Finish companion catalog work and reconcile completed approval tasks
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
parent
41e4c4a3d8
commit
e33f9c3ca5
18 changed files with 472 additions and 87 deletions
|
|
@ -13,9 +13,9 @@ its own right, reported rather than resolved away by precedence.
|
|||
Layer values are compared against §3's closed four-token vocabulary after an
|
||||
ASCII case-fold (GH-DEC-2026-017 §2-§3, amendment A9). Nothing is re-spelled:
|
||||
`Engine` and `engine` are one token. Neither form carries a standard version
|
||||
(GH-DEC-2026-017 §5, amendment A12 r2 / GH-DEC-2026-020), and its return is
|
||||
rejected. The rule reaches content, not a key name: every key and value of the
|
||||
INTENT.md frontmatter and of layer.yaml is walked, so a versioned `standard:` or
|
||||
(GH-DEC-2026-017 §5, amendment A12 r3 / GH-DEC-2026-021), and its return is
|
||||
rejected. The estate reference detector walks every key and value of the
|
||||
INTENT.md frontmatter and of layer.yaml, so a versioned `standard:` or
|
||||
`companion:` path and a `companion_version` are caught as well as a
|
||||
`standard_version`. Comments and `schema_version` are not reached. Stance maps
|
||||
and evidence classifications (pep-stance.yaml, evidence-classification.yaml)
|
||||
|
|
@ -60,29 +60,51 @@ DECISION_SURFACE = re.compile(
|
|||
LAYER_VOCABULARY = {"taxonomy", "tooling", "engine", "staff"}
|
||||
EXPECTED_LAYER = "engine"
|
||||
|
||||
# The standard text this checker was built and validated against, printed on
|
||||
# every run (GH-DEC-2026-020 §4, A12 r2). v0.7 is the accepted text in force;
|
||||
# the v0.8 §11 amendments it already applies are named alongside. Bump this
|
||||
# when the checker is re-validated against a newer accepted text.
|
||||
VALIDATED_AGAINST = "net-kingdom/canon/standards/security-layer-model_v0.7.md"
|
||||
AMENDMENTS_APPLIED = "v0.8 A9, A11, A12 r2 (GH-DEC-2026-017, GH-DEC-2026-020)"
|
||||
# The accepted text and rulings enforced by this run (GH-DEC-2026-021 §2).
|
||||
# Update together with the reference detector when the accepted text changes.
|
||||
VALIDATED_AGAINST = (
|
||||
"net-kingdom/canon/standards/security-layer-model_v0.7.md (net-kingdom@66dc491) "
|
||||
"as amended by GH-DEC-2026-017, GH-DEC-2026-020 and GH-DEC-2026-021 "
|
||||
"(A9-A13, A12 r3; gate-house@39d9287)"
|
||||
)
|
||||
SCOPE = (
|
||||
"declaration = INTENT.md frontmatter + layer.yaml (every key and value); "
|
||||
"source = src/secrets_engine/**/*.py; "
|
||||
"not reached by A12: pep-stance.yaml, evidence-classification.yaml"
|
||||
)
|
||||
|
||||
# A12 r2: a version of the standard or its companion, anywhere in the
|
||||
# declaration. `schema_version` is the declaration file's own schema and is
|
||||
# not reached.
|
||||
VERSION_KEY = re.compile(r"version", re.IGNORECASE)
|
||||
UNREACHED_KEYS = {"schema_version"}
|
||||
VERSIONED_REF = re.compile(
|
||||
r"(?i)(security-layer-model|security-companion|layer-model|companion)"
|
||||
r"[^\s]*?(?:[_@-]v?\d+(?:\.\d+)*|\bv\d+(?:\.\d+)*)"
|
||||
)
|
||||
STANDARD_KEYS = {"standard", "companion", "framework"}
|
||||
BARE_VERSION = re.compile(r"(?i)(?:^|[_@\s-])v?\d+\.\d+(?:\.\d+)*\b")
|
||||
# Estate reference detector, GH-DEC-2026-021 §3.
|
||||
VERSION_KEY = re.compile(r"(standard|companion).*version|version.*(standard|companion)", re.I)
|
||||
VERSION_IN_VALUE = re.compile(r"[_\-.]v\d+(\.\d+)*(\.md)?\b|@v?\d+\.\d+", re.I)
|
||||
NOT_REACHED_KEYS = {"schema_version"}
|
||||
IDENTITY_KEYS = {"standard", "companion"}
|
||||
IDENTITY_VERSION = re.compile(r"\bv?\d+\.\d+", re.I)
|
||||
|
||||
|
||||
def find_version_pins(node, where: str = "", identity: bool = False) -> list[str]:
|
||||
"""Every place in a parsed declaration that carries a standard/companion version.
|
||||
|
||||
Walks every key and value (comments are gone after parsing, which is the
|
||||
A12 r2 exclusion). Returns human-readable locations; empty means clean.
|
||||
"""
|
||||
pins: list[str] = []
|
||||
if isinstance(node, dict):
|
||||
for k, v in node.items():
|
||||
here = f"{where}.{k}" if where else str(k)
|
||||
if str(k) in NOT_REACHED_KEYS:
|
||||
continue
|
||||
if VERSION_KEY.search(str(k)):
|
||||
pins.append(f"{here} (key names a standard/companion version)")
|
||||
continue
|
||||
pins.extend(find_version_pins(v, here, str(k).lower() in IDENTITY_KEYS))
|
||||
elif isinstance(node, list):
|
||||
for i, v in enumerate(node):
|
||||
pins.extend(find_version_pins(v, f"{where}[{i}]", identity))
|
||||
elif isinstance(node, str) and VERSION_IN_VALUE.search(node):
|
||||
pins.append(f"{where} = {node!r} (value carries a version)")
|
||||
elif isinstance(node, str) and identity and IDENTITY_VERSION.search(node):
|
||||
pins.append(f"{where} = {node!r} (identity-bearing value carries a version)")
|
||||
return pins
|
||||
|
||||
|
||||
def _fold(value: object) -> str:
|
||||
|
|
@ -90,37 +112,13 @@ def _fold(value: object) -> str:
|
|||
return str(value).strip().encode("ascii", "ignore").decode().lower()
|
||||
|
||||
|
||||
def _version_hits(data: object, path: str = "") -> list[str]:
|
||||
"""Every place a standard or companion version appears in a declaration."""
|
||||
hits: list[str] = []
|
||||
if isinstance(data, dict):
|
||||
for key, value in data.items():
|
||||
here = f"{path}.{key}" if path else str(key)
|
||||
if str(key) in UNREACHED_KEYS:
|
||||
continue
|
||||
if VERSION_KEY.search(str(key)):
|
||||
hits.append(f"key {here!r}")
|
||||
continue
|
||||
if isinstance(value, str) and str(key).lower() in STANDARD_KEYS:
|
||||
if BARE_VERSION.search(value):
|
||||
hits.append(f"{here}: {value!r}")
|
||||
continue
|
||||
hits.extend(_version_hits(value, here))
|
||||
elif isinstance(data, list):
|
||||
for n, item in enumerate(data):
|
||||
hits.extend(_version_hits(item, f"{path}[{n}]"))
|
||||
elif isinstance(data, str) and VERSIONED_REF.search(data):
|
||||
hits.append(f"{path}: {data!r}")
|
||||
return hits
|
||||
|
||||
|
||||
def _no_standard_version(where: str, data: dict) -> None:
|
||||
hits = _version_hits(data)
|
||||
hits = find_version_pins(data)
|
||||
if hits:
|
||||
print(
|
||||
f"MALFORMED: {where} carries a standard or companion version at "
|
||||
f"{'; '.join(hits)} — a layer declaration MUST NOT carry one in any "
|
||||
"key or value (§11 as amended by A12 r2, GH-DEC-2026-020 §1-§2)"
|
||||
"key or value (§11 as amended by A12 r3, GH-DEC-2026-021 §1-§3)"
|
||||
)
|
||||
raise SystemExit(2)
|
||||
|
||||
|
|
@ -231,7 +229,7 @@ def main() -> int:
|
|||
ap = argparse.ArgumentParser()
|
||||
ap.add_argument("--report", action="store_true")
|
||||
args = ap.parse_args()
|
||||
print(f"validated against: {VALIDATED_AGAINST} [{AMENDMENTS_APPLIED}]")
|
||||
print(f"validated against: {VALIDATED_AGAINST}")
|
||||
print(f"scope: {SCOPE}")
|
||||
|
||||
front = intent_frontmatter()
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue