This is a projection, not a development branch. The tree above was constructed from the internal source named below under a manifest that decides which paths may leave, then scanned as a whole tree rather than as a series of patches, and only then published. Public history starts here because the history before it was not admissible, and neither was the tree. What used to stand in this repository included a rescue copy of another machine, a directory of phone handoffs, deployment wired to one house, and a submodule pointing at a forge no stranger can reach. None of that was ever the product. It stays in the private forge, which is allowed to hold the whole working organism, and this is what was deliberately sent out instead. Three mechanisms produced this tree, in decreasing order of trust. A top-level path the manifest does not name never arrives at all, which is the one that catches directories nobody has thought of yet. Named internal files inside admitted roots are dropped. A short, reviewed table replaces deployment defaults that a public build must not carry -- an endpoint aimed at one LAN, a VPN profile belonging to one phone, packaging built from one checkout path. Everything after this commit is an ordinary publication with the same three trailers, so a force push stops being routine and starts meaning that something deliberate happened. The trailers bind the projection to its source without pretending the public SHA is the private one: same lineage, different tree, and the record says so. Source-Sha: 8f27b1e76a8fef560a336aba18e6990713ff1047 Policy-Sha: 6b261d2f3e6e1fb19874846ba4bb1dfe15565d25b8618c1c1afba0419c101d27 Tree-Digest: 18ec3563c5e5ef9a414993a9f6734b251ff9ed3cd56eebdd6cac01e45c6e3067
2 KiB
2 KiB
Souveraine working agreement
The personal agreement is ~/.codex/AGENTS.md. The cross-repo map is
../AGENTS.md; read it when work crosses repository boundaries.
This repository
- This is the Rust agent substrate and Souveraine shell code. Use substrate, not harness, unless quoting an external source.
- The map is
../SouveraineOS/saf/INDEX.md— the living architecture lives at the umbrella, not beside the code. Read it before design work; the substrate's own oldsaf/here is a pointer, not a second spine. - Work/status documentation for the wider OS belongs in
../SouveraineOS/saf/and../SouveraineOS/saf/state.md, not a new local handoff. Update the one owner when behavior moves. - The normal branch is
primary. Verify status and recent history before editing, preserve unrelated changes, and stage explicit paths.
Build and delivery
- Gitea Actions is the reproducible build/test/package path. Push the scoped change and let CI build it.
- Keep local checks small and targeted. Do not replace the pipeline with a direct build-host build, an offline build, or a hand-copied artifact.
- Runner access is diagnostic. A green result matters only if the relevant job ran and, when required, published the expected package.
- Phone delivery is through package ownership and pacman. A symlink or copied file on glass may prove behavior, but it is not landed.
Shape of changes
- Preserve the substrate's one-owner instincts: one event path, one state writer, one canonical memory/history operation, one shipping path.
- Commit subjects are terse and honest: change and reason. Terse does not mean
sterile in our first-party forge; a body may have teeth if it still serves
the change. No AI attribution or
Co-Authored-Byline. - Separate verified behavior from reasoned design and from work never exercised on hardware.
- Before calling cross-repo work complete, reconcile the owning SouveraineOS task/state document and archive the task if its acceptance is actually met.