tools/core/factories/governance.factory.ts
tools/core/factories/governance.factory.ts is a file in Coordination Surface. 102 lines of code and 6 definitions.
import type { Finding } from "../types/segment.types.ts";
import { GENERATED_DIR } from "../constants/path.constants.ts";
import { basename } from "node:path";
import type { staleChannels } from "../validators/channel.validator.ts";
import type { unsanctionedWriters } from "../validators/writer.validator.ts";
type Breach = ReturnType<typeof unsanctionedWriters>[number];
type StaleChannel = ReturnType<typeof staleChannels>[number];
export const contractFinding = function contractFinding(
path: string,
locus: string,
actual: string,
decide: string,
resolved: string,
): Finding {
return {
actual,
expected: null,
healed: false,
line: 0,
locus,
path,
remediation: { action: "declare", decide, deterministic: false, from: actual, target: path, to: null },
rule: "governance/ruleContract",
stack: [
{ check: "ruleSource", resolved: basename(path) },
{ check: "contract", resolved },
],
};
};
export const orphanFinding = function orphanFinding(name: string): Finding {
return {
actual: name,
expected: null,
healed: true,
line: 0,
locus: name,
path: `${GENERATED_DIR}/${name}`,
remediation: {
action: "delete",
decide: "",
deterministic: true,
from: name,
target: `${GENERATED_DIR}/${name}`,
to: null,
},
rule: "governance/orphanReport",
stack: [
{ check: "reportShape", resolved: "declares rule and stage" },
{ check: "claimedBy", resolved: "no rule declaration and no step emission" },
],
};
};
export const writerFinding = function writerFinding(breach: Breach): Finding {
return {
actual: `${breach.path} writes the filesystem directly and a run reaches it`,
expected: null,
healed: false,
line: 0,
locus: breach.member,
path: breach.path,
remediation: {
action: "declare",
decide:
"route the write through the restricted writer, which takes the scope this run DECLARED and " +
"refuses a path outside it — so containment is answered at one function rather than by a witness " +
"nobody holds for a repair scattered across source. A gate over a DIRECTORY reports a complete " +
"funnel while a module writes beneath it, which is why this ranges over what a run REACHES",
deterministic: false,
from: breach.member,
target: breach.path,
to: null,
},
rule: "governance/unsanctionedWriter",
stack: [
{ check: "reachableFromARun", resolved: "yes" },
{ check: "sanctionedWriter", resolved: "no" },
],
};
};
export const staleChannelFinding = function staleChannelFinding(channel: StaleChannel): Finding {
return {
actual: channel.scope,
expected: null,
healed: true,
line: 0,
locus: channel.scope,
path: `${GENERATED_DIR}/${channel.name}`,
remediation: {
action: "delete",
decide: "",
deterministic: true,
from: channel.name,
target: `${GENERATED_DIR}/${channel.name}`,
to: null,
},
rule: "governance/staleChannel",
stack: [
{ check: "channelShape", resolved: "names its scope and declares itself non-authoritative" },
{ check: "scopeResolves", resolved: "no" },
],
};
};