Repository navigation
One persona definition for every repository, and the border follow-ups (nxf 6j6v.7k58, 6j6v.dcpd) - #17
Merged
Conversation
… folder, merged per name (nxf 6j6v.7k58) Beside a workspace's own `.nxs-personas/`, every workspace reads the user-level folder `<service home>/personas` — `~/.nexusflow/personas` for the installed suite and an embedding app, `~/.nexusflow-<name>/personas` for a development build. A persona or channel the repository declares hides the user-level one of the same name; everything else is added. - The merge lives in `Definitions::resolve` alone, so the CLI, every `Engine` verb, `nxs prime` and a spawned persona's own `nxc` see one team. Duplicates are judged per folder (naming it); handle form and flow cycles on the merged team. - `DeclarationSource` carries `user_path`, `from_user` and `shadowed`, all off the wire when there is no user-level declaration, so such a machine reads exactly as before (point 8). - `nxc list` / `Engine::directory` stamp `origin: user` per entry and print the account whenever the user-level folder takes part; `nxs prime` says it under "Declarations". - A user-level persona's session start says where its declaration lives: a relative path in a prompt means the repository the session runs in, never the declaration's folder. - The freeze projects the merged catalogue, so it holds for user-level hurdles and prompts; proved by an edit mid-operation. - The readers that loaded the folder directly (thread/search channel policy, list, prime) go through the merged catalogue now. Proved through the real binary: two repositories without a pm file both run the user-level pm, the commission scenario runs on it, a repository file hides it out loud; the live test with real sessions now uses one user-level pm for both repositories (22 s, green). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT
…a stuck handover is stopped, the cooperative depth is written down (nxf 6j6v.dcpd) 1. When the caller's workspace stops trusting the receiver while a border thread is open, the receiver's newest message is unvouched and steers nothing. The caller's coordinator now cancels at once with "the answer arrived from <peer>, a workspace no longer trusted here" and wakes the commissioner, instead of "no sign of life" two hours later. 2. The depth across the border rests on the trusted coordinator's stamp — within the trust model (spec section 4); said where `external` and the depth guard are documented. 3. A peer handover past HANDOVER_WAIT is killed and reaped, so the long-lived service no longer accumulates stuck children. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT
…agment's facade impact The two single-test binaries set HOME by hand, which the source gate every_pinned_home_pins_the_instance refuses: a pinned home without the instance resolves another directory under this repo's .envrc. They now apply nxs_test_support::pinned_home_env() to their own process. The dcpd fragment says `facade: changed` (a behaviour change behind unchanged signatures: an unvouched answer now cancels the border thread). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT
…ly policy reads, named revoked-trust cause, group stop - A build reads a user-level folder only under a NAMED development instance, never the production one, and an unresolvable home or instance means no folder rather than an error (Code #2, #3; Integrity #3, #4). Guard test: a build under the production instance does not see personas planted in the production folder. - An existing but unreadable user-level folder is an error, not a silence (Integrity #5). - `threads show`, `search`, `Engine::thread` and `Engine::search` read the merged channels only (`merged_channels`), so a malformed persona file cannot make a thread unreadable (Code #1). - `nxc prime`, `Engine::prime_as` and `nxs prime --persona` resolve the catalogue once (`prime_with`) (Code #5). - The revoked-trust cancel fires only on an answer not yet served, so a question delivered before the revocation does not cancel; two negative controls, mutation-checked (Test #1, Integrity #7). - A stuck peer handover runs in its own process group, which is killed as a whole and then reaped by polling; the sidecar it started has a group of its own and survives; start-idempotence rests on the admission claim (Code #7, Integrity #6). Test drops the wall-clock assertion and gates `true` on unix (Test #3, #4). - The freeze test now edits a user-level hurdle too (Code #6); loader failing cases for channels, a missing and an unreadable folder, a dangling member (Test #2). - A user-level `external` admits only from workspaces the running repository trusts — tested through the binary and written in the guide (Integrity #2); the guide no longer calls a hiding "never silent" but says where it is shown (Integrity #1, the lock question filed as 6j6v.3mgy). - Stale prose and wraps (Code #4, #9). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT
Member
Author
Mitigation of the review (head 2ec45af)
Local runs: |
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
6j6v.7k58: one definition, many repositories. Every workspace now reads a second declaration folder besides its own
.nxs-personas/: the user-level folder<service home>/personas. The two are merged per name. A repository's own persona or channel hides the user-level one of the same name, and everything else is added. This delivers acceptance point 7 of the slice spec (§6 behaviour).6j6v.dcpd: three follow-ups from the review of PR #14.
externaland the depth guard, in EN and DE.The four open questions from the brief, answered against the code
Engine::definitions,Engine::directory,Engine::prime_asandEngine::persona_primego throughDefinitions::resolve, which merges the two folders.nxc, andnxcresolves the folder by the same rule. Two folders would split the app from its own sessions.Definitions::resolve_with_user_direxists for tests and for callers that have already resolved the folder.knowledge/references inagentsonce a persona moves to the central folder.Declared in:in the persona brief,PersonaBrief::declared_in).a_user_level_declaration_is_frozen_per_operationproves it: an edit made mid-operation reaches the next operation, not the running one.ServiceHome::personas()of the instance. The installed suite reads~/.nexusflow/personas; a build reads one only under a named development instance (~/.nexusflow-x/personas) and never the production folder — enforced, not left to.envrc(after review: CI and a shell without direnv read none; guard test inone_definition_at_the_engine_seam).Behaviour details
DeclarationSource.user_path/from_user/shadowedandPersonaEntry/ChannelEntry.originare left off the wire in that case.primepartition. The whole-file channel rule now spans the merged channels.Proof
two_workspaces_on_one_machine): two repos with no pm file both run the user-level pm, and the border scenario runs on it.nxc list/--jsonname the source. A repo file of the same name hides it, andnxc listandnxs primereport that.--ignored, run locally, 22 s, green): one user-level pm definition for both repos. Beta's knowledge sits inBOARD.mdin beta's repo, and the answer "0.300" reaches alpha's owner.one_definition_many_repositories(8 tests);one_definition_at_the_engine_seam(the Engine seam,$HOMEpinned, its own binary);an_answer_from_a_workspace_no_longer_trusted_cancels_it_with_that_reason, which was red before the fix;wait_or_stopunit tests, including reaping.cargo test -p nexus-chatpassed (116 test binaries), as did the guide tests.After the review (2ec45af)
All findings resolved or declined with reason — see the mitigation comment. Integrity #1 (may a repository hide a gated user-level declaration) is an owner decision: 6j6v.3mgy.
For the reviewer
cargo fmt --check,nexus-chatin full,nxs-guide, the touchednxstest file, and thenxspeers unit tests. Nothing beyond what CI checks needs re-running locally.DeclarationSource,PersonaEntry,ChannelEntryandPersonaBrief. The fragment says so.external:in any app-read repo;🤖 Generated with Claude Code
https://claude.ai/code/session_018Sipejn8YQhKgngxeHpMhT