Skip to content

Pr 1148 fixed - #1154

Merged
hyperpolymath merged 8 commits into
mainfrom
pr-1148-fixed
Oct 5, 2026
Merged

hyperpolymath merged 8 commits into
mainfrom
pr-1148-fixed

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Closes #

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 💥 Breaking change (would change existing behaviour)
  • 🕳️ Soundness fix (fixes a checker/proof false-negative)
  • 📖 Documentation
  • 🧹 Refactor / tech debt (behaviour-preserving)
  • ⚡ Performance
  • 🔧 Build / CI / tooling

How has this been verified?

Checklist

  • My commits are signed (git commit -S).
  • I ran the project's own checks/tests locally and they pass.
  • New files carry the correct SPDX-License-Identifier (code/config MPL-2.0,
    prose CC-BY-SA-4.0); I did not relicense existing files.
  • Docs are updated, and no public claim now overstates what the code does.
  • I have not introduced a soundness hole (or I have flagged where I might have).

Notes for reviewers

hyperpolymath and others added 8 commits October 5, 2026 04:10
MIGRATION-1058 M3 (standards#1058, issue #C). A template is never loaded, so
it must not claim the reserved `.k9.ncl` component suffix. The three trust-tier
templates keep their TODO placeholders — that is the point of a template — and
become `template-*.k9.ncl.in`, outside every scope that reads `*.k9`/`*.k9.ncl`
as a loadable component (the pre-commit hook, the corpus walk, CI's Nickel
pathspec).

`setup-repo.k9.ncl` keeps the suffix because it IS a component, and is fixed
as one: its grant pays for all three security flags (`net.fetch`, `fs.write`,
`process.spawn` — K9-S007/§8.4), `side_effects` names what the recipes
actually do (K9-S010/§6.5), and a `signature` block is present
(K9-S009/§10.1) whose header says, per §10.2, that presence is not
verification.

- ledger: 17 → 13 — the four M3 entries removed, shrink-only ratchet intact
- docs repointed: svc/k9 README, contractiles README + INDEX.a2ml, canonical
  templates, CONTRACTILE-SPEC, K9-CONTRACT-SPEC, ADR-001 amendment note
- REGISTRY.a2ml regenerated with `just registry` (also refreshes three hashes
  already stale on main: 1-formats/k9, 2-protocols/axel, form-fill-provenance)

Verified: --self-test passes; --fixtures 5 positive / 21 negative / 0
failures; L1 clean on the four svc/k9 components; the hook is green for this
change set (1 conforming, 0 grandfathered). The corpus hook still exits 1 on
the pre-existing contractile (#A) and axel (#D) failures, untouched here.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Resolve conflict in k9-contract-debt.txt by accepting PR version
(removes 4 template entries, count 13).

Generated by Mistral Vibe.
Co-Authored-By: Mistral Vibe <vibe@mistral.ai>
Remove k9 from INDEX.a2ml verb registry (now only 6 verbs, no exceptions).
Update README.adoc and CONTRACTILE-SPEC.adoc to reflect k9 relocation to
.machine_readable/svc/k9/ estate-wide. Rename [[k9-exception]] anchor to
[[k9-relocation]] for clarity.

Addresses CodeRabbit review comment on PR #1148 lines +176-+181.

Signed-off-by: Mistral Vibe <vibe@mistral.ai>
Resolve merge conflicts by accepting main branch changes:
- Remove k9 exception from contractile registry (INDEX.a2ml)
- Update README.adoc to reflect k9 relocation
- Update CONTRACTILE-SPEC.adoc tree diagram and registry description
- Fix subpath pin in codeql-reusable.yml (init@ → @)

These changes align with ADR-001 which relocated k9 to .machine_readable/svc/k9/
and removes it from the contractile verb registry.
This fixes the merge conflict by accepting the main branch's removal of k9
exception from the contractile registry, per ADR-001.

- INDEX.a2ml: k9 removed from [[verbs]] section
- README.adoc: Updated to reflect k9 relocation to .machine_readable/svc/k9/
- CONTRACTILE-SPEC.adoc: Updated tree diagram and registry description
- codeql-reusable.yml: Fixed subpath pin (init@ → @)
Resolve conflicts by accepting main branch changes for:
- REGISTRY.a2ml (hash updates from #1151, #1149)
- k9-contract-debt.txt (ledger updates)
- k9_contract.ncl (template file references)

This incorporates all changes from main into the PR branch.
@coderabbitai

coderabbitai Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 55 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: c6f999d5-a310-46fa-b445-f4a2515a31bd
📥 Commits

Reviewing files that changed from the base of the PR and between 8ffcaf6 and 9554fed.

📒 Files selected for processing (15)
  • .machine_readable/REGISTRY.a2ml
  • .machine_readable/k9-contract-debt.txt
  • .machine_readable/svc/k9/README.adoc
  • .machine_readable/svc/k9/examples/setup-repo.k9.ncl
  • .machine_readable/svc/k9/template-hunt.k9.ncl.in
  • .machine_readable/svc/k9/template-kennel.k9.ncl.in
  • .machine_readable/svc/k9/template-yard.k9.ncl.in
  • 1-formats/contractiles/CANONICAL-TEMPLATES.adoc
  • 1-formats/k9/spec/K9-CONTRACT-SPEC.adoc
  • 1-formats/k9/spec/MIGRATION-1058.adoc
  • 1-formats/k9/spec/contract/k9_contract.ncl
  • 1-formats/k9/tools/fixtures/invalid/L1-K9-S003-todo-component-type.k9.ncl
  • docs/ADR-001-k9-relocation-to-svc.adoc
  • scripts/check-lock-sync.sh
  • scripts/tests/check-lock-sync-test.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath enabled auto-merge (squash) October 5, 2026 06:48
@hyperpolymath
hyperpolymath disabled auto-merge October 5, 2026 06:48
@hyperpolymath
hyperpolymath merged commit 44ca61e into main Oct 5, 2026
35 of 42 checks passed
@hyperpolymath
hyperpolymath deleted the pr-1148-fixed branch October 5, 2026 06:48
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37274262229

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ERROR   K9-N001 [L2] 1-formats/k9/tools/fixtures/valid/extension-fields.k9.ncl: component violates the K9.Component contract: error: contract broken by a value        extra fields `failure_mode_defenses`, `execution`    ┌─ /home/runner/work/standards/standards/1-formats/k9/tools/fixtures/valid/.k9-validate.8996.27569.driver.ncl:3:1    │  3 │ k9_doc | K9.Component 
FAIL extension-fields.k9.ncl should conform (exit 1)
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 1 failure(s)

@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

❌ The last analysis has failed.

See analysis details on SonarQube Cloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant