Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,8 @@ jobs:
include:
- language: javascript-typescript
build-mode: none
- language: actions
build-mode: none

steps:
- name: Checkout
Expand Down
10 changes: 4 additions & 6 deletions .hypatia-ignore
Original file line number Diff line number Diff line change
Expand Up @@ -12,9 +12,7 @@ web/Main.res:cicd_rules/banned_language_file
web/MainTest.res:cicd_rules/banned_language_file
web/Server.res:cicd_rules/banned_language_file

# Frozen archive (playground/experiments/_attic/, see its FROZEN.md): retired
# demo experiments kept for design lineage, not shipped code. The ArangoDB demo
# uses a placeholder DB password ("rootpassword"), not a real credential β€” this
# is a false-positive that re-fires on every scan. (Disposition keep-frozen vs
# delete is a checkpoint decision; until then, exempt the false-positive.)
playground/experiments/_attic/database-demos/arangodb-demo/queries.js:code_safety/js_hardcoded_secret
# False-positive: rsr_check.rs IS the RSR compliance checker β€” its "unsafe"
# matches are string literals in its own detector (it scans other files for the
# literal `unsafe {`), not real unsafe blocks. No unsafe code exists here.
crates/jtv-cli/src/rsr_check.rs:code_safety/unsafe_block
5 changes: 3 additions & 2 deletions .machine_readable/6a2/STATE.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ project = "julia-the-viper"
version = "0.0.1"
last-updated = "2026-06-15"
status = "active"
session = "2026-06-15 β€” bookkeeping/tidying consolidation: lake build green (8 libs, 0 sorry/admit/axiom, 0 vacuity, 0 lint warnings); 4 stray branches resolved (2 stale-merged deleted + codeql weekly->monthly cron folded + estate-standardization salvaged: CODEOWNERS + 17 wiki SPDX headers); ADR-0007 gains the graded-comonad/tropical-grade characterization note; PMPL-1.0 vs MPL-2.0 header discrepancy flagged for governance decision (gap-006); number-system-semantics + v2 (c) bridge remain queued"
session = "2026-06-15 β€” bookkeeping/tidying consolidation: lake build green (8 libs, 0 sorry/admit/axiom, 0 vacuity, 0 lint warnings); 4 stray branches resolved (2 stale-merged flagged for UI deletion β€” git push --delete returned 403 β€” + codeql weekly->monthly cron folded + estate-standardization salvaged: CODEOWNERS + 17 wiki SPDX headers); ADR-0007 gains the graded-comonad/tropical-grade characterization note; PMPL-1.0 vs MPL-2.0 header discrepancy flagged for governance decision (gap-006); number-system-semantics + v2 (c) bridge remain queued"

[project-context]
name = "Julia The Viper"
Expand Down Expand Up @@ -82,7 +82,8 @@ sessions = [
{ date = "2026-06-13", subject = "PR #26 merged: Lean suite repaired (JtvEcho.neg_injective; orphan JtvExtended wired in β†’ 8 libs); Echo a structural type-system gate over BOTH reverse{} and reversible{}->tok (checked first, before type inference); fixed pre-existing failing reverse-block echo test; root-cause Rust-CI revival (rust-ci/coverage hashFiles-in-job-if startup failure since ~05-27); clippy lint cleared; workflow pins+timeouts; *.jtv/*.pata eol=lf" },
{ date = "2026-06-13", subject = "PR #27 merged: de-vacuated 8 True-typed believeme theorems (string_not_executable, confluence, no_vulnerable_constructs, no_reverse_joinpoints, dataExpr_no_control, data_evaluation_secure, control_data_noninterference, rev_composition) into real compiled statements; NO-VACUITY + Int-only-scope recorded in capability matrix" },
{ date = "2026-06-13", subject = "ADR-0007: addition-only mandate (absolute; ×/÷ generated, not primitive); subtraction = reverse addition (not 2s-complement/not primitive); Harvard-in-von-Neumann AOLD insertability; shortest-path-to-equality + Echo lineage + cross-system routing; additive-algebra → reversibility-tier (group→Safe / cancellative→Neutral / idempotent→Breaking; Echo's own join is idempotent)" },
{ date = "2026-06-15", subject = "Bookkeeping/tidying consolidation: confirmed lake build green (8 libs); cleared all Lean unused-variable lint warnings (_-prefix); resolved 4 stray remote branches (deleted 2 stale-merged changelog/tech-debt whose content is already on main; folded codeql weekly->monthly cron; salvaged CODEOWNERS + 17 wiki SPDX headers from estate-standardization-20260607, dropped its superseded pre-repair Lean drafts + old contractiles); ADR-0007 graded-comonad/tropical-grade characterization note; flagged PMPL-1.0 vs MPL-2.0 discrepancy (gap-006)" }
{ date = "2026-06-15", subject = "Bookkeeping/tidying consolidation: confirmed lake build green (8 libs); cleared all Lean unused-variable lint warnings (_-prefix); resolved 4 stray remote branches (flagged 2 stale-merged changelog/tech-debt for UI deletion β€” content already on main, git 403 blocked programmatic delete; folded codeql weekly->monthly cron; salvaged CODEOWNERS + 17 wiki SPDX headers from estate-standardization-20260607, dropped its superseded pre-repair Lean drafts + old contractiles); ADR-0007 graded-comonad/tropical-grade characterization note; flagged PMPL-1.0 vs MPL-2.0 discrepancy (gap-006)" },
{ date = "2026-06-15", subject = "Security-hygiene clean (post-#33): triaged the Hypatia 67-finding report β€” informational (--exit-zero, gate passed), none originating from #33. Added CodeQL actions language; DELETED the frozen playground/experiments/_attic archive (17 files incl. stray npm package.json + a Julia demo), clearing both criticals + several highs at the source, with all dangling refs cleaned (deno.json excludes, bot_directives/hypatia.a2ml, .hypatia-ignore, playground README/Justfile); documented rsr_check.rs unsafe_block as a verified false-positive (Hypatia matched the RSR checker's own detection string). Deferred to a deliberate governance-hardening pass: secret-scanner.yml creation, scorecard job-perms, curl|sh install hardening." }
]

[design-artefact-locations]
Expand Down
13 changes: 7 additions & 6 deletions .machine_readable/bot_directives/hypatia.a2ml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@

[metadata]
repo = "julia-the-viper"
last-updated = "2026-06-14"
last-updated = "2026-06-15"
owner = "hyperpolymath"

[scanner]
Expand All @@ -16,13 +16,14 @@ workflow = ".github/workflows/hypatia-scan.yml"
# ============================================================

[[accepted-findings]]
rule = "code_safety/js_hardcoded_secret"
path = "playground/experiments/_attic/database-demos/arangodb-demo/queries.js"
rule = "code_safety/unsafe_block"
path = "crates/jtv-cli/src/rsr_check.rs"
status = "verified-false-positive"
reason = """
Placeholder DB password ("rootpassword") in the FROZEN demo archive
(playground/experiments/_attic/, see its FROZEN.md) β€” not a real
credential and not shipped code. Exempted in .hypatia-ignore.
rsr_check.rs IS the RSR compliance checker; its `unsafe` matches are string
literals in its own detector (it scans other files for the literal `unsafe {`),
not real unsafe blocks. No unsafe code exists in this file. Exempted in
.hypatia-ignore.
"""

[[accepted-findings]]
Expand Down
12 changes: 3 additions & 9 deletions deno.json
Original file line number Diff line number Diff line change
@@ -1,17 +1,11 @@
{
"lint": {
"exclude": [
"playground/experiments/_attic/"
]
"exclude": []
},
"fmt": {
"exclude": [
"playground/experiments/_attic/"
]
"exclude": []
},
"test": {
"exclude": [
"playground/experiments/_attic/"
]
"exclude": []
}
}
20 changes: 2 additions & 18 deletions playground/Justfile
Original file line number Diff line number Diff line change
Expand Up @@ -92,22 +92,6 @@ clean:
@find . -type f -name "*.pyc" -delete 2>/dev/null || true
@echo "Clean complete"

# ==============================================================================
# LEGACY (QUARANTINED - per ANCHOR scope policy)
# ==============================================================================

# Run legacy algorithm demos (frozen, no expansion)
_legacy-algorithms:
@echo "WARNING: Legacy code (frozen per ANCHOR scope policy)"
@echo ""
@cd experiments/_attic/algorithms && python3 sorting.py 2>/dev/null || echo "(algorithms not available)"

# List legacy experiments (frozen)
_legacy-list:
@echo "Legacy Experiments (frozen in _attic/):"
@echo ""
@find experiments/_attic -maxdepth 2 -name "README.md" -exec dirname {} \; 2>/dev/null || echo " (none)"

# ==============================================================================
# REPOSITORY MANAGEMENT
# ==============================================================================
Expand Down Expand Up @@ -150,8 +134,8 @@ scope:
@echo " - Conformance tests and corpora"
@echo ""
@echo "LEGACY QUARANTINE:"
@echo " - All non-JTV experiments in experiments/_attic/"
@echo " - No expansion allowed"
@echo " - Non-JTV experiments removed (formerly in experiments/_attic/)"
@echo " - No new non-JTV experiments allowed"
@echo ""
@echo "FORBIDDEN:"
@echo " - General polyglot experiments"
Expand Down
5 changes: 2 additions & 3 deletions playground/README.adoc
Original file line number Diff line number Diff line change
Expand Up @@ -55,7 +55,6 @@ jtv-playground/
β”‚ β”œβ”€β”€ tests/corpus/ # Test corpus (valid/invalid)
β”‚ β”œβ”€β”€ repl/ # REPL prototype
β”‚ └── tools/ # Development tools
β”œβ”€β”€ experiments/_attic/ # Legacy experiments (frozen)
β”œβ”€β”€ .machine_read/ # Control plane files
β”œβ”€β”€ Justfile # Command interface
└── Mustfile # Mandatory checks
Expand All @@ -75,8 +74,8 @@ Per `.machine_read/ANCHOR.scope-arrest.2026-01-01.scm`:

=== Legacy (Frozen)

* All non-JTV experiments are in `experiments/_attic/`
* No new features or expansion permitted
* Non-JTV experiments have been removed (formerly quarantined in `experiments/_attic/`)
* No new non-JTV experiments or expansion permitted

=== Forbidden

Expand Down
43 changes: 0 additions & 43 deletions playground/experiments/_attic/FROZEN.md

This file was deleted.

Loading
Loading