Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
93 commits
Select commit Hold shift + click to select a range
ef96cc9
test(coverage): define bounded trusted uv download retries
seonghobae Aug 5, 2026
a3ba39c
docs(coverage): define trusted uv transient retry boundary
seonghobae Aug 5, 2026
cf37fd1
ci: verify trusted uv retry repair once
seonghobae Aug 5, 2026
4aeefcc
ci: repair trusted uv retry workflow syntax
seonghobae Aug 5, 2026
781d12a
ci: add one-shot trusted uv retry patch helper
seonghobae Aug 5, 2026
43f3e55
ci: run trusted uv retry repair with a standalone helper
seonghobae Aug 5, 2026
61d5f82
ci: exclude one-shot helper from final coverage gate
seonghobae Aug 5, 2026
73dfcc0
fix(coverage): retry transient trusted uv downloads
github-actions[bot] Aug 5, 2026
cba6bd5
ci(pr790): repair transient transport classification
seonghobae Aug 5, 2026
74cf072
test(coverage): narrow trusted uv retries to transient failures
seonghobae Aug 5, 2026
577cbba
ci(pr790): trigger bounded transport repair
seonghobae Aug 5, 2026
7ad1550
ci(pr790): align repair with reviewed RED contracts
seonghobae Aug 5, 2026
be2ba69
ci: export exact PR 790 repair source for verified publication
seonghobae Aug 5, 2026
a32a7ce
ci: expose exact PR 790 source artifact to pull-request verification
seonghobae Aug 5, 2026
5156f66
chore: remove temporary PR 790 export workflow
seonghobae Aug 5, 2026
14d93b0
chore: remove temporary PR 790 repair workflow
seonghobae Aug 5, 2026
bbc3ac0
ci(pr790): add deterministic transport finalizer
seonghobae Aug 5, 2026
620b049
ci: apply test-first PR 790 classifier repair
seonghobae Aug 5, 2026
84d8d44
ci(pr790): finalize reviewed transport repair
seonghobae Aug 5, 2026
26f8efd
fix(pr790): cover explicit timeout classification
seonghobae Aug 5, 2026
9e1c0a6
ci(pr790): remove temporary sources before coverage
seonghobae Aug 5, 2026
61e5181
fix(coverage): classify transient uv transport failures
github-actions[bot] Aug 5, 2026
c68e18a
test(coverage): lock retry documentation to closed policy
seonghobae Aug 5, 2026
e3782bb
docs(coverage): reconcile closed trusted uv retry policy
seonghobae Aug 5, 2026
f532a64
docs(changelog): remove overbroad retry claim
seonghobae Aug 5, 2026
72118df
test(coverage): normalize retry policy Markdown
seonghobae Aug 5, 2026
310b5bc
test(coverage): align retry policy wording
seonghobae Aug 5, 2026
430bf58
test(security): prove Git PATH injection fails closed
seonghobae Aug 5, 2026
fba2742
ci(repair): add bounded trusted Git exact-trigger repair
seonghobae Aug 5, 2026
2df636f
ci(repair): bind trusted Git repair to PR exact head
seonghobae Aug 5, 2026
df0a661
ci(repair): correct exact-head trusted Git commit path
seonghobae Aug 5, 2026
f37a5d3
ci(repair): reconcile workflow-permission boundary
seonghobae Aug 5, 2026
76da923
fix(security): resolve Git outside ambient PATH
github-actions[bot] Aug 5, 2026
12565ca
ci(coverage): gate trusted Git executable regression
seonghobae Aug 5, 2026
fbbe293
ci(repair): remove bounded trusted Git repair workflow
seonghobae Aug 5, 2026
6b30fba
test(ci): require trusted Git contract trigger coverage
seonghobae Aug 5, 2026
9f9ab9b
fix(ci): trigger trusted Git contract quality gate
seonghobae Aug 5, 2026
2135025
test(coverage): reject malformed URL reasons without retry
seonghobae Aug 6, 2026
ddb759a
ci(pr790): add malformed URL error regression
seonghobae Aug 6, 2026
ebbb304
test(coverage): pin malformed URL error failure
github-actions[bot] Aug 6, 2026
f0ac483
test(coverage): reject malformed URL error reasons
seonghobae Aug 6, 2026
baa8b83
test(coverage): consolidate malformed URL error regression
seonghobae Aug 6, 2026
ce00587
test(coverage): remove duplicate malformed URL regression
seonghobae Aug 6, 2026
dfe84d1
test(security): reproduce materializer output path races
seonghobae Aug 6, 2026
e772583
fix(security): pin materializer output descriptors
seonghobae Aug 6, 2026
6db8da2
ci(security): gate descriptor-pinned output regressions
seonghobae Aug 6, 2026
4bcd3eb
docs(security): record descriptor-pinned output contract
seonghobae Aug 6, 2026
2df299a
chore(changelog): record output race remediation
seonghobae Aug 6, 2026
0bc5fbc
test(coverage): exercise output descriptor failure edges
seonghobae Aug 6, 2026
54946dc
test(coverage): lock malformed URLError reason fail-closed
seonghobae Aug 6, 2026
5f8810e
test(coverage): remove duplicate malformed reason contract
seonghobae Aug 6, 2026
c0160e8
test(strix): define semantic non-finding classification
seonghobae Aug 6, 2026
7737460
fix(strix): classify contradictory semantic non-findings
seonghobae Aug 6, 2026
98e3768
test(strix): require classifier before severity handling
seonghobae Aug 6, 2026
168fea2
ci(repair): apply exact-head Strix classifier integration
seonghobae Aug 6, 2026
494266e
chore(ci): stop unsafe Strix gate rewrite
seonghobae Aug 6, 2026
20677d3
revert(security): keep contradictory Strix findings blocking
seonghobae Aug 6, 2026
a8d2de0
revert(test): remove Strix gate-bypass contract
seonghobae Aug 6, 2026
5078301
test(coverage): reject hard links added during pinned writes
seonghobae Aug 7, 2026
12399fe
fix(coverage): revalidate output link count after writes
seonghobae Aug 7, 2026
e6beb71
docs(coverage): record post-write hard-link validation
seonghobae Aug 7, 2026
84c9cea
docs(coverage): define post-write link-count boundary
seonghobae Aug 7, 2026
f97e8eb
docs(uv): pin Python 3.14 urllib reference
seonghobae Aug 7, 2026
a98081a
test(uv): isolate trusted Git executable cache
seonghobae Aug 7, 2026
4ad0111
ci(uv): register retry doctoring regression consistently
seonghobae Aug 7, 2026
1043fcd
test(uv): require retry doctoring in focused quality lists
seonghobae Aug 7, 2026
9604dd2
test(coverage): reject blocking FIFO outputs
seonghobae Aug 7, 2026
8906d00
fix(coverage): reject blocking special-file outputs
seonghobae Aug 7, 2026
98b372d
ci(coverage): gate FIFO output regression
seonghobae Aug 7, 2026
ad029e6
docs(coverage): record non-blocking FIFO boundary
seonghobae Aug 7, 2026
43b9e6e
docs(changelog): record FIFO fail-closed hardening
seonghobae Aug 7, 2026
1f5dc9f
test(coverage): pin FIFO regression in quality contract
seonghobae Aug 7, 2026
5f3185e
test(strix): require complete quality-gate runtime budget
seonghobae Aug 7, 2026
75ef112
fix(strix): budget complete changed-path quality gate
seonghobae Aug 7, 2026
3224ccf
docs(strix): record bounded quality-gate runtime budget
seonghobae Aug 7, 2026
a4f5cab
docs(changelog): record bounded Strix quality budget
seonghobae Aug 7, 2026
5573ba5
chore(coverage): defer Strix fixture timing to prerequisite
seonghobae Aug 7, 2026
0b5cad6
chore(coverage): drop competing Strix budget contract
seonghobae Aug 7, 2026
8679fc4
docs(coverage): defer Strix runtime repair to prerequisite
seonghobae Aug 7, 2026
6d9258c
chore(coverage): restore canonical Strix doctoring
seonghobae Aug 7, 2026
849fafe
docs(changelog): defer Strix fixture repair to prerequisite
seonghobae Aug 7, 2026
1047f0f
docs(coverage): cite NIST 800-218 PW.4.1 uv retry
seonghobae Aug 13, 2026
dcac0ff
fix(coverage): retry trusted-uv HTTP 522 CDN timeouts
seonghobae Aug 13, 2026
82d8306
fix(coverage): accept only bounded relative requirement includes
seonghobae Aug 13, 2026
662be9b
test(coverage): prove nested requirements lock discovery
seonghobae Aug 14, 2026
b275ae2
ci: repair PR 790 nested lock discovery
seonghobae Aug 14, 2026
3c17636
fix(coverage): collect requirements-directory locks
github-actions[bot] Aug 14, 2026
a9585e9
ci: restamp verified trusted-uv repair
seonghobae Aug 14, 2026
4869282
docs: align trusted-uv security boundary
seonghobae Aug 14, 2026
88e6143
test: pin retry policy in operator docs
seonghobae Aug 14, 2026
0c95cb7
docs: align trusted uv retry statuses
seonghobae Aug 14, 2026
4e3ef14
docs: include HTTP 522 retry contract
seonghobae Aug 14, 2026
afad813
fix(strix): constrain test fixture output path
seonghobae Aug 20, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .github/workflows/trusted-uv-materializer-quality-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,7 @@ on:
- "scripts/ci/materialize_base_python_requirements.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_git_executable.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
Expand All @@ -20,6 +21,7 @@ on:
- "scripts/ci/materialize_base_python_requirements.py"
- "tests/conftest.py"
- "tests/test_materialize*.py"
- "tests/test_trusted_git_executable.py"
- "tests/test_trusted_uv*.py"
- "tests/test_uv*.py"
- "tests/test_repository_branch_coverage_*.py"
Expand Down Expand Up @@ -125,9 +127,13 @@ jobs:
python -m coverage erase
python -m coverage run -m pytest \
tests/test_materialize_base_python_requirements.py \
tests/test_materialize_fifo_output_security.py \
tests/test_materialize_output_directory_security.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_git_executable.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_trusted_uv_retry_documentation.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_flat_lock_publication_boundary.py \
tests/test_uv_redirect_and_coverage_contract.py \
Expand All @@ -152,9 +158,13 @@ jobs:
python -m compileall -q \
scripts/ci/materialize_base_python_requirements.py \
tests/test_materialize_base_python_requirements.py \
tests/test_materialize_fifo_output_security.py \
tests/test_materialize_output_directory_security.py \
tests/test_materialize_uv_export_hash_contract.py \
tests/test_trusted_git_executable.py \
tests/test_trusted_uv_download_contract.py \
tests/test_trusted_uv_portability_and_streaming.py \
tests/test_trusted_uv_retry_documentation.py \
tests/test_uv_export_isolation_contract.py \
tests/test_uv_flat_lock_publication_boundary.py \
tests/test_uv_redirect_and_coverage_contract.py \
Expand Down
3 changes: 2 additions & 1 deletion AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,8 @@
<!-- CWL-ENTRY -->
> **Agents: read the master context FIRST.** Before any work, read [`docs/CWL-MASTER-CONTEXT.md`](docs/CWL-MASTER-CONTEXT.md) (mission · naruon-as-platform + inter-component UML · cross-cutting disciplines · conventions · roadmap · current state), the live **GitHub Project #1** <https://github.com/orgs/ContextualWisdomLab/projects/1> (work/roadmap source of truth), the full spec **ContextualWisdomLab/naruon#974**, and operate the Project per [`docs/agent-github-project-protocol.md`](docs/agent-github-project-protocol.md). The repo/Project — not any private agent memory — is the source of truth.

Materialize accepts only exact SHA-256 pins or a bounded relative `-r` include (no `.`/`..`); a lone `--require-hashes` directive is not trust evidence. See [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md).
Materialize accepts only complete exact SHA-256 pins or a bounded two-token `-r`/`--requirement` include. An include target must be a normalized relative POSIX path with no absolute, `.`, `..`, option-like, home-expansion, backslash, URL/scheme, query, fragment, or extra-inline-option form, and it must name either a conventional `requirements.lock`/`requirements*.txt` lock (excluding generated `requirements-*-ci-hashes.txt`) or a direct `.txt` child of a directory named `requirements`. A lone `--require-hashes` directive is not trust evidence. See [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md).
Conflict-scope roots fail closed when the immediate parent directory is a symbolic link.
OriginWeave hourly NVIDIA NIM repair is a thin caller at minute 10. See [`docs/doctoring/originweave-hourly-review-caller.md`](docs/doctoring/originweave-hourly-review-caller.md).
nonnest2 hourly NVIDIA NIM repair is a thin caller at minute 16. See [`docs/doctoring/nonnest2-hourly-review-caller.md`](docs/doctoring/nonnest2-hourly-review-caller.md).
Trusted-uv accepts only the fixed GitHub Releases HTTPS origin and retries HTTP 408, 425, 429, 500, 502, 503, 504, and 522 plus explicitly classified transient DNS, timeout, connection, host, or network failures. TLS, permanent DNS, malformed transport evidence, and every other unclassified failure fail closed. See [`docs/doctoring/trusted-uv-transient-download-retry.md`](docs/doctoring/trusted-uv-transient-download-retry.md).
35 changes: 34 additions & 1 deletion ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,30 @@ Product callers stagger Clearfolio at minute 23, DiskSage at minute 37, and
fast-mlsirm at minute 49. Each caller is read-only, dispatches at most one
repair, and delegates all privileged logic to the same sealed scheduler.

## Trusted uv transient retry

```mermaid
flowchart TD
Get["GET pinned GitHub Releases HTTPS archive"]
Status{"408 / 425 / 429 / 500 / 502 / 503 / 504 / 522 or temporary DNS (EAI_AGAIN), timeout, connection reset/refused/aborted, host/network unreachable?"}
Retry["At most three attempts; discard partial bytes"]
Verify["SHA-256 then versioned executable"]
Fail["Fail closed after one attempt"]

Get --> Status
Status -->|"yes, attempts remain"| Retry
Retry --> Get
Status -->|"yes, exhausted"| Fail
Status -->|"TLS, permanent DNS, 404, malformed, unclassified"| Fail
Status -->|"200 + exact size"| Verify
```

A retry cannot change the origin, follow a redirect, or accept an
unverified payload. Transport evidence is classified before retry: only the
closed HTTP set and explicit temporary DNS, timeout, connection, host, or
network failures receive another attempt; certificate verification, permanent
DNS, malformed exception reasons, and other `OSError` classes fail immediately.

## Control-plane data flow

```mermaid
Expand Down Expand Up @@ -103,6 +127,13 @@ sequenceDiagram
review-agent key schemes stay unchanged.
- Rust remains the psychometric arithmetic owner. Repair never substitutes
Python for scoring math.
- Generated output directories and files are opened descriptor-relative without
following symlinks. Pre-existing destinations use `O_NONBLOCK | O_NOFOLLOW`;
`ENXIO` and every non-regular destination fail closed before mutation. The
writer verifies regular-file type, device/inode identity, and a single link
before writing, synchronizes bytes, then revalidates the same properties after
`fsync` so pathname replacement, symlink, FIFO, and hard-link races cannot be
silently accepted.

## Quality gates

Expand All @@ -123,4 +154,6 @@ trusted `uv` exporter is downloaded from the literal GitHub Releases URL for
- [`docs/doctoring/hourly-nvidia-nim-autofix.md`](docs/doctoring/hourly-nvidia-nim-autofix.md)
— current increment's repair-worker decision and APA 7th citations.
- [`docs/doctoring/fast-mlsirm-hourly-review-caller.md`](docs/doctoring/fast-mlsirm-hourly-review-caller.md)
— product-specific psychometric repair heartbeat and scientific gates.
— product-specific psychometric repair heartbeat and scientific gates.
- [`docs/doctoring/trusted-uv-transient-download-retry.md`](docs/doctoring/trusted-uv-transient-download-retry.md)
— current increment's retry decision and APA 7th citations.
19 changes: 14 additions & 5 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,14 +35,21 @@ Semantic Versioning where the repository publishes a release.

### Fixed

- Parsed `opencode.jsonc` as JSONC (stripping `//` and `/* */` comments outside string literals) in the reasoning-effort guard and its contract tests, instead of raw `json.loads`, which rejected the file the moment it carried its first explanatory comment (added for the `contextual-orchestrator` provider block) with `Expecting property name enclosed in double quotes`. Comment markers inside string values, such as the `$schema` URL, are left untouched.
- Download the pinned `uv` 0.12.1 exporter from the official GitHub Releases URL instead of `releases.astral.sh`, which now returns HTTP 403 and blocks org-wide OpenCode `coverage-evidence`. The SHA-256 pin is unchanged. The opener may follow one hop onto `release-assets.githubusercontent.com` or `objects.githubusercontent.com` and still rejects every other host, userinfo, non-HTTPS scheme, and nondefault port (ContextualWisdomLab/.github#1109).
- Compared the trusted `uv` executable's post-install `--version` output against the real GitHub Releases build's full string, `uv 0.12.1 (x86_64-unknown-linux-gnu)`, instead of the bare `uv 0.12.1` the prior check required; the genuine release binary always prints the target triple, so every installation was failing the pin check immediately after the archive download itself was fixed (ContextualWisdomLab/.github#1109).
- Excluded relative `-r` and `--requirement` referrers from generated flat base-lock publication while retaining bounded include syntax diagnostics and discovering independently complete direct `.txt` children of `requirements` directories.
- Refused a conflict-scope repository root whose immediate parent is a symbolic link, so a swapped parent cannot redirect the canonical worktree after the last-component check (CWE-367).
- Parsed `opencode.jsonc` as JSONC (stripping `//` and `/* */` comments outside string literals) in the reasoning-effort guard and its contract tests, instead of raw `json.loads`, which rejected the file the moment it carried its first explanatory comment (added for the `contextual-orchestrator` provider block) with `Expecting property name enclosed in double quotes`. Comment markers inside string values, such as the `$schema` URL, are left untouched.
- Download the pinned `uv` 0.12.1 exporter from the official GitHub Releases URL instead of `releases.astral.sh`, which now returns HTTP 403 and blocks org-wide OpenCode `coverage-evidence`. The SHA-256 pin is unchanged. The opener may follow one hop onto `release-assets.githubusercontent.com` or `objects.githubusercontent.com` and still rejects every other host, userinfo, non-HTTPS scheme, and nondefault port (ContextualWisdomLab/.github#1109).
- Compared the trusted `uv` executable's post-install `--version` output against the real GitHub Releases build's full string, `uv 0.12.1 (x86_64-unknown-linux-gnu)`, instead of the bare `uv 0.12.1` the prior check required; the genuine release binary always prints the target triple, so every installation was failing the pin check immediately after the archive download itself was fixed (ContextualWisdomLab/.github#1109).
- Excluded relative `-r` and `--requirement` referrers from generated flat base-lock publication while retaining bounded include syntax diagnostics and discovering independently complete direct `.txt` children of `requirements` directories.
- Refused a conflict-scope repository root whose immediate parent is a symbolic link, so a swapped parent cannot redirect the canonical worktree after the last-component check (CWE-367).
- Trusted-uv archive download retries HTTP 522 (CDN connection timed out) with the same closed delay set as 502/504, without widening origin or skipping SHA-256 verification.
- Trusted-uv archive download retries HTTP 522 (CDN connection timed out) with the same closed delay set as 502/504, without widening origin or skipping SHA-256 verification.
- Materialized base Python locks only when every package line is an exact SHA-256 pin or a bounded relative `-r`/`--requirement` include. A lone `--require-hashes` directive, a dotted include such as `./lock.txt`, or `-r other-hashes.txt` no longer enters the trusted build context.
- Bounded the Strix quality self-test's deterministic timeout fixtures to 3-second process and 5-second fake-sleep budgets so exact-head policy evidence completes inside the existing job limit without changing production Strix scanner timeouts, providers, credentials, or review semantics.
- Allowed commas and ASCII parentheses in the bounded Strix changed-file path policy so legal tracked Packrat fixtures can receive exact-head security analysis, while rejecting raw `..` components before normalization and keeping controls, backslashes, whitespace ambiguity, and shell punctuation fail-closed.
- Bound each review-agent invocation key to the wrapper's complete canonical payload, including the base branch and requesting actor; altered fields with a valid-format key now fail before durable-leader election or forwarding, and wrapper write permission is job-scoped.
- Pinned generated Python lock output to no-follow directory and file descriptors, rejected symbolic and multiply linked destinations before mutation, revalidated inode and single-link bindings after synchronized writes, and added deterministic regressions for output-path races, hard links introduced during writes, file swaps, and stalled writes.
- Opened existing generated-lock outputs non-blocking before regular-file validation so attacker-controlled FIFOs and other special entries cannot stall trusted materialization; `ENXIO` now fails closed and a permanent regression is included in the exact-head 100% coverage gate.
- Resolved Git only through the operating system default executable path and rejected missing or relative results before trusted base-lock materialization, preventing pull-request-controlled `PATH` selection.
- Restricted trusted uv retries to HTTP 408/425/429/500/502/503/504 and explicitly classified temporary DNS, timeout, connection, host, or network failures; every retry reuses the immutable request contract and discards failed-attempt bytes, while TLS, permanent DNS, malformed, and unclassified local errors fail after one attempt. The decision record now cites NIST SP 800-218 PW.4.1 so a transient retry cannot change the pinned GitHub origin or accept an unverified payload.
- Bound both trusted-uv quality jobs to `github.event.pull_request.head.sha` and added a permanent two-checkout regression contract so exact-head compatibility, coverage, docstring, and compilation claims cannot silently measure GitHub's generated pull-request merge revision.
- Made Strix treat only a single LiteLLM provider-error line containing NVIDIA NIM context and model-catalog 404 evidence as cross-model fallback evidence, rejecting cross-line signal assembly and provider-like target source literals; moved the public default to Nemotron 3 Super 120B and added a second NVIDIA hosted candidate before GitHub Models without neutralizing reported vulnerabilities.
- Bind reusable scheduler implementation to the validated called-workflow repository, SHA, ref, and file path, and verify the checked-out commit before executing privileged scheduler logic.
Expand Down Expand Up @@ -75,3 +82,5 @@ Semantic Versioning where the repository publishes a release.
- Added fast-mlsirm operational documentation for the hourly RCA loop, psychometric scientific gates, Rust ownership, bounded retry cadence, credential isolation, modular reuse, rollback, and APA 7 references.
- Documented the ordinary and conflict repair write-scope parity, ignored-path and symlink inventory, Git-control-file denial, hook suppression, explicit push destination, RED/GREEN evidence, operator response, and local-versus-protected evidence boundary.
- Documented the review-authentication boundary that excludes autonomous writer control-plane paths from review-derived file authority, its test-first Strix security evidence, exact-head coverage contract, and rollback prohibition.
- Pinned generated Python lock output to no-follow directory and file descriptors, rejected symbolic and multiply linked destinations before mutation, revalidated inode bindings before success, and added deterministic regressions for output-path races, file swaps, and stalled writes.
- Recorded the org control-plane architecture, including the trusted-uv retry boundary, so agents reconstruct the download trust boundary from the repo instead of private memory.
6 changes: 5 additions & 1 deletion CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,8 @@ Details: `README.md` and `PR_GOVERNANCE_AUDIT.md`.
- `docs/` — master context, Project protocol, `org-required-workflow-rollout.md`,
`scorecard-governance.md`, SBOM inventory. Doctoring records live under
`docs/doctoring/`. [`ARCHITECTURE.md`](ARCHITECTURE.md) is the control-plane
diagram for review, hourly NVIDIA NIM repair, and merge trust boundaries.
diagram for review, hourly NVIDIA NIM repair, trusted-uv retry, and merge
trust boundaries.
- `.jules/` — recorded performance (`bolt.md`) and security (`sentinel.md`) learnings from past work
on `scripts/ci/`; worth scanning before optimizing or hardening those scripts.

Expand Down Expand Up @@ -133,3 +134,6 @@ repeatable compile command.
cross-repo references as `owner/repo#num` or full URLs; durable knowledge in the repo/Project, not
private memory; one roadmap phase at a time) are defined in `docs/CWL-MASTER-CONTEXT.md` §7 and
apply here.

Trusted-uv download retries HTTP 522. See
`docs/doctoring/trusted-uv-transient-download-retry.md`.
Loading
Loading