Skip to content

chore: fill derivable placeholders, drop false ARCHITECTURE, surface the rest - #172

Closed
hyperpolymath wants to merge 3 commits into
mainfrom
chore/estate-topup
Closed

chore: fill derivable placeholders, drop false ARCHITECTURE, surface the rest#172
hyperpolymath wants to merge 3 commits into
mainfrom
chore/estate-topup

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Automated estate top-up. Nothing here invents a value.

Filled — every token with one mechanical answer (owner, repo, forge, author, dates, project name, main branch). Identity from the git remote, dates from the clock, name from the README H1.

Not filled, on purposeSECURITY_EMAIL (two competing addresses exist in the estate), RESPONSE_TIME, CONDUCT_TEAM (substitutes into "a {{CONDUCT_TEAM}} member", which is not English), WEBSITE, PROJECT_DESCRIPTION, LANG_STACK. More than one defensible answer exists, and a confident wrong value is worse than a visible gap.

DeletedARCHITECTURE.md where it is byte-identical to the 346-copy estate boilerplate (blob 607e3d8c). Those 33 lines describe a src/ tests/ docs/ scripts/ config/ tree this repo does not have. Matched by hash, so a genuinely written ARCHITECTURE can never be caught by it.

CODEOWNERS — the solo form from standards/CODEOWNERS-POLICY.adoc Rule 1, which forbids a catch-all where the only owner is the sole maintainer. templates/CODEOWNERS contradicts that policy; the policy is versioned, dated and resolves standards#55, so it wins. Genuine co-owners (Rule 2) are untouched.

SurfacedREQUIRES_INITIALISATION.md plus a priority action in 0-AI-MANIFEST.a2ml, listing every remaining token, what it means, which files it belongs in, why it was not done already, and that it is to be deleted only when the work is genuinely complete.

Built from a fresh clone of origin/main, never a local checkout — several of those are dirty and hold unpushed commits.

🤖 Generated with Claude Code

…the rest
Estate top-up pass. Three separate things, none of which invents a value.
FILLED — every token with a single mechanical answer: OWNER, REPO, FORGE,
PROJECT, PACKAGE_NAME, PROJECT_NAME, AUTHOR, AUTHOR_EMAIL, CONDUCT_EMAIL,
AUTHOR_FIRST/LAST/INITIALS, CURRENT_YEAR, CURRENT_DATE, DATE, MAIN_BRANCH.
Identity comes from the git remote, dates from the clock, project name from the
README H1 where there is one.
Deliberately NOT filled, because more than one defensible answer exists and a
confident wrong value is worse than a visible gap: SECURITY_EMAIL (two competing
addresses are in use across the estate), RESPONSE_TIME, CONDUCT_TEAM (which
substitutes into "a {{CONDUCT_TEAM}} member", not English), WEBSITE,
PROJECT_DESCRIPTION, LANG_STACK.
DELETED — ARCHITECTURE.md, where it is byte-identical to the 346-copy estate
boilerplate (blob 607e3d8). Those 33 lines describe a src/ tests/ docs/
scripts/ config/ tree that this repo does not have, so the file is not merely
uninformative, it is wrong. Genuinely written ARCHITECTURE files are matched by
hash and left alone. No file beats a confidently false one.
CODEOWNERS — rewritten to the solo form mandated by
hyperpolymath/standards CODEOWNERS-POLICY.adoc Rule 1, which forbids a catch-all
line where the only owner is the sole maintainer. The estate's own
templates/CODEOWNERS contradicts that policy; the policy is versioned, dated and
resolves standards#55, so it wins. Files naming a genuine co-owner are Rule 2
and are untouched. Note @hyperpolymath and @metadatastician are the same person,
so a file naming the other account is a copy artifact that silently routed
review requests to the wrong account.
SURFACED — REQUIRES_INITIALISATION.md, and a priority action in
0-AI-MANIFEST.a2ml. Tokens that need a decision no script can make are left
visibly unfilled rather than faked or quietly deleted. The marker says what each
one is, which files it belongs in, why it was not done already, and that it must
be deleted only once the work is genuinely finished.
@gitar-bot

gitar-botBot commented Aug 5, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review🚫 Blocked0 resolved / 3 findings

Automated estate top-up that fills derivable placeholders and prunes boilerplate architecture files, but appends invalid markdown to the S-expression manifest, strips required template-residue validation markers, and corrupts quoted literal tokens in the changelog.

🚨 Bug: Appended markdown breaks 0-AI-MANIFEST.a2ml S-expression parsing

📄 0-AI-MANIFEST.a2ml:139-153

The requires-initialisation block (lines 141-156) is raw markdown/HTML appended after the closing ))) of the (manifest …) form. The repo's own A2ML parser reads the whole file and rejects any trailing content: Parser::parse_all() returns Err("extra tokens after manifest") at src/a2ml/mod.rs:639, and its comment handling (src/a2ml/mod.rs:612) only treats # (at line start) and ; as comments — <!-- … --> and bare prose lines like "16 substitution token(s)…" are neither comments nor valid S-expressions. As a result the manifest that agents read on entry now fails to parse. Move the notice inside the manifest as an S-expression node, or prefix every added line with # and drop the <!-- --> delimiters.

Represent the notice as an S-expression node inside the manifest so parse_all() succeeds.
(metadata
(created "2026-02-07")
(updated "2026-03-01")
(version-current "2.0.0")
(version-next "2.1.0")
(status "active-development"))
(requires-initialisation
(priority-action "This repository is not fully initialised")
(outstanding-tokens 16)
(see "REQUIRES_INITIALISATION.md")))
Alternatively, keep the prose but make every line a #-comment and place it before the closing parens (or as leading comments), removing the HTML markers.
# BEGIN requires-initialisation
#
# PRIORITY ACTION — this repository is not fully initialised
#
# 16 substitution token(s) still have no value. Read
# REQUIRES_INITIALISATION.md in the repository root before doing anything
# else here.
#
# END requires-initialisation
⚠️Bug: reject-if-contains: {{PROJECT}} marker replaced with filled value

📄 .machine_readable/agent_instructions/methodology.a2ml:104

The state-validation reject-if-contains list is meant to hold template-residue markers so stale/uninitialised state files are detected. The fill pass substituted the marker {{PROJECT}} with the filled project name PANIC_ATTACK (methodology.a2ml:104). This has two wrong effects: it no longer detects leftover {{PROJECT}} residue, and it now flags any file that legitimately mentions PANIC_ATTACK (the string already appears in .machine_readable/6a2/PLAYBOOK.a2ml). This is the same blind-substitution mistake — a token used as literal config data was treated as a value to fill. Restore {{PROJECT}} in the list.

Keep the placeholder marker; do not substitute it with the resolved project name.
reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]
💡 Quality: Token fill corrupted quoted references in CHANGELOG and audit

📄 CHANGELOG.md:192📄 docs/reports/audit/pillar-audit-2026-04-15.md:20

The substitution pass replaced placeholder tokens that were being quoted/discussed as literal text, corrupting two records. CHANGELOG.md:192 now reads j.d.a.jewell@open.ac.uk → j.d.a.jewell@open.ac.uk (was {{CONDUCT_EMAIL}} → j.d.a.jewell@open.ac.uk), a nonsensical self-mapping that loses what CONDUCT_EMAIL originally resolved to. pillar-audit-2026-04-15.md:20 now lists panic-attack, {{DEPS}}, {{BUILD_OUTPUT_PATH}} as "Template Residue found" — the audit finding recorded {{PACKAGE_NAME}} as residue, so replacing it both loses the finding and makes the report self-contradictory. Restore the original literal token text in both historical/audit entries; these are records of past state, not live placeholders.

CHANGELOG.md:192 — restore the {{CONDUCT_EMAIL}} token so the entry documents the actual substitution.
(`{{CONDUCT_EMAIL}}` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →
pillar-audit line 20 — restore {{PACKAGE_NAME}} so the audit residue finding stays accurate.
- `{{PACKAGE_NAME}}`, `{{DEPS}}`, `{{BUILD_OUTPUT_PATH}}` found in `QUICKSTART-MAINTAINER.adoc`.
🤖 Prompt for agents
Code Review: Automated estate top-up that fills derivable placeholders and prunes boilerplate architecture files, but appends invalid markdown to the S-expression manifest, strips required template-residue validation markers, and corrupts quoted literal tokens in the changelog.
1. 🚨 Bug: Appended markdown breaks 0-AI-MANIFEST.a2ml S-expression parsing
Files: 0-AI-MANIFEST.a2ml:139-153
The `requires-initialisation` block (lines 141-156) is raw markdown/HTML appended after the closing `)))` of the `(manifest …)` form. The repo's own A2ML parser reads the whole file and rejects any trailing content: `Parser::parse_all()` returns `Err("extra tokens after manifest")` at src/a2ml/mod.rs:639, and its comment handling (src/a2ml/mod.rs:612) only treats `#` (at line start) and `;` as comments — `<!-- … -->` and bare prose lines like "16 substitution token(s)…" are neither comments nor valid S-expressions. As a result the manifest that agents read on entry now fails to parse. Move the notice inside the manifest as an S-expression node, or prefix every added line with `#` and drop the `<!-- -->` delimiters.
Fix (Represent the notice as an S-expression node inside the manifest so parse_all() succeeds.):
(metadata
(created "2026-02-07")
(updated "2026-03-01")
(version-current "2.0.0")
(version-next "2.1.0")
(status "active-development"))
(requires-initialisation
(priority-action "This repository is not fully initialised")
(outstanding-tokens 16)
(see "REQUIRES_INITIALISATION.md")))
Fix (Alternatively, keep the prose but make every line a #-comment and place it before the closing parens (or as leading comments), removing the HTML markers.):
# BEGIN requires-initialisation
#
# PRIORITY ACTION — this repository is not fully initialised
#
# 16 substitution token(s) still have no value. Read
# REQUIRES_INITIALISATION.md in the repository root before doing anything
# else here.
#
# END requires-initialisation
2. ⚠️ Bug: reject-if-contains: {{PROJECT}} marker replaced with filled value
Files: .machine_readable/agent_instructions/methodology.a2ml:104
The state-validation `reject-if-contains` list is meant to hold template-residue markers so stale/uninitialised state files are detected. The fill pass substituted the marker `{{PROJECT}}` with the filled project name `PANIC_ATTACK` (methodology.a2ml:104). This has two wrong effects: it no longer detects leftover `{{PROJECT}}` residue, and it now flags any file that legitimately mentions `PANIC_ATTACK` (the string already appears in `.machine_readable/6a2/PLAYBOOK.a2ml`). This is the same blind-substitution mistake — a token used as literal config data was treated as a value to fill. Restore `{{PROJECT}}` in the list.
Fix (Keep the placeholder marker; do not substitute it with the resolved project name.):
reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]
3. 💡 Quality: Token fill corrupted quoted references in CHANGELOG and audit
Files: CHANGELOG.md:192, docs/reports/audit/pillar-audit-2026-04-15.md:20
The substitution pass replaced placeholder tokens that were being quoted/discussed as literal text, corrupting two records. CHANGELOG.md:192 now reads `j.d.a.jewell@open.ac.uk → j.d.a.jewell@open.ac.uk` (was `{{CONDUCT_EMAIL}} → j.d.a.jewell@open.ac.uk`), a nonsensical self-mapping that loses what CONDUCT_EMAIL originally resolved to. pillar-audit-2026-04-15.md:20 now lists `panic-attack, {{DEPS}}, {{BUILD_OUTPUT_PATH}}` as "Template Residue found" — the audit finding recorded `{{PACKAGE_NAME}}` as residue, so replacing it both loses the finding and makes the report self-contradictory. Restore the original literal token text in both historical/audit entries; these are records of past state, not live placeholders.
Fix (CHANGELOG.md:192 — restore the {{CONDUCT_EMAIL}} token so the entry documents the actual substitution.):
(`{{CONDUCT_EMAIL}}` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →
Fix (pillar-audit line 20 — restore {{PACKAGE_NAME}} so the audit residue finding stays accurate.):
- `{{PACKAGE_NAME}}`, `{{DEPS}}`, `{{BUILD_OUTPUT_PATH}}` found in `QUICKSTART-MAINTAINER.adoc`.
Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose 

Important

Your trial ends in 5 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

Comment thread0-AI-MANIFEST.a2ml
Comment on lines 139 to +153
(status "active-development")))

<!-- BEGIN requires-initialisation -->

## PRIORITY ACTION — this repository is not fully initialised

16 substitution token(s) still have no value. **Read
`REQUIRES_INITIALISATION.md` in the repository root before doing anything
else here** — it lists every outstanding token, what it means, and which
files it belongs in.

Do not fabricate values for them, and do not delete the sections that
contain them to quiet a gate. They are unfilled because they need a
decision, not because they were overlooked. Resolve what you legitimately
can, leave the rest, and delete `REQUIRES_INITIALISATION.md` only when

@gitar-botgitar-botBotAug 5, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🚨 Bug: Appended markdown breaks 0-AI-MANIFEST.a2ml S-expression parsing

The requires-initialisation block (lines 141-156) is raw markdown/HTML appended after the closing ))) of the (manifest …) form. The repo's own A2ML parser reads the whole file and rejects any trailing content: Parser::parse_all() returns Err("extra tokens after manifest") at src/a2ml/mod.rs:639, and its comment handling (src/a2ml/mod.rs:612) only treats # (at line start) and ; as comments — <!-- … --> and bare prose lines like "16 substitution token(s)…" are neither comments nor valid S-expressions. As a result the manifest that agents read on entry now fails to parse. Move the notice inside the manifest as an S-expression node, or prefix every added line with # and drop the <!-- --> delimiters.

Was this helpful? React with 👍 / 👎


[methodology.state-validation]
reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]
reject-if-contains = ["{{PLACEHOLDER}}", "PANIC_ATTACK", "rsr-template-repo"]

@gitar-botgitar-botBotAug 5, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️Bug: reject-if-contains: {{PROJECT}} marker replaced with filled value

The state-validation reject-if-contains list is meant to hold template-residue markers so stale/uninitialised state files are detected. The fill pass substituted the marker {{PROJECT}} with the filled project name PANIC_ATTACK (methodology.a2ml:104). This has two wrong effects: it no longer detects leftover {{PROJECT}} residue, and it now flags any file that legitimately mentions PANIC_ATTACK (the string already appears in .machine_readable/6a2/PLAYBOOK.a2ml). This is the same blind-substitution mistake — a token used as literal config data was treated as a value to fill. Restore {{PROJECT}} in the list.

Keep the placeholder marker; do not substitute it with the resolved project name.:

reject-if-contains = ["{{PLACEHOLDER}}", "{{PROJECT}}", "rsr-template-repo"]

Was this helpful? React with 👍 / 👎

Comment threadCHANGELOG.md
AGPL-3.0 body to MPL-2.0 (matching SPDX headers + Cargo.toml +
README.adoc); CODE_OF_CONDUCT.md placeholders instantiated
(`{{CONDUCT_EMAIL}}` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →
(`j.d.a.jewell@open.ac.uk` → `j.d.a.jewell@open.ac.uk`, `{{CONDUCT_TEAM}}` →

@gitar-botgitar-botBotAug 5, 2026

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Quality: Token fill corrupted quoted references in CHANGELOG and audit

The substitution pass replaced placeholder tokens that were being quoted/discussed as literal text, corrupting two records. CHANGELOG.md:192 now reads j.d.a.jewell@open.ac.uk → j.d.a.jewell@open.ac.uk (was {{CONDUCT_EMAIL}} → j.d.a.jewell@open.ac.uk), a nonsensical self-mapping that loses what CONDUCT_EMAIL originally resolved to. pillar-audit-2026-04-15.md:20 now lists panic-attack, {{DEPS}}, {{BUILD_OUTPUT_PATH}} as "Template Residue found" — the audit finding recorded {{PACKAGE_NAME}} as residue, so replacing it both loses the finding and makes the report self-contradictory. Restore the original literal token text in both historical/audit entries; these are records of past state, not live placeholders.

Was this helpful? React with 👍 / 👎

@gitar-botgitar-botBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️This PR is blocked due to unresolved code review findings.

Configure merge blocking · Maintainers can dismiss this review.

hyperpolymathand others added 2 commits August 5, 2026 14:09
…t a value
The estate top-up sweep substituted {{PROJECT}} here along with every other
token. This line is a DETECTOR list: the comment above it says these rules
detect corrupt/template/stale state files, so the tokens named in it are the
ones whose PRESENCE means a state file is broken.
Substituting it did two things. It blinded the {{PROJECT}} leak detector, and it
made the detector reject any state file containing this repo's own uppercased
name — the opposite of what the rule is for.
Same failure class as a template recipe rewriting the incident record that
documents its own bug: substituting tokens inside a thing that is ABOUT tokens.
Nothing else in this PR changes.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The previous commit on this branch was written by a script that read the file
through a shell command substitution. $(...) strips trailing newlines and
printf '%s' does not put one back, so the file lost its final newline and the
diff showed "\ No newline at end of file".
Content is otherwise byte-identical to that commit.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@hyperpolymath

Copy link
Copy Markdown
OwnerAuthor

Closing in favour of a reworked substituter — hyperpolymath/standards#590.

This sweep filled {{TOKEN}} placeholders by plain text replacement across every file. Across the 90 repositories reviewed it drew 141 findings, and one is severe:

sed "s/{{PROJECT_NAME}}/$name/g" → sed "s/Conative Gating/$name/g"
sed -e "s/{{DATE}}/$DATE/g" → sed -e "s/2026-08-05/$DATE/g"

Those are the scripts whose job is to perform template substitution. Filling the left-hand side of their own sed expressions means template application silently stops working — and the breakage stays invisible until someone mints a repository from the template and gets a half-substituted tree.

Four further shapes came out of the same cause:

  • release.sh no longer substitutes {{DATE}} into release notes
  • just's own {{ARGS}} reported as an unfilled token, leaving repos permanently "not initialised"
  • instructional docs rewritten to "Replace laminar, laminar, {{DEPS}} with actuals"
  • documentation describing placeholders had its examples filled in

The rule plain replacement cannot express: a placeholder is sometimes a value to fill and sometimes the subject being discussed. standards#590 encodes that distinction and is tested against this exact corruption (9/9, the first three cases reproducing it).

Nothing here is lost — the placeholder filling will be redone with that tool. Closing rather than fixing forward because repairing 289 branches individually would repeat the mistake at the same scale.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@hyperpolymath