Skip to content

chore: fill derivable placeholders, drop false ARCHITECTURE, surface the rest - #225

Closed
hyperpolymath wants to merge 1 commit into
mainfrom
chore/estate-topup
Closed

chore: fill derivable placeholders, drop false ARCHITECTURE, surface the rest#225
hyperpolymath wants to merge 1 commit into
mainfrom
chore/estate-topup

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Automated estate top-up. Nothing here invents a value.

Filled — every token with one mechanical answer (owner, repo, forge, author, dates, project name, main branch). Identity from the git remote, dates from the clock, name from the README H1.

Not filled, on purposeSECURITY_EMAIL (two competing addresses exist in the estate), RESPONSE_TIME, CONDUCT_TEAM (substitutes into "a {{CONDUCT_TEAM}} member", which is not English), WEBSITE, PROJECT_DESCRIPTION, LANG_STACK. More than one defensible answer exists, and a confident wrong value is worse than a visible gap.

DeletedARCHITECTURE.md where it is byte-identical to the 346-copy estate boilerplate (blob 607e3d8c). Those 33 lines describe a src/ tests/ docs/ scripts/ config/ tree this repo does not have. Matched by hash, so a genuinely written ARCHITECTURE can never be caught by it.

CODEOWNERS — the solo form from standards/CODEOWNERS-POLICY.adoc Rule 1, which forbids a catch-all where the only owner is the sole maintainer. templates/CODEOWNERS contradicts that policy; the policy is versioned, dated and resolves standards#55, so it wins. Genuine co-owners (Rule 2) are untouched.

SurfacedREQUIRES_INITIALISATION.md plus a priority action in 0-AI-MANIFEST.a2ml, listing every remaining token, what it means, which files it belongs in, why it was not done already, and that it is to be deleted only when the work is genuinely complete.

Built from a fresh clone of origin/main, never a local checkout — several of those are dirty and hold unpushed commits.

🤖 Generated with Claude Code

…the rest

Estate top-up pass. Three separate things, none of which invents a value.

FILLED — every token with a single mechanical answer: OWNER, REPO, FORGE,
PROJECT, PACKAGE_NAME, PROJECT_NAME, AUTHOR, AUTHOR_EMAIL, CONDUCT_EMAIL,
AUTHOR_FIRST/LAST/INITIALS, CURRENT_YEAR, CURRENT_DATE, DATE, MAIN_BRANCH.
Identity comes from the git remote, dates from the clock, project name from the
README H1 where there is one.

Deliberately NOT filled, because more than one defensible answer exists and a
confident wrong value is worse than a visible gap: SECURITY_EMAIL (two competing
addresses are in use across the estate), RESPONSE_TIME, CONDUCT_TEAM (which
substitutes into "a {{CONDUCT_TEAM}} member", not English), WEBSITE,
PROJECT_DESCRIPTION, LANG_STACK.

DELETED — ARCHITECTURE.md, where it is byte-identical to the 346-copy estate
boilerplate (blob 607e3d8). Those 33 lines describe a src/ tests/ docs/
scripts/ config/ tree that this repo does not have, so the file is not merely
uninformative, it is wrong. Genuinely written ARCHITECTURE files are matched by
hash and left alone. No file beats a confidently false one.

CODEOWNERS — rewritten to the solo form mandated by
hyperpolymath/standards CODEOWNERS-POLICY.adoc Rule 1, which forbids a catch-all
line where the only owner is the sole maintainer. The estate's own
templates/CODEOWNERS contradicts that policy; the policy is versioned, dated and
resolves standards#55, so it wins. Files naming a genuine co-owner are Rule 2
and are untouched. Note @hyperpolymath and @metadatastician are the same person,
so a file naming the other account is a copy artifact that silently routed
review requests to the wrong account.

SURFACED — REQUIRES_INITIALISATION.md, and a priority action in
0-AI-MANIFEST.a2ml. Tokens that need a decision no script can make are left
visibly unfilled rather than faked or quietly deleted. The marker says what each
one is, which files it belongs in, why it was not done already, and that it must
be deleted only once the work is genuinely finished.
@sonarqubecloud

sonarqubecloud Bot commented Aug 5, 2026

Copy link
Copy Markdown

Comment on lines 55 to 57
ran: `.well-known/security.txt` still had template placeholders
(`{{SECURITY_EMAIL}}`, `{{PGP_KEY_URL}}`, `{{FORGE}}`,
(`{{SECURITY_EMAIL}}`, `{{PGP_KEY_URL}}`, `github.com`,
`{{WEBSITE}}`), and `ffi/zig/src/main.zig` plus

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Quality: Token substitution corrupted a quoted placeholder list in closure report

This sentence is a historical record quoting the literal placeholder tokens that a test caught in .well-known/security.txt. The mechanical top-up rewrote {{FORGE}} to github.com inside that quoted list, so it now reads that github.com "was a template placeholder" alongside the still-unfilled {{SECURITY_EMAIL}}, {{PGP_KEY_URL}}, {{WEBSITE}} — which is false and self-contradictory, and undermines the PR's own "never invent a value" intent for a document the file itself calls a "canonical written record." Restore the literal token: change github.com back to `{{FORGE}}` (and exclude this quoted list from substitution).

Was this helpful? React with 👍 / 👎

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ This PR is blocked due to unresolved code review findings.

Configure merge blocking · Maintainers can dismiss this review.

@gitar-bot

gitar-bot Bot commented Aug 5, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ⚠️ Changes requested 0 resolved / 1 findings

Estate top-up automation fills derivable placeholders and drops boilerplate ARCHITECTURE files, but token substitution corrupted a quoted placeholder list in the closure report.

⚠️ Quality: Token substitution corrupted a quoted placeholder list in closure report

📄 docs/reports/maintenance/2026-05-25-phase-0-closure.adoc:55-57

This sentence is a historical record quoting the literal placeholder tokens that a test caught in .well-known/security.txt. The mechanical top-up rewrote {{FORGE}} to github.com inside that quoted list, so it now reads that github.com "was a template placeholder" alongside the still-unfilled {{SECURITY_EMAIL}}, {{PGP_KEY_URL}}, {{WEBSITE}} — which is false and self-contradictory, and undermines the PR's own "never invent a value" intent for a document the file itself calls a "canonical written record." Restore the literal token: change github.com back to `{{FORGE}}` (and exclude this quoted list from substitution).

🤖 Prompt for agents
Code Review: Estate top-up automation fills derivable placeholders and drops boilerplate ARCHITECTURE files, but token substitution corrupted a quoted placeholder list in the closure report.

1. ⚠️ Quality: Token substitution corrupted a quoted placeholder list in closure report
   Files: docs/reports/maintenance/2026-05-25-phase-0-closure.adoc:55-57

   This sentence is a historical record quoting the *literal placeholder tokens* that a test caught in `.well-known/security.txt`. The mechanical top-up rewrote `{{FORGE}}` to `github.com` inside that quoted list, so it now reads that `github.com` "was a template placeholder" alongside the still-unfilled `{{SECURITY_EMAIL}}`, `{{PGP_KEY_URL}}`, `{{WEBSITE}}` — which is false and self-contradictory, and undermines the PR's own "never invent a value" intent for a document the file itself calls a "canonical written record." Restore the literal token: change `github.com` back to `` `{{FORGE}}` `` (and exclude this quoted list from substitution).

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Important

Your trial ends in 5 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@hyperpolymath

Copy link
Copy Markdown
Owner Author

Closing in favour of a reworked substituter — hyperpolymath/standards#590.

This sweep filled {{TOKEN}} placeholders by plain text replacement across every file. Across the 90 repositories reviewed it drew 141 findings, and one is severe:

sed "s/{{PROJECT_NAME}}/$name/g"  →  sed "s/Conative Gating/$name/g"
sed -e "s/{{DATE}}/$DATE/g"       →  sed -e "s/2026-08-05/$DATE/g"

Those are the scripts whose job is to perform template substitution. Filling the left-hand side of their own sed expressions means template application silently stops working — and the breakage stays invisible until someone mints a repository from the template and gets a half-substituted tree.

Four further shapes came out of the same cause:

  • release.sh no longer substitutes {{DATE}} into release notes
  • just's own {{ARGS}} reported as an unfilled token, leaving repos permanently "not initialised"
  • instructional docs rewritten to "Replace laminar, laminar, {{DEPS}} with actuals"
  • documentation describing placeholders had its examples filled in

The rule plain replacement cannot express: a placeholder is sometimes a value to fill and sometimes the subject being discussed. standards#590 encodes that distinction and is tested against this exact corruption (9/9, the first three cases reproducing it).

Nothing here is lost — the placeholder filling will be redone with that tool. Closing rather than fixing forward because repairing 289 branches individually would repeat the mistake at the same scale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant