Skip to content

Phase 10: deviation reconciliation — the repairs, three gates and the as-built ledger - #102

Merged
Wahbeh-Mohammad merged 9 commits into
mainfrom
10-phase-10-deviation-reconciliation-and-release-readiness
Sep 25, 2026
Merged

Wahbeh-Mohammad merged 9 commits into
mainfrom
10-phase-10-deviation-reconciliation-and-release-readiness

Conversation

@Wahbeh-Mohammad

Copy link
Copy Markdown
Contributor

Part of #34. First PR of phase 10's three-PR stack — the code — built off main at b242de6 (phases 0 through 9). The last phase of the v1 roadmap: it repairs what phase 9 and the earlier reviews found, re-derives design §10's nineteen entries from as-built source, and publishes nothing — every gem stays at 0.0.0.

What lands

378 files, +1,856 / −165 (307 of them are the one-line SPDX header on every shipped .rbs).

  • Three blocking gates, twenty-one → twenty-four, every body in tools/ and every path joined to gate_root (phase 9's P9-27 lesson): gates:ledger_audit (register row N ↔ §10 entry N — subject, ID-set equality, and a verdict row that cites a real gems/… path and only defined Dexpace:: constants), gates:spdx_rbs (line 1 of every shipped .rbs is the header; every signature declares something) and gates:sole_parse (AstScan.parse is the one RubyVM::AbstractSyntaxTree.parse_file caller). Each is in DEFAULT_GATES and CI's gates job; each exits 1 on its fixture workspace.
  • The probe's ninth check, chapters — clause-scoped chapter attribution; it found two live true positives in the phase-8 segmentation design, fixed in place on the docs branch.
  • NFR-13 — the SPDX header on all 307 .rbs files; phase 9's PackagingSuite pin flips from :failed to :passed.
  • Core repairs, each test-first (the failing test on main is the audit, P10-1):
    • the proxy warning belt no longer prints a password to Kernel#warn or the config sink for any malformed proxy spelling (phase 5b's R3-1, live on main and on no list until this phase's cross-check);
    • Status.of is total over every Integer (HTTP-10 — "never throw"), with #standard? for the protocol range;
    • Protocol admits HTTP/1.0 in WIRE_FORMS and ALIASES, with Protocol::HTTP_1_0 (HTTP-33; the plan said HTTP-24/43 and lib/dexpace/protocol.rb);
    • URL.parse! wraps every URI::Error as InvalidArgumentError naming the input and refuses a host-less http(s) URL (HTTP-47);
    • Model.own on a default_proc Hash, HeaderSyntax predicates total over non-Strings, Body.stream over a closed stream, NaN/Complex duration guards in Async.delay and Clock, the CFG-13 property-seam depth, the async instrumentation step's duration, Registry#resolve's termination pinned.
  • Both transports map an HTTP/1.0 or vendor-status head (the mappers now see the widened Protocol and Status).
  • dexpace-conformance — TransportSuite.run folded onto Runner without widening it; PackagingCase's gem-name rule covers the port's four segment exceptions.
  • tools/require_allowlist.rb refuses dexpace/../json-style dot segments; rake rubocop passes --ignore-parent-exclusion.
  • docs/deviations.md — all nineteen rows flipped to as-built verdicts (confirmed / confirmed-with-a-narrowing, none contradicted) with the amendment set C1–C19. It rides this branch because gates:ledger_audit reads it.

Decisions taken in the open, against the plan's text

Ledger rows P10-21–P10-38. Task 8 (SingleUseError) was not carried out: 7c already ships PageStateError < StandardError, so the defect is absent (P10-22). Task 9 is a verification, not a repair — the deadlock it was meant to fix does not happen (P10-21). Task 4 (Clients cap) was shipped by 8c and is a verification row (P10-23). The design's R1 file list was widened by a dated addendum (sdk-documentation, README, net_http YARD only, rbs_collection.yaml's comment, the conformance gem). Existing test files a code change invalidated ride this branch whole.

Layering

Green under all twenty-four gates on its own tree, the SimpleCov floor included (99.76 %) — the tolerated red was not needed. 3.2.11 matrix set green at 96.05 %.

Status maps every three-place code with #standard? for the protocol
range (HTTP-10); Protocol admits HTTP/1.0 (HTTP-33); URL.parse! wraps
every URI error and refuses a host-less http URL (HTTP-47); Model.own
drops a default proc; the HeaderSyntax predicates are total; a closed
stream is refused at Body.stream; the NaN and Complex duration guards;
the configuration chain no longer nests per configure (CFG-13); the
async logging step stops counting the caller's continuation; the proxy
warning's credential belt is unanchored (OBS-11, CFG-22). Every shipped
signature gains the SPDX header (NFR-13). The runtime manifest gains
Protocol::HTTP_1_0 and Status#standard?; the pins the repairs
invalidated move with them.
Both ResponseMappers now hand HTTP/1.0 and any three-place status to
the model (TRANSPORT-24); their YARD says so, and net_http's stray
@decode_content tag is backticked. The adapter pins that used HTTP/1.0
as the unmappable head now use HTTP/1.2. Every shipped signature in
the four adapter gems gains the SPDX header (NFR-13).
TransportSuite.run delegates to Runner.run, tearing its fresh cases
down through the around wrapper so Runner is not widened. The default
gem-name rule in PackagingCase reaches all six namespaces: -core is the
root and http/json are acronyms (NFR-15). The NFR-13 pin over this
repository's own signatures now expects :passed.
Twenty-four blocking gates, the three new ones in DEFAULT_GATES and in
CI's gates job, each with a fixture workspace that turns it red. The
require allowlist refuses a dexpace/ path with a dot segment, and the
rubocop gate runs with --ignore-parent-exclusion.
A requirement ID attributed to a product-spec chapter that does not
carry it, read clause by clause, with ranges expanded and negations
skipped.
All nineteen rows carry a verdict citing gems/ paths and defined
constants, and the amendment set is C1-C18. It rides here because
gates:ledger_audit reads it at run time.
Review round 0 of phase 10 found four code-layer defects.

R0-4: the proxy warning belt stopped at the first '/', '?' or '#', so
a password holding one leaked its prefix into Kernel#warn and the
config sink. ProxyResolution now scrubs the raw value from the
authority's start through the LAST '@' before the redactor runs.

R0-5: Status.of still threw outside 0..999, narrower than HTTP-10's
"any code MUST return a Status". Construction is now total over
Integer; #standard? stays the protocol range.

R0-6: docs/deviations.md row 10 cited send(:new) as the bypass, but
it runs the validating #initialize. The row is now "confirmed,
narrower" (allocate and duck typing remain) with amendment C19.

R0-8: the chapters check listed "appears in" as a negation, blinding
it to the usual positive attribution. An ID run followed by that
phrase now binds forward to the chapter it introduces.
The one rubocop:disable phase 10 added in tools/ledger_audit.rb
carried no reason; it now says why the row check threads the root
and the resolver (review round 1, R1-3).

The chapters check's forward "appears in" binding turned a negative
sentence ("SEAM-13 does not appear in <chapter>") into a positive
attribution. NEGATION gains "not appear in", "does not appear" and
"do not appear" (R1-4).
Review round 2 (R2-2) found two more negated spellings of 'appears
in' that bound forward and would fire as a wrong attribution:
'never appears in' and 'doesn't appear in'. Add 'never appear' and
"n't appear" to the chapters check's NEGATION union; 'appears
nowhere' was already there.
@Wahbeh-Mohammad Wahbeh-Mohammad added type:docs Documentation only spec:deviation Deliberate, recorded divergence from the normative contract labels Sep 25, 2026
@Wahbeh-Mohammad
Wahbeh-Mohammad merged commit 0aebd94 into main Sep 25, 2026
2 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

spec:deviation Deliberate, recorded divergence from the normative contract type:docs Documentation only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant