Skip to content

Commit b9f3b72

Browse files
committed
chore: fill derivable placeholders, drop false ARCHITECTURE, surface the rest
Estate top-up pass. Three separate things, none of which invents a value. FILLED — every token with a single mechanical answer: OWNER, REPO, FORGE, PROJECT, PACKAGE_NAME, PROJECT_NAME, AUTHOR, AUTHOR_EMAIL, CONDUCT_EMAIL, AUTHOR_FIRST/LAST/INITIALS, CURRENT_YEAR, CURRENT_DATE, DATE, MAIN_BRANCH. Identity comes from the git remote, dates from the clock, project name from the README H1 where there is one. Deliberately NOT filled, because more than one defensible answer exists and a confident wrong value is worse than a visible gap: SECURITY_EMAIL (two competing addresses are in use across the estate), RESPONSE_TIME, CONDUCT_TEAM (which substitutes into "a {{CONDUCT_TEAM}} member", not English), WEBSITE, PROJECT_DESCRIPTION, LANG_STACK. DELETED — ARCHITECTURE.md, where it is byte-identical to the 346-copy estate boilerplate (blob 607e3d8). Those 33 lines describe a src/ tests/ docs/ scripts/ config/ tree that this repo does not have, so the file is not merely uninformative, it is wrong. Genuinely written ARCHITECTURE files are matched by hash and left alone. No file beats a confidently false one. CODEOWNERS — rewritten to the solo form mandated by hyperpolymath/standards CODEOWNERS-POLICY.adoc Rule 1, which forbids a catch-all line where the only owner is the sole maintainer. The estate's own templates/CODEOWNERS contradicts that policy; the policy is versioned, dated and resolves standards#55, so it wins. Files naming a genuine co-owner are Rule 2 and are untouched. Note @hyperpolymath and @metadatastician are the same person, so a file naming the other account is a copy artifact that silently routed review requests to the wrong account. SURFACED — REQUIRES_INITIALISATION.md, and a priority action in 0-AI-MANIFEST.a2ml. Tokens that need a decision no script can make are left visibly unfilled rather than faked or quietly deleted. The marker says what each one is, which files it belongs in, why it was not done already, and that it must be deleted only once the work is genuinely finished.
1 parent 95b2d67 commit b9f3b72

7 files changed

Lines changed: 237 additions & 51 deletions

File tree

‎.machine_readable/agent_instructions/methodology.a2ml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -101,7 +101,7 @@ constraints = [
101101
# These rules detect corrupt/template/stale state files.
102102

103103
[methodology.state-validation]
104-
reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]
104+
reject-if-contains = ["{{PLACEHOLDER}}", "CLOUDGUARD_CLI", "rsr-template-repo"]
105105
reject-if-project-name-mismatch = true
106106
staleness-threshold-days = 90
107107
fallback-files = ["TODO.md", "TODO.adoc", "ROADMAP.adoc", "README.adoc"]

‎0-AI-MANIFEST.a2ml‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,3 +47,20 @@ cloudguard dns list|add|delete|bulk-add
4747
cloudguard zones list|status
4848
cloudguard pages list
4949
```
50+
51+
<!-- BEGIN requires-initialisation -->
52+
53+
## PRIORITY ACTION — this repository is not fully initialised
54+
55+
22 substitution token(s) still have no value. **Read
56+
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
57+
else here** — it lists every outstanding token, what it means, and which
58+
files it belongs in.
59+
60+
Do not fabricate values for them, and do not delete the sections that
61+
contain them to quiet a gate. They are unfilled because they need a
62+
decision, not because they were overlooked. Resolve what you legitimately
63+
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when
64+
nothing outstanding remains.
65+
66+
<!-- END requires-initialisation -->

‎ARCHITECTURE.md‎

Lines changed: 0 additions & 47 deletions
This file was deleted.

‎PLACEHOLDERS.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@ sed -i "s/2026-03-02/$(date +%Y-%m-%d)/g" $(grep -rl '2026-03-02' .)
7171
| `[PGP fingerprint not set]` | 40-char PGP fingerprint | `ABCD 1234 ...` | SECURITY.md |
7272
| `{{PGP_KEY_URL}}` | URL to public PGP key | `https://keys.openpgp.org/...` | SECURITY.md |
7373
| `{{WEBSITE}}` | Project website | `https://example.org` | SECURITY.md |
74-
| `{{CONDUCT_EMAIL}}` | Conduct reports email | `conduct@example.org` | CODE_OF_CONDUCT.md |
74+
| `j.d.a.jewell@open.ac.uk` | Conduct reports email | `conduct@example.org` | CODE_OF_CONDUCT.md |
7575
| `{{CONDUCT_TEAM}}` | Conduct committee name | `Code of Conduct Committee` | CODE_OF_CONDUCT.md |
7676
| `{{RESPONSE_TIME}}` | SLA for initial response | `48 hours` | CODE_OF_CONDUCT.md |
7777

‎REQUIRES_INITIALISATION.md‎

Lines changed: 216 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,216 @@
1+
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->
2+
3+
# REQUIRES INITIALISATION
4+
5+
**This repository is not finished being set up.** 22 substitution token(s) across 9 file(s) still have no value.
6+
7+
## Why this is not already done
8+
9+
This repo was created from `hyperpolymath/rsr-template-repo`. The mint
10+
(`just repo-init`) fills every token that has a single mechanical answer —
11+
owner, repo, author, dates, licence, branch — and it has done so here.
12+
13+
The tokens below are the ones it *deliberately cannot* answer. They need a
14+
decision or a fact that exists only in your head: what this project is for,
15+
what command builds it, which port the service listens on, whether a PGP key
16+
is held at all. The template's own token vocabulary says as much — you cannot
17+
sensibly answer "required invariants" in a thirty-second bootstrap.
18+
19+
They were left **visibly unfilled on purpose**. The alternatives were both
20+
worse: inventing plausible values would put confident falsehoods into a
21+
security policy and an architecture document, and silently deleting the
22+
sections would hide the fact that a decision is owed. A visible gap is
23+
honest; a fabricated answer is not.
24+
25+
## Do not delete this file until every item below is resolved
26+
27+
This file is the only marker that the work is outstanding. Deleting it early
28+
does not finish the setup, it just conceals it — and the next person or agent
29+
to arrive will reasonably assume the repo is complete.
30+
31+
- **If you are a person:** delete this file yourself once the last item is done.
32+
- **If you are an agent:** resolve what you legitimately can, leave the rest,
33+
and delete this file only when no token below remains anywhere in the tree.
34+
Do not delete it to make a gate go green.
35+
36+
Re-running the estate top-up tool will remove this file automatically once
37+
nothing is outstanding, so the safest way to finish is to fix the tokens and
38+
let the check confirm it.
39+
40+
## What is needed, and where it goes
41+
42+
### `{{AUTHOR_ORG}}`
43+
44+
Author's organisation. NOTE: no filled instance of this exists anywhere in the estate — consider deleting the field instead.
45+
46+
Appears in:
47+
48+
- `.machine_readable/svc/k9/examples/project-metadata.k9.ncl`
49+
- `PLACEHOLDERS.md`
50+
51+
### `{{CONDUCT_TEAM}}`
52+
53+
Name of the conduct body. If there is no committee, rewrite the sentence rather than substituting a plural noun into 'a {{CONDUCT_TEAM}} member'.
54+
55+
Appears in:
56+
57+
- `PLACEHOLDERS.md`
58+
59+
### `{{CONSUMER1}}`
60+
61+
A downstream repo that consumes this one.
62+
63+
Appears in:
64+
65+
- `.machine_readable/INTENT.contractile`
66+
67+
### `{{CONSUMER2}}`
68+
69+
A second downstream consumer.
70+
71+
Appears in:
72+
73+
- `.machine_readable/INTENT.contractile`
74+
75+
### `{{DEP1}}`
76+
77+
First named dependency, in .machine_readable/INTENT.contractile.
78+
79+
Appears in:
80+
81+
- `.machine_readable/INTENT.contractile`
82+
83+
### `{{DEP2}}`
84+
85+
Second named dependency, in .machine_readable/INTENT.contractile.
86+
87+
Appears in:
88+
89+
- `.machine_readable/INTENT.contractile`
90+
91+
### `{{DOMAIN}}`
92+
93+
Appears in:
94+
95+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
96+
97+
### `{{DS_RECORD}}`
98+
99+
Appears in:
100+
101+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
102+
103+
### `{{KEY_TAG}}`
104+
105+
Appears in:
106+
107+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
108+
109+
### `{{LICENSE}}`
110+
111+
SPDX identifier for this repo's licence.
112+
113+
Appears in:
114+
115+
- `container/Containerfile`
116+
- `container/manifest.toml`
117+
118+
### `{{MONOREPO_OR_STANDALONE}}`
119+
120+
Literally 'monorepo' or 'standalone'.
121+
122+
Appears in:
123+
124+
- `.machine_readable/INTENT.contractile`
125+
126+
### `{{MTA_STS_ID}}`
127+
128+
Appears in:
129+
130+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
131+
132+
### `{{ONE_PARAGRAPH_ANTI_PURPOSE}}`
133+
134+
A paragraph on what this deliberately is NOT for.
135+
136+
Appears in:
137+
138+
- `.machine_readable/INTENT.contractile`
139+
140+
### `{{ONE_PARAGRAPH_PURPOSE}}`
141+
142+
A paragraph on what this is for.
143+
144+
Appears in:
145+
146+
- `.machine_readable/INTENT.contractile`
147+
148+
### `{{PGP_KEY_URL}}`
149+
150+
Public URL the PGP key can be fetched from. Same caveat as PGP_FINGERPRINT.
151+
152+
Appears in:
153+
154+
- `PLACEHOLDERS.md`
155+
156+
### `{{PROJECT_DOMAIN}}`
157+
158+
Taxonomy value for the subject domain.
159+
160+
Appears in:
161+
162+
- `.machine_readable/anchors/ANCHOR.a2ml`
163+
164+
### `{{PROJECT_KIND}}`
165+
166+
Taxonomy value (library, service, tool, lab…).
167+
168+
Appears in:
169+
170+
- `.machine_readable/anchors/ANCHOR.a2ml`
171+
172+
### `{{PROJECT_PURPOSE}}`
173+
174+
One line: what this exists to do.
175+
176+
Appears in:
177+
178+
- `.machine_readable/anchors/ANCHOR.a2ml`
179+
- `PLACEHOLDERS.md`
180+
- `guix.scm`
181+
182+
### `{{PROJECT_UNIQUE_STRENGTH}}`
183+
184+
What this does that its alternatives do not.
185+
186+
Appears in:
187+
188+
- `.machine_readable/agent_instructions/methodology.a2ml`
189+
190+
### `{{RESPONSE_TIME}}`
191+
192+
Initial-response SLA for a security or conduct report. Promise only what a solo maintainer can actually meet.
193+
194+
Appears in:
195+
196+
- `PLACEHOLDERS.md`
197+
198+
### `{{SECURITY_TXT_EXPIRES}}`
199+
200+
Appears in:
201+
202+
- `.machine_readable/contractiles/trust/Trustfile.a2ml`
203+
204+
### `{{WEBSITE}}`
205+
206+
Project homepage URL, or delete the field if there is none.
207+
208+
Appears in:
209+
210+
- `PLACEHOLDERS.md`
211+
212+
---
213+
214+
Generated by the estate top-up pass. Rationale and the governing rulings are
215+
in `hyperpolymath/standards`; the token vocabulary is
216+
`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.

‎container/manifest.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,7 @@ tracking.
1717
"""
1818
license = "{{LICENSE}}"
1919
homepage = "https://github.com/hyperpolymath/cloudguard-cli"
20-
maintainer = "Jonathan D.A. Jewell <{{EMAIL}}>"
20+
maintainer = "Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>"
2121

2222
[provenance]
2323
upstream = "https://github.com/hyperpolymath/cloudguard-cli"

‎container/vordr.toml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ output = "stdout"
9494
# on = ["failure", "recovery", "resource_critical"]
9595

9696
# [notifications.email]
97-
# to = "{{EMAIL}}"
97+
# to = "j.d.a.jewell@open.ac.uk"
9898
# from = "vordr@cloudguard-cli.local"
9999
# smtp = "smtp://localhost:25"
100100
# on = ["failure", "resource_critical"]

0 commit comments

Comments
 (0)