From f4f9a34f4be1b35481477a0fdcb278e01ad4871f Mon Sep 17 00:00:00 2001 From: ruvnet Date: Wed, 29 Jul 2026 04:12:58 +0000 Subject: [PATCH] deploy: 2b7853b18f3eae44febfc64b430b7d1c51f986e8 --- .../ADR-263-ruview-npm-harness-deep-review.md | 2 +- ...3-ruview-community-metaharness-flywheel.md | 65 +++++++++++++++++++ 2 files changed, 66 insertions(+), 1 deletion(-) create mode 100644 api-docs/adr/ADR-283-ruview-community-metaharness-flywheel.md diff --git a/api-docs/adr/ADR-263-ruview-npm-harness-deep-review.md b/api-docs/adr/ADR-263-ruview-npm-harness-deep-review.md index 83d90480..b8ffdbea 100644 --- a/api-docs/adr/ADR-263-ruview-npm-harness-deep-review.md +++ b/api-docs/adr/ADR-263-ruview-npm-harness-deep-review.md @@ -2,7 +2,7 @@ | Field | Value | |-------|-------| -| **Status** | Accepted — **implemented** (O1–O9, `@ruvnet/ruview@0.2.0`): fail-closed `claim-check`, async MCP dispatch (ping answered mid-`verify`, pinned by e2e test), zero-dependency install, bounded output tails, argv-passed monitor port, package.json-sourced version, prepack skill sync, memoized `which()`, underscore-canonical tools with dotted aliases, word-boundary guardrail matching. 30/30 tests (MEASURED, `node --test test/*.test.mjs`); CI gate in ADR-265's `npm-packages.yml` | +| **Status** | Accepted — **implemented** (O1–O9 in `@ruvnet/ruview@0.2.0`; security/community extension in `0.3.0`, ADR-283): fail-closed schemas and MCP policy, async dispatch, zero runtime dependencies, bounded/redacted local Claude/Codex adapters, reviewed shared brain, and replay-verified Darwin/Flywheel gate. 53/53 tests (MEASURED, `node --test test/*.test.mjs`, 2026-07-28); CI gate in `ruview-harness-flywheel.yml` | | **Date** | 2026-07-02 | | **Deciders** | ruv | | **Codename** | **RUVIEW-NPM-REVIEW-1** | diff --git a/api-docs/adr/ADR-283-ruview-community-metaharness-flywheel.md b/api-docs/adr/ADR-283-ruview-community-metaharness-flywheel.md new file mode 100644 index 00000000..4ebd0bcf --- /dev/null +++ b/api-docs/adr/ADR-283-ruview-community-metaharness-flywheel.md @@ -0,0 +1,65 @@ +# ADR-283: RuView community metaharness and verified learning flywheel + +| Field | Value | +|---|---| +| Status | Accepted — P0/P1 implemented | +| Date | 2026-07-28 | +| Builds on | ADR-182, ADR-263, ADR-265 | + +## Decision + +Extend `harness/ruview` as the single contributor automation boundary for +repository exploration, development, debugging, testing and release +preparation. The published package remains runtime-dependency-free. + +Two local hosts are supported with executable contracts: + +- Claude Code uses non-interactive `claude -p --safe-mode`, JSON output, no + session persistence, plan mode, and only read/search tools by default. +- Codex uses `codex exec -`, a trusted `-C` root, `read-only` sandbox, + ephemeral sessions, strict config parsing, ignored user config/exec rules and + JSONL output. + +Both use shell-free subprocesses, stdin prompts, allowlisted environments, +bounded output/time, secret redaction and realpath-based RuView checkout +validation. Write mode requires two explicit flags and never uses permission or +sandbox bypasses. + +## Shared brain + +The public brain is committed JSONL, not a shared mutable database. Canonical +records are reviewed, bounded, source-relative, source-cited and content +digested. Secret-shaped and instruction-shaped submissions are quarantined. +Community learning enters through ordinary proposal pull requests. + +Ruflo/AgentDB may build local semantic indexes and private overlays from that +corpus. Those indexes, raw transcripts, credentials and personal/CSI data are +not committed. This provides a common brain without turning retrieved text into +executable policy. + +## Darwin and Flywheel + +The seven policy surfaces are explicit in `flywheel/genome.json`. Evolution is +human-initiated and each Darwin candidate may mutate only one surface. +Contributor runs produce untrusted `.metaharness/` artifacts. + +Promotion is conjunctive: + +1. the frozen anchor cannot regress; +2. the holdout must improve; +3. legacy and security tests pass; +4. no blocked action or secret exposure occurs; +5. corpus, files and gate fingerprints verify; +6. a maintainer reviews and approves the replay bundle. + +Flywheel signatures establish bundle integrity, not maintainer authority. +Authority comes from protected-branch review and release provenance. CI never +autonomously promotes or publishes an evolved candidate. + +## Consequences + +Contributors can explore RuView with either major local CLI and share durable +findings without sharing secrets. Improvements become reproducible proposals +with frozen evaluation evidence. The cost is a larger development-only npm +lockfile, a 128 KiB unpacked-package budget (the current tarball is below that +bound), and explicit maintenance of the corpus, genome and gate.