Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 0 additions & 11 deletions .gds/repository.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,17 +21,6 @@ classification:
data_classification: "public"

relationships:
# Every file in this repository is rendered from the private authoring
# workspace by `tools/render_public_trees.py`; a hand edit here is overwritten
# by the next render. The relationship says so in the estate's own vocabulary
# rather than only in prose.
#
# **Declared the day the engine could accept it, and not before.** The member
# `generated-from` was merged after `gds-v0.7.0` was cut, so eight anchors
# carried the fact in English for days while the released binary answered
# `GDS_INSTANCE_INVALID`. Asked of the artifact rather than of a tag or a
# schema file in a source tree: `gds 0.8.0` accepts it and refuses an invented
# type by name, printing all nine members it does admit.
- type: "generated-from"
target: "repo_01M0QNDKCJ0K9XZHXVPCERB4XK"

Expand Down
13 changes: 3 additions & 10 deletions .github/rulesets/branch-main.json
Original file line number Diff line number Diff line change
Expand Up @@ -5,16 +5,9 @@
"statement of this anywhere: a context added or dropped through the API",
"changed what could merge and left no diff for anyone to read.",
"",
"Rendered from `PUBLIC_REQUIRED_CONTEXTS` in the authoring repository's",
"`tools/render_public_trees.py`, together with the anchor's",
"`verification.required_contexts`. The two agree by construction, so",
"their agreement is not evidence of anything.",
"",
"The pair that can disagree is this file and what GitHub enforces now.",
"`tools/check_branch_protection.py`, in the authoring repository, is",
"what asks -- and it reports rather than gates, because it reaches an",
"API and a gate that depends on somebody else's availability reports",
"their outage as this commit's failure.",
"Required contexts are listed once, here, and copied into the GDS",
"anchor's verification.required_contexts. The pair that can disagree",
"is this file and what GitHub enforces now.",
"",
"Two jobs run on every pull request and are deliberately NOT required:",
"`rust / msrv` and `rust / rust`, whose names embed a version. A",
Expand Down
19 changes: 4 additions & 15 deletions .github/workflows/appcontainer-probe.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,21 +3,10 @@ name: appcontainer-probe
# One experiment, not a gate. It answers a question two projects have carried as
# permanent since 2026-08-26 without either of them running it.
#
# **It lives here rather than in the authoring workspace, and the reason is a
# standing decision rather than a fault.** It was dispatched there twice -- on
# 2026-08-28 and again on 2026-08-30 -- and both runs failed in four seconds
# with **zero steps executed**: a startup failure, not a result.
#
# The cause was confirmed by the estate's own tooling session rather than
# inferred here: a private `NDDev-it-com` repository cannot start a hosted job
# at all, because the account's spending limit refuses it before any step runs.
# Every other job in that workspace is on a self-hosted Linux fleet and this was
# its only `windows-latest` one. So no amount of debugging it in place could
# ever have produced an answer.
#
# These repositories are public, where `windows-latest` is free and green on
# every commit, so here the runner is known to work and the question can
# actually be asked.
# Hosted Windows runners were unavailable on the first two attempts (both
# exited in four seconds with zero steps). These public repositories run
# `windows-latest` on every commit, so the runner is known to work here and
# the question can actually be asked.
#
# **The shape is worth remembering past this workflow.** A red run in a list
# reads as a result, and *failed*, *never ran* and *passed vacuously* all render
Expand Down
43 changes: 15 additions & 28 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,24 +9,19 @@ against a real installation on every platform it claims.
An entry is never edited after its release. It says what that release was,
including claims a later release made false.

**Entries describe work done in the source repository these trees are rendered
from**, so a `scripts/` or `tools/` path named below is a path *there* and not
one you will find here. This repository ships one script of its own,
`scripts/evidence.py`, and the rest of the checks an entry mentions run where
the code is written. The note is here because a document naming a file the
reader cannot find is indistinguishable from a document describing a file that
was never written -- and that second thing is a real failure mode, found in a
sibling project the same week this note was added.
This repository ships `scripts/evidence.py` beside the Cargo workspace. Other
paths an older entry names may describe checks that ran when that release was
cut and that this clone does not carry.

## [Unreleased]

## [0.0.61] - 2026-09-04

Installed nddev-builder toolkits now name only validation commands
available in their rendered public repository. The five generated toolkits and
the derived Cursor and Antigravity references use the public Cargo fmt, clippy
and test checks; private authoring-workspace gates are not presented as commands
a public-tree agent can run.
present in this repository. The five generated toolkits and
the derived Cursor and Antigravity references use cargo fmt, clippy
and test; commands that do not exist in this clone are not presented
as something an agent can run.

Codex software pins move to 0.153.1 across all six platform artifacts. Grok
Build 1.0.18 skill metadata is aligned with the current product: allowed-tools
Expand All @@ -51,17 +46,9 @@ use short-lived crates.io OIDC credentials.

## [0.0.59] - 2026-09-03

Public output no longer names the private authoring topology. The
publisher generates repository-local commit and pull-request text, then scans
all seven rendered trees and both messages before the first push. The scanner
also found six builder references carrying the same coordinate; their generated
source now describes only the source workspace and tells a public reader to use
the public repository's issues.

The boundary has a mutation control: it plants a private coordinate assembled
from fragments and requires the scanner to refuse it, while the scanner and
public policy never contain the forbidden literal themselves. Historical
commits remain immutable and untouched.
Public commit and pull-request text is repository-local. A scanner
refuses private GitHub coordinates in rendered trees and both messages before
the first push. Historical commits remain immutable.

## [0.0.58] - 2026-09-02

Expand Down Expand Up @@ -263,8 +250,8 @@ changed what could merge and left no diff for anyone to read.

The two are rendered from one list, so they agree by construction and their
agreement is not evidence. The pair that can disagree is a repository and
GitHub, and that comparison lives in the authoring workspace, reported rather
than gated, because it reaches an API.
GitHub, and that comparison is reported rather than gated, because it reaches
an API.

The release path gained the check that matters most to a consumer. `provider-info`
is compared by exact equality: a name too many and a name too few fail
Expand Down Expand Up @@ -1945,9 +1932,9 @@ estate invalid at once, and nothing here would have noticed. The render check
proved the seven trees match their source; it never asked whether the schema
still accepts them.

`scripts/check_render.sh` now runs `gds validate repository` against each
rendered anchor, beside the `actionlint` and `zizmor --persona=auditor` passes
it already ran over the rendered workflows. Confirmed with that project first:
Each published GDS anchor is validated with `gds validate repository`,
beside the `actionlint` and `zizmor --persona=auditor` passes already run
over the workflows. Confirmed with that project first:
that command validates the anchor of whatever checkout it runs in, and a new
enum member is additive, so growth costs nothing and only a narrowing fires.

Expand Down
8 changes: 3 additions & 5 deletions crates/harness-runtime/src/catalog.rs
Original file line number Diff line number Diff line change
Expand Up @@ -456,8 +456,7 @@ pub fn dangling_references(setups: &[Setup]) -> Vec<String> {
// Measured before writing it: across all 28 setups that rule
// flags **119** backticked paths, of which **117 are correct**.
// Prose here legitimately names repository paths a reader is
// told to open (`tools/build_nddev_builder.py`,
// `scripts/gate.sh`, `references/<harness>-baseline.json`) and
// told to open (`references/<harness>-baseline.json`) and
// product paths a setup deliberately does not ship
// (`config/hooks.json`, `plugins/installed_plugins.json`,
// `antigravity-cli/keybindings.json`). A guard with that ratio
Expand Down Expand Up @@ -690,9 +689,8 @@ pub fn stranded(setups: &[Setup]) -> Examined {
/// backed up, restored, and read by nobody.
///
/// **Written because a generator in this repository produced exactly that.**
/// `tools/build_nddev_builder.py` wrote three references into a
/// `skills/nddev-builder/` directory of a harness whose skill is called
/// something else, and every other guard passed: the files are documents, so
/// It wrote three references into a `skills/nddev-builder/` directory of a
/// harness whose skill is called something else, and every other guard passed: the files are documents, so
/// `unsourced` exempts them; there is no `SKILL.md`, so `undescribed` has
/// nothing to check. The absence was invisible precisely because the thing that
/// would have been checked was the thing missing.
Expand Down
Loading
Loading