Skip to content

feat: add authorial freestanding science fabric v1 - #1069

Merged
rafaelmeloreisnovo merged 14 commits into
rll/labfrom
feat/authorial-science-fabric-v1-20261005
Oct 5, 2026
Merged

rafaelmeloreisnovo merged 14 commits into
rll/labfrom
feat/authorial-science-fabric-v1-20261005

Conversation

@rafaelmeloreisnovo

@rafaelmeloreisnovo rafaelmeloreisnovo commented Oct 5, 2026 •

Copy link
Copy Markdown
Collaborator

Intent

Materialize a low-friction RLL service boundary for authorial freestanding computation, scientific source custody, internet artifacts, capability-scoped PAT bindings and hosted adapters without turning factory tools into runtime dependencies.

Delta

  • adds services/authorial_fabric/ registry, source-manifest schema and receipt custody contract;
  • adds stdlib-only tools/rll_authorial_ingress.py for bounded HTTPS acquisition, kind checks, SHA-256 custody and sanitized receipts;
  • adds a discovery manifest for the Beinecke MS 408 / Voynich angular-graph experiment, preserving unresolved high-resolution endpoints/rights/hashes as TOKEN_VAZIO;
  • adds supplemental capability routing for PAT_ACTIONS, PAT_AGENTS, PAT_ENV, canonical PAT_ENVIRONMENTS, and legacy typo fallback PAT_ENVIOREMENTS;
  • adds path-scoped contract CI plus manual-only acquisition;
  • maps NDK/JNI/SDK/R8/ART-JIT/Python/Actions as factory/evidence adapters, never as freestanding runtime dependencies;
  • blocks Authorization-bearing redirects before follow and makes the SHA custody inventory exclude its own output.

Security / authority boundary

Secret values are never read back into repository content, logged, hashed, compared, or emitted in receipts. V1 credential use is manual-only and GET-only against GitHub Contents API with contents: read. No push/POST/PUT/PATCH/DELETE/ref-delete/force-push path is implemented. Public HTTPS sources use no PAT.

Whether the named secrets are present, share the same PAT value, or have the same provider-side scopes remains TOKEN_VAZIO because those values are intentionally outside the repository/connector evidence surface.

Scientific boundary

SOURCE != ARTIFACT != EXECUTION != EVIDENCE != CLAIM; IMPLEMENTED_UNTESTED_CI != PASS; TOKEN_VAZIO != 0; claim_allowed=false. Download/hash success is source/artifact custody only. No Voynich decipherment claim and no RLL scientific promotion.

Regression surface

Current exact head: e5f4d913481a512be902faae87d2adc66dbc12a8.
Base: rll/lab@f400a588f12db67583a6586e5892f563d1a4dc7b.
Current compare: ahead_by=14, behind_by=0; 10 files added; no legacy file rewritten. Rollback is branch/PR-local; no history rewrite.

Gates

A prior local stdlib preflight passed 6/6 before the final security hotfixes. That prior result is not promoted to the exact head. Provider readback for the exact head currently returns 0 workflow runs, so exact-head CI remains TOKEN_VAZIO/PENDING. This PR intentionally remains draft until terminal exact-head evidence is read back.

Promotion remains feature -> rll/lab by reviewed PR, followed later by the repository's existing PR-only rll/lab -> main path.

Copy link
Copy Markdown
Collaborator Author

Evidence receipt — Authorial Science Fabric V1

Exact head: e5f4d913481a512be902faae87d2adc66dbc12a8
Base: rll/lab@f400a588f12db67583a6586e5892f563d1a4dc7b
Diff state: ahead_by=14, behind_by=0; 10 added files, no legacy file rewrite.

Boundary state:

  • SOURCE != ARTIFACT != EXECUTION != EVIDENCE != CLAIM
  • claim_allowed=false
  • IMPLEMENTED_UNTESTED_CI != PASS
  • canonical secret name: PAT_ENVIRONMENTS; legacy fallback only: PAT_ENVIOREMENTS
  • secret values are not stored, logged, hashed or compared
  • V1 credential use is manual-only, GET-only, GitHub Contents API only, contents: read; delete/push/force-push are not implemented
  • credentialed redirects now fail closed before a PAT can follow them
  • custody SHA inventory excludes its own output file

Evidence readback at this exact head: GitHub provider currently returns 0 workflow runs. Therefore CI remains TOKEN_VAZIO/PENDING, not PASS. Secret presence, equality of secret values, and provider-side PAT scopes also remain TOKEN_VAZIO because those values are intentionally not exposed through the current connector.

Next gate: exact-head CI execution/readback. Only after terminal evidence should this draft be considered for reviewed landing on rll/lab; later rll/lab -> main remains PR-only under the existing deployment-path governance.

doc = self.good()
doc["sources"][0]["credential_profile"] = "pat_actions"
self.assertTrue(
any("api.github.com" in error for error in mod.validate_manifest(doc))
@rafaelmeloreisnovo
rafaelmeloreisnovo marked this pull request as ready for review October 5, 2026 15:29
@rafaelmeloreisnovo
rafaelmeloreisnovo merged commit 06677ef into rll/lab Oct 5, 2026
24 of 32 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants