Harden local Svif runtime and add native acceptance gates - #11
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope
Principal-authorized release-standard functional repair; Platform publication, release tags and live Cloudflare delivery remain paused. This is the continued candidate on
fix/local-release-readiness, distinct from earlier alternative PR #10.Implementation
Trusted provider-owned operation policy; mandatory trusted verification planning and independent receipts for model results; full checkpoint preflight, revision CAS, process locking, no-follow contained I/O and write-ahead recovery; durable uncertain-effect reconciliation without replay; source-preserving ZIP guards; native install/discovery and separately gated real-model acceptance tooling; bounded requirement matrix and coherent Agnir state.
Observed verification
Source
225e535e32a18bf8db2bfc7d76efe6bed9378e97/ tree12542123c9ab47e5e938f8db8fd8a7d36f28a513passed run35509417968with all 8 jobs: Linux Python3.12/3.13, macOS Python3.12, Windows Python3.12, repository integrity, portable contracts, native install/discovery on Linux and macOS. Local complete suite: 128 tests pass.Native Codex0.155.1 reports actual installation, enabled state, exact package-file hash equality and
svif:svifdiscovery. Exact Plugin tree7cc90517013306181a4df2238f849b85cf716665; per-file SHA256 map digest55d63f208e230b34c5f8b37a4543c5deb37d8978cfbb85013761b45b7a9d23c6.Latest continuity-only checkpoint
1c267e660e6486bdf1017e43b83a2da249655856, tree3b6d026b8d3b6b8281b9cc9f7d8e62fefc741361, preserves tested code/Plugin bytes and corrects the PR-number reference. Require its own CI before merge.Explicit remaining release gate
No authenticated real-model task/checkpoint/fresh-context/idempotency or negative native-host acceptance is claimed. Reports retain
model_exercise:not-run,complete_release_acceptance:false. Followconformance/RELEASE_READINESS.mdin a normally authenticated local Codex environment; never copy secrets into source or chat. Native installation is not full task effectiveness. Desktop GUI, public-directory availability and production effects are not certified.Earlier PR #10's source is preserved and must not be merged automatically over this candidate.