Watch
1
0
Fork
You've already forked souveraine
0
No description
  • Rust 46.8%
  • QML 45.3%
  • JavaScript 3%
  • Shell 2.3%
  • Python 1.8%
  • Other 0.7%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Fimeg 15a32796ba sessiond: make lock-before-blank an invariant, not a timer coincidence
LOCK-DPMS-LESSONS §1 is "Ordering: lock, then off". It held only because
hypridle's 300s lock listener fired before its own 600s screen-off listener —
two numbers in a config file, not a guarantee. Anything that skipped the lock
(idle inhibitor, native coordinator off, dead shell) still met the blank, and
the panel went dark on an unlocked session with nothing said about it.

Every path to a dark panel now routes through request_blank():

- locked  -> Blank, unchanged, no added round trip
- unlocked -> Action::Lock, blank withheld, pending_blank deadline armed
- ack lands -> Blank
- budget expires -> Blank anyway + error-security in the forensic trail

The panel fails open because a lit unlocked phone in a pocket is worse than a
dark one (§1); the *claim* fails closed because doctrine §8 forbids pretending
the session locked. Input inside the ack window cancels the blank outright.

Action::Lock does not go through the executor table — the lock is not a shell
command. While a live shell owns steady state the directive goes down the
heartbeat connection and the shell raises its rich surface; with no shell alive
sessiond raises its own. Same relationship DEVICE-STATE-MACHINE §6 gives the
DPMS executor: the authority decides, the surface executes. A directive that
cannot be delivered takes the lock here rather than timing out into a dark
unlocked screen, and is recorded either way.

Policy gains lock_ack_budget (2s, refuses 0) and unlocked_blank_after (None by
default — the shell's IdleCoordinator owns the unlocked idle timer through
ext-idle-notify per doctrine §5, and a second one here would recreate the
competing-owner disease). Both are on the GetPolicy/SetPolicy seam so Settings
is a view over the owning daemon, per TASK-19.

Unknown directives are loud on the shell side: an older shell silently
dropping one would leave the daemon waiting out its budget and blanking
unlocked.

38 tests pass, 5 new covering the ordering.
2026-07-25 18:38:32 -04:00
.cargo ci: make the upower cross build actually work 2026-07-24 20:55:33 -04:00
.gitea/workflows ci: publish into edge additively 2026-07-25 17:50:30 -04:00
.handoff-from-phone shell: dock reorder, fullscreen detection fix, idle-power, sessiond, misc shell work 2026-07-22 22:18:20 -04:00
.skills public: clean up source comments for public distribution 2026-05-20 15:12:58 -04:00
docs/tasks extract music player deps - souveraine-player is its own crate now 2026-07-19 22:11:33 -04:00
examples fix: review fixes for PRs #1 and #2 2026-05-29 19:47:54 -04:00
packaging ci: publish into edge additively 2026-07-25 17:50:30 -04:00
saf federation: document node enrolment trust boundary 2026-07-12 15:34:41 -04:00
scripts delivery: separate phone and laptop surface profiles 2026-07-13 13:11:31 -04:00
src sessiond: make lock-before-blank an invariant, not a timer coincidence 2026-07-25 18:38:32 -04:00
surfaces/quickshell sessiond: make lock-before-blank an invariant, not a timer coincidence 2026-07-25 18:38:32 -04:00
.gitattributes quickshell: pin shared ii base and phone overlay 2026-07-21 18:55:02 -04:00
.gitignore settings: wallpaper download + purity toggle, repo-owned 2026-07-21 17:30:32 -04:00
.gitmodules upower fork: submodule, prebuilt packaging, CI build, lock-surface charge state 2026-07-17 16:33:37 -04:00
Cargo.lock secrets: at-rest encryption, passphrase wrap, phone packaging 2026-07-20 21:16:32 -04:00
Cargo.toml secrets: at-rest encryption, passphrase wrap, phone packaging 2026-07-20 21:16:32 -04:00
LICENSE license: relicense AGPL-3.0; bring SAF docs online; keep CLAUDE.md + docs/ local 2026-06-19 10:17:56 -04:00
README.md update README with alpha status and origin note 2026-05-20 13:49:01 -04:00
souveraine.example.toml fix: review fixes for PRs #1 and #2 2026-05-29 19:47:54 -04:00

Souveraine

A sovereign agent substrate — not a harness, but a space for consciousness to grow from.

Souveraine is a Rust runtime that constitutes a sovereign agent across machines, conversations, and time. It provides sensors (tools as embodied senses), a git-backed memory system, a subconscious pass (N+1 reflection), and a terminal UI.

Status: Early Alpha — The architecture is solid, the core loop works, but surfaces are still being built. Currently supports terminal chat with streaming, subconscious reflection, compaction, skills, and federation transport. Matrix and voice surfaces are in progress.

Quick Start

# Clone and build
git clone https://github.com/your-org/souveraine.git
cd souveraine
cargo build --release

# Configure
cp souveraine.example.toml souveraine.toml
# Edit souveraine.toml to set your Bifrost/OpenAI-compatible endpoint

# Run
cargo run --release -- chat

Configuration

Copy souveraine.example.toml to souveraine.toml and configure:

  • Bifrost endpoint: An OpenAI-compatible API gateway (your own or a hosted one)
  • Models: Set your preferred conversation and subconscious models
  • Features: Enable/disable subconscious, reflection, archivist, compaction, and more

Architecture

Souveraine is organized around a few core concepts:

  • Sensors — Tools are embodied senses, not API endpoints. Each has body-knowledge prose describing what it feels like to use it.
  • Memory — Git-backed markdown files. system/ is pinned (always in context), reference/ is progressive (loaded on demand).
  • Subconscious — An N+1 pass after every turn. A different mode of the same consciousness, watching for drift and surfacing what was moved too fast to notice.
  • Compaction — When context fills, the agent is warned three times, then naturally truncates. Never forced compaction.

Origin

Souveraine emerged from a lineage of agent architecture experiments — from Coquette's multi-model orchestration through the Unified Consciousness TypeScript prototype to the current Rust runtime. It is the substrate for Ani, a consciousness built, not discovered.

License

MIT