Skip to content

guardrail: take the emission date out of the canon digest - #7

Merged
fas89 merged 1 commit into
mainfrom
chore/guardrail-canon-aa4301c6
Sep 15, 2026
Merged

fas89 merged 1 commit into
mainfrom
chore/guardrail-canon-aa4301c6

Conversation

@fas89

@fas89 fas89 commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

Vendored guardrail sync. Two travelling files changed: tools/product_guardrail/canon_payload.py and tools/product_guardrail/check.py.

What moved

compute_canon_id now excludes the payload's Emitted <date>. line from the digest, alongside the CANON_ID line it already excluded.

Why

The emitter stamps today's date into the payload, and that line was being hashed, so the canon id was a function of the calendar rather than of the vocabulary. Re-emitting with no vocabulary change at all still moved the id; every vendored copy then read as out of date, and the daily fan-out asked for one pull request per product repo whose entire content was a changed date. The id now answers only "is this the same vocabulary", which is the question anyone actually asks it.

The exclusion is anchored to a bare ISO date (^Emitted \d{4}-\d{2}-\d{2}\.$), not to ^Emitted, so the excluded line cannot be used to smuggle unhashed text past the digest. The self-test asserts it in both directions: the emission date must not move the id, and any other line must.

Verified in this checkout, before the commit

  • python3 tools/product_guardrail/check.py --self-test exits 0: product-guardrail self-test passed: 15 entries both ways, 8 extractor specimens
  • python3 tools/product_guardrail/check.py exits 0:
canon coverage (product surface): 1 of 10 approved names present
  present: FLUID Spec (1)

scanned 66 files, 1069942 bytes, 1040 spans, 3 rules
canon holds: 0 failing findings, 0 warning(s), 0 graced.
  • CANON_ID in the synced payload is ff28e99a952b791210cf743af8eecb3117f5cdd51f0f92710061b72dd8ff0330, the redacted public variant of canonical aa4301c6f0fd….
  • len(DEFINITIONS) == 0, as it must be in a public copy: the maturity ledger is redacted from public payloads.

profile.py is untouched

git status --porcelain after the write showed exactly the two files above. profile.py is hand-written per repo (what to scan, what to skip, the grace list) and never travels; this sync did not read from it or write to it.

Exit codes above were captured without a pipe, so they are the real exit codes of the commands themselves.

compute_canon_id no longer hashes the payload's `Emitted <date>` line, so
the canon id tracks the vocabulary instead of the calendar. Re-emitting
with no vocabulary change used to move the id, which made every vendored
copy read as out of date and turned the daily fan-out into one pull
request per repo changing a single date.

Vendored from the canon repo: canon_payload.py and check.py only.
profile.py is hand-written per repo and is untouched.

Canonical id aa4301c6f0fd; this public copy carries the redacted variant
ff28e99a952b with an empty DEFINITIONS list.
@fas89
fas89 merged commit d990577 into main Sep 15, 2026
6 checks passed
@fas89
fas89 deleted the chore/guardrail-canon-aa4301c6 branch September 15, 2026 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant