diff --git a/.machine_readable/arrival-pack/arrival-pack.ncl b/.machine_readable/arrival-pack/arrival-pack.ncl index 619353e..7db8b5c 100644 --- a/.machine_readable/arrival-pack/arrival-pack.ncl +++ b/.machine_readable/arrival-pack/arrival-pack.ncl @@ -14,15 +14,13 @@ # # The a2ml files remain the single source of truth; this is a VIEW. Hand-editing # the emitted region is a flagged error (see claude-md.k9.ncl drift check). - let data = import "claude-md-data.json" in # Pin to a Manifesto commit once the doctrine wording is ratified into the # owner's voice. Until then the estate-common block is explicitly DRAFT. let manifesto_pin = "DRAFT-unratified" in -let provenance = - "CLADE@%{data.h_clade} ECOSYSTEM@%{data.h_eco} AGENTIC@%{data.h_agentic} STATE@%{data.h_state} ANCHOR@%{data.h_anchor}" +let provenance = "CLADE@%{data.h_clade} ECOSYSTEM@%{data.h_eco} AGENTIC@%{data.h_agentic} STATE@%{data.h_state} ANCHOR@%{data.h_anchor}" in m%" diff --git a/.machine_readable/coaptation/coapt.ncl b/.machine_readable/coaptation/coapt.ncl index daf7468..485517d 100644 --- a/.machine_readable/coaptation/coapt.ncl +++ b/.machine_readable/coaptation/coapt.ncl @@ -24,8 +24,11 @@ let facts = facts_doc.facts in # --- fact lookup table ------------------------------------------------------- let facts_by_id = std.array.fold_left (fun acc f => acc & { "%{f.id}" = f }) {} facts in let lookup = fun id => - if std.record.has_field id facts_by_id then facts_by_id."%{id}" - else { id = id, value = "", present = false } in + if std.record.has_field id facts_by_id then + facts_by_id."%{id}" + else + { id = id, value = "", present = false } +in # --- predicate evaluation (does a single witness hold?) ---------------------- let eval_w = fun w => @@ -40,31 +43,49 @@ let eval_w = fun w => 'equals => f.value == arg, 'contains => std.string.contains arg f.value, 'not_contains => !(std.string.contains arg f.value), - } in + } +in # --- per-clause evaluation (Coverage) ---------------------------------------- -let evals = std.array.map - (fun c => - let mapped = std.record.has_field c.id wmap in - let entry = if mapped then wmap."%{c.id}" else { kind = "auto", witnesses = [] } in - let base_kind = - if entry.kind != "auto" then entry.kind - else if c.has_probe then "probe" - else "unmeasured" in - let sat = - if base_kind == "descriptile" then std.array.all eval_w entry.witnesses - else false in - let st = - if c.verb == "bust" then (if base_kind == "descriptile" && sat then "alarm" else "latent") - else if c.verb == "dust" then "expected" - else if c.verb == "intend" then (if c.is_wish then "wish:" ++ c.status else "intent:" ++ c.status) - else if base_kind == "descriptile" then (if sat then "witnessed" else "refuted") - else if base_kind == "none" then "gap" - else if base_kind == "probe" then "probe-deferred" - else "unmeasured" in - { id = c.id, verb = c.verb, status = st, kind = base_kind, wsat = sat, c_status = c.status, is_wish = c.is_wish } - ) - clauses in +let evals = + std.array.map + (fun c => + let mapped = std.record.has_field c.id wmap in + let entry = if mapped then wmap."%{c.id}" else { kind = "auto", witnesses = [] } in + let base_kind = + if entry.kind != "auto" then + entry.kind + else if c.has_probe then + "probe" + else + "unmeasured" + in + let sat = + if base_kind == "descriptile" then + std.array.all eval_w entry.witnesses + else + false + in + let st = + if c.verb == "bust" then + (if base_kind == "descriptile" && sat then "alarm" else "latent") + else if c.verb == "dust" then + "expected" + else if c.verb == "intend" then + (if c.is_wish then "wish:" ++ c.status else "intent:" ++ c.status) + else if base_kind == "descriptile" then + (if sat then "witnessed" else "refuted") + else if base_kind == "none" then + "gap" + else if base_kind == "probe" then + "probe-deferred" + else + "unmeasured" + in + { id = c.id, verb = c.verb, status = st, kind = base_kind, wsat = sat, c_status = c.status, is_wish = c.is_wish } + ) + clauses +in # --- rollups ----------------------------------------------------------------- let count = fun pred arr => std.array.length (std.array.filter pred arr) in @@ -103,7 +124,8 @@ let action = else if band == "amber" then "advisory — soft drift within bands (posture/intend). Open an advisory issue; no re-anchor." else - "none — the descriptile self-model coapts with the contractile set-point within tolerance." in + "none — the descriptile self-model coapts with the contractile set-point within tolerance." +in # --- render ------------------------------------------------------------------ let clause_lines = std.string.join "\n" (std.array.map (fun e => e.id ++ " = " ++ e.status) evals) in diff --git a/.machine_readable/coaptation/grades.ncl b/.machine_readable/coaptation/grades.ncl index 155b2a2..29030ee 100644 --- a/.machine_readable/coaptation/grades.ncl +++ b/.machine_readable/coaptation/grades.ncl @@ -27,12 +27,12 @@ # a human authority act (see coapt.sh --reanchor). { verb_grade = { - must = "boolean_gate", - trust = "boolean_gate_provenance", + must = "boolean_gate", + trust = "boolean_gate_provenance", adjust = "posture", intend = "tropical", - bust = "alarm", - dust = "expected", + bust = "alarm", + dust = "expected", }, tolerances = { diff --git a/.machine_readable/coaptation/witness-map.ncl b/.machine_readable/coaptation/witness-map.ncl index f23dfc6..ae306e9 100644 --- a/.machine_readable/coaptation/witness-map.ncl +++ b/.machine_readable/coaptation/witness-map.ncl @@ -25,7 +25,7 @@ # --- MUST: presence obligations attested by the fact that we parsed the file --- "must.machine-readable-dir" = { kind = "descriptile", - witnesses = [ { fact = "state.status", op = 'present } ], + witnesses = [{ fact = "state.status", op = 'present }], note = "descriptiles parse ⇒ .machine_readable/ exists and is populated", }, "must.six-directory-present" = { @@ -38,7 +38,7 @@ }, "must.anchors-directory" = { kind = "descriptile", - witnesses = [ { fact = "anchor.authority", op = 'present } ], + witnesses = [{ fact = "anchor.authority", op = 'present }], note = "ANCHOR.a2ml was read from .machine_readable/descriptiles/anchors/", }, @@ -55,7 +55,7 @@ # --- INTEND: a committed intent realised by the descriptive self-model --- "intend.repo-initialization" = { kind = "descriptile", - witnesses = [ { fact = "ecosystem.type", op = 'equals, arg = "repository-template" } ], + witnesses = [{ fact = "ecosystem.type", op = 'equals, arg = "repository-template" }], note = "ECOSYSTEM declares this repo IS a template ⇒ the init intent is realised", }, @@ -64,7 +64,7 @@ # itself that is expected, but it is honestly a posture dip worth surfacing. "adjust.placeholder-drift" = { kind = "descriptile", - witnesses = [ { fact = "anchor.project", op = 'not_contains, arg = "{{" } ], + witnesses = [{ fact = "anchor.project", op = 'not_contains, arg = "{{" }], note = "ANCHOR.identity.project is un-substituted ({{PROJECT_NAME}}) ⇒ posture dip", }, @@ -72,17 +72,17 @@ # failure), not satisfaction. open-failures/last-result are the live signal. --- "bust.template-substitution-failure" = { kind = "descriptile", - witnesses = [ { fact = "state.open-failures", op = 'nonzero } ], + witnesses = [{ fact = "state.open-failures", op = 'nonzero }], note = "alarm iff STATE records open failures; else latent (declared, not active)", }, "bust.sync-drift-between-repos" = { kind = "descriptile", - witnesses = [ { fact = "state.open-failures", op = 'nonzero } ], + witnesses = [{ fact = "state.open-failures", op = 'nonzero }], note = "alarm iff STATE records open failures; else latent", }, "bust.contractile-parse-error" = { kind = "descriptile", - witnesses = [ { fact = "state.last-result", op = 'equals, arg = "fail" } ], + witnesses = [{ fact = "state.last-result", op = 'equals, arg = "fail" }], note = "alarm iff the last maintenance run failed; else latent", }, } diff --git a/.machine_readable/contractiles/_base.ncl b/.machine_readable/contractiles/_base.ncl index 34ec621..b30f0aa 100644 --- a/.machine_readable/contractiles/_base.ncl +++ b/.machine_readable/contractiles/_base.ncl @@ -37,7 +37,6 @@ # } # # See: docs/CONTRACTILE-SPEC.adoc §Shared Base - { # ------------------------------------------------------------------------- # pedigree_schema @@ -49,11 +48,11 @@ # ------------------------------------------------------------------------- pedigree_schema = { schema_version | String | default = "1.0.0", - contractile_verb | String | default = "UNSET", # MUST override in verb - semantics | String | default = "UNSET", # MUST override in verb + contractile_verb | String | default = "UNSET", # MUST override in verb + semantics | String | default = "UNSET", # MUST override in verb security = { leash | [| 'Kennel, 'Yard, 'Hunt |] | default = 'Kennel, - trust_level | String | default = "UNSET", # MUST override in verb + trust_level | String | default = "UNSET", # MUST override in verb allow_network | Bool | default = false, allow_filesystem_write | Bool | default = false, allow_subprocess | Bool | default = true, @@ -62,10 +61,10 @@ # destructive_mode_requires_flag (dust) }, metadata = { - name | String | default = "UNSET", # MUST override in verb + name | String | default = "UNSET", # MUST override in verb version | String | default = "1.0.0", - description | String | default = "UNSET", # MUST override in verb - paired_xfile | String | default = "UNSET", # MUST override in verb + description | String | default = "UNSET", # MUST override in verb + paired_xfile | String | default = "UNSET", # MUST override in verb author | String | default = "Jonathan D.A. Jewell ", }, }, @@ -117,7 +116,8 @@ allowed_exit_codes | Array Number | default = [0], permission_class | [| 'read_only, 'filesystem_write, 'subprocess, 'network |] - | default = 'read_only, + | default + = 'read_only, }, # ------------------------------------------------------------------------- diff --git a/.machine_readable/contractiles/adjust/adjust.ncl b/.machine_readable/contractiles/adjust/adjust.ncl index d6c24f0..f0f0743 100644 --- a/.machine_readable/contractiles/adjust/adjust.ncl +++ b/.machine_readable/contractiles/adjust/adjust.ncl @@ -12,51 +12,54 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "adjust", - semantics = "accessibility compliance", - security = { - leash = 'Kennel, - trust_level = "fixes allowed where deterministic", - allow_network = false, - allow_filesystem_write = true, # `adjust fix` may write (deterministic patches only) - allow_subprocess = true, - }, - metadata = { - name = "adjust-runner", - version = "1.0.0", - description = "Evaluates accessibility requirements from Adjustfile.a2ml. Fixes deterministic items; flags the rest for human review.", - paired_xfile = "Adjustfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "adjust", + semantics = "accessibility compliance", + security = { + leash = 'Kennel, + trust_level = "fixes allowed where deterministic", + allow_network = false, + allow_filesystem_write = true, # `adjust fix` may write (deterministic patches only) + allow_subprocess = true, + }, + metadata = { + name = "adjust-runner", + version = "1.0.0", + description = "Evaluates accessibility requirements from Adjustfile.a2ml. Fixes deterministic items; flags the rest for human review.", + paired_xfile = "Adjustfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, schema = { requirements | Array { - id | String, - description | String, - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String, - # status_core values: 'declared, 'verified, 'failing; adjust adds 'partial - status | [| 'declared, 'partial, 'verified, 'failing |] | default = 'declared, - compliance | String | optional, # e.g. "WCAG 2.1 AA" - notes | String | optional, - fix | String | optional, # deterministic fix command (optional) - }, + id | String, + description | String, + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String, + # status_core values: 'declared, 'verified, 'failing; adjust adds 'partial + status | [| 'declared, 'partial, 'verified, 'failing |] | default = 'declared, + compliance | String | optional, # e.g. "WCAG 2.1 AA" + notes | String | optional, + fix | String | optional, # deterministic fix command (optional) + }, }, # Runner behaviour — inherits from base.run_defaults. # adjust is advisory (continue-with-warnings) not a hard gate. # auto_fix_when_available is adjust-specific. - run = base.run_defaults & { - on_any_fail = "continue-with-warnings", # accessibility is progress-tracked, not a hard gate by default - report_format = "a2ml", - emit_summary = true, - auto_fix_when_available = true, - }, + run = + base.run_defaults + & { + on_any_fail = "continue-with-warnings", # accessibility is progress-tracked, not a hard gate by default + report_format = "a2ml", + emit_summary = true, + auto_fix_when_available = true, + }, } diff --git a/.machine_readable/contractiles/bust/bust.ncl b/.machine_readable/contractiles/bust/bust.ncl index fc8cb8c..f273168 100644 --- a/.machine_readable/contractiles/bust/bust.ncl +++ b/.machine_readable/contractiles/bust/bust.ncl @@ -14,53 +14,56 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "bust", - semantics = "error handling + failure recovery", - security = { - leash = 'Kennel, - trust_level = "controlled failure injection; scoped to system-under-test", - allow_network = false, - allow_filesystem_write = true, # drills may write transient state (tmp dirs, test DBs) - allow_subprocess = true, - injection_scope = "system-under-test-only", - }, - metadata = { - name = "bust-runner", - version = "1.0.0", - description = "Exercises declared failure modes and verifies recovery paths. Hard-gates on any failure mode without working recovery.", - paired_xfile = "Bustfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "bust", + semantics = "error handling + failure recovery", + security = { + leash = 'Kennel, + trust_level = "controlled failure injection; scoped to system-under-test", + allow_network = false, + allow_filesystem_write = true, # drills may write transient state (tmp dirs, test DBs) + allow_subprocess = true, + injection_scope = "system-under-test-only", + }, + metadata = { + name = "bust-runner", + version = "1.0.0", + description = "Exercises declared failure modes and verifies recovery paths. Hard-gates on any failure mode without working recovery.", + paired_xfile = "Bustfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, schema = { failure_modes | Array { - id | String, - description | String, - class | [| 'network, 'disk_full, 'oom, 'timeout, 'partial_write, 'panic, 'crash, 'rollback, 'concurrency |], - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - injection_probe | String, # command that deterministically causes this failure - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - recovery_probe | String, # command that verifies recovery (exit 0 = recovered) - expected_recovery_time_seconds | Number | default = 30, - # status_core values: 'declared, 'verified, 'failing; bust adds 'drilled - status | [| 'declared, 'drilled, 'verified, 'failing |] | default = 'declared, - notes | String | optional, - }, + id | String, + description | String, + class | [| 'network, 'disk_full, 'oom, 'timeout, 'partial_write, 'panic, 'crash, 'rollback, 'concurrency |], + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + injection_probe | String, # command that deterministically causes this failure + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + recovery_probe | String, # command that verifies recovery (exit 0 = recovered) + expected_recovery_time_seconds | Number | default = 30, + # status_core values: 'declared, 'verified, 'failing; bust adds 'drilled + status | [| 'declared, 'drilled, 'verified, 'failing |] | default = 'declared, + notes | String | optional, + }, }, # Runner behaviour — inherits from base.run_defaults. # bust adds record_recovery_times for performance tier feeding. - run = base.run_defaults & { - on_any_fail = "exit-nonzero", # missing or broken recovery blocks merge - report_format = "a2ml", - emit_summary = true, - record_recovery_times = true, # feeds the performance tier - }, + run = + base.run_defaults + & { + on_any_fail = "exit-nonzero", # missing or broken recovery blocks merge + report_format = "a2ml", + emit_summary = true, + record_recovery_times = true, # feeds the performance tier + }, } diff --git a/.machine_readable/contractiles/dust/dust.ncl b/.machine_readable/contractiles/dust/dust.ncl index 36aa89b..8da0361 100644 --- a/.machine_readable/contractiles/dust/dust.ncl +++ b/.machine_readable/contractiles/dust/dust.ncl @@ -14,53 +14,56 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "dust", - semantics = "exnovation / removal", - security = { - leash = 'Kennel, - trust_level = "proposes deletion; --apply required to execute", - allow_network = false, - allow_filesystem_write = true, # --apply mode writes (deletes) - allow_subprocess = true, - destructive_mode_requires_flag = "--apply", - }, - metadata = { - name = "dust-runner", - version = "1.0.0", - description = "Identifies and optionally removes exnovation targets listed in Dustfile.a2ml. Destructive mode gated behind --apply.", - paired_xfile = "Dustfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "dust", + semantics = "exnovation / removal", + security = { + leash = 'Kennel, + trust_level = "proposes deletion; --apply required to execute", + allow_network = false, + allow_filesystem_write = true, # --apply mode writes (deletes) + allow_subprocess = true, + destructive_mode_requires_flag = "--apply", + }, + metadata = { + name = "dust-runner", + version = "1.0.0", + description = "Identifies and optionally removes exnovation targets listed in Dustfile.a2ml. Destructive mode gated behind --apply.", + paired_xfile = "Dustfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, schema = { removal_candidates | Array { - id | String, - description | String, - target | String, # file / path / symbol / dep name - reason | String, # why it's a removal candidate - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String | optional, # command that confirms it's still removable - # dust has a non-standard status progression (no 'verified): - # 'declared → 'proposed → 'approved → 'removed - status | [| 'declared, 'proposed, 'approved, 'removed |] | default = 'declared, - approver | String | optional, # who signed off (for 'approved / 'removed) - notes | String | optional, - }, + id | String, + description | String, + target | String, # file / path / symbol / dep name + reason | String, # why it's a removal candidate + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String | optional, # command that confirms it's still removable + # dust has a non-standard status progression (no 'verified): + # 'declared → 'proposed → 'approved → 'removed + status | [| 'declared, 'proposed, 'approved, 'removed |] | default = 'declared, + approver | String | optional, # who signed off (for 'approved / 'removed) + notes | String | optional, + }, }, # Runner behaviour — inherits from base.run_defaults. # dust is advisory; apply_requires_approval is dust-specific. - run = base.run_defaults & { - on_any_fail = "continue-with-warnings", - report_format = "a2ml", - emit_summary = true, - apply_requires_approval = true, # only 'approved items get swept, even with --apply - }, + run = + base.run_defaults + & { + on_any_fail = "continue-with-warnings", + report_format = "a2ml", + emit_summary = true, + apply_requires_approval = true, # only 'approved items get swept, even with --apply + }, } diff --git a/.machine_readable/contractiles/intend/intend.ncl b/.machine_readable/contractiles/intend/intend.ncl index 091b7f6..175b2b2 100644 --- a/.machine_readable/contractiles/intend/intend.ncl +++ b/.machine_readable/contractiles/intend/intend.ncl @@ -20,49 +20,50 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "intend", - semantics = "north-star (commitments + aspirations)", - security = { - leash = 'Kennel, - trust_level = "read-only reporting", - allow_network = false, - allow_filesystem_write = false, - allow_subprocess = true, # probe commands may shell out (intents only; wishes never probe) - }, - metadata = { - name = "intend-runner", - version = "2.0.0", - description = "Reports progress toward committed next-actions and lists horizon aspirations. Non-gating. Absorbed `lust` semantics 2026-04-18.", - paired_xfile = "Intentfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "intend", + semantics = "north-star (commitments + aspirations)", + security = { + leash = 'Kennel, + trust_level = "read-only reporting", + allow_network = false, + allow_filesystem_write = false, + allow_subprocess = true, # probe commands may shell out (intents only; wishes never probe) + }, + metadata = { + name = "intend-runner", + version = "2.0.0", + description = "Reports progress toward committed next-actions and lists horizon aspirations. Non-gating. Absorbed `lust` semantics 2026-04-18.", + paired_xfile = "Intentfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, schema = { intents | Array { - id | String, - description | String, - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String | optional, # shell command that indicates done-ness - status | [| 'declared, 'in_progress, 'done, 'deferred, 'retired |] | default = 'declared, - notes | String | optional, - target_date | String | optional, - }, + id | String, + description | String, + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String | optional, # shell command that indicates done-ness + status | [| 'declared, 'in_progress, 'done, 'deferred, 'retired |] | default = 'declared, + notes | String | optional, + target_date | String | optional, + }, wishes | Array { - id | String, - description | String, - horizon | [| 'near, 'mid, 'far |] | default = 'mid, - why | String | optional, - status | [| 'declared, 'in_progress, 'achieved, 'abandoned |] | default = 'declared, - notes | String | optional, - } + id | String, + description | String, + horizon | [| 'near, 'mid, 'far |] | default = 'mid, + why | String | optional, + status | [| 'declared, 'in_progress, 'achieved, 'abandoned |] | default = 'declared, + notes | String | optional, + } | optional, }, @@ -70,12 +71,14 @@ let base = import "../_base.ncl" in # intend never blocks; it is a report only. # emit_diff is intent-specific (declared vs observed probes). # emit_grouped_by_horizon renders wishes grouped by near/mid/far. - run = base.run_defaults & { - on_pass = "continue", - on_any_fail = "continue", # never blocks; it's a report - report_format = "a2ml", - emit_summary = true, - emit_diff = true, # declared vs observed (intents) - emit_grouped_by_horizon = true, # wishes grouped by horizon (absorbed from lust) - }, + run = + base.run_defaults + & { + on_pass = "continue", + on_any_fail = "continue", # never blocks; it's a report + report_format = "a2ml", + emit_summary = true, + emit_diff = true, # declared vs observed (intents) + emit_grouped_by_horizon = true, # wishes grouped by horizon (absorbed from lust) + }, } diff --git a/.machine_readable/contractiles/must/must.ncl b/.machine_readable/contractiles/must/must.ncl index 47509d3..9814226 100644 --- a/.machine_readable/contractiles/must/must.ncl +++ b/.machine_readable/contractiles/must/must.ncl @@ -14,51 +14,54 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "must", - semantics = "invariant", - security = { - leash = 'Kennel, - trust_level = "read-only verification", - allow_network = false, - allow_filesystem_write = false, - allow_subprocess = true, # verification probes may shell out (e.g. grep, test -f) - }, - metadata = { - name = "must-runner", - version = "1.0.0", - description = "Evaluates every invariant in the adjacent Mustfile.a2ml as a hard gate.", - paired_xfile = "Mustfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "must", + semantics = "invariant", + security = { + leash = 'Kennel, + trust_level = "read-only verification", + allow_network = false, + allow_filesystem_write = false, + allow_subprocess = true, # verification probes may shell out (e.g. grep, test -f) + }, + metadata = { + name = "must-runner", + version = "1.0.0", + description = "Evaluates every invariant in the adjacent Mustfile.a2ml as a hard gate.", + paired_xfile = "Mustfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, # Contract schema — the shape every Mustfile.a2ml must satisfy. # Used by `contractile must typecheck Mustfile.a2ml`. schema = { invariants | Array { - id | String, - description | String, - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String, # shell command; exit 0 = pass - # status_core values: 'declared, 'verified, 'failing - status | [| 'declared, 'verified, 'failing |] | default = 'declared, - severity | [| 'critical, 'high, 'medium |] | default = 'critical, - notes | String | optional, - fix | String | optional, - }, + id | String, + description | String, + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String, # shell command; exit 0 = pass + # status_core values: 'declared, 'verified, 'failing + status | [| 'declared, 'verified, 'failing |] | default = 'declared, + severity | [| 'critical, 'high, 'medium |] | default = 'critical, + notes | String | optional, + fix | String | optional, + }, }, # Runner behaviour — consumed by the contractile CLI dispatcher. # Inherits from base.run_defaults; on_any_fail is the hard-gate default. - run = base.run_defaults & { - on_any_fail = "exit-nonzero", # hard gate - report_format = "a2ml", # emit a2ml report, not json - emit_summary = true, - }, + run = + base.run_defaults + & { + on_any_fail = "exit-nonzero", # hard gate + report_format = "a2ml", # emit a2ml report, not json + emit_summary = true, + }, } diff --git a/.machine_readable/contractiles/trust/trust.ncl b/.machine_readable/contractiles/trust/trust.ncl index 21b335c..2b83624 100644 --- a/.machine_readable/contractiles/trust/trust.ncl +++ b/.machine_readable/contractiles/trust/trust.ncl @@ -14,75 +14,81 @@ # # Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. # See: docs/CONTRACTILE-SPEC.adoc - let base = import "../_base.ncl" in { - pedigree = base.pedigree_schema & { - contractile_verb = "trust", - semantics = "security + provenance + safe-hacking", - security = { - leash = 'Kennel, - trust_level = "verification + authorised-probe", - allow_network = false, # verifications are offline by default - allow_filesystem_write = false, # trust writes NOTHING - allow_subprocess = true, - authorised_probes_only = true, # probe section must explicitly list allowed targets - }, - metadata = { - name = "trust-runner", - version = "1.0.0", - description = "Security + provenance verifications plus authorised safe-hacking probes. All probes are scoped to the repo under test; never hits external systems.", - paired_xfile = "Trustfile.a2ml", - author = "Jonathan D.A. Jewell ", + pedigree = + base.pedigree_schema + & { + contractile_verb = "trust", + semantics = "security + provenance + safe-hacking", + security = { + leash = 'Kennel, + trust_level = "verification + authorised-probe", + allow_network = false, # verifications are offline by default + allow_filesystem_write = false, # trust writes NOTHING + allow_subprocess = true, + authorised_probes_only = true, # probe section must explicitly list allowed targets + }, + metadata = { + name = "trust-runner", + version = "1.0.0", + description = "Security + provenance verifications plus authorised safe-hacking probes. All probes are scoped to the repo under test; never hits external systems.", + paired_xfile = "Trustfile.a2ml", + author = "Jonathan D.A. Jewell ", + }, }, - }, schema = { verifications | Array { - id | String, - description | String, - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String, # read-only; exit 0 = pass - # status_core values: 'declared, 'verified, 'failing - status | [| 'declared, 'verified, 'failing |] | default = 'declared, - # trust uses all four severity levels (from base.severity_core) - severity | [| 'critical, 'high, 'medium, 'low |] | default = 'high, - notes | String | optional, - }, + id | String, + description | String, + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String, # read-only; exit 0 = pass + # status_core values: 'declared, 'verified, 'failing + status | [| 'declared, 'verified, 'failing |] | default = 'declared, + # trust uses all four severity levels (from base.severity_core) + severity | [| 'critical, 'high, 'medium, 'low |] | default = 'high, + notes | String | optional, + }, # Safe-hacking + testing section (added 2026-04-17 per user direction). # Each probe here is an ACTIVELY EXECUTED test — fuzz runs, chaos probes, # auth-bypass attempts, injection tests. All scoped to the current repo. safe_hacking | { - scope | String, # e.g. "this-repo-only" / "localhost" - allowed_probe_classes - | Array [| 'fuzz, 'property_test, 'chaos, 'auth_bypass, 'injection, 'timing |] - | default = [], - probes - | Array { - id | String, - class | [| 'fuzz, 'property_test, 'chaos, 'auth_bypass, 'injection, 'timing |], - description | String, - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - probe | String, # command to run the probe - expected_outcome | [| 'probe_blocks_attempt, 'probe_finds_no_issue |], - timeout_seconds | Number | default = 300, - notes | String | optional, - } - | default = [], - } - | default = { scope = "this-repo-only", allowed_probe_classes = [], probes = [] }, + scope | String, # e.g. "this-repo-only" / "localhost" + allowed_probe_classes + | Array [| 'fuzz, 'property_test, 'chaos, 'auth_bypass, 'injection, 'timing |] + | default + = [], + probes + | Array { + id | String, + class | [| 'fuzz, 'property_test, 'chaos, 'auth_bypass, 'injection, 'timing |], + description | String, + # TODO: migrate to base.probe_schema (structured probe) when CLI supports it + probe | String, # command to run the probe + expected_outcome | [| 'probe_blocks_attempt, 'probe_finds_no_issue |], + timeout_seconds | Number | default = 300, + notes | String | optional, + } + | default + = [], + } + | default + = { scope = "this-repo-only", allowed_probe_classes = [], probes = [] }, }, # Runner behaviour — inherits from base.run_defaults. # trust has an extra field for unexpected safe-hacking outcomes. - run = base.run_defaults & { - on_any_fail = "exit-nonzero", # hard gate on verifications - safe_hacking_on_unexpected_outcome = "exit-nonzero", # probe found what it shouldn't = block - report_format = "a2ml", - emit_summary = true, - }, + run = + base.run_defaults + & { + on_any_fail = "exit-nonzero", # hard gate on verifications + safe_hacking_on_unexpected_outcome = "exit-nonzero", # probe found what it shouldn't = block + report_format = "a2ml", + emit_summary = true, + }, }