[AI-Assisted] feat(mcp): qualify bounded barrier-register screening - #3711
Draft
EvenSol wants to merge 2 commits into
Draft
[AI-Assisted] feat(mcp): qualify bounded barrier-register screening#3711EvenSol wants to merge 2 commits into
EvenSol wants to merge 2 commits into
Conversation
67 tasks
This was referenced Sep 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Campaign
Advances #3153 under the bounded Phase 0 trust-evidence roadmap.
Capability contract: #3153 (comment)
Engineering question
Can
runBarrierRegisteraccept a bounded caller-supplied register, preserve deterministic source order and traceable evidence, fail closed for malformed or excessive input, exclude impaired or unqualified barriers from quantitative handoffs, and expose only advisory LOPA/SIL/bow-tie/QRA screening through the standard packaged MCP boundary?Change
BarrierRegister,SafetyBarrier,PerformanceStandard,SafetyCriticalElement, andDocumentEvidenceclasses as the only model.screeningOnly, standards-conformance, and qualified-review boundaries on success and error.Frozen scope and accounting
Exact base:
3e6262872d14fa31715e818549ca6473d79a7057Exact head:
fdcab71eff776735cf9268e9bee3385c3d4606baSix files are changed. Active autonomous PRs #3700, #3701, #3708, #3710, and #3712 are file-disjoint.
This is qualification only. Phase 0 remains 1.39 / 20 explicit + 39 contract-tested + 12 confirmed gaps, and
runBarrierRegisterremainsCONFIRMED_GAPuntil this evidence merges and a later atomic promotion re-audits currentmaster.Safety and advisory boundary
The change does not identify hazards; validate source documents, PFD, effectiveness, availability, independence, common-cause failure, proof testing, or lifecycle evidence; select or verify SIL; decide tolerability; demonstrate NORSOK/IEC/ISO compliance; authorize plant action; certify design; or replace qualified process-safety review and accountable approval. No external data, plant write, control action, or second safety model is introduced.
Exact-head validation
Passing:
Two test-only blockers remain:
safetyFunctionand leaves the impaired barrier unlinked to an SCE. Canonical validation correctly returns two warnings andvalidation.valid=false; the harness incorrectly requirestrue. Comprehensive MCP is not reached.BarrierRegisterRunnerTest.testScreeningBoundaryAndImpairedBarrierExclusionerrors. The test readslopaHandoff.excludedBarriers, but the canonical response key isexcluded, producing a null dereference. Ubuntu Java 21 was cancelled after that failure; Java 8 jobs were skipped by fail-fast.The sole permitted repair was already consumed by the exact hosted Spotless patch for initial head
7ed1eef37a4da858da266a4168e293cad33a3bed; artifact digestsha256:0349942585773986883d2bcc15576f8931022d35e1261e3cbd3c34b7f5c2c369. It changed formatting only and produced current exact headfdcab71eff776735cf9268e9bee3385c3d4606ba.VALIDATION BLOCKED — SECOND REPAIR DISALLOWED.
No reviews or unresolved review threads.
Workflow policy
Draft only. Preserve exact head
fdcab71eff776735cf9268e9bee3385c3d4606ba. Do not merge, auto-merge, mark ready, rebase, synchronize, force-push, close, replace, restart, abandon, or apply a second repair.