fix: restore standards main to green: lock-gate pin, registry regen, uuid-v7, map roots, canon 2.1.2, docstring calibration - #1088
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 22 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (27)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
CI does not exercise this PR's purpose. On this PR and on So the pin guard was run locally against each tree's own copy of
The other two reds here also appear on 🤖 Generated with Claude Code |
aee1111 to
3d5ff2d
Compare
|
Correction to my earlier comment. I attributed the Hypatia Baseline red to #1014, and that was wrong. The three unfiltered findings on main are all in 🤖 Generated with Claude Code |
|
CI status at The three reds this PR set out to cure (lock-gate pin freshness, registry
This PR is held, not merged. The owner's 2026-09-22 rule lands only fully-green PRs, and the D232 hold still needs re-asking after its premise erratum. 🤖 Generated with Claude Code |
|
Autopilot could not be updated. Open Coding to check access and billing. |
The "Lock-gate pin is not stale" step of Repo self-tests has been red on every main commit since #1064 changed scripts/update-actions-lock.sh (a stricter single-object check on the verifier's JSON). The staging pin in governance-reusable.yml still pointed at 9c256b6, one change behind. The guard is designed so the next PR owes this bump; this is that PR. Control: the guard on the old pin exits 1 against main 5f82b63. Cure: the guard on the new pin exits 0 against the same main. The guard's own mutant suite passes 10/10. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
…tale #1072 and #1075 changed files under rhodium-standard-repositories/ without regenerating the registry, so `build-registry.sh --check` exits 1 on main. That reds "Registry + topology in sync" and both build-registry-test.sh and build-scorecards-test.sh. And because the test step fails, the "Lock-gate pin is not stale" step is skipped on every PR. Output of `just registry`, one line. Owner ruling D231: regenerate now; moving the registry off .a2ml stays tracked in #1010/#479. Closes #1092. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
The three unfiltered findings that red "Validate Hypatia Baseline" on main are all in uuid-v7.yml (#1063): no `timeout-minutes` (flagged by workflow_audit and WH006), and an unscoped `push` beside `pull_request`, so every PR-branch push ran it twice (D-BURN). Scope push to main, add the repo's usual concurrency cancel block, and set `timeout-minutes: 10`. Job name and check name are unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
Owner ruling D241 (2026-09-30): delete all five rather than map or relocate. Removed from the repository root (git history keeps every byte): ULTRAPLAN-2026-09-24.adoc, ULTRAPLAN-2026-09-29.adoc, arena-session-787/, patches/, ziz-drop/. Gate D (scripts/check-standards-map.sh): rc=1 with 5 violations on main 74d2f66, rc=0 on this tree. Positive control: an unmapped probe file at the root makes it fail again with 1 violation. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
#1041 added a KNOWN-TENSIONS row under 0-canon/constitution/ without the same-commit version bump and sha256 rewrite that canon.lock's [canon.artifacts] rule requires, so Gate A (canon-spine lockstep) has failed on every PR that wakes it since. Editorial register entry, no criteria-set change: PATCH. Closes #1094 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
The calibration commit 1cc72cd is PR #1034's pre-squash head. It lives only under refs/pull/1034/head, so no clone of main contains it and Self Test has been red on main since #1073. Fetch it by full SHA when absent, with no --depth, since that would make a complete clone shallow. Keep the fail-closed assertion when the fetch fails. Closes #1099 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
b130c85 to
6192c92
Compare
Picks up #1088 (main back to green) and the merged #936/#939/#942 fixes so this PR's checks run against the current base. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QFphKkDVB9pUDSCD4bkz65
…ult" (PROVISIONAL; adopts nothing) (#1111) **Supersedes #1083.** The content is identical, rebuilt on current `main` with every commit signed. ## Why a replacement #1083 could not merge, for two reasons: - **Unsigned commits.** Two commits pushed by `coderabbitai[bot]` (`ae0a5522`, `045a2227`) were unsigned. `required_signatures` checks every commit on the head, so the squash was blocked (see `docs/SIGNING-POLICY.adoc` § *Squash signs the result, not the PR branch*, #1098). - **Conflicts.** The only conflicts were in `045a2227`'s `REGISTRY.a2ml` and `docstring-scan-test.sh` edits. That work is now on main from #1088, so the commit is **dropped**. The branch is `origin/main`, then `cherry-pick -S -x` of `af3f614a`, `81275794`, `ae0a5522`. Authors are kept. `git diff <#1083 head> HEAD -- 0-canon/RSR-PHILOSOPHY.adoc docs/decisions/` is empty. `scripts/build-registry.sh --check`: in sync. ## What Opens `CHANGE-PROCEDURE.adoc` **step 1** for _Elegance by default_, **retroactively**, as `docs/decisions/ADR-007-elegance-by-default.adoc`. - `0-canon/RSR-PHILOSOPHY.adoc`: the Elegance banner gains a *Proposal record* pointer. Its PROVISIONAL status is unchanged. - `docs/decisions/ADR-006-always-leave-it-working.adoc`: records that step 6's `Immutable-Tags` precondition is **met**. The repair was made 2026-09-23 and re-verified 2026-09-30 (`current_user_can_bypass = always` on all four repos), and `launch-scaffolder` has cut `v0.1.0`. ## Why `KNOWN-TENSIONS.adoc` records a high-severity `contradiction`: rule 15 is projected into every generated `CLAUDE.md` while the canon marks it PROVISIONAL. The owner chose the *ratify* exit (D209, #787). ## What merging does, and does not do Merging **adopts nothing**. It records the proposal only (steps 1–2). Steps 3–6 stay owed: review, contest period, recorded decision, regeneration. The KNOWN-TENSIONS row stays open until step 5. **Step-3 note:** ADR-007 step 3 says authorised review by the constitutional authority is required before this proposal record merges. The owner (the constitutional authority) instructed on 2026-10-01 that this PR be landed. That instruction is recorded here as that review. ## Review threads carried over from #1083 All three CodeRabbit threads are answered by the text in this branch: - ADR-006 "date the Immutable-Tags blocker as pre-repair": ADR-006 l.166 ("*The `Immutable-Tags` blocker is resolved.* Before the repair, …"). - ADR-007 "keep step 6 regeneration proof in scope": ADR-007 l.141–142 and the step 6 row (regenerate, validate, prove determinism "even if output is unchanged, regardless of manifesto pin changes"). - ADR-007 "do not merge before authorised review": the step 3 row, and the step-3 note above. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01DAKujx2PXHcVSA7vncTNH1 --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com>
…isioning modes (#1112) **Supersedes #1096.** The content is identical, rebuilt on current `main` as one signed commit. ## Why a replacement - **Unsigned commits.** Two docstring commits pushed by `coderabbitai[bot]` (`71cad01f`, `18dcefa2`) were unsigned. `required_signatures` refuses a PR that has any unsigned commit on its head, even under squash (`docs/SIGNING-POLICY.adoc` § *Squash signs the result, not the PR branch*). Their content (docstrings, now 74/74 covered) is kept. - **Rebuild.** `git merge --squash origin/feat/provisioning-canon` onto `origin/main`, then `git commit -S`. `git diff 18dcefa HEAD` shows only main's later #1087/#1098 files plus the delta below. The original commit list is in the commit message. ## Delta vs #1096: Hypatia `eval_in_shell` false positives #1096's `Hypatia` code-scanning check and `governance / Validate Hypatia Baseline` were red on 4 `content_patterns/eval_in_shell` findings (`provision-check.sh:23`, `provision-lib.sh:867,868,944`). The rule is a bare `\beval\b`, and every hit is the **word**: the `eval` verb name, or the `.eval/` directory. None is the shell builtin. The fix is an inline `# hypatia:ignore eval_in_shell -- <reason>` pragma on each line, not baseline entries: - `HYPATIA-BASELINE-FORMAT.adoc` lists "single new findings on freshly-introduced code" as a bad baseline entry, and the baseline is a ratcheted exemption ledger. - These files are templates minted into other repos. The pragma travels with them; a standards-only baseline entry would not. - 3 comment lines that newer hypatia (`4065424`) also flags are pragma'd too, so a scanner bump does not turn this red again. **Control:** local `hypatia@4065424 scan` over the two files reports **7** `eval_in_shell` findings on #1096's version and **0** on this branch. `bash -n` is clean for both scripts. Upstream rule precision is tracked upstream in hyperpolymath/hypatia#892 (`eval_in_shell` matches the word, not the builtin in command position). CodeRabbit's last `CHANGES_REQUESTED` (the `launcher.sh.tmpl` header saying modes delegate to the Justfile) is already addressed in this content: l.25–29 say provisioning modes call `build/just/provision-lib.sh` directly. --- ## Original description (#1096) ## What Phase 1 of the estate provisioning campaign. This PR is the canon every repository will be minted from, so that nobody who clones a repo has to search for how to install, configure, run, test, bench, diagnose or repair it. **New: `3-practice/provisioning/`** - `PROVISIONING-STANDARD.adoc` (v1.0.0) and `provisioning-standard_praxis.deed` (lints OK) - **Engine**, identical estate-wide: - `provision.just`: the `provision::` module with every verb - `provision-lib.sh`: bash only, shellcheck clean - `provision-modes.sh`: the launcher dispatch - `provision-check.sh`: the offline conformance checker, covering §8 items 1–5 - **Minted templates:** - `launcher.sh.tmpl` - `mise.toml` (latest plus `mise.lock`) - Guix: a `cargo-build-system` package for Rust, a `copy-build-system` source package for everything else, plus `manifest.scm` and a pinned `channels.scm` - `docs/SETUP.adoc`, the manual route, with a doctor-code troubleshooting table - `docs/AI_INSTALLATION_GUIDE.adoc` - `llm-warmup-{user,dev,maintainer}.adoc` - the README `[[ai-install]]` "Just say it" fragment (the neurophone pattern) - the per-repo `provisioning_praxis.deed` **Launcher standard 0.6.0** (`launcher-standard.adoc` and `launcher-standard_praxis.deed`) - Every repository carries a `launcher.sh`, profiled by archetype. Only `app` has runtime modes; the others print N/A and exit 0. - `--setup`, `--doctor`, `--heal` and `--ai-setup` call the engine directly (`build/just/provision-lib.sh`), so a repo's own root `doctor`/`setup`/`heal` recipe cannot shadow the canon. - Repo-specific checks live in the `doctor-local`, `setup-local` and `heal-local` recipes. A failing `doctor-local` is FAIL PV-E50. **`guix.scm`:** the licence field was a malformed ad-hoc licence object pointing at palimpsest-license. It is now `mpl2.0` from `(guix licenses)`, which is the licence the file's own SPDX header already declares. No licence changes. ## Verified - `deed_lint.py`: - OK on `launcher-standard_praxis.deed` and `provisioning-standard_praxis.deed` - OK on a filled instance of the per-repo deed template - Shellcheck is clean on the engine scripts. - `provision-check.sh` fixture: - The positive control gives rc=0. - 9 mutants each fail on exactly their own check: launcher not executable, root verb missing, module verb missing, banned `python`, banned `aqua:denoland/deno`, no `mise.lock`, guix stub, mechanical slot residue, README SPEC residue. - `--dev` downgrades SPEC residue to a WARN. - doctor-local, in a scratch repo: - A failing `doctor-local` gives PV-E50 and rc=1 via both `./launcher.sh --doctor` and `just doctor`. - A root `doctor` that prints fake green is not executed by `--doctor`. - just floor 1.42.0, measured: a root recipe depending on a module recipe fails on 1.31, 1.36, 1.40 and 1.41. - Guix, via `podman` with `metacall/guix` at ae77aeb: the Rust source package derivation builds (`guix build -d`, rc=0). The non-Rust derivation and the real build were still running when this PR was opened. ## Known, not introduced here - The standards-map gate (Gate D) is already red on `main`, with 5 unmapped top-level entries: `arena-session-787`, `patches`, `ULTRAPLAN-2026-09-24.adoc`, `ULTRAPLAN-2026-09-29.adoc` and `ziz-drop`. This PR adds no top-level entry, because `3-practice` is already mapped. - Dogfooding `mod provision` in this repo's own Justfile is deferred to the pilot phase. ## Update: review round (head b234caf) **Commits since opening** - **206eb6c4 — one placement resolver.** - Each Guix template resolves the repository root from its own location, so a repo can keep the files at the root or under `build/`. This resolves the CodeRabbit placement thread. - Zig is detected up to 3 directories down. - **39b790f5 — no faked zig/bun tests.** - A language with no test command prints an honest N/A. - There is now one AI-install sentence, read from the README by `ai-setup`. - **eaf3a894 — new `fmt-check` verb, the check-only twin of `fmt`.** - Per language: `cargo fmt --check`, `zig fmt --check`, `mix format --check-formatted`, `gleam format --check`, `dune build @fmt`, and bun's `fmt-check` script. - `quality` now depends on this verb. Before, it silently ran `lint`. - **b234caf5 — the remaining review findings.** - `doctor-local.sh` now runs sourced in a subshell. An `exit` or a tripped `set -e` is FAIL **PV-E51**, and the checks it completed still count. - `hp_provision_or_return` replaces `&& exit $?`, which reported success for a failing mode. - The `ai-warmup` argument is now quoted. - trivy is pinned in mise only where a recipe calls it. - The launcher currency constant is now 0.5.0 (0.6.0 after 094fd79, below). - **7e6f3db6 — `toolchain-refresh` regenerates `build/guix/crates.scm`.** - `guix.scm.cargo.tmpl` already promised this, but nothing implemented it. The new lib verb `crates-scm` runs `guix import crate --lockfile`. `GUIX` may name a container wrapper. - The file is written whole or not at all. Output is accepted only when it defines one origin per registry crate in `Cargo.lock`, because a containerised guix loses its exit status. Otherwise the run fails with the new code **PV-E41** and the old file stays. PV-E41 is in the deed, the lib and the SETUP table: all three hold the same 28 codes. - Measured on launch-scaffolder's `Cargo.lock`: - 151/151 origins; - `guix repl` gives `(length %crate-inputs)` = 151 and `origin?` = `#t`; - regeneration is byte-identical. - Mutants killed: - truncated importer output (10/151): rc 1, PV-E41, file sha256 unchanged; - a failing importer (0/151): rc 1, PV-E41, file sha256 unchanged. - **094fd798 — merge `main`; the provisioning modes are launcher standard 0.6.0.** - `main` took 0.5.0 for the `(js-runtime)` clause (D224, #1100). That number is published with that meaning, so the archetype and provisioning obligations move to **0.6.0** (2026-10-01). Updated together: the deed, the `.adoc`, the currency gate's `CURRENT_VERSION`, the launcher template and `provision-modes.sh`. - A consumer still citing 0.5.0 gets the non-blocking stale-version warning (standards#991), not a failure. - Checks: - currency test 19/19; - the gate on this tree: clean at v0.6.0; - `--self-test`: 4 mutants seeded, all detected. **Measured on rsr-template-repo (the first consumer; that PR follows)** - doctor-hook cases: | hook | PASS / WARN / FAIL | |---|---| | normal | 19 / 1 / 0 | | `exit 3` | 19 / 0 / 1 + PV-E51 | | `set -e; false` | 19 / 0 / 1 + PV-E51 | | `fail` | 18 / 0 / 1 | - `./launcher.sh --doctor`: rc 0 when clean, rc 1 with a failing hook. - `just doctor` 18/0/0, `just validate` pass, `provision-check --dev` 0 FAIL / 0 WARN, shellcheck clean. - `fmt-check`: rc 0 on clean code; a mis-formatted mutant gives rc 1. - Guix, via `metacall/guix` at ae77aeb: - `guix build -f guix.scm`: rc 0. - `guix shell -m manifest.scm --dry-run`: rc 0. - `channels.scm` evaluates to the same pinned commit. - `just registry-check` OK. `check-launcher-standard-currency` OK. **Red checks: none is a required check. Classified:** - **Canon/spine lockstep and Map integrity** are already red on `main`: the constitution hash, dogfood-gate, and the ULTRAPLAN / arena-session-787 / patches / ziz-drop entries. #1088 fixes them. - **Repo self-tests:** - This PR's `CURRENT_VERSION` drift is fixed in b234caf. - The docstring shallow-clone failure is also red on `main`. - **Hypatia:** 6 `eval_in_shell` findings are false positives on the `eval` *verb name*: a comment, the `.eval/` report directory, a `case` label, and the verb list. Nothing here calls the builtin. - **Deferred red checks, by context:** `governance / Validate Hypatia Baseline`, `scan / Hypatia Neurosymbolic Analysis` and `Hypatia` → hyperpolymath/hypatia#892. On 094fd79 the baseline gate kept exactly six findings: `eval_in_shell` at `provision-check.sh:23` and `provision-lib.sh:17,732,733,742,804`, all the *word* `eval`. The same three checks are green on `main` 8cfad82. Renaming the user-facing `eval` verb to satisfy the scanner would be the wrong arm. - Fixed at source in hyperpolymath/hypatia#892, with acceptance criteria and positive and negative controls. - Per the owner ruling, this is tracked as an issue, not a blocker. - The 3 `uuid-v7.yml` baseline findings are fixed by #1088. - #1088 also touches `REGISTRY.a2ml`. If it merges first, regenerate the registry here. **Placement labels (elegance arm)** - The engine is **vendored byte-identical** into each repo, and `provision-set --check` will prove it is equal to canon. **This is the elegant long-term arm.** - Departure considered and rejected: fetching the engine at run time. That would break offline and Guix-hermetic use and add a supply-chain hop. - **`channels.scm` is minted, not engine** (departure, labelled). `toolchain-refresh` re-pins it per repo by design, so a byte-compare would go red after every weekly refresh. Instead it is checked for a 40-hex commit pin. ## Update: one banned list, backends and bare names (heads b01a245, bf7c97a) Found by the 8-repo pilot (launch-scaffolder#67). - **b01a245:** - The deed's `:banned-tools` and the engine's `BANNED_TOOLS` had diverged. They are now one 20-item list, plus a new `:banned-backends ("npm" "pipx" "pip" "go")`. launch-scaffolder tests that the deed and the engine agree. - PV-W23 now reads `mise.toml`, `.mise.toml` and `.tool-versions`. - A tool behind a banned backend is flagged whatever its name (`npm:prettier`). - Controls: `.tool-versions` python + `.mise.toml` `"npm:prettier"` → `[python npm:prettier] rc=1`; clean → `[] rc=0`. - **bf7c97a:** a bare name whose only registry backends are banned is flagged too. `prettier` resolves only to `npm:prettier`. - The lookup uses `mise registry`, which works offline. - Shells with no mise and names mise doesn't know are never flagged on a guess. - Controls: `prettier` → `[prettier] rc=1`; `shfmt`/`zig`/an unknown `jest` → `[] rc=0`. - shellcheck is clean, and docstring coverage is 100%. - Pilot gaps that are canon work but not fixed here are filed as #1107. ## Next - the rsr-template-repo canon fix - the `provision-set` generator and the `provisioning-check.yml` gate - a pilot of about 8 repos, then fan-out in SET batches 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_01DAKujx2PXHcVSA7vncTNH1 Co-authored-by: coderabbitai[bot] <136622811+coderabbitai[bot]@users.noreply.github.com> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
Restores
standardsmain to green. The reds on main and on this PR hold each other in a cycle, so every cure is in this one PR: under the fully-green rule, no smaller PR can pass CI alone.What each commit fixes
Lock-gate staging pin bump. The
ref:under "Checkout standards for the lock gate" ingovernance-reusable.ymlmoves to5f82b635.scripts/check-lock-gate-pin-freshness.shreturns rc=1 on main and rc=0 on this branch. Each tree's own copy of the script was run; running one tree's copy against another tree reads the wrong workflow and passes vacuously.Registry
source_hashregeneration (main red: REGISTRY source_hash drift after #1072/#1075 reds Registry Verify and Repo self-tests (and skips the lock-gate pin guard) #1092). fix(scripts): replace hardcoded /tmp paths with mktemp (#936) #1072 and fix(scripts): remove eval from rsr-audit and fill-placeholders test (#939) #1075 changed files under the RSR spec home without regenerating.machine_readable/REGISTRY.a2ml, sobuild-registry.sh --checkfails. That failure reds Self-tests, and the pin guard step never runs because it comes after the failing suite. The change is one regenerated hash line. Under D231 it is a regeneration only; migrating off the generated file is a later piece of work.uuid-v7.ymlhardening. It addstimeout-minutes: 10, aconcurrencygroup, and apushtrigger bounded tomain. These are the three unfiltered Hypatia Baseline findings on main: missing_timeout_minutes, d_burn_double_trigger, and WH006.Delete the five unmapped root entries (D241, cherry-picked and signed from chore: delete the five unmapped root entries #1097). This cures the map-integrity red that woke on this PR.
Canon PATCH 2.1.1 → 2.1.2. docs(canon): open CHANGE-PROCEDURE step 1 for "Always leave it working" (PROVISIONAL — merging opens the proposal, does not adopt it) #1041 added a KNOWN-TENSIONS row under
0-canon/constitution/without the same-commit bump and sha256 rewrite thatcanon.lockrequires. Gate A is path-filtered, so main never ran it and the drift stayed invisible until this PR woke the gate. This commit bumps the version, sets released to 2026-09-30 and the tag tocanon-v2.1.2, rewrites the constitution hash tobe48496f…, and adds a header note. The spine's dogfood red was a stale hypatia compile error, fixed upstream at 9d2e6de3. Re-running rsr-template-repo run 36475038466 turned it green.Fetch the docstring calibration commit by SHA (docstring-scan-test calibration commit is a pre-squash PR head, unreachable from main: Self Test red since #1073 #1099). feat(githooks): canonical docstring scanner with a known-answer suite #1073's
docstring-scan-test.shcalibrates against1cc72cdc80c9, PR feat(rulesets): base protection floor applier, branch + tag #1034's pre-squash head, which no clone of main can contain. Self Test on main (run 36741131926) failed on this as well as the stale registry. I read only the first failure, so my earlier claim that this PR cured every main red was wrong. The test now fetches the commit by full SHA on a miss, without--depth(which would make a complete clone shallow), and still fails closed if the fetch fails. The branch was rebased onto main 74d2f66 (signed) so the test file is present.Closes #1092
Closes #1094
Closes #1095
Closes #1099
Local verification on 6192c92 (rebased on main 74d2f66)
bash scripts/run-shell-test-suite.shcheck-lock-gate-pin-freshness.sh origin/mainbuild-registry.sh --checkcheck-canon-lockstep.sh --spine rsr-template-repo@8256a6e --base origin/maincheck-standards-map.shKNOWN-TENSIONS.adoc,canon.lockuntouchedconstitution#1097 is superseded by commit 4. This PR lands under the fully-green rule only when every check is green.
🤖 Generated with Claude Code
https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57