Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions agentbox.toml
Original file line number Diff line number Diff line change
Expand Up @@ -1620,6 +1620,21 @@ enabled = false # C5 — enable with [payments.consumer
# payments fail closed at the chain guard until it runs and the payer is funded.
# Spend-policy runs on POST /v1/chain/pay only; above approval_threshold_sats a
# payment parks until an allowlisted approver releases it. RESTART-class.
# ── Poker house seat (forum ADR-2020) ─────────────────────────────────────────
# nostr-bbs-poker-citizen: deals DREAM hands to forum members at
# /community/table over the forum relay, plays the house bot, settles each hand
# on sidestr:dreamlab through the local producer (needs [sidechain].enabled).
# The key is whitelisted on the relay with cohorts dreamlab+agent and named in
# the website overlay's [poker].citizen_pubkey (website ADR-2009). Baked binary
# (lib/poker-citizen.nix). REBUILD-class.
[poker_citizen]
enabled = true
key_file = "/home/devuser/workspace/sidestr/agents/poker-citizen.key"
# state = "/home/devuser/workspace/sidestr/agents/poker-citizen.json" # unset: run-citizen.sh picks the
# workspace ledger flag-off and the custody ledger under [security].role_isolation (ADR-2122)
relay = "wss://dreamlab-nostr-relay.solitary-paper-764d.workers.dev"
daily_cap = 20000 # DREAM the house pays out per day at most

[payments.sidestr]
enabled = true
# chain_id: the SC1 demo chain; sidestr:dreamlab is the live one on :3450
Expand Down
55 changes: 55 additions & 0 deletions config/poker/run-citizen.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
#!/usr/bin/env bash
# Runner for [program:poker-citizen]: the forum poker table's house seat
# (nostr-rust-forum `nostr-bbs-poker-citizen`, forum ADR-2020). Deals DREAM
# hands to members over the forum relay, plays the house bot, settles each
# hand on sidestr:dreamlab through the local producer. Gate: [poker_citizen].enabled.
# The binary is baked (lib/poker-citizen.nix), never built from the workspace.
#
# run-citizen.sh
#
# Environment (all optional; the defaults are DreamLab's):
# POKER_CITIZEN_KEY_FILE the house key file (64 hex or nsec1…), never an argument
# POKER_CITIZEN_RELAY the forum relay (wss://…)
# POKER_CITIZEN_STATE the ledger file (what members owe, what the house owes)
# POKER_STAKES_BB / POKER_BUYIN_BB / POKER_BOT_PROFILE / POKER_DAILY_CAP
# SIDESTR_PORT the local producer's port
# POKER_CUSTODY_ROOT the custody ledger root under role_isolation (tests only)
set -euo pipefail

WORKSPACE="${WORKSPACE:-$HOME/workspace}"
KEY="${POKER_CITIZEN_KEY_FILE:-$WORKSPACE/sidestr/agents/poker-citizen.key}"
STATE="${POKER_CITIZEN_STATE:-$WORKSPACE/sidestr/agents/poker-citizen.json}"
# Custody (ADR-2122): under [security].role_isolation the ledger is on the agentbox-events volume,
# owned by ab-poker-citizen (its HOME is on the /run/secrets tmpfs and it cannot write the
# workspace). Seeded once from the workspace ledger, which stays. Flag off again with a custody
# ledger longer than the workspace one: refuse, since the workspace ledger has forgotten hands
# settled under the flag and would pay them twice.
CUSTODY_LEDGER="${POKER_CUSTODY_ROOT:-/var/lib/agentbox/events/sidestr}/poker-citizen/poker-citizen.json"
if [ "${AGENTBOX_ROLE_ISOLATION:-0}" = 1 ]; then
[ -n "${POKER_CITIZEN_STATE:-}" ] || STATE="$CUSTODY_LEDGER"
umask 027
elif [ -z "${POKER_CITIZEN_STATE:-}" ] && [ -r "$CUSTODY_LEDGER" ] \
&& [ "$(stat -c %s "$CUSTODY_LEDGER")" -gt "$(stat -c %s "$STATE" 2>/dev/null || echo 0)" ]; then
echo "run-citizen: CUSTODY-STATE-AHEAD: $CUSTODY_LEDGER is longer than $STATE (hands settled under role_isolation). Refusing to settle twice: copy it over $STATE, or set POKER_CITIZEN_STATE." >&2
exit 1
fi
RELAY="${POKER_CITIZEN_RELAY:-wss://dreamlab-nostr-relay.solitary-paper-764d.workers.dev}"
PRODUCER="http://127.0.0.1:${SIDESTR_PORT:-3450}"

[ -r "$KEY" ] || { echo "run-citizen: missing $KEY" >&2; exit 1; }
command -v nostr-bbs-poker-citizen >/dev/null || { echo "run-citizen: nostr-bbs-poker-citizen not on PATH" >&2; exit 1; }

# Settlements spend through the producer: wait for it rather than burn supervisor retries at boot.
until curl -fs --max-time 5 -o /dev/null "$PRODUCER/tip"; do
echo "run-citizen: waiting for the producer at $PRODUCER" >&2; sleep 15
done

exec nostr-bbs-poker-citizen \
--key-file "$KEY" \
--relay "$RELAY" \
--producer "$PRODUCER" \
--state "$STATE" \
--stakes-bb "${POKER_STAKES_BB:-2,10,20,100,200}" \
--buyin-bb "${POKER_BUYIN_BB:-100}" \
--profile "${POKER_BOT_PROFILE:-tag}" \
--daily-cap "${POKER_DAILY_CAP:-20000}"
20 changes: 19 additions & 1 deletion config/role-accounts.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,8 @@
"nostr-gateway",
"nip98-proxy",
"sidestr-producer*",
"sidestr-faucet*"
"sidestr-faucet*",
"poker-citizen"
],
"roles": [
{
Expand Down Expand Up @@ -93,6 +94,15 @@
"secrets": [
{ "file": "treasury.key", "env": "SIDESTR_FAUCET_KEY", "source": "/var/lib/agentbox/secrets/sidestr-faucet-dreamlab-txbt4.key", "legacy": "/home/devuser/workspace/sidestr/agents/treasury-dreamlab-txbt4.key" }
]
},
{
"name": "ab-poker-citizen",
"uid": 970,
"purpose": "Forum poker table house seat ([poker_citizen], forum ADR-2020): the house key that settles hands on sidestr:dreamlab, up to daily_cap DREAM a day.",
"programs": ["poker-citizen"],
"secrets": [
{ "file": "house.key", "env": "POKER_CITIZEN_KEY_FILE", "source": "/var/lib/agentbox/secrets/poker-citizen.key", "legacy": "/home/devuser/workspace/sidestr/agents/poker-citizen.key" }
]
}
],
"groups": [
Expand Down Expand Up @@ -155,6 +165,14 @@
"mode": "2750",
"seed": [{ "from": "/home/devuser/workspace/sidestr/agents/faucet-dreamlab-txbt4.json", "to": "faucet.json" }],
"purpose": "sidestr:dreamlab-txbt4 faucet grant ledger, as for dreamlab."
},
{
"path": "/var/lib/agentbox/events/sidestr/poker-citizen",
"owner": "ab-poker-citizen",
"group": "devuser",
"mode": "2750",
"seed": [{ "from": "/home/devuser/workspace/sidestr/agents/poker-citizen.json", "to": "poker-citizen.json" }],
"purpose": "Poker house-seat ledger (run-citizen.sh POKER_CITIZEN_STATE under the flag): member and house balances and the daily cap's spend. Losing it would re-pay settled hands and reset the cap. Seeded once from the workspace ledger, which stays."
}
]
}
1 change: 1 addition & 0 deletions docs/SECURITY-profiles.md
Original file line number Diff line number Diff line change
Expand Up @@ -214,6 +214,7 @@ it is the host docker group (`reserved_ids`).
| `ab-sidestr-dreamlab-txbt4` | 967 | `sidestr-producer-dreamlab-txbt4` | `signer.key`, `parent.credential` |
| `ab-faucet-dreamlab-txbt4` | 968 | `sidestr-faucet-dreamlab-txbt4` | `treasury.key` |
| group `ab-identity-port` | 969 | — | members devuser, `ab-identity`, `ab-gateway`; owns the port socket's directory |
| `ab-poker-citizen` | 970 | `poker-citizen` | `house.key` (copied once from the workspace path the manifest names); its ledger moves to `/var/lib/agentbox/events/sidestr/poker-citizen` |

management-api, dream-engine, aoe, tmux and the agents stay devuser. JunkieJarvis is a key held
by `ab-identity`, not an account.
Expand Down
10 changes: 9 additions & 1 deletion docs/adr/ADR-2002-aoe-token-auth-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_commit: e3b06d6888293a32a758179e8c7dc9667c5d9f58
verified_paths: [config/nip98-proxy/proxy.mjs, scripts/aoe-curl.sh, flake.nix]
owner: jjohare
review_trigger: next image rebuild (activation), or any new consumer of :9095, or per-process isolation becoming available
Expand Down Expand Up @@ -234,3 +234,11 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.

### Re-verification — 2026-10-03 (poker house seat, PR #14)

`33cbb29e8..b41d9486c`: `flake.nix` bakes `nostr-bbs-poker-citizen` (`lib/poker-citizen.nix`) and a `[program:poker-citizen]` (`user=devuser`) only when `[sidechain].enabled` and `[poker_citizen].enabled`; it opens no listener: it dials the forum relay over `wss` and the local producer at `127.0.0.1:3450` (`55b9fe9f6`). Nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) reads the new table or program. The decision holds. Re-verified by `git log 33cbb29e8..b41d9486c -- <verified_paths>`.

### Re-verification — 2026-10-03 (key-variable rule)

`b41d9486c..e3b06d688` changes one governed line: `flake.nix` passes `--env-classes ${./config/custody/env-classes.json}` to the build-time `role-accounts isolate`, which now refuses a devuser program holding a key variable without a role (ADR-2122). Nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) changes. The decision holds. Re-verified by `git log b41d9486c..e3b06d688 -- <verified_paths>`.
10 changes: 9 additions & 1 deletion docs/adr/ADR-2009-nip98-proxy-identity-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_commit: e3b06d6888293a32a758179e8c7dc9667c5d9f58
verified_paths: [config/nip98-proxy/proxy.mjs, flake.nix, docs/INGRESS-identity.md]
owner: jjohare
review_trigger: A second identity ingress is proposed, or aoe serve stops binding loopback
Expand Down Expand Up @@ -242,3 +242,11 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.

### Re-verification — 2026-10-03 (poker house seat, PR #14)

`33cbb29e8..b41d9486c`: `flake.nix` bakes `nostr-bbs-poker-citizen` (`lib/poker-citizen.nix`) and a `[program:poker-citizen]` (`user=devuser`) only when `[sidechain].enabled` and `[poker_citizen].enabled`; it opens no listener: it dials the forum relay over `wss` and the local producer at `127.0.0.1:3450` (`55b9fe9f6`). Nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) reads the new table or program. The decision holds. Re-verified by `git log 33cbb29e8..b41d9486c -- <verified_paths>`.

### Re-verification — 2026-10-03 (key-variable rule)

`b41d9486c..e3b06d688` changes one governed line: `flake.nix` passes `--env-classes ${./config/custody/env-classes.json}` to the build-time `role-accounts isolate`, which now refuses a devuser program holding a key variable without a role (ADR-2122). Nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) changes. The decision holds. Re-verified by `git log b41d9486c..e3b06d688 -- <verified_paths>`.
14 changes: 13 additions & 1 deletion docs/adr/ADR-2012-relay-allowlist-only-ingress.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_commit: e3b06d6888293a32a758179e8c7dc9667c5d9f58
verified_paths: [agentbox.toml, flake.nix]
owner: jjohare
review_trigger: ingress_policy changes from allowlist, or the ADR-040 D3 governance-publisher key-split lands
Expand Down Expand Up @@ -310,3 +310,15 @@ Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the s
### Re-verification — 2026-10-03 (vaultSrc repin)

`f93586b9e..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2012 — Relay ingress is allowlist-only, no fallback, no auto-add) reads it. The decision holds. Re-verified by `git log f93586b9e..33cbb29e8 -- <verified_paths>`.

### Re-verification — 2026-10-03 (poker house seat, PR #14)

`33cbb29e8..b41d9486c`: `agentbox.toml` gains `[poker_citizen]` (`enabled = true`, key and state under `sidestr/agents`, the forum relay, `daily_cap = 20000`) (`55b9fe9f6`); `flake.nix` bakes `nostr-bbs-poker-citizen` (`lib/poker-citizen.nix`) and a `[program:poker-citizen]` (`user=devuser`) only when `[sidechain].enabled` and `[poker_citizen].enabled`; it opens no listener: it dials the forum relay over `wss` and the local producer at `127.0.0.1:3450` (`55b9fe9f6`). The house seat is an outbound relay client, not an ingress path; the relay allowlist is untouched. The decision holds. Re-verified by `git log 33cbb29e8..b41d9486c -- <verified_paths>`.

### Re-verification — 2026-10-03 (ab-poker-citizen role)

`b41d9486c..4ea3181b5` changes one governed line: `agentbox.toml` `[poker_citizen].state` becomes a comment (the runner's default is the same path flag-off), for the poker seat's role (`4ea3181b5`). Nothing this record governs (ADR-2012 — Relay ingress is allowlist-only, no fallback, no auto-add) reads that key. The decision holds. Re-verified by `git log b41d9486c..4ea3181b5 -- <verified_paths>`.

### Re-verification — 2026-10-03 (key-variable rule)

`4ea3181b5..e3b06d688` changes one governed line: `flake.nix` passes `--env-classes ${./config/custody/env-classes.json}` to the build-time `role-accounts isolate`, which now refuses a devuser program holding a key variable without a role (ADR-2122). Nothing this record governs (ADR-2012 — Relay ingress is allowlist-only, no fallback, no auto-add) changes. The decision holds. Re-verified by `git log 4ea3181b5..e3b06d688 -- <verified_paths>`.
10 changes: 9 additions & 1 deletion docs/adr/ADR-2013-loopback-publish-except-9096.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 33cbb29e86ba0e7def92fb100029b124e9269da7
verified_commit: e3b06d6888293a32a758179e8c7dc9667c5d9f58
verified_paths: [scripts/ci/check-ports-loopback.sh, .github/workflows/invariants.yml, flake.nix, docker-compose.yml]
owner: jjohare
review_trigger: Any new entry on the SANCTIONED list, or a new compose overlay file
Expand Down Expand Up @@ -315,3 +315,11 @@ Tripped by the W10 gap fixes on `custody/integration`. `.github/workflows/invari
### Re-verification — 2026-10-03 (vaultSrc repin)

`dc91e092a..33cbb29e8` changes one governed line: `flake.nix` `vaultSrc` moves from VisionClaw `64512141b` to main `94dc0ff60` (`33cbb29e8`, PR #13; ADR-2108 records why). Its one consumer is `lib/vault.nix` (the vault CLI package, `flake.nix:781`); nothing this record governs (ADR-2013 — Loopback-only compose publishes except the sanctioned-exposure list) reads it. The decision holds. Re-verified by `git log dc91e092a..33cbb29e8 -- <verified_paths>`.

### Re-verification — 2026-10-03 (poker house seat, PR #14)

`33cbb29e8..b41d9486c`: `flake.nix` bakes `nostr-bbs-poker-citizen` (`lib/poker-citizen.nix`) and a `[program:poker-citizen]` (`user=devuser`) only when `[sidechain].enabled` and `[poker_citizen].enabled`; it opens no listener: it dials the forum relay over `wss` and the local producer at `127.0.0.1:3450` (`55b9fe9f6`). No port is published or bound; the loopback-publish rule is untouched. The decision holds. Re-verified by `git log 33cbb29e8..b41d9486c -- <verified_paths>`.

### Re-verification — 2026-10-03 (key-variable rule)

`b41d9486c..e3b06d688` changes one governed line: `flake.nix` passes `--env-classes ${./config/custody/env-classes.json}` to the build-time `role-accounts isolate`, which now refuses a devuser program holding a key variable without a role (ADR-2122). Nothing this record governs (ADR-2013 — Loopback-only compose publishes except the sanctioned-exposure list) changes. The decision holds. Re-verified by `git log b41d9486c..e3b06d688 -- <verified_paths>`.
10 changes: 9 additions & 1 deletion docs/adr/ADR-2019-model-lifecycle-384-dim-freeze.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: none
activation_status: inactive
supersedes: []
superseded_by: []
verified_commit: f93586b9e52fda0d0b367881e2d2ff3014509faf
verified_commit: 4ea3181b5296081411e95ca3687f03ed9aa11785
verified_paths: [mcp/servers/lib/aggregate-effectiveness.js, scripts/ruvector-sona-feeder.mjs, agentbox.toml]
owner: jjohare
review_trigger: A SONA binary with configurable embedding_dim (384-capable) ships, or a dimension migration is planned
Expand Down Expand Up @@ -228,3 +228,11 @@ until the owner's rebuild.
## Re-verification — 2026-10-03 (`f93586b9e52fda0d0b367881e2d2ff3014509faf`, custody W2b/W4)

Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the sidechain state move). `agentbox.toml` changes only in the comment above `[security].role_isolation = false`: it no longer says the identity port and the custody migration are absent, and names what is built (W3, W2b, W4) and what is owed (W3b). No key or value moves. The embedding model, the 384-dim column and the SONA and attention-rerank switches are untouched. The decision holds. Re-verified by `git log 3b5412963..f93586b9e -- <verified_paths>`.

### Re-verification — 2026-10-03 (poker house seat, PR #14)

`f93586b9e..b41d9486c`: `agentbox.toml` gains `[poker_citizen]` (`enabled = true`, key and state under `sidestr/agents`, the forum relay, `daily_cap = 20000`) (`55b9fe9f6`). Nothing this record governs (ADR-2019 — Model-lifecycle freeze — 384-dim bge is the active column, SONA and attention-rerank stay off) reads the new table or program. The decision holds. Re-verified by `git log f93586b9e..b41d9486c -- <verified_paths>`.

### Re-verification — 2026-10-03 (ab-poker-citizen role)

`b41d9486c..4ea3181b5` changes one governed line: `agentbox.toml` `[poker_citizen].state` becomes a comment (the runner's default is the same path flag-off), for the poker seat's role (`4ea3181b5`). Nothing this record governs (ADR-2019 — Model-lifecycle freeze — 384-dim bge is the active column, SONA and attention-rerank stay off) reads that key. The decision holds. Re-verified by `git log b41d9486c..4ea3181b5 -- <verified_paths>`.
Loading
Loading