Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion Tools/README.md

Large diffs are not rendered by default.

272 changes: 138 additions & 134 deletions Tools/check_queue.py

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions Tools/compiled/cli-contract.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ source_files:
- Tools/stamp_cards.py
- Tools/update_queue.py
- Tools/update_task.py
source_hash: sha256:f99b88729f8c7b24b5ee04c4204503c7cf09de788254e10d7510b6c5c0fe5e2f
source_hash: sha256:817a50981c3a7a36947af4811ab753c2791e691e5c3f474c9f62185fca5ba4de
receipt_shape:
base_fields:
- receipt_id
Expand Down Expand Up @@ -1752,7 +1752,7 @@ tools:
receipt_extensions_extraction: partial
- tool: check_queue
module: Tools/check_queue.py
source_hash: sha256:08012b152ee7d993b45bbad09e1c28fff223425590551bccd632c7373e1c5f08
source_hash: sha256:1ecaec9019b013358f2afda142585d3ca48360eebf90633da7b6d149ebc5c523
description: Validate canonical Required Queue state
arguments:
- dest: root
Expand Down
2 changes: 1 addition & 1 deletion Tools/compiled/host-configs/claude-code.mcp.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"mcpServers":{"cambium":{"args":["<CAMBIUM_DISTRIBUTION_ROOT>/Tools/mcp_server.py"],"command":"python3","cwd":"<CAMBIUM_DISTRIBUTION_ROOT>","env":{"CAMBIUM_INTERFACE_SOURCE_HASH":"sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65","CAMBIUM_WORKSPACE_ROOT":"<CAMBIUM_WORKSPACE_ROOT>"}}}}
{"mcpServers":{"cambium":{"args":["<CAMBIUM_DISTRIBUTION_ROOT>/Tools/mcp_server.py"],"command":"python3","cwd":"<CAMBIUM_DISTRIBUTION_ROOT>","env":{"CAMBIUM_INTERFACE_SOURCE_HASH":"sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725","CAMBIUM_WORKSPACE_ROOT":"<CAMBIUM_WORKSPACE_ROOT>"}}}}
4 changes: 2 additions & 2 deletions Tools/compiled/host-configs/codex.config.toml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
# server name: cambium
# server entry point: Tools/mcp_server.py (under the distribution root)
# source: Tools/compiled/mcp-tools.json
# source_hash: sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65
# source_hash: sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725
# regenerate: python3 Tools/render_host_configs.py .
# verify: python3 Tools/render_host_configs.py . --check
#
Expand Down Expand Up @@ -35,5 +35,5 @@ command = "python3"
cwd = "<CAMBIUM_DISTRIBUTION_ROOT>"

[mcp_servers.cambium.env]
CAMBIUM_INTERFACE_SOURCE_HASH = "sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65"
CAMBIUM_INTERFACE_SOURCE_HASH = "sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725"
CAMBIUM_WORKSPACE_ROOT = "<CAMBIUM_WORKSPACE_ROOT>"
2 changes: 1 addition & 1 deletion Tools/compiled/host-configs/dsh-profile-patch.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@
# server name: cambium
# server entry point: Tools/mcp_server.py (under the distribution root)
# source: Tools/compiled/mcp-tools.json
# source_hash: sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65
# source_hash: sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725
# regenerate: python3 Tools/render_host_configs.py .
# verify: python3 Tools/render_host_configs.py . --check
#
Expand Down
4 changes: 2 additions & 2 deletions Tools/compiled/host-configs/dsh.env
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@
# carries: binding
# server name: cambium
# source: Tools/compiled/mcp-tools.json
# source_hash: sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65
# source_hash: sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725
# regenerate: python3 Tools/render_host_configs.py .
# verify: python3 Tools/render_host_configs.py . --check
#
Expand All @@ -21,5 +21,5 @@
# valid absolute path on any of these hosts, so an un-substituted copy
# fails at launch instead of resolving to something.

CAMBIUM_INTERFACE_SOURCE_HASH="sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65"
CAMBIUM_INTERFACE_SOURCE_HASH="sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725"
CAMBIUM_WORKSPACE_ROOT="<CAMBIUM_WORKSPACE_ROOT>"
2 changes: 1 addition & 1 deletion Tools/compiled/host-configs/kimi-code.mcp.json
Original file line number Diff line number Diff line change
@@ -1 +1 @@
{"mcpServers":{"cambium":{"args":["<CAMBIUM_DISTRIBUTION_ROOT>/Tools/mcp_server.py"],"command":"python3","cwd":"<CAMBIUM_DISTRIBUTION_ROOT>","env":{"CAMBIUM_INTERFACE_SOURCE_HASH":"sha256:c59bd2a610a9c70aa95d5debcce209bc4a2446f955f6c49b287aa7bc11139e65","CAMBIUM_WORKSPACE_ROOT":"<CAMBIUM_WORKSPACE_ROOT>"}}}}
{"mcpServers":{"cambium":{"args":["<CAMBIUM_DISTRIBUTION_ROOT>/Tools/mcp_server.py"],"command":"python3","cwd":"<CAMBIUM_DISTRIBUTION_ROOT>","env":{"CAMBIUM_INTERFACE_SOURCE_HASH":"sha256:4b49c621cfe358c02a341735bdfb2f2773d0803ebdb9a54ecf944066af696725","CAMBIUM_WORKSPACE_ROOT":"<CAMBIUM_WORKSPACE_ROOT>"}}}}
2 changes: 1 addition & 1 deletion Tools/compiled/mcp-tools.json

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion Tools/compiled/metadata-execution-contract.json

Large diffs are not rendered by default.

4 changes: 2 additions & 2 deletions Tools/schemas/receipt.template.jsonl
Original file line number Diff line number Diff line change
Expand Up @@ -130,7 +130,7 @@
# check_links 1.6.0 / wiki-link-integrity; check_vocab 1.8.0 /
# frontmatter-vocabulary and priority-quota-distribution;
# check_residual_content 1.2.0 /
# registered-residual-content; check_queue 1.23.0 / its registered
# registered-residual-content; check_queue 1.24.0 / its registered
# Required-Queue modes; check_batch_close 1.12.0 / batch-close; check_proof
# 1.17.0 / terminal-proof; and adopt_standards 1.7.0 /
# standards-adoption. Deterministic producers not shown above -- among them
Expand All @@ -149,7 +149,7 @@
# after it. A run outside any Cambium runtime (no `.cambium/state/`) omits the
# three fields rather than writing null: an omitted field claims nothing, while
# an explicit null would satisfy consumers that only test field presence.
# Public R01 `check_queue.py` 1.23.0 admission reruns the complete
# Public R01 `check_queue.py` 1.24.0 admission reruns the complete
# `profile-load` closure. The lower-level runtime view used to construct a
# corrective Standards adoption retains only the selected Profile's
# identity/sentinel guard, so an invalid current Profile does not prevent a
Expand Down
126 changes: 109 additions & 17 deletions Tools/tests/test_check_queue.py
Original file line number Diff line number Diff line change
Expand Up @@ -461,6 +461,67 @@ def test_every_supported_close_era_resolves_a_child_protocol(self):
"every consistency run" % version)


class EvidenceIdentityLifecycleTests(unittest.TestCase):
"""One policy separates live authority from producer-era facts."""

def setUp(self):
self.receipt = {
"selected_profile_manifest": "profiles/old/profile.md",
"profile_snapshot_sha256": "sha256:" + "1" * 64,
"profile_contract_fingerprint": "sha256:" + "2" * 64,
"profile_load_inputs_sha256": "sha256:" + "3" * 64,
"metadata_execution_contract_fingerprint":
"sha256:" + "4" * 64,
}
self.live_profile = {
"selected_profile_manifest": "profiles/new/profile.md",
"profile_snapshot_sha256": "sha256:" + "5" * 64,
"profile_contract_fingerprint": "sha256:" + "6" * 64,
"profile_load_inputs_sha256": "sha256:" + "7" * 64,
}
self.live_metadata = "sha256:" + "8" * 64

def errors(self, use, receipt=None):
return check_queue._evidence_identity_errors(
receipt or self.receipt, "fixture evidence", use=use,
profile_view=self.live_profile,
metadata_contract_fingerprint=self.live_metadata)

def test_current_authority_and_active_transaction_require_live_identity(self):
for use in (
check_queue.EVIDENCE_USE_CURRENT_AUTHORIZATION,
check_queue.EVIDENCE_USE_ACTIVE_TRANSACTION):
with self.subTest(use=use):
errors = self.errors(use)
self.assertTrue(any(
"expected authorized Profile" in error
for error in errors), errors)
self.assertTrue(any(
"stale relative to the live contract" in error
for error in errors), errors)

def test_completed_event_and_terminal_history_replay_producer_identity(self):
for use in (
check_queue.EVIDENCE_USE_COMPLETED_EVENT,
check_queue.EVIDENCE_USE_TERMINAL_HISTORY):
with self.subTest(use=use):
self.assertEqual([], self.errors(use))

def test_every_lifecycle_rejects_malformed_producer_identity(self):
malformed = dict(self.receipt)
malformed["profile_snapshot_sha256"] = "not-a-sha"
malformed["metadata_execution_contract_fingerprint"] = "not-a-sha"
for use in check_queue.EVIDENCE_IDENTITY_USES:
with self.subTest(use=use):
errors = self.errors(use, malformed)
self.assertTrue(any(
"invalid producer-era profile_snapshot_sha256" in error
for error in errors), errors)
self.assertTrue(any(
"invalid producer-era metadata execution fingerprint" in
error for error in errors), errors)


class CurrentPropertyStateTests(unittest.TestCase):
"""Current owner state is strict without reinterpreting absent history."""

Expand Down Expand Up @@ -722,7 +783,7 @@ def test_content_event_closes_owner_evidence_and_machine_fields(self):
self.assertEqual([], self.errors_with_projection(
row, catalog, text))

def test_current_content_pointer_rejects_closed_shape_and_stale_evidence(self):
def test_content_pointer_replays_canonical_producer_era_bindings(self):
text = (
"---\ntitle: A\nlast_content_modified: 2026-08-20\n"
"---\nBody\n")
Expand All @@ -747,18 +808,20 @@ def test_current_content_pointer_rejects_closed_shape_and_stale_evidence(self):
self.assertTrue(any("not closed" in error for error in closed), closed)

row["property_state"]["last_content_modified"] = dict(record)
receipt["metadata_execution_contract_fingerprint"] = (
"sha256:" + "9" * 64)
receipt["metadata_execution_contract_fingerprint"] = "not-a-sha"
stale = self.errors(row, self.content_catalog(receipt))
self.assertTrue(any(
"metadata_execution_contract_fingerprint" in error
"metadata execution fingerprint" in error
for error in stale), stale)
receipt["metadata_execution_contract_fingerprint"] = self.META_SHA
receipt["profile_snapshot_sha256"] = "sha256:" + "0" * 64
stale_profile = self.errors(row, self.content_catalog(receipt))
self.assertTrue(any(
"profile_snapshot_sha256" in error
for error in stale_profile), stale_profile)
old_meta = "sha256:" + "9" * 64
old_profile = "sha256:" + "0" * 64
receipt["metadata_execution_contract_fingerprint"] = old_meta
receipt["profile_snapshot_sha256"] = old_profile
catalog = self.content_catalog(receipt)
opening = catalog[receipt["opening_transition_receipt"]][1]
opening["metadata_execution_contract_fingerprint"] = old_meta
opening["profile_snapshot_sha256"] = old_profile
self.assertEqual([], self.errors(row, catalog))

def test_content_event_must_bind_exact_opening_before_image(self):
text = (
Expand Down Expand Up @@ -827,7 +890,7 @@ def test_property_fields_values_and_tombstones_are_closed(self):
"tombstone without the content-change state" in error
for error in orphan), orphan)

def test_review_and_profile_gate_receipts_bind_current_profile(self):
def test_review_replays_producer_era_while_profile_gate_stays_live(self):
text = (
"---\ntitle: A\nlast_reviewed: 2026-08-20\n"
"readiness_state: accepted\n---\nBody\n")
Expand Down Expand Up @@ -980,11 +1043,13 @@ def test_review_and_profile_gate_receipts_bind_current_profile(self):
self.assertEqual([], self.errors(row, catalog))

review["profile_contract_fingerprint"] = "sha256:" + "7" * 64
self.assertEqual([], self.errors(row, catalog))
gate["profile_contract_fingerprint"] = "sha256:" + "7" * 64
stale = self.errors(row, catalog)
self.assertTrue(any(
"profile_contract_fingerprint" in error for error in stale),
stale)
review["profile_contract_fingerprint"] = self.PROFILE_CONTRACT_SHA
gate["profile_contract_fingerprint"] = self.PROFILE_CONTRACT_SHA
gate["requested_completion_value"] = "rejected"
wrong_value = self.errors(row, catalog)
self.assertTrue(any(
Expand Down Expand Up @@ -1195,7 +1260,7 @@ def transition(self, version=None):
"metadata_execution_contract_fingerprint": self.META_SHA,
}

def errors(self, transition):
def errors(self, transition, *, require_live_authority=True):
contract = SimpleNamespace(contract_fingerprint=self.META_SHA)
with mock.patch.object(
check_queue.metadata_execution_contract,
Expand All @@ -1204,7 +1269,8 @@ def errors(self, transition):
"/fixture", transition,
{"id": "B1", "manifest": [
"Topics/A.md", "Topics/B.md"]},
self.profile_view())
self.profile_view(),
require_live_authority=require_live_authority)

def test_current_open_binds_exact_manifest_before_set(self):
self.assertEqual([], self.errors(self.transition()))
Expand Down Expand Up @@ -1248,6 +1314,18 @@ def test_legacy_open_is_not_reinterpreted(self):
self.profile_view()))
loader.assert_not_called()

def test_terminal_current_era_open_replays_producer_bindings(self):
transition = self.transition()
transition["profile_snapshot_sha256"] = "sha256:" + "8" * 64
transition["metadata_execution_contract_fingerprint"] = (
"sha256:" + "7" * 64)
with mock.patch.object(
check_queue.metadata_execution_contract,
"load_metadata_execution_contract") as loader:
self.assertEqual([], self.errors(
transition, require_live_authority=False))
loader.assert_not_called()

def test_public_resolver_returns_only_current_latest_opening(self):
current = self.transition()
result = {
Expand Down Expand Up @@ -1314,7 +1392,7 @@ def errors(self, transition, catalog=None):
return check_queue._current_close_transition_metadata_errors(
"/fixture", transition, catalog or self.catalog(), "B1")

def test_current_close_binds_exact_children_and_live_metadata(self):
def test_current_close_binds_exact_children_and_producer_metadata(self):
self.assertEqual([], self.errors(self.transition()))

malformed = self.transition()
Expand All @@ -1334,8 +1412,22 @@ def test_current_close_binds_exact_children_and_live_metadata(self):
errors)
self.assertTrue(any("differs from its close Gate" in error
for error in errors), errors)
self.assertTrue(any("stale relative" in error for error in errors),
errors)

def test_terminal_current_era_close_survives_metadata_upgrade(self):
transition = self.transition()
catalog = self.catalog()
old_fingerprint = "sha256:" + "b" * 64
transition["metadata_execution_contract_fingerprint"] = \
old_fingerprint
catalog["audit-close-gate"][1][
"metadata_execution_contract_fingerprint"] = old_fingerprint
with mock.patch.object(
check_queue.metadata_execution_contract,
"load_metadata_execution_contract") as loader:
self.assertEqual([], check_queue.
_current_close_transition_metadata_errors(
"/fixture", transition, catalog, "B1"))
loader.assert_not_called()

def test_historical_close_is_not_reinterpreted(self):
for version in ("1.2.0", "1.3.0", "1.4.0"):
Expand Down
4 changes: 2 additions & 2 deletions kernel/Cards/R02 Single Note Authoring Card.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,8 +43,8 @@ readback_sources:
- kernel/K12 Quality Assurance/11 Content-level Propagation.md
- kernel/K12 Quality Assurance/13 Visual Verification Escalation.md
readback_policy: declared
source_hash: '2c50b6abf23c'
compiled_source_hash: '2c50b6abf23c'
source_hash: '5f0f7919a9ed'
compiled_source_hash: '5f0f7919a9ed'
---
# R02 Single Note Authoring Card

Expand Down
4 changes: 2 additions & 2 deletions kernel/Cards/R05 Expression Layer Card.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,8 +29,8 @@ readback_sources:
- kernel/K12 Quality Assurance/02 Rendering Verification.md
- kernel/K12 Quality Assurance/13 Visual Verification Escalation.md
readback_policy: declared
source_hash: '40bc9ac959a8'
compiled_source_hash: '40bc9ac959a8'
source_hash: '903f5e26fda4'
compiled_source_hash: '903f5e26fda4'
---
# R05 Expression Layer Card

Expand Down
4 changes: 2 additions & 2 deletions kernel/Cards/R09 Standards Governance Card.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,8 +38,8 @@ readback_sources:
- kernel/K12 Quality Assurance/02 Rendering Verification.md
- kernel/K12 Quality Assurance/05 Automated and Manual Checks.md
readback_policy: activation
source_hash: 'cc47b6b15432'
compiled_source_hash: 'cc47b6b15432'
source_hash: '547d2dc76216'
compiled_source_hash: '547d2dc76216'
---
# R09 Standards Governance Card

Expand Down
4 changes: 2 additions & 2 deletions kernel/Cards/R10 Maintenance Run Card.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,8 @@ readback_sources:
- kernel/K12 Quality Assurance/11 Content-level Propagation.md
- kernel/K12 Quality Assurance/12 Substantive Correctness Review.md
readback_policy: declared
source_hash: 'ef73059497be'
compiled_source_hash: 'ef73059497be'
source_hash: '1b513ada03a8'
compiled_source_hash: '1b513ada03a8'
---
# R10 Maintenance Run Card

Expand Down
12 changes: 6 additions & 6 deletions kernel/K00 Standards Control/12 Control Registry.md
Original file line number Diff line number Diff line change
Expand Up @@ -125,15 +125,15 @@ moves its own cell.
|---|---|---|---|---|---|---|
| `runtime-card-synchronization` | `manual-attestation` | `1.0.0` | `runtime-card-synchronization` | `*` | `guidance_and_contract` | `not-batch-scoped` |
| `profile-load` | `check_profile` | `2.0.0` | `profile-check-summary` | `*` | `guidance_and_contract` | `not-batch-scoped` |
| `runtime-startup-recovery` | `check_queue` | `1.23.0` | `required_queue` | `resume-status` | `*` | `not-batch-scoped` |
| `runtime-startup-recovery` | `check_queue` | `1.24.0` | `required_queue` | `resume-status` | `*` | `not-batch-scoped` |
| `large-scale-execution-admission` | `manual-attestation` | `1.0.0` | `large-scale-execution-admission` | `*` | `guidance_and_contract` | `not-batch-scoped` |
| `wiki-link-integrity` | `check_links` | `1.6.0` | `link-check-summary` | `*` | `*` | `not-batch-scoped` |
| `frontmatter-vocabulary` | `check_vocab` | `1.8.0` | `vocab-check-summary` | `*` | `*` | `not-batch-scoped` |
| `priority-quota-distribution` | `check_vocab` | `1.8.0` | `priority-quota-distribution` | `*` | `*` | `not-batch-scoped` |
| `required-queue-consistency` | `check_queue` | `1.23.0` | `required_queue` | `consistency` | `*` | `not-batch-scoped` |
| `required-queue-admission` | `check_queue` | `1.23.0` | `required_queue` | `require-ready:*` | `*` | `queued` |
| `required-queue-completion` | `check_queue` | `1.23.0` | `required_queue` | `require-complete` | `*` | `queue-exhausted` |
| `maintenance-completion` | `check_queue` | `1.23.0` | `required_queue` | `require-maintenance-complete` | `*` | `queue-exhausted` |
| `required-queue-consistency` | `check_queue` | `1.24.0` | `required_queue` | `consistency` | `*` | `not-batch-scoped` |
| `required-queue-admission` | `check_queue` | `1.24.0` | `required_queue` | `require-ready:*` | `*` | `queued` |
| `required-queue-completion` | `check_queue` | `1.24.0` | `required_queue` | `require-complete` | `*` | `queue-exhausted` |
| `maintenance-completion` | `check_queue` | `1.24.0` | `required_queue` | `require-maintenance-complete` | `*` | `queue-exhausted` |
| `batch-review` | `manual-attestation` | `1.0.0` | `batch_gate` | `*` | `none` | `open` |
| `batch-close` | `check_batch_close` | `1.12.0` | `batch_close_gate` | `*` | `*` | `merge-ready` |
| `structure-registry` | `check_structure` | `1.1.0` | `structure-registry-summary` | `*` | `*` | `not-batch-scoped` |
Expand All @@ -146,7 +146,7 @@ moves its own cell.
| `expression-layer-acceptance` | `manual-attestation` | `1.0.0` | `expression-layer-acceptance` | `*` | `content_and_depth`, `coverage_and_integration`, `guidance_and_contract`, `source_and_currentness`, `structure_and_links` | `not-batch-scoped` |
| `coverage-reconciliation` | `manual-attestation` | `1.0.0` | `coverage-reconciliation` | `*` | `coverage_and_integration` | `not-batch-scoped` |
| `standards-adoption` | `adopt_standards` | `1.7.0` | `standards_adoption` | `*` | `*` | `not-batch-scoped` |
| `standards-revalidation` | `check_queue` | `1.23.0` | `required_queue` | `require-revalidation:*` | `*` | `queued`, `open` |
| `standards-revalidation` | `check_queue` | `1.24.0` | `required_queue` | `require-revalidation:*` | `*` | `queued`, `open` |
| `guidance-disposition` | `manual-attestation` | `1.0.0` | `guidance-disposition` | `*` | `guidance_and_contract` | `not-batch-scoped` |
| `receipt-validity` | `manual-attestation` | `1.0.0` | `receipt-validity` | `*` | `guidance_and_contract` | `not-batch-scoped` |
| `rendering` | `manual-attestation` | `1.0.0` | `rendering` | `*` | `rendering`, `structure_and_links` | `not-batch-scoped` |
Expand Down
Loading