Skip to content

fix(k9-hook): exempt the 9-archive district from validation and the debt ledger - #1218

Merged
hyperpolymath merged 7 commits into
mainfrom
arena/2ae9b9a8-standards
Oct 9, 2026
Merged

hyperpolymath merged 7 commits into
mainfrom
arena/2ae9b9a8-standards

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

One-line change to .githooks/validate-k9.sh: is_fixture() gains a
9-archive/*) return 0 ;; case, so the archive district is neither validated
nor held to the K9 debt ledger.

This is PR A of two, and it is the prerequisite for the district move in
PR B. It is deliberately minimal: one file, +9/−0, no other change.

Note on stacking: this session is fixed to a single branch, so both PRs open
from arena/2ae9b9a8-standards. PR B will be opened against main after its
commit lands and will show A+B until A merges, at which point its diff reduces
to B alone.

What changed, and what stayed

Changed: .githooks/validate-k9.sh — one case arm plus an eight-line
comment.

Stayed, and why:

  • 1-formats/k9/tools/fixtures/* — untouched. The archive is exempted for the
    same reason as the fixtures and sits beside it, it does not replace it.
  • The debt ledger policy itself (touch → blocking, grandfathered → advisory,
    conforming-while-listed → stale). Unchanged; the archive simply never enters
    the list.
  • 1-formats/k9/tools/k9-validate.sh. The hook owns no rules and still owns
    none — this is policy about which files block a commit, which is exactly
    what the hook's header says it is for.

Why the district is exempt

9-archive/ is frozen history: the LAST COPY of dead upstream trees, kept
because the standards-map note says "ARCHIVE, do not delete". Its contents are
a historical record, not code this estate maintains.

Validating it is a choice between two bad outcomes: fail the archive for
upstream nonconformance this estate cannot fix, or grow the shrink-only debt
ledger with entries no one can ever discharge. Neither is what the ledger is
for — it exists so that debt shrinks, and an entry that cannot shrink is a
permanent licence by another name.

A grandfathered file moved here stops accruing debt rather than carrying it
into the archive. That is the point of archiving it.

Verification — diffed against a captured baseline, not eyeballed

A 95-row baseline was captured on pristine main before any edit
(Step 0): 4 gates, 10 validate-*.sh hooks in whole-repo mode, K9 at
K9_VALIDATE_LAYER=all, and the per-file exit code of all 80 test files
discovered by scripts/run-shell-test-suite.sh.

Gate / hook baseline PR A Δ
scripts/check-standards-map.sh 0 0 —
scripts/check-canonical-names.sh origin/main 0 0 —
scripts/check-inline-python.sh 0 0 —
scripts/link-rot-guard.sh 1 1 — (441 pre-existing BROKEN, see below)
.githooks/validate-k9.sh (L1) 0 0 —
K9_VALIDATE_LAYER=all (L2) 0 0 —
validate-bot-directives / codeql / gitleaks / lint-format / permissions 0 0 —
validate-actions-lock / sha-pins / spdx-workflows / spdx 1 1 — (pre-existing)
80 test files, per-file exit codes — — all identical

diff of the two rc.tsv captures: empty. All 95 rows match.

Behaviour proof. 9-archive/ does not exist yet, so the new arm is latent
— an untested latent change is how gates rot, so it was tested with planted
files staged via git add -N (the hook collects from git ls-files, so an
untracked file would have made the test vacuous):

Probe Result
Nonconforming .k9 at 9-archive/planted.k9 skipped — rc=0, zero mentions
Same bytes at planted-control/planted.k9 FAIL rc=1, K9-E004 K9-E005

The control failing is what makes the first row mean something: the hook does
catch this file, so the skip is a real behaviour change and not a no-op.

bash -n clean.

Anomalies, and what I could not check

  • link-rot-guard.sh fails on main already with 441 BROKEN lines,
    overwhelmingly docs/proofs/spec-templates/** → ../archetypes/*.md
    (nonexistent). Pre-existing, untouched here; PR B changes this script's
    prune path, so the count is the number to hold constant, not to fix.
  • Toolchain blind spots in my sandbox. yq (mikefarah v4), nickel,
    gitleaks and Ruby are unobtainable here — their only distribution is
    GitHub release assets, and release-assets.githubusercontent.com is not
    reachable. 24 of the 95 rows are therefore tool-blind: 13 test files fail
    on missing yq, 3 on missing Ruby, 1 on gitleaks, 1 on the JCS tool.

    The differential proves this PR changed nothing; it does not prove the
    gates are green. CI on the real runner is the authority.
  • No shellcheck here; the hook passed bash -n only.
  • K9 L2 caveat: with nickel absent, L2 cannot be doing semantic work in
    my sandbox, so the L2 rc=0 is weaker than CI's.

New pins: none.

Out of scope — filed separately, not bundled

  • validate-k9.sh touched-file check: printf … | grep -qxF under pipefail
    gives SIGPIPE false negatives on large change lists (~12–14% measured).
    Needs a here-string plus a regression test.
  • actions-allowlist/ deprecation and redirect plan.
  • standards-map.toml staleness after the A2ML retirement; 03-STANDARDS-REORG.md
    referenced but absent.
  • Root coordination.k9 does not parse under its own ABNF.

…ebt ledger

The archive district is frozen history: the LAST COPY of dead upstream
trees, kept because the standards-map note says "ARCHIVE, do not delete".

Running the K9 gate over it is a choice between two bad outcomes: fail the
archive for upstream nonconformance this estate cannot fix, or grow the
shrink-only debt ledger with entries no one can ever discharge. Neither is
what the ledger is for.

So 9-archive/* is treated exactly like the validator fixtures: not validated,
not ledgered. A grandfathered file moved here stops accruing debt rather than
carrying it into the archive, which is the point of archiving it.

Behaviour is unchanged today (no 9-archive/ exists yet); this is the
prerequisite for the district move that follows.

Refs: standards#1058, docs/CONTRACTILE-SPEC.adoc
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Important

Review skipped

We couldn't safely recover the incremental review. No full review was started, and the last reviewed checkpoint was preserved. Retry later, or explicitly request a full review by commenting @coderabbitai full review.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 37fd2c2f-33ad-431c-a21e-afe19cf69030

📥 Commits

Reviewing files that changed from the base of the PR and between 7712ae1 and e35d2c8.


📒 Files selected for processing (1)
  • .githooks/validate-k9.sh

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📜 Recent review details
⏰ Context from checks skipped due to timeout. (21)
  • GitHub Check: governance / Validate Hypatia Baseline
  • GitHub Check: Call CI Pipeline / Nickel
  • GitHub Check: Trust pipeline summary
  • GitHub Check: Call CI Pipeline / Rust / Detect Cargo.toml
  • GitHub Check: semgrep-cloud-platform/scan
  • GitHub Check: governance / Live Actions policy (credentialed advisory)
  • GitHub Check: Call CI Pipeline / Secret scanning / gitleaks
  • GitHub Check: governance / Licence consistency
  • GitHub Check: governance / Exemption ratchet
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Debt ratchet
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: analyze-js / analyze
  • GitHub Check: scan / gitleaks
  • GitHub Check: scorecard / Run Scorecard PR
  • GitHub Check: analyze-actions / analyze
  • GitHub Check: scan / Hypatia Neurosymbolic Analysis
  • GitHub Check: K9-SVC contractile validation
  • GitHub Check: Repo self-tests
  • GitHub Check: Verify CLAIMS.a2ml + conformance
  • GitHub Check: Report non-canonical JSON (report-only)

🔇 Additional comments (1)
.githooks/validate-k9.sh (1)

68-76: LGTM!





📝 Summary

Summary by CodeRabbit

  • Chores
    • Validation and debt-ledger processing now exclude files in the archive area, in addition to existing validator fixtures. Archived files are therefore not included in these checks or their results. Files outside these exclusions continue to be handled by the existing validation and debt-ledger processes. This change affects which files are covered by these checks; it does not describe a change to their results for included files.

Walkthrough

The is_fixture check now excludes paths under 9-archive/, so those files are excluded from validation and debt-ledger processing.

Changes

Archive validation exclusion

Layer / File(s) Summary
Exclude archived paths
.githooks/validate-k9.sh
is_fixture now excludes paths under 9-archive/, alongside validator fixtures.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Suggested reviewers: joshuajewell


Merge Risk: ⚪ Minimal · up to e35d2

Archived files are consistently excluded from validation and ledger processing by both hooks. No identified issue prevents merging.

Architecture Summary

Architecture risk: 🔵 Low · up to e35d2

The changed surface does not map to a changed system, dependency edge, entrypoint, or external dependency.

Changed systems: None identified.

Architecture concerns
No architecture-level concerns identified.

Review details

Before / after behavior

  • observed — Modified behavior in .githooks/validate-k9.sh: is_fixture now treats paths matching 9-archive/* as excluded, alongside validator fixtures. The added comments describe the archive as historical and state that files moved there stop accruing ledger debt.

Pre-merge checks | Passed 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description check Passed The description clearly explains the archive exemption, the affected hook, the rationale, verification results, and known pre-existing limitations. It is directly related to the changeset.
Title check Passed The title clearly and concisely identifies the change to exempt the 9-archive district from validation and debt ledger processing.
Docstring Coverage Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 1 files.
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.


✨ Finishing Touches
📝 Generate docstrings

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

A rabbit checks the archive path,
And leaves old files outside its task.
The ledger skips that history,
The validator agrees.
Then hops away beneath the trees.

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37981657890

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 14 conforming, 1 grandfathered (layer all, contract v1.0.0)

… (1 of 5, git renames, no content change)

Move the rhodium-standard-repositories tree into the new 9-archive/ district
as pure git renames: no content change, no reformatting, no SPDX edits.

This is one of several commits that together perform the move; it is split
only because the GitHub API will not carry 8.5 MB of file contents in a single
mutation. The commits are mechanical slices of one operation and are meant to
be read as a unit.

Why the tree moves at all: it is the LAST COPY of a dead upstream.
hyperpolymath/rhodium-standard-repositories 404s, and 8 of its 10 satellites
have no external home. Earlier revisions of standards-map.toml called it a
vendored copy to extract and DELETE; that was wrong, and the map now records
it as "ARCHIVE, do not delete".

actions-allowlist/ deliberately stays behind at the old path: allowed-actions.json
is fetched by raw URL from allowlist-preflight-reusable.yml and
governance-reusable.yml, so relocating it is a breaking change to consumers
outside this repo. It keeps its own residual map entry and needs a separate
deprecation/redirect plan.

The map, the baseline and every live pointer are updated in the final commit
of this series. Intermediate commits transiently fail GATE D by construction,
because the map still points at the pre-move paths; the head commit is green.

Refs: standards#1058.
… (2 of 5, git renames, no content change)

Move the rhodium-standard-repositories tree into the new 9-archive/ district
as pure git renames: no content change, no reformatting, no SPDX edits.

This is one of several commits that together perform the move; it is split
only because the GitHub API will not carry 8.5 MB of file contents in a single
mutation. The commits are mechanical slices of one operation and are meant to
be read as a unit.

Why the tree moves at all: it is the LAST COPY of a dead upstream.
hyperpolymath/rhodium-standard-repositories 404s, and 8 of its 10 satellites
have no external home. Earlier revisions of standards-map.toml called it a
vendored copy to extract and DELETE; that was wrong, and the map now records
it as "ARCHIVE, do not delete".

actions-allowlist/ deliberately stays behind at the old path: allowed-actions.json
is fetched by raw URL from allowlist-preflight-reusable.yml and
governance-reusable.yml, so relocating it is a breaking change to consumers
outside this repo. It keeps its own residual map entry and needs a separate
deprecation/redirect plan.

The map, the baseline and every live pointer are updated in the final commit
of this series. Intermediate commits transiently fail GATE D by construction,
because the map still points at the pre-move paths; the head commit is green.

Refs: standards#1058.
… (3 of 5, git renames, no content change)

Move the rhodium-standard-repositories tree into the new 9-archive/ district
as pure git renames: no content change, no reformatting, no SPDX edits.

This is one of several commits that together perform the move; it is split
only because the GitHub API will not carry 8.5 MB of file contents in a single
mutation. The commits are mechanical slices of one operation and are meant to
be read as a unit.

Why the tree moves at all: it is the LAST COPY of a dead upstream.
hyperpolymath/rhodium-standard-repositories 404s, and 8 of its 10 satellites
have no external home. Earlier revisions of standards-map.toml called it a
vendored copy to extract and DELETE; that was wrong, and the map now records
it as "ARCHIVE, do not delete".

actions-allowlist/ deliberately stays behind at the old path: allowed-actions.json
is fetched by raw URL from allowlist-preflight-reusable.yml and
governance-reusable.yml, so relocating it is a breaking change to consumers
outside this repo. It keeps its own residual map entry and needs a separate
deprecation/redirect plan.

The map, the baseline and every live pointer are updated in the final commit
of this series. Intermediate commits transiently fail GATE D by construction,
because the map still points at the pre-move paths; the head commit is green.

Refs: standards#1058.
… (4 of 5, git renames, no content change)

Move the rhodium-standard-repositories tree into the new 9-archive/ district
as pure git renames: no content change, no reformatting, no SPDX edits.

This is one of several commits that together perform the move; it is split
only because the GitHub API will not carry 8.5 MB of file contents in a single
mutation. The commits are mechanical slices of one operation and are meant to
be read as a unit.

Why the tree moves at all: it is the LAST COPY of a dead upstream.
hyperpolymath/rhodium-standard-repositories 404s, and 8 of its 10 satellites
have no external home. Earlier revisions of standards-map.toml called it a
vendored copy to extract and DELETE; that was wrong, and the map now records
it as "ARCHIVE, do not delete".

actions-allowlist/ deliberately stays behind at the old path: allowed-actions.json
is fetched by raw URL from allowlist-preflight-reusable.yml and
governance-reusable.yml, so relocating it is a breaking change to consumers
outside this repo. It keeps its own residual map entry and needs a separate
deprecation/redirect plan.

The map, the baseline and every live pointer are updated in the final commit
of this series. Intermediate commits transiently fail GATE D by construction,
because the map still points at the pre-move paths; the head commit is green.

Refs: standards#1058.
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37983691694

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

… (5 of 5, git renames, no content change)

Move the rhodium-standard-repositories tree into the new 9-archive/ district
as pure git renames: no content change, no reformatting, no SPDX edits.

This is one of several commits that together perform the move; it is split
only because the GitHub API will not carry 8.5 MB of file contents in a single
mutation. The commits are mechanical slices of one operation and are meant to
be read as a unit.

Why the tree moves at all: it is the LAST COPY of a dead upstream.
hyperpolymath/rhodium-standard-repositories 404s, and 8 of its 10 satellites
have no external home. Earlier revisions of standards-map.toml called it a
vendored copy to extract and DELETE; that was wrong, and the map now records
it as "ARCHIVE, do not delete".

actions-allowlist/ deliberately stays behind at the old path: allowed-actions.json
is fetched by raw URL from allowlist-preflight-reusable.yml and
governance-reusable.yml, so relocating it is a breaking change to consumers
outside this repo. It keeps its own residual map entry and needs a separate
deprecation/redirect plan.

The map, the baseline and every live pointer are updated in the final commit
of this series. Intermediate commits transiently fail GATE D by construction,
because the map still points at the pre-move paths; the head commit is green.

Refs: standards#1058.
@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37983734103

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] 14 conforming, 0 grandfathered (layer all, contract v1.0.0)

…ive district

Follow the moved paths everywhere something live depends on them, and record
the district in standards-map.toml. This is the commit that makes the tree
consistent; the five rename commits before it are inert without it.

standards-map.toml (GATE D now passes, entry_count 124 -> 126):
  - new entry  9-archive/                             district root, frozen,
    canonical=false. Required by GATE D assertion 2: a new top-level path must
    be mapped. Frozen because editing archived content to satisfy a gate would
    falsify the record.
  - new entry  9-archive/rhodium-standard-repositories archive-vendored, 1135
    files, deprecated. Same "ARCHIVE, do not delete" note, with the stale
    sentence "NOT moved wholesale" corrected now that the move has happened.
  - new entry  rhodium-standard-repositories          residual, 2 files,
    published-interface. Records why actions-allowlist/ stayed and that it
    needs its own deprecation/redirect plan.
  - moved      REORGANIZATION-PLAN.adoc -> 9-archive/REORGANIZATION-PLAN.adoc
    (its target already said 9-archive; only `from` was stale).

Live pointers followed:
  .hypatia-baseline.json                31 file keys rewritten, 189 entries
                                        retained, valid JSON, none lost. The
                                        two `note` fields mentioning the tree
                                        are prose and were left alone.
  .machine_readable/inline-python-allow.txt   6 entries repathed; every entry
                                        verified to resolve to a real file.
  .machine_readable/k9-contract-debt.txt     dropped rsr-compliance-checklist
                                        .k9.ncl: the hook now skips the
                                        district, so a ledger entry it can
                                        never discharge would be permanent.
  .machine_readable/Debtfile.a2ml       probe repathed. This one mattered:
                                        the old `git ls-files
                                        'rhodium-standard-repositories'`
                                        silently returned 0 and the debt item
                                        would have counted zero. Measured
                                        after the fix: 40 unpinned `uses:`
                                        refs across 91 workflow files.
  scripts/link-rot-guard.sh             prune target is now the district root
                                        $ROOT/9-archive, not the tree inside
                                        it, so later archives are covered with
                                        no further edit.
  scripts/rsr-selfaudit.sh, scripts/tests/governance-reusable-contract-test.sh,
  scripts/tests/wave0-false-green-test.sh (lines 14 and 48)
                                        paths repathed; all three pass.
  coordination.k9                       protected section: the old entry's
                                        reason now explains it is a residual
                                        published interface; a 9-archive/
                                        entry records it as frozen archive.
  .machine_readable/rsr-profile.a2ml    comment corrected: finding F4 said
                                        "VENDORED, to be deleted"; upstream
                                        404s, so it is ARCHIVED, do not delete.
  doc pointers repathed where the target actually exists: PALIMPSEST.adoc,
  3-practice/LICENCE-POLICY.adoc, 3-practice/SECURITY-ADVISORIES.adoc,
  1-formats/k9/spec/MIGRATION-1058.adoc, 1-formats/k9/tools/k9-validate.sh,
  foundations-readiness-grades/FOUNDATIONS-READINESS-GRADES.a2ml.

Deliberately NOT changed (justified in the PR body):
  canon.lock (pinned), frozen audits/affirmations/scorecards, external
  github.com and raw.githubusercontent.com URLs, actions-allowlist and the
  scripts that consume it, and .githooks/validate-sha-pins.sh whose vendored
  substring match still matches the new paths. TOPOLOGY.adoc is a self-declared
  frozen snapshot of commit 6d19ce0 and was left alone despite AGENTS.adoc
  conflicting with the task brief on this point.

Refs: standards#1058.
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Add Carrot credits or activate Agent usage billing to use Autofix

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Coding task changes are ready, but delivery needs attention

Open the task to resolve the delivery issue or retry.

@github-actions

github-actions Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37983810083

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] 14 conforming, 0 grandfathered (layer all, contract v1.0.0)

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 3108c1b into main Oct 9, 2026
65 of 66 checks passed
@hyperpolymath
hyperpolymath deleted the arena/2ae9b9a8-standards branch October 9, 2026 19:59

Copy link
Copy Markdown
Owner Author

@coderabbitai full review

Requesting an explicit full review: the incremental review could not be
recovered because this branch received 7 commits in quick succession (the move
was split across 5 rename commits plus the reference-update commit, since the
API will not carry 8.5 MB in one mutation). The effective diff is 1,154 changed
files, of which 1,136 are byte-identical git renames (all R100) into the new
9-archive/ district, 17 are live reference updates, and 1 is the
.githooks/validate-k9.sh exemption that PR A described.

The part worth reviewing is the 17 reference updates and standards-map.toml
(entry_count 124 -> 126), not the renames.

@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor
⚠️ Action not completed

Pull request is closed.


Your included review limit is currently reached under our Fair Usage Limits Policy. This review may still proceed through usage-based billing if eligible. Your next included review will be available in 32 minutes.

This was referenced Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant