Skip to content

feat: land the contractiles tree vendored in reposystem (147 files, incl. the contractile CLI) - #68

Merged
hyperpolymath merged 1 commit into
mainfrom
feat/land-vendored-contractiles
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
feat/land-vendored-contractiles

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Summary

This PR moves the contractiles tree that reposystem vendored into this repo. Until now that content existed only in reposystem's history, at hyperpolymath/reposystem@845679600b292e86c0389401c9d59671565be6bc^:contractiles/. That is the parent of the 2026-06-21 commit 845679600b29 ("extract the 5 local-only standalones to gitlinks"), which deleted the 236-file vendored directory and left a gitlink pointing here. None of the 236 files had ever reached this repo.

Authority: the owner's 2026-10-09 ruling on the empty/template-repo census ("they should all be standalone rsr-template-repos … get that stuff out"). The census and the ruling are in dev-notes/administration/estate-management/empty-template-repo-census-2026-10-09/.

This PR conflicts with ADR-0002, so it needs your eye. ADR-0002 (docs/decisions/0002-contractile-cli-spec-first.adoc, status Proposed) and the 2026-10-03 audit (docs/reports/audit/contractile-cli-audit-2026-10-03.adoc §E2) both say there is "no cli/" and that the CLI "existed in an unpublished local checkout and was lost, or never existed". That premise is false. The CLI is the 20-file Rust workspace at reposystem@845679600b29^:contractiles/cli/, and this PR lands it as cli/.

  • It builds and runs. contractile --help lists must, trust, dust, intend, adjust, k9, gen-just, init and status.
  • It is inert here. Its CI hook was the vendored .github/workflows/contractile.yml, which this PR does not land, so no workflow invokes the binary.
  • This PR does not edit ADR-0002 or the audit. Whether their text gets corrected, and whether the CLI stays where it lands, is an RFC-0001 ratification call.

Auto-merge is deliberately not armed. The only required context here is scan / gitleaks, which goes green within seconds of opening. Arming would merge a 22k-line PR that conflicts with an ADR before anyone reads it, so it waits for a human merge.

Changes

  • 147 files landed verbatim, at their vendored paths:
    • cli/ (20): Rust workspace, crates contractile and contractile-core, with Cargo.lock;
    • mustfile/ (54): the Mustfile runner project (Ada/SPARK, shell launchers, man page, spec);
    • runners/ (57): per-verb runners (must/ is a full Rust + Ada project; trust/, intend/, just/, bust/ READMEs);
    • config/ (5), policy/ (2), keys/signing.pub (an Ed25519 public key), schema/version.txt;
    • dustfile/, intentfile/ and trustfile/ spec docs;
    • docs/A2ML-FORMAT.adoc, docs/CLI-REFERENCE.adoc, scripts/check-6scm.sh, .flux/README.adoc.
  • .machine_readable/root-allow.txt: 11 new top-level entries, under one dated comment naming their source. Paths stay as vendored so their origin can be traced; moving them is a ratification-time decision.
  • The 24 paths both trees share keep this repo's version. These include README.adoc (this repo's spec-first self-description, 80 lines, not the vendored 298-line one), docs/QUICKSTART.adoc, MAINTAINERS.adoc, Justfile, LICENSE and the workflows. This PR modifies no existing file except root-allow.txt.
  • 65 vendored files not landed:
    • 13 .a2ml files. A2ML is retired (D99/D269c), and D313 forbids hand conversion. These are the contractile declarations themselves, recoverable at reposystem@845679600b29^, pending kcX:
      • must/Mustfile.a2ml, trust/Trustfile.a2ml, intend/Intentfile.a2ml;
      • contractiles/{dust/Dustfile,must/Mustfile,trust/Trustfile}.a2ml;
      • runners/must/0-AI-MANIFEST.a2ml;
      • runners/must/.machine_readable/6a2/{AGENTIC,ECOSYSTEM,META,NEUROSYM,PLAYBOOK,STATE}.a2ml.
    • 27 .github/ files and 1 .claude/ file: vendored CI and agent config. This repo has its own.
    • 24 template/scaffold files: each blob is in template history or in ≥3 estate repos, so nothing is lost. Examples: CODE_OF_CONDUCT.md, ROADMAP.adoc, ffi/zig/*, contractile.just, contractiles/*/README.adoc, runners/must/STATE.adoc.
  • Accounting: 147 landed + 65 not landed + 24 shared = 236 vendored.

📌 New pins

  • Head SHA: b1a57f16dea9d1cf9ceea8d85aad1c5c9e004a80
  • cli/Cargo.lock is new: 72 package records, unchanged from the vendored copy. cargo test --locked resolves against it.
  • No action uses: SHAs, actions.lock entries or container digests are added or changed.

RSR Quality Checklist

Required

  • Tests pass. cargo test --locked in cli/: 8 passed, 0 failed. The Ada/SPARK code in mustfile/ and runners/must/ was not built or tested in this PR.

  • Code is formatted. Not done, on purpose: cargo fmt --check in cli/ exits 1, and the code is landed byte-for-byte so it matches its source sha. Formatting is a follow-up commit, kept separate so this diff stays a pure copy.

  • Linter is clean. cargo clippy --locked in cli/ printed no warnings or errors.

  • No banned language patterns. The landing has no TypeScript, package.json, bun/npm lockfiles, Go or Python. mustfile/scripts/shells/ holds one launcher per shell, including .ps1 and .cmd.

  • No unsafe blocks. Both crates declare #![forbid(unsafe_code)].

  • No banned functions. A grep for believe_me, unsafeCoerce, Obj.magic, Admitted and sorry over the 147 files found none.

  • SPDX headers on all new files. 31 landed files lack one, kept verbatim:

    • runners/must/src/{manifest,rollback,state,task}.rs;
    • runners/must/Cargo.toml and the mustfile.toml fixtures;
    • runners/must/SPARK-*.md;
    • several README.adoc/INSTALL.adoc files;
    • scripts/check-6scm.sh.

    The rest carry PMPL-1.0-or-later. Note that cli/Cargo.toml declares license = "MPL-2.0" while its sources say PMPL-1.0-or-later; that mismatch is vendored, not introduced here.

  • No secrets. gitleaks detect --log-opts=origin/main..HEAD found no leaks. keys/signing.pub is a public key.

As Applicable

  • .machine_readable/6a2/STATE.a2ml updated. N/A: A2ML is retired, so no .a2ml file is added or edited.
  • .machine_readable/6a2/ECOSYSTEM.a2ml updated. N/A, same reason.
  • .machine_readable/6a2/META.a2ml updated. N/A, same reason. The ADR conflict is stated above instead.
  • Documentation updated. Not updated: README.adoc keeps this repo's version on purpose. The landed docs/CLI-REFERENCE.adoc documents the CLI.
  • TOPOLOGY.md updated. N/A: there is no TOPOLOGY.md at the root.
  • CHANGELOG updated. Not updated; I'd rather the owner word that entry once the ADR question is settled.
  • New dependencies reviewed. The cli/ crates (clap, clap_complete, anyhow, serde, serde_json, colored, toml) are MIT/Apache-2.0, which is compatible.
  • ABI/FFI changes validated. N/A: src/interface/ is not touched. The vendored ffi/zig/ stub was not landed (it is template scaffold).

Testing

git ls-files -o --exclude-standard | sort | comm -3 - <landing list>   # empty: landed set == planned set (147)
git diff --cached --name-only --diff-filter=A | grep -c '\.a2ml$'      # 0
bash scripts/check-root-shape.sh .        # PASS: root matches allowlist (55 entries, 69 permitted)
bash scripts/check-no-md-in-docs.sh .     # PASS
standards/.githooks/docstring-scan.sh --staged   # 0 shell functions; .rs/.adb are outside the scanner's languages (skipped=109)
gitleaks detect --log-opts=origin/main..HEAD     # no leaks found
(cd cli && cargo test --locked)           # 8 passed
(cd cli && cargo clippy --locked)         # clean
(cd cli && cargo fmt --check)             # rc=1 (verbatim vendored formatting; see checklist)

main at d440161 is already red on Dogfood Gate, Governance, Static Analysis Gate and Well-Known Standards, and CodeQL ends in startup_failure. Any of those that is red here was red before this PR.

Screenshots

$ ./cli/target/debug/contractile --help
Contractile — unified runner for Must/Trust/Dust/Intend/K9 contract files.
Usage: contractile [COMMAND]
Commands: must trust dust intend adjust k9 gen-just init status

🤖 Generated with Claude Code

https://claude.ai/code/session_01BbkZgW7JLugsZ5MhRjF8iE

Lands 147 files from hyperpolymath/reposystem@8456796^:contractiles/
(the parent of the 2026-06-21 commit that replaced the vendored directory
with a gitlink). Until now the content existed only in reposystem history.

Landed verbatim at their vendored paths: cli/ (Rust workspace, crates
contractile + contractile-core), mustfile/, runners/, config/, policy/,
keys/, schema/, the dust/intent/trust spec docs, docs/A2ML-FORMAT.adoc,
docs/CLI-REFERENCE.adoc, scripts/check-6scm.sh, .flux/README.adoc.

Not landed: vendored .github/, .claude/, .machine_readable/, every *.a2ml
(A2ML is retired; D313 forbids hand conversion), and the template
scaffold on every path both trees share. This repo's version wins on all
24 shared paths.

.machine_readable/root-allow.txt gains the 11 new top-level entries,
with a comment giving where they came from.

Authorised by the owner's 2026-10-09 ruling on the empty/template repo
census ("get that stuff out").

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BbkZgW7JLugsZ5MhRjF8iE
@coderabbitai

coderabbitai Bot commented Oct 9, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Too many files!

This PR contains 146 files, which is 46 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 6c60915f-ef07-4d98-8f75-3ec4bd509644

📥 Commits

Reviewing files that changed from the base of the PR and between d440161 and b1a57f1.


⛔ Files ignored due to path filters (2)
  • cli/Cargo.lock is excluded by !**/*.lock
  • keys/signing.pub is excluded by !**/*.pub

📒 Files selected for processing (146)
  • .flux/README.adoc
  • .machine_readable/root-allow.txt
  • cli/Cargo.toml
  • cli/crates/contractile-core/Cargo.toml
  • cli/crates/contractile-core/src/a2ml.rs
  • cli/crates/contractile-core/src/just_emitter.rs
  • cli/crates/contractile-core/src/k9.rs
  • cli/crates/contractile-core/src/lib.rs
  • cli/crates/contractile-core/src/toml_compat.rs
  • cli/crates/contractile/Cargo.toml
  • cli/crates/contractile/src/adjust.rs
  • cli/crates/contractile/src/doctor.rs
  • cli/crates/contractile/src/dust.rs
  • cli/crates/contractile/src/gen_just.rs
  • cli/crates/contractile/src/init.rs
  • cli/crates/contractile/src/intend.rs
  • cli/crates/contractile/src/k9_cmd.rs
  • cli/crates/contractile/src/main.rs
  • cli/crates/contractile/src/must.rs
  • cli/crates/contractile/src/status.rs
  • cli/crates/contractile/src/trust.rs
  • config/attestation.ncl
  • config/canary.ncl
  • config/policy.yaml
  • config/tpm.toml
  • config/tracing.toml
  • docs/A2ML-FORMAT.adoc
  • docs/CLI-REFERENCE.adoc
  • dustfile/docs/dust-spec.adoc
  • intentfile/docs/intent-spec.adoc
  • mustfile/CHANGELOG.adoc
  • mustfile/Containerfile
  • mustfile/INSTALL.adoc
  • mustfile/Justfile
  • mustfile/Mustfile
  • mustfile/README.adoc
  • mustfile/ROADMAP.adoc
  • mustfile/cookbook.adoc
  • mustfile/docs/ROADMAP.adoc
  • mustfile/docs/case-studies/flatracoon-netstack.adoc
  • mustfile/docs/man/must.1
  • mustfile/docs/must-spec.adoc
  • mustfile/must.gpr
  • mustfile/mustfile.toml
  • mustfile/scripts/bootstrap.sh
  • mustfile/scripts/shells/README.adoc
  • mustfile/scripts/shells/entrypoint.ash
  • mustfile/scripts/shells/entrypoint.bash
  • mustfile/scripts/shells/entrypoint.cmd
  • mustfile/scripts/shells/entrypoint.csh
  • mustfile/scripts/shells/entrypoint.dash
  • mustfile/scripts/shells/entrypoint.elvish
  • mustfile/scripts/shells/entrypoint.fish
  • mustfile/scripts/shells/entrypoint.ion
  • mustfile/scripts/shells/entrypoint.ksh
  • mustfile/scripts/shells/entrypoint.minix
  • mustfile/scripts/shells/entrypoint.murex
  • mustfile/scripts/shells/entrypoint.ngs
  • mustfile/scripts/shells/entrypoint.nu
  • mustfile/scripts/shells/entrypoint.oil
  • mustfile/scripts/shells/entrypoint.ps1
  • mustfile/scripts/shells/entrypoint.tcsh
  • mustfile/scripts/shells/entrypoint.tsh
  • mustfile/scripts/shells/entrypoint.zsh
  • mustfile/src/cli/cli_parser.adb
  • mustfile/src/cli/cli_parser.ads
  • mustfile/src/config/mustfile_loader.adb
  • mustfile/src/config/mustfile_loader.ads
  • mustfile/src/config/toml_parser.adb
  • mustfile/src/config/toml_parser.ads
  • mustfile/src/deploy/deployer.adb
  • mustfile/src/deploy/deployer.ads
  • mustfile/src/must.adb
  • mustfile/src/must_types.adb
  • mustfile/src/must_types.ads
  • mustfile/src/requirements/requirement_checker.adb
  • mustfile/src/requirements/requirement_checker.ads
  • mustfile/src/tasks/task_runner.adb
  • mustfile/src/tasks/task_runner.ads
  • mustfile/src/templates/mustache_engine.adb
  • mustfile/src/templates/mustache_engine.ads
  • mustfile/templates/ada/package.adb.mustache
  • mustfile/templates/ada/package.ads.mustache
  • mustfile/templates/elixir/module.ex.mustache
  • policy/policy.json
  • policy/policy.ncl
  • runners/bust/README.adoc
  • runners/intend/README.adoc
  • runners/just/README.adoc
  • runners/must/.gitignore
  • runners/must/CHANGELOG.adoc
  • runners/must/Cargo.toml
  • runners/must/Containerfile
  • runners/must/INSTALL.adoc
  • runners/must/Justfile
  • runners/must/LICENSE.txt
  • runners/must/MAINTAINERS.adoc
  • runners/must/Mustfile
  • runners/must/README.adoc
  • runners/must/ROADMAP.adoc
  • runners/must/SPARK-CLI-PARSER-COMPLETE.md
  • runners/must/SPARK-CONVERSION-COMPLETE.md
  • runners/must/SPARK-CONVERSION-SESSION-2026-02-05.md
  • runners/must/SPARK-MUSTACHE-ENGINE-COMPLETE.md
  • runners/must/SPARK-REQUIREMENT-CHECKER-COMPLETE.md
  • runners/must/SPARK-STATUS.md
  • runners/must/SPARK-TASK-RUNNER-COMPLETE.md
  • runners/must/fixtures/content-project/README.adoc
  • runners/must/fixtures/content-project/mustfile.toml
  • runners/must/fixtures/failing-project/README.adoc
  • runners/must/fixtures/failing-project/mustfile.toml
  • runners/must/fixtures/fix-project/README.adoc
  • runners/must/fixtures/fix-project/mustfile.toml
  • runners/must/fixtures/sample-project/README.adoc
  • runners/must/fixtures/sample-project/mustfile.toml
  • runners/must/license/PMPL-1.0.txt
  • runners/must/must.gpr
  • runners/must/mustfile.ncl
  • runners/must/mustfile.toml
  • runners/must/scripts/bootstrap.sh
  • runners/must/src/cli/cli_parser.adb
  • runners/must/src/cli/cli_parser.ads
  • runners/must/src/config/mustfile_loader.adb
  • runners/must/src/config/mustfile_loader.ads
  • runners/must/src/config/toml_parser.adb
  • runners/must/src/config/toml_parser.ads
  • runners/must/src/deploy/deployer.adb
  • runners/must/src/deploy/deployer.ads
  • runners/must/src/manifest.rs
  • runners/must/src/must.adb
  • runners/must/src/must_types.adb
  • runners/must/src/must_types.ads
  • runners/must/src/mustfile.ncl
  • runners/must/src/requirements/requirement_checker.adb
  • runners/must/src/requirements/requirement_checker.ads
  • runners/must/src/rollback.rs
  • runners/must/src/state.rs
  • runners/must/src/task.rs
  • runners/must/src/tasks/task_runner.adb
  • runners/must/src/tasks/task_runner.ads
  • runners/must/src/templates/mustache_engine.adb
  • runners/must/src/templates/mustache_engine.ads
  • runners/trust/README.adoc
  • schema/version.txt
  • scripts/check-6scm.sh
  • trustfile/docs/trust-spec.adoc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
C Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

@hyperpolymath
hyperpolymath merged commit a0b5619 into main Oct 9, 2026
37 of 42 checks passed
@hyperpolymath
hyperpolymath deleted the feat/land-vendored-contractiles branch October 9, 2026 13:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant