Dev - #740
Closed
Brad-Edwards wants to merge 15 commits into
Closed
Conversation
…lation (#668) (#685) * Add realization-envelope membership/subsumption/witness relation (#668) Implement the deterministic relation over the #667 realization-envelope semantics (ADR-070, specs/formal/realization/envelope-semantics.md): - aces_contracts.realization_envelope: closed, versioned envelope expression contract (exact / enum / boolean / numeric-interval / governed-reference / record domains, scoped bindings, posture, closure, witness policy). Intentionally unpublished; schema carriage is a downstream sibling. - aces_sdl.realization_envelope (+ _realization_envelope_engine): member / subsumes / witness / generate_negative_probes over one shared domain and closure engine, with stable secret-free diagnostics. Membership requires validated instantiated SDL; subsumption is set inclusion on the admitted fragment; witnesses are deterministic and SDL-validated; closed envelopes yield out-of-envelope negative probes; the R2 overridability rule is enforced. - Unit + hypothesis property tests: membership decidable/deterministic, subsumption is set inclusion (reflexive/transitive, authority-scoped governed refs), witness in-envelope and deterministic, negative probes out-of-envelope. Backend-manifest carriage and retiring the #663 reference-scenario conformance bridge remain the explicitly-downstream siblings (ADR-070 §5). * Reduce realization-envelope relation complexity for SonarCloud Refactor the relation for the SonarCloud quality gate (new_violations=0) without behavior change: - Split domain-kind dispatch into aces_sdl._realization_envelope_domains (finite enumeration, subset, witness selection, out-of-envelope variation) as type-keyed dispatch tables, flattening the per-kind return/complexity that tripped S1142 / cognitive-complexity. - Extract membership / subsumption / witness / negative-probe loops into focused helpers; dispatch _is_singleton_domain and scalar_in_domain in aces_contracts via lookup tables. - Type value hints as DomainScalar / object (drop Any, S6542), use min() over sorted()[0] (S8517), set .issubset() over negated <= (S1940), move trailing comments to their own lines (S139). All 42 unit + property tests still pass; ~94% line coverage on the new modules. * chore(sdl): drop orphaned changelog.d fragment for #668 The repo migrated from towncrier changelog.d fragments to release-please (#682/#684); plan-rules now state "There is no changelog.d/". The #668 changelog entry is derived from the conventional PR title/commits by release-please, so the hand-written fragment is obsolete. * refactor(sdl): flatten nested ternary in envelope enum sort key Replace the nested conditional in _enum_sort_key with an if/elif/else to clear the last SonarCloud new-code violation (S3358). Behavior unchanged; all envelope relation tests still pass.
* Bump the github-actions group with 7 updates Bumps the github-actions group with 7 updates: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `6.0.2` | `7.0.0` | | [actions/setup-python](https://github.com/actions/setup-python) | `6.2.0` | `6.3.0` | | [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) | `8.0.0` | `8.3.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.2` | `7.0.1` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.3.0` | `8.0.1` | | [SonarSource/sonarqube-scan-action](https://github.com/sonarsource/sonarqube-scan-action) | `7.1.0` | `8.2.0` | | [googleapis/release-please-action](https://github.com/googleapis/release-please-action) | `4.4.1` | `5.0.0` | Updates `actions/checkout` from 6.0.2 to 7.0.0 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@de0fac2...9c091bb) Updates `actions/setup-python` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@a309ff8...ece7cb0) Updates `astral-sh/setup-uv` from 8.0.0 to 8.3.0 - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@cec2083...d31148d) Updates `actions/upload-artifact` from 4.6.2 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](actions/upload-artifact@ea165f8...043fb46) Updates `actions/download-artifact` from 4.3.0 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](actions/download-artifact@d3f86a1...3e5f45b) Updates `SonarSource/sonarqube-scan-action` from 7.1.0 to 8.2.0 - [Release notes](https://github.com/sonarsource/sonarqube-scan-action/releases) - [Commits](SonarSource/sonarqube-scan-action@299e4b7...7138816) Updates `googleapis/release-please-action` from 4.4.1 to 5.0.0 - [Release notes](https://github.com/googleapis/release-please-action/releases) - [Changelog](https://github.com/googleapis/release-please-action/blob/main/CHANGELOG.md) - [Commits](googleapis/release-please-action@5c625bf...45996ed) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: astral-sh/setup-uv dependency-version: 8.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: SonarSource/sonarqube-scan-action dependency-version: 8.2.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: googleapis/release-please-action dependency-version: 5.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> * ci: correct stale action pin comments in group bump Dependabot bumped the pinned SHAs but left two version comments on the previous major: - actions/checkout 9c091bb is v7.0.0 (comment said # v6) - SonarSource/sonarqube-scan-action 713881 is v8.2.0 (comment said # v7) Update the comments to match the pinned SHAs so the audit trail is accurate. No SHA changes; action behavior is unchanged. --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Brad Edwards <j.bradley.edwards@gmail.com>
Add example corpus non-vacuity guard
* feat(sdl): add DSL-115 authoring specificity helper * refactor(sdl): simplify specificity path resolver * refactor(sdl): narrow specificity sequence resolver
…ce (#711) * feat: add experiment authoring-input contract and MCP authoring surface Adds experiment-authoring-input-v1 (ExperimentSpecModel), a pre-run experiment specification that binds a task to a run plan (seeds, episode controls, red-variant selection, condition allocation) before execution. It is a separate input contract that references the archival experiment-core outputs rather than weakening them, mirroring how sdl-authoring-input-v1 relates to instantiated-scenario-v1. Ships a loader, MCP authoring tools (experiment_scaffold / experiment_validate / experiment_get_example), worked examples, fixtures, and a discovery test, with ADR-074 deciding the surface and amendments to ADR-055 and ADR-069. Closes #675 * test: cover experiment authoring loader/tools; cut MCP tool cognitive complexity Addresses the SonarCloud quality gate on PR #711: - Move experiment MCP tool bodies into module-level helpers so register() stays under the cognitive-complexity threshold (S3776). - Add tests/test_experiment_authoring.py covering the loader (parse/load/find), the MCP tool helpers, and the run-plan/red-variant model validators, raising new-code coverage.
Add ecosystem evolution governance policy
* fix: reject ambiguous SDL mapping keys * Fix SonarCloud findings (cycle 1)
* Publish configuration-bound libvirt realization envelopes * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings (cycle 2)
* Enforce TechVault realization disclosure * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings (cycle 2)
* feat(sdl)!: define canonical YAML source profile * refactor(sdl): satisfy source-profile quality gate * fix(sdl): make scalar validation branch explicit * fix: reconcile normative SDL catalogs (#734) * feat(libvirt): publish configuration-bound realization envelopes (#730) * Publish configuration-bound libvirt realization envelopes * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings (cycle 2) * fix: reconcile normative SDL catalogs * chore: trigger stacked PR checks
* feat(sdl)!: define canonical YAML source profile * refactor(sdl): satisfy source-profile quality gate * fix(sdl): make scalar validation branch explicit * fix: reconcile normative SDL catalogs * chore: trigger stacked PR checks * feat: enforce portable SDL identifiers * chore: trigger stacked PR checks * chore: retrigger stacked PR checks * fix: reconcile runtime contract boundaries * chore: trigger reconciled PR checks * Fix SonarCloud findings (cycle 1)
* feat(libvirt): add guest-observed realization probes (ASR-519) Populate the guest_observed evidence slot #714 reserved: concern-specific guest observers that boot a canonical appliance through the production apply path and read realized state from inside the guest (resource, network, content, account, service), freshness-bound to a per-run challenge, with typed redacted failures and verified teardown. - New guest-certified material configuration + realization envelope - Credential-free file-backed-serial guest fact transport (injected seam) - Guest-observing appliance builder + staged observer + observation gate - Evidence artifact + validator extended for guest-observed facts/binding; native-proof boundary (certifying flag) marks injected fakes non-certifying - Cleanup moved to a finally-path; operator command + AWS proof harness - Committed real-daemon evidence report (certifying: true) * fix(libvirt): resolve review + SonarCloud findings for guest-certified probes (ASR-519) - Reject duplicate singleton guest facts with a distinct diagnostic (+ tests) - Accept accounts with no supplemental groups (optional groups field, + test) - Native-proof boundary: guest artifacts carry a `certifying` flag (true only for the production driver); injected fakes are non-certifying (+ tests) - Cover the residual-guest-artifact cleanup fail-closed branch (+ test) - SonarCloud: rename passwd-named constant, dedupe literals, add type hints, reduce returns/cognitive complexity, wrap long lines - Regenerate the committed real-daemon evidence report from the final code
* ci: publish Sphinx docs to GitHub Pages Build the Sphinx site on every PR (breakage check) and deploy it to GitHub Pages on pushes to main. Actions are SHA-pinned to match the repo convention; Pages is enabled with the GitHub Actions build source. Non-strict build (the tree currently emits 63 pre-existing toctree/orphan warnings). * docs: connect all pages, add realization-envelope guide, build strict - New decisions/index.md globs every ADR + design/preflight note into the nav; root index no longer hand-lists ADRs (auto-includes future ones). - Connect the participant-backend-contracts research subdir (hidden toctree + root wiring). - New explain/reference/realization-envelopes.md: observation-strength ladder, the libvirt generic/techvault/guest-certified configurations, how guest-observed realization is proven, and how to reproduce the proof (verified against the envelope + carrier code). - Fix cross-tree links to specs/sdl/diagnostics.md (download role) and a stray transition in the SCN-010 report. - Build is now warning-clean; docs.yml runs sphinx-build -W --keep-going.
* Define associated artifact manifest contracts * Fix SonarCloud findings (cycle 1) * Fix SonarCloud findings (cycle 2)
…1) (#743) * refactor: split oversized modules and cut function complexity (MOD-001) The dev->main promotion (PR #740) failed SonarCloud's aces-strict quality gate with 9 new violations: 5 files over the 500-line S104 cap and 4 functions over cyclomatic complexity 10. Split each oversized module along a cohesive seam and decomposed each over-complex function into helpers. Moved symbols are re-imported into their original modules so every public import path and __all__ stays stable. No behaviour change; full nox verify green. Splits: - aces_sdl.parser -> _model_diagnostics (pydantic-error diagnostic rendering) - aces_sdl._runtime_service_families -> _runtime_service_family_registry (registry data) - aces_sdl._yaml_loader -> _mapping_key_analyzer (mapping-key validation walker) - aces_operations._evidence_run_validation -> _evidence_run_realization - aces_operations.libvirt_evidence_run -> _evidence_run_native (EvidenceCheck / LibvirtEvidenceRunConfig relocated to _evidence_run_types to break the cycle) - aces_backend_libvirt.techvault_concerns -> techvault_plan_admission - aces_backend_libvirt.techvault_native -> _techvault_native_ops Complexity reductions (all now <=10): - _evidence_run_realization._validate_unrealized_substrate (11) - _mapping_key_analyzer._walk_mapping_entry (13) - techvault_native.TechVaultNativeLibvirtDriver.__post_init__ (12) - provisioner.LibvirtProvisioner._drive (14) * refactor: make LibvirtProvisioner._active_addresses static (S2325) The extracted _active_addresses helper does not use instance state; SonarCloud flagged python:S2325. Make it a staticmethod (called via the instance in _drive).
|
Brad-Edwards
added a commit
that referenced
this pull request
Jul 12, 2026
) refactor(conformance): drop redundant tuple() around tuple literals (S7496) SonarCloud activated python:S7496 and flagged the dev->main promotion (PR #740) on tuple((*a, *b)) in aces_conformance/conformance.py, where the inner starred expression is already a tuple. Unwrap both occurrences. No behaviour change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Summary
Related Issues
Requirement Context
aces-sdlChanges
Test Plan
uvx nox -s verifypasses, or the unchecked sessions are listed belowuvx nox -s docs)Checklist
docs/explain/reference/coding-standards.md)changelog.d/, or not neededNotes for Review