Skip to content

improve-modularity: split SDL security-monitoring, semantics & evidence modules (4 files) #51

Description

@Brad-Edwards

Part of #3 (modularity initiative tracker).

Context (re-scoped 2026-07-30)

Since this issue was filed the codebase moved out from under its original text, so it has been re-scoped:

No behavior change. Each file becomes a package directory behind an API-stable re-export shim.

Files (this issue)

File Lines (origin/dev) Import module
implementations/python/packages/raes/runtime_security_monitoring.py 515 raes.runtime_security_monitoring
implementations/python/packages/raes/semantics/objective_semantics.py 573 raes.semantics.objective_semantics
implementations/python/packages/raes/semantics/participant_behavior.py 1401 raes.semantics.participant_behavior
implementations/python/packages/raes_operations/_evidence_run_artifact.py 611 raes_operations._evidence_run_artifact

Note: raes/semantics/participant_behavior.py (this issue) is distinct from raes/participant_behavior.py (issue #52) — they are different modules at different paths. _evidence_run_artifact.py is a leading-underscore module; the package/__init__ re-export pattern applies to it unchanged.

Mechanics (per file)

  1. Read the file. Identify cohesive subdomains by clustering classes/functions that share concepts, types, or call relationships.
  2. Convert the file to a Python package: replace <path>.py with a directory of the same base name <path>/.
  3. Move code into subdomain files <path>/<subdomain>.py. Each subdomain file MUST be ≤ 500 lines.
  4. <path>/__init__.py re-exports the public API — every name imported from the original module anywhere else in the codebase, plus any names in __all__.
  5. For each module, run git grep -E "from <module>|import <module>" (e.g. git grep -E "from raes.semantics.participant_behavior|import raes.semantics.participant_behavior") to enumerate every external import site. Confirm zero of those lines need to change.
  6. Remove the file's entry from tools/policy/oversized_allowlist.yaml.

Acceptance criteria

  • Each file above no longer exists as a .py; a package directory with __init__.py exists in its place.
  • Every .py file under each new package directory is ≤ 500 lines (verified by tools/check_repo_policy.py after the paths are removed from the allowlist).
  • No external import line referencing any of these four modules was modified by this PR (verified by diff inspection during clause verification).
  • tools/policy/oversized_allowlist.yaml no longer contains any of the four files above.
  • uv tool run --from 'nox[uv]==2026.4.10' nox -f noxfile.py -s verify passes.
  • No pre-existing test was modified to make the suite pass.
  • CHANGELOG.md has an entry for this change.

Out of scope

  • Any behavior change. This is a pure refactor — equality of public API and equality of behavior under the existing test suite is the contract.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions