Skip to content

chore: OSS standard polish — contributing triad, repo hygiene, pluto shrapnel, canonical docs - #183

Merged
unfoundbox merged 1 commit into
mainfrom
chore/oss-standard-polish
Sep 25, 2026
Merged

unfoundbox merged 1 commit into
mainfrom
chore/oss-standard-polish

Conversation

@unfoundbox

@unfoundbox unfoundbox commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Closes every gap from the pre-v2.10 audit on what 'production standard open source codebase' means for this repo. Five items:

1. CONTRIBUTING.md / CODE_OF_CONDUCT.md / SECURITY.md — the adoptability triad. Code of Conduct is Contributor Covenant v2.1. SECURITY.md routes reports to dev@motionvector.io with a 72-hour ack, names what's in and out of scope (loopback-only middleware is trusted; spot/LTX/Hunyuan routes refuse 501 today so there is no inference path to attack), and documents the repo's own security posture record (every compute-spending endpoint requires X-SpacePilot-Token, subprocess is argv-lists only, resolve_output containment). CONTRIBUTING.md explains the two project rules (execution over ceremony, strict tests before implementation), the commit shape, the repo's relationship to spacebar and landing/, and how to read AGENTS.md as the rulebook.

2. Research receipts move from repo root to experiments/routing-research/ — all 8 files. With a README explaining they are provenance behind FLEET-PLAN/CONCEPT claims, not product, and where the live registry actually lives. Repo root was cluttered with 200 KB of non-product JSONs and CSVs.

3. Pluto shrapnel — config.py CORS whitelist had 4 hard-coded pluto.localhost entries (pre-#101 rename); mflux_driver.py error text referenced .pluto_config.json which does not exist (real name is .spacepilot_config.json). Both fixed. The legitimate read-only compat paths are kept: paths.py legacy_user_data_dir/cache_dir, cli.py LEGACY_CONFIG_FILE, and the PLUTO_MFLUX_BIN env alias all still work for configs that predate the rename. tests/test_mflux_driver.py updated: canonical name is honored, AND the legacy alias still works when canonical is unset.

4. Canonical-docs headers on the three specs a new contributor hits first:

  • docs/LOCAL-SETUP.md → CANONICAL
  • docs/BUILD-PLAN.md → STATUS: partially stale, with which phases are done and as of which date, and the standing warning about hardcoded counts
  • docs/design/INFERENCE-SURFACE.md → CANONICAL SPEC for /v1

Repo is now self-guiding for a new reader without cross-diffing.

5. Landing registry-snapshot regenerated from current main (64 models, 94 variants, 9 measured) after an earlier session's auto-deploy stopcock wiped the file.

Tests: 1072 passed, 27 skipped, full suite locally, all five fixes in place.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

…luto shrapnel gone, canonical docs

Five items, ~1 hour of work, closing every 'below standard' gap surfaced
in the pre-v2.10 audit:

1. CONTRIBUTING.md, CODE_OF_CONDUCT.md (Contributor Covenant v2.1),
   SECURITY.md — the adoptability triad. Email for security reports is
   dev@motionvector.io with 72h ack. CI expectations written down; the
   bandit baseline is called a recorded debt list, not something to wave
   away.

2. Research receipts move from repo root to experiments/routing-research/
   (all 8 files: expert_superset_*, prompt_predictor_*, step3b_*,
   moe_stability_results). They are research receipts behind
   FLEET-PLAN/CONCEPT claims, not product. README explains what they are
   and where the live registry actually lives.

3. 'pluto' shrapnel: config.py CORS whitelist had 4 hard-coded
   pluto.localhost entries (the pre-#101 rename); mflux_driver error text
   referenced .pluto_config.json which does not exist (real name is
   .spacepilot_config.json). Both fixed. The LEGACY compat paths
   (paths.py legacy_user_data_dir/cache_dir, cli.py LEGACY_CONFIG_FILE,
   PLUTO_MFLUX_BIN env alias) are intentionally kept — they are the
   'read-only compat' rule for users whose config predates the rename.
   tests/test_mflux_driver.py updated to verify the canonical name is
   honored AND the legacy alias still works when canonical is unset.

4. Canonical-docs headers on the three specs a new contributor hits
   first: docs/LOCAL-SETUP.md (CANONICAL), docs/BUILD-PLAN.md (STATUS:
   partially stale, which phases are done as of which date), and
   docs/design/INFERENCE-SURFACE.md (CANONICAL SPEC for /v1). A reader
   cold-landing on docs/ now knows which doc is current vs. history
   without cross-diffing.

5. Regenerated landing/public/registry-snapshot.json from the current
   main (64 models, 94 variants, 9 measured) after the earlier session's
   auto-deploy stopcock wiped it.

Tests: 1072 passed, 27 skipped locally, full suite.
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
spacepilot Error Error Sep 25, 2026 7:25am UTC
1 Skipped Deployment
Project Deployment Actions Updated
spacepilot.dev Ignored Ignored Sep 25, 2026 7:25am UTC

@unfoundbox
unfoundbox merged commit 9bc8a2d into main Sep 25, 2026
5 of 6 checks passed

This branch had an error being deployed

1 failed deployment
Preview – spacepilot — 25e7c4e4 Deployed Sep 25, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant