Skip to content
rlsbl.strictspec_gate
On this page

Strictspec diff-certificate deploy gate that blocks a release when a certificate reports a violated or unadjudicated format_version claim.

#rlsbl.strictspec_gate

#rlsbl.strictspec_gate

strictspec diff-certificate deploy gate.

rlsbl can consume a strictspec strictspec diff CERTIFICATE as a format_version deploy gate. The gate is feature-flagged by CONFIG PRESENCE: a project opts in by adding a strictspec_gate section to .rlsbl/config.json; projects without it are untouched (the built-in check skips).

Grade semantics (strictspec spec/appendix-certificates.md Part A, decision 25):

  • violated -- a corpus document IS the counterexample. BLOCKS release.
  • corpus-supported -- no counterexample in the declared corpus. GREEN.
  • proven -- reserved for the future analyzer; treated as GREEN.
  • any other / unsupported claim -- must be discharged by a committed ADJUDICATION

file (Part B). An unsupported, unadjudicated claim BLOCKS release. There is no bypass.

The certificate is deliberately UN-GATED (it carries certificate_format_version, not a document format_version), so rlsbl parses it as plain JSON and inspects the claim grades natively -- a strictspec document schema, which mandates the version gate, cannot validate an intentionally un-gated artifact. The ADJUDICATION file, by contrast, IS a gated strictspec document and is validated via the strictspec-generated adjudication validator.

#GateVerdict

The outcome of evaluating the certificate deploy gate.

#validate_gate_config

python
def validate_gate_config(config)

Validate the strictspec_gate config section shape.

Returns the section dict when present, or None when absent (opt-out). Raises :class:ConfigError on a malformed section.

#_load_certificate

python
def _load_certificate(path)

Load and shape-check the certificate JSON. Raises ConfigError on failure.

The certificate is un-gated by design, so it is parsed as plain JSON; only the fields the gate consumes are shape-checked.

#_load_adjudications

python
def _load_adjudications(config, project_root, section)

Load + validate the adjudication file (a gated strictspec document).

Returns the list of adjudication entry dicts, or None when no adjudication file is configured. Raises ConfigError on a missing or invalid file.

#evaluate_certificate_gate

python
def evaluate_certificate_gate(config, project_root)

Evaluate the strictspec certificate deploy gate against config.

Returns a :class:GateVerdict. When the strictspec_gate section is absent, the verdict is skipped (opt-out; no behavior change). A missing certificate file, malformed certificate, or malformed/missing adjudication file raises :class:ConfigError (a hard error -- if configured, it must work). Otherwise the verdict reflects the claim grades.

#_discharge_unsupported

python
def _discharge_unsupported(unsupported, adjudications, cert_path, blocking, notes)

Match each unsupported claim to an adjudication entry; flag stragglers.

An adjudication entry discharges a claim when its claim_kind equals the claim's kind and its scope equals the claim's statement. An unsupported claim with no matching entry BLOCKS; an adjudication entry that matches no unsupported claim is dangling and also BLOCKS (per Part B).

More tools from this site

  • claudestream Drive Claude Code from Python: run it as a subprocess and read its output as typed events, with async and sync sessions, sandbox policies, and tools you define in Python
  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search