diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 66dfcd7..ef14f9f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -11,7 +11,7 @@ jobs: permissions: contents: read actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-ci.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: # canon is a tower root (no first-party deps to vendor). Post-ADR-17 it is a MULTI-package # repo: the core under core/ (the logcraft/server layout — the repo root is the shelf), the three @@ -45,7 +45,7 @@ jobs: permissions: pull-requests: write actions: read - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-sift-post.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: run-id: ${{ github.run_id }} secrets: inherit diff --git a/.github/workflows/golden.yaml b/.github/workflows/golden.yaml index 67b2223..764e921 100644 --- a/.github/workflows/golden.yaml +++ b/.github/workflows/golden.yaml @@ -88,18 +88,18 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false - name: Provision gcc-16.2 toolchain (OUR OWN published asset; arm64 auto-picked by uname -m) if: matrix.leg == 'gcc' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-gcc@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Provision clang-21 + libc++-21 if: matrix.leg == 'clang' - uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-clang21-libcxx@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Base — ninja + CMake 4.3.x (+ gcc-16.2 /opt wiring on the gcc leg) run: | @@ -198,13 +198,13 @@ jobs: uses: actions/checkout@v5 with: repository: CodeRoasted/malf-toolchain - ref: b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + ref: da2abf639f64e1c1bca382aa7a973e9cc2f00412 path: malf fetch-depth: 1 persist-credentials: false - name: Install + activate MSVC 14.52 (the C++23-modules fix floor; not pre-installed) - uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/setup-msvc1452@da2abf639f64e1c1bca382aa7a973e9cc2f00412 - name: Verify the active toolset is MSVC 14.52, not a fallback shell: pwsh @@ -314,7 +314,7 @@ jobs: pattern: golden-digest-* - name: Compare + validate the golden (all 5 legs must be byte-identical) - uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/actions/coderoast-golden-compare@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: digests-dir: digests min-legs: '5' diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index f7473b3..11d6285 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -8,7 +8,7 @@ on: jobs: lint: - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-lint.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 # PUBLIC repo: no runs-on passthrough — a self-hosted runner reachable from a fork PR is an RCE. # No `with:` at all: every gate in the reusable workflow defaults TRUE, so a caller that says # nothing is fully gated, and a hole would have to be a written line here. diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index d2bbe43..4a2d797 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -37,7 +37,7 @@ jobs: release: needs: golden - uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@b5e15eee5e2cc9a2709309850f845b28ba8d9e58 + uses: CodeRoasted/malf-toolchain/.github/workflows/coderoast-release.yml@da2abf639f64e1c1bca382aa7a973e9cc2f00412 with: tag: ${{ github.event.inputs.tag || github.ref_name }} # ADR-17.D8: the four semantic vocabulary packages ride the train on the SAME footing as canon diff --git a/core/CMakeLists.txt b/core/CMakeLists.txt index 71c680d..6693d86 100644 --- a/core/CMakeLists.txt +++ b/core/CMakeLists.txt @@ -296,7 +296,7 @@ install(FILES ${CMAKE_CURRENT_BINARY_DIR}/insight_canon-config.cmake ########################################################### # Measurement instruments (tools/) — built on the package's own compile surface ########################################################### -# The F13 masker-cardinality re-measure (ADR-8.D5): a CLI over the PUBLIC +# The FLAW-13 masker-cardinality re-measure (ADR-8.D5): a CLI over the PUBLIC # facade, deliberately NOT a test — its population is operator-mounted, so it reports and declares # rather than asserts. Built unconditionally so it can never rot unseen (the malf one-compile-surface # rule), linked exactly as an external consumer would link. @@ -306,7 +306,7 @@ target_compile_features(f13_cardinality_measure PRIVATE cxx_std_23) set_target_properties(f13_cardinality_measure PROPERTIES CXX_SCAN_FOR_MODULES ON CXX_MODULE_STD ON) # The G-L11 leading-level TOKEN-INDEX re-measure (ADR-16.D7, ROADMAP N98): the same shape as the -# F13 tool above — a CLI over the PUBLIC facade whose population is operator-mounted, so it declares +# FLAW-13 tool above — a CLI over the PUBLIC facade whose population is operator-mounted, so it declares # (files, lines, doors, the model's own control) and never asserts. It is what the token budget's # VALUE is taken from, and it re-runs on every corpus the budget is later re-derived against. add_executable(leading_level_token_index_measure tools/leading_level_token_index_measure.cpp) diff --git a/core/tests/mask/test_stateless_template.cpp b/core/tests/mask/test_stateless_template.cpp index 0aa6242..d574443 100644 --- a/core/tests/mask/test_stateless_template.cpp +++ b/core/tests/mask/test_stateless_template.cpp @@ -81,7 +81,7 @@ TEST(StatelessTemplate, KillsThePhantomPair) // invariant: the accepted tradeoff — the region word is KEPT literal rather than wildcarded. // refs: ADR-16.D5 EXPECT_NE(in_stream_a.find("eu-west"), std::string::npos) - << "a letter-leading word stays literal (F13 boundary): " << in_stream_a; + << "a letter-leading word stays literal (FLAW-13 boundary): " << in_stream_a; } TEST(StatelessTemplate, StatusValueKeptDistinct) diff --git a/core/tools/f13_cardinality_measure.cpp b/core/tools/f13_cardinality_measure.cpp index 61acdb4..dc9f524 100644 --- a/core/tools/f13_cardinality_measure.cpp +++ b/core/tools/f13_cardinality_measure.cpp @@ -121,7 +121,7 @@ try consumed.push_back(std::move(record)); } - std::println("=== Stateless template_id cardinality (F13 re-measure) ==="); + std::println("=== Stateless template_id cardinality (FLAW-13 re-measure) ==="); std::println("population : {} of {} *.log files under {} (recursive, sorted walk)", consumed.size(), files.size(), corpus_dir.string()); std::println("line budget : {}{}", max_lines, @@ -156,7 +156,7 @@ try for (std::size_t index{0}; index < std::min(kTopTemplatesShown, by_count.size()); ++index) std::println("{} {}", by_count[index].second, std::string_view{by_count[index].first}.substr(0, kTemplatePreviewChars)); - std::println("--- {} singleton samples (the F13 over-split tail) ---", kSingletonSamplesShown); + std::println("--- {} singleton samples (the FLAW-13 over-split tail) ---", kSingletonSamplesShown); std::size_t shown{0}; for (auto iter{by_count.rbegin()}; iter != by_count.rend() && shown < kSingletonSamplesShown; ++iter) diff --git a/technical_docs/canonicalization_generations.md b/technical_docs/canonicalization_generations.md index 12961be..95618a7 100644 --- a/technical_docs/canonicalization_generations.md +++ b/technical_docs/canonicalization_generations.md @@ -41,7 +41,7 @@ the §2.4 gate by construction. ## `-1` — the stateless masker -The stateless per-line masker plus the F13 class set. The first generation. +The stateless per-line masker plus the FLAW-13 class set. The first generation. ## `-2` — OTEL awareness diff --git a/technical_docs/operations/ccc_migration.md b/technical_docs/operations/ccc_migration.md index 8374ad4..9625960 100644 --- a/technical_docs/operations/ccc_migration.md +++ b/technical_docs/operations/ccc_migration.md @@ -2292,10 +2292,10 @@ this run was **not consumed**, and the next free integer is unchanged. The census was derived from the gates this repo actually runs rather than taken from the written list, and the derivation found **three comment tokens read by live superproject gates that -`OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (`scripts/log_seat_routing_lint.py`'s opt-out, +`OPS-8.S4` does not enumerate**: `LOG-SEAT-ALLOW` (the `log_seat_routing` check module's opt-out, whose scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — so `core/tools/` is inside its surface), a closure-model declaration marker read by -`scripts/closure_declaration_lint.py`, and a pin-mirror marker read by `scripts/pin_coherence.py`. +the `closure_declaration` check module (`scripts/closure_declaration_lint.py` then), and a pin-mirror marker read by the `pin_coherence` check module. **All three have a population of ZERO in this repo's source**, checked before the strip; they are recorded because the population is a fact about today, not a property of the repo. @@ -2571,8 +2571,8 @@ The derivation of unit 14 was re-used and re-run per file: `NOLINT` in every spe and `/*name=*/`, `clang-format off/on`, `wall-clock:`, `DETERMINISM-ALLOW`, the `determinism-lint: allow()` spelling `coderoast-server` found, `SPDX-License-Identifier:`, `registry-lint: allow`, plus the three superproject markers `OPS-8.S4` does not list — the seat -opt-out of `scripts/log_seat_routing_lint.py`, the closure-model marker of -`scripts/closure_declaration_lint.py` and the mirror marker of `scripts/pin_coherence.py`. +opt-out of the `log_seat_routing` check module, the closure-model marker of +the `closure_declaration` check module and the mirror marker of the `pin_coherence` check module. **Every token has a population of ZERO in these three files except the namespace closer**, which reads 1 in `bench_tokenization.cpp` and 1 in `test_package.cpp` before and after. Zero differences, so zero census decisions. Two of the three files also sit outside `malf lint` by the standing law @@ -2825,9 +2825,9 @@ count. The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), -`CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and -`INV-17-EXEMPT-OBJECT-STORE` (`pin_coherence.py`) — plus `clang-format off`, `wall-clock:`, SPDX and +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (the `log_seat_routing` check module), +`CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and +`INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module) — plus `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. **Every one has a population of ZERO in these three files.** `NOLINT` before **2**, after **0**, and the decision is measured rather than argued. @@ -3012,9 +3012,9 @@ After: **175 comment lines, 0 would-be violations** — `pre` 3 · `post` 4 · ` The census was derived from the gates rather than read off the step's list: every marker constant in the superproject's `scripts/` that is read out of **comment text** — `DETERMINISM-ALLOW` -(`random_determinism_lint.py`, `wallclock_lint.py`), `LOG-SEAT-ALLOW` (`log_seat_routing_lint.py`), -`CLOSURE MODEL` (`closure_declaration_lint.py`), `pin-coherence: mirrors` and -`INV-17-EXEMPT-OBJECT-STORE` (`pin_coherence.py`), plus two this run added by enumerating the +(the `random_determinism` and `wallclock` check modules), `LOG-SEAT-ALLOW` (the `log_seat_routing` check module), +`CLOSURE MODEL` (the `closure_declaration` check module), `pin-coherence: mirrors` and +`INV-17-EXEMPT-OBJECT-STORE` (the `pin_coherence` check module), plus two this run added by enumerating the same directory — `retired-structure-lint: allow` (`retired_structure_lint.py`) and `registry-lint: allow` (`registry_grammar_lint.py`) — and `clang-format off`, `wall-clock:`, SPDX and the `/*name*/` forms. This repo's own five gate scripts were read too @@ -4289,15 +4289,17 @@ only units whose codes are citations. The step's three-part branch (create the directory, a roster README **and** a superproject `ShelfRuling` row) does **not** apply here, and that was checked rather than taken on the brief's -word. `scripts/docs_lint.py`'s `ShelfRuling("insight-canon", SHELF_TREE_PART, ROSTER, …)` covers the +word. The `docs` check module's `ShelfRuling("insight-canon", SHELF_TREE_PART, ROSTER, …)` covers the whole `technical_docs` tree recursively, so a new `operations/` subdirectory holding one file needs -no row — only a roster entry. Proven falsifiable: with the entry removed, `docs_lint` exits 1 and +no row — only a roster entry. Proven falsifiable: with the entry removed, the `docs` check exits 1 and names the file (*"does not link `operations/ccc_migration.md`, which is tracked under this shelf"*); with it, exit 0. Tracked-doc population 142 → 143. -**One trap worth adding to the step, met here:** these gates must be run from the workspace ROOT. -Run from inside the repo, `python3 scripts/docs_lint.py` exits 2 for a missing file, and an operator -reading only the exit code sees a red gate rather than a mistyped path. +**One trap worth adding to the step, met here:** these gates must be run from the superproject +ROOT, as `./pharos check --module docs`. Run from inside this repo, the same command has no `pharos` +to find and fails as a mistyped path, and an operator reading only the exit code sees a red gate +rather than a mistyped path. (At the time of this run the gate was the script `docs_lint.py`, since +deleted; the `docs` check module is its whole content.) ## 7. The census token is a DIRECTIVE, not the string `NOLINT` @@ -4649,8 +4651,8 @@ fail once"* is what turned it up. `OPS-8.S4` says to derive the census from the gates the repo runs and calls its own list a floor. Taken literally on `insight-canon` — enumerate `scripts/`, read each instrument's opt-out constant — it yields **three markers the list does not name**, all read from COMMENT TEXT by live superproject -gates: `log_seat_routing_lint.py`'s seat opt-out, `closure_declaration_lint.py`'s closure-model -declaration, and `pin_coherence.py`'s mirror marker. The first is the sharpest of the three, because +gates: the `log_seat_routing` check module's seat opt-out, the `closure_declaration` check module's closure-model +declaration, and the `pin_coherence` check module's mirror marker. The first is the sharpest of the three, because its scan globs cover `.cpp`/`.cppm` and exclude only tests, benchmarks and build trees — a CCC unit under `src/`, `api/` or `tools/` sits squarely inside its surface, and the CCC grammar does not list its token, so a strip would delete it exactly as the determinism waiver was deleted. @@ -5061,7 +5063,7 @@ easy to break while trying to be polite about a contended resource. ## Two census tokens checked in this repo on a sibling lane's measurement, both with a population of ZERO -* **The determinism waiver token** that `wallclock_lint.py` and `random_determinism_lint.py` read — +* **The determinism waiver token** that the `wallclock` and `random_determinism` check modules read — which the CCC grammar does not list, so the stripper deletes it silently, and a sibling lane measured a gate going from PASS to FAIL after one was stripped. **Swept over `insight-canon`'s whole source tree: zero occurrences**, so neither unit of this run could have deleted one. Census