Skip to content

feat: FRAMEWORK consolidation and Wasmer hosts - #3

Open
soltrinox wants to merge 15 commits into
feat/docker-browser-challengefrom
feat/consolidation-and-wasmer
Open

soltrinox wants to merge 15 commits into
feat/docker-browser-challengefrom
feat/consolidation-and-wasmer

Conversation

@soltrinox

Copy link
Copy Markdown
Owner

Summary

Stacked on PR #2 (feat/docker-browser-challenge). That PR is still open/unmerged, so this PR’s base is feat/docker-browser-challenge, not main. The diff is only Part A (docs/schema consolidation) and Part B (Wasmer packaging and hosts). Merge PR #2 first; then retarget or merge this branch.

Depends on: #2

Part A — consolidation

  • Canonical framework document: docs/FRAMEWORK.md (ground truth in PLANS.md / docs/README.md).
  • PROTOTYPE.md demoted to HISTORICAL — origin brief; it points at docs/FRAMEWORK.md.
  • Schema checksum guard: scripts/sync_schema.py --check plus tests so model-graph.v1.json cannot drift across the three copies.

Part B — Wasmer

  • Repo-root wasmer.toml covering both modules; local .webc packaging.
  • Registry publish: NOT_RUN (no wasmer login; compass namespace unclaimed). See wasmer/PUBLISH-NOT_RUN.md.
  • Browser @wasmer/sdk boot (Zone A): PARTIAL (local guest path evidenced; registry compass/decide NOT_RUN).
  • Desktop run-decide.sh prefers local .webc: local packaged run FULL; registry-by-name runtime NOT_RUN.
  • iOS Simulator host: PARTIAL (prior WKWebView parity capture).
  • Android: NOT_RUN (no SDK on the validation machine).

Proof

Log-backed report: test-results/PROOF-consolidation-wasmer-20260907.md

Default-venv pytest in that capture: 185 passed, 0 failed. Registry publish and Android remain NOT_RUN — not claimed as shipped.

Test plan

  • Confirm this PR shows only consolidation+Wasmer vs feat/docker-browser-challenge (not the Docker challenge client from PR feat: Docker browser challenge client #2).
  • python -m pytest tests/test_schema.py -v
  • python scripts/sync_schema.py --check
  • python -m pytest (default venv)
  • ./wasmer/desktop/run-decide.sh (local .webc)
  • Do not treat Wasmer registry publish or Android emulator as passing until those environments exist.

soltrinox and others added 15 commits September 7, 2026 20:34
Assembled from CHARTER / ARCHITECTURE / STACK / AUDIT plus ADR 0001-0007, so a
reader has one document to trust instead of a scattered set whose "ground truth"
pointer named superseded architecture.

Every ADR decision is stated in the present tense (section 0 decision table)
rather than as a delta the reader has to apply. Appendix A keeps the Phase 1-2
process layout as clearly labelled history; Appendix B is a supersession ledger
naming each prior statement, where it appears, and the ADR that supersedes it.

Links are repo-relative only; no machine-specific absolute paths.

Co-authored-by: Cursor <cursoragent@cursor.com>
…dules

wasmer/desktop/wasmer.toml only shipped the WASI decide binary and framed
publishing as optional. Move it to the repo root and add the browser cdylib as
a second module, so one compass/decide package backs both the desktop run and
the browser sandbox, and the header no longer describes local run as the
primary path.

Map wasmer/fixtures at the guest path /wasmer/fixtures so --snapshot behaves
the same whether the fixture arrives via --volume or from inside the package.

Record package-level digests in wasmer/artifacts/PACKAGE-DIGESTS.json. Both
module digests reconcile against SHA256SUMS, keeping the ADR 0005 trust root
intact; pins.json and the artifacts themselves are untouched.

Validated offline: wasmer package build --check exits 0, the built .webc runs
and emits a decide envelope identical to the loose-artifact run, and
wasmer_size_budget.py, wasmer_parity.py, and the wasm-related tests stay green.

Co-authored-by: Cursor <cursoragent@cursor.com>
…nerator

The schema was triplicated with nothing enforcing agreement. All three copies
happened to be byte-identical at 7fe7ea11..., so no bytes are changed here; only
the enforcement is new.

src/compass/schema/model-graph.v1.json stays canonical exactly where it is.
Packaging evidence: it is the only copy inside dist/compass_router-0.1.0.tar.gz
and the wheel, via [tool.setuptools.package-data]; MANIFEST.in needs no change
and nothing had to move. tests/test_schema.py now also asserts the packaged
resource resolves to that path, so making schema/ canonical would fail the suite.

scripts/sync_schema.py rewrites the two mirrors from canonical, with --check for
a read-only drift report (exit 1 on drift, [PASS]/[FAIL] markers for log parsing).

The pre-existing test compared parsed JSON, which byte-level drift can pass:
reformatting a mirror keeps it semantically equal while the digests diverge, and
consumers that pin a digest would then disagree with the wheel. The new test
compares sha256 across all three paths. Verified as a negative control — injected
a reformat, watched the checksum test fail while the semantic test still passed,
repaired with sync_schema.py, re-ran green.

tests/test_schema.py: 10 passed. Evidence: test-results/p-consolidation/.

Co-authored-by: Cursor <cursoragent@cursor.com>
Publish is blocked by two independently verified conditions: this machine has
no Wasmer credential (wasmer whoami reports not logged in, no token in config
or environment), and the compass namespace is unclaimed on the registry, so
nothing here can create compass/decide. Publishing under a guessed namespace
and creating an account were both out of scope, and fabricating a transcript is
forbidden by the same rule that governs wasmer/mobile/NOT_RUN.md.

wasmer/PUBLISH-NOT_RUN.md follows that file's structure and carries the exact
credential and namespace steps required to unblock, plus a pre-publish hygiene
finding: both committed .wasm artifacts embed absolute builder paths from the
Rust build, which would become public on publish. That predates this branch and
its fix moves the digests, so it needs its own change.

Stage evidence under test-results/q-wasmer-publish/ covers the registry probe
with control queries, manifest validation with negative controls, the
reproducible local .webc build and its digest, reconciliation of both embedded
modules against SHA256SUMS, and the existing guards still passing.

Co-authored-by: Cursor <cursoragent@cursor.com>
…lidation)

Log-backed record for todos a1-framework, a2-demote, a3-schema: every claim maps
to a command and its output, including the negative control that proves the
checksum guard fails on drift.

Raw captures are .log.txt per the SDLC constitution, which .gitignore excludes
from the repo, so the committed README reproduces their key lines and carries
re-run instructions.

Records one honest PARTIAL: tests/test_paid_sync.py::
test_manual_compass_bundle_api_stays_free fails in the sibling comPREssOR
engine's bundle.py:117, reproduced with this branch's edits stashed. Unrelated to
this stage and outside this repo's edit surface per ADR 0002/0003, so it is
graded rather than papered over.

Part B (Wasmer publish, browser SDK, desktop, mobile) is NOT_RUN here and the
cross-cutting proof report is deliberately left to a dedicated validation pass.

Co-authored-by: Cursor <cursoragent@cursor.com>
A parallel agent working Part B on this branch amended while a84612f was HEAD, so
that commit's message no longer maps to its content. All seven files are
byte-identical between a84612f and HEAD, verified per path, so nothing was lost.
History left alone rather than rebased, because the other agent was still
committing.

Co-authored-by: Cursor <cursoragent@cursor.com>
Records what a1/a2/a3 changed, why the canonical schema stayed in
src/compass/schema/, and what was deliberately left undone.

Co-authored-by: Cursor <cursoragent@cursor.com>
Opt-in registry-by-name is implemented but NOT_RUN until publish.
Air-gap wasm remains the fallback; packaged vs loose envelopes match.

Co-authored-by: Cursor <cursoragent@cursor.com>
Add worker-src and verified Wasmer registry/CDN origins to CSP without
weakening COOP/COEP. Dynamically import the /browser SDK entry, guard on
crossOriginIsolated, and keep raw instantiate as the fail-open path.
Zone A runs the local compass package plus pinned python/python;
registry compass/decide stays NOT_RUN.

Co-authored-by: Cursor <cursoragent@cursor.com>
iOS Simulator runs the SHA256SUMS-pinned cdylib through WKWebView and
matches Python reason codes (PARTIAL). Android sources exist; the SDK
was not present so emulator stays NOT_RUN. Do not claim FULL without a
device log.

Co-authored-by: Cursor <cursoragent@cursor.com>
Recursive SDLC: converged for the offline/local path after one validation pass.
Registry publish and Android remain NOT_RUN. Proof: test-results/PROOF-consolidation-wasmer-20260907.md

Co-authored-by: Cursor <cursoragent@cursor.com>
Session note for pushing feat/consolidation-and-wasmer and opening the Wasmer/FRAMEWORK PR stacked on PR #2.

Co-authored-by: Cursor <cursoragent@cursor.com>
Modified the recorded timestamp in evidence.json to reflect the latest session date. Updated paths in session-harness.txt to ensure consistency with the new advisory context. Cleaned up README.md by removing outdated entries and clarifying current file descriptions.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant