This repository was archived by the owner on Aug 7, 2026. It is now read-only.
RFL-154: cut the operator seam — contracts-only vocabulary, no app-side deps in the spine - #12
Merged
Merged
Conversation
…contracts (RFL-154 T1) Adds `operator_receipts` submodule to helm-module-contracts containing the full 18-type operator-control receipt vocabulary (verbatim from prio-agent-ops/src/lib.rs lines 44–703 + tests 705–990), including all hashing/validation private helpers and OperatorControlError. Adds sha2 = "0.11" dep. prio-agent-ops is untouched; both copies coexist (T3 will prune the source after all consumers repoint). hash logic is byte-identical: both test suites exercise the same determinism assertions and pass green. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ts (RFL-154 T2) Move OperatorControlPreview, OperatorControlPreviewBacking, OperatorReceiptFamilyView, and operator_receipt_families() from workbench-backend/src/views.rs into a new operator_preview submodule. Retargets prio_agent_ops imports to crate::operator_receipts (T1). Adds rustdoc on all public items and 9 unit tests covering backing/label behavior and all four family→record-kind mappings. Transport-pure: no axum import. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…es in helm-module-contracts (RFL-154 T3) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…dule-contracts (RFL-154 T4) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ratorApp dead weight removed (RFL-154 T5a) - Cargo.toml: drop workbench-backend and prio-agent-ops direct deps - src/lib.rs: remove pub-use re-export bridges for both dropped crates; remove OperatorControlModule* aliases (consumers use HelmModuleState etc. from helm-module-contracts directly); import JobReadinessPacket, OperatorControlError, OperatorLedgerEntry, OperatorControlPreview from contracts; remove S generic from OperatorControlModule (no longer meaningful after OperatorApp removal); remove with_store constructor - src/http_api.rs: remove OperatorApp<S> dead field and workbench_backend import; OperatorControlState becomes non-generic; state methods return Result<_, OperatorStateError> (local typed wrapper covering Feed and NotAvailable cases); typed OperatorControlError→ApiError mapper covers all 7 reachable variants exhaustively; api_error_from_storage and api_error_from_kernel removed (no longer reachable from preview handlers) - tests/module_test.rs: repoint vocab imports to helm_module_contracts (operator_receipts + operator_preview); HelmModuleState replaces OperatorControlModuleState alias; generics and config-arg removed - Risk-7 sweep: apps/desktop imports OperatorControlPreview directly from helm_module_contracts::operator_preview (was workbench_backend re-export which T4 removed); helm-module-contracts added to desktop Cargo.toml Gates: cargo test -p helm-operator-control → 13/13 ok + 1 doctest; cargo check --workspace → clean; no direct workbench-backend/prio-agent-ops deps remain (transitive prio-agent-ops via capability-registry is T3-expected) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…jected via typed ShowcaseSeedSource (RFL-154 T5b) - New: helm-module-contracts::showcase_pipeline — ShowcasePipelineInput (moved), SeedSourceError (typed 3-variant enum), ShowcaseSeedSource (async_trait injection contract). Lives in neutral contracts crate so seed-IO layer need not depend on the full spine. - helm-operator-control/pipeline.rs: PipelineRouteState gains `seed_source: Option<Arc<dyn ShowcaseSeedSource>>` + `with_seed_source()` builder; run_pipeline handler uses the injected source (501 when none wired). polars loader functions removed. Re-exports ShowcasePipelineInput/SeedSourceError/ShowcaseSeedSource from contracts for backward-compat import paths. Three new injection-path tests added. - helm-operator-control/Cargo.toml: polars dep removed. - seed-gen/src/showcase_seed.rs (new): both Parquet loaders moved verbatim here; showcase_seed is the seed-IO layer (writes AND reads the Parquet files). Loaders are unused in the binary itself — mounting-app boilerplate, documented with schema mismatch note (event_type vs event_types — pre-existing bug, out of scope). - seed-gen/Cargo.toml: +helm-module-contracts (for ShowcasePipelineInput), +serde_json. DONE_WITH_CONCERNS: polars still appears in `cargo tree -p helm-operator-control` via pre-existing transitive chain (helm-truth-execution → truth-catalog → organism → converge-prism-analytics → polars). polars is not a direct dep of the spine. No mounting app exists in this workspace (dead endpoint). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…abulary (RFL-154 T7) proptest: packet_id determinism, mutation sensitivity, sha256 format, AuthorityEffect::None invariant, serde roundtrips. Negative: exact OperatorControlError variants incl. basis-points boundary. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ers not accessible (RFL-154 T7) Adds the parse-don't-validate compile-fail suite for helm-module-contracts. One case: calling the private `validate_sha256` helper from outside the crate fails to compile (E0603), proving callers must go through `::new()`. trybuild was already a dev-dep; adds harness in tests/trybuild_compile_fail.rs and the stderr snapshot alongside the failing .rs file. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…d + prio_agent_ops not resolvable (RFL-154 T7) Adds compile-fail shim tripwires for the RFL-154 seam cut. Two cases guard that the dropped dep-edges cannot be silently re-introduced: - workbench_backend::views::OperatorControlPreview (now in contracts) - prio_agent_ops::JobReadinessPacket (now in contracts) Both must fail to compile (E0433 — unresolved crate). trybuild added to [dev-dependencies] (workspace-consistent version = "1", features = ["diff"]). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… drift (RFL-154 T7) Adds #[ignore]d soak test: iterates SOAK_ITERS (default 100_000) operator flows via StaticReadinessFeed — each builds packet + ledger entry, asserts packet_id/entry_id/payload_hash are stable, threads the live preview path, and does a mutated-input inequality check every 10 000 iterations. Proof run: SOAK_ITERS=10000 → 10 000 iter in 1.65s (6061 iter/s), no drift. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…_seed now properly exposed (RFL-154 T7) Adds src/lib.rs exposing `pub mod showcase_seed;` so a mounting app can depend on seed-gen as a library. Removes `mod showcase_seed;` from main.rs (the binary no longer re-declares the module) and drops the `#![allow(dead_code)]` lint suppression that was masking the missing lib-target. cargo check -p seed-gen clean, no new #[allow( on branch. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ontrol, Module Map, CHANGELOG Foundation Contracts: adds operator vocabulary row (helm-module-contracts is the canonical import; prio-agent-ops and workbench-backend forbidden). Operator Control Common Module: rewrites ownership section to reflect that operator vocabulary lives in helm-module-contracts, not helm-operator-control; updates import rule accordingly. Module Map: scopes prio-agent-ops to manifest-only; notes Plan-B polars chain absent; adds Seam Contracts section for helm-module-contracts. CHANGELOG: records all RFL-154 T1-T7 changes and additions including soak proof (10 000 iter / 1.65s) and trybuild suites. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Fix 1 (Critical): CHANGELOG line 15 — arena cross-extension-smoke repoint was claimed done; reworded to land-in-T6 language. Fix 2 (Important): helm-module-contracts 0.2.1 → 0.3.0 (three new public modules + sha2 runtime dep = minor surface expansion per semver). CHANGELOG entry added. All in-repo consumers updated, including desktop Cargo.toml. Fix 4 (Important): operator_receipts.rs producer/consumer rustdoc — removes false prio-agent-ops producer claim; names mounting-app readiness-feed impls and helm-operator-control as the module surface. Fix 5 (Minor): showcase_pipeline.rs SeedSourceError doc — rewords "no stringly-typed messages cross the boundary" to accurately describe the typed-signalling / String-detail distinction. Fix 6 (Minor): helm-operator-control lib.rs re-export scope — clarifies receipts/preview are never re-exported; pipeline API types are (they appear in public signatures). Fix 7 (Minor): desktop Cargo.toml — helm-module-contracts is now optional=true and added to the embedded-backend feature list, mirroring workbench-backend. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replaces free functions returning Result<_, String> with:
- ParquetSeedSource { data_dir: PathBuf } implementing ShowcaseSeedSource
- Internal helpers return SeedSourceError directly (no String errors)
- StorageError: file not found / IO failures (pre-existence check before
handing off to polars' lazy pipeline so the variant is never wrong)
- ParseError: column-missing / data failures from polars
- ProspectNotFound: empty result set after prospect_id filter
- load() dispatches via spawn_blocking — polars may internally call
block_on; this keeps it safe to call from any Tokio context
Two unit tests:
- missing_file_yields_storage_error: confirms absent parquet → StorageError
- unknown_prospect_yields_prospect_not_found: minimal in-memory Parquet
fixture; absent prospect_id → ProspectNotFound
async-trait and tokio added to [dependencies]; tempfile to [dev-dependencies].
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_3d41a73c-f538-411e-b3b8-b1a5f83643ac) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Linear: https://linear.app/reflective-labs/issue/RFL-154
Final whole-branch review: with-fixes, all fixes applied (CHANGELOG accuracy, 0.3.0 bump, typed seed-source impl, rustdoc corrections).
🤖 Generated with Claude Code
Note
Medium Risk
Wide import-path and dependency-graph changes across operator-control, workbench, and desktop, plus deterministic ID/hash behavior that many tests now enforce; runtime risk is moderate because authority invariants are preserved but showcase pipeline requires explicit seed wiring.
Overview
RFL-154 recenters Helm operator-control on
helm-module-contracts0.3.0: newoperator_receipts,operator_preview, andshowcase_pipelinemodules own the full receipt vocabulary, live-feed preview views, and seed-injection contracts (withsha2as a direct dep).prio-agent-opsdrops the moved types and stays manifest-only;workbench-backend, desktop Tauri, and other consumers import preview/receipt types from contracts instead ofprio-agent-ops/ local views.helm-operator-controlno longer depends onworkbench-backend,prio-agent-ops, orpolars: HTTP state is feed-only (noOperatorApp/ kernel store generics), errors map fromOperatorControlError, and showcase runs load data throughShowcaseSeedSource(501 when unset). Parquet loading lives inseed-gen’s libraryshowcase_seed.Tests and guards: extensive unit/property/negative coverage on receipts; trybuild cases for private validators and for blocking re-added shim deps; optional soak test for packet→ledger→preview determinism. Changelog and KB architecture docs updated; in-repo
helm-module-contractsreferences bumped to 0.3.0.Reviewed by Cursor Bugbot for commit 298694b. Bugbot is set up for automated code reviews on this repo. Configure here.