Skip to content

docs: place upstream in a subtree and settle the LINA link declaration - #4

Merged
thisisjun786 merged 1 commit into
devfrom
docs/upstream-layout
Oct 1, 2026
Merged

thisisjun786 merged 1 commit into
devfrom
docs/upstream-layout

Conversation

@thisisjun786

@thisisjun786 thisisjun786 commented Oct 1, 2026 •

Copy link
Copy Markdown
Owner

Summary

Settles how SION holds its ClawSweeper base and how its LINA link is declared, so Stage 1 can start.

  • Source layout (docs/design/sion.md): the upstream ClawSweeper tree sits under upstream/ as a git subtree. Upstream files keep their content and relative paths; the repository root (README, LICENSE, AGENTS.md, CONTRIBUTING.md, .github/) belongs to SION. Upstream workflows under upstream/.github/workflows/ never run here, because GitHub runs workflows only from the root. Operator workflows are placed by SION's installation and call SION's root reusable workflows, which run upstream code from upstream/. An upstream sync uses git subtree merge --prefix upstream and merges with a merge commit.
  • CI (docs/policy/ci.md): new "Upstream tree" section. The upstream job uses Node 24 from upstream's engines, pnpm from packageManager through corepack, pnpm install --frozen-lockfile and pnpm run check in upstream/.
  • Dependencies (docs/policy/dependencies.md, new): upstream's manifest, lockfile and workspace settings are used as upstream ships them and change only through a sync. Packages that only SION's own code uses follow SION's rules: exact registry versions, a committed frozen lockfile, no install scripts, and no minimum release age.
  • LINA link: result fields now come only from the SION section of LINA's host protocol. Every result carries the check state. The declaration is outbox/declaration.json on state, with the product version, protocol versions, capabilities and the targets whose link is on. Connecting is a person naming the operator repository in LINA. Mailbox file paths follow LINA's schema and fixtures.
  • Upstream behavior: the operator-repository visibility rule and the dashboard's public-only view are marked as upstream behavior. The dashboard no longer refuses to publish. When it leaves private targets out, it shows that on the page and records it on state.
  • Checks permission: stage permissions follow what upstream's jobs request. Upstream reads check runs and commit statuses and publishes no Check Runs, so no stage writes checks.
  • AGENTS.md: design contracts are described in the present tense.

Verification

  • Checked against ClawSweeper at c73bf38: 35 workflows exist only under .github/workflows/, and the only workflow_call ones are internal. setup-pnpm takes a working-directory, and no upstream code uses git rev-parse --show-toplevel. Every target token mints permission-checks: read, and the README says the retired commit-review lane no longer publishes Check Runs. The public dashboard projection never returns private repositories, and the scheduler doc keeps fanout public-only unless records publish to a private state surface.
  • node .github/scripts/check-docs.mjs passes. So do node --test .github/scripts/*.test.mjs and git diff --cached --check.
  • Anchors #source-layout, #types and ci.md#upstream-tree, plus the LINA anchors host-protocol.md#sion and integrations.md#sion-link, were checked by reading. No other document links to a changed sion.md section.

🤖 Generated with Claude Code


Devin Review

Keep the ClawSweeper tree under upstream/ as a git subtree, install and
check it in foundation with upstream's own Node, pnpm and lockfile, and
add a dependency policy for SION's own packages. Point result fields at
LINA's host protocol, fix the declaration at outbox/declaration.json,
mark the two visibility rules that follow upstream, and state that stage
permissions read checks as upstream's jobs do.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T17:18:01.254783Z 4883c1f PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@thisisjun786
thisisjun786 merged commit e1a343e into dev Oct 1, 2026
7 of 11 checks passed
@thisisjun786
thisisjun786 deleted the docs/upstream-layout branch October 1, 2026 17:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant