citadel
The Citadel
tests/citadel/ is where Capsem records architectural mistakes that must not
be repeated. Guards are source-level, run in the fast phase, and each one
carries its reasoning in the failure message.
The organising idea is shape. Every guard here says: constrain the form so a property stays provable. A recipe is a dispatch. A module has a ceiling. A shell body is a sequence of simple commands. An enforcement line is the whole command. When shape lapses, something grows past the point where a tool, a reviewer or a test can take it in, and then nothing checks it at all.
Why it runs first
Every guard reads source and asserts on it. None needs an artifact, a VM or a
daemon. They were reachable only through the broad suite's root, which
carries require_artifacts and runs after the whole asset build -- so a
DB-boundary violation surfaced once the VMs were up, roughly forty minutes
after the source that caused it was read.