diff --git a/CHANGELOG.adoc b/CHANGELOG.adoc
new file mode 100644
index 0000000..fce9184
--- /dev/null
+++ b/CHANGELOG.adoc
@@ -0,0 +1,71 @@
+== Changelog
+
+All notable changes to `+ipv6-tools+` will be documented in this file.
+
+This file is generated from conventional commits by the
+https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml[`+changelog-reusable.yml+`]
+workflow (`+hyperpolymath/standards#206+`). Adopt the workflow in this
+repo’s CI to keep this file in sync automatically — see
+https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml[`+templates/cliff.toml+`]
+for the canonical config.
+
+The format follows https://keepachangelog.com/en/1.1.0/[Keep a
+Changelog]; this project aims to follow
+https://semver.org/spec/v2.0.0.html[Semantic Versioning].
+
+=== [Unreleased]
+
+==== Added
+
+* feat(crg): add crg-grade and crg-badge justfile recipes
+* feat: add stapeln.toml container definition
+* feat: deploy UX Manifesto infrastructure
+* feat: add CLADE.a2ml — clade taxonomy declaration
+* feat: add RSR template structure and project metadata
+* feat: create ipv6-tools monorepo
+
+==== Fixed
+
+* fix(ci): bump a2ml/k9-validate-action pins to canonical (standards#85)
+(#10)
+* fix(ci): sync hypatia-scan.yml to canonical (kill cd-scanner build
+drift) (#9)
+* fix(ci): build Hypatia escript from repo root (estate dogfood drift)
+* fix(ci): adopt canonical hypatia-scan.yml (env.HOME/scanner-layout +
+Comment-step gate) (#6)
+* fix(ci): repair YAML block-scalar in workflow-linter Check Permissions
+step (#4)
+* fix(scorecard): enforce granular permissions and add fuzzing
+placeholder
+* fix(ci): Resolve workflow-linter self-matching and metadata issues
+* fix: correct email jonathan.jewell → j.d.a.jewell
+* fix: global AGPL-3.0-or-later → PMPL-1.0-or-later replacement
+* fix(license): SPDX AGPL-3.0 → PMPL-1.0-or-later in dotfiles
+
+==== Changed
+
+* refactor: migrate 6SCM → 6A2 (.scm → .a2ml format)
+
+==== Documentation
+
+* docs: add TEST-NEEDS.md (CRG C)
+* docs: add EXPLAINME.adoc — prove-it file backing README claims
+
+==== CI
+
+* ci: redistribute concurrency-cancel guard to read-only check workflows
+(#12)
+* ci: fix nonexistent actions/upload-artifact SHA pin (#8)
+* ci: bump actions/upload-artifact SHA to current v4 (#3)
+* ci: SHA-pin hyperpolymath validate-actions in dogfood-gate
+* ci: deploy dogfood-gate, fix hypatia-scan, add pre-commit hooks
+
+=== Pre-history
+
+Prior commits to this file’s introduction are recorded in git history
+but not formally classified into Keep-a-Changelog sections. To backfill,
+run `+git cliff -o CHANGELOG.md+` locally using the canonical
+https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml[`+cliff.toml+`]
+— this is one-shot mechanical work.
+
+'''''
diff --git a/CHANGELOG.md b/CHANGELOG.md
deleted file mode 100644
index cbdf196..0000000
--- a/CHANGELOG.md
+++ /dev/null
@@ -1,66 +0,0 @@
-
-
-# Changelog
-
-All notable changes to `ipv6-tools` will be documented in this file.
-
-This file is generated from conventional commits by the
-[`changelog-reusable.yml`](https://github.com/hyperpolymath/standards/blob/main/.github/workflows/changelog-reusable.yml)
-workflow (`hyperpolymath/standards#206`). Adopt the workflow in this repo's CI to keep this file in sync automatically — see
-[`templates/cliff.toml`](https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml)
-for the canonical config.
-
-The format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/);
-this project aims to follow [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
-
-## [Unreleased]
-
-### Added
-
-- feat(crg): add crg-grade and crg-badge justfile recipes
-- feat: add stapeln.toml container definition
-- feat: deploy UX Manifesto infrastructure
-- feat: add CLADE.a2ml — clade taxonomy declaration
-- feat: add RSR template structure and project metadata
-- feat: create ipv6-tools monorepo
-
-### Fixed
-
-- fix(ci): bump a2ml/k9-validate-action pins to canonical (standards#85) (#10)
-- fix(ci): sync hypatia-scan.yml to canonical (kill cd-scanner build drift) (#9)
-- fix(ci): build Hypatia escript from repo root (estate dogfood drift)
-- fix(ci): adopt canonical hypatia-scan.yml (env.HOME/scanner-layout + Comment-step gate) (#6)
-- fix(ci): repair YAML block-scalar in workflow-linter Check Permissions step (#4)
-- fix(scorecard): enforce granular permissions and add fuzzing placeholder
-- fix(ci): Resolve workflow-linter self-matching and metadata issues
-- fix: correct email jonathan.jewell → j.d.a.jewell
-- fix: global AGPL-3.0-or-later → PMPL-1.0-or-later replacement
-- fix(license): SPDX AGPL-3.0 → PMPL-1.0-or-later in dotfiles
-
-### Changed
-
-- refactor: migrate 6SCM → 6A2 (.scm → .a2ml format)
-
-### Documentation
-
-- docs: add TEST-NEEDS.md (CRG C)
-- docs: add EXPLAINME.adoc — prove-it file backing README claims
-
-### CI
-
-- ci: redistribute concurrency-cancel guard to read-only check workflows (#12)
-- ci: fix nonexistent actions/upload-artifact SHA pin (#8)
-- ci: bump actions/upload-artifact SHA to current v4 (#3)
-- ci: SHA-pin hyperpolymath validate-actions in dogfood-gate
-- ci: deploy dogfood-gate, fix hypatia-scan, add pre-commit hooks
-
-## Pre-history
-
-Prior commits to this file's introduction are recorded in git history but not formally classified into Keep-a-Changelog sections. To backfill, run `git cliff -o CHANGELOG.md` locally using the canonical [`cliff.toml`](https://github.com/hyperpolymath/standards/blob/main/templates/cliff.toml) — this is one-shot mechanical work.
-
----
-
-
diff --git a/CODE_OF_CONDUCT.adoc b/CODE_OF_CONDUCT.adoc
new file mode 100644
index 0000000..213b0ef
--- /dev/null
+++ b/CODE_OF_CONDUCT.adoc
@@ -0,0 +1,339 @@
+== Code of Conduct
+
+=== Our Pledge
+
+We as members, contributors, and leaders pledge to make participation in
+Ipv6 Tools a harassment-free experience for everyone, regardless of age,
+body size, visible or invisible disability, ethnicity, sex
+characteristics, gender identity and expression, level of experience,
+education, socio-economic status, nationality, personal appearance,
+race, caste, colour, religion, or sexual identity and orientation.
+
+We pledge to act and interact in ways that contribute to an open,
+welcoming, diverse, inclusive, and healthy community.
+
+We recognise that a thriving open source community requires
+*psychological safety* — an environment where people can contribute, ask
+questions, make mistakes, and learn without fear of ridicule or
+retaliation.
+
+'''''
+
+=== Our Standards
+
+==== Expected Behaviour
+
+The following behaviours contribute to a positive environment:
+
+*Communication* - Using welcoming and inclusive language - Being
+respectful of differing viewpoints and experiences - Giving and
+gracefully accepting constructive feedback - Assuming good intent while
+addressing impact - Communicating clearly and patiently, especially with
+newcomers
+
+*Collaboration* - Focusing on what is best for the community - Showing
+empathy and kindness toward other community members - Being
+collaborative rather than competitive - Mentoring and supporting less
+experienced contributors - Celebrating others’ contributions and
+successes
+
+*Professionalism* - Accepting responsibility and apologising to those
+affected by our mistakes - Learning from the experience and avoiding
+repetition - Respecting others’ time and attention - Staying on topic in
+project spaces - Following project guidelines and conventions
+
+*Accessibility* - Using plain language and avoiding unnecessary jargon -
+Providing alt text for images and transcripts for audio/video - Being
+patient with those using assistive technologies - Accommodating
+different communication styles and needs - Recognising that not everyone
+communicates the same way
+
+==== Unacceptable Behaviour
+
+The following behaviours are considered harassment and are unacceptable:
+
+*Harassment* - The use of sexualised language or imagery, and sexual
+attention or advances of any kind - Trolling, insulting or derogatory
+comments, and personal or political attacks - Public or private
+harassment - Deliberate intimidation, stalking, or following (online or
+in-person) - Unwelcome physical contact or simulated physical contact
+(e.g., emoji) - Sustained disruption of talks, events, or online
+discussions
+
+*Discrimination* - Discriminatory jokes and language - Posting or
+threatening to post others’ personally identifying information
+("`doxing`") - Advocating for, or encouraging, any of the above
+behaviour - Microaggressions — subtle, often unintentional,
+discriminatory comments or actions
+
+*Professional Misconduct* - Publishing others’ private information
+without explicit permission - Misrepresenting affiliation or
+contributions - Plagiarism or claiming credit for others’ work -
+Retaliating against anyone who reports a Code of Conduct violation -
+Other conduct which could reasonably be considered inappropriate in a
+professional setting
+
+==== Grey Areas
+
+Some situations require judgement. When uncertain:
+
+* *Intent vs Impact*: Good intentions do not excuse harmful impact.
+Focus on making things right.
+* *Power Dynamics*: Those with more power (maintainers, employers,
+experienced contributors) must be especially mindful of their impact.
+* *Cultural Differences*: What’s acceptable varies by culture. When in
+doubt, err on the side of caution and ask.
+* *Humour*: Jokes at others’ expense are rarely funny to everyone. Punch
+up, not down.
+
+'''''
+
+=== Scope
+
+This Code of Conduct applies within all community spaces, including:
+
+*Online Spaces* - Repository discussions, issues, and pull/merge
+requests - Project chat channels (Matrix, Discord, Slack, IRC) - Mailing
+lists and forums - Social media when representing the project - Video
+calls and virtual meetings
+
+*In-Person Spaces* - Conferences, meetups, and events - Workshops and
+training sessions - Any gathering where you represent the project
+
+*Representation* This Code of Conduct also applies when an individual is
+officially representing the community in public spaces. Examples
+include:
+
+* Using an official project email address
+* Posting via an official social media account
+* Acting as an appointed representative at an event
+* Speaking on behalf of the project
+
+'''''
+
+=== Enforcement
+
+==== Reporting
+
+If you experience or witness unacceptable behaviour, or have any other
+concerns, please report it as soon as possible.
+
+*How to Report*
+
+[width="99%",cols="30%,33%,37%",options="header",]
+|===
+|Method |Details |Best For
+|*Email* |j.d.a.jewell@open.ac.uk |Detailed reports, sensitive matters
+
+|*Private Message* |Contact any maintainer directly |Quick questions,
+minor issues
+
+|*Anonymous Form* |[Link to form if available] |When you need anonymity
+|===
+
+*What to Include*
+
+* Your contact information (unless anonymous)
+* Names/usernames of those involved
+* Description of what happened
+* When and where it occurred
+* Any witnesses
+* Any supporting evidence (screenshots, links)
+* How you would like us to respond (if you have a preference)
+
+*What Happens Next*
+
+[arabic]
+. You will receive acknowledgment within *\{\{RESPONSE_TIME}}*
+. The \{\{CONDUCT_TEAM}} will review the report
+. We may ask for additional information
+. We will determine appropriate action
+. We will inform you of the outcome (respecting others’ privacy)
+
+==== Confidentiality
+
+All reports will be handled with discretion:
+
+* Reporter identity is protected by default
+* Details are shared only with those who need to know
+* We will ask before naming you in any communication
+* Anonymous reports are accepted and investigated
+
+==== Conflicts of Interest
+
+If a \{\{CONDUCT_TEAM}} member is involved in an incident:
+
+* They will recuse themselves from the process
+* Another maintainer or external party will handle the report
+* We will disclose any potential conflicts
+
+'''''
+
+=== Enforcement Guidelines
+
+The \{\{CONDUCT_TEAM}} will follow these guidelines in determining
+consequences:
+
+==== 1. Correction
+
+*Community Impact*: Use of inappropriate language or other behaviour
+deemed unprofessional or unwelcome.
+
+*Consequence*: A private, written warning providing clarity around the
+nature of the violation and an explanation of why the behaviour was
+inappropriate. A public apology may be requested.
+
+*Duration*: Immediate
+
+==== 2. Warning
+
+*Community Impact*: A violation through a single incident or series of
+actions.
+
+*Consequence*: A warning with consequences for continued behaviour. No
+interaction with the people involved, including unsolicited interaction
+with those enforcing the Code of Conduct, for a specified period. This
+includes avoiding interactions in community spaces as well as external
+channels like social media. Violating these terms may lead to a
+temporary or permanent ban.
+
+*Duration*: 1-4 weeks
+
+==== 3. Temporary Ban
+
+*Community Impact*: A serious violation of community standards,
+including sustained inappropriate behaviour.
+
+*Consequence*: A temporary ban from any sort of interaction or public
+communication with the community for a specified period. No public or
+private interaction with the people involved, including unsolicited
+interaction with those enforcing the Code of Conduct, is allowed during
+this period. Violating these terms may lead to a permanent ban.
+
+*Duration*: 1-6 months
+
+==== 4. Permanent Ban
+
+*Community Impact*: Demonstrating a pattern of violation of community
+standards, including sustained inappropriate behaviour, harassment of an
+individual, or aggression toward or disparagement of classes of
+individuals.
+
+*Consequence*: A permanent ban from any sort of public interaction
+within the community.
+
+*Duration*: Permanent (with appeal rights after 12 months)
+
+==== Enforcement Across Perimeters
+
+For contributors with elevated access (Perimeter 2 or 1):
+
+[cols=",",options="header",]
+|===
+|Level |Additional Consequence
+|Correction |Noted in contributor record
+|Warning |Access privileges may be temporarily reduced
+|Temporary Ban |Access reduced to Perimeter 3 for ban duration
+|Permanent Ban |All access revoked
+|===
+
+'''''
+
+=== Appeals
+
+If you believe an enforcement decision was made in error:
+
+[arabic]
+. *Wait 7 days* after the decision (cooling-off period)
+. *Email* j.d.a.jewell@open.ac.uk with subject line "`Appeal: [Original
+Report ID]`"
+. *Explain* why you believe the decision should be reconsidered
+. *Provide* any new information not previously available
+
+*Appeals Process*
+
+* Appeals are reviewed by a different \{\{CONDUCT_TEAM}} member than the
+original
+* You will receive a response within 14 days
+* The appeals decision is final
+* You may only appeal once per incident
+
+*Grounds for Appeal*
+
+* Procedural errors in the original investigation
+* New evidence not previously available
+* Disproportionate response to the violation
+* Misunderstanding of facts
+
+'''''
+
+=== Supporting Those Who Report
+
+We are committed to supporting those who report violations:
+
+*We Will* - Believe and take all reports seriously - Respect your
+privacy and confidentiality preferences - Keep you informed of progress
+(if you wish) - Take steps to protect you from retaliation - Provide
+resources if you need support
+
+*We Will Not* - Require you to confront the person directly - Dismiss
+reports without investigation - Reveal your identity without consent -
+Tolerate retaliation against reporters - Rush you to make decisions
+
+'''''
+
+=== Prevention
+
+Beyond enforcement, we actively work to prevent issues:
+
+*Onboarding* - All contributors are expected to read this Code of
+Conduct - Perimeter 2 applicants must confirm they’ve read and
+understood it - Maintainers receive additional training on enforcement
+
+*Culture* - We model the behaviour we expect - We intervene early when
+we see potential issues - We thank people for positive contributions -
+We create opportunities for diverse voices
+
+*Review* - This Code of Conduct is reviewed annually - Community
+feedback is welcomed - Changes are communicated clearly
+
+'''''
+
+=== Acknowledgments
+
+This Code of Conduct is adapted from:
+
+* https://www.contributor-covenant.org/[Contributor Covenant], version
+2.1
+* https://www.djangoproject.com/conduct/[Django Code of Conduct]
+* https://www.rust-lang.org/policies/code-of-conduct[Rust Code of
+Conduct]
+* https://www.python.org/psf/conduct/[Python Community Code of Conduct]
+
+We thank these communities for their leadership in creating welcoming
+spaces.
+
+'''''
+
+=== Questions?
+
+If you have questions about this Code of Conduct:
+
+* Open a
+https://github.com/hyperpolymath/ipv6-tools/discussions[Discussion] (for
+general questions)
+* Email j.d.a.jewell@open.ac.uk (for private questions)
+* Contact any maintainer directly
+
+'''''
+
+=== Summary
+
+*Be kind. Be respectful. Be collaborative.*
+
+We’re all here because we care about this project. Let’s make it a place
+where everyone can do their best work.
+
+'''''
+
+Last updated: 2026 · Based on Contributor Covenant 2.1
diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md
deleted file mode 100644
index 496b7d5..0000000
--- a/CODE_OF_CONDUCT.md
+++ /dev/null
@@ -1,309 +0,0 @@
-# Code of Conduct
-
-
-
-## Our Pledge
-
-We as members, contributors, and leaders pledge to make participation in Ipv6 Tools a harassment-free experience for everyone, regardless of age, body size, visible or invisible disability, ethnicity, sex characteristics, gender identity and expression, level of experience, education, socio-economic status, nationality, personal appearance, race, caste, colour, religion, or sexual identity and orientation.
-
-We pledge to act and interact in ways that contribute to an open, welcoming, diverse, inclusive, and healthy community.
-
-We recognise that a thriving open source community requires **psychological safety** — an environment where people can contribute, ask questions, make mistakes, and learn without fear of ridicule or retaliation.
-
----
-
-## Our Standards
-
-### Expected Behaviour
-
-The following behaviours contribute to a positive environment:
-
-**Communication**
-- Using welcoming and inclusive language
-- Being respectful of differing viewpoints and experiences
-- Giving and gracefully accepting constructive feedback
-- Assuming good intent while addressing impact
-- Communicating clearly and patiently, especially with newcomers
-
-**Collaboration**
-- Focusing on what is best for the community
-- Showing empathy and kindness toward other community members
-- Being collaborative rather than competitive
-- Mentoring and supporting less experienced contributors
-- Celebrating others' contributions and successes
-
-**Professionalism**
-- Accepting responsibility and apologising to those affected by our mistakes
-- Learning from the experience and avoiding repetition
-- Respecting others' time and attention
-- Staying on topic in project spaces
-- Following project guidelines and conventions
-
-**Accessibility**
-- Using plain language and avoiding unnecessary jargon
-- Providing alt text for images and transcripts for audio/video
-- Being patient with those using assistive technologies
-- Accommodating different communication styles and needs
-- Recognising that not everyone communicates the same way
-
-### Unacceptable Behaviour
-
-The following behaviours are considered harassment and are unacceptable:
-
-**Harassment**
-- The use of sexualised language or imagery, and sexual attention or advances of any kind
-- Trolling, insulting or derogatory comments, and personal or political attacks
-- Public or private harassment
-- Deliberate intimidation, stalking, or following (online or in-person)
-- Unwelcome physical contact or simulated physical contact (e.g., emoji)
-- Sustained disruption of talks, events, or online discussions
-
-**Discrimination**
-- Discriminatory jokes and language
-- Posting or threatening to post others' personally identifying information ("doxing")
-- Advocating for, or encouraging, any of the above behaviour
-- Microaggressions — subtle, often unintentional, discriminatory comments or actions
-
-**Professional Misconduct**
-- Publishing others' private information without explicit permission
-- Misrepresenting affiliation or contributions
-- Plagiarism or claiming credit for others' work
-- Retaliating against anyone who reports a Code of Conduct violation
-- Other conduct which could reasonably be considered inappropriate in a professional setting
-
-### Grey Areas
-
-Some situations require judgement. When uncertain:
-
-- **Intent vs Impact**: Good intentions do not excuse harmful impact. Focus on making things right.
-- **Power Dynamics**: Those with more power (maintainers, employers, experienced contributors) must be especially mindful of their impact.
-- **Cultural Differences**: What's acceptable varies by culture. When in doubt, err on the side of caution and ask.
-- **Humour**: Jokes at others' expense are rarely funny to everyone. Punch up, not down.
-
----
-
-## Scope
-
-This Code of Conduct applies within all community spaces, including:
-
-**Online Spaces**
-- Repository discussions, issues, and pull/merge requests
-- Project chat channels (Matrix, Discord, Slack, IRC)
-- Mailing lists and forums
-- Social media when representing the project
-- Video calls and virtual meetings
-
-**In-Person Spaces**
-- Conferences, meetups, and events
-- Workshops and training sessions
-- Any gathering where you represent the project
-
-**Representation**
-This Code of Conduct also applies when an individual is officially representing the community in public spaces. Examples include:
-
-- Using an official project email address
-- Posting via an official social media account
-- Acting as an appointed representative at an event
-- Speaking on behalf of the project
-
----
-
-## Enforcement
-
-### Reporting
-
-If you experience or witness unacceptable behaviour, or have any other concerns, please report it as soon as possible.
-
-**How to Report**
-
-| Method | Details | Best For |
-|--------|---------|----------|
-| **Email** | j.d.a.jewell@open.ac.uk | Detailed reports, sensitive matters |
-| **Private Message** | Contact any maintainer directly | Quick questions, minor issues |
-| **Anonymous Form** | [Link to form if available] | When you need anonymity |
-
-**What to Include**
-
-- Your contact information (unless anonymous)
-- Names/usernames of those involved
-- Description of what happened
-- When and where it occurred
-- Any witnesses
-- Any supporting evidence (screenshots, links)
-- How you would like us to respond (if you have a preference)
-
-**What Happens Next**
-
-1. You will receive acknowledgment within **{{RESPONSE_TIME}}**
-2. The {{CONDUCT_TEAM}} will review the report
-3. We may ask for additional information
-4. We will determine appropriate action
-5. We will inform you of the outcome (respecting others' privacy)
-
-### Confidentiality
-
-All reports will be handled with discretion:
-
-- Reporter identity is protected by default
-- Details are shared only with those who need to know
-- We will ask before naming you in any communication
-- Anonymous reports are accepted and investigated
-
-### Conflicts of Interest
-
-If a {{CONDUCT_TEAM}} member is involved in an incident:
-
-- They will recuse themselves from the process
-- Another maintainer or external party will handle the report
-- We will disclose any potential conflicts
-
----
-
-## Enforcement Guidelines
-
-The {{CONDUCT_TEAM}} will follow these guidelines in determining consequences:
-
-### 1. Correction
-
-**Community Impact**: Use of inappropriate language or other behaviour deemed unprofessional or unwelcome.
-
-**Consequence**: A private, written warning providing clarity around the nature of the violation and an explanation of why the behaviour was inappropriate. A public apology may be requested.
-
-**Duration**: Immediate
-
-### 2. Warning
-
-**Community Impact**: A violation through a single incident or series of actions.
-
-**Consequence**: A warning with consequences for continued behaviour. No interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, for a specified period. This includes avoiding interactions in community spaces as well as external channels like social media. Violating these terms may lead to a temporary or permanent ban.
-
-**Duration**: 1-4 weeks
-
-### 3. Temporary Ban
-
-**Community Impact**: A serious violation of community standards, including sustained inappropriate behaviour.
-
-**Consequence**: A temporary ban from any sort of interaction or public communication with the community for a specified period. No public or private interaction with the people involved, including unsolicited interaction with those enforcing the Code of Conduct, is allowed during this period. Violating these terms may lead to a permanent ban.
-
-**Duration**: 1-6 months
-
-### 4. Permanent Ban
-
-**Community Impact**: Demonstrating a pattern of violation of community standards, including sustained inappropriate behaviour, harassment of an individual, or aggression toward or disparagement of classes of individuals.
-
-**Consequence**: A permanent ban from any sort of public interaction within the community.
-
-**Duration**: Permanent (with appeal rights after 12 months)
-
-### Enforcement Across Perimeters
-
-For contributors with elevated access (Perimeter 2 or 1):
-
-| Level | Additional Consequence |
-|-------|----------------------|
-| Correction | Noted in contributor record |
-| Warning | Access privileges may be temporarily reduced |
-| Temporary Ban | Access reduced to Perimeter 3 for ban duration |
-| Permanent Ban | All access revoked |
-
----
-
-## Appeals
-
-If you believe an enforcement decision was made in error:
-
-1. **Wait 7 days** after the decision (cooling-off period)
-2. **Email** j.d.a.jewell@open.ac.uk with subject line "Appeal: [Original Report ID]"
-3. **Explain** why you believe the decision should be reconsidered
-4. **Provide** any new information not previously available
-
-**Appeals Process**
-
-- Appeals are reviewed by a different {{CONDUCT_TEAM}} member than the original
-- You will receive a response within 14 days
-- The appeals decision is final
-- You may only appeal once per incident
-
-**Grounds for Appeal**
-
-- Procedural errors in the original investigation
-- New evidence not previously available
-- Disproportionate response to the violation
-- Misunderstanding of facts
-
----
-
-## Supporting Those Who Report
-
-We are committed to supporting those who report violations:
-
-**We Will**
-- Believe and take all reports seriously
-- Respect your privacy and confidentiality preferences
-- Keep you informed of progress (if you wish)
-- Take steps to protect you from retaliation
-- Provide resources if you need support
-
-**We Will Not**
-- Require you to confront the person directly
-- Dismiss reports without investigation
-- Reveal your identity without consent
-- Tolerate retaliation against reporters
-- Rush you to make decisions
-
----
-
-## Prevention
-
-Beyond enforcement, we actively work to prevent issues:
-
-**Onboarding**
-- All contributors are expected to read this Code of Conduct
-- Perimeter 2 applicants must confirm they've read and understood it
-- Maintainers receive additional training on enforcement
-
-**Culture**
-- We model the behaviour we expect
-- We intervene early when we see potential issues
-- We thank people for positive contributions
-- We create opportunities for diverse voices
-
-**Review**
-- This Code of Conduct is reviewed annually
-- Community feedback is welcomed
-- Changes are communicated clearly
-
----
-
-## Acknowledgments
-
-This Code of Conduct is adapted from:
-
-- [Contributor Covenant](https://www.contributor-covenant.org/), version 2.1
-- [Django Code of Conduct](https://www.djangoproject.com/conduct/)
-- [Rust Code of Conduct](https://www.rust-lang.org/policies/code-of-conduct)
-- [Python Community Code of Conduct](https://www.python.org/psf/conduct/)
-
-We thank these communities for their leadership in creating welcoming spaces.
-
----
-
-## Questions?
-
-If you have questions about this Code of Conduct:
-
-- Open a [Discussion](https://github.com/hyperpolymath/ipv6-tools/discussions) (for general questions)
-- Email j.d.a.jewell@open.ac.uk (for private questions)
-- Contact any maintainer directly
-
----
-
-## Summary
-
-**Be kind. Be respectful. Be collaborative.**
-
-We're all here because we care about this project. Let's make it a place where everyone can do their best work.
-
----
-
-Last updated: 2026 · Based on Contributor Covenant 2.1
diff --git a/CONTRIBUTING.adoc b/CONTRIBUTING.adoc
new file mode 100644
index 0000000..b8c9e26
--- /dev/null
+++ b/CONTRIBUTING.adoc
@@ -0,0 +1,108 @@
+== Clone the repository
+
+git clone https://github.com/hyperpolymath/ipv6-tools.git cd ipv6-tools
+
+== Using Nix (recommended for reproducibility)
+
+nix develop
+
+== Or using toolbox/distrobox
+
+toolbox create ipv6-tools-dev toolbox enter ipv6-tools-dev # Install
+dependencies manually
+
+== Verify setup
+
+just check # or: cargo check / mix compile / etc. just test # Run test
+suite
+
+....
+
+### Repository Structure
+....
+
+ipv6-tools/ ├── src/ # Source code (Perimeter 1-2) ├── lib/ # Library
+code (Perimeter 1-2) ├── extensions/ # Extensions (Perimeter 2) ├──
+plugins/ # Plugins (Perimeter 2) ├── tools/ # Tooling (Perimeter 2) ├──
+docs/ # Documentation (Perimeter 3) │ ├── architecture/ # ADRs, specs
+(Perimeter 2) │ └── proposals/ # RFCs (Perimeter 3) ├── examples/ #
+Examples (Perimeter 3) ├── spec/ # Spec tests (Perimeter 3) ├── tests/ #
+Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files (Perimeter
+1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├── ISSUE_TEMPLATE/ │
+└── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md ├──
+CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├──
+MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake
+(Perimeter 1) └── Justfile # Task runner (Perimeter 1)
+
+....
+
+---
+
+## How to Contribute
+
+### Reporting Bugs
+
+**Before reporting**:
+1. Search existing issues
+2. Check if it's already fixed in `main`
+3. Determine which perimeter the bug affects
+
+**When reporting**:
+
+Use the [bug report template](.github/ISSUE_TEMPLATE/bug_report.md) and include:
+
+- Clear, descriptive title
+- Environment details (OS, versions, toolchain)
+- Steps to reproduce
+- Expected vs actual behaviour
+- Logs, screenshots, or minimal reproduction
+
+### Suggesting Features
+
+**Before suggesting**:
+1. Check the [roadmap](ROADMAP.md) if available
+2. Search existing issues and discussions
+3. Consider which perimeter the feature belongs to
+
+**When suggesting**:
+
+Use the [feature request template](.github/ISSUE_TEMPLATE/feature_request.md) and include:
+
+- Problem statement (what pain point does this solve?)
+- Proposed solution
+- Alternatives considered
+- Which perimeter this affects
+
+### Your First Contribution
+
+Look for issues labelled:
+
+- [`good first issue`](https://github.com/hyperpolymath/ipv6-tools/labels/good%20first%20issue) — Simple Perimeter 3 tasks
+- [`help wanted`](https://github.com/hyperpolymath/ipv6-tools/labels/help%20wanted) — Community help needed
+- [`documentation`](https://github.com/hyperpolymath/ipv6-tools/labels/documentation) — Docs improvements
+- [`perimeter-3`](https://github.com/hyperpolymath/ipv6-tools/labels/perimeter-3) — Community sandbox scope
+
+---
+
+## Development Workflow
+
+### Branch Naming
+....
+
+docs/short-description # Documentation (P3) test/what-added # Test
+additions (P3) feat/short-description # New features (P2)
+fix/issue-number-description # Bug fixes (P2) refactor/what-changed #
+Code improvements (P2) security/what-fixed # Security fixes (P1-2)
+
+....
+
+### Commit Messages
+
+We follow [Conventional Commits](https://www.conventionalcommits.org/):
+....
+
+():
+
+{empty}[optional body]
+
+{empty}[optional footer]
diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md
deleted file mode 100644
index 335b752..0000000
--- a/CONTRIBUTING.md
+++ /dev/null
@@ -1,116 +0,0 @@
-# Clone the repository
-git clone https://github.com/hyperpolymath/ipv6-tools.git
-cd ipv6-tools
-
-# Using Nix (recommended for reproducibility)
-nix develop
-
-# Or using toolbox/distrobox
-toolbox create ipv6-tools-dev
-toolbox enter ipv6-tools-dev
-# Install dependencies manually
-
-# Verify setup
-just check # or: cargo check / mix compile / etc.
-just test # Run test suite
-```
-
-### Repository Structure
-```
-ipv6-tools/
-├── src/ # Source code (Perimeter 1-2)
-├── lib/ # Library code (Perimeter 1-2)
-├── extensions/ # Extensions (Perimeter 2)
-├── plugins/ # Plugins (Perimeter 2)
-├── tools/ # Tooling (Perimeter 2)
-├── docs/ # Documentation (Perimeter 3)
-│ ├── architecture/ # ADRs, specs (Perimeter 2)
-│ └── proposals/ # RFCs (Perimeter 3)
-├── examples/ # Examples (Perimeter 3)
-├── spec/ # Spec tests (Perimeter 3)
-├── tests/ # Test suite (Perimeter 2-3)
-├── .well-known/ # Protocol files (Perimeter 1-3)
-├── .github/ # GitHub config (Perimeter 1)
-│ ├── ISSUE_TEMPLATE/
-│ └── workflows/
-├── CHANGELOG.md
-├── CODE_OF_CONDUCT.md
-├── CONTRIBUTING.md # This file
-├── GOVERNANCE.md
-├── LICENSE
-├── MAINTAINERS.md
-├── README.adoc
-├── SECURITY.md
-├── flake.nix # Nix flake (Perimeter 1)
-└── Justfile # Task runner (Perimeter 1)
-```
-
----
-
-## How to Contribute
-
-### Reporting Bugs
-
-**Before reporting**:
-1. Search existing issues
-2. Check if it's already fixed in `main`
-3. Determine which perimeter the bug affects
-
-**When reporting**:
-
-Use the [bug report template](.github/ISSUE_TEMPLATE/bug_report.md) and include:
-
-- Clear, descriptive title
-- Environment details (OS, versions, toolchain)
-- Steps to reproduce
-- Expected vs actual behaviour
-- Logs, screenshots, or minimal reproduction
-
-### Suggesting Features
-
-**Before suggesting**:
-1. Check the [roadmap](ROADMAP.md) if available
-2. Search existing issues and discussions
-3. Consider which perimeter the feature belongs to
-
-**When suggesting**:
-
-Use the [feature request template](.github/ISSUE_TEMPLATE/feature_request.md) and include:
-
-- Problem statement (what pain point does this solve?)
-- Proposed solution
-- Alternatives considered
-- Which perimeter this affects
-
-### Your First Contribution
-
-Look for issues labelled:
-
-- [`good first issue`](https://github.com/hyperpolymath/ipv6-tools/labels/good%20first%20issue) — Simple Perimeter 3 tasks
-- [`help wanted`](https://github.com/hyperpolymath/ipv6-tools/labels/help%20wanted) — Community help needed
-- [`documentation`](https://github.com/hyperpolymath/ipv6-tools/labels/documentation) — Docs improvements
-- [`perimeter-3`](https://github.com/hyperpolymath/ipv6-tools/labels/perimeter-3) — Community sandbox scope
-
----
-
-## Development Workflow
-
-### Branch Naming
-```
-docs/short-description # Documentation (P3)
-test/what-added # Test additions (P3)
-feat/short-description # New features (P2)
-fix/issue-number-description # Bug fixes (P2)
-refactor/what-changed # Code improvements (P2)
-security/what-fixed # Security fixes (P1-2)
-```
-
-### Commit Messages
-
-We follow [Conventional Commits](https://www.conventionalcommits.org/):
-```
-():
-
-[optional body]
-
-[optional footer]
diff --git a/GOVERNANCE.adoc b/GOVERNANCE.adoc
new file mode 100644
index 0000000..9b836fb
--- /dev/null
+++ b/GOVERNANCE.adoc
@@ -0,0 +1,60 @@
+== Governance
+
+=== Overview
+
+This project is governed by the following principles and structures to
+ensure transparent, inclusive, and effective decision-making.
+
+=== Roles and Responsibilities
+
+==== Maintainers
+
+Maintainers are responsible for: - Reviewing and merging pull requests -
+Managing releases and versioning - Ensuring code quality and standards -
+Triaging issues and bug reports - Community engagement and support
+
+==== Contributors
+
+Contributors are expected to: - Follow the code of conduct - Submit
+well-documented pull requests - Write tests for new functionality -
+Maintain existing tests - Update documentation as needed
+
+=== Decision Making
+
+==== Minor Changes
+
+* Can be made by any maintainer
+* Include bug fixes, documentation updates, dependency updates
+
+==== Major Changes
+
+* Require discussion in issues or pull requests
+* Include new features, architectural changes, API changes
+* Need approval from at least 2 maintainers
+
+==== Breaking Changes
+
+* Require RFC (Request for Comments) process
+* Need approval from majority of maintainers
+* Must include migration guide
+
+=== Code of Conduct
+
+All participants are expected to follow our Code of Conduct. Violations
+can be reported to the maintainers.
+
+=== Communication
+
+* *Issues*: For bug reports and feature requests
+* *Discussions*: For questions and general discussion
+* *Pull Requests*: For code contributions
+
+=== Licensing
+
+All contributions are made under the terms of the repository’s LICENSE
+file. By submitting a pull request, you agree to license your
+contributions accordingly.
+
+'''''
+
+_Last updated: 2026-07-18_
diff --git a/GOVERNANCE.md b/GOVERNANCE.md
deleted file mode 100644
index e27364c..0000000
--- a/GOVERNANCE.md
+++ /dev/null
@@ -1,60 +0,0 @@
-# Governance
-
-## Overview
-
-This project is governed by the following principles and structures to ensure transparent, inclusive, and effective decision-making.
-
-## Roles and Responsibilities
-
-### Maintainers
-
-Maintainers are responsible for:
-- Reviewing and merging pull requests
-- Managing releases and versioning
-- Ensuring code quality and standards
-- Triaging issues and bug reports
-- Community engagement and support
-
-### Contributors
-
-Contributors are expected to:
-- Follow the code of conduct
-- Submit well-documented pull requests
-- Write tests for new functionality
-- Maintain existing tests
-- Update documentation as needed
-
-## Decision Making
-
-### Minor Changes
-- Can be made by any maintainer
-- Include bug fixes, documentation updates, dependency updates
-
-### Major Changes
-- Require discussion in issues or pull requests
-- Include new features, architectural changes, API changes
-- Need approval from at least 2 maintainers
-
-### Breaking Changes
-- Require RFC (Request for Comments) process
-- Need approval from majority of maintainers
-- Must include migration guide
-
-## Code of Conduct
-
-All participants are expected to follow our Code of Conduct. Violations can be reported to the maintainers.
-
-## Communication
-
-- **Issues**: For bug reports and feature requests
-- **Discussions**: For questions and general discussion
-- **Pull Requests**: For code contributions
-
-## Licensing
-
-All contributions are made under the terms of the repository's LICENSE file.
-By submitting a pull request, you agree to license your contributions accordingly.
-
----
-
-*Last updated: 2026-07-18*
diff --git a/README.adoc b/README.adoc
new file mode 100644
index 0000000..f5f9a4d
--- /dev/null
+++ b/README.adoc
@@ -0,0 +1,54 @@
+IPv6 policy enforcement and tooling for the hyperpolymath ecosystem.
+
+This monorepo consolidates two adjacent IPv6 utilities into a single
+operational unit (shared CI, shared license, shared dependency state).
+
+== Components
+
+`+ipv6-only/+` +
+IPv6-only network policy. Enforces that an environment (a node, a
+namespace, a deployment) does not fall back to IPv4 — surfacing
+mis-configurations rather than letting them degrade silently. See the
+directory’s own README for invocation.
+
+`+ipv6-site-enforcer/+` +
+Site-level enforcement tool. Validates that a public-facing site serves
+IPv6 correctly (AAAA records, IPv6 socket bind, HTTP-over-IPv6).
+Suitable for periodic CI / monitoring use.
+
+The two pair naturally: `+ipv6-only+` enforces locally,
+`+ipv6-site-enforcer+` enforces externally.
+
+== Quickstart
+
+[source,bash]
+----
+git clone git@github.com:hyperpolymath/ipv6-tools.git
+cd ipv6-tools
+
+# ipv6-only:
+cd ipv6-only/ && just build && just test
+
+# ipv6-site-enforcer:
+cd ../ipv6-site-enforcer/ && just build && just run -- example.com
+----
+
+== Status
+
+* *Licence*: MPL-2.0. (Migrated from PMPL-1.0-or-later 2026-05-26 per
+the estate licence-debt audit, hyperpolymath/standards#196.)
+* *Estate role*: infrastructure tooling — consumed by deployment
+workflows where IPv6 readiness is a hard requirement.
+* *Audit findings*: see `+docs/tech-debt-2026-05-26.md+` if present
+(added by the 2026-05-26 estate tech-debt scan).
+
+== Contributing
+
+See CONTRIBUTING. GPG-signed commits required.
+
+== Companion repositories
+
+* https://github.com/hyperpolymath/standards[`+hyperpolymath/standards+`]
+— canonical estate-wide standards.
+* https://github.com/hyperpolymath/zerotier-k8s-link[`+hyperpolymath/zerotier-k8s-link+`]
+— adjacent network-layer tooling.
diff --git a/README.md b/README.md
deleted file mode 100644
index c40ddfe..0000000
--- a/README.md
+++ /dev/null
@@ -1,62 +0,0 @@
-
-
-IPv6 policy enforcement and tooling for the hyperpolymath ecosystem.
-
-This monorepo consolidates two adjacent IPv6 utilities into a single
-operational unit (shared CI, shared license, shared dependency state).
-
-# Components
-
-`ipv6-only/`
-IPv6-only network policy. Enforces that an environment (a node, a
-namespace, a deployment) does not fall back to IPv4 — surfacing
-mis-configurations rather than letting them degrade silently. See the
-directory’s own README for invocation.
-
-`ipv6-site-enforcer/`
-Site-level enforcement tool. Validates that a public-facing site serves
-IPv6 correctly (AAAA records, IPv6 socket bind, HTTP-over-IPv6).
-Suitable for periodic CI / monitoring use.
-
-The two pair naturally: `ipv6-only` enforces locally,
-`ipv6-site-enforcer` enforces externally.
-
-# Quickstart
-
-```bash
-git clone git@github.com:hyperpolymath/ipv6-tools.git
-cd ipv6-tools
-
-# ipv6-only:
-cd ipv6-only/ && just build && just test
-
-# ipv6-site-enforcer:
-cd ../ipv6-site-enforcer/ && just build && just run -- example.com
-```
-
-# Status
-
-- **Licence**: MPL-2.0. (Migrated from PMPL-1.0-or-later 2026-05-26 per
- the estate licence-debt audit, hyperpolymath/standards#196.)
-
-- **Estate role**: infrastructure tooling — consumed by deployment
- workflows where IPv6 readiness is a hard requirement.
-
-- **Audit findings**: see `docs/tech-debt-2026-05-26.md` if present
- (added by the 2026-05-26 estate tech-debt scan).
-
-# Contributing
-
-See CONTRIBUTING. GPG-signed
-commits required.
-
-# Companion repositories
-
-- [`hyperpolymath/standards`](https://github.com/hyperpolymath/standards)
- — canonical estate-wide standards.
-
-- [`hyperpolymath/zerotier-k8s-link`](https://github.com/hyperpolymath/zerotier-k8s-link)
- — adjacent network-layer tooling.
diff --git a/REQUIRES_INITIALISATION.adoc b/REQUIRES_INITIALISATION.adoc
new file mode 100644
index 0000000..fdd2db5
--- /dev/null
+++ b/REQUIRES_INITIALISATION.adoc
@@ -0,0 +1,195 @@
+== REQUIRES INITIALISATION
+
+*This repository is not finished being set up.* 18 substitution token(s)
+across 7 file(s) still have no value.
+
+=== Why this is not already done
+
+This repo was created from `+hyperpolymath/rsr-template-repo+`. The mint
+(`+just repo-init+`) fills every token that has a single mechanical
+answer — owner, repo, author, dates, licence, branch — and it has done
+so here.
+
+The tokens below are the ones it _deliberately cannot_ answer. They need
+a decision or a fact that exists only in your head: what this project is
+for, what command builds it, which port the service listens on, whether
+a PGP key is held at all. The template’s own token vocabulary says as
+much — you cannot sensibly answer "`required invariants`" in a
+thirty-second bootstrap.
+
+They were left *visibly unfilled on purpose*. The alternatives were both
+worse: inventing plausible values would put confident falsehoods into a
+security policy and an architecture document, and silently deleting the
+sections would hide the fact that a decision is owed. A visible gap is
+honest; a fabricated answer is not.
+
+=== Do not delete this file until every item below is resolved
+
+This file is the only marker that the work is outstanding. Deleting it
+early does not finish the setup, it just conceals it — and the next
+person or agent to arrive will reasonably assume the repo is complete.
+
+* *If you are a person:* delete this file yourself once the last item is
+done.
+* *If you are an agent:* resolve what you legitimately can, leave the
+rest, and delete this file only when no token below remains anywhere in
+the tree. Do not delete it to make a gate go green.
+
+Re-running the estate top-up tool will remove this file automatically
+once nothing is outstanding, so the safest way to finish is to fix the
+tokens and let the check confirm it.
+
+=== What is needed, and where it goes
+
+==== `+{{BUILD_CMD}}+`
+
+The exact command that builds this project.
+
+Appears in:
+
+* `+QUICKSTART-DEV.adoc+`
+
+==== `+{{BUILD_OUTPUT_PATH}}+`
+
+Where the build artefact lands.
+
+Appears in:
+
+* `+QUICKSTART-MAINTAINER.adoc+`
+
+==== `+{{CONDUCT_TEAM}}+`
+
+Name of the conduct body. If there is no committee, rewrite the sentence
+rather than substituting a plural noun into '`a \{\{CONDUCT_TEAM}}
+member`'.
+
+Appears in:
+
+* `+CODE_OF_CONDUCT.md+`
+
+==== `+{{CONSUMER1}}+`
+
+A downstream repo that consumes this one.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{CONSUMER2}}+`
+
+A second downstream consumer.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{DEP1}}+`
+
+First named dependency, in .machine_readable/INTENT.contractile.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{DEP2}}+`
+
+Second named dependency, in .machine_readable/INTENT.contractile.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{DEPS}}+`
+
+Prose summary of runtime/build dependencies.
+
+Appears in:
+
+* `+QUICKSTART-MAINTAINER.adoc+`
+
+==== `+{{DOMAIN}}+`
+
+Appears in:
+
+* `+ipv6-site-enforcer/Justfile+`
+
+==== `+{{LANG_STACK}}+`
+
+The language stack, in prose.
+
+Appears in:
+
+* `+QUICKSTART-DEV.adoc+`
+
+==== `+{{MONOREPO_OR_STANDALONE}}+`
+
+Literally '`monorepo`' or '`standalone`'.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{MUST_INVARIANTS}}+`
+
+The invariants this project guarantees. Not answerable in a bootstrap;
+it is the point of the repo.
+
+Appears in:
+
+* `+QUICKSTART-DEV.adoc+`
+
+==== `+{{ONE_PARAGRAPH_ANTI_PURPOSE}}+`
+
+A paragraph on what this deliberately is NOT for.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{ONE_PARAGRAPH_PURPOSE}}+`
+
+A paragraph on what this is for.
+
+Appears in:
+
+* `+.machine_readable/INTENT.contractile+`
+
+==== `+{{PGP_KEY_URL}}+`
+
+Public URL the PGP key can be fetched from. Same caveat as
+PGP_FINGERPRINT.
+
+Appears in:
+
+* `+SECURITY.md+`
+
+==== `+{{PROJECT_UNIQUE_STRENGTH}}+`
+
+What this does that its alternatives do not.
+
+Appears in:
+
+* `+.machine_readable/agent_instructions/methodology.a2ml+`
+
+==== `+{{RESPONSE_TIME}}+`
+
+Initial-response SLA for a security or conduct report. Promise only what
+a solo maintainer can actually meet.
+
+Appears in:
+
+* `+CODE_OF_CONDUCT.md+`
+
+==== `+{{TEST_CMD}}+`
+
+The exact command that runs its tests.
+
+Appears in:
+
+* `+QUICKSTART-DEV.adoc+`
+
+'''''
+
+Generated by the estate top-up pass. Rationale and the governing rulings
+are in `+hyperpolymath/standards+`; the token vocabulary is
+`+.machine_readable/ai/PLACEHOLDERS.adoc+` in `+rsr-template-repo+`.
diff --git a/REQUIRES_INITIALISATION.md b/REQUIRES_INITIALISATION.md
deleted file mode 100644
index d9a5383..0000000
--- a/REQUIRES_INITIALISATION.md
+++ /dev/null
@@ -1,188 +0,0 @@
-
-
-# REQUIRES INITIALISATION
-
-**This repository is not finished being set up.** 18 substitution token(s) across 7 file(s) still have no value.
-
-## Why this is not already done
-
-This repo was created from `hyperpolymath/rsr-template-repo`. The mint
-(`just repo-init`) fills every token that has a single mechanical answer —
-owner, repo, author, dates, licence, branch — and it has done so here.
-
-The tokens below are the ones it *deliberately cannot* answer. They need a
-decision or a fact that exists only in your head: what this project is for,
-what command builds it, which port the service listens on, whether a PGP key
-is held at all. The template's own token vocabulary says as much — you cannot
-sensibly answer "required invariants" in a thirty-second bootstrap.
-
-They were left **visibly unfilled on purpose**. The alternatives were both
-worse: inventing plausible values would put confident falsehoods into a
-security policy and an architecture document, and silently deleting the
-sections would hide the fact that a decision is owed. A visible gap is
-honest; a fabricated answer is not.
-
-## Do not delete this file until every item below is resolved
-
-This file is the only marker that the work is outstanding. Deleting it early
-does not finish the setup, it just conceals it — and the next person or agent
-to arrive will reasonably assume the repo is complete.
-
-- **If you are a person:** delete this file yourself once the last item is done.
-- **If you are an agent:** resolve what you legitimately can, leave the rest,
- and delete this file only when no token below remains anywhere in the tree.
- Do not delete it to make a gate go green.
-
-Re-running the estate top-up tool will remove this file automatically once
-nothing is outstanding, so the safest way to finish is to fix the tokens and
-let the check confirm it.
-
-## What is needed, and where it goes
-
-### `{{BUILD_CMD}}`
-
-The exact command that builds this project.
-
-Appears in:
-
-- `QUICKSTART-DEV.adoc`
-
-### `{{BUILD_OUTPUT_PATH}}`
-
-Where the build artefact lands.
-
-Appears in:
-
-- `QUICKSTART-MAINTAINER.adoc`
-
-### `{{CONDUCT_TEAM}}`
-
-Name of the conduct body. If there is no committee, rewrite the sentence rather than substituting a plural noun into 'a {{CONDUCT_TEAM}} member'.
-
-Appears in:
-
-- `CODE_OF_CONDUCT.md`
-
-### `{{CONSUMER1}}`
-
-A downstream repo that consumes this one.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{CONSUMER2}}`
-
-A second downstream consumer.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{DEP1}}`
-
-First named dependency, in .machine_readable/INTENT.contractile.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{DEP2}}`
-
-Second named dependency, in .machine_readable/INTENT.contractile.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{DEPS}}`
-
-Prose summary of runtime/build dependencies.
-
-Appears in:
-
-- `QUICKSTART-MAINTAINER.adoc`
-
-### `{{DOMAIN}}`
-
-Appears in:
-
-- `ipv6-site-enforcer/Justfile`
-
-### `{{LANG_STACK}}`
-
-The language stack, in prose.
-
-Appears in:
-
-- `QUICKSTART-DEV.adoc`
-
-### `{{MONOREPO_OR_STANDALONE}}`
-
-Literally 'monorepo' or 'standalone'.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{MUST_INVARIANTS}}`
-
-The invariants this project guarantees. Not answerable in a bootstrap; it is the point of the repo.
-
-Appears in:
-
-- `QUICKSTART-DEV.adoc`
-
-### `{{ONE_PARAGRAPH_ANTI_PURPOSE}}`
-
-A paragraph on what this deliberately is NOT for.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{ONE_PARAGRAPH_PURPOSE}}`
-
-A paragraph on what this is for.
-
-Appears in:
-
-- `.machine_readable/INTENT.contractile`
-
-### `{{PGP_KEY_URL}}`
-
-Public URL the PGP key can be fetched from. Same caveat as PGP_FINGERPRINT.
-
-Appears in:
-
-- `SECURITY.md`
-
-### `{{PROJECT_UNIQUE_STRENGTH}}`
-
-What this does that its alternatives do not.
-
-Appears in:
-
-- `.machine_readable/agent_instructions/methodology.a2ml`
-
-### `{{RESPONSE_TIME}}`
-
-Initial-response SLA for a security or conduct report. Promise only what a solo maintainer can actually meet.
-
-Appears in:
-
-- `CODE_OF_CONDUCT.md`
-
-### `{{TEST_CMD}}`
-
-The exact command that runs its tests.
-
-Appears in:
-
-- `QUICKSTART-DEV.adoc`
-
----
-
-Generated by the estate top-up pass. Rationale and the governing rulings are
-in `hyperpolymath/standards`; the token vocabulary is
-`.machine_readable/ai/PLACEHOLDERS.adoc` in `rsr-template-repo`.
diff --git a/SECURITY.adoc b/SECURITY.adoc
new file mode 100644
index 0000000..4037abf
--- /dev/null
+++ b/SECURITY.adoc
@@ -0,0 +1,452 @@
+== Security Policy
+
+We take security seriously. We appreciate your efforts to responsibly
+disclose vulnerabilities and will make every effort to acknowledge your
+contributions.
+
+=== Table of Contents
+
+* link:#reporting-a-vulnerability[Reporting a Vulnerability]
+* link:#what-to-include[What to Include]
+* link:#response-timeline[Response Timeline]
+* link:#disclosure-policy[Disclosure Policy]
+* link:#scope[Scope]
+* link:#safe-harbour[Safe Harbour]
+* link:#recognition[Recognition]
+* link:#security-updates[Security Updates]
+* link:#security-best-practices[Security Best Practices]
+
+'''''
+
+=== Reporting a Vulnerability
+
+==== Preferred Method: GitHub Security Advisories
+
+The preferred method for reporting security vulnerabilities is through
+GitHub’s Security Advisory feature:
+
+[arabic]
+. Navigate to
+https://github.com/hyperpolymath/ipv6-tools/security/advisories/new[Report
+a Vulnerability]
+. Click *"`Report a vulnerability`"*
+. Complete the form with as much detail as possible
+. Submit — we’ll receive a private notification
+
+This method ensures:
+
+* End-to-end encryption of your report
+* Private discussion space for collaboration
+* Coordinated disclosure tooling
+* Automatic credit when the advisory is published
+
+==== Alternative: Encrypted Email
+
+If you cannot use GitHub Security Advisories, you may email us directly:
+
+[cols=",",]
+|===
+|*Email* |j.d.a.jewell@open.ac.uk
+|*PGP Key* |link:%7B%7BPGP_KEY_URL%7D%7D[Download Public Key]
+|*Fingerprint* |`+[PGP fingerprint not set]+`
+|===
+
+[source,bash]
+----
+# Import our PGP key
+curl -sSL {{PGP_KEY_URL}} | gpg --import
+
+# Verify fingerprint
+gpg --fingerprint j.d.a.jewell@open.ac.uk
+
+# Encrypt your report
+gpg --armor --encrypt --recipient j.d.a.jewell@open.ac.uk report.txt
+----
+
+____
+*⚠️ Important:* Do not report security vulnerabilities through public
+GitHub issues, pull requests, discussions, or social media.
+____
+
+'''''
+
+=== What to Include
+
+A good vulnerability report helps us understand and reproduce the issue
+quickly.
+
+==== Required Information
+
+* *Description*: Clear explanation of the vulnerability
+* *Impact*: What an attacker could achieve (confidentiality, integrity,
+availability)
+* *Affected versions*: Which versions/commits are affected
+* *Reproduction steps*: Detailed steps to reproduce the issue
+
+==== Helpful Additional Information
+
+* *Proof of concept*: Code, scripts, or screenshots demonstrating the
+vulnerability
+* *Attack scenario*: Realistic attack scenario showing exploitability
+* *CVSS score*: Your assessment of severity (use
+https://www.first.org/cvss/calculator/3.1[CVSS 3.1 Calculator])
+* *CWE ID*: Common Weakness Enumeration identifier if known
+* *Suggested fix*: If you have ideas for remediation
+* *References*: Links to related vulnerabilities, research, or
+advisories
+
+==== Example Report Structure
+
+[source,markdown]
+----
+## Summary
+[One-sentence description of the vulnerability]
+
+## Vulnerability Type
+[e.g., SQL Injection, XSS, SSRF, Path Traversal, etc.]
+
+## Affected Component
+[File path, function name, API endpoint, etc.]
+
+## Affected Versions
+[Version range or specific commits]
+
+## Severity Assessment
+- CVSS 3.1 Score: [X.X]
+- CVSS Vector: [CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X]
+
+## Description
+[Detailed technical description]
+
+## Steps to Reproduce
+1. [First step]
+2. [Second step]
+3. [...]
+
+## Proof of Concept
+[Code, curl commands, screenshots, etc.]
+
+## Impact
+[What can an attacker achieve?]
+
+## Suggested Remediation
+[Optional: your ideas for fixing]
+
+## References
+[Links to related issues, CVEs, research]
+----
+
+'''''
+
+=== Response Timeline
+
+We commit to the following response times:
+
+[width="100%",cols="24%,35%,41%",options="header",]
+|===
+|Stage |Timeframe |Description
+|*Initial Response* |48 hours |We acknowledge receipt and confirm we’re
+investigating
+
+|*Triage* |7 days |We assess severity, confirm the vulnerability, and
+estimate timeline
+
+|*Status Update* |Every 7 days |Regular updates on remediation progress
+
+|*Resolution* |90 days |Target for fix development and release (complex
+issues may take longer)
+
+|*Disclosure* |90 days |Public disclosure after fix is available
+(coordinated with you)
+|===
+
+____
+*Note:* These are targets, not guarantees. Complex vulnerabilities may
+require more time. We’ll communicate openly about any delays.
+____
+
+'''''
+
+=== Disclosure Policy
+
+We follow *coordinated disclosure* (also known as responsible
+disclosure):
+
+[arabic]
+. *You report* the vulnerability privately
+. *We acknowledge* and begin investigation
+. *We develop* a fix and prepare a release
+. *We coordinate* disclosure timing with you
+. *We publish* security advisory and fix simultaneously
+. *You may publish* your research after disclosure
+
+==== Our Commitments
+
+* We will not take legal action against researchers who follow this
+policy
+* We will work with you to understand and resolve the issue
+* We will credit you in the security advisory (unless you prefer
+anonymity)
+* We will notify you before public disclosure
+* We will publish advisories with sufficient detail for users to assess
+risk
+
+==== Your Commitments
+
+* Report vulnerabilities promptly after discovery
+* Give us reasonable time to address the issue before disclosure
+* Do not access, modify, or delete data beyond what’s necessary to
+demonstrate the vulnerability
+* Do not degrade service availability (no DoS testing on production)
+* Do not share vulnerability details with others until coordinated
+disclosure
+
+==== Disclosure Timeline
+
+....
+Day 0 You report vulnerability
+Day 1-2 We acknowledge receipt
+Day 7 We confirm vulnerability and share initial assessment
+Day 7-90 We develop and test fix
+Day 90 Coordinated public disclosure
+ (earlier if fix is ready; later by mutual agreement)
+....
+
+If we cannot reach agreement on disclosure timing, we default to 90 days
+from your initial report.
+
+'''''
+
+=== Scope
+
+==== In Scope ✅
+
+The following are within scope for security research:
+
+* This repository (`+hyperpolymath/ipv6-tools+`) and all its code
+* Official releases and packages published from this repository
+* Documentation that could lead to security issues
+* Build and deployment configurations in this repository
+* Dependencies (report here, we’ll coordinate with upstream)
+
+==== Out of Scope ❌
+
+The following are *not* in scope:
+
+* Third-party services we integrate with (report directly to them)
+* Social engineering attacks against maintainers
+* Physical security
+* Denial of service attacks against production infrastructure
+* Spam, phishing, or other non-technical attacks
+* Issues already reported or publicly known
+* Theoretical vulnerabilities without proof of concept
+
+==== Qualifying Vulnerabilities
+
+We’re particularly interested in:
+
+* Remote code execution
+* SQL injection, command injection, code injection
+* Authentication/authorisation bypass
+* Cross-site scripting (XSS) and cross-site request forgery (CSRF)
+* Server-side request forgery (SSRF)
+* Path traversal / local file inclusion
+* Information disclosure (credentials, PII, secrets)
+* Cryptographic weaknesses
+* Deserialisation vulnerabilities
+* Memory safety issues (buffer overflows, use-after-free, etc.)
+* Supply chain vulnerabilities (dependency confusion, etc.)
+* Significant logic flaws
+
+==== Non-Qualifying Issues
+
+The following generally do not qualify as security vulnerabilities:
+
+* Missing security headers on non-sensitive pages
+* Clickjacking on pages without sensitive actions
+* Self-XSS (requires victim to paste code)
+* Missing rate limiting (unless it enables a specific attack)
+* Username/email enumeration (unless high-risk context)
+* Missing cookie flags on non-sensitive cookies
+* Software version disclosure
+* Verbose error messages (unless exposing secrets)
+* Best practice deviations without demonstrable impact
+
+'''''
+
+=== Safe Harbour
+
+We support security research conducted in good faith.
+
+==== Our Promise
+
+If you conduct security research in accordance with this policy:
+
+* ✅ We will not initiate legal action against you
+* ✅ We will not report your activity to law enforcement
+* ✅ We will work with you in good faith to resolve issues
+* ✅ We consider your research authorised under the Computer Fraud and
+Abuse Act (CFAA), UK Computer Misuse Act, and similar laws
+* ✅ We waive any potential claim against you for circumvention of
+security controls
+
+==== Good Faith Requirements
+
+To qualify for safe harbour, you must:
+
+* Comply with this security policy
+* Report vulnerabilities promptly
+* Avoid privacy violations (do not access others’ data)
+* Avoid service degradation (no destructive testing)
+* Not exploit vulnerabilities beyond proof-of-concept
+* Not use vulnerabilities for profit (beyond bug bounties where offered)
+
+____
+*⚠️ Important:* This safe harbour does not extend to third-party
+systems. Always check their policies before testing.
+____
+
+'''''
+
+=== Recognition
+
+We believe in recognising security researchers who help us improve.
+
+==== Hall of Fame
+
+Researchers who report valid vulnerabilities will be acknowledged in our
+link:SECURITY-ACKNOWLEDGMENTS.md[Security Acknowledgments] (unless they
+prefer anonymity).
+
+Recognition includes:
+
+* Your name (or chosen alias)
+* Link to your website/profile (optional)
+* Brief description of the vulnerability class
+* Date of report
+
+==== What We Offer
+
+* ✅ Public credit in security advisories
+* ✅ Acknowledgment in release notes
+* ✅ Entry in our Hall of Fame
+* ✅ Reference/recommendation letter upon request (for significant
+findings)
+
+==== What We Don’t Currently Offer
+
+* ❌ Monetary bug bounties
+* ❌ Hardware or swag
+* ❌ Paid security research contracts
+
+____
+*Note:* We’re a community project with limited resources. Your
+contributions help everyone who uses this software.
+____
+
+'''''
+
+=== Security Updates
+
+==== Receiving Updates
+
+To stay informed about security updates:
+
+* *Watch this repository*: Click "`Watch`" → "`Custom`" → Select
+"`Security alerts`"
+* *GitHub Security Advisories*: Published at
+https://github.com/hyperpolymath/ipv6-tools/security/advisories[Security
+Advisories]
+* *Release notes*: Security fixes noted in link:CHANGELOG.md[CHANGELOG]
+
+==== Update Policy
+
+[cols=",",options="header",]
+|===
+|Severity |Response
+|*Critical/High* |Patch release as soon as fix is ready
+|*Medium* |Included in next scheduled release (or earlier)
+|*Low* |Included in next scheduled release
+|===
+
+==== Supported Versions
+
+[cols=",,",options="header",]
+|===
+|Version |Supported |Notes
+|`+main+` branch |✅ Yes |Latest development
+|Latest release |✅ Yes |Current stable
+|Previous minor release |✅ Yes |Security fixes backported
+|Older versions |❌ No |Please upgrade
+|===
+
+'''''
+
+=== Security Best Practices
+
+When using Ipv6 Tools, we recommend:
+
+==== General
+
+* Keep dependencies up to date
+* Use the latest stable release
+* Subscribe to security notifications
+* Review configuration against security documentation
+* Follow principle of least privilege
+
+==== For Contributors
+
+* Never commit secrets, credentials, or API keys
+* Use signed commits (`+git config commit.gpgsign true+`)
+* Review dependencies before adding them
+* Run security linters locally before pushing
+* Report any concerns about existing code
+
+'''''
+
+=== Additional Resources
+
+* link:%7B%7BPGP_KEY_URL%7D%7D[Our PGP Public Key]
+* https://github.com/hyperpolymath/ipv6-tools/security/advisories[Security
+Advisories]
+* link:CHANGELOG.md[Changelog]
+* link:CONTRIBUTING.md[Contributing Guidelines]
+* https://cve.mitre.org/[CVE Database]
+* https://www.first.org/cvss/calculator/3.1[CVSS Calculator]
+
+'''''
+
+=== Contact
+
+[width="100%",cols="50%,50%",options="header",]
+|===
+|Purpose |Contact
+|*Security issues*
+|https://github.com/hyperpolymath/ipv6-tools/security/advisories/new[Report
+via GitHub] or j.d.a.jewell@open.ac.uk
+
+|*General questions*
+|https://github.com/hyperpolymath/ipv6-tools/discussions[GitHub
+Discussions]
+
+|*Other enquiries* |See link:README.md[README] for contact information
+|===
+
+'''''
+
+=== Policy Changes
+
+This security policy may be updated from time to time. Significant
+changes will be:
+
+* Committed to this repository with a clear commit message
+* Noted in the changelog
+* Announced via GitHub Discussions (for major changes)
+
+'''''
+
+_Thank you for helping keep Ipv6 Tools and its users safe._ 🛡️
+
+'''''
+
+Last updated: 2026 · Policy version: 1.0.0
diff --git a/SECURITY.md b/SECURITY.md
deleted file mode 100644
index 859b056..0000000
--- a/SECURITY.md
+++ /dev/null
@@ -1,390 +0,0 @@
-# Security Policy
-
-
-
-We take security seriously. We appreciate your efforts to responsibly disclose vulnerabilities and will make every effort to acknowledge your contributions.
-
-## Table of Contents
-
-- [Reporting a Vulnerability](#reporting-a-vulnerability)
-- [What to Include](#what-to-include)
-- [Response Timeline](#response-timeline)
-- [Disclosure Policy](#disclosure-policy)
-- [Scope](#scope)
-- [Safe Harbour](#safe-harbour)
-- [Recognition](#recognition)
-- [Security Updates](#security-updates)
-- [Security Best Practices](#security-best-practices)
-
----
-
-## Reporting a Vulnerability
-
-### Preferred Method: GitHub Security Advisories
-
-The preferred method for reporting security vulnerabilities is through GitHub's Security Advisory feature:
-
-1. Navigate to [Report a Vulnerability](https://github.com/hyperpolymath/ipv6-tools/security/advisories/new)
-2. Click **"Report a vulnerability"**
-3. Complete the form with as much detail as possible
-4. Submit — we'll receive a private notification
-
-This method ensures:
-
-- End-to-end encryption of your report
-- Private discussion space for collaboration
-- Coordinated disclosure tooling
-- Automatic credit when the advisory is published
-
-### Alternative: Encrypted Email
-
-If you cannot use GitHub Security Advisories, you may email us directly:
-
-| | |
-|---|---|
-| **Email** | j.d.a.jewell@open.ac.uk |
-| **PGP Key** | [Download Public Key]({{PGP_KEY_URL}}) |
-| **Fingerprint** | `[PGP fingerprint not set]` |
-
-```bash
-# Import our PGP key
-curl -sSL {{PGP_KEY_URL}} | gpg --import
-
-# Verify fingerprint
-gpg --fingerprint j.d.a.jewell@open.ac.uk
-
-# Encrypt your report
-gpg --armor --encrypt --recipient j.d.a.jewell@open.ac.uk report.txt
-```
-
-> **⚠️ Important:** Do not report security vulnerabilities through public GitHub issues, pull requests, discussions, or social media.
-
----
-
-## What to Include
-
-A good vulnerability report helps us understand and reproduce the issue quickly.
-
-### Required Information
-
-- **Description**: Clear explanation of the vulnerability
-- **Impact**: What an attacker could achieve (confidentiality, integrity, availability)
-- **Affected versions**: Which versions/commits are affected
-- **Reproduction steps**: Detailed steps to reproduce the issue
-
-### Helpful Additional Information
-
-- **Proof of concept**: Code, scripts, or screenshots demonstrating the vulnerability
-- **Attack scenario**: Realistic attack scenario showing exploitability
-- **CVSS score**: Your assessment of severity (use [CVSS 3.1 Calculator](https://www.first.org/cvss/calculator/3.1))
-- **CWE ID**: Common Weakness Enumeration identifier if known
-- **Suggested fix**: If you have ideas for remediation
-- **References**: Links to related vulnerabilities, research, or advisories
-
-### Example Report Structure
-
-```markdown
-## Summary
-[One-sentence description of the vulnerability]
-
-## Vulnerability Type
-[e.g., SQL Injection, XSS, SSRF, Path Traversal, etc.]
-
-## Affected Component
-[File path, function name, API endpoint, etc.]
-
-## Affected Versions
-[Version range or specific commits]
-
-## Severity Assessment
-- CVSS 3.1 Score: [X.X]
-- CVSS Vector: [CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X]
-
-## Description
-[Detailed technical description]
-
-## Steps to Reproduce
-1. [First step]
-2. [Second step]
-3. [...]
-
-## Proof of Concept
-[Code, curl commands, screenshots, etc.]
-
-## Impact
-[What can an attacker achieve?]
-
-## Suggested Remediation
-[Optional: your ideas for fixing]
-
-## References
-[Links to related issues, CVEs, research]
-```
-
----
-
-## Response Timeline
-
-We commit to the following response times:
-
-| Stage | Timeframe | Description |
-|-------|-----------|-------------|
-| **Initial Response** | 48 hours | We acknowledge receipt and confirm we're investigating |
-| **Triage** | 7 days | We assess severity, confirm the vulnerability, and estimate timeline |
-| **Status Update** | Every 7 days | Regular updates on remediation progress |
-| **Resolution** | 90 days | Target for fix development and release (complex issues may take longer) |
-| **Disclosure** | 90 days | Public disclosure after fix is available (coordinated with you) |
-
-> **Note:** These are targets, not guarantees. Complex vulnerabilities may require more time. We'll communicate openly about any delays.
-
----
-
-## Disclosure Policy
-
-We follow **coordinated disclosure** (also known as responsible disclosure):
-
-1. **You report** the vulnerability privately
-2. **We acknowledge** and begin investigation
-3. **We develop** a fix and prepare a release
-4. **We coordinate** disclosure timing with you
-5. **We publish** security advisory and fix simultaneously
-6. **You may publish** your research after disclosure
-
-### Our Commitments
-
-- We will not take legal action against researchers who follow this policy
-- We will work with you to understand and resolve the issue
-- We will credit you in the security advisory (unless you prefer anonymity)
-- We will notify you before public disclosure
-- We will publish advisories with sufficient detail for users to assess risk
-
-### Your Commitments
-
-- Report vulnerabilities promptly after discovery
-- Give us reasonable time to address the issue before disclosure
-- Do not access, modify, or delete data beyond what's necessary to demonstrate the vulnerability
-- Do not degrade service availability (no DoS testing on production)
-- Do not share vulnerability details with others until coordinated disclosure
-
-### Disclosure Timeline
-
-```
-Day 0 You report vulnerability
-Day 1-2 We acknowledge receipt
-Day 7 We confirm vulnerability and share initial assessment
-Day 7-90 We develop and test fix
-Day 90 Coordinated public disclosure
- (earlier if fix is ready; later by mutual agreement)
-```
-
-If we cannot reach agreement on disclosure timing, we default to 90 days from your initial report.
-
----
-
-## Scope
-
-### In Scope ✅
-
-The following are within scope for security research:
-
-- This repository (`hyperpolymath/ipv6-tools`) and all its code
-- Official releases and packages published from this repository
-- Documentation that could lead to security issues
-- Build and deployment configurations in this repository
-- Dependencies (report here, we'll coordinate with upstream)
-
-### Out of Scope ❌
-
-The following are **not** in scope:
-
-- Third-party services we integrate with (report directly to them)
-- Social engineering attacks against maintainers
-- Physical security
-- Denial of service attacks against production infrastructure
-- Spam, phishing, or other non-technical attacks
-- Issues already reported or publicly known
-- Theoretical vulnerabilities without proof of concept
-
-### Qualifying Vulnerabilities
-
-We're particularly interested in:
-
-- Remote code execution
-- SQL injection, command injection, code injection
-- Authentication/authorisation bypass
-- Cross-site scripting (XSS) and cross-site request forgery (CSRF)
-- Server-side request forgery (SSRF)
-- Path traversal / local file inclusion
-- Information disclosure (credentials, PII, secrets)
-- Cryptographic weaknesses
-- Deserialisation vulnerabilities
-- Memory safety issues (buffer overflows, use-after-free, etc.)
-- Supply chain vulnerabilities (dependency confusion, etc.)
-- Significant logic flaws
-
-### Non-Qualifying Issues
-
-The following generally do not qualify as security vulnerabilities:
-
-- Missing security headers on non-sensitive pages
-- Clickjacking on pages without sensitive actions
-- Self-XSS (requires victim to paste code)
-- Missing rate limiting (unless it enables a specific attack)
-- Username/email enumeration (unless high-risk context)
-- Missing cookie flags on non-sensitive cookies
-- Software version disclosure
-- Verbose error messages (unless exposing secrets)
-- Best practice deviations without demonstrable impact
-
----
-
-## Safe Harbour
-
-We support security research conducted in good faith.
-
-### Our Promise
-
-If you conduct security research in accordance with this policy:
-
-- ✅ We will not initiate legal action against you
-- ✅ We will not report your activity to law enforcement
-- ✅ We will work with you in good faith to resolve issues
-- ✅ We consider your research authorised under the Computer Fraud and Abuse Act (CFAA), UK Computer Misuse Act, and similar laws
-- ✅ We waive any potential claim against you for circumvention of security controls
-
-### Good Faith Requirements
-
-To qualify for safe harbour, you must:
-
-- Comply with this security policy
-- Report vulnerabilities promptly
-- Avoid privacy violations (do not access others' data)
-- Avoid service degradation (no destructive testing)
-- Not exploit vulnerabilities beyond proof-of-concept
-- Not use vulnerabilities for profit (beyond bug bounties where offered)
-
-> **⚠️ Important:** This safe harbour does not extend to third-party systems. Always check their policies before testing.
-
----
-
-## Recognition
-
-We believe in recognising security researchers who help us improve.
-
-### Hall of Fame
-
-Researchers who report valid vulnerabilities will be acknowledged in our [Security Acknowledgments](SECURITY-ACKNOWLEDGMENTS.md) (unless they prefer anonymity).
-
-Recognition includes:
-
-- Your name (or chosen alias)
-- Link to your website/profile (optional)
-- Brief description of the vulnerability class
-- Date of report
-
-### What We Offer
-
-- ✅ Public credit in security advisories
-- ✅ Acknowledgment in release notes
-- ✅ Entry in our Hall of Fame
-- ✅ Reference/recommendation letter upon request (for significant findings)
-
-### What We Don't Currently Offer
-
-- ❌ Monetary bug bounties
-- ❌ Hardware or swag
-- ❌ Paid security research contracts
-
-> **Note:** We're a community project with limited resources. Your contributions help everyone who uses this software.
-
----
-
-## Security Updates
-
-### Receiving Updates
-
-To stay informed about security updates:
-
-- **Watch this repository**: Click "Watch" → "Custom" → Select "Security alerts"
-- **GitHub Security Advisories**: Published at [Security Advisories](https://github.com/hyperpolymath/ipv6-tools/security/advisories)
-- **Release notes**: Security fixes noted in [CHANGELOG](CHANGELOG.md)
-
-### Update Policy
-
-| Severity | Response |
-|----------|----------|
-| **Critical/High** | Patch release as soon as fix is ready |
-| **Medium** | Included in next scheduled release (or earlier) |
-| **Low** | Included in next scheduled release |
-
-### Supported Versions
-
-
-
-| Version | Supported | Notes |
-|---------|-----------|-------|
-| `main` branch | ✅ Yes | Latest development |
-| Latest release | ✅ Yes | Current stable |
-| Previous minor release | ✅ Yes | Security fixes backported |
-| Older versions | ❌ No | Please upgrade |
-
----
-
-## Security Best Practices
-
-When using Ipv6 Tools, we recommend:
-
-### General
-
-- Keep dependencies up to date
-- Use the latest stable release
-- Subscribe to security notifications
-- Review configuration against security documentation
-- Follow principle of least privilege
-
-### For Contributors
-
-- Never commit secrets, credentials, or API keys
-- Use signed commits (`git config commit.gpgsign true`)
-- Review dependencies before adding them
-- Run security linters locally before pushing
-- Report any concerns about existing code
-
----
-
-## Additional Resources
-
-- [Our PGP Public Key]({{PGP_KEY_URL}})
-- [Security Advisories](https://github.com/hyperpolymath/ipv6-tools/security/advisories)
-- [Changelog](CHANGELOG.md)
-- [Contributing Guidelines](CONTRIBUTING.md)
-- [CVE Database](https://cve.mitre.org/)
-- [CVSS Calculator](https://www.first.org/cvss/calculator/3.1)
-
----
-
-## Contact
-
-| Purpose | Contact |
-|---------|---------|
-| **Security issues** | [Report via GitHub](https://github.com/hyperpolymath/ipv6-tools/security/advisories/new) or j.d.a.jewell@open.ac.uk |
-| **General questions** | [GitHub Discussions](https://github.com/hyperpolymath/ipv6-tools/discussions) |
-| **Other enquiries** | See [README](README.md) for contact information |
-
----
-
-## Policy Changes
-
-This security policy may be updated from time to time. Significant changes will be:
-
-- Committed to this repository with a clear commit message
-- Noted in the changelog
-- Announced via GitHub Discussions (for major changes)
-
----
-
-*Thank you for helping keep Ipv6 Tools and its users safe.* 🛡️
-
----
-
-Last updated: 2026 · Policy version: 1.0.0
diff --git a/TEST-NEEDS.adoc b/TEST-NEEDS.adoc
new file mode 100644
index 0000000..c9ebed9
--- /dev/null
+++ b/TEST-NEEDS.adoc
@@ -0,0 +1,31 @@
+== TEST-NEEDS.md — ipv6-tools
+
+=== CRG Grade: C — ACHIEVED 2026-04-04
+
+=== Current Test State
+
+[cols=",,",options="header",]
+|===
+|Category |Count |Notes
+|Test files |0 |Current state
+|===
+
+=== What’s Covered
+
+* [ ] No test files found
+
+=== Still Missing (for CRG B+)
+
+* [ ] Add unit tests
+* [ ] Add integration tests
+* [ ] Zig FFI tests (if applicable)
+* [ ] CI/CD test automation
+* [ ] Property-based tests
+* [ ] Edge case coverage
+
+=== Run Tests
+
+[source,bash]
+----
+# Tests needed
+----
diff --git a/TEST-NEEDS.md b/TEST-NEEDS.md
deleted file mode 100644
index ab1352a..0000000
--- a/TEST-NEEDS.md
+++ /dev/null
@@ -1,28 +0,0 @@
-# TEST-NEEDS.md — ipv6-tools
-
-## CRG Grade: C — ACHIEVED 2026-04-04
-
-## Current Test State
-
-| Category | Count | Notes |
-|----------|-------|-------|
-| Test files | 0 | Current state |
-
-## What's Covered
-
-- [ ] No test files found
-
-## Still Missing (for CRG B+)
-
-- [ ] Add unit tests
-- [ ] Add integration tests
-- [ ] Zig FFI tests (if applicable)
-- [ ] CI/CD test automation
-- [ ] Property-based tests
-- [ ] Edge case coverage
-
-## Run Tests
-
-```bash
-# Tests needed
-```
diff --git a/TOPOLOGY.md b/TOPOLOGY.adoc
similarity index 87%
rename from TOPOLOGY.md
rename to TOPOLOGY.adoc
index 430cce3..9b93bda 100644
--- a/TOPOLOGY.md
+++ b/TOPOLOGY.adoc
@@ -1,12 +1,8 @@
-
-
-
+== IPv6 Tools — Project Topology
-# IPv6 Tools — Project Topology
+=== System Architecture
-## System Architecture
-
-```
+....
┌─────────────────────────────────────────┐
│ NETWORK TRAFFIC │
│ (Dual-stack / Transition) │
@@ -39,11 +35,11 @@
│ Justfile Automation .machine_readable/ │
│ .bot_directives/ 0-AI-MANIFEST.a2ml │
└─────────────────────────────────────────┘
-```
+....
-## Completion Dashboard
+=== Completion Dashboard
-```
+....
COMPONENT STATUS NOTES
───────────────────────────────── ────────────────── ─────────────────────────────────
CORE TOOLING
@@ -62,25 +58,26 @@ REPO INFRASTRUCTURE
─────────────────────────────────────────────────────────────────────────────
OVERALL: ████████░░ ~80% IPv6 toolset stable
-```
+....
-## Key Dependencies
+=== Key Dependencies
-```
+....
ipv6-only Policy ───► ipv6-site-enforcer ───► Network Audit ───► Compliance
│ │ │
▼ ▼ ▼
ip6tables Config ─────► Interface ───────────► Traffic Filter
-```
+....
-## Update Protocol
+=== Update Protocol
This file is maintained by both humans and AI agents. When updating:
-1. **After completing a component**: Change its bar and percentage
-2. **After adding a component**: Add a new row in the appropriate section
-3. **After architectural changes**: Update the ASCII diagram
-4. **Date**: Update the `Last updated` comment at the top of this file
+[arabic]
+. *After completing a component*: Change its bar and percentage
+. *After adding a component*: Add a new row in the appropriate section
+. *After architectural changes*: Update the ASCII diagram
+. *Date*: Update the `+Last updated+` comment at the top of this file
-Progress bars use: `█` (filled) and `░` (empty), 10 characters wide.
-Percentages: 0%, 10%, 20%, ... 100% (in 10% increments).
+Progress bars use: `+█+` (filled) and `+░+` (empty), 10 characters wide.
+Percentages: 0%, 10%, 20%, … 100% (in 10% increments).
diff --git a/docs/tech-debt-2026-05-26.adoc b/docs/tech-debt-2026-05-26.adoc
new file mode 100644
index 0000000..ae5968f
--- /dev/null
+++ b/docs/tech-debt-2026-05-26.adoc
@@ -0,0 +1,69 @@
+== Tech-Debt Audit — ipv6-tools — 2026-05-26
+
+*Source:* estate-wide automated scan 2026-05-26. *Companion:*
+https://github.com/hyperpolymath/standards/tree/main/docs/audits[`+hyperpolymath/standards+`
+2026-05-26-estate-*-debt audits]. *Combined severity:* `+HIGH+`.
+
+This file records the _raw findings_ — it does not by itself fix the
+debt. Each section ends with a '`Recommended next move`' line; closing
+the debt is follow-up work.
+
+=== 1. Proof debt
+
+No proof-bearing files (`+*.v+`, `+*.lean+`, `+*.agda+`, `+*.idr+`,
+`+*.idr2+`, `+*.fst+`, `+*.dfy+`, `+*.tla+`, `+*.ads+`, `+*.adb+`) found
+in this repo.
+
+*Recommended next move:* none.
+
+=== 2. Licence debt
+
+[cols=",",options="header",]
+|===
+|Field |Value
+|LICENSE file |`+LICENSE+`
+|SPDX header |`+MPL-2.0+`
+|Manifest licence |`+NONE+`
+|Body classifier |`+Palimp-MPL-2.0+`
+|Severity |`+ok+`
+|===
+
+*Recommended next move:* none for licence.
+
+=== 3. Documentation debt
+
+[cols=",",options="header",]
+|===
+|Field |Value
+|README lines |17
+|`+docs/+` files |0
+|`+docs/+` LoC |0
+|CHANGELOG.md |N
+|CONTRIBUTING.md |Y
+|CODE_OF_CONDUCT.md |Y
+|SECURITY.md |Y
+|Severity |`+HIGH+`
+|===
+
+*Recommended next move:* expand the stub README (currently 17 lines).
+Minimum: title, what-it-is in one paragraph, install/usage, link to
+deeper docs. Use `+hyperpolymath/rsr-template-repo+` as the reference.
+
+Additionally: *CHANGELOG.md is missing.* 65% of estate repos lack one —
+adopting a CHANGELOG (or auto-generating via `+git-cliff+`) is a
+recommended estate-wide follow-up.
+
+=== Cross-references
+
+* Estate proof-debt audit:
+`+hyperpolymath/standards/docs/audits/2026-05-26-estate-proof-debt.md+`
+* Estate licence-debt audit:
+`+hyperpolymath/standards/docs/audits/2026-05-26-estate-licence-debt.md+`
+* Estate documentation-debt audit:
+`+hyperpolymath/standards/docs/audits/2026-05-26-estate-documentation-debt.md+`
+
+'''''
+
+🤖 Generated by Claude Code estate-wide tech-debt scan (2026-05-26).
+This file is informational — closing the debt is follow-up work owned by
+the maintainer.
diff --git a/docs/tech-debt-2026-05-26.md b/docs/tech-debt-2026-05-26.md
deleted file mode 100644
index 5716097..0000000
--- a/docs/tech-debt-2026-05-26.md
+++ /dev/null
@@ -1,57 +0,0 @@
-
-
-# Tech-Debt Audit — ipv6-tools — 2026-05-26
-
-**Source:** estate-wide automated scan 2026-05-26.
-**Companion:** [`hyperpolymath/standards` 2026-05-26-estate-*-debt audits](https://github.com/hyperpolymath/standards/tree/main/docs/audits).
-**Combined severity:** `HIGH`.
-
-This file records the *raw findings* — it does not by itself fix the debt. Each section ends with a 'Recommended next move' line; closing the debt is follow-up work.
-
-## 1. Proof debt
-
-No proof-bearing files (`*.v`, `*.lean`, `*.agda`, `*.idr`, `*.idr2`, `*.fst`, `*.dfy`, `*.tla`, `*.ads`, `*.adb`) found in this repo.
-
-**Recommended next move:** none.
-
-## 2. Licence debt
-
-| Field | Value |
-|---|---|
-| LICENSE file | `LICENSE` |
-| SPDX header | `MPL-2.0` |
-| Manifest licence | `NONE` |
-| Body classifier | `Palimp-MPL-2.0` |
-| Severity | `ok` |
-
-**Recommended next move:** none for licence.
-
-## 3. Documentation debt
-
-| Field | Value |
-|---|---|
-| README lines | 17 |
-| `docs/` files | 0 |
-| `docs/` LoC | 0 |
-| CHANGELOG.md | N |
-| CONTRIBUTING.md | Y |
-| CODE_OF_CONDUCT.md | Y |
-| SECURITY.md | Y |
-| Severity | `HIGH` |
-
-**Recommended next move:** expand the stub README (currently 17 lines). Minimum: title, what-it-is in one paragraph, install/usage, link to deeper docs. Use `hyperpolymath/rsr-template-repo` as the reference.
-
-Additionally: **CHANGELOG.md is missing.** 65% of estate repos lack one — adopting a CHANGELOG (or auto-generating via `git-cliff`) is a recommended estate-wide follow-up.
-
-## Cross-references
-
-- Estate proof-debt audit: `hyperpolymath/standards/docs/audits/2026-05-26-estate-proof-debt.md`
-- Estate licence-debt audit: `hyperpolymath/standards/docs/audits/2026-05-26-estate-licence-debt.md`
-- Estate documentation-debt audit: `hyperpolymath/standards/docs/audits/2026-05-26-estate-documentation-debt.md`
-
----
-
-🤖 Generated by Claude Code estate-wide tech-debt scan (2026-05-26). This file is informational — closing the debt is follow-up work owned by the maintainer.
diff --git a/ipv6-only/CHANGELOG.adoc b/ipv6-only/CHANGELOG.adoc
index e64a523..05eebb5 100644
--- a/ipv6-only/CHANGELOG.adoc
+++ b/ipv6-only/CHANGELOG.adoc
@@ -1,110 +1,116 @@
-// SPDX-License-Identifier: CC-BY-SA-4.0
-= Changelog
+== Changelog
All notable changes to this project will be documented in this file.
-The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
-and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
-
-== [Unreleased]
-
-=== Added
-- Mustfile.epx for deployment state management
-- Pre-commit hook script for RSR compliance
-- Makefile prohibition enforcement in CI
-
-=== Changed
-- **BREAKING**: Migrated from Python/Go to pure Rust implementation
-- Justfile cleaned up to remove non-existent Python/Go/web paths
-- CI workflows updated for Rust-only builds
-- Containerfile now uses multi-stage Rust build with Wolfi base
-- CONTRIBUTING.md updated with RSR language policy
-- QUICKSTART.md rewritten for Rust CLI usage
-- MAINTAINERS.md updated with RSR compliance responsibilities
-
-=== Removed
-- Python library (ipv6tools package) - replaced by Rust crates
-- Go tools - replaced by Rust implementation
-- Web application references - not yet implemented
-- Makefile - replaced by Justfile
-- npm/node dependencies - use Deno if needed
-
-== [0.1.0] - 2024-12-26
-
-=== Added
-- Rust implementation of IPv6 tools
- - `ipv6-only-core`: Core IPv6Address and IPv6Network types
- - `ipv6-only-utils`: Address utilities (compression, expansion, generation)
- - `ipv6-only-subnet`: Subnet calculator with division and containment
-- CLI tool (`ipv6`) with subcommands:
- - `validate` - Address validation
- - `calc` - Subnet calculations
- - `generate` - Address generation (link-local, ULA, EUI-64)
- - `convert` - Format conversion (compress, expand, reverse DNS)
- - `analyze` - Address type analysis
-- Complete Justfile automation framework
-- Podman Containerfile with Chainguard Wolfi base
-- Nickel configuration system (config/ipv6-tools.ncl)
-- Hurricane Electric tunnel integration scripts:
- - he-tunnel-setup.sh
- - he-update-endpoint.sh
- - he-check-status.sh
- - he-cert-check.sh
-- Shell scripts for diagnostics:
- - ipv6-diag.sh
- - ipv6-config.sh
-- RSR compliance:
- - CODE_OF_CONDUCT.md
- - MAINTAINERS.md
- - CHANGELOG.md
- - RSR anti-pattern CI checks
-- Documentation:
- - README.adoc with installation and usage
- - TUTORIAL.md
- - IPv6_PRIMER.md
- - QUICKSTART.md
- - ROADMAP.adoc
-- CI/CD pipeline with GitHub Actions:
- - Multi-version Rust testing (stable, beta)
- - Clippy linting
- - Rustfmt checks
- - Security scanning (cargo-audit)
- - Container builds
-
-=== Security
-- SECURITY.md with vulnerability reporting procedures
-- Security scanning in CI/CD pipeline
-- Podman containerization with minimal attack surface
-- Non-root container execution
-- RSR language policy for supply chain security
-
-== Release Types
-
-=== Version Numbering
-
-We use Semantic Versioning (MAJOR.MINOR.PATCH):
-- **MAJOR**: Incompatible API changes
-- **MINOR**: Backwards-compatible new features
-- **PATCH**: Backwards-compatible bug fixes
-
-=== Release Process
-
-1. Update version in Cargo.toml
-2. Update this CHANGELOG.md
-3. Create git tag: `git tag -a vX.Y.Z -m "Release X.Y.Z"`
-4. Build packages: `just build-release`
-5. Build container: `just container-build vX.Y.Z`
-6. Create GitHub release with notes
-7. Push container images
-
-=== Support Policy
-
-- **Latest major version**: Full support (features + security)
-- **Previous major version**: Security updates only (6 months)
-- **Older versions**: Community support only
-
-== Links
-
-- [Repository](https://github.com/hyperpolymath/ipv6-only)
-- [Issue Tracker](https://github.com/hyperpolymath/ipv6-only/issues)
-- [Releases](https://github.com/hyperpolymath/ipv6-only/releases)
+The format is based on https://keepachangelog.com/en/1.0.0/[Keep a
+Changelog], and this project adheres to
+https://semver.org/spec/v2.0.0.html[Semantic Versioning].
+
+=== [Unreleased]
+
+==== Added
+
+* Mustfile.epx for deployment state management
+* Pre-commit hook script for RSR compliance
+* Makefile prohibition enforcement in CI
+
+==== Changed
+
+* *BREAKING*: Migrated from Python/Go to pure Rust implementation
+* Justfile cleaned up to remove non-existent Python/Go/web paths
+* CI workflows updated for Rust-only builds
+* Containerfile now uses multi-stage Rust build with Wolfi base
+* CONTRIBUTING.md updated with RSR language policy
+* QUICKSTART.md rewritten for Rust CLI usage
+* MAINTAINERS.md updated with RSR compliance responsibilities
+
+==== Removed
+
+* Python library (ipv6tools package) - replaced by Rust crates
+* Go tools - replaced by Rust implementation
+* Web application references - not yet implemented
+* Makefile - replaced by Justfile
+* npm/node dependencies - use Deno if needed
+
+=== [0.1.0] - 2024-12-26
+
+==== Added
+
+* Rust implementation of IPv6 tools
+** `+ipv6-only-core+`: Core IPv6Address and IPv6Network types
+** `+ipv6-only-utils+`: Address utilities (compression, expansion,
+generation)
+** `+ipv6-only-subnet+`: Subnet calculator with division and containment
+* CLI tool (`+ipv6+`) with subcommands:
+** `+validate+` - Address validation
+** `+calc+` - Subnet calculations
+** `+generate+` - Address generation (link-local, ULA, EUI-64)
+** `+convert+` - Format conversion (compress, expand, reverse DNS)
+** `+analyze+` - Address type analysis
+* Complete Justfile automation framework
+* Podman Containerfile with Chainguard Wolfi base
+* Nickel configuration system (config/ipv6-tools.ncl)
+* Hurricane Electric tunnel integration scripts:
+** he-tunnel-setup.sh
+** he-update-endpoint.sh
+** he-check-status.sh
+** he-cert-check.sh
+* Shell scripts for diagnostics:
+** ipv6-diag.sh
+** ipv6-config.sh
+* RSR compliance:
+** CODE_OF_CONDUCT.md
+** MAINTAINERS.md
+** CHANGELOG.md
+** RSR anti-pattern CI checks
+* Documentation:
+** README.adoc with installation and usage
+** TUTORIAL.md
+** IPv6_PRIMER.md
+** QUICKSTART.md
+** ROADMAP.adoc
+* CI/CD pipeline with GitHub Actions:
+** Multi-version Rust testing (stable, beta)
+** Clippy linting
+** Rustfmt checks
+** Security scanning (cargo-audit)
+** Container builds
+
+==== Security
+
+* SECURITY.md with vulnerability reporting procedures
+* Security scanning in CI/CD pipeline
+* Podman containerization with minimal attack surface
+* Non-root container execution
+* RSR language policy for supply chain security
+
+=== Release Types
+
+==== Version Numbering
+
+We use Semantic Versioning (MAJOR.MINOR.PATCH): - *MAJOR*: Incompatible
+API changes - *MINOR*: Backwards-compatible new features - *PATCH*:
+Backwards-compatible bug fixes
+
+==== Release Process
+
+[arabic]
+. Update version in Cargo.toml
+. Update this CHANGELOG.md
+. Create git tag: `+git tag -a vX.Y.Z -m "Release X.Y.Z"+`
+. Build packages: `+just build-release+`
+. Build container: `+just container-build vX.Y.Z+`
+. Create GitHub release with notes
+. Push container images
+
+==== Support Policy
+
+* *Latest major version*: Full support (features + security)
+* *Previous major version*: Security updates only (6 months)
+* *Older versions*: Community support only
+
+=== Links
+
+* https://github.com/hyperpolymath/ipv6-only[Repository]
+* https://github.com/hyperpolymath/ipv6-only/issues[Issue Tracker]
+* https://github.com/hyperpolymath/ipv6-only/releases[Releases]
diff --git a/ipv6-only/CHANGELOG.md b/ipv6-only/CHANGELOG.md
deleted file mode 100644
index 497e116..0000000
--- a/ipv6-only/CHANGELOG.md
+++ /dev/null
@@ -1,109 +0,0 @@
-# Changelog
-
-All notable changes to this project will be documented in this file.
-
-The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
-and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
-
-## [Unreleased]
-
-### Added
-- Mustfile.epx for deployment state management
-- Pre-commit hook script for RSR compliance
-- Makefile prohibition enforcement in CI
-
-### Changed
-- **BREAKING**: Migrated from Python/Go to pure Rust implementation
-- Justfile cleaned up to remove non-existent Python/Go/web paths
-- CI workflows updated for Rust-only builds
-- Containerfile now uses multi-stage Rust build with Wolfi base
-- CONTRIBUTING.md updated with RSR language policy
-- QUICKSTART.md rewritten for Rust CLI usage
-- MAINTAINERS.md updated with RSR compliance responsibilities
-
-### Removed
-- Python library (ipv6tools package) - replaced by Rust crates
-- Go tools - replaced by Rust implementation
-- Web application references - not yet implemented
-- Makefile - replaced by Justfile
-- npm/node dependencies - use Deno if needed
-
-## [0.1.0] - 2024-12-26
-
-### Added
-- Rust implementation of IPv6 tools
- - `ipv6-only-core`: Core IPv6Address and IPv6Network types
- - `ipv6-only-utils`: Address utilities (compression, expansion, generation)
- - `ipv6-only-subnet`: Subnet calculator with division and containment
-- CLI tool (`ipv6`) with subcommands:
- - `validate` - Address validation
- - `calc` - Subnet calculations
- - `generate` - Address generation (link-local, ULA, EUI-64)
- - `convert` - Format conversion (compress, expand, reverse DNS)
- - `analyze` - Address type analysis
-- Complete Justfile automation framework
-- Podman Containerfile with Chainguard Wolfi base
-- Nickel configuration system (config/ipv6-tools.ncl)
-- Hurricane Electric tunnel integration scripts:
- - he-tunnel-setup.sh
- - he-update-endpoint.sh
- - he-check-status.sh
- - he-cert-check.sh
-- Shell scripts for diagnostics:
- - ipv6-diag.sh
- - ipv6-config.sh
-- RSR compliance:
- - CODE_OF_CONDUCT.md
- - MAINTAINERS.md
- - CHANGELOG.md
- - RSR anti-pattern CI checks
-- Documentation:
- - README.adoc with installation and usage
- - TUTORIAL.md
- - IPv6_PRIMER.md
- - QUICKSTART.md
- - ROADMAP.adoc
-- CI/CD pipeline with GitHub Actions:
- - Multi-version Rust testing (stable, beta)
- - Clippy linting
- - Rustfmt checks
- - Security scanning (cargo-audit)
- - Container builds
-
-### Security
-- SECURITY.md with vulnerability reporting procedures
-- Security scanning in CI/CD pipeline
-- Podman containerization with minimal attack surface
-- Non-root container execution
-- RSR language policy for supply chain security
-
-## Release Types
-
-### Version Numbering
-
-We use Semantic Versioning (MAJOR.MINOR.PATCH):
-- **MAJOR**: Incompatible API changes
-- **MINOR**: Backwards-compatible new features
-- **PATCH**: Backwards-compatible bug fixes
-
-### Release Process
-
-1. Update version in Cargo.toml
-2. Update this CHANGELOG.md
-3. Create git tag: `git tag -a vX.Y.Z -m "Release X.Y.Z"`
-4. Build packages: `just build-release`
-5. Build container: `just container-build vX.Y.Z`
-6. Create GitHub release with notes
-7. Push container images
-
-### Support Policy
-
-- **Latest major version**: Full support (features + security)
-- **Previous major version**: Security updates only (6 months)
-- **Older versions**: Community support only
-
-## Links
-
-- [Repository](https://github.com/hyperpolymath/ipv6-only)
-- [Issue Tracker](https://github.com/hyperpolymath/ipv6-only/issues)
-- [Releases](https://github.com/hyperpolymath/ipv6-only/releases)
diff --git a/ipv6-only/MAINTAINERS.adoc b/ipv6-only/MAINTAINERS.adoc
new file mode 100644
index 0000000..cf95a77
--- /dev/null
+++ b/ipv6-only/MAINTAINERS.adoc
@@ -0,0 +1,181 @@
+== Maintainers
+
+This document lists the maintainers of the IPv6-Only Tools project.
+
+=== Current Maintainers
+
+==== Lead Maintainer
+
+* *Jonathan D.A. Jewell*
+(https://github.com/hyperpolymath[@hyperpolymath])
+** Role: Project Lead, Architecture
+** Focus: Overall direction, major features, releases
+** Contact: jonathan@hyperpolymath.org
+
+=== Maintainer Responsibilities
+
+Maintainers are responsible for:
+
+[arabic]
+. *Code Review*: Reviewing and merging pull requests
+. *Issue Triage*: Categorizing and prioritizing issues
+. *Release Management*: Creating and publishing releases
+. *Security*: Responding to security issues
+. *Community*: Fostering inclusive community
+. *Documentation*: Keeping documentation current
+. *Quality*: Maintaining code quality standards
+. *Testing*: Ensuring test coverage and CI/CD health
+. *RSR Compliance*: Enforcing language policy
+
+=== Areas of Focus
+
+==== Rust Core Library (`+crates/+`)
+
+* Maintainer: hyperpolymath
+* Focus: Core IPv6 address types, subnet calculation, utilities
+
+==== CLI Tools (`+src/+`)
+
+* Maintainer: hyperpolymath
+* Focus: Command-line interface, user experience
+
+==== Shell Scripts (`+scripts/+`)
+
+* Maintainer: hyperpolymath
+* Focus: Hurricane Electric integration, diagnostics
+
+==== Configuration (`+config/+`)
+
+* Maintainer: hyperpolymath
+* Focus: Nickel configuration, build system
+
+==== Documentation (`+docs/+`)
+
+* Maintainer: hyperpolymath
+* Focus: AsciiDoc documentation, tutorials, guides
+
+==== Infrastructure
+
+* Maintainer: hyperpolymath
+* Focus: CI/CD, containers, build systems, RSR compliance
+
+=== Becoming a Maintainer
+
+We welcome new maintainers! The process:
+
+[arabic]
+. *Contribute*: Make regular, high-quality contributions
+. *Demonstrate*: Show expertise in a specific area
+. *Engage*: Help with reviews, issues, community support
+. *Nominate*: Current maintainer nominates you
+. *Approve*: Existing maintainers approve (consensus)
+. *Onboard*: Training on maintainer responsibilities
+
+==== Criteria
+
+* *Technical Excellence*: Deep knowledge of Rust and IPv6
+* *RSR Familiarity*: Understanding of language policy
+* *Judgment*: Makes sound technical and social decisions
+* *Availability*: Commits to ongoing participation
+* *Communication*: Clear, respectful communicator
+* *Alignment*: Supports project values and goals
+
+=== Emeritus Maintainers
+
+Former maintainers who have stepped down but retain honorary status:
+
+(None yet - project is new)
+
+=== Decision Making
+
+==== Consensus Model
+
+* *Minor Changes*: Any maintainer can approve and merge
+* *Moderate Changes*: Two maintainer approvals required
+* *Major Changes*: All maintainers must approve
+* *Controversial*: If no consensus, lead maintainer decides
+
+==== What Requires Approval
+
+* *Minor*: Bug fixes, documentation, tests
+* *Moderate*: New features, refactoring, dependencies
+* *Major*: Architecture changes, API changes, breaking changes
+* *Critical*: Security fixes (expedited process)
+
+=== Communication Channels
+
+* *GitHub Issues*: Bug reports, feature requests
+* *GitHub Discussions*: General questions, ideas
+* *Security*: See SECURITY.md for reporting process
+
+=== Maintainer Guidelines
+
+==== Code Review
+
+* *Timely*: Respond within 48 hours
+* *Constructive*: Provide helpful feedback
+* *Thorough*: Check code, tests, docs
+* *Respectful*: Kind and professional
+* *RSR Aware*: Enforce language policy
+
+==== Issue Management
+
+* *Triage*: Label and prioritize within 24 hours
+* *Respond*: Acknowledge within 48 hours
+* *Close*: Explain closure reasons
+* *Link*: Connect related issues
+
+==== Security
+
+* *Confidential*: Keep security issues private
+* *Timely*: Respond within 24 hours
+* *Coordinated*: Follow disclosure timeline
+* *Document*: Update SECURITY.md
+
+==== Release Process
+
+[arabic]
+. Version bump in Cargo.toml
+. Update CHANGELOG.md
+. Tag release (vX.Y.Z)
+. Build and test (`+just ci+`)
+. Publish container image
+. Create GitHub release with notes
+. Announce
+
+=== Stepping Down
+
+If a maintainer needs to step down:
+
+[arabic]
+. Notify other maintainers
+. Document in-progress work
+. Transfer responsibilities
+. Move to emeritus status
+. Update this document
+
+=== Language Policy Enforcement
+
+Maintainers must enforce RSR compliance:
+
+==== Allowed
+
+* Rust, ReScript, Deno, Bash/POSIX Shell, Nickel, Guile Scheme
+
+==== Banned (Auto-reject PRs)
+
+* TypeScript, Go, Python (except SaltStack), npm, Makefile
+
+PRs with banned languages should be rejected with a pointer to
+CONTRIBUTING.md.
+
+=== Contact
+
+For maintainer-related questions: * GitHub: Open an issue
+
+=== Changes
+
+This document is maintained by current maintainers and updated as
+needed.
+
+Last updated: 2024-12-26
diff --git a/ipv6-only/MAINTAINERS.md b/ipv6-only/MAINTAINERS.md
deleted file mode 100644
index 231db89..0000000
--- a/ipv6-only/MAINTAINERS.md
+++ /dev/null
@@ -1,167 +0,0 @@
-# Maintainers
-
-This document lists the maintainers of the IPv6-Only Tools project.
-
-## Current Maintainers
-
-### Lead Maintainer
-
-* **Jonathan D.A. Jewell** ([@hyperpolymath](https://github.com/hyperpolymath))
- - Role: Project Lead, Architecture
- - Focus: Overall direction, major features, releases
- - Contact: jonathan@hyperpolymath.org
-
-## Maintainer Responsibilities
-
-Maintainers are responsible for:
-
-1. **Code Review**: Reviewing and merging pull requests
-2. **Issue Triage**: Categorizing and prioritizing issues
-3. **Release Management**: Creating and publishing releases
-4. **Security**: Responding to security issues
-5. **Community**: Fostering inclusive community
-6. **Documentation**: Keeping documentation current
-7. **Quality**: Maintaining code quality standards
-8. **Testing**: Ensuring test coverage and CI/CD health
-9. **RSR Compliance**: Enforcing language policy
-
-## Areas of Focus
-
-### Rust Core Library (`crates/`)
-* Maintainer: hyperpolymath
-* Focus: Core IPv6 address types, subnet calculation, utilities
-
-### CLI Tools (`src/`)
-* Maintainer: hyperpolymath
-* Focus: Command-line interface, user experience
-
-### Shell Scripts (`scripts/`)
-* Maintainer: hyperpolymath
-* Focus: Hurricane Electric integration, diagnostics
-
-### Configuration (`config/`)
-* Maintainer: hyperpolymath
-* Focus: Nickel configuration, build system
-
-### Documentation (`docs/`)
-* Maintainer: hyperpolymath
-* Focus: AsciiDoc documentation, tutorials, guides
-
-### Infrastructure
-* Maintainer: hyperpolymath
-* Focus: CI/CD, containers, build systems, RSR compliance
-
-## Becoming a Maintainer
-
-We welcome new maintainers! The process:
-
-1. **Contribute**: Make regular, high-quality contributions
-2. **Demonstrate**: Show expertise in a specific area
-3. **Engage**: Help with reviews, issues, community support
-4. **Nominate**: Current maintainer nominates you
-5. **Approve**: Existing maintainers approve (consensus)
-6. **Onboard**: Training on maintainer responsibilities
-
-### Criteria
-
-* **Technical Excellence**: Deep knowledge of Rust and IPv6
-* **RSR Familiarity**: Understanding of language policy
-* **Judgment**: Makes sound technical and social decisions
-* **Availability**: Commits to ongoing participation
-* **Communication**: Clear, respectful communicator
-* **Alignment**: Supports project values and goals
-
-## Emeritus Maintainers
-
-Former maintainers who have stepped down but retain honorary status:
-
-(None yet - project is new)
-
-## Decision Making
-
-### Consensus Model
-
-* **Minor Changes**: Any maintainer can approve and merge
-* **Moderate Changes**: Two maintainer approvals required
-* **Major Changes**: All maintainers must approve
-* **Controversial**: If no consensus, lead maintainer decides
-
-### What Requires Approval
-
-* **Minor**: Bug fixes, documentation, tests
-* **Moderate**: New features, refactoring, dependencies
-* **Major**: Architecture changes, API changes, breaking changes
-* **Critical**: Security fixes (expedited process)
-
-## Communication Channels
-
-* **GitHub Issues**: Bug reports, feature requests
-* **GitHub Discussions**: General questions, ideas
-* **Security**: See SECURITY.md for reporting process
-
-## Maintainer Guidelines
-
-### Code Review
-
-* **Timely**: Respond within 48 hours
-* **Constructive**: Provide helpful feedback
-* **Thorough**: Check code, tests, docs
-* **Respectful**: Kind and professional
-* **RSR Aware**: Enforce language policy
-
-### Issue Management
-
-* **Triage**: Label and prioritize within 24 hours
-* **Respond**: Acknowledge within 48 hours
-* **Close**: Explain closure reasons
-* **Link**: Connect related issues
-
-### Security
-
-* **Confidential**: Keep security issues private
-* **Timely**: Respond within 24 hours
-* **Coordinated**: Follow disclosure timeline
-* **Document**: Update SECURITY.md
-
-### Release Process
-
-1. Version bump in Cargo.toml
-2. Update CHANGELOG.md
-3. Tag release (vX.Y.Z)
-4. Build and test (`just ci`)
-5. Publish container image
-6. Create GitHub release with notes
-7. Announce
-
-## Stepping Down
-
-If a maintainer needs to step down:
-
-1. Notify other maintainers
-2. Document in-progress work
-3. Transfer responsibilities
-4. Move to emeritus status
-5. Update this document
-
-## Language Policy Enforcement
-
-Maintainers must enforce RSR compliance:
-
-### Allowed
-- Rust, ReScript, Deno, Bash/POSIX Shell, Nickel, Guile Scheme
-
-### Banned (Auto-reject PRs)
-- TypeScript, Go, Python (except SaltStack), npm, Makefile
-
-PRs with banned languages should be rejected with a pointer to CONTRIBUTING.md.
-
-## Contact
-
-For maintainer-related questions:
-* GitHub: Open an issue
-
-## Changes
-
-This document is maintained by current maintainers and updated as needed.
-
-Last updated: 2024-12-26
diff --git a/ipv6-only/QUICKSTART.md b/ipv6-only/QUICKSTART.adoc
similarity index 72%
rename from ipv6-only/QUICKSTART.md
rename to ipv6-only/QUICKSTART.adoc
index afc2d7a..b086400 100644
--- a/ipv6-only/QUICKSTART.md
+++ b/ipv6-only/QUICKSTART.adoc
@@ -1,50 +1,55 @@
-# IPv6-Only Tools - Quick Start Guide
+== IPv6-Only Tools - Quick Start Guide
Get started with IPv6-Only Tools in 5 minutes!
-## Installation
+=== Installation
-### Option 1: Install from Source (Rust)
+==== Option 1: Install from Source (Rust)
-```bash
+[source,bash]
+----
git clone https://github.com/hyperpolymath/ipv6-only.git
cd ipv6-only
cargo build --release
# Add to PATH
sudo cp target/release/ipv6 /usr/local/bin/
-```
+----
-### Option 2: Using Podman/Docker
+==== Option 2: Using Podman/Docker
-```bash
+[source,bash]
+----
podman pull ghcr.io/hyperpolymath/ipv6-only:latest
podman run -it --rm ipv6-only
-```
+----
-### Option 3: Using Just
+==== Option 3: Using Just
-```bash
+[source,bash]
+----
just build
just install # requires sudo
-```
+----
-## First Steps
+=== First Steps
-### 1. Validate an IPv6 Address
+==== 1. Validate an IPv6 Address
-```bash
+[source,bash]
+----
ipv6 validate 2001:db8::1
# Output:
# ✓ 2001:db8::1 is valid
ipv6 validate 2001:db8::1 fe80::1%eth0 ::1
# Validates multiple addresses
-```
+----
-### 2. Analyze an Address
+==== 2. Analyze an Address
-```bash
+[source,bash]
+----
ipv6 analyze 2001:db8::1
# Output:
# Address: 2001:db8::1
@@ -57,11 +62,12 @@ ipv6 analyze 2001:db8::1
# Unique Local: false
# Multicast: false
# Global: true
-```
+----
-### 3. Calculate Subnets
+==== 3. Calculate Subnets
-```bash
+[source,bash]
+----
# Get network information
ipv6 calc 2001:db8::/32 --info
@@ -70,11 +76,12 @@ ipv6 calc 2001:db8::/32 --divide 4
# Divide by prefix length
ipv6 calc 2001:db8::/32 --prefix 48
-```
+----
-### 4. Generate Addresses
+==== 4. Generate Addresses
-```bash
+[source,bash]
+----
# Generate link-local address
ipv6 generate link-local
@@ -86,11 +93,12 @@ ipv6 generate from-mac 00:11:22:33:44:55
# Random address in prefix
ipv6 generate random --prefix 2001:db8::/64
-```
+----
-### 5. Convert Formats
+==== 5. Convert Formats
-```bash
+[source,bash]
+----
# Compress address
ipv6 convert 2001:0db8:0000:0000:0000:0000:0000:0001 --compress
# Output: 2001:db8::1
@@ -104,20 +112,22 @@ ipv6 convert 2001:db8::1 --reverse
# All formats
ipv6 convert 2001:db8::1 --all
-```
+----
-## Library Usage (Rust)
+=== Library Usage (Rust)
-Add to your `Cargo.toml`:
+Add to your `+Cargo.toml+`:
-```toml
+[source,toml]
+----
[dependencies]
ipv6-only-core = { git = "https://github.com/hyperpolymath/ipv6-only" }
ipv6-only-utils = { git = "https://github.com/hyperpolymath/ipv6-only" }
ipv6-only-subnet = { git = "https://github.com/hyperpolymath/ipv6-only" }
-```
+----
-```rust
+[source,rust]
+----
use ipv6_only_core::{IPv6Address, IPv6Network};
use ipv6_only_utils::{compress_address, generate_link_local};
use ipv6_only_subnet::IPv6SubnetCalculator;
@@ -146,11 +156,12 @@ fn main() -> Result<(), Box> {
Ok(())
}
-```
+----
-## Diagnostics (requires sudo)
+=== Diagnostics (requires sudo)
-```bash
+[source,bash]
+----
# Full diagnostics
sudo ./src/scripts/ipv6-diag.sh
@@ -159,11 +170,12 @@ sudo ./src/scripts/ipv6-diag.sh
# Show IPv6 configuration
sudo ./src/scripts/ipv6-config.sh show
-```
+----
-## Hurricane Electric Tunnel Setup
+=== Hurricane Electric Tunnel Setup
-```bash
+[source,bash]
+----
# Initial setup
sudo ./scripts/he-tunnel-setup.sh
@@ -172,11 +184,12 @@ sudo ./scripts/he-update-endpoint.sh
# Check status
./scripts/he-check-status.sh
-```
+----
-## Using Just Commands
+=== Using Just Commands
-```bash
+[source,bash]
+----
# List all commands
just
@@ -197,13 +210,14 @@ just check # Format + lint
just run validate 2001:db8::1
just run calc 2001:db8::/32 --info
just run generate link-local
-```
+----
-## Common Tasks
+=== Common Tasks
-### Task 1: Validate a List of Addresses
+==== Task 1: Validate a List of Addresses
-```bash
+[source,bash]
+----
# From command line
ipv6 validate 2001:db8::1 fe80::1 ::1
@@ -212,11 +226,12 @@ cat addresses.txt | xargs ipv6 validate
# Quiet mode (exit code only)
ipv6 validate --quiet 2001:db8::1 && echo "Valid"
-```
+----
-### Task 2: Plan Network Subnets
+==== Task 2: Plan Network Subnets
-```bash
+[source,bash]
+----
# Get recommendations
ipv6 calc 2001:db8::/48 --info
@@ -225,11 +240,12 @@ ipv6 calc 2001:db8::/48 --divide 16
# Check if address is in network
ipv6 calc 2001:db8::/32 --contains 2001:db8::1
-```
+----
-### Task 3: Check IPv6 Connectivity
+==== Task 3: Check IPv6 Connectivity
-```bash
+[source,bash]
+----
# Quick check
just check-ipv6
@@ -238,11 +254,12 @@ just diag
# Network configuration
just net-show
-```
+----
-## Testing
+=== Testing
-```bash
+[source,bash]
+----
# All tests
just test
@@ -251,32 +268,34 @@ just test-crate ipv6-only-core
# With coverage
just test-coverage
-```
+----
-## Documentation
+=== Documentation
-- **README**: Overview and installation
-- **Tutorial**: `docs/TUTORIAL.md` - Comprehensive guide
-- **IPv6 Primer**: `docs/IPv6_PRIMER.md` - Learn IPv6 basics
-- **API Docs**: `cargo doc --open`
-- **Contributing**: `CONTRIBUTING.md`
+* *README*: Overview and installation
+* *Tutorial*: `+docs/TUTORIAL.md+` - Comprehensive guide
+* *IPv6 Primer*: `+docs/IPv6_PRIMER.md+` - Learn IPv6 basics
+* *API Docs*: `+cargo doc --open+`
+* *Contributing*: `+CONTRIBUTING.md+`
-## Getting Help
+=== Getting Help
-- **Documentation**: Check `docs/` directory
-- **Issues**: https://github.com/hyperpolymath/ipv6-only/issues
-- **Just commands**: `just --list`
+* *Documentation*: Check `+docs/+` directory
+* *Issues*: https://github.com/hyperpolymath/ipv6-only/issues
+* *Just commands*: `+just --list+`
-## Next Steps
+=== Next Steps
-1. Read the [Tutorial](docs/TUTORIAL.md) for detailed examples
-2. Check out the [IPv6 Primer](docs/IPv6_PRIMER.md) to learn more
-3. Explore the library API with `cargo doc --open`
-4. Set up the pre-commit hooks with `just install-hooks`
+[arabic]
+. Read the link:docs/TUTORIAL.md[Tutorial] for detailed examples
+. Check out the link:docs/IPv6_PRIMER.md[IPv6 Primer] to learn more
+. Explore the library API with `+cargo doc --open+`
+. Set up the pre-commit hooks with `+just install-hooks+`
-## Cheat Sheet
+=== Cheat Sheet
-```bash
+[source,bash]
+----
# Validate
ipv6 validate
@@ -300,6 +319,6 @@ ipv6 convert --compress
ipv6 convert --expand
ipv6 convert --reverse
ipv6 convert --all
-```
+----
Happy IPv6 networking!
diff --git a/ipv6-only/TPCF.adoc b/ipv6-only/TPCF.adoc
new file mode 100644
index 0000000..a9d0944
--- /dev/null
+++ b/ipv6-only/TPCF.adoc
@@ -0,0 +1,258 @@
+== Tri-Perimeter Contribution Framework (TPCF)
+
+=== Overview
+
+The IPv6-Only Tools project uses the *Tri-Perimeter Contribution
+Framework (TPCF)*, a graduated trust model that balances openness with
+security. This framework defines three distinct contribution perimeters,
+each with different access levels, responsibilities, and trust
+requirements.
+
+=== The Three Perimeters
+
+==== Perimeter 3: Community Sandbox (Outer Perimeter)
+
+*Trust Level:* Open to all *Current Status:* ✅ ACTIVE
+
+*Purpose:* - Encourage widespread participation - Lower barriers to
+entry - Foster community growth - Enable experimentation
+
+*What You Can Do:* - Open issues and feature requests - Submit
+documentation fixes - Contribute examples and tutorials - Participate in
+discussions - Report bugs - Suggest improvements - Review pull requests
+(informally)
+
+*Requirements:* - GitHub account - Agreement to Code of Conduct - No
+special permissions needed
+
+*Review Process:* - Community review encouraged - Maintainer approval
+required for merge - Fast turnaround for simple changes (< 48 hours) -
+Detailed feedback provided
+
+*Typical Contributions:* - Documentation improvements - Example code -
+Test cases - Bug reports - Feature proposals - Translations (future)
+
+==== Perimeter 2: Verified Contributors (Middle Perimeter)
+
+*Trust Level:* Established contributors *Current Status:* 🔜 PLANNED
+(not yet active)
+
+*Purpose:* - Recognize regular contributors - Streamline contribution
+process - Enable more substantial changes - Build trusted community
+
+*What You Can Do:* - All Perimeter 3 privileges - Direct push to feature
+branches - Merge simple pull requests - Triage issues - Label and
+prioritize - Help onboard new contributors - Participate in design
+discussions
+
+*Requirements to Join:* - 5+ merged contributions in Perimeter 3 -
+Demonstrated understanding of project goals - Positive community
+interactions - Maintainer nomination - Background check (for
+security-sensitive areas)
+
+*Review Process:* - Peer review by other P2 contributors - Maintainer
+spot-check - More autonomy for routine changes - Expedited merge for
+trusted contributors
+
+*Responsibilities:* - Mentor P3 contributors - Review pull requests -
+Maintain code quality - Follow security practices - Uphold Code of
+Conduct
+
+==== Perimeter 1: Core Team (Inner Perimeter)
+
+*Trust Level:* Full trust *Current Status:* ✅ ACTIVE (Lead Maintainer
+only)
+
+*Purpose:* - Project governance - Security-critical decisions - Release
+management - Strategic direction
+
+*What You Can Do:* - All Perimeter 2 privileges - Merge to main branch -
+Create releases - Manage security issues - Access credentials and
+secrets - Make architectural decisions - Invite P2 contributors - Handle
+Code of Conduct violations
+
+*Requirements to Join:* - Significant long-term contributions - Deep
+technical expertise - Proven judgment and responsibility - Unanimous
+approval by existing P1 members - Enhanced background verification -
+Signing authority (GPG keys)
+
+*Responsibilities:* - Project leadership - Security incident response -
+Release quality assurance - Community health - Legal compliance -
+Conflict resolution
+
+*Current Members:* - Hyperpolymath (Lead Maintainer)
+
+=== Contribution Workflow by Perimeter
+
+==== For Perimeter 3 (Community Sandbox)
+
+[arabic]
+. Fork the repository
+. Create a feature branch
+. Make changes with tests and docs
+. Submit pull request
+. Respond to review feedback
+. Maintainer merges (or P2 for simple changes)
+
+==== For Perimeter 2 (Verified Contributors)
+
+[arabic]
+. Create branch in main repo (or fork)
+. Make changes following guidelines
+. Self-review and test
+. Create pull request
+. Peer review by another P2
+. Merge when approved
+
+==== For Perimeter 1 (Core Team)
+
+[arabic]
+. Discuss major changes in advance
+. Create branch
+. Implement with full test coverage
+. Security review for sensitive changes
+. Merge after approval
+. Monitor post-merge
+
+=== Advancing Through Perimeters
+
+==== From P3 to P2
+
+*Automatic Criteria* (any of): - 10+ merged pull requests - 3+ months of
+regular contribution - Maintained significant feature
+
+*Plus Evidence Of:* - Technical competence - Good communication -
+Community respect - Alignment with project values
+
+*Process:* 1. Self-nominate or maintainer nominates 2. Review
+contribution history 3. Existing P1/P2 members vote 4. Simple majority
+required 5. Onboarding and access granted
+
+==== From P2 to P1
+
+*Criteria:* - 6+ months as P2 contributor - Leadership demonstrated -
+Security awareness proven - Deep project knowledge - Community trust
+earned
+
+*Process:* 1. Nomination by existing P1 2. Unanimous P1 approval 3.
+Background verification 4. Formal onboarding 5. Gradual privilege
+escalation
+
+=== Security Implications
+
+==== Perimeter-Specific Security
+
+*P3:* Untrusted - All contributions reviewed - No direct repository
+access - Cannot trigger deployments - Limited issue permissions
+
+*P2:* Trusted for routine work - Can review code - Cannot merge
+security-sensitive changes - No access to secrets - Subject to audit
+
+*P1:* Fully trusted - Full repository access - Security issue access -
+Deployment permissions - Signing authority
+
+==== Incident Response
+
+If security breach occurs: 1. *P3:* Contributor account compromised →
+revoke fork access, investigate 2. *P2:* Contributor account compromised
+→ immediate revocation, audit all recent changes 3. *P1:* Maintainer
+account compromised → emergency response, rotate all secrets, public
+disclosure
+
+=== Technical Implementation
+
+==== GitHub Permissions
+
+*P3:* - Role: External contributor - Access: Fork only
+
+*P2:* - Role: Triage + Write (limited) - Access: Direct branch creation
+- Restrictions: No main/release branches
+
+*P1:* - Role: Admin - Access: Full - MFA: Required - GPG: Required
+
+==== Branch Protection
+
+* *main:* P1 only, required reviews
+* **release/*:** P1 only
+* **feature/*:** P2+ can create
+* **docs/*:** P3 can contribute
+
+==== CI/CD
+
+* *P3:* Tests run, no deployments
+* *P2:* Tests + build artifacts
+* *P1:* Full deployment pipeline
+
+=== Comparison with Traditional Models
+
+[cols=",,",options="header",]
+|===
+|Aspect |Traditional OSS |TPCF
+|Entry barrier |Low |Low (P3)
+|Trust model |All-or-nothing |Graduated
+|Security |Reactive |Proactive
+|Governance |Implicit |Explicit
+|Scaling |Ad-hoc |Structured
+|===
+
+=== Benefits
+
+==== For Contributors
+
+* Clear advancement path
+* Recognized trust levels
+* Appropriate permissions
+* Reduced friction at each level
+
+==== For Maintainers
+
+* Reduced review burden
+* Distributed responsibilities
+* Better security posture
+* Sustainable governance
+
+==== For Users
+
+* Stronger security guarantees
+* More stable releases
+* Faster bug fixes
+* Transparent governance
+
+=== FAQ
+
+*Q: Why not just use GitHub’s built-in roles?* A: TPCF adds social/trust
+dimension beyond technical permissions. It’s about community norms, not
+just access control.
+
+*Q: Can I skip straight to P2?* A: No. Everyone starts at P3 to build
+trust and familiarity.
+
+*Q: How long does P3→P2 take?* A: Varies. Quality matters more than
+quantity. Typically 2-6 months of active contribution.
+
+*Q: What if I disagree with perimeter placement?* A: Contact maintainers
+at maintainers@ipv6-only.example.com. Decisions are reviewable.
+
+*Q: Can perimeter level be revoked?* A: Yes, for Code of Conduct
+violations, security incidents, or extended inactivity (with warning).
+
+=== Related Documents
+
+* *CODE_OF_CONDUCT.md*: Community standards
+* *CONTRIBUTING.md*: How to contribute
+* *MAINTAINERS.md*: Current maintainers
+* *security.md*: Security policies
+
+=== References
+
+* link:docs/academic-papers.md#tpcf-graduated-trust-model[Academic Paper
+on TPCF]
+* https://github.com/hyperpolymath/rhodium[Rhodium Standard Repository
+Framework]
+
+=== Updates
+
+This framework evolves with the project. Suggestions welcome via GitHub
+Discussions.
+
+Last updated: 2024-11-22
diff --git a/ipv6-only/TPCF.md b/ipv6-only/TPCF.md
deleted file mode 100644
index 7d232bf..0000000
--- a/ipv6-only/TPCF.md
+++ /dev/null
@@ -1,319 +0,0 @@
-# Tri-Perimeter Contribution Framework (TPCF)
-
-## Overview
-
-The IPv6-Only Tools project uses the **Tri-Perimeter Contribution Framework (TPCF)**, a graduated trust model that balances openness with security. This framework defines three distinct contribution perimeters, each with different access levels, responsibilities, and trust requirements.
-
-## The Three Perimeters
-
-### Perimeter 3: Community Sandbox (Outer Perimeter)
-
-**Trust Level:** Open to all
-**Current Status:** ✅ ACTIVE
-
-**Purpose:**
-- Encourage widespread participation
-- Lower barriers to entry
-- Foster community growth
-- Enable experimentation
-
-**What You Can Do:**
-- Open issues and feature requests
-- Submit documentation fixes
-- Contribute examples and tutorials
-- Participate in discussions
-- Report bugs
-- Suggest improvements
-- Review pull requests (informally)
-
-**Requirements:**
-- GitHub account
-- Agreement to Code of Conduct
-- No special permissions needed
-
-**Review Process:**
-- Community review encouraged
-- Maintainer approval required for merge
-- Fast turnaround for simple changes (< 48 hours)
-- Detailed feedback provided
-
-**Typical Contributions:**
-- Documentation improvements
-- Example code
-- Test cases
-- Bug reports
-- Feature proposals
-- Translations (future)
-
-### Perimeter 2: Verified Contributors (Middle Perimeter)
-
-**Trust Level:** Established contributors
-**Current Status:** 🔜 PLANNED (not yet active)
-
-**Purpose:**
-- Recognize regular contributors
-- Streamline contribution process
-- Enable more substantial changes
-- Build trusted community
-
-**What You Can Do:**
-- All Perimeter 3 privileges
-- Direct push to feature branches
-- Merge simple pull requests
-- Triage issues
-- Label and prioritize
-- Help onboard new contributors
-- Participate in design discussions
-
-**Requirements to Join:**
-- 5+ merged contributions in Perimeter 3
-- Demonstrated understanding of project goals
-- Positive community interactions
-- Maintainer nomination
-- Background check (for security-sensitive areas)
-
-**Review Process:**
-- Peer review by other P2 contributors
-- Maintainer spot-check
-- More autonomy for routine changes
-- Expedited merge for trusted contributors
-
-**Responsibilities:**
-- Mentor P3 contributors
-- Review pull requests
-- Maintain code quality
-- Follow security practices
-- Uphold Code of Conduct
-
-### Perimeter 1: Core Team (Inner Perimeter)
-
-**Trust Level:** Full trust
-**Current Status:** ✅ ACTIVE (Lead Maintainer only)
-
-**Purpose:**
-- Project governance
-- Security-critical decisions
-- Release management
-- Strategic direction
-
-**What You Can Do:**
-- All Perimeter 2 privileges
-- Merge to main branch
-- Create releases
-- Manage security issues
-- Access credentials and secrets
-- Make architectural decisions
-- Invite P2 contributors
-- Handle Code of Conduct violations
-
-**Requirements to Join:**
-- Significant long-term contributions
-- Deep technical expertise
-- Proven judgment and responsibility
-- Unanimous approval by existing P1 members
-- Enhanced background verification
-- Signing authority (GPG keys)
-
-**Responsibilities:**
-- Project leadership
-- Security incident response
-- Release quality assurance
-- Community health
-- Legal compliance
-- Conflict resolution
-
-**Current Members:**
-- Hyperpolymath (Lead Maintainer)
-
-## Contribution Workflow by Perimeter
-
-### For Perimeter 3 (Community Sandbox)
-
-1. Fork the repository
-2. Create a feature branch
-3. Make changes with tests and docs
-4. Submit pull request
-5. Respond to review feedback
-6. Maintainer merges (or P2 for simple changes)
-
-### For Perimeter 2 (Verified Contributors)
-
-1. Create branch in main repo (or fork)
-2. Make changes following guidelines
-3. Self-review and test
-4. Create pull request
-5. Peer review by another P2
-6. Merge when approved
-
-### For Perimeter 1 (Core Team)
-
-1. Discuss major changes in advance
-2. Create branch
-3. Implement with full test coverage
-4. Security review for sensitive changes
-5. Merge after approval
-6. Monitor post-merge
-
-## Advancing Through Perimeters
-
-### From P3 to P2
-
-**Automatic Criteria** (any of):
-- 10+ merged pull requests
-- 3+ months of regular contribution
-- Maintained significant feature
-
-**Plus Evidence Of:**
-- Technical competence
-- Good communication
-- Community respect
-- Alignment with project values
-
-**Process:**
-1. Self-nominate or maintainer nominates
-2. Review contribution history
-3. Existing P1/P2 members vote
-4. Simple majority required
-5. Onboarding and access granted
-
-### From P2 to P1
-
-**Criteria:**
-- 6+ months as P2 contributor
-- Leadership demonstrated
-- Security awareness proven
-- Deep project knowledge
-- Community trust earned
-
-**Process:**
-1. Nomination by existing P1
-2. Unanimous P1 approval
-3. Background verification
-4. Formal onboarding
-5. Gradual privilege escalation
-
-## Security Implications
-
-### Perimeter-Specific Security
-
-**P3:** Untrusted
-- All contributions reviewed
-- No direct repository access
-- Cannot trigger deployments
-- Limited issue permissions
-
-**P2:** Trusted for routine work
-- Can review code
-- Cannot merge security-sensitive changes
-- No access to secrets
-- Subject to audit
-
-**P1:** Fully trusted
-- Full repository access
-- Security issue access
-- Deployment permissions
-- Signing authority
-
-### Incident Response
-
-If security breach occurs:
-1. **P3:** Contributor account compromised → revoke fork access, investigate
-2. **P2:** Contributor account compromised → immediate revocation, audit all recent changes
-3. **P1:** Maintainer account compromised → emergency response, rotate all secrets, public disclosure
-
-## Technical Implementation
-
-### GitHub Permissions
-
-**P3:**
-- Role: External contributor
-- Access: Fork only
-
-**P2:**
-- Role: Triage + Write (limited)
-- Access: Direct branch creation
-- Restrictions: No main/release branches
-
-**P1:**
-- Role: Admin
-- Access: Full
-- MFA: Required
-- GPG: Required
-
-### Branch Protection
-
-- **main:** P1 only, required reviews
-- **release/*:** P1 only
-- **feature/*:** P2+ can create
-- **docs/*:** P3 can contribute
-
-### CI/CD
-
-- **P3:** Tests run, no deployments
-- **P2:** Tests + build artifacts
-- **P1:** Full deployment pipeline
-
-## Comparison with Traditional Models
-
-| Aspect | Traditional OSS | TPCF |
-|--------|----------------|------|
-| Entry barrier | Low | Low (P3) |
-| Trust model | All-or-nothing | Graduated |
-| Security | Reactive | Proactive |
-| Governance | Implicit | Explicit |
-| Scaling | Ad-hoc | Structured |
-
-## Benefits
-
-### For Contributors
-- Clear advancement path
-- Recognized trust levels
-- Appropriate permissions
-- Reduced friction at each level
-
-### For Maintainers
-- Reduced review burden
-- Distributed responsibilities
-- Better security posture
-- Sustainable governance
-
-### For Users
-- Stronger security guarantees
-- More stable releases
-- Faster bug fixes
-- Transparent governance
-
-## FAQ
-
-**Q: Why not just use GitHub's built-in roles?**
-A: TPCF adds social/trust dimension beyond technical permissions. It's about community norms, not just access control.
-
-**Q: Can I skip straight to P2?**
-A: No. Everyone starts at P3 to build trust and familiarity.
-
-**Q: How long does P3→P2 take?**
-A: Varies. Quality matters more than quantity. Typically 2-6 months of active contribution.
-
-**Q: What if I disagree with perimeter placement?**
-A: Contact maintainers at maintainers@ipv6-only.example.com. Decisions are reviewable.
-
-**Q: Can perimeter level be revoked?**
-A: Yes, for Code of Conduct violations, security incidents, or extended inactivity (with warning).
-
-## Related Documents
-
-- **CODE_OF_CONDUCT.md**: Community standards
-- **CONTRIBUTING.md**: How to contribute
-- **MAINTAINERS.md**: Current maintainers
-- **security.md**: Security policies
-
-## References
-
-- [Academic Paper on TPCF](docs/academic-papers.md#tpcf-graduated-trust-model)
-- [Rhodium Standard Repository Framework](https://github.com/hyperpolymath/rhodium)
-
-## Updates
-
-This framework evolves with the project. Suggestions welcome via GitHub Discussions.
-
-Last updated: 2024-11-22
diff --git a/ipv6-only/docs/IPv6_PRIMER.adoc b/ipv6-only/docs/IPv6_PRIMER.adoc
new file mode 100644
index 0000000..c975862
--- /dev/null
+++ b/ipv6-only/docs/IPv6_PRIMER.adoc
@@ -0,0 +1,398 @@
+== IPv6 Primer
+
+A practical introduction to IPv6 for developers and network
+administrators.
+
+=== What is IPv6?
+
+IPv6 (Internet Protocol version 6) is the latest version of the Internet
+Protocol, designed to replace IPv4. It provides:
+
+* *Vastly larger address space*: 128-bit addresses vs 32-bit in IPv4
+* *No NAT required*: Every device can have a globally routable address
+* *Built-in security*: IPSec is mandatory (optional in IPv4)
+* *Simpler routing*: More hierarchical addressing
+* *Auto-configuration*: SLAAC (Stateless Address Autoconfiguration)
+
+=== IPv6 Address Format
+
+==== Structure
+
+IPv6 addresses are 128 bits written as 8 groups of 4 hexadecimal digits:
+
+....
+2001:0db8:85a3:0000:0000:8a2e:0370:7334
+....
+
+==== Compression Rules
+
+[arabic]
+. *Leading zeros* can be omitted:
++
+....
+2001:0db8:85a3:0000 → 2001:db8:85a3:0
+....
+. *Consecutive zeros* can be replaced with `+::+` (only once):
++
+....
+2001:0db8:0000:0000:0000:0000:0000:0001 → 2001:db8::1
+....
+
+==== Examples
+
+[width="100%",cols="55%,45%",options="header",]
+|===
+|Uncompressed |Compressed
+|`+0000:0000:0000:0000:0000:0000:0000:0001+` |`+::1+`
+
+|`+fe80:0000:0000:0000:0000:0000:0000:0001+` |`+fe80::1+`
+
+|`+2001:0db8:0000:0042:0000:8a2e:0370:7334+`
+|`+2001:db8:0:42:0:8a2e:370:7334+`
+|===
+
+=== Address Types
+
+==== Unicast Addresses
+
+===== Global Unicast (`+2000::/3+`)
+
+* Globally routable addresses
+* Similar to public IPv4 addresses
+* Example: `+2001:db8:1234::1+`
+
+===== Link-Local (`+fe80::/10+`)
+
+* Only valid on local network segment
+* Auto-configured on every IPv6 interface
+* Not routable beyond local link
+* Example: `+fe80::1+` (often with zone: `+fe80::1%eth0+`)
+
+===== Unique Local (`+fc00::/7+`)
+
+* Private addresses (like IPv4 RFC1918)
+* Prefix: `+fd00::/8+` for locally assigned
+* Not globally routable
+* Example: `+fd12:3456:789a::1+`
+
+===== Loopback (`+::1/128+`)
+
+* Localhost address
+* Equivalent to `+127.0.0.1+` in IPv4
+
+===== Unspecified (`+::/128+`)
+
+* All zeros
+* Used to indicate absence of address
+* Never assigned to interface
+
+==== Multicast (`+ff00::/8+`)
+
+* One-to-many communication
+* No broadcast in IPv6 (multicast instead)
+* Examples:
+** `+ff02::1+` - All nodes on local link
+** `+ff02::2+` - All routers on local link
+** `+ff02::1:ff00:0/104+` - Solicited-node multicast
+
+=== Prefix Notation (CIDR)
+
+IPv6 uses CIDR notation like IPv4:
+
+....
+2001:db8::/32
+ ↑ ↑
+ prefix length
+....
+
+==== Common Prefix Lengths
+
+* `+/128+` - Single host
+* `+/64+` - Single subnet (standard)
+* `+/56+` - Typical home user allocation
+* `+/48+` - Typical site/organization
+* `+/32+` - ISP allocation
+* `+/8+` - Large regional allocation
+
+==== Why /64 is Standard
+
+* Required for SLAAC
+* Allows 64-bit interface ID (EUI-64)
+* 2^64 addresses per subnet (18 quintillion!)
+
+=== Address Assignment Methods
+
+==== 1. Static Configuration
+
+Manually configure address and prefix:
+
+[source,bash]
+----
+ip -6 addr add 2001:db8::1/64 dev eth0
+----
+
+==== 2. SLAAC (Stateless Address Autoconfiguration)
+
+* Automatic configuration using Router Advertisements
+* Interface creates address from prefix + interface ID
+* Most common for hosts
+
+==== 3. DHCPv6 (Stateful)
+
+* Similar to DHCP in IPv4
+* Provides more control (DNS, etc.)
+* Can work alongside SLAAC
+
+==== 4. Privacy Extensions (RFC 4941)
+
+* Generates temporary random addresses
+* Improves privacy (harder to track devices)
+* Changes addresses periodically
+
+=== Special Addresses
+
+[cols=",",options="header",]
+|===
+|Address |Purpose
+|`+::1+` |Loopback
+|`+::+` |Unspecified
+|`+fe80::/10+` |Link-local
+|`+ff00::/8+` |Multicast
+|`+2001:db8::/32+` |Documentation (examples)
+|`+2002::/16+` |6to4 transition
+|`+fd00::/8+` |Unique local
+|===
+
+=== IPv6 in URLs
+
+IPv6 addresses in URLs must be enclosed in brackets:
+
+....
+http://[2001:db8::1]/
+http://[2001:db8::1]:8080/path
+https://[fe80::1%eth0]/
+....
+
+=== Neighbor Discovery Protocol (NDP)
+
+Replaces ARP from IPv4:
+
+* *Router Solicitation/Advertisement*: Find routers
+* *Neighbor Solicitation/Advertisement*: Find neighbors (like ARP)
+* *Redirect*: Inform of better routes
+
+Uses ICMPv6 messages.
+
+=== Transition Mechanisms
+
+==== Dual Stack
+
+* Run IPv4 and IPv6 simultaneously
+* Most common approach
+* Applications choose which to use
+
+==== Tunneling
+
+* 6in4: IPv6 over IPv4 tunnel
+* 6to4: Automatic tunneling
+* Teredo: For hosts behind NAT
+
+==== Translation
+
+* NAT64: IPv6-only to IPv4 communication
+* DNS64: Synthesize AAAA records
+
+=== IPv6 Headers
+
+==== Simplified Header
+
+IPv6 header is simpler than IPv4: - Fixed 40-byte header - No header
+checksum - No fragmentation by routers - Extension headers for optional
+features
+
+==== Extension Headers
+
+* Routing
+* Fragment
+* Authentication (AH)
+* Encapsulation (ESP)
+* Hop-by-hop options
+* Destination options
+
+=== Subnetting Examples
+
+==== Example 1: Enterprise Network
+
+You receive: `+2001:db8::/32+`
+
+Allocation:
+
+....
+HQ: 2001:db8:0::/48
+Branch 1: 2001:db8:1::/48
+Branch 2: 2001:db8:2::/48
+...
+Branch 65535: 2001:db8:ffff::/48
+....
+
+Within HQ:
+
+....
+Engineering: 2001:db8:0:1::/64
+Sales: 2001:db8:0:2::/64
+IT: 2001:db8:0:3::/64
+...
+....
+
+==== Example 2: Data Center
+
+You have: `+2001:db8::/32+`
+
+....
+/32 Provider allocation
+/40 Region (256 regions)
+/48 Data center (256 DCs per region)
+/56 Customer (256 customers per DC)
+/64 Subnet (256 subnets per customer)
+....
+
+=== Best Practices
+
+==== 1. Addressing Plan
+
+* Plan hierarchy before deployment
+* Use consistent patterns
+* Document allocations
+* Leave room for growth
+
+==== 2. Use Standard Prefixes
+
+* `+/64+` for end-user subnets
+* `+/48+` for sites
+* Don’t use prefixes longer than /64 for SLAAC
+
+==== 3. Security
+
+* Still need firewalls (IPv6 doesn’t mean "`no firewall`")
+* Be aware of extension headers
+* Monitor ICMPv6 (needed for functionality)
+* Watch for ND attacks
+
+==== 4. Monitoring
+
+* Track address usage
+* Monitor ND cache
+* Watch for rogue RAs
+* Log unusual traffic
+
+==== 5. Documentation
+
+* Document address plan
+* Note special allocations
+* Keep DNS updated
+* Maintain IPAM database
+
+=== Common Misconceptions
+
+==== ❌ "`IPv6 is secure so I don’t need a firewall`"
+
+*FALSE*: IPv6 includes IPSec, but firewalls are still necessary.
+
+==== ❌ "`I can use any address in fc00::/7`"
+
+*PARTIAL*: Use `+fd00::/8+`. Generate random global ID.
+
+==== ❌ "`I should conserve IPv6 addresses`"
+
+*FALSE*: Address space is huge. Use /64 liberally.
+
+==== ❌ "`NAT provides security`"
+
+*FALSE*: NAT provides obscurity, not security. Use firewalls.
+
+==== ❌ "`I can disable ICMPv6`"
+
+*FALSE*: ICMPv6 is essential for IPv6 operation (NDP, PMTUD).
+
+=== Quick Reference
+
+==== Address Classes
+
+....
+::1/128 Loopback
+::/128 Unspecified
+fe80::/10 Link-local
+fc00::/7 Unique local (ULA)
+2000::/3 Global unicast
+ff00::/8 Multicast
+2001:db8::/32 Documentation
+....
+
+==== Tools
+
+[source,bash]
+----
+# Show IPv6 addresses
+ip -6 addr show
+
+# Show IPv6 routes
+ip -6 route show
+
+# Show neighbors
+ip -6 neigh show
+
+# Ping IPv6
+ping6 2001:db8::1
+
+# Trace route
+traceroute6 2001:db8::1
+
+# DNS lookup
+dig AAAA example.com
+----
+
+==== Python Quick Start
+
+[source,python]
+----
+from ipv6tools import IPv6Address, IPv6Network
+
+# Create address
+addr = IPv6Address("2001:db8::1")
+print(addr.is_global) # True
+
+# Create network
+net = IPv6Network("2001:db8::/32")
+print(net.contains("2001:db8::1")) # True
+----
+
+=== Learning Resources
+
+==== RFCs
+
+* https://tools.ietf.org/html/rfc8200[RFC 8200] - IPv6 Specification
+* https://tools.ietf.org/html/rfc4291[RFC 4291] - Addressing
+Architecture
+* https://tools.ietf.org/html/rfc4862[RFC 4862] - SLAAC
+* https://tools.ietf.org/html/rfc4443[RFC 4443] - ICMPv6
+
+==== Websites
+
+* https://www.ipv6.com/[IPv6.com]
+* https://ipv6.he.net/certification/[Hurricane Electric IPv6
+Certification]
+* https://www.ripe.net/support/training/material/ipv6[RIPE NCC IPv6
+Info]
+
+==== Books
+
+* "`IPv6 Fundamentals`" by Rick Graziani
+* "`IPv6 Address Planning`" by Tom Coffeen
+
+=== Next Steps
+
+[arabic]
+. Read the link:TUTORIAL.md[Tutorial]
+. Try the link:../examples/[Examples]
+. Use the link:../src/web/index.html[Web Tools]
+. Practice with the link:../README.md#command-line-tools[CLI Tools]
diff --git a/ipv6-only/docs/IPv6_PRIMER.md b/ipv6-only/docs/IPv6_PRIMER.md
deleted file mode 100644
index 1a24e68..0000000
--- a/ipv6-only/docs/IPv6_PRIMER.md
+++ /dev/null
@@ -1,348 +0,0 @@
-# IPv6 Primer
-
-A practical introduction to IPv6 for developers and network administrators.
-
-## What is IPv6?
-
-IPv6 (Internet Protocol version 6) is the latest version of the Internet Protocol, designed to replace IPv4. It provides:
-
-- **Vastly larger address space**: 128-bit addresses vs 32-bit in IPv4
-- **No NAT required**: Every device can have a globally routable address
-- **Built-in security**: IPSec is mandatory (optional in IPv4)
-- **Simpler routing**: More hierarchical addressing
-- **Auto-configuration**: SLAAC (Stateless Address Autoconfiguration)
-
-## IPv6 Address Format
-
-### Structure
-
-IPv6 addresses are 128 bits written as 8 groups of 4 hexadecimal digits:
-
-```
-2001:0db8:85a3:0000:0000:8a2e:0370:7334
-```
-
-### Compression Rules
-
-1. **Leading zeros** can be omitted:
- ```
- 2001:0db8:85a3:0000 → 2001:db8:85a3:0
- ```
-
-2. **Consecutive zeros** can be replaced with `::` (only once):
- ```
- 2001:0db8:0000:0000:0000:0000:0000:0001 → 2001:db8::1
- ```
-
-### Examples
-
-| Uncompressed | Compressed |
-|-------------|-----------|
-| `0000:0000:0000:0000:0000:0000:0000:0001` | `::1` |
-| `fe80:0000:0000:0000:0000:0000:0000:0001` | `fe80::1` |
-| `2001:0db8:0000:0042:0000:8a2e:0370:7334` | `2001:db8:0:42:0:8a2e:370:7334` |
-
-## Address Types
-
-### Unicast Addresses
-
-#### Global Unicast (`2000::/3`)
-- Globally routable addresses
-- Similar to public IPv4 addresses
-- Example: `2001:db8:1234::1`
-
-#### Link-Local (`fe80::/10`)
-- Only valid on local network segment
-- Auto-configured on every IPv6 interface
-- Not routable beyond local link
-- Example: `fe80::1` (often with zone: `fe80::1%eth0`)
-
-#### Unique Local (`fc00::/7`)
-- Private addresses (like IPv4 RFC1918)
-- Prefix: `fd00::/8` for locally assigned
-- Not globally routable
-- Example: `fd12:3456:789a::1`
-
-#### Loopback (`::1/128`)
-- Localhost address
-- Equivalent to `127.0.0.1` in IPv4
-
-#### Unspecified (`::/128`)
-- All zeros
-- Used to indicate absence of address
-- Never assigned to interface
-
-### Multicast (`ff00::/8`)
-- One-to-many communication
-- No broadcast in IPv6 (multicast instead)
-- Examples:
- - `ff02::1` - All nodes on local link
- - `ff02::2` - All routers on local link
- - `ff02::1:ff00:0/104` - Solicited-node multicast
-
-## Prefix Notation (CIDR)
-
-IPv6 uses CIDR notation like IPv4:
-
-```
-2001:db8::/32
- ↑ ↑
- prefix length
-```
-
-### Common Prefix Lengths
-
-- `/128` - Single host
-- `/64` - Single subnet (standard)
-- `/56` - Typical home user allocation
-- `/48` - Typical site/organization
-- `/32` - ISP allocation
-- `/8` - Large regional allocation
-
-### Why /64 is Standard
-
-- Required for SLAAC
-- Allows 64-bit interface ID (EUI-64)
-- 2^64 addresses per subnet (18 quintillion!)
-
-## Address Assignment Methods
-
-### 1. Static Configuration
-Manually configure address and prefix:
-```bash
-ip -6 addr add 2001:db8::1/64 dev eth0
-```
-
-### 2. SLAAC (Stateless Address Autoconfiguration)
-- Automatic configuration using Router Advertisements
-- Interface creates address from prefix + interface ID
-- Most common for hosts
-
-### 3. DHCPv6 (Stateful)
-- Similar to DHCP in IPv4
-- Provides more control (DNS, etc.)
-- Can work alongside SLAAC
-
-### 4. Privacy Extensions (RFC 4941)
-- Generates temporary random addresses
-- Improves privacy (harder to track devices)
-- Changes addresses periodically
-
-## Special Addresses
-
-| Address | Purpose |
-|---------|---------|
-| `::1` | Loopback |
-| `::` | Unspecified |
-| `fe80::/10` | Link-local |
-| `ff00::/8` | Multicast |
-| `2001:db8::/32` | Documentation (examples) |
-| `2002::/16` | 6to4 transition |
-| `fd00::/8` | Unique local |
-
-## IPv6 in URLs
-
-IPv6 addresses in URLs must be enclosed in brackets:
-
-```
-http://[2001:db8::1]/
-http://[2001:db8::1]:8080/path
-https://[fe80::1%eth0]/
-```
-
-## Neighbor Discovery Protocol (NDP)
-
-Replaces ARP from IPv4:
-
-- **Router Solicitation/Advertisement**: Find routers
-- **Neighbor Solicitation/Advertisement**: Find neighbors (like ARP)
-- **Redirect**: Inform of better routes
-
-Uses ICMPv6 messages.
-
-## Transition Mechanisms
-
-### Dual Stack
-- Run IPv4 and IPv6 simultaneously
-- Most common approach
-- Applications choose which to use
-
-### Tunneling
-- 6in4: IPv6 over IPv4 tunnel
-- 6to4: Automatic tunneling
-- Teredo: For hosts behind NAT
-
-### Translation
-- NAT64: IPv6-only to IPv4 communication
-- DNS64: Synthesize AAAA records
-
-## IPv6 Headers
-
-### Simplified Header
-IPv6 header is simpler than IPv4:
-- Fixed 40-byte header
-- No header checksum
-- No fragmentation by routers
-- Extension headers for optional features
-
-### Extension Headers
-- Routing
-- Fragment
-- Authentication (AH)
-- Encapsulation (ESP)
-- Hop-by-hop options
-- Destination options
-
-## Subnetting Examples
-
-### Example 1: Enterprise Network
-
-You receive: `2001:db8::/32`
-
-Allocation:
-```
-HQ: 2001:db8:0::/48
-Branch 1: 2001:db8:1::/48
-Branch 2: 2001:db8:2::/48
-...
-Branch 65535: 2001:db8:ffff::/48
-```
-
-Within HQ:
-```
-Engineering: 2001:db8:0:1::/64
-Sales: 2001:db8:0:2::/64
-IT: 2001:db8:0:3::/64
-...
-```
-
-### Example 2: Data Center
-
-You have: `2001:db8::/32`
-
-```
-/32 Provider allocation
-/40 Region (256 regions)
-/48 Data center (256 DCs per region)
-/56 Customer (256 customers per DC)
-/64 Subnet (256 subnets per customer)
-```
-
-## Best Practices
-
-### 1. Addressing Plan
-- Plan hierarchy before deployment
-- Use consistent patterns
-- Document allocations
-- Leave room for growth
-
-### 2. Use Standard Prefixes
-- `/64` for end-user subnets
-- `/48` for sites
-- Don't use prefixes longer than /64 for SLAAC
-
-### 3. Security
-- Still need firewalls (IPv6 doesn't mean "no firewall")
-- Be aware of extension headers
-- Monitor ICMPv6 (needed for functionality)
-- Watch for ND attacks
-
-### 4. Monitoring
-- Track address usage
-- Monitor ND cache
-- Watch for rogue RAs
-- Log unusual traffic
-
-### 5. Documentation
-- Document address plan
-- Note special allocations
-- Keep DNS updated
-- Maintain IPAM database
-
-## Common Misconceptions
-
-### ❌ "IPv6 is secure so I don't need a firewall"
-**FALSE**: IPv6 includes IPSec, but firewalls are still necessary.
-
-### ❌ "I can use any address in fc00::/7"
-**PARTIAL**: Use `fd00::/8`. Generate random global ID.
-
-### ❌ "I should conserve IPv6 addresses"
-**FALSE**: Address space is huge. Use /64 liberally.
-
-### ❌ "NAT provides security"
-**FALSE**: NAT provides obscurity, not security. Use firewalls.
-
-### ❌ "I can disable ICMPv6"
-**FALSE**: ICMPv6 is essential for IPv6 operation (NDP, PMTUD).
-
-## Quick Reference
-
-### Address Classes
-```
-::1/128 Loopback
-::/128 Unspecified
-fe80::/10 Link-local
-fc00::/7 Unique local (ULA)
-2000::/3 Global unicast
-ff00::/8 Multicast
-2001:db8::/32 Documentation
-```
-
-### Tools
-```bash
-# Show IPv6 addresses
-ip -6 addr show
-
-# Show IPv6 routes
-ip -6 route show
-
-# Show neighbors
-ip -6 neigh show
-
-# Ping IPv6
-ping6 2001:db8::1
-
-# Trace route
-traceroute6 2001:db8::1
-
-# DNS lookup
-dig AAAA example.com
-```
-
-### Python Quick Start
-```python
-from ipv6tools import IPv6Address, IPv6Network
-
-# Create address
-addr = IPv6Address("2001:db8::1")
-print(addr.is_global) # True
-
-# Create network
-net = IPv6Network("2001:db8::/32")
-print(net.contains("2001:db8::1")) # True
-```
-
-## Learning Resources
-
-### RFCs
-- [RFC 8200](https://tools.ietf.org/html/rfc8200) - IPv6 Specification
-- [RFC 4291](https://tools.ietf.org/html/rfc4291) - Addressing Architecture
-- [RFC 4862](https://tools.ietf.org/html/rfc4862) - SLAAC
-- [RFC 4443](https://tools.ietf.org/html/rfc4443) - ICMPv6
-
-### Websites
-- [IPv6.com](https://www.ipv6.com/)
-- [Hurricane Electric IPv6 Certification](https://ipv6.he.net/certification/)
-- [RIPE NCC IPv6 Info](https://www.ripe.net/support/training/material/ipv6)
-
-### Books
-- "IPv6 Fundamentals" by Rick Graziani
-- "IPv6 Address Planning" by Tom Coffeen
-
-## Next Steps
-
-1. Read the [Tutorial](TUTORIAL.md)
-2. Try the [Examples](../examples/)
-3. Use the [Web Tools](../src/web/index.html)
-4. Practice with the [CLI Tools](../README.md#command-line-tools)
diff --git a/ipv6-only/docs/TUTORIAL.md b/ipv6-only/docs/TUTORIAL.adoc
similarity index 71%
rename from ipv6-only/docs/TUTORIAL.md
rename to ipv6-only/docs/TUTORIAL.adoc
index 2d93d39..2e7ef59 100644
--- a/ipv6-only/docs/TUTORIAL.md
+++ b/ipv6-only/docs/TUTORIAL.adoc
@@ -1,40 +1,44 @@
-# IPv6 Tools Tutorial
+== IPv6 Tools Tutorial
A comprehensive guide to using the IPv6-only toolkit.
-## Table of Contents
+=== Table of Contents
-1. [Getting Started](#getting-started)
-2. [Address Basics](#address-basics)
-3. [Network Operations](#network-operations)
-4. [Subnet Planning](#subnet-planning)
-5. [Address Generation](#address-generation)
-6. [Command-Line Tools](#command-line-tools)
-7. [Advanced Topics](#advanced-topics)
+[arabic]
+. link:#getting-started[Getting Started]
+. link:#address-basics[Address Basics]
+. link:#network-operations[Network Operations]
+. link:#subnet-planning[Subnet Planning]
+. link:#address-generation[Address Generation]
+. link:#command-line-tools[Command-Line Tools]
+. link:#advanced-topics[Advanced Topics]
-## Getting Started
+=== Getting Started
-### Installation
+==== Installation
-```bash
+[source,bash]
+----
pip install ipv6-only
-```
+----
-### First Steps
+==== First Steps
-```python
+[source,python]
+----
from ipv6tools import IPv6Address, IPv6Network
# Create an address
addr = IPv6Address("2001:db8::1")
print(addr.compressed) # 2001:db8::1
-```
+----
-## Address Basics
+=== Address Basics
-### Creating Addresses
+==== Creating Addresses
-```python
+[source,python]
+----
from ipv6tools import IPv6Address
# Various formats work
@@ -43,11 +47,12 @@ addr2 = IPv6Address("2001:0db8:0000:0000:0000:0000:0000:0001")
addr3 = IPv6Address("fe80::1%eth0") # With zone ID
print(addr1 == addr2) # True - same address
-```
+----
-### Address Properties
+==== Address Properties
-```python
+[source,python]
+----
addr = IPv6Address("fe80::1")
# Check address type
@@ -57,11 +62,12 @@ print(addr.is_multicast) # False
# Get readable type
print(addr.get_address_type()) # "Link-Local"
-```
+----
-### Format Conversion
+==== Format Conversion
-```python
+[source,python]
+----
from ipv6tools.utils import compress_address, expand_address
# Compress
@@ -71,13 +77,14 @@ short = compress_address(long) # "2001:db8::1"
# Expand
expanded = expand_address("2001:db8::1")
# "2001:0db8:0000:0000:0000:0000:0000:0001"
-```
+----
-## Network Operations
+=== Network Operations
-### Creating Networks
+==== Creating Networks
-```python
+[source,python]
+----
from ipv6tools import IPv6Network
# Create network
@@ -87,11 +94,12 @@ net = IPv6Network("2001:db8::/32")
print(net.network_address) # 2001:db8::
print(net.prefix_length) # 32
print(net.num_addresses) # 2^96
-```
+----
-### Testing Address Membership
+==== Testing Address Membership
-```python
+[source,python]
+----
net = IPv6Network("2001:db8::/32")
# Test if address is in network
@@ -103,24 +111,26 @@ print(net.contains("2001:db9::1")) # False
from ipv6tools import IPv6Address
addr = IPv6Address("2001:db8::1")
print(addr in net) # True
-```
+----
-### Network Division
+==== Network Division
-```python
+[source,python]
+----
net = IPv6Network("2001:db8::/32")
# Create 4 subnets
subnets = net.subnets(prefixlen_diff=2) # /34 subnets
for subnet in subnets:
print(subnet)
-```
+----
-## Subnet Planning
+=== Subnet Planning
-### Basic Subnet Calculator
+==== Basic Subnet Calculator
-```python
+[source,python]
+----
from ipv6tools import IPv6SubnetCalculator
calc = IPv6SubnetCalculator("2001:db8::/32")
@@ -129,11 +139,12 @@ calc = IPv6SubnetCalculator("2001:db8::/32")
info = calc.get_info()
print(f"Network: {info.network}")
print(f"Addresses: {info.num_addresses}")
-```
+----
-### Dividing Networks
+==== Dividing Networks
-```python
+[source,python]
+----
calc = IPv6SubnetCalculator("2001:db8::/32")
# Method 1: Specify number of subnets
@@ -143,21 +154,23 @@ for subnet in subnets:
# Method 2: Specify new prefix length
subnets = calc.divide_by_prefix(36) # Create /36 subnets
-```
+----
-### Supernet Calculation
+==== Supernet Calculation
-```python
+[source,python]
+----
calc = IPv6SubnetCalculator("2001:db8::/32")
# Get larger network
supernet = calc.get_supernet(24) # Get /24
print(supernet.network)
-```
+----
-### Department Allocation
+==== Department Allocation
-```python
+[source,python]
+----
calc = IPv6SubnetCalculator
# Allocate to departments
@@ -174,13 +187,14 @@ for dept, subnets in allocation.items():
print(f"{dept}:")
for subnet in subnets:
print(f" {subnet.network}")
-```
+----
-## Address Generation
+=== Address Generation
-### Link-Local Addresses
+==== Link-Local Addresses
-```python
+[source,python]
+----
from ipv6tools.utils import generate_link_local
# Random link-local
@@ -190,11 +204,12 @@ print(addr) # fe80::xxxx:xxxx:xxxx:xxxx
# With specific interface ID
addr = generate_link_local("0000000000000001")
print(addr) # fe80::1
-```
+----
-### Unique Local Addresses (ULA)
+==== Unique Local Addresses (ULA)
-```python
+[source,python]
+----
from ipv6tools.utils import generate_unique_local
# Random ULA
@@ -207,11 +222,12 @@ addr = generate_unique_local(
subnet_id="0001",
interface_id="0000000000000001"
)
-```
+----
-### Random Addresses
+==== Random Addresses
-```python
+[source,python]
+----
from ipv6tools.utils import generate_random_ipv6
# Generate in default prefix (2001:db8::/64)
@@ -219,24 +235,26 @@ addr = generate_random_ipv6()
# Generate in custom prefix
addr = generate_random_ipv6("2001:db8:1234::/48")
-```
+----
-### MAC to IPv6 (EUI-64)
+==== MAC to IPv6 (EUI-64)
-```python
+[source,python]
+----
from ipv6tools.utils import mac_to_ipv6_link_local
# Convert MAC to link-local IPv6
mac = "00:11:22:33:44:55"
addr = mac_to_ipv6_link_local(mac)
print(addr) # fe80::211:22ff:fe33:4455
-```
+----
-## Command-Line Tools
+=== Command-Line Tools
-### ipv6-calc - Network Calculator
+==== ipv6-calc - Network Calculator
-```bash
+[source,bash]
+----
# Get network info
ipv6-calc 2001:db8::/32 --info
@@ -251,11 +269,12 @@ ipv6-calc 2001:db8::/32 --supernet 24
# Check if address is in network
ipv6-calc 2001:db8::/32 --contains 2001:db8::1
-```
+----
-### ipv6-validate - Validator
+==== ipv6-validate - Validator
-```bash
+[source,bash]
+----
# Validate addresses
ipv6-validate 2001:db8::1 fe80::1%eth0
@@ -264,11 +283,12 @@ ipv6-validate -n 2001:db8::/32 fe80::/10
# Quiet mode (exit code only)
ipv6-validate -q 2001:db8::1 && echo "Valid"
-```
+----
-### ipv6-gen - Generator
+==== ipv6-gen - Generator
-```bash
+[source,bash]
+----
# Generate link-local
ipv6-gen link-local
@@ -283,11 +303,12 @@ ipv6-gen from-mac 00:11:22:33:44:55
# Generate multiple
ipv6-gen link-local -n 10
-```
+----
-### Shell Scripts
+==== Shell Scripts
-```bash
+[source,bash]
+----
# Run diagnostics
sudo ./src/scripts/ipv6-diag.sh
@@ -302,24 +323,26 @@ sudo ./src/scripts/ipv6-config.sh static eth0 2001:db8::10 64
# Enable privacy extensions
sudo ./src/scripts/ipv6-config.sh enable-privacy
-```
+----
-## Advanced Topics
+=== Advanced Topics
-### Reverse DNS Pointers
+==== Reverse DNS Pointers
-```python
+[source,python]
+----
from ipv6tools.utils import reverse_pointer
addr = "2001:db8::1"
ptr = reverse_pointer(addr)
print(ptr)
# 1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.b.d.0.1.0.0.2.ip6.arpa
-```
+----
-### Binary and Hex Representation
+==== Binary and Hex Representation
-```python
+[source,python]
+----
addr = IPv6Address("2001:db8::1")
# Binary (128 bits)
@@ -329,21 +352,23 @@ print(binary)
# Hexadecimal (32 hex digits)
hex_str = addr.to_hex()
print(hex_str)
-```
+----
-### Network Overlap Detection
+==== Network Overlap Detection
-```python
+[source,python]
+----
calc = IPv6SubnetCalculator("2001:db8::/32")
# Check overlap
overlaps = calc.overlaps_with("2001:db8:1::/48")
print(overlaps) # True - /48 is within /32
-```
+----
-### Summary Address Calculation
+==== Summary Address Calculation
-```python
+[source,python]
+----
calc = IPv6SubnetCalculator("2001:db8::/48")
# Summarize multiple networks
@@ -353,13 +378,14 @@ summary = calc.get_summary_address([
"2001:db8:3::/48",
])
print(summary) # Smallest network containing all
-```
+----
-## Best Practices
+=== Best Practices
-### 1. Always Validate Input
+==== 1. Always Validate Input
-```python
+[source,python]
+----
from ipv6tools.validator import validate_ipv6
addr_input = input("Enter IPv6 address: ")
@@ -370,26 +396,28 @@ if valid:
# Process address
else:
print(f"Invalid: {error}")
-```
+----
-### 2. Use Appropriate Prefixes
+==== 2. Use Appropriate Prefixes
-- `/64` - Standard subnet (SLAAC)
-- `/48` - Typical site allocation
-- `/32` - ISP allocation
-- `/128` - Single host
+* `+/64+` - Standard subnet (SLAAC)
+* `+/48+` - Typical site allocation
+* `+/32+` - ISP allocation
+* `+/128+` - Single host
-### 3. Handle Zone IDs
+==== 3. Handle Zone IDs
-```python
+[source,python]
+----
# Zone IDs are important for link-local
addr = IPv6Address("fe80::1%eth0")
print(addr.zone_id) # "eth0"
-```
+----
-### 4. Consider Address Types
+==== 4. Consider Address Types
-```python
+[source,python]
+----
def is_usable_for_public(addr_str):
"""Check if address is suitable for public use."""
addr = IPv6Address(addr_str)
@@ -402,13 +430,14 @@ def is_usable_for_public(addr_str):
return False # ULA - not globally routable
return addr.is_global
-```
+----
-## Common Patterns
+=== Common Patterns
-### Network Inventory
+==== Network Inventory
-```python
+[source,python]
+----
networks = [
"2001:db8::/32",
"2001:db8:1000::/36",
@@ -423,11 +452,12 @@ for net_str in networks:
print(f"{info.network}")
print(f" Addresses: {info.num_addresses}")
print(f" Type: {info.addressType}")
-```
+----
-### Batch Validation
+==== Batch Validation
-```python
+[source,python]
+----
from ipv6tools.validator import is_valid_ipv6
addresses = [
@@ -439,44 +469,53 @@ addresses = [
valid_addresses = [addr for addr in addresses if is_valid_ipv6(addr)]
print(f"Valid: {len(valid_addresses)}/{len(addresses)}")
-```
+----
-## Next Steps
+=== Next Steps
-- Explore the [API Documentation](API.md)
-- Check out [Examples](../examples/)
-- Read about [IPv6 Best Practices](BEST_PRACTICES.md)
-- Try the [Web Interface](../src/web/index.html)
+* Explore the link:API.md[API Documentation]
+* Check out link:../examples/[Examples]
+* Read about link:BEST_PRACTICES.md[IPv6 Best Practices]
+* Try the link:../src/web/index.html[Web Interface]
-## Troubleshooting
+=== Troubleshooting
-### Common Issues
+==== Common Issues
-**Import Error**
-```python
+*Import Error*
+
+[source,python]
+----
# Make sure package is installed
pip install -e .
-```
+----
+
+*Invalid Address*
-**Invalid Address**
-```python
+[source,python]
+----
# Check address format
from ipv6tools.validator import validate_ipv6
valid, error = validate_ipv6("your-address")
print(error) # See specific error
-```
+----
+
+*Network Too Large*
-**Network Too Large**
-```python
+[source,python]
+----
# Don't try to enumerate hosts in large networks
net = IPv6Network("2001:db8::/32")
# net.hosts() # Don't do this! Too many addresses
# Instead, calculate specific addresses or use smaller subnets
-```
+----
-## Resources
+=== Resources
-- [IPv6 Addressing Architecture (RFC 4291)](https://tools.ietf.org/html/rfc4291)
-- [IPv6 Address Planning](https://www.ripe.net/publications/docs/ipv6-address-planning)
-- [IANA IPv6 Allocations](https://www.iana.org/assignments/ipv6-address-space/)
+* https://tools.ietf.org/html/rfc4291[IPv6 Addressing Architecture (RFC
+4291)]
+* https://www.ripe.net/publications/docs/ipv6-address-planning[IPv6
+Address Planning]
+* https://www.iana.org/assignments/ipv6-address-space/[IANA IPv6
+Allocations]
diff --git a/ipv6-only/security.adoc b/ipv6-only/security.adoc
new file mode 100644
index 0000000..ec45a03
--- /dev/null
+++ b/ipv6-only/security.adoc
@@ -0,0 +1,243 @@
+== Security Policy
+
+=== Supported Versions
+
+We release patches for security vulnerabilities for the following
+versions:
+
+[cols=",",options="header",]
+|===
+|Version |Supported
+|0.1.x |:white_check_mark:
+|< 0.1 |:x:
+|===
+
+=== Reporting a Vulnerability
+
+*Please do not report security vulnerabilities through public GitHub
+issues.*
+
+Instead, please report them via one of the following methods:
+
+==== Email
+
+Send details to: *security@ipv6-only.example.com*
+
+Please include:
+
+* Type of issue (e.g., buffer overflow, SQL injection, cross-site
+scripting, etc.)
+* Full paths of source file(s) related to the manifestation of the issue
+* The location of the affected source code (tag/branch/commit or direct
+URL)
+* Any special configuration required to reproduce the issue
+* Step-by-step instructions to reproduce the issue
+* Proof-of-concept or exploit code (if possible)
+* Impact of the issue, including how an attacker might exploit it
+
+==== GitHub Security Advisories
+
+For GitHub-specific security issues, you can also use GitHub’s private
+vulnerability reporting:
+
+[arabic]
+. Navigate to the main page of the repository
+. Click on the "`Security`" tab
+. Click "`Report a vulnerability`"
+
+=== Response Timeline
+
+* *Initial Response*: Within 48 hours
+* *Status Update*: Within 7 days
+* *Resolution Target*: Within 90 days (depending on severity)
+
+=== Disclosure Policy
+
+* Security issues are kept confidential until a fix is available
+* We will acknowledge your contribution in the security advisory
+* You may publicly disclose the vulnerability after we have released a
+fix
+
+=== Security Update Process
+
+[arabic]
+. Security issue is reported privately
+. Issue is triaged and severity assessed
+. Fix is developed in a private branch
+. Security advisory is drafted
+. Fix is released with security advisory
+. Public disclosure after fix is available
+
+=== Security Best Practices
+
+When using IPv6-Only Tools:
+
+==== Network Security
+
+* *Firewall Configuration*: Always configure firewalls for IPv6, not
+just IPv4
+* *ICMPv6*: Allow necessary ICMPv6 messages but filter appropriately
+* *Extension Headers*: Be aware of IPv6 extension header vulnerabilities
+* *Router Advertisements*: Protect against rogue RAs
+
+==== Application Security
+
+* *Input Validation*: All IPv6 addresses and networks are validated
+before processing
+* *Injection Prevention*: Use parameterized queries and proper escaping
+* *Least Privilege*: Run tools with minimum necessary permissions
+* *Secure Defaults*: Privacy extensions enabled by default where
+appropriate
+
+==== Container Security
+
+* *Wolfi Base*: We use Chainguard Wolfi for supply chain security
+* *Non-root User*: Containers run as non-root by default
+* *Minimal Dependencies*: Only essential packages included
+* *Regular Updates*: Base images updated regularly
+
+==== Scanning Tools
+
+When using security scanning features:
+
+* *Authorization Required*: Only scan networks you own or have
+permission to scan
+* *Rate Limiting*: Respect rate limits and network policies
+* *Responsible Disclosure*: Report vulnerabilities found responsibly
+* *Legal Compliance*: Ensure compliance with local laws and regulations
+
+=== Known Security Considerations
+
+==== IPv6-Specific Issues
+
+[arabic]
+. *Neighbor Discovery Protocol (NDP)*
+* Vulnerable to spoofing attacks
+* Use RA Guard and ND inspection where available
+. *Address Scanning*
+* /64 subnets too large for traditional scanning
+* Tools implement smart scanning patterns
+. *Extension Headers*
+* Can be used for evasion
+* Filter unnecessary extension headers
+. *Privacy*
+* EUI-64 addresses leak MAC information
+* Use privacy extensions (RFC 4941)
+
+==== Tool-Specific Considerations
+
+[arabic]
+. *Port Scanning*
+* Respect network policies
+* Avoid causing denial of service
+* Use appropriate rate limiting
+. *DNS Queries*
+* May trigger rate limiting
+* Respect TTL values
+* Consider privacy implications
+. *Tunnels (Hurricane Electric)*
+* Secure tunnel endpoints
+* Use strong authentication
+* Monitor for unauthorized access
+
+=== Security Features
+
+==== Input Validation
+
+* All IPv6 addresses validated using standard library functions
+* Network prefixes checked for valid ranges (0-128)
+* Zone IDs validated for link-local addresses
+* Hostnames validated before DNS queries
+
+==== Safe Defaults
+
+* Privacy extensions recommended
+* No unnecessary services exposed
+* Minimal container attack surface
+* Non-executable data directories
+
+==== Secure Communication
+
+* HTTPS for web interfaces
+* Encrypted tunnel support (IPsec, WireGuard)
+* Secure credential storage
+* No hardcoded secrets
+
+=== Dependency Security
+
+We actively monitor dependencies for vulnerabilities:
+
+* *Python*: Using `+safety+` and `+bandit+` for scanning
+* *Go*: Using `+gosec+` for static analysis
+* *Container*: Using Trivy for image scanning
+* *CI/CD*: GitHub Dependabot enabled
+
+=== Security Checklist for Contributors
+
+Before submitting code:
+
+* [ ] All inputs validated
+* [ ] No hardcoded credentials
+* [ ] Error messages don’t leak sensitive information
+* [ ] Secure defaults used
+* [ ] Security implications documented
+* [ ] Tests include security scenarios
+* [ ] Dependencies are up to date
+* [ ] No known CVEs in dependencies
+
+=== Security Tools Integration
+
+==== Automated Scanning
+
+* *Bandit*: Python code security scanning
+* *Safety*: Python dependency vulnerability checking
+* *gosec*: Go code security analysis
+* *Trivy*: Container vulnerability scanning
+* *Dependabot*: Automated dependency updates
+
+==== Manual Review
+
+* Security-focused code review for all PRs
+* Threat modeling for new features
+* Penetration testing for major releases
+
+=== Compliance
+
+==== Standards
+
+* OWASP Top 10 awareness
+* CWE/SANS Top 25 consideration
+* NIST Cybersecurity Framework alignment
+
+==== Privacy
+
+* No telemetry by default
+* User data stays local
+* Privacy-preserving defaults (RFC 4941)
+
+=== Contact
+
+For security concerns that are not vulnerabilities (questions, best
+practices, etc.):
+
+* *Discussions*: Use GitHub Discussions
+* *General Email*: contact@ipv6-only.example.com
+* *Documentation*: See security documentation in `+docs/+`
+
+=== Acknowledgments
+
+We thank the following researchers for responsibly disclosing
+vulnerabilities:
+
+* (List will be maintained here)
+
+=== Updates
+
+This security policy is reviewed quarterly and updated as needed.
+
+Last updated: 2024-11-22
+
+'''''
+
+*Note*: This is a living document and will be updated as our security
+practices evolve.
diff --git a/ipv6-only/security.md b/ipv6-only/security.md
deleted file mode 100644
index ba06b38..0000000
--- a/ipv6-only/security.md
+++ /dev/null
@@ -1,229 +0,0 @@
-# Security Policy
-
-## Supported Versions
-
-We release patches for security vulnerabilities for the following versions:
-
-| Version | Supported |
-| ------- | ------------------ |
-| 0.1.x | :white_check_mark: |
-| < 0.1 | :x: |
-
-## Reporting a Vulnerability
-
-**Please do not report security vulnerabilities through public GitHub issues.**
-
-Instead, please report them via one of the following methods:
-
-### Email
-
-Send details to: **security@ipv6-only.example.com**
-
-Please include:
-
-* Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
-* Full paths of source file(s) related to the manifestation of the issue
-* The location of the affected source code (tag/branch/commit or direct URL)
-* Any special configuration required to reproduce the issue
-* Step-by-step instructions to reproduce the issue
-* Proof-of-concept or exploit code (if possible)
-* Impact of the issue, including how an attacker might exploit it
-
-### GitHub Security Advisories
-
-For GitHub-specific security issues, you can also use GitHub's private vulnerability reporting:
-
-1. Navigate to the main page of the repository
-2. Click on the "Security" tab
-3. Click "Report a vulnerability"
-
-## Response Timeline
-
-* **Initial Response**: Within 48 hours
-* **Status Update**: Within 7 days
-* **Resolution Target**: Within 90 days (depending on severity)
-
-## Disclosure Policy
-
-* Security issues are kept confidential until a fix is available
-* We will acknowledge your contribution in the security advisory
-* You may publicly disclose the vulnerability after we have released a fix
-
-## Security Update Process
-
-1. Security issue is reported privately
-2. Issue is triaged and severity assessed
-3. Fix is developed in a private branch
-4. Security advisory is drafted
-5. Fix is released with security advisory
-6. Public disclosure after fix is available
-
-## Security Best Practices
-
-When using IPv6-Only Tools:
-
-### Network Security
-
-* **Firewall Configuration**: Always configure firewalls for IPv6, not just IPv4
-* **ICMPv6**: Allow necessary ICMPv6 messages but filter appropriately
-* **Extension Headers**: Be aware of IPv6 extension header vulnerabilities
-* **Router Advertisements**: Protect against rogue RAs
-
-### Application Security
-
-* **Input Validation**: All IPv6 addresses and networks are validated before processing
-* **Injection Prevention**: Use parameterized queries and proper escaping
-* **Least Privilege**: Run tools with minimum necessary permissions
-* **Secure Defaults**: Privacy extensions enabled by default where appropriate
-
-### Container Security
-
-* **Wolfi Base**: We use Chainguard Wolfi for supply chain security
-* **Non-root User**: Containers run as non-root by default
-* **Minimal Dependencies**: Only essential packages included
-* **Regular Updates**: Base images updated regularly
-
-### Scanning Tools
-
-When using security scanning features:
-
-* **Authorization Required**: Only scan networks you own or have permission to scan
-* **Rate Limiting**: Respect rate limits and network policies
-* **Responsible Disclosure**: Report vulnerabilities found responsibly
-* **Legal Compliance**: Ensure compliance with local laws and regulations
-
-## Known Security Considerations
-
-### IPv6-Specific Issues
-
-1. **Neighbor Discovery Protocol (NDP)**
- - Vulnerable to spoofing attacks
- - Use RA Guard and ND inspection where available
-
-2. **Address Scanning**
- - /64 subnets too large for traditional scanning
- - Tools implement smart scanning patterns
-
-3. **Extension Headers**
- - Can be used for evasion
- - Filter unnecessary extension headers
-
-4. **Privacy**
- - EUI-64 addresses leak MAC information
- - Use privacy extensions (RFC 4941)
-
-### Tool-Specific Considerations
-
-1. **Port Scanning**
- - Respect network policies
- - Avoid causing denial of service
- - Use appropriate rate limiting
-
-2. **DNS Queries**
- - May trigger rate limiting
- - Respect TTL values
- - Consider privacy implications
-
-3. **Tunnels (Hurricane Electric)**
- - Secure tunnel endpoints
- - Use strong authentication
- - Monitor for unauthorized access
-
-## Security Features
-
-### Input Validation
-
-* All IPv6 addresses validated using standard library functions
-* Network prefixes checked for valid ranges (0-128)
-* Zone IDs validated for link-local addresses
-* Hostnames validated before DNS queries
-
-### Safe Defaults
-
-* Privacy extensions recommended
-* No unnecessary services exposed
-* Minimal container attack surface
-* Non-executable data directories
-
-### Secure Communication
-
-* HTTPS for web interfaces
-* Encrypted tunnel support (IPsec, WireGuard)
-* Secure credential storage
-* No hardcoded secrets
-
-## Dependency Security
-
-We actively monitor dependencies for vulnerabilities:
-
-* **Python**: Using `safety` and `bandit` for scanning
-* **Go**: Using `gosec` for static analysis
-* **Container**: Using Trivy for image scanning
-* **CI/CD**: GitHub Dependabot enabled
-
-## Security Checklist for Contributors
-
-Before submitting code:
-
-- [ ] All inputs validated
-- [ ] No hardcoded credentials
-- [ ] Error messages don't leak sensitive information
-- [ ] Secure defaults used
-- [ ] Security implications documented
-- [ ] Tests include security scenarios
-- [ ] Dependencies are up to date
-- [ ] No known CVEs in dependencies
-
-## Security Tools Integration
-
-### Automated Scanning
-
-* **Bandit**: Python code security scanning
-* **Safety**: Python dependency vulnerability checking
-* **gosec**: Go code security analysis
-* **Trivy**: Container vulnerability scanning
-* **Dependabot**: Automated dependency updates
-
-### Manual Review
-
-* Security-focused code review for all PRs
-* Threat modeling for new features
-* Penetration testing for major releases
-
-## Compliance
-
-### Standards
-
-* OWASP Top 10 awareness
-* CWE/SANS Top 25 consideration
-* NIST Cybersecurity Framework alignment
-
-### Privacy
-
-* No telemetry by default
-* User data stays local
-* Privacy-preserving defaults (RFC 4941)
-
-## Contact
-
-For security concerns that are not vulnerabilities (questions, best practices, etc.):
-
-* **Discussions**: Use GitHub Discussions
-* **General Email**: contact@ipv6-only.example.com
-* **Documentation**: See security documentation in `docs/`
-
-## Acknowledgments
-
-We thank the following researchers for responsibly disclosing vulnerabilities:
-
-* (List will be maintained here)
-
-## Updates
-
-This security policy is reviewed quarterly and updated as needed.
-
-Last updated: 2024-11-22
-
----
-
-**Note**: This is a living document and will be updated as our security practices evolve.
diff --git a/ipv6-site-enforcer/CODE_OF_CONDUCT.adoc b/ipv6-site-enforcer/CODE_OF_CONDUCT.adoc
new file mode 100644
index 0000000..bd2a83c
--- /dev/null
+++ b/ipv6-site-enforcer/CODE_OF_CONDUCT.adoc
@@ -0,0 +1,24 @@
+== Contributor Covenant Code of Conduct
+
+=== Our Pledge
+
+We pledge to make participation a harassment-free experience for
+everyone.
+
+=== Our Standards
+
+*Positive behavior:* * Using welcoming language * Being respectful of
+differing viewpoints * Accepting constructive criticism * Focusing on
+what is best for the community
+
+*Unacceptable behavior:* * Harassment, trolling, or personal attacks *
+Publishing private information without permission
+
+=== Enforcement
+
+Report issues to the maintainers. All complaints will be reviewed.
+
+=== Attribution
+
+Adapted from https://www.contributor-covenant.org/[Contributor Covenant]
+v2.1.
diff --git a/ipv6-site-enforcer/CODE_OF_CONDUCT.md b/ipv6-site-enforcer/CODE_OF_CONDUCT.md
deleted file mode 100644
index caeda1c..0000000
--- a/ipv6-site-enforcer/CODE_OF_CONDUCT.md
+++ /dev/null
@@ -1,27 +0,0 @@
-
-# Contributor Covenant Code of Conduct
-
-## Our Pledge
-
-We pledge to make participation a harassment-free experience for everyone.
-
-## Our Standards
-
-**Positive behavior:**
-* Using welcoming language
-* Being respectful of differing viewpoints
-* Accepting constructive criticism
-* Focusing on what is best for the community
-
-**Unacceptable behavior:**
-* Harassment, trolling, or personal attacks
-* Publishing private information without permission
-
-## Enforcement
-
-Report issues to the maintainers. All complaints will be reviewed.
-
-## Attribution
-
-Adapted from [Contributor Covenant](https://www.contributor-covenant.org/) v2.1.
-
diff --git a/ipv6-site-enforcer/CONTRIBUTING.adoc b/ipv6-site-enforcer/CONTRIBUTING.adoc
index eb045d6..07c0033 100644
--- a/ipv6-site-enforcer/CONTRIBUTING.adoc
+++ b/ipv6-site-enforcer/CONTRIBUTING.adoc
@@ -1,20 +1,109 @@
-// SPDX-License-Identifier: CC-BY-SA-4.0
-= Contributing Guide
+== Clone the repository
-== Getting Started
+git clone https://github.com/hyperpolymath/ipv6-site-enforcer.git cd
+ipv6-site-enforcer
-1. Fork the repository
-2. Create a feature branch from `main`
-3. Sign off commits (`git commit -s`)
-4. Submit a pull request
+== Using Nix (recommended for reproducibility)
-== Commit Guidelines
+nix develop
-* Conventional commits: `type(scope): description`
-* Sign all commits (DCO required)
-* Atomic, focused commits
+== Or using toolbox/distrobox
-== License
+toolbox create ipv6-site-enforcer-dev toolbox enter
+ipv6-site-enforcer-dev # Install dependencies manually
-Contributions licensed under project license.
+== Verify setup
+just check # or: cargo check / mix compile / etc. just test # Run test
+suite
+
+....
+
+### Repository Structure
+....
+
+ipv6-site-enforcer/ ├── src/ # Source code (Perimeter 1-2) ├── lib/ #
+Library code (Perimeter 1-2) ├── extensions/ # Extensions (Perimeter 2)
+├── plugins/ # Plugins (Perimeter 2) ├── tools/ # Tooling (Perimeter 2)
+├── docs/ # Documentation (Perimeter 3) │ ├── architecture/ # ADRs,
+specs (Perimeter 2) │ └── proposals/ # RFCs (Perimeter 3) ├── examples/
+# Examples (Perimeter 3) ├── spec/ # Spec tests (Perimeter 3) ├── tests/
+# Test suite (Perimeter 2-3) ├── .well-known/ # Protocol files
+(Perimeter 1-3) ├── .github/ # GitHub config (Perimeter 1) │ ├──
+ISSUE_TEMPLATE/ │ └── workflows/ ├── CHANGELOG.md ├── CODE_OF_CONDUCT.md
+├── CONTRIBUTING.md # This file ├── GOVERNANCE.md ├── LICENSE ├──
+MAINTAINERS.md ├── README.adoc ├── SECURITY.md ├── flake.nix # Nix flake
+(Perimeter 1) └── Justfile # Task runner (Perimeter 1)
+
+....
+
+---
+
+## How to Contribute
+
+### Reporting Bugs
+
+**Before reporting**:
+1. Search existing issues
+2. Check if it's already fixed in `main`
+3. Determine which perimeter the bug affects
+
+**When reporting**:
+
+Use the [bug report template](.github/ISSUE_TEMPLATE/bug_report.md) and include:
+
+- Clear, descriptive title
+- Environment details (OS, versions, toolchain)
+- Steps to reproduce
+- Expected vs actual behaviour
+- Logs, screenshots, or minimal reproduction
+
+### Suggesting Features
+
+**Before suggesting**:
+1. Check the [roadmap](ROADMAP.md) if available
+2. Search existing issues and discussions
+3. Consider which perimeter the feature belongs to
+
+**When suggesting**:
+
+Use the [feature request template](.github/ISSUE_TEMPLATE/feature_request.md) and include:
+
+- Problem statement (what pain point does this solve?)
+- Proposed solution
+- Alternatives considered
+- Which perimeter this affects
+
+### Your First Contribution
+
+Look for issues labelled:
+
+- [`good first issue`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/good%20first%20issue) — Simple Perimeter 3 tasks
+- [`help wanted`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/help%20wanted) — Community help needed
+- [`documentation`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/documentation) — Docs improvements
+- [`perimeter-3`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/perimeter-3) — Community sandbox scope
+
+---
+
+## Development Workflow
+
+### Branch Naming
+....
+
+docs/short-description # Documentation (P3) test/what-added # Test
+additions (P3) feat/short-description # New features (P2)
+fix/issue-number-description # Bug fixes (P2) refactor/what-changed #
+Code improvements (P2) security/what-fixed # Security fixes (P1-2)
+
+....
+
+### Commit Messages
+
+We follow [Conventional Commits](https://www.conventionalcommits.org/):
+....
+
+():
+
+{empty}[optional body]
+
+{empty}[optional footer]
diff --git a/ipv6-site-enforcer/CONTRIBUTING.md b/ipv6-site-enforcer/CONTRIBUTING.md
deleted file mode 100644
index ff29d62..0000000
--- a/ipv6-site-enforcer/CONTRIBUTING.md
+++ /dev/null
@@ -1,116 +0,0 @@
-# Clone the repository
-git clone https://github.com/hyperpolymath/ipv6-site-enforcer.git
-cd ipv6-site-enforcer
-
-# Using Nix (recommended for reproducibility)
-nix develop
-
-# Or using toolbox/distrobox
-toolbox create ipv6-site-enforcer-dev
-toolbox enter ipv6-site-enforcer-dev
-# Install dependencies manually
-
-# Verify setup
-just check # or: cargo check / mix compile / etc.
-just test # Run test suite
-```
-
-### Repository Structure
-```
-ipv6-site-enforcer/
-├── src/ # Source code (Perimeter 1-2)
-├── lib/ # Library code (Perimeter 1-2)
-├── extensions/ # Extensions (Perimeter 2)
-├── plugins/ # Plugins (Perimeter 2)
-├── tools/ # Tooling (Perimeter 2)
-├── docs/ # Documentation (Perimeter 3)
-│ ├── architecture/ # ADRs, specs (Perimeter 2)
-│ └── proposals/ # RFCs (Perimeter 3)
-├── examples/ # Examples (Perimeter 3)
-├── spec/ # Spec tests (Perimeter 3)
-├── tests/ # Test suite (Perimeter 2-3)
-├── .well-known/ # Protocol files (Perimeter 1-3)
-├── .github/ # GitHub config (Perimeter 1)
-│ ├── ISSUE_TEMPLATE/
-│ └── workflows/
-├── CHANGELOG.md
-├── CODE_OF_CONDUCT.md
-├── CONTRIBUTING.md # This file
-├── GOVERNANCE.md
-├── LICENSE
-├── MAINTAINERS.md
-├── README.adoc
-├── SECURITY.md
-├── flake.nix # Nix flake (Perimeter 1)
-└── Justfile # Task runner (Perimeter 1)
-```
-
----
-
-## How to Contribute
-
-### Reporting Bugs
-
-**Before reporting**:
-1. Search existing issues
-2. Check if it's already fixed in `main`
-3. Determine which perimeter the bug affects
-
-**When reporting**:
-
-Use the [bug report template](.github/ISSUE_TEMPLATE/bug_report.md) and include:
-
-- Clear, descriptive title
-- Environment details (OS, versions, toolchain)
-- Steps to reproduce
-- Expected vs actual behaviour
-- Logs, screenshots, or minimal reproduction
-
-### Suggesting Features
-
-**Before suggesting**:
-1. Check the [roadmap](ROADMAP.md) if available
-2. Search existing issues and discussions
-3. Consider which perimeter the feature belongs to
-
-**When suggesting**:
-
-Use the [feature request template](.github/ISSUE_TEMPLATE/feature_request.md) and include:
-
-- Problem statement (what pain point does this solve?)
-- Proposed solution
-- Alternatives considered
-- Which perimeter this affects
-
-### Your First Contribution
-
-Look for issues labelled:
-
-- [`good first issue`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/good%20first%20issue) — Simple Perimeter 3 tasks
-- [`help wanted`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/help%20wanted) — Community help needed
-- [`documentation`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/documentation) — Docs improvements
-- [`perimeter-3`](https://github.com/hyperpolymath/ipv6-site-enforcer/labels/perimeter-3) — Community sandbox scope
-
----
-
-## Development Workflow
-
-### Branch Naming
-```
-docs/short-description # Documentation (P3)
-test/what-added # Test additions (P3)
-feat/short-description # New features (P2)
-fix/issue-number-description # Bug fixes (P2)
-refactor/what-changed # Code improvements (P2)
-security/what-fixed # Security fixes (P1-2)
-```
-
-### Commit Messages
-
-We follow [Conventional Commits](https://www.conventionalcommits.org/):
-```
-():
-
-[optional body]
-
-[optional footer]
diff --git a/ipv6-site-enforcer/SECURITY.adoc b/ipv6-site-enforcer/SECURITY.adoc
new file mode 100644
index 0000000..6833c54
--- /dev/null
+++ b/ipv6-site-enforcer/SECURITY.adoc
@@ -0,0 +1,378 @@
+Security Policy
+
+We take security seriously. We appreciate your efforts to responsibly
+disclose vulnerabilities and will make every effort to acknowledge your
+contributions. Table of Contents
+
+....
+Reporting a Vulnerability
+What to Include
+Response Timeline
+Disclosure Policy
+Scope
+Safe Harbour
+Recognition
+Security Updates
+Security Best Practices
+....
+
+Reporting a Vulnerability Preferred Method: GitHub Security Advisories
+
+The preferred method for reporting security vulnerabilities is through
+GitHub’s Security Advisory feature:
+
+....
+Navigate to Report a Vulnerability
+Click "Report a vulnerability"
+Complete the form with as much detail as possible
+Submit — we'll receive a private notification
+....
+
+This method ensures:
+
+....
+End-to-end encryption of your report
+Private discussion space for collaboration
+Coordinated disclosure tooling
+Automatic credit when the advisory is published
+....
+
+Alternative: Encrypted Email
+
+If you cannot use GitHub Security Advisories, you may email us directly:
+
+Email security@hyperpolymath.org PGP Key Download Public Key Fingerprint
+See GPG key
+
+== Import our PGP key
+
+curl -sSL https://hyperpolymath.org/gpg/security.asc | gpg –import
+
+== Verify fingerprint
+
+gpg –fingerprint security@hyperpolymath.org
+
+== Encrypt your report
+
+gpg –armor –encrypt –recipient security@hyperpolymath.org report.txt
+
+....
+⚠️ Important: Do not report security vulnerabilities through public GitHub issues, pull requests, discussions, or social media.
+....
+
+What to Include
+
+A good vulnerability report helps us understand and reproduce the issue
+quickly. Required Information
+
+....
+Description: Clear explanation of the vulnerability
+Impact: What an attacker could achieve (confidentiality, integrity, availability)
+Affected versions: Which versions/commits are affected
+Reproduction steps: Detailed steps to reproduce the issue
+....
+
+Helpful Additional Information
+
+....
+Proof of concept: Code, scripts, or screenshots demonstrating the vulnerability
+Attack scenario: Realistic attack scenario showing exploitability
+CVSS score: Your assessment of severity (use CVSS 3.1 Calculator)
+CWE ID: Common Weakness Enumeration identifier if known
+Suggested fix: If you have ideas for remediation
+References: Links to related vulnerabilities, research, or advisories
+....
+
+Example Report Structure
+
+=== Summary
+
+{empty}[One-sentence description of the vulnerability]
+
+=== Vulnerability Type
+
+{empty}[e.g., SQL Injection, XSS, SSRF, Path Traversal, etc.]
+
+=== Affected Component
+
+{empty}[File path, function name, API endpoint, etc.]
+
+=== Affected Versions
+
+{empty}[Version range or specific commits]
+
+=== Severity Assessment
+
+* CVSS 3.1 Score: [X.X]
+* CVSS Vector: [CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X]
+
+=== Description
+
+{empty}[Detailed technical description]
+
+=== Steps to Reproduce
+
+[arabic]
+. [First step]
+. [Second step]
+. […]
+
+=== Proof of Concept
+
+{empty}[Code, curl commands, screenshots, etc.]
+
+=== Impact
+
+{empty}[What can an attacker achieve?]
+
+=== Suggested Remediation
+
+{empty}[Optional: your ideas for fixing]
+
+=== References
+
+{empty}[Links to related issues, CVEs, research]
+
+Response Timeline
+
+We commit to the following response times: Stage Timeframe Description
+Initial Response 48 hours We acknowledge receipt and confirm we’re
+investigating Triage 7 days We assess severity, confirm the
+vulnerability, and estimate timeline Status Update Every 7 days Regular
+updates on remediation progress Resolution 90 days Target for fix
+development and release (complex issues may take longer) Disclosure 90
+days Public disclosure after fix is available (coordinated with you)
+
+....
+Note: These are targets, not guarantees. Complex vulnerabilities may require more time. We'll communicate openly about any delays.
+....
+
+Disclosure Policy
+
+We follow coordinated disclosure (also known as responsible disclosure):
+
+....
+You report the vulnerability privately
+We acknowledge and begin investigation
+We develop a fix and prepare a release
+We coordinate disclosure timing with you
+We publish security advisory and fix simultaneously
+You may publish your research after disclosure
+....
+
+Our Commitments
+
+....
+We will not take legal action against researchers who follow this policy
+We will work with you to understand and resolve the issue
+We will credit you in the security advisory (unless you prefer anonymity)
+We will notify you before public disclosure
+We will publish advisories with sufficient detail for users to assess risk
+....
+
+Your Commitments
+
+....
+Report vulnerabilities promptly after discovery
+Give us reasonable time to address the issue before disclosure
+Do not access, modify, or delete data beyond what's necessary to demonstrate the vulnerability
+Do not degrade service availability (no DoS testing on production)
+Do not share vulnerability details with others until coordinated disclosure
+....
+
+Disclosure Timeline
+
+Day 0 You report vulnerability Day 1-2 We acknowledge receipt Day 7 We
+confirm vulnerability and share initial assessment Day 7-90 We develop
+and test fix Day 90 Coordinated public disclosure (earlier if fix is
+ready; later by mutual agreement)
+
+If we cannot reach agreement on disclosure timing, we default to 90 days
+from your initial report. Scope In Scope ✅
+
+The following are within scope for security research:
+
+....
+This repository (hyperpolymath/terrapin-ssg) and all its code
+Official releases and packages published from this repository
+Documentation that could lead to security issues
+Build and deployment configurations in this repository
+Dependencies (report here, we'll coordinate with upstream)
+....
+
+Out of Scope ❌
+
+The following are not in scope:
+
+....
+Third-party services we integrate with (report directly to them)
+Social engineering attacks against maintainers
+Physical security
+Denial of service attacks against production infrastructure
+Spam, phishing, or other non-technical attacks
+Issues already reported or publicly known
+Theoretical vulnerabilities without proof of concept
+....
+
+Qualifying Vulnerabilities
+
+We’re particularly interested in:
+
+....
+Remote code execution
+SQL injection, command injection, code injection
+Authentication/authorisation bypass
+Cross-site scripting (XSS) and cross-site request forgery (CSRF)
+Server-side request forgery (SSRF)
+Path traversal / local file inclusion
+Information disclosure (credentials, PII, secrets)
+Cryptographic weaknesses
+Deserialisation vulnerabilities
+Memory safety issues (buffer overflows, use-after-free, etc.)
+Supply chain vulnerabilities (dependency confusion, etc.)
+Significant logic flaws
+....
+
+Non-Qualifying Issues
+
+The following generally do not qualify as security vulnerabilities:
+
+....
+Missing security headers on non-sensitive pages
+Clickjacking on pages without sensitive actions
+Self-XSS (requires victim to paste code)
+Missing rate limiting (unless it enables a specific attack)
+Username/email enumeration (unless high-risk context)
+Missing cookie flags on non-sensitive cookies
+Software version disclosure
+Verbose error messages (unless exposing secrets)
+Best practice deviations without demonstrable impact
+....
+
+Safe Harbour
+
+We support security research conducted in good faith. Our Promise
+
+If you conduct security research in accordance with this policy:
+
+....
+✅ We will not initiate legal action against you
+✅ We will not report your activity to law enforcement
+✅ We will work with you in good faith to resolve issues
+✅ We consider your research authorised under the Computer Fraud and Abuse Act (CFAA), UK Computer Misuse Act, and similar laws
+✅ We waive any potential claim against you for circumvention of security controls
+....
+
+Good Faith Requirements
+
+To qualify for safe harbour, you must:
+
+....
+Comply with this security policy
+Report vulnerabilities promptly
+Avoid privacy violations (do not access others' data)
+Avoid service degradation (no destructive testing)
+Not exploit vulnerabilities beyond proof-of-concept
+Not use vulnerabilities for profit (beyond bug bounties where offered)
+
+⚠️ Important: This safe harbour does not extend to third-party systems. Always check their policies before testing.
+....
+
+Recognition
+
+We believe in recognising security researchers who help us improve. Hall
+of Fame
+
+Researchers who report valid vulnerabilities will be acknowledged in our
+Security Acknowledgments (unless they prefer anonymity).
+
+Recognition includes:
+
+....
+Your name (or chosen alias)
+Link to your website/profile (optional)
+Brief description of the vulnerability class
+Date of report
+....
+
+What We Offer
+
+....
+✅ Public credit in security advisories
+✅ Acknowledgment in release notes
+✅ Entry in our Hall of Fame
+✅ Reference/recommendation letter upon request (for significant findings)
+....
+
+What We Don’t Currently Offer
+
+....
+❌ Monetary bug bounties
+❌ Hardware or swag
+❌ Paid security research contracts
+
+Note: We're a community project with limited resources. Your contributions help everyone who uses this software.
+....
+
+Security Updates Receiving Updates
+
+To stay informed about security updates:
+
+....
+Watch this repository: Click "Watch" → "Custom" → Select "Security alerts"
+GitHub Security Advisories: Published at Security Advisories
+Release notes: Security fixes noted in CHANGELOG
+....
+
+Update Policy Severity Response Critical/High Patch release as soon as
+fix is ready Medium Included in next scheduled release (or earlier) Low
+Included in next scheduled release Supported Versions Version Supported
+Notes main branch ✅ Yes Latest development Latest release ✅ Yes
+Current stable Previous minor release ✅ Yes Security fixes backported
+Older versions ❌ No Please upgrade Security Best Practices
+
+When using terrapin-ssg, we recommend: General
+
+....
+Keep dependencies up to date
+Use the latest stable release
+Subscribe to security notifications
+Review configuration against security documentation
+Follow principle of least privilege
+....
+
+For Contributors
+
+....
+Never commit secrets, credentials, or API keys
+Use signed commits (git config commit.gpgsign true)
+Review dependencies before adding them
+Run security linters locally before pushing
+Report any concerns about existing code
+....
+
+Additional Resources
+
+....
+Our PGP Public Key
+Security Advisories
+Changelog
+Contributing Guidelines
+CVE Database
+CVSS Calculator
+....
+
+Contact Purpose Contact Security issues Report via GitHub or
+security@hyperpolymath.org General questions GitHub Discussions Other
+enquiries See README for contact information Policy Changes
+
+This security policy may be updated from time to time. Significant
+changes will be:
+
+....
+Committed to this repository with a clear commit message
+Noted in the changelog
+Announced via GitHub Discussions (for major changes)
+....
+
+Thank you for helping keep terrapin-ssg and its users safe.
diff --git a/ipv6-site-enforcer/SECURITY.md b/ipv6-site-enforcer/SECURITY.md
deleted file mode 100644
index 5eb5e20..0000000
--- a/ipv6-site-enforcer/SECURITY.md
+++ /dev/null
@@ -1,328 +0,0 @@
-Security Policy
-
-We take security seriously. We appreciate your efforts to responsibly disclose vulnerabilities and will make every effort to acknowledge your contributions.
-Table of Contents
-
- Reporting a Vulnerability
- What to Include
- Response Timeline
- Disclosure Policy
- Scope
- Safe Harbour
- Recognition
- Security Updates
- Security Best Practices
-
-Reporting a Vulnerability
-Preferred Method: GitHub Security Advisories
-
-The preferred method for reporting security vulnerabilities is through GitHub's Security Advisory feature:
-
- Navigate to Report a Vulnerability
- Click "Report a vulnerability"
- Complete the form with as much detail as possible
- Submit — we'll receive a private notification
-
-This method ensures:
-
- End-to-end encryption of your report
- Private discussion space for collaboration
- Coordinated disclosure tooling
- Automatic credit when the advisory is published
-
-Alternative: Encrypted Email
-
-If you cannot use GitHub Security Advisories, you may email us directly:
-
-Email security@hyperpolymath.org
-PGP Key Download Public Key
-Fingerprint See GPG key
-
-# Import our PGP key
-curl -sSL https://hyperpolymath.org/gpg/security.asc | gpg --import
-
-# Verify fingerprint
-gpg --fingerprint security@hyperpolymath.org
-
-# Encrypt your report
-gpg --armor --encrypt --recipient security@hyperpolymath.org report.txt
-
- ⚠️ Important: Do not report security vulnerabilities through public GitHub issues, pull requests, discussions, or social media.
-
-What to Include
-
-A good vulnerability report helps us understand and reproduce the issue quickly.
-Required Information
-
- Description: Clear explanation of the vulnerability
- Impact: What an attacker could achieve (confidentiality, integrity, availability)
- Affected versions: Which versions/commits are affected
- Reproduction steps: Detailed steps to reproduce the issue
-
-Helpful Additional Information
-
- Proof of concept: Code, scripts, or screenshots demonstrating the vulnerability
- Attack scenario: Realistic attack scenario showing exploitability
- CVSS score: Your assessment of severity (use CVSS 3.1 Calculator)
- CWE ID: Common Weakness Enumeration identifier if known
- Suggested fix: If you have ideas for remediation
- References: Links to related vulnerabilities, research, or advisories
-
-Example Report Structure
-
-## Summary
-[One-sentence description of the vulnerability]
-
-## Vulnerability Type
-[e.g., SQL Injection, XSS, SSRF, Path Traversal, etc.]
-
-## Affected Component
-[File path, function name, API endpoint, etc.]
-
-## Affected Versions
-[Version range or specific commits]
-
-## Severity Assessment
-- CVSS 3.1 Score: [X.X]
-- CVSS Vector: [CVSS:3.1/AV:X/AC:X/PR:X/UI:X/S:X/C:X/I:X/A:X]
-
-## Description
-[Detailed technical description]
-
-## Steps to Reproduce
-1. [First step]
-2. [Second step]
-3. [...]
-
-## Proof of Concept
-[Code, curl commands, screenshots, etc.]
-
-## Impact
-[What can an attacker achieve?]
-
-## Suggested Remediation
-[Optional: your ideas for fixing]
-
-## References
-[Links to related issues, CVEs, research]
-
-Response Timeline
-
-We commit to the following response times:
-Stage Timeframe Description
-Initial Response 48 hours We acknowledge receipt and confirm we're investigating
-Triage 7 days We assess severity, confirm the vulnerability, and estimate timeline
-Status Update Every 7 days Regular updates on remediation progress
-Resolution 90 days Target for fix development and release (complex issues may take longer)
-Disclosure 90 days Public disclosure after fix is available (coordinated with you)
-
- Note: These are targets, not guarantees. Complex vulnerabilities may require more time. We'll communicate openly about any delays.
-
-Disclosure Policy
-
-We follow coordinated disclosure (also known as responsible disclosure):
-
- You report the vulnerability privately
- We acknowledge and begin investigation
- We develop a fix and prepare a release
- We coordinate disclosure timing with you
- We publish security advisory and fix simultaneously
- You may publish your research after disclosure
-
-Our Commitments
-
- We will not take legal action against researchers who follow this policy
- We will work with you to understand and resolve the issue
- We will credit you in the security advisory (unless you prefer anonymity)
- We will notify you before public disclosure
- We will publish advisories with sufficient detail for users to assess risk
-
-Your Commitments
-
- Report vulnerabilities promptly after discovery
- Give us reasonable time to address the issue before disclosure
- Do not access, modify, or delete data beyond what's necessary to demonstrate the vulnerability
- Do not degrade service availability (no DoS testing on production)
- Do not share vulnerability details with others until coordinated disclosure
-
-Disclosure Timeline
-
-Day 0 You report vulnerability
-Day 1-2 We acknowledge receipt
-Day 7 We confirm vulnerability and share initial assessment
-Day 7-90 We develop and test fix
-Day 90 Coordinated public disclosure
- (earlier if fix is ready; later by mutual agreement)
-
-If we cannot reach agreement on disclosure timing, we default to 90 days from your initial report.
-Scope
-In Scope ✅
-
-The following are within scope for security research:
-
- This repository (hyperpolymath/terrapin-ssg) and all its code
- Official releases and packages published from this repository
- Documentation that could lead to security issues
- Build and deployment configurations in this repository
- Dependencies (report here, we'll coordinate with upstream)
-
-Out of Scope ❌
-
-The following are not in scope:
-
- Third-party services we integrate with (report directly to them)
- Social engineering attacks against maintainers
- Physical security
- Denial of service attacks against production infrastructure
- Spam, phishing, or other non-technical attacks
- Issues already reported or publicly known
- Theoretical vulnerabilities without proof of concept
-
-Qualifying Vulnerabilities
-
-We're particularly interested in:
-
- Remote code execution
- SQL injection, command injection, code injection
- Authentication/authorisation bypass
- Cross-site scripting (XSS) and cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- Path traversal / local file inclusion
- Information disclosure (credentials, PII, secrets)
- Cryptographic weaknesses
- Deserialisation vulnerabilities
- Memory safety issues (buffer overflows, use-after-free, etc.)
- Supply chain vulnerabilities (dependency confusion, etc.)
- Significant logic flaws
-
-Non-Qualifying Issues
-
-The following generally do not qualify as security vulnerabilities:
-
- Missing security headers on non-sensitive pages
- Clickjacking on pages without sensitive actions
- Self-XSS (requires victim to paste code)
- Missing rate limiting (unless it enables a specific attack)
- Username/email enumeration (unless high-risk context)
- Missing cookie flags on non-sensitive cookies
- Software version disclosure
- Verbose error messages (unless exposing secrets)
- Best practice deviations without demonstrable impact
-
-Safe Harbour
-
-We support security research conducted in good faith.
-Our Promise
-
-If you conduct security research in accordance with this policy:
-
- ✅ We will not initiate legal action against you
- ✅ We will not report your activity to law enforcement
- ✅ We will work with you in good faith to resolve issues
- ✅ We consider your research authorised under the Computer Fraud and Abuse Act (CFAA), UK Computer Misuse Act, and similar laws
- ✅ We waive any potential claim against you for circumvention of security controls
-
-Good Faith Requirements
-
-To qualify for safe harbour, you must:
-
- Comply with this security policy
- Report vulnerabilities promptly
- Avoid privacy violations (do not access others' data)
- Avoid service degradation (no destructive testing)
- Not exploit vulnerabilities beyond proof-of-concept
- Not use vulnerabilities for profit (beyond bug bounties where offered)
-
- ⚠️ Important: This safe harbour does not extend to third-party systems. Always check their policies before testing.
-
-Recognition
-
-We believe in recognising security researchers who help us improve.
-Hall of Fame
-
-Researchers who report valid vulnerabilities will be acknowledged in our Security Acknowledgments (unless they prefer anonymity).
-
-Recognition includes:
-
- Your name (or chosen alias)
- Link to your website/profile (optional)
- Brief description of the vulnerability class
- Date of report
-
-What We Offer
-
- ✅ Public credit in security advisories
- ✅ Acknowledgment in release notes
- ✅ Entry in our Hall of Fame
- ✅ Reference/recommendation letter upon request (for significant findings)
-
-What We Don't Currently Offer
-
- ❌ Monetary bug bounties
- ❌ Hardware or swag
- ❌ Paid security research contracts
-
- Note: We're a community project with limited resources. Your contributions help everyone who uses this software.
-
-Security Updates
-Receiving Updates
-
-To stay informed about security updates:
-
- Watch this repository: Click "Watch" → "Custom" → Select "Security alerts"
- GitHub Security Advisories: Published at Security Advisories
- Release notes: Security fixes noted in CHANGELOG
-
-Update Policy
-Severity Response
-Critical/High Patch release as soon as fix is ready
-Medium Included in next scheduled release (or earlier)
-Low Included in next scheduled release
-Supported Versions
-Version Supported Notes
-main branch ✅ Yes Latest development
-Latest release ✅ Yes Current stable
-Previous minor release ✅ Yes Security fixes backported
-Older versions ❌ No Please upgrade
-Security Best Practices
-
-When using terrapin-ssg, we recommend:
-General
-
- Keep dependencies up to date
- Use the latest stable release
- Subscribe to security notifications
- Review configuration against security documentation
- Follow principle of least privilege
-
-For Contributors
-
- Never commit secrets, credentials, or API keys
- Use signed commits (git config commit.gpgsign true)
- Review dependencies before adding them
- Run security linters locally before pushing
- Report any concerns about existing code
-
-Additional Resources
-
- Our PGP Public Key
- Security Advisories
- Changelog
- Contributing Guidelines
- CVE Database
- CVSS Calculator
-
-Contact
-Purpose Contact
-Security issues Report via GitHub or security@hyperpolymath.org
-General questions GitHub Discussions
-Other enquiries See README for contact information
-Policy Changes
-
-This security policy may be updated from time to time. Significant changes will be:
-
- Committed to this repository with a clear commit message
- Noted in the changelog
- Announced via GitHub Discussions (for major changes)
-
-Thank you for helping keep terrapin-ssg and its users safe.
diff --git a/llm-warmup-dev.adoc b/llm-warmup-dev.adoc
new file mode 100644
index 0000000..98c95ae
--- /dev/null
+++ b/llm-warmup-dev.adoc
@@ -0,0 +1,19 @@
+== LLM Warmup — ipv6-tools (Developer)
+
+=== What is ipv6-tools?
+
+See README.adoc for overview.
+
+=== Key Commands
+
+* `+just setup+` — set up development environment
+* `+just build+` — build the project
+* `+just test+` — run tests
+* `+just doctor+` — diagnose issues
+* `+just heal+` — attempt auto-repair
+
+=== Quick Context
+
+* License: MPL-2.0
+* Part of hyperpolymath ecosystem
+* See EXPLAINME.adoc for architecture
diff --git a/llm-warmup-dev.md b/llm-warmup-dev.md
deleted file mode 100644
index d035ca2..0000000
--- a/llm-warmup-dev.md
+++ /dev/null
@@ -1,16 +0,0 @@
-# LLM Warmup — ipv6-tools (Developer)
-
-## What is ipv6-tools?
-See README.adoc for overview.
-
-## Key Commands
-- `just setup` — set up development environment
-- `just build` — build the project
-- `just test` — run tests
-- `just doctor` — diagnose issues
-- `just heal` — attempt auto-repair
-
-## Quick Context
-- License: MPL-2.0
-- Part of hyperpolymath ecosystem
-- See EXPLAINME.adoc for architecture
diff --git a/llm-warmup-user.adoc b/llm-warmup-user.adoc
new file mode 100644
index 0000000..92aeaae
--- /dev/null
+++ b/llm-warmup-user.adoc
@@ -0,0 +1,19 @@
+== LLM Warmup — ipv6-tools (User)
+
+=== What is ipv6-tools?
+
+See README.adoc for overview.
+
+=== Key Commands
+
+* `+just setup+` — set up development environment
+* `+just build+` — build the project
+* `+just test+` — run tests
+* `+just doctor+` — diagnose issues
+* `+just heal+` — attempt auto-repair
+
+=== Quick Context
+
+* License: MPL-2.0
+* Part of hyperpolymath ecosystem
+* See EXPLAINME.adoc for architecture
diff --git a/llm-warmup-user.md b/llm-warmup-user.md
deleted file mode 100644
index 011aea8..0000000
--- a/llm-warmup-user.md
+++ /dev/null
@@ -1,16 +0,0 @@
-# LLM Warmup — ipv6-tools (User)
-
-## What is ipv6-tools?
-See README.adoc for overview.
-
-## Key Commands
-- `just setup` — set up development environment
-- `just build` — build the project
-- `just test` — run tests
-- `just doctor` — diagnose issues
-- `just heal` — attempt auto-repair
-
-## Quick Context
-- License: MPL-2.0
-- Part of hyperpolymath ecosystem
-- See EXPLAINME.adoc for architecture