Skip to content

scientific(validation): bind exact-head test evidence to immutable receipt identity #630

Description

@seonghobae

Finding

#629 correctly stopped the specialized scientific-recovery path from minting ScientificallySupported authority without ExactHeadTests, but the repaired public API still accepts claim_evidence: &[ClaimEvidence]. ClaimEvidence::new(ExactHeadTests, true) contains only a kind and boolean; it carries neither the tested commit identity nor an immutable CI/test receipt identity.

That means the specialized recovery path can be handed a passing exact-head boolean that was actually obtained on a predecessor commit, while PromotionRequest only compares candidate_head with protected_head. The generic gate therefore cannot prove that the exact-head test evidence itself belongs to the candidate. #629 explicitly left durable exact-head evidence-receipt identity as a remaining hardening gap.

This is an authority/evidence-provenance defect, not a recovery-metric defect. RMSE/MCSE arithmetic, grouped independent replications, planned denominator, profile provenance, failure policy, and practical targets must not change.

Required RED

On canonical Validation Evidence PR #488, add a public contract requiring scientific recovery to consume an exact-head test receipt that carries:

  • the tested Git commit SHA;
  • an immutable canonical SHA-256 receipt/artifact identity;
  • an explicit terminal state (passed, failed, queued, skipped).

The contract must prove that:

  • a passed receipt bound to the candidate head may compose with computed recovery;
  • a passed receipt bound to another head fails as predecessor evidence;
  • failed, queued, and skipped receipts fail closed with the existing canonical errors;
  • malformed/noncanonical receipt SHA-256 fails closed;
  • the returned scientific promotion retains both the recovery-profile SHA-256 and the exact-head receipt SHA-256 so downstream code cannot silently discard which receipt supported authority.

The predecessor boolean-only recovery API should be unable to satisfy this contract.

Minimal causal repair

Keep the generic ADR 0014 ClaimEvidence model intact for now. Harden the specialized scientific-recovery boundary by introducing a versioned exact-head receipt value object in the Validation Evidence owner, validate its head/digest/status, convert only a matching passed receipt into the internal ExactHeadTests=true evidence item, compute ScientificRecovery=true internally, and then call canonical promote_claim.

Do not infer CI truth from the receipt digest: receipt contents remain trusted-adapter evidence. The repair must bind identity and prevent predecessor/queued/skipped/failing evidence from being relabeled as a detached passing boolean. A later generic claim-receipt migration may reuse this contract.

Keep open through RED → causal repair → exact-head Rust/coverage/security/CodeQL/proof-budget → qualifying independent review → normal prerequisite/protected-main integration and code-current TRACEABILITY/product-gap authority.

Refs #488 #629 #627 #628 #492 ADR 0014.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions