Skip to content

chore: remove nested duplicate trees - #76

Merged
hyperpolymath merged 1 commit into
mainfrom
claude/drop-nested-duplicate-trees
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
claude/drop-nested-duplicate-trees

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Summary

This removes two tracked duplicate trees, each nested inside the directory it copies: verification/verification/ and www/.well-known/.well-known/. The removal was first part of the licence PR #74. It moved here so that #74 contains only the licence change and stays under CodeRabbit's 100-file review limit.

The two PRs change no file in common, so they can merge in either order.

Changes

  • Deleted verification/verification/ (28 files), a copy of verification/.
  • Deleted www/.well-known/.well-known/ (3 files), a copy of www/.well-known/.
  • Nothing else changes.

30 of the 31 files match their outer copy line for line, apart from SPDX and copyright lines. 15 of them carry the retired PMPL header. The 31st, verification/verification/README.adoc, also has a title line, = Verification Pillar. #74 adds that title and the copyright line to the outer verification/README.adoc. If this PR merges first, the outer README simply lacks the title until #74 lands; no content is lost.

📌 New pins

  • Head SHA: 31fd364ba67f7497c715599b47cbb518357c76bb
  • None. No action uses:, actions.lock, lockfile or container digest is added or changed.

RSR Quality Checklist

Required

  • Tests pass: n/a. Only duplicate copies are deleted; no source, proof or test that is built or run changes.
  • Code is formatted: n/a, nothing is added.
  • Linter is clean: no file is added or edited.
  • No banned language patterns: nothing is added.
  • No unsafe blocks: n/a, no Rust changed.
  • No banned functions: n/a, no source or proofs added.
  • SPDX license headers: n/a, the PR only deletes files.
  • No secrets or credentials.

As Applicable

  • .machine_readable/*.a2ml updated: no. A2ML is retired. 9 of the deleted files are .a2ml duplicates (verification/verification/0.1-AI-MANIFEST.a2ml and one 0.2-AI-MANIFEST.a2ml in each of its 8 subdirectories). Their outer copies are unchanged.
  • Documentation updated: n/a, no document refers to the deleted paths except the signed historical record below.
  • TOPOLOGY.md: n/a.
  • CHANGELOG: not updated, since only duplicates are removed.
  • New dependencies: none.
  • ABI/FFI: n/a.

Testing

  • Each deleted file was compared with its outer copy, ignoring SPDX lines, copyright lines and bare <!-- / --> lines. Result: 30 files have no difference. verification/verification/README.adoc differs only by its title line, which is described above.
    • Positive control: a copy of verification/verification/proofs/0.2-AI-MANIFEST.a2ml with one planted line reported 1 differing line.
    • Limit: the comparison is line-based. It shows that the outer copy keeps every non-licence line of the inner one. It says nothing about which licence header is correct, which is chore(licence): MPL-2.0 for code, CC-BY-SA-4.0 for prose #74's subject.
  • No dangling references: git grep -nE 'verification/verification|\.well-known/\.well-known' origin/main matches only docs/AFFIRMATION.adoc:213-214, the signed affirmation that records this duplicate. It is left unchanged.
  • No overlap with chore(licence): MPL-2.0 for code, CC-BY-SA-4.0 for prose #74: comm -12 of the two PRs' file lists is empty.

Red checks on this head

🤖 Generated with Claude Code

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

Deletes two tracked copies nested inside the directories they copy:

- verification/verification/ (28 files), a copy of verification/
- www/.well-known/.well-known/ (3 files), a copy of www/.well-known/

30 of the 31 files match their outer copy line for line, apart from
SPDX and copyright lines; 15 of them carry the retired PMPL header. The
31st, verification/verification/README.adoc, also has a title line,
"= Verification Pillar". The licence PR (#74) adds that title and the
copyright line to the outer verification/README.adoc.

No file in the tree refers to either path. The only mention is the
signed historical record docs/AFFIRMATION.adoc:213-214, which is left
unchanged.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 27 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 01ae8eb3-de67-4e02-9021-fbebbbedf50f
📥 Commits

Reviewing files that changed from the base of the PR and between 589e1be and 31fd364.

📒 Files selected for processing (31)
  • verification/verification/0.1-AI-MANIFEST.a2ml
  • verification/verification/README.adoc
  • verification/verification/benchmarks/0.2-AI-MANIFEST.a2ml
  • verification/verification/benchmarks/README.adoc
  • verification/verification/coverage/0.2-AI-MANIFEST.a2ml
  • verification/verification/coverage/README.adoc
  • verification/verification/fuzzing/0.2-AI-MANIFEST.a2ml
  • verification/verification/fuzzing/README.adoc
  • verification/verification/proofs/0.2-AI-MANIFEST.a2ml
  • verification/verification/proofs/README.adoc
  • verification/verification/proofs/agda/Properties.agda
  • verification/verification/proofs/coq/TypeSafety.v
  • verification/verification/proofs/idris2/ABI/Compliance.idr
  • verification/verification/proofs/idris2/ABI/Foreign.idr
  • verification/verification/proofs/idris2/ABI/Layout.idr
  • verification/verification/proofs/idris2/ABI/Platform.idr
  • verification/verification/proofs/idris2/ABI/Pointers.idr
  • verification/verification/proofs/idris2/Types.idr
  • verification/verification/proofs/lean4/ApiTypes.lean
  • verification/verification/proofs/tlaplus/StateMachine.tla
  • verification/verification/safety_case/0.2-AI-MANIFEST.a2ml
  • verification/verification/safety_case/README.adoc
  • verification/verification/simulations/0.2-AI-MANIFEST.a2ml
  • verification/verification/simulations/README.adoc
  • verification/verification/tests/0.2-AI-MANIFEST.a2ml
  • verification/verification/tests/README.adoc
  • verification/verification/traceability/0.2-AI-MANIFEST.a2ml
  • verification/verification/traceability/README.adoc
  • www/.well-known/.well-known/ai.txt
  • www/.well-known/.well-known/humans.txt
  • www/.well-known/.well-known/security.txt
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 8, 2026

Copy link
Copy Markdown

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

🔍 Hypatia Security Scan

Findings: 59 issues detected

Severity Count
🔴 Critical 6
🟠 High 26
🟡 Medium 27

⚠️ Action Required: Critical security issues found!

View findings
[
  {
    "reason": "Job `triage` in label-triage.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/label-triage.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "triage"
  },
  {
    "reason": "Job `sync` in labels.yml has no `timeout-minutes:` declaration. Default is 6 hours — a stuck codeload fetch or runner hang can burn budget. Add `timeout-minutes: 10` (or proportional).",
    "type": "missing_timeout_minutes",
    "file": ".github/workflows/labels.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "medium",
    "recipe_id": "recipe-add-workflow-timeout-minutes",
    "job": "sync"
  },
  {
    "reason": "scorecard.yml delegates to hyperpolymath/standards `scorecard-reusable.yml` but the file does not declare `security-events: write`. Reusable called-workflow permissions are CAPPED by the caller's grants; the reusable's own job-level grant cannot exceed what the caller provides. Result: ossf/scorecard-action cannot upload SARIF and the run fails with `startup_failure` (no logs, no findings). Add `permissions: {security-events: write, id-token: write}` at the job level (preferred) or workflow level.",
    "type": "scorecard_wrapper_missing_job_permissions",
    "file": ".github/workflows/scorecard.yml",
    "action": "flag",
    "rule_module": "workflow_audit",
    "severity": "high",
    "fix_recipe": "add_job_level_scorecard_perms"
  },
  {
    "line": 38,
    "reason": "job in .github/workflows/labels.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 44,
    "reason": "job in .github/workflows/push-email-notify.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/push-email-notify.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 82,
    "reason": "job in .github/workflows/hypatia-scan.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 52,
    "reason": "job in .github/workflows/label-triage.yml references `secrets.*` but does not install `step-security/harden-runner` — review outbound-egress monitoring",
    "type": "RE001",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "research_extensions",
    "severity": "medium"
  },
  {
    "line": 33,
    "reason": "workflow .github/workflows/labels.yml:33 job `sync` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/labels.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": 47,
    "reason": "workflow .github/workflows/label-triage.yml:47 job `triage` has no `timeout-minutes:` — defaults to 360 min on hang",
    "type": "WH006",
    "file": ".github/workflows/label-triage.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "medium"
  },
  {
    "line": null,
    "reason": "workflow .github/workflows/hypatia-scan.yml uploads SARIF to code scanning but masks the scanner's failure (`|| true` / `|| echo 0`) and never asserts the findings artefact is a non-empty array. When the scanner fails, this uploads a SARIF with zero results, and GitHub AUTO-CLOSES every previously-open alert for that category — silently, with the job green.",
    "type": "WH014",
    "file": ".github/workflows/hypatia-scan.yml",
    "action": "report",
    "rule_module": "workflow_hardening",
    "severity": "high"
  }
]

Powered by Hypatia Neurosymbolic CI/CD Intelligence

@hyperpolymath
hyperpolymath merged commit bdef9a0 into main Oct 9, 2026
28 of 29 checks passed
@hyperpolymath
hyperpolymath deleted the claude/drop-nested-duplicate-trees branch October 9, 2026 00:23
hyperpolymath added a commit that referenced this pull request Oct 9, 2026
…facts (#77)

## Summary

This carries out four owner decisions of 2026-10-09 that #74 and #76
left open:

1. **Delete the nested `.machine_readable/.machine_readable/` copy** (75
files), after checking its diverging files for anything worth keeping.
2. **Keep `.github/FUNDING.yml` (`github: hyperpolymath`) and delete
`.github/funding.yml` (`github: metadatastician`).**
3. **Delete the unused `LICENSES/AGPL-3.0-or-later.txt`.**
4. **Delete the two PMPL exhibits in `docs/legal/`** and fix the three
files that refer to them.

It changes no file that #73, #74 or #76 changes in a conflicting way.
`git merge-tree` against each of their heads is clean (see Testing), so
the four PRs can merge in any order.

## Changes

- **Deleted `.machine_readable/.machine_readable/`** (75 files). #40
(`cc60f66`) added it in a single commit. 53 of its files contain PMPL
text. 17 differ from their outer copy beyond SPDX and copyright lines,
and 3 exist only inside it:
- **The 5 non-A2ML files are rattlescript-era template residue.** They
name `rattlescript`, `k9-svc` and `.machine_readable/contractiles/k9/`,
where the outer copies name `jaffascript` and `self-validating`. The
files are `README.adoc`, `ai/PLACEHOLDERS.adoc`,
`configs/git-cliff/cliff.toml`,
`contractiles/self-validating/README.adoc` and
`contractiles/self-validating/examples/setup-repo.k9.ncl`.
- **The only content among those 5 that the outer copy lacked** was the
README's title (`= .machine_readable Pillar`) and copyright line. Both
are now appended to `.machine_readable/README.adoc`, after its existing
comment lines.
- **12 A2ML files diverge.** 2 of them name rattlescript, and 10 name
neither repo. The 3 inner-only files are `ECOSYSTEM.a2ml`, `META.a2ml`
and `STATE.a2ml` in the old root layout. A2ML is retired, so all of them
go with the tree. Every outer A2ML file is unchanged.
- **Deleted `.github/funding.yml`.** It differs from
`.github/FUNDING.yml` only in letter case, so the two collide on a
case-insensitive checkout (Windows, macOS). `FUNDING.yml` stays:
`github`, `ko_fi` and `liberapay` all name `hyperpolymath`.
- **Deleted `LICENSES/AGPL-3.0-or-later.txt`.** No file in the repo is
AGPL-licensed. Every AGPL mention is a rule against it, or the deny list
in `.machine_readable/compliance/rust/deny.toml`, which is kept.
`LICENSES/` now holds `MPL-2.0.txt` and `CC-BY-SA-4.0.txt`.
- **Deleted `docs/legal/EXHIBIT-A-ETHICAL-USE.txt` and
`docs/legal/EXHIBIT-B-QUANTUM-SAFE.txt`**, the PMPL exhibits. Their
references are fixed:
- **`Justfile` and `.machine_readable/contractiles/Justfile`** (still
byte-identical): `validate-rsr` now checks for `LICENSES/MPL-2.0.txt`
and `LICENSES/CC-BY-SA-4.0.txt`. Before, it checked
`licensing/exhibits/EXHIBIT-{A,B}-*.txt` and
`licensing/texts/PMPL-1.0-or-later.txt`, under a `licensing/` directory
that does not exist, so it always reported all three as missing.
- **`docs/RSR_OUTLINE.adoc`**: the two exhibit rows in the file table
and the two exhibit lines in the tree are replaced by one `LICENSES/`
entry. The three places that described `LICENSE` as PMPL-1.0-or-later
now say MPL-2.0, which is what `LICENSE` already contains on `main`. The
rest of this template outline is untouched; its other stale claims are
listed below.

### Not changed

- `docs/legal/0.2-AI-MANIFEST.a2ml`, the remaining file in
`docs/legal/`. It does not refer to the exhibits.
- `docs/governance/MAINTENANCE-CHECKLIST.adoc:119`. It names
`docs/legal/` as a folder, which still exists.
- `LICENSE` and `LICENSES/MPL-2.0.txt`. Their "Exhibit A/B" text is the
MPL-2.0 licence's own exhibits, not the PMPL files.
- **Other stale claims in `docs/RSR_OUTLINE.adoc`**: the Palimpsest
badges on line 5, ReScript listed as Tier 1, `guix.scm` OR `flake.nix`,
"Python outside `salt/`" and "npm, Bun, pnpm, yarn (use Deno)", which
contradicts the estate's Bun-only rule. They are left for a separate
change, because this PR only fixes the references to the deleted files.

## 📌 New pins

- **Head SHA: `da27c4fa1ee2368fcb32f0a3e4609aefa9a3b260`**
- None. No action `uses:`, `actions.lock`, lockfile or container digest
is added or changed.

## RSR Quality Checklist

### Required

- [ ] Tests pass: n/a. No source, proof or test is changed.
`validate-rsr` was run before and after; see Testing.
- [ ] Code is formatted: n/a. The only code edit is one `for` line in
each Justfile, and `just --summary` parses both.
- [x] Linter is clean: standards `scripts/check-licence-consistency.sh`
exits 0 (see Testing).
- [x] No banned language patterns: nothing is added.
- [ ] No `unsafe` blocks: n/a, no Rust changed.
- [ ] No banned functions: n/a, no source or proofs changed.
- [x] SPDX license headers present: each of the 4 edited files keeps its
existing header. No file is added.
- [x] No secrets or credentials.

### As Applicable

- [ ] `.machine_readable/STATE.a2ml` / `ECOSYSTEM.a2ml` / `META.a2ml`
updated: no. A2ML is retired, and the outer A2ML files are unchanged.
- [x] Documentation updated: `docs/RSR_OUTLINE.adoc` and
`.machine_readable/README.adoc`.
- [ ] `TOPOLOGY.md`: n/a, the architecture is unchanged.
- [ ] `CHANGELOG`: not updated, since only duplicates and unused licence
files are removed.
- [ ] New dependencies: none.
- [ ] ABI/FFI: n/a.

## Testing

All checks ran on this head `da27c4f` against `main` at `589e1be`.

- **File list:** `git diff --name-status origin/main HEAD` shows 79 `D`
and 4 `M` (the two Justfiles, `docs/RSR_OUTLINE.adoc` and
`.machine_readable/README.adoc`). It shows no `A`.
- **No dangling references:** `git grep -nIE
'\.machine_readable/\.machine_readable|funding\.yml|AGPL-3\.0-or-later\.txt|EXHIBIT-[AB]|licensing/(exhibits|texts)'`
on this head matches nothing. The same pattern matches a planted line,
so it can find these paths.
- **`validate-rsr`**, run with `just --justfile Justfile validate-rsr`
because the root also holds a lowercase `justfile` (see below):
- On `main` it reports 6 missing paths: the 3 exhibit and PMPL paths,
and 3 old-layout A2ML paths.
- On this head it reports only the 3 A2ML paths
(`.machine_readable/{STATE,META,ECOSYSTEM}.a2ml`). They are missing on
`main` too, and this PR does not touch them.
- Positive control: with `LICENSES/CC-BY-SA-4.0.txt` removed from a copy
of this head, it also reports `LICENSES/CC-BY-SA-4.0.txt` as missing.
  - No workflow under `.github/` runs `validate-rsr`.
- **Standards `scripts/check-licence-consistency.sh`**, run from the
standards clone at `1ffe86b3`: exit 0 on both `main` and this head. Its
warning lines drop from 107 to 56, because the nested tree's PMPL
headers are gone.
- **AsciiDoc:** `asciidoctor --failure-level=WARN` reports no warnings
on either edited `.adoc`, before or after. The README title parses as
`.machine_readable Pillar`. The first table in `RSR_OUTLINE.adoc` goes
from 21 rows to 20 and stays at 2 columns.
- **No conflict with open PRs:** `git merge-tree --write-tree` of this
head with #73 (`0bee4f4`), #74 (`97377c5`) and #76 (`31fd364`) exits 0
for each. Positive control: a planted conflicting edit to
`.machine_readable/README.adoc` makes it exit 1.
- **Docstrings:** standards `.githooks/docstring-scan.sh --range
origin/main..HEAD --check` finds 0 touched functions.
- **Code-scanning alerts this PR introduces**, checked by hand because
`squabble verify-satisfied` does not evaluate them yet. Open alerts were
keyed on (rule, path), for `refs/pull/77/merge` against
`refs/heads/main`: 32 against 44. The PR-minus-main set is empty.
Control: main-minus-PR has 12 keys (Scorecard, plus Hypatia
CSA001/CSA003), which shows the diff can find a difference.

### Found while doing this, not fixed here

The repo root holds both **`Justfile`** (the RSR template, 1,545 lines)
and **`justfile`** (jaffascript's own 29-line runner for `affinescript
check/run/build --face jaffa`). As a result, a bare `just` in the root
fails with "multiple candidate justfiles", and on a case-insensitive
checkout one file overwrites the other. Merging them needs an owner
decision, so this PR leaves them alone.

## Red checks on this head

All 27 check-runs (paginated) and both legacy statuses had reported at
2026-10-09T00:00Z.

- `governance / Actions lockfile verify` is red on `main` (`589e1be`) as
well. It is fixed by #73 together with hyperpolymath/standards#1209, and
this PR does not touch it.
- Every other check-run is green: 20 `github-actions` runs, CodeQL,
Hypatia, SonarCloud, CodeFactor, GitGuardian and Semgrep. The only
required context, `scan / gitleaks`, is green.
- Statuses: CodeRabbit reports "Review rate limited", so it gave no
review (it never blocks). Codeac reports "1 errors and 4 warnings" with
state `success`, the same as on `main` `589e1be`.

## Screenshots

n/a, no UI change.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
hyperpolymath added a commit that referenced this pull request Oct 9, 2026
## Summary

This puts jaffascript on the two-tier licence rule: **MPL-2.0 for code,
CC-BY-SA-4.0 for prose**.

**This relicenses existing files, at the owner's direction.** The
owner's instruction (2026-10-09) was "mpl-2.0 code, and cc-by-sa-4.0
prose". The edits follow standards
`docs/migrations/pmpl-to-mpl-sweep-runbook.adoc` §5 and §6: every file
was opened and changed individually from an explicit list, and only a
file's own SPDX declaration was flipped. There was no bulk substitution.
The runbook makes owner sign-off on the per-repo change-list the hard
gate, so **this PR is held for the owner's merge**: auto-merge is not
armed. The full list is below.

This PR's first commit also deleted two nested duplicate trees. That
removal is now its own PR, #76, so this PR contains only the licence
change and fits CodeRabbit's 100-file limit. The two PRs change no file
in common.

## Changes

- **18 code/config files: PMPL-1.0-or-later → MPL-2.0** (SPDX header
only).
- **31 prose files: MPL-2.0 → CC-BY-SA-4.0.** 30 change only the SPDX
header. `verification/README.adoc` also gains the title (`= Verification
Pillar`) and copyright line of its nested copy, which #76 deletes.
- **16 `.adoc` files had no SPDX header and now carry `CC-BY-SA-4.0`.**
`README.adoc` is one of them: its only `SPDX-License-Identifier` text
was in body prose at line 138, not a header.
- **4 shell scripts had no SPDX header and now carry `MPL-2.0`**, on
line 2 after the shebang. Their modes are unchanged and `bash -n` passes
on each.
- **The licence rule text now states the two-tier rule** in every place
that states it: `.github/copilot-instructions.md`,
`.github/GOVERNANCE.md` footer, `.github/pull_request_template.md`,
`.machine_readable/ai/.clinerules`, `.machine_readable/ai/.cursorrules`,
`.machine_readable/ai/.windsurfrules`,
`.machine_readable/ai/PLACEHOLDERS.adoc`,
`docs/practice/AI-CONVENTIONS.adoc`, `QUICKSTART-MAINTAINER.adoc`,
`TEST-NEEDS.adoc`, `llm-warmup-{dev,user}.adoc`.
- **Declared metadata:** `stapeln.toml`,
`docs/attribution/CITATION.cff`, `docs/attribution/CITATIONS.adoc` and
`www/.well-known/humans.txt` now name MPL-2.0.
- **`www/.well-known/ai.txt`** states both licences. The line "AI agents
must preserve Emotional Lineage per PMPL Section 3" is gone, because
PMPL no longer applies.
- **The `{{LICENSE}}` placeholder** in the template-substitution recipe,
in both `Justfile` and `.machine_readable/contractiles/Justfile`, now
becomes `MPL-2.0`.
- **`.machine_readable/compliance/reuse/dep5`** (an unconsumed
template):
  - The code stanzas now say MPL-2.0.
- A final `*.adoc *.md` stanza assigns CC-BY-SA-4.0. In dep5 the last
matching stanza wins.
- The `.machine_readable/*.a2ml` stanza still says PMPL, to match those
files' headers (see "Kept").

### Kept deliberately (runbook §6)

- **Every `.a2ml` header.** A2ML is retired, and the deed migration owns
those files. The licence check lists them as warnings, and that is
expected.
- **`verification/verification/` and `www/.well-known/.well-known/`**
keep their old headers here (15 PMPL), because #76 deletes both trees.
- **`.machine_readable/.machine_readable/`**, a nested copy of 75 files.
The owner decided to delete it, and #77 does.
- **`LICENSE`** (already the verbatim MPL-2.0 text) and **`LICENSES/`**.
#77 deletes the unused `LICENSES/AGPL-3.0-or-later.txt` and the two PMPL
exhibits `docs/legal/EXHIBIT-{A,B}-*.txt`.
- **`CODE_OF_CONDUCT.adoc`**, which is adapted from the Contributor
Covenant and so was not relabelled.
- **`www/.well-known/{ai,humans,security}.txt`** keep their MPL-2.0
header, because they are machine-read data rather than prose.
- **History and policy text that names PMPL as a fact:**
`docs/tech-debt-2026-05-26.adoc` (body), `docs/decisions/0001-*`,
`docs/STATE-VISUALIZER.adoc`, `docs/RSR_OUTLINE.adoc`,
`.machine_readable/compliance/rust/deny.toml`, the k9 example bodies,
`contractile.just:65`, and `Justfile:224`/`:1057` (licence-file
tooling). #77 updates `docs/RSR_OUTLINE.adoc`'s description of `LICENSE`
and the `Justfile:1057` check, because both referred to the exhibits it
deletes. Its changes merge cleanly with this PR.

<details><summary>Full change-list (69 files relabelled)</summary>

**PMPL-1.0-or-later → MPL-2.0**

- `container/compose.example.toml`
- `container/compose.toml`
- `container/Containerfile`
- `container/ct-build.sh`
- `container/deploy.k9.ncl`
- `container/entrypoint.sh`
- `container/.gatekeeper.yaml`
- `container/manifest.toml`
- `container/vordr.toml`
- `contractile.just`
- `.devcontainer/Containerfile`
- `.devcontainer/devcontainer.json`
- `features/ssg/ssg-bootstrap.sh`
- `.gitlab-ci.yml`
- `Justfile`
- `.machine_readable/contractiles/Justfile`
- `.pre-commit-config.yaml`
- `scripts/validate-template.sh`

**MPL-2.0 → CC-BY-SA-4.0**

- `AUDIT.adoc`
- `.claude/CLAUDE.md`
- `container/README.adoc`
- `.devcontainer/README.adoc`
- `EXPLAINME.adoc`
- `features/boj-server/README.adoc`
- `features/panic-attacker/README.adoc`
- `features/README.adoc`
- `features/ssg/README.adoc`
- `.machine_readable/README.adoc`
- `MAINTAINERS.adoc`
- `ROADMAP.adoc`
- `src/aspects/integrity/README.adoc`
- `src/aspects/observability/README.adoc`
- `src/aspects/README.adoc`
- `src/aspects/security/README.adoc`
- `src/contracts/README.adoc`
- `src/definitions/README.adoc`
- `src/errors/README.adoc`
- `src/interface/Abi/README.adoc`
- `src/interface/ffi/README.adoc`
- `src/interface/ffi/src/README.adoc`
- `src/interface/ffi/test/README.adoc`
- `src/interface/generated/abi/README.adoc`
- `src/interface/generated/README.adoc`
- `src/interface/README.adoc`
- `src/README.adoc`
- `TEMPLATE-STANDARDS-AUDIT.adoc`
- `tools/invariant-path/README.adoc`
- `verification/README.adoc`
- `www/.well-known/README.adoc`

**New CC-BY-SA-4.0 header**

- `.claude/PROJECT.adoc`
- `ARCHITECTURE.adoc`
- `CHANGELOG.adoc`
- `GOVERNANCE.adoc`
- `PROOF-NEEDS.adoc`
- `PROOF-STATUS.adoc`
- `READINESS.adoc`
- `README.adoc`
- `SECURITY.adoc`
- `TEST-NEEDS.adoc`
- `TOPOLOGY.adoc`
- `docs/reports/audit/audit-2026-04-15-post.adoc`
- `docs/tech-debt-2026-05-26.adoc`
- `llm-warmup-dev.adoc`
- `llm-warmup-user.adoc`
- `session/README.adoc`

**New MPL-2.0 header**

- `.machine_readable/scripts/forge/git-cleanup.sh`
- `scripts/invariant-path.sh`
- `session/dispatch.sh`
- `session/local-hooks.sh`

</details>

## 📌 New pins

- **Head SHA: `97377c577ca4c75d6a86e3dfe524a4efb26ebad6`**
- None. No action `uses:`, `actions.lock`, lockfile or container digest
is added or changed.

## RSR Quality Checklist

### Required

- [ ] Tests pass: n/a. No source, proof or test file is changed; every
change is a comment header, rule text or metadata.
- [ ] Code is formatted: n/a, for the same reason. The four shell
scripts gained one comment line each, and `bash -n` passes on all four.
- [x] Linter is clean: standards `scripts/check-licence-consistency.sh`
passes (see Testing).
- [x] No banned language patterns: no code was added.
- [ ] No `unsafe` blocks: n/a, no Rust changed.
- [ ] No banned functions: n/a, no source or proofs changed.
- [x] SPDX license headers present: every file this PR touches has one,
with two exceptions. `docs/attribution/CITATION.cff` carries its licence
in its `license:` field, and `.machine_readable/compliance/reuse/dep5`
is itself a licence declaration. Neither had a header before this PR.
- [x] No secrets or credentials.

### As Applicable

- [ ] `.machine_readable/*.a2ml` updated: no. A2ML is retired, and its
headers are left for the deed migration.
- [x] Documentation updated: the licence rule text is listed under
Changes.
- [ ] `TOPOLOGY.md`: n/a, the architecture is unchanged.
- [ ] `CHANGELOG`: not updated. The relicence is recorded in this PR and
in the commit message, which lists every file.
- [ ] New dependencies: none.
- [ ] ABI/FFI: n/a.

## Testing

- **Standards `scripts/check-licence-consistency.sh`** (the governance
"Licence consistency" job), run locally on this head `97377c5` from the
standards clone at `1ffe86b3`: **exit 0**. It lists the kept `.a2ml`
headers and the 15 PMPL headers in the two nested trees as warnings,
which is expected.
- Positive control, run on the first head `a1c7c57`: I planted a
`Cargo.toml` declaring `PMPL-1.0-or-later` in a copy of the tree. The
script reported `Licence-vs-manifest mismatch` and exited **1**. With
the plant removed it exited 0 again.
- Limit of this check: the manifest check reads only Cargo.toml,
package.json, pyproject.toml, mix.exs, Project.toml, `*.ipkg`, `*.cabal`
and similar files. jaffascript has none of them, and the check does not
read `stapeln.toml`. Planting PMPL in `stapeln.toml` still exited 0, so
that file's licence was checked by hand.
- **No collateral edits:** across all 84 files, every changed line that
is not an `SPDX-License-Identifier` line is in one of the 21 files named
under Changes (the rule text, the declared metadata, `ai.txt`, the two
Justfiles, `dep5` and `verification/README.adoc`). Measured with `git
diff origin/main HEAD`, counting `^[-+]` lines without
`SPDX-License-Identifier` per file.
- **The restore commit `97377c5` is exact:** after it, `git diff
--name-status origin/main HEAD` lists 84 files, all `M`, with no `D` or
`A`.
- The governance "Check SPDX headers + permissions" step reads only
`.github/workflows/*`, and this PR changes no workflow.

## Red checks on this head

- `governance / Actions lockfile verify` is red on `main` (`589e1be`) as
well. It is fixed by #73 together with hyperpolymath/standards#1209, and
this PR does not touch it.
- `Hypatia` (code scanning) fails because this PR edits both Justfiles,
so their open alerts count as "in code changed by this pull request".
The alerts predate this PR, with the same alert numbers on `main`, and
the check is not required. Deferred to #75, which has acceptance
criteria.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01GpUzjdhWFi26k6s7AWxYcf

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant