Tier S (a fix inside a boundary; chaos d8=5, no override). Reported by the maintainer: "I can't save notes, I get 'refused: no session token'." The form posted to a bare `/note`. Control 1 requires the token on EVERY request, so the guard refused all of them. WHY THE TESTS MISSED IT IS THE PART WORTH RECORDING. I verified the note channel over real HTTP and got 303 -- but I appended the token to the URL by hand. I tested the ENDPOINT and not the PATH A PLAYER TAKES, so the one thing standing between the feature and the user was the one thing not exercised. Same family as timing the wrong span and counting the wrong denominator: a correct measurement of the wrong subject. Fixed with Guard::note_endpoint(), so the form's action carries the token like every other request. The assertion now pins the token's PRESENCE rather than the bare path, so reverting the fix turns it red. Verified the way it should have been done first: read the form's `action` out of the SERVED page and POST to exactly that, nothing added by hand. 303. Clippy then flagged document_with_log at 8 arguments. It was right -- the signature had grown across three passes -- so the two endpoints are now one `Endpoints` struct rather than an #[allow]. They are one concept: the guarded surface this page may talk to, one channel that becomes commands and one that provably cannot. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> |
||
|---|---|---|
| .forgejo/workflows | ||
| benchmarks | ||
| crates | ||
| decisions | ||
| editions/ground-darvo-r0 | ||
| evidence | ||
| games/ground | ||
| history | ||
| research | ||
| scenarios | ||
| specs | ||
| tools | ||
| workplans | ||
| .custodian-brief.md | ||
| .gitignore | ||
| Cargo.lock | ||
| Cargo.toml | ||
| clippy.toml | ||
| facts.toml | ||
| gates.toml | ||
| INTENT.md | ||
| LICENSE | ||
| Makefile | ||
| README.md | ||
| rust-toolchain.toml | ||
| WORK-RECORDS.md | ||
clay-borg
A rebuild from scratch simulation and games engine framework set up to assimilate and optimize techniques and implementations useful for games, simulations, robotics.
Licensed under the Target Revenue Source License (TRSL V1C1) — see LICENSE; canonical text lives in the org's target-revenue repository.
Running the gates
make all # every gate, from a clean shell
make -C /path/to/clay-borg all # …or from any other directory
There is no environment setup step. No cd, no export PATH, no
activation script. make locates the repo from its own path and cargo
from the standard rustup locations; the Python tools do the same via
tools/repo.py. The only prerequisites are a rustup toolchain and Python
3.11+.
This is deliberate and enforced: make env-test runs every tool from /
with a PATH containing no cargo, and make all includes it. CB-RES-0003
measured 84 agent turns and $15.33 spent prefixing commands with cd and
export PATH before that friction was fixed at the root (CB-WP-0004 T01).
Other useful targets: make cost (spend per task), make cost-budget
(spend since the last commit), make cost-mix (mechanical vs judgment
turns), make loop-lint (executable InnerLoop rules), make self-tests
(every tool's positive control).
GROUND
The first product vertical is a virtual tabletop implementation of GROUND — A Game of Bonds and Rivalry: DARVO Edition. The boardgame itself (rules, editions, content) is at home in the sister repository ground-game — that repo is authoritative for what GROUND is; clay-borg implements the engine that runs it.