Start with README, STATUS, the architecture, and the security model. Preserve the full terminal-first ten-layer scope, but do not claim unimplemented integrations work.
- Build the Go product with Go 1.26.6 or newer, a C compiler, system SQLite development headers, and Git.
- Run
make check,make race,make version-check, andmake demoon owned fixtures. - Run
make manifestafter adding, removing, or editing tracked files, thenmake manifest-check. CI fails whenSOURCE_MANIFEST.jsonis stale. - When a change touches the Rust port (
crates/,Cargo.toml,Cargo.lock,licenses/, orscripts/rust_*), install the pinned toolchain withrustup toolchain install 1.88.0 --profile minimal --component clippy --component rustfmtand runmake rust-check CARGO='cargo +1.88.0'. It runscargo fmt, clippy with the workspace's pedantic lints as errors, the workspace tests, the script unit tests, and the locked license/notice audit. After a reviewed dependency change,make rust-notices CARGO='cargo +1.88.0'refreshes the bundled notices. - Add a focused regression test before changing acceptance semantics.
- Update STATUS and the acceptance mapping when a capability's guarantees change.
- Inspect the diff for source/state/credential leakage and unchecked error paths.
A green hosted CI run (docs/CI.md) is necessary but not sufficient. Provide the actual command, platform, toolchain, result, and limitations in a contribution.
Keep task execution, checks, acceptance, human assertions, and delivery separate. Do not promote missing verification to passing. Never hide unsupported functionality behind a no-op adapter. Use explicit argv and context cancellation. Prefer existing standard library and tools; add dependencies only with an ADR and license/security review. New parser formats need malformed/empty/truncated/false-result fixtures. New runtimes need lifecycle and cancellation tests on the claimed platform. Never run broad checks against a user's work without consent; the development demo owns its disposable repository.
Use Developer Certificate of Origin 1.1 sign-off for future contributions (git commit -s)
only when you can personally make that certification. Do not fabricate another person's
sign-off. The locally generated initial source is marked as tool-assisted in provenance;
no human DCO certification is inferred. No CLA or relicensing consent is assumed.
Small reviewable contributions are preferred. Report limitations plainly. A verified failing behavior is more useful than a confident unsupported quality claim.