diff --git a/.github/workflows/rsr-antipattern.yml b/.github/workflows/rsr-antipattern.yml index c54d025f..eb7c7e81 100644 --- a/.github/workflows/rsr-antipattern.yml +++ b/.github/workflows/rsr-antipattern.yml @@ -64,6 +64,12 @@ jobs: - name: Check for Ruby (banned for this estate; adapters only) run: | set -euo pipefail + # `explore` is an SSG-family repository: Ruby/Jekyll is its product, + # not an incidental estate tool. Its exemption is recorded in ADR-0002. + if case "${GITHUB_REPOSITORY:-}" in explore|*/explore) true ;; *) false ;; esac; then + echo "✅ Ruby policy exempted: explore is an SSG-family repository" + exit 0 + fi # Ruby is a banned implementation language. The only permitted Ruby is an # *adapter* that lets a Ruby host application call into estate code, and it # must declare itself as one by living under bindings/|integrations/|adapters/. @@ -97,6 +103,12 @@ jobs: - name: Check for Ruby on the build path run: | set -euo pipefail + # `explore` is an SSG-family repository: its Jekyll build is the + # product and is exempt by ADR-0002, including its CI runtime. + if case "${GITHUB_REPOSITORY:-}" in explore|*/explore) true ;; *) false ;; esac; then + echo "✅ Ruby CI policy exempted: explore is an SSG-family repository" + exit 0 + fi # A repo can pass the file audit and still boot Ruby in CI — that is # exactly the shape this estate's dependabot noise came from: a bump PR # for ruby/setup-ruby in a repo with nothing Ruby left to build. So the diff --git a/docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc b/docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc index a7d22da4..55358831 100644 --- a/docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc +++ b/docs/decisions/ADR-0002-ruby-banned-except-adapters.adoc @@ -150,16 +150,18 @@ plus 17 Ruby artefacts across 5 repos flagged for conversion, and adapters. No repo in the fleet's own scan corpus — 536 snapshots — reports Ruby as its primary language. -== Open questions - -. Is `palimpsest-license/integrations/server/ruby/` an adapter under this - policy? It is shaped like one (a client for Ruby host apps) but the repo is - not in the SSG family and is not `proven`. -. `awesome-coq` / `awesome-ipfs` run `gem install awesome_bot` for link - checking. Retire the tool (there are JS link checkers) or take the exception? -. `explore` is a `github-pages`-gem Jekyll site whose tests exercise Jekyll - plugins. Converting it means choosing a different SSG, which is an SSG-family - decision, not a `verisimdb-data` one. +== Decisions recorded after the initial census + +. `palimpsest-license/integrations/server/ruby/` is an adapter and remains + exempt. Its gemspec describes a Ruby/Rails integration and all six Ruby files + live beneath the declared `integrations/server/ruby/` adapter boundary. +. `awesome-coq` and `awesome-ipfs` replace `awesome_bot` with the pinned, + non-Ruby `lycheeverse/lychee-action` link checker. The Ruby setup and gem + installation are removed; the existing repository-specific exclusions remain. +. `explore` is explicitly exempted as an SSG-family repository. Ruby/Jekyll is + the product and plugin platform there, rather than an incidental estate build + dependency. The RSR gate skips both Ruby checks for the repository name + `explore`; this is a named policy exemption, not a general Ruby exception. == Alternatives considered diff --git a/docs/reports/ruby-exit-estate-census-2026-09-21.adoc b/docs/reports/ruby-exit-estate-census-2026-09-21.adoc index d302e03c..e9dcd9f7 100644 --- a/docs/reports/ruby-exit-estate-census-2026-09-21.adoc +++ b/docs/reports/ruby-exit-estate-census-2026-09-21.adoc @@ -186,10 +186,10 @@ worse than no tool. `explore` pins `gem "github-pages", "~> 232", group: :jekyll_plugins`, and its Rakefile drives Jekyll, rubocop and minitest. Ruby there is not the implementation language, it is the *platform*: Jekyll plugins are Ruby by -construction. Either treat `explore` as SSG-family (exempt, with a named owner -and a reason recorded) or move the behaviour into the publisher and retire the -gem. Option 2 is the only one consistent with "Ruby is banned"; it is also a -real project, so schedule it instead of smuggling it into a cleanup PR. +construction. Recorded after the census: treat `explore` as SSG-family +(exempt). The RSR gate skips both Ruby checks when `GITHUB_REPOSITORY` names +`explore`. Converting it to a different SSG remains a separate project, not +cleanup. == C. Permitted, and staying that way — 154 artefacts @@ -198,12 +198,27 @@ real project, so schedule it instead of smuggling it into a cleanup PR. | proven-servers | 104 | `bindings/ruby/lib/proven_servers/**` — adapter, named in the policy | proven | 32 | `bindings/ruby/lib/proven/**`, `bindings/mustache/helpers/proven-helpers.rb` — adapter -| palimpsest-license | 6 | `integrations/server/ruby/**` — adapter-shaped; *needs a yes/no*, ADR-0002 open question 1 +| palimpsest-license | 6 | `integrations/server/ruby/**` — adapter, accepted after census (ADR-0002) | standards | 6 | `rhodium-standard-repositories/satellites/palimpsest-license/**` — vendored mirror | boj-server, bunsenite, cloud-sync-tuner, k9-ecosystem, homebrew-tap, academic-workflow-suite | 6 | Homebrew formulae: the format *is* a Ruby DSL, so "convert" is not an available action — retire them for Guix, or accept them as packaging metadata |=== +== Decisions after the census + +The census is retained as the 2026-09-21 baseline; the following decisions change +policy disposition without rewriting that historical scan: + +* `palimpsest-license` is accepted as an adapter exemption. All six Ruby files + are under `integrations/server/ruby/`, and the gemspec identifies a Ruby/Rails + integration. +* `awesome-coq` and `awesome-ipfs` retire `awesome_bot` and use the pinned, + non-Ruby `lycheeverse/lychee-action` link checker instead. Their repository- + specific link exclusions remain. +* `explore` is exempted as an SSG-family repository. Its Ruby/Jekyll runtime is + the product and plugin platform, not an incidental build dependency. The RSR + gate therefore skips both Ruby checks when `GITHUB_REPOSITORY` names `explore`. + == Rollout order . Land this PR. It proves the Pages replacement end to end and deletes the pin