Skip to content

fix: enforce glossary and inactive graph boundaries - #46

Merged
deku2026 merged 1 commit into
mainfrom
codex/wp00-01-boundary-guards
Sep 18, 2026
Merged

deku2026 merged 1 commit into
mainfrom
codex/wp00-01-boundary-guards

Conversation

@deku2026

Copy link
Copy Markdown
Contributor

Post-merge WP00.01 review reproduced two accepted invalid inputs: a product term directly in glossary section 5 bypassed the namespace check, and an inactive work package with a standalone downstream header bypassed the no-active-edges check. Apply the same guards to the root product section and both header directions. Add the two reproductions to the existing corruption suite.

Full three-file diff review passed. All 15 policy test groups, an isolated fetch/byte-for-byte check of the real pinned Design corpus, locked .NET 10.0.400 restore/build, four architecture tests and format verification pass. Exported data and its registered hashes are unchanged. This is a bounded repair within WP00.01; its prior main publication verification is still running. Latest-head CI and this repair's post-merge publication remain required before advancing.

Signed-off-by: sammiller <dekueon@gmail.com>
@deku2026

Copy link
Copy Markdown
Contributor Author

Full final-diff self-review passed: both defects were reproduced against merged main before editing. The two guards now cover the same documented section/header forms consistently, and each added failing input is independently asserted in the existing suite. All 15 groups and required local managed checks pass; real immutable exports remain byte-identical. No data, pin, registration, package scope or business behavior changes. No outstanding findings. Await all latest-head CI and post-merge publication before completing WP00.01.

@deku2026

Copy link
Copy Markdown
Contributor Author

Final review at c90cc8a: all 10 applicable CI jobs in 35390306471 succeeded, including both policy platforms, native compilation, candidate verification and Windows/Linux isolated package consumers. The complete three-file patch remains the reviewed two-guard repair with its reproductions; no outstanding findings. Proceeding with normal merge. This repair's main publication, public package verification and final source integration remain required within WP00.01.

@deku2026
deku2026 merged commit d5aacf1 into main Sep 18, 2026
10 checks passed
@deku2026

Copy link
Copy Markdown
Contributor Author

Final WP00.01 review and post-merge verification completed on 2026-09-18.

  • Merged repair: d5aacf154771f4b2aff33ca5268df9a6942ff2fb. The primary checkout is pulled and clean; both implementation worktrees and branches are retained.
  • Main CI passes all 12 jobs. Exact candidate 1.0.0-ci.9.1 verifies all 10 NuGet packages and native artifact SHA-256 ca8e0284a113533c6a353fe255f387e94faa00e707e304c1f46b33d673652882.
  • Windows/Linux immutable Design receipts match exactly apart from timestamp and retain the reviewed 1607374e81955f0a47f319cd6cc8ba1c6e254157 pin. Export hashes are unchanged by the boundary repair: glossary 54d1ae6157505fb89caf5d92afc8315c4c5ac714707e898eed993b2374a2b28e, invariants 066b207dd0b70757865975df7698f57cd3476c3557ab850e905c0e6cfdc29e70.
  • Exact-candidate evidence matches every package hash and passes five Windows JIT/AOT native consumer cases, a C17 consumer and wrong-RID/missing-owned-DLL/missing-transitive-DLL/changed-DLL rejection. Both operating systems also pass independent managed package consumption.
  • All 10 public NuGet packages are downloaded and content-identical to the tested candidate except the registry-added signature. The final media runtime became publicly available before closure; no partial publication is counted as completion.
  • The primary nine-repository scan records 770 files, zero findings, all clean source states, the actual derived declaration and its single exact historical provenance exception. Contracts producer 2d036e561c4acce1aadd866d93c16ceca0d776db is separately closed with public NuGet/npm/all 20 Maven-file verification in Contracts PR15.

The complete diff review and both added negative cases are recorded above; no remaining WP00.01 findings are known. Evidence index artifacts/evidence/wp00-01-closure.json binds 12 retained receipts by SHA-256, alongside main-candidate, main-policy-*, main-native-consumers, main-registry-availability.json and main-ci-complete.json in the retained codex/wp00-01-boundary-guards worktree.

WP00.01 now passes its policy/export/citation/graph completion gates. Invariant verification remains planned-only; PG-11 remains open. These results do not claim product/provider/device/commercial readiness. No genuinely unavailable external prerequisite remains for this substep. Proceeding serially to WP00.02 under the user's explicit instruction.

@deku2026
deku2026 deleted the codex/wp00-01-boundary-guards branch September 19, 2026 13:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant