Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion docs/adr/ADR-2002-aoe-token-auth-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [config/nip98-proxy/proxy.mjs, scripts/aoe-curl.sh, flake.nix]
owner: jjohare
review_trigger: next image rebuild (activation), or any new consumer of :9095, or per-process isolation becoming available
Expand Down Expand Up @@ -230,3 +230,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake.
## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10)

Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- <verified_paths>`. Nix was not evaluated in this container.

### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2009-nip98-proxy-identity-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [config/nip98-proxy/proxy.mjs, flake.nix, docs/INGRESS-identity.md]
owner: jjohare
review_trigger: A second identity ingress is proposed, or aoe serve stops binding loopback
Expand Down Expand Up @@ -238,3 +238,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake.
## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10)

Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- <verified_paths>`. Nix was not evaluated in this container.

### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2012-relay-allowlist-only-ingress.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [agentbox.toml, flake.nix]
owner: jjohare
review_trigger: ingress_policy changes from allowlist, or the ADR-040 D3 governance-publisher key-split lands
Expand Down Expand Up @@ -306,3 +306,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The relay allowlist and its ingress are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2012 — Relay ingress is allowlist-only, no fallback, no auto-add) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2013-loopback-publish-except-9096.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [scripts/ci/check-ports-loopback.sh, .github/workflows/invariants.yml, flake.nix, docker-compose.yml]
owner: jjohare
review_trigger: Any new entry on the SANCTIONED list, or a new compose overlay file
Expand Down Expand Up @@ -311,3 +311,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake.
## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10)

Tripped by the W10 gap fixes on `custody/integration`. `.github/workflows/invariants.yml` (`e9f5cd6da`, `dc91e092a`) adds the RC-X1-01..05 and -07 steps and the compose-role-env step, widens its path filter, and corrects one step label; no existing step changes; `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- <verified_paths>`. Nix was not evaluated in this container.

### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2013 — Loopback-only compose publishes except the sanctioned-exposure list) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2029-rune-markdown-tui-notes-window.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [flake.nix, lib/rune.nix, config/tmux-autostart.sh, config/tmux.conf, agentbox.toml, setup/agentbox.default.toml, schema/agentbox.toml.schema.json]
owner: jjohare
review_trigger: a Rune release that changes its CLI (`-w`), its keyboard-protocol requirement, or its licence; or the AoE plane absorbing note editing
Expand Down Expand Up @@ -232,3 +232,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The Rune window and its vault root are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2029 — Rune is the first-class markdown TUI) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2033-deepsec-security-gate.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: staged
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [flake.nix, agentbox.toml, schema/agentbox.toml.schema.json, scripts/agentbox-config-validate.js, management-api/lib/system-manifest.js, skills/build-with-quality/scripts, skills/build-with-quality/references/deepsec-security-gate.md, .github/workflows/deepsec.yml]
owner: jjohare
review_trigger: a deepsec major version, a change to its CLI exit-code contract or model-route schema, any new model route, or the first paid full-repo run
Expand Down Expand Up @@ -273,3 +273,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The deepsec gate and its credential policy are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2033 — deepsec is the executed Security gate of build-with-quality, baked as a manifest-gated CLI under a names-only credential policy) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2092-govern-the-agent-and-command-registries.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: staged
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [agents/registered-agents.txt, scripts/reconcile-agents.sh, scripts/reconcile-commands.sh, scripts/project-skill-roots.mjs, config/registered-commands.txt, config/entrypoint-unified.sh, flake.nix, tests/config/agent-reconcile.test.sh]
owner: jjohare
review_trigger: a new subagent worth always-loading, or evidence the router surfaces baked-but-unregistered skills too slowly
Expand Down Expand Up @@ -227,3 +227,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `config/entrypoint-unifie
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `config/entrypoint-unified.sh` changes only in three custody blocks (ADR-2122, design 3.2). (1) A new at-rest step before Phase 3: `ab_custody_migrate` when `[security].role_isolation` is on, otherwise `ab_custody_revert`, which changes nothing on a volume that was never migrated (`tests/config/role-custody-migrate.test.sh` shows the stat set, ctime included, byte-identical). (2) Under the flag only, the volume-root chown loop skips `/var/lib/agentbox/secrets`. (3) After the identity bootstrap, the identity file goes to ab-identity 0400 under the flag; with the flag off, the devuser 0600 statements are unchanged. The agent and command reconcilers are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2092 — Agents and slash-commands get the same manifest governance skills already have) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.
Original file line number Diff line number Diff line change
Expand Up @@ -174,6 +174,7 @@ docker logs <container> 2>&1 | grep '\[5d/8\] vault'
- **Suitability:** fits. The Nix-baked binary is the right mechanism. The *source* of the pin changes under the estate's break-out edict.
- **Priority:** P1 for the pin (done). P2 for the break-out, which waits for the owner's go.
- **Pin (owner decision 2026-10-02, R10):** `vaultSrc` moved from `0c195f7605f3` to VisionClaw main `64512141bd01` in `e70fcb5df`. At `0c195f760`, `vault build --with-rvdb` predates `f95d0acc1`, and the Loom reload check rejects its vector records. The pin is proven by a real `nix build` of `lib/vault.nix` against the locked inputs, with `doCheck` on: `/nix/store/p00pdlbychd3w5zk63grbdmqr4cdmh4c-vault-0.1.0`, all tests green. The "absolute path" wart in §Consequences is gone: the input is `github:DreamLab-AI/VisionClaw/<rev>`. Note also that `.#packages.<system>.vault` in the recipe above is not a flake output. `vaultPkg` is a `let` binding, so build `lib/vault.nix` directly.
- **Pin (2026-10-03, custody repin):** `vaultSrc` moved from `64512141bd01` to VisionClaw main `94dc0ff60923` (owner rule: estate pins move forward). The vault side of the change: `nostr-bbs-core` pinned to `=1.0.0-beta.13` (crates.io, not yanked), vault-core publish metadata, and a cast-safety change in `domain_class_id` with the same signature and results. No new `git+` source in `Cargo.lock`; the whelk rev, and with it the one `outputHashes` entry, is unchanged. The narHash was computed with the NAR-serialisation method that reproduces the previous pin's hash exactly. Unlike the entry above, this pin is **not yet proven by a `nix build`**; the owner's agentbox rebuild proves it.
- **Break-out judgement (standing edict 2026-10-02):** Is it generalisable, meaning could another operator use it with their own Obsidian corpus and ontology?
- **`vault-core`: yes.** Its dependencies are all on crates.io, with no VisionClaw internals. The page/frontmatter parser, vocabulary model, OKF v0.2 types, link graph and promotion machine are format-level. Coupling points:
1. `vocabulary.rs` defaults the namespaces to `urn:ngm:class:` / `urn:ngm:individual:` and builds in the `vc`/`ngm`/`ngmi` → `narrativegoldmine.com` prefixes. These belong in the estate's `vocabulary.yaml`.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [config/instructions, services/agentbox-manifest/src/instructions.rs, services/agentbox-manifest/src/cred_sync.rs, config/entrypoint-unified.sh, agentbox.sh, flake.nix, docker-compose.yml, docker-compose.override.yml, docker-compose.hp.yml, tests/config/claude-home-migration.test.sh, tests/config/compose-persistence.test.cjs]
owner: jjohare
review_trigger: the connected node runs migrate-claude-home; or Claude Code starts reading AGENTS.md natively (drop the @AGENTS.md wrappers and the embed); or a Claude Code release changes where credentials live
Expand Down Expand Up @@ -128,3 +128,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `config/entrypoint-unifie
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `config/entrypoint-unified.sh` changes only in three custody blocks (ADR-2122, design 3.2). (1) A new at-rest step before Phase 3: `ab_custody_migrate` when `[security].role_isolation` is on, otherwise `ab_custody_revert`, which changes nothing on a volume that was never migrated (`tests/config/role-custody-migrate.test.sh` shows the stat set, ctime included, byte-identical). (2) Under the flag only, the volume-root chown loop skips `/var/lib/agentbox/secrets`. (3) After the identity bootstrap, the identity file goes to ab-identity 0400 under the flag; with the flag off, the devuser 0600 statements are unchanged. The instruction mounts, `instructions-project` and `cred-sync` are untouched. The decision holds. Re-verified by `git log dc91e092a..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2118 — Own the instruction tiers and the Claude home in the repo) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: dc91e092ab646b4a825805b8229602ac8b15bad3
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_paths: [flake.nix, lib/ontology-tools.nix, services/ontology-tools, services/agentbox-mcp/src/web_summary, skills/ontology-core, skills/ontology-enrich, dream.config.json]
owner: jjohare
review_trigger: commit and rebuild the image; or introduce a corpus writer or output format
Expand Down Expand Up @@ -94,3 +94,7 @@ Tripped by `32cedf992`, the fix for the PR's clippy and statix failures. `flake.
## Re-verification — 2026-10-03 (`dc91e092ab646b4a825805b8229602ac8b15bad3`, custody W10)

Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`) gains one let-binding, `roleIsolationBaked = securityCfg.role_isolation or false`, and its inline `/etc/sudoers` lines become a call to `config/bake-devuser-privilege.sh` with that flag; with the flag off (the shipped value) the baked `/etc/group`, `/etc/sudoers` and `/etc/sudoers.d/devuser` are byte-identical (RC-X1-07). Nothing this record governs changes meaning. The decision holds. Re-verified by `git log 32cedf992..dc91e092a -- <verified_paths>`. Nix was not evaluated in this container.

### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2119 — Remove the retired outliner ontology runtime) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.
Loading
Loading