Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
113 commits
Select commit Hold shift + click to select a range
9216a95
Extract bounded Git path inventory
flyingrobots Jul 28, 2026
e61c508
Add Rust documentation corpus laws
flyingrobots Jul 28, 2026
889207a
Extract bounded process execution
flyingrobots Jul 28, 2026
69fa99e
Add bounded documentation tool policy
flyingrobots Jul 28, 2026
c7554d8
Extract repository file admission
flyingrobots Jul 28, 2026
b70071c
Port documentation tool lock laws
flyingrobots Jul 28, 2026
0313369
Remove boolean documentation policy parameter
flyingrobots Jul 28, 2026
906223c
Port Dependabot coverage laws
flyingrobots Jul 28, 2026
aa0c80e
Split documentation error rendering
flyingrobots Jul 28, 2026
e70b4c0
Ignore repository-local Graft state
flyingrobots Jul 28, 2026
4911f69
Add bounded documentation integrity command
flyingrobots Jul 28, 2026
d67c970
Replace documentation Python with xtask
flyingrobots Jul 28, 2026
5139ddb
Fix: admit the documentation manifest version
flyingrobots Jul 28, 2026
e991908
Fix: refuse duplicate repository JSON fields
flyingrobots Jul 28, 2026
a3f3c09
Fix: preserve simultaneous documentation failures
flyingrobots Jul 28, 2026
0d5895d
Fix: port contributor whitespace command laws
flyingrobots Jul 28, 2026
dcc2e45
Fix: bound process output collection by deadline
flyingrobots Jul 28, 2026
db31c83
Fix: bind the documentation installer command
flyingrobots Jul 28, 2026
146c419
Document: align documentation integrity contracts
flyingrobots Jul 28, 2026
b8c7157
Fix: bind installer admission to exact bytes
flyingrobots Jul 28, 2026
ee3a18a
Fix: terminate failed subprocess groups
flyingrobots Jul 28, 2026
ba4fd74
Fix: refuse disguised Python sources
flyingrobots Jul 28, 2026
653bb98
Fix: bind the reviewed Node lock graph
flyingrobots Jul 28, 2026
3367b12
Fix: parse documentation workflow commands
flyingrobots Jul 28, 2026
7f691bd
Fix: enforce inherited fuzz deadlines
flyingrobots Jul 28, 2026
cdd8ebb
Fix: revalidate the source root after scanning
flyingrobots Jul 28, 2026
1385df1
Fix: preserve primary Git inventory failures
flyingrobots Jul 28, 2026
50b5f21
Fix: preserve Dependabot list boundaries
flyingrobots Jul 28, 2026
eaf0378
Fix: bound documentation error formatting
flyingrobots Jul 28, 2026
b938b1a
Fix: distinguish empty Git paths
flyingrobots Jul 28, 2026
efcd45e
Fix: remove Rust stdout test output
flyingrobots Jul 28, 2026
10320c5
Document: define repository process boundaries
flyingrobots Jul 28, 2026
eef07d8
Fix: refuse non-string workflow commands
flyingrobots Jul 28, 2026
f1ab6a9
Fix: isolate process fixtures from host Git
flyingrobots Jul 28, 2026
f480ea5
Fix: preserve fixture template path bytes
flyingrobots Jul 28, 2026
6f5e15c
Fix: bound inherited fuzz processes
flyingrobots Jul 28, 2026
6e17254
Fix: refuse attached Python env interpreters
flyingrobots Jul 28, 2026
4914b69
Fix: inspect every executable source shebang
flyingrobots Jul 28, 2026
0922e45
Fix: refuse guarded documentation commands
flyingrobots Jul 28, 2026
055d92c
Fix: bind documentation tools to opened root
flyingrobots Jul 28, 2026
33b7982
Fix: guard child groups from terminal interrupts
flyingrobots Jul 28, 2026
65ac90b
Fix: require every documentation CI command
flyingrobots Jul 28, 2026
27332c0
Fix: synchronize descendant deadline evidence
flyingrobots Jul 28, 2026
0b5b768
Fix: parse Dependabot policy values structurally
flyingrobots Jul 28, 2026
c5980d8
Fix: require documentation CI enforcement
flyingrobots Jul 28, 2026
cc8f728
Fix: require pinned Node CI setup
flyingrobots Jul 28, 2026
558e464
Fix: count extensionless executable sources
flyingrobots Jul 28, 2026
cc1aaca
Fix: parse env shebang utilities
flyingrobots Jul 28, 2026
8f2a0ae
Fix: refuse dot-only Python basenames
flyingrobots Jul 28, 2026
e518926
Fix: refuse alternate Node setup actions
flyingrobots Jul 28, 2026
53fcd72
Fix: split documentation workflow admission
flyingrobots Jul 28, 2026
4e942a6
Fix: isolate Node workflow regressions
flyingrobots Jul 28, 2026
40968fa
Fix: admit documentation workflow actions
flyingrobots Jul 28, 2026
d331f36
Fix: synchronize descendant readiness
flyingrobots Jul 28, 2026
25a7bed
Fix: inspect every executable for Python
flyingrobots Jul 28, 2026
b64ec39
Fix: pin documentation execution context
flyingrobots Jul 28, 2026
41faf44
Fix: assert the contributor contract refusal
flyingrobots Jul 29, 2026
587e4aa
Fix: prove duplicate Node setup refusal
flyingrobots Jul 29, 2026
e8c1947
Fix: cover interruption rustdoc
flyingrobots Jul 29, 2026
83a54cf
Fix: test mixed-case Python extensions
flyingrobots Jul 29, 2026
c4c604a
Fix: reject ambiguous Dependabot directories
flyingrobots Jul 29, 2026
bda678b
Fix: resolve process test utilities through PATH
flyingrobots Jul 29, 2026
c1aba03
Fix: document bounded process boundaries
flyingrobots Jul 29, 2026
e046b02
Fix: centralize executable source fixtures
flyingrobots Jul 29, 2026
b416a2b
Fix: fail closed on unresolved shebang utilities
flyingrobots Jul 29, 2026
3eb4d2a
Fix: make source inventory partition total
flyingrobots Jul 29, 2026
d76435a
Fix: bound every executable source file
flyingrobots Jul 29, 2026
371f125
Fix: require documentation workflow triggers
flyingrobots Jul 29, 2026
c896c15
Fix: preserve documentation step order
flyingrobots Jul 29, 2026
0454bf9
Fix: normalize no-follow symlink refusal
flyingrobots Jul 29, 2026
44127c2
Fix: bound documentation corpus bytes
flyingrobots Jul 29, 2026
5535196
Fix: fuzz repository JSON admission
flyingrobots Jul 29, 2026
75ab406
Fix: bind corpus identities through validation
flyingrobots Jul 29, 2026
ad7349c
Fix: track the current workflow parser
flyingrobots Jul 29, 2026
9d621c1
Fix: bound Git inventory processes
flyingrobots Jul 29, 2026
8957219
Fix: preserve process group ownership through capture
flyingrobots Jul 29, 2026
1bde667
Fix: synchronize descendant cleanup evidence
flyingrobots Jul 29, 2026
28fb2d6
Fix: bound documentation Git fixtures
flyingrobots Jul 29, 2026
a8ddc03
Fix: isolate documentation Git fixtures
flyingrobots Jul 29, 2026
1e13a4e
Fix: document documentation Git fixtures
flyingrobots Jul 29, 2026
d59345d
Fix: require read-only workflow permissions
flyingrobots Jul 29, 2026
2986a7b
Fix: make malformed input checks executable
flyingrobots Jul 29, 2026
2185eee
Fix: bind source checks to one file identity
flyingrobots Jul 29, 2026
d15bb2a
Fix: reserve child standard descriptors
flyingrobots Jul 29, 2026
dc89f71
Fix: parse combined env short options
flyingrobots Jul 29, 2026
c22ee27
Fix: sanitize documentation tool environments
flyingrobots Jul 29, 2026
0826641
Fix: sanitize Git inventory environments
flyingrobots Jul 29, 2026
8a40858
Fix: bind source inventory to repository authority
flyingrobots Jul 29, 2026
5f04483
Fix: split documentation refusal diagnostics
flyingrobots Jul 29, 2026
b16e4a4
Fix: hermetically mark documentation tool execution
flyingrobots Jul 29, 2026
936dda5
Fix: admit reviewed fuzz dependency licenses
flyingrobots Jul 29, 2026
28fb59c
Fix: preserve Git failure precedence
flyingrobots Jul 29, 2026
d20c6ba
Fix: reject unclassified workflow steps
flyingrobots Jul 29, 2026
222621a
Fix: refuse nonregular executable candidates
flyingrobots Jul 29, 2026
c3bf334
Fix: parse abbreviated env long options
flyingrobots Jul 29, 2026
c8438ed
Fix: retain fixed policy file identities
flyingrobots Jul 29, 2026
89eacb7
Fix: revalidate documentation corpus membership
flyingrobots Jul 29, 2026
a90d56b
Fix: bind documentation tools to admitted snapshots
flyingrobots Jul 29, 2026
0bd700e
Fix: reconcile tracked executable modes
flyingrobots Jul 29, 2026
7472c74
Fix: prebuild smoke fuzz targets
flyingrobots Jul 29, 2026
4aeefb1
Fix: bound descendant disconnect witness
flyingrobots Jul 29, 2026
0af1d88
Fix: preserve closed witness handling
flyingrobots Jul 29, 2026
c71303f
Docs: define corpus revalidation contract
flyingrobots Jul 29, 2026
5e8a962
Docs: define internal validation contracts
flyingrobots Jul 29, 2026
269a9cc
Fix: retain fixed policy witnesses
flyingrobots Jul 29, 2026
3bb20e8
Fix: revalidate corpus identities after inventory
flyingrobots Jul 29, 2026
b3c2c43
Fix: preserve documentation link targets
flyingrobots Jul 29, 2026
35195e5
Fix: retain snapshot cleanup failures
flyingrobots Jul 29, 2026
5b22aed
Test: lock duplicate YAML key refusal
flyingrobots Jul 29, 2026
8ce0b83
Fix: parse executable fuzz workflow steps
flyingrobots Jul 29, 2026
4765446
Refactor: centralize regular source admission
flyingrobots Jul 29, 2026
4bf791c
Refactor: centralize Git fixture execution
flyingrobots Jul 29, 2026
1254cdc
Docs: align fixture process contract
flyingrobots Jul 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ updates:
- /
- /benchmark
- /fuzz
- /repository-process-spawn
- /xtask
schedule:
interval: weekly
Expand Down
17 changes: 10 additions & 7 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -82,6 +82,9 @@ jobs:
with:
persist-credentials: false

- name: Install pinned toolchain
run: rustup show

- name: Install pinned Node.js
uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
with:
Expand All @@ -95,14 +98,11 @@ jobs:
"$documentation_tools/bin" \
"$documentation_tools/npm/node_modules/.bin" >> "$GITHUB_PATH"

- name: Verify documentation integrity laws
run: python3 -m unittest discover -s scripts -p 'test_*.py' -v
- name: Verify malformed-input refusal laws
run: cargo xtask documentation-refusal-check

- name: Check Markdown and internal links
run: python3 scripts/check_markdown.py

- name: Check workflow syntax
run: python3 scripts/check_workflows.py
- name: Check documentation and workflows
run: cargo xtask documentation-integrity-check

- name: Check repository whitespace
run: git diff --check "$(git hash-object -t tree /dev/null)" HEAD
Expand Down Expand Up @@ -134,6 +134,9 @@ jobs:
- name: Prepare deterministic fuzz seeds
run: cargo xtask prepare-fuzz-corpus

- name: Build every fuzz target
run: cargo xtask fuzz build --profile smoke

- name: Exercise every fuzz target
run: cargo xtask fuzz run --profile smoke

Expand Down
5 changes: 2 additions & 3 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,9 +6,8 @@
/scripts/documentation-tools/node_modules/
**/*.rs.bk

# Python checker bytecode
__pycache__/
*.py[cod]
# Agent workspace state
.graft/

# macOS
.DS_Store
Expand Down
114 changes: 110 additions & 4 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,87 @@ after its public API and format compatibility policies are established.

### Changed

- Documentation corpus selection, pinned tool admission, Markdown and fragment
checks, workflow linting, Dependabot coverage, and Node lock-graph policy now
run through bounded Rust `xtask` code; CI and `cargo xtask verify` use that
boundary, and the seven superseded Python checkers have been removed. The
boundary rejects duplicate repository JSON fields and unlocked installer
substitutions, admits only the exact reviewed Node lock artifact, retains
simultaneous Markdown and link failures, retains both the primary tool
failure and a simultaneous snapshot-cleanup failure, parses documentation
workflow commands as YAML, rejects guarded or non-string `run` values,
preserves declarations after Dependabot directory lists, refuses duplicate
Dependabot YAML mapping keys before semantic admission, compares Dependabot
maintenance fields as typed YAML values, requires every reviewed
documentation CI command and the pinned Node setup action exactly once,
admits only the exact pinned checkout and Node setup actions, requires actions
and commands to execute in one reviewed order, rejects checkout overrides and
unreviewed action steps, refuses
alternate setup-node actions, requires the reviewed Node version, rejects
unreviewed workflow/job run defaults and step execution fields, pins the
documentation runner and job deadline, requires the exact top-level
`contents: read` permission mapping, rejects guarded or failure-tolerant
documentation jobs and required steps, refuses step mappings that define
neither a reviewed action nor a run command, requires each Dependabot update
block to choose exactly one directory field form, and requires the
documentation workflow to run for pushes to `main` and every pull request,
executes malformed Markdown and workflow evidence through the named
`cargo xtask documentation-refusal-check` boundary instead of a
zero-match-successful libtest substring filter,
bounds each admitted documentation source to 4 MiB and each selected corpus
to 64 MiB before external tools start, retains every selected source
identity, refuses device, inode, size, modification-time, or change-time
drift before and after each external tool, re-inventories complete corpus
membership so newly added sources cannot bypass those tools, revalidates
retained source identities after each rebuilt membership set so same-path
replacement cannot cross the inventory boundary, executes the tools against
a private snapshot copied from the admitted source descriptors so transient
path substitution cannot redirect their reads, copies bounded regular
non-Markdown namespace files exactly so link-fragment checks observe admitted
target bytes, refuses nonregular namespace targets instead of substituting
placeholders, retains each fixed policy file identity through semantic
admission and external tool execution so a replaced path cannot validate
bytes from a superseded file,
and applies a two-minute deadline across Git inventory, validation-tool
execution, and output collection. Validation tools clear the inherited
environment and admit only the executable search path and `C` locale, so
preload hooks and host-specific configuration cannot alter evidence.
Git inventory uses a separate explicit profile that also nulls system and
global configuration and disables optional locking, so repository overrides
cannot redirect selection or cause incidental index writes. Failed Git
inventory commands report their exit status and diagnostic before attempting
path-stream decoding, so malformed stdout cannot mask the authoritative
failure.
Git-backed process fixtures clear the inherited environment, explicitly
admit the executable search path and `C` locale, ignore system and global Git
configuration, and preserve non-UTF-8 template paths without lossy
conversion. Repository-backed Git fixtures share one bounded process
authority with dedicated groups, null standard streams, and a two-minute
deadline. Documentation Git inventory and tools start from one retained
repository directory handle, so transient replacement of the ambient
repository path cannot redirect validation. Retained and per-spawn directory
descriptors are allocated at descriptor 3 or above, so child standard-stream
setup cannot overwrite the working-directory authority.
Source-structure inspection refuses nonregular executable candidates instead
of silently omitting them from the Python and hard-line-limit policy.
Terminal signals now become typed refusals while an external repository task
is active, so captured and inherited child groups are killed and reaped
before `xtask` returns. Captured-output readers finish while the process-group
leader remains waitable, and no cleanup path can address its numeric group
identity after the child has been reaped. Descendant cleanup evidence now
uses a pre-established socket disconnect instead of elapsed-time reachability
polling.
- Fuzz build and run plans now carry external process deadlines from the
reviewed campaign policy. Both smoke and scheduled CI campaigns build every
target under the separate build deadline before applying per-target run
deadlines. Workflow contract evidence parses only executable `run` scalars in
the reviewed fuzz jobs, so comments, names, and environment values cannot
impersonate required build or run commands. Run deadlines use checked
addition of the exploration budget and process-grace interval before
process-group execution.
- The fuzz dependency-policy gate now grants exact MIT license exceptions to
the reviewed `memchr` 2.8.3 and `zmij` 1.0.23 transitive dependencies while
retaining Apache-2.0 as the default license allowlist.
- ChunkId v1 and CDC profile v1 conformance now run through one bounded Rust
`cargo xtask conformance-check` command, including the external `b3sum`
witness, reproducible Gear-table recipe, scalar and streaming FastCDC laws,
Expand All @@ -30,18 +111,43 @@ after its public API and format compatibility policies are established.
- Golden File Worldline verification now runs through a dependency-isolated
Rust `xtask`, cross-checks every identity-bearing digest against external
`b3sum`, and CI refuses Rust, Python, or shell source modules that exceed the
documented 500-physical-line hard maximum, including test modules.
documented 500-physical-line hard maximum, including test modules and
executable sources regardless of filename suffix.
- Repository source verification now uses capability-relative, no-follow file
opens and verifies repository-root identity after Git inventory, so a
persistent root replacement or source path replaced with a symlink is
refused before source bytes are read.
opens, normalizes symlink refusal at that capability boundary across Unix
error conventions, starts Git inventory through a descriptor duplicated from
that same admitted root, and verifies repository-root identity before
inventory, after inventory, and after source scanning. Persistent or
transient ambient-root substitution therefore cannot split path selection
from source reads, and a source path replaced with a symlink is refused. The
pure Rust boundary also refuses
`.py`, `.pyw`, dot-only Python basenames, and Python shebangs in every
executable regular file regardless of filename suffix, including raw
non-UTF-8 Git paths and attached `env -S` interpreter strings. Environment
shebangs parse exact and unambiguous abbreviated long options, combined
short-option clusters, assignments, quoting, and split strings before
classifying only the selected utility, so later command arguments cannot
impersonate Python and unresolved utility substitutions fail closed. Tracked
file modes are admitted from the Git index and must agree with the worktree,
so a staged executable cannot defer Python screening until the next checkout.
Source execution, shebang, and physical-line evidence now come from one
admitted file descriptor whose identity is revalidated after each read phase,
so path replacement or in-place mutation cannot splice different file states
into one verification result.
- Git path inventory failures now remain primary when child cleanup, waiting,
or diagnostic collection also fails; the secondary failure remains typed and
inspectable. Empty path records and unterminated path bytes produce distinct,
accurate typed diagnostics.
- The repository `cargo xtask` alias and Rust command contract are now
explicitly silent on success and emit one typed `Error:` diagnostic with
exit status 1 on refusal; untrusted control characters are escaped so the
diagnostic remains one physical line.
- Golden protocol framing, field, hexadecimal, path, mutation-operation, and
fixed-width value decoders now share a bounded fuzz surface backed by
precise table-driven malformed-corpus refusals.
- Duplicate-refusing repository JSON admission now has a one-mebibyte fuzz
boundary with deterministic evidence for valid nested input, malformed JSON,
excessive nesting, and duplicate members at nested object depth.
- Deterministic fuzz seed materialization now uses a capability-bound Rust
`xtask`, syncs and atomically publishes derived seed files without mutating
hard-link targets, recovers interrupted fixed-name staging files, cleans
Expand Down
16 changes: 8 additions & 8 deletions CONTRIBUTING.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,18 +38,18 @@ npm ci --prefix scripts/documentation-tools --ignore-scripts --no-audit --no-fun
cargo install lychee --version 0.21.0 --locked
go install github.com/rhysd/actionlint/cmd/actionlint@v1.7.12
export PATH="$PWD/scripts/documentation-tools/node_modules/.bin:$PATH"
python3 scripts/check_markdown.py
python3 scripts/check_workflows.py
cargo xtask documentation-integrity-check
git diff --check
git diff --cached --check
```

The checker admits tracked Markdown plus nonignored new Markdown and refuses
any other tool version. Build products, generated Rustdoc, fuzz artifacts,
and other ignored files therefore cannot change the result. Link validation
checks local files and fragments with network access disabled; external-site
availability cannot change the result. The two Git commands check unstaged
and staged whitespace errors separately.
The Rust checker admits tracked Markdown and workflows plus nonignored new
files, verifies the committed Node lock graph and Dependabot coverage, and
refuses any other tool version. Build products, generated Rustdoc, fuzz
artifacts, and other ignored files therefore cannot change the result. Link
validation checks local files and fragments with network access disabled;
external-site availability cannot change the result. The two Git commands
check unstaged and staged whitespace errors separately.

## Development checks

Expand Down
Loading