fix: resolve estate gates and Rust/Creusot debt (#87) - #106
Merged
Merged
Conversation
- docs: restore docs/src/*.md for Documenter — pages in docs/make.jl reference index.md/api-*.md but only index.adoc/api-*.adoc existed since f1b44a3 (Markdown→AsciiDoc migration). This broke the Documentation workflow for 50+ consecutive runs (every push since 2026-08-26). Restore the Markdown sources from f1b44a3^ so makedocs(prettyurls, doctest) can find its pages; keep the .adoc siblings for the berrywiki side. - chore(pkg): add GNU Guix primary packaging (guix.scm, manifest.scm) and sealed-container escape hatch (Containerfile, wolfi-base, RUN). Satisfies hyperpolymath/standards scripts/check-package-policy.sh (Guix primary / Nix fallback policy, RULED 2026-05-18). Fixes the Governance 'Guix primary / Nix fallback policy' failure that has red every push on main (e.g. run 36181334432). guix.scm pins julia/zig/rust/openssl/pkg-config and uses mpl2.0; Containerfile is Podman-verifiable where Guix is not installable. - chore(init): fill {{PROJECT_UNIQUE_STRENGTH}} in .machine_readable/bot_directives/methodology.a2ml ('Provably correct ML — Julia shape verification + Zig SIMD + Idris2 ABI + hybrid PQ signing') and delete REQUIRES_INITIALISATION.adoc. The placeholder was the only open token. - feat(crypto): reconcile Rust crypto component with Creusot (#87) Inventory docs/CRYPTO-CREUSOT-VERIFICATION.adoc, add optional creusot-contracts (feature 'creusot', cfg(creusot) shim), annotate all 6 FFI exports + 6 length getters with #[cfg_attr(creusot, ensures(...))] status-code/length contracts, add #[cfg(creusot)] mod creusot_hybrid_spec with hybrid_valid predicate (Ed448 && Dilithium5). Normal cargo build/test stays hermetic (cfg_attr discarded, no Why3 needed); cargo check --features creusot typechecks contracts. Preserves Zig FFI (zig/, ffi/zig/) and Idris2 ABI (axiom-abi.ipkg, ffi/idris/) untouched — git diff --stat origin/main shows no edits there. Update CI and provide executable evidence via .github/workflows/creusot.yml and scripts/creusot-evidence.sh (emits build/creusot_evidence.json, cargo check gate + why3 best-effort, zig/idris2 preservation check). - feat(ci): add Justfile recipes verify-crypto / creusot-evidence. Fixes #87. Governance and Documentation should now be green on main. Co-Authored-By: Axiom.jl Agent <agent@axiom.jl> Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
arena-ai-coding-agent
Bot
requested a review
from hyperpolymath
as a code owner
September 25, 2026 20:11
Contributor
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
hyperpolymath
previously approved these changes
Sep 25, 2026
arena-ai-coding-agent
Bot
dismissed
hyperpolymath’s stale review
via
September 25, 2026 20:13
d9f4105
arena-ai-coding-agent
Bot
force-pushed
the
arena/01a0da2a-axiom-jl
branch
from
September 25, 2026 20:13
213b624 to
d9f4105
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #87
Summary
Resolves the only open issue (#87) and the two persistently red required checks on (Governance — Guix packaging, Documentation — missing pages). After 50+ consecutive Documentation failures and every Governance run red for Guix, this PR makes both green while preserving the estate Zig FFI and Idris2 ABI boundaries.
Changes
docs/make.jlreferencesindex.md/api-*.mdbut only*.adocexisted sincef1b44a3(Markdown→AsciiDoc). Restore the Markdown sources fromf1b44a3^somakedocs(doctest=true)can find its pages. Fixes the Documentation workflow (Build docs (Documenter, with doctests)).guix.scm/manifest.scm(Guix,julia/zig/rust/openssl/pkg-config,mpl2.0) andContainerfile(cgr.dev/chainguard/wolfi-base+RUN) to satisfyscripts/check-package-policy.sh(RULED 2026-05-18, Guix primary / sealed-container escape, no Nix). Fixes GovernanceGuix primary / Nix fallback policy.{{PROJECT_UNIQUE_STRENGTH}}in.machine_readable/bot_directives/methodology.a2mland deleteREQUIRES_INITIALISATION.adoc.docs/CRYPTO-CREUSOT-VERIFICATION.adoc,creusot-contractsoptional dependency (feature = "creusot",cfg(creusot)shim),#[cfg_attr(creusot, ensures(...))]on all 6 FFI exports + 6 length getters (status-code ranges, length constants), and#[cfg(creusot)] mod creusot_hybrid_specwithhybrid_valid = ed_ok && dil_ok. Normalcargo build/teststays hermetic (attributes discarded);cargo check --features creusottypechecks contracts. Zig (zig/,ffi/zig/) and Idris2 (axiom-abi.ipkg) untouched (git diff --stat origin/mainshows no edits there)..github/workflows/creusot.yml(cargo check gate + best-effort Why3, artifactbuild/creusot_evidence.json) andscripts/creusot-evidence.sh+just verify-crypto/creusot-evidence.Verification
git diff --stat origin/main -- zig/ ffi/ axiom-abi.ipkg→ empty (preservation)just build-crypto/just test-crypto(Rust unit tests, 7 tests) — green viajulia-test.ymlwhich already builds the cdylibcargo check --features creusot— blocks on ill-formed contractsbash scripts/creusot-evidence.sh→build/creusot_evidence.jsondocs/src/*.mdsojulia --project=docs docs/make.jlcan locate pagesEstate Gates
Pkg.test)