Complete G8 fleet source-reference sweep with provenance exceptions
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a070b5-4994-7271-bd8b-7c3dbcedec4b
This commit is contained in:
parent
4d61ff5e11
commit
8a1f1b9fb2
11 changed files with 1887 additions and 5 deletions
|
|
@ -17,8 +17,8 @@
|
||||||
| task | CFED-WP-0001-T06 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T06 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T07 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T07 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T08 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T08 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T09 | todo | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T09 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T10 | wait | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T10 | todo | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T11 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T11 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T12 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T12 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
| task | CFED-WP-0001-T13 | done | — | workplans/CFED-WP-0001-foundation.md |
|
| task | CFED-WP-0001-T13 | done | — | workplans/CFED-WP-0001-foundation.md |
|
||||||
|
|
|
||||||
33
docs/evidence/2026-09-06-hub-coordinates.json
Normal file
33
docs/evidence/2026-09-06-hub-coordinates.json
Normal file
|
|
@ -0,0 +1,33 @@
|
||||||
|
{
|
||||||
|
"repo_count": 133,
|
||||||
|
"fields_checked": [
|
||||||
|
"slug",
|
||||||
|
"local_path",
|
||||||
|
"host_paths",
|
||||||
|
"remote_url",
|
||||||
|
"mcp_server_name",
|
||||||
|
"mcp_server_url"
|
||||||
|
],
|
||||||
|
"obsolete_live_coordinates": [],
|
||||||
|
"git_repos_checked": 141,
|
||||||
|
"obsolete_git_remote_repos": [],
|
||||||
|
"nonadjacent_dispositions": {
|
||||||
|
"inter-hub": "State Hub archived; excluded from live source coverage",
|
||||||
|
"markitect-project": "State Hub archived; excluded from live source coverage",
|
||||||
|
"vergabe_teilnahme": "Resolved by local_path to scanned vergabe-teilnahme checkout"
|
||||||
|
},
|
||||||
|
"agent_configuration_scan": {
|
||||||
|
"roots": [
|
||||||
|
"~/.codex",
|
||||||
|
"~/.config",
|
||||||
|
"~/.claude"
|
||||||
|
],
|
||||||
|
"filename_patterns": [
|
||||||
|
"*config*",
|
||||||
|
"*mcp*",
|
||||||
|
"*settings*"
|
||||||
|
],
|
||||||
|
"live_matches": 0,
|
||||||
|
"historical_tool_result_matches": 2
|
||||||
|
}
|
||||||
|
}
|
||||||
9
docs/evidence/2026-09-06-reference-sweep.json
Normal file
9
docs/evidence/2026-09-06-reference-sweep.json
Normal file
|
|
@ -0,0 +1,9 @@
|
||||||
|
{
|
||||||
|
"gate": "G8-source-scan",
|
||||||
|
"result": "pass",
|
||||||
|
"repositories_scanned": 141,
|
||||||
|
"files_scanned": 22414,
|
||||||
|
"reviewed_exception_files": 164,
|
||||||
|
"matching_lines": 307,
|
||||||
|
"errors": []
|
||||||
|
}
|
||||||
104
docs/evidence/2026-09-06-reference-sweep.md
Normal file
104
docs/evidence/2026-09-06-reference-sweep.md
Normal file
|
|
@ -0,0 +1,104 @@
|
||||||
|
# G8 — Fleet source-reference sweep, 2026-09-06
|
||||||
|
|
||||||
|
CFED-WP-0001-T09 updates current source references across eight owning
|
||||||
|
repositories and the project ledger's validation command. Identity, actor,
|
||||||
|
access and shared-evidence references point to InfoTechCanon; repository and
|
||||||
|
commercial references point to CommerceCanon. No runtime contract, capability
|
||||||
|
identifier, maturity vector or concept assignment changes.
|
||||||
|
|
||||||
|
## Source coverage and preserved references
|
||||||
|
|
||||||
|
The [scan result](2026-09-06-reference-sweep.json) covers 141 adjacent Git
|
||||||
|
repositories and more than 22,000 files: tracked files (including ignored tracked
|
||||||
|
files), nonignored untracked files, hidden source/configuration files, and
|
||||||
|
symlink target paths (including dangling pointers). It
|
||||||
|
finds zero unreviewed legacy references. The
|
||||||
|
[exception ledger](../../ledger/reference-sweep.json) reviews 164 files / 307
|
||||||
|
matching lines and fingerprints each exact reference line. Historical research,
|
||||||
|
accepted ADR context, authored accounts, completed workplans, migration scope
|
||||||
|
and stable test/scenario identifiers remain deliberate provenance. Changing or
|
||||||
|
adding a matching line requires a fresh review; exceptions are not directory-wide
|
||||||
|
suppression rules. G8's own evidence files are excluded as scan metadata.
|
||||||
|
|
||||||
|
[State Hub coordinate evidence](2026-09-06-hub-coordinates.json) checks all 133
|
||||||
|
registered repo records, their source coordinates and all 141 local Git remotes.
|
||||||
|
No obsolete live coordinate remains. The old State Hub lookup is a protected
|
||||||
|
alias resolving the same UUID `8c82baea-bb40-435d-ac42-ec7a7c20dbb8` and current
|
||||||
|
CommerceCanon paths/remote. Two records without adjacent checkouts, inter-hub
|
||||||
|
and markitect-project, are archived; vergabe_teilnahme resolves to the scanned
|
||||||
|
vergabe-teilnahme path. This source scan does not certify unregistered external
|
||||||
|
repositories or stale copies of historical checkouts on other hosts.
|
||||||
|
|
||||||
|
Agent config/MCP/settings filename searches under ~/.codex, ~/.config and
|
||||||
|
~/.claude found no live match; two historical tool-result files were preserved.
|
||||||
|
Repository-owned MCP/config files are included in the source scan. Untracked ignored
|
||||||
|
third-party dependency trees and unrelated caches are not treated as source.
|
||||||
|
|
||||||
|
## Published changes
|
||||||
|
|
||||||
|
| Owner | Result | Published revision |
|
||||||
|
| --- | --- | --- |
|
||||||
|
| reuse-surface | Canonical source/roster, refreshed cache and composed index; live registration handover | `5501b8b` |
|
||||||
|
| repo-manager | CommerceCanon slug/Forge coordinate; existing repository UUID preserved | `6854ea10b278664baee7167efcceb2713bbab754` |
|
||||||
|
| binky-control | Current ecosystem and inventory references | `143b78e` |
|
||||||
|
| feature-control | Technical identity/evidence source references | `a555aaa` |
|
||||||
|
| kaizen-agentic | Identity/organization source references | `894d34c` |
|
||||||
|
| user-engine | Technical owner references in intent, mapping/card, docs and exporter docstring | `b9ae48b` |
|
||||||
|
| the-custodian | Current classification example and authoring override; obsolete human-review override retired | `4df570a` |
|
||||||
|
| commerce-canon | Current downstream owner links; original research proposal explicitly historical | `4a5b3d8fcbfd168ed1b3b326f3ecbedc6689b080` |
|
||||||
|
|
||||||
|
Each owning repo has a synchronized native ADHOC-2026-09-06 record, except
|
||||||
|
reuse-surface, which uses existing REUSE-WP-0021. Consistency also assigned a
|
||||||
|
missing UUID to Kaizen's existing ADHOC-2026-08-21 record without changing its
|
||||||
|
body or task identities. The project ledger command now uses the renamed local
|
||||||
|
source path while retaining the original pinned Git blob.
|
||||||
|
|
||||||
|
## Live federation proof
|
||||||
|
|
||||||
|
[Registration evidence](2026-09-06-reuse-registration.json) records the enabled
|
||||||
|
CommerceCanon registration and the old source retained disabled with a replacement
|
||||||
|
note. Its history is preserved without keeping it in the active composition.
|
||||||
|
[Composed live proof](2026-09-06-reuse-composed.json) verifies exactly the two
|
||||||
|
expected capability IDs, owner/source repo, canonical URLs and cache paths:
|
||||||
|
|
||||||
|
- capability.identity.subject-resolution — D3 / A0 / C1 / R0
|
||||||
|
- capability.identity.vocabulary-canonicalize — D4 / A0 / C2 / R0
|
||||||
|
|
||||||
|
The fresh live response has no target warning. The local federation composer
|
||||||
|
refreshed just CommerceCanon, then its source slice replaced the old slice in
|
||||||
|
the generated index; all 60 unrelated local capability rows were preserved.
|
||||||
|
The two obsolete local cache files were backed up and removed. Capability
|
||||||
|
ownership metadata here is registry stewardship, not a competing concept owner.
|
||||||
|
|
||||||
|
## Verification
|
||||||
|
|
||||||
|
```bash
|
||||||
|
python3 tools/validate_fleet_references.py --workspace ..
|
||||||
|
PYTHONDONTWRITEBYTECODE=1 python3 tools/test_fleet_references.py
|
||||||
|
python3 tools/validate_ownership.py --source-repo ../commerce-canon
|
||||||
|
python3 tools/validate_corpus.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon
|
||||||
|
python3 docs/evidence/2026-09-05-counterparty-validate.py --commerce-repo ../commerce-canon --info-tech-repo ../info-tech-canon
|
||||||
|
```
|
||||||
|
|
||||||
|
The three sweep regression tests verify tracked ignored/hidden coverage,
|
||||||
|
rejection of new live references, and exact exception fingerprints. Existing
|
||||||
|
reuse-surface federation tests: 15 passed. Existing User Engine identity-alignment
|
||||||
|
tests: 4 passed, run with PYTHONPATH=src. Changed YAML/fenced examples/Python parse;
|
||||||
|
new relative links resolve; Custodian's example/authoring override match
|
||||||
|
CommerceCanon source classification. Existing ownership, counterparty and corpus
|
||||||
|
preservation proofs remain passing.
|
||||||
|
|
||||||
|
## Residuals and limits
|
||||||
|
|
||||||
|
G8 source-reference acceptance passes. Whole-fleet State Hub consistency is not
|
||||||
|
claimed. REUSE-WP-0021-T01 is done; T02 remains waiting on supported restoration
|
||||||
|
of three archived blank bindings to their existing legacy identities. The
|
||||||
|
missing-identifier tool rejects blank scalars and would derive different UUIDs;
|
||||||
|
no manual substitution or identity migration was performed. REUSE-WP-0021 remains
|
||||||
|
active and is the live owner of this repair.
|
||||||
|
|
||||||
|
Custodian's 13 historical consistency failures remain owned by CUST-IN-0017
|
||||||
|
from the prior gate. Other touched native records synchronized successfully.
|
||||||
|
CFED-WP-0001-T10 retains the final project residual/adoption review.
|
||||||
|
|
||||||
|
Acceptance decision: `48be4584-48df-4e81-8190-7a356e20f18b`.
|
||||||
59
docs/evidence/2026-09-06-reuse-composed.json
Normal file
59
docs/evidence/2026-09-06-reuse-composed.json
Normal file
|
|
@ -0,0 +1,59 @@
|
||||||
|
{
|
||||||
|
"capabilities": [
|
||||||
|
{
|
||||||
|
"id": "capability.identity.subject-resolution",
|
||||||
|
"name": "Identity Subject Resolution",
|
||||||
|
"summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.",
|
||||||
|
"vector": "D3 / A0 / C1 / R0",
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"status": "draft",
|
||||||
|
"owner": "commerce-canon",
|
||||||
|
"path": "registry/capabilities/capability.identity.subject-resolution.md",
|
||||||
|
"tags": [
|
||||||
|
"identity",
|
||||||
|
"subject",
|
||||||
|
"architecture"
|
||||||
|
],
|
||||||
|
"consumption_modes": [
|
||||||
|
"informational"
|
||||||
|
],
|
||||||
|
"source_repo": "commerce-canon",
|
||||||
|
"source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"source_index": "/data/cache/commerce-canon.yaml"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "capability.identity.vocabulary-canonicalize",
|
||||||
|
"name": "Identity Vocabulary Canonicalization",
|
||||||
|
"summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.",
|
||||||
|
"vector": "D4 / A0 / C2 / R0",
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"status": "draft",
|
||||||
|
"owner": "commerce-canon",
|
||||||
|
"path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md",
|
||||||
|
"tags": [
|
||||||
|
"identity",
|
||||||
|
"terminology",
|
||||||
|
"research"
|
||||||
|
],
|
||||||
|
"consumption_modes": [
|
||||||
|
"informational"
|
||||||
|
],
|
||||||
|
"source_repo": "commerce-canon",
|
||||||
|
"source_url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"source_index": "/data/cache/commerce-canon.yaml"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"sources": [
|
||||||
|
{
|
||||||
|
"repo": "commerce-canon",
|
||||||
|
"count": 2,
|
||||||
|
"url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"cache": "/data/cache/commerce-canon.yaml"
|
||||||
|
}
|
||||||
|
],
|
||||||
|
"composed_at": "2026-09-05T23:23:57+00:00",
|
||||||
|
"stale": false,
|
||||||
|
"target_warnings": [],
|
||||||
|
"total_capabilities": 65,
|
||||||
|
"other_warning_count": 0
|
||||||
|
}
|
||||||
84
docs/evidence/2026-09-06-reuse-registration.json
Normal file
84
docs/evidence/2026-09-06-reuse-registration.json
Normal file
|
|
@ -0,0 +1,84 @@
|
||||||
|
{
|
||||||
|
"old_registration_before": {
|
||||||
|
"repo": "identity-canon",
|
||||||
|
"url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"enabled": true,
|
||||||
|
"required": false,
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"cache_ttl_seconds": 86400,
|
||||||
|
"auth_header": "Authorization",
|
||||||
|
"registered_at": "2026-06-15T23:35:02+00:00",
|
||||||
|
"updated_at": "2026-08-20T21:44:34+00:00"
|
||||||
|
},
|
||||||
|
"retired_registration": {
|
||||||
|
"repo": "identity-canon",
|
||||||
|
"url": "https://forgejo.coulomb.social/coulomb/identity-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"enabled": false,
|
||||||
|
"required": false,
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"cache_ttl_seconds": 86400,
|
||||||
|
"auth_header": "Authorization",
|
||||||
|
"registered_at": "2026-06-15T23:35:02+00:00",
|
||||||
|
"updated_at": "2026-09-05T23:22:01+00:00",
|
||||||
|
"description": "Retired source registration after repository rename; replaced by commerce-canon under CFED-WP-0001-T09. Kept for history."
|
||||||
|
},
|
||||||
|
"canonical_registration": {
|
||||||
|
"repo": "commerce-canon",
|
||||||
|
"url": "https://forgejo.coulomb.social/coulomb/commerce-canon/raw/branch/main/registry/indexes/capabilities.yaml",
|
||||||
|
"enabled": true,
|
||||||
|
"required": false,
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"cache_ttl_seconds": 86400,
|
||||||
|
"auth_header": "Authorization",
|
||||||
|
"description": "Canonical source after CFED-WP-0001-T03/T09; stable capability.identity identifiers retained.",
|
||||||
|
"registered_at": "2026-09-05T23:22:01+00:00",
|
||||||
|
"updated_at": "2026-09-05T23:22:01+00:00"
|
||||||
|
},
|
||||||
|
"capability_ids": [
|
||||||
|
"capability.identity.subject-resolution",
|
||||||
|
"capability.identity.vocabulary-canonicalize"
|
||||||
|
],
|
||||||
|
"source_payload": {
|
||||||
|
"version": 1,
|
||||||
|
"updated": "2026-06-16",
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"capabilities": [
|
||||||
|
{
|
||||||
|
"id": "capability.identity.subject-resolution",
|
||||||
|
"name": "Identity Subject Resolution",
|
||||||
|
"summary": "Resolve who or what is acting by mapping principals, accounts, actors, and identifiers to a stable subject model.",
|
||||||
|
"vector": "D3 / A0 / C1 / R0",
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"status": "draft",
|
||||||
|
"owner": "commerce-canon",
|
||||||
|
"path": "registry/capabilities/capability.identity.subject-resolution.md",
|
||||||
|
"tags": [
|
||||||
|
"identity",
|
||||||
|
"subject",
|
||||||
|
"architecture"
|
||||||
|
],
|
||||||
|
"consumption_modes": [
|
||||||
|
"informational"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"id": "capability.identity.vocabulary-canonicalize",
|
||||||
|
"name": "Identity Vocabulary Canonicalization",
|
||||||
|
"summary": "Define an implementation-neutral vocabulary for identity-related concepts across overlapping domains.",
|
||||||
|
"vector": "D4 / A0 / C2 / R0",
|
||||||
|
"domain": "helix_forge",
|
||||||
|
"status": "draft",
|
||||||
|
"owner": "commerce-canon",
|
||||||
|
"path": "registry/capabilities/capability.identity.vocabulary-canonicalize.md",
|
||||||
|
"tags": [
|
||||||
|
"identity",
|
||||||
|
"terminology",
|
||||||
|
"research"
|
||||||
|
],
|
||||||
|
"consumption_modes": [
|
||||||
|
"informational"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
@ -34,7 +34,7 @@ Run from this repository:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
python3 tools/validate_ownership.py
|
python3 tools/validate_ownership.py
|
||||||
python3 tools/validate_ownership.py --source-repo ../identity-canon
|
python3 tools/validate_ownership.py --source-repo ../commerce-canon
|
||||||
python3 -m unittest discover -s tools -p 'test_*.py'
|
python3 -m unittest discover -s tools -p 'test_*.py'
|
||||||
```
|
```
|
||||||
|
|
||||||
|
|
@ -74,3 +74,7 @@ from the project root. Historical source assertions are not current definitions.
|
||||||
|
|
||||||
[Reciprocal interface evidence](../docs/evidence/2026-09-06-interface-cards.md)
|
[Reciprocal interface evidence](../docs/evidence/2026-09-06-interface-cards.md)
|
||||||
records the three published canon cards and explicit upstream import review (G7).
|
records the three published canon cards and explicit upstream import review (G7).
|
||||||
|
|
||||||
|
[Fleet reference review](reference-sweep.json) records exact historical-reference
|
||||||
|
exceptions; [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md) records
|
||||||
|
current source coordinates and service validation.
|
||||||
|
|
|
||||||
1442
ledger/reference-sweep.json
Normal file
1442
ledger/reference-sweep.json
Normal file
File diff suppressed because it is too large
Load diff
50
tools/test_fleet_references.py
Normal file
50
tools/test_fleet_references.py
Normal file
|
|
@ -0,0 +1,50 @@
|
||||||
|
from pathlib import Path
|
||||||
|
import hashlib
|
||||||
|
import json
|
||||||
|
import subprocess
|
||||||
|
import tempfile
|
||||||
|
import unittest
|
||||||
|
|
||||||
|
from validate_fleet_references import scan, validate
|
||||||
|
|
||||||
|
|
||||||
|
class FleetReferenceTests(unittest.TestCase):
|
||||||
|
def setUp(self):
|
||||||
|
self.tmp = tempfile.TemporaryDirectory()
|
||||||
|
self.addCleanup(self.tmp.cleanup)
|
||||||
|
self.root = Path(self.tmp.name)
|
||||||
|
self.repo = self.root / 'example'
|
||||||
|
self.repo.mkdir()
|
||||||
|
subprocess.run(['git', 'init', '-q'], cwd=self.repo, check=True)
|
||||||
|
self.legacy = 'identity' + '-canon'
|
||||||
|
self.ledger = self.root / 'review.json'
|
||||||
|
self.ledger.write_text(json.dumps({'repositories': ['example'], 'exceptions': []}))
|
||||||
|
|
||||||
|
def test_tracked_ignored_and_hidden_files_are_scanned(self):
|
||||||
|
(self.repo / '.gitignore').write_text('ignored.md\n')
|
||||||
|
(self.repo / 'ignored.md').write_text(self.legacy)
|
||||||
|
(self.repo / '.settings').write_text(self.legacy)
|
||||||
|
(self.repo / 'source-link').symlink_to('../' + self.legacy)
|
||||||
|
subprocess.run(['git', 'add', '-f', 'ignored.md'], cwd=self.repo, check=True)
|
||||||
|
_, _, found = scan(self.root)
|
||||||
|
self.assertEqual(set(found), {'example/ignored.md', 'example/.settings', 'example/source-link'})
|
||||||
|
|
||||||
|
def test_new_live_reference_is_rejected(self):
|
||||||
|
(self.repo / 'README.md').write_text('Source: ' + self.legacy)
|
||||||
|
result = validate(self.root, self.ledger)
|
||||||
|
self.assertEqual(result['result'], 'fail')
|
||||||
|
self.assertEqual(result['errors'][0]['reason'], 'unreviewed reference')
|
||||||
|
|
||||||
|
def test_review_is_bound_to_exact_reference_content(self):
|
||||||
|
text = 'Historical source: ' + self.legacy
|
||||||
|
(self.repo / 'README.md').write_text(text)
|
||||||
|
data = {'repositories': ['example'], 'exceptions': [{'file': 'example/README.md',
|
||||||
|
'reason': 'Historical source', 'line_sha256': [hashlib.sha256(text.encode()).hexdigest()]}]}
|
||||||
|
self.ledger.write_text(json.dumps(data))
|
||||||
|
self.assertEqual(validate(self.root, self.ledger)['result'], 'pass')
|
||||||
|
(self.repo / 'README.md').write_text(text + '\nCurrent source: ' + self.legacy)
|
||||||
|
self.assertEqual(validate(self.root, self.ledger)['result'], 'fail')
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
unittest.main()
|
||||||
86
tools/validate_fleet_references.py
Normal file
86
tools/validate_fleet_references.py
Normal file
|
|
@ -0,0 +1,86 @@
|
||||||
|
"""Validate reviewed legacy-reference exceptions across adjacent Git repositories.
|
||||||
|
|
||||||
|
Scans tracked files plus nonignored untracked files, including hidden files and symlink target paths.
|
||||||
|
Matches are fingerprints, not embedded file content. Git internals and ignored untracked
|
||||||
|
dependency/cache trees are outside the source scan; live registry/cache
|
||||||
|
and service checks are separate evidence.
|
||||||
|
"""
|
||||||
|
from __future__ import annotations
|
||||||
|
import argparse
|
||||||
|
from collections import Counter
|
||||||
|
import hashlib
|
||||||
|
import json
|
||||||
|
import os
|
||||||
|
from pathlib import Path
|
||||||
|
import re
|
||||||
|
import subprocess
|
||||||
|
|
||||||
|
PROJECT = Path(__file__).resolve().parents[1]
|
||||||
|
PATTERN = re.compile('identity' + r'[-_ ]?canon(?![a-z])', re.I)
|
||||||
|
AUDIT_FILES = {
|
||||||
|
'ledger/reference-sweep.json',
|
||||||
|
'docs/evidence/2026-09-06-reference-sweep.json',
|
||||||
|
'docs/evidence/2026-09-06-reference-sweep.md',
|
||||||
|
'docs/evidence/2026-09-06-reuse-registration.json',
|
||||||
|
'docs/evidence/2026-09-06-reuse-composed.json',
|
||||||
|
'docs/evidence/2026-09-06-hub-coordinates.json',
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
def scan(workspace):
|
||||||
|
repos = sorted(p for p in workspace.iterdir() if (p / '.git').exists())
|
||||||
|
matches = {}
|
||||||
|
total_files = 0
|
||||||
|
for repo in repos:
|
||||||
|
paths = subprocess.check_output(['git', 'ls-files', '-z', '--cached', '--others', '--exclude-standard'], cwd=repo)
|
||||||
|
for relative in sorted(set(p.decode() for p in paths.split(b'\0') if p)):
|
||||||
|
if repo.name == PROJECT.name and relative in AUDIT_FILES:
|
||||||
|
continue
|
||||||
|
path = repo / relative
|
||||||
|
if path.is_symlink():
|
||||||
|
# Audit the routing pointer even if its destination is absent.
|
||||||
|
data = os.readlink(path).encode()
|
||||||
|
elif path.is_file():
|
||||||
|
data = path.read_bytes()
|
||||||
|
else:
|
||||||
|
continue
|
||||||
|
total_files += 1
|
||||||
|
if b'\0' in data:
|
||||||
|
continue
|
||||||
|
lines = data.decode('utf-8', errors='replace').splitlines()
|
||||||
|
found = [{'line': i, 'sha256': hashlib.sha256(line.encode()).hexdigest()}
|
||||||
|
for i, line in enumerate(lines, 1) if PATTERN.search(line)]
|
||||||
|
if found:
|
||||||
|
matches[f'{repo.name}/{relative}'] = found
|
||||||
|
return repos, total_files, matches
|
||||||
|
|
||||||
|
|
||||||
|
def validate(workspace, ledger_path):
|
||||||
|
ledger = json.loads(ledger_path.read_text())
|
||||||
|
repos, file_count, found = scan(workspace)
|
||||||
|
accepted = {e['file']: e for e in ledger['exceptions']}
|
||||||
|
errors = []
|
||||||
|
for name, rows in found.items():
|
||||||
|
entry = accepted.get(name)
|
||||||
|
if not entry:
|
||||||
|
errors.append({'file': name, 'reason': 'unreviewed reference', 'lines': [r['line'] for r in rows]})
|
||||||
|
elif Counter(r['sha256'] for r in rows) != Counter(entry['line_sha256']):
|
||||||
|
errors.append({'file': name, 'reason': 'reference content changed; review required'})
|
||||||
|
for name in accepted.keys() - found.keys():
|
||||||
|
errors.append({'file': name, 'reason': 'obsolete exception; remove or review'})
|
||||||
|
missing = set(ledger['repositories']) - {p.name for p in repos}
|
||||||
|
errors.extend({'repo': r, 'reason': 'reviewed checkout missing'} for r in sorted(missing))
|
||||||
|
return {'gate': 'G8-source-scan', 'result': 'pass' if not errors else 'fail',
|
||||||
|
'repositories_scanned': len(repos), 'files_scanned': file_count,
|
||||||
|
'reviewed_exception_files': len(accepted), 'matching_lines': sum(map(len, found.values())),
|
||||||
|
'errors': errors}
|
||||||
|
|
||||||
|
|
||||||
|
if __name__ == '__main__':
|
||||||
|
parser = argparse.ArgumentParser(description=__doc__)
|
||||||
|
parser.add_argument('--workspace', type=Path, default=PROJECT.parent)
|
||||||
|
parser.add_argument('--ledger', type=Path, default=PROJECT / 'ledger/reference-sweep.json')
|
||||||
|
args = parser.parse_args()
|
||||||
|
result = validate(args.workspace.resolve(), args.ledger)
|
||||||
|
print(json.dumps(result, indent=2))
|
||||||
|
raise SystemExit(0 if result['result'] == 'pass' else 1)
|
||||||
|
|
@ -332,7 +332,7 @@ G7 passes; T09 is now todo. Whole-fleet consistency is not claimed by this gate.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: CFED-WP-0001-T09
|
id: CFED-WP-0001-T09
|
||||||
status: todo
|
status: done
|
||||||
priority: medium
|
priority: medium
|
||||||
state_hub_task_id: "42ebf476-6a45-5e23-b507-eb90bc4f5c07"
|
state_hub_task_id: "42ebf476-6a45-5e23-b507-eb90bc4f5c07"
|
||||||
```
|
```
|
||||||
|
|
@ -344,6 +344,17 @@ registries, and `reuse-surface` entries. Deliberate historical provenance
|
||||||
|
|
||||||
Gate **G8** is a clean sweep.
|
Gate **G8** is a clean sweep.
|
||||||
|
|
||||||
|
**Result (2026-09-06):** [G8 evidence](../docs/evidence/2026-09-06-reference-sweep.md)
|
||||||
|
records eight published owner updates, 141 scanned local Git repositories,
|
||||||
|
133 checked State Hub records and a verified live reuse-service handover.
|
||||||
|
The [exception ledger](../ledger/reference-sweep.json) fingerprints deliberate
|
||||||
|
provenance and stable test/scenario names; zero unreviewed references remain.
|
||||||
|
Two existing capability ids/vectors and repository identity are preserved.
|
||||||
|
REUSE-WP-0021-T01 is done; its T02 retains the unrelated archived-binding repair
|
||||||
|
as live waiting work. CUST-IN-0017 retains prior Custodian consistency debt.
|
||||||
|
G8 passes; T10 is now todo. Overall progress: 12/13 tasks complete.
|
||||||
|
|
||||||
|
|
||||||
## Land the evidence model in InfoTechCanon
|
## Land the evidence model in InfoTechCanon
|
||||||
|
|
||||||
```task
|
```task
|
||||||
|
|
@ -443,7 +454,7 @@ T07 is now todo; destination concept areas are established for corpus routing.
|
||||||
|
|
||||||
```task
|
```task
|
||||||
id: CFED-WP-0001-T10
|
id: CFED-WP-0001-T10
|
||||||
status: wait
|
status: todo
|
||||||
priority: low
|
priority: low
|
||||||
state_hub_task_id: "2faeb8fb-58cc-5ea8-b5a8-ea0ed9583b30"
|
state_hub_task_id: "2faeb8fb-58cc-5ea8-b5a8-ea0ed9583b30"
|
||||||
```
|
```
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue