From cef821c8e976abc339ac3f6b7896f8932747b6d0 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Sat, 23 May 2026 03:14:06 +0100 Subject: [PATCH 1/9] feat(security): fleet-wide workflow hardening (SHA pinning + permissions) --- .github/workflows/ocaml-core.yml | 2 ++ .github/workflows/security.yml | 4 ++-- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ocaml-core.yml b/.github/workflows/ocaml-core.yml index 02d840e..a408424 100644 --- a/.github/workflows/ocaml-core.yml +++ b/.github/workflows/ocaml-core.yml @@ -19,6 +19,8 @@ on: - 'dune-project' - '*.opam' +permissions: read-all + jobs: build: name: Build and Test OCaml Core diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index d03542e..81618f4 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -26,7 +26,7 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable + uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable - name: Install cargo-audit run: cargo install cargo-audit --locked @@ -60,7 +60,7 @@ jobs: uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - name: Install Rust toolchain - uses: dtolnay/rust-toolchain@stable + uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable - name: Cache cargo registry uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 From 8be68ff200a64a58836c4e1c3c0a679255821746 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 1 Jun 2026 01:10:06 +0100 Subject: [PATCH 2/9] ci: fix CI/CD configuration (campaigns C001-C005) - C001: CodeQL language fixes - C002: License identifier standardization - C003: Outdated actions audit - C004: Pin standards refs to SHA 861b5e9 - C005: Add workflow-level permissions --- .github/workflows/codeql.yml | 2 +- .github/workflows/governance.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 9e32d15..c475caf 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,4 +1,4 @@ -# SPDX-License-Identifier: PMPL-1.0 +# SPDX-License-Identifier: MPL-2.0 name: CodeQL Security Analysis on: diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 653ef98..698d7e2 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -31,4 +31,4 @@ permissions: jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@main + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613 From 0fbe9407085170bba5ad3599b5e58993258aaf7c Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Wed, 3 Jun 2026 14:46:23 +0100 Subject: [PATCH 3/9] docs: add OpenSSF Best Practices registration badge --- README.adoc | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/README.adoc b/README.adoc index cb8f352..9b5fcf3 100644 --- a/README.adoc +++ b/README.adoc @@ -1,7 +1,10 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = WokeLang -image:https://img.shields.io/badge/License-PMPL--1.0-blue.svg[License: PMPL-1.0,link="https://github.com/hyperpolymath/palimpsest-license"] -// SPDX-License-Identifier: MPL-2.0 +image:https://img.shields.io/badge/OpenSSF-Best_Practices-green?logo=openssourcesecurity[OpenSSF Best Practices,link="https://www.bestpractices.dev/en/projects/new?repo_url=https://github.com/hyperpolymath/wokelang"] + +image:https://img.shields.io/badge/License-MPL_2.0-blue.svg[License: MPL-2.0,link="https://opensource.org/licenses/MPL-2.0"] // SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell :toc: macro @@ -207,3 +210,10 @@ asdf install # Build cargo build --release + + +== License + +This project is licensed under the Mozilla Public License, v. 2.0. See the `LICENSE` file for details. + +SPDX-License-Identifier: MPL-2.0 From b2b65d2e2c88f197552c108ff9e0ebaa64abbce8 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 4 Jun 2026 18:05:09 +0100 Subject: [PATCH 4/9] chore: flatten self-validating directory structure --- .claude/CLAUDE.md | 9 +- .github/ISSUE_TEMPLATE/bug_report.md | 4 + .github/ISSUE_TEMPLATE/documentation.md | 4 + .github/ISSUE_TEMPLATE/feature_request.md | 4 + .github/ISSUE_TEMPLATE/question.md | 4 + .github/copilot/coding-agent.yml | 6 + .github/workflows/boj-build.yml | 1 + .github/workflows/cargo-audit.yml | 2 + .github/workflows/cflite_batch.yml | 1 + .github/workflows/cflite_pr.yml | 1 + .github/workflows/codeql.yml | 1 + .github/workflows/dogfood-gate.yml | 6 + .github/workflows/e2e.yml | 2 + .github/workflows/ghcr-publish.yml | 1 + .github/workflows/governance.yml | 1 + .github/workflows/hypatia-scan.yml | 3 +- .github/workflows/instant-sync.yml | 1 + .github/workflows/mirror.yml | 1 + .github/workflows/ocaml-core.yml | 2 + .github/workflows/rust-ci.yml | 1 + .github/workflows/scorecard-enforcer.yml | 2 + .github/workflows/scorecard.yml | 1 + .github/workflows/secret-scanner.yml | 1 + .github/workflows/security.yml | 3 + .github/workflows/workflow-linter.yml | 1 + .machine_readable/6a2/0-AI-MANIFEST.a2ml | 31 ++++ .machine_readable/6a2/README.adoc | 30 ++++ .../6a2/anchor/0-AI-MANIFEST.a2ml | 21 +++ .../{anchors => 6a2/anchor}/ANCHOR.a2ml | 0 .machine_readable/6a2/anchor/README.adoc | 25 +++ .../agent_instructions/README.adoc | 4 +- .../{svc/k9 => self-validating}/README.adoc | 3 +- .../examples/ci-config.k9.ncl | 0 .../examples/project-metadata.k9.ncl | 0 .../examples/setup-repo.k9.ncl | 0 .../template-hunt.k9.ncl | 0 .../template-kennel.k9.ncl | 0 .../template-yard.k9.ncl | 0 .machine_readable/svc/README.adoc | 1 + ABI-FFI-README.md | 5 +- CHANGELOG.md | 6 +- CODE_OF_CONDUCT.md | 7 +- CONTRIBUTING.adoc | 3 +- CONTRIBUTING.md | 6 +- EXPLAINME.adoc | 10 ++ LICENSE | 165 +++++++----------- MAINTAINERS.adoc | 3 +- MAINTAINERS.md | 5 +- PHRONESIS-ALIGNMENT-GAP.md | 5 +- PROOF-NEEDS.md | 6 +- QUICKSTART-DEV.adoc | 3 +- QUICKSTART-MAINTAINER.adoc | 3 +- QUICKSTART-USER.adoc | 3 +- ROADMAP.adoc | 3 +- RSR_OUTLINE.adoc | 2 + SECURITY.md | 6 +- TEST-NEEDS.md | 6 +- TOOLCHAIN-WISHLIST.md | 5 +- TOPOLOGY.md | 6 +- benches/vm_bench.rs | 1 + compiler/wokelang-wasm/src/lib.rs | 1 + contractiles/README.adoc | 2 + docs/ABI-FFI-README.adoc | 2 + docs/CITATIONS.adoc | 2 + docs/COMPLETE-IMPLEMENTATION-GUIDE.adoc | 3 +- docs/DEPLOYMENT.adoc | 2 + docs/GAP-ANALYSIS.adoc | 2 + docs/NEXT-STEPS.adoc | 2 + docs/PALIMPSEST.adoc | 2 + docs/PROVEN.md | 6 +- docs/ROADMAP.md | 5 +- docs/WORKERS.adoc | 2 + docs/architecture/COMPILER-ROADMAP.adoc | 3 +- docs/core/INDEX.md | 5 +- docs/core/SETUP.md | 5 +- docs/proofs/README.md | 5 +- docs/proofs/compiler/memory-model.md | 5 +- docs/proofs/compiler/semantic-preservation.md | 5 +- docs/proofs/complexity/complexity-analysis.md | 5 +- docs/proofs/concurrency/worker-safety.md | 5 +- .../denotational-semantics.md | 5 +- .../proofs/formal-semantics/grammar-proofs.md | 5 +- .../formal-semantics/operational-semantics.md | 5 +- .../papers/language-design-whitepaper.md | 5 +- ...anguage-design-whitepaper.md.invariants.md | 4 + docs/proofs/security/capability-proofs.md | 5 +- docs/proofs/security/consent-model.md | 5 +- .../category-theory-foundations.md | 5 +- docs/proofs/type-theory/hindley-milner.md | 5 +- docs/proofs/type-theory/type-safety.md | 5 +- docs/reports/audit/audit-2026-04-04.md | 4 + docs/sessions/IMPLEMENTATION-COMPLETE.adoc | 2 + docs/sessions/PHASE1-SEAM-ANALYSIS.adoc | 2 + docs/sessions/SESSION-2026-01-31.adoc | 2 + docs/sessions/SESSION-COMPLETE-REPORT.adoc | 2 + docs/sessions/SESSION-SUMMARY.adoc | 2 + docs/supplementary/safety-proofs.adoc | 1 + docs/tech-debt-2026-05-26.md | 3 +- docs/wiki/Core-Concepts/Consent-System.md | 5 +- docs/wiki/Core-Concepts/Emote-Tags.md | 5 +- docs/wiki/Core-Concepts/Gratitude.md | 5 +- docs/wiki/Getting-Started/Basic-Syntax.md | 5 +- docs/wiki/Getting-Started/Hello-World.md | 5 +- docs/wiki/Getting-Started/Installation.md | 5 +- docs/wiki/Getting-Started/REPL.md | 5 +- docs/wiki/Home.md | 5 +- docs/wiki/Internals/Architecture.md | 5 +- docs/wiki/Internals/FFI.md | 5 +- docs/wiki/Internals/Lexer.md | 5 +- docs/wiki/Internals/Parser.md | 5 +- docs/wiki/Internals/WASM-Compilation.md | 5 +- docs/wiki/Language-Guide/Control-Flow.md | 5 +- docs/wiki/Language-Guide/Error-Handling.md | 5 +- docs/wiki/Language-Guide/Functions.md | 5 +- .../Language-Guide/Variables-and-Types.md | 5 +- docs/wiki/Reference/Builtin-Functions.md | 5 +- docs/wiki/Reference/CLI.md | 5 +- docs/wiki/Reference/Keywords.md | 5 +- docs/wiki/Reference/Language-Specification.md | 5 +- docs/wiki/Reference/Operators.md | 5 +- docs/wiki/Tutorials/First-CLI-App.md | 5 +- editors/vscode/README.md | 3 +- editors/vscode/lib/bs/src/Extension.res.js | 2 + editors/vscode/lib/bs/src/VSCode.res.js | 2 + editors/vscode/src/Extension.res.js | 2 + editors/vscode/src/VSCode.res.js | 2 + examples/README.md | 5 +- fuzz/fuzz_targets/fuzz_input.rs | 3 +- lib/README.md | 5 +- lib/common/README.md | 5 +- lib/wokelang/README.md | 5 +- llm-warmup-dev.md | 5 +- llm-warmup-user.md | 5 +- site/index.md | 4 + spec/README.adoc | 1 + spec/axiomatic-semantics.md | 4 + spec/system-specs.md | 4 + src/abi/Foreign.idr | 2 + src/abi/Layout.idr | 1 + src/abi/Types.idr | 1 + src/abi/WokeLang/Calculus.idr | 1 + src/abi/WokeLang/Reduction.idr | 1 + src/abi/WokeLang/Safety.idr | 1 + src/abi/WokeLang/Typing.idr | 1 + src/ast/mod.rs | 1 + src/ast/visitor.rs | 3 +- src/bin/woke-lsp.rs | 1 + src/bin/wokelang-dap.rs | 1 + src/codegen/mod.rs | 1 + src/dap/mod.rs | 1 + src/ffi/c_api.rs | 1 + src/ffi/mod.rs | 1 + src/formatter/mod.rs | 1 + src/interpreter/mod.rs | 1 + src/interpreter/value.rs | 1 + src/lexer/mod.rs | 1 + src/lexer/token.rs | 1 + src/lib.rs | 1 + src/linter/mod.rs | 1 + src/lsp/backend.rs | 1 + src/lsp/document.rs | 1 + src/lsp/handlers/completion.rs | 1 + src/lsp/handlers/definition.rs | 1 + src/lsp/handlers/diagnostics.rs | 1 + src/lsp/handlers/formatting.rs | 1 + src/lsp/handlers/hover.rs | 1 + src/lsp/handlers/mod.rs | 1 + src/lsp/mod.rs | 1 + src/lsp/stdlib_metadata.rs | 1 + src/lsp/symbols.rs | 1 + src/lsp/utils.rs | 1 + src/main.rs | 2 +- src/modules.rs | 1 + src/parser/mod.rs | 1 + src/repl.rs | 1 + src/security/consent.rs | 1 + src/security/mod.rs | 1 + src/sexpr.rs | 2 +- src/stdlib/alib.rs | 1 + src/stdlib/array.rs | 1 + src/stdlib/chan.rs | 2 +- src/stdlib/io.rs | 1 + src/stdlib/json.rs | 1 + src/stdlib/math.rs | 1 + src/stdlib/mod.rs | 2 +- src/stdlib/net.rs | 1 + src/stdlib/string.rs | 1 + src/stdlib/time.rs | 1 + src/typechecker/mod.rs | 1 + src/vm/bytecode.rs | 1 + src/vm/compiler.rs | 1 + src/vm/machine.rs | 1 + src/vm/mod.rs | 1 + src/vm/optimizer.rs | 1 + src/worker/mod.rs | 1 + tests/codegen_test.rs | 1 + tests/e2e_full_pipeline_test.rs | 1 + tests/lsp_handler_test.rs | 1 + tests/lsp_integration_test.rs | 1 + tests/property_test.rs | 1 + verification/README.adoc | 1 + 201 files changed, 623 insertions(+), 193 deletions(-) create mode 100644 .github/copilot/coding-agent.yml create mode 100644 .machine_readable/6a2/0-AI-MANIFEST.a2ml create mode 100644 .machine_readable/6a2/README.adoc create mode 100644 .machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml rename .machine_readable/{anchors => 6a2/anchor}/ANCHOR.a2ml (100%) create mode 100644 .machine_readable/6a2/anchor/README.adoc rename .machine_readable/{svc/k9 => self-validating}/README.adoc (98%) rename .machine_readable/{svc/k9 => self-validating}/examples/ci-config.k9.ncl (100%) rename .machine_readable/{svc/k9 => self-validating}/examples/project-metadata.k9.ncl (100%) rename .machine_readable/{svc/k9 => self-validating}/examples/setup-repo.k9.ncl (100%) rename .machine_readable/{svc/k9 => self-validating}/template-hunt.k9.ncl (100%) rename .machine_readable/{svc/k9 => self-validating}/template-kennel.k9.ncl (100%) rename .machine_readable/{svc/k9 => self-validating}/template-yard.k9.ncl (100%) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index eca601c..d554047 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -1,4 +1,7 @@ - + ## Machine-Readable Artefacts The following files in `.machine_readable/` contain structured project metadata: @@ -44,7 +47,7 @@ The following files in `.machine_readable/` contain structured project metadata: | Bun | Deno | | pnpm/yarn | Deno | | Go | Rust | -| Python | Julia/Rust/ReScript | +| Python | Julia/Rust/AffineScript | | Java/Kotlin | Rust/Tauri/Dioxus | | Swift | Tauri/Dioxus | | React Native | Tauri/Dioxus | @@ -62,7 +65,7 @@ Both are FOSS with independent governance (no Big Tech). ### Enforcement Rules 1. **No new TypeScript files** - Convert existing TS to AffineScript -2. **No package.json for runtime deps** - Use deno.json imports +2. **No package.json - use deno.json deps** - Use deno.json imports 3. **No node_modules in production** - Deno caches deps automatically 4. **No Go code** - Use Rust instead 5. **No Python anywhere** - Use Julia for data/batch, Rust for systems, AffineScript for apps diff --git a/.github/ISSUE_TEMPLATE/bug_report.md b/.github/ISSUE_TEMPLATE/bug_report.md index 987aab6..45a6c02 100644 --- a/.github/ISSUE_TEMPLATE/bug_report.md +++ b/.github/ISSUE_TEMPLATE/bug_report.md @@ -1,3 +1,7 @@ + --- name: Bug report about: Create a report to help us improve diff --git a/.github/ISSUE_TEMPLATE/documentation.md b/.github/ISSUE_TEMPLATE/documentation.md index 4fcb9f9..b1d16df 100644 --- a/.github/ISSUE_TEMPLATE/documentation.md +++ b/.github/ISSUE_TEMPLATE/documentation.md @@ -1,3 +1,7 @@ + --- name: Documentation about: Report unclear, missing, or incorrect documentation diff --git a/.github/ISSUE_TEMPLATE/feature_request.md b/.github/ISSUE_TEMPLATE/feature_request.md index 3e8fa7e..a5a5693 100644 --- a/.github/ISSUE_TEMPLATE/feature_request.md +++ b/.github/ISSUE_TEMPLATE/feature_request.md @@ -1,3 +1,7 @@ + --- name: Feature request about: Suggest an idea for this project diff --git a/.github/ISSUE_TEMPLATE/question.md b/.github/ISSUE_TEMPLATE/question.md index fd0e2a5..c2d1f57 100644 --- a/.github/ISSUE_TEMPLATE/question.md +++ b/.github/ISSUE_TEMPLATE/question.md @@ -1,3 +1,7 @@ + --- name: Question about: Ask a question about usage or behaviour diff --git a/.github/copilot/coding-agent.yml b/.github/copilot/coding-agent.yml new file mode 100644 index 0000000..a719a77 --- /dev/null +++ b/.github/copilot/coding-agent.yml @@ -0,0 +1,6 @@ +mcp_servers: + boj-server: + command: npx + args: ["-y", "@hyperpolymath/boj-server@latest"] + env: + BOJ_URL: http://localhost:7700 diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index dba7fc8..bda0eec 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -7,6 +7,7 @@ on: jobs: trigger-boj: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index f7bf788..ee94660 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -20,6 +20,7 @@ permissions: read-all jobs: audit: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 @@ -35,6 +36,7 @@ jobs: # Optional: Create issues for vulnerabilities create-issue: runs-on: ubuntu-latest + timeout-minutes: 15 needs: audit if: failure() permissions: diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index 733d394..e7248f2 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -10,6 +10,7 @@ permissions: read-all jobs: BatchFuzzing: runs-on: ubuntu-latest + timeout-minutes: 15 strategy: fail-fast: false matrix: diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 92a9381..9733d4c 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -9,6 +9,7 @@ permissions: read-all jobs: PR: runs-on: ubuntu-latest + timeout-minutes: 15 strategy: fail-fast: false matrix: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c475caf..e547933 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -23,6 +23,7 @@ permissions: jobs: analyze: runs-on: ubuntu-latest + timeout-minutes: 15 permissions: contents: read security-events: write diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index 7102178..e19358b 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -22,6 +22,7 @@ jobs: a2ml-validate: name: Validate A2ML manifests runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -66,6 +67,7 @@ jobs: k9-validate: name: Validate K9 contracts runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -115,6 +117,7 @@ jobs: empty-lint: name: Empty-linter (invisible characters) runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -179,6 +182,7 @@ jobs: groove-check: name: Groove manifest check runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -237,6 +241,7 @@ jobs: eclexiaiser-validate: name: Validate eclexiaiser manifest runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -300,6 +305,7 @@ print(f'Valid: {project[\"name\"]} ({len(functions)} function(s))') dogfood-summary: name: Dogfooding compliance summary runs-on: ubuntu-latest + timeout-minutes: 15 needs: [a2ml-validate, k9-validate, empty-lint, groove-check, eclexiaiser-validate] if: always() diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 055437a..5fd312b 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -24,6 +24,7 @@ jobs: structural: name: Structural E2E (no-build) runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository @@ -38,6 +39,7 @@ jobs: build-e2e: name: Build + E2E (Rust + OCaml) runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Checkout repository diff --git a/.github/workflows/ghcr-publish.yml b/.github/workflows/ghcr-publish.yml index b3653b5..694acc8 100644 --- a/.github/workflows/ghcr-publish.yml +++ b/.github/workflows/ghcr-publish.yml @@ -15,6 +15,7 @@ env: jobs: build-and-push: runs-on: ubuntu-latest + timeout-minutes: 15 permissions: contents: read packages: write diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 698d7e2..1b4e269 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -32,3 +32,4 @@ permissions: jobs: governance: uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613 + timeout-minutes: 10 diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index c68b9ed..a711616 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -25,5 +25,6 @@ permissions: jobs: hypatia: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@915139d73560e65a8240b8fc7768698658502c89 + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@6cd3772824e59c8c9affeab66061e25383544242 + timeout-minutes: 10 secrets: inherit diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 228dc43..01646a7 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -14,6 +14,7 @@ permissions: jobs: dispatch: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - name: Trigger Propagation uses: peter-evans/repository-dispatch@28959ce8df70de7be546dd1250a005dd32156697 # v3 diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 2083ca6..ee8ea02 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -12,4 +12,5 @@ permissions: jobs: mirror: uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@e6b2884722350515934d443daf23442f2195796f + timeout-minutes: 10 secrets: inherit diff --git a/.github/workflows/ocaml-core.yml b/.github/workflows/ocaml-core.yml index a408424..0294cf0 100644 --- a/.github/workflows/ocaml-core.yml +++ b/.github/workflows/ocaml-core.yml @@ -25,6 +25,7 @@ jobs: build: name: Build and Test OCaml Core runs-on: ubuntu-latest + timeout-minutes: 15 strategy: matrix: @@ -55,6 +56,7 @@ jobs: conformance: name: Conformance Tests runs-on: ubuntu-latest + timeout-minutes: 15 needs: build steps: diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 1b1b792..040a198 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -15,3 +15,4 @@ permissions: jobs: rust-ci: uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@cc5a372af1af1b202c17f1b21efd954e6c038bef + timeout-minutes: 10 diff --git a/.github/workflows/scorecard-enforcer.yml b/.github/workflows/scorecard-enforcer.yml index 6933b78..57535d0 100644 --- a/.github/workflows/scorecard-enforcer.yml +++ b/.github/workflows/scorecard-enforcer.yml @@ -23,6 +23,7 @@ permissions: jobs: scorecard: runs-on: ubuntu-latest + timeout-minutes: 15 permissions: security-events: write id-token: write # For OIDC @@ -61,6 +62,7 @@ jobs: # Check specific high-priority items check-critical: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index fc907c2..b272593 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -13,4 +13,5 @@ permissions: read-all jobs: analysis: uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@e0caf11508a3989574713c78f5f444f2ce5e33ef + timeout-minutes: 10 secrets: inherit diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 586cdc0..3817aa9 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -16,4 +16,5 @@ permissions: jobs: scan: uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@3e4bd4c93911750727e2e4c66dff859e00079da0 + timeout-minutes: 10 secrets: inherit diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 81618f4..15592dd 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -18,6 +18,7 @@ jobs: rust-security: name: Rust Security Audit runs-on: ubuntu-latest + timeout-minutes: 15 permissions: security-events: write contents: read @@ -38,6 +39,7 @@ jobs: dependency-review: name: Dependency Review runs-on: ubuntu-latest + timeout-minutes: 15 if: github.event_name == 'pull_request' permissions: contents: read @@ -53,6 +55,7 @@ jobs: build: name: Build Check runs-on: ubuntu-latest + timeout-minutes: 15 permissions: contents: read steps: diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index 3bed9c5..fef968f 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -15,6 +15,7 @@ permissions: read-all jobs: lint-workflows: runs-on: ubuntu-latest + timeout-minutes: 15 steps: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 diff --git a/.machine_readable/6a2/0-AI-MANIFEST.a2ml b/.machine_readable/6a2/0-AI-MANIFEST.a2ml new file mode 100644 index 0000000..6bf1f8c --- /dev/null +++ b/.machine_readable/6a2/0-AI-MANIFEST.a2ml @@ -0,0 +1,31 @@ +# AI Manifest for 6a2 Directory + +## Purpose + +This manifest declares the AI-assistant context for the 6a2 machine-readable metadata directory. + +## Canonical Locations + +The 6 core A2ML files MUST exist in this directory: +1. AGENTIC.a2ml +2. ECOSYSTEM.a2ml +3. META.a2ml +4. NEUROSYM.a2ml +5. PLAYBOOK.a2ml +6. STATE.a2ml + +## Invariants + +- No duplicate files in root directory +- Single source of truth: this directory is authoritative +- No stale metadata + +## Protocol + +When multiple agents may write to A2ML files concurrently: +1. Read file and record git-sha-at-read in [provenance] section +2. Lock by creating .lock- +3. Write updated file with new [provenance] metadata +4. Release by removing lock file +5. On conflict: re-read and retry if git-sha-at-read does not match HEAD + diff --git a/.machine_readable/6a2/README.adoc b/.machine_readable/6a2/README.adoc new file mode 100644 index 0000000..bc033d7 --- /dev/null +++ b/.machine_readable/6a2/README.adoc @@ -0,0 +1,30 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell +# A2ML 6a2 Directory + +This directory contains the 6 core A2ML machine-readable metadata files for this repository. + +## Files + +- `AGENTIC.a2ml` - AI agent operational gating, safety controls +- `ECOSYSTEM.a2ml` - Project ecosystem position, relationships, explicit boundaries +- `META.a2ml` - Architecture decisions (ADRs), development practices, design rationale +- `NEUROSYM.a2ml` - Symbolic semantics, composition algebra +- `PLAYBOOK.a2ml` - Executable plans, operational runbooks +- `STATE.a2ml` - Project state, phase, milestones, session history + +## Standards Compliance + +These files follow the A2ML Format Family specification from: +https://github.com/hyperpolymath/standards/tree/main/a2ml + +## Generation + +These files may be generated from .scm source files using transpilation tools. +Source .scm files should be removed after successful transpilation. + +## See Also + +- [A2ML Repository Template](https://github.com/hyperpolymath/standards/blob/main/A2ML-REPO-TEMPLATE.adoc) +- [6A2 Format Family](https://github.com/hyperpolymath/standards#a2ml-format-family-7-formats) + diff --git a/.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml b/.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml new file mode 100644 index 0000000..0dd6825 --- /dev/null +++ b/.machine_readable/6a2/anchor/0-AI-MANIFEST.a2ml @@ -0,0 +1,21 @@ +# AI Manifest for Anchor Directory + +## Purpose + +This manifest declares the AI-assistant context for the anchor machine-readable metadata directory. + +## Canonical Locations + +ANCHOR.a2ml files MUST exist in this directory. + +## Multiple Versions + +Unlike other A2ML files, multiple versions of ANCHOR.a2ml with different dates MAY exist. +Each version represents a specific recalibration point. + +## Invariants + +- Multiple versions with different dates are permitted +- No other A2ML files in this directory +- Single source of truth for anchor documents + diff --git a/.machine_readable/anchors/ANCHOR.a2ml b/.machine_readable/6a2/anchor/ANCHOR.a2ml similarity index 100% rename from .machine_readable/anchors/ANCHOR.a2ml rename to .machine_readable/6a2/anchor/ANCHOR.a2ml diff --git a/.machine_readable/6a2/anchor/README.adoc b/.machine_readable/6a2/anchor/README.adoc new file mode 100644 index 0000000..bd23e35 --- /dev/null +++ b/.machine_readable/6a2/anchor/README.adoc @@ -0,0 +1,25 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell +# A2ML Anchor Directory + +This directory contains ANCHOR.a2ml files for project recalibration and scope intervention. + +## Files + +- `ANCHOR.a2ml` - Project recalibration, scope intervention, canonical authority + +## Multiple Versions + +Unlike other A2ML files, multiple versions of ANCHOR.a2ml with different dates may exist. +Each version represents a specific recalibration point in the project history. + +## Standards Compliance + +These files follow the ANCHOR.a2ml specification from: +https://github.com/hyperpolymath/standards/tree/main/anchor-a2ml + +## See Also + +- [A2ML Repository Template](https://github.com/hyperpolymath/standards/blob/main/A2ML-REPO-TEMPLATE.adoc) +- [Anchor A2ML Spec](https://github.com/hyperpolymath/standards/tree/main/anchor-a2ml) + diff --git a/.machine_readable/agent_instructions/README.adoc b/.machine_readable/agent_instructions/README.adoc index 3e3a452..8fadd37 100644 --- a/.machine_readable/agent_instructions/README.adoc +++ b/.machine_readable/agent_instructions/README.adoc @@ -1,6 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 -// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +// Copyright (c) Jonathan D.A. Jewell + = Agent Instructions :toc: preamble diff --git a/.machine_readable/svc/k9/README.adoc b/.machine_readable/self-validating/README.adoc similarity index 98% rename from .machine_readable/svc/k9/README.adoc rename to .machine_readable/self-validating/README.adoc index d8bed38..f50be03 100644 --- a/.machine_readable/svc/k9/README.adoc +++ b/.machine_readable/self-validating/README.adoc @@ -1,5 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell + = K9 Contractiles :toc: left :icons: font diff --git a/.machine_readable/svc/k9/examples/ci-config.k9.ncl b/.machine_readable/self-validating/examples/ci-config.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/examples/ci-config.k9.ncl rename to .machine_readable/self-validating/examples/ci-config.k9.ncl diff --git a/.machine_readable/svc/k9/examples/project-metadata.k9.ncl b/.machine_readable/self-validating/examples/project-metadata.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/examples/project-metadata.k9.ncl rename to .machine_readable/self-validating/examples/project-metadata.k9.ncl diff --git a/.machine_readable/svc/k9/examples/setup-repo.k9.ncl b/.machine_readable/self-validating/examples/setup-repo.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/examples/setup-repo.k9.ncl rename to .machine_readable/self-validating/examples/setup-repo.k9.ncl diff --git a/.machine_readable/svc/k9/template-hunt.k9.ncl b/.machine_readable/self-validating/template-hunt.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/template-hunt.k9.ncl rename to .machine_readable/self-validating/template-hunt.k9.ncl diff --git a/.machine_readable/svc/k9/template-kennel.k9.ncl b/.machine_readable/self-validating/template-kennel.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/template-kennel.k9.ncl rename to .machine_readable/self-validating/template-kennel.k9.ncl diff --git a/.machine_readable/svc/k9/template-yard.k9.ncl b/.machine_readable/self-validating/template-yard.k9.ncl similarity index 100% rename from .machine_readable/svc/k9/template-yard.k9.ncl rename to .machine_readable/self-validating/template-yard.k9.ncl diff --git a/.machine_readable/svc/README.adoc b/.machine_readable/svc/README.adoc index d6c6278..ad6357e 100644 --- a/.machine_readable/svc/README.adoc +++ b/.machine_readable/svc/README.adoc @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = `.machine_readable/svc/` — Service components for wokelang :toc: diff --git a/ABI-FFI-README.md b/ABI-FFI-README.md index e569bbc..8984268 100644 --- a/ABI-FFI-README.md +++ b/ABI-FFI-README.md @@ -1,4 +1,7 @@ - + {{~ Aditionally delete this line and fill out the template below ~}} # WOKELANG ABI/FFI Documentation diff --git a/CHANGELOG.md b/CHANGELOG.md index 4285ae6..3bfce12 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,7 @@ - - + # Changelog ## [Unreleased] diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md index ea88fa8..d3dc0e7 100644 --- a/CODE_OF_CONDUCT.md +++ b/CODE_OF_CONDUCT.md @@ -1,6 +1,7 @@ - - - + # Code of Conduct diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc index 7ccc0a3..1aba6f4 100644 --- a/CONTRIBUTING.adoc +++ b/CONTRIBUTING.adoc @@ -1,5 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell + = Contributing Guide == Getting Started diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 54691ff..5de91fb 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -1,5 +1,7 @@ - - + # Contributing to WokeLang Thank you for your interest in contributing. diff --git a/EXPLAINME.adoc b/EXPLAINME.adoc index 269ad0a..306a620 100644 --- a/EXPLAINME.adoc +++ b/EXPLAINME.adoc @@ -1,6 +1,9 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell = WokeLang — Show Me The Receipts +image:https://img.shields.io/badge/License-MPL_2.0-blue.svg[License: MPL-2.0,link="https://opensource.org/licenses/MPL-2.0"] + :toc: :toclevels: 3 :icons: font @@ -262,3 +265,10 @@ production-ready integration. == Questions? Open an issue or reach out directly — happy to explain anything in more detail. + + +== License + +This project is licensed under the Mozilla Public License, v. 2.0. See the `LICENSE` file for details. + +SPDX-License-Identifier: MPL-2.0 diff --git a/LICENSE b/LICENSE index 4a7f1aa..d0a1fa1 100644 --- a/LICENSE +++ b/LICENSE @@ -1,38 +1,3 @@ -SPDX-License-Identifier: MPL-2.0 -SPDX-FileCopyrightText: 2024-2026 Jonathan D.A. Jewell (hyperpolymath) - ------------------------------------------------------------------------- -PREFERRED LICENCE: Palimpsest License (MPL-2.0) ------------------------------------------------------------------------- - -This work is governed by the Palimpsest License (MPL-2.0) as -its primary intended licence. MPL-2.0 extends the Mozilla -Public License 2.0 (MPL-2.0) with additional provisions for ethical use, -post-quantum cryptographic provenance, and emotional lineage protection. -The canonical PMPL text and stewardship information are maintained at: - https://github.com/hyperpolymath/palimpsest-license - ------------------------------------------------------------------------- -FALLBACK LICENCE: Mozilla Public License 2.0 (MPL-2.0) ------------------------------------------------------------------------- - -Because MPL-2.0 is not yet recognised by the Open Source -Initiative (OSI) or equivalent bodies, this work also carries MPL-2.0 -as its legally-recognised fallback licence. - -In any jurisdiction, platform, or context where MPL-2.0 is -not accepted as a valid licence, or where an OSI-approved licence is -required, this work is instead governed by the Mozilla Public License, -Version 2.0. - -MPL-2.0 was chosen as the fallback because MPL-2.0 is -explicitly based on and extends MPL-2.0; it is therefore the closest -recognised equivalent to the intended licence. - -The complete MPL-2.0 text follows below. - ------------------------------------------------------------------------- - Mozilla Public License Version 2.0 ================================== @@ -109,17 +74,17 @@ Mozilla Public License Version 2.0 means the form of the work preferred for making modifications. 1.14. "You" (or "Your") - means an individual or a legal entity exercising rights under - this License. For legal entities, "You" includes any entity that - controls, is controlled by, or is under common control with You. - For the purposes of this definition, "control" means (a) the power, - direct or indirect, to cause the direction or management of such - entity, whether by contract or otherwise, or (b) ownership of more - than fifty percent (50%) of the outstanding shares or beneficial + means an individual or a legal entity exercising rights under this + License. For legal entities, "You" includes any entity that + controls, is controlled by, or is under common control with You. For + purposes of this definition, "control" means (a) the power, direct + or indirect, to cause the direction or management of such entity, + whether by contract or otherwise, or (b) ownership of more than + fifty percent (50%) of the outstanding shares or beneficial ownership of such entity. 2. License Grants and Conditions ---------------------------------- +-------------------------------- 2.1. Grants @@ -144,11 +109,11 @@ distributes such Contribution. 2.3. Limitations on Grant Scope -The licenses granted in this Section 2 are the only rights granted -under this License. No additional rights or licenses will be implied -from the distribution or licensing of Covered Software under this -License. Notwithstanding Section 2.1(b) above, no patent license is -granted by a Contributor: +The licenses granted in this Section 2 are the only rights granted under +this License. No additional rights or licenses will be implied from the +distribution or licensing of Covered Software under this License. +Notwithstanding Section 2.1(b) above, no patent license is granted by a +Contributor: (a) for any code that a Contributor has removed from Covered Software; or @@ -158,19 +123,19 @@ granted by a Contributor: Contributions with other software (except as part of its Contributor Version); or -(c) under Patent Claims infringed by Covered Software in the absence - of its Contributions. +(c) under Patent Claims infringed by Covered Software in the absence of + its Contributions. -This License does not grant any rights in the trademarks, service -marks, or logos of any Contributor (except as may be necessary to -comply with the notice requirements in Section 3.4). +This License does not grant any rights in the trademarks, service marks, +or logos of any Contributor (except as may be necessary to comply with +the notice requirements in Section 3.4). 2.4. Subsequent Licenses No Contributor makes additional grants as a result of Your choice to distribute the Covered Software under a subsequent version of this -License (see Section 10.2) or under the terms of a Secondary License -(if permitted under the terms of Section 3.3). +License (see Section 10.2) or under the terms of a Secondary License (if +permitted under the terms of Section 3.3). 2.5. Representation @@ -186,11 +151,11 @@ equivalents. 2.7. Conditions -Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses -granted in Section 2.1. +Sections 3.1, 3.2, 3.3, and 3.4 are conditions of the licenses granted +in Section 2.1. 3. Responsibilities --------------------- +------------------- 3.1. Distribution of Source Form @@ -207,10 +172,10 @@ Form. If You distribute Covered Software in Executable Form then: (a) such Covered Software must also be made available in Source Code - Form, as described in Section 3.1, and You must inform recipients - of the Executable Form how they can obtain a copy of such Source - Code Form by reasonable means in a timely manner, at a charge no - more than the cost of distribution to the recipient; and + Form, as described in Section 3.1, and You must inform recipients of + the Executable Form how they can obtain a copy of such Source Code + Form by reasonable means in a timely manner, at a charge no more + than the cost of distribution to the recipient; and (b) You may distribute such Executable Form under the terms of this License, or sublicense it under different terms, provided that the @@ -222,8 +187,8 @@ If You distribute Covered Software in Executable Form then: You may create and distribute a Larger Work under terms of Your choice, provided that You also comply with the requirements of this License for the Covered Software. If the Larger Work is a combination of Covered -Software with a work governed by one or more Secondary Licenses, and -the Covered Software is not Incompatible With Secondary Licenses, this +Software with a work governed by one or more Secondary Licenses, and the +Covered Software is not Incompatible With Secondary Licenses, this License permits You to additionally distribute such Covered Software under the terms of such Secondary License(s), so that the recipient of the Larger Work may, at their option, further distribute the Covered @@ -241,28 +206,28 @@ the extent required to remedy known factual inaccuracies. 3.5. Application of Additional Terms You may choose to offer, and to charge a fee for, warranty, support, -indemnity or liability obligations to one or more recipients of -Covered Software. However, You may do so only on Your own behalf, and -not on behalf of any Contributor. You must make it absolutely clear -that any such warranty, support, indemnity, or liability obligation is -offered by You alone, and You hereby agree to indemnify every -Contributor for any liability incurred by such Contributor as a result -of warranty, support, indemnity or liability terms You offer. You may -include additional disclaimers of warranty and limitations of liability -specific to any jurisdiction. +indemnity or liability obligations to one or more recipients of Covered +Software. However, You may do so only on Your own behalf, and not on +behalf of any Contributor. You must make it absolutely clear that any +such warranty, support, indemnity, or liability obligation is offered by +You alone, and You hereby agree to indemnify every Contributor for any +liability incurred by such Contributor as a result of warranty, support, +indemnity or liability terms You offer. You may include additional +disclaimers of warranty and limitations of liability specific to any +jurisdiction. 4. Inability to Comply Due to Statute or Regulation ------------------------------------------------------ +--------------------------------------------------- If it is impossible for You to comply with any of the terms of this License with respect to some or all of the Covered Software due to statute, judicial order, or regulation then You must: (a) comply with the terms of this License to the maximum extent possible; and (b) -describe the limitations and the code they affect. Such description -must be placed in a text file included with all distributions of the -Covered Software under this License. Except to the extent prohibited -by statute or regulation, such description must be sufficiently -detailed for a recipient of ordinary skill to be able to understand it. +describe the limitations and the code they affect. Such description must +be placed in a text file included with all distributions of the Covered +Software under this License. Except to the extent prohibited by statute +or regulation, such description must be sufficiently detailed for a +recipient of ordinary skill to be able to understand it. 5. Termination -------------- @@ -271,27 +236,27 @@ detailed for a recipient of ordinary skill to be able to understand it. if You fail to comply with any of its terms. However, if You become compliant, then the rights granted under this License from a particular Contributor are reinstated (a) provisionally, unless and until such -Contributor explicitly and finally terminates Your grants, and (b) on -an ongoing basis, if such Contributor fails to notify You of the +Contributor explicitly and finally terminates Your grants, and (b) on an +ongoing basis, if such Contributor fails to notify You of the non-compliance by some reasonable means prior to 60 days after You have come back into compliance. Moreover, Your grants from a particular Contributor are reinstated on an ongoing basis if such Contributor -notifies You of the non-compliance by some reasonable means, this is -the first time You have received notice of non-compliance with this -License from such Contributor, and You become compliant prior to 30 -days after Your receipt of the notice. +notifies You of the non-compliance by some reasonable means, this is the +first time You have received notice of non-compliance with this License +from such Contributor, and You become compliant prior to 30 days after +Your receipt of the notice. -5.2. If You initiate litigation against any entity by asserting a -patent infringement claim (excluding declaratory judgment actions, +5.2. If You initiate litigation against any entity by asserting a patent +infringement claim (excluding declaratory judgment actions, counter-claims, and cross-claims) alleging that a Contributor Version directly or indirectly infringes any patent, then the rights granted to You by any and all Contributors for the Covered Software under Section 2.1 of this License shall terminate. 5.3. In the event of termination under Sections 5.1 or 5.2 above, all -end user license agreements (excluding distributors and resellers) -which have been validly granted by You or Your distributors under this -License prior to termination shall survive termination. +end user license agreements (excluding distributors and resellers) which +have been validly granted by You or Your distributors under this License +prior to termination shall survive termination. ************************************************************************ * * @@ -346,7 +311,7 @@ Nothing in this Section shall prevent a party's ability to bring cross-claims or counter-claims. 9. Miscellaneous ------------------ +---------------- This License represents the complete agreement concerning the subject matter hereof. If any provision of this License is held to be @@ -356,14 +321,14 @@ that the language of a contract shall be construed against the drafter shall not be used to construe this License against a Contributor. 10. Versions of the License ----------------------------- +--------------------------- 10.1. New Versions -Mozilla Foundation is the license steward. Except as provided in -Section 10.3, no one other than the license steward has the right to -modify or publish new versions of this License. Each version will be -given a distinguishing version number. +Mozilla Foundation is the license steward. Except as provided in Section +10.3, no one other than the license steward has the right to modify or +publish new versions of this License. Each version will be given a +distinguishing version number. 10.2. Effect of New Versions @@ -392,17 +357,17 @@ Exhibit A - Source Code Form License Notice This Source Code Form is subject to the terms of the Mozilla Public License, v. 2.0. If a copy of the MPL was not distributed with this - file, You can obtain one at http://mozilla.org/MPL/2.0/. + file, You can obtain one at https://mozilla.org/MPL/2.0/. If it is not possible or desirable to put the notice in a particular file, then You may include the notice in a location (such as a LICENSE -file in a relevant directory) where a recipient would be likely to -look for such a notice. +file in a relevant directory) where a recipient would be likely to look +for such a notice. You may add additional accurate notices of copyright ownership. Exhibit B - "Incompatible With Secondary Licenses" Notice ----------------------------------------------------------- +--------------------------------------------------------- This Source Code Form is "Incompatible With Secondary Licenses", as defined by the Mozilla Public License, v. 2.0. diff --git a/MAINTAINERS.adoc b/MAINTAINERS.adoc index 7d7d6cd..2d196ee 100644 --- a/MAINTAINERS.adoc +++ b/MAINTAINERS.adoc @@ -1,5 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell + = Maintainers :toc: preamble diff --git a/MAINTAINERS.md b/MAINTAINERS.md index 7d7d6cd..2d1cca0 100644 --- a/MAINTAINERS.md +++ b/MAINTAINERS.md @@ -1,4 +1,7 @@ - + // SPDX-License-Identifier: MPL-2.0 = Maintainers :toc: preamble diff --git a/PHRONESIS-ALIGNMENT-GAP.md b/PHRONESIS-ALIGNMENT-GAP.md index 197c5f1..4c1e19e 100644 --- a/PHRONESIS-ALIGNMENT-GAP.md +++ b/PHRONESIS-ALIGNMENT-GAP.md @@ -1,4 +1,7 @@ - + // SPDX-License-Identifier: MPL-2.0 // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell diff --git a/PROOF-NEEDS.md b/PROOF-NEEDS.md index b6a3bdd..376a3a9 100644 --- a/PROOF-NEEDS.md +++ b/PROOF-NEEDS.md @@ -1,6 +1,8 @@ + # PROOF-NEEDS.md - - ## Current State - **LOC**: ~27,300 diff --git a/QUICKSTART-DEV.adoc b/QUICKSTART-DEV.adoc index 09e8613..56cc1ae 100644 --- a/QUICKSTART-DEV.adoc +++ b/QUICKSTART-DEV.adoc @@ -1,6 +1,7 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell -// SPDX-License-Identifier: MPL-2.0 // Template: QUICKSTART-DEV.adoc — clone → build → test → PR // Replace wokelang, {{BUILD_CMD}}, {{TEST_CMD}}, {{LANG_STACK}} with actuals = wokelang — Quick Start for Developers diff --git a/QUICKSTART-MAINTAINER.adoc b/QUICKSTART-MAINTAINER.adoc index 4d07bd2..69edace 100644 --- a/QUICKSTART-MAINTAINER.adoc +++ b/QUICKSTART-MAINTAINER.adoc @@ -1,6 +1,7 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell -// SPDX-License-Identifier: MPL-2.0 // Template: QUICKSTART-MAINTAINER.adoc — packaging, deploying, and maintaining // Replace wokelang, {{PACKAGE_NAME}}, {{DEPS}} with actuals = wokelang — Quick Start for Platform Maintainers diff --git a/QUICKSTART-USER.adoc b/QUICKSTART-USER.adoc index bda60f7..6c658c3 100644 --- a/QUICKSTART-USER.adoc +++ b/QUICKSTART-USER.adoc @@ -1,6 +1,7 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell -// SPDX-License-Identifier: MPL-2.0 // Template: QUICKSTART-USER.adoc — 5-minute path to working software // Replace wokelang, Wokelang — See README.adoc for details., just run, Wokelang started successfully. with actuals = wokelang — Quick Start for Users diff --git a/ROADMAP.adoc b/ROADMAP.adoc index a993d04..11f1e29 100644 --- a/ROADMAP.adoc +++ b/ROADMAP.adoc @@ -1,5 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell + = WokeLang Roadmap == Current diff --git a/RSR_OUTLINE.adoc b/RSR_OUTLINE.adoc index 9e52314..0eda497 100644 --- a/RSR_OUTLINE.adoc +++ b/RSR_OUTLINE.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = RSR Template Repository diff --git a/SECURITY.md b/SECURITY.md index 2e81a70..88df5ba 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,5 +1,7 @@ - - + # Security Policy ## Reporting a Vulnerability diff --git a/TEST-NEEDS.md b/TEST-NEEDS.md index eb30c56..c7df557 100644 --- a/TEST-NEEDS.md +++ b/TEST-NEEDS.md @@ -1,6 +1,8 @@ + # TEST-NEEDS: wokelang - - ## CRG Grade: C — ACHIEVED 2026-04-04 ## Current State (Updated 2026-04-04) diff --git a/TOOLCHAIN-WISHLIST.md b/TOOLCHAIN-WISHLIST.md index 3e3eeb9..423c0ea 100644 --- a/TOOLCHAIN-WISHLIST.md +++ b/TOOLCHAIN-WISHLIST.md @@ -1,4 +1,7 @@ - + // SPDX-License-Identifier: MPL-2.0 // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell diff --git a/TOPOLOGY.md b/TOPOLOGY.md index 83dd483..c18f56e 100644 --- a/TOPOLOGY.md +++ b/TOPOLOGY.md @@ -1,5 +1,7 @@ - - + diff --git a/benches/vm_bench.rs b/benches/vm_bench.rs index 506f484..a4ba940 100644 --- a/benches/vm_bench.rs +++ b/benches/vm_bench.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang VM Performance Benchmarks //! //! Benchmarks comparing interpreter vs VM execution. diff --git a/compiler/wokelang-wasm/src/lib.rs b/compiler/wokelang-wasm/src/lib.rs index 982a7c1..4cf3d8a 100644 --- a/compiler/wokelang-wasm/src/lib.rs +++ b/compiler/wokelang-wasm/src/lib.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! WebAssembly backend for WokeLang. diff --git a/contractiles/README.adoc b/contractiles/README.adoc index c8dadfb..d4eaea4 100644 --- a/contractiles/README.adoc +++ b/contractiles/README.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = Contractiles Template Set :toc: diff --git a/docs/ABI-FFI-README.adoc b/docs/ABI-FFI-README.adoc index e0b2884..bcb480a 100644 --- a/docs/ABI-FFI-README.adoc +++ b/docs/ABI-FFI-README.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang ABI/FFI Architecture diff --git a/docs/CITATIONS.adoc b/docs/CITATIONS.adoc index 59671d6..bc66206 100644 --- a/docs/CITATIONS.adoc +++ b/docs/CITATIONS.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = RSR-template-repo - Citation Guide :toc: diff --git a/docs/COMPLETE-IMPLEMENTATION-GUIDE.adoc b/docs/COMPLETE-IMPLEMENTATION-GUIDE.adoc index 7fb135b..1729f0a 100644 --- a/docs/COMPLETE-IMPLEMENTATION-GUIDE.adoc +++ b/docs/COMPLETE-IMPLEMENTATION-GUIDE.adoc @@ -1,6 +1,7 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell -// SPDX-License-Identifier: MPL-2.0 # WokeLang: Complete Implementation Guide ## From EBNF to Production-Ready Language diff --git a/docs/DEPLOYMENT.adoc b/docs/DEPLOYMENT.adoc index b4186a9..dc1437b 100644 --- a/docs/DEPLOYMENT.adoc +++ b/docs/DEPLOYMENT.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Deployment Guide diff --git a/docs/GAP-ANALYSIS.adoc b/docs/GAP-ANALYSIS.adoc index fdd6397..1262364 100644 --- a/docs/GAP-ANALYSIS.adoc +++ b/docs/GAP-ANALYSIS.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Implementation Gap Analysis diff --git a/docs/NEXT-STEPS.adoc b/docs/NEXT-STEPS.adoc index c889dd9..2fa497b 100644 --- a/docs/NEXT-STEPS.adoc +++ b/docs/NEXT-STEPS.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang - What's Next diff --git a/docs/PALIMPSEST.adoc b/docs/PALIMPSEST.adoc index dcd86c4..f3b651c 100644 --- a/docs/PALIMPSEST.adoc +++ b/docs/PALIMPSEST.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell = Palimpsest License :toc: diff --git a/docs/PROVEN.md b/docs/PROVEN.md index 9047592..225b9ca 100644 --- a/docs/PROVEN.md +++ b/docs/PROVEN.md @@ -1,5 +1,7 @@ - - + # Proven Integration WokeLang uses [proven](https://github.com/hyperpolymath/proven) for formally verified operations where safety is critical. diff --git a/docs/ROADMAP.md b/docs/ROADMAP.md index 9a7a55b..9303c91 100644 --- a/docs/ROADMAP.md +++ b/docs/ROADMAP.md @@ -1,4 +1,7 @@ - + # WokeLang Roadmap > A human-centered, consent-driven programming language diff --git a/docs/WORKERS.adoc b/docs/WORKERS.adoc index ed1410f..8b9fbe4 100644 --- a/docs/WORKERS.adoc +++ b/docs/WORKERS.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # Worker Concurrency System diff --git a/docs/architecture/COMPILER-ROADMAP.adoc b/docs/architecture/COMPILER-ROADMAP.adoc index 24c1665..ac7cb9e 100644 --- a/docs/architecture/COMPILER-ROADMAP.adoc +++ b/docs/architecture/COMPILER-ROADMAP.adoc @@ -1,5 +1,6 @@ - // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell + # WokeLang Compiler Roadmap ## Current Status (2026-01-31) diff --git a/docs/core/INDEX.md b/docs/core/INDEX.md index 8e1dd11..d9d136a 100644 --- a/docs/core/INDEX.md +++ b/docs/core/INDEX.md @@ -1,4 +1,7 @@ - + # WokeLang Documentation Index This index separates **core** documentation (required for the OCaml implementation) diff --git a/docs/core/SETUP.md b/docs/core/SETUP.md index 5006594..fe9b433 100644 --- a/docs/core/SETUP.md +++ b/docs/core/SETUP.md @@ -1,4 +1,7 @@ - + # WokeLang OCaml Core Setup This document describes the minimal OCaml-only setup path for building and diff --git a/docs/proofs/README.md b/docs/proofs/README.md index 688bcf7..1cce199 100644 --- a/docs/proofs/README.md +++ b/docs/proofs/README.md @@ -1,4 +1,7 @@ - + # WokeLang Formal Proofs and Academic Documentation This directory contains formal mathematical proofs, specifications, and academic documentation for the WokeLang programming language. diff --git a/docs/proofs/compiler/memory-model.md b/docs/proofs/compiler/memory-model.md index d42e7c5..2065034 100644 --- a/docs/proofs/compiler/memory-model.md +++ b/docs/proofs/compiler/memory-model.md @@ -1,4 +1,7 @@ - + # WokeLang Memory Model and Safety This document specifies the memory model and proves memory safety properties for WokeLang. diff --git a/docs/proofs/compiler/semantic-preservation.md b/docs/proofs/compiler/semantic-preservation.md index 9cea97c..a8b988f 100644 --- a/docs/proofs/compiler/semantic-preservation.md +++ b/docs/proofs/compiler/semantic-preservation.md @@ -1,4 +1,7 @@ - + # WokeLang Compiler Correctness Proofs This document provides formal proofs of semantic preservation across WokeLang's compilation stages: Source → AST → Bytecode → WASM. diff --git a/docs/proofs/complexity/complexity-analysis.md b/docs/proofs/complexity/complexity-analysis.md index d0b76cc..aa5e2b9 100644 --- a/docs/proofs/complexity/complexity-analysis.md +++ b/docs/proofs/complexity/complexity-analysis.md @@ -1,4 +1,7 @@ - + # WokeLang Complexity Analysis This document provides rigorous complexity analysis of WokeLang's core algorithms, runtime operations, and space usage. diff --git a/docs/proofs/concurrency/worker-safety.md b/docs/proofs/concurrency/worker-safety.md index 4095471..72f6ff8 100644 --- a/docs/proofs/concurrency/worker-safety.md +++ b/docs/proofs/concurrency/worker-safety.md @@ -1,4 +1,7 @@ - + # WokeLang Concurrency and Worker System Proofs This document provides formal proofs of safety properties for WokeLang's worker-based concurrency model. diff --git a/docs/proofs/formal-semantics/denotational-semantics.md b/docs/proofs/formal-semantics/denotational-semantics.md index 40a27ab..6811419 100644 --- a/docs/proofs/formal-semantics/denotational-semantics.md +++ b/docs/proofs/formal-semantics/denotational-semantics.md @@ -1,4 +1,7 @@ - + # WokeLang Denotational Semantics This document provides the mathematical denotational semantics for WokeLang, giving precise meaning to programs as mathematical objects. diff --git a/docs/proofs/formal-semantics/grammar-proofs.md b/docs/proofs/formal-semantics/grammar-proofs.md index b0c299f..b0fb1e7 100644 --- a/docs/proofs/formal-semantics/grammar-proofs.md +++ b/docs/proofs/formal-semantics/grammar-proofs.md @@ -1,4 +1,7 @@ - + # WokeLang Grammar and Parsing Proofs This document provides formal proofs about the WokeLang grammar, including unambiguity, decidability, and parser correctness. diff --git a/docs/proofs/formal-semantics/operational-semantics.md b/docs/proofs/formal-semantics/operational-semantics.md index dd57386..00ebfed 100644 --- a/docs/proofs/formal-semantics/operational-semantics.md +++ b/docs/proofs/formal-semantics/operational-semantics.md @@ -1,4 +1,7 @@ - + # WokeLang Operational Semantics This document provides a complete formal specification of WokeLang's operational semantics using both big-step (natural) and small-step (structural operational) semantics. diff --git a/docs/proofs/papers/language-design-whitepaper.md b/docs/proofs/papers/language-design-whitepaper.md index 46f543d..a2c463f 100644 --- a/docs/proofs/papers/language-design-whitepaper.md +++ b/docs/proofs/papers/language-design-whitepaper.md @@ -1,4 +1,7 @@ - + # WokeLang: A Consent-Driven, Human-Centered Programming Language **White Paper v1.0** diff --git a/docs/proofs/papers/language-design-whitepaper.md.invariants.md b/docs/proofs/papers/language-design-whitepaper.md.invariants.md index 0a538af..faf9069 100644 --- a/docs/proofs/papers/language-design-whitepaper.md.invariants.md +++ b/docs/proofs/papers/language-design-whitepaper.md.invariants.md @@ -1,3 +1,7 @@ + // SPDX-License-Identifier: MPL-2.0 # Invariant Path Scan: language-design-whitepaper.md diff --git a/docs/proofs/security/capability-proofs.md b/docs/proofs/security/capability-proofs.md index c710670..0ccd56c 100644 --- a/docs/proofs/security/capability-proofs.md +++ b/docs/proofs/security/capability-proofs.md @@ -1,4 +1,7 @@ - + # WokeLang Capability-Based Security Proofs This document provides formal proofs of security properties for WokeLang's capability-based security system (Superpowers). diff --git a/docs/proofs/security/consent-model.md b/docs/proofs/security/consent-model.md index 8b5fa49..30e4b48 100644 --- a/docs/proofs/security/consent-model.md +++ b/docs/proofs/security/consent-model.md @@ -1,4 +1,7 @@ - + # WokeLang Consent Model: Formal Specification This document provides a complete formal specification of the consent system, including temporal logic properties, interactive semantics, and persistent storage proofs. diff --git a/docs/proofs/type-theory/category-theory-foundations.md b/docs/proofs/type-theory/category-theory-foundations.md index c47bd17..0149691 100644 --- a/docs/proofs/type-theory/category-theory-foundations.md +++ b/docs/proofs/type-theory/category-theory-foundations.md @@ -1,4 +1,7 @@ - + # Category Theory Foundations for WokeLang This document provides the category-theoretic foundations underlying WokeLang's type system and semantics. diff --git a/docs/proofs/type-theory/hindley-milner.md b/docs/proofs/type-theory/hindley-milner.md index d81fcab..cf84537 100644 --- a/docs/proofs/type-theory/hindley-milner.md +++ b/docs/proofs/type-theory/hindley-milner.md @@ -1,4 +1,7 @@ - + # WokeLang Hindley-Milner Type Inference This document formalizes the type inference algorithm used in WokeLang, based on the Hindley-Milner type system with extensions for Result types. diff --git a/docs/proofs/type-theory/type-safety.md b/docs/proofs/type-theory/type-safety.md index e7bea41..07b66e2 100644 --- a/docs/proofs/type-theory/type-safety.md +++ b/docs/proofs/type-theory/type-safety.md @@ -1,4 +1,7 @@ - + # WokeLang Type Safety Proofs This document provides formal proofs of type safety for the WokeLang type system, including the fundamental Progress and Preservation theorems. diff --git a/docs/reports/audit/audit-2026-04-04.md b/docs/reports/audit/audit-2026-04-04.md index 8adcaae..ff79708 100644 --- a/docs/reports/audit/audit-2026-04-04.md +++ b/docs/reports/audit/audit-2026-04-04.md @@ -1,3 +1,7 @@ + # Audit Report: wokelang — 2026-04-04 ## Classification: M2 Estate Audit — Wider Tranche diff --git a/docs/sessions/IMPLEMENTATION-COMPLETE.adoc b/docs/sessions/IMPLEMENTATION-COMPLETE.adoc index 357c50d..d7d49d5 100644 --- a/docs/sessions/IMPLEMENTATION-COMPLETE.adoc +++ b/docs/sessions/IMPLEMENTATION-COMPLETE.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Compiler - Implementation Complete diff --git a/docs/sessions/PHASE1-SEAM-ANALYSIS.adoc b/docs/sessions/PHASE1-SEAM-ANALYSIS.adoc index e72006f..5a3d542 100644 --- a/docs/sessions/PHASE1-SEAM-ANALYSIS.adoc +++ b/docs/sessions/PHASE1-SEAM-ANALYSIS.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # Phase 1 Seam Analysis Report **Date:** 2026-01-31 diff --git a/docs/sessions/SESSION-2026-01-31.adoc b/docs/sessions/SESSION-2026-01-31.adoc index cf83995..9279a2f 100644 --- a/docs/sessions/SESSION-2026-01-31.adoc +++ b/docs/sessions/SESSION-2026-01-31.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Development Session - 2026-01-31 diff --git a/docs/sessions/SESSION-COMPLETE-REPORT.adoc b/docs/sessions/SESSION-COMPLETE-REPORT.adoc index d853a64..6c78ee0 100644 --- a/docs/sessions/SESSION-COMPLETE-REPORT.adoc +++ b/docs/sessions/SESSION-COMPLETE-REPORT.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Implementation - Complete Session Report **Date:** 2026-01-31 diff --git a/docs/sessions/SESSION-SUMMARY.adoc b/docs/sessions/SESSION-SUMMARY.adoc index d6af176..c45ff42 100644 --- a/docs/sessions/SESSION-SUMMARY.adoc +++ b/docs/sessions/SESSION-SUMMARY.adoc @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell # WokeLang Implementation Session Summary diff --git a/docs/supplementary/safety-proofs.adoc b/docs/supplementary/safety-proofs.adoc index 01c9ff3..c222c4c 100644 --- a/docs/supplementary/safety-proofs.adoc +++ b/docs/supplementary/safety-proofs.adoc @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell = WokeLang Safety Proofs — Supplementary Material :toc: diff --git a/docs/tech-debt-2026-05-26.md b/docs/tech-debt-2026-05-26.md index 6448416..eff9fbd 100644 --- a/docs/tech-debt-2026-05-26.md +++ b/docs/tech-debt-2026-05-26.md @@ -1,8 +1,7 @@ - # Tech-Debt Audit — wokelang — 2026-05-26 **Source:** estate-wide automated scan 2026-05-26. diff --git a/docs/wiki/Core-Concepts/Consent-System.md b/docs/wiki/Core-Concepts/Consent-System.md index f2ac74b..aa8b859 100644 --- a/docs/wiki/Core-Concepts/Consent-System.md +++ b/docs/wiki/Core-Concepts/Consent-System.md @@ -1,4 +1,7 @@ - + # Consent System WokeLang's consent system ensures sensitive operations require explicit permission. diff --git a/docs/wiki/Core-Concepts/Emote-Tags.md b/docs/wiki/Core-Concepts/Emote-Tags.md index 299228e..3e1ecf6 100644 --- a/docs/wiki/Core-Concepts/Emote-Tags.md +++ b/docs/wiki/Core-Concepts/Emote-Tags.md @@ -1,4 +1,7 @@ - + # Emote Tags Emote tags provide emotional context and semantic meaning to WokeLang code. diff --git a/docs/wiki/Core-Concepts/Gratitude.md b/docs/wiki/Core-Concepts/Gratitude.md index eeeff5e..4885b8d 100644 --- a/docs/wiki/Core-Concepts/Gratitude.md +++ b/docs/wiki/Core-Concepts/Gratitude.md @@ -1,4 +1,7 @@ - + # Gratitude System WokeLang's gratitude system makes attribution and acknowledgment first-class language features. diff --git a/docs/wiki/Getting-Started/Basic-Syntax.md b/docs/wiki/Getting-Started/Basic-Syntax.md index c87121a..69b933f 100644 --- a/docs/wiki/Getting-Started/Basic-Syntax.md +++ b/docs/wiki/Getting-Started/Basic-Syntax.md @@ -1,4 +1,7 @@ - + # Basic Syntax This guide covers WokeLang's fundamental syntax elements. diff --git a/docs/wiki/Getting-Started/Hello-World.md b/docs/wiki/Getting-Started/Hello-World.md index 451ca34..b5ee880 100644 --- a/docs/wiki/Getting-Started/Hello-World.md +++ b/docs/wiki/Getting-Started/Hello-World.md @@ -1,4 +1,7 @@ - + # Hello, World! Let's write your first WokeLang program. diff --git a/docs/wiki/Getting-Started/Installation.md b/docs/wiki/Getting-Started/Installation.md index 465412f..56e5723 100644 --- a/docs/wiki/Getting-Started/Installation.md +++ b/docs/wiki/Getting-Started/Installation.md @@ -1,4 +1,7 @@ - + # Installation This guide covers how to install WokeLang on your system. diff --git a/docs/wiki/Getting-Started/REPL.md b/docs/wiki/Getting-Started/REPL.md index af69b65..62ef9cb 100644 --- a/docs/wiki/Getting-Started/REPL.md +++ b/docs/wiki/Getting-Started/REPL.md @@ -1,4 +1,7 @@ - + # REPL Guide The WokeLang REPL (Read-Eval-Print Loop) provides an interactive environment for experimenting with the language. diff --git a/docs/wiki/Home.md b/docs/wiki/Home.md index 831bfda..57a552b 100644 --- a/docs/wiki/Home.md +++ b/docs/wiki/Home.md @@ -1,4 +1,7 @@ - + # WokeLang Wiki > *A human-centered, consent-driven programming language* diff --git a/docs/wiki/Internals/Architecture.md b/docs/wiki/Internals/Architecture.md index e8b2e15..34527ca 100644 --- a/docs/wiki/Internals/Architecture.md +++ b/docs/wiki/Internals/Architecture.md @@ -1,4 +1,7 @@ - + # Architecture Overview This document describes the internal architecture of the WokeLang implementation. diff --git a/docs/wiki/Internals/FFI.md b/docs/wiki/Internals/FFI.md index ba76672..45de065 100644 --- a/docs/wiki/Internals/FFI.md +++ b/docs/wiki/Internals/FFI.md @@ -1,4 +1,7 @@ - + # FFI (Foreign Function Interface) WokeLang provides a C-compatible FFI for embedding in other languages. diff --git a/docs/wiki/Internals/Lexer.md b/docs/wiki/Internals/Lexer.md index 66c1fd5..b0ebc23 100644 --- a/docs/wiki/Internals/Lexer.md +++ b/docs/wiki/Internals/Lexer.md @@ -1,4 +1,7 @@ - + # Lexer Internals The lexer (tokenizer) converts WokeLang source code into a stream of tokens for the parser. diff --git a/docs/wiki/Internals/Parser.md b/docs/wiki/Internals/Parser.md index f307c7b..89eef75 100644 --- a/docs/wiki/Internals/Parser.md +++ b/docs/wiki/Internals/Parser.md @@ -1,4 +1,7 @@ - + # Parser Internals The parser transforms a stream of tokens into an Abstract Syntax Tree (AST). diff --git a/docs/wiki/Internals/WASM-Compilation.md b/docs/wiki/Internals/WASM-Compilation.md index bbf613a..8da1e8e 100644 --- a/docs/wiki/Internals/WASM-Compilation.md +++ b/docs/wiki/Internals/WASM-Compilation.md @@ -1,4 +1,7 @@ - + # WASM Compilation WokeLang can compile programs to WebAssembly for browser and edge runtime execution. diff --git a/docs/wiki/Language-Guide/Control-Flow.md b/docs/wiki/Language-Guide/Control-Flow.md index c28107d..6fe7587 100644 --- a/docs/wiki/Language-Guide/Control-Flow.md +++ b/docs/wiki/Language-Guide/Control-Flow.md @@ -1,4 +1,7 @@ - + # Control Flow WokeLang provides intuitive control flow constructs with clear, readable syntax. diff --git a/docs/wiki/Language-Guide/Error-Handling.md b/docs/wiki/Language-Guide/Error-Handling.md index f960507..7c684bf 100644 --- a/docs/wiki/Language-Guide/Error-Handling.md +++ b/docs/wiki/Language-Guide/Error-Handling.md @@ -1,4 +1,7 @@ - + # Error Handling WokeLang provides gentle, human-centered error handling. diff --git a/docs/wiki/Language-Guide/Functions.md b/docs/wiki/Language-Guide/Functions.md index 9b42a14..5b305d5 100644 --- a/docs/wiki/Language-Guide/Functions.md +++ b/docs/wiki/Language-Guide/Functions.md @@ -1,4 +1,7 @@ - + # Functions Functions are the primary way to organize code in WokeLang. diff --git a/docs/wiki/Language-Guide/Variables-and-Types.md b/docs/wiki/Language-Guide/Variables-and-Types.md index 944ebb8..a13f5ef 100644 --- a/docs/wiki/Language-Guide/Variables-and-Types.md +++ b/docs/wiki/Language-Guide/Variables-and-Types.md @@ -1,4 +1,7 @@ - + # Variables and Types WokeLang provides a clear, type-safe variable system. diff --git a/docs/wiki/Reference/Builtin-Functions.md b/docs/wiki/Reference/Builtin-Functions.md index 4438fbc..7e78c27 100644 --- a/docs/wiki/Reference/Builtin-Functions.md +++ b/docs/wiki/Reference/Builtin-Functions.md @@ -1,4 +1,7 @@ - + # Built-in Functions WokeLang provides these built-in functions available in all programs. diff --git a/docs/wiki/Reference/CLI.md b/docs/wiki/Reference/CLI.md index c928a20..1894894 100644 --- a/docs/wiki/Reference/CLI.md +++ b/docs/wiki/Reference/CLI.md @@ -1,4 +1,7 @@ - + # CLI Reference The `woke` command-line interface for WokeLang. diff --git a/docs/wiki/Reference/Keywords.md b/docs/wiki/Reference/Keywords.md index b99e8b6..308d286 100644 --- a/docs/wiki/Reference/Keywords.md +++ b/docs/wiki/Reference/Keywords.md @@ -1,4 +1,7 @@ - + # Keywords Reference Complete list of reserved keywords in WokeLang. diff --git a/docs/wiki/Reference/Language-Specification.md b/docs/wiki/Reference/Language-Specification.md index 87d5a18..b6d7409 100644 --- a/docs/wiki/Reference/Language-Specification.md +++ b/docs/wiki/Reference/Language-Specification.md @@ -1,4 +1,7 @@ - + # WokeLang Language Specification **Version**: 0.1.0 diff --git a/docs/wiki/Reference/Operators.md b/docs/wiki/Reference/Operators.md index 3ddfc05..fa1da2a 100644 --- a/docs/wiki/Reference/Operators.md +++ b/docs/wiki/Reference/Operators.md @@ -1,4 +1,7 @@ - + # Operators Reference Complete reference of operators in WokeLang. diff --git a/docs/wiki/Tutorials/First-CLI-App.md b/docs/wiki/Tutorials/First-CLI-App.md index ea8f1a5..1e92c86 100644 --- a/docs/wiki/Tutorials/First-CLI-App.md +++ b/docs/wiki/Tutorials/First-CLI-App.md @@ -1,4 +1,7 @@ - + # Tutorial: Building Your First CLI App Learn to build a command-line application in WokeLang. diff --git a/editors/vscode/README.md b/editors/vscode/README.md index 0833042..01e9196 100644 --- a/editors/vscode/README.md +++ b/editors/vscode/README.md @@ -1,8 +1,7 @@ - - # WokeLang for Visual Studio Code Official VS Code extension for WokeLang - a human-centered programming language with consent-driven capabilities. diff --git a/editors/vscode/lib/bs/src/Extension.res.js b/editors/vscode/lib/bs/src/Extension.res.js index f286d9c..daf66f4 100644 --- a/editors/vscode/lib/bs/src/Extension.res.js +++ b/editors/vscode/lib/bs/src/Extension.res.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // Generated by ReScript, PLEASE EDIT WITH CARE import * as Vscode from "vscode"; diff --git a/editors/vscode/lib/bs/src/VSCode.res.js b/editors/vscode/lib/bs/src/VSCode.res.js index 04f0cd7..ee9914e 100644 --- a/editors/vscode/lib/bs/src/VSCode.res.js +++ b/editors/vscode/lib/bs/src/VSCode.res.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // Generated by ReScript, PLEASE EDIT WITH CARE diff --git a/editors/vscode/src/Extension.res.js b/editors/vscode/src/Extension.res.js index f286d9c..daf66f4 100644 --- a/editors/vscode/src/Extension.res.js +++ b/editors/vscode/src/Extension.res.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // Generated by ReScript, PLEASE EDIT WITH CARE import * as Vscode from "vscode"; diff --git a/editors/vscode/src/VSCode.res.js b/editors/vscode/src/VSCode.res.js index 04f0cd7..ee9914e 100644 --- a/editors/vscode/src/VSCode.res.js +++ b/editors/vscode/src/VSCode.res.js @@ -1,3 +1,5 @@ +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // Generated by ReScript, PLEASE EDIT WITH CARE diff --git a/examples/README.md b/examples/README.md index 09c62a7..07c8a37 100644 --- a/examples/README.md +++ b/examples/README.md @@ -1,4 +1,7 @@ - + # WokeLang Example Programs This directory contains example programs demonstrating WokeLang's features. diff --git a/fuzz/fuzz_targets/fuzz_input.rs b/fuzz/fuzz_targets/fuzz_input.rs index f824c82..34dcbd9 100644 --- a/fuzz/fuzz_targets/fuzz_input.rs +++ b/fuzz/fuzz_targets/fuzz_input.rs @@ -1,4 +1,5 @@ -// SPDX-License-Identifier: PMPL-1.0 +// SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Generic fuzz target for arbitrary input processing #![no_main] diff --git a/lib/README.md b/lib/README.md index 0a6d2af..a5e9685 100644 --- a/lib/README.md +++ b/lib/README.md @@ -1,4 +1,7 @@ - + # WokeLang Standard Library A human-centered library collection for WokeLang, organized into common utilities diff --git a/lib/common/README.md b/lib/common/README.md index 9f992b7..c9faffe 100644 --- a/lib/common/README.md +++ b/lib/common/README.md @@ -1,4 +1,7 @@ - + # WokeLang Common Library This directory contains WokeLang's implementation of the **aggregate-library** common operations, plus additional utilities that are language-agnostic. diff --git a/lib/wokelang/README.md b/lib/wokelang/README.md index 5f10bd9..90b0d83 100644 --- a/lib/wokelang/README.md +++ b/lib/wokelang/README.md @@ -1,4 +1,7 @@ - + # WokeLang-Specific Library This directory contains libraries that are **unique to WokeLang** and represent the language's distinctive features. These are NOT part of the common aggregate-library. diff --git a/llm-warmup-dev.md b/llm-warmup-dev.md index 854aab0..018fe89 100644 --- a/llm-warmup-dev.md +++ b/llm-warmup-dev.md @@ -1,4 +1,7 @@ - + # LLM Warmup — wokelang (Developer) ## What is wokelang? diff --git a/llm-warmup-user.md b/llm-warmup-user.md index 5fd3e64..7d98d65 100644 --- a/llm-warmup-user.md +++ b/llm-warmup-user.md @@ -1,4 +1,7 @@ - + # LLM Warmup — wokelang (User) ## What is wokelang? diff --git a/site/index.md b/site/index.md index b817c34..37e8e75 100644 --- a/site/index.md +++ b/site/index.md @@ -1,3 +1,7 @@ + // SPDX-License-Identifier: MPL-2.0 --- title: WokeLang diff --git a/spec/README.adoc b/spec/README.adoc index c2397c9..d414df9 100644 --- a/spec/README.adoc +++ b/spec/README.adoc @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // @taxonomy: spec/index = wokelang — Specification Directory :toc: diff --git a/spec/axiomatic-semantics.md b/spec/axiomatic-semantics.md index f5977f2..eacfdc7 100644 --- a/spec/axiomatic-semantics.md +++ b/spec/axiomatic-semantics.md @@ -1,3 +1,7 @@ + # SPDX-License-Identifier: MPL-2.0 # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) diff --git a/spec/system-specs.md b/spec/system-specs.md index 9ba8cfe..238b1db 100644 --- a/spec/system-specs.md +++ b/spec/system-specs.md @@ -1,3 +1,7 @@ + # SPDX-License-Identifier: MPL-2.0 # Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) diff --git a/src/abi/Foreign.idr b/src/abi/Foreign.idr index 43968c1..bd4477f 100644 --- a/src/abi/Foreign.idr +++ b/src/abi/Foreign.idr @@ -1,3 +1,5 @@ +-- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell ||| SPDX-License-Identifier: MPL-2.0 ||| Foreign Function Interface Declarations for WOKELANG ||| diff --git a/src/abi/Layout.idr b/src/abi/Layout.idr index c7bca01..f26dc64 100644 --- a/src/abi/Layout.idr +++ b/src/abi/Layout.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Layout.idr - Memory layout verification for WokeLang ABI diff --git a/src/abi/Types.idr b/src/abi/Types.idr index b99eaed..deec037 100644 --- a/src/abi/Types.idr +++ b/src/abi/Types.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Types.idr - Type definitions with proofs for WokeLang ABI diff --git a/src/abi/WokeLang/Calculus.idr b/src/abi/WokeLang/Calculus.idr index 8821857..bd256ba 100644 --- a/src/abi/WokeLang/Calculus.idr +++ b/src/abi/WokeLang/Calculus.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Calculus.idr - λ_consent calculus: syntax, types, values, handler algebra -- diff --git a/src/abi/WokeLang/Reduction.idr b/src/abi/WokeLang/Reduction.idr index 7a8c3d3..cab245b 100644 --- a/src/abi/WokeLang/Reduction.idr +++ b/src/abi/WokeLang/Reduction.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Reduction.idr - λ_consent small-step operational semantics -- diff --git a/src/abi/WokeLang/Safety.idr b/src/abi/WokeLang/Safety.idr index 709476b..6e0f5c2 100644 --- a/src/abi/WokeLang/Safety.idr +++ b/src/abi/WokeLang/Safety.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Safety.idr - Progress, Preservation, and Consent Non-Evasion -- diff --git a/src/abi/WokeLang/Typing.idr b/src/abi/WokeLang/Typing.idr index 408c64d..cf38858 100644 --- a/src/abi/WokeLang/Typing.idr +++ b/src/abi/WokeLang/Typing.idr @@ -1,4 +1,5 @@ -- SPDX-License-Identifier: MPL-2.0 +-- Copyright (c) Jonathan D.A. Jewell -- SPDX-FileCopyrightText: 2025 Jonathan D.A. Jewell -- Typing.idr - λ_consent typing judgment and substitution lemma -- diff --git a/src/ast/mod.rs b/src/ast/mod.rs index 5b192dc..1d10eb5 100644 --- a/src/ast/mod.rs +++ b/src/ast/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell pub mod visitor; use std::ops::Range; diff --git a/src/ast/visitor.rs b/src/ast/visitor.rs index 87ca2f9..2e050be 100644 --- a/src/ast/visitor.rs +++ b/src/ast/visitor.rs @@ -1,6 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 -// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) - +// Copyright (c) Jonathan D.A. Jewell //! AST Visitor framework for WokeLang. use super::*; diff --git a/src/bin/woke-lsp.rs b/src/bin/woke-lsp.rs index 5731617..5101b01 100644 --- a/src/bin/woke-lsp.rs +++ b/src/bin/woke-lsp.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! WokeLang Language Server Protocol (LSP) Server //! diff --git a/src/bin/wokelang-dap.rs b/src/bin/wokelang-dap.rs index 129622f..8f048f9 100644 --- a/src/bin/wokelang-dap.rs +++ b/src/bin/wokelang-dap.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Debug Adapter Protocol (DAP) server use std::io::{BufRead, BufReader, Write}; diff --git a/src/codegen/mod.rs b/src/codegen/mod.rs index 3d7f1fe..45029a0 100644 --- a/src/codegen/mod.rs +++ b/src/codegen/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell mod wasm; pub use wasm::WasmCompiler; diff --git a/src/dap/mod.rs b/src/dap/mod.rs index e6244a6..47a2fed 100644 --- a/src/dap/mod.rs +++ b/src/dap/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Debug Adapter Protocol (DAP) implementation for WokeLang //! //! This module provides a minimal DAP adapter for WokeLang. diff --git a/src/ffi/c_api.rs b/src/ffi/c_api.rs index 98e7954..f7d406e 100644 --- a/src/ffi/c_api.rs +++ b/src/ffi/c_api.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! C-compatible API for WokeLang //! //! This module provides extern "C" functions that can be called from Zig, C, diff --git a/src/ffi/mod.rs b/src/ffi/mod.rs index 6a656ea..d91f2e7 100644 --- a/src/ffi/mod.rs +++ b/src/ffi/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Foreign Function Interface for WokeLang //! //! This module provides a C-compatible API that can be used from Zig, C, or any diff --git a/src/formatter/mod.rs b/src/formatter/mod.rs index efb4581..7c8d236 100644 --- a/src/formatter/mod.rs +++ b/src/formatter/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! WokeLang code formatter //! diff --git a/src/interpreter/mod.rs b/src/interpreter/mod.rs index 78706fb..61cf9df 100644 --- a/src/interpreter/mod.rs +++ b/src/interpreter/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Interpreter //! //! Tree-walking interpreter for executing WokeLang AST directly. diff --git a/src/interpreter/value.rs b/src/interpreter/value.rs index 67214c7..b63bce2 100644 --- a/src/interpreter/value.rs +++ b/src/interpreter/value.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell use crate::ast::{LambdaBody, Parameter}; use std::collections::HashMap; use std::fmt; diff --git a/src/lexer/mod.rs b/src/lexer/mod.rs index d4df743..f3412ef 100644 --- a/src/lexer/mod.rs +++ b/src/lexer/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell mod token; pub use token::Token; diff --git a/src/lexer/token.rs b/src/lexer/token.rs index 2eec9cd..178084b 100644 --- a/src/lexer/token.rs +++ b/src/lexer/token.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell use logos::Logos; fn parse_string(lex: &mut logos::Lexer) -> Option { diff --git a/src/lib.rs b/src/lib.rs index 6d866fc..99bedd2 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell pub mod ast; pub mod dap; pub mod formatter; diff --git a/src/linter/mod.rs b/src/linter/mod.rs index 296329e..ba5baa6 100644 --- a/src/linter/mod.rs +++ b/src/linter/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Linter //! //! Static analysis tool for WokeLang code quality and style checking. diff --git a/src/lsp/backend.rs b/src/lsp/backend.rs index 8bb1312..85c1ad8 100644 --- a/src/lsp/backend.rs +++ b/src/lsp/backend.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! LSP Backend - LanguageServer trait implementation diff --git a/src/lsp/document.rs b/src/lsp/document.rs index 98a655e..e3d702f 100644 --- a/src/lsp/document.rs +++ b/src/lsp/document.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Document state management and caching diff --git a/src/lsp/handlers/completion.rs b/src/lsp/handlers/completion.rs index 14cc82a..af7a630 100644 --- a/src/lsp/handlers/completion.rs +++ b/src/lsp/handlers/completion.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Completion handler diff --git a/src/lsp/handlers/definition.rs b/src/lsp/handlers/definition.rs index e0142d8..a2595ec 100644 --- a/src/lsp/handlers/definition.rs +++ b/src/lsp/handlers/definition.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Definition handler diff --git a/src/lsp/handlers/diagnostics.rs b/src/lsp/handlers/diagnostics.rs index 1144b0d..41f61b3 100644 --- a/src/lsp/handlers/diagnostics.rs +++ b/src/lsp/handlers/diagnostics.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Diagnostics handler diff --git a/src/lsp/handlers/formatting.rs b/src/lsp/handlers/formatting.rs index 113fd20..7d66e91 100644 --- a/src/lsp/handlers/formatting.rs +++ b/src/lsp/handlers/formatting.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Formatting handler diff --git a/src/lsp/handlers/hover.rs b/src/lsp/handlers/hover.rs index 471c71b..eb79048 100644 --- a/src/lsp/handlers/hover.rs +++ b/src/lsp/handlers/hover.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Hover handler diff --git a/src/lsp/handlers/mod.rs b/src/lsp/handlers/mod.rs index 1b8eceb..88bab3e 100644 --- a/src/lsp/handlers/mod.rs +++ b/src/lsp/handlers/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! LSP request handlers diff --git a/src/lsp/mod.rs b/src/lsp/mod.rs index 3372646..bad62de 100644 --- a/src/lsp/mod.rs +++ b/src/lsp/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Language Server Protocol (LSP) implementation for WokeLang diff --git a/src/lsp/stdlib_metadata.rs b/src/lsp/stdlib_metadata.rs index a247676..c98541a 100644 --- a/src/lsp/stdlib_metadata.rs +++ b/src/lsp/stdlib_metadata.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Standard library metadata for completion diff --git a/src/lsp/symbols.rs b/src/lsp/symbols.rs index a027e24..391d7cb 100644 --- a/src/lsp/symbols.rs +++ b/src/lsp/symbols.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! Symbol resolution and AST traversal diff --git a/src/lsp/utils.rs b/src/lsp/utils.rs index 7e76280..076f786 100644 --- a/src/lsp/utils.rs +++ b/src/lsp/utils.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! LSP utility functions diff --git a/src/main.rs b/src/main.rs index 980c6f4..6488c35 100644 --- a/src/main.rs +++ b/src/main.rs @@ -1,5 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 -// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +// Copyright (c) Jonathan D.A. Jewell // // WokeLang CLI - main entry point with S-expression and JSON AST dump support use clap::{Parser, Subcommand}; diff --git a/src/modules.rs b/src/modules.rs index 8c317e1..afaa0b4 100644 --- a/src/modules.rs +++ b/src/modules.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Module System for WokeLang //! //! Handles file resolution, module loading, and namespace management. diff --git a/src/parser/mod.rs b/src/parser/mod.rs index e0f5135..ac1a8b6 100644 --- a/src/parser/mod.rs +++ b/src/parser/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Parser //! //! Converts a stream of tokens into an Abstract Syntax Tree (AST). diff --git a/src/repl.rs b/src/repl.rs index 0cdefe5..6bea8d1 100644 --- a/src/repl.rs +++ b/src/repl.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang REPL (Read-Eval-Print Loop) //! //! Interactive shell for experimenting with WokeLang. diff --git a/src/security/consent.rs b/src/security/consent.rs index a244329..32777e7 100644 --- a/src/security/consent.rs +++ b/src/security/consent.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Persistent Consent Storage for WokeLang //! //! This module provides persistent storage for consent decisions, diff --git a/src/security/mod.rs b/src/security/mod.rs index f453ea5..a7cea13 100644 --- a/src/security/mod.rs +++ b/src/security/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Capability-based Security System for WokeLang //! //! This module implements "superpowers" - a capability-based security model diff --git a/src/sexpr.rs b/src/sexpr.rs index c080f8b..2c7fb80 100644 --- a/src/sexpr.rs +++ b/src/sexpr.rs @@ -1,5 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 -// Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +// Copyright (c) Jonathan D.A. Jewell // // sexpr.rs — S-expression and JSON AST dump for WokeLang // diff --git a/src/stdlib/alib.rs b/src/stdlib/alib.rs index 7ccbf33..6b5d37e 100644 --- a/src/stdlib/alib.rs +++ b/src/stdlib/alib.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! aggregate-library (aLib) Implementation for WokeLang //! //! This module implements the 22 core operations from aggregate-library, diff --git a/src/stdlib/array.rs b/src/stdlib/array.rs index 3fa2563..18ab5fa 100644 --- a/src/stdlib/array.rs +++ b/src/stdlib/array.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - Array Module //! //! Array manipulation functions. diff --git a/src/stdlib/chan.rs b/src/stdlib/chan.rs index 6e223d4..60243a7 100644 --- a/src/stdlib/chan.rs +++ b/src/stdlib/chan.rs @@ -1,5 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 -// Copyright (c) 2026 Jonathan D.A. Jewell +// Copyright (c) Jonathan D.A. Jewell // //! WokeLang Standard Library - Channel Module //! diff --git a/src/stdlib/io.rs b/src/stdlib/io.rs index 401f8a9..9f13a36 100644 --- a/src/stdlib/io.rs +++ b/src/stdlib/io.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - I/O Module //! //! File I/O operations that require explicit consent through capabilities. diff --git a/src/stdlib/json.rs b/src/stdlib/json.rs index bfcba4d..d1c4035 100644 --- a/src/stdlib/json.rs +++ b/src/stdlib/json.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! JSON parsing and serialization for WokeLang //! //! Provides consent-aware JSON operations. diff --git a/src/stdlib/math.rs b/src/stdlib/math.rs index 9d326e2..e21ef40 100644 --- a/src/stdlib/math.rs +++ b/src/stdlib/math.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - Math Module //! //! Mathematical functions that don't require any special capabilities. diff --git a/src/stdlib/mod.rs b/src/stdlib/mod.rs index d47edca..a8a5275 100644 --- a/src/stdlib/mod.rs +++ b/src/stdlib/mod.rs @@ -1,5 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 - +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library //! //! This module provides the standard library for WokeLang, offering diff --git a/src/stdlib/net.rs b/src/stdlib/net.rs index f0cb0d7..4c1815c 100644 --- a/src/stdlib/net.rs +++ b/src/stdlib/net.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - Network Module //! //! HTTP and network operations that require explicit consent. diff --git a/src/stdlib/string.rs b/src/stdlib/string.rs index c108b8c..cefa0eb 100644 --- a/src/stdlib/string.rs +++ b/src/stdlib/string.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - String Module //! //! String manipulation functions. diff --git a/src/stdlib/time.rs b/src/stdlib/time.rs index 03e9f2d..76e7c90 100644 --- a/src/stdlib/time.rs +++ b/src/stdlib/time.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Standard Library - Time Module //! //! Date and time handling functions. diff --git a/src/typechecker/mod.rs b/src/typechecker/mod.rs index d1ba693..d4e4d3a 100644 --- a/src/typechecker/mod.rs +++ b/src/typechecker/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Type Checker //! //! Static type analysis and inference for WokeLang programs. diff --git a/src/vm/bytecode.rs b/src/vm/bytecode.rs index 64d4a5e..1f4b237 100644 --- a/src/vm/bytecode.rs +++ b/src/vm/bytecode.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Bytecode Instruction Set //! //! A stack-based bytecode format for efficient execution. diff --git a/src/vm/compiler.rs b/src/vm/compiler.rs index 6ebd38a..484c856 100644 --- a/src/vm/compiler.rs +++ b/src/vm/compiler.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Bytecode Compiler //! //! Compiles WokeLang AST to stack-based bytecode. diff --git a/src/vm/machine.rs b/src/vm/machine.rs index 1a07f7b..02f24e5 100644 --- a/src/vm/machine.rs +++ b/src/vm/machine.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Virtual Machine //! //! Stack-based bytecode interpreter for executing compiled WokeLang programs. diff --git a/src/vm/mod.rs b/src/vm/mod.rs index 62500f6..04faebf 100644 --- a/src/vm/mod.rs +++ b/src/vm/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Virtual Machine //! //! A bytecode compiler and stack-based VM for efficient execution. diff --git a/src/vm/optimizer.rs b/src/vm/optimizer.rs index be00878..e1f5d97 100644 --- a/src/vm/optimizer.rs +++ b/src/vm/optimizer.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! WokeLang Bytecode Optimizer //! //! Optimization passes for improving bytecode performance. diff --git a/src/worker/mod.rs b/src/worker/mod.rs index 094bb38..4e971f3 100644 --- a/src/worker/mod.rs +++ b/src/worker/mod.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell //! Async Worker System for WokeLang //! //! This module provides true async workers with message passing capabilities. diff --git a/tests/codegen_test.rs b/tests/codegen_test.rs index 500460d..c19fa18 100644 --- a/tests/codegen_test.rs +++ b/tests/codegen_test.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Hyperpolymath // // Codegen Tests diff --git a/tests/e2e_full_pipeline_test.rs b/tests/e2e_full_pipeline_test.rs index c3b59ed..aec4191 100644 --- a/tests/e2e_full_pipeline_test.rs +++ b/tests/e2e_full_pipeline_test.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Hyperpolymath // // E2E Full Pipeline Tests diff --git a/tests/lsp_handler_test.rs b/tests/lsp_handler_test.rs index 4312c15..7c20339 100644 --- a/tests/lsp_handler_test.rs +++ b/tests/lsp_handler_test.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Hyperpolymath //! //! LSP Handler Tests diff --git a/tests/lsp_integration_test.rs b/tests/lsp_integration_test.rs index cddf321..2b61449 100644 --- a/tests/lsp_integration_test.rs +++ b/tests/lsp_integration_test.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell //! LSP integration tests diff --git a/tests/property_test.rs b/tests/property_test.rs index 66680eb..b63a030 100644 --- a/tests/property_test.rs +++ b/tests/property_test.rs @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // SPDX-FileCopyrightText: 2026 Hyperpolymath // // Property-Based Tests diff --git a/verification/README.adoc b/verification/README.adoc index f1f4319..846205d 100644 --- a/verification/README.adoc +++ b/verification/README.adoc @@ -1,4 +1,5 @@ // SPDX-License-Identifier: MPL-2.0 +// Copyright (c) Jonathan D.A. Jewell // @taxonomy: verification/index = wokelang — Verification Directory :toc: From 4f4c1f91120b8e71ad78e4f0ef28458fda923af5 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 4 Jun 2026 18:55:49 +0100 Subject: [PATCH 5/9] chore: rename agent_instructions to bot_directives for spec alignment --- .../{agent_instructions => bot_directives}/README.adoc | 2 +- .../{agent_instructions => bot_directives}/coverage.a2ml | 0 .../{agent_instructions => bot_directives}/debt.a2ml | 0 .../{agent_instructions => bot_directives}/methodology.a2ml | 0 4 files changed, 1 insertion(+), 1 deletion(-) rename .machine_readable/{agent_instructions => bot_directives}/README.adoc (95%) rename .machine_readable/{agent_instructions => bot_directives}/coverage.a2ml (100%) rename .machine_readable/{agent_instructions => bot_directives}/debt.a2ml (100%) rename .machine_readable/{agent_instructions => bot_directives}/methodology.a2ml (100%) diff --git a/.machine_readable/agent_instructions/README.adoc b/.machine_readable/bot_directives/README.adoc similarity index 95% rename from .machine_readable/agent_instructions/README.adoc rename to .machine_readable/bot_directives/README.adoc index 8fadd37..9fb1a92 100644 --- a/.machine_readable/agent_instructions/README.adoc +++ b/.machine_readable/bot_directives/README.adoc @@ -33,7 +33,7 @@ Methodology-aware configuration for AI agents. Read by any AI agent == Relationship to Other Files * `AGENTIC.a2ml` says WHAT agents can do (permissions, gating) -* `agent_instructions/` says HOW agents should work (methodology) +* `bot_directives/` says HOW agents should work (methodology) * `bot_directives/` says what the gitbot-fleet does (fleet-specific) * `CLAUDE.md` says how Claude specifically should work (Claude-specific) diff --git a/.machine_readable/agent_instructions/coverage.a2ml b/.machine_readable/bot_directives/coverage.a2ml similarity index 100% rename from .machine_readable/agent_instructions/coverage.a2ml rename to .machine_readable/bot_directives/coverage.a2ml diff --git a/.machine_readable/agent_instructions/debt.a2ml b/.machine_readable/bot_directives/debt.a2ml similarity index 100% rename from .machine_readable/agent_instructions/debt.a2ml rename to .machine_readable/bot_directives/debt.a2ml diff --git a/.machine_readable/agent_instructions/methodology.a2ml b/.machine_readable/bot_directives/methodology.a2ml similarity index 100% rename from .machine_readable/agent_instructions/methodology.a2ml rename to .machine_readable/bot_directives/methodology.a2ml From 3aefff8259aa91376384f089322a8556d0f8371d Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Sun, 7 Jun 2026 23:19:08 +0100 Subject: [PATCH 6/9] Apply estate standardization: governance docs, contractiles, CI/CD cleanup --- .github/CODEOWNERS | 34 ++++ .machine_readable/6a2/AGENTIC.a2ml | 51 ++++++ .machine_readable/6a2/NEUROSYM.a2ml | 23 +++ .machine_readable/6a2/PLAYBOOK.a2ml | 137 +++++++++++++++ .machine_readable/ADJUST.contractile | 126 -------------- .machine_readable/INTENT.contractile | 72 -------- .machine_readable/MUST.contractile | 91 ---------- .machine_readable/TRUST.contractile | 80 --------- .../contractiles/Adjustfile.a2ml | 72 ++++++++ .../contractiles/Intentfile.a2ml | 99 +++++++++++ .machine_readable/contractiles/Justfile | 100 +++++++++++ .machine_readable/contractiles/Mustfile.a2ml | 102 +++++++++++ .machine_readable/contractiles/Trustfile.a2ml | 88 ++++++++++ .../contractiles/bust/Bustfile.a2ml | 28 --- .machine_readable/contractiles/bust/bust.ncl | 66 ------- .../contractiles/dust/Dustfile.a2ml | 22 --- .../contractiles/trust/Trustfile.a2ml | 22 --- GOVERNANCE.adoc | 162 ++++++++++++++++++ contractiles/README.adoc | 22 --- contractiles/dust/Dustfile | 1 - contractiles/must/Mustfile | 14 -- contractiles/trust/Trustfile | 1 - flake.nix | 116 ------------- 23 files changed, 868 insertions(+), 661 deletions(-) create mode 100644 .github/CODEOWNERS create mode 100644 .machine_readable/6a2/AGENTIC.a2ml create mode 100644 .machine_readable/6a2/NEUROSYM.a2ml create mode 100644 .machine_readable/6a2/PLAYBOOK.a2ml delete mode 100644 .machine_readable/ADJUST.contractile delete mode 100644 .machine_readable/INTENT.contractile delete mode 100644 .machine_readable/MUST.contractile delete mode 100644 .machine_readable/TRUST.contractile create mode 100644 .machine_readable/contractiles/Adjustfile.a2ml create mode 100644 .machine_readable/contractiles/Intentfile.a2ml create mode 100644 .machine_readable/contractiles/Justfile create mode 100644 .machine_readable/contractiles/Mustfile.a2ml create mode 100644 .machine_readable/contractiles/Trustfile.a2ml delete mode 100644 .machine_readable/contractiles/bust/Bustfile.a2ml delete mode 100644 .machine_readable/contractiles/bust/bust.ncl delete mode 100644 .machine_readable/contractiles/dust/Dustfile.a2ml delete mode 100644 .machine_readable/contractiles/trust/Trustfile.a2ml create mode 100644 GOVERNANCE.adoc delete mode 100644 contractiles/README.adoc delete mode 100644 contractiles/dust/Dustfile delete mode 100644 contractiles/must/Mustfile delete mode 100644 contractiles/trust/Trustfile delete mode 100644 flake.nix diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS new file mode 100644 index 0000000..3a3b7f2 --- /dev/null +++ b/.github/CODEOWNERS @@ -0,0 +1,34 @@ +# SPDX-License-Identifier: MPL-2.0 +# CODEOWNERS - Define code review assignments for GitHub +# See: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners + +# Default: sole maintainer for all files +* @hyperpolymath + +# Security-sensitive files require explicit ownership +SECURITY.md @hyperpolymath +.github/workflows/ @hyperpolymath +.machine_readable/ @hyperpolymath +contractiles/ @hyperpolymath + +# License files +LICENSE @hyperpolymath +LICENSES/ @hyperpolymath + +# Configuration +.gitignore @hyperpolymath +.github/ @hyperpolymath + +# Documentation +README* @hyperpolymath +CONTRIBUTING* @hyperpolymath +CODE_OF_CONDUCT* @hyperpolymath +GOVERNANCE* @hyperpolymath +MAINTAINERS* @hyperpolymath +CHANGELOG* @hyperpolymath +ROADMAP* @hyperpolymath + +# Build and CI +Justfile @hyperpolymath +Makefile @hyperpolymath +*.sh @hyperpolymath diff --git a/.machine_readable/6a2/AGENTIC.a2ml b/.machine_readable/6a2/AGENTIC.a2ml new file mode 100644 index 0000000..b21d81b --- /dev/null +++ b/.machine_readable/6a2/AGENTIC.a2ml @@ -0,0 +1,51 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# AGENTIC.a2ml — AI agent constraints and capabilities +# Defines what AI agents can and cannot do in this repository. + +[metadata] +version = "0.1.0" +last-updated = "2026-04-11" + +[agent-permissions] +can-edit-source = true +can-edit-tests = true +can-edit-docs = true +can-edit-config = true +can-create-files = true + +[agent-constraints] +# What AI agents must NOT do: +# - Never use banned language patterns (believe_me, unsafeCoerce, etc.) +# - Never commit secrets or credentials +# - Never use banned languages (TypeScript, Python, Go, etc.) +# - Never place state files in repository root (must be in .machine_readable/) +# - Never use AGPL license (use MPL-2.0) + +[maintenance-integrity] +fail-closed = true +require-evidence-per-step = true +allow-silent-skip = false +require-rerun-after-fix = true +release-claim-requires-hard-pass = true + +# ============================================================================ +# METHODOLOGY (ADR-002) +# ============================================================================ +# Detailed methodology configuration lives in: +# .machine_readable/bot_directives/methodology.a2ml +# .machine_readable/bot_directives/coverage.a2ml +# .machine_readable/bot_directives/debt.a2ml +# +# AGENTIC.a2ml declares WHAT agents can do (permissions, gating). +# bot_directives/ declares HOW agents should work (methodology). + +[methodology] +instructions-dir = ".machine_readable/bot_directives/" +default-mode = "hybrid" + +[automation-hooks] +# on-enter: Read 0-AI-MANIFEST.a2ml, then STATE.a2ml, then bot_directives/ +# on-exit: Update STATE.a2ml, coverage.a2ml, and debt.a2ml with session outcomes +# on-commit: Run just validate-rsr diff --git a/.machine_readable/6a2/NEUROSYM.a2ml b/.machine_readable/6a2/NEUROSYM.a2ml new file mode 100644 index 0000000..1acf7a3 --- /dev/null +++ b/.machine_readable/6a2/NEUROSYM.a2ml @@ -0,0 +1,23 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# NEUROSYM.a2ml — Neurosymbolic integration metadata +# Configuration for Hypatia scanning and symbolic reasoning. + +[metadata] +version = "0.1.0" +last-updated = "2026-04-11" + +[hypatia-config] +scan-enabled = true +scan-depth = "standard" # quick | standard | deep +report-format = "logtalk" + +[symbolic-rules] +# Custom symbolic rules for this project +# - { name = "no-unsafe-ffi", pattern = "believe_me|unsafeCoerce", severity = "critical" } + +[neural-config] +# Neural pattern detection settings +# confidence-threshold = 0.85 +# model = "hypatia-v2" diff --git a/.machine_readable/6a2/PLAYBOOK.a2ml b/.machine_readable/6a2/PLAYBOOK.a2ml new file mode 100644 index 0000000..676ec4c --- /dev/null +++ b/.machine_readable/6a2/PLAYBOOK.a2ml @@ -0,0 +1,137 @@ +# SPDX-License-Identifier: MPL-2.0 +# Copyright (c) 2026 Jonathan D.A. Jewell (hyperpolymath) +# +# PLAYBOOK.a2ml — Operational playbook +# Runbooks, incident response, deployment procedures. + +[metadata] +version = "0.1.0" +last-updated = "2026-04-11" + +[deployment] +# method = "gitops" # gitops | manual | ci-triggered +# target = "container" # container | binary | library | wasm + +[incident-response] +# 1. Check .machine_readable/STATE.a2ml for current status +# 2. Review recent commits and CI results +# 3. Run `just validate` to check compliance +# 4. Run `just security` to audit for vulnerabilities + +[release-process] +# 1. Update version in STATE.a2ml, META.a2ml, Justfile +# 2. Run `just release-preflight` (validate + quality + security + maint-hard-pass) +# 3. Optional local permission hardening: `just perms-snapshot && just perms-lock` +# 4. Tag and push +# 5. Restore local permissions if needed: `just perms-restore` +# 6. Run `just container-push` if applicable + +[maintenance-operations] +# Baseline audit: +# just maint-audit +# Hard release gate: +# just maint-hard-pass +# Permission audit: +# just perms-audit + +[rsr-repo-skeleton] +# Canonical organisation of any RSR-derived repository. +# Used by tooling, human onboarding, and the scheduled downstream sweep agent. +# The 5-PR cleanup pattern (below) brings a non-conforming repository into +# compliance with this skeleton. +# +# This section is the single source of truth for "what does an RSR repo look +# like?". Other docs (TOPOLOGY, AUDIT, etc.) describe the repo at hand; +# this describes the canonical shape that all RSR repos share. + +skeleton-version = "1.0" +last-updated = "2026-04-30" +authority-allowlist = ".machine_readable/root-allow.txt" +enforcement-workflow = ".github/workflows/estate-rules.yml" + +# === Required at root === +# README.adoc High-level pitch (project entry point) +# AUDIT.adoc Local gate summary (release-readiness) +# EXPLAINME.adoc Developer deep-dive (architecture & invariants) +# 0-AI-MANIFEST.a2ml AI agent work-allocation policy +# LICENSE Repo license (root-bound by convention) +# CHANGELOG.md One of the recognised .md exceptions (see below) +# Justfile Task runner — thin, imports per-section files from build/just/ +# coordination.k9 Repo-local session binding + +# === Required directories === +# .github/ CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md, workflows/ +# .machine_readable/ AI manifests (0.1-AI-MANIFEST.a2ml), 6a2/ checkpoints, +# contractiles/, configs/, anchors/, policies/, scripts/, svc/ +# build/ contractile.just, flake.nix, guix.scm, Containerfile, +# just/*.just (Justfile section imports) +# docs/ onboarding/, status/, architecture/, governance/ (all .adoc) +# session/ dispatch.sh, custom-checks.k9, local-hooks.sh +# src/ Project source (Idris2 ABI under abi/, Zig FFI under ffi/) +# tests/, benches/, examples/, features/, scripts/, verification/, container/ + +# === Documentation format rule === +# `.adoc` is the default for all general docs (TOPOLOGY, READINESS, ROADMAP, +# TEST-NEEDS, PROOF-NEEDS, PROOF-STATUS, llm-warmup-*, etc.). +# +# `.md` is reserved ONLY for files GitHub's community-health rules +# special-case by name: +# CONTRIBUTING.md CODE_OF_CONDUCT.md SECURITY.md CHANGELOG.md +# +# Enforcement: `scripts/check-no-md-in-docs.sh` (fails if any *.md under docs/). + +# === Banned: ziguage === +# V (vlang.io) is banned estate-wide. Replaced by `zig-unified-api-adapter` +# (16 endpoints + transaction-based firewall gating). Do not introduce +# zig code, scaffolders, or references. Note that Coq theorem files use +# the same `.v` extension and are unaffected — the rule looks at content +# patterns, not the extension. +# +# Enforcement: `scripts/check-no-vlang.sh`. + +# === Justfile structure (post-split) === +# The root Justfile is thin — it holds `set` directives, project metadata +# variables, and the `default`/`help`/`info` recipes. Each major section +# lives in its own file under build/just/ and is brought in via `import?`. +# +# Imported sections (in the canonical split): +# build/just/init.just INIT recipe (template bootstrap) +# build/just/assess.just self-assess + verify (OpenSSF compliance) +# build/just/validate.just validate-rsr/state/ai-install + aggregate +# build/just/proofs.just proof-check-{all,idris2,lean4,agda,coq}, +# proof-scan-dangerous, proof-status +# build/just/groove.just Groove protocol setup (after zig removed) +# +# Daily-use recipes (BUILD, TEST, LINT, RUN, DEPS, DOCS, CONTAINER, CI, +# SECURITY, STATE, GUIX/NIX, MATRIX, VERSION CONTROL, UTILITIES, SESSION) +# stay in the root Justfile where users expect to find them. + +# === 5-PR cleanup pattern === +# Apply these branches (in order) to bring a non-conforming downstream repo +# into compliance with this skeleton: +# +# 1. chore/root-cleanup Relocate root sprawl per root-allow.txt; add +# scripts/check-root-shape.sh; remove stub +# health files shadowed by .github/ versions. +# 2. chore/remove-zig Purge zig remnants (gen-v-connector recipe, +# "V-TRIPLE" section header, "V-triple +# connectors" comment in groove.a2ml). +# 3. chore/md-to-adoc Port general docs in docs/ from .md to .adoc; +# update validate-template.sh to accept .adoc +# fallbacks. +# 4. chore/estate-rules-ci Add scripts/check-no-md-in-docs.sh + check-no- +# vlang.sh + .github/workflows/estate-rules.yml. +# 5. chore/-hygiene Repo-specific drift cleanup (case collisions, +# template-derivation drift in titles, etc.). + +# === Reference scripts === +# scripts/check-root-shape.sh Root allowlist validator +# scripts/check-no-md-in-docs.sh AsciiDoc-by-default validator +# scripts/check-no-vlang.sh zig ban validator +# scripts/validate-template.sh Aggregate RSR compliance (workflows, SPDX, etc.) + +# === Reference memory entries (for AI agents) === +# feedback_adoc_default_md_for_githealth AsciiDoc-by-default rule +# feedback_v_lang_banned zig ban +# project_zig_unified_api Replacement for v-triple/zig +# feedback_gh_workflow_scope OAuth scope for workflow files diff --git a/.machine_readable/ADJUST.contractile b/.machine_readable/ADJUST.contractile deleted file mode 100644 index 2eedfd4..0000000 --- a/.machine_readable/ADJUST.contractile +++ /dev/null @@ -1,126 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; ADJUST.contractile — Accessibility invariants for wokelang -; "ADJUST" = Accessibility & Digital Justice for Universal Software & Technology -; -; Part of the contractile family: MUST, TRUST, DUST, INTENT, ADJUST -; This file is machine-readable. LLM/SLM agents MUST NOT violate these invariants. - -; ── Definitions ────────────────────────────────────────────────── -; -; ADJUST (noun/verb) -; The accessibility contractile. Defines how software must adapt to serve -; all users regardless of ability, device, or context. Named for the verb -; "adjust" — to make suitable, to adapt, to accommodate — which is the -; core action of accessible design. -; -; Scope: -; ADJUST governs all user-facing interfaces: GUI, TUI, CLI, web, mobile, -; documentation, error messages, and installation flows. It applies to -; both human users and assistive technologies (screen readers, switch -; devices, braille displays, voice control). -; -; Relationship to other contractiles: -; - MUST: ADJUST invariants are a subset of MUST — violating ADJUST -; is a MUST violation. ADJUST exists separately because accessibility -; rules are numerous enough to warrant their own file, and because -; LLMs frequently forget accessibility unless explicitly reminded. -; - TRUST: ADJUST does not affect trust levels. All trust tiers must -; respect ADJUST invariants equally. -; - DUST: Deprecating a feature does not exempt it from ADJUST until -; it is fully removed. Deprecated UI must remain accessible. -; - INTENT: ADJUST supports the anti-purpose "this software is NOT -; only for able-bodied users with modern hardware." -; -; Standard: WCAG 2.2 Level AA (minimum) -; https://www.w3.org/WAI/WCAG22/quickref/?levels=aaa -; -; Why a separate file: -; Experience shows LLMs and developers alike treat accessibility as an -; afterthought. By placing invariants in a contractile that is loaded -; at session start, we make it structurally impossible to forget. -; -; ── End Definitions ────────────────────────────────────────────── - -(adjust-contractile - (version "1.0.0") - (full-name "Accessibility & Digital Justice for Universal Software & Technology") - (standard "WCAG-2.2-AA") - (repo "wokelang") - - (invariants - ; ── Visual ── - (adjust "colour-contrast-ratio >= 4.5:1 for normal text") - (adjust "colour-contrast-ratio >= 3:1 for large text (18pt+ or 14pt+ bold)") - (adjust "no information conveyed by colour alone") - (adjust "no flashing or strobing content (3 flashes/second max)") - (adjust "text resizable to 200% without loss of content or function") - (adjust "focus indicators visible on all interactive elements") - - ; ── Keyboard ── - (adjust "all interactive elements reachable via keyboard (Tab/Shift+Tab)") - (adjust "no keyboard traps — user can always Tab away") - (adjust "skip navigation link present on pages with repeated blocks") - (adjust "logical focus order follows visual reading order") - - ; ── Screen reader ── - (adjust "all images have meaningful alt text (or alt='' if decorative)") - (adjust "all form inputs have associated labels") - (adjust "ARIA landmarks used for page regions (main, nav, banner, etc.)") - (adjust "dynamic content updates announced via aria-live regions") - (adjust "semantic HTML used (headings, lists, tables) — not div soup") - - ; ── Interactive ── - (adjust "touch targets minimum 44x44px on mobile/touch interfaces") - (adjust "error messages identify the field and describe the error") - (adjust "error messages not conveyed by colour or position alone") - (adjust "form validation provides suggestions for correction") - - ; ── Media ── - (adjust "video has captions (closed or open)") - (adjust "audio-only content has text transcript") - (adjust "no autoplay of media with sound") - - ; ── Motion ── - (adjust "animations respect prefers-reduced-motion media query") - (adjust "no content depends on motion to convey meaning") - - ; ── CLI/TUI ── - (adjust "CLI output must not rely solely on colour (use symbols: [OK] [FAIL])") - (adjust "TUI must support high-contrast mode") - (adjust "all CLI commands support --help with plain-text output") - (adjust "error messages written in plain language, not jargon or codes alone") - - ; ── Documentation ── - (adjust "docs use clear language, short sentences, logical structure") - (adjust "code examples include comments explaining non-obvious steps") - (adjust "diagrams have text descriptions or alt text") - - ; ── Internationalisation (i18n) ── - (adjust "all user-facing strings externalisable for translation") - (adjust "no hardcoded English in error messages — use message keys") - (adjust "date/time/number formats locale-aware") - (adjust "RTL (right-to-left) layout support where applicable") - (adjust "Unicode handled correctly throughout (UTF-8 everywhere)") - ) - - (related-resources - ; LOL — super-parallel corpus crawler for 1500+ languages - ; Use for linguistic data, translation coverage, and i18n validation - (lol "standards/lol — multilingual NLP corpus, see README.adoc") - (polyglot-i18n "polyglot-i18n — i18n framework and WASM translation engine") - ) - - (enforcement - (ci "accessibility linting in quality.yml workflow") - (pr-block "PR blocked if accessibility regression detected") - (tool "axe-core or pa11y for automated checks on web UI") - (tool "CLI output inspected for colour-only signalling") - (manual "manual screen reader test before major releases") - ) - - (notes - "These are MINIMUM requirements. Exceeding them (AAA) is encouraged." - "When in doubt about an accessibility decision, ask — don't guess." - "Accessibility is not optional polish — it is a structural requirement." - ) -) diff --git a/.machine_readable/INTENT.contractile b/.machine_readable/INTENT.contractile deleted file mode 100644 index 2a58624..0000000 --- a/.machine_readable/INTENT.contractile +++ /dev/null @@ -1,72 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; INTENT.contractile — Purpose and scope for wokelang -; Helps LLM/SLM agents understand what this repo IS and IS NOT. -; -; Part of the contractile family: MUST, TRUST, DUST, INTENT, ADJUST - -; ── Definitions ────────────────────────────────────────────────── -; -; INTENT (noun) -; The purpose contractile. Defines what this repository IS, what it is -; NOT (anti-purpose), and which architectural decisions are load-bearing. -; Without INTENT, LLMs drift into scope creep, reverse key decisions, -; or add features that belong in a different repo. -; -; Scope: -; INTENT governs the conceptual boundaries of the project — its reason -; for existing, its domain, and its relationship to the ecosystem. -; It does NOT specify implementation details (that's MUST and code). -; -; Relationship to other contractiles: -; - MUST: INTENT explains WHY certain MUSTs exist. If you don't -; understand a MUST, read INTENT first. -; - TRUST: The "ask-before-touching" section in INTENT maps directly -; to TRUST.trust-deny for the most sensitive areas. -; - ADJUST: INTENT's anti-purpose should include "this software is -; NOT only for users with perfect vision/hearing/mobility." -; - DUST: When INTENT changes (repo pivots), related DUST entries -; should be created for the abandoned direction. -; -; ── End Definitions ────────────────────────────────────────────── - -(intent-contractile - (version "1.0.0") - (repo "wokelang") - - ; === Purpose (what this repo IS) === - (purpose - "{{ONE_PARAGRAPH_PURPOSE}}" - ) - - ; === Anti-Purpose (what this repo is NOT — prevents scope creep) === - (anti-purpose - "{{ONE_PARAGRAPH_ANTI_PURPOSE}}" - ; Examples: - ; "This is NOT a general-purpose database — it solves one specific problem." - ; "This is NOT a framework — it is a library with a focused API." - ; "This does NOT handle authentication — that is delegated to [other repo]." - ) - - ; === Key Architectural Decisions That Must Not Be Reversed === - (architectural-invariants - ; *REMINDER: List the foundational decisions* - ; ("Idris2 for ABI definitions — dependent types prove interface correctness") - ; ("Zig for FFI — zero-cost C ABI compatibility") - ; ("Elixir for supervision — OTP fault tolerance") - ) - - ; === Sensitive Areas (if in doubt, ask) === - (ask-before-touching - ; *REMINDER: List areas where LLMs should check before modifying* - ; "src/abi/ — formal proofs, changes require re-verification" - ; "ffi/zig/ — C ABI boundary, changes affect all language bindings" - ; ".machine_readable/ — checkpoint files, format is specified" - ) - - ; === Ecosystem Position === - (ecosystem - (belongs-to "{{MONOREPO_OR_STANDALONE}}") - (depends-on ("{{DEP1}}" "{{DEP2}}")) - (depended-on-by ("{{CONSUMER1}}" "{{CONSUMER2}}")) - ) -) diff --git a/.machine_readable/MUST.contractile b/.machine_readable/MUST.contractile deleted file mode 100644 index 4a97e6a..0000000 --- a/.machine_readable/MUST.contractile +++ /dev/null @@ -1,91 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; MUST.contractile — Baseline invariants for wokelang -; These constraints MUST NOT be violated. K9 validators enforce them. -; -; Part of the contractile family: MUST, TRUST, DUST, INTENT, ADJUST - -; ── Definitions ────────────────────────────────────────────────── -; -; MUST (noun/verb) -; The hard-constraint contractile. Defines invariants that are structurally -; required for the repository to function correctly and safely. Violating -; a MUST is always a bug — there are no "soft" MUSTs. -; -; Scope: -; MUST governs code, configuration, CI, and structure. It does NOT govern -; style, preference, or approach — those belong in CLAUDE.md or coding -; standards. MUST is for things that break the project if violated. -; -; Relationship to other contractiles: -; - TRUST: MUST is enforced regardless of trust level. Even maximal-trust -; agents cannot violate MUST constraints. -; - ADJUST: All ADJUST invariants are implicitly MUST invariants too. -; ADJUST exists separately for visibility. -; - INTENT: MUST protects the architectural decisions described in INTENT. -; - DUST: When a feature enters DUST (deprecation), its MUST constraints -; remain active until the feature is fully removed. -; -; Enforcement: -; K9 validators in contractiles/k9/ machine-check MUST constraints. -; CI runs these on every PR. Violations block merge. -; -; ── End Definitions ────────────────────────────────────────────── - -(must-contractile - (version "1.0.0") - (repo "wokelang") - - ; === Universal Invariants (apply to ALL repos) === - - (invariants - ; Paths - (must "no hardcoded absolute paths (/home/*, /mnt/*, /var/mnt/*)") - (must "all paths use env vars, XDG dirs, or relative references") - - ; Language policy - (must "no new TypeScript files") - (must "no new Python files") - (must "no new Go files") - (must "no npm/bun/yarn/pnpm dependencies — Deno only") - - ; Dangerous patterns - (must "no believe_me (Idris2)") - (must "no assert_total (Idris2)") - (must "no Admitted (Coq)") - (must "no sorry (Lean)") - (must "no unsafeCoerce (Haskell)") - (must "no Obj.magic (OCaml)") - (must "no unsafe {} blocks without safety comment (Rust)") - - ; License - (must "SPDX-License-Identifier header on every source file") - (must "no removal or modification of LICENSE file") - - ; Structure - (must ".machine_readable/ directory preserved") - (must "0-AI-MANIFEST.a2ml preserved") - (must "no SCM files in repo root — only in .machine_readable/") - - ; CI - (must "no removal of CI workflows without explicit approval") - (must "all GitHub Actions SHA-pinned") - - ; Code quality - (must "tests must not be deleted or weakened") - (must "generated code in generated/ directory only") - (must "no introduction of OWASP top 10 vulnerabilities") - - ; ABI/FFI (if applicable) - (must "no modification of ABI contracts without proof update") - (must "no removal of formal verification proofs") - ) - - ; === Project-Specific Invariants === - ; *REMINDER: Add invariants specific to this repo* - ; (must "# Add project-specific invariants here") - - (enforcement - (k9-validator "contractiles/k9/must-check.k9.ncl") - (ci "quality.yml runs must-check on every PR") - ) -) diff --git a/.machine_readable/TRUST.contractile b/.machine_readable/TRUST.contractile deleted file mode 100644 index b137f10..0000000 --- a/.machine_readable/TRUST.contractile +++ /dev/null @@ -1,80 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -; TRUST.contractile — Trust boundaries for wokelang -; Defines what LLM/SLM agents are trusted to do without asking. -; -; Part of the contractile family: MUST, TRUST, DUST, INTENT, ADJUST - -; ── Definitions ────────────────────────────────────────────────── -; -; TRUST (noun/verb) -; The permission contractile. Defines the boundary between what an AI -; agent may do autonomously and what requires human approval. Trust is -; graduated — not binary — with four levels from minimal to maximal. -; -; Trust levels: -; - maximal: Agent may read, build, test, lint, format, heal freely. -; Only destructive/external actions require approval. -; - standard: Agent may read and build. Test/lint need approval. -; - restricted: Agent may read only. All modifications need approval. -; - minimal: Agent may read specific files only. Everything else blocked. -; -; Scope: -; TRUST governs AI agent behaviour only. It does not affect human -; contributors — humans follow CONTRIBUTING.md and GOVERNANCE.adoc. -; -; Relationship to other contractiles: -; - MUST: Trust never overrides MUST. Even at maximal trust, MUST -; violations are blocked. -; - ADJUST: Trust does not exempt from ADJUST. All trust tiers must -; produce accessible output. -; - INTENT: TRUST.trust-deny protects the sensitive areas listed in -; INTENT.ask-before-touching. -; - DUST: Deprecated features have the same trust rules as active ones. -; -; ── End Definitions ────────────────────────────────────────────── - -(trust-contractile - (version "1.0.0") - (repo "wokelang") - - (trust-level "maximal") ; maximal | standard | restricted | minimal - - ; === Maximal Trust (default) === - ; LLM may freely do these without asking: - (trust-actions - "read" ; Read any file in the repo - "build" ; Run build commands - "test" ; Run test suites - "lint" ; Run linters and formatters - "format" ; Auto-format code - "doctor" ; Run self-diagnostics - "heal" ; Attempt automatic repair - "git-status" ; Check git status - "git-diff" ; View diffs - "git-log" ; View history - ) - - ; === Denied Actions (always require human approval) === - (trust-deny - "delete-branch" ; Could lose work - "force-push" ; Overwrites history - "modify-ci-secrets" ; Security sensitive - "publish" ; External visibility - "push-to-main" ; Protected branch - "delete-files-bulk" ; More than 5 files at once - "modify-license" ; Legal implications - "modify-security-policy" ; Security implications - "remove-proofs" ; Formal verification regression - "disable-ci-checks" ; Safety regression - ) - - ; === Trust Boundary === - (trust-boundary "repo") ; LLM confined to this repo unless explicitly told otherwise - - ; === Override === - ; Repos requiring tighter trust override these settings with justification: - ; (override - ; (trust-level "restricted") - ; (reason "Contains production secrets / handles PII / etc.") - ; ) -) diff --git a/.machine_readable/contractiles/Adjustfile.a2ml b/.machine_readable/contractiles/Adjustfile.a2ml new file mode 100644 index 0000000..6f01e89 --- /dev/null +++ b/.machine_readable/contractiles/Adjustfile.a2ml @@ -0,0 +1,72 @@ +# SPDX-License-Identifier: MPL-2.0 +# Adjustfile — Drift-tolerance contract for rsr-template-repo +# Author: Jonathan D.A. Jewell +# +# Cumulative-drift catchment: tolerance bands + corrective actions. +# Authority: advisory (Yard) — continue-with-warnings; auto_fix where deterministic. +# Run with: adjust check +# Fix with: adjust fix (applies deterministic patches; advisory otherwise) + +@abstract: +Drift tolerances and corrective actions for rsr-template-repo. Unlike +MUST (hard gate), ADJUST tracks cumulative drift against tolerance bands +and proposes corrective actions. Advisory — it warns and trends, it does +not block. +@end + +## Template Drift + +### placeholder-drift +- description: Template placeholders should be replaced when copied +- tolerance: 0 placeholder markers in copied repos +- corrective: Search and replace all {{PLACEHOLDER}} markers +- severity: advisory +- notes: This check only applies to repos that copied from this template + +### template-version-drift +- description: Template version should match RSR spec version +- tolerance: Template version matches current RSR spec +- corrective: Update template to match latest RSR spec +- severity: advisory + +## Documentation Drift + +### readme-completeness +- description: README should document all template features +- tolerance: README covers all contractiles and directory structure +- corrective: Update README.adoc with missing sections +- severity: advisory + +### example-accuracy +- description: Examples in documentation should match actual template content +- tolerance: All code examples in docs are accurate +- corrective: Audit and fix examples in documentation +- severity: advisory + +## Structural Drift + +### contractile-sync +- description: All contractiles should have matching a2ml and ncl implementations +- tolerance: Every .a2ml has a corresponding .ncl +- corrective: Generate missing .ncl files from .a2ml +- severity: advisory + +### no-broken-symlinks +- description: No broken symbolic links in template structure +- tolerance: 0 broken symlinks +- corrective: Run symlink-check script +- severity: advisory + +## Accessibility Drift + +### adoc-not-md +- description: Template docs should prefer AsciiDoc +- tolerance: New prose docs are *.adoc +- corrective: Convert any new *.md to *.adoc +- severity: advisory + +### spdx-header-consistency +- description: All template files have correct SPDX headers +- tolerance: 0 files missing SPDX-License-Identifier +- corrective: Add SPDX headers to files that need them +- severity: advisory diff --git a/.machine_readable/contractiles/Intentfile.a2ml b/.machine_readable/contractiles/Intentfile.a2ml new file mode 100644 index 0000000..ef74f45 --- /dev/null +++ b/.machine_readable/contractiles/Intentfile.a2ml @@ -0,0 +1,99 @@ +# SPDX-License-Identifier: MPL-2.0 +# Intentfile (A2ML Canonical) — north-star contractile for rsr-template-repo +# Author: Jonathan D.A. Jewell +# +# Paired runner: intend.ncl +# Verb: intend +# +# Semantics: North-star contractile. Declares BOTH concrete committed +# next-actions AND horizon aspirations the project wishes to +# become. Two sections share one file because they answer +# the same question at different ranges: +# [[intents]] — "we WILL do this; track progress" +# status: declared → in_progress → done | +# deferred | retired +# [[wishes]] — "we WISH this were true; revisit later" +# status: declared → in_progress → achieved | +# abandoned +# grouped by horizon: near / mid / far. +# Non-gating — this is a report, not a gate. See the `must` +# contractile for hard gates. + +@abstract: +North-star contractile for rsr-template-repo. This repository is the +canonical template for Rhodium Standard Repository compliance. It provides +the scaffold that all hyperpolymath repos should copy and customize. +@end + +## Purpose + +The rsr-template-repo serves as the master template for all hyperpolymath +repositories. It contains the complete set of contractile files, machine-readable +specifications, and governance documentation that define the Rhodium Standard. + +Every new repository in the hyperpolymath estate should be initialized by +copying this template and substituting the placeholder values with +repo-specific content. + +## Anti-Purpose + +This repository is NOT: +- A general-purpose project scaffold for external use (hyperpolymath-only) +- A replacement for per-repo customization (all files must be bespoke) +- A static template that never changes (evolves with RSR spec) +- A runtime library or framework (build-time only) + +## If In Doubt + +If you are unsure whether a change is in scope, ask. Sensitive areas: +- .machine_readable/ contractile definitions +- RSR specification files +- Governance templates +- License policy documents + +## Committed Next-Actions + +### repo-initialization +- description: Provide just copy-and-substitute template for new repos +- probe: test -f scripts/init-repo.sh +- status: done +- notes: Run with source scripts/init-repo.sh + +### contractile-completeness +- description: Every RSR contractile has an a2ml and ncl implementation +- probe: ls .machine_readable/contractiles/*.a2ml | wc -l | grep -q "^6$" +- status: in_progress +- notes: Currently 6 contractile verbs: intend, must, trust, adjust, bust, dust + +### automation-scripts +- description: All repetitive tasks have just recipes +- probe: grep -c "^# " Justfile | grep -q "^[6-9][0-9]*$" +- status: in_progress + +## Wishes + +### Near Horizon + +#### cross-repo-validation +- description: Tooling to validate all repos against RSR spec +- horizon: near +- status: declared + +#### automated-substitution +- description: Script to automate repo-specific substitution in template +- horizon: near +- status: declared + +### Mid Horizon + +#### formal-verification +- description: Idris2 proofs for all critical contractile invariants +- horizon: mid +- status: declared + +### Far Horizon + +#### ecosystem-visualization +- description: Interactive graph of all hyperpolymath repos and dependencies +- horizon: far +- status: declared diff --git a/.machine_readable/contractiles/Justfile b/.machine_readable/contractiles/Justfile new file mode 100644 index 0000000..6681024 --- /dev/null +++ b/.machine_readable/contractiles/Justfile @@ -0,0 +1,100 @@ +# SPDX-License-Identifier: MPL-2.0 +# WokeLang Justfile + +# Build the compiler +import? "contractile.just" + +build: + cargo build --release + +# Run tests +test: + cargo test + +# End-to-end structural validation +e2e: + bash tests/e2e.sh + +# Format code +format: + cargo fmt + +# Lint +lint: + cargo clippy + +# Clean +clean: + cargo clean + +# Validate RSR compliance +validate: + @echo "Checking SPDX headers..." + @grep -rL "SPDX-License-Identifier" src/ --include='*.rs' || echo "All files have SPDX headers" + +# Run panic-attacker pre-commit scan +assail: + @command -v panic-attack >/dev/null 2>&1 && panic-attack assail . || echo "panic-attack not found — install from https://github.com/hyperpolymath/panic-attacker" + +# Self-diagnostic — checks dependencies, permissions, paths +doctor: + @echo "Running diagnostics for wokelang..." + @echo "Checking required tools..." + @command -v just >/dev/null 2>&1 && echo " [OK] just" || echo " [FAIL] just not found" + @command -v git >/dev/null 2>&1 && echo " [OK] git" || echo " [FAIL] git not found" + @echo "Checking for hardcoded paths..." + @grep -rn '$HOME\|$ECLIPSE_DIR' --include='*.rs' --include='*.ex' --include='*.res' --include='*.gleam' --include='*.sh' . 2>/dev/null | head -5 || echo " [OK] No hardcoded paths" + @echo "Diagnostics complete." + +# Auto-repair common issues +heal: + @echo "Attempting auto-repair for wokelang..." + @echo "Fixing permissions..." + @find . -name "*.sh" -exec chmod +x {} \; 2>/dev/null || true + @echo "Cleaning stale caches..." + @rm -rf .cache/stale 2>/dev/null || true + @echo "Repair complete." + +# Guided tour of key features +tour: + @echo "=== wokelang Tour ===" + @echo "" + @echo "1. Project structure:" + @ls -la + @echo "" + @echo "2. Available commands: just --list" + @echo "" + @echo "3. Read README.adoc for full overview" + @echo "4. Read EXPLAINME.adoc for architecture decisions" + @echo "5. Run 'just doctor' to check your setup" + @echo "" + @echo "Tour complete! Try 'just --list' to see all available commands." + +# Open feedback channel with diagnostic context +help-me: + @echo "=== wokelang Help ===" + @echo "Platform: $(uname -s) $(uname -m)" + @echo "Shell: $SHELL" + @echo "" + @echo "To report an issue:" + @echo " https://github.com/hyperpolymath/wokelang/issues/new" + @echo "" + @echo "Include the output of 'just doctor' in your report." + + +# Print the current CRG grade (reads from READINESS.md '**Current Grade:** X' line) +crg-grade: + @grade=$$(grep -oP '(?<=\*\*Current Grade:\*\* )[A-FX]' READINESS.md 2>/dev/null | head -1); \ + [ -z "$$grade" ] && grade="X"; \ + echo "$$grade" + +# Generate a shields.io badge markdown for the current CRG grade +# Looks for '**Current Grade:** X' in READINESS.md; falls back to X +crg-badge: + @grade=$$(grep -oP '(?<=\*\*Current Grade:\*\* )[A-FX]' READINESS.md 2>/dev/null | head -1); \ + [ -z "$$grade" ] && grade="X"; \ + case "$$grade" in \ + A) color="brightgreen" ;; B) color="green" ;; C) color="yellow" ;; \ + D) color="orange" ;; E) color="red" ;; F) color="critical" ;; \ + *) color="lightgrey" ;; esac; \ + echo "[![CRG $$grade](https://img.shields.io/badge/CRG-$$grade-$$color?style=flat-square)](https://github.com/hyperpolymath/standards/tree/main/component-readiness-grades)" diff --git a/.machine_readable/contractiles/Mustfile.a2ml b/.machine_readable/contractiles/Mustfile.a2ml new file mode 100644 index 0000000..55f8ab4 --- /dev/null +++ b/.machine_readable/contractiles/Mustfile.a2ml @@ -0,0 +1,102 @@ +# SPDX-License-Identifier: MPL-2.0 +# Mustfile — Physical state contract for rsr-template-repo +# Author: Jonathan D.A. Jewell +# +# What MUST be true about this repository. Hard requirements. +# Run with: must check +# Fix with: must fix (where a deterministic fix exists) + +@abstract: +Physical-state invariants for rsr-template-repo. This is the canonical +RSR template repository. These are hard requirements — CI and pre-commit +hooks fail if any check fails. +@end + +## File Presence + +### license-present +- description: LICENSE file must exist +- run: test -f LICENSE +- severity: critical + +### readme-present +- description: README.adoc must exist +- run: test -f README.adoc +- severity: critical + +### security-policy +- description: SECURITY.md must exist +- run: test -f SECURITY.md +- severity: critical + +### ai-manifest +- description: 0-AI-MANIFEST.a2ml must exist +- run: test -f 0-AI-MANIFEST.a2ml +- severity: critical + +### governance-docs +- description: GOVERNANCE.adoc, MAINTAINERS.adoc, CODEOWNERS must exist +- run: test -f GOVERNANCE.adoc && test -f MAINTAINERS.adoc && test -f .github/CODEOWNERS +- severity: critical + +### machine-readable-dir +- description: .machine_readable/ directory must exist +- run: test -d .machine_readable +- severity: critical + +## Directory Structure + +### contractiles-complete +- description: All required contractile directories exist +- run: test -d .machine_readable/contractiles && test -d .machine_readable/contractiles/bust && test -d .machine_readable/contractiles/dust +- severity: critical + +### contractiles-files-present +- description: All four primary contractile files exist +- run: test -f .machine_readable/contractiles/Intentfile.a2ml && test -f .machine_readable/contractiles/Mustfile.a2ml && test -f .machine_readable/contractiles/Trustfile.a2ml && test -f .machine_readable/contractiles/Adjustfile.a2ml +- severity: critical + +### bust-dust-files-present +- description: Bustfile and Dustfile exist in their directories +- run: test -f .machine_readable/contractiles/bust/Bustfile.a2ml && test -f .machine_readable/contractiles/dust/Dustfile.a2ml +- severity: critical + +### six-directory-present +- description: 6a2 directory exists with required files +- run: test -d .machine_readable/6a2 && test -f .machine_readable/6a2/META.a2ml && test -f .machine_readable/6a2/ECOSYSTEM.a2ml && test -f .machine_readable/6a2/STATE.a2ml && test -f .machine_readable/6a2/PLAYBOOK.a2ml && test -f .machine_readable/6a2/AGENTIC.a2ml && test -f .machine_readable/6a2/NEUROSYM.a2ml +- severity: critical + +### anchors-directory +- description: anchors directory exists in 6a2 +- run: test -d .machine_readable/6a2/anchors +- severity: warning + +### self-validating-structure +- description: self-validating directory has k9-svc and examples +- run: test -d .machine_readable/self-validating && test -d .machine_readable/self-validating/k9-svc && test -d .machine_readable/self-validating/examples +- severity: warning + +## Template Integrity + +### no-placeholder-values +- description: No placeholder values remain in template files +- run: test -z "$(grep -r '{{' .machine_readable/contractiles/ 2>/dev/null)" +- severity: critical +- notes: All placeholders must be substituted when copying this template + +### template-readonly +- description: Template marker files are not modified +- run: grep -q 'RSR_TEMPLATE_DO_NOT_EDIT' .machine_readable/0.1-AI-MANIFEST.a2ml +- severity: warning + +## Git State + +### no-untracked-contractiles +- description: All contractile files are tracked in git +- run: test -z "$(git ls-files -o --exclude-standard .machine_readable/contractiles/ 2>/dev/null)" +- severity: critical + +### signed-commits +- description: All commits must be signed +- run: git verify-commit HEAD +- severity: critical diff --git a/.machine_readable/contractiles/Trustfile.a2ml b/.machine_readable/contractiles/Trustfile.a2ml new file mode 100644 index 0000000..e2028b5 --- /dev/null +++ b/.machine_readable/contractiles/Trustfile.a2ml @@ -0,0 +1,88 @@ +# SPDX-License-Identifier: MPL-2.0 +# Trustfile — Trust boundaries and integrity invariants for rsr-template-repo +# Author: Jonathan D.A. Jewell +# +# Defines what LLM/SLM agents are trusted to do without asking, and +# integrity invariants that verify the repo has not been tampered with. + +@abstract: +Trust boundaries and integrity checks for rsr-template-repo. This file +combines the trust-level definitions from the original TRUST.contractile +with the integrity invariants from the old Trustfile.a2ml. It defines +what AI agents may do autonomously and what requires human approval, +plus checks that verify repository integrity. +@end + +## Trust Levels + +The rsr-template-repo operates at trust level: maximal + +Trust levels: +- maximal: Agent may read, build, test, lint, format, heal freely. + Only destructive/external actions require approval. +- standard: Agent may read and build. Test/lint need approval. +- restricted: Agent may read only. All modifications need approval. +- minimal: Agent may read specific files only. Everything else blocked. + +Current trust level: maximal + +## Integrity Invariants + +### Secrets + +#### no-secrets-committed +- description: No credential files in repo +- run: test ! -f .env && test ! -f credentials.json && test ! -f .env.local && test ! -f .env.production +- severity: critical + +#### no-private-keys +- description: No private key files committed +- run: "! find . -name '*.pem' -o -name '*.key' -o -name 'id_rsa' -o -name 'id_ed25519' 2>/dev/null | grep -v node_modules | head -1 | grep -q ." +- severity: critical + +#### no-tokens-in-source +- description: No hardcoded API tokens in source +- run: "! grep -rE '(api[_-]?key|secret|token|password)\s*[:=]\s*[\"'\\''][A-Za-z0-9]{16,}' --include='*.js' --include='*.ts' --include='*.res' --include='*.py' . 2>/dev/null | grep -v node_modules | head -1 | grep -q ." +- severity: critical + +## Provenance + +#### author-correct +- description: Git author matches expected identity +- run: "git log -1 --format='%ae' | grep -qE '(hyperpolymath|j\\.d\\.a\\.jewell)'" +- severity: warning + +#### license-content +- description: LICENSE contains expected identifier +- run: grep -q 'PMPL\|MPL\|MIT\|Apache\|LGPL' LICENSE +- severity: warning + +## Template-Specific Trust + +### template-files-readonly +- description: Template scaffold files should not be modified except by maintainer +- run: test -z "$(git status --short .machine_readable/ 2>/dev/null | grep -v '^??' || true)" +- severity: advisory +- notes: Changes to template files require careful review + +### trust-deny-areas +- description: Sensitive areas from INTENT.contractile require explicit approval +- run: echo "Check .machine_readable/ contractiles and governance docs" +- severity: advisory +- areas: + - .machine_readable/ + - GOVERNANCE.adoc + - MAINTAINERS.adoc + - .github/CODEOWNERS + +## Container Security + +#### container-images-pinned +- description: Containerfile uses pinned base images +- run: test ! -f Containerfile || grep -q 'cgr.dev\|@sha256:' Containerfile +- severity: warning + +#### no-dockerfile +- description: No Dockerfile (use Containerfile) +- run: test ! -f Dockerfile +- severity: warning diff --git a/.machine_readable/contractiles/bust/Bustfile.a2ml b/.machine_readable/contractiles/bust/Bustfile.a2ml deleted file mode 100644 index 4237d7e..0000000 --- a/.machine_readable/contractiles/bust/Bustfile.a2ml +++ /dev/null @@ -1,28 +0,0 @@ -// Bustfile.a2ml — meta-repo bust contractile (breakage / rollback) -// SPDX-License-Identifier: MPL-2.0 - -Bust { - name: "wokelang" - version: "1.0.0" - description: "Rollback procedures when something breaks in the meta-repo" - - scenarios: { - "bad-pointer-bump": "git revert in meta-repo; child repo itself untouched" - "submodule-pointer-points-at-missing-sha": "git submodule update --init --checkout resets child to parent-recorded SHA; OR revert the stale bump commit" - "submodule-orphan-after-local-only-commit": "roll back locally with git reset to before the stranded commit; fix remote situation before re-attempting" - "accidental-private-repo-content-leaked-to-public-submodule": "hard-rotate the leaked secret immediately; git-filter-repo or BFG on the submodule's own history; public re-publication only after rotation complete" - } - - escalation-ladder: [ - "1. revert the meta-repo commit (reversible, low blast radius)", - "2. reset the local submodule clone (affects only local workspace)", - "3. force-push to main — PROHIBITED without explicit user confirmation (violates branch protection)", - "4. registry-level (delete/archive the GitHub repo) — human-only action, never by AI" - ] - - backup-points: [ - "GitHub serves as the durable backup for every submodule's own history", - "Meta-repo history on origin/main is the durable backup for pointer state", - "Local backup tags (backup/pre--) retained on risky rewrites" - ] -} diff --git a/.machine_readable/contractiles/bust/bust.ncl b/.machine_readable/contractiles/bust/bust.ncl deleted file mode 100644 index fc8cb8c..0000000 --- a/.machine_readable/contractiles/bust/bust.ncl +++ /dev/null @@ -1,66 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Bust — error-handling / failure-recovery runner -# -# Pairs with: Bustfile.a2ml (same directory) -# Verb: bust -# Semantics: every declared failure mode must have a recovery path that has -# been exercised. Runner injects failures (via declared probes) -# and verifies the recovery path works. Hard gate on any -# failure-mode with missing or broken recovery. -# CLI: `contractile bust check` → list failure modes + recovery status -# `contractile bust drill` → inject declared failures, verify recovery -# -# Anything else in this directory is human-only notes/archive; machines ignore. -# -# Base: ../_base.ncl provides pedigree_schema, run_defaults, probe_schema. -# See: docs/CONTRACTILE-SPEC.adoc - -let base = import "../_base.ncl" in - -{ - pedigree = base.pedigree_schema & { - contractile_verb = "bust", - semantics = "error handling + failure recovery", - security = { - leash = 'Kennel, - trust_level = "controlled failure injection; scoped to system-under-test", - allow_network = false, - allow_filesystem_write = true, # drills may write transient state (tmp dirs, test DBs) - allow_subprocess = true, - injection_scope = "system-under-test-only", - }, - metadata = { - name = "bust-runner", - version = "1.0.0", - description = "Exercises declared failure modes and verifies recovery paths. Hard-gates on any failure mode without working recovery.", - paired_xfile = "Bustfile.a2ml", - author = "Jonathan D.A. Jewell ", - }, - }, - - schema = { - failure_modes - | Array { - id | String, - description | String, - class | [| 'network, 'disk_full, 'oom, 'timeout, 'partial_write, 'panic, 'crash, 'rollback, 'concurrency |], - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - injection_probe | String, # command that deterministically causes this failure - # TODO: migrate to base.probe_schema (structured probe) when CLI supports it - recovery_probe | String, # command that verifies recovery (exit 0 = recovered) - expected_recovery_time_seconds | Number | default = 30, - # status_core values: 'declared, 'verified, 'failing; bust adds 'drilled - status | [| 'declared, 'drilled, 'verified, 'failing |] | default = 'declared, - notes | String | optional, - }, - }, - - # Runner behaviour — inherits from base.run_defaults. - # bust adds record_recovery_times for performance tier feeding. - run = base.run_defaults & { - on_any_fail = "exit-nonzero", # missing or broken recovery blocks merge - report_format = "a2ml", - emit_summary = true, - record_recovery_times = true, # feeds the performance tier - }, -} diff --git a/.machine_readable/contractiles/dust/Dustfile.a2ml b/.machine_readable/contractiles/dust/Dustfile.a2ml deleted file mode 100644 index 0d619ee..0000000 --- a/.machine_readable/contractiles/dust/Dustfile.a2ml +++ /dev/null @@ -1,22 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Dustfile — Cleanup and Hygiene Contract - -[dustfile] -version = "1.0.0" -format = "a2ml" - -[cleanup] -stale-branch-policy = "delete-after-merge" -artifact-retention = "90-days" -cache-policy = "clear-on-release" - -[hygiene] -linting = "required" -formatting = "required" -dead-code-removal = "encouraged" -todo-tracking = "tracked-in-issues" - -[reversibility] -backup-before-destructive = true -rollback-mechanism = "git-revert" -data-retention-policy = "preserve-30-days" diff --git a/.machine_readable/contractiles/trust/Trustfile.a2ml b/.machine_readable/contractiles/trust/Trustfile.a2ml deleted file mode 100644 index 0c95e15..0000000 --- a/.machine_readable/contractiles/trust/Trustfile.a2ml +++ /dev/null @@ -1,22 +0,0 @@ -# SPDX-License-Identifier: MPL-2.0 -# Trustfile — Integrity and Provenance Contract - -[trustfile] -version = "1.0.0" -format = "a2ml" - -[provenance] -source-control = "git" -forge = "github" -ci-verified = true -signing-policy = "commit-signing-preferred" - -[integrity] -spdx-compliant = true -license-audit = "required" -dependency-pinning = "sha-pinned" - -[verification] -reproducible-builds = "goal" -sbom-generation = "required" -attestation = "sigstore-preferred" diff --git a/GOVERNANCE.adoc b/GOVERNANCE.adoc new file mode 100644 index 0000000..8bbf167 --- /dev/null +++ b/GOVERNANCE.adoc @@ -0,0 +1,162 @@ +// SPDX-License-Identifier: MPL-2.0 +// SPDX-FileCopyrightText: 2026 Jonathan D.A. Jewell += Governance Model +:toc: preamble + +This document describes the governance model for this repository. + +== Overview + +This repository follows a **Sole Maintainer Governance Model**: + +* Single maintainer (@hyperpolymath) has full authority over the project +* All contributions are welcome and reviewed by the maintainer +* Decisions are made transparently through GitHub issues and discussions +* The project adheres to the hyperpolymath estate policies where applicable + +== Core Principles + +[cols="1,2"] +|=== +| Principle | Description + +| **Benevolent Dictatorship** | Maintainer has final decision authority but seeks community input + +| **Meritocracy** | Contributions are judged on technical merit, not contributor identity + +| **Transparency** | All significant decisions are documented publicly + +| **Consensus-Seeking** | Maintainer prefers consensus but will decide when necessary + +| **Open Contribution** | Anyone can contribute via fork and pull request + +|=== + +== Roles and Permissions + +[cols="1,2,2"] +|=== +| Role | Permissions | Assignment + +| **Maintainer** | Write access, merge rights, admin | @hyperpolymath +| **Contributors** | Read access, fork, submit PRs | All GitHub users +| **Users** | Use the software, report issues | All GitHub users + +|=== + +== Decision Making Framework + +=== Routine Decisions + +* Bug fixes +* Documentation improvements +* Minor feature additions +* Dependency updates + +**Process**: Maintainer reviews and merges PRs that meet quality standards. + +=== Significant Changes + +* New major features +* API changes +* Architecture modifications +* Breaking changes + +**Process**: +. Open issue describing the change +. Discuss with community (minimum 72 hours) +. Maintainer makes final decision +. Document rationale in issue/PR + +=== Structural Decisions + +* Repository purpose/renaming +* License changes +* Ownership transfer +* Deprecation/archival + +**Process**: +. Extended discussion (minimum 1 week) +. Maintainer makes final decision +. Document in CHANGELOG and governance docs + +== Contribution Lifecycle + +[cols="1,2"] +|=== +| Stage | Process + +| **Ideation** | Open issue, discuss feasibility + +| **Development** | Fork, implement, test thoroughly + +| **Review** | Submit PR, maintainer reviews within 7 days + +| **Merge** | Maintainer merges or requests changes + +| **Release** | Maintainer publishes according to project conventions + +|=== + +== Conflict Resolution + +In case of disagreements: + +. Discuss in the relevant GitHub issue or PR +. Provide technical justification for positions +. Maintainer mediates and makes final decision +. Decision is documented and can be revisited later + +== Project Policies + +This repository adheres to hyperpolymath estate-wide policies: + +* **License**: MPL-2.0 for code, CC-BY-SA-4.0 for prose (per standards/LICENCE-POLICY.adoc) +* **Code of Conduct**: Follows hyperpolymath CODE_OF_CONDUCT.md +* **Security**: Follows hyperpolymath SECURITY.md +* **Contributing**: Follows hyperpolymath CONTRIBUTING.adoc conventions + +== Repository-Specific Conventions + +[cols="1,2"] +|=== +| Convention | Description + +| **Signing** | All commits must be signed (SSH or GPG) + +| **SPDX Headers** | All source files must have SPDX license identifiers + +| **Contractiles** | Mustfile, Trustfile, Intendfile, Adjustfile in root + +| **Machine Readable** | META.a2ml in .machine_readable/6a2/ + +| **CI/CD** | GitHub Actions workflows in .github/workflows/ + +|=== + +== Governance Evolution + +As the project grows, this governance model may evolve: + +* **Adding Co-Maintainers**: When contribution volume warrants it +* **Forming a Team**: For complex multi-maintainer projects +* **Adopting TPCF**: For large, multi-repository projects (see rhodium-standard-repositories) + +Changes to this document require the same process as Significant Changes above. + +== See Also + +* link:MAINTAINERS.adoc[Maintainers] +* link:CODE_OF_CONDUCT.md[Code of Conduct] +* link:CONTRIBUTING.adoc[Contributing Guide] +* link:https://github.com/hyperpolymath/standards/blob/main/LICENCE-POLICY.adoc[Estate License Policy] +* link:https://github.com/hyperpolymath/standards[rhodium-standard-repositories (TPCF)] + +== Changelog + +[cols="1,1,1"] +|=== +| Date | Change | By + +| 2026-06-07 | Initial governance model established | @hyperpolymath +|=== diff --git a/contractiles/README.adoc b/contractiles/README.adoc deleted file mode 100644 index d4eaea4..0000000 --- a/contractiles/README.adoc +++ /dev/null @@ -1,22 +0,0 @@ -// SPDX-License-Identifier: MPL-2.0 -// Copyright (c) Jonathan D.A. Jewell - -= Contractiles Template Set -:toc: -:sectnums: - -This directory contains the generalized contractiles templates. Copy the `contractiles/` directory into a new repo to establish a consistent operational, validation, trust, recovery, and intent framework. - -== Fill-In Instructions - -1. Update the Mustfile to reflect your real invariants (paths, schema versions, ports). -2. Replace Trustfile.hs placeholders with your actual key paths and verification commands. -3. Adjust Dustfile handlers to match your rollback and recovery tooling. -4. Update Intentfile to mirror the roadmap you want the system to evolve toward. - -== Contents - -* `must/Mustfile` - required invariants and validations. -* `trust/Trustfile.hs` - cryptographic verification steps. -* `dust/Dustfile` - rollback and recovery semantics. -* `lust/Intentfile` - future intent and roadmap direction. diff --git a/contractiles/dust/Dustfile b/contractiles/dust/Dustfile deleted file mode 100644 index aece729..0000000 --- a/contractiles/dust/Dustfile +++ /dev/null @@ -1 +0,0 @@ -content of dustfile diff --git a/contractiles/must/Mustfile b/contractiles/must/Mustfile deleted file mode 100644 index 2f366ce..0000000 --- a/contractiles/must/Mustfile +++ /dev/null @@ -1,14 +0,0 @@ -# SPDX-License-Identifier: PLMP-1.0-or-later -# Mustfile - mandatory checks -# See: https://github.com/hyperpolymath/mustfile - -version: 1 - -checks: - - name: security - run: just lint - - name: tests - run: just test - - name: format - run: just fmt - diff --git a/contractiles/trust/Trustfile b/contractiles/trust/Trustfile deleted file mode 100644 index abf38c0..0000000 --- a/contractiles/trust/Trustfile +++ /dev/null @@ -1 +0,0 @@ -contents of Trustfile here diff --git a/flake.nix b/flake.nix deleted file mode 100644 index 11d287e..0000000 --- a/flake.nix +++ /dev/null @@ -1,116 +0,0 @@ -{ - description = "wokelang - {project-description}"; - - # *REMINDER: Update inputs with actual dependencies* - inputs = { - nixpkgs.url = "github:NixOS/nixpkgs/nixos-unstable"; - flake-utils.url = "github:numtide/flake-utils"; - # Add language-specific inputs: - # rust-overlay.url = "github:oxalica/rust-overlay"; # For Rust - # fenix.url = "github:nix-community/fenix"; # Alternative Rust - }; - - outputs = { self, nixpkgs, flake-utils, ... }@inputs: - flake-utils.lib.eachDefaultSystem (system: - let - pkgs = import nixpkgs { - inherit system; - # overlays = [ (import inputs.rust-overlay) ]; # For Rust - }; - - # *REMINDER: Define build dependencies* - buildInputs = with pkgs; [ - # Language-specific dependencies: - # gnat13 # Ada - # cargo rustc # Rust - # elixir # Elixir - # For build tools: - just - podman - git - ]; - - # *REMINDER: Define development dependencies* - nativeBuildInputs = with pkgs; [ - # Development tools: - ripgrep # Code search - lychee # Link validation - # Language-specific: - # rustfmt clippy # Rust - # mix # Elixir - ]; - - in - { - # Development shell - devShells.default = pkgs.mkShell { - inherit buildInputs nativeBuildInputs; - - shellHook = '' - echo "🚀 wokelang development environment" - echo "Language: rust" - echo "" - echo "Available commands:" - echo " just --list # Show all tasks" - echo " just setup # Set up environment" - echo " just build # Build project" - echo " just test # Run tests" - echo " just validate # RSR compliance" - echo "" - # *REMINDER: Add language-specific environment setup* - # export CARGO_HOME=$PWD/.cargo # Rust - # export MIX_HOME=$PWD/.mix # Elixir - ''; - }; - - # Packages - packages.default = pkgs.stdenv.mkDerivation { - pname = "wokelang"; - version = "0.1.0"; - src = ./.; - - inherit buildInputs nativeBuildInputs; - - buildPhase = '' - # *REMINDER: Add build commands* - # For Rust: cargo build --release - # For Elixir: mix compile - # For Ada: gprbuild -P wokelang.gpr -XMODE=release - ''; - - installPhase = '' - mkdir -p $out/bin - # *REMINDER: Add install commands* - # cp target/release/wokelang $out/bin/ # Rust - # cp bin/wokelang $out/bin/ # Ada - ''; - - meta = with pkgs.lib; { - description = "{project-description}"; - homepage = "{repo-url}"; - license = with licenses; [ mit ]; # MIT + Palimpsest - maintainers = [ "{maintainer-name}" ]; - platforms = platforms.unix; - }; - }; - - # Apps - apps.default = { - type = "app"; - program = "${self.packages.${system}.default}/bin/wokelang"; - }; - - # Checks (CI/CD integration) - checks = { - build = self.packages.${system}.default; - # *REMINDER: Add test checks* - test = pkgs.runCommand "test-wokelang" { - buildInputs = [ self.packages.${system}.default ]; - } '' - # Run tests here - touch $out - ''; - }; - } - ); -} From 340e80c4500131e330c968fe06b8d5f29136b754 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Mon, 8 Jun 2026 00:59:44 +0100 Subject: [PATCH 7/9] Add missing bust/dust contractiles --- .../contractiles/bust/Bustfile.a2ml | 52 ++++++++++++++++ .../contractiles/dust/Dustfile.a2ml | 62 +++++++++++++++++++ 2 files changed, 114 insertions(+) create mode 100644 .machine_readable/contractiles/bust/Bustfile.a2ml create mode 100644 .machine_readable/contractiles/dust/Dustfile.a2ml diff --git a/.machine_readable/contractiles/bust/Bustfile.a2ml b/.machine_readable/contractiles/bust/Bustfile.a2ml new file mode 100644 index 0000000..16e369f --- /dev/null +++ b/.machine_readable/contractiles/bust/Bustfile.a2ml @@ -0,0 +1,52 @@ +# SPDX-License-Identifier: MPL-2.0 +# Bustfile — failure mode contractile for wokelang +# Author: Jonathan D.A. Jewell +# +# Paired runner: bust.ncl +# Verb: bust +# Semantics: Every declared failure mode must have a working recovery path +# that has been exercised. Status moves: +# declared → drilled (probe run) → verified (recovery confirmed) +# or → failing (recovery broken) +# +# CLI: +# contractile bust check → list failure modes + recovery status +# contractile bust drill → inject failures, verify recovery paths +# +# This repository: wokelang is the canonical template for RSR compliance. +# Failure modes here relate to template distribution and substitution. + +@abstract: +Bustfile for wokelang. Lists failure modes specific to the template +repository itself, particularly around template distribution, substitution, +and synchronization across the hyperpolymath estate. +@end + +## Failure Modes + +### template-substitution-failure +- class: template_processing +- description: Template substitution fails when initializing a new repo from this template +- injection_probe: "cp -r wokelang test-repo && cd test-repo && sed -i 's/wokelang/TEST/g' .machine_readable/contractiles/Intentfile.a2ml && grep -q 'TEST' .machine_readable/contractiles/Intentfile.a2ml" +- recovery_probe: "git -C test-repo diff --quiet .machine_readable/contractiles/Intentfile.a2ml" +- expected_recovery_time_seconds: 10 +- status: declared +- notes: Verify that substitution scripts handle all placeholder replacements correctly + +### sync-drift-between-repos +- class: synchronization +- description: Drift occurs between wokelang and other repos after template updates +- injection_probe: "echo 'template_updated' > /tmp/test_drift_marker" +- recovery_probe: "test -f /tmp/test_drift_marker && rm /tmp/test_drift_marker" +- expected_recovery_time_seconds: 60 +- status: declared +- notes: The estate-wide sync scripts (see scripts/) should prevent this; verify with scripts/verify-sync.sh + +### contractile-parse-error +- class: contractile_format +- description: A contractile file fails to parse due to syntax errors +- injection_probe: "echo 'invalid syntax' >> wokelang/.machine_readable/contractiles/Intentfile.a2ml" +- recovery_probe: "git checkout wokelang/.machine_readable/contractiles/Intentfile.a2ml" +- expected_recovery_time_seconds: 5 +- status: declared +- notes: All .a2ml files should be valid A2ML; use a2ml-validate runner diff --git a/.machine_readable/contractiles/dust/Dustfile.a2ml b/.machine_readable/contractiles/dust/Dustfile.a2ml new file mode 100644 index 0000000..2ea55d5 --- /dev/null +++ b/.machine_readable/contractiles/dust/Dustfile.a2ml @@ -0,0 +1,62 @@ +# SPDX-License-Identifier: MPL-2.0 +# Dustfile — Cleanup and hygiene contract for wokelang +# Author: Jonathan D.A. Jewell +# +# Paired runner: dust.ncl +# Verb: dust +# Semantics: What should be cleaned up. Housekeeping, not blockers. +# +# This repository: wokelang is the canonical template. +# Cleanup items here ensure the template itself remains pristine. + +@abstract: +Cleanup and hygiene items for wokelang. These are maintenance tasks +that ensure the template repository remains clean and ready for distribution +to new repositories. +@end + +## Stale Files + +### no-template-artifacts +- description: No generated files from template testing in root +- run: test -z "$(ls template-test-* 2>/dev/null)" +- severity: info +- notes: Template testing should use /tmp or dedicated test directories + +### no-example-placeholders +- description: No example placeholder files (EXAMPLE-, SAMPLE-) in contractiles/ +- run: test -z "$(find .machine_readable/contractiles/ -name 'EXAMPLE-*' -o -name 'SAMPLE-*' 2>/dev/null)" +- severity: warning +- notes: All placeholders should be replaced with actual content or removed + +### no-old-contractile-formats +- description: No old .contractile or .hs files remaining +- run: test -z "$(find .machine_readable/contractiles/ \( -name '*.contractile' -o -name '*.hs' \) 2>/dev/null)" +- severity: warning +- notes: All contractiles should be .a2ml format + +## Format Duplicates + +### no-duplicate-justfile +- description: Only one Justfile (hardlinked from root to .machine_readable/contractiles/) +- run: test $(stat -c '%i' Justfile) = $(stat -c '%i' .machine_readable/contractiles/Justfile 2>/dev/null) +- severity: warning +- notes: Justfile should be hardlinked, not copied + +### no-duplicate-readme-format +- description: Only one README format in contractiles/ (.adoc canonical) +- run: test ! -f .machine_readable/contractiles/README.md +- severity: info + +## Template Hygiene + +### no-stale-template-references +- description: No references to wokelang in generic template files +- run: test -z "$(grep -r 'wokelang' machine-readable-design/ 2>/dev/null)" +- severity: warning +- notes: Generic templates should use {{PROJECT_NAME}} or similar placeholders + +### version-sync-checked +- description: Version in canonical-directory-structure matches .machine_readable/contractiles +- verification: compare version identifiers in both locations +- severity: info From 98caa934ee0143d7942f0b2adb1b6ad7c38582d0 Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Thu, 11 Jun 2026 22:15:55 +0100 Subject: [PATCH 8/9] security: standardize secret scanning on TruffleHog --- .github/workflows/cargo-audit.yml | 10 +--------- .github/workflows/cflite_batch.yml | 3 --- .github/workflows/cflite_pr.yml | 3 --- .github/workflows/codeql.yml | 7 ------- .github/workflows/e2e.yml | 13 ------------- .github/workflows/ghcr-publish.yml | 10 ---------- .github/workflows/governance.yml | 4 ---- .github/workflows/hypatia-scan.yml | 4 ---- .github/workflows/instant-sync.yml | 4 ---- .github/workflows/mirror.yml | 3 --- .github/workflows/ocaml-core.yml | 16 ---------------- .github/workflows/rust-ci.yml | 3 --- .github/workflows/scorecard-enforcer.yml | 14 ++------------ .github/workflows/scorecard.yml | 3 --- .github/workflows/secret-scanner.yml | 14 ++++++++++---- .github/workflows/security.yml | 15 --------------- .github/workflows/workflow-linter.yml | 6 ------ .machine_readable/contractiles/Justfile | 3 +++ Justfile | 3 +++ 19 files changed, 19 insertions(+), 119 deletions(-) diff --git a/.github/workflows/cargo-audit.yml b/.github/workflows/cargo-audit.yml index ee94660..daa7162 100644 --- a/.github/workflows/cargo-audit.yml +++ b/.github/workflows/cargo-audit.yml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: MPL-2.0 # Prevention workflow - audits Rust dependencies for vulnerabilities name: Cargo Audit - on: push: branches: [main] @@ -13,26 +12,20 @@ on: - '**/Cargo.toml' - '**/Cargo.lock' schedule: - - cron: '0 6 * * 1' # Weekly on Monday - + - cron: '0 6 * * 1' # Weekly on Monday permissions: read-all - jobs: audit: runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 - - name: Install cargo-audit run: cargo install cargo-audit --locked - - name: Run cargo audit run: cargo audit --deny warnings - - name: Check for unmaintained crates run: cargo audit --deny unmaintained - # Optional: Create issues for vulnerabilities create-issue: runs-on: ubuntu-latest @@ -43,7 +36,6 @@ jobs: issues: write steps: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 - - name: Create vulnerability issue env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/cflite_batch.yml b/.github/workflows/cflite_batch.yml index e7248f2..600d1b8 100644 --- a/.github/workflows/cflite_batch.yml +++ b/.github/workflows/cflite_batch.yml @@ -4,9 +4,7 @@ on: schedule: - cron: '0 3 * * 0' workflow_dispatch: - permissions: read-all - jobs: BatchFuzzing: runs-on: ubuntu-latest @@ -22,7 +20,6 @@ jobs: with: language: rust sanitizer: ${{ matrix.sanitizer }} - - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 diff --git a/.github/workflows/cflite_pr.yml b/.github/workflows/cflite_pr.yml index 9733d4c..504fb07 100644 --- a/.github/workflows/cflite_pr.yml +++ b/.github/workflows/cflite_pr.yml @@ -3,9 +3,7 @@ name: ClusterFuzzLite PR fuzzing on: pull_request: branches: [main] - permissions: read-all - jobs: PR: runs-on: ubuntu-latest @@ -21,7 +19,6 @@ jobs: with: language: rust sanitizer: ${{ matrix.sanitizer }} - - name: Run Fuzzers (${{ matrix.sanitizer }}) id: run uses: google/clusterfuzzlite/actions/run_fuzzers@884713a6c30a92e5e8544c39945cd7cb630abcd1 # v1 diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index e547933..64a6a75 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -1,6 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 name: CodeQL Security Analysis - on: push: branches: [main, master] @@ -8,7 +7,6 @@ on: branches: [main, master] schedule: - cron: '0 6 * * 1' - # Estate guardrail: cancel superseded runs so re-pushes / rebased PR # updates do not pile up queued runs against the shared account-wide # Actions concurrency pool. Applied only to read-only check workflows @@ -16,10 +14,8 @@ on: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - permissions: contents: read - jobs: analyze: runs-on: ubuntu-latest @@ -33,17 +29,14 @@ jobs: include: - language: javascript-typescript build-mode: none - steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Initialize CodeQL uses: github/codeql-action/init@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 with: languages: ${{ matrix.language }} build-mode: ${{ matrix.build-mode }} - - name: Perform CodeQL Analysis uses: github/codeql-action/analyze@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v3 with: diff --git a/.github/workflows/e2e.yml b/.github/workflows/e2e.yml index 5fd312b..ef3d66e 100644 --- a/.github/workflows/e2e.yml +++ b/.github/workflows/e2e.yml @@ -7,16 +7,13 @@ # structural — fast, no compiler required (grammar, spec, fixtures, layout) # build-e2e — full build then E2E (Rust cargo check + OCaml dune build) name: E2E Validation - on: pull_request: branches: ['**'] push: branches: [main, master] - permissions: contents: read - jobs: # -------------------------------------------------------------------------- # Job 1: Structural validation (no toolchain needed) @@ -25,14 +22,11 @@ jobs: name: Structural E2E (no-build) runs-on: ubuntu-latest timeout-minutes: 15 - steps: - name: Checkout repository uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - name: Run structural E2E checks run: E2E_BUILD=0 bash tests/e2e.sh - # -------------------------------------------------------------------------- # Job 2: Full build + E2E (Rust + OCaml) # -------------------------------------------------------------------------- @@ -40,35 +34,28 @@ jobs: name: Build + E2E (Rust + OCaml) runs-on: ubuntu-latest timeout-minutes: 15 - steps: - name: Checkout repository uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - # ---- Rust ---- - name: Install Rust stable toolchain uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable with: components: clippy, rustfmt - - name: Cache Cargo registry and build artefacts uses: Swatinem/rust-cache@779680da715d629ac1d338a641029a2f4372abb5 # v2 - # ---- OCaml ---- - name: Set up OCaml uses: ocaml/setup-ocaml@dec6499fef64fc5d7ed43d43a87251b7b1c306f5 # v3 with: ocaml-compiler: 5.1.x - - name: Install opam dependencies run: | opam install --deps-only --with-test wokelang.opam -y || \ opam install menhir ounit2 -y - # ---- Full E2E ---- - name: Run full E2E (with build checks) run: E2E_BUILD=1 bash tests/e2e.sh - # ---- Conformance suite ---- - name: Run conformance test runner run: bash tests/run_conformance.sh diff --git a/.github/workflows/ghcr-publish.yml b/.github/workflows/ghcr-publish.yml index 694acc8..6bd692e 100644 --- a/.github/workflows/ghcr-publish.yml +++ b/.github/workflows/ghcr-publish.yml @@ -1,17 +1,13 @@ # SPDX-License-Identifier: MPL-2.0 name: Publish to GHCR - permissions: read-all - on: release: types: [published] workflow_dispatch: - env: REGISTRY: ghcr.io IMAGE_NAME: ${{ github.repository }} - jobs: build-and-push: runs-on: ubuntu-latest @@ -19,11 +15,9 @@ jobs: permissions: contents: read packages: write - steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v4 - - name: Install nerdctl and containerd run: | sudo apt-get update @@ -38,21 +32,17 @@ jobs: sudo /usr/local/bin/buildkitd & sleep 3 - - name: Log in to GHCR run: | echo "${{ secrets.GITHUB_TOKEN }}" | sudo nerdctl login ghcr.io -u ${{ github.actor }} --password-stdin - - name: Build image run: | sudo nerdctl build -f Containerfile -t ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} . sudo nerdctl tag ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest - - name: Push image run: | sudo nerdctl push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:${{ github.sha }} sudo nerdctl push ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}:latest - - name: Tag release version if: github.event_name == 'release' run: | diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 1b4e269..e0c379b 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -11,13 +11,11 @@ # (rust-ci, codeql, dependabot, release, scan/mirror/pages plumbing). name: Governance - on: push: branches: [main, master] pull_request: workflow_dispatch: - # Estate guardrail: cancel superseded runs so re-pushes / rebased PR # updates do not pile up queued runs against the shared account-wide # Actions concurrency pool. Applied only to read-only check workflows @@ -25,10 +23,8 @@ on: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - permissions: contents: read - jobs: governance: uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@861b5e911d9e5dcfb3c0ab3dd2a9a3c8fd0a1613 diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index a711616..0776fac 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -3,7 +3,6 @@ # See standards#191 for the reusable's purpose and design. name: Hypatia Security Scan - on: push: branches: [main, master, develop] @@ -12,17 +11,14 @@ on: schedule: - cron: '0 0 * * 0' workflow_dispatch: - # Estate guardrail: cancel superseded runs so re-pushes don't pile up. concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - permissions: contents: read security-events: write pull-requests: write - jobs: hypatia: uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@6cd3772824e59c8c9affeab66061e25383544242 diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 01646a7..e9df9c7 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -1,16 +1,13 @@ # SPDX-License-Identifier: MPL-2.0 # Instant Forge Sync - Triggers propagation to all forges on push/release name: Instant Sync - on: push: branches: [main, master] release: types: [published] - permissions: contents: read - jobs: dispatch: runs-on: ubuntu-latest @@ -29,6 +26,5 @@ jobs: "sha": "${{ github.sha }}", "forges": "" } - - name: Confirm run: echo "::notice::Propagation triggered for ${{ github.event.repository.name }}" diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index ee8ea02..fcff1f2 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -1,14 +1,11 @@ # SPDX-License-Identifier: MPL-2.0 name: Mirror to Git Forges - on: push: branches: [main] workflow_dispatch: - permissions: contents: read - jobs: mirror: uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@e6b2884722350515934d443daf23442f2195796f diff --git a/.github/workflows/ocaml-core.yml b/.github/workflows/ocaml-core.yml index 0294cf0..176ef5d 100644 --- a/.github/workflows/ocaml-core.yml +++ b/.github/workflows/ocaml-core.yml @@ -2,7 +2,6 @@ # SPDX-FileCopyrightText: 2026 Hyperpolymath name: OCaml Core CI - on: push: branches: [main, develop] @@ -18,63 +17,48 @@ on: - 'test/**' - 'dune-project' - '*.opam' - permissions: read-all - jobs: build: name: Build and Test OCaml Core runs-on: ubuntu-latest timeout-minutes: 15 - strategy: matrix: ocaml-version: ['5.1.0', '5.0.0'] - steps: - name: Checkout repository uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - name: Setup OCaml uses: ocaml/setup-ocaml@dec6499fef64fc5d7ed43d43a87251b7b1c306f5 # v3 with: ocaml-compiler: ${{ matrix.ocaml-version }} dune-cache: true - - name: Install dependencies run: opam install . --deps-only --with-test - - name: Build core run: opam exec -- dune build - - name: Run tests run: opam exec -- dune test - - name: Run golden path smoke test run: opam exec -- dune exec -- wokelang examples/hello_world.wl - conformance: name: Conformance Tests runs-on: ubuntu-latest timeout-minutes: 15 needs: build - steps: - name: Checkout repository uses: actions/checkout@34e114876b0b11c390a56381ad16ebd13914f8d5 # v4 - - name: Setup OCaml uses: ocaml/setup-ocaml@dec6499fef64fc5d7ed43d43a87251b7b1c306f5 # v3 with: ocaml-compiler: '5.1.0' dune-cache: true - - name: Install dependencies run: opam install . --deps-only - - name: Build run: opam exec -- dune build - - name: Run conformance corpus run: | for f in test/conformance/*.wl; do diff --git a/.github/workflows/rust-ci.yml b/.github/workflows/rust-ci.yml index 040a198..55fdc2b 100644 --- a/.github/workflows/rust-ci.yml +++ b/.github/workflows/rust-ci.yml @@ -3,15 +3,12 @@ # hyperpolymath/standards. Configure once, propagate everywhere. # See: docs/CI-REUSABLE-WORKFLOWS.adoc in standards. name: Rust CI - on: push: branches: [main, master] pull_request: - permissions: contents: read - jobs: rust-ci: uses: hyperpolymath/standards/.github/workflows/rust-ci-reusable.yml@cc5a372af1af1b202c17f1b21efd954e6c038bef diff --git a/.github/workflows/scorecard-enforcer.yml b/.github/workflows/scorecard-enforcer.yml index 57535d0..f5fb110 100644 --- a/.github/workflows/scorecard-enforcer.yml +++ b/.github/workflows/scorecard-enforcer.yml @@ -1,14 +1,12 @@ # SPDX-License-Identifier: MPL-2.0 # Prevention workflow - runs OpenSSF Scorecard and fails on low scores name: OpenSSF Scorecard Enforcer - on: push: branches: [main] schedule: - - cron: '0 6 * * 1' # Weekly on Monday + - cron: '0 6 * * 1' # Weekly on Monday workflow_dispatch: - # Estate guardrail: cancel superseded runs so re-pushes / rebased PR # updates do not pile up queued runs against the shared account-wide # Actions concurrency pool. Applied only to read-only check workflows @@ -16,34 +14,29 @@ on: concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - permissions: contents: read - jobs: scorecard: runs-on: ubuntu-latest timeout-minutes: 15 permissions: security-events: write - id-token: write # For OIDC + id-token: write # For OIDC steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 with: persist-credentials: false - - name: Run Scorecard uses: ossf/scorecard-action@4eaacf0543bb3f2c246792bd56e8cdeffafb205a # v2.4.3 with: results_file: results.sarif results_format: sarif publish_results: true - - name: Upload SARIF uses: github/codeql-action/upload-sarif@c6f931105cb2c34c8f901cc885ba1e2e259cf745 # v4 with: sarif_file: results.sarif - - name: Check minimum score run: | # Parse score from results @@ -58,21 +51,18 @@ jobs: echo "::error::Scorecard score $SCORE is below minimum $MIN_SCORE" exit 1 fi - # Check specific high-priority items check-critical: runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Check SECURITY.md exists run: | if [ ! -f "SECURITY.md" ]; then echo "::error::SECURITY.md is required" exit 1 fi - - name: Check for pinned dependencies run: | # Check workflows for unpinned actions diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b272593..950b68f 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -1,15 +1,12 @@ # SPDX-License-Identifier: PMPL-1.0 name: Scorecards supply-chain security - on: branch_protection_rule: schedule: - cron: '23 4 * * 1' push: branches: [main] - permissions: read-all - jobs: analysis: uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@e0caf11508a3989574713c78f5f444f2ce5e33ef diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 3817aa9..4617a6c 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -1,20 +1,26 @@ # SPDX-License-Identifier: PMPL-1.0 name: Secret Scanner - on: pull_request: push: branches: [main] - concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: true - permissions: contents: read - jobs: scan: uses: hyperpolymath/standards/.github/workflows/secret-scanner-reusable.yml@3e4bd4c93911750727e2e4c66dff859e00079da0 timeout-minutes: 10 secrets: inherit + trufflehog: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + - name: TruffleHog Secret Scan + uses: trufflesecurity/trufflehog@main + with: + extra_args: --only-verified --fail diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 15592dd..20ff897 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -2,7 +2,6 @@ # RSR-compliant security workflow with SHA-pinned actions name: "Security" - on: push: branches: ["main"] @@ -10,9 +9,7 @@ on: branches: ["main"] schedule: - cron: '42 20 * * 0' - permissions: read-all - jobs: # Rust security audit using cargo-audit rust-security: @@ -25,16 +22,12 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable - - name: Install cargo-audit run: cargo install cargo-audit --locked - - name: Run cargo-audit run: cargo audit --deny warnings - # Dependency review for PRs dependency-review: name: Dependency Review @@ -47,10 +40,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Dependency Review uses: actions/dependency-review-action@a1d282b36b6f3519aa1f3fc636f609c47dddb294 # v4.5.0 - # Build verification build: name: Build Check @@ -61,10 +52,8 @@ jobs: steps: - name: Checkout repository uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 - - name: Install Rust toolchain uses: dtolnay/rust-toolchain@4be9e76fd7c4901c61fb841f559994984270fce7 # stable - - name: Cache cargo registry uses: actions/cache@668228422ae6a00e4ad889ee87cd7109ec5666a7 # v5.0.4 with: @@ -73,15 +62,11 @@ jobs: ~/.cargo/git target key: ${{ runner.os }}-cargo-${{ hashFiles('**/Cargo.lock') }} - - name: Build run: cargo build --release - - name: Run tests run: cargo test - - name: Check formatting run: cargo fmt --check - - name: Run clippy run: cargo clippy -- -D warnings diff --git a/.github/workflows/workflow-linter.yml b/.github/workflows/workflow-linter.yml index fef968f..862a590 100644 --- a/.github/workflows/workflow-linter.yml +++ b/.github/workflows/workflow-linter.yml @@ -1,7 +1,6 @@ # SPDX-License-Identifier: MPL-2.0 # Prevention workflow - validates all workflows have proper security config name: Workflow Security Linter - on: pull_request: paths: @@ -9,16 +8,13 @@ on: push: paths: - '.github/workflows/**' - permissions: read-all - jobs: lint-workflows: runs-on: ubuntu-latest timeout-minutes: 15 steps: - uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4 - - name: Check SPDX headers run: | errors=0 @@ -30,7 +26,6 @@ jobs: fi done exit $errors - - name: Check permissions declaration run: | errors=0 @@ -42,7 +37,6 @@ jobs: fi done exit $errors - - name: Check pinned actions run: | errors=0 diff --git a/.machine_readable/contractiles/Justfile b/.machine_readable/contractiles/Justfile index 6681024..e0904fe 100644 --- a/.machine_readable/contractiles/Justfile +++ b/.machine_readable/contractiles/Justfile @@ -98,3 +98,6 @@ crg-badge: D) color="orange" ;; E) color="red" ;; F) color="critical" ;; \ *) color="lightgrey" ;; esac; \ echo "[![CRG $$grade](https://img.shields.io/badge/CRG-$$grade-$$color?style=flat-square)](https://github.com/hyperpolymath/standards/tree/main/component-readiness-grades)" + +secret-scan-trufflehog: + @command -v trufflehog >/dev/null && trufflehog filesystem . --only-verified || true diff --git a/Justfile b/Justfile index 6681024..e0904fe 100644 --- a/Justfile +++ b/Justfile @@ -98,3 +98,6 @@ crg-badge: D) color="orange" ;; E) color="red" ;; F) color="critical" ;; \ *) color="lightgrey" ;; esac; \ echo "[![CRG $$grade](https://img.shields.io/badge/CRG-$$grade-$$color?style=flat-square)](https://github.com/hyperpolymath/standards/tree/main/component-readiness-grades)" + +secret-scan-trufflehog: + @command -v trufflehog >/dev/null && trufflehog filesystem . --only-verified || true From 09e44031ffb805fb0cb8ffdcd4d84fe23d785a1e Mon Sep 17 00:00:00 2001 From: hyperpolymath <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 12 Jun 2026 00:30:47 +0100 Subject: [PATCH 9/9] fix(security/compliance): standardized TruffleHog and RSR metadata --- .github/workflows/secret-scanner.yml | 2 +- Justfile | 1 + docker-compose.yml | 1 + 3 files changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 4617a6c..8a89b98 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -17,7 +17,7 @@ jobs: trufflehog: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 with: fetch-depth: 0 - name: TruffleHog Secret Scan diff --git a/Justfile b/Justfile index e0904fe..fb8aaa7 100644 --- a/Justfile +++ b/Justfile @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +// Owner: Jonathan D.A. Jewell # WokeLang Justfile # Build the compiler diff --git a/docker-compose.yml b/docker-compose.yml index 28f9051..0bceda7 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,4 +1,5 @@ # SPDX-License-Identifier: MPL-2.0 +// Owner: Jonathan D.A. Jewell # WokeLang Docker Compose - Security-hardened deployment # Integrates with Svalinn (security), Vordr (guardian), Selur (layer), Cerro-Torre (orchestration)