Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions .claude/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
| **2. The 007 repo** | All Rights Reserved (ARR) | `hyperpolymath/007` specifically. Out-of-scope for any normalisation, scanning, or labelling. Surface to owner only. |
| **3. Shared with son (Joshua)** | `AGPL-3.0-or-later` | Repos with son as co-author/maintainer. Examples: `idaptik`, `paint-type`. Permanent. |
| **4. Third-party / forks** | DO NOT TOUCH | Whatever upstream chose. Never sweep, never normalise. Flag as out-of-scope if it surfaces in an audit. |
| **5. Palimpsest register** | `PMPL-1.0-or-later` | **Only repos named in the register** in `LICENCE-POLICY.adoc` Rule 2 — currently five: `palimpsest-license`, `palimpsest-plasma`, `metadatastician/consent-aware-web` (prospectively only — don't flip existing content), `insolvency-tycoon`, `sim-public-relations`. The cap of three was lifted 2026-08-26 as the Palimpsest family develops; the register is a growing **allowlist**, so PMPL in an unlisted repo is still drift. `LICENCE-POLICY.adoc` is authoritative — do not duplicate the list's contents here. |
| **5. Palimpsest register** | `PMPL-1.0-or-later` | **Only repos named in the register** in `3-practice/LICENCE-POLICY.adoc` Rule 2 — currently five: `palimpsest-license`, `palimpsest-plasma`, `metadatastician/consent-aware-web` (prospectively only — don't flip existing content), `insolvency-tycoon`, `sim-public-relations`. The cap of three was lifted 2026-08-26 as the Palimpsest family develops; the register is a growing **allowlist**, so PMPL in an unlisted repo is still drift. `3-practice/LICENCE-POLICY.adoc` is authoritative — do not duplicate the list's contents here. |

### Hard rules for agents

Expand Down Expand Up @@ -106,15 +106,15 @@ for the canonical statement.

> **Corrected 2026-08-07.** This section previously listed **Bun** as banned
> with **Deno** as its replacement, and described Deno as "replaces Node/npm/bun".
> That inverted `LANGUAGE-POLICY.adoc` §1, which has ruled Bun > Deno > pnpm > npm
> That inverted `3-practice/LANGUAGE-POLICY.adoc` §1, which has ruled Bun > Deno > pnpm > npm
> since 2026-07-29. Because this file is what agents read first, the recorded
> ruling and agent behaviour had diverged: agents were being instructed to migrate
> *away* from the estate's first-choice runtime.
>
> **RESOLVED 2026-08-25 — this file governs.** The contradiction previously
> flagged here (this table bans TypeScript in favour of AffineScript, while
> `LANGUAGE-POLICY.adoc` §1.2 stated "TypeScript is *permitted under Bun*") has
> been ruled by the owner: **AffineScript governs.** `LANGUAGE-POLICY.adoc` §1.2
> `3-practice/LANGUAGE-POLICY.adoc` §1.2 stated "TypeScript is *permitted under Bun*") has
> been ruled by the owner: **AffineScript governs.** `3-practice/LANGUAGE-POLICY.adoc` §1.2
> was the error and has been rewritten to match.
>
> The distinction that keeps both documents coherent: **Bun is the runtime, tier 1
Expand Down Expand Up @@ -225,7 +225,7 @@ Both are FOSS with independent governance (no Big Tech).
### Documentation Format

- All docs must be `.adoc` (AsciiDoc), **including `README.adoc`** — this is the estate default. GitHub renders AsciiDoc natively on the repo page, so the README, its community-health view, and the file-list tab bar all display correctly.
- GitHub-required `.md` (must be Markdown): SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, CHANGELOG.md. (README is **not** in this list — see the README rule below.)
- GitHub-required `.md` (must be Markdown): 3-practice/SECURITY.md, CONTRIBUTING.md, CODE_OF_CONDUCT.md, CHANGELOG.md. (README is **not** in this list — see the README rule below.)
- **README is `.adoc` by default, with exactly two `.md` exceptions:**
* `hyperpolymath/hyperpolymath` — the GitHub **profile** repo; profile READMEs render *only* `README.md`, never `.adoc`.
* `hyperpolymath/boj-server` — surfaced in external MCP directories (Glama), which show AsciiDoc as raw markup.
Expand Down
4 changes: 2 additions & 2 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
Expand Up @@ -21,14 +21,14 @@
# ⚠ ON EVERY LINE, not just the `*` default: in CODEOWNERS the LAST matching
# rule wins, and a specific path line REPLACES the default rather than adding to
# it. Naming a co-owner only on `*` would leave every explicitly-listed path
# below (SECURITY.md, .github/workflows/, *.sh …) single-owned and therefore
# below (3-practice/SECURITY.md, .github/workflows/, *.sh …) single-owned and therefore
# still deadlocked for any PR touching them.

# Default: both maintainers
* @hyperpolymath @JoshuaJewell

# Security-sensitive files require explicit ownership
SECURITY.md @hyperpolymath @JoshuaJewell
3-practice/SECURITY.md @hyperpolymath @JoshuaJewell
.github/workflows/ @hyperpolymath @JoshuaJewell
.machine_readable/ @hyperpolymath @JoshuaJewell
1-formats/contractiles/ @hyperpolymath @JoshuaJewell
Expand Down
12 changes: 6 additions & 6 deletions .github/workflows/doc-format.yml
Original file line number Diff line number Diff line change
Expand Up @@ -58,9 +58,9 @@ jobs:
fi

# CONTRIBUTING can have both but .md should just be a redirect
if [ -f "CONTRIBUTING.md" ] && [ -f "CONTRIBUTING.adoc" ]; then
if ! grep -q "See.*CONTRIBUTING.adoc" CONTRIBUTING.md 2>/dev/null; then
echo "::warning::CONTRIBUTING.md exists alongside CONTRIBUTING.adoc but is not a redirect"
if [ -f "CONTRIBUTING.md" ] && [ -f "3-practice/CONTRIBUTING.adoc" ]; then
if ! grep -q "See.*3-practice/CONTRIBUTING.adoc" CONTRIBUTING.md 2>/dev/null; then
echo "::warning::CONTRIBUTING.md exists alongside 3-practice/CONTRIBUTING.adoc but is not a redirect"
fi
fi

Expand All @@ -81,7 +81,7 @@ jobs:
# profile repo) need the derived .md.

# Community-health files that GitHub special-cases by exact .md name:
# SECURITY.md, CONTRIBUTING.md (can redirect), CODE_OF_CONDUCT.md, CHANGELOG.md
# 3-practice/SECURITY.md, CONTRIBUTING.md (can redirect), CODE_OF_CONDUCT.md, CHANGELOG.md

# Check other docs are .adoc
for doc in ARCHITECTURE ROADMAP PHILOSOPHY INSTALL; do
Expand All @@ -97,8 +97,8 @@ jobs:
# These files are required/preferred by GitHub in .md format
MISSING=0

if [ ! -f "SECURITY.md" ]; then
echo "::warning::SECURITY.md not found (required for GitHub security tab)"
if [ ! -f "3-practice/SECURITY.md" ]; then
echo "::warning::3-practice/SECURITY.md not found (required for GitHub security tab)"
fi

if [ ! -f "LICENSE.txt" ] && [ ! -f "LICENSE" ]; then
Expand Down
10 changes: 5 additions & 5 deletions .github/workflows/governance-reusable.yml
Original file line number Diff line number Diff line change
Expand Up @@ -563,11 +563,11 @@ jobs:
- name: Check for npm/yarn artifacts
# standards#67 — npm-avoidant: package-lock.json must never be tracked
# estate-wide. Check recursively (not just root) to catch monorepo
# sub-packages. See LANGUAGE-POLICY.adoc §1 and docs/JS-RUNTIME-POLICY.adoc.
# sub-packages. See 3-practice/LANGUAGE-POLICY.adoc §1 and docs/JS-RUNTIME-POLICY.adoc.
#
# 2026-08-07: this step previously failed any repository carrying
# bun.lockb ("Use Deno instead") and any package.json declaring runtime
# dependencies. LANGUAGE-POLICY.adoc §1 has made Bun the tier-1 runtime
# dependencies. 3-practice/LANGUAGE-POLICY.adoc §1 has made Bun the tier-1 runtime
# since 2026-07-29, and Bun's model IS an npm-compatible package.json
# plus bun.lock — so this gate made adopting the estate's first-choice
# runtime impossible, not merely awkward. It blocked what the policy
Expand Down Expand Up @@ -597,7 +597,7 @@ jobs:
FAILED=1
fi
if [ -n "$BUN_LOCK" ]; then
echo "✅ Bun lockfile present — tier 1 (LANGUAGE-POLICY.adoc §1)."
echo "✅ Bun lockfile present — tier 1 (3-practice/LANGUAGE-POLICY.adoc §1)."
fi
# Root package.json with runtime "dependencies". Bun consumes
# package.json by design, so this is only an anti-pattern when the
Expand Down Expand Up @@ -754,7 +754,7 @@ jobs:
fi
echo "✅ Security policy check passed"
- name: SSH-remote policy (token-in-URL detection)
# Estate Remote-URL policy (standards#69 / REMOTE-URL-POLICY.adoc).
# Estate Remote-URL policy (standards#69 / 3-practice/REMOTE-URL-POLICY.adoc).
# Scans every .git/config present in the checkout tree for token-in-URL
# remotes. Fails hard so a compromised credential cannot silently reach
# a PR or main-branch push.
Expand All @@ -771,7 +771,7 @@ jobs:
if [ "$found" -gt 0 ]; then
echo ""
echo "Remediation: git remote set-url <name> git@github.com:<org>/<repo>.git"
echo "Policy: REMOTE-URL-POLICY.adoc — SSH-only remotes; no PAT/token in URL ever."
echo "Policy: 3-practice/REMOTE-URL-POLICY.adoc — SSH-only remotes; no PAT/token in URL ever."
exit 1
fi
echo "✅ SSH-remote policy: no token-in-URL remotes detected"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/registry-verify.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ jobs:

# The scorecard `--verify` step below EXECUTES every pass-row's check.
# Those checks shell out to real tools; ubuntu-latest ships neither
# ripgrep nor xmllint. Without them `release-pre-flight/v1-audit.sh`
# ripgrep nor xmllint. Without them `3-practice/release-pre-flight/v1-audit.sh`
# exits 2 ("v1-audit requires ripgrep") and the k9-svc MIME check exits
# 127 — which the verifier then reported as "claimed PASS but the pass
# is not real". That was a FALSE ACCUSATION: the passes were real, the
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/scorecard-enforcer.yml
Original file line number Diff line number Diff line change
Expand Up @@ -69,10 +69,10 @@ jobs:
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1

- name: Check SECURITY.md exists
- name: Check 3-practice/SECURITY.md exists
run: |
if [ ! -f "SECURITY.md" ]; then
echo "::error::SECURITY.md is required"
if [ ! -f "3-practice/SECURITY.md" ]; then
echo "::error::3-practice/SECURITY.md is required"
exit 1
fi

Expand Down
2 changes: 1 addition & 1 deletion .hypatia-baseline.json
Original file line number Diff line number Diff line change
Expand Up @@ -701,7 +701,7 @@
"severity": "medium",
"rule_module": "structural_drift",
"type": "SD022",
"file": "testing-and-benchmarking/TESTING-TAXONOMY.adoc",
"file": "3-practice/testing-and-benchmarking/TESTING-TAXONOMY.adoc",
"note": "FALSE POSITIVE (hypatia triage 2026-07-21): All src/rust/ mentions are explicitly paths inside the external echidna repo (named on each line). Cross-repo reference, not local drift."
},
{
Expand Down
2 changes: 1 addition & 1 deletion .machine_readable/MUST.contractile
Original file line number Diff line number Diff line change
Expand Up @@ -91,7 +91,7 @@
(must "code, configuration and scripts carry SPDX-License-Identifier: MPL-2.0")
(must "prose documentation (*.adoc, *.md) carries SPDX-License-Identifier: CC-BY-SA-4.0")
(must "PMPL-1.0-or-later appears in NO standards file — it is reserved for palimpsest-license, palimpsest-plasma and consent-aware-http only")
(must "LICENCE-POLICY.adoc and .machine_readable/licensing-policy.toml state the same licence model — no contradiction")
(must "3-practice/LICENCE-POLICY.adoc and .machine_readable/licensing-policy.toml state the same licence model — no contradiction")
(must "LICENSES/ contains the canonical text for every SPDX id in use (MPL-2.0, CC-BY-SA-4.0)")
(must "no automated or bulk SPDX/licence edit — owner-only, manual, per-file (policy A2)")
(must "consent-aware-http/ and any palimpsest* path is never relicensed by a sweep (protected)")
Expand Down
16 changes: 8 additions & 8 deletions .machine_readable/REGISTRY.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -214,8 +214,8 @@ route = "the repository-compliance standard every repo is graded against"
id = "session-management-standards"
name = "Session Management Standards"
stream = "governance"
home = "session-management-standards/"
canonical_doc = "session-management-standards/README.adoc"
home = "3-practice/session-management-standards/"
canonical_doc = "3-practice/session-management-standards/README.adoc"
source_hash = "sha256:f97ff391eea3fc80a4ab0b94031cf4ad9a373f8699ca99f0f0daecfb968ac148"
route = "continuity / verify / handover protocols"

Expand All @@ -241,26 +241,26 @@ route = "the ensaid configuration standard"
id = "accessibility"
name = "Accessibility Standard"
stream = "governance"
home = "accessibility/"
canonical_doc = "accessibility/STANDARD.a2ml"
home = "3-practice/accessibility/"
canonical_doc = "3-practice/accessibility/STANDARD.a2ml"
source_hash = "sha256:73898902f539078297c9c1d952e403dc62ddcb39c1d0282442fdf4c22bea330b"
route = "estate accessibility requirements"

[[spec]]
id = "publication-pre-flight"
name = "Publication Pre-Flight"
stream = "governance"
home = "publication-pre-flight/"
canonical_doc = "publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc"
home = "3-practice/publication-pre-flight/"
canonical_doc = "3-practice/publication-pre-flight/HOL-SUITABILITY-CHECKLIST.adoc"
source_hash = "sha256:86e93a00784d646d99dcaf412efc3d647a02ff7ac2e38cc1f94c1d6bc775c188"
route = "submission gate (HOL + Zenodo checklists)"

[[spec]]
id = "release-pre-flight"
name = "Release Pre-Flight (V1 Gate)"
stream = "governance"
home = "release-pre-flight/"
canonical_doc = "release-pre-flight/V1-GATE.adoc"
home = "3-practice/release-pre-flight/"
canonical_doc = "3-practice/release-pre-flight/V1-GATE.adoc"
source_hash = "sha256:f9dc04e36e6638518ccc9d72518ef5ed9f1187da1fe1044e6d1394bfecf86000"
route = "hard v1.0.0 audit requirements"

Expand Down
6 changes: 3 additions & 3 deletions .machine_readable/contractiles/dust/Dustfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -37,10 +37,10 @@ dry-run by default and gated behind --apply.
- severity: warning

### no-duplicate-licence-policy
- description: only one licence-policy doc (LICENCE-POLICY.adoc canonical)
- run: test ! -f docs/LICENSE-POLICY.md || test ! -f LICENCE-POLICY.adoc
- description: only one licence-policy doc (3-practice/LICENCE-POLICY.adoc canonical)
- run: test ! -f docs/LICENSE-POLICY.md || test ! -f 3-practice/LICENCE-POLICY.adoc
- severity: warning
- notes: resolved 2026-06-04 — deleted the stale docs/LICENSE-POLICY.md (it wrongly asserted standards=AGPL); LICENCE-POLICY.adoc is the sole source of truth. Probe stands guard against reintroduction.
- notes: resolved 2026-06-04 — deleted the stale docs/LICENSE-POLICY.md (it wrongly asserted standards=AGPL); 3-practice/LICENCE-POLICY.adoc is the sole source of truth. Probe stands guard against reintroduction.

## Licence Hygiene

Expand Down
12 changes: 6 additions & 6 deletions .machine_readable/contractiles/must/Mustfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,8 @@ requirements — CI and pre-commit hooks fail if any check fails.
- severity: critical

### licence-policy-present
- description: LICENCE-POLICY.adoc (canonical licence policy) must exist
- run: test -f LICENCE-POLICY.adoc
- description: 3-practice/LICENCE-POLICY.adoc (canonical licence policy) must exist
- run: test -f 3-practice/LICENCE-POLICY.adoc
- severity: critical

### readme-present
Expand All @@ -30,8 +30,8 @@ requirements — CI and pre-commit hooks fail if any check fails.
- severity: critical

### security-policy
- description: SECURITY.adoc must exist
- run: test -f SECURITY.adoc
- description: 3-practice/SECURITY.adoc must exist
- run: test -f 3-practice/SECURITY.adoc
- severity: critical

### ai-manifest
Expand Down Expand Up @@ -75,8 +75,8 @@ requirements — CI and pre-commit hooks fail if any check fails.
- notes: Header-form only (head -8); LICENSES/ text and deep example mentions are not headers.

### policy-no-contradiction
- description: LICENCE-POLICY.adoc and licensing-policy.toml agree (both name CC-BY-SA-4.0)
- run: grep -q 'CC-BY-SA-4.0' LICENCE-POLICY.adoc && grep -q 'CC-BY-SA-4.0' .machine_readable/licensing-policy.toml
- description: 3-practice/LICENCE-POLICY.adoc and licensing-policy.toml agree (both name CC-BY-SA-4.0)
- run: grep -q 'CC-BY-SA-4.0' 3-practice/LICENCE-POLICY.adoc && grep -q 'CC-BY-SA-4.0' .machine_readable/licensing-policy.toml
- severity: critical

## Structure
Expand Down
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/trust/Trustfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -564,7 +564,7 @@ security:
### [VULNERABILITY_DISCLOSURE]
policy: |
Responsible disclosure welcomed. Researchers reporting real vulnerabilities
in good faith receive acknowledgement in SECURITY.adoc and in
in good faith receive acknowledgement in 3-practice/SECURITY.adoc and in
/.well-known/security-acknowledgments. See security.txt for contact path.
# TEMPLATE NOTE: replace {{SECURITY_CONTACT}} with a mailto: URI for this repo's
# security contact, e.g. "mailto:j.d.a.jewell@open.ac.uk".
Expand Down
2 changes: 1 addition & 1 deletion .machine_readable/descriptiles/META.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ author = "Jonathan D.A. Jewell (hyperpolymath)"

[architecture-decisions]
decisions = [
{ id = "ADR-001", date = "2026-05-15", title = "CODEOWNERS policy for hyperpolymath repos", status = "accepted", ref = "CODEOWNERS-POLICY.adoc", issue = "standards#55", summary = "Solo-owned repos carry no catch-all `*` or `/.github/workflows/` CODEOWNERS lines (silences Dependabot review_requested flood); path lines kept only for genuine co-owners; co-owner removal needs explicit confirmation." }
{ id = "ADR-001", date = "2026-05-15", title = "CODEOWNERS policy for hyperpolymath repos", status = "accepted", ref = "3-practice/CODEOWNERS-POLICY.adoc", issue = "standards#55", summary = "Solo-owned repos carry no catch-all `*` or `/.github/workflows/` CODEOWNERS lines (silences Dependabot review_requested flood); path lines kept only for genuine co-owners; co-owner removal needs explicit confirmation." }
]

[development-practices]
Expand Down
2 changes: 1 addition & 1 deletion .machine_readable/licensing-policy.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# SPDX-License-Identifier: MPL-2.0
# SPDX-FileCopyrightText: 2026 Jonathan Jewell (hyperpolymath)
#
# Machine-readable form of LICENCE-POLICY.adoc. Tools enforce from this;
# Machine-readable form of 3-practice/LICENCE-POLICY.adoc. Tools enforce from this;
# humans read the .adoc (the .adoc is the source of truth — keep in
# sync, do not diverge). NOT a REUSE per-file dep5 map: this encodes
# the RULES, not per-file claims.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ effects = "Downstream projects copying this standard rely on this file as the ca
[[must]]
id = "M2"
text = "Projects MUST implement keyboard navigation for all functionality (Level A)."
system = "probe in STANDARD.a2ml: test -f accessibility/keyboard.ex || find . -name \"*keyboard*\" -type f — but this is a per-consumer-project probe, not something the standards repo itself implements"
system = "probe in STANDARD.a2ml: test -f 3-practice/accessibility/keyboard.ex || find . -name \"*keyboard*\" -type f — but this is a per-consumer-project probe, not something the standards repo itself implements"
status = "fail"
effects = "Consuming projects (e.g. the example 'Burble' project referenced in docs/accessibility/README.adoc) cannot claim Level A compliance without their own implementation; the standards repo itself ships no reference implementation or fixture proving the probe works."

Expand Down
4 changes: 2 additions & 2 deletions .machine_readable/scorecards/axel-protocol.scorecard.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -32,10 +32,10 @@ effects = "Downstream systems-integration consumers relying on the advertised 'Z

[[must]]
id = "M4"
text = "The repository MUST have a filled-in, non-boilerplate vulnerability-disclosure policy (SECURITY.md)."
text = "The repository MUST have a filled-in, non-boilerplate vulnerability-disclosure policy (3-practice/SECURITY.md)."
system = "manual-only"
status = "fail"
effects = "Security researchers and downstream adopters have no real contact path or supported-version table; SECURITY.md still contains the generic GitHub template text ('Use this section to tell people...') rather than project-specific content."
effects = "Security researchers and downstream adopters have no real contact path or supported-version table; 3-practice/SECURITY.md still contains the generic GitHub template text ('Use this section to tell people...') rather than project-specific content."

[[must]]
id = "M5"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -71,7 +71,7 @@ effects = "1-formats/contractiles/must/Mustfile still contains the literal templ

[[should]]
id = "S4"
text = "Repository-level governance files that the README's 'Project Structure' section lists as present in 1-formats/a2ml/ecosystem/ (CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md, LICENSE) SHOULD actually exist at that stated path."
text = "Repository-level governance files that the README's 'Project Structure' section lists as present in 1-formats/a2ml/ecosystem/ (CONTRIBUTING.md, CODE_OF_CONDUCT.md, 3-practice/SECURITY.md, LICENSE) SHOULD actually exist at that stated path."
system = "none"
status = "fail"
effects = "A contributor following the README's tree diagram (which places CONTRIBUTING.md/CODE_OF_CONDUCT.md/SECURITY.md/LICENSE directly under 1-formats/a2ml/ecosystem/) will find none of those files there; only monorepo-root equivalents exist (/home/user/standards/CONTRIBUTING.md etc.), which may or may not apply identically to this subproject's PMPL-1.0 licence claim."
Expand Down
Loading
Loading