Repository navigation
Axiom flagship (4) — estate tooling: Aqua/JET/Documenter/test-gate + k9/panic-attack/RSR - #49
Merged
Conversation
…anic-attack/RSR (tier-2) Makes Axiom.jl demonstrably best-practice (tier-2; G07, G08, G13, G14, G15, G16). Quality/testing: - Aqua.test_all(Axiom): all 11 checks pass with ZERO overrides. Fixed a real unbound-type-param bug in LayerNorm/InstanceNorm/GroupNorm inner constructors; removed the stale JSON3 dep (its only consumer, dead huggingface.jl, is not included in the module). (G07) - JET.test_package(Axiom; target_modules=(Axiom,)): zero Axiom-rooted errors, no allowlist. (G07) - Full [compat] closure incl. all six weakdeps + stdlibs + extras; widened Zygote 0.6 -> 0.6,0.7 (resolves to 0.7.11; suite unchanged). (G08) - Documenter docs/make.jl builds with doctests (explicit GitHub remote for the proxy env; API split into 4 pages under Documenter's HTML size limit). (G13) - julia-test.yml CI gate builds the crypto cdylib BEFORE Pkg.test, so the hybrid-signing tests actually run in CI (they had been silently @test_skip'd); matrix 1.10 + 1 + nightly(continue-on-error); no on.*.paths. Compliance/gates: - k9iser.toml (safety-tier fv) over Project.toml / axiom-abi.ipkg / crypto. (G15) - static-analysis-gate.yml (panic-attack assail, fail-on-critical) + Justfile assail recipe fixed (panic-attacker -> panic-attack). First assail: 0 critical, 2 high (legit crypto/FFI unsafe boundary, tracked for P5 audit). (G14) - estate-rules.yml (correctly bans V-lang, NOT Zig) + RSR files: docs/legal/ EXHIBIT-A/B, docs/governance/*, .machine_readable/policies/*. (G16) Verified: Pkg.test 709/709 (697 + 11 Aqua + 1 JET); docs build clean; Pkg.resolve clean; no licence/key files touched; SPDX on all new files. Residual: dead huggingface.jl (stale dep removed; deletion is tier-3); assail residuals audited in P5. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1
hyperpolymath
marked this pull request as ready for review
July 1, 2026 07:53
hyperpolymath
added a commit
that referenced
this pull request
Jul 1, 2026
## Summary The tier‑2 bundle (#49) merged with two required gates red; they're now failing on `main` and will fail every subsequent PR's CI. This is a minimal follow‑up that closes both — no functional change to the tier‑2 work. ## Changes - **`estate-rules.yml`** — the "AsciiDoc by default under `docs/`" check flagged the **Documenter source pages** (`docs/src/*.md`) that #49 added for the new docs build. Documenter's native source format is **Markdown** — it cannot consume `.adoc` — so `docs/src/` is a legitimate carve‑out, exactly like the existing `docs/wiki/` GitHub‑wiki mirror. Added `-not -path 'docs/src/*'` to the check and updated the comments/step name to document the carve‑out. - **`.machine_readable/policies/MAINTENANCE-AXES.a2ml`** + **`MAINTENANCE-CHECKLIST.a2ml`** — A2ML validation requires an identity field (`agent-id`/`name`/`project`); these two were missing it. Added `name` + `project` to each `[metadata]` block. ## Verification (local) - `find docs -name '*.md' -not -path 'docs/wiki/*' -not -path 'docs/src/*'` → **empty** (no disallowed `.md`; `docs/legal/*.txt` and `docs/governance/*.adoc` are unaffected). - Both policy files now carry `name` + `project` in `[metadata]` (the exact fields the validator's error named). ## Why this happened Two parallel workers built #49 on disjoint file‑sets; the docs worker added `docs/src/*.md` (Documenter) while the compliance worker wrote the `estate-rules` docs check — neither saw the other's additions. Caught here on the first real CI run and fixed at the workflow level. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1 --- _Generated by [Claude Code](https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1)_ --------- Co-authored-by: Claude <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Tier‑2 of the flagship effort: wires the estate/ecosystem tooling that makes Axiom.jl demonstrably best‑practice and CI‑gated. Two disjoint work‑streams, independently verified before commit (gaps G07, G08, G13, G14, G15, G16).
Quality & testing
test/aqua.jl):Aqua.test_all(Axiom)passes all 11 checks with zero overrides. Along the way it found + fixed a real unbound‑type‑param bug inLayerNorm/InstanceNorm/GroupNorminner constructors, and removed the staleJSON3dep (its only consumer, deadhuggingface.jl, isn'tincluded). (G07)test/jet.jl):JET.test_package(Axiom; target_modules=(Axiom,))— zero Axiom‑rooted errors, scoped via JET's own mechanism, no hand‑rolled allowlist. (G07)[compat]closure (G08): upper‑bounded compat for all six weakdeps + stdlibs + extras;Zygotewidened0.6 → 0.6,0.7(resolves to 0.7.11, suite unchanged).docs/) (G13):docs/make.jlbuilds with doctests; fixed the proxy‑URL remote detection and split the API into 4 pages under Documenter's size limit..github/workflows/julia-test.yml): builds the crypto cdylib beforePkg.test— closing a real gap where the 27 hybrid‑signing tests had been silently@test_skip'd in CI. Matrix1.10+1+ nightly(continue‑on‑error); noon.*.paths.Compliance & gates
k9iser.toml(G15): safety‑tierfv, constraints overProject.toml/axiom-abi.ipkg/crypto/.static-analysis-gate.yml) + Justfileassailrecipe fixed (panic-attacker→panic-attack) (G14). First realassailrun: 0 critical, 2 high (the legitimate crypto/FFIunsafeboundary — tracked for P5 audit, not suppressed here).estate-rules.yml— correctly bans V‑lang, explicitly not Zig (Axiom legitimately ships a Zig compute layer) — plus RSR files:docs/legal/EXHIBIT-A/B,docs/governance/*,.machine_readable/policies/*. (G16)Verification (independent re‑run)
Pkg.test()→ 709 / 709 pass (697 + 11 Aqua + 1 JET); Aqua/JET green.docs/make.jlbuilds clean with doctests;Pkg.resolve()clean.NOTICEfiles touched; no private‑key material; SPDX on every new file.Residuals (tracked)
huggingface.jl(its stale dep is removed here; deletion belongs to the doc‑reconciliation/tier‑3 pass).assailfindings (legit FFI/cryptounsafe) get auditedassail-classifications.a2mlentries in P5.standards/julia-ci-reusable.ymlrefactor (G40) + the flagship measuring‑stick rubric (P8) are the tier‑2 tail.🤖 Generated with Claude Code
https://claude.ai/code/session_01UPFC9YQ7g9gc3VnRox42Q1
Generated by Claude Code