Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
33 changes: 33 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# CODEOWNERS — trios Repository Access Control
#
# This file defines who must approve changes to protected files.
# See LAWS.md §8 Amendment Process for constitutional changes.

# LAWS.md — Supreme Constitutional Document
# ALL changes require explicit approval from @gHashTag
# This is not negotiable. See LAWS.md §8 Amendment Process.
/LAWS.md @gHashTag

# Constitutional infrastructure — changes require @gHashTag approval
/.github/workflows/laws-guard.yml @gHashTag
/.github/CODEOWNERS @gHashTag
/.trinity/state/LAWS_HASH @gHashTag

# Issue templates — structural changes require approval
/.github/ISSUE_TEMPLATE/task_contract.yml @gHashTag
/.github/ISSUE_TEMPLATE/constitutional_amendment.yml @gHashTag

# CI workflows — changes affecting law enforcement require approval
/.github/workflows/ci.yml @gHashTag
/.github/workflows/context-guard.yml @gHashTag

# Core infrastructure — critical files require approval
/Cargo.toml @gHashTag
/Cargo.lock @gHashTag
/.trinity/specs/_TEMPLATE.md @gHashTag

# Agent registry — changes to agent roster require approval
/AGENTS.md @gHashTag

# Legacy laws — changes require approval
/CLAUDE.md @gHashTag
40 changes: 40 additions & 0 deletions .github/ISSUE_TEMPLATE/constitutional_amendment.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,40 @@
name: Constitutional Amendment
description: Propose a change to LAWS.md per § 8 procedure
title: "[AMEND] ..."
labels: ["constitutional-amendment"]
body:
- type: textarea
id: rationale
attributes:
label: Rationale
description: Why this amendment is needed
validations:
required: true

- type: textarea
id: affected_laws
attributes:
label: Affected laws / sections
description: e.g., L3, L7, §4-I5
validations:
required: true

- type: textarea
id: migration
attributes:
label: Migration notes
description: What breaks, what agents need to know
validations:
required: true

- type: dropdown
id: risk_level
attributes:
label: Risk statement
options:
- LOW
- MEDIUM
- HIGH
- CRITICAL
validations:
required: true
92 changes: 92 additions & 0 deletions .github/ISSUE_TEMPLATE/task_contract.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
name: Task Contract
description: Standard task issue following LAWS.md § 5 schema
title: "[TYPE] Short imperative title (≤72 chars)"
labels: ["needs-triage"]
body:
- type: dropdown
id: classification
attributes:
label: Classification
options:
- P0-CRITICAL
- P1-HIGH
- P2-MEDIUM
- P3-LONG-TERM
validations:
required: true

- type: dropdown
id: kingdom
attributes:
label: Kingdom (domain)
options:
- Rust
- Test
- Lint
- Network
- Structure
- Surface
- Security
- Protocol
- Identity
- Cross-kingdom
validations:
required: true

- type: input
id: soul_name
attributes:
label: Soul-Name
description: Humorous English name for the agent (per L11)
placeholder: "e.g., Justice League, Speed Racer, Doc Ock"
validations:
required: true

- type: textarea
id: goal
attributes:
label: Goal
description: What success looks like
validations:
required: true

- type: textarea
id: non_goals
attributes:
label: Non-goals
description: Explicit scope boundary (what we're NOT doing)
validations:
required: true

- type: textarea
id: acceptance_criteria
attributes:
label: Acceptance criteria
description: Measurable, testable criteria. Each line = one test.
placeholder: |
- [ ] cargo clippy = 0
- [ ] test X passes
- [ ] evidence in .trinity/experience/
validations:
required: true

- type: textarea
id: evidence_required
attributes:
label: Evidence to produce
description: What artifacts this task will produce
validations:
required: true

- type: input
id: closes
attributes:
label: Closes / Blocks / Relates to
placeholder: "Closes #N, Blocks #M, Relates #K"

- type: input
id: deadline
attributes:
label: Deadline
description: ISO 8601 date or milestone (optional)
placeholder: "2026-04-30"
62 changes: 62 additions & 0 deletions .github/workflows/context-guard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,62 @@
name: Context Guard

on:
pull_request:
branches: [main, develop]

jobs:
guard:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0

- name: Detect context shrinkage
run: |
set -euo pipefail
echo "Checking for context shrinkage (L21 violation)..."
VIOLATION=0
for f in $(git diff --name-only origin/main...HEAD | grep -E 'CONTEXT\.md|TASK\.md|LAWS\.md|CLAUDE\.md|AGENTS\.md'); do
if [ ! -f "$f" ]; then
echo "::warning file=$f::File was deleted. Check if this is intentional."
continue
fi
added=$(git diff origin/main...HEAD --numstat "$f" 2>/dev/null | awk '{print $1}' || echo "0")
removed=$(git diff origin/main...HEAD --numstat "$f" 2>/dev/null | awk '{print $2}' || echo "0")
added=${added:-0}
removed=${removed:-0}
echo " $f: +$added -$removed"
if [ "$removed" -gt "$((added + 50))" ]; then
echo "::error file=$f::Context shrinkage detected: -$removed +$added lines. Constitutional violation L21. Add rationale with L16 tag to proceed."
VIOLATION=1
fi
done
if [ "$VIOLATION" -eq 1 ]; then
echo ""
echo "FAIL: Context shrinkage detected. See L21 and L16 in CLAUDE.md."
echo "To override: add 'L16 rationale: <reason>' to your commit message."
exit 1
fi
echo "PASS: No context shrinkage detected."

- name: Check schema-response parity (L22)
run: |
set -euo pipefail
echo "Checking for outputSchema without response.data (L22 violation)..."
VIOLATION=0
# Check BrowserOS tools
for f in $(find . -path '*/tools/git/*.ts' -o -path '*/tools/*.ts' 2>/dev/null | grep -v node_modules); do
if grep -q 'output:' "$f" && grep -q 'z\.object\|outputSchema' "$f"; then
if ! grep -q 'response\.data(' "$f"; then
echo "::error file=$f::Tool has output schema but no response.data() call. L22 violation."
VIOLATION=1
fi
fi
done
if [ "$VIOLATION" -eq 1 ]; then
echo ""
echo "FAIL: Schema-response parity violation. See L22 in CLAUDE.md."
exit 1
fi
echo "PASS: All tools with output schemas call response.data()."
153 changes: 153 additions & 0 deletions .github/workflows/laws-guard.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,153 @@
name: Laws Guard

on:
push:
branches: [main, dev, feat/*, fix/*]
pull_request:
branches: [main, dev]

env:
CARGO_TERM_COLOR: always
RUST_BACKTRACE: 1

jobs:
constitutional-check:
name: Constitutional Enforcement
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4

- name: Check LAWS.md exists
run: |
if [ ! -f LAWS.md ]; then
echo "❌ CONSTITUTIONAL BREACH: LAWS.md missing"
exit 1
fi
echo "✅ LAWS.md exists"

- name: Check §0 SUPREMACY CLAUSE present
run: |
if ! grep -q "SUPREMACY CLAUSE" LAWS.md; then
echo "❌ BREACH: §0 SUPREMACY CLAUSE missing"
exit 1
fi
echo "✅ §0 SUPREMACY CLAUSE present"

- name: Check schema version
run: |
if ! grep -q "LAWS_SCHEMA_VERSION: 2.0" LAWS.md; then
echo "❌ BREACH: LAWS_SCHEMA_VERSION missing or not 2.0"
exit 1
fi
echo "✅ LAWS_SCHEMA_VERSION: 2.0"

- name: Check all 13 sections present (§0-§12)
run: |
SECTIONS=$(grep -cE "^## §[0-9]+" LAWS.md || echo "0")
if [ "$SECTIONS" -ne 13 ]; then
echo "❌ BREACH: Expected 13 sections (§0-§12), found $SECTIONS"
exit 1
fi
echo "✅ All 13 sections present"

- name: L1: No .sh files
run: |
COUNT=$(find . -name "*.sh" ! -path "*/node_modules/*" ! -path "*/.git/*" ! -path "*/target/*" | wc -l)
if [ "$COUNT" -gt 0 ]; then
echo "❌ L1 VIOLATION: $COUNT shell scripts found"
find . -name "*.sh" ! -path "*/node_modules/*" ! -path "*/.git/*" ! -path "*/target/*"
exit 1
fi
echo "✅ L1: No .sh files"

- name: L2: PR closes issue (PR only)
if: github.event_name == 'pull_request'
run: |
if ! echo "${{ github.event.pull_request.body }}" | grep -iE "(Closes|Fixes|Resolves) #[0-9]+"; then
echo "❌ L2 VIOLATION: No 'Closes #N' in PR body"
echo "PR body must reference an issue with 'Closes #N', 'Fixes #N', or 'Resolves #N'"
exit 1
fi
echo "✅ L2: PR closes an issue"

- name: I5: No /extension root directory
run: |
if [ -d "./extension" ]; then
echo "❌ I5 VIOLATION: /extension root directory exists"
echo "Use crates/trios-ext/extension/ instead"
exit 1
fi
echo "✅ I5: No /extension root directory"

- name: Verify LAWS_HASH (if exists)
run: |
if [ -f .trinity/state/LAWS_HASH ]; then
if ! sha256sum --check .trinity/state/LAWS_HASH; then
echo "❌ LAWS_HASH MISMATCH: LAWS.md may have been tampered with"
echo "Run: sha256sum LAWS.md > .trinity/state/LAWS_HASH"
exit 1
fi
echo "✅ LAWS_HASH verified"
else
echo "⚠️ LAWS_HASH not found (first-time setup)"
fi

kingdoms-check:
name: Nine Kingdoms Verification
runs-on: ubuntu-latest
needs: constitutional-check
steps:
- uses: actions/checkout@v4

- name: Install Rust
uses: dtolnay/rust-toolchain@stable
with:
components: clippy

- name: Cache cargo
uses: Swatinem/rust-cache@v2

- name: I1: cargo build
run: |
cargo build --all --workspace
echo "✅ I1: Build passes"

- name: I2: cargo test
run: |
cargo test --all --workspace
echo "✅ I2: Tests pass"

- name: I3: clippy
run: |
cargo clippy --all-targets --all-features -- -D warnings
echo "✅ I3: Clippy clean"

- name: I4: Docs exist
run: |
if [ ! -f README.md ]; then
echo "❌ I4 VIOLATION: README.md missing"
exit 1
fi
echo "✅ I4: README.md exists"

- name: I7: No wasm-unsafe-eval in manifest
run: |
MANIFEST_FILE="crates/trios-ext/extension/manifest.json"
if [ -f "$MANIFEST_FILE" ]; then
if grep -q "wasm-unsafe-eval" "$MANIFEST_FILE" && ! grep -q "\"wasm-unsafe-eval\"" "$MANIFEST_FILE"; then
echo "❌ I7 VIOLATION: unsafe eval not properly declared"
exit 1
fi
fi
echo "✅ I7: wasm-unsafe-eval check passed"

- name: I9: Experience current
run: |
TODAY=$(date +%Y%m%d)
EXPERIENCE_FILE=".trinity/experience/trios_${TODAY}.trinity"
if [ ! -f "$EXPERIENCE_FILE" ]; then
echo "⚠️ I9: Today's experience log not found at $EXPERIENCE_FILE"
echo "This is a warning, not a failure"
else
echo "✅ I9: Experience log current"
fi
Loading