Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
87 commits
Select commit Hold shift + click to select a range
b2fe9f2
fix(site): render a three-backtick fence indented one to three spaces
REPPL Sep 26, 2026
5a599c4
chore: resolve iss-2609251600023777 — an indented three-backtick fenc…
REPPL Sep 26, 2026
2a05a0e
fix(site): report the output directory without the home path
REPPL Sep 26, 2026
e0a5f82
chore(capture): the lifeboat and launch reports carry absolute direct…
REPPL Sep 26, 2026
09f7dcd
fix(lifeboat): report directories with the home redacted
REPPL Sep 26, 2026
9334ed2
chore: resolve iss-2608291957114882 and iss-2609261848326365 — site a…
REPPL Sep 26, 2026
52329d9
feat(site): the health page carries the disclosure rate
REPPL Sep 26, 2026
fd59d11
chore: resolve iss-2608231008315498 — the contributors rethink is com…
REPPL Sep 26, 2026
5b56c19
feat(site): read the community-health files from .github/ as the forg…
REPPL Sep 26, 2026
4d4bbfb
refactor: move CONTRIBUTING.md and SECURITY.md into .github/
REPPL Sep 26, 2026
085ad84
chore: resolve iss-2608270540523859 — the community-health files live…
REPPL Sep 26, 2026
6c9718e
chore(capture): the board, memory lint and launch archive report abso…
REPPL Sep 26, 2026
a321dff
chore(capture): the launch bundle names every payload file absolutely
REPPL Sep 26, 2026
693e1a7
refactor(fsutil): promote the site display rule to fsutil.DisplayPath
REPPL Sep 26, 2026
ae58e92
fix(launch): report the payload, archive and bundle paths without the…
REPPL Sep 26, 2026
c5eab8b
fix(core): name the board's directory with the home redacted
REPPL Sep 26, 2026
dc6ff0c
fix(memory): report lint's paths relative to the repository
REPPL Sep 26, 2026
91b4cea
chore: resolve five absolute-path reports — launch, the board and mem…
REPPL Sep 26, 2026
989f69a
fix(memory): print the board's drift line on the text render
REPPL Sep 26, 2026
c5576af
chore: resolve iss-2609091647582259 — the memory board prints its drift
REPPL Sep 26, 2026
7d5785b
fix(memory): prove the local tier before lint writes its run log
REPPL Sep 26, 2026
934ae94
fix(capture,reading): prove the local tier before the drift receipt a…
REPPL Sep 26, 2026
dc10dd1
chore: resolve iss-2609260948440803 — the local-tier run logs are pro…
REPPL Sep 26, 2026
b156bb1
fix(lifeboat): one render discipline for every markdown file the life…
REPPL Sep 26, 2026
8d27662
chore: resolve iss-2609251355497247 — the lifeboat renders through on…
REPPL Sep 26, 2026
f5c5b43
chore: capture iss-2609262148072415 — memory lint's report.md cleans …
REPPL Sep 26, 2026
bc51fd4
fix(memory): clean lint's report.md fields as markdown, not only for …
REPPL Sep 26, 2026
efd06f7
chore: resolve iss-2609262148072415 — memory lint's report.md cleans …
REPPL Sep 26, 2026
9b2fe2a
chore(fsutil): carry ProbeRealDirAll from main, byte-identical
REPPL Sep 26, 2026
862809b
fix(lifeboat): prove every operand against a symlinked ancestor insid…
REPPL Sep 26, 2026
b794114
refactor(gitutil): make the operand proof shared, and keep absolute p…
REPPL Sep 26, 2026
43089d3
chore: capture iss-2609262156124513 — history reconstruct proves --ou…
REPPL Sep 26, 2026
b2bf22f
fix(history): prove reconstruct's --out against a symlinked ancestor
REPPL Sep 26, 2026
f6b82bf
chore: resolve iss-2609262156124513 — reconstruct proves its --out di…
REPPL Sep 26, 2026
b28923c
chore: re-stamp three resolutions after the reword, and keep a sub-ve…
REPPL Sep 26, 2026
f9b06e7
chore: keep a record's prose from citing an id this branch does not c…
REPPL Sep 26, 2026
803f0cf
chore: capture iss-2609262231500173 — reading assemble follows an abs…
REPPL Sep 26, 2026
6412b80
fix(reading): prove every spelling of assemble's --out against a syml…
REPPL Sep 26, 2026
e475752
chore: resolve iss-2609262231500173 — assemble proves an absolute --out
REPPL Sep 26, 2026
cc3bde0
chore: capture iss-2609262235543552 — ProveOperandDir trusts its call…
REPPL Sep 26, 2026
58df144
fix(gitutil): absolutise the operand inside ProveOperandDir
REPPL Sep 26, 2026
6d03f68
chore: resolve iss-2609262235543552 — ProveOperandDir holds its own a…
REPPL Sep 26, 2026
a6378d0
chore: capture iss-2609262237352137 — a lifeboat block value can defi…
REPPL Sep 26, 2026
791a582
chore: capture iss-2609262237415400 — the lifeboat block escape break…
REPPL Sep 26, 2026
70fefd5
fix(lifeboat): escape a leading bracket so a block value cannot defin…
REPPL Sep 26, 2026
6e01cb3
chore: resolve iss-2609262237352137 — a lifeboat block value cannot d…
REPPL Sep 26, 2026
4df17e7
fix(lifeboat): leave a balanced leading code span unescaped in a bloc…
REPPL Sep 26, 2026
15ca2dd
chore: resolve iss-2609262237415400 — a balanced leading code span su…
REPPL Sep 26, 2026
d33ffba
chore: capture iss-2609262241109876 — ideate's block escape shows a l…
REPPL Sep 26, 2026
08efdae
fix(ideate): escape an ordered-list idea before its delimiter, not it…
REPPL Sep 26, 2026
4d23eea
chore: resolve iss-2609262241109876 — ideate's ordered-marker escape …
REPPL Sep 26, 2026
c3f2e66
fix(guard): read a kill by the search that fed it, and by user or ter…
REPPL Sep 26, 2026
2473d20
chore: capture the kill spellings the search and owner readings leave
REPPL Sep 26, 2026
6a3ab97
chore: resolve iss-2609251640452031 — the guard reads a kill by the s…
REPPL Sep 26, 2026
89e98c8
fix(cli): a flag-group refusal on the hook plane fails open at exit 1
REPPL Sep 26, 2026
d568f5f
chore: resolve iss-2609251755278758 — the hook plane re-codes a flag-…
REPPL Sep 26, 2026
09ce02b
docs(guard): name the feed count by the method that keeps it
REPPL Sep 26, 2026
68be007
chore: capture iss-2609262309556167 — the site renderer opens a fence…
REPPL Sep 26, 2026
7f99136
fix(mdrender): open a fence only where mdrecord's rule opens one
REPPL Sep 26, 2026
60a7256
chore: resolve iss-2609262309556167 — the renderer opens a fence only…
REPPL Sep 26, 2026
93f03af
chore: capture iss-2609262322244502 — the renderer's inline code span…
REPPL Sep 26, 2026
4e93aab
chore: describe iss-2609262322244502's input in words so the site ren…
REPPL Sep 26, 2026
f671a86
chore: record the xargs-string kill spellings on the kill-readings ca…
REPPL Sep 26, 2026
4cc1290
fix(guard): follow a kill's search through groups and shell strings
REPPL Sep 26, 2026
419d7bf
chore: narrow the kill-readings capture to the ruling-bound spellings
REPPL Sep 26, 2026
3a4ba0b
chore: capture iss-2609262350446885 — two more walks pair backticks o…
REPPL Sep 27, 2026
e275afc
fix(mdrender): pair every code span through one CommonMark pairer
REPPL Sep 27, 2026
da875bc
fix(lint,lab): pair backtick runs through termsafe's pairer
REPPL Sep 27, 2026
f6e28d3
test(termsafe): refuse a second code-span pairer
REPPL Sep 27, 2026
1ebaafb
chore: resolve iss-2609262322244502 — one code-span pairer for every …
REPPL Sep 27, 2026
e4ce596
chore: resolve iss-2609262350446885 — lint and lab pair runs through …
REPPL Sep 27, 2026
f61544a
chore: capture the review's group-input and BSD xargs findings
REPPL Sep 27, 2026
8be1fc0
chore: capture two siblings found fixing the group-input reading
REPPL Sep 27, 2026
a9f1676
fix(guard): hand a group's piped input and a string's redirects on
REPPL Sep 27, 2026
c58c0de
chore: resolve iss-2609270028388291 and iss-2609270036259517 — group …
REPPL Sep 27, 2026
88d92df
fix(guard): step over BSD xargs's -J, -R and -S values
REPPL Sep 27, 2026
d5f3d77
chore: resolve iss-2609270028432249 — BSD xargs value flags
REPPL Sep 27, 2026
d833a6f
test(guard): drop the names no pkill takes, and pin the args reader
REPPL Sep 27, 2026
5d7a5c5
merge: land the site/paths/fs/code-span chain (fix/drain-code-span e4…
REPPL Sep 28, 2026
5d8ef4e
chore: resolve iss-2609261232464351 — lifeboat operands proved at eve…
REPPL Sep 28, 2026
efe074c
merge: land the guard cluster (fix/drain-guard d833a6f60)
REPPL Sep 28, 2026
16d464b
chore: recalibrate the reading windows at the integration tip
REPPL Sep 28, 2026
c250bc7
fix(lint): the name gate reads the contribution guide in .github/
REPPL Sep 28, 2026
d7ada1b
chore: re-measure the reading windows after the name-root fix
REPPL Sep 28, 2026
1292599
test(banlist): the public-entry fixtures create the guide in .github/
REPPL Sep 28, 2026
0dd22bd
merge: bring main (#735) into the integration branch
REPPL Sep 28, 2026
c28ee99
chore: re-measure the reading windows after bringing main in
REPPL Sep 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 9 additions & 9 deletions .abcd/config/reading-presets.json
Original file line number Diff line number Diff line change
Expand Up @@ -61,9 +61,9 @@
],
"window": {
"tokens_est": 1340000,
"measured_tokens_est": 1322032,
"measured_bytes": 5089824,
"measured_at": "b727b969a992532a9e67adb23734914a4f331513"
"measured_tokens_est": 1325292,
"measured_bytes": 5102376,
"measured_at": "0dd22bdc043952a36800be0d41d72ac65b23055d"
}
},
"entailment": {
Expand Down Expand Up @@ -133,9 +133,9 @@
],
"window": {
"tokens_est": 390000,
"measured_tokens_est": 382812,
"measured_bytes": 1473830,
"measured_at": "b727b969a992532a9e67adb23734914a4f331513"
"measured_tokens_est": 383234,
"measured_bytes": 1475453,
"measured_at": "0dd22bdc043952a36800be0d41d72ac65b23055d"
}
},
"comparative": {
Expand Down Expand Up @@ -217,9 +217,9 @@
],
"window": {
"tokens_est": 1350000,
"measured_tokens_est": 1331068,
"measured_bytes": 5124612,
"measured_at": "b727b969a992532a9e67adb23734914a4f331513"
"measured_tokens_est": 1334328,
"measured_bytes": 5137164,
"measured_at": "0dd22bdc043952a36800be0d41d72ac65b23055d"
}
}
}
Expand Down
1 change: 1 addition & 0 deletions .abcd/development/brief/04-surfaces/02-disembark.md
Original file line number Diff line number Diff line change
Expand Up @@ -86,6 +86,7 @@ INVENTORY (read-only)
DESTINATION SAFETY GATE
refuse unless <dest> is absent, empty, or carries a parseable _provenance.json
→ never overwrite a directory abcd did not produce (adr-35)
refuse a <dest> reached through a symlink at any level inside a checkout
│
▼
SECRET SCAN (before any write)
Expand Down
5 changes: 4 additions & 1 deletion .abcd/development/brief/04-surfaces/03-embark.md
Original file line number Diff line number Diff line change
Expand Up @@ -88,7 +88,10 @@ scaffolder and no model sit in the write path.
specs — plus the report-only files that inform the run. The lifeboat is
untrusted input: embark verifies its `manifest_sha256` against the on-disk
tree, over every hashed file, and refuses a symlink or an oversize file
anywhere inside. A tampered hashed record or an added stray file is refused.
anywhere inside. Both operands, the lifeboat and the target, are refused
when they are reached through a symlink at any level inside a checkout, the
one place a commit can plant one; outside every checkout the path is the
operator's own and is taken as given. A tampered hashed record or an added stray file is refused.
The post-pack synthesis layer sits outside the manifest seal deliberately,
because it is written after the hash: those files carry their own per-entry
integrity (cite-or-be-dropped, the registered-verdict gate) rather than the
Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/04-surfaces/04-launch.md
Original file line number Diff line number Diff line change
Expand Up @@ -584,7 +584,7 @@ fingerprinted — not the unversioned working tree.
older harnesses fail to install it, and very old ones fail to load the
marketplace. The install instructions and the release notes state the floor.
- **Contributors** load the plugin from their own checkout rather than through a
second catalog entry (`CONTRIBUTING.md`).
second catalog entry (`.github/CONTRIBUTING.md`).

**Anti-drift.** The two manifests in the artefact describe one release, so the
version at the selected location and the marketplace entry must agree. A
Expand Down
12 changes: 7 additions & 5 deletions .abcd/development/brief/04-surfaces/07-memory.md
Original file line number Diff line number Diff line change
Expand Up @@ -44,11 +44,13 @@ surface contract: what the user types and what happens.

**Bare `/abcd:memory`** renders the store's state and nothing else: how many
pages there are by class, when the last ingest happened, the recent
contradictions, and per-source quotation-budget headroom. It never mutates and
never rebuilds an index. The JSON render carries one element the text render
drops, a `drift` list saying that the catalogue or the contradictions register
no longer hash-matches what the store's pages would render, so a reader knows
the numbers are stale rather than wrong. Headroom is read-only in the same
contradictions, per-source quotation-budget headroom, and drift. It never
mutates and never rebuilds an index. Drift is a line saying that the catalogue
or the contradictions register no longer hash-matches what the store's pages
would render, naming the ingest as the verb that rebuilds it, so a reader
knows the numbers are stale rather than wrong; the text board prints
each line in the words the JSON's `drift` list carries, and a current store
prints none. Headroom is read-only in the same
spirit: a fresh index shows per-source warn and block headroom, a drifted one
says to run the lint, and an absent or unreadable one says the headroom is
unavailable rather than guessing at it.
Expand Down
4 changes: 3 additions & 1 deletion .abcd/development/brief/04-surfaces/11-history.md
Original file line number Diff line number Diff line change
Expand Up @@ -111,7 +111,9 @@ ahoy's registry stays under `~/.abcd/history/` and holds no transcripts.
- **Reconstructing** — render one session, named by its id, as **one
self-contained artefact** (`<session>.md`) and **one telemetry file**
(`<session>.telemetry.json`), written into an output directory (default the working
directory) or to stdout. The artefact is Markdown because its
directory) or to stdout. The directory must already exist, and it is refused
when it is reached through a symlink at any level inside a checkout; outside
every checkout the path is the operator's own. The artefact is Markdown because its
consumer is a model being handed the session as context; it names its records
by basename and carries no store path, so it reads with the store gone.

Expand Down
14 changes: 12 additions & 2 deletions .abcd/development/brief/04-surfaces/17-guard.md
Original file line number Diff line number Diff line change
Expand Up @@ -260,7 +260,15 @@ command string handed to a shell is opened and read. A git alias declared on the
command git would actually run is what gets checked. A commit or push that
moves `core.hooksPath` for itself is read as skipping its hooks, which is what
it does. A delete chained after `pushd` or `popd` is read as one chained after
`cd`. In a repository with more
`cd`. A `kill` handed what a process search prints, in a substitution or
piped into `xargs kill`, is read as the kill by name it is — through a group
and into one, whose every command is read as handed what is piped into it,
through a shell string that runs the search, and into a shell string `xargs`
runs or a pipe or redirect feeds, whose every command is read as handed its
input — and a `pkill` or
`killall` selecting by user, group or terminal, its value written apart or
attached, as selecting every session under the account; `pkill`'s signal name
is read as a signal first, in any case. In a repository with more
than one worktree, a stash or pop that does not name its entry is warned about,
because the stash stack is shared across worktrees. Where the reading is a
guess, over-blocking is the direction the guard takes.
Expand All @@ -273,7 +281,9 @@ table does not name; a REST
path an entry names by its root segment when the host serves that API under a
prefix; an IFS the shell already holds when the line starts, or gains during the line
through a name the guard does not read (`declare $(echo I)FS=x`, a sourced file),
since every line is read from the default IFS; a payload inside a non-shell interpreter such as `python -c`, which is
since every line is read from the default IFS; a pid list a kill reads through a variable or a file, or from a `ps |
grep` chain;
a payload inside a non-shell interpreter such as `python -c`, which is
one opaque token and today a silent allow; and any dangerous form no entry
describes. Nor does an allow see through a parameter expansion that carries no
substitution (`$VAR`, `${VAR:-git}`), wherever it stands — as the command's
Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/brief/04-surfaces/20-banlist.md
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,7 @@ markdown, with `exempt_paths` excusing a historical tree as it does under
blocks, which the rest of the family skips by default: a fenced example is not
prose, but a fence is published as readily as prose, so an entry that means to
skip fences declares `skip_code_fences: true`. This repository's `name_roots` are `.abcd`, `AGENTS.md`,
`CONTRIBUTING.md` and `scripts`, and its `exempt_paths` excuse the
`.github/CONTRIBUTING.md` and `scripts`, and its `exempt_paths` excuse the
configuration itself (whose entries spell every ban), the research data and the
review archive.

Expand Down
7 changes: 4 additions & 3 deletions .abcd/development/brief/04-surfaces/22-site.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,9 +151,10 @@ The build reads the repository and nothing else — no network at any point. Its
inputs are the composition declaration and the interface-string allowlist; the
record itself, read through the record-lint engine's own frontmatter scan so there
is one parser rather than two; the bibliography and the glossary through their own
parsers; one pass of git history; `CHANGELOG.md`; the two root prose files whose
text the site publishes, which are the acknowledgements behind the references page
and the authorship section of the contribution guide behind the contributors page;
parsers; one pass of git history; `CHANGELOG.md`; the two prose files whose
text the site publishes, which are the acknowledgements at the root behind the
references page and the authorship section of the contribution guide in `.github/`
behind the contributors page;
and `docs/` with its committed assets. It writes the landing page, the record explorer, the machine-readable
record export, the install script from its committed template, the redirect and
header maps, the stylesheets and scripts, every referenced raster, and its own
Expand Down
5 changes: 5 additions & 0 deletions .abcd/development/brief/04-surfaces/23-reading.md
Original file line number Diff line number Diff line change
Expand Up @@ -142,6 +142,11 @@ contamination. And both artefacts are refused as input wherever an admitted path
holds one, recognised by the type tag they carry, so a run committed before that
refusal existed cannot ride in either.

An output directory reached through a symlink at any level inside a checkout is
refused however it is spelled (relative, absolute, or climbing out of the
repository and back in), because a committed link would carry both files
elsewhere; outside every checkout the path is the operator's own.

Run identifiers are minted per adr-45, from a mint that reads no maximum, so two
checkouts assembling in the same window cannot converge on one id.

Expand Down
2 changes: 1 addition & 1 deletion .abcd/development/principles/adopt-contributor-commits.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,6 @@ the same diff — a missing entry is a follow-up debt, not a separate decision.
Surfaced by the second operator in the 2026-08-27 security-advisory pilot
(F-W): the issue-sweep's re-author-with-`Reported-by` default cost a
contributor with a ready branch their contributor-graph authorship. The
enabling convention beneath this principle is `CONTRIBUTING.md`'s attribution
enabling convention beneath this principle is `.github/CONTRIBUTING.md`'s attribution
section; the discipline rung (a gate that notices an adopted-and-rewritten
external branch) is unfiled.
6 changes: 1 addition & 5 deletions .abcd/docs-lint.json
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
"name_roots": [
".abcd",
"AGENTS.md",
"CONTRIBUTING.md",
".github/CONTRIBUTING.md",
"scripts"
],
"banned_tokens": [
Expand Down Expand Up @@ -257,10 +257,8 @@
"severity": "blocker",
"extra_roots": [
"AGENTS.md",
"CONTRIBUTING.md",
"CHANGELOG.md",
"ACKNOWLEDGEMENTS.md",
"SECURITY.md",
"RELEASE.md",
".abcd/README.md",
".github",
Expand Down Expand Up @@ -293,8 +291,6 @@
"AGENTS",
"CHANGELOG",
"RELEASE",
"CONTRIBUTING",
"SECURITY",
"LICENSE",
"ACKNOWLEDGEMENTS"
]
Expand Down
2 changes: 1 addition & 1 deletion .abcd/site.json
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,7 @@
"record_pages": {
"contributors": {
"policy": {
"file": "CONTRIBUTING.md",
"file": ".github/CONTRIBUTING.md",
"heading": "AI assistance and authorship",
"part": "first-bullet"
}
Expand Down
Loading
Loading