Skip to content

docs: name which side of the library/deploy split a version, tag or report is on - #192

Merged
thedavidmeister merged 4 commits into
mainfrom
2026-09-20-issue-111-provenance-boundary
Sep 21, 2026
Merged

thedavidmeister merged 4 commits into
mainfrom
2026-09-20-issue-111-provenance-boundary

Conversation

@thedavidmeister

@thedavidmeister thedavidmeister commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Closes #111

The rain-factory Soldeer series and this repo's tag namespace both run
continuously across the library/deploy split, and the three Protofire PDFs in
audit/protofire/ all name refs from the pre-split side. Nothing in the repo
said which side of the cut a version, a tag or a report belongs to, so a reader
could resolve any of them to source that is no longer here and conclude audited
or deployed code is the code they are reading.

  • README.md — one paragraph fixing the version and tag boundary: Soldeer
    rain-factory 0.1.5 and earlier carry the concrete CloneFactory and its
    deploy pins, 0.1.6 dropped them, and the five pre-split tags are named.
  • audit/protofire/README.md — new: each report audits the ref its filename
    names, none covers the current tree, and ICloneableFactoryV4 /
    LibICloneableFactoryV4 postdate all three.

REUSE needs no change: REUSE.toml:11 already annotates audit/**/.

QA

  • Discriminating tests: n/a — documentation only, no src/ behaviour
    changes, and tests never assert README text.
  • Mutations applied: n/a — no executable change to mutate.
  • Oracle: the repo's own git history, the Soldeer registry and the PDFs.
    git ls-tree -r sol-v0.1.5 (c29d5827309d2f10a6e68c76bc2ea385e0a4e701)
    carries src/concrete/CloneFactory.sol, src/lib/LibCloneFactoryDeploy.sol,
    src/generated/0_1_{3,4,5}/ and script/Deploy.sol; sol-v0.1.6
    (1b6adb965ac527ef114ddda11f4dad65400dbeeb) carries none of them. The Soldeer
    registry lists rain-factory 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.5, then 0.1.6
    through 0.1.23 — one ascending series across the cut. pdftotext on
    rain.factory.sol-v0.1.5-r3.0.jul-2026.pdf gives its own Reviews table
    (1a92a868…, 08fecb98… tag v0.1.1, c29d5827… tag sol-v0.1.5) and its
    Scope list (src/concrete/CloneFactory.sol,
    src/interface/ICloneableFactoryV2.sol, ICloneableFactoryV3.sol,
    ICloneableV2.sol, src/lib/LibCloneFactoryDeploy.sol) — neither V4 file is
    in it, and neither existed: ICloneableFactoryV4 landed 2026-08-08,
    LibICloneableFactoryV4 2026-08-20, both after the newest report.
  • Category check: the category is "a fact in this repo that resolves to the
    other side of the split". The other two carriers of that category are the
    deployed factory's embedded library version ([F06] [MEDIUM] The live CloneFactory embeds rain-factory 0.1.9 while this repo publishes 0.1.23, and nothing here detects the gap #110) and the CI/tag mechanism
    that let a surface removal ship as a patch bump. The first is [F06] [MEDIUM] The live CloneFactory embeds rain-factory 0.1.9 while this repo publishes 0.1.23, and nothing here detects the gap #110's; the
    second is rainix's — the autopublish lifecycle and its next-v<x.y.z> tag are
    owned by rainix-autopublish.yaml, so a gate on "published surface changed
    without a minor tag" belongs in that reusable, not in a repo-local workflow
    here.

🤖 Generated with Claude Code

thedavidmeister and others added 2 commits September 20, 2026 14:04
…eport is on

Soldeer `rain-factory` 0.1.5 and earlier carry the concrete `CloneFactory` and
its deploy pins; 0.1.6 dropped them. The five tags on the pre-split side are
named in README.md, and audit/protofire/ gets a README saying each report
audits the ref its filename names and that neither V4 file is in any of them.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@thedavidmeister thedavidmeister self-assigned this Sep 20, 2026
@coderabbitai

coderabbitai Bot commented Sep 20, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 197726d7-b6eb-46ce-9b28-a0b413a77cbd

📥 Commits

Reviewing files that changed from the base of the PR and between ffd3041 and 751483f.

📒 Files selected for processing (1)
  • README.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

thedavidmeister and others added 2 commits September 21, 2026 11:14
The audit note repeated the three refs its filenames already carry and
restated the split the root README states. "not revisions of this
library" repeated "are those pre-split releases".

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
…t README

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@thedavidmeister
thedavidmeister merged commit 710dff5 into main Sep 21, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

1 participant