From 33cbb29e86ba0e7def92fb100029b124e9269da7 Mon Sep 17 00:00:00 2001 From: Claude Code Date: Sat, 3 Oct 2026 10:25:04 +0000 Subject: [PATCH 1/2] build(flake): move vaultSrc to VisionClaw main 94dc0ff60 (custody repin) Owner rule: estate pins move forward. vaultSrc 64512141bd01 -> 94dc0ff60923, VisionClaw main head on 2026-10-03. What vault sees in that range: nostr-bbs-core pinned =1.0.0-beta.13 (crates.io, not yanked, registry source with checksum in Cargo.lock), vault-core publish metadata, and a cast-safety change in domain_class_id (same signature, same results). crates/vault/src is untouched. No new git+ source in Cargo.lock; whelk stays at 79a1ee2, so the one cargoLock outputHashes entry in lib/vault.nix still holds. Hash method check: NAR serialisation (python3, nix-archive-1, sorted entries, executable bit, symlinks) of the GitHub tarball with the top directory stripped. It reproduces the previous pin exactly (64512141b -> sha256-htBUpXUUcqY/w71tWdVapU+DBhi/FgNvEye+5JKQmeg=), then gives 94dc0ff60 -> sha256-1mQSa9/d2SebzDSgP0V2DmNedxSDoWi0o//cM8Qe7P4=. lastModified is the committer date (2026-10-03T08:46:26Z = 1791017186), the same source that reproduces the previous value. Not verified here: no nix in this container. The owner's agentbox rebuild proves the hash and the vault build (doCheck on). ADR-2108 gets a dated note. Co-Authored-By: jjohare --- ...ADR-2108-ontology-bridge-retired-vault-baked-by-nix.md | 1 + flake.lock | 8 ++++---- flake.nix | 2 +- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/adr/ADR-2108-ontology-bridge-retired-vault-baked-by-nix.md b/docs/adr/ADR-2108-ontology-bridge-retired-vault-baked-by-nix.md index 9090a49e4..b2ee9fc99 100644 --- a/docs/adr/ADR-2108-ontology-bridge-retired-vault-baked-by-nix.md +++ b/docs/adr/ADR-2108-ontology-bridge-retired-vault-baked-by-nix.md @@ -174,6 +174,7 @@ docker logs 2>&1 | grep '\[5d/8\] vault' - **Suitability:** fits. The Nix-baked binary is the right mechanism. The *source* of the pin changes under the estate's break-out edict. - **Priority:** P1 for the pin (done). P2 for the break-out, which waits for the owner's go. - **Pin (owner decision 2026-10-02, R10):** `vaultSrc` moved from `0c195f7605f3` to VisionClaw main `64512141bd01` in `e70fcb5df`. At `0c195f760`, `vault build --with-rvdb` predates `f95d0acc1`, and the Loom reload check rejects its vector records. The pin is proven by a real `nix build` of `lib/vault.nix` against the locked inputs, with `doCheck` on: `/nix/store/p00pdlbychd3w5zk63grbdmqr4cdmh4c-vault-0.1.0`, all tests green. The "absolute path" wart in §Consequences is gone: the input is `github:DreamLab-AI/VisionClaw/`. Note also that `.#packages..vault` in the recipe above is not a flake output. `vaultPkg` is a `let` binding, so build `lib/vault.nix` directly. +- **Pin (2026-10-03, custody repin):** `vaultSrc` moved from `64512141bd01` to VisionClaw main `94dc0ff60923` (owner rule: estate pins move forward). The vault side of the change: `nostr-bbs-core` pinned to `=1.0.0-beta.13` (crates.io, not yanked), vault-core publish metadata, and a cast-safety change in `domain_class_id` with the same signature and results. No new `git+` source in `Cargo.lock`; the whelk rev, and with it the one `outputHashes` entry, is unchanged. The narHash was computed with the NAR-serialisation method that reproduces the previous pin's hash exactly. Unlike the entry above, this pin is **not yet proven by a `nix build`**; the owner's agentbox rebuild proves it. - **Break-out judgement (standing edict 2026-10-02):** Is it generalisable, meaning could another operator use it with their own Obsidian corpus and ontology? - **`vault-core`: yes.** Its dependencies are all on crates.io, with no VisionClaw internals. The page/frontmatter parser, vocabulary model, OKF v0.2 types, link graph and promotion machine are format-level. Coupling points: 1. `vocabulary.rs` defaults the namespaces to `urn:ngm:class:` / `urn:ngm:individual:` and builds in the `vc`/`ngm`/`ngmi` → `narrativegoldmine.com` prefixes. These belong in the estate's `vocabulary.yaml`. diff --git a/flake.lock b/flake.lock index b65cc6a56..5c5ac792b 100644 --- a/flake.lock +++ b/flake.lock @@ -245,17 +245,17 @@ "vaultSrc": { "flake": false, "locked": { - "lastModified": 1790959747, - "narHash": "sha256-htBUpXUUcqY/w71tWdVapU+DBhi/FgNvEye+5JKQmeg=", + "lastModified": 1791017186, + "narHash": "sha256-1mQSa9/d2SebzDSgP0V2DmNedxSDoWi0o//cM8Qe7P4=", "owner": "DreamLab-AI", "repo": "VisionClaw", - "rev": "64512141bd0103ff70c2ca2f962f05f2fb3bb8a4", + "rev": "94dc0ff609237e06f5f0cbf4e93941f867a63260", "type": "github" }, "original": { "owner": "DreamLab-AI", "repo": "VisionClaw", - "rev": "64512141bd0103ff70c2ca2f962f05f2fb3bb8a4", + "rev": "94dc0ff609237e06f5f0cbf4e93941f867a63260", "type": "github" } } diff --git a/flake.nix b/flake.nix index 00cec4a27..3babbe2e4 100644 --- a/flake.nix +++ b/flake.nix @@ -39,7 +39,7 @@ # Pin the parent VisionClaw commit so the corpus door is reproducible and # cannot drift with a mutable branch. vaultSrc = { - url = "github:DreamLab-AI/VisionClaw/64512141bd0103ff70c2ca2f962f05f2fb3bb8a4"; + url = "github:DreamLab-AI/VisionClaw/94dc0ff609237e06f5f0cbf4e93941f867a63260"; flake = false; }; From a19d833c78d9d2ad8a915695c71c9ba0aa20f319 Mon Sep 17 00:00:00 2001 From: Claude Code Date: Sat, 3 Oct 2026 11:49:31 +0000 Subject: [PATCH 2/2] docs(adr): re-verify 11 records after the vaultSrc repin (33cbb29e8) The only governed-path change since each stamp is the one-line flake.nix vaultSrc move to VisionClaw main 94dc0ff60, whose single consumer is lib/vault.nix. One dated note per record; earlier notes kept. Co-Authored-By: jjohare --- docs/adr/ADR-2002-aoe-token-auth-boundary.md | 6 +++++- docs/adr/ADR-2009-nip98-proxy-identity-boundary.md | 6 +++++- docs/adr/ADR-2012-relay-allowlist-only-ingress.md | 6 +++++- docs/adr/ADR-2013-loopback-publish-except-9096.md | 6 +++++- docs/adr/ADR-2029-rune-markdown-tui-notes-window.md | 6 +++++- docs/adr/ADR-2033-deepsec-security-gate.md | 6 +++++- .../adr/ADR-2092-govern-the-agent-and-command-registries.md | 6 +++++- ...own-the-instruction-tiers-and-claude-home-in-the-repo.md | 6 +++++- .../ADR-2119-remove-retired-outliner-ontology-runtime.md | 6 +++++- docs/adr/ADR-2120-codex-daemon-package-volume.md | 6 +++++- ...le-service-accounts-run-secrets-and-the-identity-port.md | 6 +++++- 11 files changed, 55 insertions(+), 11 deletions(-) diff --git a/docs/adr/ADR-2002-aoe-token-auth-boundary.md b/docs/adr/ADR-2002-aoe-token-auth-boundary.md index aa1145739..73ffafcb5 100644 --- a/docs/adr/ADR-2002-aoe-token-auth-boundary.md +++ b/docs/adr/ADR-2002-aoe-token-auth-boundary.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: live supersedes: [] superseded_by: [] -verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3 +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [config/nip98-proxy/proxy.mjs, scripts/aoe-curl.sh, flake.nix] owner: jjohare review_trigger: next image rebuild (activation), or any new consumer of :9095, or per-process isolation becoming available @@ -230,3 +230,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake. ## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10) Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- `. Nix was not evaluated in this container. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2009-nip98-proxy-identity-boundary.md b/docs/adr/ADR-2009-nip98-proxy-identity-boundary.md index 4b2079697..ec113130d 100644 --- a/docs/adr/ADR-2009-nip98-proxy-identity-boundary.md +++ b/docs/adr/ADR-2009-nip98-proxy-identity-boundary.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: live supersedes: [] superseded_by: [] -verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3 +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [config/nip98-proxy/proxy.mjs, flake.nix, docs/INGRESS-identity.md] owner: jjohare review_trigger: A second identity ingress is proposed, or aoe serve stops binding loopback @@ -238,3 +238,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake. ## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10) Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- `. Nix was not evaluated in this container. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2012-relay-allowlist-only-ingress.md b/docs/adr/ADR-2012-relay-allowlist-only-ingress.md index efd1fd731..e1b7d054e 100644 --- a/docs/adr/ADR-2012-relay-allowlist-only-ingress.md +++ b/docs/adr/ADR-2012-relay-allowlist-only-ingress.md @@ -7,7 +7,7 @@ implementation_status: partial activation_status: live supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [agentbox.toml, flake.nix] owner: jjohare review_trigger: ingress_policy changes from allowlist, or the ADR-040 D3 governance-publisher key-split lands @@ -306,3 +306,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The relay allowlist and its ingress are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2012 — Relay ingress is allowlist-only, no fallback, no auto-add) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2013-loopback-publish-except-9096.md b/docs/adr/ADR-2013-loopback-publish-except-9096.md index a76d663f0..2d9048456 100644 --- a/docs/adr/ADR-2013-loopback-publish-except-9096.md +++ b/docs/adr/ADR-2013-loopback-publish-except-9096.md @@ -7,7 +7,7 @@ implementation_status: partial activation_status: live supersedes: [] superseded_by: [] -verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3 +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [scripts/ci/check-ports-loopback.sh, .github/workflows/invariants.yml, flake.nix, docker-compose.yml] owner: jjohare review_trigger: Any new entry on the SANCTIONED list, or a new compose overlay file @@ -311,3 +311,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake. ## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10) Tripped by the W10 gap fixes on `custody/integration`. `.github/workflows/invariants.yml` (`e9f5cd6da`, `dc91e092a`) adds the RC-X1-01..05 and -07 steps and the compose-role-env step, widens its path filter, and corrects one step label; no existing step changes; `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- `. Nix was not evaluated in this container. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2013 — Loopback-only compose publishes except the sanctioned-exposure list) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2029-rune-markdown-tui-notes-window.md b/docs/adr/ADR-2029-rune-markdown-tui-notes-window.md index 106098318..81ec47862 100644 --- a/docs/adr/ADR-2029-rune-markdown-tui-notes-window.md +++ b/docs/adr/ADR-2029-rune-markdown-tui-notes-window.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: live supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [flake.nix, lib/rune.nix, config/tmux-autostart.sh, config/tmux.conf, agentbox.toml, setup/agentbox.default.toml, schema/agentbox.toml.schema.json] owner: jjohare review_trigger: a Rune release that changes its CLI (`-w`), its keyboard-protocol requirement, or its licence; or the AoE plane absorbing note editing @@ -232,3 +232,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The Rune window and its vault root are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2029 — Rune is the first-class markdown TUI) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2033-deepsec-security-gate.md b/docs/adr/ADR-2033-deepsec-security-gate.md index 1c8c53b32..118b6a772 100644 --- a/docs/adr/ADR-2033-deepsec-security-gate.md +++ b/docs/adr/ADR-2033-deepsec-security-gate.md @@ -7,7 +7,7 @@ implementation_status: partial activation_status: staged supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [flake.nix, agentbox.toml, schema/agentbox.toml.schema.json, scripts/agentbox-config-validate.js, management-api/lib/system-manifest.js, skills/build-with-quality/scripts, skills/build-with-quality/references/deepsec-security-gate.md, .github/workflows/deepsec.yml] owner: jjohare review_trigger: a deepsec major version, a change to its CLI exit-code contract or model-route schema, any new model route, or the first paid full-repo run @@ -273,3 +273,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The deepsec gate and its credential policy are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2033 — deepsec is the executed Security gate of build-with-quality, baked as a manifest-gated CLI under a names-only credential policy) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2092-govern-the-agent-and-command-registries.md b/docs/adr/ADR-2092-govern-the-agent-and-command-registries.md index dc57d1012..05dfe463f 100644 --- a/docs/adr/ADR-2092-govern-the-agent-and-command-registries.md +++ b/docs/adr/ADR-2092-govern-the-agent-and-command-registries.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: staged supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [agents/registered-agents.txt, scripts/reconcile-agents.sh, scripts/reconcile-commands.sh, scripts/project-skill-roots.mjs, config/registered-commands.txt, config/entrypoint-unified.sh, flake.nix, tests/config/agent-reconcile.test.sh] owner: jjohare review_trigger: a new subagent worth always-loading, or evidence the router surfaces baked-but-unregistered skills too slowly @@ -227,3 +227,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `config/entrypoint-unifie ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `config/entrypoint-unified.sh` changes only in three custody blocks (ADR-2122, design 3.2). (1) A new at-rest step before Phase 3: `ab_custody_migrate` when `[security].role_isolation` is on, otherwise `ab_custody_revert`, which changes nothing on a volume that was never migrated (`tests/config/role-custody-migrate.test.sh` shows the stat set, ctime included, byte-identical). (2) Under the flag only, the volume-root chown loop skips `/var/lib/agentbox/secrets`. (3) After the identity bootstrap, the identity file goes to ab-identity 0400 under the flag; with the flag off, the devuser 0600 statements are unchanged. The agent and command reconcilers are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2092 — Agents and slash-commands get the same manifest governance skills already have) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2118-own-the-instruction-tiers-and-claude-home-in-the-repo.md b/docs/adr/ADR-2118-own-the-instruction-tiers-and-claude-home-in-the-repo.md index 105ddd498..26f8cbd0e 100644 --- a/docs/adr/ADR-2118-own-the-instruction-tiers-and-claude-home-in-the-repo.md +++ b/docs/adr/ADR-2118-own-the-instruction-tiers-and-claude-home-in-the-repo.md @@ -7,7 +7,7 @@ implementation_status: partial activation_status: live supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [config/instructions, services/agentbox-manifest/src/instructions.rs, services/agentbox-manifest/src/cred_sync.rs, config/entrypoint-unified.sh, agentbox.sh, flake.nix, docker-compose.yml, docker-compose.override.yml, docker-compose.hp.yml, tests/config/claude-home-migration.test.sh, tests/config/compose-persistence.test.cjs] owner: jjohare review_trigger: the connected node runs migrate-claude-home; or Claude Code starts reading AGENTS.md natively (drop the @AGENTS.md wrappers and the embed); or a Claude Code release changes where credentials live @@ -128,3 +128,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `config/entrypoint-unifie ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `config/entrypoint-unified.sh` changes only in three custody blocks (ADR-2122, design 3.2). (1) A new at-rest step before Phase 3: `ab_custody_migrate` when `[security].role_isolation` is on, otherwise `ab_custody_revert`, which changes nothing on a volume that was never migrated (`tests/config/role-custody-migrate.test.sh` shows the stat set, ctime included, byte-identical). (2) Under the flag only, the volume-root chown loop skips `/var/lib/agentbox/secrets`. (3) After the identity bootstrap, the identity file goes to ab-identity 0400 under the flag; with the flag off, the devuser 0600 statements are unchanged. The instruction mounts, `instructions-project` and `cred-sync` are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2118 — Own the instruction tiers and the Claude home in the repo) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2119-remove-retired-outliner-ontology-runtime.md b/docs/adr/ADR-2119-remove-retired-outliner-ontology-runtime.md index 05d2bb80e..65df705b7 100644 --- a/docs/adr/ADR-2119-remove-retired-outliner-ontology-runtime.md +++ b/docs/adr/ADR-2119-remove-retired-outliner-ontology-runtime.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: live supersedes: [] superseded_by: [] -verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3 +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [flake.nix, lib/ontology-tools.nix, services/ontology-tools, services/agentbox-mcp/src/web_summary, skills/ontology-core, skills/ontology-enrich, dream.config.json] owner: jjohare review_trigger: commit and rebuild the image; or introduce a corpus writer or output format @@ -94,3 +94,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake. ## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10) Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- `. Nix was not evaluated in this container. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2119 — Remove the retired outliner ontology runtime) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2120-codex-daemon-package-volume.md b/docs/adr/ADR-2120-codex-daemon-package-volume.md index 57297041a..59b4b94ee 100644 --- a/docs/adr/ADR-2120-codex-daemon-package-volume.md +++ b/docs/adr/ADR-2120-codex-daemon-package-volume.md @@ -7,7 +7,7 @@ implementation_status: complete activation_status: live supersedes: [] superseded_by: [] -verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [agentbox.sh, config/entrypoint-unified.sh, flake.nix, docker-compose.yml, scripts/refresh-compose.sh, tests/config/compose-persistence.test.cjs, tests/config/refresh-compose.test.cjs] owner: jjohare review_trigger: commit verification and rebuild; or change Codex daemon packaging @@ -107,3 +107,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `config/entrypoint-unifie ## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4) Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `config/entrypoint-unified.sh` changes only in three custody blocks (ADR-2122, design 3.2). (1) A new at-rest step before Phase 3: `ab_custody_migrate` when `[security].role_isolation` is on, otherwise `ab_custody_revert`, which changes nothing on a volume that was never migrated (`tests/config/role-custody-migrate.test.sh` shows the stat set, ctime included, byte-identical). (2) Under the flag only, the volume-root chown loop skips `/var/lib/agentbox/secrets`. (3) After the identity bootstrap, the identity file goes to ab-identity 0400 under the flag; with the flag off, the devuser 0600 statements are unchanged. The Codex package volume and its exec mount are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2120 — Give Codex daemon packages executable persistent storage) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- `. diff --git a/docs/adr/ADR-2122-role-service-accounts-run-secrets-and-the-identity-port.md b/docs/adr/ADR-2122-role-service-accounts-run-secrets-and-the-identity-port.md index fcda9fd6b..c0a511746 100644 --- a/docs/adr/ADR-2122-role-service-accounts-run-secrets-and-the-identity-port.md +++ b/docs/adr/ADR-2122-role-service-accounts-run-secrets-and-the-identity-port.md @@ -7,7 +7,7 @@ implementation_status: partial activation_status: inactive supersedes: [] superseded_by: [] -verified_commit: 5c787fedc999001c5bbe275a8111a21276a5abbc +verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7 verified_paths: [config/role-accounts.json, services/agentbox-manifest/src/role_accounts.rs, services/agentbox-manifest/src/main.rs, lib/agentbox-manifest.nix, config/lib/role-custody.sh, config/entrypoint-unified.sh, flake.nix, docker-compose.yml, agentbox.toml, setup/agentbox.default.toml, schema/agentbox.toml.schema.json, management-api/lib/system-manifest.js, tests/config/role-isolation-supervisor.test.sh, tests/config/role-secrets-delivery.test.sh, tests/config/role-isolation-boot.test.sh, tests/config/fixtures/role-isolation/supervisord.conf, config/custody/env-classes.json, scripts/ci/env-secret-inventory.js, management-api/lib/role-secret.js, services/nostr-pod-bridge/src/role_secret.rs, services/nostr-pod-bridge/src/bootstrap.rs, tests/runtime-contract/RC-X1-06.sh, config/custody/identity-port-acl.json, services/nostr-pod-bridge/src/identity_port/mod.rs, services/nostr-pod-bridge/src/identity_port/server.rs, management-api/lib/pod-signer.js, scripts/activation/role-isolation-rehearsal.sh, scripts/activation/role-isolation-rehearsal.host.sh, tests/config/role-isolation-rehearsal.test.sh, config/bake-devuser-privilege.sh, tests/runtime-contract/RC-X1-07.sh, tests/security/compose-role-env.test.mjs, docker-compose.override.yml, docker-compose.hp.yml, tests/config/role-custody-migrate.test.sh, config/sidechain/run-producer.sh, config/sidechain/run-faucet.sh, config/sidechain/mirror-sync.sh] owner: jjohare review_trigger: the role-isolation rehearsal (scripts/activation/role-isolation-rehearsal.sh) passing or failing on a rebuilt image; a new secret-bearing supervisor program; a new [sidechain.] chain; a change to the host docker gid; the identity port's consumer cutover (W3b: JunkieJarvis, the mirror hook, the gateway, dream-engine); a change to config/custody/identity-port-acl.json @@ -516,3 +516,7 @@ Tripped by `ad5d0b91a`, a shellcheck-only change to `config/lib/role-custody.sh` ### Re-verification — 2026-10-03 (integration, CI portability) `ad5d0b91a..5c787fedc` touches `scripts/activation/role-isolation-rehearsal.host.sh` only to add the test seam `HR_ASSUME_CONTAINER=1`, which forces the in-container refusal and cannot suppress it, plus two test fixtures (`5c787fedc`). Detection, the root check and every rehearsal row are unchanged; the decision holds. Re-verified by `git log ad5d0b91a..5c787fedc -- `. + +### Re-verification — 2026-10-03 (vaultSrc repin) + +`5c787fedc..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2122 — Role service accounts, /run/secrets, and the identity port) reads it. The decision holds. Re-verified by `git log 5c787fedc..33cbb29e8 -- `.