From afb8a4f6fcc4c66124964923b9fbcbad6505236c Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 9 Oct 2026 10:09:34 +0100 Subject: [PATCH] chore(r5): archive the scorecard corpus and clean path leaks (#837) Ruling R5 on #837 (owner, 2026-10-09): option B, with the section 4 leak clean first. This is increment 1 of three. - Remove machine-local absolute paths from 47 lines (25 evidence, 12 system, 10 effects) of the 29 *.scorecard.a2ml records, before the move, so the archive is clean from its first commit. - Drop the generator header from each record (the recipe is gone) and repoint each "# Schema:" comment at the archived schema. - Move .machine_readable/scorecards/ (29 records + schema) to .machine_readable/archive/scorecards-v1/ and add a README tombstone. - Repoint the four consumers: .hypatia-baseline.json, docs/BADGE-CRITERIA-SPEC.adoc, 1-formats/k9/spec/MIGRATION-1058.adoc, REGISTRY.adoc. - Record the ruling and the three increments in 1-formats/deed/mappings/scorecard-corpus-decision.adoc section 5. - Exclude the archived records (only *.scorecard.a2ml, not the README and not a sibling archive) from check-canonical-names.sh and from both modes of validate-bot-directives.sh. Scan mode of the latter was red on the base tree on k9-coordination-protocol.scorecard.a2ml; it passes now. Planted-positive tests pin the narrow scope; removing either exclusion fails exactly the archive case. Pending: increment 2 (one (assessment ...) clause per spec_id) needs a chora deed for this repository; increment 3 is the estate-audit emitter. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML --- .githooks/validate-bot-directives.sh | 9 ++- .hypatia-baseline.json | 2 +- .../0-ai-gatekeeper-protocol.scorecard.a2ml | 13 ++-- .../archive/scorecards-v1/README.adoc | 66 +++++++++++++++++++ .../a2ml-templates.scorecard.a2ml | 3 +- .../accessibility.scorecard.a2ml | 11 ++-- .../adoption-readiness-grades.scorecard.a2ml | 7 +- .../agentic-a2ml.scorecard.a2ml | 7 +- .../scorecards-v1}/anchor-a2ml.scorecard.a2ml | 5 +- .../avow-protocol.scorecard.a2ml | 3 +- .../axel-protocol.scorecard.a2ml | 3 +- .../component-readiness-grades.scorecard.a2ml | 3 +- .../contractiles.scorecard.a2ml | 3 +- .../did-you-actually-do-that.scorecard.a2ml | 3 +- .../ecosystem-a2ml.scorecard.a2ml | 9 ++- .../ensaid-config.scorecard.a2ml | 3 +- .../estate-constitution.scorecard.a2ml | 1 - .../form-fill-provenance.scorecard.a2ml | 3 +- ...oundations-readiness-grades.scorecard.a2ml | 5 +- .../hypatia-rules.scorecard.a2ml | 5 +- .../k9-coordination-protocol.scorecard.a2ml | 5 +- .../scorecards-v1}/k9-svc.scorecard.a2ml | 17 +++-- .../scorecards-v1}/meta-a2ml.scorecard.a2ml | 9 ++- .../neurosym-a2ml.scorecard.a2ml | 5 +- .../overlay-protocol.scorecard.a2ml | 5 +- .../playbook-a2ml.scorecard.a2ml | 3 +- .../publication-pre-flight.scorecard.a2ml | 3 +- .../release-pre-flight.scorecard.a2ml | 27 ++++---- ...odium-standard-repositories.scorecard.a2ml | 3 +- .../scorecards-v1}/scorecard.schema.json | 0 ...ession-management-standards.scorecard.a2ml | 3 +- .../scorecards-v1}/state-a2ml.scorecard.a2ml | 3 +- .../toolchain-readiness-grades.scorecard.a2ml | 9 ++- .../mappings/scorecard-corpus-decision.adoc | 29 +++++++- 1-formats/k9/spec/MIGRATION-1058.adoc | 2 +- REGISTRY.adoc | 10 +-- docs/BADGE-CRITERIA-SPEC.adoc | 2 +- scripts/check-canonical-names.sh | 5 +- scripts/tests/validate-bot-directives-test.sh | 28 ++++++++ scripts/tests/wave6-canonical-names-test.sh | 25 +++++++ 40 files changed, 242 insertions(+), 115 deletions(-) rename .machine_readable/{scorecards => archive/scorecards-v1}/0-ai-gatekeeper-protocol.scorecard.a2ml (74%) create mode 100644 .machine_readable/archive/scorecards-v1/README.adoc rename .machine_readable/{scorecards => archive/scorecards-v1}/a2ml-templates.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/accessibility.scorecard.a2ml (82%) rename .machine_readable/{scorecards => archive/scorecards-v1}/adoption-readiness-grades.scorecard.a2ml (93%) rename .machine_readable/{scorecards => archive/scorecards-v1}/agentic-a2ml.scorecard.a2ml (91%) rename .machine_readable/{scorecards => archive/scorecards-v1}/anchor-a2ml.scorecard.a2ml (96%) rename .machine_readable/{scorecards => archive/scorecards-v1}/avow-protocol.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/axel-protocol.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/component-readiness-grades.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/contractiles.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/did-you-actually-do-that.scorecard.a2ml (97%) rename .machine_readable/{scorecards => archive/scorecards-v1}/ecosystem-a2ml.scorecard.a2ml (90%) rename .machine_readable/{scorecards => archive/scorecards-v1}/ensaid-config.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/estate-constitution.scorecard.a2ml (97%) rename .machine_readable/{scorecards => archive/scorecards-v1}/form-fill-provenance.scorecard.a2ml (97%) rename .machine_readable/{scorecards => archive/scorecards-v1}/foundations-readiness-grades.scorecard.a2ml (95%) rename .machine_readable/{scorecards => archive/scorecards-v1}/hypatia-rules.scorecard.a2ml (97%) rename .machine_readable/{scorecards => archive/scorecards-v1}/k9-coordination-protocol.scorecard.a2ml (96%) rename .machine_readable/{scorecards => archive/scorecards-v1}/k9-svc.scorecard.a2ml (85%) rename .machine_readable/{scorecards => archive/scorecards-v1}/meta-a2ml.scorecard.a2ml (90%) rename .machine_readable/{scorecards => archive/scorecards-v1}/neurosym-a2ml.scorecard.a2ml (94%) rename .machine_readable/{scorecards => archive/scorecards-v1}/overlay-protocol.scorecard.a2ml (94%) rename .machine_readable/{scorecards => archive/scorecards-v1}/playbook-a2ml.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/publication-pre-flight.scorecard.a2ml (97%) rename .machine_readable/{scorecards => archive/scorecards-v1}/release-pre-flight.scorecard.a2ml (77%) rename .machine_readable/{scorecards => archive/scorecards-v1}/rhodium-standard-repositories.scorecard.a2ml (95%) rename .machine_readable/{scorecards => archive/scorecards-v1}/scorecard.schema.json (100%) rename .machine_readable/{scorecards => archive/scorecards-v1}/session-management-standards.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/state-a2ml.scorecard.a2ml (98%) rename .machine_readable/{scorecards => archive/scorecards-v1}/toolchain-readiness-grades.scorecard.a2ml (88%) diff --git a/.githooks/validate-bot-directives.sh b/.githooks/validate-bot-directives.sh index f6673e117..d282128d8 100755 --- a/.githooks/validate-bot-directives.sh +++ b/.githooks/validate-bot-directives.sh @@ -21,9 +21,15 @@ validate_file() { # the same population scan mode checks below. Without this fence the grep ran # over every staged prose file, so any README naming the AI tool "Codex" # could not be committed (owner ruling D316). +# Records in the frozen scorecard archive (ruling R5, #837) are skipped in +# both modes: they are assessments that name the tools of their day, not live +# directives. Only the records are skipped; nothing else under the archive is. if [ -n "$STAGED_FILES" ]; then while IFS=$'\n' read -r file; do [ -z "$file" ] && continue + case "$file" in + .machine_readable/archive/scorecards-v1/*.scorecard.a2ml) continue ;; + esac case "$file" in .machine_readable/*|*/.machine_readable/*) ;; *) continue ;; @@ -42,7 +48,8 @@ else if [ -d "$MACHINE_READABLE" ]; then while IFS= read -r file; do validate_file "$file" - done < <(find "$MACHINE_READABLE" -type f \( -name '*.a2ml' -o -name '*.deed' -o -name '*.md' -o -name '*.txt' \) 2>/dev/null || true) + done < <(find "$MACHINE_READABLE" -type f \( -name '*.a2ml' -o -name '*.deed' -o -name '*.md' -o -name '*.txt' \) \ + ! -path "$MACHINE_READABLE/archive/scorecards-v1/*.scorecard.a2ml" 2>/dev/null || true) fi fi diff --git a/.hypatia-baseline.json b/.hypatia-baseline.json index c1927a9ad..bd9fdcb5c 100644 --- a/.hypatia-baseline.json +++ b/.hypatia-baseline.json @@ -774,7 +774,7 @@ "severity": "medium", "rule_module": "structural_drift", "type": "SD022", - "file": ".machine_readable/scorecards/hypatia-rules.scorecard.a2ml", + "file": ".machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml", "note": "TEMPORARY REVIEW BASELINE (2026-08-29): classify whether the src/A2ML path is target-relative example content or stale repository-local documentation.", "expires_at": "2026-11-29", "tracking_issue": "hyperpolymath/standards#687" diff --git a/.machine_readable/scorecards/0-ai-gatekeeper-protocol.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/0-ai-gatekeeper-protocol.scorecard.a2ml similarity index 74% rename from .machine_readable/scorecards/0-ai-gatekeeper-protocol.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/0-ai-gatekeeper-protocol.scorecard.a2ml index a73b19d1b..1e9816c7f 100644 --- a/.machine_readable/scorecards/0-ai-gatekeeper-protocol.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/0-ai-gatekeeper-protocol.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # 0-ai-gatekeeper-protocol.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "0-ai-gatekeeper-protocol" @@ -23,7 +22,7 @@ id = "M2" text = "The manifest MUST contain all required sections defined by AI-MANIFEST-SPEC.adoc §Required Sections (Warning Header, What Is This, Canonical Locations, Core Invariants, Repository Structure, Attestation Proof)." system = "none (no parser/linter script in this repo enforces the spec against 0-AI-MANIFEST.a2ml; mcp-repo-guardian's manifest_test.js only tests inline reimplementations of parsing logic, not a repo-facing validator CLI)" status = "pass" -evidence = "Manual read of /home/user/standards/0-ai-gatekeeper-protocol/0-AI-MANIFEST.a2ml confirms presence of '# ⚠️ STOP', '## WHAT IS THIS?', '## CANONICAL LOCATIONS', '## CORE INVARIANTS', '## REPOSITORY STRUCTURE', and '## ATTESTATION PROOF' headings." +evidence = "Manual read of 0-ai-gatekeeper-protocol/0-AI-MANIFEST.a2ml confirms presence of '# ⚠️ STOP', '## WHAT IS THIS?', '## CANONICAL LOCATIONS', '## CORE INVARIANTS', '## REPOSITORY STRUCTURE', and '## ATTESTATION PROOF' headings." check = "grep -q '# ⚠️ STOP' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## WHAT IS THIS?' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## CANONICAL LOCATIONS' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## CORE INVARIANTS' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## REPOSITORY STRUCTURE' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## ATTESTATION PROOF' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml" effects = "Missing sections would leave AI agents without required guardrail information, defeating the protocol's stated purpose across all adopting repos." @@ -33,14 +32,14 @@ text = "The repository's own machine-readable state MUST accurately reflect this system = "none" status = "fail" check = "true" -effects = "/home/user/standards/0-ai-gatekeeper-protocol/.machine_readable/6a2/STATE.a2ml declares project = \"rsr-template-repo\" (name = \"Rsr Template Repo\", completion-percentage = 5, generic scaffolding actions like 'Define project scope and objectives'), i.e. it is an un-edited template copy, not this repo's actual state — directly violating the protocol's own 'no stale metadata' invariant it asks every other repo to uphold. Any agent trusting STATE.a2ml for context (as the manifest's own Session Startup Checklist instructs) would be misled about project identity/status, undermining the protocol's core value proposition." +effects = "0-ai-gatekeeper-protocol/.machine_readable/6a2/STATE.a2ml declares project = \"rsr-template-repo\" (name = \"Rsr Template Repo\", completion-percentage = 5, generic scaffolding actions like 'Define project scope and objectives'), i.e. it is an un-edited template copy, not this repo's actual state — directly violating the protocol's own 'no stale metadata' invariant it asks every other repo to uphold. Any agent trusting STATE.a2ml for context (as the manifest's own Session Startup Checklist instructs) would be misled about project identity/status, undermining the protocol's core value proposition." [[must]] id = "M4" text = "Core manifest-parsing/session/guard logic (as implemented for FFI/offline consumption) MUST have an automated test suite that passes." system = "none in this repo — repo-guardian-fs moved to hyperpolymath/repo-guardian per standards#492 (2026-08-28). Previously verified by: cargo test --manifest-path repo-guardian-fs/tests-offline/Cargo.toml (Rust unit tests for manifest parsing, session management, and path-guard invariant enforcement)." status = "manual-only" -evidence = "Ran `cargo test` in /home/user/standards/0-ai-gatekeeper-protocol/repo-guardian-fs/tests-offline: 29 passed; 0 failed (manifest hashing, canonical-location extraction, invariant detection, session ack/expiry, path-traversal/SCM-duplication guard tests, and a dogfood test parsing the repo's real 0-AI-MANIFEST.a2ml)." +evidence = "Ran `cargo test` in 0-ai-gatekeeper-protocol/repo-guardian-fs/tests-offline: 29 passed; 0 failed (manifest hashing, canonical-location extraction, invariant detection, session ack/expiry, path-traversal/SCM-duplication guard tests, and a dogfood test parsing the repo's real 0-AI-MANIFEST.a2ml)." effects = "If these regress, any FFI/native consumer (e.g. Zig bindings, future editor plugins) linking against this logic would silently mis-enforce or fail to enforce invariants." [[must]] @@ -48,7 +47,7 @@ id = "M5" text = "The repo-guardian-fs FUSE enforcement component MUST build/compile so the 'OS-level enforcement for ANY tool/agent' claim in README.adoc is actually deliverable." system = "cargo build (in repo-guardian-fs/, main crate, not tests-offline)" status = "fail" -effects = "`cargo build` in /home/user/standards/0-ai-gatekeeper-protocol/repo-guardian-fs fails with 58+ compile errors in the fuse3 v0.7.3 dependency (missing Future::poll impl, type-inference errors) on the installed Rust toolchain — exactly the known incompatibility documented in tests-offline/Cargo.toml's own comment ('fuse3 v0.7.3 fails to compile on Rust stable >= 1.80'). The FUSE wrapper, one of the protocol's three enforcement mechanisms advertised in README.adoc §Components, is currently non-functional for any real mount/enforcement use, affecting every non-MCP AI agent (Gemini, Copilot, ChatGPT) that the README says relies on it." +effects = "`cargo build` in 0-ai-gatekeeper-protocol/repo-guardian-fs fails with 58+ compile errors in the fuse3 v0.7.3 dependency (missing Future::poll impl, type-inference errors) on the installed Rust toolchain — exactly the known incompatibility documented in tests-offline/Cargo.toml's own comment ('fuse3 v0.7.3 fails to compile on Rust stable >= 1.80'). The FUSE wrapper, one of the protocol's three enforcement mechanisms advertised in README.adoc §Components, is currently non-functional for any real mount/enforcement use, affecting every non-MCP AI agent (Gemini, Copilot, ChatGPT) that the README says relies on it." [[should]] id = "S1" @@ -62,7 +61,7 @@ id = "S2" text = "CONTRIBUTING.md SHOULD accurately describe the actual build/test workflow for this specific repository." system = "none" status = "fail" -effects = "/home/user/standards/0-ai-gatekeeper-protocol/CONTRIBUTING.md instructs contributors to run `just test` and references `spec/` and `tests/` directories (Perimeter 2-3 language from a generic template), but no Justfile exists anywhere under 2-protocols/0-ai-gatekeeper/ and there is no spec/ or top-level tests/ directory (real tests live in repo-guardian-fs/tests-offline/ and mcp-repo-guardian/test/). New contributors following CONTRIBUTING.md literally would hit an immediate 'command not found' and be unable to run any tests." +effects = "0-ai-gatekeeper-protocol/CONTRIBUTING.md instructs contributors to run `just test` and references `spec/` and `tests/` directories (Perimeter 2-3 language from a generic template), but no Justfile exists anywhere under 2-protocols/0-ai-gatekeeper/ and there is no spec/ or top-level tests/ directory (real tests live in repo-guardian-fs/tests-offline/ and mcp-repo-guardian/test/). New contributors following CONTRIBUTING.md literally would hit an immediate 'command not found' and be unable to run any tests." [[should]] id = "S3" diff --git a/.machine_readable/archive/scorecards-v1/README.adoc b/.machine_readable/archive/scorecards-v1/README.adoc new file mode 100644 index 000000000..07a0c7011 --- /dev/null +++ b/.machine_readable/archive/scorecards-v1/README.adoc @@ -0,0 +1,66 @@ +// SPDX-License-Identifier: CC-BY-SA-4.0 += Spec scorecards, v1 — Archived 2026-10-09 +:icons: font + +[IMPORTANT] +==== +This directory is a *frozen archive*. Nothing in this repository generates, +reads, checks or extends these files. Do not edit them, do not add new +`*.scorecard.a2ml` files, and do not convert them by hand: A2ML is retired +(owner rulings D99, D269c, D312 and D313). +==== + +== What this is + +The 29 per-spec assessment records that used to live at +`.machine_readable/scorecards/`, one per `spec_id`, plus the +`scorecard.schema.json` they were written against. Each record is a +time-stamped MUST/SHOULD/COULD assessment of one specification in this +repository, not a description of current state. Read them as history. + +== Why it was archived + +Ruling R5 on https://github.com/hyperpolymath/standards/issues/837[#837] +chose option B (owner, 2026-10-09): freeze the corpus as an archive rather +than translate each file. The reasoning and the alternatives are in +link:../../../1-formats/deed/mappings/scorecard-corpus-decision.adoc[`scorecard-corpus-decision.adoc`]. + +The executor that ran each record's `check` commands +(`scripts/build-scorecards.sh --verify`) was retired with the spec registry +on 2026-10-09; see link:../../../REGISTRY.adoc[`REGISTRY.adoc`]. The `check` +fields here are therefore not run by anything. + +== What changed on the way in + +The records are otherwise byte-for-byte as they were. Three mechanical +edits were made before the move, so that the archive is clean from its +first day: + +* *Absolute local paths removed.* 47 lines (25 `evidence`, 12 `system`, + 10 `effects`) carried a machine-local absolute path to a workstation + checkout. Each was rewritten + to the repository-relative path it pointed at. The pull request that made + the move lists every affected file and line. +* *Generator header dropped.* Each file named a `just` recipe that + regenerated a dashboard from it. That recipe no longer exists. +* *Schema comment repointed.* The `# Schema:` line now names this + directory. The schema's own `$id` is unchanged: it is the historical + identifier of the v1 format, not a location. + +== What replaces it + +* *Summaries of these assessments* are to become one aggregate + `(assessment …)` clause per `spec_id` on the assessed repository's chora + deed (grammar: + link:../../../1-formats/deed/spec/abnf/deed.abnf[`deed.abnf`]). This + repository has no chora deed yet, so those clauses are *pending*; nothing + here links forward to them until they exist. +* *New assessments* are to be emitted by estate-audit, not written by hand. + +== Not to be confused with + +* The per-repository scorecards that the RSR oracle writes to verisim-data + (see `0-canon/rsr/RSR-SPEC-v2.adoc`): a different corpus, in a different + repository. +* The OpenSSF Scorecard workflow (`scorecard-reusable.yml`): a supply-chain + scanner, unrelated to these files. diff --git a/.machine_readable/scorecards/a2ml-templates.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/a2ml-templates.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/a2ml-templates.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/a2ml-templates.scorecard.a2ml index 5d4cd64b1..0990c14cf 100644 --- a/.machine_readable/scorecards/a2ml-templates.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/a2ml-templates.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # a2ml-templates.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "a2ml-templates" diff --git a/.machine_readable/scorecards/accessibility.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/accessibility.scorecard.a2ml similarity index 82% rename from .machine_readable/scorecards/accessibility.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/accessibility.scorecard.a2ml index 7202474f4..558b8cedc 100644 --- a/.machine_readable/scorecards/accessibility.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/accessibility.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # accessibility.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "accessibility" @@ -14,7 +13,7 @@ id = "M1" text = "The spec MUST provide a machine-readable Adjustfile.a2ml contract at .machine_readable/contractiles/adjust/Adjustfile.a2ml to satisfy Level A minimum viability." system = "probe: test -f .machine_readable/contractiles/adjust/Adjustfile.a2ml (as literally defined in STANDARD.a2ml Level A section)" status = "pass" -evidence = "/home/user/standards/.machine_readable/contractiles/adjust/Adjustfile.a2ml exists on disk (along with sibling adjust.manifest.a2ml, adjust.ncl, adjust.k9.ncl in the same directory)." +evidence = ".machine_readable/contractiles/adjust/Adjustfile.a2ml exists on disk (along with sibling adjust.manifest.a2ml, adjust.ncl, adjust.k9.ncl in the same directory)." check = "test -f .machine_readable/contractiles/adjust/Adjustfile.a2ml" effects = "Downstream projects copying this standard rely on this file as the canonical contractile template; if missing, their own Level-A probe fails." @@ -30,7 +29,7 @@ id = "M3" text = "Projects MUST provide accessibility documentation (docs/accessibility/README.adoc) per Level A 'documentation' requirement." system = "probe: test -f docs/accessibility/README.adoc" status = "pass" -evidence = "/home/user/standards/docs/accessibility/README.adoc exists and documents keyboard, screen-reader, and roadmap sections (though it is written as a template for a hypothetical 'Burble' project, not the standards repo itself)" +evidence = "docs/accessibility/README.adoc exists and documents keyboard, screen-reader, and roadmap sections (though it is written as a template for a hypothetical 'Burble' project, not the standards repo itself)" check = "test -f docs/accessibility/README.adoc" effects = "If absent, any project claiming HAS Level A compliance has no discoverable documentation trail, undermining auditability." @@ -53,14 +52,14 @@ id = "S1" text = "User-facing projects SHOULD achieve WCAG 2.1 AA compliance by Q4 2026, including automated accessibility testing (pa11y/axe-core) wired into CI." system = "probe: grep -r \"pa11y\\|axe\\|accessibility\" .github/workflows/ — checked repo-wide" status = "fail" -effects = "No CI job anywhere in /home/user/standards/.github/workflows references pa11y, axe, or accessibility; automated AA verification is entirely absent, so the Q4 2026 target has no tooling in place yet." +effects = "No CI job anywhere in .github/workflows references pa11y, axe, or accessibility; automated AA verification is entirely absent, so the Q4 2026 target has no tooling in place yet." [[should]] id = "S2" text = "Projects SHOULD publish a VPAT 2.4-format compliance report at docs/compliance/ACCESSIBILITY.adoc." system = "probe: test -f docs/compliance/ACCESSIBILITY.adoc" status = "fail" -effects = "The file at /home/user/standards/docs/compliance/ACCESSIBILITY.adoc exists but is an unrendered template — it contains literal unexpanded shell expressions ($(basename \"$repo\"), $(date '+%Y-%m-%d')) rather than actual filled-in product/version/date fields, so it does not constitute a genuine completed VPAT for any real project; treating the probe's file-existence check as satisfied would overstate actual compliance." +effects = "The file at docs/compliance/ACCESSIBILITY.adoc exists but is an unrendered template — it contains literal unexpanded shell expressions ($(basename \"$repo\"), $(date '+%Y-%m-%d')) rather than actual filled-in product/version/date fields, so it does not constitute a genuine completed VPAT for any real project; treating the probe's file-existence check as satisfied would overstate actual compliance." [[should]] id = "S3" diff --git a/.machine_readable/scorecards/adoption-readiness-grades.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/adoption-readiness-grades.scorecard.a2ml similarity index 93% rename from .machine_readable/scorecards/adoption-readiness-grades.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/adoption-readiness-grades.scorecard.a2ml index 424acb5c7..155174799 100644 --- a/.machine_readable/scorecards/adoption-readiness-grades.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/adoption-readiness-grades.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # adoption-readiness-grades.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "adoption-readiness-grades" @@ -14,7 +13,7 @@ id = "M1" text = "The ARG normative spec MUST exist as an AsciiDoc document with SPDX headers." system = "none (manual inspection)" status = "pass" -evidence = "/home/user/standards/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc (507 lines, 12 sections + revision history), SPDX-License-Identifier: CC-BY-SA-4.0 header present at line 1." +evidence = "adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc (507 lines, 12 sections + revision history), SPDX-License-Identifier: CC-BY-SA-4.0 header present at line 1." check = "test -f adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc && head -1 adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc | grep -q 'SPDX-License-Identifier' && grep -q '^== ' adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc" effects = "If absent, no downstream language repo has a normative baseline to cite in spec/ARG-PROFILE.adoc; per-language profiles would have nothing to tighten against." @@ -72,7 +71,7 @@ id = "S4" text = "A machine-readable counterpart of the normative spec (.a2ml) SHOULD exist and stay consistent with the .adoc." system = "none - no script cross-validates ADOPTION-READINESS-GRADES.a2ml against ADOPTION-READINESS-GRADES.adoc for consistency; consistency is asserted only in SELF-ASSESSMENT.adoc's manually-ticked checklist" status = "pass" -evidence = "/home/user/standards/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml exists (339 lines, SPDX-License-Identifier: MPL-2.0), referenced consistently in README.adoc and SELF-ASSESSMENT.adoc as the machine-readable counterpart." +evidence = "adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml exists (339 lines, SPDX-License-Identifier: MPL-2.0), referenced consistently in README.adoc and SELF-ASSESSMENT.adoc as the machine-readable counterpart." check = "test -f adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml && [ \"$(wc -l < adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml)\" -eq 339 ] && grep -q 'MPL-2.0' adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml" effects = "If it drifted from the prose spec unnoticed, any tool consuming the a2ml form would diverge from the documented normative rules; currently no automated guard against that drift." diff --git a/.machine_readable/scorecards/agentic-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/agentic-a2ml.scorecard.a2ml similarity index 91% rename from .machine_readable/scorecards/agentic-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/agentic-a2ml.scorecard.a2ml index ca7e1dd64..f9916b3b5 100644 --- a/.machine_readable/scorecards/agentic-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/agentic-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # agentic-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "agentic-a2ml" @@ -14,7 +13,7 @@ id = "M1" text = "The repository MUST provide a normative specification document defining the AGENTIC.a2ml format." system = "spec/AGENTIC-FORMAT-SPEC.adoc (383 lines, present and referenced from README.adoc)" status = "pass" -evidence = "/home/user/standards/agentic-a2ml/spec/AGENTIC-FORMAT-SPEC.adoc exists (383 lines) and is linked as 'the complete normative specification' from README.adoc." +evidence = "agentic-a2ml/spec/AGENTIC-FORMAT-SPEC.adoc exists (383 lines) and is linked as 'the complete normative specification' from README.adoc." check = "cd 1-formats/a2ml/agentic && test -f spec/AGENTIC-FORMAT-SPEC.adoc && [ \"$(wc -l < spec/AGENTIC-FORMAT-SPEC.adoc)\" -ge 383 ] && grep -q \"AGENTIC-FORMAT-SPEC.adoc\\[spec/AGENTIC-FORMAT-SPEC.adoc\\]\" README.adoc" effects = "Consumers (playbook-a2ml, meta-a2ml, downstream agent tooling) rely on this document as the authoritative contract for gating-policy fields; without it, dependent repos cannot implement conformant readers." @@ -51,7 +50,7 @@ id = "S1" text = "The project SHOULD run CI that lints/tests the artifacts actually present in the repository." system = ".gitlab-ci.yml (trivy, gitleaks, semgrep security jobs run unconditionally; rustfmt/clippy/cargo-test/cargo-build and mix-format/credo/mix-test/mix-build jobs are gated on `exists: Cargo.toml` / `exists: mix.exs`)" status = "fail" -effects = "There is no Cargo.toml or mix.exs anywhere under /home/user/standards/agentic-a2ml, so every lint/test/build stage in .gitlab-ci.yml is a no-op for this repo; only generic filesystem/secret scanners (trivy, gitleaks, semgrep) actually execute, giving false confidence that 'CI passes' when nothing spec-specific (schema validation, ABNF parsing, example conformance) is ever checked." +effects = "There is no Cargo.toml or mix.exs anywhere under agentic-a2ml, so every lint/test/build stage in .gitlab-ci.yml is a no-op for this repo; only generic filesystem/secret scanners (trivy, gitleaks, semgrep) actually execute, giving false confidence that 'CI passes' when nothing spec-specific (schema validation, ABNF parsing, example conformance) is ever checked." [[should]] id = "S2" diff --git a/.machine_readable/scorecards/anchor-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/anchor-a2ml.scorecard.a2ml similarity index 96% rename from .machine_readable/scorecards/anchor-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/anchor-a2ml.scorecard.a2ml index 7b9beb099..eec1904e9 100644 --- a/.machine_readable/scorecards/anchor-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/anchor-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # anchor-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "anchor-a2ml" @@ -61,7 +60,7 @@ effects = "No validator enforces presence of an 'expires' field or checks expiry [[should]] id = "S3" text = "The repository SHOULD supply the 'contractiles' operational/trust/recovery framework wired into this repo's own layout (per 1-formats/contractiles/README.adoc's fill-in instructions) rather than leaving it as an unfilled generic template." -system = "/home/user/standards/audit-contractiles.sh (checks for .machine_readable/contractiles/{must,trust,dust,bust,adjust,intend})" +system = "audit-contractiles.sh (checks for .machine_readable/contractiles/{must,trust,dust,bust,adjust,intend})" status = "fail" effects = "Running audit-contractiles.sh against this repo reports '❌ No contractiles directory' and '❌ K9 missing' because 1-formats/contractiles/ lives at repo root (1-formats/contractiles/must/Mustfile, 1-formats/contractiles/dust/Dustfile) rather than under .machine_readable/contractiles/, and only 'must' and 'dust' are present (trust/bust/adjust/intend absent, and Trustfile.hs/Intentfile mentioned in 1-formats/contractiles/README.adoc do not exist on disk). Any monorepo-wide contractile audit will flag this spec as non-compliant; downstream tooling relying on the audit script's monorepo-standard path will not find this repo's contractile files at all." diff --git a/.machine_readable/scorecards/avow-protocol.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/avow-protocol.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/avow-protocol.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/avow-protocol.scorecard.a2ml index 28a84c763..4c2435b58 100644 --- a/.machine_readable/scorecards/avow-protocol.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/avow-protocol.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # avow-protocol.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "avow-protocol" diff --git a/.machine_readable/scorecards/axel-protocol.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/axel-protocol.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/axel-protocol.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/axel-protocol.scorecard.a2ml index 38a053c73..faf6f615d 100644 --- a/.machine_readable/scorecards/axel-protocol.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/axel-protocol.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # axel-protocol.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "axel-protocol" diff --git a/.machine_readable/scorecards/component-readiness-grades.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/component-readiness-grades.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/component-readiness-grades.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/component-readiness-grades.scorecard.a2ml index a51621ac9..989092cd2 100644 --- a/.machine_readable/scorecards/component-readiness-grades.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/component-readiness-grades.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # component-readiness-grades.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "component-readiness-grades" diff --git a/.machine_readable/scorecards/contractiles.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/contractiles.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/contractiles.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/contractiles.scorecard.a2ml index 92dcd7a51..a1f338e93 100644 --- a/.machine_readable/scorecards/contractiles.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/contractiles.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # contractiles.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "contractiles" diff --git a/.machine_readable/scorecards/did-you-actually-do-that.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/did-you-actually-do-that.scorecard.a2ml similarity index 97% rename from .machine_readable/scorecards/did-you-actually-do-that.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/did-you-actually-do-that.scorecard.a2ml index 9aa13b694..9015ca5d9 100644 --- a/.machine_readable/scorecards/did-you-actually-do-that.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/did-you-actually-do-that.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # did-you-actually-do-that.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "did-you-actually-do-that" diff --git a/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/ecosystem-a2ml.scorecard.a2ml similarity index 90% rename from .machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/ecosystem-a2ml.scorecard.a2ml index 1d0e1352d..ae2fd810d 100644 --- a/.machine_readable/scorecards/ecosystem-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/ecosystem-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # ecosystem-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "ecosystem-a2ml" @@ -14,7 +13,7 @@ id = "M1" text = "ECOSYSTEM.a2ml documents MUST declare version, name, type, and purpose as required fields, and this MUST be captured in a formal machine-checkable schema." system = "spec/ecosystem.schema.json (\"required\": [\"version\", \"name\", \"type\", \"purpose\"])" status = "pass" -evidence = "/home/user/standards/ecosystem-a2ml/spec/ecosystem.schema.json line 7 declares required: [\"version\",\"name\",\"type\",\"purpose\"], matching README.adoc's \"Required Fields\" table." +evidence = "ecosystem-a2ml/spec/ecosystem.schema.json line 7 declares required: [\"version\",\"name\",\"type\",\"purpose\"], matching README.adoc's \"Required Fields\" table." check = "python3 -c \"import json; d=json.load(open('1-formats/a2ml/ecosystem/spec/ecosystem.schema.json')); assert 'properties' in d\" && grep -q '2020-12/schema' 1-formats/a2ml/ecosystem/spec/ecosystem.schema.json" effects = "Consumers building parsers/validators around this schema can rely on these four fields always being present; if unmet, downstream tooling (linters, dependency-mapping generators) would need defensive null-checks." @@ -30,7 +29,7 @@ id = "M3" text = "A machine-readable JSON Schema MUST exist to validate the JSON representation of conformant ECOSYSTEM.a2ml documents." system = "spec/ecosystem.schema.json (2020-12 draft JSON Schema with typed properties, patterns for semver, enums)" status = "pass" -evidence = "/home/user/standards/ecosystem-a2ml/spec/ecosystem.schema.json exists, is well-formed JSON Schema (draft 2020-12), and defines version/name/type/purpose plus optional properties (family, position-in-ecosystem, related-projects, etc.) matching the README's documented field set." +evidence = "ecosystem-a2ml/spec/ecosystem.schema.json exists, is well-formed JSON Schema (draft 2020-12), and defines version/name/type/purpose plus optional properties (family, position-in-ecosystem, related-projects, etc.) matching the README's documented field set." check = "python3 -c \"import json; d=json.load(open('1-formats/a2ml/ecosystem/spec/ecosystem.schema.json')); assert 'properties' in d\" && grep -q '2020-12/schema' 1-formats/a2ml/ecosystem/spec/ecosystem.schema.json" effects = "Downstream tooling (a2ml-to-json converters, CI validators in consuming repos) depends on this schema being present and internally coherent to validate ecosystem manifests at scale." @@ -74,7 +73,7 @@ id = "S4" text = "Repository-level governance files that the README's 'Project Structure' section lists as present in 1-formats/a2ml/ecosystem/ (CONTRIBUTING.md, CODE_OF_CONDUCT.md, 3-practice/SECURITY.md, LICENSE) SHOULD actually exist at that stated path." system = "none" status = "fail" -effects = "A contributor following the README's tree diagram (which places CONTRIBUTING.md/CODE_OF_CONDUCT.md/SECURITY.md/LICENSE directly under 1-formats/a2ml/ecosystem/) will find none of those files there; only monorepo-root equivalents exist (/home/user/standards/CONTRIBUTING.md etc.), which may or may not apply identically to this subproject's PMPL-1.0 licence claim." +effects = "A contributor following the README's tree diagram (which places CONTRIBUTING.md/CODE_OF_CONDUCT.md/SECURITY.md/LICENSE directly under 1-formats/a2ml/ecosystem/) will find none of those files there; only monorepo-root equivalents exist (CONTRIBUTING.md etc.), which may or may not apply identically to this subproject's PMPL-1.0 licence claim." [[could]] id = "C1" diff --git a/.machine_readable/scorecards/ensaid-config.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/ensaid-config.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/ensaid-config.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/ensaid-config.scorecard.a2ml index fd4a35606..e5b5d9bdc 100644 --- a/.machine_readable/scorecards/ensaid-config.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/ensaid-config.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # ensaid-config.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "ensaid-config" diff --git a/.machine_readable/scorecards/estate-constitution.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/estate-constitution.scorecard.a2ml similarity index 97% rename from .machine_readable/scorecards/estate-constitution.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/estate-constitution.scorecard.a2ml index 893ab1f84..38d84f69c 100644 --- a/.machine_readable/scorecards/estate-constitution.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/estate-constitution.scorecard.a2ml @@ -1,5 +1,4 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 -# Hand-authored source. Regenerate the dashboard with: just scorecards [scorecard] spec_id = "estate-constitution" diff --git a/.machine_readable/scorecards/form-fill-provenance.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/form-fill-provenance.scorecard.a2ml similarity index 97% rename from .machine_readable/scorecards/form-fill-provenance.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/form-fill-provenance.scorecard.a2ml index 7e8603d35..16f63c59f 100644 --- a/.machine_readable/scorecards/form-fill-provenance.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/form-fill-provenance.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # form-fill-provenance.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "form-fill-provenance" diff --git a/.machine_readable/scorecards/foundations-readiness-grades.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/foundations-readiness-grades.scorecard.a2ml similarity index 95% rename from .machine_readable/scorecards/foundations-readiness-grades.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/foundations-readiness-grades.scorecard.a2ml index 1f4b2b398..b8e5d9020 100644 --- a/.machine_readable/scorecards/foundations-readiness-grades.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/foundations-readiness-grades.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # foundations-readiness-grades.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "foundations-readiness-grades" @@ -14,7 +13,7 @@ id = "M1" text = "The normative FRG spec MUST exist as a versioned .adoc document defining the X..A grade ladder and worst-of-required-element aggregation rule." system = "none (manual inspection of FOUNDATIONS-READINESS-GRADES.adoc)" status = "pass" -evidence = "/home/user/standards/foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.adoc exists, Status: Active v1.0 2026-05-28, defines grades X|F|E|D|C|B|A per README.adoc quick mental model (lines 73-84)." +evidence = "foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.adoc exists, Status: Active v1.0 2026-05-28, defines grades X|F|E|D|C|B|A per README.adoc quick mental model (lines 73-84)." check = "test -f foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.adoc && grep -q \"X | F | E | D | C | B | A\" foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.adoc && grep -q \"worst-of\" foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.adoc" effects = "Without this document, no downstream language repo has a rubric to author spec/FRG-PROFILE.adoc against, and ARG's 'ARG-A requires FRG >= B' cross-axis coupling would be unenforceable." diff --git a/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml similarity index 97% rename from .machine_readable/scorecards/hypatia-rules.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml index e33279416..8fab307c1 100644 --- a/.machine_readable/scorecards/hypatia-rules.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # hypatia-rules.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "hypatia-rules" @@ -14,7 +13,7 @@ id = "M1" text = "Each of the seven documented rules (HYP-S001..HYP-S007) MUST exist as an `.a2ml` file in hypatia-rules/ with an `@rule` block declaring id, name, severity, category and source, matching the table in README.adoc." system = "none (no automated parser runs against these files in this repo's CI; a2ml/.github/workflows/a2ml-validation.yml exists but lives under a2ml/.github/workflows/ — a nested path GitHub Actions does not register — so it never fires for pushes/PRs to the standards repo root)" status = "pass" -evidence = "All seven files present and manually verified to contain matching @rule blocks: crg-demotion-detector.a2ml (HYP-S001), k9-orphan-detector.a2ml (HYP-S002), proof-freshness.a2ml (HYP-S003), rsr-self-compliance.a2ml (HYP-S004), crg-overclaim-detector.a2ml (HYP-S005), registry-staleness.a2ml (HYP-S006), profile-drift-detector.a2ml (HYP-S007) — read directly from /home/user/standards/hypatia-rules/*.a2ml on 2026-07-03." +evidence = "All seven files present and manually verified to contain matching @rule blocks: crg-demotion-detector.a2ml (HYP-S001), k9-orphan-detector.a2ml (HYP-S002), proof-freshness.a2ml (HYP-S003), rsr-self-compliance.a2ml (HYP-S004), crg-overclaim-detector.a2ml (HYP-S005), registry-staleness.a2ml (HYP-S006), profile-drift-detector.a2ml (HYP-S007) — read directly from hypatia-rules/*.a2ml on 2026-07-03." check = "grep -q 'id: HYP-S001' hypatia-rules/crg-demotion-detector.a2ml && grep -q 'id: HYP-S002' hypatia-rules/k9-orphan-detector.a2ml && grep -q 'id: HYP-S003' hypatia-rules/proof-freshness.a2ml && grep -q 'id: HYP-S004' hypatia-rules/rsr-self-compliance.a2ml && grep -q 'id: HYP-S005' hypatia-rules/crg-overclaim-detector.a2ml && grep -q 'id: HYP-S006' hypatia-rules/registry-staleness.a2ml && grep -q 'id: HYP-S007' hypatia-rules/profile-drift-detector.a2ml" effects = "If a file goes missing or the id/name drifts from README.adoc, any downstream Hypatia deployment loading rules by path (per the [[rules]] config snippet in README.adoc) silently fails to activate that rule, and the standards estate loses coverage for that compliance signal (e.g. CRG grade-honesty, registry drift) without any repo-side alarm." diff --git a/.machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/k9-coordination-protocol.scorecard.a2ml similarity index 96% rename from .machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/k9-coordination-protocol.scorecard.a2ml index d17acaa9d..725710edd 100644 --- a/.machine_readable/scorecards/k9-coordination-protocol.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/k9-coordination-protocol.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # k9-coordination-protocol.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "k9-coordination-protocol" @@ -69,7 +68,7 @@ effects = "Latency regressions in the generator (e.g. from a future target addit [[should]] id = "S3" text = "The spec SHOULD be wired into repository CI so tests, mutation score, and the k9-init Rust binary are checked on every push/PR (as READINESS.md's 'dogfood-gate' claim implies)." -system = "none — searched /home/user/standards/.github/workflows (repo root) and 2-protocols/k9-coordination/ for any workflow referencing k9-coordination, k9-init, or coordination.k9; found zero matches, and no dogfood-gate.yml file exists anywhere in the repo" +system = "none — searched .github/workflows (repo root) and 2-protocols/k9-coordination/ for any workflow referencing k9-coordination, k9-init, or coordination.k9; found zero matches, and no dogfood-gate.yml file exists anywhere in the repo" status = "fail" effects = "READINESS.md's Grade-B justification claims deployment 'via dogfood-gate on 105+ repos' and CI integration with a '--fail-on-missing flag', but no such CI job exists in this repo; this is an unverifiable/undischarged claim. Any consuming repo that trusts the stated CRG grade is relying on an assertion with no reproducible mechanical check backing it in-repo." diff --git a/.machine_readable/scorecards/k9-svc.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/k9-svc.scorecard.a2ml similarity index 85% rename from .machine_readable/scorecards/k9-svc.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/k9-svc.scorecard.a2ml index 7a757aadc..90c97d7a5 100644 --- a/.machine_readable/scorecards/k9-svc.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/k9-svc.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # k9-svc.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "k9-svc" @@ -14,7 +13,7 @@ id = "M1" text = "Every `.k9` file MUST begin with the magic number `K9!` (0x4B 0x39 0x21) for L1 identification." system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: test.sh 'Example Components' section (checks `head -1 examples/hello.k9 | grep K9!`) and mime/k9.xml, mime/k9.magic magic-byte definitions; run in CI job 'test' and 'mime' in .github/workflows/ci.yml." status = "manual-only" -evidence = "/home/user/standards/k9-svc/test.sh lines ~128-219 assert hello.k9, k9.xml and k9.magic all carry the K9! magic; examples/hello.k9 exists on disk and CI job `test`/`mime` in ci.yml executes test.sh and xmllint/file checks on push and PR." +evidence = "k9-svc/test.sh lines ~128-219 assert hello.k9, k9.xml and k9.magic all carry the K9! magic; examples/hello.k9 exists on disk and CI job `test`/`mime` in ci.yml executes test.sh and xmllint/file checks on push and PR." effects = "Downstream OS/kernel MIME recognition (Freedesktop, UTI, Minix mime.types) and any consumer tool that dispatches on the magic number depend on this holding; if broken, file-type detection silently fails across all K9 consumers." @@ -23,7 +22,7 @@ id = "M2" text = "An implementation MUST enforce the three-tier Leash security model (Kennel/Yard/Hunt) with escalating capability (data-only -> pure Nickel eval -> full triad execution)." system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: leash.ncl (canonical encoding) typechecked in CI job 'validate' (`nickel typecheck leash.ncl`) in .github/workflows/ci.yml; test.sh 'Schema Validation' section also runs `nickel typecheck leash.ncl`." status = "manual-only" -evidence = "/home/user/standards/k9-svc/leash.ncl defines `levels.kennel/yard/hunt` with distinct `allows` maps; CI job 'validate' in .github/workflows/ci.yml runs `nickel typecheck leash.ncl` on every push/PR, and test.sh line ~111-115 does the same locally." +evidence = "k9-svc/leash.ncl defines `levels.kennel/yard/hunt` with distinct `allows` maps; CI job 'validate' in .github/workflows/ci.yml runs `nickel typecheck leash.ncl` on every push/PR, and test.sh line ~111-115 does the same locally." effects = "Any tool executing a .k9 component (must, Just recipes, k9-sign, future runtimes) relies on this typed contract; a break would let a Yard component perform I/O or a Kennel component execute code." @@ -53,16 +52,16 @@ id = "M6" text = "MIME registration for `.k9`/`.k9.ncl` MUST be provided for Linux (Freedesktop XML), macOS (UTI plist), and Minix (static mime.types mapping)." system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: mime/k9.xml, mime/k9.uti.plist, mime/mime.types on disk; validated by CI job 'mime' in .github/workflows/ci.yml (`xmllint --noout mime/k9.xml mime/k9.uti.plist`, `file --compile mime/k9.magic || true`) and register.ncl typechecked in CI job 'validate'." status = "manual-only" -evidence = "/home/user/standards/k9-svc/mime/k9.xml, k9.uti.plist, mime.types, k9.magic all exist; ci.yml job 'mime' runs xmllint validation on push/PR; job 'validate' runs `nickel typecheck register.ncl`." +evidence = "k9-svc/mime/k9.xml, k9.uti.plist, mime.types, k9.magic all exist; ci.yml job 'mime' runs xmllint validation on push/PR; job 'validate' runs `nickel typecheck register.ncl`." effects = "OS-level file-manager/desktop integration for K9 files across the three named platforms depends on these being syntactically valid and present." [[should]] id = "S1" text = "An implementation SHOULD refuse to run as root by default, requiring an explicit `K9_ALLOW_ROOT=true` or `--allow-root` escape hatch." -system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: must shim `check_root()` function (/home/user/standards/k9-svc/must lines ~20-40); exercised indirectly whenever `./must` is invoked (no dedicated CI job running must as root to prove the refusal path, but the code path is present and unconditional)." +system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: must shim `check_root()` function (k9-svc/must lines ~20-40); exercised indirectly whenever `./must` is invoked (no dedicated CI job running must as root to prove the refusal path, but the code path is present and unconditional)." status = "manual-only" -evidence = "/home/user/standards/k9-svc/must defines `check_root()` which checks `id -u` and exits with a warning unless `K9_ALLOW_ROOT=true`; this function is called before other must subcommands per the script's control flow." +evidence = "k9-svc/must defines `check_root()` which checks `id -u` and exits with a warning unless `K9_ALLOW_ROOT=true`; this function is called before other must subcommands per the script's control flow." effects = "Prevents accidental privileged execution of Hunt-level components by naive users/CI runners; without it, a compromised or buggy component would have full system access by default." @@ -71,7 +70,7 @@ id = "S2" text = "The reference signing tool (k9-sign) SHOULD be a memory-safe implementation with an automated test suite covering keygen/sign/verify/trust/list." system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: k9-sign/src/tests.rs (15 #[test] functions) run via CI job 'test' in .github/workflows/k9-sign-ci.yml (`cargo test --verbose` and `cargo test --release --verbose`) across ubuntu-latest/macos-latest x stable/beta matrix." status = "manual-only" -evidence = "/home/user/standards/k9-svc/k9-sign/src/tests.rs contains 15 `#[test]` functions (grep count); k9-sign-ci.yml job 'test' runs `cargo test --verbose -- --test-threads=1` in both debug and release mode on a 2x2 OS/toolchain matrix on every push/PR touching k9-sign/**." +evidence = "k9-svc/k9-sign/src/tests.rs contains 15 `#[test]` functions (grep count); k9-sign-ci.yml job 'test' runs `cargo test --verbose -- --test-threads=1` in both debug and release mode on a 2x2 OS/toolchain matrix on every push/PR touching k9-sign/**." effects = "Bindings and tools that shell out to k9-sign for Ed25519 signing rely on this correctness; a regression would compromise the signature precondition of the Hunt gate." @@ -119,6 +118,6 @@ id = "C3" text = "K9 COULD support container-based deployment as a first-class, non-root, multi-stage build on a minimal/hardened base image." system = "none in this repo — the implementation moved to hyperpolymath/k9-ecosystem under standards#491. Previously verified by: Containerfile (Chainguard wolfi-base per README); validated by CI job 'container' in .github/workflows/ci.yml (`podman build`, then `podman run --rm k9-svc:ci status` and `run typecheck`) and test.sh 'Container' section (4 tests: multi-stage build, non-root user)." status = "manual-only" -evidence = "/home/user/standards/k9-svc/Containerfile exists; ci.yml job 'container' builds and smoke-tests the image on every push/PR (needs: validate); TESTING.adoc documents a 4-test Container section in test.sh." +evidence = "k9-svc/Containerfile exists; ci.yml job 'container' builds and smoke-tests the image on every push/PR (needs: validate); TESTING.adoc documents a 4-test Container section in test.sh." effects = "Users following the README's `podman build/run` quick-start depend on this; a break would surface immediately in CI rather than only for end users." diff --git a/.machine_readable/scorecards/meta-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/meta-a2ml.scorecard.a2ml similarity index 90% rename from .machine_readable/scorecards/meta-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/meta-a2ml.scorecard.a2ml index 791d16836..e4c1b49be 100644 --- a/.machine_readable/scorecards/meta-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/meta-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # meta-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "meta-a2ml" @@ -14,7 +13,7 @@ id = "M1" text = "The repository MUST provide a formal specification document defining the META.a2ml/META format syntax and semantics." system = "spec/META-FORMAT-SPEC.adoc (present, IETF Internet-Draft style)" status = "pass" -evidence = "/home/user/standards/meta-a2ml/spec/META-FORMAT-SPEC.adoc exists with Abstract, Status of Memo, Introduction, ABNF cross-references, etc." +evidence = "meta-a2ml/spec/META-FORMAT-SPEC.adoc exists with Abstract, Status of Memo, Introduction, ABNF cross-references, etc." check = "test -f 1-formats/a2ml/meta/spec/META-FORMAT-SPEC.adoc && grep -q 'Abstract' 1-formats/a2ml/meta/spec/META-FORMAT-SPEC.adoc && grep -q 'Status of' 1-formats/a2ml/meta/spec/META-FORMAT-SPEC.adoc" effects = "Consumers/implementers (parsers, tooling, sibling *-a2ml repos) rely on this doc as the normative reference." @@ -72,7 +71,7 @@ id = "S4" text = "The repository SHOULD have automated dependency/version currency checks for its CI Action pins." system = ".github/dependabot.yml (github-actions ecosystem, daily schedule, grouped 'actions' updates)" status = "pass" -evidence = "/home/user/standards/meta-a2ml/.github/dependabot.yml configures package-ecosystem: github-actions with daily interval and grouped patterns." +evidence = "meta-a2ml/.github/dependabot.yml configures package-ecosystem: github-actions with daily interval and grouped patterns." check = "test -f 1-formats/a2ml/meta/.github/dependabot.yml && grep -q 'github-actions' 1-formats/a2ml/meta/.github/dependabot.yml" effects = "Without this, stale/vulnerable pinned Action SHAs would go unnoticed by downstream users of these workflows." @@ -95,6 +94,6 @@ id = "C3" text = "The repository COULD publish a GitHub Pages rendering of the spec docs for easier consumption." system = ".github/workflows/casket-pages.yml (GitHub Pages build workflow triggered on push to main)" status = "pass" -evidence = "/home/user/standards/meta-a2ml/.github/workflows/casket-pages.yml defines a 'build' job under permissions pages:write, id-token:write, triggered on push to main and workflow_dispatch." +evidence = "meta-a2ml/.github/workflows/casket-pages.yml defines a 'build' job under permissions pages:write, id-token:write, triggered on push to main and workflow_dispatch." check = "test -f 1-formats/a2ml/meta/.github/workflows/casket-pages.yml && grep -q 'pages: write' 1-formats/a2ml/meta/.github/workflows/casket-pages.yml" effects = "Improves discoverability/readability of the spec for external readers; absence would only reduce convenience, not correctness." diff --git a/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/neurosym-a2ml.scorecard.a2ml similarity index 94% rename from .machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/neurosym-a2ml.scorecard.a2ml index 732e8389e..1300e646f 100644 --- a/.machine_readable/scorecards/neurosym-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/neurosym-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # neurosym-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "neurosym-a2ml" @@ -42,7 +41,7 @@ id = "M5" text = "The spec's home directory, canonical doc, and content hash MUST be correctly registered in the estate spec registry so downstream tooling (TOPOLOGY.md, drift detection) can locate it." system = "scripts/build-registry.sh --check, run as the \"Registry + topology in sync\" job in .github/workflows/registry-verify.yml" status = "pass" -evidence = "/home/user/standards/.machine_readable/REGISTRY.a2ml lines 97-103 contain a `[[spec]]` entry with id=\"neurosym-a2ml\", home=\"1-formats/a2ml/neurosym/\", canonical_doc=\"1-formats/a2ml/neurosym/README.adoc\", and a computed source_hash; /home/user/standards/TOPOLOGY.md line 29 lists the corresponding human-readable row — both are consistent with the current file tree." +evidence = ".machine_readable/REGISTRY.a2ml lines 97-103 contain a `[[spec]]` entry with id=\"neurosym-a2ml\", home=\"1-formats/a2ml/neurosym/\", canonical_doc=\"1-formats/a2ml/neurosym/README.adoc\", and a computed source_hash; TOPOLOGY.md line 29 lists the corresponding human-readable row — both are consistent with the current file tree." check = "bash scripts/build-registry.sh --check" effects = "Estate-wide tooling (drift detection, Hypatia rule HYP-S006, cross-repo navigation) depends on this registry entry staying accurate; it currently is." diff --git a/.machine_readable/scorecards/overlay-protocol.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/overlay-protocol.scorecard.a2ml similarity index 94% rename from .machine_readable/scorecards/overlay-protocol.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/overlay-protocol.scorecard.a2ml index a7ee6294c..cc5f94b39 100644 --- a/.machine_readable/scorecards/overlay-protocol.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/overlay-protocol.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # overlay-protocol.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "overlay-protocol" @@ -65,7 +64,7 @@ id = "S3" text = "The README and ROADMAP SHOULD mark overlay-protocol as SPEC-ONLY status, and TOPOLOGY/PROTOCOLS listings SHOULD include the SPEC-ONLY tag, per the recorded DECISION." system = "none" status = "fail" -effects = "grep of /home/user/standards/README.adoc and /home/user/standards/ROADMAP.adoc for 'overlay-protocol' or 'SPEC-ONLY' returns zero matches — action item 3 of DECISION.adoc (dated 2026-04-05) was never carried out. Anyone browsing README/ROADMAP has no indication overlay-protocol is spec-only with zero implementation, risking a false impression of maturity." +effects = "grep of README.adoc and ROADMAP.adoc for 'overlay-protocol' or 'SPEC-ONLY' returns zero matches — action item 3 of DECISION.adoc (dated 2026-04-05) was never carried out. Anyone browsing README/ROADMAP has no indication overlay-protocol is spec-only with zero implementation, risking a false impression of maturity." [[should]] id = "S4" diff --git a/.machine_readable/scorecards/playbook-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/playbook-a2ml.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/playbook-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/playbook-a2ml.scorecard.a2ml index be707691e..c5ee4347d 100644 --- a/.machine_readable/scorecards/playbook-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/playbook-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # playbook-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "playbook-a2ml" diff --git a/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/publication-pre-flight.scorecard.a2ml similarity index 97% rename from .machine_readable/scorecards/publication-pre-flight.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/publication-pre-flight.scorecard.a2ml index 21218f62e..370341b0e 100644 --- a/.machine_readable/scorecards/publication-pre-flight.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/publication-pre-flight.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # publication-pre-flight.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "publication-pre-flight" diff --git a/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/release-pre-flight.scorecard.a2ml similarity index 77% rename from .machine_readable/scorecards/release-pre-flight.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/release-pre-flight.scorecard.a2ml index f31118837..2432d6d62 100644 --- a/.machine_readable/scorecards/release-pre-flight.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/release-pre-flight.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # release-pre-flight.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "release-pre-flight" @@ -12,7 +11,7 @@ assessor = "estate-audit" [[must]] id = "M1" text = "The gate document MUST enumerate hard gates (proof completeness, test completeness, benchmark completeness, build/execution integrity, aspect integrity, static/security audit, claim/artifact parity) that block a v1.0.0 stable claim." -system = "/home/user/standards/release-pre-flight/V1-GATE.adoc sections 3.1-3.7" +system = "release-pre-flight/V1-GATE.adoc sections 3.1-3.7" status = "pass" evidence = "V1-GATE.adoc lines 47-130 define sections 3.1 through 3.7 with concrete, checkable criteria for each hard gate." check = "for s in \"3.1 Proof Completeness\" \"3.2 Test Completeness\" \"3.3 Benchmark Completeness\" \"3.4 Build and Execution Integrity\" \"3.5 Aspect Integrity\" \"3.6 Static and Security Audit\" \"3.7 Claim and Artifact Parity\"; do grep -q \"=== $s\" 3-practice/release-pre-flight/V1-GATE.adoc || exit 1; done" @@ -21,7 +20,7 @@ effects = "Any repo/spec claiming v1.0.0 without meeting these criteria has no d [[must]] id = "M2" text = "There MUST be an automated audit script that mechanically scans a target repo for unfinished-marker residue (TODO/FIXME/XXX/HACK/STUB/PARTIAL, template placeholders) in claimed release paths." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_marker_scan() (MARKER_PATTERN regex via ripgrep)" +system = "release-pre-flight/v1-audit.sh check_marker_scan() (MARKER_PATTERN regex via ripgrep)" status = "pass" evidence = "Running `bash 3-practice/release-pre-flight/v1-audit.sh .` against the monorepo root exercises check_marker_scan and correctly flags real STUB/TODO occurrences (e.g. 3-practice/session-management-standards/continuity/*/CHECKLIST.adoc:7 'Status: STUB', 2-protocols/axel/config/ci.k9.ncl:68 'TODO: Add coverage')." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: unfinished markers or placeholders present'" @@ -30,7 +29,7 @@ effects = "Without this, downstream repos could tag v1.0.0 while shipping scaffo [[must]] id = "M3" text = "The audit script MUST detect proof-debt escape hatches (believe_me, sorry, Admitted, postulate, assert_total, unsafeCoerce, Obj.magic) in proof-bearing source files." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_proof_debt() (PROOF_DEBT_PATTERN via ripgrep)" +system = "release-pre-flight/v1-audit.sh check_proof_debt() (PROOF_DEBT_PATTERN via ripgrep)" status = "pass" evidence = "Executing the script against the repo root correctly surfaced 4 real `postulate` occurrences in lol/proofs/theories/information_theory.agda:115,121,127,132, recorded as a BLOCKER." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'BLOCKER: proof escape hatches found'" @@ -39,16 +38,16 @@ effects = "Repos with unresolved proof holes (e.g. lol's Agda postulates) would [[must]] id = "M4" text = "The audit script MUST verify that the target repo has real build, point-to-point/unit test, end-to-end test, aspect test, benchmark, and execution/smoke recipes (via Justfile or equivalent test paths), not placeholder recipes." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_audit_surfaces()" +system = "release-pre-flight/v1-audit.sh check_audit_surfaces()" status = "fail" -effects = "check_audit_surfaces() calls `Justfile_path` (capital J) at line 271, but the function is defined as `justfile_path` (lowercase) at line 198. This is a real bash case-sensitivity bug: the call always fails with 'command not found', is swallowed by `if !`, and the script unconditionally records a false 'missing Justfile/Justfile' blocker and returns early -- even though a top-level Justfile exists in the repo root (confirmed: /home/user/standards/Justfile is present, 10380 bytes). Verified by running `bash 3-practice/release-pre-flight/v1-audit.sh .`, which printed 'Justfile_path: command not found' followed by 'BLOCKER: missing Justfile/Justfile'. This means the entire build/test/benchmark/aspect/execution-surface portion of the gate is non-functional for every invocation, silently short-circuiting the most substantive part of the audit." +effects = "check_audit_surfaces() calls `Justfile_path` (capital J) at line 271, but the function is defined as `justfile_path` (lowercase) at line 198. This is a real bash case-sensitivity bug: the call always fails with 'command not found', is swallowed by `if !`, and the script unconditionally records a false 'missing Justfile/Justfile' blocker and returns early -- even though a top-level Justfile exists in the repo root (confirmed: Justfile is present, 10380 bytes). Verified by running `bash 3-practice/release-pre-flight/v1-audit.sh .`, which printed 'Justfile_path: command not found' followed by 'BLOCKER: missing Justfile/Justfile'. This means the entire build/test/benchmark/aspect/execution-surface portion of the gate is non-functional for every invocation, silently short-circuiting the most substantive part of the audit." [[must]] id = "M5" text = "The audit script MUST verify the target repo has a CI workflow surface (e.g. .github/workflows or .gitlab-ci.yml) backing the release gate." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_ci_surface()" +system = "release-pre-flight/v1-audit.sh check_ci_surface()" status = "pass" -evidence = "Running the script against the monorepo root printed 'PASS: CI workflow surface present', correctly detecting /home/user/standards/.github/workflows (30+ workflow files present, e.g. codeql.yml, secret-scanner.yml)." +evidence = "Running the script against the monorepo root printed 'PASS: CI workflow surface present', correctly detecting .github/workflows (30+ workflow files present, e.g. codeql.yml, secret-scanner.yml)." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: CI workflow surface present'" effects = "Without this check, a repo could claim v1.0.0 with no CI wired at all, and no automated signal would catch it." @@ -57,12 +56,12 @@ id = "S1" text = "The v1-audit.sh script SHOULD itself be exercised by the monorepo's own CI so that regressions in the gate tooling (such as the Justfile_path typo) are caught automatically." system = "none" status = "fail" -effects = "No workflow in /home/user/standards/.github/workflows references v1-audit.sh (confirmed via grep across .github). The M4 bug (Justfile_path typo) has shipped undetected because nothing runs or tests the audit script itself; any future edits to v1-audit.sh carry the same risk of silent breakage." +effects = "No workflow in .github/workflows references v1-audit.sh (confirmed via grep across .github). The M4 bug (Justfile_path typo) has shipped undetected because nothing runs or tests the audit script itself; any future edits to v1-audit.sh carry the same risk of silent breakage." [[should]] id = "S2" text = "The audit script SHOULD attempt to detect fake or placeholder test/benchmark evidence (e.g. black_box(42), 'not configured yet', copied templates) in tests/benches directories." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_fake_evidence() (PLACEHOLDER_EVIDENCE_PATTERN)" +system = "release-pre-flight/v1-audit.sh check_fake_evidence() (PLACEHOLDER_EVIDENCE_PATTERN)" status = "pass" evidence = "Running the script printed 'PASS: no obvious fake test or benchmark evidence found' and 'PASS: no placeholder fuzz/bench artifact files found' for the monorepo root, exercising the check_fake_evidence() function successfully (it ran without error and returned a clean result)." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'PASS: no obvious fake test or benchmark evidence found'" @@ -71,7 +70,7 @@ effects = "Without this, a repo could pad coverage numbers with trivial/copied s [[should]] id = "S3" text = "The audit script SHOULD surface (not gate) explicit stable/high-assurance claims found in README/CHANGELOG/ROADMAP/docs so a human reviewer can cross-check claim-vs-artifact parity (gate 3.7)." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_stable_claims()" +system = "release-pre-flight/v1-audit.sh check_stable_claims()" status = "pass" evidence = "Running the script surfaced real matches such as 2-protocols/axel/ROADMAP.adoc:15 'v1.0.0 - Stable Release', .machine_readable/contractiles/trust/Trustfile.a2ml:395 'ALPHA -- NOT production-ready', confirming the informational scan works end-to-end." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: stable or high-assurance claims detected'" @@ -80,9 +79,9 @@ effects = "Reviewers doing the manual claim-parity judgement (gate 3.7) lose the [[should]] id = "S4" text = "The audit script SHOULD cross-check any STATE.a2ml release-stage metadata against the audit's own findings so stage/maturity claims are not divorced from the actual audit outcome." -system = "/home/user/standards/release-pre-flight/v1-audit.sh check_state_release_stage()" +system = "release-pre-flight/v1-audit.sh check_state_release_stage()" status = "pass" -evidence = "Running the script found /home/user/standards/.machine_readable/6a2/STATE.a2ml and printed 'maturity = \"experimental\"', confirming the discovery/print logic executes correctly (though it is informational only, not a correlation/gate)." +evidence = "Running the script found .machine_readable/6a2/STATE.a2ml and printed 'maturity = \"experimental\"', confirming the discovery/print logic executes correctly (though it is informational only, not a correlation/gate)." check = "bash 3-practice/release-pre-flight/v1-audit.sh . 2>&1 | grep -q 'INFO: STATE metadata found'" effects = "Without even this informational cross-reference, a repo's maturity metadata could drift from what the audit actually found with no automated flag." diff --git a/.machine_readable/scorecards/rhodium-standard-repositories.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/rhodium-standard-repositories.scorecard.a2ml similarity index 95% rename from .machine_readable/scorecards/rhodium-standard-repositories.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/rhodium-standard-repositories.scorecard.a2ml index eb3110bf7..f93be3ed2 100644 --- a/.machine_readable/scorecards/rhodium-standard-repositories.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/rhodium-standard-repositories.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # rhodium-standard-repositories.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "rhodium-standard-repositories" diff --git a/.machine_readable/scorecards/scorecard.schema.json b/.machine_readable/archive/scorecards-v1/scorecard.schema.json similarity index 100% rename from .machine_readable/scorecards/scorecard.schema.json rename to .machine_readable/archive/scorecards-v1/scorecard.schema.json diff --git a/.machine_readable/scorecards/session-management-standards.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/session-management-standards.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/session-management-standards.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/session-management-standards.scorecard.a2ml index 1c1c4b24c..719aac776 100644 --- a/.machine_readable/scorecards/session-management-standards.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/session-management-standards.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # session-management-standards.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "session-management-standards" diff --git a/.machine_readable/scorecards/state-a2ml.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/state-a2ml.scorecard.a2ml similarity index 98% rename from .machine_readable/scorecards/state-a2ml.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/state-a2ml.scorecard.a2ml index 7f556e314..288e22215 100644 --- a/.machine_readable/scorecards/state-a2ml.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/state-a2ml.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # state-a2ml.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "state-a2ml" diff --git a/.machine_readable/scorecards/toolchain-readiness-grades.scorecard.a2ml b/.machine_readable/archive/scorecards-v1/toolchain-readiness-grades.scorecard.a2ml similarity index 88% rename from .machine_readable/scorecards/toolchain-readiness-grades.scorecard.a2ml rename to .machine_readable/archive/scorecards-v1/toolchain-readiness-grades.scorecard.a2ml index 94098f552..83c9b19be 100644 --- a/.machine_readable/scorecards/toolchain-readiness-grades.scorecard.a2ml +++ b/.machine_readable/archive/scorecards-v1/toolchain-readiness-grades.scorecard.a2ml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: CC-BY-SA-4.0 # toolchain-readiness-grades.scorecard.a2ml -# Hand-authored source. Regenerate the dashboard with: just scorecards -# Schema: .machine_readable/scorecards/scorecard.schema.json +# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json [scorecard] spec_id = "toolchain-readiness-grades" @@ -14,7 +13,7 @@ id = "M1" text = "The TRG spec MUST exist as a normative AsciiDoc document with a companion machine-readable A2ML counterpart." system = "none (manual file presence check only)" status = "pass" -evidence = "/home/user/standards/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc (~40KB, present) and /home/user/standards/toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.a2ml (present, well-formed s-expression grade/tier definitions verified by inspection)" +evidence = "toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc (~40KB, present) and toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.a2ml (present, well-formed s-expression grade/tier definitions verified by inspection)" check = "test -f toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.adoc && test -f toolchain-readiness-grades/TOOLCHAIN-READINESS-GRADES.a2ml" effects = "Downstream toolchain repos (007, ephapax, AffineScript, my-lang, etc.) have no baseline rubric to point their own TRG-PROFILE.adoc at." @@ -35,7 +34,7 @@ effects = "Consumers evaluating a toolchain repo (e.g. 007) cannot mechanically [[must]] id = "M4" text = "The standard MUST grade itself honestly via a SELF-ASSESSMENT.adoc, re-run after any change to the directory, using the invariant-path doc-claims grounder to validate file-path claims." -system = "none found in this repo — no invariant-path / doc-claims-grounder script or CI job exists under /home/user/standards (searched .github/workflows and repo tree); the self-assessment refers to a prior manual run whose output is quoted but not reproducible from any script present here" +system = "none found in this repo — no invariant-path / doc-claims-grounder script or CI job exists under the repository root (searched .github/workflows and repo tree); the self-assessment refers to a prior manual run whose output is quoted but not reproducible from any script present here" status = "fail" effects = "The self-assessment's claim of '519 grounded / 2597 ungrounded / 1 unknown / 3117 total' (SELF-ASSESSMENT.adoc line 129) cannot be independently re-verified by any automated system in this repo, so the honesty of the self-grade rests entirely on unverifiable prose." @@ -51,7 +50,7 @@ id = "S1" text = "The five canonical templates referenced from the spec (AUDIT-TEMPLATE, CANONICAL-PROOF-SUITE, QUALIFYING-PROVERS, FUZZING-CORPUS-FLOOR, A-GRADE-LLM-PANEL) SHOULD all exist and be internally consistent with the spec's references to them." system = "none (manual cross-reference check)" status = "pass" -evidence = "All five templates present under /home/user/standards/toolchain-readiness-grades/templates/: AUDIT-TEMPLATE.adoc, CANONICAL-PROOF-SUITE.adoc, QUALIFYING-PROVERS.adoc, FUZZING-CORPUS-FLOOR.adoc, A-GRADE-LLM-PANEL.adoc (plus an additional TRG-PROFILE-TEMPLATE.adoc not mentioned in the README's file table)" +evidence = "All five templates present under toolchain-readiness-grades/templates/: AUDIT-TEMPLATE.adoc, CANONICAL-PROOF-SUITE.adoc, QUALIFYING-PROVERS.adoc, FUZZING-CORPUS-FLOOR.adoc, A-GRADE-LLM-PANEL.adoc (plus an additional TRG-PROFILE-TEMPLATE.adoc not mentioned in the README's file table)" check = "test -f toolchain-readiness-grades/templates/AUDIT-TEMPLATE.adoc && test -f toolchain-readiness-grades/templates/CANONICAL-PROOF-SUITE.adoc && test -f toolchain-readiness-grades/templates/QUALIFYING-PROVERS.adoc && test -f toolchain-readiness-grades/templates/FUZZING-CORPUS-FLOOR.adoc && test -f toolchain-readiness-grades/templates/A-GRADE-LLM-PANEL.adoc" effects = "Adopting repos writing audits or per-language TRG-PROFILE.adoc files have concrete templates to copy; if these went missing, every audit author would have to invent the format from scratch." diff --git a/1-formats/deed/mappings/scorecard-corpus-decision.adoc b/1-formats/deed/mappings/scorecard-corpus-decision.adoc index 0060e7af0..eb3e78eef 100644 --- a/1-formats/deed/mappings/scorecard-corpus-decision.adoc +++ b/1-formats/deed/mappings/scorecard-corpus-decision.adoc @@ -1,8 +1,9 @@ // SPDX-License-Identifier: CC-BY-SA-4.0 = Decision spec — `*.scorecard.a2ml` corpus (70+) → deed era (family 5) Campaign: standards#837 · Frame: link:README.adoc[mappings/README] · -Status: **DECISION REQUIRED (owner)** — plus one remediation that needs -no ruling (the absolute-path leak, §4) +Status: **RULED: option B** (owner, 2026-10-09, ruling R5 on standards#837). +Increment 1 (§4 leak clean + archive) is done; increments 2 and 3 are +pending. See §5. Scorecards are the wrong shape for the naïve "translate each file" move: they are **time-stamped assessment records**, not repo state. Translating @@ -73,3 +74,27 @@ first day. Deliverable list of offending lines rides in the owner-side residue ledger rather than being silently edited in a translation PR. (Per closeout discipline: listed, evidence-attached, owner-visible — not swept.) + +== 5. Ruling and increments + +The owner ruled **B**, with the §4 leak clean first (2026-10-09). The +corpus in this repository measured *29* files at the time of the ruling, +not the 70+ estimated in the title. The work lands in three increments: + +. *Done.* The §4 leak clean (47 lines, 50 occurrences) and the move to + link:../../../.machine_readable/archive/scorecards-v1/README.adoc[`.machine_readable/archive/scorecards-v1/`], + with a directory tombstone. Acceptance item 1 (§3) holds: no + `*.scorecard.a2ml` remains outside the archive. The file:line list of + cleaned lines is in the pull request that made the move, not in + `.machine_readable/estate-residue-ledger.tsv`: that ledger is generated by + `scripts/spine/board.awk`, so a hand-added row would not survive the next + regeneration. +. *Pending.* One `(assessment …)` clause per `spec_id` (§2 B.2), with the + counts computed from the archived records. This needs a chora deed for + this repository, which does not exist yet. Acceptance item 2 waits on it. +. *Pending.* estate-audit emits future assessments as deed clauses (§2 B.3). + +Acceptance item 3 will be met by the directory tombstone, not by editing each +archived file: adding a forward link inside a frozen `.a2ml` record would +add content to a retired format. Increment 2 adds the forward link to the +tombstone when the deed exists. diff --git a/1-formats/k9/spec/MIGRATION-1058.adoc b/1-formats/k9/spec/MIGRATION-1058.adoc index ffde6a693..4b461f687 100644 --- a/1-formats/k9/spec/MIGRATION-1058.adoc +++ b/1-formats/k9/spec/MIGRATION-1058.adoc @@ -219,7 +219,7 @@ of them closes again. These are YAML stubs for a session-management protocol. They are neither K9 SVC (no Nickel body) nor `k9-coordination` (no `K9!` magic, and a different schema -again). `.machine_readable/scorecards/session-management-standards.scorecard.a2ml` +again). `.machine_readable/archive/scorecards-v1/session-management-standards.scorecard.a2ml` already flags the collision in its own words: *".k9 files that don't follow the actual K9 grammar could confuse tooling or reviewers who expect the k9-svc schema."* diff --git a/REGISTRY.adoc b/REGISTRY.adoc index 745d5617c..749e9f613 100644 --- a/REGISTRY.adoc +++ b/REGISTRY.adoc @@ -85,10 +85,12 @@ https://github.com/hyperpolymath/standards/tree/6d19ce0ebae047027dcfd594c7810bf3 link:0-canon/COMPLIANCE-DASHBOARD.adoc[`0-canon/COMPLIANCE-DASHBOARD.adoc`] are kept as *frozen snapshots* of their last generation. Nothing regenerates them. Read them as history, not as current state. -* The per-spec scorecards under `.machine_readable/scorecards/` are not - touched by this retirement. Their fate is ruling R5 on - https://github.com/hyperpolymath/standards/issues/837[#837] (the mapping is - in https://github.com/hyperpolymath/standards/pull/845[#845]). +* The per-spec scorecards are archived, frozen, at + link:.machine_readable/archive/scorecards-v1/README.adoc[`.machine_readable/archive/scorecards-v1/`] + (ruling R5 on + https://github.com/hyperpolymath/standards/issues/837[#837], option B, + 2026-10-09; the mapping is in + link:1-formats/deed/mappings/scorecard-corpus-decision.adoc[`scorecard-corpus-decision.adoc`]). == What replaces it diff --git a/docs/BADGE-CRITERIA-SPEC.adoc b/docs/BADGE-CRITERIA-SPEC.adoc index a95389c4a..bfb4c188b 100644 --- a/docs/BADGE-CRITERIA-SPEC.adoc +++ b/docs/BADGE-CRITERIA-SPEC.adoc @@ -652,7 +652,7 @@ field a citation rests on is renamed away -- so the review verified cited | Citation rests on | Location | Verified 2026-09-04 | Honesty rules H1, H2, H4, H5, H11 -| `.machine_readable/scorecards/scorecard.schema.json` +| `.machine_readable/archive/scorecards-v1/scorecard.schema.json` | Fields `evidence`, `check`, `aspirational`, `system` all still present | Honesty rule H12 diff --git a/scripts/check-canonical-names.sh b/scripts/check-canonical-names.sh index 4b2f0ec17..ec032f372 100755 --- a/scripts/check-canonical-names.sh +++ b/scripts/check-canonical-names.sh @@ -27,11 +27,14 @@ fi declare -A REPL=( ["6a2"]="descriptiles" ["agent_instructions"]="bot_directives" ) # Files that legitimately NAME the deprecated tokens (the mandate itself, this -# guard, migration/charter docs). Excluded from the check. +# guard, migration/charter docs, and frozen archives whose records cite the +# paths of their day). Excluded from the check. The scorecard archive is +# excluded record by record (ruling R5, #837): its README is still checked. is_excluded() { case "$1" in 0-canon/CANONICAL-NAMES.adoc|scripts/check-canonical-names.sh|scripts/tests/*|\ *MIGRATION*|*migration*|*CHANGELOG*|\ + .machine_readable/archive/scorecards-v1/*.scorecard.a2ml|\ standards-update/.machine_readable/6scm-archive/.machine_readable/6a2/*) return 0 ;; esac return 1 diff --git a/scripts/tests/validate-bot-directives-test.sh b/scripts/tests/validate-bot-directives-test.sh index d2d76b552..1ad233a68 100755 --- a/scripts/tests/validate-bot-directives-test.sh +++ b/scripts/tests/validate-bot-directives-test.sh @@ -36,5 +36,33 @@ ck "nested .machine_readable .a2ml directive fails" 1 sub/.machine_readab ck "clean directive file passes" 0 .machine_readable/bot_directives/ok.deed ck "mixed set fails on the directive file alone" 1 docs/README.adoc .machine_readable/bot_directives/legacy.deed +# The frozen scorecard archive (ruling R5, #837): its records name the tools +# of their day and are skipped; its README and a sibling archive are not +# (planted positives, so a skip of the whole archive tree would be caught). +A=".machine_readable/archive/scorecards-v1" +mkdir -p "$T/$A" "$T/.machine_readable/archive/scorecards-v2" +printf 'evidence = "Codex"\n' > "$T/$A/k.scorecard.a2ml" +printf 'Codex\n' > "$T/$A/README.adoc" +printf 'evidence = "Codex"\n' > "$T/.machine_readable/archive/scorecards-v2/k.scorecard.a2ml" +ck "archived scorecard record naming Codex passes" 0 "$A/k.scorecard.a2ml" +ck "archive README is still checked" 1 "$A/README.adoc" +ck "sibling archive is still checked" 1 .machine_readable/archive/scorecards-v2/k.scorecard.a2ml + +# cks NAME EXPECTED_EXIT DIR — run the hook in scan mode (no staged list) over +# DIR and compare its exit code with EXPECTED_EXIT. +cks() { + local name="$1" want="$2" dir="$3" out rc + out="$(INPUT_PATH="$dir" INPUT_STAGED_FILES="" bash "$HOOK" 2>&1)"; rc=$? + if [ "$rc" = "$want" ]; then printf ' ok %s (exit %s)\n' "$name" "$rc"; pass=$((pass+1)) + else printf ' FAIL %s (expected exit %s, got %s) output=%s\n' "$name" "$want" "$rc" "${out:-}"; fail=$((fail+1)); fi +} + +S="$T/scan" +mkdir -p "$S/$A" +printf 'evidence = "Codex"\n' > "$S/$A/k.scorecard.a2ml" +cks "scan: archived scorecard record passes" 0 "$S" +printf '(bot codex)\n' > "$S/.machine_readable/live.deed" +cks "scan: live directive beside the archive still fails" 1 "$S" + printf '%s passed, %s failed\n' "$pass" "$fail" [ "$fail" -eq 0 ] && [ "$pass" -gt 0 ] diff --git a/scripts/tests/wave6-canonical-names-test.sh b/scripts/tests/wave6-canonical-names-test.sh index 64aae9167..c49149dac 100755 --- a/scripts/tests/wave6-canonical-names-test.sh +++ b/scripts/tests/wave6-canonical-names-test.sh @@ -52,6 +52,31 @@ git add "$f" 2>/dev/null bash "$CHK" HEAD >/dev/null 2>&1 && ok "canonical names pass" || bad "canonical names wrongly blocked" git reset -q "$f" 2>/dev/null; rm -f "$f" +echo "== the frozen scorecard archive is excluded record by record ==" +# The real move: a record is renamed into the archive AND one line of it is +# edited, so the diff carries a rename with a '+' line under the new path. +old=".machine_readable/scorecards/probe.scorecard.a2ml" +arc=".machine_readable/archive/scorecards-v1" +mkdir -p "$(dirname "$old")" "$arc" +printf '[scorecard]\nspec_id = "probe"\nversion = "0.1.0"\nassessor = "estate-audit"\nevidence = "x"\n' > "$old" +git add "$old" && git commit -qm "scorecard fixture" +git mv "$old" "$arc/probe.scorecard.a2ml" +sed -i 's#^evidence = "x"$#evidence = ".machine_readable/6a2/STATE.a2ml"#' "$arc/probe.scorecard.a2ml" +git add "$arc/probe.scorecard.a2ml" +if bash "$CHK" HEAD >/dev/null 2>&1; then ok "archived scorecard record (moved + edited) excluded"; else bad "archived scorecard record wrongly blocked"; fi +# Planted positives: the exclusion must not reach the archive's README or a +# sibling archive. Without these, an exclusion of the whole tree would pass. +printf 'see .machine_readable/6a2/STATE.a2ml\n' > "$arc/README.adoc" +git add "$arc/README.adoc" +if bash "$CHK" HEAD >/dev/null 2>&1; then bad "archive README escaped the guard"; else ok "archive README still guarded"; fi +git rm -q --cached "$arc/README.adoc"; rm -f "$arc/README.adoc" +sib=".machine_readable/archive/scorecards-v2" +mkdir -p "$sib" +printf 'evidence = ".machine_readable/6a2/STATE.a2ml"\n' > "$sib/probe.scorecard.a2ml" +git add "$sib/probe.scorecard.a2ml" +if bash "$CHK" HEAD >/dev/null 2>&1; then bad "sibling archive escaped the guard"; else ok "sibling archive still guarded"; fi +git rm -q --cached "$sib/probe.scorecard.a2ml"; rm -rf "$sib" + echo "== the guard excludes 0-canon/CANONICAL-NAMES.adoc itself ==" grep -q '0-canon/CANONICAL-NAMES.adoc' "$CHK" && ok "mandate doc is excluded from the guard" || bad "mandate doc not excluded"