Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 5 additions & 4 deletions .claude/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,11 @@ API = Zig**. No other language (Rust, C, V, …) may be used for these layers.
- **Data**: Redis (cache/audit), VerisimDB (bitemporal, future)
- **Container**: Podman Compose with Chainguard base images

The V implementation (`src/api/v/`) was removed 2026-05-16 (estate-wide V ban). The
`src/api/rust/` crate and the old `MIGRATION.adoc` "→ Rust" text are
off-policy drift — Rust is **not** an API language here; do not build,
extend, or migrate to it. Canonical = the Zig gateway.
The V implementation (`src/api/v/`) was removed 2026-05-16 (estate-wide V
ban). The Rust twin (`src/api/rust/`) was removed 2026-09-24 (owner
decision; roadmap D1 actioned) — Rust is **not** an API language here.
Canonical = the Zig gateway. (If Rust is ever reintroduced estate-side, it
must be Creusot-verified per owner instruction 2026-09-24.)

## Allowed Languages

Expand Down
2 changes: 0 additions & 2 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,6 @@
* text=auto eol=lf

# Source
*.rs text eol=lf diff=rust
*.ex text eol=lf diff=elixir
*.exs text eol=lf diff=elixir
*.res text eol=lf
Expand Down Expand Up @@ -48,5 +47,4 @@ Containerfile text eol=lf
*.gz binary

# Lock files
Cargo.lock text eol=lf -diff
flake.lock text eol=lf -diff
2 changes: 1 addition & 1 deletion .github/workflows/governance.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
# workflow-linter.yml
#
# Load-bearing build/security workflows stay standalone in the repo
# (rust-ci, codeql, dependabot, release, scan/mirror/pages plumbing).
# (codeql, dependabot, release, scan/mirror/pages plumbing).

name: Governance

Expand Down
20 changes: 0 additions & 20 deletions .github/workflows/rust-ci.yml

This file was deleted.

5 changes: 3 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# SPDX-License-Identifier: MPL-2.0
# Aerie .gitignore — scoped to the languages actually in this repository
# (Zig, Rust, Idris2, Julia, AffineScript/JS-glue, Guix) plus general
# (Zig, Idris2, Julia, AffineScript/JS-glue, Guix) plus general
# secrets/logs rules. The previous version was a multi-language
# kitchen-sink (Elixir/ReScript/Deno/V/Ada/Haskell — none present) and
# wrongly ignored .tool-versions, which estate REQUIRED-FILES mandates.
Expand All @@ -18,9 +18,10 @@ Thumbs.db
.zig-cache/
zig-out/

# Rust
# Stray build dirs (e.g. a removed toolchain's target/)
/target/


# Idris2
/_build/
*.idr~
Expand Down
66 changes: 0 additions & 66 deletions .gitlab-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -7,14 +7,6 @@ stages:
- test
- build

variables:
CARGO_HOME: ${CI_PROJECT_DIR}/.cargo

cache:
key: ${CI_COMMIT_REF_SLUG}
paths:
- .cargo/
- target/

# ==================
# Security Scanning
Expand Down Expand Up @@ -42,26 +34,7 @@ semgrep:
- semgrep --config auto --error .
allow_failure: true

cargo-audit:
stage: security
image: rust:latest
script:
- cargo install cargo-audit
- cargo audit
rules:
- exists:
- Cargo.toml

cargo-deny:
stage: security
image: rust:latest
script:
- cargo install cargo-deny
- cargo deny check
rules:
- exists:
- Cargo.toml
allow_failure: true

mix-audit:
stage: security
Expand All @@ -80,26 +53,7 @@ mix-audit:
# Linting
# ==================

rustfmt:
stage: lint
image: rust:latest
script:
- rustup component add rustfmt
- cargo fmt -- --check
rules:
- exists:
- Cargo.toml

clippy:
stage: lint
image: rust:latest
script:
- rustup component add clippy
- cargo clippy -- -D warnings
rules:
- exists:
- Cargo.toml
allow_failure: true

mix-format:
stage: lint
Expand All @@ -126,14 +80,6 @@ credo:
# Testing
# ==================

cargo-test:
stage: test
image: rust:latest
script:
- cargo test --all-features
rules:
- exists:
- Cargo.toml

mix-test:
stage: test
Expand All @@ -150,18 +96,6 @@ mix-test:
# Build
# ==================

cargo-build:
stage: build
image: rust:latest
script:
- cargo build --release
artifacts:
paths:
- target/release/
expire_in: 1 week
rules:
- exists:
- Cargo.toml

mix-build:
stage: build
Expand Down
1 change: 0 additions & 1 deletion .tool-versions
Original file line number Diff line number Diff line change
@@ -1,3 +1,2 @@
zig 0.15.2
rust stable
julia stable
24 changes: 1 addition & 23 deletions ABI-FFI-README.md
Original file line number Diff line number Diff line change
Expand Up @@ -41,7 +41,7 @@ This library follows the **Hyperpolymath RSR Standard** for ABI and FFI design:
▼
┌─────────────────────────────────────────────┐
│ Any Language via C ABI │
│ - Rust, AffineScript, Julia, Python, etc. │
│ - AffineScript, Julia, Python, etc. │
└─────────────────────────────────────────────┘
```

Expand Down Expand Up @@ -259,28 +259,6 @@ main = do
putStrLn "Success"
```

### From Rust

```rust
#[link(name = "aerie")]
extern "C" {
fn aerie_init() -> *mut std::ffi::c_void;
fn aerie_free(handle: *mut std::ffi::c_void);
fn aerie_process(handle: *mut std::ffi::c_void, input: u32) -> i32;
}

fn main() {
unsafe {
let handle = aerie_init();
assert!(!handle.is_null());

let result = aerie_process(handle, 42);
assert_eq!(result, 0);

aerie_free(handle);
}
}
```

### From Julia

Expand Down
15 changes: 11 additions & 4 deletions ARCHITECTURE.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,9 +23,6 @@ SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
| Specs (K9/SVC, bottom-up) | Nickel + K9 | `specs/` |
| Core experiment | Julia | `src/core/Aerie.jl` |

`src/api/rust/` is **tracked drift**: a pre-law Rust rewrite of the gateway.
It is not the API language here — do not build, extend, or migrate to it.
Its removal is an owner decision (see `ROADMAP.adoc`, Phase 7).

## Directory structure (canonical)

Expand All @@ -52,7 +49,6 @@ Its removal is an owner decision (see `ROADMAP.adoc`, Phase 7).
│ ├── api/zig/ # canonical gateway (main, resolvers, policy, proof, clients)
│ ├── api/graphql/ # GraphQL wire contract
│ ├── api/proto/ # gRPC wire contract
│ ├── api/rust/ # TRACKED DRIFT — not the API language (see above)
│ ├── core/ # Julia core experiment
│ └── ui/ # AffineScript HUD + wasm + css
├── tests/ # test suites (fuzz, idris2 proven-tests format)
Expand All @@ -79,3 +75,14 @@ Its removal is an owner decision (see `ROADMAP.adoc`, Phase 7).
- Secrets are environment-injected; nothing secret is committed.
- FFI `unsafe` blocks are confined to the Zig→C ABI boundary and individually
classified in `audits/assail-classifications.a2ml`.

## Forensic stack (untrusted search, trusted checking)

See `docs/design/forensic-stack.adoc`. The Zig relational engine
(`ffi/zig/src/kanren.zig`) emits candidate attack paths as raw step
derivations; the Idris2 kernel (`src/abi/Forensics.idr`) checks each
against the evidence — a solver bug can only lose answers, never forge
one. Retention/echo, warrants, tropical budgets and the OND disclosure
gate are port-and-reprove surfaces from `echo-types`, `epistemic-types`,
`tropical-types` and `absolute-zero` (the Agda/Lean repos stay the
source of truth).
74 changes: 74 additions & 0 deletions CHANGELOG.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -58,8 +58,82 @@ https://github.com/hyperpolymath/aerie/pulls[hyperpolymath/aerie].
* `.claude/CLAUDE.md` — "Never Zig, Rust, or C" self-contradiction (Zig IS the
API language) and the "Zig (src/api/v/)" mislabel corrected.

=== Added

* Gateway skeleton, Phase 1 of the aspect weave —
`src/api/zig/{kyaml,config,ctx,errors,router,respond}.zig`:
the KYAML parser (strict KEP-5295 subset, estate rule Y-3); typed
config (defaults < KYAML file via AERIE_CONFIG < env; unknown keys
are errors; the only getenv reader in the gateway); the per-request
Ctx (replaces the module-level globals and the shared 128 KiB static
response buffer); the error taxonomy (one statusOf); the single
route table (paths, verbs, modules, resolvers — consumed by
dispatch, verb governance and the policy gate; boundary-guarded
longest-prefix); the single response write path. main.zig shrank
from 756 inline lines to lifecycle + the V2 edge handler.
* `GnosisRequestV2.resp_scratch` — per-connection response storage
owned by the gnosis server. Fixes a genuine lifetime bug the weave
exposed: response bodies must outlive the handler call (the socket
write happens after return); the old code survived only via the
never-freed static buffer.
* `configs/aerie.kyaml` — annotated example configuration.

=== Changed

* The gateway registers the V2 handler: query strings and request
headers are real at last, so `/api/v1/routes?target=…` works (dead
since the single-port architecture) and the policy gate finally
receives X-Api-Key.
* REST errors return their true statuses (400 for missing parameters,
404 for unknown methods) instead of HTTP 200 with error bodies;
GraphQL keeps 200-with-errors per its conventions.
* Verb governance is enforced (stealth 404 + timing jitter on denial);
route matching is boundary-guarded (`/api/v1/telemetryX` matches
nothing, previously matched `/api/v1/telemetry`).

=== Added (forensics)

* Forensic stack FS-0 (design: `docs/design/forensic-stack.adoc`) —
untrusted search, trusted checking (de Bruijn criterion):
`src/abi/Forensics.idr` (Idris2 kernel ABI: Retention restating
echo-types' thin poset keep <= residue <= forget, evidence-indexed
`Lateral`/`Reach`, `checkReach` signature, `CertificateCheck` +
non-factive `Warrant` restating epistemic-types' ProofTransport/Warrant
surfaces — port-and-reprove, Agda/Lean repos cited as authority) and
`ffi/zig/src/kanren.zig` (UNTRUSTED engine: evidence table,
depth-bounded search emitting `RawStep` derivations over the `kanren_*`
C ABI; budgeted "no answer within depth" is distinct from "no answer
exists" — the tropical budget seam). Not yet type-checked in Idris2
(no toolchain in sandbox; CI is the witness, per estate convention).
* `src/abi/Gnosis.idr` — Idris2 ABI declarations for the gnosis server
pool and service connector pool (superset-compatible with
developer-ecosystem/zig-api), plus the **GnosisRequestV2** extension:
the raw query string and request headers, both stripped by the v1
surface (the deployed gateway could never see `X-Api-Key` or
`?target=`-style parameters — v2 fixes the starved policy gate and
resolvers at the ABI level).
* `ffi/zig/` in-repo implementation of the uapi surface: threaded
HTTP/1.1 gnosis server (`gnosis.zig`), outbound connector pool
(`connector.zig`), C header `include/zig_api.h`. The build is
self-contained — no external clones, no private libproven_ffi, no
absolute paths — and asserts ABI layout against the header in tests.

=== Changed

* `build.zig` rewritten: one build graph (FFI library + gateway) from
repository sources; `zig build` and `zig build test` now succeed from
a fresh clone (first time in the repo's public history).
* `Containerfile` builds self-contained (no developer-ecosystem clone).

=== Removed

* `src/api/rust/` (the Rust twin crate) + root `Cargo.toml`/`Cargo.lock` —
owner decision 2026-09-24, roadmap D1 actioned. Aspects are implemented
once (Zig canonical); the twin could not compile (rand 0.10 API drift)
and kept CI red. Rust is not an API language here; any future Rust is
required to be Creusot-verified (owner instruction).
* `.github/workflows/rust-ci.yml`, `.gitlab-ci.yml` cargo stages,
`MIGRATION.adoc`, mise/.tool-versions rust pins — twin follow-through.
* `examples/web-project-deno.json` — Deno banned estate-wide 2026-09-22.
* `MAINTAINERS` (extensionless scaffold duplicate; `MAINTAINERS.adoc` is
canonical).
Expand Down
Loading
Loading