Files
treg/CLAUDE.md
SToneX 8031c83d99 docs(agents): contract-first AGENTS.md and a pinned uv floor instead of a lock ban (#335)
* docs(agents): AGENTS.md is the single guide, contract first, no state snapshots

CLAUDE.md now only imports AGENTS.md so Claude Code, Codex and Cursor read one file.

AGENTS.md is rewritten around what an agent cannot learn from the code:

- Non-negotiables move to the top and are corrected against the code. "Own key
  always wins, never metered, never routed or overflowed" is promoted to rule 1.
  The relay rule now scopes to plain /call/ and names routed endpoints and
  overflow as wrappers, since route.py injects `_treg` into the body and overflow
  adds X-Treg-Served-Via; the old wording contradicted both. The hold rule
  defines "hold"; the pool rule says why reserve and settle are two transactions;
  the ledger rule records that there is deliberately no refund entry.
- The dataplane write allowlist becomes guidance that points at
  tests/test_call_architecture.py as the authority instead of a prose copy.
- Enforcement gap inventories, per-file commit lists, contract-by-contract
  recaps and the CLI-module list are removed: they duplicate pyproject, the
  import-boundaries fragment and the tests, and rot without a drift check.
- Endpoint and provider counts are removed (three files carried three values).
- Duplicated statements (own-key, faithful relay, keep-four-in-step, money-only
  path, relay guard, secrets) are stated once each.
- Sections reordered: contract, where the truth lives, architecture,
  development, working agreement, and a closing section for user-facing copy.

* build(uv): pin required-version instead of banning `uv lock`

uv.lock is revision 3, first written by uv 0.8.4. An older uv reads it fine but
rewrites it to revision 2 on any touch, dropping every upload-time field: the
~650-line no-op diff the old "always --frozen, never uv sync or uv lock" rule
worked around. That rule also told agents to hand-edit the lock, which --frozen
would then install unchecked.

- pyproject.toml: `[tool.uv] required-version = ">=0.12"`, so an old uv refuses
  to run instead of rewriting the lock.
- ci.yml: `--frozen` becomes `--locked`, so a stale lock fails CI instead of
  being installed silently. The comment about the team's older uv is gone.
- CONTRIBUTING.md names the floor; AGENTS.md replaces the ban with "change
  dependencies through uv add or uv lock, never by hand".
- docs/context/architecture/import-boundaries.md describes the CI step as it
  now runs.

Verified: uv lock --check, uv sync --locked and uv run --locked lint-imports
(12 kept, 0 broken) on uv 0.12.3.
2026-09-05 14:52:29 +08:00

215 B