Under TREG_TEST_DB_URL each xdist worker now creates and uses its own
database, so the Postgres job no longer has to run serially. Without it,
every sqlite test process gets its own pid-named file, removed at exit,
so two runs in one checkout no longer wipe each other's tables.
Also move test_orgs_isolation.py and test_orgs_mgmt.py into the Postgres
test list: they had landed inside the failure-diagnostics psql script and
never ran on Postgres.
Daily local runs now match CI (`pytest -n auto` via --with). Two catalog
refresh=True parses and the per-parametrize AST walk in the pool-isolation
guard were paying ~25-30s for no extra coverage. High-confidence tautologies
that only pinned tables living inside the test file are gone; gateway blame
now reads production `_BLAME_BY_KIND`. Visual CSS substring pins on the
dashboard were dropped; trapped-dialog, confirm-slug, masked referrer and
empty platPrice stay.
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
* docs(agents): AGENTS.md is the single guide, contract first, no state snapshots
CLAUDE.md now only imports AGENTS.md so Claude Code, Codex and Cursor read one file.
AGENTS.md is rewritten around what an agent cannot learn from the code:
- Non-negotiables move to the top and are corrected against the code. "Own key
always wins, never metered, never routed or overflowed" is promoted to rule 1.
The relay rule now scopes to plain /call/ and names routed endpoints and
overflow as wrappers, since route.py injects `_treg` into the body and overflow
adds X-Treg-Served-Via; the old wording contradicted both. The hold rule
defines "hold"; the pool rule says why reserve and settle are two transactions;
the ledger rule records that there is deliberately no refund entry.
- The dataplane write allowlist becomes guidance that points at
tests/test_call_architecture.py as the authority instead of a prose copy.
- Enforcement gap inventories, per-file commit lists, contract-by-contract
recaps and the CLI-module list are removed: they duplicate pyproject, the
import-boundaries fragment and the tests, and rot without a drift check.
- Endpoint and provider counts are removed (three files carried three values).
- Duplicated statements (own-key, faithful relay, keep-four-in-step, money-only
path, relay guard, secrets) are stated once each.
- Sections reordered: contract, where the truth lives, architecture,
development, working agreement, and a closing section for user-facing copy.
* build(uv): pin required-version instead of banning `uv lock`
uv.lock is revision 3, first written by uv 0.8.4. An older uv reads it fine but
rewrites it to revision 2 on any touch, dropping every upload-time field: the
~650-line no-op diff the old "always --frozen, never uv sync or uv lock" rule
worked around. That rule also told agents to hand-edit the lock, which --frozen
would then install unchecked.
- pyproject.toml: `[tool.uv] required-version = ">=0.12"`, so an old uv refuses
to run instead of rewriting the lock.
- ci.yml: `--frozen` becomes `--locked`, so a stale lock fails CI instead of
being installed silently. The comment about the team's older uv is gone.
- CONTRIBUTING.md names the floor; AGENTS.md replaces the ban with "change
dependencies through uv add or uv lock, never by hand".
- docs/context/architecture/import-boundaries.md describes the CI step as it
now runs.
Verified: uv lock --check, uv sync --locked and uv run --locked lint-imports
(12 kept, 0 broken) on uv 0.12.3.
GitHub redirects the old slug, but every URL we publish (pyproject,
npm package, plugin manifest, issue templates, web pages, llms.txt)
now says the real name. PyPI package name stays tools-registry.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
.claude/ (the tools-registry-context + dev-local skills) is local dev tooling
now — untracked from the repo and added to .gitignore. The design docs it
manages stay public in docs/context/. Fix the AGENTS/CONTRIBUTING/README
references that pointed at .claude/skills.
Fill the TODOs with real content: commit/PR conventions, do-not-touch
areas (faithful-relay contract, deliberate security guards), agent
orientation notes (API-is-the-brain, no-build dashboard, portable
migrations, /llms.txt), roadmap pointer, and a short code of conduct.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
- LICENSE: Apache 2.0 + additional terms (free internal/commercial use
and self-hosting; no third-party hosted offerings without written
permission) — modeled on the Multica license, no logo clause. Wired
into pyproject.
- CI: pytest (uv, py3.13) + gitleaks full-history scan on PRs and main.
- SECURITY.md: contact set to jason@superdesign.dev, draft banner gone.
- CONTRIBUTING.md: real clone URL; no .env needed for dev (config knobs
documented in the README instead — no .env.example).
- Delete OSS-PREP-NOTES.md (internal staging notes; its checklist is
now fully executed).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
A remote registry that turns a team's skills into shareable, callable tools:
any member's agent or a human calls a tool without owning its credentials —
a proxy injects the secret server-side.
This is the curated public tree (internal handoffs, plans, meeting notes,
and dev journal are kept in the private archive). Still WIP before going
public: see OSS-PREP-NOTES.md for the remaining genericization + the LICENSE,
CONTRIBUTING, AGENTS, and SECURITY items to finish.