Skip to content
Merged

Pr 1148 #1153

Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 10 additions & 3 deletions .github/workflows/actions.lock
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,7 @@ workflows:
'.github/workflows/ci-pipeline.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'haskell-actions/setup@0f8e8c99d88aeb3fbfd523f1ef2c6f762d10d64d'
- 'hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd'
- 'oven-sh/setup-bun@0c5077e51419868618aeaa5fe8019c62421857d6'
'.github/workflows/codeql-reusable.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
Expand Down Expand Up @@ -96,7 +97,8 @@ workflows:
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'dtolnay/rust-toolchain@02cb101ec7c40f2c49e1d9714d64511d8e1b74de'
- 'webfactory/ssh-agent@e83874834305fe9a4a2997156cb26c5de65a8555'
'.github/workflows/mirror.yml': []
'.github/workflows/mirror.yml':
- 'hyperpolymath/standards@571cc734cd69fb846032ec77a662aa8ee4fc32cd'
'.github/workflows/no-js-scan.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
'.github/workflows/pages-archive.yml':
Expand Down Expand Up @@ -148,8 +150,6 @@ workflows:
- 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1'
'.github/workflows/signed-push-smoke.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
- 'actions/create-github-app-token@bcd2ba49218906704ab6c1aa796996da409d3eb1'
- 'asana/push-signed-commits@d615ca88d8e1a946734c24970d1e7a6c56f34897'
- 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1'
'.github/workflows/spark-theatre-gate.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
Expand All @@ -160,6 +160,8 @@ workflows:
- 'step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1'
'.github/workflows/tailscale-connect-reusable.yml':
- 'tailscale/github-action@d1b6cd204f8dceda5b3eaad7f1f767be390056cd'
'.github/workflows/uuid-v7.yml':
- 'actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1'
dependencies:
'actions/cache@55cc8345863c7cc4c66a329aec7e433d2d1c52a9':
ref: '55cc8345863c7cc4c66a329aec7e433d2d1c52a9'
Expand All @@ -171,6 +173,11 @@ dependencies:
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
owner_id: 44036562
repo_id: 197814629
'actions/checkout@v7.0.1':
ref: 'v7.0.1'
commit: 'sha1-3d3c42e5aac5ba805825da76410c181273ba90b1'
owner_id: 44036562
repo_id: 197814629
'actions/configure-pages@45bfe0192ca1faeb007ade9deae92b16b8254a0d':
ref: '45bfe0192ca1faeb007ade9deae92b16b8254a0d'
commit: 'sha1-45bfe0192ca1faeb007ade9deae92b16b8254a0d'
Expand Down
153 changes: 88 additions & 65 deletions .github/workflows/provisioning-check-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,69 +21,92 @@
# jobs:
# provisioning:
# uses: hyperpolymath/standards/.github/workflows/provisioning-check-reusable.yml@<sha>
{
name: "Provisioning Check Reusable",
on: {
workflow_call: null,
},
permissions: {
contents: "read",
},
jobs: {
provisioning: {
name: "Provisioning set conforms",
runs-on: "ubuntu-latest",
timeout-minutes: 10,
steps: [
{
name: "Checkout caller repository",
uses: "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", # v7.0.1
with: {
repository: "${{ github.repository }}",
ref: "${{ github.sha }}",
name: "Provisioning Check Reusable"

on:
workflow_call: null

permissions:
contents: read

jobs:
provisioning:
name: "Provisioning set conforms"
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: "Checkout caller repository"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: "${{ github.repository }}"
ref: "${{ github.sha }}"
# launcher.sh (caller code) runs below: never leave the token in .git/config.
persist-credentials: false,
},
},
{
name: "Checkout the provisioning canon",
uses: "actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1", # v7.0.1
with: {
repository: "hyperpolymath/standards",
ref: "${{ job.workflow_sha }}",
path: ".standards-checkout",
persist-credentials: false,
sparse-checkout: "3-practice/provisioning/templates/build/just\n",
sparse-checkout-cone-mode: false,
},
},
{
name: "Stage the canon engine outside the checked tree",
shell: "bash",
run: "mkdir -p \"$RUNNER_TEMP/canon\"\ncp .standards-checkout/3-practice/provisioning/templates/build/just/* \"$RUNNER_TEMP/canon/\"\nrm -rf .standards-checkout\nls \"$RUNNER_TEMP/canon\"\n",
},
{
name: "Install just (the engine's runner; >= 1.42 is required)",
shell: "bash",
env: {
JUST_VERSION: "1.56.0",
JUST_SHA256: "fa2a8ec1015d9df5330941ade12437488fc40d33f9c9f8cd4eb70a26de11b639",
},
run: "set +e\ntgz=\"$RUNNER_TEMP/just.tar.gz\"\ncurl -fsSL -o \"$tgz\" \\\n \"https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-x86_64-unknown-linux-musl.tar.gz\" \\\n && echo \"${JUST_SHA256} $tgz\" | sha256sum -c - \\\n && mkdir -p \"$RUNNER_TEMP/bin\" \\\n && tar -xzf \"$tgz\" -C \"$RUNNER_TEMP/bin\" just\nSTATUS=$?\nif [ \"$STATUS\" -ne 0 ]; then\n echo \"::error title=just install::could not fetch or verify just ${JUST_VERSION}\"\n exit \"$STATUS\"\nfi\necho \"$RUNNER_TEMP/bin\" >> \"$GITHUB_PATH\"\n\"$RUNNER_TEMP/bin/just\" --version\n",
},
{
name: "Engine files match the canon",
if: "${{ !cancelled() }}",
shell: "bash",
run: "set +e\ndrift=0\nfor f in provision.just provision-lib.sh provision-modes.sh provision-check.sh; do\n if [ ! -f \"build/just/$f\" ]; then\n echo \"::error file=build/just/$f,title=engine missing::build/just/$f is missing (run: launch-scaffolder provision-set realign)\"\n drift=1\n elif ! cmp -s \"build/just/$f\" \"$RUNNER_TEMP/canon/$f\"; then\n echo \"::error file=build/just/$f,title=engine drift::build/just/$f differs from the canon at standards@${{ job.workflow_sha }} (run: launch-scaffolder provision-set realign)\"\n drift=1\n else\n echo \"ok build/just/$f\"\n fi\ndone\nexit \"$drift\"\n",
},
{
name: "Provisioning set conforms (provision-check.sh)",
if: "${{ !cancelled() }}",
shell: "bash",
run: "set +e\nbash \"$RUNNER_TEMP/canon/provision-check.sh\" . | tee \"$RUNNER_TEMP/check.log\"\nSTATUS=\"${PIPESTATUS[0]}\"\ngrep '^ FAIL' \"$RUNNER_TEMP/check.log\" | sed 's/^ FAIL //' | while IFS= read -r line; do\n echo \"::error title=provisioning::$line\"\ndone\n{\n echo \"## Provisioning check\"\n echo \"\"\n echo '```'\n cat \"$RUNNER_TEMP/check.log\"\n echo '```'\n} >> \"$GITHUB_STEP_SUMMARY\"\nexit \"$STATUS\"\n",
},
],
},
},
}
persist-credentials: false
- name: "Checkout the provisioning canon"
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
repository: hyperpolymath/standards
ref: ${{ job.workflow_sha }}
path: .standards-checkout
persist-credentials: false
sparse-checkout: "3-practice/provisioning/templates/build/just\n"
sparse-checkout-cone-mode: false
- name: "Stage the canon engine outside the checked tree"
shell: bash
run: "mkdir -p \"$RUNNER_TEMP/canon\"\ncp .standards-checkout/3-practice/provisioning/templates/build/just/* \"$RUNNER_TEMP/canon/\"\nrm -rf .standards-checkout\nls \"$RUNNER_TEMP/canon\"\n"
- name: "Install just (the engine's runner; >= 1.42 is required)"
shell: bash
env:
JUST_VERSION: "1.56.0"
JUST_SHA256: "fa2a8ec1015d9df5330941ade12437488fc40d33f9c9f8cd4eb70a26de11b639"
run: |
set +e
tgz="$RUNNER_TEMP/just.tar.gz"
curl -fsSL -o "$tgz" \
"https://github.com/casey/just/releases/download/${JUST_VERSION}/just-${JUST_VERSION}-x86_64-unknown-linux-musl.tar.gz" \

Check warning on line 66 in .github/workflows/provisioning-check-reusable.yml

View check run for this annotation

SonarQubeCloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=hyperpolymath_standards&issues=AaEKzteQuWbptJe4KKZe&open=AaEKzteQuWbptJe4KKZe&pullRequest=1152
&& echo "${JUST_SHA256} $tgz" | sha256sum -c - \
&& mkdir -p "$RUNNER_TEMP/bin" \
&& tar -xzf "$tgz" -C "$RUNNER_TEMP/bin" just
STATUS=$?
if [ "$STATUS" -ne 0 ]; then
echo "::error title=just install::could not fetch or verify just ${JUST_VERSION}"
exit "$STATUS"
fi
echo "$RUNNER_TEMP/bin" >> "$GITHUB_PATH"
"$RUNNER_TEMP/bin/just" --version
- name: "Engine files match the canon"
if: "${{ !cancelled() }}"
shell: bash
run: |
set +e
drift=0
for f in provision.just provision-lib.sh provision-modes.sh provision-check.sh; do
if [ ! -f "build/just/$f" ]; then
echo "::error file=build/just/$f,title=engine missing::build/just/$f is missing (run: launch-scaffolder provision-set realign)"
drift=1
elif ! cmp -s "build/just/$f" "$RUNNER_TEMP/canon/$f"; then
echo "::error file=build/just/$f,title=engine drift::build/just/$f differs from the canon at standards@${{ job.workflow_sha }} (run: launch-scaffolder provision-set realign)"
drift=1
else
echo "ok build/just/$f"
fi
done
exit "$drift"
- name: "Provisioning set conforms (provision-check.sh)"
if: "${{ !cancelled() }}"
shell: bash
run: |
set +e
bash "$RUNNER_TEMP/canon/provision-check.sh" . | tee "$RUNNER_TEMP/check.log"
STATUS="${PIPESTATUS[0]}"
grep '^ FAIL' "$RUNNER_TEMP/check.log" | sed 's/^ FAIL //' | while IFS= read -r line; do
echo "::error title=provisioning::$line"
done
{
echo "## Provisioning check"
echo ""
echo '```'
cat "$RUNNER_TEMP/check.log"
echo '```'
} >> "$GITHUB_STEP_SUMMARY"
exit "$STATUS"
4 changes: 2 additions & 2 deletions .github/workflows/rust-ci-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -188,7 +188,7 @@ jobs:
version: ${{ inputs.zig_version }}

- name: Cache cargo registry and build
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
uses: swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: ${{ inputs.working_directory }}

Expand Down Expand Up @@ -236,7 +236,7 @@ jobs:
version: ${{ inputs.zig_version }}

- name: Cache cargo registry and build
uses: Swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
uses: swatinem/rust-cache@6323deb102c322ba6fcbdcafc7e3dddab59af2b6 # v2
with:
workspaces: ${{ inputs.working_directory }}

Expand Down
17 changes: 3 additions & 14 deletions .machine_readable/contractiles/INDEX.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -10,9 +10,9 @@

---
id = "contractiles-registry"
version = "2.0.0" # 2.0.0 (2026-04-18): all 6 verbs on trident shape; verb set complete.
version = "2.1.0" # 2.1.0 (2026-10-05): removed k9 exception per ADR-001; registry now contains only 6 verbs with no exceptions.
spec = "docs/CONTRACTILE-SPEC.adoc"
last_updated = "2026-04-18"
last_updated = "2026-10-05"
base_schema = ".machine_readable/contractiles/_base.ncl"
meta_schema_status = "pending β€” see CONTRACTILE-SPEC Β§validator-meta-schema"

Expand Down Expand Up @@ -82,18 +82,7 @@ gating = "non-gating (continue)"
cardinality = "one per repo"
notes = "First trident instance in the estate (2026-04-18). Reports progress toward committed next-actions AND lists horizon aspirations. Absorbed the deprecated `lust` verb 2026-04-18. Never blocks. Remaining 5 verbs still on file_pair shape until tridents are built."

[[verbs]]
name = "k9"
semantics = "trust-tier templates (EXCEPTION to one-verbfile rule)"
file_pair = [
"k9/template-hunt.k9.ncl",
"k9/template-kennel.k9.ncl",
"k9/template-yard.k9.ncl",
]
status = "exception"
gating = "not applicable"
notes = "k9 is service-automation meta-infrastructure, not a verb contractile. Three trust-tier templates (Kennel/Yard/Hunt). Does not have a Verbfile.a2ml. See CONTRACTILE-SPEC Β§k9-exception."

# [[verbs]] k9 REMOVED 2026-10-05 β€” relocated by ADR-001 to .machine_readable/svc/k9/; not a verb contractile
# [[verbs]] lust REMOVED 2026-04-18 β€” name had unwanted associations;
# the horizon/aspiration semantics were always meant to live inside `intend`
# (the north-star verb). The [[wishes]] schema was absorbed into
Expand Down
60 changes: 11 additions & 49 deletions .machine_readable/contractiles/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ PascalCase in the A2ML (e.g. `intend.ncl` + `Intentfile.a2ml`,
All verb runners import `_base.ncl` (shared pedigree + run-defaults + probe-schema).
See `docs/CONTRACTILE-SPEC.adoc` for the normative specification.

== Verbs (6 + k9 exception)
== Verbs (6)

[cols="1,2,3", options="header"]
|===
Expand Down Expand Up @@ -60,55 +60,18 @@ associations). Its [[wishes]] semantics live inside `intend/Intentfile.a2ml`
as a second section alongside [[intents]]. Any `lust/` dir encountered in
an estate repo is drift and should be removed.

== k9 β€” Service-Automation Layer (EXCEPTION to the one-verbfile rule)
[[k9-relocation]]
== k9 Service-Automation Layer (Relocated)

IMPORTANT: `k9/` is **not a contractile verb** and does NOT follow the
`<Verb>file.a2ml` + `<verb>.ncl` pattern. This is an intentional, documented
exception. Do not apply the naming rule to k9.
IMPORTANT: k9 is **not a contractile verb**. As of ADR-001 (2026-04-18),
k9 has been relocated from this directory to `.machine_readable/svc/k9/`
estate-wide. The `k9/` directory entry in this location is a **signpost only**.

=== Why k9 is different

The seven verb contractiles each declare *one concern per repo* in a single
xfile. k9 is not a concern; it is the *graded automation surface* that
enforces or validates concern declarations. k9 provides three trust-tier
*templates* that repos copy and instantiate:

[cols="1,1,3", options="header"]
|===
| File | Trust tier | Description

| `k9/template-kennel.k9.ncl`
| Kennel
| Pure data. No subprocess, no filesystem write, no network. Safe for
metadata and declarative settings.

| `k9/template-yard.k9.ncl`
| Yard
| Nickel evaluation with contracts and validation. No side effects.

| `k9/template-hunt.k9.ncl`
| Hunt
| Full execution surface. Must declare side effects, support dry-run, and
be signed before the estate treats it as trustworthy automation.
|===

=== Why the naming rule does not apply

The one-verb-one-Verbfile rule exists to enforce clean concern separation.
k9 is meta-infrastructure: it does not have a `K9file.a2ml` because it is
not a declarative xfile β€” it is a template set that instantiates into
specific repos. Applying the rule would produce a meaningless `K9file.a2ml`
with nothing to declare.

=== Audit rule

If a repo claims `k9` enforcement, each k9 component in that repo MUST
declare a `paired_xfile` pointing to a specific contractile xfile (e.g.
`../must/Mustfile.a2ml`). Floating k9 components with no paired xfile are
non-conformant.

See `k9/README.adoc` for the full k9 security model and usage instructions.
See `docs/CONTRACTILE-SPEC.adoc Β§k9-exception` for the normative statement.
k9 provides three trust-tier templates (Kennel, Yard, Hunt) that repos copy
and instantiate. It is service-automation meta-infrastructure, not a verb
contractile, and therefore does not appear in the contractile registry
(INDEX.a2ml). See ADR-001 for the relocation rationale and
`.machine_readable/svc/k9/README.adoc` for the full k9 security model.

== Fill-In Instructions

Expand All @@ -125,7 +88,6 @@ When copying this set into a new repo:
6. `Bustfile` β€” declare real breakage / expiry / hard-stop conditions.
7. `Intentfile` β€” list tracked next-actions with observable probes
([[intents]] section) AND horizon aspirations ([[wishes]] section).
8. Pair any `k9/*.k9.ncl` with a specific contractile via `paired_xfile`.

== Intentfile: Commitments vs Aspirations β€” Two Sections, One File

Expand Down
Loading
Loading