Skip to content

chore: Item 9 — retire ReScript guidance → AffineScript - #73

Merged
hyperpolymath merged 3 commits into
mainfrom
chore/item9-rescript-to-affinescript-guidance
May 18, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
chore/item9-rescript-to-affinescript-guidance

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Estate Tech-Debt — Item 9 (ReScript→AffineScript CI-text sweep)

Rewrites guidance/policy text that recommended ReScript as the
TypeScript/Python replacement to recommend AffineScript instead, per the
estate language policy (RS/TS/JS → AffineScript → typed-wasm).

Scope

  • ✅ In scope: "use ReScript instead" guidance, Rust/ReScript migration-guide
    phrasing, Rust or ReScript policy text.
  • ⛔ Out of scope (intentionally untouched): any rescript-named path/dir and
    ReScript adapters (e.g. proven). That work is preserved intact and usable
    for the ReScript ecosystem — only the forward-looking recommendation changes.

Mechanical, reviewed substitution; residual in-scope occurrences verified 0.

🤖 Generated with Claude Code

Estate language policy: RS/TS/JS → AffineScript → typed-wasm. This rewrites
guidance/policy text that recommended ReScript as the TypeScript/Python
replacement so it now points at AffineScript.

Scope guard (deliberate): rescript-named paths and ReScript adapters are NOT
touched — that work is preserved intact for the ReScript ecosystem. Only the
forward-looking "use ReScript instead" recommendation is updated.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request May 18, 2026
…rywhere (#101)

## What

Canonicalises the estate ruling of 2026-05-18 and supersedes the prior
standing
rule "Nix shard fallback on Guix channel primary everywhere".

- **`spec/LANGUAGE-POLICY.adoc` §Package Management** — the canonical
statement.
Guix primary; **sealed container (not a Nix mirror)** is the single
universal
escape hatch for the not-in-Guix / non-free tail; one packager per repo;
a
second packager only as the sole source of a specific named dependency.
- **`.machine_readable/agent_instructions/debt.a2ml`** — estate-wide
`flake.nix`-mirror removal + consumer-doc reconciliation logged as a
SHOULD
  debt item.

## Why

A `flake.nix` that only mirrors the Guix manifest is two incomplete
manifests
hand-synced plus containers anyway = pure drift surface, never exercised
as a
real fallback. Guix's full-source bootstrap + `guix time-machine` is
provenance-thesis-aligned; the non-free / not-in-Guix tail (which Guix's
FSDG
structurally excludes) goes to the already-mandated sealed container,
not a Nix
twin.

## Pilot already landed

`hyperpolymath/echidna` PR #73 applied this: `flake.nix`/`flake.lock`
removed,
9 Tier-3 prover Containerfiles consolidated into one sealed multi-target
`Containerfile.wave3`, manifest/CLAUDE/Justfile/STATE reconciled.

## Scope

Surgical: only the canonical §Package Management statement + the debt
record.
The broad consumer-repo sweep (other docs that still say "Fallback:
Nix") is
deliberately deferred to the tracked debt item, per
centralised-standards
(link-don't-copy) — not swept here.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
…to-affinescript-guidance

# Conflicts:
#	0-ai-gatekeeper-protocol/.github/workflows/rsr-antipattern.yml
#	0-ai-gatekeeper-protocol/.github/workflows/ts-blocker.yml
#	0-ai-gatekeeper-protocol/mcp-repo-guardian/.github/workflows/rsr-antipattern.yml
#	0-ai-gatekeeper-protocol/mcp-repo-guardian/.github/workflows/ts-blocker.yml
#	0-ai-gatekeeper-protocol/repo-guardian-fs/.github/workflows/rsr-antipattern.yml
#	0-ai-gatekeeper-protocol/repo-guardian-fs/.github/workflows/ts-blocker.yml
#	a2ml/.github/workflows/rsr-antipattern.yml
#	a2ml/.github/workflows/ts-blocker.yml
#	a2ml/bindings/deno/.github/workflows/rsr-antipattern.yml
#	a2ml/bindings/deno/.github/workflows/ts-blocker.yml
#	a2ml/bindings/haskell/.github/workflows/rsr-antipattern.yml
#	a2ml/bindings/haskell/.github/workflows/ts-blocker.yml
#	a2ml/bindings/rust/.github/workflows/rsr-antipattern.yml
#	a2ml/bindings/rust/.github/workflows/ts-blocker.yml
#	a2ml/editors/vscode/.github/workflows/rsr-antipattern.yml
#	a2ml/editors/vscode/.github/workflows/ts-blocker.yml
#	a2ml/pandoc/.github/workflows/rsr-antipattern.yml
#	a2ml/pandoc/.github/workflows/ts-blocker.yml
#	consent-aware-http/.github/workflows/rsr-antipattern.yml
#	k9-svc/actions/validate/.github/workflows/rsr-antipattern.yml
#	k9-svc/actions/validate/.github/workflows/ts-blocker.yml
#	k9-svc/bindings/deno/.github/workflows/rsr-antipattern.yml
#	k9-svc/bindings/deno/.github/workflows/ts-blocker.yml
#	k9-svc/bindings/haskell/.github/workflows/rsr-antipattern.yml
#	k9-svc/bindings/haskell/.github/workflows/ts-blocker.yml
#	k9-svc/bindings/rust/.github/workflows/rsr-antipattern.yml
#	k9-svc/bindings/rust/.github/workflows/ts-blocker.yml
#	k9-svc/editors/vscode/.github/workflows/rsr-antipattern.yml
#	k9-svc/editors/vscode/.github/workflows/ts-blocker.yml
#	k9-svc/pandoc/.github/workflows/rsr-antipattern.yml
#	k9-svc/pandoc/.github/workflows/ts-blocker.yml
#	lol/.github/workflows/rsr-antipattern.yml
#	lol/.github/workflows/ts-blocker.yml
#	meta-a2ml/.github/workflows/rsr-antipattern.yml
#	meta-a2ml/.github/workflows/ts-blocker.yml
#	rhodium-standard-repositories/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/cccp/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/cccp/.github/workflows/ts-blocker.yml
#	rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/cccp/satellites/nextgen-languages/7-tentacles/.github/workflows/ts-blocker.yml
#	rhodium-standard-repositories/satellites/consent-aware-http/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/consent-aware-http/.github/workflows/ts-blocker.yml
#	rhodium-standard-repositories/satellites/mustfile/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/palimpsest-license/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/robot-repo-automaton/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/rsr-certifier/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/rsr-certifier/.github/workflows/ts-blocker.yml
#	rhodium-standard-repositories/satellites/rsr-deployer/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/state.scm/.github/workflows/rsr-antipattern.yml
#	rhodium-standard-repositories/satellites/well-known-ecosystem/.github/workflows/rsr-antipattern.yml
hyperpolymath added a commit that referenced this pull request May 18, 2026
Closes the actionable of #103 (Wave 0 of campaign #102; policy #101).

Read-only discovery over all **379** hyperpolymath repos (top-level
`HEAD`), committed as the durable worklist
`rhodium-standard-repositories/spec/nix-retirement-inventory.adoc`:

| Class | Count |
|---|---|
| Candidate (→ 14 waves) | 277 |
| Monorepo → handle at source | 8 |
| Excluded (standards, echidna #73) | 2 |
| Out-of-scope (no flake / no Guix) | 92 |

Verdicts are **provisional** — final keep/remove is per-repo at wave
time (`flake` inputs vs `Guix ∪ sealed-container`). The
`.guix-channel`-only and flake-without-Guix traps were checked and are
**empty**; the earlier triage's "my-lang = channel-only" was inaccurate
(my-lang has no flake.nix → out-of-scope). The `Wave` column is
authoritative for slicing the wave sub-issues.

Gate rules are **not duplicated** here — the artifact links to #102 /
`LANGUAGE-POLICY.adoc`.

Refs #103
Refs #101

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit c46026e into main May 18, 2026
16 checks passed
@hyperpolymath
hyperpolymath deleted the chore/item9-rescript-to-affinescript-guidance branch May 18, 2026 05:12
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Hypatia Security Scan

Findings: 100 issues detected

Severity Count
🔴 Critical 62
🟠 High 28
🟡 Medium 10

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in security-policy.yml",
    "type": "missing_workflow",
    "file": "security-policy.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance-reusable.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/a2ml/bindings/deno/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/lol/test/vitest.config.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "TypeScript file detected -- banned language",
    "type": "banned_language_file",
    "file": "/home/runner/work/standards/standards/k9-svc/bindings/deno/mod.ts",
    "action": "flag",
    "rule_module": "cicd_rules",
    "severity": "critical"
  },
  {
    "reason": "believe_me undermines formal verification (1 occurrences, CWE-704)",
    "type": "believe_me",
    "file": "/home/runner/work/standards/standards/lol/src/abi/Locale.idr",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "critical"
  },
  {
    "reason": "Wildcard CORS -- restrict to specific origins or use env var (1 occurrences, CWE-942)",
    "type": "js_wildcard_cors",
    "file": "/home/runner/work/standards/standards/consent-aware-http/examples/reference-implementations/deno/aibdp_middleware.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "innerHTML assignment -- XSS risk, use textContent or SafeDOM (1 occurrences, CWE-79)",
    "type": "js_innerhtml",
    "file": "/home/runner/work/standards/standards/axel-protocol/src/Tea.res.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

hyperpolymath added a commit that referenced this pull request Sep 22, 2026
Owner ruling 2026-09-22: "should be no deno, it's deprecated in standards,
and rsr-template-repo, and we are all bun and bunx now."

rhodium-standard-repositories/ is plain tracked content of this repo — no
.gitmodules, no nested .git, 1121 x 100644 + 17 x 100755 index entries — so
it is in scope for that ruling, not a separate repo's problem.

Its spec/LANGUAGE-POLICY.adoc had frozen the 2026-04-10 reach order, and was
not merely permissive about Deno: it BANNED Bun outright.

  | *Bun*
  | Deno, then pnpm (as Node fallback only)
  | ... Bun is too young and moves too fast for policy-level adoption.

and its ratified reach order read "1. Deno first, always." with "`Bun` — too
young, moves too fast" in the explicitly-banned list. The ALLOWED table
carried "| *Deno* | Runtime & package management | Replaces Node/npm/Bun"
and had NO Bun row at all. That is the exact inversion the root
.claude/CLAUDE.md corrected on 2026-08-07, left standing in the seed.

It matters because RSR is a seed: scripts/check-package-policy.sh:12 names
rhodium-standard-repositories/spec/ as its canonical source, so every repo
graded against RSR inherited a spec telling it to migrate off the estate's
tier-1 runtime and onto a banned one. The repo also carried TWO
LANGUAGE-POLICY.adoc files asserting opposite orderings.

Six normative sites corrected, plus a v1.6.0 Amendments entry recording the
supersession with the ruling quoted verbatim, in the file's existing dated
house style:

  1. ALLOWED   — the *Deno* row becomes the *Bun* tier-1 row
  2. BANNED    — *Node.js* replacement Deno -> Bun
  3. BANNED    — *npm/Bun/pnpm/yarn* -> *npm/yarn*, replacement Deno -> Bun,
                 npm restated as tier 4 (permitted, never preferred)
  4. BANNED    — the *Bun* row WITHDRAWN and removed, not struck through: a
                 struck row in a policy table is ambiguous to the agents
                 that read it, which is what codacy raised on #655
  5. Pkg mgmt  — *JS deps*: deno.json imports -> package.json + bun.lock
  6. JS/Node   — reach order now Bun -> pnpm -> npm, Deno in the banned list

Verified: asciidoctor --failure-level=WARN parses clean (rc=0, no warnings),
6 table delimiters still paired, no double blank lines, and Bun now appears
in the BANNED table only as a replacement cell.

Deliberately left as history, not treated as residue: the dated "Done
2026-05-31" migration record, the project_estate_npm_to_deno_2026_05_28.md
tracker filenames, and the */bindings/{deno,ts,typescript}/ and **/.deno/**
carve-out globs — those name interop targets and compiled output, not a
runtime choice, and the matching hypatia rules still key on them.

NOT touching rhodium-standard-repositories/CLAUDE.md, and this is a
deliberate refusal rather than an oversight. That file is 877 lines with 13
ReScript mentions, 13 Deno mentions, and ZERO Bun or bunx. It still directs
agents "For frontend: Convert to ReScript" — banned 2026-04-30, destination
AffineScript. Its last commit, c46026e "retire ReScript guidance ->
AffineScript (#73)", was itself a partial sweep that left those 13 mentions
standing. A Deno-only edit would be the third partial pass on a document
stale against three separate bans, leaving it still wrong while looking
freshly reviewed; and rewriting its CADRE architecture sections to say "Bun"
would describe a design that was never built. It needs an owner authoring
decision, and is reported instead.

Also reported, not fixed: the seed .github/workflows/language-policy.yml has
13 deno hits, but 12 are path-exclusion globs (/bindings/(deno|ts)/,
affinescript-deno-test/, **/.deno/ output) and its error message already
says "Use Bun (tier 1)". It never installs or runs Deno, so the executable
surface is correct; only the stale comment at :116 ("npm banned, replacement:
Deno") is wrong.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ji1bq3TypfycfUPAR7hSxR
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant