Skip to content

fix(k9): reopen §5.5 tails on component records (D310, #1165) - #1175

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/k9-component-open-tails
Oct 6, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/k9-component-open-tails

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 6, 2026 •

Copy link
Copy Markdown
Owner

Summary

This turns K9-SVC Contractile Validation green on main.

#1154 removed the .. tails from the five component-facing records in 1-formats/k9/spec/contract/k9_contract.ncl (Component, Pedigree, Security, Metadata, Signature), and deleted the comments that explained them. Nickel record contracts are closed by default, so the contract again rejected extension fields that SPEC §5.5 permits ("Unknown fields anywhere | PERMITTED"). As a result the positive control tools/fixtures/valid/extension-fields.k9.ncl failed K9-N001 at L2, which made main red.

Owner ruling D310 (standards#787, 2026-10-06): K9.Component is an open record. This PR restores the tails and their rationale exactly as #1149 wrote them. It keeps #1154's one real improvement, the .k9.ncl.in template wording. HuntEvidence stays closed (§9.2 host evidence, where a misspelt field must be an error), and its comment saying so is restored.

Closes #1165

Type of change

  • 🐛 Bug fix (non-breaking change that fixes an issue): contract conformance to §5.5; contract_version stays 1.0.0, because the prose never changed.
  • ✨ New feature: no
  • 💥 Breaking change: no. This only widens acceptance to what §5.5 already permits.
  • 🕳️ Soundness fix: not a checker false-negative. It fixes a false-positive rejection.
  • 📖 Documentation: comments only, restored with the code they explain
  • 🧹 Refactor: no
  • ⚡ Performance: no
  • 🔧 Build / CI / tooling: no workflow change

📌 New pins

Head SHA: 51321ad. This PR adds or changes no action pins, actions.lock entries, lockfiles or container digests.

How has this been verified?

Run locally with nickel 1.17.0. CI pins 1.18.0.

  • nickel typecheck 1-formats/k9/spec/contract/k9_contract.ncl → rc 0
  • 1-formats/k9/tools/k9-validate.sh --strict --fixtures fixtures → fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)
  • The control can fail. With main's contract (git show origin/main:…) swapped back in, the same command gives ERROR K9-N001 [L2] fixtures/valid/extension-fields.k9.ncl: … extra fields failure_mode_defenses, execution → 1 failure(s), the exact CI error on main.

#1165 acceptance item 3 asks that the fix not open the contract wholesale. The tails admit only unknown names. Known fields keep their contracts, as the negatives that still fail show:

  • L2-K9-N001-wrong-field-type (a declared field with a wrong type, rejected at L2)
  • L2-K9-N001-two-segment-version
  • L1-K9-S004-unknown-leash (an unknown tag in the closed SecurityLevel set)
  • HuntEvidence remains closed.

§5.5's last clause (an unknown field never relaxes §8/§9) is enforced by the validator's capability arithmetic, which this PR leaves unchanged (K9-S007/S008 negatives pass).

Checklist

  • My commits are signed: git log --format=%G? → G.
  • I ran the project's own checks/tests locally and they pass: the pre-commit suite and k9-validate.sh --strict --fixtures, as above.
  • SPDX: no new files; the existing MPL-2.0 header is untouched.
  • Docs are updated, and no public claim overstates the code. The restored comments describe the restored behaviour.
  • No soundness hole: see item 3 above.

Notes for reviewers

  • Pr 1148 fixed #1154 was titled "Pr 1148 fixed" with an empty template, so its removal of the tails did not look deliberate. D310 now settles the direction.
  • Local nickel is 1.17.0 against CI's 1.18.0. CI is the authority.

Pre-existing reds, deferred (§5c item 3)

K9-SVC contractile validation goes from failure on the base 0ae8b773 to success here. The other 7 reds on this head are all red on that base as well, and none of them reads 1-formats/k9/:

🤖 Generated with Claude Code

https://claude.ai/code/session_01D6JVLvmCeSFGcY6jSNesbL

#1154 removed the `..` tails from Component, Pedigree, Security, Metadata
and Signature, together with the comments explaining them. Nickel records
are closed by default, so the contract again rejected extension fields that
SPEC §5.5 permits ("Unknown fields anywhere | PERMITTED"). The positive
control fixtures/valid/extension-fields.k9.ncl failed K9-N001 at L2, and
K9-SVC was red on main.

This restores the tails and their rationale. It keeps #1154's later
`.k9.ncl.in` template wording. HuntEvidence stays closed: §9.2 host
evidence, where a misspelt field must be an error.

Owner ruling D310 (standards#787): K9.Component is an open record.

Closes #1165

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01D6JVLvmCeSFGcY6jSNesbL
@coderabbitai

coderabbitai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 9bb83370-5822-41f9-93bf-ccfde8236d34
📥 Commits

Reviewing files that changed from the base of the PR and between 0ae8b77 and 51321ad.

📒 Files selected for processing (1)
  • 1-formats/k9/spec/contract/k9_contract.ncl
 ________________________________________
< CI is red. I'm also red. We match now. >
 ----------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

K9 contract conformance

run https://github.com/hyperpolymath/standards/actions/runs/37520244341

K9 normative contract typecheck

k9_contract.ncl typechecks

K9 contract self-test

== the bash mirrors cannot drift from the normative contract ==
ok   leash_levels mirrors k9_contract.ncl
ok   core_capabilities mirrors k9_contract.ncl
ok   contract_version mirrors k9_contract.ncl
ok   schema_major mirrors k9_contract.ncl
== capability arithmetic (§8) ==
ok   capability_ok fs.read accepted
ok   capability_ok rollback.apply accepted
ok   capability_ok x-acme.gpu.alloc accepted
ok   capability_ok x-acme rejected
ok   capability_ok x-.gpu rejected
ok   capability_ok fs.delete rejected
ok   capability_ok  rejected
== the extractor ==
ok   extracts pedigree.security.leash
ok   extracts pedigree.component_type
ok   extracts pedigree.metadata.name
ok   pedigree leash is not reported as top-level leash
ok   required_capabilities for a quiet component
ok   required_capabilities follows allow_network
== the envelope strip keeps line numbers (§3.6) ==
ok   line 1 becomes a comment
ok   line count is preserved
ok   schema_version stays on line 5
== L3: signature presence is not verification (§10) ==
ok   no verifier -> K9-C001 is SKIPPED, never a pass
ok   the skip states presence does not authorise 'Hunt
ok   verifier accepts -> verdict 'Verified, no K9-C001 finding
ok   verifier refuses -> K9-C001 error, verdict 'Rejected
== the fixture runner's attribution cannot be fooled by a filename ==
ok   every extracted finding is well-formed rule+layer
ok   the rule that really fired is attributed
ok   a rule named only in the filename is NOT attributed
ok   K9-C001 is present as a skipped finding
ok   and that same finding is NOT extractable as a rejection
== no Nickel reserved word is used as an identifier ==
ok   the contract and all 27 fixtures avoid Nickel's reserved words

self-test: all assertions passed

K9 conformance fixtures

== positive controls (must pass) ==
ok   extension-capability.k9.ncl
ok   extension-fields.k9.ncl
ok   hunt-fully-granted.k9.ncl
ok   kennel-data.k9.ncl
ok   library-base.ncl
ok   yard-typed-config.k9.ncl

== negative controls (must fail, by the named rule) ==
ok   L0-K9-E001-bad-magic.k9.ncl (rejected by K9-E001 at L0)
ok   L0-K9-E002-nul-byte.k9.ncl (rejected by K9-E002 at L0)
ok   L0-K9-E003-crlf.k9.ncl (rejected by K9-E003 at L0)
ok   L0-K9-E004-no-spdx.k9.ncl (rejected by K9-E004 at L0)
ok   L0-K9-E005-unclaimed-body.k9.ncl (rejected by K9-E005 at L0)
ok   L0-K9-S012-library-with-pedigree.ncl (rejected by K9-S012 at L0)
ok   L0-K9-S014-stray-leash.ncl (rejected by K9-S014 at L0)
ok   L1-K9-S001-no-pedigree.k9.ncl (rejected by K9-S001 at L1)
ok   L1-K9-S002-wrong-major.k9.ncl (rejected by K9-S002 at L1)
ok   L1-K9-S003-todo-component-type.k9.ncl (rejected by K9-S003 at L1)
ok   L1-K9-S004-unknown-leash.k9.ncl (rejected by K9-S004 at L1)
ok   L1-K9-S005-missing-name.k9.ncl (rejected by K9-S005 at L1)
ok   L1-K9-S006-unknown-capability.k9.ncl (rejected by K9-S006 at L1)
ok   L1-K9-S007-ungranted-flag.k9.ncl (rejected by K9-S007 at L1)
ok   L1-K9-S008-hunt-signature-not-required.k9.ncl (rejected by K9-S008 at L1)
ok   L1-K9-S009-hunt-no-signature-block.k9.ncl (rejected by K9-S009 at L1)
ok   L1-K9-S010-hunt-empty-side-effects.k9.ncl (rejected by K9-S010 at L1)
ok   L1-K9-S011-recipes-at-yard.k9.ncl (rejected by K9-S011 at L1)
ok   L1-K9-S013-dangling-import.k9.ncl (rejected by K9-S013 at L1)
ok   L2-K9-N001-two-segment-version.k9.ncl (rejected by K9-N001 at L2)
ok   L2-K9-N001-wrong-field-type.k9.ncl (rejected by K9-N001 at L2)

fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)

K9 corpus conformance (L2)

[validate-k9] debt rhodium-standard-repositories/rsr-compliance-checklist.k9.ncl (fail) — K9-N001 K9-S004 K9-S005 K9-S014 (grandfathered; touching it makes it blocking)
[validate-k9] 14 conforming, 1 grandfathered (layer all, contract v1.0.0)

@sonarqubecloud

sonarqubecloud Bot commented Oct 6, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit 617f3bc into main Oct 6, 2026
59 of 67 checks passed
@hyperpolymath
hyperpolymath deleted the fix/k9-component-open-tails branch October 6, 2026 19:38
@hyperpolymath hyperpolymath mentioned this pull request Oct 7, 2026
13 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

K9-SVC red on main: valid fixture extension-fields.k9.ncl breaks the K9.Component contract

1 participant