From ee76e7cd7439f2fb92ebc73b540b32373279f401 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 00:31:26 +0100 Subject: [PATCH 1/2] chore(rsr): stop requiring or blessing Nix where policy retired it Governance / Guix packaging policy rejects a flake.nix-only repo, yet three standards surfaces still asked for Nix: - .claude/CLAUDE.md listed "Fallback: Nix (flake.nix)". Now: Nix is retired; package with guix.scm or a working Containerfile. - rsr-audit.sh category 1 scored flake.nix / flake.lock / description, and the reproducibility check credited "Nix flakes". Both now check guix.scm. bun.lock replaces flake.lock as pinned-versions evidence. - ux-test-harness passed on flake.nix present. It now warns on it. template-capability-gates.toml keeps its flake.nix row for now. It is a canon artefact pinned in canon.lock (Gate A), so it goes through the change procedure: #1125. hypatia-rules/rsr-self-compliance.a2ml is left untouched (A2ML is retired; not edited in either direction). Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP --- .claude/CLAUDE.md | 2 +- rhodium-standard-repositories/rsr-audit.sh | 18 +++++++++--------- .../ux-test-harness/run-ux-test.sh | 6 +++--- 3 files changed, 13 insertions(+), 13 deletions(-) diff --git a/.claude/CLAUDE.md b/.claude/CLAUDE.md index 2b0a1d52b..06e7f3e02 100644 --- a/.claude/CLAUDE.md +++ b/.claude/CLAUDE.md @@ -219,7 +219,7 @@ Both are FOSS with independent governance (no Big Tech). ### Package Management - **Primary**: Guix (guix.scm) -- **Fallback**: Nix (flake.nix) +- **Nix**: retired — `flake.nix` is not accepted by Governance / Guix packaging policy; a repo with no `guix.scm` packages through a working Containerfile instead - **JS deps**: **Bun** (`package.json` + `bun.lock`); `bunx ` to run one-off tooling ### Documentation Format diff --git a/rhodium-standard-repositories/rsr-audit.sh b/rhodium-standard-repositories/rsr-audit.sh index c84c941e9..d0d0b1687 100755 --- a/rhodium-standard-repositories/rsr-audit.sh +++ b/rhodium-standard-repositories/rsr-audit.sh @@ -204,10 +204,10 @@ check_command_exists() { audit_category_1_infrastructure() { log_section "Category 1: Foundational Infrastructure" - # Nix flakes - check_file_exists "flake.nix" "Nix flake configuration present" - check_file_exists "flake.lock" "Nix flake lockfile present" - check_file_contains "flake.nix" "description" "flake.nix has description field" + # Guix (Nix is retired estate-wide) + check_file_exists "guix.scm" "Guix package definition present" + check_file_contains "guix.scm" "(name " "guix.scm declares a package name" + check_file_contains "guix.scm" "license" "guix.scm declares a license" # Justfile check_file_exists "justfile" "Justfile present" @@ -407,9 +407,9 @@ audit_category_4_architecture() { # Reversibility (Git-based) check "Reversibility: Git repository" test -d "$REPO_PATH/.git" - # Build reproducibility (Nix) - if [[ -f "$REPO_PATH/flake.nix" ]]; then - check "Reproducible builds: Nix flakes" true + # Build reproducibility (Guix) + if [[ -f "$REPO_PATH/guix.scm" ]]; then + check "Reproducible builds: Guix" true fi # Documentation of architecture @@ -612,9 +612,9 @@ audit_category_9_lifecycle() { check_file_contains "CHANGELOG.md" "\\[.*\\]" "CHANGELOG uses version brackets" fi - # Pinned versions (Cargo.lock, flake.lock, etc.) + # Pinned versions (Cargo.lock, bun.lock, etc.) local has_lockfile=false - if [[ -f "$REPO_PATH/Cargo.lock" ]] || [[ -f "$REPO_PATH/flake.lock" ]] || [[ -f "$REPO_PATH/mix.lock" ]]; then + if [[ -f "$REPO_PATH/Cargo.lock" ]] || [[ -f "$REPO_PATH/bun.lock" ]] || [[ -f "$REPO_PATH/mix.lock" ]]; then log_success "Dependency lockfile present (pinned versions)" PASSED_CHECKS=$((PASSED_CHECKS + 1)) has_lockfile=true diff --git a/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh b/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh index 57e2ad9c2..3ed932f7f 100755 --- a/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh +++ b/rhodium-standard-repositories/ux-test-harness/run-ux-test.sh @@ -138,15 +138,15 @@ MR="$REPO_DIR/.machine_readable" [ -f "$MR/ADJUST.contractile" ] && record "adjust_contractile" "pass" "ADJUST.contractile present" \ || record "adjust_contractile" "warn" "ADJUST.contractile missing" -# --- Phase 5: Guix/Nix environment --- +# --- Phase 5: Guix environment (Nix is retired) --- echo "" >&2 echo "Phase 5: Reproducible environment" >&2 [ -f "$REPO_DIR/guix.scm" ] && record "guix" "pass" "guix.scm present" \ || record "guix" "warn" "guix.scm missing" -[ -f "$REPO_DIR/flake.nix" ] && record "nix" "pass" "flake.nix present" \ - || record "nix" "warn" "flake.nix missing" +[ -f "$REPO_DIR/flake.nix" ] && record "nix" "warn" "flake.nix present (Nix is retired; remove it)" \ + || record "nix" "pass" "no flake.nix" # --- Phase 6: LLM warmup --- echo "" >&2 From 72bd3b1e561e589453bbfd993ceec92025b37604 Mon Sep 17 00:00:00 2001 From: "Jonathan D.A. Jewell" <6759885+hyperpolymath@users.noreply.github.com> Date: Fri, 2 Oct 2026 00:40:47 +0100 Subject: [PATCH 2/2] chore(registry): regenerate after rsr-audit.sh change Generator output only (bash scripts/build-registry.sh): one source_hash line for rhodium-standard-repositories, whose rsr-audit.sh this PR edits. No hand edits. Clears Registry + topology in sync and the three scorecard passes (component-readiness-grades/M3, estate-constitution/M2, neurosym-a2ml/M5) whose check is build-registry.sh --check. Co-Authored-By: Claude Opus 5.5 Claude-Session: https://claude.ai/code/session_016L7GFo3yGQ2vK9YgKL2wsP --- .machine_readable/REGISTRY.a2ml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.machine_readable/REGISTRY.a2ml b/.machine_readable/REGISTRY.a2ml index 008927d55..01c85cef7 100644 --- a/.machine_readable/REGISTRY.a2ml +++ b/.machine_readable/REGISTRY.a2ml @@ -207,7 +207,7 @@ name = "RSR — Rhodium Standard Repositories" stream = "governance" home = "rhodium-standard-repositories/" canonical_doc = "rhodium-standard-repositories/README.adoc" -source_hash = "sha256:dcd870a92e82159d764a26bf6ca4f37d2cdbf9c418561dc51fc5bc2ab28279f9" +source_hash = "sha256:8bcf1e52445efa2c7f9c83850ca98f7a92190230b76f897d8442c5a377e74c39" route = "the repository-compliance standard every repo is graded against" [[spec]]