Skip to content

docs: affirm state at 14386f3e (docs/AFFIRMATION.adoc) - #351

Merged
hyperpolymath merged 2 commits into
mainfrom
docs/affirmation
Oct 7, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
docs/affirmation

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 7, 2026 •

Copy link
Copy Markdown
Owner

Summary

Adds docs/AFFIRMATION.adoc (the rsr-template profile A "evidential" affirmation), anchored to main at 14386f3e61cdfd324853cca3a36f5c37192d59d7 and verified 2026-10-07T10:20:02Z–10:22:34Z. boj-server didn't have one before.

What the file records:

  • Verified by running it at the anchor:
    • 68 unit tests pass: 31 under node and bun, plus 11 and 26 more under bun.
    • The node and bun boot smokes pass.
    • A clean stdio handshake exposes 68 tools (45 boj_* + 23 coord_*), 6 prompts and 7 resources, with serverInfo 0.4.7. That matches the README exactly.
  • CI evidence for the anchor SHA (read, not re-run): Idris2 type-check, trusted-base audit, readme-derive and gitleaks are green. The Idris2, trusted-base and Zig rows were upgraded to local runs after merge, in docs(affirmation): affirm Idris2 0.8.0, trusted base and Zig break by local run #352.
  • Problems the file states openly:
    • The Justfile doesn't parse (guix-shell redefined, from refactor(root): move root artefacts to their canonical locations #327), so no just recipe runs.
    • ffi/zig/src/bench.zig:27 uses Io.Clock.monotonic, which Zig 0.16 removed. That breaks both E2E jobs and the Bench job.
    • Seven CI checks are red but not required, and all seven were already red on the parent.
    • npm latest 0.4.7 is behind main: it serves 65/6/6 and reports serverInfo 0.4.0.
    • The version strings disagree: Justfile 0.4.6, package.json 0.5.0.
    • The start script uses deno.
    • A2ML files are still present, and there's no _chora.deed.
    • Three Dependabot alerts are open in the Rust tray/coord-tui lockfiles.

Merge timing: the template treats the affirmation as valid only if its anchor is the parent of the commit that lands it. Please squash-merge this before main moves past 14386f3e. If main moves first, the file reads as a draft and I'll re-anchor it.

Type of change

Documentation only (a new doc file).

📌 New pins

Head SHA: 5c0eb80cc26b7d10b456155d54db17fc686cc189 (merged as 3de2f6ff). This PR adds or changes no pins: no action uses:, actions.lock, lockfile or container digest changes.

Changes

  • New: docs/AFFIRMATION.adoc.

RSR Quality Checklist

Required

  • Tests pass. The bridge suites were run at the anchor, with results in the file. This PR changes no code.
  • Code is formatted. N/A: no code changed.
  • Linter is clean. N/A: no code changed. Note that just lint can't run at all on main (the Justfile parse error), as the file records.
  • No banned language patterns. A single AsciiDoc file.
  • No unsafe blocks without // SAFETY: comments. N/A: no code changed.
  • No banned functions. N/A: no code changed.
  • SPDX license headers present. The new file has CC-BY-SA-4.0 and SPDX-FileCopyrightText.
  • No secrets, credentials, or .env files included.

As Applicable

  • .machine_readable/* updated. N/A: A2ML is retired (D308), and the file records the leftover A2ML instead of editing it (D313).
  • Documentation updated: this is a new doc.
  • TOPOLOGY.md updated. N/A: architecture didn't change.
  • CHANGELOG updated. N/A: no release.
  • New dependencies reviewed. N/A: no dependencies added.
  • ABI/FFI changes validated. N/A: ABI and FFI untouched. The file only reports the existing Zig bench compile failure.

Testing

  • asciidoctor --failure-level=WARN docs/AFFIRMATION.adoc returned rc 0, and the boj_*, coord_* and {error, hint} passthroughs render correctly.
  • Every "affirmed" row lists the exact command and its output. The Reproduce it yourself section in the file repeats them in order.
  • CI rows come from gh api …/commits/14386f3e…/check-runs --paginate (47 success, 10 skipped, 7 failure). The failures were confirmed identical on the parent 0e700c9d.

Deferred non-required reds (pre-existing on main, not caused by this PR): governance / UUID v7 conformance and SonarQube → #338. The Zig 0.16 Io.Clock.monotonic break (both E2E jobs and Bench), deploy, and Dependabot → #338. I'm adding those to #338 in a comment with this PR.

🤖 Generated with Claude Code

https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC

hyperpolymath and others added 2 commits October 7, 2026 11:24
Add docs/AFFIRMATION.adoc (profile A, evidential), anchored to main at
14386f3, verified 2026-10-07T10:20Z-10:22Z.

Affirmed by live run: 68 unit tests (node + bun), node and bun boot smokes,
a clean stdio handshake exposing 68 tools / 6 prompts / 7 resources with
serverInfo 0.4.7, matching the README. CI evidence: Idris2 type-check,
trusted-base audit, readme-derive, gitleaks.

Outstanding, stated not hidden: the Justfile does not parse (guix-shell
redefined), ffi/zig/src/bench.zig fails on Zig 0.16 (Io.Clock.monotonic),
breaking both E2E jobs; 7 non-required reds, all pre-existing; npm latest
lags main; version strings disagree; start script uses deno.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC
Signed-off-by: Jonathan D.A. Jewell <6759885+hyperpolymath@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Review in Change Stack →

Note

Currently processing new changes in this PR. This may take a few minutes, please wait...

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: b227af5d-53b0-4167-827a-e8dc16489758
📥 Commits

Reviewing files that changed from the base of the PR and between 14386f3 and 5c0eb80.

📒 Files selected for processing (1)
  • docs/AFFIRMATION.adoc
 ___________________________________________
< Sending Skynet back to the drawing board. >
 -------------------------------------------
  \
   \   \
        \ /\
        ( )
      .( o ).
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 113 issues detected

Severity Count
🔴 Critical 10
🟠 High 20
🟡 Medium 83

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `sonarqube` in build.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/build.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sonarqube"
  },
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "Job `deploy` in pages-deploy.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/pages-deploy.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "deploy"
  },
  {
    "reason": "Step uses `peter-evans/repository-dispatch` with `token: ${{ secrets.FARM_DISPATCH_TOKEN }}` but has no `if: secrets.FARM_DISPATCH_TOKEN != ''` gate. On repos where the secret hasn't been propagated the action fails on every push, red-maining the repo. Add the step-level gate (or env+if pattern) so the missing-secret path is a clean skip instead of a red.",
    "type": "secret_action_without_presence_gate",
    "file": ".github/workflows/instant-sync.yml",
    "action": "peter-evans/repository-dispatch",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_secret_presence_gate"
  },
  {
    "reason": "codeql.yml does not list `language: actions` in its matrix, but the repo has workflow files. CodeQL's `actions` language scans workflow YAML for injection and other CI/CD-specific weaknesses — every repo with workflows benefits. Add an entry to `matrix.include` with `language: actions` + `build-mode: none`.",
    "type": "codeql_missing_actions_language",
    "file": ".github/workflows/codeql.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "fix_recipe": "add_codeql_actions_language"
  },
  {
    "line": 39,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 46,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 32,
    "reason": "job in .github/workflows/build.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/build.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/container-publish.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/container-publish.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit 3de2f6f into main Oct 7, 2026
58 of 61 checks passed
@hyperpolymath
hyperpolymath deleted the docs/affirmation branch October 7, 2026 10:26
hyperpolymath added a commit that referenced this pull request Oct 7, 2026
… local run (#352)

## Summary

A follow-up to #351, which was squash-merged as `3de2f6ff` before this
commit reached its branch. This PR upgrades three rows of
`docs/AFFIRMATION.adoc` from **CI evidence** to **affirmed by local
run**, using the pinned toolchain. It also records how the affirmation
landed.

The runs were all made on a cold `git archive` of the same anchor,
`14386f3e61cdfd324853cca3a36f5c37192d59d7`, between 10:26:56Z and
10:27:40Z:
- Idris2 **0.8.0** (the `.mise.toml` pin, at `tools/opt/idris2-0.8.0`,
with `IDRIS2_PREFIX` set so `contrib` resolves). `cd src/abi && idris2
--typecheck boj.ipkg` gave rc 0, **17/17** modules built.
- `scripts/typecheck-proofs.sh` gave rc 0, `PASS=1 FAIL=0`.
- `scripts/check-trusted-base.sh` gave rc 0: **4 sanctioned class-(J)
axioms**, all in `src/abi/Boj/SafetyLemmas.idr`.
- Zig **0.16.0** `zig build` in `ffi/zig` gave rc 1 with **13 errors**,
all `src/bench.zig: enum 'Io.Clock' has no member named 'monotonic'`,
the same as CI.

**The anchor doesn't move.** The template's parent check concerns the
commit that *introduced* the file. That commit is `3de2f6ff`, whose
parent is `14386f3e`, and `git diff --stat 14386f3 3de2f6f` shows only
`docs/AFFIRMATION.adoc`. The new "Landing record" note in the file says
so.

Credit: the boj-server session [bf7923] pointed out the pinned Idris2
install and its `IDRIS2_PREFIX` requirement, and its 10:25Z run matched
mine.

## Type of change

Documentation only.

## 📌 New pins

Head SHA: **`b39db8d103aa6e705db2f246bbef8272ef89a007`**. This PR adds
or changes no pins: no action `uses:`, `actions.lock`, lockfile or
container digest changes.

## Changes

- `docs/AFFIRMATION.adoc`:
- The anchor's toolchain row now lists Zig 0.16.0 and Idris2 0.8.0, and
the working-tree row describes the cold archive build.
- The Idris2 and trusted-base rows are now "affirmed", with the commands
and output.
  - The Zig bench item now cites the local run.
- The one-paragraph summary and the one-line quote now describe the
pinned Idris2 run.
  - The verification window ends at 10:27:40Z.
  - The "Squash-merge note" is replaced by a "Landing record".

## RSR Quality Checklist

### Required

- [x] Tests pass. This PR changes no code. The checks it reports were
run as described above.
- [x] Code is formatted. N/A: no code changed.
- [x] Linter is clean. N/A: no code changed.
- [x] No banned language patterns. A single AsciiDoc file.
- [x] No `unsafe` blocks without `// SAFETY:` comments. N/A: no code
changed.
- [x] No banned functions. N/A: no code changed. The 4 `believe_me`
axioms are the documented `SafetyLemmas` ones, which
`check-trusted-base.sh` reports as sanctioned.
- [x] SPDX license headers present. The header is unchanged
(`CC-BY-SA-4.0`).
- [x] No secrets, credentials, or `.env` files included.

### As Applicable

- [ ] `.machine_readable/*` updated. N/A: A2ML is retired (D308).
- [x] Documentation updated.
- [ ] `TOPOLOGY.md` updated. N/A: architecture didn't change.
- [ ] `CHANGELOG` updated. N/A: no release.
- [ ] New dependencies reviewed. N/A: no dependencies added.
- [ ] ABI/FFI changes validated. N/A: ABI and FFI untouched. The file
only reports their state.

## Testing

- `asciidoctor --failure-level=WARN docs/AFFIRMATION.adoc` returned rc
0.
- The commands and outputs are the ones quoted above. The **Reproduce it
yourself** section in the file is unchanged.

Deferred non-required reds (pre-existing on main): `governance / UUID v7
conformance`, `SonarQube`, the Zig E2E and Bench jobs, `deploy` and
`Dependabot` → #338, with acceptance criteria in comment 6035981182.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01P56iYjCwHmbRyfFrpyJzTC

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant