feat(standards): clarify publication and preflight evidence - #2
Merged
MrScripty merged 23 commits intoOct 1, 2026
Merged
Conversation
…ture' into implementation/authoring-publication-evidence-a1
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…nces Keep authoring evidence diagnostics within field-specific shape and size limits. Reject review evidence and exclusions that coverage publication replaces before readiness or publication can proceed.
MrScripty
marked this pull request as ready for review
October 1, 2026 22:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Owning plan and exact candidate
Plan:
docs/plans/authoring-publication-evidence/plan.md, milestone A1 — Explicit publication observations and early evidence failures.Base:
mainat149ba317e9397519bc181a048ecf76aef129a69c.Head:
implementation/authoring-publication-evidence-a1at8260489e8e3ad6b7e170bbf7bd411bac90758abd.Intended outcome
Prerequisites, gates, and exclusions
The only implementation prerequisite is accepted Coding-Standards main at the base above. Local A1 acceptance passed on source candidate
ecbf25cdcd8218b44e68b6adb359c7efaeea765d; current head33a93cf5includes the path-diagnostic repair, refreshed suite-input digests, and updated execution-ledger/PR report. The plan remainsVerifyinguntil exact-head hosted checks, the required Passeur security/lifecycle review, and accepted main integration are complete.Acceptance matrix status: A-C1 satisfied for the tested apply/recovery/status scope, including cold readback through a replacement MCP process. A-C2 remains pending until its bound-reference matrix covers both entrypoints; A1 repairs repository-content preflight and overwritten-path rejection. A-C3 and A-C4 remain pending for A2's baseline/candidate/imported-local evidence acquisition and cold-clone verification. A-C10 remains pending for independent Passeur review and acceptance-owner disposition. A3 checkout reconciliation and the overall plan objective remain pending.
Pumas-Library acquisition/runtime plans are separate from A1 and are not prerequisites. Q1/AQ-HTTP is not ready; runtime R1/R2 remain separately gated. This PR does not qualify any Pumas gate.
Excluded: A2 evidence binding, durable evidence-bundle acquisition, reconciliation writes, Pumas consumers, and migration of existing application/readiness persistence formats.
Ownership, persistence, security, and lifecycle
Repository Git owns fresh checkout/index observation and descriptor lifecycle; Analysis owns evidence validation; the Engine owns publication projection. Existing durable receipts and live publication authorization remain authoritative. No application/readiness persistence schema changes or retained-state migration are included. Descriptor exhaustion, filesystem races, and cancellation release observation resources. Application-facing diagnostics are bounded and redact private exception text. Preflight rejects evidence and exclusions that refer to Engine receipts, the attestation registry, or suite-input manifest paths that publication will overwrite; final candidate validation remains in force.
Evidence
On source candidate
ecbf25cd, the combined twelve-module A1 and interface-consumer acceptance command passed 108 tests in 427.181 seconds in the offline hash-locked Python 3.12 environment. The five affected consumer modules independently passed 24 tests in 165.995 seconds. The added diagnostics regression retains bounded printable spaces, Unicode and dot-prefixed paths, rejects control/absolute/traversal forms, and preserves application redaction.verify_repositorypassed 73 suites and 121 checks with bothrefresh_verification_inputs=trueandfalse; the refresh updatedengine.pyandtest_analysis.pydigests, committed inecbf25cd.tools/standards_verifier/verify.py --completepassed all 73 suites, with zero failures or blocked checks.git diff --checkpassed.The suite exercises test-owned local Git repositories and controlled failure, race, cancellation, readiness, and destination-overwrite cases. Mocked boundary assertions are unit evidence, not proof of real partial-clone or hosted-service behavior. No live remote repository or hosted MCP publication was qualified.
Earlier hosted run 36648831399 failed after 612 tests on nine stale current-interface assertions and did not reach its structural-verifier step. Exact prior-head run 36651259589 also failed on the obsolete interface-45 expectations in head
95b13802. Those five test assertions have now been aligned with current interface 46. Previous exact-head run 36653728027 passed on6921489cin 44m08s. Exact-head run 36656178893 passed on33a93cf5in 48m06s. Exact-head run 36660853570 was canceled after commit8260489esuperseded it. Current exact-head run 36661745679 is queued and is not counted as a pass yet.Runtime profile and optimization
The baseline main workflow run 36574954850 took 43m14s before this A1 branch. A successful prior A1 run reported 613 Engine tests in 42m35s; the other twelve package suites together took about 70s, and the final structural verifier about 8s. The workflow runs the same broad package-test sequence followed by the complete verifier. The latest completed exact-head run before this test-only optimization took 48m06s, so the long end-to-end runtime is not explained by the added tests alone.
A cProfile run of the expanded publication lifecycle test exposed an exhaustive Markdown evidence-candidate read. The test made 495
Repository.read_filecalls (7.5s cumulative under profiling); selection now reads sorted candidates only until the first acceptable file and reuses its bytes. The targeted test passed in 38.6s after the change, compared with 43.6s on A1 before it and 29.5s on the base revision (one unprofiled run per revision). The repository Git suite, including its 11 new tests, passed all 52 tests in 3.7s.The supporting-workflow test had a separate preliminary publication of its test-owned unexposed standard. It now adds that standard to the main proposal and checks authoring/application visibility at the same accepted snapshot, removing one full propose/resolve/review/apply cycle. Its focused test passed in 43.6s after the change, versus 53.5s before consolidation (one local run each; this is not a base comparison).
Reviews and remaining acceptance
GPT-6.1 Sol high's read-only review of
f676cfaffound two P2 gaps: unbounded phase-specific evidence diagnostics and evidence accepted at paths publication would overwrite. GPT-6.1 Sol medium fixed both in01bb2d03; Sol high's follow-up found both closed and no new actionable issue. Sol high's read-only review classified all nine hosted failures as stale current-interface expectations, not intentional v45 client fixtures. Sol medium changed exactly five installed-interface assertions to 46; surrounding lifecycle, disclosure, and legacy client checks remain intact. Sol high's final check of95b13802found no source or scope issue. Sol high's architecture review found one P2 gap: valid spaced, Unicode and dot-prefixed repository evidence paths could lose their diagnostic identity. Sol medium fixed it ine6da2e5f; Sol high's read-only follow-up confirmed closure with no other architecture findings.GPT-6 Luna High's bounded spec/reference review found no remaining gap in the reviewed A1 contracts. Standards Engine routing selected 30 applicable standards with no unresolved questions; the resulting obligations were checked against the source.
The independent Passeur security/lifecycle review remains outstanding. The available Passeur service is bound to Pumas-Library, so no review request was sent through that unrelated repository context.
This PR remains draft pending successful exact-head hosted checks, the required Passeur review, and maintainer-authorized integration to
main. No merge is requested or performed. A2 implementation starts only after A1 is accepted and merged.