Skip to content

OCR 1.11.1 evidence integrity and trusted context for v0.8.7 - #164

Merged
xeonvs merged 13 commits into
mainfrom
codex/v0.8.7-ocr-1.11.1-evidence-trust
Sep 1, 2026
Merged

OCR 1.11.1 evidence integrity and trusted context for v0.8.7#164
xeonvs merged 13 commits into
mainfrom
codex/v0.8.7-ocr-1.11.1-evidence-trust

Conversation

@xeonvs

@xeonvs xeonvs commented Aug 31, 2026

Copy link
Copy Markdown
Owner

Scope

Deliver toolkit 0.8.7 with exact OCR 1.11.1 compatibility, evidence-integrity fixes,
bounded evidence search and coverage, protected same-revision CI outcome evidence, and the
release documentation tracked by #157#163.

This is the feature PR. Stable publication remains gated by a separate protected PR titled
exactly Release v0.8.7 after this PR merges and its TestPyPI development publication is
verified.

Added

  • fixed read-only ocr_toolkit_evidence_search and ocr_toolkit_evidence_coverage tools over
    the existing DLP-admitted evidence store;
  • exact count-only action receipt v2 and toolkit receipt v6 reconciliation for
    summary/list/get/search/coverage;
  • protected review-context policy v3 with bounded provider-neutral ci_outcome evidence for
    exact-head GitLab checks;
  • dynamic stable PyPI version, supported-Python, and Apache-2.0 product badges;
  • qualified Pug, Verilog/SystemVerilog, and VHDL selection from OCR 1.11.1.

Fixed and changed

  • incomplete base/head evidence can no longer manufacture dependency deltas;
  • prior-round OCR findings remain unverified until current code, tests, or admitted evidence
    validates them;
  • compatibility probes separately verify below-threshold grouping, threshold-crossing semantic
    grouping, high-churn per-file grouping, and partial budget behavior;
  • GitLab CI snapshot hashing is provider-order independent;
  • evidence search rejects operators and controls both before and after Unicode normalization;
  • the evidence store performs one complete live environment redaction pass per string leaf.

OCR 1.11.1 is the sole accepted runtime. The review effort remains medium, concurrency remains
operator-configurable with the public example default unchanged, and the toolkit does not set a
provider-specific completion-token override. OCR remains authoritative for its current grouping,
background, tool-loop, and token-limit contracts.

Trust boundaries

  • no forced tool_choice and no arbitrary repository search through the evidence MCP;
  • tool arguments/results, prompts, reasoning, provider payloads, credentials, session state, raw
    forge identities, URLs, logs, and artifacts stay outside public output and receipts;
  • CI outcomes, search results, coverage hints, repeated findings, and tool counts do not change
    finding lifecycle, severity, suppression, merge authority, or approval;
  • DLP, cleanup, immutable refs, receipt validation, and conservative approval remain fail-closed;
  • provider acquisition and posting remain at provider edges; evidence/store/MCP/receipt contracts
    remain provider-neutral.

Validation

  • complete project gate: 1,386 tests and 367 subtests; 86.26% branch coverage; risk groups
    85%, 82%, 86%, and 87%;
  • Ruff format/lint, strict MyPy, Bandit, Gitleaks, OCR compatibility manifest, Towncrier draft,
    and diff hygiene passed;
  • three complete OCR 1.11.1 project-rule reviews covered all 29 selected files; confirmed findings
    were remediated and revalidated;
  • the final controlled OCR 1.11.1 review completed 1/1 selected file with no finding, warning,
    failed, reused, or waived work and with publication and cleanup passed;
  • that model-driven run selected summary/list/get/search/coverage once each. The primary subtotal
    reconciled exactly to three ocr_toolkit_evidence calls; search and coverage each reconciled to
    one dedicated by-tool call. Context mode was off, so no enriched-context qualification is
    claimed;
  • production-composed stdio MCP benchmarking improved from 1.95 seconds to 1.51–1.63 seconds after
    removing the redundant redaction pass, while preserving the same private/read-only contract.

Delivery

Exact reviewed feature head: 410194895f85be37e1801b3b92e959177aabf04f.

Tracks #157, #158, #159, #160, #161, #162, and #163 in milestone v0.8.7. These issues and the
milestone remain open until the stable workflow publishes immutable artifacts and records its
release receipts.

@xeonvs xeonvs changed the title Draft: release 0.8.7 with OCR 1.11.1 evidence boundaries OCR 1.11.1 evidence integrity and trusted context for v0.8.7 Sep 1, 2026
@xeonvs
xeonvs marked this pull request as ready for review September 1, 2026 09:34
@xeonvs
xeonvs merged commit 73a17ff into main Sep 1, 2026
13 checks passed
@xeonvs
xeonvs deleted the codex/v0.8.7-ocr-1.11.1-evidence-trust branch September 1, 2026 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant