Keyboard shortcuts

Press or to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Project status

This page describes the supported surface on main, not the history of individual releases. Versions and release-specific changes live in the changelog. Future work and its entry conditions live in the Roadmap.

Supported surface

AreaCurrent contractImplementation anchor
Commandamiss check compares a base commit with either a candidate commit or the staged index, amiss fix applies the staged evaluation’s proof-gated fixes to the working tree, amiss claim authors a value claim proven against the working tree before it is printed, amiss policy-include authors one validated exact-suffix policy row and can preview its staged matches, amiss record-set converts normalized specialist rows into a checked self-asserted semantic template without opening a repository, amiss adopt mints an adoption-debt snapshot from a commit pair’s eligible findings, amiss external-plan derives the delegated-evidence destination delta from a written report without opening a repository, amiss external-assess judges that plan against a producer’s observations under a fixed offline policy, amiss render projects one validated report without evaluating it again, amiss refs returns the exact candidate occurrences that refer to one repository path, amiss --help prints that closed grammar, and amiss --version reports the binary’s version, with its engine digest when the binary can read itself. The command grammar is closed at those twelve forms.CLI parser
Repository accessThe engine reads Git objects, packs, deltas, trees, and the index directly. It does not invoke git, follow repository symlinks, or fetch missing data.Git store
DocumentsBuilt-in discovery covers Markdown, GFM, MDX, AsciiDoc, reStructuredText, six extensionless Markdown basenames, and two plain-advisory basenames. Repository policy may add exact paths or trees narrowed by one exact suffix, each optionally bound to one built-in grammar, without installing another parser.Classifier
ReferencesRelative repository paths and same-repository GitHub, GitLab, Gitea-family, Bitbucket Cloud, and Bitbucket Data Center URLs are resolved under their declared dialect. Full immutable IDs are accepted only in the run’s object format and resolve against that exact commit when every required object is already available under the declared Git roots and budgets. A complete local walk may prove a missing historical path; unavailable objects retain the exact ID and path as unsupported historical scope and enter the provider-evidence plan, while the engine never fetches them. A relative destination the tree does not hold is asked again under the spellings a pinned documentation router serves, which can only reach a file the tree already holds. A missing candidate path carries evidence of a unique unchanged relocation when the base and candidate entries have the identical Git mode and object ID, but never a repair. Numeric line fragments select and compare an exact inclusive byte range, and a heading anchor resolves when any of twelve pinned renderer rules would publish it or the document declares the identity itself, in raw HTML, in an attr_list block, or in the MDX comment Docusaurus uses. Option-free local AsciiDoc and reStructuredText includes expand recursively from the frozen scanned set, and literal includes never parse their target as markup; dynamic, selected, nested-context, unavailable, and AsciiDoc build-state-dependent absence retain conservative boundaries. Unsupported shapes remain visible in the report, and a delegated destination is recorded where it is seen, never fetched.Resolver
Policy.amiss/scanner-policy.json may expand discovery, own exact visible source, tree-inventory, and inventory-count projections, and raise the disposition of missing targets, target-type mismatches, and invalid references. It cannot downgrade or suppress a finding.Policy application
ReportsMachine output uses the frozen report envelope and payload contract. Exact findings remain the evidence surface; engine-grouped Fix, Check, and Existing feedback is its review projection. The wire is versioned by the in-report compatibility field, not by the engine release; it reads 1, frozen and additive within the major, with the retained first frozen example holding every later schema to that promise.Current schema
Semantic evidenceA separate 16 MiB envelope binds one external producer and at most 100,000 canonical observations to the exact candidate and optional source report. Every sealed value also carries the controller-plan-owned context digest its producer must reproduce. Unknown observation kinds are inert. Compiled consumers resolve unique prefixless Sphinx labels; exact built-site routes, anchors, redirects, and navigation; and exact values, sorted rows, or counts from complete record sets. The public check command can bind one candidate-free local template after resolving the exact commit or staged-index identity, but that caller-selected input remains self-asserted. The offline record-set form can assemble such a template from strictly validated normalized rows while leaving specialist digests, completeness, and authority as caller assertions. An isolated operator binary normalizes bounded, format-matched Rustdoc JSON into a complete record set of root-crate public free, inherent, and trait function declarations without invoking Cargo or entering provider binaries. Provider plans produce the bounded operator-local or cached Sphinx inventory set. Trusted acquisition adds strictly checked candidate-independent template bytes under a unique planned acquisition identity; the controller binds the exact candidate and constructs a bounded audit value from the source and envelope bytes. The controller can derive routes, anchors, and navigation from a pinned mdBook renderer context and caller-opened completed HTML output, bound to an exact configuration path, publication prefix, locale, and version. The GitHub provider lane can acquire a plan-frozen workflow artifact for the exact candidate; the other provider lanes expose no workflow-artifact source.Contract, Rust producer, inventory producer, mdBook producer, and consumer
Publication auditsClosed digest-bound contracts model an operator-owned publication plan, one provider-normalized successful-deployment receipt, and a conservative offline matched/refuted/unproven assessment. They bind the accepted report and exact docs, target, completed-site, product, deployment, workflow, producer, and evaluator identities. The controller validates that a complete chain describes its exact scanner report and replays to the supplied assessment. Its artifact store retains and reopens the exact report, plan, optional evidence, assessment, digest set, and verdict as one immutable evaluation-bound record. No command or controller lane acquires, stages, or publishes it yet.Publication audits
Locale coverage auditsOne closed digest-bound plan binds an accepted report and exact docs candidate to a site, locale pair, independently selected producer, operator-owned coverage/fallback/optional target-lineage policy, and an optional immutable product resource reused from publication audits. Evidence carries independently complete source and target inventories with independent nullable product receipts; every target page is target-owned with nullable exact source lineage or declares an exact fallback class and source digest. The offline assessment reports proved missing/orphan pages, fallback status, current/stale/unproven target lineage, and matched/refuted/unproven product identity for each side. Only an exhaustive clean selected comparison matches. Exact lineage and product equality prove only the named digest relations, never translation quality or semantic equivalence. Command and controller intake are not built yet.Locale coverage audits
Cross-repository relationsThe provider-neutral controller atomically freezes operator-owned two-subject relations, one opaque pair/release/workflow coordination identity, and all four exact base/candidate commit/tree identities without inferring intent from timestamps. A pure admission law assigns the first exact transition a fence, preserves identical work as a duplicate across either trigger role, rejects stable-identity rebinding, and advances the fence when a different coordination supersedes pending work. A bounded file-backed store applies the same law under a cross-process lock and atomically committed hash-chained journal; it serializes concurrent admission, recovers an uncommitted append after restart, and refuses exhausted capacity or missing, shortened, mutated, or rebound committed state. Exact historical retries retain their first fence without rolling current work back. The existing strict Git transport acquires each subject into a physically independent root under per-subject and aggregate streaming object/byte limits, rechecks every commit-tree binding, and returns the complete relation as unproven on any unavailable subject. A closed digest-bound plan retains the accepted report digest, trigger role, relation context, coordination identity, shared projection, human-readable repositories and selectors, and all four exact snapshots without copying credentials into the wire. The provider-neutral Git layer binds that plan back to the frozen transition and projects exact blob-line, named-region, or tree-path sources from all four acquired snapshots under joint record/byte budgets; unavailable sources produce null slots, while record values and sets await a trusted snapshot-bound producer. A separate plan-bound receipt gives each role independent nullable base/candidate slots; a present slot is only a projected-value digest and exact byte length, while null cannot claim emptiness or inequality. The replayable offline assessment binds the report, plan, optional evidence, and evaluator, then symmetrically classifies the complete equality transition as aligned, introduced drift, pre-existing drift, or resolved drift; absent, foreign, misrouted, or partial evidence remains unproven. Before immutable restart-safe retention, the controller reopens the accepted report, binds its repository, target, coordination, and snapshots to the trigger role and frozen operator transition, and independently replays the plan, optional evidence, and assessment. Pure status preparation requires both complete registered subjects at their still-current candidate commits and freezes only configured destinations under the pending fence. A second pure transition replays the retained audit against that pending work, freezes the exact target/audit record, resumes an unfinished exact retry, rejects immutable-field substitution, and completes the exact record idempotently. The same bounded journal commits status stage, per-destination acknowledgement, and completion actions under the scheduling lock, verifies the retained artifact before first stage and unfinished replay, and retains compact digest bindings instead of duplicating provider configuration or credentials. A provider-neutral delivery claim selects the oldest unresolved fence for each stable destination, reacquires its exact registry and artifact record, and holds one of 256 deterministic OS-lock shards across provider I/O. Dropped claims recover without durable mutation; a newer coordination cannot pass an unresolved older destination; unrelated shards remain parallel; and the final acknowledgement completes the batch, including recovery from failure between the two journal actions. The outbox itself performs no provider call. The GitHub installation and Gitea-family clients resolve exact registered branch heads. GitHub reconciles App-owned relation checks, while Gitea-family reconciles dedicated-reviewer commit statuses with its documented writer-binding limitation. A GitLab adapter resolves only the ephemeral candidate of an authenticated active policy job and returns the exact staged relation decision after a final live refresh, without making a provider write. The shared service loads one bounded strict-JSON operator registry and derives repository hosts from provider instances. An immutable generic router binds every required credential identity to one caller-owned authority under its exact provider and integration and rejects missing, unused, repeated, or rebound rows. Coordination admission consumes one authenticated delivery and accepts only an opaque operator identity for a relation owned by its exact trigger set. Provider binaries do not construct or install those values yet; snapshot acquisition and live lifecycle integration are not built.Cross-repository relations
GitHub convenience ActionA source-tag dispatcher selects the same version’s immutable runtime tree. The runtime derives snapshots from supported GitHub events, verifies the selected engine against its manifest, shows at most ten grouped items, and annotates only displayed Fixes. It is not a provider-authenticated controller adapter or an independent trust boundary.Dispatcher and runtime
GitHub provider laneA source-built App service authenticates pull-request events, refreshes exact state and strict App-bound rules, acquires exact SHA-1 objects and optional plan-frozen workflow artifacts, runs the sealed bootstrap, and publishes on GitHub’s test-merge commit. GitHub.com and compatible GHES releases are supported.GitHub setup
GitLab provider laneA source-built service authenticates a pipeline execution policy job through OIDC, verifies its enforced merge train, policy origin, runner, project, and exact train commit, then lets only an exact pass make that job succeed. GitLab 19.3 or newer with Ultimate is supported.GitLab setup
Gitea and Forgejo provider laneA source-built service authenticates pull-request webhooks, refreshes the effective protected-branch rule, acquires exact SHA-1 objects, runs the sealed bootstrap, and approves or rejects through one dedicated reviewer. Gitea 1.27 or newer and Forgejo 16 or newer are supported.Gitea and Forgejo setup
Provider service operationEvery service has an offline configuration check, separate liveness and readiness, fourteen fixed label-free counters, redacted lifecycle events, and graceful drain. The listener and its operator endpoints remain private.Service operation

Repository form is deliberately closed too. The reader accepts the non-bare checkouts: a primary checkout whose .git entry is a real directory, a linked worktree, and a separate-git-dir checkout. The .git file forms resolve through one bounded gitdir: indirection plus at most one bounded commondir hop, symlinked targets are refused, the index always reads from the worktree’s private directory, and depth is structural rather than configured. Bare repositories stay unavailable directly, though a bare main’s linked worktrees read through their commondir, and alternate object stores are not consulted. The repository boundary and its boundary tests pin that behavior.

The supported reference surface is intentionally smaller than “every path-like phrase in prose.” Bare filenames in ordinary text are not inferred; raw HTML and MDX code regions are opaque; leading-slash site routes without sealed build evidence, code symbols, live URLs, and references to other repositories are not validated under those systems’ semantics. Their visible boundary behavior is described in Discovery and Resolution.

Trust surfaces

The repository contains strict parsers and canonical writers for evaluation, snapshot, and external-control requests, plus evaluation logic for organization floors, adoption debt, waivers, trusted time, and execution constraints. The evaluation identity separates the candidate ref used for same-repository URL resolution from the protected target ref used by the branch-scoped floor, trusted-time, debt, and waiver gates. The public command still supplies all five external controls as absent and has no target-ref option; its repository and candidate-ref fields remain caller assertions. check may add one caller-selected semantic template, which does not change that trust level. The forge field selects a URL dialect, not an authenticated provider. Compare the request schemas, strict parsers, pipeline shell, and CLI wiring.

amiss-bootstrap now has a sealed engine path. It bounded-captures the three request files, requires their canonical forms, a complete repository/dialect/ref identity, and coherent commit-pair materialization, matches the embedded execution constraint and trusted-time provider/run tuple, checks that both requested commits were pre-acquired, validates the action tree and runtime closure, and then sends only a closed evaluation/snapshot/controls frame over stdin to the verified engine. The child receives the repository as its fixed working directory, a cleared environment, one private engine argument, and no caller-selected engine command. Report acceptance rejects an unavailable hybrid and binds the requested profile, both commits, candidate and target refs, candidate identity, provider run and trusted instant, the exact presence, digest, and trust source of the organization floor, debt snapshot, and waiver bundle, and the execution constraint’s digest, trust source, and recomputed semantics, plus every supplied semantic envelope’s payload and producer/input identity after its plan-owned context matches. It likewise recomputes the trusted-time statement’s semantic digest and requires the sandbox provenance to remain self-asserted. The wire crate exposes checked constructors and canonical writers for the execution constraint and trusted-time statement, and the controller uses them when it derives a sealed job. The source-built amiss-constraint companion reads an exact local action commit and bootstrap, derives the redundant execution fields, validates the dependency locks and selected runtime closure, and writes the canonical constraint without fetching or authenticating either input. The release workflow builds the sealed action and bootstrap path; it does not publish the companion or provider services. The published composite Action still launches amiss directly, while separately operated provider services acquire their inputs and invoke the sealed path. The distinction is visible in the bootstrap entry point, constraint producer, release assembly, and Action execution.

The unpublished crates under controller/ define the provider-neutral identities, bounded ingress, rotating verifier keys, durable raw inbox, delivery record, retained artifact store, worker, orchestration, acquisition, and supervised runner contracts. Its state uses checksummed ordinary files with fixed capacity and atomic replacement, not SQL or a database. Controller delivery records the cross-process ownership, heartbeat, replay, and exact-publication retry rules; authenticated report and assessment retrieval is defined by Retained provider artifacts.

The provider crates add signed-input decoders, controller-owned credentials and API clients, strict merge-rule authorization, fixed-budget protocol-v2 Git acquisition, and provider evidence. GitHub uses an App-bound required Check Run on the test merge. GitLab uses an independently owned pipeline execution policy job on an enforced merge train and authenticates that job through OIDC. Gitea and Forgejo use a protected approval restricted to one dedicated reviewer. The workspace keeps those adapters separate instead of turning provider differences into one closed provider enum. Provider-verified controls compares the supported lanes and links their exact setup, retry limits, and trust boundaries.

All three service binaries share an offline configuration check. It validates local configuration and named trust inputs before creating the runtime or touching provider and mutable service state. Once running, their shared service operation contract separates liveness from readiness, keeps metrics and lifecycle events bounded, and drains admitted work without losing a durable webhook backlog. These are deployment tools, not retained live-provider evidence.

Local and convenience-Action reports still describe repository policy with no outside authority consulted. Their external controls are absent, an optional local semantic template has no outside authority, and sandbox assurance is self-asserted. A report produced through a provider lane can contain verified external controls, but the report does not authenticate who supplied them and gains no provider_verified field or signature. Provider evidence lives in the App-owned Check Run, protected policy job, or dedicated review and the matching merge rule. See Controls and policy and The report for the exact distinction.

Keeping this page honest

Links from factual prose to the implementation are deliberate. The repository’s own Amiss scan makes a changed dependency under unchanged prose visible for review.

The mechanical claims are generated, not maintained. Default dispositions in Profiles and findings and resource ceilings in Limits and refusals come from the Rust constants through a test, so changing a constant without the book fails CI. The same documentation contract test finds every public schema-backed example, validates it against its schema, and feeds it to its owning typed reader; a contract without a registered reader fails CI too.

The examples execute. The report’s readable form passes the strict JSON reader, and its canonical bytes clear the wrapper acceptance law end to end. The commit and staged-index identity preimages reproduce the production digest chain in the identity golden test. The published semantic corpora drive their live code paths: frontmatter vectors through the recognizer, correlation vectors through the intent projection, and governed-definition vectors through report construction, value-grammar refusals included.

Published CI snippets must pin upstream Actions immutably, name an explicit reviewed crate version, and advertise the current release major. Version strings inside example fixtures are reproducible evidence, not claims about the latest release. None of this proves the meaning of free prose. It makes the mechanical drift visible, which is the part a machine can own.

Last change: , commit: cae956c4