Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 4 additions & 9 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -1,9 +1,4 @@
# Code Owners

# Default: All contributors with write access are code owners
* @metadatastician

# For specific paths, add explicit owners below
# Example:
# /src/* @team-lead
# /docs/* @docs-maintainer
# SPDX-License-Identifier: MPL-2.0
# Solo-maintained hyperpolymath repo: no owner lines by policy.
# See hyperpolymath/standards CODEOWNERS-POLICY.adoc (Rule 1).
# Sole-maintainer review is moot; SPDX headers carry attribution.
17 changes: 17 additions & 0 deletions 0-AI-MANIFEST.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -137,3 +137,20 @@
(version-current "2.0.0")
(version-next "2.1.0")
(status "active-development")))

<!-- BEGIN requires-initialisation -->

## PRIORITY ACTION — this repository is not fully initialised

16 substitution token(s) still have no value. **Read
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
else here** — it lists every outstanding token, what it means, and which
files it belongs in.

Do not fabricate values for them, and do not delete the sections that
contain them to quiet a gate. They are unfilled because they need a
decision, not because they were overlooked. Resolve what you legitimately
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when
Comment on lines 139 to +153

@gitar-bot gitar-bot Bot Aug 5, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Bug: Appended markdown breaks 0-AI-MANIFEST.a2ml S-expression parsing

The requires-initialisation block (lines 141-156) is raw markdown/HTML appended after the closing ))) of the (manifest …) form. The repo's own A2ML parser reads the whole file and rejects any trailing content: Parser::parse_all() returns Err("extra tokens after manifest") at src/a2ml/mod.rs:639, and its comment handling (src/a2ml/mod.rs:612) only treats # (at line start) and ; as comments — <!-- … --> and bare prose lines like "16 substitution token(s)…" are neither comments nor valid S-expressions. As a result the manifest that agents read on entry now fails to parse. Move the notice inside the manifest as an S-expression node, or prefix every added line with # and drop the <!-- --> delimiters.

Was this helpful? React with 👍 / 👎

nothing outstanding remains.

<!-- END requires-initialisation -->
47 changes: 0 additions & 47 deletions ARCHITECTURE.md

This file was deleted.

2 changes: 1 addition & 1 deletion CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -189,7 +189,7 @@ Eight PRs landed in one cohort closing the v2.5.5 ROADMAP section, a v3.0.0 item
- **rsr-template scaffolding gaps filled** (#96): LICENSE flipped from
AGPL-3.0 body to MPL-2.0 (matching SPDX headers + Cargo.toml +
README.adoc); CODE_OF_CONDUCT.md placeholders instantiated
(`{{CONDUCT_EMAIL}}` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →
(`j.d.a.jewell@open.ac.uk` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →

@gitar-bot gitar-bot Bot Aug 5, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: Token fill corrupted quoted references in CHANGELOG and audit

The substitution pass replaced placeholder tokens that were being quoted/discussed as literal text, corrupting two records. CHANGELOG.md:192 now reads j.d.a.jewell@open.ac.uk → j.d.a.jewell@open.ac.uk (was {{CONDUCT_EMAIL}} → j.d.a.jewell@open.ac.uk), a nonsensical self-mapping that loses what CONDUCT_EMAIL originally resolved to. pillar-audit-2026-04-15.md:20 now lists panic-attack, {{DEPS}}, {{BUILD_OUTPUT_PATH}} as "Template Residue found" — the audit finding recorded {{PACKAGE_NAME}} as residue, so replacing it both loses the finding and makes the report self-contradictory. Restore the original literal token text in both historical/audit entries; these are records of past state, not live placeholders.

Was this helpful? React with 👍 / 👎

`panic-attack maintainers`, `{{RESPONSE_TIME}}` → `48 hours`,
`language-bridges` → `panic-attack`); bug_report/feature_request
issue templates Rust-toolchain-aware; empty `custom.md` removed;
Expand Down
174 changes: 174 additions & 0 deletions REQUIRES_INITIALISATION.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,174 @@
<!-- SPDX-License-Identifier: CC-BY-SA-4.0 -->

# REQUIRES INITIALISATION

**This repository is not finished being set up.** 16 substitution token(s) across 5 file(s) still have no value.

## Why this is not already done

This repo was created from `hyperpolymath/rsr-template-repo`. The mint
(`just repo-init`) fills every token that has a single mechanical answer —
owner, repo, author, dates, licence, branch — and it has done so here.

The tokens below are the ones it *deliberately cannot* answer. They need a
decision or a fact that exists only in your head: what this project is for,
what command builds it, which port the service listens on, whether a PGP key
is held at all. The template's own token vocabulary says as much — you cannot
sensibly answer "required invariants" in a thirty-second bootstrap.

They were left **visibly unfilled on purpose**. The alternatives were both
worse: inventing plausible values would put confident falsehoods into a
security policy and an architecture document, and silently deleting the
sections would hide the fact that a decision is owed. A visible gap is
honest; a fabricated answer is not.

## Do not delete this file until every item below is resolved

This file is the only marker that the work is outstanding. Deleting it early
does not finish the setup, it just conceals it — and the next person or agent
to arrive will reasonably assume the repo is complete.

- **If you are a person:** delete this file yourself once the last item is done.
- **If you are an agent:** resolve what you legitimately can, leave the rest,
and delete this file only when no token below remains anywhere in the tree.
Do not delete it to make a gate go green.

Re-running the estate top-up tool will remove this file automatically once
nothing is outstanding, so the safest way to finish is to fix the tokens and
let the check confirm it.

## What is needed, and where it goes

### `{{BUILD_CMD}}`

The exact command that builds this project.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{BUILD_OUTPUT_PATH}}`

Where the build artefact lands.

Appears in:

- `docs/reports/audit/pillar-audit-2026-04-15.md`

### `{{CONDUCT_TEAM}}`

Name of the conduct body. If there is no committee, rewrite the sentence rather than substituting a plural noun into 'a {{CONDUCT_TEAM}} member'.

Appears in:

- `CHANGELOG.md`

### `{{CONSUMER1}}`

A downstream repo that consumes this one.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{CONSUMER2}}`

A second downstream consumer.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{DEP1}}`

First named dependency, in .machine_readable/INTENT.contractile.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{DEP2}}`

Second named dependency, in .machine_readable/INTENT.contractile.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{DEPS}}`

Prose summary of runtime/build dependencies.

Appears in:

- `docs/reports/audit/pillar-audit-2026-04-15.md`

### `{{LANG_STACK}}`

The language stack, in prose.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{MONOREPO_OR_STANDALONE}}`

Literally 'monorepo' or 'standalone'.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{MUST_INVARIANTS}}`

The invariants this project guarantees. Not answerable in a bootstrap; it is the point of the repo.

Appears in:

- `QUICKSTART-DEV.adoc`

### `{{ONE_PARAGRAPH_ANTI_PURPOSE}}`

A paragraph on what this deliberately is NOT for.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{ONE_PARAGRAPH_PURPOSE}}`

A paragraph on what this is for.

Appears in:

- `.machine_readable/INTENT.contractile`

### `{{PROJECT_UNIQUE_STRENGTH}}`

What this does that its alternatives do not.

Appears in:

- `.machine_readable/agent_instructions/methodology.a2ml`

### `{{RESPONSE_TIME}}`

Initial-response SLA for a security or conduct report. Promise only what a solo maintainer can actually meet.

Appears in:

- `CHANGELOG.md`

### `{{TEST_CMD}}`

The exact command that runs its tests.

Appears in:

- `QUICKSTART-DEV.adoc`

---

Generated by the estate top-up pass. Rationale and the governing rulings are
in `hyperpolymath/standards`; the token vocabulary is
`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.
2 changes: 1 addition & 1 deletion docs/reports/audit/pillar-audit-2026-04-15.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Repository: /var/mnt/eclipse/repos/panic-attacker
- Claims: 49 languages, 196 tests, v2.1.0.
- Actual: Matches implementation files and badges.
- **Template Residue**:
- `{{PACKAGE_NAME}}`, `{{DEPS}}`, `{{BUILD_OUTPUT_PATH}}` found in `QUICKSTART-MAINTAINER.adoc`.
- `panic-attack`, `{{DEPS}}`, `{{BUILD_OUTPUT_PATH}}` found in `QUICKSTART-MAINTAINER.adoc`.

## Verdict
- **CRG Grade**: B
Expand Down