Skip to content

docs(affirmation): define the anchor for squash-only repositories - #1212

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-squash-landing
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
docs/affirmation-squash-landing

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Amends docs/AFFIRMATION-STANDARD.adoc (v1.0 → v1.1) so an affirmation can be anchored in a repository that only allows squash merges. Owner ruling 2026-10-07: amend the standard rather than relax required_linear_history or bypass with direct pushes.

The old rule ("the anchor SHA matches the parent of the signed commit that lands the file") cannot be met where required_linear_history holds: a squash creates a new commit signed by the forge, not the owner. That covers 8 of the 9 repos in the 2026-10-07 affirmation round.

The new <<linear-history>> section says a squash-landed affirmation is anchored when:

  1. the PR head S is owner-signed and its parent is the anchor A;
  2. the squash commit M is on the default branch and its first parent is A (merge only while main is still at A);
  3. tree(M) == tree(S);
  4. refs/pull/<N>/head still resolves to S.

A new anti-pattern entry warns against squashing after main has moved. scripts/verify-affirmation-anchor.sh <owner/repo> <PR> checks all four and exits non-zero on any failure.

Closes: no issue.

Type of change

  • 🐛 Bug fix
  • ✨ New feature: scripts/verify-affirmation-anchor.sh
  • 💥 Breaking change: no; merge-commit landings still satisfy the rule unchanged
  • 🕳️ Soundness fix
  • 📖 Documentation: one new section and one anti-pattern line in AFFIRMATION-STANDARD
  • 🧹 Refactor / tech debt
  • ⚡ Performance
  • 🔧 Build / CI / tooling

📌 New pins

Head: c3d315160cc57d52e5ee18153100b8649a0a3ae5. No new or changed pins: no uses: SHA, actions.lock entry, lockfile record or container digest is touched.

How has this been verified?

scripts/verify-affirmation-anchor.sh <repo> <PR>   # on the 8 affirmation PRs merged 2026-10-07
PR Result
hyperpolymath/network-outpost#33 ANCHORED
hyperpolymath/git-reticulator#121 ANCHORED
hyperpolymath/gitbot-fleet#602 ANCHORED
metadatastician/_pathroot#40 ANCHORED
metadatastician/marid#79 ANCHORED
metadatastician/harvard-dehallucinator#27 ANCHORED
metadatastician/ziz#15 ANCHORED
metadatastician/burble#241 DRAFT, rc=1. The head 7db18c34 is a "Merge branch 'main'" update commit, and the squash's parent is 5cd5a951, not the anchor 308c118a.

burble is the negative control: it shows the script fails a real non-conforming landing. bash -n and shellcheck are clean, and .githooks/docstring-scan.sh --worktree --check gives 3/3 documented.

Checklist

  • My commit is signed (git commit -S).
  • I ran the relevant check (above).
  • New files carry the correct SPDX. The script is MPL-2.0, like the other scripts/*.sh.
  • Docs are updated, and no claim overstates what was measured.
  • No soundness hole introduced. Condition 3 (tree equality) is what keeps the squash from smuggling in content the owner did not sign.

Notes for reviewers

Out of scope: metadatastician/boj-server-mk2#14 (the 9th affirmation) is open and BLOCKED for a separate reason. That repo is private, Code Security is disabled, and the org EstateBranching ruleset's code_scanning rule can therefore never be satisfied. Recorded in dev-notes.

🤖 Generated with Claude Code

https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm

Most estate repositories enforce required_linear_history, so the owner's
signed commit cannot reach main unchanged: a squash re-creates it under
the forge's key. AFFIRMATION-STANDARD v1.1 adds <<linear-history>>: a
squash-landed affirmation is anchored when the owner-signed PR head has
the anchor as parent, the squash commit's first parent is the anchor,
the trees are identical, and refs/pull/<N>/head still holds the signed
commit. scripts/verify-affirmation-anchor.sh checks all four.

Owner ruling 2026-10-07 ("Amend standard").

Verified on the eight affirmation PRs merged 2026-10-07: seven ANCHORED,
metadatastician/burble#241 DRAFT (its head is a branch-update merge
commit and main had moved past the anchor), so the script both passes
and fails on real data.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X3hgXxWm6umMgZkjYyHnnm
@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 9, 2026 00:35
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 56 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b09fc156-354f-4de2-aa07-eae3e45fc50b
📥 Commits

Reviewing files that changed from the base of the PR and between 2e12b31 and c3d3151.

📒 Files selected for processing (2)
  • docs/AFFIRMATION-STANDARD.adoc
  • scripts/verify-affirmation-anchor.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37865521376

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 14 conforming, 1 grandfathered (layer all, contract v1.0.0)

@hyperpolymath
hyperpolymath merged commit d8848f8 into main Oct 9, 2026
59 of 62 checks passed
@hyperpolymath
hyperpolymath deleted the docs/affirmation-squash-landing branch October 9, 2026 00:35
@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

hyperpolymath added a commit to hyperpolymath/sanctify-php that referenced this pull request Oct 9, 2026
## Summary

Adds `AFFIRMATION.adoc` (Profile A) for sanctify-php at anchor
`d7634557f35c330ca97c2ccb1fa997d4506b84f2`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the checks at that anchor on 2026-10-07 and drafted the file. The owner
affirms it with the signed commit in this PR, whose parent is the
anchor.

The file's one-line characterisation: *sanctify-php is a substantial but
unfinished Haskell codebase for PHP hardening; at `d7634557` it does not
compile, so none of its security analyses has been run or verified.*

Closes: none.

## Type of change

- [ ] 🐛 Bug fix
- [ ] ✨ New feature
- [ ] 💥 Breaking change
- [ ] 🕳️ Soundness fix
- [x] 📖 Documentation
- [ ] 🧹 Refactor / tech debt
- [ ] ⚡ Performance
- [ ] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `47d7d2a6a0bf12fefa3e048fcacb933b0dfed4be`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `d7634557f35c330ca97c2ccb1fa997d4506b84f2`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## How has this been verified?

- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.
- `asciidoctor -S safe --failure-level=WARN -o /dev/null
AFFIRMATION.adoc` returned rc=0 with no warnings. A planted
out-of-sequence section in a scratch file returned rc=1, so the gate can
fail.
- The evidence inside the file was gathered at the anchor on 2026-10-07,
and each claim names its command and output:
- `cabal build all` stops with 11 errors (CI run `37603063882`, GHC
9.8.2). Each error was re-checked locally.
- Eight parser helpers are defined nowhere (grep count `0` for each).
`isWpdbObject` is imported but not exported. `transformAddTypeHints` is
declared twice.
- Licence metadata is MPL-2.0 throughout. There are 20 modules, about
6,100 lines, and 109 declared `it` cases, none of them executed.
- `governance / Actions lockfile verify` is red at the anchor:
Dependabot #112 bumped `smtp-notify-action` without updating
`actions.lock`.

## Checklist

- [x] My commits are **signed** (`git commit -S`). The head is `G`.
- [ ] I ran the project's own checks/tests locally and they pass. **Not
ticked.** This PR changes documentation only, and the file it adds
records that the library does not compile at this anchor, so the suite
cannot run.
- [x] New files carry the correct `SPDX-License-Identifier`.
`AFFIRMATION.adoc` line 1 is `CC-BY-SA-4.0` (prose). No existing file is
touched.
- [x] Docs are updated, and no public claim now overstates what the code
does. The file refutes "the parser is complete" and marks the README
feature list as aspiration.
- [x] I have not introduced a soundness hole. No code changed.

## Notes for reviewers

**Merge form: a merge commit, and only while `main` is still at the
anchor `d7634557`.**
- This repo allows merge commits. The AFFIRMATION-STANDARD v1.1
amendment (hyperpolymath/standards#1212, open) says such a repo SHOULD
land the signed commit that way, so the signed commit itself reaches
`main`.
- The anchor check also requires the merge commit's first parent to be
the anchor, so merge before anything else lands on `main`.
- If `main` has moved, do not merge and do not press **Update branch**.
Ask for a re-anchor instead.

**Automerge is deliberately not armed.**
- The one required check, `scan / gitleaks`, is not strict. An armed
merge would therefore still fire after `main` moved past the anchor, and
the affirmation would land unanchored.
- This PR is held for the owner's merge.

After the merge, `scripts/verify-affirmation-anchor.sh
hyperpolymath/sanctify-php <N>` (from standards#1212) should print
`ANCHORED`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/ZenodoDeposits.jl that referenced this pull request Oct 9, 2026
## Summary

Refreshes `AFFIRMATION.adoc` for ZenodoDeposits.jl at anchor
`796971f0adf64a60a0b64fc22849531ac1a53722`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the checks at that anchor on 2026-10-07 and drafted the file. The owner
affirms it with the signed commit in this PR, whose parent is the
anchor. The previous affirmation (anchor `a68b5852`, 2026-10-02) moves
unchanged to `docs/affirmations/AFFIRMATION-2026-10-02.adoc`.

Closes: none.

## 📌 New pins

- **Head SHA: `6a59fb744722b6b94f71341ac86f919b20311cc6`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `796971f0adf64a60a0b64fc22849531ac1a53722`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## Changes

- `AFFIRMATION.adoc`, refreshed as of 2026-10-07T10:26:55Z (+35/−10). It
includes a "Changes since the previous affirmation" section. Between the
two anchors, `git diff --stat a68b585 796971f -- src test proofs
Project.toml bin` shows two one-line changes and none under `src/`:
  - the package UUID was re-minted as UUIDv8;
  - one UUID literal in a test changed.
- `docs/affirmations/AFFIRMATION-2026-10-02.adoc`: the previous
affirmation, kept verbatim (+144).

## RSR Quality Checklist

### Required

- [x] Tests pass. This change is documentation only. The file records
`Pkg.test()` at the anchor: 377 pass, 0 fail, 0 error, 1 broken (the
live sandbox test, skipped without a token), Aqua and JET included.
- [x] Code is formatted. `asciidoctor -S safe --failure-level=WARN`
returned rc=0 with no warnings.
- [x] Linter is clean. The same asciidoctor gate reported 0 warnings. A
planted out-of-sequence section in a scratch file returned rc=1, so the
gate can fail.
- [x] No banned language patterns: AsciiDoc only.
- [x] No `unsafe` blocks: no code changed.
- [x] No banned functions: no code changed. The Agda proofs the file
cites run `--safe --without-K` with no postulates.
- [x] SPDX headers on the new and modified files: both start with `//
SPDX-License-Identifier: CC-BY-SA-4.0`.
- [x] No secrets, credentials or `.env` files.

### As Applicable

- [ ] `ZenodoDeposits.jl_chora.deed` `state` section: not touched. The
affirmation records state; it changes none.
- [ ] `ecosystem` section: no integration changed.
- [ ] `meta` section: no architectural decision changed.
- [x] Documentation updated: this PR is documentation.
- [ ] `TOPOLOGY.md`: no architecture change.
- [ ] `CHANGELOG`: not updated for an affirmation. Say so if you want an
entry.
- [ ] New dependencies: none.
- [ ] ABI/FFI: no change.

## Testing

**What I checked:**
- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.

**What the file records** (gathered at the anchor):
- `Pkg.test()` on Julia 1.12.6, as above.
- `proofs/agda/check.sh` proves six journal theorems (at most one
publish, at most one mint, resume never re-publishes, and others).
- Regenerating `Transitions.agda` from the code's table gives no diff.

**What the file does NOT claim:**
- No live deposit was made.
- The package is not registered in General and not tagged.
- `SonarQube` is red because the repo has no `SONAR_TOKEN`, so it says
nothing about code quality (#3).

**Merge form: squash, and only while `main` is still at the anchor
`796971f0`.**
- This repo requires linear history, so a merge commit is not available.
The ruleset also lists rebase, but rebase is never used here, because it
replays commits unsigned.
- Under the AFFIRMATION-STANDARD v1.1 amendment
(hyperpolymath/standards#1212, open), a squash keeps the affirmation
anchored when four things hold:
  1. this signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. this commit stays retrievable at `refs/pull/<N>/head`.
- If `main` has moved, do not squash and do not press **Update branch**.
Ask for a re-anchor instead.

**Automerge is deliberately not armed.**
- The five required checks are not strict, so an armed squash would
still fire after `main` moved past the anchor.
- This PR is held for the owner's merge.

**The ruleset also requires code-owner review and resolved review
threads, and Copilot code review is configured.** Copilot's threads are
answered on this PR before it is called done.

After the merge, run `scripts/verify-affirmation-anchor.sh
metadatastician/ZenodoDeposits.jl <N>
796971f` (from standards#1212). This
file's anchor row is labelled `Commit (SHA)`, not `Commit (HEAD)`, so
the checker cannot read it and the anchor is passed explicitly. The
command should print `ANCHORED`.

## Screenshots

N/A: documentation only.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/sr71-blackglider that referenced this pull request Oct 9, 2026
## Summary

Rewrites `AFFIRMATION.adoc` for sr71-blackglider at anchor
`9f8da4efe497fbe1f502e7471847b13eacee620a`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the repo's own checks at that anchor on 2026-10-07 and drafted the file.
The owner affirms it with the signed commit in this PR, whose parent is
the anchor.

Closes: none.

## 📌 New pins

- **Head SHA: `4189e6e7f95cf992f3e6dc408cb4d432437ffe68`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `9f8da4efe497fbe1f502e7471847b13eacee620a`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## Changes

- `AFFIRMATION.adoc` is rewritten in profile A with the full section
layout (+282/−177).
- The old file moves, byte-identical, to
`docs/affirmations/AFFIRMATION-2026-08-07.adoc` (+222).

## RSR Quality Checklist

### Required

- [ ] Tests pass: not applicable to a documentation-only change. The
file *records* the repo's test results, including failures (see
Testing).
- [x] Code is formatted. `asciidoctor -S safe --failure-level=WARN`
returned rc=0 with no warnings.
- [x] Linter is clean. The same asciidoctor gate reported 0 warnings. A
planted out-of-sequence section in a scratch file returned rc=1, so the
gate can fail.
- [x] No banned language patterns: AsciiDoc only.
- [x] No `unsafe` blocks: no code changed.
- [x] No banned functions: no code changed.
- [x] SPDX headers: both files start with `// SPDX-License-Identifier:
CC-BY-SA-4.0`. The moved file is byte-identical to the anchor's
`AFFIRMATION.adoc`.
- [x] No secrets, credentials or `.env` files.

### As Applicable

- [ ] Descriptile state files: not touched. A2ML is retired (D308), and
this PR changes no project state.
- [x] Documentation updated: this PR is documentation.
- [ ] `TOPOLOGY.md`: no architecture change.
- [ ] CHANGELOG: not updated for an affirmation. Say so if you want an
entry.
- [ ] New dependencies: none.
- [ ] ABI/FFI: no change.

## Testing

**What I checked:**
- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.

**What the file records** (gathered at the anchor on 2026-10-07):
- `cargo test --all-targets --locked`: 12/12. `cargo clippy -- -D
warnings` and `cargo fmt --check` returned rc=0.
- `zig build test` (FFI): 11/11.
- Proof gate: 10/10 modules, none quarantined. `just test && just
quality` returned rc=0.
- Four planted defects (an Idris type error, an unlisted `.idr`, a Lean
`sorry`, a Zig `expect(false)`) were all caught.
- `reuse lint` returned rc=1 (225/463 files carry copyright info).

The file refutes two claims from the old one: DEBT P-3 (the grep for
`CABICompliant`), and the claim that the `SafePtr` repair is in the
shipped seam.

**Merge form: squash, and only while `main` is still at the anchor
`9f8da4ef`.**
- This repo requires linear history and does not allow merge commits.
- Under the AFFIRMATION-STANDARD v1.1 amendment
(hyperpolymath/standards#1212, open), a squash keeps the affirmation
anchored when four things hold:
  1. this signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. this commit stays retrievable at `refs/pull/<N>/head`.
- If `main` has moved, do not squash and do not press **Update branch**.
Ask for a re-anchor instead. Never rebase.

**Automerge is deliberately not armed.**
- The one required check, `scan / gitleaks`, is not strict. An armed
squash would therefore still fire after `main` moved past the anchor.
- This PR is held for the owner's merge.

**The ruleset also requires code-owner review and resolved review
threads, and Copilot code review is configured.** Copilot's threads are
answered on this PR before it is called done.

After the merge, `scripts/verify-affirmation-anchor.sh
metadatastician/sr71-blackglider <N>` (from standards#1212) should print
`ANCHORED`.

## Screenshots

N/A: documentation only.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to hyperpolymath/airborne-submarine-squadron that referenced this pull request Oct 9, 2026
## Summary

Adds `AFFIRMATION.adoc` for Airborne Submarine Squadron at anchor
`69655e2a8d769bc215f09220acd122746fc61d03`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the checks at that anchor on 2026-10-07 and drafted the file. The owner
affirms it with the signed commit in this PR, whose parent is the
anchor.

The file's one-line characterisation: *At `69655e2`, ASS's JavaScript
engine and Bun server pass their own 288-test suite and serve locally,
the AffineScript/WASM core does not yet match its reference, and the
public Pages URL returned 404.*

Closes: none.

## Type of change

- [ ] 🐛 Bug fix
- [ ] ✨ New feature
- [ ] 💥 Breaking change
- [ ] 🕳️ Soundness fix
- [x] 📖 Documentation
- [ ] 🧹 Refactor / tech debt
- [ ] ⚡ Performance
- [ ] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `7e2dad7f6891878c56916bc156445e559077e3da`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `69655e2a8d769bc215f09220acd122746fc61d03`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## How has this been verified?

**What this PR changes:**
- `AFFIRMATION.adoc` (new, +438).
- `.machine_readable/root-allow.txt` (+1 line). It adds
`AFFIRMATION.adoc` to the root allowlist that
`scripts/check-root-shape.sh` enforces in both directions. Without that
line, the root-shape check would reject the new file.

**What I checked:**
- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.
- `asciidoctor -S safe --failure-level=WARN -o /dev/null
AFFIRMATION.adoc` returned rc=0 with no warnings. A planted
out-of-sequence section in a scratch file returned rc=1, so the gate can
fail.

**What the file records** (gathered at the anchor on 2026-10-07):
- `bun test` in a full clone: 285 pass, 3 skip, 0 fail (288 tests across
19 files).
- `bun test` in a git worktree on a loaded machine: 3 fail. Two were
5000 ms timeouts, and one was a contract test that assumes `.git` is a
directory.
- `bun run bench` rc=0, `just vectors-check`, `just must-spdx` and
`affinescript check` all pass.
- The local server serves the game.
- The compiled WASM does not match the reference twin.
- The Pages URL returned 404.

## Checklist

- [x] My commits are **signed** (`git commit -S`). The head is `G`.
- [ ] I ran the project's own checks/tests locally and they pass. **Not
ticked.**
- The suite passes in a full clone, but 3 tests fail in a worktree on a
loaded machine. The file records both results.
  - This PR changes documentation and one allowlist line, no code.
- [x] New files carry the correct `SPDX-License-Identifier`.
`AFFIRMATION.adoc` line 1 is `CC-BY-SA-4.0` (prose). `root-allow.txt`
keeps its existing `AGPL-3.0-or-later` header, so nothing is relicensed.
- [x] Docs are updated, and no public claim now overstates what the code
does. The file lists stale self-assessments (`READINESS.adoc`,
`docs/EXPLAINME.adoc`, `STATE.a2ml`) as outstanding rather than
affirming them.
- [x] I have not introduced a soundness hole. No code changed.

## Notes for reviewers

**Merge form: a merge commit, and only while `main` is still at the
anchor `69655e2a`.**
- This repo allows merge commits. The AFFIRMATION-STANDARD v1.1
amendment (hyperpolymath/standards#1212, open) says such a repo SHOULD
land the signed commit that way.
- The anchor check also requires the merge commit's first parent to be
the anchor, so merge before anything else lands on `main`.
- If `main` has moved, do not merge and do not press **Update branch**.
Ask for a re-anchor instead.

**Automerge is deliberately not armed.**
- The one required check, `scan / gitleaks`, is not strict. An armed
merge would therefore still fire after `main` moved past the anchor.
- This PR is held for the owner's merge.

This repo has no `required_signatures` rule. The signature here is the
owner's attestation under the standard, not something a gate demands.

After the merge, `scripts/verify-affirmation-anchor.sh
hyperpolymath/airborne-submarine-squadron <N>` (from standards#1212)
should print `ANCHORED`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/proglanging-languages that referenced this pull request Oct 9, 2026
## What this changes

Adds `AFFIRMATION.adoc` (profile A, evidential) for
proglanging-languages at anchor
`9b43eb48b409b280ee67cf3d585fdcf93ab0d716`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the checks at that anchor on 2026-10-07 and drafted the file. The owner
affirms it with the signed commit in this PR, whose parent is the
anchor.

## 📌 New pins

- **Head SHA: `4bcff2742227db6305bdfd33d6c7fa718ad057bf`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `9b43eb48b409b280ee67cf3d585fdcf93ab0d716`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## Why

An affirmation pins what is true of the repository at one commit, and
each claim names the command that shows it. The file's one-line
characterisation:

> At `9b43eb48`, proglanging-languages is a working, stdlib-only Julia
console whose 140-assertion suite passes on 1.10 and 1.12 and whose
every gate can say no. Its offline verifier is red on a stale lock
entry, its README overstates the test count and ships a broken package
example, and "evidence-backed" is true for anti-patterns but not for
language verdicts.

## How it was verified

**What I checked:**
- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.
- `asciidoctor -S safe --failure-level=WARN -o /dev/null
AFFIRMATION.adoc` returned rc=0 with no warnings. A planted
out-of-sequence section in a scratch file returned rc=1, so the gate can
fail.

**What the file records** (gathered at the anchor on 2026-10-07):
- `Pkg.test()` rc=0 on Julia 1.12.6 and on 1.10.10: 16 testsets, 140
assertions.
- The console's `gate`, `scan`, `bench` and `doctor` run. The planted
positives (`kill_repo`, `nix_repo --strict`, an empty scan returning
rc=3) each fail as they should.
- `./tools/selfcheck.sh` returns rc=1 on a stale `actions.lock` entry.
- CI conclusions at the anchor were not measured.

## Checklist

- [x] Commits are **signed** (`git commit -S`). The head is `G`.
- [x] New files carry the correct **SPDX header**. `AFFIRMATION.adoc`
line 1 is `CC-BY-SA-4.0` (prose).
- [x] **No existing file's licence was changed.** No existing file is
touched.
- [x] Any claim added to a README or doc is true of the code as merged,
**provided it merges while `main` is still at the anchor** (see below).
- [ ] Documentation updated if behaviour changed: not applicable. No
behaviour changed; this PR is documentation only.

## Merge notes

**Merge form: squash, and only while `main` is still at the anchor
`9b43eb48`.**
- This repo requires linear history and does not allow merge commits.
- Under the AFFIRMATION-STANDARD v1.1 amendment
(hyperpolymath/standards#1212, open), a squash keeps the affirmation
anchored when four things hold:
  1. this signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. this commit stays retrievable at `refs/pull/<N>/head`.
- If `main` has moved, do not squash and do not press **Update branch**.
Ask for a re-anchor instead. Never rebase.

**Automerge is deliberately not armed, for two reasons.**
- `main` has no required status checks, so automerge would merge at
once.
- An armed merge also ignores whether `main` is still at the anchor.

This PR is held for the owner's merge.

**The ruleset also requires code-owner review and resolved review
threads, and Copilot code review is configured.** Copilot's threads are
answered on this PR before it is called done.

After the merge, `scripts/verify-affirmation-anchor.sh
metadatastician/proglanging-languages <N>` (from standards#1212) should
print `ANCHORED`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to hyperpolymath/reasonably-good-token-vault that referenced this pull request Oct 9, 2026
## Summary

Adds `AFFIRMATION.adoc` for reasonably-good-token-vault (RGTV) at anchor
`6baae4fbed7d310c0ea998485b5f6460839ac314`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc`. Claude ran
the checks at that anchor on 2026-10-07 and drafted the file. The owner
affirms it with the signed commit in this PR, whose parent is the
anchor.

The file's one-line characterisation: *At 6baae4f, RGTV is an alpha,
untested, non-post-quantum credential broker whose three crates compile,
but whose broker binary aborts at startup on an axum 0.7 route under
axum 0.8, so its documented quickstart cannot run.*

Closes: none.

## Type of change

- [ ] 🐛 Bug fix
- [ ] ✨ New feature
- [ ] 💥 Breaking change
- [ ] 🕳️ Soundness fix
- [x] 📖 Documentation
- [ ] 🧹 Refactor / tech debt
- [ ] ⚡ Performance
- [ ] 🔧 Build / CI / tooling

## 📌 New pins

- **Head SHA: `0e7bf3637e3fdaafa0aca92ffdc4a49dc9696af1`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `6baae4fbed7d310c0ea998485b5f6460839ac314`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed.

## How has this been verified?

**What I checked:**
- `git log -1 --format=%G?` on the head printed `G` (the owner's SSH
signing key). `git rev-parse HEAD^` printed the anchor.
- The opener script refuses to open the PR unless `git ls-remote` shows
`main` at the anchor and the branch at the head above. It did not
refuse.
- `asciidoctor -S safe --failure-level=WARN -o /dev/null
AFFIRMATION.adoc` returned rc=0 with no warnings. A planted
out-of-sequence section in a scratch file returned rc=1, so the gate can
fail.

**What the file records** (gathered at the anchor on 2026-10-07):
- `just build` rc=0. `just check` rc=0 (fmt and clippy `-D warnings` on
broker and CLI). The worker builds for `wasm32-unknown-unknown`.
- The worker fails clippy with one error,
`needless_borrows_for_generic_args`.
- `target/release/vault-broker` panics at `src/main.rs:410:10` (exit
134). The route `/v1/grants/:grant_id/redeem` uses axum 0.7 syntax,
which axum 0.8 rejects.
- `cargo audit` on the CLI reports RUSTSEC-2026-0285 (rustls 0.23.37,
severity 5.3).
- There are no tests. Three must/trust gates pass by vacuity.

## Checklist

- [x] My commits are **signed** (`git commit -S`). The head is `G`.
- [ ] I ran the project's own checks/tests locally and they pass. **Not
ticked.** There are no tests, and the worker fails clippy. Both facts
are recorded in the file. This PR changes documentation only.
- [x] New files carry the correct `SPDX-License-Identifier`.
`AFFIRMATION.adoc` line 1 is `CC-BY-SA-4.0` (prose). No existing file is
touched.
- [x] Docs are updated, and no public claim now overstates what the code
does. The file refutes "vault-broker: axum HTTP server 100%" and names
the README's known-unsafe gaps.
- [x] I have not introduced a soundness hole. No code changed.

## Notes for reviewers

**Merge form: squash, and only while `main` is still at the anchor
`6baae4fb`.**
- This repo requires linear history and does not allow merge commits.
- Under the AFFIRMATION-STANDARD v1.1 amendment
(hyperpolymath/standards#1212, open), a squash keeps the affirmation
anchored when four things hold:
  1. this signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. this commit stays retrievable at `refs/pull/<N>/head`.
- If `main` has moved, do not squash and do not press **Update branch**.
Ask for a re-anchor instead. Never rebase.

**Automerge is deliberately not armed.**
- The one required check, `scan / gitleaks`, is not strict. An armed
squash would therefore still fire after `main` moved past the anchor.
- This PR is held for the owner's merge.

After the merge, `scripts/verify-affirmation-anchor.sh
hyperpolymath/reasonably-good-token-vault <N>` (from standards#1212)
should print `ANCHORED`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to hyperpolymath/bofig that referenced this pull request Oct 9, 2026
## Summary

Adds `AFFIRMATION.adoc` for bofig at anchor
`008665f841bbaac6fe8d2d32cff2b9c3d04064e6`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc` (Profile A,
evidential). Claude ran or read the checks at that anchor on 2026-10-09
between 01:55:32Z and 08:11:43Z, and drafted the file. The owner affirms
it with the signed commit in this PR, whose parent is the anchor. This
is bofig's first committed affirmation. An earlier draft at `cc41782a`
(2026-10-07) was never committed: `main` moved past it, so it was
re-anchored here.

Closes: none.

## Type of change

- [ ] 🐛 Bug fix: no code changed.
- [ ] ✨ New feature: no code changed.
- [ ] 💥 Breaking change: no code changed.
- [ ] 🕳️ Soundness fix: no checker or proof changed.
- [x] 📖 Documentation
- [ ] 🧹 Refactor / tech debt: no code changed.
- [ ] ⚡ Performance: no code changed.
- [ ] 🔧 Build / CI / tooling: no workflow or tool changed.

## 📌 New pins

- **Head SHA: `99f49d708dcebf681e58c59f1996a90d79888fa5`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `008665f841bbaac6fe8d2d32cff2b9c3d04064e6`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed. The file *records* the `elixir-ci`
reusable pin `d7b85cac57eb16edf51508d6f30806e86d63c9d3` that the anchor
already carries; it does not change it.

## How has this been verified?

**The file itself:**
- `asciidoctor -S safe --failure-level=WARN -o /dev/null
AFFIRMATION.adoc` returned rc=0 with no output. A planted copy with a
broken table returned an `ERROR` (so the gate can fail).
- Asciidoctor 2.0.26 does not report a dangling `<<xref>>`, so every
`<<x>>` was also checked against the `[[x]]` anchors with `comm -23`:
none dangling.
- gitleaks 8.16.0, the version installed here, skips every path ending
in `doc`, so a plain local scan never opens this file (inbox,
2026-10-09). It was scanned as a `.md` copy instead, using this repo's
`.gitleaks.toml` plus the estate baseline from standards `8f2ee508`,
which is what CI stages. Result: no leaks (rc=0). With a planted `ghp_`
token beside it, the same scan returned rc=1 and flagged only the plant.

**What the file records** (at the anchor; the file labels each line
local or CI):
- CI: the Elixir suite passed against live PostgreSQL and ArangoDB in
two workflows, `344 tests, 0 failures, 21 excluded` (jobs 112771119645
and 112771051985). `lib/` compiled with warnings as errors, `mix credo
--strict` found no issues, and coverage was 29.73% against a floor of
29.
- Local: gitleaks scoped to the anchor's history scanned 320 commits and
found no leaks. A planted file with two fake secrets was caught (rc=1).
In CI, `scan / gitleaks` concluded `success`.
- Local: `actionlint` reported 28 `[shellcheck]` findings and no syntax
or schema errors. `asciidoctor -v` on five repository documents was
clean.

**What the file reports as failing or unrun (none omitted):**
- Four non-required CI jobs failed at the anchor. The "GitHub Pages" run
37614986624 has sat pending with no jobs since the anchor landed. (Since
then: the stale 10-07 run 37612831304 that held the `pages` concurrency
group was cancelled at 08:45:39Z, and 37614986624 then deployed
successfully at 08:48:24Z. The file records the state when it was
measured.)
- None of the six K9 contracts passes `k9-validate.sh --strict` (rc=1
each). The legacy JS suite does not load.
- The Elixir suite did not run locally: the pinned Erlang 27.2.1 and
Elixir 1.18.2 are not installed, and installing them was not authorised.
- README, EXPLAINME and the status files state figures that the code
contradicts. The file lists each one.

## Checklist

- [x] My commits are **signed**: the owner signed the head with `git
commit -S` via `owner-actions.sh reanchored`. Claude made no commit.
Before opening this PR, the opener checked that `git log -1
--format=%G?` prints `G` on the head; it refuses to open the PR
otherwise.
- [x] I ran the project's own checks/tests locally, as far as this
machine allows. The Elixir suite could not run locally (above); the CI
results at the anchor are cited by job ID.
- [x] New files carry the correct `SPDX-License-Identifier`:
`AFFIRMATION.adoc` is prose and starts with `// SPDX-License-Identifier:
CC-BY-SA-4.0`. No existing file was relicensed.
- [x] Docs are updated, and no public claim now overstates what the code
does. The file corrects overstatements elsewhere; it adds none.
- [x] I have not introduced a soundness hole: no code changed.

## Notes for reviewers

**Deferred red checks (§5c). None is required; the only required
context, `scan / gitleaks`, passed.** Each one is tracked in #210:
- **`SonarQube`: new on this head, not red at the anchor.** SonarCloud
rejects `SONAR_TOKEN`: the first API call returns HTTP 403 (run
37907974087). It passed at the anchor on 10-07 and has failed on every
PR since 10-09 06:13Z. That is a token problem, not this file (#210,
comment of 2026-10-09).
- **`build`** (Deno CI) is red at the anchor too: `deno task lint` finds
no `deno.json` or `package.json` (#210).
- **`governance / Validate Hypatia Baseline`** is red at the anchor too:
three findings on `boj-build.yml` and a scorecard (#210).
- **`governance / Workflow security linter`** is red at the anchor too:
`boj-build.yml` has no top-level `permissions:` (#210).
- **`Hypatia Neurosymbolic Analysis`** is red at the anchor too:
installing rebar from `builds.hex.pm` fails TLS, so no SARIF is produced
(#210).

**Review output deferred:** CodeRabbit's two findings on
`AFFIRMATION.adoc` (lines 161 and 517) are correct, but the file is the
owner's signed commit and cannot change without a re-anchor. Both are
carried to the next affirmation in #218.

**Merge form: squash, and only while `main` is still at the anchor
`008665f8`.**
- Under AFFIRMATION-STANDARD v1.1 (hyperpolymath/standards#1212), a
squash keeps the affirmation anchored when four things hold:
  1. the signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. the signed commit stays retrievable at `refs/pull/<N>/head`.
- This repo also allows a merge commit and has no linear-history rule. A
merge commit keeps the signed commit itself in `main`'s history and
meets the same four conditions. Rebase is disabled here and is never
used, because it replays commits unsigned.
- If `main` has moved, do not merge and do not press **Update branch**.
Ask for a re-anchor instead.

**Automerge is deliberately not armed.** The one required context, `scan
/ gitleaks`, is not strict, so an armed merge would still fire after
`main` moved past the anchor. This PR is held for the owner's merge. The
effective rules on `main` are `deletion`, `non_fast_forward` and
`required_status_checks` (read 2026-10-09).

After the merge, run `scripts/verify-affirmation-anchor.sh
hyperpolymath/bofig <N>` from standards. It reads the anchor from the
file's `Commit (HEAD)` row, and it should print `ANCHORED`.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit to metadatastician/ZeroInflatedCounts.jl that referenced this pull request Oct 9, 2026
## Summary

Fills `docs/AFFIRMATION.adoc` for ZeroInflatedCounts.jl at anchor
`e27b7e436707dd6a07ce7de9fa35cd67f6377adb`, following
`hyperpolymath/standards` `docs/AFFIRMATION-STANDARD.adoc` (profile A,
evidential). On `main` the file is still the unfilled template from
`b6a9d25`. Claude ran the checks at the anchor on 2026-10-09 between
08:04:28Z and 08:12:55Z and drafted the file. The owner affirms it with
the signed commit in this PR, whose parent is the anchor. An earlier
draft at `d987960` was never committed: `main` moved past it (#9, #10),
so every claim was re-measured here and none was copied forward.

**`main` is red at this anchor, and the file says so.** `Pkg.test()`
exited 1: 636 behaviour assertions passed, 0 failed, and 2 testsets in
`test/cases/36-fit-responses.jl` errored on RCall. Both CI test jobs
reported the same. The anchor also carries three temporary probe files
that #10 re-landed, and their own headers say "deleted before the PR
lands". An affirmation records the state as it is, so this is not a
reason to hold it. It is a reason the owner may prefer to fix `main`
first and re-anchor.

Closes: none.

## Changes

- `docs/AFFIRMATION.adoc`: template replaced by the affirmation as of
2026-10-09 (+360/−126). It includes a "Changes since `d987960`" section
covering #9 (the UUIDv8 re-mint) and #10 (the `pscl` convergence fix,
the new tests, and the re-landed probe files).

## 📌 New pins

- **Head SHA: `95a8f58da56a7ffd5e1b937a8e96f28e7086b114`**. This is the
owner's signed commit, the one CI runs on.
- **Anchor: `e27b7e436707dd6a07ce7de9fa35cd67f6377adb`**. It is the
head's parent, and it was `main` when this PR opened.
- No action `uses:` SHAs, `actions.lock` entries, lockfiles or container
digests are added or changed. No manifest is committed. The file records
the versions that `Pkg.instantiate` resolved; it pins none.

## RSR Quality Checklist

### Required

- [ ] Tests pass: **no.** This change is documentation only. The file
records that `Pkg.test()` *failed* at the anchor: 11/11 Aqua, 636
passed, 2 errored, exit 1. That is the anchor's state, not something
this PR introduces.
- [x] Code is formatted: `asciidoctor -S safe --failure-level=WARN` on
the file returned rc=0 with no output.
- [x] Linter is clean: the same asciidoctor gate reported 0 warnings.
Every `<<xref>>` resolves to an anchor, checked with `comm -23`, because
Asciidoctor 2.0.26 does not report a dangling xref.
- [x] No banned language patterns: AsciiDoc only.
- [x] No `unsafe` blocks: no code changed.
- [x] No banned functions: no code changed. The file reports that the
three Agda model proofs the specification requires do not exist yet.
- [x] SPDX headers: the file starts with `// SPDX-License-Identifier:
CC-BY-SA-4.0`.
- [x] No secrets, credentials or `.env` files. gitleaks 8.16.0 skips
every path ending in `doc` (inbox, 2026-10-09), so the file was scanned
as a `.md` copy with the default config, because this repo ships no
`.gitleaks.toml`. Result: no leaks (rc=0). With a planted `ghp_` token
beside it, the scan returned rc=1 and flagged only the plant.

### As Applicable

- [ ] Repo deed: not touched. The file reports that the deed's `status`
clause is stale; it does not change it.
- [ ] `docs/status/ROADMAP.adoc`: not touched. The file reports it as
stale.
- [x] Documentation updated: this PR is documentation.
- [ ] `TOPOLOGY.md`: no architecture change.
- [ ] `CHANGELOG`: not updated for an affirmation. Say so if you want an
entry.
- [ ] New dependencies: none.
- [ ] ABI/FFI: no change.

## Testing

**What I checked:**
- Before this PR opens, `git log -1 --format=%G?` on the head prints
`G`, `git rev-parse HEAD^` prints the anchor, and `git ls-remote` shows
`main` at the anchor. The opener refuses to open the PR otherwise.

**What the file records** (gathered at the anchor, on Julia 1.12.6, R
4.5.0 and pscl 1.5.9):
- `Pkg.test()`: Aqua 11/11; behaviour 636 passed, 0 failed, 2 errored
(`36-fit-responses.jl:87`, "hurdle_nb/zinb rejects unusable fit
responses"); exit 1.
- Agda 2.7.0.1: `Properties.agda` typechecks under `--safe --without-K`
(exit 0). A planted `1 ≡ 2` exited 42, so the check can fail. The module
is still the template and states no model identity.
- CI at the anchor (71 check runs, read with `--paginate`): 49 success,
17 skipped, 5 failure, including both test jobs (R 4.3.3, the same 2
errors).

**What the file does NOT claim:**
- That the suite passes, or that the three model identities are proved.
- Anything about the `just` recipes, JET or the formatter, which ran
only in CI, or about the probe script, which was not run.

**Merge form: squash, and only while `main` is still at the anchor
`e27b7e43`.**
- This repo requires linear history and signed commits, so a merge
commit is not available. GitHub signs the squash commit. The ruleset
also lists rebase, but rebase is never used here, because it replays
commits unsigned.
- Under AFFIRMATION-STANDARD v1.1 (hyperpolymath/standards#1212), a
squash keeps the affirmation anchored when four things hold:
  1. the signed commit's parent is the anchor;
  2. the squash commit's first parent is the anchor;
  3. the two trees are equal;
  4. the signed commit stays retrievable at `refs/pull/<N>/head`.
- If `main` has moved, do not squash and do not press **Update branch**.
Ask for a re-anchor instead.

**Automerge is deliberately not armed.** The effective rules on `main`
(read 2026-10-09) have no required status checks, and an armed PR on
such a repo merges at once. They do require code-owner review, resolved
review threads and signed commits, and Copilot code review is
configured. Copilot's threads are answered on this PR before it is
called done.

After the merge, run `scripts/verify-affirmation-anchor.sh
metadatastician/ZeroInflatedCounts.jl <N>` from standards. It reads the
anchor from the file's `Commit (HEAD)` row, and it should print
`ANCHORED`.

## Deferred red checks and review output (§5c)

There are no required status checks on `main`. All four red contexts are
red at the anchor `e27b7e43` too, on the same error, and this PR changes
only `docs/AFFIRMATION.adoc`:
- **`estate-rules`**: `probe/` is not on the root allowlist. It is one
of the probe files #10 re-landed (#12).
- **`Test (Test + Aqua) (1, ubuntu-24.04)`**: 636 passed and 2 errored,
both on RCall's `MethodError: no method matching protect(::Int32)` in
`36-fit-responses.jl`. The cause is a test fixture interpolating Julia
`missing` into R (#12).
- **`Test (Test + Aqua) (1.9, ubuntu-24.04)`**: the same 2 errors (#12).
- **`governance / Allowlist Preflight`**:
`julia-actions/julia-docdeploy@v1` is not covered by the estate
allowlist (1 of 31 refs). See #3, comment of 2026-10-09.

**Review output.** CodeRabbit's one finding is correct: the Agda
reproduction step (`-l standard-library`, no Agda in the prerequisites)
does not match the verified run. The file is the owner's signed commit,
so it is deferred to the re-anchor after `main` is fixed (#12, third
criterion). Copilot code review is configured on `main` (ruleset
18225024), but it had requested no review and posted none by 09:12Z, 17
minutes after this PR opened.

**Automerge stays unarmed on purpose.** With no required status checks,
an armed PR merges as soon as the code-owner review lands, even if
`main` has moved past the anchor by then. That would leave the
affirmation unanchored. This PR waits for the owner's squash while
`main` is still `e27b7e43`.
## Screenshots

N/A: documentation only.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Replaced the reusable affirmation template with a dated verification
record, including the environment, checks performed, results,
limitations, and reproduction commands.
* Updated the attestation and signed-commit guidance to reflect the
recorded verification session and checkout.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 9, 2026
…tacked on #1213) (#1214)

## Summary

> **Rebased onto `main` after #1213 merged** (squash commit `9d629d11`,
2026-10-09T09:21Z). `git range-diff` shows the commit unchanged (`=`).
`main` differs from #1213's head `ed4f98a3` only in
`docs/AFFIRMATION.adoc` and
`docs/affirmations/AFFIRMATION-2026-10-07.adoc` (#1212's follow-up
`76773445`), so the measurements below that name the base `ed4f98a3`
still hold for `main`.

A2ML is retired (owner rulings D99, D269c, D312, D313). The files an
agent reads first in this repo still told it to **create** the seven
A2ML files:
- `0-AI-MANIFEST.a2ml`: "The 7 A2ML files MUST exist", under a
"UNIVERSAL RULE".
- `.meta/REQUIRED-FILES.adoc`: "Mandatory A2ML Files".
- `.claude/CLAUDE.md`: "Every Hyperpolymath repo must have
`.machine_readable/` with these 6 A2ML files", plus an ALLOWED-languages
row for A2ML.
- `README.adoc`: the 7-format family table, the templates and the
execution pipeline.

So agents kept writing new A2ML, or rewriting old A2ML into "new" A2ML
in a different shape, instead of producing the forms that replace it.
This PR repoints every one of those front doors at the three live forms.
Each form is named with its **normative grammar** in this repo and the
**checker** that enforces it:

| Form | Grammar | Check |
|---|---|---|
| `<repo>_chora.deed` at the repo root (D312) |
`1-formats/deed/spec/abnf/deed.abnf` (normative, D308) | `bun
1-formats/deed/tools/deed_lint.js FILE.deed` |
| `*.k9.ncl` contracts | `1-formats/k9/spec/K9-CONTRACT-SPEC.adoc` |
`1-formats/k9/tools/k9-validate.sh --strict FILE` |
| `coordination.k9` at the repo root |
`2-protocols/k9-coordination/spec/abnf/coordination-k9-grammar_v1.1.abnf`
+ `COORDINATION-K9-SPEC.adoc` | no validator script yet (stated as such)
|

The front doors also point at the deed mapping specs
(`1-formats/deed/mappings/`) for where former A2ML content goes
("anything a mapping spec does not list does not translate"), name
`rsr-template-repo_chora.deed` as the worked model, and forbid bulk
hand-conversion (D313).

**Per file:**
- **`.claude/CLAUDE.md`:**
- "Machine-Readable Artefacts" is rewritten: the A2ML-retired paragraph,
the three-form table, and notes on translation, the worked model, no
bulk conversion, "a deed is not TOML", and existing `.a2ml` files.
- The ALLOWED table's A2ML row is replaced by **deed** and **k9** rows.
  - The License Policy section is untouched.
- **`.meta/REQUIRED-FILES.adoc`:** "Mandatory A2ML Files" becomes
"Machine-Readable Metadata", with the same three forms and relative
links. See Also now points at the deed README and COORDINATION-K9-SPEC.
- **`AGENTS.adoc`:** adds the A2ML-retired paragraph. The validation
line now names both checkers.
- **`README.adoc`:**
- New section "Machine-Readable Metadata", which the front-door table
and the Overview link to.
- The "A2ML Format Family (7 Formats)" table, the templates line and the
"Execution Pipeline" are replaced by one short **retired-history** note.
No deed-era execution ordering has been ruled, and deed lists carry no
ordering, so the pipeline is not restated.
  - "Monorepo Architecture" gets a history NOTE.
- The tree listing and Related Projects label the `1-formats/a2ml/*`
specs and `1-formats/templates/` as retired history.
- Usage step 2 now says to create `<repo>_chora.deed` (plus
`coordination.k9` / `*.k9.ncl` where they apply) and not `.a2ml`.
- The dead Document Formats link `tree/main/a2ml` (that directory does
not exist) is replaced by a link to `1-formats/deed/`.
- **`0-AI-MANIFEST.a2ml`: deletion only.**
- Removed: the "CANONICAL LOCATIONS (UNIVERSAL RULE)" section ("The 7
A2ML files MUST exist…"), "A2ML" and the dead paths `a2ml/` and
`*-a2ml/` from the Stream 1 routing row, "the A2ML metadata family" from
the description, and the A2ML sentence of the attestation.
- Every `+` line is a shortened copy of a removed line, and no word is
added (checked mechanically, below). Deed routing is **not** added into
the `.a2ml`: its startup checklist sends the agent to `README.adoc`
next, and that file now carries it.

No issue is closed. This is the follow-up to #1213 that removes the
instructions that keep regenerating A2ML.

## Type of change

- [ ] 🐛 Bug fix. No code or gate behaviour changes; only instructions
do.
- [ ] ✨ New feature. Nothing is added beyond documentation.
- [ ] 💥 Breaking change. No tool, recipe, path or check is removed or
renamed. The A2ML files in this repo stay where they are.
- [ ] 🕳️ Soundness fix. No checker changes.
- [x] 📖 Documentation. Five front-door files now route to deed, k9 and
coordination with their ABNFs.
- [ ] 🧹 Refactor / tech debt. Docs only.
- [ ] ⚡ Performance. Not applicable.
- [ ] 🔧 Build / CI / tooling. No workflow, hook, script or lockfile is
touched.

## 📌 New pins

- **Head SHA: `11d458334a0ae9c0954dc7f4a712cd9862376543`**
- **No pins added or changed.** No `uses:` SHA, no `actions.lock` entry,
no lockfile record, no container digest.

## How has this been verified?

All commands were run locally in the worktree (Debian 13, WSL2) with
`MISE_DISABLE=1`.

- **After the rebase onto `9d629d11`:** `bash
scripts/check-canonical-names.sh origin/main` → `no deprecated names
reintroduced`, rc 0. `git range-diff ed4f98a..ec64f1f
origin/main..HEAD` → `1: ec64f1f = 1: 11d4583`.

- **`bash scripts/run-shell-test-suite.sh` → `All 80 test file(s)
passed.`, rc 0.**
- **The two checkers the docs now name run as written.** Each was run on
a valid fixture and on an invalid control:
- `bun 1-formats/deed/tools/deed_lint.js
1-formats/deed/tools/fixtures/valid/booleans-uuid_chora.deed` → `OK`, rc
0. On `fixtures/invalid/inequals_chora.deed` → `FAIL … '=' as a field
separator is not a deed`, rc 1.
- `bash 1-formats/k9/tools/k9-validate.sh --strict
1-formats/k9/tools/fixtures/valid/extension-capability.k9.ncl` → `1
file(s) conforming`, rc 0. On
`fixtures/invalid/L0-K9-E001-bad-magic.k9.ncl` → `K9-E001`, rc 1.
- **Every new link resolves.** Each added `link:` target and each added
backticked repo path was tested with `-e`, relative to the file that
holds it (`.meta/` links use `../`). Result: 18 links and 15 paths, 0
missing.
- **The cross-reference resolves.** `asciidoctor -v README.adoc` renders
the anchor `_machine_readable_metadata`, and all 5 `<<Machine-Readable
Metadata>>` references link to it.
- **asciidoctor warnings: none new.** Each edited `.adoc` was rendered
both new and on the base. The single error, `README.adoc: line 71:
dropping cells from incomplete row`, is identical on the base `ed4f98a3`
and is not introduced here.
- **`0-AI-MANIFEST.a2ml` is deletion-only.** The set of words on its `+`
lines, minus the set of words in the original file, is empty.
- **No remaining instruction to create A2ML.** In the five files, `grep
-i -E
'(must|should|create|include|add|use|write|generate|mandatory|required).{0,60}a2ml'`
finds only prohibitions ("do not create…") and history.
- **Pre-commit passed in full**, including gitleaks, the canonical-names
guard and bot directives. The first attempt was refused by
`check-canonical-names.sh`, because the draft repeated a deprecated
directory name. That clause was dropped and the guard now reports `no
deprecated names reintroduced`.
- **`.githooks/docstring-scan.sh --worktree --check` → rc 0.** No
function is touched.
- **`git diff --check` → clean.**

## Checklist

- [x] My commits are **signed** (`git commit -S`). `git log
--show-signature` reports a good ED25519 signature on `11d45833`.
- [x] I ran the project's own checks/tests locally and they pass. See
above.
- [x] New files carry the correct `SPDX-License-Identifier`. No new
files are added, and no existing header is changed.
- [x] Docs are updated, and no public claim now overstates what the code
does. `coordination.k9` is described as having no validator script yet,
and the retired pipeline is not restated as live.
- [x] I have not introduced a soundness hole, or I have flagged where I
might have. No checker changes.

## Notes for reviewers

- **Left as they are, on purpose:**
- **README L26 and `AGENTS.adoc` L4** still send an AI agent to
`0-AI-MANIFEST.a2ml` first. That is an instruction to *read* an existing
file, not to create one, and the manifest no longer tells anyone to
create A2ML.
- **The manifest's other reading pointers** (`descriptiles/STATE.a2ml`,
`AGENTIC.a2ml`) and its "no A2ML in the repo root" invariant stay. They
describe this repo's existing files, which are not hand-converted
(D313).
- **Not in this PR:**
`2-protocols/0-ai-gatekeeper/docs/AI-MANIFEST-SPEC.adoc` L258 still says
normatively "These 6 A2ML files MUST exist in
`.machine_readable/descriptiles/`". That is a versioned protocol spec,
not a front door, so changing it needs its own ruling. It is logged in
the owner's findings ledger.
- **Where STATE content goes** in the deed era is still marked "DECISION
REQUIRED (owner)" in the mapping specs. These docs point at the mappings
and do not pre-empt that decision.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 9, 2026
…1216)

## Summary

> **Rebased onto `main` after #1213 merged** (squash commit `9d629d11`,
2026-10-09T09:21Z). `git range-diff` shows the commit unchanged (`=`).
`main` differs from #1213's head `ed4f98a3` only in
`docs/AFFIRMATION.adoc` and
`docs/affirmations/AFFIRMATION-2026-10-07.adoc` (#1212's follow-up
`76773445`), so the measurements below that name the base `ed4f98a3`
still hold for `main`.

**Ruling R5 on #837 (owner, 2026-10-09): option B, with the §4 path-leak
clean first.** This PR is increment 1 of three. It freezes the spec
scorecard corpus into a tombstoned archive. It does not translate the
records into deeds.

- **Leak clean, before the move.** 47 lines in the 29 `*.scorecard.a2ml`
records cited the machine-local prefix `/home/user/standards/` (50
occurrences: 25 `evidence`, 12 `system` and 10 `effects` lines). Each
prefix is removed, so every path is now repo-relative. The one bare root
reference (`toolchain-readiness-grades`, "under /home/user/standards")
now reads "under the repository root". The full file:line list is below.
- **Record hygiene, deletion and repointing only.** Each record's
"Regenerate the dashboard with: just scorecards" header line is deleted,
because that recipe is already gone. Each `# Schema:` comment now points
at the archived schema (28 files; `estate-constitution` has none). The
schema's `$id` is a historical identifier and is left as it is. No fact
is added to any `.a2ml` file.
- **The move.** `.machine_readable/scorecards/` (29 records +
`scorecard.schema.json`) moves with `git mv` to
`.machine_readable/archive/scorecards-v1/`. All 30 are renames, with
history kept. A new `README.adoc` there is the tombstone: frozen, do not
edit, add or convert; why it was archived; what changed on the way in;
what replaces it; and what it is not (the verisim-data per-repo RSR
scorecards, and the OpenSSF Scorecard workflow).
- **Consumers repointed.** `.hypatia-baseline.json` (the SD022 entry's
`file`), `docs/BADGE-CRITERIA-SPEC.adoc`,
`1-formats/k9/spec/MIGRATION-1058.adoc` and `REGISTRY.adoc` ("What
stays, frozen").
- **Decision record.**
`1-formats/deed/mappings/scorecard-corpus-decision.adoc` goes from
"awaiting ruling" to **RULED: option B**. A new §5 records the three
increments and what each one closes.
- **Two guards learn the archive, narrowly.**
`scripts/check-canonical-names.sh` and both modes of
`.githooks/validate-bot-directives.sh` now skip
`.machine_readable/archive/scorecards-v1/*.scorecard.a2ml`. They do not
skip the archive README, any other file there, or a sibling archive. The
records are assessments that cite the names and tools of their day. They
are not live directives, and the README forbids editing them.

Refs #837. It does not close it: increments 2 and 3 remain (see Notes).

## Type of change

- [x] 🐛 Bug fix. `validate-bot-directives.sh` scan mode (what `pre-push`
runs without a diff) exits 1 on the base tree: "Codex" in
`k9-coordination-protocol.scorecard.a2ml` L23 is a historical
assessment, not a directive. It exits 0 after this PR.
- [ ] ✨ New feature. No new capability. The tombstone is documentation.
- [ ] 💥 Breaking change. The old path has no remaining consumer in this
repo. Every consumer found with `git grep` is repointed, and the `just
scorecards` recipe and its builder were already gone before this PR.
Callers outside this repo, if any, are not covered by that search.
- [ ] 🕳️ Soundness fix. The guard changes widen nothing beyond the
archived records, and planted positives pin that (see verification).
- [x] 📖 Documentation. A tombstone README, the ruling recorded in the
decision spec, and four consumer docs repointed.
- [x] 🧹 Refactor / tech debt. 29 records frozen and leak-free; ruled
debt on #837 paid down.
- [ ] ⚡ Performance. Not applicable.
- [x] 🔧 Build / CI / tooling. Two hook scripts gain one exclusion each;
two hook tests gain cases.

## 📌 New pins

- **Head SHA: `afb8a4f6fcc4c66124964923b9fbcbad6505236c`**
- **No pins added or changed.** No `uses:` SHA, no `actions.lock` entry,
no lockfile record, no container digest.

## How has this been verified?

All commands were run locally in the worktree (Debian 13, WSL2) with
`MISE_DISABLE=1`.

- **After the rebase onto `9d629d11`:** `bash
scripts/check-canonical-names.sh origin/main` → `no deprecated names
reintroduced`. `wave6-canonical-names-test.sh` → 8 passed, 0 failed.
`validate-bot-directives-test.sh` → 10 passed, 0 failed.
`validate-bot-directives.sh` in scan mode → `All files validated`. `git
range-diff ed4f98a..321f616 origin/main..HEAD` → `1: 321f616 = 1:
afb8a4f`.

- **`bash scripts/run-shell-test-suite.sh` → `All 80 test file(s)
passed.`, rc 0.** That includes both edited tests.
- **`bash scripts/tests/wave6-canonical-names-test.sh` → 8 passed, 0
failed.** The new case reproduces the real move: a record is committed,
`git mv`'d into the archive and edited, so the diff is a rename carrying
a `+` line under the new path.
- Mutant: deleting the exclusion line from the guard gives **7 passed, 1
failed**, and the failure is exactly the archived-record case.
- Planted positives: the archive README and a sibling
`archive/scorecards-v2/` are still blocked.
- **`bash scripts/tests/validate-bot-directives-test.sh` → 10 passed, 0
failed.** It has 5 new cases: staged-mode archived record → 0; archive
README → 1; sibling archive → 1; scan-mode archived record → 0;
scan-mode live `.deed` directive beside the archive → 1.
- Mutant: removing both exclusions gives **8 passed, 2 failed**, and the
failures are exactly the two archived-record cases.
- **The guards on the real change:**
- `bash scripts/check-canonical-names.sh ed4f98a` → `no deprecated
names reintroduced`, rc 0. With the exclusion removed, it flags
`0-ai-gatekeeper-protocol` and `release-pre-flight`, so the exclusion is
load-bearing and is reached through the rename.
- `INPUT_PATH=. bash .githooks/validate-bot-directives.sh` (scan mode) →
`All files validated`, rc 0.
- The same hook on a `git archive` of the base `ed4f98a3` → `ERROR:
.machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml
contains deprecated bot directives`, rc 1.
- **No absolute path is left.** `grep -E
'/home/|/Users/|/root/|/tmp/|/mnt/|C:\\|~/'` over the 29 archived
records → 0 matches. `git ls-files '*.scorecard.a2ml'` → 29, all under
`archive/scorecards-v1/` (acceptance item 1 of the decision spec, §3).
- **Every added link resolves.** Each new `link:` target in the four
edited or new `.adoc` files was tested with `-e` relative to its file: 6
links, 0 missing.
- **`.hypatia-baseline.json` still parses** (`jq -e .`), and its one
changed value is the `file` of the SD022 entry. Its entry count is
unchanged by this PR. The ratchet's `205 -> 189` reading below is the
base's own delta from `main`.
- **`bash scripts/check-exemption-ratchet.sh origin/main` → `Exemption
ratchet: OK.`** `bash scripts/check-standards-map.sh` → `GATE D PASSED`.
`apply-baseline-test.sh`, `filter-sarif-by-baseline-test.sh` and
`hypatia-blocking-gate-test.sh` → rc 0.
- **`.githooks/docstring-scan.sh --staged --check` → rc 0.** The
modified `is_excluded` and the new `cks` are both documented.
- **Pre-commit and pre-push passed in full**, including gitleaks,
canonical names and bot directives. The first commit attempt was refused
by `commit-msg` (subject was 78 characters, limit 72) and was shortened.
No hook was bypassed.
- **`git diff --cached --check` → clean.**

## Checklist

- [x] My commits are **signed** (`git commit -S`). `git log
--show-signature` reports a good ED25519 signature on `afb8a4f6`.
- [x] I ran the project's own checks/tests locally and they pass. See
above.
- [x] New files carry the correct `SPDX-License-Identifier`. The one new
file, the archive `README.adoc`, is prose and carries `CC-BY-SA-4.0`. No
existing header is changed.
- [x] Docs are updated, and no public claim now overstates what the code
does. The README and §5 say plainly that the `(assessment …)` clauses
and the estate-audit emitter do **not** exist yet.
- [x] I have not introduced a soundness hole, or I have flagged where I
might have. The two guard exclusions are the only widening. They are
fenced to `*.scorecard.a2ml` in one directory, and planted positives
prove that nothing else there, and no sibling archive, escapes.

## Notes for reviewers

- **Reduced scope, stated (§5b):**
- **Acceptance item 2**, one `(assessment …)` clause per `spec_id`, is
increment 2. It needs a `<repo>_chora.deed` for this repository, which
does not exist yet. Whether the canon repo's own deed carries a canon
clause is an open question for that increment.
- **Acceptance item 3**, a forward link from each archived record, will
be met by the directory tombstone, not by editing each record: writing a
link into a frozen `.a2ml` would add content to a retired format. The
tombstone gains the forward link when the deed exists.
  - **Increment 3** is the estate-audit emitter for future assessments.
- **Why the leak list is here and not in `estate-residue-ledger.tsv`:**
the decision spec's §4 suggested the residue ledger, but that file is
generated by `scripts/spine/board.awk` and checked by `verify-board.sh`,
so a hand-added row would be lost at the next regeneration.
- **47 lines here, 48 in the R5 register.** The register comment on #837
(2026-09-19) counted 48 leak lines, on `main` at `000b9f6b`. One of
them, an `evidence` line in `0-ai-gatekeeper-protocol`, was rewritten by
#947 (`7b05a323`, 2026-09-22), so 47 remained at the base, and all 47
are cleaned here. After this PR, 0 remain.
- **The corpus measured 29 files, not the "70+" in the decision spec's
title.** The title is left as it was, and §5 records the measured count.
- **Left as they are, on purpose:** `0-canon/COMPLIANCE-DASHBOARD.adoc`
(a frozen snapshot), `RSR-SPEC-v2.adoc` L147 and `rsr-criteria-v2.a2ml`
L65 (a different scorecard corpus), `canon.lock` (its only "scorecard"
hit is the OpenSSF workflow), and the data line `hypatia-rules` L69,
which mentions `just scorecards` as assessment evidence rather than as
an instruction.

<details>
<summary>The 47 cleaned lines (file:line on the base
<code>ed4f98a3</code>, under <code>.machine_readable/scorecards/</code>;
each line held the prefix named in the Summary; content
omitted)</summary>

```
0-ai-gatekeeper-protocol.scorecard.a2ml:26
0-ai-gatekeeper-protocol.scorecard.a2ml:36
0-ai-gatekeeper-protocol.scorecard.a2ml:43
0-ai-gatekeeper-protocol.scorecard.a2ml:51
0-ai-gatekeeper-protocol.scorecard.a2ml:65
accessibility.scorecard.a2ml:17
accessibility.scorecard.a2ml:33
accessibility.scorecard.a2ml:56
accessibility.scorecard.a2ml:63
adoption-readiness-grades.scorecard.a2ml:17
adoption-readiness-grades.scorecard.a2ml:75
agentic-a2ml.scorecard.a2ml:17
agentic-a2ml.scorecard.a2ml:54
anchor-a2ml.scorecard.a2ml:64
ecosystem-a2ml.scorecard.a2ml:17
ecosystem-a2ml.scorecard.a2ml:33
ecosystem-a2ml.scorecard.a2ml:77
foundations-readiness-grades.scorecard.a2ml:17
hypatia-rules.scorecard.a2ml:17
k9-coordination-protocol.scorecard.a2ml:72
k9-svc.scorecard.a2ml:17
k9-svc.scorecard.a2ml:26
k9-svc.scorecard.a2ml:56
k9-svc.scorecard.a2ml:63
k9-svc.scorecard.a2ml:65
k9-svc.scorecard.a2ml:74
k9-svc.scorecard.a2ml:122
meta-a2ml.scorecard.a2ml:17
meta-a2ml.scorecard.a2ml:75
meta-a2ml.scorecard.a2ml:98
neurosym-a2ml.scorecard.a2ml:45
overlay-protocol.scorecard.a2ml:68
release-pre-flight.scorecard.a2ml:15
release-pre-flight.scorecard.a2ml:24
release-pre-flight.scorecard.a2ml:33
release-pre-flight.scorecard.a2ml:42
release-pre-flight.scorecard.a2ml:44
release-pre-flight.scorecard.a2ml:49
release-pre-flight.scorecard.a2ml:51
release-pre-flight.scorecard.a2ml:60
release-pre-flight.scorecard.a2ml:65
release-pre-flight.scorecard.a2ml:74
release-pre-flight.scorecard.a2ml:83
release-pre-flight.scorecard.a2ml:85
toolchain-readiness-grades.scorecard.a2ml:17
toolchain-readiness-grades.scorecard.a2ml:38
toolchain-readiness-grades.scorecard.a2ml:54
```

</details>

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant