Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 3 additions & 33 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,34 +1,4 @@
# SPDX-License-Identifier: MPL-2.0
# CODEOWNERS - Define code review assignments for GitHub
# See: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners

# Default: sole maintainer for all files
* @hyperpolymath

# Security-sensitive files require explicit ownership
SECURITY.md @hyperpolymath
.github/workflows/ @hyperpolymath
.machine_readable/ @hyperpolymath
contractiles/ @hyperpolymath

# License files
LICENSE @hyperpolymath
LICENSES/ @hyperpolymath

# Configuration
.gitignore @hyperpolymath
.github/ @hyperpolymath

# Documentation
README* @hyperpolymath
CONTRIBUTING* @hyperpolymath
CODE_OF_CONDUCT* @hyperpolymath
GOVERNANCE* @hyperpolymath
MAINTAINERS* @hyperpolymath
CHANGELOG* @hyperpolymath
ROADMAP* @hyperpolymath

# Build and CI
Justfile @hyperpolymath
Makefile @hyperpolymath
*.sh @hyperpolymath
# Solo-maintained hyperpolymath repo: no owner lines by policy.
# See hyperpolymath/standards CODEOWNERS-POLICY.adoc (Rule 1).
# Sole-maintainer review is moot; SPDX headers carry attribution.
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ let methodology_guard = {
description = "STATE.a2ml must not contain template placeholders",
severity = "warning",
file = ".machine_readable/6a2/STATE.a2ml",
reject_patterns = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"],
reject_patterns = ["{{PLACEHOLDER}}", "JANUSKEY", "rsr-template-repo"],

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Bug: Placeholder substitution corrupted STATE.a2ml guard patterns

The top-up pass substituted the project name into the guards' own reject lists, turning the {{PROJECT}} detection token into the literal JANUSKEY. This has two bad effects: (1) the guards no longer detect an unfilled {{PROJECT}} placeholder in STATE.a2ml — the very template-staleness case they exist to catch now passes silently; (2) they will now reject/warn on any legitimate STATE.a2ml that contains the string JANUSKEY (e.g. an uppercased project name in a heading or field), producing false positives. Restore the meta-token {{PROJECT}} in both reject-if-contains and reject_patterns — it is a guard vocabulary term, not a value to be filled.

Fix 1: methodology.a2ml line 104: keep the placeholder token, not the substituted name.
reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]
  • Apply fix
Fix 2: methodology-guard.k9.ncl line 64: keep the placeholder token, not the substituted name.
reject_patterns = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"],
  • Apply fix

Check a box to apply a fix or reply for a change | Was this helpful? React with 👍 / 👎

},

coverage_updated = {
Expand Down
17 changes: 17 additions & 0 deletions 0-AI-MANIFEST.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -114,3 +114,20 @@ After reading this file, demonstrate understanding by stating:
- **Maintained By:** [YOUR-NAME/ORG]
- **License:** MPL-2.0
- **Protocol:** https://github.com/hyperpolymath/0-ai-gatekeeper-protocol

<!-- BEGIN requires-initialisation -->

## PRIORITY ACTION — this repository is not fully initialised

7 substitution token(s) still have no value. **Read
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
else here** — it lists every outstanding token, what it means, and which
files it belongs in.

Do not fabricate values for them, and do not delete the sections that
contain them to quiet a gate. They are unfilled because they need a
decision, not because they were overlooked. Resolve what you legitimately
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when
nothing outstanding remains.

<!-- END requires-initialisation -->
16 changes: 8 additions & 8 deletions QUICKSTART-MAINTAINER.adoc
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
// Template: QUICKSTART-MAINTAINER.adoc — packaging, deploying, and maintaining
// Replace januskey, {{PACKAGE_NAME}}, {{DEPS}} with actuals
// Replace januskey, januskey, {{DEPS}} with actuals
= januskey — Quick Start for Platform Maintainers
:toc:
:toclevels: 2
Expand Down Expand Up @@ -66,10 +66,10 @@ Files installed:
| `$PREFIX/bin/`
| Executables

| `$PREFIX/share/{{PACKAGE_NAME}}/`
| `$PREFIX/share/januskey/`
| Data files, assets

| `$PREFIX/share/doc/{{PACKAGE_NAME}}/`
| `$PREFIX/share/doc/januskey/`
| Documentation

| `$PREFIX/share/applications/`
Expand All @@ -81,9 +81,9 @@ Files installed:

== Configuration

Default config location: `$XDG_CONFIG_HOME/{{PACKAGE_NAME}}/config.toml`
Default config location: `$XDG_CONFIG_HOME/januskey/config.toml`

Fallback: `$HOME/.config/{{PACKAGE_NAME}}/config.toml`
Fallback: `$HOME/.config/januskey/config.toml`

== Health Checks

Expand All @@ -103,7 +103,7 @@ just build-release
just install --prefix=/usr/local
----

Or via OPSM: `opsm update {{PACKAGE_NAME}}`
Or via OPSM: `opsm update januskey`

== Security Notes

Expand All @@ -118,8 +118,8 @@ For deploying multiple instances (e.g., different users or tenants):

[source,bash]
----
just install --prefix=/opt/{{PACKAGE_NAME}}-instance1 --config=/etc/{{PACKAGE_NAME}}/instance1.toml
just install --prefix=/opt/{{PACKAGE_NAME}}-instance2 --config=/etc/{{PACKAGE_NAME}}/instance2.toml
just install --prefix=/opt/januskey-instance1 --config=/etc/januskey/instance1.toml
just install --prefix=/opt/januskey-instance2 --config=/etc/januskey/instance2.toml
----

Each instance has isolated config, data, and logs.
Expand Down
102 changes: 102 additions & 0 deletions REQUIRES_INITIALISATION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,102 @@
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# REQUIRES INITIALISATION

**This repository is not finished being set up.** 7 substitution token(s) across 3 file(s) still have no value.

## Why this is not already done

This repo was created from `hyperpolymath/rsr-template-repo`. The mint
(`just repo-init`) fills every token that has a single mechanical answer —
owner, repo, author, dates, licence, branch — and it has done so here.

The tokens below are the ones it *deliberately cannot* answer. They need a
decision or a fact that exists only in your head: what this project is for,
what command builds it, which port the service listens on, whether a PGP key
is held at all. The template's own token vocabulary says as much — you cannot
sensibly answer "required invariants" in a thirty-second bootstrap.

They were left **visibly unfilled on purpose**. The alternatives were both
worse: inventing plausible values would put confident falsehoods into a
security policy and an architecture document, and silently deleting the
sections would hide the fact that a decision is owed. A visible gap is
honest; a fabricated answer is not.

## Do not delete this file until every item below is resolved

This file is the only marker that the work is outstanding. Deleting it early
does not finish the setup, it just conceals it — and the next person or agent
to arrive will reasonably assume the repo is complete.

- **If you are a person:** delete this file yourself once the last item is done.
- **If you are an agent:** resolve what you legitimately can, leave the rest,
and delete this file only when no token below remains anywhere in the tree.
Do not delete it to make a gate go green.

Re-running the estate top-up tool will remove this file automatically once
nothing is outstanding, so the safest way to finish is to fix the tokens and
let the check confirm it.

## What is needed, and where it goes

### `{{BUILD_CMD}}`

The exact command that builds this project.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{BUILD_OUTPUT_PATH}}`

Where the build artefact lands.

Appears in:

- `QUICKSTART-MAINTAINER.adoc`

### `{{DEPS}}`

Prose summary of runtime/build dependencies.

Appears in:

- `QUICKSTART-MAINTAINER.adoc`

### `{{LANG_STACK}}`

The language stack, in prose.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{MUST_INVARIANTS}}`

The invariants this project guarantees. Not answerable in a bootstrap; it is the point of the repo.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{PROJECT_UNIQUE_STRENGTH}}`

What this does that its alternatives do not.

Appears in:

- `.machine_readable/bot_directives/methodology.a2ml`

### `{{TEST_CMD}}`

The exact command that runs its tests.

Appears in:

- `QUICKSTART-DEV.adoc`

---

Generated by the estate top-up pass. Rationale and the governing rulings are
in `hyperpolymath/standards`; the token vocabulary is
`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.
Loading