A synthetic single-writer settlement ledger with replicas and a deterministic adversarial laboratory, built to show Macroonz 0.2.0 automating mechanical work while independent judgments stay authored.
The sentence the completed project must make true: we author domain decisions once, generate their repetitive mechanical consequences through Macroonz, and challenge the resulting behavior through independently authored checks that Macroonz runs and records.
AGENTS.mdis the working law for anyone who edits this repository.docs/BUILD_PLAN.mdis the implementation sequence, the workspace layout, and the map from every acceptance row to the step that closes it.HANDOFF.mdis the current status, the commands run, and the open blockers.MacroRail_Claude_Code_Packet/is the frozen specification packet, private input that git ignores and that is present only on the author's machines; nothing in it is edited, and the tree builds and qualifies without it.
| Package | Path | Role |
|---|---|---|
rail-substrate |
crates/rail-substrate |
neutral identifiers, amounts, ticks, sequence numbers, and request shapes; depends on nothing |
rail-model |
crates/rail-model |
the independent reference model; depends on rail-substrate alone |
rail-compiler |
crates/rail-compiler |
callable projections over macroonz-compiler |
rail-macros |
crates/rail-macros |
the procedural entrances; tokens and spans, no grammar |
rail-core |
crates/rail-core |
the settlement ledger; consumes Macroonz with default features off |
rail-lab |
crates/rail-lab |
the adversarial laboratory; consumes Macroonz in full |
rail-cli |
crates/rail-cli |
the macrorail binary; reads one request line from stdin |
xtask |
xtask |
repository tooling; reads one request line from stdin |
rail-specimen-dupcommit |
specimens/dupcommit |
the retained defective specimen; a member but not a default member |
| adopters | adopters/{full,harness-only,diet,renamed} |
package-shaped consumers outside the workspace, one per Macroonz posture plus the renamed facade crossing; built by cargo xtask <<< adopters |
The toolchain is pinned by rust-toolchain.toml: Rust 1.98.1 with rustfmt, clippy, rust-src, llvm-tools-preview, and the wasm32-unknown-unknown target; install it with rustup toolchain install 1.98.1 --profile minimal --component rustfmt,clippy,rust-src,llvm-tools-preview and rustup target add wasm32-unknown-unknown --toolchain 1.98.1.
Every macroonz crate resolves to exactly 0.2.0 from crates.io through the committed Cargo.lock; cargo +1.98.1 fetch --locked brings the graph in once, and every command below runs offline after that.
cargo-nextest runs the lanes, and cargo-mutants 27.0.0 is the wrapped mutation backend; both are ordinary cargo installs.
The smoke set builds the workspace, checks the packet, formats, checks, lints under the wall, regenerates twice, and runs every test: cargo +1.98.1 run -q -p xtask <<< 'qualify --lane smoke'.
Both binaries read one request line from standard input.
macrorail (cargo +1.98.1 run -q -p rail-cli <<< '<request>') answers help, inspect automation [--format text|json], inspect recipe <path> [--harness available|unavailable], demo automation, demo defect [--out <dir>], replay <capsule.json> [--subject defective|fixed|double-sided], scenario <schedule> [--from-transcript <file>], coverage [--out <dir>], mutants [--out <dir>], proposal offer|list [--out <dir>], proposal admit <id> --by <name> --depot <dir> [--out <dir>], check --profile deterministic|control|all [--suite <namespace/stem>] [--out <dir>], bench --profile qualified-work [--out <dir>], and report <run-dir> [--format markdown|html].
xtask (cargo +1.98.1 run -q -p xtask <<< '<request>') answers attach --emit <producer.rs>, generate [--check [--twice]], automation, adopters, loom, demo-change [<extension>], qualify [--lane <name>|smoke|mutants|fresh-clone] [--resume], and acceptance.
Every request exits 0 when it succeeds and prints its refusal on standard error otherwise; nothing reads the environment, the arguments, or the clock.
qualify runs the named lanes in order and retains one outcome line per lane, without timings, in evidence/qualification/qualify.txt; each lane's whole output lands under target/qualification/logs/.
The lanes are the toolchain and dependency facts, the packet's own integrity check, format, check, clippy under the wall, the twice-regenerated matrices, the automation inventory, every test, the carriers, the release benchmarks, the coverage lane and the coverage campaign reproducing its retained pack, the loom lane with the wasm control, the mutation lane, the defect road reproducing its retained capsule, the retained proposal, the deterministic and control checks, a rendered report, the retained transcript replayed, the automation demo and help, the four adopters, and the change demo.
Two lanes run only when named: --lane mutants runs the wrapped cargo-mutants backend and compares its console with the retained one, and belongs to continuous integration rather than a laptop; --lane fresh-clone clones the committed tree under target/qualification/ and runs the smoke set there.
The packet lane is not in the smoke set and reads blocked on a checkout without the packet.
acceptance copies the packet's rows by identifier and sets each status only from executed probes over those outcomes and the retained evidence, writing evidence/acceptance_results.json; a lane that could not run blocks every row that stands on it, a lane that refused fails them, and a lane that never ran leaves them not_run.
The packet under MacroRail_Claude_Code_Packet/ is never edited; its tools/verify_packet.py is a qualification lane on the machines that carry it, and acceptance checks its row identifiers against the rows xtask/src/acceptance.rs declares whenever it is present.
.github/workflows/qualify.yml runs on Blacksmith runners as three jobs: the default qualification set followed by acceptance, the mutants lane, and the fresh-clone lane.
The cargo-mutants campaign runs only there; the retained evidence under evidence/ is committed from the author's machine, and the workflow uploads each job's logs and reports any drift it produced against the retained files.
The packet lane reads blocked there because the packet is private input absent from the checkout; the first job's verdict admits exactly that one blocked lane and fails on any other lane that is not ok, and the acceptance it writes is a sensor uploaded with the logs, not the retained evidence.
Retained evidence lives under evidence/ in the directories qualification/, package/, defect/, network/, corpus/, mutation/, proposals/, and change/, and every file there is named by a probe in evidence/acceptance_results.json.
Runs the command-line program persists land under target/qualification/runs/ until qualification retains them; nothing under target/ is evidence.
Every ceiling the packet names has one owning sentence in the tree: persistence in docs/PROTOCOL.md, settlement in docs/PROTOCOL.md, preemption scope in crates/rail-core/README.md, source attribution in crates/rail-lab/README.md, and the provenance posture in crates/rail-lab/README.md beside the defect road.
The workspace compiles under the pinned Macroonz lint wall with no relief anywhere.
rail-core is the settlement ledger: three recipes (lifecycle, policy, wire), an engine with an idempotency gate, memory and checksummed file journals, a replica, a coordinator, typed transfer handles rendered by a caller-owned projector, the two-faced synchronization vocabulary, and the commit door.
rail-model is the independent reference model with its own vocabulary and hand-authored wire vectors.
rail-compiler holds the attachment kinds, the ledger bake, the matrix kinds, the identifier stamp, and the automation schema; cargo xtask <<< generate publishes the matrices, the rail_id! definition, and its landings, and generate --check compares regeneration byte for byte.
rail-lab carries the host layer, the spike carriers, the parity, golden, isolation, attachment, stamp, and compile-matrix lanes, the reach fixture, eighteen authored compile cases the real rustc judges, the roster of twenty-eight trial rows with their laws, generator, defect road, storage faults, network, interleavings, the preemption lane that runs under cargo xtask <<< loom, the coverage lane over the ledger's real frame parser under stable rustc source coverage, the mutation lane that presses the declared record-kind order through every road the harness opens, the bench lane of four measured roads with executed planted-worse controls, the carriers lane where three roads seat one roster, and the export lane behind macrorail check, bench, and report.
Every slice of docs/BUILD_PLAN.md has landed; HANDOFF.md records the standing and the notes.
evidence/acceptance_results.json holds the row-by-row standing the last cargo xtask <<< acceptance wrote: on 2026-09-06, from the outcomes in evidence/qualification/qualify.txt, all sixty-three rows read passed, none failed, blocked, or not_run.
Those outcomes came from the default set, the mutants lane, and the fresh-clone lane run on the author's machine with the packet present; HANDOFF.md names the open blockers, of which there are none recorded.