From 76773445d8b0c3a2558f33cc426bacc638206a6f Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 9 Oct 2026 09:54:54 +0100 Subject: [PATCH] docs(affirmation): re-anchor at 6d19ce0e, refs #787 Drafted by Claude from local runs at the anchor; affirmed by the owner. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_013omQK26s4uDjJMkdqNEvEG Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com> --- docs/AFFIRMATION.adoc | 302 ++++++++++++------ docs/affirmations/AFFIRMATION-2026-10-07.adoc | 277 ++++++++++++++++ 2 files changed, 480 insertions(+), 99 deletions(-) create mode 100644 docs/affirmations/AFFIRMATION-2026-10-07.adoc diff --git a/docs/AFFIRMATION.adoc b/docs/AFFIRMATION.adoc index 7d1d4c5d9..a27bdb836 100644 --- a/docs/AFFIRMATION.adoc +++ b/docs/AFFIRMATION.adoc @@ -16,15 +16,19 @@ applies; profile A (evidential) is for implementation repos. [CAUTION] ==== -**Status: DRAFT — UNSIGNED.** This is a refresh of the 2026-09-17 draft, -which is kept verbatim at -link:affirmations/AFFIRMATION-2026-09-17.adoc[affirmations/AFFIRMATION-2026-09-17.adoc]. -Every check below was re-run on 2026-10-07 against the anchor in -<>; nothing was copied forward unmeasured. - -An affirmation is *signed* by the owner. That signature is not an agent's to -give. Every claim below is measured and reproducible; the attestation block at -the end is empty and MUST be filled by the owner before this file is cited. +**Status: an affirmation only if landed as <> describes; otherwise a +draft.** An AI engineering party re-ran every check below on 2026-10-09 +against the anchor in <> and drafted this file. Every check and count +under "We affirm" and "We intend" was re-run at the anchor. The rulings, +issue references and history cited under <> were carried from the +2026-10-07 file unless a number there says it was re-measured. The file +becomes an affirmation when the owner lands it +with a signed commit whose parent is that anchor. If the commit that lands it +has any other parent, read this file as a draft. + +This refreshes the 2026-10-07 affirmation, which is kept verbatim at +link:affirmations/AFFIRMATION-2026-10-07.adoc[affirmations/AFFIRMATION-2026-10-07.adoc]. +That file did not land anchored; see <>. ==== toc::[] @@ -44,39 +48,44 @@ returned at the anchor. implemented". This item affirms assertions 1 and 2 only. . *A canon change cannot be silent.* Assertion 2 fails a commit that changes a file named in `canon.lock [canon.artifacts]` without touching `canon.lock`. - Positive control, run for this refresh: a throwaway commit (never pushed) - appended one line to `0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc`; - `--base HEAD~1` then reported `FAIL canon artefacts changed ( applicability - ) but canon.lock is untouched` and exited `1`. An uncommitted edit to the - same file fails assertion 1 instead (also measured, exit `1`). + Positive control, run for this refresh in a separate scratch clone: a + throwaway commit (unsigned, never pushed, then discarded) appended one line + to `0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc`. With `--base HEAD~1` the + script reported the assertion-1 hash mismatch *and* `FAIL canon artefacts + changed ( applicability ) but canon.lock is untouched` (passed 5, failed 2) + and exited `1`. An uncommitted edit to the same file fails assertion 1 alone + (passed 6, failed 1, exit `1`). . *The canon passes its own profile check.* `bash scripts/check-rsr-profile.sh .` exits `0` (`rsr-profile check: OK — scaffold matches declared capabilities`), with role `canon` and effective capabilities `bash docs-site governance-tier reproducible-build`. Positive control: with - `docs/AUDIT.adoc` moved aside, the same command exits `1`. The profile it - reads, `.machine_readable/rsr-profile.a2ml`, is in the retired A2ML dialect; - see <>. The earlier draft's statement that this script once exited `2` - on this repository is history and was not re-measured. + `docs/AUDIT.adoc` moved aside, the same command exits `1` (`MISSING + (governance-tier)`). The profile it reads, + `.machine_readable/rsr-profile.a2ml`, is in the retired A2ML dialect; see + <>. . *The repository is mapped, both ways.* `bash scripts/check-standards-map.sh --repo .` exits `0` (Gate D): 124 records, all 124 mapped paths exist, all 74 top-level entries are mapped, every `canon_slot` resolves in `canon.lock`. Positive control: an unmapped top-level directory planted in the working tree made it exit `1` with `unmapped top-level entry`. . *UUID literals are v8-only (ADR-008, strict).* `sh scripts/check-uuid-v8.sh - --strict .` exits `0`, and so does the default mode. ADR-008's status line + --strict .` exits `0`, and so does the default mode. ADR-008's status row reads *Accepted* (D305/D305b), *Amended* by D320 (2026-10-07). By design (D320) the scanner skips retired `*.a2ml` files, so this affirms *non-A2ML* files only. Its own suite, `bash scripts/tests/uuid-v8-test.sh`, - reports `PASS=32 FAIL=0`, including rejection of a planted v7 under - `--strict`. A v4 literal planted outside the tree also made the default mode - exit `1`. + reports `PASS=32 FAIL=0`. Positive controls, planted outside the tree: a v4 + literal fails the default mode (exit `1`); a v7 literal passes the default + mode (exit `0`) and fails `--strict` (exit `1`); a v8 literal passes + `--strict` (exit `0`). A v4 literal planted inside the tree failed + `--strict .` (exit `1`). . *Ruling R-A is settled: the machine tree is `.machine_readable/`.* At the anchor `.machine_readable/` exists and `machine-readable/` does not (`test -d` / `test -e`). The basis is a *historical* census, not a current count: rsr-template-repo's `docs/governance/TEMPLATE-LINEAGE-AUDIT.adoc` (at - rsr-template-repo `3e6d4aa27ddac8a3aa2431cc4321c600b02f3e75`) records **48 - repositories dotted against 9 hyphenated** at the 2026-08 divergence. This - confirms ruling 10 of `STANDARDS-CRITICAL-PATH.adoc`. + rsr-template-repo `3e6d4aa27ddac8a3aa2431cc4321c600b02f3e75`, line 216) + records **48 repositories dotted against 9 hyphenated** at the 2026-08 + divergence. This confirms ruling 10 of `STANDARDS-CRITICAL-PATH.adoc`, which + reads "RESOLVED: yes" on that census. == We intend @@ -84,18 +93,21 @@ Committed next actions. **Not yet true.** The release conditions they serve are enumerated in link:AUDIT.adoc[AUDIT.adoc]. . Migrate this repository's A2ML to deed. At the anchor `git ls-files - '*.a2ml'` counts **225** files against **20** `*.deed`. Per D313 the - conversion is kcX's first front end, not a hand conversion; per D312 the - descriptiles become clauses of a `standards_chora.deed`, which does not yet - exist at the root. + '*.a2ml'` counts **225** files against **26** `*.deed`. Of those 26, 24 are + deed-lint fixtures under `1-formats/deed/tools/fixtures/`; two are + descriptive (`3-practice/provisioning/provisioning-standard_praxis.deed`, + `launcher/launcher-standard_praxis.deed`). Per D313 the conversion is kcX's + first front end, not a hand conversion; per D312 the descriptiles become + clauses of a `standards_chora.deed`, which does not yet exist at the root. . Re-express the canon's own law in deed. The criteria SSOT, `0-canon/rsr/rsr-criteria-v2.a2ml`, and the canon profile, `.machine_readable/rsr-profile.a2ml`, are both A2ML; `check-rsr-profile.sh` reads only the `.a2ml` path. . Move the generated estate telemetry (board, censuses, scorecards, audits) out to a separate repository, so the canon versions by law changes only. - `hyperpolymath/estate-telemetry` does not exist yet (`gh repo view` could - not resolve it); 36 tracked files under `audits/` and + `hyperpolymath/estate-telemetry` does not exist yet: a GraphQL repository + lookup, made with the owner's token (which administers this repository), + returned `NOT_FOUND`. 36 tracked files under `audits/` and `.machine_readable/{estate-board*,scorecards,audits}` remain here. . Implement `hypatia:rsr-conformance`, the one normative oracle named in `rsr-criteria-v2.a2ml` §`[oracle]`. Gate A still skips assertion 5's oracle @@ -103,11 +115,14 @@ enumerated in link:AUDIT.adoc[AUDIT.adoc]. criterion's `detect` column is aspirational. . Carry canon identity and provenance into minted repos as clauses of each repo's `_chora.deed`, not as new `rsr-profile.a2ml` or - `PROVENANCE.a2ml` files: A2ML is retired, so the earlier draft's "mint - `.a2ml` files" intent is withdrawn and restated here. + `PROVENANCE.a2ml` files. A2ML is retired, so the 2026-09-17 draft's "mint + `.a2ml` files" intent stays withdrawn. . Turn on Gate A assertions 3–5 in `--strict` mode. . Bring this repository's own `coordination.k9` to grammar 1.1.1 (see <>). +. Make the registry and the scorecards honest again (see <>): regenerate + `.machine_readable/REGISTRY.a2ml`, and re-grade the three scorecard rows + whose claimed pass does not hold. == We wish @@ -123,33 +138,66 @@ Horizon aspirations. **Explicitly not commitments.** == Held Not affirmed here: ruled but not enforced, unmeasurable with the tools at hand, -or under coordinated realignment. +failing at the anchor, or under coordinated realignment. === Ruled, not yet enforced -* *Ruling R-B — `.a2ml` or `.deed`: RULED, not enforced.* The earlier draft - listed R-B as open. It is now ruled on `hyperpolymath/standards#787`: A2ML is - retired (D99, D269c), deed is the destination (D312: descriptiles are - clauses of `_chora.deed`; D313: conversion through kcX), and D308 - makes `deed.abnf` authoritative over the deed README (comment - `6023959688`). D308 itself does not say "A2ML is dead"; the retirement is - the combined effect of those rulings. Enforcement is absent here: 225 - `.a2ml` files remain, and `1-formats/deed/spec/DEED-GRAMMAR-SPEC.adoc` - still declares `:version: 0.2.1` and `:status: DRAFT`. Not affirmed until - the migration lands. -* *JSON is I-JSON + JCS (D306; JSON-POLICY, standards#1189): could not run.* - `bash scripts/check-ijson-jcs.sh .` exited `2` (`ijson-jcs: not found`) on - the verifying machine. That exit means "the check could not look", not a - pass and not a failure. Nothing is affirmed about this repository's JSON. +* *Ruling R-B — `.a2ml` or `.deed`: RULED, not enforced.* It is ruled on + `hyperpolymath/standards#787`: A2ML is retired (D99, D269c), deed is the + destination (D312: descriptiles are clauses of `_chora.deed`; D313: + conversion through kcX), and D308 makes `deed.abnf` authoritative over the + deed README (comment `6023959688`). D308 itself does not say "A2ML is + dead"; the retirement is the combined effect of those rulings. Enforcement + is absent here: 225 `.a2ml` files remain, and + `1-formats/deed/spec/DEED-GRAMMAR-SPEC.adoc` declares `:version: 0.2.2` and + `:status: DRAFT`. Not affirmed until the migration lands. +* *JSON is I-JSON + JCS (D306; JSON-POLICY, standards#1189): measured, not + conformant.* `bash scripts/check-ijson-jcs.sh .` now runs (`ijson-jcs` + 0.1.0) and exits `0` because the gate is report-only: *62 files checked, 0 + canonical, 62 not canonical, 0 invalid, 0 JSONC carve-outs skipped*. + Positive controls: a canonical file reads as canonical (exit `0`); + `--enforce` over a pretty-printed file exits `1`; a missing tool exits `2`. + This repository's JSON does not yet conform, and nothing is affirmed about + it. * *This repository's `coordination.k9` does not conform to grammar 1.1.1.* The coordination spec is at `:revnumber: 1.1.1` (D311 made the 1.1 line canonical; the 1.1.1 patch landed in standards#1182, `23975997`). The spec says a `---` separator is invalid. `coordination.k9` declares `schema_version: 1.0.0` (line 15) and carries `---` at line 12. There is no - conforming coordination validator in-tree to run: `k9-validate.sh` checks - `.k9.ncl` contracts, and the generator is a Deno, YAML-subset parser that - accepts `---`. These are grep facts, recorded as a measured - non-conformance. + conforming coordination validator in-tree to run: + `1-formats/k9/tools/k9-validate.sh` checks `.k9.ncl` contracts, and the + generator (`2-protocols/k9-coordination/generator/generate.js`) is a Deno + script (`deno run` shebang) with a "YAML-like subset" parser that strips + `---`. These are grep facts, recorded as a measured non-conformance. + +[[ci]] +=== Failing at the anchor + +Context, not evidence. A green check is no evidence for an affirmation, but a +red one is a fact a reader needs. Read at `2026-10-09T08:08:09Z`, about 7.5 +hours after the push, the anchor carried **69** check runs (paginated: 48 +success, 13 skipped, 8 failure) and no legacy commit statuses. The eight +failures: + +* `Repo self-tests` and `Registry + topology in sync`. Both reproduce locally + at the anchor, in a tree that was clean before and after: + `bash scripts/build-registry.sh --check` exits `1` (`DRIFT: + .machine_readable/REGISTRY.a2ml is stale`); + `bash scripts/tests/build-registry-test.sh` reports *7 passed, 2 failed*; + `bash scripts/tests/build-scorecards-test.sh` reports *7 passed, 2 failed*, + naming three scorecard rows that claim PASS while their check exits `1`: + `component-readiness-grades/M3`, `estate-constitution/M2` and + `neurosym-a2ml/M5`. +* `SonarCloud Code Analysis`: quality gate failed on "D Security Rating on New + Code". A scanner finding; it surfaces and does not block. +* Five mirror jobs, `mirror / mirror-{codeberg,gitea,bitbucket,sourcehut, + disroot}`. The one log read (codeberg) ends `fatal: Could not read from + remote repository.` + +The same eight contexts were failing at `85aa1934`, so none is new since the +last affirmation; that file did not record them. None is a required context. +The three required contexts on `main` (`uses ⊆ actions.lock`, +`governance / Actions lockfile verify`, `scan / gitleaks`) succeeded. === Under realignment @@ -164,9 +212,8 @@ or under coordinated realignment. * *`rhodium-standard-repositories/`.* Disposition settled: archive in place, do not delete. It is the last copy of satellites with no external home (standards-map.toml; the upstream 404s). It holds 1137 tracked files at the - anchor (1138 in the earlier draft). The `spec/` extraction to - `0-canon/rsr/` was done on 2026-09-17; that is a past fact and is no longer - listed as an intent. + anchor. The `spec/` extraction to `0-canon/rsr/` was done on 2026-09-17; + that is a past fact and is not listed as an intent. === Refuted at this anchor (moved out of "We affirm") @@ -175,16 +222,57 @@ or under coordinated realignment. worded. `git log -- LICENSE` lists 11 commits; **8** carry an AI co-author trailer (`Co-Authored-By: Claude …`): `747b2f0f`, `0d4e97e2`, `0b96f61a`, `9723890d`, `3c979d20`, `1177a066`, `89b88de2`, `2dc67fe5`. All **3** - commits touching `LICENSES/` carry one too. This is a trailer count. It does - not establish who wrote the text or whether the owner directed the change - (several subjects say "owner-directed"), but it does mean the - absolute "no agent has edited" claim cannot be affirmed. The SPDX half has - no command that could check it. The rule remains policy; it is not an - affirmation. + commits touching `LICENSES/` carry one too. This is a trailer count, checked + commit by commit. It does not establish who wrote the text or whether the + owner directed the change (several subjects say "owner-directed"), but it + does mean the absolute "no agent has edited" claim cannot be affirmed. The + SPDX half has no command that could check it. The rule remains policy; it + is not an affirmation. +* *The 2026-10-07 toolchain row.* It recorded `grep` = `ugrep 7.8.4` and + `find` = `bfs 4.1.1`. Those are wrappers defined as functions in the + verifying agent's interactive shell; they are not exported, so the + `bash scripts/*.sh` children resolve `/usr/bin/grep` (GNU grep 3.11) and + `/usr/bin/find` (GNU findutils 4.10.0). This file records what the checks + actually ran. * *Erratum in the 2026-09-17 draft.* Its reproduction block checks out `beecaee…` while its anchor is `bbecaee…`. The archived copy is left verbatim; this file's reproduction block uses its own anchor. +[[changes]] +== Changes since the 2026-10-07 affirmation + +The previous file is archived byte-identically at +link:affirmations/AFFIRMATION-2026-10-07.adoc[affirmations/AFFIRMATION-2026-10-07.adoc]. + +* *It did not land anchored.* `bash scripts/verify-affirmation-anchor.sh + hyperpolymath/standards 1203`, run at `2026-10-09T08:07:49Z`, printed + `DRAFT` and exited `1`. Three conditions failed: the signed head + `f777d7c4` has parent `58db3356` (a README badge commit), not the anchor + `85aa1934`; the squash `e35431d5` has first parent `a709d3a6`, because + `main` had moved (#1202) before the PR was opened; and the two trees + differ. The signature, the squash being on `main`, and + `refs/pull/1203/head` all passed. Read the archived file as a draft. +* The anchor moves from `85aa1934` to `6d19ce0e`: 15 first-parent commits + (pull requests #1198 to #1212; #1206 is a dependabot rustls bump), + 36 files. None touches `canon.lock`, `0-canon/`, `coordination.k9`, `standards-map.toml`, + `.machine_readable/rsr-profile.a2ml` or any check script the battery runs. + The paths changed are listed by `git diff --name-only 85aa1934 6d19ce0e`. +* `*.deed` files: 20 → 26. The six new ones are deed-lint fixtures (#1198, + #1204). +* `DEED-GRAMMAR-SPEC.adoc` 0.2.1 → 0.2.2, and `deed.abnf` now admits a + `#u8"domain:name"` literal, ADR-008 profile C (#1198, D320/D323). The + `nostos` repo-deed vocabulary (draft v0.1) was added (#1204). +* The JSON check moved from "could not run" (exit `2`, tool absent) to a + measurement: 0 of 62 files canonical. +* `ci-pipeline.yml` no longer runs semgrep (#1205). At `85aa1934` the check run + `Call CI Pipeline / SAST (semgrep)` succeeded; at the anchor no semgrep check + run or status exists. The workflow's comment says the Semgrep Code App now + reports on pull requests. +* `AFFIRMATION-STANDARD.adoc` gained its rule for landing in a linear-history + repository, and `scripts/verify-affirmation-anchor.sh` was added (#1212). +* The CI failures in <> and the toolchain correction are newly recorded; + neither is new at the anchor. + [[anchor]] == Provenance @@ -199,37 +287,50 @@ or under coordinated realignment. | `main` | Commit (HEAD) -| `85aa1934975a8df576c7a4912bacbb8160ab2d2d` +| `6d19ce0ebae047027dcfd594c7810bf35c642faa` | Permalink -| https://github.com/hyperpolymath/standards/tree/85aa1934975a8df576c7a4912bacbb8160ab2d2d +| https://github.com/hyperpolymath/standards/tree/6d19ce0ebae047027dcfd594c7810bf35c642faa | Verified (UTC) -| `2026-10-07T10:28:41Z` (battery start; finished `2026-10-07T10:29:23Z`) +| `2026-10-09T08:05:13Z` to `2026-10-09T08:23:53Z`. Battery + `08:05:13Z`–`08:05:24Z`; positive controls `08:07:08Z`–`08:07:12Z`; + anchor verifier `08:07:49Z`; CI and ruleset reads `08:08:09Z`–`08:10:59Z`; + registry and scorecard re-runs `08:12:53Z`–`08:13:27Z`; repository + permission and `estate-telemetry` re-read `08:23:53Z`. | Working-tree delta at verification -| `clean`. `git status --short` was empty before and after the battery. - The planted positive controls ran before the battery and were reverted. - The assertion-2 control used a separate throwaway worktree, since removed. - The LICENSE trailer census and the R-A evidence were read from history and - from rsr-template-repo `3e6d4aa2…`, not from the working tree. - The branch that lands this file also adds a CC-BY-SA-4.0 docs badge to - `README.adoc` (`58db3356`). That is a README-only change and affects no - claim below. +| `clean`. The battery and the registry re-runs ran in a separate detached + worktree at the anchor; `git status --short` was empty before and after. + The positive controls ran in a separate scratch clone, which was clean and + back at the anchor afterwards. The LICENSE trailer census and the R-A + evidence were read from history and from rsr-template-repo `3e6d4aa2…`, not + from a working tree. The branch that lands this file changes only this file + and adds the 2026-10-07 archive; neither affects a claim. | Toolchain | `GNU bash 5.2.37`; `/bin/sh` = `dash 0.5.12` (runs `check-uuid-v8.sh`); - `git 2.47.3`; `GNU Awk 5.2.1`; `sha256sum` (GNU coreutils 9.7); - `grep` = `ugrep 7.8.4`; `find` = `bfs 4.1.1`; `gh 2.96.0` (ruling and repo - lookups only). `bun 1.3.14` was installed but no check used it. - `ijson-jcs` was absent. No Python, Deno or TypeScript was run. + `git 2.47.3`; `GNU Awk 5.2.1`; `sha256sum` (GNU coreutils 9.7); `grep` = + `GNU grep 3.11`; `find` = `GNU findutils 4.10.0`; `ijson-jcs 0.1.0` (git + `38e81e24`); `gh 2.96.0` with `jq 1.8.2` (CI, ruleset, repository and + verifier reads only); `asciidoctor 2.0.26` (this file's format gate). + `bun 1.4.2` was installed but no check used it. |=== +[[landing]] +.When this file is anchored [NOTE] ==== -This file lands by squash merge. If `main` moves before the merge, the anchor -above is not the parent of the landed commit, and the file must be read as a -draft until it is re-verified. It is unsigned in any case. +This file is anchored when either of these holds. Otherwise read it as a +draft. + +* The commit on `main` that adds it is the owner's signed commit, and its + parent is the anchor above (a fast-forward landing). +* It lands by squash, and `bash scripts/verify-affirmation-anchor.sh + hyperpolymath/standards 6d19ce0ebae047027dcfd594c7810bf35c642faa` + exits `0`: all four conditions of + link:AFFIRMATION-STANDARD.adoc#linear-history[AFFIRMATION-STANDARD §"Landing + in a linear-history repository"] hold. ==== [quote] @@ -242,36 +343,39 @@ ____ [source,bash] ---- -git checkout 85aa1934975a8df576c7a4912bacbb8160ab2d2d # the anchor +git checkout 6d19ce0ebae047027dcfd594c7810bf35c642faa # the anchor bash scripts/check-canon-lockstep.sh --canon . --base HEAD # 0: 7/0/3 bash scripts/check-rsr-profile.sh . # 0 bash scripts/check-standards-map.sh --repo . # 0: Gate D sh scripts/check-uuid-v8.sh --strict . # 0 bash scripts/tests/uuid-v8-test.sh # 0: PASS=32 -bash scripts/check-ijson-jcs.sh . # 2 without tool +bash scripts/check-ijson-jcs.sh . # 0: 0/62 canon +bash scripts/build-registry.sh --check # 1: DRIFT +bash scripts/tests/build-registry-test.sh # 1: 7 / 2 +bash scripts/tests/build-scorecards-test.sh # 1: 7 / 2 git ls-files '*.a2ml' | wc -l # 225 -git ls-files '*.deed' | wc -l # 20 +git ls-files '*.deed' | wc -l # 26 git ls-files rhodium-standard-repositories | wc -l # 1137 git ls-files docs/proofs | wc -l # 283 grep -n -e '^---$' -e schema_version coordination.k9 # 12, 15 -git log --format=%B -- LICENSE | grep -ci 'co-authored-by: claude' # 8 +for c in $(git log --format=%H -- LICENSE); do + git show -s --format=%B "$c" | grep -qi 'co-authored-by: claude' && echo "$c" +done | wc -l # 8 +bash scripts/verify-affirmation-anchor.sh hyperpolymath/standards 1203 # 1 +git show e35431d5:docs/AFFIRMATION.adoc | sha256sum # fceedc98…, the archive ---- == Attestation -[NOTE] -==== -**Unsigned.** The owner's joint attestation is required before this file may be -cited as an affirmation. Until then it is a measured draft. - -[cols="1,3", options="header"] -|=== -| Party | Signature / date - -| Owner — Jonathan D.A. Jewell -| _(empty — awaiting attestation)_ - -| Witness (if required) -| _(empty)_ -|=== -==== +Engineering party (AI):: + `claude-opus-5-5` ran every command named above against + `6d19ce0ebae047027dcfd594c7810bf35c642faa` between `2026-10-09T08:05:13Z` + and `2026-10-09T08:23:53Z`. The wording of this file faithfully reports + those runs, including the failures and the refutations of the previous + file. + +Owner / maintainer:: + Jonathan D.A. Jewell affirms this file by landing it with a signed commit + (`git commit -S -s`) whose parent is the anchor SHA, then checks it with + `git log --show-signature -1`. The signature on that commit is the + attestation; this file carries no separate signature block. diff --git a/docs/affirmations/AFFIRMATION-2026-10-07.adoc b/docs/affirmations/AFFIRMATION-2026-10-07.adoc new file mode 100644 index 000000000..7d1d4c5d9 --- /dev/null +++ b/docs/affirmations/AFFIRMATION-2026-10-07.adoc @@ -0,0 +1,277 @@ +// SPDX-License-Identifier: CC-BY-SA-4.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell (hyperpolymath) += AFFIRMATION — hyperpolymath/standards +Jonathan D.A. Jewell +:toc: macro +:toclevels: 2 +:icons: font +:std-docs: https://github.com/hyperpolymath/standards/blob/main/docs + +_What we affirm was true and checkable at a stamped moment._ + +**Profile B** (MUST / INTEND / WISH), per +link:AFFIRMATION-STANDARD.adoc[AFFIRMATION-STANDARD.adoc] §"Profile B — +required sections". This repository is a *policy surface*, so profile B +applies; profile A (evidential) is for implementation repos. + +[CAUTION] +==== +**Status: DRAFT — UNSIGNED.** This is a refresh of the 2026-09-17 draft, +which is kept verbatim at +link:affirmations/AFFIRMATION-2026-09-17.adoc[affirmations/AFFIRMATION-2026-09-17.adoc]. +Every check below was re-run on 2026-10-07 against the anchor in +<>; nothing was copied forward unmeasured. + +An affirmation is *signed* by the owner. That signature is not an agent's to +give. Every claim below is measured and reproducible; the attestation block at +the end is empty and MUST be filled by the owner before this file is cited. +==== + +toc::[] + +== We affirm + +Binding now. Each item names the command that checks it and the exit code it +returned at the anchor. + +. *The canon's law is hash-pinned.* `canon.lock` (version `2.1.2`, status + `draft`) records a `sha256` for five artefacts: the criteria, the gate table, + the applicability policy, the lifecycle spec and the constitution + directory. `bash scripts/check-canon-lockstep.sh --canon . --base HEAD` + exits `0`: *passed 7, failed 0, skipped 3*. The script's own + "NOT VERIFIED" list names the three skips: assertions 3 and 4 need a + `--spine` directory, and assertion 5's oracle (hypatia) is "to be + implemented". This item affirms assertions 1 and 2 only. +. *A canon change cannot be silent.* Assertion 2 fails a commit that changes a + file named in `canon.lock [canon.artifacts]` without touching `canon.lock`. + Positive control, run for this refresh: a throwaway commit (never pushed) + appended one line to `0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc`; + `--base HEAD~1` then reported `FAIL canon artefacts changed ( applicability + ) but canon.lock is untouched` and exited `1`. An uncommitted edit to the + same file fails assertion 1 instead (also measured, exit `1`). +. *The canon passes its own profile check.* `bash scripts/check-rsr-profile.sh + .` exits `0` (`rsr-profile check: OK — scaffold matches declared + capabilities`), with role `canon` and effective capabilities `bash + docs-site governance-tier reproducible-build`. Positive control: with + `docs/AUDIT.adoc` moved aside, the same command exits `1`. The profile it + reads, `.machine_readable/rsr-profile.a2ml`, is in the retired A2ML dialect; + see <>. The earlier draft's statement that this script once exited `2` + on this repository is history and was not re-measured. +. *The repository is mapped, both ways.* `bash scripts/check-standards-map.sh + --repo .` exits `0` (Gate D): 124 records, all 124 mapped paths exist, all + 74 top-level entries are mapped, every `canon_slot` resolves in + `canon.lock`. Positive control: an unmapped top-level directory planted in + the working tree made it exit `1` with `unmapped top-level entry`. +. *UUID literals are v8-only (ADR-008, strict).* `sh scripts/check-uuid-v8.sh + --strict .` exits `0`, and so does the default mode. ADR-008's status line + reads *Accepted* (D305/D305b), *Amended* by D320 (2026-10-07). By design + (D320) the scanner skips retired `*.a2ml` files, so this affirms + *non-A2ML* files only. Its own suite, `bash scripts/tests/uuid-v8-test.sh`, + reports `PASS=32 FAIL=0`, including rejection of a planted v7 under + `--strict`. A v4 literal planted outside the tree also made the default mode + exit `1`. +. *Ruling R-A is settled: the machine tree is `.machine_readable/`.* At the + anchor `.machine_readable/` exists and `machine-readable/` does not + (`test -d` / `test -e`). The basis is a *historical* census, not a current + count: rsr-template-repo's `docs/governance/TEMPLATE-LINEAGE-AUDIT.adoc` (at + rsr-template-repo `3e6d4aa27ddac8a3aa2431cc4321c600b02f3e75`) records **48 + repositories dotted against 9 hyphenated** at the 2026-08 divergence. This + confirms ruling 10 of `STANDARDS-CRITICAL-PATH.adoc`. + +== We intend + +Committed next actions. **Not yet true.** The release conditions they serve are +enumerated in link:AUDIT.adoc[AUDIT.adoc]. + +. Migrate this repository's A2ML to deed. At the anchor `git ls-files + '*.a2ml'` counts **225** files against **20** `*.deed`. Per D313 the + conversion is kcX's first front end, not a hand conversion; per D312 the + descriptiles become clauses of a `standards_chora.deed`, which does not yet + exist at the root. +. Re-express the canon's own law in deed. The criteria SSOT, + `0-canon/rsr/rsr-criteria-v2.a2ml`, and the canon profile, + `.machine_readable/rsr-profile.a2ml`, are both A2ML; `check-rsr-profile.sh` + reads only the `.a2ml` path. +. Move the generated estate telemetry (board, censuses, scorecards, audits) out + to a separate repository, so the canon versions by law changes only. + `hyperpolymath/estate-telemetry` does not exist yet (`gh repo view` could + not resolve it); 36 tracked files under `audits/` and + `.machine_readable/{estate-board*,scorecards,audits}` remain here. +. Implement `hypatia:rsr-conformance`, the one normative oracle named in + `rsr-criteria-v2.a2ml` §`[oracle]`. Gate A still skips assertion 5's oracle + run because it is marked "to be implemented"; until it lands, every + criterion's `detect` column is aspirational. +. Carry canon identity and provenance into minted repos as clauses of each + repo's `_chora.deed`, not as new `rsr-profile.a2ml` or + `PROVENANCE.a2ml` files: A2ML is retired, so the earlier draft's "mint + `.a2ml` files" intent is withdrawn and restated here. +. Turn on Gate A assertions 3–5 in `--strict` mode. +. Bring this repository's own `coordination.k9` to grammar 1.1.1 (see + <>). + +== We wish + +Horizon aspirations. **Explicitly not commitments.** + +* That every repository in the estate can answer "which canon am I on?" from a + machine-readable file rather than a campaign. +* That the canon's own criteria are written in a ratified grammar with a + normative ABNF. +* That `NO-PROVENANCE` reaches zero. + +[[held]] +== Held + +Not affirmed here: ruled but not enforced, unmeasurable with the tools at hand, +or under coordinated realignment. + +=== Ruled, not yet enforced + +* *Ruling R-B — `.a2ml` or `.deed`: RULED, not enforced.* The earlier draft + listed R-B as open. It is now ruled on `hyperpolymath/standards#787`: A2ML is + retired (D99, D269c), deed is the destination (D312: descriptiles are + clauses of `_chora.deed`; D313: conversion through kcX), and D308 + makes `deed.abnf` authoritative over the deed README (comment + `6023959688`). D308 itself does not say "A2ML is dead"; the retirement is + the combined effect of those rulings. Enforcement is absent here: 225 + `.a2ml` files remain, and `1-formats/deed/spec/DEED-GRAMMAR-SPEC.adoc` + still declares `:version: 0.2.1` and `:status: DRAFT`. Not affirmed until + the migration lands. +* *JSON is I-JSON + JCS (D306; JSON-POLICY, standards#1189): could not run.* + `bash scripts/check-ijson-jcs.sh .` exited `2` (`ijson-jcs: not found`) on + the verifying machine. That exit means "the check could not look", not a + pass and not a failure. Nothing is affirmed about this repository's JSON. +* *This repository's `coordination.k9` does not conform to grammar 1.1.1.* + The coordination spec is at `:revnumber: 1.1.1` (D311 made the 1.1 line + canonical; the 1.1.1 patch landed in standards#1182, `23975997`). The spec + says a `---` separator is invalid. `coordination.k9` declares + `schema_version: 1.0.0` (line 15) and carries `---` at line 12. There is no + conforming coordination validator in-tree to run: `k9-validate.sh` checks + `.k9.ncl` contracts, and the generator is a Deno, YAML-subset parser that + accepts `---`. These are grep facts, recorded as a measured + non-conformance. + +=== Under realignment + +* *The conformance tier of this repository.* `rsr-criteria-v2.a2ml` sets + `gold = 100`. This repository has never been scored by its own oracle, and + the oracle does not yet exist. No tier is claimed. +* *The `formal-proofs` posture of `docs/proofs/`.* Those 283 tracked files + (`git ls-files docs/proofs | wc -l`) are proof artefacts *of the estate*, + gathered from other repositories; they are not mechanised proofs *of this + repository's own code*. Whether that directory belongs in the canon at all + is open. +* *`rhodium-standard-repositories/`.* Disposition settled: archive in place, do + not delete. It is the last copy of satellites with no external home + (standards-map.toml; the upstream 404s). It holds 1137 tracked files at the + anchor (1138 in the earlier draft). The `spec/` extraction to + `0-canon/rsr/` was done on 2026-09-17; that is a past fact and is no longer + listed as an intent. + +=== Refuted at this anchor (moved out of "We affirm") + +* *"Licence and SPDX are manual-only. No agent has edited, swept or + relicensed `LICENSE` or any SPDX header in this repository."* Refuted as + worded. `git log -- LICENSE` lists 11 commits; **8** carry an AI co-author + trailer (`Co-Authored-By: Claude …`): `747b2f0f`, `0d4e97e2`, `0b96f61a`, + `9723890d`, `3c979d20`, `1177a066`, `89b88de2`, `2dc67fe5`. All **3** + commits touching `LICENSES/` carry one too. This is a trailer count. It does + not establish who wrote the text or whether the owner directed the change + (several subjects say "owner-directed"), but it does mean the + absolute "no agent has edited" claim cannot be affirmed. The SPDX half has + no command that could check it. The rule remains policy; it is not an + affirmation. +* *Erratum in the 2026-09-17 draft.* Its reproduction block checks out + `beecaee…` while its anchor is `bbecaee…`. The archived copy is left + verbatim; this file's reproduction block uses its own anchor. + +[[anchor]] +== Provenance + +[cols="1,3", options="header"] +|=== +| Field | Value + +| Repo +| `hyperpolymath/standards` + +| Branch +| `main` + +| Commit (HEAD) +| `85aa1934975a8df576c7a4912bacbb8160ab2d2d` + +| Permalink +| https://github.com/hyperpolymath/standards/tree/85aa1934975a8df576c7a4912bacbb8160ab2d2d + +| Verified (UTC) +| `2026-10-07T10:28:41Z` (battery start; finished `2026-10-07T10:29:23Z`) + +| Working-tree delta at verification +| `clean`. `git status --short` was empty before and after the battery. + The planted positive controls ran before the battery and were reverted. + The assertion-2 control used a separate throwaway worktree, since removed. + The LICENSE trailer census and the R-A evidence were read from history and + from rsr-template-repo `3e6d4aa2…`, not from the working tree. + The branch that lands this file also adds a CC-BY-SA-4.0 docs badge to + `README.adoc` (`58db3356`). That is a README-only change and affects no + claim below. + +| Toolchain +| `GNU bash 5.2.37`; `/bin/sh` = `dash 0.5.12` (runs `check-uuid-v8.sh`); + `git 2.47.3`; `GNU Awk 5.2.1`; `sha256sum` (GNU coreutils 9.7); + `grep` = `ugrep 7.8.4`; `find` = `bfs 4.1.1`; `gh 2.96.0` (ruling and repo + lookups only). `bun 1.3.14` was installed but no check used it. + `ijson-jcs` was absent. No Python, Deno or TypeScript was run. +|=== + +[NOTE] +==== +This file lands by squash merge. If `main` moves before the merge, the anchor +above is not the parent of the landed commit, and the file must be read as a +draft until it is re-verified. It is unsigned in any case. +==== + +[quote] +____ +If you are reading this at a later commit, the claims may have drifted. Re-run +the reproduction steps and write a fresh affirmation; do not trust a stale one. +____ + +=== Reproduction + +[source,bash] +---- +git checkout 85aa1934975a8df576c7a4912bacbb8160ab2d2d # the anchor +bash scripts/check-canon-lockstep.sh --canon . --base HEAD # 0: 7/0/3 +bash scripts/check-rsr-profile.sh . # 0 +bash scripts/check-standards-map.sh --repo . # 0: Gate D +sh scripts/check-uuid-v8.sh --strict . # 0 +bash scripts/tests/uuid-v8-test.sh # 0: PASS=32 +bash scripts/check-ijson-jcs.sh . # 2 without tool +git ls-files '*.a2ml' | wc -l # 225 +git ls-files '*.deed' | wc -l # 20 +git ls-files rhodium-standard-repositories | wc -l # 1137 +git ls-files docs/proofs | wc -l # 283 +grep -n -e '^---$' -e schema_version coordination.k9 # 12, 15 +git log --format=%B -- LICENSE | grep -ci 'co-authored-by: claude' # 8 +---- + +== Attestation + +[NOTE] +==== +**Unsigned.** The owner's joint attestation is required before this file may be +cited as an affirmation. Until then it is a measured draft. + +[cols="1,3", options="header"] +|=== +| Party | Signature / date + +| Owner — Jonathan D.A. Jewell +| _(empty — awaiting attestation)_ + +| Witness (if required) +| _(empty)_ +|=== +====