Skip to content

fix(gitleaks): estate baseline — a documentation filename is not a secret - #1087

Merged
hyperpolymath merged 3 commits into
mainfrom
fix/gitleaks-baseline-doc-filename-value
Oct 1, 2026
Merged

hyperpolymath merged 3 commits into
mainfrom
fix/gitleaks-baseline-doc-filename-value

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

What

This PR adds one anchored value entry to the estate gitleaks baseline. It says that a value which is exactly one .adoc or .md filename is not a secret:

^[A-Za-z0-9][A-Za-z0-9._-]*\.(adoc|md)$

Why

generic-api-key fires on a prose record in echo-types' machine-readable STATE record. The record's key contains an auth-like word, and its quoted value starts with a doc filename, so gitleaks captures the filename as the "secret". That false positive has kept scan / gitleaks red on echo-types main since 2026-09-27, and it is the only red check on hyperpolymath/echo-types#331, the fix for echo-types#329.

echo-types has no .gitleaks.toml. Its secret-scanner reusable therefore fetches this baseline from standards ref: main, so the fix reaches echo-types on its next run with no edit there.

This is the arm the owner ruled on 2026-09-30: fix the baseline first, then file the a2ml→deed template issue, then delete echo-types' .a2ml records.

Evidence (CI-pinned gitleaks 8.18.4, tarball sha256 verified)

run findings
mutant: baseline without the entry, echo-types tree 1
cure: baseline with the entry, echo-types tree 0
control fixture without the entry lines 1, 2
control fixture with the entry line 1 only, the real-looking token is still caught
standards' own tree (.gitleaks.toml extends the baseline), before / after 0 / 0

Config and reports were kept outside --source, per the instrument trap in the file header. The new comment describes the shape instead of quoting the triggering line, per the rule at the top of the regexes list.

Estate-wide admission: no credential format ends in .adoc or .md, and the character class has no /, so it names one file, never a path or a blob. The commit carries a column-0 Ratchet-exception line naming the baseline, so the growth is attributed. The ratchet's ledger list itself does not include this file.

Merge

This PR needs an owner merge. Standards requires "SonarCloud Code Analysis", which never reports here, so agent merges are denied.

🤖 Generated with Claude Code

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57

…cret

Add one anchored VALUE entry to config/gitleaks/estate-baseline.toml:
  ^[A-Za-z0-9][A-Za-z0-9._-]*\.(adoc|md)$

generic-api-key keys on an `auth`-like word in a prose record's key and
captures the doc filename in its quoted value as the "secret". Found in
echo-types (.machine_readable/6a2 STATE record), where it has red
`scan / gitleaks` on main since 2026-09-27 and on PR #331 (echo-types#329).
echo-types has no .gitleaks.toml, so the secret-scanner reusable fetches this
baseline from standards `ref: main` and the cure reaches it on its next run.

Measured on the CI-pinned gitleaks 8.18.4 (tarball sha256 verified):
  mutant  baseline without the entry, echo-types tree   1 finding
  cure    baseline with the entry,    echo-types tree   0 findings
  control fixture: a real-looking token beside a filename record —
          without the entry lines 1,2 flagged; with it, line 1 only
  standards own tree (.gitleaks.toml extends the baseline): 0 before, 0 after
Config and reports kept outside --source (the instrument trap in the header).

Estate-wide admission: no credential format ends in .adoc or .md and the
class admits no `/`, so it names one file, never a path or a blob. The
comment describes the shape rather than quoting the triggering line.

Ratchet-exception: config/gitleaks/estate-baseline.toml — one anchored value entry (doc filename), owner-ruled 2026-09-30 as the echo-types #331 cure; see commit body for mutant/cure/control

Refs: hyperpolymath/echo-types#329, hyperpolymath/echo-types#331

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 54 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 130c0b90-f5ec-4344-9131-efc63cabb795

📥 Commits

Reviewing files that changed from the base of the PR and between 3c5bf1e and 17abf7a.

📒 Files selected for processing (1)
  • config/gitleaks/estate-baseline.toml
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

hyperpolymath added a commit to hyperpolymath/echo-types that referenced this pull request Sep 30, 2026
## What this does

Deletes the 27 tracked `.a2ml` records from echo-types, by owner ruling
of 2026-09-30 (booked as D222 on hyperpolymath/standards#787). Per the
owner, `STATE.a2ml` should not exist any more because the estate moved
to `.deed` records with `.k9` and coordination.

- **Removed:** `.machine_readable/6a2/*.a2ml` (7), `agent_instructions/`
(3), `anchors/` (1), `bot_directives/` (3), `contractiles/*.a2ml` (6),
`integrations/` (5), root `0-AI-MANIFEST.a2ml`,
`audits/assail-classifications.a2ml`.
- **History stays reachable.** Every retired directory keeps a
`README.adoc` notice that permalinks the frozen tree at
39a7a99. `.github/CONTRIBUTING.md`
items 3, 6 and 7 now point at the frozen `STATE.a2ml` sections instead
of a live file.
- **K9 guard.** `methodology-guard.k9.ncl` loses its three checks that
inspected the deleted records (`state_not_template`,
`anchor_clade_not_fabricated`, `coverage_updated`). A check aimed at a
deleted file is a false check. The proof-discipline checks stay.
- **CHANGELOG.adoc** gains a dated Removed entry.

## Checks run locally

| check | result |
|---|---|
| `nickel typecheck` edited guard | rc=0 |
| `nickel typecheck` original guard (control) | rc=0 |
| `nickel typecheck` truncated mutant | rc=1 |

## Known tension, recorded not hidden

Ruling D43 on hyperpolymath/rsr-template-repo#209 says held `.a2ml`
sweeps resume "as conversions, never as in-place edits". This PR is a
deletion, not a conversion, by the owner's explicit order. The template
side and the `.deed` conversion stay with #209; see the comment there
dated today.

An org-wide code search counted 109 files outside echo-types that name
`STATE.a2ml`. None is a CI gate that echo-types calls: the pinned
governance reusable references only `Debtfile.a2ml`, which echo-types
never had.

## Left for the `.deed` conversion

Prose mentions remain in `.gitattributes`,
`.machine_readable/self-validating/`,
`.machine_readable/svc/k9/README.adoc`, CLAUDE.md, GOVERNANCE, INDEX,
PROOF-STATUS, QUICKSTART-DEV/MAINTAINER, TOPOLOGY, roadmap,
`docs/.../decoration-bridge/README.adoc`, a comment in
`proofs/agda/EchoDecorationBridge.agda`, and the wiki.
`self-validating/examples/setup-repo.k9.ncl` still writes a new `.a2ml`;
that example belongs to the template lane.

## Relation to #331

Removing `STATE.a2ml` also removes the prose line that gitleaks'
`generic-api-key` rule misread as a secret on #331.
hyperpolymath/standards#1087 cures the same false positive at the
baseline, independently.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
@coderabbitai

coderabbitai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Autopilot could not be updated. Open Coding to check access and billing.

@hyperpolymath
hyperpolymath merged commit 9f0a8be into main Oct 1, 2026
49 checks passed
@hyperpolymath
hyperpolymath deleted the fix/gitleaks-baseline-doc-filename-value branch October 1, 2026 14:44
hyperpolymath added a commit that referenced this pull request Oct 1, 2026
…isioning modes (#1112)

**Supersedes #1096.** The content is identical, rebuilt on current
`main` as one signed commit.

## Why a replacement
- **Unsigned commits.** Two docstring commits pushed by
`coderabbitai[bot]` (`71cad01f`, `18dcefa2`) were unsigned.
`required_signatures` refuses a PR that has any unsigned commit on its
head, even under squash (`docs/SIGNING-POLICY.adoc` § *Squash signs the
result, not the PR branch*). Their content (docstrings, now 74/74
covered) is kept.
- **Rebuild.** `git merge --squash origin/feat/provisioning-canon` onto
`origin/main`, then `git commit -S`. `git diff 18dcefa HEAD` shows only
main's later #1087/#1098 files plus the delta below. The original commit
list is in the commit message.

## Delta vs #1096: Hypatia `eval_in_shell` false positives
#1096's `Hypatia` code-scanning check and `governance / Validate Hypatia
Baseline` were red on 4 `content_patterns/eval_in_shell` findings
(`provision-check.sh:23`, `provision-lib.sh:867,868,944`). The rule is a
bare `\beval\b`, and every hit is the **word**: the `eval` verb name, or
the `.eval/` directory. None is the shell builtin.

The fix is an inline `# hypatia:ignore eval_in_shell -- <reason>` pragma
on each line, not baseline entries:
- `HYPATIA-BASELINE-FORMAT.adoc` lists "single new findings on
freshly-introduced code" as a bad baseline entry, and the baseline is a
ratcheted exemption ledger.
- These files are templates minted into other repos. The pragma travels
with them; a standards-only baseline entry would not.
- 3 comment lines that newer hypatia (`4065424`) also flags are pragma'd
too, so a scanner bump does not turn this red again.

**Control:** local `hypatia@4065424 scan` over the two files reports
**7** `eval_in_shell` findings on #1096's version and **0** on this
branch. `bash -n` is clean for both scripts. Upstream rule precision is
tracked upstream in hyperpolymath/hypatia#892 (`eval_in_shell` matches
the word, not the builtin in command position).

CodeRabbit's last `CHANGES_REQUESTED` (the `launcher.sh.tmpl` header
saying modes delegate to the Justfile) is already addressed in this
content: l.25–29 say provisioning modes call
`build/just/provision-lib.sh` directly.

---

## Original description (#1096)

## What

Phase 1 of the estate provisioning campaign. This PR is the canon every
repository will be minted from, so that nobody who clones a repo has to
search for how to install, configure, run, test, bench, diagnose or
repair it.

**New: `3-practice/provisioning/`**
- `PROVISIONING-STANDARD.adoc` (v1.0.0) and
`provisioning-standard_praxis.deed` (lints OK)
- **Engine**, identical estate-wide:
  - `provision.just`: the `provision::` module with every verb
  - `provision-lib.sh`: bash only, shellcheck clean
  - `provision-modes.sh`: the launcher dispatch
- `provision-check.sh`: the offline conformance checker, covering §8
items 1–5
- **Minted templates:**
  - `launcher.sh.tmpl`
  - `mise.toml` (latest plus `mise.lock`)
- Guix: a `cargo-build-system` package for Rust, a `copy-build-system`
source package for everything else, plus `manifest.scm` and a pinned
`channels.scm`
- `docs/SETUP.adoc`, the manual route, with a doctor-code
troubleshooting table
  - `docs/AI_INSTALLATION_GUIDE.adoc`
  - `llm-warmup-{user,dev,maintainer}.adoc`
- the README `[[ai-install]]` "Just say it" fragment (the neurophone
pattern)
  - the per-repo `provisioning_praxis.deed`

**Launcher standard 0.6.0** (`launcher-standard.adoc` and
`launcher-standard_praxis.deed`)
- Every repository carries a `launcher.sh`, profiled by archetype. Only
`app` has runtime modes; the others print N/A and exit 0.
- `--setup`, `--doctor`, `--heal` and `--ai-setup` call the engine
directly (`build/just/provision-lib.sh`), so a repo's own root
`doctor`/`setup`/`heal` recipe cannot shadow the canon.
- Repo-specific checks live in the `doctor-local`, `setup-local` and
`heal-local` recipes. A failing `doctor-local` is FAIL PV-E50.

**`guix.scm`:** the licence field was a malformed ad-hoc licence object
pointing at palimpsest-license. It is now `mpl2.0` from `(guix
licenses)`, which is the licence the file's own SPDX header already
declares. No licence changes.

## Verified
- `deed_lint.py`:
- OK on `launcher-standard_praxis.deed` and
`provisioning-standard_praxis.deed`
  - OK on a filled instance of the per-repo deed template
- Shellcheck is clean on the engine scripts.
- `provision-check.sh` fixture:
  - The positive control gives rc=0.
- 9 mutants each fail on exactly their own check: launcher not
executable, root verb missing, module verb missing, banned `python`,
banned `aqua:denoland/deno`, no `mise.lock`, guix stub, mechanical slot
residue, README SPEC residue.
  - `--dev` downgrades SPEC residue to a WARN.
- doctor-local, in a scratch repo:
- A failing `doctor-local` gives PV-E50 and rc=1 via both `./launcher.sh
--doctor` and `just doctor`.
- A root `doctor` that prints fake green is not executed by `--doctor`.
- just floor 1.42.0, measured: a root recipe depending on a module
recipe fails on 1.31, 1.36, 1.40 and 1.41.
- Guix, via `podman` with `metacall/guix` at ae77aeb: the Rust source
package derivation builds (`guix build -d`, rc=0). The non-Rust
derivation and the real build were still running when this PR was
opened.

## Known, not introduced here
- The standards-map gate (Gate D) is already red on `main`, with 5
unmapped top-level entries: `arena-session-787`, `patches`,
`ULTRAPLAN-2026-09-24.adoc`, `ULTRAPLAN-2026-09-29.adoc` and `ziz-drop`.
This PR adds no top-level entry, because `3-practice` is already mapped.
- Dogfooding `mod provision` in this repo's own Justfile is deferred to
the pilot phase.

## Update: review round (head b234caf)

**Commits since opening**

- **206eb6c4 — one placement resolver.**
- Each Guix template resolves the repository root from its own location,
so a repo can keep the files at the root or under `build/`. This
resolves the CodeRabbit placement thread.
  - Zig is detected up to 3 directories down.
- **39b790f5 — no faked zig/bun tests.**
  - A language with no test command prints an honest N/A.
- There is now one AI-install sentence, read from the README by
`ai-setup`.
- **eaf3a894 — new `fmt-check` verb, the check-only twin of `fmt`.**
- Per language: `cargo fmt --check`, `zig fmt --check`, `mix format
--check-formatted`, `gleam format --check`, `dune build @fmt`, and bun's
`fmt-check` script.
  - `quality` now depends on this verb. Before, it silently ran `lint`.
- **b234caf5 — the remaining review findings.**
- `doctor-local.sh` now runs sourced in a subshell. An `exit` or a
tripped `set -e` is FAIL **PV-E51**, and the checks it completed still
count.
- `hp_provision_or_return` replaces `&& exit $?`, which reported success
for a failing mode.
  - The `ai-warmup` argument is now quoted.
  - trivy is pinned in mise only where a recipe calls it.
- The launcher currency constant is now 0.5.0 (0.6.0 after 094fd79,
below).

- **7e6f3db6 — `toolchain-refresh` regenerates
`build/guix/crates.scm`.**
- `guix.scm.cargo.tmpl` already promised this, but nothing implemented
it. The new lib verb `crates-scm` runs `guix import crate --lockfile`.
`GUIX` may name a container wrapper.
- The file is written whole or not at all. Output is accepted only when
it defines one origin per registry crate in `Cargo.lock`, because a
containerised guix loses its exit status. Otherwise the run fails with
the new code **PV-E41** and the old file stays. PV-E41 is in the deed,
the lib and the SETUP table: all three hold the same 28 codes.
  - Measured on launch-scaffolder's `Cargo.lock`:
    - 151/151 origins;
- `guix repl` gives `(length %crate-inputs)` = 151 and `origin?` = `#t`;
    - regeneration is byte-identical.
  - Mutants killed:
- truncated importer output (10/151): rc 1, PV-E41, file sha256
unchanged;
    - a failing importer (0/151): rc 1, PV-E41, file sha256 unchanged.
- **094fd798 — merge `main`; the provisioning modes are launcher
standard 0.6.0.**
- `main` took 0.5.0 for the `(js-runtime)` clause (D224, #1100). That
number is published with that meaning, so the archetype and provisioning
obligations move to **0.6.0** (2026-10-01). Updated together: the deed,
the `.adoc`, the currency gate's `CURRENT_VERSION`, the launcher
template and `provision-modes.sh`.
- A consumer still citing 0.5.0 gets the non-blocking stale-version
warning (standards#991), not a failure.
  - Checks:
    - currency test 19/19;
    - the gate on this tree: clean at v0.6.0;
    - `--self-test`: 4 mutants seeded, all detected.

**Measured on rsr-template-repo (the first consumer; that PR follows)**

- doctor-hook cases:

  | hook | PASS / WARN / FAIL |
  |---|---|
  | normal | 19 / 1 / 0 |
  | `exit 3` | 19 / 0 / 1 + PV-E51 |
  | `set -e; false` | 19 / 0 / 1 + PV-E51 |
  | `fail` | 18 / 0 / 1 |

- `./launcher.sh --doctor`: rc 0 when clean, rc 1 with a failing hook.
- `just doctor` 18/0/0, `just validate` pass, `provision-check --dev` 0
FAIL / 0 WARN, shellcheck clean.
- `fmt-check`: rc 0 on clean code; a mis-formatted mutant gives rc 1.
- Guix, via `metacall/guix` at ae77aeb:
  - `guix build -f guix.scm`: rc 0.
  - `guix shell -m manifest.scm --dry-run`: rc 0.
  - `channels.scm` evaluates to the same pinned commit.
- `just registry-check` OK. `check-launcher-standard-currency` OK.

**Red checks: none is a required check. Classified:**

- **Canon/spine lockstep and Map integrity** are already red on `main`:
the constitution hash, dogfood-gate, and the ULTRAPLAN /
arena-session-787 / patches / ziz-drop entries. #1088 fixes them.
- **Repo self-tests:**
  - This PR's `CURRENT_VERSION` drift is fixed in b234caf.
  - The docstring shallow-clone failure is also red on `main`.
- **Hypatia:** 6 `eval_in_shell` findings are false positives on the
`eval` *verb name*: a comment, the `.eval/` report directory, a `case`
label, and the verb list. Nothing here calls the builtin.
- **Deferred red checks, by context:** `governance / Validate Hypatia
Baseline`, `scan / Hypatia Neurosymbolic Analysis` and `Hypatia` →
hyperpolymath/hypatia#892. On 094fd79 the baseline gate kept exactly
six findings: `eval_in_shell` at `provision-check.sh:23` and
`provision-lib.sh:17,732,733,742,804`, all the *word* `eval`. The same
three checks are green on `main` 8cfad82. Renaming the user-facing
`eval` verb to satisfy the scanner would be the wrong arm.
- Fixed at source in hyperpolymath/hypatia#892, with acceptance criteria
and positive and negative controls.
  - Per the owner ruling, this is tracked as an issue, not a blocker.
  - The 3 `uuid-v7.yml` baseline findings are fixed by #1088.
- #1088 also touches `REGISTRY.a2ml`. If it merges first, regenerate the
registry here.

**Placement labels (elegance arm)**

- The engine is **vendored byte-identical** into each repo, and
`provision-set --check` will prove it is equal to canon. **This is the
elegant long-term arm.**
- Departure considered and rejected: fetching the engine at run time.
That would break offline and Guix-hermetic use and add a supply-chain
hop.
- **`channels.scm` is minted, not engine** (departure, labelled).
`toolchain-refresh` re-pins it per repo by design, so a byte-compare
would go red after every weekly refresh. Instead it is checked for a
40-hex commit pin.

## Update: one banned list, backends and bare names (heads b01a245,
bf7c97a)

Found by the 8-repo pilot (launch-scaffolder#67).

- **b01a245:**
- The deed's `:banned-tools` and the engine's `BANNED_TOOLS` had
diverged. They are now one 20-item list, plus a new `:banned-backends
("npm" "pipx" "pip" "go")`. launch-scaffolder tests that the deed and
the engine agree.
  - PV-W23 now reads `mise.toml`, `.mise.toml` and `.tool-versions`.
- A tool behind a banned backend is flagged whatever its name
(`npm:prettier`).
- Controls: `.tool-versions` python + `.mise.toml` `"npm:prettier"` →
`[python npm:prettier] rc=1`; clean → `[] rc=0`.
- **bf7c97a:** a bare name whose only registry backends are banned is
flagged too. `prettier` resolves only to `npm:prettier`.
  - The lookup uses `mise registry`, which works offline.
- Shells with no mise and names mise doesn't know are never flagged on a
guess.
- Controls: `prettier` → `[prettier] rc=1`; `shfmt`/`zig`/an unknown
`jest` → `[] rc=0`.
  - shellcheck is clean, and docstring coverage is 100%.
- Pilot gaps that are canon work but not fixed here are filed as #1107.

## Next
- the rsr-template-repo canon fix
- the `provision-set` generator and the `provisioning-check.yml` gate
- a pilot of about 8 repos, then fan-out in SET batches


🤖 Generated with [Claude Code](https://claude.com/claude-code)

https://claude.ai/code/session_01DAKujx2PXHcVSA7vncTNH1

Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant