Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions Cargo.lock

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions crates/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,7 @@ Boundary rule: if you need an upstream crate in a low-level crate, stop and chec
| `ironclaw_common` | `ironclaw_common/AGENTS.md`, `Cargo.toml` | Low-dependency shared types/utilities: app events, identity, trust-boundary helpers, paths, platform/env/timezone, attachment helpers. | Runtime orchestration, persistence, clients, policy, product domain logic. |
| `ironclaw_host_api` | `ironclaw_host_api/AGENTS.md`, `ironclaw_host_api/CLAUDE.md`, `docs/reborn/contracts/host-api.md` | Neutral authority vocabulary: IDs, scopes, paths, actions, decisions, resources, approvals, audit, HTTP, dispatch, runtime-policy, trust types. | Runtime execution, persistence, HTTP clients, product workflow, policy engines. |
| `ironclaw_extension_contracts` | `ironclaw_extension_contracts/CLAUDE.md`, `docs/reborn/target-architecture/families/contracts.md` | The extension tier's contract: what an installable extension declares and exposes — `ChannelAdapter`/`ToolAdapter`/`RestrictedEgress` and their DTO families, channel egress transport vocabulary, the external vendor refs, the channel-rendered auth-prompt views, the hosted-MCP registration input, the bounded package-identity newtypes, channel manifest-surface descriptors, channel-identity hooks, the `Extension` trait, the `[memory]` surface, the auth recipe schema, the installation state machine, `CapabilitySurfaceKind`, and the vendor-implemented `PreferenceTargetCodec`. | Any implementation of a port declared here, the registry or installation stores, lifecycle execution or ingress routing, product workflow, vendor names, any framework or driver crate. |
| `ironclaw_product_contracts` | `ironclaw_product_contracts/CLAUDE.md`, `docs/reborn/target-architecture/families/contracts.md` | The product tier's contract: the `ProductSurface`/`BoundProductSurface`/caller membrane and its invoke/query/stream DTOs, `ChannelInboundProductSurface`, the inbound/outbound/projection product wire DTOs, the interaction-reply grammar, the operator LLM menu vocabulary, and the package-lifecycle projection vocabulary. | The `ProductSurface` implementation or the frozen command/view inventory (those are `ironclaw_product`), any handler/admission/delivery logic, projection reducers, HTTP of any kind, vendor names, any framework or driver crate. |
| `ironclaw_product_contracts` | `ironclaw_product_contracts/CLAUDE.md`, `docs/reborn/target-architecture/families/contracts.md` | The product tier's contract: the `ProductSurface`/`BoundProductSurface`/caller membrane and its invoke/query/stream DTOs, `ChannelInboundProductSurface`, the inbound/outbound/projection product wire DTOs, the interaction-reply grammar, the operator LLM menu vocabulary, the package-lifecycle projection vocabulary, and — since WS2's first row — the **product-side ports the extension host implements**: delivery resolution + reply context, account-connection status, channel config, the view-provider conduit, command context + actor-role admission, gate-prompt enrichment, the lifecycle product service, the admin-user directory, and the operator tool catalog. | The `ProductSurface` implementation or the frozen command/view inventory (those are `ironclaw_product`), any handler/admission/delivery logic, projection reducers, HTTP of any kind, vendor names, any framework or driver crate. **Any implementation of a port declared here** — including a fail-closed default; those stay with their owner. |
| `ironclaw_prompt_envelope` | `Cargo.toml`, `src/lib.rs` | Leaf prompt-envelope helper: wraps model-visible snippets with closed-vocabulary source/trust labels, size limits, and instruction-hijack rejection. | Runtime orchestration, model routing, policy decisions, or free-form source labels. |
| `ironclaw_architecture` | `ironclaw_architecture/AGENTS.md`, `ironclaw_architecture/CLAUDE.md` | Workspace architecture tests, Reborn dependency boundaries, composition-boundary checks. | Production runtime code or production deps. |
| `ironclaw_observability` | `Cargo.toml`, `src/lib.rs` | Shared latency-tracing macros (`live_latency_trace*`) over the `ironclaw_latency` tracing target. | Policy, state, or runtime behavior. |
Expand Down Expand Up @@ -144,7 +144,7 @@ Boundary rule: if you need an upstream crate in a low-level crate, stop and chec
| `ironclaw_telegram_v2_adapter` | `ironclaw_telegram_v2_adapter/AGENTS.md`, `Cargo.toml`, `src/lib.rs` | Telegram Bot API **protocol engine only**: payload normalization (`payload.rs`) and outbound request rendering (`render.rs`). No I/O, no secrets. | The `ChannelAdapter` impl itself (that is `ironclaw_telegram_extension`); host verification/egress. |
| `ironclaw_telegram_extension` | `ironclaw_telegram_extension/AGENTS.md`, `Cargo.toml`, `src/lib.rs` | The Telegram **`ChannelAdapter`**: live inbound/outbound, webhook registration hooks, preference targets, attachment transfer — layered on `ironclaw_telegram_v2_adapter`'s protocol work. Stays free of raw token bytes. | Bot API payload/render logic; host signing secrets, admission, or egress credentials. |
| `ironclaw_webui` | `ironclaw_webui/AGENTS.md`, `ironclaw_webui/CLAUDE.md`, `ironclaw_webui/README.md` | The whole WebUI host stack for Reborn WebChat v2: the `webui_v2` route surface + axum handlers + descriptor table + redacted `WebUiV2HttpError` (folded up from the former `ironclaw_webui_v2` crate), the Vite SPA bundle (`frontend/`), the `webui_v2_app` gateway assembly + middleware stack, the listener/serve loop, and host authentication (Env/Session/OIDC authenticators, `SessionStore`, `/auth/*` OAuth login). | Product/API business logic, product services, lower substrates, transcript storage, and v1 channel code. Use `ProductSurface`; direct `ironclaw_product` imports are DTOs/descriptors only. |
| `ironclaw_extension_host` | `Cargo.toml`, `src/lib.rs` | Generic channel-host assembly binding installed extensions to inbound/outbound channel surfaces for the Reborn product surface: ingress registration, extension lifecycle command execution, delivery, and per-extension idempotency ledgers. Also the **hosted-MCP registration pipeline** (`hosted_mcp_admission`, `hosted_mcp_manifest`, `hosted_mcp_preparation`, `mcp_catalog_safety`): endpoint admission, synthesized manifests, tool discovery, and catalog safety for user-registered remote MCP servers. That pipeline is deliberately separate from the shared install→activate→remove lifecycle — `crates/ironclaw_architecture/tests/reborn_registration_pipeline_boundary.rs` fails the build if registration vocabulary (`PreparationRequirement`, `initial_preparation`) appears outside `src/hosted_mcp_*`, so put "registered but not yet discovered" state inside the pipeline, never in generic lifecycle code. | Host authority (signing secrets, bot tokens, network egress) and workflow admission; keep those in lower host crates and `ironclaw_reborn_composition`. |
| `ironclaw_extension_host` | `Cargo.toml`, `src/lib.rs` | Generic channel-host assembly binding installed extensions to inbound/outbound channel surfaces for the Reborn product surface: ingress registration, extension lifecycle command execution, delivery, and per-extension idempotency ledgers. Also the **hosted-MCP registration pipeline** (`hosted_mcp_admission`, `hosted_mcp_manifest`, `hosted_mcp_preparation`, `mcp_catalog_safety`): endpoint admission, synthesized manifests, tool discovery, and catalog safety for user-registered remote MCP servers. That pipeline is deliberately separate from the shared install→activate→remove lifecycle — `crates/ironclaw_architecture/tests/reborn_registration_pipeline_boundary.rs` fails the build if registration vocabulary (`PreparationRequirement`, `initial_preparation`) appears outside `src/hosted_mcp_*`, so put "registered but not yet discovered" state inside the pipeline, never in generic lifecycle code. | Host authority (signing secrets, bot tokens, network egress) and workflow admission; keep those in lower host crates and `ironclaw_reborn_composition`. **New product-side ports**: this crate is below product in the target tree, so a port it implements is declared in `ironclaw_product_contracts`, never in `ironclaw_product` — `reborn_extension_host_port_inversion.rs` fails on a new one and its residue list is shrink-only. |
| `ironclaw_slack_extension` | `ironclaw_slack_extension/AGENTS.md` | Slack `ChannelAdapter`: protocol parsing/rendering (payloads, mrkdwn, delivery DTOs, preference targets, attachment transfer). Host-side ingress — signature verification and delivery — is generic and lives in `ironclaw_extension_host` (`src/ingress/verifier.rs`, `src/channel_host.rs`), driven by the manifest recipe, not by Slack-specific host code. | Signing secrets, bot tokens, network, workflow admission — the boundary test bans host concerns here. |
| `ironclaw_reborn_identity` | `Cargo.toml`, `src/lib.rs` | Canonical identity mapping: every external identity (OAuth login, channel actor) → stable `UserId` before runtime state; filesystem-backed resolver fronted through composition. | Auth flows, session storage, provider HTTP. |

Expand Down
Loading
Loading