Skip to content

docs: add faithful RUST-SPARK-STANCE.adoc#11

Merged
hyperpolymath merged 1 commit into
mainfrom
docs/rust-spark-stance-2026-05-18
May 18, 2026
Merged

docs: add faithful RUST-SPARK-STANCE.adoc#11
hyperpolymath merged 1 commit into
mainfrom
docs/rust-spark-stance-2026-05-18

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Adds a faithful RUST-SPARK-STANCE.adoc for verisimdb.

The Idris2+Zig ABI seam (src/abi/{Types,Layout,Foreign}.idr + ffi/zig/) was present but carried no stance doc — the silent-regress risk flagged in the estate audit (status "DESIGNED-ONLY"). This doc records the seam, the SPARK/Ada admission path, and honest gaps (unfilled {{PROJECT}} placeholders in ffi/zig/src/main.zig; Idris2 not wired into CI; owed octad/drift invariants) without overclaiming.

Adversarial proof-escape census: 6 corpus files (src/abi, debugger/src/abi), all %default total, zero escapes (no believe_me/assert_total/postulate/idris_crash/sorry/admit).

Refs hyperpolymath/standards#124 (not Closes)

🤖 Generated with Claude Code

Records the existing Idris2+Zig ABI seam (src/abi/*.idr + ffi/zig/) and
SPARK/Ada admission path honestly. Seam was present but undocumented
(silent-regress risk per estate audit). No proof escapes in the corpus;
honest gaps (Zig template placeholders, Idris2 not in CI, owed octad
invariants) recorded explicitly.

Refs hyperpolymath/standards#124

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@hyperpolymath
hyperpolymath merged commit fc43b8f into main May 18, 2026
6 of 9 checks passed
@github-actions

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 120 issues detected

Severity Count
🔴 Critical 18
🟠 High 64
🟡 Medium 38

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Stale AI task file -- delete or move to docs/",
    "type": "stale",
    "file": "SONNET-TASKS.md",
    "action": "delete",
    "rule_module": "root_hygiene",
    "severity": "high"
  },
  {
    "reason": "Issue in quality.yml",
    "type": "missing_workflow",
    "file": "quality.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Issue in security-policy.yml",
    "type": "missing_workflow",
    "file": "security-policy.yml",
    "action": "create",
    "rule_module": "workflow_audit",
    "severity": "medium"
  },
  {
    "reason": "Action hyperpolymath/standards/.github/workflows/governance-reusable.yml@main needs attention",
    "type": "unpinned_action",
    "file": "governance.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "Action hyperpolymath/panic-attacker/.github/workflows/scan-and-report.yml@main needs attention",
    "type": "unpinned_action",
    "file": "security-scan.yml",
    "action": "pin_sha",
    "rule_module": "workflow_audit",
    "severity": "high"
  },
  {
    "reason": "binary_to_term without :safe option -- deserialization attack (1 occurrences, CWE-502)",
    "type": "elixir_send_unsanitised",
    "file": "/home/runner/work/verisimdb/verisimdb/lib/verisim/query_cache.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "binary_to_term without :safe option -- deserialization attack (1 occurrences, CWE-502)",
    "type": "elixir_send_unsanitised",
    "file": "/home/runner/work/verisimdb/verisimdb/lib/verisim/query_planner_config.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "String.to_existing_atom with user input exhausts atom table -- use to_existing_atom (1 occurrences, CWE-400)",
    "type": "elixir_atom_from_user",
    "file": "/home/runner/work/verisimdb/verisimdb/elixir-orchestration/lib/verisim/query/vql_type_checker.ex",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "high"
  },
  {
    "reason": "HTTP URL in code -- use HTTPS for non-localhost (1 occurrences, CWE-319)",
    "type": "js_http_url_in_code",
    "file": "/home/runner/work/verisimdb/verisimdb/connectors/test-infra/seed/mongodb-init.js",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "medium"
  },
  {
    "reason": "getExn on external data -- use pattern matching (1 occurrences, CWE-754)",
    "type": "getexn_on_external",
    "file": "/home/runner/work/verisimdb/verisimdb/src/registry/Registry.res",
    "action": "flag",
    "rule_module": "code_safety",
    "severity": "critical"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath deleted the docs/rust-spark-stance-2026-05-18 branch May 20, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant