Skip to content

Axiom flagship (4) — estate tooling: Aqua/JET/Documenter/test-gate + k9/panic-attack/RSR - #49

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/axiom-jl-registry-infra-kr7t4a
Jul 1, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
claude/axiom-jl-registry-infra-kr7t4a

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

Tier‑2 of the flagship effort: wires the estate/ecosystem tooling that makes Axiom.jl demonstrably best‑practice and CI‑gated. Two disjoint work‑streams, independently verified before commit (gaps G07, G08, G13, G14, G15, G16).

Quality & testing

  • Aqua (test/aqua.jl): Aqua.test_all(Axiom) passes all 11 checks with zero overrides. Along the way it found + fixed a real unbound‑type‑param bug in LayerNorm/InstanceNorm/GroupNorm inner constructors, and removed the stale JSON3 dep (its only consumer, dead huggingface.jl, isn't included). (G07)
  • JET (test/jet.jl): JET.test_package(Axiom; target_modules=(Axiom,)) — zero Axiom‑rooted errors, scoped via JET's own mechanism, no hand‑rolled allowlist. (G07)
  • [compat] closure (G08): upper‑bounded compat for all six weakdeps + stdlibs + extras; Zygote widened 0.6 → 0.6,0.7 (resolves to 0.7.11, suite unchanged).
  • Documenter (docs/) (G13): docs/make.jl builds with doctests; fixed the proxy‑URL remote detection and split the API into 4 pages under Documenter's size limit.
  • Julia test‑gate CI (.github/workflows/julia-test.yml): builds the crypto cdylib before Pkg.test — closing a real gap where the 27 hybrid‑signing tests had been silently @test_skip'd in CI. Matrix 1.10 + 1 + nightly(continue‑on‑error); no on.*.paths.

Compliance & gates

  • k9iser.toml (G15): safety‑tier fv, constraints over Project.toml / axiom-abi.ipkg / crypto/.
  • panic‑attack gate (static-analysis-gate.yml) + Justfile assail recipe fixed (panic-attacker→panic-attack) (G14). First real assail run: 0 critical, 2 high (the legitimate crypto/FFI unsafe boundary — tracked for P5 audit, not suppressed here).
  • estate-rules.yml — correctly bans V‑lang, explicitly not Zig (Axiom legitimately ships a Zig compute layer) — plus RSR files: docs/legal/EXHIBIT-A/B, docs/governance/*, .machine_readable/policies/*. (G16)

Verification (independent re‑run)

  • Pkg.test() → 709 / 709 pass (697 + 11 Aqua + 1 JET); Aqua/JET green.
  • docs/make.jl builds clean with doctests; Pkg.resolve() clean.
  • No licence/NOTICE files touched; no private‑key material; SPDX on every new file.

Residuals (tracked)

  • Dead huggingface.jl (its stale dep is removed here; deletion belongs to the doc‑reconciliation/tier‑3 pass).
  • The 2 high assail findings (legit FFI/crypto unsafe) get audited assail-classifications.a2ml entries in P5.
  • standards/julia-ci-reusable.yml refactor (G40) + the flagship measuring‑stick rubric (P8) are the tier‑2 tail.

🤖 Generated with Claude Code

https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1


Generated by Claude Code

…anic-attack/RSR (tier-2)

Makes Axiom.jl demonstrably best-practice (tier-2; G07, G08, G13, G14, G15, G16).

Quality/testing:
- Aqua.test_all(Axiom): all 11 checks pass with ZERO overrides. Fixed a real
  unbound-type-param bug in LayerNorm/InstanceNorm/GroupNorm inner constructors;
  removed the stale JSON3 dep (its only consumer, dead huggingface.jl, is not
  included in the module). (G07)
- JET.test_package(Axiom; target_modules=(Axiom,)): zero Axiom-rooted errors,
  no allowlist. (G07)
- Full [compat] closure incl. all six weakdeps + stdlibs + extras; widened
  Zygote 0.6 -> 0.6,0.7 (resolves to 0.7.11; suite unchanged). (G08)
- Documenter docs/make.jl builds with doctests (explicit GitHub remote for the
  proxy env; API split into 4 pages under Documenter's HTML size limit). (G13)
- julia-test.yml CI gate builds the crypto cdylib BEFORE Pkg.test, so the
  hybrid-signing tests actually run in CI (they had been silently @test_skip'd);
  matrix 1.10 + 1 + nightly(continue-on-error); no on.*.paths.

Compliance/gates:
- k9iser.toml (safety-tier fv) over Project.toml / axiom-abi.ipkg / crypto. (G15)
- static-analysis-gate.yml (panic-attack assail, fail-on-critical) + Justfile
  assail recipe fixed (panic-attacker -> panic-attack). First assail: 0 critical,
  2 high (legit crypto/FFI unsafe boundary, tracked for P5 audit). (G14)
- estate-rules.yml (correctly bans V-lang, NOT Zig) + RSR files: docs/legal/
  EXHIBIT-A/B, docs/governance/*, .machine_readable/policies/*. (G16)

Verified: Pkg.test 709/709 (697 + 11 Aqua + 1 JET); docs build clean; Pkg.resolve
clean; no licence/key files touched; SPDX on all new files.

Residual: dead huggingface.jl (stale dep removed; deletion is tier-3); assail
residuals audited in P5.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1
@hyperpolymath
hyperpolymath marked this pull request as ready for review July 1, 2026 07:53
@hyperpolymath
hyperpolymath merged commit 4e40494 into main Jul 1, 2026
11 of 13 checks passed
@hyperpolymath
hyperpolymath deleted the claude/axiom-jl-registry-infra-kr7t4a branch July 1, 2026 07:53
hyperpolymath added a commit that referenced this pull request Jul 1, 2026
## Summary

The tier‑2 bundle (#49) merged with two required gates red; they're now
failing on `main` and will fail every subsequent PR's CI. This is a
minimal follow‑up that closes both — no functional change to the tier‑2
work.

## Changes

- **`estate-rules.yml`** — the "AsciiDoc by default under `docs/`" check
flagged the **Documenter source pages** (`docs/src/*.md`) that #49 added
for the new docs build. Documenter's native source format is
**Markdown** — it cannot consume `.adoc` — so `docs/src/` is a
legitimate carve‑out, exactly like the existing `docs/wiki/` GitHub‑wiki
mirror. Added `-not -path 'docs/src/*'` to the check and updated the
comments/step name to document the carve‑out.
- **`.machine_readable/policies/MAINTENANCE-AXES.a2ml`** +
**`MAINTENANCE-CHECKLIST.a2ml`** — A2ML validation requires an identity
field (`agent-id`/`name`/`project`); these two were missing it. Added
`name` + `project` to each `[metadata]` block.

## Verification (local)
- `find docs -name '*.md' -not -path 'docs/wiki/*' -not -path
'docs/src/*'` → **empty** (no disallowed `.md`; `docs/legal/*.txt` and
`docs/governance/*.adoc` are unaffected).
- Both policy files now carry `name` + `project` in `[metadata]` (the
exact fields the validator's error named).

## Why this happened
Two parallel workers built #49 on disjoint file‑sets; the docs worker
added `docs/src/*.md` (Documenter) while the compliance worker wrote the
`estate-rules` docs check — neither saw the other's additions. Caught
here on the first real CI run and fixed at the workflow level.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1

---
_Generated by [Claude
Code](https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1)_

---------

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants