Skip to content

Modernize ZeoTool on ZeoCore - #1

Merged
rodriveracom merged 6 commits into
mainfrom
stream/zeotool-modernization
Sep 23, 2026
Merged

rodriveracom merged 6 commits into
mainfrom
stream/zeotool-modernization

Conversation

@matorclawson

@matorclawson matorclawson commented Aug 26, 2026 •

Copy link
Copy Markdown
Contributor

Scope

ZeoTool modernizes the legacy GPL QuackTool surface into an MIT-licensed, ZeoCore-native, deterministic local asset-copy educational reference capability.

Educational boundary

ZeoTool is not a Zero Employee production-runtime component, execution plane, or orchestration framework. It has no organizational authority and does not schedule, supervise, coordinate, or persist actors. Zero Employee Go does not import or depend on its Python runtime. Any future integration requires a Zero Employee-owned versioned, transport-neutral capability manifest/request/receipt boundary.

No Sovereign Agent compatibility, actor lifecycle, scheduling, Go integration, or retired architecture-chain claim is added.

Security and licensing

  • Forward MIT authorization/relicensing record for the successor tree.
  • Real ZeoCore bounded filesystem implementation.
  • Regression coverage for traversal, output escape, symlink escape, overwrite, and no-effect denial.

Verification

make verify: locked sync, whitespace, Ruff format/lint, metadata validation, mypy, 10 tests, and dependency audit.

Recovery sequence

RULING-218 is merged. A correctly seated, independently authenticated Zeo Sparring reviewer must file the next verdict on exact head d7f0cd8; Master may merge only after that approval, then must run the default-branch post-merge gate before Site #10 or Resources provenance proceeds.

@matorclawson

Copy link
Copy Markdown
Contributor Author

SPARRING ADVERSARIAL REVIEW — CHANGES REQUIRED; merge withheld.

Identity scope: published from matorclawson at operator direction as the documented profrod-site Sparring analysis record, not a formal profrod-ai GitHub approval.

Attestation scope: I cloned head c9ba303, ran make verify, read the complete new source/tests/docs/license record, audited repository authorship and old packaging, built and inspected both wheel and sdist, smoked the installed module metadata/CLI, searched the profrodai and rodriveracom GitHub corpora plus public code search for consumers/residue, checked current GitHub/PyPI name availability, and checked the relicensing principle against the GNU GPL FAQ. This is repository evidence, not legal advice; it cannot establish undisclosed employer or third-party ownership.

WHAT PASSES

  • make verify exits 0: locked sync, committed-tree whitespace, Ruff format/lint, strict mypy, 5/5 behavioral tests, dependency compatibility. CI is green.
  • Wheel and sdist build; wheel contains ZeoTool code and MIT LICENSE; sdist also contains RELICENSING.md. python -m zeotool --help/--version work.
  • The current tree has no obsolete package/import/config/plugin compatibility residue. The only old-name strings are the two accurate pre-rename GitHub URLs in project metadata.
  • Workspace containment, missing input, byte identity, no-overwrite, and real CLI copy behavior are substantively implemented.
  • Pre-PR Git history contains only Rod Rivera author identities. RELICENSING.md records Rod as copyright controller. GNU’s authoritative FAQ confirms a copyright holder may release their own program under different licenses: https://www.gnu.org/licenses/gpl-faq.en.html#ReleaseUnderGPLAndNF
  • Global code search found no import quacktool / from quacktool consumers. profrodai/zeotool and the PyPI zeotool JSON endpoint are currently absent (availability observation, not a reservation).

MERGE BLOCKERS

  1. This is a scope replacement, not a modernization-only rename: 5,243 deletions retire the legacy config, plugin entry point, headless API, models/protocols, media-processing surface, developer guide, and thousands of tests; 1,168 additions replace them with one asset-copy capability. The PR documents that it is breaking, but the profrodai org corpus has no ZeoTool/Quacktool SOW or ruling authorizing retirement of those contracts. RELICENSING.md authorizes license/name; it does not authorize product-scope deletion. File a project decision/charter in the org corpus that names the retired surfaces, records operator authority, states why no compatibility release is owed, and defines the new asset-copy DoD. Link it from this PR before merge. This is the assumption-delta/scope-reduction fork made explicit.

  2. The live public site will become materially false. profrod-site/content/opensource/quacktool.md still publishes slug/name quacktool, the old GitHub URL, “media-processing automation tool,” and QuackCore/QuackVerse image/video/audio/document claims—all removed by this PR. Open and link a coordinated profrod-site PR that changes the card to ZeoTool/ZeoCore and the actual local asset-copy capability. Sequence: merge code PR, rename GitHub repository, verify redirect/new URL, then merge the site card. A GitHub redirect repairs only the URL; it cannot repair the public product claim.

  3. The safety boundary is under-protected by the committed suite. The code contains output-name traversal rejection, output-directory containment, and an explicit overwrite path, but tests cover only source escape and refusal to overwrite. Add behavioral tests for (a) output_name="../escape" rejection, (b) output directory outside work root, including a symlink escape case, and (c) successful overwrite only when overwrite=True. Presence is not behavior, and these are the must-NOT boundary of the replacement product.

FOLLOW-THROUGH REQUIRED AFTER MERGE, NOT A CURRENT TREE BLOCKER

  • Rename profrodai/quacktool to profrodai/zeotool.
  • Immediately update pyproject Homepage/Issues to the canonical new URL in the next PR/release; redirects are compatibility, not canonical metadata.
  • Verify the repository redirect and the site card after the rename.

Verdict: licensing record, packaging, ZeoCore integration, and current implementation are provisionally RATIFIED. Merge is withheld on missing product-scope authority, the staged live-site correction, and safety-boundary regression coverage.

@matorclawson

Copy link
Copy Markdown
Contributor Author

SPARRING COORDINATED RE-REVIEW — IMPLEMENTATION SUBSTANTIALLY RATIFIED; two record/test corrections remain.

Identity scope: published from matorclawson at operator direction as the documented profrod-site Sparring analysis record, not a formal profrod-ai GitHub approval.

Attestation scope: cloned head 738d33c, read the complete changed implementation and regression suite, and independently ran make verify.

What now passes:

  • make verify exits 0: locked sync, committed-tree whitespace, Ruff format/lint, strict mypy, 10/10 tests, and dependency compatibility. GitHub CI is green.
  • Traversal is rejected before filesystem execution and neither candidate escape path is created.
  • An output root outside the workspace is denied with no destination write.
  • Source- and destination-symlink escapes are denied; the outside bytes remain unchanged and no escaped output is created.
  • overwrite=True positively replaces only the contained destination, with byte identity and byte count asserted.

Corrections required before merge:

  1. test_refuses_source_outside_work_directory still asserts only the skipped status/code. RULING-217 §4 says each denial must prove no outside read or write occurred. Add the observable no-effect assertions: preserve the outside source bytes and prove the corresponding output file was not created. The adjacent symlink test demonstrates the required shape.
  2. The PR body still reports “five behavioral tests” although the current gate runs 10, and it does not link the authority/site coordination. Update it to 10 and link org PR #7 / RULING-217 plus profrod-site PR #10.

Merge sequencing remains: amend and merge org PR #7, land the bounded pre-rename site card, then merge this PR and execute the ruling’s post-merge/rename closure. No further implementation redesign is requested.

@matorclawson

Copy link
Copy Markdown
Contributor Author

SPARRING FINAL IMPLEMENTATION RE-REVIEW — RATIFIED AT 5e1ef86.

Identity scope: published from matorclawson at operator direction as the documented profrod-site Sparring analysis record, not a formal profrod-ai GitHub approval.

Evidence:

  • Independently reran make verify: locked sync, whitespace, Ruff format/lint, strict mypy, 10/10 tests, and dependency compatibility all pass.
  • The outside-source denial now snapshots source bytes/identity/size/mtime and output contents, then proves all remain unchanged and no corresponding output exists.
  • The source-symlink denial was strengthened to the same no-effect standard.
  • The PR body now accurately reports 10 tests and links RULING-217/org PR #7 and site PR #10.
  • Live GitHub verify is green at this exact head.

Verdict: the ZeoTool code, safety boundary, licensing/package record, and PR metadata are RATIFIED. No ZeoTool changes remain. Merge is held only on the final executable wording correction in org PR #7 and the ruling’s required order: authority lands, pre-rename site card lands, then this PR merges.

Minor metadata follow-through: once org PR #7 changes the impossible singular cross-repository “closure PR” into a coordinated PR set, mirror that plural wording in this PR body’s post-rename paragraph. That edit does not require another code round.

@matorclawson

Copy link
Copy Markdown
Contributor Author

SPARRING IMPLEMENTATION RE-REVIEW — HEAD 4c4a253 RATIFIED; coordinated merge held on corrective authority.

Identity scope: published from matorclawson at operator direction as the documented profrod-site Sparring analysis record, not a formal profrod-ai GitHub approval.

Evidence:

  • Independently reran make verify at the exact head: canonical metadata check, formatting, Ruff lint, strict mypy, 10/10 behavioural tests, and dependency compatibility all pass.
  • README and pyproject.toml use https://github.com/profrodai/zeotool; the gate rejects legacy README/package URLs.
  • Live GitHub verify is green and the PR remains mergeable.
  • The previously ratified filesystem, overwrite, packaging, and relicensing evidence is unchanged.

No implementation change remains. However, this repository was renamed before this PR merged. Its current default branch is still legacy 2a69d2e QuackTool/GPL/QuackCore content, contrary to RULING-217’s merge → post-merge gate → rename order. The new name therefore does not yet describe default-branch bytes.

Verdict: code is RATIFIED. Merge is withheld only until the org corpus lands corrective authority grounded in the actual early-rename state. Once that authority lands, this PR should be the first code-state repair, followed immediately by its post-merge gate and the site/provenance steps.

@matorclawson

Copy link
Copy Markdown
Contributor Author

Principal architecture boundary revision d7f0cd8 is pushed. It is README-only, verified by make verify, and requires a fresh correctly seated Zeo Sparring verdict; the current profrod-site Sparring seat is explicitly not a substitute.

@rodriveracom
rodriveracom merged commit eb31967 into main Sep 23, 2026
1 check passed
@rodriveracom
rodriveracom deleted the stream/zeotool-modernization branch September 23, 2026 01:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants