Skip to content

Repair EDCM audit defects with versioned 0.2 contracts - #75

Merged
erinepshovel-code merged 6 commits into
mainfrom
repair/edcm-audit-contracts-20260917
Sep 23, 2026
Merged

erinepshovel-code merged 6 commits into
mainfrom
repair/edcm-audit-contracts-20260917

Conversation

@erinepshovel-code

@erinepshovel-code erinepshovel-code commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

The audit found six defects behind green CI: omitted transcript text, supplied rounds presented as measured output, unsupported evidence crossing optional-package boundaries, incomplete result hashes, stale construction ownership, and token metadata lost by the codec.

This repair retains full transcript source and continuations; rejects caller-supplied outputs and retired evidence at public intake; validates completed readouts; keeps unsupported geometry/factorization typed NA; hashes the complete emitted contract; preserves bone entries in codec 2; and routes active construction to Stack/UCNS.

Observable changes are versioned: package/measurement 0.2.0, candidate edcm-measurement-v2, result schema 2.0.0, codec 2. Migration guidance explains input rejection, changed parsing, historical replay, and old lossy archives. Frozen canon resources and sealed reports remain unchanged.

Validation:

  • 337 base tests passed; 50 optional integration skips.
  • 140 exact METAPAT/UCNS shared-stack tests passed.
  • 17 pinned historical experiment tests passed; all four experiment runners produced byte-identical repeats in CI.
  • All 12 CI jobs passed on 3cd47643a4649987e909e4ccc9f696e5495d3885, including Python 3.11, 3.12, and 3.13 base coverage.
  • Source integrity, 35-module metadata, eight canonical skill copies, build and distribution metadata checks passed.
  • Clean-wheel CI smoke passed outside the checkout.
  • Added regression witnesses and included them in base/absence/exact-stack CI.
  • Published code trees match the locally verified git trees exactly.
  • The historical gate caught separator newlines leaking into utterance identities; the correction and three line-ending regressions now pass.

Upgrade avenues are documented in docs/UPGRADE_AVENUES.md: source-span explanations, independent validity study, scope/order candidate, recovery stress tests, and an exact construction-receipt consumer. The portfolio report cites the implementation commit.

hmmm: empirical validity remains unresolved. The retained refusal example still misses the frozen refusal marker axis; the sealed booking candidate's sensitivity failure is preserved. No sealed holdout was retuned or promoted by this repair.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-23T15:51:47.035935Z 0215a9f New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Copy link
Copy Markdown
Contributor Author

@codex review

Review exact head 3cd47643a4649987e909e4ccc9f696e5495d3885 for substantive P1/P2 defects in the EDCM 0.2 audit repair: source preservation, rejection of caller-supplied derived output, typed optional-evidence absence, complete result identity, codec-2 metadata preservation, historical replay boundaries, Stack/UCNS construction ownership, migration/versioning, and clean distribution behavior. Preserve frozen canon and sealed historical evidence. Do not treat passing CI as empirical validation.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3cd47643a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread edcm/layers.py Outdated
Comment thread edcm/measurement/parser/turns_rounds.py
Comment thread edcm/ucns_edcm_experiments.py Outdated
Comment thread edcm/measurement/compress.py

Copy link
Copy Markdown
Contributor Author

@codex address that feedback

Repair the exact-head review findings without changing frozen canon or historical evidence. Prioritize the P1: codec-2 decode must fail closed unless each metric record contains the complete expected RoundMetrics field set with valid values; missing evidence must never become numeric zero. Then close the P2s: reject every result-contract/result-identity compartment at public intake; strip every delimiter recognized by splitlines() from Turn.text while preserving exact bytes in source_text; keep the historical 0.1.0 UCNS/EDCM experiment entrypoint bound to edcm-measurement-v1 or add a separately versioned v2 runner/docs rather than silently rebinding history. Add focused regressions, rerun all declared EDCM/producer/clean-wheel gates and CodeQL, then request a new exact-head review. Preserve empirical validity as hmmm.

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: 3cd47643a4

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Copy link
Copy Markdown
Contributor Author

@codex address that feedback. Repair only the four current exact-head P1/P2 findings, preserve the historical v1 experiment identity by introducing a separately versioned v2 runner rather than rewriting history, add focused regressions, and rerun the repository's declared gates. Do not broaden scope.

@chatgpt-codex-connector

Copy link
Copy Markdown

Summary

Testing

  • ✅ python -m pytest -q — 375 passed, 72 optional/environment-specific tests skipped.
  • ✅ /tmp/edcm-full-stack/bin/python -m pytest -q tests/test_goal_vector_experiment.py tests/test_metapat_adapter.py tests/test_ucns_adapter.py tests/test_multiwoz21_corpus.py tests/test_ucns_dependency.py tests/test_measurement.py tests/test_shared_stack_contract.py tests/test_audit_regressions.py — 199 passed against the exact full-stack producer pins.
  • ✅ UCNS_SOURCE_ROOT=/tmp/ucns-experiment /tmp/edcm-ucns-experiments/bin/python -m pytest -q tests/test_ucns_edcm_experiments.py tests/test_ucns_edcm_experiments_v2.py tests/test_ucns_edcm_experiments_v3.py tests/test_ucns_edcm_experiments_v4.py — 18 passed against the historical UCNS commit.
  • ✅ python -m edcm.integrity
  • ✅ python tools/check_metadata_contracts.py — all 36 declared modules passed.
  • ✅ python -m build
  • ✅ python -m twine check dist/*
  • ✅ Repeated v0.1.1 measurement-v2 and v0.2–v0.4 experiment runs produced byte-identical report pairs.
  • ✅ Clean-wheel installation smoke verified package integrity, Unicode delimiter preservation, codec round-tripping, and rejection of caller-supplied readouts.
  • ⚠️ codeql — no local CodeQL runner is available in this environment; the new pull request is configured to run repository-hosted security/CI checks.

View task →

@erinepshovel-code
erinepshovel-code merged commit 616484d into main Sep 23, 2026
16 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 0215a9fcde

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

transcript intake; it is not a replay of the historical 0.1.0/v1 program.

For the historical 0.1.0 experiment, use a separate checkout of EDCM commit
`211ce860446d3576ae2930a101eefdd07d3e3dcc` and its exact UCNS dependency.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Point historical replay at the recorded EDCM commit

When a user follows this newly added historical-replay guidance, they check out 211ce86…, but the sealed v0.1.0 report records its EDCM producer as 5d15592d509a760ff9fbcdd346a2e749537bb2ba in experiments/results/2026-07-21-ucns-edcm-v0.1.0.json:952. Because the producer commit is included in the report and its digest, the documented checkout cannot reproduce the historical artifact's identity even if its measurement behavior happens to match; direct replay instructions to the commit recorded by the artifact.

AGENTS.md reference: AGENTS.md:L63-L64

Useful? React with 👍 / 👎.

"generated_at": "2026-08-18",
"note": "This report describes the cited EDCM state plus the current repo-owned plan. Report-only and language-boundary documentation commits are coordination metadata; they do not upgrade measurement, empirical, proof, semantic, or canon status. The current upstream UCNS lexical program selects the xkcd constrained-English 1,000-word vocabulary as lexical-floor candidate and OEWN 2025 Core as the primary contemporary lexical-semantic corpus."
"branch": "repair/edcm-audit-contracts-20260917",
"commit": "ac2f8653f95483a59624f675e03c00fbd962a7fb",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Refresh the plan report against the delivered implementation

At the reviewed commit, ac2f865… is neither an ancestor nor the complete tree being described: it lacks the subsequently merged codec metric validation, expanded result-field intake rejection, Unicode delimiter handling, and versioned experiment-runner changes. Portfolio consumers treat source.commit as the exact repository state behind status.current_claim and delivered, so this report attributes the final 0.2 repair claims to a revision that cannot reproduce them; publish a follow-up report pinned to the complete delivered state or explicitly record all component revisions.

AGENTS.md reference: AGENTS.md:L52-L52

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant