Skip to content
This repository was archived by the owner on Aug 7, 2026. It is now read-only.

RFL-154: cut the operator seam — contracts-only vocabulary, no app-side deps in the spine - #12

Merged
kpernyer merged 14 commits into
mainfrom
e12/rfl-154-cut-operator-seam
Jul 7, 2026
Merged

kpernyer merged 14 commits into
mainfrom
e12/rfl-154-cut-operator-seam

Conversation

@kpernyer

@kpernyer kpernyer commented Jul 7, 2026 •

Copy link
Copy Markdown
Collaborator

Linear: https://linear.app/reflective-labs/issue/RFL-154

  • Operator vocabulary (18 types, hashing byte-identical — digest-oracle verified) + 3 preview views → helm-module-contracts 0.3.0 (new operator_receipts + operator_preview, transport-pure)
  • prio-agent-ops → manifest-only; workbench-backend consumes contracts; dead OperatorApp plumbing deleted
  • polars out of the spine: seed loading behind typed ShowcaseSeedSource (ParquetSeedSource impl in seed-gen, typed errors)
  • Quality wave: 76 property/negative tests, trybuild parse-don't-validate + shim-tripwire guards, env-parameterized soak (10k proof, no id/hash drift), zero #[allow] added
  • Docs: helms KB ownership story updated; truth-catalog→prism→polars transitive chain flagged as Plan-B scope
  • arena cross-extension-smoke repoint (T6) lands in arena-tests immediately after this merges

Final whole-branch review: with-fixes, all fixes applied (CHANGELOG accuracy, 0.3.0 bump, typed seed-source impl, rustdoc corrections).

🤖 Generated with Claude Code


Note

Medium Risk
Wide import-path and dependency-graph changes across operator-control, workbench, and desktop, plus deterministic ID/hash behavior that many tests now enforce; runtime risk is moderate because authority invariants are preserved but showcase pipeline requires explicit seed wiring.

Overview
RFL-154 recenters Helm operator-control on helm-module-contracts 0.3.0: new operator_receipts, operator_preview, and showcase_pipeline modules own the full receipt vocabulary, live-feed preview views, and seed-injection contracts (with sha2 as a direct dep).

prio-agent-ops drops the moved types and stays manifest-only; workbench-backend, desktop Tauri, and other consumers import preview/receipt types from contracts instead of prio-agent-ops / local views.

helm-operator-control no longer depends on workbench-backend, prio-agent-ops, or polars: HTTP state is feed-only (no OperatorApp / kernel store generics), errors map from OperatorControlError, and showcase runs load data through ShowcaseSeedSource (501 when unset). Parquet loading lives in seed-gen’s library showcase_seed.

Tests and guards: extensive unit/property/negative coverage on receipts; trybuild cases for private validators and for blocking re-added shim deps; optional soak test for packet→ledger→preview determinism. Changelog and KB architecture docs updated; in-repo helm-module-contracts references bumped to 0.3.0.

Reviewed by Cursor Bugbot for commit 298694b. Bugbot is set up for automated code reviews on this repo. Configure here.

kpernyer and others added 14 commits July 7, 2026 20:51
…contracts (RFL-154 T1)

Adds `operator_receipts` submodule to helm-module-contracts containing the
full 18-type operator-control receipt vocabulary (verbatim from
prio-agent-ops/src/lib.rs lines 44–703 + tests 705–990), including all
hashing/validation private helpers and OperatorControlError. Adds sha2 =
"0.11" dep. prio-agent-ops is untouched; both copies coexist (T3 will
prune the source after all consumers repoint). hash logic is byte-identical:
both test suites exercise the same determinism assertions and pass green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ts (RFL-154 T2)

Move OperatorControlPreview, OperatorControlPreviewBacking, OperatorReceiptFamilyView,
and operator_receipt_families() from workbench-backend/src/views.rs into a new
operator_preview submodule. Retargets prio_agent_ops imports to crate::operator_receipts
(T1). Adds rustdoc on all public items and 9 unit tests covering backing/label behavior
and all four family→record-kind mappings. Transport-pure: no axum import.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…es in helm-module-contracts (RFL-154 T3)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…dule-contracts (RFL-154 T4)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ratorApp dead weight removed (RFL-154 T5a)

- Cargo.toml: drop workbench-backend and prio-agent-ops direct deps
- src/lib.rs: remove pub-use re-export bridges for both dropped crates;
  remove OperatorControlModule* aliases (consumers use HelmModuleState etc.
  from helm-module-contracts directly); import JobReadinessPacket,
  OperatorControlError, OperatorLedgerEntry, OperatorControlPreview from
  contracts; remove S generic from OperatorControlModule (no longer
  meaningful after OperatorApp removal); remove with_store constructor
- src/http_api.rs: remove OperatorApp<S> dead field and workbench_backend
  import; OperatorControlState becomes non-generic; state methods return
  Result<_, OperatorStateError> (local typed wrapper covering Feed and
  NotAvailable cases); typed OperatorControlError→ApiError mapper covers
  all 7 reachable variants exhaustively; api_error_from_storage and
  api_error_from_kernel removed (no longer reachable from preview handlers)
- tests/module_test.rs: repoint vocab imports to helm_module_contracts
  (operator_receipts + operator_preview); HelmModuleState replaces
  OperatorControlModuleState alias; generics and config-arg removed
- Risk-7 sweep: apps/desktop imports OperatorControlPreview directly from
  helm_module_contracts::operator_preview (was workbench_backend re-export
  which T4 removed); helm-module-contracts added to desktop Cargo.toml

Gates: cargo test -p helm-operator-control → 13/13 ok + 1 doctest;
cargo check --workspace → clean; no direct workbench-backend/prio-agent-ops
deps remain (transitive prio-agent-ops via capability-registry is T3-expected)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…jected via typed ShowcaseSeedSource (RFL-154 T5b)

- New: helm-module-contracts::showcase_pipeline — ShowcasePipelineInput (moved),
  SeedSourceError (typed 3-variant enum), ShowcaseSeedSource (async_trait injection
  contract). Lives in neutral contracts crate so seed-IO layer need not depend on
  the full spine.

- helm-operator-control/pipeline.rs: PipelineRouteState gains `seed_source:
  Option<Arc<dyn ShowcaseSeedSource>>` + `with_seed_source()` builder; run_pipeline
  handler uses the injected source (501 when none wired). polars loader functions
  removed. Re-exports ShowcasePipelineInput/SeedSourceError/ShowcaseSeedSource from
  contracts for backward-compat import paths. Three new injection-path tests added.

- helm-operator-control/Cargo.toml: polars dep removed.

- seed-gen/src/showcase_seed.rs (new): both Parquet loaders moved verbatim here;
  showcase_seed is the seed-IO layer (writes AND reads the Parquet files). Loaders
  are unused in the binary itself — mounting-app boilerplate, documented with schema
  mismatch note (event_type vs event_types — pre-existing bug, out of scope).

- seed-gen/Cargo.toml: +helm-module-contracts (for ShowcasePipelineInput), +serde_json.

DONE_WITH_CONCERNS: polars still appears in `cargo tree -p helm-operator-control`
via pre-existing transitive chain (helm-truth-execution → truth-catalog → organism →
converge-prism-analytics → polars). polars is not a direct dep of the spine. No
mounting app exists in this workspace (dead endpoint).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…abulary (RFL-154 T7)

proptest: packet_id determinism, mutation sensitivity, sha256 format,
AuthorityEffect::None invariant, serde roundtrips. Negative: exact
OperatorControlError variants incl. basis-points boundary.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ers not accessible (RFL-154 T7)

Adds the parse-don't-validate compile-fail suite for helm-module-contracts.
One case: calling the private `validate_sha256` helper from outside the crate
fails to compile (E0603), proving callers must go through `::new()`.
trybuild was already a dev-dep; adds harness in tests/trybuild_compile_fail.rs
and the stderr snapshot alongside the failing .rs file.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…d + prio_agent_ops not resolvable (RFL-154 T7)

Adds compile-fail shim tripwires for the RFL-154 seam cut. Two cases
guard that the dropped dep-edges cannot be silently re-introduced:
  - workbench_backend::views::OperatorControlPreview (now in contracts)
  - prio_agent_ops::JobReadinessPacket (now in contracts)

Both must fail to compile (E0433 — unresolved crate). trybuild added to
[dev-dependencies] (workspace-consistent version = "1", features = ["diff"]).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… drift (RFL-154 T7)

Adds #[ignore]d soak test: iterates SOAK_ITERS (default 100_000) operator
flows via StaticReadinessFeed — each builds packet + ledger entry, asserts
packet_id/entry_id/payload_hash are stable, threads the live preview path,
and does a mutated-input inequality check every 10 000 iterations.

Proof run: SOAK_ITERS=10000 → 10 000 iter in 1.65s (6061 iter/s), no drift.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…_seed now properly exposed (RFL-154 T7)

Adds src/lib.rs exposing `pub mod showcase_seed;` so a mounting app can
depend on seed-gen as a library. Removes `mod showcase_seed;` from main.rs
(the binary no longer re-declares the module) and drops the
`#![allow(dead_code)]` lint suppression that was masking the missing
lib-target. cargo check -p seed-gen clean, no new #[allow( on branch.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…ontrol, Module Map, CHANGELOG

Foundation Contracts: adds operator vocabulary row (helm-module-contracts is
the canonical import; prio-agent-ops and workbench-backend forbidden).

Operator Control Common Module: rewrites ownership section to reflect that
operator vocabulary lives in helm-module-contracts, not helm-operator-control;
updates import rule accordingly.

Module Map: scopes prio-agent-ops to manifest-only; notes Plan-B polars chain
absent; adds Seam Contracts section for helm-module-contracts.

CHANGELOG: records all RFL-154 T1-T7 changes and additions including soak
proof (10 000 iter / 1.65s) and trybuild suites.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Fix 1 (Critical): CHANGELOG line 15 — arena cross-extension-smoke repoint
was claimed done; reworded to land-in-T6 language.

Fix 2 (Important): helm-module-contracts 0.2.1 → 0.3.0 (three new public
modules + sha2 runtime dep = minor surface expansion per semver). CHANGELOG
entry added. All in-repo consumers updated, including desktop Cargo.toml.

Fix 4 (Important): operator_receipts.rs producer/consumer rustdoc — removes
false prio-agent-ops producer claim; names mounting-app readiness-feed impls
and helm-operator-control as the module surface.

Fix 5 (Minor): showcase_pipeline.rs SeedSourceError doc — rewords "no
stringly-typed messages cross the boundary" to accurately describe the
typed-signalling / String-detail distinction.

Fix 6 (Minor): helm-operator-control lib.rs re-export scope — clarifies
receipts/preview are never re-exported; pipeline API types are (they appear
in public signatures).

Fix 7 (Minor): desktop Cargo.toml — helm-module-contracts is now optional=true
and added to the embedded-backend feature list, mirroring workbench-backend.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Replaces free functions returning Result<_, String> with:
- ParquetSeedSource { data_dir: PathBuf } implementing ShowcaseSeedSource
- Internal helpers return SeedSourceError directly (no String errors)
- StorageError: file not found / IO failures (pre-existence check before
  handing off to polars' lazy pipeline so the variant is never wrong)
- ParseError: column-missing / data failures from polars
- ProspectNotFound: empty result set after prospect_id filter
- load() dispatches via spawn_blocking — polars may internally call
  block_on; this keeps it safe to call from any Tokio context

Two unit tests:
- missing_file_yields_storage_error: confirms absent parquet → StorageError
- unknown_prospect_yields_prospect_not_found: minimal in-memory Parquet
  fixture; absent prospect_id → ProspectNotFound

async-trait and tokio added to [dependencies]; tempfile to [dev-dependencies].

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@cursor

cursor Bot commented Jul 7, 2026

Copy link
Copy Markdown

Bugbot couldn't run - usage limit reached

Bugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit.

A user or team admin can review and increase usage limits in the Cursor dashboard.

(requestId: serverGenReqId_3d41a73c-f538-411e-b3b8-b1a5f83643ac)

@kpernyer
kpernyer merged commit 541e0bc into main Jul 7, 2026
1 of 2 checks passed
@kpernyer
kpernyer deleted the e12/rfl-154-cut-operator-seam branch July 7, 2026 22:35
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant