Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 8 additions & 1 deletion .githooks/validate-bot-directives.sh
Original file line number Diff line number Diff line change
Expand Up @@ -21,9 +21,15 @@
# the same population scan mode checks below. Without this fence the grep ran
# over every staged prose file, so any README naming the AI tool "Codex"
# could not be committed (owner ruling D316).
# Records in the frozen scorecard archive (ruling R5, #837) are skipped in
# both modes: they are assessments that name the tools of their day, not live
# directives. Only the records are skipped; nothing else under the archive is.
if [ -n "$STAGED_FILES" ]; then
while IFS=$'\n' read -r file; do
[ -z "$file" ] && continue
case "$file" in

Check failure on line 30 in .githooks/validate-bot-directives.sh

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Add a default case (*) to handle unexpected values.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaEf-WMVw1j80ZetBptL&open=AaEf-WMVw1j80ZetBptL&pullRequest=1216
.machine_readable/archive/scorecards-v1/*.scorecard.a2ml) continue ;;
esac
case "$file" in
.machine_readable/*|*/.machine_readable/*) ;;
*) continue ;;
Expand All @@ -42,7 +48,8 @@
if [ -d "$MACHINE_READABLE" ]; then
while IFS= read -r file; do
validate_file "$file"
done < <(find "$MACHINE_READABLE" -type f \( -name '*.a2ml' -o -name '*.deed' -o -name '*.md' -o -name '*.txt' \) 2>/dev/null || true)
done < <(find "$MACHINE_READABLE" -type f \( -name '*.a2ml' -o -name '*.deed' -o -name '*.md' -o -name '*.txt' \) \
! -path "$MACHINE_READABLE/archive/scorecards-v1/*.scorecard.a2ml" 2>/dev/null || true)
fi
fi

Expand Down
2 changes: 1 addition & 1 deletion .hypatia-baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -774,7 +774,7 @@
"severity": "medium",
"rule_module": "structural_drift",
"type": "SD022",
"file": ".machine_readable/scorecards/hypatia-rules.scorecard.a2ml",
"file": ".machine_readable/archive/scorecards-v1/hypatia-rules.scorecard.a2ml",
"note": "TEMPORARY REVIEW BASELINE (2026-08-29): classify whether the src/A2ML path is target-relative example content or stale repository-local documentation.",
"expires_at": "2026-11-29",
"tracking_issue": "hyperpolymath/standards#687"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
# SPDX-License-Identifier: CC-BY-SA-4.0
# 0-ai-gatekeeper-protocol.scorecard.a2ml
# Hand-authored source. Regenerate the dashboard with: just scorecards
# Schema: .machine_readable/scorecards/scorecard.schema.json
# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json

[scorecard]
spec_id = "0-ai-gatekeeper-protocol"
Expand All @@ -23,7 +22,7 @@ id = "M2"
text = "The manifest MUST contain all required sections defined by AI-MANIFEST-SPEC.adoc §Required Sections (Warning Header, What Is This, Canonical Locations, Core Invariants, Repository Structure, Attestation Proof)."
system = "none (no parser/linter script in this repo enforces the spec against 0-AI-MANIFEST.a2ml; mcp-repo-guardian's manifest_test.js only tests inline reimplementations of parsing logic, not a repo-facing validator CLI)"
status = "pass"
evidence = "Manual read of /home/user/standards/0-ai-gatekeeper-protocol/0-AI-MANIFEST.a2ml confirms presence of '# ⚠️ STOP', '## WHAT IS THIS?', '## CANONICAL LOCATIONS', '## CORE INVARIANTS', '## REPOSITORY STRUCTURE', and '## ATTESTATION PROOF' headings."
evidence = "Manual read of 0-ai-gatekeeper-protocol/0-AI-MANIFEST.a2ml confirms presence of '# ⚠️ STOP', '## WHAT IS THIS?', '## CANONICAL LOCATIONS', '## CORE INVARIANTS', '## REPOSITORY STRUCTURE', and '## ATTESTATION PROOF' headings."
check = "grep -q '# ⚠️ STOP' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## WHAT IS THIS?' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## CANONICAL LOCATIONS' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## CORE INVARIANTS' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## REPOSITORY STRUCTURE' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml && grep -q '## ATTESTATION PROOF' 2-protocols/0-ai-gatekeeper/0-AI-MANIFEST.a2ml"
effects = "Missing sections would leave AI agents without required guardrail information, defeating the protocol's stated purpose across all adopting repos."

Expand All @@ -33,22 +32,22 @@ text = "The repository's own machine-readable state MUST accurately reflect this
system = "none"
status = "fail"
check = "true"
effects = "/home/user/standards/0-ai-gatekeeper-protocol/.machine_readable/6a2/STATE.a2ml declares project = \"rsr-template-repo\" (name = \"Rsr Template Repo\", completion-percentage = 5, generic scaffolding actions like 'Define project scope and objectives'), i.e. it is an un-edited template copy, not this repo's actual state — directly violating the protocol's own 'no stale metadata' invariant it asks every other repo to uphold. Any agent trusting STATE.a2ml for context (as the manifest's own Session Startup Checklist instructs) would be misled about project identity/status, undermining the protocol's core value proposition."
effects = "0-ai-gatekeeper-protocol/.machine_readable/6a2/STATE.a2ml declares project = \"rsr-template-repo\" (name = \"Rsr Template Repo\", completion-percentage = 5, generic scaffolding actions like 'Define project scope and objectives'), i.e. it is an un-edited template copy, not this repo's actual state — directly violating the protocol's own 'no stale metadata' invariant it asks every other repo to uphold. Any agent trusting STATE.a2ml for context (as the manifest's own Session Startup Checklist instructs) would be misled about project identity/status, undermining the protocol's core value proposition."

[[must]]
id = "M4"
text = "Core manifest-parsing/session/guard logic (as implemented for FFI/offline consumption) MUST have an automated test suite that passes."
system = "none in this repo — repo-guardian-fs moved to hyperpolymath/repo-guardian per standards#492 (2026-08-28). Previously verified by: cargo test --manifest-path repo-guardian-fs/tests-offline/Cargo.toml (Rust unit tests for manifest parsing, session management, and path-guard invariant enforcement)."
status = "manual-only"
evidence = "Ran `cargo test` in /home/user/standards/0-ai-gatekeeper-protocol/repo-guardian-fs/tests-offline: 29 passed; 0 failed (manifest hashing, canonical-location extraction, invariant detection, session ack/expiry, path-traversal/SCM-duplication guard tests, and a dogfood test parsing the repo's real 0-AI-MANIFEST.a2ml)."
evidence = "Ran `cargo test` in 0-ai-gatekeeper-protocol/repo-guardian-fs/tests-offline: 29 passed; 0 failed (manifest hashing, canonical-location extraction, invariant detection, session ack/expiry, path-traversal/SCM-duplication guard tests, and a dogfood test parsing the repo's real 0-AI-MANIFEST.a2ml)."
effects = "If these regress, any FFI/native consumer (e.g. Zig bindings, future editor plugins) linking against this logic would silently mis-enforce or fail to enforce invariants."

[[must]]
id = "M5"
text = "The repo-guardian-fs FUSE enforcement component MUST build/compile so the 'OS-level enforcement for ANY tool/agent' claim in README.adoc is actually deliverable."
system = "cargo build (in repo-guardian-fs/, main crate, not tests-offline)"
status = "fail"
effects = "`cargo build` in /home/user/standards/0-ai-gatekeeper-protocol/repo-guardian-fs fails with 58+ compile errors in the fuse3 v0.7.3 dependency (missing Future::poll impl, type-inference errors) on the installed Rust toolchain — exactly the known incompatibility documented in tests-offline/Cargo.toml's own comment ('fuse3 v0.7.3 fails to compile on Rust stable >= 1.80'). The FUSE wrapper, one of the protocol's three enforcement mechanisms advertised in README.adoc §Components, is currently non-functional for any real mount/enforcement use, affecting every non-MCP AI agent (Gemini, Copilot, ChatGPT) that the README says relies on it."
effects = "`cargo build` in 0-ai-gatekeeper-protocol/repo-guardian-fs fails with 58+ compile errors in the fuse3 v0.7.3 dependency (missing Future::poll impl, type-inference errors) on the installed Rust toolchain — exactly the known incompatibility documented in tests-offline/Cargo.toml's own comment ('fuse3 v0.7.3 fails to compile on Rust stable >= 1.80'). The FUSE wrapper, one of the protocol's three enforcement mechanisms advertised in README.adoc §Components, is currently non-functional for any real mount/enforcement use, affecting every non-MCP AI agent (Gemini, Copilot, ChatGPT) that the README says relies on it."

[[should]]
id = "S1"
Expand All @@ -62,7 +61,7 @@ id = "S2"
text = "CONTRIBUTING.md SHOULD accurately describe the actual build/test workflow for this specific repository."
system = "none"
status = "fail"
effects = "/home/user/standards/0-ai-gatekeeper-protocol/CONTRIBUTING.md instructs contributors to run `just test` and references `spec/` and `tests/` directories (Perimeter 2-3 language from a generic template), but no Justfile exists anywhere under 2-protocols/0-ai-gatekeeper/ and there is no spec/ or top-level tests/ directory (real tests live in repo-guardian-fs/tests-offline/ and mcp-repo-guardian/test/). New contributors following CONTRIBUTING.md literally would hit an immediate 'command not found' and be unable to run any tests."
effects = "0-ai-gatekeeper-protocol/CONTRIBUTING.md instructs contributors to run `just test` and references `spec/` and `tests/` directories (Perimeter 2-3 language from a generic template), but no Justfile exists anywhere under 2-protocols/0-ai-gatekeeper/ and there is no spec/ or top-level tests/ directory (real tests live in repo-guardian-fs/tests-offline/ and mcp-repo-guardian/test/). New contributors following CONTRIBUTING.md literally would hit an immediate 'command not found' and be unable to run any tests."

[[should]]
id = "S3"
Expand Down
66 changes: 66 additions & 0 deletions .machine_readable/archive/scorecards-v1/README.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
= Spec scorecards, v1 — Archived 2026-10-09
:icons: font

[IMPORTANT]
====
This directory is a *frozen archive*. Nothing in this repository generates,
reads, checks or extends these files. Do not edit them, do not add new
`*.scorecard.a2ml` files, and do not convert them by hand: A2ML is retired
(owner rulings D99, D269c, D312 and D313).
====

== What this is

The 29 per-spec assessment records that used to live at
`.machine_readable/scorecards/`, one per `spec_id`, plus the
`scorecard.schema.json` they were written against. Each record is a
time-stamped MUST/SHOULD/COULD assessment of one specification in this
repository, not a description of current state. Read them as history.

== Why it was archived

Ruling R5 on https://github.com/hyperpolymath/standards/issues/837[#837]
chose option B (owner, 2026-10-09): freeze the corpus as an archive rather
than translate each file. The reasoning and the alternatives are in
link:../../../1-formats/deed/mappings/scorecard-corpus-decision.adoc[`scorecard-corpus-decision.adoc`].

The executor that ran each record's `check` commands
(`scripts/build-scorecards.sh --verify`) was retired with the spec registry
on 2026-10-09; see link:../../../REGISTRY.adoc[`REGISTRY.adoc`]. The `check`
fields here are therefore not run by anything.

== What changed on the way in

The records are otherwise byte-for-byte as they were. Three mechanical
edits were made before the move, so that the archive is clean from its
first day:

* *Absolute local paths removed.* 47 lines (25 `evidence`, 12 `system`,
10 `effects`) carried a machine-local absolute path to a workstation
checkout. Each was rewritten
to the repository-relative path it pointed at. The pull request that made
the move lists every affected file and line.
* *Generator header dropped.* Each file named a `just` recipe that
regenerated a dashboard from it. That recipe no longer exists.
* *Schema comment repointed.* The `# Schema:` line now names this
directory. The schema's own `$id` is unchanged: it is the historical
identifier of the v1 format, not a location.

== What replaces it

* *Summaries of these assessments* are to become one aggregate
`(assessment …)` clause per `spec_id` on the assessed repository's chora
deed (grammar:
link:../../../1-formats/deed/spec/abnf/deed.abnf[`deed.abnf`]). This
repository has no chora deed yet, so those clauses are *pending*; nothing
here links forward to them until they exist.
* *New assessments* are to be emitted by estate-audit, not written by hand.

== Not to be confused with

* The per-repository scorecards that the RSR oracle writes to verisim-data
(see `0-canon/rsr/RSR-SPEC-v2.adoc`): a different corpus, in a different
repository.
* The OpenSSF Scorecard workflow (`scorecard-reusable.yml`): a supply-chain
scanner, unrelated to these files.
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
# SPDX-License-Identifier: CC-BY-SA-4.0
# a2ml-templates.scorecard.a2ml
# Hand-authored source. Regenerate the dashboard with: just scorecards
# Schema: .machine_readable/scorecards/scorecard.schema.json
# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json

[scorecard]
spec_id = "a2ml-templates"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
# SPDX-License-Identifier: CC-BY-SA-4.0
# accessibility.scorecard.a2ml
# Hand-authored source. Regenerate the dashboard with: just scorecards
# Schema: .machine_readable/scorecards/scorecard.schema.json
# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json

[scorecard]
spec_id = "accessibility"
Expand All @@ -14,7 +13,7 @@ id = "M1"
text = "The spec MUST provide a machine-readable Adjustfile.a2ml contract at .machine_readable/contractiles/adjust/Adjustfile.a2ml to satisfy Level A minimum viability."
system = "probe: test -f .machine_readable/contractiles/adjust/Adjustfile.a2ml (as literally defined in STANDARD.a2ml Level A section)"
status = "pass"
evidence = "/home/user/standards/.machine_readable/contractiles/adjust/Adjustfile.a2ml exists on disk (along with sibling adjust.manifest.a2ml, adjust.ncl, adjust.k9.ncl in the same directory)."
evidence = ".machine_readable/contractiles/adjust/Adjustfile.a2ml exists on disk (along with sibling adjust.manifest.a2ml, adjust.ncl, adjust.k9.ncl in the same directory)."
check = "test -f .machine_readable/contractiles/adjust/Adjustfile.a2ml"
effects = "Downstream projects copying this standard rely on this file as the canonical contractile template; if missing, their own Level-A probe fails."

Expand All @@ -30,7 +29,7 @@ id = "M3"
text = "Projects MUST provide accessibility documentation (docs/accessibility/README.adoc) per Level A 'documentation' requirement."
system = "probe: test -f docs/accessibility/README.adoc"
status = "pass"
evidence = "/home/user/standards/docs/accessibility/README.adoc exists and documents keyboard, screen-reader, and roadmap sections (though it is written as a template for a hypothetical 'Burble' project, not the standards repo itself)"
evidence = "docs/accessibility/README.adoc exists and documents keyboard, screen-reader, and roadmap sections (though it is written as a template for a hypothetical 'Burble' project, not the standards repo itself)"
check = "test -f docs/accessibility/README.adoc"
effects = "If absent, any project claiming HAS Level A compliance has no discoverable documentation trail, undermining auditability."

Expand All @@ -53,14 +52,14 @@ id = "S1"
text = "User-facing projects SHOULD achieve WCAG 2.1 AA compliance by Q4 2026, including automated accessibility testing (pa11y/axe-core) wired into CI."
system = "probe: grep -r \"pa11y\\|axe\\|accessibility\" .github/workflows/ — checked repo-wide"
status = "fail"
effects = "No CI job anywhere in /home/user/standards/.github/workflows references pa11y, axe, or accessibility; automated AA verification is entirely absent, so the Q4 2026 target has no tooling in place yet."
effects = "No CI job anywhere in .github/workflows references pa11y, axe, or accessibility; automated AA verification is entirely absent, so the Q4 2026 target has no tooling in place yet."

[[should]]
id = "S2"
text = "Projects SHOULD publish a VPAT 2.4-format compliance report at docs/compliance/ACCESSIBILITY.adoc."
system = "probe: test -f docs/compliance/ACCESSIBILITY.adoc"
status = "fail"
effects = "The file at /home/user/standards/docs/compliance/ACCESSIBILITY.adoc exists but is an unrendered template — it contains literal unexpanded shell expressions ($(basename \"$repo\"), $(date '+%Y-%m-%d')) rather than actual filled-in product/version/date fields, so it does not constitute a genuine completed VPAT for any real project; treating the probe's file-existence check as satisfied would overstate actual compliance."
effects = "The file at docs/compliance/ACCESSIBILITY.adoc exists but is an unrendered template — it contains literal unexpanded shell expressions ($(basename \"$repo\"), $(date '+%Y-%m-%d')) rather than actual filled-in product/version/date fields, so it does not constitute a genuine completed VPAT for any real project; treating the probe's file-existence check as satisfied would overstate actual compliance."

[[should]]
id = "S3"
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
# SPDX-License-Identifier: CC-BY-SA-4.0
# adoption-readiness-grades.scorecard.a2ml
# Hand-authored source. Regenerate the dashboard with: just scorecards
# Schema: .machine_readable/scorecards/scorecard.schema.json
# Schema: .machine_readable/archive/scorecards-v1/scorecard.schema.json

[scorecard]
spec_id = "adoption-readiness-grades"
Expand All @@ -14,7 +13,7 @@ id = "M1"
text = "The ARG normative spec MUST exist as an AsciiDoc document with SPDX headers."
system = "none (manual inspection)"
status = "pass"
evidence = "/home/user/standards/adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc (507 lines, 12 sections + revision history), SPDX-License-Identifier: CC-BY-SA-4.0 header present at line 1."
evidence = "adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc (507 lines, 12 sections + revision history), SPDX-License-Identifier: CC-BY-SA-4.0 header present at line 1."
check = "test -f adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc && head -1 adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc | grep -q 'SPDX-License-Identifier' && grep -q '^== ' adoption-readiness-grades/ADOPTION-READINESS-GRADES.adoc"
effects = "If absent, no downstream language repo has a normative baseline to cite in spec/ARG-PROFILE.adoc; per-language profiles would have nothing to tighten against."

Expand Down Expand Up @@ -72,7 +71,7 @@ id = "S4"
text = "A machine-readable counterpart of the normative spec (.a2ml) SHOULD exist and stay consistent with the .adoc."
system = "none - no script cross-validates ADOPTION-READINESS-GRADES.a2ml against ADOPTION-READINESS-GRADES.adoc for consistency; consistency is asserted only in SELF-ASSESSMENT.adoc's manually-ticked checklist"
status = "pass"
evidence = "/home/user/standards/adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml exists (339 lines, SPDX-License-Identifier: MPL-2.0), referenced consistently in README.adoc and SELF-ASSESSMENT.adoc as the machine-readable counterpart."
evidence = "adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml exists (339 lines, SPDX-License-Identifier: MPL-2.0), referenced consistently in README.adoc and SELF-ASSESSMENT.adoc as the machine-readable counterpart."
check = "test -f adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml && [ \"$(wc -l < adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml)\" -eq 339 ] && grep -q 'MPL-2.0' adoption-readiness-grades/ADOPTION-READINESS-GRADES.a2ml"
effects = "If it drifted from the prose spec unnoticed, any tool consuming the a2ml form would diverge from the documented normative rules; currently no automated guard against that drift."

Expand Down
Loading
Loading