Depone verifies; witnessd executes; ORRO exposes the workflow.
The thin wrapper is the executable ORRO product surface in this repository. It is intentionally narrow: it reports ORRO wrapper boundaries and delegates engine commands to the existing witnessd-hosted ORRO surface.
The wrapper is not proof, not verifier truth, not package publish, not approval, and not assurance.
The package exposes the ORRO-owned orro command and keeps orro-wrapper as a
compatibility alias for the same wrapper module.
python3 -m pip install -e .
orro-wrapper boundary
orro boundary
orro-wrapper self-test
orro-wrapper delegate -- --helpdelegate forwards arguments to an existing engine command. By default that
command is the current Python interpreter running -m orro. Operators
may override it with --engine-command or ORRO_ENGINE_COMMAND.
The wrapper:
- owns the user-facing
orrocommand; - delegates to witnessd-hosted ORRO commands;
- contains no engine logic;
- does not implement proofrun;
- does not implement proofcheck;
- does not implement scheduler, observer, fan-in, team-lane, or team-ledger logic;
- does not verify evidence itself;
- does not approve merge;
- does not raise assurance.
When a delegated command runs proofrun or proofcheck, that behavior belongs to the engine command the operator explicitly invoked. The wrapper only delegates.
The post-release target state is: orro 0.2.25 is published on PyPI. It becomes
true only after v0.2.25 is tagged and the Trusted-Publishing workflow completes;
until then, PyPI contains the ORRO product line through 0.2.24. This repository is
the canonical 0.2.25 source, whose metadata declares witnessd>=2.40.0,<3.0.0.
Package work must keep:
- pinned engine lock checks;
- bootstrap setup/fallback policy;
- pinned-engine e2e CI;
- no engine code in ORRO.
The self-test does not execute an engine command:
python3 -m pip install -e .
orro-wrapper self-testIt verifies the wrapper boundary, default delegation command parsing, and that
empty delegate invocations fail closed. It also reads the pinned witnessd
distribution's ORRO_COMMAND_MAP and packaged skill documents, then fails if a
public command named by either skill is absent from the engine map. An
intentional wrapper-only --no-deps packaging smoke reports that parity was not
checked because the engine metadata is absent; normal installs include witnessd
through the declared package dependency and run the parity check.
The local install smoke creates a temporary virtual environment, installs this
repository in editable mode, and verifies the installed orro and
orro-wrapper console scripts:
python3 scripts/check_orro_wrapper_install.py --jsonThe install smoke checks that both commands are installed, that boundary and self-test commands pass, and that explicit delegation works with a harmless Python command. The self-test reads witnessd's packaged command/skill metadata, but the smoke does not run proofrun, run proofcheck, call Depone, or publish a package.
The install smoke result is setup/test metadata, not proof, not verifier truth, not package publish, not approval, and not assurance.
The wrapper distribution smoke builds and installs a local wheel:
python3 scripts/check_orro_wrapper_distribution.py --json --allow-networkIt verifies that the wheel contains wrapper modules only, exposes orro and
orro-wrapper, and contains no Depone, witnessd, proofrun, proofcheck,
scheduler, observer, fan-in, team-ledger, or verifier implementation files.
The explicit network flag authorizes only pip build isolation for the wrapper's
declared build dependency.
The distribution smoke is local test metadata, not proof, not verifier truth, not package publish, not approval, and not assurance.