Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 3 additions & 13 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,14 +1,4 @@
# SPDX-License-Identifier: MPL-2.0
# CODEOWNERS - Define code review assignments
# See: https://docs.github.com/en/repositories/managing-your-repositorys-settings-and-features/customizing-your-repository/about-code-owners
#
# Replace hyperpolymath with your GitHub username or team

# Default owners for everything
* @hyperpolymath

# Security-sensitive files require explicit review
SECURITY.md @hyperpolymath
.github/workflows/ @hyperpolymath
Trustfile.a2ml @hyperpolymath
.machine_readable/ @hyperpolymath
# Solo-maintained hyperpolymath repo: no owner lines by policy.
# See hyperpolymath/standards CODEOWNERS-POLICY.adoc (Rule 1).
# Sole-maintainer review is moot; SPDX headers carry attribution.
2 changes: 1 addition & 1 deletion .machine_readable/contractiles/dust/Dustfile.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -54,7 +54,7 @@ to new repositories.
- description: No references to krl in generic template files
- run: test -z "$(grep -r 'krl' machine-readable-design/ 2>/dev/null)"
- severity: warning
- notes: Generic templates should use {{PROJECT_NAME}} or similar placeholders
- notes: Generic templates should use KRL — Knot Resolution Language or similar placeholders

### version-sync-checked
- description: Version in canonical-directory-structure matches .machine_readable/contractiles
Expand Down
17 changes: 17 additions & 0 deletions 0-AI-MANIFEST.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -129,3 +129,20 @@ KRL/
## ATTESTATION PROOF

**"I have read the AI manifest. All machine-readable content (state files, anchors, policies, bot directives, contractiles, AI guides) is located in `.machine_readable/` ONLY, community metadata is in `.github/`, and `AUDIT.adoc` constrains release and publication claims. I will not create duplicate files in the root directory or make optimistic claims that bypass the audit gate."**

<!-- BEGIN requires-initialisation -->

## PRIORITY ACTION — this repository is not fully initialised

11 substitution token(s) still have no value. **Read
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
else here** — it lists every outstanding token, what it means, and which
files it belongs in.

Do not fabricate values for them, and do not delete the sections that
contain them to quiet a gate. They are unfilled because they need a
decision, not because they were overlooked. Resolve what you legitimately
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when
nothing outstanding remains.

<!-- END requires-initialisation -->
16 changes: 8 additions & 8 deletions QUICKSTART-MAINTAINER.adoc
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
// SPDX-License-Identifier: CC-BY-SA-4.0
// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk>
// Template: QUICKSTART-MAINTAINER.adoc — packaging, deploying, and maintaining
// Replace rsr-template-repo, {{PACKAGE_NAME}}, {{DEPS}} with actuals
// Replace rsr-template-repo, krl, {{DEPS}} with actuals

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: PACKAGE_NAME filled but project name 'rsr-template-repo' left literal

This edit replaced {{PACKAGE_NAME}} with krl in install paths, but the file still hard-codes the template's own name rsr-template-repo in the title (line 5), overview (line 11) and the clone/build commands (lines 22-24, 50). The result is contradictory guidance: maintainers are told to build/clone rsr-template-repo yet install artefacts under krl. The edited comment on line 4 ("Replace rsr-template-repo, krl, {{DEPS}} with actuals") even lists the now-resolved value krl as something still to replace. Replace the remaining rsr-template-repo literals with krl and drop krl from the replace-list comment.

Was this helpful? React with 👍 / 👎

= rsr-template-repo — Quick Start for Platform Maintainers
:toc:
:toclevels: 2
Expand Down Expand Up @@ -66,10 +66,10 @@ Files installed:
| `$PREFIX/bin/`
| Executables

| `$PREFIX/share/{{PACKAGE_NAME}}/`
| `$PREFIX/share/krl/`
| Data files, assets

| `$PREFIX/share/doc/{{PACKAGE_NAME}}/`
| `$PREFIX/share/doc/krl/`
| Documentation

| `$PREFIX/share/applications/`
Expand All @@ -81,9 +81,9 @@ Files installed:

== Configuration

Default config location: `$XDG_CONFIG_HOME/{{PACKAGE_NAME}}/config.toml`
Default config location: `$XDG_CONFIG_HOME/krl/config.toml`

Fallback: `$HOME/.config/{{PACKAGE_NAME}}/config.toml`
Fallback: `$HOME/.config/krl/config.toml`

== Health Checks

Expand All @@ -103,7 +103,7 @@ just build-release
just install --prefix=/usr/local
----

Or via OPSM: `opsm update {{PACKAGE_NAME}}`
Or via OPSM: `opsm update krl`

== Security Notes

Expand All @@ -118,8 +118,8 @@ For deploying multiple instances (e.g., different users or tenants):

[source,bash]
----
just install --prefix=/opt/{{PACKAGE_NAME}}-instance1 --config=/etc/{{PACKAGE_NAME}}/instance1.toml
just install --prefix=/opt/{{PACKAGE_NAME}}-instance2 --config=/etc/{{PACKAGE_NAME}}/instance2.toml
just install --prefix=/opt/krl-instance1 --config=/etc/krl/instance1.toml
just install --prefix=/opt/krl-instance2 --config=/etc/krl/instance2.toml
----

Each instance has isolated config, data, and logs.
Expand Down
144 changes: 144 additions & 0 deletions REQUIRES_INITIALISATION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,144 @@
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# REQUIRES INITIALISATION

**This repository is not finished being set up.** 11 substitution token(s) across 6 file(s) still have no value.

## Why this is not already done

This repo was created from `hyperpolymath/rsr-template-repo`. The mint
(`just repo-init`) fills every token that has a single mechanical answer —
owner, repo, author, dates, licence, branch — and it has done so here.

The tokens below are the ones it *deliberately cannot* answer. They need a
decision or a fact that exists only in your head: what this project is for,
what command builds it, which port the service listens on, whether a PGP key
is held at all. The template's own token vocabulary says as much — you cannot
sensibly answer "required invariants" in a thirty-second bootstrap.

They were left **visibly unfilled on purpose**. The alternatives were both
worse: inventing plausible values would put confident falsehoods into a
security policy and an architecture document, and silently deleting the
sections would hide the fact that a decision is owed. A visible gap is
honest; a fabricated answer is not.

## Do not delete this file until every item below is resolved

This file is the only marker that the work is outstanding. Deleting it early
does not finish the setup, it just conceals it — and the next person or agent
to arrive will reasonably assume the repo is complete.

- **If you are a person:** delete this file yourself once the last item is done.
- **If you are an agent:** resolve what you legitimately can, leave the rest,
and delete this file only when no token below remains anywhere in the tree.
Do not delete it to make a gate go green.

Re-running the estate top-up tool will remove this file automatically once
nothing is outstanding, so the safest way to finish is to fix the tokens and
let the check confirm it.

## Do these first

`.github/settings.yml` is applied to the forge by a GitHub App. An
unfilled token here can be written into the repository's real name or
description. This has fired before in this estate: illegal braces were
collapsed to dashes and a repo was renamed `-REPO-`, which then read as
deleted.

- `{{DESCRIPTION}}` — One-line description used in .github/settings.yml. HIGH PRIORITY: settings.yml is applied by a GitHub App, so an unfilled token here can be written into forge metadata verbatim.

## What is needed, and where it goes

### `{{BUILD_CMD}}`

The exact command that builds this project.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{BUILD_OUTPUT_PATH}}`

Where the build artefact lands.

Appears in:

- `QUICKSTART-MAINTAINER.adoc`

### `{{DEPS}}`

Prose summary of runtime/build dependencies.

Appears in:

- `QUICKSTART-MAINTAINER.adoc`

### `{{DESCRIPTION}}`

One-line description used in .github/settings.yml. HIGH PRIORITY: settings.yml is applied by a GitHub App, so an unfilled token here can be written into forge metadata verbatim.

Appears in:

- `.github/settings.yml`

### `{{LANG_STACK}}`

The language stack, in prose.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{MUST_INVARIANTS}}`

The invariants this project guarantees. Not answerable in a bootstrap; it is the point of the repo.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{PGP_KEY_URL}}`

Public URL the PGP key can be fetched from. Same caveat as PGP_FINGERPRINT.

Appears in:

- `.well-known/security.txt`

### `{{PROJECT_DOMAIN}}`

Taxonomy value for the subject domain.

Appears in:

- `.machine_readable/6a2/anchor/ANCHOR.a2ml`

### `{{PROJECT_KIND}}`

Taxonomy value (library, service, tool, lab…).

Appears in:

- `.machine_readable/6a2/anchor/ANCHOR.a2ml`

### `{{PROJECT_UNIQUE_STRENGTH}}`

What this does that its alternatives do not.

Appears in:

- `.machine_readable/bot_directives/methodology.a2ml`

### `{{TEST_CMD}}`

The exact command that runs its tests.

Appears in:

- `QUICKSTART-DEV.adoc`

---

Generated by the estate top-up pass. Rationale and the governing rulings are
in `hyperpolymath/standards`; the token vocabulary is
`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.
Loading