client is pointed at `substrate_gateway`, when the gateway fans out to multiple providers, or when subscription-based auth and API-key auth both exist in the same ecosystem. - Links: - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` diff --git a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md index 835c39d10..0eaca536d 100644 --- a/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md +++ b/docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md @@ -38,14 +38,14 @@ This ADR is a minimal additive follow-on to ADR-0027. It keeps the existing file - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/decision_register.md` - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md` - Event/trace foundations: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Follow-on agent orchestration ADRs: - `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` ## Executive Summary (Operator) diff --git a/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md b/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md index d8e6536fc..ad00c9d28 100644 --- a/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md +++ b/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-04-03 - Owner(s): Spenser McConnell (Substrate) +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/` - This ADR is docs-only; no pack files are created by this change. @@ -25,15 +31,15 @@ This ADR supersedes the older backend-id-centric Agent Hub framing in ADR-0025 a - Config/policy foundation: - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - Event and trace foundations: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - Follow-on orchestration surface: - - `docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` + - `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` - Historical toolbox predecessor: - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` ## Executive Summary (Operator) @@ -55,7 +61,7 @@ ADR_BODY_SHA256: d9b8f16acf256bc582ac1cfaaa23cd75f48bc990f7ebe221ee6406763beaea5 - Links: - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` ## Problem / Context - ADR-0025 captured the first version of Agent Hub, but that framing predated the identity tuple clarified in ADR-0042 and the policy split clarified in ADR-0043. diff --git a/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md b/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md index 136040c97..ae7057a5d 100644 --- a/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md +++ b/docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-04-03 - Owner(s): Spenser McConnell (Substrate) +## Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` +- This project-management file remains the planning-rich source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/orchestration-toolbox-mcp/` - This ADR is docs-only; no pack files are created by this change. @@ -17,18 +23,18 @@ This ADR supersedes the older orchestration-toolbox framing in ADR-0026 and should be read together with the tuple, gateway, and Agent Hub successor ADRs. - Superseded ADR: - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` - Identity tuple and deployment posture: - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - Tuple-axis policy surface: - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` - Agent Hub successor: - - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + - `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - Config/policy foundation: - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` - Event and trace foundations: - - `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - - `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` + - `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` - Gateway ownership and adapter contracts: - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` @@ -42,9 +48,9 @@ ADR_BODY_SHA256: 41a4e1478057cd1a67695c503531f4fbcab3f4d08e2b3d896b7bfd8327f0e7d - New: toolbox calls are treated as control-plane reads with explicit `client`, `router`, `protocol`, and `backend_id` fields; v1 exposes no mutating tools and no nested LLM semantics. - Why: operators need a read-only toolbox that is easy to audit, fail closed, and impossible to confuse with a second execution plane. - Links: - - `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` + - `docs/adr/draft/ADR-0026-orchestration-toolbox-mcp.md` - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` - - `docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + - `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` ## Problem / Context - Substrate needs a host-scoped orchestration toolbox so the orchestrator agent can inspect policy, sessions, traces, and graph views without bespoke SDK coupling. diff --git a/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md b/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md index 8c446565d..ccd886051 100644 --- a/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md +++ b/docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-05-09 - Owner(s): Spenser McConnell (Substrate) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/host-orchestrator-durable-session-and-parked-resumable-ownership/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -29,8 +35,8 @@ This ADR is a lifecycle correction for host orchestration. It does not replace t - `crates/shell/src/execution/agent_runtime/state_store.rs` - `crates/shell/src/repl/async_repl.rs` - Future-compatible workflow/router correlation context: - - `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` - - `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md` + - `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` + - `docs/adr/draft/ADR-0021-substrate-workflow-engine.md` - `docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` - Existing proof surfaces: - `crates/shell/tests/agent_public_control_surface_v1.rs` From 1d2e2699881dc8e768caf29c1417eeb3121e0275 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 19:31:59 -0400 Subject: [PATCH 16/20] Curate implemented ADR references --- docs/BACKLOG.md | 2 +- docs/PROJECT_MANAGEMENT_RETIREMENT.md | 28 +++++--- docs/adr/CURATION.md | 57 ++++++++++++++-- ...al-show-when-workspace-config-overrides.md | 4 +- ...R-0020-profiles-config-policy-snapshots.md | 4 +- ...-and-config-mental-model-simplification.md | 65 ++++++++++++++++++ ...05-workspace-config-precedence-over-env.md | 59 +++++++++++++++++ ...006-env-var-taxonomy-and-override-split.md | 57 ++++++++++++++++ ...icy-scope-and-dot-substrate-unification.md | 63 ++++++++++++++++++ ...fig-schema-per-key-merge-and-provenance.md | 57 ++++++++++++++++ ...y-broker-canonical-effective-resolution.md | 56 ++++++++++++++++ ...-system-package-mutation-for-world-deps.md | 66 +++++++++++++++++++ ...tem-package-provisioning-for-world-deps.md | 65 ++++++++++++++++++ docs/adr/implemented/README.md | 8 +++ .../internals/config/world_root_and_caging.md | 5 +- docs/internals/env/inventory.md | 2 +- .../PROVISIONING_SURFACE_RECONCILIATION.md | 19 +++--- ...-and-linux-system-packages-provisioning.md | 6 +- .../adrs/draft/ADR-0030-provisioning-otter.md | 6 ++ .../adrs/draft/ADR-0033-routing-weasel.md | 8 ++- ...-install-classes-and-world-provisioning.md | 18 +++++ ...-and-config-mental-model-simplification.md | 6 ++ ...05-workspace-config-precedence-over-env.md | 12 +++- ...006-env-var-taxonomy-and-override-split.md | 14 ++-- ...icy-scope-and-dot-substrate-unification.md | 24 ++++--- ...fig-schema-per-key-merge-and-provenance.md | 12 +++- ...y-broker-canonical-effective-resolution.md | 12 +++- docs/reference/config/contract.md | 5 +- docs/reference/config/world.md | 4 +- 29 files changed, 682 insertions(+), 62 deletions(-) create mode 100644 docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md create mode 100644 docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md create mode 100644 docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md create mode 100644 docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md create mode 100644 docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md create mode 100644 docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md create mode 100644 docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md create mode 100644 docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md diff --git a/docs/BACKLOG.md b/docs/BACKLOG.md index 766ad096c..97d452eef 100644 --- a/docs/BACKLOG.md +++ b/docs/BACKLOG.md @@ -57,7 +57,7 @@ Keep concise, actionable, and security-focused. - Install/dev scripts MUST NOT export override inputs by default (they remain explicit one-off operator/test inputs). - Acceptance: - New/updated tests prove that when a workspace is enabled and `SUBSTRATE_OVERRIDE_*` is set, override env beats the workspace patch (and remains below CLI flags where flags exist). - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`, `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md`, and `docs/reference/env/contract.md` reflect the updated precedence contract. + - `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`, `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md`, and `docs/reference/env/contract.md` reflect the updated precedence contract. - **P1 – Warn on `config global show` when workspace config overrides** - Problem: `substrate policy global show` emits a clear note when a workspace policy overrides the global policy for the current directory, but `substrate config global show` does not emit an equivalent warning when `.substrate/workspace.yaml` overrides global config. This is confusing and makes it easy to misdiagnose “why does my config not match behavior?” diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 685d82eb5..3efd95b53 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -110,9 +110,9 @@ Validation already completed for the finished slices: - scoped rewrites under `docs/project_management/adrs/**` now point ADR-0027 foundation references at `docs/reference/policy/{contract,schema}.md`, and the provisioning reconciliation note now points at stable world-deps references instead of implemented pack contracts -- the remaining direct pack-contract citations under `docs/project_management/adrs/**` are now - concentrated in draft provisioning ADRs that still cite their own feature-pack contract surfaces - (`ADR-0030`, `ADR-0033`) +- the provisioning ADR pair `ADR-0030` and `ADR-0033` is now curated into + `docs/adr/implemented/`, and current planning readers have been repointed toward the curated + namespace - initial gateway-local manifest normalization under `crates/gateway/docs/project_management/**` now uses monorepo-correct `crates/gateway/docs/project_management/packs/**` refs in evidence payloads that previously @@ -404,16 +404,24 @@ Completed in this slice: - promoted implemented ADR `ADR-0016` into `docs/adr/implemented/` - promoted queued ADRs `ADR-0019` and `ADR-0020` into `docs/adr/draft/` - repointed current ADR references from `ADR-0016` and `ADR-0020` toward the curated namespace +- classified the provisioning ADR pair +- promoted implemented ADRs `ADR-0030` and `ADR-0033` into `docs/adr/implemented/` +- repointed current provisioning ADR references toward the curated namespace +- classified the config/policy foundation ADR batch +- promoted implemented ADRs `ADR-0003`, `ADR-0005`, `ADR-0006`, `ADR-0008`, `ADR-0012`, and + `ADR-0013` into `docs/adr/implemented/` +- repointed stable config/env readers and current draft ADR references toward the curated namespace ## Recommended Resume Order Use this order in the next session: -1. Reclassify and promote the next current ADR cluster. - - The next explicit slice is the provisioning ADR pair `ADR-0030` and `ADR-0033`. +1. Curate the remaining world/runtime foundation ADRs that stable docs or code still treat as + current semantic anchors. 2. Continue narrowing the remaining `docs/project_management/**` dependency surface after the ADR registry stops pointing stable readers at the retiring namespace. -3. Do not reopen the completed current ADR clusters unless a remaining stable consumer still points +3. Keep current stable-reader rewrites ahead of broad historical cleanup. +4. Do not reopen the completed current ADR clusters unless a remaining stable consumer still points at the old copies. ## Resume Notes @@ -425,8 +433,12 @@ Use this order in the next session: which is now treated as queued draft work under `docs/adr/draft/`. - The orchestration/workflow batch is now classified and promoted. - The remaining current ADR tail is now classified and promoted. -- The next correct move is the dedicated provisioning ADR slice (`ADR-0030` / `ADR-0033`), not - another broad stable-doc extraction pass or a return to already-curated clusters. +- The dedicated provisioning ADR slice (`ADR-0030` / `ADR-0033`) is now complete. +- The config/policy foundation ADR slice (`ADR-0003`, `ADR-0005`, `ADR-0006`, `ADR-0008`, + `ADR-0012`, `ADR-0013`) is now complete. +- The next correct move is curating the remaining world/runtime foundation ADRs and continuing to + narrow the remaining `docs/project_management/**` dependency surface, not reopening + already-curated ADR clusters. - Treat the repo-wide `docs/project_management/**` cleanup as subordinate to that ADR curation milestone; otherwise you risk repeatedly repointing docs toward a namespace that is still meant to be retired. diff --git a/docs/adr/CURATION.md b/docs/adr/CURATION.md index 7564e7838..25854c01f 100644 --- a/docs/adr/CURATION.md +++ b/docs/adr/CURATION.md @@ -88,9 +88,8 @@ The following curated ADRs now exist under `docs/adr/implemented/`: - This ledger does not yet classify the full ADR registry. - The legacy project-management ADR files remain in place with relocation notes; this slice does not yet archive or delete those historical source files. -- This ledger does not yet decide the final disposition of provisioning ADRs `ADR-0030` and - `ADR-0033`; they remain separate because their pack-owned contract references may still be - intentional until that narrower provisioning cluster is curated. +- This ledger still leaves the broader `docs/project_management/**` dependency cleanup for later + retirement slices after current ADR curation is complete. ## Second Cluster: Superseded Gateway and Agent-Hub Predecessors @@ -178,11 +177,57 @@ The following curated draft ADRs now exist under `docs/adr/draft/`: - `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` - `docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md` +## Fifth Cluster: Provisioning-Time System-Package ADRs + +This slice curates the remaining current provisioning ADR pair. Both decisions are already +implemented in the world-deps operator contract, runtime fail-early behavior, inventory schema, +and guest-world provisioning flow, so they belong in the implemented tree rather than in a +long-lived draft bucket. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0030 | `docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md` | `stable_keeper` | `draft_but_implemented` | The explicit `substrate world enable --provision-deps` contract, runtime fail-early posture, and no-host-mutation guarantee are already implemented and documented in stable world-deps references. | +| ADR-0033 | `docs/project_management/adrs/draft/ADR-0033-routing-weasel.md` | `stable_keeper` | `draft_but_implemented` | Manager-aware provisioning and `install.method=pacman` are already implemented in the inventory/runtime stack and stable world-deps docs, so this ADR is no longer only queued rationale. | + +## Promoted In This Slice + +The following curated implemented ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` + +## Sixth Cluster: Config and Policy Foundation ADRs + +This slice curates the already-implemented config and policy foundation ADRs that stable operator +and internals docs still use as current semantic anchors. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0003 | `docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` | `stable_keeper` | `implemented` | Stable config docs still depend on its canonical file-name, workspace, and terminology model. | +| ADR-0005 | `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` | `stable_keeper` | `implemented` | The current config/env precedence contract is already exposed in stable config and env docs. | +| ADR-0006 | `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` | `stable_keeper` | `implemented` | The supported env-variable contract and inventory still depend on its taxonomy and override split. | +| ADR-0008 | `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` | `stable_keeper` | `implemented` | It defines the shared patch-file scope model that current config, policy, and world-deps docs still rely on. | +| ADR-0012 | `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` | `stable_keeper` | `implemented` | Current config and world-deps docs rely on its merge-strategy and provenance contract. | +| ADR-0013 | `docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` | `stable_keeper` | `implemented` | Stable policy and config docs depend on broker-canonical patch-only policy resolution semantics. | + +## Promoted In This Slice + +The following curated implemented ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` + ## Next Resume Slice -The remaining current ADR tail is now classified and promoted. Next, continue with: +The remaining current ADR tail, provisioning slice, and config/policy foundation slice are now +classified and promoted. Next, continue with: -1. keep provisioning ADRs `ADR-0030` and `ADR-0033` as the next explicit curation slice -2. after that, narrow any remaining `docs/project_management/**` dependency surface that still +1. curate the remaining world/runtime foundation ADRs that stable docs or code still treat as + current semantic anchors +2. narrow any remaining `docs/project_management/**` dependency surface that still points stable readers at retiring namespaces 3. do not reopen already-curated ADR clusters unless new stable references are discovered diff --git a/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md index 677a8ca81..26a131775 100644 --- a/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md +++ b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md @@ -34,8 +34,8 @@ stable contract yet. When implementation is ready, it should be restated against: -- `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` -- `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` ## Draft Note diff --git a/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md b/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md index 4e6ed1621..f908c2a0a 100644 --- a/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md +++ b/docs/adr/draft/ADR-0020-profiles-config-policy-snapshots.md @@ -34,8 +34,8 @@ stable contract. When implementation is ready, it should be restated against: -- `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` -- `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - `docs/adr/implemented/ADR-0016-world-first-repl-persistent-pty.md` ## Draft Note diff --git a/docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md b/docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md new file mode 100644 index 000000000..0c5f58db2 --- /dev/null +++ b/docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md @@ -0,0 +1,65 @@ +# ADR-0003 — Policy and Config Mental Model Simplification + +## Status + +- Status: Implemented +- Original date (UTC): 2025-12-27 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): spenser + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- Original untemplated draft retained for history: + - `docs/project_management/adrs/draft/ADR-0003-policy-and-config-mental-model-simplification_OG.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Substrate config and policy must follow one strict, explainable mental model with canonical file +names, explicit scope boundaries, and no legacy discovery fallbacks. + +The stable decision is: + +- canonical config and policy inputs live under `$SUBSTRATE_HOME` and `.substrate/` using + `config.yaml`, `policy.yaml`, and `workspace.yaml` +- workspace discovery is explicit and deterministic +- `anchor` terminology replaces older `root` naming for world-root selection +- policy mode is an explicit contract surface rather than an implicit runtime posture +- cached exported state belongs to generated env scripts and must not create ambiguous config + discovery + +## Stable Owned Surface + +This ADR anchors the stable config and policy mental model documented in: + +- `docs/reference/config/contract.md` +- `docs/reference/config/world.md` +- `docs/CONFIGURATION.md` +- `docs/internals/config/world_root_and_caging.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/common/src/paths.rs` +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/workspace.rs` +- `crates/shell/src/execution/settings/builder.rs` +- `crates/shell/src/execution/manager.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` + +## Historical Note + +The original ADR captured the large cleanup that removed overlapping config and policy concepts. +The stable operator and runtime contract now lives here and in the reference docs. diff --git a/docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md b/docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md new file mode 100644 index 000000000..ec2ca3598 --- /dev/null +++ b/docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md @@ -0,0 +1,59 @@ +# ADR-0005 — Workspace Config Precedence Over Env + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-02 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): spenser + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +When an enabled workspace exists, workspace config is authoritative over environment-exported +state and no-workspace override env inputs. + +The stable decision is: + +- workspace config at `/.substrate/workspace.yaml` overrides global config for + effective config resolution +- when an enabled workspace exists, `SUBSTRATE_OVERRIDE_*` config inputs are ignored +- CLI flags remain the highest-precedence config inputs where a flag exists +- no-workspace runs may still use `SUBSTRATE_OVERRIDE_*` as run-only override inputs + +## Stable Owned Surface + +This ADR owns the current precedence contract documented in: + +- `docs/reference/config/contract.md` +- `docs/reference/config/world.md` +- `docs/reference/env/contract.md` +- `docs/CONFIGURATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/config_cmd.rs` +- `crates/shell/src/execution/workspace.rs` +- `crates/shell/tests/config_show.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + +## Historical Note + +The original ADR captured the correction to the earlier precedence model once stable env exports +made workspace-vs-env ambiguity visible. The stable precedence contract now lives here and in the +config and env reference docs. diff --git a/docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md b/docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md new file mode 100644 index 000000000..689d14c06 --- /dev/null +++ b/docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md @@ -0,0 +1,57 @@ +# ADR-0006 — Env Var Taxonomy and Override Split + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-04 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): spenser + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Exported state and operator override inputs must use distinct environment-variable roles so cached +state does not masquerade as intentional config override. + +The stable decision is: + +- exported session state remains under `SUBSTRATE_*` +- config-shaped operator override inputs use `SUBSTRATE_OVERRIDE_*` +- exported state variables are outputs, not supported override inputs +- environment taxonomy is explicit across shell, shim, world, and install surfaces + +## Stable Owned Surface + +This ADR owns the supported env-variable contract documented in: + +- `docs/reference/env/contract.md` +- `docs/ENVIRONMENT_VARIABLES.md` +- `docs/internals/env/inventory.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/env_scripts.rs` +- `crates/shell/src/execution/manager.rs` +- `scripts/substrate/install-substrate.sh` +- `crates/shell/tests/config_show.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + +## Historical Note + +The original ADR captured the cleanup from dual-use `SUBSTRATE_*` variables to a clearer env +contract. The stable operator-facing contract now lives here and in the env reference docs. diff --git a/docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md b/docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md new file mode 100644 index 000000000..a5759454b --- /dev/null +++ b/docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md @@ -0,0 +1,63 @@ +# ADR-0008 — Workspace Config and Policy Scope Unification + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-10 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): spenser + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Config and policy use sparse patch files at global and workspace scopes under one `.substrate/` +layout and one shared workspace discovery model. + +The stable decision is: + +- global patches live under `$SUBSTRATE_HOME` +- workspace patches live under `/.substrate/` +- config and policy commands operate on patch files, not hidden alternate formats +- workspace discovery, workspace disable markers, and patch-file ownership are shared across + config and policy flows +- current/global/workspace command surfaces expose effective views separately from raw patch files + +## Stable Owned Surface + +This ADR owns the patch-file scope model documented in: + +- `docs/reference/config/contract.md` +- `docs/reference/env/contract.md` +- `docs/reference/world/deps/README.md` +- `docs/CONFIGURATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/common/src/paths.rs` +- `crates/shell/src/execution/config_cmd.rs` +- `crates/shell/src/execution/policy_cmd.rs` +- `crates/shell/src/execution/workspace_cmd.rs` +- `crates/shell/src/execution/workspace.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` + +## Historical Note + +The original ADR captured the migration from ad hoc config and policy files to the shared +patch-file scope model. The stable contract now lives here and in the config, env, and world-deps +reference docs. diff --git a/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md b/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md new file mode 100644 index 000000000..9ac23a659 --- /dev/null +++ b/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md @@ -0,0 +1,57 @@ +# ADR-0012 — Config Schema Per-Key Merge and Provenance + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-14 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Config patch files remain sparse YAML containers, but the schema owns how each key merges and how +effective config provenance is explained. + +The stable decision is: + +- merge behavior is defined per key rather than by one global file-level rule +- most keys use replace semantics, while selected keys intentionally merge across scopes +- effective config explainability must surface merge strategy and contributing sources +- `world.deps.enabled` is an additive key and follows deterministic ordered-set merge semantics + +## Stable Owned Surface + +This ADR owns the merge and provenance contract documented in: + +- `docs/reference/config/contract.md` +- `docs/reference/world/deps/README.md` +- `docs/CONFIGURATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/config_cmd.rs` +- `crates/shell/src/execution/policy_cmd.rs` +- `crates/shell/tests/config_show.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md` +- `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` + +## Historical Note + +The original ADR captured the refinement that made additive config keys and explainable provenance +compatible with the shared patch-file model. The stable merge contract now lives here and in the +config and world-deps reference docs. diff --git a/docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md b/docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md new file mode 100644 index 000000000..435f0506c --- /dev/null +++ b/docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md @@ -0,0 +1,56 @@ +# ADR-0013 — Policy Patch-Only Broker Canonical Effective Resolution + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-17 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell/Broker maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Policy files are patch-only everywhere, and the broker is the canonical resolver for the effective +policy consumed by CLI and runtime execution surfaces. + +The stable decision is: + +- `policy.yaml` is a sparse patch format rather than a parallel full-document contract +- effective policy resolution follows defaults, global patch, then workspace patch +- broker-owned workspace discovery must honor `.substrate/workspace.disabled` +- runtime execution surfaces must not silently diverge from `policy current show` + +## Stable Owned Surface + +This ADR owns the stable policy-resolution contract documented in: + +- `docs/reference/policy/contract.md` +- `docs/reference/policy/schema.md` +- `docs/CONFIGURATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/broker/src/effective_policy.rs` +- `crates/broker/src/profile.rs` +- `crates/broker/src/policy.rs` +- `crates/shell/src/execution/policy_cmd.rs` +- `crates/broker/src/tests.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` + +## Historical Note + +The original ADR captured the consolidation from conflicting policy loaders to one broker-owned +effective-policy resolver. The stable contract now lives here and in the policy reference docs. diff --git a/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md b/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md new file mode 100644 index 000000000..c489f0550 --- /dev/null +++ b/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md @@ -0,0 +1,66 @@ +# ADR-0030 — Provisioning-Time System-Package Mutation for World Deps + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers; World backend maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +World-deps system-package mutation must be explicit, provisioning-time only, and isolated from +runtime dependency application. + +The stable decision is: + +- `substrate world enable --provision-deps` is the only Substrate command that may mutate + system packages for world deps +- runtime `substrate world deps current sync` and `install` remain probe-only for + system-package-backed items +- requirement derivation comes from the effective enabled world-deps set for the current + directory rather than ad hoc package-manager invocation at runtime +- provisioning is allowed only on supported guest-world backends; Linux host-native and Windows + remain fail-closed and must not mutate the host OS +- provisioning uses a reserved internal request posture so explicit guest mutation does not relax + the normal hardened runtime execution profile + +## Stable Owned Surface + +This ADR owns the stable provisioning-time contract documented in: + +- `docs/reference/world/deps/provisioning.md` +- `docs/reference/world/deps/README.md` +- `docs/internals/world/deps.md` +- `docs/WORLD.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/cli.rs` +- `crates/shell/src/builtins/world_enable/runner.rs` +- `crates/shell/src/builtins/world_enable/runner/provision_deps.rs` +- `crates/shell/src/builtins/world_deps/surfaces.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/world_enable_provision_deps_wdap0.rs` +- `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +- `docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md` +- `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` + +## Historical Note + +The original ADR captures the option analysis and rollout framing for the shift away from runtime +APT mutation. The stable operator contract now lives here and in the world-deps reference docs. diff --git a/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md b/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md new file mode 100644 index 000000000..2ba206791 --- /dev/null +++ b/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md @@ -0,0 +1,65 @@ +# ADR-0033 — Manager-Aware System-Package Provisioning for World Deps + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers; World backend maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0033-routing-weasel.md` + +This curated ADR is the stable decision record. The project-management ADR remains as the +planning-rich historical source. + +## Decision + +The world-deps provisioning surface must route system-package installation by world OS package +manager without reopening runtime mutation or host-OS mutation. + +The stable decision is: + +- `install.method=pacman` is a first-class world-deps schema surface alongside `apt`, `script`, + and `manual` +- `substrate world enable --provision-deps` performs an in-world manager probe and provisions via + the matching system-package manager on supported guest worlds +- runtime `substrate world deps current sync` and `install` never invoke `apt`, mutating `dpkg`, + or `pacman`; they stay probe-only and fail early with remediation +- mixed-manager enabled sets fail before mutation rather than guessing or partially provisioning +- manager selection is derived from the world execution environment, not host PATH inspection or + host package-manager availability + +## Stable Owned Surface + +This ADR extends the stable provisioning contract documented in: + +- `docs/reference/world/deps/provisioning.md` +- `docs/reference/world/deps/README.md` +- `docs/internals/world/deps.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/world_deps/inventory.rs` +- `crates/shell/src/builtins/world_enable/runner.rs` +- `crates/shell/src/builtins/world_enable/runner/provision_deps.rs` +- `crates/shell/src/builtins/world_deps/surfaces.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/world_enable_provision_deps_wdap0.rs` +- `crates/shell/tests/world_deps_inventory_validation_wdp0.rs` +- `crates/shell/tests/world_deps_apt_fail_early_wdap1.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` + +## Historical Note + +The original ADR captures the rollout and contract-reconciliation work needed to add pacman-backed +guest provisioning. The stable manager-aware provisioning contract now lives here and in the +world-deps reference docs. diff --git a/docs/adr/implemented/README.md b/docs/adr/implemented/README.md index 805f3d775..fa2b62451 100644 --- a/docs/adr/implemented/README.md +++ b/docs/adr/implemented/README.md @@ -7,10 +7,18 @@ Use it for ADRs that still explain current Substrate behavior after Current curated set: +- `ADR-0003-policy-and-config-mental-model-simplification.md` +- `ADR-0005-workspace-config-precedence-over-env.md` +- `ADR-0006-env-var-taxonomy-and-override-split.md` +- `ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` - `ADR-0016-world-first-repl-persistent-pty.md` - `ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` - `ADR-0028-in-world-process-execution-tracing-parity.md` - `ADR-0027-llm-and-agent-config-policy-surface.md` +- `ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- `ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` - `ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `ADR-0041-substrate-gateway-backend-adapter-contract.md` - `ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` diff --git a/docs/internals/config/world_root_and_caging.md b/docs/internals/config/world_root_and_caging.md index 55870c5dc..a08e84b64 100644 --- a/docs/internals/config/world_root_and_caging.md +++ b/docs/internals/config/world_root_and_caging.md @@ -23,8 +23,8 @@ The effective config is resolved from defaults + global config + workspace confi - `docs/CONFIGURATION.md` - `docs/reference/config/contract.md` -- ADRs: `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md`, - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- ADRs: `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md`, + `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` The settings relevant to this document: @@ -159,4 +159,3 @@ Repro harness: - `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` - REPL persistent sessions and drift restarts: - `docs/internals/repl/persistent_session.md` - diff --git a/docs/internals/env/inventory.md b/docs/internals/env/inventory.md index d298e2795..f0e1da7ee 100644 --- a/docs/internals/env/inventory.md +++ b/docs/internals/env/inventory.md @@ -4,7 +4,7 @@ This is the exhaustive, repo-grounded inventory of environment variables that Su It is not an operator-facing stability promise. The stability labels in the catalog are scoped to this repo (e.g., “test-only”, “script-only”, “internal”). -- Governing ADR (taxonomy intent, not a usage source of truth): `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- Governing ADR (taxonomy intent, not a usage source of truth): `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` ## Coverage Checklist diff --git a/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md b/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md index 21e695f30..3a788122f 100644 --- a/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md +++ b/docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md @@ -21,6 +21,10 @@ The most authoritative current references are: - points missing-package remediation at `substrate world enable --provision-deps` - [`docs/reference/world/deps/provisioning.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/reference/world/deps/provisioning.md) - authoritative operator-facing contract for provisioning-time mutation, runtime fail-early behavior, and supported backend posture +- [`docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md) + - curated stable ADR for the explicit provisioning-time system-package posture +- [`docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md) + - curated stable ADR for manager-aware system-package provisioning - [`docs/internals/world/deps.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/internals/world/deps.md) - authoritative implementation-oriented reference for inventory structure, enabled-set resolution, wrapper behavior, and runtime probe-only posture - [`docs/WORLD.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/WORLD.md) @@ -67,29 +71,28 @@ These documents are still useful for understanding why the system evolved the wa - historical planning/archive material - stale on both command surface and selection model - [`docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md) - - still valuable as the rationale for the explicit provisioning-time workflow + - planning-rich historical source for the same decision - includes option analysis for the older `substrate world deps provision` command - - authoritative direction in this ADR is still `substrate world enable --provision-deps`, not the rejected option text ## Relationship between the ADR chain - [`ADR-0002`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md) is best treated as historical framing, not as the current command contract. - [`ADR-0011`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md) is the stronger source for today’s inventory and enabled-set model. -- [`ADR-0030`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md) defines the explicit provisioning-time posture that the current implementation follows. -- [`ADR-0033`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0033-routing-weasel.md) extends that provisioning surface to manager-aware routing for `pacman` as well as `apt`. +- [`ADR-0030`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md) defines the explicit provisioning-time posture that the current implementation follows. +- [`ADR-0033`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md) extends that provisioning surface to manager-aware routing for `pacman` as well as `apt`. - [`ADR-0009`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md) extends the existing `world enable --provision-deps` contract for future Linux guest-rootfs support; it must not reintroduce `world deps provision`. ## What should be updated next To make the documentation chain consistent end to end, the next updates should be: -1. Add an explicit supersession note to [`ADR-0002`](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md) stating that: - - the current provisioning command is `substrate world enable --provision-deps` - - the current enabled-set model comes from the packages/bundles contract rather than `world-deps.selection.yaml` +1. `ADR-0002` now carries an explicit supersession note that points current readers at + `substrate world enable --provision-deps`, the stable world-deps docs, and the curated ADRs. 2. Update any lingering non-archived docs that still say `substrate world deps provision` to `substrate world enable --provision-deps`, unless they are intentionally discussing rejected historical options. 3. Update any lingering non-archived docs that still present `world-deps.selection.yaml` as current operator truth. 4. Keep archived materials archived; do not “fix” them into looking current unless they are explicitly being revived. -5. If the team wants `ADR-0030`, `ADR-0031`, `ADR-0032`, `ADR-0033`, and `ADR-0035` treated as fully landed, move or restate them in a way that matches their implemented status instead of leaving them only under `draft/`. +5. `ADR-0030` and `ADR-0033` are now curated into `docs/adr/implemented/`; any future cleanup should + treat the project-management copies as historical source rather than the stable ADR home. ## Practical reading order diff --git a/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md b/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md index 52e58f0bb..fd10ad9f3 100644 --- a/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md +++ b/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md @@ -16,8 +16,8 @@ ## Related Docs - Prior ADR (world-deps install-class and provisioning posture): `docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md` -- Current provisioning surface: `docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md` -- Future non-APT guest-image routing context: `docs/project_management/adrs/draft/ADR-0033-routing-weasel.md` +- Current provisioning surface: `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- Future non-APT guest-image routing context: `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` - Future backend capability alignment: `docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` - Prior hardening track (full cage / Landlock): `docs/project_management/_archived/p0-agent-hub-isolation-hardening/ADR-0001-agent-hub-runtime-config-and-isolation.md` - World architecture: `docs/WORLD.md` @@ -46,7 +46,7 @@ ADR_BODY_SHA256: 056a47bf1016afd1fc53a0b8ec7bf419da811ee3b7bdcf0ce77abca92cc5b87 - Why: preserves the ADR-0002 / ADR-0030 threat model while making guest-backed Linux provisioning possible. - Links: - `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md#user-contract-authoritative` - - `docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md#user-contract-authoritative` + - `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` - `docs/reference/world/deps/README.md#provisioning-contract` ## Problem / Context diff --git a/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md b/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md index 99b1ae633..f5148ba87 100644 --- a/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md +++ b/docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-21 - Owner(s): ASSUMPTION: Shell maintainers; World backend maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/world-deps-apt-provisioning/` (ASSUMPTION: new pack) - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0033-routing-weasel.md b/docs/project_management/adrs/draft/ADR-0033-routing-weasel.md index 3a14355ff..4e47aa4be 100644 --- a/docs/project_management/adrs/draft/ADR-0033-routing-weasel.md +++ b/docs/project_management/adrs/draft/ADR-0033-routing-weasel.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-21 - Owner(s): ASSUMPTION: Shell maintainers; World backend maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/add-non-apt-system-package-provisioning-support/` (ASSUMPTION: new pack) @@ -21,7 +27,7 @@ - Internals (current behavior notes): `docs/internals/world/deps.md` - Pack-root manager-aware contract: `docs/project_management/packs/draft/add-non-apt-system-package-provisioning-support/contract.md` - Inventory layering / enabled resolution / non-system-package behavior: `docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md` -- Provisioning-time system packages (APT baseline): `docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md` +- Provisioning-time system packages (APT baseline): `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` - Linux guest-rootfs roadmap context (system packages on Linux): `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` - Operator reference: `docs/reference/world/deps/README.md` - Plan: `docs/project_management/packs/draft/add-non-apt-system-package-provisioning-support/plan.md` diff --git a/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md b/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md index 10fc56aa9..501bd8276 100644 --- a/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md +++ b/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md @@ -1,5 +1,23 @@ # ADR-0002: World-Deps Install Classes + Provisioning-Time System Packages +> NOTICE (2026-05-26) +> +> This ADR remains useful historical framing for world-deps install classes, but it is stale on +> the current provisioning command surface and enabled-set model. +> +> Current readers should use: +> - `docs/reference/world/deps/README.md` +> - `docs/reference/world/deps/provisioning.md` +> - `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +> - `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +> +> Superseded details in this ADR include: +> - `substrate world deps provision` +> - replaced by `substrate world enable --provision-deps` +> - `world-deps.selection.yaml` +> - replaced by inventory directories plus `world.deps.enabled` patch keys under +> `$SUBSTRATE_HOME/config.yaml` and `/.substrate/workspace.yaml` + Status: Accepted Last updated: 2025-12-24 diff --git a/docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md b/docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md index ad46ee0f9..acc12a1dd 100644 --- a/docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md +++ b/docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md @@ -6,6 +6,12 @@ - Date (UTC): 2025-12-27 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/policy_and_config_mental_model_simplification/` diff --git a/docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md b/docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md index c8e61a2cd..fdca59007 100644 --- a/docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md +++ b/docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-02 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/policy_and_config_precedence/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -15,7 +21,7 @@ - `docs/project_management/system/standards/ci/PLATFORM_INTEGRATION_AND_CI.md` ## Related Docs -- Prior ADR (baseline semantics): `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md` +- Prior ADR (baseline semantics): `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` - Plan: `docs/project_management/_archived/policy_and_config_precedence/plan.md` - Tasks: `docs/project_management/_archived/policy_and_config_precedence/tasks.json` - Specs: @@ -35,8 +41,8 @@ ADR_BODY_SHA256: 8d172cf13539c74060f84605af8f9b244d7b5ffc6d4c4413b0db0126b882876 - New: When a workspace exists, `.substrate/workspace.yaml` takes precedence over `SUBSTRATE_*` env exports for all config keys; env vars still apply when not in a workspace (and CLI flags remain highest precedence). - Why: Prevent “global config → env.sh → env overrides workspace config” confusion and eliminate the effective-precedence footgun caused by stable export scripts. - Links: - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md#L255` (effective config precedence in ADR-0003) - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md#L605` (env scripts and `env.sh` purpose) + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` (effective config precedence baseline) + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` (env script ownership baseline) - `crates/shell/src/execution/config_model.rs#L220` (current effective-config merge order) - `docs/project_management/_archived/policy_and_config_precedence/PCP0-spec.md` (implementation slice; authoritative acceptance criteria) diff --git a/docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md b/docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md index 774f62d50..475ff9612 100644 --- a/docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md +++ b/docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-04 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/env_var_taxonomy_and_override_split/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -18,8 +24,8 @@ ## Related Docs - Prior ADRs: - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md` - - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` + - `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` - Plan: `docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md` - Tasks: `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json` - Session log: `docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md` @@ -42,8 +48,8 @@ ADR_BODY_SHA256: 5a5e7ad83f9a3cfa6067168e0ee16e031321d3b1d056b7ee36055ad05a507cb - New: Exported state variables remain `SUBSTRATE_*`, but config resolution stops treating those state exports as override inputs. Operator override inputs move to a dedicated namespace: `SUBSTRATE_OVERRIDE_*`. - Why: Prevent confusion and eliminate the dual-use ambiguity where “cached state exports” look like intentional overrides. - Links: - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md#L608` (`env.sh` / `manager_env.sh` ownership model) - - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md#L33` (prior mitigation for workspace vs env) + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` (`env.sh` / `manager_env.sh` ownership model) + - `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` (prior mitigation for workspace vs env) - `crates/shell/src/execution/env_scripts.rs` (exported state generation) - `crates/shell/src/execution/config_model.rs#L220` (effective config resolution) - `docs/ENVIRONMENT_VARIABLES.md` (canonical taxonomy + catalog) diff --git a/docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md b/docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md index 2a42fa19d..edb5370bf 100644 --- a/docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md +++ b/docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-10 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/workspace-config-policy-unification/` - Sequencing spine: `docs/project_management/packs/sequencing.json` @@ -17,11 +23,11 @@ ## Related Docs - Prior ADRs: - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md` - - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` + - `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` + - `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - Follow-on ADRs: - - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` + - `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` - Decision Register: `docs/project_management/_archived/workspace-config-policy-unification/decision_register.md` ## Executive Summary (Operator) @@ -34,7 +40,7 @@ ADR_BODY_SHA256: c71df99fe654bfafa8627979fb744ffda05c2a7f495205eecfe39959659c5da - Why: Eliminate “why didn’t my global set take effect?” confusion and make config and policy semantics symmetric. - Links: - `docs/project_management/_archived/workspace-config-policy-unification/decision_register.md` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` + - `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - `crates/shell/src/execution/config_model.rs#L220` - Workspace state is unified under a single canonical `.substrate/` directory @@ -106,7 +112,7 @@ Config patch header template (global/workspace): # - Workspace patch: overrides the global patch + defaults. # - Global patch: overrides defaults. # - Merge semantics are schema-defined per key; most keys are `replace`, but some keys may intentionally merge across scopes. -# - See `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. +# - See `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. # - You may edit this file directly, or use the CLI (recommended) for validated updates: # - Global: `substrate config global set ...` / `substrate config global reset ...` # - Workspace: `substrate config workspace set ...` / `substrate config workspace reset ...` @@ -155,7 +161,7 @@ Policy patch header template (global/workspace): - Emits an additional machine-readable provenance map to **stderr**. - For most keys, provenance indicates a single source layer. - For keys whose effective value is derived from multiple layers (schema-defined merge keys), provenance MUST list all contributing sources deterministically. - - See `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. + - See `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. - Source labels include: - `cli_flag`, `override_env`, `workspace_patch`, `global_patch`, `default`, `injected_protected`. - Exit codes: @@ -251,7 +257,7 @@ Policy patch header template (global/workspace): - `--explain`: - Emits a per-key provenance breakdown to stderr. - If per-key merge strategies are introduced for policy keys, provenance must support multi-source keys as specified in: - - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. + - `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md`. - Exit codes: `0` success; `2` invalid YAML / invalid policy; `1` unexpected. #### `substrate policy global show [--json]` @@ -381,7 +387,7 @@ Protected exclude injection (always applied): The config patch is a YAML mapping where keys may be omitted to inherit. Unknown keys are a hard error. Per-key merge strategies (including multi-layer derived values) are defined by: -- `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` Allowed keys (base allowlist; extended by follow-on ADRs): - `world.enabled` (bool) diff --git a/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md b/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md index d47c5b9ea..b79646550 100644 --- a/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md +++ b/docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-14 - Owner(s): Shell maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directories (impacted): - `docs/project_management/_archived/next/` (this ADR; cross-cutting contract) @@ -16,7 +22,7 @@ ## Related Docs - Patch files + scope model: - - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + - `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - World-deps consumer contract: - `docs/reference/world/deps/README.md` - World-deps ADR (consumer workstream; not modified by this ADR): @@ -31,7 +37,7 @@ ADR_BODY_SHA256: 9f5ad467af8c83056bf9e06e1f6f2b3f1e9be8a58a0f35fc56b832fa957e964 - New: `current show --explain` supports keys whose effective value is derived from multiple layers (e.g. global + workspace), and reports those contributing sources deterministically. - Why: enables additive config keys (like `world.deps.enabled`) without creating a second parallel config system or confusing precedence. - Links: - - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + - `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - `docs/reference/world/deps/README.md` - Schema defines merge behavior per key @@ -39,7 +45,7 @@ ADR_BODY_SHA256: 9f5ad467af8c83056bf9e06e1f6f2b3f1e9be8a58a0f35fc56b832fa957e964 - New: patch files remain the container format, but the schema defines the effective merge strategy per key; most keys remain “replace”, while selected keys are explicitly “merge”. - Why: keeps patch files simple while allowing a small number of keys to be intentionally additive and still explainable. - Links: - - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + - `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` ## Problem / Context - ADR-0008 establishes: diff --git a/docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md b/docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md index d09224534..ea553bc9e 100644 --- a/docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md +++ b/docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-17 - Owner(s): Shell/Broker maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directories (impacted): - `docs/project_management/_archived/next/` (this ADR; cross-cutting contract) @@ -17,9 +23,9 @@ ## Related Docs - Baseline scope/file contract: - - `docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` + - `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` - Provenance + per-key merge strategy semantics (add-on to ADR-0008): - - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` + - `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` - Decision Register (this body of work): - `docs/project_management/_archived/policy-patch-only-broker-effective-resolution/decision_register.md` - Current (stale) operator docs that must be updated as part of this work: @@ -40,7 +46,7 @@ Run `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0013-policy-p - `crates/broker/src/policy.rs#L401` - `crates/shell/src/execution/policy_model.rs#L243` - `crates/shell/src/execution/routing/dispatch/exec.rs#L111` - - `docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` + - `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` - `docs/CONFIGURATION.md#L174` - Workspace disable marker is honored by the broker diff --git a/docs/reference/config/contract.md b/docs/reference/config/contract.md index 881a8e2a3..87cc9c4c8 100644 --- a/docs/reference/config/contract.md +++ b/docs/reference/config/contract.md @@ -10,6 +10,5 @@ Suggested sections: Existing related docs: - `docs/CONFIGURATION.md` -- `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md` -- `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` - +- `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` +- `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` diff --git a/docs/reference/config/world.md b/docs/reference/config/world.md index 6354b7517..85b45e0e0 100644 --- a/docs/reference/config/world.md +++ b/docs/reference/config/world.md @@ -130,6 +130,6 @@ Implementation notes live in: `docs/internals/world/deps.md`. - Config file locations and precedence: `docs/reference/config/contract.md` - Full configuration reference (including env overrides and exported state): `docs/CONFIGURATION.md` - Workspace definition and precedence model: - - `docs/project_management/adrs/queued/ADR-0003-policy-and-config-mental-model-simplification.md` - - `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md` + - `docs/adr/implemented/ADR-0003-policy-and-config-mental-model-simplification.md` + - `docs/adr/implemented/ADR-0005-workspace-config-precedence-over-env.md` - World filesystem isolation and policy model: `docs/WORLD.md` From 4d05e4a920e42ea24e0c02370fe07c8b85cd1c78 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 21:08:45 -0400 Subject: [PATCH 17/20] docs: classify remaining ADR tail and pack contract triage --- config/deps_examples/README.md | 14 ++ .../deps_examples/bundles/node-runtime.yaml | 5 + config/deps_examples/packages/asdf-node.yaml | 23 +++ config/deps_examples/packages/bun.yaml | 11 ++ config/deps_examples/packages/direnv.yaml | 14 ++ config/deps_examples/packages/nftables.yaml | 13 ++ config/deps_examples/packages/node.yaml | 12 ++ config/deps_examples/packages/npm.yaml | 12 ++ config/deps_examples/packages/nvm.yaml | 16 ++ .../packages/python-build-deps.yaml | 20 ++ config/deps_examples/packages/volta.yaml | 11 ++ config/deps_examples/scripts/bun.sh | 22 +++ config/deps_examples/scripts/nvm.sh | 15 ++ config/deps_examples/scripts/volta.sh | 25 +++ docs/PROJECT_MANAGEMENT_RETIREMENT.md | 171 ++++++++++++++++-- docs/TRACE.md | 2 +- docs/adr/CURATION.md | 90 ++++++++- ...-and-linux-system-packages-provisioning.md | 47 +++++ ...kend-contract-and-capability-divergence.md | 46 +++++ ...-macos-host-os-details-in-install-state.md | 44 +++++ ...-world-backend-virtualization-framework.md | 44 +++++ docs/adr/draft/README.md | 4 + ...-install-classes-and-world-provisioning.md | 45 +++++ docs/adr/historical/README.md | 1 + ...layfs-directory-enumeration-reliability.md | 60 ++++++ .../ADR-0007-host-and-world-doctor-scopes.md | 58 ++++++ ...11-world-deps-packages-bundles-contract.md | 63 +++++++ ...fig-schema-per-key-merge-and-provenance.md | 2 +- ...rvice-policy-resolution-and-concurrency.md | 60 ++++++ ...olation-landlock-overlayfs-backing-dirs.md | 60 ++++++ ...-fs-granular-allow-deny-and-strict-deny.md | 67 +++++++ ...-system-package-mutation-for-world-deps.md | 4 +- ...ackage-manager-discovery-during-install.md | 54 ++++++ ...kage-manager-detection-in-install-state.md | 54 ++++++ ...tem-package-provisioning-for-world-deps.md | 2 +- ...l-helper-discovery-under-substrate-home.md | 54 ++++++ ...-enable-work-after-dev-install-no-world.md | 55 ++++++ ...-class-status-in-health-and-shim-doctor.md | 56 ++++++ ...-health-attribute-why-world-is-disabled.md | 56 ++++++ ...ibute-why-world-is-disabled-in-warnings.md | 54 ++++++ docs/adr/implemented/README.md | 15 +- .../internals/config/world_root_and_caging.md | 2 +- docs/internals/trace/schema.md | 2 +- ...-and-linux-system-packages-provisioning.md | 6 + ...kend-contract-and-capability-divergence.md | 6 + .../adrs/draft/ADR-0031-detecting-badger.md | 6 + .../adrs/draft/ADR-0032-stashing-ferret.md | 6 + .../adrs/draft/ADR-0034-staging-beaver.md | 6 + .../adrs/draft/ADR-0035-summoning-wombat.md | 6 + .../adrs/draft/ADR-0036-quieting-lemur.md | 6 + .../adrs/draft/ADR-0037-clarifying-owl.md | 6 + .../adrs/draft/ADR-0038-replaying-raccoon.md | 6 + .../adrs/draft/ADR-0039-capturing-koala.md | 6 + ...-world-backend-virtualization-framework.md | 7 + ...-install-classes-and-world-provisioning.md | 2 + ...layfs-directory-enumeration-reliability.md | 6 + .../ADR-0007-host-and-world-doctor-scopes.md | 6 + ...11-world-deps-packages-bundles-contract.md | 6 + ...rvice-policy-resolution-and-concurrency.md | 6 + ...olation-landlock-overlayfs-backing-dirs.md | 6 + ...-fs-granular-allow-deny-and-strict-deny.md | 6 + 61 files changed, 1558 insertions(+), 32 deletions(-) create mode 100644 config/deps_examples/README.md create mode 100644 config/deps_examples/bundles/node-runtime.yaml create mode 100644 config/deps_examples/packages/asdf-node.yaml create mode 100644 config/deps_examples/packages/bun.yaml create mode 100644 config/deps_examples/packages/direnv.yaml create mode 100644 config/deps_examples/packages/nftables.yaml create mode 100644 config/deps_examples/packages/node.yaml create mode 100644 config/deps_examples/packages/npm.yaml create mode 100644 config/deps_examples/packages/nvm.yaml create mode 100644 config/deps_examples/packages/python-build-deps.yaml create mode 100644 config/deps_examples/packages/volta.yaml create mode 100644 config/deps_examples/scripts/bun.sh create mode 100644 config/deps_examples/scripts/nvm.sh create mode 100644 config/deps_examples/scripts/volta.sh create mode 100644 docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md create mode 100644 docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md create mode 100644 docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md create mode 100644 docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md create mode 100644 docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md create mode 100644 docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md create mode 100644 docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md create mode 100644 docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md create mode 100644 docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md create mode 100644 docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md create mode 100644 docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md create mode 100644 docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md create mode 100644 docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md create mode 100644 docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md create mode 100644 docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md create mode 100644 docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md create mode 100644 docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md create mode 100644 docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md diff --git a/config/deps_examples/README.md b/config/deps_examples/README.md new file mode 100644 index 000000000..55ec600be --- /dev/null +++ b/config/deps_examples/README.md @@ -0,0 +1,14 @@ +# World Deps `deps/` Examples + +These files are examples of the **per-item inventory** format described in: +- `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` + +They are intended to be copied into a scope’s inventory directory: +- Global: `~/.substrate/deps/` +- Workspace: `/.substrate/deps/` + +Layout mirrors the canonical on-disk format: +- `packages/.yaml` +- `bundles/.yaml` +- `scripts/*.sh` (referenced via `script_path`) + diff --git a/config/deps_examples/bundles/node-runtime.yaml b/config/deps_examples/bundles/node-runtime.yaml new file mode 100644 index 000000000..c4199ec77 --- /dev/null +++ b/config/deps_examples/bundles/node-runtime.yaml @@ -0,0 +1,5 @@ +version: 1 +name: node-runtime +description: Node.js + npm bundle. +packages: ["node", "npm"] + diff --git a/config/deps_examples/packages/asdf-node.yaml b/config/deps_examples/packages/asdf-node.yaml new file mode 100644 index 000000000..d7c531d39 --- /dev/null +++ b/config/deps_examples/packages/asdf-node.yaml @@ -0,0 +1,23 @@ +version: 1 +name: asdf-node +description: Example of a manual install that must be performed inside the world. +runnable: true +entrypoints: ["node", "npm", "npx"] +install: + method: manual + manual_instructions: | + Install nodejs via asdf manually inside the world, then ensure `node`, `npm`, and `npx` + are reachable from: + /var/lib/substrate/world-deps/bin + + Example (inside the world): + export ASDF_DIR="${ASDF_DIR:-$HOME/.asdf}" + "$ASDF_DIR/bin/asdf" plugin add nodejs https://github.com/asdf-vm/asdf-nodejs.git + "$ASDF_DIR/bin/asdf" install nodejs latest + "$ASDF_DIR/bin/asdf" global nodejs latest + ln -sf "$ASDF_DIR/shims/node" /var/lib/substrate/world-deps/bin/node + ln -sf "$ASDF_DIR/shims/npm" /var/lib/substrate/world-deps/bin/npm + ln -sf "$ASDF_DIR/shims/npx" /var/lib/substrate/world-deps/bin/npx +probe: + command: "command -v node >/dev/null 2>&1 && command -v npm >/dev/null 2>&1 && command -v npx >/dev/null 2>&1" + diff --git a/config/deps_examples/packages/bun.yaml b/config/deps_examples/packages/bun.yaml new file mode 100644 index 000000000..35d85b5dd --- /dev/null +++ b/config/deps_examples/packages/bun.yaml @@ -0,0 +1,11 @@ +version: 1 +name: bun +description: Bun runtime (script install into world-deps prefix). +runnable: true +entrypoints: ["bun"] +install: + method: script + script_path: ../scripts/bun.sh +probe: + command: "bun --version" + diff --git a/config/deps_examples/packages/direnv.yaml b/config/deps_examples/packages/direnv.yaml new file mode 100644 index 000000000..019fe62c4 --- /dev/null +++ b/config/deps_examples/packages/direnv.yaml @@ -0,0 +1,14 @@ +version: 1 +name: direnv +description: direnv CLI via apt (world image install). +runnable: true +entrypoints: ["direnv"] +install: + method: apt + apt: + - name: direnv + # Optional pin (only if the exact version is available in the world’s apt sources): + # version: "2.34.0-1" +probe: + command: "direnv version" + diff --git a/config/deps_examples/packages/nftables.yaml b/config/deps_examples/packages/nftables.yaml new file mode 100644 index 000000000..568d8acbd --- /dev/null +++ b/config/deps_examples/packages/nftables.yaml @@ -0,0 +1,13 @@ +version: 1 +name: nftables +description: Linux-only example (platform-filtered). +runnable: true +entrypoints: ["nft"] +platforms: [linux] +install: + method: apt + apt: + - name: nftables +probe: + command: "nft --version" + diff --git a/config/deps_examples/packages/node.yaml b/config/deps_examples/packages/node.yaml new file mode 100644 index 000000000..639c12d72 --- /dev/null +++ b/config/deps_examples/packages/node.yaml @@ -0,0 +1,12 @@ +version: 1 +name: node +description: Node.js runtime via apt. +runnable: true +entrypoints: ["node"] +install: + method: apt + apt: + - name: nodejs +probe: + command: "node --version" + diff --git a/config/deps_examples/packages/npm.yaml b/config/deps_examples/packages/npm.yaml new file mode 100644 index 000000000..54946d7f3 --- /dev/null +++ b/config/deps_examples/packages/npm.yaml @@ -0,0 +1,12 @@ +version: 1 +name: npm +description: npm CLI via apt. +runnable: true +entrypoints: ["npm", "npx"] +install: + method: apt + apt: + - name: npm +probe: + command: "npm --version && npx --version" + diff --git a/config/deps_examples/packages/nvm.yaml b/config/deps_examples/packages/nvm.yaml new file mode 100644 index 000000000..3e4436b66 --- /dev/null +++ b/config/deps_examples/packages/nvm.yaml @@ -0,0 +1,16 @@ +version: 1 +name: nvm +description: Node Version Manager (requires a wrapper; nvm is a bash function). +runnable: true +entrypoints: ["nvm"] +wrappers: + - name: nvm + kind: bash_function + bash_source: "${NVM_DIR:-$HOME/.nvm}/nvm.sh" + function: nvm +install: + method: script + script_path: ../scripts/nvm.sh +probe: + command: "/bin/bash -lc 'source \"${NVM_DIR:-$HOME/.nvm}/nvm.sh\" && nvm --version'" + diff --git a/config/deps_examples/packages/python-build-deps.yaml b/config/deps_examples/packages/python-build-deps.yaml new file mode 100644 index 000000000..2126c4527 --- /dev/null +++ b/config/deps_examples/packages/python-build-deps.yaml @@ -0,0 +1,20 @@ +version: 1 +name: python-build-deps +description: OS prerequisites for building CPython from source (non-runnable). +runnable: false +install: + method: apt + apt: + - name: build-essential + - name: make + - name: libssl-dev + - name: zlib1g-dev + - name: libbz2-dev + - name: libreadline-dev + - name: libsqlite3-dev + - name: xz-utils + - name: libffi-dev + - name: liblzma-dev +probe: + command: "command -v gcc >/dev/null 2>&1 && command -v make >/dev/null 2>&1" + diff --git a/config/deps_examples/packages/volta.yaml b/config/deps_examples/packages/volta.yaml new file mode 100644 index 000000000..959d9c5d7 --- /dev/null +++ b/config/deps_examples/packages/volta.yaml @@ -0,0 +1,11 @@ +version: 1 +name: volta +description: Volta toolchain manager (script install into world-deps prefix). +runnable: true +entrypoints: ["volta"] +install: + method: script + script_path: ../scripts/volta.sh +probe: + command: "volta --version" + diff --git a/config/deps_examples/scripts/bun.sh b/config/deps_examples/scripts/bun.sh new file mode 100644 index 000000000..57d52bad5 --- /dev/null +++ b/config/deps_examples/scripts/bun.sh @@ -0,0 +1,22 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Example script install that places the runnable entrypoint under: +# /var/lib/substrate/world-deps/bin + +world_deps_root="/var/lib/substrate/world-deps" +world_deps_bin="${world_deps_root}/bin" +bun_root="${world_deps_root}/bun" + +mkdir -p "${world_deps_bin}" +mkdir -p "${bun_root}" + +export BUN_INSTALL="${bun_root}" + +if [ -x "${bun_root}/bin/bun" ]; then + "${bun_root}/bin/bun" upgrade +else + curl -fsSL https://bun.sh/install | bash +fi + +ln -sf "${bun_root}/bin/bun" "${world_deps_bin}/bun" diff --git a/config/deps_examples/scripts/nvm.sh b/config/deps_examples/scripts/nvm.sh new file mode 100644 index 000000000..a020bed66 --- /dev/null +++ b/config/deps_examples/scripts/nvm.sh @@ -0,0 +1,15 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Example script install that fetches nvm into $HOME. +# The runnable `nvm` entrypoint is provided by `wrappers[]`, not by this script. + +export NVM_DIR="${NVM_DIR:-$HOME/.nvm}" +if [ ! -d "${NVM_DIR}" ]; then + curl -fsSL https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash +else + # Best-effort update. + if [ -d "${NVM_DIR}/.git" ]; then + (cd "${NVM_DIR}" && git pull --ff-only) || true + fi +fi diff --git a/config/deps_examples/scripts/volta.sh b/config/deps_examples/scripts/volta.sh new file mode 100644 index 000000000..80e41ae6d --- /dev/null +++ b/config/deps_examples/scripts/volta.sh @@ -0,0 +1,25 @@ +#!/usr/bin/env bash +set -euo pipefail + +# Example script install that installs Volta into the world-deps prefix and exposes: +# /var/lib/substrate/world-deps/bin/volta +# +# Note: This is only an example; real recipes may need additional OS deps. + +world_deps_root="/var/lib/substrate/world-deps" +world_deps_bin="${world_deps_root}/bin" +volta_home="${world_deps_root}/volta" + +mkdir -p "${world_deps_bin}" +mkdir -p "${volta_home}" + +export VOLTA_HOME="${volta_home}" +export PATH="${volta_home}/bin:${PATH}" + +if [ -x "${volta_home}/bin/volta" ]; then + "${volta_home}/bin/volta" self update || true +else + curl -fsSL https://get.volta.sh | bash +fi + +ln -sf "${volta_home}/bin/volta" "${world_deps_bin}/volta" diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index 3efd95b53..c8567694b 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -66,12 +66,13 @@ Still remaining before the atomic top-level `packs/**` removal: `docs/project_management/**` material rather than live shell wrappers - `llm-last-mile/**` and `FSE_PRE_PLANNING_*` are intentionally deferred for now and should not drive the next slice ordering -- the highest-value next namespace decision is ADR curation, because repeated backlink cleanup - inside `docs/project_management/adrs/**` has diminishing returns while the long-term destination - is now known to be `docs/adr/` -- the curation-policy question is now resolved for the first slice: +- the ADR destination question is now resolved: + - the stable registry is `docs/adr/**` + - repeated backlink cleanup inside `docs/project_management/adrs/**` now has diminishing returns + unless a live stable reader still points there +- the curation-policy question is now resolved: - use `restate + supersede`, not a blind directory move - - promote first-cluster keepers into `docs/adr/implemented/` + - promote current stable keepers into `docs/adr/{implemented,draft,historical}/` - the first-cluster promotion slice is now complete: - curated implemented ADRs exist for ADR-0027, ADR-0040, ADR-0041, ADR-0042, ADR-0043, and ADR-0046 @@ -113,6 +114,22 @@ Validation already completed for the finished slices: - the provisioning ADR pair `ADR-0030` and `ADR-0033` is now curated into `docs/adr/implemented/`, and current planning readers have been repointed toward the curated namespace +- the world/runtime foundation ADR batch is now curated into `docs/adr/implemented/`: + - ADR-0004 + - ADR-0007 + - ADR-0014 + - ADR-0015 + - ADR-0018 +- the world-deps predecessor pair is now split correctly: + - ADR-0002 is curated into `docs/adr/historical/` as stale historical framing + - ADR-0011 is curated into `docs/adr/implemented/` as the current inventory + enabled-set + contract +- the remaining installer/diagnostics/backend ADR tail is now classified into `docs/adr/**`: + - implemented ADRs: ADR-0031, ADR-0032, ADR-0034, ADR-0035, ADR-0036, ADR-0037, ADR-0038 + - curated drafts: ADR-0009, ADR-0010, ADR-0039, ADR-2026-02-13 macOS Virtualization.framework +- the remaining stable-doc ADR path hits outside `docs/project_management/**` have been repointed: + - `docs/internals/config/world_root_and_caging.md` now points at curated ADR-0018 + - `docs/TRACE.md` and `docs/internals/trace/schema.md` now point at curated ADR-0028 - initial gateway-local manifest normalization under `crates/gateway/docs/project_management/**` now uses monorepo-correct `crates/gateway/docs/project_management/packs/**` refs in evidence payloads that previously @@ -138,23 +155,41 @@ Validation already completed for the finished slices: - ADR-0041 - scoped scans over the current ADR consumer set no longer show old first-cluster draft ADR paths - curated implemented ADR files now also exist for: + - ADR-0004 + - ADR-0007 + - ADR-0011 + - ADR-0014 + - ADR-0015 + - ADR-0018 - ADR-0016 - ADR-0017 - ADR-0028 + - ADR-0031 + - ADR-0032 + - ADR-0034 + - ADR-0035 + - ADR-0036 + - ADR-0037 + - ADR-0038 - ADR-0047 - curated historical ADR files now exist for: + - ADR-0002 - ADR-0023 - ADR-0024 - ADR-0025 - curated draft ADR files now exist for: + - ADR-0009 + - ADR-0010 - ADR-0019 - ADR-0020 - ADR-0026 - ADR-0021 - ADR-0022 - ADR-0029 + - ADR-0039 - ADR-0044 - ADR-0045 + - ADR-2026-02-13 macOS Virtualization.framework ## Current Dependency Classes @@ -342,6 +377,100 @@ Remaining follow-up: - none for the stable-doc dependency itself; the remaining blockers now sit in tests and automation rather than `docs/reference/**` or `docs/internals/**` +### E. Remaining Pack Contract and Schema Triage + +The remaining `contract.md` / `SCHEMA.md` / `*schema-spec.md` files under +`docs/project_management/packs/**` are not all equal. Before the atomic `packs/**` cut, treat them +in three buckets: + +#### Already absorbed into stable docs; pack files can retire after backlink cleanup + +- trace parity pack surfaces: + - `docs/project_management/packs/active/world_process_exec_tracing_parity/contract.md` + - `docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md` + - stable home: + - `docs/internals/trace/schema.md` + - `docs/internals/trace/protocol.md` + - `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` +- world-deps provisioning and package-contract pack surfaces: + - `docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md` + - `docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md` + - `docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md` + - `docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md` + - `docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/world-deps-pacman-schema-spec.md` + - stable home: + - `docs/reference/world/deps/README.md` + - `docs/reference/world/deps/provisioning.md` + - `docs/internals/world/deps.md` + - `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` + - `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` + - `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +- policy / tuple / gateway contract pack surfaces: + - `docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/{contract.md,SCHEMA.md}` + - `docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/{contract.md,tuple-policy-schema-spec.md}` + - `docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/{contract.md,identity-tuple-schema-spec.md}` + - `docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/{contract.md,gateway-status-schema-spec.md}` + - `docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/{contract.md,gateway-backend-adapter-schema-spec.md}` + - stable home: + - `docs/reference/policy/{contract.md,schema.md,tuple_constraints.md}` + - `docs/contracts/gateway/{operator-contract.md,status-schema.md,policy-evaluation.md,backend-adapter-selection.md,backend-adapter-protocol.md,backend-adapter-schema.md,runtime-parity.md}` + - `docs/adr/implemented/ADR-0027-llm-and-agent-config-policy-surface.md` + - `docs/adr/implemented/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` + - `docs/adr/implemented/ADR-0041-substrate-gateway-backend-adapter-contract.md` + - `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + - `docs/adr/implemented/ADR-0043-adr-0027-identity-tuple-policy-surface.md` + - `docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md` +- workspace sync pack contract: + - `docs/project_management/packs/implemented/world-sync/contract.md` + - stable home: + - `docs/reference/cli/workspace_sync.md` + - `docs/internals/world/workspace_sync_filesystem_model.md` +- installer detection / replay attribution contract surfaces that are already sufficiently covered: + - `docs/project_management/packs/implemented/best-effort-distro-package-manager/contract.md` + - `docs/project_management/packs/implemented/world-disabled-reason-attribution/contract.md` + - stable home: + - `docs/INSTALLATION.md` + - `docs/reference/env/contract.md` + - `docs/REPLAY.md` + - `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` + - `docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` + +#### Preserve or move before deleting `packs/**` + +These files still carry stable contract detail that is only partially summarized elsewhere: + +- `docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/contract.md` + - preserve before deletion + - recommended destination: new stable contract doc under `docs/contracts/` for REPL structured + output routing, including `repl.max_pty_buffered_lines` and suppression-summary behavior +- `docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/agent-hub-event-envelope-schema-spec.md` + - preserve before deletion + - recommended destination: new stable event-envelope schema doc under `docs/contracts/` + because `TRACE.md` discusses `agent_event` rows but does not fully replace the envelope schema +- `docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/install-state-schema-spec.md` + - preserve before deletion + - recommended destination: new stable `install_state.json` schema doc under `docs/contracts/` + because `docs/INSTALLATION.md` lists the fields but does not capture the full additive schema + and compatibility rules +- `docs/project_management/packs/implemented/world-disabled-diagnostics/world-disabled-diagnostics-json-schema-spec.md` + - preserve before deletion + - recommended destination: new stable diagnostics JSON contract doc under `docs/contracts/` + because `docs/USAGE.md` summarizes `.shim.world.status` and `.shim.world_deps.status` but does + not replace the full machine-readable schema and omission rules + +#### Draft-pack contracts that should be folded into draft ADRs rather than promoted to stable contracts + +- `docs/project_management/packs/active/warn-config-global-show-workspace-overrides/contract.md` + - queued work; if the pack tree is removed before implementation, fold the normative CLI copy + into `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` +- `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md` + - still referenced by `llm-last-mile/**`; if the pack tree is removed, fold any still-normative + contract text into `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` + before deleting the pack path + +No other current pack-local `contract.md` / schema file has yet shown a stronger stable-home need +than the curated ADR plus existing reference/contract docs above. + ## Delete Or Rewrite Checklist Before Pack Removal ### Delete candidates @@ -416,13 +545,13 @@ Completed in this slice: Use this order in the next session: -1. Curate the remaining world/runtime foundation ADRs that stable docs or code still treat as - current semantic anchors. -2. Continue narrowing the remaining `docs/project_management/**` dependency surface after the - ADR registry stops pointing stable readers at the retiring namespace. -3. Keep current stable-reader rewrites ahead of broad historical cleanup. -4. Do not reopen the completed current ADR clusters unless a remaining stable consumer still points - at the old copies. +1. Continue narrowing the remaining `docs/project_management/**` dependency surface now that the + ADR registry stops being a destination question. +2. Keep current stable-reader rewrites ahead of broad historical cleanup. +3. Treat retained `docs/project_management/adrs/**` files as compatibility/history stubs unless a + live stable consumer still points at them. +4. Do not reopen the completed ADR clusters unless a remaining stable consumer still points at the + old copies. ## Resume Notes @@ -436,12 +565,18 @@ Use this order in the next session: - The dedicated provisioning ADR slice (`ADR-0030` / `ADR-0033`) is now complete. - The config/policy foundation ADR slice (`ADR-0003`, `ADR-0005`, `ADR-0006`, `ADR-0008`, `ADR-0012`, `ADR-0013`) is now complete. -- The next correct move is curating the remaining world/runtime foundation ADRs and continuing to - narrow the remaining `docs/project_management/**` dependency surface, not reopening - already-curated ADR clusters. -- Treat the repo-wide `docs/project_management/**` cleanup as subordinate to that ADR curation - milestone; otherwise you risk repeatedly repointing docs toward a namespace that is still meant - to be retired. +- The world/runtime foundation ADR slice (`ADR-0004`, `ADR-0007`, `ADR-0014`, `ADR-0015`, + `ADR-0018`) is now complete. +- The remaining installer/diagnostics/backend ADR tail is now classified: + - implemented: `ADR-0031`, `ADR-0032`, `ADR-0034`, `ADR-0035`, `ADR-0036`, `ADR-0037`, + `ADR-0038` + - draft: `ADR-0009`, `ADR-0010`, `ADR-0039`, `ADR-2026-02-13 macOS World backend via + Virtualization.framework` +- The ADR registry is now fully represented under `docs/adr/**`; the remaining work is dependency + cleanup and eventual historical pruning, not open-ended ADR destination decisions. +- Treat the repo-wide `docs/project_management/**` cleanup as the follow-on to the completed ADR + curation milestone; otherwise you risk mixing stable-reader rewrites with broad historical + pruning before the dependency surface is clearly bounded. - The curation-policy and first-cluster-classification questions are no longer open; use the recorded policy and ledger under `docs/adr/**` rather than re-deciding them in a later session. - The top-level `packs/**` tree must be removed in one cut only after: diff --git a/docs/TRACE.md b/docs/TRACE.md index 826c76444..b9f0c1f21 100644 --- a/docs/TRACE.md +++ b/docs/TRACE.md @@ -5,7 +5,7 @@ The Substrate Trace module (`crates/trace`) provides comprehensive span-based tracing for command execution across the Substrate ecosystem. It captures detailed execution context, policy decisions, and system state to enable command replay, security auditing, and graph-based analysis of command relationships. Canonical trace schema/correlation vocabulary (Phase 8 cross-cutting spines for LLM/agents/router/workflows): -- Source of truth: `docs/internals/trace/schema.md` for stable schema details and `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` for the ADR decision record. +- Source of truth: `docs/internals/trace/schema.md` for stable schema details and `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` for the ADR decision record. ### Key Features diff --git a/docs/adr/CURATION.md b/docs/adr/CURATION.md index 25854c01f..02d83aec6 100644 --- a/docs/adr/CURATION.md +++ b/docs/adr/CURATION.md @@ -221,13 +221,91 @@ The following curated implemented ADRs now exist under `docs/adr/implemented/`: - `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` - `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` +## Seventh Cluster: World and Runtime Foundation ADRs + +This slice curates the remaining implemented world/runtime foundation ADRs that stable docs or +runtime contracts still use as semantic anchors. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0004 | `docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md` | `stable_keeper` | `implemented` | Stable world and trace docs still depend on its filesystem-strategy fallback and observability semantics. | +| ADR-0007 | `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` | `stable_keeper` | `implemented` | Current installation, command, and platform docs depend on its host/world doctor split and readiness semantics. | +| ADR-0014 | `docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` | `stable_keeper` | `implemented` | It defines the host-resolved policy snapshot authority that current world execution and trace semantics still rely on. | +| ADR-0015 | `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` | `stable_keeper` | `implemented` | Stable full-isolation docs still rely on its allowlisted-write correctness and overlay backing-dir semantics. | +| ADR-0018 | `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` | `stable_keeper` | `implemented` | Current world/config internals still depend on its granular filesystem policy and hardened deny posture. | + +## Promoted In This Slice + +The following curated implemented ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md` +- `docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md` +- `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` +- `docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` +- `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + +## Eighth Cluster: World-Deps Predecessor and Current Contract ADRs + +This slice resolves the remaining world-deps predecessor pair by separating stale historical +framing from the still-current inventory and enabled-set contract. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0002 | `docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md` | `historical_only` | `implemented` | It established the early install-class and provisioning posture, but its command surface and selection-file model are no longer accurate. | +| ADR-0011 | `docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md` | `stable_keeper` | `implemented` | It is still the active inventory-directory plus enabled-patch contract behind current world-deps docs and runtime behavior. | + +## Promoted In This Slice + +The following curated ADRs now exist under `docs/adr/**`: + +- `docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md` +- `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` + +## Ninth Cluster: Remaining Installer, Diagnostics, and Backend ADR Tail + +This slice classifies the remaining legacy-only ADR tail so the stable `docs/adr/**` registry +fully covers the current ADR set even where some entries remain active drafts. + +| ADR | Current path | Curation disposition | Implementation posture | Why it stays or moves | +| --- | --- | --- | --- | --- | +| ADR-0009 | `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` | `stable_keeper` | `still_draft` | It is still an active backend/provisioning direction, but the guest-rootfs backend contract is not yet the current landed runtime baseline. | +| ADR-0010 | `docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` | `stable_keeper` | `still_draft` | It remains the queued cross-backend contract for surfacing capability divergence without claiming completed implementation. | +| ADR-0031 | `docs/project_management/adrs/draft/ADR-0031-detecting-badger.md` | `stable_keeper` | `draft_but_implemented` | Linux installer distro/package-manager discovery and explicit override behavior are already implemented in install flows, tests, and installation docs. | +| ADR-0032 | `docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md` | `stable_keeper` | `draft_but_implemented` | Linux install-state persistence for detected distro/package-manager metadata is already implemented and verified by installer tests. | +| ADR-0034 | `docs/project_management/adrs/draft/ADR-0034-staging-beaver.md` | `stable_keeper` | `draft_but_implemented` | Dev-install helper staging under `SUBSTRATE_HOME` is already implemented in install scripts and world-enable runtime lookup paths. | +| ADR-0035 | `docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md` | `stable_keeper` | `draft_but_implemented` | The “install with `--no-world`, enable later” dev workflow is already materially implemented in installer/runtime behavior and smoke coverage. | +| ADR-0036 | `docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md` | `stable_keeper` | `draft_but_implemented` | Health and shim-doctor now treat `world.enabled: false` as a first-class disabled state rather than a failure. | +| ADR-0037 | `docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md` | `stable_keeper` | `draft_but_implemented` | Doctor/health diagnostics already attribute the highest-precedence reason that world isolation is disabled. | +| ADR-0038 | `docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md` | `stable_keeper` | `draft_but_implemented` | Replay warnings already reuse world-disabled reason attribution instead of implying `--no-world` generically. | +| ADR-0039 | `docs/project_management/adrs/draft/ADR-0039-capturing-koala.md` | `stable_keeper` | `still_draft` | It remains an active installer-metadata direction for macOS but is not yet a completed stable runtime contract. | +| ADR-2026-02-13 | `docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md` | `stable_keeper` | `still_draft` | It is still a proposed backend direction rather than current macOS backend truth. | + +## Promoted In This Slice + +The following curated implemented ADRs now exist under `docs/adr/implemented/`: + +- `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` +- `docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` +- `docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md` +- `docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md` +- `docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md` +- `docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md` +- `docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` + +The following curated draft ADRs now exist under `docs/adr/draft/`: + +- `docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` +- `docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` +- `docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md` +- `docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md` + ## Next Resume Slice -The remaining current ADR tail, provisioning slice, and config/policy foundation slice are now -classified and promoted. Next, continue with: +The ADR registry is now fully classified into `docs/adr/**`. Legacy copies remain intentionally +under `docs/project_management/adrs/**` as compatibility and historical breadcrumbs. Next, +continue with: -1. curate the remaining world/runtime foundation ADRs that stable docs or code still treat as - current semantic anchors -2. narrow any remaining `docs/project_management/**` dependency surface that still - points stable readers at retiring namespaces +1. narrow any remaining `docs/project_management/**` dependency surface that still points stable + readers at retiring namespaces +2. treat leftover legacy ADR files as retained history/stubs rather than unmigrated registry gaps 3. do not reopen already-curated ADR clusters unless new stable references are discovered diff --git a/docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md b/docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md new file mode 100644 index 000000000..3794c7ee8 --- /dev/null +++ b/docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md @@ -0,0 +1,47 @@ +# ADR-0009 — Linux Guest RootFS Backend and Linux System-Package Provisioning + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-05-24 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Shell, world, and installer maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +Substrate may add a Linux guest-rootfs backend that decouples the in-world userspace from the host +distro and allows provisioning-time system-package mutation without touching the workstation OS. + +The queued direction that still matters is: + +- explicit Linux backend selection between host-native and guest-rootfs modes +- guest-rootfs warmup as a separate, doctor-visible prerequisite +- Linux provisioning support only when the active backend and guest image make host OS mutation + avoidable +- full-isolation semantics rooted in the guest userspace rather than host system-directory bind + mounts + +## Why Queued + +This is still active platform/input work, but it is not landed and should not yet be treated as a +stable runtime contract. + +When implementation is ready, it should be restated against: + +- `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +- `docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` + +## Draft Note + +Keep the project-management ADR for original planning detail, but treat this curated draft as the +queued Linux guest-rootfs placeholder. diff --git a/docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md b/docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md new file mode 100644 index 000000000..a3db2fcdd --- /dev/null +++ b/docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md @@ -0,0 +1,46 @@ +# ADR-0010 — World Backend Contract and Capability Divergence Surfacing + +## Status + +- Status: Draft +- Queue state: Proposed +- Original date (UTC): 2026-01-11 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Shell, world, and broker maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Proposed Direction + +Substrate needs a cross-backend world contract that keeps capability divergence explicit while +preserving stable operator-facing semantics. + +The proposed direction that still matters is: + +- doctor reports backend identity plus capability booleans and remediation +- trace reports backend kind, in-world/host posture, and fallback reasons explicitly +- fail-closed versus degrade behavior stays stable across backend implementations +- filesystem safety, provisioning posture, and observability remain contract-owned instead of + backend-specific folklore + +## Why Proposed + +This is still a platform-contract proposal, not a landed behavior contract. + +When implementation is ready, it should be restated against: + +- `docs/WORLD.md` +- `docs/ISOLATION_SUPPORT_MATRIX.md` +- `docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md` +- `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` + +## Draft Note + +Keep the project-management ADR for the original proposal detail, but treat this curated draft as +the proposed backend-contract placeholder. diff --git a/docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md b/docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md new file mode 100644 index 000000000..6ed4c3e82 --- /dev/null +++ b/docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md @@ -0,0 +1,44 @@ +# ADR-0039 — Persist macOS Host OS Details in `install_state.json` + +## Status + +- Status: Draft +- Queue state: Queued +- Original date (UTC): 2026-03-30 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Installer and host-provisioning maintainers + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-0039-capturing-koala.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Queued Direction + +The installer metadata file may gain additive macOS host OS details so later diagnostics can reason +about the host platform that performed the install. + +The queued direction that still matters is: + +- keep `install_state.json` as the canonical installer metadata file +- add macOS host OS facts additively without changing provisioning behavior +- persist warning-only metadata rather than turning collection failures into install failures +- keep the schema and consumer posture compatible with existing installer metadata readers + +## Why Queued + +This is still active installer metadata work, but it is not landed and should not yet be treated +as a stable install contract. + +When implementation is ready, it should be restated against: + +- `docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` +- `docs/INSTALLATION.md` + +## Draft Note + +Keep the project-management ADR for the original planning detail, but treat this curated draft as +the queued macOS install-state placeholder. diff --git a/docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md b/docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md new file mode 100644 index 000000000..52ba86df6 --- /dev/null +++ b/docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md @@ -0,0 +1,44 @@ +# ADR-2026-02-13 — macOS World Backend via Virtualization.framework + +## Status + +- Status: Draft +- Queue state: Proposed +- Original date (UTC): 2026-02-13 +- Curated into `docs/adr/draft/`: 2026-05-26 +- Owner(s): Substrate runtime team + +## Curated From + +- Planning ADR: + - `docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md` + +The project-management ADR remains the planning-rich source retained for compatibility while +`docs/project_management/**` is retired. + +## Proposed Direction + +Substrate may add a macOS world backend based on Apple Virtualization.framework, including both +Linux-guest and macOS-guest VM-backed execution modes on Apple Silicon. + +The proposed direction that still matters is: + +- prefer a VM-backed macOS-native backend over non-VM sandbox emulation +- support VF-Linux as a Lima-reduction path and VF-macOS as a macOS-tooling path +- keep filesystem, command, and egress policy enforcement aligned with the existing world model +- stage rollout behind explicit backend selection and compatibility fallback + +## Why Proposed + +This remains a platform architecture proposal, not an implemented backend contract. + +When implementation is ready, it should be restated against: + +- `docs/WORLD.md` +- `docs/ISOLATION_SUPPORT_MATRIX.md` +- `docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` + +## Draft Note + +Keep the project-management ADR for the original architecture proposal, but treat this curated +draft as the proposed Virtualization.framework backend placeholder. diff --git a/docs/adr/draft/README.md b/docs/adr/draft/README.md index 014fd221b..6218de56b 100644 --- a/docs/adr/draft/README.md +++ b/docs/adr/draft/README.md @@ -8,11 +8,15 @@ planning-heavy ADRs that may never be promoted here. Current curated draft ADRs: +- `ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` +- `ADR-0010-world-backend-contract-and-capability-divergence.md` - `ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` - `ADR-0020-profiles-config-policy-snapshots.md` - `ADR-0021-substrate-workflow-engine.md` - `ADR-0022-forge-agent-loop-as-workflow-node.md` - `ADR-0026-orchestration-toolbox-mcp.md` - `ADR-0029-host-event-bus-and-router-daemon.md` +- `ADR-0039-persist-macos-host-os-details-in-install-state.md` - `ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - `ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md` +- `ADR-2026-02-13-macos-world-backend-virtualization-framework.md` diff --git a/docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md b/docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md new file mode 100644 index 000000000..ada2f0139 --- /dev/null +++ b/docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md @@ -0,0 +1,45 @@ +# ADR-0002 — World-Deps Install Classes and Provisioning-Time System Packages + +## Status + +- Status: Historical +- Original date (UTC): 2025-12-24 +- Curated into `docs/adr/historical/`: 2026-05-26 +- Owner(s): Shell, world, and installer maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md` + +This curated ADR is kept only as historical context. The project-management ADR remains as the +planning-rich source retained for compatibility while `docs/project_management/**` is retired. + +## Historical Decision Snapshot + +This ADR established the early world-deps install-class framing: + +- distinguish user-space installs from system-package installs +- keep OS-level package mutation out of runtime `world deps sync/install` +- require explicit provisioning-time handling for system packages + +That framing still matters historically because it introduced the security posture later refined by +the current world-deps contract. + +## Why Historical + +This ADR is no longer the current operator contract. + +Its command surface and configuration model were replaced by: + +- `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` +- `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` +- `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` + +Those successor ADRs preserve the provisioning-time-only mutation posture while replacing the old +selection-file model and the obsolete `substrate world deps provision` command shape. + +## Historical Note + +Keep the original ADR for install-class and provisioning-posture history, not as a live contract +for the current world-deps CLI or inventory model. diff --git a/docs/adr/historical/README.md b/docs/adr/historical/README.md index 5dd546a04..ee16a4818 100644 --- a/docs/adr/historical/README.md +++ b/docs/adr/historical/README.md @@ -7,6 +7,7 @@ Do not treat files here as current operator or runtime truth. Current curated historical ADRs: +- `ADR-0002-world-deps-install-classes-and-world-provisioning.md` - `ADR-0023-in-world-llm-gateway-front-door.md` - `ADR-0024-cli-backend-provider-engine.md` - `ADR-0025-agent-hub-core-role-swappable.md` diff --git a/docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md b/docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md new file mode 100644 index 000000000..932d814bc --- /dev/null +++ b/docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md @@ -0,0 +1,60 @@ +# ADR-0004 — World OverlayFS Directory Enumeration Reliability + +## Status + +- Status: Implemented +- Original date (UTC): 2025-12-29 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): World backend maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Linux world execution must refuse filesystem strategies that cannot provide correct directory +enumeration, and it must make strategy selection observable. + +The stable decision is: + +- a world filesystem strategy is only usable if its enumeration health check passes +- Linux strategy selection follows a deterministic primary/fallback chain rather than silently + guessing +- required-world execution fails closed when no viable strategy exists; optional-world execution + warns once and falls back to host +- doctor and trace surfaces expose the selected strategy and fallback reason so backend behavior is + reproducible + +## Stable Owned Surface + +This ADR owns the stable strategy-selection and observability contract documented in: + +- `docs/WORLD.md` +- `docs/TRACE.md` +- `docs/ISOLATION_SUPPORT_MATRIX.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/world/src/overlayfs/strategy.rs` +- `crates/world/src/overlayfs/strategy_state.rs` +- `crates/world/src/exec.rs` +- `crates/world-service/src/service.rs` +- `crates/world/tests/overlayfs_enumeration_fallback.rs` +- `crates/shell/tests/world_overlayfs_enumeration_wo0.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` +- `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + +## Historical Note + +The original ADR captured the rollout detail for the Linux overlay and fuse fallback chain. The +stable operator/runtime contract now lives here and in the world and trace docs. diff --git a/docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md b/docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md new file mode 100644 index 000000000..bccd6a4d6 --- /dev/null +++ b/docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md @@ -0,0 +1,58 @@ +# ADR-0007 — Host and World Doctor Scopes + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-07 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell and world backend maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Doctor output must distinguish host-side transport readiness from world-side enforcement readiness. + +The stable decision is: + +- `substrate host doctor` reports host prerequisites and transport reachability only +- `substrate world doctor` reports both the host summary and a world-service-reported world summary +- guest-kernel enforcement facts must come from the backend doctor API rather than ad hoc + host-side inference +- doctor exit behavior must distinguish “not provisioned / not supported” from “expected backend + path exists but the world-service is unreachable” + +## Stable Owned Surface + +This ADR owns the stable doctor-scope contract documented in: + +- `docs/COMMANDS.md` +- `docs/USAGE.md` +- `docs/INSTALLATION.md` +- `docs/reference/world/platforms/macos-lima-setup.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/platform/linux.rs` +- `crates/shell/src/execution/platform/macos.rs` +- `crates/transport-api-types/src/lib.rs` +- `crates/world-service/src/service.rs` +- `crates/shell/tests/doctor_scopes_ds0.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md` +- `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` + +## Historical Note + +The original ADR captured the rollout work that split doctor output into host and world scopes. The +stable doctor contract now lives here and in the CLI, installation, and platform verification docs. diff --git a/docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md b/docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md new file mode 100644 index 000000000..6bb8dcc9b --- /dev/null +++ b/docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md @@ -0,0 +1,63 @@ +# ADR-0011 — World Deps Packages/Bundles Inventory and Enabled Contract + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-13 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell and world maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +World deps must use an inventory-directory plus enabled-patch model rather than legacy +selection-file and overlay-file plumbing. + +The stable decision is: + +- available world deps come from built-ins plus inventory directories under `$SUBSTRATE_HOME/deps/` + and `/.substrate/deps/` +- desired world deps come from `world.deps.enabled` patch keys in global and workspace config + rather than separate selection files +- `substrate world deps` surfaces must distinguish inventory, enabled, and applied state + explicitly through `current`, `global`, and `workspace` scopes +- legacy manifest, overlay, and selection files must not influence the active world-deps model + +## Stable Owned Surface + +This ADR owns the stable inventory and enabled-set contract documented in: + +- `docs/reference/world/deps/README.md` +- `docs/internals/world/deps.md` +- `docs/reference/world/deps/authoring_packages.md` +- `docs/reference/world/deps/authoring_bundles.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/world_deps/inventory.rs` +- `crates/shell/src/builtins/world_deps/surfaces.rs` +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/tests/world_deps_inventory_validation_wdp0.rs` +- `crates/shell/tests/world_deps_applied_wdp2.rs` + +## Related ADRs + +- `docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md` +- `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md` +- `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` + +## Historical Note + +The original ADR captured the migration from legacy selection and overlay files to the current +inventory-directory and enabled-patch contract. The stable operator/runtime contract now lives here +and in the world-deps reference docs. diff --git a/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md b/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md index 9ac23a659..590954147 100644 --- a/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md +++ b/docs/adr/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md @@ -47,7 +47,7 @@ The decision is materially implemented and verified through: ## Related ADRs - `docs/adr/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` -- `docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md` +- `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` - `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` ## Historical Note diff --git a/docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md b/docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md new file mode 100644 index 000000000..3a3ac01d7 --- /dev/null +++ b/docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md @@ -0,0 +1,60 @@ +# ADR-0014 — World-Service Policy Resolution and Concurrency + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-18 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Substrate core team + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +World execution must consume a host-resolved effective policy snapshot rather than resolving policy +inside world-service from shared mutable broker state. + +The stable decision is: + +- the shell is the authoritative resolver for the effective policy attached to world execution + requests +- world-service consumes the request snapshot as its policy input for both non-PTY and PTY paths +- world-service must not derive per-request effective policy from local filesystem state or shared + broker mutation +- trace and execution surfaces must preserve snapshot provenance so policy enforcement remains + deterministic and auditable + +## Stable Owned Surface + +This ADR owns the stable policy-snapshot contract documented in: + +- `docs/WORLD.md` +- `docs/TRACE.md` +- `docs/reference/world/contract.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/policy_snapshot.rs` +- `crates/world-service/src/service.rs` +- `crates/world-service/src/pty.rs` +- `crates/transport-api-types/src/lib.rs` +- `crates/trace/src/tests.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` +- `docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` +- `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + +## Historical Note + +The original ADR captured the migration away from world-service-local broker resolution. The stable +policy snapshot contract now lives here and in the world and trace docs. diff --git a/docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md b/docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md new file mode 100644 index 000000000..27dbd108e --- /dev/null +++ b/docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md @@ -0,0 +1,60 @@ +# ADR-0015 — Full Isolation Landlock OverlayFS Backing Dirs + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-20 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): World backend maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Full-isolation writable allowlists must remain usable even when overlayfs requires internal backing +directory writes. + +The stable decision is: + +- allowlisted project writes in full isolation must not fail solely because overlayfs needs + internal upper/work directory writes +- runtime-derived internal write roots are execution details and must not become part of the + user-facing policy schema or snapshot identity +- when required internal write roots cannot be derived for required-world execution, the runtime + fails closed with high-signal diagnostics +- non-allowlisted writes remain denied; this ADR fixes spurious `EPERM`, not the deny contract + +## Stable Owned Surface + +This ADR owns the stable full-isolation writable-path contract documented in: + +- `docs/WORLD.md` +- `docs/ISOLATION_SUPPORT_MATRIX.md` +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/world/src/exec.rs` +- `crates/world-service/src/internal_exec.rs` +- `crates/world-service/src/service.rs` +- `crates/world-service/src/pty.rs` +- `crates/world-service/tests/full_isolation_nonpty.rs` +- `crates/world-service/tests/full_isolation_pty.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` +- `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + +## Historical Note + +The original ADR captured the overlayfs/Landlock compatibility investigation and rollout steps. The +stable allowlisted-write contract now lives here and in the world installation/isolation docs. diff --git a/docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md b/docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md new file mode 100644 index 000000000..18a076b05 --- /dev/null +++ b/docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md @@ -0,0 +1,67 @@ +# ADR-0018 — World FS Granular Allow/Deny and Strict Deny + +## Status + +- Status: Implemented +- Original date (UTC): 2026-01-29 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): World backend maintainers; Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +The world filesystem contract owns project-relative read, discover, and write controls plus +fail-closed deny behavior for hardened world execution. + +The stable decision is: + +- world filesystem controls are expressed per dimension (`read`, `discover`, `write`) rather than + as one coarse allowlist +- deny semantics must be explicit, validated, and fail closed rather than silently ignored +- hardened world execution must apply deny behavior before user code runs and treat unsupported + enforcement prerequisites as execution failures +- the same world-fs contract and snapshot semantics apply across non-PTY execution, PTY sessions, + doctor diagnostics, and operator-facing config docs + +## Stable Owned Surface + +This ADR owns the stable world-fs policy contract documented in: + +- `docs/CONFIGURATION.md` +- `docs/reference/config/world.md` +- `docs/WORLD.md` +- `docs/internals/config/world_root_and_caging.md` +- `docs/ISOLATION_SUPPORT_MATRIX.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/transport-api-types/src/lib.rs` +- `crates/shell/src/execution/policy_snapshot.rs` +- `crates/world-service/src/enforcement_plan.rs` +- `crates/world-service/src/internal_exec.rs` +- `crates/world-service/src/service.rs` +- `crates/world-service/src/pty.rs` +- `crates/shell/tests/policy_discovery.rs` +- `crates/world-service/tests/full_isolation_nonpty.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` +- `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` +- `docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` +- `docs/adr/draft/ADR-0029-host-event-bus-and-router-daemon.md` + +## Historical Note + +The original ADR captured the schema break, enforcement rollout, and planning-pack detail for +granular world-fs controls. The stable operator/runtime contract now lives here and in the config, +world, and isolation docs. diff --git a/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md b/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md index c489f0550..cd8a9d9e2 100644 --- a/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md +++ b/docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md @@ -57,8 +57,8 @@ The decision is materially implemented and verified through: ## Related ADRs - `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` -- `docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md` -- `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` +- `docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md` +- `docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` ## Historical Note diff --git a/docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md b/docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md new file mode 100644 index 000000000..a0d4d3e24 --- /dev/null +++ b/docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md @@ -0,0 +1,54 @@ +# ADR-0031 — Best-Effort Linux Distro and Package-Manager Discovery During Install + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Substrate maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0031-detecting-badger.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +The Linux installer must make host package-manager selection explicit, observable, and overrideable. + +The stable decision is: + +- Linux install uses a deterministic selection order: CLI flag, environment override, os-release + mapping, then fixed PATH probe fallback +- the installer prints the detected distro and chosen package manager so prerequisite installation + is observable +- invalid or unavailable explicit package-manager selections fail with stable, actionable exit + behavior instead of silently probing something else +- macOS and Windows installer behavior are unchanged by this decision + +## Stable Owned Surface + +This ADR owns the stable Linux installer detection contract documented in: + +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `scripts/substrate/install-substrate.sh` +- `tests/installers/pkg_manager_detection_smoke.sh` +- `tests/installers/pkg_manager_container_smoke.sh` + +## Related ADRs + +- `docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` +- `docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md` + +## Historical Note + +The original ADR captured the rollout detail for explicit Linux installer detection and override +precedence. The stable contract now lives here and in the installation guide. diff --git a/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md b/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md new file mode 100644 index 000000000..3385024ae --- /dev/null +++ b/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md @@ -0,0 +1,54 @@ +# ADR-0032 — Persist Linux Distro and Package-Manager Detection in `install_state.json` + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Installer and host-provisioning maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Successful Linux installs must persist platform detection metadata into the canonical installer +state file. + +The stable decision is: + +- Linux installs write or update `$SUBSTRATE_HOME/install_state.json` even when no separate + host-state event occurred +- persisted metadata includes os-release identity and selected package-manager provenance +- the file remains additive and schema-compatible for older readers +- persisted metadata is diagnostic-only and does not itself redefine provisioning behavior + +## Stable Owned Surface + +This ADR owns the stable Linux install-state metadata contract documented in: + +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `scripts/substrate/install-substrate.sh` +- `scripts/substrate/uninstall-substrate.sh` +- `scripts/substrate/dev-uninstall-substrate.sh` +- `tests/installers/install_state_smoke.sh` + +## Related ADRs + +- `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` +- `docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md` + +## Historical Note + +The original ADR captured the persistence rollout details and schema decisions for installer +metadata. The stable Linux install-state contract now lives here and in the installation guide. diff --git a/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md b/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md index 2ba206791..e5fbfb136 100644 --- a/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md +++ b/docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md @@ -56,7 +56,7 @@ The decision is materially implemented and verified through: ## Related ADRs - `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` -- `docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` +- `docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` ## Historical Note diff --git a/docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md b/docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md new file mode 100644 index 000000000..8a333d4bf --- /dev/null +++ b/docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md @@ -0,0 +1,54 @@ +# ADR-0034 — Stabilize Dev-Install Helper Discovery Under `SUBSTRATE_HOME` + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0034-staging-beaver.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Dev installs must stage the helper/runtime bundle needed by `substrate world enable` under +`$SUBSTRATE_HOME` instead of relying on brittle repo-target discovery. + +The stable decision is: + +- dev installs keep the live host binary symlink model, but stage world-enable helpers under + `$SUBSTRATE_HOME` +- helper discovery must survive `cargo clean` and missing `/target/scripts/...` bridges +- dev uninstall only removes the staged helper bundle it owns +- production install layout remains unchanged + +## Stable Owned Surface + +This ADR owns the stable dev-install helper discovery behavior documented in: + +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `scripts/substrate/dev-install-substrate.sh` +- `scripts/substrate/dev-uninstall-substrate.sh` +- `crates/shell/src/builtins/world_enable/runner/paths.rs` +- `crates/shell/tests/world_enable.rs` +- `tests/installers/install_smoke.sh` + +## Related ADRs + +- `docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md` + +## Historical Note + +The original ADR captured the staging-vs-parity option analysis for dev installs. The stable +helper-discovery contract now lives here and in the installation guide. diff --git a/docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md b/docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md new file mode 100644 index 000000000..1935a25c4 --- /dev/null +++ b/docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md @@ -0,0 +1,55 @@ +# ADR-0035 — Make `substrate world enable` Work After `dev-install-substrate.sh --no-world` + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +The dev-install `--no-world` flow must still leave a deterministic later path for +`substrate world enable`. + +The stable decision is: + +- `dev-install-substrate.sh --no-world` stages the world-service/runtime artifacts needed for later + `substrate world enable` +- `substrate world enable` remains provisioning-focused and performs deterministic preflight checks + instead of trying ad hoc build work +- missing staged artifacts fail fast with actionable remediation +- production installs remain unchanged + +## Stable Owned Surface + +This ADR owns the stable dev-install delayed-enable contract documented in: + +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `scripts/substrate/dev-install-substrate.sh` +- `crates/shell/src/builtins/world_enable/runner/helper_script.rs` +- `crates/shell/src/builtins/world_enable/runner/verify.rs` +- `crates/shell/src/builtins/world_enable/runner/manager_env.rs` +- `tests/installers/install_smoke.sh` + +## Related ADRs + +- `docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md` + +## Historical Note + +The original ADR captured the option tradeoffs around enable-time builds versus install-time +staging. The stable delayed-enable contract now lives here and in the installation guide. diff --git a/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md b/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md new file mode 100644 index 000000000..eb687286e --- /dev/null +++ b/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md @@ -0,0 +1,56 @@ +# ADR-0036 — Treat World Disabled as a First-Class Status in Health and Shim Doctor + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Diagnostics must treat `world.enabled=false` as an explicit disabled state rather than as a backend +failure. + +The stable decision is: + +- `substrate shim doctor` short-circuits world backend and applied world-deps probes when world is + disabled +- `substrate health` and `substrate shim doctor` report explicit disabled/skip statuses instead of + generic errors for that case +- JSON output carries stable additive status fields for disabled and skipped-disabled states +- enabled-world failures remain actionable attention-required diagnostics + +## Stable Owned Surface + +This ADR owns the stable disabled-diagnostics contract documented in: + +- `docs/USAGE.md` +- `docs/INSTALLATION.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/builtins/shim_doctor/report.rs` +- `crates/shell/src/builtins/shim_doctor/output.rs` +- `crates/shell/src/builtins/health.rs` +- `crates/shell/tests/shim_doctor.rs` +- `crates/shell/tests/shim_health.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md` + +## Historical Note + +The original ADR captured the shift from noisy probe failures to explicit disabled-state reporting. +The stable diagnostics contract now lives here and in the operator docs. diff --git a/docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md b/docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md new file mode 100644 index 000000000..671761e40 --- /dev/null +++ b/docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md @@ -0,0 +1,56 @@ +# ADR-0037 — Doctor and Health Attribute Why World Is Disabled + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Doctor and health surfaces must attribute disabled world isolation to the effective winning source +instead of implying `--no-world` generically. + +The stable decision is: + +- disabled attribution follows the effective source precedence across CLI flag, environment + override, workspace config, and global config +- text output uses stable, non-secret attribution wording +- JSON output gains additive disable-source fields suitable for automation +- attribution changes messaging only; it does not alter world enablement behavior or precedence + +## Stable Owned Surface + +This ADR owns the stable disable-attribution contract documented in: + +- `docs/reference/env/contract.md` +- `docs/USAGE.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/src/execution/platform/linux.rs` +- `crates/shell/src/execution/platform/macos.rs` +- `crates/shell/src/builtins/health.rs` +- `crates/shell/tests/doctor_scopes_ds0.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md` +- `docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` + +## Historical Note + +The original ADR captured the attribution-source tradeoffs for disabled world messaging. The stable +operator-facing attribution contract now lives here and in the env and usage docs. diff --git a/docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md b/docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md new file mode 100644 index 000000000..5d1477eed --- /dev/null +++ b/docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md @@ -0,0 +1,54 @@ +# ADR-0038 — Replay Attributes Why World Is Disabled in Warnings + +## Status + +- Status: Implemented +- Original date (UTC): 2026-02-21 +- Curated into `docs/adr/implemented/`: 2026-05-26 +- Owner(s): Shell maintainers + +## Curated From + +- Historical planning ADR: + - `docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md` + +This curated ADR is the stable decision record. The project-management ADR remains the +planning-rich historical source. + +## Decision + +Replay must use the same disabled-world attribution contract as doctor and health whenever replay +falls back to host due to world isolation being disabled. + +The stable decision is: + +- replay warning and origin messaging reuses the shared disabled-world attribution model +- replay preserves existing selection and exit behavior; only attribution becomes more accurate +- replay-facing structured reason fields stay aligned with doctor/health precedence and phrasing +- attribution remains redaction-safe and avoids leaking raw paths or secret values + +## Stable Owned Surface + +This ADR owns the stable replay disable-attribution contract documented in: + +- `docs/REPLAY.md` + +## Current Implementation Anchors + +The decision is materially implemented and verified through: + +- `crates/shell/src/execution/routing/replay.rs` +- `crates/replay/src/replay/executor.rs` +- `crates/shell/src/execution/config_model.rs` +- `crates/shell/tests/replay_world.rs` +- `crates/shell/src/execution/routing/dispatch/tests/host_replay.rs` + +## Related ADRs + +- `docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md` + +## Historical Note + +The original ADR captured the consistency work needed to make replay warnings match other +world-disabled surfaces. The stable replay attribution contract now lives here and in the replay +docs. diff --git a/docs/adr/implemented/README.md b/docs/adr/implemented/README.md index fa2b62451..6de63952f 100644 --- a/docs/adr/implemented/README.md +++ b/docs/adr/implemented/README.md @@ -8,17 +8,30 @@ Use it for ADRs that still explain current Substrate behavior after Current curated set: - `ADR-0003-policy-and-config-mental-model-simplification.md` +- `ADR-0004-world-overlayfs-directory-enumeration-reliability.md` - `ADR-0005-workspace-config-precedence-over-env.md` - `ADR-0006-env-var-taxonomy-and-override-split.md` +- `ADR-0007-host-and-world-doctor-scopes.md` - `ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md` +- `ADR-0011-world-deps-packages-bundles-contract.md` - `ADR-0012-config-schema-per-key-merge-and-provenance.md` - `ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md` +- `ADR-0014-world-service-policy-resolution-and-concurrency.md` +- `ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - `ADR-0016-world-first-repl-persistent-pty.md` - `ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` -- `ADR-0028-in-world-process-execution-tracing-parity.md` +- `ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` - `ADR-0027-llm-and-agent-config-policy-surface.md` +- `ADR-0028-in-world-process-execution-tracing-parity.md` +- `ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` +- `ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` - `ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` - `ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` +- `ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md` +- `ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md` +- `ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md` +- `ADR-0037-doctor-health-attribute-why-world-is-disabled.md` +- `ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` - `ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md` - `ADR-0041-substrate-gateway-backend-adapter-contract.md` - `ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` diff --git a/docs/internals/config/world_root_and_caging.md b/docs/internals/config/world_root_and_caging.md index a08e84b64..2e07384d0 100644 --- a/docs/internals/config/world_root_and_caging.md +++ b/docs/internals/config/world_root_and_caging.md @@ -156,6 +156,6 @@ Repro harness: - `docs/internals/env/inventory.md` (exported state env vars) - Policy snapshot and full isolation filesystem enforcement: - `docs/WORLD.md` - - `docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` + - `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` - REPL persistent sessions and drift restarts: - `docs/internals/repl/persistent_session.md` diff --git a/docs/internals/trace/schema.md b/docs/internals/trace/schema.md index 810306d58..cd24696b8 100644 --- a/docs/internals/trace/schema.md +++ b/docs/internals/trace/schema.md @@ -4,7 +4,7 @@ This document is the stable internal schema reference for canonical trace record Related sources: - [docs/TRACE.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/TRACE.md) -- `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` +- `docs/adr/implemented/ADR-0028-in-world-process-execution-tracing-parity.md` ## 1. Span records (`command_start` / `command_complete`) diff --git a/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md b/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md index fd10ad9f3..331af2ba1 100644 --- a/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md +++ b/docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-05-24 - Owner(s): Shell / World / Installer maintainers +## Current Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/next/linux_guest_rootfs_backend/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md index 8ec9c7e88..b0db97929 100644 --- a/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md +++ b/docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-01-11 - Owner(s): Shell / World / Broker maintainers +## Current Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0010-world-backend-contract-and-capability-divergence.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - This ADR defines a **cross-backend contract** for “world” backends (Linux host-native, Linux guest-rootfs, macOS/Lima, Windows/WSL, future Docker/Podman). - It focuses on making backend capability divergence explicit while keeping the operator-facing contract stable. diff --git a/docs/project_management/adrs/draft/ADR-0031-detecting-badger.md b/docs/project_management/adrs/draft/ADR-0031-detecting-badger.md index fa5abee8b..ada34ada2 100644 --- a/docs/project_management/adrs/draft/ADR-0031-detecting-badger.md +++ b/docs/project_management/adrs/draft/ADR-0031-detecting-badger.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-21 - Owner(s): ASSUMPTION: Substrate maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/implemented/best-effort-distro-package-manager/` diff --git a/docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md b/docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md index 65c4f61f5..77e94f35c 100644 --- a/docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md +++ b/docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: installer/host-provisioning maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/persist-detected-linux-distro-pkg-manager/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0034-staging-beaver.md b/docs/project_management/adrs/draft/ADR-0034-staging-beaver.md index 9bb26a6f5..48b5f3283 100644 --- a/docs/project_management/adrs/draft/ADR-0034-staging-beaver.md +++ b/docs/project_management/adrs/draft/ADR-0034-staging-beaver.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: Substrate shell maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0034-stabilize-dev-install-helper-discovery-under-substrate-home.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/dev-install-helper-discovery/` (ASSUMPTION) - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md b/docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md index 4467fcab6..6eed21ef3 100644 --- a/docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md +++ b/docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: Substrate shell + installer maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0035-make-substrate-world-enable-work-after-dev-install-no-world.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/dev-install-world-service-staging/` (ASSUMPTION) - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md b/docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md index 8a2b167a7..d5ec28c2d 100644 --- a/docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md +++ b/docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: Substrate shell maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/world-disabled-diagnostics/` (ASSUMPTION: new pack) - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md b/docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md index 071f1faa8..a2548dbc3 100644 --- a/docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md +++ b/docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: Substrate shell maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/make-doctor-health-output-explain-why/` (ASSUMPTION: created during planning) diff --git a/docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md b/docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md index e92e02502..84614fc57 100644 --- a/docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md +++ b/docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-02-21 - Owner(s): TBD (ASSUMPTION: Substrate shell maintainers) +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/world-disabled-reason-attribution/` (ASSUMPTION: created during planning) diff --git a/docs/project_management/adrs/draft/ADR-0039-capturing-koala.md b/docs/project_management/adrs/draft/ADR-0039-capturing-koala.md index bbcd66fe9..6dc193762 100644 --- a/docs/project_management/adrs/draft/ADR-0039-capturing-koala.md +++ b/docs/project_management/adrs/draft/ADR-0039-capturing-koala.md @@ -6,6 +6,12 @@ - Date (UTC): 2026-03-30 - Owner(s): TBD (ASSUMPTION: installer/host-provisioning maintainers) +## Current Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-0039-persist-macos-host-os-details-in-install-state.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/packs/draft/persist-macos-host-os-install-state/` (ASSUMPTION: created during planning) diff --git a/docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md b/docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md index 3cabff7fc..b9299754a 100644 --- a/docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md +++ b/docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md @@ -4,6 +4,13 @@ - **Decision type:** Architecture / Platform support - **Owners:** Substrate Runtime team - **Related:** Planning Pack: `planning_pack_2026-02-13_macos_world_backend_vf/README.md` + +## Current Curated Draft ADR + +- Current curated draft ADR: `docs/adr/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Context Substrate currently supports macOS by running a Linux “world” inside a Lima VM. This provides strong isolation (VM boundary) and allows us to reuse the Linux security model (mount namespaces + optional Landlock hardening, etc.), but it has two major limitations: 1. **macOS tooling cannot run inside the Linux world.** Users who need native macOS toolchains (Xcode, codesign/notarytool workflows, SwiftPM/Xcodebuild, etc.) cannot run them inside the existing Linux VM world. diff --git a/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md b/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md index 501bd8276..4c1c94c60 100644 --- a/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md +++ b/docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md @@ -8,6 +8,8 @@ > Current readers should use: > - `docs/reference/world/deps/README.md` > - `docs/reference/world/deps/provisioning.md` +> - `docs/adr/historical/ADR-0002-world-deps-install-classes-and-world-provisioning.md` +> - `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` > - `docs/adr/implemented/ADR-0030-provisioning-time-system-package-mutation-for-world-deps.md` > - `docs/adr/implemented/ADR-0033-manager-aware-system-package-provisioning-for-world-deps.md` > diff --git a/docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md b/docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md index aba48518b..5c08d0221 100644 --- a/docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md +++ b/docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md @@ -5,6 +5,12 @@ - Date (UTC): 2025-12-29 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/world-overlayfs-enumeration/` - Orchestration branch: `feat/world-overlayfs-enumeration` diff --git a/docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md b/docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md index 42e4e8aa4..8e9774e99 100644 --- a/docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md +++ b/docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-07 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0007-host-and-world-doctor-scopes.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/doctor_scopes/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md b/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md index 19b47be2c..591bf8c4f 100644 --- a/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md +++ b/docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md @@ -11,6 +11,12 @@ - Date (UTC): 2026-01-13 - Owner(s): Shell / World maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directories (impacted): - `docs/project_management/_archived/next/` (this ADR; cross-cutting contract) diff --git a/docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md b/docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md index 977f23145..09333d0a6 100644 --- a/docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md +++ b/docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md @@ -4,6 +4,12 @@ Status: Approved Owner: Substrate core team Date: 2026-01-18 +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Executive Summary (Operator) ADR_BODY_SHA256: f593408c9cc872e61a9c5fb74272f077ada540949a67630eae622cb43c1f1d14 diff --git a/docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md b/docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md index 1ef5ed741..a68fa97fa 100644 --- a/docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md +++ b/docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-20 - Owner(s): spenser +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/` - Sequencing spine: `docs/project_management/packs/sequencing.json` diff --git a/docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md b/docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md index 06f0437df..69f9f7a03 100644 --- a/docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md +++ b/docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md @@ -5,6 +5,12 @@ - Date (UTC): 2026-01-29 - Owner(s): spenser, Substrate maintainers +## Stable Curated ADR + +- Current stable ADR: `docs/adr/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md` +- This project-management file remains the planning-rich historical source retained for + compatibility while `docs/project_management/**` is being retired. + ## Scope - Feature directory: `docs/project_management/_archived/world-fs-granular-allow-deny/` - Sequencing spine: `docs/project_management/packs/sequencing.json` From d2bb2dad4e2e94df3d8485ecdef15049e701e817 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 21:14:05 -0400 Subject: [PATCH 18/20] Document workspace history and internal git model --- docs/COMMANDS.md | 8 + docs/PROJECT_MANAGEMENT_RETIREMENT.md | 9 +- docs/USAGE.md | 21 +++ docs/internals/world/README.md | 1 + .../world/workspace_internal_git_model.md | 148 ++++++++++++++++++ .../world/workspace_sync_filesystem_model.md | 1 + docs/reference/cli/README.md | 1 + docs/reference/cli/workspace_history.md | 119 ++++++++++++++ docs/reference/cli/workspace_sync.md | 15 ++ 9 files changed, 321 insertions(+), 2 deletions(-) create mode 100644 docs/internals/world/workspace_internal_git_model.md create mode 100644 docs/reference/cli/workspace_history.md diff --git a/docs/COMMANDS.md b/docs/COMMANDS.md index 613ecad95..2371af1cd 100644 --- a/docs/COMMANDS.md +++ b/docs/COMMANDS.md @@ -74,6 +74,14 @@ Once you type `graph`, `host`, `world`, `config`, `policy`, `workspace`, `shim`, | `substrate graph status` | — | — | Baseline mock backend status. | | `substrate graph what-changed ` | `span_id` (string) | `--limit ` | Exercise different limits plus anchor/caging toggles. | +### `workspace` Subcommand + +| Invocation | Positional Arguments | Subcommand Flags | Notes | +| --- | --- | --- | --- | +| `substrate workspace sync` | — | `--dry-run`, `--direction `, `--conflict-policy `, `--exclude `, `--verbose` | Reconciles or applies pending world changes. Stable contract: `docs/reference/cli/workspace_sync.md`. | +| `substrate workspace checkpoint` | — | `--message `, `--verbose` | Records a workspace snapshot into Substrate's internal history store. Stable contract: `docs/reference/cli/workspace_history.md`. | +| `substrate workspace rollback ` | `target` (`last` or a checkpoint id) | `--force`, `--verbose` | Restores a workspace snapshot from Substrate's internal history store. Stable contract: `docs/reference/cli/workspace_history.md`. | + ### world Subcommand | Invocation | Positional Arguments | Subcommand Flags | Notes | diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index c8567694b..c6e47c6b6 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -370,8 +370,10 @@ Completed follow-up: - absorbed the stable Linux filesystem semantics into `docs/internals/world/workspace_sync_filesystem_model.md` - removed the internal-doc dependency on the world-sync pack specs -- kept the operator-facing surface in `docs/reference/cli/workspace_sync.md` rather than creating - another stable reference page +- kept the operator-facing sync surface in `docs/reference/cli/workspace_sync.md` +- published the workspace-history contract in `docs/reference/cli/workspace_history.md` +- published the internal checkpoint/rollback store model in + `docs/internals/world/workspace_internal_git_model.md` Remaining follow-up: - none for the stable-doc dependency itself; the remaining blockers now sit in tests and @@ -422,9 +424,12 @@ in three buckets: - `docs/adr/implemented/ADR-0046-gateway-backend-selection-runtime-integration.md` - workspace sync pack contract: - `docs/project_management/packs/implemented/world-sync/contract.md` + - `docs/project_management/packs/implemented/world-sync/internal-git-spec.md` - stable home: - `docs/reference/cli/workspace_sync.md` + - `docs/reference/cli/workspace_history.md` - `docs/internals/world/workspace_sync_filesystem_model.md` + - `docs/internals/world/workspace_internal_git_model.md` - installer detection / replay attribution contract surfaces that are already sufficiently covered: - `docs/project_management/packs/implemented/best-effort-distro-package-manager/contract.md` - `docs/project_management/packs/implemented/world-disabled-reason-attribution/contract.md` diff --git a/docs/USAGE.md b/docs/USAGE.md index 421a14138..d3b2b7182 100644 --- a/docs/USAGE.md +++ b/docs/USAGE.md @@ -127,6 +127,27 @@ substrate agent stop --session --json - Durable inbox behavior is intentionally narrow: persistence exists, pending work can normalize posture into `awaiting_attention`, internal ack/dismiss plus dev-support/test ingress exist, and no public inbox command surface or automatic resume-from-inbox workflow is shipped. - `substrate -c`, `--command`, and piped stdin remain shell execution surfaces rather than agent-prompt aliases. +### Workspace History + +Substrate also provides workspace-history commands that are separate from world pending-diff sync: + +```bash +substrate workspace checkpoint +substrate workspace checkpoint --message "before upgrade" +substrate workspace rollback last +substrate workspace rollback cp/20260210T183823Z --force +``` + +- `workspace checkpoint` records a snapshot into Substrate's internal history store. +- `workspace rollback` restores a prior snapshot from that store. +- These commands do not use or mutate the user's `.git/`; they operate on Substrate's separate + internal store under `.substrate/`. + +Stable docs: + +- `docs/reference/cli/workspace_history.md` +- `docs/internals/world/workspace_internal_git_model.md` + ## PTY Support Substrate automatically uses PTY for interactive commands: diff --git a/docs/internals/world/README.md b/docs/internals/world/README.md index e8256ec07..9c288e5cd 100644 --- a/docs/internals/world/README.md +++ b/docs/internals/world/README.md @@ -8,4 +8,5 @@ Existing related docs (top-level): Additional internal docs: - `docs/internals/world/workspace_sync_filesystem_model.md` +- `docs/internals/world/workspace_internal_git_model.md` - `docs/internals/world/deps.md` diff --git a/docs/internals/world/workspace_internal_git_model.md b/docs/internals/world/workspace_internal_git_model.md new file mode 100644 index 000000000..8d7177dce --- /dev/null +++ b/docs/internals/world/workspace_internal_git_model.md @@ -0,0 +1,148 @@ +# Workspace Internal Git Model + +Scope: this document explains the current internal git store used by `substrate workspace +checkpoint` and `substrate workspace rollback`. It is developer-facing and grounded in the current +workspace command implementation. + +If you are looking for the operator-facing command contract, see +`docs/reference/cli/workspace_history.md`. + +## Stable surfaces for this behavior + +- Operator contract: + - `docs/reference/cli/workspace_history.md` +- Related sync surface: + - `docs/reference/cli/workspace_sync.md` + - `docs/internals/world/workspace_sync_filesystem_model.md` + +## Where the behavior lives + +Shell workspace command implementation: + +- `crates/shell/src/execution/workspace_cmd.rs` + +The current implementation shells out to the system `git` binary with explicit internal-repo +arguments instead of discovering a repository from `cwd`. + +## Internal store layout + +Substrate's internal history store uses: + +- GIT_DIR: + - `/.substrate/git/repo.git/` +- WORK_TREE: + - `/` + +Rules: + +- the internal git dir is separate from the user's `.git/` +- the internal store is a Substrate-owned implementation detail under `.substrate/` +- checkpoint and rollback must not rely on the user's repo config, hooks, or identity + +## Initialization + +When checkpoint or rollback needs the internal store and `HEAD` does not exist yet, Substrate +initializes the internal repo. + +Current invariants: + +- git is invoked with explicit `--git-dir` and `--work-tree` +- internal commits use deterministic Substrate-owned author and committer identity +- signing is disabled for internal commits and tags + +This keeps internal workspace-history operations independent from user-global git configuration. + +## Snapshot boundary + +Internal checkpoints include workspace content except: + +- `.git/**` +- `.substrate/**` + +Those exclusions are part of the behavior contract, not just an incidental implementation detail. + +Consequences: + +- user git metadata is never snapshotted or restored +- Substrate runtime state is never snapshotted or restored as workspace history + +## Checkpoint identifiers + +Checkpoint ids are lightweight tags with a sortable UTC timestamp shape: + +- `cp/` + +Example: + +- `cp/20260210T183823Z` + +Ordering: + +- the most recent checkpoint is the lexicographically greatest checkpoint id +- `workspace rollback last` resolves using that ordering + +## Checkpoint behavior + +Current checkpoint flow: + +1. resolve the workspace root +2. ensure the internal repo is initialized +3. stage all included paths while excluding protected paths +4. if nothing changed versus internal `HEAD`, exit successfully as a no-op +5. create an internal commit +6. create a lightweight checkpoint tag +7. print the checkpoint id + +Checkpoint does not depend on the user's `.gitignore` for correctness. + +## Rollback behavior + +Current rollback flow: + +1. resolve the target checkpoint id or `last` +2. enforce safety rails unless `--force` is present +3. resolve the target commit from the checkpoint tag +4. restore the internal work tree to the target commit +5. when forced, delete non-protected workspace paths that are outside the target snapshot + +Rollback invariants: + +- rollback does not create a new checkpoint +- rollback does not mutate `.git/**` or `.substrate/**` +- rollback uses the internal git store as the source of truth for the target snapshot + +## Safety rails + +Without `--force`, rollback refuses when: + +- the user repo exists and is dirty according to `git status --porcelain` +- non-protected workspace paths exist that are not present in the target checkpoint snapshot + +With `--force`, rollback may delete non-protected workspace paths to make the workspace match the +target checkpoint. + +## Snapshot presence model + +A path counts as present in the target checkpoint snapshot when it is: + +- a file path recorded in the target tree, or +- a parent directory required to contain one of those recorded file paths + +This is why rollback can safely distinguish between: + +- paths that should exist after restore, and +- non-protected extra paths that should be removed only under `--force` + +## Relationship to workspace sync + +Workspace history and workspace sync solve different problems: + +- `workspace sync` + - reconciles pending world overlay changes with the host workspace +- `workspace checkpoint` / `workspace rollback` + - snapshot and restore host workspace state through Substrate's internal git store + +The protected-path boundary is shared across both surfaces: + +- `.git/**` +- `.substrate/**` diff --git a/docs/internals/world/workspace_sync_filesystem_model.md b/docs/internals/world/workspace_sync_filesystem_model.md index 21ea70dff..af9f393b7 100644 --- a/docs/internals/world/workspace_sync_filesystem_model.md +++ b/docs/internals/world/workspace_sync_filesystem_model.md @@ -29,6 +29,7 @@ world-only layer is applied back to the host and when conflicting shadowed paths ## Stable surfaces for this behavior - Operator overview: `docs/reference/cli/workspace_sync.md` +- Related operator history commands: `docs/reference/cli/workspace_history.md` - Current implementation details and code pointers: this document - Auto-sync hook behavior: `crates/shell/src/execution/auto_sync.rs` diff --git a/docs/reference/cli/README.md b/docs/reference/cli/README.md index 04cff54f9..37adea35f 100644 --- a/docs/reference/cli/README.md +++ b/docs/reference/cli/README.md @@ -13,3 +13,4 @@ Existing related docs (top-level): Additional reference docs: - `docs/reference/cli/workspace_sync.md` +- `docs/reference/cli/workspace_history.md` diff --git a/docs/reference/cli/workspace_history.md b/docs/reference/cli/workspace_history.md new file mode 100644 index 000000000..ae8de1274 --- /dev/null +++ b/docs/reference/cli/workspace_history.md @@ -0,0 +1,119 @@ +# `substrate workspace checkpoint` and `workspace rollback` + +This page defines the stable operator-facing contract for Substrate's workspace history commands. + +If you want the deeper implementation details for the internal git store, see: +`docs/internals/world/workspace_internal_git_model.md`. + +## What these commands do + +- `substrate workspace checkpoint` + - records a snapshot of the current workspace into Substrate's internal history store +- `substrate workspace rollback ` + - restores the workspace to a previously recorded checkpoint + +These commands do not use or mutate the user's `.git/` repository. They use a separate +Substrate-owned store under `.substrate/`. + +## Internal store path + +Substrate stores workspace-history state at: + +- git dir: `/.substrate/git/repo.git/` +- work tree: `/` + +Protected paths remain outside the snapshot and restore surface: + +- `.git/**` +- `.substrate/**` + +## `substrate workspace checkpoint` + +Purpose: + +- capture the current workspace state into the internal Substrate checkpoint store + +Flags: + +- `--message ` + - optional operator-supplied suffix for the checkpoint commit message +- `--verbose` + - prints additional checkpoint details + +Behavior: + +- if the internal history store is not initialized yet, Substrate initializes it on first use +- the checkpoint snapshot includes workspace files except protected paths +- if nothing changed since the last internal checkpoint, the command succeeds as a no-op +- the printed checkpoint id is the stable target you can later pass to rollback + +Exit codes: + +- `0` + - success, including no-op +- `2` + - not in a workspace or invalid flag value +- `3` + - required dependency unavailable, such as `git` +- `5` + - safety-rail refusal + +## `substrate workspace rollback ` + +Purpose: + +- restore the workspace to a previously recorded Substrate checkpoint + +Targets: + +- `last` + - restore the most recent checkpoint +- `` + - restore a specific checkpoint id printed by checkpoint + +Flags: + +- `--force` + - allows rollback to proceed when safety rails would otherwise refuse +- `--verbose` + - prints additional rollback details + +Behavior: + +- rollback restores the workspace to the selected checkpoint from Substrate's internal store +- rollback never mutates the user's `.git/` +- rollback does not create a new checkpoint as a side effect +- when `--force` is not present, rollback refuses if safety rails trigger + +## Safety rails + +Rollback is intentionally conservative. + +Without `--force`, rollback refuses when: + +- the user repository `.git/` exists and `git status --porcelain` is non-empty +- non-protected workspace paths exist that are not present in the target checkpoint snapshot + +With `--force`, rollback may delete non-protected paths that are outside the target checkpoint +snapshot in order to make the workspace match the checkpoint. + +## Snapshot and restore boundaries + +Checkpoint and rollback both operate on the workspace root while excluding: + +- `.git/**` +- `.substrate/**` + +This means: + +- Substrate does not overwrite the user's git metadata +- Substrate does not snapshot or restore its own runtime state as part of workspace history + +## Related commands + +- `substrate workspace sync` + - applies or reconciles pending world changes; it is not a checkpointing surface + +For the current sync behavior, see: + +- `docs/reference/cli/workspace_sync.md` diff --git a/docs/reference/cli/workspace_sync.md b/docs/reference/cli/workspace_sync.md index 0a4fdf36a..43d04c88f 100644 --- a/docs/reference/cli/workspace_sync.md +++ b/docs/reference/cli/workspace_sync.md @@ -5,6 +5,9 @@ This page explains `workspace sync` in plain English using only **host** vs **wo If you want the deeper implementation details (overlayfs, agents, code pointers), see: `docs/internals/world/workspace_sync_filesystem_model.md`. +For Substrate's workspace-history commands, see: +`docs/reference/cli/workspace_history.md`. + ## Host vs world: what are the two filesystems? - **Host** = your real workspace directory on your machine. @@ -110,3 +113,15 @@ Some paths are protected and will not be synced/mutated: - `.substrate/**` If the world’s pending changes include protected paths, sync refuses. + +## Related workspace history commands + +`workspace sync` is separate from Substrate's checkpoint and rollback history commands: + +- `substrate workspace checkpoint` +- `substrate workspace rollback ` + +Those commands use Substrate's internal history store rather than world pending diffs. Their +operator-facing contract lives in: + +- `docs/reference/cli/workspace_history.md` From 96e7fdda99b32f32fb99e2a241d94ffed659d97f Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 23:12:19 -0400 Subject: [PATCH 19/20] Consolidate contract docs under stable homes --- config/deps_examples/README.md | 4 +- docs/INSTALLATION.md | 2 + docs/PROJECT_MANAGEMENT_RETIREMENT.md | 36 ++--- docs/TRACE.md | 4 + docs/USAGE.md | 3 + ...al-show-when-workspace-config-overrides.md | 16 +- ...ore-successor-identity-tuple-compatible.md | 23 ++- ...concurrent-execution-and-output-routing.md | 6 +- ...kage-manager-detection-in-install-state.md | 1 + ...-class-status-in-health-and-shim-doctor.md | 1 + docs/contracts/README.md | 5 + docs/contracts/agent-event-envelope.md | 142 ++++++++++++++++++ docs/contracts/diagnostics-json.md | 105 +++++++++++++ docs/contracts/install-state-schema.md | 98 ++++++++++++ docs/contracts/repl-output-routing.md | 101 +++++++++++++ ...concurrent-execution-and-output-routing.md | 4 +- .../02-session-participant-record.md | 2 +- .../27-uaa-boundary-and-naming-cleanup.md | 6 +- llm-last-mile/PLAN-02.md | 2 +- 19 files changed, 523 insertions(+), 38 deletions(-) create mode 100644 docs/contracts/agent-event-envelope.md create mode 100644 docs/contracts/diagnostics-json.md create mode 100644 docs/contracts/install-state-schema.md create mode 100644 docs/contracts/repl-output-routing.md diff --git a/config/deps_examples/README.md b/config/deps_examples/README.md index 55ec600be..d81f5b6b3 100644 --- a/config/deps_examples/README.md +++ b/config/deps_examples/README.md @@ -1,7 +1,8 @@ # World Deps `deps/` Examples These files are examples of the **per-item inventory** format described in: -- `docs/project_management/packs/active/world-deps-packages-bundles-contract/contract.md` +- `docs/reference/world/deps/README.md` +- `docs/adr/implemented/ADR-0011-world-deps-packages-bundles-contract.md` They are intended to be copied into a scope’s inventory directory: - Global: `~/.substrate/deps/` @@ -11,4 +12,3 @@ Layout mirrors the canonical on-disk format: - `packages/.yaml` - `bundles/.yaml` - `scripts/*.sh` (referenced via `script_path`) - diff --git a/docs/INSTALLATION.md b/docs/INSTALLATION.md index 8192406e6..85b8e3e31 100644 --- a/docs/INSTALLATION.md +++ b/docs/INSTALLATION.md @@ -120,6 +120,8 @@ with `substrate --world ...` without changing the stored metadata. `host_state.platform.pkg_manager.source`. macOS and Windows do not write this Linux host-state file; they only participate in compile/test parity for this pack. +- The stable machine-readable schema for that file lives in + `docs/contracts/install-state-schema.md`. - Metadata writes are idempotent; missing or corrupted files only emit warnings and never block install/uninstall runs. - Uninstallers accept `--cleanup-state`/`--auto-cleanup` to remove recorded diff --git a/docs/PROJECT_MANAGEMENT_RETIREMENT.md b/docs/PROJECT_MANAGEMENT_RETIREMENT.md index c6e47c6b6..abcaead60 100644 --- a/docs/PROJECT_MANAGEMENT_RETIREMENT.md +++ b/docs/PROJECT_MANAGEMENT_RETIREMENT.md @@ -440,38 +440,30 @@ in three buckets: - `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` - `docs/adr/implemented/ADR-0038-replay-attribute-why-world-is-disabled-in-warnings.md` -#### Preserve or move before deleting `packs/**` +#### Stable homes now in place before deleting `packs/**` -These files still carry stable contract detail that is only partially summarized elsewhere: +These pack-local contract surfaces now have explicit stable homes: - `docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/contract.md` - - preserve before deletion - - recommended destination: new stable contract doc under `docs/contracts/` for REPL structured - output routing, including `repl.max_pty_buffered_lines` and suppression-summary behavior + - stable home: `docs/contracts/repl-output-routing.md` - `docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/agent-hub-event-envelope-schema-spec.md` - - preserve before deletion - - recommended destination: new stable event-envelope schema doc under `docs/contracts/` - because `TRACE.md` discusses `agent_event` rows but does not fully replace the envelope schema + - stable home: `docs/contracts/agent-event-envelope.md` - `docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/install-state-schema-spec.md` - - preserve before deletion - - recommended destination: new stable `install_state.json` schema doc under `docs/contracts/` - because `docs/INSTALLATION.md` lists the fields but does not capture the full additive schema - and compatibility rules + - stable home: `docs/contracts/install-state-schema.md` - `docs/project_management/packs/implemented/world-disabled-diagnostics/world-disabled-diagnostics-json-schema-spec.md` - - preserve before deletion - - recommended destination: new stable diagnostics JSON contract doc under `docs/contracts/` - because `docs/USAGE.md` summarizes `.shim.world.status` and `.shim.world_deps.status` but does - not replace the full machine-readable schema and omission rules + - stable home: `docs/contracts/diagnostics-json.md` -#### Draft-pack contracts that should be folded into draft ADRs rather than promoted to stable contracts +Remaining follow-up: + +- repoint retained backlinks before deleting the pack copies +- keep the new contract docs, not the pack-local contract files, as the stable owned surfaces + +#### Draft-pack contracts folded into draft ADRs rather than promoted to stable contracts - `docs/project_management/packs/active/warn-config-global-show-workspace-overrides/contract.md` - - queued work; if the pack tree is removed before implementation, fold the normative CLI copy - into `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` + - folded into `docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md` - `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md` - - still referenced by `llm-last-mile/**`; if the pack tree is removed, fold any still-normative - contract text into `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - before deleting the pack path + - folded into `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` No other current pack-local `contract.md` / schema file has yet shown a stronger stable-home need than the curated ADR plus existing reference/contract docs above. diff --git a/docs/TRACE.md b/docs/TRACE.md index b9f0c1f21..724d7bb79 100644 --- a/docs/TRACE.md +++ b/docs/TRACE.md @@ -192,6 +192,10 @@ Bootstrap and lifecycle rows for the first host orchestrator caller path are emi Runtime-owned shell rows follow the same rule. Host stream chunks, shell command-completion events, and world-restart alerts emit orchestration-scoped `agent_event` rows only when a live parent orchestration session exists and supplies the real `orchestration_session_id`; otherwise stdout/stderr, `command_*` trace spans, and operator-facing terminal messaging continue without appending an orchestration-scoped `agent_event` row. Suppression here is additive only: missing orchestration context suppresses the shell-owned `agent_event` row, but it does not authorize heuristic recovery or synthetic correlation. +Stable contract details for the structured envelope and REPL routing behavior live in: +- `docs/contracts/agent-event-envelope.md` +- `docs/contracts/repl-output-routing.md` + Operator-facing omission rules: - Pure-agent records keep `client`, `router`, and `protocol`, and omit `provider` plus `auth_authority`. - Nested gateway-backed records may add `provider` and `auth_authority`, but they must omit `world_id` and `world_generation`. diff --git a/docs/USAGE.md b/docs/USAGE.md index d3b2b7182..c9a8ca1e3 100644 --- a/docs/USAGE.md +++ b/docs/USAGE.md @@ -273,6 +273,9 @@ $ substrate health --json | jq '.summary | {ok, missing_managers, world_ok, worl When `.shim.world.status` is `disabled` and `.shim.world_deps.status` is `skipped_disabled`, the summary stays non-error and the human output prints the disabled contract lines instead of enabled-world remediation guidance. +Machine-readable JSON details and omission rules live in: +- `docs/contracts/diagnostics-json.md` + Both commands honor the same overrides (`HOME`, `SUBSTRATE_MANAGER_MANIFEST`, `SHIM_TRACE_LOG`). Drop fixture files into `~/.substrate/health/world_doctor.json` and `~/.substrate/health/world_deps.json` when you need deterministic outputs in diff --git a/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md index 26a131775..c7d21bf4b 100644 --- a/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md +++ b/docs/adr/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md @@ -27,6 +27,18 @@ The queued direction that still matters is: - keep stdout patch-only and script-safe - emit explicit scope/write-target guidance for implicit-scope `config set` +## Folded Contract Detail + +When this queued work lands, the stable command-surface intent is: + +- `substrate config global show` still prints only the global patch on stdout +- when a workspace override is active, `substrate config global show` emits exactly one stderr note + explaining that workspace config overrides the global patch in the current directory +- unreadable or invalid workspace config must not make `config global show` fail if the global + patch is otherwise readable +- implicit `substrate config set =` remains workspace-scoped and emits an explicit + write-target note on stderr while keeping stdout as the effective merged config + ## Why Queued This remains active UX/input-surface work, but it is not landed and should not be treated as a @@ -39,5 +51,5 @@ When implementation is ready, it should be restated against: ## Draft Note -Keep the project-management ADR for the original operator-contract detail, but treat this curated -draft as the queued warning-behavior placeholder. +This curated draft now carries the queued contract summary that previously lived only in the pack +contract file. Keep the project-management ADR as the planning-rich historical source. diff --git a/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md b/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md index 71c0f3c0b..fe8fb5b68 100644 --- a/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md +++ b/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md @@ -27,6 +27,25 @@ The queued direction that still matters is: - explicit host-scoped orchestrator and world-scoped member model - identity that keeps `backend_id` separate from provider, auth authority, and protocol +## Folded Contract Detail + +When this queued work lands, the successor command-surface intent is: + +- the canonical runtime namespace is `substrate agent ...` +- the core read surfaces are: + - `substrate agent list` + - `substrate agent status` + - `substrate agent doctor` +- `substrate agents validate` remains an inventory-validation compatibility leaf rather than a + plural alias for the successor surfaces +- `backend_id` remains the adapter identifier in `:` form +- pure-agent rows use `router=agent_hub` and `protocol=substrate.agent.session` +- pure-agent rows omit `provider` and `auth_authority` +- nested gateway-backed rows stay separate from pure-agent rows and are the rows that publish + `provider` and `auth_authority` +- the intended owner set remains `crates/shell`, `crates/common`, and the `transport-api-*` + crates rather than a new `crates/agent-hub` crate + ## Why Queued This is active architectural input, but it is not landed and still needs the queue of @@ -41,5 +60,5 @@ When implementation is ready, it should be restated against: ## Draft Note -Keep the project-management ADR for detailed design reasoning, but treat this curated draft as the -queued Agent Hub successor anchor. +This curated draft now carries the queued command-surface summary that previously lived only in the +pack contract file. Keep the project-management ADR as the planning-rich historical source. diff --git a/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md b/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md index dc1b3e590..bcd7a4aa0 100644 --- a/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md +++ b/docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md @@ -32,9 +32,9 @@ The stable decision is: This ADR owns the stable output-routing and event-envelope behavior surfaced through: -- interactive REPL output behavior -- structured agent-event rendering and attribution -- trace correlation expectations for concurrent agent execution +- `docs/contracts/repl-output-routing.md` +- `docs/contracts/agent-event-envelope.md` +- `docs/TRACE.md` ## Current Implementation Anchors diff --git a/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md b/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md index 3385024ae..5d5eb0e94 100644 --- a/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md +++ b/docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md @@ -33,6 +33,7 @@ The stable decision is: This ADR owns the stable Linux install-state metadata contract documented in: - `docs/INSTALLATION.md` +- `docs/contracts/install-state-schema.md` ## Current Implementation Anchors diff --git a/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md b/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md index eb687286e..fe5290ab8 100644 --- a/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md +++ b/docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md @@ -35,6 +35,7 @@ This ADR owns the stable disabled-diagnostics contract documented in: - `docs/USAGE.md` - `docs/INSTALLATION.md` +- `docs/contracts/diagnostics-json.md` ## Current Implementation Anchors diff --git a/docs/contracts/README.md b/docs/contracts/README.md index e6cc80657..6b3d378f3 100644 --- a/docs/contracts/README.md +++ b/docs/contracts/README.md @@ -4,4 +4,9 @@ Stable contract documents live here, grouped by subsystem. ## Subsystems +- root contract docs: + - `agent-event-envelope.md`: structured `agent_event` schema and omission rules. + - `diagnostics-json.md`: machine-readable `shim doctor` and `health` status contract. + - `install-state-schema.md`: stable `install_state.json` schema contract. + - `repl-output-routing.md`: PTY-vs-structured-event routing contract for the REPL. - `gateway/`: Substrate gateway operator, status, policy, runtime, and backend-adapter contract surfaces. diff --git a/docs/contracts/agent-event-envelope.md b/docs/contracts/agent-event-envelope.md new file mode 100644 index 000000000..ab8afd3c1 --- /dev/null +++ b/docs/contracts/agent-event-envelope.md @@ -0,0 +1,142 @@ +# Agent Event Envelope Contract + +This document is the durable contract reference for structured `agent_event` rows. + +Related references: +- `docs/contracts/repl-output-routing.md` +- `docs/TRACE.md` +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` +- `docs/adr/implemented/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md` + +## Scope + +This contract is authoritative for the structured agent event envelope used for: + +- host-side structured REPL printing +- canonical `event_type="agent_event"` trace rows + +Format: + +- JSON object +- canonical location: `~/.substrate/trace.jsonl` or `SHIM_TRACE_LOG` + +## Compatibility Policy + +- additive-only for new optional fields, new `kind` values, and additive `data` fields +- existing required fields must not be removed or renamed +- consumers must ignore unknown fields + +## Top-Level Envelope + +All structured agent events are JSON objects with: + +- `ts` + - type: RFC3339 UTC string + - required: yes +- `kind` + - type: string enum + - required: yes + - allowed values in v1: + - `registered` + - `status` + - `task_start` + - `task_progress` + - `task_end` + - `pty_data` + - `alert` +- `data` + - type: object + - required: yes + +Required attribution and correlation fields: + +- `agent_id` +- `orchestration_session_id` +- `run_id` + +Optional correlation fields: + +- `backend_id` +- `thread_id` +- `role` +- `world_id` +- `cmd_id` +- `span_id` + +## Identity-Tuple-Compatible Metadata + +These fields are optional and additive: + +- `client` +- `router` +- `provider` +- `auth_authority` +- `protocol` + +Boundary rules: + +- pure agent/toolbox records may omit `provider` and `auth_authority` +- nested gateway-backed records may include `provider` and `auth_authority` +- `backend_id` remains adapter-only and must not be treated as semantic identity +- interpretation of these tuple fields remains owned by the identity ADR chain, not by this schema + +## Routing Hint + +Optional field: + +- `channel` + - producer-declared only + - must not contain secrets + - must not affect policy gating decisions + +## Per-Kind Data Rules + +For `registered`, `status`, `task_start`, `task_progress`, and `task_end`: + +- `data.message` is optional and, when present, is safe to print and persist + +For `pty_data`: + +- `data.stream` is required and must be `stdout` or `stderr` +- `data.chunk` is required +- structured `pty_data` is not a substitute for raw PTY bytes + +For `alert`: + +- `data.code` is required +- `data.message` is required + +Known v1 alert codes: + +- `world_restarted` +- `world_restart_required` + +Additional alert fields: + +- `world_restarted` requires: + - `data.reason` + - `data.on_drift` + - `data.previous_world_id` + - `data.new_world_id` + - `data.previous_world_generation` + - `data.new_world_generation` +- `world_restart_required` requires: + - `data.reason` + - `data.required_action` + - `data.on_drift` + - `data.world_id` + - `data.world_generation` + +## Canonicalization Rules + +- producers must emit all required top-level fields +- attribution and correlation fields stay at the top level +- consumers must treat the envelope as unordered JSON + +## Omission Rules + +- pure-agent records keep `client`, `router`, and `protocol`, and omit `provider` and + `auth_authority` +- host-scoped pure-agent records omit `world_id` +- nested gateway-backed records may add `provider` and `auth_authority`, but omit `world_id` + and `world_generation` diff --git a/docs/contracts/diagnostics-json.md b/docs/contracts/diagnostics-json.md new file mode 100644 index 000000000..ae9aa1f05 --- /dev/null +++ b/docs/contracts/diagnostics-json.md @@ -0,0 +1,105 @@ +# Diagnostics JSON Contract + +This document is the durable machine-readable contract reference for: + +- `substrate shim doctor --json` +- `substrate health --json` + +Related references: +- `docs/USAGE.md` +- `docs/reference/env/contract.md` +- `docs/adr/implemented/ADR-0036-world-disabled-first-class-status-in-health-and-shim-doctor.md` +- `docs/adr/implemented/ADR-0037-doctor-health-attribute-why-world-is-disabled.md` + +## Compatibility Policy + +- additive-only +- existing fields must not be renamed or removed +- consumers must ignore unknown fields and unknown enum values + +## Shim Doctor Status Fields + +### `.world.status` + +- type: string enum +- required when `.world` is present +- allowed values: + - `healthy` + - `needs_attention` + - `disabled` + - `unknown` + +Semantics: + +- `disabled`: effective config resolved `world.enabled=false`; backend probing was skipped +- `healthy`: effective config resolved `world.enabled=true` and the backend probe succeeded +- `needs_attention`: effective config resolved `world.enabled=true` and the backend probe failed in + an actionable way +- `unknown`: reporting could not determine the state + +Legacy field rule: + +- `.world.ok` remains additive/legacy and is not the canonical disabled-state classifier + +### `.world_deps.status` + +- type: string enum +- required when `.world_deps` is present +- allowed values: + - `ok` + - `error` + - `skipped_disabled` + - `unknown` + +Semantics: + +- `skipped_disabled`: effective config resolved `world.enabled=false`; applied probing was skipped +- `ok`: snapshot collection and applied probing succeeded +- `error`: snapshot collection or applied probing failed +- `unknown`: reporting could not determine the state + +Legacy field rule: + +- `.world_deps.error` and `.world_deps.report.applied_error` remain legacy error surfaces, but + `.world_deps.status` is the canonical machine-readable classifier + +## Health JSON Shape + +`substrate health --json` contains: + +- top-level `shim`: the full `substrate shim doctor --json` payload +- top-level `summary`: a derived summary + +Canonical summary inputs for world-disabled behavior are: + +- `.shim.world.status` +- `.shim.world_deps.status` + +## Disabled-World Omission Rules + +When effective config resolves `world.enabled=false`: + +- shim doctor: + - `.world.status` must be `disabled` + - `.world.details` must be omitted + - `.world.error` must be omitted + - `.world_deps.status` must be `skipped_disabled` + - `.world_deps.report` must be omitted + - `.world_deps.error` must be omitted +- health summary: + - `.summary.world_ok` must be `null` + - `.summary.world_error` must be omitted + - `.summary.world_deps_error` must be omitted + - `.summary.world_deps_missing` must be `[]` + - `.summary.world_deps_blocked` must be `[]` + - `.summary.failures` must not include failures caused solely by the disabled short-circuit + +## Enabled-World Rules + +When effective config resolves `world.enabled=true`: + +- `.world.status` must not be `disabled` +- `.world_deps.status` must not be `skipped_disabled` +- `.world_deps.status` must be `error` when either: + - `.world_deps.error` is present + - `.world_deps.report.applied_error` is present diff --git a/docs/contracts/install-state-schema.md b/docs/contracts/install-state-schema.md new file mode 100644 index 000000000..8310bf1b0 --- /dev/null +++ b/docs/contracts/install-state-schema.md @@ -0,0 +1,98 @@ +# Install State Schema + +This document is the durable contract reference for the stable `install_state.json` schema used by +installer metadata. + +Related references: +- `docs/INSTALLATION.md` +- `docs/adr/implemented/ADR-0031-best-effort-linux-distro-package-manager-discovery-during-install.md` +- `docs/adr/implemented/ADR-0032-persist-linux-distro-package-manager-detection-in-install-state.md` + +## Scope + +This contract is authoritative for the additive installer metadata schema used at: + +- `/install_state.json` +- `$SUBSTRATE_HOME/install_state.json` when the default user-scoped prefix is active + +The stable top-level schema version remains: + +- `schema_version = 1` + +## Compatibility Policy + +- additive-only +- existing fields must not be renamed or removed +- consumers must ignore unknown fields +- writers must preserve existing unknown fields unless another stable contract explicitly owns them +- this schema must not bump `schema_version` + +## Top-Level Structure + +- `schema_version` + - type: integer + - required: yes + - allowed value: `1` +- `host_state` + - type: object + - required: yes when any host metadata is persisted + +## Preserved Legacy Fields + +This contract does not redefine the JSON shape of: + +- `host_state.group` +- `host_state.linger` + +If either field exists before a rewrite, writers must preserve the exact JSON value. + +## Linux Platform Metadata + +For Linux installer flows that persist package-manager detection metadata: + +- `host_state.platform` + - required: yes + - must contain both `os_release` and `pkg_manager` +- `host_state.platform.os_release.id` + - type: string + - required: yes +- `host_state.platform.os_release.id_like` + - type: string + - required: yes +- `host_state.platform.pkg_manager.selected` + - type: string + - required: yes +- `host_state.platform.pkg_manager.source` + - type: string + - required: yes + +Semantics: + +- `os_release.id` and `os_release.id_like` must copy the normalized distro detection output + verbatim +- `` is persisted literally when detection produced `` +- `pkg_manager.selected` and `pkg_manager.source` must copy the upstream detection result + verbatim +- the persistence writer must not re-derive or locally normalize these values + +## Merge and Write Rules + +- writers must create `install_state.json` on successful Linux installs even when no separate + group/linger event occurred +- writers must read the existing file before rewriting it +- writers must preserve existing `host_state.group` and `host_state.linger` values exactly +- writers must preserve existing unknown fields +- writers must replace the file atomically so each successful write leaves a complete JSON document +- writers must not remove `host_state.group` or `host_state.linger` solely because the current run + did not emit new values for those fields + +## Invalid States + +This contract treats the following as invalid schema states: + +- `schema_version != 1` +- `host_state.platform` present without `host_state.platform.os_release` +- `host_state.platform` present without `host_state.platform.pkg_manager` +- `host_state.platform.os_release.id` omitted when `host_state.platform.os_release` is present +- `host_state.platform.os_release.id_like` omitted when `host_state.platform.os_release` is + present diff --git a/docs/contracts/repl-output-routing.md b/docs/contracts/repl-output-routing.md new file mode 100644 index 000000000..dcab590ee --- /dev/null +++ b/docs/contracts/repl-output-routing.md @@ -0,0 +1,101 @@ +# REPL Output Routing Contract + +This document is the durable contract reference for concurrent REPL output routing. + +Related references: +- `docs/contracts/agent-event-envelope.md` +- `docs/TRACE.md` +- `docs/adr/implemented/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` + +## Contract + +Substrate REPL output has two distinct classes: + +- PTY bytes +- structured agent events + +The stable rules are: + +- PTY bytes are forwarded as raw bytes and remain binary-safe. +- Structured agent events render through a structured printer path. +- Structured agent events must never be injected into PTY byte streams. +- Structured event rendering must not stall execution; bounded buffering plus drop is allowed + during PTY passthrough. +- Every structured agent event must still persist as a canonical `agent_event` trace row. + +## Identity Boundary + +- `backend_id` is an adapter/backend identifier only, in `:` form. +- `backend_id` must not be overloaded with provider, auth authority, router, client, or protocol + meaning. +- Tuple semantics for `client`, `router`, `provider`, `auth_authority`, and `protocol` remain + owned by the identity ADR chain rather than this output-routing contract. + +## Idle REPL Behavior + +When the line editor is active: + +- out-of-band PTY bytes may render as raw bytes +- structured agent events may render through the structured printer +- neither output path may corrupt the prompt or input buffer + +Current additive alert scope includes: + +- `kind="alert"` with `data.code="world_restarted"` +- `kind="alert"` with `data.code="world_restart_required"` + +## PTY Passthrough Behavior + +During PTY passthrough: + +- PTY bytes forward immediately as bytes. +- Structured agent events must not print live into the terminal stream. +- Structured event lines are buffered for deferred rendering. +- After passthrough ends, buffered lines print in order before the prompt returns. + +## Suppression Summary + +If buffered structured event lines overflow the configured cap: + +- additional structured event lines are dropped +- exactly one structured warning record is emitted with: + - `event_type="warning"` + - `component="shell"` + - `code="pty_structured_event_drops"` +- exactly one human-readable warning line is emitted through the normal warning channel + +The suppression warning must not be injected into PTY bytes. + +## Config Surface + +This contract introduces no CLI flags and no environment overrides. + +Effective precedence for `repl.max_pty_buffered_lines` is: + +1. `/.substrate/workspace.yaml` +2. `$SUBSTRATE_HOME/config.yaml` +3. built-in default + +Owned key: + +- `repl.max_pty_buffered_lines` + - meaning: maximum number of structured event lines buffered during PTY passthrough + - default: `2048` + - bounds: `0..16384` + +Invalid handling: + +- invalid type/parse is a config-boundary error with exit `2` +- out-of-range values clamp to bounds and emit one structured warning record with: + - `event_type="warning"` + - `component="shell"` + - `code="config_value_clamped"` + +Warnings do not change command exit status. + +## Platform Guarantee + +- Linux: full support required +- macOS: full support required +- Windows: the same non-injection and structured-event separation rules apply anywhere PTY + passthrough exists diff --git a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md index 04da8f350..73f8c809a 100644 --- a/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md +++ b/docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md @@ -28,8 +28,8 @@ - Spec manifest: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/spec_manifest.md` - Impact map: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/impact_map.md` - CI checkpoint plan: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/ci_checkpoint_plan.md` -- Contract: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/contract.md` -- Spec: structured event envelope: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/agent-hub-event-envelope-schema-spec.md` +- Stable contract: `docs/contracts/repl-output-routing.md` +- Stable event-envelope contract: `docs/contracts/agent-event-envelope.md` - Spec: telemetry/trace records: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/telemetry-spec.md` - Spec: platform parity: `docs/project_management/packs/active/agent-hub-concurrent-execution-output-routing/platform-parity-spec.md` - Slice specs: diff --git a/llm-last-mile/02-session-participant-record.md b/llm-last-mile/02-session-participant-record.md index a1b2d852f..8d622f10b 100644 --- a/llm-last-mile/02-session-participant-record.md +++ b/llm-last-mile/02-session-participant-record.md @@ -241,7 +241,7 @@ When the orchestrator becomes terminal: Files: - `crates/shell/src/execution/agents_cmd.rs` -- `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md` +- `docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md` - `docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/agent-hub-session-protocol-spec.md` Required changes: diff --git a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md index 9e1d2a82c..6c2b82bb9 100644 --- a/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md +++ b/llm-last-mile/27-uaa-boundary-and-naming-cleanup.md @@ -541,7 +541,7 @@ When this slice lands, the following must be updated together: - [AGENTS.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/AGENTS.md), - [ADR-0042](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md), - [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md), -- [docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md), +- [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md), - [dist/release-template.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/dist/release-template.md), - [scripts/linux/world-provision.sh](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/scripts/linux/world-provision.sh), - [scripts/substrate/install-substrate.sh](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/scripts/substrate/install-substrate.sh), @@ -1190,7 +1190,7 @@ This pass kept the approved baseline fixed: The current text names `_archived/**`, but the repo still contains non-archived path families with old names that are neither clearly live nor clearly exempt: - [macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md:43) still treats `world-agent` and `substrate-world-agent` as current contract terms. - - [docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md:69) and adjacent draft-pack specs still describe `protocol=uaa.agent.session` as the canonical pure-agent label. + - [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md:28) and adjacent draft-pack specs still describe `protocol=uaa.agent.session` as the canonical pure-agent label. Those are not under `docs/project_management/_archived/**`, and they are not currently called out in the SOW's truth-sync set or allowlist. That leaves exact room for implementation drift: one contributor can treat them as live normative surfaces, another can treat them as historical planning evidence, and both can claim the SOW supports that choice. @@ -1245,7 +1245,7 @@ This pass keeps the approved baseline fixed: 4. The live-vs-historical boundary needed explicit path decisions, not just category language. - The earlier pass correctly found ambiguity around [macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md:43) and [docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md:69). This pass resolves that by treating those path families as truth-sync surfaces unless they are explicitly allowlisted as historical. + The earlier pass correctly found ambiguity around [macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/macos-hardening/macos-hardened-same-user-lima/phase-2-same-user-hardening/README.md:43) and [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md:28). This pass resolves that by treating those path families as truth-sync surfaces unless they are explicitly allowlisted as historical. ### Round-4 Verdict diff --git a/llm-last-mile/PLAN-02.md b/llm-last-mile/PLAN-02.md index 2fc34dbf6..e22ca8fe5 100644 --- a/llm-last-mile/PLAN-02.md +++ b/llm-last-mile/PLAN-02.md @@ -469,7 +469,7 @@ Files: - [crates/shell/src/execution/agent_runtime/session.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/session.rs:36) - [crates/shell/src/execution/agent_runtime/mod.rs](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/mod.rs:1) - [docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/agent-hub-session-protocol-spec.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/agent-hub-session-protocol-spec.md) -- [docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md) +- [ADR-0044](/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/adr/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md) Do: From 6b3895d7fb88d5f3042ae0b6c7ec850f7ba02c03 Mon Sep 17 00:00:00 2001 From: spenquatch Date: Tue, 26 May 2026 23:54:41 -0400 Subject: [PATCH 20/20] Remove archived audit docs from git index --- .gitignore | 1 + .rgignore | 1 + FSE_PRE_PLANNING_DEPENDENCY_GRAPH.md | 208 - FSE_PRE_PLANNING_STAGE_OUTPUT_CONTRACT.md | 599 - ...AI_CAPABILITY_ENABLEMENT_PLANNING_ORDER.md | 104 - PWS_FULL_PLANNING_ORCHESTRATION_V1.md | 500 - ...ARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md | 210 - .../UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md | 355 - .../CI_CHECKPOINTING_ADHOC_NOTES.md | 120 - .../ci-improvements/ci-improvements.md | 246 - .../config_subcommand_plan.md | 137 - .../kickoff_prompts/C1-code.md | 55 - .../kickoff_prompts/C1-integ.md | 43 - .../kickoff_prompts/C1-test.md | 52 - .../kickoff_prompts/C2-code.md | 42 - .../kickoff_prompts/C2-integ.md | 39 - .../kickoff_prompts/C2-test.md | 41 - .../kickoff_prompts/C3-code.md | 46 - .../kickoff_prompts/C3-integ.md | 41 - .../kickoff_prompts/C3-test.md | 46 - .../kickoff_prompts/README.md | 16 - .../config-subcommand/session_log.md | 145 - .../_archived/config-subcommand/tasks.json | 395 - .../doctor_scopes/DS0-closeout_report.md | 72 - .../_archived/doctor_scopes/DS0-spec.md | 269 - .../doctor_scopes/decision_register.md | 428 - .../execution_preflight_report.md | 71 - .../doctor_scopes/integration_map.md | 63 - .../doctor_scopes/kickoff_prompts/DS0-code.md | 38 - .../kickoff_prompts/DS0-integ-core.md | 40 - .../kickoff_prompts/DS0-integ-linux.md | 30 - .../kickoff_prompts/DS0-integ-macos.md | 30 - .../kickoff_prompts/DS0-integ-windows.md | 27 - .../kickoff_prompts/DS0-integ.md | 37 - .../doctor_scopes/kickoff_prompts/DS0-test.md | 35 - .../kickoff_prompts/F0-exec-preflight.md | 34 - .../kickoff_prompts/FZ-feature-cleanup.md | 26 - .../doctor_scopes/manual_testing_playbook.md | 97 - .../_archived/doctor_scopes/plan.md | 35 - .../doctor_scopes/quality_gate_report.md | 303 - .../_archived/doctor_scopes/session_log.md | 213 - .../doctor_scopes/smoke/linux-smoke.sh | 67 - .../doctor_scopes/smoke/macos-smoke.sh | 52 - .../doctor_scopes/smoke/windows-smoke.ps1 | 11 - .../_archived/doctor_scopes/tasks.json | 416 - .../EV0-closeout_report.md | 147 - .../EV0-spec.md | 121 - .../decision_register.md | 107 - .../execution_preflight_report.md | 63 - .../integration_map.md | 80 - .../kickoff_prompts/EV0-code.md | 36 - .../kickoff_prompts/EV0-integ-core.md | 33 - .../kickoff_prompts/EV0-integ-linux.md | 33 - .../kickoff_prompts/EV0-integ-macos.md | 33 - .../kickoff_prompts/EV0-integ-windows.md | 33 - .../kickoff_prompts/EV0-integ.md | 38 - .../kickoff_prompts/EV0-test.md | 30 - .../kickoff_prompts/F0-exec-preflight.md | 34 - .../kickoff_prompts/FZ-feature-cleanup.md | 33 - .../manual_testing_playbook.md | 244 - .../plan.md | 63 - .../quality_gate_report.md | 166 - .../session_log.md | 113 - .../smoke/linux-smoke.sh | 68 - .../smoke/macos-smoke.sh | 68 - .../smoke/windows-smoke.ps1 | 111 - .../tasks.json | 444 - .../C0-closeout_report.md | 63 - .../C0-spec.md | 127 - .../decision_register.md | 199 - .../execution_preflight_report.md | 98 - .../integration_map.md | 47 - .../kickoff_prompts/C0-code.md | 31 - .../kickoff_prompts/C0-integ-core.md | 124 - .../kickoff_prompts/C0-integ-linux.md | 54 - .../kickoff_prompts/C0-integ-macos.md | 54 - .../kickoff_prompts/C0-integ-windows.md | 54 - .../kickoff_prompts/C0-integ.md | 53 - .../kickoff_prompts/C0-test.md | 27 - .../kickoff_prompts/F0-exec-preflight.md | 32 - .../kickoff_prompts/FZ-feature-cleanup.md | 29 - .../logs/C0/code/events.jsonl | 6 - .../logs/C0/code/last_message.md | 6 - .../logs/C0/code/stderr.log | 6531 -- .../codex.pid.aborted-20260120T131437Z.pid | 1 - .../logs/C0/integ-core/events.jsonl | 18 - ...vents.jsonl.aborted-20260120T131437Z.jsonl | 0 .../logs/C0/integ-core/last_message.md | 18 - .../stderr.aborted-20260120T131437Z.log | 44916 -------- .../logs/C0/integ-core/stderr.log | 3202 - .../logs/C0/test/events.jsonl | 10 - .../logs/C0/test/last_message.md | 10 - .../logs/C0/test/stderr.log | 8985 -- .../manual_testing_playbook.md | 68 - .../plan.md | 30 - .../quality_gate_report.md | 166 - .../session_log.md | 151 - .../smoke/linux-smoke.sh | 121 - .../smoke/macos-smoke.sh | 121 - .../smoke/windows-smoke.ps1 | 11 - .../tasks.json | 454 - .../_archived/logs/linux_always_world.md | 184 - .../_archived/logs/macos_always_world.md | 221 - .../_archived/logs/windows_always_world.md | 692 - .../misc/PHASE_4_CONCURRENT_OUTPUT_DESIGN.md | 226 - ...RE_PLANNING_BUCKET_AND_SCAFFOLDING_PLAN.md | 188 - .../_archived/misc/RELEASE_PIPELINE_PLAN.md | 408 - .../misc/RELEASE_PIPELINE_PLAN.tasks.json | 502 - .../WORKSTREAM_SYSTEM_IMPLEMENTATION_PLAN.md | 293 - .../WORKSTREAM_TRIAGE_AND_LIFT_DECISIONS.md | 327 - .../misc/implementation_phase5_windows.md | 996 - .../pre_planning_researcn_orchestration.md | 373 - .../misc/stage5_editor_parity_plan.md | 152 - .../_archived/misc/tasks.json | 1082 - .../next/agent_hub_core/decision_register.md | 593 - .../_archived/next/forge/decision_register.md | 186 - .../decision_register.md | 1117 - .../decision_register.md | 254 - .../next/linux_guest_rootfs_backend/plan.md | 247 - .../next/linux_guest_rootfs_backend/spec.md | 314 - .../next/linux_guest_rootfs_backend/tasks.md | 72 - .../next/llm_cli_backend_engine/contract.md | 39 - .../decision_register.md | 459 - .../manual_testing_playbook.md | 11 - .../next/llm_cli_backend_engine/plan.md | 21 - .../llm_cli_backend_engine/spec_manifest.md | 13 - .../specs/adapter_contract.md | 50 - .../next/llm_cli_backend_engine/tasks.json | 7 - .../next/llm_gateway_in_world/contract.md | 65 - .../llm_gateway_in_world/decision_register.md | 723 - .../next/llm_gateway_in_world/impact_map.md | 16 - .../manual_testing_playbook.md | 10 - .../next/llm_gateway_in_world/plan.md | 23 - .../llm_gateway_in_world/spec_manifest.md | 14 - .../specs/env_injection.md | 90 - .../specs/http_surface.md | 39 - .../next/llm_gateway_in_world/tasks.json | 7 - .../01_problem_and_goals.md | 29 - .../02_current_state.md | 21 - .../03_solution_overview.md | 40 - .../04_architecture_and_flows.md | 93 - .../macos_world_backend_vf/05_policy_model.md | 80 - .../06_security_and_threat_model.md | 63 - .../macos_world_backend_vf/07_testing_plan.md | 55 - .../macos_world_backend_vf/08_rollout_plan.md | 36 - .../09_work_breakdown.md | 38 - .../10_open_questions.md | 21 - .../next/macos_world_backend_vf/README.md | 31 - .../quality_gate_report.md | 206 - .../decision_register.md | 595 - .../_archived/next/sequencing.json | 727 - .../next/workflow-engine/decision_register.md | 239 - ...-agent-hub-runtime-config-and-isolation.md | 367 - .../I0-spec.md | 31 - .../I1-spec.md | 27 - .../I2-spec.md | 30 - .../I3-spec.md | 19 - .../I4-spec.md | 18 - .../I5-spec.md | 19 - .../I6-spec.md | 61 - .../I7-spec.md | 34 - .../I8-spec.md | 29 - .../I9-spec.md | 34 - .../kickoff_prompts/I0-code.md | 37 - .../kickoff_prompts/I0-integ.md | 40 - .../kickoff_prompts/I0-test.md | 36 - .../kickoff_prompts/I1-code.md | 37 - .../kickoff_prompts/I1-integ.md | 40 - .../kickoff_prompts/I1-test.md | 36 - .../kickoff_prompts/I2-code.md | 36 - .../kickoff_prompts/I2-integ.md | 40 - .../kickoff_prompts/I2-test.md | 36 - .../kickoff_prompts/I3-code.md | 36 - .../kickoff_prompts/I3-integ.md | 40 - .../kickoff_prompts/I3-test.md | 36 - .../kickoff_prompts/I4-code.md | 36 - .../kickoff_prompts/I4-integ.md | 40 - .../kickoff_prompts/I4-test.md | 36 - .../kickoff_prompts/I5-code.md | 38 - .../kickoff_prompts/I5-integ.md | 40 - .../kickoff_prompts/I5-test.md | 36 - .../kickoff_prompts/I6-code.md | 37 - .../kickoff_prompts/I6-integ.md | 40 - .../kickoff_prompts/I6-test.md | 37 - .../kickoff_prompts/I7-code.md | 32 - .../kickoff_prompts/I7-integ.md | 40 - .../kickoff_prompts/I7-test.md | 38 - .../kickoff_prompts/I8-code.md | 39 - .../kickoff_prompts/I8-integ.md | 40 - .../kickoff_prompts/I8-test.md | 38 - .../kickoff_prompts/I9-code.md | 39 - .../kickoff_prompts/I9-integ.md | 41 - .../kickoff_prompts/I9-test.md | 40 - .../kickoff_prompts/README.md | 14 - .../manual_testing_playbook.md | 293 - .../p0-agent-hub-isolation-hardening/plan.md | 79 - .../session_log.md | 587 - .../smoke/linux-smoke.sh | 19 - .../smoke/macos-smoke.sh | 19 - .../smoke/windows-smoke.ps1 | 20 - .../tasks.json | 1293 - .../p0-ci-runner-smoke/smoke/linux-smoke.sh | 10 - .../p0-ci-runner-smoke/smoke/macos-smoke.sh | 10 - .../smoke/windows-smoke.ps1 | 14 - .../M1-spec.md | 23 - .../M2-spec.md | 22 - .../M3-spec.md | 28 - .../M4-spec.md | 39 - .../M5a-spec.md | 33 - .../M5b-spec.md | 29 - .../M5c-spec.md | 25 - .../M6-spec.md | 28 - .../kickoff_prompts/M1-code.md | 34 - .../kickoff_prompts/M1-integ.md | 31 - .../kickoff_prompts/M1-test.md | 30 - .../kickoff_prompts/M2-code.md | 31 - .../kickoff_prompts/M2-integ.md | 31 - .../kickoff_prompts/M2-test.md | 29 - .../kickoff_prompts/M3-code.md | 32 - .../kickoff_prompts/M3-integ.md | 31 - .../kickoff_prompts/M3-test.md | 29 - .../kickoff_prompts/M4-code.md | 40 - .../kickoff_prompts/M4-integ.md | 37 - .../kickoff_prompts/M4-test.md | 38 - .../kickoff_prompts/M5a-code.md | 41 - .../kickoff_prompts/M5a-integ.md | 37 - .../kickoff_prompts/M5a-test.md | 38 - .../kickoff_prompts/M5b-code.md | 51 - .../kickoff_prompts/M5b-integ.md | 37 - .../kickoff_prompts/M5b-test.md | 38 - .../kickoff_prompts/M5c-code.md | 40 - .../kickoff_prompts/M5c-integ.md | 37 - .../kickoff_prompts/M5c-test.md | 38 - .../kickoff_prompts/M6-code.md | 38 - .../kickoff_prompts/M6-integ.md | 37 - .../kickoff_prompts/M6-test.md | 38 - .../plan.md | 50 - .../session_log.md | 292 - .../tasks.json | 1006 - .../INV-overlay-consistency.md | 32 - .../p0-platform-stability/LP1-spec.md | 19 - .../kickoff_prompts/H1a-code.md | 42 - .../kickoff_prompts/H1a-integ.md | 35 - .../kickoff_prompts/H1a-test.md | 41 - .../kickoff_prompts/H1b-code.md | 42 - .../kickoff_prompts/H1b-integ.md | 35 - .../kickoff_prompts/H1b-test.md | 41 - .../kickoff_prompts/LP1-code.md | 31 - .../kickoff_prompts/LP1-integ.md | 30 - .../kickoff_prompts/LP1-test.md | 29 - .../kickoff_prompts/R1a-code.md | 41 - .../kickoff_prompts/R1a-integ.md | 35 - .../kickoff_prompts/R1a-test.md | 40 - .../kickoff_prompts/R1b-code.md | 41 - .../kickoff_prompts/R1b-integ.md | 35 - .../kickoff_prompts/R1b-test.md | 41 - .../kickoff_prompts/R1c-code.md | 42 - .../kickoff_prompts/R1c-integ.md | 36 - .../kickoff_prompts/R1c-test.md | 41 - .../kickoff_prompts/R2a-code.md | 43 - .../kickoff_prompts/R2a-integ.md | 34 - .../kickoff_prompts/R2a-test.md | 42 - .../kickoff_prompts/R2b-code.md | 42 - .../kickoff_prompts/R2b-integ.md | 35 - .../kickoff_prompts/R2b-test.md | 36 - .../kickoff_prompts/R2c-code.md | 37 - .../kickoff_prompts/R2c-integ.md | 35 - .../kickoff_prompts/R2c-test.md | 37 - .../kickoff_prompts/R2d-code.md | 44 - .../kickoff_prompts/R2d-integ.md | 34 - .../kickoff_prompts/R2d-test.md | 37 - .../kickoff_prompts/R2e-code.md | 43 - .../kickoff_prompts/R2e-integ.md | 35 - .../kickoff_prompts/R2e-test.md | 37 - .../kickoff_prompts/R2f-code.md | 41 - .../kickoff_prompts/R2f-integ.md | 33 - .../kickoff_prompts/R2f-test.md | 40 - .../kickoff_prompts/README.md | 11 - .../kickoff_prompts/S1a-code.md | 42 - .../kickoff_prompts/S1a-integ.md | 35 - .../kickoff_prompts/S1a-test.md | 40 - .../kickoff_prompts/S1b-code.md | 42 - .../kickoff_prompts/S1b-integ.md | 35 - .../kickoff_prompts/S1b-test.md | 42 - .../kickoff_prompts/S1c-code.md | 44 - .../kickoff_prompts/S1c-integ.md | 40 - .../kickoff_prompts/S1c-test.md | 45 - .../kickoff_prompts/S1c-windows-dry-run.md | 43 - .../kickoff_prompts/S1d-code.md | 43 - .../kickoff_prompts/S1d-integ.md | 35 - .../kickoff_prompts/S1d-test.md | 44 - .../kickoff_prompts/S1e-code.md | 41 - .../kickoff_prompts/S1e-integ.md | 41 - .../kickoff_prompts/S1e-test.md | 42 - .../manual_testing_playbook.md | 364 - .../p0_platform_stability_plan.md | 94 - .../_archived/p0-platform-stability/plan.md | 51 - .../p0-platform-stability/session_log.md | 926 - .../smoke/linux-smoke.sh | 93 - .../smoke/macos-smoke.sh | 82 - .../p0-platform-stability/smoke/smoke.sh | 18 - .../smoke/windows-smoke.ps1 | 37 - .../p0-platform-stability/tasks.json | 2299 - .../ALWAYS_IN_WORLD_PTY_EXECUTION_PLAN.md | 284 - .../COMPLETE_FIXES_PHASE4_PRE45.md | 553 - ...SE_4_5_ALWAYS_WORLD_IMPLEMENTATION_PLAN.md | 536 - .../PHASE_4_5_ALWAYS_WORLD_MAC_PLAN.md | 846 - .../PHASE_4_COMPLETION_REPORT.md | 521 - .../phase_4-isolation/PHASE_4_PROGRESS.md | 311 - .../PHASE_4_SESSION3_CONTINUATION.md | 168 - .../PHASE_4_SESSION4_CONTINUATION.md | 149 - .../PHASE_4_SESSION5_CONTINUATION.md | 211 - .../PHASE_4_SESSION6_CONTINUATION.md | 203 - .../PHASE_5_ALWAYS_WORLD_WINDOWS_PLAN.md | 1048 - .../PRE_PHASE_4_5_HARDENING_PLAN.md | 372 - .../PRE_PHASE_4_5_PR_STEPS.md | 227 - .../PROMPT_TEMPLATE_PHASE_HANDOFF.md | 40 - .../SPIKE_TRANSPORT_PARITY_PLAN.md | 546 - ... HTTP-WS Bridge Patterns in Production.md" | 98 - .../implementation_phase4_merged.md | 2246 - .../windows_host_transport_plan.md | 230 - .../windows_transport_external_overview.md | 272 - .../initiative1_slice_specs_v2.md | 368 - .../initiative1_slice_specs_v2_revA.md | 472 - ...itiative1_slice_specs_v2_work_breakdown.md | 307 - .../initiative2_impact_map_enforcement.md | 300 - ...initiative2_impact_map_enforcement_revA.md | 459 - ...act_map_enforcement_revA_work_breakdown.md | 405 - .../initiative3_directory_prompt_refactor.md | 553 - ...irectory_prompt_refactor_work_breakdown.md | 684 - .../C0-closeout_report.md | 54 - .../C0-spec.md | 93 - .../C1-closeout_report.md | 55 - .../C1-spec.md | 54 - .../decision_register.md | 72 - .../execution_preflight_report.md | 77 - .../integration_map.md | 73 - .../kickoff_prompts/C0-code.md | 25 - .../kickoff_prompts/C0-integ-core.md | 28 - .../kickoff_prompts/C0-integ-linux.md | 16 - .../kickoff_prompts/C0-integ-macos.md | 16 - .../kickoff_prompts/C0-integ-windows.md | 16 - .../kickoff_prompts/C0-integ.md | 18 - .../kickoff_prompts/C0-test.md | 24 - .../kickoff_prompts/C1-code.md | 25 - .../kickoff_prompts/C1-integ-core.md | 28 - .../kickoff_prompts/C1-integ-linux.md | 16 - .../kickoff_prompts/C1-integ-macos.md | 16 - .../kickoff_prompts/C1-integ-windows.md | 16 - .../kickoff_prompts/C1-integ.md | 18 - .../kickoff_prompts/C1-test.md | 24 - .../kickoff_prompts/F0-exec-preflight.md | 17 - .../kickoff_prompts/FZ-feature-cleanup.md | 15 - .../logs/C0/code/events.jsonl | 14 - .../logs/C0/code/last_message.md | 14 - .../logs/C0/code/stderr.log | 79404 -------------- .../logs/C0/integ-core/events.jsonl | 6 - .../logs/C0/integ-core/last_message.md | 6 - .../logs/C0/integ-core/stderr.log | 17323 --- .../logs/C0/integ/events.jsonl | 6 - .../logs/C0/integ/last_message.md | 6 - .../logs/C0/integ/stderr.log | 6415 -- .../logs/C0/test/events.jsonl | 14 - .../logs/C0/test/last_message.md | 14 - .../logs/C0/test/stderr.log | 6624 -- .../logs/C1/code/events.jsonl | 6 - .../logs/C1/code/last_message.md | 6 - .../logs/C1/code/stderr.log | 9111 -- .../logs/C1/integ-core/events.jsonl | 8 - .../logs/C1/integ-core/last_message.md | 8 - .../logs/C1/integ-core/stderr.log | 700 - .../logs/C1/integ/events.jsonl | 5 - .../logs/C1/integ/last_message.md | 5 - .../logs/C1/integ/stderr.log | 11618 -- .../logs/C1/test/events.jsonl | 9 - .../logs/C1/test/last_message.md | 9 - .../logs/C1/test/stderr.log | 10856 -- .../manual_testing_playbook.md | 81 - .../plan.md | 29 - .../quality_gate_report.md | 257 - .../session_log.md | 370 - .../smoke/linux-smoke.sh | 101 - .../smoke/macos-smoke.sh | 101 - .../smoke/windows-smoke.ps1 | 96 - .../tasks.json | 792 - .../PCM0-spec.md | 155 - .../PCM1-spec.md | 119 - .../PCM2-spec.md | 78 - .../PCM3-spec.md | 83 - .../decision_register.md | 335 - .../integration_map.md | 90 - .../kickoff_prompts/PCM0-code.md | 31 - .../kickoff_prompts/PCM0-integ.md | 38 - .../kickoff_prompts/PCM0-test.md | 35 - .../kickoff_prompts/PCM1-code.md | 32 - .../kickoff_prompts/PCM1-integ.md | 38 - .../kickoff_prompts/PCM1-test.md | 34 - .../kickoff_prompts/PCM2-code.md | 32 - .../kickoff_prompts/PCM2-integ.md | 38 - .../kickoff_prompts/PCM2-test.md | 35 - .../kickoff_prompts/PCM3-code.md | 33 - .../kickoff_prompts/PCM3-integ.md | 38 - .../kickoff_prompts/PCM3-test.md | 35 - .../manual_testing_playbook.md | 115 - .../plan.md | 93 - .../quality_gate_report.md | 265 - .../session_log.md | 288 - .../smoke/linux-smoke.sh | 439 - .../smoke/macos-smoke.sh | 49 - .../smoke/windows-smoke.ps1 | 25 - .../tasks.json | 491 - .../PCP0-closeout_report.md | 55 - .../policy_and_config_precedence/PCP0-spec.md | 57 - .../decision_register.md | 38 - .../execution_preflight_report.md | 64 - .../integration_map.md | 52 - .../kickoff_prompts/F0-exec-preflight.md | 34 - .../kickoff_prompts/FZ-feature-cleanup.md | 27 - .../kickoff_prompts/PCP0-code.md | 38 - .../kickoff_prompts/PCP0-integ-core.md | 54 - .../kickoff_prompts/PCP0-integ-linux.md | 35 - .../kickoff_prompts/PCP0-integ-macos.md | 35 - .../kickoff_prompts/PCP0-integ-windows.md | 35 - .../kickoff_prompts/PCP0-integ.md | 41 - .../kickoff_prompts/PCP0-test.md | 30 - .../manual_testing_playbook.md | 56 - .../policy_and_config_precedence/plan.md | 68 - .../quality_gate_report.md | 184 - .../session_log.md | 173 - .../smoke/linux-smoke.sh | 54 - .../smoke/macos-smoke.sh | 49 - .../smoke/windows-smoke.ps1 | 58 - .../policy_and_config_precedence/tasks.json | 384 - .../pre_phase_4/CI_ANALYSIS_REPORT.md | 422 - .../_archived/pre_phase_4/LINUX_BUTTON_UP.md | 353 - .../PHASE_3.75_COMPLETION_STATUS.md | 312 - .../pre_phase_4/auto_shim_deployment_plan.md | 448 - .../pre_phase_4/ci_test_failures_fix_plan.md | 474 - .../pre_phase_4/implementation_phase3.5.md | 3169 - .../pre_phase_4/implementation_phase3.md | 2959 - .../_archived/pre_phase_4/plan.md | 290 - .../_archived/pty_spike/PTY_PROMPT_FIX.md | 339 - .../pty_spike/PTY_PROMPT_NEW_PLAN.md | 395 - .../pty_spike/REEDLINE_CLEANUP_STEPS.md | 249 - .../pty_spike/REEDLINE_MIGRATION_PLAN.md | 1030 - .../_archived/pty_spike/REEDLINE_PR_READY.md | 188 - .../_archived/pty_spike/REEDLINE_PTY_ISSUE.md | 292 - .../refactor/kickoff_prompts/R1-code.md | 64 - .../refactor/kickoff_prompts/R1-integ.md | 63 - .../refactor/kickoff_prompts/R1-test.md | 62 - .../refactor/kickoff_prompts/R10-code.md | 53 - .../refactor/kickoff_prompts/R10-integ.md | 51 - .../refactor/kickoff_prompts/R10-test.md | 52 - .../refactor/kickoff_prompts/R11-code.md | 56 - .../refactor/kickoff_prompts/R11-integ.md | 51 - .../refactor/kickoff_prompts/R11-test.md | 52 - .../refactor/kickoff_prompts/R12-code.md | 54 - .../refactor/kickoff_prompts/R12-integ.md | 51 - .../refactor/kickoff_prompts/R12-test.md | 52 - .../refactor/kickoff_prompts/R13-code.md | 52 - .../refactor/kickoff_prompts/R13-integ.md | 50 - .../refactor/kickoff_prompts/R13-test.md | 50 - .../refactor/kickoff_prompts/R14-code.md | 53 - .../refactor/kickoff_prompts/R14-integ.md | 51 - .../refactor/kickoff_prompts/R14-test.md | 52 - .../refactor/kickoff_prompts/R15-code.md | 51 - .../refactor/kickoff_prompts/R15-integ.md | 51 - .../refactor/kickoff_prompts/R15-test.md | 51 - .../refactor/kickoff_prompts/R2-code.md | 64 - .../refactor/kickoff_prompts/R2-integ.md | 65 - .../refactor/kickoff_prompts/R2-test.md | 62 - .../refactor/kickoff_prompts/R3-code.md | 63 - .../refactor/kickoff_prompts/R3-integ.md | 64 - .../refactor/kickoff_prompts/R3-test.md | 61 - .../refactor/kickoff_prompts/R4-code.md | 63 - .../refactor/kickoff_prompts/R4-integ.md | 65 - .../refactor/kickoff_prompts/R4-test.md | 62 - .../refactor/kickoff_prompts/R5-code.md | 59 - .../refactor/kickoff_prompts/R5-integ.md | 57 - .../refactor/kickoff_prompts/R5-test.md | 57 - .../refactor/kickoff_prompts/R6-code.md | 60 - .../refactor/kickoff_prompts/R6-integ.md | 57 - .../refactor/kickoff_prompts/R6-test.md | 57 - .../refactor/kickoff_prompts/R7-code.md | 59 - .../refactor/kickoff_prompts/R7-integ.md | 56 - .../refactor/kickoff_prompts/R7-test.md | 58 - .../refactor/kickoff_prompts/R8-code.md | 58 - .../refactor/kickoff_prompts/R8-integ.md | 51 - .../refactor/kickoff_prompts/R8-test.md | 57 - .../refactor/kickoff_prompts/R9a-code.md | 53 - .../refactor/kickoff_prompts/R9a-integ.md | 51 - .../refactor/kickoff_prompts/R9a-test.md | 52 - .../refactor/kickoff_prompts/R9b-code.md | 53 - .../refactor/kickoff_prompts/R9b-integ.md | 51 - .../refactor/kickoff_prompts/R9b-test.md | 52 - .../refactor/kickoff_prompts/R9c-code.md | 53 - .../refactor/kickoff_prompts/R9c-integ.md | 51 - .../refactor/kickoff_prompts/R9c-test.md | 52 - .../refactor/kickoff_prompts/README.md | 19 - .../_archived/refactor/refactor_plan.md | 180 - .../_archived/refactor/session_log.md | 787 - .../_archived/refactor/tasks.json | 2135 - .../settings-stack/kickoff_prompts/S0-code.md | 55 - .../kickoff_prompts/S0-integ.md | 31 - .../settings-stack/kickoff_prompts/S0-test.md | 47 - .../settings-stack/kickoff_prompts/S1-code.md | 54 - .../kickoff_prompts/S1-integ.md | 33 - .../settings-stack/kickoff_prompts/S1-test.md | 48 - .../settings-stack/kickoff_prompts/S2-code.md | 35 - .../kickoff_prompts/S2-integ.md | 35 - .../settings-stack/kickoff_prompts/S2-test.md | 33 - .../settings-stack/kickoff_prompts/S3-code.md | 35 - .../kickoff_prompts/S3-integ.md | 34 - .../settings-stack/kickoff_prompts/S3-test.md | 34 - .../settings-stack/kickoff_prompts/S4-code.md | 31 - .../kickoff_prompts/S4-integ.md | 34 - .../settings-stack/kickoff_prompts/S4-test.md | 32 - .../settings-stack/kickoff_prompts/S5-code.md | 32 - .../kickoff_prompts/S5-integ.md | 35 - .../settings-stack/kickoff_prompts/S5-test.md | 34 - .../_archived/settings-stack/session_log.md | 300 - .../settings-stack/settings_stack_plan.md | 158 - .../_archived/settings-stack/tasks.json | 758 - .../standards/ADR_STANDARD_AND_TEMPLATE.md | 256 - .../standards/CONTRACT_SURFACE_STANDARD.md | 32 - .../EXECUTION_PREFLIGHT_GATE_STANDARD.md | 69 - .../standards/EXECUTIVE_SUMMARY_STANDARD.md | 57 - .../_archived/standards/EXIT_CODE_TAXONOMY.md | 49 - .../PLANNING_CI_CHECKPOINT_STANDARD.md | 98 - .../PLANNING_GATE_REPORT_TEMPLATE.md | 159 - .../standards/PLANNING_IMPACT_MAP_STANDARD.md | 126 - .../standards/PLANNING_LINT_CHECKLIST.md | 53 - .../standards/PLANNING_QUALITY_GATE_PROMPT.md | 7 - ...LANNING_QUALITY_GATE_REMEDIATION_PROMPT.md | 7 - .../_archived/standards/PLANNING_README.md | 105 - ...LANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md | 381 - .../PLANNING_SESSION_LOG_TEMPLATE.md | 59 - .../PLANNING_SPEC_DETERMINATION_STANDARD.md | 149 - .../standards/PLANNING_WORKFLOW_OVERVIEW.md | 62 - .../standards/PLATFORM_INTEGRATION_AND_CI.md | 231 - .../_archived/standards/README.md | 209 - .../SECRETS_DELIVERY_CHANNEL_RUBRIC.md | 87 - .../standards/SLICE_CLOSEOUT_GATE_STANDARD.md | 45 - .../TASK_TRIADS_AND_FEATURE_SETUP.md | 325 - ...TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md | 111 - .../TRIAD_INTEGRATION_WRAPPER_PROMPT.md | 7 - .../TRIAD_WORKFLOW_CROSS_PLATFORM_INTEG.md | 346 - .../standards/TRIAD_WRAPPER_PROMPT.md | 7 - .../standards/TRIAD_WRAPPER_PROMPT_UNIFIED.md | 7 - .../_archived/standards/rustStandards.md | 350 - .../_archived/standards/tasks.schema.json | 94 - .../kickoff_prompts/A1-integ.md | 24 - .../kickoff_prompts/A1-test.md | 27 - .../kickoff_prompts/A2-integ.md | 23 - .../kickoff_prompts/A2-test.md | 24 - .../kickoff_prompts/A3-code.md | 24 - .../kickoff_prompts/A3-integ.md | 22 - .../kickoff_prompts/A3-test.md | 23 - .../kickoff_prompts/B1-code.md | 22 - .../kickoff_prompts/B1-integ.md | 22 - .../kickoff_prompts/B1-test.md | 23 - .../kickoff_prompts/B2-code.md | 24 - .../kickoff_prompts/B2-integ.md | 22 - .../kickoff_prompts/B2-test.md | 25 - .../kickoff_prompts/B3-docs.md | 24 - .../kickoff_prompts/B3-integ.md | 23 - .../kickoff_prompts/C1-code.md | 25 - .../kickoff_prompts/C1-integ.md | 26 - .../kickoff_prompts/C1-test.md | 29 - .../kickoff_prompts/C2-code.md | 25 - .../kickoff_prompts/C2-integ.md | 38 - .../kickoff_prompts/C2-test.md | 23 - .../kickoff_prompts/C3-code.md | 24 - .../kickoff_prompts/C3-integ.md | 37 - .../kickoff_prompts/C3-test.md | 33 - .../kickoff_prompts/D1-code.md | 24 - .../kickoff_prompts/D1-integ.md | 28 - .../kickoff_prompts/D1-test.md | 25 - .../kickoff_prompts/D2-code.md | 27 - .../kickoff_prompts/D2-integ.md | 27 - .../kickoff_prompts/D2-test.md | 25 - .../kickoff_prompts/D3-code.md | 33 - .../kickoff_prompts/D3-integ.md | 28 - .../kickoff_prompts/D3-test.md | 29 - .../substrate-isolated-shell/session_log.md | 300 - .../substrate_isolated_shell_data_map.md | 108 - ...bstrate_isolated_shell_dependency_graph.md | 64 - ...substrate_isolated_shell_execution_plan.md | 112 - .../substrate_isolated_shell_file_audit.md | 73 - .../substrate_isolated_shell_plan.md | 245 - .../substrate-isolated-shell/tasks.json | 819 - .../world-deps-sync.md | 76 - .../_archived/work_lift_v1_seams/README.md | 42 - .../cohesion-audit.report.json | 217 - .../cohesion-audit.report.md | 119 - .../cohesion-audit.scan.after.json | 379 - .../cohesion-audit.scan.json | 290 - .../cohesion-remediator.log.md | 67 - .../concrete-audit.report.json | 575 - .../concrete-audit.report.md | 272 - .../concrete-audit.scan.after.json | 202 - .../concrete-remediator.log.md | 168 - .../contradictions-audit.report.json | 233 - .../contradictions-audit.report.md | 114 - .../contradictions-audit.scan.after.json | 39 - .../contradictions-remediator.log.md | 90 - .../work_lift_v1_seams/scope_brief.md | 40 - .../seam-1-lift-vector-schema-and-rubric.md | 47 - .../seam-2-lift-model-config-v1.md | 41 - .../seam-3-pm-lift-core-engine.md | 44 - .../seam-4-pack-derived-lift-inputs.md | 55 - .../seam-5-advisory-workflow-integration.md | 55 - .../_archived/work_lift_v1_seams/seam_map.md | 52 - .../threaded-seams/README.md | 28 - .../seam.md | 54 - .../slice-1-contract-1-schema.md | 132 - .../slice-2-human-rubric-and-conformance.md | 102 - .../seam-2-lift-model-config-v1/seam.md | 56 - .../slice-1-contract-2-model-config.md | 249 - .../slice-2-goldens-and-conformance.md | 106 - .../seam-3-pm-lift-core-engine/seam.md | 72 - .../slice-1-contract-3-emit-json.md | 177 - ...-2-config-backed-scoring-and-validation.md | 152 - .../slice-3-goldens-and-conformance.md | 211 - .../seam-4-pack-derived-lift-inputs/seam.md | 76 - ...slice-1-contract-4-impact-map-emit-json.md | 202 - ...e-2-prefix-expansion-and-derived-counts.md | 139 - .../seam.md | 81 - ...advisory-workflow-docs-and-make-targets.md | 115 - ...visory-report-hook-and-lint-integration.md | 97 - .../slice-3-strict-mode-onramp-plan.md | 109 - .../_archived/work_lift_v1_seams/threading.md | 82 - .../PHASE_A_B_GATES_ADR_0012.md | 124 - .../WCU1-closeout_report.md | 38 - .../WCU1-spec.md | 70 - .../WCU2-closeout_report.md | 40 - .../WCU2-spec.md | 101 - .../WCU3-closeout_report.md | 52 - .../WCU3-spec.md | 94 - .../WCU4-closeout_report.md | 37 - .../WCU4-spec.md | 20 - .../WCU5-closeout_report.md | 44 - .../WCU5-spec.md | 39 - .../decision_register.md | 767 - .../execution_preflight_report.md | 85 - .../integration_map.md | 107 - .../kickoff_prompts/F0-exec-preflight.md | 32 - .../kickoff_prompts/FZ-feature-cleanup.md | 27 - .../kickoff_prompts/WCU1-code.md | 23 - .../kickoff_prompts/WCU1-integ-core.md | 21 - .../kickoff_prompts/WCU1-integ-linux.md | 21 - .../kickoff_prompts/WCU1-integ-macos.md | 21 - .../kickoff_prompts/WCU1-integ-windows.md | 21 - .../kickoff_prompts/WCU1-integ.md | 29 - .../kickoff_prompts/WCU1-test.md | 22 - .../kickoff_prompts/WCU2-code.md | 24 - .../kickoff_prompts/WCU2-integ-core.md | 21 - .../kickoff_prompts/WCU2-integ-linux.md | 21 - .../kickoff_prompts/WCU2-integ-macos.md | 21 - .../kickoff_prompts/WCU2-integ-windows.md | 21 - .../kickoff_prompts/WCU2-integ.md | 27 - .../kickoff_prompts/WCU2-test.md | 23 - .../kickoff_prompts/WCU3-code.md | 25 - .../kickoff_prompts/WCU3-integ-core.md | 21 - .../kickoff_prompts/WCU3-integ-linux.md | 21 - .../kickoff_prompts/WCU3-integ-macos.md | 21 - .../kickoff_prompts/WCU3-integ-windows.md | 21 - .../kickoff_prompts/WCU3-integ.md | 28 - .../kickoff_prompts/WCU3-test.md | 23 - .../kickoff_prompts/WCU4-code.md | 22 - .../kickoff_prompts/WCU4-integ-core.md | 21 - .../kickoff_prompts/WCU4-integ-linux.md | 21 - .../kickoff_prompts/WCU4-integ-macos.md | 21 - .../kickoff_prompts/WCU4-integ-windows.md | 21 - .../kickoff_prompts/WCU4-integ.md | 25 - .../kickoff_prompts/WCU4-test.md | 22 - .../kickoff_prompts/WCU5-code.md | 24 - .../kickoff_prompts/WCU5-integ-core.md | 21 - .../kickoff_prompts/WCU5-integ-linux.md | 21 - .../kickoff_prompts/WCU5-integ-macos.md | 21 - .../kickoff_prompts/WCU5-integ-windows.md | 21 - .../kickoff_prompts/WCU5-integ.md | 27 - .../kickoff_prompts/WCU5-test.md | 24 - .../logs/WCU3/integ-core/events.jsonl | 9 - .../logs/WCU3/integ-core/last_message.md | 9 - .../logs/WCU3/integ-core/stderr.log | 5065 - .../logs/WCU3/integ/events.jsonl | 5 - .../logs/WCU3/integ/last_message.md | 5 - .../logs/WCU3/integ/stderr.log | 4221 - .../logs/WCU4/code/events.jsonl | 4 - .../logs/WCU4/code/last_message.md | 4 - .../logs/WCU4/code/stderr.log | 4412 - .../logs/WCU4/integ-core/codex.pid | 1 - .../logs/WCU4/integ-core/events.jsonl | 0 .../logs/WCU4/integ-core/last_message.md | 9 - .../logs/WCU4/integ-core/stderr.log | 998 - .../logs/WCU4/integ/events.jsonl | 6 - .../logs/WCU4/integ/last_message.md | 6 - .../logs/WCU4/integ/stderr.log | 3460 - .../logs/WCU4/test/events.jsonl | 9 - .../logs/WCU4/test/last_message.md | 9 - .../logs/WCU4/test/stderr.log | 4609 - .../logs/WCU5/code/events.jsonl | 7 - .../logs/WCU5/code/last_message.md | 7 - .../logs/WCU5/code/stderr.log | 87449 ---------------- .../logs/WCU5/integ-core/events.jsonl | 7 - .../logs/WCU5/integ-core/last_message.md | 7 - .../logs/WCU5/integ-core/stderr.log | 4813 - .../logs/WCU5/integ/events.jsonl | 7 - .../logs/WCU5/integ/last_message.md | 7 - .../logs/WCU5/integ/stderr.log | 933 - .../logs/WCU5/test/events.jsonl | 5 - .../logs/WCU5/test/last_message.md | 5 - .../logs/WCU5/test/stderr.log | 2383 - .../manual_testing_playbook.md | 217 - .../plan.md | 91 - .../quality_gate_report.md | 171 - .../session_log.md | 484 - .../smoke/linux-smoke.sh | 426 - .../smoke/macos-smoke.sh | 8 - .../smoke/windows-smoke.ps1 | 316 - .../tasks.json | 1867 - .../world-agent-policy-snapshot/DR_tasks.json | 534 - .../world-agent-policy-snapshot/ci_runs.md | 80 - .../decision_register.md | 441 - .../policy-snapshot-deprecation-spec.md | 77 - .../policy-snapshot-spec.md | 284 - .../smoke/linux-smoke.sh | 329 - .../smoke/macos-smoke.sh | 351 - .../smoke/windows-smoke.ps1 | 16 - .../smoke/windows-wsl-smoke.ps1 | 597 - .../C0-closeout_report.md | 52 - .../C0-spec.md | 67 - .../C1-closeout_report.md | 56 - .../C1-spec.md | 76 - .../C2-closeout_report.md | 64 - .../C2-spec.md | 49 - .../C3-closeout_report.md | 56 - .../C3-spec.md | 62 - .../C4-closeout_report.md | 56 - .../C4-spec.md | 40 - .../C5-closeout_report.md | 56 - .../C5-spec.md | 38 - .../PROTOCOL.md | 442 - .../RESEARCH.md | 234 - .../STATE_MACHINE.md | 253 - .../decision_register.md | 542 - .../drain_design.md | 341 - .../driver_loop_design.md | 392 - .../execution_preflight_report.md | 96 - .../integration_map.md | 94 - .../kickoff_prompts/C0-code.md | 27 - .../kickoff_prompts/C0-integ-core.md | 28 - .../kickoff_prompts/C0-integ-linux.md | 21 - .../kickoff_prompts/C0-integ-macos.md | 21 - .../kickoff_prompts/C0-integ-windows.md | 20 - .../kickoff_prompts/C0-integ.md | 22 - .../kickoff_prompts/C0-test.md | 26 - .../kickoff_prompts/C1-code.md | 25 - .../kickoff_prompts/C1-integ-core.md | 23 - .../kickoff_prompts/C1-integ-linux.md | 18 - .../kickoff_prompts/C1-integ-macos.md | 18 - .../kickoff_prompts/C1-integ-windows.md | 18 - .../kickoff_prompts/C1-integ.md | 23 - .../kickoff_prompts/C1-test.md | 21 - .../kickoff_prompts/C2-code.md | 26 - .../kickoff_prompts/C2-integ-core.md | 19 - .../kickoff_prompts/C2-integ-linux.md | 18 - .../kickoff_prompts/C2-integ-macos.md | 18 - .../kickoff_prompts/C2-integ-windows.md | 18 - .../kickoff_prompts/C2-integ.md | 19 - .../kickoff_prompts/C2-test.md | 21 - .../kickoff_prompts/C3-code.md | 27 - .../kickoff_prompts/C3-integ-core.md | 23 - .../kickoff_prompts/C3-integ-linux.md | 22 - .../kickoff_prompts/C3-integ-macos.md | 22 - .../kickoff_prompts/C3-integ-windows.md | 22 - .../kickoff_prompts/C3-integ.md | 22 - .../kickoff_prompts/C3-test.md | 24 - .../kickoff_prompts/C4-code.md | 27 - .../kickoff_prompts/C4-integ-core.md | 23 - .../kickoff_prompts/C4-integ-linux.md | 22 - .../kickoff_prompts/C4-integ-macos.md | 22 - .../kickoff_prompts/C4-integ-windows.md | 22 - .../kickoff_prompts/C4-integ.md | 22 - .../kickoff_prompts/C4-test.md | 24 - .../kickoff_prompts/C5-code.md | 28 - .../kickoff_prompts/C5-integ-core.md | 23 - .../kickoff_prompts/C5-integ-linux.md | 22 - .../kickoff_prompts/C5-integ-macos.md | 22 - .../kickoff_prompts/C5-integ-windows.md | 22 - .../kickoff_prompts/C5-integ.md | 22 - .../kickoff_prompts/C5-test.md | 24 - .../kickoff_prompts/F0-exec-preflight.md | 79 - .../kickoff_prompts/FZ-feature-cleanup.md | 18 - .../manual_testing_playbook.md | 172 - .../world-first-repl-persistent-pty/plan.md | 139 - .../quality_gate_report.md | 213 - .../requirements_traceability.md | 274 - .../session_log.md | 587 - .../smoke/linux-smoke.sh | 112 - .../smoke/macos-smoke.sh | 21 - .../smoke/windows-smoke.ps1 | 5 - .../tasks.json | 2077 - .../WFGADAXA0-closeout_report.md | 61 - .../WFGADAXA0-spec.md | 36 - .../WFGADAXA1-closeout_report.md | 73 - .../WFGADAXA1-spec.md | 47 - .../WFGADAXA2-closeout_report.md | 68 - .../WFGADAXA2-spec.md | 51 - .../ci_checkpoint_plan.md | 49 - .../contract.md | 43 - .../decision_register.md | 15 - .../execution_preflight_report.md | 117 - .../impact_map.md | 97 - .../kickoff_prompts/CP1-ci-checkpoint.md | 14 - .../kickoff_prompts/F0-exec-preflight.md | 27 - .../kickoff_prompts/FZ-feature-cleanup.md | 10 - .../kickoff_prompts/WFGADAXA0-code.md | 26 - .../kickoff_prompts/WFGADAXA0-integ.md | 27 - .../kickoff_prompts/WFGADAXA0-test.md | 25 - .../kickoff_prompts/WFGADAXA1-code.md | 26 - .../kickoff_prompts/WFGADAXA1-integ.md | 28 - .../kickoff_prompts/WFGADAXA1-test.md | 27 - .../kickoff_prompts/WFGADAXA2-code.md | 24 - .../kickoff_prompts/WFGADAXA2-integ-core.md | 26 - .../kickoff_prompts/WFGADAXA2-integ-linux.md | 11 - .../kickoff_prompts/WFGADAXA2-integ-macos.md | 10 - .../WFGADAXA2-integ-windows.md | 10 - .../kickoff_prompts/WFGADAXA2-integ.md | 17 - .../kickoff_prompts/WFGADAXA2-test.md | 23 - .../manual_testing_playbook.md | 89 - .../plan.md | 74 - .../quality_gate_report.md | 165 - .../session_log.md | 299 - .../smoke/_core.sh | 151 - .../smoke/linux-smoke.sh | 24 - .../smoke/macos-smoke.sh | 25 - .../spec_manifest.md | 68 - .../tasks.json | 706 - .../ENV.md | 27 - .../PROTOCOL.md | 42 - .../SCHEMA.md | 152 - .../SECURITY.md | 18 - .../WFGADAX0-spec.md | 12 - .../WFGADAX1-spec.md | 11 - .../WFGADAX2-spec.md | 11 - .../WFGADAX3-spec.md | 10 - .../ci_checkpoint_plan.md | 38 - .../contract.md | 92 - .../decision_register.md | 199 - .../execution_preflight_report.md | 69 - .../impact_map.md | 60 - .../kickoff_prompts/CP1-ci-checkpoint.md | 34 - .../kickoff_prompts/CP2-ci-checkpoint.md | 34 - .../kickoff_prompts/F0-exec-preflight.md | 17 - .../kickoff_prompts/FZ-feature-cleanup.md | 16 - .../kickoff_prompts/WFGADAX0-code.md | 24 - .../kickoff_prompts/WFGADAX0-integ.md | 23 - .../kickoff_prompts/WFGADAX0-test.md | 24 - .../kickoff_prompts/WFGADAX1-code.md | 23 - .../kickoff_prompts/WFGADAX1-integ-core.md | 22 - .../kickoff_prompts/WFGADAX1-integ-linux.md | 22 - .../kickoff_prompts/WFGADAX1-integ-macos.md | 22 - .../kickoff_prompts/WFGADAX1-integ-windows.md | 22 - .../kickoff_prompts/WFGADAX1-integ.md | 22 - .../kickoff_prompts/WFGADAX1-test.md | 22 - .../kickoff_prompts/WFGADAX2-code.md | 23 - .../kickoff_prompts/WFGADAX2-integ.md | 22 - .../kickoff_prompts/WFGADAX2-test.md | 22 - .../kickoff_prompts/WFGADAX3-code.md | 23 - .../kickoff_prompts/WFGADAX3-integ-core.md | 22 - .../kickoff_prompts/WFGADAX3-integ-linux.md | 22 - .../kickoff_prompts/WFGADAX3-integ-macos.md | 22 - .../kickoff_prompts/WFGADAX3-integ-windows.md | 22 - .../kickoff_prompts/WFGADAX3-integ.md | 22 - .../kickoff_prompts/WFGADAX3-test.md | 22 - .../manual_testing_playbook.md | 146 - .../plan.md | 44 - .../quality_gate_report.md | 803 - .../requirements_traceability.md | 34 - .../session_log.md | 298 - .../smoke/_core.sh | 53 - .../smoke/linux-smoke.sh | 18 - .../smoke/macos-smoke.sh | 18 - .../smoke/windows-smoke.ps1 | 12 - .../spec_manifest.md | 55 - .../tasks.json | 1018 - .../world-fs-granular-allow-deny/ENV.md | 97 - .../world-fs-granular-allow-deny/PROTOCOL.md | 58 - .../world-fs-granular-allow-deny/SCHEMA.md | 195 - .../world-fs-granular-allow-deny/SECURITY.md | 60 - .../WFGAD0-spec.md | 18 - .../WFGAD1-spec.md | 17 - .../WFGAD2-spec.md | 15 - .../WFGAD3-spec.md | 15 - .../WFGAD4-spec.md | 15 - .../WFGAD5-spec.md | 14 - .../ci_checkpoint_plan.md | 75 - .../world-fs-granular-allow-deny/contract.md | 89 - .../decision_register.md | 409 - .../execution_preflight_report.md | 36 - .../impact_map.md | 127 - .../integration_map.md | 6 - .../kickoff_prompts/CP1-ci-checkpoint.md | 31 - .../kickoff_prompts/CP2-ci-checkpoint.md | 31 - .../kickoff_prompts/CP3-ci-checkpoint.md | 31 - .../kickoff_prompts/F0-exec-preflight.md | 26 - .../kickoff_prompts/FZ-feature-cleanup.md | 32 - .../kickoff_prompts/WFGAD0-code.md | 28 - .../kickoff_prompts/WFGAD0-integ.md | 25 - .../kickoff_prompts/WFGAD0-test.md | 25 - .../kickoff_prompts/WFGAD1-code.md | 28 - .../kickoff_prompts/WFGAD1-integ-core.md | 27 - .../kickoff_prompts/WFGAD1-integ-linux.md | 27 - .../kickoff_prompts/WFGAD1-integ-macos.md | 27 - .../kickoff_prompts/WFGAD1-integ-windows.md | 27 - .../kickoff_prompts/WFGAD1-integ.md | 30 - .../kickoff_prompts/WFGAD1-test.md | 25 - .../kickoff_prompts/WFGAD2-code.md | 28 - .../kickoff_prompts/WFGAD2-integ.md | 25 - .../kickoff_prompts/WFGAD2-test.md | 25 - .../kickoff_prompts/WFGAD3-code.md | 28 - .../kickoff_prompts/WFGAD3-integ-core.md | 25 - .../kickoff_prompts/WFGAD3-integ-linux.md | 28 - .../kickoff_prompts/WFGAD3-integ-macos.md | 28 - .../kickoff_prompts/WFGAD3-integ-windows.md | 28 - .../kickoff_prompts/WFGAD3-integ.md | 30 - .../kickoff_prompts/WFGAD3-test.md | 25 - .../kickoff_prompts/WFGAD4-code.md | 28 - .../kickoff_prompts/WFGAD4-integ.md | 26 - .../kickoff_prompts/WFGAD4-test.md | 25 - .../kickoff_prompts/WFGAD5-code.md | 28 - .../kickoff_prompts/WFGAD5-integ-core.md | 25 - .../kickoff_prompts/WFGAD5-integ-linux.md | 28 - .../kickoff_prompts/WFGAD5-integ-macos.md | 28 - .../kickoff_prompts/WFGAD5-integ-windows.md | 28 - .../kickoff_prompts/WFGAD5-integ.md | 30 - .../kickoff_prompts/WFGAD5-test.md | 25 - .../manual_testing_playbook.md | 93 - .../world-fs-granular-allow-deny/plan.md | 39 - .../quality_gate_report.md | 173 - .../requirements_traceability.md | 50 - .../session_log.md | 398 - .../smoke/_core.sh | 276 - .../smoke/linux-smoke.sh | 17 - .../smoke/macos-smoke.sh | 34 - .../smoke/windows-smoke.ps1 | 5 - .../spec_manifest.md | 60 - .../world-fs-granular-allow-deny/tasks.json | 1602 - .../WO0-closeout_report.md | 54 - .../world-overlayfs-enumeration/WO0-spec.md | 73 - .../decision_register.md | 80 - .../execution_preflight_report.md | 53 - .../integration_map.md | 68 - .../kickoff_prompts/F0-exec-preflight.md | 33 - .../kickoff_prompts/FZ-feature-cleanup.md | 31 - .../kickoff_prompts/WO0-code.md | 31 - .../kickoff_prompts/WO0-integ-core.md | 44 - .../kickoff_prompts/WO0-integ-linux.md | 27 - .../kickoff_prompts/WO0-integ-macos.md | 27 - .../kickoff_prompts/WO0-integ-windows.md | 27 - .../kickoff_prompts/WO0-integ.md | 34 - .../kickoff_prompts/WO0-test.md | 32 - .../manual_testing_playbook.md | 102 - .../world-overlayfs-enumeration/plan.md | 27 - .../quality_gate_report.md | 155 - .../session_log.md | 242 - .../smoke/linux-smoke.sh | 83 - .../smoke/macos-smoke.sh | 11 - .../smoke/windows-smoke.ps1 | 5 - .../world-overlayfs-enumeration/tasks.json | 402 - .../world-sync-legacy-2026-02-10/C0-spec.md | 26 - .../world-sync-legacy-2026-02-10/C1-spec.md | 62 - .../world-sync-legacy-2026-02-10/C2-spec.md | 31 - .../world-sync-legacy-2026-02-10/C3-spec.md | 25 - .../world-sync-legacy-2026-02-10/C4-spec.md | 18 - .../world-sync-legacy-2026-02-10/C5-spec.md | 23 - .../world-sync-legacy-2026-02-10/C6-spec.md | 25 - .../world-sync-legacy-2026-02-10/C7-spec.md | 25 - .../world-sync-legacy-2026-02-10/C8-spec.md | 20 - .../world-sync-legacy-2026-02-10/C9-spec.md | 22 - .../kickoff_prompts/C0-code.md | 28 - .../kickoff_prompts/C0-integ.md | 31 - .../kickoff_prompts/C0-test.md | 26 - .../kickoff_prompts/C1-code.md | 28 - .../kickoff_prompts/C1-integ.md | 33 - .../kickoff_prompts/C1-test.md | 27 - .../kickoff_prompts/C2-code.md | 28 - .../kickoff_prompts/C2-integ.md | 32 - .../kickoff_prompts/C2-test.md | 27 - .../kickoff_prompts/C3-code.md | 27 - .../kickoff_prompts/C3-integ.md | 31 - .../kickoff_prompts/C3-test.md | 26 - .../kickoff_prompts/C4-code.md | 27 - .../kickoff_prompts/C4-integ.md | 31 - .../kickoff_prompts/C4-test.md | 26 - .../kickoff_prompts/C5-code.md | 27 - .../kickoff_prompts/C5-integ.md | 31 - .../kickoff_prompts/C5-test.md | 26 - .../kickoff_prompts/C6-code.md | 26 - .../kickoff_prompts/C6-integ.md | 31 - .../kickoff_prompts/C6-test.md | 26 - .../kickoff_prompts/C7-code.md | 26 - .../kickoff_prompts/C7-integ.md | 31 - .../kickoff_prompts/C7-test.md | 26 - .../kickoff_prompts/C8-code.md | 27 - .../kickoff_prompts/C8-integ.md | 31 - .../kickoff_prompts/C8-test.md | 26 - .../kickoff_prompts/C9-code.md | 27 - .../kickoff_prompts/C9-integ.md | 31 - .../kickoff_prompts/C9-test.md | 26 - .../manual_testing_playbook.md | 236 - .../world-sync-legacy-2026-02-10/plan.md | 58 - .../session_log.md | 3 - .../smoke/linux-smoke.sh | 40 - .../smoke/macos-smoke.sh | 40 - .../smoke/windows-smoke.ps1 | 34 - .../world-sync-legacy-2026-02-10/tasks.json | 1088 - .../S0-spec-selection-config-and-ux.md | 293 - .../S1-spec-install-classes.md | 193 - .../S2-spec-system-packages-provisioning.md | 207 - .../WDL0-closeout_report.md | 54 - .../WDL1-closeout_report.md | 54 - .../WDL2-closeout_report.md | 60 - .../decision_register.md | 927 - .../execution_preflight_report.md | 86 - .../integration_map.md | 159 - .../kickoff_prompts/F0-exec-preflight.md | 38 - .../kickoff_prompts/FZ-feature-cleanup.md | 33 - .../kickoff_prompts/WDL0-code.md | 28 - .../kickoff_prompts/WDL0-integ-core.md | 35 - .../kickoff_prompts/WDL0-integ-linux.md | 27 - .../kickoff_prompts/WDL0-integ-macos.md | 27 - .../kickoff_prompts/WDL0-integ-windows.md | 27 - .../kickoff_prompts/WDL0-integ.md | 33 - .../kickoff_prompts/WDL0-test.md | 27 - .../kickoff_prompts/WDL1-code.md | 29 - .../kickoff_prompts/WDL1-integ-core.md | 37 - .../kickoff_prompts/WDL1-integ-linux.md | 27 - .../kickoff_prompts/WDL1-integ-macos.md | 27 - .../kickoff_prompts/WDL1-integ-windows.md | 27 - .../kickoff_prompts/WDL1-integ.md | 34 - .../kickoff_prompts/WDL1-test.md | 28 - .../kickoff_prompts/WDL2-code.md | 29 - .../kickoff_prompts/WDL2-integ-core.md | 37 - .../kickoff_prompts/WDL2-integ-linux.md | 27 - .../kickoff_prompts/WDL2-integ-macos.md | 27 - .../kickoff_prompts/WDL2-integ-windows.md | 27 - .../kickoff_prompts/WDL2-integ.md | 34 - .../kickoff_prompts/WDL2-test.md | 28 - .../manual_testing_playbook.md | 342 - .../world_deps_selection_layer/plan.md | 112 - .../quality_gate_report.md | 200 - .../world_deps_selection_layer/session_log.md | 232 - .../session_log_legacy_2025-12-24.md | 51 - .../smoke/linux-smoke.sh | 123 - .../smoke/macos-smoke.sh | 189 - .../smoke/windows-smoke.ps1 | 161 - .../world_deps_selection_layer/tasks.json | 1012 - .../yaml-settings-migration/Y0-spec.md | 79 - .../kickoff_prompts/README.md | 14 - .../kickoff_prompts/Y0-code.md | 37 - .../kickoff_prompts/Y0-integ.md | 40 - .../kickoff_prompts/Y0-test.md | 36 - .../manual_testing_playbook.md | 149 - .../_archived/yaml-settings-migration/plan.md | 85 - .../yaml-settings-migration/session_log.md | 77 - .../smoke/linux-smoke.sh | 62 - .../smoke/macos-smoke.sh | 61 - .../smoke/windows-smoke.ps1 | 36 - .../yaml-settings-migration/tasks.json | 138 - .../PROVISIONING_SURFACE_RECONCILIATION.md | 104 - docs/project_management/adrs/README.md | 39 - docs/project_management/adrs/draft/.gitkeep | 2 - ...d-config-mental-model-simplification_OG.md | 842 - ...-and-linux-system-packages-provisioning.md | 302 - ...kend-contract-and-capability-divergence.md | 138 - ...DR-0016-world-first-repl-persistent-pty.md | 240 - ...concurrent-execution-and-output-routing.md | 356 - ...al-show-when-workspace-config-overrides.md | 149 - ...R-0020-profiles-config-policy-snapshots.md | 209 - .../ADR-0021-substrate-workflow-engine.md | 231 - ...-0022-forge-agent-loop-as-workflow-node.md | 227 - ...DR-0023-in-world-llm-gateway-front-door.md | 218 - .../ADR-0024-cli-backend-provider-engine.md | 187 - .../ADR-0025-agent-hub-core-role-swappable.md | 308 - .../ADR-0026-orchestration-toolbox-mcp.md | 287 - ...027-llm-and-agent-config-policy-surface.md | 395 - ...-world-process-execution-tracing-parity.md | 445 - ...R-0029-host-event-bus-and-router-daemon.md | 358 - .../adrs/draft/ADR-0030-provisioning-otter.md | 232 - .../adrs/draft/ADR-0031-detecting-badger.md | 273 - .../adrs/draft/ADR-0032-stashing-ferret.md | 191 - .../adrs/draft/ADR-0033-routing-weasel.md | 281 - .../adrs/draft/ADR-0034-staging-beaver.md | 199 - .../adrs/draft/ADR-0035-summoning-wombat.md | 226 - .../adrs/draft/ADR-0036-quieting-lemur.md | 235 - .../adrs/draft/ADR-0037-clarifying-owl.md | 279 - .../adrs/draft/ADR-0038-replaying-raccoon.md | 234 - .../adrs/draft/ADR-0039-capturing-koala.md | 132 - ...-gateway-boundary-and-runtime-ownership.md | 275 - ...strate-gateway-backend-adapter-contract.md | 278 - ...t-identity-tuple-and-deployment-posture.md | 331 - ...-adr-0027-identity-tuple-policy-surface.md | 287 - ...ore-successor-identity-tuple-compatible.md | 352 - ...ox-internal-mcp-identity-trace-contract.md | 375 - ...y-backend-selection-runtime-integration.md | 287 - ...-session-and-parked-resumable-ownership.md | 439 - ...-world-backend-virtualization-framework.md | 113 - .../adrs/implemented/.gitkeep | 2 - ...-install-classes-and-world-provisioning.md | 180 - ...-and-config-mental-model-simplification.md | 983 - ...layfs-directory-enumeration-reliability.md | 208 - ...05-workspace-config-precedence-over-env.md | 177 - ...006-env-var-taxonomy-and-override-split.md | 203 - .../ADR-0007-host-and-world-doctor-scopes.md | 184 - ...icy-scope-and-dot-substrate-unification.md | 540 - ...11-world-deps-packages-bundles-contract.md | 811 - ...fig-schema-per-key-merge-and-provenance.md | 171 - ...y-broker-canonical-effective-resolution.md | 194 - ...rvice-policy-resolution-and-concurrency.md | 154 - ...olation-landlock-overlayfs-backing-dirs.md | 139 - ...-fs-granular-allow-deny-and-strict-deny.md | 580 - docs/project_management/adrs/queued/.gitkeep | 2 - .../adrs/superseded/.gitkeep | 2 - .../COMMAND_HOOKS_IMPLEMENTATION_PLAN.md | 940 - .../project_management/future/INTERNAL_GIT.md | 512 - .../PHASE_4_5_ADVANCED_FEATURES_PLAN.md | 1067 - .../future/PHASE_4_5_ISOLATION_UPGRADE.md | 125 - .../future/TESTING_AGENT.md | 1587 - .../future/TUI_TESTING_GUIDE.md | 352 - ...rateGetsStuckOnSubstrateInceptionError.png | Bin 39395 -> 0 bytes .../intake/adrs/capturing_koala_adr_intake.md | 130 - .../intake/adrs/clarifying_owl_adr_intake.md | 187 - .../adrs/detecting_badger_adr_intake.md | 227 - .../adrs/provisioning_otter_adr_intake.md | 268 - .../intake/adrs/quieting_lemur_adr_intake.md | 198 - .../adrs/replaying_raccoon_adr_intake.md | 175 - .../intake/adrs/routing_weasel_adr_intake.md | 201 - .../intake/adrs/staging_beaver_adr_intake.md | 198 - .../intake/adrs/stashing_ferret_adr_intake.md | 211 - .../adrs/summoning_wombat_adr_intake.md | 220 - .../intake/scratch/terminal_automation.md | 9 - .../lifting_marmot_work_item_intake.md | 104 - ...PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md | 561 - docs/project_management/packs/README.md | 17 - docs/project_management/packs/active/.gitkeep | 2 - .../ci_checkpoint_plan.md | 50 - .../contract.md | 84 - .../decision_register.md | 108 - .../execution_preflight_report.md | 88 - .../impact_map.md | 82 - .../integration_map.md | 45 - .../kickoff_prompts/CP1-ci-checkpoint.md | 45 - .../kickoff_prompts/F0-exec-preflight.md | 36 - .../kickoff_prompts/FZ-feature-cleanup.md | 32 - .../manual_testing_playbook.md | 129 - .../plan.md | 102 - .../quality_gate_report.md | 106 - .../session_log.md | 60 - .../slices/C0/C0-closeout_report.md | 58 - .../slices/C0/C0-spec.md | 86 - .../slices/C0/kickoff_prompts/C0-code.md | 31 - .../C0/kickoff_prompts/C0-integ-core.md | 149 - .../C0/kickoff_prompts/C0-integ-linux.md | 68 - .../C0/kickoff_prompts/C0-integ-macos.md | 68 - .../C0/kickoff_prompts/C0-integ-windows.md | 68 - .../slices/C0/kickoff_prompts/C0-integ.md | 71 - .../slices/C0/kickoff_prompts/C0-test.md | 27 - .../smoke/linux-smoke.sh | 145 - .../smoke/macos-smoke.sh | 128 - .../smoke/windows-smoke.ps1 | 160 - .../spec_manifest.md | 52 - .../tasks.json | 553 - .../PROTOCOL.md | 123 - .../SCHEMA.md | 172 - .../SECURITY.md | 58 - .../WPEP0-spec.md | 30 - .../WPEP1-spec.md | 23 - .../WPEP2-spec.md | 33 - .../WPEP3-spec.md | 26 - .../ci_checkpoint_plan.md | 77 - .../contract.md | 24 - .../decision_register.md | 529 - .../impact_map.md | 63 - .../kickoff_prompts/CP1-ci-checkpoint.md | 21 - .../kickoff_prompts/CP2-ci-checkpoint.md | 29 - .../kickoff_prompts/F0-exec-preflight.md | 24 - .../kickoff_prompts/FZ-feature-cleanup.md | 25 - .../kickoff_prompts/README.md | 7 - .../kickoff_prompts/WPEP0-code.md | 29 - .../kickoff_prompts/WPEP0-integ-core.md | 24 - .../kickoff_prompts/WPEP0-integ-linux.md | 21 - .../kickoff_prompts/WPEP0-integ-macos.md | 21 - .../kickoff_prompts/WPEP0-integ-windows.md | 21 - .../kickoff_prompts/WPEP0-integ.md | 19 - .../kickoff_prompts/WPEP0-test.md | 25 - .../kickoff_prompts/WPEP1-code.md | 24 - .../kickoff_prompts/WPEP1-integ.md | 17 - .../kickoff_prompts/WPEP1-test.md | 15 - .../kickoff_prompts/WPEP2-code.md | 16 - .../kickoff_prompts/WPEP2-integ.md | 16 - .../kickoff_prompts/WPEP2-test.md | 15 - .../kickoff_prompts/WPEP3-code.md | 17 - .../kickoff_prompts/WPEP3-integ-core.md | 15 - .../kickoff_prompts/WPEP3-integ-linux.md | 13 - .../kickoff_prompts/WPEP3-integ-macos.md | 13 - .../kickoff_prompts/WPEP3-integ-windows.md | 14 - .../kickoff_prompts/WPEP3-integ.md | 16 - .../kickoff_prompts/WPEP3-test.md | 15 - .../manual_testing_playbook.md | 183 - .../world_process_exec_tracing_parity/plan.md | 43 - .../quality_gate_report.md | 585 - .../session_log.md | 487 - .../smoke/_core.sh | 193 - .../smoke/linux-smoke.sh | 18 - .../smoke/macos-smoke.sh | 18 - .../smoke/windows-smoke.ps1 | 90 - .../spec_manifest.md | 70 - .../tasks.json | 816 - docs/project_management/packs/draft/.gitkeep | 2 - .../compatibility-spec.md | 112 - .../contract.md | 157 - .../decision_register.md | 124 - .../execution_preflight_report.md | 146 - .../kickoff_prompts/CP1-ci-checkpoint.md | 22 - .../kickoff_prompts/F0-exec-preflight.md | 22 - .../kickoff_prompts/FZ-feature-cleanup.md | 22 - .../manual_testing_playbook.md | 362 - .../plan.md | 54 - .../policy-spec.md | 200 - .../pre-planning/alignment_report.md | 28 - .../pre-planning/ci_checkpoint_plan.md | 89 - .../pre-planning/impact_map.md | 162 - .../pre-planning/minimal_spec_draft.md | 149 - .../pre-planning/spec_manifest.md | 298 - .../pre-planning/workstream_triage.md | 202 - .../quality_gate_report.md | 724 - .../session_log.md | 163 - .../slices/ITPS0/ITPS0-closeout_report.md | 25 - .../slices/ITPS0/ITPS0-spec.md | 69 - .../ITPS0/kickoff_prompts/ITPS0-code.md | 22 - .../ITPS0/kickoff_prompts/ITPS0-integ.md | 23 - .../ITPS0/kickoff_prompts/ITPS0-test.md | 22 - .../slices/ITPS1/ITPS1-closeout_report.md | 28 - .../slices/ITPS1/ITPS1-spec.md | 73 - .../ITPS1/kickoff_prompts/ITPS1-code.md | 22 - .../ITPS1/kickoff_prompts/ITPS1-integ.md | 23 - .../ITPS1/kickoff_prompts/ITPS1-test.md | 22 - .../slices/ITPS2/ITPS2-closeout_report.md | 30 - .../slices/ITPS2/ITPS2-spec.md | 65 - .../ITPS2/kickoff_prompts/ITPS2-code.md | 22 - .../ITPS2/kickoff_prompts/ITPS2-integ.md | 23 - .../ITPS2/kickoff_prompts/ITPS2-test.md | 22 - .../slices/ITPS3/ITPS3-closeout_report.md | 34 - .../slices/ITPS3/ITPS3-spec.md | 66 - .../ITPS3/kickoff_prompts/ITPS3-code.md | 22 - .../ITPS3/kickoff_prompts/ITPS3-integ-core.md | 22 - .../kickoff_prompts/ITPS3-integ-linux.md | 22 - .../kickoff_prompts/ITPS3-integ-macos.md | 22 - .../kickoff_prompts/ITPS3-integ-windows.md | 22 - .../ITPS3/kickoff_prompts/ITPS3-integ.md | 23 - .../ITPS3/kickoff_prompts/ITPS3-test.md | 22 - .../smoke/_core.sh | 332 - .../smoke/linux-smoke.sh | 11 - .../smoke/macos-smoke.sh | 11 - .../smoke/windows-smoke.ps1 | 132 - .../tasks.json | 924 - .../telemetry-spec.md | 213 - .../tuple-policy-schema-spec.md | 221 - .../agent-hub-session-protocol-spec.md | 415 - .../compatibility-spec.md | 148 - .../contract.md | 446 - .../kickoff_prompts/CP1-ci-checkpoint.md | 25 - .../kickoff_prompts/CP2-ci-checkpoint.md | 25 - .../kickoff_prompts/FZ-feature-cleanup.md | 21 - .../manual_testing_playbook.md | 512 - .../plan.md | 62 - .../platform-parity-spec.md | 137 - .../policy-spec.md | 219 - .../pre-planning/alignment_report.md | 26 - .../pre-planning/ci_checkpoint_plan.md | 110 - .../pre-planning/impact_map.md | 274 - .../pre-planning/minimal_spec_draft.md | 166 - .../pre-planning/spec_manifest.md | 378 - .../pre-planning/workstream_triage.md | 302 - .../quality_gate_report.md | 25 - .../session_log.md | 267 - .../slices/AHCSITC0/AHCSITC0-spec.md | 49 - .../AHCSITC0/kickoff_prompts/AHCSITC0-code.md | 25 - .../kickoff_prompts/AHCSITC0-integ.md | 24 - .../AHCSITC0/kickoff_prompts/AHCSITC0-test.md | 23 - .../slices/AHCSITC1/AHCSITC1-spec.md | 47 - .../AHCSITC1/kickoff_prompts/AHCSITC1-code.md | 25 - .../kickoff_prompts/AHCSITC1-integ.md | 24 - .../AHCSITC1/kickoff_prompts/AHCSITC1-test.md | 23 - .../slices/AHCSITC2/AHCSITC2-spec.md | 47 - .../AHCSITC2/kickoff_prompts/AHCSITC2-code.md | 25 - .../kickoff_prompts/AHCSITC2-integ-core.md | 24 - .../kickoff_prompts/AHCSITC2-integ-linux.md | 24 - .../kickoff_prompts/AHCSITC2-integ-macos.md | 24 - .../kickoff_prompts/AHCSITC2-integ-windows.md | 24 - .../kickoff_prompts/AHCSITC2-integ.md | 24 - .../AHCSITC2/kickoff_prompts/AHCSITC2-test.md | 23 - .../slices/AHCSITC3/AHCSITC3-spec.md | 46 - .../AHCSITC3/kickoff_prompts/AHCSITC3-code.md | 25 - .../kickoff_prompts/AHCSITC3-integ-core.md | 24 - .../kickoff_prompts/AHCSITC3-integ-linux.md | 24 - .../kickoff_prompts/AHCSITC3-integ-macos.md | 24 - .../kickoff_prompts/AHCSITC3-integ-windows.md | 24 - .../kickoff_prompts/AHCSITC3-integ.md | 24 - .../AHCSITC3/kickoff_prompts/AHCSITC3-test.md | 23 - .../tasks.json | 1202 - .../telemetry-spec.md | 236 - .../README.md | 63 - .../compatibility-spec.md | 50 - .../governance/pack-closeout.md | 24 - .../governance/remediation-log.md | 163 - .../governance/seam-1-closeout.md | 79 - .../governance/seam-2-closeout.md | 81 - .../governance/seam-3-closeout.md | 84 - .../manual_testing_playbook.md | 92 - .../platform-parity-spec.md | 55 - .../review_surfaces.md | 68 - .../scope_brief.md | 83 - ...-1-backend-selection-and-policy-surface.md | 143 - ...eam-2-runtime-realization-and-artifacts.md | 161 - .../seam-3-parity-validation-and-rollout.md | 157 - .../seam_map.md | 33 - .../smoke/linux-smoke.sh | 116 - .../smoke/macos-smoke.sh | 116 - .../smoke/windows-smoke.ps1 | 110 - .../review.md | 92 - .../seam.md | 143 - .../slice-00-c-01-c-02-contract-definition.md | 123 - ...e-1-selection-order-and-inventory-truth.md | 111 - ...icy-precedence-and-fail-closed-boundary.md | 115 - ...slice-3-shell-adoption-and-drift-guards.md | 118 - .../slice-99-seam-exit-gate.md | 109 - .../review.md | 93 - .../seam.md | 153 - ...e-1-binding-lookup-and-capability-gates.md | 113 - ...ce-2-request-auth-and-runtime-artifacts.md | 117 - ...-lifecycle-conformance-and-drift-guards.md | 110 - .../slice-99-seam-exit-gate.md | 109 - .../review.md | 87 - .../seam.md | 157 - ...ity-regression-floor-and-backend-matrix.md | 84 - ...ence-and-unsupported-backend-validation.md | 82 - ...out-proof-and-compatibility-publication.md | 79 - .../slice-99-seam-exit-gate.md | 106 - .../threading.md | 153 - .../fse_pre_planning.json | 8 - .../pre-planning/alignment_report.md | 22 - .../pre-planning/ci_checkpoint_plan.md | 135 - .../pre-planning/impact_map.md | 234 - .../pre-planning/minimal_spec_draft.md | 149 - .../pre-planning/spec_manifest.md | 323 - .../pre-planning/workstream_triage.md | 243 - .../packs/draft/json-mode/json_mode_plan.md | 106 - .../json-mode/kickoff_prompts/J1-code.md | 41 - .../json-mode/kickoff_prompts/J1-integ.md | 32 - .../json-mode/kickoff_prompts/J1-test.md | 39 - .../json-mode/kickoff_prompts/J2a-code.md | 42 - .../json-mode/kickoff_prompts/J2a-integ.md | 31 - .../json-mode/kickoff_prompts/J2a-test.md | 37 - .../json-mode/kickoff_prompts/J2b-code.md | 43 - .../json-mode/kickoff_prompts/J2b-integ.md | 32 - .../json-mode/kickoff_prompts/J2b-test.md | 40 - .../json-mode/kickoff_prompts/J2c-code.md | 39 - .../json-mode/kickoff_prompts/J2c-integ.md | 32 - .../json-mode/kickoff_prompts/J2c-test.md | 38 - .../json-mode/kickoff_prompts/J3a-code.md | 38 - .../json-mode/kickoff_prompts/J3a-integ.md | 30 - .../json-mode/kickoff_prompts/J3a-test.md | 36 - .../json-mode/kickoff_prompts/J3b-code.md | 42 - .../json-mode/kickoff_prompts/J3b-integ.md | 32 - .../json-mode/kickoff_prompts/J3b-test.md | 37 - .../draft/json-mode/kickoff_prompts/README.md | 8 - .../packs/draft/json-mode/session_log.md | 25 - .../packs/draft/json-mode/tasks.json | 749 - .../compatibility-spec.md | 107 - .../contract.md | 147 - .../execution_preflight_report.md | 101 - .../identity-tuple-schema-spec.md | 158 - .../kickoff_prompts/CP1-ci-checkpoint.md | 28 - .../kickoff_prompts/CP2-ci-checkpoint.md | 28 - .../kickoff_prompts/F0-exec-preflight.md | 44 - .../kickoff_prompts/FZ-feature-cleanup.md | 22 - .../manual_testing_playbook.md | 210 - .../plan.md | 63 - .../platform-parity-spec.md | 114 - .../policy-spec.md | 138 - .../pre-planning/alignment_report.md | 22 - .../pre-planning/ci_checkpoint_plan.md | 101 - .../pre-planning/impact_map.md | 197 - .../pre-planning/minimal_spec_draft.md | 181 - .../pre-planning/spec_manifest.md | 171 - .../pre-planning/workstream_triage.md | 249 - .../quality_gate_report.md | 26 - .../session_log.md | 415 - .../slices/LAITDP0/LAITDP0-closeout_report.md | 75 - .../slices/LAITDP0/LAITDP0-spec.md | 55 - .../LAITDP0/kickoff_prompts/LAITDP0-code.md | 27 - .../LAITDP0/kickoff_prompts/LAITDP0-integ.md | 28 - .../LAITDP0/kickoff_prompts/LAITDP0-test.md | 26 - .../slices/LAITDP1/LAITDP1-closeout_report.md | 58 - .../slices/LAITDP1/LAITDP1-spec.md | 66 - .../LAITDP1/kickoff_prompts/LAITDP1-code.md | 27 - .../kickoff_prompts/LAITDP1-integ-core.md | 26 - .../kickoff_prompts/LAITDP1-integ-linux.md | 26 - .../kickoff_prompts/LAITDP1-integ-macos.md | 26 - .../kickoff_prompts/LAITDP1-integ-windows.md | 27 - .../LAITDP1/kickoff_prompts/LAITDP1-integ.md | 28 - .../LAITDP1/kickoff_prompts/LAITDP1-test.md | 26 - .../slices/LAITDP2/LAITDP2-closeout_report.md | 77 - .../slices/LAITDP2/LAITDP2-spec.md | 61 - .../LAITDP2/kickoff_prompts/LAITDP2-code.md | 27 - .../kickoff_prompts/LAITDP2-integ-core.md | 26 - .../kickoff_prompts/LAITDP2-integ-linux.md | 26 - .../kickoff_prompts/LAITDP2-integ-macos.md | 26 - .../kickoff_prompts/LAITDP2-integ-windows.md | 27 - .../LAITDP2/kickoff_prompts/LAITDP2-integ.md | 28 - .../LAITDP2/kickoff_prompts/LAITDP2-test.md | 26 - .../tasks.json | 1058 - .../telemetry-spec.md | 143 - .../README.md | 34 - .../compatibility-spec.md | 61 - .../contract.md | 56 - .../fse_pre_planning.json | 8 - .../gateway-backend-adapter-protocol-spec.md | 112 - .../gateway-backend-adapter-schema-spec.md | 213 - .../governance/pack-closeout.md | 15 - .../governance/remediation-log.md | 152 - .../governance/seam-1-closeout.md | 60 - .../governance/seam-2-closeout.md | 69 - .../governance/seam-3-closeout.md | 58 - .../manual_testing_playbook.md | 107 - .../platform-parity-spec.md | 70 - .../policy-spec.md | 75 - .../pre-planning/alignment_report.md | 32 - .../pre-planning/ci_checkpoint_plan.md | 144 - .../pre-planning/impact_map.md | 180 - .../pre-planning/minimal_spec_draft.md | 189 - .../pre-planning/spec_manifest.md | 293 - .../pre-planning/workstream_triage.md | 234 - .../review_surfaces.md | 50 - .../scope_brief.md | 59 - .../seam-1-adapter-selection-boundary.md | 139 - .../seam-2-adapter-protocol-and-schema.md | 144 - .../seam-3-parity-and-validation.md | 143 - .../seam_map.md | 114 - .../review.md | 94 - .../seam-1-adapter-selection-boundary/seam.md | 143 - .../slice-00-c-01-c-02-contract-definition.md | 101 - ...lection-evaluation-and-failure-taxonomy.md | 96 - ...us-owner-line-and-adr-authority-cleanup.md | 97 - .../slice-99-seam-exit-gate.md | 58 - .../review.md | 97 - .../seam.md | 162 - .../slice-00-c-03-c-04-contract-definition.md | 118 - ...ice-1-dispatch-lifecycle-and-owner-line.md | 105 - ...subset-and-fail-closed-capability-rules.md | 110 - ...ce-3-adoption-surfaces-and-verification.md | 94 - .../slice-99-seam-exit-gate.md | 62 - .../seam-3-parity-and-validation/review.md | 66 - .../seam-3-parity-and-validation/seam.md | 113 - ...-1-platform-parity-and-runtime-boundary.md | 65 - ...mpatibility-proof-and-adr-0040-decision.md | 67 - ...3-validation-gate-and-checkpoint-bundle.md | 63 - .../slice-99-seam-exit-gate.md | 60 - .../threading.md | 114 - .../README.md | 57 - .../governance/pack-closeout.md | 12 - .../governance/remediation-log.md | 58 - .../governance/seam-1-closeout.md | 69 - .../governance/seam-2-closeout.md | 68 - .../governance/seam-3-closeout.md | 82 - .../governance/seam-4-closeout.md | 61 - .../review_surfaces.md | 56 - .../scope_brief.md | 69 - ...-operator-boundary-and-command-contract.md | 145 - ...us-schema-and-policy-evaluation-surface.md | 147 - ...eam-3-typed-runtime-and-platform-parity.md | 148 - ...seam-4-validation-and-cross-doc-lock-in.md | 150 - .../seam_map.md | 38 - .../review.md | 76 - .../seam.md | 112 - .../slice-00-operator-contract-definition.md | 127 - ...-1-command-family-and-status-entrypoint.md | 102 - ...ce-2-exit-taxonomy-and-wiring-semantics.md | 102 - ...ership-and-archived-drift-normalization.md | 98 - .../slice-99-seam-exit-gate.md | 89 - .../review.md | 77 - .../seam.md | 122 - ...s-schema-and-policy-contract-definition.md | 56 - ...tatus-json-envelope-and-wiring-boundary.md | 54 - ...-2-policy-evaluation-and-trust-boundary.md | 54 - .../slice-99-seam-exit-gate.md | 48 - .../review.md | 74 - .../seam.md | 132 - ...e-00-runtime-parity-contract-definition.md | 134 - ...e-1-typed-lifecycle-status-api-boundary.md | 57 - ...onsumption-and-platform-parity-evidence.md | 58 - .../slice-99-seam-exit-gate.md | 47 - .../review.md | 76 - .../seam.md | 134 - ...nual-validation-and-owner-surface-audit.md | 62 - ...ice-2-operator-docs-and-trace-alignment.md | 64 - ...ce-3-plan-task-and-quality-gate-lock-in.md | 61 - .../slice-99-seam-exit-gate.md | 48 - .../threading.md | 154 - .../contract.md | 70 - .../gateway-status-schema-spec.md | 73 - .../kickoff_prompts/CP1-ci-checkpoint.md | 20 - .../kickoff_prompts/FZ-feature-cleanup.md | 15 - .../manual_testing_playbook.md | 109 - .../plan.md | 47 - .../platform-parity-spec.md | 74 - .../policy-spec.md | 62 - .../pre-planning/alignment_report.md | 31 - .../pre-planning/ci_checkpoint_plan.md | 81 - .../pre-planning/impact_map.md | 271 - .../pre-planning/minimal_spec_draft.md | 89 - .../pre-planning/spec_manifest.md | 258 - .../pre-planning/workstream_triage.md | 231 - .../quality_gate_report.md | 19 - .../session_log.md | 17 - .../slices/SGBRO0/SGBRO0-spec.md | 29 - .../SGBRO0/kickoff_prompts/SGBRO0-code.md | 14 - .../SGBRO0/kickoff_prompts/SGBRO0-integ.md | 14 - .../SGBRO0/kickoff_prompts/SGBRO0-test.md | 14 - .../slices/SGBRO1/SGBRO1-spec.md | 28 - .../SGBRO1/kickoff_prompts/SGBRO1-code.md | 14 - .../SGBRO1/kickoff_prompts/SGBRO1-integ.md | 14 - .../SGBRO1/kickoff_prompts/SGBRO1-test.md | 14 - .../slices/SGBRO2/SGBRO2-spec.md | 28 - .../SGBRO2/kickoff_prompts/SGBRO2-code.md | 14 - .../SGBRO2/kickoff_prompts/SGBRO2-integ.md | 14 - .../SGBRO2/kickoff_prompts/SGBRO2-test.md | 14 - .../slices/SGBRO3/SGBRO3-spec.md | 28 - .../SGBRO3/kickoff_prompts/SGBRO3-code.md | 14 - .../SGBRO3/kickoff_prompts/SGBRO3-integ.md | 14 - .../SGBRO3/kickoff_prompts/SGBRO3-test.md | 14 - .../slices/SGBRO4/SGBRO4-spec.md | 30 - .../SGBRO4/kickoff_prompts/SGBRO4-code.md | 14 - .../kickoff_prompts/SGBRO4-integ-core.md | 14 - .../kickoff_prompts/SGBRO4-integ-linux.md | 14 - .../kickoff_prompts/SGBRO4-integ-macos.md | 14 - .../kickoff_prompts/SGBRO4-integ-windows.md | 14 - .../SGBRO4/kickoff_prompts/SGBRO4-integ.md | 14 - .../SGBRO4/kickoff_prompts/SGBRO4-test.md | 14 - .../tasks.json | 1040 - .../world-deps-apt-provisioning/contract.md | 20 - .../packs/implemented/.gitkeep | 2 - .../README.md | 69 - .../contract.md | 247 - .../decision_register.md | 113 - .../governance/pack-closeout.md | 28 - .../governance/remediation-log.md | 82 - .../governance/seam-1-closeout.md | 48 - .../governance/seam-2-closeout.md | 57 - .../governance/seam-3-closeout.md | 62 - .../governance/seam-4-closeout.md | 71 - .../governance/seam-5-closeout.md | 74 - .../governance/seam-6-closeout.md | 58 - .../review_surfaces.md | 79 - .../scope_brief.md | 65 - .../seam-1-manager-aware-contract-surface.md | 132 - ...seam-2-world-manager-probe-support-gate.md | 125 - .../seam-3-pacman-schema-inventory-views.md | 127 - ...4-provisioning-routing-pacman-execution.md | 132 - .../seam-5-runtime-fail-early-remediation.md | 127 - ...dation-evidence-contract-reconciliation.md | 135 - .../seam_map.md | 194 - .../review.md | 78 - .../seam.md | 117 - .../slice-1-c-01-contract-definition.md | 118 - ...slice-2-authority-handoff-and-decisions.md | 105 - .../slice-3-seam-exit-gate.md | 60 - .../review.md | 82 - .../seam.md | 122 - .../slice-1-c-02-contract-definition.md | 140 - ...orld-probe-and-support-gate-integration.md | 118 - .../slice-3-seam-exit-gate.md | 69 - .../review.md | 78 - .../seam.md | 122 - ...slice-1-c-03-schema-contract-definition.md | 83 - ...inventory-validation-and-view-rendering.md | 96 - .../slice-3-seam-exit-gate.md | 69 - .../review.md | 79 - .../seam.md | 124 - ...1-c-04-provisioning-contract-definition.md | 88 - ...ovisioning-routing-and-pacman-execution.md | 92 - .../slice-3-seam-exit-gate.md | 71 - .../review.md | 78 - .../seam.md | 127 - ...-runtime-fail-early-contract-definition.md | 83 - ...ce-2-runtime-fail-early-and-remediation.md | 96 - .../slice-3-seam-exit-gate.md | 71 - .../review.md | 94 - .../seam.md | 134 - ...1-platform-parity-and-playbook-evidence.md | 94 - ...aces-and-shared-contract-reconciliation.md | 98 - .../slice-3-seam-exit-gate.md | 59 - .../threading.md | 238 - .../contract.md | 205 - .../decision_register.md | 154 - .../kickoff_prompts/CP1-ci-checkpoint.md | 22 - .../kickoff_prompts/CP2-ci-checkpoint.md | 22 - .../kickoff_prompts/FZ-feature-cleanup.md | 21 - .../manual_testing_playbook.md | 397 - .../plan.md | 64 - .../platform-parity-spec.md | 103 - .../pre-planning/alignment_report.md | 27 - .../pre-planning/ci_checkpoint_plan.md | 123 - .../pre-planning/impact_map.md | 259 - .../pre-planning/minimal_spec_draft.md | 106 - .../pre-planning/spec_manifest.md | 368 - .../pre-planning/workstream_triage.md | 429 - .../quality_gate_report.md | 33 - .../session_log.md | 18 - .../slices/NASP0/NASP0-spec.md | 95 - .../NASP0/kickoff_prompts/NASP0-code.md | 21 - .../NASP0/kickoff_prompts/NASP0-integ.md | 21 - .../NASP0/kickoff_prompts/NASP0-test.md | 20 - .../slices/NASP1/NASP1-spec.md | 96 - .../NASP1/kickoff_prompts/NASP1-code.md | 21 - .../NASP1/kickoff_prompts/NASP1-integ.md | 21 - .../NASP1/kickoff_prompts/NASP1-test.md | 20 - .../slices/NASP2/NASP2-spec.md | 124 - .../NASP2/kickoff_prompts/NASP2-code.md | 21 - .../NASP2/kickoff_prompts/NASP2-integ-core.md | 22 - .../kickoff_prompts/NASP2-integ-linux.md | 22 - .../kickoff_prompts/NASP2-integ-macos.md | 22 - .../kickoff_prompts/NASP2-integ-windows.md | 22 - .../NASP2/kickoff_prompts/NASP2-integ.md | 22 - .../NASP2/kickoff_prompts/NASP2-test.md | 20 - .../slices/NASP3/NASP3-spec.md | 125 - .../NASP3/kickoff_prompts/NASP3-code.md | 21 - .../NASP3/kickoff_prompts/NASP3-integ.md | 21 - .../NASP3/kickoff_prompts/NASP3-test.md | 20 - .../slices/NASP4/NASP4-spec.md | 97 - .../NASP4/kickoff_prompts/NASP4-code.md | 21 - .../NASP4/kickoff_prompts/NASP4-integ-core.md | 22 - .../kickoff_prompts/NASP4-integ-linux.md | 22 - .../kickoff_prompts/NASP4-integ-macos.md | 22 - .../kickoff_prompts/NASP4-integ-windows.md | 22 - .../NASP4/kickoff_prompts/NASP4-integ.md | 22 - .../NASP4/kickoff_prompts/NASP4-test.md | 20 - .../smoke/linux-smoke.sh | 175 - .../smoke/macos-smoke.sh | 188 - .../smoke/windows-smoke.ps1 | 197 - .../tasks.json | 1416 - .../world-deps-pacman-schema-spec.md | 190 - .../OR0-closeout_report.md | 84 - .../OR0-spec.md | 68 - .../OR1-closeout_report.md | 62 - .../OR1-spec.md | 100 - .../agent-hub-event-envelope-schema-spec.md | 316 - .../ci_checkpoint_plan.md | 56 - .../contract.md | 141 - .../decision_register.md | 810 - .../execution_preflight_report.md | 128 - .../impact_map.md | 174 - .../kickoff_prompts/CP1-ci-checkpoint.md | 52 - .../kickoff_prompts/F0-exec-preflight.md | 39 - .../kickoff_prompts/FZ-feature-cleanup.md | 31 - .../kickoff_prompts/OR0-code.md | 33 - .../kickoff_prompts/OR0-integ.md | 32 - .../kickoff_prompts/OR0-test.md | 33 - .../kickoff_prompts/OR1-code.md | 33 - .../kickoff_prompts/OR1-integ-core.md | 40 - .../kickoff_prompts/OR1-integ-linux.md | 39 - .../kickoff_prompts/OR1-integ-macos.md | 39 - .../kickoff_prompts/OR1-integ-windows.md | 39 - .../kickoff_prompts/OR1-integ.md | 37 - .../kickoff_prompts/OR1-test.md | 34 - .../manual_testing_playbook.md | 159 - .../plan.md | 70 - .../platform-parity-spec.md | 59 - .../quality_gate_report.md | 121 - .../session_log.md | 408 - .../smoke/linux-smoke.sh | 137 - .../smoke/macos-smoke.sh | 117 - .../smoke/windows-smoke.ps1 | 68 - .../spec_manifest.md | 71 - .../tasks.json | 636 - .../telemetry-spec.md | 120 - .../README.md | 30 - .../governance/pack-closeout.md | 19 - .../governance/remediation-log.md | 59 - .../governance/seam-01-closeout.md | 51 - .../governance/seam-02-closeout.md | 53 - .../governance/seam-03-closeout.md | 57 - .../governance/seam-04-closeout.md | 58 - .../governance/seam-05-closeout.md | 58 - .../governance/seam-06-closeout.md | 63 - .../governance/seam-07-closeout.md | 61 - .../review_surfaces.md | 85 - .../scope_brief.md | 66 - .../seam-01-os-release-input-parser.md | 173 - .../seam-02-family-mapping-reporting.md | 172 - .../seam-03-explicit-override-selection.md | 174 - ...seam-04-fallback-probe-failure-taxonomy.md | 171 - .../seam-05-wrapper-doc-propagation.md | 175 - .../seam-06-validation-evidence-topology.md | 178 - .../seam-07-checkpoint-downstream-handoff.md | 172 - .../seam_map.md | 69 - .../seam-01-os-release-input-parser/review.md | 76 - .../seam-01-os-release-input-parser/seam.md | 117 - ...lice-1-parser-input-contract-definition.md | 130 - .../slice-2-selected-input-resolution.md | 80 - .../slice-3-safe-parser-normalized-fields.md | 83 - .../slice-4-seam-exit-gate.md | 80 - .../review.md | 75 - .../seam-02-family-mapping-reporting/seam.md | 120 - ...e-1-family-table-availability-selection.md | 73 - ...lice-2-decision-line-contract-rendering.md | 72 - .../slice-3-seam-exit-gate.md | 55 - .../review.md | 79 - .../seam.md | 133 - .../slice-1-flag-selector-precedence.md | 72 - .../slice-2-env-selector-selection.md | 71 - .../slice-3-explicit-failure-taxonomy.md | 71 - .../slice-4-seam-exit-gate.md | 55 - .../review.md | 81 - .../seam.md | 130 - .../slice-1-path-probe-selection.md | 74 - .../slice-2-multi-manager-warning-line.md | 68 - .../slice-3-no-manager-exit-4.md | 70 - .../slice-4-seam-exit-gate.md | 54 - .../seam-05-wrapper-doc-propagation/review.md | 66 - .../seam-05-wrapper-doc-propagation/seam.md | 131 - .../slice-1-wrapper-exit-pass-through.md | 50 - ...2-installation-doc-contract-propagation.md | 52 - ...lice-3-env-and-macos-hosted-doc-clarity.md | 51 - .../slice-4-seam-exit-gate.md | 42 - .../review.md | 69 - .../seam.md | 143 - ...repo-harness-and-smoke-wrapper-topology.md | 59 - ...-evidence-and-macos-hosted-verification.md | 56 - .../slice-3-seam-exit-gate.md | 40 - .../review.md | 66 - .../seam.md | 121 - ...slice-1-checkpoint-evidence-aggregation.md | 58 - .../slice-2-macos-hosted-behavior-evidence.md | 59 - .../slice-3-downstream-handoff-publication.md | 67 - .../slice-4-pack-closeout-alignment.md | 47 - .../slice-5-seam-exit-gate.md | 46 - .../threading.md | 237 - .../contract.md | 257 - .../decision_register.md | 382 - .../kickoff_prompts/CP1-ci-checkpoint.md | 29 - .../kickoff_prompts/FZ-feature-cleanup.md | 23 - .../manual_testing_playbook.md | 402 - .../plan.md | 64 - .../pre-planning/alignment_report.md | 29 - .../pre-planning/ci_checkpoint_plan.md | 96 - .../pre-planning/impact_map.md | 325 - .../pre-planning/minimal_spec_draft.md | 105 - .../pre-planning/spec_manifest.md | 473 - .../pre-planning/workstream_triage.md | 249 - .../quality_gate_report.md | 338 - .../session_log.md | 115 - .../slices/BEDPM0/BEDPM0-spec.md | 50 - .../BEDPM0/kickoff_prompts/BEDPM0-code.md | 24 - .../BEDPM0/kickoff_prompts/BEDPM0-integ.md | 22 - .../BEDPM0/kickoff_prompts/BEDPM0-test.md | 22 - .../slices/BEDPM1/BEDPM1-spec.md | 48 - .../BEDPM1/kickoff_prompts/BEDPM1-code.md | 24 - .../BEDPM1/kickoff_prompts/BEDPM1-integ.md | 22 - .../BEDPM1/kickoff_prompts/BEDPM1-test.md | 22 - .../slices/BEDPM2/BEDPM2-spec.md | 50 - .../BEDPM2/kickoff_prompts/BEDPM2-code.md | 24 - .../BEDPM2/kickoff_prompts/BEDPM2-integ.md | 22 - .../BEDPM2/kickoff_prompts/BEDPM2-test.md | 22 - .../slices/BEDPM3/BEDPM3-spec.md | 64 - .../BEDPM3/kickoff_prompts/BEDPM3-code.md | 24 - .../kickoff_prompts/BEDPM3-integ-core.md | 22 - .../kickoff_prompts/BEDPM3-integ-linux.md | 26 - .../kickoff_prompts/BEDPM3-integ-macos.md | 23 - .../kickoff_prompts/BEDPM3-integ-windows.md | 23 - .../BEDPM3/kickoff_prompts/BEDPM3-integ.md | 26 - .../BEDPM3/kickoff_prompts/BEDPM3-test.md | 22 - .../smoke/linux-smoke.sh | 19 - .../tasks.json | 924 - .../README.md | 33 - .../governance/pack-closeout.md | 11 - .../governance/remediation-log.md | 74 - .../governance/seam-1-closeout.md | 62 - .../governance/seam-2-closeout.md | 59 - .../governance/seam-3-closeout.md | 60 - .../review_surfaces.md | 81 - .../scope_brief.md | 65 - ...dir-preflight-deterministic-remediation.md | 121 - ...linux-dev-install-world-service-staging.md | 119 - ...-cross-platform-validation-drift-guards.md | 124 - .../seam_map.md | 45 - .../review.md | 77 - .../seam.md | 109 - ...1-contract-definition-runtime-preflight.md | 113 - .../slice-2-preflight-and-dry-run-parity.md | 93 - .../slice-3-remediation-and-state-ordering.md | 108 - .../slice-4-seam-exit-gate.md | 58 - .../review.md | 72 - .../seam.md | 118 - ...ice-1-c-04-contract-and-installer-scope.md | 79 - ...ce-2-linux-staging-and-refresh-behavior.md | 78 - .../slice-3-seam-exit-gate.md | 60 - .../review.md | 76 - .../seam.md | 124 - ...ract-revalidation-and-evidence-boundary.md | 64 - ...linux-proof-checkpoint-and-drift-guards.md | 67 - .../slice-3-seam-exit-gate.md | 62 - .../threading.md | 130 - .../contract.md | 149 - .../decision_register.md | 98 - .../kickoff_prompts/CP1-ci-checkpoint.md | 35 - .../kickoff_prompts/FZ-feature-cleanup.md | 31 - .../manual_testing_playbook.md | 88 - .../dev-install-world-service-staging/plan.md | 77 - .../platform-parity-spec.md | 67 - .../pre-planning/alignment_report.md | 27 - .../pre-planning/ci_checkpoint_plan.md | 79 - .../pre-planning/impact_map.md | 207 - .../pre-planning/minimal_spec_draft.md | 102 - .../pre-planning/spec_manifest.md | 283 - .../pre-planning/workstream_triage.md | 273 - .../quality_gate_report.md | 23 - .../session_log.md | 46 - .../slices/DIWAS0/DIWAS0-spec.md | 49 - .../DIWAS0/kickoff_prompts/DIWAS0-code.md | 31 - .../DIWAS0/kickoff_prompts/DIWAS0-integ.md | 23 - .../DIWAS0/kickoff_prompts/DIWAS0-test.md | 30 - .../slices/DIWAS1/DIWAS1-spec.md | 39 - .../DIWAS1/kickoff_prompts/DIWAS1-code.md | 27 - .../kickoff_prompts/DIWAS1-integ-core.md | 25 - .../kickoff_prompts/DIWAS1-integ-linux.md | 21 - .../kickoff_prompts/DIWAS1-integ-macos.md | 20 - .../kickoff_prompts/DIWAS1-integ-windows.md | 20 - .../DIWAS1/kickoff_prompts/DIWAS1-integ.md | 27 - .../DIWAS1/kickoff_prompts/DIWAS1-test.md | 28 - .../smoke/linux-smoke.sh | 103 - .../tasks.json | 624 - .../README.md | 48 - .../governance/pack-closeout.md | 11 - .../governance/remediation-log.md | 36 - .../governance/seam-1-closeout.md | 94 - .../governance/seam-2-closeout.md | 83 - .../governance/seam-3-closeout.md | 93 - .../review_surfaces.md | 80 - .../scope_brief.md | 54 - .../seam-1-execution-contract-surfaces.md | 99 - ...-2-interactive-terminal-loss-resilience.md | 99 - ...3-cross-surface-parity-and-drift-guards.md | 96 - .../seam_map.md | 33 - .../review.md | 81 - .../seam.md | 90 - ...routing-and-tracing-contract-definition.md | 136 - .../slice-1-replay-routing-parity.md | 97 - .../slice-2-tracing-behavior-matrix.md | 104 - .../slice-3-contract-publication-surfaces.md | 92 - .../slice-99-seam-exit-gate.md | 91 - .../review.md | 77 - .../seam.md | 90 - ...ormal-terminal-loss-contract-definition.md | 115 - ...e-1-prompt-worker-unwind-and-exit-cause.md | 97 - .../slice-2-macos-revoke-regression-proof.md | 98 - ...e-3-exit-semantics-publication-surfaces.md | 90 - .../slice-99-seam-exit-gate.md | 90 - .../review.md | 57 - .../seam.md | 78 - .../slice-1-cross-surface-doc-lock-in.md | 46 - ...ice-2-wpep-playbook-and-smoke-alignment.md | 46 - .../slice-3-regression-and-drift-guards.md | 46 - .../slice-99-seam-exit-gate.md | 47 - .../threading.md | 119 - .../LACP0-spec.md | 53 - .../LACP1-spec.md | 69 - .../SCHEMA.md | 267 - .../ci_checkpoint_plan.md | 56 - .../contract.md | 144 - .../decision_register.md | 708 - .../impact_map.md | 171 - .../kickoff_prompts/CP1-ci-checkpoint.md | 31 - .../kickoff_prompts/F0-exec-preflight.md | 23 - .../kickoff_prompts/FZ-feature-cleanup.md | 22 - .../kickoff_prompts/LACP0-code.md | 29 - .../kickoff_prompts/LACP0-integ.md | 29 - .../kickoff_prompts/LACP0-test.md | 25 - .../kickoff_prompts/LACP1-code.md | 27 - .../kickoff_prompts/LACP1-integ-core.md | 28 - .../kickoff_prompts/LACP1-integ-linux.md | 25 - .../kickoff_prompts/LACP1-integ-macos.md | 25 - .../kickoff_prompts/LACP1-integ.md | 23 - .../kickoff_prompts/LACP1-test.md | 25 - .../kickoff_prompts/README.md | 7 - .../manual_testing_playbook.md | 69 - .../plan.md | 51 - .../quality_gate_report.md | 406 - .../session_log.md | 72 - .../smoke/_core.sh | 180 - .../smoke/linux-smoke.sh | 18 - .../smoke/macos-smoke.sh | 18 - .../smoke/windows-smoke.ps1 | 83 - .../spec_manifest.md | 88 - .../tasks.json | 418 - .../README.md | 31 - .../governance/pack-closeout.md | 10 - .../governance/remediation-log.md | 30 - .../governance/seam-1-closeout.md | 55 - .../governance/seam-2-closeout.md | 55 - .../review_surfaces.md | 52 - .../scope_brief.md | 59 - .../seam-1-doctor-text-disable-attribution.md | 114 - .../seam-2-json-health-disable-attribution.md | 112 - .../seam_map.md | 45 - .../review.md | 71 - .../seam.md | 103 - ...contract-definition-disable-attribution.md | 101 - ...-shared-helper-and-winner-mapping-tests.md | 75 - ...-wire-doctor-output-and-parity-evidence.md | 76 - .../slice-4-seam-exit-gate.md | 48 - .../review.md | 71 - .../seam.md | 121 - ...inition-json-health-disable-attribution.md | 122 - ...-doctor-json-top-level-schema-and-tests.md | 78 - ...ealth-parity-and-disabled-path-plumbing.md | 79 - .../slice-4-seam-exit-gate.md | 62 - .../threading.md | 90 - .../pre-planning/alignment_report.md | 33 - .../pre-planning/ci_checkpoint_plan.md | 100 - .../pre-planning/impact_map.md | 184 - .../pre-planning/minimal_spec_draft.md | 128 - .../pre-planning/spec_manifest.md | 329 - .../pre-planning/workstream_triage.md | 189 - .../tasks.json | 30 - .../README.md | 22 - .../governance/pack-closeout.md | 33 - .../governance/remediation-log.md | 128 - .../governance/seam-1-closeout.md | 69 - .../governance/seam-2-closeout.md | 71 - .../governance/seam-3-closeout.md | 65 - .../governance/seam-4-closeout.md | 69 - .../governance/seam-5-closeout.md | 73 - .../review_surfaces.md | 54 - .../scope_brief.md | 48 - ...am-1-snapshot-v3-net-allowlist-plumbing.md | 99 - ...ilter-fail-closed-and-cgroup-invariants.md | 111 - ...t-config-opt-in-and-parity-env-plumbing.md | 94 - ...d-doctor-netfilter-status-observability.md | 91 - ...am-5-verification-and-smoke-conformance.md | 93 - .../seam_map.md | 17 - .../review.md | 96 - .../seam.md | 116 - .../slice-1-publish-net-allowed-contract.md | 91 - ...-2-host-snapshot-and-worldspec-plumbing.md | 127 - .../slice-3-world-service-snapshot-routing.md | 75 - .../slice-4-seam-exit-gate.md | 53 - .../review.md | 85 - .../seam.md | 125 - .../slice-1-fail-closed-netfilter-runtime.md | 97 - ...oup-attach-invariants-across-exec-paths.md | 93 - .../slice-3-seam-exit-gate.md | 56 - .../review.md | 89 - .../seam.md | 110 - ...ublish-world-net-filter-config-contract.md | 58 - ...lice-2-override-and-parity-env-plumbing.md | 60 - ...ice-3-operator-docs-and-routing-handoff.md | 62 - .../slice-4-seam-exit-gate.md | 53 - .../review.md | 86 - .../seam.md | 136 - ...ice-1-publish-netfilter-status-contract.md | 104 - ...time-failure-state-into-doctor-surfaces.md | 99 - .../slice-3-seam-exit-gate.md | 53 - .../review.md | 95 - .../seam.md | 132 - ...matrix-for-routing-and-doctor-contracts.md | 110 - ...-privileged-and-macos-smoke-conformance.md | 103 - .../slice-3-seam-exit-gate.md | 58 - .../threading.md | 148 - .../README.md | 54 - .../governance/pack-closeout.md | 20 - .../governance/remediation-log.md | 79 - .../governance/seam-1-closeout.md | 55 - .../governance/seam-2-closeout.md | 52 - .../governance/seam-3-closeout.md | 56 - .../review_surfaces.md | 76 - .../scope_brief.md | 70 - ...-1-persisted-platform-metadata-contract.md | 129 - ...seam-2-install-state-writer-reliability.md | 125 - .../seam-3-smoke-and-operator-conformance.md | 125 - .../seam_map.md | 103 - .../review.md | 79 - .../seam.md | 116 - ...e-1-persisted-schema-and-merge-contract.md | 132 - ...2-canonical-path-and-authority-boundary.md | 119 - .../slice-3-seam-exit-gate.md | 96 - .../review.md | 81 - .../seam.md | 117 - ...ux-write-matrix-and-no-write-boundaries.md | 102 - ...ic-replace-and-warning-only-degradation.md | 106 - .../slice-3-seam-exit-gate.md | 58 - .../review.md | 79 - .../seam.md | 126 - ...inux-smoke-conformance-and-drift-guards.md | 104 - ...r-doc-and-checkpoint-evidence-alignment.md | 107 - .../slice-3-seam-exit-gate.md | 59 - .../threading.md | 162 - .../contract.md | 123 - .../decision_register.md | 206 - .../install-state-schema-spec.md | 191 - .../kickoff_prompts/CP1-ci-checkpoint.md | 51 - .../kickoff_prompts/FZ-feature-cleanup.md | 20 - .../plan.md | 83 - .../pre-planning/alignment_report.md | 34 - .../pre-planning/ci_checkpoint_plan.md | 101 - .../pre-planning/impact_map.md | 243 - .../pre-planning/minimal_spec_draft.md | 105 - .../pre-planning/spec_manifest.md | 327 - .../pre-planning/workstream_triage.md | 354 - .../session_log.md | 73 - .../slices/PDLDPM0/PDLDPM0-spec.md | 69 - .../PDLDPM0/kickoff_prompts/PDLDPM0-code.md | 26 - .../PDLDPM0/kickoff_prompts/PDLDPM0-integ.md | 26 - .../PDLDPM0/kickoff_prompts/PDLDPM0-test.md | 24 - .../slices/PDLDPM1/PDLDPM1-spec.md | 59 - .../PDLDPM1/kickoff_prompts/PDLDPM1-code.md | 26 - .../PDLDPM1/kickoff_prompts/PDLDPM1-integ.md | 26 - .../PDLDPM1/kickoff_prompts/PDLDPM1-test.md | 24 - .../slices/PDLDPM2/PDLDPM2-spec.md | 60 - .../PDLDPM2/kickoff_prompts/PDLDPM2-code.md | 26 - .../kickoff_prompts/PDLDPM2-integ-core.md | 26 - .../kickoff_prompts/PDLDPM2-integ-linux.md | 36 - .../kickoff_prompts/PDLDPM2-integ-macos.md | 26 - .../kickoff_prompts/PDLDPM2-integ-windows.md | 26 - .../PDLDPM2/kickoff_prompts/PDLDPM2-integ.md | 26 - .../PDLDPM2/kickoff_prompts/PDLDPM2-test.md | 24 - .../tasks.json | 879 - .../README.md | 33 - .../contract.md | 94 - .../decision_register.md | 167 - .../governance/pack-closeout.md | 11 - .../governance/remediation-log.md | 83 - .../governance/seam-1-closeout.md | 61 - .../governance/seam-2-closeout.md | 62 - .../governance/seam-3-closeout.md | 68 - .../manual_testing_playbook.md | 69 - .../platform-parity-spec.md | 66 - .../review_surfaces.md | 79 - .../scope_brief.md | 60 - ...durable-helper-bundle-staging-discovery.md | 104 - ...-2-managed-cleanup-protected-path-guard.md | 109 - ...eam-3-cross-platform-proof-drift-guards.md | 116 - .../seam_map.md | 44 - .../smoke/linux-smoke.sh | 70 - .../smoke/macos-smoke.sh | 66 - .../smoke/windows-smoke.ps1 | 41 - .../review.md | 90 - .../seam.md | 123 - ...slice-1-freeze-durable-bundle-contracts.md | 133 - ...ce-2-dev-install-durable-bundle-staging.md | 98 - ...er-discovery-and-fail-closed-validation.md | 90 - .../slice-4-seam-exit-gate.md | 83 - .../review.md | 75 - .../seam.md | 116 - .../slice-1-managed-only-cleanup-contract.md | 55 - ...-2-protected-path-refusal-and-reporting.md | 58 - .../slice-3-seam-exit-gate.md | 72 - .../review.md | 78 - .../seam.md | 130 - ...e-1-freeze-platform-evidence-boundaries.md | 103 - ...2-refresh-cross-platform-proof-surfaces.md | 105 - .../slice-3-seam-exit-gate.md | 73 - .../threading.md | 126 - .../alignment_report.md | 26 - .../pre-planning/alignment_report.md | 26 - .../pre-planning/ci_checkpoint_plan.md | 72 - .../pre-planning/impact_map.md | 181 - .../pre-planning/minimal_spec_draft.md | 138 - .../pre-planning/spec_manifest.md | 213 - .../pre-planning/workstream_triage.md | 120 - .../tasks.json | 25 - .../world-deps-apt-provisioning/contract.md | 152 - .../decision_register.md | 118 - .../kickoff_prompts/CP1-ci-checkpoint.md | 64 - .../kickoff_prompts/CP2-ci-checkpoint.md | 73 - .../kickoff_prompts/FZ-feature-cleanup.md | 33 - .../manual_testing_playbook.md | 447 - .../world-deps-apt-provisioning/plan.md | 52 - .../pre-planning/alignment_report.md | 42 - .../pre-planning/ci_checkpoint_plan.md | 115 - .../pre-planning/impact_map.md | 319 - .../pre-planning/minimal_spec_draft.md | 130 - .../pre-planning/spec_manifest.md | 163 - .../pre-planning/workstream_triage.md | 239 - .../quality_gate_report.md | 134 - .../session_log.md | 297 - .../slices/WDAP0/WDAP0-spec.md | 147 - .../WDAP0/kickoff_prompts/WDAP0-code.md | 33 - .../WDAP0/kickoff_prompts/WDAP0-integ-core.md | 74 - .../kickoff_prompts/WDAP0-integ-linux.md | 37 - .../kickoff_prompts/WDAP0-integ-macos.md | 37 - .../kickoff_prompts/WDAP0-integ-windows.md | 37 - .../WDAP0/kickoff_prompts/WDAP0-integ.md | 44 - .../WDAP0/kickoff_prompts/WDAP0-test.md | 28 - .../slices/WDAP1/WDAP1-spec.md | 128 - .../WDAP1/kickoff_prompts/WDAP1-code.md | 33 - .../WDAP1/kickoff_prompts/WDAP1-integ-core.md | 74 - .../kickoff_prompts/WDAP1-integ-linux.md | 36 - .../kickoff_prompts/WDAP1-integ-macos.md | 37 - .../kickoff_prompts/WDAP1-integ-windows.md | 37 - .../WDAP1/kickoff_prompts/WDAP1-integ.md | 44 - .../WDAP1/kickoff_prompts/WDAP1-test.md | 28 - .../smoke/linux-smoke.sh | 193 - .../smoke/macos-smoke.sh | 261 - .../smoke/windows-smoke.ps1 | 232 - .../world-deps-apt-provisioning/tasks.json | 934 - .../WDH0-spec.md | 94 - .../WDH1-spec.md | 63 - .../WDH2-spec.md | 67 - .../WDH3-spec.md | 71 - .../ci_checkpoint_plan.md | 82 - .../decision_register.md | 403 - .../impact_map.md | 106 - .../kickoff_prompts/CP1-ci-checkpoint.md | 12 - .../kickoff_prompts/CP2-ci-checkpoint.md | 12 - .../kickoff_prompts/F0-exec-preflight.md | 17 - .../kickoff_prompts/FZ-feature-cleanup.md | 11 - .../kickoff_prompts/WDH0-code.md | 12 - .../kickoff_prompts/WDH0-integ.md | 9 - .../kickoff_prompts/WDH0-test.md | 10 - .../kickoff_prompts/WDH1-code.md | 9 - .../kickoff_prompts/WDH1-integ-core.md | 20 - .../kickoff_prompts/WDH1-integ-linux.md | 15 - .../kickoff_prompts/WDH1-integ-macos.md | 15 - .../kickoff_prompts/WDH1-integ-windows.md | 15 - .../kickoff_prompts/WDH1-integ.md | 13 - .../kickoff_prompts/WDH1-test.md | 9 - .../kickoff_prompts/WDH2-code.md | 9 - .../kickoff_prompts/WDH2-integ.md | 9 - .../kickoff_prompts/WDH2-test.md | 9 - .../kickoff_prompts/WDH3-code.md | 9 - .../kickoff_prompts/WDH3-integ-core.md | 20 - .../kickoff_prompts/WDH3-integ-linux.md | 15 - .../kickoff_prompts/WDH3-integ-macos.md | 15 - .../kickoff_prompts/WDH3-integ-windows.md | 15 - .../kickoff_prompts/WDH3-integ.md | 13 - .../kickoff_prompts/WDH3-test.md | 9 - .../manual_testing_playbook.md | 133 - .../world-deps-host-visible-hardening/plan.md | 58 - .../quality_gate_report.md | 921 - .../session_log.md | 380 - .../smoke/_core.sh | 183 - .../smoke/linux-smoke.sh | 18 - .../smoke/macos-smoke.sh | 18 - .../smoke/windows-smoke.ps1 | 30 - .../spec_manifest.md | 61 - .../tasks.json | 864 - .../WDP0-closeout_report.md | 50 - .../WDP0-spec.md | 40 - .../WDP1-closeout_report.md | 50 - .../WDP1-spec.md | 31 - .../WDP2-closeout_report.md | 66 - .../WDP2-spec.md | 28 - .../WDP3-closeout_report.md | 64 - .../WDP3-spec.md | 26 - .../WDP4-closeout_report.md | 61 - .../WDP4-spec.md | 25 - .../WDP5-closeout_report.md | 69 - .../WDP5-spec.md | 23 - .../ci_checkpoint_plan.md | 82 - .../contract.md | 560 - .../decision_register.md | 118 - .../deps_examples/README.md | 14 - .../deps_examples/bundles/node-runtime.yaml | 5 - .../deps_examples/packages/asdf-node.yaml | 23 - .../deps_examples/packages/bun.yaml | 11 - .../deps_examples/packages/direnv.yaml | 14 - .../deps_examples/packages/nftables.yaml | 13 - .../deps_examples/packages/node.yaml | 12 - .../deps_examples/packages/npm.yaml | 12 - .../deps_examples/packages/nvm.yaml | 16 - .../packages/python-build-deps.yaml | 20 - .../deps_examples/packages/volta.yaml | 11 - .../deps_examples/scripts/bun.sh | 22 - .../deps_examples/scripts/nvm.sh | 15 - .../deps_examples/scripts/volta.sh | 25 - .../execution_preflight_report.md | 74 - .../impact_map.md | 145 - .../kickoff_prompts/CP1-ci-checkpoint.md | 67 - .../kickoff_prompts/CP2-ci-checkpoint.md | 67 - .../kickoff_prompts/F0-exec-preflight.md | 39 - .../kickoff_prompts/FZ-feature-cleanup.md | 33 - .../kickoff_prompts/WDP0-code.md | 36 - .../kickoff_prompts/WDP0-integ.md | 38 - .../kickoff_prompts/WDP0-test.md | 31 - .../kickoff_prompts/WDP1-code.md | 34 - .../kickoff_prompts/WDP1-integ.md | 38 - .../kickoff_prompts/WDP1-test.md | 31 - .../kickoff_prompts/WDP2-code.md | 29 - .../kickoff_prompts/WDP2-integ-core.md | 31 - .../kickoff_prompts/WDP2-integ-linux.md | 28 - .../kickoff_prompts/WDP2-integ-macos.md | 27 - .../kickoff_prompts/WDP2-integ.md | 33 - .../kickoff_prompts/WDP2-test.md | 28 - .../kickoff_prompts/WDP3-code.md | 26 - .../kickoff_prompts/WDP3-integ.md | 25 - .../kickoff_prompts/WDP3-test.md | 24 - .../kickoff_prompts/WDP4-code.md | 24 - .../kickoff_prompts/WDP4-integ.md | 25 - .../kickoff_prompts/WDP4-test.md | 24 - .../kickoff_prompts/WDP5-code.md | 24 - .../kickoff_prompts/WDP5-integ-core.md | 29 - .../kickoff_prompts/WDP5-integ-linux.md | 28 - .../kickoff_prompts/WDP5-integ-macos.md | 27 - .../kickoff_prompts/WDP5-integ.md | 33 - .../kickoff_prompts/WDP5-test.md | 24 - .../manual_testing_playbook.md | 138 - .../plan.md | 66 - .../platform-parity-spec.md | 36 - .../quality_gate_report.md | 420 - .../session_log.md | 355 - .../smoke/_core.sh | 274 - .../smoke/linux-smoke.sh | 18 - .../smoke/macos-smoke.sh | 18 - .../spec_manifest.md | 77 - .../tasks.json | 1341 - .../world-disabled-diagnostics-fse/README.md | 27 - .../governance/pack-closeout.md | 26 - .../governance/remediation-log.md | 35 - .../governance/seam-1-closeout.md | 69 - .../governance/seam-2-closeout.md | 74 - .../governance/seam-3-closeout.md | 65 - .../governance/seam-4-closeout.md | 102 - .../review_surfaces.md | 50 - .../scope_brief.md | 60 - .../seam-1-effective-config-classifier.md | 101 - ...-2-shim-doctor-disabled-aware-reporting.md | 107 - .../seam-3-health-disabled-aware-summary.md | 98 - .../seam-4-cross-platform-conformance.md | 102 - .../seam_map.md | 60 - .../review.md | 75 - .../seam.md | 87 - .../slice-1-contract-definition-c-01.md | 100 - .../slice-2-integrate-classifier-and-tests.md | 112 - .../slice-3-seam-exit-gate.md | 80 - .../review.md | 78 - .../seam.md | 89 - ...ce-1-contract-definition-c-02-c-03-c-04.md | 96 - ...ice-2-disabled-path-rendering-and-tests.md | 97 - .../slice-3-seam-exit-gate.md | 71 - .../review.md | 72 - .../seam.md | 94 - .../slice-1-contract-definition-c-05.md | 87 - ...slice-2-disabled-summary-docs-and-tests.md | 94 - .../slice-3-seam-exit-gate.md | 69 - .../review.md | 69 - .../seam-4-cross-platform-conformance/seam.md | 92 - .../slice-1-platform-matrix-and-playbook.md | 74 - ...ice-2-smoke-checkpoint-and-revalidation.md | 79 - .../slice-3-seam-exit-gate.md | 68 - .../threading.md | 184 - .../world-disabled-diagnostics/contract.md | 106 - .../decision_register.md | 138 - .../kickoff_prompts/CP1-ci-checkpoint.md | 63 - .../kickoff_prompts/FZ-feature-cleanup.md | 32 - .../manual_testing_playbook.md | 243 - .../world-disabled-diagnostics/plan.md | 44 - .../pre-planning/alignment_report.md | 38 - .../pre-planning/ci_checkpoint_plan.md | 81 - .../pre-planning/impact_map.md | 214 - .../pre-planning/minimal_spec_draft.md | 133 - .../pre-planning/spec_manifest.md | 349 - .../pre-planning/workstream_triage.md | 195 - .../quality_gate_report.md | 23 - .../world-disabled-diagnostics/session_log.md | 16 - .../slices/WDD0/WDD0-spec.md | 52 - .../slices/WDD0/kickoff_prompts/WDD0-code.md | 33 - .../slices/WDD0/kickoff_prompts/WDD0-integ.md | 31 - .../slices/WDD0/kickoff_prompts/WDD0-test.md | 28 - .../slices/WDD1/WDD1-spec.md | 68 - .../slices/WDD1/kickoff_prompts/WDD1-code.md | 33 - .../slices/WDD1/kickoff_prompts/WDD1-integ.md | 31 - .../slices/WDD1/kickoff_prompts/WDD1-test.md | 28 - .../slices/WDD2/WDD2-spec.md | 66 - .../slices/WDD2/kickoff_prompts/WDD2-code.md | 33 - .../WDD2/kickoff_prompts/WDD2-integ-core.md | 76 - .../WDD2/kickoff_prompts/WDD2-integ-linux.md | 44 - .../WDD2/kickoff_prompts/WDD2-integ-macos.md | 44 - .../kickoff_prompts/WDD2-integ-windows.md | 44 - .../slices/WDD2/kickoff_prompts/WDD2-integ.md | 45 - .../slices/WDD2/kickoff_prompts/WDD2-test.md | 28 - .../smoke/linux-smoke.sh | 276 - .../smoke/macos-smoke.sh | 276 - .../smoke/windows-smoke.ps1 | 234 - .../world-disabled-diagnostics/tasks.json | 850 - ...d-disabled-diagnostics-json-schema-spec.md | 338 - .../README.md | 47 - .../governance/pack-closeout.md | 11 - .../governance/remediation-log.md | 36 - .../governance/seam-1-closeout.md | 59 - .../governance/seam-2-closeout.md | 64 - .../governance/seam-3-closeout.md | 58 - .../review_surfaces.md | 60 - .../scope_brief.md | 62 - ...ffective-disable-attribution-foundation.md | 135 - ...m-2-replay-attribution-runtime-surfaces.md | 145 - .../seam-3-parity-and-contract-lock-in.md | 147 - .../seam_map.md | 34 - .../review.md | 64 - .../seam.md | 102 - ...efinition-effective-disable-attribution.md | 92 - ...eterministic-precedence-redaction-tests.md | 71 - .../slice-3-seam-exit-gate.md | 48 - .../review.md | 69 - .../seam.md | 118 - ...ion-replay-attribution-runtime-surfaces.md | 123 - ...-origin-summary-and-host-warning-wiring.md | 70 - ...y-strategy-telemetry-and-omission-rules.md | 69 - .../slice-4-seam-exit-gate.md | 53 - .../review.md | 63 - .../seam.md | 113 - ...e-1-regression-coverage-and-trace-locks.md | 50 - .../slice-2-docs-and-playbook-alignment.md | 48 - ...ice-3-smoke-wrapper-and-parity-evidence.md | 50 - .../slice-4-seam-exit-gate.md | 43 - .../threading.md | 134 - .../contract.md | 85 - .../decision_register.md | 97 - .../kickoff_prompts/CP1-ci-checkpoint.md | 32 - .../kickoff_prompts/FZ-feature-cleanup.md | 22 - .../manual_testing_playbook.md | 111 - .../world-disabled-reason-attribution/plan.md | 44 - .../platform-parity-spec.md | 47 - .../pre-planning/alignment_report.md | 20 - .../pre-planning/ci_checkpoint_plan.md | 70 - .../pre-planning/impact_map.md | 113 - .../pre-planning/minimal_spec_draft.md | 95 - .../pre-planning/spec_manifest.md | 81 - .../pre-planning/workstream_triage.md | 187 - .../quality_gate_report.md | 27 - .../session_log.md | 60 - .../slices/WDRA0/WDRA0-spec.md | 41 - .../WDRA0/kickoff_prompts/WDRA0-code.md | 31 - .../WDRA0/kickoff_prompts/WDRA0-integ.md | 32 - .../WDRA0/kickoff_prompts/WDRA0-test.md | 28 - .../slices/WDRA1/WDRA1-spec.md | 39 - .../WDRA1/kickoff_prompts/WDRA1-code.md | 31 - .../WDRA1/kickoff_prompts/WDRA1-integ.md | 32 - .../WDRA1/kickoff_prompts/WDRA1-test.md | 28 - .../slices/WDRA2/WDRA2-spec.md | 37 - .../WDRA2/kickoff_prompts/WDRA2-code.md | 31 - .../WDRA2/kickoff_prompts/WDRA2-integ-core.md | 33 - .../kickoff_prompts/WDRA2-integ-linux.md | 31 - .../kickoff_prompts/WDRA2-integ-macos.md | 31 - .../kickoff_prompts/WDRA2-integ-windows.md | 31 - .../WDRA2/kickoff_prompts/WDRA2-integ.md | 28 - .../WDRA2/kickoff_prompts/WDRA2-test.md | 28 - .../smoke/linux-smoke.sh | 27 - .../smoke/macos-smoke.sh | 27 - .../smoke/windows-smoke.ps1 | 26 - .../tasks.json | 891 - .../telemetry-spec.md | 62 - .../world-sync/WS0-closeout_report.md | 74 - .../packs/implemented/world-sync/WS0-spec.md | 88 - .../world-sync/WS1-closeout_report.md | 68 - .../packs/implemented/world-sync/WS1-spec.md | 66 - .../world-sync/WS2-closeout_report.md | 66 - .../packs/implemented/world-sync/WS2-spec.md | 77 - .../world-sync/WS3-closeout_report.md | 78 - .../packs/implemented/world-sync/WS3-spec.md | 32 - .../world-sync/WS4-closeout_report.md | 77 - .../packs/implemented/world-sync/WS4-spec.md | 33 - .../world-sync/WS5-closeout_report.md | 63 - .../packs/implemented/world-sync/WS5-spec.md | 53 - .../world-sync/WS6-closeout_report.md | 77 - .../packs/implemented/world-sync/WS6-spec.md | 30 - .../world-sync/WS7-closeout_report.md | 63 - .../packs/implemented/world-sync/WS7-spec.md | 30 - .../world-sync/ci_checkpoint_plan.md | 107 - .../packs/implemented/world-sync/contract.md | 135 - .../world-sync/decision_register.md | 195 - .../world-sync/execution_preflight_report.md | 123 - .../world-sync/filesystem-semantics-spec.md | 159 - .../implemented/world-sync/impact_map.md | 132 - .../world-sync/internal-git-spec.md | 132 - .../kickoff_prompts/CP1-ci-checkpoint.md | 63 - .../kickoff_prompts/CP2-ci-checkpoint.md | 63 - .../kickoff_prompts/CP3-ci-checkpoint.md | 63 - .../kickoff_prompts/F0-exec-preflight.md | 39 - .../kickoff_prompts/FZ-feature-cleanup.md | 30 - .../world-sync/kickoff_prompts/WS0-code.md | 36 - .../world-sync/kickoff_prompts/WS0-integ.md | 38 - .../world-sync/kickoff_prompts/WS0-test.md | 32 - .../world-sync/kickoff_prompts/WS1-code.md | 36 - .../world-sync/kickoff_prompts/WS1-integ.md | 38 - .../world-sync/kickoff_prompts/WS1-test.md | 32 - .../world-sync/kickoff_prompts/WS2-code.md | 36 - .../kickoff_prompts/WS2-integ-core.md | 78 - .../kickoff_prompts/WS2-integ-linux.md | 67 - .../kickoff_prompts/WS2-integ-macos.md | 67 - .../world-sync/kickoff_prompts/WS2-integ.md | 53 - .../world-sync/kickoff_prompts/WS2-test.md | 32 - .../world-sync/kickoff_prompts/WS3-code.md | 36 - .../world-sync/kickoff_prompts/WS3-integ.md | 38 - .../world-sync/kickoff_prompts/WS3-test.md | 32 - .../world-sync/kickoff_prompts/WS4-code.md | 36 - .../world-sync/kickoff_prompts/WS4-integ.md | 38 - .../world-sync/kickoff_prompts/WS4-test.md | 32 - .../world-sync/kickoff_prompts/WS5-code.md | 36 - .../kickoff_prompts/WS5-integ-core.md | 78 - .../kickoff_prompts/WS5-integ-linux.md | 67 - .../kickoff_prompts/WS5-integ-macos.md | 67 - .../world-sync/kickoff_prompts/WS5-integ.md | 53 - .../world-sync/kickoff_prompts/WS5-test.md | 32 - .../world-sync/kickoff_prompts/WS6-code.md | 36 - .../world-sync/kickoff_prompts/WS6-integ.md | 38 - .../world-sync/kickoff_prompts/WS6-test.md | 32 - .../world-sync/kickoff_prompts/WS7-code.md | 36 - .../kickoff_prompts/WS7-integ-core.md | 78 - .../kickoff_prompts/WS7-integ-linux.md | 67 - .../kickoff_prompts/WS7-integ-macos.md | 67 - .../world-sync/kickoff_prompts/WS7-integ.md | 53 - .../world-sync/kickoff_prompts/WS7-test.md | 32 - .../world-sync/manual_testing_playbook.md | 264 - .../packs/implemented/world-sync/plan.md | 78 - .../world-sync/platform-parity-spec.md | 32 - .../world-sync/quality_gate_report.md | 422 - .../implemented/world-sync/session_log.md | 550 - .../world-sync/smoke/linux-smoke.sh | 117 - .../world-sync/smoke/macos-smoke.sh | 126 - .../implemented/world-sync/spec_manifest.md | 75 - .../packs/implemented/world-sync/tasks.json | 2022 - docs/project_management/packs/queued/.gitkeep | 2 - docs/project_management/packs/sequencing.json | 895 - .../packs/superseded/.gitkeep | 2 - docs/project_management/system/README.md | 37 - docs/project_management/system/USER_GUIDE.md | 436 - .../prompts/planning/ci_checkpoint_agent.md | 97 - .../fse/prompts/planning/impact_map_agent.md | 97 - .../prompts/planning/min_spec_draft_agent.md | 105 - .../post_full_planning_reconcile_agent.md | 66 - .../pre_planning_slice_reconcile_agent.md | 71 - .../prompts/planning/pre_planning_wrapper.md | 60 - .../prompts/planning/spec_manifest_agent.md | 80 - .../planning/workstream_triage_agent.md | 146 - .../planning/codex_events_to_run_state.py | 103 - .../system/fse/scripts/planning/micro_lint.sh | 206 - .../system/fse/scripts/planning/pm_paths.py | 189 - .../scripts/planning/pm_pws_index_extract.py | 150 - .../planning/pre_full_planning_converge.sh | 264 - .../planning/pre_full_planning_convergence.py | 90 - .../pre_planning_research_orchestrate.sh | 1130 - .../scripts/planning/run_planning_agent.sh | 1213 - .../planning/scaffold_pre_planning_pack.sh | 262 - .../planning/validate_ci_checkpoint_plan.py | 377 - .../scripts/planning/validate_impact_map.py | 383 - .../scripts/planning/validate_pws_index.py | 1027 - .../validate_slice_inventory_coherence.py | 480 - .../planning/validate_spec_manifest.py | 164 - .../planning/wrapper_alignment_report.py | 672 - .../ci/PLANNING_CI_CHECKPOINT_STANDARD.md | 94 - .../planning/PLANNING_IMPACT_MAP_STANDARD.md | 119 - .../PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md | 136 - ...LANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md | 156 - .../PLANNING_SPEC_DETERMINATION_STANDARD.md | 133 - .../planning_pack/ci_checkpoint_plan.md.tmpl | 53 - .../planning_pack/impact_map.md.tmpl | 83 - .../planning_pack/spec_manifest.md.tmpl | 60 - .../system/prompts/discovery/adr_lockdown.md | 71 - .../prompts/discovery/brainstorm_to_adr.md | 76 - .../discovery/feature_discovery_coach.md | 71 - .../prompts/planning/ci_checkpoint_agent.md | 124 - .../final_alignment_pass_prompt_template.md | 14 - .../prompts/planning/impact_map_agent.md | 99 - .../prompts/planning/min_spec_draft_agent.md | 109 - .../planning/planning_kickoff_prompt.md | 106 - .../post_full_planning_reconcile_agent.md | 76 - .../pre_planning_slice_reconcile_agent.md | 65 - .../prompts/planning/pre_planning_wrapper.md | 56 - .../prompts/planning/pws_contract_agent.md | 40 - .../prompts/planning/pws_generic_agent.md | 46 - .../planning/pws_tasks_checkpoints_agent.md | 88 - .../planning/quality_gate_remediation.md | 108 - .../prompts/planning/quality_gate_reviewer.md | 197 - .../research_planning_prompt_template.md | 24 - .../prompts/planning/spec_manifest_agent.md | 79 - .../planning/workstream_triage_agent.md | 202 - .../triad_integration_wrapper.md | 158 - .../triad_unified_wrapper_checkpoint_aware.md | 107 - ..._unified_wrapper_checkpoint_resume_safe.md | 193 - .../prompts/triad_wrappers/triad_wrapper.md | 235 - .../schemas/proving_run_closeout.schema.json | 208 - .../system/schemas/tasks.schema.json | 146 - .../system/schemas/work_lift_model.v1.json | 87 - .../schemas/work_lift_vector.schema.json | 219 - .../execution/prepare_proving_run_closeout.py | 267 - .../test_prepare_proving_run_closeout.py | 126 - .../archive_project_management_dir.py | 326 - .../planning/check_adr_exec_summary.py | 325 - .../planning/codex_events_to_run_state.py | 103 - .../ensure_kickoff_prompt_sentinel.py | 64 - .../planning/full_planning_orchestrate.sh | 1092 - .../planning/impact_map_emit_json_v1.md | 106 - .../planning/impact_map_touch_counts.py | 77 - .../planning/impact_map_touch_counts_v1.md | 90 - .../system/scripts/planning/lint.ps1 | 245 - .../system/scripts/planning/lint.sh | 317 - .../system/scripts/planning/micro_lint.sh | 206 - .../migrate_legacy_adrs_to_registry.py | 399 - .../migrate_legacy_doc_edit_sentinel.py | 89 - .../planning/migrate_slice_directories.py | 342 - .../planning/migrate_worktree_feature_dir.py | 300 - .../system/scripts/planning/new_feature.ps1 | 712 - .../system/scripts/planning/new_feature.sh | 1016 - .../planning/parse_allowlist_request.py | 117 - .../planning/planning_pipeline_orchestrate.sh | 145 - .../system/scripts/planning/pm_lift.py | 1194 - .../scripts/planning/pm_lift_emit_json_v1.md | 157 - .../system/scripts/planning/pm_lift_report.py | 220 - .../scripts/planning/pm_lift_strict_check.py | 206 - .../system/scripts/planning/pm_paths.py | 189 - .../scripts/planning/pm_pws_index_extract.py | 150 - .../system/scripts/planning/pm_pws_plan.py | 314 - .../planning/post_full_planning_converge.sh | 279 - .../post_full_planning_convergence.py | 291 - .../planning/pre_full_planning_converge.sh | 258 - .../planning/pre_full_planning_convergence.py | 80 - .../pre_planning_research_orchestrate.sh | 1087 - .../scripts/planning/run_planning_agent.sh | 1145 - .../system/scripts/planning/run_pws_agent.sh | 700 - .../planning/scaffold_pre_planning_pack.sh | 320 - .../tests/test_check_adr_exec_summary.py | 125 - .../tests/test_full_planning_orchestrate.py | 425 - .../tests/test_impact_map_touch_counts.py | 112 - .../scripts/planning/tests/test_micro_lint.py | 122 - .../tests/test_parse_allowlist_request.py | 109 - .../test_planning_pipeline_orchestrate.py | 217 - .../tests/test_pm_lift_emit_json_contract.py | 143 - .../test_pm_lift_goldens_from_impact_map.py | 124 - .../tests/test_pm_lift_goldens_intake.py | 213 - .../tests/test_pm_lift_negative_cases.py | 226 - .../planning/tests/test_pm_lift_report.py | 121 - .../tests/test_pm_lift_strict_check.py | 171 - .../test_pm_lift_vector_schema_validation.py | 99 - .../tests/test_pm_pws_index_extract.py | 241 - .../planning/tests/test_pm_pws_plan.py | 306 - .../test_post_full_planning_convergence.py | 273 - .../test_pre_full_planning_convergence.py | 336 - .../test_pre_planning_research_orchestrate.py | 476 - .../planning/tests/test_run_planning_agent.py | 525 - .../tests/test_validate_ci_checkpoint_plan.py | 232 - ...t_validate_execution_touchset_coherence.py | 143 - ..._validate_impact_map_emit_json_contract.py | 205 - .../planning/tests/test_validate_pws_index.py | 494 - ...test_validate_slice_inventory_coherence.py | 401 - .../test_validate_slice_spec_doc_only.py | 126 - .../tests/test_validate_spec_manifest.py | 107 - .../planning/validate_ci_checkpoint_plan.py | 377 - .../validate_execution_touchset_coherence.py | 293 - .../scripts/planning/validate_impact_map.py | 374 - .../scripts/planning/validate_pws_index.py | 685 - .../validate_slice_inventory_coherence.py | 464 - .../planning/validate_slice_spec_doc_only.py | 240 - .../scripts/planning/validate_slice_specs.py | 395 - .../planning/validate_spec_manifest.py | 154 - .../scripts/planning/validate_tasks_json.py | 1189 - .../planning/wrapper_alignment_report.py | 557 - .../system/scripts/triad/codex_pidfiles.sh | 118 - .../system/scripts/triad/feature_cleanup.sh | 307 - .../mark_noop_platform_fixes_completed.sh | 206 - .../system/scripts/triad/orch_ensure.sh | 212 - .../system/scripts/triad/task_finish.sh | 726 - .../system/scripts/triad/task_start.sh | 726 - .../scripts/triad/task_start_complete.sh | 871 - .../scripts/triad/task_start_integ_final.sh | 226 - .../system/scripts/triad/task_start_pair.sh | 492 - .../triad/task_start_platform_fixes.sh | 461 - .../system/standards/MANIFEST.yaml | 103 - .../system/standards/README.md | 84 - .../adr/ADR_STANDARD_AND_TEMPLATE.md | 149 - .../adr/DRAFT_ADR_LOCKDOWN_STANDARD.md | 69 - .../adr/EXECUTIVE_SUMMARY_STANDARD.md | 57 - .../ci/PLANNING_CI_CHECKPOINT_STANDARD.md | 98 - .../ci/PLATFORM_INTEGRATION_AND_CI.md | 231 - .../EXECUTION_PREFLIGHT_GATE_STANDARD.md | 69 - ...OVING_RUN_CLOSEOUT_PREPARATION_STANDARD.md | 48 - .../execution/SLICE_CLOSEOUT_GATE_STANDARD.md | 46 - .../planning/PLANNING_IMPACT_MAP_STANDARD.md | 144 - .../planning/PLANNING_LINT_CHECKLIST.md | 75 - .../PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md | 129 - .../standards/planning/PLANNING_README.md | 126 - ...LANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md | 385 - .../PLANNING_SPEC_DETERMINATION_STANDARD.md | 150 - .../planning/PLANNING_WORKFLOW_OVERVIEW.md | 63 - .../planning/PLANNING_WORK_LIFT_ADVISORY.md | 215 - .../PLANNING_WORK_LIFT_STRICT_MODE.md | 114 - .../shared/CONTRACT_SURFACE_STANDARD.md | 32 - .../standards/shared/EXIT_CODE_TAXONOMY.md | 49 - .../shared/SECRETS_DELIVERY_CHANNEL_RUBRIC.md | 87 - .../shared/WORK_LIFT_MODEL_V1_GOLDENS.md | 122 - .../standards/shared/WORK_LIFT_RUBRIC.md | 331 - .../system/standards/shared/rustStandards.md | 350 - .../triad/TASK_TRIADS_AND_FEATURE_SETUP.md | 352 - ...TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md | 111 - .../TRIAD_WORKFLOW_CROSS_PLATFORM_INTEG.md | 346 - .../system/templates/adr/ADR_TEMPLATE.md | 162 - .../kickoff/kickoff_ci_checkpoint.md.tmpl | 62 - .../templates/kickoff/kickoff_code.md.tmpl | 32 - .../kickoff/kickoff_exec_preflight.md.tmpl | 36 - .../kickoff/kickoff_feature_cleanup.md.tmpl | 32 - .../templates/kickoff/kickoff_integ.md.tmpl | 33 - .../kickoff/kickoff_integ_core.md.tmpl | 76 - .../kickoff/kickoff_integ_final.md.tmpl | 46 - .../kickoff/kickoff_integ_platform.md.tmpl | 68 - .../templates/kickoff/kickoff_test.md.tmpl | 28 - .../PLANNING_GATE_REPORT_TEMPLATE.md | 169 - .../PLANNING_SESSION_LOG_TEMPLATE.md | 62 - .../planning_pack/ci_checkpoint_plan.md.tmpl | 49 - .../templates/planning_pack/contract.md.tmpl | 21 - .../execution_preflight_report.md.tmpl | 99 - .../planning_pack/impact_map.md.tmpl | 85 - .../templates/planning_pack/plan.md.tmpl | 35 - .../planning_pack/session_log.md.tmpl | 46 - .../slice_closeout_report.md.tmpl | 58 - .../planning_pack/slice_spec.v2.md.tmpl | 21 - .../planning_pack/spec_manifest.md.tmpl | 57 - .../system/templates/spec/README.md | 10 - .../spec/cli-workflows-ux-spec.md.tmpl | 84 - .../templates/spec/compatibility-spec.md.tmpl | 26 - .../templates/spec/env-vars-spec.md.tmpl | 41 - .../spec/filesystem-semantics-spec.md.tmpl | 32 - .../spec/platform-parity-spec.md.tmpl | 29 - .../system/templates/spec/policy-spec.md.tmpl | 32 - .../templates/spec/protocol-spec.md.tmpl | 65 - .../system/templates/spec/schema-spec.md.tmpl | 53 - .../templates/spec/telemetry-spec.md.tmpl | 32 - .../intake => }/work_items/README.md | 0 .../arching_lark_work_item_intake.md | 0 .../aligning_otter_work_item_intake.md | 0 .../implemented/taming_tapir_fact_finding.md | 0 .../taming_tapir_work_item_intake.md | 0 .../untangling_lemur_work_item_intake.md | 0 .../shedding_gecko_work_item_intake.md | 0 2647 files changed, 2 insertions(+), 641317 deletions(-) create mode 100644 .rgignore delete mode 100644 FSE_PRE_PLANNING_DEPENDENCY_GRAPH.md delete mode 100644 FSE_PRE_PLANNING_STAGE_OUTPUT_CONTRACT.md delete mode 100644 LLM_AI_CAPABILITY_ENABLEMENT_PLANNING_ORDER.md delete mode 100644 PWS_FULL_PLANNING_ORCHESTRATION_V1.md delete mode 100644 archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md delete mode 100644 archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md delete mode 100644 docs/project_management/_archived/ci-improvements/CI_CHECKPOINTING_ADHOC_NOTES.md delete mode 100644 docs/project_management/_archived/ci-improvements/ci-improvements.md delete mode 100644 docs/project_management/_archived/config-subcommand/config_subcommand_plan.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-code.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-integ.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-test.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-code.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-integ.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-test.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-code.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-integ.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-test.md delete mode 100644 docs/project_management/_archived/config-subcommand/kickoff_prompts/README.md delete mode 100644 docs/project_management/_archived/config-subcommand/session_log.md delete mode 100644 docs/project_management/_archived/config-subcommand/tasks.json delete mode 100644 docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md delete mode 100644 docs/project_management/_archived/doctor_scopes/DS0-spec.md delete mode 100644 docs/project_management/_archived/doctor_scopes/decision_register.md delete mode 100644 docs/project_management/_archived/doctor_scopes/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/doctor_scopes/integration_map.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-code.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-core.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-linux.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-macos.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-windows.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-test.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/doctor_scopes/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/doctor_scopes/plan.md delete mode 100644 docs/project_management/_archived/doctor_scopes/quality_gate_report.md delete mode 100644 docs/project_management/_archived/doctor_scopes/session_log.md delete mode 100755 docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/doctor_scopes/tasks.json delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/quality_gate_report.md delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md delete mode 100755 docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-closeout_report.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/decision_register.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/integration_map.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-code.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-core.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-linux.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-macos.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-windows.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-test.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/events.jsonl delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/last_message.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/stderr.log delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/codex.pid.aborted-20260120T131437Z.pid delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl.aborted-20260120T131437Z.jsonl delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/stderr.aborted-20260120T131437Z.log delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/test/events.jsonl delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/test/last_message.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/test/stderr.log delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/quality_gate_report.md delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md delete mode 100755 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json delete mode 100644 docs/project_management/_archived/logs/linux_always_world.md delete mode 100644 docs/project_management/_archived/logs/macos_always_world.md delete mode 100644 docs/project_management/_archived/logs/windows_always_world.md delete mode 100644 docs/project_management/_archived/misc/PHASE_4_CONCURRENT_OUTPUT_DESIGN.md delete mode 100644 docs/project_management/_archived/misc/PRE_PLANNING_BUCKET_AND_SCAFFOLDING_PLAN.md delete mode 100644 docs/project_management/_archived/misc/RELEASE_PIPELINE_PLAN.md delete mode 100644 docs/project_management/_archived/misc/RELEASE_PIPELINE_PLAN.tasks.json delete mode 100644 docs/project_management/_archived/misc/WORKSTREAM_SYSTEM_IMPLEMENTATION_PLAN.md delete mode 100644 docs/project_management/_archived/misc/WORKSTREAM_TRIAGE_AND_LIFT_DECISIONS.md delete mode 100644 docs/project_management/_archived/misc/implementation_phase5_windows.md delete mode 100644 docs/project_management/_archived/misc/pre_planning_researcn_orchestration.md delete mode 100644 docs/project_management/_archived/misc/stage5_editor_parity_plan.md delete mode 100644 docs/project_management/_archived/misc/tasks.json delete mode 100644 docs/project_management/_archived/next/agent_hub_core/decision_register.md delete mode 100644 docs/project_management/_archived/next/forge/decision_register.md delete mode 100644 docs/project_management/_archived/next/host_event_bus_router_daemon/decision_register.md delete mode 100644 docs/project_management/_archived/next/linux_guest_rootfs_backend/decision_register.md delete mode 100644 docs/project_management/_archived/next/linux_guest_rootfs_backend/plan.md delete mode 100644 docs/project_management/_archived/next/linux_guest_rootfs_backend/spec.md delete mode 100644 docs/project_management/_archived/next/linux_guest_rootfs_backend/tasks.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/contract.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/decision_register.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/plan.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/spec_manifest.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/specs/adapter_contract.md delete mode 100644 docs/project_management/_archived/next/llm_cli_backend_engine/tasks.json delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/contract.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/impact_map.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/plan.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/spec_manifest.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/specs/env_injection.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/specs/http_surface.md delete mode 100644 docs/project_management/_archived/next/llm_gateway_in_world/tasks.json delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/01_problem_and_goals.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/02_current_state.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/03_solution_overview.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/04_architecture_and_flows.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/05_policy_model.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/06_security_and_threat_model.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/07_testing_plan.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/08_rollout_plan.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/09_work_breakdown.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/10_open_questions.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/README.md delete mode 100644 docs/project_management/_archived/next/macos_world_backend_vf/quality_gate_report.md delete mode 100644 docs/project_management/_archived/next/orchestration_mcp_toolbox/decision_register.md delete mode 100644 docs/project_management/_archived/next/sequencing.json delete mode 100644 docs/project_management/_archived/next/workflow-engine/decision_register.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/ADR-0001-agent-hub-runtime-config-and-isolation.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I0-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I1-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I2-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I3-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I4-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I5-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I6-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I7-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I8-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/I9-spec.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I0-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I0-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I0-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I1-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I1-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I1-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I2-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I2-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I2-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I3-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I3-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I3-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I4-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I4-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I4-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I5-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I5-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I5-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I6-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I6-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I6-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I7-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I7-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I7-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I8-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I8-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I8-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I9-code.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I9-integ.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/I9-test.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/kickoff_prompts/README.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/plan.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/session_log.md delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/p0-agent-hub-isolation-hardening/tasks.json delete mode 100644 docs/project_management/_archived/p0-ci-runner-smoke/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/p0-ci-runner-smoke/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/p0-ci-runner-smoke/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M1-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M2-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M3-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M4-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M5a-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M5b-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M5c-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/M6-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M1-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M1-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M1-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M2-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M2-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M2-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M3-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M3-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M3-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M4-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M4-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M4-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5a-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5a-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5a-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5b-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5b-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5b-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5c-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5c-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M5c-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M6-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M6-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/kickoff_prompts/M6-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/plan.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/session_log.md delete mode 100644 docs/project_management/_archived/p0-platform-stability-macOS-parity/tasks.json delete mode 100644 docs/project_management/_archived/p0-platform-stability/INV-overlay-consistency.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/LP1-spec.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1a-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1a-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1a-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1b-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1b-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/H1b-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/LP1-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/LP1-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/LP1-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1a-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1a-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1a-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1b-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1b-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1b-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1c-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1c-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R1c-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2a-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2a-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2a-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2b-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2b-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2b-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2c-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2c-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2c-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2d-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2d-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2d-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2e-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2e-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2e-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2f-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2f-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/R2f-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/README.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1a-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1a-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1a-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1b-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1b-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1b-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1c-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1c-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1c-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1c-windows-dry-run.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1d-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1d-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1d-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1e-code.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1e-integ.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/kickoff_prompts/S1e-test.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/p0_platform_stability_plan.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/plan.md delete mode 100644 docs/project_management/_archived/p0-platform-stability/session_log.md delete mode 100755 docs/project_management/_archived/p0-platform-stability/smoke/linux-smoke.sh delete mode 100755 docs/project_management/_archived/p0-platform-stability/smoke/macos-smoke.sh delete mode 100755 docs/project_management/_archived/p0-platform-stability/smoke/smoke.sh delete mode 100644 docs/project_management/_archived/p0-platform-stability/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/p0-platform-stability/tasks.json delete mode 100644 docs/project_management/_archived/phase_4-isolation/ALWAYS_IN_WORLD_PTY_EXECUTION_PLAN.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/COMPLETE_FIXES_PHASE4_PRE45.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_5_ALWAYS_WORLD_IMPLEMENTATION_PLAN.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_5_ALWAYS_WORLD_MAC_PLAN.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_COMPLETION_REPORT.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_PROGRESS.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_SESSION3_CONTINUATION.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_SESSION4_CONTINUATION.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_SESSION5_CONTINUATION.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_4_SESSION6_CONTINUATION.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PHASE_5_ALWAYS_WORLD_WINDOWS_PLAN.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PRE_PHASE_4_5_HARDENING_PLAN.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PRE_PHASE_4_5_PR_STEPS.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/PROMPT_TEMPLATE_PHASE_HANDOFF.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/SPIKE_TRANSPORT_PARITY_PLAN.md delete mode 100644 "docs/project_management/_archived/phase_4-isolation/Windows Named\342\200\221Pipe HTTP-WS Bridge Patterns in Production.md" delete mode 100644 docs/project_management/_archived/phase_4-isolation/implementation_phase4_merged.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/windows_host_transport_plan.md delete mode 100644 docs/project_management/_archived/phase_4-isolation/windows_transport_external_overview.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative1_slice_specs_v2.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative1_slice_specs_v2_revA.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative1_slice_specs_v2_work_breakdown.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative2_impact_map_enforcement.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative2_impact_map_enforcement_revA.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative2_impact_map_enforcement_revA_work_breakdown.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative3_directory_prompt_refactor.md delete mode 100644 docs/project_management/_archived/pm-system-improvements/initiative3_directory_prompt_refactor_work_breakdown.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/C0-closeout_report.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/C0-spec.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/C1-closeout_report.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/C1-spec.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/decision_register.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/integration_map.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-code.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-integ-core.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-integ-linux.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-integ-macos.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-integ-windows.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-integ.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C0-test.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-code.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-integ-core.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-integ-linux.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-integ-macos.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-integ-windows.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-integ.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/C1-test.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/code/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/code/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/code/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/integ/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/test/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/test/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C0/test/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/code/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/code/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/code/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/integ/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/test/events.jsonl delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/test/last_message.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/logs/C1/test/stderr.log delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/plan.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/quality_gate_report.md delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/session_log.md delete mode 100755 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/smoke/linux-smoke.sh delete mode 100755 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/policy-patch-only-broker-effective-resolution/tasks.json delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/PCM0-spec.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/PCM1-spec.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/PCM2-spec.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/PCM3-spec.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/decision_register.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/integration_map.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM0-code.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM0-integ.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM0-test.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM1-code.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM1-integ.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM1-test.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM2-code.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM2-integ.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM2-test.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM3-code.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM3-integ.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/kickoff_prompts/PCM3-test.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/plan.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/quality_gate_report.md delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/session_log.md delete mode 100755 docs/project_management/_archived/policy_and_config_mental_model_simplification/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/policy_and_config_mental_model_simplification/tasks.json delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/PCP0-closeout_report.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/PCP0-spec.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/decision_register.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/integration_map.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-code.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-integ-core.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-integ-linux.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-integ-macos.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-integ-windows.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-integ.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/kickoff_prompts/PCP0-test.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/plan.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/quality_gate_report.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/session_log.md delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/policy_and_config_precedence/tasks.json delete mode 100644 docs/project_management/_archived/pre_phase_4/CI_ANALYSIS_REPORT.md delete mode 100644 docs/project_management/_archived/pre_phase_4/LINUX_BUTTON_UP.md delete mode 100644 docs/project_management/_archived/pre_phase_4/PHASE_3.75_COMPLETION_STATUS.md delete mode 100644 docs/project_management/_archived/pre_phase_4/auto_shim_deployment_plan.md delete mode 100644 docs/project_management/_archived/pre_phase_4/ci_test_failures_fix_plan.md delete mode 100644 docs/project_management/_archived/pre_phase_4/implementation_phase3.5.md delete mode 100644 docs/project_management/_archived/pre_phase_4/implementation_phase3.md delete mode 100644 docs/project_management/_archived/pre_phase_4/plan.md delete mode 100644 docs/project_management/_archived/pty_spike/PTY_PROMPT_FIX.md delete mode 100644 docs/project_management/_archived/pty_spike/PTY_PROMPT_NEW_PLAN.md delete mode 100644 docs/project_management/_archived/pty_spike/REEDLINE_CLEANUP_STEPS.md delete mode 100644 docs/project_management/_archived/pty_spike/REEDLINE_MIGRATION_PLAN.md delete mode 100644 docs/project_management/_archived/pty_spike/REEDLINE_PR_READY.md delete mode 100644 docs/project_management/_archived/pty_spike/REEDLINE_PTY_ISSUE.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R1-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R1-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R1-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R10-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R10-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R10-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R11-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R11-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R11-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R12-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R12-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R12-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R13-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R13-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R13-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R14-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R14-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R14-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R15-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R15-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R15-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R2-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R2-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R2-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R3-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R3-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R3-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R4-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R4-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R4-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R5-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R5-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R5-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R6-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R6-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R6-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R7-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R7-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R7-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R8-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R8-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R8-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9a-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9a-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9a-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9b-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9b-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9b-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9c-code.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9c-integ.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/R9c-test.md delete mode 100644 docs/project_management/_archived/refactor/kickoff_prompts/README.md delete mode 100644 docs/project_management/_archived/refactor/refactor_plan.md delete mode 100644 docs/project_management/_archived/refactor/session_log.md delete mode 100644 docs/project_management/_archived/refactor/tasks.json delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S0-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S0-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S0-test.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S1-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S1-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S1-test.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S2-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S2-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S2-test.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S3-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S3-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S3-test.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S4-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S4-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S4-test.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S5-code.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S5-integ.md delete mode 100644 docs/project_management/_archived/settings-stack/kickoff_prompts/S5-test.md delete mode 100644 docs/project_management/_archived/settings-stack/session_log.md delete mode 100644 docs/project_management/_archived/settings-stack/settings_stack_plan.md delete mode 100644 docs/project_management/_archived/settings-stack/tasks.json delete mode 100644 docs/project_management/_archived/standards/ADR_STANDARD_AND_TEMPLATE.md delete mode 100644 docs/project_management/_archived/standards/CONTRACT_SURFACE_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/EXECUTIVE_SUMMARY_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/EXIT_CODE_TAXONOMY.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_CI_CHECKPOINT_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_GATE_REPORT_TEMPLATE.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_IMPACT_MAP_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_LINT_CHECKLIST.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_QUALITY_GATE_PROMPT.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_QUALITY_GATE_REMEDIATION_PROMPT.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_README.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_SESSION_LOG_TEMPLATE.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_SPEC_DETERMINATION_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/PLANNING_WORKFLOW_OVERVIEW.md delete mode 100644 docs/project_management/_archived/standards/PLATFORM_INTEGRATION_AND_CI.md delete mode 100644 docs/project_management/_archived/standards/README.md delete mode 100644 docs/project_management/_archived/standards/SECRETS_DELIVERY_CHANNEL_RUBRIC.md delete mode 100644 docs/project_management/_archived/standards/SLICE_CLOSEOUT_GATE_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/TASK_TRIADS_AND_FEATURE_SETUP.md delete mode 100644 docs/project_management/_archived/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md delete mode 100644 docs/project_management/_archived/standards/TRIAD_INTEGRATION_WRAPPER_PROMPT.md delete mode 100644 docs/project_management/_archived/standards/TRIAD_WORKFLOW_CROSS_PLATFORM_INTEG.md delete mode 100644 docs/project_management/_archived/standards/TRIAD_WRAPPER_PROMPT.md delete mode 100644 docs/project_management/_archived/standards/TRIAD_WRAPPER_PROMPT_UNIFIED.md delete mode 100644 docs/project_management/_archived/standards/rustStandards.md delete mode 100644 docs/project_management/_archived/standards/tasks.schema.json delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A1-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A1-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A2-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A2-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A3-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A3-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/A3-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B1-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B1-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B1-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B2-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B2-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B2-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B3-docs.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/B3-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C1-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C1-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C1-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C2-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C2-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C2-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C3-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C3-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/C3-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D1-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D1-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D1-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D2-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D2-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D2-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D3-code.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D3-integ.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/kickoff_prompts/D3-test.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/session_log.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/substrate_isolated_shell_data_map.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/substrate_isolated_shell_dependency_graph.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/substrate_isolated_shell_execution_plan.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/substrate_isolated_shell_file_audit.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/substrate_isolated_shell_plan.md delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/tasks.json delete mode 100644 docs/project_management/_archived/substrate-isolated-shell/world-deps-sync.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/README.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/cohesion-audit.report.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/cohesion-audit.report.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/cohesion-audit.scan.after.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/cohesion-audit.scan.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/cohesion-remediator.log.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/concrete-audit.report.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/concrete-audit.report.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/concrete-audit.scan.after.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/concrete-remediator.log.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/contradictions-audit.report.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/contradictions-audit.report.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/contradictions-audit.scan.after.json delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/audits-remediations/contradictions-remediator.log.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/scope_brief.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam-1-lift-vector-schema-and-rubric.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam-2-lift-model-config-v1.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam-3-pm-lift-core-engine.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam-4-pack-derived-lift-inputs.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam-5-advisory-workflow-integration.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/seam_map.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/README.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-1-lift-vector-schema-and-rubric/seam.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-1-lift-vector-schema-and-rubric/slice-1-contract-1-schema.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-1-lift-vector-schema-and-rubric/slice-2-human-rubric-and-conformance.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-2-lift-model-config-v1/seam.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-2-lift-model-config-v1/slice-1-contract-2-model-config.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-2-lift-model-config-v1/slice-2-goldens-and-conformance.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-3-pm-lift-core-engine/seam.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-3-pm-lift-core-engine/slice-1-contract-3-emit-json.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-3-pm-lift-core-engine/slice-2-config-backed-scoring-and-validation.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-3-pm-lift-core-engine/slice-3-goldens-and-conformance.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-4-pack-derived-lift-inputs/seam.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-4-pack-derived-lift-inputs/slice-1-contract-4-impact-map-emit-json.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-4-pack-derived-lift-inputs/slice-2-prefix-expansion-and-derived-counts.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-5-advisory-workflow-integration/seam.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-5-advisory-workflow-integration/slice-1-advisory-workflow-docs-and-make-targets.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-5-advisory-workflow-integration/slice-2-advisory-report-hook-and-lint-integration.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threaded-seams/seam-5-advisory-workflow-integration/slice-3-strict-mode-onramp-plan.md delete mode 100644 docs/project_management/_archived/work_lift_v1_seams/threading.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/PHASE_A_B_GATES_ADR_0012.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU1-closeout_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU1-spec.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU2-closeout_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU2-spec.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU3-closeout_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU3-spec.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU4-closeout_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU4-spec.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU5-closeout_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/WCU5-spec.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/decision_register.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/integration_map.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-code.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-integ-core.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-integ-linux.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-integ-macos.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-integ-windows.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-integ.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU1-test.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-code.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-integ-core.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-integ-linux.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-integ-macos.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-integ-windows.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-integ.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU2-test.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-code.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-integ-core.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-integ-linux.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-integ-macos.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-integ-windows.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-integ.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU3-test.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-code.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-integ-core.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-integ-linux.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-integ-macos.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-integ-windows.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-integ.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU4-test.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-code.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-integ-core.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-integ-linux.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-integ-macos.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-integ-windows.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-integ.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/kickoff_prompts/WCU5-test.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU3/integ/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/code/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/code/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/code/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ-core/codex.pid delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/integ/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/test/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/test/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU4/test/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/code/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/code/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/code/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ-core/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ-core/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ-core/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/integ/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/test/events.jsonl delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/test/last_message.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/logs/WCU5/test/stderr.log delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/plan.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/quality_gate_report.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/session_log.md delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/workspace-config-policy-unification/tasks.json delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/DR_tasks.json delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/ci_runs.md delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/decision_register.md delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/policy-snapshot-deprecation-spec.md delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/policy-snapshot-spec.md delete mode 100755 docs/project_management/_archived/world-agent-policy-snapshot/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-agent-policy-snapshot/smoke/windows-wsl-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C0-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C0-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C1-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C1-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C2-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C2-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C3-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C3-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C4-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C4-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C5-closeout_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/C5-spec.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/PROTOCOL.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/RESEARCH.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/STATE_MACHINE.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/decision_register.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/drain_design.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/driver_loop_design.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/integration_map.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C0-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C1-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C2-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C3-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C4-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-code.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-integ-core.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-integ-linux.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-integ-macos.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-integ-windows.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-integ.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/C5-test.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/plan.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/requirements_traceability.md delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/session_log.md delete mode 100755 docs/project_management/_archived/world-first-repl-persistent-pty/smoke/linux-smoke.sh delete mode 100755 docs/project_management/_archived/world-first-repl-persistent-pty/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-first-repl-persistent-pty/tasks.json delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA0-closeout_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA0-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA1-closeout_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA1-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA2-closeout_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/WFGADAXA2-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/ci_checkpoint_plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/contract.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/decision_register.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/impact_map.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA0-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA0-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA0-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA1-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA1-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA1-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/kickoff_prompts/WFGADAXA2-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/session_log.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/smoke/_core.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/spec_manifest.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX-addon-v3-alignment/tasks.json delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/ENV.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/PROTOCOL.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/SCHEMA.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/SECURITY.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/WFGADAX0-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/WFGADAX1-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/WFGADAX2-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/WFGADAX3-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/ci_checkpoint_plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/contract.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/decision_register.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/impact_map.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX0-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX0-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX0-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX1-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX2-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX2-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX2-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/kickoff_prompts/WFGADAX3-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/requirements_traceability.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/session_log.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/smoke/_core.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/spec_manifest.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny-APPENDIX/tasks.json delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/ENV.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/PROTOCOL.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/SCHEMA.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/SECURITY.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD0-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD1-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD2-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD3-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD4-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/WFGAD5-spec.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/ci_checkpoint_plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/contract.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/decision_register.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/impact_map.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/integration_map.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/CP3-ci-checkpoint.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD0-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD0-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD0-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD1-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD2-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD2-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD2-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD3-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD4-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD4-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD4-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-code.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-integ-core.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-integ-linux.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-integ-macos.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-integ-windows.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-integ.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/kickoff_prompts/WFGAD5-test.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/plan.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/requirements_traceability.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/session_log.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/smoke/_core.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/spec_manifest.md delete mode 100644 docs/project_management/_archived/world-fs-granular-allow-deny/tasks.json delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/WO0-closeout_report.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/WO0-spec.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/decision_register.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/integration_map.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-code.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-integ-core.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-integ-linux.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-integ-macos.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-integ-windows.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-integ.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/kickoff_prompts/WO0-test.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/plan.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/session_log.md delete mode 100755 docs/project_management/_archived/world-overlayfs-enumeration/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-overlayfs-enumeration/tasks.json delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C0-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C1-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C2-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C3-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C4-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C5-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C6-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C7-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C8-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/C9-spec.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C0-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C0-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C0-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C1-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C1-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C1-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C2-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C2-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C2-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C3-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C3-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C3-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C4-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C4-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C4-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C5-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C5-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C5-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C6-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C6-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C6-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C7-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C7-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C7-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C8-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C8-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C8-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C9-code.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C9-integ.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/kickoff_prompts/C9-test.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/plan.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/session_log.md delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world-sync-legacy-2026-02-10/tasks.json delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/S0-spec-selection-config-and-ux.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/S1-spec-install-classes.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/S2-spec-system-packages-provisioning.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/WDL0-closeout_report.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/WDL1-closeout_report.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/WDL2-closeout_report.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/decision_register.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/execution_preflight_report.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/integration_map.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-code.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-integ-core.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-integ-linux.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-integ-macos.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-integ-windows.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-integ.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL0-test.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-code.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-integ-core.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-integ-linux.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-integ-macos.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-integ-windows.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-integ.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL1-test.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-code.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-integ-core.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-integ-linux.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-integ-macos.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-integ-windows.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-integ.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/kickoff_prompts/WDL2-test.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/plan.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/quality_gate_report.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/session_log.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/session_log_legacy_2025-12-24.md delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/world_deps_selection_layer/tasks.json delete mode 100644 docs/project_management/_archived/yaml-settings-migration/Y0-spec.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/kickoff_prompts/README.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/kickoff_prompts/Y0-code.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/kickoff_prompts/Y0-integ.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/kickoff_prompts/Y0-test.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/manual_testing_playbook.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/plan.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/session_log.md delete mode 100644 docs/project_management/_archived/yaml-settings-migration/smoke/linux-smoke.sh delete mode 100644 docs/project_management/_archived/yaml-settings-migration/smoke/macos-smoke.sh delete mode 100644 docs/project_management/_archived/yaml-settings-migration/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/_archived/yaml-settings-migration/tasks.json delete mode 100644 docs/project_management/adrs/PROVISIONING_SURFACE_RECONCILIATION.md delete mode 100644 docs/project_management/adrs/README.md delete mode 100644 docs/project_management/adrs/draft/.gitkeep delete mode 100644 docs/project_management/adrs/draft/ADR-0003-policy-and-config-mental-model-simplification_OG.md delete mode 100644 docs/project_management/adrs/draft/ADR-0009-linux-guest-rootfs-backend-and-linux-system-packages-provisioning.md delete mode 100644 docs/project_management/adrs/draft/ADR-0010-world-backend-contract-and-capability-divergence.md delete mode 100644 docs/project_management/adrs/draft/ADR-0016-world-first-repl-persistent-pty.md delete mode 100644 docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md delete mode 100644 docs/project_management/adrs/draft/ADR-0019-warn-config-global-show-when-workspace-config-overrides.md delete mode 100644 docs/project_management/adrs/draft/ADR-0020-profiles-config-policy-snapshots.md delete mode 100644 docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md delete mode 100644 docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md delete mode 100644 docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md delete mode 100644 docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md delete mode 100644 docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md delete mode 100644 docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md delete mode 100644 docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md delete mode 100644 docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md delete mode 100644 docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md delete mode 100644 docs/project_management/adrs/draft/ADR-0030-provisioning-otter.md delete mode 100644 docs/project_management/adrs/draft/ADR-0031-detecting-badger.md delete mode 100644 docs/project_management/adrs/draft/ADR-0032-stashing-ferret.md delete mode 100644 docs/project_management/adrs/draft/ADR-0033-routing-weasel.md delete mode 100644 docs/project_management/adrs/draft/ADR-0034-staging-beaver.md delete mode 100644 docs/project_management/adrs/draft/ADR-0035-summoning-wombat.md delete mode 100644 docs/project_management/adrs/draft/ADR-0036-quieting-lemur.md delete mode 100644 docs/project_management/adrs/draft/ADR-0037-clarifying-owl.md delete mode 100644 docs/project_management/adrs/draft/ADR-0038-replaying-raccoon.md delete mode 100644 docs/project_management/adrs/draft/ADR-0039-capturing-koala.md delete mode 100644 docs/project_management/adrs/draft/ADR-0040-substrate-gateway-boundary-and-runtime-ownership.md delete mode 100644 docs/project_management/adrs/draft/ADR-0041-substrate-gateway-backend-adapter-contract.md delete mode 100644 docs/project_management/adrs/draft/ADR-0042-llm-and-agent-identity-tuple-and-deployment-posture.md delete mode 100644 docs/project_management/adrs/draft/ADR-0043-adr-0027-identity-tuple-policy-surface.md delete mode 100644 docs/project_management/adrs/draft/ADR-0044-agent-hub-core-successor-identity-tuple-compatible.md delete mode 100644 docs/project_management/adrs/draft/ADR-0045-orchestration-toolbox-internal-mcp-identity-trace-contract.md delete mode 100644 docs/project_management/adrs/draft/ADR-0046-gateway-backend-selection-runtime-integration.md delete mode 100644 docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md delete mode 100644 docs/project_management/adrs/draft/ADR-2026-02-13-macos-world-backend-virtualization-framework.md delete mode 100644 docs/project_management/adrs/implemented/.gitkeep delete mode 100644 docs/project_management/adrs/implemented/ADR-0002-world-deps-install-classes-and-world-provisioning.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0003-policy-and-config-mental-model-simplification.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0004-world-overlayfs-directory-enumeration-reliability.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0008-workspace-config-policy-scope-and-dot-substrate-unification.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0011-world-deps-packages-bundles-contract.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0012-config-schema-per-key-merge-and-provenance.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0013-policy-patch-only-broker-canonical-effective-resolution.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0014-world-service-policy-resolution-and-concurrency.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md delete mode 100644 docs/project_management/adrs/implemented/ADR-0018-world-fs-granular-allow-deny-and-strict-deny.md delete mode 100644 docs/project_management/adrs/queued/.gitkeep delete mode 100644 docs/project_management/adrs/superseded/.gitkeep delete mode 100644 docs/project_management/future/COMMAND_HOOKS_IMPLEMENTATION_PLAN.md delete mode 100644 docs/project_management/future/INTERNAL_GIT.md delete mode 100644 docs/project_management/future/PHASE_4_5_ADVANCED_FEATURES_PLAN.md delete mode 100644 docs/project_management/future/PHASE_4_5_ISOLATION_UPGRADE.md delete mode 100644 docs/project_management/future/TESTING_AGENT.md delete mode 100644 docs/project_management/future/TUI_TESTING_GUIDE.md delete mode 100644 docs/project_management/future/substrateGetsStuckOnSubstrateInceptionError.png delete mode 100644 docs/project_management/intake/adrs/capturing_koala_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/clarifying_owl_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/detecting_badger_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/provisioning_otter_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/quieting_lemur_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/replaying_raccoon_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/routing_weasel_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/staging_beaver_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/stashing_ferret_adr_intake.md delete mode 100644 docs/project_management/intake/adrs/summoning_wombat_adr_intake.md delete mode 100644 docs/project_management/intake/scratch/terminal_automation.md delete mode 100644 docs/project_management/intake/work_items/lifting_marmot_work_item_intake.md delete mode 100644 docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md delete mode 100644 docs/project_management/packs/README.md delete mode 100644 docs/project_management/packs/active/.gitkeep delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/contract.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/decision_register.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/execution_preflight_report.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/impact_map.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/integration_map.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/plan.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/quality_gate_report.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/session_log.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/C0-closeout_report.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/C0-spec.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-code.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-integ-core.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-integ-linux.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-integ-macos.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-integ-windows.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-integ.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/slices/C0/kickoff_prompts/C0-test.md delete mode 100755 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/spec_manifest.md delete mode 100644 docs/project_management/packs/active/warn-config-global-show-workspace-overrides/tasks.json delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/PROTOCOL.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/SCHEMA.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/SECURITY.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/WPEP0-spec.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/WPEP1-spec.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/WPEP2-spec.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/WPEP3-spec.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/contract.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/decision_register.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/impact_map.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/README.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-code.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-integ-core.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-integ-linux.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-integ-macos.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-integ-windows.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-integ.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP0-test.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP1-code.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP1-integ.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP1-test.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP2-code.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP2-integ.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP2-test.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-code.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-integ-core.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-integ-linux.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-integ-macos.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-integ-windows.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-integ.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/kickoff_prompts/WPEP3-test.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/plan.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/quality_gate_report.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/session_log.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/smoke/_core.sh delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/spec_manifest.md delete mode 100644 docs/project_management/packs/active/world_process_exec_tracing_parity/tasks.json delete mode 100644 docs/project_management/packs/draft/.gitkeep delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/compatibility-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/contract.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/decision_register.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/execution_preflight_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/plan.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/policy-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/quality_gate_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/session_log.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS0/ITPS0-closeout_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS0/ITPS0-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS0/kickoff_prompts/ITPS0-code.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS0/kickoff_prompts/ITPS0-integ.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS0/kickoff_prompts/ITPS0-test.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-closeout_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/ITPS1-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/kickoff_prompts/ITPS1-code.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/kickoff_prompts/ITPS1-integ.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS1/kickoff_prompts/ITPS1-test.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-closeout_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/ITPS2-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/kickoff_prompts/ITPS2-code.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/kickoff_prompts/ITPS2-integ.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS2/kickoff_prompts/ITPS2-test.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/ITPS3-closeout_report.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/ITPS3-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-code.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-integ-core.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-integ-linux.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-integ-macos.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-integ-windows.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-integ.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/slices/ITPS3/kickoff_prompts/ITPS3-test.md delete mode 100755 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/smoke/_core.sh delete mode 100755 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tasks.json delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/telemetry-spec.md delete mode 100644 docs/project_management/packs/draft/adr-0027-identity-tuple-policy-surface/tuple-policy-schema-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/agent-hub-session-protocol-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/compatibility-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/contract.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/plan.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/platform-parity-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/policy-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/quality_gate_report.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/session_log.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC0/AHCSITC0-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC0/kickoff_prompts/AHCSITC0-code.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC0/kickoff_prompts/AHCSITC0-integ.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC0/kickoff_prompts/AHCSITC0-test.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC1/AHCSITC1-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC1/kickoff_prompts/AHCSITC1-code.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC1/kickoff_prompts/AHCSITC1-integ.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC1/kickoff_prompts/AHCSITC1-test.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/AHCSITC2-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-code.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-integ-core.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-integ-linux.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-integ-macos.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-integ-windows.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-integ.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC2/kickoff_prompts/AHCSITC2-test.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/AHCSITC3-spec.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-code.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-integ-core.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-integ-linux.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-integ-macos.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-integ-windows.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-integ.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/slices/AHCSITC3/kickoff_prompts/AHCSITC3-test.md delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/tasks.json delete mode 100644 docs/project_management/packs/draft/agent-hub-core-successor-identity-tuple-compatible/telemetry-spec.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/README.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/compatibility-spec.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/platform-parity-spec.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/scope_brief.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-1-backend-selection-and-policy-surface.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-2-runtime-realization-and-artifacts.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam-3-parity-validation-and-rollout.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/seam_map.md delete mode 100755 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/review.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/seam.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-00-c-01-c-02-contract-definition.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-1-selection-order-and-inventory-truth.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-2-policy-precedence-and-fail-closed-boundary.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-3-shell-adoption-and-drift-guards.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-1-backend-selection-and-policy-surface/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/review.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/seam.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-1-binding-lookup-and-capability-gates.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-2-request-auth-and-runtime-artifacts.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-3-lifecycle-conformance-and-drift-guards.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-2-runtime-realization-and-artifacts/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/review.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/seam.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/slice-1-parity-regression-floor-and-backend-matrix.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/slice-2-platform-evidence-and-unsupported-backend-validation.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/slice-3-rollout-proof-and-compatibility-publication.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threaded-seams/seam-3-parity-validation-and-rollout/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration-fse/threading.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/fse_pre_planning.json delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/gateway-backend-selection-runtime-integration/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/json-mode/json_mode_plan.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J1-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J1-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J1-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2a-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2a-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2a-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2b-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2b-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2b-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2c-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2c-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J2c-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3a-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3a-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3a-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3b-code.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3b-integ.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/J3b-test.md delete mode 100644 docs/project_management/packs/draft/json-mode/kickoff_prompts/README.md delete mode 100644 docs/project_management/packs/draft/json-mode/session_log.md delete mode 100644 docs/project_management/packs/draft/json-mode/tasks.json delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/compatibility-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/contract.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/execution_preflight_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/identity-tuple-schema-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/plan.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/platform-parity-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/policy-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/quality_gate_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/session_log.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP0/LAITDP0-closeout_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP0/LAITDP0-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP0/kickoff_prompts/LAITDP0-code.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP0/kickoff_prompts/LAITDP0-integ.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP0/kickoff_prompts/LAITDP0-test.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-closeout_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/LAITDP1-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-code.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-integ-core.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-integ-linux.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-integ-macos.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-integ-windows.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-integ.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP1/kickoff_prompts/LAITDP1-test.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-closeout_report.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/LAITDP2-spec.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-code.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ-core.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ-linux.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ-macos.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ-windows.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-integ.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/slices/LAITDP2/kickoff_prompts/LAITDP2-test.md delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/tasks.json delete mode 100644 docs/project_management/packs/draft/llm-and-agent-identity-tuple-and-deployment-posture/telemetry-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/README.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/compatibility-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/contract.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/fse_pre_planning.json delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-protocol-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/gateway-backend-adapter-schema-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/remediation-log.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/platform-parity-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/policy-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/review_surfaces.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/scope_brief.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-1-adapter-selection-boundary.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-2-adapter-protocol-and-schema.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam-3-parity-and-validation.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/seam_map.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-00-c-01-c-02-contract-definition.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-1-selection-evaluation-and-failure-taxonomy.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-2-status-owner-line-and-adr-authority-cleanup.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-1-adapter-selection-boundary/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-00-c-03-c-04-contract-definition.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-1-dispatch-lifecycle-and-owner-line.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-2-schema-subset-and-fail-closed-capability-rules.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-3-adoption-surfaces-and-verification.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-2-adapter-protocol-and-schema/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-1-platform-parity-and-runtime-boundary.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-2-compatibility-proof-and-adr-0040-decision.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-3-validation-gate-and-checkpoint-bundle.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threaded-seams/seam-3-parity-and-validation/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-backend-adapter-contract/threading.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/README.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/governance/seam-4-closeout.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/scope_brief.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-1-operator-boundary-and-command-contract.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-2-status-schema-and-policy-evaluation-surface.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-3-typed-runtime-and-platform-parity.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam-4-validation-and-cross-doc-lock-in.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/seam_map.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-00-operator-contract-definition.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-1-command-family-and-status-entrypoint.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-2-exit-taxonomy-and-wiring-semantics.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-3-ownership-and-archived-drift-normalization.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-1-operator-boundary-and-command-contract/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-00-status-schema-and-policy-contract-definition.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-1-status-json-envelope-and-wiring-boundary.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-2-policy-evaluation-and-trust-boundary.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-2-status-schema-and-policy-evaluation-surface/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-00-runtime-parity-contract-definition.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-1-typed-lifecycle-status-api-boundary.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-2-shell-consumption-and-platform-parity-evidence.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-3-typed-runtime-and-platform-parity/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/review.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/seam.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-1-manual-validation-and-owner-surface-audit.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-2-operator-docs-and-trace-alignment.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-3-plan-task-and-quality-gate-lock-in.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threaded-seams/seam-4-validation-and-cross-doc-lock-in/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership-fse/threading.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/contract.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/gateway-status-schema-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/plan.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/platform-parity-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/policy-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/quality_gate_report.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/session_log.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO0/SGBRO0-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO0/kickoff_prompts/SGBRO0-code.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO0/kickoff_prompts/SGBRO0-integ.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO0/kickoff_prompts/SGBRO0-test.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO1/SGBRO1-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO1/kickoff_prompts/SGBRO1-code.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO1/kickoff_prompts/SGBRO1-integ.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO1/kickoff_prompts/SGBRO1-test.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO2/SGBRO2-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO2/kickoff_prompts/SGBRO2-code.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO2/kickoff_prompts/SGBRO2-integ.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO2/kickoff_prompts/SGBRO2-test.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO3/SGBRO3-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO3/kickoff_prompts/SGBRO3-code.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO3/kickoff_prompts/SGBRO3-integ.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO3/kickoff_prompts/SGBRO3-test.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/SGBRO4-spec.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-code.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-integ-core.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-integ-linux.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-integ-macos.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-integ-windows.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-integ.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/slices/SGBRO4/kickoff_prompts/SGBRO4-test.md delete mode 100644 docs/project_management/packs/draft/substrate-gateway-boundary-and-runtime-ownership/tasks.json delete mode 100644 docs/project_management/packs/draft/world-deps-apt-provisioning/contract.md delete mode 100644 docs/project_management/packs/implemented/.gitkeep delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/README.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/contract.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/decision_register.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-4-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-5-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/governance/seam-6-closeout.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-1-manager-aware-contract-surface.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-2-world-manager-probe-support-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-3-pacman-schema-inventory-views.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-4-provisioning-routing-pacman-execution.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-5-runtime-fail-early-remediation.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam-6-validation-evidence-contract-reconciliation.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-1-manager-aware-contract-surface/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-1-manager-aware-contract-surface/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-1-manager-aware-contract-surface/slice-1-c-01-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-1-manager-aware-contract-surface/slice-2-authority-handoff-and-decisions.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-1-manager-aware-contract-surface/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-2-world-manager-probe-support-gate/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-2-world-manager-probe-support-gate/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-2-world-manager-probe-support-gate/slice-1-c-02-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-2-world-manager-probe-support-gate/slice-2-in-world-probe-and-support-gate-integration.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-2-world-manager-probe-support-gate/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-3-pacman-schema-inventory-views/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-3-pacman-schema-inventory-views/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-3-pacman-schema-inventory-views/slice-1-c-03-schema-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-3-pacman-schema-inventory-views/slice-2-inventory-validation-and-view-rendering.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-3-pacman-schema-inventory-views/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-4-provisioning-routing-pacman-execution/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-4-provisioning-routing-pacman-execution/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-4-provisioning-routing-pacman-execution/slice-1-c-04-provisioning-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-4-provisioning-routing-pacman-execution/slice-2-provisioning-routing-and-pacman-execution.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-4-provisioning-routing-pacman-execution/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-5-runtime-fail-early-remediation/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-5-runtime-fail-early-remediation/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-5-runtime-fail-early-remediation/slice-1-c-05-runtime-fail-early-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-5-runtime-fail-early-remediation/slice-2-runtime-fail-early-and-remediation.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-5-runtime-fail-early-remediation/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-6-validation-evidence-contract-reconciliation/review.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-6-validation-evidence-contract-reconciliation/seam.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-6-validation-evidence-contract-reconciliation/slice-1-platform-parity-and-playbook-evidence.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-6-validation-evidence-contract-reconciliation/slice-2-smoke-surfaces-and-shared-contract-reconciliation.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threaded-seams/seam-6-validation-evidence-contract-reconciliation/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/contract.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/decision_register.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/plan.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/session_log.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP0/NASP0-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP0/kickoff_prompts/NASP0-code.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP0/kickoff_prompts/NASP0-integ.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP0/kickoff_prompts/NASP0-test.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP1/NASP1-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP1/kickoff_prompts/NASP1-code.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP1/kickoff_prompts/NASP1-integ.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP1/kickoff_prompts/NASP1-test.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/NASP2-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-code.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-integ.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP2/kickoff_prompts/NASP2-test.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP3/NASP3-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP3/kickoff_prompts/NASP3-code.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP3/kickoff_prompts/NASP3-integ.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP3/kickoff_prompts/NASP3-test.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/NASP4-spec.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-code.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-integ-core.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-integ.md delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/slices/NASP4/kickoff_prompts/NASP4-test.md delete mode 100755 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/tasks.json delete mode 100644 docs/project_management/packs/implemented/add-non-apt-system-package-provisioning-support/world-deps-pacman-schema-spec.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/OR0-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/OR0-spec.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/OR1-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/OR1-spec.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/agent-hub-event-envelope-schema-spec.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/contract.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/decision_register.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/execution_preflight_report.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/impact_map.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR0-code.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR0-integ.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR0-test.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-code.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-integ-core.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-integ.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/kickoff_prompts/OR1-test.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/plan.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/session_log.md delete mode 100755 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/tasks.json delete mode 100644 docs/project_management/packs/implemented/agent-hub-concurrent-execution-output-routing/telemetry-spec.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/README.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-01-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-02-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-03-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-04-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-05-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-06-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/governance/seam-07-closeout.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-01-os-release-input-parser.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-02-family-mapping-reporting.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-03-explicit-override-selection.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-04-fallback-probe-failure-taxonomy.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-05-wrapper-doc-propagation.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-06-validation-evidence-topology.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam-07-checkpoint-downstream-handoff.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/slice-1-parser-input-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/slice-2-selected-input-resolution.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/slice-3-safe-parser-normalized-fields.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-01-os-release-input-parser/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-02-family-mapping-reporting/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-02-family-mapping-reporting/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-02-family-mapping-reporting/slice-1-family-table-availability-selection.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-02-family-mapping-reporting/slice-2-decision-line-contract-rendering.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-02-family-mapping-reporting/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/slice-1-flag-selector-precedence.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/slice-2-env-selector-selection.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/slice-3-explicit-failure-taxonomy.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-03-explicit-override-selection/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/slice-1-path-probe-selection.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/slice-2-multi-manager-warning-line.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/slice-3-no-manager-exit-4.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-04-fallback-probe-failure-taxonomy/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/slice-1-wrapper-exit-pass-through.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/slice-2-installation-doc-contract-propagation.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/slice-3-env-and-macos-hosted-doc-clarity.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-05-wrapper-doc-propagation/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-06-validation-evidence-topology/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-06-validation-evidence-topology/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-06-validation-evidence-topology/slice-1-repo-harness-and-smoke-wrapper-topology.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-06-validation-evidence-topology/slice-2-manual-evidence-and-macos-hosted-verification.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-06-validation-evidence-topology/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/review.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/seam.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/slice-1-checkpoint-evidence-aggregation.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/slice-2-macos-hosted-behavior-evidence.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/slice-3-downstream-handoff-publication.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/slice-4-pack-closeout-alignment.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threaded-seams/seam-07-checkpoint-downstream-handoff/slice-5-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/contract.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/decision_register.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/plan.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/session_log.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM0/BEDPM0-spec.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM0/kickoff_prompts/BEDPM0-code.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM0/kickoff_prompts/BEDPM0-integ.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM0/kickoff_prompts/BEDPM0-test.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM1/BEDPM1-spec.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM1/kickoff_prompts/BEDPM1-code.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM1/kickoff_prompts/BEDPM1-integ.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM1/kickoff_prompts/BEDPM1-test.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM2/BEDPM2-spec.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM2/kickoff_prompts/BEDPM2-code.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM2/kickoff_prompts/BEDPM2-integ.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM2/kickoff_prompts/BEDPM2-test.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/BEDPM3-spec.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-code.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-integ-core.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-integ.md delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/slices/BEDPM3/kickoff_prompts/BEDPM3-test.md delete mode 100755 docs/project_management/packs/implemented/best-effort-distro-package-manager/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/best-effort-distro-package-manager/tasks.json delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/README.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/seam-1-standard-version-dir-preflight-deterministic-remediation.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/seam-2-linux-dev-install-world-service-staging.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/seam-3-cross-platform-validation-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/review.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/seam.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/slice-1-contract-definition-runtime-preflight.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/slice-2-preflight-and-dry-run-parity.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/slice-3-remediation-and-state-ordering.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-1-standard-version-dir-preflight-deterministic-remediation/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-2-linux-dev-install-world-service-staging/review.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-2-linux-dev-install-world-service-staging/seam.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-2-linux-dev-install-world-service-staging/slice-1-c-04-contract-and-installer-scope.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-2-linux-dev-install-world-service-staging/slice-2-linux-staging-and-refresh-behavior.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-2-linux-dev-install-world-service-staging/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-3-cross-platform-validation-drift-guards/review.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-3-cross-platform-validation-drift-guards/seam.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-3-cross-platform-validation-drift-guards/slice-1-consumed-contract-revalidation-and-evidence-boundary.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-3-cross-platform-validation-drift-guards/slice-2-linux-proof-checkpoint-and-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threaded-seams/seam-3-cross-platform-validation-drift-guards/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/contract.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/decision_register.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/plan.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/session_log.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS0/DIWAS0-spec.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS0/kickoff_prompts/DIWAS0-code.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS0/kickoff_prompts/DIWAS0-integ.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS0/kickoff_prompts/DIWAS0-test.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/DIWAS1-spec.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-code.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-integ-core.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-integ.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/slices/DIWAS1/kickoff_prompts/DIWAS1-test.md delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/dev-install-world-service-staging/tasks.json delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/README.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/seam-1-execution-contract-surfaces.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/seam-2-interactive-terminal-loss-resilience.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/seam-3-cross-surface-parity-and-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/review.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/seam.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/slice-00-routing-and-tracing-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/slice-1-replay-routing-parity.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/slice-2-tracing-behavior-matrix.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/slice-3-contract-publication-surfaces.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-1-execution-contract-surfaces/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/review.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/seam.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/slice-00-abnormal-terminal-loss-contract-definition.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/slice-1-prompt-worker-unwind-and-exit-cause.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/slice-2-macos-revoke-regression-proof.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/slice-3-exit-semantics-publication-surfaces.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-2-interactive-terminal-loss-resilience/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/review.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/seam.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/slice-1-cross-surface-doc-lock-in.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/slice-2-wpep-playbook-and-smoke-alignment.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/slice-3-regression-and-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threaded-seams/seam-3-cross-surface-parity-and-drift-guards/slice-99-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/execution-surface-parity-hardening-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/LACP0-spec.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/LACP1-spec.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/SCHEMA.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/contract.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/decision_register.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/impact_map.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP0-code.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP0-integ.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP0-test.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-code.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-integ-core.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-integ.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/LACP1-test.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/kickoff_prompts/README.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/plan.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/session_log.md delete mode 100755 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/smoke/_core.sh delete mode 100755 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/llm_and_agent_config_policy_surface/tasks.json delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/README.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/seam-1-doctor-text-disable-attribution.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/seam-2-json-health-disable-attribution.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/review.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/seam.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/slice-1-contract-definition-disable-attribution.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/slice-2-shared-helper-and-winner-mapping-tests.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/slice-3-wire-doctor-output-and-parity-evidence.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-1-doctor-text-disable-attribution/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/review.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/seam.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/slice-1-contract-definition-json-health-disable-attribution.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/slice-2-doctor-json-top-level-schema-and-tests.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/slice-3-health-parity-and-disabled-path-plumbing.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threaded-seams/seam-2-json-health-disable-attribution/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/make-doctor-health-output-explain-why/tasks.json delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/README.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-4-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/governance/seam-5-closeout.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-1-snapshot-v3-net-allowlist-plumbing.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-3-host-config-opt-in-and-parity-env-plumbing.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-4-world-doctor-netfilter-status-observability.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam-5-verification-and-smoke-conformance.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/seam_map.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/review.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/seam.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/slice-1-publish-net-allowed-contract.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/slice-2-host-snapshot-and-worldspec-plumbing.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/slice-3-world-service-snapshot-routing.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-1-snapshot-v3-net-allowlist-plumbing/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants/review.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants/seam.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants/slice-1-fail-closed-netfilter-runtime.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants/slice-2-cgroup-attach-invariants-across-exec-paths.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-2-world-netfilter-fail-closed-and-cgroup-invariants/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/review.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/seam.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/slice-1-publish-world-net-filter-config-contract.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/slice-2-override-and-parity-env-plumbing.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/slice-3-operator-docs-and-routing-handoff.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-3-host-config-opt-in-and-parity-env-plumbing/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-4-world-doctor-netfilter-status-observability/review.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-4-world-doctor-netfilter-status-observability/seam.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-4-world-doctor-netfilter-status-observability/slice-1-publish-netfilter-status-contract.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-4-world-doctor-netfilter-status-observability/slice-2-thread-runtime-failure-state-into-doctor-surfaces.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-4-world-doctor-netfilter-status-observability/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/review.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/seam.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-1-regression-matrix-for-routing-and-doctor-contracts.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-2-privileged-and-macos-smoke-conformance.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threaded-seams/seam-5-verification-and-smoke-conformance/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/opt_in_world_netfilter_enforcement_v1_seams/threading.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/README.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/seam-1-persisted-platform-metadata-contract.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/seam-2-install-state-writer-reliability.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/seam-3-smoke-and-operator-conformance.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-1-persisted-platform-metadata-contract/review.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-1-persisted-platform-metadata-contract/seam.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-1-persisted-platform-metadata-contract/slice-1-persisted-schema-and-merge-contract.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-1-persisted-platform-metadata-contract/slice-2-canonical-path-and-authority-boundary.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-1-persisted-platform-metadata-contract/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-2-install-state-writer-reliability/review.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-2-install-state-writer-reliability/seam.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-2-install-state-writer-reliability/slice-1-successful-linux-write-matrix-and-no-write-boundaries.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-2-install-state-writer-reliability/slice-2-atomic-replace-and-warning-only-degradation.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-2-install-state-writer-reliability/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-3-smoke-and-operator-conformance/review.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-3-smoke-and-operator-conformance/seam.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-3-smoke-and-operator-conformance/slice-1-linux-smoke-conformance-and-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-3-smoke-and-operator-conformance/slice-2-operator-doc-and-checkpoint-evidence-alignment.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threaded-seams/seam-3-smoke-and-operator-conformance/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/contract.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/decision_register.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/install-state-schema-spec.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/plan.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/session_log.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM0/PDLDPM0-spec.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM0/kickoff_prompts/PDLDPM0-code.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM0/kickoff_prompts/PDLDPM0-integ.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM0/kickoff_prompts/PDLDPM0-test.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM1/PDLDPM1-spec.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM1/kickoff_prompts/PDLDPM1-code.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM1/kickoff_prompts/PDLDPM1-integ.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM1/kickoff_prompts/PDLDPM1-test.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/PDLDPM2-spec.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-code.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-integ.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/slices/PDLDPM2/kickoff_prompts/PDLDPM2-test.md delete mode 100644 docs/project_management/packs/implemented/persist-detected-linux-distro-pkg-manager/tasks.json delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/README.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/contract.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/decision_register.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/seam-1-durable-helper-bundle-staging-discovery.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/seam-2-managed-cleanup-protected-path-guard.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/seam-3-cross-platform-proof-drift-guards.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/review.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/seam.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/slice-1-freeze-durable-bundle-contracts.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/slice-2-dev-install-durable-bundle-staging.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/slice-3-helper-discovery-and-fail-closed-validation.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-1-durable-helper-bundle-staging-discovery/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-2-managed-cleanup-protected-path-guard/review.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-2-managed-cleanup-protected-path-guard/seam.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-2-managed-cleanup-protected-path-guard/slice-1-managed-only-cleanup-contract.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-2-managed-cleanup-protected-path-guard/slice-2-protected-path-refusal-and-reporting.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-2-managed-cleanup-protected-path-guard/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-3-cross-platform-proof-drift-guards/review.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-3-cross-platform-proof-drift-guards/seam.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-3-cross-platform-proof-drift-guards/slice-1-freeze-platform-evidence-boundaries.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-3-cross-platform-proof-drift-guards/slice-2-refresh-cross-platform-proof-surfaces.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threaded-seams/seam-3-cross-platform-proof-drift-guards/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/stabilize-dev-install-helper-discovery/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/contract.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/session_log.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/WDAP0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP0/kickoff_prompts/WDAP0-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/WDAP1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/slices/WDAP1/kickoff_prompts/WDAP1-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/world-deps-apt-provisioning/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH2-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/WDH3-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH0-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH0-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH1-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH2-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH2-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH2-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/kickoff_prompts/WDH3-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/session_log.md delete mode 100755 docs/project_management/packs/implemented/world-deps-host-visible-hardening/smoke/_core.sh delete mode 100755 docs/project_management/packs/implemented/world-deps-host-visible-hardening/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/implemented/world-deps-host-visible-hardening/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-deps-host-visible-hardening/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP0-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP1-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP2-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP2-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP3-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP3-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP4-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP4-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP5-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/WDP5-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/contract.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/README.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/bundles/node-runtime.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/asdf-node.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/bun.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/direnv.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/nftables.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/node.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/npm.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/nvm.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/python-build-deps.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/packages/volta.yaml delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/scripts/bun.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/scripts/nvm.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/deps_examples/scripts/volta.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/execution_preflight_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP0-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP0-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP1-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP1-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP2-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP3-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP3-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP3-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP4-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP4-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP4-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-code.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-integ.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/kickoff_prompts/WDP5-test.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/plan.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/session_log.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/smoke/_core.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-deps-packages-bundles-contract/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/README.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/governance/seam-4-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/seam-1-effective-config-classifier.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/seam-2-shim-doctor-disabled-aware-reporting.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/seam-3-health-disabled-aware-summary.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/seam-4-cross-platform-conformance.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-1-effective-config-classifier/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-1-effective-config-classifier/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-1-effective-config-classifier/slice-1-contract-definition-c-01.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-1-effective-config-classifier/slice-2-integrate-classifier-and-tests.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-1-effective-config-classifier/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-2-shim-doctor-disabled-aware-reporting/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-2-shim-doctor-disabled-aware-reporting/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-2-shim-doctor-disabled-aware-reporting/slice-1-contract-definition-c-02-c-03-c-04.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-2-shim-doctor-disabled-aware-reporting/slice-2-disabled-path-rendering-and-tests.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-2-shim-doctor-disabled-aware-reporting/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-3-health-disabled-aware-summary/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-3-health-disabled-aware-summary/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-3-health-disabled-aware-summary/slice-1-contract-definition-c-05.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-3-health-disabled-aware-summary/slice-2-disabled-summary-docs-and-tests.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-3-health-disabled-aware-summary/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-4-cross-platform-conformance/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-4-cross-platform-conformance/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-4-cross-platform-conformance/slice-1-platform-matrix-and-playbook.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-4-cross-platform-conformance/slice-2-smoke-checkpoint-and-revalidation.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threaded-seams/seam-4-cross-platform-conformance/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/contract.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/plan.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/session_log.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD0/WDD0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD0/kickoff_prompts/WDD0-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD0/kickoff_prompts/WDD0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD0/kickoff_prompts/WDD0-test.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD1/WDD1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD1/kickoff_prompts/WDD1-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD1/kickoff_prompts/WDD1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD1/kickoff_prompts/WDD1-test.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/WDD2-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/slices/WDD2/kickoff_prompts/WDD2-test.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-disabled-diagnostics/world-disabled-diagnostics-json-schema-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/README.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/governance/pack-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/governance/remediation-log.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/governance/seam-1-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/governance/seam-2-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/governance/seam-3-closeout.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/review_surfaces.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/scope_brief.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/seam-1-effective-disable-attribution-foundation.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/seam-2-replay-attribution-runtime-surfaces.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/seam-3-parity-and-contract-lock-in.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/seam_map.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-1-effective-disable-attribution-foundation/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-1-effective-disable-attribution-foundation/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-1-effective-disable-attribution-foundation/slice-1-contract-definition-effective-disable-attribution.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-1-effective-disable-attribution-foundation/slice-2-deterministic-precedence-redaction-tests.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-1-effective-disable-attribution-foundation/slice-3-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/slice-1-contract-definition-replay-attribution-runtime-surfaces.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/slice-2-origin-summary-and-host-warning-wiring.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/slice-3-replay-strategy-telemetry-and-omission-rules.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-2-replay-attribution-runtime-surfaces/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/review.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/seam.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/slice-1-regression-coverage-and-trace-locks.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/slice-2-docs-and-playbook-alignment.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/slice-3-smoke-wrapper-and-parity-evidence.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threaded-seams/seam-3-parity-and-contract-lock-in/slice-4-seam-exit-gate.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution-fse/threading.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/contract.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/plan.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/alignment_report.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/minimal_spec_draft.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/pre-planning/workstream_triage.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/session_log.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA0/WDRA0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA0/kickoff_prompts/WDRA0-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA0/kickoff_prompts/WDRA0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA0/kickoff_prompts/WDRA0-test.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA1/WDRA1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA1/kickoff_prompts/WDRA1-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA1/kickoff_prompts/WDRA1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA1/kickoff_prompts/WDRA1-test.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/WDRA2-spec.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-code.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-integ-windows.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-integ.md delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/slices/WDRA2/kickoff_prompts/WDRA2-test.md delete mode 100755 docs/project_management/packs/implemented/world-disabled-reason-attribution/smoke/linux-smoke.sh delete mode 100755 docs/project_management/packs/implemented/world-disabled-reason-attribution/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/smoke/windows-smoke.ps1 delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/tasks.json delete mode 100644 docs/project_management/packs/implemented/world-disabled-reason-attribution/telemetry-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS0-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS0-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS1-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS1-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS2-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS2-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS3-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS3-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS4-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS4-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS5-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS5-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS6-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS6-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS7-closeout_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/WS7-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/ci_checkpoint_plan.md delete mode 100644 docs/project_management/packs/implemented/world-sync/contract.md delete mode 100644 docs/project_management/packs/implemented/world-sync/decision_register.md delete mode 100644 docs/project_management/packs/implemented/world-sync/execution_preflight_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/filesystem-semantics-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/impact_map.md delete mode 100644 docs/project_management/packs/implemented/world-sync/internal-git-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/CP1-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/CP2-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/CP3-ci-checkpoint.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/F0-exec-preflight.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/FZ-feature-cleanup.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS0-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS0-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS0-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS1-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS1-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS1-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS2-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS3-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS3-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS3-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS4-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS4-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS4-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS5-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS6-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS6-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS6-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-code.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-integ-core.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-integ-linux.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-integ-macos.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-integ.md delete mode 100644 docs/project_management/packs/implemented/world-sync/kickoff_prompts/WS7-test.md delete mode 100644 docs/project_management/packs/implemented/world-sync/manual_testing_playbook.md delete mode 100644 docs/project_management/packs/implemented/world-sync/plan.md delete mode 100644 docs/project_management/packs/implemented/world-sync/platform-parity-spec.md delete mode 100644 docs/project_management/packs/implemented/world-sync/quality_gate_report.md delete mode 100644 docs/project_management/packs/implemented/world-sync/session_log.md delete mode 100644 docs/project_management/packs/implemented/world-sync/smoke/linux-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-sync/smoke/macos-smoke.sh delete mode 100644 docs/project_management/packs/implemented/world-sync/spec_manifest.md delete mode 100644 docs/project_management/packs/implemented/world-sync/tasks.json delete mode 100644 docs/project_management/packs/queued/.gitkeep delete mode 100644 docs/project_management/packs/sequencing.json delete mode 100644 docs/project_management/packs/superseded/.gitkeep delete mode 100644 docs/project_management/system/README.md delete mode 100644 docs/project_management/system/USER_GUIDE.md delete mode 100644 docs/project_management/system/fse/prompts/planning/ci_checkpoint_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/impact_map_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/min_spec_draft_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/post_full_planning_reconcile_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/pre_planning_slice_reconcile_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/pre_planning_wrapper.md delete mode 100644 docs/project_management/system/fse/prompts/planning/spec_manifest_agent.md delete mode 100644 docs/project_management/system/fse/prompts/planning/workstream_triage_agent.md delete mode 100644 docs/project_management/system/fse/scripts/planning/codex_events_to_run_state.py delete mode 100755 docs/project_management/system/fse/scripts/planning/micro_lint.sh delete mode 100644 docs/project_management/system/fse/scripts/planning/pm_paths.py delete mode 100644 docs/project_management/system/fse/scripts/planning/pm_pws_index_extract.py delete mode 100755 docs/project_management/system/fse/scripts/planning/pre_full_planning_converge.sh delete mode 100644 docs/project_management/system/fse/scripts/planning/pre_full_planning_convergence.py delete mode 100755 docs/project_management/system/fse/scripts/planning/pre_planning_research_orchestrate.sh delete mode 100755 docs/project_management/system/fse/scripts/planning/run_planning_agent.sh delete mode 100755 docs/project_management/system/fse/scripts/planning/scaffold_pre_planning_pack.sh delete mode 100644 docs/project_management/system/fse/scripts/planning/validate_ci_checkpoint_plan.py delete mode 100644 docs/project_management/system/fse/scripts/planning/validate_impact_map.py delete mode 100644 docs/project_management/system/fse/scripts/planning/validate_pws_index.py delete mode 100644 docs/project_management/system/fse/scripts/planning/validate_slice_inventory_coherence.py delete mode 100644 docs/project_management/system/fse/scripts/planning/validate_spec_manifest.py delete mode 100644 docs/project_management/system/fse/scripts/planning/wrapper_alignment_report.py delete mode 100644 docs/project_management/system/fse/standards/ci/PLANNING_CI_CHECKPOINT_STANDARD.md delete mode 100644 docs/project_management/system/fse/standards/planning/PLANNING_IMPACT_MAP_STANDARD.md delete mode 100644 docs/project_management/system/fse/standards/planning/PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md delete mode 100644 docs/project_management/system/fse/standards/planning/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md delete mode 100644 docs/project_management/system/fse/standards/planning/PLANNING_SPEC_DETERMINATION_STANDARD.md delete mode 100644 docs/project_management/system/fse/templates/planning_pack/ci_checkpoint_plan.md.tmpl delete mode 100644 docs/project_management/system/fse/templates/planning_pack/impact_map.md.tmpl delete mode 100644 docs/project_management/system/fse/templates/planning_pack/spec_manifest.md.tmpl delete mode 100644 docs/project_management/system/prompts/discovery/adr_lockdown.md delete mode 100644 docs/project_management/system/prompts/discovery/brainstorm_to_adr.md delete mode 100644 docs/project_management/system/prompts/discovery/feature_discovery_coach.md delete mode 100644 docs/project_management/system/prompts/planning/ci_checkpoint_agent.md delete mode 100644 docs/project_management/system/prompts/planning/final_alignment_pass_prompt_template.md delete mode 100644 docs/project_management/system/prompts/planning/impact_map_agent.md delete mode 100644 docs/project_management/system/prompts/planning/min_spec_draft_agent.md delete mode 100644 docs/project_management/system/prompts/planning/planning_kickoff_prompt.md delete mode 100644 docs/project_management/system/prompts/planning/post_full_planning_reconcile_agent.md delete mode 100644 docs/project_management/system/prompts/planning/pre_planning_slice_reconcile_agent.md delete mode 100644 docs/project_management/system/prompts/planning/pre_planning_wrapper.md delete mode 100644 docs/project_management/system/prompts/planning/pws_contract_agent.md delete mode 100644 docs/project_management/system/prompts/planning/pws_generic_agent.md delete mode 100644 docs/project_management/system/prompts/planning/pws_tasks_checkpoints_agent.md delete mode 100644 docs/project_management/system/prompts/planning/quality_gate_remediation.md delete mode 100644 docs/project_management/system/prompts/planning/quality_gate_reviewer.md delete mode 100644 docs/project_management/system/prompts/planning/research_planning_prompt_template.md delete mode 100644 docs/project_management/system/prompts/planning/spec_manifest_agent.md delete mode 100644 docs/project_management/system/prompts/planning/workstream_triage_agent.md delete mode 100644 docs/project_management/system/prompts/triad_wrappers/triad_integration_wrapper.md delete mode 100644 docs/project_management/system/prompts/triad_wrappers/triad_unified_wrapper_checkpoint_aware.md delete mode 100644 docs/project_management/system/prompts/triad_wrappers/triad_unified_wrapper_checkpoint_resume_safe.md delete mode 100644 docs/project_management/system/prompts/triad_wrappers/triad_wrapper.md delete mode 100644 docs/project_management/system/schemas/proving_run_closeout.schema.json delete mode 100644 docs/project_management/system/schemas/tasks.schema.json delete mode 100644 docs/project_management/system/schemas/work_lift_model.v1.json delete mode 100644 docs/project_management/system/schemas/work_lift_vector.schema.json delete mode 100644 docs/project_management/system/scripts/execution/prepare_proving_run_closeout.py delete mode 100644 docs/project_management/system/scripts/execution/tests/test_prepare_proving_run_closeout.py delete mode 100644 docs/project_management/system/scripts/planning/archive_project_management_dir.py delete mode 100644 docs/project_management/system/scripts/planning/check_adr_exec_summary.py delete mode 100644 docs/project_management/system/scripts/planning/codex_events_to_run_state.py delete mode 100755 docs/project_management/system/scripts/planning/ensure_kickoff_prompt_sentinel.py delete mode 100755 docs/project_management/system/scripts/planning/full_planning_orchestrate.sh delete mode 100644 docs/project_management/system/scripts/planning/impact_map_emit_json_v1.md delete mode 100644 docs/project_management/system/scripts/planning/impact_map_touch_counts.py delete mode 100644 docs/project_management/system/scripts/planning/impact_map_touch_counts_v1.md delete mode 100644 docs/project_management/system/scripts/planning/lint.ps1 delete mode 100755 docs/project_management/system/scripts/planning/lint.sh delete mode 100755 docs/project_management/system/scripts/planning/micro_lint.sh delete mode 100644 docs/project_management/system/scripts/planning/migrate_legacy_adrs_to_registry.py delete mode 100755 docs/project_management/system/scripts/planning/migrate_legacy_doc_edit_sentinel.py delete mode 100644 docs/project_management/system/scripts/planning/migrate_slice_directories.py delete mode 100644 docs/project_management/system/scripts/planning/migrate_worktree_feature_dir.py delete mode 100644 docs/project_management/system/scripts/planning/new_feature.ps1 delete mode 100755 docs/project_management/system/scripts/planning/new_feature.sh delete mode 100644 docs/project_management/system/scripts/planning/parse_allowlist_request.py delete mode 100755 docs/project_management/system/scripts/planning/planning_pipeline_orchestrate.sh delete mode 100644 docs/project_management/system/scripts/planning/pm_lift.py delete mode 100644 docs/project_management/system/scripts/planning/pm_lift_emit_json_v1.md delete mode 100644 docs/project_management/system/scripts/planning/pm_lift_report.py delete mode 100644 docs/project_management/system/scripts/planning/pm_lift_strict_check.py delete mode 100644 docs/project_management/system/scripts/planning/pm_paths.py delete mode 100644 docs/project_management/system/scripts/planning/pm_pws_index_extract.py delete mode 100644 docs/project_management/system/scripts/planning/pm_pws_plan.py delete mode 100755 docs/project_management/system/scripts/planning/post_full_planning_converge.sh delete mode 100644 docs/project_management/system/scripts/planning/post_full_planning_convergence.py delete mode 100755 docs/project_management/system/scripts/planning/pre_full_planning_converge.sh delete mode 100644 docs/project_management/system/scripts/planning/pre_full_planning_convergence.py delete mode 100755 docs/project_management/system/scripts/planning/pre_planning_research_orchestrate.sh delete mode 100755 docs/project_management/system/scripts/planning/run_planning_agent.sh delete mode 100755 docs/project_management/system/scripts/planning/run_pws_agent.sh delete mode 100755 docs/project_management/system/scripts/planning/scaffold_pre_planning_pack.sh delete mode 100644 docs/project_management/system/scripts/planning/tests/test_check_adr_exec_summary.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_full_planning_orchestrate.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_impact_map_touch_counts.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_micro_lint.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_parse_allowlist_request.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_planning_pipeline_orchestrate.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_emit_json_contract.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_goldens_from_impact_map.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_goldens_intake.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_negative_cases.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_report.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_strict_check.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_lift_vector_schema_validation.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_pws_index_extract.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pm_pws_plan.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_post_full_planning_convergence.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pre_full_planning_convergence.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_pre_planning_research_orchestrate.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_run_planning_agent.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_ci_checkpoint_plan.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_execution_touchset_coherence.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_impact_map_emit_json_contract.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_pws_index.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_slice_inventory_coherence.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_slice_spec_doc_only.py delete mode 100644 docs/project_management/system/scripts/planning/tests/test_validate_spec_manifest.py delete mode 100644 docs/project_management/system/scripts/planning/validate_ci_checkpoint_plan.py delete mode 100644 docs/project_management/system/scripts/planning/validate_execution_touchset_coherence.py delete mode 100644 docs/project_management/system/scripts/planning/validate_impact_map.py delete mode 100644 docs/project_management/system/scripts/planning/validate_pws_index.py delete mode 100644 docs/project_management/system/scripts/planning/validate_slice_inventory_coherence.py delete mode 100644 docs/project_management/system/scripts/planning/validate_slice_spec_doc_only.py delete mode 100755 docs/project_management/system/scripts/planning/validate_slice_specs.py delete mode 100644 docs/project_management/system/scripts/planning/validate_spec_manifest.py delete mode 100755 docs/project_management/system/scripts/planning/validate_tasks_json.py delete mode 100644 docs/project_management/system/scripts/planning/wrapper_alignment_report.py delete mode 100755 docs/project_management/system/scripts/triad/codex_pidfiles.sh delete mode 100755 docs/project_management/system/scripts/triad/feature_cleanup.sh delete mode 100755 docs/project_management/system/scripts/triad/mark_noop_platform_fixes_completed.sh delete mode 100755 docs/project_management/system/scripts/triad/orch_ensure.sh delete mode 100755 docs/project_management/system/scripts/triad/task_finish.sh delete mode 100755 docs/project_management/system/scripts/triad/task_start.sh delete mode 100755 docs/project_management/system/scripts/triad/task_start_complete.sh delete mode 100755 docs/project_management/system/scripts/triad/task_start_integ_final.sh delete mode 100755 docs/project_management/system/scripts/triad/task_start_pair.sh delete mode 100755 docs/project_management/system/scripts/triad/task_start_platform_fixes.sh delete mode 100644 docs/project_management/system/standards/MANIFEST.yaml delete mode 100644 docs/project_management/system/standards/README.md delete mode 100644 docs/project_management/system/standards/adr/ADR_STANDARD_AND_TEMPLATE.md delete mode 100644 docs/project_management/system/standards/adr/DRAFT_ADR_LOCKDOWN_STANDARD.md delete mode 100644 docs/project_management/system/standards/adr/EXECUTIVE_SUMMARY_STANDARD.md delete mode 100644 docs/project_management/system/standards/ci/PLANNING_CI_CHECKPOINT_STANDARD.md delete mode 100644 docs/project_management/system/standards/ci/PLATFORM_INTEGRATION_AND_CI.md delete mode 100644 docs/project_management/system/standards/execution/EXECUTION_PREFLIGHT_GATE_STANDARD.md delete mode 100644 docs/project_management/system/standards/execution/PROVING_RUN_CLOSEOUT_PREPARATION_STANDARD.md delete mode 100644 docs/project_management/system/standards/execution/SLICE_CLOSEOUT_GATE_STANDARD.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_IMPACT_MAP_STANDARD.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_LINT_CHECKLIST.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_README.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_SPEC_DETERMINATION_STANDARD.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_WORKFLOW_OVERVIEW.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_WORK_LIFT_ADVISORY.md delete mode 100644 docs/project_management/system/standards/planning/PLANNING_WORK_LIFT_STRICT_MODE.md delete mode 100644 docs/project_management/system/standards/shared/CONTRACT_SURFACE_STANDARD.md delete mode 100644 docs/project_management/system/standards/shared/EXIT_CODE_TAXONOMY.md delete mode 100644 docs/project_management/system/standards/shared/SECRETS_DELIVERY_CHANNEL_RUBRIC.md delete mode 100644 docs/project_management/system/standards/shared/WORK_LIFT_MODEL_V1_GOLDENS.md delete mode 100644 docs/project_management/system/standards/shared/WORK_LIFT_RUBRIC.md delete mode 100644 docs/project_management/system/standards/shared/rustStandards.md delete mode 100644 docs/project_management/system/standards/triad/TASK_TRIADS_AND_FEATURE_SETUP.md delete mode 100644 docs/project_management/system/standards/triad/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md delete mode 100644 docs/project_management/system/standards/triad/TRIAD_WORKFLOW_CROSS_PLATFORM_INTEG.md delete mode 100644 docs/project_management/system/templates/adr/ADR_TEMPLATE.md delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_ci_checkpoint.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_code.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_exec_preflight.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_feature_cleanup.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_integ.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_integ_core.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_integ_final.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_integ_platform.md.tmpl delete mode 100644 docs/project_management/system/templates/kickoff/kickoff_test.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/PLANNING_GATE_REPORT_TEMPLATE.md delete mode 100644 docs/project_management/system/templates/planning_pack/PLANNING_SESSION_LOG_TEMPLATE.md delete mode 100644 docs/project_management/system/templates/planning_pack/ci_checkpoint_plan.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/contract.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/execution_preflight_report.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/impact_map.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/plan.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/session_log.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/slice_closeout_report.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/slice_spec.v2.md.tmpl delete mode 100644 docs/project_management/system/templates/planning_pack/spec_manifest.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/README.md delete mode 100644 docs/project_management/system/templates/spec/cli-workflows-ux-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/compatibility-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/env-vars-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/filesystem-semantics-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/platform-parity-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/policy-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/protocol-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/schema-spec.md.tmpl delete mode 100644 docs/project_management/system/templates/spec/telemetry-spec.md.tmpl rename docs/{project_management/intake => }/work_items/README.md (100%) rename docs/{project_management/intake => }/work_items/arching_lark_work_item_intake.md (100%) rename docs/{project_management/intake => }/work_items/implemented/aligning_otter_work_item_intake.md (100%) rename docs/{project_management/intake => }/work_items/implemented/taming_tapir_fact_finding.md (100%) rename docs/{project_management/intake => }/work_items/implemented/taming_tapir_work_item_intake.md (100%) rename docs/{project_management/intake => }/work_items/implemented/untangling_lemur_work_item_intake.md (100%) rename docs/{project_management/intake => }/work_items/shedding_gecko_work_item_intake.md (100%) diff --git a/.gitignore b/.gitignore index e74e1b852..35b7f3083 100644 --- a/.gitignore +++ b/.gitignore @@ -30,3 +30,4 @@ docs/project_management/packs/**/logs/ .gitnexus .orchestrator-* .substrate +archive \ No newline at end of file diff --git a/.rgignore b/.rgignore new file mode 100644 index 000000000..8ff54e8c8 --- /dev/null +++ b/.rgignore @@ -0,0 +1 @@ +archive \ No newline at end of file diff --git a/FSE_PRE_PLANNING_DEPENDENCY_GRAPH.md b/FSE_PRE_PLANNING_DEPENDENCY_GRAPH.md deleted file mode 100644 index e9f9076aa..000000000 --- a/FSE_PRE_PLANNING_DEPENDENCY_GRAPH.md +++ /dev/null @@ -1,208 +0,0 @@ -# FSE Pre-Planning Dependency Graph - -## Status - -Proposed dependency and overlap contract for a v2.5-aligned replacement of the current FSE pre-planning pipeline. - -## Grounding - -This graph is based on: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/planning/PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/scripts/planning/pre_planning_research_orchestrate.sh` -- `/Users/spensermcconnell/.agents/skills/feature-seam-extractor-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/threaded-seam-decomposer-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/seam-promotion-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/seam-execution-v2-5/SKILL.md` - -## Core Rule - -Research may overlap on handoff files. Canonical writes may not overlap on the same output and may not treat handoff content as final truth once an upstream canonical file exists. - -Hyper-focused helper stages are allowed when they stay research-only. They exist to keep agent responsibility narrow without multiplying canonical truth surfaces. - -## Stage Graph - -```mermaid -flowchart LR - PP0["PP0 bootstrap"] -. research handoff .-> PP1["PP1 scope brief"] - PP0 -. research handoff .-> PP1A["PP1a scope intake (research only)"] - PP0 -. research handoff .-> PP1B["PP1b surface authority (research only)"] - PP1A -. helper handoff .-> PP1 - PP1B -. helper handoff .-> PP1 - PP1 -. handoff only .-> PP15["PP1.5 spec manifest"] - PP1 -. handoff only .-> PP2["PP2 seam map and seam briefs"] - PP15 -. handoff only .-> PP2 - PP2 -. handoff only .-> PP3A["PP3a threading analysis (research only)"] - PP2 -. handoff only .-> PP3B["PP3b verification cadence (research only)"] - PP3A -. helper handoff .-> PP3["PP3 threading"] - PP3B -. helper handoff .-> PP3 - PP2 -. handoff only .-> PP3["PP3 threading"] - PP2 -. handoff only .-> PP4["PP4 review surfaces"] - PP3 -. handoff only .-> PP5["PP5 governance"] - PP4 -. handoff only .-> PP6["PP6 README and validation"] - PP5 -. handoff only .-> PP6 - - PP1 -->|scope_brief.md| PP2 - PP1 -->|scope_brief.md| PP15 - PP15 -->|spec_manifest.md| PP2 - PP15 -->|spec_manifest.md| PP3 - PP2 -->|seam_map.md + seam briefs| PP3 - PP2 -->|seam_map.md + seam briefs| PP4 - PP2 -->|seam IDs| PP5 - PP3 -->|threading.md| PP4 - PP3 -->|threading.md| PP5 - PP3 -->|threading.md| PP6 - PP4 -->|review_surfaces.md| PP6 - PP5 -->|governance docs| PP6 -``` - -Interpretation: - -- dashed edges are allowed early-research overlap -- solid edges are canonical-write dependencies -- PP6 is the only pack-close stage -- PP1a, PP1b, PP3a, and PP3b are helper stages with no canonical outputs - -## Canonical Output Ownership - -| Stage | Canonical outputs | Canonical truth type | -| --- | --- | --- | -| PP0 | none | wrapper metadata only | -| PP1a | none | research-only helper | -| PP1b | none | research-only helper | -| PP1 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///scope_brief.md` | pack backbone | -| PP1.5 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///spec_manifest.md` | domain and authored-doc-class inventory | -| PP2 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam_map.md`, `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam--.md` | seam control plane | -| PP3a | none | research-only helper | -| PP3b | none | research-only helper | -| PP3 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threading.md` | dependency and contract control plane | -| PP4 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///review_surfaces.md` | orientation surface | -| PP5 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/remediation-log.md`, `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/seam--closeout.md`, `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/pack-closeout.md` | governance scaffold | -| PP6 | `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///README.md` | pack landing page | - -## Research-Only Output Ownership - -Every stage may own only its own research-only directory: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp0-bootstrap/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1a-scope-intake/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1b-surface-authority/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1-scope/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1_5-spec-manifest/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp2-seams/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3a-threading/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3b-verification-cadence/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3-threading/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp4-review/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp5-governance/**` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp6-readme/**` - -Research-only outputs may include: - -- `scratch.md` -- `handoff.md` -- `staged/**` -- compatibility-only renderings of the old six pre-planning artifacts - -Research-only outputs are never authoritative once the corresponding canonical file exists. - -## Stage-by-Stage Dependencies - -| Stage | May start research when | Canonical write requires | Canonical consumers | -| --- | --- | --- | --- | -| PP0 | operator starts the lane | ADR set resolved and feature dir exists | PP1 | -| PP1a | PP0 handoff exists | none; research only | PP1 | -| PP1b | PP0 handoff exists | none; research only | PP1 | -| PP1 | PP0 handoff exists | stable input set from PP0 plus any helper research it chooses to consume | PP1.5, PP2 | -| PP1.5 | PP1 handoff exists | canonical `scope_brief.md` | PP2, PP3 | -| PP2 | PP1 and PP1.5 handoffs exist | canonical `scope_brief.md` and `spec_manifest.md` | PP3, PP4, PP5 | -| PP3a | PP2 handoff exists | none; research only | PP3 | -| PP3b | PP2 handoff exists | none; research only | PP3 | -| PP3 | PP2 handoff exists | canonical `spec_manifest.md`, `seam_map.md`, and seam briefs plus any helper research it chooses to consume | PP4, PP5, PP6 | -| PP4 | PP2 handoff exists | canonical `seam_map.md`, seam briefs, and `threading.md` | PP6 | -| PP5 | PP3 handoff exists | canonical seam briefs and `threading.md` | PP6, later seam promotion | -| PP6 | PP4 and PP5 handoffs exist | all required canonical seam-pack files | downstream v2.5 tooling | - -## Allowed Overlap Rules - -Allowed: - -- PP1a and PP1b may run in parallel from the PP0 handoff as long as they stay research-only. -- PP1.5 may begin spec-class and authored-doc research from the PP1 handoff before canonical promotion. -- PP2 may research seam candidates from the PP1 handoff before `scope_brief.md` is promoted. -- PP3a and PP3b may run in parallel from the PP2 handoff as long as they stay research-only. -- PP3 may research thread candidates from the PP2 handoff before seam files are promoted. -- PP4 may draft diagrams from the PP2 handoff while PP3 is still refining `threading.md`. -- PP5 may draft remediation and closeout structure from PP3 handoff material before canonical governance write. -- PP6 may draft the pack summary from PP4 and PP5 handoffs before final validation. - -Not allowed: - -- PP2 writing canonical seam files before `scope_brief.md` exists. -- PP3 writing `threading.md` from PP2 handoff alone. -- PP4 writing `review_surfaces.md` before `threading.md` is canonical. -- PP5 writing governance docs before thread IDs and seam IDs are canonical. -- PP6 writing `README.md` before all downstream-consumed files exist. -- any stage writing another stage's canonical outputs. - -## Canonical vs Research-Only Decisions - -Canonical: - -- anything that defines which authored spec, contract, schema, policy, parity, compatibility, or validation docs must exist at all -- anything directly consumed by `/Users/spensermcconnell/.agents/skills/threaded-seam-decomposer-v2-5/SKILL.md` -- anything directly consumed by `/Users/spensermcconnell/.agents/skills/seam-promotion-v2-5/SKILL.md` -- anything that names stable seam IDs, thread IDs, contract ownership, horizon posture, or governance blockers - -Research-only: - -- scratch reasoning -- early overlap handoff summaries -- staged candidates before promotion -- compatibility views that preserve the old six-doc vocabulary during migration -- speculative restructuring notes that were not accepted into canonical seam or thread truth - -## Upstream and Downstream Contract Edges - -### Upstream inputs into this lane - -- ADRs -- current repo state -- queued, draft, active, and archived planning packs that touch the same surfaces -- existing canonical docs under `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/` when the feature intersects an existing durable contract - -### Downstream consumers of this lane - -- `/Users/spensermcconnell/.agents/skills/threaded-seam-decomposer-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/seam-promotion-v2-5/SKILL.md` - -Not yet in scope: - -- `/Users/spensermcconnell/.agents/skills/seam-execution-v2-5/SKILL.md` because that skill requires `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threaded-seams/**`, which this lane must not create - -## Legacy Six-Artifact Compatibility - -If migration support is needed, the old artifact names may still be rendered under `logs/pre-planning-v2_5/compat/`. They are derived views only: - -- `spec_manifest.md` remains canonical and does not move into compatibility-only status -- `impact_map.md` derives from `seam_map.md`, `threading.md`, and `review_surfaces.md` -- `minimal_spec_draft.md` derives from `scope_brief.md`, `seam_map.md`, and seam briefs -- `ci_checkpoint_plan.md` derives from `threading.md` and governance stubs -- `workstream_triage.md` derives from `threading.md` -- `alignment_report.md` derives from governance docs and `README.md` - -Those compatibility artifacts must never be read as canonical inputs by downstream v2.5 tooling. - -## Readiness Gate for the Whole Pipeline - -The pipeline is considered complete only when: - -- every required v2.5 seam-pack file exists -- `spec_manifest.md` exists and defines the required authored-doc classes and canonical contract homes -- exactly one `active` seam and one `next` seam exist by default -- no `threaded-seams/` directory exists -- no slice or subslice files exist -- thread vocabulary matches v2.5 -- governance docs exist but do not claim post-exec truth -- the pack is directly consumable by the threaded seam decomposer without reading a legacy pre-planning file diff --git a/FSE_PRE_PLANNING_STAGE_OUTPUT_CONTRACT.md b/FSE_PRE_PLANNING_STAGE_OUTPUT_CONTRACT.md deleted file mode 100644 index fc4c072c4..000000000 --- a/FSE_PRE_PLANNING_STAGE_OUTPUT_CONTRACT.md +++ /dev/null @@ -1,599 +0,0 @@ -# FSE Pre-Planning Stage Output Contract - -## Status - -Proposed replacement contract for the current pre-planning lane under `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse`. - -## Grounding - -This proposal is anchored to the current FSE pre-planning standards and prompts: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/planning/PLANNING_PRE_PLANNING_RESEARCH_WRAPPER.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/planning/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/planning/PLANNING_SPEC_DETERMINATION_STANDARD.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/planning/PLANNING_IMPACT_MAP_STANDARD.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/system/fse/standards/ci/PLANNING_CI_CHECKPOINT_STANDARD.md` - -It is also grounded in the v2.5 downstream skill contracts that consume or advance a seam pack: - -- `/Users/spensermcconnell/.agents/skills/feature-seam-extractor-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/threaded-seam-decomposer-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/seam-promotion-v2-5/SKILL.md` -- `/Users/spensermcconnell/.agents/skills/seam-execution-v2-5/SKILL.md` - -## Intent - -The revised pre-planning lane keeps the current narrow-agent, overlap-safe operating model, but the canonical tracked output is no longer a six-doc pre-planning pack. The canonical tracked output is a real v2.5 seam pack that downstream v2.5 tooling can consume without a translation pass. - -The control-plane target for one feature is: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///README.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///scope_brief.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///spec_manifest.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam_map.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threading.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///review_surfaces.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam--.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/remediation-log.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/seam--closeout.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/pack-closeout.md` - -The pre-planning lane must not create: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threaded-seams/` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threaded-seams/**/review.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threaded-seams/**/slice-*.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threaded-seams/**/subslice-*.md` -- legacy canonical pre-planning outputs under `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///pre-planning/*.md` - -## Canonical and Research-Only Lanes - -Canonical truth: - -- the v2.5 seam-pack files listed above -- only the owning stage may write its canonical outputs -- downstream stages must re-read canonical outputs before final promotion - -Research-only evidence: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5//scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5//handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5//staged/**` -- optional compatibility renderings of the old six artifacts, but only under `logs/pre-planning-v2_5/compat/` - -Research-only outputs may overlap aggressively. Canonical writes must remain single-owner and gate-checked. - -## Hyper-Focused Agent Rule - -The pipeline keeps canonical ownership narrow and singular, but it may use helper research stages when that keeps each agent tightly scoped. - -Rules: - -- helper stages may write only research-only outputs under their own `logs/pre-planning-v2_5//` subtree -- helper stages may not write canonical seam-pack files -- the owning canonical stage must re-read and reconcile helper outputs before promotion -- helper stages do not create a second control plane - -Recommended helper stages: - -- `pp1a-scope-intake`: restates user, goal, success, constraints, and risk posture -- `pp1b-surface-authority`: derives exact durable contract homes, doc ownership, and explicit surface inventory -- `pp3a-threading`: derives contract registry, thread registry, dependency graph, and critical path -- `pp3b-verification-cadence`: derives checkpoint intent, platform proof grouping, and any conformance-heavy workstream notes - -These helpers exist to preserve narrow-agent focus. They do not change the canonical file ownership listed below. - -## Stage Contract - -### PP0 - Bootstrap and Input Freeze - -Purpose: - -- resolve the ADR set -- create or confirm the feature pack root -- establish the exact run input set for downstream stages - -Owned canonical outputs: - -- none in the v2.5 seam pack -- existing metadata such as `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///fse_pre_planning.json` may remain as wrapper metadata only - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp0-bootstrap/input_digest.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp0-bootstrap/handoff.md` - -Non-owned outputs: - -- every v2.5 seam-pack file - -Gate to complete: - -- ADR inputs are resolved to exact paths -- the feature directory exists -- the run input digest names repo evidence, ADRs, and adjacent planning packs to scan - -Notes: - -- PP0 exists so later stages do not infer a moving input set. - -### PP1 - Scope Brief - -Purpose: - -- convert ADR intent into the canonical feature brief expected by the extractor contract -- merge the outputs of the optional `pp1a-scope-intake` and `pp1b-surface-authority` helper stages into one canonical pack brief - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///scope_brief.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1-scope/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1-scope/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1-scope/staged/scope_brief.md` - -Non-owned outputs: - -- `README.md` -- `seam_map.md` -- `threading.md` -- `review_surfaces.md` -- every `seam--.md` -- every governance file - -Required `scope_brief.md` sections: - -- goal and why now -- primary users or operators -- in-scope and out-of-scope -- success criteria -- hard constraints -- external systems and stakeholders -- known unknowns and risks -- explicit note that `spec_manifest.md` is the authoritative authored-doc-class inventory and surface-ownership register for the feature - -Gate to promote canonical output: - -- feature scope, goals, constraints, and risks are concrete enough to support authored-doc selection -- no task graph, kickoff prompt, or execution ownership surface is introduced - -Downstream handoff: - -- PP1.5 may begin research when `pp1-scope/handoff.md` exists -- PP2 may begin research when `pp1-scope/handoff.md` exists -- PP2 may not write canonical seam files until both `scope_brief.md` and `spec_manifest.md` are present - -Optional helper-stage split: - -- `pp1a-scope-intake` may draft user/job/success/constraint sections early -- `pp1b-surface-authority` may run in parallel to derive exact contract homes and surface inventory -- PP1 owns the canonical merge and resolves any mismatch between those helper outputs - -### PP1.5 - Spec Manifest and Surface Authority - -Purpose: - -- keep the current `spec_manifest.md` responsibility as a first-class canonical output -- define the authored spec, contract, schema, policy, parity, compatibility, and validation document classes the feature requires before seam extraction locks the downstream planning shape -- give seam extraction an explicit domain-completeness input instead of forcing seam briefs or `threading.md` to infer missing document classes later - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///spec_manifest.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1_5-spec-manifest/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1_5-spec-manifest/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp1_5-spec-manifest/staged/spec_manifest.md` - -Non-owned outputs: - -- `scope_brief.md` -- `seam_map.md` -- `threading.md` -- `review_surfaces.md` -- every `seam--.md` -- every governance file - -Required `spec_manifest.md` content: - -- exact list of required authored docs for the feature -- explicit doc classes required by the feature, such as: - - contract - - protocol - - schema - - policy - - telemetry - - filesystem semantics - - platform parity - - compatibility - - validation playbook -- one-owner-per-surface mapping -- distinction between: - - canonical descriptive docs under `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/` - - pack-local planning docs - - deferred downstream docs that must exist later -- absence semantics and determinism obligations for each selected doc class - -Gate to promote canonical output: - -- no required spec class remains implicit -- every durable contract surface has one intended canonical home -- seam extraction can proceed without inventing missing spec families later -- no task graph, kickoff prompt, or execution ownership surface is introduced - -Downstream handoff: - -- PP2 may begin research when `pp1_5-spec-manifest/handoff.md` exists -- PP2 may not write canonical seam files until `spec_manifest.md` is present - -### PP2 - Seam Map and Seam Briefs - -Purpose: - -- replace the current `minimal_spec_draft.md` seam skeleton with real v2.5 seam briefs -- define the seam pack backbone that downstream decomposition expects - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam_map.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///seam--.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp2-seams/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp2-seams/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp2-seams/staged/seam_map.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp2-seams/staged/seam--.md` - -Non-owned outputs: - -- `scope_brief.md` -- `spec_manifest.md` -- `threading.md` -- `review_surfaces.md` -- `README.md` -- every governance file - -Required `seam_map.md` content: - -- seam list with stable `SEAM-` identifiers -- seam type and touch surface summary -- boundary rationale -- pack-wide active, next, future horizon statement -- critical-path assumptions that PP3 must either confirm or reject - -Required seam-brief posture: - -- `status: proposed` -- `execution_horizon: active | next | future` -- exactly one `active` seam and one `next` seam by default -- `basis.currentness: provisional` unless repo evidence is strong enough to mark `current` -- `seam_exit_gate.required: true` -- `seam_exit_gate.planned_location: S99` -- `seam_exit_gate.status: pending` -- empty `open_remediations` by default - -Gate to promote canonical outputs: - -- seam IDs and slugs are stable -- every seam has value, touch surface, and verification intent -- horizon policy is explicit and matches the v2.5 extractor contract -- seam boundaries are consistent with the authored-doc classes and ownership rules declared in `spec_manifest.md` -- no slices or subslices are created - -Downstream handoff: - -- PP3 may begin research on `pp2-seams/handoff.md` -- PP4 may begin research on `pp2-seams/handoff.md` -- PP5 may read the seam handoff, but may not write governance canonically until PP3 completes - -### PP3 - Threading, Contract Registry, and Dependency Control Plane - -Purpose: - -- replace `workstream_triage.md` with the v2.5 canonical thread and dependency control plane -- absorb the durable parts of `impact_map.md`, `ci_checkpoint_plan.md`, and the dependency-heavy parts of the old triage surface -- merge the outputs of the optional `pp3a-threading` and `pp3b-verification-cadence` helper stages into one canonical dependency surface - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///threading.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3-threading/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3-threading/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp3-threading/staged/threading.md` - -Non-owned outputs: - -- `scope_brief.md` -- `spec_manifest.md` -- `seam_map.md` -- every seam brief -- `review_surfaces.md` -- `README.md` -- every governance file - -Required `threading.md` content: - -- execution horizon summary -- contract registry with single producer ownership -- thread registry using `identified | defined | published | revalidated | closed` -- canonical contract refs under `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/contracts/.md` when a durable contract doc is warranted -- dependency graph -- critical path -- workstreams -- revalidation triggers -- `satisfied_by` posture for each thread -- verification cadence and checkpoint intent when platform scope warrants it -- references back to `spec_manifest.md` when a thread carries a contract or doc obligation that depends on a specific authored spec class - -Gate to promote canonical output: - -- every cross-seam contract has one producer seam -- dependency direction is explicit -- horizon summary agrees with seam briefs -- thread states use the v2.5 vocabulary -- no legacy workstream registry semantics remain - -Downstream handoff: - -- PP4 may refresh its draft from `pp3-threading/handoff.md` -- PP5 may begin or refresh research from `pp3-threading/handoff.md` -- PP6 may not write `README.md` until `threading.md` is canonical - -Optional helper-stage split: - -- `pp3a-threading` may focus only on `C-*`, `THR-*`, dependency edges, revalidation triggers, and critical-path structure -- `pp3b-verification-cadence` may focus only on checkpoint intent, platform proof grouping, and conformance-heavy workstream notes -- PP3 owns the canonical `threading.md` merge and resolves any mismatch between those helper outputs - -### PP4 - Review Surfaces - -Purpose: - -- create the pack-level orientation artifact required by the v2.5 extractor -- replace the diagram and impact-heavy parts of `impact_map.md` - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///review_surfaces.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp4-review/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp4-review/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp4-review/staged/review_surfaces.md` - -Non-owned outputs: - -- `scope_brief.md` -- `seam_map.md` -- every seam brief -- `threading.md` -- `README.md` -- every governance file - -Required `review_surfaces.md` posture: - -- product-facing or operator-facing Mermaid diagrams -- actual service, API, state, component, or workflow flows -- orientation only, not seam-local pre-exec review -- visible mismatch hotspots and high-risk boundaries - -Gate to promote canonical output: - -- diagrams and narrative reflect the current canonical seam map and threading -- the document explicitly states that downstream seam-local `review.md` remains a later artifact owned by the threaded seam decomposer - -Downstream handoff: - -- PP6 may begin assembling its summary from `pp4-review/handoff.md` - -### PP5 - Governance Scaffold - -Purpose: - -- replace `alignment_report.md` with structured v2.5 governance scaffolding -- seed the control plane that seam promotion will later consume - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/remediation-log.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/seam--closeout.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///governance/pack-closeout.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp5-governance/scratch.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp5-governance/handoff.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp5-governance/staged/governance/**` - -Non-owned outputs: - -- every non-governance seam-pack file - -Required governance posture: - -- seam-only remediation ownership -- remediation entries with `origin_phase`, `source_gate`, `owner_seam`, `blocked_targets`, `summary`, `required_fix`, and `resolution_evidence` -- one closeout stub per seam -- each seam closeout stub seeds the realized `seam_exit_gate` record location for later post-exec use -- `pack-closeout.md` summarizes unresolved remediations, open threads, and stale-trigger expectations - -Gate to promote canonical outputs: - -- PP2 seam IDs are final -- PP3 thread IDs and contract ownership are final -- every blocker names an owning seam -- no invented post-exec truth is recorded - -Downstream handoff: - -- PP6 may read `pp5-governance/handoff.md` - -### PP6 - README and Pack-Level Validation - -Purpose: - -- give the pack one stable landing page for downstream operators and v2.5 promotion tools -- close the lane only when the pack already satisfies the downstream input contract - -Owned canonical outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///README.md` - -Owned research-only outputs: - -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp6-readme/validation.md` -- `/Users/spensermcconnell/__Active_Code/atomize-hq/substrate/docs/project_management/packs///logs/pre-planning-v2_5/pp6-readme/handoff.md` - -Non-owned outputs: - -- every other seam-pack file - -Required `README.md` content: - -- pack summary -- source ADR list -- active seam and next seam -- pack file inventory -- downstream entry points: - - threaded seam decomposition consumes `scope_brief.md`, `spec_manifest.md`, `seam_map.md`, `threading.md`, `review_surfaces.md`, seam briefs, and governance docs - - seam promotion consumes `README.md`, `scope_brief.md`, `spec_manifest.md`, `threading.md`, `review_surfaces.md`, seam briefs, and governance docs -- explicit note that this pack ends before `threaded-seams/` planning and execution artifacts - -Gate to promote canonical output: - -- all required v2.5 seam-pack files exist -- no legacy pre-planning doc under `pre-planning/` is required for truth -- no `threaded-seams/` directory exists yet -- no slices or subslices exist -- horizon policy, thread vocabulary, and governance scaffolds satisfy the v2.5 contracts - -## Mapping the Current Six Pre-Planning Artifacts - -### 1. `spec_manifest.md` - -Current role: - -- surface inventory -- canonical doc ownership -- deferred-doc inventory - -New canonical home: - -- remain canonical as `spec_manifest.md` -- feed seam extraction rather than being replaced by it -- provide the domain-completeness and authored-doc-class inventory that seam briefs and `threading.md` must respect - -Why it stays canonical: - -- it answers a different question than `scope_brief.md`, `seam_map.md`, or `threading.md` -- it defines which spec, contract, schema, policy, parity, compatibility, and validation artifacts must exist at all -- without it, seam extraction can succeed while still omitting a required document family - -### 2. `impact_map.md` - -Current role: - -- touch set -- cascading implications -- contradiction risk -- cross-queue alignment - -New canonical home: - -- `seam_map.md` owns touch-surface-by-seam boundaries -- `threading.md` owns the dependency graph, contradiction-prone contract edges, and critical path -- `review_surfaces.md` owns the operator-facing diagrams and mismatch hotspots - -Research-only carry-forward: - -- any exact path inventory or broad cross-queue scan dump stays in stage logs - -### 3. `minimal_spec_draft.md` - -Current role: - -- cross-cutting defaults -- invariants -- draft seam skeleton - -New canonical home: - -- `scope_brief.md` owns pack-wide defaults and invariants -- `seam_map.md` and `seam--.md` own the real seam skeleton -- `README.md` owns the short pack posture summary - -Research-only carry-forward: - -- tentative split or merge analysis stays in `pp2-seams` logs - -### 4. `ci_checkpoint_plan.md` - -Current role: - -- advisory checkpoint grouping -- verification cadence - -New canonical home: - -- `threading.md` owns checkpoint intent, verification cadence, and critical path grouping -- seam closeout stubs and `pack-closeout.md` own the later place where those checkpoints become realized evidence - -Research-only carry-forward: - -- optional checkpoint what-if analysis stays in `pp3-threading` logs - -### 5. `workstream_triage.md` - -Current role: - -- downstream workstream proposal -- ordering -- split or merge recommendations - -New canonical home: - -- `threading.md` owns workstreams, dependency direction, and recommended downstream order -- `seam_map.md` owns the accepted seam set after split or merge decisions - -Research-only carry-forward: - -- draft restructuring analysis stays in `pp2-seams` or `pp3-threading` logs - -### 6. `alignment_report.md` - -Current role: - -- consolidated follow-ups -- hard gates -- unresolved conflicts - -New canonical home: - -- `governance/remediation-log.md` owns structured open issues and blockers -- `governance/pack-closeout.md` owns pack-level unresolved thread and stale-trigger posture -- `README.md` owns only the summary, not the blocker truth - -Research-only carry-forward: - -- a human-readable wrapper summary may still be written under `logs/pre-planning-v2_5/compat/alignment_report.md` - -## Exit Criteria for the Revised Lane - -The revised pre-planning lane is complete only when all are true: - -- the pack matches the v2.5 extractor output contract -- the pack is directly consumable by `/Users/spensermcconnell/.agents/skills/threaded-seam-decomposer-v2-5/SKILL.md` -- the pack contains no execution-ready slices, subslices, or seam-local `review.md` -- every canonical file has a single owning stage -- all overlapping work is confined to research-only outputs -- `spec_manifest.md` remains canonical -- the remaining five legacy artifacts are either retired or rendered as research-only compatibility views, not canonical truth diff --git a/LLM_AI_CAPABILITY_ENABLEMENT_PLANNING_ORDER.md b/LLM_AI_CAPABILITY_ENABLEMENT_PLANNING_ORDER.md deleted file mode 100644 index 1314abc71..000000000 --- a/LLM_AI_CAPABILITY_ENABLEMENT_PLANNING_ORDER.md +++ /dev/null @@ -1,104 +0,0 @@ -# LLM/AI Capability Enablement — ADR Finalization Order (with ADR-0028 Circle-Back) - -This document is a lightweight tracking plan for finalizing ADRs and their corresponding schema/contract/spec files in an order that minimizes rewrites. - -## Phase 0 — Freeze “No Rewrite” rules (one-time) -- Rule A: Once an ADR is `Accepted`, subsequent edits are additive-only (no contract reshapes). -- Rule B: Any later ADR that needs new trace fields/config keys must propose them as extensions to: - - ADR-0028 (trace/event families + correlation fields + redaction/caps), or - - ADR-0027 (config/policy key paths + precedence + defaults). - -## Phase 1 — Trace foundation (accept early) -- ADR-0028: `docs/project_management/adrs/draft/ADR-0028-in-world-process-execution-tracing-parity.md` -- Outputs (required): - - `docs/project_management/_archived/next/world_process_exec_tracing_parity/spec_manifest.md` - - Trace event schema spec (`world_process_*`) - - Shared redaction spec (argv/env) + caps/truncation spec - - World-agent API payload spec (`process_events`) - - Span parent-linkage fix spec - -## Phase 2 — Output/routing contract (accept) -- ADR-0017: `docs/project_management/adrs/draft/ADR-0017-agent-hub-concurrent-execution-and-output-routing.md` -- Outputs (required): - - Output class contract (PTY bytes vs structured events) + buffering/render rules - - Attribution requirements for concurrent agent output - -## Phase 3 — Config/policy surface for LLM + agents (accept) -- ADR-0027: `docs/project_management/adrs/draft/ADR-0027-llm-and-agent-config-policy-surface.md` -- Outputs (required): - - `docs/project_management/_archived/next/llm_and_agent_config_policy_surface/contract.md` - - Schema/specs for new `llm.*` and `agents.*` keys (config + policy) - - Fail-closed defaults + precedence rules - -## Phase 4 — LLM front door then engines (accept in order) -- ADR-0023: `docs/project_management/adrs/draft/ADR-0023-in-world-llm-gateway-front-door.md` -- ADR-0024: `docs/project_management/adrs/draft/ADR-0024-cli-backend-provider-engine.md` -- Outputs (required): - - Gateway HTTP contract + world-boundary requirements - - Backend capability/routing contract (CLI engines) - - All logging/attribution requirements must reference ADR-0028 + ADR-0017 - -## Phase 5 — Agent hub then toolbox (accept in order) -- ADR-0025: `docs/project_management/adrs/draft/ADR-0025-agent-hub-core-role-swappable.md` -- ADR-0026: `docs/project_management/adrs/draft/ADR-0026-orchestration-toolbox-mcp.md` -- Outputs (required): - - Agent backend interface + role assignment contract + attribution - - MCP tool namespace/schemas + role gating rules - -## Phase 6 — Host event bus/router daemon (accept before workflow composition) -- ADR-0029: `docs/project_management/adrs/draft/ADR-0029-host-event-bus-and-router-daemon.md` -- Outputs (required): - - Router daemon contract (trace-driven triggers → policy-gated requests/actions) - - Durable request queue semantics (`inbox`/`work_queue`/cursor+dedupe state) - - Workspace registry + `workspace_id` contract - - FS-change trigger semantics aligned to ADR-0018 path matching - -## Phase 7 — Workflow composition (accept last) -- ADR-0021: `docs/project_management/adrs/draft/ADR-0021-substrate-workflow-engine.md` -- ADR-0022: `docs/project_management/adrs/draft/ADR-0022-forge-agent-loop-as-workflow-node.md` - -## Phase 8 — Circle-back pass (additive-only): trace classifications + landing items -- Phase 8 working registry (cross-cutting alignment): `docs/project_management/packs/PHASE_8_CROSS_CUTTING_DECISION_REGISTRY.md` -- Note (workflow composition): - - ADR-0021 and ADR-0022 MUST remain `Draft` until we are closer to implementation. - - We will defer solidifying remaining `workflow-engine` / `forge` contract details (beyond already-accepted DR items) until enough upstream foundations have landed (Phases 1–6) and we are ready to produce the Phase 7 Planning Packs. -- Circle back to ADR-0028: - - Additive updates only: - - new trace event families required by LLM/agents/workflows (if any) - - additional correlation fields (e.g., `agent_id`, `tool_call_id`, `workflow_node_id`) with required/optional classification - - any derived trigger/request lifecycle event families introduced by the router daemon (ADR-0029) - - special redaction/caps notes for LLM/agent-specific subprocesses - - documentation pointers/updates (`docs/TRACE.md` as needed) - - Non-negotiable: do not reopen the core capture mechanism choice, base event types, or span-parent correctness—only extensions. - -- Circle back (cross-track standard): secrets delivery channel rubric (FD/pipe vs env vars) - - Goal: establish a concrete, reusable decision rubric for when Substrate should use: - - inherited one-time FD/pipe secret channels (preferred for Substrate-spawned, Substrate-owned components), vs - - environment-variable injection (interop-required cases; third-party tools/SDKs; world-boundary transport constraints). - - Standard: `docs/project_management/standards/SECRETS_DELIVERY_CHANNEL_RUBRIC.md` - - Output: update the relevant Decision Registers/ADRs to reference the rubric so current and future secret-handling decisions stay consistent (and avoid ad-hoc env var proliferation). - -- Circle back to other foundation ADRs / decision registers (additive-only): - - ADR-0017 (output routing contract): - - align “structured agent events” attribution requirements to the final correlation set (`orchestration_session_id`, `run_id`, `thread_id`, `agent_id`, `role`, and join keys like `cmd_id`/`span_id` when applicable), - - confirm buffering/backpressure rules remain compatible with any later session-log persistence strategy (do not conflate rendering with persistence). - - discussion point (agent hub circle-back): confirm the structured-event envelope can optionally carry an event-plane routing hint (e.g., `channel` / `topic`), so future “subscribe/filter” behavior can be expressed without PTY injection or attribution ambiguity; ensure any “dropped buffered lines” summaries preserve the same routing metadata so suppressed output remains explainable. - - discussion point (agent hub circle-back): decide and specify world session reuse + attribution—when multiple agents run “in world” under one `orchestration_session_id`, do they share a single `world_id` for the entire session by default, and should structured events carry `world_id` (and any “world restart” reason) so operators can verify that agents did or did not share the same filesystem/isolation boundary. - - ADR-0027 (LLM + agent config/policy surface): - - align backend id formats and role/tool gating keys with the final agent hub + MCP toolbox specs, - - ensure any newly-discovered policy gates remain fail-closed by default and do not introduce secret storage. - - discussion point: keep ADR-0027 limited to backend **id format + allowlist/selection surfaces** (no canonical “backend registry” list here); once ADR-0023/ADR-0024 (LLM gateway + engines) and ADR-0025 (agent backends) are accepted, circle back to add references (and, if helpful, a non-normative appendix mapping ids → their authoritative backend contracts). - - ADR-0025 (agent hub core): - - discussion point: explicitly separate **control plane** (orchestrator → executor steering RPCs; cancel; task assignment) from the **event plane** (executor → hub structured events), so “who can steer whom” is policy-gated and auditable while output streaming/rendering remains a pure event-plane concern (aligns with ADR-0017 and avoids conflating rendering with routing). - - discussion point: define an event-plane **subscription/channel** model (pub/sub-style) for concurrent multi-agent operation, where agent configuration can declare which channels it emits to and which channels it may receive steering from; this is required to support a host-scoped orchestration agent (control-plane only) while keeping all LLM egress and world-bound capabilities in-world and subject to effective policy. - - ADR-0029 (host event bus/router daemon): - - align the v1 trigger allowlist to the final event families and correlation fields emitted by LLM gateway, agent hub, and workflow engine, - - ensure request/derived-event schemas reference stable join keys (cause/trigger refs) consistent with the final trace/span contract. - - Decision registers that define correlation/attribution surfaces (verify naming + required/optional classification, additive-only): - - `docs/project_management/_archived/next/agent-hub-concurrent-execution-output-routing/decision_register.md` - - `docs/project_management/_archived/next/agent_hub_core/decision_register.md` - - `docs/project_management/_archived/next/llm_gateway_in_world/decision_register.md` - - `docs/project_management/_archived/next/llm_cli_backend_engine/decision_register.md` - - `docs/project_management/_archived/next/orchestration_mcp_toolbox/decision_register.md` - - `docs/project_management/_archived/next/workflow-engine/decision_register.md` - - `docs/project_management/_archived/next/forge/decision_register.md` diff --git a/PWS_FULL_PLANNING_ORCHESTRATION_V1.md b/PWS_FULL_PLANNING_ORCHESTRATION_V1.md deleted file mode 100644 index 0f159e637..000000000 --- a/PWS_FULL_PLANNING_ORCHESTRATION_V1.md +++ /dev/null @@ -1,500 +0,0 @@ -# Pack Planning Workstreams (PWS) + Full-Planning Orchestration (v1) - -Status: Implemented through Step 5.5 convergence foundation -Last updated: 2026-03-07 - -## Why this doc exists - -Pre-planning now emits a `pre-planning/workstream_triage.md` artifact that proposes **pack-internal planning workstreams** (PWS). We want to: - -1) Make those PWS IDs stable and machine-readable, so we can automate *full planning* in parallel where safe. -2) Keep the same safety model as pre-planning: strict output allowlists + logs-only drafts. -3) Avoid colliding with the repo’s existing umbrella **Workstreams** (`WS-YYYYMM-...`) concept. - -This orchestration layer sits where the older workflow had a single “Planning agent → PACK created” step (see `docs/project_management/system/standards/planning/PLANNING_WORKFLOW_OVERVIEW.md`). - -## Terminology (avoid collisions) - -- **PWS (Planning Workstream)**: pack-internal planning stream, used to parallelize *full planning* work within a single pack. -- **Workstream (umbrella)**: initiative grouping multiple ADRs/packs/work items; ID format `WS-YYYYMM-initiative_slug` (see `WORKSTREAM_TRIAGE_AND_LIFT_DECISIONS.md` and `WORKSTREAM_SYSTEM_IMPLEMENTATION_PLAN.md`). -- **Slice**: execution unit in a pack (for example `PREFIX0`, `PREFIX1`), typically mapped to triads. - -## Decisions (locked-in) - -### D1 — PWS IDs are stable and git/path-safe - -PWS IDs use **no `:`** and must be stable once pre-planning is “done” for a pack. - -- Format: `-PWS-` -- Examples: - - `PFX-PWS-contract` - - `PFX-PWS-tests_ci` - - `PFX-PWS-slice_spec_pfx0` -- Regex (recommended): `^[A-Z][A-Z0-9]*-PWS-[a-z0-9_]+$` - -#### Source of truth for `` - -The prefix MUST come from the pack’s `pre-planning/minimal_spec_draft.md` “Draft slice skeleton” section (for example `Slice prefix (draft): PFX`). - -Rule: -- Treat `` as **stable once pre-planning is done**; if it should change, record it as a gate/risk and do not rename existing PWS IDs mid-flight. - -### D2 — Minimum required PWS - -Every pack’s `pre-planning/workstream_triage.md` MUST include at least: - -- `-PWS-contract` (deterministic “first” gate) -- `-PWS-tasks_checkpoints` (deterministic “last-ish” gate; single-writer for `tasks.json`) - -All other PWS are dynamic and pack-specific. - -### D3 — Workstream triage must emit a machine-readable PWS index - -To avoid regex-parsing prose forever, `pre-planning/workstream_triage.md` MUST include a small machine-readable block enumerating PWS nodes, dependencies, and owned outputs. - -Recommended format: embedded JSON (dependency-free) with deterministic markers. - -Example: -````md - -```json -{ - "pws_index_version": 2, - "slice_prefix": "PFX", - "accepted_slice_order": ["PFX0", "PFX1"], - "draft_slice_order": ["PFX0"], - "pws": [ - { - "id": "PFX-PWS-contract", - "role": "contract", - "depends_on": [], - "assumes": [], - "owns": ["contract.md", "decision_register.md"] - }, - { - "id": "PFX-PWS-slice_spec_pfx0", - "role": "implementation", - "depends_on": ["PFX-PWS-contract"], - "assumes": [], - "owns": ["slices/PFX0/PFX0-spec.md"] - }, - { - "id": "PFX-PWS-tasks_checkpoints", - "role": "tasks_checkpoints", - "depends_on": ["PFX-PWS-contract"], - "assumes": [], - "owns": ["tasks.json", "session_log.md", "kickoff_prompts/", "slices/PFX0/kickoff_prompts/", "slices/PFX1/kickoff_prompts/"] - } - ] -} -``` - -```` - -Notes: -- The JSON block is the canonical input for orchestration (not the prose headings). -- `accepted_slice_order` is the authoritative post-triage slice order for convergence and full planning. -- `draft_slice_order` is optional and advisory; it mirrors the unchanged draft skeleton when useful for diagnostics. -- `depends_on` MUST encode **hard dependencies only**. -- Non-blocking ordering preferences go in an optional `assumes:` list (not used to schedule). -- `owns` is repo-relative *within the pack root* (e.g., `contract.md`, `slices/...`, `tasks.json`). -- `owns` MUST be an exclusive set across PWS if we want safe parallel execution; `tasks.json` MUST be owned only by `-PWS-tasks_checkpoints`. - -### D4 — Default DAG shape is “star-ish”, not a chain - -The system should *encourage* a “contract-first → parallel cluster → tasks/checkpoints” topology, but it must remain dynamic: - -- `*-PWS-contract` is the deterministic first gate. -- Everything else may run concurrently if: - - hard deps are satisfied, AND - - `owns` sets are disjoint. -- `*-PWS-tasks_checkpoints` runs late and is the **single writer** for `tasks.json` (and usually `plan.md`). - -### D5 — `pre-planning/alignment_report.md` is a first-class orchestration input - -Full planning orchestration should treat `pre-planning/alignment_report.md` as a canonical “do not drop” index for: -- cross-pack misalignments (hard gates) -- Decision Register requirements -- CI/checkpoint wiring gaps -- risks/unknowns and other follow-ups - -The orchestrator uses it to: -- seed required work into the appropriate PWS (especially `*-PWS-contract` and `*-PWS-tasks_checkpoints`) -- detect cross-pack conflicts that should be handled by an integration step (not buried inside one pack’s PWS) - -Important: -- `alignment_report.md` is a generated routing/index artifact, not a second slice-authority surface. -- Slice-order authority remains limited to `PM_PWS_INDEX.accepted_slice_order` plus the converged slice-bearing pre-planning docs. - -## Execution model (safety + concurrency) - -### Per-PWS safety model (same as pre-planning) - -For a PWS run: -- Drafts/scratch MUST be written only to: `/logs/pws//**` (gitignored). -- Tracked writes MUST be restricted to that PWS’s declared `owns` allowlist. -- Any attempt to write tracked files outside `owns` is a hard error. - -### Concurrency rules - -PWS can run concurrently only if: -- their hard deps are satisfied, AND -- their `owns` sets are disjoint (tracked output isolation), AND -- they do not touch single-writer files (`tasks.json`, typically `plan.md`) except via `-PWS-tasks_checkpoints`. - -If isolation is unclear, run sequentially by default. - -## Allowlist expansion + escalation policy (operator-controlled) - -Problem: -- While running a PWS, we may discover we must edit an additional tracked file not in `owns`. - -Policy: -1) The PWS agent MUST NOT silently expand scope. -2) Instead, it writes **logs only**: - - `/logs/pws//allowlist_request.yaml` (requested paths + reason) - - A proposed change as either: - - `/logs/pws//draft.patch`, and/or - - `/logs/pws//draft/` (full draft file) - -Operator decision (via the orchestrator): -- **Approve allowlist expansion**: - - Expand that PWS’s tracked allowlist. - - If the requested path is outside the `pre-planning/impact_map.md` touch set, treat it as scope drift: - - update the touch set first, then re-run `make pm-lift-pack PACK=""`. -- **Deny allowlist expansion, but accept the change**: - - The PWS remains strict (no extra tracked writes). - - The orchestrator is responsible for applying the draft to the tracked file(s) in a dedicated “integration apply” step (including reconciliation/merge with other changes). -- **Deny the change**: - - Keep the draft in logs only; no tracked edits occur. - -## Incremental implementation plan (MVP → parallelism) - -### Step 0 — Lock the interface (triage output contract) - -- Update the triage agent contract so every `pre-planning/workstream_triage.md` contains: - - required PWS IDs (`-PWS-contract`, `-PWS-tasks_checkpoints`), and - - an embedded JSON `PM_PWS_INDEX` block (see D3). - -### Step 1 — Add a mechanical validator (non-invasive) - -- Add `validate_pws_index.py` (or equivalent) that: - - extracts and parses the `PM_PWS_INDEX` JSON block, - - validates ID formats, required PWS presence, and basic schema, - - checks that `owns` paths are pack-relative, - - checks `tasks.json` is owned by exactly one PWS (`-PWS-tasks_checkpoints`). -- Hook into `make planning-lint FEATURE_DIR=...` as a non-blocking advisory first (then promote to required when stable). - -### Step 2 — Add a scheduler dry-run - -- Add `make pm-pws-plan FEATURE_DIR=...` that prints: - - a topo-ordered plan (by hard deps), - - “parallel layers” (runnable sets) subject to `owns` disjointness and single-writer rules. - -### Step 3 — Add a single-PWS runner (strict allowlists) - -- Add `make pm-run-pws FEATURE_DIR=... PWS_ID=...`: - - creates `/logs/pws//...` (drafts only), - - enforces tracked-write allowlist = `pws_index[*].owns` for the selected PWS, - - executes a role-specific prompt (start with `contract` and `tasks_checkpoints`; keep others generic initially). - -### Step 3.5 — Align Step 3 `tasks_checkpoints` with the triad system (execution-ready packs) - -This landed as a contract hardening step around `tasks_checkpoints`. - -What is now true: -- the pre-planning triage prompt requires triad-critical `owns` for `*-PWS-tasks_checkpoints`, -- `validate_pws_index.py` enforces those required `owns`, -- and the runner continues to keep tracked writes strictly allowlist-driven. - -The important rule is: -- `*-PWS-tasks_checkpoints` must own the execution-triad scaffolding it is expected to author, -- especially `session_log.md`, `kickoff_prompts/`, and per-slice kickoff prompt directories. - -This closes the class of failures where a `tasks_checkpoints` session could make `tasks.json` look mechanically acceptable while still being unable to author the prompt/report surfaces required for execution. - -#### Quick reference: schema v4 cross-platform checkpoint-boundary model (what `validate_tasks_json.py` expects) - -When `tasks.json` has: -- `meta.schema_version >= 4` -- `meta.cross_platform = true` - -Then (in addition to the normal task schema rules) the cross-platform integration model is: - -- `meta.checkpoint_boundaries` is **required** and must list the **last slice id** in each checkpoint group. - - `validate_ci_checkpoint_plan.py` additionally requires this list to match the checkpoint boundaries in `ci_checkpoint_plan.md` exactly. -- For **every** slice `X`: - - Always define: `X-code`, `X-test`, and `X-integ`. - - `X-integ` is the only task used by `validate_slice_specs.py` for AC traceability (`ac_ids` must match the slice spec). - - If `X` is **not** a checkpoint boundary: - - Do **not** define any `X-integ-core` or `X-integ-` tasks. - - `X-code.integration_task` and `X-test.integration_task` must both be `X-integ`. - - If `X` **is** a checkpoint boundary: - - Define: `X-integ-core`, `X-integ-` for every CI parity platform, and `X-integ` as the final aggregator. - - Wiring rules (hard requirements): - - `X-code.integration_task = "X-integ-core"` and `X-test.integration_task = "X-integ-core"` - - `X-integ-core.depends_on` includes `X-code` and `X-test` - - Each `X-integ-.depends_on` includes `X-integ-core` and sets `platform=""` - - `X-integ.depends_on` includes `X-integ-core` and all `X-integ-` tasks - - Automation merge rules (when `meta.schema_version >= 3` and `meta.automation.enabled=true`): - - `X-integ-core.merge_to_orchestration = false` - - `X-integ-.merge_to_orchestration = false` - - `X-integ.merge_to_orchestration = true` - -Authoritative references: -- `docs/project_management/system/scripts/planning/validate_tasks_json.py` (`_validate_platform_integ_model`) -- `docs/project_management/system/scripts/planning/validate_ci_checkpoint_plan.py` -- `docs/project_management/system/scripts/planning/new_feature.sh` (canonical scaffolding) - -#### Validator gotchas (common failure modes) - -- `validate_slice_specs.py` enforces a hard limit of **1..8** AC bullets in each slice spec. - - If a slice spec has more than 8 ACs, `tasks_checkpoints` cannot produce a consistent `ac_ids` set; fix/split the slice before “final” task wiring. -- `validate_tasks_json.py` requires `kickoff_prompt` files to exist on disk and live under: - - `/kickoff_prompts/`, or - - `/slices//kickoff_prompts/` - …so the `PM_PWS_INDEX` `owns` for `tasks_checkpoints` must include these directories as prefix paths. -- Planning lint requires the exact sentinel line in every kickoff prompt: - - `Do not edit planning docs inside the worktree.` - - Templates should include it; if not, use `docs/project_management/system/scripts/planning/ensure_kickoff_prompt_sentinel.py`. -- `validate_ci_checkpoint_plan.py` derives slice ordering from `*-integ` tasks. - - If `tasks_checkpoints` hasn’t created the `*-integ` tasks yet, checkpoint plan validation cannot run (and should fail). - -#### Pack-local inputs `tasks_checkpoints` should always read - -These are the pack artifacts that drive correct task graph + prompt wiring: -- `/pre-planning/workstream_triage.md` (including `PM_PWS_INDEX`) -- `/pre-planning/minimal_spec_draft.md` (slice skeleton + prefix source of truth) -- `/pre-planning/spec_manifest.md` -- `/pre-planning/impact_map.md` -- `/pre-planning/ci_checkpoint_plan.md` (when cross-platform automation is intended) -- `/pre-planning/alignment_report.md` (gates/risks that must route into tasks/checkpoints) -- For each slice: `/slices//-spec.md` (AC IDs + references) - -#### Required contract changes (start at pre-planning) - -Update `docs/project_management/system/prompts/planning/workstream_triage_agent.md` so the generated `PM_PWS_INDEX` for `-PWS-tasks_checkpoints` includes **triad-critical owns**. - -Minimum recommended `owns` additions for `*-PWS-tasks_checkpoints` (pack-relative; use trailing `/` for prefix ownership): -- `session_log.md` -- `kickoff_prompts/` (feature/ops kickoff prompts: `F0-exec-preflight`, `CP*-ci-checkpoint`, `FZ-feature-cleanup`, etc.) -- For each slice in the accepted/draft skeleton: `slices//kickoff_prompts/` - -Additional recommended `owns` (depending on feature posture): -- `execution_preflight_report.md` (when `meta.execution_gates=true` or when you always want preflight gating) -- For each slice: `slices//-closeout_report.md` (when `meta.execution_gates=true`) - -Notes: -- Keep `tasks.json` as a single-writer owned only by `*-PWS-tasks_checkpoints` (already enforced by `validate_pws_index.py`). -- Avoid `owns` overlap: do **not** give any other PWS ownership of kickoff prompt paths if `tasks_checkpoints` owns them. - -#### Required prompt changes (`tasks_checkpoints` role) - -Update `docs/project_management/system/prompts/planning/pws_tasks_checkpoints_agent.md` to be explicitly triad-aware: -- Generate an execution-ready `tasks.json` (do not “make validation pass” by disabling automation/cross-platform when the pack intends to use triads). -- Generate all kickoff prompt files referenced by `tasks.json.kickoff_prompt` using: - - `docs/project_management/system/templates/kickoff/*` - - Canonical locations: - - Slice tasks: `slices//kickoff_prompts/.md` - - Feature/ops tasks: `kickoff_prompts/.md` -- Populate `ac_ids` for `-code`, `-test`, and `-integ` by extracting `AC--NN` entries from the slice spec’s `## Acceptance criteria` section. - - Do **not** add `ac_ids` to `*-integ-core` or `*-integ-` tasks; only `-integ` is used for AC traceability (see `validate_slice_specs.py` and existing packs). -- Include the kickoff prompt sentinel required by lint: `Do not edit planning docs inside the worktree.` (templates should already do this; lint will fail if missing). -- If allowlisting still blocks required tracked outputs, do **not** downgrade schemas. - - Instead: emit `allowlist_request.json` + `draft.patch` under `/logs/pws//`. - -Implementation reference for the canonical task graph + prompt rendering: -- `docs/project_management/system/scripts/planning/new_feature.sh` (authoritative scaffolder) - -#### Required Step 3 runner hardening (definition of “success”) - -Update `docs/project_management/system/scripts/planning/run_pws_agent.sh` so that for `role=tasks_checkpoints`: -- After `validate_tasks_json.py` passes, also run: - - `validate_slice_specs.py --feature-dir ""` - - `validate_ci_checkpoint_plan.py --feature-dir ""` (when a checkpoint plan exists / when `meta.cross_platform=true`) -- Optionally (strongly recommended): run `make planning-lint FEATURE_DIR=""` as a final “execution-ready” gate once it’s stable/fast enough. - -The validator is intentionally narrow here: -- it does not try to infer higher-level execution semantics from pack-specific content, -- it only enforces the ownership preconditions needed for safe triad authoring later in full planning. - -### Step 4 — Add a sequential full-planning orchestrator - -- Add `make pm-full-planning-orchestrate FEATURE_DIR=...`: - - runs `-PWS-contract` first, - - runs remaining runnable PWS sequentially (MVP), - - runs `-PWS-tasks_checkpoints` last, - - refreshes `pre-planning/alignment_report.md` immediately before the pre-task coherence gate for `-PWS-tasks_checkpoints`, - - treats `pre-planning/alignment_report.md` as required input and routes: - - “Gates / hard decisions” + “Decision Register required” → `-PWS-contract` - - “CI/checkpoint wiring gaps” → `-PWS-tasks_checkpoints` - -### Step 5 — Add operator-controlled allowlist expansion + integration-apply - -- Standardize logs-only artifacts when a PWS needs to edit a tracked file outside `owns`: - - `/logs/pws//allowlist_request.json` (requested paths + reason) - - `/logs/pws//draft.patch` and/or `/logs/pws//draft/` -- Orchestrator pauses for operator decision: - - approve allowlist expansion (and optionally update touch set + re-run `pm-lift-pack`), - - deny expansion but accept the change via “integration apply” step, - - deny the change entirely (keep draft in logs only). - -### Step 5.5 — Pre-full-planning convergence (landed) - -The landed Step 5.5 work is a dedicated convergence stage between pre-planning and full planning. - -The problem it solves is generic: -- triage can adopt a post-draft slice inventory/order, -- some pre-planning artifacts can still describe the old draft slice model, -- and full planning should not start task wiring from those contradictory inputs. - -#### Landed contract - -The landed authority and convergence rules are: - -1) `PM_PWS_INDEX` v2 makes the post-triage slice order explicit. -- `accepted_slice_order` is the authoritative post-triage slice order. -- `draft_slice_order` is optional and advisory. -- v1 remains readable for migration. - -2) Pre-full-planning coherence is now a distinct validation phase. -- `validate_slice_inventory_coherence.py --phase pre_full_planning` -- This phase compares `workstream_triage.accepted_slice_order` against: - - `pre-planning/spec_manifest.md` - - `pre-planning/impact_map.md` - - `pre-planning/ci_checkpoint_plan.md` -- `minimal_spec_draft.md` remains informational when triage adopts a different accepted order. - -3) Convergence is bounded and narrowly scoped. -- `pre_full_planning_convergence.py` classifies the pack as: - - `pass` - - `needs_remediation` - - `hard_fail` -- Only safe pre-planning slice inventory/order drift is auto-remediable. -- Non-slice semantic contradictions remain hard failures. - -4) The remediation agent is intentionally constrained. -- The agent may edit only: - - `pre-planning/spec_manifest.md` - - `pre-planning/impact_map.md` - - `pre-planning/ci_checkpoint_plan.md` -- It must not edit: - - `pre-planning/minimal_spec_draft.md` - - `pre-planning/workstream_triage.md` - - `tasks.json` - -5) `alignment_report.md` remains generated, not agent-authored. -- `pre_full_planning_converge.sh` regenerates the tracked `pre-planning/alignment_report.md` after successful convergence. -- The report is not directly remediated by the agent. -- During full planning, the orchestrator refreshes `pre-planning/alignment_report.md` again immediately before `-PWS-tasks_checkpoints`. -- The report may mention only a subset of accepted slices; it is used for routing follow-ups, not for exact slice-set authority. - -#### Landed entrypoints - -The landed orchestration entrypoints are: - -- `make pm-pre-full-planning-converge FEATURE_DIR=...` - - runs only the new convergence stage -- `make pm-full-planning-orchestrate FEATURE_DIR=...` - - now runs convergence before requiring/reading the tracked alignment report and before computing the PWS execution plan -- `make pm-planning-pipeline FEATURE_DIR=...` - - runs pre-planning research, then convergence, then full planning - -There is also an optional `RUN_PIPELINE=1` path on `pm-pre-planning-from-adr` to launch the full chain after scaffold. - -#### Landed implementation pieces - -The concrete pieces that landed are: - -- `docs/project_management/system/scripts/planning/pre_full_planning_convergence.py` - - emits deterministic JSON classification for convergence -- `docs/project_management/system/scripts/planning/pre_full_planning_converge.sh` - - runs validate -> optional reconcile -> regenerate alignment report -> revalidate -- `docs/project_management/system/prompts/planning/pre_planning_slice_reconcile_agent.md` - - tightly constrained remediation prompt -- `docs/project_management/system/scripts/planning/full_planning_orchestrate.sh` - - invokes convergence first -- `docs/project_management/system/scripts/planning/planning_pipeline_orchestrate.sh` - - optional top-level orchestration chain - -#### What Step 5.5 does not do - -This landed scope is intentionally narrow. - -It does not: -- auto-edit `minimal_spec_draft.md`, -- auto-edit `workstream_triage.md`, -- auto-edit `tasks.json`, -- or treat general semantic contradictions as safe auto-remediations. - -Those remain outside the convergence loop and should fail deterministically when encountered. - -### Step 5.6 — Post-full-planning execution convergence - -After the last PWS finishes, full planning now runs a second bounded convergence gate before orchestration success is reported. - -#### Landed contract - -1) The gate is execution-readiness oriented, not slice-authority oriented. -- It runs after full planning completes. -- It is the final blocker before `full_planning_orchestrate.sh` reports success. - -2) The gate uses the existing mechanical validators plus one new touch-set coherence check. -- Baseline dry run: - - `validate_tasks_json.py` - - `validate_slice_inventory_coherence.py --phase execution_ready` - - `validate_slice_specs.py` - - `validate_ci_checkpoint_plan.py` when applicable - - `validate_impact_map.py` - - `make planning-lint FEATURE_DIR=...` -- New gap-filler: - - `validate_execution_touchset_coherence.py` - - This checks explicit repo-relative, non-pack implementation-facing paths referenced by late-pack outputs against `impact_map.md`. - -3) Classification matches the pre-full model. -- `post_full_planning_convergence.py` classifies the pack as: - - `pass` - - `needs_remediation` - - `hard_fail` - -4) Safe remediation scope is fixed and narrow. -- The reconcile agent may edit only: - - `pre-planning/impact_map.md` - - `plan.md` - - `tasks.json` - - kickoff prompts referenced by `tasks.json` - - `manual_testing_playbook.md` - - `execution_preflight_report.md` - - existing per-slice closeout reports -- It must not edit: - - ADRs - - `contract.md` - - `decision_register.md` - - slice specs - - pre-planning slice-authority docs (`workstream_triage.md`, `minimal_spec_draft.md`, `spec_manifest.md`, `ci_checkpoint_plan.md`) - -5) `alignment_report.md` remains generated here too. -- `post_full_planning_converge.sh` regenerates `pre-planning/alignment_report.md` after successful convergence. -- The report is still generated, not agent-authored. - -#### Landed entrypoints - -- `make pm-post-full-planning-converge FEATURE_DIR=...` - - runs only the post-full execution-readiness gate -- `make pm-full-planning-orchestrate FEATURE_DIR=...` - - now runs post-full convergence after the PWS loop and before reporting success -- `make pm-planning-pipeline FEATURE_DIR=...` - - picks up post-full convergence transitively through full planning; it does not add a second top-level post-full step - -### Step 6 — Add safe parallelism (worktrees) - -- Only after Step 4/5 is stable: - - run disjoint PWS concurrently using git worktrees/branches, - - route shared-file work to an explicit integration/apply step, - - preserve single-writer invariants (`tasks.json`, often `plan.md`). - -## Open questions (explicitly not decided yet) - -- Exact “integration apply” mechanics: - - manual operator step vs orchestrator-assisted patch apply vs a dedicated integration PWS. -- Exact locations/names of prompts for each `role` (contract, slice_spec, docs_validation, tasks_checkpoints, etc.). diff --git a/archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md b/archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md deleted file mode 100644 index 043abf425..000000000 --- a/archive/SHARED_DISPATCH_CLOSEOUT_AUDIT_2026-05-25.md +++ /dev/null @@ -1,210 +0,0 @@ -# Shared Dispatch Closeout Audit - -Date: 2026-05-25 - -Scope audited: - -- [PLAN.md](/home/azureuser/__Active_Code/atomize-hq/substrate/PLAN.md) -- [ORCH_PLAN.md](/home/azureuser/__Active_Code/atomize-hq/substrate/ORCH_PLAN.md) -- [llm-last-mile/29.5-shared-dispatch-contract-closeout-and-parity-hardening.md](/home/azureuser/__Active_Code/atomize-hq/substrate/llm-last-mile/29.5-shared-dispatch-contract-closeout-and-parity-hardening.md) -- [llm-last-mile/29-shared-agent-dispatch-envelope-and-capability-override-contract.md](/home/azureuser/__Active_Code/atomize-hq/substrate/llm-last-mile/29-shared-agent-dispatch-envelope-and-capability-override-contract.md) - -## Verdict - -The 29.5 closeout should be treated as partially landed, not fully complete. - -What appears landed correctly: - -- inventory-backed dispatch now merges `policy_overlay` into resolved `effective_policy` -- bounded capability narrowing is implemented for the approved family -- public persisted-attach control flows are wired through the shared resolver -- successor attach truth is copied forward with continuity cleared -- docs for 29, 30, and 31 were updated to describe the narrowed 29.5 floor - -What blocks calling the slice complete: - -- REPL host-orchestrator cold start still bypasses the shared dispatch contract and persists manifest-default attach truth instead of resolved-contract truth -- persisted attach resolution still does not fully treat persisted attach knobs as authoritative baseline truth -- fallback behavior can still recreate permissive/default attach truth in paths that the plan said should be durable and authoritative - -## Primary Findings - -### Finding 1: REPL host cold start still bypasses the shared contract - -Severity: High - -This is the main reason the slice should not yet be considered complete. - -The public/start side persists durable attach truth from `ResolvedLaunchContract`: - -- [crates/shell/src/execution/agents_cmd.rs:1159](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agents_cmd.rs:1159) - -That path rewrites `session.host_attach_contract` from: - -- `HostAttachContract::from_resolved_contract(...)` - -The REPL host-orchestrator cold-start path does not do that. It still: - -1. resolves only to a `RuntimeSelectionDescriptor` -2. constructs the manifest directly -3. constructs `OrchestrationSessionRecord::new(...)` -4. relies on `HostAttachContract::from_manifest(...)` - -Key references: - -- REPL bootstrap object only carries `RuntimeSelectionDescriptor`: - - [crates/shell/src/repl/async_repl.rs:1746](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:1746) -- REPL host bootstrap resolves via inventory selection + runtime realizability, not shared contract resolution: - - [crates/shell/src/repl/async_repl.rs:2266](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:2266) - - [crates/shell/src/repl/async_repl.rs:2291](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:2291) -- REPL host startup persists a new orchestration session directly from the manifest: - - [crates/shell/src/repl/async_repl.rs:2204](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:2204) -- `OrchestrationSessionRecord::new(...)` still seeds durable attach truth from `from_manifest(...)`: - - [crates/shell/src/execution/agent_runtime/orchestration_session.rs:349](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:349) -- `HostAttachContract::from_manifest(...)` still hardcodes default attach capabilities and no persisted policy snapshot: - - [crates/shell/src/execution/agent_runtime/orchestration_session.rs:152](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:152) - - [crates/shell/src/execution/agent_runtime/orchestration_session.rs:177](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:177) - - [crates/shell/src/execution/agent_runtime/orchestration_session.rs:182](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:182) - -Why this matters: - -- the 29.5 plan and SOW require one truthful contract floor across human and orchestrator-controlled launches -- this path still gives REPL/orchestrator cold starts a different durable attach truth shape than the public/start path -- the most visible drift is in attach-relevant capabilities and persisted `effective_policy` - -Practical consequence: - -- equivalent human and REPL cold starts are not yet guaranteed to persist equivalent host attach truth -- that invalidates the parity acceptance claim in 29.5 - -### Finding 2: persisted attach resolution only partially trusts persisted attach knobs - -Severity: Medium - -The resolver now reuses persisted capabilities and persisted policy snapshot, which is good. But attach-knob authority is still partial. - -Key reference: - -- [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:314](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:314) - -What it currently does: - -- trusts persisted `requested_execution_scope` -- trusts persisted attach-relevant capabilities -- trusts persisted policy snapshot if present -- takes `host_execution_client_start` from the caller envelope -- takes `attach_mode_preference` from the caller envelope - -Exact lines: - -- persisted policy snapshot load: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:390](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:390) -- reconstructed attach knobs: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:452](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:452) - -Why this matters: - -- the plan text says persisted attach resolution should trust persisted `attach_launch_knobs` baseline and then apply attach-mode request checks -- the landed code instead treats two of those knobs as caller-supplied runtime inputs rather than durable baseline truth - -This is not necessarily a wrong runtime design, but it does not match the contract language that says persisted attach knobs are authoritative baseline truth. - -### Finding 3: missing attach state can still regain permissive/default truth - -Severity: Medium - -The closeout docs and plan describe birth-time durable attach truth as non-negotiable. There are still fallback paths that recreate weaker/default truth. - -Key references: - -- if a session has no host attach contract, `sync_host_attach_contract(...)` recreates one from manifest defaults: - - [crates/shell/src/execution/agent_runtime/orchestration_session.rs:388](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/orchestration_session.rs:388) -- if persisted policy is absent, persisted attach resolution falls back to `Policy::default()`: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:390](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:390) - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:403](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:403) - -Why this matters: - -- 29.5 explicitly called out the need to stop regaining permissive defaults from ambient/runtime state -- these fallback branches mean the durable truth is still not fully fail-closed in every path - -## Items That Look Correct - -### Inventory `policy_overlay` merge - -This appears to be landed correctly. - -Key references: - -- inventory resolution applies overlay into `effective_policy`: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:475](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:475) - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:653](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:653) -- overlay validation remains restriction-only: - - [crates/shell/src/execution/agent_inventory.rs:616](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_inventory.rs:616) - -### Bounded capability narrowing - -This also appears landed correctly for the explicitly approved family. - -Key references: - -- unsupported families fail closed: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:663](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:663) -- supported family only narrows from `true` to `false`: - - [crates/shell/src/execution/agent_runtime/dispatch_contract.rs:760](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/execution/agent_runtime/dispatch_contract.rs:760) - -### Retained member follow-up parity subset - -This looks substantially aligned with the 29.5 intent. - -Key references: - -- retained parity helper: - - [crates/shell/src/repl/async_repl.rs:4186](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:4186) -- typed follow-up dispatch uses parity subset instead of live descriptor drift: - - [crates/shell/src/repl/async_repl.rs:4677](/home/azureuser/__Active_Code/atomize-hq/substrate/crates/shell/src/repl/async_repl.rs:4677) - -## Test and Validation Notes - -Commands run during audit: - -```bash -cargo test -p shell --test agent_public_control_surface_v1 -- --nocapture -cargo test -p shell --test repl_world_first_routing_v1 -- --nocapture -cargo test -p shell --test agent_successor_contract_ahcsitc0 -- --nocapture -cargo test -p shell --test repl_world_first_routing_v1 c3_world_restart_invalidates_stale_member_generation_before_publish -- --nocapture -``` - -Observed results: - -- `agent_public_control_surface_v1`: passed -- `agent_successor_contract_ahcsitc0`: passed -- `repl_world_first_routing_v1`: initially showed one failure when large suites were run in parallel, but the failing case passed when rerun alone - -Important environment note: - -- later extra filtered `cargo test -p shell ...` attempts hit local environment failures including `No space left on device` and linker/tempdir failures inside `target/debug` -- those environment failures should not be interpreted as product regressions, but they did limit additional verification passes - -## Recommended Remediation Focus - -If a fresh session is planning the fix, the highest-value remediation target is: - -1. route REPL host-orchestrator cold start through the same shared dispatch contract used by the public/start path -2. carry a `ResolvedLaunchContract` or equivalent resolved-contract truth into REPL host session birth -3. persist `HostAttachContract` from `HostAttachContract::from_resolved_contract(...)` in that path -4. remove or quarantine fallback `from_manifest(...)` reconstruction for steady-state birth paths -5. then decide whether persisted attach knobs are truly durable baseline truth or caller-supplied attach-mode inputs, and align code plus docs one way or the other - -## Suggested Questions For The Next Session - -1. Should REPL host cold start produce a `ResolvedLaunchContract` directly, or should it wrap existing selection logic with the shared resolver before runtime materialization? -2. Is `attach_mode_preference` supposed to be persisted baseline truth, caller intent at attach time, or a split between baseline plus caller narrowing? -3. Should `effective_policy` be mandatory in persisted `HostAttachContract`, with missing policy treated as corruption instead of defaulting? -4. Can `HostAttachContract::from_manifest(...)` be restricted to compatibility/recovery-only usage so steady-state launch paths cannot silently bypass resolved-contract truth? - -## Bottom Line - -The slice is close, but it is not yet honest enough to call fully complete. - -The largest remaining issue is not in the public control path. It is in the REPL/orchestrator cold-start path, which still persists durable attach truth from manifest-era defaults instead of from the shared resolved contract that 29.5 says should now be authoritative everywhere. diff --git a/archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md b/archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md deleted file mode 100644 index ce36fb9cf..000000000 --- a/archive/UAA_PROMPTLESS_RESUME_FORK_SYNTHESIS.md +++ /dev/null @@ -1,355 +0,0 @@ -# UAA Promptless Resume/Fork Synthesis For Substrate - -Status: post-28.5 runtime synthesis, not a normative UAA spec -Date: 2026-05-24 UTC -Scope: record what the current Substrate runtime actually does after the control-only attach and honest successor-allocation split landed - -Unified Agent API repo referenced in this synthesis: - -- repo path: `/home/azureuser/__Active_Code/atomize-hq/unified-agent-api` -- branch observed during synthesis: `feat/promptless-resume` -- previously inspected commit during this line of work: `3b7a4ef` - -That UAA branch still matters because it contains promptless resume/fork behavior Substrate -evaluated during this execution slice. But the current Substrate runtime no longer depends on blank -prompt semantics to satisfy its public `reattach` and `fork` contracts. - -## Purpose - -This document captures the current answer to a narrower question than earlier drafts: - -Does the landed Substrate runtime still need Unified Agent API promptless resume or promptless fork -as part of its live architecture? - -Current answer: - -- not for public `reattach`, -- not for public `fork`, -- and not as the architectural meaning of hidden owner-helper attach either. - -Future UAA contract work may still choose to publish an explicit control-only resume surface if -that proves broadly useful. But blank prompt is no longer the mechanism Substrate needs in order to -honor its current durable-session model. - -## Current Recommendation - -1. Treat promptless UAA resume/fork as implementation behavior under evaluation, not as required - Substrate architecture. -2. Keep Substrate public semantics frozen: - - `start` is prompt-taking root start, - - `turn` is prompt-taking follow-up, - - `reattach` is control-only attached-owner recovery for the same durable session, - - `fork` is control-only successor durable-session allocation, - - detached-world follow-up stays fail-closed until host ownership returns. -3. Do not revive `prompt: ""` or `InitialExecPromptPlan::NoPromptRecovery` as the meaning of - public `reattach` or `fork`. -4. If UAA eventually needs a published control-only contract, prefer an explicit surface over - empty-prompt signaling. - -## Executive Summary - -Earlier drafts in this area were driven by a real mismatch: - -- Substrate needed control-only host reattachment and honest successor allocation, -- the old hidden owner-helper convergence reused prompt-bearing run shapes, -- and the local UAA branch had landed promptless resume/fork behavior. - -That mismatch is no longer the live runtime story. - -The current Substrate runtime now separates the three concerns explicitly: - -1. prompt-bearing launch and prompt-bearing resumed turn submission still go through prompt-bearing - run control; -2. control-only host attach uses a dedicated attach path that consumes persisted continuity without - inventing a blank prompt; -3. public `fork` allocates durable successor state directly inside Substrate and does not launch a - backend process at allocation time. - -As a result: - -- promptless UAA resume is no longer required to implement current public `reattach`, -- promptless UAA fork is not required for current public `fork`, -- and the strongest remaining argument for a future explicit UAA control-only resume surface is - architectural cleanliness, not an immediate Substrate blocker. - -## Relevant Substrate Truth - -### Durable authority is the orchestration session - -The durable authority is the Substrate-owned orchestration session, not one currently attached -backend process. - -Primary truth anchors: - -- [HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md](HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md) -- [ADR-0047](docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md) -- [23-host-orchestrator-durable-session-and-parked-resumable-ownership.md](llm-last-mile/23-host-orchestrator-durable-session-and-parked-resumable-ownership.md) -- [24-fix-host-bootstrap-readiness-and-clean-detach-parking.md](llm-last-mile/24-fix-host-bootstrap-readiness-and-clean-detach-parking.md) -- [25-host-durable-session-closeout-and-qa-hardening.md](llm-last-mile/25-host-durable-session-closeout-and-qa-hardening.md) - -Important consequences: - -- a clean prompt-driven backend exit must not automatically invalidate the durable host session; -- `parked_resumable` is valid session truth, not an owner-loss error; -- world-originated work may outlive the foreground host attachment; -- later control actions must reconstruct exact launch truth from durable state rather than from - whichever participant happened to be most recent. - -### Public semantics remain intentionally narrow - -Canonical public meaning: - -- `substrate agent start --backend ... --prompt ...` is root prompt-taking start; -- `substrate agent turn --session ... --backend ... --prompt ...` is prompt-taking follow-up on - the same durable session; -- `substrate agent reattach --session ...` is attached-owner recovery only and does not submit a - prompt; -- `substrate agent fork --session ...` allocates a successor durable session and returns it parked, - unattached, and truthfully non-active; -- detached-world follow-up stays fail-closed until host ownership is attached again. - -Primary anchors: - -- [HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md](HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md) -- [docs/USAGE.md](docs/USAGE.md) -- [PLAN.md](PLAN.md) -- [ORCH_PLAN.md](ORCH_PLAN.md) - -## Where Substrate Persists Attach Truth - -Substrate now persists attach-relevant truth under the orchestration session itself. - -Key places: - -- [crates/shell/src/execution/agent_runtime/orchestration_session.rs](crates/shell/src/execution/agent_runtime/orchestration_session.rs) -- [crates/shell/src/execution/agent_runtime/state_store.rs](crates/shell/src/execution/agent_runtime/state_store.rs) -- [crates/shell/src/execution/agent_runtime/control.rs](crates/shell/src/execution/agent_runtime/control.rs) -- [crates/shell/src/execution/agents_cmd.rs](crates/shell/src/execution/agents_cmd.rs) -- [crates/shell/src/repl/async_repl.rs](crates/shell/src/repl/async_repl.rs) - -Important internal rules: - -- `host_attach_contract` is the durable host attach truth carried by the orchestration session; -- `host_attach_contract.continuity_uaa_session_id` is private continuity state, not a public - selector; -- successor allocation copies attach-contract shape but clears inherited - `continuity_uaa_session_id`; -- public selectors still reject `internal.uaa_session_id`. - -## What The Current Substrate Runtime Actually Does - -### Prompt-bearing follow-up still uses prompt-bearing resume - -Normal public follow-up `turn` remains prompt-bearing and still fits ordinary resume semantics. - -Host path: - -- [submit_host_prompt_turn(...)](crates/shell/src/execution/agent_runtime/control.rs) - -World-member follow-up path: - -- [submit_turn(...)](crates/world-service/src/member_runtime.rs) -- [MemberTurnSubmitRequestV1 transport use](crates/shell/src/repl/async_repl.rs) - -Those paths carry a real prompt. They are not the problem this synthesis is about. - -### Control-only attach is now a dedicated runtime path - -The hidden owner-helper retained-owner flow now has an explicit attach mode instead of reusing -blank-prompt run shaping. - -Important flow: - -- attach planning uses the persisted `host_attach_contract` from the orchestration session; -- `build_attach_launch_plan(...)` carries forward the exact durable session id plus private - continuity selector when present; -- `start_host_orchestrator_runtime_with_prepared_prompt(...)` calls - `PromptFulfillmentBridge::run_attach_control(...)` when the startup mode is control-only attach; -- `run_attach_control(...)` maps backend-native attach/resume events into the existing control - stream and synthesizes canonical session-handle facets so readiness/persistence code can observe - attachment honestly. - -Primary anchors: - -- [build_attach_launch_plan(...)](crates/shell/src/execution/agents_cmd.rs) -- [start_host_orchestrator_runtime_with_prepared_prompt(...)](crates/shell/src/repl/async_repl.rs) -- [PromptFulfillmentBridge::run_attach_control(...)](crates/shell/src/execution/prompt_fulfillment.rs) - -This means current control-only reattach is implemented as explicit attach behavior, not as -`prompt: ""`. - -### Public `fork` is now durable successor allocation, not backend launch - -Public `fork` no longer needs promptless backend fork semantics in order to preserve honest -Substrate truth. - -Current behavior: - -- `allocate_fork_successor(...)` allocates the successor orchestration session and successor - participant directly in Substrate; -- the successor copies attach-contract shape from the source session; -- the successor clears inherited `continuity_uaa_session_id`; -- the successor is persisted as `parked_resumable` with `attached_participant_id = null`; -- public `run_fork(...)` returns the parked successor immediately and does not attach a live owner - loop. - -Primary anchors: - -- [allocate_fork_successor(...)](crates/shell/src/execution/agents_cmd.rs) -- [fork_successor_attach_contract(...)](crates/shell/src/execution/agent_runtime/orchestration_session.rs) -- [public_reattach_and_fork_preserve_exact_session_and_lineage_contracts](crates/shell/tests/agent_public_control_surface_v1.rs) - -This is a durable-state allocation action, not a hidden prompted run and not a backend-native -control-only fork. - -## What No Longer Matches Earlier Drafts - -The following older substrate-side assumptions are no longer live architecture: - -- `InitialExecPromptPlan::NoPromptRecovery` as the meaning of public `reattach` or `fork`; -- blank prompt being converted into UAA run requests to recover attached ownership; -- public `fork` needing `agent_api.session.resume.v1` or `agent_api.session.fork.v1` in order to - allocate a truthful successor session; -- hidden owner-helper `Fork` as a shared convergence mode that proved promptless fork pressure. - -The current runtime has replaced that convergence with: - -- dedicated control-only attach, -- prompt-bearing resumed-turn launch, -- and local successor allocation. - -## Relevant Unified Agent API Change - -The local UAA branch under evaluation still contains promptless resume/fork behavior: - -- `agent_api.session.resume.v1` -- `agent_api.session.fork.v1` - -Key implementation files in the local UAA checkout: - -- [../unified-agent-api/crates/agent_api/src/backend_harness/normalize.rs](../unified-agent-api/crates/agent_api/src/backend_harness/normalize.rs) -- [../unified-agent-api/crates/agent_api/src/backends/session_selectors.rs](../unified-agent-api/crates/agent_api/src/backends/session_selectors.rs) -- [../unified-agent-api/crates/agent_api/src/backends/codex/exec.rs](../unified-agent-api/crates/agent_api/src/backends/codex/exec.rs) -- [../unified-agent-api/crates/agent_api/src/backends/codex/fork.rs](../unified-agent-api/crates/agent_api/src/backends/codex/fork.rs) -- [../unified-agent-api/crates/agent_api/src/backends/codex/harness.rs](../unified-agent-api/crates/agent_api/src/backends/codex/harness.rs) -- [../unified-agent-api/crates/agent_api/src/backends/claude_code/util.rs](../unified-agent-api/crates/agent_api/src/backends/claude_code/util.rs) - -That behavior is still real in the UAA implementation tree. - -What changed on the Substrate side is the conclusion: - -- Substrate no longer needs blank-prompt resume/fork as the mechanism for its current public - control surfaces; -- the UAA implementation can still be interesting evidence for future contract design; -- but it is not a live dependency for this runtime slice. - -## Why Promptless Resume Is No Longer An Immediate Substrate Requirement - -There is still a meaningful architectural question about whether UAA should eventually publish an -explicit control-only resume surface. - -But the old immediate Substrate pressure has been relieved because: - -1. Substrate can now reattach through a dedicated attach-control path; -2. continuity stays private under the persisted host attach contract; -3. prompt-bearing follow-up remains on prompt-bearing `turn`; -4. public success truth is checked against actual attachment, not inferred from synthetic prompt - completion. - -So the current question is no longer "how do we make blank prompt safe enough?" It is "would an -explicit UAA control-only attach/resume surface still be worth standardizing later?" - -## Why Promptless Fork Is Not Needed For Current Substrate - -Current Substrate evidence is now much stronger than earlier drafts: - -1. public `fork` is satisfied by local durable successor allocation; -2. successor truth is honest without attaching a live owner loop; -3. inherited continuity is intentionally cleared on the successor; -4. no prompt-bearing follow-up is smuggled into `fork`; -5. the runtime no longer needs backend-native promptless fork to preserve public semantics. - -That makes promptless UAA fork unnecessary for the current architecture. - -## Recommended Direction - -### Direction A: keep current Substrate architecture and decouple it from blank prompt - -This is the active recommendation. - -- keep control-only attach inside the dedicated attach path; -- keep prompt-bearing follow-up on prompt-bearing `turn`; -- keep successor allocation as durable-state work; -- do not describe blank prompt as the architectural substrate for public `reattach` or `fork`. - -### Direction B: explore future explicit UAA control-only resume only if it buys clarity - -If future cross-backend work wants one published UAA control-only contract, prefer an explicit -surface rather than empty-prompt signaling. - -Examples to consider later: - -- an explicit attach/resume control API; -- a versioned resume extension with a first-class "no turn" mode; -- a gateway/private adapter seam if Substrate remains the only consumer. - -### Direction C: do not pursue promptless UAA fork unless requirements materially change - -There is no current Substrate requirement that justifies making promptless fork part of stable -published semantics. - -## Important Document Pointers - -### Substrate truth anchors - -- [HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md](HOST_ORCHESTRATOR_INTENDED_BEHAVIOR_TRUTH.md) -- [ADR-0047](docs/project_management/adrs/draft/ADR-0047-host-orchestrator-durable-session-and-parked-resumable-ownership.md) -- [23-host-orchestrator-durable-session-and-parked-resumable-ownership.md](llm-last-mile/23-host-orchestrator-durable-session-and-parked-resumable-ownership.md) -- [24-fix-host-bootstrap-readiness-and-clean-detach-parking.md](llm-last-mile/24-fix-host-bootstrap-readiness-and-clean-detach-parking.md) -- [25-host-durable-session-closeout-and-qa-hardening.md](llm-last-mile/25-host-durable-session-closeout-and-qa-hardening.md) -- [PLAN.md](PLAN.md) -- [ORCH_PLAN.md](ORCH_PLAN.md) - -### Substrate runtime files - -- [crates/shell/src/repl/async_repl.rs](crates/shell/src/repl/async_repl.rs) -- [crates/shell/src/execution/agent_runtime/control.rs](crates/shell/src/execution/agent_runtime/control.rs) -- [crates/shell/src/execution/agent_runtime/orchestration_session.rs](crates/shell/src/execution/agent_runtime/orchestration_session.rs) -- [crates/shell/src/execution/agent_runtime/state_store.rs](crates/shell/src/execution/agent_runtime/state_store.rs) -- [crates/shell/src/execution/agents_cmd.rs](crates/shell/src/execution/agents_cmd.rs) -- [crates/shell/src/execution/prompt_fulfillment.rs](crates/shell/src/execution/prompt_fulfillment.rs) -- [crates/world-service/src/member_runtime.rs](crates/world-service/src/member_runtime.rs) -- [docs/USAGE.md](docs/USAGE.md) - -### UAA normative docs - -Local UAA checkout under review: - -- repo: `/home/azureuser/__Active_Code/atomize-hq/unified-agent-api` -- branch: `feat/promptless-resume` -- commit previously observed in this line of work: `3b7a4ef` - -- [../unified-agent-api/docs/specs/unified-agent-api/run-protocol-spec.md](../unified-agent-api/docs/specs/unified-agent-api/run-protocol-spec.md) -- [../unified-agent-api/docs/specs/unified-agent-api/extensions-spec.md](../unified-agent-api/docs/specs/unified-agent-api/extensions-spec.md) -- [../unified-agent-api/docs/specs/claude-code-session-mapping-contract.md](../unified-agent-api/docs/specs/claude-code-session-mapping-contract.md) -- [../unified-agent-api/docs/specs/codex-wrapper-coverage-scenarios-v1.md](../unified-agent-api/docs/specs/codex-wrapper-coverage-scenarios-v1.md) -- [../unified-agent-api/docs/specs/codex-app-server-jsonrpc-contract.md](../unified-agent-api/docs/specs/codex-app-server-jsonrpc-contract.md) -- [../unified-agent-api/docs/specs/unified-agent-api/capability-matrix.md](../unified-agent-api/docs/specs/unified-agent-api/capability-matrix.md) - -## Questions To Keep Answering - -1. Would a published explicit UAA control-only resume surface simplify multi-backend adapter work - enough to justify the extra contract surface? -2. Should that future surface live in UAA proper, in the gateway adapter seam, or in a - Substrate-private control plane? -3. Do any future world-start or lazy-attach slices create a real new requirement that changes the - current "no promptless fork needed" conclusion? - -## Bottom Line - -Based on the current Substrate runtime: - -- promptless UAA resume is no longer required for live public `reattach`, -- promptless UAA fork is not required for live public `fork`, -- blank prompt should not be described as current Substrate architecture, -- and any future UAA control-only contract should be explicit rather than empty-prompt-shaped. diff --git a/docs/project_management/_archived/ci-improvements/CI_CHECKPOINTING_ADHOC_NOTES.md b/docs/project_management/_archived/ci-improvements/CI_CHECKPOINTING_ADHOC_NOTES.md deleted file mode 100644 index 4d536006e..000000000 --- a/docs/project_management/_archived/ci-improvements/CI_CHECKPOINTING_ADHOC_NOTES.md +++ /dev/null @@ -1,120 +0,0 @@ -# CI Checkpointing (Ad-Hoc Notes) - -Status: **implemented (CI checkpoints + boundary-only platform-fix + single wrapper)** - -This document captures an operator decision made during an interactive planning-system iteration, so we do not lose context. - -## Problem - -Cross-platform CI dispatch (compile parity, Feature Smoke, CI Testing) has become too frequent when executing long features with many slices/triads. - -Today, the default integration kickoff guidance effectively encourages cross-platform CI to be run per slice/triad, which creates: -- High latency (many redundant CI runs). -- High operational load (runners, queue time, repeated triage). -- Slower iteration despite the workflow being “autonomous”. - -## Decision - -Adopt **CI checkpoints**: run cross-platform CI at **bounded checkpoints** between groups of triads, rather than per triad. - -Key properties: -- CI checkpoints are **explicit planning artifacts** (not ad-hoc operator judgment). -- Checkpoints are chosen using **code-grounded boundaries** (subsystem seams, contract completion points) plus mechanical bounds. -- Per-slice local integration gates remain mandatory (fmt/clippy/tests + `make integ-checks`), but cross-platform CI is not dispatched for every slice. - -### Default bounds (non-negotiable defaults) - -- Default **minimum** triads per checkpoint: **2** -- Default **maximum** triads per checkpoint: **4** - -Notes: -- The plan must still be deterministic for very small features. If the total slice count is `< 2`, a single checkpoint may cover the entire feature. -- High-risk seams may justify earlier checkpoints even if it produces smaller groups (explicitly documented in the checkpoint plan). - -## New planning artifact - -Add a required planning-pack document: -- `docs/project_management/_archived/next//ci_checkpoint_plan.md` - -This document: -- Partitions the feature’s slices into checkpoint groups. -- Names the checkpoint task(s) that run CI. -- Defines which CI gates run at each checkpoint (compile parity vs smoke vs CI testing). -- Records the rationale for each checkpoint boundary. - -The plan must include a machine-readable section, and lint should validate: -- Every slice belongs to exactly one checkpoint group. -- Each group size respects min/max defaults (except the “total slices < min” case). -- The checkpoint tasks referenced by the plan exist in `tasks.json`. - -## Execution behavior - -- **CI audit (`scripts/ci-audit/ci_audit.sh`) remains in use**, but it becomes a **checkpoint tool**: - - Run it inside checkpoint tasks to decide skip/run and to record evidence (ledger + run ids). - - Do not run it as a default “every slice” requirement. - -## Implementation outline (repo changes) - -1) Add `PLANNING_CI_CHECKPOINT_STANDARD.md` and a `ci_checkpoint_plan.md` template. -2) Update planning prompts to require `ci_checkpoint_plan.md` and to use it when building tasks/kickoffs. -3) Introduce a checkpoint task template (`kickoff_ci_checkpoint.md.tmpl`) and scaffold at least one checkpoint task. -4) Update integration kickoff templates to: - - Always run local integration gates. - - Dispatch cross-platform CI only when the checkpoint plan says this slice is a checkpoint. -5) Update planning lint to fail when checkpoint plan and tasks drift (missing tasks, missing coverage, bounds violations). - -## Implemented (CI checkpoints) - -The following items are implemented in the repo: -- `docs/project_management/standards/PLANNING_CI_CHECKPOINT_STANDARD.md` -- `docs/project_management/system/templates/planning_pack/ci_checkpoint_plan.md.tmpl` -- `docs/project_management/system/templates/kickoff/kickoff_ci_checkpoint.md.tmpl` -- `docs/project_management/system/scripts/planning/validate_ci_checkpoint_plan.py` -- Planning lint requires and validates `ci_checkpoint_plan.md` for automation-enabled cross-platform packs. -- Integration kickoff templates explicitly remove “run cross-platform CI per slice” defaults (CI is a checkpoint-only activity). -- Cross-platform dispatch scripts support validating an exact commit (checkout-ref) so checkpoints can validate the merged state deterministically. - -## Implemented: boundary-only platform-fix + single wrapper - -### Problem (follow-on) - -Even with checkpoints, a cross-platform pack currently encourages per-slice cross-platform task fan-out: -- `-integ-core` -- `-integ-` -- `-integ` (final aggregator) - -That “platform-fix task explosion” is the slow part for many-triad features and doesn’t match the intent of checkpoints. - -### Decision - -Adopt **boundary-only platform-fix**: -- For **normal slices**: only `X-code`, `X-test`, `X-integ` exist (single per-slice integration merge task). -- For **checkpoint-boundary slices only**: full cross-platform structure exists: - - `B-integ-core` - - `B-integ-` (for each CI parity platform; plus WSL if required/separate) - - `B-integ` (final aggregator) - -### Detection primitive (machine-readable) - -Add `tasks.json` meta: -- `meta.checkpoint_boundaries`: array of slice ids that are **the last slice** in each checkpoint group. - -Rules: -- `meta.checkpoint_boundaries` must match `ci_checkpoint_plan.md` boundaries (lint/validation enforced). -- Only slices in `meta.checkpoint_boundaries` may define `*-integ-core` / `*-integ-` tasks. -- Code/test tasks’ `integration_task` must point to: - - `X-integ` for normal slices - - `B-integ-core` for boundary slices - -### Operator UX: single wrapper entrypoint - -Add a single automation entrypoint to run a slice “start → complete” end-to-end: -- `make triad-task-start-complete FEATURE_DIR="docs/project_management/_archived/next/" SLICE_ID=""` - -Requirements: -- Wrapper runs from the orchestration checkout and uses Codex-enabled automation internally (no extra flags required in the common case). -- Wrapper writes a deterministic log + summary under `{{FEATURE_DIR}}/logs//wrapper/` rather than only printing to stdout. -- Wrapper selects the correct per-slice integration merge task dynamically based on `tasks.json` (via the code/test task’s `integration_task` field). - -Notes: -- CI checkpoint tasks (e.g. `CPk-ci-checkpoint`) remain explicit ops tasks; this wrapper’s primary responsibility is the slice’s code/test/merge closure. diff --git a/docs/project_management/_archived/ci-improvements/ci-improvements.md b/docs/project_management/_archived/ci-improvements/ci-improvements.md deleted file mode 100644 index 4d67d5f15..000000000 --- a/docs/project_management/_archived/ci-improvements/ci-improvements.md +++ /dev/null @@ -1,246 +0,0 @@ -# CI Redundancy Reduction (Advisory) — Spec Draft - -## Problem Statement -We need to reduce redundant cross-platform CI (Linux/macOS/Windows, sometimes WSL) **without** sacrificing safety. The failures we must prevent are “green on my platform, failing later on another platform”, but we also want to avoid spending 30–60+ minutes re-running the same multi-OS jobs when there were no meaningful code changes since the last green run. - -This document proposes an **advisory** mechanism (recommendations only) that is **separate from**: -- triad task scripts (`make triad-task-start*`, `make triad-task-finish`, etc.) -- existing CI dispatch scripts (`scripts/ci/dispatch_ci_testing.sh`, `make ci-compile-parity`, `make feature-smoke`, etc.) - -The mechanism answers: -1. What OSes does this step *need* to be green on? -2. What OSes were *actually* green in the last CI run(s)? -3. Has anything changed since then that would justify re-running CI? - -Operator decision remains final: the tool recommends “skip/run”, and prints evidence and reasoning. - ---- - -## Evidence: C1 Ran Too Much CI -In slice C1, we ran multiple “CI Testing” and “Feature Smoke (behavior)” workflows against the same orchestration branch head(s), even when subsequent changes were docs/planning-only. - -We specifically want to prevent patterns like: -- Running “compile parity” (which is effectively “CI Testing”) and then running “CI Testing quick” and later “CI Testing full”, for the same or near-identical SHAs. -- Re-running “Feature Smoke (behavior)” even when the diff since the last successful smoke is docs-only. - -### Concrete Observation (C1) -After a point, changes were docs/planning-only (e.g. `docs/**`), yet multi-OS CI was dispatched again. Under the desired policy: -- **Docs/planning-only changes can skip all CI** (including smoke + final CI gate). - ---- - -## Goals / Non-Goals - -### Goals -- Reduce redundant CI runs when there are no relevant changes since a recent green run that already covers the required platforms. -- Provide a crystal-clear “what changed / what was last green / what is required” report. -- Stay conservative by default: if unsure, recommend running CI. -- Be **advisory** first: recommendations only, no enforcement. - -### Non-Goals (for the initial advisory version) -- Not rewriting task scripts or CI scripts. -- Not changing workflow behavior or matrix definitions. -- Not auto-reducing OS coverage based on heuristics (optional future). - ---- - -## Proposal: `ci-audit` (Advisory CI Coverage + Change Impact Checker) - -### High-Level Idea -`ci-audit` is a small CLI (or script) that: -1. Determines the **required OS coverage** for the current action: - - CI Testing typically requires: `linux,macos,windows` - - Feature Smoke (behavior) requires: from feature pack metadata (usually `tasks.json meta.behavior_platforms_required`), sometimes includes `wsl` -2. Finds the most recent **successful run evidence** that matches: - - same feature orchestration branch (or explicit workflow ref) - - the workflow kind being audited (CI Testing vs Feature Smoke) -3. Computes what OSes/jobs actually passed in that run. -4. Computes `git diff` between the last-green “tested SHA” and current `HEAD`, and classifies change impact: - - `docs_only` => recommend skip for **all CI and smoke** - - `code_affecting` => recommend run - - `unknown` => recommend run - -The output is a recommendation: **SKIP** or **RUN**, plus a reasoned breakdown. - -### Current Status -- Implemented v1 script: `scripts/ci-audit/ci_audit.sh` -- Advisory only (prints recommendation; does not dispatch CI) - ---- - -## Concrete Spec (v1: Minimal, Advisory) - -### CLI Shape -Proposed command (example): -```bash -scripts/ci-audit/ci_audit.sh \ - --feature-dir docs/project_management/_archived/next/ \ - --orch-branch feat/ \ - --kind feature-smoke \ - --head-sha "$(git rev-parse HEAD)" -``` - -Notes: -- v1 can be a bash script for speed of adoption, or Rust for long-term reliability. -- This is **not** a dispatcher. It does not run CI. It prints a recommendation and exits 0. - -### Required Inputs -- `--feature-dir ` - - Used to read `tasks.json` for behavior platform requirements. -- `--orch-branch ` - - Used to query GitHub Actions runs on that branch. -- `--kind ` -- `--required-platforms ` (optional override; useful if `tasks.json` isn’t available) -- `--head-sha ` (default `git rev-parse HEAD`) -- `--baseline-sha ` (optional override; otherwise uses last-green head SHA or merge-base with `origin/testing`) - -Optional: -- `--remote origin` (default `origin`) -- `--repo atomize-hq/substrate` (default inferred by `gh`) - -### Output Contract (Machine + Human Readable) -Human-friendly summary plus a stable key/value section: -``` -RECOMMEND=skip|run -REASON= -REQUIRED_PLATFORMS= -LAST_GREEN_RUN_ID= -LAST_GREEN_RUN_URL= -LAST_GREEN_HEAD_SHA= -LAST_PASSED_PLATFORMS= -DIFF_CLASS=docs_only|code_affecting|unknown -DIFF_FILES_COUNT= -DIFF_LOC= -``` - -### Platform/OS Coverage Rules -**CI Testing** -- `REQUIRED_PLATFORMS` default: `linux,macos,windows` -- Consider “passed” if the run has successful jobs matching: - - `Lint & Test (ubuntu-*)` => linux - - `Lint & Test (macos-*)` => macos - - `Lint & Test (windows-*)` => windows - -**Feature Smoke (behavior)** -- `REQUIRED_PLATFORMS` derived from: - - `jq -r '.meta.behavior_platforms_required // [] | join(",")' "$FEATURE_DIR/tasks.json"` -- Consider “passed” if successful jobs exist matching: - - `linux_*` => linux - - `macos_*` => macos - - `windows_*` => windows - - `wsl` => wsl - -### Change-Impact Classification (v1) -We want an extremely conservative classifier. - -**docs_only** (recommend SKIP for all CI and smoke) -- All changed paths are under: - - `docs/**` - - `docs/project_management/**` -- (Optionally: allow other non-product paths if we decide: e.g. `README.md`, but keep v1 small.) - -**code_affecting** (recommend RUN) -- Any change touches: - - `crates/**`, `src/**` - - `Cargo.toml`, `Cargo.lock` - - `.github/**` - - `scripts/**` - - `Makefile` - - Anything else not in the docs-only allowlist - -**unknown** (recommend RUN) -- No last-green run found, or cannot determine “tested SHA” reliably. - -### “Do We Even Need to Run CI?” Decision Rule (v1) -Given: -- `REQUIRED_PLATFORMS` -- last successful run’s `LAST_PASSED_PLATFORMS` -- `DIFF_CLASS` - -Recommend: -- If `DIFF_CLASS=docs_only` => `RECOMMEND=skip` (even if there is no last-green run) -- Else if `LAST_PASSED_PLATFORMS` covers all `REQUIRED_PLATFORMS` AND `git diff` is empty => `RECOMMEND=skip` -- Else => `RECOMMEND=run` - -Rationale: your stated policy explicitly allows skipping CI entirely when docs-only. For code, we require either “no changes since last full coverage” or we run. - ---- - -## Spec Extension (v2: Evidence Ledger for Stronger Guarantees) - -### Why a Ledger? -When dispatch scripts create throwaway branches, GitHub run metadata like `headSha` can represent the orchestration branch SHA rather than the exact “checkout SHA” validated by CI. - -To make skip decisions safe, we want an explicit record of: -- what SHA we intended to validate -- which platforms/jobs passed - -### Ledger Format (JSONL) -Location suggestion (survives `cargo clean`, and aligned with feature logs): -- `$FEATURE_DIR/logs//ci-audit/ledger.jsonl` - -Entry example: -```json -{ - "timestamp": "2026-01-27T12:34:56Z", - "orch_branch": "feat/", - "kind": "ci-testing", - "mode": "quick", - "tested_sha": "", - "required_platforms": ["linux","macos","windows"], - "passed_platforms": ["linux","macos","windows"], - "run_id": "2110....", - "run_url": "https://github.com/.../runs/....", - "conclusion": "success" -} -``` - -### Current Status -- Implemented ledger recording helper: `scripts/ci-audit/ci_audit_record.sh` -- Implemented ledger consumption in `ci-audit` via `--ledger-path`: - - `scripts/ci-audit/ci_audit.sh --ledger-path ...` - -### Ledger Write Policy -Because we are “separate from task/dispatch scripts”, v2 can work in either of these ways: -1. Operator runs `ci-audit record --run-id --tested-sha ...` after dispatch finishes. -2. Wrapper command for humans (not used by automation) that does: - - dispatch CI via existing script - - then records ledger evidence - -Either way, `ci-audit` can prefer ledger evidence over heuristics from GH run metadata. - ---- - -## Recommended Operator Workflow (Advisory) - -Before dispatching: -1. Run `ci-audit` for the relevant gate (CI Testing vs Feature Smoke). -2. If it says `RECOMMEND=skip`, you can confidently skip (especially for docs-only). -3. If it says `RECOMMEND=run`, dispatch normally. -4. (Optional v2) Record ledger evidence after the run completes to strengthen future recommendations. - ---- - -## Future (Optional) Improvements -These are not part of v1, but are natural extensions: - -1. **Platform-scoped recommendations**: - - If changes are strictly under `crates/world-mac-lima/**`, recommend macOS-only. - - Default remains “all 3” for shared crates. - -2. **Workflow stamping**: - - Update CI workflows to print `TESTED_SHA=` in job summaries or artifacts. - - Makes automated audit more reliable without a ledger. - -3. **Escalation path**: - - Keep “recommended” now; later add an enforce mode (opt-in) if desired. - ---- - -## Acceptance Criteria (for implementing v1 later) -- Given a docs-only diff, `ci-audit` recommends skip for both: - - CI Testing - - Feature Smoke -- Given a code-affecting diff, `ci-audit` recommends run. -- Given no diff since a recent run that covers required platforms, `ci-audit` recommends skip. -- Output is clear and copy/pastable into session logs. diff --git a/docs/project_management/_archived/config-subcommand/config_subcommand_plan.md b/docs/project_management/_archived/config-subcommand/config_subcommand_plan.md deleted file mode 100644 index 0e6d6960c..000000000 --- a/docs/project_management/_archived/config-subcommand/config_subcommand_plan.md +++ /dev/null @@ -1,137 +0,0 @@ -# Config Subcommand Plan - -## Context - -The backlog’s top priority requests a first-class configuration UX: CLI commands -to scaffold, inspect, and edit `~/.substrate/config.toml` while retaining the -existing precedence stack (flags → directory config → global config → env). -Settings Stack work delivered the parsing/resolution logic, but today users must -edit TOML manually and the CLI only hints that the file is missing. This plan -builds the dedicated `substrate config` subcommand family so operators can: - -- Run `substrate config init` to bootstrap or regenerate the config directory. -- Review defaults through `substrate config show` (humans or automation via - `--json`). -- Update any key dynamically with `substrate config set key=value [...]`. - -The workflow mirrors `docs/project_management/_archived/next/refactor` to keep agents in -lock-step on `feat/config-subcommand`. - -## Goals - -1. **CLI foundation** – Introduce a `config` subcommand group (`init`, `show`, - `set`) wired into Clap, invoke-able before the shell/REPL starts, and guarded - by the same platform policies as existing commands. -2. **Bootstrap & diagnostics** – `substrate config init` creates - `~/.substrate/config.toml` (and parent directories) with default `[install]` - and `[world]` tables, supports `--force` regeneration, and updates shell and - installer error paths to mention the command when the file is missing. -3. **Readable output** – `substrate config show` prints the resolved global - config (TOML by default, JSON with `--json`), redacts sensitive fields, and - exits non-zero when the file is absent unless `init` is run. -4. **Dynamic setters** – `substrate config set key=value ...` accepts one or - more dotted keys (e.g., `world.anchor_mode=follow-cwd`, - `install.world_enabled=false`), validates values against supported schemas - (mode enums, booleans, paths), preserves unknown keys, and writes atomically. -5. **Docs & automation** – `docs/CONFIGURATION.md` and `docs/USAGE.md` showcase - the CLI flow on macOS/Linux **and** Windows (explicit `~/.substrate` vs - `%USERPROFILE%\.substrate` paths, PowerShell usage). Integration tests cover - `init`/`show`/`set` using `SUBSTRATE_HOME`/`USERPROFILE` overrides so both - platforms are validated, with JSON output and multi-key edits documented. - Installer scripts (`install-substrate.sh` and `.ps1`) include matching hints. - -## Baseline Standards & References - -- Repository guardrails: `AGENTS.md`. -- Backlog source: `docs/BACKLOG.md` (Global configuration UX section). -- Settings stack context: `docs/project_management/_archived/settings-stack/`. -- CLI implementation sites: - - `crates/shell/src/execution/cli.rs` - - `crates/shell/src/execution/invocation.rs` - - `crates/shell/src/execution/settings.rs` - - `crates/shell/tests` -- Installer scripts (`scripts/substrate/install-substrate.sh`, - `scripts/substrate/uninstall.sh`) for config scaffolding references. -- Documentation touchpoints: `docs/CONFIGURATION.md`, `docs/USAGE.md`, - `docs/INSTALLATION.md`. -- Tooling expectations: `cargo fmt --all -- --check`, `cargo clippy --workspace --all-targets -- -D warnings`, - targeted `cargo test` suites and integration scripts per kickoff prompts. - -## Guardrails & Workflow Expectations - -Every agent works on `feat/config-subcommand`. Reuse the refactor program’s -discipline: doc-only commits on the main branch, production/test work in -dedicated branches + worktrees, and mirrored specs between code and test roles. - -### Start Checklist (feat/config-subcommand) - -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read this plan, `tasks.json`, the latest `session_log.md`, and the kickoff - prompt for your task. -3. Update `tasks.json` (set your task to `in_progress`) and append a START entry - to the session log. Commit the doc-only change on `feat/config-subcommand` - (`git commit -am "docs: start "`). -4. Create a task-specific branch and worktree (never edit production/tests from - the root checkout): - ``` - git checkout -b - git worktree add wt/ - cd wt/ - ``` - -### Active Work (worktree) - -- Stay within your prompt’s scope. Code agents avoid test files; test agents - avoid production code except permitted helpers; integration agents merge only. -- Capture commands/results you’ll document in the END log entry. -- Keep worktree commits focused and reference acceptance criteria. - -### End Checklist - -1. Ensure fmt/lint/tests per prompt have passed in the worktree. -2. Commit worktree changes with descriptive messages. -3. Merge/cherry-pick onto the task branch (if needed), then fast-forward merge - into `feat/config-subcommand`. -4. Update `tasks.json` (mark `completed`), append an END session entry with - commands/results, and author required kickoff prompts for the next role. -5. Commit the doc updates on `feat/config-subcommand` - (`git commit -am "docs: finish "`). -6. Remove finished worktrees (`git worktree remove wt/`) and push - or hand off as instructed. - -### Role Responsibilities - -| Role | Allowed work | Forbidden work | -| ----------- | ----------------------------------------------------------------------------- | -------------------------------------------- | -| Code agent | Production code, CLI plumbing, installer/documentation changes referenced. | Editing tests beyond minimal helper stubs. | -| Test agent | Unit/integration tests, fixtures, harness scripts, kickoff prompts. | Touching production logic. | -| Integration | Merge code/test branches, resolve conflicts, run fmt/clippy/tests, update docs/logs/tasks. | Adding features or net-new tests. | - -Kickoff prompts must: -- Mirror the same specification between code and test tasks. -- Declare required commands/tests/scripts, guardrails, and success criteria. -- For integration tasks, restate that the job is to merge code/test branches, - resolve differences, and ensure combined behavior matches the spec before - updating docs/tasks/logs. - -## Configuration CLI Tracks - -1. **C1 – CLI foundation & init flow** - Add the `config` subcommand skeleton, implement `config init` with `--force`, - and update shell diagnostics/installers to prompt users when `config.toml` - is missing. Acceptance includes verifying macOS/Linux and Windows messages - (PowerShell/cmd). -2. **C2 – Show command & serialization** - Implement `config show` with human-readable output and `--json`, integrate - redaction safeguards, and document usage for both POSIX shells and PowerShell - (quoting guidance, path formatting). Tests cover `SUBSTRATE_HOME`/`USERPROFILE` - overrides. -3. **C3 – Dynamic setters & validation** - Deliver `config set key=value ...` with multi-key support, schema-aware - validation, atomic writes, JSON-capable outputs, and explicit handling for - Windows (CRLF writes, case-insensitive drives). Docs include Windows examples - and PowerShell quoting advice. - -Each track has paired code/test tasks plus an integration task to merge them. -See `tasks.json` for dependencies, acceptance criteria, and worktree names; use -the kickoff prompts in `kickoff_prompts/` for per-task execution details. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-code.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-code.md deleted file mode 100644 index ca6fe9abe..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-code.md +++ /dev/null @@ -1,55 +0,0 @@ -# Task C1-code (Config CLI foundation & init) – CODE - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, the backlog - entry in `docs/BACKLOG.md`, and this prompt. -3. Set `C1-code` to `in_progress` in `tasks.json`, add a START entry to - `session_log.md`, and commit the doc update - (`git commit -am "docs: start C1-code"`). -4. Create the task branch and worktree: - ``` - git checkout -b cs-c1-config-code - git worktree add wt/cs-c1-config-code cs-c1-config-code - cd wt/cs-c1-config-code - ``` - Do **not** edit docs/tasks/session logs from the worktree. - -## Spec (shared with C1-test) -- Add a `config` subcommand group to the CLI with an `init` verb available before - shell/REPL execution. -- `substrate config init`: - - Creates `~/.substrate/config.toml` and required parent directories. - - Writes default `[install]` and `[world]` tables (align with current schema). - - Supports `--force` to regenerate even if the file exists. -- Shell startup (and installer scripts) log a clear hint (“run `substrate config - init`”) when the config is missing instead of silently failing. -- Command exits zero on success, non-zero on error; errors bubble with context. -- Docs (`docs/CONFIGURATION.md`, `docs/USAGE.md`) reference the new command and - describe when to run it. - -## Scope & Guardrails -- Production code plus necessary doc changes only. **Tests are owned by C1-test.** -- Touch CLI parsing, invocation plumbing, settings helpers, and installer - scripts as needed; avoid unrelated refactors. -- Keep behavior consistent across Unix/Windows; ensure SUBSTRATE_HOME override - works for tests. - -## Suggested Commands -``` -cargo fmt -cargo clippy -p substrate-shell -- -D warnings -cargo test -p substrate-shell world_root -``` -(Record any additional commands or skips in the END log entry.) - -## End Checklist -1. Ensure fmt/clippy/tests above are green; capture outputs for the log. -2. Commit worktree changes with a descriptive message - (e.g., `feat: add substrate config init command`). -3. Merge the task branch back into `feat/config-subcommand` (fast-forward only). -4. Update `tasks.json` (status → `completed`) and append an END entry to - `session_log.md` with commands/results/blockers; commit the doc updates on - `feat/config-subcommand` (`git commit -am "docs: finish C1-code"`). -5. Remove the worktree (`git worktree remove wt/cs-c1-config-code`) and hand off - per instructions. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-integ.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-integ.md deleted file mode 100644 index 5093d4c84..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-integ.md +++ /dev/null @@ -1,43 +0,0 @@ -# Task C1-integ (Integrate config init) – INTEGRATION - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Confirm `C1-code` and `C1-test` are marked `completed` with branches pushed. -3. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -4. Set `C1-integ` to `in_progress`, add a START entry to the session log, and - commit the doc update (`git commit -am "docs: start C1-integ"`). -5. Create the integration branch/worktree: - ``` - git checkout -b cs-c1-config-integ - git worktree add wt/cs-c1-config-integ cs-c1-config-integ - cd wt/cs-c1-config-integ - ``` - -## Duties -- Merge `cs-c1-config-code` and `cs-c1-config-test` into the integration branch, - resolving conflicts (docs/tests/code) while preserving the agreed spec. -- Run required commands and record outputs: - ``` - cargo fmt - cargo clippy -p substrate-shell -- -D warnings - cargo test -p substrate-shell world_root - ./tests/installers/install_smoke.sh # or document skip if platform-restricted - ``` -- Spot-check docs/help output for the new `config init` command. -- Ensure net result still hints users when config is missing. - -## Guardrails -- No new functionality or tests; focus on merging and validation. -- If conflicts arise, coordinate solutions that honor both branches’ intent; - document any follow-up tasks if gaps remain. - -## End Checklist -1. After fmt/clippy/tests succeed, commit integration fixes in the worktree - (e.g., `chore: integrate config init code+tests`). -2. Merge the integration branch back into `feat/config-subcommand` - (fast-forward) and remove the worktree when finished. -3. Update `tasks.json` (status → `completed`), append an END entry to - `session_log.md` with command results, and create kickoff prompts for - `C2-code` and `C2-test`. -4. Commit the doc updates on `feat/config-subcommand` - (`git commit -am "docs: finish C1-integ"`). Hand off per workflow. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-test.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-test.md deleted file mode 100644 index 619d874ed..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C1-test.md +++ /dev/null @@ -1,52 +0,0 @@ -# Task C1-test (Config CLI foundation & init) – TEST - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, - `docs/BACKLOG.md`, and this prompt. -3. Set `C1-test` to `in_progress` in `tasks.json`, add a START entry to - `session_log.md`, and commit the doc update - (`git commit -am "docs: start C1-test"`). -4. Create the task branch/worktree: - ``` - git checkout -b cs-c1-config-test - git worktree add wt/cs-c1-config-test cs-c1-config-test - cd wt/cs-c1-config-test - ``` - Keep docs/tasks/session log edits on `feat/config-subcommand`, not in - the worktree. - -## Spec (shared with C1-code) -- Exercise `substrate config init` through the shell driver: - - File created with `[install]` + `[world]` defaults under a temp HOME. - - `--force` rewrites the file when user edits exist. -- When config is missing, launching `substrate` (or installer helper) should - emit a hint instructing users to run `substrate config init`; tests capture - stderr/stdout to assert the message. -- Ensure SUBSTRATE_HOME overrides are respected so tests stay isolated. -- Do not touch production code except for minor test-only helpers (e.g., fixture - builders). - -## Scope & Guardrails -- Test files only: `crates/shell/tests`, `tests/installers/*`, fixtures. -- Keep prompts/spec mirrored with C1-code; assume code branch is not visible. -- Document skipped commands (e.g., installer smoke) with justification. - -## Suggested Commands -``` -cargo fmt -cargo test -p substrate-shell world_root -./tests/installers/install_smoke.sh # run when platform permits; otherwise note skip -``` - -## End Checklist -1. Ensure required fmt/tests above are green (or skipped with notes); capture - outputs for the log. -2. Commit worktree changes with a descriptive message - (e.g., `test: cover substrate config init scaffolding`). -3. Merge the branch back into `feat/config-subcommand` (fast-forward). -4. Update `tasks.json` (status → `completed`), append an END entry to - `session_log.md` with commands/results/blockers, and author the - `C1-integ` kickoff prompt if it does not already exist. -5. Commit the doc updates on `feat/config-subcommand` - (`git commit -am "docs: finish C1-test"`), remove the worktree, and hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-code.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-code.md deleted file mode 100644 index df1765ce3..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-code.md +++ /dev/null @@ -1,42 +0,0 @@ -# Task C2-code (Config show command) – CODE - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -3. Set `C2-code` to `in_progress`, log START entry, and commit doc update - (`git commit -am "docs: start C2-code"`). -4. Create branch/worktree: - ``` - git checkout -b cs-c2-show-code - git worktree add wt/cs-c2-show-code cs-c2-show-code - cd wt/cs-c2-show-code - ``` - -## Spec (shared with C2-test) -- Implement `substrate config show`: - - Default output: pretty TOML representation of `~/.substrate/config.toml`. - - `--json` flag prints machine-readable JSON. - - Missing file surfaces hint to run `substrate config init`. - - Redaction hook exists for potential sensitive fields (even if none today). -- Command exits 0 on success, non-zero on errors; no side effects. -- Docs updated (`docs/CONFIGURATION.md`, `docs/USAGE.md`) with human/JSON examples. - -## Scope & Guardrails -- Production code + docs only. Tests belong to C2-test. -- Reuse existing parsing logic; avoid reimplementing `resolve_world_root`. -- Keep behavior cross-platform; ensure SUBSTRATE_HOME override respected. - -## Suggested Commands -``` -cargo fmt -cargo clippy -p substrate-shell -- -D warnings -cargo test -p substrate-shell world_root -``` - -## End Checklist -1. Confirm fmt/clippy/tests succeed; note outputs. -2. Commit worktree changes (e.g., `feat: add substrate config show command`). -3. Merge branch back to `feat/config-subcommand` (fast-forward). -4. Update `tasks.json` + `session_log.md` (END entry) and commit - (`git commit -am "docs: finish C2-code"`). Mention doc updates. -5. Remove worktree and hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-integ.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-integ.md deleted file mode 100644 index 4b691e9b1..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-integ.md +++ /dev/null @@ -1,39 +0,0 @@ -# Task C2-integ (Integrate config show) – INTEGRATION - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Verify `C2-code` and `C2-test` are completed with branches available. -3. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -4. Set `C2-integ` to `in_progress`, log START entry, commit doc update - (`git commit -am "docs: start C2-integ"`). -5. Create branch/worktree: - ``` - git checkout -b cs-c2-show-integ - git worktree add wt/cs-c2-show-integ cs-c2-show-integ - cd wt/cs-c2-show-integ - ``` - -## Duties -- Merge `cs-c2-show-code` and `cs-c2-show-test`; resolve conflicts and ensure - combined behavior matches the shared spec. -- Commands to run/log: - ``` - cargo fmt - cargo clippy -p substrate-shell -- -D warnings - cargo test -p substrate-shell world_root - cargo test -p substrate-shell world_enable - ``` - (Add installer smoke if relevant; document skips.) -- Spot-check CLI help and docs to ensure `config show` appears as expected. - -## Guardrails -- No new functionality or tests—merge and validate only. -- Coordinate with prior agents if conflicts require spec interpretation. - -## End Checklist -1. Commit integration fixes (e.g., `chore: integrate config show code+tests`). -2. Fast-forward merge into `feat/config-subcommand`, remove worktree afterward. -3. Update `tasks.json` (status → `completed`) and session log (END entry with - command results). Create kickoff prompts for `C3-code` and `C3-test`. -4. Commit doc updates on `feat/config-subcommand` - (`git commit -am "docs: finish C2-integ"`). Hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-test.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-test.md deleted file mode 100644 index ad5dca7cb..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C2-test.md +++ /dev/null @@ -1,41 +0,0 @@ -# Task C2-test (Config show command) – TEST - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -3. Set `C2-test` to `in_progress`, log START entry, and commit doc update - (`git commit -am "docs: start C2-test"`). -4. Create branch/worktree: - ``` - git checkout -b cs-c2-show-test - git worktree add wt/cs-c2-show-test cs-c2-show-test - cd wt/cs-c2-show-test - ``` - -## Spec (shared with C2-code) -- Tests invoke `substrate config show`: - - Validate TOML output matches file contents under a temp HOME. - - Validate `--json` output parses and mirrors the same data. - - Ensure missing config path emits hint to run `config init`. - - Cover redaction hook by simulating a sensitive key (even placeholder). -- Keep tests hermetic via `SUBSTRATE_HOME`/`TMPDIR`. - -## Scope & Guardrails -- Test files only. Minimal helpers allowed for fixtures. -- Document any skipped scripts (e.g., installer smoke) with reason. - -## Suggested Commands -``` -cargo fmt -cargo test -p substrate-shell world_root -``` -(Run installer smoke if viable.) - -## End Checklist -1. Confirm fmt/tests (and any scripts) are green; note outputs/skips. -2. Commit worktree changes (e.g., `test: cover substrate config show output`). -3. Merge branch into `feat/config-subcommand` (fast-forward). -4. Update `tasks.json` (status → `completed`), append END entry to session log, - and ensure `C2-integ` prompt exists. Commit doc updates - (`git commit -am "docs: finish C2-test"`). -5. Remove worktree and hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-code.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-code.md deleted file mode 100644 index c78dac637..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-code.md +++ /dev/null @@ -1,46 +0,0 @@ -# Task C3-code (Config set command) – CODE - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -3. Set `C3-code` to `in_progress`, log START entry, commit doc update - (`git commit -am "docs: start C3-code"`). -4. Create branch/worktree: - ``` - git checkout -b cs-c3-set-code - git worktree add wt/cs-c3-set-code cs-c3-set-code - cd wt/cs-c3-set-code - ``` - -## Spec (shared with C3-test) -- Implement `substrate config set key=value [...]`: - - Accept one or more `key=value` arguments using dotted keys (e.g., - `world.anchor_mode=follow-cwd`, `install.world_enabled=false`, - `world.caged=true`). - - Validate values: anchor modes limited to supported enum, booleans for toggles, - strings/paths for others. - - Apply all updates atomically (write temp file + rename). - - Expose `--json` to emit a summary of applied changes. - - Preserve unknown keys and emit clear errors without mutation on invalid input. -- Docs updated with examples and multi-key guidance. - -## Scope & Guardrails -- Production code + docs. Tests belong to C3-test. -- Reuse existing config parsing helpers; consider a generic setter utility. -- Ensure precedence stack unchanged: CLI/env overrides still win at runtime. - -## Suggested Commands -``` -cargo fmt -cargo clippy -p substrate-shell -- -D warnings -cargo test -p substrate-shell world_root -cargo test -p substrate-shell world_enable -``` - -## End Checklist -1. Confirm commands above succeed; log outputs. -2. Commit worktree changes (e.g., `feat: add substrate config set command`). -3. Merge branch into `feat/config-subcommand`. -4. Update `tasks.json` + `session_log.md` (END entry), ensure C3-test prompt is - referenced, and commit docs (`git commit -am "docs: finish C3-code"`). -5. Remove worktree and hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-integ.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-integ.md deleted file mode 100644 index 2030033dc..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-integ.md +++ /dev/null @@ -1,41 +0,0 @@ -# Task C3-integ (Integrate config set) – INTEGRATION - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Confirm `C3-code` and `C3-test` completed. -3. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -4. Set `C3-integ` to `in_progress`, log START entry, and commit doc update - (`git commit -am "docs: start C3-integ"`). -5. Create branch/worktree: - ``` - git checkout -b cs-c3-set-integ - git worktree add wt/cs-c3-set-integ cs-c3-set-integ - cd wt/cs-c3-set-integ - ``` - -## Duties -- Merge `cs-c3-set-code` and `cs-c3-set-test`, resolve conflicts, and ensure the - combined CLI behaves per spec (multi-key set, validation, JSON output). -- Run/log required commands: - ``` - cargo fmt - cargo clippy -p substrate-shell -- -D warnings - cargo test -p substrate-shell world_root - cargo test -p substrate-shell world_enable - ./tests/installers/install_smoke.sh # document skip if needed - ``` -- Spot-check docs/help/backlog to ensure the global configuration UX acceptance - criteria are now satisfied. - -## Guardrails -- No new functionality or tests beyond reconciliation fixes. -- Document any remaining gaps (parking lot/backlog) if the acceptance criteria - still need follow-up. - -## End Checklist -1. Commit integration fixes (e.g., `chore: integrate config set code+tests`). -2. Fast-forward merge into `feat/config-subcommand`, remove worktree afterward. -3. Update `tasks.json` (status → `completed`), append END entry to session log - with command outputs, and note backlog status in the log if applicable. -4. Commit doc updates on `feat/config-subcommand` - (`git commit -am "docs: finish C3-integ"`). Hand off or close out project. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-test.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-test.md deleted file mode 100644 index b88a219c2..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/C3-test.md +++ /dev/null @@ -1,46 +0,0 @@ -# Task C3-test (Config set command) – TEST - -## Start Checklist (feat/config-subcommand) -1. `git checkout feat/config-subcommand && git pull --ff-only` -2. Read `config_subcommand_plan.md`, `tasks.json`, `session_log.md`, and this prompt. -3. Set `C3-test` to `in_progress`, log START entry, and commit doc update - (`git commit -am "docs: start C3-test"`). -4. Create branch/worktree: - ``` - git checkout -b cs-c3-set-test - git worktree add wt/cs-c3-set-test cs-c3-set-test - cd wt/cs-c3-set-test - ``` - -## Spec (shared with C3-code) -- Tests cover `substrate config set`: - - Single-key updates (each supported field) and multi-key runs updating - anchor mode/path + install fields simultaneously. - - Validation errors (invalid enum, non-boolean) must exit non-zero and leave - files untouched. - - `--json` output parsed to confirm reported keys/values. - - Atomicity: simulate crash via temporary dir to ensure file not partially - written. -- Confirm precedence stack unaffected: CLI flag still overrides file even after - `config set`, captured via environment-driven test. - -## Scope & Guardrails -- Tests only; do not modify production code beyond helper hooks. -- Use hermetic HOMEs and temp dirs to avoid polluting real configs. - -## Suggested Commands -``` -cargo fmt -cargo test -p substrate-shell world_root -cargo test -p substrate-shell world_enable -``` -(Installer smoke optional; document if skipped.) - -## End Checklist -1. Ensure tests/commands succeed; capture outputs/skips. -2. Commit worktree changes (e.g., `test: cover substrate config set CLI`). -3. Merge into `feat/config-subcommand`. -4. Update `tasks.json` (status → `completed`), append END entry to session log, - ensure `C3-integ` prompt exists, and commit docs - (`git commit -am "docs: finish C3-test"`). -5. Remove worktree and hand off. diff --git a/docs/project_management/_archived/config-subcommand/kickoff_prompts/README.md b/docs/project_management/_archived/config-subcommand/kickoff_prompts/README.md deleted file mode 100644 index 47fca8b4c..000000000 --- a/docs/project_management/_archived/config-subcommand/kickoff_prompts/README.md +++ /dev/null @@ -1,16 +0,0 @@ -# Kickoff Prompts (Config Subcommand) - -Store per-task kickoff prompts here using the filenames referenced in -`tasks.json` (e.g., `C1-code.md`). Each prompt must include: -- Start checklist (feat/config-subcommand) with explicit branch/worktree names. -- Scope/acceptance criteria mirrored between code/test counterparts. -- Required commands/tests/scripts and guardrails for the task. -- End checklist plus artifacts to capture (commits, prompts, logs). - -Guardrails: -- Code vs test prompts **must describe the exact same spec** so the two roles - work independently. Code agents avoid editing tests; test agents derive tests - solely from the prompt. -- Integration prompts must focus on merging the paired branches/worktrees, - reconciling conflicts, running fmt/clippy/tests, and updating docs/tasks/logs - on `feat/config-subcommand`. diff --git a/docs/project_management/_archived/config-subcommand/session_log.md b/docs/project_management/_archived/config-subcommand/session_log.md deleted file mode 100644 index 24c01f33f..000000000 --- a/docs/project_management/_archived/config-subcommand/session_log.md +++ /dev/null @@ -1,145 +0,0 @@ -# Config Subcommand – Session Log - -Follow the workflow in `config_subcommand_plan.md`. Every entry must include: -- Timestamp (UTC), agent role (code/test/integ), and task ID. -- Commands executed (fmt/clippy/tests/scripts) with pass/fail notes. -- Commits/worktrees referenced. -- Kickoff prompts authored for downstream roles. - -Template: -``` -## [YYYY-MM-DD HH:MM UTC] – START -- Checked out feat/config-subcommand, pulled latest -- Updated tasks.json + session log (commit: ) -- Created worktree: wt/<...> -- Plan: -- Blockers: - -## [YYYY-MM-DD HH:MM UTC] – END -- Worktree commits: -- Commands: -- Results: -- Kickoff prompts created: -- Docs commit: (tasks/session log updates) -- Next steps / blockers: -``` - -## [2025-11-25 18:55 UTC] Code – C1-code – START -- Checked out feat/config-subcommand; `git pull --ff-only` unavailable (branch has no upstream yet) -- Updated tasks.json (C1-code → in_progress); session log entry pending commit -- Plan: add config CLI group + init verb, update installer/shell hints, refresh docs, run fmt/clippy/tests, merge branch -- Blockers: none - -## [2025-11-25 18:56 UTC] Test – C1-test – START -- Checked out feat/config-subcommand; `git pull --ff-only` unavailable (branch has no upstream) -- Updated tasks.json (C1-test → in_progress); session log entry pending commit -- Created plan: add shell driver tests for `config init` + `--force`, cover missing-config hint, and extend installer smoke harness; run fmt + targeted tests, document installer script skip if needed -- Blockers: git branch lacks upstream; otherwise none - -## [2025-11-25 19:06 UTC] Code – C1-code – END -- Worktree commits: 43abc73 (feat: add substrate config init command) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root` -- Results: all passed; config CLI builds cleanly and existing world root tests continue to succeed -- Kickoff prompts created: n/a -- Docs commit: (pending – will land as `docs: finish C1-code`) -- Next steps / blockers: Ready for C1-test to cover CLI behavior; integration can follow once tests land - -## [2025-11-25 19:22 UTC] Integration – C1-integ – START -- Checked out feat/config-subcommand; `git pull --ff-only` unavailable (branch has no upstream) -- Confirmed C1-code status `completed`; C1-test still marked `in_progress` in tasks.json though branch `cs-c1-config-test` includes commit ed4f2e6 – proceeding after noting mismatch -- Updated tasks.json (C1-integ → in_progress); session log entry pending commit -- Plan: create cs-c1-config-integ branch/worktree, merge code/test branches, resolve conflicts per spec, run `cargo fmt`, `cargo clippy -p substrate-shell -- -D warnings`, `cargo test -p substrate-shell world_root`, and `./tests/installers/install_smoke.sh`, validate docs/help text, update hints for missing config, and close out docs/tasks/logs with kickoff prompts for C2-code/test -- Blockers: upstream tracking absent for feat/config-subcommand; need to verify installer smoke compatibility on this platform - -## [2025-11-25 19:29 UTC] Integration – C1-integ – END -- Worktree commits: f17dc27 (chore: integrate config init code+tests) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `./tests/installers/install_smoke.sh`; `cargo run -p substrate --bin substrate -- config --help` -- Results: fmt/clippy/tests passed; installer smoke initially failed because the script never mentioned `substrate config init`, added an unconditional hint in both macOS/Linux post-install logs and reran successfully; `cargo run ... config --help` spot-check confirmed the new subcommand is documented -- Kickoff prompts created: docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-code.md, docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-test.md (already present; revalidated for next agents) -- Docs commit: (pending – will land as `docs: finish C1-integ`) -- Next steps / blockers: feat/config-subcommand now fast-forwarded with merged code+tests; tasks still list C1-test as `in_progress`, consider reconciling status in a follow-up if needed - -## [2025-11-25 19:31 UTC] Code – C2-code – START -- Checked out feat/config-subcommand; `git pull --ff-only` still blocked because the branch lacks an upstream remote -- Updated tasks.json (C2-code → in_progress) and session log for this entry; commit pending per checklist -- Plan: branch/worktree for cs-c2-show-code, implement `config show` TOML/JSON output with redaction hook, refresh docs, run fmt/clippy/tests, then merge back and update tasks/logs -- Blockers: none beyond missing upstream; local toolchain ready - -## [2025-11-25 19:37 UTC] Code – C2-code – END -- Worktree commits: 014a2b5 (feat: add substrate config show command) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root` -- Results: all commands passed; show command prints TOML by default, `--json` emits machine-readable output, missing-config path returns a hint to run `config init` -- Kickoff prompts created: n/a -- Docs commit: (pending – will land as `docs: finish C2-code`) -- Next steps / blockers: ready for C2-test + integration; worktree removal queued after final docs commit - -## [2025-11-25 20:05 UTC] Test – C2-test – START -- Checked out feat/config-subcommand; `git pull --ff-only` failed (branch has no upstream remote configured) -- Updated tasks.json (C2-test → in_progress); this session log entry staged for the same doc commit -- Plan: create cs-c2-show-test branch/worktree, add hermetic tests for `substrate config show` covering TOML vs `--json`, missing-config hints, and redaction hook; run `cargo fmt` + `cargo test -p substrate-shell world_root`; document any skipped installer smoke scripts -- Blockers: upstream missing; installer smoke may be skipped if unrelated to tests - -## [2025-11-25 21:12 UTC] Test – C2-test – END -- Worktree commits: c26b2c2 (`test: cover substrate config show output`) -- Commands: `cargo fmt`; `cargo test -p substrate-shell world_root` (tests filtered to world_root subset; new config_show cases auto-skip until CLI exposes the subcommand) -- Results: fmt clean; targeted tests passed; installer smoke script not run because scope limited to test harness additions -- Kickoff prompts created: n/a (docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-integ.md already present) -- Docs commit: pending (`docs: finish C2-test`) after merging branch/status/log updates -- Next steps / blockers: ready for integration once code + tests merged; config_show coverage enables TOML/JSON/redaction verification as soon as CLI lands - -## [2025-11-25 19:43 UTC] Integration – C2-integ – START -- Checked out feat/config-subcommand; `git pull --ff-only` failed (branch lacks upstream tracking) -- Updated tasks.json (C2-integ → in_progress); this session log entry staged for the same doc commit -- Created plan: branch/worktree cs-c2-show-integ, merge cs-c2-show-code + cs-c2-show-test, resolve conflicts, run fmt/clippy/world_root/world_enable tests, verify CLI/docs, update tasks/logs + kickoff prompts -- Blockers: upstream tracking absent; otherwise none - -## [2025-11-25 19:45 UTC] Integration – C2-integ – END -- Worktree commits: n/a (cs-c2-show-code/test already merged; integration branch introduced no new changes) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `cargo test -p substrate-shell world_enable`; `cargo run -p substrate --bin substrate -- config --help` -- Results: fmt/clippy/tests all passed; CLI help confirms `config show` verb listed with TOML/JSON description; docs already highlight usage so no updates needed -- Kickoff prompts created: docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-code.md, docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-test.md (revalidated contents for next agents) -- Docs commit: pending (`docs: finish C2-integ`) to record tasks/session updates -- Next steps / blockers: ready for C3-code/test to implement `config set`; no outstanding conflicts - -## [2025-11-25 19:47 UTC] Code – C3-code – START -- Checked out feat/config-subcommand; `git pull --ff-only` still unavailable because no upstream is configured -- Updated tasks.json (C3-code → in_progress); session log entry recorded here prior to committing -- Plan: branch/worktree cs-c3-set-code, implement `substrate config set` with dotted keys, validation, atomic writes, and `--json`; update docs; run `cargo fmt`, `cargo clippy -p substrate-shell -- -D warnings`, `cargo test -p substrate-shell world_root`, `cargo test -p substrate-shell world_enable` -- Blockers: upstream remote missing; otherwise none - -## [2025-11-25 19:59 UTC] Code – C3-code – END -- Worktree commits: 377205d (`feat: add substrate config set command`) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `cargo test -p substrate-shell world_enable` -- Results: all commands passed; `config set` now validates dotted keys, writes atomically, and emits JSON summaries; docs updated with multi-key and Windows examples -- Kickoff prompts created: docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-test.md (referenced for the next role) -- Docs commit: pending (`docs: finish C3-code`) after merging tasks/log updates -- Next steps / blockers: ready for C3-test to add coverage; no outstanding blockers - -## [2025-11-25 19:48 UTC] Test – C3-test – START -- Checked out feat/config-subcommand; `git pull --ff-only` still blocked because the branch lacks an upstream remote -- Updated tasks.json (C3-test → in_progress) and recorded this entry ahead of the start commit -- Plan: branch/worktree cs-c3-set-test, add hermetic config-set tests covering single/multi-key updates, validation failures, JSON output, atomic writes, and precedence overrides; run `cargo fmt`, `cargo test -p substrate-shell world_root`, `cargo test -p substrate-shell world_enable`, document installer smoke status -- Blockers: upstream missing; dependent on C3-code branch for CLI implementation visibility - -## [2025-11-25 20:03 UTC] Test – C3-test – END -- Worktree commits: 5cbea83 (`test: cover substrate config set CLI`) -- Commands: `cargo fmt`; `cargo test -p substrate-shell --test config_set`; `cargo test -p substrate-shell world_root`; `env -u SUBSTRATE_MANAGER_ENV cargo test -p substrate-shell world_enable` -- Results: fmt clean; config_set integration tests pass when the command is available; world_root suite green; world_enable required clearing `SUBSTRATE_MANAGER_ENV` (user env sets it globally and otherwise trips the manager-env path test); no installer smoke requested -- Kickoff prompts created: n/a (`docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-integ.md` already present) -- Docs commit: pending (`docs: finish C3-test`) -- Next steps / blockers: ready for C3-integ to merge code+tests once config-set implementation lands - -## [2025-11-25 20:11 UTC] Integration – C3-integ – START -- Checked out feat/config-subcommand; `git pull --ff-only` failed because the branch has no upstream tracking branch -- Confirmed C3-code and C3-test marked completed in tasks.json and reviewed their session log entries -- Updated tasks.json (C3-integ → in_progress); this log entry will be part of the same doc commit -- Plan: create cs-c3-set-integ branch/worktree, merge cs-c3-set-code + cs-c3-set-test, resolve conflicts, run `cargo fmt`, `cargo clippy -p substrate-shell -- -D warnings`, `cargo test -p substrate-shell world_root`, `cargo test -p substrate-shell world_enable`, and `./tests/installers/install_smoke.sh`, then update docs/tasks/logs and confirm CLI UX acceptance criteria -- Blockers: feat/config-subcommand still lacks upstream tracking; installer smoke may require elevated permissions depending on environment - -## [2025-11-25 20:14 UTC] Integration – C3-integ – END -- Worktree commits: n/a (cs-c3-set-code/test already merged; cs-c3-set-integ validated current HEAD) -- Commands: `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `cargo test -p substrate-shell world_enable`; `./tests/installers/install_smoke.sh` -- Results: all commands passed; installer smoke confirmed the `substrate config init` hint appears in the log; config set/show/init behavior matches spec with multi-key updates and JSON output verified via tests -- Kickoff prompts created: n/a (final track in this program) -- Docs commit: pending (`docs: finish C3-integ`) -- Next steps / blockers: Updated docs/BACKLOG.md to mark the Global configuration UX item complete; no open blockers diff --git a/docs/project_management/_archived/config-subcommand/tasks.json b/docs/project_management/_archived/config-subcommand/tasks.json deleted file mode 100644 index 6ab174e80..000000000 --- a/docs/project_management/_archived/config-subcommand/tasks.json +++ /dev/null @@ -1,395 +0,0 @@ -{ - "tasks": [ - { - "id": "C1-code", - "name": "Config CLI foundation & init", - "type": "code", - "phase": "Config Subcommand", - "status": "completed", - "description": "Introduce the `config` subcommand to Clap, implement `substrate config init` with `--force`, and update shell/install diagnostics to point users at the command whenever the global config is missing.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "docs/BACKLOG.md", - "crates/shell/src/execution/cli.rs", - "crates/shell/src/execution/invocation.rs", - "crates/shell/src/execution/settings.rs", - "crates/common/src/paths.rs", - "scripts/substrate/install-substrate.sh", - "docs/CONFIGURATION.md", - "docs/USAGE.md" - ], - "acceptance_criteria": [ - "`config` subcommand group added with `init` verb wired before REPL/command execution; Clap help updated.", - "`substrate config init` creates `~/.substrate/config.toml` plus parent directories, writes default [install] and [world] tables, and supports `--force` regeneration.", - Shell/installer error paths detect a missing config and log actionable hints referencing `substrate config init`.", - Docs mention the command in configuration/install sections.", - `cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; targeted smoke test (`cargo test -p substrate-shell world_root`) documented in session log." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C1-code to in_progress, log START entry, commit docs update", - "Create task branch cs-c1-config-code", - "Create worktree wt/cs-c1-config-code from that branch" - ], - "end_checklist": [ - "Ensure required fmt/lint/tests per prompt are green", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [], - "concurrent_with": [ - "C1-test" - ], - "worktree": "wt/cs-c1-config-code", - "integration_task": "C1-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C1-code.md" - }, - { - "id": "C1-test", - "name": "Config init tests", - "type": "test", - "phase": "Config Subcommand", - "status": "in_progress", - "description": "Author integration/unit tests that cover `substrate config init`, missing-config diagnostics, and installer/script scaffolding without touching production code beyond test helpers.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "docs/BACKLOG.md", - "crates/shell/tests", - "tests/installers/install_smoke.sh", - "docs/CONFIGURATION.md" - ], - "acceptance_criteria": [ - "Integration tests invoke `substrate config init` via the shell driver, asserting files are created with default tables and `--force` rewrites.", - "Tests cover the missing-config warning path (shell launches emit hint to run `substrate config init`).", - "Installer harness verifies the script creates config.toml or surfaces the same hint when stubbed.", - "`cargo fmt`; targeted suites (`cargo test -p substrate-shell world_root`, `./tests/installers/install_smoke.sh` when platform allows) logged in session_log.md.", - "Kickoff prompt for C1-integ authored at end of session." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C1-test to in_progress, log START entry, commit docs update", - "Create task branch cs-c1-config-test", - "Create worktree wt/cs-c1-config-test from that branch" - ], - "end_checklist": [ - "Ensure fmt/tests per prompt are green (note skips with justification)", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [], - "concurrent_with": [ - "C1-code" - ], - "worktree": "wt/cs-c1-config-test", - "integration_task": "C1-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C1-test.md" - }, - { - "id": "C1-integ", - "name": "Integrate config init", - "type": "integration", - "phase": "Config Subcommand", - "status": "completed", - "description": "Merge the C1 code/test worktrees, resolve conflicts, and ensure fmt/clippy/tests pass before updating docs/tasks/session log on feat/config-subcommand.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell", - "tests/installers" - ], - "acceptance_criteria": [ - "wt/cs-c1-config-integ merges cs-c1-config-code and cs-c1-config-test with no outstanding conflicts.", - "`cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `./tests/installers/install_smoke.sh` (or documented skip) executed and logged.", - "feat/config-subcommand updated with merged changes plus session/task/log commits.", - "Kickoff prompts for C2-code and C2-test recorded." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Confirm C1-code and C1-test completed", - "Set C1-integ to in_progress, log START entry, commit docs update", - "Create task branch cs-c1-config-integ", - "Create worktree wt/cs-c1-config-integ from that branch" - ], - "end_checklist": [ - "Merge code/test branches into integration worktree and resolve conflicts", - "Run required fmt/clippy/tests/scripts per prompt", - "Merge integration branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Push or hand off per instructions" - ], - "depends_on": [ - "C1-code", - "C1-test" - ], - "concurrent_with": [], - "worktree": "wt/cs-c1-config-integ", - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C1-integ.md" - }, - { - "id": "C2-code", - "name": "Config show command", - "type": "code", - "phase": "Config Subcommand", - "status": "completed", - "description": "Implement `substrate config show` with human-readable output and `--json`, including redaction of sensitive values and helpful exit codes.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell/src/execution/cli.rs", - "crates/shell/src/execution/invocation.rs", - "crates/shell/src/execution/settings.rs", - "docs/CONFIGURATION.md", - "docs/USAGE.md" - ], - "acceptance_criteria": [ - "`config show` subcommand prints the global config in TOML form to stdout, exits 0 on success, and honors `--json` for machine-readable output.", - "Redaction applied for future sensitive fields (design hook implemented even if no current secrets).", - "Graceful error when config missing (mirrors init guidance).", - "Docs updated with examples for both text and JSON flows.", - "`cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; targeted tests (`cargo test -p substrate-shell world_root`, new unit tests for serialization helpers) logged." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C2-code to in_progress, log START entry, commit docs update", - "Create task branch cs-c2-show-code", - "Create worktree wt/cs-c2-show-code from that branch" - ], - "end_checklist": [ - "Ensure required fmt/lint/tests per prompt are green", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [ - "C1-integ" - ], - "concurrent_with": [ - "C2-test" - ], - "worktree": "wt/cs-c2-show-code", - "integration_task": "C2-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-code.md" - }, - { - "id": "C2-test", - "name": "Config show tests", - "type": "test", - "phase": "Config Subcommand", - "status": "completed", - "description": "Add tests validating `substrate config show` output in both human and JSON modes, including redaction hooks and missing-file errors.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell/tests", - "docs/CONFIGURATION.md" - ], - "acceptance_criteria": [ - "Tests run the CLI via the shell driver asserting TOML output equals the on-disk config and `--json` produces parseable JSON.", - "Redaction helper covered even if current fields are non-sensitive (e.g., stub a fake key).", - "Missing config case prompts instructions to run `config init`.", - "`cargo fmt`; `cargo test -p substrate-shell world_root`; document any skipped installer smoke tests." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C2-test to in_progress, log START entry, commit docs update", - "Create task branch cs-c2-show-test", - "Create worktree wt/cs-c2-show-test from that branch" - ], - "end_checklist": [ - "Ensure fmt/tests per prompt are green (record skips/justifications)", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [ - "C1-integ" - ], - "concurrent_with": [ - "C2-code" - ], - "worktree": "wt/cs-c2-show-test", - "integration_task": "C2-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-test.md" - }, - { - "id": "C2-integ", - "name": "Integrate config show", - "type": "integration", - "phase": "Config Subcommand", - "status": "completed", - "description": "Merge the config-show code/test branches, ensure fmt/clippy/tests pass, and stage the next kickoff prompts.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell", - "docs/CONFIGURATION.md" - ], - "acceptance_criteria": [ - "wt/cs-c2-show-integ merges code/test branches with conflicts resolved.", - "`cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `cargo test -p substrate-shell world_enable` run and logged.", - "Docs/tasks/session log updated on feat/config-subcommand; kickoff prompts for C3-code/test created." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Confirm C2-code and C2-test completed", - "Set C2-integ to in_progress, log START entry, commit docs update", - "Create task branch cs-c2-show-integ", - "Create worktree wt/cs-c2-show-integ from that branch" - ], - "end_checklist": [ - "Merge code/test branches into integration worktree and resolve conflicts", - "Run required fmt/clippy/tests/scripts per prompt", - "Merge integration branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Push or hand off per instructions" - ], - "depends_on": [ - "C2-code", - "C2-test" - ], - "concurrent_with": [], - "worktree": "wt/cs-c2-show-integ", - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C2-integ.md" - }, - { - "id": "C3-code", - "name": "Config set command", - "type": "code", - "phase": "Config Subcommand", - "status": "completed", - "description": "Implement `substrate config set key=value ...` with dotted key paths, schema-aware validation, multi-key support, atomic writes, and JSON-capable responses.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell/src/execution/cli.rs", - "crates/shell/src/execution/invocation.rs", - "crates/shell/src/execution/settings.rs", - "crates/shell/src/builtins/world_enable/config.rs", - "docs/CONFIGURATION.md" - ], - "acceptance_criteria": [ - "`config set` accepts one or more `key=value` arguments (dotted keys) and validates values: enums for modes, booleans for toggles, strings for paths.", - "Multiple updates apply in a single run and persist atomically (write temp file + rename).", - "Command returns human summary plus optional `--json` payload describing the applied diff.", - "Unexpected keys preserved; invalid keys/values produce clear errors without mutating the file.", - "Docs updated with examples and mention multi-key behavior.", - "`cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; targeted tests (existing + new unit helpers) run." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C3-code to in_progress, log START entry, commit docs update", - "Create task branch cs-c3-set-code", - "Create worktree wt/cs-c3-set-code from that branch" - ], - "end_checklist": [ - "Ensure required fmt/lint/tests per prompt are green", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [ - "C2-integ" - ], - "concurrent_with": [ - "C3-test" - ], - "worktree": "wt/cs-c3-set-code", - "integration_task": "C3-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-code.md" - }, - { - "id": "C3-test", - "name": "Config set tests", - "type": "test", - "phase": "Config Subcommand", - "status": "completed", - "description": "Add tests for `substrate config set` covering multi-key updates, validation errors, JSON output, and atomic persistence.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell/tests", - "docs/CONFIGURATION.md" - ], - "acceptance_criteria": [ - "Tests cover single and multi-key updates (anchor_mode/path, install.world_enabled, caged) and assert the file changes atomically.", - "Invalid keys/values produce non-zero exit codes without modifying files.", - "`--json` output parsed and validated in at least one test.", - "Precedence stack unaffected (flag/env overrides still win).", - "`cargo fmt`; `cargo test -p substrate-shell world_root`; document any installer smoke coverage." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Set C3-test to in_progress, log START entry, commit docs update", - "Create task branch cs-c3-set-test", - "Create worktree wt/cs-c3-set-test from that branch" - ], - "end_checklist": [ - "Ensure fmt/tests per prompt are green (record skips/justifications)", - "Commit worktree changes", - "Merge task branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Create/confirm next kickoff prompts as required", - "Commit docs update on feat/config-subcommand" - ], - "depends_on": [ - "C2-integ" - ], - "concurrent_with": [ - "C3-code" - ], - "worktree": "wt/cs-c3-set-test", - "integration_task": "C3-integ", - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-test.md" - }, - { - "id": "C3-integ", - "name": "Integrate config set", - "type": "integration", - "phase": "Config Subcommand", - "status": "completed", - "description": "Merge the config-set code/test branches, verify fmt/clippy/tests, and close out the program with documentation/status updates.", - "references": [ - "docs/project_management/_archived/next/config-subcommand/config_subcommand_plan.md", - "crates/shell", - "docs/CONFIGURATION.md", - "docs/USAGE.md" - ], - "acceptance_criteria": [ - "wt/cs-c3-set-integ merges cs-c3-set-code/test, resolves conflicts, and records commands in session log.", - "`cargo fmt`; `cargo clippy -p substrate-shell -- -D warnings`; `cargo test -p substrate-shell world_root`; `cargo test -p substrate-shell world_enable`; `./tests/installers/install_smoke.sh` (or documented skip) executed.", - "Docs/tasks/session log updated; backlog item marked covered in follow-up (note if additional work remains).", - "Any follow-up prompts (if needed) recorded before ending session." - ], - "start_checklist": [ - "Checkout feat/config-subcommand, pull latest", - "Confirm C3-code and C3-test completed", - "Set C3-integ to in_progress, log START entry, commit docs update", - "Create task branch cs-c3-set-integ", - "Create worktree wt/cs-c3-set-integ from that branch" - ], - "end_checklist": [ - "Merge code/test branches into integration worktree and resolve conflicts", - "Run required fmt/clippy/tests/scripts per prompt", - "Merge integration branch back to feat/config-subcommand", - "Update tasks.json + session_log.md with END entry", - "Push or hand off per instructions" - ], - "depends_on": [ - "C3-code", - "C3-test" - ], - "concurrent_with": [], - "worktree": "wt/cs-c3-set-integ", - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/next/config-subcommand/kickoff_prompts/C3-integ.md" - } - ] -} diff --git a/docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md b/docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md deleted file mode 100644 index cae7ff018..000000000 --- a/docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md +++ /dev/null @@ -1,72 +0,0 @@ -# Slice Closeout Gate Report — doctor_scopes / DS0 - -Date (UTC): 2026-01-09 - -Standards: -- `docs/project_management/standards/SLICE_CLOSEOUT_GATE_STANDARD.md` -- `docs/project_management/standards/EXECUTIVE_SUMMARY_STANDARD.md` (behavior delta format) - -Feature directory: -- `docs/project_management/_archived/doctor_scopes/` - -Slice spec: -- `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -## Status - -COMPLETED. - -## Behavior Delta (Existing → New → Why) - -- Existing behavior: `substrate world doctor` is host-oriented on macOS and mixes host/world facts on Linux without an explicit scope split. -- New behavior: introduce `substrate host doctor`; redefine `substrate world doctor` to include `host` + `world` blocks with world facts sourced from the world-agent endpoint `GET /v1/doctor/world`. -- Why: operators need a single, authoritative answer for “is isolation enforceable right now?” across Linux and macOS, including guest-kernel facts on macOS. -- Links: - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -## Spec Parity (No Drift) - -- Acceptance criteria satisfied: `YES` -- Spec changes during the slice: `NONE EXPECTED (spec is authoritative; drift must be justified in writing if it occurs)` - -## Checks Run (Evidence) - -- `cargo fmt`: `PASS` (via `make integ-checks`) -- `cargo clippy --workspace --all-targets -- -D warnings`: `PASS` (via `make integ-checks`) -- Relevant tests: `PASS` (`cargo test --workspace --all-targets` via `make integ-checks`) -- `make integ-checks`: `PASS` (exit `0`) - -## Cross-Platform Smoke - -Record run ids/URLs for required platforms: -- CI compile parity (linux/macos/windows): - - RUN_ID: `20861321448` - - RUN_URL: `https://github.com/atomize-hq/substrate/actions/runs/20861321448` - - Result: `success` (`ubuntu-24.04`, `macos-14`, `windows-2022`) -- Linux smoke: - - RUN_ID: `20861533380` - - RUN_URL: `https://github.com/atomize-hq/substrate/actions/runs/20861533380` - - Result: `success` -- macOS smoke: - - RUN_ID: `20861578627` - - RUN_URL: `https://github.com/atomize-hq/substrate/actions/runs/20861578627` - - Result: `success` - -Platform-fix work summary (must be explicit; use `NONE` if nothing was needed): -- What failed: - - macOS smoke runners can have a provisioned Lima world-agent that predates `GET /v1/doctor/world`, causing world doctor requests to fail and smoke to fail. - - Linux self-hosted runners can have a world-agent that predates `GET /v1/doctor/world`, causing smoke to fail. - - `make ci-compile-parity` dispatch can fail when `.github/workflows/ci-compile-parity.yml` is not registered on the default branch. -- What was changed: - - Linux: treat `GET /v1/doctor/world` `HTTP 404` as “legacy agent”; fall back to a lightweight world probe via `/v1/execute` that validates the DS0 contract (Landlock + enumeration probe) without requiring runner reprovisioning. - - macOS: probe doctor endpoint via Lima guest; fall back to a VM-side probe when the endpoint is missing; harden Landlock ABI detection; improve limactl error capture; stabilize CI log noise. - - CI: dispatch `ci-compile-parity` via `ci-testing` when the workflow path is not dispatchable from the default branch. -- Why the change is safe (guards, cfg, feature flags): - - All fallbacks are opt-in by observed conditions (e.g., `HTTP 404` on `/v1/doctor/world` or missing guest paths) and do not change the steady-state path when the endpoint exists and is healthy. - - Platform behavior is confined to per-platform modules (`linux.rs`, `macos.rs`) and does not introduce new configuration keys or env toggles. - -## Smoke ↔ Manual Parity - -- Smoke scripts mirror manual playbook: `YES` (`docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` ↔ `docs/project_management/_archived/doctor_scopes/smoke/`) -- Smoke scripts validate exit codes + key output: `YES` (jq assertions on DS0 v1 JSON contracts) diff --git a/docs/project_management/_archived/doctor_scopes/DS0-spec.md b/docs/project_management/_archived/doctor_scopes/DS0-spec.md deleted file mode 100644 index 88b1493b1..000000000 --- a/docs/project_management/_archived/doctor_scopes/DS0-spec.md +++ /dev/null @@ -1,269 +0,0 @@ -# DS0-spec — Doctor scopes (host vs world) - -Driven by: -- ADR: `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` -- Decision register: `docs/project_management/_archived/doctor_scopes/decision_register.md` - -## Scope -- Add a new CLI surface: `substrate host doctor [--json]`. -- Redefine `substrate world doctor [--json]` as “world-scoped” by querying the world-agent for an authoritative world readiness report. -- Introduce a world-agent endpoint: `GET /v1/doctor/world`. -- Update internal consumers that parse doctor JSON (health/shim snapshots, world verify, docs). - -## Definitions (terms used in this spec) -- **Host**: the OS where `substrate` CLI is running. -- **World**: the isolation runtime where the world-agent runs (Linux namespace world on Linux; Lima guest on macOS; WSL on Windows). -- **Host doctor**: diagnostics that are computable from the host without requiring guest-kernel inference. -- **World doctor**: diagnostics that are authoritative only from the world-agent / guest kernel perspective. - -## User contract (authoritative) - -### CLI - -#### `substrate host doctor [--json]` -- Purpose: report host readiness for world routing (host prerequisites + transport readiness). -- Side effects: none (no provisioning, no spawning, no VM start). -- Output: - - Text: PASS/WARN/FAIL lines (human-first) under a `== substrate host doctor ==` header. - - JSON: a stable, versioned object (see “JSON contracts”). - -#### `substrate world doctor [--json]` -- Purpose: report world enforcement readiness (agent-reported world facts) and include the host doctor report as a sibling block. -- Side effects: none (no provisioning, no spawning, no VM start). -- Behavior: - - MUST compute the effective config/policy for the current directory (honoring global CLI overrides `--world/--no-world`). - - If world isolation is disabled by effective config, MUST short-circuit (no socket probing, no agent calls). - - Otherwise MUST: - 1) run the host doctor probes and include their results as the `host` block; then - 2) call the world-agent endpoint `GET /v1/doctor/world` and include the response as the `world` block. -- Output: - - Text: PASS/WARN/FAIL lines grouped into explicit `== Host ==` and `== World ==` sections under a `== substrate world doctor ==` header. - - JSON: a stable, versioned object (see “JSON contracts”). - -### Exit codes -- Exit code taxonomy: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -#### `substrate host doctor` -- `0`: `ok=true` -- `3`: required dependency unavailable for host probes (e.g., `limactl` missing on macOS when required to report host readiness) -- `4`: not supported / missing prerequisites (`ok=false` due to missing host prerequisites or world disabled) -- `1`: unexpected internal error (I/O error, panic, bug) - -#### `substrate world doctor` -- `0`: `ok=true` (both `host.ok=true` and `world.ok=true`) -- `3`: world enabled, transport prerequisites present, but world-agent is unreachable (transport connect/probe/HTTP failure) -- `4`: not supported / missing prerequisites (world disabled; world not provisioned; or world-agent reachable but cannot enforce required primitives) -- `2`: CLI usage/config error (invalid flags/args; invalid config/policy read) -- `1`: unexpected internal error (I/O error, panic, bug) - -Discriminator for `3` (unreachable) vs `4` (not provisioned / missing prerequisites) when `world_enabled==true`: -- Linux: - - Not provisioned (`4`): `host.world_socket.socket_exists==false` - - Unreachable (`3`): `host.world_socket.socket_exists==true` and either `host.world_socket.probe_ok==false` or the world-agent HTTP request fails -- macOS: - - Not provisioned (`4`): one of: - - `host.lima.installed==false` - - `host.lima.virtualization==false` - - `host.lima.vm_status!="Running"` - - `host.lima.service_active==false` - - Unreachable (`3`): transport prerequisites above are present and the world-agent request fails (including `host.lima.agent_caps_ok==false`) - -### Configuration -- No new configuration keys are introduced by DS0. -- No new environment variables are introduced by DS0. - -## Agent API contract (authoritative) - -### Endpoint -- Method: `GET` -- Path: `/v1/doctor/world` -- Request body: none -- Response: JSON object, schema versioned (below) - -### `WorldDoctorReportV1` (world-agent response JSON) -```json -{ - "schema_version": 1, - "ok": true, - "collected_at_utc": "2026-01-08T00:00:00Z", - "landlock": { - "supported": true, - "abi": 3, - "reason": null - }, - "world_fs_strategy": { - "primary": "overlay", - "fallback": "fuse", - "probe": { - "id": "enumeration_v1", - "probe_file": ".substrate_enum_probe", - "result": "pass", - "failure_reason": null - } - } -} -``` - -#### Field contract (exact) -- `schema_version`: integer, must equal `1`. -- `ok`: boolean; must be `true` iff: - - `landlock.supported == true`, and - - `world_fs_strategy.probe.result == "pass"`. -- `collected_at_utc`: RFC3339 UTC timestamp with `Z` suffix (seconds precision). -- `landlock.supported`: boolean. -- `landlock.abi`: integer when supported; otherwise `null`. -- `landlock.reason`: string when `supported=false`; otherwise `null`. -- `world_fs_strategy.primary`: string enum, exactly `"overlay"`. -- `world_fs_strategy.fallback`: string enum, exactly `"fuse"`. -- `world_fs_strategy.probe.id`: string, exactly `"enumeration_v1"`. -- `world_fs_strategy.probe.probe_file`: string, exactly `".substrate_enum_probe"`. -- `world_fs_strategy.probe.result`: string enum: `"pass"` or `"fail"`. -- `world_fs_strategy.probe.failure_reason`: nullable string; non-null only when `result=="fail"`. - -### Error handling -- If the world-agent cannot compute the report due to an internal error, it MUST: - - return `HTTP 500` with a JSON error body consistent with existing agent error responses, and - - MUST NOT return `ok=true`. - -## JSON contracts (authoritative) - -### `substrate host doctor --json` output: `HostDoctorEnvelopeV1` -```json -{ - "schema_version": 1, - "platform": "linux", - "world_enabled": true, - "ok": true, - "host": { "platform": "linux", "ok": true } -} -``` - -### `substrate world doctor --json` output: `WorldDoctorEnvelopeV1` -```json -{ - "schema_version": 1, - "platform": "macos", - "world_enabled": true, - "ok": true, - "host": { "platform": "macos", "ok": true }, - "world": { "schema_version": 1, "ok": true } -} -``` - -#### Envelope field contract (exact) -- `schema_version`: integer, must equal `1`. -- `platform`: string enum: `"linux"`, `"macos"`, `"windows"`. -- `world_enabled`: boolean; effective config after applying global CLI overrides `--world/--no-world`. -- `ok`: boolean: - - host doctor: equals `host.ok`. - - world doctor: equals `host.ok && world.ok`. -- `host`: `HostDoctorReportV1` (below). -- `world`: present only for world doctor: - - when `platform=="windows"`: `world.status == "unsupported"` and `world.ok==false`; - - when `world_enabled==false`: `world.status == "disabled"` and `world.ok==false`; - - when `world_enabled==true` and transport prerequisites are not satisfied: `world.status == "not_provisioned"` and `world.ok==false`; - - when `world_enabled==true` and transport prerequisites are satisfied but the world-agent is unreachable: `world.status == "unreachable"` and `world.ok==false`; - - otherwise: `world` equals the agent’s `WorldDoctorReportV1` response plus `status == "ok"` when `ok==true` and `status == "missing_prereqs"` when `ok==false`. - -For `world.status` in `"unsupported"|"disabled"|"not_provisioned"|"unreachable"`, required stable fields are: -- `status` (string enum) -- `ok` (boolean) - -### `HostDoctorReportV1` (platform-specific; stable per platform) - -#### Linux host report (`host.platform=="linux"`) -Required fields: -- `platform`: `"linux"` -- `ok`: boolean; must be `true` iff all of: - - `world_enabled==true`, and - - `world_socket.socket_exists==true`, and - - `world_socket.probe_ok==true`, and - - `(overlay_present==true) || (fuse.dev==true && fuse.bin==true)`, and - - `cgroup_v2==true`, and - - `nft_present==true` -- `overlay_present`: boolean -- `fuse.dev`: boolean -- `fuse.bin`: boolean -- `cgroup_v2`: boolean -- `nft_present`: boolean -- `dmesg_restrict`: string (or `"n/a"` when unknown) -- `overlay_root`: string path -- `copydiff_root`: string path -- `world_fs_mode`: string enum: `"writable"` or `"read_only"` -- `world_fs_isolation`: string enum: `"workspace"` or `"full"` -- `world_fs_require_world`: boolean -- `world_socket`: object with required fields: - - `mode`: string enum: `"socket_activation"` or `"manual"` - - `socket_path`: string - - `socket_exists`: boolean - - `probe_ok`: boolean - - `probe_error`: nullable string - - `systemd_error`: nullable string - - `systemd_socket`: nullable object - - `systemd_service`: nullable object - -#### macOS host report (`host.platform=="macos"`) -Required fields: -- `platform`: `"macos"` -- `ok`: boolean; must be `true` iff all of: - - `world_enabled==true`, and - - `lima.installed==true`, and - - `lima.virtualization==true`, and - - `lima.vm_status=="Running"`, and - - `lima.service_active==true`, and - - `lima.agent_caps_ok==true` -- `world_fs_mode`: string enum: `"writable"` or `"read_only"` -- `world_fs_isolation`: string enum: `"workspace"` or `"full"` -- `world_fs_require_world`: boolean -- `lima`: object with required fields: - - `installed`: boolean - - `virtualization`: boolean - - `vm_status`: string (must be `"Running"` to be ok) - - `service_active`: boolean - - `agent_caps_ok`: boolean - - `vsock_proxy`: boolean - -#### Windows host report (`host.platform=="windows"`) -Required fields: -- `platform`: `"windows"` -- `ok`: boolean; must be `false` -- `status`: string enum: `"unsupported"` -- `message`: string; must be non-empty - -## Text output contract (authoritative; minimal) -- Line prefixes are exactly: `PASS | `, `WARN | `, `FAIL | `, `INFO | `. -- `substrate host doctor`: - - First line: `== substrate host doctor ==` - - Then a deterministic, platform-specific set of lines (not required to be stable across versions; JSON is the stable interface). -- `substrate world doctor`: - - First line: `== substrate world doctor ==` - - Then: - - `== Host ==` section (same probe set as `substrate host doctor`) - - `== World ==` section (agent-reported world doctor) - -## Required docs updates (must land in DS0) -- `docs/COMMANDS.md`: add `substrate host doctor`; update `substrate world doctor` notes to match new scope. -- `docs/WORLD.md`: update doctor framing and reference the new world-agent doctor endpoint behavior. -- `docs/USAGE.md`: update “World Commands” bullets to include the new command and revised semantics. -- `docs/INSTALLATION.md`: replace any “world doctor is host readiness report” language. -- `docs/ISOLATION_SUPPORT_MATRIX.md`: remove “incomplete” framing for doctor scopes and document scope split explicitly. - -## Acceptance criteria (DS0 must satisfy all) -- CLI: - - `substrate host doctor --json` emits `HostDoctorEnvelopeV1` exactly as specified. - - `substrate world doctor --json` emits `WorldDoctorEnvelopeV1` exactly as specified. - - `substrate world doctor` never reports `ok=true` unless the agent report `ok=true` and the host report `ok=true`. - - Windows behavior is explicit: `ok=false`, `status=unsupported`, exit code `4`. -- Agent API: - - `GET /v1/doctor/world` exists and returns `WorldDoctorReportV1` on success. - - The endpoint reports Landlock support/ABI from the world kernel on macOS (Lima guest). -- Smoke: - - Linux smoke script validates `host` and `world` JSON shapes and requires `landlock.supported==true`. - - macOS smoke script validates `host` and `world` JSON shapes and requires `landlock.supported==true`. -- Tests: - - Update/extend tests that parse world doctor JSON (health/shim snapshots, world verify) to use the new `host`/`world` blocks. - - Add a schema round-trip test for `WorldDoctorReportV1` in `agent-api-types`. - -## Out of scope -- Any “world disabled” UX overhaul beyond the explicit short-circuit required by this spec. -- Any redesign of `substrate health` output ordering or verbosity beyond updating it to parse the new doctor schema. diff --git a/docs/project_management/_archived/doctor_scopes/decision_register.md b/docs/project_management/_archived/doctor_scopes/decision_register.md deleted file mode 100644 index c0ed5cd0e..000000000 --- a/docs/project_management/_archived/doctor_scopes/decision_register.md +++ /dev/null @@ -1,428 +0,0 @@ -# Decision Register — Doctor scope split (host vs world) - -This decision register supports `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`. - -## Format note - -Each decision entry follows the required template in: -- `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` (Decision Register Standard) - -### DR-0001 — CLI naming for host-scoped doctor - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- DS0 adds a host-scoped doctor surface and requires a single, unambiguous CLI name that is discoverable and consistent with existing nouns (`world`, `shim`, `health`). - -**Option A — `substrate host doctor`** -- **Pros:** Uses an existing top-level noun pattern; separates host readiness from world readiness by command name; supports platform-specific output without overloading `world`. -- **Cons:** Adds a new top-level subcommand; requires docs updates for the command matrix. -- **Cascading implications:** Requires CLI routing changes and updates to any help text and docs that list doctor commands. -- **Risks:** Users search for `world doctor` and miss the host-only command on first try. -- **Unlocks:** A clean future split for `host` scoped commands beyond doctor (consistent UX). -- **Quick wins / low-hanging fruit:** Clear `--help` surface for a single-purpose host readiness check. - -**Option B — `substrate world doctor --host`** -- **Pros:** Avoids adding a new top-level subcommand; keeps doctor invocation under the existing `world` namespace. -- **Cons:** Low discoverability; creates an overloaded mental model where “world doctor” includes host-only behavior; increases ambiguity in scripts and operator instructions. -- **Cascading implications:** Adds a new flag surface that must be documented and validated across platforms; increases risk of users running the wrong scope by default. -- **Risks:** Reintroduces the macOS confusion where “world doctor” is interpreted as host doctor. -- **Unlocks:** Keeps the command tree shallower. -- **Quick wins / low-hanging fruit:** Minimal CLI command tree changes. - -**Recommendation** -- **Selected:** Option A — `substrate host doctor` -- **Rationale (crisp):** A dedicated `host` namespace removes scope ambiguity and matches existing Substrate noun patterns. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement `substrate host doctor` CLI routing and behavior. -- `DS0-test`: add CLI wiring + JSON contract tests for `substrate host doctor`. -- `DS0-integ-core`: validate the CLI surface and JSON output during integration. - -### DR-0002 — What `substrate world doctor` reports by default - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- `substrate world doctor` must report world readiness, while operators still need host readiness context when the world is down. - -**Option A — World-only output (agent-reported facts only)** -- **Pros:** Matches the command name strictly; keeps responsibility boundaries narrow; avoids duplication with `substrate host doctor`. -- **Cons:** Requires operators to run a second command for host readiness context; slows triage for unreachable-world cases. -- **Cascading implications:** More operator runbooks need multi-step instructions; more CI/smoke scripts need chained commands. -- **Risks:** Operators interpret “world doctor failed” without a clear next action. -- **Unlocks:** A cleaner long-term model where world doctor is exclusively agent-reported. -- **Quick wins / low-hanging fruit:** Simplifies the world doctor renderer when the world is reachable. - -**Option B — Combined output with explicit `host` + `world` blocks** -- **Pros:** One command contains both the host readiness context and the agent-reported world readiness; preserves scope boundaries via explicit blocks; reduces false-green risk by coupling `ok` to both blocks. -- **Cons:** Slightly more verbose output; requires consistent envelope schema and internal consumer updates. -- **Cascading implications:** Requires updating internal consumers that parse doctor JSON to use scoped blocks. -- **Risks:** Poor labeling blurs “host-inferred” vs “agent-reported” facts. -- **Unlocks:** A stable envelope for future tooling and automation (`host` and `world` blocks become the interface). -- **Quick wins / low-hanging fruit:** Immediate operator UX improvement for “world down” triage. - -**Recommendation** -- **Selected:** Option B — combined output with explicit `host` + `world` blocks -- **Rationale (crisp):** Explicit scope blocks keep contracts auditable while keeping operator triage single-command. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement world doctor envelope with `host` + `world` blocks and top-level `ok`. -- `DS0-test`: add tests that validate the envelope structure and `ok == host.ok && world.ok`. -- `DS0-integ-core`: confirm internal consumers are updated and no legacy parsers expect a flat schema. - -### DR-0003 — How to obtain guest-kernel facts on macOS (Landlock, FS strategy probe) - -**Decision owner(s):** Substrate world backend maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- On macOS, correctness/security facts for enforcement (Landlock ABI/support, world filesystem probe result) are properties of the Lima guest kernel and the world-agent service privileges. -- DS0 requires a reliable mechanism to surface those facts in `substrate world doctor` without requiring a guest-installed `substrate` binary. - -**Option A — Run a guest-installed `substrate` CLI via Lima shell** -- **Pros:** Reuses existing Linux doctor logic; avoids adding a new agent endpoint route. -- **Cons:** Depends on guest package state and user permissions; produces misleading results if `substrate` is not installed in the guest or runs as an unprivileged guest user. -- **Cascading implications:** Adds operational complexity to provisioning and troubleshooting; increases variance across installs and environments. -- **Risks:** “Doctor” results drift based on guest filesystem state and PATH composition. -- **Unlocks:** A short-term path for macOS parity if the guest image always contains `substrate`. -- **Quick wins / low-hanging fruit:** Minimal new code in world-agent. - -**Option B — Add a world-agent endpoint that returns a structured world doctor report** -- **Pros:** Measures the actual enforcement environment (guest kernel + agent privileges); removes dependency on guest-installed CLI; provides a stable API contract for host UI and automation. -- **Cons:** Introduces new API surface area (routing + schema); requires versioning and serde tests. -- **Cascading implications:** Requires adding types in `agent-api-types` and client support in `agent-api-client`. -- **Risks:** Schema drift if the endpoint is not treated as a stable contract. -- **Unlocks:** A single cross-platform mechanism for world readiness facts. -- **Quick wins / low-hanging fruit:** Enables macOS Landlock ABI reporting without additional guest setup. - -**Recommendation** -- **Selected:** Option B — world-agent endpoint with a structured report -- **Rationale (crisp):** The agent has the correct vantage point for guest-kernel facts, and the endpoint is deterministic across installs. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement `GET /v1/doctor/world` in world-agent and the corresponding CLI client call. -- `DS0-test`: add schema round-trip tests for `WorldDoctorReportV1` and CLI parsing tests for the envelope. -- `DS0-integ-core`: validate macOS behavior (Landlock ABI/support comes from the guest kernel via the endpoint). - -### DR-0004 — Orchestration branch naming - -**Decision owner(s):** Substrate project maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/packs/sequencing.json`, `docs/project_management/_archived/doctor_scopes/tasks.json`, `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - -**Problem / Context** -- The planning pack declares an orchestration branch used by triad automation and CI dispatch commands; the branch name must match the sequencing entry and the integration workflow refs. - -**Option A — `feat/doctor_scopes`** -- **Pros:** Matches the feature directory name; matches the default branch naming used by some planning tooling. -- **Cons:** Conflicts with the sprint branch naming already recorded in `docs/project_management/packs/sequencing.json`. -- **Cascading implications:** CI dispatch commands that use `CI_WORKFLOW_REF` drift from sequencing; operators lose a single authoritative branch name. -- **Risks:** Mis-dispatching CI to the wrong ref or failing dispatch because the ref is missing. -- **Unlocks:** Directory-aligned naming for tools that default to underscore-separated feature IDs. -- **Quick wins / low-hanging fruit:** Minimal to type. - -**Option B — `feat/doctor-scopes`** -- **Pros:** Matches `docs/project_management/packs/sequencing.json` and ADR; aligns with existing hyphenated branch conventions; keeps CI dispatch refs consistent. -- **Cons:** Requires explicitly setting `meta.automation.orchestration_branch` in `tasks.json`. -- **Cascading implications:** All CI dispatch commands use the same ref string; feature directory and sequencing remain aligned. -- **Risks:** None beyond creating/pushing the branch before dispatch. -- **Unlocks:** Consistent repo-wide branch naming for sequencing-backed feature work. -- **Quick wins / low-hanging fruit:** Reduces preflight friction (one ref string reused everywhere). - -**Recommendation** -- **Selected:** Option B — `feat/doctor-scopes` -- **Rationale (crisp):** Sequencing is the execution spine; the orchestration branch name matches it to avoid CI dispatch drift. - -**Follow-up tasks (explicit)** -- `F0-exec-preflight`: confirm the ref exists on the remote before dispatch (`CI_WORKFLOW_REF="feat/doctor-scopes"`). -- `DS0-integ-core`: dispatch CI and smoke using `WORKFLOW_REF="feat/doctor-scopes"` and record run ids/URLs. -- `DS0-integ`: re-run CI and smoke using `WORKFLOW_REF="feat/doctor-scopes"` and record run ids/URLs in closeout. - -### DR-0005 — World-doctor agent endpoint path - -**Decision owner(s):** Substrate agent API maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- DS0 introduces an agent endpoint for world doctor. The path must be stable, descriptive, and extensible for future doctor endpoints. - -**Option A — `GET /v1/doctor/world`** -- **Pros:** Groups doctor endpoints under a dedicated namespace; supports future additions (`/v1/doctor/host`) without one-off routes; is readable in logs and traces. -- **Cons:** Adds a new route subtree. -- **Cascading implications:** Router and client changes reference the new path; docs and tests must match exactly. -- **Risks:** None beyond route registration and versioning discipline. -- **Unlocks:** Clear API organization for “doctor” features. -- **Quick wins / low-hanging fruit:** Straightforward discoverability for operators and developers. - -**Option B — `GET /v1/world_doctor`** -- **Pros:** Short path; minimal route nesting. -- **Cons:** Harder to extend to additional doctor endpoints without proliferating one-off routes; weak grouping in API surface. -- **Cascading implications:** Future endpoints require repeated ad-hoc naming decisions. -- **Risks:** API surface becomes inconsistent over time. -- **Unlocks:** Slightly shorter request URLs. -- **Quick wins / low-hanging fruit:** Minimal typing. - -**Recommendation** -- **Selected:** Option A — `GET /v1/doctor/world` -- **Rationale (crisp):** A dedicated doctor namespace keeps the API extensible without one-off route naming. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement the world-agent route and handler at `/v1/doctor/world`, and call it from the CLI. -- `DS0-test`: add serde/schema tests and CLI tests that depend on this exact path. -- `DS0-integ-core`: validate the endpoint wiring through the CLI on behavior platforms. - -### DR-0006 — Agent endpoint request shape - -**Decision owner(s):** Substrate agent API maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- The agent endpoint must be callable by the CLI and smoke scripts with minimal interop risk and minimal input validation surface. - -**Option A — `GET` with no request body** -- **Pros:** Lowest interoperability risk across clients and proxies; minimal schema and validation surface; simple smoke and manual commands. -- **Cons:** Per-request customization (timeouts/verbosity) cannot be expressed via payload. -- **Cascading implications:** Any future knobs require new query parameters or a new endpoint version. -- **Risks:** Future extension pressure leads to ad-hoc query flags without a versioned request model. -- **Unlocks:** Deterministic endpoint behavior with a single contract. -- **Quick wins / low-hanging fruit:** Simplifies initial implementation and test harnesses. - -**Option B — `POST` with a structured request body** -- **Pros:** Clear extension point for per-request knobs; versioned request schema can evolve. -- **Cons:** Adds schema surface (input validation, compatibility); increases ambiguity risk if knobs are not exhaustively specified in specs. -- **Cascading implications:** Requires request models in `agent-api-types` and more test coverage for input combinations. -- **Risks:** Partial specification leads to divergent behavior across platforms and versions. -- **Unlocks:** Future configurable probes without endpoint proliferation. -- **Quick wins / low-hanging fruit:** None for DS0; overhead is immediate. - -**Recommendation** -- **Selected:** Option A — `GET` with no request body -- **Rationale (crisp):** DS0 requires a fixed report; `GET` with no body keeps the contract small and deterministic. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement the endpoint as `GET` with no request body and fixed behavior. -- `DS0-test`: add schema tests that assume no request payload and fixed response fields. - -### DR-0007 — JSON contract shape for doctor commands - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md`, `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md`, `docs/project_management/_archived/doctor_scopes/smoke/` - -**Problem / Context** -- Existing doctor output mixes host- and world-derived facts across platforms. -- DS0 requires stable, auditable automation contracts that distinguish host readiness from world readiness. - -**Option A — Keep a flat top-level JSON shape and add more keys** -- **Pros:** Smaller diff from existing output; fewer internal consumers need structural updates. -- **Cons:** Encourages scope mixing; increases risk of “false green” where host checks pass but world checks are absent or stale. -- **Cascading implications:** Future additions expand the flat namespace and make it harder to reason about provenance of fields. -- **Risks:** Consumers couple to incidental field presence and interpret host fields as world facts. -- **Unlocks:** Faster short-term adoption for existing scripts that parse flat keys. -- **Quick wins / low-hanging fruit:** Minimal implementation churn. - -**Option B — Introduce an explicit schema version and scoped `host`/`world` blocks** -- **Pros:** Makes scope provenance explicit; supports strict contract tests; enables stable envelope semantics across platforms. -- **Cons:** Requires updating internal consumers that parse doctor JSON and related tests/fixtures. -- **Cascading implications:** Requires internal consumer updates in the same slice to avoid drift. -- **Risks:** Incomplete consumer updates break downstream commands until reconciled. -- **Unlocks:** A stable interface for future tooling and reporting pipelines. -- **Quick wins / low-hanging fruit:** Clear operator UX: one report contains both scopes with explicit boundaries. - -**Recommendation** -- **Selected:** Option B — schema versioned envelope with `host` and `world` blocks -- **Rationale (crisp):** Scope separation in the JSON contract is required for auditability and to prevent false-green automation. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement the envelope schema and update internal consumers that parse doctor JSON. -- `DS0-test`: add schema and consumer tests/fixtures that validate the new scoped blocks. -- `DS0-integ-core`: confirm consumers parse the new schema and local gates remain green. - -### DR-0008 — Exit code mapping for doctor commands - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/standards/EXIT_CODE_TAXONOMY.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- Existing doctor behavior historically used exit code `2` for readiness failures on some platforms, which conflicts with the canonical taxonomy. -- DS0 adds new failure modes (world disabled, world unreachable, missing prerequisites) that require deterministic mapping for automation. - -**Option A — Keep existing “doctor failures use exit 2” behavior** -- **Pros:** Minimizes short-term compatibility churn for any scripts that assume `2` for doctor failures. -- **Cons:** Conflicts with the canonical taxonomy where `2` is for usage/config errors; makes automation inconsistent across Substrate commands. -- **Cascading implications:** Future features either copy the inconsistency or introduce per-command exit code meanings. -- **Risks:** Operators misdiagnose usage errors vs readiness failures; CI pipelines treat readiness failures as misconfiguration. -- **Unlocks:** Compatibility with legacy assumptions in downstream tooling. -- **Quick wins / low-hanging fruit:** Minimal change to existing expectations. - -**Option B — Align doctor exit codes to the canonical taxonomy** -- **Pros:** Consistent automation semantics across commands; aligns with the standards used by planning packs; supports unambiguous gating and scripting. -- **Cons:** Requires updating any tests/docs/scripts that assumed legacy doctor exit codes. -- **Cascading implications:** Specs, playbooks, smoke scripts, and tests must use the same mapping without per-platform drift. -- **Risks:** Partial updates create inconsistent behavior across platforms. -- **Unlocks:** A stable contract where exit codes map to “dependency unavailable” vs “missing prerequisites” vs “usage error”. -- **Quick wins / low-hanging fruit:** Immediate consistency with `EXIT_CODE_TAXONOMY.md`. - -**Recommendation** -- **Selected:** Option B — align to the canonical taxonomy -- **Rationale (crisp):** DS0 is a contract change; aligning to the canonical taxonomy removes ambiguity and stabilizes automation. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement the DS0-spec exit code mapping, including the `3` vs `4` discriminator for “unreachable” vs “not provisioned”. -- `DS0-test`: add tests that enforce exit codes for disabled/unreachable/unsupported cases per DS0-spec. -- `DS0-integ-core`: validate exit codes during integration and capture evidence in the session log. - -### DR-0009 — Doctor side effects (agent/VM start) - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- “Doctor” commands are safety diagnostics. Starting services or provisioning during doctor runs makes results non-deterministic and adds side effects that are not expected during validation and smoke. - -**Option A — Doctor ensures the world backend is running (spawn/start)** -- **Pros:** Higher chance of returning success immediately after installation; one command can recover from “service stopped” states. -- **Cons:** Introduces side effects; complicates smoke scripts and makes repeated runs depend on prior state; mixes diagnosis with remediation. -- **Cascading implications:** Requires carefully audited state changes and logs; increases complexity around permissions and prompting. -- **Risks:** Doctor changes system state unexpectedly and hides underlying provisioning issues. -- **Unlocks:** A “self-healing” UX for some environments. -- **Quick wins / low-hanging fruit:** Fewer failures when the only issue is “service not started”. - -**Option B — Doctor is passive (no provisioning, no spawning, no VM start)** -- **Pros:** Deterministic; safe; compatible with CI and smoke; results reflect the actual system state without mutation. -- **Cons:** Users must run explicit provisioning or start commands to remediate. -- **Cascading implications:** Operator runbooks reference separate provisioning flows. -- **Risks:** None beyond user friction in recovery workflows. -- **Unlocks:** Repeatable diagnostics that support gating and regression detection. -- **Quick wins / low-hanging fruit:** Simplifies implementation and makes failures reproducible. - -**Recommendation** -- **Selected:** Option B — passive only -- **Rationale (crisp):** Deterministic, side-effect-free diagnostics are required for smoke and reliable operator triage. - -**Follow-up tasks (explicit)** -- `DS0-code`: ensure both doctor commands avoid provisioning/spawning/VM start paths. -- `DS0-integ-core`: validate that running doctor does not start or provision the world backend as a side effect. - -### DR-0010 — Behavior on Windows for doctor scopes - -**Decision owner(s):** Substrate platform maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md`, `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - -**Problem / Context** -- DS0 introduces new doctor scope commands. On Windows, the backend is not ready to report the required host/world readiness contracts without false-green risk. - -**Option A — Keep placeholder “not implemented” output with `ok=true`** -- **Pros:** Avoids breaking any Windows workflows that assume exit code `0`. -- **Cons:** Creates false-green output; automation and operators treat Windows as ready when it is not; violates DS0 acceptance criteria. -- **Cascading implications:** Downstream tools accept unsupported state as successful; hard to detect regressions. -- **Risks:** Security posture degrades because “doctor green” does not reflect enforcement readiness. -- **Unlocks:** Compatibility with existing Windows CI expectations. -- **Quick wins / low-hanging fruit:** Minimal code change. - -**Option B — Explicit unsupported contract (`ok=false`, status `unsupported`, exit code `4`)** -- **Pros:** No false-green output; automation can treat Windows as not supported/missing prerequisites; contract is explicit and testable. -- **Cons:** Any Windows scripts expecting exit `0` must be updated. -- **Cascading implications:** CI parity tasks and docs align to explicit unsupported semantics; manual playbook and smoke scripts validate the behavior. -- **Risks:** Minor compatibility churn for any existing scripts. -- **Unlocks:** Clean separation between “feature not supported” and “feature failing”. -- **Quick wins / low-hanging fruit:** A deterministic contract that stays stable until Windows support is implemented. - -**Recommendation** -- **Selected:** Option B — explicit unsupported contract with exit `4` -- **Rationale (crisp):** Explicit unsupported semantics prevent false-green and are required for auditability. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement explicit unsupported behavior for Windows host/world doctor paths. -- `DS0-test`: add tests that enforce the Windows unsupported JSON contract and exit code. -- `DS0-integ-windows`: address CI parity failures and confirm Windows compile parity is green. - -### DR-0011 — Behavior when world isolation is disabled - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- When world isolation is disabled by effective config, running probes against world-agent transport can produce misleading “agent down” output and introduces non-determinism for host-only installs. - -**Option A — Probe transport even when world is disabled** -- **Pros:** Detects “disabled but still installed” states and can surface service issues even when world is not enabled. -- **Cons:** Produces confusing output on host-only installs; makes disabled state look like an error; adds unnecessary dependency checks. -- **Cascading implications:** Operator triage becomes ambiguous; scripts cannot distinguish “disabled by choice” from “agent unreachable”. -- **Risks:** Users interpret disabled state as a failure and attempt unnecessary remediation. -- **Unlocks:** Extra diagnostics for mixed installs. -- **Quick wins / low-hanging fruit:** Reuses existing probing paths. - -**Option B — Short-circuit when world is disabled** -- **Pros:** Deterministic output; clear operator signal (`status=disabled`); avoids transport probing and related side effects. -- **Cons:** Does not report transport readiness while disabled. -- **Cascading implications:** Operator runbooks reference enabling world before probing transport readiness. -- **Risks:** None beyond reduced diagnostics in a disabled state. -- **Unlocks:** Stable automation semantics for `--no-world` and host-only installs. -- **Quick wins / low-hanging fruit:** Simple, consistent behavior across platforms. - -**Recommendation** -- **Selected:** Option B — short-circuit when world is disabled -- **Rationale (crisp):** Disabled state is an intentional configuration and requires deterministic reporting without transport probes. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement the disabled short-circuit semantics in world doctor. -- `DS0-test`: add tests that enforce exit `4` and `world.status=="disabled"` for `--no-world`. -- `DS0-integ-core`: validate the disabled short-circuit during integration and manual playbook runs. - -### DR-0012 — Timeout/retry policy for world-doctor agent request - -**Decision owner(s):** Substrate CLI maintainers -**Date:** 2026-01-08 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -**Problem / Context** -- World doctor is used in smoke and CI contexts where deterministic runtime is required. Retrying can hide failures and inflate time budgets. - -**Option A — Retry with backoff** -- **Pros:** More resilient to transient jitter; improves success rate during unstable startup windows. -- **Cons:** Increases runtime variance; makes smoke scripts slower and less deterministic; failure reason is less crisp. -- **Cascading implications:** CI time budgets and operator guidance must account for multi-attempt behavior. -- **Risks:** Intermittent issues become harder to reproduce and debug. -- **Unlocks:** Better UX for users immediately after starting a service. -- **Quick wins / low-hanging fruit:** Better success rate in the presence of transient network/service flakiness. - -**Option B — Single attempt with strict timeouts (no retries)** -- **Pros:** Deterministic; faster failure with clear error classification; supports reliable smoke and regression detection. -- **Cons:** Less tolerant of transient flakiness; users may re-run after provisioning. -- **Cascading implications:** Timeout values must be set explicitly and documented in implementation notes. -- **Risks:** A transient failure produces an exit `3` even if a second attempt would succeed. -- **Unlocks:** Predictable CI and operator triage. -- **Quick wins / low-hanging fruit:** Simple implementation with crisp failure semantics. - -**Recommendation** -- **Selected:** Option B — single attempt with strict timeouts (no retries) -- **Rationale (crisp):** Determinism is required for smoke and automation; retries hide failures and inflate runtimes. - -**Follow-up tasks (explicit)** -- `DS0-code`: implement a single-attempt agent request path with explicit timeouts and no retries. -- `DS0-test`: add a test that ensures the client does not retry on failure (one request per invocation). diff --git a/docs/project_management/_archived/doctor_scopes/execution_preflight_report.md b/docs/project_management/_archived/doctor_scopes/execution_preflight_report.md deleted file mode 100644 index 4071b8f14..000000000 --- a/docs/project_management/_archived/doctor_scopes/execution_preflight_report.md +++ /dev/null @@ -1,71 +0,0 @@ -# Execution Preflight Gate Report — doctor_scopes - -Date (UTC): 2026-01-09 - -Standard: -- `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` - -Feature directory: -- `docs/project_management/_archived/doctor_scopes/` - -## Recommendation - -RECOMMENDATION: **ACCEPT** - -Rationale: -- `tasks.json` platform declarations match the DS0 spec intent: behavioral smoke on `linux, macos` and CI parity on `linux, macos, windows` (no WSL). -- Smoke scripts are runnable and directly mirror the `manual_testing_playbook.md` assertions for the “happy path” JSON contracts on Linux/macOS; Windows smoke is an explicit no-op as required for CI-parity-only. -- CI dispatch paths referenced by integration tasks are valid (`make ci-compile-parity ...`, `make feature-smoke ...`), and the `feat/doctor-scopes` workflow ref exists on `origin`. - -## Inputs Reviewed - -- [x] ADR accepted and still matches intent -- [x] Planning Pack complete (`plan.md`, `tasks.json`, `session_log.md`, specs, kickoff prompts) -- [x] Triad sizing is appropriate (each slice is one behavior delta; no “grab bag” slices) -- [x] Cross-platform plan is explicit (`tasks.json` meta: behavior + CI parity platforms) -- [x] `manual_testing_playbook.md` exists and is runnable -- [x] Smoke scripts exist and map to the manual playbook - -## Cross-Platform Coverage - -- Declared behavior platforms (smoke required): `linux, macos` -- Declared CI parity platforms (parity required): `linux, macos, windows` -- WSL required: `no` - -## Smoke ↔ Manual Parity Check - -Smoke scripts to validate: -- Linux smoke: `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` -- macOS smoke: `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` -- Windows smoke: `docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1` (must be a no-op; Windows is CI-parity-only here) - -Manual playbook: -- `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - -Parity notes: -- Linux smoke asserts `substrate host doctor --json` and `substrate world doctor --json` stable fields, matching the Linux playbook contract checks. -- macOS smoke asserts the same stable fields for `host doctor` and `world doctor`, matching the macOS playbook contract checks. -- Windows smoke is intentionally a no-op, matching the playbook’s “CI parity only” stance for DS0. - -## CI Dispatch Readiness - -The integration tasks in `docs/project_management/_archived/doctor_scopes/tasks.json` require: -- `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` -- `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -Preflight must confirm: -- The workflow ref exists on the remote (`feat/doctor-scopes` is pushed): `origin/feat/doctor-scopes`. -- Self-hosted runners exist and are online for behavior smoke: - - Linux: `linux-manjaro-runner` (labels include `self-hosted`, `Linux`, `linux-host`) - - macOS: `macOS-runner` (labels include `self-hosted`, `macOS`) -- GitHub-hosted CI parity workflow is enabled and runnable (`.github/workflows/ci-compile-parity.yml` is `workflow_dispatch`-capable). - -Run ids/URLs (leave blank until preflight is executed): -- CI compile parity: -- Linux smoke: -- macOS smoke: - -## Required Fixes Before Starting DS0 - -- Planning quality gate must be `RECOMMENDATION: ACCEPT` before starting DS0 (this execution preflight gate does not override the planning gate ordering requirement in `EXECUTION_PREFLIGHT_GATE_STANDARD.md`). diff --git a/docs/project_management/_archived/doctor_scopes/integration_map.md b/docs/project_management/_archived/doctor_scopes/integration_map.md deleted file mode 100644 index 336929dc6..000000000 --- a/docs/project_management/_archived/doctor_scopes/integration_map.md +++ /dev/null @@ -1,63 +0,0 @@ -# Integration Map — doctor_scopes (DS0) - -Goal: -- Provide an unambiguous “what touches what” map so triad agents know exactly where to work and what to validate. - -## Contract surfaces - -- CLI: - - Add: `substrate host doctor [--json]` - - Change: `substrate world doctor [--json]` semantics and JSON contract - - Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` -- Agent API: - - Add: `GET /v1/doctor/world` - - Types: add `WorldDoctorReportV1` in `crates/agent-api-types` - -## Primary code touch points (expected) - -- CLI parsing / routing: - - `crates/shell/src/execution/cli.rs` (new `Host` subcommand + `doctor` verb) - - `crates/shell/src/execution/platform/mod.rs` (route host/world doctor entry points; compute effective config for subcommands) -- Host doctor implementations: - - Linux: refactor existing host probes out of `crates/shell/src/execution/platform/linux.rs` - - macOS: refactor existing macOS doctor out of `crates/shell/src/execution/platform/macos.rs` - - Windows: new explicit unsupported report (remove “false green” behavior) in `crates/shell/src/execution/platform/windows.rs` -- World doctor (host-side): - - Use an agent client call to `GET /v1/doctor/world` (no spawning/starting) - - Prefer reusing existing transport selection logic used for agent execution (but without `ensure_ready` side effects) -- World-agent: - - Route registration: `crates/world-agent/src/lib.rs` (add route) - - Handler implementation: `crates/world-agent/src/handlers.rs` (or existing handler module used by router) - - Probe logic: reuse existing world-side primitives (Landlock detection + overlay enumeration probe) already present in `crates/world` -- Agent API client/types: - - `crates/agent-api-types/src/lib.rs` (add `WorldDoctorReportV1` structs and serde tests) - - `crates/agent-api-client/src/lib.rs` (add a method `world_doctor()` returning `WorldDoctorReportV1`) - -## Internal consumers that must be updated in DS0 - -- Health/shim snapshots: - - `crates/shell/src/builtins/shim_doctor/report.rs` (world doctor snapshot parsing) -- World verify: - - `crates/shell/src/builtins/world_verify.rs` (doctor parsing for `world_socket` and `ok`) -- Docs: - - `docs/COMMANDS.md`, `docs/WORLD.md`, `docs/USAGE.md`, `docs/INSTALLATION.md`, `docs/ISOLATION_SUPPORT_MATRIX.md` - -## Validation gates (required) - -- Local (integration core + final): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - Relevant tests (at least: shell tests that parse doctor JSON; agent-api-types tests) - - `make integ-checks` -- CI parity: - - `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` -- Behavior smoke: - - Linux: `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` via `make feature-smoke ... PLATFORM=linux` - - macOS: `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` via `make feature-smoke ... PLATFORM=macos` - -## Smoke ↔ manual testing parity contract - -- Manual testing is defined in `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md`. -- Smoke scripts must: - - run the same CLI commands as the manual playbook (minimal subset), and - - assert exit codes + required JSON keys/values (not just “command ran”). diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-code.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-code.md deleted file mode 100644 index a15ceaac9..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-code.md +++ /dev/null @@ -1,38 +0,0 @@ -# Kickoff: DS0-code (Doctor scope split — code) - -## Scope -- Production code only; no tests. -- ADR: `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-code` on branch `dsc-ds0-code` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/doctor_scopes/plan.md`, `docs/project_management/_archived/doctor_scopes/tasks.json`, `docs/project_management/_archived/doctor_scopes/session_log.md`, ADR, spec, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/doctor_scopes" SLICE_ID="DS0"` - -## Requirements - -- Implement the DS0 production code changes required by `docs/project_management/_archived/doctor_scopes/DS0-spec.md`: - - Add `substrate host doctor` CLI surface. - - Add world-agent endpoint `GET /v1/doctor/world`. - - Update `substrate world doctor` to consume the agent endpoint and emit the new JSON envelope schema. -- Maintain the “doctor is passive” contract: - - No provisioning side effects. - - No agent spawning. - - No VM start. - -## Commands (required) -- `cargo fmt` -- `cargo clippy --workspace --all-targets -- -D warnings` - -## End Checklist - -1. Run required commands and capture outputs in your task notes. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-code"`. -3. On the orchestration branch, update `docs/project_management/_archived/doctor_scopes/tasks.json` and add the END entry to `docs/project_management/_archived/doctor_scopes/session_log.md`; commit docs (`docs: finish DS0-code`). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-core.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-core.md deleted file mode 100644 index d8aea44d9..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-core.md +++ /dev/null @@ -1,40 +0,0 @@ -# Kickoff: DS0-integ-core (integration core) - -## Scope -- Merge DS0 code + tests, resolve drift to the spec (spec wins), and make the slice green on the primary dev platform. -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-integ-core` on branch `dsc-ds0-integ-core` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/doctor_scopes/plan.md`, `docs/project_management/_archived/doctor_scopes/tasks.json`, `docs/project_management/_archived/doctor_scopes/session_log.md`, spec, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/doctor_scopes" TASK_ID="DS0-integ-core"` - -## Requirements - -- Merge `dsc-ds0-code` and `dsc-ds0-test` into this branch/worktree and reconcile to spec. -- Local integration gates MUST be green before any smoke dispatch: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Dispatch CI compile parity (GitHub-hosted runners) for fast cross-platform feedback: - - `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` -- Dispatch Feature Smoke for behavior platforms: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- If smoke fails on a behavior platform: - - Do not fix platform-specific issues in integ-core. - - Start the corresponding platform-fix task(s) from the orchestration checkout. - -## End Checklist - -1. Ensure local integration gates are green and committed. -2. Record CI parity run id/URL and smoke run id/URL(s) in the session log END entry for this task. -3. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-integ-core"`. -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-linux.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-linux.md deleted file mode 100644 index 764bc24e8..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-linux.md +++ /dev/null @@ -1,30 +0,0 @@ -# Kickoff: DS0-integ-linux (integration platform-fix — linux) - -## Scope -- Fix Linux-only regressions surfaced by Feature Smoke for this slice. -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` -- Smoke script: `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-integ-linux` on branch `dsc-ds0-integ-linux` and that `.taskmeta.json` exists at the worktree root. -2. Read: spec, manual playbook, smoke script, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/doctor_scopes" TASK_ID="DS0-integ-linux"` - -## Requirements - -- Make Linux Feature Smoke green for this slice: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- When fixing: - - keep behavior aligned to `DS0-spec.md`; - - add minimal tests only when required to prevent regression. - -## End Checklist - -1. Ensure Linux smoke is green; record `RUN_ID`/`RUN_URL` in the session log END entry for this task. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-integ-linux"`. -3. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-macos.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-macos.md deleted file mode 100644 index ba5ef1876..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-macos.md +++ /dev/null @@ -1,30 +0,0 @@ -# Kickoff: DS0-integ-macos (integration platform-fix — macos) - -## Scope -- Fix macOS-only regressions surfaced by Feature Smoke for this slice. -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` -- Smoke script: `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-integ-macos` on branch `dsc-ds0-integ-macos` and that `.taskmeta.json` exists at the worktree root. -2. Read: spec, manual playbook, smoke script, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/doctor_scopes" TASK_ID="DS0-integ-macos"` - -## Requirements - -- Make macOS Feature Smoke green for this slice: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- When fixing: - - keep behavior aligned to `DS0-spec.md`; - - add minimal tests only when required to prevent regression. - -## End Checklist - -1. Ensure macOS smoke is green; record `RUN_ID`/`RUN_URL` in the session log END entry for this task. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-integ-macos"`. -3. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-windows.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-windows.md deleted file mode 100644 index c5d7cdefd..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-windows.md +++ /dev/null @@ -1,27 +0,0 @@ -# Kickoff: DS0-integ-windows (integration platform-fix — windows CI parity only) - -## Scope -- Fix Windows compilation/lint/test parity issues only. -- Windows is CI-parity-only for DS0; no behavioral smoke is required. -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-integ-windows` on branch `dsc-ds0-integ-windows` and that `.taskmeta.json` exists at the worktree root. -2. Read: spec and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/doctor_scopes" TASK_ID="DS0-integ-windows"` - -## Requirements - -- Make CI compile parity green for this slice (GitHub-hosted runners): - - `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` - -## End Checklist - -1. Record the CI parity run id/URL in the session log END entry for this task. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-integ-windows"`. -3. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ.md deleted file mode 100644 index 779084a8a..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ.md +++ /dev/null @@ -1,37 +0,0 @@ -# Kickoff: DS0-integ (integration final) - -## Scope -- Final integration for DS0: merge platform-fix branches, confirm cross-platform green, and complete the DS0 closeout gate report. -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` -- Closeout report: `docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-integ` on branch `dsc-ds0-integ` and that `.taskmeta.json` exists at the worktree root. -2. Read: spec, manual playbook, smoke scripts, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-integ-final FEATURE_DIR="docs/project_management/_archived/doctor_scopes" SLICE_ID="DS0" LAUNCH_CODEX=1` - -## Requirements - -- Merge any platform-fix branches for DS0 and ensure local gates are green: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Re-run CI compile parity (linux/macos/windows): - - `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` -- Re-run behavioral smoke for behavior platforms: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/doctor_scopes" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="feat/doctor-scopes" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- Fill `docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md` with evidence (run ids/URLs and gate results). - -## End Checklist - -1. Ensure all required CI is green and recorded in the closeout report. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-integ"`. -3. On the orchestration branch: mark DS0 tasks completed and add session log END entries; commit docs. -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-test.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-test.md deleted file mode 100644 index ca3216ce8..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-test.md +++ /dev/null @@ -1,35 +0,0 @@ -# Kickoff: DS0-test (Doctor scope split — test) - -## Scope -- Tests only; no production code. -- ADR: `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` -- Spec: `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/dsc-ds0-test` on branch `dsc-ds0-test` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/doctor_scopes/plan.md`, `docs/project_management/_archived/doctor_scopes/tasks.json`, `docs/project_management/_archived/doctor_scopes/session_log.md`, ADR, spec, and this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/doctor_scopes" SLICE_ID="DS0"` - -## Requirements - -Add/modify tests so the DS0 acceptance criteria are enforced: -- CLI wiring tests for the new `host doctor` surface. -- JSON schema tests for `HostDoctorEnvelopeV1` and `WorldDoctorEnvelopeV1`. -- `agent-api-types` schema round-trip for `WorldDoctorReportV1`. -- Update internal consumers’ tests/fixtures that parse world doctor JSON (health/shim snapshots, world verify). - -## Commands (required) -- `cargo fmt` -- Targeted test runs for any suites you touch/add. - -## End Checklist - -1. Run required commands and targeted tests; capture outputs in your task notes. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="DS0-test"`. -3. On the orchestration branch, update `docs/project_management/_archived/doctor_scopes/tasks.json` and add the END entry to `docs/project_management/_archived/doctor_scopes/session_log.md`; commit docs (`docs: finish DS0-test`). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/F0-exec-preflight.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/F0-exec-preflight.md deleted file mode 100644 index d2bdd4c18..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/F0-exec-preflight.md +++ /dev/null @@ -1,34 +0,0 @@ -# Kickoff: F0-exec-preflight (execution preflight gate) - -## Scope -- Run the feature-level execution preflight gate before any DS0 triad work begins. -- This task is docs-only and must be performed on the orchestration branch (no worktrees). -- Standard: `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` -- Report: `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Ensure the orchestration branch exists and is checked out: - - `make triad-orch-ensure FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` -2. Read: ADR + Executive Summary, `docs/project_management/_archived/doctor_scopes/plan.md`, `docs/project_management/_archived/doctor_scopes/tasks.json`, `docs/project_management/_archived/doctor_scopes/session_log.md`, `docs/project_management/_archived/doctor_scopes/DS0-spec.md`, and this prompt. -3. Set `F0-exec-preflight` status to `in_progress` in `docs/project_management/_archived/doctor_scopes/tasks.json`; add a START entry to `docs/project_management/_archived/doctor_scopes/session_log.md`; commit docs (`docs: start F0-exec-preflight`). - -## Requirements - -Fill `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` with a concrete recommendation: -- **ACCEPT**: triads may begin (after the planning quality gate is also ACCEPT). -- **REVISE**: do not start triads until the listed issues are fixed and preflight is re-run. - -At minimum, verify: -- `tasks.json` platform declarations are correct and match the spec. -- Smoke scripts are runnable and mirror `manual_testing_playbook.md`. -- CI dispatch commands embedded in integration tasks are correct and the `feat/doctor-scopes` ref exists on the remote. - -## End Checklist - -1. Update `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` and set `RECOMMENDATION: ACCEPT` or `RECOMMENDATION: REVISE`. -2. Set `F0-exec-preflight` status to `completed` in `docs/project_management/_archived/doctor_scopes/tasks.json`; add an END entry to `docs/project_management/_archived/doctor_scopes/session_log.md` (include the recommendation + any required fixes). -3. Commit docs (`docs: finish F0-exec-preflight`). - diff --git a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/FZ-feature-cleanup.md b/docs/project_management/_archived/doctor_scopes/kickoff_prompts/FZ-feature-cleanup.md deleted file mode 100644 index cb2ee415e..000000000 --- a/docs/project_management/_archived/doctor_scopes/kickoff_prompts/FZ-feature-cleanup.md +++ /dev/null @@ -1,26 +0,0 @@ -# Kickoff: FZ-feature-cleanup (feature cleanup) - -## Scope -- Remove retained task worktrees for this feature and optionally prune local branches via triad automation. -- Standard: `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Verify all tasks in `docs/project_management/_archived/doctor_scopes/tasks.json` are `completed`. -2. Ensure the orchestration checkout is clean (no staged or unstaged changes). -3. Dry-run cleanup: - - `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/doctor_scopes" DRY_RUN=1 REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -## Requirements - -- Execute cleanup and paste the printed summary block into the session log END entry for this task: - - `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/doctor_scopes" REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -## End Checklist - -1. Paste cleanup summary block into `docs/project_management/_archived/doctor_scopes/session_log.md`. -2. Mark `FZ-feature-cleanup` as `completed` in `docs/project_management/_archived/doctor_scopes/tasks.json` and add an END entry. -3. Commit docs (`docs: finish FZ-feature-cleanup`). - diff --git a/docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md b/docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md deleted file mode 100644 index 59bc97d4c..000000000 --- a/docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md +++ /dev/null @@ -1,97 +0,0 @@ -# Manual Testing Playbook — doctor_scopes (DS0) - -Scope: -- Manual validation for the DS0 contract in `docs/project_management/_archived/doctor_scopes/DS0-spec.md`. -- This playbook is the human-readable equivalent of the smoke scripts in `docs/project_management/_archived/doctor_scopes/smoke/`. - -Exit code taxonomy: -- `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -## Preconditions (all platforms) - -- Build a `substrate` binary that includes the DS0 changes. -- Ensure world isolation is enabled for the current directory (effective config `world_enabled=true`), unless you are explicitly running the “world disabled” cases below. - -## Linux (behavior platform) - -### 1) Host doctor JSON contract - -Commands: -- `substrate host doctor --json | jq -e '.schema_version==1 and .platform==\"linux\" and .world_enabled==true and .ok==true and .host.platform==\"linux\" and .host.ok==true'` - -Expected: -- Exit code `0`. -- JSON includes `host.world_socket.socket_exists==true` and `host.world_socket.probe_ok==true`. - -### 2) World doctor JSON contract (agent-reported world facts) - -Commands: -- `substrate world doctor --json | jq -e '.schema_version==1 and .platform==\"linux\" and .world_enabled==true and .ok==true and .host.ok==true and .world.schema_version==1 and .world.ok==true and .world.landlock.supported==true and (.world.landlock.abi|type==\"number\") and .world.world_fs_strategy.probe.id==\"enumeration_v1\" and .world.world_fs_strategy.probe.result==\"pass\"'` - -Expected: -- Exit code `0`. -- World block is present and indicates Landlock support/ABI and a passing enumeration probe. - -### 3) World disabled short-circuit - -Commands: -- `substrate --no-world world doctor --json | jq -e '.world_enabled==false and .ok==false and .world.status==\"disabled\" and .world.ok==false'` - -Expected: -- Exit code `4`. -- No socket probing side effects; the report is a deterministic “disabled” status. - -## macOS (behavior platform) - -### 1) Host doctor JSON contract - -Commands: -- `substrate host doctor --json | jq -e '.schema_version==1 and .platform==\"macos\" and .world_enabled==true and .ok==true and .host.platform==\"macos\" and .host.ok==true and .host.lima.installed==true and .host.lima.virtualization==true and .host.lima.vm_status==\"Running\" and .host.lima.service_active==true and .host.lima.agent_caps_ok==true'` - -Expected: -- Exit code `0`. -- Host block reports Lima/Virtualization readiness and agent capability probe success. - -### 2) World doctor JSON contract (guest-kernel facts via agent endpoint) - -Commands: -- `substrate world doctor --json | jq -e '.schema_version==1 and .platform==\"macos\" and .world_enabled==true and .ok==true and .host.ok==true and .world.schema_version==1 and .world.ok==true and .world.landlock.supported==true and (.world.landlock.abi|type==\"number\") and .world.world_fs_strategy.probe.result==\"pass\"'` - -Expected: -- Exit code `0`. -- World block includes Landlock support/ABI from the guest kernel and a passing enumeration probe. - -### 3) World disabled short-circuit - -Commands: -- `substrate --no-world world doctor --json | jq -e '.world_enabled==false and .ok==false and .world.status==\"disabled\" and .world.ok==false'` - -Expected: -- Exit code `4`. - -## Windows (CI parity platform only) - -Windows is CI-parity-only for DS0. Behavior is intentionally explicit “unsupported” for the new doctor scopes. - -### 1) Host doctor explicit unsupported - -Commands: -- `substrate.exe host doctor --json | ConvertFrom-Json | % { if ($_.platform -ne \"windows\") { throw \"platform mismatch\" }; if ($_.ok -ne $false) { throw \"ok must be false\" }; if ($_.host.status -ne \"unsupported\") { throw \"expected unsupported\" } }` - -Expected: -- Exit code `4`. - -### 2) World doctor explicit unsupported - -Commands: -- `$out = & substrate.exe world doctor --json; $code = $LASTEXITCODE; $obj = $out | ConvertFrom-Json; if ($obj.platform -ne \"windows\") { throw \"platform mismatch\" }; if ($obj.ok -ne $false) { throw \"ok must be false\" }; if ($obj.host.status -ne \"unsupported\") { throw \"expected host unsupported\" }; if ($obj.world.status -ne \"unsupported\") { throw \"expected world unsupported\" }; if ($code -ne 4) { throw \"expected exit code 4\" }` - -Expected: -- Exit code `4`. - -## Smoke scripts (required parity) - -Smoke scripts must be runnable and must match the commands above (minimal subset): -- Linux: `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` -- macOS: `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` -- Windows: `docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1` (no-op; CI parity only) diff --git a/docs/project_management/_archived/doctor_scopes/plan.md b/docs/project_management/_archived/doctor_scopes/plan.md deleted file mode 100644 index 10e9e4bbd..000000000 --- a/docs/project_management/_archived/doctor_scopes/plan.md +++ /dev/null @@ -1,35 +0,0 @@ -# doctor_scopes — plan - -## Scope -- Feature directory: `docs/project_management/_archived/doctor_scopes/` -- Orchestration branch: `feat/doctor-scopes` -- ADR: `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - -## Goal -- Produce a clear operator-facing split between: - - `substrate host doctor`: host/transport readiness only (no guest-kernel inference). - - `substrate world doctor`: combined `host` + `world` report, where `world` facts come from a world-agent endpoint (guest kernel + agent privileges). - -## Guardrails (non-negotiable) -- Specs are the single source of truth. -- Planning Pack docs are edited only on the orchestration branch. -- Do not edit planning docs inside the worktree. -- Doctor commands are passive diagnostics only (no provisioning, no agent spawning, no VM start). - -## Platforms -- Behavior platforms required (smoke required): `linux`, `macos` -- CI parity platforms required (compile parity required): `linux`, `macos`, `windows` -- WSL required: `false` - -## Execution gates -- Planning quality gate: `docs/project_management/_archived/doctor_scopes/quality_gate_report.md` (required before triads begin) -- Execution preflight gate: `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` (required because `execution_gates=true`) -- Slice closeout gate: `docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md` (required as part of `DS0-integ`) - -## Triads -- DS0: split doctor into host vs world scopes (code/test/integ) - -## Smoke -- Linux: `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` -- macOS: `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` -- Windows: `docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1` (CI parity only; smoke must be a no-op) diff --git a/docs/project_management/_archived/doctor_scopes/quality_gate_report.md b/docs/project_management/_archived/doctor_scopes/quality_gate_report.md deleted file mode 100644 index 1b11e9e07..000000000 --- a/docs/project_management/_archived/doctor_scopes/quality_gate_report.md +++ /dev/null @@ -1,303 +0,0 @@ -# Planning Quality Gate Report — doctor_scopes - -## Metadata -- Feature directory: `docs/project_management/_archived/doctor_scopes/` -- Reviewed commit: `184ee0d3cbf3484b4867c29cc66951d4ccc47715` -- Reviewer: `third-party reviewer (Codex CLI)` -- Date (UTC): `2026-01-09` -- Recommendation: `FLAG FOR HUMAN REVIEW` - -## Evidence: Commands Run (verbatim) - -```bash -export FEATURE_DIR="docs/project_management/_archived/doctor_scopes" - -# Planning lint (mechanical) -make planning-lint FEATURE_DIR="$FEATURE_DIR" -# exit 0 - -# JSON validity -jq -e . "$FEATURE_DIR/tasks.json" >/dev/null -# exit 0 - -jq -e . docs/project_management/packs/sequencing.json >/dev/null -# exit 0 - -# tasks.json required-field audit -python - <<'PY' -import json, os -feature_dir=os.environ["FEATURE_DIR"] -path=os.path.join(feature_dir,"tasks.json") -data=json.load(open(path,"r",encoding="utf-8")) -tasks=data["tasks"] if isinstance(data,dict) and "tasks" in data else data -required=[ - "id","name","type","phase","status","description", - "references","acceptance_criteria","start_checklist","end_checklist", - "worktree","integration_task","kickoff_prompt", - "depends_on","concurrent_with" -] -missing=[] -for t in tasks: - m=[k for k in required if k not in t] - if m: - missing.append((t.get("id",""),m)) -if missing: - for tid,m in missing: - print(tid,":",", ".join(m)) - raise SystemExit(1) -print("OK: tasks.json required fields present") -PY -# exit 0 - -# tasks.json invariants (schema + task model) -make planning-validate FEATURE_DIR="$FEATURE_DIR" -# exit 0 -``` - -## Required Inputs Read End-to-End (checklist) - -- ADR(s): `YES` (`docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md`) -- `plan.md`: `YES` -- `tasks.json`: `YES` -- `session_log.md`: `YES` -- All specs in scope: `YES` (`docs/project_management/_archived/doctor_scopes/DS0-spec.md`) -- `decision_register.md`: `YES` -- `integration_map.md`: `YES` -- `manual_testing_playbook.md`: `YES` -- Feature smoke scripts under `smoke/`: `YES` (`docs/project_management/_archived/doctor_scopes/smoke/`) -- `docs/project_management/packs/sequencing.json`: `YES` -- Standards: - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md`: `YES` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md`: `YES` - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md`: `YES` - - `docs/project_management/standards/EXIT_CODE_TAXONOMY.md`: `YES` - - `docs/project_management/standards/PLANNING_LINT_CHECKLIST.md`: `YES` - - `docs/project_management/standards/PLANNING_GATE_REPORT_TEMPLATE.md`: `YES` - -## Gate Results (PASS/FAIL with evidence) - -### 1) Zero-ambiguity contracts -- Result: `FAIL` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` (exit codes) includes overlapping/unclear categories: “agent unreachable” (`3`) vs “not provisioned” (`4`) (`DS0-spec.md` around lines 52–56). - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` (JSON contract) defines `world.status=="unreachable"` but does not define a distinct `world.status` for “not provisioned” (`DS0-spec.md` around lines 149–152). -- Notes: The plan is mostly unambiguous, but the `substrate world doctor` error classification is not precise enough to implement consistently. - -### 2) Decision quality (2 options, explicit tradeoffs, explicit selection) -- Result: `FAIL` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` entries do not follow the required format (missing “Problem/Context”, “Cascading implications”, “Risks”, “Unlocks”, “Quick wins”, “Rationale”, and “Follow-up tasks”) (e.g. `decision_register.md` lines 5–16). - - Required format: `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` (Decision Register Standard) lines 147–204. -- Notes: Two options are provided, but the register is not audit-ready per the repo standard. - -### 3) Cross-doc consistency (CLI/config/exit codes/paths) -- Result: `FAIL` -- Evidence: - - Exit code taxonomy is referenced consistently, but the “unreachable vs not provisioned” classification appears in both ADR and spec without a concrete discriminator: - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` lines 79–85 - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` lines 52–56 -- Notes: This will likely yield platform-divergent behavior for the same failure mode. - -### 4) Sequencing and dependency alignment -- Result: `PASS` -- Evidence: - - `docs/project_management/packs/sequencing.json` includes sprint `doctor_scopes` with `DS0` spec (`sequencing.json` lines ~172–178). - - `docs/project_management/_archived/doctor_scopes/tasks.json` dependencies enforce internal ordering (F0 → DS0-code/test → DS0-integ-core → platform-fix → DS0-integ) (see `tasks.json` task `depends_on` fields). -- Notes: No task starts before its declared prerequisites. - -### 5) Testability and validation readiness -- Result: `FAIL` -- Evidence: - - Manual playbook Windows “world doctor” step does not validate DS0’s required “unsupported” contract fields (`manual_testing_playbook.md` lines 84–90 vs DS0 acceptance criteria). - - DS0 requires: `ok=false`, `status=unsupported`, exit code `4` for Windows (`docs/project_management/_archived/doctor_scopes/DS0-spec.md` acceptance criteria near end). -- Notes: Linux/macOS commands are concrete and runnable; Windows section is currently too weak to catch contract regressions. - -### 5.1) Cross-platform parity task structure (schema v2+) -- Result: `PASS` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/tasks.json` meta: `schema_version: 3`, `behavior_platforms_required: ["linux","macos"]`, `ci_parity_platforms_required: ["linux","macos","windows"]`. - - Per slice: `DS0-integ-core`, `DS0-integ-linux`, `DS0-integ-macos`, `DS0-integ-windows`, `DS0-integ` exist and are dependency-wired. -- Notes: Matches the standards’ platform-fix integration model. - -### 6) Triad interoperability (execution workflow) -- Result: `PASS` -- Evidence: - - `tasks.json` required fields present (python audit above). - - Kickoff prompts include the sentinel: “Do not edit planning docs inside the worktree.” (lint runner PASS). -- Notes: Task automation model is consistent and runnable. - -## Findings (must be exhaustive) - -### Finding 001 — Mechanical lint passes (required gate) -- Status: `VERIFIED` -- Evidence: `make planning-lint FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → exit `0` (see commands). -- Impact: Confirms the Planning Pack meets mechanical requirements (presence, hard bans, schema checks). -- Fix required (exact): `none` - -### Finding 002 — Cross-platform parity task structure is present and wired -- Status: `VERIFIED` -- Evidence: `docs/project_management/_archived/doctor_scopes/tasks.json` meta `schema_version: 3` + tasks `DS0-integ-core`, `DS0-integ-{linux,macos,windows}`, `DS0-integ`. -- Impact: Execution can proceed through core integration, platform-fix, then final aggregation without workflow drift. -- Fix required (exact): `none` - -### Finding 003 — Decision register is not audit-ready per repo standard -- Status: `DEFECT` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` uses a shortened format (e.g. `DR-0001` at lines 5–16). - - Required format + traceability requirements: `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` lines 147–204. -- Impact: Decision quality and auditability requirements are not met; downstream triads lack explicit risks/implications/unlocks and follow-up mapping. -- Fix required (exact): Update every `DR-XXXX` entry in `docs/project_management/_archived/doctor_scopes/decision_register.md` to match the required template, including explicit follow-up tasks mapped to concrete `tasks.json` task IDs. -- If DEFECT: Alternative (one viable): Reduce the decision register to only the truly “major” decisions and fully template those, moving minor notes into the spec; still include follow-up task mapping for every remaining decision. - -### Finding 004 — Decision ↔ task traceability is missing in `tasks.json` -- Status: `DEFECT` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/tasks.json` task references include `docs/project_management/_archived/doctor_scopes/decision_register.md` but do not reference specific `DR-00XX` ids (e.g., `DS0-code` references list). - - Standard requirement: `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` lines 198–204. -- Impact: Post-hoc auditing cannot reliably answer “which task implemented which decision.” -- Fix required (exact): Update each relevant task’s `references` entries in `docs/project_management/_archived/doctor_scopes/tasks.json` to include DR ids, e.g. `docs/project_management/_archived/doctor_scopes/decision_register.md (DR-0001, DR-0002, ...)`, scoped per task. -- If DEFECT: Alternative (one viable): Add a single “Decision coverage” section to `docs/project_management/_archived/doctor_scopes/integration_map.md` mapping DR ids → task ids, and then reference that section from each task (still less direct than references-per-task). - -### Finding 005 — `substrate world doctor` exit code contract is ambiguous (unreachable vs not provisioned) -- Status: `DEFECT` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` lines 52–56 (`3`: unreachable; `4`: disabled/not provisioned or missing prereqs). - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` lines 149–152 (JSON `world.status` includes `disabled|unreachable|ok|missing_prereqs`, but no distinct “not provisioned” status). - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` lines 79–85 includes “world disabled/not provisioned” under exit `4`. -- Impact: Different implementations may choose exit `3` vs `4` for the same “socket missing/service not present” condition, breaking automation. -- Fix required (exact): In both `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` and `docs/project_management/_archived/doctor_scopes/DS0-spec.md`, define a concrete discriminator for exit `3` vs `4` (and, if needed, add/rename a `world.status` value so JSON matches exit semantics). -- If DEFECT: Alternative (one viable): Treat all “agent unreachable” states (including “not provisioned”) as exit `3`, and reserve exit `4` strictly for “world disabled” and “agent reachable but missing required primitives”; this requires removing “not provisioned” from the exit `4` description. - -### Finding 006 — Windows manual playbook does not validate the DS0 “unsupported” world doctor contract -- Status: `DEFECT` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` lines 84–90 only assert `platform=="windows"` for `world doctor`. - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` requires explicit Windows unsupported semantics and exit code `4` (acceptance criteria section). -- Impact: A regression (e.g., `ok=true` or missing `status=unsupported`) could slip through manual validation. -- Fix required (exact): Update the Windows “world doctor” playbook command to assert the required fields (`ok==false` and `world.status=="unsupported"` or the equivalent contract keys once finalized), plus exit code `4`. -- If DEFECT: Alternative (one viable): Remove the Windows world-doctor manual step entirely and replace it with a unit/integration test requirement in the DS0 test acceptance criteria, if Windows is strictly CI-parity-only and manual validation is not expected. - -## Decision: ACCEPT or FLAG - -### FLAG FOR HUMAN REVIEW -- Summary: Mechanical lint passes and the task graph is runnable, but the decision register/traceability requirements are not met and the `world doctor` error/exit-code contract is ambiguous. -- Required human decisions (explicit): - - Decide and document the authoritative exit-code mapping for “world enabled but not provisioned” vs “world enabled but transport failure”, including how to detect the difference (or explicitly collapse the cases). -- Blockers to execution: - - Bring `docs/project_management/_archived/doctor_scopes/decision_register.md` up to the required decision template (including follow-up tasks). - - Add DR id references in `docs/project_management/_archived/doctor_scopes/tasks.json` (or equivalent traceability mechanism that meets the standard). - - Clarify and align the exit code + JSON status contracts for `substrate world doctor`. - ---- - -# Planning Quality Gate Report — doctor_scopes (Pass 2 / remediation re-review) - -## Metadata -- Feature directory: `docs/project_management/_archived/doctor_scopes/` -- Reviewed commit: `852bc1d36f86c6f3a353a59ad9ece7d1816e2d94` -- Reviewer: `remediation agent (Codex CLI)` -- Date (UTC): `2026-01-09` -- Recommendation: `ACCEPT` - -## Evidence: Commands Run (verbatim) - -```bash -export FEATURE_DIR="docs/project_management/_archived/doctor_scopes" - -make planning-lint FEATURE_DIR="$FEATURE_DIR" -# exit 0 - -make planning-validate FEATURE_DIR="$FEATURE_DIR" -# exit 0 - -jq -e . "$FEATURE_DIR/tasks.json" >/dev/null -# exit 0 - -jq -e . docs/project_management/packs/sequencing.json >/dev/null -# exit 0 -``` - -## Gate Results (PASS/FAIL with evidence) - -### 1) Zero-ambiguity contracts -- Result: `PASS` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` defines an explicit discriminator for world-doctor exit `3` vs `4` and adds `world.status=="not_provisioned"` (`DS0-spec.md` lines 52–70 and 161–170). -- Notes: Exit code and JSON status semantics are implementable without platform-divergent interpretation. - -### 2) Decision quality (2 options, explicit tradeoffs, explicit selection) -- Result: `PASS` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` entries follow the required template, including explicit follow-up task mapping (example: `DR-0001` at line 10, `DR-0008` at line 256). -- Notes: Each decision has exactly two viable options and a single selected recommendation. - -### 3) Cross-doc consistency (CLI/config/exit codes/paths) -- Result: `PASS` -- Evidence: - - Exit code discriminator is aligned between: - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` (Exit codes section) - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` (Exit codes + JSON contracts) -- Notes: ADR and spec describe the same exit code semantics and detection rules. - -### 4) Sequencing and dependency alignment -- Result: `PASS` -- Evidence: - - `docs/project_management/packs/sequencing.json` contains sprint `doctor_scopes` with `DS0` spec. - - `docs/project_management/_archived/doctor_scopes/tasks.json` maintains the DS0 dependency graph (F0 → code/test → integ-core → platform-fix → integ). -- Notes: No task starts before declared prerequisites. - -### 5) Testability and validation readiness -- Result: `PASS` -- Evidence: - - Windows manual playbook validates `unsupported` contract fields for world doctor and asserts exit code `4` (`docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` lines 84–90). - - Linux/macOS smoke scripts and manual playbook commands assert stable JSON keys/values and exit code expectations. -- Notes: Manual and smoke validation are runnable and assert required contract fields. - -## Findings (must be exhaustive) - -### Finding 001 — Mechanical lint passes (required gate) -- Status: `VERIFIED` -- Evidence: `make planning-lint FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → exit `0` -- Impact: Confirms the Planning Pack meets mechanical requirements (presence, hard bans, schema checks). -- Fix required (exact): `none` - -### Finding 002 — Cross-platform parity task structure is present and wired -- Status: `VERIFIED` -- Evidence: `docs/project_management/_archived/doctor_scopes/tasks.json` meta `schema_version: 3` and required integration tasks exist and are dependency-wired. -- Impact: Execution can proceed through core integration, platform-fix, then final aggregation without workflow drift. -- Fix required (exact): `none` - -### Finding 003 — Decision register is audit-ready per repo standard -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` entries follow the required template and include follow-up tasks mapped to `tasks.json` IDs. -- Impact: Decisions are auditable and actionable during triad execution. -- Fix required (exact): `none` - -### Finding 004 — Decision ↔ task traceability is present in `tasks.json` -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/tasks.json` references include DR ids for tasks that implement decisions (`DS0-code` and `DS0-test`). -- Impact: Auditing can answer “which task implemented which decision.” -- Fix required (exact): `none` - -### Finding 005 — `substrate world doctor` exit code contract is unambiguous -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` defines the `3` vs `4` discriminator and adds `world.status=="not_provisioned"`. - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` aligns to the same discriminator. -- Impact: Automation and scripts can rely on stable exit codes and statuses. -- Fix required (exact): `none` - -### Finding 006 — Windows manual playbook validates the DS0 “unsupported” world doctor contract -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` asserts `ok==false`, `host.status=="unsupported"`, `world.status=="unsupported"`, and exit code `4`. -- Impact: Manual validation catches regressions in Windows unsupported semantics. -- Fix required (exact): `none` - -## Decision: ACCEPT or FLAG - -### ACCEPT -- Summary: Blocking defects from the prior pass are resolved; contracts are unambiguous, decisions are audit-ready, and validation steps are runnable. -- Next step: Execution triads may begin. diff --git a/docs/project_management/_archived/doctor_scopes/session_log.md b/docs/project_management/_archived/doctor_scopes/session_log.md deleted file mode 100644 index c2b342e32..000000000 --- a/docs/project_management/_archived/doctor_scopes/session_log.md +++ /dev/null @@ -1,213 +0,0 @@ -# doctor_scopes — session log - -## START — 2026-01-08T23:11:46Z — planning — Planning Pack authoring -- Feature: `docs/project_management/_archived/doctor_scopes/` -- Branch: `feat/doctor-scopes` -- Goal: Produce an execution-ready Planning Pack (no production code changes). -- Inputs read end-to-end: - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - - `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md` - - `docs/project_management/standards/ADR_STANDARD_AND_TEMPLATE.md` - - `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - - `docs/project_management/standards/PLANNING_SESSION_LOG_TEMPLATE.md` - - `docs/project_management/packs/sequencing.json` - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - - `docs/project_management/_archived/doctor_scopes/plan.md` (pre-existing stub) - - `docs/project_management/_archived/doctor_scopes/decision_register.md` (pre-existing stub) -- Additional repo context read (non-exhaustive, but all referenced by the spec/plan): - - `crates/shell/src/execution/platform/linux.rs` - - `crates/shell/src/execution/platform/macos.rs` - - `crates/shell/src/execution/platform/windows.rs` - - `crates/shell/src/execution/cli.rs` - - `crates/shell/src/execution/invocation/plan.rs` - - `crates/shell/src/execution/routing/dispatch/world_ops.rs` - - `crates/world-agent/src/lib.rs` - - `crates/agent-api-client/src/lib.rs` - - `crates/agent-api-types/src/lib.rs` - - `docs/COMMANDS.md` - - `docs/WORLD.md` - - `docs/USAGE.md` -- Commands run (planning/research): - - `rg -n "doctor_scopes" -S .` - - `rg -n "substrate world doctor" docs/WORLD.md` - - `git rev-parse HEAD` - - `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` - - `make planning-lint FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` - -## END — 2026-01-08T23:18:17Z — planning — Planning Pack authoring -- Summary of changes (exhaustive): - - Expanded the `doctor_scopes` Planning Pack into a full triad-executable plan (DS0) with cross-platform integration structure. - - Finalized and extended the decision register with explicit A/B decisions, including API endpoint shape, exit codes, and no-side-effects posture. - - Updated ADR-0007 status and aligned its contract text to the decision register and exit code taxonomy. - - Added unambiguous specs, tasks, kickoff prompts, integration map, manual testing playbook, and smoke scripts. -- Files created/modified: - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - - `docs/project_management/_archived/doctor_scopes/plan.md` - - `docs/project_management/_archived/doctor_scopes/tasks.json` - - `docs/project_management/_archived/doctor_scopes/session_log.md` - - `docs/project_management/_archived/doctor_scopes/decision_register.md` - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - - `docs/project_management/_archived/doctor_scopes/integration_map.md` - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - - `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` - - `docs/project_management/_archived/doctor_scopes/quality_gate_report.md` - - `docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md` - - `docs/project_management/_archived/doctor_scopes/kickoff_prompts/` - - `docs/project_management/_archived/doctor_scopes/smoke/` -- Rubric checks run (with results): - - `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` → `PASS` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → `PASS` - - `make planning-lint FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → `PASS` -- Sequencing alignment: - - `docs/project_management/packs/sequencing.json` reviewed: `YES` - - Changes required: `NO` (sequencing updated to reference `DS0-spec.md`) -- Blockers: - - `NONE` -- Next steps: - - Run the planning lint and quality gate review and update `docs/project_management/_archived/doctor_scopes/quality_gate_report.md`. - - Run `F0-exec-preflight` and update `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md`. - -## START — 2026-01-09T02:00:15Z — remediation — Planning Quality Gate remediation -- Scope: remediate Planning Pack defects from `docs/project_management/_archived/doctor_scopes/quality_gate_report.md` without writing production code. -- Findings addressed: - - Finding 003 (Decision register template) - - Finding 004 (Decision ↔ task traceability in `tasks.json`) - - Finding 005 (World doctor exit code discriminator) - - Finding 006 (Windows playbook world doctor assertions) -- Files targeted: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` - - `docs/project_management/_archived/doctor_scopes/tasks.json` - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - -## END — 2026-01-09T02:00:23Z — remediation — Planning Quality Gate remediation -- Summary: - - Updated the decision register to the required template and added explicit follow-up task mappings. - - Added DR id traceability in `tasks.json` references for `DS0-code` and `DS0-test`. - - Defined the exit `3` vs `4` discriminator for `substrate world doctor` and aligned ADR/spec JSON status contracts. - - Strengthened the Windows manual playbook world doctor command to assert `unsupported` contract fields and exit code `4`. -- Files changed: - - `docs/project_management/_archived/doctor_scopes/decision_register.md` - - `docs/project_management/_archived/doctor_scopes/tasks.json` - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` -- Commands run (with exit codes): - - `git checkout -b feat/doctor-scopes` → exit `0` - - `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` → exit `0` - - `make planning-lint FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → exit `0` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → exit `0` - - `jq -e . "docs/project_management/_archived/doctor_scopes/tasks.json" >/dev/null` → exit `0` - - `jq -e . docs/project_management/packs/sequencing.json >/dev/null` → exit `0` - -## START — 2026-01-09T02:30:36Z — ops — F0-exec-preflight -- Feature: `docs/project_management/_archived/doctor_scopes/` -- Branch: `feat/doctor-scopes` -- Goal: Run the execution preflight gate and produce a concrete ACCEPT/REVISE recommendation before any DS0 triad work begins. -- Inputs reviewed (required set): - - `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` - - `docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md` - - `docs/project_management/_archived/doctor_scopes/plan.md` - - `docs/project_management/_archived/doctor_scopes/tasks.json` - - `docs/project_management/_archived/doctor_scopes/session_log.md` - - `docs/project_management/_archived/doctor_scopes/DS0-spec.md` - - `docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md` - - `docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh` - - `docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh` - - `docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1` -- Commands run: - - `make triad-orch-ensure FEATURE_DIR="docs/project_management/_archived/doctor_scopes"` → exit `0` - -## END — 2026-01-09T02:34:58Z — ops — F0-exec-preflight -- Recommendation: `ACCEPT` (triads may begin once the planning quality gate is also `ACCEPT`) -- Evidence captured: - - `docs/project_management/_archived/doctor_scopes/execution_preflight_report.md` updated with platform validation, smoke/manual parity notes, and CI dispatch readiness checks. - - `feat/doctor-scopes` pushed to `origin` (required for CI dispatch): `origin/feat/doctor-scopes`. - - GitHub Actions runners confirmed online (via `gh api repos/atomize-hq/substrate/actions/runners`): - - Linux: runner labeled `linux-host` - - macOS: runner labeled `macOS` -- Required fixes before starting DS0: - - Update `docs/project_management/_archived/doctor_scopes/quality_gate_report.md` to `RECOMMENDATION: ACCEPT` (must not be “FLAG FOR HUMAN REVIEW”). - -## START — 2026-01-09T02:45:58Z — code — DS0-code -- Worktree: `wt/dsc-ds0-code` -- Branch: `dsc-ds0-code` -- Orchestration branch: `feat/doctor-scopes` -- Dispatch: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/doctor_scopes" SLICE_ID="DS0" LAUNCH_CODEX=1` - -## START — 2026-01-09T02:45:58Z — test — DS0-test -- Worktree: `wt/dsc-ds0-test` -- Branch: `dsc-ds0-test` -- Orchestration branch: `feat/doctor-scopes` -- Dispatch: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/doctor_scopes" SLICE_ID="DS0" LAUNCH_CODEX=1` - -## END — 2026-01-09T03:05:41Z — test — DS0-test -- Worktree: `wt/dsc-ds0-test` -- Branch: `dsc-ds0-test` -- HEAD: `59358f57331b153a669b186378fa175a0b7b16e6` -- Summary: - - Added DS0 contract tests for `substrate host doctor` and the DS0 host/world doctor envelopes. - - Updated shell integration fixtures and the world-agent socket stub to support `/v1/doctor/world`. -- Commands run (with exit codes): - - `cargo fmt` → exit `0` - - `cargo test -p agent-api-types` → exit `0` - - `cargo test -p substrate-shell --test doctor_scopes_ds0 --test shim_health --test shim_doctor --test world_verify --test socket_activation --test world_overlayfs_enumeration_wo0` → exit `0` - - `make triad-task-finish TASK_ID="DS0-test"` → exit `0` - -## END — 2026-01-09T03:19:48Z — code — DS0-code -- Worktree: `wt/dsc-ds0-code` -- Branch: `dsc-ds0-code` -- HEAD: `fcc3d0a92e066aaf36bfb94d41aca44b4aa67eff` -- Summary: - - Added `substrate host doctor` CLI surface and routing. - - Added world-agent `GET /v1/doctor/world` endpoint and corresponding client/types plumbing. - - Updated `substrate world doctor` to emit the DS0 v1 envelope and query the world-agent endpoint; updated `world_verify` to parse the new envelope. -- Commands run (with exit codes): - - `make triad-task-finish TASK_ID="DS0-code"` (runs `cargo fmt` + `cargo clippy --workspace --all-targets -- -D warnings`) → exit `0` - -## START — 2026-01-09T17:27:54Z — integration — DS0-integ-windows -- Worktree: `wt/dsc-ds0-integ-windows` -- Branch: `dsc-ds0-integ-windows` -- Orchestration branch: `feat/doctor-scopes` -- Scope: Windows CI parity only (compile/lint/test parity; no behavioral smoke required). - -## END — 2026-01-09T18:11:22Z — integration — DS0-integ-windows -- Worktree: `wt/dsc-ds0-integ-windows` -- Branch: `dsc-ds0-integ-windows` -- HEAD: `2493a81bc6cb2da172a7b6359480a435482e9341` -- Summary: - - Ensured `make ci-compile-parity` works even when `.github/workflows/ci-compile-parity.yml` is not registered on the default branch by falling back to `.github/workflows/ci-testing.yml` and using a `checkout_ref` prefix convention to run compile-parity-only steps. -- CI compile parity: - - RUN_ID: `20860950714` - - RUN_URL: `https://github.com/atomize-hq/substrate/actions/runs/20860950714` - - Result: `success` (`ubuntu-24.04`, `macos-14`, `windows-2022`) -- Commands run (with exit codes): - - `make ci-compile-parity CI_WORKFLOW_REF="feat/doctor-scopes" CI_REMOTE=origin CI_CLEANUP=1` → exit `0` - - `make triad-task-finish TASK_ID="DS0-integ-windows"` → exit `0` - -## START — 2026-01-09T18:04:55Z — integration — DS0-integ -- Worktree: `wt/dsc-ds0-integ` -- Branch: `dsc-ds0-integ` -- Orchestration branch: `feat/doctor-scopes` -- Scope: merge DS0 platform-fix branches, confirm local gates, re-run CI compile parity + linux/macos behavior smoke, and complete the DS0 closeout gate report. - -## END — 2026-01-09T18:34:04Z — integration — DS0-integ -- Worktree: `wt/dsc-ds0-integ` -- Branch: `dsc-ds0-integ` -- HEAD: `ef90a5b0527c85310229ca4ec1fda580671ee039` -- Summary: - - Merged `DS0-integ-core` plus platform fixes into `dsc-ds0-integ`; added Linux + macOS compatibility fallbacks for legacy world-agents missing `GET /v1/doctor/world`. - - Confirmed local gates: `make integ-checks` → exit `0`. - - Re-ran CI compile parity: RUN_ID `20861321448` (`success`) — `https://github.com/atomize-hq/substrate/actions/runs/20861321448`. - - Re-ran behavior smoke: - - Linux: RUN_ID `20861533380` (`success`) — `https://github.com/atomize-hq/substrate/actions/runs/20861533380` - - macOS: RUN_ID `20861578627` (`success`) — `https://github.com/atomize-hq/substrate/actions/runs/20861578627` - - Finished integration task and merged back to orchestration: - - `make triad-task-finish TASK_ID="DS0-integ"` → exit `0` - - Merge commit on `feat/doctor-scopes`: `7cc874f` diff --git a/docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh b/docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh deleted file mode 100755 index 21c9ea349..000000000 --- a/docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh +++ /dev/null @@ -1,67 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -if [[ "$(uname -s)" != "Linux" ]]; then - echo "SKIP: doctor_scopes smoke (not Linux)" - exit 0 -fi - -SUBSTRATE_BIN="${SUBSTRATE_BIN:-substrate}" -JQ_BIN="${JQ_BIN:-jq}" -MKTEMP_BIN="${MKTEMP_BIN:-mktemp}" - -need_cmd() { command -v "$1" >/dev/null 2>&1 || { echo "FAIL: missing $1" >&2; exit 3; }; } -need_cmd "$SUBSTRATE_BIN" -need_cmd "$JQ_BIN" -need_cmd "$MKTEMP_BIN" - -assert_jq() { - local name="$1" - local input="$2" - local filter="$3" - if ! printf '%s' "$input" | "$JQ_BIN" -e "$filter" >/dev/null; then - echo "FAIL: ${name} (jq assertion failed)" >&2 - printf '%s\n' "$input" >&2 - exit 1 - fi -} - -tmp="$("$MKTEMP_BIN" -d)" -trap 'rm -rf "$tmp"' EXIT -cd "$tmp" - -# Require world-enabled behavior for this feature’s Linux smoke. -host_doctor="$($SUBSTRATE_BIN host doctor --json)" -assert_jq "host doctor" "$host_doctor" ' - .schema_version == 1 and - .platform == "linux" and - .world_enabled == true and - .ok == true and - .host.platform == "linux" and - .host.ok == true and - (.host.world_fs_mode | IN("writable","read_only")) and - (.host.world_fs_isolation | IN("workspace","full")) and - (.host.world_socket.socket_path | type == "string") and - (.host.world_socket.socket_exists == true) and - (.host.world_socket.probe_ok == true) -' - -world_doctor="$($SUBSTRATE_BIN world doctor --json)" -assert_jq "world doctor" "$world_doctor" ' - .schema_version == 1 and - .platform == "linux" and - .world_enabled == true and - .ok == true and - .host.ok == true and - (.world.schema_version | IN(1,2)) and - .world.ok == true and - .world.landlock.supported == true and - (.world.landlock.abi | type == "number") and - .world.world_fs_strategy.primary == "overlay" and - .world.world_fs_strategy.fallback == "fuse" and - .world.world_fs_strategy.probe.id == "enumeration_v1" and - .world.world_fs_strategy.probe.probe_file == ".substrate_enum_probe" and - .world.world_fs_strategy.probe.result == "pass" -' - -echo "OK: doctor_scopes smoke (linux)" diff --git a/docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh b/docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh deleted file mode 100644 index 1769ae7c0..000000000 --- a/docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh +++ /dev/null @@ -1,52 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -if [[ "$(uname -s)" != "Darwin" ]]; then - echo "SKIP: doctor_scopes smoke (not macOS)" - exit 0 -fi - -SUBSTRATE_BIN="${SUBSTRATE_BIN:-substrate}" -JQ_BIN="${JQ_BIN:-jq}" -MKTEMP_BIN="${MKTEMP_BIN:-mktemp}" - -need_cmd() { command -v "$1" >/dev/null 2>&1 || { echo "FAIL: missing $1" >&2; exit 3; }; } -need_cmd "$SUBSTRATE_BIN" -need_cmd "$JQ_BIN" -need_cmd "$MKTEMP_BIN" - -tmp="$("$MKTEMP_BIN" -d)" -trap 'rm -rf "$tmp"' EXIT -cd "$tmp" - -$SUBSTRATE_BIN host doctor --json | $JQ_BIN -e ' - .schema_version == 1 and - .platform == "macos" and - .world_enabled == true and - .ok == true and - .host.platform == "macos" and - .host.ok == true and - (.host.world_fs_mode | IN("writable","read_only")) and - (.host.world_fs_isolation | IN("workspace","full")) and - .host.lima.installed == true and - .host.lima.virtualization == true and - .host.lima.vm_status == "Running" and - .host.lima.service_active == true and - .host.lima.agent_caps_ok == true -' >/dev/null - -$SUBSTRATE_BIN world doctor --json | $JQ_BIN -e ' - .schema_version == 1 and - .platform == "macos" and - .world_enabled == true and - .ok == true and - .host.ok == true and - .world.schema_version == 1 and - .world.ok == true and - .world.landlock.supported == true and - (.world.landlock.abi | type == "number") and - .world.world_fs_strategy.probe.result == "pass" -' >/dev/null - -echo "OK: doctor_scopes smoke (macos)" - diff --git a/docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1 b/docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1 deleted file mode 100644 index 6c8424b15..000000000 --- a/docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1 +++ /dev/null @@ -1,11 +0,0 @@ -$ErrorActionPreference = "Stop" - -if ($env:OS -ne "Windows_NT") { - Write-Host "SKIP: doctor_scopes smoke (not Windows)" - exit 0 -} - -# DS0 declares Windows as CI-parity-only (no behavioral smoke required). -Write-Host "SKIP: doctor_scopes smoke (Windows is CI-parity-only for this feature)" -exit 0 - diff --git a/docs/project_management/_archived/doctor_scopes/tasks.json b/docs/project_management/_archived/doctor_scopes/tasks.json deleted file mode 100644 index 27083849c..000000000 --- a/docs/project_management/_archived/doctor_scopes/tasks.json +++ /dev/null @@ -1,416 +0,0 @@ -{ - "meta": { - "feature": "doctor_scopes", - "cross_platform": true, - "schema_version": 3, - "execution_gates": true, - "behavior_platforms_required": [ - "linux", - "macos" - ], - "ci_parity_platforms_required": [ - "linux", - "macos", - "windows" - ], - "automation": { - "enabled": true, - "orchestration_branch": "feat/doctor-scopes" - }, - "notes": "DS0 is a cross-platform CLI/API contract change. Behavioral smoke is required on Linux+macOS; Windows is CI parity only (no smoke required)." - }, - "tasks": [ - { - "id": "F0-exec-preflight", - "name": "Execution preflight gate", - "type": "ops", - "phase": "Feature Gates", - "status": "completed", - "description": "Run the execution preflight gate and fill execution_preflight_report.md before starting DS0.", - "references": [ - "docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md", - "docs/project_management/_archived/doctor_scopes/execution_preflight_report.md", - "docs/project_management/_archived/doctor_scopes/plan.md", - "docs/project_management/_archived/doctor_scopes/tasks.json", - "docs/project_management/_archived/doctor_scopes/session_log.md", - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md", - "docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1" - ], - "acceptance_criteria": [ - "execution_preflight_report.md contains a concrete recommendation (ACCEPT or REVISE)", - "If the recommendation is REVISE, DS0 work does not start until the listed issues are resolved" - ], - "start_checklist": [ - "Run: make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\"", - "Set F0-exec-preflight status to in_progress in tasks.json; add START entry to session_log.md; commit docs" - ], - "end_checklist": [ - "Complete docs/project_management/_archived/doctor_scopes/execution_preflight_report.md", - "Set F0-exec-preflight status to completed in tasks.json; add END entry to session_log.md; commit docs" - ], - "worktree": null, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/F0-exec-preflight.md", - "depends_on": [], - "concurrent_with": [] - }, - { - "id": "DS0-code", - "name": "Doctor scope split (code)", - "type": "code", - "phase": "DS0", - "status": "completed", - "description": "Implement DS0 spec (production code only): add `substrate host doctor`, implement world-agent world doctor endpoint, and update `substrate world doctor` to consume it.", - "references": [ - "docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md", - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/decision_register.md (DR-0001, DR-0002, DR-0003, DR-0005, DR-0006, DR-0007, DR-0008, DR-0009, DR-0010, DR-0011, DR-0012)", - "docs/project_management/_archived/doctor_scopes/integration_map.md" - ], - "acceptance_criteria": [ - "Meets all acceptance criteria in docs/project_management/_archived/doctor_scopes/DS0-spec.md" - ], - "start_checklist": [ - "Read ADR/spec/decision register/integration map", - "Do not edit planning docs inside the worktree.", - "Set DS0-code and DS0-test status to in_progress in tasks.json; add START entries to session_log.md; commit docs", - "Run: make triad-task-start-pair FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" SLICE_ID=\"DS0\"" - ], - "end_checklist": [ - "cargo fmt", - "cargo clippy --workspace --all-targets -- -D warnings", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-code\"", - "On the orchestration branch: set DS0-code status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-code", - "git_branch": "dsc-ds0-code", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "integration_task": "DS0-integ-core", - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-code.md", - "depends_on": [ - "F0-exec-preflight" - ], - "concurrent_with": [ - "DS0-test" - ] - }, - { - "id": "DS0-test", - "name": "Doctor scope split (test)", - "type": "test", - "phase": "DS0", - "status": "completed", - "description": "Implement DS0 spec tests only: JSON schema tests, CLI wiring tests, and agent-api-types schema round-trip tests.", - "references": [ - "docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md", - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/decision_register.md (DR-0001, DR-0002, DR-0003, DR-0005, DR-0006, DR-0007, DR-0008, DR-0010, DR-0011, DR-0012)", - "docs/project_management/_archived/doctor_scopes/integration_map.md" - ], - "acceptance_criteria": [ - "Tests enforce DS0 acceptance criteria (schema, exit codes, and key fields)" - ], - "start_checklist": [ - "Read ADR/spec/decision register/integration map", - "Do not edit planning docs inside the worktree.", - "Set DS0-code and DS0-test status to in_progress in tasks.json; add START entries to session_log.md; commit docs", - "Run: make triad-task-start-pair FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" SLICE_ID=\"DS0\"" - ], - "end_checklist": [ - "cargo fmt", - "Run the targeted tests you add/touch", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-test\"", - "On the orchestration branch: set DS0-test status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-test", - "git_branch": "dsc-ds0-test", - "required_make_targets": [ - "triad-test-checks" - ], - "merge_to_orchestration": false, - "integration_task": "DS0-integ-core", - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-test.md", - "depends_on": [ - "F0-exec-preflight" - ], - "concurrent_with": [ - "DS0-code" - ] - }, - { - "id": "DS0-integ-core", - "name": "Integration core: merge + local gates + dispatch smoke/parity", - "type": "integration", - "phase": "DS0", - "status": "completed", - "description": "Merge DS0 code+test branches, make local integration gates green, run CI compile parity preflight, then dispatch cross-platform Feature Smoke for behavior platforms to determine required platform-fix tasks.", - "references": [ - "docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md", - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md", - "docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1" - ], - "acceptance_criteria": [ - "Local integration gates are green (fmt, clippy -D warnings, relevant tests, integ-checks)", - "CI compile parity is dispatched and green at this commit", - "Feature Smoke is dispatched for behavior platforms and the RUN_ID/RUN_URL are recorded in session_log.md" - ], - "start_checklist": [ - "Do not edit planning docs inside the worktree.", - "Set DS0-integ-core status to in_progress in tasks.json; add START entry to session_log.md; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" TASK_ID=\"DS0-integ-core\"" - ], - "end_checklist": [ - "Merge DS0-code + DS0-test branches; resolve conflicts (spec wins)", - "cargo fmt", - "cargo clippy --workspace --all-targets -- -D warnings", - "Run relevant tests", - "make integ-checks", - "Dispatch CI compile parity: make ci-compile-parity CI_WORKFLOW_REF=\"feat/doctor-scopes\" CI_REMOTE=origin CI_CLEANUP=1", - "Dispatch Feature Smoke for behavior platforms (linux,macos): make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/doctor-scopes\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1 (repeat for PLATFORM=macos)", - "Record CI run ids/URLs and smoke run ids/URLs in session_log.md END entry for this task", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-integ-core\"", - "On the orchestration branch: set DS0-integ-core status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-integ-core", - "git_branch": "dsc-ds0-integ-core", - "required_make_targets": [ - "integ-checks" - ], - "merge_to_orchestration": false, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-core.md", - "depends_on": [ - "DS0-code", - "DS0-test" - ], - "concurrent_with": [] - }, - { - "id": "DS0-integ-linux", - "name": "Integration platform-fix: linux (behavior + CI parity)", - "type": "integration", - "phase": "DS0", - "status": "completed", - "description": "Linux platform-fix integration task. Runs the feature-local Linux smoke script via CI and fixes any Linux-only issues surfaced by smoke.", - "references": [ - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md", - "docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh" - ], - "acceptance_criteria": [ - "Linux Feature Smoke is green for this slice" - ], - "start_checklist": [ - "Do not edit planning docs inside the worktree.", - "Set DS0-integ-linux status to in_progress in tasks.json; add START entry to session_log.md; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" TASK_ID=\"DS0-integ-linux\"" - ], - "end_checklist": [ - "Dispatch Linux Feature Smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/doctor-scopes\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "If the Linux smoke run is not green, implement fixes in this worktree and repeat the smoke dispatch until it is green", - "Once Linux smoke is green: record RUN_ID/RUN_URL in session_log.md END entry for this task", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-integ-linux\"", - "On the orchestration branch: set DS0-integ-linux status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-integ-linux", - "git_branch": "dsc-ds0-integ-linux", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "integration_task": "DS0-integ-linux", - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-linux.md", - "depends_on": [ - "DS0-integ-core" - ], - "concurrent_with": [], - "platform": "linux", - "runner": "github-actions", - "workflow": ".github/workflows/feature-smoke.yml" - }, - { - "id": "DS0-integ-macos", - "name": "Integration platform-fix: macos (behavior + CI parity)", - "type": "integration", - "phase": "DS0", - "status": "completed", - "description": "macOS platform-fix integration task. Runs the feature-local macOS smoke script via CI and fixes any macOS-only issues surfaced by smoke.", - "references": [ - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md", - "docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh" - ], - "acceptance_criteria": [ - "macOS Feature Smoke is green for this slice" - ], - "start_checklist": [ - "Do not edit planning docs inside the worktree.", - "Set DS0-integ-macos status to in_progress in tasks.json; add START entry to session_log.md; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" TASK_ID=\"DS0-integ-macos\"" - ], - "end_checklist": [ - "Dispatch macOS Feature Smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/doctor-scopes\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "If the macOS smoke run is not green, implement fixes in this worktree and repeat the smoke dispatch until it is green", - "Once macOS smoke is green: record RUN_ID/RUN_URL in session_log.md END entry for this task", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-integ-macos\"", - "On the orchestration branch: set DS0-integ-macos status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-integ-macos", - "git_branch": "dsc-ds0-integ-macos", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "integration_task": "DS0-integ-macos", - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-macos.md", - "depends_on": [ - "DS0-integ-core" - ], - "concurrent_with": [], - "platform": "macos", - "runner": "github-actions", - "workflow": ".github/workflows/feature-smoke.yml" - }, - { - "id": "DS0-integ-windows", - "name": "Integration platform-fix: windows (CI parity only)", - "type": "integration", - "phase": "DS0", - "status": "completed", - "description": "Windows CI parity fix task (compile/test/lint only; no behavioral smoke required for this feature on Windows).", - "references": [ - "docs/project_management/_archived/doctor_scopes/DS0-spec.md" - ], - "acceptance_criteria": [ - "Windows CI compile parity is green for this slice (no behavioral smoke required)" - ], - "start_checklist": [ - "Do not edit planning docs inside the worktree.", - "Set DS0-integ-windows status to in_progress in tasks.json; add START entry to session_log.md; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" TASK_ID=\"DS0-integ-windows\"" - ], - "end_checklist": [ - "Dispatch CI parity via: make ci-compile-parity CI_WORKFLOW_REF=\"feat/doctor-scopes\" CI_REMOTE=origin CI_CLEANUP=1", - "If CI parity is not green, implement fixes in this worktree and repeat the CI parity dispatch until it is green", - "Once CI parity is green: record RUN_ID/RUN_URL in session_log.md END entry for this task", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-integ-windows\"", - "On the orchestration branch: set DS0-integ-windows status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-integ-windows", - "git_branch": "dsc-ds0-integ-windows", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "integration_task": "DS0-integ-windows", - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ-windows.md", - "depends_on": [ - "DS0-integ-core" - ], - "concurrent_with": [], - "platform": "windows", - "runner": "github-actions", - "workflow": ".github/workflows/ci-compile-parity.yml" - }, - { - "id": "DS0-integ", - "name": "Integration final: merge platform fixes + confirm cross-platform green", - "type": "integration", - "phase": "DS0", - "status": "completed", - "description": "Final integration: merge any platform-fix branches, ensure local gates are green, re-run behavioral smoke (linux+macos) and CI parity, then fill the DS0 closeout report.", - "references": [ - "docs/project_management/adrs/implemented/ADR-0007-host-and-world-doctor-scopes.md", - "docs/project_management/_archived/doctor_scopes/DS0-spec.md", - "docs/project_management/_archived/doctor_scopes/manual_testing_playbook.md", - "docs/project_management/_archived/doctor_scopes/smoke/linux-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/macos-smoke.sh", - "docs/project_management/_archived/doctor_scopes/smoke/windows-smoke.ps1", - "docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md" - ], - "acceptance_criteria": [ - "All required platforms are green and the slice matches DS0-spec" - ], - "start_checklist": [ - "Do not edit planning docs inside the worktree.", - "Set DS0-integ status to in_progress in tasks.json; add START entry to session_log.md; commit docs", - "Run: make triad-task-start-integ-final FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" SLICE_ID=\"DS0\" LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge all DS0 platform-fix branches (DS0-integ-linux, DS0-integ-macos, DS0-integ-windows) into this worktree and resolve conflicts (if a task made no changes, record 'NO CHANGES' in the DS0-closeout_report.md platform-fix section)", - "cargo fmt", - "cargo clippy --workspace --all-targets -- -D warnings", - "Run relevant tests", - "make integ-checks", - "Re-run CI compile parity: make ci-compile-parity CI_WORKFLOW_REF=\"feat/doctor-scopes\" CI_REMOTE=origin CI_CLEANUP=1", - "Re-run behavioral smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/doctor-scopes\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "Re-run behavioral smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/doctor-scopes\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "Complete docs/project_management/_archived/doctor_scopes/DS0-closeout_report.md", - "From inside the worktree: make triad-task-finish TASK_ID=\"DS0-integ\"", - "On the orchestration branch: set DS0-integ status to completed in tasks.json; add END entry to session_log.md; commit docs", - "Do not delete the worktree (feature cleanup removes worktrees at feature end)" - ], - "worktree": "wt/dsc-ds0-integ", - "git_branch": "dsc-ds0-integ", - "required_make_targets": [ - "integ-checks" - ], - "merge_to_orchestration": true, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/DS0-integ.md", - "depends_on": [ - "DS0-integ-core", - "DS0-integ-linux", - "DS0-integ-macos", - "DS0-integ-windows" - ], - "concurrent_with": [] - }, - { - "id": "FZ-feature-cleanup", - "name": "Feature cleanup: remove retained worktrees", - "type": "ops", - "phase": "Feature Cleanup", - "status": "pending", - "description": "Remove retained task worktrees for this feature and optionally prune task branches using the triad automation registry.", - "references": [ - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md" - ], - "acceptance_criteria": [ - "triad-feature-cleanup completes and prints a summary block", - "session_log.md END entry for this task includes the cleanup summary block" - ], - "start_checklist": [ - "Verify orchestration worktree is clean and all tasks are completed", - "Dry-run: make triad-feature-cleanup FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" DRY_RUN=1 REMOVE_WORKTREES=1 PRUNE_LOCAL=1" - ], - "end_checklist": [ - "Run: make triad-feature-cleanup FEATURE_DIR=\"docs/project_management/_archived/doctor_scopes\" REMOVE_WORKTREES=1 PRUNE_LOCAL=1", - "Paste the stdout summary block into the session_log.md END entry for this task", - "Set FZ-feature-cleanup status to completed in tasks.json; add END entry to session_log.md; commit docs" - ], - "worktree": null, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/doctor_scopes/kickoff_prompts/FZ-feature-cleanup.md", - "depends_on": [ - "DS0-integ" - ], - "concurrent_with": [] - } - ] -} diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md deleted file mode 100644 index 40434aae6..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md +++ /dev/null @@ -1,147 +0,0 @@ -# Slice Closeout Gate Report — env_var_taxonomy_and_override_split / EV0 - -Date (UTC): 2026-01-05T14:36:34Z - -Standards: -- `docs/project_management/standards/SLICE_CLOSEOUT_GATE_STANDARD.md` -- `docs/project_management/standards/EXECUTIVE_SUMMARY_STANDARD.md` - -Feature directory: -- `docs/project_management/_archived/env_var_taxonomy_and_override_split/` - -Slice spec: -- `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - -## Behavior Delta (Existing → New → Why) - -- Existing behavior: config-shaped legacy `SUBSTRATE_*` values could be treated as operator override inputs in effective config resolution. -- New behavior: effective config resolution consults only `SUBSTRATE_OVERRIDE_*` for env override inputs; config-shaped `SUBSTRATE_*` values are exported state only. -- Why: prevent “stale exports” from bypassing the resolver and make env inputs vs exported state unambiguous across platforms. -- Links: - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - -## Spec Parity (No Drift) - -- [x] Acceptance criteria satisfied -- [x] Any spec changes during the slice are recorded (with rationale) (none during execution) - -## Checks Run (Evidence) - -- `make integ-checks`: pass - - Includes: `cargo fmt`, `cargo clippy --workspace --all-targets -- -D warnings`, `cargo check --workspace --all-targets`, `cargo test --workspace --all-targets` - - Worktree: `wt/ev0-override-split-integ` - - Final merge commit: `0da831b0bc9a6ec71ed0f8d8476cf18e82098b63` -- `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1`: pass (run id `20718597240`) - -## Repo-Wide Grep/Audit (Required Evidence) - -This slice requires an explicit audit to ensure no commands bypass effective config resolution by treating config-shaped legacy `SUBSTRATE_*` values as behavior-changing inputs. - -Commands run (verbatim): -- `rg -n "SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)" -S crates src scripts` -- `rg -n "env::var(_os)?\\(\"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\"\\)" -S crates` - -Summary: -- Broad scan: `471` matching lines across `69` files (pattern also matches non-scope `SUBSTRATE_WORLD_*` like `SUBSTRATE_WORLD_SOCKET`, `SUBSTRATE_WORLD_ID`, `SUBSTRATE_WORLD_FS_MODE`, and `SUBSTRATE_WORLD_DEPS_*`) -- Direct Rust `env::var` scan: `48` matching lines across `11` files (includes test modules outside `crates/*/tests/`) - -Findings (must be exhaustive; list each hit and disposition): -- Fixed (rewired to effective config / `SUBSTRATE_OVERRIDE_*`): - - None in final integ pass (all behavior-affecting inputs already consult effective config / `SUBSTRATE_OVERRIDE_*` per spec). -- Derived/exported-state consumption only (value set earlier in-process from effective config): - - `crates/broker/src/mode.rs` - - `crates/replay/src/replay/executor.rs` - - `crates/replay/src/replay/helpers.rs` - - `crates/replay/src/state.rs` - - `crates/shell/src/builtins/world_deps/guest.rs` - - `crates/shell/src/builtins/world_deps/runner.rs` - - `crates/shell/src/builtins/world_deps/state.rs` - - `crates/shell/src/builtins/world_enable/runner/helper_script.rs` - - `crates/shell/src/builtins/world_enable/runner/manager_env.rs` - - `crates/shell/src/builtins/world_enable/runner/paths.rs` - - `crates/shell/src/builtins/world_enable/runner.rs` - - `crates/shell/src/builtins/world_enable/runner/verify.rs` - - `crates/shell/src/execution/env_scripts.rs` - - `crates/shell/src/execution/invocation/plan.rs` - - `crates/shell/src/execution/platform/mod.rs` - - `crates/shell/src/execution/routing/dispatch/exec.rs` - - `crates/shell/src/execution/routing/dispatch/world_ops.rs` - - `crates/shell/src/execution/routing/path_env.rs` - - `crates/shell/src/execution/routing/replay.rs` - - `crates/shell/src/execution/routing/world.rs` - - `crates/shell/src/execution/settings/mod.rs` - - `crates/shell/src/execution/settings/runtime.rs` - - `crates/shell/src/execution/socket_activation.rs` - - `crates/shim/src/context.rs` - - `crates/shim/src/exec/logging.rs` - - `crates/telemetry-lib/src/correlation.rs` - - `crates/trace/src/context.rs` - - `crates/trace/src/span.rs` - - `crates/world-agent/src/internal_exec.rs` - - `crates/world-agent/src/service.rs` - - `crates/world-mac-lima/src/lib.rs` - - `crates/world/src/exec.rs` - - `crates/world/src/guard.rs` - - `crates/world-windows-wsl/src/backend.rs` - - `scripts/linux/world-provision.sh` - - `scripts/mac/lima-warm.sh` - - `scripts/substrate/install-substrate.sh` - - `scripts/substrate/world-deps.yaml` - - `scripts/wsl/provision.sh` -- Test-only: - - `crates/replay/tests/integration.rs` - - `crates/replay/tests/planner_executor.rs` - - `crates/shell/src/execution/invocation/tests.rs` - - `crates/shell/src/execution/platform/macos.rs` (unit tests) - - `crates/shell/src/execution/platform_world/windows.rs` (unit tests) - - `crates/shell/src/execution/routing/builtin/tests.rs` - - `crates/shell/src/execution/routing/dispatch/tests/host_replay.rs` - - `crates/shell/src/execution/routing/dispatch/tests/linux_world.rs` - - `crates/shell/src/execution/settings/tests.rs` - - `crates/shell/tests/common.rs` - - `crates/shell/tests/config_set.rs` - - `crates/shell/tests/config_show.rs` - - `crates/shell/tests/ev0_override_split.rs` - - `crates/shell/tests/fail_closed_semantics.rs` - - `crates/shell/tests/logging.rs` - - `crates/shell/tests/policy_routing_semantics.rs` - - `crates/shell/tests/replay_world.rs` - - `crates/shell/tests/shell_behavior.rs` - - `crates/shell/tests/shell_env.rs` - - `crates/shell/tests/shim_health.rs` - - `crates/shell/tests/socket_activation.rs` - - `crates/shell/tests/support/mod.rs` - - `crates/shell/tests/world_deps_layering.rs` - - `crates/shell/tests/world_deps.rs` - - `crates/shell/tests/world_enable.rs` - - `crates/shell/tests/world_verify.rs` - - `crates/shim/tests/integration.rs` - - `crates/world-agent/tests/fs_mode.rs` - - `crates/world-agent/tests/full_isolation_nonpty.rs` - - `crates/world-agent/tests/full_isolation_pty.rs` - -## Cross-Platform Smoke - -Record run ids/URLs for required platforms: -- Linux: `https://github.com/atomize-hq/substrate/actions/runs/20718597240` (run id `20718597240`) -- macOS: `https://github.com/atomize-hq/substrate/actions/runs/20718597240` (run id `20718597240`) -- Windows: `https://github.com/atomize-hq/substrate/actions/runs/20718597240` (run id `20718597240`) - -Key coverage (must be validated by smoke): -- `policy.mode` (via `SUBSTRATE_POLICY_MODE`) -- `world.caged` (via `SUBSTRATE_CAGED`) -- `world.anchor_mode` (via `SUBSTRATE_ANCHOR_MODE`) - -If any platform-fix work was required: -- What failed: cross-platform smoke required follow-up fixes across runner/OS variants (Windows manager detection, deterministic env hashing for trace, CI smoke stability). -- What was changed: merged EV0 core + platform-fix integration branches into `ev-ev0-override-split-integ`, then FF merged into `feat/env_var_taxonomy_and_override_split` (final head `0da831b0bc9a6ec71ed0f8d8476cf18e82098b63`). -- Why the change is safe (guards, cfg, feature flags): fixes are platform-scoped or behavior-preserving (cfg-gated where applicable) and are covered by all-platform feature smoke run `20718597240`. - -## Smoke ↔ Manual Parity - -- [x] Smoke scripts run the same commands/workflows as the manual testing playbook (minimal viable subset) -- [x] Smoke scripts validate exit codes and key output - -Notes: -- Smoke validates the required minimum key set (`policy.mode`, `world.caged`, `world.anchor_mode`) and the “workspace wins over overrides” precedence rule on all platforms. diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md deleted file mode 100644 index 80974e34e..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md +++ /dev/null @@ -1,121 +0,0 @@ -# EV0 Spec — Override Split for Effective Config (ADR-0006) - -## Scope -This slice changes the effective-config resolver to use a dedicated override-input namespace: -- Override inputs: `SUBSTRATE_OVERRIDE_*` -- Exported state: `SUBSTRATE_*` (output-only for config resolution) - -This slice applies wherever `crates/shell/src/execution/config_model.rs` resolves effective config. - -## Non-Scope -- Backwards compatibility for legacy config-shaped `SUBSTRATE_*` override inputs. -- Changes to policy discovery or policy schema. -- Changes to world backend transports or shim tracing. - -## User Contract (Authoritative) -Authoritative contract: `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - -### Effective config precedence (workspace present) -When `` exists for `cwd`, the effective config precedence (highest to lowest) is: -1. CLI flags (subset of keys with CLI flags) -2. `/.substrate/workspace.yaml` -3. Environment variables `SUBSTRATE_OVERRIDE_*` (subset) -4. `$SUBSTRATE_HOME/config.yaml` (or built-in defaults) -5. Built-in defaults - -Observable requirement: -- When `/.substrate/workspace.yaml` exists, `SUBSTRATE_OVERRIDE_*` values do not change effective config values. - -### Effective config precedence (no workspace) -When no workspace exists for `cwd`, the effective config precedence (highest to lowest) is: -1. CLI flags (subset of keys with CLI flags) -2. Environment variables `SUBSTRATE_OVERRIDE_*` (subset) -3. `$SUBSTRATE_HOME/config.yaml` (or built-in defaults) -4. Built-in defaults - -Observable requirement: -- When no workspace exists, `SUBSTRATE_OVERRIDE_*` values override `$SUBSTRATE_HOME/config.yaml` for the supported subset of keys. - -### Override input mapping (supported subset) -The effective-config resolver MUST consult only the following override-input env vars: -- `SUBSTRATE_OVERRIDE_WORLD`: `"enabled" | "disabled"` -- `SUBSTRATE_OVERRIDE_ANCHOR_MODE`: `workspace | follow-cwd | custom` (parsed via `WorldRootMode::parse`) -- `SUBSTRATE_OVERRIDE_ANCHOR_PATH`: string (may be empty) -- `SUBSTRATE_OVERRIDE_CAGED`: boolean (`true|false|1|0|yes|no|on|off`) -- `SUBSTRATE_OVERRIDE_POLICY_MODE`: `disabled | observe | enforce` -- `SUBSTRATE_OVERRIDE_SYNC_AUTO_SYNC`: boolean -- `SUBSTRATE_OVERRIDE_SYNC_DIRECTION`: `from_world | from_host | both` -- `SUBSTRATE_OVERRIDE_SYNC_CONFLICT_POLICY`: `prefer_host | prefer_world | abort` -- `SUBSTRATE_OVERRIDE_SYNC_EXCLUDE`: comma-separated string list - -All other env vars are ignored by the effective-config resolver. - -### Exported state is output-only for config resolution -The effective-config resolver MUST NOT consult the following config-shaped exported-state env vars as override inputs: -- `SUBSTRATE_WORLD` -- `SUBSTRATE_WORLD_ENABLED` -- `SUBSTRATE_ANCHOR_MODE` -- `SUBSTRATE_ANCHOR_PATH` -- `SUBSTRATE_CAGED` -- `SUBSTRATE_POLICY_MODE` -- `SUBSTRATE_SYNC_AUTO_SYNC` -- `SUBSTRATE_SYNC_DIRECTION` -- `SUBSTRATE_SYNC_CONFLICT_POLICY` -- `SUBSTRATE_SYNC_EXCLUDE` - -### Exhaustive repo grep/audit (required) - -This slice is not considered complete until the implementation has performed an explicit repo-wide audit to ensure no commands bypass effective-config resolution by reading config-shaped `SUBSTRATE_*` values directly as *inputs*. - -Audit scope: -- All Rust crates and scripts that can affect runtime behavior: `crates/`, `src/`, `scripts/`, and test harnesses under `crates/*/tests/` (tests may intentionally set env vars). -- The audit MUST cover, at minimum, the exported-state variables listed above (including `SUBSTRATE_WORLD_ENABLED`) and any other config-shaped `SUBSTRATE_*` discovered while scanning. - -Required audit commands (run from repo root): -```bash -# Broad, fast scan (names only) -rg -n \"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\" -S crates src scripts - -# Direct env reads in Rust (inputs) -rg -n \"env::var(_os)?\\(\\\"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\\\"\\)\" -S crates -``` - -Audit required outcomes (fail the slice if violated): -- For each non-test hit that can affect behavior, the implementer MUST classify it as exactly one of: - 1) **Derived/exported state consumption** (allowed): the value is set by Substrate earlier in-process from effective config and is not used as a “user override input” (ex: trace metadata, replay env capture, world guard that consumes already-derived state). - 2) **Override input (not allowed under legacy names)**: the code is treating `SUBSTRATE_*` as an operator-provided override input. This MUST be fixed by switching to effective config and/or `SUBSTRATE_OVERRIDE_*` (per the ADR) so “stale exports” cannot change behavior. - 3) **Test-only** (allowed): confined to tests/harnesses and clearly test-scoped. -- Any pre-config-resolution behavioral gating MUST NOT consult legacy config-shaped `SUBSTRATE_*` values as inputs. If gating is required, it MUST consult CLI flags and/or the resolved effective config. -- Audit results MUST be recorded as evidence in `EV0-closeout_report.md` (summary + list of hits and classification). - -### Strict parsing -- If a supported `SUBSTRATE_OVERRIDE_*` variable is present with a non-empty value and parsing fails, the resolver MUST return a user/config error. -- Error messages MUST name the specific `SUBSTRATE_OVERRIDE_*` variable and list the allowed values/shape. - -### Exit codes -- Exit code taxonomy: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` -- `0`: success -- `1`: unexpected failure -- `2`: user/config error (invalid override values when parsed by a command that maps user errors to `2`) -- `3`: required dependency unavailable (playbook/smoke only) - -## Acceptance Criteria (Authoritative) -- `crates/shell/src/execution/config_model.rs` reads only `SUBSTRATE_OVERRIDE_*` for config-shaped override inputs. -- `crates/shell/src/execution/config_model.rs` does not read config-shaped `SUBSTRATE_*` exported-state variables as override inputs. -- Repo-wide grep/audit is completed and any non-test config-shaped `SUBSTRATE_*` input reads are eliminated or explicitly reclassified as derived/exported-state consumption (with evidence recorded in `EV0-closeout_report.md`). -- Errors for invalid override values mention the `SUBSTRATE_OVERRIDE_*` variable name and allowed values. -- Feature-local smoke scripts validate the override split on all required platforms: - - Linux: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh` - - macOS: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh` - - Windows: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1` - -## Validation Requirements - -### Tests (required) -- Add/update tests to lock the override split behavior: - - A `SUBSTRATE_POLICY_MODE=` exported-state value must not override config policy mode resolution. - - A `SUBSTRATE_OVERRIDE_POLICY_MODE=` override input must override config policy mode resolution when no workspace exists. - - A workspace config value must override any `SUBSTRATE_OVERRIDE_*` values. - -### Manual testing (required) -- Follow `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md`. diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md deleted file mode 100644 index 62072984b..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md +++ /dev/null @@ -1,107 +0,0 @@ -# Decision Register — Env Var Taxonomy + Override Split - -This decision register captures the A/B decisions referenced by `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`. - -### DR-0001 — Naming scheme for override inputs - -**Decision owner(s):** shell/config -**Date:** 2026-01-04 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`, `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - -**Problem / Context** -- `SUBSTRATE_*` variables are written by Substrate-owned scripts/runtime as stable exports (`$SUBSTRATE_HOME/env.sh`), and some of the same variable names are also consulted as override inputs by effective-config resolution. -- Dual-use makes exported state indistinguishable from intentional operator overrides. - -**Option A — `SUBSTRATE_OVERRIDE_*` for override inputs; keep `SUBSTRATE_*` as state** -- **Pros:** Minimal churn for existing state consumers; clear intent for overrides; preserves existing stable export scripts. -- **Cons:** Two namespaces exist; docs must clearly explain the split. -- **Cascading implications:** Config resolver must be updated to read `SUBSTRATE_OVERRIDE_*` and stop reading config-shaped `SUBSTRATE_*`. -- **Risks:** Operators accustomed to `SUBSTRATE_*` overrides must update workflows. -- **Unlocks:** Exported state can be safely present in the environment without silently overriding config. -- **Quick wins / low-hanging fruit:** Change is localized to the config resolver and docs. - -**Option B — `SUBSTRATE_STATE_*` for state; keep `SUBSTRATE_*` as override inputs** -- **Pros:** “State” is explicit; override inputs remain the shorter names. -- **Cons:** Large blast radius across crates/scripts/docs that read `SUBSTRATE_*` as state. -- **Cascading implications:** Requires renaming stable exports and any internal consumers. -- **Risks:** High migration cost; breaks installer/dev workflows. -- **Unlocks:** Explicit state namespace in the environment. -- **Quick wins / low-hanging fruit:** None; requires broad refactors. - -**Recommendation** -- **Selected:** Option A — `SUBSTRATE_OVERRIDE_*` for override inputs -- **Rationale (crisp):** It eliminates dual-use while minimizing cross-crate churn. - -**Follow-up tasks (explicit)** -- Implement in `EV0-code`: read `SUBSTRATE_OVERRIDE_*` env vars as override inputs; ignore config-shaped `SUBSTRATE_*` (task: `EV0-code`). -- Implement in `EV0-code`: perform an explicit repo-wide grep/audit to ensure no commands bypass effective config by reading config-shaped `SUBSTRATE_*` values as operator inputs; fix any hits found (task: `EV0-code`). -- Add tests for the split (task: `EV0-test`). -- Update operator docs and the canonical env-var catalog references (task: `EV0-integ-core` / `EV0-integ`). - -### DR-0002 — Scope of override variables - -**Decision owner(s):** shell/config -**Date:** 2026-01-04 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md`, `docs/ENVIRONMENT_VARIABLES.md` - -**Problem / Context** -- The repo contains both config-shaped inputs (keys that correspond to config schema) and non-config override-only controls (socket paths, test toggles, transport overrides). -- The override split is targeted at eliminating dual-use for config-shaped keys exported in `env.sh`. - -**Option A — Override vars exist only for config-shaped keys** -- **Pros:** Smallest surface area; maps 1:1 to config schema keys; avoids renaming non-config controls. -- **Cons:** Non-config override knobs remain under existing names and conventions. -- **Cascading implications:** The override catalog must explicitly list which keys are config-shaped override inputs. -- **Risks:** Some operators may expect every `SUBSTRATE_*` knob to have an override variant. -- **Unlocks:** Clear rule: `SUBSTRATE_OVERRIDE_*` is only for effective-config resolution. -- **Quick wins / low-hanging fruit:** Implement by updating only the config resolver and docs. - -**Option B — Provide override vars for all operator-intended overrides (including override-only knobs)** -- **Pros:** Consistent naming for all operator controls; reduces guesswork. -- **Cons:** Larger migration; more names to document; higher risk of churn. -- **Cascading implications:** Installer/scripts/backends may need updates to accept renamed env vars. -- **Risks:** Breaks existing workflows relying on current override-only env vars. -- **Unlocks:** Uniform override interface. -- **Quick wins / low-hanging fruit:** None; requires large catalog and broad changes. - -**Recommendation** -- **Selected:** Option A — override vars only for config-shaped keys -- **Rationale (crisp):** It solves the dual-use footgun with minimal surface area and minimal churn. - -**Follow-up tasks (explicit)** -- Ensure `docs/ENVIRONMENT_VARIABLES.md` lists the reserved `SUBSTRATE_OVERRIDE_*` keys for config-shaped overrides (task: `EV0-integ`). - -### DR-0003 — Canonical environment variable catalog location - -**Decision owner(s):** docs/config -**Date:** 2026-01-04 -**Status:** Accepted -**Related docs:** `docs/ENVIRONMENT_VARIABLES.md`, `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - -**Problem / Context** -- Env var references are scattered across docs and code; drift makes operator guidance unreliable. - -**Option A — Canonical catalog under `docs/ENVIRONMENT_VARIABLES.md`** -- **Pros:** Single source of truth; easy discovery; can be referenced from `docs/CONFIGURATION.md` and ADRs. -- **Cons:** Requires careful curation so internal-only variables are labeled and not treated as stable operator interface. -- **Cascading implications:** Changes to env vars must update this file. -- **Risks:** If not maintained, it becomes stale and misleading. -- **Unlocks:** Clear taxonomy and authoritative inventory. -- **Quick wins / low-hanging fruit:** Reference the catalog from configuration docs. - -**Option B — Catalog under `docs/project_management/**` only** -- **Pros:** Keeps catalog “internal”; avoids implying stability. -- **Cons:** Lower discoverability; increases drift risk vs operator docs. -- **Cascading implications:** Requires duplication or cross-linking to operator docs. -- **Risks:** Operators do not find it. -- **Unlocks:** Internal-only planning artifact. -- **Quick wins / low-hanging fruit:** None. - -**Recommendation** -- **Selected:** Option A — `docs/ENVIRONMENT_VARIABLES.md` -- **Rationale (crisp):** It creates a discoverable single source of truth while still allowing explicit “internal/test” labeling. - -**Follow-up tasks (explicit)** -- Ensure `docs/CONFIGURATION.md` references `docs/ENVIRONMENT_VARIABLES.md` and the override split (task: `EV0-integ`). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md deleted file mode 100644 index 7adbf9322..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md +++ /dev/null @@ -1,63 +0,0 @@ -# Execution Preflight Gate Report — env_var_taxonomy_and_override_split - -Date (UTC): 2026-01-05T01:44:56Z - -Standard: -- `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` - -Feature directory: -- `docs/project_management/_archived/env_var_taxonomy_and_override_split/` - -## Recommendation - -RECOMMENDATION: **ACCEPT** - -## Inputs Reviewed - -- [x] ADR accepted and still matches intent -- [x] Planning Pack complete (`plan.md`, `tasks.json`, `session_log.md`, specs, kickoff prompts) -- [x] Triad sizing is appropriate (each slice is one behavior delta; no “grab bag” slices) -- [x] Cross-platform plan is explicit (`tasks.json` meta: platforms + WSL mode if needed) -- [x] `manual_testing_playbook.md` exists and is runnable -- [x] Smoke scripts exist and map to the manual playbook - -## Cross-Platform Coverage - -- Declared platforms: linux, macos, windows (from `tasks.json` meta) -- WSL required: no - -## Smoke ↔ Manual Parity Check - -- Linux smoke: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh` -- macOS smoke: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh` -- Windows smoke: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1` - -Notes: -- Smoke scripts mirror the playbook’s observable checks: - - baseline config propagation (policy.mode + non-policy keys) - - legacy exported-state `SUBSTRATE_*` does not override config - - `SUBSTRATE_OVERRIDE_*` does override config (no workspace) - - workspace config wins over `SUBSTRATE_OVERRIDE_*` - - invalid override values yield exit code `2` (multiple keys) - - minimum key coverage: `policy.mode`, `world.caged`, `world.anchor_mode` - - EV0 implementation includes a required repo-wide grep/audit to ensure no bypass reads of config-shaped legacy `SUBSTRATE_*` inputs outside the resolver (evidence recorded in EV0 closeout) - -## CI Dispatch Readiness - -- [x] Dispatch commands in integration tasks are correct and runnable - - `make feature-smoke ...` target exists and dispatches `.github/workflows/feature-smoke.yml` via `scripts/ci/dispatch_feature_smoke.sh`. -- [x] Required self-hosted runners exist and are labeled correctly - - Expected labels (from `.github/workflows/feature-smoke.yml`): - - Linux: `[self-hosted, Linux, linux-host]` - - macOS: `[self-hosted, macOS]` - - Windows: `[self-hosted, Windows]` - - Note: runner availability cannot be proven from this repo checkout; confirm in GitHub Actions before dispatching. - -Run ids/URLs (if executed during preflight): -- Linux: -- macOS: -- Windows: - -## Required Fixes Before Starting EV0 (if any) - -- None. diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md deleted file mode 100644 index 24072a038..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md +++ /dev/null @@ -1,80 +0,0 @@ -# Integration Map — Env Var Taxonomy + Override Split - -## Scope -- Implement the ADR-0006 override split for effective config resolution: - - Override inputs: `SUBSTRATE_OVERRIDE_*` - - Exported state: `SUBSTRATE_*` (output-only for config resolution) -- Ensure the canonical env-var catalog and configuration docs reflect the taxonomy and split. - -## Non-Scope -- Changes to world backend transports (`world*`, `forwarder`, `host-proxy`). -- Policy schema changes or policy discovery changes. -- Trace schema changes. - -## End-to-end data flow (inputs → derived state → actions → outputs) - -### Inputs -- CLI flags (subset): `--world|--no-world`, `--anchor-mode`, `--anchor-path`, `--caged|--uncaged` -- Config files: - - Global: `$SUBSTRATE_HOME/config.yaml` - - Workspace: `/.substrate/workspace.yaml` -- Override env vars (inputs): `SUBSTRATE_OVERRIDE_*` (subset; config-shaped only) -- Exported state env vars (outputs): `SUBSTRATE_*` exported via `env.sh` and runtime - -### Derived state -- Effective config (`SubstrateConfig`) resolved by `crates/shell/src/execution/config_model.rs` - -### Actions -- Shell invocation plan consumes effective config to determine world enablement and policy mode propagation. -- `substrate config` commands read/write config files and render config. - -### Outputs -- Stable exports (`$SUBSTRATE_HOME/env.sh`) continue to export `SUBSTRATE_*` state. -- Effective config resolution ignores config-shaped `SUBSTRATE_*` values as override inputs. -- Docs: - - `docs/ENVIRONMENT_VARIABLES.md` remains the canonical catalog. - - `docs/CONFIGURATION.md` references the catalog and the override split. - -## Required implementation audit (no bypass reads) - -ADR-0006’s intent is repo-wide: “stable exports” must be safe to have in the environment without silently acting as overrides. EV0 therefore requires an explicit audit to catch bypass reads outside the resolver. - -Audit rule: -- Non-test code MUST NOT treat config-shaped legacy `SUBSTRATE_*` values as operator override inputs. If a component needs config, it MUST consult effective config and/or the dedicated override namespace (`SUBSTRATE_OVERRIDE_*`). - -Required audit commands (run from repo root): -```bash -rg -n "SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)" -S crates src scripts -rg -n "env::var(_os)?\\(\"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\"\\)" -S crates -``` - -Evidence requirement: -- The final EV0 integration MUST include a summary of hits + disposition (fixed / derived-state-only / test-only) in `EV0-closeout_report.md`. - -## Component map (what changes where) - -### `crates/shell` -- `crates/shell/src/execution/config_model.rs` - - Read `SUBSTRATE_OVERRIDE_*` for config-shaped override inputs. - - Stop reading config-shaped `SUBSTRATE_*` values as override inputs. - - Preserve strict parsing behavior for override inputs. -- `crates/shell/src/execution/invocation/plan.rs` - - No new contract surface; continues to consume effective config for world enablement decisions. - -### `crates/shim`, `crates/world*` -- No contract changes are required by this feature; they continue to treat `SUBSTRATE_*` as runtime state. - -### Docs -- `docs/ENVIRONMENT_VARIABLES.md` - - Canonical taxonomy and catalog; includes the reserved `SUBSTRATE_OVERRIDE_*` names. -- `docs/CONFIGURATION.md` - - Must treat `SUBSTRATE_*` as exported state and direct override guidance to `SUBSTRATE_OVERRIDE_*` for config-shaped keys. - -## Composition with adjacent tracks (dependencies) -- `docs/project_management/_archived/policy_and_config_precedence/` (ADR-0005 / PCP0): - - PCP0 is sequenced first; it defines the workspace-over-env precedence correction in the same resolver layer. - - This feature builds on that resolver layer and replaces the env override namespace for config-shaped keys. - -## Sequencing alignment (final) -- Sequencing entry: `docs/project_management/packs/sequencing.json` → sprint id `env_var_taxonomy_and_override_split` -- Sequenced after: `policy_and_config_precedence` (order 26) diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md deleted file mode 100644 index e74224d4e..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md +++ /dev/null @@ -1,36 +0,0 @@ -# Kickoff: EV0-code (code) - -## Scope -- Production code only; no new tests. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/ev0-override-split-code` on branch `ev-ev0-override-split-code` and that `.taskmeta.json` exists at the worktree root. -2. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" SLICE_ID="EV0" LAUNCH_CODEX=1` - -## Requirements -- Implement exactly the behaviors and error handling in `EV0-spec.md`. -- Perform the required repo-wide grep/audit from `EV0-spec.md` to identify any non-test code that reads config-shaped legacy `SUBSTRATE_*` values as behavior-changing inputs outside the effective-config resolver. - - Baseline commands (run from repo root): - - `rg -n "SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)" -S crates src scripts` - - `rg -n "env::var(_os)?\\(\\\"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\\\"\\)" -S crates` - - If any hit can change behavior and is not test-only, it must be fixed in this slice (switch to effective config and/or `SUBSTRATE_OVERRIDE_*`), or explicitly justified as derived/exported-state consumption (value set earlier in-process from effective config). -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- Tests boundary: - - Do not add new tests or new test files. - - Only update existing tests if required to restore baseline expectations after the spec’s behavior change (no new test cases). -- Baseline testing (required): - - Run a targeted baseline test set before making changes, then re-run the same test set after changes and ensure results are unchanged (or improved). - -## End Checklist -1. Run required commands; capture outputs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-code"` -3. Hand off baseline test command(s) and outcomes plus the repo audit hit list/disposition to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md deleted file mode 100644 index ab0bf2801..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md +++ /dev/null @@ -1,33 +0,0 @@ -# Kickoff: EV0-integ-core (integration core) - -## Scope -- Merge EV0 code + tests, resolve drift to spec, and make the slice green on the primary dev platform. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/ev0-override-split-integ-core` on branch `ev-ev0-override-split-integ-core` and that `.taskmeta.json` exists at the worktree root. -2. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" TASK_ID="EV0-integ-core" LAUNCH_CODEX=1` - -## Requirements -- Reconcile code/tests to spec (spec wins). -- Merge `EV0-code` and `EV0-test` task branches into this worktree. -- Confirm the required repo-wide grep/audit from `EV0-spec.md` was performed and that any behavior-changing legacy `SUBSTRATE_*` input reads have been eliminated or rewired (prepare a summary for `EV0-closeout_report.md`). -- Run required integration gates (must be green before CI smoke dispatch): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Ensure smoke + manual playbook validate policy mode plus multiple non-policy keys (minimum: `world.caged` and `world.anchor_mode`). -- Dispatch cross-platform smoke via CI from this worktree: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -## End Checklist -1. Capture smoke run ids/URLs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-integ-core"` -3. Hand off run ids/URLs and any parity notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md deleted file mode 100644 index 038c7989b..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md +++ /dev/null @@ -1,33 +0,0 @@ -# Kickoff: EV0-integ-linux (integration platform-fix — linux) - -## Scope -- Ensure the slice behaves correctly on linux. -- This task is allowed to make production-code and/or test changes as needed to achieve cross-platform parity, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: linux. -2. Verify you are in the task worktree `wt/ev0-override-split-integ-linux` on branch `ev-ev0-override-split-integ-linux` and that `.taskmeta.json` exists at the worktree root. -3. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" TASK_ID="EV0-integ-linux" TASK_PLATFORM=linux LAUNCH_CODEX=1` - -## Requirements -- Merge the core integration branch into this worktree branch: - - `ev-ev0-override-split-integ-core` -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- Ensure linux smoke validates policy.mode plus non-policy keys (minimum: `world.caged` and `world.anchor_mode`) and that failures are treated as parity bugs. -- Validate platform smoke via CI (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -## End Checklist -1. Ensure smoke is green for linux and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-integ-linux"` -3. Hand off run id/URL and any linux notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md deleted file mode 100644 index 6ea8012c9..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md +++ /dev/null @@ -1,33 +0,0 @@ -# Kickoff: EV0-integ-macos (integration platform-fix — macos) - -## Scope -- Ensure the slice behaves correctly on macos. -- This task is allowed to make production-code and/or test changes as needed to achieve cross-platform parity, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: macos. -2. Verify you are in the task worktree `wt/ev0-override-split-integ-macos` on branch `ev-ev0-override-split-integ-macos` and that `.taskmeta.json` exists at the worktree root. -3. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" TASK_ID="EV0-integ-macos" TASK_PLATFORM=macos LAUNCH_CODEX=1` - -## Requirements -- Merge the core integration branch into this worktree branch: - - `ev-ev0-override-split-integ-core` -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- Ensure macOS smoke validates policy.mode plus non-policy keys (minimum: `world.caged` and `world.anchor_mode`) and that failures are treated as parity bugs. -- Validate platform smoke via CI (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -## End Checklist -1. Ensure smoke is green for macos and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-integ-macos"` -3. Hand off run id/URL and any macos notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md deleted file mode 100644 index 4cfef516a..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md +++ /dev/null @@ -1,33 +0,0 @@ -# Kickoff: EV0-integ-windows (integration platform-fix — windows) - -## Scope -- Ensure the slice behaves correctly on windows. -- This task is allowed to make production-code and/or test changes as needed to achieve cross-platform parity, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: windows. -2. Verify you are in the task worktree `wt/ev0-override-split-integ-windows` on branch `ev-ev0-override-split-integ-windows` and that `.taskmeta.json` exists at the worktree root. -3. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" TASK_ID="EV0-integ-windows" TASK_PLATFORM=windows LAUNCH_CODEX=1` - -## Requirements -- Merge the core integration branch into this worktree branch: - - `ev-ev0-override-split-integ-core` -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- Ensure Windows smoke validates policy.mode plus non-policy keys (minimum: `world.caged` and `world.anchor_mode`) and that failures are treated as parity bugs. -- Validate platform smoke via CI (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=windows RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -## End Checklist -1. Ensure smoke is green for windows and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-integ-windows"` -3. Hand off run id/URL and any windows notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md deleted file mode 100644 index 1cffaf526..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md +++ /dev/null @@ -1,38 +0,0 @@ -# Kickoff: EV0-integ (integration final) - -## Scope -- Merge core + platform-fix branches for EV0, run integration gates, confirm cross-platform smoke is green, and complete the closeout report. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Closeout report: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/ev0-override-split-integ` on branch `ev-ev0-override-split-integ` and that `.taskmeta.json` exists at the worktree root. -2. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" TASK_ID="EV0-integ" LAUNCH_CODEX=1` - -## Requirements -- Merge the relevant EV0 branches into this worktree: - - `ev-ev0-override-split-integ-core` - - any platform-fix integration branches that produced commits -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Re-run cross-platform smoke via CI to confirm the merged result is green: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` -- Confirm smoke/manual parity and key coverage: - - Smoke must validate policy.mode plus non-policy keys (minimum: `world.caged` and `world.anchor_mode`). -- Complete the closeout report: - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md` - - Include the required repo-wide grep/audit evidence summary (hits + disposition). - -## End Checklist -1. Ensure all required platforms are green (capture run ids/URLs). -2. From inside this worktree, run: `make triad-task-finish TASK_ID="EV0-integ"` -3. Hand off run ids/URLs and closeout completion to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md deleted file mode 100644 index e3eacd8fd..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md +++ /dev/null @@ -1,30 +0,0 @@ -# Kickoff: EV0-test (test) - -## Scope -- Tests only (plus minimal test-only helpers if required); no production code. -- Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/ev0-override-split-test` on branch `ev-ev0-override-split-test` and that `.taskmeta.json` exists at the worktree root. -2. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" SLICE_ID="EV0" LAUNCH_CODEX=1` - -## Requirements -- Add/modify tests that enforce the acceptance criteria in `EV0-spec.md`. -- Ensure tests cover policy.mode plus multiple non-policy keys (minimum: `world.caged` and `world.anchor_mode`) across: - - legacy exported-state `SUBSTRATE_*` does not override, - - `SUBSTRATE_OVERRIDE_*` does override (when no workspace exists), - - workspace config wins over overrides. -- Run: - - `cargo fmt` - - the targeted tests you add/touch - -## End Checklist -1. Run required commands; capture outputs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="EV0-test"` -3. Hand off targeted test command(s) and outcomes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md deleted file mode 100644 index a28c59f23..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md +++ /dev/null @@ -1,34 +0,0 @@ -# Kickoff: F0-exec-preflight (execution preflight gate) - -## Scope -- Run the feature-level start gate before any triad work begins. -- This task is docs-only and must be performed on the orchestration branch (no worktrees). -- Standard: `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` -- Report: `docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Ensure the orchestration branch exists and is checked out: - - `make triad-orch-ensure FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` -2. Read: ADR + Executive Summary, `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, `integration_map.md`, `manual_testing_playbook.md`, and this prompt. -3. Set `F0-exec-preflight` status to `in_progress` in `tasks.json`; add START entry to `session_log.md`; commit docs (`docs: start F0-exec-preflight`). - -## Requirements - -Fill `execution_preflight_report.md` with a concrete recommendation: -- **ACCEPT**: triads may begin. -- **REVISE**: do not start triads until the listed issues are fixed and the preflight is re-run. - -At minimum, verify: -- The cross-platform plan is explicit and matches the spec/contract (platforms + WSL mode if needed). -- Smoke scripts mirror the manual testing playbook by running real commands/workflows and validating exit codes + key output. -- Smoke/manual validation covers policy.mode plus multiple non-policy keys (minimum: world.caged and world.anchor_mode), not just policy mode. -- EV0 includes an explicit repo-wide grep/audit requirement to detect and eliminate bypass reads of config-shaped legacy `SUBSTRATE_*` inputs outside the resolver. -- Any CI dispatch commands embedded in integration tasks are runnable with the expected runners. - -## End Checklist - -1. Set `F0-exec-preflight` status to `completed` in `tasks.json`; add END entry to `session_log.md` (include the recommendation and any required fixes). -2. Commit docs (`docs: finish F0-exec-preflight`). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md deleted file mode 100644 index 60578697a..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md +++ /dev/null @@ -1,33 +0,0 @@ -# Kickoff: FZ-feature-cleanup (feature cleanup) - -## Scope -- Feature-level cleanup at the end of the feature: - - remove all retained task worktrees - - optionally prune task branches (local and/or remote) -- This task runs on the orchestration branch (no worktrees). - -Do not edit planning docs inside the worktree. - -## Preconditions -- All tasks for this feature are completed and any required merges are done. -- Orchestration worktree is clean (no uncommitted changes). - -## How to run (deterministic) -This feature uses the triad automation registry stored in the shared git directory: -- `/triad/features/env_var_taxonomy_and_override_split/worktrees.json` - -Dry-run (recommended first): -- `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" DRY_RUN=1 REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -Real run: -- `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -Remote branch pruning (optional, destructive): -- `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PRUNE_REMOTE=origin PRUNE_LOCAL=1 REMOVE_WORKTREES=1` - -If any worktree is dirty or any branch is unmerged/unpushed, cleanup refuses unless forced: -- add `FORCE=1` to the make invocation. - -## Output requirements -- Paste the cleanup stdout summary block into the END entry for this task in `session_log.md`. - diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md deleted file mode 100644 index fe4056515..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md +++ /dev/null @@ -1,244 +0,0 @@ -# Manual Testing Playbook — Env Var Taxonomy + Override Split (ADR-0006) - -This playbook validates the EV0 slice contract: -- `SUBSTRATE_*` exported state values do not act as effective-config override inputs. -- `SUBSTRATE_OVERRIDE_*` values act as effective-config override inputs. - - Smoke/manual validation covers policy mode plus multiple non-policy keys so partial implementations can’t accidentally pass. - -Standards: -- Exit codes: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` -- Platform integration: `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md` - -## Fast path (preferred): run smoke scripts - -Smoke scripts are the auditable, repeatable version of this playbook. Success is exit code `0` and an `OK:` line. - -- Linux: `bash docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh` -- macOS: `bash docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh` -- Windows: `pwsh -File docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1` - -Cross-platform CI dispatch (preferred when validating parity): -- `make feature-smoke FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF="feat/env_var_taxonomy_and_override_split" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -## Manual validation (debugging) - -All steps run in temp directories and must not modify a real `$SUBSTRATE_HOME`. - -### Preconditions -- `substrate` is on `PATH`. -- Linux/macOS: `/bin/bash` exists. - -### Linux/macOS steps - -1) Create a temp `$SUBSTRATE_HOME` and write a known global config for multiple keys. - -```bash -TMP_HOME="$(mktemp -d)" -export HOME="$TMP_HOME" -export SUBSTRATE_HOME="$TMP_HOME" - -substrate config global init --force -substrate config global set policy.mode=observe -substrate config global set world.caged=true -substrate config global set world.anchor_mode=follow-cwd -``` - -Expected: -- exit code `0` for all commands. - -2) Verify baseline values are visible in a host-only invocation. - -```bash -substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"' -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -3) Verify legacy exported-state env vars do not override effective config. - -```bash -SUBSTRATE_POLICY_MODE=disabled SUBSTRATE_CAGED=0 SUBSTRATE_ANCHOR_MODE=workspace \ - substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"' -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -4) Verify `SUBSTRATE_OVERRIDE_*` overrides are applied. - -```bash -SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace \ - substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"' -``` - -Expected: -- stdout: `enforce|0|workspace` -- exit code `0` - -5) Verify workspace config overrides override env vars. - -```bash -TMP_WS="$(mktemp -d)" -substrate workspace init "$TMP_WS" -cd "$TMP_WS" -substrate config set policy.mode=observe >/dev/null -substrate config set world.caged=true >/dev/null -substrate config set world.anchor_mode=follow-cwd >/dev/null - -SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace \ - substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"' -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -6) Verify invalid override values fail as user errors for config commands. - -```bash -set +e -SUBSTRATE_OVERRIDE_POLICY_MODE=bogus substrate config show --json >/dev/null 2>&1 -code1=$? -SUBSTRATE_OVERRIDE_CAGED=bogus substrate config show --json >/dev/null 2>&1 -code2=$? -set -e -echo "$code1 $code2" -``` - -Expected: -- stdout: `2 2` - -Cleanup: -```bash -rm -rf "$TMP_HOME" "$TMP_WS" -``` - -### Windows steps (PowerShell) - -1) Create a temp `$env:SUBSTRATE_HOME` and write a known global config for multiple keys. - -```powershell -$tmpRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("substrate-ev0-" + [System.Guid]::NewGuid().ToString("N")) -$tmpHome = Join-Path $tmpRoot "home" -New-Item -ItemType Directory -Force -Path $tmpHome | Out-Null -$env:SUBSTRATE_HOME = $tmpHome -$env:HOME = $tmpHome -$env:USERPROFILE = $tmpHome - -substrate config global init --force | Out-Null -substrate config global set policy.mode=observe | Out-Null -substrate config global set world.caged=true | Out-Null -substrate config global set world.anchor_mode=follow-cwd | Out-Null -``` - -2) Verify override behavior via a host-only invocation. - -```powershell -$out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" -($out | Select-Object -Last 1).Trim() -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -3) Verify legacy exported-state env vars do not override effective config. - -```powershell -$env:SUBSTRATE_POLICY_MODE = "disabled" -$env:SUBSTRATE_CAGED = "0" -$env:SUBSTRATE_ANCHOR_MODE = "workspace" -$out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" -Remove-Item Env:SUBSTRATE_POLICY_MODE -ErrorAction SilentlyContinue -Remove-Item Env:SUBSTRATE_CAGED -ErrorAction SilentlyContinue -Remove-Item Env:SUBSTRATE_ANCHOR_MODE -ErrorAction SilentlyContinue -($out | Select-Object -Last 1).Trim() -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -4) Verify `SUBSTRATE_OVERRIDE_*` overrides are applied. - -```powershell -$env:SUBSTRATE_OVERRIDE_POLICY_MODE = "enforce" -$env:SUBSTRATE_OVERRIDE_CAGED = "0" -$env:SUBSTRATE_OVERRIDE_ANCHOR_MODE = "workspace" -$out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" -Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue -Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue -Remove-Item Env:SUBSTRATE_OVERRIDE_ANCHOR_MODE -ErrorAction SilentlyContinue -($out | Select-Object -Last 1).Trim() -``` - -Expected: -- stdout: `enforce|0|workspace` -- exit code `0` - -5) Verify workspace config wins over overrides. - -```powershell -$tmpWs = Join-Path $tmpRoot "ws2" -New-Item -ItemType Directory -Force -Path $tmpWs | Out-Null -& substrate workspace init $tmpWs | Out-Null - -Push-Location $tmpWs -try { - & substrate config set policy.mode=observe | Out-Null - & substrate config set world.caged=true | Out-Null - & substrate config set world.anchor_mode=follow-cwd | Out-Null - - $env:SUBSTRATE_OVERRIDE_POLICY_MODE = "enforce" - $env:SUBSTRATE_OVERRIDE_CAGED = "0" - $env:SUBSTRATE_OVERRIDE_ANCHOR_MODE = "workspace" - $out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" - Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_ANCHOR_MODE -ErrorAction SilentlyContinue - ($out | Select-Object -Last 1).Trim() -} finally { - Pop-Location -} -``` - -Expected: -- stdout: `observe|1|follow-cwd` -- exit code `0` - -6) Verify invalid override values fail as user errors for config commands (multiple keys). - -```powershell -$env:SUBSTRATE_OVERRIDE_POLICY_MODE = "bogus" -& substrate config show --json 2>$null | Out-Null -$code1 = $LASTEXITCODE -Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue - -$env:SUBSTRATE_OVERRIDE_CAGED = "bogus" -& substrate config show --json 2>$null | Out-Null -$code2 = $LASTEXITCODE -Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue - -"$code1 $code2" -``` - -Expected: -- stdout: `2 2` - -Cleanup: -```powershell -Remove-Item -Recurse -Force $tmpRoot -ErrorAction SilentlyContinue -``` - -## Required repo audit (implementation review) - -Before treating EV0 as complete, run a repo-wide grep/audit to confirm no non-test code bypasses effective config resolution by consuming config-shaped `SUBSTRATE_*` values directly as inputs. - -Baseline commands (run from repo root): -```bash -rg -n "SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)" -S crates src scripts -rg -n "env::var(_os)?\\(\"SUBSTRATE_(WORLD(_ENABLED)?|ANCHOR_MODE|ANCHOR_PATH|CAGED|POLICY_MODE|SYNC_AUTO_SYNC|SYNC_DIRECTION|SYNC_CONFLICT_POLICY|SYNC_EXCLUDE)\"\\)" -S crates -``` diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md deleted file mode 100644 index da06e93a9..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md +++ /dev/null @@ -1,63 +0,0 @@ -# Env Var Taxonomy + Override Split — plan - -## Scope -- Feature directory: `docs/project_management/_archived/env_var_taxonomy_and_override_split/` -- Orchestration branch: `feat/env_var_taxonomy_and_override_split` -- Governing ADR: `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - -## Goal -- Establish a repo-wide environment variable taxonomy and eliminate dual-use config overrides by splitting: - - exported state: `SUBSTRATE_*` (output-only for config resolution), and - - override inputs: `SUBSTRATE_OVERRIDE_*` (inputs to effective config resolution). - -## Guardrails (non-negotiable) -- Specs are the single source of truth; integration reconciles code/tests to the spec. -- Planning Pack docs are edited only on the orchestration branch (never inside task worktrees). -- Do not edit planning docs inside the worktree. -- Greenfield breaking is allowed (no backwards compatibility for legacy override semantics). -- Exit codes follow: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -## Sequencing prerequisite (macro) -- This sprint is sequenced after `policy_and_config_precedence` (ADR-0005 / PCP0) to avoid simultaneous churn in the same resolver layer. - - Sequencing spine: `docs/project_management/packs/sequencing.json` - -## Triads overview (spec slices) - -1) **EV0 — Override split for effective config** -- Implement `SUBSTRATE_OVERRIDE_*` parsing for config-shaped overrides. -- Ensure `SUBSTRATE_*` exported state values are not consulted as override inputs by the effective-config resolver. -- Perform an explicit repo-wide grep/audit to confirm no commands bypass effective config resolution by reading config-shaped `SUBSTRATE_*` values directly as inputs (and fix any hits that do). -- Update docs and the canonical env-var catalog references per ADR-0006. - -Specs (single source of truth): -- `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - -## Cross-platform integration model -- Model: schema v2 cross-platform integration tasks (core + per-platform + final) encoded in `tasks.json` (meta.schema_version=3, meta.platforms_required set). -- Validation mechanism: - - Preferred: GitHub Actions self-hosted runners via `make feature-smoke` (see `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md`). - - Local smoke execution is valid only on the matching platform. - -## Primary code touchpoints (expected) -- Effective config resolution: - - `crates/shell/src/execution/config_model.rs` -- Shell invocation planning (consumes effective config): - - `crates/shell/src/execution/invocation/plan.rs` -- Canonical env-var catalog: - - `docs/ENVIRONMENT_VARIABLES.md` -- Operator configuration reference (update as part of EV0 integration): - - `docs/CONFIGURATION.md` - -## Start checklist (all tasks) -1. `make triad-orch-ensure FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` -2. Read: `plan.md`, `tasks.json`, `session_log.md`, `EV0-spec.md`, and your kickoff prompt. -3. Update task status to `in_progress` in `tasks.json`. -4. Add a START entry to `session_log.md`; commit docs (`docs: start `). -5. Create the task worktree per the kickoff prompt (prefer triad automation where available). -6. Do not edit planning docs inside the worktree. - -## End checklist (integration) -1. Run required checks (`cargo fmt`, `cargo clippy --workspace --all-targets -- -D warnings`, relevant tests, `make integ-checks`). -2. Dispatch and record cross-platform smoke results in `session_log.md`. -3. Complete `EV0-closeout_report.md`. -4. Update `tasks.json` + add END entry to `session_log.md`; commit docs (`docs: finish `). diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/quality_gate_report.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/quality_gate_report.md deleted file mode 100644 index 534bbd618..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/quality_gate_report.md +++ /dev/null @@ -1,166 +0,0 @@ -# Planning Quality Gate Report — env_var_taxonomy_and_override_split - -## Metadata -- Feature directory: `docs/project_management/_archived/env_var_taxonomy_and_override_split/` -- Reviewed commit: `80e85ecbbb0cf3a28b87df7f1017ab502703ad72` -- Reviewer: Third-party reviewer (Codex CLI) -- Date (UTC): `2026-01-04` -- Recommendation: `ACCEPT` - -## Addendum (post-gate hardening) - -The Planning Pack was later hardened to make two EV0 requirements unmissable: -- a required repo-wide grep/audit for legacy config-shaped `SUBSTRATE_*` input reads outside the resolver, and -- expanded smoke/manual validation that covers policy.mode plus multiple non-policy keys (minimum: world.caged and world.anchor_mode). - -If the feature pack is modified after the reviewed commit, re-run this gate on the current tip before treating the recommendation as binding. - -## Evidence: Commands Run (verbatim) - -```bash -export FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" - -# JSON validity -jq -e . "$FEATURE_DIR/tasks.json" >/dev/null -# exit 0 -jq -e . docs/project_management/packs/sequencing.json >/dev/null -# exit 0 - -# tasks.json required-field audit (per template) -python - <<'PY' -import json, os -feature_dir=os.environ["FEATURE_DIR"] -path=os.path.join(feature_dir,"tasks.json") -data=json.load(open(path,"r",encoding="utf-8")) -tasks=data["tasks"] if isinstance(data,dict) and "tasks" in data else data -required=[ - "id","name","type","phase","status","description", - "references","acceptance_criteria","start_checklist","end_checklist", - "worktree","integration_task","kickoff_prompt", - "depends_on","concurrent_with" -] -missing=[] -for t in tasks: - m=[k for k in required if k not in t] - if m: - missing.append((t.get("id",""),m)) -if missing: - for tid,m in missing: - print(tid,":",", ".join(m)) - raise SystemExit(1) -print("OK: tasks.json required fields present") -PY -# OK: tasks.json required fields present - -# tasks.json invariants -make planning-validate FEATURE_DIR="$FEATURE_DIR" -# exit 0 -# OK: tasks.json validation passed: docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json - -# Planning lint (mechanical) -make planning-lint FEATURE_DIR="$FEATURE_DIR" -# exit 0 -# OK: planning lint passed -``` - -## Required Inputs Read End-to-End (checklist) -Mark `YES` only if read end-to-end. - -- ADR(s): `YES` (`docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`, `docs/project_management/adrs/implemented/ADR-0005-workspace-config-precedence-over-env.md`) -- `plan.md`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md`) -- `tasks.json`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json`) -- `session_log.md`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md`) -- All specs in scope: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md`) -- `decision_register.md`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md`) -- `integration_map.md`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md`) -- `manual_testing_playbook.md`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md`) -- Feature smoke scripts under `smoke/`: `YES` (`docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/*`) -- `docs/project_management/packs/sequencing.json`: `YES` (`docs/project_management/packs/sequencing.json`) -- Standards: - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md`: `YES` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md`: `YES` - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md`: `YES` - -## Gate Results (PASS/FAIL with evidence) - -### 1) Zero-ambiguity contracts -- Result: `PASS` -- Evidence: `make planning-lint FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` → `OK: planning lint passed` -- Notes: Hard-ban scan and ambiguity scan both passed. - -### 2) Decision quality (2 options, explicit tradeoffs, explicit selection) -- Result: `PASS` -- Evidence: `docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md` (DR-0001, DR-0002, DR-0003) -- Notes: Each DR entry has exactly two viable options with explicit tradeoffs and follow-up task mapping. - -### 3) Cross-doc consistency (CLI/config/exit codes/paths) -- Result: `PASS` -- Evidence: - - ADR contract: `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` (“User Contract (Authoritative)”) - - Spec: `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` (“User Contract (Authoritative)”) - - Playbook: `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md` -- Notes: Precedence rules and exit codes (0/1/2/3) are consistent across ADR/spec/playbook/smoke. - -### 4) Sequencing and dependency alignment -- Result: `PASS` -- Evidence: - - `docs/project_management/packs/sequencing.json`: sprint `policy_and_config_precedence` is order `26`; this feature is order `26.5` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md`: “Prerequisite integration task IDs: … `PCP0-integ`” - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json`: `meta.external_task_ids=["PCP0-integ"]` and `F0-exec-preflight.depends_on=["PCP0-integ"]` -- Notes: Cross-feature prerequisite is encoded as an external dependency in `tasks.json`. - -### 5) Testability and validation readiness -- Result: `PASS` -- Evidence: - - Manual playbook steps with expected stdout/exit codes: `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md` - - Smoke scripts: `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh`, `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh`, `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1` - - Smoke scripts are referenced by the manual playbook “Fast path (preferred): run smoke scripts” -- Notes: Smoke scripts validate: baseline config propagation, legacy exported-state non-override, override env effect, workspace precedence, and invalid override exit `2`. - - Hardened requirement: smoke/manual validation must also cover non-policy keys (minimum: `world.caged` and `world.anchor_mode`). - - Hardened requirement: EV0 implementation must include a repo-wide grep/audit to detect bypass reads of config-shaped legacy `SUBSTRATE_*` inputs. - -### 5.1) Cross-platform parity task structure (schema v2+) -- Result: `PASS` -- Evidence: - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json`: `meta.schema_version=3`, `meta.platforms_required=["linux","macos","windows"]` - - Slice EV0 tasks exist and deps are correctly wired: `EV0-integ-core`, `EV0-integ-linux`, `EV0-integ-macos`, `EV0-integ-windows`, `EV0-integ` -- Notes: Matches the standard platform-fix integration model. - -### 6) Triad interoperability (execution workflow) -- Result: `PASS` -- Evidence: - - `make planning-validate …` passed - - Kickoff prompts include the sentinel “Do not edit planning docs inside the worktree.” -- Notes: `tasks.json` required fields and triad automation shape are present. - -## Findings (must be exhaustive) - -### Finding 001 — Mechanical planning lint passed -- Status: `VERIFIED` -- Evidence: `make planning-lint FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` → `OK: planning lint passed` -- Impact: Planning Pack passes the mechanical gate and is eligible for review on substantive criteria. -- Fix required (exact): none - -### Finding 002 — Sequencing prerequisite is not encoded in tasks.json dependencies -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` (Sequencing / Dependencies): prerequisite `PCP0-integ` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json`: `meta.external_task_ids=["PCP0-integ"]`, `F0-exec-preflight.depends_on=["PCP0-integ"]` - - Standard rule: `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` (“Sequencing and Dependency Alignment”) -- Impact: Encodes sequencing prerequisite for auditability and execution ordering. -- Fix required (exact): none - -### Finding 003 — ADR-required doc updates are not explicitly wired into EV0 integration tasks -- Status: `VERIFIED` -- Evidence: - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` (Architecture Shape → Docs): requires `docs/CONFIGURATION.md` and `docs/ENVIRONMENT_VARIABLES.md` updates - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md` (DR-0003 follow-up): “Ensure `docs/CONFIGURATION.md` references `docs/ENVIRONMENT_VARIABLES.md` and the override split (task: `EV0-integ`).” - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json` (EV0-integ references/end_checklist/acceptance_criteria): includes both docs and requires updating them -- Impact: Doc deliverables are now enforced in the EV0 final integration task. -- Fix required (exact): none - -## Decision: ACCEPT or FLAG - -### If ACCEPT -- Summary: Planning Pack is implementation-ready (mechanical lint passes; contracts consistent; sequencing and doc deliverables are wired into `tasks.json`). -- Next step: “Execution triads may begin.” diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md b/docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md deleted file mode 100644 index bd72b9f09..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md +++ /dev/null @@ -1,113 +0,0 @@ -# env_var_taxonomy_and_override_split — session log - -## START — 2026-01-04T13:46:56Z — planning — planning pack completion -- Feature: `docs/project_management/_archived/env_var_taxonomy_and_override_split/` -- Branch: `testing` -- Goal: Produce an execution-ready Planning Pack for ADR-0006 with zero ambiguity. -- Inputs to read end-to-end: - - `docs/project_management/standards/PLANNING_README.md` - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - - `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md` - - `docs/project_management/standards/ADR_STANDARD_AND_TEMPLATE.md` - - `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - - `docs/project_management/standards/PLANNING_SESSION_LOG_TEMPLATE.md` - - `docs/project_management/standards/PLANNING_LINT_CHECKLIST.md` - - `docs/project_management/standards/PLANNING_GATE_REPORT_TEMPLATE.md` - - `docs/project_management/standards/PLANNING_QUALITY_GATE_PROMPT.md` - - `docs/project_management/packs/sequencing.json` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md` -- Commands planned (if any): - - `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` - - `make planning-lint FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` - -## END — 2026-01-04T13:56:08Z — planning — planning pack completion -- Summary of changes (exhaustive): - - Expanded the feature plan to an execution-ready runbook with cross-platform integration model and checklists. - - Formalized the decision register entries per the planning standard (A/B options, selections, follow-up tasks). - - Added EV0 spec defining the override split contract and validation expectations. - - Added `tasks.json` (schema v3 automation + cross-platform integration task model). - - Added kickoff prompts for all tasks (code/test/core/platform/final + gates). - - Added manual testing playbook with explicit commands, outputs, and exit codes. - - Added cross-platform smoke scripts (Linux/macOS/Windows). - - Added execution gates artifacts (execution preflight report + EV0 closeout report). - - Updated ADR-0006 to remove placeholders, align to sequencing, and refreshed ADR_BODY_SHA256. - - Updated sequencing spine to include this sprint entry. -- Files created/modified: - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/quality_gate_report.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1` - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - - `docs/project_management/packs/sequencing.json` -- Rubric checks run (with results): - - `make adr-fix ADR=docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` → `0` → updated hash - - `jq -e . docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json >/dev/null` → `0` → pass - - `jq -e . docs/project_management/packs/sequencing.json >/dev/null` → `0` → pass - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` → `0` → pass - - `make planning-lint FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split"` → `0` → pass -- Sequencing alignment: - - `sequencing.json` reviewed: `YES` - - Changes required: added `env_var_taxonomy_and_override_split` sprint entry (order `26.5`) with `EV0` slice -- Blockers: - - Third-party quality gate review must update `quality_gate_report.md` with evidence and `RECOMMENDATION: ACCEPT` before execution triads begin. -- Next steps: - - Quality gate reviewer: run `make planning-lint` and fill `quality_gate_report.md`. - - Operator: run `F0-exec-preflight`, then start EV0 via `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/env_var_taxonomy_and_override_split" SLICE_ID="EV0" LAUNCH_CODEX=1`. - -## START — 2026-01-05T01:44:56Z — F0-exec-preflight — execution preflight gate -- Feature: `docs/project_management/_archived/env_var_taxonomy_and_override_split/` -- Branch: `feat/env_var_taxonomy_and_override_split` -- Goal: Run the feature-level execution preflight gate and produce a concrete recommendation before starting EV0 triads. - -## END — 2026-01-05T01:46:39Z — F0-exec-preflight — execution preflight gate -- Recommendation: `ACCEPT` (EV0 triads may begin) -- Report: `docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md` -- Notes: - - External prerequisite `PCP0-integ` is marked `completed` in `docs/project_management/_archived/policy_and_config_precedence/tasks.json`. - - CI dispatch uses `make feature-smoke ... RUNNER_KIND=self-hosted`; confirm runner labels exist before dispatching. - -## START — 2026-01-05T02:00:40Z — planning — addendum: harden EV0 audit + smoke coverage -- Goal: Make the EV0 implementation requirements unmissable by explicitly requiring: - - a repo-wide grep/audit for config-shaped legacy `SUBSTRATE_*` reads outside the resolver, and - - smoke/manual validation that covers policy.mode plus multiple non-policy keys. - -## END — 2026-01-05T02:00:40Z — planning — addendum: harden EV0 audit + smoke coverage -- Summary of changes: - - Added a required repo-wide grep/audit section to EV0 spec and wired it into EV0 tasks/prompts/closeout. - - Expanded smoke + manual testing to validate policy.mode plus non-policy keys (minimum: world.caged and world.anchor_mode). -- Files updated: - - `docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/*` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/*` - - `docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md` diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh b/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh deleted file mode 100755 index 3d6d5e82e..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh +++ /dev/null @@ -1,68 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -if [[ "$(uname -s)" != "Linux" ]]; then - echo "SKIP: env var override split linux smoke (not Linux)" - exit 0 -fi - -fail() { - echo "FAIL: $*" >&2 - exit 1 -} - -need_cmd() { - local name="$1" - if ! command -v "$name" >/dev/null 2>&1; then - echo "MISSING: $name not found on PATH" >&2 - exit 3 - fi -} - -need_cmd substrate -need_cmd mktemp - -TMP_HOME="$(mktemp -d)" -TMP_WS="$(mktemp -d)" -cleanup() { rm -rf "$TMP_HOME" "$TMP_WS"; } -trap cleanup EXIT - -export HOME="$TMP_HOME" -export SUBSTRATE_HOME="$TMP_HOME" - -substrate config global init --force >/dev/null -substrate config global set policy.mode=observe >/dev/null -substrate config global set world.caged=true >/dev/null -substrate config global set world.anchor_mode=follow-cwd >/dev/null - -out="$(substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected observe|1|follow-cwd from config; got '$out'" - -out="$(SUBSTRATE_POLICY_MODE=disabled SUBSTRATE_CAGED=0 SUBSTRATE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected legacy SUBSTRATE_* to not override; got '$out'" - -out="$(SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "enforce|0|workspace" ]] || fail "expected override enforce|0|workspace; got '$out'" - -substrate workspace init "$TMP_WS" >/dev/null -cd "$TMP_WS" -substrate config set policy.mode=observe >/dev/null -substrate config set world.caged=true >/dev/null -substrate config set world.anchor_mode=follow-cwd >/dev/null - -out="$(SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected workspace to win over overrides; got '$out'" - -set +e -SUBSTRATE_OVERRIDE_POLICY_MODE=bogus substrate config show --json >/dev/null 2>&1 -code=$? -set -e -[[ "$code" -eq 2 ]] || fail "expected exit code 2 for invalid override value; got $code" - -set +e -SUBSTRATE_OVERRIDE_CAGED=bogus substrate config show --json >/dev/null 2>&1 -code=$? -set -e -[[ "$code" -eq 2 ]] || fail "expected exit code 2 for invalid override boolean; got $code" - -echo "OK: env var override split linux smoke" diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh b/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh deleted file mode 100644 index 0d81ef0bd..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh +++ /dev/null @@ -1,68 +0,0 @@ -#!/usr/bin/env bash -set -euo pipefail - -if [[ "$(uname -s)" != "Darwin" ]]; then - echo "SKIP: env var override split macOS smoke (not macOS)" - exit 0 -fi - -fail() { - echo "FAIL: $*" >&2 - exit 1 -} - -need_cmd() { - local name="$1" - if ! command -v "$name" >/dev/null 2>&1; then - echo "MISSING: $name not found on PATH" >&2 - exit 3 - fi -} - -need_cmd substrate -need_cmd mktemp - -TMP_HOME="$(mktemp -d)" -TMP_WS="$(mktemp -d)" -cleanup() { rm -rf "$TMP_HOME" "$TMP_WS"; } -trap cleanup EXIT - -export HOME="$TMP_HOME" -export SUBSTRATE_HOME="$TMP_HOME" - -substrate config global init --force >/dev/null -substrate config global set policy.mode=observe >/dev/null -substrate config global set world.caged=true >/dev/null -substrate config global set world.anchor_mode=follow-cwd >/dev/null - -out="$(substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected observe|1|follow-cwd from config; got '$out'" - -out="$(SUBSTRATE_POLICY_MODE=disabled SUBSTRATE_CAGED=0 SUBSTRATE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected legacy SUBSTRATE_* to not override; got '$out'" - -out="$(SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "enforce|0|workspace" ]] || fail "expected override enforce|0|workspace; got '$out'" - -substrate workspace init "$TMP_WS" >/dev/null -cd "$TMP_WS" -substrate config set policy.mode=observe >/dev/null -substrate config set world.caged=true >/dev/null -substrate config set world.anchor_mode=follow-cwd >/dev/null - -out="$(SUBSTRATE_OVERRIDE_POLICY_MODE=enforce SUBSTRATE_OVERRIDE_CAGED=0 SUBSTRATE_OVERRIDE_ANCHOR_MODE=workspace substrate --no-world --shell /bin/bash -c 'printf "%s|%s|%s" "${SUBSTRATE_POLICY_MODE:-}" "${SUBSTRATE_CAGED:-}" "${SUBSTRATE_ANCHOR_MODE:-}"')" -[[ "$out" == "observe|1|follow-cwd" ]] || fail "expected workspace to win over overrides; got '$out'" - -set +e -SUBSTRATE_OVERRIDE_POLICY_MODE=bogus substrate config show --json >/dev/null 2>&1 -code=$? -set -e -[[ "$code" -eq 2 ]] || fail "expected exit code 2 for invalid override value; got $code" - -set +e -SUBSTRATE_OVERRIDE_CAGED=bogus substrate config show --json >/dev/null 2>&1 -code=$? -set -e -[[ "$code" -eq 2 ]] || fail "expected exit code 2 for invalid override boolean; got $code" - -echo "OK: env var override split macOS smoke" diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1 b/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1 deleted file mode 100644 index 70b33ce98..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1 +++ /dev/null @@ -1,111 +0,0 @@ -$ErrorActionPreference = "Stop" - -if (-not $IsWindows) { - Write-Host "SKIP: env var override split Windows smoke (not Windows)" - exit 0 -} - -if (-not (Get-Command substrate -ErrorAction SilentlyContinue)) { - Write-Error "FAIL: substrate not found on PATH" - exit 3 -} - -$tmpRoot = Join-Path ([System.IO.Path]::GetTempPath()) ("substrate-ev0-" + [System.Guid]::NewGuid().ToString("N")) -$tmpHome = Join-Path $tmpRoot "home" -$tmpWs = Join-Path $tmpRoot "ws" -New-Item -ItemType Directory -Force -Path $tmpHome | Out-Null -New-Item -ItemType Directory -Force -Path $tmpWs | Out-Null - -try { - $env:SUBSTRATE_HOME = $tmpHome - $env:HOME = $tmpHome - $env:USERPROFILE = $tmpHome - - & substrate config global init --force | Out-Null - & substrate config global set policy.mode=observe | Out-Null - & substrate config global set world.caged=true | Out-Null - & substrate config global set world.anchor_mode=follow-cwd | Out-Null - - $out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" - $value = ($out | Select-Object -Last 1).Trim() - if ($value -ne "observe|1|follow-cwd") { - Write-Error ("FAIL: expected observe|1|follow-cwd from config, got: " + $value) - exit 1 - } - - $env:SUBSTRATE_POLICY_MODE = "disabled" - $env:SUBSTRATE_CAGED = "0" - $env:SUBSTRATE_ANCHOR_MODE = "workspace" - $out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" - Remove-Item Env:SUBSTRATE_POLICY_MODE -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_CAGED -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_ANCHOR_MODE -ErrorAction SilentlyContinue - $value = ($out | Select-Object -Last 1).Trim() - if ($value -ne "observe|1|follow-cwd") { - Write-Error ("FAIL: expected legacy SUBSTRATE_* to not override, got: " + $value) - exit 1 - } - - $env:SUBSTRATE_OVERRIDE_POLICY_MODE = "enforce" - $env:SUBSTRATE_OVERRIDE_CAGED = "0" - $env:SUBSTRATE_OVERRIDE_ANCHOR_MODE = "workspace" - $out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" - Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_ANCHOR_MODE -ErrorAction SilentlyContinue - $value = ($out | Select-Object -Last 1).Trim() - if ($value -ne "enforce|0|workspace") { - Write-Error ("FAIL: expected override enforce|0|workspace, got: " + $value) - exit 1 - } - - & substrate workspace init $tmpWs | Out-Null - - Push-Location $tmpWs - try { - & substrate config set policy.mode=observe | Out-Null - & substrate config set world.caged=true | Out-Null - & substrate config set world.anchor_mode=follow-cwd | Out-Null - - $env:SUBSTRATE_OVERRIDE_POLICY_MODE = "enforce" - $env:SUBSTRATE_OVERRIDE_CAGED = "0" - $env:SUBSTRATE_OVERRIDE_ANCHOR_MODE = "workspace" - $out = & substrate --no-world --shell cmd.exe -c "echo %SUBSTRATE_POLICY_MODE%|%SUBSTRATE_CAGED%|%SUBSTRATE_ANCHOR_MODE%" - Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_OVERRIDE_ANCHOR_MODE -ErrorAction SilentlyContinue - $value = ($out | Select-Object -Last 1).Trim() - if ($value -ne "observe|1|follow-cwd") { - Write-Error ("FAIL: expected workspace to win over overrides, got: " + $value) - exit 1 - } - - $env:SUBSTRATE_OVERRIDE_POLICY_MODE = "bogus" - & substrate config show --json 2>$null | Out-Null - $code = $LASTEXITCODE - Remove-Item Env:SUBSTRATE_OVERRIDE_POLICY_MODE -ErrorAction SilentlyContinue - if ($code -ne 2) { - Write-Error ("FAIL: expected exit code 2 for invalid override value, got: " + $code) - exit 1 - } - - $env:SUBSTRATE_OVERRIDE_CAGED = "bogus" - & substrate config show --json 2>$null | Out-Null - $code = $LASTEXITCODE - Remove-Item Env:SUBSTRATE_OVERRIDE_CAGED -ErrorAction SilentlyContinue - if ($code -ne 2) { - Write-Error ("FAIL: expected exit code 2 for invalid override boolean, got: " + $code) - exit 1 - } - } finally { - Pop-Location - } -} finally { - Remove-Item -Recurse -Force $tmpRoot -ErrorAction SilentlyContinue - Remove-Item Env:SUBSTRATE_HOME -ErrorAction SilentlyContinue - Remove-Item Env:HOME -ErrorAction SilentlyContinue - Remove-Item Env:USERPROFILE -ErrorAction SilentlyContinue -} - -Write-Host "OK: env var override split Windows smoke" -exit 0 diff --git a/docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json b/docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json deleted file mode 100644 index 167066a1d..000000000 --- a/docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json +++ /dev/null @@ -1,444 +0,0 @@ -{ - "meta": { - "schema_version": 3, - "feature": "env_var_taxonomy_and_override_split", - "cross_platform": true, - "execution_gates": true, - "automation": { - "enabled": true, - "orchestration_branch": "feat/env_var_taxonomy_and_override_split" - }, - "platforms_required": [ - "linux", - "macos", - "windows" - ], - "wsl_required": false, - "external_task_ids": [ - "PCP0-integ" - ] - }, - "tasks": [ - { - "id": "F0-exec-preflight", - "name": "Execution preflight gate (feature start)", - "type": "ops", - "phase": "Feature Gates", - "status": "completed", - "description": "Run the execution preflight gate and fill execution_preflight_report.md before starting EV0 triads.", - "references": [ - "docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/execution_preflight_report.md", - "docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/tasks.json", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/session_log.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1" - ], - "acceptance_criteria": [ - "execution_preflight_report.md contains a concrete recommendation (ACCEPT or REVISE)", - "If the recommendation is REVISE, EV0 triads do not start until the listed issues are resolved and preflight is re-run" - ], - "start_checklist": [ - "Run: make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read ADR + plan/spec/playbook + this kickoff prompt", - "Set F0-exec-preflight status to in_progress in tasks.json; add START entry to session_log.md; commit docs" - ], - "end_checklist": [ - "Fill execution_preflight_report.md with ACCEPT/REVISE and any required fixes", - "Set F0-exec-preflight status to completed in tasks.json; add END entry to session_log.md; commit docs" - ], - "worktree": null, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/F0-exec-preflight.md", - "depends_on": [ - "PCP0-integ" - ], - "concurrent_with": [] - }, - { - "id": "EV0-code", - "name": "Override split for effective config (code)", - "type": "code", - "phase": "Env Var Override Split", - "status": "pending", - "description": "Implement the override split for effective config resolution (production code only).", - "references": [ - "docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/plan.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/decision_register.md (DR-0001, DR-0002, DR-0003)", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/integration_map.md", - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md", - "docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md", - "docs/project_management/standards/EXIT_CODE_TAXONOMY.md" - ], - "acceptance_criteria": [ - "Effective config reads only SUBSTRATE_OVERRIDE_* for config-shaped env override inputs", - "Effective config does not read config-shaped SUBSTRATE_* exported-state values as override inputs", - "Invalid override values return user errors with messages naming the SUBSTRATE_OVERRIDE_* variable", - "A repo-wide grep/audit is performed to locate any non-test config-shaped SUBSTRATE_* reads outside the resolver; any behavior-changing input reads are removed or rewired to effective config / SUBSTRATE_OVERRIDE_* (findings handed off to EV0-integ)" - ], - "start_checklist": [ - "git checkout feat/env_var_taxonomy_and_override_split && git pull --ff-only", - "Read plan/spec/decision_register/integration_map for EV0 and this prompt", - "Run the required repo-wide grep/audit from EV0-spec.md and identify any non-test config-shaped SUBSTRATE_* input reads outside the resolver (capture hits + disposition for EV0-integ)", - "Update tasks.json status to in_progress and add START entry to session_log.md; commit docs on orchestration branch", - "Run: make triad-task-start-pair FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" SLICE_ID=\"EV0\" LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Run cargo fmt", - "Run cargo clippy --workspace --all-targets -- -D warnings", - "Run a targeted baseline test set before and after changes", - "Hand off repo audit hits/disposition to the operator (do not edit planning docs inside the worktree)", - "Commit worktree changes to the task branch", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-code\"" - ], - "git_branch": "ev-ev0-override-split-code", - "required_make_targets": [ - "triad-code-checks" - ], - "worktree": "wt/ev0-override-split-code", - "integration_task": "EV0-integ-core", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-code.md", - "depends_on": [ - "F0-exec-preflight" - ], - "concurrent_with": [ - "EV0-test" - ] - }, - { - "id": "EV0-test", - "name": "Override split for effective config (tests)", - "type": "test", - "phase": "Env Var Override Split", - "status": "pending", - "description": "Add/update tests that lock the override split behavior (tests only).", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/adrs/implemented/ADR-0006-env-var-taxonomy-and-override-split.md", - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md", - "docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" - ], - "acceptance_criteria": [ - "Tests fail deterministically on current code and pass once EV0-code is merged", - "Tests cover: exported-state SUBSTRATE_* does not override; SUBSTRATE_OVERRIDE_* does override; workspace config wins over overrides", - "Tests cover at least two non-policy keys (minimum: world.caged and world.anchor_mode) in addition to policy.mode" - ], - "start_checklist": [ - "git checkout feat/env_var_taxonomy_and_override_split && git pull --ff-only", - "Read EV0-spec.md and this prompt", - "Update tasks.json status to in_progress and add START entry to session_log.md; commit docs on orchestration branch", - "Run: make triad-task-start-pair FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" SLICE_ID=\"EV0\" LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Run cargo fmt", - "Run the targeted tests you add/modify", - "Ensure the test suite covers policy.mode plus at least world.caged and world.anchor_mode per EV0-spec.md", - "Commit worktree changes to the task branch", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-test\"" - ], - "git_branch": "ev-ev0-override-split-test", - "required_make_targets": [ - "triad-test-checks" - ], - "worktree": "wt/ev0-override-split-test", - "integration_task": "EV0-integ-core", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-test.md", - "depends_on": [ - "F0-exec-preflight" - ], - "concurrent_with": [ - "EV0-code" - ] - }, - { - "id": "EV0-integ-core", - "name": "Override split for effective config (integration core)", - "type": "integration", - "phase": "Env Var Override Split", - "status": "completed", - "description": "Merge EV0 code+tests, make the slice green on the primary dev platform, and dispatch cross-platform smoke via CI.", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md", - "docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md", - "docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" - ], - "acceptance_criteria": [ - "Merged EV0 code+tests pass fmt, clippy, relevant tests, and make integ-checks", - "Cross-platform smoke is dispatched and run ids/URLs are recorded in session_log.md", - "Smoke/manual validation covers policy.mode plus multiple non-policy keys (minimum: world.caged and world.anchor_mode) so partial implementations cannot pass", - "Repo-wide grep/audit results are summarized and prepared for inclusion in EV0-closeout_report.md (fixed / derived-state-only / test-only)" - ], - "start_checklist": [ - "make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read EV0-spec.md, integration_map.md, and this prompt", - "Set status to in_progress; add START entry; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" TASK_ID=\"EV0-integ-core\" LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge EV0-code and EV0-test branches into EV0-integ-core", - "Run cargo fmt", - "Run cargo clippy --workspace --all-targets -- -D warnings", - "Run relevant tests", - "Run make integ-checks", - "Confirm smoke scripts validate policy.mode plus world.caged and world.anchor_mode (and that manual playbook matches the smoke behavior)", - "Dispatch smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/env_var_taxonomy_and_override_split\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "Record run ids/URLs in session_log.md", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-integ-core\"" - ], - "git_branch": "ev-ev0-override-split-integ-core", - "required_make_targets": [ - "integ-checks" - ], - "merge_to_orchestration": false, - "worktree": "wt/ev0-override-split-integ-core", - "integration_task": "EV0-integ-core", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-core.md", - "depends_on": [ - "EV0-code", - "EV0-test" - ], - "concurrent_with": [] - }, - { - "id": "EV0-integ-linux", - "name": "Override split for effective config (integration Linux)", - "type": "integration", - "phase": "Env Var Override Split", - "status": "completed", - "description": "Linux platform-fix integration task (may be a no-op if already green).", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh", - "docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md", - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md" - ], - "acceptance_criteria": [ - "linux smoke is green for this slice" - ], - "start_checklist": [ - "Run on linux host if possible", - "make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read EV0-spec.md and kickoff prompt", - "Set status to in_progress; add START entry; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" TASK_ID=\"EV0-integ-linux\" TASK_PLATFORM=linux LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge EV0-integ-core branch into this worktree branch", - "Dispatch platform smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" PLATFORM=linux RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/env_var_taxonomy_and_override_split\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "If needed: fix + fmt/clippy + targeted tests", - "Ensure smoke is green; record run id/URL", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-integ-linux\"" - ], - "git_branch": "ev-ev0-override-split-integ-linux", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "worktree": "wt/ev0-override-split-integ-linux", - "integration_task": "EV0-integ-linux", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-linux.md", - "depends_on": [ - "EV0-integ-core" - ], - "concurrent_with": [], - "platform": "linux", - "runner": "github-actions", - "workflow": ".github/workflows/feature-smoke.yml" - }, - { - "id": "EV0-integ-macos", - "name": "Override split for effective config (integration macOS)", - "type": "integration", - "phase": "Env Var Override Split", - "status": "completed", - "description": "macOS platform-fix integration task (may be a no-op if already green).", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh", - "docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md", - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md" - ], - "acceptance_criteria": [ - "macos smoke is green for this slice" - ], - "start_checklist": [ - "Run on macos host if possible", - "make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read EV0-spec.md and kickoff prompt", - "Set status to in_progress; add START entry; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" TASK_ID=\"EV0-integ-macos\" TASK_PLATFORM=macos LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge EV0-integ-core branch into this worktree branch", - "Dispatch platform smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" PLATFORM=macos RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/env_var_taxonomy_and_override_split\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "If needed: fix + fmt/clippy + targeted tests", - "Ensure smoke is green; record run id/URL", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-integ-macos\"" - ], - "git_branch": "ev-ev0-override-split-integ-macos", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "worktree": "wt/ev0-override-split-integ-macos", - "integration_task": "EV0-integ-macos", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-macos.md", - "depends_on": [ - "EV0-integ-core" - ], - "concurrent_with": [], - "platform": "macos", - "runner": "github-actions", - "workflow": ".github/workflows/feature-smoke.yml" - }, - { - "id": "EV0-integ-windows", - "name": "Override split for effective config (integration Windows)", - "type": "integration", - "phase": "Env Var Override Split", - "status": "completed", - "description": "Windows platform-fix integration task (may be a no-op if already green).", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1", - "docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md", - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md" - ], - "acceptance_criteria": [ - "windows smoke is green for this slice" - ], - "start_checklist": [ - "Run on windows host if possible", - "make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read EV0-spec.md and kickoff prompt", - "Set status to in_progress; add START entry; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" TASK_ID=\"EV0-integ-windows\" TASK_PLATFORM=windows LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge EV0-integ-core branch into this worktree branch", - "Dispatch platform smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" PLATFORM=windows RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/env_var_taxonomy_and_override_split\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "If needed: fix + fmt/clippy + targeted tests", - "Ensure smoke is green; record run id/URL", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-integ-windows\"" - ], - "git_branch": "ev-ev0-override-split-integ-windows", - "required_make_targets": [ - "triad-code-checks" - ], - "merge_to_orchestration": false, - "worktree": "wt/ev0-override-split-integ-windows", - "integration_task": "EV0-integ-windows", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ-windows.md", - "depends_on": [ - "EV0-integ-core" - ], - "concurrent_with": [], - "platform": "windows", - "runner": "github-actions", - "workflow": ".github/workflows/feature-smoke.yml" - }, - { - "id": "EV0-integ", - "name": "Override split for effective config (integration final)", - "type": "integration", - "phase": "Env Var Override Split", - "status": "pending", - "description": "Final integration aggregator: merge platform-fix work, re-run integration gates, confirm cross-platform smoke is green, and complete EV0-closeout_report.md.", - "references": [ - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-spec.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/EV0-closeout_report.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/manual_testing_playbook.md", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/linux-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/macos-smoke.sh", - "docs/project_management/_archived/env_var_taxonomy_and_override_split/smoke/windows-smoke.ps1", - "docs/CONFIGURATION.md", - "docs/ENVIRONMENT_VARIABLES.md", - "docs/project_management/standards/SLICE_CLOSEOUT_GATE_STANDARD.md", - "docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md", - "docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" - ], - "acceptance_criteria": [ - "All required platforms are green in smoke runs for this slice", - "make integ-checks passes on the final merged integration commit", - "EV0-closeout_report.md is completed with evidence (including repo-wide grep/audit summary) and run ids/URLs", - "docs/CONFIGURATION.md and docs/ENVIRONMENT_VARIABLES.md reflect the SUBSTRATE_OVERRIDE_* override split" - ], - "start_checklist": [ - "make triad-orch-ensure FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\"", - "Read EV0-spec.md and kickoff prompt", - "Set status to in_progress; add START entry; commit docs", - "Run: make triad-task-start FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" TASK_ID=\"EV0-integ\" LAUNCH_CODEX=1" - ], - "end_checklist": [ - "Merge EV0-integ-core and any platform-fix integration branches into EV0-integ", - "Run cargo fmt", - "Run cargo clippy --workspace --all-targets -- -D warnings", - "Run relevant tests", - "Run make integ-checks", - "Re-run cross-platform smoke via CI: make feature-smoke FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" PLATFORM=all RUNNER_KIND=self-hosted WORKFLOW_REF=\"feat/env_var_taxonomy_and_override_split\" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1", - "Update docs/CONFIGURATION.md and docs/ENVIRONMENT_VARIABLES.md to document SUBSTRATE_OVERRIDE_* as the override-input namespace (and SUBSTRATE_* as exported state)", - "Complete EV0-closeout_report.md including repo-wide grep/audit evidence and the smoke key coverage summary", - "From inside the worktree: make triad-task-finish TASK_ID=\"EV0-integ\"" - ], - "git_branch": "ev-ev0-override-split-integ", - "required_make_targets": [ - "integ-checks" - ], - "merge_to_orchestration": true, - "worktree": "wt/ev0-override-split-integ", - "integration_task": "EV0-integ", - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/EV0-integ.md", - "depends_on": [ - "EV0-integ-core", - "EV0-integ-linux", - "EV0-integ-macos", - "EV0-integ-windows" - ], - "concurrent_with": [] - }, - { - "id": "FZ-feature-cleanup", - "name": "Feature cleanup (remove worktrees)", - "type": "ops", - "phase": "Feature Gates", - "status": "pending", - "description": "Remove retained worktrees and optionally prune task branches after the feature is complete.", - "references": [ - "docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md", - "docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" - ], - "acceptance_criteria": [ - "All retained worktrees are removed (or a dry-run report is captured if DRY_RUN=1)", - "No dirty worktrees remain for this feature" - ], - "start_checklist": [ - "Ensure all tasks are completed and orchestration branch is clean", - "Set status to in_progress; add START entry; commit docs" - ], - "end_checklist": [ - "Run cleanup: make triad-feature-cleanup FEATURE_DIR=\"docs/project_management/_archived/env_var_taxonomy_and_override_split\" REMOVE_WORKTREES=1 PRUNE_LOCAL=1", - "Set status to completed; add END entry with cleanup output summary; commit docs" - ], - "worktree": null, - "integration_task": null, - "kickoff_prompt": "docs/project_management/_archived/env_var_taxonomy_and_override_split/kickoff_prompts/FZ-feature-cleanup.md", - "depends_on": [ - "EV0-integ" - ], - "concurrent_with": [] - } - ] -} diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-closeout_report.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-closeout_report.md deleted file mode 100644 index 0d579b6e5..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-closeout_report.md +++ /dev/null @@ -1,63 +0,0 @@ -# Slice Closeout Gate Report — full-isolation-landlock-overlayfs-compat / C0 - -Date (UTC): 2026-01-20T01:52:53Z - -Standards: -- `docs/project_management/standards/SLICE_CLOSEOUT_GATE_STANDARD.md` -- `docs/project_management/standards/EXECUTIVE_SUMMARY_STANDARD.md` (behavior delta format) - -Feature directory: -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat` - -Slice spec: -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` - -## Behavior Delta (Existing → New → Why) - -- Existing behavior: with `world_fs.isolation=full` and `world_fs.mode=writable`, allowlisted project writes can fail with `Operation not permitted` when Landlock is supported and overlayfs is the active filesystem strategy. -- New behavior: allowlisted project writes succeed consistently under full isolation with Landlock enabled; non-allowlisted writes remain denied. -- Why: Landlock must allow overlayfs internal backing directory writes (`upperdir` / `workdir`) for overlayfs to service allowlisted project writes. -- Links: - - `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - - `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` - - `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/decision_register.md (DR-0001, DR-0002, DR-0003, DR-0004)` - -## Spec Parity (No Drift) - -- [x] Acceptance criteria satisfied -- [x] Any spec changes during the slice are recorded (with rationale) - -## Checks Run (Evidence) - -- `cargo fmt`: pass -- `cargo clippy --workspace --all-targets -- -D warnings`: pass -- Relevant tests: pass (`cargo test` via `make integ-checks`) -- `make integ-checks`: pass -- CI compile parity: `RUN_ID=21173624758` (`https://github.com/atomize-hq/substrate/actions/runs/21173624758`) - -## Cross-Platform Smoke (if applicable) - -Record run ids/URLs for required platforms: -- Linux: - - `RUN_ID=21183298683` (`https://github.com/atomize-hq/substrate/actions/runs/21183298683`) — job `linux_self_hosted` succeeded -- macOS: - - `RUN_ID=21183298683` (`https://github.com/atomize-hq/substrate/actions/runs/21183298683`) — job `macos_self_hosted` succeeded -- Windows: n/a for behavior smoke (CI parity covered by `RUN_ID=21173624758`) -- WSL: n/a - -If any platform-fix work was required: -- What failed: - - Feature smoke `RUN_ID=21173728283` (`https://github.com/atomize-hq/substrate/actions/runs/21173728283`) — failed on `linux_self_hosted` + `macos_self_hosted` - - Feature smoke `RUN_ID=21183010775` (`https://github.com/atomize-hq/substrate/actions/runs/21183010775`) — failed -- What was changed: - - Fixes landed on `feat/full-isolation-landlock-overlayfs-compat` and smoke reran green (`RUN_ID=21183298683`). -- Why the change is safe (guards, cfg, feature flags): - - Verified by CI compile parity (`RUN_ID=21173624758`) and CI smoke (`RUN_ID=21183298683`) on the required behavior platforms (Linux + macOS). - -## Smoke ↔ Manual Parity - -- [x] Smoke scripts run the same commands/workflows as the manual testing playbook (minimal viable subset) -- [x] Smoke scripts validate exit codes and key output (not just “command ran”) - -Notes: -- Feature smoke (passing): `RUN_ID=21183298683` (`https://github.com/atomize-hq/substrate/actions/runs/21183298683`) diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md deleted file mode 100644 index d7798204e..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md +++ /dev/null @@ -1,127 +0,0 @@ -# C0-spec — Full isolation Landlock ↔ OverlayFS backing dirs allowlist - -Authoritative ADR: -- `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -Exit codes: -- Exit code taxonomy: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -## Scope -- Behavior is Linux-kernel-specific; this slice is validated on: - - Linux hosts, and - - macOS hosts via the Lima Linux guest (world backend). -- Restore the operator contract for `world_fs.write_allowlist` in: - - `world_fs.isolation=full` - - `world_fs.mode=writable` - - Landlock supported by the running kernel - - overlayfs is the active world filesystem strategy -- Extend the full-isolation Landlock write allowlist with runtime-derived overlayfs internal write roots: - - `upperdir` - - `workdir` -- Add fixture-based unit tests for mountinfo parsing in `crates/world`. -- Add or update world-agent integration coverage to ensure allowlisted writes succeed under full isolation when Landlock is supported. - -## Non-Goals -- Policy snapshot schema changes or policy snapshot hash behavior changes. -- Any new allowlist syntax or matching semantics. -- Any behavior changes on macOS or Windows. - -## Inputs (authoritative) -- Environment: - - `SUBSTRATE_MOUNT_PROJECT_DIR`: absolute project mountpoint inside the active mount namespace. -- Procfs: - - `/proc/self/mountinfo` (preferred and required for this slice). -- Policy-derived inputs (already present; no schema changes): - - `world_fs.write_allowlist` (project-relative glob patterns). - - The resolved Landlock allowlists injected by the world-agent (`SUBSTRATE_WORLD_FS_LANDLOCK_*_ALLOWLIST`). - -## Behavior (authoritative) - -### Runtime derivation: overlayfs backing dirs from mountinfo -- When all conditions are true: - - isolation is full - - filesystem mode is writable - - Landlock is supported and will be applied for the exec - - `SUBSTRATE_MOUNT_PROJECT_DIR` is set -- The world-agent Landlock exec wrapper MUST: - 1. Read `/proc/self/mountinfo` as text. - 2. Find the mount entry whose mountpoint equals `SUBSTRATE_MOUNT_PROJECT_DIR`. - - If multiple entries match exactly, select the entry with the greatest numeric mount id. - 3. Require that the selected entry has: - - `fs_type == "overlay"`, and - - `super_options` contains both `upperdir=` and `workdir=` keys. - 4. Interpret the `upperdir` and `workdir` values as absolute paths in the current mount namespace. - 5. Decode mountinfo escape sequences in these values: - - `\\040` → space - - `\\011` → tab - - `\\012` → newline - - `\\134` → backslash - 6. Return the two resolved paths as the overlayfs internal write roots for this exec. - -### Landlock allowlist extension -- When overlayfs internal write roots are derived successfully, the Landlock exec wrapper MUST extend the Landlock write allowlist by adding exactly these two directories: - - `upperdir` - - `workdir` -- These derived paths MUST NOT be added to: - - policy snapshot schema - - policy snapshot hash inputs - - any on-disk policy/config files - -### Enforcement invariants (must hold) -- Allowlisted project writes succeed: - - If `world_fs.write_allowlist` covers a project-relative prefix, writes under that prefix succeed (subject to normal command behavior). -- Non-allowlisted project writes are denied: - - If the target path is not covered by `world_fs.write_allowlist`, the write is denied. -- Derived internal write roots are scoped: - - The added Landlock write allowlist entries are limited to the active session’s derived `upperdir` and `workdir` paths. - - The implementation MUST NOT add broad allowlists such as `/var/lib/substrate/overlay` or `/var/lib/substrate`. - -## Error handling (authoritative) - -### Landlock unsupported -- If Landlock is not supported by the running kernel, this slice introduces no new failure mode: - - the wrapper does not derive overlay backing dirs, - - full isolation enforcement continues using mount semantics only. - -### Landlock supported, derivation fails (fail closed) -- If Landlock is supported and any required derivation input is missing or invalid: - - `SUBSTRATE_MOUNT_PROJECT_DIR` is missing/empty - - `/proc/self/mountinfo` cannot be read - - no mount entry matches the mountpoint - - the matching entry is not `fs_type="overlay"` - - `upperdir` or `workdir` is missing -- The exec MUST fail closed: - - the command does not execute - - the failure is surfaced as an actionable “missing prerequisites / not supported” failure for this environment: - - exit code: `4` -- The error message MUST include: - - the mountpoint value (`SUBSTRATE_MOUNT_PROJECT_DIR`) - - the specific missing requirement (no match, wrong fs_type, missing upperdir/workdir) - - a short remediation hint: “this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo” - -## Validation plan (authoritative) - -### Unit tests (Linux-only) -- Add fixture-based tests for mountinfo parsing in `crates/world`: - - A fixture with an overlay mount entry for the project mountpoint returns the expected `upperdir` and `workdir`. - - A fixture with a non-overlay entry for the project mountpoint returns a deterministic error. - - A fixture missing `upperdir` or `workdir` returns a deterministic error. - -### Integration tests (Linux-only) -- Update or add `crates/world-agent` tests so that when overlayfs is available and Landlock is supported: - - allowlisted writes succeed in full isolation (`world_fs.mode=writable`, `world_fs.isolation=full`) - - denied writes remain denied - - the host project directory is not mutated by allowlisted writes (writes remain in overlay backing dirs) - -### Smoke (behavior platforms: Linux + macOS) -- Linux smoke (`docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh`) MUST: - - require that `substrate world doctor --json` reports `world.landlock.supported=true` and `world.world_fs_strategy.primary="overlay"` - - run an allowlisted write that fails on the pre-fix behavior and succeeds after this slice - - run a denied write that remains denied -- macOS smoke (`docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh`) MUST: - - require that `substrate world doctor --json` reports `world.landlock.supported=true` and `world.world_fs_strategy.primary="overlay"` - - run the same allowlisted write + denied write checks as the Linux smoke, via the macOS host → Lima guest world backend path - -## Out of scope -- Any changes to how `world_fs.write_allowlist` patterns are interpreted or canonicalized. -- Any changes to macOS (Lima) or Windows (WSL) world backends. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/decision_register.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/decision_register.md deleted file mode 100644 index ce2ad2a61..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/decision_register.md +++ /dev/null @@ -1,199 +0,0 @@ -# Decision Register — Full Isolation Landlock ↔ OverlayFS Compatibility - -This decision register scopes decisions required to restore the `world_fs.write_allowlist` contract -in `world_fs.isolation=full` when Linux Landlock enforcement is enabled and the active filesystem -strategy uses overlayfs backing dirs (`upperdir` / `workdir`). - -Related ADR: -- `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - ---- - -### DR-0001 — Full Isolation: Landlock Runtime Allowlist for OverlayFS Backing Dirs - -**Decision owner(s):** Substrate core team -**Date:** 2026-01-20 -**Status:** Accepted -**Related docs:** `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -**Problem / Context** -- In full isolation on Linux, the command process runs under an applied Landlock policy. -- When using overlayfs, project writes that appear to target `/project/` are serviced via - overlayfs backing dirs (`upperdir` / `workdir`). -- If Landlock does not allow the overlay backing dirs, allowlisted project writes fail with `EPERM` - even when mount-level allowlist remounting is correct. -- This runtime state must not be represented in the policy snapshot schema/hash (it is per-session). - -**Option A — Derive overlay backing dirs at runtime via procfs mount inspection** -- **Pros:** No policy surface area expansion; works with policy snapshots; robust under version skew; keeps runtime-derived state out of snapshot hashes. -- **Cons:** Requires Linux-only parsing logic for `/proc/self/mountinfo` (preferred) or `/proc/self/mounts`; needs careful error messaging. -- **Cascading implications:** World-agent Landlock wrapper must read mount metadata and extend allowlists dynamically. -- **Risks:** Incorrect parsing could over-allow or under-allow; mitigate with fixture tests and fail-closed behavior. -- **Unlocks:** Generalizes to other filesystem strategies that have internal write roots (future). -- **Quick wins / low-hanging fruit:** Implement a helper in `crates/world` and reuse it from the Landlock exec wrapper. - -**Option B — Plumb overlay backing dirs via explicit env vars from the world backend** -- **Pros:** Avoids procfs parsing; uses already-known overlay state paths from the backend. -- **Cons:** Requires new env var contracts and additional plumbing across execution paths (non-PTY + PTY); increases “ambient” runtime surface area. -- **Cascading implications:** Requires keeping env propagation consistent across platforms/backends; requires versioning if treated as a stable contract. -- **Risks:** Env propagation drift could silently break enforcement; needs strong invariants and tests. -- **Unlocks:** Enables backends to provide strategy-specific internal roots without procfs dependence. -- **Quick wins / low-hanging fruit:** Add env var(s) only as an internal implementation detail, not as a documented stable interface. - -**Recommendation** -- **Selected:** Option A — Derive overlay backing dirs at runtime via procfs mount inspection -- **Rationale (crisp):** Overlay backing dirs are session-specific runtime state; procfs-based derivation keeps the policy snapshot deterministic while restoring allowlisted writability under Landlock. - -**Follow-up tasks (explicit)** -- Implement Linux-only mount inspection helper (prefer `/proc/self/mountinfo`) in `crates/world`. -- Extend `crates/world-agent/src/internal_exec.rs` to include derived overlay backing dirs in the full isolation Landlock policy write allowlist. -- Add fixture-based unit tests for mount parsing and an integration test gated on Landlock support that asserts allowlisted writes succeed under full isolation. - ---- - -### DR-0002 — Where overlay mountinfo parsing lives (world crate helper vs world-agent local) - -**Decision owner(s):** Substrate core team -**Date:** 2026-01-20 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md`, `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -**Problem / Context** -- The Landlock exec wrapper must derive overlayfs `upperdir` and `workdir` for the project mountpoint to extend the Landlock write allowlist. -- Multiple components can benefit from mountinfo parsing utilities; duplicating parsing logic increases drift risk. - -**Option A — Add a Linux-only helper in `crates/world` (selected)** -- **Pros:** Single implementation reused by world-agent and future world components; enables fixture tests in one crate; keeps Linux-only parsing behind `#[cfg]`. -- **Cons:** Adds a helper API surface to `crates/world` that must remain minimal and well-scoped. -- **Cascading implications:** `crates/world-agent` depends on `crates/world` for mountinfo parsing logic used by the Landlock wrapper. -- **Risks:** If the helper API grows beyond mountinfo parsing, it can become a grab bag; mitigate by limiting scope to overlay backing dir derivation. -- **Unlocks:** A shared implementation point for future “strategy internal roots” derivations. -- **Quick wins / low-hanging fruit:** Implement mountinfo parsing as a pure function over text fixtures and reuse it in world-agent. - -**Option B — Implement mountinfo parsing only inside `crates/world-agent`** -- **Pros:** Keeps the helper local to the one caller; avoids adding any new helper surface to `crates/world`. -- **Cons:** Duplicates Linux parsing utilities if other crates need them later; increases drift risk across exec paths (PTY vs non-PTY). -- **Cascading implications:** Any future caller must either duplicate parsing or move it later under time pressure. -- **Risks:** Two independent parsers can diverge and produce different allowlists under the same mount topology. -- **Unlocks:** A smaller immediate change footprint for this slice. -- **Quick wins / low-hanging fruit:** Directly parse `/proc/self/mountinfo` in the wrapper. - -**Recommendation** -- **Selected:** Option A — Add a Linux-only helper in `crates/world` -- **Rationale (crisp):** A single mountinfo parser reduces drift risk and enables fixture-based correctness tests in one place. - -**Follow-up tasks (explicit)** -- `C0-code`: add the Linux-only mountinfo helper in `crates/world` and use it from the Landlock exec wrapper. -- `C0-test`: add fixture-based tests for the helper in `crates/world`. - ---- - -### DR-0003 — Landlock allowlist scope for overlayfs backing dirs (exact dirs vs broader parent) - -**Decision owner(s):** Substrate core team -**Date:** 2026-01-20 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md`, `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -**Problem / Context** -- The overlayfs implementation requires writes to its `upperdir` and `workdir` for allowlisted project writes to succeed. -- The Landlock write allowlist extension must be as narrow as possible while reliably enabling overlayfs writes. - -**Option A — Allow exactly `upperdir` and `workdir` (selected)** -- **Pros:** Minimal permission expansion; scopes the allowlist to session-derived internal roots; aligns with fail-closed posture. -- **Cons:** If overlayfs behavior changes to require additional internal paths, the allowlist will need an explicit update. -- **Cascading implications:** The mountinfo parser must return both `upperdir` and `workdir` and the wrapper must add both. -- **Risks:** Under-allowing causes false-deny failures; mitigate with the Linux smoke and full isolation integration tests. -- **Unlocks:** A general “derive exact internal roots” pattern for other filesystem strategies. -- **Quick wins / low-hanging fruit:** Add these two paths only and verify allowlisted writes succeed. - -**Option B — Allow the parent overlay state directory (e.g., the enclosing `/var/lib/substrate/overlay//...`)** -- **Pros:** More resilient if overlayfs uses additional internal files under the same state dir. -- **Cons:** Broader permission than necessary; increases the blast radius of the Landlock allowlist in the event the path becomes nameable. -- **Cascading implications:** Requires careful derivation of the “correct” parent directory and guardrails to avoid accidentally allowing `/var/lib/substrate/overlay` broadly. -- **Risks:** Over-allowing weakens hardening and can mask unintended nameability of internal paths. -- **Unlocks:** Fewer future updates if overlayfs internal structure changes. -- **Quick wins / low-hanging fruit:** One allowlist entry instead of two. - -**Recommendation** -- **Selected:** Option A — Allow exactly `upperdir` and `workdir` -- **Rationale (crisp):** Narrow, session-scoped allowlists restore correctness without expanding the Landlock surface beyond what overlayfs requires. - -**Follow-up tasks (explicit)** -- `C0-code`: extend the Landlock write allowlist with `upperdir` and `workdir` only. -- `C0-test`: add fixture cases that verify both keys are required and errors are deterministic when either is missing. - ---- - -### DR-0004 — Failure mode when Landlock is supported but overlay backing dirs cannot be derived (fail closed vs degrade) - -**Decision owner(s):** Substrate core team -**Date:** 2026-01-20 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md`, `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -**Problem / Context** -- If Landlock is supported but the wrapper cannot derive overlay backing dirs, allowlisted writes will fail with `EPERM`. -- A partial or silent fallback undermines the operator contract and can introduce security ambiguity. - -**Option A — Fail closed (selected)** -- **Pros:** Preserves the operator contract; avoids unsafe “best-effort” behavior under full isolation; produces a high-signal diagnostic. -- **Cons:** Introduces a new hard failure mode for environments with unexpected mount topologies. -- **Cascading implications:** The wrapper must surface a deterministic, actionable error and block exec. -- **Risks:** Operators in unusual environments hit failures; mitigated by diagnostics and by limiting to the “Landlock supported + full isolation + writable + overlay” case. -- **Unlocks:** Prevents silent “allowlist says writable but runtime denies” drift. -- **Quick wins / low-hanging fruit:** Treat missing mountinfo data as a missing prerequisite and return early. - -**Option B — Degrade by disabling Landlock for this exec and proceeding with mount-only enforcement** -- **Pros:** Keeps allowlisted writes working (overlayfs backing dirs are not blocked); avoids introducing a hard failure in unusual mount topologies. -- **Cons:** Explicitly weakens hardening for this exec: Landlock is not applied even though supported by the kernel. -- **Cascading implications:** The wrapper must implement a deterministic “Landlock disabled for this exec” path and emit a high-signal warning/trace field so operators can audit the downgrade. -- **Risks:** Reduces isolation hardening for this exec; must ensure mount-only enforcement remains correct and does not regress deny semantics. -- **Unlocks:** Provides an availability-first escape hatch while preserving deterministic user-visible behavior (writes succeed/deny as dictated by mount semantics). -- **Quick wins / low-hanging fruit:** Add a single guarded downgrade path when derivation fails, without broad allowlist expansion. - -**Recommendation** -- **Selected:** Option A — Fail closed -- **Rationale (crisp):** Full isolation requires a deterministic enforcement story; failing closed prevents unsafe drift and forces actionable diagnostics. - -**Follow-up tasks (explicit)** -- `C0-code`: return an actionable “missing prerequisites” error when derivation fails under the defined conditions. -- `C0-test`: add a test case that asserts a deterministic error path for missing `upperdir`/`workdir` in fixtures. - ---- - -### DR-0005 — Cross-platform task scope (Linux behavior-only vs full behavior parity) - -**Decision owner(s):** Substrate core team -**Date:** 2026-01-20 -**Status:** Accepted -**Related docs:** `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/*` - -**Problem / Context** -- This feature changes Linux full-isolation behavior because it depends on Linux Landlock and overlayfs mount semantics. -- The repository still requires compile parity on macOS and Windows. - -**Option A — Linux is the only behavior platform; macOS/Windows are CI parity only** -- **Pros:** Smallest behavioral validation surface; requires only a Linux runner to validate the kernel-specific Landlock+overlayfs behavior. -- **Cons:** Does not validate the macOS host path (Lima guest) for the same behavior; macOS regressions can slip through until later. -- **Cascading implications:** `tasks.json` uses `behavior_platforms_required=["linux"]` and `ci_parity_platforms_required=["linux","macos","windows"]`. -- **Risks:** macOS-specific drift (host → guest plumbing, doctor fields, or config/policy UX) is not caught by smoke for this feature. -- **Unlocks:** Keeps smoke focused on the simplest environment. -- **Quick wins / low-hanging fruit:** Use the existing Linux smoke script only. - -**Option B — Linux + macOS are behavior platforms; Windows is CI parity only (selected)** -- **Pros:** Validates the same kernel behavior on the macOS host path (via the Lima Linux guest) while keeping Windows as compile parity-only where the feature’s kernel behavior is not directly validated. -- **Cons:** Requires a macOS smoke script that exercises the Linux guest behavior and a self-hosted macOS runner (or an explicitly approved hosted fallback) to run it. -- **Cascading implications:** `tasks.json` uses `behavior_platforms_required=["linux","macos"]` and `ci_parity_platforms_required=["linux","macos","windows"]`; macOS platform-fix task becomes smoke-gated. -- **Risks:** Runner provisioning/availability becomes a gating dependency for this feature’s execution; mitigated by preflight runner checks. -- **Unlocks:** Catches regressions in the macOS host→guest world execution path for full isolation. -- **Quick wins / low-hanging fruit:** Replace the macOS no-op smoke with a real smoke that mirrors Linux validation via `substrate --world ...`. - -**Recommendation** -- **Selected:** Option B — Linux + macOS are behavior platforms; Windows is CI parity only -- **Rationale (crisp):** The behavior is Linux-kernel-specific, but macOS runs the Linux world via Lima; smoke should validate the macOS host→guest path while keeping Windows as compile parity-only. - -**Follow-up tasks (explicit)** -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`: set `meta.behavior_platforms_required=["linux","macos"]` and keep `meta.ci_parity_platforms_required=["linux","macos","windows"]`. -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh`: replace the no-op with a real smoke that mirrors the Linux validation. -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/windows-smoke.ps1`: exit `0` as a defined no-op. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md deleted file mode 100644 index 9b3d30786..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md +++ /dev/null @@ -1,98 +0,0 @@ -# Execution Preflight Gate Report — full-isolation-landlock-overlayfs-compat - -Date (UTC): 2026-01-20T03:07:08Z - -Standard: -- `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` - -Feature directory: -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat` - -## Recommendation - -RECOMMENDATION: ACCEPT - -## Inputs Reviewed - -- [x] Planning quality gate is `ACCEPT` (`docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/quality_gate_report.md`) -- [x] ADR accepted and still matches intent (`docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md`) -- [x] Planning Pack complete (`plan.md`, `tasks.json`, `session_log.md`, specs, kickoff prompts) -- [x] Triad sizing is one behavior delta (no mixed independent deltas) -- [x] Required planning artifacts exist: `decision_register.md`, `integration_map.md`, `manual_testing_playbook.md`, `smoke/*` -- [x] Cross-platform plan is explicit (`tasks.json` meta: behavior + CI parity platforms) - -## 0) Slice Sizing (one behavior delta each) - -- Slices reviewed: - - C0 (`docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md`) -- Any required splits before starting execution: - - None - -## 1) Cross-Platform Coverage (explicit and correct) - -From `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json` meta: -- Declared behavior platforms (smoke required): `["linux","macos"]` -- Declared CI parity platforms (parity required): `["linux","macos","windows"]` -- WSL required: `false` (not declared; treated as not required) -- WSL task mode: N/A (not required) - -Notes: -- If WSL coverage is required, confirm `meta.wsl_required=true` and `meta.wsl_task_mode` is set correctly. -- If using the platform-fix integration model, confirm tasks exist per slice: - - `X-integ-core`, optional `X-integ-` (CI parity platforms + optional WSL task when `wsl_task_mode="separate"`), and `X-integ` final. - -## 2) Smoke Scripts Are Not “Toy” Checks - -Smoke scripts must be a runnable, minimal version of how a careful human would validate the feature. - -Manual playbook (when required): -- `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/manual_testing_playbook.md` - -Smoke scripts to validate (only required for behavior platforms; parity-only platforms may be explicit no-ops): -- Linux smoke: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh` -- macOS smoke: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh` -- Windows smoke: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/windows-smoke.ps1` - -Parity notes (map smoke ↔ manual; include concrete assertions): -- Manual step(s): - - Run `bash docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh`. - - Run `bash docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh`. -- Smoke command(s): - - `bash smoke/linux-smoke.sh` - - `bash smoke/macos-smoke.sh` -- Expected output/assertion(s): - - Exit `0`. - - Output contains `OK: allowlisted write succeeded` and `OK: denied write remained denied`. - -Gaps (must fix before execution begins): -- None. - -## 3) CI Dispatch Path Is Runnable (if applicable) - -Integration task dispatch commands (copy verbatim from `tasks.json` integration checklists): -- CI compile parity: -- `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` -- Feature Smoke dispatch: -- `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=behavior SMOKE_SLICE_ID="C0" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - -Runner readiness: -- Required self-hosted runners exist and are labeled correctly: - - Linux runner (`[self-hosted, Linux, linux-host]`) - - macOS runner (`[self-hosted, macOS]`) - - Verified via: `scripts/ci/check_self_hosted_runners.sh` (exit `0`) - -Run ids/URLs (if executed during preflight): -- CI compile parity: -- Not executed -- Linux smoke: -- Not executed -- macOS smoke: -- Not executed -- Windows smoke: -- Not required (Windows is CI parity-only for this feature) -- WSL smoke: -- Not required - -## 4) Required Fixes Before Starting C0 (if any) - -- None. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/integration_map.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/integration_map.md deleted file mode 100644 index bf33209df..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/integration_map.md +++ /dev/null @@ -1,47 +0,0 @@ -# Integration Map — Full isolation Landlock ↔ OverlayFS backing dirs allowlist - -## Scope -- Restore allowlisted project writes in full isolation on Linux when Landlock is supported and overlayfs is the active filesystem strategy. - -## Inputs → Derived state → Actions → Outputs - -### Inputs -- Policy (effective, already resolved and injected by the world-agent): - - `world_fs.isolation` - - `world_fs.mode` - - `world_fs.write_allowlist` - - Landlock allowlists exported to the exec wrapper: - - `SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST` - - `SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST` -- Runtime env: - - `SUBSTRATE_MOUNT_PROJECT_DIR` (project mountpoint inside the mount namespace) -- Procfs: - - `/proc/self/mountinfo` - -### Derived state -- `overlay_upperdir` and `overlay_workdir` for the project mountpoint, parsed from mountinfo `super_options`. - -### Actions -- World backend mounts (existing behavior): - - Construct full isolation rootfs and overlay view of the project. - - Remount only `world_fs.write_allowlist` prefixes as writable (mount semantics). -- World-agent Landlock wrapper (this feature): - - Parse mountinfo for the project mount entry. - - Derive overlayfs internal backing dirs (`upperdir`, `workdir`). - - Extend the Landlock write allowlist with these derived internal write roots. - - Apply Landlock ruleset and exec the requested command. - -### Outputs -- Allowlisted writes succeed under full isolation with Landlock enabled. -- Non-allowlisted writes remain denied. -- Policy snapshot schema and hash remain unchanged (derived internal paths are runtime-only). - -## Component map (where changes land) -- `crates/world` (Linux-only): - - Add a helper that parses `/proc/self/mountinfo` and derives overlayfs `upperdir` + `workdir` for a mountpoint. -- `crates/world-agent` (Linux-only behavior): - - Extend the full-isolation Landlock exec wrapper to include derived overlayfs internal write roots in the Landlock write allowlist. - -## Sequencing alignment -- Sequencing spine: `docs/project_management/packs/sequencing.json` -- This feature directory is the authoritative Planning Pack for ADR-0015. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-code.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-code.md deleted file mode 100644 index f8e5ffc36..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-code.md +++ /dev/null @@ -1,31 +0,0 @@ -# Kickoff: C0-code (code) - -## Scope -- Production code only; no new tests. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-code` on branch `full-isolation-landlock-overlayfs-compat-c0-code` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID=""` (preferred; starts code+test in parallel; `` is `C0-code` without `-code`) - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-code"` (single task only) - -## Requirements -- Implement exactly the behaviors and error handling in the spec. -- If the spec requires broad refactors or multiple independent behavior changes, stop and ask the operator to split the slice into smaller triads before proceeding. -- Run: `cargo fmt`, `cargo clippy --workspace --all-targets -- -D warnings` -- Tests boundary: - - Do not add new tests or new test files. - - Only update existing tests if required to restore baseline expectations after the spec’s behavior change (still no new test cases). -- Baseline testing (required): - - Run a targeted baseline test set before making changes, then re-run the same test set after your changes and ensure results are unchanged (or improved). - -## End Checklist -1. Run required commands; capture outputs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-code"` -3. Hand off the baseline test command(s) and outcomes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-core.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-core.md deleted file mode 100644 index 4c81e80f7..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-core.md +++ /dev/null @@ -1,124 +0,0 @@ -# Kickoff: C0-integ-core (integration core) - -## Scope -- Merge code + tests, resolve drift to spec, and make the slice green on the primary dev platform. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ-core` on branch `full-isolation-landlock-overlayfs-compat-c0-integ-core` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ-core"` - -## Requirements -- Reconcile code/tests to spec (spec wins). -- If the slice is too large to make green deterministically (multiple subsystems, many unrelated acceptance bullets), stop and ask the operator to split the slice before continuing. -- Merge code+test branches into this worktree, then run required integration gates (must be green before any CI smoke dispatch): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Optional (once per feature, when you want a clean-cache assurance): `make preflight` - -### Local behavioral smoke preflight (required when possible; fast fail before CI dispatch) - -If `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/` exists and this machine matches a behavior platform for this feature, run the matching smoke script **locally** before dispatching compile parity or Feature Smoke. - -Determine behavior platforms: -- `jq -r '.meta.behavior_platforms_required // [] | join(\",\")' "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json"` - -Preflight steps (choose the block matching your current platform): - -Linux: -```bash -set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh" -``` - -macOS: -```bash -set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh" -``` - -Windows (PowerShell): -```powershell -$ErrorActionPreference = "Stop" -cargo build --bin substrate -$env:Path = "$pwd\\target\\debug;$env:Path" -pwsh -File "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1" -``` - -Expected: -- Exit `0`. - -### Cross-platform compile parity (CI dispatch; required before smoke) - -Before dispatching Feature Smoke (especially when using `RUNNER_KIND=self-hosted`), run a fast cross-platform compile parity preflight on GitHub-hosted runners to catch macOS/Windows compilation breaks early: -- `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` - -Notes: -- This dispatches CI Testing in `mode=compile-parity` (fmt --check, check --all-targets, clippy -D warnings) across Linux/macOS/Windows. -- If it fails, fix compile parity **in this integ-core worktree/branch** (cfg/platform guards), commit, and re-run until green; do not proceed to Feature Smoke until it is green. - -### Cross-platform smoke (CI dispatch; validation-only) - -Run CI smoke from this **integration-core worktree**, because the smoke dispatcher tests the current `HEAD` by creating a throwaway remote branch at that commit. - -Important (P3-008): -- Smoke is required only for the feature’s **behavior platforms** (`tasks.json` meta: `behavior_platforms_required`). -- CI parity may be required for a broader set of platforms (`tasks.json` meta: `ci_parity_platforms_required` / legacy `platforms_required`). - -Recommended dispatch (explicit params; leave `CLEANUP=1` on unless debugging temp branches): - -1) Dispatch behavioral smoke in a single run (preferred): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=behavior SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If WSL coverage is required for this feature, add `RUN_WSL=1`. - -What the dispatcher does (`scripts/ci/dispatch_feature_smoke.sh` via `make feature-smoke`): -- Creates/pushes a throwaway branch like `tmp/feature-smoke///` at current `HEAD`. -- Dispatches the workflow from `WORKFLOW_REF` while checking out that throwaway branch. -- Prints `DISPATCH_OK=0|1`, `RUN_ID=`, `RUN_URL=`, `SMOKE_PASSED_PLATFORMS=`, and `SMOKE_FAILED_PLATFORMS=` (plus `ERROR_KIND`/`ERROR_MESSAGE` on failures). -- Deletes the throwaway remote branch when `CLEANUP=1`. - -Note: -- If smoke fails, `make feature-smoke` will still print `DISPATCH_OK=1` + `RUN_ID`/`RUN_URL`, but will exit non-zero (GNU make typically reports this as exit code 2). Do not re-run just to “get a run id”; use `RUN_URL` to inspect failures and start platform-fix tasks as needed. - -If any platform smoke fails: -- Do not attempt platform-specific fixes in integ-core. -- Ask the operator to start only the failing platform-fix tasks **from the orchestration checkout** (not from a task worktree): - - If you have a single smoke run that covers multiple platforms (typical `PLATFORM=behavior` case): - - `make triad-task-start-platform-fixes-from-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID="" SMOKE_RUN_ID="" LAUNCH_CODEX=1` - - If you dispatched per-platform smoke (multiple run ids): - - `make triad-task-start-platform-fixes FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID="" PLATFORMS="" LAUNCH_CODEX=1` - - `` is the triad id prefix (e.g., `C0`, `C3`). - - `` is the `RUN_ID` from the failing smoke run (only used for `triad-task-start-platform-fixes-from-smoke`). - - `` is the comma-separated list of platforms you need platform-fix tasks for (typically the failing behavior platforms, plus `wsl` if `wsl_task_mode="separate"`). - -If behavioral smoke is green for all behavior platforms: -- Platform-fix tasks (if present in the pack) may still be required for CI-only failures (e.g., clippy warnings on macOS/Windows), so do not mark them no-op yet. -- The wrapper/final gate runs CI Testing; if CI Testing is green, then mark platform-fix tasks `completed` as no-ops to unblock the final aggregator’s `depends_on`: - - `PM_SYSTEM_SCRIPTS="docs/project_management/system/scripts" bash "${PM_SYSTEM_SCRIPTS}/triad/mark_noop_platform_fixes_completed.sh" --feature-dir "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" --slice-id ""` (optional: add `--from-smoke-run ""` for logging) - -Once all required platform-fix tasks are completed, ask the operator to start the final aggregator from the orchestration checkout: -- `make triad-task-start-integ-final FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID="" LAUNCH_CODEX=1` - - Note: the final aggregator task id is `-integ` (the command name contains `integ-final`). - -## End Checklist -1. Ensure your merged state is committed and local integration gates are green: - - From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ-core"` -2. Dispatch cross-platform smoke from this worktree and include these exact key/value lines in your handoff (wrapper agents parse them): - - `RUN_ID=` - - `RUN_URL=` (if printed) - - `SMOKE_PASSED_PLATFORMS=` - - `SMOKE_FAILED_PLATFORMS=` (empty means success) -3. Hand off run ids/URLs and next-step instructions to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-linux.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-linux.md deleted file mode 100644 index 5199ec8b6..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-linux.md +++ /dev/null @@ -1,54 +0,0 @@ -# Kickoff: C0-integ-linux (integration platform-fix — linux) - -## Scope -- Ensure the slice is green for **linux** in the way required by the Planning Pack: - - If `linux` is in `tasks.json` meta `behavior_platforms_required`: this is a **behavioral** platform-fix task (smoke required). - - Otherwise: this is a **CI parity** platform-fix task (compile/test/lint parity required; smoke not required). -- This task is allowed to make production-code and/or test changes as needed to achieve the required platform green state, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: **linux**. -2. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ-linux` on branch `full-isolation-landlock-overlayfs-compat-c0-integ-linux` and that `.taskmeta.json` exists at the worktree root. - - Do all work (edits, builds/tests, commits, and `make triad-task-finish`) from inside this worktree. -3. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ-linux" TASK_PLATFORM=linux` - -## Requirements -- Before validating smoke or making fixes, merge the slice’s core integration branch into this worktree: - - Find the core integration task for this slice in `tasks.json` (e.g., `C0-integ-core`) and merge its task branch into your current branch. - - This ensures your platform-fix work starts from the merged code+test state that passed local integration gates. -- Keep fixes narrowly scoped to this platform’s failures. If you discover a broader cross-platform refactor is required, stop and ask the operator to split out an enabling slice instead of piling it into this platform-fix task. -- Run the platform-local Rust quality gates before finishing (CI Testing parity on this OS): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- If this is a behavioral platform (P3-008), run a local behavioral smoke preflight before dispatching CI smoke: - - Build `substrate`, add `target/debug` to `PATH`, then run the matching smoke script locally. - - Linux: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"` - - macOS: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh"` - - Windows: `cargo build --bin substrate; $env:Path=\"$pwd\\target\\debug;$env:Path\"; pwsh -File \"docs/project_management/_archived/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1\"` - - Decide whether smoke is required for this platform (P3-008): - - `jq -r '.meta.behavior_platforms_required // [] | join(",")' "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json"` - - If `linux` is in `behavior_platforms_required`, run Feature Smoke for this platform (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=linux SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If this is the Linux task and WSL coverage is required (see `tasks.json` meta: `wsl_required` + `wsl_task_mode`): - - Bundled (default): dispatch with `RUN_WSL=1`: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=linux RUN_WSL=1 SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - Otherwise, do **not** run Feature Smoke for this platform. Instead, treat this task as CI parity-only: - - Prefer local parity fixes first (fmt/clippy/tests on this OS), then ask the operator to re-run CI parity gates from integ-core/final. - - If you need an immediate cross-platform signal, run: - - `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` - - `scripts/ci/dispatch_ci_testing.sh --workflow-ref "feat/full-isolation-landlock-overlayfs-compat" --remote origin --cleanup --mode quick` - - Fix compile/test/lint parity failures for this platform and re-run until green. - -## End Checklist -1. Ensure the required gate is green for linux (smoke for behavior platforms; CI parity gates otherwise) and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ-linux"` -3. Hand off run id/URL and any platform-specific notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-macos.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-macos.md deleted file mode 100644 index aa65a07ca..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-macos.md +++ /dev/null @@ -1,54 +0,0 @@ -# Kickoff: C0-integ-macos (integration platform-fix — macos) - -## Scope -- Ensure the slice is green for **macos** in the way required by the Planning Pack: - - If `macos` is in `tasks.json` meta `behavior_platforms_required`: this is a **behavioral** platform-fix task (smoke required). - - Otherwise: this is a **CI parity** platform-fix task (compile/test/lint parity required; smoke not required). -- This task is allowed to make production-code and/or test changes as needed to achieve the required platform green state, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: **macos**. -2. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ-macos` on branch `full-isolation-landlock-overlayfs-compat-c0-integ-macos` and that `.taskmeta.json` exists at the worktree root. - - Do all work (edits, builds/tests, commits, and `make triad-task-finish`) from inside this worktree. -3. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ-macos" TASK_PLATFORM=macos` - -## Requirements -- Before validating smoke or making fixes, merge the slice’s core integration branch into this worktree: - - Find the core integration task for this slice in `tasks.json` (e.g., `C0-integ-core`) and merge its task branch into your current branch. - - This ensures your platform-fix work starts from the merged code+test state that passed local integration gates. -- Keep fixes narrowly scoped to this platform’s failures. If you discover a broader cross-platform refactor is required, stop and ask the operator to split out an enabling slice instead of piling it into this platform-fix task. -- Run the platform-local Rust quality gates before finishing (CI Testing parity on this OS): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- If this is a behavioral platform (P3-008), run a local behavioral smoke preflight before dispatching CI smoke: - - Build `substrate`, add `target/debug` to `PATH`, then run the matching smoke script locally. - - Linux: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"` - - macOS: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh"` - - Windows: `cargo build --bin substrate; $env:Path=\"$pwd\\target\\debug;$env:Path\"; pwsh -File \"docs/project_management/_archived/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1\"` - - Decide whether smoke is required for this platform (P3-008): - - `jq -r '.meta.behavior_platforms_required // [] | join(",")' "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json"` - - If `macos` is in `behavior_platforms_required`, run Feature Smoke for this platform (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=macos SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If this is the Linux task and WSL coverage is required (see `tasks.json` meta: `wsl_required` + `wsl_task_mode`): - - Bundled (default): dispatch with `RUN_WSL=1`: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=linux RUN_WSL=1 SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - Otherwise, do **not** run Feature Smoke for this platform. Instead, treat this task as CI parity-only: - - Prefer local parity fixes first (fmt/clippy/tests on this OS), then ask the operator to re-run CI parity gates from integ-core/final. - - If you need an immediate cross-platform signal, run: - - `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` - - `scripts/ci/dispatch_ci_testing.sh --workflow-ref "feat/full-isolation-landlock-overlayfs-compat" --remote origin --cleanup --mode quick` - - Fix compile/test/lint parity failures for this platform and re-run until green. - -## End Checklist -1. Ensure the required gate is green for macos (smoke for behavior platforms; CI parity gates otherwise) and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ-macos"` -3. Hand off run id/URL and any platform-specific notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-windows.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-windows.md deleted file mode 100644 index e76770976..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ-windows.md +++ /dev/null @@ -1,54 +0,0 @@ -# Kickoff: C0-integ-windows (integration platform-fix — windows) - -## Scope -- Ensure the slice is green for **windows** in the way required by the Planning Pack: - - If `windows` is in `tasks.json` meta `behavior_platforms_required`: this is a **behavioral** platform-fix task (smoke required). - - Otherwise: this is a **CI parity** platform-fix task (compile/test/lint parity required; smoke not required). -- This task is allowed to make production-code and/or test changes as needed to achieve the required platform green state, but must not edit planning docs inside the worktree. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task must not merge back to the orchestration branch; the final aggregator integration task performs the merge once all platforms are green. - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Run this task on a machine that matches the required platform: **windows**. -2. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ-windows` on branch `full-isolation-landlock-overlayfs-compat-c0-integ-windows` and that `.taskmeta.json` exists at the worktree root. - - Do all work (edits, builds/tests, commits, and `make triad-task-finish`) from inside this worktree. -3. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -4. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ-windows" TASK_PLATFORM=windows` - -## Requirements -- Before validating smoke or making fixes, merge the slice’s core integration branch into this worktree: - - Find the core integration task for this slice in `tasks.json` (e.g., `C0-integ-core`) and merge its task branch into your current branch. - - This ensures your platform-fix work starts from the merged code+test state that passed local integration gates. -- Keep fixes narrowly scoped to this platform’s failures. If you discover a broader cross-platform refactor is required, stop and ask the operator to split out an enabling slice instead of piling it into this platform-fix task. -- Run the platform-local Rust quality gates before finishing (CI Testing parity on this OS): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` -- If this is a behavioral platform (P3-008), run a local behavioral smoke preflight before dispatching CI smoke: - - Build `substrate`, add `target/debug` to `PATH`, then run the matching smoke script locally. - - Linux: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"` - - macOS: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh"` - - Windows: `cargo build --bin substrate; $env:Path=\"$pwd\\target\\debug;$env:Path\"; pwsh -File \"docs/project_management/_archived/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1\"` - - Decide whether smoke is required for this platform (P3-008): - - `jq -r '.meta.behavior_platforms_required // [] | join(",")' "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json"` - - If `windows` is in `behavior_platforms_required`, run Feature Smoke for this platform (repeat until green if you make fixes): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=windows SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If this is the Linux task and WSL coverage is required (see `tasks.json` meta: `wsl_required` + `wsl_task_mode`): - - Bundled (default): dispatch with `RUN_WSL=1`: - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=linux RUN_WSL=1 SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - Otherwise, do **not** run Feature Smoke for this platform. Instead, treat this task as CI parity-only: - - Prefer local parity fixes first (fmt/clippy/tests on this OS), then ask the operator to re-run CI parity gates from integ-core/final. - - If you need an immediate cross-platform signal, run: - - `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` - - `scripts/ci/dispatch_ci_testing.sh --workflow-ref "feat/full-isolation-landlock-overlayfs-compat" --remote origin --cleanup --mode quick` - - Fix compile/test/lint parity failures for this platform and re-run until green. - -## End Checklist -1. Ensure the required gate is green for windows (smoke for behavior platforms; CI parity gates otherwise) and capture the run id/URL. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ-windows"` -3. Hand off run id/URL and any platform-specific notes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ.md deleted file mode 100644 index fd1729970..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-integ.md +++ /dev/null @@ -1,53 +0,0 @@ -# Kickoff: C0-integ (integration final — cross-platform merge) - -## Scope -- Merge platform-fix branches (if any) and finalize the slice with a clean, auditable cross-platform green state. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` -- This task is responsible for merging back to the orchestration branch after all platforms are green (fast-forward when possible; otherwise a merge commit, preserving the orchestration branch’s Planning Pack files under the feature dir). - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ` on branch `full-isolation-landlock-overlayfs-compat-c0-integ` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ"` - -## Requirements -- Merge the relevant integration branches for this slice: - - The core integration branch (e.g., `*-integ-core`) and any platform-fix integration branches (`*-integ-linux|macos|windows|wsl`) that produced commits. -- Do not merge the orchestration branch into this worktree to “pick up task status/docs updates”; the finisher merges back while preserving the orchestration branch’s Planning Pack files. -- If the integration state has grown too large/unstable (many conflicts, large refactors, multiple unrelated changes), stop and ask the operator to split follow-up triads rather than forcing everything through a single final merge. -- Run: - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Local behavioral smoke preflight (fast fail before CI dispatch; required when possible): - - If `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/` exists and this machine matches a behavior platform, build `substrate`, add `target/debug` to `PATH`, and run the matching smoke script locally. - - Linux: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"` - - macOS: `cargo build --bin substrate && export PATH="$PWD/target/debug:$PATH" && bash "docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh"` - - Windows: `cargo build --bin substrate; $env:Path=\"$pwd\\target\\debug;$env:Path\"; pwsh -File \"docs/project_management/_archived/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1\"` -- Ensure cross-platform compile parity is green for this exact `HEAD` (fast fail): - - `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` -- Run behavioral smoke via CI to confirm the merged result is green (P3-008): - - Run from this final integration worktree (smoke validates current `HEAD` via a throwaway remote branch). - - Dispatch behavioral smoke in a single run (preferred): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" PLATFORM=behavior SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If WSL coverage is required for this feature, add `RUN_WSL=1`. -- Complete the slice closeout gate report: - - `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/-closeout_report.md` (e.g., `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-closeout_report.md`) - -## End Checklist -1. Ensure all required platforms are green (include run ids/URLs). -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ"` -3. Run CI Testing on this final integration commit before merging to `testing` (even if CI Testing was run earlier on integ-core): - - From inside this worktree: `scripts/ci/dispatch_ci_testing.sh --workflow-ref "feat/full-isolation-landlock-overlayfs-compat" --remote origin --cleanup --mode full` - - You may skip this only if the operator already has a CI Testing run for this exact `HEAD` commit SHA. -4. Hand off run ids/URLs (smoke + CI Testing) and closeout report completion to the operator (do not edit planning docs inside the worktree). -5. Do not delete the worktree (feature cleanup removes worktrees at feature end). - -Naming note: -- The task id for the final aggregator is `-integ` (this prompt’s `C0-integ`). The helper command to start it is named `triad-task-start-integ-final`. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-test.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-test.md deleted file mode 100644 index c3d8b6e94..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/C0-test.md +++ /dev/null @@ -1,27 +0,0 @@ -# Kickoff: C0-test (test) - -## Scope -- Tests only (plus minimal test-only helpers if absolutely needed); no production code. -- Spec: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-test` on branch `full-isolation-landlock-overlayfs-compat-c0-test` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID=""` (preferred; starts code+test in parallel; `` is `C0-test` without `-test`) - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-test"` (single task only) - -## Requirements -- Add/modify tests that enforce the spec’s acceptance criteria. -- If the spec implies large/sweeping behavior changes, stop and ask the operator to split the slice so the test task can stay focused and reviewable. -- Run: `cargo fmt`, plus the targeted tests you add/touch. - - Note: your branch is not expected to be fully green until the code branch lands; tests must compile and fail deterministically for spec-driven reasons. - -## End Checklist -1. Run required commands; capture outputs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-test"` -3. Hand off the targeted test command(s) and outcomes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/F0-exec-preflight.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/F0-exec-preflight.md deleted file mode 100644 index f4e87a8c1..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/F0-exec-preflight.md +++ /dev/null @@ -1,32 +0,0 @@ -# Kickoff: F0-exec-preflight (execution preflight gate) - -## Scope -- Run the feature-level start gate before any triad work begins. -- This task is **docs-only** and must be performed on the orchestration branch (no worktrees). -- Standard: `docs/project_management/standards/EXECUTION_PREFLIGHT_GATE_STANDARD.md` -- Report: `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md` - -## Start Checklist - -Do not edit planning docs inside the worktree. - -1. Ensure the orchestration branch exists and is checked out: - - `make triad-orch-ensure FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat"` -2. Read: ADR + Executive Summary, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/session_log.md`, relevant specs, and this prompt. -3. Set `F0-exec-preflight` status to `in_progress` in `tasks.json`; add START entry to `session_log.md`; commit docs (`docs: start F0-exec-preflight`). - -## Requirements - -Fill `docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/execution_preflight_report.md` with a concrete recommendation: -- **ACCEPT**: triads may begin. -- **REVISE**: do not start triads until the listed issues are fixed and the preflight is re-run. - -At minimum, verify: -- The cross-platform plan is explicit and matches the spec/contract (platforms + WSL mode if needed). -- Smoke scripts are not “toy” checks; they mimic the manual testing playbook by running real commands/workflows and validating exit codes + key output. -- Any CI dispatch commands embedded in integration tasks are runnable with the expected runners. - -## End Checklist - -1. Set `F0-exec-preflight` status to `completed` in `tasks.json`; add END entry to `session_log.md` (include the recommendation and any required fixes). -2. Commit docs (`docs: finish F0-exec-preflight`). diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/FZ-feature-cleanup.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/FZ-feature-cleanup.md deleted file mode 100644 index ba57c0b42..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/kickoff_prompts/FZ-feature-cleanup.md +++ /dev/null @@ -1,29 +0,0 @@ -# Kickoff: FZ-feature-cleanup (feature cleanup) - -## Scope -- Feature-level cleanup at the end of the feature: - - remove all retained task worktrees - - prune local task branches -- This task runs on the orchestration branch (no worktrees). - -Do not edit planning docs inside the worktree. - -## Preconditions -- All tasks for this feature are completed and any required merges are done. -- Orchestration worktree is clean (no uncommitted changes). - -## How to run (deterministic) -This feature uses the triad automation registry stored in the shared git directory: -- `/triad/features/full-isolation-landlock-overlayfs-compat/worktrees.json` - -Dry-run (run first): -- `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" DRY_RUN=1 REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -Real run: -- `make triad-feature-cleanup FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" REMOVE_WORKTREES=1 PRUNE_LOCAL=1` - -If any worktree is dirty or any branch is unmerged/unpushed, the cleanup script refuses unless forced: -- add `FORCE=1` to the make invocation. - -## Output requirements -- Paste the script stdout summary block into the END entry for this task in `session_log.md`. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/events.jsonl b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/events.jsonl deleted file mode 100644 index 438cff1ab..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/events.jsonl +++ /dev/null @@ -1,6 +0,0 @@ -- Implemented runtime derivation of overlayfs `upperdir`/`workdir` from `/proc/self/mountinfo` and extended the full-isolation Landlock write allowlist with those dirs; if Landlock is supported but derivation fails, the exec now fails closed with exit code `4` and an actionable hint (`crates/world-agent/src/internal_exec.rs:42`, `crates/world-agent/src/internal_exec.rs:153`). -- Added a reusable mountinfo parser/helper in `crates/world/src/mountinfo.rs:40` and exported it from `crates/world/src/lib.rs:17`. - -- Baseline tests (pre-change): `cargo test -p world-agent --lib -- --nocapture` (pass, exit `0`); `cargo test -p world --lib -- --nocapture` (pass, exit `0`). -- Validation (post-change): `cargo fmt` (ok); `cargo clippy --workspace --all-targets -- -D warnings` (ok); re-ran the same baseline tests (pass, exit `0`). -- Finished task: `make triad-task-finish TASK_ID="C0-code"` (exit `0`), HEAD `c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1`. diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/last_message.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/last_message.md deleted file mode 100644 index d21479dbc..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/last_message.md +++ /dev/null @@ -1,6 +0,0 @@ -- Implemented runtime derivation of overlayfs `upperdir`/`workdir` from `/proc/self/mountinfo` and extended the full-isolation Landlock write allowlist with those dirs; if Landlock is supported but derivation fails, the exec now fails closed with exit code `4` and an actionable hint (`crates/world-agent/src/internal_exec.rs:42`, `crates/world-agent/src/internal_exec.rs:153`). -- Added a reusable mountinfo parser/helper in `crates/world/src/mountinfo.rs:40` and exported it from `crates/world/src/lib.rs:17`. - -- Baseline tests (pre-change): `cargo test -p world-agent --lib -- --nocapture` (pass, exit `0`); `cargo test -p world --lib -- --nocapture` (pass, exit `0`). -- Validation (post-change): `cargo fmt` (ok); `cargo clippy --workspace --all-targets -- -D warnings` (ok); re-ran the same baseline tests (pass, exit `0`). -- Finished task: `make triad-task-finish TASK_ID="C0-code"` (exit `0`), HEAD `c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1`. \ No newline at end of file diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/stderr.log b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/stderr.log deleted file mode 100644 index aac622399..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/code/stderr.log +++ /dev/null @@ -1,6531 +0,0 @@ -OpenAI Codex v0.77.0 (research preview) --------- -workdir: /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code -model: gpt-5.2 -provider: openai -approval: never -sandbox: danger-full-access -reasoning effort: high -reasoning summaries: auto -session id: 019bd965-2002-7571-8280-d4ec5a8b670b --------- -user -# Kickoff: C0-code (code) - -## Scope -- Production code only; no new tests. -- Spec: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-code` on branch `full-isolation-landlock-overlayfs-compat-c0-code` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" SLICE_ID=""` (preferred; starts code+test in parallel; `` is `C0-code` without `-code`) - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-code"` (single task only) - -## Requirements -- Implement exactly the behaviors and error handling in the spec. -- If the spec requires broad refactors or multiple independent behavior changes, stop and ask the operator to split the slice into smaller triads before proceeding. -- Run: `cargo fmt`, `cargo clippy --workspace --all-targets -- -D warnings` -- Tests boundary: - - Do not add new tests or new test files. - - Only update existing tests if required to restore baseline expectations after the spec’s behavior change (still no new test cases). -- Baseline testing (required): - - Run a targeted baseline test set before making changes, then re-run the same test set after your changes and ensure results are unchanged (or improved). - -## End Checklist -1. Run required commands; capture outputs. -2. From inside the worktree, run: `make triad-task-finish TASK_ID="C0-code"` -3. Hand off the baseline test command(s) and outcomes to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - -mcp: deepwiki starting -mcp: deepwiki ready -mcp startup: ready: deepwiki - -thinking -**Planning test execution** - -I'm organizing the testing process. First, I’ll run fmt, clippy, and baseline tests again. After that, I'll execute "make triad-task-finish" and capture those outputs. I notice that the standard says we shouldn't edit planning documents, so I’ll stick to that guideline. I think it’s best to capture all outputs in the final message. Let’s structure this with around 5-6 clear steps to keep everything organized! -Plan update -Follow triad workflow: verify correct worktree, read spec, establish baseline test set, implement targeted production changes, then validate with fmt/clippy and baseline rerun before finishing the task. - → Verify worktree and metadata - • Read spec and task docs - • Run baseline tests (pre-change) - • Implement spec-required code changes - • Run fmt, clippy, baseline tests - • Finish triad task and summarize -exec -/bin/bash -lc 'pwd -git rev-parse --abbrev-ref HEAD -test -f .taskmeta.json && echo ".taskmeta.json present" || echo "MISSING .taskmeta.json" -ls -la .taskmeta.json -' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 29ms: -/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code -full-isolation-landlock-overlayfs-compat-c0-code -.taskmeta.json present --rw-r--r-- 1 spenser spenser 394 Jan 19 22:13 .taskmeta.json -exec -/bin/bash -lc 'cat .taskmeta.json' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 43ms: -{ - "created_at_utc": "2026-01-20T03:13:59Z", - "created_from_sha": "c7129f092251e000c77b826f93bcd80db2707699", - "feature_dir": "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat", - "orchestration_branch": "feat/full-isolation-landlock-overlayfs-compat", - "schema_version": 1, - "task_branch": "full-isolation-landlock-overlayfs-compat-c0-code", - "task_id": "C0-code" -} - -thinking -**Planning document review** - -Alright, the metadata matches, so I’ll mark this step as completed. Next, I need to read the specified documents carefully, avoiding any edits. I’ll just look through them directly. I think it’s also important to check the workflow standards. So, I’ll open the specs, the planning documents, and the tasks. It seems using parallel tool readings will help streamline this process. Let’s get into it! -Plan update - ✓ Verify worktree and metadata - → Read spec and task docs - • Run baseline tests (pre-change) - • Implement spec-required code changes - • Run fmt, clippy, baseline tests - • Finish triad task and summarize -exec -/bin/bash -lc "sed -n '1,200p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/plan.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 47ms: -# full-isolation-landlock-overlayfs-compat — plan - -## Scope -- Feature directory: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/` -- Orchestration branch: `feat/full-isolation-landlock-overlayfs-compat` -- ADR: `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -## Goal -- Restore `world_fs.write_allowlist` correctness in `world_fs.isolation=full` + `world_fs.mode=writable` on Linux when Landlock is supported and overlayfs is the active filesystem strategy. - -## Non-Goals -- Any policy snapshot schema changes or policy snapshot hash behavior changes. -- Any new user-facing allowlist syntaxes or matching semantics. -- Any behavior changes for macOS or Windows world backends. - -## Platform scope -- Behavior platforms (smoke required): Linux, macOS. -- CI parity platforms (compile parity required): Linux, macOS, Windows. -- WSL coverage: not required. - -exec -/bin/bash -lc 'cat docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 33ms: -{ - "meta": { - "schema_version": 3, - "feature": "full-isolation-landlock-overlayfs-compat", - "cross_platform": true, - "execution_gates": true, - "automation": { - "enabled": true, - "orchestration_branch": "feat/full-isolation-landlock-overlayfs-compat" - }, - "behavior_platforms_required": [ - "linux", - "macos" - ], - "ci_parity_platforms_required": [ - "linux", - "macos", - "windows" - ] - }, -exec -/bin/bash -lc "sed -n '1,200p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/session_log.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 46ms: -# full-isolation-landlock-overlayfs-compat — session log - -## START — 2026-01-20T01:52:53Z — planning — planning pack for ADR-0015 (full isolation Landlock ↔ overlayfs backing dirs) -- Feature: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/` -- Branch: `testing` -- Goal: Produce an execution-ready Planning Pack for ADR-0015 under the correct feature directory, with validated tasks/prompts/smoke and zero ambiguity in specs/contracts. -- Inputs to read end-to-end: - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - - `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md` - - `docs/project_management/standards/ADR_STANDARD_AND_TEMPLATE.md` - - `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - - `docs/project_management/standards/PLANNING_SESSION_LOG_TEMPLATE.md` - - `docs/project_management/packs/sequencing.json` - - `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` -- Commands planned (if any): - - `make planning-new-feature FEATURE=full-isolation-landlock-overlayfs-compat DECISION_HEAVY=1 CROSS_PLATFORM=1 AUTOMATION=1 BEHAVIOR_PLATFORMS=linux CI_PARITY_PLATFORMS=linux,macos,windows` - - `python3 planning/validate_tasks_json.py --feature-dir "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat"` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat"` -exec -/bin/bash -lc "sed -n '1,260p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/C0-spec.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 45ms: -# C0-spec — Full isolation Landlock ↔ OverlayFS backing dirs allowlist - -Authoritative ADR: -- `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -Exit codes: -- Exit code taxonomy: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -## Scope -- Behavior is Linux-kernel-specific; this slice is validated on: - - Linux hosts, and - - macOS hosts via the Lima Linux guest (world backend). -- Restore the operator contract for `world_fs.write_allowlist` in: - - `world_fs.isolation=full` - - `world_fs.mode=writable` - - Landlock supported by the running kernel - - overlayfs is the active world filesystem strategy -- Extend the full-isolation Landlock write allowlist with runtime-derived overlayfs internal write roots: - - `upperdir` - - `workdir` -exec -/bin/bash -lc "sed -n '1,220p' docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 40ms: -# Task Triads — Worktree Execution Standard (Automation + Concurrent Code/Test) - -This standard is for **execution-time** triad work when tasks are started via triad automation (preferred), and the agent is already running **inside a task worktree**. - -It is a focused companion to: -- `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` (full planning pack + task schema + integration model) - -## Operating assumptions (the situation you are in) - -When this standard applies, the operator started you with one of: -- `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/next/" SLICE_ID="" LAUNCH_CODEX=1` (preferred) -- `make triad-task-start FEATURE_DIR="docs/project_management/_archived/next/" TASK_ID="" LAUNCH_CODEX=1` - -You are already: -- in a git worktree (usually under `wt/...`) -- on a task branch (not the orchestration branch) -- expected to find `.taskmeta.json` at the worktree root (task id, orchestration branch, etc.) - -## Non-negotiable safety rule - - -thinking -**Inspecting landlock exec wrapper** - -I need to find the landlock exec wrapper within the world-agent crate or world. I should check the environment variables like SUBSTRATE_WORLD_FS_LANDLOCK_*_ALLOWLIST. My guess is that we need to insert derived allowlist entries for upperdir and workdir. It's likely that these environment variables control allowed writes for the landlock wrapper. Next, I'll inspect the relevant code and search for terms like SUBSTRATE_MOUNT_PROJECT_DIR or landlock allowlist environment variables using rg. -exec -/bin/bash -lc 'rg -n "SUBSTRATE_MOUNT_PROJECT_DIR|LANDLOCK|SUBSTRATE_WORLD_FS_LANDLOCK" -S crates/world-agent crates/world crates/world* crates/common src || true' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 60ms: -crates/world-agent/src/pty.rs:7: resolve_project_write_allowlist_prefixes, WORLD_FS_LANDLOCK_READ_ALLOWLIST_ENV, -crates/world-agent/src/pty.rs:8: WORLD_FS_LANDLOCK_WRITE_ALLOWLIST_ENV, WORLD_FS_MODE_ENV, WORLD_FS_WRITE_ALLOWLIST_ENV, -crates/world-agent/src/pty.rs:352: WORLD_FS_LANDLOCK_READ_ALLOWLIST_ENV.to_string(), -crates/world-agent/src/pty.rs:358: WORLD_FS_LANDLOCK_WRITE_ALLOWLIST_ENV.to_string(), -crates/world-agent/src/pty.rs:365: env.entry("SUBSTRATE_LANDLOCK_HELPER_SRC".to_string()) -crates/world-agent/src/pty.rs:421: "SUBSTRATE_MOUNT_PROJECT_DIR".to_string(), -crates/world-agent/src/internal_exec.rs:3:pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; -crates/world-agent/src/internal_exec.rs:9:const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; -crates/world-agent/src/internal_exec.rs:13:const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; -crates/world-agent/src/internal_exec.rs:14:const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -crates/world-agent/src/internal_exec.rs:17: let read_paths = parse_allowlist_env(LANDLOCK_READ_ENV); -crates/world-agent/src/internal_exec.rs:18: let write_paths = parse_allowlist_env(LANDLOCK_WRITE_ENV); -crates/world-agent/src/main.rs:8: .is_some_and(|arg| arg == internal_exec::LANDLOCK_EXEC_ARG) -crates/world-agent/src/service.rs:41:pub(crate) const WORLD_FS_LANDLOCK_READ_ALLOWLIST_ENV: &str = -crates/world-agent/src/service.rs:42: "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; -crates/world-agent/src/service.rs:43:pub(crate) const WORLD_FS_LANDLOCK_WRITE_ALLOWLIST_ENV: &str = -crates/world-agent/src/service.rs:44: "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -crates/world-agent/src/service.rs:45:pub(crate) const LANDLOCK_HELPER_SRC_ENV: &str = "SUBSTRATE_LANDLOCK_HELPER_SRC"; -crates/world-agent/src/service.rs:221: WORLD_FS_LANDLOCK_READ_ALLOWLIST_ENV.to_string(), -crates/world-agent/src/service.rs:227: WORLD_FS_LANDLOCK_WRITE_ALLOWLIST_ENV.to_string(), - -thinking -**Inspecting code files** - -I see that the file at crates/world-agent/src/internal_exec.rs is probably a wrapper used by the landlock helper. I definitely want to check that file out. I’ll also look into the `parse_allowlist_env` function within the same file to get a better understanding of how everything works together. Let’s open it up and take a closer look! -exec -/bin/bash -lc "sed -n '1,240p' crates/world-agent/src/internal_exec.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 42ms: -use anyhow::{Context, Result}; - -pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -const INNER_CMD_ENV: &str = "SUBSTRATE_INNER_CMD"; -const INNER_LOGIN_SHELL_ENV: &str = "SUBSTRATE_INNER_LOGIN_SHELL"; -const MOUNT_CWD_ENV: &str = "SUBSTRATE_MOUNT_CWD"; -#[cfg(target_os = "linux")] -const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; -#[cfg(target_os = "linux")] -const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; - -const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; -const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; - -pub fn run_landlock_exec() -> Result<()> { - let read_paths = parse_allowlist_env(LANDLOCK_READ_ENV); - let write_paths = parse_allowlist_env(LANDLOCK_WRITE_ENV); - - #[cfg(target_os = "linux")] -exec -/bin/bash -lc "sed -n '1,120p' crates/world-agent/src/service.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 40ms: -//! Core service implementation for world agent. - -#[cfg(target_os = "linux")] -use agent_api_types::ExecuteStreamFrame; -use agent_api_types::{Budget, ExecuteRequest, ExecuteResponse}; -#[cfg(target_os = "linux")] -use anyhow::Context; -use anyhow::{anyhow, Result}; -use axum::response::Response; -#[cfg(target_os = "linux")] -use axum::{ - body::{boxed, Bytes, StreamBody}, - http::StatusCode, -}; -use base64::engine::general_purpose::STANDARD as BASE64; -use base64::Engine; -#[cfg(target_os = "linux")] -use futures_util::StreamExt; -use std::collections::HashMap; -#[cfg(target_os = "linux")] -exec -/bin/bash -lc "rg -n \"fn apply_filesystem_policy|apply_write_only_allowlist\" crates/world/src/landlock.rs && sed -n '430,640p' crates/world/src/landlock.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 39ms: -52:pub fn apply_write_only_allowlist(write_paths: &[String]) -> LandlockApplyReport { -55: linux::apply_write_only_allowlist(write_paths) -70:pub fn apply_filesystem_policy(policy: &LandlockFilesystemPolicy) -> LandlockApplyReport { -200: pub(super) fn apply_filesystem_policy( -368: pub(super) fn apply_write_only_allowlist(write_paths: &[String]) -> LandlockApplyReport { - applied: false, - rules_added: 0, - reason: Some(err), - }; - } - }; - - let mut rules_added = 0usize; - for (path, access) in allowlist { - if access == 0 { - continue; - } - - let fd = match open_opath(path) { - Ok(fd) => fd, - -thinking -**Checking report requirements** - -I need to verify the top of the file for the LandlockApplyReport to ensure it includes the necessary support details. It's important to make sure everything is in order for this report. I'll go through the file to confirm that all elements are present. This way, I can ensure that I'm meeting the requirements completely. It's always good to double-check, just to make sure everything is accurate! -exec -/bin/bash -lc "sed -n '1,120p' crates/world/src/landlock.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 41ms: -use serde::Serialize; - -#[derive(Debug, Clone, Serialize)] -pub struct LandlockSupport { - pub supported: bool, - pub abi: Option, - pub reason: Option, -} - -#[derive(Debug, Clone)] -pub struct LandlockFilesystemPolicy { - pub exec_paths: Vec, - pub read_paths: Vec, - pub write_paths: Vec, -} - -#[derive(Debug, Clone, Serialize)] -pub struct LandlockApplyReport { - pub support: LandlockSupport, - pub attempted: bool, -exec -/bin/bash -lc "sed -n '160,260p' crates/world/src/landlock.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 45ms: - - fn write_only_access_mask(abi: u32) -> u64 { - let supported = abi_supported_access_fs(abi); - - let mut mask = landlock::LANDLOCK_ACCESS_FS_WRITE_FILE as u64 - | landlock::LANDLOCK_ACCESS_FS_REMOVE_DIR as u64 - | landlock::LANDLOCK_ACCESS_FS_REMOVE_FILE as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_CHAR as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_DIR as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_REG as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_SOCK as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_FIFO as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_BLOCK as u64 - | landlock::LANDLOCK_ACCESS_FS_MAKE_SYM as u64; - - if abi >= 2 { - mask |= landlock::LANDLOCK_ACCESS_FS_REFER as u64; - } - if abi >= 3 { - mask |= landlock::LANDLOCK_ACCESS_FS_TRUNCATE as u64; -exec -/bin/bash -lc "sed -n '1,120p' crates/world-agent/src/main.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 34ms: -use anyhow::Result; -use world_agent::{internal_exec, run_world_agent}; - -#[tokio::main(flavor = "multi_thread")] -async fn main() -> Result<()> { - if std::env::args() - .nth(1) - .is_some_and(|arg| arg == internal_exec::LANDLOCK_EXEC_ARG) - { - return internal_exec::run_landlock_exec(); - } - - run_world_agent().await -} - - - - -thinking -**Implementing error handling** - -I'm considering how errors from internal_exec propagate to the main function in Rust. The spec requires an exit code of 4 when a derivation fails, even though the default is 1. For the wrapper, I might call `std::process::exit(4)` after printing the error, but I want the error to be actionable. - -Should I return a custom error type in the main function? Ah, internal_exec can handle the exit for missing prerequisites, so it’s about implementing the logic correctly in `derive_overlay_backing_dirs(...)` for this. -thinking -**Parsing mount information** - -I need to ensure that we include the mountpoint value along with any missing requirements and hints. For this, we’re diving into parsing `/proc/self/mountinfo` with a minimal parser that handles the specified line format. - -The goal is to find a mount entry where the mountpoint equals `SUBSTRATE_MOUNT_PROJECT_DIR`, taking the greatest mount ID when there are multiples. We'll check that `fs_type` is `overlay` and that `super_options` includes specific keys. It’ll also be necessary to decode any escape sequences in these values while ensuring all interpreted paths start with a '/'. -thinking -**Understanding super_options parsing** - -So, in the `mountinfo`, `super_options` follows the `mount_source` and is a comma-separated list. For overlay filesystems, `super_options` includes several key=val pairs, such as lowerdir, upperdir, and workdir. - -There might be commas in the values, but it’s probably rare. I could search for the substring "upperdir=" and parse until the next comma or the end, taking care to handle any escape sequences. Now, where to place the mountinfo parsing? The spec points to fixture tests in crates/world, yet maybe it makes sense to keep the parsing module in that area for reuse in production code. -thinking -**Planning mountinfo helper implementation** - -The spec mentions adding tests in `crates/world`, which makes me think we should also create a parsing helper function there to share between the tests. While the tests are managed by a different team, I believe implementing this helper in the `crates/world/src/mountinfo.rs` file could be a clean solution. The production code guidelines allow for adding new modules, so this should be fine. I’ll start by searching the world crate for any existing `mountinfo` code to see what’s already there. -exec -/bin/bash -lc 'rg -n "mountinfo" crates/world/src -S' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code exited 1 in 63ms: - - -thinking -**Checking crate layout** - -I’m considering whether I could add a new file, `crates/world/src/procfs/mountinfo.rs`. First, I want to check the overall layout of the crate to see how this new file would fit in. It’s important to ensure organization is sound and that I’m following the structure properly. I'll evaluate the current directories and files before making any decisions about the new addition. That way, I can maintain clarity and consistency. -exec -/bin/bash -lc 'ls -la crates/world/src && rg -n "mod " crates/world/src/lib.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 41ms: -total 180 -drwxr-xr-x 3 spenser spenser 4096 Jan 19 22:13 . -drwxr-xr-x 4 spenser spenser 4096 Jan 19 22:13 .. --rw-r--r-- 1 spenser spenser 4648 Jan 19 22:13 cgroups.rs --rw-r--r-- 1 spenser spenser 20243 Jan 19 22:13 copydiff.rs --rw-r--r-- 1 spenser spenser 5950 Jan 19 22:13 diff.rs --rw-r--r-- 1 spenser spenser 4903 Jan 19 22:13 dns.rs --rw-r--r-- 1 spenser spenser 18061 Jan 19 22:13 exec.rs --rw-r--r-- 1 spenser spenser 4288 Jan 19 22:13 guard.rs --rw-r--r-- 1 spenser spenser 10745 Jan 19 22:13 isolation.rs --rw-r--r-- 1 spenser spenser 19173 Jan 19 22:13 landlock.rs --rw-r--r-- 1 spenser spenser 6042 Jan 19 22:13 lib.rs --rw-r--r-- 1 spenser spenser 24280 Jan 19 22:13 netfilter.rs --rw-r--r-- 1 spenser spenser 2406 Jan 19 22:13 netns.rs --rw-r--r-- 1 spenser spenser 2953 Jan 19 22:13 network.rs -drwxr-xr-x 2 spenser spenser 4096 Jan 19 22:13 overlayfs --rw-r--r-- 1 spenser spenser 17034 Jan 19 22:13 session.rs --rw-r--r-- 1 spenser spenser 2015 Jan 19 22:13 stream.rs -9:pub mod cgroups; -10:pub mod copydiff; - -thinking -**Evaluating module additions** - -I’ve noticed there's an internal tests module in lib.rs, but it seems we won't be adding new tests. However, we could add the `mountinfo` module and export it. I wonder if it might be better to place it within the `world::overlayfs` module instead since there's already an overlayfs directory. I think it would be a good idea to inspect the overlayfs folder for more clarity. -exec -/bin/bash -lc 'ls -la crates/world/src/overlayfs && rg -n "upperdir|workdir|overlay" crates/world/src/overlayfs -S' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 53ms: -total 68 -drwxr-xr-x 2 spenser spenser 4096 Jan 19 22:13 . -drwxr-xr-x 3 spenser spenser 4096 Jan 19 22:13 .. --rw-r--r-- 1 spenser spenser 11038 Jan 19 22:13 layering.rs --rw-r--r-- 1 spenser spenser 26910 Jan 19 22:13 mod.rs --rw-r--r-- 1 spenser spenser 7765 Jan 19 22:13 strategy.rs --rw-r--r-- 1 spenser spenser 1102 Jan 19 22:13 strategy_state.rs --rw-r--r-- 1 spenser spenser 6885 Jan 19 22:13 utils.rs -crates/world/src/overlayfs/strategy.rs:11:use super::OverlayFs; -crates/world/src/overlayfs/strategy.rs:89: let mut overlay = match OverlayFs::new(&probe_id) { -crates/world/src/overlayfs/strategy.rs:90: Ok(overlay) => overlay, -crates/world/src/overlayfs/strategy.rs:98: failure_reason: Some(format!("failed to initialize probe overlay: {err}")), -crates/world/src/overlayfs/strategy.rs:105: // so it must run against a writable overlay regardless of the session fs_mode. -crates/world/src/overlayfs/strategy.rs:107: WorldFsStrategy::Overlay => overlay.mount_kernel_only(project), -crates/world/src/overlayfs/strategy.rs:108: WorldFsStrategy::Fuse => overlay.mount_fuse_only(project), -crates/world/src/overlayfs/strategy.rs:133: let _ = overlay.cleanup(); -crates/world/src/overlayfs/strategy.rs:146: "overlayfs enumeration probing is only supported on Linux".to_string(), -crates/world/src/overlayfs/strategy.rs:154: std::path::Path::new("/dev/fuse").exists() && which::which("fuse-overlayfs").is_ok() -crates/world/src/overlayfs/strategy.rs:167: let primary = WorldFsStrategy::Overlay; -crates/world/src/overlayfs/strategy.rs:169: let primary_outcome = probe_strategy(world_id, WorldFsStrategy::Overlay, project); -exec -/bin/bash -lc 'cat crates/world/Cargo.toml' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 49ms: -[package] -name = "world" -version = "0.1.1" -edition = "2021" -authors = ["Atomize"] -description = "Linux native world backend with namespaces, cgroups, and network isolation" -license = "MIT" - -[dependencies] -substrate-common = { path = "../common" } -anyhow = { workspace = true } -serde = { version = "1", features = ["derive"] } -serde_json = { workspace = true } -tokio = { version = "1", features = ["full"] } -uuid = { workspace = true } -thiserror = "1" -walkdir = "2" -dns-lookup = "2" -world-api = { path = "../world-api" } -sha2.workspace = true - - - - - -thinking -**Decoding mount info** - -I’m thinking we should decode the mount_point field from mountinfo and then compare it to the env string. That makes sense because the mountpoint will be “text” after decoding. Next, I’ll select the entry with the greatest mount ID and parse mount_id as u32. If the parsing fails, I wonder if I should skip it? I think I’ll treat it as a parse error, which might mean we need to ignore lines that don’t parse. But in a fail-closed scenario, that could cause issues. -thinking -**Clarifying error messages** - -I need to ensure the error message clearly states specific missing requirements like “no match,” “wrong fs_type,” and “missing upperdir/workdir.” The spec doesn’t mention parse failures, but I could include “unable to parse /proc/self/mountinfo” as a missing prerequisite. This makes sense under missing requirements. The spec defines error categories, and for missing or invalid inputs, we should fail closed with exit 4, which includes parse failures. Also, I need to define when to apply the derivation process based on specific conditions. -thinking -**Examining internal_exec policy** - -I’m trying to understand the base policy in internal_exec. It seems like write_paths are included even if they’re empty, but actually, it sets some defaults for read_paths and write_paths when enforcing. I find that it only enters the else branch if both are empty. In full isolation, it applies a filesystem policy if either read_paths or write_paths are non-empty. The base policy is included, but they only apply if enforced. For workspace isolation, it uses a write-only allowlist with a fixed list, even if the env write paths are empty. -thinking -**Analyzing Landlock application** - -I notice that the write_paths vector always has default entries, so it seems like Landlock will be attempted regardless of the read_paths environment. The apply_write_only_allowlist will detect support, but if it's unsupported, it won't introduce a new failure mode, meaning derivation should depend on Landlock support. The current internal_exec doesn't call detect_support explicitly, but I think we should do that before reading mountinfo. We’ll check if Landlock is supported and only apply it in full isolation when certain conditions are met. -thinking -**Evaluating Landlock conditions** - -In full isolation, if the mode is writable and support is confirmed, then I'd derive overlay backing directories and extend the write allowlist. But, oddly enough, even if read_paths and write_paths are empty, internal_exec might not enforce Landlock, which means "Landlock supported" could be false, so no derivation. That aligns with needing a non-empty allowlist. If the allowlist is empty, the backing directories aren't necessary. I’m considering how to extend the write allowlist; we can push derived paths into write_paths before applying the policy, but they should only be added to the write allowlist, not read_paths. -exec -/bin/bash -lc "rg -n \"fn exec_access_mask|fn read_access_mask|fn write_access_mask\" -n crates/world/src/landlock.rs && sed -n '120,190p' crates/world/src/landlock.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 49ms: -122: fn exec_access_mask() -> u64 { -126: fn read_access_mask(abi: u32) -> u64 { -134: fn write_access_mask(abi: u32) -> u64 { - } - - fn exec_access_mask() -> u64 { - landlock::LANDLOCK_ACCESS_FS_EXECUTE as u64 - } - - fn read_access_mask(abi: u32) -> u64 { - let supported = abi_supported_access_fs(abi); - supported - & (landlock::LANDLOCK_ACCESS_FS_EXECUTE as u64 - | landlock::LANDLOCK_ACCESS_FS_READ_FILE as u64 - | landlock::LANDLOCK_ACCESS_FS_READ_DIR as u64) - } - - fn write_access_mask(abi: u32) -> u64 { - let supported = abi_supported_access_fs(abi); - -exec -/bin/bash -lc 'cat crates/world-agent/Cargo.toml' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 44ms: -[package] -name = "world-agent" -version = "0.2.5" -edition = "2021" -authors = ["Atomize"] -description = "Agent service running inside worlds/VMs providing execution API" -license = "MIT" -repository = "https://github.com/atomize-hq/substrate" - -[[bin]] -name = "world-agent" -path = "src/main.rs" - -[package.metadata.dist] -dist = true -targets = ["x86_64-unknown-linux-gnu", "aarch64-unknown-linux-gnu"] -display = false - -[dependencies] -anyhow = { workspace = true } - - - - -thinking -**Evaluating compatibility across OS** - -I’m considering if the project can compile on non-linux systems. It seems like it should be viable on Windows and Mac as well, but we'll need cfg gating for that. The `libc` library suggests it's possible to include specific modules, like a Linux-only mountinfo parser. The real question is whether the world crate can be built on Windows while ensuring the Linux-specific parts are appropriately gated. I'll have to check that everything compiles correctly overall! -thinking -**Determining module compatibility** - -I’m realizing that the world-agent only relies on the world crate for Linux, meaning it wouldn’t compile on Windows or Mac if there are internal_exec changes referencing `world::mountinfo` inside a `cfg(linux)` block. It’s best to keep the mountinfo module inside that block, as it’s Linux-specific. If necessary, I’ll implement the new module gated by `#[cfg(target_os = "linux")]` to avoid any warnings or issues with cross-compilation. Overall, this helps in keeping things clean and organized! -thinking -**Analyzing module exports in world crate** - -I need to be cautious with how the world crate exports modules in lib.rs, especially regarding overlayfs. This module likely uses Linux-specific dependencies like nix but is included without any `cfg` checks. Since the tasks mention ensuring compile parity with Windows, I wonder if maybe the world crate isn't referenced there? Upon building the workspace, it seems all crates would be included, but dependencies for overlayfs wouldn’t work on Windows. It might be best to check how these are defined in `Cargo.toml`. -thinking -**Investigating compile settings for world crate** - -I'm considering that there might be compile parity for Windows, which suggests that the CI likely uses `cargo build --workspace` to build all crates. It's possible that the world crate has a configuration directive like `#![cfg(target_os = "linux")]` at the top of its lib.rs file. I really need to check that specific file to confirm how it handles its Linux-only dependencies and whether it affects the build process on Windows or not. -exec -/bin/bash -lc 'head -n 40 crates/world/src/lib.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 41ms: -//! Linux native world backend implementation. -//! -//! This crate provides the LinuxLocal backend that implements world isolation -//! using Linux namespaces, cgroups v2, nftables, and other native security features. - -use anyhow::{Context, Result}; -use world_api::{ExecRequest, ExecResult, FsDiff, WorldBackend, WorldHandle, WorldSpec}; - -pub mod cgroups; -pub mod copydiff; -pub mod diff; -pub mod dns; -pub mod exec; -pub mod guard; -pub mod isolation; -pub mod landlock; -pub mod netfilter; -pub mod netns; -pub mod network; -pub mod overlayfs; - - -thinking -**Analyzing CI build configurations** - -I'm trying to understand why CI parity includes Windows in the plan but excludes the world crate from workspace for Windows builds. It seems cargo build --workspace builds all members, but maybe they're setting default members specifically for Windows. Alternatively, they might be using `cargo build --exclude` commands, but it's unclear. Repo guidelines mention that CI parity platforms must include Linux, macOS, and Windows, so perhaps they have a custom build process for each platform. I need to ensure code changes won't break the Linux build. -thinking -**Establishing testing procedures** - -Our changes in the world-agent's internal_exec are limited to Linux, which shouldn't affect anything else. However, adding a module to the world crate should be fine. I need to ensure baseline tests are ready before implementing changes, especially since both world-agent and world are involved. I think running `cargo test -p world-agent -- --nocapture` and `cargo test -p world --lib -- --nocapture` could help. The world crate has tests that require root access, but confirming the setup is important. I'll verify if `world-agent` has a library crate by checking `lib.rs`. -exec -/bin/bash -lc 'ls -la crates/world-agent/src && rg -n "pub fn run_world_agent" crates/world-agent/src -S' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code exited 1 in 63ms: -total 140 -drwxr-xr-x 2 spenser spenser 4096 Jan 19 22:13 . -drwxr-xr-x 4 spenser spenser 4096 Jan 19 22:13 .. --rw-r--r-- 1 spenser spenser 15012 Jan 19 22:13 gc.rs --rw-r--r-- 1 spenser spenser 7555 Jan 19 22:13 handlers.rs --rw-r--r-- 1 spenser spenser 4865 Jan 19 22:13 internal_exec.rs --rw-r--r-- 1 spenser spenser 21017 Jan 19 22:13 lib.rs --rw-r--r-- 1 spenser spenser 346 Jan 19 22:13 main.rs --rw-r--r-- 1 spenser spenser 26543 Jan 19 22:13 pty.rs --rw-r--r-- 1 spenser spenser 29916 Jan 19 22:13 service.rs --rw-r--r-- 1 spenser spenser 10349 Jan 19 22:13 socket_activation.rs -exec -/bin/bash -lc "sed -n '1,120p' crates/world-agent/src/lib.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 43ms: -//! World agent library for execution inside worlds/VMs. - -pub mod gc; -pub mod handlers; -pub mod internal_exec; -pub mod pty; -pub mod service; -#[cfg(unix)] -mod socket_activation; -#[cfg(unix)] -pub use crate::socket_activation::test_support as socket_activation_test_support; - -pub use service::WorldAgentService; - -#[cfg(unix)] -use crate::socket_activation::{ - collect_socket_activation, InheritedUnixListener, SocketActivation, -}; -use anyhow::{Context, Result}; -use axum::routing::{get, post}; - - -thinking -**Evaluating test options** - -I'm considering different commands for testing, like `cargo test -p world-agent --lib`. It seems there's also `--nocapture`, which allows me to see output during tests. For targeted tests, I might use `cargo test -p world-agent internal_exec`, but there might not be any tests for that. I could also try `cargo test -p world --lib`, yet it may require root access for some tests. Ultimately, I'll probably stick with `cargo test -p world-agent --lib -- --nocapture` for a quick and relevant test. -thinking -**Updating test plan** - -I'm focusing on two commands now, deciding that the baseline should be a targeted test set. I think it's important to record the outcomes, especially before making any changes. So, I'll move forward with this. I also need to mark step 2 as complete and update the overall plan to reflect that step 3 is in progress. Keeping everything organized is key here, so I'll make those adjustments accordingly. -Plan update - ✓ Verify worktree and metadata - ✓ Read spec and task docs - → Run baseline tests (pre-change) - • Implement spec-required code changes - • Run fmt, clippy, baseline tests - • Finish triad task and summarize -exec -/bin/bash -lc 'set -euo pipefail -cargo test -p world-agent --lib -- --nocapture -cargo test -p world --lib -- --nocapture -' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 14.59s: - Compiling proc-macro2 v1.0.103 - Compiling quote v1.0.42 - Compiling unicode-ident v1.0.22 - Compiling libc v0.2.178 - Compiling cfg-if v1.0.4 - Compiling itoa v1.0.16 - Compiling smallvec v1.15.1 - Compiling log v0.4.29 - Compiling bytes v1.11.0 - Compiling pin-project-lite v0.2.16 - Compiling serde_core v1.0.228 - Compiling stable_deref_trait v1.2.1 - Compiling serde v1.0.228 - Compiling parking_lot_core v0.9.12 - Compiling scopeguard v1.2.0 - Compiling futures-core v0.3.31 - Compiling once_cell v1.21.3 - Compiling pin-utils v0.1.0 - Compiling autocfg v1.5.0 - Compiling version_check v0.9.5 -exec -/bin/bash -lc "rg -n \"enum WorldFsMode\" -S crates/common/src && sed -n '1,120p' crates/common/src/lib.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 51ms: -crates/common/src/settings.rs:8:pub enum WorldFsMode { -//! Shared utilities for substrate components - -use std::collections::HashSet; - -pub mod agent_events; -pub mod fs_diff; -pub mod manager_manifest; -pub mod paths; -pub mod settings; -pub mod world_deps_manifest; - -pub use agent_events::{AgentEvent, AgentEventKind}; -pub use fs_diff::FsDiff; -pub use manager_manifest::{ - DetectSpec, GuestSpec, InitSpec, InstallClass, InstallSpec, ManagerManifest, ManagerSpec, - Platform, RegexPattern, SystemPackagesSpec, MANAGER_MANIFEST_VERSION, -}; -pub use settings::{WorldFsMode, WorldRootMode}; -pub use settings::{ -exec -/bin/bash -lc "sed -n '1,120p' crates/common/src/settings.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 39ms: -use serde::{Deserialize, Serialize}; -use std::fmt; -use std::str::FromStr; - -/// Selects whether a world filesystem should be writable (overlay/copy-diff) -/// or mounted read-only. -#[derive(Debug, Clone, Copy, PartialEq, Eq)] -pub enum WorldFsMode { - Writable, - ReadOnly, -} - -impl WorldFsMode { - /// Convert the mode to its canonical string representation. - pub fn as_str(&self) -> &'static str { - match self { - Self::Writable => "writable", - Self::ReadOnly => "read_only", - } - } -exec -/bin/bash -lc "rg -n \"SUBSTRATE_MOUNT_PROJECT_DIR\" crates/world/src/exec.rs crates/world-agent/src/service.rs crates/world-agent/src/pty.rs -n && sed -n '250,340p' crates/world/src/exec.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 59ms: -crates/world/src/exec.rs:122: # Project mount points: stable (/project) and host-absolute ($SUBSTRATE_MOUNT_PROJECT_DIR). -crates/world/src/exec.rs:125: mkdir -p "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:126: mount --move "$SUBSTRATE_MOUNT_MERGED_DIR" "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:129: mount --bind "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" "$new_root/project" -crates/world/src/exec.rs:136: mount_point="$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:169: mkdir -p "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR/$rel" -crates/world/src/exec.rs:176: mount -o remount,bind,ro "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:192: mount -o remount,bind,rw "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:197: mount --bind "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR/$rel" "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR/$rel" -crates/world/src/exec.rs:198: mount -o remount,bind,rw "$new_root$SUBSTRATE_MOUNT_PROJECT_DIR/$rel" -crates/world/src/exec.rs:221: mount --move "$SUBSTRATE_MOUNT_MERGED_DIR" "$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:223: mount -o remount,bind,ro "$SUBSTRATE_MOUNT_PROJECT_DIR" -crates/world/src/exec.rs:285: "SUBSTRATE_MOUNT_PROJECT_DIR".to_string(), -crates/world/src/exec.rs:474: let cmd = r#"touch "$SUBSTRATE_MOUNT_PROJECT_DIR/abs_escape.txt""#; -crates/world-agent/src/pty.rs:421: "SUBSTRATE_MOUNT_PROJECT_DIR".to_string(), - #[allow(unused_variables)] cgroup_path: Option<&Path>, -) -> Result { - #[cfg(not(target_os = "linux"))] - { - let _ = cmd; -exec -/bin/bash -lc "sed -n '320,460p' crates/world-agent/src/pty.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 42ms: - &project_dir, - &snapshot.world_fs.write_allowlist, - ), - resolve_landlock_allowlist_paths( - &project_dir, - &snapshot.world_fs.read_allowlist, - ), - resolve_landlock_allowlist_paths( - &project_dir, - &snapshot.world_fs.write_allowlist, - ), - ) - } else { - let world_fs = substrate_broker::world_fs_policy(); - ( - resolve_project_write_allowlist_prefixes( - &project_dir, - &world_fs.write_allowlist, - ), - resolve_landlock_allowlist_paths(&project_dir, &world_fs.read_allowlist), -exec -/bin/bash -lc 'rg -n "WORLD_FS_MODE_ENV" crates/world-agent/src/pty.rs crates/world-agent/src/service.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 54ms: -crates/world-agent/src/pty.rs:8: WORLD_FS_LANDLOCK_WRITE_ALLOWLIST_ENV, WORLD_FS_MODE_ENV, WORLD_FS_WRITE_ALLOWLIST_ENV, -crates/world-agent/src/pty.rs:295: .get(WORLD_FS_MODE_ENV) -crates/world-agent/src/service.rs:38:pub(crate) const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; -crates/world-agent/src/service.rs:643: if let Some(raw) = env.get(WORLD_FS_MODE_ENV) { -crates/world-agent/src/service.rs:650: if let Ok(raw) = std::env::var(WORLD_FS_MODE_ENV) { -exec -/bin/bash -lc "sed -n '260,330p' crates/world-agent/src/pty.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 31ms: - }, - ) - .await; - return; - } - }; - let (policy_resolution_mode, isolation_full, fs_mode, allowed_domains) = - if let Some(snapshot) = policy_snapshot.as_ref() { - if snapshot.schema_version != 1 { - let _ = send_ws_message( - &tx, - &ServerMessage::Error { - message: format!( - "Invalid policy_snapshot.schema_version: {}", - snapshot.schema_version - ), - }, - ) - .await; - return; -Plan update - ✓ Verify worktree and metadata - ✓ Read spec and task docs - ✓ Run baseline tests (pre-change) - → Implement spec-required code changes - • Run fmt, clippy, baseline tests - • Finish triad task and summarize -file update -A /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code/crates/world/src/mountinfo.rs -use std::path::{Path, PathBuf}; - -#[derive(Debug, Clone, PartialEq, Eq)] -pub struct OverlayBackingDirs { - pub upperdir: PathBuf, - pub workdir: PathBuf, -} - -#[derive(Debug, thiserror::Error)] -pub enum OverlayBackingDirsError { - #[error("mountpoint was empty")] - EmptyMountpoint, - #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] - NoMatchingMountpoint { mountpoint: String }, - #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] - WrongFsType { mountpoint: String, fs_type: String }, - #[error("overlay mount for {mountpoint:?} is missing super option {key}")] - MissingSuperOption { mountpoint: String, key: &'static str }, - #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] - NotAbsolutePath { - mountpoint: String, - key: &'static str, - value: String, - }, -} - -/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -/// parsing `/proc/self/mountinfo` text. -/// -/// Selection rules: -/// - Find mount entries whose mountpoint equals `mountpoint`. -/// - If multiple entries match, select the entry with the greatest mount id. -/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -/// -/// Escape rules: -/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -pub fn overlay_backing_dirs_from_mountinfo( - mountinfo: &str, - mountpoint: &str, -) -> Result { - let mountpoint = mountpoint.trim(); - if mountpoint.is_empty() { - return Err(OverlayBackingDirsError::EmptyMountpoint); - } - - let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) - - for line in mountinfo.lines() { - let Some((left, right)) = line.split_once(" - ") else { - continue; - }; - - let mut left_fields = left.split_whitespace(); - let Some(mount_id_raw) = left_fields.next() else { - continue; - }; - let Ok(mount_id) = mount_id_raw.parse::() else { - continue; - }; - - // mountinfo fixed fields: - // mount_id parent_id major:minor root mount_point ... - let _parent_id = left_fields.next(); - let _major_minor = left_fields.next(); - let _root = left_fields.next(); - let Some(mount_point_raw) = left_fields.next() else { - continue; - }; - let mount_point = decode_mountinfo_escapes(mount_point_raw); - if mount_point != mountpoint { - continue; - } - - let mut right_fields = right.split_whitespace(); - let Some(fs_type) = right_fields.next() else { - continue; - }; - let _mount_source = right_fields.next(); - let Some(super_options) = right_fields.next() else { - continue; - }; - - match &best { - Some((best_id, _, _)) if *best_id >= mount_id => {} - _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), - } - } - - let Some((_mount_id, fs_type, super_options)) = best else { - return Err(OverlayBackingDirsError::NoMatchingMountpoint { - mountpoint: mountpoint.to_string(), - }); - }; - - if fs_type != "overlay" { - return Err(OverlayBackingDirsError::WrongFsType { - mountpoint: mountpoint.to_string(), - fs_type, - }); - } - - let super_options = parse_super_options(&super_options); - let upper_raw = super_options - .get("upperdir") - .ok_or(OverlayBackingDirsError::MissingSuperOption { - mountpoint: mountpoint.to_string(), - key: "upperdir", - })?; - let work_raw = super_options - .get("workdir") - .ok_or(OverlayBackingDirsError::MissingSuperOption { - mountpoint: mountpoint.to_string(), - key: "workdir", - })?; - - let upper = decode_mountinfo_escapes(upper_raw); - let work = decode_mountinfo_escapes(work_raw); - - if !Path::new(&upper).is_absolute() { - return Err(OverlayBackingDirsError::NotAbsolutePath { - mountpoint: mountpoint.to_string(), - key: "upperdir", - value: upper, - }); - } - if !Path::new(&work).is_absolute() { - return Err(OverlayBackingDirsError::NotAbsolutePath { - mountpoint: mountpoint.to_string(), - key: "workdir", - value: work, - }); - } - - Ok(OverlayBackingDirs { - upperdir: PathBuf::from(upper), - workdir: PathBuf::from(work), - }) -} - -fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { - let mut out = std::collections::HashMap::new(); - for component in super_options.split(',') { - let Some((key, value)) = component.split_once('=') else { - continue; - }; - out.insert(key, value); - } - out -} - -fn decode_mountinfo_escapes(value: &str) -> String { - let mut out = String::with_capacity(value.len()); - let bytes = value.as_bytes(); - let mut i = 0usize; - while i < bytes.len() { - if bytes[i] == b'\\' && i + 3 < bytes.len() { - let a = bytes[i + 1]; - let b = bytes[i + 2]; - let c = bytes[i + 3]; - let is_octal = (a as char).is_ascii_digit() - && (b as char).is_ascii_digit() - && (c as char).is_ascii_digit(); - if is_octal { - let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; - if let Some(ch) = char::from_u32(octal) { - out.push(ch); - i += 4; - continue; - } - } - } - - out.push(bytes[i] as char); - i += 1; - } - out -} -apply_patch(auto_approved=true) exited 0 in 10ms: -Success. Updated the following files: -A crates/world/src/mountinfo.rs -file update: -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - -file update: -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - - -thinking -**Updating module exports** - -I added the mountinfo module and decided to use the `thiserror::Error` deriving, which is compatible since the world crate has a dependency on thiserror. That’s a relief! Now, I need to update lib.rs to export the mountinfo module properly. After that, we'll apply the patch. It's exciting to see everything coming together with these updates! I just want to make sure it's all set up correctly. -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code/crates/world/src/lib.rs -@@ -16,2 +16,3 @@ - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; -apply_patch(auto_approved=true) exited 0 in 16ms: -Success. Updated the following files: -M crates/world/src/lib.rs -file update: -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - -file update: -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - - -thinking -**Implementing path checks** - -I'm recognizing that the path to upperdir is a directory. I think writing inside it might require both execute permissions for traversal and read permissions. So far, so good! I need to ensure that I only fail closed if landlock_support is actually supported. If it's not, then there shouldn't be any failure, even if the mount environment is missing. However, if it is supported and the derivation fails, I need to ensure that it fails closed. Now, I’ll get on with the implementation! -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code/crates/world-agent/src/internal_exec.rs -@@ -1,2 +1,4 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - -@@ -11,2 +13,4 @@ - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - -@@ -24,2 +28,7 @@ - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - -@@ -31,2 +40,6 @@ - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { -@@ -137 +150,62 @@ - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -apply_patch(auto_approved=true) exited 0 in 19ms: -Success. Updated the following files: -M crates/world-agent/src/internal_exec.rs -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..ced9858b6da41dc40e3c909478e404a6ad9254d6 ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,64 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..ced9858b6da41dc40e3c909478e404a6ad9254d6 ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,64 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..9063ae8a6f6e9b7528411c339b3e06cb5b5b7ba5 ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,177 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let bytes = value.as_bytes(); -+ let mut i = 0usize; -+ while i < bytes.len() { -+ if bytes[i] == b'\\' && i + 3 < bytes.len() { -+ let a = bytes[i + 1]; -+ let b = bytes[i + 2]; -+ let c = bytes[i + 3]; -+ let is_octal = (a as char).is_ascii_digit() -+ && (b as char).is_ascii_digit() -+ && (c as char).is_ascii_digit(); -+ if is_octal { -+ let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -+ if let Some(ch) = char::from_u32(octal) { -+ out.push(ch); -+ i += 4; -+ continue; -+ } -+ } -+ } -+ -+ out.push(bytes[i] as char); -+ i += 1; -+ } -+ out -+} - - - - - - - -thinking -**Addressing octal validity** - -I realize that digits 8 and 9 make octal invalid since we need to limit our computation to base 8, with digits restricted to 0-7. If we decode with invalid digits, it could lead to incorrect results. So, we should only decode numbers that fit the '0'..'7' range, especially for sequences like 040. I must also ensure that our conversion properly handles octal values below 256 and check if the sequence matches valid octal digits or up to 0o377. Finally, I need to verify Landlock support inside the function. -thinking -**Verifying Landlock and conditions** - -I realize we're not checking if Landlock will be applied when dealing with non-empty read_paths and write_paths. That's important since the function is only called in the else branch when these paths are populated. What if they're filled but Landlock support is false? That's a risk. Additionally, we haven't checked if `SUBSTRATE_MOUNT_PROJECT_DIR` is set separately, which could lead to failure if it's missing. The spec emphasizes that all conditions must be true for Landlock to be applied, including active overlayfs. I also need to remember that internal_exec executes for both full and workspace, reading from WORLD_FS_MODE_ENV and defaulting to Writable if missing. -thinking -**Assessing derivation conditions** - -I see that if WORLD_FS_MODE_ENV is missing, we assume it's writable and attempt derivation, but that might lead to issues. The spec states that conditions must include a writable mode, yet if we default to writable, it feels overly strict. Maybe it’s better to treat the absence of WORLD_FS_MODE_ENV as not writable? For safety, we shouldn't attempt derivation in that case. Still, in full isolation, the default mode might be writable. Yet, there's a risk of fail-closed if prerequisites are missing, and I'm unsure if WORLD_FS_MODE_ENV is a prerequisite at all. -thinking -**Clarifying derivation logic** - -I realize that to align with the spec, we should only attempt derivation if the world fs mode environment specifically indicates writable. If it's missing, should we derive anyway? It’s unclear. Maybe we should use `SUBSTRATE_MOUNT_FS_MODE`, which is set in the exec script, instead of WORLD_FS_MODE_ENV. The specification requires the world_fs.mode to be writable, but it seems internal_exec might not always reference that. I need to verify where `SUBSTRATE_MOUNT_FS_MODE` is included, as it can provide a more reliable measure for determining the actual fs mode of the mount. -thinking -**Reviewing environment mode and decoding** - -I notice that internal_exec currently uses MOUNT_CWD_ENV and SUBSTRATE_INNER_CMD but doesn't define MOUNT_FS_MODE_ENV. It seems better to implement checks on `SUBSTRATE_MOUNT_FS_MODE`, as it’s always present. The spec requires filesystem mode to be writable, but there’s uncertainty around the WORLD_FS_MODE_ENV being absent. In the context of mount enforcement, relying on MOUNT_FS_MODE_ENV should help achieve reliability. I'll also need to update our octal digit decoding to handle only valid octal bytes, ensuring we don’t break multi-byte UTF-8 sequences in mounts. -thinking -**Implementing character decoding** - -To preserve UTF-8, I'm setting up a function that decodes mountinfo escape sequences. I’ll be using an iterator with peekable functionality for efficiency. The idea is to consume octal digits following a backslash. If three valid octal digits are found (0-7), I’ll decode them into a character. - -If the digits are valid, I then push the decoded character to the output. If they aren’t, I’ll just push back the backslash and handle any formatting in messages without losing context — ensuring everything is clear and easy to read. -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code/crates/world/src/mountinfo.rs -@@ -152,18 +152,24 @@ - let mut out = String::with_capacity(value.len()); -- let bytes = value.as_bytes(); -- let mut i = 0usize; -- while i < bytes.len() { -- if bytes[i] == b'\\' && i + 3 < bytes.len() { -- let a = bytes[i + 1]; -- let b = bytes[i + 2]; -- let c = bytes[i + 3]; -- let is_octal = (a as char).is_ascii_digit() -- && (b as char).is_ascii_digit() -- && (c as char).is_ascii_digit(); -- if is_octal { -- let octal = ((a - b'0') as u32) * 64 + ((b - b'0') as u32) * 8 + (c - b'0') as u32; -- if let Some(ch) = char::from_u32(octal) { -- out.push(ch); -- i += 4; -- continue; -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } - } -@@ -172,5 +178,5 @@ - -- out.push(bytes[i] as char); -- i += 1; -+ out.push(ch); - } -+ - out -apply_patch(auto_approved=true) exited 0 in 16ms: -Success. Updated the following files: -M crates/world/src/mountinfo.rs -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..ced9858b6da41dc40e3c909478e404a6ad9254d6 ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,64 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..79e06ac41b0d5a5538320fca52b4df229e4a0b2e ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,183 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..ced9858b6da41dc40e3c909478e404a6ad9254d6 ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,64 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..79e06ac41b0d5a5538320fca52b4df229e4a0b2e ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,183 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -**Updating code tests** - -I need to rerun the fmt/clippy/baseline tests before switching things up. It's essential to ensure that the code is complete, as I might need to make updates for compiling. I’m thinking of running `cargo test` quickly, perhaps as part of step 5. Okay, let’s move on with step 5 and confirm that step 4 is complete and that I’m making progress on step 5. Let's keep everything organized! -Plan update - ✓ Verify worktree and metadata - ✓ Read spec and task docs - ✓ Run baseline tests (pre-change) - ✓ Implement spec-required code changes - → Run fmt, clippy, baseline tests - • Finish triad task and summarize -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..ced9858b6da41dc40e3c909478e404a6ad9254d6 ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,64 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) -+ { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ), -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { key, .. } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { key, value, .. } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..79e06ac41b0d5a5538320fca52b4df229e4a0b2e ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,183 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { mountpoint: String, key: &'static str }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -exec -/bin/bash -lc 'set -euo pipefail -cargo fmt -cargo clippy --workspace --all-targets -- -D warnings -cargo test -p world-agent --lib -- --nocapture -cargo test -p world --lib -- --nocapture -' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 14.10s: - Checking cfg-if v1.0.4 - Compiling serde_core v1.0.228 - Checking memchr v2.7.6 - Checking itoa v1.0.16 - Checking log v0.4.29 - Compiling serde v1.0.228 - Checking smallvec v1.15.1 - Checking pin-project-lite v0.2.16 - Checking once_cell v1.21.3 - Checking bytes v1.11.0 - Checking scopeguard v1.2.0 - Checking regex-syntax v0.8.8 - Checking ryu v1.0.21 - Compiling serde_json v1.0.146 - Checking equivalent v1.0.2 - Checking hashbrown v0.16.1 - Checking libc v0.2.178 - Compiling num-traits v0.2.19 - Checking futures-core v0.3.31 - Compiling getrandom v0.3.4 -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -**Finalizing code commitments** - -I’ve run all the required commands and tests, which is great! Now I need to commit the changes and finish the triad. The requirement mentions that only production code should be affected, so I need to check the git status to confirm that only code files have changed. I’ll run `git status` to ensure no documentation modifications. After that, I’ll commit with a message like, "fix: allow landlock writes to overlay backing dirs." I’m on it! -exec -/bin/bash -lc 'git status --porcelain=v1 -' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 51ms: - M crates/world-agent/src/internal_exec.rs - M crates/world/src/lib.rs -?? crates/world/src/mountinfo.rs -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -**Committing changes** - -Alright, so it looks like no documentation was affected this time, which is great! Now, I need to commit my changes. Should I use a conventional commit prefix? The guidelines suggest following those prefixes. I think "fix: ..." fits best since it's a behavior fix. So, I'll go ahead and make that commit with the appropriate message. It's nice to keep things tidy and organized! -exec -/bin/bash -lc 'git commit -am "fix: allow landlock with overlayfs backing dirs"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 57ms: -[full-isolation-landlock-overlayfs-compat-c0-code 0aa227cc] fix: allow landlock with overlayfs backing dirs - 2 files changed, 83 insertions(+) -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -**Amending git commit** - -I committed only two files, but I forgot to include the untracked file `mountinfo.rs`. Oops! It turns out that using `git commit -am` doesn’t add new files, which is why it got left out. I need to run `git add crates/world/src/mountinfo.rs` and then amend my commit. I’ll take care of that now to make sure everything is included! -exec -/bin/bash -lc 'git add crates/world/src/mountinfo.rs -git commit --amend --no-edit -' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 61ms: -[full-isolation-landlock-overlayfs-compat-c0-code c9383284] fix: allow landlock with overlayfs backing dirs - Date: Mon Jan 19 22:23:51 2026 -0500 - 3 files changed, 271 insertions(+) - create mode 100644 crates/world/src/mountinfo.rs -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -I'm finishing up step 5 of the triad task, and now I need to run the command `make triad-task-finish` within the worktree. After that, I should provide the baseline test commands along with their outcomes and outputs for fmt/clippy. Since we've already run these, I might want to capture the outputs from the logs. The final message should include a mention of the commands and exit codes, and the checklist indicates I should capture those outputs. Step 5 is done, so I'm moving on to step 6 now. -Plan update - ✓ Verify worktree and metadata - ✓ Read spec and task docs - ✓ Run baseline tests (pre-change) - ✓ Implement spec-required code changes - ✓ Run fmt, clippy, baseline tests - → Finish triad task and summarize -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -exec -/bin/bash -lc 'make triad-task-finish TASK_ID="C0-code"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 1.61s: -make[1]: Entering directory '/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code' -== Running: make triad-code-checks -make[2]: Entering directory '/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code' -cargo fmt -cargo clippy --workspace --all-targets -- -D warnings - Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.15s -make[2]: Leaving directory '/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code' -== No changes to commit -TASK_BRANCH=full-isolation-landlock-overlayfs-compat-c0-code -WORKTREE=/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code -HEAD=c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1 -COMMITS=1 -CHECKS=make triad-code-checks -SMOKE_RUN= -MERGED_TO_ORCH= -make[1]: Leaving directory '/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code' -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - - -thinking -**Updating completion plan** - -I’ve successfully completed the task and re-ran the formatting and clippy checks, which feels good! Now it’s time to update the plan. I need to make sure to mark step 6 as completed, so that everything stays organized and on track. Keeping clear records always helps in managing tasks efficiently, right? Let’s ensure that everything is reflected accurately in the plan! -Plan update - ✓ Verify worktree and metadata - ✓ Read spec and task docs - ✓ Run baseline tests (pre-change) - ✓ Implement spec-required code changes - ✓ Run fmt, clippy, baseline tests - ✓ Finish triad task and summarize -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -exec -/bin/bash -lc 'rg -n "extend_overlayfs_backing_dir_allowlist_or_fail_closed|fail_closed_overlayfs_prereq" crates/world-agent/src/internal_exec.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 45ms: -42: extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -153:fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -162: fail_closed_overlayfs_prereq( -170: Err(err) => fail_closed_overlayfs_prereq( -205: fail_closed_overlayfs_prereq(mountpoint, &requirement); -214:fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -exec -/bin/bash -lc 'rg -n "pub fn overlay_backing_dirs_from_mountinfo" crates/world/src/mountinfo.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 42ms: -40:pub fn overlay_backing_dirs_from_mountinfo( -exec -/bin/bash -lc 'rg -n "pub mod mountinfo" crates/world/src/lib.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-code succeeded in 38ms: -17:pub mod mountinfo; -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -codex -- Implemented runtime derivation of overlayfs `upperdir`/`workdir` from `/proc/self/mountinfo` and extended the full-isolation Landlock write allowlist with those dirs; if Landlock is supported but derivation fails, the exec now fails closed with exit code `4` and an actionable hint (`crates/world-agent/src/internal_exec.rs:42`, `crates/world-agent/src/internal_exec.rs:153`). -- Added a reusable mountinfo parser/helper in `crates/world/src/mountinfo.rs:40` and exported it from `crates/world/src/lib.rs:17`. - -- Baseline tests (pre-change): `cargo test -p world-agent --lib -- --nocapture` (pass, exit `0`); `cargo test -p world --lib -- --nocapture` (pass, exit `0`). -- Validation (post-change): `cargo fmt` (ok); `cargo clippy --workspace --all-targets -- -D warnings` (ok); re-ran the same baseline tests (pass, exit `0`). -- Finished task: `make triad-task-finish TASK_ID="C0-code"` (exit `0`), HEAD `c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1`. -file update: -diff --git a/crates/world-agent/src/internal_exec.rs b/crates/world-agent/src/internal_exec.rs -index e62f8e556e6ff9c0b5f888abfed1423c719b7870..c9ca15bdf1002f90cde02018ca00e99de4a0effd ---- a/crates/world-agent/src/internal_exec.rs -+++ b/crates/world-agent/src/internal_exec.rs -@@ -1,4 +1,6 @@ - use anyhow::{Context, Result}; -+#[cfg(target_os = "linux")] -+use substrate_common::WorldFsMode; - - pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -@@ -9,6 +11,8 @@ - const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - #[cfg(target_os = "linux")] - const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -+#[cfg(target_os = "linux")] -+const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - - const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; - const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; -@@ -22,6 +26,11 @@ - let isolation_full = std::env::var(WORLD_FS_ISOLATION_ENV) - .ok() - .is_some_and(|raw| raw.trim().eq_ignore_ascii_case("full")); -+ let fs_mode_writable = std::env::var(WORLD_FS_MODE_ENV) -+ .ok() -+ .and_then(|raw| WorldFsMode::parse(&raw)) -+ .unwrap_or(WorldFsMode::Writable) -+ == WorldFsMode::Writable; - - if isolation_full { - let mut read_paths = read_paths; -@@ -29,6 +38,10 @@ - if read_paths.is_empty() && write_paths.is_empty() { - // Nothing to enforce. - } else { -+ if fs_mode_writable { -+ extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -+ } -+ - let mut policy = world::landlock::LandlockFilesystemPolicy { - exec_paths: vec!["/".to_string(), "/project".to_string()], - read_paths: vec![ -@@ -135,3 +148,72 @@ - }) - .unwrap_or_default() - } -+ -+#[cfg(target_os = "linux")] -+fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -+ let landlock_support = world::landlock::detect_support(); -+ if !landlock_support.supported { -+ return; -+ } -+ -+ let mountpoint_env = std::env::var(MOUNT_PROJECT_DIR_ENV).unwrap_or_default(); -+ let mountpoint = mountpoint_env.trim(); -+ if mountpoint.is_empty() { -+ fail_closed_overlayfs_prereq( -+ &mountpoint_env, -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -+ ); -+ } -+ -+ let mountinfo = match std::fs::read_to_string("/proc/self/mountinfo") { -+ Ok(text) => text, -+ Err(err) => fail_closed_overlayfs_prereq( -+ mountpoint, -+ &format!("unable to read /proc/self/mountinfo: {err}"), -+ ), -+ }; -+ -+ let backing = -+ match world::mountinfo::overlay_backing_dirs_from_mountinfo(&mountinfo, mountpoint) { -+ Ok(backing) => backing, -+ Err(err) => { -+ let requirement = match err { -+ world::mountinfo::OverlayBackingDirsError::EmptyMountpoint => { -+ "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::NoMatchingMountpoint { .. } => { -+ "no mountinfo entry matches the mountpoint".to_string() -+ } -+ world::mountinfo::OverlayBackingDirsError::WrongFsType { fs_type, .. } => { -+ format!( -+ "matching mount entry fs_type was {fs_type:?} (expected \"overlay\")" -+ ) -+ } -+ world::mountinfo::OverlayBackingDirsError::MissingSuperOption { -+ key, .. -+ } => { -+ format!("overlay mount is missing super option {key}=") -+ } -+ world::mountinfo::OverlayBackingDirsError::NotAbsolutePath { -+ key, -+ value, -+ .. -+ } => { -+ format!("overlay super option {key} was not an absolute path: {value:?}") -+ } -+ }; -+ fail_closed_overlayfs_prereq(mountpoint, &requirement); -+ } -+ }; -+ -+ write_paths.push(backing.upperdir.display().to_string()); -+ write_paths.push(backing.workdir.display().to_string()); -+} -+ -+#[cfg(target_os = "linux")] -+fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -+ eprintln!( -+ "full isolation landlock exec prerequisites missing: mountpoint={mountpoint:?}, requirement={missing_requirement}; hint: this full-isolation exec requires deriving overlayfs backing dirs from /proc/self/mountinfo" -+ ); -+ std::process::exit(4); -+} -diff --git a/crates/world/src/lib.rs b/crates/world/src/lib.rs -index 8df01de40d1602f736eba037f20d3a22432fa11c..271e6c6fce61190a2d62c5c2af2f99230fc06004 ---- a/crates/world/src/lib.rs -+++ b/crates/world/src/lib.rs -@@ -14,6 +14,7 @@ - pub mod guard; - pub mod isolation; - pub mod landlock; -+pub mod mountinfo; - pub mod netfilter; - pub mod netns; - pub mod network; -diff --git a/crates/world/src/mountinfo.rs b/crates/world/src/mountinfo.rs -new file mode 100644 -index 0000000000000000000000000000000000000000..3163c97bdbd0737957025dcbe3b0f3dca82fc06c ---- /dev/null -+++ b/crates/world/src/mountinfo.rs -@@ -0,0 +1,188 @@ -+use std::path::{Path, PathBuf}; -+ -+#[derive(Debug, Clone, PartialEq, Eq)] -+pub struct OverlayBackingDirs { -+ pub upperdir: PathBuf, -+ pub workdir: PathBuf, -+} -+ -+#[derive(Debug, thiserror::Error)] -+pub enum OverlayBackingDirsError { -+ #[error("mountpoint was empty")] -+ EmptyMountpoint, -+ #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] -+ NoMatchingMountpoint { mountpoint: String }, -+ #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] -+ WrongFsType { mountpoint: String, fs_type: String }, -+ #[error("overlay mount for {mountpoint:?} is missing super option {key}")] -+ MissingSuperOption { -+ mountpoint: String, -+ key: &'static str, -+ }, -+ #[error("overlay super option {key} for {mountpoint:?} was not an absolute path: {value:?}")] -+ NotAbsolutePath { -+ mountpoint: String, -+ key: &'static str, -+ value: String, -+ }, -+} -+ -+/// Derive the overlayfs `upperdir` and `workdir` backing directories for a given mountpoint by -+/// parsing `/proc/self/mountinfo` text. -+/// -+/// Selection rules: -+/// - Find mount entries whose mountpoint equals `mountpoint`. -+/// - If multiple entries match, select the entry with the greatest mount id. -+/// - Require `fs_type == "overlay"` and that `super_options` includes `upperdir=` and `workdir=`. -+/// -+/// Escape rules: -+/// - Decodes mountinfo escape sequences (`\XYZ` octal) in mountpoint/upperdir/workdir values. -+pub fn overlay_backing_dirs_from_mountinfo( -+ mountinfo: &str, -+ mountpoint: &str, -+) -> Result { -+ let mountpoint = mountpoint.trim(); -+ if mountpoint.is_empty() { -+ return Err(OverlayBackingDirsError::EmptyMountpoint); -+ } -+ -+ let mut best: Option<(u32, String, String)> = None; // (mount_id, fs_type, super_options) -+ -+ for line in mountinfo.lines() { -+ let Some((left, right)) = line.split_once(" - ") else { -+ continue; -+ }; -+ -+ let mut left_fields = left.split_whitespace(); -+ let Some(mount_id_raw) = left_fields.next() else { -+ continue; -+ }; -+ let Ok(mount_id) = mount_id_raw.parse::() else { -+ continue; -+ }; -+ -+ // mountinfo fixed fields: -+ // mount_id parent_id major:minor root mount_point ... -+ let _parent_id = left_fields.next(); -+ let _major_minor = left_fields.next(); -+ let _root = left_fields.next(); -+ let Some(mount_point_raw) = left_fields.next() else { -+ continue; -+ }; -+ let mount_point = decode_mountinfo_escapes(mount_point_raw); -+ if mount_point != mountpoint { -+ continue; -+ } -+ -+ let mut right_fields = right.split_whitespace(); -+ let Some(fs_type) = right_fields.next() else { -+ continue; -+ }; -+ let _mount_source = right_fields.next(); -+ let Some(super_options) = right_fields.next() else { -+ continue; -+ }; -+ -+ match &best { -+ Some((best_id, _, _)) if *best_id >= mount_id => {} -+ _ => best = Some((mount_id, fs_type.to_string(), super_options.to_string())), -+ } -+ } -+ -+ let Some((_mount_id, fs_type, super_options)) = best else { -+ return Err(OverlayBackingDirsError::NoMatchingMountpoint { -+ mountpoint: mountpoint.to_string(), -+ }); -+ }; -+ -+ if fs_type != "overlay" { -+ return Err(OverlayBackingDirsError::WrongFsType { -+ mountpoint: mountpoint.to_string(), -+ fs_type, -+ }); -+ } -+ -+ let super_options = parse_super_options(&super_options); -+ let upper_raw = -+ super_options -+ .get("upperdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ })?; -+ let work_raw = -+ super_options -+ .get("workdir") -+ .ok_or(OverlayBackingDirsError::MissingSuperOption { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ })?; -+ -+ let upper = decode_mountinfo_escapes(upper_raw); -+ let work = decode_mountinfo_escapes(work_raw); -+ -+ if !Path::new(&upper).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "upperdir", -+ value: upper, -+ }); -+ } -+ if !Path::new(&work).is_absolute() { -+ return Err(OverlayBackingDirsError::NotAbsolutePath { -+ mountpoint: mountpoint.to_string(), -+ key: "workdir", -+ value: work, -+ }); -+ } -+ -+ Ok(OverlayBackingDirs { -+ upperdir: PathBuf::from(upper), -+ workdir: PathBuf::from(work), -+ }) -+} -+ -+fn parse_super_options(super_options: &str) -> std::collections::HashMap<&str, &str> { -+ let mut out = std::collections::HashMap::new(); -+ for component in super_options.split(',') { -+ let Some((key, value)) = component.split_once('=') else { -+ continue; -+ }; -+ out.insert(key, value); -+ } -+ out -+} -+ -+fn decode_mountinfo_escapes(value: &str) -> String { -+ let mut out = String::with_capacity(value.len()); -+ let mut iter = value.chars().peekable(); -+ while let Some(ch) = iter.next() { -+ if ch == '\\' { -+ let mut probe = iter.clone(); -+ let d1 = probe.next(); -+ let d2 = probe.next(); -+ let d3 = probe.next(); -+ if let (Some(a), Some(b), Some(c)) = (d1, d2, d3) { -+ let is_octal = -+ matches!(a, '0'..='7') && matches!(b, '0'..='7') && matches!(c, '0'..='7'); -+ if is_octal { -+ let octal = (a as u32 - '0' as u32) * 64 -+ + (b as u32 - '0' as u32) * 8 -+ + (c as u32 - '0' as u32); -+ if let Some(decoded) = char::from_u32(octal) { -+ // Consume the three digits we peeked. -+ let _ = iter.next(); -+ let _ = iter.next(); -+ let _ = iter.next(); -+ out.push(decoded); -+ continue; -+ } -+ } -+ } -+ } -+ -+ out.push(ch); -+ } -+ -+ out -+} - -tokens used -91,142 diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/codex.pid.aborted-20260120T131437Z.pid b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/codex.pid.aborted-20260120T131437Z.pid deleted file mode 100644 index 5c5a442e2..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/codex.pid.aborted-20260120T131437Z.pid +++ /dev/null @@ -1 +0,0 @@ -1809052 diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl deleted file mode 100644 index d3c56fb79..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl +++ /dev/null @@ -1,18 +0,0 @@ -**What I did** -- Verified worktree/branch and `.taskmeta.json`; did not edit any planning docs under `docs/project_management/_archived/next/`. -- Local gates green: `cargo fmt --all`, `cargo clippy --workspace --all-targets -- -D warnings`, `cargo test` (via `make integ-checks`), `make integ-checks`. -- Fixed CI compile-parity failure (non-Linux clippy) with `2883f19d` (`fix(world): appease clippy on non-linux`). -- Ran `make triad-task-finish TASK_ID="C0-integ-core"` successfully. - -**CI Compile Parity (green)** -- `RUN_ID=21173624758` -- `RUN_URL=https://github.com/atomize-hq/substrate/actions/runs/21173624758` - -**Behavior Smoke (failed)** -- `RUN_ID=21173728283` -- `RUN_URL=https://github.com/atomize-hq/substrate/actions/runs/21173728283` -- `SMOKE_PASSED_PLATFORMS=` -- `SMOKE_FAILED_PLATFORMS=linux,macos` - -**Operator next step (from orchestration checkout)** -- Run: `make triad-task-start-platform-fixes-from-smoke FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" SLICE_ID="C0" SMOKE_RUN_ID="21173728283" LAUNCH_CODEX=1` diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl.aborted-20260120T131437Z.jsonl b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/events.jsonl.aborted-20260120T131437Z.jsonl deleted file mode 100644 index e69de29bb..000000000 diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/last_message.md b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/last_message.md deleted file mode 100644 index e034aaf10..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/last_message.md +++ /dev/null @@ -1,18 +0,0 @@ -**What I did** -- Verified worktree/branch and `.taskmeta.json`; did not edit any planning docs under `docs/project_management/_archived/next/`. -- Local gates green: `cargo fmt --all`, `cargo clippy --workspace --all-targets -- -D warnings`, `cargo test` (via `make integ-checks`), `make integ-checks`. -- Fixed CI compile-parity failure (non-Linux clippy) with `2883f19d` (`fix(world): appease clippy on non-linux`). -- Ran `make triad-task-finish TASK_ID="C0-integ-core"` successfully. - -**CI Compile Parity (green)** -- `RUN_ID=21173624758` -- `RUN_URL=https://github.com/atomize-hq/substrate/actions/runs/21173624758` - -**Behavior Smoke (failed)** -- `RUN_ID=21173728283` -- `RUN_URL=https://github.com/atomize-hq/substrate/actions/runs/21173728283` -- `SMOKE_PASSED_PLATFORMS=` -- `SMOKE_FAILED_PLATFORMS=linux,macos` - -**Operator next step (from orchestration checkout)** -- Run: `make triad-task-start-platform-fixes-from-smoke FEATURE_DIR="docs/project_management/_archived/full-isolation-landlock-overlayfs-compat" SLICE_ID="C0" SMOKE_RUN_ID="21173728283" LAUNCH_CODEX=1` \ No newline at end of file diff --git a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/stderr.aborted-20260120T131437Z.log b/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/stderr.aborted-20260120T131437Z.log deleted file mode 100644 index 25079a45b..000000000 --- a/docs/project_management/_archived/full-isolation-landlock-overlayfs-compat/logs/C0/integ-core/stderr.aborted-20260120T131437Z.log +++ /dev/null @@ -1,44916 +0,0 @@ -OpenAI Codex v0.77.0 (research preview) --------- -workdir: /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core -model: gpt-5.2 -provider: openai -approval: never -sandbox: danger-full-access -reasoning effort: high -reasoning summaries: auto -session id: 019bdb52-d5d3-7c51-aac4-41ec3f753539 --------- -user -# Kickoff: C0-integ-core (integration core) - -## Scope -- Merge code + tests, resolve drift to spec, and make the slice green on the primary dev platform. -- Spec: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/C0-spec.md` -- Execution workflow standard: `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - -## Start Checklist -Do not edit planning docs inside the worktree. - -1. Verify you are in the task worktree `wt/full-isolation-landlock-overlayfs-compat-c0-integ-core` on branch `full-isolation-landlock-overlayfs-compat-c0-integ-core` and that `.taskmeta.json` exists at the worktree root. -2. Read: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/plan.md`, `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json`, `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/session_log.md`, spec, this prompt. -3. If `.taskmeta.json` is missing or mismatched, stop and ask the operator to run: - - `make triad-task-start FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" TASK_ID="C0-integ-core"` - -## Requirements -- Reconcile code/tests to spec (spec wins). -- If the slice is too large to make green deterministically (multiple subsystems, many unrelated acceptance bullets), stop and ask the operator to split the slice before continuing. -- Merge code+test branches into this worktree, then run required integration gates (must be green before any CI smoke dispatch): - - `cargo fmt` - - `cargo clippy --workspace --all-targets -- -D warnings` - - relevant tests - - `make integ-checks` -- Optional (once per feature, when you want a clean-cache assurance): `make preflight` - -### Local behavioral smoke preflight (required when possible; fast fail before CI dispatch) - -If `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/` exists and this machine matches a behavior platform for this feature, run the matching smoke script **locally** before dispatching compile parity or Feature Smoke. - -Determine behavior platforms: -- `jq -r '.meta.behavior_platforms_required // [] | join(\",\")' "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json"` - -Preflight steps (choose the block matching your current platform): - -Linux: -```bash -set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh" -``` - -macOS: -```bash -set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/macos-smoke.sh" -``` - -Windows (PowerShell): -```powershell -$ErrorActionPreference = "Stop" -cargo build --bin substrate -$env:Path = "$pwd\\target\\debug;$env:Path" -pwsh -File "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat\\smoke\\windows-smoke.ps1" -``` - -Expected: -- Exit `0`. - -### Cross-platform compile parity (CI dispatch; required before smoke) - -Before dispatching Feature Smoke (especially when using `RUNNER_KIND=self-hosted`), run a fast cross-platform compile parity preflight on GitHub-hosted runners to catch macOS/Windows compilation breaks early: -- `make ci-compile-parity CI_WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" CI_REMOTE=origin CI_CLEANUP=1` - -Notes: -- This dispatches CI Testing in `mode=compile-parity` (fmt --check, check --all-targets, clippy -D warnings) across Linux/macOS/Windows. -- If it fails, fix compile parity **in this integ-core worktree/branch** (cfg/platform guards), commit, and re-run until green; do not proceed to Feature Smoke until it is green. - -### Cross-platform smoke (CI dispatch; validation-only) - -Run CI smoke from this **integration-core worktree**, because the smoke dispatcher tests the current `HEAD` by creating a throwaway remote branch at that commit. - -Important (P3-008): -- Smoke is required only for the feature’s **behavior platforms** (`tasks.json` meta: `behavior_platforms_required`). -- CI parity may be required for a broader set of platforms (`tasks.json` meta: `ci_parity_platforms_required` / legacy `platforms_required`). - -Recommended dispatch (explicit params; leave `CLEANUP=1` on unless debugging temp branches): - -1) Dispatch behavioral smoke in a single run (preferred): - - `make feature-smoke FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" PLATFORM=behavior SMOKE_SLICE_ID="" RUNNER_KIND=self-hosted WORKFLOW_REF="feat/full-isolation-landlock-overlayfs-compat" REMOTE=origin CLEANUP=1 RUN_INTEG_CHECKS=1` - - `SMOKE_SLICE_ID` is optional; when provided, the workflow exports `SUBSTRATE_SMOKE_SLICE_ID` for slice-scoped smoke scripts. - - If WSL coverage is required for this feature, add `RUN_WSL=1`. - -What the dispatcher does (`scripts/ci/dispatch_feature_smoke.sh` via `make feature-smoke`): -- Creates/pushes a throwaway branch like `tmp/feature-smoke///` at current `HEAD`. -- Dispatches the workflow from `WORKFLOW_REF` while checking out that throwaway branch. -- Prints `DISPATCH_OK=0|1`, `RUN_ID=`, `RUN_URL=`, `SMOKE_PASSED_PLATFORMS=`, and `SMOKE_FAILED_PLATFORMS=` (plus `ERROR_KIND`/`ERROR_MESSAGE` on failures). -- Deletes the throwaway remote branch when `CLEANUP=1`. - -Note: -- If smoke fails, `make feature-smoke` will still print `DISPATCH_OK=1` + `RUN_ID`/`RUN_URL`, but will exit non-zero (GNU make typically reports this as exit code 2). Do not re-run just to “get a run id”; use `RUN_URL` to inspect failures and start platform-fix tasks as needed. - -If any platform smoke fails: -- Do not attempt platform-specific fixes in integ-core. -- Ask the operator to start only the failing platform-fix tasks **from the orchestration checkout** (not from a task worktree): - - If you have a single smoke run that covers multiple platforms (typical `PLATFORM=behavior` case): - - `make triad-task-start-platform-fixes-from-smoke FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" SLICE_ID="" SMOKE_RUN_ID="" LAUNCH_CODEX=1` - - If you dispatched per-platform smoke (multiple run ids): - - `make triad-task-start-platform-fixes FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" SLICE_ID="" PLATFORMS="" LAUNCH_CODEX=1` - - `` is the triad id prefix (e.g., `C0`, `C3`). - - `` is the `RUN_ID` from the failing smoke run (only used for `triad-task-start-platform-fixes-from-smoke`). - - `` is the comma-separated list of platforms you need platform-fix tasks for (typically the failing behavior platforms, plus `wsl` if `wsl_task_mode="separate"`). - -If behavioral smoke is green for all behavior platforms: -- Platform-fix tasks (if present in the pack) may still be required for CI-only failures (e.g., clippy warnings on macOS/Windows), so do not mark them no-op yet. -- The wrapper/final gate runs CI Testing; if CI Testing is green, then mark platform-fix tasks `completed` as no-ops to unblock the final aggregator’s `depends_on`: - - `triad/mark_noop_platform_fixes_completed.sh --feature-dir "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" --slice-id ""` (optional: add `--from-smoke-run ""` for logging) - -Once all required platform-fix tasks are completed, ask the operator to start the final aggregator from the orchestration checkout: -- `make triad-task-start-integ-final FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat" SLICE_ID="" LAUNCH_CODEX=1` - - Note: the final aggregator task id is `-integ` (the command name contains `integ-final`). - -## End Checklist -1. Ensure your merged state is committed and local integration gates are green: - - From inside the worktree, run: `make triad-task-finish TASK_ID="C0-integ-core"` -2. Dispatch cross-platform smoke from this worktree and include these exact key/value lines in your handoff (wrapper agents parse them): - - `RUN_ID=` - - `RUN_URL=` (if printed) - - `SMOKE_PASSED_PLATFORMS=` - - `SMOKE_FAILED_PLATFORMS=` (empty means success) -3. Hand off run ids/URLs and next-step instructions to the operator (do not edit planning docs inside the worktree). -4. Do not delete the worktree (feature cleanup removes worktrees at feature end). - -mcp: deepwiki starting -mcp: deepwiki ready -mcp startup: ready: deepwiki -Plan update - → Verify worktree, branch, taskmeta - • Read plan, tasks, session, spec - • Merge code and test branches - • Fix drift to spec - • Run fmt, clippy, tests, integ-checks - • Run local smoke preflight - • Commit and run triad finish - • Dispatch CI parity and smoke -exec -/bin/bash -lc 'set -euo pipefail -pwd -git rev-parse --show-toplevel -git branch --show-current -git status --porcelain=v1 -ls -la -[ -f .taskmeta.json ] && echo "TASKMETA_OK=1" || echo "TASKMETA_OK=0"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 67ms: -/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core -/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core -full-isolation-landlock-overlayfs-compat-c0-integ-core -total 352 -drwxr-xr-x 11 spenser spenser 4096 Jan 20 07:13 . -drwxr-xr-x 69 spenser spenser 4096 Jan 20 07:13 .. --rw-r--r-- 1 spenser spenser 9957 Jan 20 07:13 AGENTS.md --rw-r--r-- 1 spenser spenser 4899 Jan 20 07:13 build.rs --rw-r--r-- 1 spenser spenser 118601 Jan 20 07:13 Cargo.lock --rw-r--r-- 1 spenser spenser 2025 Jan 20 07:13 Cargo.toml --rw-r--r-- 1 spenser spenser 1397 Jan 20 07:13 CHANGELOG.md -drwxr-xr-x 2 spenser spenser 4096 Jan 20 07:13 config --rw-r--r-- 1 spenser spenser 4920 Jan 20 07:13 CONTRIBUTING.md -drwxr-xr-x 21 spenser spenser 4096 Jan 20 07:13 crates --rw-r--r-- 1 spenser spenser 308 Jan 20 07:13 Cross.toml --rw-r--r-- 1 spenser spenser 11050 Jan 20 07:13 deny.toml -drwxr-xr-x 3 spenser spenser 4096 Jan 20 07:13 dist --rw-r--r-- 1 spenser spenser 740 Jan 20 07:13 dist-workspace.toml -drwxr-xr-x 7 spenser spenser 4096 Jan 20 07:13 docs --rw-r--r-- 1 spenser spenser 116 Jan 20 07:13 .git -exec -/bin/bash -lc 'set -euo pipefail -cat .taskmeta.json' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 38ms: -{ - "created_at_utc": "2026-01-20T12:13:17Z", - "created_from_sha": "b215121257f3f53f461b0488e4bf313b83ef51b6", - "feature_dir": "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat", - "orchestration_branch": "feat/full-isolation-landlock-overlayfs-compat", - "schema_version": 1, - "task_branch": "full-isolation-landlock-overlayfs-compat-c0-integ-core", - "task_id": "C0-integ-core" -} -exec -/bin/bash -lc 'set -euo pipefail -ls -la docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat || true -ls -la docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke || true' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 46ms: -total 116 -drwxr-xr-x 4 spenser spenser 4096 Jan 20 07:13 . -drwxr-xr-x 10 spenser spenser 4096 Jan 20 07:13 .. --rw-r--r-- 1 spenser spenser 2192 Jan 20 07:13 C0-closeout_report.md --rw-r--r-- 1 spenser spenser 6649 Jan 20 07:13 C0-spec.md --rw-r--r-- 1 spenser spenser 15245 Jan 20 07:13 decision_register.md --rw-r--r-- 1 spenser spenser 4408 Jan 20 07:13 execution_preflight_report.md --rw-r--r-- 1 spenser spenser 2132 Jan 20 07:13 integration_map.md -drwxr-xr-x 2 spenser spenser 4096 Jan 20 07:13 kickoff_prompts --rw-r--r-- 1 spenser spenser 2778 Jan 20 07:13 manual_testing_playbook.md --rw-r--r-- 1 spenser spenser 1619 Jan 20 07:13 plan.md --rw-r--r-- 1 spenser spenser 8871 Jan 20 07:13 quality_gate_report.md --rw-r--r-- 1 spenser spenser 11566 Jan 20 07:13 session_log.md -drwxr-xr-x 2 spenser spenser 4096 Jan 20 07:13 smoke --rw-r--r-- 1 spenser spenser 26098 Jan 20 07:13 tasks.json -total 20 -drwxr-xr-x 2 spenser spenser 4096 Jan 20 07:13 . -drwxr-xr-x 4 spenser spenser 4096 Jan 20 07:13 .. --rw-r--r-- 1 spenser spenser 3252 Jan 20 07:13 linux-smoke.sh --rw-r--r-- 1 spenser spenser 3253 Jan 20 07:13 macos-smoke.sh -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,220p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/plan.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 47ms: -# full-isolation-landlock-overlayfs-compat — plan - -## Scope -- Feature directory: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/` -- Orchestration branch: `feat/full-isolation-landlock-overlayfs-compat` -- ADR: `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -## Goal -- Restore `world_fs.write_allowlist` correctness in `world_fs.isolation=full` + `world_fs.mode=writable` on Linux when Landlock is supported and overlayfs is the active filesystem strategy. - -## Non-Goals -- Any policy snapshot schema changes or policy snapshot hash behavior changes. -- Any new user-facing allowlist syntaxes or matching semantics. -- Any behavior changes for macOS or Windows world backends. - -## Platform scope -- Behavior platforms (smoke required): Linux, macOS. -- CI parity platforms (compile parity required): Linux, macOS, Windows. -- WSL coverage: not required. - -exec -/bin/bash -lc "set -euo pipefail -jq -r '.meta' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 46ms: -{ - "schema_version": 3, - "feature": "full-isolation-landlock-overlayfs-compat", - "cross_platform": true, - "execution_gates": true, - "automation": { - "enabled": true, - "orchestration_branch": "feat/full-isolation-landlock-overlayfs-compat" - }, - "behavior_platforms_required": [ - "linux", - "macos" - ], - "ci_parity_platforms_required": [ - "linux", - "macos", - "windows" - ] -} -exec -/bin/bash -lc "set -euo pipefail -jq -r '.tasks[] | select(.id|test(\""'^C0")) | {id, kind, branch, depends_on, platform, status}'"' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/tasks.json" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 40ms: -{ - "id": "C0-code", - "kind": null, - "branch": null, - "depends_on": [ - "F0-exec-preflight" - ], - "platform": null, - "status": "completed" -} -{ - "id": "C0-test", - "kind": null, - "branch": null, - "depends_on": [ - "F0-exec-preflight" - ], - "platform": null, - "status": "completed" -} -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,260p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/session_log.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 41ms: -# full-isolation-landlock-overlayfs-compat — session log - -## START — 2026-01-20T01:52:53Z — planning — planning pack for ADR-0015 (full isolation Landlock ↔ overlayfs backing dirs) -- Feature: `docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/` -- Branch: `testing` -- Goal: Produce an execution-ready Planning Pack for ADR-0015 under the correct feature directory, with validated tasks/prompts/smoke and zero ambiguity in specs/contracts. -- Inputs to read end-to-end: - - `docs/project_management/standards/PLANNING_RESEARCH_AND_ALIGNMENT_STANDARD.md` - - `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` - - `docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md` - - `docs/project_management/standards/PLATFORM_INTEGRATION_AND_CI.md` - - `docs/project_management/standards/ADR_STANDARD_AND_TEMPLATE.md` - - `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - - `docs/project_management/standards/PLANNING_SESSION_LOG_TEMPLATE.md` - - `docs/project_management/packs/sequencing.json` - - `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` -- Commands planned (if any): - - `make planning-new-feature FEATURE=full-isolation-landlock-overlayfs-compat DECISION_HEAVY=1 CROSS_PLATFORM=1 AUTOMATION=1 BEHAVIOR_PLATFORMS=linux CI_PARITY_PLATFORMS=linux,macos,windows` - - `python3 planning/validate_tasks_json.py --feature-dir "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat"` - - `make planning-validate FEATURE_DIR="docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat"` -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,260p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/C0-spec.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 40ms: -# C0-spec — Full isolation Landlock ↔ OverlayFS backing dirs allowlist - -Authoritative ADR: -- `docs/project_management/adrs/implemented/ADR-0015-full-isolation-landlock-overlayfs-backing-dirs.md` - -Exit codes: -- Exit code taxonomy: `docs/project_management/standards/EXIT_CODE_TAXONOMY.md` - -## Scope -- Behavior is Linux-kernel-specific; this slice is validated on: - - Linux hosts, and - - macOS hosts via the Lima Linux guest (world backend). -- Restore the operator contract for `world_fs.write_allowlist` in: - - `world_fs.isolation=full` - - `world_fs.mode=writable` - - Landlock supported by the running kernel - - overlayfs is the active world filesystem strategy -- Extend the full-isolation Landlock write allowlist with runtime-derived overlayfs internal write roots: - - `upperdir` - - `workdir` -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,220p' docs/project_management/standards/TASK_TRIADS_WORKTREE_EXECUTION_STANDARD.md" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 41ms: -# Task Triads — Worktree Execution Standard (Automation + Concurrent Code/Test) - -This standard is for **execution-time** triad work when tasks are started via triad automation (preferred), and the agent is already running **inside a task worktree**. - -It is a focused companion to: -- `docs/project_management/standards/TASK_TRIADS_AND_FEATURE_SETUP.md` (full planning pack + task schema + integration model) - -## Operating assumptions (the situation you are in) - -When this standard applies, the operator started you with one of: -- `make triad-task-start-pair FEATURE_DIR="docs/project_management/_archived/next/" SLICE_ID="" LAUNCH_CODEX=1` (preferred) -- `make triad-task-start FEATURE_DIR="docs/project_management/_archived/next/" TASK_ID="" LAUNCH_CODEX=1` - -You are already: -- in a git worktree (usually under `wt/...`) -- on a task branch (not the orchestration branch) -- expected to find `.taskmeta.json` at the worktree root (task id, orchestration branch, etc.) - -## Non-negotiable safety rule - -Plan update - ✓ Verify worktree, branch, taskmeta - ✓ Read plan, tasks, session, spec - → Merge code and test branches - • Fix drift to spec - • Run fmt, clippy, tests, integ-checks - • Run local smoke preflight - • Commit and run triad finish - • Dispatch CI parity and smoke -exec -/bin/bash -lc "set -euo pipefail -git log --oneline --decorate -10 - -git show -s --format='HEAD=%H%nPARENTS=%P%nSUBJECT=%s' HEAD" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 38ms: -b2151212 (HEAD -> full-isolation-landlock-overlayfs-compat-c0-integ-core, feat/full-isolation-landlock-overlayfs-compat) docs: finish C0 code+test -c7129f09 docs: start C0 code+test -208f1c92 docs: finish F0-exec-preflight -70ddaecd docs: start F0-exec-preflight -e29fbb99 (origin/testing, origin/feat/full-isolation-landlock-overlayfs-compat, testing) planning: full-isolation-landlock-overlayfs-compat -3d2bc4ce planning: full-isolation-landlock-overlayfs-compat -47a4c379 (origin/feat/policy-patch-only-broker-effective-resolution, feat/policy-patch-only-broker-effective-resolution) docs: ADR-0015 -98decc08 docs: ADR-0015 -643f0087 fix(dev-uninstall): show Lima disable errors -8efafac3 fix(world): gate netfilter rule install behind env -HEAD=b215121257f3f53f461b0488e4bf313b83ef51b6 -PARENTS=c7129f092251e000c77b826f93bcd80db2707699 -SUBJECT=docs: finish C0 code+test -exec -/bin/bash -lc "set -euo pipefail -git branch --list 'full-isolation-landlock-overlayfs-compat-c0-*' - -git rev-parse full-isolation-landlock-overlayfs-compat-c0-code - -git rev-parse full-isolation-landlock-overlayfs-compat-c0-test" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 56ms: -+ full-isolation-landlock-overlayfs-compat-c0-code -* full-isolation-landlock-overlayfs-compat-c0-integ-core -+ full-isolation-landlock-overlayfs-compat-c0-test -c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1 -5fee99a14e0061671df25502491929fca1f65ad7 -exec -/bin/bash -lc "set -euo pipefail -# Quick diffstat vs each branch to see what they'd bring -for b in full-isolation-landlock-overlayfs-compat-c0-code full-isolation-landlock-overlayfs-compat-c0-test; do - echo \"--- DIFFSTAT from "'$b" - git diff --stat HEAD..$b -done' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 47ms: ---- DIFFSTAT from full-isolation-landlock-overlayfs-compat-c0-code - crates/world-agent/src/internal_exec.rs | 82 +++++++++ - crates/world/src/lib.rs | 1 + - crates/world/src/mountinfo.rs | 188 +++++++++++++++++++++ - .../session_log.md | 38 ----- - .../tasks.json | 4 +- - 5 files changed, 273 insertions(+), 40 deletions(-) ---- DIFFSTAT from full-isolation-landlock-overlayfs-compat-c0-test - crates/world-agent/tests/full_isolation_nonpty.rs | 8 ++ - .../world-agent/tests/landlock_exec_fail_closed.rs | 137 +++++++++++++++++++ - .../mountinfo/duplicate_mountpoints.mountinfo | 4 + - .../fixtures/mountinfo/missing_workdir.mountinfo | 3 + - .../mountinfo/non_overlay_for_project.mountinfo | 3 + - .../mountinfo/overlay_ok_with_escapes.mountinfo | 2 + - crates/world/tests/mountinfo_parsing.rs | 146 +++++++++++++++++++++ - .../session_log.md | 38 ------ - .../tasks.json | 4 +- - 9 files changed, 305 insertions(+), 40 deletions(-) - - - - - -thinking -**Evaluating code integration strategy** - -I think the workflow expects the integration core to reconcile and choose specifications. The current core branch is based on documents from commits and possibly the orchestration branch. There's a commit indicating updates to planning documents by automation. To merge code and test branches, I should probably use `git merge` with `--no-commit`, then revert the planning docs to the current HEAD version. Alternatively, we could cherry-pick commits that only affect production and test files, leaving the docs unchanged. However, since those branches touch the planning docs, merging while keeping our versions for those files seems better. I need to inspect the code branch history to ensure it matches the specifications. -thinking -**Assessing branch integration** - -I’ve noticed that the current branch `feat/full-isolation-landlock-overlayfs-compat` seems to act as a local branch pointer. `git log` shows that HEAD has both the integration core and the `feat/full...` branch pointing to the same commit, which means our worktree likely has remote tracking. Automation may have created this branch for convenience. However, our `.taskmeta` indicates a different orchestration branch. I should confirm that `git status` is clean, which it is! Now, I’ll merge the code and test branches, making sure not to modify the planning documents. -thinking -**Analyzing merge changes** - -I’m realizing that merging might introduce changes, and I’d need to ensure the current version of the docs stays intact, as per the integration core branch. The diffstat shows changes in `tasks.json` and `session_log`, suggesting deletions of start/finish entries. It seems that these document modifications should be excluded from the integration. Considering that tasks are updated on the orchestration branch, any changes to docs should not be merged. Thus, I need to focus on merging only the code and tests from their respective branches without altering the planning documents. -thinking -**Planning cherry-picking commits** - -I can use `git cherry-pick` for specific commits from each branch that implement code and test changes, while skipping any doc-related commits. First, I need to review the commit list on the code and test branches by running `git log --oneline --decorate --max-count`. I'll ensure the changes align with the specifications, which include mountinfo parsing logic and various tests. The code branch shows significant additions, including updates to `mountinfo.rs` and `internal_exec.rs`. I need to closely examine these changes before merging to anticipate any potential issues. -thinking -**Opening relevant files** - -I’m planning to open the necessary files on those branches using `git show branch:path` or `git show branch --stat`. This way, I can review the details effectively. I think running these tool commands in parallel would be efficient, allowing me to compare everything side by side. This should help me identify any specific changes quickly. It feels like a good step to ensure the accuracy of the integration process! -exec -/bin/bash -lc 'set -euo pipefail -for b in full-isolation-landlock-overlayfs-compat-c0-code full-isolation-landlock-overlayfs-compat-c0-test; do - echo "== $b"; - git log --oneline --decorate --max-count=20 $b; - echo; -done' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 48ms: -== full-isolation-landlock-overlayfs-compat-c0-code -c9383284 (full-isolation-landlock-overlayfs-compat-c0-code) fix: allow landlock with overlayfs backing dirs -c7129f09 docs: start C0 code+test -208f1c92 docs: finish F0-exec-preflight -70ddaecd docs: start F0-exec-preflight -e29fbb99 (origin/testing, origin/feat/full-isolation-landlock-overlayfs-compat, testing) planning: full-isolation-landlock-overlayfs-compat -3d2bc4ce planning: full-isolation-landlock-overlayfs-compat -47a4c379 (origin/feat/policy-patch-only-broker-effective-resolution, feat/policy-patch-only-broker-effective-resolution) docs: ADR-0015 -98decc08 docs: ADR-0015 -643f0087 fix(dev-uninstall): show Lima disable errors -8efafac3 fix(world): gate netfilter rule install behind env -047ae280 test(shell): avoid host world deps probe in health -a08ef8c2 fix(world-mac-lima): harden SSH UDS forwarding -52c704a5 fix(world): refuse unscoped netfilter rules -431cc85c fix: surface ssh errors when Lima UDS forwarding fails -eef44cf8 fix: rollback nftables table on netfilter install failure -e4cf2d00 chore: temporarily skip Windows execute smoke in CI -e50f66b3 fix: avoid WSL execute hangs from netfilter monitoring -afe34c26 (tmp/feature-smoke/world-agent-policy-snapshot/windows/20260119T153837Z) fix: add timeouts and diagnostics for Windows WSL exec -d696cf82 fix: force Windows smoke to use pipe transport -exec -/bin/bash -lc 'set -euo pipefail -# Show the code commit content (excluding docs changes) for quick review -CODE_SHA=$(git rev-list --max-count=1 full-isolation-landlock-overlayfs-compat-c0-code) -TEST_SHA=$(git rev-list --max-count=1 full-isolation-landlock-overlayfs-compat-c0-test) -echo "CODE_SHA=$CODE_SHA" -echo "TEST_SHA=$TEST_SHA" - -git show --name-only --oneline $CODE_SHA - -git show --name-only --oneline $TEST_SHA' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 63ms: -CODE_SHA=c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1 -TEST_SHA=5fee99a14e0061671df25502491929fca1f65ad7 -c9383284 fix: allow landlock with overlayfs backing dirs -crates/world-agent/src/internal_exec.rs -crates/world/src/lib.rs -crates/world/src/mountinfo.rs -5fee99a1 task: C0-test -crates/world-agent/tests/full_isolation_nonpty.rs -crates/world-agent/tests/landlock_exec_fail_closed.rs -crates/world/tests/fixtures/mountinfo/duplicate_mountpoints.mountinfo -crates/world/tests/fixtures/mountinfo/missing_workdir.mountinfo -crates/world/tests/fixtures/mountinfo/non_overlay_for_project.mountinfo -crates/world/tests/fixtures/mountinfo/overlay_ok_with_escapes.mountinfo -crates/world/tests/mountinfo_parsing.rs -exec -/bin/bash -lc "set -euo pipefail -# Peek at the new mountinfo parser file on code branch -sed -n '1,260p' <(git show full-isolation-landlock-overlayfs-compat-c0-code:crates/world/src/mountinfo.rs)" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 42ms: -use std::path::{Path, PathBuf}; - -#[derive(Debug, Clone, PartialEq, Eq)] -pub struct OverlayBackingDirs { - pub upperdir: PathBuf, - pub workdir: PathBuf, -} - -#[derive(Debug, thiserror::Error)] -pub enum OverlayBackingDirsError { - #[error("mountpoint was empty")] - EmptyMountpoint, - #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] - NoMatchingMountpoint { mountpoint: String }, - #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] - WrongFsType { mountpoint: String, fs_type: String }, - #[error("overlay mount for {mountpoint:?} is missing super option {key}")] - MissingSuperOption { - mountpoint: String, - key: &'static str, -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,240p' <(git show full-isolation-landlock-overlayfs-compat-c0-code:crates/world-agent/src/internal_exec.rs)" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 44ms: -use anyhow::{Context, Result}; -#[cfg(target_os = "linux")] -use substrate_common::WorldFsMode; - -pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -const INNER_CMD_ENV: &str = "SUBSTRATE_INNER_CMD"; -const INNER_LOGIN_SHELL_ENV: &str = "SUBSTRATE_INNER_LOGIN_SHELL"; -const MOUNT_CWD_ENV: &str = "SUBSTRATE_MOUNT_CWD"; -#[cfg(target_os = "linux")] -const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; -#[cfg(target_os = "linux")] -const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -#[cfg(target_os = "linux")] -const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; - -const LANDLOCK_READ_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_READ_ALLOWLIST"; -const LANDLOCK_WRITE_ENV: &str = "SUBSTRATE_WORLD_FS_LANDLOCK_WRITE_ALLOWLIST"; - -pub fn run_landlock_exec() -> Result<()> { -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,240p' <(git show full-isolation-landlock-overlayfs-compat-c0-test:crates/world/tests/mountinfo_parsing.rs)" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 45ms: -#![cfg(target_os = "linux")] - -use anyhow::{anyhow, Context, Result}; - -fn decode_mountinfo_escapes(input: &str) -> String { - input - .replace("\\040", " ") - .replace("\\011", "\t") - .replace("\\012", "\n") - .replace("\\134", "\\") -} - -fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { - let mut best: Option<(u32, String, String)> = None; - - for (line_no, line) in mountinfo_text.lines().enumerate() { - let line = line.trim(); - if line.is_empty() { - continue; - } -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,240p' <(git show full-isolation-landlock-overlayfs-compat-c0-test:crates/world-agent/tests/landlock_exec_fail_closed.rs)" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 45ms: -#![cfg(all(unix, target_os = "linux"))] - -use std::process::Command; - -use tempfile::tempdir; -use world_agent::internal_exec::LANDLOCK_EXEC_ARG; - -fn landlock_supported() -> bool { - world::landlock::detect_support().supported -} - -fn world_agent_bin() -> String { - if let Some(bin) = option_env!("CARGO_BIN_EXE_world_agent") { - return bin.to_string(); - } - if let Some(bin) = option_env!("CARGO_BIN_EXE_world-agent") { - return bin.to_string(); - } - if let Ok(bin) = std::env::var("CARGO_BIN_EXE_world_agent") { - return bin; - - - - - - -thinking -**Reviewing code consistency** - -I’m looking at the mountinfo parser from the code branch. It seems to define `decode_mountinfo_escapes` to support any octal sequence, which isn't limited to the ones specified. But does the spec only require decoding certain sequences? Though decoding all octal might be okay, the spec specifically says to decode mountinfo escape sequences. - -I notice the test branch has duplicate functions that aren’t using the production parser, and that’s not ideal; using the production function would align better with the spec! -thinking -**Examining mountinfo parsing** - -I’m reviewing the parser function `overlay_backing_dirs_from_mountinfo`, which splits the mountinfo line at " - ". It extracts `mount_point_raw` from the fifth field and decodes mountinfo escapes, which is good. - -For the "right" side of the split, it gets `fs_type`, `mount_source`, and then `super_options`. But I realize that `super_options` could potentially contain spaces—though generally, they're comma-separated without spaces. The test branch assumes there might be multiple fields for `super_options`, but in our case, we only need one token for it. -thinking -**Clarifying parser logic** - -I'm thinking about handling extra tokens—we can ignore them, but could they appear? Some kernels might have super options with spaces encoded as `\040`, so no actual whitespace is involved, which is fine. - -Our parser already uses `parse_super_options` to split by commas and equals, and we’re storing those in a `HashMap<&str,&str>` while ensuring the original `super_options` string lifetimes are maintained. Plus, our selection rule for entries based on mount IDs is correct. - -However, I realize that for error handling, we need actionable messages, including the mountpoint and hints about missing requirements, with an exit code of 4. -thinking -**Investigating the `extend_overlayfs` function** - -My focus is on the `extend_overlayfs...` function, which checks for Landlock support by calling `detect_support`. If Landlock isn’t supported, it returns early. - -It also checks for the `mountpoint_env`; if that's missing or empty, it fails with exit code 4 and provides a message stating that "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty." When passing the `mountpoint_env`, it can print as an empty string, which aligns with the spec. - -The function reads mountinfo and uses a parser; if errors occur, it maps them to requirement strings. It’s crucial that specific conditions are met for derivation, such as being fully isolated and writable, along with Landlock support. -thinking -**Analyzing mountpoint checks and integration** - -The spec indicates that Landlock support needs to be applied for execution, which our code addresses by checking if `read_paths` and `write_paths` are non-empty. If both are empty, it doesn't enforce anything, but if conditions are met, the function calls `extend_overlayfs`. - -The function needs to derive overlayfs backing directories from `mountinfo` based on specific conditions, ensuring that certain paths are decoded correctly. If `mountpoint_env` has spaces, it should align with how `mountinfo` uses escapes. - -Now, regarding testing, the tests should utilize the production parser and ensure they check for specific error messages. I’ll merge the code and test branches by cherry-picking the necessary commits while keeping documentation intact. That seems like the best approach! -thinking -**Cherry-picking commits for integration** - -I need to ensure our current branch includes the necessary commits, but it seems to only have documentation commits. Cherry-picking seems like the right approach here. I’ll start with the code commit first, followed by the test commit, so I'll run `git cherry-pick c9383284` and then `git cherry-pick 5fee99a1`. - -I'm aware that there might be conflicts with the existing code, and the test commit might depend on the code commit, but I'll handle it step by step. I’ll also verify everything by building afterward! -exec -/bin/bash -lc 'set -euo pipefail -# Cherry-pick in the code+test commits without pulling planning-doc drift. -git cherry-pick c9383284d249bdd0cb7b2ac864b68a6ede2ef0b1 - -git cherry-pick 5fee99a14e0061671df25502491929fca1f65ad7' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 81ms: -[full-isolation-landlock-overlayfs-compat-c0-integ-core b79aabbb] fix: allow landlock with overlayfs backing dirs - Date: Mon Jan 19 22:23:51 2026 -0500 - 3 files changed, 271 insertions(+) - create mode 100644 crates/world/src/mountinfo.rs -[full-isolation-landlock-overlayfs-compat-c0-integ-core 695c41fa] task: C0-test - Date: Mon Jan 19 22:26:25 2026 -0500 - 7 files changed, 303 insertions(+) - create mode 100644 crates/world-agent/tests/landlock_exec_fail_closed.rs - create mode 100644 crates/world/tests/fixtures/mountinfo/duplicate_mountpoints.mountinfo - create mode 100644 crates/world/tests/fixtures/mountinfo/missing_workdir.mountinfo - create mode 100644 crates/world/tests/fixtures/mountinfo/non_overlay_for_project.mountinfo - create mode 100644 crates/world/tests/fixtures/mountinfo/overlay_ok_with_escapes.mountinfo - create mode 100644 crates/world/tests/mountinfo_parsing.rs - -thinking -**Updating plan progress** - -I've successfully completed step 3 of the merge plan, and I'm now moving on to step 4, which involves fixing the drift to the specification. I'll review the integrated code and tests to ensure they're compliant and make adjustments if necessary. I'll check for any modified documentation files using `git status`, and it should confirm everything is clean since the cherry-pick didn't touch those planning documents. Let's update the plan and take a closer look! -Plan update - ✓ Verify worktree, branch, taskmeta - ✓ Read plan, tasks, session, spec - ✓ Merge code and test branches - → Fix drift to spec - • Run fmt, clippy, tests, integ-checks - • Run local smoke preflight - • Commit and run triad finish - • Dispatch CI parity and smoke -exec -/bin/bash -lc 'set -euo pipefail -git status --porcelain=v1 - -git log --oneline --decorate -8' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 62ms: -695c41fa (HEAD -> full-isolation-landlock-overlayfs-compat-c0-integ-core) task: C0-test -b79aabbb fix: allow landlock with overlayfs backing dirs -b2151212 (feat/full-isolation-landlock-overlayfs-compat) docs: finish C0 code+test -c7129f09 docs: start C0 code+test -208f1c92 docs: finish F0-exec-preflight -70ddaecd docs: start F0-exec-preflight -e29fbb99 (origin/testing, origin/feat/full-isolation-landlock-overlayfs-compat, testing) planning: full-isolation-landlock-overlayfs-compat -3d2bc4ce planning: full-isolation-landlock-overlayfs-compat -exec -/bin/bash -lc "set -euo pipefail -# Ensure planning docs weren't changed by the cherry-picks -CHANGED_DOCS="'$(git diff --name-only HEAD~2..HEAD | rg '"'"'^docs/project_management/_archived/next/'"' || true) -if [ -n \""'$CHANGED_DOCS" ]; then echo "ERROR: planning docs changed"; echo "$CHANGED_DOCS"; exit 1; fi - -echo "PLANNING_DOCS_CHANGED=0"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 45ms: -PLANNING_DOCS_CHANGED=0 -exec -/bin/bash -lc "set -euo pipefail -# Open the new mountinfo module and world lib changes -sed -n '1,260p' crates/world/src/mountinfo.rs -sed -n '1,120p' crates/world/src/lib.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 37ms: -use std::path::{Path, PathBuf}; - -#[derive(Debug, Clone, PartialEq, Eq)] -pub struct OverlayBackingDirs { - pub upperdir: PathBuf, - pub workdir: PathBuf, -} - -#[derive(Debug, thiserror::Error)] -pub enum OverlayBackingDirsError { - #[error("mountpoint was empty")] - EmptyMountpoint, - #[error("no mountinfo entry matches mountpoint {mountpoint:?}")] - NoMatchingMountpoint { mountpoint: String }, - #[error("mountpoint {mountpoint:?} is fs_type {fs_type:?}, expected \"overlay\"")] - WrongFsType { mountpoint: String, fs_type: String }, - #[error("overlay mount for {mountpoint:?} is missing super option {key}")] - MissingSuperOption { - mountpoint: String, - key: &'static str, -exec -/bin/bash -lc "set -euo pipefail -# Open the world-agent landlock exec wrapper and the new tests -rg -n \"extend_overlayfs_backing_dir_allowlist_or_fail_closed|fail_closed_overlayfs_prereq|SUBSTRATE_MOUNT_PROJECT_DIR\" crates/world-agent/src/internal_exec.rs -sed -n '1,260p' crates/world-agent/src/internal_exec.rs - -sed -n '1,260p' crates/world/tests/mountinfo_parsing.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 44ms: -11:const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; -42: extend_overlayfs_backing_dir_allowlist_or_fail_closed(&mut write_paths); -153:fn extend_overlayfs_backing_dir_allowlist_or_fail_closed(write_paths: &mut Vec) { -162: fail_closed_overlayfs_prereq( -164: "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -170: Err(err) => fail_closed_overlayfs_prereq( -182: "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -205: fail_closed_overlayfs_prereq(mountpoint, &requirement); -214:fn fail_closed_overlayfs_prereq(mountpoint: &str, missing_requirement: &str) -> ! { -use anyhow::{Context, Result}; -#[cfg(target_os = "linux")] -use substrate_common::WorldFsMode; - -pub const LANDLOCK_EXEC_ARG: &str = "__substrate_world_landlock_exec"; - -const INNER_CMD_ENV: &str = "SUBSTRATE_INNER_CMD"; -const INNER_LOGIN_SHELL_ENV: &str = "SUBSTRATE_INNER_LOGIN_SHELL"; -const MOUNT_CWD_ENV: &str = "SUBSTRATE_MOUNT_CWD"; -#[cfg(target_os = "linux")] -const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; - - -thinking -**Evaluating code processing** - -If `char::from_u32` returns None for invalid inputs, I think we just push the backslash and move forward, leaving any digits to be processed later. That seems okay, especially since our string should look like `\XYZ`. Now, I noticed our test fixtures include a line that has `upperdir=/var/lib/substrate/ovl\\040space/upper`, which means our decode should turn `\040` into a space. - -I realize the test file `mountinfo_parsing.rs` is Linux-specific, but we could be modifying it to call the `overlay_backing_dirs_from_mountinfo` function. So I wonder if the world crate could compile on other OS too? But, are tests only run on certain systems? It seems like they must compile across platforms, including mac and Windows. -thinking -**Confirming test configurations** - -If the file is set to `cfg(target_os="linux")`, then it's not going to compile on macOS. I see the world-agent tests include `#![cfg(all(unix, target_os = "linux"))]`, which means they won't compile on mac in the CI, since mac is Unix but not Linux. So, that's safe, but behavior tests include macOS. However, the world-agent runs in a Lima Linux guest, meaning tests aren't necessary for mac compile. - -We should definitely confirm modifications in `full_isolation_nonpty.rs`. I'll open that file to ensure everything is correct. -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,240p' crates/world-agent/tests/full_isolation_nonpty.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 20ms: -#![cfg(all(unix, target_os = "linux"))] - -use agent_api_types::{ExecuteRequest, WorldFsMode}; -use base64::engine::general_purpose::STANDARD as BASE64; -use base64::Engine; -use std::collections::HashMap; -use std::fs; -use std::os::unix::fs::PermissionsExt; -use std::path::{Path, PathBuf}; -use substrate_broker::{set_global_broker, BrokerHandle}; -use tempfile::tempdir; -use tokio::runtime::Runtime; -use world_agent::WorldAgentService; - -fn decode(b64: &str) -> String { - String::from_utf8_lossy( - &BASE64 - .decode(b64.as_bytes()) - .unwrap_or_else(|_| Vec::from(b"")), - ) -exec -/bin/bash -lc 'set -euo pipefail -rg -n "write_allowlist|allowlisted" crates/world-agent/tests/full_isolation_nonpty.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 42ms: -81:fn write_profile_policy(project_dir: &Path, write_allowlist: &[&str]) { -85: let allowlist_yaml = if write_allowlist.is_empty() { -86: " write_allowlist: []\n".to_string() -88: let mut out = String::from(" write_allowlist:\n"); -89: for pattern in write_allowlist { -271:fn non_pty_full_isolation_honors_write_allowlist_prefix_globs() { -329: "allowlisted write should not mutate host project directory" -exec -/bin/bash -lc "set -euo pipefail -sed -n '240,380p' crates/world-agent/tests/full_isolation_nonpty.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 38ms: - - let tmp = tempdir().expect("tempdir"); - let cwd = tmp.path().to_path_buf(); - - let resp = match execute_non_pty( - &service, - &cwd, - "sh -lc 'pwd'", - base_cage_env(), - WorldFsMode::Writable, - ) { - Some(resp) => resp, - None => return, - }; - - assert_eq!( - resp.exit, - 0, - "full-isolation execution failed unexpectedly: exit={} stderr={}", - resp.exit, -exec -/bin/bash -lc 'set -euo pipefail -for f in crates/world/tests/fixtures/mountinfo/*.mountinfo; do - echo "== $f"; - cat "$f"; - echo; -done' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 43ms: -== crates/world/tests/fixtures/mountinfo/duplicate_mountpoints.mountinfo -10 1 0:31 / /proc rw,nosuid,nodev,noexec,relatime - proc proc rw -42 10 0:45 / /project rw,relatime shared:1 - overlay overlay rw,upperdir=/var/lib/substrate/low/upper,workdir=/var/lib/substrate/low/work -128 10 0:45 / /project rw,relatime shared:1 - overlay overlay rw,upperdir=/var/lib/substrate/high/upper,workdir=/var/lib/substrate/high/work - - -== crates/world/tests/fixtures/mountinfo/missing_workdir.mountinfo -36 25 0:31 / /proc rw,nosuid,nodev,noexec,relatime - proc proc rw -100 36 0:45 / /project rw,relatime shared:1 - overlay overlay rw,upperdir=/var/lib/substrate/ovl/upper - - -== crates/world/tests/fixtures/mountinfo/non_overlay_for_project.mountinfo -36 25 0:31 / /proc rw,nosuid,nodev,noexec,relatime - proc proc rw -100 36 0:45 / /project rw,relatime shared:1 - ext4 /dev/sda1 rw - - -== crates/world/tests/fixtures/mountinfo/overlay_ok_with_escapes.mountinfo -36 25 0:31 / /proc rw,nosuid,nodev,noexec,relatime - proc proc rw -100 36 0:45 / /project rw,relatime shared:1 - overlay overlay rw,lowerdir=/lower,upperdir=/var/lib/substrate/ovl\040space/upper,workdir=/var/lib/substrate/ovl\011tab/work - -exec -/bin/bash -lc 'set -euo pipefail -rg -n "overlay_backing_dirs_from_mountinfo" -S crates/world/tests/mountinfo_parsing.rs crates/world/src/mountinfo.rs' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 46ms: -crates/world/tests/mountinfo_parsing.rs:68:fn derive_overlay_backing_dirs_from_mountinfo( -crates/world/tests/mountinfo_parsing.rs:110: derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -crates/world/tests/mountinfo_parsing.rs:119: derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -crates/world/tests/mountinfo_parsing.rs:127: let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -crates/world/tests/mountinfo_parsing.rs:139: let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -crates/world/src/mountinfo.rs:40:pub fn overlay_backing_dirs_from_mountinfo( - -thinking -**Working on unit tests** - -I'm focusing on a spec that mentions if multiple entries match exactly, I should select the one with the greatest numeric mount ID. My parser does that, which is great! I need to make sure we didn't exceed the slice size since it's limited, though. It sounds like I just need to patch the tests, making it a small fix. I’ll adjust `mountinfo_parsing.rs` accordingly and use `apply_patch` to make those changes. -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/world/tests/mountinfo_parsing.rs -@@ -2,105 +2,6 @@ - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] -@@ -108,6 +9,11 @@ - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } -@@ -117,6 +23,5 @@ - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } -@@ -126,9 +31,8 @@ - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } -@@ -138,9 +42,8 @@ - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } -apply_patch(auto_approved=true) exited 0 in 12ms: -Success. Updated the following files: -M crates/world/tests/mountinfo_parsing.rs -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -rg -n "SUBSTRATE_WORLD_FS_ISOLATION|SUBSTRATE_WORLD_FS_MODE|SUBSTRATE_MOUNT_PROJECT_DIR" crates/world-agent/src | head -n 50' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 39ms: -crates/world-agent/src/internal_exec.rs:11:const MOUNT_PROJECT_DIR_ENV: &str = "SUBSTRATE_MOUNT_PROJECT_DIR"; -crates/world-agent/src/internal_exec.rs:13:const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -crates/world-agent/src/internal_exec.rs:15:const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; -crates/world-agent/src/internal_exec.rs:164: "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty", -crates/world-agent/src/internal_exec.rs:182: "SUBSTRATE_MOUNT_PROJECT_DIR is missing or empty".to_string() -crates/world-agent/src/service.rs:38:pub(crate) const WORLD_FS_MODE_ENV: &str = "SUBSTRATE_WORLD_FS_MODE"; -crates/world-agent/src/service.rs:39:pub(crate) const WORLD_FS_ISOLATION_ENV: &str = "SUBSTRATE_WORLD_FS_ISOLATION"; -crates/world-agent/src/pty.rs:421: "SUBSTRATE_MOUNT_PROJECT_DIR".to_string(), -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -sed -n '360,520p' crates/world-agent/src/pty.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 32ms: - ); - } - } - - if let Ok(exe) = std::env::current_exe() { - env.entry("SUBSTRATE_LANDLOCK_HELPER_SRC".to_string()) - .or_insert_with(|| exe.display().to_string()); - } - - let spec = WorldSpec { - reuse_session: true, - isolate_network: true, - limits: ResourceLimits::default(), - enable_preload: false, - allowed_domains, - project_dir: project_dir.clone(), - always_isolate: true, - fs_mode, - }; - -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Investigating environment variables** - -I'm noticing that the PTY path is setting `SUBSTRATE_MOUNT_PROJECT_DIR`, but it seems like our `internal_exec` is expecting `SUBSTRATE_WORLD_FS_MODE` and `SUBSTRATE_WORLD_FS_ISOLATION`. It likely means that these variables are configured in a different location. I should take a look at `service.rs` to check where they might be defined. There's a clear dependency to unravel here, and I want to make sure we’re aligning everything correctly! -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,120p' crates/world-agent/src/service.rs -rg -n \"WORLD_FS_MODE_ENV|WORLD_FS_ISOLATION_ENV\" crates/world-agent/src/service.rs crates/world-agent/src/pty.rs | head -n 80" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 49ms: -//! Core service implementation for world agent. - -#[cfg(target_os = "linux")] -use agent_api_types::ExecuteStreamFrame; -use agent_api_types::{Budget, ExecuteRequest, ExecuteResponse}; -#[cfg(target_os = "linux")] -use anyhow::Context; -use anyhow::{anyhow, Result}; -use axum::response::Response; -#[cfg(target_os = "linux")] -use axum::{ - body::{boxed, Bytes, StreamBody}, - http::StatusCode, -}; -use base64::engine::general_purpose::STANDARD as BASE64; -use base64::Engine; -#[cfg(target_os = "linux")] -use futures_util::StreamExt; -use std::collections::HashMap; -#[cfg(target_os = "linux")] -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -sed -n '620,760p' crates/world-agent/src/service.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 39ms: - - pub(crate) fn set_last_policy_resolution_mode( - &self, - mode: agent_api_types::PolicyResolutionModeV1, - ) { - let encoded = match mode { - agent_api_types::PolicyResolutionModeV1::SnapshotV1 => 1, - agent_api_types::PolicyResolutionModeV1::LegacyLocal => 2, - }; - self.last_policy_resolution_mode - .store(encoded, Ordering::Relaxed); - } -} - -pub(crate) fn resolve_fs_mode( - requested: Option, - env: Option<&HashMap>, -) -> WorldFsMode { - if let Some(mode) = requested { - return mode; -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Updating progress on plan** - -I’m considering whether the slice is too large, and it seems small enough. So, I’m thinking about updating step 4, which is still in progress until the tests pass. Since we've already changed the tests, adjustments might still be needed. I guess we can treat it as progress until we run the tests. However, we should evaluate the code against the specs again. Now, I’ll proceed to run the gates and update the plan accordingly. -Plan update - ✓ Verify worktree, branch, taskmeta - ✓ Read plan, tasks, session, spec - ✓ Merge code and test branches - ✓ Fix drift to spec - → Run fmt, clippy, tests, integ-checks - • Run local smoke preflight - • Commit and run triad finish - • Dispatch CI parity and smoke -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..433fc6febdbc5bdfd4beba717d6ef8fe2b5e108e ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,49 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -+use std::path::PathBuf; - -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -- -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!(backing.upperdir, PathBuf::from("/var/lib/substrate/high/upper")); -+ assert_eq!(backing.workdir, PathBuf::from("/var/lib/substrate/high/work")); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Running integrity checks** - -I need to conduct some integrity checks, which might involve additional confirmations, like using fmt or clippy again. However, the specifications clearly state that these checks should be executed before dispatching. So, I’ll prioritize the initial run to ensure everything’s in order. It’s important to stick to the guidance, even if it gets a little complicated! Let’s make sure we’re following the right steps to set up properly. -exec -/bin/bash -lc 'set -euo pipefail -cargo fmt --all' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 646ms: - -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -cargo clippy --workspace --all-targets -- -D warnings' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 12.31s: - Compiling proc-macro2 v1.0.103 - Compiling quote v1.0.42 - Compiling unicode-ident v1.0.22 - Compiling libc v0.2.178 - Checking cfg-if v1.0.4 - Compiling serde_core v1.0.228 - Checking memchr v2.7.6 - Checking itoa v1.0.16 - Checking log v0.4.29 - Compiling serde v1.0.228 - Compiling autocfg v1.5.0 - Checking smallvec v1.15.1 - Checking pin-project-lite v0.2.16 - Checking once_cell v1.21.3 - Checking bytes v1.11.0 - Compiling parking_lot_core v0.9.12 - Checking scopeguard v1.2.0 - Checking ryu v1.0.21 - Checking regex-syntax v0.8.8 - Compiling serde_json v1.0.146 -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -cargo test -p world -- --nocapture' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 5.34s: - Compiling libc v0.2.178 - Compiling cfg-if v1.0.4 - Compiling serde_core v1.0.228 - Compiling bitflags v2.10.0 - Compiling serde v1.0.228 - Compiling memchr v2.7.6 - Compiling getrandom v0.3.4 - Compiling itoa v1.0.16 - Compiling serde_json v1.0.146 - Compiling ryu v1.0.21 - Compiling hashbrown v0.16.1 - Compiling regex-syntax v0.8.8 - Compiling option-ext v0.2.0 - Compiling typenum v1.19.0 - Compiling num-traits v0.2.19 - Compiling equivalent v1.0.2 - Compiling syn v2.0.111 - Compiling nix v0.30.1 - Compiling smallvec v1.15.1 - Compiling iana-time-zone v0.1.64 -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Running tests and checking results** - -Okay, the world tests passed, which is a relief! I noticed a panic in the unnamed thread labeled "poison cache lock," but it seems to be okay since the test result is still marked as successful. I assume that’s expected behavior. Now, I need to run the command `cargo test -p world-agent -- --nocapture`, but I might need extra privileges for that. It's possible some tests could be skipped, so I'll keep that in mind. -exec -/bin/bash -lc 'set -euo pipefail -cargo test -p world-agent -- --nocapture' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 8.88s: - Compiling log v0.4.29 - Compiling smallvec v1.15.1 - Compiling serde_core v1.0.228 - Compiling stable_deref_trait v1.2.1 - Compiling futures-core v0.3.31 - Compiling pin-utils v0.1.0 - Compiling memchr v2.7.6 - Compiling tracing-core v0.1.36 - Compiling litemap v0.8.1 - Compiling writeable v0.6.2 - Compiling futures-sink v0.3.31 - Compiling thiserror v1.0.69 - Compiling zerofrom v0.1.6 - Compiling slab v0.4.11 - Compiling futures-task v0.3.31 - Compiling httparse v1.10.1 - Compiling serde_json v1.0.146 - Compiling percent-encoding v2.3.2 - Compiling zerocopy v0.8.31 - Compiling icu_normalizer_data v2.1.1 -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Running integration checks** - -It seems like the world-agent tests have passed, even though many were skipped. Now, I need to run `make integ-checks` to carry out additional checks. It's essential to ensure everything functions correctly, so I'm just going to go ahead and execute that now. I hope this goes smoothly and confirms that everything is working as intended! -exec -/bin/bash -lc 'set -euo pipefail -make integ-checks' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 1m 16s: -make[1]: Entering directory '/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core' -##integ-checks -- must run from repo root -##integ-checks -- integration gate without cargo clean -cargo fmt && cargo clippy --workspace --all-targets -- -D warnings && cargo check --workspace --all-targets && cargo test --workspace --all-targets - Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.16s - Checking substrate-common v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/common) - Compiling substrate-shell v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shell) - Compiling substrate v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core) - Compiling substrate-shim v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shim) - Checking version-bump v0.1.0 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/tools/version-bump) - Checking substrate-forwarder v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/forwarder) - Checking world-api v0.1.1 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/world-api) - Checking agent-api-types v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/agent-api-types) - Checking substrate-broker v0.1.0 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/broker) - Checking substrate-trace v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/trace) - Checking substrate-telemetry v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/telemetry-lib) - Checking world v0.1.1 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/world) - Checking substrate-graph v0.1.0 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/substrate-graph) - Checking agent-api-client v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/agent-api-client) - Checking agent-api-core v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/agent-api-core) -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -Plan update - ✓ Verify worktree, branch, taskmeta - ✓ Read plan, tasks, session, spec - ✓ Merge code and test branches - ✓ Fix drift to spec - ✓ Run fmt, clippy, tests, integ-checks - → Run local smoke preflight - • Commit and run triad finish - • Dispatch CI parity and smoke -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 2 in 5.66s: - Compiling ring v0.17.14 - Compiling rustls v0.22.4 - Compiling rustls-webpki v0.102.8 - Compiling tokio-rustls v0.25.0 - Compiling tungstenite v0.21.0 - Compiling tokio-tungstenite v0.21.0 - Compiling substrate-shell v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shell) - Compiling substrate v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core) - Finished `dev` profile [unoptimized + debuginfo] target(s) in 5.42s - Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.09s -error: unrecognized subcommand 'init' - -Usage: substrate policy workspace [OPTIONS] - -For more information, try '--help'. -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Investigating smoke script** - -I need to check the smoke script to see what's happening. It's located in the planning documents, so I can access it there. I think I should focus on the section that’s failing and then I can work with `sed` on the linux-smoke.sh file to see if I can make necessary adjustments. Let’s get to it and see what can be fixed! -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,220p' docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 39ms: -#!/usr/bin/env bash -set -euo pipefail - -fail() { - echo "FAIL: $*" >&2 - exit 1 -} - -need_cmd() { - command -v "$1" >/dev/null 2>&1 || fail "missing dependency: $1" -} - -if [[ "$(uname -s)" != "Linux" ]]; then - echo "SKIP: full-isolation-landlock-overlayfs-compat smoke (not Linux)" - exit 0 -fi - -need_cmd cargo -need_cmd git -need_cmd jq -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -./target/debug/substrate policy workspace --help' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 50ms: -Workspace-scoped policy patch commands (/.substrate/policy.yaml) - -Usage: substrate policy workspace [OPTIONS] - -Commands: - show Print the workspace policy patch (/.substrate/policy.yaml) - set Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) - reset Remove keys from the workspace policy patch (restore inheritance from global+defaults) - help Print this message or the help of the given subcommand(s) - -Options: - --world Force world isolation for this run (overrides disabled install/config/env) - --no-world Disable world isolation (host pass-through) - -h, --help Print help -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - - -thinking -**Examining script issues** - -I’m looking into the smoke script; it seems to expect an init command that creates a `.substrate/policy.yaml` file at the workspace root. Right now, the `set` command likely needs that file to exist and might fail if it doesn't. I could adjust the `set` command to create the file automatically if it’s missing, avoiding the need for `init`. However, since the script calls `init` first, I might need to implement a new alias to ensure the file exists and support a `--force` flag. I'll also search for related policy commands in the code. -thinking -**Implementing command safely** - -To move forward, I need to ensure that adding the new command doesn't disrupt any existing functionality. It should only modify the CLI to support the workspace policy patch. I see that the workspace policy patch is located at `/.substrate/policy.yaml`. Commands like "set," "show," and others are considered patch operations. There's also a global `policy global init` that likely creates `/.substrate/policy.yaml`. I should use ripgrep to locate the CLI code related to `policy workspace` and similar commands. -exec -/bin/bash -lc 'set -euo pipefail -rg -n "policy workspace" -S src crates | head -n 50 -rg -n "Workspace-scoped policy patch" -S src crates | head -n 50 -rg -n "enum.*Workspace" -S crates/shell/src src | head -n 50' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 88ms: -crates/broker/src/approval/tests.rs:121: "echo pcm2 save-to-policy workspace", -crates/shell/src/execution/cli.rs:322: /// Workspace-scoped policy patch commands (/.substrate/policy.yaml) -crates/shell/src/execution/cli.rs:217:pub enum ConfigWorkspaceAction { -crates/shell/src/execution/cli.rs:333:pub enum PolicyWorkspaceAction { -crates/shell/src/execution/cli.rs:394:pub enum WorkspaceAction { -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -sed -n '260,460p' crates/shell/src/execution/cli.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 41ms: - #[command(subcommand)] - pub action: ConfigGlobalAction, -} - -#[derive(Subcommand, Debug)] -pub enum ConfigGlobalAction { - /// Initialize $SUBSTRATE_HOME/config.yaml (creates if missing; overwrites with --force) - Init(ConfigInitArgs), - /// Print the global config patch ($SUBSTRATE_HOME/config.yaml) - Show(ConfigShowArgs), - /// Update $SUBSTRATE_HOME/config.yaml via dotted updates (key=value, key+=value, key-=value) - Set(ConfigSetArgs), - /// Remove keys from the global config patch (restore inheritance from defaults) - Reset(ConfigResetArgs), -} - -#[derive(Args, Debug)] -pub struct ConfigInitArgs { - /// Overwrite the config even if it already exists - #[arg(long)] -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -rg -n "PolicyWorkspaceAction::" crates/shell/src | head -n 80 -rg -n "match .*PolicyWorkspaceAction" -S crates/shell/src | head -n 80' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 1 in 67ms: -crates/shell/src/execution/policy_cmd.rs:83: PolicyWorkspaceAction::Show(args) => run_workspace_show(args), -crates/shell/src/execution/policy_cmd.rs:84: PolicyWorkspaceAction::Set(args) => run_workspace_set(args), -crates/shell/src/execution/policy_cmd.rs:85: PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -sed -n '1,220p' crates/shell/src/execution/policy_cmd.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 40ms: -use crate::execution::cli::{ - Cli, ConfigResetArgs, PolicyAction, PolicyCmd, PolicyCurrentAction, PolicyGlobalAction, - PolicyGlobalCmd, PolicyInitArgs, PolicySetArgs, PolicyShowArgs, PolicyWorkspaceAction, - PolicyWorkspaceCmd, -}; -use crate::execution::config_model; -use crate::execution::policy_model::PolicyPatch; -use crate::execution::{policy_model, workspace}; -use anyhow::{anyhow, Context, Result}; -use std::fs; -use std::io::Write; -use std::path::{Path, PathBuf}; -use substrate_broker::{Policy, PolicyExplainV1}; -use tempfile::NamedTempFile; - -const DEFAULT_GLOBAL_POLICY_PATCH_HEADER: &str = r#"# Substrate policy patch (sparse overrides; scope=global). -# - This file is a YAML mapping of global-scoped policy overrides. -# - Omitted keys inherit from defaults (and from workspace overrides when applicable). -# - View the effective merged policy with: `substrate policy current show --explain` -"#; -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -sed -n '220,340p' crates/shell/src/execution/policy_cmd.rs" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 46ms: - if existed { - println!( - "substrate: overwrote workspace policy patch at {} (--force)", - path.display() - ); - } else { - println!( - "substrate: wrote workspace policy patch to {}", - path.display() - ); - } - - Ok(()) -} - -fn run_workspace_show(args: &PolicyShowArgs) -> Result<()> { - if args.explain { - return Err(config_model::user_error( - "--explain is only supported for `substrate policy current show`", - )); -file update: -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shell/src/execution/cli.rs -@@ -333,2 +333,4 @@ - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) -apply_patch(auto_approved=true) exited 0 in 16ms: -Success. Updated the following files: -M crates/shell/src/execution/cli.rs -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -file update -M /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shell/src/execution/policy_cmd.rs -@@ -82,2 +82,3 @@ - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), -apply_patch(auto_approved=true) exited 0 in 20ms: -Success. Updated the following files: -M crates/shell/src/execution/policy_cmd.rs -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - - -thinking -**Compiling and checking code** - -Alright, I need to format and compile my code now. I'll start with `cargo fmt` since the patch adds a doc comment and match variant, which likely requires it. Afterward, I'll rebuild and rerun the smoke script. - -I might skip a full clippy run since necessary gates are already passed, but we did change code after that. So, I’ll at least focus on `fmt` and `clippy` to ensure no warnings. I’ll also check the integration gate at the end to be safe. -thinking -**Verifying integration gates** - -I need to check the integration gates since they're not green after the recent changes. The documentation says they must be green before any CI smoke dispatch. - -I think I should rerun the necessary commands after the modifications and probably rely on the same commands again. I’ll plan to run `make integ-checks` at the end, which should clear up quickly due to incremental changes. For now, I’ll start by running `cargo fmt`. -exec -/bin/bash -lc 'set -euo pipefail -cargo fmt --all' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 630ms: - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -cargo build --bin substrate -export PATH="$PWD/target/debug:$PATH" -bash "docs/project_management/_archived/next/full-isolation-landlock-overlayfs-compat/smoke/linux-smoke.sh"' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 1 in 4.01s: - Compiling substrate-shell v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core/crates/shell) - Compiling substrate v0.2.5 (/home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core) - Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.07s - Finished `dev` profile [unoptimized + debuginfo] target(s) in 0.09s -Setting up command tracing (one-time setup)... -Command tracing setup complete. -sh: line 1: writable/sub/ok.txtncat: No such file or directory -FAIL: allowlisted write failed (expected exit 0) -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - - -thinking -**Exploring command strings** - -I’ve realized that a single-quoted string can include newline characters in shell. This means that a substrate could convert `\n` to actual newlines in the command string, allowing for newlines in the `--command` argument. When passed to the substrate command, the shell should interpret these newlines correctly. - -However, there’s an issue in the smoke script regarding embedding newlines in double quotes. Instead, it’s been using `\n` placeholders, relying on substrate to decode them at runtime. The failure suggests it didn’t decode properly and was passed to sh, which interpreted `\n` as escapes. -thinking -**Restoring newline decoding** - -I need to restore the decoding of `\n` sequences in the `substrate --command` processing to support smoke scripts. Alternatively, I could change the smoke script to use `$'...'` quoting, but I can't modify the planning documents. So, the decoding should be implemented in the substrate CLI. - -When parsing the `--command` argument, it makes sense to convert `\n` into actual newlines. I suspect that substrate already supports `\n` decoding for `--command`, but I need to verify that by inspecting the CLI options in the code, especially around `src/substrate.rs` or `crates/shell`. -exec -/bin/bash -lc 'set -euo pipefail -rg -n "--command" crates/shell/src/execution/cli.rs crates/shell/src/execution -S | head -n 80 -rg -n "command" crates/shell/src/execution/cli.rs | head -n 120' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 2 in 46ms: -rg: unrecognized flag --command -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Fixing command interpretation** - -I realized that I made a mistake with the `rg` command interpretation. Instead of just `--command`, I need to use `rg -n -- '--command' file` or quote it correctly to avoid confusion. It’s a small error, but getting the syntax right is crucial for it to work properly. I’ll make sure to remember this for next time! Let’s move forward with the corrected command usage. -exec -/bin/bash -lc "set -euo pipefail -rg -n -- \"--command\" crates/shell/src/execution/cli.rs crates/shell/src/execution | head -n 80 -rg -n -- \"\\bci\\b\" crates/shell/src/execution/cli.rs | head -n 80" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 1 in 62ms: - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc 'set -euo pipefail -rg -n -- "--command" -S src crates | head -n 80 -rg -n -- "struct .*Command" -S src/crates | head -n 80' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 2 in 48ms: -rg: -S: No such file or directory (os error 2) -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Correcting syntax error** - -I'm noticing that I made a mistake with the syntax. The `-S` option for ripgrep should actually come before the patterns, not after. That could affect how the command runs. I think I need to reformat it and run the correct command as `rg -n -S -- '--command' src crates` to see if it executes properly this time. Alright, let’s give that a try! -exec -/bin/bash -lc 'set -euo pipefail -rg -n -S -- "--command" src crates | head -n 80 -rg -n -S -- "--ci" src crates | head -n 80' in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 1 in 58ms: - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -ls -la src -sed -n '1,220p' src/main.rs -sed -n '1,260p' src/lib.rs 2>/dev/null || true" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 47ms: -total 16 -drwxr-xr-x 2 spenser spenser 4096 Jan 20 07:13 . -drwxr-xr-x 12 spenser spenser 4096 Jan 20 07:18 .. --rw-r--r-- 1 spenser spenser 260 Jan 20 07:13 main.rs --rw-r--r-- 1 spenser spenser 645 Jan 20 07:13 shim_main.rs -use anyhow::Result; -use substrate_shell::run_shell; - -fn main() -> Result<()> { - // Initialize logger early for debugging (non-fatal to avoid panics) - let _ = env_logger::try_init(); - - let exit_code = run_shell()?; - std::process::exit(exit_code); -} -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - -exec -/bin/bash -lc "set -euo pipefail -rg -n -S -- \"command\\s*:\\s*String\" crates/shell/src | head -n 80 -rg -n -S -- \"ci\" crates/shell/src/execution/cli.rs crates/shell/src | head -n 80 -rg -n -S -- \"--ci\" crates/shell/src | head -n 80 -rg -n -S -- \"--world\" crates/shell/src | head -n 80" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core exited 1 in 21ms: - -file update: -diff --git a/crates/shell/src/execution/cli.rs b/crates/shell/src/execution/cli.rs -index 92aeea24cb9890831e2e93dac57ff529b4de9b1f..bdef2a29c2c98e2b1bd1692cb018dfa8ecc99742 ---- a/crates/shell/src/execution/cli.rs -+++ b/crates/shell/src/execution/cli.rs -@@ -331,6 +331,8 @@ - - #[derive(Subcommand, Debug)] - pub enum PolicyWorkspaceAction { -+ /// Initialize /.substrate/policy.yaml (creates if missing; overwrites with --force) -+ Init(PolicyInitArgs), - /// Print the workspace policy patch (/.substrate/policy.yaml) - Show(PolicyShowArgs), - /// Update the workspace policy patch via dotted updates (key=value, key+=value, key-=value) -diff --git a/crates/shell/src/execution/policy_cmd.rs b/crates/shell/src/execution/policy_cmd.rs -index 3ae984f75ccdeaab96ec3290b37c34c225f06e8b..4ec10bdfebbb35cc159096d03227a22440dae40c ---- a/crates/shell/src/execution/policy_cmd.rs -+++ b/crates/shell/src/execution/policy_cmd.rs -@@ -80,6 +80,7 @@ - - fn run_workspace(cmd: &PolicyWorkspaceCmd) -> Result<()> { - match &cmd.action { -+ PolicyWorkspaceAction::Init(args) => run_workspace_init(args), - PolicyWorkspaceAction::Show(args) => run_workspace_show(args), - PolicyWorkspaceAction::Set(args) => run_workspace_set(args), - PolicyWorkspaceAction::Reset(args) => run_workspace_reset(args), -diff --git a/crates/world/tests/mountinfo_parsing.rs b/crates/world/tests/mountinfo_parsing.rs -index 4e34e8285ecc714e90e983f262ba66a47363df6f..44b2c379e57b36f25b7c81a5524de7b43af82a6b ---- a/crates/world/tests/mountinfo_parsing.rs -+++ b/crates/world/tests/mountinfo_parsing.rs -@@ -1,146 +1,55 @@ - #![cfg(target_os = "linux")] - --use anyhow::{anyhow, Context, Result}; -- --fn decode_mountinfo_escapes(input: &str) -> String { -- input -- .replace("\\040", " ") -- .replace("\\011", "\t") -- .replace("\\012", "\n") -- .replace("\\134", "\\") --} -- --fn select_mountinfo_entry(mountinfo_text: &str, mountpoint: &str) -> Result<(u32, String, String)> { -- let mut best: Option<(u32, String, String)> = None; -- -- for (line_no, line) in mountinfo_text.lines().enumerate() { -- let line = line.trim(); -- if line.is_empty() { -- continue; -- } -- -- let (pre, post) = line.split_once(" - ").with_context(|| { -- format!( -- "invalid mountinfo line (missing ' - ') at line {}", -- line_no + 1 -- ) -- })?; -- -- let pre_fields: Vec<&str> = pre.split_whitespace().collect(); -- if pre_fields.len() < 6 { -- return Err(anyhow!( -- "invalid mountinfo line (too few fields) at line {}", -- line_no + 1 -- )); -- } -- -- let mount_id: u32 = pre_fields[0] -- .parse() -- .with_context(|| format!("invalid mount_id at line {}", line_no + 1))?; -- let mp = pre_fields[4]; -- if mp != mountpoint { -- continue; -- } -- -- let post_fields: Vec<&str> = post.split_whitespace().collect(); -- if post_fields.len() < 3 { -- return Err(anyhow!( -- "invalid mountinfo line (missing fs_type/super_options) at line {}", -- line_no + 1 -- )); -- } -- -- let fs_type = post_fields[0].to_string(); -- let super_options = post_fields[2..].join(" "); -- -- if best -- .as_ref() -- .map(|(best_id, _, _)| mount_id > *best_id) -- .unwrap_or(true) -- { -- best = Some((mount_id, fs_type, super_options)); -- } -- } -- -- best.ok_or_else(|| anyhow!("no mount entry matches mountpoint {mountpoint:?}")) --} -- --fn derive_overlay_backing_dirs_from_mountinfo( -- mountinfo_text: &str, -- mountpoint: &str, --) -> Result<(String, String)> { -- let (_mount_id, fs_type, super_options) = select_mountinfo_entry(mountinfo_text, mountpoint)?; -- -- if fs_type != "overlay" { -- return Err(anyhow!( -- "mountpoint {mountpoint:?} is not overlay (fs_type={fs_type:?})" -- )); -- } -- -- let mut upperdir: Option = None; -- let mut workdir: Option = None; -- for opt in super_options.split(',') { -- if let Some(val) = opt.strip_prefix("upperdir=") { -- upperdir = Some(decode_mountinfo_escapes(val)); -- } -- if let Some(val) = opt.strip_prefix("workdir=") { -- workdir = Some(decode_mountinfo_escapes(val)); -- } -- } -- -- let upperdir = -- upperdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing upperdir"))?; -- let workdir = -- workdir.ok_or_else(|| anyhow!("overlay mountpoint {mountpoint:?} missing workdir"))?; -+use std::path::PathBuf; - -- if !upperdir.starts_with('/') { -- return Err(anyhow!("upperdir is not absolute: {upperdir:?}")); -- } -- if !workdir.starts_with('/') { -- return Err(anyhow!("workdir is not absolute: {workdir:?}")); -- } -+use world::mountinfo::{overlay_backing_dirs_from_mountinfo, OverlayBackingDirsError}; - -- Ok((upperdir, workdir)) --} -- - #[test] - fn mountinfo_overlay_entry_returns_upperdir_and_workdir_with_decoding() { - let mountinfo = include_str!("fixtures/mountinfo/overlay_ok_with_escapes.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/ovl space/upper"); -- assert_eq!(workdir, "/var/lib/substrate/ovl\ttab/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/ovl space/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/ovl\ttab/work") -+ ); - } - - #[test] - fn mountinfo_selects_greatest_mount_id_when_multiple_entries_match() { - let mountinfo = include_str!("fixtures/mountinfo/duplicate_mountpoints.mountinfo"); -- let (upperdir, workdir) = -- derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -- assert_eq!(upperdir, "/var/lib/substrate/high/upper"); -- assert_eq!(workdir, "/var/lib/substrate/high/work"); -+ let backing = overlay_backing_dirs_from_mountinfo(mountinfo, "/project").unwrap(); -+ assert_eq!( -+ backing.upperdir, -+ PathBuf::from("/var/lib/substrate/high/upper") -+ ); -+ assert_eq!( -+ backing.workdir, -+ PathBuf::from("/var/lib/substrate/high/work") -+ ); - } - - #[test] - fn mountinfo_non_overlay_entry_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/non_overlay_for_project.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected non-overlay error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("not overlay"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::WrongFsType { fs_type, .. } => assert_eq!(fs_type, "ext4"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - #[test] - fn mountinfo_missing_upperdir_or_workdir_returns_error() { - let mountinfo = include_str!("fixtures/mountinfo/missing_workdir.mountinfo"); -- let err = derive_overlay_backing_dirs_from_mountinfo(mountinfo, "/project") -+ let err = overlay_backing_dirs_from_mountinfo(mountinfo, "/project") - .expect_err("expected missing workdir error"); -- let msg = format!("{err:#}"); -- assert!( -- msg.contains("missing workdir"), -- "unexpected error message: {msg}" -- ); -+ match err { -+ OverlayBackingDirsError::MissingSuperOption { key, .. } => assert_eq!(key, "workdir"), -+ other => panic!("unexpected error: {other:?}"), -+ } - } - - -thinking -**Investigating ripgrep commands** - -I’m wondering why the ripgrep commands didn't return results. It could be that the file uses Clap but doesn't have the expected spelling with `#[arg(long)]`. I think I should search for `ci` and `command` more carefully. Maybe I should be looking for `ci: bool` and `command: Option`. Searching for phrases like `pub command` could help as well. Let’s see what I can find! -exec -/bin/bash -lc "set -euo pipefail -rg -n -S -- \"\\bci\\b\" crates/shell/src | head -n 120 -rg -n -S -- \"\\bcommand\\b\" crates/shell/src | head -n 120" in /home/spenser/__Active_code/substrate/wt/full-isolation-landlock-overlayfs-compat-c0-integ-core succeeded in 67ms: -crates/shell/src/execution/lock.rs:168: // Very lenient timing for CI environments -crates/shell/src/execution/lock.rs:170: assert!(elapsed < Duration::from_millis(500)); // Much more lenient for slow CI -crates/shell/src/execution/lock.rs:192: // Very lenient timing for CI environments -crates/shell/src/execution/lock.rs:194: assert!(elapsed < Duration::from_millis(500)); // Much more lenient for slow CI -crates/shell/src/execution/lock.rs:295: // Very lenient timing assertions for CI -crates/shell/src/builtins/world_verify.rs:687: cmd.arg("--world").arg("--ci").arg("-c").arg(script); -crates/shell/src/builtins/world_verify.rs:694: "run `{}` --ci -c