Skip to content

CEG-263-001/002: Gate_SDK pin policy decision required (immutable SHA vs moving @v1), lock incoherent until then #266

Description

@cryptoxdog

Audit ceg-open-prs-2026-09-17, findings CEG-263-001 (INVARIANT, High) and CEG-263-002 (COMPLETENESS, High). Owner class HUMAN; semantic owner CEG constellation dependency policy. Filed because this needs an architecture decision no agent may take — the audit's own authority resolution says PR intent does not supersede repository law.

The decision

PR #263 replaces the immutable Gate_SDK pin with a moving major tag:

-constellation-node-sdk = {git = "...Gate_SDK.git", rev = "69c6c67060b08440734a61473c03663423709964"}
+constellation-node-sdk = {git = "...Gate_SDK.git", rev = "v1"}

Current repository law requires immutable SHA constellation pins, and the enforcement script rejects the change on #263's head 29bc0a2:

$ python scripts/validate_sdk_pin.py
FAIL
pyproject.toml: missing pin
requirements.txt: missing pin
exit 1

PRESERVE-IMMUTABLE-SDK-IDENTITY is VIOLATED: CEG source revisions must deterministically identify the Gate SDK revision they were reviewed and tested with.

Why the tag is not equivalent to the pin

refs/tags/v1 does not point at the reviewed revision, and moves on each release:

$ git ls-remote https://github.com/Quantum-L9/Gate_SDK.git 'refs/tags/v1*'
e9f829f982110be13752da8f18c7a9692e8ed908  refs/tags/v1
e9f829f982110be13752da8f18c7a9692e8ed908  refs/tags/v1.1.0
a770e8531dc1c59ce01e1dbb0f4162785d9dda89  refs/tags/v1.0.1^{}

v1 currently resolves to the same object as v1.1.0, not to the reviewed 69c6c67. Adopting it silently moves the SDK off the revision the code was tested against, and will move again at the next minor release.

Two ways to resolve — both need you

  1. Keep immutable pins. Restore a single immutable commit identity across pyproject.toml, requirements.txt, poetry.lock and validate_sdk_pin.py. chore: pin constellation-node-sdk to @v1 (moving major tag) #263 closes or is reworked.
  2. Adopt moving-major policy. Land an explicit architecture decision that supersedes the immutable-pin law, and update the governing law plus validate_sdk_pin.py in a separately authorized change before this consumer PR implements it.

CEG-263-002 is blocked behind that choice

#263 changed only the two human-edited manifests and left the resolved lock untouched. On head 29bc0a2:

$ poetry check --lock
Error: pyproject.toml changed significantly since poetry.lock was last generated.
exit 1

poetry.lock still records reference/resolved_reference = 69c6c67… while pyproject.toml says rev = "v1". Which identity to lock to is the question above, so regenerating the lock now would silently decide the policy. Its second closing validation, docker compose -f docker-compose.prod.yml build api, is equally premature.

Once you pick a direction, CEG-263-002 is mechanical and I can do it: synchronize poetry.lock to the chosen identity and prove the production image builds from the repaired head.

Evidence: E006, E013, E014, E015, E016, E017, E018, E026. Authorities: AUTH-IMMUTABLE-CONSTELLATION, AUTH-PROD-DEPENDENCY-COHERENCE, AUTH-USER-SCOPE.

Related: #263.


Generated by Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions