Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
9 changes: 9 additions & 0 deletions .githooks/validate-k9.sh
Original file line number Diff line number Diff line change
Expand Up @@ -65,6 +65,15 @@ fi
is_fixture() {
case "$1" in
1-formats/k9/tools/fixtures/*) return 0 ;;
# 9-archive/ is a frozen district, not the live K9 corpus. It holds the
# LAST COPY of dead upstream trees, kept because the standards-map note
# says "ARCHIVE, do not delete" — its contents are historical record, not
# code this estate maintains. Validating it would mean either failing the
# archive for upstream's nonconformance or growing the debt ledger with
# entries no one can ever discharge. So: not validated, not ledgered.
# A grandfathered file moved here stops accruing debt rather than
# carrying it into the archive — which is the point of archiving it.
9-archive/*) return 0 ;;
esac
return 1
}
Expand Down
62 changes: 31 additions & 31 deletions .hypatia-baseline.json

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions .machine_readable/Debtfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -71,8 +71,8 @@ forgotten.
## Vendored mirrors

### vendored-mirror-unpinned-actions
- description: Unpinned `uses:` refs inside `rhodium-standard-repositories/**` -- the vendored mirror of the RSR canon (gitlab.com/hyperpolymath/rhodium-standard-repositories). These are OTHER repositories' workflows reproduced here as templates, and this repo's own CI lock gate (.github/workflows/actions-lock-gate.yml -> .githooks/validate-actions-lock.sh) covers only the root .github tree, so `.githooks/validate-sha-pins.sh` matches that scope and skips the mirror rather than silently passing it. Re-pinning the mirror here fixes no live runner and desynchronises the copy; it is fixed upstream, or the mirror retires. MEASURED 2026-09-21 by the probe.
- probe: n=$(git ls-files 'rhodium-standard-repositories' | grep -E '/\.github/(workflows|actions)/.*\.ya?ml$' | xargs -r grep -hE '^[[:space:]]*(-[[:space:]]*)?uses:[[:space:]]+[A-Za-z0-9]' | grep -vcE '@[0-9a-f]{40}([^0-9a-f]|$)' || true); echo "${n:-0}"
- description: Unpinned `uses:` refs inside `9-archive/rhodium-standard-repositories/**` -- the vendored mirror of the RSR canon (gitlab.com/hyperpolymath/rhodium-standard-repositories). These are OTHER repositories' workflows reproduced here as templates, and this repo's own CI lock gate (.github/workflows/actions-lock-gate.yml -> .githooks/validate-actions-lock.sh) covers only the root .github tree, so `.githooks/validate-sha-pins.sh` matches that scope and skips the mirror rather than silently passing it. Re-pinning the mirror here fixes no live runner and desynchronises the copy; it is fixed upstream, or the mirror retires. MEASURED 2026-09-21 by the probe.
- probe: n=$(git ls-files '9-archive/rhodium-standard-repositories' | grep -E '/\.github/(workflows|actions)/.*\.ya?ml$' | xargs -r grep -hE '^[[:space:]]*(-[[:space:]]*)?uses:[[:space:]]+[A-Za-z0-9]' | grep -vcE '@[0-9a-f]{40}([^0-9a-f]|$)' || true); echo "${n:-0}"
- count: 42
- ceiling: 42
- severity: low
Expand Down
12 changes: 6 additions & 6 deletions .machine_readable/inline-python-allow.txt
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,12 @@
# a line; never raise a count. Regenerate the current set with
# bash scripts/check-inline-python.sh --print
2-protocols/axel/Containerfile:1
rhodium-standard-repositories/Justfile:1
rhodium-standard-repositories/rhodium-pipeline/Justfile:1
rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/Justfile:1
rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml:2
rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml:2
rhodium-standard-repositories/ux-test-harness/test-repo.sh:2
9-archive/rhodium-standard-repositories/Justfile:1
9-archive/rhodium-standard-repositories/rhodium-pipeline/Justfile:1
9-archive/rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/Justfile:1
9-archive/rhodium-standard-repositories/satellites/cccp/satellites/php-aegis/.github/workflows/comprehensive-quality.yml:2
9-archive/rhodium-standard-repositories/satellites/state.scm/.github/workflows/comprehensive-quality.yml:2
9-archive/rhodium-standard-repositories/ux-test-harness/test-repo.sh:2
scripts/check-allowed-actions.sh:1
scripts/cicd-census.sh:2
scripts/tests/apply-branch-gates-test.sh:1
1 change: 0 additions & 1 deletion .machine_readable/k9-contract-debt.txt
Original file line number Diff line number Diff line change
Expand Up @@ -34,4 +34,3 @@
3-practice/session-management-standards/verify/maintenance-sweep/PROTOCOL.k9
3-practice/session-management-standards/verify/release-audit/PROTOCOL.k9
3-practice/session-management-standards/verify/substantial-completion/PROTOCOL.k9
rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl
6 changes: 5 additions & 1 deletion .machine_readable/rsr-profile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -125,4 +125,8 @@ omitted-rationale = "The canon defines conformance; it is not an instance of it.
# the applicability policy (0-canon/TEMPLATE-APPLICABILITY-POLICY.adoc)
# the reusable workflows (.github/workflows/*-reusable.yml)
# docs/proofs/ — proof artefacts of the estate, not proofs of this repo
# rhodium-standard-repositories/ — VENDORED, to be deleted (finding F4)
# 9-archive/rhodium-standard-repositories/ — ARCHIVED 2026-10-09, do NOT delete.
# Finding F4 called it "VENDORED, to be deleted"; that assumed upstream still
# existed. It does not (hyperpolymath/rhodium-standard-repositories 404s) and
# 8 of 10 satellites have no other home, so this is the LAST COPY. Only
# actions-allowlist/ stayed behind, because it is a live published interface.
6 changes: 3 additions & 3 deletions 1-formats/k9/spec/MIGRATION-1058.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -310,7 +310,7 @@ Both files now declare `pedigree.security.leash` and pass the canonical
validator at L1 with no findings; K9-S014 no longer has an instance here. The
two ledger entries were already gone, so this change removes none: it makes the
earlier removal true rather than speculative. The remaining stray leash in the
corpus is `rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl`
corpus is `9-archive/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl`
(M5).

Three corrections to the paragraph above, from reading the bodies rather than
Expand Down Expand Up @@ -349,7 +349,7 @@ files as much as these two. The record now takes a `, ..` tail.

=== M5 — `rsr-compliance-checklist.k9.ncl` is not a single Nickel term

*File:* `rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl`
*File:* `9-archive/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl`
*Rules cleared:* K9-S004, K9-S005, K9-S014 · *ledger entries removed:* 1

The file has the envelope and a `pedigree`, but its top level is a *sequence of
Expand Down Expand Up @@ -405,7 +405,7 @@ K9 corpus conformance ok 5 conforming, 25 grandfathered
The corpus step runs the local hook, which is pinned to `--layer L1` so it can
run in a pre-commit hook without a toolchain. So the 25 grandfathered files
have **still never been through Nickel**, and M5's prediction is untested:
`rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl` opens with a
`9-archive/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl` opens with a
top-level *sequence of bindings*, which is not a Nickel term and should be a
parse error the moment anything typechecks it.

Expand Down
2 changes: 1 addition & 1 deletion 1-formats/k9/tools/k9-validate.sh
Original file line number Diff line number Diff line change
Expand Up @@ -407,7 +407,7 @@ check_l1() {
# K9-S014 — a leash claim outside pedigree.security. Same rule as the L0
# library check, but reachable from a component too: a file may carry the
# envelope and still declare its level somewhere no host reads. This is the
# live shape of rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl.
# live shape of 9-archive/rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl.
if [ -n "$(fact_get "$facts" leash)" ]; then
err K9-S014 L1 "top-level 'leash = $(fact_get "$facts" leash)' outside pedigree.security; a leash declared there is read by nothing"
fi
Expand Down
2 changes: 1 addition & 1 deletion 3-practice/LICENCE-POLICY.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -422,6 +422,6 @@ MPL-2.0 so the single GitHub display resolves as above.
== See Also

* `PALIMPSEST.adoc` (this directory) — full narrative
* `rhodium-standard-repositories/PALIMPSEST.adoc` — RSR integration
* `9-archive/rhodium-standard-repositories/PALIMPSEST.adoc` — RSR integration
* link:https://github.com/hyperpolymath/palimpsest-license[palimpsest-license] — PMPL licence text
* link:https://www.mozilla.org/en-US/MPL/2.0/[MPL-2.0] — legal fallback text
4 changes: 2 additions & 2 deletions 3-practice/SECURITY-ADVISORIES.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ deferral is re-evaluated.
=== GHSA-xgp8-3hg3-c2mh + GHSA-965h-392x-2mh5 (rustls-webpki, low, 2026-04-18)

`rustls-webpki` 0.103.10 → 0.103.12 in
`rhodium-standard-repositories/satellites/rsr-certifier/Cargo.lock`.
`9-archive/rhodium-standard-repositories/satellites/rsr-certifier/Cargo.lock`.
Transitive dep, Cargo.lock-only bump. Both advisories closed by the
same upstream patch level.

Expand Down Expand Up @@ -43,7 +43,7 @@ version: `rand` 0.9.3. Severity: low.
|Build-time / template-render only. `k9-init` does not install a custom global logger.
|`tera` 1.x still pins `rand` 0.8. Fix requires upstream `tera` 2.x migration (or a replacement template engine).

|`rhodium-standard-repositories/examples/enterprise-service/Cargo.lock`
|`9-archive/rhodium-standard-repositories/examples/enterprise-service/Cargo.lock`
|Dev-dependency via `axum-test` → `rust-multipart-rfc7578_2`.
|Test-time only. `enterprise-service` does not ship any binary that embeds `axum-test`.
|`rust-multipart-rfc7578_2` still depends on `rand` 0.8. Fix requires upstream (or replacing `axum-test` in dev-deps).
Expand Down
File renamed without changes.
File renamed without changes.
Loading
Loading