Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
275 changes: 142 additions & 133 deletions .cspell.json

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions .cursor/rules/n-bun.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@ version: '2.1'
"dependencies": "кореневий package.json не повинен містити dependencies — додай у workspace-пакети (bun.mdc)"
}
```

- `bunfig.toml`:

```toml
Expand Down
7 changes: 7 additions & 0 deletions .cursor/rules/n-ga.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ alwaysApply: false
```json
{ "[github-actions-workflow]": { "editor.defaultFormatter": "oxc.oxc-vscode" } }
```

- `git-ai.yml`:

```yaml
Expand Down Expand Up @@ -46,6 +47,7 @@ jobs:
git config --global user.email "github-actions[bot]@users.noreply.github.com"
git-ai ci github run
```

- `clean-ga-workflows.yml`:

```yaml
Expand Down Expand Up @@ -76,6 +78,7 @@ jobs:
save_period: 31
save_min_runs_number: 0
```

- `lint-ga.yml`:

```yaml
Expand Down Expand Up @@ -121,6 +124,7 @@ jobs:
- name: Lint GA
run: bunx n-rules lint ga --no-fix
```

- `zizmor.yml`:

```yaml
Expand All @@ -130,6 +134,7 @@ rules:
policies:
'*': ref-pin
```

- `clean-merged-branch.yml`:

```yaml
Expand Down Expand Up @@ -171,11 +176,13 @@ jobs:
run: |
echo "Deleted branches: ${DELETED_BRANCHES}"
```

- `extensions.json`:

```json
{ "recommendations": ["github.vscode-github-actions"] }
```

- `uses-min-versions`:

```json
Expand Down
2 changes: 2 additions & 0 deletions .cursor/rules/n-js-run.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,7 @@ Rego-пакети, які запускає `npx @7n/rules fix js-run` / `npx @7n
"include": ["src/**/*"]
}
```

- `configmap.yaml`:

```yaml
Expand All @@ -33,6 +34,7 @@ data:
- 'service.name='
- 'service.namespace='
```

- `package.json`:

```json
Expand Down
3 changes: 3 additions & 0 deletions .cursor/rules/n-js.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,7 @@ jobs:
- name: Eslint
run: bunx n-rules lint js --no-fix
```

- `.jscpd.json`:

```json
Expand All @@ -68,13 +69,15 @@ jobs:
"ignore": [".claude/worktrees/**", "**/dist/**", "**/CHANGELOG.md"]
}
```

- `extensions.json`:

```json
{
"recommendations": ["dbaeumer.vscode-eslint", "github.vscode-github-actions", "oxc.oxc-vscode"]
}
```

- `package.json`:

```json
Expand Down
3 changes: 3 additions & 0 deletions .cursor/rules/n-npm-module.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -37,6 +37,7 @@ Rego-пакети (запускаються через `npx @7n/rules fix`):
```json
{ "files": ["types"] }
```

- `npm-publish.yml`:

```yaml
Expand Down Expand Up @@ -90,11 +91,13 @@ jobs:
with:
package: npm/package.json
```

- `package.json`:

```json
{ "workspaces": ["npm"] }
```

- `tsconfig.emit-types.json`:

```json
Expand Down
1 change: 1 addition & 0 deletions .cursor/rules/n-security.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@ jobs:
with:
extra_args: --results=verified,unknown
```

- `package.json`:

```json
Expand Down
8 changes: 8 additions & 0 deletions .cursor/rules/n-text.mdc
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,7 @@ Rego-пакети, що перевіряються через conftest (auto-dis
"[html]": { "editor.defaultFormatter": "oxc.oxc-vscode" }
}
```

- `.oxfmtrc.json`:

```json
Expand All @@ -35,6 +36,7 @@ Rego-пакети, що перевіряються через conftest (auto-dis
"ignorePatterns": ["**/hasura/metadata/**", "**/schema.graphql", "**/auto-imports.d.ts"]
}
```

- `.markdownlint-cli2.jsonc`:

```
Expand All @@ -50,6 +52,7 @@ Rego-пакети, що перевіряються через conftest (auto-dis
}
}
```

- `.cspell.json`:

```json
Expand All @@ -69,6 +72,7 @@ Rego-пакети, що перевіряються через conftest (auto-dis
]
}
```

- `.cspell.json`:

```json
Expand All @@ -78,20 +82,23 @@ Rego-пакети, що перевіряються через conftest (auto-dis
}
}
```

- `.cspell.json`:

```json
{
"import": ["@nitra/cspell-dict"]
}
```

- `extensions.json`:

```json
{
"recommendations": ["DavidAnson.vscode-markdownlint", "oxc.oxc-vscode", "timonwong.shellcheck"]
}
```

- `lint-text.yml`:

```yaml
Expand Down Expand Up @@ -157,6 +164,7 @@ jobs:
- name: Lint text
run: bunx n-rules lint text --no-fix
```

- `package.json`:

```json
Expand Down
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -32,3 +32,6 @@ packages/*/*.node
# Python bytecode (випадкові артефакти, джерел .py у репо немає)
__pycache__/
*.pyc

# PII-мапінг handle → email (operations.md) — ніколи в git
.mt/directory.json
1 change: 1 addition & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
## Захищені директорії

Ніколи не змінюй, не видаляй і не створюй файли у цих директоріях:

- `.worktrees/`

@.cursor/rules/n-adr.mdc
Expand Down
2 changes: 1 addition & 1 deletion crates/agent-protocol/src/docs/envelope.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@ type: Rust Module
title: envelope.rs
resource: crates/agent-protocol/src/envelope.rs
docgen:
crc: 7f5cb0ad
crc: 56f75017
model: openai-codex/gpt-5.4-mini
score: 100
issues: judge:inaccurate:0.99
Expand Down
1 change: 1 addition & 0 deletions crates/agent-protocol/src/docs/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,3 +10,4 @@ resource: crates/agent-protocol/src/
| [envelope.rs](envelope.md) | Rust Module |
| [handshake.rs](handshake.md) | Rust Module |
| [lib.rs](lib.md) | Rust Module |
| [transfers.rs](transfers.md) | Rust Module |
3 changes: 1 addition & 2 deletions crates/agent-protocol/src/docs/lib.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,9 +3,8 @@ type: Rust Module
title: lib.rs
resource: crates/agent-protocol/src/lib.rs
docgen:
crc: 78efc0e6
crc: 4844f2b9
model: openai-codex/gpt-5.4-mini
tier: cloud-min
score: 100
issues: judge:inaccurate:0.97
judgeModel: openai-codex/gpt-5.4-mini
Expand Down
35 changes: 35 additions & 0 deletions crates/agent-protocol/src/docs/transfers.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
---
type: Rust Module
title: transfers.rs
resource: crates/agent-protocol/src/transfers.rs
docgen:
crc: d2fec6bc
model: openai-codex/gpt-5.4-mini
score: 100
issues: judge:inaccurate:0.99
judgeModel: openai-codex/gpt-5.4-mini
---

## Огляд

Файл описує canonical акт transfer ownership у Membership API та його byte-for-byte сумісність із relay через доменний префікс і NUL-роздільник полів. Він потрібен, щоб пристрій поточного owner-а міг підписати цей акт Ed25519, а relay — перевірити підпис проти pubkey пристрою поточного owner-а за тим самим форматом повідомлення. `TransferPayload`, `message`, `sign_transfer`, `verify_transfer` працюють read-only, fail-safe, не кидають винятків назовні й за окремих помилок повертають порожнє значення замість винятку.

## Поведінка

- `TransferPayload` — описує акт передачі ownership між поточним і новим owner для кореневої задачі.
- `message` — формує canonical bytes акта transfer для підпису й перевірки, сумісні з relay.
- `sign_transfer` — створює Ed25519-підпис акта transfer приватним ключем пристрою owner-а.
- `verify_transfer` — перевіряє підпис акта transfer проти public key пристрою та повертає помилку, якщо підпис хибний або має некоректну довжину.

## Публічний API

- TransferPayload — Фіксує акт передачі права власності на кореневу задачу.
- message — Формує канонічні байти акта передачі для підпису й звірки.
- sign_transfer — Підписує акт transfer ключем пристрою власника.
- verify_transfer — Звіряє підпис акта з pubkey пристрою, що ініціював передачу.

## Гарантії поведінки

- Read-only: не виконує операцій запису (ФС/БД).
- Перехоплює помилки і не пропускає винятків назовні (fail-safe).
- За певних помилок повертає порожнє значення (напр. `null`) замість винятку.
19 changes: 19 additions & 0 deletions crates/agent-protocol/src/envelope.rs
Original file line number Diff line number Diff line change
Expand Up @@ -151,6 +151,19 @@ pub enum Event {
AuditPending {
fact_ref: String,
},
/// Ескалація «вгору»: записка власника гілки замовникові вузла
/// (owner-app, спека 260714). `from`/`to` — handles, як у git-файлах
/// (`escalation_NNN.md`); `to_account_id` резолвиться емітером через
/// git-ignored `.mt/directory.json` (PII у стрічку не тече — account_id
/// непрозорий) і потрібен relay для адресного push «потребує уваги».
Escalation {
from: String,
to: String,
#[serde(default, skip_serializing_if = "Option::is_none")]
to_account_id: Option<Uuid>,
/// Шлях записки у теці вузла, напр. `escalation_001.md`.
reason_ref: String,
},
Error {
message: String,
},
Expand Down Expand Up @@ -277,6 +290,12 @@ mod tests {
Event::AuditPending {
fact_ref: "refs/mt/runs/x/fact".into(),
},
Event::Escalation {
from: "olena".into(),
to: "vkozlov".into(),
to_account_id: Some(Uuid::from_u128(6)),
reason_ref: "escalation_001.md".into(),
},
Event::Error {
message: "boom".into(),
},
Expand Down
2 changes: 2 additions & 0 deletions crates/agent-protocol/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -9,13 +9,15 @@
pub mod approvals;
pub mod envelope;
pub mod handshake;
pub mod transfers;

pub use approvals::{
sign_approval, verify_approval, ApprovalError, ApprovalPayload, Signature, SigningKey,
VerifyingKey,
};
pub use envelope::{ClaimInfo, Envelope, Event, Rect};
pub use handshake::{check_protocol_version, ClientHello, ProtocolError, ServerHello, SessionInfo};
pub use transfers::{sign_transfer, verify_transfer, TransferPayload};

/// Поточна версія протоколу подій. v1/v2 — історія scaffold-spec; v3 —
/// проміжний draft без `lang`. Несумісна версія відхиляється на хендшейку
Expand Down
Loading
Loading