Skip to content

fix(governance): normalize licensing and project state - #116

Merged
hyperpolymath merged 2 commits into
mainfrom
arena/01a1037d-vcl-ut
Oct 3, 2026
Merged

hyperpolymath merged 2 commits into
mainfrom
arena/01a1037d-vcl-ut

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Summary

Implements the repository-side work tracked by #53. This is a draft pending explicit owner confirmation of the license policy and branch-protection change.

  • Records ci(codeql): cron weekly→monthly (cut 3, standards#288) #51 and feat(abi): Tier-2 Idris bindings + retire legacy Foreign + close L10 transitive cycle #52 as reconciled: both issues are closed; the monthly CodeQL schedule and Tier-2/L10/proof-corpus work are present in the current tree.
  • Normalizes live license metadata to the policy already declared by this repository: MPL-2.0 for software/configuration and CC-BY-SA-4.0 for human documentation. GitHub Licensee currently recognizes the public main license as MPL-2.0. Removed the unused AGPL license text; no source file currently declares AGPL. Corrected invalid PMPL SPDX headers, package/release metadata, and misleading legacy license wording. The ethical-use exhibits now expressly state they are non-binding guidance and do not modify MPL-2.0.
  • Adds a closed license-policy contract and fail-closed checker: REUSE 6.2.0 lint, one inline SPDX declaration, path-specific documentation/software rules, allowed-ID checks, Cargo metadata checks, root license and Zenodo checks. Wires it into just license-check, pre-commit, the K9/Must contract, and the CI check license-policy.
  • Adds explicit CC-BY-SA headers to untagged human documentation and missing MPL headers to code/configuration manifests; fixes REUSE copyright gaps.
  • Rewrites .machine_readable/STATE.a2ml to reflect the actual VCL-UT implementation, proof corpus, limitations, and next actions; removes the byte-identical 6a2/STATE.a2ml mirror. Documents the distinct roles of the four contractile locations and removes the remaining template-state wording from the AI entry point.

Validation

  • REUSE 6.2.0 reuse lint — pass (0 missing, invalid, deprecated, or unused licenses).
  • scripts/check-license-policy.sh — pass; negative test confirmed the documentation path rule rejects MPL-2.0.
  • Strict .githooks/validate-a2ml.sh — pass (121 files, 0 errors/warnings).
  • pre-commit validate-config, shell syntax, TOML/JSON/YAML parsing, and git diff --check — pass.
  • Full pre-commit execution is currently blocked by the existing https://github.com/hyperpolymath/a2ml-pre-commit remote returning “Repository not found”. Strict K9 validation also flags the existing container/deploy.k9.ncl envelope-format mismatch. Cargo, Idris2, and Nickel are not installed in this sandbox, so build/proof corpus execution was not possible here.

Owner actions before this can be merged/closed

  1. Confirm that MPL-2.0 code + CC-BY-SA-4.0 documentation is the intended ruling (rather than retaining an AGPL core). The current repository headers, Cargo metadata, policy docs, and GitHub Licensee result point to that choice; the orphan AGPL text was removed accordingly.
  2. After this check appears on a PR, make the license-policy status check required in branch protection/rulesets. GitHub reports its exact check context as license-policy; this session's integration cannot read or change branch-protection settings (HTTP 403).
  3. Optionally provide the correct A2ML pre-commit repository/ref so the full pre-commit suite can be run locally; the new local license hook itself is configured and independently passes.

This PR intentionally does not auto-close #53; owner confirmation and the required-check setting are still needed for full conclusion.

GitHub CI status (observed 2026-10-03)

The PR-head license-policy job passes in REUSE compliance run 37153345024; the A2ML validation job also passes here (the corresponding job failed on main before this PR). Parse Gate, E2E/property tests, CodeQL, OpenSSF, and the dedicated Hypatia scan passed.

Several other red checks are pre-existing on main and reproduce on this PR: K9 contract validation (PR, main) rejects container/deploy.k9.ncl because its metadata envelope differs from the validator's expected literal K9!/top-level pedigree format; the Governance workflow linter (PR, main) fails at “Check SPDX headers + permissions”; Static Analysis Gate / Hypatia critical findings (PR, main); Rust CI / Clippy (PR, main); and Cargo Audit (PR, main). These are not attributed to this change; the Actions log archive endpoint returned EOF when detailed failed-step logs were requested. The K9 validator mismatch is documented rather than suppressed or “fixed” by weakening the gate.

At the time checked, Proof Corpus remained in progress and the large Backend Matrix remained queued, so this is not a claim that the full CI suite completed. Maintainers should resolve or explicitly disposition the pre-existing red checks as appropriate for branch protection, then wait for the proof/matrix jobs.

Additional maintainer follow-up

  1. Resolve the pre-existing K9 envelope mismatch without a blanket ignore (either teach the validator the deployed component_pedigree / metadata.magic_number / trust_level representation with regression coverage, or migrate the deployment config to the canonical format). Also triage the baseline governance, Hypatia, Clippy, and Cargo Audit failures if they are required checks.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 128 files, which is 28 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 5e7feedc-263e-4f55-af29-0fa3e7be9131
📥 Commits

Reviewing files that changed from the base of the PR and between cc943a3 and 70a5fa4.

📒 Files selected for processing (128)
  • .github/0.1-AI-MANIFEST.a2ml
  • .github/CODE_OF_CONDUCT.md
  • .github/CONTRIBUTING.md
  • .github/DIRECTORY.adoc
  • .github/SECURITY.md
  • .github/funding.yml
  • .github/pull_request_template.md
  • .github/workflows/governance.yml
  • .github/workflows/hypatia-scan.yml
  • .github/workflows/reuse.yml
  • .github/workflows/scorecard.yml
  • .machine_readable/6a2/STATE.a2ml
  • .machine_readable/MUST.contractile
  • .machine_readable/README.adoc
  • .machine_readable/STATE.a2ml
  • .machine_readable/ai/AI.a2ml
  • .machine_readable/ai/PLACEHOLDERS.adoc
  • .machine_readable/ai/README.adoc
  • .machine_readable/anchors/README.adoc
  • .machine_readable/compliance/license-policy.toml
  • .machine_readable/configs/README.adoc
  • .machine_readable/contractiles/README.adoc
  • .machine_readable/contractiles/_base.ncl
  • .machine_readable/contractiles/must/Mustfile.a2ml
  • .machine_readable/contractiles/trust/Trustfile.a2ml
  • .machine_readable/policies/README.adoc
  • .machine_readable/scripts/forge/README.adoc
  • .machine_readable/scripts/forge/git-cleanup.sh
  • .machine_readable/scripts/lifecycle/README.adoc
  • .machine_readable/scripts/verification/README.adoc
  • .machine_readable/self-validating/examples/setup-repo.k9.ncl
  • .pre-commit-config.yaml
  • .zenodo.json
  • ARCHITECTURE.adoc
  • CHANGELOG.adoc
  • CODE_OF_CONDUCT.adoc
  • CONTRIBUTING.adoc
  • CONTRIBUTING.md
  • GOVERNANCE.adoc
  • Justfile
  • LICENSES/AGPL-3.0-or-later.txt
  • MAINTAINERS
  • README.adoc.invariants.adoc
  • REUSE.toml
  • SECURITY.adoc
  • SECURITY.md
  • audits/assail-classifications.a2ml
  • contractile.just
  • contractiles/README.adoc
  • contractiles/trust/Trustfile.a2ml
  • docs/QUICKSTART-MAINTAINER.adoc
  • docs/README.adoc
  • docs/RSR_OUTLINE.adoc
  • docs/STATE-VISUALIZER.adoc
  • docs/attribution/CITATIONS.adoc
  • docs/attribution/CODEOWNERS.adoc
  • docs/attribution/README.adoc
  • docs/decisions/README.adoc
  • docs/developer/README.adoc
  • docs/governance/CRG-CRITERIA.adoc
  • docs/governance/MAINTENANCE-CHECKLIST.a2ml
  • docs/governance/MAINTENANCE-CHECKLIST.adoc
  • docs/governance/README.adoc
  • docs/governance/SOFTWARE-DEVELOPMENT-APPROACH.adoc
  • docs/governance/TSDM.adoc
  • docs/governance/audit/README.adoc
  • docs/governance/audit/compliance/README.adoc
  • docs/governance/audit/effects/README.adoc
  • docs/governance/audit/systems/README.adoc
  • docs/governance/maintenance/README.adoc
  • docs/governance/maintenance/adaptive/README.adoc
  • docs/governance/maintenance/corrective/README.adoc
  • docs/governance/maintenance/perfective/README.adoc
  • docs/governance/planning/README.adoc
  • docs/governance/planning/could/README.adoc
  • docs/governance/planning/must/README.adoc
  • docs/governance/planning/should/README.adoc
  • docs/legal/EXHIBIT-A-ETHICAL-USE.txt
  • docs/legal/EXHIBIT-B-QUANTUM-SAFE.txt
  • docs/onboarding/llm-warmup-dev.adoc
  • docs/onboarding/llm-warmup-user.adoc
  • docs/practice/README.adoc
  • docs/proof-debt.adoc
  • docs/reports/README.adoc
  • docs/reports/compliance/README.adoc
  • docs/reports/maintenance/README.adoc
  • docs/reports/performance/README.adoc
  • docs/reports/quality/README.adoc
  • docs/reports/security/README.adoc
  • docs/standards/README.adoc
  • docs/status/PROOF-NEEDS.adoc
  • docs/status/TEST-NEEDS.adoc
  • docs/tech-debt-2026-05-26.adoc
  • docs/theory/README.adoc
  • docs/theory/computing/README.adoc
  • docs/theory/formalisms/README.adoc
  • docs/theory/mathematics/README.adoc
  • docs/theory/ontologies/README.adoc
  • docs/theory/other/README.adoc
  • docs/theory/socio-technical/README.adoc
  • docs/vcl-total-grammar.ebnf
  • docs/whitepapers/README.adoc
  • docs/whitepapers/academic/README.adoc
  • docs/whitepapers/arcvix-10-level-query-safety.bib
  • docs/whitepapers/arcvix-10-level-query-safety.tex
  • docs/whitepapers/industry/README.adoc
  • docs/whitepapers/outreach/README.adoc
  • docs/wikis/README.adoc
  • examples/0.1-AI-MANIFEST.a2ml
  • examples/README.adoc
  • features/README.adoc
  • features/boj-server/README.adoc
  • features/panic-attacker/README.adoc
  • features/ssg/README.adoc
  • guix.scm
  • mise.toml
  • scripts/check-license-policy.sh
  • verification/README.adoc
  • verification/benchmarks/README.adoc
  • verification/coverage/README.adoc
  • verification/fuzzing/README.adoc
  • verification/safety_case/README.adoc
  • verification/simulations/README.adoc
  • verification/tests/0.2-AI-MANIFEST.a2ml
  • verification/tests/README.adoc
  • verification/traceability/README.adoc
  • www/.well-known/ai.txt
  • www/.well-known/humans.txt

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
@hyperpolymath
hyperpolymath marked this pull request as ready for review October 3, 2026 21:10
@hyperpolymath
hyperpolymath merged commit 9546eda into main Oct 3, 2026
185 of 190 checks passed
@hyperpolymath
hyperpolymath deleted the arena/01a1037d-vcl-ut branch October 3, 2026 21:10
hyperpolymath added a commit that referenced this pull request Oct 4, 2026
…nic family (#117)

Closes #49.

## What #49 asked, and where it stands

Re-audited all three items against the current tree (the gate has
evolved since the issue was filed in June — it now scopes checks 2–3 to
production code and accepts `// SAFETY:`-justified FFI, both correct
refinements):

| Issue item | Disposition |
|---|---|
| 5 missing SPDX headers | **Done** (landed earlier, e.g. #116).
Verified: 0 missing. |
| 20 `unsafe` in `src/` | **10 remain, all justified**: each carries a
contiguous `// SAFETY:` comment; `attest` and `recompute-wasm` (the only
crates with `unsafe`) both set
`#![deny(clippy::undocumented_unsafe_blocks)]`. These are `#[no_mangle]
extern "C"` FFI trust boundaries, which *cannot* be written without
`unsafe` — elimination is impossible, documentation is the correct
posture, and the gate enforces it. |
| 61 `unwrap`/`expect` in `src/` | **All remaining hits are test-only**:
every one sits inside a `#[cfg(test)]` module or under `src/*/tests/`
(plus `testing.expect` in Zig test files, out of the Rust gate's scope
by design). Production count is 0. |

The gate already passed 6/6 — but the audit found one genuine hole in
the same SPARK-grade family that the gate didn't cover: a production
`panic!`.

## Changes

* `src/interface/lsp/src/main.rs` — the request dispatcher `panic!`'d
(crashing the whole server) when a request's method matched but its
params failed JSON deserialization. It now answers JSON-RPC `Invalid
params` (-32602) naming the method and the error, via a new
three-outcome `Cast` type that rescues the request id before `extract()`
consumes it. Also adds `#![deny(clippy::unwrap_used,
clippy::expect_used)]`, mirroring `vclt-gate`, and dedupes error
responses through a new `send_error` helper.
* `tests/aspect_tests.sh` — check 3 now also rejects
`panic!`/`unreachable!`/`todo!`/`unimplemented!` in production `src/`,
matching the documented `vcltotal-parse` SPARK-grade lint set (the
estate pattern per `parse/src/lib.rs`).
* `src/interface/parse/src/parser.rs` — one doc comment reworded
(`panic!` → `panic`, meaning unchanged) so the textual gate stays
precise.
* `CHANGELOG.adoc` — `[Unreleased] / Fixed` entries.

## Validation

* `bash tests/aspect_tests.sh` → **6 passed, 0 failed** (before and
after; the gate is now strictly stronger).
* Negative test: temporarily injecting `panic!("boom")` into production
`src/` makes the new check FAIL as intended; removed afterwards.
* `bash -n` on the script and `git diff --check` clean.
* Note: `vcltotal-lsp` is not built by standalone CI (it needs the
echidna sibling path-dep; only the estate e2e layout compiles it), and
this sandbox has no Rust toolchain — so the `main.rs` change was
verified by inspection against the [lsp-server 0.7 API on
docs.rs](https://docs.rs/lsp-server/0.7.7/lsp_server/struct.Request.html)
(`Request { pub id, pub method, pub params }`, `Request: Clone`,
`extract` signature, `ExtractError::{MethodMismatch, JsonError { method,
error }}` shapes all confirmed). Only previously-unused-but-public API
surface (`req.id.clone()`) is introduced; every other construct mirrors
adjacent existing code.

## Suggested follow-up (not in this PR)

Per-crate `#![deny(clippy::unwrap_used, clippy::expect_used,
clippy::panic, …)]` on the remaining lib crates (`lsp`, `dap`, `fmt`,
`lint`, `attest`, `echidna-client`) with `allow`s in their test modules,
mirroring `vcltotal-parse`. Deliberately left out: it needs `cargo
clippy` validation per crate, which isn't available in this sandbox —
and #49 itself warns against blind passes.

Co-authored-by: arena-agent <297053741+arena-agent@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Checkpoint 2026-06-05: branch reconciliation (#51/#52) + licence normalisation + provable gate + STATE rewrite

1 participant