Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .machine_readable/Debtfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@ forgotten.
### docs-md-not-adoc
- description: Docs under docs/ still in Markdown; estate policy is AsciiDoc (.adoc) except the four GitHub-required .md files
- probe: git ls-files 'docs/**/*.md' 'docs/*.md' | grep -vEi '(SECURITY|CONTRIBUTING|CODE_OF_CONDUCT|CHANGELOG)\.md$' | wc -l
- count: 2
- count: 1
- ceiling: 1
- severity: low
- policy: remediable
Expand All @@ -39,7 +39,7 @@ forgotten.
### gate-scripts-without-tests
- description: Scripts under scripts/ with no matching scripts/tests/<name>-test.sh — a gate with no test has never been shown able to fail Re-baselined 2026-09-22 (round 2, issue #953): the committed count had fossilized at 31 while the tree measured 38+; set to measured 40 with a declared ceiling raise. Falls automatically as tests land.
- probe: n=0; for f in $(git ls-files 'scripts/*.sh'); do b=$(basename "$f" .sh); case "$b" in *-test) continue;; esac; if [ ! -f "scripts/tests/${b}-test.sh" ] && [ ! -f "scripts/tests/${b#check-}-test.sh" ] && [ ! -f "scripts/tests/${b#run-}-test.sh" ]; then n=$((n+1)); fi; done; echo "$n"
- count: 43
- count: 40
- ceiling: 40
- severity: high
- policy: remediable
Expand Down
4 changes: 2 additions & 2 deletions .machine_readable/REGISTRY.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -153,7 +153,7 @@ name = "AXEL Protocol"
stream = "protocol"
home = "2-protocols/axel/"
canonical_doc = "2-protocols/axel/README.adoc"
source_hash = "sha256:3074c2eb863fe42ff4e26fc85c2520bb40da2853af90b50a1908e111a8908db2"
source_hash = "sha256:84005883477e12b0c748bc9e7d68cbb309c199e4509fbfaed27b0454e773a88d"
route = "age-gating + explicit-content enforcement"

[[spec]]
Expand Down Expand Up @@ -270,7 +270,7 @@ name = "Standards Hypatia Rules"
stream = "integration"
home = "hypatia-rules/"
canonical_doc = "hypatia-rules/README.adoc"
source_hash = "sha256:b78a413b26148b04b2de9485d31514bd2ba6461832bb741c48010a58518afa29"
source_hash = "sha256:60a367489822dda378a6f0049add96a52f511777e08868c31f9b6a062134264d"
route = "the dogfooding rules that scan THIS repo (incl. drift detection)"

[[spec]]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,6 +44,6 @@ id = "S1"
text = "Known tensions SHOULD identify class, priority, containment, next action, and evidence status."
system = "manual document review"
status = "pass"
evidence = "0-canon/constitution/KNOWN-TENSIONS.adoc supplies all six fields for the twelve required tensions."
check = "test $(grep -c '^|.*|.*|.*|.*|.*|' 0-canon/constitution/KNOWN-TENSIONS.adoc) -eq 13"
evidence = "0-canon/constitution/KNOWN-TENSIONS.adoc supplies all six fields for the thirteen recorded tensions."
check = "test $(grep -c '^|.*|.*|.*|.*|.*|' 0-canon/constitution/KNOWN-TENSIONS.adoc) -eq 14"
effects = "Omission would allow unresolved policy questions to masquerade as implementation completion."
2 changes: 1 addition & 1 deletion ULTRAPLAN-2026-09-29.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -271,7 +271,7 @@ Keep the evidence, but do not treat as standards-repo implementation work unless
|https://github.com/hyperpolymath/standards/issues/309[#309] |2026-08-27 |[campaign] Python residual cleanup — ~45 estate-authored .py files remain (banned) |meta:recurring |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/323[#323] |2026-08-27 |[standing] Estate CodeQL cron drift detection + 6-week budget review |cicd, meta:campaign |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/324[#324] |2026-08-27 |[campaign] Long-tail non-canonical CodeQL cron sweep (~86 files / 30 repos) |cicd, meta:campaign |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/331[#331] |2026-09-08 |[campaign] Estate boj-build.yml sweep — repair or retire (~30 repos with malformed JSON + dead .local host + http://) |meta:campaign, refactor |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/331[#331] |2026-09-08 |[campaign] Estate boj-build.yml sweep — repair or retire (~30 repos with malformed JSON + dead .local host + plain HTTP) |meta:campaign, refactor |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/342[#342] |2026-08-26 |audit: contractiles estate state 2026-06-02 — schema drift + trident-claim/on-disk mismatch |meta:recurring, status:needs-owner |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/343[#343] |2026-09-03 |audit: dotfile drift across estate (2026-06-02 sample) — .editorconfig / .gitignore / .gitattributes |status:needs-owner |Carry-forward from 2026-09-24 plan
|https://github.com/hyperpolymath/standards/issues/348[#348] |2026-08-27 |automation: hypatia ruleset + gitbots should be able to fan-out doc + 6a2 + contractile refreshes themselves |automation, enhancement, governance |Carry-forward from 2026-09-24 plan
Expand Down
8 changes: 4 additions & 4 deletions docs/tier3-gate-probe.md → docs/tier3-gate-probe.adoc
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
# Tier 3 gate probe
= Tier 3 gate probe

Positive control for ruleset 23359343 `Optimus-Branch`, armed 2026-09-22.

Expand All @@ -8,13 +8,13 @@ registry, so a red result here is a fault in the gate, not in the change.

What this probe is meant to establish:

1. The four required contexts (`CodeQL`, `SonarCloud Code Analysis`,
. The four required contexts (`CodeQL`, `SonarCloud Code Analysis`,
`governance / Code quality + docs`, `uses ⊆ actions.lock`) all reach a
terminal state on a real pull-request head.
2. Whether the `code_scanning` rule passes when Scorecard has published no
. Whether the `code_scanning` rule passes when Scorecard has published no
analysis to `refs/pull/N/merge` — measured at 2 of 696 pull-ref analyses,
so this is the expected case rather than an edge case.
3. That `mergeStateStatus` reflects the ruleset, now that
. That `mergeStateStatus` reflects the ruleset, now that
`current_user_can_bypass` reads `never`.

Delete the branch once read. The measurement lives in `dev-notes`, not here.
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
#!/usr/bin/env bash
# SPDX-License-Identifier: MPL-2.0
#
# branch-gates-apply-test.sh — regression test for apply-branch-gates.sh.
# apply-branch-gates-test.sh — regression test for apply-branch-gates.sh.
#
# WHAT THIS PINS, AND WHY A PASSING SUITE WOULD NOT BE ENOUGH
# The defect this script exists to prevent is a VACUOUS GATE: a
Expand All @@ -15,7 +15,7 @@
# removed, and the suite must go RED. A mutant that survives means the
# corresponding control is decorative.
#
# Run: bash scripts/tests/branch-gates-apply-test.sh
# Run: bash scripts/tests/apply-branch-gates-test.sh
set -uo pipefail

SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
# SPDX-License-Identifier: MPL-2.0
# Regression suite for scripts/apply-protection-floor.sh
#
# House conventions, shared with scripts/tests/branch-gates-apply-test.sh:
# House conventions, shared with scripts/tests/apply-branch-gates-test.sh:
# * a `gh` shim maps an API path to a fixture by KEY=$(tr '/?&=' '____')
# * A MISSING FIXTURE IS A FREE ASSERTION that the path is never queried: the shim
# exits 1, so any code reaching for an unplanned endpoint fails loudly.
Expand Down
8 changes: 7 additions & 1 deletion scripts/tests/build-registry-test.sh
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,14 @@ cp "$ROOT/scripts/build-registry.sh" scripts/build-registry.sh

REG=".machine_readable/REGISTRY.a2ml"
TOP="TOPOLOGY.adoc"
# Carry the proposed artefacts too: a local regeneration must be testable
# before committing. Stage only in this throwaway clone so the mutation
# controls below restore these exact inputs with git checkout.
cp "$ROOT/$REG" "$REG"
cp "$ROOT/$TOP" "$TOP"
git add -- "$REG" "$TOP"

echo "== the committed artefacts are in sync with the committed tree =="
echo "== the proposed artefacts are in sync with the committed source tree =="
out="$(bash scripts/build-registry.sh --check 2>&1)"; rc=$?
if [ "$rc" -eq 0 ] && printf '%s' "$out" | grep -qF "OK:"; then
ok "--check reports OK on a clean checkout"
Expand Down
83 changes: 83 additions & 0 deletions scripts/tests/triage-2026-09-24-apply-test.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,83 @@
#!/usr/bin/env bash
# SPDX-License-Identifier: MPL-2.0
# Exercise the triage applier with an offline gh stub; never contact GitHub.
# Keep shell startup hooks from replacing the offline command stubs.
unset BASH_ENV ENV
set -euo pipefail
ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
TMP=$(mktemp -d)
trap 'rm -rf "$TMP"' EXIT
mkdir -p "$TMP/bin" "$TMP/temp with spaces"
export TRIAGE_TEST_LOG="$TMP/calls.jsonl"
export TMPDIR="$TMP/temp with spaces"
cat > "$TMP/bin/gh" <<'STUB'
#!/usr/bin/env bash
set -euo pipefail
case "$1 $2" in
'auth status') exit "${TRIAGE_TEST_AUTH_RC:-0}" ;;
'label list') printf '%s\n' scope:estate scope:repo priority:p1 ;;
'issue view')
if [[ " $* " == *' --json title '* ]]; then
echo 'Document the standard'
else
case "$3" in 89|913|956) echo OPEN ;; *) echo CLOSED ;; esac
fi ;;
'api repos/hyperpolymath/standards/issues/1/comments') echo 0 ;;
'api -X'|'issue comment'|'issue close')
jq -cn --args '$ARGS.positional' -- "$@" >> "$TRIAGE_TEST_LOG"
# Read payloads during the call, before the applier's cleanup.
args=("$@")
for ((i=0; i<${#args[@]}; i++)); do
case "${args[i]}" in
--input) jq -e '.labels | length > 0' "${args[i+1]}" >/dev/null ;;
--body-file) test -s "${args[i+1]}" ;;
esac
done ;;
*) echo "Unexpected gh invocation: $*" >&2; exit 2 ;;
esac
STUB
cat > "$TMP/bin/sleep" <<'STUB'
#!/usr/bin/env bash
exit 0
STUB
chmod +x "$TMP/bin/gh" "$TMP/bin/sleep"
export PATH="$TMP/bin:$PATH"
cd "$ROOT"

: > "$TRIAGE_TEST_LOG"
DRY_RUN=1 bash scripts/triage-2026-09-24-apply.sh > "$TMP/dry.log"
test ! -s "$TRIAGE_TEST_LOG"
test -z "$(find "$TMPDIR" -mindepth 1 -print -quit)"
grep -qF '[dry-run] gh api -X POST' "$TMP/dry.log"
grep -qF '[dry-run] gh issue comment 913' "$TMP/dry.log"
grep -qF '[dry-run] gh api -X PATCH' "$TMP/dry.log"
echo 'PASS: dry run previews commands, makes no write calls and cleans temporary files'

for run in 1 2; do
: > "$TRIAGE_TEST_LOG"
DRY_RUN=0 bash scripts/triage-2026-09-24-apply.sh > "$TMP/run.log"
jq -se '
([.[] | select(.[0:3] == ["api", "-X", "POST"])] | length) == 2 and
([.[] | select(.[0:2] == ["issue", "close"])] | length) == 1 and
([.[] | select(.[0:2] == ["issue", "comment"])] | length) == 1 and
([.[] | select(.[0:3] == ["api", "-X", "PATCH"])] | length) == 1 and
any(.[]; .[0:3] == ["issue", "close", "956"] and
any(.[]; startswith("Closed as fixed by #1034") and contains("\n\n"))) and
any(.[]; .[0:3] == ["api", "-X", "PATCH"] and
any(.[]; startswith("description=Canonical standards, specifications")) and
index("topics[]=policy-as-code") != null)
' "$TRIAGE_TEST_LOG" >/dev/null
jq -sr '[.[] | select(.[0:3] == ["api", "-X", "POST"])][0][-1]' \
"$TRIAGE_TEST_LOG" > "$TMP/path-$run"
test -z "$(find "$TMPDIR" -mindepth 1 -print -quit)"
done
! cmp -s "$TMP/path-1" "$TMP/path-2"
echo 'PASS: argument boundaries and payloads survive spaces; runs use distinct, cleaned directories'

: > "$TRIAGE_TEST_LOG"
if TRIAGE_TEST_AUTH_RC=1 DRY_RUN=0 bash scripts/triage-2026-09-24-apply.sh > "$TMP/fail.log"; then
echo 'FAIL: authentication failure was ignored' >&2; exit 1
fi
test ! -s "$TRIAGE_TEST_LOG"
test -z "$(find "$TMPDIR" -mindepth 1 -print -quit)"
echo 'PASS: preflight failure makes no writes and cleans its temporary directory'
40 changes: 23 additions & 17 deletions scripts/triage-2026-09-24-apply.sh
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,9 @@ set -uo pipefail
cd "$(git rev-parse --show-toplevel)"
REPO=hyperpolymath/standards
DRY=${DRY_RUN:-0}
run() { if [ "$DRY" = "1" ]; then echo "[dry-run] $*"; else eval "$@"; fi; }
run() { if [ "$DRY" = "1" ]; then echo "[dry-run] $*"; else "$@" >/dev/null; fi; }
TRIAGE_TMP=$(mktemp -d) || exit 1
trap 'rm -rf "$TRIAGE_TMP"' EXIT
pause() { [ "$DRY" = "1" ] || sleep 0.15; }

echo "== 0. preflight"
Expand Down Expand Up @@ -268,8 +270,8 @@ while IFS='|' read -r num disp; do
done
[ ${#want[@]} -eq 0 ] && continue
json=$(printf '%s\n' "${want[@]}" | jq -R . | jq -s .)
printf '{"labels":%s}' "$json" > /tmp/arena-label-body.json
if run "gh api -X POST repos/$REPO/issues/$num/labels --input /tmp/arena-label-body.json >/dev/null 2>&1"; then
printf '{"labels":%s}' "$json" > "$TRIAGE_TMP/arena-label-body.json"
if run gh api -X POST "repos/$REPO/issues/$num/labels" --input "$TRIAGE_TMP/arena-label-body.json" 2>/dev/null; then
labelled=$((labelled+1))
else
echo " label POST failed on #$num - continuing"
Expand All @@ -287,67 +289,67 @@ close_if_open() { # $1=number $2=reason-tag
local state=$(gh issue view "$n" -R "$REPO" --json state --jq .state 2>/dev/null) || return
[ "$state" = "OPEN" ] || { echo " #$n already $state - skipping"; return; }
if [ "$DRY" = "1" ]; then echo "[dry-run] close #$n"; else
gh issue close "$n" -R "$REPO" --comment "$(cat "/tmp/arena-close-$n.md")" >/dev/null \
gh issue close "$n" -R "$REPO" --comment "$(cat "$TRIAGE_TMP/arena-close-$n.md")" >/dev/null \
&& echo " closed #$n" || echo " close FAILED #$n"
fi
pause
}

cat > /tmp/arena-close-956.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-956.md" <<'EOF'
Closed as fixed by #1034 (2026-09-23). Verified via the rulesets API on 2026-09-24: the active ruleset `main gate: append-only + required checks + signatures + scanning` enforces 21 required status contexts, required signatures, and code-scanning thresholds on the default branch. Every gate this repo ships is now actually required here.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-637.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-637.md" <<'EOF'
Closed as absorbed: #787 (Owner decision sheet D1-D72) is "one answerable place for #637 + #715 + #709 + #658", so this register is superseded by it. Rulings continue on #787.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF
cp /tmp/arena-close-637.md /tmp/arena-close-709.md
cp /tmp/arena-close-637.md /tmp/arena-close-715.md
cp "$TRIAGE_TMP/arena-close-637.md" "$TRIAGE_TMP/arena-close-709.md"
cp "$TRIAGE_TMP/arena-close-637.md" "$TRIAGE_TMP/arena-close-715.md"

cat > /tmp/arena-close-784.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-784.md" <<'EOF'
Closed as answered: the census this issue was waiting for is #968 - 39 repos with step-level actions.lock desync (plus #969 for the job-level population). The hypothesis is no longer open.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-808.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-808.md" <<'EOF'
Closed as subsumed by #913: the 2026-09-22 census measured this same defect population at 76 `uses: ../../` refs, with acceptance criteria. The mis-triage knowledge from this issue (failure + 0 jobs + run name == path, indistinguishable from callee-lockfile poisoning) is preserved in a comment on #913 before this close. The fix continues under #913.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-708.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-708.md" <<'EOF'
Closed as fixed: the current `lockfile-drift-detect.yml` implements rc-honesty (1 = drift, 2 = usage/env error), per-repo slugs (no more anonymised `_w`), and counts tab-delimited data rows only (banner lines no longer counted as drift) - its comments cite this issue as the resolved reference. "Has only ever run once" is stale: the sweep runs weekly.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-658.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-658.md" <<'EOF'
Closed as superseded by the 2026-09-22 ruling (Deno banned outright; Bun is tier 1). The "migrate Deno to Bun" premise is replaced by Deno retirement: #919 sizes it (95 `deno task` definitions across 23 files in the 11 ledgered repos) and #926 covers the k9-coordination harness. Preserved data from this issue: 30 deno.json locations assessed, of which 18 were blocked on npm packages that do not exist.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-920.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-920.md" <<'EOF'
Closed as fixed: `rhodium-standard-repositories/.github/workflows/language-policy.yml` line 116 now reads "the JS runtime is Bun per the 2026-09-22 ruling, which banned Deno as well" (committed with the 2026-09-24 intake/canon changes). Remaining estate copies of the old comment sit in the template-sync population tracked under #659.

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-close-927.md <<'EOF'
cat > "$TRIAGE_TMP/arena-close-927.md" <<'EOF'
Closed as fixed: `:source-repo:` now points at https://github.com/hyperpolymath/standards (committed with the 2026-09-24 intake/canon changes).

(ULTRAPLAN-2026-09-24.adoc, part 5.2)
EOF

cat > /tmp/arena-913-preserve.md <<'EOF'
cat > "$TRIAGE_TMP/arena-913-preserve.md" <<'EOF'
Preserved from #808 (subsumed by this issue, closed 2026-09-24): why the malformed `uses: ../../` refs were invisible. A workflow that fails to parse produces the triple `conclusion=failure`, **0 jobs**, and a run `name` equal to its file *path* - the same triple produced by callee-lockfile poisoning. These were repeatedly mis-triaged as lockfile faults; they never parsed. Also: do not use `gh actions-lock` rewrite mode to fix these refs - it previously invented `uses: $/.github/actions/...` refs that fail the same way.
EOF
if [ "$(gh issue view 913 -R "$REPO" --json state --jq .state 2>/dev/null)" = "OPEN" ]; then
run "gh issue comment 913 -R $REPO --body-file /tmp/arena-913-preserve.md >/dev/null" \
run gh issue comment 913 -R "$REPO" --body-file "$TRIAGE_TMP/arena-913-preserve.md" \
|| echo " (913 preservation comment skipped/failed - continuing)"
fi

Expand All @@ -367,7 +369,11 @@ echo "2. closes done"
# 3. DESCRIPTION + TOPICS (ULTRAPLAN part 7)
# ---------------------------------------------------------------------------
DESC='Canonical standards, specifications and governance for the Hyperpolymath estate: policy-as-code, machine-readable specs (A2ML/DEED), and the reusable CI/CD + security canon for a 500+ repository software estate.'
run "gh api -X PATCH repos/$REPO -f description=\"$DESC\" -f topics[]=standards -f topics[]=specification -f topics[]=\"policy-as-code\" -f topics[]=governance -f topics[]=compliance -f topics[]=\"machine-readable\" -f topics[]=documentation -f topics[]=\"open-standards\" -f topics[]=deed -f topics[]=k9 -f topics[]=\"epistemic-computing\" -f topics[]=hyperpolymath >/dev/null"
run gh api -X PATCH "repos/$REPO" -f "description=$DESC" \
-f 'topics[]=standards' -f 'topics[]=specification' -f 'topics[]=policy-as-code' \
-f 'topics[]=governance' -f 'topics[]=compliance' -f 'topics[]=machine-readable' \
-f 'topics[]=documentation' -f 'topics[]=open-standards' -f 'topics[]=deed' \
-f 'topics[]=k9' -f 'topics[]=epistemic-computing' -f 'topics[]=hyperpolymath'
echo "3. description + topics set"

echo "done. (DRY_RUN=$DRY)"
Loading
Loading