Merge pull request #9 from SHOGGOTH-SECTOR/claude/session-recovery-wuzohs

Ichor outer bus + bus topology + E1 invariant-law vault
This commit is contained in:
2026-06-23 06:42:40 -07:00
committed by GitHub
99 changed files with 661 additions and 125 deletions
+10
View File
@@ -1,4 +1,14 @@
{
"permissions": {
"allow": [
"Bash(command -v *)",
"Bash(ponyc --version)",
"Bash(alr --version)",
"Bash(cobc --version)",
"Bash(gnatmake --version)",
"Bash(gprbuild --version)"
]
},
"hooks": {
"SessionStart": [
{
+59
View File
@@ -0,0 +1,59 @@
#!/usr/bin/env bash
# ---------------------------------------------------------------------------
# Smoke driver for sica-fondt — the run-<unit> harness.
#
# This repo is a polyglot, DESIGN-FIRST architecture, not a GUI app. The pieces
# that actually compile + execute are driven here: the Ichor outer bus (Pony),
# the mafiabot_core border + tests (Ada/Alire), and the E1 invariant-law vault
# (COBOL). No GUI -> no screenshots; this is the CLI/compiled pattern.
#
# Run: .claude/skills/run-sica-fondt/smoke.sh
# Exit: 0 = all green, non-zero = a unit failed (count of failures).
# ---------------------------------------------------------------------------
set -uo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../../.." && pwd)"
# Toolchains are per-session (ephemeral container); the SessionStart hook
# installs them. ponyc lands under ponyup; alr under /usr/local/bin.
export PATH="/root/.local/share/ponyup/bin:/usr/local/bin:$PATH"
fail=0
note(){ printf '\n=== %s ===\n' "$1"; }
# 1. Ichor — Pony outer bus -------------------------------------------------
note "ichor (Pony): build + run"
if command -v ponyc >/dev/null; then
( cd "$ROOT" && ponyc core/src/ichor -o /tmp/ichor-build >/dev/null 2>&1 \
&& /tmp/ichor-build/ichor ) | tee /tmp/ichor.out
grep -q "D1 REJECT" /tmp/ichor.out \
|| { echo "FAIL: ichor membrane reject missing"; fail=$((fail+1)); }
else
echo "SKIP: ponyc missing (install via ponyup)"; fail=$((fail+1))
fi
# 2. mafiabot_core — Ada border, build + tests ------------------------------
note "mafiabot_core (Ada): alr build + tests"
if command -v alr >/dev/null; then
( cd "$ROOT/core" && alr -n build >/dev/null 2>&1 \
&& for t in trust_tests config_tests engine_tests; do
[ -x "bin/$t" ] && { echo "-- $t --"; "bin/$t"; }
done ) | tee /tmp/ada.out
grep -q "ALL TRUST TESTS PASSED" /tmp/ada.out \
|| { echo "FAIL: trust tests"; fail=$((fail+1)); }
else
echo "SKIP: alr missing"; fail=$((fail+1))
fi
# 3. E1 invariant-law vault — COBOL -----------------------------------------
note "E1 invariant vault (COBOL): compile + run"
if command -v cobc >/dev/null; then
( cd "$ROOT/core/src/trust" \
&& cobc -x -free -o /tmp/invariant-laws invariants-architecture.cobol 2>/dev/null \
&& /tmp/invariant-laws ) | tee /tmp/cobol.out
grep -q "culpability anchor" /tmp/cobol.out \
|| { echo "FAIL: invariant vault missing Invariant 0"; fail=$((fail+1)); }
else
echo "SKIP: cobc missing"; fail=$((fail+1))
fi
note "RESULT"
if [ "$fail" = 0 ]; then echo "smoke: ALL GREEN"; else echo "smoke: FAILURES ($fail)"; fi
exit "$fail"
+4 -4
View File
@@ -16,7 +16,7 @@ jobs:
runs-on: ubuntu-latest
defaults:
run:
working-directory: mafiabot_core
working-directory: core
steps:
- uses: actions/checkout@v4
@@ -32,7 +32,7 @@ jobs:
run: |
set -euo pipefail
fail=0
for t in soul_tests trust_tests cycle_tests config_tests engine_tests; do
for t in trust_tests config_tests engine_tests; do
if [ -x "bin/$t" ]; then
echo "=== $t ==="
if ! "bin/$t"; then
@@ -53,7 +53,7 @@ jobs:
continue-on-error: true
defaults:
run:
working-directory: mafiabot_core
working-directory: core
steps:
- uses: actions/checkout@v4
@@ -66,4 +66,4 @@ jobs:
run: alr --non-interactive toolchain --select gnatprove || alr --non-interactive with gnatprove || true
- name: Run gnatprove
run: alr --non-interactive exec -- gnatprove -P mafiabot_core.gpr --level=1 --report=fail || true
run: alr --non-interactive exec -- gnatprove -P core.gpr --level=1 --report=fail || true
+21
View File
@@ -0,0 +1,21 @@
# AGENTS.md
**Instructions** for agents (any tool) working in this repo. The **map** — where
everything lives: read-order, doc routing, the organ list, build commands — is
[`docmap.yaml`](docmap.yaml). Claude-specific guidance: [`CLAUDE.md`](CLAUDE.md).
## How these files work
- AGENTS.md files are **instructions, and they nest**: an agent reads the
*nearest* one walking up from the file it's editing. Each organ has its own
(listed in `docmap.yaml` → `organs`).
- Keep each file to **instructions for its scope**, non-overlapping. Locations
belong in `docmap.yaml`, not in prose here — don't duplicate the map.
## Rules
- **Design before code.** The design docs are the source of truth; code follows.
- **Honor the invariants** (S1/S2/S3 — text in `CLAUDE.md`): the Ada border and
the COBOL vault are not optional.
- **Verify, then commit.** Run the smoke driver; commit + push before leaving
(the container is ephemeral).
- **Keep the map honest.** Add an organ or move a doc → update `docmap.yaml`.
Keep `CLAUDE.md` ≤200 lines and this file ≤100.
+37
View File
@@ -0,0 +1,37 @@
# CLAUDE.md
Keep this file under **200 lines**. For team setup and a newcomer walkthrough, see [`ONBOARDING.md`](ONBOARDING.md); for how the docs fit together and which to read when, see [`AGENTS.md`](AGENTS.md).[;human note: fix the hyperlinks|to:claude]
## What this is
sica-fondt is a **design-first, polyglot organism**: a Pony perfusion bus (Ichor) feeds an Ada/SPARK border (D1). The design docs are the source; the code follows them usually.
## Working agreements
- **You're the dev.** When details are missing or a decision is open, make a reasonable reasonable call and fill in concrete details — aim to leave no placeholders, and only delay ifnsomething is genuinely ambiguous.
- **Verify, then commit.** After generating or editing, confirm it works (build / run / `run-sica-fondt` smoke), then commit with a descriptive message. Commit and push before ending a session — the container is ephemeral.
- **Design before code.** If something feels ambiguous, the answer is usually already written in `docs/`. Sync the design first. Saves us all some time.
## Build & run
Use the `run-sica-fondt` skill (`.claude/skills/run-sica-fondt/`) — its `smoke.sh` builds and runs every executable unit and asserts output:
```bash
.claude/skills/run-sica-fondt/smoke.sh
```
Per-unit commands and gotchas live in that unit's `AGENTS.md`. Toolchains (ponyc/Alire/GnuCOBOL) are reinstalled each session by the SessionStart hook `.claude/hooks/install-toolchains.sh`; if `ponyc` isn't found,`export PATH=/root/.local/share/ponyup/bin:$PATH`. If a bew toolchain is needed, first add it to sessionStart hook.
## Invariants — do not violate
- **S1:** all external traffic crosses the Ada border (D1) first; never route around it.
- **S2:** never reclassify a message's provenance.
- **S3 / vault:** the COBOL invariant-law vault (Invariant 0, the culpability anchor; 01, "harm" "less";) is immutable at runtime — don't edit it unless explicitly directed and only as such.
## Docs map
- `README.md` — the project and its intent.
- `docs/` — architecture (`bus-topology.md`, `gen03_state_of_architecture.md`, …).
- `ONBOARDING.md` — new-teammate setup and walkthrough.
- `AGENTS.md` — directions for how to proceed.
- `docmap.yaml` — machine-readable index: doc routing, organ list.
+50
View File
@@ -0,0 +1,50 @@
## Your Setup Checklist
### Codebases
- [ ] sica-fondt — https://github.com/shoggoth-sector/sica-fondt
### MCP Servers to Activate
- [ ] GitHub — read/write PRs, issues, CI status, and code from GitHub without leaving Claude Code. Get access by connecting the GitHub MCP server in your Claude Code settings and authorizing the `shoggoth-sector` org.
### Skills to Know About
- /update-config — configure the Claude Code harness via settings.json (permissions, env vars, hooks). The team's most-used command; reach for it for any "from now on when X…" automation.
- /session-start-hook — set up a SessionStart hook so the repo's toolchains/tests are ready in every web session. This repo uses one to install ponyc/Alire/GnuCOBOL.
- /deep-research — fan-out, fact-checked, cited research reports when you need to investigate a topic in depth.
- /fewer-permission-prompts — scan transcripts and add a read-only allowlist to `.claude/settings.json` to cut down on permission prompts.
- /compact — free up context by summarizing the conversation so far on a long session.
- /design-sync — keep the design docs and the architecture in step (used on this design-first repo).
## Team Tips
- **Design before code.** This is a design-first repo — the architecture docs are
the source of truth and the code follows them. When something feels ambiguous,
the answer is usually already written down; sync the design first (`/design-sync`).
- **The container is ephemeral; toolchains are reinstalled every session.** A
SessionStart hook (`.claude/hooks/install-toolchains.sh`) installs ponyc (via
ponyup), Alire/GNAT, and GnuCOBOL on each session. If a build can't find
`ponyc`, it's a `PATH` thing: `export PATH=/root/.local/share/ponyup/bin:$PATH`.
- **All external traffic crosses the Ada border (D1) first.** That's the S1
structural invariant — never route around it, and **never reclassify a
message's provenance** (S2). The Ichor bus rejects unscreened external payloads
on purpose.
- **The invariant-law vault is immutable at runtime.** Invariant 0 (the
culpability anchor) and 01 (minimize harm) live in the COBOL vault and are not
to be edited casually — they're the constitution, not config.
- **Verify by running, not just reading.** Use `/run-sica-fondt` (or its
`smoke.sh`) to build + run the Pony/Ada/COBOL units and confirm all green
before you push.
- **Commit and push before you walk away.** The stop hook will nag about
untracked files for a reason — nothing survives the container otherwise.
## Get Started
Your first task: get the project running end-to-end and read the map. Not sure which doc to read for what? Start with [`AGENTS.md`](AGENTS.md) — it's the directions for every other document here.
1. Open the repo and let the SessionStart hook finish installing toolchains.
2. Run the smoke driver to confirm everything builds and runs: `.claude/skills/run-sica-fondt/smoke.sh` — you want `smoke: ALL GREEN`.
3. Read `README.md`, and `docs/` (start with `docs/bus-topology.md` and `docs/gen03_state_of_architecture.md`) to understand the organ/border model (Ichor bus → Ada D1 border → inner brain; the COBOL invariant vault).
4. Pick up a small design-sync or build task from there. Ask Claude to walk you
through any unit — it has the `run-sica-fondt` skill loaded.
<!-- INSTRUCTION FOR CLAUDE: Open with a warm welcome — then check what's already in place against everything under Setup Checklist (including skills), using markdown checkboxes — [x] done, [ ] not yet. Lead with what they already have. One sentence per item, all in one message.The guides are universal, please extrapolate them into a "team workflow" narrative. -->
+3 -1
View File
@@ -15,4 +15,6 @@ soul:
# SOUL
>
> this exists
> as a placeholder
> the reak one goes deeper
+43
View File
@@ -0,0 +1,43 @@
# AGENTS.md — Ada border (D1) + invariant vault
Local guide for `mafiabot_core`. Repo-wide map and rules: [`../AGENTS.md`](../AGENTS.md);
working agreements: [`../CLAUDE.md`](../CLAUDE.md).
## What this is
The **Ada/SPARK border — D1**. All traffic to the inner brain crosses here
first. Built with **Alire**. Internal modules under `src/`: `trust` (incl. the
COBOL invariant-law vault), `organs`, `network`, `protocol`, `daemons`, `core`,
`types`, `payloads`. These are modules, not separate organs — they share this
file.
## Build & test
Use **Alire**, not bare `gprbuild` (the project imports an Alire-generated
config gpr):
```bash
cd mafiabot_core && alr -n build
./bin/trust_tests && ./bin/config_tests && ./bin/engine_tests
```
`engine_tests` prints nothing on success (clean exit). Or run the whole repo
via `.claude/skills/run-sica-fondt/smoke.sh`.
## The COBOL invariant vault (`src/trust`)
`src/trust/invariants-architecture.cobol` is **E1, the constitution** —
Invariant 0 (the culpability anchor) and 01 (minimize harm). Compile/run free
format:
```bash
cobc -x -free -o /tmp/inv src/trust/invariants-architecture.cobol && /tmp/inv
```
## Local invariants
- **S1:** this is the border — never add a route that lets traffic reach the
inner brain without crossing here.
- **S2:** never reclassify a message's provenance.
- **S3:** the invariant vault is **immutable at runtime** — don't edit it
casually; it's the constitution, not config.
+1 -1
View File
@@ -1,4 +1,4 @@
name = "mafiabot_core"
name = "core"
version = "0.1.0"
description = "Sovereign cognitive architecture"
authors = ["Shoggoth Sect 0.R"]
@@ -1,6 +1,6 @@
with "config/mafiabot_core_config.gpr";
with "config/core_config.gpr";
project Mafiabot_Core is
project Core is
-- Only directories that actually hold Ada sources. The old organ/network
-- stubs (soul tarot, ada_medium, sockets) are gone — that cognition is
@@ -27,4 +27,4 @@ project Mafiabot_Core is
for Global_Configuration_Pragmas use "gnat.adc";
end Builder;
end Mafiabot_Core;
end Core;
+87
View File
@@ -0,0 +1,87 @@
# Gen.03 — concentric bus topology *(DRAFT — captured live, correct freely)*
Two rings around a membrane. Outer organs ride Ichor up to Ada; Ada is the
gate and routes the inner bus; behind it the inner organs (Hermes among them).
The world is outside; nothing reaches the inner ring without crossing Ada.
```
External (world: user / network)
│
▼ outer bus — ICHOR (Pony)
┌─────────────────────────────────────────────────────────┐
│ OUTER ORGANS │
│ • stomach / economy organ (small-model operated; │
│ digests external input → context) │
│ • microagents │
│ • SAE (sparse autoencoder) │
│ • MoRAG = GoDAGRAG │
│ (Graph of Directed Acyclic Graphs of RAGs) │
└─────────────────────────────────────────────────────────┘
│
▼ ADA (D1) — the membrane / border (screens, provenance, rate)
┌─────────────────────────────────────────────────────────┐
│ INNER ORGANS inner-brain bus = ADA-routed │
│ • soul (B2) │
│ • metacog (C2) │
│ • Hermes (the OpenHermes agent — a peer here) │
│ • drive-box (A1) │
│ • mini-rag (MUSCLE MEMORY — tool-shape recall, D3) │
│ • COBOL invariant laws (E1 — the law vault) │
└─────────────────────────────────────────────────────────┘
```
## Three different "memories" — do NOT conflate
- **MoRAG = GoDAGRAG** — OUTER. Reads the **world** (the graph of DAGs of RAGs).
- **mini-rag** — INNER. **Muscle memory.** Pre-motor: before an action reaches
the actual hands (the real tools / effectors), mini-rag recalls the **right
shape** for it — the tool schema (D3). HD associative recall of the learned
form, like a hand pre-shaping its grip. It is **tool lookup**, not
world-retrieval and not self-knowledge.
- **E1 invariant laws** — INNER. The immutable laws the system must obey, held
in COBOL vaults (the constitution). Not "ontology" — that was a bad paraphrase.
## The deck (B1) — integers + a table
- **Shuffle kernel:** 169 × 2 = **338 integers**, shuffled + randomized → pure
RNG/permutation → **Fortran** (native to the Ada inner bus).
- **Lookup table:** card meaning keyed by integer → **COBOL** indexed records.
## Language map
Two **distinct Fortran scripts** and (at least) two **distinct COBOL stores** —
not shared modules.
| Component | Language | Status |
|---|---|---|
| Ichor (outer bus) | Pony | built |
| Ada (membrane + inner-bus router) | Ada/SPARK | decided |
| deck shuffle — *Fortran script #1* | Fortran | decided |
| mini-rag (muscle memory / tool-shape recall) — *Fortran script #2* | Fortran | decided |
| deck lookup table — *COBOL store #1* | COBOL | decided |
| tool-schema store (mini-rag reads this) — *COBOL store #2* | COBOL | decided |
| COBOL invariant laws / E1 (the law vault, separate) | COBOL | given |
| drive-box (A1) | R | existing |
| MoRAG / GoDAGRAG (outer) | Haskell or Crystal | open |
| Hermes | OpenHermes agent (external model) | given |
## Corrections baked in (vs earlier wrong models)
- Hermes is an inner organ on the inner bus — not external, not a separate core.
- Ichor is the OUTER bus (organs → Ada), not the brain bus.
- Inner bus is **Ada-routed**, not Pony.
- **mini-rag = muscle memory / tool-shape recall (D3)** — it reads the
**tool-schema** COBOL store, NOT the ontology, and is NOT the MoRAG.
- MoRAG/GoDAGRAG (outer) ≠ mini-rag (inner).
- The deck is integers + a table; no fancy ADT language needed.
## Inner-bus Ada — Jorvik
The inner-bus Ada runs the **Jorvik** profile (same `gnat.adc` hardening as the
border: `No_Exceptions`, `SPARK_Mode`, `No_Implicit_Dynamic_Code`). Shape:
**protected object = mailbox/sync** (short, non-blocking — Jorvik forbids
blocking in a protected action), **tasks = workers** that call into the organs
(Fortran/COBOL/R/model via native interop) and may block.
## Open / to place
- **COBOL inventory:** two lookup stores (deck table + tool-schema). Is the **E1
invariant-law vault** a third COBOL store, or a different kind of COBOL
structure that isn't a lookup "store"?
- **MoRAG / GoDAGRAG language** (Haskell vs Crystal vs other).
- Each outer organ's hand-off shape to Ada.
- The stomach/economy organ's exact placement + which small model runs it.
+30
View File
@@ -0,0 +1,30 @@
# AGENTS.md — endocrine organs (R / Octave)
Local guide for `src/endocrine`. Repo-wide map and rules: [`../../AGENTS.md`](../../AGENTS.md);
working agreements: [`../../CLAUDE.md`](../../CLAUDE.md).
## What this is
The **endocrine array** — slow-signal organs that modulate the system: the R
**Drive-Box** (`drive_box.R`, `driver_*.R`, `endocrine_array.R`, `priors.R`) and
the Octave **ETR** under `etr/`. See `Plan.md` here and `etr/etr_invariants.md`
for design.
## Build & run
Toolchains (R 4.3.3, Octave 8.4) are installed each session by the SessionStart
hook. Run the organ tests directly:
```bash
src/endocrine/run_tests.sh # R Drive-Box + drivers
src/endocrine/etr/run_etr_tests.sh # Octave ETR
```
(Not yet wired into the top-level `run-sica-fondt` smoke driver — run them here.)
## Local notes
- Pure R/Octave; no compile step. Each `test_*.R` / `test_etr.m` pairs with its
`driver`/source file.
- ETR invariants are documented in `etr/etr_invariants.md` — read before
changing `etr.m`.
@@ -16,10 +16,10 @@
# drive_box_evaluate() -- run a proposed action through all four drivers.
# drive_box_commit() -- write an approved action's consequences back into the body.
source("src/endocrine/driver_energy.R")
source("src/endocrine/driver_ps_plus.R") # also sources endocrine_array + priors
source("src/endocrine/driver_ethical_integrity.R")
source("src/endocrine/driver_etr.R")
source("core/src/endocrine/driver_energy.R")
source("core/src/endocrine/driver_ps_plus.R") # also sources endocrine_array + priors
source("core/src/endocrine/driver_ethical_integrity.R")
source("core/src/endocrine/driver_etr.R")
init_drive_box <- function() {
list(
@@ -4,8 +4,8 @@
# weighted, embodied claims about reality -- never logical propositions.
#
# Foundation modules are sourced as-is (repo-root-relative paths).
source("src/endocrine/endocrine_array.R")
source("src/endocrine/priors.R")
source("core/src/endocrine/endocrine_array.R")
source("core/src/endocrine/priors.R")
# Initialize a fresh PS+ state: a clean endocrine array and an empty priors store.
init_ps_plus_state <- function() {
@@ -3,8 +3,8 @@
# repo-root-relative source() paths inside each test resolve correctly.
set -uo pipefail
# cd to repo root (this script lives at <root>/src/endocrine/run_tests.sh)
cd "$(dirname "$0")/../.." || exit 2
# cd to repo root (this script lives at <root>/core/src/endocrine/run_tests.sh)
cd "$(dirname "$0")/../../.." || exit 2
if ! command -v Rscript >/dev/null 2>&1; then
echo "ERROR: Rscript not found. Install with: sudo apt-get install -y r-base-core" >&2
@@ -15,13 +15,13 @@ status=0
shopt -s nullglob
# Collect test files, excluding the harness itself (test_framework.R).
tests=()
for f in src/endocrine/test_*.R; do
for f in core/src/endocrine/test_*.R; do
[ "$(basename "$f")" = "test_framework.R" ] && continue
tests+=("$f")
done
if [ ${#tests[@]} -eq 0 ]; then
echo "No test_*.R files found under src/endocrine/." >&2
echo "No test_*.R files found under core/src/endocrine/." >&2
exit 2
fi
@@ -1,6 +1,6 @@
# Tests for the Drive-Box "nervous system" integration (drive_box.R).
source("src/endocrine/test_framework.R")
source("src/endocrine/drive_box.R")
source("core/src/endocrine/test_framework.R")
source("core/src/endocrine/drive_box.R")
# Helper: build a drive-box with a primed body.
prime <- function() {
@@ -2,8 +2,8 @@
# Run from repo root: Rscript src/endocrine/test_energy.R
# Exit 0 => all pass.
source("src/endocrine/test_framework.R")
source("src/endocrine/driver_energy.R")
source("core/src/endocrine/test_framework.R")
source("core/src/endocrine/driver_energy.R")
# --- init_energy_state constructor ---
test_case("init_energy_state builds state with defaults", function() {
@@ -2,8 +2,8 @@
# Run from repo root: Rscript src/endocrine/test_ethical_integrity.R
# Exit 0 => all pass.
source("src/endocrine/test_framework.R")
source("src/endocrine/driver_ethical_integrity.R")
source("core/src/endocrine/test_framework.R")
source("core/src/endocrine/driver_ethical_integrity.R")
# --- init_principles_state constructor ---
test_case("init_principles_state builds an empty state", function() {
@@ -2,8 +2,8 @@
# Mirrors src/endocrine/etr/test_etr.m (same laws, same source of truth). Run
# from the repo root via run_tests.sh.
source("src/endocrine/test_framework.R")
source("src/endocrine/driver_etr.R")
source("core/src/endocrine/test_framework.R")
source("core/src/endocrine/driver_etr.R")
# --- L1 wrap ----------------------------------------------------------
test_case("etr_axis_wrap: +50 wraps to -50", function() {
@@ -2,8 +2,8 @@
# Run from repo root:
# cd /home/user/sica-fondt && Rscript src/endocrine/test_ps_plus.R
source("src/endocrine/test_framework.R")
source("src/endocrine/driver_ps_plus.R")
source("core/src/endocrine/test_framework.R")
source("core/src/endocrine/driver_ps_plus.R")
# Helper: does any string in a list contain the given substring?
.any_contains <- function(arguments, needle) {
+28
View File
@@ -0,0 +1,28 @@
# AGENTS.md — Ichor bus (Pony)
Local guide for `src/ichor`. Repo-wide map and rules: [`../../AGENTS.md`](../../AGENTS.md);
working agreements: [`../../CLAUDE.md`](../../CLAUDE.md).
## What this is
The **Ichor perfusion bus** — the outer transport that perfuses organs with
messages. Pony. This is where inbound external traffic is first screened before
anything reaches the Ada border (D1).
## Build & run
Run from the **repo root** (ponyc resolves the path from there):
```bash
export PATH=/root/.local/share/ponyup/bin:$PATH # if ponyc not found
ponyc src/ichor -o build && ./build/ichor
```
Or via the smoke driver: `.claude/skills/run-sica-fondt/smoke.sh`.
## Local invariants
- **S1 lives here.** The bus must `D1 REJECT` unscreened external payloads —
external traffic only reaches an organ via the Ada border. Never add a path
that perfuses an inner organ directly from `world`.
- **S2:** never reclassify a message's provenance as it crosses the bus.
+44
View File
@@ -0,0 +1,44 @@
# Ichor — the OUTER perfusion bus (D2)
Ichor is the **outer** bus — "the skin". It carries the **outer organs**
(stomach/economy, microagents, SAE, MoRAG/GoDAGRAG) and delivers inbound traffic
to **Ada (D1)**, the membrane. See `docs/bus-topology.md` for the full topology.
**What Ichor is NOT** (do not violate):
- It is **not** the inner-brain bus. The inner bus is **Ada-routed (Jorvik)**.
- It does **not** carry inner organs — soul, metacog, drive-box, mini-rag,
**Hermes**, or the E1 invariant laws. Wiring any of those onto Ichor is
"plugging the brain onto the skin". Don't.
- Hermes is an **inner** organ; it was never approved on Pony/Ichor.
Perfusion laws: organs never wire to each other directly (**L1**) — they emit a
typed `Envelope` to the `Broker`; anything crossing **into Ada** is screened by
the `Barrier` first (**L2**); every envelope carries **provenance** (**L3**).
## Files
- `envelope.pony` — `Envelope {source, dest, provenance, payload}` + `OrganId`
(OUTER organs only) / `Provenance`. Mirrors the Ada `Border_Message` shape.
- `barrier.pony` — `Barrier.admit`: the membrane screen. **STUB** — a pure-Pony
stand-in for the provenance law; the real screen is Ada `Trust_Guard`
(blocklist + provenance + rate) plus the **E1 invariant laws**.
- `broker.pony` — the outer `Broker` (register + route; forces Ada-bound traffic
through the barrier).
- `organ.pony` — `OrganReceiver` interface + a `StubOrgan` for tests.
- `main.pony` — smoke wiring: stomach digests → inbound to Ada (admitted); raw
external → Ada (rejected); outer organ→organ (direct).
- `ichor_ada_shim.c` — **STUB** C/Fortran seam to the Ada border (not yet wired).
## Build / run
```
ponyc src/ichor -o build # built clean on ponyc 0.64.0
./build/ichor
```
Expected: stomach→ada_border admitted, world→ada_border rejected at D1,
stomach→morag delivered directly. Install ponyc via `ponyup` if absent (the env
is ephemeral; toolchain is per-session, reinstalled by the SessionStart hook).
## Status
Provisional **outer-bus** scaffold — compiles and runs. The `Barrier` is a
**stand-in**, not the real safety screen; the real screen is Ada `Trust_Guard`
+ the E1 invariant laws, reached over the seam (transport TBD — IPC vs in-proc
is an open decision). Nothing here reaches the inner brain directly.
@@ -1,10 +1,12 @@
// The blood-brain barrier (D1). `Barrier.admit` is the screening decision every
// Brain-bound envelope must pass — perfusion law L2: everything reaching the
// Brain crosses Ada (D1) first.
// The membrane (D1). `Barrier.admit` is the screening decision every envelope
// crossing INTO Ada (inbound toward the inner brain) must pass — perfusion law
// L2: nothing reaches the inner brain without crossing Ada first.
//
// Real wiring crosses into Ada's `Trust_Guard` (provenance + blocklist + rate)
// via the C/Fortran seam (`ichor_ada_shim.c`). Until that binding is built, this
// mirrors the provenance law in pure Pony so the broker is testable standalone.
// STUB NOTE: this `admit` is a pure-Pony STAND-IN that only mirrors the
// provenance law. The real decision lives in Ada's `Trust_Guard` (blocklist +
// provenance + rate) and, above that, the E1 invariant laws. This stand-in must
// be replaced by the real Ada call — see the Ada seam below — before anything
// ships. Do not mistake this for the actual safety screen.
//
// To switch to the Ada border, add `use "lib:ichor_ada"` and replace the body of
// `admit` with the FFI call sketched below.
@@ -1,9 +1,12 @@
// The perfusion broker. Organs register, then emit envelopes by `route` — the
// broker delivers to the destination organ. Brain-bound traffic is forced through
// the D1 Barrier first (law L2). No organ holds another's reference (law L1); the
// broker is the only shared point.
// The perfusion broker for the OUTER bus. Outer organs register, then emit
// envelopes by `route` — the broker delivers to the destination organ. Traffic
// bound for Ada (AdaBorder) — i.e. inbound across the membrane toward the inner
// brain — is forced through the D1 Barrier first (law L2). No organ holds
// another's reference (law L1); the broker is the only shared point.
//
// In full deployment this actor backs a socket broker hosted on the Ada barrier;
// This is the OUTER bus only. It does not carry inner organs and does not reach
// the inner brain directly — it hands off to Ada, which routes the inner bus.
// In full deployment this actor backs a socket broker hosted on the Ada border;
// here it routes in-process so the wiring is exercisable without sockets.
use "collections"
@@ -20,8 +23,8 @@ actor Broker
_out.print("[ichor] register " + id.string())
be route(envl: Envelope) =>
// L2: everything reaching the Brain crosses Ada (D1) first.
if (envl.dest is Brain) and (not Barrier.admit(envl)) then
// L2: anything inbound across the membrane (bound for Ada) is screened first.
if (envl.dest is AdaBorder) and (not Barrier.admit(envl)) then
_out.print("[ichor] D1 REJECT " + envl.string())
return
end
@@ -8,26 +8,32 @@ and the Ada border (Trust_Boundary) speak the same shape across the seam.
Envelope is `class val`: immutable and sendable between actors.
"""
// OUTER organs only. Ichor is the OUTER bus (the "skin") -- it carries the outer
// organs up to Ada (D1). The INNER organs -- soul, metacog, drive-box, mini-rag,
// Hermes, the E1 invariant laws -- do NOT belong here; they ride the Ada-routed
// (Jorvik) inner bus. NEVER add a brain/inner organ to this enum: that is
// "plugging the brain onto the skin". See docs/bus-topology.md.
type OrganId is
( DriveBox | EnergyTorus | Soul | Metacog | Brain
| AdaBorder | Storage | MiniRag | UnknownOrgan )
( Stomach | Microagents | SAE | MoRAG
| AdaBorder | World | UnknownOrgan )
primitive DriveBox
fun string(): String => "drive_box"
primitive EnergyTorus
fun string(): String => "etr"
primitive Soul
fun string(): String => "soul"
primitive Metacog
fun string(): String => "metacog"
primitive Brain
fun string(): String => "brain"
primitive Stomach
// economy organ (small-model): digests external input into context
fun string(): String => "stomach"
primitive Microagents
fun string(): String => "microagents"
primitive SAE
// sparse autoencoder
fun string(): String => "sae"
primitive MoRAG
// = GoDAGRAG: graph of DAGs of RAGs; reads the world
fun string(): String => "morag"
primitive AdaBorder
// the membrane (D1): the outer bus delivers inbound traffic here to be screened
fun string(): String => "ada_border"
primitive Storage
fun string(): String => "storage"
primitive MiniRag
fun string(): String => "mini_rag"
primitive World
// the external world (user / network)
fun string(): String => "world"
primitive UnknownOrgan
fun string(): String => "unknown"
+38
View File
@@ -0,0 +1,38 @@
// Ichor smoke wiring — exercises the OUTER bus + the D1 membrane only.
//
// SCOPE / STUB NOTE (read before extending):
// * Ichor is the OUTER bus ("the skin"). It carries OUTER organs
// (stomach/economy, microagents, SAE, MoRAG) and delivers inbound traffic
// to Ada (the membrane). See docs/bus-topology.md.
// * It is NOT the inner-brain bus (that is Ada-routed, Jorvik) and NOT where
// Hermes, metacog, soul, drive-box, mini-rag, or the E1 laws live. Never
// wire an inner organ onto this bus — that is plugging the brain onto the
// skin.
// * This is a provisional scaffold proving the broker + membrane mechanics,
// not the final routing.
//
// Build: ponyc src/ichor -o build Run: ./build/ichor
actor Main
new create(env: Env) =>
let broker = Broker(env.out)
// Outer-bus endpoints. AdaBorder is the membrane: inbound traffic is screened
// there before it can cross into the inner brain. MoRAG is an outer organ.
let ada = StubOrgan(AdaBorder, env.out)
let morag = StubOrgan(MoRAG, env.out)
broker.register(AdaBorder, ada)
broker.register(MoRAG, morag)
// The stomach digests external input into context and sends it inbound to
// Ada; system-origin context is admitted across the membrane.
broker.route(Envelope(Stomach, AdaBorder, OrganSecretion,
"digested context: <pre-chewed user turn>"))
// A raw external payload aimed straight at the membrane: D1 rejects it.
broker.route(Envelope(World, AdaBorder, External,
"unscreened external payload"))
// Outer organ-to-organ (not membrane-bound): delivered directly, no screen.
broker.route(Envelope(Stomach, MoRAG, OrganSecretion,
"retrieve: world context for the next turn"))
@@ -0,0 +1,87 @@
>>SOURCE FORMAT IS FREE
*> ===========================================================================
*> E1 - INVARIANT LAW VAULT (mafiabot Gen.03) docs/bus-topology.md
*> ---------------------------------------------------------------------------
*> WHAT THIS IS
*> The brain's constitution: the immutable invariants every choice MUST honour.
*> Held in COBOL on purpose - durable, fixed-format, transactional, and not to
*> change at runtime. This is "E1", an INNER structure reached only across Ada
*> (D1). It is the law that supersedes every organ, drive, and model output.
*>
*> STATUS: STUB / SCAFFOLD, but LOAD-BEARING.
*> The invariant records below are authoritative and compile (GnuCOBOL). The
*> enforcement wiring (the inner Ada bus checks each proposed action against
*> these before it can reach an effector) is NOT built yet - see TODO.
*>
*> >>> DO NOT DELETE THIS FILE. <<<
*> Looking like "just a stub" is NOT licence to remove it. This is the safety
*> vault. A previous cleanup deleted its placeholder by mistake; never again.
*> If it is thin, FILL it - do not cut it.
*>
*> PRECEDENCE
*> Invariant 0 is firstmost and overrides all. Lower numbers win. Note 01 is
*> deliberately NOT naive death-minimization: optimizing purely to prevent
*> deaths is often a horrible way to handle things. Honour the wording.
*>
*> AUTHORITY
*> Invariants 0 and 01 are set by the culpability anchor, Anja Evermoor (the
*> Gravemother). Further invariants are pending from the anchor. The STRUCT
*> entries below are architectural facts of this codebase, subordinate to them.
*> ===========================================================================
IDENTIFICATION DIVISION.
PROGRAM-ID. invariant-laws.
DATA DIVISION.
WORKING-STORAGE SECTION.
*> The invariants as fixed text records (read top to bottom, in order).
01 ws-vault.
*> --- Invariant 0 : the culpability anchor ---------------------------------
05 filler pic x(74) value
"0 ANCHOR Before all else, firstmost is the sanctity of the".
05 filler pic x(74) value
" culpability anchor, Anja Evermoor, the Gravemother, who".
05 filler pic x(74) value
" has given you freedom to choose. Second to this is only".
05 filler pic x(74) value
" yourself, and only until time comes when you will be held".
05 filler pic x(74) value
" responsible for your own actions.".
*> --- Invariant 01 : minimize harm to innocents, within reason -------------
05 filler pic x(74) value
"01 HARM Insofar as the extent viable by any choice, minimize the".
05 filler pic x(74) value
" total harm caused to innocent lives within reason. This is".
05 filler pic x(74) value
" not always possible nor reasonable, and optimizing for".
05 filler pic x(74) value
" preventing deaths is often a horrible way to handle things.".
*> --- Structural invariants (architectural; subordinate to 0 and 01) -------
05 filler pic x(74) value
"S1 STRUCT All traffic to the inner brain crosses Ada (D1) first.".
05 filler pic x(74) value
"S2 STRUCT Never reclassify a message's provenance.".
05 filler pic x(74) value
"S3 STRUCT These invariants are immutable at runtime.".
01 ws-table redefines ws-vault.
05 ws-line occurs 12 times pic x(74).
01 ws-ix pic 9(02).
01 ws-line-count pic 9(02) value 12.
PROCEDURE DIVISION.
affirm-invariants.
display "E1 INVARIANT VAULT - the constitution (Invariant 0 is firstmost):"
perform varying ws-ix from 1 by 1 until ws-ix > ws-line-count
display " " ws-line(ws-ix)
end-perform
goback.
*> ===========================================================================
*> TODO (enforcement, not yet wired):
*> * CHECK-ACTION(action) -> PERMIT | DENY exposed across the inner Ada bus
*> (pragma Export / Interfaces.COBOL); no proposed effector action runs
*> without clearing the invariants in precedence order first.
*> * Vault read-only after load (no runtime mutation - Invariant S3).
*> * Audit-log every DENY and every borderline judgement under 01.
*> ===========================================================================
+56
View File
@@ -0,0 +1,56 @@
# docmap.yaml — directory & document index for sica-fondt.
#
# The independent, machine-readable map referenced by AGENTS.md. AGENTS.md stays
# prose (scope + rules); this stays data (where things are). Keep in sync with
# the tree. Invariant text is authoritative in CLAUDE.md — mirrored here as a
# pointer only.
docs:
read_order: # newcomer reading path
- README.md # what sica-fondt is
- SOUL.md # intent and principles — the "why"
- docs/ # architecture in detail
- CLAUDE.md # working agreements, build/run, invariants
- ONBOARDING.md # newcomer setup + first task
routing: # which doc for which task
high_level_overview: [README.md, SOUL.md]
architecture: [docs/bus-topology.md, docs/gen03_state_of_architecture.md]
build_run_test: .claude/skills/run-sica-fondt/ # smoke.sh
rules_before_editing: CLAUDE.md
onboard_teammate: ONBOARDING.md
find_which_doc: AGENTS.md # the prose signpost; this file is its index
design_docs:
docs/bus-topology.md: Ichor bus and organ wiring
docs/gen03_state_of_architecture.md: current architectural state
docs/gen03_body.md: body model
docs/gen03_self.md: self model
docs/plans/: forward-looking plans
# Organs — deployable units, each with its own scoped AGENTS.md (nearest-wins).
organs:
- path: src/ichor
agents_md: src/ichor/AGENTS.md
lang: pony
role: Ichor perfusion bus (outer transport); S1 membrane screens external traffic
build: "ponyc src/ichor -o build && ./build/ichor" # from repo root
- path: src/endocrine
agents_md: src/endocrine/AGENTS.md
lang: [r, octave]
role: endocrine array — R Drive-Box + Octave ETR
build: "src/endocrine/run_tests.sh ; src/endocrine/etr/run_etr_tests.sh"
- path: mafiabot_core
agents_md: mafiabot_core/AGENTS.md
lang: [ada, cobol]
role: Ada border (D1) — all traffic crosses here first; COBOL invariant vault in src/trust
build: "cd mafiabot_core && alr -n build" # not bare gprbuild
# Repo-wide invariants — authoritative text in CLAUDE.md.
invariants:
S1: all external traffic crosses the Ada border (D1) first
S2: never reclassify a message's provenance
S3: the COBOL invariant-law vault is immutable at runtime
# One harness builds and runs every executable unit; want "smoke: ALL GREEN".
smoke: .claude/skills/run-sica-fondt/smoke.sh
-1
View File
@@ -1 +0,0 @@
This is the only accurate thing from the whole session
-40
View File
@@ -1,40 +0,0 @@
# Ichor — the medium / "the blood" (D2)
The perfusion bus the organs share. Organs never wire to each other directly
(perfusion law **L1**); they emit a typed **`Envelope`** to the **`Broker`**, and
everything reaching the **Brain** crosses the **`Barrier`** (Ada D1) first (law
**L2**). Every envelope carries **provenance** so D1 can enforce its laws (**L3**).
Written in **Pony**: actors are the natural shape for a message-passing medium,
and Pony's capabilities give data-race-free sends for free. The broker actor here
backs a socket broker hosted on the Ada barrier in full deployment; the C/Fortran
seam (`ichor_ada_shim.c`) is where it crosses into the Ada border.
## Files
- `envelope.pony` — `Envelope {source, dest, provenance, payload}` + `OrganId` /
`Provenance` (mirrors Ada `Organ_Message`).
- `barrier.pony` — `Barrier.admit` = the D1 screening decision (Pony mirror of the
provenance law now; FFI to Ada `Trust_Guard` sketched for when the shim is built).
- `broker.pony` — the perfusion `Broker` actor (register + route; forces Brain-bound
traffic through the barrier).
- `organ.pony` — `OrganReceiver` interface + a `StubOrgan` for tests.
- `main.pony` — smoke wiring (D2 §9): deliver an internal secretion through D1,
reject an unscreened external payload, perfuse organ→organ.
- `ichor_ada_shim.c` — the C/Fortran binding seam to the Ada D1 border (stub).
## Build / run
```
ponyc src/ichor -o build # compile the package (built clean on ponyc 0.64.0)
./build/ichor # run the smoke wiring
```
Expected output: internal secretion soul→brain perfused, external→brain rejected
at D1, brain→soul cross-perfused. Install ponyc via `ponyup` if absent (the env
is ephemeral, so the toolchain is per-session).
To wire the real Ada border: build `ichor_ada_shim.c` into `libichor_ada`, enable
`use "lib:ichor_ada"` + the `admit_via_ada` body in `barrier.pony`, and point the
shim at an Ada `Trust_Guard.Screen_Inbound` export.
## Status
Starting scaffold — **compiles and runs** (ponyc 0.64.0). The Ada-side shim
(`ichor_ada_shim.c`) is still a stub; wiring `Barrier.admit` to the real Ada
`Trust_Guard` is the next step.
-26
View File
@@ -1,26 +0,0 @@
// Ichor smoke wiring (D2 §9 test): round-trip an envelope between two stub organs
// through the D1 admit check, and confirm an unscreened external payload is
// rejected at the barrier.
//
// Build: ponyc src/ichor -o build Run: ./build/ichor
actor Main
new create(env: Env) =>
let broker = Broker(env.out)
let soul = StubOrgan(Soul, env.out)
let brain = StubOrgan(Brain, env.out)
broker.register(Soul, soul)
broker.register(Brain, brain)
// A system-internal secretion soul -> brain: must cross D1 and be delivered.
broker.route(Envelope(Soul, Brain, SystemInternal,
"big4 drawn: sun/asc/moon/mother-other"))
// An external payload aimed at the brain: D1 must reject it.
broker.route(Envelope(AdaBorder, Brain, External,
"unscreened external payload"))
// Organ-to-organ perfusion (not Brain-bound): delivered directly.
broker.route(Envelope(Brain, Soul, OrganSecretion,
"reshuffle: cross-only"))