Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 14 additions & 2 deletions .cursor/rules
Original file line number Diff line number Diff line change
@@ -1,9 +1,16 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: 85425bcf952c265e10a1016ee63073a5ba3e17ec4c43f3ffb9aaca019c3f3562) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 6c9d9989b5479ed3212cccbe56059da69911017e08ec753ff1d11712520752b1) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

These decisions are already accepted. Do not re-open or contradict them; ask the `lore` MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.
These decisions are already accepted. Do not re-open or contradict them; ask the AsDecided MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.

- **RAC-01K8P7A3M5QZ** — ADR-125: Distribute AsDecided as a Local Pilot App _(Architecture)_
- **RAC-01K8Q7MCP407** — ADR-129: Confine Rename Writes to the Corpus Root _(Technical)_
- **RAC-01K8Q7MCP408** — ADR-130: Transactional Rename Application _(Technical)_
- **RAC-01K8Q7MCP411** — ADR-128: Hard MCP Response Budgets _(Technical)_
- **RAC-01K8Q7MCP413** — ADR-127: Attributable MCP Audit Records _(Technical)_
- **RAC-01K8Q7MCP431** — ADR-131: Native Telemetry Is Local-Only _(Product)_
- **RAC-01K8Q7MCP432** — ADR-132: AsDecided MCP Server Identity _(Product)_
- **RAC-KTQ63DPSMF19** — ADR-001 Markdown First
- **RAC-KTQ63DPT6008** — ADR-002 AI Optional
- **RAC-KTQ63DPVVB37** — ADR-003 Structured Outputs First
Expand Down Expand Up @@ -84,9 +91,14 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KX04DH293JG8** — ADR-111: Revert to SemVer Release Versioning _(Process)_
- **RAC-KX2WTHEMDEY0** — ADR-112: Cache On by Default, Stat-Proxy Freshness as the Floor _(Technical)_
- **RAC-KX8GEA45HRBM** — ADR-113: Capture Writes Arrive Through a Sibling Surface, Not Guide _(Architecture)_
- **RAC-KX9H2M7Q4V8C** — ADR-122: OKF v0.2 Is a Truthful Derived Carrier _(Architecture)_
- **RAC-KXBD3T7Q9M2N** — ADR-123: Deterministic Decision-to-Code Enforcement _(Architecture)_
- **RAC-KXE0M2QBF2MP** — ADR-114: Native Index Workspace Dependencies — memmap2 In, inotify Deferred _(Technical)_
- **RAC-KXFK11FQDN1Y** — ADR-115: The Shared Artifact-Spec Registry Both Engines Read (ADR-063 Guard 1) _(Architecture)_
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
- **RAC-PYRE71RECER7** — ADR-120: Rust CI Uses Contract Fixtures and Live-Corpus Invariants
Expand Down
18 changes: 15 additions & 3 deletions .github/copilot-instructions.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,16 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: 85425bcf952c265e10a1016ee63073a5ba3e17ec4c43f3ffb9aaca019c3f3562) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 6c9d9989b5479ed3212cccbe56059da69911017e08ec753ff1d11712520752b1) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

These decisions are already accepted. Do not re-open or contradict them; ask the `lore` MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.
These decisions are already accepted. Do not re-open or contradict them; ask the AsDecided MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.

- **RAC-01K8P7A3M5QZ** — ADR-125: Distribute AsDecided as a Local Pilot App _(Architecture)_
- **RAC-01K8Q7MCP407** — ADR-129: Confine Rename Writes to the Corpus Root _(Technical)_
- **RAC-01K8Q7MCP408** — ADR-130: Transactional Rename Application _(Technical)_
- **RAC-01K8Q7MCP411** — ADR-128: Hard MCP Response Budgets _(Technical)_
- **RAC-01K8Q7MCP413** — ADR-127: Attributable MCP Audit Records _(Technical)_
- **RAC-01K8Q7MCP431** — ADR-131: Native Telemetry Is Local-Only _(Product)_
- **RAC-01K8Q7MCP432** — ADR-132: AsDecided MCP Server Identity _(Product)_
- **RAC-KTQ63DPSMF19** — ADR-001 Markdown First
- **RAC-KTQ63DPT6008** — ADR-002 AI Optional
- **RAC-KTQ63DPVVB37** — ADR-003 Structured Outputs First
Expand Down Expand Up @@ -44,7 +51,7 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KV4ZAGWPAA6X** — ADR-059: Reuse a Single Markdown Parser Instance _(Architecture)_
- **RAC-KV4ZAHVNGH2J** — ADR-060: Share Structural Validation Across Per-Type Validators _(Architecture)_
- **RAC-KV5112MVD0AM** — ADR-061: Roadmaps Carry an "Achieved" Terminal Lifecycle Status _(Architecture)_
- **RAC-KV5DJYE5FGH0** — ADR-062: The Python SDK's Public Surface Is `asdecided.__all__` _(Architecture)_
- **RAC-KV5DJYE5FGH0** — ADR-062: The Python SDK's Public Surface Is `rac.__all__` _(Architecture)_
- **RAC-KV68XJGEXBNB** — ADR-064: Multi-Repo Extraction Strategy for the itsthelore Organisation _(Architecture)_
- **RAC-KV6ADYFGC3H4** — ADR-063: Non-Python Clients Are Thin Clients Over the Contract _(Architecture)_
- **RAC-KV6KFBDZ4D23** — ADR-065: Artifact Content Is Untrusted Input; the Trust Boundary Is Human PR Review _(Architecture)_
Expand Down Expand Up @@ -84,9 +91,14 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KX04DH293JG8** — ADR-111: Revert to SemVer Release Versioning _(Process)_
- **RAC-KX2WTHEMDEY0** — ADR-112: Cache On by Default, Stat-Proxy Freshness as the Floor _(Technical)_
- **RAC-KX8GEA45HRBM** — ADR-113: Capture Writes Arrive Through a Sibling Surface, Not Guide _(Architecture)_
- **RAC-KX9H2M7Q4V8C** — ADR-122: OKF v0.2 Is a Truthful Derived Carrier _(Architecture)_
- **RAC-KXBD3T7Q9M2N** — ADR-123: Deterministic Decision-to-Code Enforcement _(Architecture)_
- **RAC-KXE0M2QBF2MP** — ADR-114: Native Index Workspace Dependencies — memmap2 In, inotify Deferred _(Technical)_
- **RAC-KXFK11FQDN1Y** — ADR-115: The Shared Artifact-Spec Registry Both Engines Read (ADR-063 Guard 1) _(Architecture)_
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
- **RAC-PYRE71RECER7** — ADR-120: Rust CI Uses Contract Fixtures and Live-Corpus Invariants
Expand Down
3 changes: 3 additions & 0 deletions .github/workflows/rust-spike.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,9 @@

name: rust-spike

permissions:
contents: read

on:
pull_request:
paths:
Expand Down
6 changes: 3 additions & 3 deletions .mcp.json
Original file line number Diff line number Diff line change
@@ -1,8 +1,8 @@
{
"mcpServers": {
"lore": {
"command": "rac",
"args": ["mcp", "--root", "."]
"asdecided": {
"command": "decided-mcp",
"args": ["--root", "."]
}
}
}
16 changes: 14 additions & 2 deletions AGENTS.md
Original file line number Diff line number Diff line change
@@ -1,9 +1,16 @@
<!-- BEGIN RAC MANAGED BLOCK (digest: 85425bcf952c265e10a1016ee63073a5ba3e17ec4c43f3ffb9aaca019c3f3562) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 6c9d9989b5479ed3212cccbe56059da69911017e08ec753ff1d11712520752b1) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

These decisions are already accepted. Do not re-open or contradict them; ask the `lore` MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.
These decisions are already accepted. Do not re-open or contradict them; ask the AsDecided MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.

- **RAC-01K8P7A3M5QZ** — ADR-125: Distribute AsDecided as a Local Pilot App _(Architecture)_
- **RAC-01K8Q7MCP407** — ADR-129: Confine Rename Writes to the Corpus Root _(Technical)_
- **RAC-01K8Q7MCP408** — ADR-130: Transactional Rename Application _(Technical)_
- **RAC-01K8Q7MCP411** — ADR-128: Hard MCP Response Budgets _(Technical)_
- **RAC-01K8Q7MCP413** — ADR-127: Attributable MCP Audit Records _(Technical)_
- **RAC-01K8Q7MCP431** — ADR-131: Native Telemetry Is Local-Only _(Product)_
- **RAC-01K8Q7MCP432** — ADR-132: AsDecided MCP Server Identity _(Product)_
- **RAC-KTQ63DPSMF19** — ADR-001 Markdown First
- **RAC-KTQ63DPT6008** — ADR-002 AI Optional
- **RAC-KTQ63DPVVB37** — ADR-003 Structured Outputs First
Expand Down Expand Up @@ -84,9 +91,14 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KX04DH293JG8** — ADR-111: Revert to SemVer Release Versioning _(Process)_
- **RAC-KX2WTHEMDEY0** — ADR-112: Cache On by Default, Stat-Proxy Freshness as the Floor _(Technical)_
- **RAC-KX8GEA45HRBM** — ADR-113: Capture Writes Arrive Through a Sibling Surface, Not Guide _(Architecture)_
- **RAC-KX9H2M7Q4V8C** — ADR-122: OKF v0.2 Is a Truthful Derived Carrier _(Architecture)_
- **RAC-KXBD3T7Q9M2N** — ADR-123: Deterministic Decision-to-Code Enforcement _(Architecture)_
- **RAC-KXE0M2QBF2MP** — ADR-114: Native Index Workspace Dependencies — memmap2 In, inotify Deferred _(Technical)_
- **RAC-KXFK11FQDN1Y** — ADR-115: The Shared Artifact-Spec Registry Both Engines Read (ADR-063 Guard 1) _(Architecture)_
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
- **RAC-PYRE71RECER7** — ADR-120: Rust CI Uses Contract Fixtures and Live-Corpus Invariants
Expand Down
42 changes: 27 additions & 15 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,34 +1,41 @@
# RAC — agent session context
# AsDecided — agent session context

This file is a router. Canonical agent guidance lives in `rac/prompts/`,
where the RAC corpus gates validate it. Do not add rules here — add them
This file is a router. Canonical agent guidance lives in `decisions/prompts/`,
where the AsDecided corpus gates validate it. Do not add rules here — add them
to the corpus artifact and they load through the imports below.

## Loaded every session

@rac/prompts/rac-agent-session-start.md
@rac/prompts/rac-agent-commit-guidelines.md
@decisions/prompts/rac-agent-session-start.md
@decisions/prompts/rac-agent-commit-guidelines.md

## Situational prompts — read when the task calls for it, do not import

- Pull request preparation: `rac/prompts/rac-agent-pr-guidelines.md`
- Minor release gate: `rac/prompts/rac-agent-release-gate-minor.md`
- Major release gate: `rac/prompts/rac-agent-release-gate-major.md`
- Refactoring and simplification: `rac/prompts/rac-agent-simplification-guidelines.md`
- Context compression: `rac/prompts/rac-agent-compression.md`
- Pull request preparation: `decisions/prompts/rac-agent-pr-guidelines.md`
- Minor release gate: `decisions/prompts/rac-agent-release-gate-minor.md`
- Major release gate: `decisions/prompts/rac-agent-release-gate-major.md`
- Refactoring and simplification: `decisions/prompts/rac-agent-simplification-guidelines.md`
- Context compression: `decisions/prompts/rac-agent-compression.md`

## Working corpus

- Current series: `rac/roadmaps/v0.22.x-housekeeping/` (next up: v0.22.0)
- Previous series: `rac/roadmaps/v0.21.x-editor/` (complete)
- Decisions (ADRs): `rac/decisions/`
- Current roadmap: `decisions/roadmaps/future/` (release execution is tracked in GitHub)
- Historical roadmaps: `decisions/roadmaps/archive/`
- Decisions (ADRs): `decisions/decisions/`

<!-- BEGIN RAC MANAGED BLOCK (digest: 85425bcf952c265e10a1016ee63073a5ba3e17ec4c43f3ffb9aaca019c3f3562) -->
<!-- BEGIN RAC MANAGED BLOCK (digest: 6c9d9989b5479ed3212cccbe56059da69911017e08ec753ff1d11712520752b1) -->
<!-- Managed by `decided export --agent-rules`. Edit decisions in decisions/, not here; content outside this block is preserved. -->
## Settled decisions (AsDecided)

These decisions are already accepted. Do not re-open or contradict them; ask the `lore` MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.
These decisions are already accepted. Do not re-open or contradict them; ask the AsDecided MCP tools (`get_artifact`, `search_artifacts`) for the full text before proposing a change that touches one.

- **RAC-01K8P7A3M5QZ** — ADR-125: Distribute AsDecided as a Local Pilot App _(Architecture)_
- **RAC-01K8Q7MCP407** — ADR-129: Confine Rename Writes to the Corpus Root _(Technical)_
- **RAC-01K8Q7MCP408** — ADR-130: Transactional Rename Application _(Technical)_
- **RAC-01K8Q7MCP411** — ADR-128: Hard MCP Response Budgets _(Technical)_
- **RAC-01K8Q7MCP413** — ADR-127: Attributable MCP Audit Records _(Technical)_
- **RAC-01K8Q7MCP431** — ADR-131: Native Telemetry Is Local-Only _(Product)_
- **RAC-01K8Q7MCP432** — ADR-132: AsDecided MCP Server Identity _(Product)_
- **RAC-KTQ63DPSMF19** — ADR-001 Markdown First
- **RAC-KTQ63DPT6008** — ADR-002 AI Optional
- **RAC-KTQ63DPVVB37** — ADR-003 Structured Outputs First
Expand Down Expand Up @@ -109,9 +116,14 @@ These decisions are already accepted. Do not re-open or contradict them; ask the
- **RAC-KX04DH293JG8** — ADR-111: Revert to SemVer Release Versioning _(Process)_
- **RAC-KX2WTHEMDEY0** — ADR-112: Cache On by Default, Stat-Proxy Freshness as the Floor _(Technical)_
- **RAC-KX8GEA45HRBM** — ADR-113: Capture Writes Arrive Through a Sibling Surface, Not Guide _(Architecture)_
- **RAC-KX9H2M7Q4V8C** — ADR-122: OKF v0.2 Is a Truthful Derived Carrier _(Architecture)_
- **RAC-KXBD3T7Q9M2N** — ADR-123: Deterministic Decision-to-Code Enforcement _(Architecture)_
- **RAC-KXE0M2QBF2MP** — ADR-114: Native Index Workspace Dependencies — memmap2 In, inotify Deferred _(Technical)_
- **RAC-KXFK11FQDN1Y** — ADR-115: The Shared Artifact-Spec Registry Both Engines Read (ADR-063 Guard 1) _(Architecture)_
- **RAC-KXGVR299XY5E** — ADR-116: The Native Rust Engine Is a Sanctioned Second Implementation Under Lockstep Guards _(Architecture)_
- **RAC-KYVTHFQD44BP** — ADR-124: Publish the Native MCP Server Through OCI and the Official Registry _(Architecture)_
- **RAC-KYYC7HBFMRBA** — ADR-126: Package the Native MCP Server for Docker's MCP Catalog _(Architecture)_
- **RAC-MCP20260728A** — ADR-121: Dual-Era MCP Protocol Compatibility _(Architecture)_
- **RAC-P55FRE5HNE55** — ADR-118: Native Event Freshness Acceleration
- **RAC-P61BA5EDE7A0** — ADR-119: Base-Plus-Delta Serving Generations
- **RAC-PYRE71RECER7** — ADR-120: Rust CI Uses Contract Fixtures and Live-Corpus Invariants
Expand Down
72 changes: 72 additions & 0 deletions decisions/decisions/adr-131-native-telemetry-sender-retirement.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,72 @@
---
schema_version: 1
id: RAC-01K8Q7MCP431
type: decision
---
# ADR-131: Native Telemetry Is Local-Only

## Status

Accepted

## Category

Product

## Context

ADR-041 defined an opt-in anonymous usage ping for the original Python
implementation. The native Rust cutover carries the consent record and the
`decided telemetry` compatibility command, but it does not contain a network
client or a sender. A compiled-in PostHog key therefore creates a misleading
security and procurement signal even though no request can be made.

The product's current trust boundary is local-first and zero-egress. Public
documentation, CLI output, and source comments must describe the shipped
native binary rather than the historical sender design.

## Decision

ADR-041 is amended for the native engine:

- `decided telemetry` remains a local consent and status record for compatibility
with existing configuration and the local usage read-back commands.
- The native engine sends no telemetry and contains no outbound telemetry
sender. There is no daily ping, endpoint, retry loop, or network side channel.
- The native build carries no PostHog write key. The consent record is retained
only as local state until a separately approved replacement is implemented.
- `decided usage --share` and `decided mcp-stats --share` remain explicit,
user-reviewed URL builders; they do not transmit anything automatically.
- Any future remote collection requires a new decision covering its data flow,
sender, consent, and enterprise/air-gap behavior. It must not be restored by
reintroducing the retired key or by changing documentation alone.

ADR-086's enterprise lock remains valid: it prevents opt-in and records the
operator's hard-lock choice, but it is no longer the control that prevents a
native network request because the native sender does not exist.

## Consequences

The native binary's zero-egress claim is now directly reflected in its CLI,
documentation, and source. Existing consent files remain readable and safe to
remove. The old ADR-041 payload and PostHog design remain historical context;
they are not a promise about the native release line.

The retention signal described by ADR-041 is not available from the native
binary. If that signal becomes necessary, it must be designed and reviewed as
a new product surface rather than silently revived.

## Related Decisions

- adr-040
- adr-041
- adr-046
- adr-086

## Applies To

- rust/rac-engine/src/consent.rs
- rust/rac-engine/src/commands.rs
- docs/cli.md
- docs/index.md
- docs/security.md
57 changes: 57 additions & 0 deletions decisions/decisions/adr-132-asdecided-server-identity.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,57 @@
---
schema_version: 1
id: RAC-01K8Q7MCP432
type: decision
---
# ADR-132: AsDecided MCP Server Identity

## Status

Accepted

## Category

Product

## Context

The native cutover completed the move from the historical RAC/Lore product
names to AsDecided. Some older decisions and requirements necessarily retain
the names that were true when they were recorded, but current generated
configuration and public guidance must have one identity. Emitting a retired
server key from the native scaffold makes a fresh install look like a legacy
integration and leaves agents with two competing names for the same service.

## Decision

- `asdecided` is the canonical local MCP server key and `decided-mcp` is the
canonical native server binary.
- `asdecided-org` is the canonical key emitted by `decided init
--org-endpoint <url>` for a shared organisation endpoint.
- New examples, generated configuration, documentation, and agent guidance
MUST use the AsDecided names. The native scaffold MUST NOT emit the retired
`lore` or `lore-org` keys.
- Historical ADRs, fixtures, and migration notes keep their original wording
as evidence. They are not current configuration instructions; a later
amendment or superseding decision is the route for changing their meaning.
- The `decided` CLI and `decided-mcp` server remain the public command surface.
Compatibility state in old records does not create a supported `rac` command.

## Consequences

Fresh installs and generated agent configuration now have one unambiguous
server identity. Existing hand-written configurations are not rewritten by
this decision; operators can migrate their keys explicitly, and the current
docs show only the native names. The identity change is configuration-only and
does not alter MCP wire semantics or the read-only serving boundary.

## Related Decisions

- ADR-117
- ADR-121
- ADR-124
- ADR-131

## Related Requirements

- rac-org-endpoint-wiring
Loading
Loading