Skip to content

docs: affirm state at 465cec6 (AFFIRMATION, profile A) - #69

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-2026-10-07
Oct 7, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-2026-10-07

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Adds docs/AFFIRMATION.adoc, a profile A (evidential) affirmation under standards docs/AFFIRMATION-STANDARD.adoc. It is anchored to main at 465cec698878c4eaf427c073e3c5e4b21c0f5f68. Every claim in it comes from live runs at that commit on 2026-10-07T10:27:03Z.

Changes

  • New docs/AFFIRMATION.adoc:
    • Solid: bin/jaffa check and compile work on examples/hello.affine and produce valid wasm. A planted unresolved name is rejected. Workflow validation passes.
    • Outstanding, all found by this run:
      • the README's jaffa eval examples/hello.affine fails with "Unhandled effect: println";
      • just refuses to run because both Justfile and justfile exist;
      • the aspect FAIL is a false positive on text that forbids sorry/Admitted;
      • tests/e2e.sh checks nothing (PASS=0);
      • the template recipes echo "passed" without running anything;
      • 1 non-required red check, tracked in CI: 1 red check(s) on the default branch, deferred from #65 #66.
    • The toolchain is recorded honestly as a local affinescript 0.1.1 build from a dirty branch.

📌 New pins

Head SHA: b08c8fa. This PR adds no pins: no action uses: SHAs, no actions.lock entries, no lockfile or container changes.

RSR Quality Checklist

Required

  • Tests pass (just test): just cannot run here (two justfiles), and the test recipe is a stub, as the affirmation says. The real checks that were run are listed under Testing.
  • Code is formatted: n/a, no code changed.
  • Linter is clean: n/a, no code changed. There is no real lint recipe.
  • No banned language patterns. Only an AsciiDoc file is added.
  • No unsafe without // SAFETY:: n/a, no code.
  • No banned functions. The prose names sorry/Admitted only to describe the scanner false positive.
  • SPDX header present: CC-BY-SA-4.0. LICENSES/CC-BY-SA-4.0.txt exists.
  • No secrets, credentials or .env files.

As Applicable

  • STATE/ECOSYSTEM/META: not changed. This records state; it does not change it.
  • Documentation updated: the affirmation itself.
  • TOPOLOGY, CHANGELOG, dependencies, ABI/FFI: n/a, none changed.

Testing

  • bin/jaffa check|compile|eval examples/hello.affine and a planted-error control, run on the anchor commit (results in the file).
  • bash tests/aspect_tests.sh gives PASS=2 FAIL=1. bash tests/workflows/validate_workflows_test.sh rc=0.
  • The standards gate .github/actions/affirmation-check/check.sh reports "Affirmation commit signature verified with a trusted key", then "AFFIRMATION document validation passed".
  • The commit is G (signed), and its parent equals the anchor (465cec6).

Screenshots

n/a.

🤖 Generated with Claude Code

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

Profile A affirmation per standards docs/AFFIRMATION-STANDARD.adoc; every
claim produced by live runs at the anchor commit on 2026-10-07.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 99e6ecdb-0bb5-4c85-8bdb-c6c7bf9c8a45
📥 Commits

Reviewing files that changed from the base of the PR and between 465cec6 and b08c8fa.

📒 Files selected for processing (1)
  • docs/AFFIRMATION.adoc
 ________________________________________________________________________________
< Please don't use comments to explain what code should be doing. Make it do it. >
 --------------------------------------------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 7, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 75 issues detected

Severity Count
🔴 Critical 6
🟠 High 26
🟡 Medium 43

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 24,
    "reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/mirror.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/mirror.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 64,
    "reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/mirror.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 84,
    "reason": "job in .github/workflows/mirror.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/mirror.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 1ff2314 into main Oct 7, 2026
13 of 15 checks passed
@hyperpolymath
hyperpolymath deleted the docs/affirmation-2026-10-07 branch October 7, 2026 10:33
hyperpolymath added a commit that referenced this pull request Oct 7, 2026
)

## Summary

Marks the AFFIRMATION landed in #69 as an **agent-authored DRAFT, not
affirmed by the owner**. It adds a `:status:` attribute and a visible
`[IMPORTANT]` block. The owner's rule (dev-notes
`for-jonathan-todo.adoc` §7, 2026-10-07) is that an agent must not sign
an affirmation. #69 was committed by an agent with the machine key, so
it does not carry the owner's affirmation. Owner chose this correction
on 2026-10-07. No claim in the file changes.

## Type of change

- [x] 📖 Documentation. Two status lines only.

## 📌 New pins

Head SHA: **dff2f0e3d3bde80ac96a866d2740b1b3602cf422**. No pins are
added or changed.

## How has this been verified?

- `git diff` shows 8 lines added and 0 removed.
- The commit is `G` (signed). This status-marker commit is agent-signed
by design; the owner's affirmation is still to come.
- The standards `affirmation-check/check.sh` shows the document passes
its content checks. Locally, signature verification reports the previous
squash commit's GitHub web-flow signature as unverifiable, because the
GitHub key is not in the local keyring. Treat that as a limit of the
local copy, not a verdict.

## Checklist

- [x] My commits are **signed**.
- [x] No code changed. The only check that bears on this change is the
affirmation checker (above).
- [x] SPDX: the existing `CC-BY-SA-4.0` header is unchanged.
- [x] No public claim now overstates anything. This PR exists to remove
an overstatement.
- [x] No soundness hole introduced.

## Notes for reviewers

Next step for the owner: once you have reviewed the file, re-anchor it,
then land it with `git commit -S` and remove the DRAFT lines.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant