Conversation
Assembled from CHARTER / ARCHITECTURE / STACK / AUDIT plus ADR 0001-0007, so a reader has one document to trust instead of a scattered set whose "ground truth" pointer named superseded architecture. Every ADR decision is stated in the present tense (section 0 decision table) rather than as a delta the reader has to apply. Appendix A keeps the Phase 1-2 process layout as clearly labelled history; Appendix B is a supersession ledger naming each prior statement, where it appears, and the ADR that supersedes it. Links are repo-relative only; no machine-specific absolute paths. Co-authored-by: Cursor <cursoragent@cursor.com>
…dules wasmer/desktop/wasmer.toml only shipped the WASI decide binary and framed publishing as optional. Move it to the repo root and add the browser cdylib as a second module, so one compass/decide package backs both the desktop run and the browser sandbox, and the header no longer describes local run as the primary path. Map wasmer/fixtures at the guest path /wasmer/fixtures so --snapshot behaves the same whether the fixture arrives via --volume or from inside the package. Record package-level digests in wasmer/artifacts/PACKAGE-DIGESTS.json. Both module digests reconcile against SHA256SUMS, keeping the ADR 0005 trust root intact; pins.json and the artifacts themselves are untouched. Validated offline: wasmer package build --check exits 0, the built .webc runs and emits a decide envelope identical to the loose-artifact run, and wasmer_size_budget.py, wasmer_parity.py, and the wasm-related tests stay green. Co-authored-by: Cursor <cursoragent@cursor.com>
…nerator The schema was triplicated with nothing enforcing agreement. All three copies happened to be byte-identical at 7fe7ea11..., so no bytes are changed here; only the enforcement is new. src/compass/schema/model-graph.v1.json stays canonical exactly where it is. Packaging evidence: it is the only copy inside dist/compass_router-0.1.0.tar.gz and the wheel, via [tool.setuptools.package-data]; MANIFEST.in needs no change and nothing had to move. tests/test_schema.py now also asserts the packaged resource resolves to that path, so making schema/ canonical would fail the suite. scripts/sync_schema.py rewrites the two mirrors from canonical, with --check for a read-only drift report (exit 1 on drift, [PASS]/[FAIL] markers for log parsing). The pre-existing test compared parsed JSON, which byte-level drift can pass: reformatting a mirror keeps it semantically equal while the digests diverge, and consumers that pin a digest would then disagree with the wheel. The new test compares sha256 across all three paths. Verified as a negative control — injected a reformat, watched the checksum test fail while the semantic test still passed, repaired with sync_schema.py, re-ran green. tests/test_schema.py: 10 passed. Evidence: test-results/p-consolidation/. Co-authored-by: Cursor <cursoragent@cursor.com>
Publish is blocked by two independently verified conditions: this machine has no Wasmer credential (wasmer whoami reports not logged in, no token in config or environment), and the compass namespace is unclaimed on the registry, so nothing here can create compass/decide. Publishing under a guessed namespace and creating an account were both out of scope, and fabricating a transcript is forbidden by the same rule that governs wasmer/mobile/NOT_RUN.md. wasmer/PUBLISH-NOT_RUN.md follows that file's structure and carries the exact credential and namespace steps required to unblock, plus a pre-publish hygiene finding: both committed .wasm artifacts embed absolute builder paths from the Rust build, which would become public on publish. That predates this branch and its fix moves the digests, so it needs its own change. Stage evidence under test-results/q-wasmer-publish/ covers the registry probe with control queries, manifest validation with negative controls, the reproducible local .webc build and its digest, reconciliation of both embedded modules against SHA256SUMS, and the existing guards still passing. Co-authored-by: Cursor <cursoragent@cursor.com>
…lidation) Log-backed record for todos a1-framework, a2-demote, a3-schema: every claim maps to a command and its output, including the negative control that proves the checksum guard fails on drift. Raw captures are .log.txt per the SDLC constitution, which .gitignore excludes from the repo, so the committed README reproduces their key lines and carries re-run instructions. Records one honest PARTIAL: tests/test_paid_sync.py:: test_manual_compass_bundle_api_stays_free fails in the sibling comPREssOR engine's bundle.py:117, reproduced with this branch's edits stashed. Unrelated to this stage and outside this repo's edit surface per ADR 0002/0003, so it is graded rather than papered over. Part B (Wasmer publish, browser SDK, desktop, mobile) is NOT_RUN here and the cross-cutting proof report is deliberately left to a dedicated validation pass. Co-authored-by: Cursor <cursoragent@cursor.com>
A parallel agent working Part B on this branch amended while a84612f was HEAD, so that commit's message no longer maps to its content. All seven files are byte-identical between a84612f and HEAD, verified per path, so nothing was lost. History left alone rather than rebased, because the other agent was still committing. Co-authored-by: Cursor <cursoragent@cursor.com>
Records what a1/a2/a3 changed, why the canonical schema stayed in src/compass/schema/, and what was deliberately left undone. Co-authored-by: Cursor <cursoragent@cursor.com>
Opt-in registry-by-name is implemented but NOT_RUN until publish. Air-gap wasm remains the fallback; packaged vs loose envelopes match. Co-authored-by: Cursor <cursoragent@cursor.com>
Add worker-src and verified Wasmer registry/CDN origins to CSP without weakening COOP/COEP. Dynamically import the /browser SDK entry, guard on crossOriginIsolated, and keep raw instantiate as the fail-open path. Zone A runs the local compass package plus pinned python/python; registry compass/decide stays NOT_RUN. Co-authored-by: Cursor <cursoragent@cursor.com>
iOS Simulator runs the SHA256SUMS-pinned cdylib through WKWebView and matches Python reason codes (PARTIAL). Android sources exist; the SDK was not present so emulator stays NOT_RUN. Do not claim FULL without a device log. Co-authored-by: Cursor <cursoragent@cursor.com>
Recursive SDLC: converged for the offline/local path after one validation pass. Registry publish and Android remain NOT_RUN. Proof: test-results/PROOF-consolidation-wasmer-20260907.md Co-authored-by: Cursor <cursoragent@cursor.com>
Session note for pushing feat/consolidation-and-wasmer and opening the Wasmer/FRAMEWORK PR stacked on PR #2. Co-authored-by: Cursor <cursoragent@cursor.com>
Modified the recorded timestamp in evidence.json to reflect the latest session date. Updated paths in session-harness.txt to ensure consistency with the new advisory context. Cleaned up README.md by removing outdated entries and clarifying current file descriptions.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Stacked on PR #2 (
feat/docker-browser-challenge). That PR is still open/unmerged, so this PR’s base isfeat/docker-browser-challenge, notmain. The diff is only Part A (docs/schema consolidation) and Part B (Wasmer packaging and hosts). Merge PR #2 first; then retarget or merge this branch.Depends on: #2
Part A — consolidation
docs/FRAMEWORK.md(ground truth inPLANS.md/docs/README.md).PROTOTYPE.mddemoted to HISTORICAL — origin brief; it points atdocs/FRAMEWORK.md.scripts/sync_schema.py --checkplus tests somodel-graph.v1.jsoncannot drift across the three copies.Part B — Wasmer
wasmer.tomlcovering both modules; local.webcpackaging.wasmer login;compassnamespace unclaimed). Seewasmer/PUBLISH-NOT_RUN.md.@wasmer/sdkboot (Zone A): PARTIAL (local guest path evidenced; registrycompass/decideNOT_RUN).run-decide.shprefers local.webc: local packaged run FULL; registry-by-name runtime NOT_RUN.Proof
Log-backed report:
test-results/PROOF-consolidation-wasmer-20260907.mdDefault-venv pytest in that capture: 185 passed, 0 failed. Registry publish and Android remain NOT_RUN — not claimed as shipped.
Test plan
feat/docker-browser-challenge(not the Docker challenge client from PR feat: Docker browser challenge client #2).python -m pytest tests/test_schema.py -vpython scripts/sync_schema.py --checkpython -m pytest(default venv)./wasmer/desktop/run-decide.sh(local.webc)