Repository navigation
fix(k9): reopen §5.5 tails on component records (D310, #1165) - #1175
Merged
Merged
Conversation
#1154 removed the `..` tails from Component, Pedigree, Security, Metadata and Signature, together with the comments explaining them. Nickel records are closed by default, so the contract again rejected extension fields that SPEC §5.5 permits ("Unknown fields anywhere | PERMITTED"). The positive control fixtures/valid/extension-fields.k9.ncl failed K9-N001 at L2, and K9-SVC was red on main. This restores the tails and their rationale. It keeps #1154's later `.k9.ncl.in` template wording. HuntEvidence stays closed: §9.2 host evidence, where a misspelt field must be an error. Owner ruling D310 (standards#787): K9.Component is an open record. Closes #1165 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01D6JVLvmCeSFGcY6jSNesbL
Contributor
|
Note Currently processing new changes in this PR. This may take a few minutes, please wait... ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
K9 contract conformancerun https://github.com/hyperpolymath/standards/actions/runs/37520244341 K9 normative contract typecheckK9 contract self-testK9 conformance fixturesK9 corpus conformance (L2) |
|
13 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
This turns
K9-SVC Contractile Validationgreen onmain.#1154 removed the
..tails from the five component-facing records in1-formats/k9/spec/contract/k9_contract.ncl(Component,Pedigree,Security,Metadata,Signature), and deleted the comments that explained them. Nickel record contracts are closed by default, so the contract again rejected extension fields that SPEC §5.5 permits ("Unknown fields anywhere | PERMITTED"). As a result the positive controltools/fixtures/valid/extension-fields.k9.nclfailed K9-N001 at L2, which made main red.Owner ruling D310 (standards#787, 2026-10-06):
K9.Componentis an open record. This PR restores the tails and their rationale exactly as #1149 wrote them. It keeps #1154's one real improvement, the.k9.ncl.intemplate wording.HuntEvidencestays closed (§9.2 host evidence, where a misspelt field must be an error), and its comment saying so is restored.Closes #1165
Type of change
contract_versionstays 1.0.0, because the prose never changed.📌 New pins
Head SHA: 51321ad. This PR adds or changes no action pins,
actions.lockentries, lockfiles or container digests.How has this been verified?
Run locally with
nickel 1.17.0. CI pins 1.18.0.nickel typecheck 1-formats/k9/spec/contract/k9_contract.ncl→ rc 01-formats/k9/tools/k9-validate.sh --strict --fixtures fixtures→fixtures: 6 positive, 21 negative (0 needing nickel), 0 failure(s)git show origin/main:…) swapped back in, the same command givesERROR K9-N001 [L2] fixtures/valid/extension-fields.k9.ncl: … extra fields failure_mode_defenses, execution→1 failure(s), the exact CI error on main.#1165 acceptance item 3 asks that the fix not open the contract wholesale. The tails admit only unknown names. Known fields keep their contracts, as the negatives that still fail show:
L2-K9-N001-wrong-field-type(a declared field with a wrong type, rejected at L2)L2-K9-N001-two-segment-versionL1-K9-S004-unknown-leash(an unknown tag in the closedSecurityLevelset)HuntEvidenceremains closed.§5.5's last clause (an unknown field never relaxes §8/§9) is enforced by the validator's capability arithmetic, which this PR leaves unchanged (K9-S007/S008 negatives pass).
Checklist
git log --format=%G?→G.k9-validate.sh --strict --fixtures, as above.Notes for reviewers
Pre-existing reds, deferred (§5c item 3)
K9-SVC contractile validationgoes from failure on the base0ae8b773to success here. The other 7 reds on this head are all red on that base as well, and none of them reads1-formats/k9/:Call CI Pipeline / Haskell: no.cabal/cabal.projectat the root. Deferred to Two unowned reds on #1160: self-ci Haskell job builds at root with no cabal.project; registry drift on main #1161.Call CI Pipeline / Pipeline report: rolls up the Haskell red above. Deferred to Two unowned reds on #1160: self-ci Haskell job builds at root with no cabal.project; registry drift on main #1161.Registry + topology in sync:REGISTRY.a2mldrift on main. Deferred to Two unowned reds on #1160: self-ci Haskell job builds at root with no cabal.project; registry drift on main #1161.Repo self-tests:build-registry-test.sh7 passed, 2 failed, from the same registry drift (as Self Test red on main: direct push 5b56aec0 overwrote kyaml-format.sh with a different exit contract #1174 attributes it). Deferred to Two unowned reds on #1160: self-ci Haskell job builds at root with no cabal.project; registry drift on main #1161.governance / Allowlist Preflight:swatinem/rust-cacheis not covered. Deferred to Allowlist Preflight red on main: check-allowed-actions.sh compares owner/repo case-sensitively #1172.governance / Validate Hypatia Baseline: 12 new findings since feat(k9): normative Nickel contract, canonical validator, conformance suite (#1058, D173) #1143. Deferred to Hypatia baseline and scan red on main: 12 new findings since #1143 #1173.scan / Hypatia Neurosymbolic Analysis: the same 12 findings. Deferred to Hypatia baseline and scan red on main: 12 new findings since #1143 #1173.🤖 Generated with Claude Code
https://claude.ai/code/session_01D6JVLvmCeSFGcY6jSNesbL