Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions .github/workflows/invariants.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,9 @@ on:
- 'tests/config/protocol-registry-lint.test.mjs'
- 'tests/config/declared-vs-running.test.js'
- 'tests/config/fixtures/runtime-state.json'
- 'tests/config/ruflo-console.test.mjs'
- 'config/claude-plugins/**'
- 'flake.lock'
# Custody X-1 W0/W2 runtime contracts (RC-X1-01..06) and what they read
# beyond config/entrypoint-unified.sh and flake.nix (both listed here).
- 'tests/runtime-contract/RC-X1-*'
Expand Down Expand Up @@ -136,6 +139,9 @@ jobs:
- name: check-manifest-catalogue (ADR-039 gate-path parity)
run: node scripts/ci/check-manifest-catalogue.js

- name: ruflo-console bake + boot projection ([toolchains].ruflo_console)
run: node --test tests/config/ruflo-console.test.mjs

# CY-A2: the manifest must not lie about what runs. CI has no runtime, so
# it checks agentbox.toml against the committed, dated snapshot captured
# on the box (`--capture`); on the box the same script reads the live
Expand Down
1 change: 1 addition & 0 deletions agentbox.toml
Original file line number Diff line number Diff line change
Expand Up @@ -1876,6 +1876,7 @@ codex = true
opencode = true
code_server = true
cuda = true
ruflo_console = false # ruflo's Claude Code mods (function hooks), baked from the pinned ruflo v3.51.1 tag (flake input rufloConsole): ruflo-console (the /ruflo cockpit) + ruflo-mods (/ruflo mods) + ruflo-swarm (/ruflo swarm …) in the `agentbox` marketplace, userConfig cli=ruflo (the baked bin; also pulls in the ruflo closure). Rebuild-class; needs Claude Code >= 2.1.287. Off = the three ids are unregistered at boot

# ── Plugins (ruflo/claude-flow plugin system) ────────────────────────────────
# Plugins are installed into $HOME/.claude-flow/plugins/ at container boot
Expand Down
21 changes: 21 additions & 0 deletions config/claude-plugins/.claude-plugin/marketplace.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,27 @@
"description": "Jev compaction with fact rails: reduces what Jev lets go instead of deleting it, keeps the email taint fence, /factrail switch (ADR-2121). Baked from DreamLab-AI/factrail by lib/factrail.nix.",
"version": "0.1.0",
"license": "MIT OR Apache-2.0"
},
{
"name": "ruflo-console",
"source": "./ruflo-console",
"description": "ruflo's cockpit inside Claude Code and the one /ruflo command for every ruflo mod (function hooks): overview, swarms, claims, federation, plugins, learning, MetaHarness, memory and cost views, a confirm-gated command palette and a band above the prompt. Baked from ruvnet/ruflo v3.51.1 (09a1cb0) behind [toolchains].ruflo_console; cli defaults to the baked ruflo bin.",
"version": "0.1.0",
"license": "MIT"
},
{
"name": "ruflo-mods",
"source": "./ruflo-mods",
"description": "ruflo as a Claude Code mod (function hooks): in-process prompt routing, edit learning signals, tighten-only tool checks, the cost-tracker budget ladder, a mod trust gate and the $.ruflo noun; answers /ruflo mods. Baked from ruvnet/ruflo v3.51.1 (09a1cb0) behind [toolchains].ruflo_console; cli defaults to the baked ruflo bin.",
"version": "0.1.0",
"license": "MIT"
},
{
"name": "ruflo-swarm",
"source": "./ruflo-swarm",
"description": "Agent teams and swarm coordination with a live swarm pane (function hooks); answers /ruflo swarm pane|status|topology|claims|consensus. Baked from ruvnet/ruflo v3.51.1 (09a1cb0) behind [toolchains].ruflo_console; cli defaults to the baked ruflo bin.",
"version": "0.3.0",
"license": "MIT"
}
]
}
2 changes: 2 additions & 0 deletions config/custody/env-classes.json
Original file line number Diff line number Diff line change
Expand Up @@ -807,6 +807,8 @@
"_RB_MCP_DIR",
"_RB_NS",
"_RB_STAGING",
"_RC_MARKET",
"_RC_ON",
"_RECONCILE_AGENTS",
"_RECONCILE_COMMANDS",
"_RECONCILE_SKILLS",
Expand Down
38 changes: 34 additions & 4 deletions config/entrypoint-unified.sh
Original file line number Diff line number Diff line change
Expand Up @@ -2690,13 +2690,17 @@ unset _INSTR_LAYERS
# store (scripts/factrail-store-migrate.mjs), so a resumed email session stays
# fenced.
_JC_ON="$(_ab_toml_bool features.jev_compaction enabled)"
# [toolchains].ruflo_console shares the `agentbox` marketplace and the
# function-hook switch with factrail, so the factrail block below keeps both
# while either gate is on (see the ruflo-console block after it).
_RC_ON="$(_ab_toml_bool toolchains ruflo_console)"
_JC_MARKET="/opt/agentbox/config/claude-plugins"
_JC_PLUGIN="$_JC_MARKET/factrail"
_JC_BIN="/opt/agentbox/bin/factrail"
if command -v claude >/dev/null 2>&1 && [ -f "$_CLAUDE_SETTINGS" ] || [ "$_JC_ON" = "1" ]; then
SETTINGS="$_CLAUDE_SETTINGS" JC_ON="$_JC_ON" node <<'JCENVJS' || true
if command -v claude >/dev/null 2>&1 && [ -f "$_CLAUDE_SETTINGS" ] || [ "$_JC_ON" = "1" ] || [ "$_RC_ON" = "1" ]; then
SETTINGS="$_CLAUDE_SETTINGS" JC_ON="$_JC_ON" RC_ON="$_RC_ON" node <<'JCENVJS' || true
const fs = require('fs');
const f = process.env.SETTINGS, on = process.env.JC_ON === '1';
const f = process.env.SETTINGS, on = process.env.JC_ON === '1' || process.env.RC_ON === '1';
let s = {}, orig = ''; try { orig = fs.readFileSync(f, 'utf8'); s = JSON.parse(orig); } catch {}
if (on) { s.env = s.env || {}; s.env.CLAUDE_CODE_ENABLE_FUNCTION_HOOKS = '1'; }
else if (s.env) { delete s.env.CLAUDE_CODE_ENABLE_FUNCTION_HOOKS; if (!Object.keys(s.env).length) delete s.env; }
Expand Down Expand Up @@ -2806,12 +2810,38 @@ elif command -v claude >/dev/null 2>&1 && [ -d /home/devuser/.claude/plugins ];
run_as_devuser env HOME=/home/devuser timeout 60 claude plugin uninstall factrail@agentbox >/dev/null 2>&1 \
&& echo " [factrail] uninstalled plugin (gate off)"
fi
if grep -q '"agentbox"' /home/devuser/.claude/plugins/known_marketplaces.json 2>/dev/null; then
if [ "$_RC_ON" != "1" ] && grep -q '"agentbox"' /home/devuser/.claude/plugins/known_marketplaces.json 2>/dev/null; then
run_as_devuser env HOME=/home/devuser timeout 60 claude plugin marketplace remove agentbox >/dev/null 2>&1 \
&& echo " [factrail] removed agentbox marketplace (gate off)"
fi
fi

# ── [toolchains].ruflo_console: ruflo-console + ruflo-mods + ruflo-swarm ──────
# Baked from the pinned ruflo v3.51.1 tag (flake input rufloConsole) into the
# `agentbox` marketplace beside factrail. Gate on: the marketplace is
# registered, and scripts/ruflo-console-project.mjs registers the three plugins
# at their stable /opt paths in installed_plugins.json (the codex-plugin-cc
# pattern: no cache copy, so a rebuild is never served a stale plugin), enables
# them in settings.json and sets userConfig cli=ruflo (the baked bin on PATH;
# upstream's npx-offline default fails without a warm npm cache).
# CLAUDE_CODE_ENABLE_FUNCTION_HOOKS is set by the block above. Self-healing: a
# wrong installPath, version or cli is rewritten every boot. Gate off: the three
# ids are removed and nothing else changes. Fail-open throughout.
_RC_MARKET="/opt/agentbox/config/claude-plugins"
if command -v node >/dev/null 2>&1 && [ -d /home/devuser/.claude ]; then
if [ "$_RC_ON" = "1" ] && [ -d "$_RC_MARKET/ruflo-console" ] && command -v claude >/dev/null 2>&1; then
run_as_devuser env HOME=/home/devuser timeout 60 claude plugin marketplace add "$_RC_MARKET" >/dev/null 2>&1 \
|| echo " [ruflo-console] marketplace add failed (continuing; a stale registration may remain)"
command -v ruflo >/dev/null 2>&1 \
|| echo " [ruflo-console] the ruflo bin is not on PATH — console probes will read n/a until the image is rebuilt with the gate on"
fi
run_as_devuser env HOME=/home/devuser node /opt/agentbox/scripts/ruflo-console-project.mjs \
--on "$_RC_ON" --settings "$_CLAUDE_SETTINGS" \
--installed /home/devuser/.claude/plugins/installed_plugins.json \
--market "$_RC_MARKET" || true
fi
unset _RC_MARKET

# ── MCP registry projection (MCP-1 / MCP-2): project .mcp.json FROM skills/mcp.json ──
# audit-2026-07-15 MCP-1: skills/mcp.json (the 28-server registry) had NO runtime
# consumer — ~19 gated servers registered nowhere the harness reads. This makes the
Expand Down
6 changes: 5 additions & 1 deletion docs/adr/ADR-2002-aoe-token-auth-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: daba195e5671cdf3906095965d323cef3f80aa3a
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [config/nip98-proxy/proxy.mjs, scripts/aoe-curl.sh, flake.nix]
owner: jjohare
review_trigger: next image rebuild (activation), or any new consumer of :9095, or per-process isolation becoming available
Expand Down Expand Up @@ -246,3 +246,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
### Re-verification — 2026-10-03 (ruflo 3.51.1, Claude Code 2.1.288)

`e3b06d688..daba195e5`: `flake.nix` changes only the `rufloPkg` pin: version 3.51.1, its lock (`config/npm-locks/ruflo-3.51.1.package-lock.json`) and both hashes (`daba195e5`), with the rationale comment. The ruflo closure's bins and extraBins aliases, every gate and every other derivation are unchanged. Nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) changes meaning. The decision holds. Re-verified by `git log e3b06d688..daba195e5 -- <verified_paths>`. Nix was not evaluated here; the image is unverified until the host rebuild.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`daba195e5..451823ca8`: `flake.nix` adds the pinned `rufloConsole` input (ruflo v3.51.1, files-only), the `rufloConsolePlugins` bake (only the three mod directories) and its copy into the `agentbox` marketplace under `[toolchains].ruflo_console`, and lets that gate pull in the ruflo closure. Nothing this record governs (ADR-2002 — AoE interaction plane requires token auth — loopback is not a boundary) changes meaning. The decision holds. Re-verified by `git log daba195e5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2009-nip98-proxy-identity-boundary.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: complete
activation_status: live
supersedes: []
superseded_by: []
verified_commit: daba195e5671cdf3906095965d323cef3f80aa3a
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [config/nip98-proxy/proxy.mjs, flake.nix, docs/INGRESS-identity.md]
owner: jjohare
review_trigger: A second identity ingress is proposed, or aoe serve stops binding loopback
Expand Down Expand Up @@ -254,3 +254,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `flake.nix` (`dc91e092a`)
### Re-verification — 2026-10-03 (ruflo 3.51.1, Claude Code 2.1.288)

`e3b06d688..daba195e5`: `flake.nix` changes only the `rufloPkg` pin: version 3.51.1, its lock (`config/npm-locks/ruflo-3.51.1.package-lock.json`) and both hashes (`daba195e5`), with the rationale comment. The ruflo closure's bins and extraBins aliases, every gate and every other derivation are unchanged. Nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) changes meaning. The decision holds. Re-verified by `git log e3b06d688..daba195e5 -- <verified_paths>`. Nix was not evaluated here; the image is unverified until the host rebuild.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`daba195e5..451823ca8`: `flake.nix` adds the pinned `rufloConsole` input (ruflo v3.51.1, files-only), the `rufloConsolePlugins` bake (only the three mod directories) and its copy into the `agentbox` marketplace under `[toolchains].ruflo_console`, and lets that gate pull in the ruflo closure. Nothing this record governs (ADR-2009 — The nip98-proxy is the fail-closed AoE identity boundary) changes meaning. The decision holds. Re-verified by `git log daba195e5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2012-relay-allowlist-only-ingress.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: daba195e5671cdf3906095965d323cef3f80aa3a
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [agentbox.toml, flake.nix]
owner: jjohare
review_trigger: ingress_policy changes from allowlist, or the ADR-040 D3 governance-publisher key-split lands
Expand Down Expand Up @@ -326,3 +326,7 @@ Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the s
### Re-verification — 2026-10-03 (ruflo 3.51.1, Claude Code 2.1.288)

`e3b06d688..daba195e5`: `flake.nix` changes only the `rufloPkg` pin: version 3.51.1, its lock (`config/npm-locks/ruflo-3.51.1.package-lock.json`) and both hashes (`daba195e5`), with the rationale comment. The ruflo closure's bins and extraBins aliases, every gate and every other derivation are unchanged. Nothing this record governs (ADR-2012 — Relay ingress is allowlist-only with no fallback and no auto-add) changes meaning. The decision holds. Re-verified by `git log e3b06d688..daba195e5 -- <verified_paths>`. Nix was not evaluated here; the image is unverified until the host rebuild.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`daba195e5..451823ca8`: `agentbox.toml` adds `[toolchains].ruflo_console = false`; `flake.nix` adds the pinned `rufloConsole` input (ruflo v3.51.1, files-only), the `rufloConsolePlugins` bake (only the three mod directories) and its copy into the `agentbox` marketplace under `[toolchains].ruflo_console`, and lets that gate pull in the ruflo closure. Nothing this record governs (ADR-2012 — Relay ingress is allowlist-only with no fallback and no auto-add) changes meaning. The decision holds. Re-verified by `git log daba195e5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2013-loopback-publish-except-9096.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: daba195e5671cdf3906095965d323cef3f80aa3a
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [scripts/ci/check-ports-loopback.sh, .github/workflows/invariants.yml, flake.nix, docker-compose.yml]
owner: jjohare
review_trigger: Any new entry on the SANCTIONED list, or a new compose overlay file
Expand Down Expand Up @@ -327,3 +327,7 @@ Tripped by the W10 gap fixes on `custody/integration`. `.github/workflows/invari
### Re-verification — 2026-10-03 (ruflo 3.51.1, Claude Code 2.1.288)

`e3b06d688..daba195e5`: `flake.nix` changes only the `rufloPkg` pin: version 3.51.1, its lock (`config/npm-locks/ruflo-3.51.1.package-lock.json`) and both hashes (`daba195e5`), with the rationale comment. The ruflo closure's bins and extraBins aliases, every gate and every other derivation are unchanged. Nothing this record governs (ADR-2013 — Every compose publish binds 127.0.0.1 unless on the sanctioned-exposure list, CI-enforced across all overlays) changes meaning. The decision holds. Re-verified by `git log e3b06d688..daba195e5 -- <verified_paths>`. Nix was not evaluated here; the image is unverified until the host rebuild.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`daba195e5..451823ca8`: `invariants.yml` runs `tests/config/ruflo-console.test.mjs` and widens its path filter; `flake.nix` adds the pinned `rufloConsole` input (ruflo v3.51.1, files-only), the `rufloConsolePlugins` bake (only the three mod directories) and its copy into the `agentbox` marketplace under `[toolchains].ruflo_console`, and lets that gate pull in the ruflo closure. Nothing this record governs (ADR-2013 — Every compose publish binds 127.0.0.1 unless on the sanctioned-exposure list, CI-enforced across all overlays) changes meaning. The decision holds. Re-verified by `git log daba195e5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2019-model-lifecycle-384-dim-freeze.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: none
activation_status: inactive
supersedes: []
superseded_by: []
verified_commit: 4ea3181b5296081411e95ca3687f03ed9aa11785
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [mcp/servers/lib/aggregate-effectiveness.js, scripts/ruvector-sona-feeder.mjs, agentbox.toml]
owner: jjohare
review_trigger: A SONA binary with configurable embedding_dim (384-capable) ships, or a dimension migration is planned
Expand Down Expand Up @@ -236,3 +236,7 @@ Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the s
### Re-verification — 2026-10-03 (ab-poker-citizen role)

`b41d9486c..4ea3181b5` changes one governed line: `agentbox.toml` `[poker_citizen].state` becomes a comment (the runner's default is the same path flag-off), for the poker seat's role (`4ea3181b5`). Nothing this record governs (ADR-2019 — Model-lifecycle freeze — 384-dim bge is the active column, SONA and attention-rerank stay off) reads that key. The decision holds. Re-verified by `git log b41d9486c..4ea3181b5 -- <verified_paths>`.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`4ea3181b5..451823ca8`: `agentbox.toml` adds `[toolchains].ruflo_console = false`. Nothing this record governs (ADR-2019 — Model-lifecycle freeze — 384-dim bge is the active column, SONA and attention-rerank stay off) changes meaning. The decision holds. Re-verified by `git log 4ea3181b5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2020-capability-gating.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 4ea3181b5296081411e95ca3687f03ed9aa11785
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [agentbox.toml, skills/tree-search-coder/SKILL.md, services/agentbox-ops/src/bin/tree-search-cap.rs]
owner: jjohare
review_trigger: any new optional skill/feature block added to agentbox.toml, or any change to the tree-search-coder spend/route posture
Expand Down Expand Up @@ -243,3 +243,7 @@ Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the s
### Re-verification — 2026-10-03 (ab-poker-citizen role)

`b41d9486c..4ea3181b5` changes one governed line: `agentbox.toml` `[poker_citizen].state` becomes a comment (the runner's default is the same path flag-off), for the poker seat's role (`4ea3181b5`). Nothing this record governs (ADR-2020 — Optional capabilities are manifest-gated and byte-identical-when-off; execution-gated tools are spend-capped and never auto-routed) reads that key. The decision holds. Re-verified by `git log b41d9486c..4ea3181b5 -- <verified_paths>`.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`4ea3181b5..451823ca8`: `agentbox.toml` adds `[toolchains].ruflo_console = false`. Nothing this record governs (ADR-2020 — Optional capabilities are manifest-gated and byte-identical-when-off; execution-gated tools are spend-capped and never auto-routed) changes meaning. This record's rule is exercised directly: the gate defaults off, flake.nix bakes nothing under it when off, and the boot projection leaves `settings.json` and `installed_plugins.json` byte-identical when none of the three ids is present (asserted in `tests/config/ruflo-console.test.mjs`). The decision holds. Re-verified by `git log 4ea3181b5..451823ca8 -- <verified_paths>`.
6 changes: 5 additions & 1 deletion docs/adr/ADR-2023-loom-facade.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ implementation_status: partial
activation_status: live
supersedes: []
superseded_by: []
verified_commit: 4ea3181b5296081411e95ca3687f03ed9aa11785
verified_commit: 451823ca8ec0b5452ceb8fdc52e777f77a2bbc43
verified_paths: [agentbox.toml, mcp/servers/lib/ontology-retrieval.js]
owner: jjohare
review_trigger: model swap behind the Loom, or ADR-051 deferred-distillation MCP tools becoming a discrete server
Expand Down Expand Up @@ -306,3 +306,7 @@ Tripped by `f93586b9e` (custody W2b and W4: the at-rest migrate/revert and the s
### Re-verification — 2026-10-03 (ab-poker-citizen role)

`b41d9486c..4ea3181b5` changes one governed line: `agentbox.toml` `[poker_citizen].state` becomes a comment (the runner's default is the same path flag-off), for the poker seat's role (`4ea3181b5`). Nothing this record governs (ADR-2023 — The Loom is a façade — consumers hold the :8084 door and the model is a swappable URL behind it) reads that key. The decision holds. Re-verified by `git log b41d9486c..4ea3181b5 -- <verified_paths>`.

### Re-verification — 2026-10-03 (ruflo-console gate, `451823ca8`)

`4ea3181b5..451823ca8`: `agentbox.toml` adds `[toolchains].ruflo_console = false`. Nothing this record governs (ADR-2023 — The Loom is a façade — consumers hold the :8084 door and the model is a swappable URL behind it) changes meaning. The decision holds. Re-verified by `git log 4ea3181b5..451823ca8 -- <verified_paths>`.
Loading
Loading