From 433171331f6ed2a12a3c8a6093cf63af199e2d34 Mon Sep 17 00:00:00 2001 From: Monsky Date: Wed, 19 Aug 2026 18:39:48 -0400 Subject: [PATCH 1/3] docs: authorize CK-07R1 clean committed transition --- docs/INDEX.md | 12 + ...nal-failure-clean-commit-authority-v1.json | 137 ++++++++++ ...lure-clean-commit-authority-v1.schema.json | 176 +++++++++++++ docs/roadmap/REMAINING_EXECUTION_PLAN.md | 8 + docs/roadmap/TASK_PACKETS.md | 2 +- ...7r1-correct-lifecycle-preparation-scale.md | 8 +- scripts/check_kernel_scope.py | 8 + scripts/ck07r1_terminal_failure_correction.py | 236 +++++++++++++++++- .../test_ck07r1_shared_successor_overlay.py | 32 ++- ...1_terminal_failure_correction_authority.py | 233 +++++++++++++++-- tests/kernel/test_documentation_authority.py | 23 ++ tests/kernel/test_kernel_scope.py | 9 + 12 files changed, 840 insertions(+), 44 deletions(-) create mode 100644 docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json create mode 100644 docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json diff --git a/docs/INDEX.md b/docs/INDEX.md index 04a53488..4e1c63a1 100644 --- a/docs/INDEX.md +++ b/docs/INDEX.md @@ -199,6 +199,18 @@ readiness. A corrected implementation may be reviewed and prequalified only through deterministic synthetic non-consuming evidence; the existing receipt-required runtime acceptance gate remains unsatisfied and CK-07R1, CK-08R4, CK-08RG, and CK-09 remain blocked pending a separate roadmap decision. +The additive versioned +[`lifecycle-terminal-failure-clean-commit-authority-v1`](decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json) +preserves the terminal-failure v1 authority byte-for-byte and binds PR #448 +base `652f2166…`, source head `927aa06f…`, and its exact seven candidate and +terminal-evidence paths. It admits either the exact all-or-none dirty +prepublication representation over the byte-identical authority-main tree or +the exact clean committed PR/integrated representation. Mixed, partial, extra, +wrong-base, wrong-tree, wrong-head, or wrong-byte states fail closed. This +clean-committed transition representation bridge grants no implementation or +runtime acceptance and +does not authorize a command, launch, token refund, retry, restart, +replacement, receipt, or downstream transition. The V11 candidate must construct and validate the exact overlay/cohort-bound receipt and non-null stdout/stderr/output evidence before its first durable diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json b/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json new file mode 100644 index 00000000..76be2edc --- /dev/null +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json @@ -0,0 +1,137 @@ +{ + "schema": "codex-usage-tracker.ck07r1-lifecycle-terminal-failure-clean-commit-authority.v1", + "version": 1, + "task": "CK-07R1", + "status": "permitted_not_accepted", + "authority_base_sha": "652f2166b58b9ee0d719348a769901577d11e6fd", + "authority_base_tree_sha": "cc148aa820962c084655017e404cce54430313bd", + "source_authority": [ + { + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.json", + "sha256": "7752565abd5c5f27a852b8a8814ea1b7afde03d967de46419856eae85583f97b" + }, + { + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.schema.json", + "sha256": "f4affab070de6aa1ed54cfc648051b7b6398bd57011fed8d942309894714744e" + } + ], + "implementation_transition": { + "pull_request": 448, + "base_sha": "652f2166b58b9ee0d719348a769901577d11e6fd", + "head_sha": "927aa06f7c4c88319cc30247343c40db8e9b817e", + "paths": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "role": "unchanged_preparation_source", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "role": "corrected_planner_path_benchmark", + "sha256": "8f4900b1ecc841fe04f6cd1232c3741efef105e8b997c7fd15cc61b5d8d14cc1" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "role": "corrected_planner_path_tests", + "sha256": "8364c4387b8e588cb18f420805d47e48241da22d6fb793e838a522cc7fb29e33" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v1.launch-token.json", + "role": "immutable_v1_terminal_ledger", + "sha256": "5c2b42eca6a3e54cf4163226bc55f3c75aa35112c4ed0342c11f4e39cb9922be" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.launch-token.json", + "role": "immutable_v2_terminal_ledger", + "sha256": "570e27824ee04a51aa4012adb461bd4aebb00b61541f2477fd9e1665854325a2" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.stderr.txt", + "role": "immutable_v2_terminal_stderr", + "sha256": "4cf4b10fd04f20a190e4ac41898d25b9295b3dc9d7addead8a81edd27b3aca2f" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.stdout.txt", + "role": "immutable_v2_terminal_stdout", + "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + } + ], + "representations": { + "dirty_prepublication": { + "head_tree": "authority_base_tree", + "worktree_delta": "exact_candidate_scope", + "committed_delta": "none" + }, + "clean_pr_head": { + "head": "exact_bound_implementation_head", + "worktree_delta": "empty", + "committed_delta": "exact_candidate_scope" + }, + "clean_integrated": { + "base": "exact_authority_base", + "worktree_delta": "empty", + "committed_delta": "exact_authority_scope_plus_candidate_scope", + "source_identity": "bound_pr_head_or_exact_tree_equivalent_squash" + } + } + }, + "decision": { + "root_cause": "clean_committed_ci_representation_was_not_modeled", + "dirty_prepublication_remains_valid": true, + "clean_committed_transition_permitted": true, + "implementation_acceptance": "not_claimed", + "runtime_acceptance": "not_claimed", + "new_command_invocations_permitted": 0, + "launch_authorized": false, + "token_consumed": true, + "token_refund": false, + "retry": "none", + "restart": "none", + "replacement": "none", + "receipt_fabrication": "forbidden", + "post_single_run": "unavailable_without_complete_planner_valid_receipt", + "final_accepted": "unavailable" + }, + "scope": { + "authority_write_scope": [ + "docs/INDEX.md", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json", + "docs/roadmap/REMAINING_EXECUTION_PLAN.md", + "docs/roadmap/TASK_PACKETS.md", + "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md", + "scripts/check_kernel_scope.py", + "scripts/ck07r1_terminal_failure_correction.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck07r1_terminal_failure_correction_authority.py", + "tests/kernel/test_documentation_authority.py", + "tests/kernel/test_kernel_scope.py" + ], + "candidate_scope": [ + "output/ck07r1/lifecycle-requalification-v1.launch-token.json", + "output/ck07r1/lifecycle-requalification-v2.launch-token.json", + "output/ck07r1/lifecycle-requalification-v2.stderr.txt", + "output/ck07r1/lifecycle-requalification-v2.stdout.txt", + "scripts/benchmark_ck07r1_lifecycle_scale.py", + "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "tests/agent_kernel/publication/test_lifecycle_scale.py" + ], + "forbidden": [ + "mixed_partial_or_extra_candidate_delta", + "wrong_authority_base_or_tree", + "wrong_implementation_head_or_candidate_bytes", + "v1_authority_rewrite", + "terminal_evidence_mutation", + "qualification_command_invocation", + "child_or_fork", + "token_refund_or_new_invocation", + "retry_restart_or_replacement", + "receipt_fabrication", + "implementation_files_in_authority_pr", + "PR_394_mutation", + "live_or_real_data", + "downstream_dispatch", + "cleanup_or_witness_loss" + ] + } +} diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json b/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json new file mode 100644 index 00000000..517cd9ff --- /dev/null +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json @@ -0,0 +1,176 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://local.codex/schemas/ck07r1-lifecycle-terminal-failure-clean-commit-authority-v1.json", + "title": "CK-07R1 lifecycle terminal failure clean committed transition authority v1", + "type": "object", + "additionalProperties": false, + "required": [ + "schema", + "version", + "task", + "status", + "authority_base_sha", + "authority_base_tree_sha", + "source_authority", + "implementation_transition", + "decision", + "scope" + ], + "properties": { + "schema": { + "const": "codex-usage-tracker.ck07r1-lifecycle-terminal-failure-clean-commit-authority.v1" + }, + "version": { + "const": 1 + }, + "task": { + "const": "CK-07R1" + }, + "status": { + "const": "permitted_not_accepted" + }, + "authority_base_sha": { + "const": "652f2166b58b9ee0d719348a769901577d11e6fd" + }, + "authority_base_tree_sha": { + "const": "cc148aa820962c084655017e404cce54430313bd" + }, + "source_authority": { + "const": [ + { + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.json", + "sha256": "7752565abd5c5f27a852b8a8814ea1b7afde03d967de46419856eae85583f97b" + }, + { + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.schema.json", + "sha256": "f4affab070de6aa1ed54cfc648051b7b6398bd57011fed8d942309894714744e" + } + ] + }, + "implementation_transition": { + "const": { + "pull_request": 448, + "base_sha": "652f2166b58b9ee0d719348a769901577d11e6fd", + "head_sha": "927aa06f7c4c88319cc30247343c40db8e9b817e", + "paths": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "role": "unchanged_preparation_source", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "role": "corrected_planner_path_benchmark", + "sha256": "8f4900b1ecc841fe04f6cd1232c3741efef105e8b997c7fd15cc61b5d8d14cc1" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "role": "corrected_planner_path_tests", + "sha256": "8364c4387b8e588cb18f420805d47e48241da22d6fb793e838a522cc7fb29e33" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v1.launch-token.json", + "role": "immutable_v1_terminal_ledger", + "sha256": "5c2b42eca6a3e54cf4163226bc55f3c75aa35112c4ed0342c11f4e39cb9922be" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.launch-token.json", + "role": "immutable_v2_terminal_ledger", + "sha256": "570e27824ee04a51aa4012adb461bd4aebb00b61541f2477fd9e1665854325a2" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.stderr.txt", + "role": "immutable_v2_terminal_stderr", + "sha256": "4cf4b10fd04f20a190e4ac41898d25b9295b3dc9d7addead8a81edd27b3aca2f" + }, + { + "path": "output/ck07r1/lifecycle-requalification-v2.stdout.txt", + "role": "immutable_v2_terminal_stdout", + "sha256": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" + } + ], + "representations": { + "dirty_prepublication": { + "head_tree": "authority_base_tree", + "worktree_delta": "exact_candidate_scope", + "committed_delta": "none" + }, + "clean_pr_head": { + "head": "exact_bound_implementation_head", + "worktree_delta": "empty", + "committed_delta": "exact_candidate_scope" + }, + "clean_integrated": { + "base": "exact_authority_base", + "worktree_delta": "empty", + "committed_delta": "exact_authority_scope_plus_candidate_scope", + "source_identity": "bound_pr_head_or_exact_tree_equivalent_squash" + } + } + } + }, + "decision": { + "const": { + "root_cause": "clean_committed_ci_representation_was_not_modeled", + "dirty_prepublication_remains_valid": true, + "clean_committed_transition_permitted": true, + "implementation_acceptance": "not_claimed", + "runtime_acceptance": "not_claimed", + "new_command_invocations_permitted": 0, + "launch_authorized": false, + "token_consumed": true, + "token_refund": false, + "retry": "none", + "restart": "none", + "replacement": "none", + "receipt_fabrication": "forbidden", + "post_single_run": "unavailable_without_complete_planner_valid_receipt", + "final_accepted": "unavailable" + } + }, + "scope": { + "const": { + "authority_write_scope": [ + "docs/INDEX.md", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json", + "docs/roadmap/REMAINING_EXECUTION_PLAN.md", + "docs/roadmap/TASK_PACKETS.md", + "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md", + "scripts/check_kernel_scope.py", + "scripts/ck07r1_terminal_failure_correction.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck07r1_terminal_failure_correction_authority.py", + "tests/kernel/test_documentation_authority.py", + "tests/kernel/test_kernel_scope.py" + ], + "candidate_scope": [ + "output/ck07r1/lifecycle-requalification-v1.launch-token.json", + "output/ck07r1/lifecycle-requalification-v2.launch-token.json", + "output/ck07r1/lifecycle-requalification-v2.stderr.txt", + "output/ck07r1/lifecycle-requalification-v2.stdout.txt", + "scripts/benchmark_ck07r1_lifecycle_scale.py", + "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "tests/agent_kernel/publication/test_lifecycle_scale.py" + ], + "forbidden": [ + "mixed_partial_or_extra_candidate_delta", + "wrong_authority_base_or_tree", + "wrong_implementation_head_or_candidate_bytes", + "v1_authority_rewrite", + "terminal_evidence_mutation", + "qualification_command_invocation", + "child_or_fork", + "token_refund_or_new_invocation", + "retry_restart_or_replacement", + "receipt_fabrication", + "implementation_files_in_authority_pr", + "PR_394_mutation", + "live_or_real_data", + "downstream_dispatch", + "cleanup_or_witness_loss" + ] + } + } + } +} diff --git a/docs/roadmap/REMAINING_EXECUTION_PLAN.md b/docs/roadmap/REMAINING_EXECUTION_PLAN.md index 0e2fc169..054f8229 100644 --- a/docs/roadmap/REMAINING_EXECUTION_PLAN.md +++ b/docs/roadmap/REMAINING_EXECUTION_PLAN.md @@ -206,6 +206,14 @@ the token, authorize any launch, fabricate a receipt, or make corrective implementation prequalification because the existing receipt-required runtime acceptance contract remains unsatisfied; CK-08R4, CK-08RG, and CK-09 remain blocked pending an explicit future roadmap decision. +The linked +[clean-committed transition authority](../decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json) +keeps the v1 authority immutable while binding PR #448 base `652f2166…`, +source head `927aa06f…`, and the exact seven-path cohort. The same bytes may be +represented only as an all-or-none dirty prepublication delta over the exact +authority-main tree or as a clean committed PR/integrated delta with exact +base, scope, and hashes. Neither representation reopens the consumed run or +changes the existing blocked state. The exact V11 launcher contract constructs and validates the fully overlay/cohort-bound receipt and non-null stdout/stderr/output evidence before diff --git a/docs/roadmap/TASK_PACKETS.md b/docs/roadmap/TASK_PACKETS.md index 9aa8d442..c4e73180 100644 --- a/docs/roadmap/TASK_PACKETS.md +++ b/docs/roadmap/TASK_PACKETS.md @@ -69,7 +69,7 @@ locks are unchanged. - [x] **CK-08R3 — Qualify evidence service scale** · PR #425 hosted-green and squash-merged at `0fad272b`; both frozen synthetic profiles accepted and exact-main verified · [packet](tasks/ck-08r3-qualify-evidence-scale.md) - [x] **CK-07R1A — Correct hosted lifecycle tail** · Accepted/merged at `4d807495`; exact-main verified · [packet](tasks/ck-07r1a-correct-hosted-lifecycle-tail.md) - [x] **CK-07R1A0 — Freeze lifecycle planner/recovery path authority** · Path, finite source/runtime, run-invocation authority, and argv-correction authority merged through `479cbdb`; retained witnesses remain read-only · [packet](tasks/ck-07r1a0-freeze-lifecycle-path-authority.md) -- [ ] **CK-07R1 — Correct lifecycle preparation scale** · Blocked after the prelaunch-recovery-authorized sole v2 child handshake consumed the non-refundable token and terminated `failed_after_launch`; the versioned [terminal-failure correction authority](../decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.json) permits only deterministic non-consuming benchmark/test correction prequalification, never another run or receipt-based acceptance; PR #394 remains read-only · [packet](tasks/ck-07r1-correct-lifecycle-preparation-scale.md) +- [ ] **CK-07R1 — Correct lifecycle preparation scale** · Blocked after the prelaunch-recovery-authorized sole v2 child handshake consumed the non-refundable token and terminated `failed_after_launch`; the versioned [terminal-failure correction authority](../decisions/evidence/ck07r1a0/lifecycle-terminal-failure-correction-authority-v1.json) permits only deterministic non-consuming benchmark/test correction prequalification, while its [clean-committed transition bridge](../decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json) binds exact PR #448 dirty and clean representations without authorizing another run or receipt-based acceptance; PR #394 remains read-only · [packet](tasks/ck-07r1-correct-lifecycle-preparation-scale.md) - [x] **CK-QG1A — Correct page-executor complexity** · PR #408 merged/exact-main `30983d4`; authorized successor `9e80c867…` accepted without behavior or baseline change · [packet](tasks/ck-qg1a-correct-page-executor-complexity.md) - [x] **CK-QG1 — Enforce replacement-kernel maintainability** · PR #392 hosted-green, squash-merged at `68050b93`, exact-main verified, and its [v2 writer transition authority](../decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json) is linked for the reviewed PR #430 successor · [packet](tasks/ck-qg1-enforce-agent-kernel-maintainability.md) - [ ] **CK-08R4 — Reclassify physical named plans** · Blocked on CK-07R1; CK-08R1/R2/R3 are complete · [packet](tasks/ck-08r4-reclassify-physical-plans.md) diff --git a/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md b/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md index f09ad12e..56ea94dc 100644 --- a/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md +++ b/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md @@ -102,7 +102,13 @@ WAL bound. The benchmark incorrectly asserted `APPEND_SAFE_SMALL` for every chunk and therefore never exercised the selected large-artifact path. The terminal-failure correction authority permits the same worker to correct -only the benchmark and its lifecycle test. Every chunk must preserve the exact +only the benchmark and its lifecycle test. The additive +[clean-committed transition authority](../../decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json) +preserves the v1 authority bytes and binds exact PR #448 base `652f2166…`, +source head `927aa06f…`, and seven-path scope. It accepts only the exact dirty +all-or-none prepublication representation or the exact clean committed +PR/integrated representation; mixed, partial, extra, wrong-lineage, and +wrong-byte states remain forbidden. Every chunk must preserve the exact `plan_refresh` result: small plans use the pointer-coordinated short writer; large plans use the production-reachable isolated-artifact build, validation, durable promotion, recovery, rollback, and prior-readability path. Tail limits, diff --git a/scripts/check_kernel_scope.py b/scripts/check_kernel_scope.py index b2e0a6a5..f80dfb06 100644 --- a/scripts/check_kernel_scope.py +++ b/scripts/check_kernel_scope.py @@ -890,6 +890,13 @@ } ) +CK07R1_TERMINAL_CLEAN_COMMIT_AUTHORITY_ADDITIONS = frozenset( + { + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json", + } +) + CK08_PREREQUISITE_BLOCKER_ADDITIONS = frozenset( { "docs/decisions/evidence/ck08/fact-backed-oracle-prerequisite-gap.json", @@ -969,6 +976,7 @@ | CK07R1_CONSUMING_BOUNDARY_AUTHORITY_ADDITIONS | CK07R1_PRELAUNCH_RECOVERY_AUTHORITY_ADDITIONS | CK07R1_TERMINAL_FAILURE_CORRECTION_AUTHORITY_ADDITIONS + | CK07R1_TERMINAL_CLEAN_COMMIT_AUTHORITY_ADDITIONS | CK08_PREREQUISITE_BLOCKER_ADDITIONS | { "config/agent-kernel/maintainability-baseline-v1.json", diff --git a/scripts/ck07r1_terminal_failure_correction.py b/scripts/ck07r1_terminal_failure_correction.py index 3b43e059..72ee292a 100644 --- a/scripts/ck07r1_terminal_failure_correction.py +++ b/scripts/ck07r1_terminal_failure_correction.py @@ -20,6 +20,14 @@ "docs/decisions/evidence/ck07r1a0/" "lifecycle-terminal-failure-correction-authority-v1.schema.json" ) +CLEAN_COMMIT_AUTHORITY_PATH = Path( + "docs/decisions/evidence/ck07r1a0/" + "lifecycle-terminal-failure-clean-commit-authority-v1.json" +) +CLEAN_COMMIT_SCHEMA_PATH = Path( + "docs/decisions/evidence/ck07r1a0/" + "lifecycle-terminal-failure-clean-commit-authority-v1.schema.json" +) class TerminalCorrectionError(RuntimeError): @@ -57,6 +65,19 @@ def load_authority(root: Path) -> dict[str, Any]: return authority +def load_clean_commit_authority(root: Path) -> dict[str, Any]: + authority = _load_json(root / CLEAN_COMMIT_AUTHORITY_PATH) + schema = _load_json(root / CLEAN_COMMIT_SCHEMA_PATH) + try: + Draft202012Validator.check_schema(schema) + Draft202012Validator(schema).validate(authority) + except Exception as exc: + raise TerminalCorrectionError( + f"terminal clean-commit authority/schema validation failed: {exc}" + ) from exc + return authority + + def _git(root: Path, *args: str) -> str: result = subprocess.run( ("git", *args), @@ -101,6 +122,137 @@ def _status_paths(root: Path) -> set[str]: return paths +def _is_ancestor(root: Path, ancestor: str, descendant: str = "HEAD") -> bool: + result = subprocess.run( + ("git", "merge-base", "--is-ancestor", ancestor, descendant), + cwd=root, + check=False, + capture_output=True, + text=True, + ) + return result.returncode == 0 + + +def verify_clean_commit_authority_bytes( + authority: Mapping[str, Any], root: Path +) -> None: + for record in authority["source_authority"]: + path = root / record["path"] + if not path.is_file() or _sha256(path) != record["sha256"]: + raise TerminalCorrectionError( + f"clean-commit source authority byte identity mismatch: {record['path']}" + ) + + +def verify_clean_commit_authority_delta( + authority: Mapping[str, Any], + root: Path, + *, + include_committed_candidate: bool = False, + observed: set[str] | None = None, + observed_worktree: set[str] | None = None, + base_is_ancestor: bool | None = None, +) -> None: + base = str(authority["authority_base_sha"]) + if base_is_ancestor is None: + base_is_ancestor = _is_ancestor(root, base) + if not base_is_ancestor: + raise TerminalCorrectionError("clean-commit authority base is not an ancestor of HEAD") + expected = set(authority["scope"]["authority_write_scope"]) + if include_committed_candidate: + expected |= set(authority["scope"]["candidate_scope"]) + if observed is None: + head = _git(root, "rev-parse", "HEAD") + worktree = _status_paths(root) + if head == base: + actual = worktree + permitted_worktree = expected + else: + actual = { + line + for line in _git( + root, "diff", "--name-only", f"{base}..{head}", "--" + ).splitlines() + if line + } + permitted_worktree = set() + else: + actual = observed + permitted_worktree = set() + worktree = observed_worktree or set() + if worktree != permitted_worktree: + raise TerminalCorrectionError( + "clean-commit authority worktree delta must be exact: " + f"expected={sorted(permitted_worktree)} actual={sorted(worktree)}" + ) + if actual != expected: + raise TerminalCorrectionError( + "clean-commit authority Git delta must be exact: " + f"expected={sorted(expected)} actual={sorted(actual)}" + ) + + +def verify_clean_candidate_transition( + authority: Mapping[str, Any], + root: Path, + *, + observed_head: str | None = None, + observed_head_tree: str | None = None, + observed_worktree: set[str] | None = None, + observed_committed_delta: set[str] | None = None, + base_is_ancestor: bool | None = None, +) -> str: + transition = authority["implementation_transition"] + base = str(transition["base_sha"]) + bound_head = str(transition["head_sha"]) + base_tree = str(authority["authority_base_tree_sha"]) + candidate_scope = set(authority["scope"]["candidate_scope"]) + authority_scope = set(authority["scope"]["authority_write_scope"]) + head = observed_head or _git(root, "rev-parse", "HEAD") + head_tree = observed_head_tree or _git(root, "rev-parse", "HEAD^{tree}") + worktree = _status_paths(root) if observed_worktree is None else observed_worktree + + if worktree == candidate_scope: + if head_tree != base_tree: + raise TerminalCorrectionError( + "dirty prepublication head tree does not match exact authority main" + ) + return "dirty_prepublication" + if worktree: + raise TerminalCorrectionError( + "candidate Git delta must be exact and all-or-none: " + f"expected={sorted(candidate_scope)} actual={sorted(worktree)}" + ) + + if base_is_ancestor is None: + base_is_ancestor = _is_ancestor(root, base, head) + if not base_is_ancestor: + raise TerminalCorrectionError( + "clean committed candidate base is not an ancestor of HEAD" + ) + if observed_committed_delta is None: + committed_delta = { + line + for line in _git( + root, "diff", "--name-only", f"{base}..{head}", "--" + ).splitlines() + if line + } + else: + committed_delta = observed_committed_delta + if head == bound_head and committed_delta == candidate_scope: + return "clean_pr_head" + if committed_delta == authority_scope | candidate_scope: + return "clean_integrated" + raise TerminalCorrectionError( + "clean committed candidate lineage/delta must be exact: " + f"head={head} expected_head={bound_head} " + f"expected_candidate={sorted(candidate_scope)} " + f"expected_integrated={sorted(authority_scope | candidate_scope)} " + f"actual={sorted(committed_delta)}" + ) + + def verify_exact_authority_delta( authority: Mapping[str, Any], root: Path, @@ -109,6 +261,15 @@ def verify_exact_authority_delta( allowed_worktree_delta: set[str] | None = None, base_is_ancestor: bool | None = None, ) -> None: + if ( + observed is None + and allowed_worktree_delta is None + and (root / CLEAN_COMMIT_AUTHORITY_PATH).is_file() + ): + clean_commit = load_clean_commit_authority(root) + verify_clean_commit_authority_bytes(clean_commit, root) + verify_clean_commit_authority_delta(clean_commit, root) + return expected = set(authority["scope"]["authority_write_scope"]) base = str(authority["authority_base_sha"]) if base_is_ancestor is None: @@ -327,20 +488,54 @@ def verify_planner_reproduction(authority: Mapping[str, Any], root: Path) -> Non ) -def verify_combined(authority: Mapping[str, Any], root: Path) -> dict[str, Any]: - candidate_delta = set(authority["scope"]["combined_candidate_scope"]) - verify_immutable_authority_bytes(authority, root) - verify_exact_authority_delta( - authority, - root, - allowed_worktree_delta=candidate_delta, - ) - verify_exact_candidate_delta(authority, root) +def verify_combined( + authority: Mapping[str, Any], + root: Path, + *, + authority_root: Path | None = None, +) -> dict[str, Any]: + clean_commit_root = authority_root or root + clean_commit_path = clean_commit_root / CLEAN_COMMIT_AUTHORITY_PATH + if clean_commit_path.is_file(): + clean_commit = load_clean_commit_authority(clean_commit_root) + verify_clean_commit_authority_bytes(clean_commit, clean_commit_root) + same_root = clean_commit_root == root + if same_root: + representation = verify_clean_candidate_transition(clean_commit, root) + verify_clean_commit_authority_delta( + clean_commit, + clean_commit_root, + include_committed_candidate=representation == "clean_integrated", + ) + else: + verify_clean_commit_authority_delta(clean_commit, clean_commit_root) + representation = verify_clean_candidate_transition(clean_commit, root) + expected_paths = { + record["path"]: record["sha256"] + for record in clean_commit["implementation_transition"]["paths"] + } + for path, digest in expected_paths.items(): + candidate = root / path + if not candidate.is_file() or _sha256(candidate) != digest: + raise TerminalCorrectionError( + f"clean committed candidate byte identity mismatch: {path}" + ) + else: + candidate_delta = set(authority["scope"]["combined_candidate_scope"]) + verify_immutable_authority_bytes(authority, root) + verify_exact_authority_delta( + authority, + root, + allowed_worktree_delta=candidate_delta, + ) + verify_exact_candidate_delta(authority, root) + representation = "dirty_prepublication" verify_corrected_cohort(authority, root) verify_terminal_evidence(authority, root) verify_planner_reproduction(authority, root) return { "candidate_paths": len(authority["scope"]["combined_candidate_scope"]), + "candidate_representation": representation, "new_run_permitted": False, "runtime_acceptance": "not_claimed", "token_consumed": True, @@ -357,16 +552,33 @@ def _main(argv: Sequence[str] | None = None) -> int: authority = load_authority(authority_root) verify_immutable_authority_bytes(authority, authority_root) verify_exact_authority_delta(authority, authority_root) + clean_commit = ( + load_clean_commit_authority(authority_root) + if (authority_root / CLEAN_COMMIT_AUTHORITY_PATH).is_file() + else None + ) result: dict[str, Any] = { - "authority_paths": len(authority["scope"]["authority_write_scope"]), - "authority_schema": authority["schema"], + "authority_paths": len( + clean_commit["scope"]["authority_write_scope"] + if clean_commit is not None + else authority["scope"]["authority_write_scope"] + ), + "authority_schema": ( + clean_commit["schema"] if clean_commit is not None else authority["schema"] + ), "status": authority["status"], "verification": "passed", } if args.command == "combined": if args.candidate_root is None: parser.error("--candidate-root is required for combined") - result.update(verify_combined(authority, args.candidate_root.absolute())) + result.update( + verify_combined( + authority, + args.candidate_root.absolute(), + authority_root=authority_root, + ) + ) print(json.dumps(result, sort_keys=True, separators=(",", ":"))) return 0 diff --git a/tests/kernel/test_ck07r1_shared_successor_overlay.py b/tests/kernel/test_ck07r1_shared_successor_overlay.py index 6ebc8f24..f03b4c70 100644 --- a/tests/kernel/test_ck07r1_shared_successor_overlay.py +++ b/tests/kernel/test_ck07r1_shared_successor_overlay.py @@ -37,6 +37,11 @@ from scripts.ck07r1_terminal_failure_correction import ( AUTHORITY_PATH as TERMINAL_AUTHORITY_PATH, ) +from scripts.ck07r1_terminal_failure_correction import ( + CLEAN_COMMIT_AUTHORITY_PATH, + load_clean_commit_authority, + verify_clean_candidate_transition, +) from scripts.ck07r1_terminal_failure_correction import ( load_authority as load_terminal_authority, ) @@ -493,8 +498,29 @@ def test_overlay_scope_and_launcher_contract_are_exact() -> None: verify_launcher_safety_contract(weakened) weakened = deepcopy(authority) - weakened["launcher_safety"]["interpreter_identity"]["symlink_or_resolved_equivalence"] = ( - "accepted" - ) + weakened["launcher_safety"]["interpreter_identity"][ + "symlink_or_resolved_equivalence" + ] = "accepted" with pytest.raises(SharedSuccessorOverlayError, match="safety"): verify_launcher_safety_contract(weakened) + + +def test_terminal_clean_commit_bridge_preserves_worker_prequalification_only() -> None: + assert (ROOT / CLEAN_COMMIT_AUTHORITY_PATH).is_file() + authority = load_clean_commit_authority(ROOT) + candidate = set(authority["scope"]["candidate_scope"]) + representation = verify_clean_candidate_transition( + authority, + ROOT, + observed_head=authority["implementation_transition"]["head_sha"], + observed_head_tree="candidate-tree", + observed_worktree=set(), + observed_committed_delta=candidate, + base_is_ancestor=True, + ) + assert representation == "clean_pr_head" + assert authority["status"] == "permitted_not_accepted" + assert authority["decision"]["implementation_acceptance"] == "not_claimed" + assert authority["decision"]["runtime_acceptance"] == "not_claimed" + assert authority["decision"]["new_command_invocations_permitted"] == 0 + assert authority["decision"]["token_consumed"] is True diff --git a/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py b/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py index 7c05b30e..4b69a509 100644 --- a/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py +++ b/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py @@ -12,9 +12,15 @@ import scripts.ck07r1_terminal_failure_correction as terminal_module from scripts.ck07r1_terminal_failure_correction import ( AUTHORITY_PATH, + CLEAN_COMMIT_AUTHORITY_PATH, + CLEAN_COMMIT_SCHEMA_PATH, SCHEMA_PATH, TerminalCorrectionError, load_authority, + load_clean_commit_authority, + verify_clean_candidate_transition, + verify_clean_commit_authority_bytes, + verify_clean_commit_authority_delta, verify_corrected_cohort, verify_exact_authority_delta, verify_exact_candidate_delta, @@ -29,6 +35,10 @@ def _authority() -> dict[str, Any]: return load_authority(ROOT) +def _clean_commit_authority() -> dict[str, Any]: + return load_clean_commit_authority(ROOT) + + def _write(path: Path, value: bytes) -> str: path.parent.mkdir(parents=True, exist_ok=True) path.write_bytes(value) @@ -102,6 +112,137 @@ def test_terminal_correction_schema_is_versioned_strict_and_exact() -> None: assert authority["status"] == "permitted_not_accepted" +def test_clean_commit_authority_is_versioned_strict_and_preserves_v1() -> None: + authority = _clean_commit_authority() + schema = json.loads((ROOT / CLEAN_COMMIT_SCHEMA_PATH).read_text(encoding="utf-8")) + Draft202012Validator.check_schema(schema) + Draft202012Validator(schema).validate(authority) + assert authority["schema"].endswith(".v1") + assert authority["authority_base_sha"] == ( + "652f2166b58b9ee0d719348a769901577d11e6fd" + ) + assert authority["implementation_transition"]["head_sha"] == ( + "927aa06f7c4c88319cc30247343c40db8e9b817e" + ) + assert authority["status"] == "permitted_not_accepted" + verify_clean_commit_authority_bytes(authority, ROOT) + + +def test_clean_commit_authority_delta_is_exact() -> None: + authority = _clean_commit_authority() + expected = set(authority["scope"]["authority_write_scope"]) + candidate = set(authority["scope"]["candidate_scope"]) + verify_clean_commit_authority_delta(authority, ROOT, observed=expected) + verify_clean_commit_authority_delta( + authority, + ROOT, + include_committed_candidate=True, + observed=expected | candidate, + ) + for changed in ( + expected - {next(iter(expected))}, + expected | {"scripts/benchmark_ck07r1_lifecycle_scale.py"}, + ): + with pytest.raises(TerminalCorrectionError, match="authority Git delta"): + verify_clean_commit_authority_delta(authority, ROOT, observed=changed) + with pytest.raises(TerminalCorrectionError, match="not an ancestor"): + verify_clean_commit_authority_delta( + authority, + ROOT, + observed=expected, + base_is_ancestor=False, + ) + + +def test_candidate_representation_accepts_exact_dirty_and_clean_states() -> None: + authority = _clean_commit_authority() + candidate = set(authority["scope"]["candidate_scope"]) + authority_scope = set(authority["scope"]["authority_write_scope"]) + base = authority["authority_base_sha"] + tree = authority["authority_base_tree_sha"] + head = authority["implementation_transition"]["head_sha"] + assert ( + verify_clean_candidate_transition( + authority, + ROOT, + observed_head=base, + observed_head_tree=tree, + observed_worktree=candidate, + ) + == "dirty_prepublication" + ) + assert ( + verify_clean_candidate_transition( + authority, + ROOT, + observed_head=head, + observed_head_tree="candidate-tree", + observed_worktree=set(), + observed_committed_delta=candidate, + base_is_ancestor=True, + ) + == "clean_pr_head" + ) + assert ( + verify_clean_candidate_transition( + authority, + ROOT, + observed_head="integrated-head", + observed_head_tree="integrated-tree", + observed_worktree=set(), + observed_committed_delta=authority_scope | candidate, + base_is_ancestor=True, + ) + == "clean_integrated" + ) + + +def test_candidate_representation_rejects_partial_extra_wrong_base_and_wrong_head() -> None: + authority = _clean_commit_authority() + candidate = set(authority["scope"]["candidate_scope"]) + tree = authority["authority_base_tree_sha"] + for changed in ( + candidate - {next(iter(candidate))}, + candidate | {"output/ck07r1/lifecycle-requalification-v2.json"}, + ): + with pytest.raises(TerminalCorrectionError, match="all-or-none"): + verify_clean_candidate_transition( + authority, + ROOT, + observed_head=authority["authority_base_sha"], + observed_head_tree=tree, + observed_worktree=changed, + ) + with pytest.raises(TerminalCorrectionError, match="head tree"): + verify_clean_candidate_transition( + authority, + ROOT, + observed_head=authority["authority_base_sha"], + observed_head_tree="wrong-tree", + observed_worktree=candidate, + ) + with pytest.raises(TerminalCorrectionError, match="not an ancestor"): + verify_clean_candidate_transition( + authority, + ROOT, + observed_head=authority["implementation_transition"]["head_sha"], + observed_head_tree="candidate-tree", + observed_worktree=set(), + observed_committed_delta=candidate, + base_is_ancestor=False, + ) + with pytest.raises(TerminalCorrectionError, match="lineage/delta"): + verify_clean_candidate_transition( + authority, + ROOT, + observed_head="wrong-head", + observed_head_tree="candidate-tree", + observed_worktree=set(), + observed_committed_delta=candidate, + base_is_ancestor=True, + ) + + def test_terminal_correction_preserves_accepted_authority_bytes() -> None: verify_immutable_authority_bytes(_authority(), ROOT) @@ -189,58 +330,57 @@ def test_combined_verifies_authority_binding_before_candidate( monkeypatch: pytest.MonkeyPatch, ) -> None: authority = _authority() - expected_delta = set(authority["scope"]["combined_candidate_scope"]) - calls: list[tuple[str, object]] = [] + clean_commit = _clean_commit_authority() + calls: list[str] = [] monkeypatch.setattr( terminal_module, - "verify_immutable_authority_bytes", - lambda _authority, _root: calls.append(("immutable", None)), + "load_clean_commit_authority", + lambda _root: clean_commit, ) - - def _authority_delta( - _authority: dict[str, Any], - _root: Path, - *, - observed: set[str] | None = None, - allowed_worktree_delta: set[str] | None = None, - base_is_ancestor: bool | None = None, - ) -> None: - assert observed is None - assert base_is_ancestor is None - calls.append(("authority_delta", allowed_worktree_delta)) - monkeypatch.setattr( terminal_module, - "verify_exact_authority_delta", - _authority_delta, + "verify_clean_commit_authority_bytes", + lambda _authority, _root: calls.append("authority_bytes"), ) monkeypatch.setattr( terminal_module, - "verify_exact_candidate_delta", - lambda _authority, _root: calls.append(("candidate_delta", None)), + "verify_clean_candidate_transition", + lambda _authority, _root: calls.append("candidate_transition") + or "clean_integrated", + ) + monkeypatch.setattr( + terminal_module, + "verify_clean_commit_authority_delta", + lambda _authority, _root, **_kwargs: calls.append("authority_delta"), ) monkeypatch.setattr( terminal_module, "verify_corrected_cohort", - lambda _authority, _root: calls.append(("cohort", None)), + lambda _authority, _root: calls.append("cohort"), ) monkeypatch.setattr( terminal_module, "verify_terminal_evidence", - lambda _authority, _root: calls.append(("evidence", None)), + lambda _authority, _root: calls.append("evidence"), ) monkeypatch.setattr( terminal_module, "verify_planner_reproduction", - lambda _authority, _root: calls.append(("planner", None)), + lambda _authority, _root: calls.append("planner"), ) + monkeypatch.setattr(terminal_module, "_sha256", lambda _path: next( + record["sha256"] + for record in clean_commit["implementation_transition"]["paths"] + if ROOT / record["path"] == _path + )) + monkeypatch.setattr(Path, "is_file", lambda _path: True) terminal_module.verify_combined(authority, ROOT) assert calls[:3] == [ - ("immutable", None), - ("authority_delta", expected_delta), - ("candidate_delta", None), + "authority_bytes", + "candidate_transition", + "authority_delta", ] @@ -305,3 +445,42 @@ def test_schema_rejects_token_scope_planner_and_acceptance_weakening() -> None: def test_authority_file_name_is_versioned() -> None: assert Path(AUTHORITY_PATH).name.endswith("-v1.json") + + +def test_clean_commit_schema_rejects_lineage_scope_and_no_run_weakening() -> None: + authority = _clean_commit_authority() + schema = json.loads( + (ROOT / CLEAN_COMMIT_SCHEMA_PATH).read_text(encoding="utf-8") + ) + mutations = ( + lambda value: value["implementation_transition"].__setitem__( + "base_sha", "0" * 40 + ), + lambda value: value["implementation_transition"].__setitem__( + "head_sha", "1" * 40 + ), + lambda value: value["implementation_transition"]["paths"].pop(), + lambda value: value["scope"]["candidate_scope"].pop(), + lambda value: value["scope"]["candidate_scope"].append( + "output/ck07r1/lifecycle-requalification-v2.json" + ), + lambda value: value["decision"].__setitem__("token_consumed", False), + lambda value: value["decision"].__setitem__( + "new_command_invocations_permitted", 1 + ), + lambda value: value["decision"].__setitem__("launch_authorized", True), + lambda value: value["decision"].__setitem__( + "implementation_acceptance", "claimed" + ), + lambda value: value["source_authority"][0].__setitem__( + "sha256", "2" * 64 + ), + ) + for mutate in mutations: + changed = deepcopy(authority) + mutate(changed) + assert list(Draft202012Validator(schema).iter_errors(changed)) + + +def test_clean_commit_authority_file_name_is_versioned() -> None: + assert Path(CLEAN_COMMIT_AUTHORITY_PATH).name.endswith("-v1.json") diff --git a/tests/kernel/test_documentation_authority.py b/tests/kernel/test_documentation_authority.py index 2e19bd8d..d60841a4 100644 --- a/tests/kernel/test_documentation_authority.py +++ b/tests/kernel/test_documentation_authority.py @@ -1350,3 +1350,26 @@ def test_ck07r1_terminal_failure_correction_is_documented_no_rerun() -> None: assert authority["run_token"]["remaining_invocations"] == 0 assert authority["decision"]["launch_authorized"] is False assert authority["decision"]["final_accepted"] == "unavailable" + + +def test_ck07r1_terminal_clean_commit_bridge_is_documented_fail_closed() -> None: + index = _read("docs/INDEX.md") + central = _read("docs/roadmap/REMAINING_EXECUTION_PLAN.md") + accounting = _read("docs/roadmap/TASK_PACKETS.md") + packet = _read("docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md") + authority = _json( + "docs/decisions/evidence/ck07r1a0/" + "lifecycle-terminal-failure-clean-commit-authority-v1.json" + ) + for body in (index, central, accounting, packet): + assert "clean-committed transition" in body + assert "PR #448" in body + assert authority["implementation_transition"]["base_sha"] == ( + "652f2166b58b9ee0d719348a769901577d11e6fd" + ) + assert authority["implementation_transition"]["head_sha"] == ( + "927aa06f7c4c88319cc30247343c40db8e9b817e" + ) + assert authority["decision"]["new_command_invocations_permitted"] == 0 + assert authority["decision"]["launch_authorized"] is False + assert authority["decision"]["token_consumed"] is True diff --git a/tests/kernel/test_kernel_scope.py b/tests/kernel/test_kernel_scope.py index 8009ad53..d35454ce 100644 --- a/tests/kernel/test_kernel_scope.py +++ b/tests/kernel/test_kernel_scope.py @@ -23,6 +23,7 @@ CK07R1_PRELAUNCH_RECOVERY_AUTHORITY_ADDITIONS, CK07R1_RUN_INVOCATION_AUTHORITY_ADDITIONS, CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS, + CK07R1_TERMINAL_CLEAN_COMMIT_AUTHORITY_ADDITIONS, CK07R1_TERMINAL_FAILURE_CORRECTION_AUTHORITY_ADDITIONS, CK07R1A0_AUTHORITY_ADDITIONS, CK08_PREREQUISITE_BLOCKER_ADDITIONS, @@ -705,6 +706,7 @@ def test_k6_additions_are_explicit_and_bounded() -> None: | CK07R1_RUN_INVOCATION_AUTHORITY_ADDITIONS | CK07R1_PRELAUNCH_RECOVERY_AUTHORITY_ADDITIONS | CK07R1_TERMINAL_FAILURE_CORRECTION_AUTHORITY_ADDITIONS + | CK07R1_TERMINAL_CLEAN_COMMIT_AUTHORITY_ADDITIONS | CK08_PREREQUISITE_BLOCKER_ADDITIONS | { "config/agent-kernel/maintainability-baseline-v1.json", @@ -841,6 +843,13 @@ def test_ck07r1_terminal_failure_correction_additions_are_explicit_and_bounded() } == CK07R1_TERMINAL_FAILURE_CORRECTION_AUTHORITY_ADDITIONS +def test_ck07r1_terminal_clean_commit_additions_are_explicit_and_bounded() -> None: + assert { + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-terminal-failure-clean-commit-authority-v1.schema.json", + } == CK07R1_TERMINAL_CLEAN_COMMIT_AUTHORITY_ADDITIONS + + def test_kernel_skeleton_imports_without_legacy_runtime() -> None: import codex_usage_tracker.kernel as kernel From 7b17a2511f6fa2fffb4c303b31b08b6636888e9a Mon Sep 17 00:00:00 2001 From: Monsky Date: Wed, 19 Aug 2026 18:46:11 -0400 Subject: [PATCH 2/3] fix: admit integrated CK-07R1 authority state --- scripts/ck07r1_terminal_failure_correction.py | 42 ++++++++++++++----- ...1_terminal_failure_correction_authority.py | 40 ++++++++++++++++++ 2 files changed, 71 insertions(+), 11 deletions(-) diff --git a/scripts/ck07r1_terminal_failure_correction.py b/scripts/ck07r1_terminal_failure_correction.py index 72ee292a..535ea6df 100644 --- a/scripts/ck07r1_terminal_failure_correction.py +++ b/scripts/ck07r1_terminal_failure_correction.py @@ -144,6 +144,27 @@ def verify_clean_commit_authority_bytes( ) +def _clean_candidate_bytes_exact( + authority: Mapping[str, Any], root: Path +) -> bool: + return all( + (root / record["path"]).is_file() + and _sha256(root / record["path"]) == record["sha256"] + for record in authority["implementation_transition"]["paths"] + ) + + +def verify_clean_candidate_bytes( + authority: Mapping[str, Any], root: Path +) -> None: + for record in authority["implementation_transition"]["paths"]: + candidate = root / record["path"] + if not candidate.is_file() or _sha256(candidate) != record["sha256"]: + raise TerminalCorrectionError( + f"clean committed candidate byte identity mismatch: {record['path']}" + ) + + def verify_clean_commit_authority_delta( authority: Mapping[str, Any], root: Path, @@ -268,7 +289,15 @@ def verify_exact_authority_delta( ): clean_commit = load_clean_commit_authority(root) verify_clean_commit_authority_bytes(clean_commit, root) - verify_clean_commit_authority_delta(clean_commit, root) + include_committed_candidate = False + if _clean_candidate_bytes_exact(clean_commit, root): + representation = verify_clean_candidate_transition(clean_commit, root) + include_committed_candidate = representation == "clean_integrated" + verify_clean_commit_authority_delta( + clean_commit, + root, + include_committed_candidate=include_committed_candidate, + ) return expected = set(authority["scope"]["authority_write_scope"]) base = str(authority["authority_base_sha"]) @@ -510,16 +539,7 @@ def verify_combined( else: verify_clean_commit_authority_delta(clean_commit, clean_commit_root) representation = verify_clean_candidate_transition(clean_commit, root) - expected_paths = { - record["path"]: record["sha256"] - for record in clean_commit["implementation_transition"]["paths"] - } - for path, digest in expected_paths.items(): - candidate = root / path - if not candidate.is_file() or _sha256(candidate) != digest: - raise TerminalCorrectionError( - f"clean committed candidate byte identity mismatch: {path}" - ) + verify_clean_candidate_bytes(clean_commit, root) else: candidate_delta = set(authority["scope"]["combined_candidate_scope"]) verify_immutable_authority_bytes(authority, root) diff --git a/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py b/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py index 4b69a509..401f252d 100644 --- a/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py +++ b/tests/kernel/test_ck07r1_terminal_failure_correction_authority.py @@ -154,6 +154,46 @@ def test_clean_commit_authority_delta_is_exact() -> None: ) +def test_exact_authority_delta_admits_only_exact_clean_integrated_candidate( + monkeypatch: pytest.MonkeyPatch, +) -> None: + authority = _authority() + clean_commit = _clean_commit_authority() + calls: list[tuple[str, object]] = [] + monkeypatch.setattr( + terminal_module, + "load_clean_commit_authority", + lambda _root: clean_commit, + ) + monkeypatch.setattr( + terminal_module, + "verify_clean_commit_authority_bytes", + lambda _authority, _root: calls.append(("authority_bytes", None)), + ) + monkeypatch.setattr( + terminal_module, + "_clean_candidate_bytes_exact", + lambda _authority, _root: True, + ) + monkeypatch.setattr( + terminal_module, + "verify_clean_candidate_transition", + lambda _authority, _root: "clean_integrated", + ) + monkeypatch.setattr( + terminal_module, + "verify_clean_commit_authority_delta", + lambda _authority, _root, **kwargs: calls.append( + ("authority_delta", kwargs["include_committed_candidate"]) + ), + ) + terminal_module.verify_exact_authority_delta(authority, ROOT) + assert calls == [ + ("authority_bytes", None), + ("authority_delta", True), + ] + + def test_candidate_representation_accepts_exact_dirty_and_clean_states() -> None: authority = _clean_commit_authority() candidate = set(authority["scope"]["candidate_scope"]) From af00e3c60d120575ef8d722d4b904e3c2d18ff56 Mon Sep 17 00:00:00 2001 From: Monsky Date: Wed, 19 Aug 2026 20:55:10 -0400 Subject: [PATCH 3/3] fix: preserve terminal verifier result contract --- scripts/ck07r1_terminal_failure_correction.py | 1 - 1 file changed, 1 deletion(-) diff --git a/scripts/ck07r1_terminal_failure_correction.py b/scripts/ck07r1_terminal_failure_correction.py index 535ea6df..00da4dfe 100644 --- a/scripts/ck07r1_terminal_failure_correction.py +++ b/scripts/ck07r1_terminal_failure_correction.py @@ -555,7 +555,6 @@ def verify_combined( verify_planner_reproduction(authority, root) return { "candidate_paths": len(authority["scope"]["combined_candidate_scope"]), - "candidate_representation": representation, "new_run_permitted": False, "runtime_acceptance": "not_claimed", "token_consumed": True,