diff --git a/.github/workflows/governance-reusable.yml b/.github/workflows/governance-reusable.yml index 85395a041..0f13910e7 100644 --- a/.github/workflows/governance-reusable.yml +++ b/.github/workflows/governance-reusable.yml @@ -1387,7 +1387,7 @@ jobs: # review in their repositories. This pin is invisible to the caller's # `uses:` ref and to actions.lock — it is a third, independent pin, # which is precisely how it went stale across standards#946. - ref: 9c256b67486b4b30c757730e1b65b2c2d2af935b + ref: 5f82b635c5da5c3df44d5a0caa8983d9b95e0db9 path: .standards-lock persist-credentials: false sparse-checkout: | diff --git a/.github/workflows/uuid-v7.yml b/.github/workflows/uuid-v7.yml index dc6708dfd..1d20279f4 100644 --- a/.github/workflows/uuid-v7.yml +++ b/.github/workflows/uuid-v7.yml @@ -4,15 +4,21 @@ name: UUID v7 conformance on: push: + branches: [main] pull_request: permissions: contents: read +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: true + jobs: uuid-v7: name: Reject non-v7 UUID literals runs-on: ubuntu-latest + timeout-minutes: 10 steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/.machine_readable/REGISTRY.a2ml b/.machine_readable/REGISTRY.a2ml index 763f73517..82172235a 100644 --- a/.machine_readable/REGISTRY.a2ml +++ b/.machine_readable/REGISTRY.a2ml @@ -207,7 +207,7 @@ name = "RSR — Rhodium Standard Repositories" stream = "governance" home = "rhodium-standard-repositories/" canonical_doc = "rhodium-standard-repositories/README.adoc" -source_hash = "sha256:bc9c99e1d48f9b6ca6985fc705976ed0fee560d60c1d3259e1647a382b76a1e1" +source_hash = "sha256:51b38eb327df7ea430078bd75566d15ab9a6618f19a3b9ee7c2a1cfb8ce6adda" route = "the repository-compliance standard every repo is graded against" [[spec]] diff --git a/ULTRAPLAN-2026-09-24.adoc b/ULTRAPLAN-2026-09-24.adoc deleted file mode 100644 index 8f0a578ee..000000000 --- a/ULTRAPLAN-2026-09-24.adoc +++ /dev/null @@ -1,1665 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -= ULTRAPLAN 2026-09-24 — the issue influx, its root cause, and the reconciliation -Jonathan D.A. Jewell -v1.0.0, 2026-09-24 -:toc: -:toclevels: 2 -:icons: font - -Status: *complete as written* — the analysis in parts 1–4 is a census; part 5 -records the actions: the repository changes are committed on the working -branch, and the live GitHub actions (labels, closes, description/topics) are -packaged as one idempotent owner-run script because the agent token used for -this work has `labels:write` but not `issues:write`/repo-admin (see 5.2). -Part 6 states what is fixed and what is not; parts 7–8 are the forward plan. -Every number below was measured on 2026-09-24 (~14:30 UTC) with the commands -in Appendix A. - -== 0. TL;DR - -* The "explosion" is real and bounded: *91 issues filed on 2026-09-22 and 7 on - 2026-09-23*, on top of 95 filed over the preceding four months. Total open: - *193*. 192 of 193 were filed by the owner, essentially all of them with an AI - coding agent doing the drafting. -* The explosion was *not* a bot malfunction. The only automated filer that - exists (lockfile-drift-detect) is working exactly as designed — one issue, - updated in place. The explosion was a *process* failure: an AI-assisted - estate audit filed **one issue per finding, with no deduplication, no scope - filter, and no umbrella**, in a repository that had no intake rules at all. -* Roughly *one third of the backlog does not belong in this repository*: its - actionable fix lives in other repos, in org rulesets, or in upstream tools. - This repo was being used as a de facto inbox for a ~570-repo estate. -* Fixed at the source in this action: the missing intake specification - (link:docs/ISSUE-INTAKE-SPEC.adoc[ISSUE-INTAKE-SPEC v1.0.0]), mandatory issue - templates with the blank form disabled, a rewritten `0-canon/GOVERNANCE.adoc` - (it was a broken AI-generated placeholder describing a governance model that - does not exist), two spec-drift defects closed in canon (#927, #920), the - full 193-issue backlog classified, and the optimised description + topics. - The mechanical follow-through — labelling all 193 and *closing 10 issues - with evidence comments* (6 fixed or superseded, 4 absorbed into the - decision register) — ships as - `scripts/triage-2026-09-24-apply.sh`: one idempotent command the owner runs - with full credentials (the agent token lacks `issues:write`). -* What remains is ranked in part 8. The single highest-leverage owner action - is answering the batched decision sheet (#787) — one reply resolves a dozen - rulings. - -== 1. State of the house (census, 2026-09-24) - -[cols="2,4,2",options="header"] -|=== -|Measure |Value |Note - -|Open issues -|193 -|`gh issue list --state open` (limit 1000); matches the API `open_issues_count` - -|Closed issues -|174 -|state=closed census - -|Open PRs -|0 -|none open; the "48 Dependabot PRs" of #1037 are in *other* repos - -|Issues filed 2026-09-22 -|91 -|the explosion day (#894–#1028 range) - -|Issues filed 2026-09-21 / 23 -|4 / 7 -|the wave started the 21st and continued the 23rd - -|Issues filed 2026-05-17 … 09-20 -|95 -|the steady drumbeat: ~1.3/day for four months - -|Authors (open) -|hyperpolymath 192, github-actions 1 -|the bot issue is #803, the lockfile-drift tracking issue - -|Required checks on main -|21 contexts + signatures + code scanning -|ruleset `main gate: append-only + required checks + signatures + scanning`, -enforcement *active*, landed in #1034 (2026-09-23) - -|CI at HEAD c56f4ec -|green -|Governance, CodeQL, Hypatia, gitleaks, rust-ci etc. all succeeded on the -last main push - -|Labels defined / issues carrying one -|66 / a minority -|the taxonomy exists and an auto-labeler (`label-triage.yml`) fires on *new* -issues only; the existing backlog is mostly unlabelled -|=== - -== 2. What actually happened (the timeline) - -[cols="14,8,78",options="header"] -|=== -|Date |Issues |What - -|2026-05-17 … 06-27 -|28 -|First campaigns filed: boj/isers epics, TS/ReScript migration umbrellas -(#239, #252), estate sweeps (CodeQL cadence, .scm to .a2ml, Python residue), -Pages decisions. Healthy rate, one defect per issue. - -|2026-06-28 … 07-16 -|9 -|Carve-out of this repo (keep the canon, evict products) #479 and its steps; -badges framework #446; licensing cascade #404. - -|2026-08-25 … 08-31 -|~25 -|First audit *wave*: estate control plane #633–#637, lockfile/pin forensics -#657–#670, estate health #675–#681, owner-decision batches #709. - -|2026-09-02 … 09-17 -|~13 -|Second wave fragments: O1–O10 #715, decision sheet #787 (the good part — a -*batched* register), pin-campaign forensics #784/#792/#795. - -|2026-09-21 -|4 -|Wave start: ruleset findings #887–#890. - -|*2026-09-22* -|*91* -|*The explosion.* A CI/CD pipeline delivery + estate audit, run with an AI -agent, produced checkpoint documents -(`developer/.claude/checkpoints/2026-09-22-cicd-pipeline-delivery.md` and -companions — which "duplicated each other and disagreed on the number (3 vs -6)" per #904's own body) and every finding was filed as a separate issue: -#894–#1028. Clusters: the actions.lock machinery (~15), Hypatia findings -(~10), Deno/Bun policy (~12), rulesets/org settings (~10), KYAML campaign -(5), Nickel/K9 defects (4), debtfile mechanics (4), the rest estate-wide. - -|2026-09-23 -|7 -|Wave continuation (#1031–#1040) + #1034 landing the branch/tag protection -floor on main (which already retires several open findings — see #956 below). -|=== - -Two properties of the explosion matter for the diagnosis: - -. *It was a filing model, not a broken tool.* Every one of the 91 issues is - a real, measured finding with evidence and acceptance criteria. The defect - is the 1:1 finding-to-issue ratio applied without a filter. -. *It was the fifth consecutive audit wave* in a month. The first four were - smaller because they were not yet running a full pipeline audit; the model - was the same. Without the intake rules now in place, a sixth wave would - have re-inflated the backlog in the same shape. - -== 3. Root cause analysis - -=== 3.1 Direct cause - -The 2026-09-22 audit filed findings with no intake discipline: - -. *No deduplication against the open backlog.* 95 issues were already open, - several on the same components (the actions.lock machinery alone already - had #657/#669/#670/#674/#707/#708/#727 open when the wave added at least six - more overlapping issues on it). -. *No scope filter.* Estate-wide findings — org rulesets, other repos' - workflows, upstream tool behaviour — were filed *here*, because the agent - had this repository open. About one third of the wave is this class (see the - ESTATE rows in part 4). -. *No umbrella.* A 91-issue wave had no `meta:campaign` tracking issue, so - nothing could report wave progress or close the wave as a unit. -. *Lossy source documents.* The findings were drafted from two checkpoint - notes that duplicated each other and disagreed; the filed text resolved - some of the disagreements (in #904's favour of "6") but the source drift - itself was never recorded as a defect. - -=== 3.2 Contributing structural factors (all now addressed or addressed-by-design) - -[cols="3,7",options="header"] -|=== -|Factor |State after this action - -|No intake specification existed -|*Fixed* — link:docs/ISSUE-INTAKE-SPEC.adoc[ISSUE-INTAKE-SPEC v1.0.0] -(defines scope rules, dedup obligation, wave-umbrella rule, automation -contract, no-silent-closes) - -|No issue templates; blank form open -|*Fixed* — bug / decision / campaign templates; blank form disabled via -`.github/ISSUE_TEMPLATE/config.yml` - -|This repo doubling as the estate's inbox -|*Named and constrained* — Intake Spec Rule 1 (scope filter) + Rule 1's -pointer to the estate register; the backlog table in part 4 marks every -estate-wide row so the owner can migrate them deliberately - -|Label taxonomy + auto-labeler existed but only prospective -|*Partially fixed* — the existing 193 were classified and labelled in this -action (part 5); the auto-labeler (`label-triage.yml`) continues to cover new -issues. A retroactive backfill job is a candidate for the next fix wave - -|`0-canon/GOVERNANCE.adoc` was a generic placeholder (fictional -"2 maintainers" approval rule, broken document tail) that contradicted the -real constitution -|*Fixed* — v2.0.0 rewritten to summarise the Constitutional District without -inventing governance - -|No codified "estate register" for cross-repo findings -|*Conventionalised* — the open `meta:umbrella` + `decision` issue (#787) is -named as the register in the Intake Spec; making it a file (e.g. in the -estate repo) is a follow-up, not a blocker -|=== - -=== 3.3 What was NOT the cause (checked, ruled out) - -* *The automated detectors.* `lockfile-drift-detect.yml` (Tue 07:20) and - `settings-drift-detect.yml` (Mon 06:40) are "REPORTS ONLY" by design and each - maintains *exactly one* tracking issue, edited in place. The only - bot-filed issue in the repo's history is #803. They are the *correct* shape - of automated issue-filing; the Intake Spec (Rule 6) now codifies that shape - as the contract for any future detector. -* *Dependabot.* Zero open PRs in this repo. #1037's 48 PRs are in 15 *other* - repos (where the `codeql-action` hold in `dependabot.yml` was bypassed by - #977 on 2026-09-22 — that file's comment records the incident). -* *CI.* Main is green at HEAD; the required-checks floor landed in #1034. - There is no runaway pipeline filing issues. - -=== 3.4 The "AI sprawl" pattern, precisely - -AI drafting makes each additional finding near-free: the cost of a 91st issue -is the same as the cost of a 3rd. Without a *mechanical* filter — a template -that forces evidence, a dedup field the filer must fill, a scope dropdown, an -umbrella reference — volume scales with the audit's ambition, not with the -defect count. The fix is therefore not "instruct the AI to be careful" -(instructions drift; the checkpoint notes prove it); the fix is putting the -filter in the mechanism, which is exactly what the templates and the Intake -Spec do. The quality of the wave's *investigation* was high and is worth -keeping; only the *filing* is what changed. -== 4. The full backlog: 193 issues, classified - -[NOTE] -==== -Every open issue on 2026-09-24 is listed exactly once below (verified -mechanically against the API census). Disposition codes: - -*KEEP* - open, actionable in this repo; label scope:repo. -*ESTATE* - estate-wide; belongs in the estate register, not this repo's actionable backlog; label scope:estate. -*DECIDE* - blocked on an owner ruling; belongs in the #787 register. -*VERIFY* - recent work (chiefly #1034) suggests it is already fixed; verify, then close. -*PARK* - deliberately deferred. -*CLOSED* - closed by this action, with the reason in the closing comment. -==== - -=== Cluster C1: Language & runtime policy (Deno to Bun, TS/ReScript bans, Python) (23 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#239 -|[campaign] TypeScript → AffineScript estate migration (UMBRELLA) -|PARK -|TS to AS umbrella; subsumed by 2026-08-27 TS retirement ruling - keep as historical pointer only -|#252 -|[campaign] ReScript → AffineScript estate migration (UMBRELLA) -|ESTATE -|ReScript to AS umbrella; still cited by language-policy.yml gate - the campaign register for that migration -|#272 -|[campaign #252] STEP 5 — TAIL BATCH: smallest tail-end repos (≤20 -|ESTATE -|[252] step 5 tail batch -|#276 -|[campaign #252] STEP 6 — MID-TIER: 20-100 file repos (~15 repos) -|ESTATE -|[252] step 6 mid-tier -|#278 -|[campaign #252] STEP 7 — LARGE REPOS: 100-500 file repos (~6 repos) -|ESTATE -|[252] step 7 large repos -|#279 -|[campaign #252] STEP 8 — MEGAPORT: idaptik (516, was 1235) + panll ( -|ESTATE -|[252] step 8 megaport -|#309 -|[campaign] Python residual cleanup — ~45 estate-authored .py files r -|ESTATE -|Python residual cleanup, ~45 estate files -|#658 -|Deno→Bun: all 30 deno.json locations assessed — 18 blocked on npm -|CLOSED -|superseded by the 2026-09-22 Deno-ban ruling; successors #919/#926 (key blocker data preserved in closing comment) -|#659 -|Language policy is duplicated into ~372 per-repo CLAUDE.md files acros -|ESTATE -|372 per-repo CLAUDE.md files; canonical here, propagation estate -|#663 -|TypeScript retirement: measured — 308 of 613 .ts files were never ex -|ESTATE -|TS retirement measurement (308 of 613 never exempt) -|#664 -|43% of estate .affine files are 200-byte Harvard Engine stubs — migr -|ESTATE -|43% of .affine files are 200-byte stubs -|#698 -|Banned languages appear in dev-environment definitions (guix.scm ×14, -|ESTATE -|banned languages in dev-environment definitions (guix.scm x14, mise.toml) -|#704 -|examples/web-project-deno.json template ships phantom npm:affinescript -|KEEP -|deno.json template ships phantom npm:affinescript - examples/ is in this repo -|#706 -|mise.toml pins banned toolchains estate-wide — python in 543/573 fil -|ESTATE -|mise.toml pins banned toolchains, 543/573 files -|#905 -|runtime-policy.yml's Deno branch emits only ::warning:: and cannot fai -|KEEP -|runtime-policy.yml Deno branch warn-only - seed here -|#917 -|234 .pre-commit-config.yaml files depend on Python, which LANGUAGE-POL -|ESTATE -|234 .pre-commit-config.yaml depend on Python; estate-wide -|#919 -|Deno retirement sizing: 95 'deno task' definitions across 23 files in -|ESTATE -|Deno retirement sizing (95 deno tasks, 11 ledgered repos) -|#920 -|language-policy.yml:116 comment names Deno as npm's replacement; the r -|CLOSED -|fixed - language-policy.yml:116 comment corrected to Bun (this action); estate copies via template sync (#659 population) -|#921 -|55 agent-instruction files assert 'TypeScript IS PERMITTED under Bun', -|KEEP -|55 agent-instruction files assert TS permitted under Bun - canonical here, propagation estate -|#922 -|No pinned Bun lint/format gate: staged JavaScript is a declared skip -|KEEP -|no pinned Bun lint/format gate - this repo -|#925 -|check-ts-allowlist.deno.js cannot be deleted: 11 of the last 12 govern -|KEEP -|check-ts-allowlist.deno.js still invoked by 11 of last 12 governance revisions - this repo -|#926 -|k9-coordination-protocol vendors a Deno test harness: 260 Deno API lin -|KEEP -|k9-coordination-protocol Deno test harness, 260 lines - this repo (2-protocols/) -|#928 -|language-policy.scm v2.0.0 has no wired regression test (needs a decis -|KEEP -|language-policy.scm v2.0.0 has no regression test - this repo; needs guile-in-CI decision -|=== - -=== Cluster C2: actions.lock & pin campaign (incl. Dependabot / codeql 4.38.1) (19 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#657 -|MEASURED: a lockfile policy kills 77% of dead workflows — the wiped -|ESTATE -|lockfile policy measurement (kills 77% of dead workflows) -|#669 -|Orphaned/phantom action pins still live post-remediation: dtolnay ×35 -|ESTATE -|orphaned/phantom action pins estate-wide -|#670 -|Dependabot bumps uses: without regenerating actions.lock — every rem -|ESTATE -|Dependabot bumps without lock regen; mechanism behind #803 -|#707 -|Phantom upload-artifact pin ea165f8d65b6db9a… (commit never existed, -|ESTATE -|phantom upload-artifact pin, 11 repos -|#727 -|gh actions-lock fix mode prepends its banner above the SPDX header — -|ESTATE -|gh actions-lock banner vs SPDX header (upstream tool behaviour) -|#784 -|Pin campaign may have startup-killed every repo carrying a stale actio -|CLOSED -|hypothesis answered by #968 census (39 repos, step-level desync) -|#803 -|lockfile drift: 15 repo(s) as of 2026-09-22 -|ESTATE -|bot tracking issue (lockfile-drift-detect); stays open while drift exists -|#903 -|actions-lock cliff: ENFORCE_ACTIONS_LOCK_FROM=2026-10-01 reddens 163 c -|KEEP -|ENFORCE_ACTIONS_LOCK_FROM=2026-10-01 cliff reddens 163 callers - spec here; ruling needed; time-bounded -|#909 -|actions.lock never covers denoland/setup-deno -|KEEP -|actions.lock never covers denoland/setup-deno - this repo -|#916 -|setup-deno pins are inconsistent and some look fabricated: one SHA lab -|KEEP -|setup-deno pins inconsistent, one SHA labelled four tags - this repo -|#924 -|rsr-template-repo has 62 unpinned workflow refs, including two @main a -|ESTATE -|rsr-template-repo 62 unpinned workflow refs -|#963 -|main is red: actions.lock omits a transitive dependency of asana/push- -|VERIFY -|actions.lock omits transitive dep; main green at HEAD - verify and close -|#968 -|actions.lock step-level desync: 39 repos with silently dead CI (startu -|ESTATE -|step-level desync census: 39 repos (answers #784) -|#969 -|actions.lock omits job-level reusable refs in 159 repos (no runtime im -|ESTATE -|job-level refs unreported in 159 repos; tracks upstream #129 -|#987 -|Phantom blob-pin: 18 refs across 7 repos pin standards reusable workfl -|ESTATE -|phantom blob pins: 18 refs across 7 repos (the guard is itself blob-pinned) -|#991 -|AC4 arming policy: retired-filename blocks, stale-version warns (each -|DECIDE -|AC4 arming policy (retired-filename blocks, stale-version warns) -|#993 -|actions.lock policy: job-level reusable refs are reported, never requi -|KEEP -|job-level refs reported, never required (policy text) - this repo -|#1005 -|Supply chain: 75 estate pins are spelled v4.38.0 but are the v4.38.1 t -|ESTATE -|75 estate pins spelled v4.38.0 but are the v4.38.1 target (estate-blocked) -|#1037 -|48 open Dependabot PRs re-introduce the codeql-action v4.38.1 startup- -|ESTATE -|48 open Dependabot PRs re-introduce codeql v4.38.1 in 15 repos; dependabot.yml hold bypassed -|=== - -=== Cluster C3: CI/CD gates & workflow defects (this repo) (31 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#346 -|governance: hoist bridge-forbidden-phrases check into reusable workflo -|KEEP -|hoist bridge-forbidden-phrases into reusable workflow - this repo -|#409 -|promote CI-CRITICALITY tiers (Gate/Check/Advisory/Auto) → standards -|KEEP -|promote CI-CRITICALITY tiers into standards + rsr-template - this repo -|#708 -|Lockfile Drift Detect anonymizes repos as _w, counts banners as entrie -|CLOSED -|fixed - workflow implements rc honesty + slug + banner fixes and cites #708 as resolved -|#791 -|githooks: validate-a2ml admits 0 of 222 files and validate-spdx reject -|KEEP -|githook validators never run against own corpus - this repo -|#808 -|RSR workflow templates use an illegal `uses: ../../` ref — every ins -|CLOSED -|subsumed by #913 (2026-09-22 census measured the same defect, 76 refs); mis-triage triple preserved in comment on #913 -|#894 -|Gate table + criterion 1.2.1 ignore manifest.scm (estate Guix conventi -|KEEP -|gate table + criterion 1.2.1 ignore manifest.scm - this repo -|#895 -|Gate format cannot express partial modules or nested layouts (2 concre -|KEEP -|gate format cannot express partial modules / nested layouts - this repo -|#896 -|changelog-reusable can never start: called-job write perms are checked -|KEEP -|changelog-reusable caller write-perm check - this repo -|#904 -|run_validator() is fail-open: 6 validators named by rsr-template-repo' -|ESTATE -|rsr-template-repo pre-commit fail-open; validator copies are here -|#906 -|workflow-lint's lock regex is blind to '- uses:' list items, so its gr -|KEEP -|workflow-lint lock regex blind to list items - this repo -|#907 -|check-actions-lock-gate.sh unconditionally exempts actions/github-scri -|KEEP -|check-actions-lock-gate.sh exempts actions/github-script - this repo (security) -|#908 -|root-allow.txt is registered in the exemption ratchet but absent on di -|KEEP -|root-allow.txt registered in ratchet but absent on disk - this repo -|#910 -|governance-reusable.yml still has 7 'ref: main' helper checkouts reach -|KEEP -|governance-reusable.yml 7 ref:main helper checkouts - this repo -|#911 -|shell-e2e-reusable.yml has the repo's only 2 unpinned refs (owner's st -|KEEP -|shell-e2e-reusable 2 unpinned refs (owner's staged work; report only) -|#913 -|76 'uses: ../../...' relative refs in vendored seeds are invalid synta -|KEEP -|76 malformed uses: ../../ refs in vendored seed - this repo; startup-death class -|#914 -|46 genuinely unpinned third-party refs in the vendored seed trees -|KEEP -|46 unpinned third-party refs in vendored seed - this repo -|#930 -|actions-lock gate's remedy text names a repo-relative path that exists -|KEEP -|actions-lock gate remedy text names a path that exists in no consumer - this repo -|#932 -|validate-lint-format.sh: Rust and Nickel arms ask a different question -|KEEP -|validate-lint-format.sh Rust/Nickel arms ask a different question - this repo -|#935 -|actions-lock gate is permanently red on main, and its remediation cont -|VERIFY -|claims gate permanently red on main; main green at HEAD c56f4ec - verify and close -|#964 -|governance-reusable.yml dupkey helper pin 317101e0 is stale by 45 file -|KEEP -|governance-reusable dupkey helper pin stale by 45 files - this repo -|#967 -|ci-pipeline detect is blind to 56 code-bearing repos (and probes Deno, -|KEEP -|ci-pipeline detect blind to 56 code-bearing repos; probes Deno not Bun - this repo -|#972 -|pre-commit hands validators git-QUOTED paths, so non-ASCII filenames a -|KEEP -|pre-commit hands validators git-quoted paths - this repo -|#976 -|detect: the Nickel probe matches RSR template boilerplate, silencing t -|KEEP -|Nickel probe matches RSR boilerplate, silencing zero-denominator refusal - this repo -|#980 -|ci-pipeline.yml: the ledger pin's "same commit" invariant is unsatisfi -|KEEP -|ci-pipeline ledger pin "same commit" invariant unsatisfiable (12/12 squash) - this repo -|#981 -|validate-actions-lock prescribes a cure that can re-legitimise a block -|KEEP -|validate-actions-lock cure can re-legitimise a blocked version - this repo -|#992 -|check-lock-sync.sh and GitHub startup disagree for job-level-reusable- -|KEEP -|check-lock-sync vs GitHub startup disagree; gate error text inverted - this repo -|#994 -|Cross-cutting governance reds surfaced by the actions.lock cure — 9 -|KEEP -|cross-cutting governance reds, 9 classes across 17 PRs - this repo -|#998 -|ci-pipeline.yml: standards does not call its own pipeline (AC6 of #986 -|KEEP -|standards does not call its own ci-pipeline (AC6 of #986) - this repo -|#1010 -|ci: retire the dead A2ML validation gate (13 repos — the renamed-act -|ESTATE -|retire dead A2ML validation gate, 13 repos; gate source is here -|#1015 -|check-action-pins-resolve.sh scans prose: a documentation example SHA -|KEEP -|check-action-pins-resolve.sh scans prose (doc example SHA fails gate) - this repo -|#1018 -|rust-ci-reusable: explicit ref refs/pull/N/merge dies when the PR merg -|KEEP -|rust-ci-reusable: refs/pull/N/merge dies when PR merges mid-run - this repo -|=== - -=== Cluster C4: Hypatia scanner findings (this repo) (11 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#687 -|audit(hypatia): classify 61 structural-drift and canonical-home findin -|ESTATE -|classify 61 structural-drift findings (estate) -|#936 -|Hypatia content_patterns/hardcoded_tmp: /tmp paths without mktemp (30 -|KEEP -|hypatia /tmp without mktemp x30 - this repo -|#937 -|Hypatia content_patterns/http_in_docs: plain-HTTP URLs in prose (11 in -|KEEP -|hypatia plain-HTTP URLs in prose x11 - this repo -|#938 -|Hypatia content_patterns/npx_in_workflow: npx/npm in CI config (9 inst -|KEEP -|hypatia npx/npm in CI config x9 - this repo -|#939 -|Hypatia shell-exec patterns: download_then_run_shell + eval_in_shell ( -|KEEP -|hypatia download-then-run + eval patterns x13 - this repo -|#940 -|Hypatia content_patterns/known_fake_action_sha in vendored satellite e -|KEEP -|hypatia known fake action SHAs in vendored satellites x6 - this repo -|#941 -|Hypatia RE001: adopt step-security/harden-runner estate-wide, or recor -|DECIDE -|RE001 harden-runner estate-wide or record WONTFIX -|#942 -|Hypatia RE005: review exit-masking steps (` -|KEEP -|RE005 exit-masking steps x20 - this repo -|#943 -|Hypatia workflow_hardening triage: secrets-inherit convention + WH013/ -|KEEP -|workflow_hardening secrets-inherit + WH013/WH006 false positives - this repo -|#945 -|Hypatia misc: scorecard DependencyPinning + SD022 k9 spec stale path ( -|KEEP -|scorecard DependencyPinning + SD022 k9 stale path - this repo -|#1014 -|governance: the Hypatia scanner pin predates the consumer fixes it sca -|KEEP -|Hypatia scanner pin predates the consumer fixes it scans for - this repo -|=== - -=== Cluster C5: Rulesets, branch protection & org settings (15 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#408 -|policy: estate settings standard — merge opts, protection, required- -|ESTATE -|estate settings standard (WS4) -|#681 -|adaptive/must: 342 of 415 repos cannot merge a clean PR without --admi -|VERIFY -|342 repos unsatisfiable required contexts; #1034 floor applier may have fixed - verify -|#887 -|D65 — EstatePushing is an active org ruleset with zero rules -|VERIFY -|EstatePushing org ruleset with zero rules; verify after #1034 -|#889 -|Repo metadata hygiene: 22 hyperpolymath repos have blank descriptions -|ESTATE -|22 repos with blank descriptions; standards' fixed by this action -|#890 -|Optimus-Branch is enforcement:disabled on standards, hypatia and cicd- -|VERIFY -|Optimus-Branch disabled on standards/hypatia/cicd-squabbler; verify after #1034 -|#956 -|standards/main has no required status checks — every gate this repo -|CLOSED -|fixed by #1034 - active ruleset verified via API: 21 required checks + signatures + scanning -|#1003 -|rsr-template-repo: no ruleset requires pull requests on any branch -|ESTATE -|rsr-template-repo: no ruleset requires pull requests -|#1004 -|Estate census: 124 of 456 repos carry retired or unsatisfiable ruleset -|ESTATE -|124 of 456 repos carry retired/unsatisfiable ruleset rules (report only) -|#1006 -|EstateTagging's workflows rule is vacuous (workflows: []), and no Inte -|ESTATE -|EstateTagging workflows rule vacuous; no Integration can create a tag -|#1007 -|EstatePushing is scoped ~ALL but binds to 6 of 68 repos — push rules -|ESTATE -|EstatePushing scoped ~ALL but binds to 6 of 68 repos -|#1008 -|rsr-template-repo Base ruleset repaired; 5-8 error-severity alerts rem -|DECIDE -|rsr-template-repo Base ruleset: 5-8 error-severity alerts, threshold semantics undetermined -|#1013 -|code_scanning trim applied to hyperpolymath (77/77); metadatastician b -|VERIFY -|metadatastician blocked by ONE inherited org ruleset; verify after #1034 -|#1028 -|Tag rulesets restrict `creation` with no bypass actors — an unknown -|DECIDE -|tag rulesets restrict creation with no bypass actors -|#1032 -|O6 propagation: four contradictions between the ruling and the committ -|ESTATE -|O6 propagation: four contradictions between ruling and committed rulesets -|#1040 -|apply-branch-gates: a gate workflow no PR can trigger still derives a -|KEEP -|apply-branch-gates: untriggerable gate workflow still derives a required context - this repo -|=== - -=== Cluster C6: Estate infrastructure & fleets (mirrors, gitdb, census) (36 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#306 -|ci(estate): Pages enablement decision needed across 48 repos (failing -|ESTATE -|Pages enablement decision, 48 repos -|#331 -|[campaign] Estate boj-build.yml sweep — repair or retire (~30 repos -|ESTATE -|boj-build.yml sweep, ~30 repos -|#342 -|audit: contractiles estate state 2026-06-02 — schema drift + trident -|ESTATE -|contractiles estate-state audit -|#348 -|automation: hypatia ruleset + gitbots should be able to fan-out doc + -|ESTATE -|hypatia ruleset + gitbots fan-out charter -|#403 -|Build the Estate Manifesto & Atlas (front-door, owner-gated) -|ESTATE -|Estate Manifesto & Atlas -|#410 -|standard: MCP settings template = boj-server cartridge config (WS6) -|ESTATE -|MCP settings template = boj-server cartridge config (WS6) -|#411 -|standard: discussion + wiki templates + discussions-toggle policy (WS5 -|ESTATE -|discussion + wiki templates policy (WS5/WS8) -|#438 -|Estate recovery: audit + revert unauthorized mass migrations (README . -|VERIFY -|audit + revert of unauthorised mass migrations; verify state before closing -|#443 -|Estate campaign: roll SonarCloud across all repos (parked, resume late -|PARK -|SonarCloud rollout; self-declared parked -|#460 -|[umbrella] Estate audit & optimization — make the enforcement real ( -|ESTATE -|estate audit & optimisation umbrella (Waves 0-6) -|#462 -|Implement the DYADT production verifier (hyperpolymath/did-you-actuall -|ESTATE -|DYADT production verifier; separate repo -|#633 -|[umbrella] Estate control plane — close the automation loop (the las -|ESTATE -|estate control plane umbrella -|#634 -|[umbrella] Template family rationalisation — variant packs, not vari -|ESTATE -|template family rationalisation -|#635 -|[umbrella] Surface the buried projects — DYADT is the worked example -|ESTATE -|surface buried projects (DYADT detector) -|#636 -|[charter] git-logistics-office — the estate control plane (repo life -|ESTATE -|git-logistics-office charter -|#645 -|Fix the scaffold that propagates 'License: PMPL-1.0-or-later' (runbook -|ESTATE -|scaffold PMPL propagation; source is the scaffold repo -|#653 -|40 referenced-but-absent files across 19 repos — triaged (estate swe -|ESTATE -|40 referenced-but-absent files, 19 repos -|#662 -|wordpress-tools PR #57 deleted 108 source files and added nothing — -|ESTATE -|wordpress-tools PR#57 deletion scoring; other repo -|#668 -|gh search/code silently undercounts by up to 31% while reporting incom -|ESTATE -|gh search undercount doctrine (enumerate-then-filter) -|#675 -|Estate sweep: Fork A 'postulate' damage confined to proven — but the -|ESTATE -|proven postulate damage; estate repo -|#677 -|Estate: 13 repos have a DAMAGED GIT OBJECT DATABASE (not the corrupt-i -|ESTATE -|13 repos with damaged git object databases; recovery -|#678 -|Estate: 132 repos track files their own .gitignore hides; template-syn -|ESTATE -|132 repos track files their own .gitignore hides -|#689 -|fix(rsr-certifier): complete or honestly gate the uncompilable satelli -|ESTATE -|rsr-certifier satellite (also vendored here) -|#702 -|install-tools.sh regenerated estate-wide WITHOUT the #678 cure — fak -|ESTATE -|install-tools.sh re-propagated without the #678 cure; fix the template -|#703 -|Duplicate checkout trees double-count every estate census — repos/ v -|ESTATE -|duplicate checkout trees double-count every census -|#705 -|proven: postulate cure is NOT on origin/main — 42 .idr files/360 sit -|ESTATE -|proven postulate cure not on origin/main -|#750 -|Deletion census: use `git ls-files --deleted`, never `git status` — -|ESTATE -|deletion census doctrine (git ls-files --deleted) -|#751 -|Agent handover surface is lossy: `.claude/checkpoints/` prunes files a -|ESTATE -|agent handover surface is lossy (checkpoints + developer dirs) -|#759 -|[decision] 72 of 111 rhodibot workflows still run the MUTATING variant -|ESTATE -|rhodibot mutating-variant cron; canary 39/111 -|#792 -|Pin-consumption census TSV has TWO extractor defects — 145 of 1,434 -|ESTATE -|pin-consumption TSV extractor defects (census data) -|#795 -|1,073 byte-identical Optimus-Branch.json replicas are a STALE, WEAKER -|ESTATE -|1073 Optimus-Branch.json replicas stale; canonical pointer unresolved -|#918 -|Mirror callers drifted across >=3 live SHAs (de-duplicate worktrees be -|ESTATE -|mirror callers drifted across >=3 live SHAs -|#949 -|Estate health: 87% of default branches are red (388 of 447) — a red -|ESTATE -|87% of default branches red (388 of 447) -|#950 -|Mirror fleet: 27% of estate CI failures — destinations unprovisioned -|ESTATE -|mirror fleet: 27% of estate CI failures -|#1002 -|Mirror to Git Forges: 3 of 7 forges failing, three different root caus -|ESTATE -|mirror to Git Forges: 3 of 7 failing, three root causes -|#1019 -|CodeRabbit's unsigned pushes re-kill CI on every required_signatures r -|ESTATE -|CodeRabbit unsigned pushes re-kill required_signatures repos -|=== - -=== Cluster C7: Spec & documentation contradiction / drift (17 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#281 -|[campaign #239] Estate seam audit: stale .claude/CLAUDE.md language ta -|ESTATE -|stale CLAUDE.md language tables; canonical here, propagation estate -|#307 -|[campaign] .scm → .a2ml machine-readable convergence (104 repos rema -|ESTATE -|.scm to .a2ml convergence, 104 repos -|#343 -|audit: dotfile drift across estate (2026-06-02 sample) — .editorconf -|ESTATE -|dotfile drift sweep (2026-06-02 sample) -|#401 -|Docs: complete the audience-split education layer (docs/wikis/) -|KEEP -|audience-split education layer (docs/wikis/) - this repo -|#446 -|Proposal: an honest, adoptable readiness/insight badge framework — g -|KEEP -|readiness/insight badge framework - this repo (docs/BADGE-CRITERIA-SPEC.adoc) -|#463 -|Complete the per-language testing guides (Zig, BEAM, proofs) + Julia r -|KEEP -|per-language testing guides - this repo -|#479 -|[campaign] standards carve-out: evict products/impls, keep the canon ( -|VERIFY -|standards carve-out campaign; verify completion of the 9 sub-steps -|#493 -|[carve-out 4/9] rhodium-standard-repositories/ cleanup: de-vendor sate -|ESTATE -|carve-out 4/9: rsr-template-repo cleanup -|#495 -|[carve-out 6/9] Data out of spec dirs: grade data → archive, PORT-RE -|KEEP -|carve-out 6/9: data out of spec dirs - this repo -|#646 -|AGENTIC.a2ml instructs agents to 'Never use AGPL' — contradicts Rule -|KEEP -|AGENTIC.a2ml "Never use AGPL" contradicts Rules 3-5 - this repo; ruling on which side holds -|#732 -|AI-MANIFEST ply: relay items after #731 — two renames, CI wiring, mi -|KEEP -|AI-MANIFEST ply relay - 0-AI-MANIFEST.a2ml is here -|#897 -|Canonical cliff.toml should strip ZWSP at generation (bot regens re-im -|KEEP -|canonical cliff.toml should strip ZWSP at generation - this repo -|#915 -|~138 files cannot carry a '#' SPDX header; 58 .json need REUSE sidecar -|KEEP -|138 files cannot carry SPDX header; 58 .json need REUSE sidecars - this repo -|#923 -|The Deno ruling is dated two ways across the estate (2026-08-26 vs 202 -|DECIDE -|Deno ruling dated two ways; canonical = 2026-09-22 (LANGUAGE-POLICY v1.6.0 + language-policy.scm) -|#927 -|LANGUAGE-POLICY.adoc:10 ':source-repo:' points at cccp, which holds no -|CLOSED -|fixed - :source-repo: pointer cccp to standards (this action) -|#929 -|Seed CLAUDE.md claims the estate uses GitLab and not GitHub (flag only -|DECIDE -|seed CLAUDE.md claims GitLab not GitHub; flag only -|#960 -|D73-C downstream: 21 launcher descriptors + trigger/ still name the de -|KEEP -|21 launcher descriptors + trigger/ name deleted launcher-standard (.a2ml) - this repo -|=== - -=== Cluster C8: Debtfile & ratchet mechanics (4 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#953 -|debt paydown: gate-scripts-without-tests re-baselined 30->40, todo-fix -|KEEP -|Debtfile re-baselined 30 to 40, 76 to 80 - this repo -|#955 -|Debt ratchet red on every PR since #820 — run-debtfile.sh --write em -|KEEP -|debt ratchet red on every PR since #820 - this repo; blocks merges -|#958 -|Debt-exception / Ratchet-exception trailers never survive the squash m -|KEEP -|debt-exception trailers never survive squash merge (0 of 8) - this repo -|#975 -|21 baseline acks lapse on 2026-10-22 and 17 point at closed issues -|KEEP -|21 baseline acks lapse 2026-10-22; 17 point at closed issues - this repo; time-bounded -|=== - -=== Cluster C9: Legacy (May-Jul) boj/isers & proof-debt (8 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#89 -|Epic: -iser regeneration-cartridge pattern — wire all 28 -isers into -|ESTATE -|boj-server epic; work lives in hyperpolymath/boj-server -|#90 -|Roll unified-gated-adapter + SSE + regen-trigger into the iseriser sca -|ESTATE -|iseriser scaffold; boj-server -|#91 -|http-capability-gateway tier-2 production-wiring (ADR-0004) -|ESTATE -|http-capability-gateway tier-2 (ADR-0004); boj-server -|#92 -|Idris2 as source-of-truth: generate/verify Zig FFI from the ABI -|ESTATE -|Idris2 source-of-truth to Zig FFI; research/estate -|#93 -|Stop committing generated/* — gitignore + regenerate-on-trigger -|ESTATE -|stop committing generated/*; estate repos -|#100 -|Phase E — Production wiring + staging validation + rollout/rollback -|PARK -|Phase E rollout runbook; verify whether Phase D landed, then close -|#124 -|Epic: estate proof-debt remediation (2026-05-18 reconciled audit) -|ESTATE -|proof-debt remediation epic (2026-05-18 audit) -|#156 -|[#92 Class D] abbreviation / acronym-boundary drift across DB + cloud -|ESTATE -|Class D abbreviation/acronym drift; estate cartridges -|=== - -=== Cluster C10: KYAML campaign (5 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#1021 -|KYAML step 2/6 — comment-preservation proof (shared by Y-2 and Y-3) -|KEEP -|KYAML step 2/6: comment-preservation proof - this repo -|#1022 -|KYAML step 3/6 — a KYAML formatter/linter for arbitrary YAML -|KEEP -|KYAML step 3/6: formatter/linter for arbitrary YAML - this repo -|#1023 -|KYAML step 4/6 — decide KYAML scope on the evidence (owner ruling) -|DECIDE -|KYAML step 4/6: scope ruling on the evidence -|#1024 -|KYAML step 5/6 — migrate estate-authored non-bot YAML -|ESTATE -|KYAML step 5/6: migrate estate-authored non-bot YAML -|#1025 -|KYAML step 6/6 — workflows, only if step 4 rules them in scope -|ESTATE -|KYAML step 6/6: workflows, only if step 4 rules them in scope -|=== - -=== Cluster C11: Nickel/K9 format defects (this repo) (4 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#934 -|6 contractiles fail nickel typecheck: import path points one level off -|KEEP -|6 contractiles fail nickel typecheck (import path one level off) - this repo -|#999 -|config.ncl cannot be evaluated: std.record.merge does not exist -|KEEP -|config.ncl cannot be evaluated (std.record.merge) - this repo -|#1000 -|8 of 16 *.k9.ncl files lack the K9! line-1 sentinel -|KEEP -|8 of 16 *.k9.ncl files lack the K9! line-1 sentinel - this repo -|#1001 -|os_detect.ncl: 'Apple_Darwin falls through to the wildcard in deployme -|KEEP -|os_detect.ncl: Apple_Darwin falls through to wildcard - this repo -|=== - -=== Cluster C12: DEED / A2ML conversion (1 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#837 -|DEED conversion campaign — tracking & acceptance criteria (.a2ml → -|KEEP -|DEED conversion campaign - this repo -|=== - -=== Cluster C13: Security tooling (gitleaks / secret scanner) (2 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#888 -|secret-scanner-reusable stages the estate baseline unconditionally, so -|KEEP -|secret-scanner-reusable stages estate baseline unconditionally - this repo -|#957 -|PAT-refresh tripwire: live HYPATIA_SCAN_PAT will arm 6 unackable CSA f -|KEEP -|HYPATIA_SCAN_PAT refresh tripwire would arm 6 unackable CSA findings - this repo (security) -|=== - -=== Cluster C14: CodeQL / Scorecard tooling defects (8 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#288 -|[campaign] Estate CodeQL weekly→monthly sweep (cut 3, standards#233 -|ESTATE -|CodeQL weekly to monthly sweep estate-wide -|#323 -|[standing] Estate CodeQL cron drift detection + 6-week budget review -|ESTATE -|CodeQL cron drift detection + 6-week budget review -|#324 -|[campaign] Long-tail non-canonical CodeQL cron sweep (~86 files / 30 r -|ESTATE -|long-tail CodeQL sweep, ~30 repos -|#674 -|Scorecard's PinnedDependencies is wrong for lockfile-enforced repos � -|ESTATE -|Scorecard PinnedDependencies wrong for lockfile repos (79 alerts) -|#1031 -|CodeQL default setup and a committed advanced workflow cannot coexist -|ESTATE -|CodeQL default + advanced workflow cannot coexist (3 metadatastician repos) -|#1033 -|gates.json: never_required_contexts cannot catch default-setup CodeQL -|KEEP -|gates.json never_required_contexts cannot catch default-setup CodeQL by name - this repo -|#1035 -|27 Scorecard callers omit actions:read and will startup_failure on the -|ESTATE -|27 Scorecard callers omit actions:read -|#1036 -|Scorecard reconciler fails correct repos: gh actions-lock --verify is -|KEEP -|scorecard reconciler blind to job-level refs - this repo (half its severity claim self-retracted in-thread) -|=== - -=== Cluster C15: Owner decisions & registers (8 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#404 -|Estate licence cascade (PMPL -> MPL/CC-BY-SA axis) — per HANDOFF -|DECIDE -|licence cascade PMPL to MPL/CC-BY-SA; owner ruling -|#497 -|[carve-out 8/9] ⚠️ OWNER-ONLY licence-flag items: 007 audits in pu -|DECIDE -|carve-out 8/9: owner-only licence-flag items -|#637 -|[register] Owner-decision backlog — 17 issues blocked on a ruling, n -|CLOSED -|duplicate of #787 - decision register absorbed it -|#692 -|policy: enforce Rust = Rust + Creusot without proof theatre -|DECIDE -|Rust = Rust + Creusot policy without proof theatre -|#709 -|Owner decision batch 2026-08-31: 7 decisions from the triage wave, one -|CLOSED -|absorbed into #787 decision sheet -|#715 -|CI/CD regularisation: owner decisions O1–O10 (batch, non-blocking) -|CLOSED -|absorbed into #787 decision sheet -|#787 -|Owner decision sheet D1–D72: one answerable place for #637 + #715 + -|DECIDE -|owner decision sheet D1-D72 - the register itself; keep open until rulings land -|#944 -|Banned-language deed tools: port a2ml_to_deed.py + deed_lint.py off Py -|DECIDE -|port the 2 deed Python tools or exempt permanently - tools are here (1-formats/deed/tools/) -|=== - -=== Cluster C16: Rust formatting debt (this repo) (1 issues) - -[cols="10,38,12,40",options="header"] -|=== -|Issue -|Title -|Disposition -|Note -|#933 -|All 12 Rust crates fail cargo fmt --check (pre-existing formatting deb -|KEEP -|all 12 Rust crates fail cargo fmt --check - this repo (needs toolchain) -|=== -== 5. What this action did - -=== 5.1 Repository changes (committed on the working branch, in a PR) - -[cols="2,3,5",options="header"] -|=== -|File |Change |Why - -|`ULTRAPLAN-2026-09-24.adoc` -|new (this document) -|the durable record of the census, diagnosis, and reconciliation - -|`docs/ISSUE-INTAKE-SPEC.adoc` -|new, v1.0.0, normative -|*the upstream fix*: one issue / one defect / correct scope; dedup -obligation; wave-umbrella rule; mandatory templates; scope labels; -automation contract (only the two designated detectors may file, one tracking -issue each); no silent closes; spec-reconciliation-on-contact - -|`.github/ISSUE_TEMPLATE/bug.yml`, `decision.yml`, `campaign.yml`, `config.yml` -|new -|structured intake that enforces the spec: evidence required for bugs, -options + recommendation + register entry for decisions, source + scope + -steps for campaigns; blank form disabled - -|`0-canon/GOVERNANCE.adoc` -|rewritten v2.0.0 -|the v1 placeholder described a multi-maintainer approval model that does not -exist in a single-owner estate and ended in broken asciidoc. v2.0.0 -summarises the Constitutional District (roles, decision making, -communication, licensing) and defers to it where they differ - -|`0-canon/rsr/LANGUAGE-POLICY.adoc` -|`:source-repo:` cccp to standards -|closes #927 — the pointer named a repo that holds no such spec - -|`rhodium-standard-repositories/.github/workflows/language-policy.yml` -|line-116 comment "replacement: Deno" to "the JS runtime is Bun per the -2026-09-22 ruling" -|closes #920 in this repo; estate copies propagate via template sync -(see the #659 population) - -|`scripts/triage-2026-09-24-apply.sh` -|new, executable, idempotent -|the live actions of 5.2 as one owner-run command (labels, closes with -their evidence comments, description + topics); dry-run supported via -`DRY_RUN=1` -|=== - -=== 5.2 Live repository actions — packaged in `scripts/triage-2026-09-24-apply.sh` - -*Boundary found while executing*: the agent performing this work is -authenticated as `arena-ai-coding-agent[bot]` — a GitHub App installation with -repo read, `labels:write`, and `contents:write` (git), but *without* -`issues:write` or repo-admin. Verified empirically: reading issues and -creating labels succeed; commenting on issues, closing issues, adding labels -to issues, and `PATCH repos` all return 403. So the live actions below are -fully prepared — exact label sets, exact close comments, exact -description/topics — in one idempotent script the owner runs once: - ----- -gh auth login # or: export GH_TOKEN= -bash scripts/triage-2026-09-24-apply.sh # or DRY_RUN=1 first ----- - -The script skips already-closed issues and re-posts nothing it already has, -so it is safe to run before or after the merge, any number of times. - -* *Description* — old: `Organization-wide standards and specifications` - (true but inert). New: describes what the repo *is*, what it hosts, and who - it is for (see part 7 for the final value). -* *Topics* — 18 topics narrowed to 12 non-redundant, discoverable ones (part 7). -* *Backlog labelled* — all open issues: the estate's own classifier - (`.github/scripts/classify-issue.jq` + `.github/label-classifier.json`) runs - over every title, with the scope/status/priority assignments from part 4 on - top. Additive only; nothing pre-existing is removed. -* *10 issues closed with evidence comments* (each comment in the script - states the reason and names the canonical/fixed issue, per Intake Spec - Rule 7): - -[cols="10,20,70",options="header"] -|=== -|Issue |Was |Closing reason (stated in the script's evidence comment) - -|#956 -|standards/main has no required status checks -|*Fixed by #1034.* Verified via the rulesets API: the active `main gate` -ruleset carries 21 required status contexts, required signatures, and -code-scanning thresholds. - -|#637 -|[register] Owner-decision backlog, 17 issues -|*Absorbed.* #787's title names it: "one answerable place for #637 + #715 + -#709 + #658". The register lives on #787. - -|#709 -|Owner decision batch 2026-08-31 -|*Absorbed* into #787 (named there). - -|#715 -|CI/CD regularisation O1–O10 -|*Absorbed* into #787 (named there). - -|#784 -|Pin campaign may have startup-killed every repo with a stale lock (hypothesis, -needs census) -|*Answered.* The census #968 exists: 39 repos with step-level desync. The -hypothesis issue's own acceptance condition is met by it. - -|#808 -|RSR templates use illegal `uses: ../../` refs -|*Subsumed by #913*, whose 2026-09-22 census measured the same defect -population at 76 refs with acceptance criteria. #808's "why it was invisible" -mis-triage triple (failure / 0 jobs / name==path, indistinguishable from -callee-lockfile poisoning) was preserved in a comment on #913 before closing. - -|#708 -|Lockfile Drift Detect anonymises repos, counts banners, treats errors as drift -|*Fixed.* The current workflow implements rc-honesty (1=drift, 2=error), -per-repo slugs, and banner-free counting, and its comments cite #708 as the -resolved reference. "Has only ever run once" is stale — it runs weekly. - -|#658 -|Deno to Bun: 30 deno.json locations, 18 blocked -|*Superseded.* The 2026-09-22 ruling banned Deno outright, replacing -"migrate Deno to Bun" with "retire Deno" (#919 sizes it, #926 handles the k9 -harness). The unique data (18-of-30 blocked count) was copied into the closing -comment before closure. - -|#920 -|language-policy.yml:116 names Deno as npm's replacement -|*Fixed in this repo* (the seed copy committed with this action). Estate -copies remain in the template-sync population (#659). - -|#927 -|LANGUAGE-POLICY.adoc `:source-repo:` points at cccp -|*Fixed in this repo* (pointer committed with this action). -|=== - -* *One comment on #913* (in the script, posted before #808 is closed) - preserving #808's mis-triage knowledge (see above) — evidence is not - orphaned by a close. - -=== 5.3 What this action deliberately did NOT do - -* *Did not execute the 5.2 actions under the agent token.* The token lacks - `issues:write`, so labelling/closing/commenting/repo-PATCH would have - failed (and the label attempt failed with 403 on every issue, leaving the - backlog exactly as found). The script in 5.2 is the execution vehicle, and - running the closes under the owner's identity is correct: they are - statements about the owner's backlog. -* *Did not close the ~60 ESTATE rows.* They are labelled `scope:estate` and - listed in part 4, but moving them to the estate register is the owner's - call (they are the working memory of estate audits). Say the word and the - migration is mechanical. -* *Did not close the VERIFY rows on inference.* Where main's green state - suggests a fix (#935, #963, #438, #479, #681, #887, #890, #1013), the rule - is verify-then-close with a fresh measurement, not close-on-hunch. -* *Did not touch the org rulesets* (EstatePushing, Optimus-Branch, - EstateTagging) — those are estate-governance objects, and #1034's floor - applier is the instrument for them; VERIFY rows check their state after it - has run estate-wide. - -== 6. Spec reconciliation: what is fixed, what is not - -The wave's value is that it *found* the contradictions. The list below is the -reconciliation status of every spec-level contradiction surfaced by the -backlog (full rows in part 4). - -[cols="4,3,3",options="header"] -|=== -|Contradiction |Where the fix lives |Status - -|GOVERNANCE placeholder vs the Constitutional District -|this repo (`0-canon/`) -|*Fixed* (v2.0.0, this action) - -|`:source-repo:` pointer to cccp (#927) -|this repo (`0-canon/rsr/`) -|*Fixed* (this action) - -|language-policy.yml "replacement: Deno" comment (#920) -|this repo (seed) + estate copies -|*Fixed here*; estate copies via template sync - -|AGENTIC.a2ml "Never use AGPL" vs licence Rules 3–5 (#646) -|this repo (`.machine_readable/` descriptiles) -|*Open* — a ruling is needed on which side holds before the descriptiles are -amended (Rule 8: record the supersession, don't amend silently) - -|55 agent-instruction files "TypeScript IS PERMITTED under Bun" vs the -2026-08-27 TS ban (#921) -|canonical here, propagation estate -|*Open* — fix the canonical wording here, then sweep; the sweep is estate work - -|Deno ruling dated two ways, 2026-08-26 vs 2026-09-22 (#923) -|this repo states 2026-09-22 (LANGUAGE-POLICY v1.6.0, `language-policy.scm`) -|*Needs a one-line ruling* declaring 2026-09-22 canonical, then propagation - -|21 launcher descriptors naming deleted `launcher-standard (.a2ml)` (#960) -|this repo (`launcher/`) -|*Open, fixable here* — rename-or-delete the references - -|Nickel/K9 defects: `config.ncl` unevaluable (#999), 8/16 missing K9! -sentinels (#1000), `os_detect.ncl` Darwin fallthrough (#1001), 6 contractiles -failing typecheck (#934) -|this repo -|*Open, fixable here* — the fix wave (part 8) - -|138 files without SPDX headers; 58 .json needing REUSE sidecars (#915) -|this repo -|*Open, mechanical* — REUSE sidecar pass - -|Debtfile mechanics: ratchet red on every PR (#955), trailers lost to squash -(#958), re-baselining (#953) -|this repo -|*Open, fixable here* — #955 is the only one that blocks merges today - -|gates.json `never_required_contexts` vs default-setup CodeQL (#1033, #1031) -|this repo + 3 estate repos -|*Open* — spec fix here, propagation after - -|DEED conversion (#837), Python deed tools (#944), dead A2ML gate (#1010) -|this repo + 13 estate repos -|*Open* — campaign (#837) + a ruling (#944) - -|Optimus-Branch.json canonical pointer unresolved (#795) -|design doc here, 1073 replicas estate -|*Open* — fix the canonical here, then re-replicate - -|Licence axis: PMPL to MPL/CC-BY-SA cascade (#404), owner-only flags (#497), -scaffold PMPL propagation (#645) -|owner + estate -|*Open — owner ruling* -|=== - -== 7. Forward process (what now keeps the backlog shaped) - -[cols="2,8",options="header"] -|=== -|Mechanism |State - -|Issue Intake Spec -|v1.0.0 committed (this action). Canonical home `docs/ISSUE-INTAKE-SPEC.adoc`. - -|Issue templates, blank form disabled -|Committed (this action). An issue that fits no template does not fit this -repo. - -|Auto-labeling of new issues -|`label-triage.yml` already live; conservative, additive, never overrides a -human. - -|Backlog classification -|Done for all 193 (this action); future waves get an umbrella (Rule 3) and -the triage pass rides on the umbrella's close-out. - -|Repository description (set by the apply script) -|`Canonical standards, specifications and governance for the Hyperpolymath -estate: policy-as-code, machine-readable specs (A2ML/DEED), and the reusable -CI/CD + security canon for a 500+ repository software estate.` - -|Topics (new, 12) -|`standards` `specification` `policy-as-code` `governance` `compliance` -`machine-readable` `documentation` `open-standards` `deed` `k9` -`epistemic-computing` `hyperpolymath` — the old set's redundant epistemic- -triple, `documents-and-standards`, `open-source`, and `taxonomy-as-code` -(duplicated by `policy-as-code`/`machine-readable`) were dropped. -|=== - -== 8. Ranked next actions for the owner - -[cols="4,10,30,26",options="header"] -|=== -|Rank |Issue(s) |Action |Why this order - -|1 -|this PR + the apply script -|Review and merge the intake spec + templates + canon fixes, then run -`bash scripts/triage-2026-09-24-apply.sh` (dry-run first if desired) -|Everything else assumes the new intake shape; the script lands the labels, -the 10 evidenced closes, and the description/topics in one idempotent pass; -merging also propagates the fixed seed comment estate-wide over time - -|2 -|#787 (D1–D72) plus the DECIDE rows: #404, #497, #692, #923, #929, #941, -#944, #991, #1008, #1023, #1028 -|Answer the batched decision sheet in one reply -|One answer unblocks the most rows of any single action; several DECIDE rows -gate whole campaigns (KYAML, deed tools, tag rulesets, arming policy) - -|3 -|#903 (ENFORCE cliff 2026-10-01), #1037 (48 Dependabot PRs), #975 (21 acks -lapse 2026-10-22) -|The time-bounded trio -|Dates beat priorities. #1037 is mechanical (close PRs in 15 repos under the -existing dependabot hold); #903 needs a ruling on the cliff date or a -163-caller migration window; #975 is a two-hour refresh of the ack ledger - -|4 -|#955, #913, #914, #907, #933 -|The repo-local reds that block or arm -|#955 blocks every merge (ratchet write/verify mismatch); #913/#914 make -every repo seeded from this tree dead at startup; #907 is a standing security -exemption in the actions-lock gate; #933 is mechanical once a Rust toolchain -is in CI - -|5 -|VERIFY rows: #935, #963, #438, #479, #681, #887, #890, #1013 -|Verify-then-close with fresh measurements -|Cheapest win in the backlog: most are probably already fixed by #1034's -floor applier; each needs one measurement, one comment, one close - -|6 -|ESTATE rows (~60) -|Migrate to the estate register (or close as transferred) -|After ranks 1–5, this repo's backlog is exactly its actionable scope; the -estate rows move to where the work is. Mechanical; on request. -|=== - -== Appendix A — Census methodology - -Per the estate's measurement doctrine (#668, #750: enumerate, then filter; a -count landing on a page size is a page size, not a measurement): - -* Issue censuses: `gh issue list --state open|closed --limit 1000 --json ...` - (explicit limit above the ceiling, JSON, local aggregation with `jq`). - `gh search issues` was *not* used for counting. -* Daily/author distributions: `jq` over the censuses (part 1 and part 2 - tables). -* Ruleset state: `gh api repos/hyperpolymath/standards/rulesets` (list) and - the per-ruleset rule detail (21 required contexts, required_signatures, - code_scanning thresholds) — the evidence behind closing #956. -* CI state: `gh run list --branch main` at HEAD `c56f4ec`. -* Duplicate/subsumption calls: issue bodies read pairwise before any close - (part 5.2); every close carries its evidence in the closing comment and is - one command to reverse. - -Timestamp: 2026-09-24 ~14:30 UTC, branch `arena/01a0d3ce-standards` off -`main@c56f4ec`. - -== Appendix B — Reading the backlog without drowning - -The 193 rows in part 4 are grouped so that no reader needs more than one -view: - -* *Daily life* = the `scope:repo` rows (part 4, KEEP/VERIFY/PARK). That is - this repo's actual worklist. -* *Estate memory* = the `scope:estate` rows. Valuable evidence, wrong - house; migrate per rank 6. -* *The owner's desk* = the DECIDE rows, all batched under #787. -* *The wave that made this plan* = clusters C2–C5 and C7–C14 rows dated - 2026-09-21…23. - -== 9. Addendum — current triage and two-estate scope (2026-09-28) - -This addendum supersedes the *ordering* in section 8 where live state has -changed; it does not rewrite the 2026-09-24 historical census. The open-issue -snapshot was re-read from GitHub on 2026-09-28 with `gh issue list --state open ---limit 1000`. It returned *193 open issues*, including *98 created on or after -2026-09-22* and *72 without labels*. These are triage signals, not proof that -any particular issue is invalid. Recheck state, evidence, and CI at the start -of each execution phase. - -=== Scope ruling: both estates are in scope for the standard - -The Multi-Repository Scope Standard (`docs/MULTI-REPOSITORY-SCOPE-STANDARD.adoc`) -and its illustrative TOML declaration (`docs/repo-scope.example.toml`) now -explicitly name both `hyperpolymath` and `metadatastician`. This is the scope -of the *standard and future explicitly authorized estate work*, not blanket -authority to modify every repository. The live estate board (`docs/ESTATE-BOARD.adoc`) -is a dated measurement and must not be treated as a current complete membership -source without refresh. Resolve canonical `github.com/owner/repo` identities, -record a source/revision and observation time, and surface archived, vendor, -renamed, inaccessible, and unknown entries separately. `The-Metadatastician` -may be an organization login alias; use the canonical `metadatastician` owner -identity used in current estate records, and verify redirects before acting. - -=== First-pass disposition: fix, decide, validate, or batch - -No issue should be closed merely because it is old, oddly worded, unlabelled, -or estate-wide. Use this four-way triage; every disposition needs current -evidence and a comment that preserves it. - -[cols="1,3,5",options="header"] -|=== -|Disposition |Examples in the live open snapshot |Next action - -|*P0 — reproduce / contain* -|#1050, Hypatia scan emits no SARIF; #1037, open Dependabot PRs reportedly reintroduce the CodeQL startup-killer -|Reproduce against current reusable SHA and a clean runner; check whether the 48 PR population still exists before acting. Preserve last-known-good pins and do not merge risky PRs while verified. Split scanner defect from consumer pin mitigation only if the fixes differ. - -|*P1 — contradiction or merge-blocking gate* -|#1032 (ruling vs committed rulesets); #1040 (non-PR-reachable workflow can become a required check); #1031 (default and advanced CodeQL coexist in three metadatastician repos); #1028 (tag creation may be blocked); #1005 (tag spelling vs resolved SHA) -|Read the cited ruling and inspect live platform state. State the conflicting authorities explicitly, identify which has precedence, and get an owner ruling where needed. Do not silently amend one side. Test both organizations, with a positive and negative control, before propagation. - -|*P1 — fix control before broad rollout* -|#1036 (scorecard verifier misses job-level refs); #1035 (27 callers omit `actions:read`); #1013 (metadatastician finding is one inherited ruleset, not 67 separate repo defects); #1010 (13-repo dead validation gate) -|Confirm the measured populations remain true. Fix reusable source/checker once where possible, then run a read-only, canonical-identity census across both estates. Use one campaign umbrella and an explicit resolved target list for any write. - -|*P2 — owner decision batch* -|#787 remains open; #1023 KYAML scope decision; #903 actions-lock cliff; #975 baseline acknowledgements -|Answer the batched decision register once, recording options, affected scopes, consequences, and chosen disposition. Check dates and owners first; move stale entries out of the urgent lane rather than treating an expired date as a live blocker. - -|*P3 — safe batch / low urgency* -|#1049 (35 repos below the seven-topic minimum) -|One issue is the right shape. Re-census both orgs; curate topics from each repository's own README; batch only where descriptions are unambiguous. Do not auto-apply invented topics. Close only when the measured remainder is zero or explicitly excepted. - -|*Verify before dismissing* -|Any apparently superseded, duplicate, already-fixed, or out-of-scope issue; particularly older estate audit findings and unlabeled issues -|Search for a canonical surviving issue or landed fix, verify at current default-branch HEAD / live settings, transfer estate-only work to its correct register or campaign, copy unique evidence, then close with a reason and cross-reference. If evidence is stale or access is missing, park as unknown/blocked rather than dismiss. -|=== - -The issue numbers above are triage examples, not a claim that all remaining 193 -have been individually re-audited in this addendum. The per-issue pass must -record at least: current state; repo-local vs estate scope; contradiction vs -ordinary debt vs capacity limit; evidence freshness; duplicate/superseding -reference; owner decision needed; and next action. Issues without a scope label -are untriaged, not automatically wrong. - -=== How to get through the spike without another spike - -The earlier burst was an audit filing-model failure: many findings were opened -one-by-one without adequate deduplication, scope routing, or a campaign umbrella -(see sections 2–3 and `docs/ISSUE-INTAKE-SPEC.adoc`). The remedy is not a -mass-close and not another full-estate issue dump. Work in this order: - -. *Freeze intake shape.* Apply the existing issue-intake rules: search before - filing, one umbrella for a wave over five findings, separate repo-local - source fixes from estate propagation, and keep per-repository evidence in an - attached ledger rather than one issue per repo. -. *Build a current, read-only inventory.* Page through open issues and PRs; - canonicalize redirects; capture labels, dates, evidence, linked commits and - campaigns. Split at least into `scope:repo`, `scope:estate`, owner decision, - duplicate/superseded, and unknown. Include both organizations explicitly. -. *Reconcile contradictions first.* For each conflict, pair the committed - standard/ruling with current implementation and authority precedence. An - unresolved owner choice stays a decision; a proven implementation defect - becomes a bounded fix. Never infer the winner from which document is newer - alone. -. *Contain active failures.* Reproduce P0/P1 risks before broad cleanup. Make - the smallest repo-local correction and test it. For propagation, produce a - dry-run manifest containing exact canonical targets, exclusions, and - expected diff; obtain approval if the task has not already granted that - exact write. -. *Close cheap stale rows with proof.* For each candidate, test the acceptance - criteria, locate the actual landing commit or superseding issue, copy unique - evidence, and add a factual closing comment. Do not batch-close by number - range or age. -. *Move estate work to an estate campaign/register.* Keep one umbrella per - coherent campaign, with a single evidence ledger and per-repo result rows. - Preserve this repo as canonical source where appropriate; do not make it the - inbox for fixes whose source lives elsewhere. -. *Publish a short reconciliation report.* Give totals by disposition and - scope, the unverified/blocked remainder, any new owner decisions, and links - to campaign umbrellas. Re-census after the pass; the ending counts must be - reproducible. - -The first execution should be a *triage-only campaign* over the 193 current -open issues, not an estate write campaign. The standards repo issue register is -not evidence that every related estate issue belongs to this repository. The -separate estate workstream explicitly covers `hyperpolymath` *and* -`metadatastician`; a task touching either must declare which estate(s), resolve -its exact target list, and honor read-only default authority. - -== 10. Proposed execution gates - -Do not call the backlog "sorted" until each open issue has a disposition and -there is no unlabelled or unknown row silently omitted. Do not call an estate -campaign complete until its target list is reconciled against a dated, -canonical membership source for *both* estates and every target has an -individual outcome. Suggested completion evidence: - -* every remaining issue has a scope label, owner, next action, or documented - exception; -* every duplicate/superseded close cites its survivor or landed fix and retains - unique evidence; -* contradictions have an explicit authority resolution; -* urgent findings have a current reproduction or reason they no longer apply; -* both estates are represented in scope manifests, and any unmeasured repo is - named rather than counted as clean; -* a subsequent issue census reproduces the reported counts. diff --git a/ULTRAPLAN-2026-09-29.adoc b/ULTRAPLAN-2026-09-29.adoc deleted file mode 100644 index 64c648804..000000000 --- a/ULTRAPLAN-2026-09-29.adoc +++ /dev/null @@ -1,431 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -= Issue Backlog Triage — Current Inventory and Ultra-Plan -Jonathan D.A. Jewell -v1.0.0, 2026-09-29 -:toc: -:toclevels: 3 - -Status: *triage plan and issue inventory; no remote issue writes completed*. - -== 0. Decision summary - -On 2026-09-29, the live GitHub API returned *199 open issues*. This file lists every one, assigns a first-pass bucket, and gives an execution order. Carried-forward rows use the curated dispositions in `ULTRAPLAN-2026-09-24.adoc`; they are *not* represented as freshly re-audited. - -[cols="2,4,5",options="header"] -|=== -|Measure |Live count |Meaning -|Open issues |199 |Complete `gh issue list --state open` snapshot; every current open number is listed in §2. -|Unlabelled |78 |No GitHub label at all. -|Missing `scope:repo` / `scope:estate` |169 |Fails `docs/ISSUE-INTAKE-SPEC.adoc` Rule 5; must not be guessed silently. -|Unassigned |198 |No assignee recorded. -|Without milestone |199 |No milestone grouping. -|New since 2026-09-24 inventory |8 |#1049, #1050, #1054–#1059; assigned a first-pass bucket below. -|Prior-plan close candidates still open |8 |#637, #658, #708, #709, #715, #784, #808, #956; several are not yet safe to close. -|=== - -=== First-pass disposition totals - -[cols="2,1,5",options="header"] -|=== -|Bucket |Count |Interpretation -|ESTATE |91 |Carry-forward estate disposition plus #1049, #1055, #1056. -|KEEP / repo-local |75 |Prior repo-local disposition plus #1050, #1054, and #1058. -|DECIDE |13 |Prior decision items plus #1059; use #787 as the register. -|VERIFY |8 |Legacy verify items; current evidence required. -|CLOSE-CANDIDATE |8 |Old plan proposed closure; still open, not authorization to mass-close. -|PARK |3 |Retain with explicit trigger and revisit condition. -|INVALID |1 |#1057 “probe”: empty body, no actionable request. -|=== - -=== Provisional scope mapping for the label pass - -* `KEEP` → propose `scope:repo`; `ESTATE` → propose `scope:estate`. -* `DECIDE` → repo scope except #404, #497, #692, #787, #941, #1008, #1023, and #1028, which are estate-scope decisions; #1059 is repo-scope. -* `VERIFY` → estate scope for #438, #681, #887, #890, and #1013; repo scope for the remaining verify rows. -* `PARK` → estate scope. Close-candidate scope should be retained from the issue body/canonical survivor, not inferred from the fact that closure was proposed. -* `INVALID` → do not spend time classifying; close with a reason when permitted. - -This mapping is *proposed*, derived from the prior plan’s curated dispositions, and still needs human confirmation before the bulk label pass. - -NOTE: #1050 is an active repo-local P0 reproduction, not one of the eight legacy VERIFY rows. It is included under KEEP and promoted in the execution plan. - -== 1. Execution order (ultraplan) - -=== Phase 0 — remove noise / record easy proven resolution - -. *#1057 — close invalid.* Body is empty and title is only “probe”; no reproducible defect, decision, or campaign. A close/label attempt was made in this session and GitHub returned `403 Resource not accessible by integration`; it remains OPEN pending a write-capable session. No silent dismissal. -. *#956 — verify fixed, then close.* Read-only live endpoint `GET /repos/hyperpolymath/standards/rules/branches/main` now reports `required_status_checks` (along with `code_scanning`, `required_signatures`, `deletion`, and `non_fast_forward`); the issue thread records the 18-context gate. Close as fixed only after recording read-back evidence. -. *#637, #709, #715 — merge/close into #787.* The decision register is the surviving owner-decision surface; preserve any unresolved rows in #787 before closing source trackers. -. *#784 — close as answered by #968.* The census answered the hypothesis; cross-link #968 in the close comment. -. *#808 — subsume under #913.* First copy #808’s unique startup-death / zero-jobs mis-triage evidence into #913; then close #808 with the survivor link. Do not close silently. -. *#708 — do NOT close yet.* Its latest comment makes closure conditional on a post-fix weekly re-run and an artifact showing repo slugs, clean row counts, and an error count. Verify the scheduled run. -. *#658 — do NOT close yet.* Although the Deno→Bun campaign was superseded, its package decision remains represented as D10 on #787; preserve it until that ruling is answered or explicitly transferred. - -=== Phase 1 — contain live failures and contradiction risks - -. *P0 reproduce #1050* on a clean runner: missing `hypatia.sarif` is caller-visible; compare the current reusable SHA against its last known-good run and distinguish scanner build/cache failure from missing output conversion. Keep callers on known-good pins until verified. -. *P0 validate #1037* before touching the reported Dependabot PRs: re-enumerate the live PR population and effective ignore rules; do not merge a startup-killing bump based on the historic count alone. -. *P1 reproduce #1054* with exactly one JSON document: `[]` must pass only after scanner success; malformed, empty, multi-document, wrong-shape, and crash controls must fail closed. -. *P1 reconcile rule/implementation contradictions*: #1032, #1040, #1031, #1028, #1005. Cite governing ruling, current implementation, and authority precedence; ask the owner where policy is undecided. -. *P1 fix source/checker before propagation*: #1036, #1035, #1013, #1010. Reconfirm populations, then prepare a read-only exact-target manifest; no estate write is authorized by this triage pass. - -=== Phase 2 — split, merge, and refine - -. *#1055 split its two acceptance paths.* Keep the no-merge-base/orphan-ref gate and branch-disposition taxonomy in #1055. Move the #1005 AC2 pin-population remeasurement (28 mislabeled v4.38.1, 21 true v4.38.0, 15 v4.38.2) into #1005 as dated evidence; remove that unrelated acceptance criterion from #1055 only after copying it. -. *#1056 fold into existing canonical threads.* Move the four #994 class determinations to #994; move startup-death/Dependabot recurrence and recovery-path notes to #968. Close #1056 only after both cross-links exist. -. *#1058 split by artifact.* Keep the K9 envelope/contract/leash taxonomy in #1058. Move the `deed.abnf` contradictory ruling-header finding to the existing DEED campaign #837 (or its canonical grammar issue), with a link back. -. *#1059 stays a decision/architecture parent, not a duplicate of #1058.* Keep it for the cross-layer ruling (canon / deed / K9 / Nickel / environment / serialization, derivation invariant); link the K9 contract and KYAML sequence #1021–#1025. Batch owner choices through #787 where possible. -. Keep one actionable defect per issue. The 2026-09-24 cluster table remains the dedup reference for the other 191 carried-forward issues; shared component alone is not a reason to merge when acceptance criteria differ. - -=== Phase 3 — route and label the full backlog - -. Add `scope:repo` / `scope:estate` for all 169 currently missing scope only after checking the action location, not merely the affected population. Use carry-forward buckets below as proposals, not a blind API payload. -. Fill one primary type and area label, plus owner/status/priority where warranted. The title classifier cannot infer scope or evidence freshness. -. Assign one accountable owner per remaining actionable issue; route estate-only work to one existing umbrella/register. No milestone is required by intake policy unless it represents a real delivery window. -. Re-census after writes; completion means zero unscoped rows or an explicit exception, not merely “all got some label.” - -=== Phase 4 — evidence-based closure and follow-through - -. For every close: re-check open state, current default-branch HEAD or live platform state; locate fix/survivor; copy unique evidence; leave a factual closing comment; cross-link the survivor; then close. -. For every estate transfer: identify the canonical campaign/register and add evidence there before removing it from this repo’s actionable queue. -. Batch owner decisions by shared dependency; #787 is the register. Re-present decisions blocked more than 30 days as a single batch, consistent with `docs/ISSUE-INTAKE-SPEC.adoc`. -. Publish totals by bucket, missing evidence, unowned work, and blocked decisions after each phase. - -== 2. Complete open-issue inventory - -All 199 open issues returned by the snapshot are below exactly once. Current labels and update dates are live values. Legacy dispositions come from `ULTRAPLAN-2026-09-24.adoc`; the eight newer rows are first-pass proposals. `CLOSED` from the earlier plan is rendered as `CLOSE-CANDIDATE`, never as already closed. - -=== Invalid / trivial-close candidate (1) - -Close with a short factual reason once issue-write permission is available; no issue-body evidence to preserve. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/1057[#1057] |2026-09-28 |probe |— |New first pass -|=== - -=== Verify against current state (8) - -Reproduce or inspect current live state; close only if the exact acceptance criteria are met. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/438[#438] |2026-08-25 |Estate recovery: audit + revert unauthorized mass migrations (README .adoc→.md sweep; protected rescript/v-ecosystem repos) |documentation, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/479[#479] |2026-08-27 |[campaign] standards carve-out: evict products/impls, keep the canon (spec + policy + registry + template) |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/681[#681] |2026-08-29 |adaptive/must: 342 of 415 repos cannot merge a clean PR without --admin (unsatisfiable required contexts) |cicd, enhancement, governance, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/887[#887] |2026-09-22 |D65 — EstatePushing is an active org ruleset with zero rules |security |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/890[#890] |2026-09-22 |Optimus-Branch is enforcement:disabled on standards, hypatia and cicd-squabbler — 0 rules in force on main, while the ruleset count reads as governed |audit, governance, scope:estate, status:needs-ruling |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/935[#935] |2026-09-22 |actions-lock gate is permanently red on main, and its remediation contradicts canon rule 10 |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/963[#963] |2026-09-22 |main is red: actions.lock omits a transitive dependency of asana/push-signed-commits (actions/setup-python@v2) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1013[#1013] |2026-09-22 |code_scanning trim applied to hyperpolymath (77/77); metadatastician blocked by ONE inherited org ruleset, not 67 repos |— |Carry-forward from 2026-09-24 plan -|=== - -=== Prior plan: close candidate; revalidate before closing (8) - -These were proposed for closure in the 2026-09-24 plan but remain open. Re-check live acceptance evidence and copy unique evidence to the survivor before closing. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/637[#637] |2026-09-21 |[register] Owner-decision backlog — 17 issues blocked on a ruling, not on effort |meta:umbrella, status:needs-owner |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/658[#658] |2026-09-14 |Deno→Bun: all 30 deno.json locations assessed — 18 blocked on npm packages that do not exist |chore, migration, packaging, scope:estate |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/708[#708] |2026-09-17 |Lockfile Drift Detect anonymizes repos as _w, counts banners as entries, treats script errors as drift — and has only ever run once |bug, cicd, scope:repo |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/709[#709] |2026-09-14 |Owner decision batch 2026-08-31: 7 decisions from the triage wave, one reply resolves all |audit, decision, scope:estate, status:needs-owner |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/715[#715] |2026-09-14 |CI/CD regularisation: owner decisions O1–O10 (batch, non-blocking) |cicd, decision, status:needs-owner |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/784[#784] |2026-09-14 |Pin campaign may have startup-killed every repo carrying a stale actions.lock (hypothesis, needs census) |cicd, meta:campaign, tech-debt |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/808[#808] |2026-09-15 |RSR workflow templates use an illegal `uses: ../../` ref — every instantiated workflow is permanently dead (0 jobs) |— |Prior close proposal; revalidate -|https://github.com/hyperpolymath/standards/issues/956[#956] |2026-09-22 |standards/main has no required status checks — every gate this repo ships is advisory here |— |Prior close proposal; revalidate -|=== - -=== Owner ruling needed (13) - -Batch under the owner decision register (#787); state options, consequences, scope and decision owner. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/404[#404] |2026-09-21 |Estate licence cascade (PMPL -> MPL/CC-BY-SA axis) — per HANDOFF |documentation |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/497[#497] |2026-08-27 |[carve-out 8/9] ⚠️ OWNER-ONLY licence-flag items: 007 audits in public canon; PALIMPSEST.adoc narrative |documentation, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/692[#692] |2026-08-29 |policy: enforce Rust = Rust + Creusot without proof theatre |chore, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/787[#787] |2026-09-23 |Owner decision sheet D1–D72: one answerable place for #637 + #715 + #709 + #658 and this week's unfiled decisions |audit, bug, chore, cicd, decision, governance, meta:umbrella, scope:estate, status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/923[#923] |2026-09-22 |The Deno ruling is dated two ways across the estate (2026-08-26 vs 2026-09-22) |decision, migration, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/929[#929] |2026-09-22 |Seed CLAUDE.md claims the estate uses GitLab and not GitHub (flag only, owner decision) |decision |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/941[#941] |2026-09-22 |Hypatia RE001: adopt step-security/harden-runner estate-wide, or record WONTFIX (23 instances) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/944[#944] |2026-09-22 |Banned-language deed tools: port a2ml_to_deed.py + deed_lint.py off Python, or exempt permanently (2 files) |enhancement, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/991[#991] |2026-09-22 |AC4 arming policy: retired-filename blocks, stale-version warns (each CURRENT_VERSION bump is a measure-then-arm event) |governance, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1008[#1008] |2026-09-22 |rsr-template-repo Base ruleset repaired; 5-8 error-severity alerts remain (threshold semantics undetermined), and copilot_code_review may be a fifth unsatisfiable rule type |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1023[#1023] |2026-09-22 |KYAML step 4/6 — decide KYAML scope on the evidence (owner ruling) |decision |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1028[#1028] |2026-09-22 |Tag rulesets restrict `creation` with no bypass actors — an unknown number of repos can never ship a release |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1059[#1059] |2026-09-28 |decide the attestation/orchestration chain: canon → .deed → .k9 → Nickel → environment → serialization, with derivation (never restatement) as the invariant |— |New first pass -|=== - -=== Repo-local actionable (75) - -Keep in standards backlog; assign an owner and order by severity / dependencies. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/346[#346] |2026-08-27 |governance: hoist bridge-forbidden-phrases check into reusable workflow |meta:recurring |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/401[#401] |2026-08-27 |Docs: complete the audience-split education layer (docs/wikis/) |meta:recurring |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/409[#409] |2026-08-27 |promote CI-CRITICALITY tiers (Gate/Check/Advisory/Auto) → standards + rsr-template |cicd |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/446[#446] |2026-09-04 |Proposal: an honest, adoptable readiness/insight badge framework — grade our own work, and challenge the evaluators |design, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/463[#463] |2026-08-27 |Complete the per-language testing guides (Zig, BEAM, proofs) + Julia refresh + AffineScript SSOT |meta:campaign |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/495[#495] |2026-08-27 |[carve-out 6/9] Data out of spec dirs: grade data → archive, PORT-REGISTRY → verisim-data, retire SATELLITES.a2ml |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/646[#646] |2026-08-31 |AGENTIC.a2ml instructs agents to 'Never use AGPL' — contradicts Rules 3, 4 and 5 |governance, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/704[#704] |2026-08-31 |examples/web-project-deno.json template ships phantom npm:affinescript@^12.1.0, replicated across ≥12 repos — the purge phantoms are still propagating via scaffold |bug, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/732[#732] |2026-09-04 |AI-MANIFEST ply: relay items after #731 — two renames, CI wiring, migration, and one owner ruling |decision |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/791[#791] |2026-09-19 |githooks: validate-a2ml admits 0 of 222 files and validate-spdx rejects all 1,046 .adoc — neither was run against its own corpus |documentation, licensing |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/837[#837] |2026-09-19 |DEED conversion campaign — tracking & acceptance criteria (.a2ml → .deed) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/888[#888] |2026-09-21 |secret-scanner-reusable stages the estate baseline unconditionally, so it detonates on itself in every consumer with its own .gitleaks.toml |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/894[#894] |2026-09-22 |Gate table + criterion 1.2.1 ignore manifest.scm (estate Guix convention) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/895[#895] |2026-09-22 |Gate format cannot express partial modules or nested layouts (2 concrete cases) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/896[#896] |2026-09-22 |changelog-reusable can never start: called-job write perms are checked against caller TOP-LEVEL (own caller fails too) |bug |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/897[#897] |2026-09-22 |Canonical cliff.toml should strip ZWSP at generation (bot regens re-import GitHub-defused mentions) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/903[#903] |2026-09-22 |actions-lock cliff: ENFORCE_ACTIONS_LOCK_FROM=2026-10-01 reddens 163 callers with no human action |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/905[#905] |2026-09-22 |runtime-policy.yml's Deno branch emits only ::warning:: and cannot fail a job |bug, governance, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/906[#906] |2026-09-22 |workflow-lint's lock regex is blind to '- uses:' list items, so its green is partly vacuous |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/907[#907] |2026-09-22 |check-actions-lock-gate.sh unconditionally exempts actions/github-script, so @main passes today |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/908[#908] |2026-09-22 |root-allow.txt is registered in the exemption ratchet but absent on disk, so that ledger is inert |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/909[#909] |2026-09-22 |actions.lock never covers denoland/setup-deno |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/910[#910] |2026-09-22 |governance-reusable.yml still has 7 'ref: main' helper checkouts reached by 368 pinned callers |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/911[#911] |2026-09-22 |shell-e2e-reusable.yml has the repo's only 2 unpinned refs (owner's staged work: report only) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/913[#913] |2026-09-22 |76 'uses: ../../...' relative refs in vendored seeds are invalid syntax and cause startup death |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/914[#914] |2026-09-22 |46 genuinely unpinned third-party refs in the vendored seed trees |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/915[#915] |2026-09-22 |~138 files cannot carry a '#' SPDX header; 58 .json need REUSE sidecars |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/916[#916] |2026-09-22 |setup-deno pins are inconsistent and some look fabricated: one SHA labelled four different tags |migration, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/921[#921] |2026-09-22 |55 agent-instruction files assert 'TypeScript IS PERMITTED under Bun', contradicting the 2026-08-27 ban |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/922[#922] |2026-09-22 |No pinned Bun lint/format gate: staged JavaScript is a declared skip |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/925[#925] |2026-09-22 |check-ts-allowlist.deno.js cannot be deleted: 11 of the last 12 governance revisions still invoke it |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/926[#926] |2026-09-22 |k9-coordination-protocol vendors a Deno test harness: 260 Deno API lines across 10 files |migration, testing |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/928[#928] |2026-09-22 |language-policy.scm v2.0.0 has no wired regression test (needs a decision on guile in CI) |bug, governance, performance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/930[#930] |2026-09-22 |actions-lock gate's remedy text names a repo-relative path that exists in no consumer repo |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/932[#932] |2026-09-22 |validate-lint-format.sh: Rust and Nickel arms ask a different question than their tool |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/933[#933] |2026-09-22 |All 12 Rust crates fail cargo fmt --check (pre-existing formatting debt) |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/934[#934] |2026-09-22 |6 contractiles fail nickel typecheck: import path points one level off an existing file |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/936[#936] |2026-09-22 |Hypatia content_patterns/hardcoded_tmp: /tmp paths without mktemp (30 instances) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/937[#937] |2026-09-22 |Hypatia content_patterns/http_in_docs: plain-HTTP URLs in prose (11 instances) |automation, documentation |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/938[#938] |2026-09-22 |Hypatia content_patterns/npx_in_workflow: npx/npm in CI config (9 instances, stale rule + vendored) |automation, cicd, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/939[#939] |2026-09-22 |Hypatia shell-exec patterns: download_then_run_shell + eval_in_shell (13 instances) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/940[#940] |2026-09-22 |Hypatia content_patterns/known_fake_action_sha in vendored satellite examples (6 instances) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/942[#942] |2026-09-22 |Hypatia RE005: review exit-masking steps (`\|\| true` / continue-on-error) (20 instances) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/943[#943] |2026-09-22 |Hypatia workflow_hardening triage: secrets-inherit convention + WH013/WH006 false positives (7 instances) |automation, cicd, research, security |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/945[#945] |2026-09-22 |Hypatia misc: scorecard DependencyPinning + SD022 k9 spec stale path (2 instances) |automation, cicd, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/953[#953] |2026-09-22 |debt paydown: gate-scripts-without-tests re-baselined 30->40, todo-fixme 76->80 |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/955[#955] |2026-09-22 |Debt ratchet red on every PR since #820 — run-debtfile.sh --write emits a file check-debtfile-structure.sh rejects |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/957[#957] |2026-09-22 |PAT-refresh tripwire: live HYPATIA_SCAN_PAT will arm 6 unackable CSA findings in both gates |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/958[#958] |2026-09-22 |Debt-exception / Ratchet-exception trailers never survive the squash merge — 0 of 8 in the Debtfile's whole history |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/960[#960] |2026-09-22 |D73-C downstream: 21 launcher descriptors + trigger/ still name the deleted launcher-standard (.a2ml) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/964[#964] |2026-09-22 |governance-reusable.yml dupkey helper pin 317101e0 is stale by 45 files — and its sparse-checkout scope is too wide for #962's freshness guard |governance, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/967[#967] |2026-09-22 |ci-pipeline detect is blind to 56 code-bearing repos (and probes Deno, not Bun) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/972[#972] |2026-09-22 |pre-commit hands validators git-QUOTED paths, so non-ASCII filenames are silently skipped (6 validators) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/975[#975] |2026-09-22 |21 baseline acks lapse on 2026-10-22 and 17 point at closed issues |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/976[#976] |2026-09-22 |detect: the Nickel probe matches RSR template boilerplate, silencing the zero-denominator refusal on 9 of 24 sampled repos |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/980[#980] |2026-09-22 |ci-pipeline.yml: the ledger pin's "same commit" invariant is unsatisfiable (12/12 merges are squash) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/981[#981] |2026-09-22 |validate-actions-lock prescribes a cure that can re-legitimise a blocked action version |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/992[#992] |2026-09-22 |check-lock-sync.sh and GitHub startup disagree for job-level-reusable-only callers, and the gate's error text is inverted |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/993[#993] |2026-09-22 |actions.lock policy: job-level reusable refs are reported, never required — and the pin bump that disarms the latent blocker |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/994[#994] |2026-09-22 |Cross-cutting governance reds surfaced by the actions.lock cure — 9 classes across 17 PRs (incl. a live gate for the retired A2ML) |cicd, governance, refactor |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/998[#998] |2026-09-22 |ci-pipeline.yml: standards does not call its own pipeline (AC6 of #986) |bug |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/999[#999] |2026-09-22 |config.ncl cannot be evaluated: std.record.merge does not exist |bug |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1000[#1000] |2026-09-22 |8 of 16 *.k9.ncl files lack the K9! line-1 sentinel |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1001[#1001] |2026-09-22 |os_detect.ncl: 'Apple_Darwin falls through to the wildcard in deployment_priority |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1014[#1014] |2026-09-22 |governance: the Hypatia scanner pin predates the consumer fixes it scans for — compiled-in suppression cannot cure a caller's gate failure |automation, chore, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1015[#1015] |2026-09-22 |check-action-pins-resolve.sh scans prose: a documentation example SHA fails the gate |bug |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1018[#1018] |2026-09-22 |rust-ci-reusable: explicit ref refs/pull/N/merge dies when the PR merges mid-run (absolute-zero #164 evidence) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1021[#1021] |2026-09-22 |KYAML step 2/6 — comment-preservation proof (shared by Y-2 and Y-3) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1022[#1022] |2026-09-22 |KYAML step 3/6 — a KYAML formatter/linter for arbitrary YAML |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1033[#1033] |2026-09-23 |gates.json: never_required_contexts cannot catch default-setup CodeQL by name |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1036[#1036] |2026-09-23 |Scorecard reconciler fails correct repos: gh actions-lock --verify is blind to job-level reusable refs (wrong in both directions) |bug, cicd |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1040[#1040] |2026-09-23 |apply-branch-gates: a gate workflow no PR can trigger still derives a required context |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1050[#1050] |2026-09-27 |hypatia-scan-reusable @2479cf7: scan produces no hypatia.sarif — "Path does not exist: hypatia.sarif" (caller-visible startup-shaped failure) |— |New first pass -|https://github.com/hyperpolymath/standards/issues/1054[#1054] |2026-09-28 |Hypatia reusable validation rejects clean [] and accepts multiple JSON documents |— |New first pass -|https://github.com/hyperpolymath/standards/issues/1058[#1058] |2026-09-28 |grammar artifacts: .k9 has no grammar or contract at all, and deed.abnf states both “sole normative” and “pending owner ruling” |— |New first pass -|=== - -=== Estate-scope / route to the right campaign (91) - -Keep the evidence, but do not treat as standards-repo implementation work unless this repo is the canonical fix source. Link the estate campaign/register. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/89[#89] |2026-08-27 |Epic: -iser regeneration-cartridge pattern — wire all 28 -isers into boj-server (unified gated adapter) |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/90[#90] |2026-09-03 |Roll unified-gated-adapter + SSE + regen-trigger into the iseriser scaffold |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/91[#91] |2026-08-27 |http-capability-gateway tier-2 production-wiring (ADR-0004) |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/92[#92] |2026-08-27 |Idris2 as source-of-truth: generate/verify Zig FFI from the ABI |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/93[#93] |2026-09-19 |Stop committing generated/* — gitignore + regenerate-on-trigger |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/124[#124] |2026-08-27 |Epic: estate proof-debt remediation (2026-05-18 reconciled audit) |major, meta:recurring, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/156[#156] |2026-09-19 |[#92 Class D] abbreviation / acronym-boundary drift across DB + cloud cartridges |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/252[#252] |2026-08-27 |[campaign] ReScript → AffineScript estate migration (UMBRELLA) |documentation, governance, meta:campaign, meta:recurring, meta:umbrella |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/272[#272] |2026-08-27 |[campaign #252] STEP 5 — TAIL BATCH: smallest tail-end repos (≤20 files × ~50 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/276[#276] |2026-08-27 |[campaign #252] STEP 6 — MID-TIER: 20-100 file repos (~15 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/278[#278] |2026-08-27 |[campaign #252] STEP 7 — LARGE REPOS: 100-500 file repos (~6 repos) |meta:campaign, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/279[#279] |2026-08-27 |[campaign #252] STEP 8 — MEGAPORT: idaptik (516, was 1235) + panll (726) batched conversion |meta:campaign, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/281[#281] |2026-08-27 |[campaign #239] Estate seam audit: stale .claude/CLAUDE.md language tables + carve-out candidate pattern |meta:campaign, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/288[#288] |2026-08-27 |[campaign] Estate CodeQL weekly→monthly sweep (cut 3, standards#233 Option B — ~206 repos) |cicd, meta:campaign |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/306[#306] |2026-08-26 |ci(estate): Pages enablement decision needed across 48 repos (failing 'Setup Pages' on every push) |cicd, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/307[#307] |2026-08-27 |[campaign] .scm → .a2ml machine-readable convergence (104 repos remaining) |meta:recurring |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/309[#309] |2026-08-27 |[campaign] Python residual cleanup — ~45 estate-authored .py files remain (banned) |meta:recurring |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/323[#323] |2026-08-27 |[standing] Estate CodeQL cron drift detection + 6-week budget review |cicd, meta:campaign |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/324[#324] |2026-08-27 |[campaign] Long-tail non-canonical CodeQL cron sweep (~86 files / 30 repos) |cicd, meta:campaign |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/331[#331] |2026-09-08 |[campaign] Estate boj-build.yml sweep — repair or retire (~30 repos with malformed JSON + dead .local host + plain HTTP) |meta:campaign, refactor |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/342[#342] |2026-08-26 |audit: contractiles estate state 2026-06-02 — schema drift + trident-claim/on-disk mismatch |meta:recurring, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/343[#343] |2026-09-03 |audit: dotfile drift across estate (2026-06-02 sample) — .editorconfig / .gitignore / .gitattributes |status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/348[#348] |2026-08-27 |automation: hypatia ruleset + gitbots should be able to fan-out doc + 6a2 + contractile refreshes themselves |automation, enhancement, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/403[#403] |2026-08-26 |Build the Estate Manifesto & Atlas (front-door, owner-gated) |status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/408[#408] |2026-08-26 |policy: estate settings standard — merge opts, protection, required-checks = 🔴 Gate set (WS4) |status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/410[#410] |2026-08-27 |standard: MCP settings template = boj-server cartridge config (WS6) |chore, governance, scaffolding |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/411[#411] |2026-08-27 |standard: discussion + wiki templates + discussions-toggle policy (WS5/WS8) |documentation, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/460[#460] |2026-08-27 |[umbrella] Estate audit & optimization — make the enforcement real (Waves 0–6) |meta:recurring, meta:umbrella |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/462[#462] |2026-08-26 |Implement the DYADT production verifier (hyperpolymath/did-you-actually-do-that) |meta:campaign, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/493[#493] |2026-08-26 |[carve-out 4/9] rhodium-standard-repositories/ cleanup: de-vendor satellites/, merge templates into rsr-template-repo, delete the lying .gitmodules |status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/633[#633] |2026-08-26 |[umbrella] Estate control plane — close the automation loop (the last link was never connected) |cicd, meta:umbrella, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/634[#634] |2026-08-25 |[umbrella] Template family rationalisation — variant packs, not variant repos (measured: 6-file delta) |design, meta:umbrella, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/635[#635] |2026-08-25 |[umbrella] Surface the buried projects — DYADT is the worked example, the detector is the deliverable |meta:umbrella, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/636[#636] |2026-08-26 |[charter] git-logistics-office — the estate control plane (repo lifecycle: birth, enrollment, life, death) |design, meta:umbrella, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/645[#645] |2026-09-21 |Fix the scaffold that propagates 'License: PMPL-1.0-or-later' (runbook §7a source fix) |scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/653[#653] |2026-08-31 |40 referenced-but-absent files across 19 repos — triaged (estate sweep) |scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/657[#657] |2026-08-27 |MEASURED: a lockfile policy kills 77% of dead workflows — the wiped allowlist is only 10%, and the policy is invisible to the API |cicd, governance, research, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/659[#659] |2026-08-27 |Language policy is duplicated into ~372 per-repo CLAUDE.md files across 131 repos — fixing standards fixes one |governance, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/662[#662] |2026-08-31 |wordpress-tools PR #57 deleted 108 source files and added nothing — deletion scored as migration |bug, governance, scope:repo, status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/663[#663] |2026-08-27 |TypeScript retirement: measured — 308 of 613 .ts files were never exempt, and the largest exempt class is upstream forks |governance, migration, research, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/664[#664] |2026-08-31 |43% of estate .affine files are 200-byte Harvard Engine stubs — migration campaigns count deletions as ports |conformance, scope:estate, status:needs-owner, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/668[#668] |2026-08-27 |gh search/code silently undercounts by up to 31% while reporting incomplete_results:false — adopt enumerate-then-filter as doctrine |automation, research, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/669[#669] |2026-08-31 |Orphaned/phantom action pins still live post-remediation: dtolnay ×35 repos (two orphaned SHAs), trufflehog ≥20, codeql-action ≥14 |bug, cicd, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/670[#670] |2026-08-27 |Dependabot bumps uses: without regenerating actions.lock — every remediated repo is newly exposed |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/674[#674] |2026-08-29 |Scorecard's PinnedDependencies is wrong for lockfile-enforced repos — 79 alerts on _pathroot, inline pinning would break CI |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/675[#675] |2026-08-31 |Estate sweep: Fork A 'postulate' damage confined to proven — but the Idris2/Agda keyword misconception is hand-authored and predates it by 4 months |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/677[#677] |2026-08-31 |Estate: 13 repos have a DAMAGED GIT OBJECT DATABASE (not the corrupt-index problem) — 1 with 9 unpushed commits at risk |chore, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/678[#678] |2026-08-31 |Estate: 132 repos track files their own .gitignore hides; template-sync sweep (92 repos) left a SILENT fake gate in 29 |chore, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/687[#687] |2026-08-29 |audit(hypatia): classify 61 structural-drift and canonical-home findings |automation, research |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/689[#689] |2026-08-31 |fix(rsr-certifier): complete or honestly gate the uncompilable satellite |bug, scaffolding |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/698[#698] |2026-08-31 |Banned languages appear in dev-environment definitions (guix.scm ×14, empty-linter mise.toml) |status:needs-owner |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/702[#702] |2026-08-31 |install-tools.sh regenerated estate-wide WITHOUT the #678 cure — fake exit-0 gate re-propagated to 245/248 copies (fix the template, not the copies) |bug, cicd, priority:p1, scaffolding, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/703[#703] |2026-08-31 |Duplicate checkout trees double-count every estate census — repos/ vs hyper-repos/ overlap on 213 names, _SET containers hold 412 nested repos |audit, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/705[#705] |2026-08-31 |proven: postulate cure is NOT on origin/main — 42 .idr files/360 sites still unparseable there; the full cure exists only as ~77 UNCOMMITTED working-tree files on a local branch |bug, priority:p1, scope:repo |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/706[#706] |2026-09-22 |mise.toml pins banned toolchains estate-wide — python in 543/573 files (249 repos); 59 files still pin deno despite the Deno→Bun ruling |audit, scope:estate, tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/707[#707] |2026-08-31 |Phantom upload-artifact pin ea165f8d65b6db9a… (commit never existed, 422) live in 11 repos — spliced mutant of the healthy v4 SHA |bug, cicd, priority:p1, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/727[#727] |2026-09-03 |gh actions-lock fix mode prepends its banner above the SPDX header — blocks the central lock-refresh (plan §6.4) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/750[#750] |2026-09-08 |Deletion census: use `git ls-files --deleted`, never `git status` — the 83,441 figure was an empty-index artefact |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/751[#751] |2026-09-08 |Agent handover surface is lossy: `.claude/checkpoints/` prunes files and `developer/` is not a git repo |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/759[#759] |2026-09-09 |[decision] 72 of 111 rhodibot workflows still run the MUTATING variant on a weekly cron — the canary migration is 39/111 done |cicd, decision |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/792[#792] |2026-09-14 |Pin-consumption census TSV has TWO extractor defects — 145 of 1,434 rows carry a non-SHA in pin_sha, and every background rate quoted off it is contaminated |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/795[#795] |2026-09-15 |1,073 byte-identical Optimus-Branch.json replicas are a STALE, WEAKER policy than the canonical — and the design doc's canonical pointer does not resolve |bug, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/803[#803] |2026-09-22 |lockfile drift: 15 repo(s) as of 2026-09-22 |cicd, lockfile-drift |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/889[#889] |2026-09-21 |Repo metadata hygiene: 22 hyperpolymath repos have blank descriptions (5 public) |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/904[#904] |2026-09-22 |run_validator() is fail-open: 6 validators named by rsr-template-repo's pre-commit do not exist |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/917[#917] |2026-09-22 |234 .pre-commit-config.yaml files depend on Python, which LANGUAGE-POLICY bans |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/918[#918] |2026-09-22 |Mirror callers drifted across >=3 live SHAs (de-duplicate worktrees before counting) |tech-debt |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/919[#919] |2026-09-22 |Deno retirement sizing: 95 'deno task' definitions across 23 files in the 11 ledgered repos |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/924[#924] |2026-09-22 |rsr-template-repo has 62 unpinned workflow refs, including two @main and one feature branch |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/949[#949] |2026-09-22 |Estate health: 87% of default branches are red (388 of 447) — a red branch is no longer a signal |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/950[#950] |2026-09-22 |Mirror fleet: 27% of estate CI failures — destinations unprovisioned, advisory doctrine not implemented, 3 live caller refs |enhancement, security |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/968[#968] |2026-09-22 |actions.lock step-level desync: 39 repos with silently dead CI (startup_failure) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/969[#969] |2026-09-22 |actions.lock omits job-level reusable refs in 159 repos (no runtime impact; tracks upstream #129) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/987[#987] |2026-09-22 |Phantom blob-pin: 18 refs across 7 repos pin standards reusable workflows at non-commit SHAs (and the guard that detects this is itself blob-pinned) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1002[#1002] |2026-09-22 |Mirror to Git Forges: 3 of 7 forges failing, three different root causes |bug |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1003[#1003] |2026-09-22 |rsr-template-repo: no ruleset requires pull requests on any branch |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1004[#1004] |2026-09-22 |Estate census: 124 of 456 repos carry retired or unsatisfiable ruleset rules (report only) |governance, refactor |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1005[#1005] |2026-09-23 |Supply chain: 75 estate pins are spelled v4.38.0 but are the v4.38.1 tag target (estate-blocked) |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1006[#1006] |2026-09-22 |EstateTagging's workflows rule is vacuous (workflows: []), and no Integration can create a tag org-wide |cicd, enhancement |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1007[#1007] |2026-09-22 |EstatePushing is scoped ~ALL but binds to 6 of 68 repos — push rulesets reach private repos only |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1010[#1010] |2026-09-22 |ci: retire the dead A2ML validation gate (13 repos — the renamed-action population) |refactor, scope:estate |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1019[#1019] |2026-09-22 |CodeRabbit's unsigned pushes re-kill CI on every required_signatures repo — re-signing is triage, not repair |research |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1024[#1024] |2026-09-22 |KYAML step 5/6 — migrate estate-authored non-bot YAML |automation, refactor |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1025[#1025] |2026-09-22 |KYAML step 6/6 — workflows, only if step 4 rules them in scope |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1031[#1031] |2026-09-23 |CodeQL default setup and a committed advanced workflow cannot coexist — 3 metadatastician repos run both, and the advanced one is rejected at upload |— |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1032[#1032] |2026-09-23 |O6 propagation: four contradictions between the ruling and the committed rulesets |decision, governance |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1035[#1035] |2026-09-23 |27 Scorecard callers omit actions:read and will startup_failure on their next standards pin bump |cicd, meta:campaign |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1037[#1037] |2026-09-23 |48 open Dependabot PRs re-introduce the codeql-action v4.38.1 startup-killer, and the dependabot.yml ignore rule is being bypassed in 15 repos |cicd, enhancement |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/1049[#1049] |2026-09-26 |Estate listing: 35 repositories are below the RSR 7-topic minimum |— |New first pass -|https://github.com/hyperpolymath/standards/issues/1055[#1055] |2026-09-28 |Orphan refs: automated agents leave unrelated-history branches that no gate can see (8 arena/* refs estate-wide; #1005's AC2 population has drifted again) |— |New first pass -|https://github.com/hyperpolymath/standards/issues/1056[#1056] |2026-09-28 |slavia #100 closure: class determinations for #994, startup-death mechanics + Dependabot recurrence for #968 (comment-perms cross-file) |— |New first pass -|=== - -=== Deliberately parked (3) - -Retain with an explicit blocker/resume trigger; revisit only when that trigger changes. - -[cols="1,1,7,3,2",options="header"] -|=== -|Issue |Updated |Title |Current labels |Basis -|https://github.com/hyperpolymath/standards/issues/100[#100] |2026-08-27 |Phase E — Production wiring + staging validation + rollout/rollback runbook |major, requirements-target |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/239[#239] |2026-08-27 |[campaign] TypeScript → AffineScript estate migration (UMBRELLA) |documentation, governance, meta:campaign, meta:recurring, meta:umbrella, migration |Carry-forward from 2026-09-24 plan -|https://github.com/hyperpolymath/standards/issues/443[#443] |2026-08-25 |Estate campaign: roll SonarCloud across all repos (parked, resume later) |status:needs-owner |Carry-forward from 2026-09-24 plan -|=== - -== 3. Permission and execution note - -This session authenticated as `arena-ai-coding-agent[bot]`. Read-only issue census and live branch-rule read succeeded, but both `gh issue edit #1057 --add-label invalid` and the REST add-label call returned HTTP 403 `Resource not accessible by integration`. The issue was not labeled or closed; no other issue writes were attempted. This is a permission boundary, not an authentication failure. The inventory and plan are repository work; a maintainer with issue-write permission can apply the phases safely. - -== 4. Source and method - -* Live open census: `gh issue list --repo hyperpolymath/standards --state open --limit 500 --json number,title,createdAt,updatedAt,labels,assignees,milestone,url`. -* Live rule read: `gh api repos/hyperpolymath/standards/rules/branches/main`; response includes `required_status_checks` and `code_scanning`. -* Carry-forward buckets: issue-by-issue table in `ULTRAPLAN-2026-09-24.adoc`, not title-only guesses. -* Intake policy: `docs/ISSUE-INTAKE-SPEC.adoc`, especially Rules 1, 2, 3, 5, and 7. -* This is one repository’s issue list; estate-wide issues must be routed to a canonical campaign/register and do not authorize cross-repo writes. - -== 5. Completion gate - -Do not call the backlog under control until all 199 listed issues have a verified live disposition; all open issues have scope or an explicit exception; every duplicate/superseded item points to a survivor; every decision is reachable from #787; and a fresh API census reproduces the ending counts. Order: *inventory → triage → contain P0/P1 → owner decisions → repo fixes → estate campaigns → verified closures*. - -== 6. 2026-09-29 Execution Progress & Live Verification Results - -=== Phase 0 — Live Verification & Ready-to-Close Evidence (`scripts/triage-2026-09-29-apply.sh`) - -[cols="1,2,5",options="header"] -|=== -|Issue |Live Verification |Status / Action - -|https://github.com/hyperpolymath/standards/issues/1057[#1057] -|Confirmed OPEN (`"probe"`, empty body, zero labels). -|Queued in `scripts/triage-2026-09-29-apply.sh` to label `invalid` and close with factual note. - -|https://github.com/hyperpolymath/standards/issues/956[#956] -|Verified live via `gh api repos/hyperpolymath/standards/rules/branches/main`: active rules are `deletion`, `non_fast_forward`, `required_status_checks` (22 required contexts across integration IDs `15368`, `57789`, `12526`), `required_signatures`, and `code_scanning` (`CodeQL`, `Hypatia`, `Scorecard` at `errors` / `high_or_higher`); zero retired rule types remain. -|Ready to close; automated in `scripts/triage-2026-09-29-apply.sh`. - -|https://github.com/hyperpolymath/standards/issues/708[#708] -|Verified scheduled Tuesday cron run `35700165587` (`2026-09-22T07:33:04Z`, `completed/success`), which updated tracker #803 (`scanned: 347`, `carrying a lockfile: 180`, `with drift: 15`, `check errors (rc≠0,1): 0`, `drifted entries: 29`) and uploaded artifact `lockfile-drift-report` (`id: 10682326843`, `1032` bytes). -|`scripts/triage-2026-09-29-apply.sh` downloads artifact `10682326843`, verifies zero `_w` slugs and zero `[drift] clean` stdout rows in the TSV, and closes #708 with evidence. - -|https://github.com/hyperpolymath/standards/issues/1013[#1013] -|Verified live via `gh api repos/metadatastician/burble/rulesets/18225024`: organization ruleset `EstateBranching` (`18225024`) carries `code_scanning: [CodeQL (errors / high_or_higher)]` only (`Hypatia` and `Scorecard` removed on 2026-09-22), curing all 68 inheriting `metadatastician/*` repos; `hyperpolymath/canonical-ums` is trimmed and re-archived (`archived: true`). -|Ready to close; automated in `scripts/triage-2026-09-29-apply.sh`. - -|https://github.com/hyperpolymath/standards/issues/1005[#1005] -|Confirmed from `2026-09-23T00:01:30Z` report: AC1 decided (keep `4.38.1` blocked; re-pin to `b96794f015dfd88f77b49b1c93e0fa7110f94c63`) and AC2 executed across all 40 live repos (94 workflow refs, 52 lock lines; 40/40 PRs merged; 0 live `@1c5b6756` or `@v4.38.1` remain). Subsequent Dependabot grouped `actions` re-bumps are tracked on #1037. -|Ready to close; automated in `scripts/triage-2026-09-29-apply.sh`. - -|https://github.com/hyperpolymath/standards/issues/1010[#1010] -|Narrowed to 13 Population-A repos (6 remaining repos are Population B under #1013). Verified via `gh api` that 11/11 public PRs (`proven-servers#90`, `cadastra#53`, `consent-aware-web#10`, `harvard-dehallucinator#18`, `paint-type#89`, `_pathroot#29`, `pong-ping#7`, `project-ovine#26`, `sim-public-relations#24`, `sr71-blackglider#20`, `stapeln#75`) are `MERGED`; 2 private PRs (`boj-server-mk2#47`, `common-signal#7`) are checked by `scripts/triage-2026-09-29-apply.sh` before closing. -|Ready to close once `scripts/triage-2026-09-29-apply.sh` confirms the 2 private PRs. - -|https://github.com/hyperpolymath/standards/issues/637[#637], https://github.com/hyperpolymath/standards/issues/709[#709], https://github.com/hyperpolymath/standards/issues/715[#715], https://github.com/hyperpolymath/standards/issues/784[#784], https://github.com/hyperpolymath/standards/issues/808[#808] -|Verified deduplication targets (#787, #968, #913); #658 is explicitly held open pending D10 on #787. -|Automated in `scripts/triage-2026-09-29-apply.sh` (including copying #808's zero-jobs startup-failure note onto #913 before closing #808). -|=== - -=== Phase 1 & 2 — Root-Cause Reproductions & Repository Fixes Applied on This Branch - -* **#1050 (P0) & #1054 (P1) — `.github/workflows/hypatia-scan-reusable.yml`, `.github/workflows/governance-reusable.yml`, `scripts/tests/hypatia-blocking-gate-test.sh`, `scripts/tests/science-ci-security-test.rb`**: - ** Reproduced #1050 against run `36504013478` (`hypatia-scan.yml`) and run `36504013387` (`governance.yml`): both dynamically resolve `hyperpolymath/hypatia.git HEAD`, which has failed `mix escript.build` since commit `4654d7a3d4` (`2026-09-26T14:56Z`, `hyperpolymath/hypatia#862`, tracked upstream at `hyperpolymath/hypatia#869`: unescaped `/` inside `~r/.../` character class at `lib/rules/pin_integrity.ex:56`; last compilable commit is `9f2f62f5c9463c79b33a5ebf54372166ce56f349`). When `Build Hypatia scanner` failed, `Relativize finding paths`, `Filter SARIF through the baseline before upload`, `Upload SARIF to code scanning`, and `Upload findings artifacts` still executed due to `if: always()`, causing `Upload SARIF to code scanning` to fail on a nonexistent `hypatia.sarif` (`Path does not exist: hypatia.sarif`) and mask the scanner build failure. - ** Removed `if: always()` from those four post-validation steps (which already sit upstream of the blocking gates), added a targeted hold on `9f2f62f5c9463c79b33a5ebf54372166ce56f349` for the 4-commit `hypatia#869` broken window (`4654d7a3d4..4f9874e3f5`) in both `hypatia-scan-reusable.yml` and `governance-reusable.yml` (automatically resuming `HEAD` once `hypatia` advances), and restored single-document `jq -e -s` validation in `Validate findings and count severities` so a clean `[]` scan is a positive control while empty/whitespace/truncated/multi-document output fails closed (#1054). All 30 checks in `scripts/tests/hypatia-blocking-gate-test.sh` pass. -* **#1040 (P1) — `scripts/apply-branch-gates.sh`, `config/rulesets/gates.json`, `scripts/tests/branch-gates-apply-test.sh`**: - ** Added `yaml_has_pr_trigger` / `wf_triggers_on_pr` so `apply-branch-gates.sh` verifies that each candidate gate workflow triggers on `pull_request` / `pull_request_target` targeting the default branch before deriving its job contexts into `required_status_checks`, reporting `no_pr_trigger=[]` (and `UNGATED` if zero contexts survive) instead of writing deadlocking contexts from `push`/`schedule`/`workflow_dispatch`-only workflows. Added Case 26 and Mutant J in `scripts/tests/branch-gates-apply-test.sh` (**103 passed, 0 failed**). -* **#1036 (P1) — `scripts/reconcile-scorecard-actions-lock.rb`, `scripts/tests/reconcile-scorecard-actions-lock-test.rb`**: - ** Updated `ScorecardActionsLock` to handle both directions of `gh-actions-lock v0.1.6`'s blindness to job-level reusable workflow `uses:` refs: (AC1) pre-filtering false `stale` findings whose `dependency` (`owner/repo@ref`) is referenced by a job-level reusable `uses:` in that workflow, and (AC2 / Arm D) rejecting workflows whose job-level reusable `uses:` ref is absent from `.github/workflows/actions.lock`. Added regression tests for both directions in `scripts/tests/reconcile-scorecard-actions-lock-test.rb`. -* **#1032 (P1, items 3 & 4) — `scripts/apply-tag-ruleset-canon.sh`, `config/README.adoc`, `tests/test_tag_ruleset_canon.sh`**: - ** Enforced `.source_type == "Repository"` before repo-level `PUT` in `scripts/apply-tag-ruleset-canon.sh` (failing closed with `REFUSED-NO-SOURCE-TYPE` when `.source_type` is absent and reporting `ORG-INHERITED` for `.source_type == "Organization"`), updated `config/README.adoc` canon identification rules, and added Property 14 + mutant test in `tests/test_tag_ruleset_canon.sh` (**31 passed, 0 failed**). -* **#1037 (P1) — `docs/DEPENDABOT-POLICY.adoc` & Live 48-PR Census**: - ** Re-enumerated all 48 Dependabot PRs: **14 open** (`bgp-backbone-lab#102`, `ensaid-spec#37`, `git-reticulator#115`, `hyperpolymath.github.io#42`, `ipv6-site-enforcer#99`, `JuliaForChildren.jl#25`, `marches#32`, `network-outpost#29`, `pow-the-game#101`, `self-destructing-git-garbage#25`, `social-media-polygraph#107`, `tangle#126`, `the-metadatastician#47`, `zerostep#97`), **19 merged**, **13 closed-unmerged**, **2 private (404)** (`canonical-ums#20`, `common-signal#6`). Confirmed root cause: subpath actions require `dependency-name: "github/codeql-action*"` (with trailing `*`), which holds even alongside `groups: actions: patterns: ["*"]` (proven by `standards#1060`). Documented the wildcard rule and revisit trigger in `docs/DEPENDABOT-POLICY.adoc` (AC5). -* **#1058 (Finding 2) — `1-formats/deed/spec/abnf/deed.abnf`**: - ** Removed the orphaned `; pending owner ruling. Grammar below is unchanged.` comment line from `1-formats/deed/spec/abnf/deed.abnf` and regenerated `.machine_readable/REGISTRY.a2ml` (`scripts/build-registry.sh --check` passes). -* **Additional `standards` `main` CI repairs**: - ** Updated `.github/workflows/actions.lock` for the #1060 Dependabot bumps (`haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d` and `tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd`) and fixed the `jq -e` empty-stdout hazard in `scripts/update-actions-lock.sh` (`scripts/tests/actions-lock-update-test.sh` passes). - ** Repaired the duplicate `if [ ! -s "$cache" ]` merge artifact in `scripts/apply-protection-floor.sh` (#1031; `scripts/tests/protection-floor-test.sh` passes **50/50**). - ** Cleared the retired `launcher-standard` filename token from `ULTRAPLAN-2026-09-24.adoc` and `ULTRAPLAN-2026-09-29.adoc` (`scripts/tests/check-launcher-standard-currency-test.sh` passes **17/17**). diff --git a/arena-session-787/787-execution-kit.md b/arena-session-787/787-execution-kit.md deleted file mode 100644 index 37a482b3d..000000000 --- a/arena-session-787/787-execution-kit.md +++ /dev/null @@ -1,166 +0,0 @@ -# #787 execution kit — 2026-09-26 owner rulings - -> Re-verified 2026-09-27: #787 body unchanged since 2026-09-23T17:28:50Z; all five -> Find-blocks byte-match the live body; `standards` main still at `2479cf7`. -> Stored on session branch `arena/01a0dd13-standards` because workspace-root files do not -> persist between turns in this environment. - -Three steps, in order. Step 1 uses the comment draft beside this file; steps 2–3 are below. -(Agent sessions with write access may execute these on the owner's behalf — the rulings -were given by the owner via selection UI on 2026-09-26.) - ---- - -## STEP 1 — post the ruling comment on #787 - -Paste the full contents of **`owner-rulings-comment-2026-09-26.md`** (beside this file) as a -comment on https://github.com/hyperpolymath/standards/issues/787 — then copy the comment's -URL (`#issuecomment-…`) for use in STEP 2. - ---- - -## STEP 2 — strike the five rows in the #787 issue body - -Edit the issue body and replace each row below with its struck counterpart -(F4a convention: strike, never delete; answer beside the row). -Replace `COMMENT-URL` in all five with the STEP 1 comment URL. - -Find: - -**D12. O1** GitHub Team for `metadatastician` — is it listed at education.github.com? Until then org rulesets 403 and it stays on per-repo rulesets. - -Replace with: - -~~**D12. O1** GitHub Team for `metadatastician` — is it listed at education.github.com? Until then org rulesets 403 and it stays on per-repo rulesets.~~ - -→ RULED 2026-09-26: **D12 — NOT listed → apply for GitHub for Nonprofits (Team free).** Per-repo rulesets until Team is active; the ratified Branch-Floor / Tag-Floor org rulesets (D94–D96) execute the moment it lands. ([ruling comment](COMMENT-URL)) - -Find: - -**D14. O3** Dispositions: `boj-build.yml` (255 repos — drop if BoJ is retired) · `mirror.yml` (142 repos skip for missing forge secrets — keep on which?) · `rhodibot.yml` (93 repos, 78% red — retire or remake?) · ClusterFuzzLite `cflite_*` (keep on which Rust/Zig repos?). - -Replace with: - -~~**D14. O3** Dispositions: `boj-build.yml` (255 repos — drop if BoJ is retired) · `mirror.yml` (142 repos skip for missing forge secrets — keep on which?) · `rhodibot.yml` (93 repos, 78% red — retire or remake?) · ClusterFuzzLite `cflite_*` (keep on which Rust/Zig repos?).~~ - -→ RULED 2026-09-26: **D14 — all four families stay; repair, not prune.** **BoJ is ALIVE** (*"in boj-server and boj-server-cartridges in hyperpolymath"*), so `boj-build.yml` stays; the KYAML migration (step 1 of 6 done, #1020 closed; steps 2–6 open) is **piloted on `standards` first** and **boj-server / boj-server-cartridges take updates as part of that critical path**. `mirror.yml`: provision the missing forge secrets (secret inventory first). `rhodibot.yml`: remake — 78% red is the bot's defect, not a retirement signal. `cflite_*`: keep on the Rust/Zig repos. ([ruling comment](COMMENT-URL)) - -Find: - -**D24. #306** Pages across **48** repos — enable, or delete the Pages workflow? Pages enablement is API/UI-only, so there is no implementable middle path. - -Replace with: - -~~**D24. #306** Pages across **48** repos — enable, or delete the Pages workflow? Pages enablement is API/UI-only, so there is no implementable middle path.~~ - -→ RULED 2026-09-26: **D24 — class-based disposition** (census corrected 2026-08-26: **40 repos, not 48**; 345 carry a Pages workflow; metadatastician has 0 defects). Genuine site repos (`pages.yml` / casket-ssg docs class) → enable Pages (`POST /repos/{o}/{r}/pages -f build_type=workflow`); `casket-pages.yml` on repos with nothing to publish → remove the workflow; `jekyll*` → always remove (Jekyll banned estate-wide); libraries/internal tooling → remove the workflow. Re-verify per the "an issue body is a dated record" rule before each write. ([ruling comment](COMMENT-URL)) - -Find: - -**D29. #245** Which plugin hosts to bind **at all** — WordPress / WebExtensions / Thunderbird MailExt / React-Next — given WP-PHP cannot load WASM? Four questions posted 2026-05-28, none answered. Blocks #246 and #280. - -Replace with: - -~~**D29. #245** Which plugin hosts to bind **at all** — WordPress / WebExtensions / Thunderbird MailExt / React-Next — given WP-PHP cannot load WASM? Four questions posted 2026-05-28, none answered. Blocks #246 and #280.~~ - -→ RULED 2026-09-26: **D29 — REOPENED.** #245 had been closed not_planned 2026-08-26 ("no TypeScript left to port"); the owner rules the plugin-host binding work back on. The old #245 / #246 / #280 stay closed as records of their own scope; a fresh issue carries the reopened work (filed with current evidence — note wordpress-tools is now 138 `.php` + Rust + PowerShell, so the WordPress question is a PHP/WASM question, not a TS-porting one). ([ruling comment](COMMENT-URL)) - -Find: - -**D43. When is the A2ML / `.deed` agent clear?** #19 (161 repos left, resumable at line 153 `lcb-website`) and #35 are held on this and nothing else. - -Replace with: - -~~**D43. When is the A2ML / `.deed` agent clear?** #19 (161 repos left, resumable at line 153 `lcb-website`) and #35 are held on this and nothing else.~~ - -→ RULED 2026-09-26: **D43 — the hold clears when #837 steps 1–3 have landed** (normative ABNF · per-family mapping specs · canonical translator + conformance lane). Until then the held sweeps stay parked; when they resume they resume **as conversions, never as in-place `.a2ml` edits**. Baseline at ruling: `launcher/launcher-standard_praxis.deed` landed (D73-C), 222 `.a2ml` remain in `standards`, no general translator yet, no Rust `.deed` reader anywhere (deed-ecosystem#67). ([ruling comment](COMMENT-URL)) - ---- - -## STEP 3 — file the fresh D29 issue (standards) - -Title: - -Plugin-host bindings, second opening: WordPress (PHP/WASM) · WebExtensions · Thunderbird MailExt · React-Next - -Body: - -Reopened by the D29 ruling on #787 (2026-09-26). The first opening (#245, closed not_planned -2026-08-26; children #246 / #280 closed completed) was closed as moot on the finding that all -five plugin repos then held **zero TypeScript files** — there was nothing left to port. The -owner has ruled the underlying question — which plugin hosts to bind **at all** — back open. - -## Current state of the candidate hosts (re-measured 2026-08-26) - -| Host | Estate repo(s) | What is actually there now | The real question | -|---|---|---|---| -| WordPress | wordpress-tools | **138 `.php`**, Rust, PowerShell — no TS | PHP plugin entry points cannot load WASM; can AffineScript reach the Gutenberg-blocks JS surface at all, or is this a PHP-only zone? | -| WebExtensions | universal-chat-extractor, double-track-browser | `.idr`, `.affine`, `.rs` | `browser.tabs.*` / `browser.runtime.*` surface (~200+ fns) — JS-loaded, workable in principle | -| Thunderbird MailExt | thunderbird-template-reloaded | `.idr`, `.affine` | MailExtensions API surface | -| React-Next | polyglot-i18n | 79 `.js`, 31 `.affine` | React component model, Next.js Pages Router | - -## Acceptance criteria (per the original #245 shape) - -- Each of the four hosts gets either **a bindings PR in the affinescript repo** or an explicit - **"won't bind" rationale** recorded here. -- WordPress's PHP/WASM ceiling is decided first — it gates whether wordpress-tools has any - AffineScript path or stays PHP/Rust. -- This issue closes when every plugin-blocked repo has at least one recorded path forward. - -## Relations - -- Supersedes the *scope* of #245 / #246 / #280 (all stay closed as their own records). -- Parent decision surface: #787 (D29 ruling comment). -- Book as a new D-row at `max(ledger, issue)` at write time; never renumber. - ---- - -## Owner-only browser steps (cannot be delegated to any agent session) - -### D12 — GitHub for Nonprofits application (after STEP 1–3, or in parallel) - -1. Sign in at **education.github.com** with the account that owns `metadatastician`. -2. Teachers/organisations path → **GitHub for Nonprofits** → start the application. -3. Applicant type: the organisation (`metadatastician`), not an individual. -4. Have ready: the org's mission description, a request letter on org letterhead (GitHub's - application form names what it accepts), and evidence of nonprofit status if held. -5. On approval (typically days–weeks), Team activates → org rulesets stop 403ing → - **execute Branch-Floor / Tag-Floor (D94–D96) per the ratified staging**: create scoped to - one repo → verify by `GET /repos/{o}/{r}/rules/branches/{default}` → widen to `~ALL` by - full-body PUT → re-verify → `apply-protection-floor.sh` report-only must return - **0 WOULD-CREATE** across all 68 repos. -6. Until then: per-repo floors remain the mechanism (PR #1034's applier is merged and - rsr-template-repo already carries a live `Branch-Floor` ruleset — the per-repo arm is - executing). - -### D16 — the bypass-actor app IDs (one glance, then the ruling executes) - -1. GitHub → **Settings → Applications** (Installed GitHub Apps / Authorized OAuth Apps). -2. Find the names behind IDs **1561**, **85455**, **946600** (the API will not resolve them; - only the UI shows them). -3. Recognised → keep and record the name. Unrecognised → remove; the D16 ruling is already - made ("remove if unrecognised"), so removal can then proceed estate-wide. - (Status check 2026-09-27: the `standards` and `rsr-template-repo` rulesets show empty - bypass lists, but the three IDs lived on other rulesets — no signal either way; the glance - is still owed.) - ---- - -## State of the surrounding work, measured 2026-09-27 - -- **#787**: no comments or body edits since the 2026-09-23T17:28Z batch. Nobody has pasted - this ruling, struck the rows, or filed the D29 issue yet. -- **`standards` main**: still `2479cf7` (2026-09-24) — three quiet days; this kit was - verified against that state. -- **KYAML** (couples to the D14/BoJ ruling): step 1/6 (#1020) CLOSED; steps 2–6 OPEN, and - **step 4 (#1023) is itself a pending owner ruling** — deciding KYAML scope is now the - next owner decision queued behind this one. -- **#837 (.deed conversion, gates D43)**: no activity since 2026-09-19; steps 1–3 not - started. The hold stands as ruled. -- **#306 (Pages, gates D24)**: unchanged since the 2026-08-26 census — the 40-repo list is - still the operative one. -- **New since the sheet was last worked**: #1049 (2026-09-26 — 35 repos below the RSR - 7-topic minimum) and #1050 (2026-09-27 — hypatia-scan-reusable at `2479cf7` produces no - `hypatia.sarif`; caller-visible failure at current main). Neither touches the five rows. -- **Succession rule**: after the 09-23 mass strike, open rows sit well below the ~30 - re-compilation threshold — answering these five will not trigger re-compilation. diff --git a/arena-session-787/RULESET-B-PROTOCOL.md b/arena-session-787/RULESET-B-PROTOCOL.md deleted file mode 100644 index 52fd526be..000000000 --- a/arena-session-787/RULESET-B-PROTOCOL.md +++ /dev/null @@ -1,81 +0,0 @@ -# RULESET B-PROTOCOL — merging PR #1051 past the `main gate` (2026-09-27) - -**Status:** the merge was instructed twice by the owner and refused by both routes -(normal and admin): ruleset `23787415` ("main gate: append-only + required checks + -signatures + scanning") is active with `bypass_actors: []`, and **19 of 19 workflow -runs on the PR head are `startup_failure`** (D39's `allowed_actions=selected` with -empty patterns + the codeql-action v4.38.1 startup-killer, #1037), so the 22 required -contexts never produce check-runs. No actor — owner included — can merge until the -ruleset is relaxed or the startup deaths are cured. - -This file makes Option B (relax → merge → byte-exact restore) turnkey for any session -holding `administration:write` (the owner's Claude Code sessions have done ruleset PUTs -before — see the D84 re-scope). The Arena session that authored PR #1051 cannot: its -token gets 404 on the ruleset write route (probed 2026-09-27, no-op PATCH; backup -verified byte-identical after the probe). - -**Auto-merge is ARMED on PR #1051** (`--auto --squash`). If the startup deaths are -cured first (Option A), the PR merges itself with no ruleset edit at all. - ---- - -## Path 1 — session with administration:write - -```bash -# 0. Fresh backup (never trust a file over the live state) -gh api repos/hyperpolymath/standards/rulesets/23787415 > /tmp/fresh-backup.json - -# 1. Confirm no drift since the committed backup -diff <(jq -S . /tmp/fresh-backup.json) \ - <(jq -S . arena-session-787/ruleset-23787415-backup-2026-09-27.json) - -# 2. Relax: drop required_status_checks + code_scanning, keep the rest -jq '.rules |= map(select(.type != "required_status_checks" and .type != "code_scanning"))' \ - /tmp/fresh-backup.json > /tmp/relaxed.json -gh api -X PUT repos/hyperpolymath/standards/rulesets/23787415 --input /tmp/relaxed.json - -# 3. Verify the PUT actually applied (a ruleset PUT has returned 200-with-empty-body -# and not applied before — always re-GET) -gh api repos/hyperpolymath/standards/rulesets/23787415 --jq '[.rules[].type]' -# expect: ["deletion","non_fast_forward","required_signatures"] - -# 4. Merge (squash, per D19a) -gh pr merge 1051 --repo hyperpolymath/standards --squash - -# 4b. ONLY if refused on required_signatures (unsigned squash commit): -# also drop that rule (jq select != "required_signatures"), re-PUT, retry merge. - -# 5. Restore — byte-exact, immediately -gh api -X PUT repos/hyperpolymath/standards/rulesets/23787415 --input /tmp/fresh-backup.json - -# 6. Verify restoration -diff <(gh api repos/hyperpolymath/standards/rulesets/23787415 | jq -S .) \ - <(jq -S . /tmp/fresh-backup.json) && echo RESTORED - -# 7. Record the timeline (relax → merge → restore, with clock times) on the PR and #787. -``` - -## Path 2 — owner, browser only - -1. `standards` → **Settings → Rules → Rulesets** → `main gate: append-only + required - checks + signatures + scanning`. -2. Toggle **Enforcement: Active → Disabled** (or Edit → remove the two rules above). -3. Merge [PR #1051](https://github.com/hyperpolymath/standards/pull/1051) — **Squash and merge**. -4. Toggle enforcement back / restore the rules. -5. Verify the ruleset reads 5 rules again. - -## The real cure (no ruleset edit needed) - -Relaxing the ruleset is the expedient. The durable fix is curing the startup deaths: -apply the **D39 canon `allowed_actions` payload** (88 patterns, on `origin/main` at -`d1bd7f42`) and the **#1037 codeql-action pin fix**, at which point the 19 workflows -run, the 22 contexts report, and auto-merge fires on its own. Note: re-scoping the -required contexts alone (the #1040 fix) is NOT sufficient — startup-dead workflows -produce no check-runs to require. - -## Doctrine note - -The estate records "disable-to-merge" as a defect shape (375 rulesets were disabled on -2026-09-22; D94–D96 added zero-bypass floors deliberately). This protocol is a one-off -under explicit, repeated owner instruction, with a pre-verified byte-exact restore and -mandatory post-restore verification — document it where the merge is recorded. diff --git a/arena-session-787/owner-rulings-comment-2026-09-26.md b/arena-session-787/owner-rulings-comment-2026-09-26.md deleted file mode 100644 index 0b545dcf4..000000000 --- a/arena-session-787/owner-rulings-comment-2026-09-26.md +++ /dev/null @@ -1,29 +0,0 @@ -## Rulings — the five owner-only rows, 2026-09-26 - -All five rows held back from the 2026-09-23 batch, answered together. Rows ruled here can be struck; owner's words quoted verbatim where given. - -**~~D12~~ — metadatastician is NOT listed at education.github.com → apply for GitHub for Nonprofits (Team free).** -Owner checked the dashboard ("Upgrade your academic organizations"): not listed. The nonprofits application is owner-and-browser-only — no agent can file it. Until Team is active, org rulesets stay 403, so the ratified **Branch-Floor / Tag-Floor org rulesets (D94–D96) execute the moment Team lands**, and until then the per-repo floor remains the mechanism for the 68 metadatastician repos (report-only baseline stands: 67 WOULD-CREATE + 1 ARCHIVED). - -**~~D14~~ — all four families stay; repair, not prune.** -- **BoJ: ALIVE.** Owner, verbatim: *"boj is alive, in boj-server and boj-server-cartridges in hyperpolymath, migration to kyaml as per standards repo to be piloted on the standards repo first and will need updates to boj-server / cartridges for this to happen effectively."* → `boj-build.yml` stays (consistent with D11's boj-server badge-pilot ruling). New dependency recorded: the KYAML migration (standards #1021–#1025) is **piloted on `standards` first**, and boj-server / boj-server-cartridges will need updates for the KYAML route to work — the cartridges side is now coupled to the KYAML step sequence, so those updates belong on the KYAML critical path, not after it. -- **`mirror.yml`: keep — repair.** Provision the missing forge secrets on the 142 skipping repos (secret inventory first, then per-forge enablement). -- **`rhodibot.yml`: keep — remake.** 78% red is a defect of the bot, not a signal to retire the function. -- **ClusterFuzzLite `cflite_*`: keep broadly** on the Rust/Zig repos. - -**~~D24~~ — class-based disposition, on the re-verified census (40 repos, not 48).** -- Genuine site repos (the `pages.yml` / casket-ssg docs class) → **enable Pages** (`gh api -X POST /repos/{o}/{r}/pages -f build_type=workflow`, one call per repo). -- `casket-pages.yml` on repos with nothing to publish → **remove the workflow**. -- `jekyll*` → **always remove** — Jekyll is banned estate-wide; no per-repo consideration. -- Libraries / internal tooling → **remove the workflow**. -- metadatastician needs nothing (0 defects there). The 2026-08-26 census comment on #306 is the enumerated list; re-verify before each write per the standing "an issue body is a dated record" rule. - -**~~D29~~ — REOPENED.** -#245 was closed not_planned 2026-08-26 on the re-verification "no TypeScript left to port"; the owner rules plugin-host binding work back **on**. The old #245 / #246 / #280 stay closed as records of their own scope. A fresh issue is to be filed with current evidence (host list unchanged: WordPress / WebExtensions / Thunderbird MailExt / React-Next — and note wordpress-tools is now 138 `.php` + Rust + PowerShell, so the WordPress question is a PHP/WASM question, not a TS-porting one). Its scope books as a new row at `max(ledger, issue)` at write time. - -**~~D43~~ — the A2ML/`.deed` agent hold clears when #837 steps 1–3 have landed.** -That is: (1) one normative ABNF, (2) per-family mapping specs, (3) the canonical translator + conformance lane. Until then: no new `.a2ml` writes, and the held sweeps (#19, 161 repos left, resumable at line 153 `lcb-website`; #35) stay parked. When they resume, they resume **as conversions, never as in-place `.a2ml` edits**. Progress marker at ruling time: `launcher/launcher-standard_praxis.deed` has landed (D73-C); 222 `.a2ml` remain in `standards`; no general translator exists yet and no Rust `.deed` reader exists anywhere (deed-ecosystem#67). - -**Still owed from the owner (unchanged):** the D16 glance — Settings → Applications, the names behind app IDs **1561, 85455, 946600** (ruled "remove if unrecognised"; the API will not resolve them, only the UI shows them). - -**Not owner-blocked:** D97's scope & cost study is agent work; the D29 fresh-issue filing likewise. diff --git a/arena-session-787/ruleset-23787415-backup-2026-09-27.json b/arena-session-787/ruleset-23787415-backup-2026-09-27.json deleted file mode 100644 index dce45aaba..000000000 --- a/arena-session-787/ruleset-23787415-backup-2026-09-27.json +++ /dev/null @@ -1 +0,0 @@ -{"id":23787415,"name":"main gate: append-only + required checks + signatures + scanning","target":"branch","source_type":"Repository","source":"hyperpolymath/standards","enforcement":"active","conditions":{"ref_name":{"exclude":[],"include":["~DEFAULT_BRANCH"]}},"rules":[{"type":"deletion"},{"type":"non_fast_forward"},{"type":"required_status_checks","parameters":{"strict_required_status_checks_policy":false,"do_not_enforce_on_create":false,"required_status_checks":[{"context":"CodeQL","integration_id":57789},{"context":"SPARK Theatre Gate","integration_id":15368},{"context":"SonarCloud Code Analysis","integration_id":12526},{"context":"analyze-actions / analyze","integration_id":15368},{"context":"analyze-js / analyze","integration_id":15368},{"context":"governance / Actions lockfile verify","integration_id":15368},{"context":"governance / Check Workflow Staleness","integration_id":15368},{"context":"governance / Code quality + docs","integration_id":15368},{"context":"governance / Debt ratchet","integration_id":15368},{"context":"governance / Exemption ratchet","integration_id":15368},{"context":"governance / Guix packaging policy (Nix retired)","integration_id":15368},{"context":"governance / Language / package anti-pattern policy","integration_id":15368},{"context":"governance / Licence consistency","integration_id":15368},{"context":"governance / Security policy checks","integration_id":15368},{"context":"governance / Trusted-base reduction policy","integration_id":15368},{"context":"governance / Well-Known (RFC 9116 + RSR)","integration_id":15368},{"context":"governance / Workflow security linter","integration_id":15368},{"context":"scan / Hypatia Neurosymbolic Analysis","integration_id":15368},{"context":"scan / gitleaks","integration_id":15368},{"context":"scan / rust-secrets","integration_id":15368},{"context":"scan / shell-secrets","integration_id":15368},{"context":"uses ⊆ actions.lock","integration_id":15368}]}},{"type":"required_signatures"},{"type":"code_scanning","parameters":{"code_scanning_tools":[{"tool":"CodeQL","security_alerts_threshold":"high_or_higher","alerts_threshold":"errors"},{"tool":"Hypatia","security_alerts_threshold":"high_or_higher","alerts_threshold":"errors"},{"tool":"Scorecard","security_alerts_threshold":"high_or_higher","alerts_threshold":"errors"}]}}],"node_id":"RRS_lACqUmVwb3NpdG9yec5CjMQdzgFq95c","created_at":"2026-09-21T19:48:43.361Z","updated_at":"2026-09-23T09:52:06.663Z","current_user_can_bypass":"never","_links":{"self":{"href":"https://api.github.com/repos/hyperpolymath/standards/rulesets/23787415"},"html":{"href":"https://github.com/hyperpolymath/standards/rules/23787415"}}} \ No newline at end of file diff --git a/canon.lock b/canon.lock index 7b14c6e94..e660a70ce 100644 --- a/canon.lock +++ b/canon.lock @@ -115,6 +115,16 @@ # --------------------------------------------------------------------------- # +# 2026-09-30 - PATCH 2.1.1 -> 2.1.2. THE MISSED CONSTITUTION BUMP (#1094). +# +# #1041 (2026-09-23) added one KNOWN-TENSIONS row to 0-canon/constitution/ +# (a measured contradiction: an unratified principle already projected as +# doctrine) without the bump THE RULE above requires in the same commit, so +# Gate A has failed on main since. PATCH: editorial register entry, no +# criteria-set change; #1041 itself adopts nothing. The constitution +# artefact hash is rewritten below in this commit per the +# [canon.artifacts] protocol. +# # 2026-09-19 - PATCH 2.1.0 -> 2.1.1. ADR-0003 RATIFIED. # # SCAFFOLD-LIFECYCLE.adoc flips Status: draft -> accepted (owner ruling @@ -209,16 +219,16 @@ # A released major is immutable. Bumping `version` to a new MAJOR means the # prior major's criteria file is copied to 0-canon/rsr/archive/ and pinned # there; a freeze guard fails any PR that mutates a frozen major. -version = "2.1.1" +version = "2.1.2" spec_family = "rhodium-standard-repositories" status = "draft" # draft | stable -released = "2026-09-19" +released = "2026-09-30" authority = "0-canon/constitution/ESTATE-CONSTITUTION.adoc" # The full git ref that realises this canon. A tag alone is not sufficient # (tags move); a commit alone is not sufficient (it has no version). Both. commit = "0000000000000000000000000000000000000000" # ← fill at release -tag = "canon-v2.1.1" +tag = "canon-v2.1.2" # --------------------------------------------------------------------------- # THE ARTEFACT SET — the files that ARE the canon. @@ -249,7 +259,7 @@ lifecycle = { path = "0-canon/rsr/SCAFFOLD-LIFECYCLE.adoc", constitution = { path = "0-canon/constitution/", # directory slots use the registry's own method: # sha256 over `git ls-files -s ` - sha256 = "e0f2c790f01b05bd331748918f197e7df0273ec0aa745908a109db3b2113bca7", + sha256 = "be48496f7f786d9aca12271afeb063c10b8ea6ce6bec2efad4f2401d0186ccef", method = "sha256(git ls-files -s )", slot = "constitution", normative = true } diff --git a/patches/airborne-submarine-squadron.patch b/patches/airborne-submarine-squadron.patch deleted file mode 100644 index 616d3d9c6..000000000 --- a/patches/airborne-submarine-squadron.patch +++ /dev/null @@ -1,341 +0,0 @@ -diff --git a/.github/workflows/actions.lock b/.github/workflows/actions.lock -index 9efbbfc..52f7e80 100644 ---- a/.github/workflows/actions.lock -+++ b/.github/workflows/actions.lock -@@ -8,7 +8,7 @@ workflows: - - 'denoland/setup-deno@v2.0.5' - '.github/workflows/codeql-analysis.yml': - - 'actions/checkout@v7.0.1' -- - 'github/codeql-action@v4.38.0' -+ - 'github/codeql-action@v4.38.1' - '.github/workflows/dogfood-gate.yml': - - 'actions/checkout@v7.0.1' - - 'hyperpolymath/deed-ecosystem@main' -@@ -61,9 +61,9 @@ dependencies: - commit: 'sha1-22d081ff2d3a40755e97629de92e3bcbfa7cf2ed' - owner_id: 42048915 - repo_id: 356423100 -- 'github/codeql-action@v4.38.0': -- ref: 'v4.38.0' -- commit: 'sha1-b96794f015dfd88f77b49b1c93e0fa7110f94c63' -+ 'github/codeql-action@v4.38.1': -+ ref: 'v4.38.1' -+ commit: 'sha1-1c5b675653bb5c22dbe9b12b556ec555138e09fd' - owner_id: 9919 - repo_id: 259445878 - 'hyperpolymath/deed-ecosystem@main': -diff --git a/.github/workflows/build-chain.yml b/.github/workflows/build-chain.yml -index aa03266..200dd1a 100644 ---- a/.github/workflows/build-chain.yml -+++ b/.github/workflows/build-chain.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # AffineScript build-chain gate — validates that build.sh produces a - # usable WASM artifact under the three supported scenarios: - # 1. affinescript is on PATH (real compile) -diff --git a/.github/workflows/codeql-analysis.yml b/.github/workflows/codeql-analysis.yml -index 7b2c1e9..103c539 100644 ---- a/.github/workflows/codeql-analysis.yml -+++ b/.github/workflows/codeql-analysis.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # For most projects, this workflow file will not need changing; you simply need - # to commit it to your repository. - # -diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml -index bb18b45..d97c733 100644 ---- a/.github/workflows/dogfood-gate.yml -+++ b/.github/workflows/dogfood-gate.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) - # - # dogfood-gate.yml — Hyperpolymath Dogfooding Quality Gate -diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml -index 431048f..37c9690 100644 ---- a/.github/workflows/governance.yml -+++ b/.github/workflows/governance.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: Governance - - on: -diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml -index eeea328..350aa63 100644 ---- a/.github/workflows/hypatia-scan.yml -+++ b/.github/workflows/hypatia-scan.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: Hypatia Security Scan - - on: -diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml -index 1684675..b323e6e 100644 ---- a/.github/workflows/instant-sync.yml -+++ b/.github/workflows/instant-sync.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # Instant sync — lightweight forge propagation on every push to any branch. - # Keeps GitLab and Bitbucket mirrors up to date without waiting for the main-only mirror. - -diff --git a/.github/workflows/label-triage.yml b/.github/workflows/label-triage.yml -index 814a192..fc79947 100644 ---- a/.github/workflows/label-triage.yml -+++ b/.github/workflows/label-triage.yml -@@ -1,5 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: MPL-2.0 -+# This workflow is managed by gh actions-lock. - name: Label Triage - - # Classify newly-filed issues against the estate label taxonomy. -diff --git a/.github/workflows/labels.yml b/.github/workflows/labels.yml -index 83ab941..af34c6b 100644 ---- a/.github/workflows/labels.yml -+++ b/.github/workflows/labels.yml -@@ -1,5 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: MPL-2.0 -+# This workflow is managed by gh actions-lock. - name: Labels - - # Applies the canonical estate label set from .github/labels.json. -diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml -index d31cb38..d12c355 100644 ---- a/.github/workflows/mirror.yml -+++ b/.github/workflows/mirror.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: Mirror to Git Forges - - on: -diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml -index 02e72c2..de6cdce 100644 ---- a/.github/workflows/pages.yml -+++ b/.github/workflows/pages.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0 - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: GitHub Pages (Ddraig SSG) - on: - push: -diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml -index 2f1b3ab..4252069 100644 ---- a/.github/workflows/push-email-notify.yml -+++ b/.github/workflows/push-email-notify.yml -@@ -1,4 +1,3 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. - # Dormant push-email notification. ARMED by setting the repo variable -diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml -index d2158a0..2f564ef 100644 ---- a/.github/workflows/scorecard.yml -+++ b/.github/workflows/scorecard.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: OSSF Scorecard - - on: -diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml -index 85b26e9..00cf1ca 100644 ---- a/.github/workflows/secret-scanner.yml -+++ b/.github/workflows/secret-scanner.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - name: Secret Scanner - - on: -diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml -index 3b5785e..7e414c4 100644 ---- a/.github/workflows/test.yml -+++ b/.github/workflows/test.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # Multi-platform test suite — runs blitz tests on Linux + macOS - name: Test Suite - -diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml -index 22bc284..faef2c6 100644 ---- a/.github/workflows/workflow-linter.yml -+++ b/.github/workflows/workflow-linter.yml -@@ -1,7 +1,5 @@ --# This workflow is managed by gh actions-lock. - # SPDX-License-Identifier: AGPL-3.0-or-later - # This workflow is managed by gh actions-lock. --# This workflow is managed by gh actions-lock. - # Prevention workflow - validates all workflows have proper security config - name: Workflow Security Linter - -@@ -26,7 +24,7 @@ jobs: - errors=0 - for f in .github/workflows/*.yml .github/workflows/*.yaml; do - [ -f "$f" ] || continue -- if ! head -1 "$f" | grep -q "SPDX-License-Identifier"; then -+ if ! awk '/^---[[:space:]]*$/ { next } /^#/ { print; next } { exit }' "$f" | grep -q "^# SPDX-License-Identifier:"; then - echo "ERROR: $f missing SPDX header" - errors=$((errors + 1)) - fi -diff --git a/dist/airborne-submarine-squadron.wasm b/dist/airborne-submarine-squadron.wasm -new file mode 100644 -index 0000000000000000000000000000000000000000..ca2481cd30b107e1cd6c50149c7883ccd7191bfe -GIT binary patch -literal 8099 -zcmd5>%a0z#5$~CAzUR#D_P6i%*6jOfFp54Ak^?PRVjDjYb|6wB*=xLp{nqQXcbAZy -z>|+i@igJoj4qP}S61n8g4T)PM5KYfj?b+{K8V}b|a3)iB1_%FD3&1Csmln{x=h?@tSjaIepAMC9E*Sn`>u~4l;q9$E -zhwtqlUA=R#{qvpe4^B63-nja~!OqdPF_jli2Vo_u*6NLBD^7ZP`)s>^U~p)7WOQtN -zVsdJFhSJ%&`Gv)$<(1X7^^H@{J%2h1Otli2pjL-DcfS$W*P`0q_TK)%FGJJXxxI6A -z_3&s5t8cUpkGAh*FQ=ltt)1KEbTcrm&tE(p8E0ZVf;ct={=#qqRwvnpxXL!gQ({4^!h&tF -zRUt4S&M(G83T@2eLLvf+LG|>gl1VbQrxOxL(h29Yz|CMAw!+!rf-VEBGPf&GIVmo+JF|-#{0bbN>U%on+3Zxa=PT_wz -zx}8=FJ2k2)hN#P?vX?4eBD^3u8X#4+rb8URnppd(-;Faivh`FAeKzrAPIOe1PKmu;T{9c&`7Gv9>#!@6W*yabb^e08U(c*Two_8*r6RquqD+h -zyD7RSCtcKa%eLkQcM%`N)ZK!m0)3t89A^U}-LIa9sm@Iyp}K6KP-qbL#tO&~-Yz<& -zUvj%ggjp=NZR^=e^@O^jDFg -zZ?O%3&UvTB|CGR@cHk@I`rV8zX7$katL!Uyc_QOYYO0@`TK~;_hkpozCUSub -z09nia5nI?<@v>`&eI_#wenok?+8HEp?Tnx5#&*+M5dzL-zbDT{xeRc#Q6#nIMjiHR -z&YUk71n)~@##>VkyJH1TajA($8lo8#HNkuJI-ZLlLxD7?sb$e*9qD5wQn<54E%uWE -zK{JV{CGPrD7_^R;jrT_B2w~@N4{4pD3LfkniCy1r8WqmrHszh;IW((Gh9Kt7kv?Xr -znz>e*9J|)<&~xlsmBF>@n0nd}iwWNr*el2zqmF<-*b(qYkti~acP?qz;(Wo*)z#_% -zF1}*Lm|~q8>(p4M#(8StzKCSnM<01iL)FvE&D&XSJ+1@#9q#qKAAUt-JVA{{AHwc%&b0k?jtAC#{muuU743hA1n?d7F;Z6FE>Vw2_L-5 -z;p|nHJn;gH07ol<&>M^oSEXZXn-Jt5)f391wkbZg5X#l1wosd -z1VK>}2zu8%2oiJ|q-jSw;W`-HTAv5O<@9?X35#C@gS+StL3%sk%OHI$eie-Egl9n7 -zo$x$Jerl{0%4+Rvphx;(8B&4&B=?T?L5tMBn${55rH5Q4Uj%wA)$F5E6rb^1&)mYL2M!r -z#HIl#pVh8MCs&_j(%{RL2ijLW;GLxcP<1Iy7 -zUJfJl;c9l0m8PKU@|2iKlqQJLRN4cVPo=$5pFA~mAL7bgb$<`+SlU+-e-^k0Rrk9P -zVoQB|fwhxqo6rb_>!&vLAl?Hsz%~Y%MClL>QZJ;#G|bWwCQ&*{{WJvW7>%)XoJo{U -z&^V1kI!Ti(MM1E1nntK<(-axYQeqONDZ-ONigaS>9Fr(TD$s~s!0JdbRCMbx3#PEj}ZKiISb~40~*EPlM4e -zi-*3f$hR9l1mIefG*@sPCECPID5ivZs25dbk)r)HfT|gyVPyU&jiD+g&`VbEBc1U- -zeW4Q)&OkIcO|m(f(XKN`q+MqYrWfZXc5I_7JGcBh^W;$Zi73>Qc -z15I8eawnRGmYT+#F5e??B`ld%9-_i@JbrRza&!5}^2cY%AN&JUH3L;+P}Lk%4WRJF -zd6GY%rJyjU%hwrvyp}*I4^aWC>OQsn*;+C!U#^+y2Ak%?QvHFSFz}6cqG|s4lTctz -zSHEkR^Px~4a|+W>^2cX3Z5{)~UqQ_bREt41b5JdSYMl%US_%qtx_Sp=&Vy1Oa|%#Z -z_q9#qW2O_doH#R`u<1BAoxpT*vT10kY0T*oexx-J6sDDjs4#uZAIOPsY}#`SNH6+c -zPX?ryf%N1+dI6;OWFXK|AehtTo1}rD0HQoZ1rWVFVQu^cj&E(+cMOL`@9oQQSjN$p -zQABCBP(o|?<#5+HxS%HPP7XxwTn6EZETl0?|0=P@^*1G -zk=|z4aEq?m=f>Ure*USW1cZO>;HJcD)fq@F2T})+`pH0`r9dzTO+}RpAS@MS4+QtA -zKZdxb>0QaLr|=-`6c7LM478;3U1E>z?P-A7Wj;CO))fCGOpLp4i`fy)7?!+g;g&>?0cw^oeZq!r9HsnEA?;vu|x090qZ_r#x`+(nW|rv+>9P#BaQL -z>D(r!o-gZsZR4T#!-J~#O*VAl?B&a6FI{|zUb%GPjq{sVu;jNHgnZ~Vhh<+isCmVf -z4|r^!wBu8&u;X?PuJ0e*-log%U*Fq0*kSJO`&%~-_HWa&yLl6W%kLcQ+&Nk??yGjZ -zu>zg9-Q^1#H+K#WkLX}q{%`L~^v?dlHtp@-*uF*A_xF!>Zohl#)G2tdKdyyPx%B$~ -E0E7_r_W%F@ - -literal 0 -HcmV?d00001 - -diff --git a/gossamer/app_gossamer.js b/gossamer/app_gossamer.js -index ee2a91f..26688b3 100644 ---- a/gossamer/app_gossamer.js -+++ b/gossamer/app_gossamer.js -@@ -771,8 +771,6 @@ function drawEvelCameratron() { - ctx.moveTo(-2, -5); - ctx.quadraticCurveTo(-8 - Math.sin(world.tick * 0.1) * 3, -8, -6 - Math.sin(world.tick * 0.15) * 4, -3); - ctx.stroke(); -- ctx.restore(); -- - ctx.restore(); // Undo zoom transform - - // Frame border + label -diff --git a/index.html b/index.html -index 03139ba..c0c5332 100644 ---- a/index.html -+++ b/index.html -@@ -704,9 +704,19 @@ - })(); - - -- -- -- -- -+ -+ -+ -+ -+ -+ -+ -+ -+ -+ -+ -+ -+ -+ - - -diff --git a/test/compatibility_test.js b/test/compatibility_test.js -index edd0f7b..aec1669 100644 ---- a/test/compatibility_test.js -+++ b/test/compatibility_test.js -@@ -116,7 +116,12 @@ Deno.test("compat: HTML entry points load gossamer/wasm_abi.js", async () => { - - // ── 10. Groove manifest shape remains explicit and passive ─────────────── - Deno.test("compat: .well-known/groove/manifest.json keeps current ASS contract", async () => { -- const raw = await Deno.readTextFile(ROOT + ".well-known/groove/manifest.json"); -+ let raw; -+ try { -+ raw = await Deno.readTextFile(ROOT + "www/.well-known/groove/manifest.json"); -+ } catch { -+ raw = await Deno.readTextFile(ROOT + ".well-known/groove/manifest.json"); -+ } - const manifest = JSON.parse(raw); - - assertEquals(manifest.service_id, "airborne-submarine-squadron"); diff --git a/scripts/tests/docstring-scan-test.sh b/scripts/tests/docstring-scan-test.sh index c2c692dd5..5f5232521 100755 --- a/scripts/tests/docstring-scan-test.sh +++ b/scripts/tests/docstring-scan-test.sh @@ -50,7 +50,13 @@ EOF scan() { bash "$SCANNER" "$@" 2>&1; } echo "== calibration: standards PR #1034 at 1cc72cdc80c9 (CodeRabbit: 13 functions / 2 files / 0.00% / 3 skipped)" -if git -C "$ROOT" cat-file -e 1cc72cdc80c9 2>/dev/null; then +# The calibration commit is PR #1034's PRE-SQUASH head: it lives only under refs/pull/1034/head, +# so no clone of main contains it, however deep. Fetch it by full SHA on a miss. No --depth: in a +# complete clone that would write .git/shallow and truncate main's history for every later test. +CALIBRATION=1cc72cdc80c9c60b2a857df7d8753a7dfb7e87fb +git -C "$ROOT" cat-file -e "$CALIBRATION^{commit}" 2>/dev/null || + git -C "$ROOT" fetch --quiet --no-tags origin "$CALIBRATION" 2>/dev/null || true +if git -C "$ROOT" cat-file -e "$CALIBRATION^{commit}" 2>/dev/null; then out="$(cd "$ROOT" && scan --range 1cc72cdc80c9^..1cc72cdc80c9)" check "calibration files" 2 "$(field "$out" files)" check "calibration functions" 13 "$(field "$out" functions)" @@ -58,8 +64,8 @@ if git -C "$ROOT" cat-file -e 1cc72cdc80c9 2>/dev/null; then check "calibration skipped" 3 "$(field "$out" skipped)" check "calibration coverage" 0.00% "$(field "$out" coverage)" else - # A skip is not a pass: a shallow clone must not report the known-answer control as green. - bad "calibration commit present (fetch full history)" "1cc72cdc80c9 reachable" "absent" + # A skip is not a pass: an unfetchable calibration commit must not report the known-answer control as green. + bad "calibration commit present (fetch by SHA from refs/pull/1034/head failed)" "1cc72cdc80c9 reachable" "absent" fi echo "== planted positive: a new undocumented function blocks under --check" diff --git a/ziz-drop/DESIGN.adoc b/ziz-drop/DESIGN.adoc deleted file mode 100644 index 9c890bbed..000000000 --- a/ziz-drop/DESIGN.adoc +++ /dev/null @@ -1,208 +0,0 @@ -// SPDX-License-Identifier: CC-BY-SA-4.0 -= Žiz — Design -:toc: macro -:icons: font - -toc::[] - -Status: *pre-alpha design.* Everything here is intent until `ziz0` runs it. -See link:TRIAGE.adoc[TRIAGE.adoc] for what was deliberately left out, and why. - -== One-paragraph summary - -Žiz is a unityped, homoiconic, reflexive language. There is one value domain, -programs are values, and the reader, printer, evaluator and environment are -ordinary values reachable from user code. Žiz has *no typechecker* and never -rejects a program for classification reasons. Instead every term carries a -*Judgement Evidence Graph* (JEG) entry: claims about the term, each linked to -the evidence for it (author assertion, static inference, runtime observation, -test outcome). Tooling *reads* the JEG; the runtime *appends* to it. The -first implementation, `ziz0`, is an interpreter written in Chapel. - -== What Žiz is *not* - -It is not dialectical. Expressions are not triads. There is no boundary -operator, no simplicial complex, no sheaf, no "Real". The name is a pun and -the pun is permitted in documentation and error messages; it has no -semantics. See TRIAGE.adoc §Finding 1. - -== Unityped, precisely - -Following Harper: a "dynamically typed" language is a statically typed -language with exactly one type. Every Žiz term has type `V`. "Untyped" is -the same fact seen from the syntax side (no annotations, no static -judgement). Runtime tag dispatch is pattern-matching on the single sum -`V = nil + bool + int + real + str + sym + pair + … + (V → V)`. The classical -denotational backdrop is Scott's D∞ (`D ≅ [D → D]`); we cite it and do -nothing further with it. - -== Core value domain - -[cols="1,2,2", options="header"] -|=== -| Tag | Payload | Notes - -| `nil` | — | the empty list and the false-ish sentinel -| `bool` | true / false | -| `int` | arbitrary precision | `ziz0` uses Chapel `int(64)` for now -| `real` | IEEE 754 binary64 | -| `str` | UTF-8 byte sequence | *content* may be any Unicode; *syntax* is ASCII -| `sym` | interned name | -| `pair` | car, cdr | lists are right-nested pairs ending in `nil` -| `vec` | contiguous sequence | -| `map` | ordered associative | -| `fn` | params, body, env | closures -| `prim` | host procedure | -| `env` | frame + parent | first-class -| `node` | tree-sitter node id | anchor into the CST; used by the JEG -| `claim` | subject, judgement, evidence | a JEG entry, also a value -|=== - -== Homoiconicity - -Source text →(reader)→ `V` →(evaluator)→ `V` →(printer)→ source text. -The reader's output is the AST; the AST is a list. Macros are ordinary -functions from `V` to `V` marked with `defmacro`. - -== Metaiconicity - -*Owner's term; this is the working definition pending the owner's own.* - -The mapping between text and values is itself a value. Concretely: - -* `(reader)` returns the current reader as a `map` of dispatch entries - (`char -> fn`). `(set-reader! m)` installs a new one. Reader macros are - therefore user code, and the *shape* of the language is data. -* `(printer)` / `(set-printer! m)` likewise. -* Both are scoped to the current `env`, so a module can change its own - surface syntax without changing anyone else's. - -This is what makes the off-side surface and the plain S-expression surface -*the same language* with two reader tables, rather than two dialects. It is -also where a one-glyph alias for the evaluator (e.g. a Cyrillic letter) would -live *if* the owner wants one: as a reader-table entry mapping to an ASCII -name, never as a lexical primitive. - -== Reflexivity - -* `(eval v [env])`, `(current-env)`, `(env-parent e)`, `(env-bindings e)`. -* `(jeg)` returns the live Judgement Evidence Graph for the current program. -* `(claim subject judgement . evidence)` appends to it. -* `(node-of v)` returns the CST anchor of a value if it came from source. - -Closest existing relative: Kernel (Shutt) — operatives receive unevaluated -operands and the caller's environment as first-class objects. Žiz's -`defmacro` + first-class `env` is a conservative version of that; whether to -go the full fexpr route is an open question. - -== Lexical rules (ASCII-only) - -The surface syntax uses *only printable ASCII* plus newline and tab. -Identifiers may not contain non-ASCII. String *contents* may. Rationale: -grep/diff/review/terminal/keyboard hygiene, and because anything non-ASCII -that matters can be introduced as a reader alias (§Metaiconicity). - -=== `sexp` reader - ----- -( ) [ ] { } ' ` , ,@ ; -"string with \" \\ \n escapes" -integer ::= -?[0-9]+ -real ::= -?[0-9]+\.[0-9]+([eE][-+]?[0-9]+)? -symbol ::= [A-Za-z_+\-*/<>=!?%&|^~$][A-Za-z0-9_+\-*/<>=!?%&|^~$.:]* -keyword ::= :symbol ----- - -`[ ]` reads as a `vec`, `{ }` as a `map`. - -=== `layout` reader (off-side) - -A line with two or more forms is an implicit list. A following block that is -indented deeper continues that list, one form (or nested implicit list) per -line. A line with a single form is *not* wrapped. `\` at end of line -continues. Explicit brackets disable layout inside them. - -Implemented as a tree-sitter *external scanner* emitting -`INDENT` / `DEDENT` / `NEWLINE` from an indent stack — off-side syntax is not -expressible in a context-free grammar, which is why any "N-rule EBNF" claim -for a layout language is wrong on its face. - ----- -define (fact n) - if (= n 0) - 1 - * n (fact (- n 1)) ----- - -reads identically to - ----- -(define (fact n) (if (= n 0) 1 (* n (fact (- n 1))))) ----- - -== Special forms - -`quote` `quasiquote` `unquote` `unquote-splicing` `if` `define` `set!` -`lambda` `defmacro` `begin` `let` `claim`. Everything else is a function. - -== Evaluation - -Eager, left-to-right, lexically scoped, proper tail calls required of any -conforming implementation (`ziz0` does not have them yet — that fact is a -JEG entry on `ziz0`, not a lie in this document). - -Errors are values. A failed operation returns an `error` map and *records a -claim* (`(claim node :raised {...} :evidence :runtime)`). Nothing unwinds -unless the caller asks via `(raise!)`. - -== Judgement Evidence Graph - -Full model in link:docs/JEG.adoc[docs/JEG.adoc]. Summary: - -* *Judgement*: a proposition about a subject (`:callable`, `:arity 2`, - `:returns :int`, `:pure`, `:raised`, `:tested-by`, …). Open vocabulary. -* *Evidence*: why we believe it — *kind* (`:asserted`, `:inferred`, - `:observed`, `:tested`, `:contradicted`) and *provenance* (who/what/when). -* Subjects are CST node ids; the graph survives re-parsing via tree-sitter's - incremental edit tracking. -* Append-only during a run; merged across runs. - -A JEG lint reports *unsupported* and *contested* judgements. It never blocks -a build; a `Mustfile` may make a threshold a gate — project policy, not -language semantics. - -== Toolchain - -Names are the owner's: `claudia`, `boggs`, `federici`, `dunayevskaya`, -`assata`. *Role assignment is undecided.* Two candidate mappings exist -(this repo's original guess, and Gemini's); the owner picks. Needed roles: - -. reader/printer registry (metaiconic tables) -. evaluator core -. JEG store / merge / query -. grammar, CST anchoring, editor integration -. CLI / REPL / project driver -. (later) memory / resource management, if not delegated to Chapel - -== Bootstrap plan - -. `ziz0` (Chapel): `sexp` reader, evaluator, printer, in-memory JEG. - Single locale. No FPGA. -. `ziz0` gains the `layout` reader via the tree-sitter C parser through - Chapel's C interop. -. JEG persisted (`.jeg.a2ml`, see JEG.adoc). -. Self-hosting: reader/evaluator rewritten in Žiz, run under `ziz0`. A - λ-calculus interpreter with the Y combinator is the smoke test. -. Only then: backends. Chapel-PGAS distribution via `chapeliser` first, - because the host is already Chapel. FPGA acceleration lives inside - `chapeliser`, behind Chapel; Žiz never sees it. - -== Related work (real) - -Kernel (Shutt, fexprs + first-class envs) · Refal (structural rewriting) · -Scheme R7RS-small (the sexp core) · sweet-expressions / SRFI-110 (layout -over S-expressions) · Harper, PFPL ch. 22 (unityped) · Scott 1969 (D∞). - -== Non-goals for the foreseeable future - -Static types. A typechecker under another name. Triads. Kaomoji. Bitstreams. diff --git a/ziz-drop/Justfile.ziz-fragment b/ziz-drop/Justfile.ziz-fragment deleted file mode 100644 index 260076b75..000000000 --- a/ziz-drop/Justfile.ziz-fragment +++ /dev/null @@ -1,15 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Append these recipes to the Justfile supplied by the RSR template. - -build: - chpl --fast bootstrap/ziz0.chpl -o ziz0 - -examples: build - for f in examples/hello.ziz examples/fact.ziz examples/quote-eval.ziz examples/reflexive.ziz; do \ - echo "== $f"; ./ziz0 --file=$f --jeg=observe; done - -grammar: - cd grammar && tree-sitter generate && tree-sitter test - -ascii-check: - ! grep -rnP '[^\x00-\x7F]' examples/ grammar/grammar.js bootstrap/ziz0.chpl | grep -v '"' || true diff --git a/ziz-drop/README.adoc b/ziz-drop/README.adoc deleted file mode 100644 index 7538c6a05..000000000 --- a/ziz-drop/README.adoc +++ /dev/null @@ -1,92 +0,0 @@ -// SPDX-License-Identifier: CC-BY-SA-4.0 -= Žiz -:toc: macro -:icons: font - -image:https://img.shields.io/badge/status-pre--alpha-red.svg[Status: pre-alpha] -image:https://img.shields.io/badge/License-MPL--2.0-blue.svg[License: MPL-2.0] - -A unityped, homoiconic, *metaiconic*, reflexive language with **no -typechecker** — instead, a *Judgement Evidence Graph* records what is -believed about every term and why. Bootstrapped in Chapel. - -toc::[] - -== Status — read this first - -*Nothing runs yet.* This repository holds a design, a tree-sitter grammar -skeleton, and a Chapel bootstrap interpreter that has not yet been through a -Chapel compiler. If a model or a person tells you Žiz is "locked in", is -"dialectical", evaluates "triads", or can be "synthesised end-to-end in 48 -hours", see link:TRIAGE.adoc[TRIAGE.adoc]. - -== Routing - -[cols="2,3", options="header"] -|=== -| If you want… | Go to - -| What Žiz is, precisely, and what it is not -| link:DESIGN.adoc[DESIGN.adoc] - -| The Judgement Evidence Graph — the thing that replaces a typechecker -| link:docs/JEG.adoc[docs/JEG.adoc] - -| Which AI-generated claims about Žiz are real, misapplied, or invented -| link:TRIAGE.adoc[TRIAGE.adoc] - -| The grammar (tree-sitter, ASCII-only, off-side via external scanner) -| link:grammar/grammar.js[grammar/grammar.js], link:grammar/src/scanner.c[grammar/src/scanner.c] - -| The bootstrap interpreter -| link:bootstrap/ziz0.chpl[bootstrap/ziz0.chpl] - -| Examples -| link:examples/[examples/] -|=== - -== Sixty-second tour - -[source,lisp] ----- -(define (fact n) - (if (= n 0) 1 (* n (fact (- n 1))))) - -(claim fact :arity 1 :evidence :asserted) ; a judgement, with provenance -(print (fact 10)) ----- - ----- -$ ziz0 --file=examples/fact.ziz --jeg=observe -3628800 -; --- JEG: 6 judgements, 23 evidence edges -(sym:fact :arity 1) ; asserted=1 observed=11 -(sym:fact :takes 0 :int) ; observed=11 -(sym:fact :returns :int) ; observed=11 -(sym:fact :pure) ; asserted=1 ----- - -No type was declared. No type was checked. Every belief about `fact` is in -the graph with the evidence that supports it; tools decide what to do with -that, and they can disagree with each other. - -== Building (once Chapel is available) - ----- -just build # chpl --fast bootstrap/ziz0.chpl -o ziz0 -just examples # runs every examples/*.ziz the sexp reader can read -just grammar # tree-sitter generate && tree-sitter test ----- - -== Toolchain names - -`claudia` · `boggs` · `federici` · `dunayevskaya` · `assata` — the owner's -names. Role assignment is *not yet decided*; see TRIAGE.adoc appendix. - -== Governance - -Follows the Rhodium Standard Repository conventions from -`hyperpolymath/standards` (the RSR template supplies `SECURITY`, -`CONTRIBUTING`, `Mustfile`, `.machine_readable/`, etc.). Language policy: -Chapel for the bootstrap, C only for the tree-sitter scanner, JavaScript -only for the tree-sitter grammar DSL. No Python, no Rust component, no Deno. diff --git a/ziz-drop/TRIAGE.adoc b/ziz-drop/TRIAGE.adoc deleted file mode 100644 index 38e2256ea..000000000 --- a/ziz-drop/TRIAGE.adoc +++ /dev/null @@ -1,235 +0,0 @@ -// SPDX-License-Identifier: CC-BY-SA-4.0 -= Žiz — Triage of the Gemini material -:toc: macro -:icons: font - -toc::[] - -== Purpose - -A third-party model (Gemini) produced a large body of material about Žiz and -asserted it was "locked in" and sufficient to "synthesize the entire system -end-to-end" in 48 hours. This document sorts that material into bins so -that nothing hallucinated leaks into the canonical design. - -*Rule:* anything in bin B or C is quarantined. It may be promoted to bin A -only by the owner, in a commit that cites the design reason — never by an AI -agent. - -== Finding 1 — the contamination has a single root - -Every hallucinated structure in the transcript descends from one move: -Gemini took the name *Žiz* (a Žižek pun), inferred "therefore Hegelian -dialectics", and made *dialectics the semantics of the language*. From there: - ----- -"Žiz" → Žižek → Hegel → thesis/antithesis/synthesis - → "every expression is a 3-tuple (triad)" - → "a triad is a 2-simplex" → boundary operator ∂₂ → "∂∘∂ = 0 is the invariant" - → simplicial complexes replace ASTs → homotopy = execution → sheaves → H¹ = consensus - → Lacan → "Standard Lacanary", the Real = /dev/null, objet petit a GC - → Sartre / Lippmann / interpassivity / fetishistic disavowal - → Cyrillic Ж as "the reflexive self-evaluator node" ----- - -None of this was in the owner's brief. Cut the root and the tree falls. -*The language is not dialectical. The pun lives in docs, not in semantics.* - -== Finding 2 — Gemini's examples refute Gemini's grammar - -Its "14-rule EBNF" says `Triad = "(" Thesis Antithesis Sublation ")" | Atom` -— every list has exactly three elements. Its own programs then contain -`(Ж 'if c a b)` (5), `(Ж 'match term c1 c2 c3)` (6), `(Ж 'let (…) body)` -(4), `(Ж 'attach-evidence a b "s")` (4). The λ-calculus interpreter it wrote -is an ordinary n-ary Lisp with quote marks sprinkled on and `Ж` prepended -to every call. When the owner said it looked "unusually familiar", Gemini -conceded: "beneath the Cyrillic Ж and the Hegelian terminology, the engine is -fundamentally a homoiconic S-expression evaluator". That is the most honest -sentence in the transcript. - -== Finding 3 — three incompatible syntaxes - -The transcript contains (a) parenthesised pseudo-Lisp, (b) a -Kotlin/Scala-flavoured `val x = Ž.Dialectic(False)` with `throw`/`catch`, -and (c) verbatim **Zig** (`@import`, `comptime`, `!void`, `for (xs) |*x|`, -`@compileError`). (c) also demands compile-time *rejection* of programs — -the exact thing the brief forbids. A model that has not noticed it is -switching languages is not designing one. - -== Finding 4 — reliability anti-signals to watch for - -"Beyond a shadow of a doubt" · "everything is locked in" · "always the only -correct choice" · an architecture diagram credited to a stock-photo site · -an "existential hazards" section for a language that does not exist · a -sixth toolchain name (`anuradha`) and a `MarxInterpreter` appearing once with -no introduction · a system prompt for another model that misspells its own -core term ("HOMOMICONIC"). - -== What the owner's brief actually contained (reconstructed) - -. Unitype / untyped — one value domain. -. Homoiconic. -. Metaiconic — *owner's term; owner's definition still needed.* -. Reflexive. -. No typechecker; a Judgement Evidence Graph alongside tree-sitter. -. Bootstrapped in FPGA-augmented Chapel. -. Off-side / bracketless surface (appears mid-transcript; assumed owner's). -. Toolchain names `claudia`, `boggs`, `federici`, `dunayevskaya`, `assata`. -. The name — and therefore a licence for jokes in *documentation*. - -Everything else in the transcript is Gemini. - -== Bin A — real, adopted - -[cols="2,3", options="header"] -|=== -| Item | Notes - -| Unityped vs untyped explanation (Harper/Scott; one universal type `D ≅ [D→D]`; runtime tag checks are pattern matches on the sum) -| Correct and well put — the only fully accurate technical passage. Adopted - in DESIGN.adoc §Unityped. - -| Comparison to Kernel (Shutt) and Refal -| Kernel's fexprs + first-class environments are the closest real relative - of "reflexive + metaiconic". Added to DESIGN.adoc §Related work. - -| Off-side / bracketless surface -| Adopted, but via a tree-sitter external scanner; Gemini's own layout - examples are inconsistent (an ad-hoc `:` opener with no rule). - -| tree-sitter grammar with an external layout scanner -| Adopted (`grammar/`). This was the one concrete, correct engineering - suggestion in the Mythos prompt. - -| Toolchain names -| Owner's. *Roles undecided* — see below. -|=== - -== Owner to confirm - -[cols="2,3", options="header"] -|=== -| Item | Question - -| Ж (Cyrillic zhe) as a one-glyph name for the evaluator/self -| Cute, not intrinsically wrong, collides with ASCII-only. If kept, it should - be a *reader-table alias* for an ASCII name — which is what metaiconicity - is for — never a lexical primitive. Keep as alias, or drop? - -| Toolchain role mapping -| Gemini: claudia=router, boggs=AST rewriter, federici=allocator, - dunayevskaya=evaluator, assata=sandbox. This repo's first guess: - claudia=readers, boggs=evaluator, federici=JEG store, - dunayevskaya=grammar, assata=CLI. "federici = memory reproduction" is - witty enough to keep. Owner picks; neither is authoritative. - -| Definition of "metaiconic" -| DESIGN.adoc uses "the text↔value mapping is itself a first-class value - (reader/printer tables are data, env-scoped)". Is that what you meant? -|=== - -== Bin B — real concepts, misapplied (quarantined) - -[cols="2,3", options="header"] -|=== -| Item | Why it is not what Gemini says - -| D∞ "convergence proofs … invariant for code generation" -| D∞ is the reason a unityped language *has* a semantics. Not a per-language - proof obligation; yields no invariant a backend could check. - -| ∂₂([T,A,S]) = [A,S] − [T,S] + [T,A]; "∂∘∂ = 0 is the invariant" -| Formula correct; meaning nil. ∂∘∂ = 0 is the *definition* of a chain - complex — it cannot fail, so it cannot be preserved. "Isolating the - friction edge [T,A]" is not an operation on programs. - -| Sheaf gluing / H¹ as distributed consensus -| A real research direction (Robinson, *Topological Signal Processing*) - with no connection to anything here. - -| λ-calculus interpreter + Y combinator "in Žiz" -| Textbook `subst`/`eval` — for a Lisp. Violates the stated triad grammar in - every clause. Worth rewriting in real Žiz later as a self-hosting smoke - test. - -| "Why Chapel was always the only correct choice" (PGAS vs MPI/Ray) -| Fair for HPC *data*, irrelevant to a bootstrap interpreter; the C++/Python - strawmen are cartoons. Real reason: the estate already has `chapeliser`. - -| 4-tier grammar hierarchy (Metal / Micro / Standard / Macro) -| A generic compiler-layering diagram with stickers. "Micro-Žiz = VAR/LAM/APP" - is just the λ-calculus. Small core + macro layer is ordinary Lisp practice - and already implied by `defmacro`. - -| Comparison to Iota/Jot/Thue/Underload -| Minimalism-for-its-own-sake esolangs; share nothing with the JEG. -|=== - -== Bin C — confabulation (discard) - -[cols="2,3", options="header"] -|=== -| Item | Why - -| Triads as the universal expression form; "control flow is dialectical friction"; `0 = (Ж Ж Ж)` -| Root-cause cascade (Finding 1); refuted by its own examples (Finding 2). - -| Distributed JEG in Chapel (`BlockDist`, `SyntheticAPriori` / `EmpiricalData` / `ReflexiveCritique`) -| A node array with **no edges**, no subjects, no provenance. Kantian kinds. - `verifyGraphIntegrity` prints and verifies nothing. Global `fetchAdd` per - claim is the one thing PGAS code must not do. - -| `ZizBootstrap` Chapel triad evaluator (`begin` thesis, `begin` antithesis, return sublation) -| Evaluates two subterms in parallel, *discards both results*, returns the - third. Computes nothing. Leaks `tRes`/`aRes`; races on unsynchronised vars. - -| Standard Lacanary / `libimaginary.so` / the Real as `/dev/null` / objet petit a GC -| Comedy. Not design. - -| Lippmann pseudo-environment tool / comptime ideology audit / "saves humanity" -| Zig, not Žiz (Finding 3); contradicts "no typechecker". - -| `val abstract_falsity = Ž.Dialectic(False)` block; "Fetishistic Disavowals" as error category -| Third syntax (Finding 3). - -| "5 Structural Hazards" / "Seventh Circle of Sartre" / "opiate of the coder" -| Gemini satirising its own output. - -| Kaomoji operators -| Hallucination drift; also breaks every tool in the pipeline. ASCII-only. - -| "14-rule EBNF" -| Counted after the fact; inconsistent; cannot express layout. - -| Chapel PGAS / C99 / LLVM / Wasm-via-Deno / SystemVerilog "HLS" / ICAP PR driver "fully detailed" -| Nothing detailed anywhere. SystemVerilog is not an HLS input; ICAP is a - Xilinx bitstream port; Deno is banned in the estate. No backend exists - before self-hosting. - -| `Cargo.toml` / "Rust workspace" -| No Rust component. tree-sitter's CLI being Rust does not put a Cargo.toml - here. - -| "Rainbow Indentation Linter", "memory singularity suppression", `anuradha`, `MarxInterpreter` -| Invented on the spot. - -| "Hand this to Mythos … 48-hour clock … final 20 minutes of sheer REPL magic" -| Theatre. No component depends on any model. - -| "The architecture of the Žiz execution engine. Source: StockCake" -| Self-describing. -|=== - -== What actually exists in this repository - -* `README.adoc`, `DESIGN.adoc`, `docs/JEG.adoc`, this file. -* `grammar/` — tree-sitter grammar + indent-stack external scanner + corpus. - Grammar DSL evaluates; scanner compiles under `-Wall -Wextra -Werror`; - `tree-sitter generate` *not yet run* (no CLI available where this was - written). -* `bootstrap/ziz0.chpl` — Chapel reader + evaluator + printer + in-memory - JEG. *Written without a Chapel compiler; expect small fixes on first run.* -* `examples/*.ziz`. -* `Justfile.ziz-fragment`. - -Nothing from bins B or C appears in any of those files. diff --git a/ziz-drop/bootstrap/ziz0.chpl b/ziz-drop/bootstrap/ziz0.chpl deleted file mode 100644 index 37fc05fd3..000000000 --- a/ziz-drop/bootstrap/ziz0.chpl +++ /dev/null @@ -1,569 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -// ziz0 — bootstrap interpreter for Žiz, in Chapel. -// -// Scope (milestone 0, see DESIGN.adoc §Bootstrap plan): -// * sexp reader (no layout reader yet — that arrives via tree-sitter) -// * eager evaluator with lexical closures -// * printer -// * in-memory Judgement Evidence Graph populated by observation -// -// Deliberately NOT here: FPGA anything, multi-locale anything, backends, -// triads, boundary operators. -// -// STATUS: written without a Chapel compiler available. Expect small fixes on -// first `chpl` run; the structure is what matters. Target: Chapel 2.x. -// -// Build: chpl --fast bootstrap/ziz0.chpl -o ziz0 -// Run: ./ziz0 --file=examples/hello.ziz -// ./ziz0 --file=examples/fact.ziz --jeg=observe - -use IO, Map, List; - -config const file: string = ""; -config const jeg: string = "off"; // "off" | "observe" -config const repl: bool = false; - -// -------------------------------------------------------------------------- -// Value domain (unityped: every term is a Value) -// -------------------------------------------------------------------------- - -enum Tag { Nil, Bool, Int, Real, Str, Sym, Pair, Vec, MapV, Fn, Prim, Env, Node, Claim, Err } - -class Value { - var tag: Tag; - var b: bool; - var i: int(64); - var r: real(64); - var s: string; // Str, Sym, Err message, Prim name - var car: shared Value?; // Pair - var cdr: shared Value?; - var items: list(shared Value); // Vec, Fn params - var kv: map(string, shared Value); // MapV, Env frame - var body: shared Value?; // Fn body, Claim subject - var env: shared Value?; // Fn closure env, Env parent - var prim: int; // Prim dispatch id - var nodeId: int; // CST anchor (reader-assigned) - - proc init(tag: Tag) { this.tag = tag; } -} - -type V = shared Value; - -proc mkNil(): V { return new shared Value(Tag.Nil); } -proc mkBool(x: bool): V { var v = new shared Value(Tag.Bool); v.b = x; return v; } -proc mkInt(x: int): V { var v = new shared Value(Tag.Int); v.i = x; return v; } -proc mkReal(x: real): V { var v = new shared Value(Tag.Real); v.r = x; return v; } -proc mkStr(x: string): V { var v = new shared Value(Tag.Str); v.s = x; return v; } -proc mkSym(x: string): V { var v = new shared Value(Tag.Sym); v.s = x; return v; } -proc mkErr(x: string): V { var v = new shared Value(Tag.Err); v.s = x; return v; } -proc mkPair(a: V, d: V): V { var v = new shared Value(Tag.Pair); v.car = a; v.cdr = d; return v; } -proc mkPrim(id: int, name: string): V { var v = new shared Value(Tag.Prim); v.prim = id; v.s = name; return v; } -proc mkEnv(parent: V?): V { var v = new shared Value(Tag.Env); v.env = parent; return v; } - -proc isNil(v: V): bool { return v.tag == Tag.Nil; } -proc truthy(v: V): bool { return !(v.tag == Tag.Nil || (v.tag == Tag.Bool && !v.b)); } - -proc listFrom(ref xs: list(V)): V { - var acc = mkNil(); - for idx in 0..#xs.size by -1 do acc = mkPair(xs[idx], acc); - return acc; -} - -iter listItems(v: V): V { - var cur = v; - while cur.tag == Tag.Pair { - yield cur.car!; - cur = cur.cdr!; - } -} - -proc listLen(v: V): int { var n = 0; for _ in listItems(v) do n += 1; return n; } - -// -------------------------------------------------------------------------- -// Environment (first-class; see DESIGN.adoc §Reflexivity) -// -------------------------------------------------------------------------- - -proc envLookup(e: V, name: string): V? { - var cur: V? = e; - while cur != nil { - if cur!.kv.contains(name) then return cur!.kv[name]; - cur = cur!.env; - } - return nil; -} - -proc envDefine(e: V, name: string, v: V) { e.kv[name] = v; } - -proc envSet(e: V, name: string, v: V): bool { - var cur: V? = e; - while cur != nil { - if cur!.kv.contains(name) { cur!.kv[name] = v; return true; } - cur = cur!.env; - } - return false; -} - -// -------------------------------------------------------------------------- -// Reader (sexp table only). ASCII-only surface syntax. -// -------------------------------------------------------------------------- - -record Reader { - var src: string; - var pos: int = 0; - var nextNode: int = 1; - - proc ref peek(): string { return if pos < src.size then src[pos] else ""; } - proc ref adv(): string { const c = peek(); pos += 1; return c; } - proc ref atEnd(): bool { return pos >= src.size; } - - proc ref skipWs() { - while !atEnd() { - const c = peek(); - if c == ";" { while !atEnd() && peek() != "\n" do adv(); } - else if c == " " || c == "\t" || c == "\n" || c == "\r" { adv(); } - else break; - } - } - - proc isDelim(c: string): bool { - return c == "" || c == " " || c == "\t" || c == "\n" || c == "\r" || - c == "(" || c == ")" || c == "[" || c == "]" || c == "{" || c == "}" || - c == "\"" || c == ";"; - } - - proc ref read(): V { - skipWs(); - if atEnd() then return mkErr("eof"); - const c = peek(); - select c { - when "(" { adv(); return readSeq(")"); } - when "[" { adv(); var l = readSeq("]"); var v = new shared Value(Tag.Vec); - for x in listItems(l) do v.items.pushBack(x); return v; } - when "{" { adv(); var l = readSeq("}"); var v = new shared Value(Tag.MapV); - var k: V? = nil; - for x in listItems(l) { if k == nil then k = x; else { v.kv[show(k!)] = x; k = nil; } } - return v; } - when ")" { adv(); return mkErr("unexpected )"); } - when "]" { adv(); return mkErr("unexpected ]"); } - when "}" { adv(); return mkErr("unexpected }"); } - when "'" { adv(); return mkPair(mkSym("quote"), mkPair(read(), mkNil())); } - when "`" { adv(); return mkPair(mkSym("quasiquote"), mkPair(read(), mkNil())); } - when "," { adv(); - if peek() == "@" { adv(); return mkPair(mkSym("unquote-splicing"), mkPair(read(), mkNil())); } - return mkPair(mkSym("unquote"), mkPair(read(), mkNil())); } - when "\"" { adv(); return readString(); } - otherwise { return readAtom(); } - } - } - - proc ref readSeq(close: string): V { - var xs: list(V); - while true { - skipWs(); - if atEnd() then return mkErr("unterminated list"); - if peek() == close { adv(); break; } - xs.pushBack(read()); - } - var v = listFrom(xs); - if v.tag == Tag.Pair { v.nodeId = nextNode; nextNode += 1; } - return v; - } - - proc ref readString(): V { - var out = ""; - while !atEnd() { - const c = adv(); - if c == "\"" then return mkStr(out); - if c == "\\" { - const e = adv(); - select e { - when "n" do out += "\n"; - when "t" do out += "\t"; - when "r" do out += "\r"; - when "\"" do out += "\""; - when "\\" do out += "\\"; - otherwise do out += e; - } - } else out += c; - } - return mkErr("unterminated string"); - } - - proc ref readAtom(): V { - var tok = ""; - while !isDelim(peek()) do tok += adv(); - if tok == "nil" then return mkNil(); - if tok == "true" then return mkBool(true); - if tok == "false" then return mkBool(false); - try { return mkInt(tok: int); } catch { } - try { if tok.find(".") != -1 then return mkReal(tok: real); } catch { } - var v = mkSym(tok); - v.nodeId = nextNode; nextNode += 1; - return v; - } -} - -// -------------------------------------------------------------------------- -// Printer -// -------------------------------------------------------------------------- - -proc show(v: V): string { - select v.tag { - when Tag.Nil do return "nil"; - when Tag.Bool do return if v.b then "true" else "false"; - when Tag.Int do return v.i: string; - when Tag.Real do return v.r: string; - when Tag.Str do return "\"" + v.s.replace("\\", "\\\\").replace("\"", "\\\"") + "\""; - when Tag.Sym do return v.s; - when Tag.Err do return "#"; - when Tag.Prim do return "#"; - when Tag.Fn do return "#"; - when Tag.Env do return "#"; - when Tag.Node do return "(node " + v.nodeId: string + ")"; - when Tag.Claim do return "#"; - when Tag.Vec { - var s = "["; - for (x, k) in zip(v.items, 0..) { if k > 0 then s += " "; s += show(x); } - return s + "]"; - } - when Tag.MapV { - var s = "{"; var first = true; - for k in v.kv.keys() { if !first then s += " "; first = false; s += k + " " + show(v.kv[k]); } - return s + "}"; - } - when Tag.Pair { - var s = "("; var cur = v; var first = true; - while cur.tag == Tag.Pair { - if !first then s += " "; first = false; - s += show(cur.car!); - cur = cur.cdr!; - } - if !isNil(cur) then s += " . " + show(cur); - return s + ")"; - } - } - return "#"; -} - -// -------------------------------------------------------------------------- -// Judgement Evidence Graph (in-memory; docs/JEG.adoc) -// -// Litmus test: apply() below is the code path where evaluating (fact 3) -// creates evidence edges. -// -------------------------------------------------------------------------- - -record Judgement { var subject: string; var predicate: string; var args: string; } -record Evidence { var forId: int; var kind: string; var by: string; var where_: string; } - -class JEG { - var judgements: list(Judgement); - var index: map(string, int); // structural key -> id (hash-consing) - var evidence: list(Evidence); - - proc assert_(subject: string, predicate: string, args: string, - kind: string, by: string, where_: string) { - const key = subject + "\x01" + predicate + "\x01" + args; - var id: int; - if index.contains(key) then id = index[key]; - else { - judgements.pushBack(new Judgement(subject, predicate, args)); - id = judgements.size - 1; - index[key] = id; - } - evidence.pushBack(new Evidence(id, kind, by, where_)); - } - - proc dump() { - writeln("; --- JEG: ", judgements.size, " judgements, ", evidence.size, " evidence edges"); - for (j, id) in zip(judgements, 0..) { - var kinds: map(string, int); - for e in evidence do if e.forId == id then kinds[e.kind] += 1; - var ks = ""; - for k in kinds.keys() do ks += " " + k + "=" + kinds[k]: string; - writeln("(", j.subject, " ", j.predicate, if j.args != "" then " " + j.args else "", ") ;", ks); - } - } -} - -var theJEG = new shared JEG(); - -proc subjectOf(v: V): string { - if v.tag == Tag.Sym then return "sym:" + v.s; - if v.nodeId != 0 then return "node:" + v.nodeId: string; - return "anon:" + show(v); -} - -proc tagName(v: V): string { return ":" + (v.tag: string).toLower(); } - -// -------------------------------------------------------------------------- -// Primitives -// -------------------------------------------------------------------------- - -enum P { Add, Sub, Mul, Div, Lt, Gt, Le, Ge, NumEq, Eq, Cons, Car, Cdr, ListP, Print, - Eval, CurrentEnv, JegDump, Not, IsNil, Len, Str } - -proc numOf(v: V): real { return if v.tag == Tag.Int then v.i: real else v.r; } - -proc arith(op: P, ref args: list(V)): V { - if args.size == 0 then return mkErr("arity"); - var allInt = true; - for a in args do if a.tag != Tag.Int then allInt = false; - if allInt { - var acc = args[0].i; - if args.size == 1 && op == P.Sub then return mkInt(-acc); - for idx in 1.. numOf(args[1])); - when P.Le do return mkBool(numOf(args[0]) <= numOf(args[1])); - when P.Ge do return mkBool(numOf(args[0]) >= numOf(args[1])); - when P.NumEq do return mkBool(numOf(args[0]) == numOf(args[1])); - when P.Eq do return mkBool(valEq(args[0], args[1])); - when P.Cons do return mkPair(args[0], args[1]); - when P.Car do return if args[0].tag == Tag.Pair then args[0].car! else mkErr("car of non-pair"); - when P.Cdr do return if args[0].tag == Tag.Pair then args[0].cdr! else mkErr("cdr of non-pair"); - when P.ListP do return listFrom(args); - when P.Print { for a in args do write(if a.tag == Tag.Str then a.s else show(a)); writeln(); return mkNil(); } - when P.Eval do return eval(args[0], if args.size > 1 then args[1] else env); - when P.CurrentEnv do return env; - when P.JegDump { theJEG.dump(); return mkNil(); } - when P.Not do return mkBool(!truthy(args[0])); - when P.IsNil do return mkBool(isNil(args[0])); - when P.Len do return mkInt(if args[0].tag == Tag.Vec then args[0].items.size else listLen(args[0])); - when P.Str { var s = ""; for a in args do s += if a.tag == Tag.Str then a.s else show(a); return mkStr(s); } - } - return mkErr("unknown prim"); -} - -proc installPrims(g: V) { - const names = ["+", "-", "*", "/", "<", ">", "<=", ">=", "=", "eq?", "cons", "car", "cdr", - "list", "print", "eval", "current-env", "jeg-dump", "not", "nil?", "len", "str"]; - for (n, k) in zip(names, 0..) do envDefine(g, n, mkPrim(k, n)); -} - -// -------------------------------------------------------------------------- -// Evaluator -// -------------------------------------------------------------------------- - -proc quasi(x: V, env: V): V { - if x.tag != Tag.Pair then return x; - const head = x.car!; - if head.tag == Tag.Sym && head.s == "unquote" then return eval(x.cdr!.car!, env); - var out: list(V); - for item in listItems(x) { - if item.tag == Tag.Pair && item.car!.tag == Tag.Sym && item.car!.s == "unquote-splicing" { - for y in listItems(eval(item.cdr!.car!, env)) do out.pushBack(y); - } else out.pushBack(quasi(item, env)); - } - return listFrom(out); -} - -proc apply(f: V, ref args: list(V), env: V, callNode: V): V { - const subj = subjectOf(callNode.car!); - const where_ = "node:" + callNode.nodeId: string; - if jeg == "observe" { - theJEG.assert_(subj, ":callable", "", "observed", "ziz0", where_); - theJEG.assert_(subj, ":arity", args.size: string, "observed", "ziz0", where_); - for (a, k) in zip(args, 0..) do - theJEG.assert_(subj, ":takes", k: string + " " + tagName(a), "observed", "ziz0", where_); - } - var result: V; - select f.tag { - when Tag.Prim do result = applyPrim(f, args, env); - when Tag.Fn { - if f.items.size != args.size then return mkErr("arity mismatch calling fn"); - var frame = mkEnv(f.env); - for (p, a) in zip(f.items, args) do envDefine(frame, p.s, a); - result = eval(f.body!, frame); - } - otherwise do return mkErr("not callable: " + show(f)); - } - if jeg == "observe" then - theJEG.assert_(subj, ":returns", tagName(result), "observed", "ziz0", where_); - return result; -} - -proc eval(x: V, env: V): V { - select x.tag { - when Tag.Sym { - const v = envLookup(env, x.s); - return if v != nil then v! else mkErr("unbound: " + x.s); - } - when Tag.Pair { - const head = x.car!; - if head.tag == Tag.Sym { - select head.s { - when "quote" do return x.cdr!.car!; - when "quasiquote" do return quasi(x.cdr!.car!, env); - when "if" { - const c = eval(x.cdr!.car!, env); - const rest = x.cdr!.cdr!; - if truthy(c) then return eval(rest.car!, env); - return if rest.cdr!.tag == Tag.Pair then eval(rest.cdr!.car!, env) else mkNil(); - } - when "define" { - const target = x.cdr!.car!; - if target.tag == Tag.Pair { - var fn = new shared Value(Tag.Fn); - for p in listItems(target.cdr!) do fn.items.pushBack(p); - fn.body = mkPair(mkSym("begin"), x.cdr!.cdr!); - fn.env = env; - envDefine(env, target.car!.s, fn); - if jeg == "observe" then - theJEG.assert_("sym:" + target.car!.s, ":defined-at", "", "observed", "ziz0", - "node:" + x.nodeId: string); - return mkSym(target.car!.s); - } - const v = eval(x.cdr!.cdr!.car!, env); - envDefine(env, target.s, v); - return mkSym(target.s); - } - when "set!" { - const v = eval(x.cdr!.cdr!.car!, env); - return if envSet(env, x.cdr!.car!.s, v) then v else mkErr("set! of unbound"); - } - when "lambda" { - var fn = new shared Value(Tag.Fn); - for p in listItems(x.cdr!.car!) do fn.items.pushBack(p); - fn.body = mkPair(mkSym("begin"), x.cdr!.cdr!); - fn.env = env; - return fn; - } - when "begin" { - var last = mkNil(); - for form in listItems(x.cdr!) do last = eval(form, env); - return last; - } - when "let" { - var frame = mkEnv(env); - for binding in listItems(x.cdr!.car!) do - envDefine(frame, binding.car!.s, eval(binding.cdr!.car!, env)); - var last = mkNil(); - for form in listItems(x.cdr!.cdr!) do last = eval(form, frame); - return last; - } - when "claim" { - // (claim subject predicate args... :evidence kind [:by who]) - const subj = x.cdr!.car!; - var rest: list(V); - for item in listItems(x.cdr!.cdr!) do rest.pushBack(item); - var predicate = "", args = "", kind = "asserted", by = "author"; - var idx = 0; - while idx < rest.size { - const it = rest[idx]; - if it.tag == Tag.Sym && it.s == ":evidence" { kind = rest[idx+1].s.strip(":"); idx += 2; continue; } - if it.tag == Tag.Sym && it.s == ":by" { by = show(rest[idx+1]).strip("\""); idx += 2; continue; } - if predicate == "" then predicate = show(it); - else args += (if args != "" then " " else "") + show(it); - idx += 1; - } - theJEG.assert_(subjectOf(subj), predicate, args, kind, by, "node:" + x.nodeId: string); - var c = new shared Value(Tag.Claim); c.body = subj; - return c; - } - } - } - const f = eval(head, env); - if f.tag == Tag.Err then return f; - var args: list(V); - for a in listItems(x.cdr!) { - const v = eval(a, env); - if v.tag == Tag.Err then return v; - args.pushBack(v); - } - return apply(f, args, env, x); - } - otherwise do return x; // self-evaluating - } -} - -// -------------------------------------------------------------------------- -// Driver -// -------------------------------------------------------------------------- - -proc runSource(src: string, env: V, echo: bool) { - var rd = new Reader(src); - while true { - var form = rd.read(); - if form.tag == Tag.Err && form.s == "eof" then break; - const v = eval(form, env); - if echo || v.tag == Tag.Err then writeln(if v.tag == Tag.Err then ";; " + show(v) else show(v)); - } -} - -proc main() { - var global = mkEnv(nil); - installPrims(global); - - if file != "" { - var src: string; - try { - var f = open(file, ioMode.r); - var r = f.reader(); - r.readAll(src); - r.close(); f.close(); - } catch e { - writeln("cannot read ", file, ": ", e.message()); - exit(1); - } - runSource(src, global, echo=false); - if jeg == "observe" then theJEG.dump(); - } - - if repl || file == "" { - writeln("ziz0 -- unityped, homoiconic, no typechecker. Ctrl-D exits."); - var line: string; - while true { - write("ziz> "); - if !stdin.readLine(line) then break; - runSource(line, global, echo=true); - } - } -} diff --git a/ziz-drop/docs/JEG.adoc b/ziz-drop/docs/JEG.adoc deleted file mode 100644 index 9a5083a64..000000000 --- a/ziz-drop/docs/JEG.adoc +++ /dev/null @@ -1,150 +0,0 @@ -// SPDX-License-Identifier: CC-BY-SA-4.0 -= Judgement Evidence Graph (JEG) -:toc: macro -:icons: font - -toc::[] - -== What it is, and what it is not - -A typechecker answers "is this program well-formed under theory T?" and stops -you if not. The JEG answers "what do we currently believe about each term, -and why?" and never stops you. - -It is *not* gradual typing, *not* soft typing, *not* a linter with a -different hat, and *not* a log of "dialectical sublations". Those all -compute a verdict or narrate. The JEG stores *claims with provenance* and -lets tools compute whatever verdict they like, later — including "no -verdict, insufficient evidence". - -Litmus test for any implementation claiming to be a JEG: *show the code path -where evaluating `(fact 3)` creates an evidence edge.* If there isn't one, it -is not a JEG. - -== Model - ----- -Subject := node-id | symbol | (subject . path) -Judgement := (subject, predicate, args...) -EvidenceKind := :asserted | :inferred | :observed | :tested | :contradicted -Evidence := (kind, provenance, [supports: judgement-id...]) -Provenance := { :by , :at , :where , :via } -Graph := Judgement nodes + Evidence edges (judgement -> judgement | judgement -> ground) ----- - -* A judgement with *no* incoming evidence is *unsupported*. -* A judgement with a `:contradicted` edge is *contested*. -* Evidence kinds are ordered by default strength for *display only*: - `:tested` > `:observed` > `:inferred` > `:asserted`. -* Nothing is deleted during a run. Retraction is a new `:contradicted` edge. -* Judgements are *hash-consed* on `(subject, predicate, args)`: ten - observations of `fact :arity 1` are one judgement with ten evidence edges, - not ten judgements. - -== Predicate vocabulary (open; these are the ones `ziz0` emits) - -[cols="1,2", options="header"] -|=== -| Predicate | Meaning - -| `:callable` | subject was applied and application proceeded -| `:arity n` | subject was applied to `n` args -| `:returns tag` | application returned a value with `tag` -| `:takes i tag` | argument `i` had `tag` at a call site -| `:pure` | no `set!`, no side-effecting prim, during observed calls -| `:raised map` | an error value was produced -| `:tested-by node-id` | a test form referenced the subject -| `:defined-at node-id` | binding site -| `:shadowed-by node-id` | rebinding in an inner scope -| `:reader sym` | which reader table produced this node (metaiconic provenance) -|=== - -== Surface syntax - ----- -(claim fact :arity 1 :evidence :asserted) -(claim fact :returns :int :evidence :tested :by "examples/fact-test.ziz") -(claim (node 0x2f1a) :pure :evidence :inferred :via boggs) ----- - -`claim` is a special form: its first argument is a *subject expression* -(symbol, `(node id)`, or a quoted form) and is not evaluated. - -== Runtime behaviour in `ziz0` - -Each application `(f a b)` under `--jeg=observe` appends, with -provenance `{:by ziz0 :where }`: - -* `(f :callable)`, `(f :arity 2)`, `(f :takes 0 )`, - `(f :takes 1 )`, `(f :returns )` — all `:observed`. - -Cheap: a hash-cons plus an edge. Off by default until measured. - -== Querying - ----- -(jeg-query '(?s :returns :int)) ; all subjects observed returning int -(jeg-support 'fact) ; every judgement about fact with evidence -(jeg-unsupported) ; judgements nobody has evidence for -(jeg-contested) ; judgements with contradicting evidence ----- - -== On-disk format - -Sidecar per source file: `foo.ziz` → `foo.jeg.a2ml`. A2ML because it is the -estate's machine-readable format; schema to be registered in -`hyperpolymath/standards` under `1-formats/a2ml/` once stable. - ----- -# A2ML jeg/0 -[meta] -source = "examples/fact.ziz" -source-sha256 = "..." -grammar = "tree-sitter-ziz@0.0.1" - -[[judgement]] -id = "j0001" -subject = "sym:fact" -predicate = "arity" -args = [1] - -[[evidence]] -for = "j0001" -kind = "observed" -by = "ziz0" -at = "2026-09-24T15:02:11Z" -where = "examples/fact.ziz:3:1" ----- - -== Merge semantics across runs - -Union of judgements (by structural id); union of evidence. Node-keyed -subjects are re-anchored through tree-sitter's edit log; if a node no longer -exists its judgements are kept and marked `:orphaned` (a judgement about a -judgement — the graph is reflexive too). - -== Interaction with tree-sitter - -* Node ids: `(start_byte, end_byte, kind)` hashed with grammar version — - stable across whitespace-only edits after re-anchoring. -* Editor integration: colour a symbol by *strength of evidence* rather than - by type. Unsupported = plain; observed = one tone; tested = another; - contested = warning. (A display policy. Not a component. Not a "rainbow - linter".) - -== Distribution (deferred) - -If the JEG is ever sharded across Chapel locales, the natural key is -*source file / subject*, not a flat integer id handed out by a global -atomic counter. A single `fetchAdd` on every claim would serialise the whole -cluster on one locale — the one thing PGAS code must not do. Not a milestone -0–3 concern. - -== Open questions (honest list) - -* Cost of `--jeg=observe` under deep recursion. -* Whether `:pure` should be *asserted by default* for lambdas with no `set!` - in the body, or left unsupported until observed. -* Provenance for macro-expanded code: expansion node, origin node, or both - with an `:expanded-from` edge? (Leaning: both.) -* Graph size limits and a compaction policy. diff --git a/ziz-drop/examples/fact.ziz b/ziz-drop/examples/fact.ziz deleted file mode 100644 index 2639dc169..000000000 --- a/ziz-drop/examples/fact.ziz +++ /dev/null @@ -1,14 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; Run with: ziz0 --file=examples/fact.ziz --jeg=observe -; No typechecker. The JEG records what was *observed*: fact was applied -; with arity 1, took :int, returned :int. Nobody declared that; it was seen. - -(define (fact n) - (if (= n 0) - 1 - (* n (fact (- n 1))))) - -(claim fact :arity 1 :evidence :asserted) -(claim fact :pure :evidence :asserted :by "author") - -(print (fact 10)) diff --git a/ziz-drop/examples/hello.ziz b/ziz-drop/examples/hello.ziz deleted file mode 100644 index ad95100b2..000000000 --- a/ziz-drop/examples/hello.ziz +++ /dev/null @@ -1,2 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -(print "hello, ziz") diff --git a/ziz-drop/examples/layout.ziz b/ziz-drop/examples/layout.ziz deleted file mode 100644 index b09ea4cb7..000000000 --- a/ziz-drop/examples/layout.ziz +++ /dev/null @@ -1,10 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; The off-side surface. Reads identically to fact.ziz ONCE the layout reader -; lands (tree-sitter external scanner). ziz0 milestone 0 will NOT read this. - -define (fact n) - if (= n 0) - 1 - * n (fact (- n 1)) - -print (fact 10) diff --git a/ziz-drop/examples/quote-eval.ziz b/ziz-drop/examples/quote-eval.ziz deleted file mode 100644 index 66f9b4cd1..000000000 --- a/ziz-drop/examples/quote-eval.ziz +++ /dev/null @@ -1,11 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; Homoiconicity: code is a list; lists are code. - -(define code '(+ 1 2 3)) -(print code) ; (+ 1 2 3) -(print (car code)) ; + -(print (eval code)) ; 6 - -(define (make-adder-form n) `(lambda (x) (+ x ,n))) -(define add5 (eval (make-adder-form 5))) -(print (add5 10)) ; 15 diff --git a/ziz-drop/examples/reflexive.ziz b/ziz-drop/examples/reflexive.ziz deleted file mode 100644 index d7f17a1e6..000000000 --- a/ziz-drop/examples/reflexive.ziz +++ /dev/null @@ -1,12 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; Reflexivity: the environment and the evidence graph are values. - -(define x 1) -(define e (current-env)) -(print e) - -(define (twice f v) (f (f v))) -(print (twice (lambda (n) (* n 2)) 21)) - -; Ask the graph what it has seen so far (observe mode). -(jeg-dump) diff --git a/ziz-drop/grammar/grammar.js b/ziz-drop/grammar/grammar.js deleted file mode 100644 index 2d6f9e625..000000000 --- a/ziz-drop/grammar/grammar.js +++ /dev/null @@ -1,111 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -// tree-sitter grammar for Žiz — S-expression core + off-side layout. -// -// The layout (off-side) rule is NOT context-free. It is handled by the -// external scanner in src/scanner.c, which emits _indent / _dedent / _newline -// from an indent stack. Inside explicit brackets the scanner suppresses -// layout tokens, so parenthesised code is layout-insensitive. -// -// Surface syntax is ASCII-only. String *contents* may be any UTF-8. - -const SYM_START = /[A-Za-z_+\-*\/<>=!?%&|^~$]/; -const SYM_REST = /[A-Za-z0-9_+\-*\/<>=!?%&|^~$.:]*/; - -module.exports = grammar({ - name: 'ziz', - - externals: $ => [ - $._indent, - $._dedent, - $._newline, - $.error_sentinel, // lets the scanner detect error recovery - ], - - extras: $ => [ - /[ \t\r]/, - $.comment, - $.line_continuation, - ], - - word: $ => $.symbol, - - rules: { - source_file: $ => repeat(choice($._layout_form, $._newline)), - - // ---- layout (off-side) surface ------------------------------------ - // A logical line with >1 item, optionally followed by an indented block, - // is an implicit list whose tail is the block's lines. A single bare - // atom on a line is itself, not a one-element list. - _layout_form: $ => choice( - $.layout_list, - seq($._form, $._newline), - ), - - layout_list: $ => prec.right(seq( - $._form, - repeat1($._form), - optional($.layout_block), - $._newline, - )), - - layout_block: $ => seq( - $._indent, - repeat1($._layout_form), - $._dedent, - ), - - // ---- S-expression core -------------------------------------------- - _form: $ => choice( - $.list, - $.vector, - $.map, - $.quote, - $.quasiquote, - $.unquote_splicing, - $.unquote, - $._atom, - ), - - list: $ => seq('(', repeat($._form), ')'), - vector: $ => seq('[', repeat($._form), ']'), - map: $ => seq('{', repeat(seq(field('key', $._form), field('value', $._form))), '}'), - - quote: $ => seq("'", $._form), - quasiquote: $ => seq('`', $._form), - unquote_splicing: $ => seq(',@', $._form), - unquote: $ => seq(',', $._form), - - _atom: $ => choice( - $.nil, - $.boolean, - $.real, - $.integer, - $.string, - $.keyword, - $.symbol, - ), - - nil: $ => 'nil', - boolean: $ => choice('true', 'false'), - - // real before integer so the longer match wins - real: $ => token(/-?[0-9]+\.[0-9]+([eE][-+]?[0-9]+)?/), - integer: $ => token(/-?[0-9]+/), - - string: $ => seq( - '"', - repeat(choice( - token.immediate(prec(1, /[^"\\\n]+/)), - $.escape_sequence, - )), - '"', - ), - escape_sequence: $ => token.immediate(/\\[nrt"\\]|\\u[0-9a-fA-F]{4}/), - - keyword: $ => token(seq(':', SYM_START, SYM_REST)), - symbol: $ => token(seq(SYM_START, SYM_REST)), - - comment: $ => token(seq(';', /.*/)), - line_continuation: $ => token(seq('\\', /\r?\n/)), - }, -}); diff --git a/ziz-drop/grammar/package.json b/ziz-drop/grammar/package.json deleted file mode 100644 index b0ed38ff6..000000000 --- a/ziz-drop/grammar/package.json +++ /dev/null @@ -1,8 +0,0 @@ -{ - "name": "tree-sitter-ziz", - "version": "0.0.1", - "description": "tree-sitter grammar for the Žiz language", - "license": "MPL-2.0", - "main": "bindings/node", - "tree-sitter": [{ "scope": "source.ziz", "file-types": ["ziz"] }] -} diff --git a/ziz-drop/grammar/src/scanner.c b/ziz-drop/grammar/src/scanner.c deleted file mode 100644 index cb81ba342..000000000 --- a/ziz-drop/grammar/src/scanner.c +++ /dev/null @@ -1,157 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -// External scanner for tree-sitter-ziz: off-side (indentation) layout. -// -// Emits INDENT / DEDENT / NEWLINE from an indent stack. Layout is suppressed -// while bracket_depth > 0, i.e. inside ( ) [ ] { }, so explicit S-expressions -// are layout-insensitive as DESIGN.adoc requires. - -#include "tree_sitter/parser.h" -#include -#include - -enum TokenType { INDENT, DEDENT, NEWLINE, ERROR_SENTINEL }; - -#define MAX_INDENTS 128 - -typedef struct { - uint16_t indents[MAX_INDENTS]; - uint8_t depth; // indent stack height (indents[0] is always 0) - uint16_t bracket_depth; - uint8_t pending_dedents; -} Scanner; - -static inline void push(Scanner *s, uint16_t col) { - if (s->depth < MAX_INDENTS) s->indents[s->depth++] = col; -} - -void *tree_sitter_ziz_external_scanner_create(void) { - Scanner *s = (Scanner *)calloc(1, sizeof(Scanner)); - push(s, 0); - return s; -} - -void tree_sitter_ziz_external_scanner_destroy(void *p) { free(p); } - -unsigned tree_sitter_ziz_external_scanner_serialize(void *p, char *buf) { - Scanner *s = (Scanner *)p; - unsigned n = 0; - buf[n++] = (char)s->depth; - buf[n++] = (char)(s->bracket_depth & 0xff); - buf[n++] = (char)(s->bracket_depth >> 8); - buf[n++] = (char)s->pending_dedents; - for (unsigned i = 0; i < s->depth && n + 1 < TREE_SITTER_SERIALIZATION_BUFFER_SIZE; i++) { - buf[n++] = (char)(s->indents[i] & 0xff); - buf[n++] = (char)(s->indents[i] >> 8); - } - return n; -} - -void tree_sitter_ziz_external_scanner_deserialize(void *p, const char *buf, unsigned len) { - Scanner *s = (Scanner *)p; - memset(s, 0, sizeof(*s)); - if (len == 0) { push(s, 0); return; } - unsigned n = 0; - uint8_t depth = (uint8_t)buf[n++]; - s->bracket_depth = (uint8_t)buf[n] | ((uint8_t)buf[n + 1] << 8); n += 2; - s->pending_dedents = (uint8_t)buf[n++]; - for (unsigned i = 0; i < depth && n + 1 < len; i++) { - s->indents[s->depth++] = (uint8_t)buf[n] | ((uint8_t)buf[n + 1] << 8); - n += 2; - } - if (s->depth == 0) push(s, 0); -} - -static void skip_comment(TSLexer *lx) { - while (lx->lookahead && lx->lookahead != '\n') lx->advance(lx, true); -} - -bool tree_sitter_ziz_external_scanner_scan(void *p, TSLexer *lx, const bool *valid) { - Scanner *s = (Scanner *)p; - - if (valid[ERROR_SENTINEL]) return false; - - if (s->pending_dedents > 0 && valid[DEDENT]) { - s->pending_dedents--; - s->depth--; - lx->result_symbol = DEDENT; - return true; - } - - // Observe brackets without consuming them (the internal lexer does that). - if (lx->lookahead == '(' || lx->lookahead == '[' || lx->lookahead == '{') { - s->bracket_depth++; - return false; - } - if (lx->lookahead == ')' || lx->lookahead == ']' || lx->lookahead == '}') { - if (s->bracket_depth > 0) s->bracket_depth--; - return false; - } - - if (s->bracket_depth > 0) return false; - - bool saw_newline = false; - uint16_t col = 0; - - for (;;) { - if (lx->lookahead == '\n') { - saw_newline = true; col = 0; - lx->advance(lx, true); - } else if (lx->lookahead == '\r') { - lx->advance(lx, true); - } else if (lx->lookahead == ' ') { - col++; lx->advance(lx, true); - } else if (lx->lookahead == '\t') { - col = (uint16_t)((col / 8 + 1) * 8); lx->advance(lx, true); - } else if (lx->lookahead == ';') { - skip_comment(lx); - } else if (lx->lookahead == '\\') { - lx->mark_end(lx); - lx->advance(lx, true); - if (lx->lookahead == '\r') lx->advance(lx, true); - if (lx->lookahead == '\n') { lx->advance(lx, true); col = 0; continue; } - return false; - } else { - break; - } - } - - if (!saw_newline && lx->lookahead != 0) return false; - if (lx->lookahead == '\n') return false; - - uint16_t top = s->indents[s->depth - 1]; - - if (lx->eof(lx)) { - if (s->depth > 1 && valid[DEDENT]) { - s->pending_dedents = (uint8_t)(s->depth - 2); - s->depth--; - lx->result_symbol = DEDENT; - return true; - } - if (valid[NEWLINE]) { lx->result_symbol = NEWLINE; return true; } - return false; - } - - if (col > top) { - if (valid[INDENT]) { - push(s, col); - lx->result_symbol = INDENT; - return true; - } - if (valid[NEWLINE]) { lx->result_symbol = NEWLINE; return true; } - return false; - } - - if (col < top) { - uint8_t levels = 0; - for (int i = s->depth - 1; i > 0 && s->indents[i] > col; i--) levels++; - if (levels > 0 && valid[DEDENT]) { - s->pending_dedents = (uint8_t)(levels - 1); - s->depth--; - lx->result_symbol = DEDENT; - return true; - } - } - - if (valid[NEWLINE]) { lx->result_symbol = NEWLINE; return true; } - return false; -} diff --git a/ziz-drop/grammar/test/corpus/basics.txt b/ziz-drop/grammar/test/corpus/basics.txt deleted file mode 100644 index 4c1c2a3a8..000000000 --- a/ziz-drop/grammar/test/corpus/basics.txt +++ /dev/null @@ -1,34 +0,0 @@ -================================================================================ -sexp list -================================================================================ -(define (fact n) (if (= n 0) 1 (* n (fact (- n 1))))) --------------------------------------------------------------------------------- -(source_file - (list (symbol) (list (symbol) (symbol)) - (list (symbol) (list (symbol) (symbol) (integer)) (integer) - (list (symbol) (symbol) (list (symbol) (list (symbol) (symbol) (integer))))))) - -================================================================================ -layout list -================================================================================ -define (fact n) - if (= n 0) - 1 - * n (fact (- n 1)) --------------------------------------------------------------------------------- -(source_file - (layout_list (symbol) (list (symbol) (symbol)) - (layout_block - (layout_list (symbol) (list (symbol) (symbol) (integer)) - (layout_block - (integer) - (layout_list (symbol) (symbol) (list (symbol) (list (symbol) (symbol) (integer))))))))) - -================================================================================ -atoms -================================================================================ -nil true 42 -7 3.14 "s\"t" :kw sym-bol? [1 2] {:a 1} --------------------------------------------------------------------------------- -(source_file - (layout_list (nil) (boolean) (integer) (integer) (real) (string (escape_sequence)) (keyword) (symbol) - (vector (integer) (integer)) (map (keyword) (integer)))) diff --git a/ziz-drop/grammar/tree-sitter.json b/ziz-drop/grammar/tree-sitter.json deleted file mode 100644 index fd9188b6b..000000000 --- a/ziz-drop/grammar/tree-sitter.json +++ /dev/null @@ -1,4 +0,0 @@ -{ - "grammars": [{ "name": "ziz", "camelcase": "Ziz", "scope": "source.ziz", "path": ".", "file-types": ["ziz"] }], - "metadata": { "version": "0.0.1", "license": "MPL-2.0", "description": "tree-sitter grammar for Žiz" } -}