diff --git a/.github/workflows/boj-build.yml b/.github/workflows/boj-build.yml index dba7fc8..786b8fb 100644 --- a/.github/workflows/boj-build.yml +++ b/.github/workflows/boj-build.yml @@ -16,4 +16,5 @@ jobs: curl -X POST "http://boj-server.local:7700/cartridges/ssg-mcp/invoke" -H "Content-Type: application/json" -d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\\"}"} continue-on-error: true permissions: + actions: read contents: read diff --git a/.github/workflows/casket-pages.yml b/.github/workflows/casket-pages.yml index e6af13d..11741ac 100644 --- a/.github/workflows/casket-pages.yml +++ b/.github/workflows/casket-pages.yml @@ -7,6 +7,7 @@ on: workflow_dispatch: permissions: + actions: read contents: read pages: write id-token: write diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index c475caf..7282f84 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -18,6 +18,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/dogfood-gate.yml b/.github/workflows/dogfood-gate.yml index a9f5c7c..bcbfd8b 100644 --- a/.github/workflows/dogfood-gate.yml +++ b/.github/workflows/dogfood-gate.yml @@ -13,6 +13,7 @@ on: branches: [main, master] permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/governance.yml b/.github/workflows/governance.yml index 8776de0..aad0d03 100644 --- a/.github/workflows/governance.yml +++ b/.github/workflows/governance.yml @@ -9,8 +9,9 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: governance: - uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 \ No newline at end of file + uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 \ No newline at end of file diff --git a/.github/workflows/hypatia-scan.yml b/.github/workflows/hypatia-scan.yml index 9dde27a..1f8c940 100644 --- a/.github/workflows/hypatia-scan.yml +++ b/.github/workflows/hypatia-scan.yml @@ -11,9 +11,10 @@ on: workflow_dispatch: permissions: + actions: read contents: read security-events: write jobs: scan: - uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 \ No newline at end of file + uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 \ No newline at end of file diff --git a/.github/workflows/instant-sync.yml b/.github/workflows/instant-sync.yml index 228dc43..0f86f6c 100644 --- a/.github/workflows/instant-sync.yml +++ b/.github/workflows/instant-sync.yml @@ -9,6 +9,7 @@ on: types: [published] permissions: + actions: read contents: read jobs: diff --git a/.github/workflows/mirror.yml b/.github/workflows/mirror.yml index 81e9903..72824fb 100644 --- a/.github/workflows/mirror.yml +++ b/.github/workflows/mirror.yml @@ -7,9 +7,10 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: mirror: - uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@d135b05bfc647d0c0fbfedc7e80f37ea50f49236 + uses: hyperpolymath/standards/.github/workflows/mirror-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 secrets: inherit diff --git a/.github/workflows/push-email-notify.yml b/.github/workflows/push-email-notify.yml index 4b4e754..112afd1 100644 --- a/.github/workflows/push-email-notify.yml +++ b/.github/workflows/push-email-notify.yml @@ -7,6 +7,7 @@ name: Push email notification on: push: {} permissions: + actions: read contents: read jobs: notify: diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml index b97e2cb..03413b9 100644 --- a/.github/workflows/scorecard.yml +++ b/.github/workflows/scorecard.yml @@ -9,11 +9,12 @@ on: workflow_dispatch: permissions: + actions: read contents: read jobs: scorecard: - uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@81dbf2dd854b1444fd6236fa2352474383b2c2b9 + uses: hyperpolymath/standards/.github/workflows/scorecard-reusable.yml@7fdc2705df74b4e352d2a1cde3e87a5923fdf329 permissions: contents: read security-events: write diff --git a/.github/workflows/secret-scanner.yml b/.github/workflows/secret-scanner.yml index 3ba3bac..599c64a 100644 --- a/.github/workflows/secret-scanner.yml +++ b/.github/workflows/secret-scanner.yml @@ -16,6 +16,7 @@ concurrency: cancel-in-progress: true permissions: + actions: read contents: read jobs: diff --git a/guix.scm b/guix.scm deleted file mode 100644 index d42a768..0000000 --- a/guix.scm +++ /dev/null @@ -1,18 +0,0 @@ -; SPDX-License-Identifier: MPL-2.0 -;; guix.scm — GNU Guix package definition for polyglot-formalisms-elixir -;; Usage: guix shell -f guix.scm - -(use-modules (guix packages) - (guix build-system gnu) - (guix licenses)) - -(package - (name "polyglot-formalisms-elixir") - (version "0.1.0") - (source #f) - (build-system gnu-build-system) - (synopsis "polyglot-formalisms-elixir") - (description "polyglot-formalisms-elixir — part of the hyperpolymath ecosystem.") - (home-page "https://github.com/hyperpolymath/polyglot-formalisms-elixir") - (license ((@@ (guix licenses) license) "MPL-2.0" - "https://github.com/hyperpolymath/palimpsest-license"))) diff --git a/test/zigzag/zigzag_test.exs b/test/zigzag/zigzag_test.exs new file mode 100755 index 0000000..4f3632d --- /dev/null +++ b/test/zigzag/zigzag_test.exs @@ -0,0 +1,42 @@ +defmodule ZigzagTest do + use ExUnit.Case, async: true + use ExUnitProperties + + @moduledoc """ + Zigzag test implementation: Meandering routes through the system aspects. + """ + + # Define aspects + @aspects [:auth, :db, :network, :telemetry] + + property "meandering route maintains cross-cutting invariants" do + check all steps <- list_of(member_of(@aspects), min_length: 5, max_length: 50) do + # Initial system state + state = %{auth: false, db_connected: true, metrics: 0} + + final_state = + Enum.reduce(steps, state, fn aspect, acc -> + # Execute the aspect transition (simulated) + case aspect do + :auth -> + %{acc | auth: not acc.auth, metrics: acc.metrics + 1} + :db -> + # DB might disconnect and reconnect + %{acc | db_connected: not acc.db_connected, metrics: acc.metrics + 1} + :network -> + acc + :telemetry -> + %{acc | metrics: acc.metrics + 1} + end + end) + + # Cross-cutting invariants that MUST hold after a chaotic meandering route: + # Invariant 1: Metrics should never be negative + assert final_state.metrics >= 0 + + # Invariant 2: (Simulated) if we finish the route, the DB should ultimately be able to reconnect + # or if it's disconnected, it shouldn't crash the next read. + assert is_boolean(final_state.db_connected) + end + end +end diff --git a/tests/zigzag/ZigzagModel.idr b/tests/zigzag/ZigzagModel.idr new file mode 100755 index 0000000..8ed3275 --- /dev/null +++ b/tests/zigzag/ZigzagModel.idr @@ -0,0 +1,30 @@ +module ZigzagModel + +-- Idris2 state machine for aspect-oriented zigzag testing + +data Aspect = Auth | DB | Network | Telemetry + +record SystemState where + constructor MkSystemState + isAuthenticated : Bool + dbConnected : Bool + metricsCount : Nat + +-- Define the transitions +transition : Aspect -> SystemState -> SystemState +transition Auth state = record { isAuthenticated = not state.isAuthenticated, metricsCount = S state.metricsCount } state +transition DB state = record { dbConnected = not state.dbConnected, metricsCount = S state.metricsCount } state +transition Network state = state +transition Telemetry state = record { metricsCount = S state.metricsCount } state + +-- Proof that metrics never decrease during a transition +metricsNeverDecrease : (a : Aspect) -> (s : SystemState) -> (transition a s).metricsCount >= s.metricsCount +metricsNeverDecrease Auth s = LTEZero -- (simplified proof stub) +metricsNeverDecrease DB s = LTEZero +metricsNeverDecrease Network s = LTEZero +metricsNeverDecrease Telemetry s = LTEZero + +-- A meandering route is just a list of aspects applied sequentially +meander : List Aspect -> SystemState -> SystemState +meander [] s = s +meander (x :: xs) s = meander xs (transition x s)