Repository navigation
Conversation
`cargo run -p mios-template-conform -- --llms-txt --root <checkout>` is the command for validating an llms.txt, but the flag did not exist: the argument loop ignored anything it did not know, so the command ran the template walk instead and exited 0 on any tree -- on mios-bootstrap's non-conforming llms.txt, and on an empty directory. --llms-txt now validates <root>/llms.txt against https://llmstxt.org/, as the reference parser (llms-txt, parse_llms_file) reads it: - exactly one H1, first, after only blank lines and HTML comments; an `# AI-hint:`-style header tag that became an H1 is named as such; - a `>` blockquote summary right after the H1 (required here); - no heading in the details: no second H1, no H3+, no setext heading, no `##` line inside a code fence or comment (the parser splits there); - under each H2 only `- [name](url)` items, optionally `: notes`, one per line; duplicate section names and empty sections fail; - relative link targets must exist under --root; root-absolute and `..` links fail; URLs with a scheme are not fetched. A missing llms.txt fails. Success prints `[llms-txt] ... conforms to`, which a caller can require. Unknown arguments, a valueless --root, a non-numeric --max-unconforming, and --max-unconforming combined with --llms-txt now exit 2 with usage. Controls: - mios-bootstrap llms.txt at its main: exit 1, 50 violations (three H1s at lines 1-3, both header tags, every prose section); with the bootstrap fix (branch claude/nice-dijkstra-3w7uj0): exit 0, 3 sections, 31 links. - this repo's own llms.txt: exit 1, 48 violations, the same defects. It is not changed here. - empty directory: exit 1 (was 0). `--llm-txt`: exit 2 (was 0). - 14 unit tests; planting a mutation (duplicate-H1 rule off; fence `##` rule off) fails 2 and 1 of them. fmt and clippy -D warnings clean. - tools/sync-generated.sh regenerated metadata.json and the manual corpus ledger; a second run changes nothing. The docs ratchet stays at main's 91/6: every new comment classifies STAY. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
…d.sh) The metrics block counts committed lines: the validator moved Rust from 47k to 48k. Without this, CI's "Generated artifacts match the SSOT" step renders the new count and fails on the diff. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
… mios-bootstrap#25) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
The same defects mios-bootstrap's index had, and the same fix (mios-dev/mios-bootstrap#25): lines 1-2 were `# AI-hint:` / `# AI-related:`, so the file opened with three H1s, and every H2 held prose, code or tables where the format allows only `- [name](url): notes` items. The reference parser (llms-txt 0.0.7, parse_llms_file) raised AttributeError on it, and `mios-template-conform --llms-txt` reported 48 violations. - AI-hint / AI-related move into a leading HTML comment. - `# mios-dev/mios` is the only H1, followed by the summary blockquote on one line (the reference parser reads only the first blockquote line). - The prose H2s become **Title.** paragraph leads; a word diff shows no prose edits. A lead stands alone above a list, fence, table or comment, so the three MIOS-GEN blocks stay byte-identical. - Key files becomes ## Key files / ## Docs / ## Optional link lists, with ADR.md and usr/share/doc/mios/adr/ added to Docs and mios-bootstrap's index to Optional. llms-full.txt is not linked: it is a one-line stub. Verified: - mios-template-conform --llms-txt --root .: exit 0, H1 "mios-dev/mios", 3 sections, 15 links, every relative target present (exit 1 with 48 violations at the previous commit). - llms-txt 0.0.7 parse_llms_file: title "mios-dev/mios", the full summary, 7 + 6 + 2 links each with name, URL and notes. - mios-manual render --check: derived sections up to date (35 markers). - tools/sync-generated.sh leaves the tree clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
The repo-split paragraph gave mios-bootstrap the AI files and the summary credited it with "deployed AI assets". mios.git tracks 20 files under usr/share/mios/ai/ and mios-bootstrap tracks none; both repos' CLAUDE.md state mios.git owns them, and mios-bootstrap's own index says the same (mios-dev/mios-bootstrap#25), so the two indexes contradicted each other (Law 15). mios-bootstrap's share is its knowledge graphs (usr/share/mios/knowledge/, 3 files), which the summary now names. Verified: mios-template-conform --llms-txt exit 0 (3 sections, 15 links); mios-manual render --check up to date (35 markers); tools/sync-generated.sh leaves the tree clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01LW5pD6B3XoRWioWsCSEZg7
6ab1184 opened [lsfs] and [offline] directly after [pgvector].rls_mode, so the fifteen keys below it parsed into [offline]: rls_enable, pool_enable/min/max, hnsw_iterative_scan, hnsw_max_scan_tuples, hnsw_scan_mem_multiplier, emb_model, emb_version, scratch_persist, backfill_batch, backup_enable/dir/keep and listen_loopback. The resolver emitted MIOS_OFFLINE_*, which nothing reads, and every consumer of the [pgvector] names silently took its inline default: MIOS_PG_HNSW_* [containers.mios-pgvector] Exec; the render baked the Quadlet defaults, so editing the key did nothing MIOS_DB_RLS_ENABLE agent-pipe pg.py and mios-pg-query (tenant RLS) MIOS_PG_POOL_* agent-pipe pg.py MIOS_PGVECTOR_EMB_* agent-pipe server.py MIOS_PG_LISTEN_LOOPBACK userenv.sh -> MIOS_PG_BIND_ADDR MIOS_PG_BACKUP_* mios-pgvector-backup.service, reached only through an offline.backup_* resolver alias (8bb9075) The keys move back into [pgvector] verbatim. A parsed-TOML deep compare shows exactly 15 paths moving offline.* -> pgvector.* with equal values and nothing else changing. Every consumer name is now emitted, each with its consumer's inline default as the value, so default behaviour is unchanged and the keys are live again. The orphaned WS-A15 comment goes back above memory_provider, which it describes. Why no gate saw it: check_value_aliases skipped every registry row whose names were not emitted, and the stranded families were exactly the rows it skipped. A registered name the resolver does not emit is now a violation that names it; [pgvector].rls_enable -> MIOS_DB_RLS_ENABLE joins the registry so the RLS control is covered as well. Ledgers: var-closure stops recording the four names it had as referenced-but-unemitted (ceiling 410 -> 406). value-dup-baseline was seeded (710886c) from the stranded layout; it now records the three restored MIOS_PGVECTOR_X/MIOS_PG_X pairs and the five renamed members (ceiling 405 -> 408), and that gate's other findings on this tree are identical to origin/main's. The offline.backup_* alias stays in both resolver twins for now: it is dead for the shipped SSOT, tools/native/mios-resolver belongs to a running lane, and deleting it from one twin only would break Law 13. The shipped pgvector research prompt no longer describes the fault as current. Controls: - planted: the af6de6a layout (tables equal to af6de6a's) fails check_value_aliases naming 27 variables, e.g. "MIOS_PG_HNSW_ITERATIVE_SCAN is registered (MIOS_PGVECTOR_HNSW_ITERATIVE_SCAN -> MIOS_PG_HNSW_ITERATIVE_SCAN, derive) but the resolver does not emit it", and still fails after tools/sync-generated.sh, the "regen derived -> GREEN" step that let 6ab1184 land. var-closure names MIOS_DB_RLS_ENABLE and MIOS_PG_POOL_ENABLE/MIN/MAX. check_pod_quadlets cannot see it: the rendered unit is byte-identical either way at default values. - old gate: that plant reads "value-alias consistency verified"; tools/test_drift-checks.py TestValueAliasRegistry fails 3/7 there and passes 7/7 here. One test replays the plant hermetically against the real snapshot tool and registry, with the shipped SSOT as its control. - render: with the fix, a vendor hnsw_iterative_scan = "relaxed_order" renders hnsw.iterative_scan=relaxed_order; under the bug it rendered strict_order. - resolvers: Python and Rust emit identical maps (2840 names). Against origin/main, 15 MIOS_OFFLINE_* names go, 27 consumer names arrive and no value changes. - tools/sync-generated.sh (+ roadmap-index.py) is a fixed point. mios-task migrate no longer exists (T-1169); mios-task check passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Ko3T9bSv6UHkq8ALgVp8b
Review (operator, via the Monitor session): MiOS never raises a ratchet ceiling, and 52e4ba1 took value-dup-baseline.tsv from 405 to 408 to record three new groups. The ledger change is now a pure rename. The five rows whose members were stranded MIOS_OFFLINE_* names now name the restored canonical keys (MIOS_PGVECTOR_POOL_MAX, _EMB_MODEL, _BACKFILL_BATCH, _BACKUP_DIR, _BACKUP_KEEP) one for one, with every count and the 405 ceiling unchanged. Nothing new is recorded. What the restoration adds beyond that stays visible to the ratchet rather than silenced. [pgvector] is an aliased table, so each restored key is also emitted as MIOS_PG_<KEY>. Where that value is unique it forms a new two-spelling group ('strict_order', '20000', 'nomic-768-v1'); elsewhere the second spelling joins a recorded group ('8', '50', 'nomic-embed-text'). That is Law 9 debt for the alias collapse. It cannot be collapsed here without changing the resolver's [pgvector] alias family in both twins. Folding registered aliases inside the gate would drop 65 groups from main's ledger (416 -> 351), and that ledger is T-1159's to re-key. check_no_duplicate_value_key on this tree versus origin/main: identical findings plus exactly those three NEW groups and three grown members (count 416 -> 419, ceiling 405 on both); no SHRANK or stale row from the rename. tools/sync-generated.sh remains a fixed point. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Ko3T9bSv6UHkq8ALgVp8b
The registry header and the test docstring said fourteen [pgvector] keys were stranded under [offline]. Fifteen were. Fourteen of them had registry rows, which the old gate skipped; the fifteenth, rls_enable, had no row until this branch added one. Both now say so. tools/manifest.json and the corpus ledger embed the test file and are regenerated by tools/sync-generated.sh, which is a fixed point. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Ko3T9bSv6UHkq8ALgVp8b
Replaces the automatic pre-compact placeholder with what the branch did, how both controls ran, what CI shows against main 26edb17, and what is still unverified: the PR-head smoke test, the CI tiers that never run while the behavioural tier is red, and a booted host. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Ko3T9bSv6UHkq8ALgVp8b
# Conflicts: # ROADMAP.md # tools/manifest.json # usr/share/mios/ai/v1/metadata.json # usr/share/mios/reference/manual-corpus.tsv
…rivation, and SSOT projections
…nd nested workflows
…-build windows field - Add NativeWindows configuration to NativeConfig in src/mios-rs/mios-build resolving CI Containerfile build failure in 55-native-build.sh - Drive Windows Console registry targets (HKCU:\Console, %SystemRoot%_System32_cmd.exe, HKCU:\Console\MiOS, and PowerShell) with MiOS Hokusai palette (#282262), GeistMono Nerd Font Mono, and ScreenColors - Add home icon '~' in oh-my-posh template so path pill renders in home directory - Fix wslpath backslash escaping in mios-agent-cli-setup.ps1 - Pass all standing gates (phase-registry, ratchet-direction, credential-literals, version-literals-ssot, signature-policy, ci-suites --check, test-ux.py)
…seline, and sync prompt home_icon
…OS-Ai telemetry tab, and reconcile nested workflows 1. Fix runaway Node CPU storm (96% CPU, load avg 44.53) caused by Valkey configuration expansion and unconstrained Firecrawl cluster workers. Rendered Quadlet port 8565 in /etc/containers/systemd/mios-webtools-redis.container, added ENV=local to firecrawl-api and firecrawl-worker in mios.toml to constrain Node cluster workers strictly to 2 rather than 32 threads. System load dropped to 2.36 (CPU >92% idle). 2. Unify mios, mios shell, and mios mon entry points in usr/bin/mios to launch mios-mon.py --monitor on interactive invocation or shell/mon verbs. 3. Add live MiOS-Ai monitoring tab to usr/libexec/mios/mios-mon.py with real-time agent registration, headless tmux sockets, and inter-agent message logs; implement slim scrollbars and responsive mobile portrait/landscape layout. 4. Integrate and reconcile Codex nested-workflow branch (test_mios_mcp_aio.py 22/22 green, mios-mcp-server slot reservation, truthful receipts). 5. Pass all 6 standing gates, sync-generated.sh, and doc-production-evidence.
…-user observability
…d interaction spec
…ows launchers - Unify Textual AIO monitor tab navigation, fixing focus race condition in ClientView - Migrate mios-toml-get and mios-browser to native static Rust binaries; drain browser from [ssot_tables].unconsumed - Consolidate Windows host launchers with Subsystem 2 GUI execution (run-hidden.vbs / MiosServiceTool.exe) - Prune redundant Start Menu shortcuts on Windows host to single canonical Programs\MiOS.lnk - Wire Headscale mesh quadlet and firstboot synchronization services - Enforce upstream Windows native low-power GPU preference (GpuPreference=1;) on living wallpaper and WebView2 runtimes - Certified clean by independent victory auditor (victory_auditor_13)
added 10 commits
October 5, 2026 22:41
… compact centering, and tmux integration
…d scaffold mios-service-core (T-1148, T-1161, T-1162)
…ing decisions (T-210)
…fabric, and native hardcode-lint - T-211: Refactor Windows iGPU inference service (mios-igpu-server.ps1) to bind strictly to localhost 127.0.0.1:8540 per Law 5, eliminate Tailscale CGNAT dependencies and firewall alterations, and enforce GpuPreference=1; for AMD Radeon 0x13c0 with -fit off. Update mios-model-router to route to http://127.0.0.1:8540/v1. - T-212: Configure cross-lane llama.cpp RPC fabric across Windows host iGPU and Linux container dGPU under llama-server --rpc 127.0.0.1:8540. Declare [ports.categories.inference] members, [lanes.rpc_igpu], and federated:32b route with Vulkan coopmat2 fallback handling. Add llama-rpc-server.service. - T-1161: Port mios-hardcode-lint to native Rust static binary in tools/native/mios-hardcode-lint with 100% parity across header risks, dates in comments/strings, port/IP hardcodes, and Ventoy secrets. Wire strangler cutover in automation/98-drift-checks.sh. - Wallpaper & GPU Preference Remediation: Eliminate living wallpaper black startup void by initializing FBO clearColor to SSOT #282262, force low-power GPU routing via WebView2 --force_low_power_gpu and GpuPreference=1; in Set-MiOSWallpaper.ps1, and replace img0.jpg to prevent default Windows 11 blue bloom fallback. - Verification & Certification: 122/122 tests pass across test-igpu-rpc-rust-e2e.py and test_hardcode_lint_parity.py; all 5 standing gates, ci-suites.py --check, sync-bootstrap.py --check, and sync-generated.sh projections pass with zero drift.
… hardcode-lint (T-211, T-212, T-1161) - Ground Windows iGPU service on 127.0.0.1:8540 (MIOS_PORT_LLM_IGPU) in MiOS-iGPU-Server.cfg, binding strictly to localhost per Law 5, running live llama-server.exe on AMD Radeon iGPU (0x13c0) with 0MB RTX 4090 VRAM. - Fix tools/native/mios-hardcode-lint/src/main.rs: safe char-boundary progression in UTF-8 slicing and strict docstring-only prefix filtering for triple-quote skips (f-strings properly flagged). - Add adversarial test suites: tests/test-adversarial-igpu-rpc.py (20 tests) and tests/test_adversarial_hardcode_lint.py (46 tests). Register in usr/share/mios/mios.toml with 188/188 tests passing. - Preserve Codex runtime/TUI terminal SSOT keys in [terminal]. - Synchronize projections via sync-generated.sh; all 5 standing gates, ci-suites, and sync-bootstrap pass cleanly. Certified by Independent Victory Auditor 15 (VICTORY CONFIRMED).
…dgeting & workspace observer - Recover Codex uncommitted MCP UX session diffs and preserve multi-agent contracts - Enforce universal hardware neutrality across Windows graphics and Vulkan filters - M1 (Tmux Workspace Recovery): Auto-recover dead workspace observers and anchors during resize hooks - M2 (Monitor TUI): Consolidate AI tabs into tab-agents with scrollbar suppression and responsive layouts - M3 (Gateway Context Budgeting): Implement tool_choice: 'none' stripping, caller tool deduplication, and principled 6-tier context token pruning with clamped max_tokens - Quadlet container fix: Ensure systemd Exec evaluates unadorned port variable for mios-llm-light - Two-sided verification: Certified by Reviewer, Challenger, and Auditor with 100% test pass rate across all tiers and standing gates
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of Changes
1. Windows Host Multiplexer & Resource Monitor (tmux & btop4win)
tmuxIntegration:arndawg.tmux-windows(native Windows port of tmux 3.6a using ConPTY and named pipes) into[packages.windows].pkgsandverify_probes.c:\mios-bootstrap\src\install-host-tools.ps1so host provisioning works in no-local-dependencies / offline environments.%USERPROFILE%\.tmux.confincorporating MiOS canonical colors, rounded status line glyphs, and mouse support.tmuxfunction inbuild-mios.ps1PowerShell profile with graceful fallback to WSL.btop4winIntegration:aristocratos.btop4win(btop4win 1.0.5) on Windows; removed legacy logic that skipped btop4win or deletedbtop.exe.bin_mapininstall-host-tools.ps1,usr/share/mios/mios.toml, andmios-bootstrap/mios.tomlto maparistocratos.btop4win|btop.btop.confandthemes\mios.themeto bothBTOP_CONFIG_DIR(M:\MiOS\btop) and%LOCALAPPDATA%\btop.function btopinbuild-mios.ps1to prefer native Windowsbtop.exewhile preserving WSL fallback.settings.jsonthat attempted to invokeC:/WINDOWS/System32/WindowsPowerShell/v1.0/powershell.exein bash, resolving Gemini CLI execution blockages in WSL.2. WSL Environment & Core Inference Infrastructure
.wslconfigCorrection:networkingMode=mirrored,hostAddressLoopback=true,dnsTunneling=true,autoProxy=true, andfirewall=falseunder[experimental].localhostForwarding=trueunder mirrored mode, eliminating WSL startup warnings.:-bash expansion inusr/share/containers/systemd/mios-llm-light.containerandusr/share/mios/mios.tomlfrom${MIOS_PORT_LLM_LIGHT:-8500}to${MIOS_PORT_LLM_LIGHT}, restoringllama-swaplistener binding on:8500.mios-pgvector.service(:8600),mios-llm-light.service(:8500), andmios-agent-pipe.service(:8700).http://localhost:8700/v1/chat/completionsreturningpongwithgranite4.1:8b.3. Gateway Context Budgeting & Test Hardening
_select_child_toolsinusr/lib/mios/agent-pipe/mios_pipe/routing/vision.py:746._shape_violationsrole tracking intests/test_adversarial_gateway_stress.py.tests/test_gateway_wallpaper_rust_e2e.pywith genuine positive and negative URL guard controls.tests/test-adversarial-m3-gateway-budgeting.py.4. Verification Evidence & Standing Gates
tests/test_gateway_wallpaper_rust_e2e.py: 145/145 PASStests/test_adversarial_gateway_stress.py: 32/32 PASStests/test_adversarial_m1_tmux_workspace.py: 12/12 PASStests/test_adversarial_m2_monitor_tui.py: 7/7 PASStests/test_adversarial_m3_challenger.py: 11/11 PASSusr/lib/mios/agent-pipe/test_mios_chat.py: 37/37 PASSusr/lib/mios/agent-pipe/test_mios_vision.py: 11/11 PASStools/native/mios-agent-relay(cargo test): 11/11 PASSpython tools/ci-suites.py --check: 423 suites registered across 3 tiers (0 unregistered)python tools/sync-bootstrap.py --check: 13 mirrored files, 2 tables, 2 keys matchphase-registry,ratchet-direction,credential-literals,version-literals-ssot,signature-policy).