Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
412 changes: 9 additions & 403 deletions .github/SECURITY.md

Large diffs are not rendered by default.

30 changes: 30 additions & 0 deletions .github/workflows/estate-rules.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,3 +45,33 @@ jobs:

- name: Neutral template (no project identifiers)
run: bash scripts/check-no-project-identifiers.sh .

- name: State required fields
run: bash scripts/check-state.sh

- name: Required workflow capabilities
run: bash tests/workflows/validate_workflows_test.sh

- name: Compliance guardrail regression tests
run: bash tests/workflows/compliance_regression_test.sh

core-tests:
name: Zig core and LMDB crash tests
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- name: Checkout
uses: actions/checkout@v7.0.1
- name: Install LMDB and pinned Zig distribution
run: |
sudo apt-get update
sudo apt-get install --yes liblmdb-dev python3-venv
python3 -m venv "$RUNNER_TEMP/grace-tools"
"$RUNNER_TEMP/grace-tools/bin/pip" install ziglang==0.15.2
ZIG_PATH=$("$RUNNER_TEMP/grace-tools/bin/python" -c 'import pathlib, ziglang; print(pathlib.Path(ziglang.__file__).parent / "zig")')
ln -s "$ZIG_PATH" "$RUNNER_TEMP/grace-tools/bin/zig"
echo "$RUNNER_TEMP/grace-tools/bin" >> "$GITHUB_PATH"
- name: Run bounded core tests
run: bash scripts/test-core.sh
- name: Run optimized core tests
run: bash scripts/test-core.sh -O ReleaseSafe
3 changes: 1 addition & 2 deletions .github/workflows/rust-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,8 +36,7 @@ jobs:
- name: Install Rust toolchain
uses: dtolnay/rust-toolchain@v1
with:
toolchain: master
with:
toolchain: stable
components: clippy, rustfmt

- name: Cache cargo registry and build
Expand Down
32 changes: 14 additions & 18 deletions .machine_readable/STATE.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -2,26 +2,22 @@
;; Project state — update throughout each session
(state
(metadata
(version "1.0.1")
(project "rsr-template-repo")
(last-updated "2026-04-04"))
(version "1.0.2")
(project "llm-grace")
(last-updated "2026-09-28"))
(project-context
(description "RSR Standard Repository Template — baseline for all hyperpolymath projects")
(description "Graceful degradation for concurrent LLM/agent terminals")
(primary-language "Idris2 (ABI) + Zig (FFI)")
(status "testing-complete"))
(status "development; release readiness not established"))
(current-position
(phase "testing")
(completion-percentage 100)
(milestone "CRG C - Testing & Benchmarking complete"))
(phase "implementation-and-validation")
(milestone "Issue #4: ledger and checked sampler primitives implemented; monitor integration pending"))
(testing-summary
(validation-script "scripts/validate-template.sh: PASS (0 errors)")
(workflow-tests "tests/workflows/validate_workflows_test.sh: PASS (21/21 workflows)")
(integration-tests "test/integration_test.zig: PASS (placeholder template)")
(e2e-tests "tests/e2e/template_instantiation_test.sh: READY")
(benchmarks "benches/template_bench.sh: PASS (5 suites)")
(zig-build "Zig 0.15.2 compatible: PASS"))
(repository-structure "Local structural checks pass; not a release gate")
(compiler-checks "Zig 0.15.2: core sampler/control/ledger tests; Idris2 unavailable; FFI build is scaffolding")
(security-scans "Not run in compliance audit: scanners unavailable")
(compliance-review "docs/governance/COMPLIANCE-REVIEW.adoc"))
(critical-next-actions
("Commit test suite"
"Push to GitHub"
"Verify CI workflows pass"
"Document test instantiation patterns")))
("Owner reconcile issue #2, ADR-0005 and draft REUSE.toml without automated relicensing"
"Run compiler, integration and security gates with required toolchains"
"Verify hosted governance and branch protection before release")))
4 changes: 4 additions & 0 deletions .machine_readable/identifier-allow.txt
Original file line number Diff line number Diff line change
Expand Up @@ -27,3 +27,7 @@
.machine_readable/ai/.cursorrules AffineScript
.machine_readable/ai/.windsurfrules AffineScript
docs/RSR_OUTLINE.adoc AffineScript
# Shared label taxonomy and classifier examples, not project identity.
.github/label-classifier.json AffineScript
.github/labels.json AffineScript
.github/scripts/classify-issue.jq AffineScript
3 changes: 3 additions & 0 deletions .machine_readable/root-allow.txt
Original file line number Diff line number Diff line change
Expand Up @@ -78,3 +78,6 @@ container/ # may host Containerfile if not at build/
.gitlab-ci.yml # TODO: relocate to ci/.gitlab-ci.yml after GitLab project-setting update
.pre-commit-config.yaml # TODO: relocate to ci/.pre-commit-config.yaml after invocation pattern decided
tools/ # TODO: consolidate with scripts/ or document the split (pending decision)

# Local Zig test/build cache; ignored by Git, created by `just test`.
.zig-cache/
3 changes: 3 additions & 0 deletions .tool-versions
Original file line number Diff line number Diff line change
Expand Up @@ -8,3 +8,6 @@
# zig 0.14.0
# idris2 0.7.0
rust nightly

# Core sampler/ledger test toolchain (do not use a floating Zig version).
zig 0.15.2
13 changes: 12 additions & 1 deletion 0-AI-MANIFEST.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
#
[metadata]
version = "0.1.0"
last-updated = "2026-05-18"
last-updated = "2026-09-28"

[project]
name = "llm-grace"
Expand All @@ -32,3 +32,14 @@ items = [
{ agent = "GEMINI", task = "estate audits, cross-repo sweeps, long-context triage, pattern detection" },
{ agent = "VIBE", task = "UI/frontend, PanLL panels, ReScript components, theming, rapid prototyping" },
]

[compliance-review]
report = "docs/governance/COMPLIANCE-REVIEW.adoc"
licensing = "Issue #2 remains owner-manual only; no existing SPDX or license declarations changed"
status = "Local guardrail repairs; full RSR and release compliance not certified"

[core-implementation]
issue = "https://github.com/hyperpolymath/llm-grace/issues/4"
decision = "docs/decisions/0006-ledger-and-proof-boundaries.adoc"
status = "Tested primitives; no live monitor, session autoconnection, or global deployment"
proofs = "Finite policy tests only; no new formal proofs claimed"
52 changes: 16 additions & 36 deletions Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -124,36 +124,22 @@ clean-all: clean
# TEST & QUALITY
# ═══════════════════════════════════════════════════════════════════════════════

# Run all tests
# Run real core tests (LMDB headers/library required; optional LMDB_PREFIX).
test *args:
@echo "Running tests..."
# TODO: Replace with your test command
# Examples:
# cargo test {{args}}
# mix test {{args}}
# zig build test {{args}}
# deno test {{args}}
@echo "Tests passed!"
bash scripts/test-core.sh {{args}}

# Run tests with verbose output
# Zig's test runner already reports each named test and its outcome.
test-verbose:
@echo "Running tests (verbose)..."
# TODO: Replace with verbose test command
just test

# Smoke test
# Pure signal smoke test (no LMDB required).
test-smoke:
@echo "Smoke test..."
# TODO: Add basic sanity checks
zig test src/signal/sampler.zig

# Run end-to-end tests (full pipeline: build → run → verify)
# End-to-end monitor/hook tests are not implemented; never report fake success.
e2e:
@echo "Running E2E tests..."
# TODO: Replace with your E2E test command. Examples:
# bash tests/e2e.sh # Shell-based E2E
# npx playwright test # Browser E2E
# mix test test/integration/e2e_test.exs # Elixir E2E
# cargo test --test end_to_end # Rust E2E
@echo "E2E tests passed!"
@echo "ERROR: live monitor/hook acceptance suite is not implemented (issue #4)" >&2
@exit 1

# Run aspect tests (cross-cutting concern validation)
aspect:
Expand Down Expand Up @@ -287,14 +273,9 @@ deps:

# Audit dependencies for vulnerabilities
deps-audit:
@echo "Auditing for vulnerabilities..."
# TODO: Replace with your audit command
# Examples:
# cargo audit
# mix audit
@command -v trivy >/dev/null && trivy fs --severity HIGH,CRITICAL --quiet . || true
@command -v gitleaks >/dev/null && gitleaks detect --source . --no-git --quiet || true
@echo "Audit complete"
@command -v trivy >/dev/null || { echo "ERROR: trivy is required" >&2; exit 1; }
trivy fs --severity HIGH,CRITICAL --exit-code 1 .


# ═══════════════════════════════════════════════════════════════════════════════
# DOCUMENTATION
Expand Down Expand Up @@ -529,10 +510,8 @@ install-hooks:

# Run security audit
security: deps-audit
@echo "=== Security Audit ==="
@command -v gitleaks >/dev/null && gitleaks detect --source . --verbose || true
@command -v trivy >/dev/null && trivy fs --severity HIGH,CRITICAL . || true
@echo "Security audit complete"
@command -v gitleaks >/dev/null || { echo "ERROR: gitleaks is required" >&2; exit 1; }
gitleaks detect --source . --redact

# Generate SBOM
sbom:
Expand Down Expand Up @@ -678,7 +657,8 @@ maint-assault:

# Run panic-attacker pre-commit scan (foundational floor-raise requirement)
assail:
@command -v panic-attack >/dev/null 2>&1 && panic-attack assail . || echo "WARN: panic-attack not found — install from https://github.com/hyperpolymath/panic-attacker"
@command -v panic-attack >/dev/null 2>&1 || { echo "ERROR: panic-attack is required" >&2; exit 1; }
panic-attack assail .


# Self-diagnostic — checks dependencies, permissions, paths
Expand Down
8 changes: 8 additions & 0 deletions PROOF-STATUS.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -98,3 +98,11 @@ panic-attack assail --proofs-only

| 2026-04-04 | Initial proof status tracking | Template
|===

== Core Ledger and Control Review (2026-09-28)

No new formal proofs are claimed. The finite control model now has exhaustive
state/event tests in `src/control/ladder.zig`; ledger process-crash tests and
checked sampler fixtures are executable evidence, not Lean/Agda/Idris proofs.
See `docs/decisions/0006-ledger-and-proof-boundaries.adoc` for concrete proof
targets and scoped applications of the owner's type-theory repositories.
6 changes: 6 additions & 0 deletions README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -75,3 +75,9 @@ link:docs/decisions/0005-licensing-mpl-now-pmpl-overlay-later.adoc[ADR-0005].
Scaffolded from `+rsr-template-repo+` (the neutral RSR skeleton). The
full RSR placeholder bootstrap and the per-file SPDX relicense are
tracked build sub-issues rather than rushed inline — foundation-first.

== AI-Assisted Installation

There is no production installer yet. For a safe development checkout, see
link:docs/AI_INSTALLATION_GUIDE.adoc[AI-assisted development setup].
Local structural checks are not proof of runtime safety or release readiness.
42 changes: 42 additions & 0 deletions SECURITY.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -9,3 +9,45 @@ assessment within 7 days - Fix or mitigation within 90 days

*Safe harbour:* We will not pursue legal action against security
researchers who follow responsible disclosure.


=== Scope and Supported Versions

llm-grace is development software; no stable-release or historical-version
support promise is established. Reports against the current development branch
are welcome. Response timelines above are targets, not guaranteed remediation
deadlines. No monetary bounty is offered.

Private reporting is also available at
https://github.com/hyperpolymath/llm-grace/security/advisories/new[GitHub Security Advisories]
when enabled; use the email address above if it is unavailable.
Do not publish credentials, private prompts, process environments, or ledger
contents in public issues. Include the affected commit, minimal reproduction,
impact, and a redacted diagnostic sample.

=== Safe Research and Deployment

Test only systems and sessions you own or have explicit permission to test.
Do not load-test shared hosts, terminate unrelated processes, or inspect another
user's session data. Safe harbour does not extend to third-party infrastructure.

Run memory-balloon and process-signal experiments in an isolated, disposable
session with resource limits. Do not run the sampler as root or enable global
process control before the isolation and recovery tests pass. Treat ledger
files and diagnostic artefacts as potentially sensitive; restrict access and
redact them before sharing.

=== Contributor Security and Quality Gates

* Never commit credentials or unredacted scanner output.
* `just security` requires Trivy and Gitleaks and fails on scanner errors or
configured findings; a missing scanner is not a clean scan.
* `just assail` requires panic-attack and propagates its exit status.
* `just validate` checks repository structure and documentation. It is not
evidence that runtime tests, proofs, external governance, or security scans pass.
* Review CI permissions, external action/tool provenance, dependencies, and
changes to process targeting, resource limits, and crash recovery.
* Follow `AUDIT.adoc` and `READINESS.adoc`; do not infer release readiness from
template tests or skipped jobs.

See `docs/governance/COMPLIANCE-REVIEW.adoc` for outstanding audit limitations.
55 changes: 7 additions & 48 deletions build/just/validate.just
Original file line number Diff line number Diff line change
Expand Up @@ -10,56 +10,15 @@

# Validate RSR compliance
validate-rsr:
#!/usr/bin/env bash
echo "=== RSR Compliance Check ==="
MISSING=""
for f in .editorconfig .gitignore Justfile README.adoc LICENSE; do
[ -f "$f" ] || MISSING="$MISSING $f"
done
for f in .machine_readable/STATE.a2ml .machine_readable/META.a2ml .machine_readable/ECOSYSTEM.a2ml .machine_readable/anchors/ANCHOR.a2ml .machine_readable/policies/MAINTENANCE-AXES.a2ml .machine_readable/policies/MAINTENANCE-CHECKLIST.a2ml .machine_readable/policies/SOFTWARE-DEVELOPMENT-APPROACH.a2ml; do
[ -f "$f" ] || MISSING="$MISSING $f"
done
for f in licensing/exhibits/EXHIBIT-A-ETHICAL-USE.txt licensing/exhibits/EXHIBIT-B-QUANTUM-SAFE.txt licensing/texts/MPL-2.0.txt; do
[ -f "$f" ] || MISSING="$MISSING $f"
done
if [ ! -d "src/interface/Abi" ] && [ ! -d "src/interface/abi" ]; then
MISSING="$MISSING src/interface/Abi"
fi
for f in src/interface/ffi src/interface/generated; do
[ -d "$f" ] || MISSING="$MISSING $f"
done
for f in docs/governance/MAINTENANCE-CHECKLIST.adoc docs/governance/SOFTWARE-DEVELOPMENT-APPROACH.adoc; do
[ -f "$f" ] || MISSING="$MISSING $f"
done
if [ -f ".machine_readable/META.a2ml" ]; then
grep -q 'axis-1 = "must > intend > like"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:axis-1"
grep -q 'axis-2 = "corrective > adaptive > perfective"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:axis-2"
grep -q 'axis-3 = "systems > compliance > effects"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:axis-3"
grep -q 'scoping-first = true' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:scoping-first"
grep -q 'idris-unsound-scan = "believe_me/assert_total"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:idris-unsound-scan"
grep -q 'audit-focus = "systems in place, documentation explains actual state, safety/security accounted for, observed effects reviewed"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:audit-focus"
grep -q 'compliance-focus = "seams/compromises/exception register, bounded exceptions, anti-drift checks"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:compliance-focus"
grep -q 'effects-evidence = "benchmark execution/results and maintainer status dialogue/review"' .machine_readable/META.a2ml || MISSING="$MISSING META.a2ml:effects-evidence"
grep -q 'compliance-tooling = "panic-attack"' .machine_readable/policies/MAINTENANCE-AXES.a2ml || MISSING="$MISSING MAINTENANCE-AXES.a2ml:compliance-tooling"
grep -q 'effects-tooling = "ecological checking with sustainabot guidance"' .machine_readable/policies/MAINTENANCE-AXES.a2ml || MISSING="$MISSING MAINTENANCE-AXES.a2ml:effects-tooling"
grep -q 'source-human = "docs/governance/MAINTENANCE-CHECKLIST.adoc"' .machine_readable/policies/MAINTENANCE-CHECKLIST.a2ml || MISSING="$MISSING MAINTENANCE-CHECKLIST.a2ml:source-human"
grep -q 'source-human = "docs/governance/SOFTWARE-DEVELOPMENT-APPROACH.adoc"' .machine_readable/policies/SOFTWARE-DEVELOPMENT-APPROACH.a2ml || MISSING="$MISSING SOFTWARE-DEVELOPMENT-APPROACH.a2ml:source-human"
fi
if [ -n "$MISSING" ]; then
echo "MISSING:$MISSING"
exit 1
fi
echo "RSR compliance: PASS"
bash scripts/validate-template.sh .
bash scripts/check-root-shape.sh .
bash scripts/check-no-md-in-docs.sh .
bash tests/workflows/validate_workflows_test.sh

# Validate STATE.a2ml syntax
# Structural check for the repository's S-expression STATE format, not TOML.
# This is a required-field check, not a full A2ML parser or readiness proof.
validate-state:
@if [ -f ".machine_readable/STATE.a2ml" ]; then \
grep -q '^\[metadata\]' .machine_readable/STATE.a2ml && \
grep -q 'project\s*=' .machine_readable/STATE.a2ml && \
echo "STATE.a2ml: valid" || echo "STATE.a2ml: INVALID (missing required sections)"; \
else \
echo "No .machine_readable/STATE.a2ml found"; \
fi
bash scripts/check-state.sh .machine_readable/STATE.a2ml

# Validate AI installation guide completeness (finishbot pre-release check)
validate-ai-install:
Expand Down
43 changes: 43 additions & 0 deletions docs/AI_INSTALLATION_GUIDE.adoc
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
= llm-grace: AI-Assisted Development Setup

[[ai-implementation]]
== Current Implementation Boundary

This is a development checkout, not an installable production service.
The sampler and crash-safe ledger work is tracked in GitHub issue #4.
Do not install a global daemon, wire production hooks, or promise recovery of
user work based on this scaffolding.

== Obtain and Inspect the Source

[source,shell]
----
git clone https://github.com/hyperpolymath/llm-grace.git
cd llm-grace
bash scripts/check-root-shape.sh .
bash scripts/check-state.sh
bash tests/workflows/compliance_regression_test.sh
----

Read `README.adoc`, `AUDIT.adoc`, `READINESS.adoc`, `SECURITY.adoc`, and
`docs/decisions/0003-graceful-degradation-architecture.adoc` before making changes.
With Just installed, `just validate` runs the local structural/documentation
gates. Zig and Idris2 are needed for compiler checks; skipped checks do not
constitute build evidence. `just security` additionally requires Trivy and
Gitleaks. Consult `.tool-versions` and the component build documentation before
selecting compiler versions. Do not pipe remote installation scripts into a shell
without reviewing and verifying their provenance.

== Privacy and Isolation

Never send credentials, private prompts, ledger records, or full process
environments to an assistant. Review commands before execution. Keep experimental
memory pressure and process signalling inside a disposable, resource-limited
session; no privileged or global deployment is authorized by this guide.

== Licensing Boundary

Issue #2 reserves existing license/SPDX changes to manual owner review.
Agents must not relicense files, expand blanket licensing globs, or rewrite
third-party headers as part of setup. Report conflicts instead.
Loading
Loading