The README makes claims. This file backs them up — against files that actually exist. (An earlier version of this document cited OCaml sources that were never written; that failure mode is precisely what this project now exists to prevent.)
From README: "You write policies as machine-readable, deontic rules and
plasma check evaluates a repository against them exactly."
Evidence: The typed AST is plasma-engine/src/ast.rs (subjects, resources,
composable conditions, deontic modalities, actions, overlays). The evaluator
is plasma-engine/src/eval.rs — a pure function with no IO; every fact it
sees comes from plasma-engine/src/facts.rs (BTree-ordered, no timestamps).
Determinism is enforced by test: tests/check_selftest.rs
(check_json_is_deterministic) runs plasma check twice and asserts
byte-identical JSON, and plasma-engine/src/eval.rs has the same check at
unit level (test_determinism_identical_runs). Unsupported constructs are
rejected at load in plasma-engine/src/schema.rs, so evaluation is total.
From README: "`plasma check .` evaluates this very repository."
Evidence: The bundled policy plasma-engine/policies/repo-hygiene.plasma.toml
requires a LICENSE, a README, and parseable SPDX headers on source files.
tests/check_selftest.rs (check_self_passes) fails the build if this
repository stops satisfying its own shipped policy.
From README: "`plasma audit` checks SPDX headers against a zone-aware license map, powered by a real SPDX expression parser."
Evidence: The recursive-descent SPDX parser is
plasma-parser/src/spdx/mod.rs with lexer (spdx/lexer.rs) and identifier
catalog (spdx/catalog.rs, including Palimpsest-family extensions). Zone
mapping from .plasma.toml is plasma-parser/src/zone/boundary.rs; the
repository scanner is plasma-parser/src/audit/scan.rs; the CLI wiring is
src/audit.rs — which uses that parser rather than substring matching.
cargo test --workspace: 66 tests at the time of writing — inline units in
plasma-parser (SPDX parsing, catalog, zones, compat, content detection) and
plasma-engine (schema validation, evaluation semantics, SARIF shape), plus
the root self-tests described above.
| Technology | Why |
|---|---|
Rust |
One toolchain for parser, engine, and CLI; |
TOML + JSON policies |
TOML for humans, JSON for interchange; both deserialize to the same serde model ( |
SARIF 2.1.0 |
Stable |
Elixir (NimblePublisher) |
Static site generation for the guidance site ( |
| Path | What’s There |
|---|---|
|
Typed policy AST: subjects, resources, conditions, modalities, actions, overlays |
|
Versioned loading (TOML/JSON), load-time rejection of reserved constructs |
|
Fact collection — the only impure module |
|
Pure, total evaluator with the deontic matrix |
|
Human and SARIF renderers |
|
The bundled, self-applied policy |
|
SPDX lexer, parser, identifier catalog |
|
|
|
Header extraction, repo scanning, LICENSE content detection |
|
The |
|
Normative semantics + Catala-readiness guarantees |
|
Historical OCaml-typed design (lineage) |
|
Elixir mix project for the guidance site |