diff --git a/AGENTS.md b/AGENTS.md index aa2686db..5b6804cc 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -40,10 +40,16 @@ behavior or the frozen baseline and is accepted at exact main `30983d4`; QG1 PR #392 passed hosted CI, squash-merged, and was exact-main verified at `68050b93`. CK-07R1A corrected the exact hosted Python 3.14 lifecycle-tail blocker; the linked CK-07R1A0 -authorities, including argv correction, are merged through `479cbdb`. The -existing CK-07R1 worker remains stopped pending coordinator disposition of the -preserved `prelaunch_failed` witness incident and a clean exact-main -reapplication path. PR #394 remains stale failed read-only. +authorities, including argv correction, are merged through `479cbdb`. +Coordinator disposition and clean exact-main reapplication from `cf44f4fd` +derived the exact `66c015de…` / `4b1c62b2…` / `75d03f53…` candidate cohort. +The versioned +[`shared-successor-overlay-authority-v1`](docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) +preserves accepted CK-08R1B, CK-08R1, and CK-QG1 bytes while admitting only +that complete cohort as CK-07 `worker_prequalification`. +The existing CK-07R1 worker remains stopped until that authority transition is +merged and exact-main verified; no launch or token use is authorized. PR #394 +remains stale failed read-only. Retained R3 evidence proved the EvidenceService outer query physically unbounded; CK-08R3A owns that isolated fix and R3 awaits its accepted, merged, exact-main-verified result. diff --git a/docs/INDEX.md b/docs/INDEX.md index 715b0db1..ca12adcd 100644 --- a/docs/INDEX.md +++ b/docs/INDEX.md @@ -109,13 +109,13 @@ authority](decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json) and [run-invocation authority](decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json) keep CK-07R1 `blocked_hold` (`docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json`). -The shared-preparation transition is exactly two-state: live exact-main -preparation `408d18e4…` before R3A, and the current session-bounded preparation -`6689d61f…` only inside the complete R3A cohort after its acceptance. Prior -candidate `e204e0da…` and historical candidate `d192c858…` are retained -read-only, revoked for the new base, and forbidden for direct use. CK-07 must -later reapply its retained lifecycle diff onto the accepted R3A base to derive -a new exact preparation digest before any run. PR #394 remains a stale failed +The accepted source history retains R3A preparation `6689d61f…` as a +historical predecessor and R1B/current exact-main preparation `7d1831ff…` as +the live predecessor. The sole CK-07 worker-prequalification successor is the +atomic `66c015de…` preparation, `4b1c62b2…` benchmark, and `75d03f53…` +lifecycle-test cohort derived from exact main `cf44f4fd`. Mixed or incomplete +cohorts, prior candidate `e204e0da…`, and historical candidate `d192c858…` +fail closed. PR #394 remains a stale failed read-only witness; it is not updated, rerun, or merged. The old argv-guard attempt remains the historical `pre_child_argv_guard_failure`: exit 2 after `0.075241709` seconds, with no child, PID, handshake, token, output, ledger, stdout, stderr, receipt, or @@ -123,10 +123,15 @@ runtime evidence. The corrected guard is `(sys.argv[0], *sys.argv[1:]) == LAUNCH_COMMAND[1:]`. The run authority freezes the exact launch, fixture, revoked malformed dispatch value, 720-second wrapper timeout, four-path non-overwriting preflight, evidence, token, and no-retry -contract while preserving the 5000/120000/100/500/500 ms budgets. No worker -resumes from this authority task, no run token is consumed, no launch/output is -authorized, no other successor is advanced, and the one-run gate remains -unspent. Reclassification and maintainability remain open. The central authority is +contract while preserving the 5000/120000/100/500/500 ms budgets. This +versioned +[`shared-successor-overlay-authority-v1`](decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) +is the only additive consumer bridge: accepted CK-08R1B v1, CK-08R1 evidence, +and CK-QG1 authority bytes remain exact, and the overlay grants neither +implementation acceptance nor launch authority. This +authority task does not resume the worker, consume the run token, authorize +launch/output, or advance another successor. The one-run gate remains unspent +and unavailable. The central authority is [REMAINING_EXECUTION_PLAN.md](roadmap/REMAINING_EXECUTION_PLAN.md). The finite source/runtime state machine is currently `authority_main`: the live diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json b/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json index c8a544f8..1ea83ab3 100644 --- a/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json @@ -1,11 +1,11 @@ { - "schema": "codex-usage-tracker.lifecycle-run-invocation-authority.v5", - "authority_version": 5, + "schema": "codex-usage-tracker.lifecycle-run-invocation-authority.v6", + "authority_version": 6, "owner": "CK-07R1A0", - "authority_base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", + "authority_base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", "status": "blocked_no_run", "shared_preparation_binding": { - "authority_main_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", + "authority_main_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", "r3a_atomic_cohort_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", "r3a_requires_complete_cohort": true, @@ -27,8 +27,8 @@ "corrected_guard": "(sys.argv[0], *sys.argv[1:]) == LAUNCH_COMMAND[1:]", "corrected_candidate_status": "frozen_not_run", "corrected_candidate_artifacts": { - "benchmark_sha256": "f173837d71e393e53e13f0253f3f1ede4045befb5dab2cbf81d6fe147be4b47a", - "lifecycle_test_sha256": "b6468b609dd7e47462d4e0c958f33d37d876959c90fb17ae02d64c3d18c22eed" + "benchmark_sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "lifecycle_test_sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2" }, "old_candidate_artifacts": { "benchmark_sha256": "6a864c74a403da3edb671d9750fc2b2a59b73899102075ee0cec89fbb429b783", @@ -92,8 +92,8 @@ "states": [ { "name": "authority_main", - "source_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_role": "live_predecessor", + "source_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_role": "accepted_current_r1b_predecessor", "runtime_acceptance": "not_claimed", "receipt_policy": "receipt_absent_and_non_qualifying", "evidence_identity_policy": "not_available", @@ -101,8 +101,8 @@ }, { "name": "worker_prequalification", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "not_claimed", "receipt_policy": "not_yet_available", "evidence_identity_policy": "not_available", @@ -110,8 +110,8 @@ }, { "name": "post_single_run", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "qualified_only_with_complete_planner_valid_receipt", "receipt_policy": "complete_planner_valid_receipt_required", "evidence_identity_policy": "bind_exact_dynamic_receipt_and_evidence_identity", @@ -119,8 +119,8 @@ }, { "name": "final_accepted", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "accepted_only_with_worker_merge_and_exact_main", "receipt_policy": "same_complete_planner_valid_receipt_identity_required", "evidence_identity_policy": "same_exact_dynamic_receipt_and_evidence_identity", @@ -133,8 +133,8 @@ "to": "worker_prequalification", "requires": [ "this authority is merged and exact-main verified", - "the existing worker starts from that exact main in a fresh worktree", - "the worker deliberately reapplies only the exact selected successor over the live predecessor", + "the existing worker resumes only the preserved exact candidate worktree", + "the worker presents the byte-exact 66c015de/4b1c62b2/75d03f53 cohort over the 7d1831ff predecessor", "runtime_acceptance remains not_claimed", "authority-integrity and prelaunch gates pass", "maximum_new_end_to_end_runs remains 1 and unspent_unavailable", @@ -146,7 +146,7 @@ "from": "worker_prequalification", "to": "post_single_run", "requires": [ - "only the exact corrected selected successor digest is present", + "only the exact corrected selected successor cohort is present", "exact prelaunch gates pass and one child launch consumes the run token", "a complete planner-valid receipt is produced", "receipt schema, static identities, workload_transition_digest, and stdout/stderr/output evidence identities validate", @@ -204,31 +204,31 @@ ] }, "selected_candidate": { - "status": "r3a_shared_preparation_not_ck07_candidate", - "base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", - "retained_branch": "not_applicable_until_ck07_reapplication", - "retained_worktree": "not_applicable_until_ck07_reapplication", - "witness_status": "r3a_candidate_retained_uncommitted_read_only_not_ck07_qualified", - "source_predecessor_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_successor_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", + "status": "exact_ck07_successor_permitted_not_accepted", + "base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", + "retained_branch": "feature/ck-07r1-launcher-correction-v7", + "retained_worktree": "2026-08-11/codex-usage-tracker-ck07r1-launcher-correction-v7", + "witness_status": "retained_uncommitted_read_only_exact_candidate", + "source_predecessor_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_successor_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", "runtime_acceptance": "not_claimed", - "requires_complete_r3a_cohort": true, - "direct_ck07_use": "forbidden", + "requires_complete_candidate_cohort": true, + "direct_ck07_use": "worker_prequalification_only_after_authority_exact_main", "launch_authorized": false, "artifacts": [ { "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "role": "r3a_shared_preparation_not_ck07_source" + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source" }, { "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", - "sha256": "f173837d71e393e53e13f0253f3f1ede4045befb5dab2cbf81d6fe147be4b47a", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", "role": "benchmark" }, { "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", - "sha256": "b6468b609dd7e47462d4e0c958f33d37d876959c90fb17ae02d64c3d18c22eed", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", "role": "lifecycle_test" }, { @@ -237,7 +237,7 @@ "role": "linked_evidence" } ], - "binding": "r3a_preparation_is_not_a_ck07_candidate; complete_cohort_required_before_ck07_reapplication", + "binding": "only the byte-exact 66c015de/4b1c62b2/75d03f53 cohort may enter worker_prequalification after this authority merges and exact-main verifies", "worker_revalidation_required": true }, "preserved_authorities": { @@ -249,9 +249,9 @@ }, "lifecycle_source_digest": { "path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json", - "sha256": "fdda4898e1f2f638453410b9536d7de12b6e16f7034243e28624bb5c975b611e", + "sha256": "6156780a7e8663859658bb5309f13eb6bf5283704784d8270edf0512c167d70b", "schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json", - "schema_sha256": "b31270111e700ea3bc78d60ce539f1f1dce510f8cac3df929ee1635fbac44405" + "schema_sha256": "4026a4e971c1b6b177b467440a36931bc6a15a0b376918bdc4169b732a0d489c" } }, "launch_contract": { @@ -270,6 +270,20 @@ "one_tool_tail": 500 } }, + "launcher_safety": { + "overlay_and_cohort_verification": "must_complete_before_ledger_fork_child_release_or_token_consumption", + "receipt_binding": "must_equal_exact_overlay_verification_result_and_three_artifact_cohort", + "post_token_or_release_failure_state": "failed_after_launch", + "termination_sequence": [ + "SIGTERM", + "wait_up_to_5_seconds", + "SIGKILL" + ], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none" + }, "repository_relative_command": [ ".venv/bin/python", "scripts/benchmark_ck07r1_lifecycle_scale.py", @@ -566,7 +580,7 @@ "refund": false, "prior_identities_reused": false, "concurrent_processes_allowed": false, - "eligibility": "only after this authority merges and exact-main verifies, the stopped existing worker deliberately reapplies only the corrected exact candidate, and all gates pass", + "eligibility": "only after this authority merges and exact-main verifies, the stopped existing worker resumes only the preserved exact 66c015de/4b1c62b2/75d03f53 candidate cohort, and all gates pass", "first_successful_launch": "exactly one first successful child launch may consume the still-unspent token; this is not a retry, restart, or replacement of a launched process", "old_candidate_reuse": "forbidden" }, @@ -629,14 +643,15 @@ }, "feasibility": { "candidate_script": "scripts/benchmark_ck07r1_lifecycle_scale.py", - "candidate_status": "corrected_no_run_runtime_unqualified", - "exact_blocker": "the corrected no-run candidate is identity-reconciled but the stopped worker has not deliberately reapplied it on exact merged main or produced the planner-valid receipt; the sole end-to-end gate remains unconsumed", + "candidate_status": "exact_successor_bound_no_run_runtime_unqualified", + "exact_blocker": "the exact successor cohort is authority-bound but this authority is not yet merged and exact-main verified, the stopped worker has not re-entered worker_prequalification, and no planner-valid receipt exists; the sole end-to-end gate remains unconsumed", "authority_action": "freeze contract only; do not implement runtime or harness behavior in this authority", "run_action": "do not execute production or end-to-end qualification; do not consume the run token; keep CK-07R1 blocked", "fixture_identity_status": "proven_for_static_manifest_and_file_values; workload_transition_digest remains a required runtime-produced value" }, "scope": { "authority_only_files": [ + "AGENTS.md", "docs/INDEX.md", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json b/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json index 1af88899..d6c0f7dd 100644 --- a/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json @@ -1,6 +1,6 @@ { "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "https://codex-usage-tracker.invalid/schemas/lifecycle-run-invocation-authority-v5.schema.json", + "$id": "https://codex-usage-tracker.invalid/schemas/lifecycle-run-invocation-authority-v6.schema.json", "title": "CK-07R1A0 finite lifecycle source/runtime authority", "type": "object", "additionalProperties": false, @@ -29,23 +29,23 @@ ], "properties": { "schema": { - "const": "codex-usage-tracker.lifecycle-run-invocation-authority.v5" + "const": "codex-usage-tracker.lifecycle-run-invocation-authority.v6" }, "authority_version": { - "const": 5 + "const": 6 }, "owner": { "const": "CK-07R1A0" }, "authority_base_sha": { - "const": "7d5a4b1717db78891fd2c38d8803d7fe2f922986" + "const": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" }, "status": { "const": "blocked_no_run" }, "shared_preparation_binding": { "const": { - "authority_main_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", + "authority_main_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", "r3a_atomic_cohort_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", "r3a_requires_complete_cohort": true, @@ -99,10 +99,10 @@ ], "properties": { "benchmark_sha256": { - "const": "f173837d71e393e53e13f0253f3f1ede4045befb5dab2cbf81d6fe147be4b47a" + "const": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde" }, "lifecycle_test_sha256": { - "const": "b6468b609dd7e47462d4e0c958f33d37d876959c90fb17ae02d64c3d18c22eed" + "const": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2" } } }, @@ -323,8 +323,8 @@ "const": [ { "name": "authority_main", - "source_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_role": "live_predecessor", + "source_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_role": "accepted_current_r1b_predecessor", "runtime_acceptance": "not_claimed", "receipt_policy": "receipt_absent_and_non_qualifying", "evidence_identity_policy": "not_available", @@ -332,8 +332,8 @@ }, { "name": "worker_prequalification", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "not_claimed", "receipt_policy": "not_yet_available", "evidence_identity_policy": "not_available", @@ -341,8 +341,8 @@ }, { "name": "post_single_run", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "qualified_only_with_complete_planner_valid_receipt", "receipt_policy": "complete_planner_valid_receipt_required", "evidence_identity_policy": "bind_exact_dynamic_receipt_and_evidence_identity", @@ -350,8 +350,8 @@ }, { "name": "final_accepted", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", "runtime_acceptance": "accepted_only_with_worker_merge_and_exact_main", "receipt_policy": "same_complete_planner_valid_receipt_identity_required", "evidence_identity_policy": "same_exact_dynamic_receipt_and_evidence_identity", @@ -366,8 +366,8 @@ "to": "worker_prequalification", "requires": [ "this authority is merged and exact-main verified", - "the existing worker starts from that exact main in a fresh worktree", - "the worker deliberately reapplies only the exact selected successor over the live predecessor", + "the existing worker resumes only the preserved exact candidate worktree", + "the worker presents the byte-exact 66c015de/4b1c62b2/75d03f53 cohort over the 7d1831ff predecessor", "runtime_acceptance remains not_claimed", "authority-integrity and prelaunch gates pass", "maximum_new_end_to_end_runs remains 1 and unspent_unavailable", @@ -379,7 +379,7 @@ "from": "worker_prequalification", "to": "post_single_run", "requires": [ - "only the exact corrected selected successor digest is present", + "only the exact corrected selected successor cohort is present", "exact prelaunch gates pass and one child launch consumes the run token", "a complete planner-valid receipt is produced", "receipt schema, static identities, workload_transition_digest, and stdout/stderr/output evidence identities validate", @@ -476,7 +476,7 @@ "source_predecessor_sha256", "source_successor_sha256", "runtime_acceptance", - "requires_complete_r3a_cohort", + "requires_complete_candidate_cohort", "direct_ck07_use", "launch_authorized", "artifacts", @@ -485,34 +485,34 @@ ], "properties": { "status": { - "const": "r3a_shared_preparation_not_ck07_candidate" + "const": "exact_ck07_successor_permitted_not_accepted" }, "base_sha": { - "const": "7d5a4b1717db78891fd2c38d8803d7fe2f922986" + "const": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" }, "retained_branch": { - "const": "not_applicable_until_ck07_reapplication" + "const": "feature/ck-07r1-launcher-correction-v7" }, "retained_worktree": { - "const": "not_applicable_until_ck07_reapplication" + "const": "2026-08-11/codex-usage-tracker-ck07r1-launcher-correction-v7" }, "witness_status": { - "const": "r3a_candidate_retained_uncommitted_read_only_not_ck07_qualified" + "const": "retained_uncommitted_read_only_exact_candidate" }, "source_predecessor_sha256": { - "const": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872" + "const": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb" }, "source_successor_sha256": { - "const": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c" + "const": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea" }, "runtime_acceptance": { "const": "not_claimed" }, - "requires_complete_r3a_cohort": { + "requires_complete_candidate_cohort": { "const": true }, "direct_ck07_use": { - "const": "forbidden" + "const": "worker_prequalification_only_after_authority_exact_main" }, "launch_authorized": { "const": false @@ -521,17 +521,17 @@ "const": [ { "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "role": "r3a_shared_preparation_not_ck07_source" + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source" }, { "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", - "sha256": "f173837d71e393e53e13f0253f3f1ede4045befb5dab2cbf81d6fe147be4b47a", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", "role": "benchmark" }, { "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", - "sha256": "b6468b609dd7e47462d4e0c958f33d37d876959c90fb17ae02d64c3d18c22eed", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", "role": "lifecycle_test" }, { @@ -542,7 +542,7 @@ ] }, "binding": { - "const": "r3a_preparation_is_not_a_ck07_candidate; complete_cohort_required_before_ck07_reapplication" + "const": "only the byte-exact 66c015de/4b1c62b2/75d03f53 cohort may enter worker_prequalification after this authority merges and exact-main verifies" }, "worker_revalidation_required": { "const": true @@ -595,13 +595,13 @@ "const": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json" }, "sha256": { - "const": "fdda4898e1f2f638453410b9536d7de12b6e16f7034243e28624bb5c975b611e" + "const": "6156780a7e8663859658bb5309f13eb6bf5283704784d8270edf0512c167d70b" }, "schema_path": { "const": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json" }, "schema_sha256": { - "const": "b31270111e700ea3bc78d60ce539f1f1dce510f8cac3df929ee1635fbac44405" + "const": "4026a4e971c1b6b177b467440a36931bc6a15a0b376918bdc4169b732a0d489c" } } } @@ -612,6 +612,7 @@ "additionalProperties": false, "required": [ "aggregate_timeout", + "launcher_safety", "repository_relative_command", "required_cwd", "cwd_rule", @@ -666,6 +667,22 @@ } } }, + "launcher_safety": { + "const": { + "overlay_and_cohort_verification": "must_complete_before_ledger_fork_child_release_or_token_consumption", + "receipt_binding": "must_equal_exact_overlay_verification_result_and_three_artifact_cohort", + "post_token_or_release_failure_state": "failed_after_launch", + "termination_sequence": [ + "SIGTERM", + "wait_up_to_5_seconds", + "SIGKILL" + ], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none" + } + }, "repository_relative_command": { "const": [ ".venv/bin/python", @@ -1248,7 +1265,7 @@ "const": false }, "eligibility": { - "const": "only after this authority merges and exact-main verifies, the stopped existing worker deliberately reapplies only the corrected exact candidate, and all gates pass" + "const": "only after this authority merges and exact-main verifies, the stopped existing worker resumes only the preserved exact 66c015de/4b1c62b2/75d03f53 candidate cohort, and all gates pass" }, "first_successful_launch": { "const": "exactly one first successful child launch may consume the still-unspent token; this is not a retry, restart, or replacement of a launched process" @@ -1408,10 +1425,10 @@ "const": "scripts/benchmark_ck07r1_lifecycle_scale.py" }, "candidate_status": { - "const": "corrected_no_run_runtime_unqualified" + "const": "exact_successor_bound_no_run_runtime_unqualified" }, "exact_blocker": { - "const": "the corrected no-run candidate is identity-reconciled but the stopped worker has not deliberately reapplied it on exact merged main or produced the planner-valid receipt; the sole end-to-end gate remains unconsumed" + "const": "the exact successor cohort is authority-bound but this authority is not yet merged and exact-main verified, the stopped worker has not re-entered worker_prequalification, and no planner-valid receipt exists; the sole end-to-end gate remains unconsumed" }, "authority_action": { "const": "freeze contract only; do not implement runtime or harness behavior in this authority" @@ -1434,6 +1451,7 @@ "properties": { "authority_only_files": { "const": [ + "AGENTS.md", "docs/INDEX.md", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json b/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json index 24418b89..56afe334 100644 --- a/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json @@ -1,19 +1,19 @@ { - "schema": "codex-usage-tracker.lifecycle-source-digest-authority.v6", - "authority_version": 6, + "schema": "codex-usage-tracker.lifecycle-source-digest-authority.v7", + "authority_version": 7, "owner": "CK-07R1A0", - "authority_base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", + "authority_base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", "source_path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", "status": "blocked_hold", "acceptance_state": { - "status": "conditional_two_state_no_run", - "authority_main_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", + "status": "exact_successor_selected_no_run", + "authority_main_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", "r3a_atomic_cohort_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", - "binding": "408d18e4 remains the live source before R3A; the current session-bounded preparation is permitted only inside the complete current R3A cohort; prior e204e0da and historical d192c858 are forbidden", + "binding": "7d1831ff is the accepted current R1B predecessor, 6689d61f remains the accepted historical R3A predecessor, and only the atomic 66c015de candidate cohort may enter CK-07 worker prequalification; prior e204e0da and historical d192c858 are forbidden", "runtime_acceptance": "not_claimed", "direct_use_of_d192": "forbidden", - "worker_reapplication_required": true, + "worker_reapplication_required": false, "linked_final_shared_authority": "docs/decisions/evidence/ck08r3a/final-shared-authority.json" }, "state_machine_binding": { @@ -23,46 +23,65 @@ "states": [ { "name": "authority_main", - "source_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_role": "live_predecessor", + "source_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_role": "accepted_current_r1b_predecessor", "runtime_acceptance": "not_claimed" }, { - "name": "r3a_worker_prequalification", + "name": "r3a_accepted_predecessor", "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", + "source_role": "accepted_historical_r3a_predecessor", "runtime_acceptance": "not_claimed", "requires_complete_r3a_cohort": true }, { - "name": "ck07_requalification", - "source_sha256": "new_digest_required_after_reapplication", - "source_role": "future_ck07_successor", - "runtime_acceptance": "not_available" + "name": "worker_prequalification", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", + "runtime_acceptance": "not_claimed", + "requires_complete_candidate_cohort": true } ], - "source_digest_rule": "authority_main remains 408d18e4; the current session-bounded preparation may enter only with every selected R3A production and support identity; prior e204e0da is superseded and CK-07 later requires a newly derived preparation digest", + "source_digest_rule": "authority_main remains exact 7d1831ff; historical accepted 6689d61f remains predecessor-only; worker_prequalification admits only 66c015de with byte-exact 4b1c62b2 benchmark and 75d03f53 lifecycle test; every mixed, incomplete, historical, or other digest state fails closed", "other_digest": "fail_closed", "current_runtime_claim": "not_claimed", "launch_state": "blocked_hold_no_run" }, "predecessor": { - "sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "accepted_merge_sha": "d911b1f0d17596890a6a0a608be904330c96e9a6", + "sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "accepted_merge_sha": "9e9332b3ae2be78cedb581ff8f76149ad76f4440", "authority": { - "path": "docs/decisions/evidence/ck08r0/corrective-gates-v1.json", - "sha256": "8f2bc6762b3b12f3c42ad72fb23ccaa49bfde3124280082fa65766bb9ceb9936" + "path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.json", + "sha256": "d35bca7600e2e372d6c7b71420cc95996ee1222343982ffd323fee9ba5cbf8b5" } }, "selected_successor": { - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", "status": "permitted_not_accepted", - "role": "selected_r3a_atomic_cohort_preparation", - "base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", - "requires_full_r3a_cohort": true, - "direct_ck07_use": "forbidden", + "role": "selected_ck07_exact_candidate", + "base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", + "requires_full_candidate_cohort": true, + "direct_ck07_use": "worker_prequalification_only_after_authority_exact_main", "mixed_state": "fail_closed", - "runtime_acceptance": "not_claimed" + "runtime_acceptance": "not_claimed", + "launch_authorized": false, + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "role": "benchmark" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", + "role": "lifecycle_test" + } + ] }, "historical_candidate": { "sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", @@ -95,10 +114,10 @@ "worker_revalidation": { "required": true, "worker_task": "019fbfe2-8fe4-7de2-9264-d58572366727", - "start": "fresh exact-main worktree after accepted R3A cohort", - "reapply": "deliberately reapply the retained CK-07 lifecycle diff onto exact-main preparation after the accepted current R3A cohort; do not mutate the retained witness", - "derive_new_digest": true, - "update_source_authority_before_run": true, + "start": "resume the preserved exact-main candidate worktree only after this authority merges and exact-main verifies", + "reapply": "use only the already-derived atomic 66c015de/4b1c62b2/75d03f53 candidate cohort; do not mutate any historical witness or substitute another digest", + "derive_new_digest": false, + "update_source_authority_before_run": false, "old_d192_reuse": "fail_closed", "different_digest": "fail_closed", "one_run_gate": "unspent_unavailable_until_authority_merge_exact_main_and_all_worker_pre_run_gates_pass" @@ -127,8 +146,10 @@ "constraints": [ "generic_digest_drift_forbidden", "any_different_preparation_digest_fails_closed", - "408d18e4_live_before_r3a", - "current_session_bounded_preparation_requires_complete_r3a_cohort", + "7d1831ff_is_current_exact_main_predecessor", + "6689d61f_is_historical_accepted_r3a_predecessor_only", + "66c015de_requires_atomic_4b1c62b2_and_75d03f53_cohort", + "mixed_or_incomplete_candidate_cohort_fails_closed", "e204e0da_superseded_and_direct_use_forbidden", "historical_d192_direct_use_forbidden", "blocked_hold_no_launch", diff --git a/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json b/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json index d57c9993..656d6618 100644 --- a/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json +++ b/docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json @@ -1,6 +1,6 @@ { "$schema": "https://json-schema.org/draft/2020-12/schema", - "$id": "https://codex-usage-tracker.invalid/schemas/lifecycle-source-digest-authority-v6.schema.json", + "$id": "https://codex-usage-tracker.invalid/schemas/lifecycle-source-digest-authority-v7.schema.json", "title": "CK-07R1A0 shared-preparation source digest authority", "type": "object", "additionalProperties": false, @@ -28,16 +28,16 @@ ], "properties": { "schema": { - "const": "codex-usage-tracker.lifecycle-source-digest-authority.v6" + "const": "codex-usage-tracker.lifecycle-source-digest-authority.v7" }, "authority_version": { - "const": 6 + "const": 7 }, "owner": { "const": "CK-07R1A0" }, "authority_base_sha": { - "const": "7d5a4b1717db78891fd2c38d8803d7fe2f922986" + "const": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" }, "source_path": { "const": "src/codex_usage_tracker/agent_kernel/publication/preparation.py" @@ -47,14 +47,14 @@ }, "acceptance_state": { "const": { - "status": "conditional_two_state_no_run", - "authority_main_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", + "status": "exact_successor_selected_no_run", + "authority_main_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", "r3a_atomic_cohort_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", - "binding": "408d18e4 remains the live source before R3A; the current session-bounded preparation is permitted only inside the complete current R3A cohort; prior e204e0da and historical d192c858 are forbidden", + "binding": "7d1831ff is the accepted current R1B predecessor, 6689d61f remains the accepted historical R3A predecessor, and only the atomic 66c015de candidate cohort may enter CK-07 worker prequalification; prior e204e0da and historical d192c858 are forbidden", "runtime_acceptance": "not_claimed", "direct_use_of_d192": "forbidden", - "worker_reapplication_required": true, + "worker_reapplication_required": false, "linked_final_shared_authority": "docs/decisions/evidence/ck08r3a/final-shared-authority.json" } }, @@ -64,27 +64,28 @@ "run_authority_schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", "current_state": "authority_main", "states": [ - { - "name": "authority_main", - "source_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_role": "live_predecessor", - "runtime_acceptance": "not_claimed" - }, - { - "name": "r3a_worker_prequalification", - "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "source_role": "selected_r3a_atomic_cohort_preparation", - "runtime_acceptance": "not_claimed", - "requires_complete_r3a_cohort": true - }, - { - "name": "ck07_requalification", - "source_sha256": "new_digest_required_after_reapplication", - "source_role": "future_ck07_successor", - "runtime_acceptance": "not_available" - } - ], - "source_digest_rule": "authority_main remains 408d18e4; the current session-bounded preparation may enter only with every selected R3A production and support identity; prior e204e0da is superseded and CK-07 later requires a newly derived preparation digest", + { + "name": "authority_main", + "source_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_role": "accepted_current_r1b_predecessor", + "runtime_acceptance": "not_claimed" + }, + { + "name": "r3a_accepted_predecessor", + "source_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", + "source_role": "accepted_historical_r3a_predecessor", + "runtime_acceptance": "not_claimed", + "requires_complete_r3a_cohort": true + }, + { + "name": "worker_prequalification", + "source_sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "source_role": "selected_ck07_exact_candidate", + "runtime_acceptance": "not_claimed", + "requires_complete_candidate_cohort": true + } + ], + "source_digest_rule": "authority_main remains exact 7d1831ff; historical accepted 6689d61f remains predecessor-only; worker_prequalification admits only 66c015de with byte-exact 4b1c62b2 benchmark and 75d03f53 lifecycle test; every mixed, incomplete, historical, or other digest state fails closed", "other_digest": "fail_closed", "current_runtime_claim": "not_claimed", "launch_state": "blocked_hold_no_run" @@ -92,24 +93,42 @@ }, "predecessor": { "const": { - "sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "accepted_merge_sha": "d911b1f0d17596890a6a0a608be904330c96e9a6", + "sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "accepted_merge_sha": "9e9332b3ae2be78cedb581ff8f76149ad76f4440", "authority": { - "path": "docs/decisions/evidence/ck08r0/corrective-gates-v1.json", - "sha256": "8f2bc6762b3b12f3c42ad72fb23ccaa49bfde3124280082fa65766bb9ceb9936" + "path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.json", + "sha256": "d35bca7600e2e372d6c7b71420cc95996ee1222343982ffd323fee9ba5cbf8b5" } } }, "selected_successor": { "const": { - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", "status": "permitted_not_accepted", - "role": "selected_r3a_atomic_cohort_preparation", - "base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", - "requires_full_r3a_cohort": true, - "direct_ck07_use": "forbidden", + "role": "selected_ck07_exact_candidate", + "base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", + "requires_full_candidate_cohort": true, + "direct_ck07_use": "worker_prequalification_only_after_authority_exact_main", "mixed_state": "fail_closed", - "runtime_acceptance": "not_claimed" + "runtime_acceptance": "not_claimed", + "launch_authorized": false, + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "role": "benchmark" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", + "role": "lifecycle_test" + } + ] } }, "historical_candidate": { @@ -148,10 +167,10 @@ "const": { "required": true, "worker_task": "019fbfe2-8fe4-7de2-9264-d58572366727", - "start": "fresh exact-main worktree after accepted R3A cohort", - "reapply": "deliberately reapply the retained CK-07 lifecycle diff onto exact-main preparation after the accepted current R3A cohort; do not mutate the retained witness", - "derive_new_digest": true, - "update_source_authority_before_run": true, + "start": "resume the preserved exact-main candidate worktree only after this authority merges and exact-main verifies", + "reapply": "use only the already-derived atomic 66c015de/4b1c62b2/75d03f53 candidate cohort; do not mutate any historical witness or substitute another digest", + "derive_new_digest": false, + "update_source_authority_before_run": false, "old_d192_reuse": "fail_closed", "different_digest": "fail_closed", "one_run_gate": "unspent_unavailable_until_authority_merge_exact_main_and_all_worker_pre_run_gates_pass" @@ -192,8 +211,10 @@ "const": [ "generic_digest_drift_forbidden", "any_different_preparation_digest_fails_closed", - "408d18e4_live_before_r3a", - "current_session_bounded_preparation_requires_complete_r3a_cohort", + "7d1831ff_is_current_exact_main_predecessor", + "6689d61f_is_historical_accepted_r3a_predecessor_only", + "66c015de_requires_atomic_4b1c62b2_and_75d03f53_cohort", + "mixed_or_incomplete_candidate_cohort_fails_closed", "e204e0da_superseded_and_direct_use_forbidden", "historical_d192_direct_use_forbidden", "blocked_hold_no_launch", diff --git a/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json b/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json new file mode 100644 index 00000000..799e9e68 --- /dev/null +++ b/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json @@ -0,0 +1,199 @@ +{ + "schema": "codex-usage-tracker.ck07r1-shared-successor-overlay.v1", + "authority_version": 1, + "owner": "CK-07R1-SHARED-OVERLAY", + "authority_base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", + "status": "permitted_not_accepted", + "decision": "authorize_exact_ck07_worker_prequalification_overlay_only", + "immutable_authorities": [ + { + "id": "CK-08R1B-v1", + "path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.json", + "sha256": "d35bca7600e2e372d6c7b71420cc95996ee1222343982ffd323fee9ba5cbf8b5", + "schema_path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.schema.json", + "schema_sha256": "4921d75b71138d4a2ced9345cc4cb40ea0873305e3245b22f16059e3d41ebd3b" + }, + { + "id": "CK-08R1-accepted-evidence", + "path": "docs/decisions/evidence/ck08r1/answer-truth-requalification-v2.json", + "sha256": "54a5a1c2ca590e8d09591a4143ad2689d9be72be4fe0542effa5d8f3d07c4294", + "schema_path": "docs/decisions/evidence/ck08r1a/answer-truth-requalification-v2.schema.json", + "schema_sha256": "ea35833d4dcca418f5e2776002249cb55174cb73d2f70a54d1c3f1721ca03fcc" + }, + { + "id": "CK-QG1-accepted-authority", + "path": "docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json", + "sha256": "f7bedece9116beec29880bd8211e2facaaa8071d036ab13f1af217d77aa6505e", + "schema_path": "docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.schema.json", + "schema_sha256": "9290f65352718c67f6e9306350fb20c9998f225f59be64de58e9bd8397a20633" + } + ], + "ck07_authorities": [ + { + "id": "lifecycle-source-digest-v7", + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json", + "sha256": "6156780a7e8663859658bb5309f13eb6bf5283704784d8270edf0512c167d70b", + "schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json", + "schema_sha256": "4026a4e971c1b6b177b467440a36931bc6a15a0b376918bdc4169b732a0d489c" + }, + { + "id": "lifecycle-run-invocation-v6", + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", + "sha256": "6b1a2753e935da9a9c0121e4f1691957b06b388c1bc55631920725ae6d9089be", + "schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", + "schema_sha256": "e3f24adc98078524523dcb404b9cf9d934fe6c68637abb8a5c40e2eb97ea7e74" + } + ], + "states": { + "predecessor": { + "name": "authority_main", + "status": "accepted_historical_and_current_predecessor_only", + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "presence": "required" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "presence": "absent" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "presence": "absent" + } + ] + }, + "successor": { + "name": "worker_prequalification", + "status": "permitted_not_accepted", + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "presence": "required" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "presence": "required" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", + "presence": "required" + } + ], + "entry": "worker_prequalification_only_after_authority_merge_and_exact_main", + "runtime_acceptance": "not_claimed", + "launch_authorized": false + }, + "forbidden": { + "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", + "superseded_e204_sha256": "e204e0da8f6dce7b6c4cf7a981803d2d8c08b45cb3a2ca370fe1838fd6cf2174", + "mixed_or_partial": "fail_closed", + "other_digest": "fail_closed", + "extra_cohort_artifact": "fail_closed" + } + }, + "consumer_bridge": { + "policy": "accepted_v1_bytes_remain_authoritative; only the exact complete CK-07 successor is interpreted as a successor of the accepted 7d1831ff preparation state", + "consumers": [ + "scripts/qualify_ck08r1_answer_truth.py", + "tests/kernel/test_ck08r1b_answer_semantics_join_authority.py", + "tests/kernel/test_ckqg1_maintainability_baseline_authority.py" + ], + "ck08r1b_history": "the accepted 23-path predecessor/successor cohort and all historical Git identities remain unchanged", + "ck08r1_evidence": "the accepted evidence and closure identities remain unchanged", + "ckqg1_semantics": "the accepted baseline, C/B/B thresholds, normalized findings, and writer transition remain unchanged" + }, + "launcher_safety": { + "overlay_and_cohort_verification": "must_complete_before_ledger_fork_child_release_or_token_consumption", + "receipt_binding": "must_equal_exact_overlay_verification_result_and_three_artifact_cohort", + "post_token_or_release_failure_state": "failed_after_launch", + "aggregate_timeout_seconds": 720, + "termination_sequence": [ + "SIGTERM", + "wait_up_to_5_seconds", + "SIGKILL" + ], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none" + }, + "non_consuming_invariants": { + "maximum_new_end_to_end_runs": 1, + "token_status": "unspent_unavailable", + "token_consumed": false, + "matching_processes": [], + "successful_child": "absent", + "pid": "absent", + "handshake": "absent", + "runtime_acceptance": "not_claimed", + "receipt": "absent_non_qualifying", + "output": "absent", + "ledger": "absent", + "stdout": "absent", + "stderr": "absent", + "retry": "none", + "restart": "none", + "replacement": "none", + "pr394": "stale_read_only", + "downstream": "CK-08R4_CK-08RG_CK-09_blocked", + "data_policy": "synthetic_only" + }, + "scope": { + "authority_write_scope": [ + "AGENTS.md", + "docs/INDEX.md", + "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json", + "docs/roadmap/REMAINING_EXECUTION_PLAN.md", + "docs/roadmap/TASK_PACKETS.md", + "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md", + "docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md", + "scripts/check_kernel_scope.py", + "scripts/ck07r1_shared_successor_overlay.py", + "scripts/qualify_ck08r1_answer_truth.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck08r1b_answer_semantics_join_authority.py", + "tests/kernel/test_ckqg1_maintainability_baseline_authority.py", + "tests/kernel/test_documentation_authority.py", + "tests/kernel/test_kernel_scope.py", + "tests/kernel/test_lifecycle_run_invocation_authority.py" + ], + "combined_preflight_candidate_scope": [ + "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "scripts/benchmark_ck07r1_lifecycle_scale.py", + "tests/agent_kernel/publication/test_lifecycle_scale.py" + ], + "forbidden": [ + "accepted CK-08R1B v1 authority or schema edits", + "accepted CK-08R1 evidence or schema edits", + "accepted CK-QG1 authority or schema edits", + "candidate or support bytes in the authority PR", + "implementation acceptance or launch authorization", + "output, ledger, stdout, stderr, or receipt creation", + "token consumption", + "PR #394 mutation", + "CK-08R4, CK-08RG, or CK-09 readiness" + ] + }, + "negative_mutations": [ + "rewrite any immutable accepted authority byte", + "remove or add a successor cohort artifact", + "substitute any successor digest", + "present a mixed or partial predecessor/successor cohort", + "present any extra dirty or CK-QG1-allowed path in combined preflight", + "claim post_single_run or final_accepted", + "claim runtime acceptance, launch authorization, or token consumption", + "weaken launcher overlay, receipt, failure classification, or timeout binding", + "fabricate a receipt or any output path", + "weaken the exact authority or preflight scope" + ] +} diff --git a/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json b/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json new file mode 100644 index 00000000..34df55e5 --- /dev/null +++ b/docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json @@ -0,0 +1,294 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "title": "CK-07R1 exact shared-successor overlay authority", + "type": "object", + "required": [ + "schema", + "authority_version", + "owner", + "authority_base_sha", + "status", + "decision", + "immutable_authorities", + "ck07_authorities", + "states", + "consumer_bridge", + "launcher_safety", + "non_consuming_invariants", + "scope", + "negative_mutations" + ], + "additionalProperties": false, + "properties": { + "schema": { + "const": "codex-usage-tracker.ck07r1-shared-successor-overlay.v1" + }, + "authority_version": { + "const": 1 + }, + "owner": { + "const": "CK-07R1-SHARED-OVERLAY" + }, + "authority_base_sha": { + "const": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" + }, + "status": { + "const": "permitted_not_accepted" + }, + "decision": { + "const": "authorize_exact_ck07_worker_prequalification_overlay_only" + }, + "immutable_authorities": { + "const": [ + { + "id": "CK-08R1B-v1", + "path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.json", + "sha256": "d35bca7600e2e372d6c7b71420cc95996ee1222343982ffd323fee9ba5cbf8b5", + "schema_path": "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.schema.json", + "schema_sha256": "4921d75b71138d4a2ced9345cc4cb40ea0873305e3245b22f16059e3d41ebd3b" + }, + { + "id": "CK-08R1-accepted-evidence", + "path": "docs/decisions/evidence/ck08r1/answer-truth-requalification-v2.json", + "sha256": "54a5a1c2ca590e8d09591a4143ad2689d9be72be4fe0542effa5d8f3d07c4294", + "schema_path": "docs/decisions/evidence/ck08r1a/answer-truth-requalification-v2.schema.json", + "schema_sha256": "ea35833d4dcca418f5e2776002249cb55174cb73d2f70a54d1c3f1721ca03fcc" + }, + { + "id": "CK-QG1-accepted-authority", + "path": "docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json", + "sha256": "f7bedece9116beec29880bd8211e2facaaa8071d036ab13f1af217d77aa6505e", + "schema_path": "docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.schema.json", + "schema_sha256": "9290f65352718c67f6e9306350fb20c9998f225f59be64de58e9bd8397a20633" + } + ] + }, + "ck07_authorities": { + "const": [ + { + "id": "lifecycle-source-digest-v7", + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json", + "sha256": "6156780a7e8663859658bb5309f13eb6bf5283704784d8270edf0512c167d70b", + "schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json", + "schema_sha256": "4026a4e971c1b6b177b467440a36931bc6a15a0b376918bdc4169b732a0d489c" + }, + { + "id": "lifecycle-run-invocation-v6", + "path": "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", + "sha256": "6b1a2753e935da9a9c0121e4f1691957b06b388c1bc55631920725ae6d9089be", + "schema_path": "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", + "schema_sha256": "e3f24adc98078524523dcb404b9cf9d934fe6c68637abb8a5c40e2eb97ea7e74" + } + ] + }, + "states": { + "type": "object", + "required": [ + "predecessor", + "successor", + "forbidden" + ], + "additionalProperties": false, + "properties": { + "predecessor": { + "const": { + "name": "authority_main", + "status": "accepted_historical_and_current_predecessor_only", + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "presence": "required" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "presence": "absent" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "presence": "absent" + } + ] + } + }, + "successor": { + "const": { + "name": "worker_prequalification", + "status": "permitted_not_accepted", + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "presence": "required" + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "presence": "required" + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", + "presence": "required" + } + ], + "entry": "worker_prequalification_only_after_authority_merge_and_exact_main", + "runtime_acceptance": "not_claimed", + "launch_authorized": false + } + }, + "forbidden": { + "const": { + "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", + "superseded_e204_sha256": "e204e0da8f6dce7b6c4cf7a981803d2d8c08b45cb3a2ca370fe1838fd6cf2174", + "mixed_or_partial": "fail_closed", + "other_digest": "fail_closed", + "extra_cohort_artifact": "fail_closed" + } + } + } + }, + "consumer_bridge": { + "type": "object", + "required": [ + "policy", + "consumers", + "ck08r1b_history", + "ck08r1_evidence", + "ckqg1_semantics" + ], + "additionalProperties": false, + "properties": { + "policy": { + "const": "accepted_v1_bytes_remain_authoritative; only the exact complete CK-07 successor is interpreted as a successor of the accepted 7d1831ff preparation state" + }, + "consumers": { + "const": [ + "scripts/qualify_ck08r1_answer_truth.py", + "tests/kernel/test_ck08r1b_answer_semantics_join_authority.py", + "tests/kernel/test_ckqg1_maintainability_baseline_authority.py" + ] + }, + "ck08r1b_history": { + "const": "the accepted 23-path predecessor/successor cohort and all historical Git identities remain unchanged" + }, + "ck08r1_evidence": { + "const": "the accepted evidence and closure identities remain unchanged" + }, + "ckqg1_semantics": { + "const": "the accepted baseline, C/B/B thresholds, normalized findings, and writer transition remain unchanged" + } + } + }, + "launcher_safety": { + "const": { + "overlay_and_cohort_verification": "must_complete_before_ledger_fork_child_release_or_token_consumption", + "receipt_binding": "must_equal_exact_overlay_verification_result_and_three_artifact_cohort", + "post_token_or_release_failure_state": "failed_after_launch", + "aggregate_timeout_seconds": 720, + "termination_sequence": [ + "SIGTERM", + "wait_up_to_5_seconds", + "SIGKILL" + ], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none" + } + }, + "non_consuming_invariants": { + "const": { + "maximum_new_end_to_end_runs": 1, + "token_status": "unspent_unavailable", + "token_consumed": false, + "matching_processes": [], + "successful_child": "absent", + "pid": "absent", + "handshake": "absent", + "runtime_acceptance": "not_claimed", + "receipt": "absent_non_qualifying", + "output": "absent", + "ledger": "absent", + "stdout": "absent", + "stderr": "absent", + "retry": "none", + "restart": "none", + "replacement": "none", + "pr394": "stale_read_only", + "downstream": "CK-08R4_CK-08RG_CK-09_blocked", + "data_policy": "synthetic_only" + } + }, + "scope": { + "type": "object", + "required": [ + "authority_write_scope", + "combined_preflight_candidate_scope", + "forbidden" + ], + "additionalProperties": false, + "properties": { + "authority_write_scope": { + "const": [ + "AGENTS.md", + "docs/INDEX.md", + "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json", + "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.schema.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json", + "docs/roadmap/REMAINING_EXECUTION_PLAN.md", + "docs/roadmap/TASK_PACKETS.md", + "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md", + "docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md", + "scripts/check_kernel_scope.py", + "scripts/ck07r1_shared_successor_overlay.py", + "scripts/qualify_ck08r1_answer_truth.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck08r1b_answer_semantics_join_authority.py", + "tests/kernel/test_ckqg1_maintainability_baseline_authority.py", + "tests/kernel/test_documentation_authority.py", + "tests/kernel/test_kernel_scope.py", + "tests/kernel/test_lifecycle_run_invocation_authority.py" + ] + }, + "combined_preflight_candidate_scope": { + "const": [ + "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "scripts/benchmark_ck07r1_lifecycle_scale.py", + "tests/agent_kernel/publication/test_lifecycle_scale.py" + ] + }, + "forbidden": { + "const": [ + "accepted CK-08R1B v1 authority or schema edits", + "accepted CK-08R1 evidence or schema edits", + "accepted CK-QG1 authority or schema edits", + "candidate or support bytes in the authority PR", + "implementation acceptance or launch authorization", + "output, ledger, stdout, stderr, or receipt creation", + "token consumption", + "PR #394 mutation", + "CK-08R4, CK-08RG, or CK-09 readiness" + ] + } + } + }, + "negative_mutations": { + "const": [ + "rewrite any immutable accepted authority byte", + "remove or add a successor cohort artifact", + "substitute any successor digest", + "present a mixed or partial predecessor/successor cohort", + "present any extra dirty or CK-QG1-allowed path in combined preflight", + "claim post_single_run or final_accepted", + "claim runtime acceptance, launch authorization, or token consumption", + "weaken launcher overlay, receipt, failure classification, or timeout binding", + "fabricate a receipt or any output path", + "weaken the exact authority or preflight scope" + ] + } + } +} diff --git a/docs/roadmap/REMAINING_EXECUTION_PLAN.md b/docs/roadmap/REMAINING_EXECUTION_PLAN.md index 014548d9..d6a15a3a 100644 --- a/docs/roadmap/REMAINING_EXECUTION_PLAN.md +++ b/docs/roadmap/REMAINING_EXECUTION_PLAN.md @@ -93,10 +93,17 @@ run-invocation authority, and argv-correction authority are merged through `98a9b5b82951d136644a5fe5f8a70d320131ba08` failed the hosted Python 3.14 `ordinary.2000_call_tail` gate and is superseded read-only. It must not be updated, rerun, or merged. The planner-valid lifecycle receipt is an -acceptance output of the existing CK-07R1 worker only after the coordinator -records the preserved prelaunch-incident disposition and the worker -revalidates the candidate from a clean exact-main worktree. The accepted -authorities do not authorize a launch by themselves. +acceptance output of the existing CK-07R1 worker. The coordinator recorded the +preserved incident disposition and the worker derived the exact candidate +cohort from exact main `cf44f4fd`: preparation `66c015de…`, benchmark +`4b1c62b2…`, and lifecycle test `75d03f53…`. That cohort remains +permitted-not-accepted and cannot enter `worker_prequalification` until this +authority transition merges and exact-main verifies. +The versioned [shared successor overlay](../decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) +preserves the accepted CK-08R1B v1, CK-08R1 evidence, and CK-QG1 authority +bytes and reconciles only their consumers with this atomic CK-07 transition. +Predecessor-only, exact complete successor, and every mixed, partial, extra, or +other-digest state remain explicit and fail closed. The old frozen-command attempt is preserved exactly as a terminal `pre_child_argv_guard_failure` (exit 2 after `0.075241709` seconds, no child or runtime evidence), and its old benchmark/test identities cannot be reused. @@ -107,21 +114,21 @@ instrumentation mistake invoked the corrected candidate from the retained V5 witness and stopped at the child-handshake boundary. It produced only the preserved `prelaunch_failed` launch-token ledger, with `token_consumed=false`, no successful child/PID/receipt/runtime evidence, and -no retry. The witness remains read-only. CK-07R1 stays Conditional Ready until -the coordinator records an incident disposition and a clean exact-main -reapplication path; the incident does not authorize a launch or a replacement -worker. +no retry. The witness remains read-only. The incident does not authorize a +launch or replacement worker. The first sample, 720-second wrapper timeout, all five underlying budgets, one-run ceiling, and every fail-closed rule remain binding. CK-07R1 is -Conditional Ready pending the incident disposition and clean exact-main -reapplication path; until then its current authority state is `authority_main` -and no worker may resume. After that handoff only the existing stopped worker -may be resumed for required revalidation of the corrected exact candidate. The -worker may enter -`worker_prequalification` only with the exact selected successor, -`post_single_run` only with a complete planner-valid receipt and bound dynamic -evidence identity, and `final_accepted` only after worker merge and exact-main -verification. The still-unspent one-run token may fund exactly one first +Conditional Ready pending merge and exact-main verification of the exact +successor authority. Until then its current authority state is +`authority_main` at preparation `7d1831ff…` and no worker may resume. After +that handoff only the existing stopped worker may resume with the complete +`66c015de…` / `4b1c62b2…` / `75d03f53…` cohort. Historical accepted R3A +`6689d61f…`, revoked `d192c858…`, mixed cohorts, and every other digest are +predecessor-only or fail-closed and cannot enter `worker_prequalification`. +The worker may enter `worker_prequalification` only with the exact selected +cohort, `post_single_run` only with a complete planner-valid receipt and bound +dynamic evidence identity, and `final_accepted` only after worker merge and +exact-main verification. The still-unspent one-run token may fund exactly one first successful child launch after all gates pass; this is not a retry, restart, or replacement of a launched process. Earlier wording that says to resume, refresh, or rerun PR #394 is historical provenance and does not authorize action. This source-digest @@ -224,7 +231,7 @@ conditions in the table and child files; they are not unconditional DAG edges. "completed": ["CK-08R0", "CK-08R1A", "CK-08R1B", "CK-08R1C", "CK-08R1", "CK-08R2", "CK-08R3A", "CK-08R3", "CK-QG1A0", "CK-QG1A", "CK-QG1", "CK-07R1A", "CK-07R1A0"], "ready": [], "conditional_ready": [{ - "condition": "ARGV authority accepted at 479cbdb; coordinator records the preserved prelaunch incident disposition and a clean exact-main reapplication path; resume only existing worker 019fbfe2-8fe4-7de2-9264-d58572366727; no replacement, launch, or downstream task", + "condition": "exact 66c015de/4b1c62b2/75d03f53 successor authority merges and exact-main verifies; resume only existing worker 019fbfe2-8fe4-7de2-9264-d58572366727 with the atomic cohort; no replacement, launch, token consumption, or downstream task", "tasks": ["CK-07R1"] }], "blocked": [], diff --git a/docs/roadmap/TASK_PACKETS.md b/docs/roadmap/TASK_PACKETS.md index 23cb8847..b5d13195 100644 --- a/docs/roadmap/TASK_PACKETS.md +++ b/docs/roadmap/TASK_PACKETS.md @@ -15,7 +15,7 @@ parents are accounting umbrellas. - Completed corrective child tasks: **13 — CK-08R0, CK-08R1A, CK-08R1B, CK-08R1C, CK-08R1, CK-08R2, CK-08R3A, CK-08R3, CK-QG1A0, CK-QG1A, CK-QG1, CK-07R1A, CK-07R1A0** - Remaining delegable child tasks: **37** - Ready child tasks: **0** -- Conditional-ready child tasks: **1 — CK-07R1 after coordinator disposition of the preserved prelaunch incident and a clean exact-main reapplication path** +- Conditional-ready child tasks: **1 — CK-07R1 after the exact 66c015de/4b1c62b2/75d03f53 successor authority merges and exact-main verifies** - Blocked child tasks: **36** - Orchestration mode: **convergence — one coordinator, one existing task per active packet, at most one shared-authority task** - Continuation policy: **reuse the active packet task for ordinary corrections; create a task only for a newly Ready distinct packet or a genuinely new authority decision** @@ -69,7 +69,7 @@ locks are unchanged. - [x] **CK-08R3 — Qualify evidence service scale** · PR #425 hosted-green and squash-merged at `0fad272b`; both frozen synthetic profiles accepted and exact-main verified · [packet](tasks/ck-08r3-qualify-evidence-scale.md) - [x] **CK-07R1A — Correct hosted lifecycle tail** · Accepted/merged at `4d807495`; exact-main verified · [packet](tasks/ck-07r1a-correct-hosted-lifecycle-tail.md) - [x] **CK-07R1A0 — Freeze lifecycle planner/recovery path authority** · Path, finite source/runtime, run-invocation authority, and argv-correction authority merged through `479cbdb`; retained witnesses remain read-only · [packet](tasks/ck-07r1a0-freeze-lifecycle-path-authority.md) -- [ ] **CK-07R1 — Correct lifecycle preparation scale** · Conditional Ready after argv authority merge `479cbdb`, coordinator disposition of the preserved `prelaunch_failed` witness incident, and a clean exact-main reapplication path; only the existing worker may resume and no launch is yet authorized; PR #394 is stale read-only · [packet](tasks/ck-07r1-correct-lifecycle-preparation-scale.md) +- [ ] **CK-07R1 — Correct lifecycle preparation scale** · Conditional Ready after the versioned [shared successor overlay](../decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) for the exact `66c015de…` / `4b1c62b2…` / `75d03f53…` cohort merges and exact-main verifies; only the existing worker may resume and no launch is yet authorized; PR #394 is stale read-only · [packet](tasks/ck-07r1-correct-lifecycle-preparation-scale.md) - [x] **CK-QG1A — Correct page-executor complexity** · PR #408 merged/exact-main `30983d4`; authorized successor `9e80c867…` accepted without behavior or baseline change · [packet](tasks/ck-qg1a-correct-page-executor-complexity.md) - [x] **CK-QG1 — Enforce replacement-kernel maintainability** · PR #392 hosted-green, squash-merged at `68050b93`, exact-main verified, and its [v2 writer transition authority](../decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json) is linked for the reviewed PR #430 successor · [packet](tasks/ck-qg1-enforce-agent-kernel-maintainability.md) - [ ] **CK-08R4 — Reclassify physical named plans** · Blocked on CK-07R1; CK-08R1/R2/R3 are complete · [packet](tasks/ck-08r4-reclassify-physical-plans.md) diff --git a/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md b/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md index 8b1a0490..0e516a0c 100644 --- a/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md +++ b/docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md @@ -1,6 +1,7 @@ # CK-07R1 — Correct lifecycle preparation scale -**Status:** `blocked_hold`; CK-07R1 remains unlaunched until a later exact-main reapplication produces a new CK-07 preparation digest +**Status:** `blocked_hold`; the exact successor cohort is selected but remains +unlaunched and unavailable until its authority merges and exact-main verifies **Parent:** Corrective prerequisite for CK-09 @@ -27,24 +28,26 @@ contracts. **Dependencies:** CK-07R1A accepted, merged, and exact-main verified at `4d8074952f679877f2b4fbb3e89c51015e96a197`; CK-07R1A0 path authority remains historical; and the linked finite source/runtime authorities remain -`blocked_hold` with the one-run token unspent/unavailable. Exact-main -preparation `408d18e4…` is the only live source before R3A. Preparation -`e204e0da…` is permitted only inside the complete CK-08R3A cohort and is not a -direct CK-07 candidate. Historical `d192c858…` is retained read-only, revoked -for the new base, and forbidden for direct use. After accepted R3A exact-main, -the existing worker must start in a fresh worktree, deliberately reapply its -retained lifecycle diff onto the new preparation base, derive a new exact -preparation digest, and update CK-07 source authority before any end-to-end -run. PR #394 head `98a9b5b82951d136644a5fe5f8a70d320131ba08` is a stale failed +`blocked_hold` with the one-run token unspent/unavailable. Accepted R3A +preparation `6689d61f…` remains a historical predecessor and accepted +R1B/current exact-main preparation `7d1831ff…` is the live predecessor. The +existing worker's fresh exact-main `cf44f4fd` reapplication derived the sole +candidate cohort: preparation `66c015de…`, benchmark `4b1c62b2…`, and lifecycle +test `75d03f53…`. Historical `d192c858…`, mixed or incomplete cohorts, and +every other digest fail closed. PR #394 head +`98a9b5b82951d136644a5fe5f8a70d320131ba08` is a stale failed read-only witness and is not refreshed, rerun, or merged. **Owned files/interfaces:** Lifecycle preparation implementation, focused publication tests, profile/benchmark, and linked CK-07 evidence amendment; -the current authority binds the live preparation `408d18e4…`, the shared R3A -preparation `e204e0da…` only as a conditional two-state source, retained -benchmark `f173837d…`, lifecycle test `b6468b60…`, linked evidence `36eb76ca…`, -and the 720-second wrapper timeout without executing the worker. No CK-07 -successor is currently selected for runtime use. +the current authority binds predecessor preparation `7d1831ff…` to the atomic +`66c015de…` / `4b1c62b2…` / `75d03f53…` successor cohort, linked evidence +`36eb76ca…`, and the 720-second wrapper timeout without executing the worker. +The successor is permitted-not-accepted and launch remains unauthorized. +The versioned [shared successor overlay](../../decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) +preserves all accepted CK-08R1B v1, CK-08R1 evidence, and CK-QG1 authority +bytes while allowing their consumers to recognize only this exact atomic +worker-prequalification state. **Produces:** Publication-scale requalification with equivalent fold identity. @@ -54,10 +57,9 @@ database postconditions. **Consumer seam:** Preparation to `PublicationWriter` to read-only publication. **Parallelism:** Resume only the existing stopped CK-07R1 worker after the -R3A cohort is accepted and exact-main verifies, using an exact-main START, a -fresh worktree, and deliberate reapplication of only the retained lifecycle -diff onto the new R3A preparation base. Historical `d192c858…` cannot be -reapplied directly. +exact successor authority merges and exact-main verifies, using only the +preserved exact candidate worktree and complete selected cohort. Historical +`d192c858…` cannot be reapplied directly. Never rebase, stash, reset, clean, delete, overwrite, or mutate the witness; do not create a replacement worker task. The planner-valid receipt is produced by that worker diff --git a/docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md b/docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md index a0b8f26b..9b7ef700 100644 --- a/docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md +++ b/docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md @@ -1,6 +1,9 @@ # CK-07R1A0 — Freeze lifecycle planner/recovery path authority -**Status:** Completed on merge; path authority exact-main verified at `519b503aa3b23019033b6481687c08b23fc6c31e`; finite source/runtime state authority is pending merge and exact-main verification, so the existing CK-07R1 worker remains held +**Status:** Completed on merge; path authority exact-main verified at `519b503aa3b23019033b6481687c08b23fc6c31e`; +the exact CK-07 successor +source/runtime transition is pending merge and exact-main verification, so the +existing worker remains held **Release-candidate package ceilings:** sdist remains at most 2,000,000 bytes and wheel remains at most 1,000,000 bytes. The historical 828000/383000 @@ -33,16 +36,18 @@ remains accepted. contract is [lifecycle-path-authority.json](../../decisions/evidence/ck07r1a0/lifecycle-path-authority.json) with its schema. The linked [source-digest authority](../../decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json) -and its schema freeze the exact predecessor/successor transition. The retained +and its schema freeze the exact predecessor/successor transition. The +[versioned shared successor overlay](../../decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json) +preserves accepted CK-08R1B v1, CK-08R1 evidence, and CK-QG1 authority bytes +while reconciling their consumers with only the complete exact successor. The retained CK-07R1 implementation/profile/evidence diff is read-only evidence; -the shared-preparation authority binds exact-main preparation `408d18e4…` before -R3A and preparation `e204e0da…` only inside the complete R3A cohort; historical -`d192c858…` is revoked for the new base and forbidden for direct use. The -retained CK-07R1 diff must later be reapplied onto the accepted R3A base to -derive a new preparation digest before any run. It does not claim runtime -acceptance. The corrected benchmark -`f173837d…`, corrected lifecycle test `b6468b60…`, linked evidence `36eb76ca…`, and -canonical fixture identities without claiming runtime acceptance. +accepted R3A preparation `6689d61f…` remains historical, current R1B +preparation `7d1831ff…` is the live predecessor, and only the exact +`66c015de…` preparation plus `4b1c62b2…` benchmark and `75d03f53…` lifecycle +test may enter worker prequalification. Historical `d192c858…`, mixed cohorts, +and every other digest fail closed; prior R3A candidate `e204e0da…` remains +superseded and forbidden. The selected cohort does not claim runtime acceptance. +Linked evidence `36eb76ca…` and canonical fixture identities remain unchanged. The linked run-invocation authority is `docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json`; it adds no runtime implementation, freezes the corrected argv guard, @@ -81,10 +86,10 @@ Codex data. **Invariants:** CK-07R1A remains accepted at `4d807495…`; CK-07R1 remains `blocked_hold` with no launch/output/token consumption. The exact predecessor digest is -`408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872` and the +`7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb` and the permitted-not-accepted retained successor digest is -`e204e0da8f6dce7b6c4cf7a981803d2d8c08b45cb3a2ca370fe1838fd6cf2174` only as -the R3A shared-preparation state; historical +`66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea` +only with benchmark `4b1c62b2…` and lifecycle test `75d03f53…`; historical `d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1` is revoked and direct use fails closed; generic or different digest drift fails closed; linked evidence is @@ -98,9 +103,7 @@ identity/timestamp/failure remains visible; receipt `935e4427b93e67c5ca649b773b0b3895dafac87f49bc76d7ed8917dff2f0250d` remains writer-only evidence and is never reused or upgraded. The old argv-guard attempt is preserved as `pre_child_argv_guard_failure`, not a launch; no old -candidate invocation may recur. The retained lifecycle diff must be -reapplied only after accepted R3A exact-main verification and must yield a new -exact preparation digest before any run. +candidate invocation may recur. The current finite state is `authority_main`; no worker resumes from this packet, no receipt can claim qualification, and final acceptance additionally requires worker PR merge and exact-main verification. diff --git a/scripts/check_kernel_scope.py b/scripts/check_kernel_scope.py index 49b12c99..b74eaab8 100644 --- a/scripts/check_kernel_scope.py +++ b/scripts/check_kernel_scope.py @@ -830,6 +830,15 @@ } ) +CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS = frozenset( + { + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json", + "scripts/ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + } +) + CK07R1_LIFECYCLE_SCOPE_ADDITIONS = frozenset( { "scripts/benchmark_ck07r1_lifecycle_scale.py", @@ -918,6 +927,7 @@ | CKQG1_AUTHORITY_ADDITIONS | PACKAGE_BUDGET_POLICY_ADDITIONS | CK07R1A0_AUTHORITY_ADDITIONS + | CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS | CK07R1_LIFECYCLE_SCOPE_ADDITIONS | CK07R1_RUN_INVOCATION_AUTHORITY_ADDITIONS | CK08_PREREQUISITE_BLOCKER_ADDITIONS diff --git a/scripts/ck07r1_shared_successor_overlay.py b/scripts/ck07r1_shared_successor_overlay.py new file mode 100644 index 00000000..f09a0ba4 --- /dev/null +++ b/scripts/ck07r1_shared_successor_overlay.py @@ -0,0 +1,274 @@ +"""Fail-closed verifier for the versioned CK-07R1 shared-successor overlay.""" + +from __future__ import annotations + +import hashlib +import json +import subprocess +from collections.abc import Mapping +from pathlib import Path +from typing import Any + +from jsonschema import Draft202012Validator + +ROOT = Path(__file__).resolve().parents[1] +AUTHORITY_PATH = "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json" +SCHEMA_PATH = AUTHORITY_PATH.removesuffix(".json") + ".schema.json" +PREPARATION_PATH = "src/codex_usage_tracker/agent_kernel/publication/preparation.py" + + +class SharedSuccessorOverlayError(RuntimeError): + """The workspace is not an exact state admitted by the shared overlay.""" + + +def sha256_path(root: Path, relative: str) -> str | None: + """Return an exact file digest, or ``None`` when the path is absent.""" + + path = root / relative + if not path.is_file(): + return None + return hashlib.sha256(path.read_bytes()).hexdigest() + + +def load_overlay(root: Path = ROOT) -> dict[str, Any]: + """Load and schema-validate the exact versioned overlay.""" + + authority_path = root / AUTHORITY_PATH + schema_path = root / SCHEMA_PATH + authority = json.loads(authority_path.read_text(encoding="utf-8")) + schema = json.loads(schema_path.read_text(encoding="utf-8")) + Draft202012Validator.check_schema(schema) + Draft202012Validator(schema).validate(authority) + return authority + + +def verify_bound_authority_bytes( + authority: Mapping[str, Any], + root: Path = ROOT, +) -> None: + """Verify every immutable and CK-07 authority byte bound by the overlay.""" + + for section in ("immutable_authorities", "ck07_authorities"): + records = authority.get(section) + if not isinstance(records, list): + raise SharedSuccessorOverlayError(f"{section} missing") + for record in records: + if not isinstance(record, Mapping): + raise SharedSuccessorOverlayError(f"{section} record malformed") + for path_key, digest_key in ( + ("path", "sha256"), + ("schema_path", "schema_sha256"), + ): + relative = record.get(path_key) + expected = record.get(digest_key) + if not isinstance(relative, str) or not isinstance(expected, str): + raise SharedSuccessorOverlayError(f"{section} byte binding is malformed") + if sha256_path(root, relative) != expected: + raise SharedSuccessorOverlayError(f"bound authority digest drift: {relative}") + + +def observed_candidate_artifacts( + authority: Mapping[str, Any], + root: Path = ROOT, +) -> dict[str, str | None]: + """Read exactly the three paths owned by the predecessor/successor fold.""" + + states = authority.get("states") + if not isinstance(states, Mapping): + raise SharedSuccessorOverlayError("states missing") + successor = states.get("successor") + if not isinstance(successor, Mapping): + raise SharedSuccessorOverlayError("successor state missing") + artifacts = successor.get("artifacts") + if not isinstance(artifacts, list) or len(artifacts) != 3: + raise SharedSuccessorOverlayError("successor state must contain exactly three artifacts") + + observed: dict[str, str | None] = {} + for record in artifacts: + if not isinstance(record, Mapping) or not isinstance(record.get("path"), str): + raise SharedSuccessorOverlayError("successor artifact malformed") + relative = str(record["path"]) + if relative in observed: + raise SharedSuccessorOverlayError(f"duplicate successor path: {relative}") + observed[relative] = sha256_path(root, relative) + return observed + + +def _expected_state(state: Mapping[str, Any]) -> dict[str, str | None]: + artifacts = state.get("artifacts") + if not isinstance(artifacts, list) or len(artifacts) != 3: + raise SharedSuccessorOverlayError("authorized state must contain exactly three paths") + + expected: dict[str, str | None] = {} + for record in artifacts: + if not isinstance(record, Mapping) or not isinstance(record.get("path"), str): + raise SharedSuccessorOverlayError("authorized artifact malformed") + relative = str(record["path"]) + if relative in expected: + raise SharedSuccessorOverlayError(f"duplicate authorized path: {relative}") + presence = record.get("presence") + if presence == "absent": + expected[relative] = None + elif presence == "required" and isinstance(record.get("sha256"), str): + expected[relative] = str(record["sha256"]) + else: + raise SharedSuccessorOverlayError(f"invalid presence contract for {relative}") + return expected + + +def classify_observed_state( + authority: Mapping[str, Any], + observed: Mapping[str, str | None], +) -> str: + """Fold exact path presence and digests into one authorized state.""" + + states = authority.get("states") + if not isinstance(states, Mapping): + raise SharedSuccessorOverlayError("states missing") + predecessor = states.get("predecessor") + successor = states.get("successor") + if not isinstance(predecessor, Mapping) or not isinstance(successor, Mapping): + raise SharedSuccessorOverlayError("authorized states malformed") + + predecessor_expected = _expected_state(predecessor) + successor_expected = _expected_state(successor) + if set(observed) != set(successor_expected): + raise SharedSuccessorOverlayError("candidate cohort paths missing or extra") + if dict(observed) == predecessor_expected: + return str(predecessor["name"]) + if dict(observed) == successor_expected: + return str(successor["name"]) + raise SharedSuccessorOverlayError("mixed, partial, historical, or unbound CK-07R1 cohort") + + +def _git_paths(root: Path, *arguments: str) -> set[str]: + try: + result = subprocess.run( + ("git", *arguments), + cwd=root, + check=True, + capture_output=True, + text=True, + ) + except (OSError, subprocess.CalledProcessError) as exc: + raise SharedSuccessorOverlayError( + f"cannot verify exact Git delta: git {' '.join(arguments)}" + ) from exc + return {line for line in result.stdout.splitlines() if line} + + +def observed_worktree_delta(root: Path = ROOT) -> set[str]: + """Return every tracked, staged, and untracked path relative to ``HEAD``.""" + + unstaged = _git_paths(root, "diff", "--name-only", "--no-renames", "HEAD") + staged = _git_paths( + root, + "diff", + "--cached", + "--name-only", + "--no-renames", + "HEAD", + ) + untracked = _git_paths(root, "ls-files", "--others", "--exclude-standard") + return unstaged | staged | untracked + + +def expected_worktree_delta( + authority: Mapping[str, Any], + state: str, +) -> set[str]: + """Return the sole exact dirty set allowed for the classified state.""" + + scope = authority.get("scope") + if not isinstance(scope, Mapping): + raise SharedSuccessorOverlayError("overlay scope missing") + candidate_paths = scope.get("combined_preflight_candidate_scope") + if not isinstance(candidate_paths, list) or not all( + isinstance(path, str) for path in candidate_paths + ): + raise SharedSuccessorOverlayError("candidate scope malformed") + if state == "authority_main": + return set() + if state == "worker_prequalification": + return set(candidate_paths) + raise SharedSuccessorOverlayError(f"unrecognized overlay state: {state}") + + +def verify_exact_worktree_delta( + authority: Mapping[str, Any], + state: str, + root: Path = ROOT, + *, + observed: set[str] | None = None, +) -> None: + """Reject any partial, extra, staged, or otherwise hidden Git delta.""" + + actual = observed_worktree_delta(root) if observed is None else set(observed) + expected = expected_worktree_delta(authority, state) + if actual != expected: + missing = sorted(expected - actual) + extra = sorted(actual - expected) + raise SharedSuccessorOverlayError( + f"exact Git delta mismatch; missing={missing!r}; extra={extra!r}" + ) + + +def verify_launcher_safety_contract(authority: Mapping[str, Any]) -> None: + """Pin the corrected candidate's non-consuming launcher semantics.""" + + expected = { + "overlay_and_cohort_verification": ( + "must_complete_before_ledger_fork_child_release_or_token_consumption" + ), + "receipt_binding": ( + "must_equal_exact_overlay_verification_result_and_three_artifact_cohort" + ), + "post_token_or_release_failure_state": "failed_after_launch", + "aggregate_timeout_seconds": 720, + "termination_sequence": ["SIGTERM", "wait_up_to_5_seconds", "SIGKILL"], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none", + } + if authority.get("launcher_safety") != expected: + raise SharedSuccessorOverlayError("launcher safety contract drifted") + + +def verify_shared_successor_overlay( + root: Path = ROOT, +) -> tuple[dict[str, Any], str]: + """Validate authority bytes, atomic cohort, exact Git delta, and launcher gate.""" + + authority = load_overlay(root) + verify_bound_authority_bytes(authority, root) + verify_launcher_safety_contract(authority) + state = classify_observed_state( + authority, + observed_candidate_artifacts(authority, root), + ) + verify_exact_worktree_delta(authority, state, root) + return authority, state + + +def overlay_changed_path_allowance( + authority: Mapping[str, Any], + state: str, +) -> set[str]: + """Return exact base-to-HEAD paths admitted for an authority/preflight lane.""" + + scope = authority.get("scope") + if not isinstance(scope, Mapping): + raise SharedSuccessorOverlayError("overlay scope missing") + authority_paths = scope.get("authority_write_scope") + if not isinstance(authority_paths, list) or not all( + isinstance(path, str) for path in authority_paths + ): + raise SharedSuccessorOverlayError("authority write scope malformed") + + allowed = set(authority_paths) + if state == "worker_prequalification": + allowed.update(expected_worktree_delta(authority, state)) + elif state != "authority_main": + raise SharedSuccessorOverlayError(f"unrecognized overlay state: {state}") + return allowed diff --git a/scripts/qualify_ck08r1_answer_truth.py b/scripts/qualify_ck08r1_answer_truth.py index f17a2a15..941df949 100644 --- a/scripts/qualify_ck08r1_answer_truth.py +++ b/scripts/qualify_ck08r1_answer_truth.py @@ -41,6 +41,12 @@ QueryService, QueryServiceError, ) +from scripts.ck07r1_shared_successor_overlay import ( # noqa: E402 + PREPARATION_PATH as CK07R1_PREPARATION_PATH, +) +from scripts.ck07r1_shared_successor_overlay import ( # noqa: E402 + verify_shared_successor_overlay, +) from tests.agent_kernel.fixtures.independent import ( # noqa: E402 semantic as independent_semantic, ) @@ -123,6 +129,9 @@ def _git_last_touch(relative: str) -> str: def recompute_authority_identities() -> dict[str, Any]: """Recompute all R1A/B/C identities from committed authority paths.""" + overlay, overlay_state = verify_shared_successor_overlay(ROOT) + overlay_predecessor = overlay["states"]["predecessor"]["artifacts"][0]["sha256"] + overlay_successor = overlay["states"]["successor"]["artifacts"][0]["sha256"] authority = _json(JOIN_AUTHORITY) producer = authority.get("producer_authority") independent = authority.get("independent_truth_authority") @@ -176,7 +185,13 @@ def recompute_authority_identities() -> dict[str, Any]: if relative in selected_by_path: raise QualificationError(f"R1B cohort path is duplicated: {relative}") actual = sha256_file(ROOT / relative) - if actual != record.get("sha256"): + is_exact_ck07_successor = ( + overlay_state == "worker_prequalification" + and relative == CK07R1_PREPARATION_PATH + and record.get("sha256") == overlay_predecessor + and actual == overlay_successor + ) + if actual != record.get("sha256") and not is_exact_ck07_successor: raise QualificationError(f"R1B authority digest drift: {relative}") selected_by_path[relative] = record if len(selected_by_path) != 23: @@ -194,7 +209,15 @@ def recompute_authority_identities() -> dict[str, Any]: if ( successor is None or successor.get("predecessor_sha256") != accepted_digest - or successor.get("sha256") != actual + or ( + successor.get("sha256") != actual + and not ( + overlay_state == "worker_prequalification" + and relative == CK07R1_PREPARATION_PATH + and successor.get("sha256") == overlay_predecessor + and actual == overlay_successor + ) + ) ): raise QualificationError(f"R1C root has unbound successor drift: {relative}") @@ -212,6 +235,7 @@ def recompute_authority_identities() -> dict[str, Any]: "dependency_shas": dependency_shas, "authority_digests": authority_digests, "r1b_selected_paths": len(selected_by_path), + "ck07r1_overlay_state": overlay_state, } diff --git a/tests/kernel/test_ck07r1_shared_successor_overlay.py b/tests/kernel/test_ck07r1_shared_successor_overlay.py new file mode 100644 index 00000000..b5c3229c --- /dev/null +++ b/tests/kernel/test_ck07r1_shared_successor_overlay.py @@ -0,0 +1,200 @@ +from __future__ import annotations + +import json +from copy import deepcopy +from pathlib import Path + +import pytest +from jsonschema import Draft202012Validator + +from scripts.ck07r1_shared_successor_overlay import ( + ROOT, + SCHEMA_PATH, + SharedSuccessorOverlayError, + classify_observed_state, + expected_worktree_delta, + load_overlay, + observed_candidate_artifacts, + overlay_changed_path_allowance, + sha256_path, + verify_bound_authority_bytes, + verify_exact_worktree_delta, + verify_launcher_safety_contract, + verify_shared_successor_overlay, +) + + +def _state_observed( + authority: dict, + state_name: str, +) -> dict[str, str | None]: + state = authority["states"][state_name] + return { + item["path"]: None if item["presence"] == "absent" else item["sha256"] + for item in state["artifacts"] + } + + +def test_overlay_is_exact_and_live_state_is_authorized() -> None: + authority, state = verify_shared_successor_overlay() + + assert state in {"authority_main", "worker_prequalification"} + assert authority["status"] == "permitted_not_accepted" + assert authority["states"]["successor"]["status"] == "permitted_not_accepted" + assert authority["states"]["successor"]["launch_authorized"] is False + assert authority["non_consuming_invariants"] == { + "maximum_new_end_to_end_runs": 1, + "token_status": "unspent_unavailable", + "token_consumed": False, + "matching_processes": [], + "successful_child": "absent", + "pid": "absent", + "handshake": "absent", + "runtime_acceptance": "not_claimed", + "receipt": "absent_non_qualifying", + "output": "absent", + "ledger": "absent", + "stdout": "absent", + "stderr": "absent", + "retry": "none", + "restart": "none", + "replacement": "none", + "pr394": "stale_read_only", + "downstream": "CK-08R4_CK-08RG_CK-09_blocked", + "data_policy": "synthetic_only", + } + state_key = "predecessor" if state == "authority_main" else "successor" + assert observed_candidate_artifacts(authority) == _state_observed(authority, state_key) + + +def test_overlay_admits_only_the_complete_exact_successor() -> None: + authority = load_overlay() + predecessor = _state_observed(authority, "predecessor") + successor = _state_observed(authority, "successor") + + assert classify_observed_state(authority, predecessor) == "authority_main" + assert classify_observed_state(authority, successor) == "worker_prequalification" + + for path in successor: + partial = dict(successor) + partial[path] = predecessor[path] + with pytest.raises(SharedSuccessorOverlayError, match="mixed, partial"): + classify_observed_state(authority, partial) + + other = dict(successor) + other[next(iter(other))] = "0" * 64 + with pytest.raises(SharedSuccessorOverlayError, match="unbound"): + classify_observed_state(authority, other) + + missing = dict(successor) + missing.pop(next(iter(missing))) + with pytest.raises(SharedSuccessorOverlayError, match="missing or extra"): + classify_observed_state(authority, missing) + + extra = dict(successor) + extra["unexpected.py"] = "0" * 64 + with pytest.raises(SharedSuccessorOverlayError, match="missing or extra"): + classify_observed_state(authority, extra) + + +def test_overlay_schema_rejects_status_token_launch_scope_and_safety_weakening() -> None: + authority = load_overlay() + schema = json.loads((ROOT / SCHEMA_PATH).read_text(encoding="utf-8")) + validator = Draft202012Validator(schema) + mutations = [ + lambda value: value.__setitem__("status", "final_accepted"), + lambda value: value["states"]["successor"].__setitem__("launch_authorized", True), + lambda value: value["non_consuming_invariants"].__setitem__("token_consumed", True), + lambda value: value["non_consuming_invariants"].__setitem__("receipt", "fabricated"), + lambda value: value["states"]["successor"]["artifacts"].pop(), + lambda value: value["states"]["successor"]["artifacts"].append( + {"path": "extra.py", "sha256": "0" * 64, "presence": "required"} + ), + lambda value: value["scope"]["authority_write_scope"].append( + "src/codex_usage_tracker/agent_kernel/publication/writer.py" + ), + lambda value: value["scope"]["combined_preflight_candidate_scope"].pop(), + lambda value: value["launcher_safety"].__setitem__( + "overlay_and_cohort_verification", "after_ledger" + ), + lambda value: value["launcher_safety"].__setitem__("receipt_binding", "optional"), + lambda value: value["launcher_safety"].__setitem__( + "post_token_or_release_failure_state", "prelaunch_failed" + ), + lambda value: value["launcher_safety"].__setitem__("final_reap_timeout_seconds", 0), + ] + for mutate in mutations: + changed = deepcopy(authority) + mutate(changed) + assert list(validator.iter_errors(changed)) + + +def test_overlay_rejects_any_immutable_v1_rewrite( + monkeypatch: pytest.MonkeyPatch, +) -> None: + authority = load_overlay() + original = sha256_path + first = authority["immutable_authorities"][0]["path"] + + def changed_digest(root: Path, relative: str) -> str | None: + if relative == first: + return "0" * 64 + return original(root, relative) + + monkeypatch.setattr( + "scripts.ck07r1_shared_successor_overlay.sha256_path", + changed_digest, + ) + with pytest.raises(SharedSuccessorOverlayError, match="digest drift"): + verify_bound_authority_bytes(authority) + + +def test_overlay_requires_exact_all_or_none_git_delta() -> None: + authority = load_overlay() + candidate = set(authority["scope"]["combined_preflight_candidate_scope"]) + + assert expected_worktree_delta(authority, "authority_main") == set() + assert expected_worktree_delta(authority, "worker_prequalification") == candidate + verify_exact_worktree_delta(authority, "authority_main", observed=set()) + verify_exact_worktree_delta( + authority, + "worker_prequalification", + observed=candidate, + ) + + with pytest.raises(SharedSuccessorOverlayError, match="missing="): + verify_exact_worktree_delta( + authority, + "worker_prequalification", + observed=candidate - {next(iter(candidate))}, + ) + with pytest.raises(SharedSuccessorOverlayError, match="extra="): + verify_exact_worktree_delta( + authority, + "worker_prequalification", + observed=candidate | {"src/codex_usage_tracker/agent_kernel/publication/writer.py"}, + ) + with pytest.raises(SharedSuccessorOverlayError, match="extra="): + verify_exact_worktree_delta( + authority, + "worker_prequalification", + observed=candidate + | {"docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json"}, + ) + + +def test_overlay_scope_and_launcher_contract_are_exact() -> None: + authority = load_overlay() + predecessor = overlay_changed_path_allowance(authority, "authority_main") + successor = overlay_changed_path_allowance(authority, "worker_prequalification") + candidate = set(authority["scope"]["combined_preflight_candidate_scope"]) + + assert successor == predecessor | candidate + assert candidate.isdisjoint(predecessor) + assert "src/codex_usage_tracker/agent_kernel/publication/writer.py" not in successor + verify_launcher_safety_contract(authority) + + weakened = deepcopy(authority) + weakened["launcher_safety"]["termination_sequence"] = ["SIGTERM"] + with pytest.raises(SharedSuccessorOverlayError, match="safety"): + verify_launcher_safety_contract(weakened) diff --git a/tests/kernel/test_ck08r1b_answer_semantics_join_authority.py b/tests/kernel/test_ck08r1b_answer_semantics_join_authority.py index fe7b3af8..e8f43425 100644 --- a/tests/kernel/test_ck08r1b_answer_semantics_join_authority.py +++ b/tests/kernel/test_ck08r1b_answer_semantics_join_authority.py @@ -8,6 +8,11 @@ import pytest from jsonschema import Draft202012Validator +from scripts.ck07r1_shared_successor_overlay import ( + PREPARATION_PATH, + verify_shared_successor_overlay, +) + ROOT = Path(__file__).resolve().parents[2] AUTHORITY_PATH = ( ROOT / "docs/decisions/evidence/ck08r1b/answer-semantics-join-authority.json" @@ -267,10 +272,23 @@ def test_successor_cohort_is_all_or_none_and_rejects_unbound_bytes() -> None: files = authority["selected_successor_cohort"]["files"] assert isinstance(files, list) observed = {item["path"]: _sha256(item["path"]) for item in files} - state = _cohort_state(files, observed) + overlay, overlay_state = verify_shared_successor_overlay(ROOT) + bound_observed = dict(observed) + if overlay_state == "worker_prequalification": + preparation = next(item for item in files if item["path"] == PREPARATION_PATH) + assert preparation["sha256"] == overlay["states"]["predecessor"]["artifacts"][0][ + "sha256" + ] + assert observed[PREPARATION_PATH] == overlay["states"]["successor"]["artifacts"][0][ + "sha256" + ] + bound_observed[PREPARATION_PATH] = preparation["sha256"] + + state = _cohort_state(files, bound_observed) assert state in {"predecessor", "successor"} + assert overlay_state in {"authority_main", "worker_prequalification"} - mixed = dict(observed) + mixed = dict(bound_observed) mixed[files[0]["path"]] = ( files[0]["sha256"] if state == "predecessor" @@ -279,7 +297,7 @@ def test_successor_cohort_is_all_or_none_and_rejects_unbound_bytes() -> None: with pytest.raises(AssertionError, match="mixed predecessor/successor"): _cohort_state(files, mixed) - unbound = dict(observed) + unbound = dict(bound_observed) unbound[files[0]["path"]] = "0" * 64 with pytest.raises(AssertionError, match="unbound cohort identity"): _cohort_state(files, unbound) diff --git a/tests/kernel/test_ckqg1_maintainability_baseline_authority.py b/tests/kernel/test_ckqg1_maintainability_baseline_authority.py index 6b62e603..83ca9bf6 100644 --- a/tests/kernel/test_ckqg1_maintainability_baseline_authority.py +++ b/tests/kernel/test_ckqg1_maintainability_baseline_authority.py @@ -9,6 +9,10 @@ from jsonschema import Draft202012Validator from scripts.check_kernel_scope import authority_changed_path_failures +from scripts.ck07r1_shared_successor_overlay import ( + overlay_changed_path_allowance, + verify_shared_successor_overlay, +) _REPO_ROOT = Path(__file__).resolve().parents[2] _AUTHORITY_PATH = "docs/decisions/evidence/ckqg1/maintainability-baseline-transition-authority.json" @@ -162,10 +166,14 @@ def test_ckqg1_authority_is_exact_and_binds_the_selected_successor() -> None: ] changed_paths = _changed_paths(authority["authority_base_sha"]) allowed_paths = set(scope["authority_write_scope"]) - assert changed_paths <= allowed_paths - assert authority_changed_path_failures(changed_paths, allowed_paths) == [] + overlay, overlay_state = verify_shared_successor_overlay(_REPO_ROOT) + overlay_paths = overlay_changed_path_allowance(overlay, overlay_state) + ckqg1_changed_paths = changed_paths - overlay_paths + assert ckqg1_changed_paths <= allowed_paths + assert authority_changed_path_failures(ckqg1_changed_paths, allowed_paths) == [] assert authority_changed_path_failures( - changed_paths | {"src/codex_usage_tracker/agent_kernel/publication/writer.py"}, + ckqg1_changed_paths + | {"src/codex_usage_tracker/agent_kernel/publication/writer.py"}, allowed_paths, ) == [ "authority scope forbids changed path: " diff --git a/tests/kernel/test_documentation_authority.py b/tests/kernel/test_documentation_authority.py index f6b525b2..fe449b51 100644 --- a/tests/kernel/test_documentation_authority.py +++ b/tests/kernel/test_documentation_authority.py @@ -239,9 +239,9 @@ def test_remaining_execution_plan_is_complete_acyclic_and_fail_closed() -> None: assert manifest["conditional_ready"] == [ { "condition": ( - "ARGV authority accepted at 479cbdb; coordinator records the preserved prelaunch incident " - "disposition and a clean exact-main reapplication path; resume only existing worker " - "019fbfe2-8fe4-7de2-9264-d58572366727; no replacement, launch, or downstream task" + "exact 66c015de/4b1c62b2/75d03f53 successor authority merges and exact-main " + "verifies; resume only existing worker 019fbfe2-8fe4-7de2-9264-d58572366727 " + "with the atomic cohort; no replacement, launch, token consumption, or downstream task" ), "tasks": ["CK-07R1"], }, @@ -481,13 +481,18 @@ def test_remaining_execution_plan_is_complete_acyclic_and_fail_closed() -> None: } elif artifact["path"] == "src/codex_usage_tracker/agent_kernel/publication/preparation.py": final = _json("docs/decisions/evidence/ck08r3a/final-shared-authority.json") - selected = final["ck07_shared_preparation"]["r3a_atomic_cohort"]["sha256"] + r3a_selected = final["ck07_shared_preparation"]["r3a_atomic_cohort"]["sha256"] + source_authority = _json( + "docs/decisions/evidence/ck07r1a0/lifecycle-source-digest-authority.json" + ) + ck07_selected = source_authority["selected_successor"] assert actual in { artifact["sha256"], - selected, - _ck08r1b_selected_hashes()[artifact["path"]], + r3a_selected, + source_authority["predecessor"]["sha256"], + ck07_selected["sha256"], } - if actual == selected: + if actual == r3a_selected: for required in ( final["r3a"]["selected"]["production_identities"] + final["r3a"]["selected"]["support_identities"] @@ -499,6 +504,11 @@ def test_remaining_execution_plan_is_complete_acyclic_and_fail_closed() -> None: elif required["path"] == "tests/agent_kernel/fact_adapters/support.py": expected.add(_ck08r1b_selected_hashes()[required["path"]]) assert hashlib.sha256(required_path.read_bytes()).hexdigest() in expected + elif actual == ck07_selected["sha256"]: + for required in ck07_selected["artifacts"]: + required_path = _REPO_ROOT / required["path"] + assert required_path.is_file() + assert hashlib.sha256(required_path.read_bytes()).hexdigest() == required["sha256"] elif artifact["path"] in { "config/agent-kernel/formula-contract-v1.json", "config/agent-kernel/plan-operand-contract-v1.json", @@ -1030,24 +1040,42 @@ def test_ck07r1a0_source_digest_authority_is_exact_and_fail_closed() -> None: validator = Draft202012Validator(schema) validator.validate(authority) - assert authority["schema"] == "codex-usage-tracker.lifecycle-source-digest-authority.v6" - assert authority["authority_version"] == 6 - assert authority["authority_base_sha"] == "7d5a4b1717db78891fd2c38d8803d7fe2f922986" + assert authority["schema"] == "codex-usage-tracker.lifecycle-source-digest-authority.v7" + assert authority["authority_version"] == 7 + assert authority["authority_base_sha"] == "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" assert authority["status"] == "blocked_hold" assert authority["predecessor"]["sha256"] == ( - "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872" + "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb" ) assert authority["selected_successor"] == { - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", "status": "permitted_not_accepted", - "role": "selected_r3a_atomic_cohort_preparation", - "base_sha": "7d5a4b1717db78891fd2c38d8803d7fe2f922986", - "requires_full_r3a_cohort": True, - "direct_ck07_use": "forbidden", + "role": "selected_ck07_exact_candidate", + "base_sha": "cf44f4fdd3f54ad53263b5e744203be468fbe5ca", + "requires_full_candidate_cohort": True, + "direct_ck07_use": "worker_prequalification_only_after_authority_exact_main", "mixed_state": "fail_closed", "runtime_acceptance": "not_claimed", + "launch_authorized": False, + "artifacts": [ + { + "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source", + }, + { + "path": "scripts/benchmark_ck07r1_lifecycle_scale.py", + "sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "role": "benchmark", + }, + { + "path": "tests/agent_kernel/publication/test_lifecycle_scale.py", + "sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", + "role": "lifecycle_test", + }, + ], } - assert authority["acceptance_state"]["status"] == "conditional_two_state_no_run" + assert authority["acceptance_state"]["status"] == "exact_successor_selected_no_run" assert authority["acceptance_state"]["direct_use_of_d192"] == "forbidden" assert authority["superseded_r3a_candidate"]["sha256"].startswith("e204e0da") assert authority["historical_candidate"] == { @@ -1063,8 +1091,8 @@ def test_ck07r1a0_source_digest_authority_is_exact_and_fail_closed() -> None: assert authority["state_machine_binding"]["current_state"] == "authority_main" assert [state["name"] for state in authority["state_machine_binding"]["states"]] == [ "authority_main", - "r3a_worker_prequalification", - "ck07_requalification", + "r3a_accepted_predecessor", + "worker_prequalification", ] assert authority["state_machine_binding"]["other_digest"] == "fail_closed" assert authority["state_machine_binding"]["launch_state"] == "blocked_hold_no_run" @@ -1079,28 +1107,24 @@ def test_ck07r1a0_source_digest_authority_is_exact_and_fail_closed() -> None: assert actual_source in { authority["predecessor"]["sha256"], authority["selected_successor"]["sha256"], - _ck08r1b_selected_hashes()[ - "src/codex_usage_tracker/agent_kernel/publication/preparation.py" - ], } if actual_source == authority["selected_successor"]["sha256"]: - final = _json("docs/decisions/evidence/ck08r3a/final-shared-authority.json") - for required in ( - final["r3a"]["selected"]["production_identities"] - + final["r3a"]["selected"]["support_identities"] - ): + for required in authority["selected_successor"]["artifacts"]: required_path = _REPO_ROOT / required["path"] - expected = {required["sha256"]} - if required["path"] == "tests/agent_kernel/evidence/test_service.py": - expected = {_portable_selected_support_hashes()[required["path"]]} - elif required["path"] == "tests/agent_kernel/fact_adapters/support.py": - expected.add(_ck08r1b_selected_hashes()[required["path"]]) - assert hashlib.sha256(required_path.read_bytes()).hexdigest() in expected + assert required_path.is_file() + assert hashlib.sha256(required_path.read_bytes()).hexdigest() == required["sha256"] mutations = [ ("selected_successor", "sha256", "0" * 64), ("selected_successor", "direct_ck07_use", "allow"), - ("selected_successor", "requires_full_r3a_cohort", False), + ("selected_successor", "requires_full_candidate_cohort", False), + ("selected_successor", "launch_authorized", True), + ("selected_successor", "runtime_acceptance", "accepted"), + ( + "selected_successor", + "artifacts", + authority["selected_successor"]["artifacts"][:-1], + ), ("acceptance_state", "mixed_state", "allow"), ("state_machine_binding", "other_digest", "allow"), ("state_machine_binding", "launch_state", "ready"), diff --git a/tests/kernel/test_kernel_scope.py b/tests/kernel/test_kernel_scope.py index 80830963..a95bd6f6 100644 --- a/tests/kernel/test_kernel_scope.py +++ b/tests/kernel/test_kernel_scope.py @@ -20,6 +20,7 @@ CK07E_INDEPENDENT_FACT_ADAPTER_ADDITIONS, CK07R1_LIFECYCLE_SCOPE_ADDITIONS, CK07R1_RUN_INVOCATION_AUTHORITY_ADDITIONS, + CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS, CK07R1A0_AUTHORITY_ADDITIONS, CK08_PREREQUISITE_BLOCKER_ADDITIONS, CK08_QUERY_EVIDENCE_ADDITIONS, @@ -695,6 +696,7 @@ def test_k6_additions_are_explicit_and_bounded() -> None: | CKQG1_AUTHORITY_ADDITIONS | PACKAGE_BUDGET_POLICY_ADDITIONS | CK07R1A0_AUTHORITY_ADDITIONS + | CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS | CK07R1_LIFECYCLE_SCOPE_ADDITIONS | CK07R1_RUN_INVOCATION_AUTHORITY_ADDITIONS | CK08_PREREQUISITE_BLOCKER_ADDITIONS @@ -788,6 +790,15 @@ def test_ck07r1a0_authority_and_lifecycle_scope_additions_are_explicit() -> None } == CK07R1_LIFECYCLE_SCOPE_ADDITIONS +def test_ck07r1_shared_overlay_additions_are_explicit_and_bounded() -> None: + assert { + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.json", + "docs/decisions/evidence/ck07r1a0/shared-successor-overlay-authority-v1.schema.json", + "scripts/ck07r1_shared_successor_overlay.py", + "tests/kernel/test_ck07r1_shared_successor_overlay.py", + } == CK07R1_SHARED_OVERLAY_AUTHORITY_ADDITIONS + + def test_kernel_skeleton_imports_without_legacy_runtime() -> None: import codex_usage_tracker.kernel as kernel diff --git a/tests/kernel/test_lifecycle_run_invocation_authority.py b/tests/kernel/test_lifecycle_run_invocation_authority.py index bb69c44f..86bb5b65 100644 --- a/tests/kernel/test_lifecycle_run_invocation_authority.py +++ b/tests/kernel/test_lifecycle_run_invocation_authority.py @@ -16,7 +16,9 @@ _ROOT = Path(__file__).resolve().parents[2] _AUTHORITY_PATH = _ROOT / "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json" -_SCHEMA_PATH = _ROOT / "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json" +_SCHEMA_PATH = ( + _ROOT / "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json" +) def _authority() -> dict[str, Any]: @@ -87,12 +89,19 @@ def test_corrected_argv_guard_accepts_exact_candidate_in_real_non_launching_subp _ROOT.parents[1] / authority["selected_candidate"]["retained_worktree"], ] candidate = next( - (root / relative_candidate for root in candidate_roots if (root / relative_candidate).is_file()), + ( + root / relative_candidate + for root in candidate_roots + if (root / relative_candidate).is_file() + ), None, ) if candidate is None: pytest.skip("the retained candidate is unavailable until the worker reapplies it") - assert hashlib.sha256(candidate.read_bytes()).hexdigest() == authority["selected_candidate"]["artifacts"][1]["sha256"] + assert ( + hashlib.sha256(candidate.read_bytes()).hexdigest() + == authority["selected_candidate"]["artifacts"][1]["sha256"] + ) candidate_copy = tmp_path / relative_candidate candidate_copy.parent.mkdir(parents=True) candidate_copy.write_bytes(candidate.read_bytes()) @@ -165,8 +174,8 @@ def test_argv_correction_preserves_first_failure_and_one_run_gate() -> None: assert correction["old_guard"] == "sys.argv[1:] == LAUNCH_COMMAND[1:]" assert correction["corrected_guard"] == "(sys.argv[0], *sys.argv[1:]) == LAUNCH_COMMAND[1:]" assert correction["corrected_candidate_artifacts"] == { - "benchmark_sha256": "f173837d71e393e53e13f0253f3f1ede4045befb5dab2cbf81d6fe147be4b47a", - "lifecycle_test_sha256": "b6468b609dd7e47462d4e0c958f33d37d876959c90fb17ae02d64c3d18c22eed", + "benchmark_sha256": "4b1c62b2d56bf808b66f47c71b1bb1fa3595e2d590d0fa0192b5f7be3b2b4dde", + "lifecycle_test_sha256": "75d03f5346ffe2d02ffedc5df007ce45bef5533b324202ccf41b535de8b33cd2", } assert correction["old_candidate_artifacts"]["reuse"] == "forbidden" assert correction["non_launching_subprocess_test"]["required"] is True @@ -192,15 +201,15 @@ def test_argv_correction_preserves_first_failure_and_one_run_gate() -> None: } -def test_selected_candidate_is_r3a_shared_preparation_only_and_ck07_stays_blocked() -> None: +def test_selected_candidate_is_exact_ck07_cohort_and_runtime_stays_blocked() -> None: authority = _authority() candidate = authority["selected_candidate"] - assert authority["schema"] == "codex-usage-tracker.lifecycle-run-invocation-authority.v5" - assert authority["authority_version"] == 5 - assert authority["authority_base_sha"] == "7d5a4b1717db78891fd2c38d8803d7fe2f922986" + assert authority["schema"] == "codex-usage-tracker.lifecycle-run-invocation-authority.v6" + assert authority["authority_version"] == 6 + assert authority["authority_base_sha"] == "cf44f4fdd3f54ad53263b5e744203be468fbe5ca" assert authority["status"] == "blocked_no_run" assert authority["shared_preparation_binding"] == { - "authority_main_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", + "authority_main_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", "r3a_atomic_cohort_sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", "historical_d192_sha256": "d192c858b48e44b5aa7a7e39ef524e5ec2f08085655fe485639f5e875a727aa1", "r3a_requires_complete_cohort": True, @@ -211,21 +220,24 @@ def test_selected_candidate_is_r3a_shared_preparation_only_and_ck07_stays_blocke "launch_authorized": False, } assert authority["historical_d192"]["direct_use"] == "forbidden" - assert candidate["status"] == "r3a_shared_preparation_not_ck07_candidate" + assert candidate["status"] == "exact_ck07_successor_permitted_not_accepted" assert candidate["base_sha"] == authority["authority_base_sha"] assert candidate["source_successor_sha256"] == ( - "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c" + "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea" + ) + assert candidate["requires_complete_candidate_cohort"] is True + assert candidate["direct_ck07_use"] == ( + "worker_prequalification_only_after_authority_exact_main" ) - assert candidate["requires_complete_r3a_cohort"] is True - assert candidate["direct_ck07_use"] == "forbidden" assert candidate["launch_authorized"] is False assert candidate["artifacts"][0] == { "path": "src/codex_usage_tracker/agent_kernel/publication/preparation.py", - "sha256": "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c", - "role": "r3a_shared_preparation_not_ck07_source", + "sha256": "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea", + "role": "source", } assert candidate["binding"] == ( - "r3a_preparation_is_not_a_ck07_candidate; complete_cohort_required_before_ck07_reapplication" + "only the byte-exact 66c015de/4b1c62b2/75d03f53 cohort may enter " + "worker_prequalification after this authority merges and exact-main verifies" ) assert authority["run_token"]["status"] == "unspent_unavailable" assert authority["run_token"]["maximum_new_end_to_end_runs"] == 1 @@ -243,17 +255,17 @@ def test_finite_source_runtime_state_machine_is_exact_and_currently_unlaunched() ] assert machine["states"][0] == { "name": "authority_main", - "source_sha256": "408d18e44c87da234d220c29298ebac1780e9426e2dce767b0bfc3ae65e8a872", - "source_role": "live_predecessor", + "source_sha256": "7d1831ff5229e8e2a9819f0bd155d116ad97c3c3579bfa0444f791fe81e81feb", + "source_role": "accepted_current_r1b_predecessor", "runtime_acceptance": "not_claimed", "receipt_policy": "receipt_absent_and_non_qualifying", "evidence_identity_policy": "not_available", "merge_policy": "current_authority_state", } assert machine["states"][1]["source_sha256"] == ( - "6689d61fbf6d7948e1958a9d0bc58b4ea326a7f04221914b74c0651e0be1e37c" + "66c015de949a6c380bd49964cb6c48c30dee64ecb14074b480837c44024328ea" ) - assert machine["states"][1]["source_role"] == "selected_r3a_atomic_cohort_preparation" + assert machine["states"][1]["source_role"] == "selected_ck07_exact_candidate" assert machine["states"][1]["runtime_acceptance"] == "not_claimed" assert machine["states"][2]["receipt_policy"] == "complete_planner_valid_receipt_required" assert machine["states"][2]["evidence_identity_policy"] == ( @@ -262,7 +274,9 @@ def test_finite_source_runtime_state_machine_is_exact_and_currently_unlaunched() assert machine["states"][3]["merge_policy"] == ( "worker_pr_squash_merge_and_exact_main_verification_required" ) - assert [transition["from"] + "->" + transition["to"] for transition in machine["transitions"]] == [ + assert [ + transition["from"] + "->" + transition["to"] for transition in machine["transitions"] + ] == [ "authority_main->worker_prequalification", "worker_prequalification->post_single_run", "post_single_run->final_accepted", @@ -358,7 +372,10 @@ def test_fixture_identity_vocabulary_and_static_file_shas_are_distinct_and_prove "fixture_file_sha256", "workload_transition_digest", } - assert identity["manifest"]["fixture_manifest_digest"] != identity["manifest"]["fixture_file_sha256"] + assert ( + identity["manifest"]["fixture_manifest_digest"] + != identity["manifest"]["fixture_file_sha256"] + ) assert identity["rejected_dispatch_values"] == [ { "value": "e8c79373697ebe2af5385dbb2899ae49cec61037c4a3b0909f91225128e0bc", @@ -452,6 +469,7 @@ def test_profiles_samples_counts_seed_and_tail_limits_are_frozen() -> None: "model_call_tail_rows": 32000, } + def test_reachable_path_and_plan_identity_are_explicit() -> None: path = _authority()["launch_contract"]["reachable_path"] assert path["ordered_steps"] == [ @@ -468,6 +486,29 @@ def test_reachable_path_and_plan_identity_are_explicit() -> None: assert path["failure"].startswith("any path") +def test_corrected_launcher_safety_contract_is_exact() -> None: + safety = _authority()["launch_contract"]["launcher_safety"] + + assert safety == { + "overlay_and_cohort_verification": ( + "must_complete_before_ledger_fork_child_release_or_token_consumption" + ), + "receipt_binding": ( + "must_equal_exact_overlay_verification_result_and_three_artifact_cohort" + ), + "post_token_or_release_failure_state": "failed_after_launch", + "termination_sequence": [ + "SIGTERM", + "wait_up_to_5_seconds", + "SIGKILL", + ], + "final_reap_timeout_seconds": 5, + "retry": "none", + "restart": "none", + "replacement": "none", + } + + def test_process_exclusion_launch_token_and_evidence_capture_are_required() -> None: authority = _authority() prelaunch = authority["launch_gates"]["prelaunch"] @@ -495,7 +536,7 @@ def test_process_exclusion_launch_token_and_evidence_capture_are_required() -> N "refund": False, "prior_identities_reused": False, "concurrent_processes_allowed": False, - "eligibility": "only after this authority merges and exact-main verifies, the stopped existing worker deliberately reapplies only the corrected exact candidate, and all gates pass", + "eligibility": "only after this authority merges and exact-main verifies, the stopped existing worker resumes only the preserved exact 66c015de/4b1c62b2/75d03f53 candidate cohort, and all gates pass", "first_successful_launch": "exactly one first successful child launch may consume the still-unspent token; this is not a retry, restart, or replacement of a launched process", "old_candidate_reuse": "forbidden", } @@ -508,11 +549,15 @@ def test_no_retry_semantics_and_candidate_blocker_are_explicit() -> None: assert after_launch["no_restart"] is True assert after_launch["no_replacement"] is True assert after_launch["token_remains_consumed"] is True - assert {"interruption", "timeout", "incomplete receipt", "budget miss", "postcondition failure"} <= set( - after_launch["failures"] - ) + assert { + "interruption", + "timeout", + "incomplete receipt", + "budget miss", + "postcondition failure", + } <= set(after_launch["failures"]) feasibility = authority["feasibility"] - assert feasibility["candidate_status"] == "corrected_no_run_runtime_unqualified" + assert feasibility["candidate_status"] == "exact_successor_bound_no_run_runtime_unqualified" assert "planner-valid receipt" in feasibility["exact_blocker"] assert feasibility["run_action"].startswith("do not execute") @@ -521,41 +566,150 @@ def test_no_retry_semantics_and_candidate_blocker_are_explicit() -> None: ("label", "path", "replacement"), [ ("old-argv-guard", ("argv_correction", "old_guard"), "sys.argv == LAUNCH_COMMAND"), - ("corrected-argv-guard", ("argv_correction", "corrected_guard"), "sys.argv[1:] == LAUNCH_COMMAND[1:]"), - ("first-failure-classification", ("first_failure", "classification"), "successful_process_launch"), + ( + "corrected-argv-guard", + ("argv_correction", "corrected_guard"), + "sys.argv[1:] == LAUNCH_COMMAND[1:]", + ), + ( + "first-failure-classification", + ("first_failure", "classification"), + "successful_process_launch", + ), ("first-failure-exit", ("first_failure", "exit_code"), 0), ("first-failure-token-evidence", ("first_failure", "evidence", "token"), "consumed"), - ("exclusive-output-path", ("launch_contract", "output", "exclusive_paths", "ledger"), "output/other.json"), + ( + "exclusive-output-path", + ("launch_contract", "output", "exclusive_paths", "ledger"), + "output/other.json", + ), ("old-candidate-reuse", ("run_token", "old_candidate_reuse"), "allowed"), ("merge-sha-invention", ("change_control", "merged_sha"), "0" * 40), ("command", ("launch_contract", "repository_relative_command", 1), "wrong.py"), ("cwd", ("launch_contract", "required_cwd"), "scripts"), - ("fixture-vocabulary", ("launch_contract", "fixture_identity", "vocabulary", "fixture_file_sha256"), "manifest"), - ("fixture-digest-binding", ("launch_contract", "fixture_identity", "manifest", "fixture_file_sha256"), "0" * 64), + ( + "fixture-vocabulary", + ("launch_contract", "fixture_identity", "vocabulary", "fixture_file_sha256"), + "manifest", + ), + ( + "fixture-digest-binding", + ("launch_contract", "fixture_identity", "manifest", "fixture_file_sha256"), + "0" * 64, + ), ("aggregate-timeout", ("launch_contract", "aggregate_timeout", "seconds"), 120), + ( + "overlay-after-ledger", + ( + "launch_contract", + "launcher_safety", + "overlay_and_cohort_verification", + ), + "after_ledger", + ), + ( + "receipt-unbound", + ("launch_contract", "launcher_safety", "receipt_binding"), + "optional", + ), + ( + "post-token-prelaunch-label", + ( + "launch_contract", + "launcher_safety", + "post_token_or_release_failure_state", + ), + "prelaunch_failed", + ), + ( + "unbounded-reap", + ( + "launch_contract", + "launcher_safety", + "final_reap_timeout_seconds", + ), + 0, + ), ("candidate-benchmark", ("selected_candidate", "artifacts", 1, "sha256"), "0" * 64), - ("rejected-dispatch", ("launch_contract", "fixture_identity", "rejected_dispatch_values", 0, "status"), "used"), + ("candidate-launch-authorization", ("selected_candidate", "launch_authorized"), True), + ("shared-launch-authorization", ("shared_preparation_binding", "launch_authorized"), True), + ("candidate-runtime-acceptance", ("selected_candidate", "runtime_acceptance"), "accepted"), + ( + "rejected-dispatch", + ("launch_contract", "fixture_identity", "rejected_dispatch_values", 0, "status"), + "used", + ), ("output-overwrite", ("launch_contract", "output", "overwrite_rule"), "overwrite"), - ("process-exclusion", ("launch_gates", "prelaunch", "required", 3), "process check omitted"), + ( + "process-exclusion", + ("launch_gates", "prelaunch", "required", 3), + "process check omitted", + ), ("run-token-timing", ("run_token", "consumption"), "before launch"), + ("run-token-status", ("run_token", "status"), "spent"), ("no-retry", ("failure_matrix", "after_launch", "no_retry"), False), ("tail-limit", ("launch_contract", "tail_limits", "values", "observations"), 12001), ("count", ("launch_contract", "profiles", "workloads", 0, "observations"), 1370), ("seed", ("launch_contract", "profiles", "seed"), 42), - ("reachable-path", ("launch_contract", "reachable_path", "ordered_steps", 2), "direct writer"), + ( + "reachable-path", + ("launch_contract", "reachable_path", "ordered_steps", 2), + "direct writer", + ), ("generic-drift", ("preserved_history", "source_predecessor_sha256"), "0" * 64), ("current-state", ("lifecycle_state_machine", "current_state"), "worker_prequalification"), ("successor-drift", ("lifecycle_state_machine", "states", 1, "source_sha256"), "0" * 64), ("receipt-bypass", ("lifecycle_state_machine", "states", 2, "receipt_policy"), "optional"), - ("post-run-no-receipt-qualification", ("lifecycle_state_machine", "states", 2, "runtime_acceptance"), "accepted"), - ("final-no-receipt-acceptance", ("lifecycle_state_machine", "states", 3, "receipt_policy"), "optional"), - ("final-no-evidence-acceptance", ("lifecycle_state_machine", "states", 3, "evidence_identity_policy"), "not_available"), - ("final-merge-bypass", ("lifecycle_state_machine", "states", 3, "merge_policy"), "optional"), - ("transition-bypass", ("lifecycle_state_machine", "transitions", 0, "to"), "final_accepted"), - ("receipt-path-drift", ("lifecycle_state_machine", "dynamic_receipt_identity", "identity_paths", "output_sha256"), "receipt.output_file_sha256"), - ("receipt-ledger-drift", ("lifecycle_state_machine", "dynamic_receipt_identity", "ledger_path"), "output/other.json"), - ("fixture-inventory-omission", ("launch_contract", "fixture_identity", "fixture_files", 0), None), - ("fixture-inventory-digest", ("launch_contract", "fixture_identity", "fixture_files", 1, "fixture_file_sha256"), "0" * 64), + ( + "post-run-no-receipt-qualification", + ("lifecycle_state_machine", "states", 2, "runtime_acceptance"), + "accepted", + ), + ( + "final-no-receipt-acceptance", + ("lifecycle_state_machine", "states", 3, "receipt_policy"), + "optional", + ), + ( + "final-no-evidence-acceptance", + ("lifecycle_state_machine", "states", 3, "evidence_identity_policy"), + "not_available", + ), + ( + "final-merge-bypass", + ("lifecycle_state_machine", "states", 3, "merge_policy"), + "optional", + ), + ( + "transition-bypass", + ("lifecycle_state_machine", "transitions", 0, "to"), + "final_accepted", + ), + ( + "receipt-path-drift", + ( + "lifecycle_state_machine", + "dynamic_receipt_identity", + "identity_paths", + "output_sha256", + ), + "receipt.output_file_sha256", + ), + ( + "receipt-ledger-drift", + ("lifecycle_state_machine", "dynamic_receipt_identity", "ledger_path"), + "output/other.json", + ), + ( + "fixture-inventory-omission", + ("launch_contract", "fixture_identity", "fixture_files", 0), + None, + ), + ( + "fixture-inventory-digest", + ("launch_contract", "fixture_identity", "fixture_files", 1, "fixture_file_sha256"), + "0" * 64, + ), ], ) def test_negative_contract_mutations_fail_closed( @@ -574,8 +728,12 @@ def test_dag_ledger_index_and_scope_bind_the_authority_without_new_task() -> Non index = (_ROOT / "docs/INDEX.md").read_text(encoding="utf-8") central = (_ROOT / "docs/roadmap/REMAINING_EXECUTION_PLAN.md").read_text(encoding="utf-8") ledger = (_ROOT / "docs/roadmap/TASK_PACKETS.md").read_text(encoding="utf-8") - packet = (_ROOT / "docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md").read_text(encoding="utf-8") - ck07r1 = (_ROOT / "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md").read_text(encoding="utf-8") + packet = (_ROOT / "docs/roadmap/tasks/ck-07r1a0-freeze-lifecycle-path-authority.md").read_text( + encoding="utf-8" + ) + ck07r1 = ( + _ROOT / "docs/roadmap/tasks/ck-07r1-correct-lifecycle-preparation-scale.md" + ).read_text(encoding="utf-8") artifact = "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json" assert artifact in index assert artifact in packet @@ -585,6 +743,7 @@ def test_dag_ledger_index_and_scope_bind_the_authority_without_new_task() -> Non assert "CK-07R1" in central and "CK-07R1" in ledger assert authority["scope"]["authority_only_files"] assert set(authority["scope"]["authority_only_files"]) == { + "AGENTS.md", "docs/INDEX.md", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.json", "docs/decisions/evidence/ck07r1a0/lifecycle-run-invocation-authority.schema.json",