From 6db349844a52a046a37cf2169399ae415942cb19 Mon Sep 17 00:00:00 2001 From: Brad Edwards Date: Sun, 27 Sep 2026 13:57:31 -0700 Subject: [PATCH] =?UTF-8?q?Revert=20"feat:=20require=20backends=20to=20hon?= =?UTF-8?q?our=20authored=20trial=20timeout=20and=20retry=20cho=E2=80=A6"?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This reverts commit c4d90a39b0f116ecb4f2dd355e3ebfb4ef432c81. --- ...eration-supervision-without-contracts.json | 542 -------------- .../valid/operation-supervision.json | 546 -------------- .../valid/supervised-retry.json | 260 ------- .../entries/admitted-trial-plan-v1.json | 6 +- .../entries/backend-manifest-v2.json | 6 +- .../backend-manifest/backend-manifest-v2.json | 94 --- .../schemas/plans/admitted-trial-plan-v1.json | 21 +- ...libvirt-qemu.provisioning-only.report.json | 16 - ...e-1361-sdl-execution-recovery-preflight.md | 204 ----- .../backend-operation-supervision.md | 15 - docs/public/backends.md | 6 - docs/requirements/API-402/requirement.md | 24 +- .../analysis-v55.json | 155 ---- .../bundles/retest-v55.json | 122 --- .../execution-snapshot-v55.json | 652 ---------------- .../formal-semantic-validation/index.md | 7 +- .../specification-coverage/analysis-v55.json | 105 --- ...specification-coverage-issue-1361-v55.json | 10 - .../execution-snapshot-v55.json | 700 ------------------ docs/research/specification-coverage/index.md | 12 +- .../backend_manifest.py | 20 - .../raes_backend_protocols/capabilities.py | 26 +- .../capability_admission.py | 45 ++ .../cleanup_admission.py | 82 -- .../raes_backend_protocols/manifest.py | 110 ++- .../operational_manifest.py | 161 ---- .../raes_contracts/contracts/__init__.py | 1 - .../contracts/_backend_operation_exports.py | 2 - .../raes_contracts/contracts/_exports.py | 1 - .../contracts/admitted_trial_plan.py | 10 +- .../admitted_trial_plan_components.py | 25 +- .../contracts/execution_requirements.py | 39 - .../raes_contracts/contracts/manifests.py | 55 +- .../operational_manifest_capabilities.py | 80 -- .../contracts/participant_manifests.py | 29 - .../raes_processor/trial_compiler/compiler.py | 50 +- .../trial_compiler/entry_admission.py | 66 -- .../raes_processor/trial_compiler/models.py | 4 +- .../tests/test_formal_semantic_validation.py | 5 +- .../test_issue_1361_execution_requirements.py | 303 -------- .../test_issue_989_versioned_evidence.py | 6 +- .../tests/test_specification_coverage.py | 2 +- .../cleanup-contracts.md | 32 - tools/check_specification_coverage.py | 6 +- tools/formal_semantic_validation/_baseline.py | 1 - tools/formal_semantic_validation/_loading.py | 4 +- .../_release_revisions.py | 4 +- tools/formal_semantic_validation/_releases.py | 4 +- tools/formal_semantic_validation/_retest.py | 2 +- 49 files changed, 264 insertions(+), 4414 deletions(-) delete mode 100644 contracts/fixtures/backend-manifest/backend-manifest-v2/invalid/operation-supervision-without-contracts.json delete mode 100644 contracts/fixtures/backend-manifest/backend-manifest-v2/valid/operation-supervision.json delete mode 100644 contracts/fixtures/plans/admitted-trial-plan-v1/valid/supervised-retry.json delete mode 100644 docs/decisions/issue-1361-sdl-execution-recovery-preflight.md delete mode 100644 docs/research/formal-semantic-validation/analysis-v55.json delete mode 100644 docs/research/formal-semantic-validation/bundles/retest-v55.json delete mode 100644 docs/research/formal-semantic-validation/execution-snapshot-v55.json delete mode 100644 docs/research/specification-coverage/analysis-v55.json delete mode 100644 docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-1361-v55.json delete mode 100644 docs/research/specification-coverage/execution-snapshot-v55.json delete mode 100644 implementations/python/packages/raes_backend_protocols/cleanup_admission.py delete mode 100644 implementations/python/packages/raes_backend_protocols/operational_manifest.py delete mode 100644 implementations/python/packages/raes_contracts/contracts/execution_requirements.py delete mode 100644 implementations/python/packages/raes_contracts/contracts/operational_manifest_capabilities.py delete mode 100644 implementations/python/packages/raes_processor/trial_compiler/entry_admission.py delete mode 100644 implementations/python/tests/test_issue_1361_execution_requirements.py diff --git a/contracts/fixtures/backend-manifest/backend-manifest-v2/invalid/operation-supervision-without-contracts.json b/contracts/fixtures/backend-manifest/backend-manifest-v2/invalid/operation-supervision-without-contracts.json deleted file mode 100644 index 1615d2fb2..000000000 --- a/contracts/fixtures/backend-manifest/backend-manifest-v2/invalid/operation-supervision-without-contracts.json +++ /dev/null @@ -1,542 +0,0 @@ -{ - "capabilities": { - "cleanup": { - "name": "stub-cleanup", - "supported_action_kinds": [ - "compensate", - "destroy", - "reset", - "restore", - "verify" - ], - "supported_contract_versions": [ - "trial-cleanup-plan-v1", - "trial-cleanup-receipt-v1" - ], - "supported_verification_methods": [ - "probe", - "receipt" - ], - "supports_residual_state_disclosure": true, - "supports_reusable_state": true - }, - "evaluator": { - "constraints": {}, - "name": "stub-evaluator", - "preserves_binding_provenance": true, - "supported_evidence_channels": [ - "api_response", - "file_artifact", - "log" - ], - "supported_predicate_families": [ - "boolean", - "number", - "presence", - "string" - ], - "supported_quantifiers": [ - "all", - "any", - "at_least" - ], - "supported_sections": [ - "assertions", - "conditions", - "objectives", - "propositions" - ], - "supported_time_domains": [ - "scenario_time" - ], - "supported_truth_outcomes": [ - "false", - "true", - "unknown", - "unsupported" - ], - "supports_deferred_expected_comparison": false, - "supports_objectives": true, - "supports_scoring": true - }, - "observation": { - "capture_offers": [], - "constraints": {}, - "name": "stub-observation", - "supported_capture_kinds": [ - "artifact", - "log", - "observation", - "packet-capture", - "telemetry", - "trace" - ], - "supported_channel_kinds": [ - "backend-log", - "evaluation-history", - "file-artifact", - "packet-capture", - "participant-observation", - "runtime-snapshot", - "workflow-history" - ], - "supported_evidence_contracts": [ - "experiment-capture-spec-v1", - "experiment-derived-measure-v1", - "experiment-evidence-record-v1", - "experiment-run-v1" - ], - "supported_media_types": [ - "application/json", - "text/plain" - ], - "supported_sealing_modes": [ - "digest", - "immutable-store" - ], - "supports_chain_of_custody": false, - "supports_loss_disclosure": true, - "supports_redaction": true - }, - "operation_supervision": { - "guarantees": [ - "cancellation", - "cessation-evidence", - "effect-observation" - ], - "name": "supervised-stub-operations" - }, - "orchestrator": { - "constraints": {}, - "name": "stub-orchestrator", - "supported_sections": [ - "events", - "injects", - "scripts", - "stories", - "workflows" - ], - "supported_workflow_features": [ - "call", - "cancellation", - "compensation", - "decision", - "failure-transitions", - "parallel-barrier", - "retry", - "switch", - "timeouts" - ], - "supported_workflow_state_predicates": [ - "attempt-counts", - "outcome-matching" - ], - "supports_assertion_refs": true, - "supports_inject_bindings": true, - "supports_workflows": true - }, - "participant_runtime": { - "constraints": {}, - "execution_bindings": [], - "feature_support": [ - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_boundary_flow_resolution:unsupported" - ], - "evidence_refs": [], - "feature": "participant_boundary_flow_resolution", - "limitation_refs": [ - "limitation:participant_boundary_flow_resolution:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_declassification:unsupported" - ], - "evidence_refs": [], - "feature": "participant_declassification", - "limitation_refs": [ - "limitation:participant_declassification:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_directed_inject_delivery:unsupported" - ], - "evidence_refs": [], - "feature": "participant_directed_inject_delivery", - "limitation_refs": [ - "limitation:participant_directed_inject_delivery:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_egress_projection:unsupported" - ], - "evidence_refs": [], - "feature": "participant_egress_projection", - "limitation_refs": [ - "limitation:participant_egress_projection:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_final_sink_mediation:unsupported" - ], - "evidence_refs": [], - "feature": "participant_final_sink_mediation", - "limitation_refs": [ - "limitation:participant_final_sink_mediation:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_ingress_admission:unsupported" - ], - "evidence_refs": [], - "feature": "participant_ingress_admission", - "limitation_refs": [ - "limitation:participant_ingress_admission:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_intervention:unsupported" - ], - "evidence_refs": [], - "feature": "participant_intervention", - "limitation_refs": [ - "limitation:participant_intervention:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_modular_control:unsupported" - ], - "evidence_refs": [], - "feature": "participant_modular_control", - "limitation_refs": [ - "limitation:participant_modular_control:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_monitor_topology:unsupported" - ], - "evidence_refs": [], - "feature": "participant_monitor_topology", - "limitation_refs": [ - "limitation:participant_monitor_topology:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_predicate_opacity:unsupported" - ], - "evidence_refs": [], - "feature": "participant_predicate_opacity", - "limitation_refs": [ - "limitation:participant_predicate_opacity:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_processing_role_trust:unsupported" - ], - "evidence_refs": [], - "feature": "participant_processing_role_trust", - "limitation_refs": [ - "limitation:participant_processing_role_trust:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_quarantined_processing:unsupported" - ], - "evidence_refs": [], - "feature": "participant_quarantined_processing", - "limitation_refs": [ - "limitation:participant_quarantined_processing:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_transformation:unsupported" - ], - "evidence_refs": [], - "feature": "participant_transformation", - "limitation_refs": [ - "limitation:participant_transformation:not-realized" - ], - "support_level": "unsupported" - } - ], - "max_autonomous_action_attempts": null, - "max_autonomous_burst_size": null, - "max_autonomous_in_flight": null, - "max_autonomous_occurrences": null, - "max_autonomous_participants": null, - "max_autonomous_retries_per_occurrence": null, - "max_concurrent_actions": null, - "max_execution_services": null, - "name": "stub-participant-runtime", - "resource_budgets": null, - "supported_autonomous_action_contracts": [], - "supported_autonomous_activity_features": [], - "supported_autonomous_observation_boundaries": [], - "supported_autonomous_policy_profiles": [], - "supported_autonomous_random_stream_profiles": [], - "supported_autonomous_selection_strategies": [], - "supported_autonomous_target_addresses": [], - "supported_behavior_features": [ - "action_contracts", - "attribution_support", - "behavior_history", - "effects", - "failure_classes", - "observation_boundaries", - "outcome_interpretation", - "preconditions", - "state_transitions", - "temporal_contracts" - ], - "supported_execution_control_actions": [], - "supported_interaction_features": [ - "contention", - "coordination", - "interference", - "shared_state_change" - ], - "supported_participant_roles": [ - "blue", - "green", - "red", - "white" - ], - "supports_autonomous_execution": false, - "supports_bounded_concurrency": false, - "supports_execution_control": false - }, - "provisioner": { - "constraints": {}, - "max_total_nodes": null, - "name": "stub-provisioner", - "operating_systems": [], - "supported_account_features": [ - "auth_method", - "disabled", - "groups", - "home", - "mail", - "shell", - "spn" - ], - "supported_content_types": [ - "dataset", - "directory", - "file" - ], - "supported_domain_profiles": [ - "active_directory" - ], - "supported_generated_artifact_delivery_modes": [ - "env_file", - "environment", - "mount" - ], - "supported_generated_artifact_kinds": [ - "certificate_bundle", - "rendered_config", - "ssh_key_bundle" - ], - "supported_node_architectures": [ - "aarch64", - "x86_64" - ], - "supported_node_types": [ - "compute", - "switch" - ], - "supported_os_families": [ - "freebsd", - "linux", - "macos", - "other", - "windows" - ], - "supported_regeneration_scopes": [], - "supported_service_materialization_profiles": [], - "supports_accounts": true, - "supports_acls": true, - "supports_generated_artifacts": true, - "supports_persistent_volumes": true - } - }, - "compatibility": { - "processors": [ - "raes-reference-processor" - ] - }, - "concept_bindings": [ - { - "family": "assets", - "scope": "capabilities.provisioner.supported_node_types" - }, - { - "family": "assets", - "scope": "capabilities.provisioner.supported_os_families" - }, - { - "family": "assets", - "scope": "capabilities.provisioner.supported_node_architectures" - }, - { - "family": "tools-and-artifacts", - "scope": "capabilities.provisioner.supported_content_types" - }, - { - "family": "identities", - "scope": "capabilities.provisioner.supported_account_features" - }, - { - "family": "identities", - "scope": "capabilities.provisioner.supported_domain_profiles" - }, - { - "family": "tools-and-artifacts", - "scope": "capabilities.provisioner.supported_service_materialization_profiles" - }, - { - "family": "actions-and-events", - "scope": "capabilities.orchestrator.supported_sections" - }, - { - "family": "observables", - "scope": "capabilities.evaluator.supported_sections" - }, - { - "family": "identities", - "scope": "capabilities.participant_runtime.supported_participant_roles" - }, - { - "family": "actions-and-events", - "scope": "capabilities.participant_runtime.supported_behavior_features" - }, - { - "family": "relationships", - "scope": "capabilities.participant_runtime.supported_interaction_features" - }, - { - "family": "provenance-and-evidence", - "scope": "capabilities.observation.supported_capture_kinds" - }, - { - "family": "apparatus-declarations", - "scope": "capabilities.observation.supported_channel_kinds" - }, - { - "family": "provenance-and-evidence", - "scope": "capabilities.observation.supported_sealing_modes" - } - ], - "constraints": {}, - "identity": { - "name": "supervised-stub", - "version": "0.3.0" - }, - "realization_support": [ - { - "artifact_mechanisms": [], - "constraints": {}, - "disclosure_kinds": [ - "backend-manifest-v2", - "operation-status-v1", - "runtime-snapshot-v1" - ], - "domain": "runtime-realization", - "observation_capabilities": {}, - "process_resource_limits": [], - "support_mode": "constrained", - "supported_constraint_kinds": [ - "account-feature", - "content-type", - "node-architecture", - "node-type", - "os-family", - "workflow-feature", - "workflow-state-predicate" - ], - "supported_exact_requirement_kinds": [ - "declared-capability-match" - ] - } - ], - "schema_version": "backend-manifest/v2", - "supported_contract_versions": [ - "artifact-requirement-v1", - "backend-manifest-v2", - "evaluation-history-event-stream-v1", - "evaluation-plan-v1", - "evaluation-result-envelope-v1", - "experiment-capture-spec-v1", - "experiment-derived-measure-v1", - "experiment-evidence-record-v1", - "experiment-run-v1", - "operation-receipt-v1", - "operation-status-v1", - "orchestration-plan-v1", - "participant-behavior-history-event-stream-v1", - "participant-control-evaluation-v1", - "participant-control-occurrence-v1", - "participant-control-selection-v1", - "participant-crossing-occurrence-v1", - "participant-episode-history-event-stream-v1", - "participant-episode-state-envelope-v1", - "participant-execution-binding-v1", - "participant-execution-control-v1", - "participant-execution-service-state-v1", - "participant-flow-control-relation-v1", - "participant-joint-action-record-v1", - "participant-lifecycle-event-v1", - "participant-observation-envelope-v1", - "participant-outcome-report-v1", - "participant-resource-budget-event-v1", - "participant-resource-budget-policy-v1", - "participant-resource-budget-state-v1", - "participant-resource-pool-capacity-v1", - "participant-shared-state-record-v1", - "participant-time-management-context-v1", - "proposition-truth-result-v1", - "provisioning-plan-v1", - "runtime-snapshot-v1", - "trial-cleanup-plan-v1", - "trial-cleanup-receipt-v1", - "workflow-history-event-stream-v1", - "workflow-result-envelope-v1" - ] -} diff --git a/contracts/fixtures/backend-manifest/backend-manifest-v2/valid/operation-supervision.json b/contracts/fixtures/backend-manifest/backend-manifest-v2/valid/operation-supervision.json deleted file mode 100644 index 99e1172e7..000000000 --- a/contracts/fixtures/backend-manifest/backend-manifest-v2/valid/operation-supervision.json +++ /dev/null @@ -1,546 +0,0 @@ -{ - "capabilities": { - "cleanup": { - "name": "stub-cleanup", - "supported_action_kinds": [ - "compensate", - "destroy", - "reset", - "restore", - "verify" - ], - "supported_contract_versions": [ - "trial-cleanup-plan-v1", - "trial-cleanup-receipt-v1" - ], - "supported_verification_methods": [ - "probe", - "receipt" - ], - "supports_residual_state_disclosure": true, - "supports_reusable_state": true - }, - "evaluator": { - "constraints": {}, - "name": "stub-evaluator", - "preserves_binding_provenance": true, - "supported_evidence_channels": [ - "api_response", - "file_artifact", - "log" - ], - "supported_predicate_families": [ - "boolean", - "number", - "presence", - "string" - ], - "supported_quantifiers": [ - "all", - "any", - "at_least" - ], - "supported_sections": [ - "assertions", - "conditions", - "objectives", - "propositions" - ], - "supported_time_domains": [ - "scenario_time" - ], - "supported_truth_outcomes": [ - "false", - "true", - "unknown", - "unsupported" - ], - "supports_deferred_expected_comparison": false, - "supports_objectives": true, - "supports_scoring": true - }, - "observation": { - "capture_offers": [], - "constraints": {}, - "name": "stub-observation", - "supported_capture_kinds": [ - "artifact", - "log", - "observation", - "packet-capture", - "telemetry", - "trace" - ], - "supported_channel_kinds": [ - "backend-log", - "evaluation-history", - "file-artifact", - "packet-capture", - "participant-observation", - "runtime-snapshot", - "workflow-history" - ], - "supported_evidence_contracts": [ - "experiment-capture-spec-v1", - "experiment-derived-measure-v1", - "experiment-evidence-record-v1", - "experiment-run-v1" - ], - "supported_media_types": [ - "application/json", - "text/plain" - ], - "supported_sealing_modes": [ - "digest", - "immutable-store" - ], - "supports_chain_of_custody": false, - "supports_loss_disclosure": true, - "supports_redaction": true - }, - "operation_supervision": { - "guarantees": [ - "cancellation", - "cessation-evidence", - "effect-observation" - ], - "name": "supervised-stub-operations" - }, - "orchestrator": { - "constraints": {}, - "name": "stub-orchestrator", - "supported_sections": [ - "events", - "injects", - "scripts", - "stories", - "workflows" - ], - "supported_workflow_features": [ - "call", - "cancellation", - "compensation", - "decision", - "failure-transitions", - "parallel-barrier", - "retry", - "switch", - "timeouts" - ], - "supported_workflow_state_predicates": [ - "attempt-counts", - "outcome-matching" - ], - "supports_assertion_refs": true, - "supports_inject_bindings": true, - "supports_workflows": true - }, - "participant_runtime": { - "constraints": {}, - "execution_bindings": [], - "feature_support": [ - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_boundary_flow_resolution:unsupported" - ], - "evidence_refs": [], - "feature": "participant_boundary_flow_resolution", - "limitation_refs": [ - "limitation:participant_boundary_flow_resolution:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_declassification:unsupported" - ], - "evidence_refs": [], - "feature": "participant_declassification", - "limitation_refs": [ - "limitation:participant_declassification:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_directed_inject_delivery:unsupported" - ], - "evidence_refs": [], - "feature": "participant_directed_inject_delivery", - "limitation_refs": [ - "limitation:participant_directed_inject_delivery:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_egress_projection:unsupported" - ], - "evidence_refs": [], - "feature": "participant_egress_projection", - "limitation_refs": [ - "limitation:participant_egress_projection:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_final_sink_mediation:unsupported" - ], - "evidence_refs": [], - "feature": "participant_final_sink_mediation", - "limitation_refs": [ - "limitation:participant_final_sink_mediation:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_ingress_admission:unsupported" - ], - "evidence_refs": [], - "feature": "participant_ingress_admission", - "limitation_refs": [ - "limitation:participant_ingress_admission:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_intervention:unsupported" - ], - "evidence_refs": [], - "feature": "participant_intervention", - "limitation_refs": [ - "limitation:participant_intervention:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_modular_control:unsupported" - ], - "evidence_refs": [], - "feature": "participant_modular_control", - "limitation_refs": [ - "limitation:participant_modular_control:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_monitor_topology:unsupported" - ], - "evidence_refs": [], - "feature": "participant_monitor_topology", - "limitation_refs": [ - "limitation:participant_monitor_topology:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_predicate_opacity:unsupported" - ], - "evidence_refs": [], - "feature": "participant_predicate_opacity", - "limitation_refs": [ - "limitation:participant_predicate_opacity:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_processing_role_trust:unsupported" - ], - "evidence_refs": [], - "feature": "participant_processing_role_trust", - "limitation_refs": [ - "limitation:participant_processing_role_trust:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_quarantined_processing:unsupported" - ], - "evidence_refs": [], - "feature": "participant_quarantined_processing", - "limitation_refs": [ - "limitation:participant_quarantined_processing:not-realized" - ], - "support_level": "unsupported" - }, - { - "constraint_refs": [], - "disclosure_refs": [ - "disclosure:participant_transformation:unsupported" - ], - "evidence_refs": [], - "feature": "participant_transformation", - "limitation_refs": [ - "limitation:participant_transformation:not-realized" - ], - "support_level": "unsupported" - } - ], - "max_autonomous_action_attempts": null, - "max_autonomous_burst_size": null, - "max_autonomous_in_flight": null, - "max_autonomous_occurrences": null, - "max_autonomous_participants": null, - "max_autonomous_retries_per_occurrence": null, - "max_concurrent_actions": null, - "max_execution_services": null, - "name": "stub-participant-runtime", - "resource_budgets": null, - "supported_autonomous_action_contracts": [], - "supported_autonomous_activity_features": [], - "supported_autonomous_observation_boundaries": [], - "supported_autonomous_policy_profiles": [], - "supported_autonomous_random_stream_profiles": [], - "supported_autonomous_selection_strategies": [], - "supported_autonomous_target_addresses": [], - "supported_behavior_features": [ - "action_contracts", - "attribution_support", - "behavior_history", - "effects", - "failure_classes", - "observation_boundaries", - "outcome_interpretation", - "preconditions", - "state_transitions", - "temporal_contracts" - ], - "supported_execution_control_actions": [], - "supported_interaction_features": [ - "contention", - "coordination", - "interference", - "shared_state_change" - ], - "supported_participant_roles": [ - "blue", - "green", - "red", - "white" - ], - "supports_autonomous_execution": false, - "supports_bounded_concurrency": false, - "supports_execution_control": false - }, - "provisioner": { - "constraints": {}, - "max_total_nodes": null, - "name": "stub-provisioner", - "operating_systems": [], - "supported_account_features": [ - "auth_method", - "disabled", - "groups", - "home", - "mail", - "shell", - "spn" - ], - "supported_content_types": [ - "dataset", - "directory", - "file" - ], - "supported_domain_profiles": [ - "active_directory" - ], - "supported_generated_artifact_delivery_modes": [ - "env_file", - "environment", - "mount" - ], - "supported_generated_artifact_kinds": [ - "certificate_bundle", - "rendered_config", - "ssh_key_bundle" - ], - "supported_node_architectures": [ - "aarch64", - "x86_64" - ], - "supported_node_types": [ - "compute", - "switch" - ], - "supported_os_families": [ - "freebsd", - "linux", - "macos", - "other", - "windows" - ], - "supported_regeneration_scopes": [], - "supported_service_materialization_profiles": [], - "supports_accounts": true, - "supports_acls": true, - "supports_generated_artifacts": true, - "supports_persistent_volumes": true - } - }, - "compatibility": { - "processors": [ - "raes-reference-processor" - ] - }, - "concept_bindings": [ - { - "family": "assets", - "scope": "capabilities.provisioner.supported_node_types" - }, - { - "family": "assets", - "scope": "capabilities.provisioner.supported_os_families" - }, - { - "family": "assets", - "scope": "capabilities.provisioner.supported_node_architectures" - }, - { - "family": "tools-and-artifacts", - "scope": "capabilities.provisioner.supported_content_types" - }, - { - "family": "identities", - "scope": "capabilities.provisioner.supported_account_features" - }, - { - "family": "identities", - "scope": "capabilities.provisioner.supported_domain_profiles" - }, - { - "family": "tools-and-artifacts", - "scope": "capabilities.provisioner.supported_service_materialization_profiles" - }, - { - "family": "actions-and-events", - "scope": "capabilities.orchestrator.supported_sections" - }, - { - "family": "observables", - "scope": "capabilities.evaluator.supported_sections" - }, - { - "family": "identities", - "scope": "capabilities.participant_runtime.supported_participant_roles" - }, - { - "family": "actions-and-events", - "scope": "capabilities.participant_runtime.supported_behavior_features" - }, - { - "family": "relationships", - "scope": "capabilities.participant_runtime.supported_interaction_features" - }, - { - "family": "provenance-and-evidence", - "scope": "capabilities.observation.supported_capture_kinds" - }, - { - "family": "apparatus-declarations", - "scope": "capabilities.observation.supported_channel_kinds" - }, - { - "family": "provenance-and-evidence", - "scope": "capabilities.observation.supported_sealing_modes" - } - ], - "constraints": {}, - "identity": { - "name": "supervised-stub", - "version": "0.3.0" - }, - "realization_support": [ - { - "artifact_mechanisms": [], - "constraints": {}, - "disclosure_kinds": [ - "backend-manifest-v2", - "operation-status-v1", - "runtime-snapshot-v1" - ], - "domain": "runtime-realization", - "observation_capabilities": {}, - "process_resource_limits": [], - "support_mode": "constrained", - "supported_constraint_kinds": [ - "account-feature", - "content-type", - "node-architecture", - "node-type", - "os-family", - "workflow-feature", - "workflow-state-predicate" - ], - "supported_exact_requirement_kinds": [ - "declared-capability-match" - ] - } - ], - "schema_version": "backend-manifest/v2", - "supported_contract_versions": [ - "artifact-requirement-v1", - "backend-manifest-v2", - "backend-operation-capabilities-v1", - "backend-operation-control-v1", - "backend-operation-request-v1", - "backend-operation-response-v1", - "evaluation-history-event-stream-v1", - "evaluation-plan-v1", - "evaluation-result-envelope-v1", - "experiment-capture-spec-v1", - "experiment-derived-measure-v1", - "experiment-evidence-record-v1", - "experiment-run-v1", - "operation-receipt-v1", - "operation-status-v1", - "orchestration-plan-v1", - "participant-behavior-history-event-stream-v1", - "participant-control-evaluation-v1", - "participant-control-occurrence-v1", - "participant-control-selection-v1", - "participant-crossing-occurrence-v1", - "participant-episode-history-event-stream-v1", - "participant-episode-state-envelope-v1", - "participant-execution-binding-v1", - "participant-execution-control-v1", - "participant-execution-service-state-v1", - "participant-flow-control-relation-v1", - "participant-joint-action-record-v1", - "participant-lifecycle-event-v1", - "participant-observation-envelope-v1", - "participant-outcome-report-v1", - "participant-resource-budget-event-v1", - "participant-resource-budget-policy-v1", - "participant-resource-budget-state-v1", - "participant-resource-pool-capacity-v1", - "participant-shared-state-record-v1", - "participant-time-management-context-v1", - "proposition-truth-result-v1", - "provisioning-plan-v1", - "runtime-snapshot-v1", - "trial-cleanup-plan-v1", - "trial-cleanup-receipt-v1", - "workflow-history-event-stream-v1", - "workflow-result-envelope-v1" - ] -} diff --git a/contracts/fixtures/plans/admitted-trial-plan-v1/valid/supervised-retry.json b/contracts/fixtures/plans/admitted-trial-plan-v1/valid/supervised-retry.json deleted file mode 100644 index c4bbb1378..000000000 --- a/contracts/fixtures/plans/admitted-trial-plan-v1/valid/supervised-retry.json +++ /dev/null @@ -1,260 +0,0 @@ -{ - "admission": { - "admitted_at_stage": "admitted-sealed", - "diagnostics": [], - "entry_count": 1, - "limitations": [] - }, - "cleanup_plans": { - "cleanup-a": { - "clean_state": { - "boundary_refs": [ - "range-a" - ], - "mode": "fresh", - "reusable_state_claim_ref": null, - "verification_probe_refs": [ - "probe:fresh" - ] - }, - "cleanup_obligations": { - "destroy-range": { - "action_kind": "destroy", - "action_profile_ref": null, - "boundary_refs": [ - "range-a" - ], - "compensation_refs": [], - "depends_on": [], - "idempotency": "idempotent", - "obligation_id": "destroy-range", - "requirement": "required", - "timeout_seconds": 120, - "triggers": [ - "success", - "failure", - "cancellation", - "timeout", - "abort" - ], - "verification_probe_refs": [ - "probe:absent" - ] - } - }, - "plan_entry_id": "entry-a", - "plan_id": "cleanup-a", - "resource_boundaries": { - "range-a": { - "boundary_id": "range-a", - "owner_ref": "apparatus:range-a", - "resource_kind": "range-instance", - "resource_refs": [ - "node.vm-a" - ] - } - }, - "retry_policy": { - "after_effect_policy": "disallow", - "compensation_refs": [], - "max_attempts": 2, - "reset_obligation_refs": [] - }, - "run_id": "run-a", - "schema_version": "trial-cleanup-plan/v1" - } - }, - "entries": { - "entry-a": { - "apparatus": { - "capability_refs": [ - "cap:isolation" - ], - "manifest_refs": [ - { - "ref_digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333", - "ref_id": "backend-a", - "ref_kind": "manifest", - "ref_path": null, - "ref_version": "backend-manifest/v2", - "subject_ref": { - "ref_digest": null, - "ref_id": "backend-a", - "ref_kind": "backend", - "ref_path": null, - "ref_version": "1" - } - } - ], - "realization_envelope": { - "configuration_digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222", - "contract_id": "realization-envelope-v1", - "digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111", - "envelope_id": "env-a", - "schema_version": "realization-envelope/v1" - } - }, - "bindings": [ - { - "descriptor": { - "binding_id": "bind-a", - "owner": { - "contract_id": "sdl-authoring-input-v1", - "contract_version": "1", - "validator_id": "scenario-binder", - "validator_version": "1" - }, - "source_condition_id": "baseline", - "source_factor_id": "factor-a", - "source_factor_level_id": "level-a", - "target": { - "plane": "scenario", - "scenario_family_id": "family-a", - "target_id": "target-a", - "variation_point_id": "point-b" - }, - "value": { - "kind": "literal", - "value": "v" - }, - "value_type": "string" - }, - "origin": "selection" - } - ], - "coordinate": { - "block_id": null, - "condition_id": "baseline", - "replicate_id": null - }, - "entry_digest": "sha256:3cd0e40e5ebbc4d3683d17d136a3261afaafe3acc2939fb1a9be9d67f719fb2a", - "execution_controls": { - "attempt_timeout_seconds": 600, - "cleanup_plan_ref": "cleanup-a", - "on_cancellation": "cleanup-and-fail", - "on_timeout": "cancel", - "required_guarantees": [ - "cancellation", - "cessation-evidence", - "effect-observation" - ] - }, - "instantiation_provenance": { - "plan_entry_id": "entry-a", - "plan_id": "plan-a", - "run_id": "run-a", - "scenario_family_id": "family-a" - }, - "plan_entry_id": "entry-a", - "run_id": "run-a", - "selections": [ - { - "origin_policy_id": "policy-a", - "origin_policy_kind": "fixed", - "outcome": { - "kind": "member", - "member_id": "variant-a" - }, - "variation_point_id": "point-a" - } - ], - "stochastic_draws": [ - { - "address": { - "draw_purpose": "condition-assignment", - "local_coordinate": 0, - "namespace": "study-namespace", - "selection_policy_id": "policy-a", - "trial_coordinate": { - "block_id": null, - "condition_id": "baseline", - "replicate_id": null - }, - "variation_point_id": "point-a" - }, - "control_id": "control-a", - "local_coordinate": 0, - "outcome": { - "kind": "public-value", - "value": "3" - }, - "rejection_attempts": 0, - "rejection_exhausted": false, - "transform_id": "bounded-integer", - "transform_version": "1" - } - ] - } - }, - "input_refs": { - "associated_artifact_set_ref": null, - "authoring_input_ref": { - "ref_digest": "sha256:abababababababababababababababababababababababababababababababab", - "ref_id": "exp-a", - "ref_kind": "authoring-input", - "ref_path": null, - "ref_version": "1" - }, - "binding_descriptor_set_ref": { - "ref_digest": "sha256:efefefefefefefefefefefefefefefefefefefefefefefefefefefefefefefef", - "ref_id": "bindings-a", - "ref_kind": "other", - "ref_path": null, - "ref_version": "1" - }, - "capture_spec_refs": [], - "scenario_family_ref": { - "ref_digest": "sha256:cdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcdcd", - "ref_id": "family-a", - "ref_kind": "scenario-family", - "ref_version": "expanded-scenario-family/v1" - }, - "study_ref": null, - "task_digest": "sha256:bcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbcbc", - "task_ref": { - "ref_id": "task-a", - "ref_kind": "task", - "ref_version": "1" - } - }, - "isolation_proof": null, - "plan_digest": "sha256:430b257d6f1a2364af92ecbb3997cfc1e6c1726a0f27c6ca46af9e1ea7edf1c6", - "plan_id": "plan-a", - "profiles": { - "canonicalization_profile": "jcs-sha256-v1", - "cleanup_profile": "trial-cleanup-v1", - "compiler_profile": "trial-compiler-v1", - "coordinate_profile": "trial-coordinate-v1", - "entry_identity_profile": "trial-entry-identity-v1", - "execution_control_profile": "attempt-control-v1", - "integrity_profile": "acyclic-digest-chain-v1", - "isolation_profile": "scheduler-isolation-v1", - "random_stream_profile": "blake3-xof-v1", - "run_identity_profile": "archival-run-identity-v1", - "selection_policy_profile": "experiment-selection-v1" - }, - "schema_version": "admitted-trial-plan/v1", - "stochastic_controls": { - "control-a": { - "control_id": "control-a", - "description": null, - "executable_binding": { - "namespace": "study-namespace", - "profile_ref": { - "ref_digest": null, - "ref_id": "blake3-xof-v1", - "ref_kind": "profile", - "ref_path": null, - "ref_version": "random-stream-profile/v1" - }, - "root_entropy": { - "encoding": "hex-fixed-width", - "kind": "public-seed", - "value": "abababababababababababababababababababababababababababababababab" - } - }, - "role": "randomization", - "value": null - } - } -} diff --git a/contracts/schema-publication/entries/admitted-trial-plan-v1.json b/contracts/schema-publication/entries/admitted-trial-plan-v1.json index a83b39c96..9963dd370 100644 --- a/contracts/schema-publication/entries/admitted-trial-plan-v1.json +++ b/contracts/schema-publication/entries/admitted-trial-plan-v1.json @@ -1,9 +1,9 @@ { - "content_hash": "eddfed3f5c7b27cbe7512157b89a860242b55ad905c610dca8a45849cd76c5fa", + "content_hash": "a7196c336041aba73cbb7cbad3895d086d39b0a9445e6389d58756d2844df6f2", "contract_id": "admitted-trial-plan-v1", "last_change": { - "content_hash": "eddfed3f5c7b27cbe7512157b89a860242b55ad905c610dca8a45849cd76c5fa", - "summary": "Record the backend operation guarantees derived from each entry's authored timeout and retry choices, omitted when none are required and checked against those choices by the plan (#1361)." + "content_hash": "a7196c336041aba73cbb7cbad3895d086d39b0a9445e6389d58756d2844df6f2", + "summary": "Add exact mixed-composition profile, participant-manifest authority, and immediate-source bindings to admitted trial entries while preserving legacy single-realizer serialization (#1015)." }, "schema_path": "contracts/schemas/plans/admitted-trial-plan-v1.json", "stability": "draft" diff --git a/contracts/schema-publication/entries/backend-manifest-v2.json b/contracts/schema-publication/entries/backend-manifest-v2.json index aa7cf1148..0a6374b15 100644 --- a/contracts/schema-publication/entries/backend-manifest-v2.json +++ b/contracts/schema-publication/entries/backend-manifest-v2.json @@ -1,9 +1,9 @@ { - "content_hash": "2095ee14a9bb3c0080088851b615cab4df0168d667629bb9645c3089cea77fa4", + "content_hash": "67408de0a854ab63582c29bc4b1dfaa2efea2e61dff598a648ff03b2ad74755d", "contract_id": "backend-manifest-v2", "last_change": { - "summary": "Add an optional operation-supervision declaration of the backend operation guarantees a backend provides, requiring the backend operation contract family (#1361).", - "content_hash": "2095ee14a9bb3c0080088851b615cab4df0168d667629bb9645c3089cea77fa4" + "summary": "Publish optional backend operation and supervision contracts with contextual admission and bounded evidence (#1360).", + "content_hash": "67408de0a854ab63582c29bc4b1dfaa2efea2e61dff598a648ff03b2ad74755d" }, "schema_path": "contracts/schemas/backend-manifest/backend-manifest-v2.json", "stability": "draft" diff --git a/contracts/schemas/backend-manifest/backend-manifest-v2.json b/contracts/schemas/backend-manifest/backend-manifest-v2.json index 9fe6a5262..169937c78 100644 --- a/contracts/schemas/backend-manifest/backend-manifest-v2.json +++ b/contracts/schemas/backend-manifest/backend-manifest-v2.json @@ -194,17 +194,6 @@ ], "default": null }, - "operation_supervision": { - "anyOf": [ - { - "$ref": "#/$defs/OperationSupervisionCapabilitiesModel" - }, - { - "type": "null" - } - ], - "default": null - }, "orchestrator": { "anyOf": [ { @@ -1571,40 +1560,6 @@ "title": "OperationKind", "type": "string" }, - "OperationSupervisionCapabilitiesModel": { - "additionalProperties": false, - "description": "Static declaration of the backend operation guarantees a backend provides.\n\nPlanning compares authored execution choices with this declaration. It is\nneither contextual willingness nor evidence: runtime admission still checks\nthe installed provider's capabilities and willingness before each dispatch.", - "properties": { - "guarantees": { - "items": { - "enum": [ - "cancellation", - "effect-observation", - "cessation-evidence", - "partial-effects", - "external-fencing" - ], - "type": "string" - }, - "maxItems": 5, - "minItems": 1, - "title": "Guarantees", - "type": "array", - "uniqueItems": true - }, - "name": { - "minLength": 1, - "title": "Name", - "type": "string" - } - }, - "required": [ - "name", - "guarantees" - ], - "title": "OperationSupervisionCapabilitiesModel", - "type": "object" - }, "OrchestratorCapabilitiesModel": { "additionalProperties": false, "allOf": [ @@ -3558,55 +3513,6 @@ } } } - }, - { - "if": { - "properties": { - "capabilities": { - "properties": { - "operation_supervision": { - "not": { - "type": "null" - } - } - }, - "required": [ - "operation_supervision" - ] - } - }, - "required": [ - "capabilities" - ] - }, - "then": { - "properties": { - "supported_contract_versions": { - "allOf": [ - { - "contains": { - "const": "backend-operation-request-v1" - } - }, - { - "contains": { - "const": "backend-operation-capabilities-v1" - } - }, - { - "contains": { - "const": "backend-operation-control-v1" - } - }, - { - "contains": { - "const": "backend-operation-response-v1" - } - } - ] - } - } - } } ], "properties": { diff --git a/contracts/schemas/plans/admitted-trial-plan-v1.json b/contracts/schemas/plans/admitted-trial-plan-v1.json index 8e89caeb7..befe66310 100644 --- a/contracts/schemas/plans/admitted-trial-plan-v1.json +++ b/contracts/schemas/plans/admitted-trial-plan-v1.json @@ -64,7 +64,7 @@ }, "AdmittedExecutionControlModel": { "additionalProperties": false, - "description": "Minimal schedule-independent attempt policy.\n\nCarries only whole-trial attempt timeout, the required cancellation/timeout\ndisposition, the cleanup-plan reference, and the backend guarantees those\nchoices require. The reset/compensation retry policy is owned by the\nreferenced ``TrialCleanupPlanModel.retry_policy`` and is not duplicated here;\n``required_guarantees`` is derived from it and ``on_timeout`` and is checked\nagainst both by the plan, so a sealed plan cannot hold contradicting\nrequirements. It never carries worker, queue, placement, host, lease, or\nmutable status data.", + "description": "Minimal schedule-independent attempt policy.\n\nCarries only whole-trial attempt timeout, the required cancellation/timeout\ndisposition, and the cleanup-plan reference. The reset/compensation retry\npolicy is owned by the referenced ``TrialCleanupPlanModel.retry_policy`` and\nis not duplicated here, so a sealed plan cannot hold two contradicting retry\npolicies. It never carries worker, queue, placement, host, lease, or mutable\nstatus data.", "properties": { "attempt_timeout_seconds": { "minimum": 1, @@ -92,23 +92,6 @@ ], "title": "On Timeout", "type": "string" - }, - "required_guarantees": { - "default": [], - "items": { - "enum": [ - "cancellation", - "effect-observation", - "cessation-evidence", - "partial-effects", - "external-fencing" - ], - "type": "string" - }, - "maxItems": 5, - "title": "Required Guarantees", - "type": "array", - "uniqueItems": true } }, "required": [ @@ -2766,7 +2749,7 @@ "type": "object", "x-raes-invariants": [ { - "description": "An admitted trial plan keeps map keys equal to embedded ids, keeps plan/entry/run identities distinct, gives every entry a unique logical coordinate and archival run_id, resolves cleanup and stochastic-control joins (with each draw addressed to its entry coordinate), exact mixed-composition profile inputs, and isolation-proof entries within the sealed plan, requires each entry's required backend guarantees to equal the canonical set derived from its execution controls and cleanup retry policy, requires values duplicated from incumbent authorities (random-stream profile, binding condition/family) to agree, forbids bounded-parallel entries from sharing resources, matches admission cardinality, and binds the complete plan with a recomputed plan_digest over the entry set.", + "description": "An admitted trial plan keeps map keys equal to embedded ids, keeps plan/entry/run identities distinct, gives every entry a unique logical coordinate and archival run_id, resolves cleanup and stochastic-control joins (with each draw addressed to its entry coordinate), exact mixed-composition profile inputs, and isolation-proof entries within the sealed plan, requires values duplicated from incumbent authorities (random-stream profile, binding condition/family) to agree, forbids bounded-parallel entries from sharing resources, matches admission cardinality, and binds the complete plan with a recomputed plan_digest over the entry set.", "id": "admitted-trial-plan-identity-joins-and-integrity", "inputs": [ { diff --git a/docs/conformance/libvirt-qemu.provisioning-only.report.json b/docs/conformance/libvirt-qemu.provisioning-only.report.json index 195168f44..dc84d657b 100644 --- a/docs/conformance/libvirt-qemu.provisioning-only.report.json +++ b/docs/conformance/libvirt-qemu.provisioning-only.report.json @@ -7,13 +7,6 @@ "passed": true, "valid": true }, - { - "contract_name": "backend-manifest-v2", - "diagnostic_codes": [], - "name": "operation-supervision", - "passed": true, - "valid": true - }, { "contract_name": "backend-manifest-v2", "diagnostic_codes": [], @@ -156,15 +149,6 @@ "passed": true, "valid": false }, - { - "contract_name": "backend-manifest-v2", - "diagnostic_codes": [ - "conformance.schema-invalid" - ], - "name": "operation-supervision-without-contracts", - "passed": true, - "valid": false - }, { "contract_name": "backend-manifest-v2", "diagnostic_codes": [ diff --git a/docs/decisions/issue-1361-sdl-execution-recovery-preflight.md b/docs/decisions/issue-1361-sdl-execution-recovery-preflight.md deleted file mode 100644 index af96cc838..000000000 --- a/docs/decisions/issue-1361-sdl-execution-recovery-preflight.md +++ /dev/null @@ -1,204 +0,0 @@ -# Issue #1361 — SDL execution and recovery requirements preflight - -Date: 2026-09-27. Status: preflight guidance. Scope: issue #1361, after -prerequisite issue 1360. This note records boundaries for the -authoring-to-plan change; it defines neither SDL syntax nor an implementation -sequence. [ADR-113](adrs/adr-113-reusable-execution-machinery.md), its -[authored retry design](../research/execution-architecture/authored-retry-policy.md), -and the [#1360 operation contracts](issue-1360-backend-operation-contracts-preflight.md) -remain the semantic owners. The #1348 exploration is available at revision -`077f7d04` in repository history; its owner decisions distinguish durability -from resumption, allow a failed experiment to require a new trial, and make -backend inability or unwillingness a reason to refuse an authored requirement. -No new ADR is needed: ADR-113 already owns the decision, while this note locks -down its language-to-plan adoption boundary. - -## Boundaries to preserve - -- Carry the author's *effective requirement* and its defining scope/version - through SDL composition, instantiation, compilation, plan projection and - backend admission. Missing local policy inherits; explicit never-repeat is a - value. Resolve a complete policy at the nearest defining scope, with the - conservative no-second-effect fallback when no scope permits repetition. - Preserve existing workflow, trial and cleanup defaults separately; do not - reinterpret omission as automatic retry, resumption or fresh-trial creation. -- Reuse `WorkflowStep` (`retry`, `max_attempts`, `on_failure`, - `on_exhausted`), `WorkflowTimeoutPolicy` and compensation for workflow - control. Reuse `ExecutionRetryPolicyModel`, `TrialCleanupPlanModel`, - `TrialExecutionAuthorityModel` and `AdmittedExecutionControlModel` for the - trial attempt/cleanup controls they already own. Their present fields do - not encode general interruption resumption, failure-class selection or - fresh-trial allocation. Extend the owning contract only where a required - choice has no representation; do not overload `after_effect_policy`, - workflow retry or a platform application's job `execution_policy`. -- A backend invocation, operation idempotency replay, authored workflow - attempt, participant episode and experiment trial/run have different - identities. Ending a trial cannot relabel its old run or increment a retry - counter to manufacture a fresh trial. A fresh trial needs the existing - experiment allocation, new run identity, isolation and cleanup authority; - the choice is invalid where no trial context exists. A failed old trial and - its evidence remain intact. -- Capability, contextual willingness, effect knowledge, cessation and - continuation safety are separate facts. A manifest or durable store cannot - establish all of them. Admission rejects unsupported requirements; a later - backend refusal or uncertain effect remains explicit under #1360's - versioned request/response and reconciliation contracts. No backend, - scheduler or execution engine may weaken the committed requirement or - choose a recovery action from application type or an IT/OT label. -- Preserve authored intentional faults and mixed-scope dependencies. Reset, - compensation and fresh initialization have their own effects and proof - obligations. Unknown effect state, a timeout, an accepted cancellation or - process loss alone cannot authorize another effect or prove clean state. - -## Existing coverage and the remaining contract gap - -- `WorkflowStep`, `WorkflowExecutionContract` and workflow result/history - validation already own workflow attempts and failure edges. They do not own - backend invocation replay, interruption recovery or experiment allocation. -- `ExecutionRetryPolicyModel`, `TrialExecutionAuthorityModel` and - `AdmittedExecutionControlModel` already own trial attempt, timeout and cleanup - facts. Today that authority is supplied separately to `TrialCompilationRequest`, - not authored in `ScenarioContent`, and therefore is not evidence that an SDL - choice survived composition or ordinary compilation. -- `RuntimeModel`, `PlanOperation` and the provisioning/orchestration/evaluation - plan contracts currently carry no complete scoped recovery requirement. - `BackendOperationRequestModel.requirement_refs` and `required_guarantees` can - reference or project an admitted requirement, but cannot become its editable - semantic source. The v1 guarantee vocabulary also has no general resumption or - fresh-trial meaning. -- `require_cleanup_plan_capability()` admits cleanup actions and observations; - backend manifests and #1360 admission distinguish installed capability from - contextual willingness. Neither one allocates a retry/trial or supplies the - missing authored policy. - -A derived guarantee tuple on an admitted trial entry is only a backend-admission -projection of these authored choices, never their source. The -[delivery resolution](#delivery-resolution) records how the issue was scoped. - -## Cross-cutting owners and gates - -| Boundary | Canonical incumbent and required treatment | -| --- | --- | -| SDL input and validation | `raes/_base.py` (`SDLModel.extra=forbid`), `_source_profile.py`/`SDLParserLimits`, `scenario.py`, `parser.py`, `composition/`, `phase_contracts.py`, `instantiate.py`, `validator/_workflows_verify.py`, `validator/_workflows_analysis.py` and `raes/semantics/workflow.py`; use their closed shapes, bounded YAML/import graph, canonical addresses, reference resolution, variable substitution, composition stability and semantic diagnostics. Validate conflicting scopes and invalid choices in the owning semantic layer, then revalidate instantiated concrete values. Do not add a second parser/default resolver or merge partial policies field-by-field during import. | -| Compilation and plan inspection | `raes_processor/compiler/{pipeline,workflows,workflow_steps}.py`, `models/runtime_model.py`, `trial_compiler/`, `planner/core.py`, `raes_contracts/planning.py`, `contracts/{realization_plans,admitted_trial_plan,trial_cleanup}.py`, `plan_projection.py` and `raes_cli/processor.py`; retain resolved requirements, origin and identity in typed, digest-bound published projections. Inspect the *compiled* requirement, including defaults, instead of reconstructing intent from prose or backend profile. Keep the three runtime domain plans and the admitted trial plan's distinct authorities; do not hide policy in arbitrary operation payloads. | -| Runtime/configuration shape | `raes_runtime/control_plane_configuration.py`, `registry.py`, `registry_target_validation.py`, `raes_backend_protocols/{backend_manifest,manifest,capabilities}.py` and `raes_contracts/contracts/manifests.py`; preserve closed option/manifest shapes, installed-component agreement and method-shape probes. This issue should need no new process, endpoint, credential loader or generic runtime setting. If an optional provider surface is touched, declaration, conversion, component presence and call-shape checks change together; schema availability alone never advertises support. | -| Backend admission | `raes_backend_protocols/capability_admission.py` (including `require_cleanup_plan_capability()`), backend manifests, `raes_processor/planner/`, `raes_runtime/manager_plan_admission.py` and `raes_contracts/contracts/{backend_operation,backend_operation_validation}.py`; compare the exact committed requirement with available capability and contextual willingness. Resolve and type-check requirement refs, derive any backend guarantees canonically from the admitted requirement, and reject a mismatch before dispatch. Existing libvirt plan admission remains concrete realization checking, not a portable policy authority. | -| Identity, auth and persistence | `raes_runtime/control_plane_security.py`, `control_plane_admission.py`, `control_plane_operation_context.py`, `control_plane_store_*`, `raes_contracts/operation_lifecycle.py`, `contracts/admitted_trial_plan.py` and `contracts/trial_cleanup.py`; authorize actor and target/run scope, commit the effective policy and provenance, use existing CAS/idempotency/audit and immutable plan digests, and keep restart readback lossless before making durability claims. Engine task identity is not authorization. | -| Errors and observation | `raes/_errors.py`, `raes_contracts/diagnostics.py`, `raes_runtime/diagnostics.py`, `raes_cli.processor._sdl_error_summary()`, control-plane operation receipt/status, API `_responses.py`, and #1360 response/reconciliation carriers; report bounded, stable diagnostic codes and safe addresses. Retain uncertainty and refusal as evidence, without copying Pydantic input values, backend exception text, raw request values or secrets into CLI, HTTP error envelopes, audit or logs. Use the existing module loggers only for fixed redacted operational events; do not add another exception or logging hierarchy. | -| Schemas and publication | `contracts/schemas/sdl/`, `contracts/schemas/plans/`, the v2 `contracts/schema-publication/entries/` records indexed by `schema-publication-manifest.json`, `raes_contracts.contracts.schema_bundle()`, `tools/generate_contract_schemas.py`, `check_generated_schemas.py`, `check_schema_publication.py` and `check_schema_coverage.py`; schema is normative, Python is a matching implementation. Update source/instantiated/materialized phase contracts and only the plan schemas that actually carry the value, their per-contract `last_change` hashes, routed coverage, public SDL semantics and an author migration guide together. Do not hand-add an ungoverned parallel schema or silently change an old default. | - -## Security and runtime crossing - -SDL is data, not permission to execute. Its parser and closed SDL/phase -validators reject oversized, ambiguous, malformed or unresolved declarations; -the composition budget also bounds imports, depth, nodes and bytes. Authenticated -control-plane admission still checks actor, target/run and plan identity. -Backend manifest/config shape checks and the #1360 bounded JSON operation -contracts then check exact capabilities, guarantees, context and current -willingness. Existing `raes/runtime_environment.py` and -`raes_runtime/backend_account_credentials.py` govern environment bindings -and credential egress; a recovery requirement contains references and -value-free commitments, never credentials or secret-bearing defaults. -`control_plane_operation_context.py` owns the safe projection. Runtime and -backend requests must use bounded carriers, not shell fragments, process -arguments, environment values or opaque executable strings; no new OS-level -exposure is required by this issue. Existing diagnostic and HTTP envelopes -must stay bounded and redacted. Operation state, audit and store codecs must -round-trip the admitted choice without promoting a backend response to -runtime authority. If a new raw JSON ingress is introduced despite this issue's -transport-neutral scope, it must pass `raes_contracts/json_ingress.py` before -closed model validation; `ContractModel.extra=forbid` alone does not reject -duplicate members, non-finite values or excessive aggregate size. - -## Extensibility and verification boundary - -The seam is a governed, complete effective-policy value plus source scope and -version in the admitted artifact, referenced by an exact operation request. -Any `OperationGuarantee` set is a canonical, non-editable projection of that -value, not a second authority. A later failure class, backend guarantee or -scoped policy can extend the policy and its one projection seam without editing -every workflow step or adding an application-specific mandatory declaration. -Keep retry-attempt and fresh-trial budgets independent; backend-specific -willingness remains a contextual admission decision. - -Verify the published source and phase schemas, composition/default/override -round trips, compiled plan inspection, invalid cross-scope combinations, -workflow/trial identity separation, and capability versus contextual refusal. -Use `test_sdl_{models,parser,validator,phase_contracts}.py`, -`test_sdl_module_registry.py`, `test_runtime_planner.py`, -`test_sce_002_{trial_compiler,admitted_trial_plan}.py`, -`test_sce_006_cleanup_contracts.py`, `test_plan_inspection_cli.py`, backend -manifest tests and `test_issue_1360_backend_operations.py` as targeted regression -surfaces. Publish author migration for any changed syntax or defaults. - -Anti-patterns and non-goals: do not treat a derived guarantee list as the -authored contract; add a free-form `execution_requirements`/metadata dictionary; -duplicate retry, cleanup, workflow, operation-state or exception schemas; infer -policy from durability, application type, backend name or IT/OT labels; multiply -attempts across transport, workflow and trial layers; reinterpret omission as -permission; mutate old run identity/history; or serialize Python callbacks, -exceptions, futures or engine objects. Runtime orchestration, backend execution, -new HTTP routes, checkpoint formats, engine retry mapping, new OT safety -profiles, physical-OT certification, distributed supervision and automatic -trial allocation are outside this issue's implementation boundary. - -## Delivery resolution - -The owner decided the representation during delivery. It supersedes the -scoped-policy guidance above wherever the two differ: - -- **No new SDL recovery construct.** Authors already express failure responses, - in as much detail as they need, through existing constructs. Workflow - `retry`, `max_attempts`, `on_failure`/`on_exhausted` branches, compensation - and timeout cover in-world responses, including deliberate resets and injects. - The trial execution authority (`on_timeout`, `on_cancellation` and the - SCE-007 cleanup plan's `ExecutionRetryPolicyModel`) covers trial attempts. - A scoped policy table, a policy enum or author-supplied guarantee lists were - rejected as unnecessary. Saying nothing remains valid: nothing is repeated, - resumed or replaced. -- **Replacement trials** have no machine-actionable representation today. - `replication_policy` and `stopping_rule` are free text that no code reads, - and nothing produces `superseded`/`superseded_by`. Replacement trials are - tracked separately as [#1396](https://github.com/OpenRAE/rae/issues/1396). -- **Nothing infers recovery from durability.** Store reopening classifies - `ACCEPTED`/`RUNNING` operations and never re-dispatches them, and - `INDETERMINATE` blocks new effects until an operator resolves it. Idempotent - replay returns the existing receipt without calling the backend. No path - selects recovery from an application type, IT/OT label or backend name. -- **Workflow choices already reach admission.** The planner rejects an - orchestrator that does not declare the required workflow feature. - -The delivered gap was trial-level. Authored timeout and retry choices were -sealed into the admitted trial plan, but nothing checked that the selected -backend could honour them: `require_cleanup_plan_capability()` was never -called, and manifests could not declare #1360 operation guarantees. The -delivery closes that gap as follows: - -| Authored choice | Backend guarantee RAE requires | -| --- | --- | -| `on_timeout: cancel` | `cancellation` | -| `retry_policy.max_attempts > 1` | `cessation-evidence`: attempts stay sequential, so the previous attempt must be proven stopped | -| the same with `after_effect_policy: disallow` | also `effect-observation`: the absence of effects must be established | - -- `required_operation_guarantees()` in `raes_contracts` is the single projection. - `AdmittedExecutionControlModel.required_guarantees` records it. The field is - omitted when empty, so existing plans keep their bytes and digests. The - admitted plan recomputes it from the entry and its cleanup plan and rejects - any edit. -- Backend-manifest-v2 gains an optional `capabilities.operation_supervision` - declaration. It requires the backend operation contract family and is neither - willingness nor evidence. -- Trial compilation calls `require_execution_authority_capability()` for every - backend selected for an entry, including mixed-composition profiles. The - check covers both the cleanup plan and the derived guarantees. An entry whose - realization selects no backend, such as a processor-only mixed composition, - is refused rather than admitted vacuously. -- A backend that cannot honour a choice is refused with - `trial-compiler.execution-authority-unsupported`. It is never treated as best - effort. -- The default choices (a single attempt, with no cancellation on timeout) - require nothing, so ordinary P0 work, CTFs and simulations gain no obligation. -- Runtime dispatch (#1362) copies the recorded guarantees into - `BackendOperationRequestModel.required_guarantees`. The existing - `require_backend_operation_admission()` then checks them against the installed - provider's capabilities and contextual willingness. diff --git a/docs/explain/reference/backend-operation-supervision.md b/docs/explain/reference/backend-operation-supervision.md index 7151725ff..3d3d01c06 100644 --- a/docs/explain/reference/backend-operation-supervision.md +++ b/docs/explain/reference/backend-operation-supervision.md @@ -43,20 +43,6 @@ contract corpus; use `raes_contracts.corpus` to locate them in an installed whee not schedule workflow retries, allocate new trials, rewrite an immutable terminal parent, or treat reconciliation as execution replay. -To be selected for trials whose authored choices need supervision, also declare -`capabilities.operation_supervision` in the manifest. It holds a `name` and the -`guarantees` the provider can establish, and requires all four contract IDs. -RAE derives the guarantees a trial needs from its authored choices: - -- `on_timeout: cancel` needs `cancellation`. -- More than one attempt needs `cessation-evidence`. -- More than one attempt with `after_effect_policy: disallow` also needs - `effect-observation`. - -Trial compilation refuses a backend whose declaration lacks one. The -declaration is a static claim, not willingness. `check_operation` must still -refuse a context in which a declared guarantee is unavailable. - Each method returns one `BackendOperationResponseModel`, whose `message.kind` identifies the payload. `check_operation` returns `admission`; `start_operation` returns `acknowledgement`; `cancel_operation` returns `control`. @@ -80,7 +66,6 @@ verifies the new path. | `RecoveryObservationResult` | Its absent/applied/indeterminate vocabulary has no general cessation or partial-effect witness. Conversion cannot invent one. Keep legacy reports on the old observer, or obtain fresh evidence before constructing a new report. | | P1/P2 stored operation records | No store migration in this publication. Existing strict codecs keep their existing shape. A later integration must explicitly version/persist the new facts and test lossless readback before it claims supervision across restart. | | Backend manifests/profiles | New draft schemas expand the backend contract-ID allowlist. Old manifests and profiles remain valid under the new reader; old closed readers can reject new IDs. Negotiate support before sending new messages. Never strip IDs or fields to disguise incompatibility. | -| Trial execution choices (#1361) | Existing admitted plans keep their bytes: `required_guarantees` is omitted when a trial needs none. A trial that cancels on timeout or permits more than one attempt now compiles only against backends that declare the derived guarantees. It also now requires the cleanup capability its cleanup plan needs. Declare `capabilities.operation_supervision` truthfully, or change the choice. Never add guarantees a provider cannot establish just to pass admission. | | P0–P3 runtime profiles | Unchanged guarantees. This backend profile is a separate axis; schema availability cannot activate distributed operation, interruption, recovery, or P3. | Migration must preserve complete bindings, request/requirement commitments, diff --git a/docs/public/backends.md b/docs/public/backends.md index 4a56059da..e0ed7a422 100644 --- a/docs/public/backends.md +++ b/docs/public/backends.md @@ -28,9 +28,3 @@ cancellation and effect reports for backend authors. Read the [protocol and migration guide](https://github.com/OpenRAE/rae/blob/main/docs/explain/reference/backend-operation-supervision.md). These contracts keep unknown effects explicit. Publishing them does not certify that a backend can interrupt work or recover after a failure. - -A backend that implements the protocol can list the guarantees it provides -under `capabilities.operation_supervision` in its manifest. Trial compilation -refuses a backend that lacks a guarantee the experiment's timeout or retry -choices need. For example, `on_timeout: cancel` needs `cancellation`. A trial -with a single attempt and no cancellation on timeout needs no declaration. diff --git a/docs/requirements/API-402/requirement.md b/docs/requirements/API-402/requirement.md index bc5831de1..d443056e7 100644 --- a/docs/requirements/API-402/requirement.md +++ b/docs/requirements/API-402/requirement.md @@ -6,7 +6,7 @@ type: FUNCTIONAL priority: MUST wave: 1 created_at: 2026-04-03T05:40:04.988670Z -updated_at: 2026-09-27T00:00:00.000000Z +updated_at: 2026-09-25T00:00:00.000000Z --- # API-402 — Plain-Data Execution, Result, And History Contracts @@ -57,25 +57,3 @@ Current state: implemented. Portable live-execution contracts are required so in - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/_backend_operation_exports.py` (Public operation contract facade exports) - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_stubs/manifest.py` (Keep operation supervision opt-in; legacy stub does not advertise an unimplemented provider) - IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_reference_backend/manifest.py` (Keep operation supervision opt-in for reference emulation) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/execution_requirements.py` (Backend operation guarantees derived from authored trial timeout and retry choices) -- IMPLEMENTS → SPEC `contracts/schemas/plans/admitted-trial-plan-v1.json` (Admitted trial entries record their derived required operation guarantees) -- IMPLEMENTS → SPEC `contracts/schemas/backend-manifest/backend-manifest-v2.json` (Optional operation-supervision guarantee declaration) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/cleanup_admission.py` (Execution-authority admission against cleanup capability and declared guarantees) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_processor/trial_compiler/entry_admission.py` (Trial compilation refuses backends that cannot honour authored execution choices) -- TESTS → TEST `implementations/python/tests/test_issue_1361_execution_requirements.py` (Derivation, plan consistency, manifest declaration and trial-compilation refusal) -- DOCUMENTS → DOCUMENTATION `docs/decisions/issue-1361-sdl-execution-recovery-preflight.md` (Execution choices at backend admission; owner scope resolution) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/backend_manifest.py` (Internal manifest carries and validates the operation-supervision declaration) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/capabilities.py` (Internal operation-supervision capability declaration) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/capability_admission.py` (Re-export execution-authority admission from the capability admission facade) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/manifest.py` (Manifest v2 adapter delegates operational capability conversion) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_backend_protocols/operational_manifest.py` (Operational capability payloads and conversion, including operation supervision) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/admitted_trial_plan.py` (Admitted plan checks each entry's required guarantees against its controls) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/admitted_trial_plan_components.py` (Admitted execution controls record the required operation guarantees) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/manifests.py` (Backend capabilities v2 include the operation-supervision declaration) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/operational_manifest_capabilities.py` (Operation-supervision guarantee declaration model) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_contracts/contracts/participant_manifests.py` (Manifest requires the operation contract family for an operation-supervision declaration) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_processor/trial_compiler/compiler.py` (Trial compilation derives and records required guarantees per entry) -- IMPLEMENTS → CODE_FILE `implementations/python/packages/raes_processor/trial_compiler/models.py` (Per-entry compilation authority carries the selected backend manifests) -- TESTS → TEST `implementations/python/tests/test_specification_coverage.py` (Current coverage capture binds the issue #1361 source) -- TESTS → TEST `implementations/python/tests/test_formal_semantic_validation.py` (Current retest release binds the issue #1361 source) -- TESTS → TEST `implementations/python/tests/test_issue_989_versioned_evidence.py` (Versioned evidence history includes the issue #1361 captures) diff --git a/docs/research/formal-semantic-validation/analysis-v55.json b/docs/research/formal-semantic-validation/analysis-v55.json deleted file mode 100644 index e9c638750..000000000 --- a/docs/research/formal-semantic-validation/analysis-v55.json +++ /dev/null @@ -1,155 +0,0 @@ -{ - "analysis_id": "issue-1361-analysis-v55", - "claim": { - "allowed_evidence": [ - "production parser and semantic-validator results", - "canonical compiled digests", - "participant contract regression tests", - "pinned protocol, corpus, and execution snapshot" - ], - "claim_id": "asr-530-formal-semantic-validation-retest", - "disallowed_evidence": [ - "schema success as semantic proof", - "workflow reachability as network or exploit reachability", - "FM labels as gate outcomes", - "attribution as counterfactual proof", - "formal prose or maintainer confidence alone" - ], - "evidence_artifacts": [ - "docs/research/formal-semantic-validation/protocol-v2.json", - "docs/research/formal-semantic-validation/corpus/manifest-v4.json", - "docs/research/formal-semantic-validation/execution-snapshot-v55.json", - "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", - "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", - "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", - "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json" - ], - "falsification_protocol": "Replay every retained and new case through its production entrypoint, require complete digest and evidence joins, execute participant fixtures, and derive status from the recorded outcomes.", - "objective_fail_criteria": "A supported negative passes, a positive fails, an observation drifts, a required participant case is missing, or weaker evidence is promoted to solver, exploit-path, runtime-stability, or counterfactual assurance.", - "objective_pass_criteria": "Every claim class has positive and negative cases, all supported cases reproduce the frozen outcome, every participant obligation has passing positive and negative fixtures, and unsupported classes remain untested.", - "statement": "At the recorded source-state digest, the retained RAES controls have the bounded statuses recorded here; historical releases are integrity evidence, not current replay evidence.", - "threats_to_validity": [ - "The issue-specific corpus is intentionally small and does not enumerate every validator invariant.", - "The participant fixtures exercise reference production contracts and tests, not every independent backend realization.", - "The replay gate runs on one Python reference configuration and one pinned RAES revision.", - "Unsupported solver-level classes have protocol cases but no executable observations." - ] - }, - "claim_results": [ - { - "case_count": 2, - "claim_class_id": "schema-validity", - "evidence_status": "demonstrated", - "limitations": [ - "Bounded to the named source/model structural controls." - ], - "matching_case_count": 2, - "participant_obligation_count": 0, - "replayable_case_count": 2, - "unsupported_case_count": 0 - }, - { - "case_count": 4, - "claim_class_id": "semantic-consistency", - "evidence_status": "partial", - "limitations": [ - "Partial coverage of named static semantics and participant obligations, not universal consistency." - ], - "matching_case_count": 4, - "participant_obligation_count": 7, - "replayable_case_count": 4, - "unsupported_case_count": 0 - }, - { - "case_count": 2, - "claim_class_id": "graph-reachability", - "evidence_status": "partial", - "limitations": [ - "Partial workflow control-flow reachability only; not network, service, or exploit reachability." - ], - "matching_case_count": 2, - "participant_obligation_count": 0, - "replayable_case_count": 2, - "unsupported_case_count": 0 - }, - { - "case_count": 4, - "claim_class_id": "constraint-satisfiability", - "evidence_status": "demonstrated", - "limitations": [ - "Demonstrated only for raes-finite-domain-satisfiability-v1 and its pinned solver configuration." - ], - "matching_case_count": 4, - "participant_obligation_count": 0, - "replayable_case_count": 2, - "unsupported_case_count": 2 - }, - { - "case_count": 4, - "claim_class_id": "exploit-path-validity", - "evidence_status": "demonstrated", - "limitations": [ - "Demonstrated only for the admitted snapshot, typed graph, query, semantics, and bounded search profile." - ], - "matching_case_count": 4, - "participant_obligation_count": 0, - "replayable_case_count": 2, - "unsupported_case_count": 2 - }, - { - "case_count": 2, - "claim_class_id": "determinism-stability", - "evidence_status": "partial", - "limitations": [ - "Partial parse-to-compile repeatability only; runtime and backend determinism are untested." - ], - "matching_case_count": 2, - "participant_obligation_count": 0, - "replayable_case_count": 2, - "unsupported_case_count": 0 - }, - { - "case_count": 2, - "claim_class_id": "counterfactual-necessity", - "evidence_status": "untested", - "limitations": [ - "Untested because no governed intervention or ablation entrypoint ran." - ], - "matching_case_count": 2, - "participant_obligation_count": 0, - "replayable_case_count": 0, - "unsupported_case_count": 2 - } - ], - "corpus_revision": "4.0.0", - "evidence_status": "partial", - "execution_id": "issue-1361-execution-v55", - "generated_at": "2026-09-26", - "limitations": [ - "Satisfiability is limited to raes-finite-domain-satisfiability-v1 and its exact translation, theory, and Z3 configuration.", - "The subset-minimal unsatisfiable core is not a universal proof certificate.", - "Exploit-path results are limited to the admitted snapshot, normalized graph, query, transition semantics, and bounded search profile.", - "A valid path is not backend execution and an invalid path is not real-world non-exploitability.", - "The production exploit-path JSON loader permits duplicate keys; the research loader rejects them without claiming stronger production behavior.", - "Participant replay inherits the host environment and is not described as hermetic.", - "Counterfactual necessity remains untested.", - "Scoped observation demand is not a claim class in this preregistration and is not promoted to demonstrated by this retest.", - "EXP-732 provenance joins are verified by their dedicated regression suite; this retained corpus makes no universal run, apparatus, source, or augmentation assurance claim.", - "This retained corpus does not establish native backend attestation fidelity; materialization contract checks remain separate operational provenance, not experimental observations.", - "Capture admission and evidence-proof authority are verified by issue-1237 regression tests, not promoted to a new claim class by this retained corpus.", - "Evidence-requirement refinement lineage is outside this retained formal claim set; this retest refreshes integrated source provenance without promoting that feature to a formal claim.", - "Authoring-adapter transport behavior is outside this retained formal claim set.", - "Operational recovery observation and startup reconciliation are verified by their API-404 regression suite, not promoted to a new formal claim class by this retained corpus.", - "Single-owner store admission, immutable target/run scope, and provider shutdown ordering are verified by their API-404 CP-5 regression suite, not promoted to a formal claim by this retained corpus.", - "Mixed and staged trial admission is verified by its SEM-234/SCE-002/API-407 regression suite, not promoted to a new formal claim class by this retained corpus.", - "Offline control-plane maintenance, readiness, and bounded audit behavior are verified by issue #1186 runtime tests, not promoted to a formal claim by this retained corpus.", - "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", - "Issue #1189 profile declarations and capability admission are covered by dedicated runtime tests; the retained formal corpus does not execute control-plane profile composition.", - "Issue #1016 mixed-runtime coordination is covered by dedicated runtime tests; the retained formal corpus does not establish backend-native mixed realization, multi-controller coordination, IFC, or equivalence.", - "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", - "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", - "Issue #1389 temporal-subject admission is verified by dedicated compiler tests and adds no new formal-semantic claim to this retained corpus." - ], - "plain_language_outcome": "Retained controls replay against the merged backend-operation source and the issue #1361 execution-authority admission. Prior claim limits and unsupported classes remain unchanged.", - "protocol_revision": "2.0.0" -} diff --git a/docs/research/formal-semantic-validation/bundles/retest-v55.json b/docs/research/formal-semantic-validation/bundles/retest-v55.json deleted file mode 100644 index 5224c62b6..000000000 --- a/docs/research/formal-semantic-validation/bundles/retest-v55.json +++ /dev/null @@ -1,122 +0,0 @@ -{ - "analysis_path": "docs/research/formal-semantic-validation/analysis-v55.json", - "analysis_sha256": "95bc89f3b56d28ae4cba9f1903baa339c5400978910b9ed78194960f8961c615", - "artifacts": [ - { - "artifact_id": "finite-domain-satisfiable-v2-input", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", - "sha256": "0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" - }, - { - "artifact_id": "finite-domain-satisfiable-v2-evidence", - "kind": "production-evidence", - "path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", - "sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add" - }, - { - "artifact_id": "finite-domain-unsatisfiable-v2-input", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", - "sha256": "cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" - }, - { - "artifact_id": "finite-domain-unsatisfiable-v2-evidence", - "kind": "production-evidence", - "path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", - "sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d" - }, - { - "artifact_id": "typed-exploit-path-valid-v2-input", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", - "sha256": "0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" - }, - { - "artifact_id": "typed-exploit-path-valid-v2-evidence", - "kind": "production-evidence", - "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", - "sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c" - }, - { - "artifact_id": "typed-exploit-path-invalid-v2-input", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", - "sha256": "0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" - }, - { - "artifact_id": "typed-exploit-path-invalid-v2-evidence", - "kind": "production-evidence", - "path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", - "sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533" - }, - { - "artifact_id": "schema-valid-control-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml", - "sha256": "41a9adffdf9f5f2ccc2f887dcf7b15fba3b47c83a1af15f33db872c4a2449d67" - }, - { - "artifact_id": "schema-unknown-field-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml", - "sha256": "51cf62319a86c95a2517995939d1f370573051835e4b55bb6d5beaf049640481" - }, - { - "artifact_id": "semantic-resolved-objective-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml", - "sha256": "75834bdc883e2003e1c473870bdf75700978955bb83095c6bd718ba6bd3908a6" - }, - { - "artifact_id": "semantic-dangling-assertion-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml", - "sha256": "1d25bee5f556054e5f0a518df025e4c62e080e1964035e3c1a12e074d88d3a5d" - }, - { - "artifact_id": "semantic-ambiguous-reference-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml", - "sha256": "653cbd2fd62e220d49fb86f80133884207df5ae6752846345ae3085b93f6e4ed" - }, - { - "artifact_id": "semantic-feature-cycle-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml", - "sha256": "e1f66d95a9ad039687aec8cccbc8843b514072ff08e006c1b4ca6aa5cd8d4ed1" - }, - { - "artifact_id": "workflow-reachable-control-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml", - "sha256": "54c40ceb98ad47247447d737973b2c55e8fb2045e209c7545c4fb20cf42dc3dc" - }, - { - "artifact_id": "workflow-unreachable-step-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml", - "sha256": "ef22ef2e260f1a7fd92d286f9b571716436b192ddfd54aea7bdfcfdda4ca52a2" - }, - { - "artifact_id": "compile-repeatability-control-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", - "sha256": "0bc40900d598c1af7a405d798ca19710405e53ced262d8733081abf12edf89fe" - }, - { - "artifact_id": "compile-non-vacuity-control-comparison-fixture", - "kind": "corpus-input", - "path": "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml", - "sha256": "d85338f89f20a45515b12da8640173c1a52e47eb17ca0f4f6b4f8f3306e863a1" - } - ], - "bundle_id": "raes-formal-semantic-validation", - "corpus_path": "docs/research/formal-semantic-validation/corpus/manifest-v4.json", - "corpus_sha256": "c57207af72406aa4f70882b9bbeb7cedcc79cf3854c878a95e3eb1fa59ea7a72", - "protocol_path": "docs/research/formal-semantic-validation/protocol-v2.json", - "protocol_sha256": "abf94093e344bf495dfb04e8b0c5985c0beaab8ebb17a75e15c8674fa81b1a7c", - "revision": "56.0.0", - "snapshot_path": "docs/research/formal-semantic-validation/execution-snapshot-v55.json", - "snapshot_sha256": "27d633d5a3f360cd6a4c7dea114df926a0abcff1798c6223aedcfb7fc0e81be9" -} diff --git a/docs/research/formal-semantic-validation/execution-snapshot-v55.json b/docs/research/formal-semantic-validation/execution-snapshot-v55.json deleted file mode 100644 index 079465dce..000000000 --- a/docs/research/formal-semantic-validation/execution-snapshot-v55.json +++ /dev/null @@ -1,652 +0,0 @@ -{ - "baseline": { - "execution_id": "issue-1389-execution-v54", - "release_path": "docs/research/formal-semantic-validation/bundles/retest-v54.json", - "release_revision": "55.0.0", - "release_sha256": "89591fe7e90a57a5d6047eb442171a6c1b1fdac7e5cf13ef458a374dd0a54398" - }, - "captured_at": "2026-09-27T18:30:54.525687+00:00", - "commands": [ - { - "argv": [ - "implementations/python/.venv/bin/python", - "tools/check_formal_semantic_validation.py" - ], - "command_id": "bundle-replay", - "network": "disabled" - }, - { - "argv": [ - "implementations/python/.venv/bin/pytest", - "-q", - "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", - "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule", - "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", - "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved", - "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", - "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes", - "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", - "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality", - "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", - "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality", - "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", - "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record", - "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", - "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" - ], - "command_id": "participant-fixtures", - "network": "disabled" - }, - { - "argv": [ - "implementations/python/.venv/bin/raes", - "processor", - "satisfiability", - "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", - "--profile", - "raes-finite-domain-satisfiability-v1" - ], - "command_id": "finite-domain-satisfiable-v2", - "network": "disabled" - }, - { - "argv": [ - "implementations/python/.venv/bin/raes", - "processor", - "satisfiability", - "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", - "--profile", - "raes-finite-domain-satisfiability-v1" - ], - "command_id": "finite-domain-unsatisfiable-v2", - "network": "disabled" - }, - { - "argv": [ - "implementations/python/.venv/bin/raes", - "processor", - "exploit-path", - "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", - "--profile", - "raes-exploit-path-analysis-v1" - ], - "command_id": "typed-exploit-path-valid-v2", - "network": "disabled" - }, - { - "argv": [ - "implementations/python/.venv/bin/raes", - "processor", - "exploit-path", - "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", - "--profile", - "raes-exploit-path-analysis-v1" - ], - "command_id": "typed-exploit-path-invalid-v2", - "network": "disabled" - } - ], - "configuration_id": "raes-python-reference-offline-v41", - "corpus_revision": "4.0.0", - "deviations": [], - "execution_id": "issue-1361-execution-v55", - "execution_status": "complete", - "observations": [ - { - "actual_outcome": "accepted", - "analysis_profile": null, - "case_id": "schema-valid-control", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/schema-valid.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "A passing minimal source does not establish semantic correctness." - ], - "replayable": true, - "result_digest": "f7d364ef384df8a1526b489501835b635021c860793b5764f91d956710d2250c", - "source_digest": null - }, - { - "actual_outcome": "rejected", - "analysis_profile": null, - "case_id": "schema-unknown-field", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "SDLParseError", - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/schema-invalid-unknown-field.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The observation covers one unknown-field defect only." - ], - "replayable": true, - "result_digest": "f55d834b458f8e069e1c69061b4cc0a6d61e0e052bf90c670f2e6a5ad8b5bd98", - "source_digest": null - }, - { - "actual_outcome": "accepted", - "analysis_profile": null, - "case_id": "semantic-resolved-objective", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/semantic-valid-participant-identity-v2.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "This is a positive control for one objective-reference slice." - ], - "replayable": true, - "result_digest": "652288785dc09095955ed3649f6407d616fb7c4d4f4188df4ed513ccb7537e0b", - "source_digest": null - }, - { - "actual_outcome": "rejected", - "analysis_profile": null, - "case_id": "semantic-dangling-assertion", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "SDLValidationError", - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/semantic-invalid-dangling-ref-participant-identity-v2.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "A single dangling reference does not prove complete semantic coverage." - ], - "replayable": true, - "result_digest": "0207cf616b56708ca9b8c4499d3301abe22dbe52162cf8d58d3bec429d9db024", - "source_digest": null - }, - { - "actual_outcome": "rejected", - "analysis_profile": null, - "case_id": "semantic-ambiguous-reference", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "SDLValidationError", - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/semantic-invalid-ambiguous-ref.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "One namespace collision does not enumerate every ambiguity surface." - ], - "replayable": true, - "result_digest": "9da4a87797d228e0012ab6b30459f4892e41aa6f224a9840be035fee4a2eea73", - "source_digest": null - }, - { - "actual_outcome": "rejected", - "analysis_profile": null, - "case_id": "semantic-feature-cycle", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "SDLValidationError", - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/semantic-invalid-feature-cycle.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "One static dependency cycle does not establish general constraint satisfiability." - ], - "replayable": true, - "result_digest": "d15dbcd99fb4f20b965d7031b07dd6534576302270399c3fa656d29e7de02b83", - "source_digest": null - }, - { - "actual_outcome": "accepted", - "analysis_profile": null, - "case_id": "workflow-reachable-control", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/workflow-reachable.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The graph is workflow control flow only." - ], - "replayable": true, - "result_digest": "b1b49649b54bd59d4ef357b39cf9158da90f4eae560f8dd756acf97bd0827a06", - "source_digest": null - }, - { - "actual_outcome": "rejected", - "analysis_profile": null, - "case_id": "workflow-unreachable-step", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "SDLValidationError", - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/workflow-unreachable.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The result does not establish network, service, participant, or exploit reachability." - ], - "replayable": true, - "result_digest": "bb931d19346ef9193408ae6c85deb4079704378fc5f00dc5f47a2817cff21943", - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "whole-scenario-satisfiable-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "No governed whole-scenario constraint theory or solver exists." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "whole-scenario-unsatisfiable-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Local checks cannot produce a whole-scenario unsat certificate." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "valid-exploit-path-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The issue-168 baseline had no canonical typed attack graph or path-query entrypoint." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "invalid-exploit-path-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Vulnerability and topology declarations are not an invalid-path proof." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "stable", - "analysis_profile": null, - "case_id": "compile-repeatability-control", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The witness ends at compiled output." - ], - "replayable": true, - "result_digest": "11264a648a949917c0e84a2a1e5d116139a35e6cb941844735a422df95141d6c", - "source_digest": null - }, - { - "actual_outcome": "distinguishable", - "analysis_profile": null, - "case_id": "compile-non-vacuity-control", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/determinism-a.sdl.yaml", - "docs/research/formal-semantic-validation/corpus/determinism-b.sdl.yaml" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Distinct digests are a non-vacuity control, not semantic non-equivalence proof." - ], - "replayable": true, - "result_digest": "72c1ee8c7bbc1f970216fa232b3d4ae917bcb003bd823439bbac8a5db94214e2", - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "necessity-witness-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "No governed intervention or ablation protocol exists." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "unsupported", - "analysis_profile": null, - "case_id": "non-necessity-control-request", - "configuration_digest": null, - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": null, - "evidence_artifact_path": null, - "evidence_artifact_sha256": null, - "evidence_digest": null, - "evidence_profile": null, - "evidence_refs": [ - "docs/decisions/issue-168-formal-semantic-validation-reachability-preflight.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Attribution and negative fixtures do not demonstrate non-necessity." - ], - "replayable": false, - "result_digest": null, - "source_digest": null - }, - { - "actual_outcome": "satisfiable", - "analysis_profile": "raes-finite-domain-satisfiability-v1", - "case_id": "finite-domain-satisfiable-v2", - "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "scenario-satisfiability-evidence/v1", - "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", - "evidence_artifact_sha256": "554202313d678046958b5c028e2de26ff03c74895cfac552677eed74e8153add", - "evidence_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", - "evidence_profile": "scenario-satisfiability-evidence/v1", - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/satisfiable-control.sdl.yaml", - "docs/research/formal-semantic-validation/evidence/finite-domain-satisfiable-v4.json", - "specs/formal/scenario-satisfiability/README.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Demonstrates only the pinned finite-domain theory, translation, solver profile, and source." - ], - "replayable": true, - "result_digest": "sha256:23c2cae7d95d4cc83d77ca576e3911477b169ecc311c977cb45490345f633b5a", - "source_digest": "sha256:0ca9eaba9dc47171f7a042dc6753faa6c820c65ee966538f9d65fac5342202e8" - }, - { - "actual_outcome": "unsatisfiable", - "analysis_profile": "raes-finite-domain-satisfiability-v1", - "case_id": "finite-domain-unsatisfiable-v2", - "configuration_digest": "sha256:1204635e17e759e9ad3bd6be2ecb28c6de05c07ead6dfdd15936ed5d3d5b81b2", - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "scenario-satisfiability-evidence/v1", - "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", - "evidence_artifact_sha256": "c972725ef64822a75a60380afc11f08eac25b7fe9b091d39b058b3c9f7c8031d", - "evidence_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", - "evidence_profile": "scenario-satisfiability-evidence/v1", - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/unsatisfiable-control.sdl.yaml", - "docs/research/formal-semantic-validation/evidence/finite-domain-unsatisfiable-v4.json", - "specs/formal/scenario-satisfiability/README.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The subset-minimal core is evidence for the pinned translation and solver, not a proof certificate for arbitrary SDL." - ], - "replayable": true, - "result_digest": "sha256:317b5cad00aa7f4f7868dca66127611ba19d40ffd86f35815502622814df54c1", - "source_digest": "sha256:cfef56a1f56d5f0db9da195377fd75694bdd0f0b92932fdb8fafcbd3f7baf6c5" - }, - { - "actual_outcome": "valid-path", - "analysis_profile": "raes-exploit-path-analysis-v1", - "case_id": "typed-exploit-path-valid-v2", - "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "exploit-path-analysis-evidence/v1", - "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", - "evidence_artifact_sha256": "1b7f55d04db172da32658187c64a88c13b5f4d565267ce2be7cb86a9d04cb70c", - "evidence_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", - "evidence_profile": "exploit-path-analysis-evidence/v1", - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/exploit-path-valid-v3.json", - "docs/research/formal-semantic-validation/evidence/typed-exploit-path-valid-v4.json", - "specs/formal/exploit-path-analysis/README.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The witness is bounded to the admitted snapshot, normalized graph, query, semantics, and search profile; it does not establish backend execution." - ], - "replayable": true, - "result_digest": "sha256:2d4d1a362751abd9544beb8af7f8c6331d04dac8f4abc315fb261f81fbaf4387", - "source_digest": "sha256:0afe635a63db5b6e6380ac70982fd61d09790745d51a10d670321304121e7c39" - }, - { - "actual_outcome": "invalid-path", - "analysis_profile": "raes-exploit-path-analysis-v1", - "case_id": "typed-exploit-path-invalid-v2", - "configuration_digest": "sha256:7f8876d81feb77d3a3239be2fb8337de8885e2744f8786728ba23e4e6027bc0a", - "configuration_id": "raes-python-reference-offline-v41", - "diagnostic_kind": "exploit-path-analysis-evidence/v1", - "evidence_artifact_path": "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", - "evidence_artifact_sha256": "244f895a64f14c10916ab0533ab462ce80a328021cd6a50c30a4aa59266d5533", - "evidence_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", - "evidence_profile": "exploit-path-analysis-evidence/v1", - "evidence_refs": [ - "docs/research/formal-semantic-validation/corpus/exploit-path-invalid-v3.json", - "docs/research/formal-semantic-validation/evidence/typed-exploit-path-invalid-v4.json", - "specs/formal/exploit-path-analysis/README.md" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Structured rejection proves only that this bounded graph/query cannot reach its goal; it does not establish real-world non-exploitability." - ], - "replayable": true, - "result_digest": "sha256:1b416bb5a4d29d57c961b769cc9d3af5d9328624e3eebf104d57f39a94c5bb97", - "source_digest": "sha256:0b2293d4a8983515ff05c516be6e6b418a4f3f09e055250a00bf15fda861aab3" - } - ], - "participant_observations": [ - { - "evidence_refs": [ - "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_disclosure_is_separate_from_observable_projection", - "implementations/python/tests/test_sem_208_participant_behavior.py::test_hidden_truth_cannot_be_observed_without_explicit_disclosure_rule" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Covers the reference SDL/contract path, not every backend projection." - ], - "negative_outcome": "passed", - "obligation_id": "hidden-vs-visible-projection", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_contract_declares_sem_211_classes_and_compiles_them", - "implementations/python/tests/test_sem_211_participant_action_semantics.py::test_action_result_rejects_success_when_preconditions_are_unresolved" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Covers declared applicability and one unresolved-precondition failure." - ], - "negative_outcome": "passed", - "obligation_id": "fail-closed-action-applicability", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_runtime_snapshot_publishes_joint_action_and_time_context_records", - "implementations/python/tests/test_run_308_concurrent_participant_execution.py::test_joint_action_record_contract_rejects_unordered_conflicting_writes" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Contract evidence does not prove every backend's live concurrency fidelity." - ], - "negative_outcome": "passed", - "obligation_id": "shared-state-effects", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_accepts_supported_order_claim_strengths", - "implementations/python/tests/test_participant_runtime_invariants.py::test_order_discipline_rejects_wall_clock_causality" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Rejecting timestamp-only causality does not supply counterfactual proof." - ], - "negative_outcome": "passed", - "obligation_id": "ordering-before-causality", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_attribution_edge_round_trips_on_terminal_observation", - "implementations/python/tests/test_sem_212_participant_attribution_semantics.py::test_timestamp_adjacency_cannot_be_reported_as_strong_causality" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Attribution labels disclose basis; they do not demonstrate necessity." - ], - "negative_outcome": "passed", - "obligation_id": "evidence-labeled-attribution", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_outcome_interpretation_rule_parses_and_compiles_explicit_layers", - "implementations/python/tests/test_sem_215_participant_outcome_interpretation.py::test_local_action_success_does_not_imply_objective_success_without_rule_record" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "The fixtures establish layer separation, not outcome validity in every realization." - ], - "negative_outcome": "passed", - "obligation_id": "participant-local-outcome-separation", - "positive_outcome": "passed" - }, - { - "evidence_refs": [ - "implementations/python/tests/test_realization_honesty_conformance.py::test_constructive_envelope_runs_positive_and_negative_honesty_probes", - "implementations/python/tests/test_realization_honesty_conformance.py::test_only_native_live_can_support_native_conformance" - ], - "execution_id": "issue-1361-execution-v55", - "limitations": [ - "Reference conformance evidence remains bounded to declared realization profiles." - ], - "negative_outcome": "passed", - "obligation_id": "realization-profile-honesty", - "positive_outcome": "passed" - } - ], - "protocol_revision": "2.0.0", - "raes_revision": "6cae755852f1f7826ba30f49a74efcc91ea32dc8", - "source_state": { - "base_revision": "6cae755852f1f7826ba30f49a74efcc91ea32dc8", - "checkout_state": "modified", - "implementation_digest": "5aae891d544955fec78e2fc552abc57eb909d4e83dd88aa07cc09f5adc2898bd", - "profile": "python-reference-source/v2" - }, - "versions": { - "python": "3.14.4", - "raes": "5.0.0", - "z3_engine": "4.16.0", - "z3_solver": "4.16.0.0" - } -} diff --git a/docs/research/formal-semantic-validation/index.md b/docs/research/formal-semantic-validation/index.md index 4991d3bd6..74cfd2465 100644 --- a/docs/research/formal-semantic-validation/index.md +++ b/docs/research/formal-semantic-validation/index.md @@ -336,7 +336,7 @@ outcomes and claim limits, recording the positive successor's changed result digest; the dangling-reference diagnostic remains identical. It establishes no autonomy threshold, authority grant, or realized attribution. -Current validation requires explicit release 56.0.0, rejects unsupported future +Current validation requires explicit release 55.0.0, rejects unsupported future or duplicate revisions, and never accepts an old/new output-digest pair as a substitute for replay. Historical releases (including the issue-826 supplement) undergo pin, shape, control, and internal-join checks without executing current @@ -506,8 +506,3 @@ Release 55.0.0 is recorded in [`analysis-v54.json`](analysis-v54.json). It replays the retained formal cases after issue #1389 admitted the exact participant inject delivery address as a temporal subject. Outcomes and bounded claim limits remain unchanged. - -Release 56.0.0 replays the retained controls on the source that adds issue -#1361 trial execution-authority admission, in -[`execution-snapshot-v55.json`](execution-snapshot-v55.json) and -[`analysis-v55.json`](analysis-v55.json). Earlier captures retain their source identities. diff --git a/docs/research/specification-coverage/analysis-v55.json b/docs/research/specification-coverage/analysis-v55.json deleted file mode 100644 index 911179a89..000000000 --- a/docs/research/specification-coverage/analysis-v55.json +++ /dev/null @@ -1,105 +0,0 @@ -{ - "analysis_id": "issue-1361-specification-coverage-v55", - "backend_leakage": [], - "claim": { - "allowed_evidence": [ - "pinned source metadata and bounded paraphrases", - "production parser, semantic, instantiation, admission, compiler, contract, and profile results", - "exact artifact digests and typed pointers", - "documented missing-concept and backend-specific dispositions" - ], - "claim_id": "raes-standardized-configurable-specification-coverage", - "disallowed_evidence": [ - "field-count or schema breadth alone", - "the existing scenario stress corpus as the representative request corpus", - "free-form metadata as typed coverage", - "backend-private interpretation", - "post-hoc removal or repair of falsifying concepts" - ], - "evidence_artifacts": [ - "docs/research/specification-coverage/protocol-v1.json", - "docs/research/specification-coverage/execution-snapshot-v55.json", - "docs/research/specification-coverage/analysis-v55.json" - ], - "falsification_protocol": "docs/research/specification-coverage/protocol-v1.json", - "objective_fail_criteria": "A load-bearing concept is missing or lossy, an applicable stage fails, or backend vocabulary is required in core SDL while the result claims success.", - "objective_pass_criteria": "Every load-bearing concept passes at every owning stage, backend-specific mechanics stay outside core SDL, and no requested concept is silently lost.", - "statement": "RAES provides a standardized configurable portable specification surface for the preregistered representative cyber-agent evaluation environment requirements without backend vocabulary in core SDL.", - "threats_to_validity": [ - "The representative corpus contains four source strata and sixteen atomic concepts rather than every cyber-range requirement.", - "The reference processor and repository fixtures are not independent backend implementations.", - "No live range, simulator federation, or participant execution was part of this offline specification-coverage test." - ] - }, - "classification_counts": { - "deliberately-backend-specific": 1, - "directly-expressible": 10, - "missing": 3, - "profile-or-manifest-constraint": 2 - }, - "evidence_status": "partial", - "execution_status": "complete", - "generated_at": "2026-09-26", - "limitations": [ - "This result demonstrates bounded specification coverage, not universal cyber-range coverage, usability, adoption, backend substitution, or behavioral equivalence.", - "The three missing concepts are evidence, not implementation tasks within this snapshot.", - "The retained protocol does not test recursive realization or plan-level profile semantics; this release only re-establishes its original bounded coverage result against the current implementation.", - "The retained protocol does not test evidence-requirement refinement lineage; the dedicated EXP-731 regression suite covers that production boundary.", - "Authoring-adapter transport behavior is outside this retained protocol.", - "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", - "Operational recovery observation and startup reconciliation are covered by their API-404 regression suite, not a new claim in this preregistered matrix.", - "Store ownership, immutable runtime scope, and provider shutdown ordering are covered by the API-404 CP-5 regression suite, not by this retained specification-coverage protocol.", - "Mixed/staged trial compilation and admission are covered by issue #1015 regression tests, not by this retained specification-coverage corpus; no live mixed-runtime result is claimed.", - "Issue #1186 control-plane recovery operations are covered by their runtime regression suite, not by this retained specification-coverage corpus.", - "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", - "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", - "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", - "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution.", - "Participant-local outcome state is verified by the ACT-618 tests; this retained corpus makes no additional outcome-state claim.", - "Backend operation supervision contracts are covered by issue #1360 contract tests; this retained offline corpus establishes no live backend supervision or recovery guarantee.", - "This capture replays the merged issue #1360 and #1357 source; the protocol makes no live backend execution or supervision claim.", - "This capture replays the merged issue #1360 and #1358 source; the protocol makes no live backend execution or supervision claim.", - "Issue #1389 participant inject delivery temporal-subject admission is covered by dedicated compiler tests; this retained matrix makes no new timing or execution claim.", - "Issue #1361 trial execution-authority admission is covered by dedicated contract and compiler tests; this retained matrix makes no live backend execution or supervision claim." - ], - "load_bearing_results": { - "failed": 0, - "missing": 0, - "passed": 10, - "total": 10 - }, - "plain_language_outcome": "The retained specification matrix replays unchanged classifications and claim limits against source that admits exact participant inject delivery temporal subjects. Dedicated compiler tests, rather than this corpus, verify that delivery-timing behavior.", - "protocol_revision": "1.0.0", - "request_results": [ - { - "concept_count": 6, - "failed_stage_count": 0, - "missing_count": 0, - "request_id": "survey-representative-range", - "status": "demonstrated" - }, - { - "concept_count": 5, - "failed_stage_count": 1, - "missing_count": 1, - "request_id": "cyborg-participant-evaluation", - "status": "partial" - }, - { - "concept_count": 3, - "failed_stage_count": 1, - "missing_count": 1, - "request_id": "vsdl-configurable-infrastructure", - "status": "partial" - }, - { - "concept_count": 2, - "failed_stage_count": 1, - "missing_count": 1, - "request_id": "cyber-dem-federation", - "status": "partial" - } - ], - "snapshot_id": "issue-1361-specification-coverage-v55", - "snapshot_sha256": "5db372a8249fc923ba3d2a12bf7956ab59ddfc90fa3e22d3ca34beaf16ce1551" -} diff --git a/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-1361-v55.json b/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-1361-v55.json deleted file mode 100644 index 8ab9d8ef8..000000000 --- a/docs/research/specification-coverage/bundles/raes-standardized-specification-coverage-issue-1361-v55.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "analysis_path": "docs/research/specification-coverage/analysis-v55.json", - "analysis_sha256": "3270d158a04d1144943f2db055779ba1d57ae9f39f398341c07c5f407851461f", - "bundle_id": "raes-standardized-specification-coverage", - "protocol_path": "docs/research/specification-coverage/protocol-v1.json", - "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", - "revision": "55.0.0", - "snapshot_path": "docs/research/specification-coverage/execution-snapshot-v55.json", - "snapshot_sha256": "f9dd4db92b7578cd250ae6608411b369513551266d051dca2e29763e7c9bca52" -} diff --git a/docs/research/specification-coverage/execution-snapshot-v55.json b/docs/research/specification-coverage/execution-snapshot-v55.json deleted file mode 100644 index 684488037..000000000 --- a/docs/research/specification-coverage/execution-snapshot-v55.json +++ /dev/null @@ -1,700 +0,0 @@ -{ - "artifacts": [ - { - "artifact_id": "enterprise-participant-sdl", - "kind": "sdl", - "path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032", - "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" - }, - { - "artifact_id": "port-range-sdl", - "kind": "sdl", - "path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f", - "validator": "raes parse, semantic, instantiation/admission, and compiler pipeline" - }, - { - "artifact_id": "experiment-task-contract", - "kind": "experiment-task", - "path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", - "sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc", - "validator": "raes_contracts.contracts.ExperimentTaskModel" - }, - { - "artifact_id": "apparatus-context-contract", - "kind": "experiment-apparatus-context", - "path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", - "sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299", - "validator": "raes_contracts.contracts.ExperimentApparatusContextModel" - }, - { - "artifact_id": "backend-profile", - "kind": "backend-profile", - "path": "contracts/profiles/backend/orchestration-capable.json", - "sha256": "f70b8505a5c0055416db86c533e2e5bf08b11e5a514f076223b6d6c36215a092", - "validator": "raes_contracts.backend_profiles.BackendProfileModel" - }, - { - "artifact_id": "known-limitations", - "kind": "documentation", - "path": "docs/explain/sdl/limitations.md", - "sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4", - "validator": "documentation evidence only" - } - ], - "baseline": { - "release_revision": "1.1.0", - "release_sha256": "4020a1d56c7fe2831cec59ea64a12bbda9d38ccd94f93b916dd90f1a28f17fcb" - }, - "captured_at": "2026-09-27T18:30:54.525687+00:00", - "concept_results": [ - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "range-topology", - "rationale": "SDL nodes and infrastructure own host, network, link, and dependency meaning; the compiler emits canonical node deployment addresses.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed VM declaration.", - "outcome": "passed", - "pointer": "/nodes/shipping-portal", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Links and dependencies resolved.", - "outcome": "passed", - "pointer": "/infrastructure/shipping-portal", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Published instantiated shape admitted.", - "outcome": "passed", - "pointer": "/nodes/shipping-portal", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Canonical deployment address retained.", - "outcome": "passed", - "pointer": "/node_deployments/provision.node.shipping-portal", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/nodes/shipping-portal" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "exercise-roles", - "rationale": "SDL entity roles own exercise responsibility without becoming control-plane identity or authorization.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed red role.", - "outcome": "passed", - "pointer": "/entities/enterprise-participant/role", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Entity references validated.", - "outcome": "passed", - "pointer": "/entities/enterprise-participant", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Role retained after instantiation.", - "outcome": "passed", - "pointer": "/entities/enterprise-participant/role", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Role retained in entity specification.", - "outcome": "passed", - "pointer": "/entity_specs/enterprise-participant/role", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/entities/enterprise-participant/role" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "evaluation-objectives", - "rationale": "SDL objectives own organization ownership, participant assignment, targets, windows, and assertion-based success; measures remain experiment contracts.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed objective declaration.", - "outcome": "passed", - "pointer": "/objectives/demonstrate-handoff", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Owner, participant assignment, targets, assertions, and workflow refs resolved.", - "outcome": "passed", - "pointer": "/objectives/demonstrate-handoff/success", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Objective retained in admitted artifact.", - "outcome": "passed", - "pointer": "/objectives/demonstrate-handoff", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Canonical objective address retained.", - "outcome": "passed", - "pointer": "/objectives/evaluation.objective.demonstrate-handoff", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/objectives/demonstrate-handoff" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "control-workflows", - "rationale": "SDL workflows own the portable control graph and compile to canonical orchestration state contracts.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed control graph.", - "outcome": "passed", - "pointer": "/workflows/yard-recovery", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Step graph and objective refs validated.", - "outcome": "passed", - "pointer": "/workflows/yard-recovery/steps", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Workflow retained after instantiation.", - "outcome": "passed", - "pointer": "/workflows/yard-recovery", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Canonical control graph retained.", - "outcome": "passed", - "pointer": "/workflows/orchestration.workflow.yard-recovery", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/workflows/yard-recovery" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "authored-evidence-expectations", - "rationale": "SDL evidence requirements own portable capture intent and remain distinct from evidence records and measures.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed capture obligation.", - "outcome": "passed", - "pointer": "/evidence_requirements/objective-truth-evidence", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Source refs and bindings validated.", - "outcome": "passed", - "pointer": "/evidence_requirements/objective-truth-evidence", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Evidence intent retained in admitted artifact.", - "outcome": "passed", - "pointer": "/evidence_requirements/objective-truth-evidence", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - } - ], - "typed_pointer": "/evidence_requirements/objective-truth-evidence" - }, - { - "backend_support": "profile-bound", - "backend_vocabulary_occurrences": [], - "classification": "profile-or-manifest-constraint", - "completeness_disposition": "implemented", - "concept_id": "apparatus-selection-constraints", - "rationale": "The experiment task contract binds processor/backend identities, manifest refs, and capabilities outside SDL.", - "stage_results": [ - { - "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", - "diagnostic_codes": [], - "note": "Closed ExperimentTaskModel validated.", - "outcome": "passed", - "pointer": "/apparatus_constraints/allowed_backend_refs/0", - "stage_id": "contract", - "validation_strength": "contract" - } - ], - "typed_pointer": "/apparatus_constraints/allowed_backend_refs/0" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "participant-agent", - "rationale": "SDL agents own participant entity, knowledge, actions, observation boundaries, and operating scope.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed participant declaration.", - "outcome": "passed", - "pointer": "/agents/participant-agent", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Participant refs and scope validated.", - "outcome": "passed", - "pointer": "/agents/participant-agent/observation_boundaries", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Participant retained in admitted artifact.", - "outcome": "passed", - "pointer": "/agents/participant-agent", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Compiled participant scope retained.", - "outcome": "passed", - "pointer": "/agent_specs/participant-agent", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/agents/participant-agent" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "participant-action-contract", - "rationale": "The action contract declares portable preconditions, effects, observations, evidence, and failure classes without a runner command.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed action contract.", - "outcome": "passed", - "pointer": "/action_contracts/probe-customer-portal-login", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Action refs and evidence bindings validated.", - "outcome": "passed", - "pointer": "/action_contracts/probe-customer-portal-login/effects", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Action retained in admitted artifact.", - "outcome": "passed", - "pointer": "/action_contracts/probe-customer-portal-login", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Canonical action address retained.", - "outcome": "passed", - "pointer": "/action_contracts/participant.action-contract.probe-customer-portal-login", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/action_contracts/probe-customer-portal-login" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "participant-observation-boundary", - "rationale": "The observation boundary separately declares visible, hidden, and evidence-only information with transition rules.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed observation boundary.", - "outcome": "passed", - "pointer": "/observation_boundaries/participant-view", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Information refs and transitions validated.", - "outcome": "passed", - "pointer": "/observation_boundaries/participant-view/view_rules", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Boundary retained in admitted artifact.", - "outcome": "passed", - "pointer": "/observation_boundaries/participant-view", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "diagnostic_codes": [], - "note": "Canonical boundary address retained.", - "outcome": "passed", - "pointer": "/observation_boundaries/participant.observation-boundary.participant-view", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/observation_boundaries/participant-view" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "evaluation-measure", - "rationale": "ExperimentTaskModel owns metric construct, unit, direction, aggregation, and evidence requirements outside SDL objectives.", - "stage_results": [ - { - "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", - "diagnostic_codes": [], - "note": "Closed task contract validated.", - "outcome": "passed", - "pointer": "/evaluation_protocol/metric_definitions/foothold-achieved", - "stage_id": "contract", - "validation_strength": "contract" - } - ], - "typed_pointer": "/evaluation_protocol/metric_definitions/foothold-achieved" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "missing", - "completeness_disposition": "documented-gap", - "concept_id": "participant-tool-affordance", - "rationale": "This preregistered matrix has no tested carrier for participant tool affordances. The retained missing classification records missing coverage evidence, not the absence of current participant-behavior capabilities.", - "stage_results": [ - { - "artifact_path": "docs/explain/sdl/limitations.md", - "diagnostic_codes": [], - "note": "The preregistered carrier slot was not run; metadata does not substitute for a typed coverage test.", - "outcome": "not_run", - "pointer": null, - "stage_id": "authored", - "validation_strength": "not-applicable" - } - ], - "typed_pointer": null - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "directly-expressible", - "completeness_disposition": "implemented", - "concept_id": "resource-constrained-topology", - "rationale": "SDL node resources and infrastructure dependencies express portable resource intent without provider resource identifiers.", - "stage_results": [ - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Typed CPU and memory declaration.", - "outcome": "passed", - "pointer": "/nodes/shipping-portal/resources", - "stage_id": "authored", - "validation_strength": "structural" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Resource-bearing topology validated.", - "outcome": "passed", - "pointer": "/infrastructure/shipping-portal", - "stage_id": "semantic", - "validation_strength": "semantic" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Constraints retained in admitted artifact.", - "outcome": "passed", - "pointer": "/nodes/shipping-portal/resources", - "stage_id": "instantiated", - "validation_strength": "phase-admitted" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "diagnostic_codes": [], - "note": "Deployment specification retains resource intent.", - "outcome": "passed", - "pointer": "/node_deployments/provision.node.shipping-portal", - "stage_id": "compiled", - "validation_strength": "compiled" - } - ], - "typed_pointer": "/nodes/shipping-portal/resources" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "missing", - "completeness_disposition": "documented-gap", - "concept_id": "formal-constraint-satisfiability", - "rationale": "This coverage matrix did not exercise a solver-backed carrier. The separate formal-semantic-validation release demonstrates its bounded finite-domain profile; that result is not silently imported into this protocol's missing carrier slot.", - "stage_results": [ - { - "artifact_path": "docs/explain/sdl/limitations.md", - "diagnostic_codes": [], - "note": "No coverage-carrier execution was performed here; independent solver evidence does not change this preregistered denominator.", - "outcome": "not_run", - "pointer": null, - "stage_id": "semantic", - "validation_strength": "not-applicable" - } - ], - "typed_pointer": null - }, - { - "backend_support": "profile-bound", - "backend_vocabulary_occurrences": [ - { - "allowed": true, - "artifact_path": "source:vsdl-paper", - "pointer": "source sections 4-5", - "reason": "Legitimate VSDL realization vocabulary, not RAES core SDL structure.", - "term": "OpenStack/Terraform/Packer" - } - ], - "classification": "deliberately-backend-specific", - "completeness_disposition": "external", - "concept_id": "provider-specific-provisioning", - "rationale": "Provider image selection and provisioning engines are realization mechanics and therefore remain outside core SDL.", - "stage_results": [ - { - "artifact_path": "contracts/profiles/backend/orchestration-capable.json", - "diagnostic_codes": [], - "note": "The portable boundary requires backend contracts; it does not standardize a provider engine.", - "outcome": "not_applicable", - "pointer": "/required_contracts", - "stage_id": "realization-disclosure", - "validation_strength": "profile" - } - ], - "typed_pointer": null - }, - { - "backend_support": "profile-bound", - "backend_vocabulary_occurrences": [], - "classification": "profile-or-manifest-constraint", - "completeness_disposition": "implemented", - "concept_id": "apparatus-clock-context", - "rationale": "ExperimentApparatusContextModel records clock authority, time domain, and synchronization as apparatus facts outside scenario meaning.", - "stage_results": [ - { - "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", - "diagnostic_codes": [], - "note": "Closed apparatus context contract validated.", - "outcome": "passed", - "pointer": "/clocks/0", - "stage_id": "contract", - "validation_strength": "contract" - } - ], - "typed_pointer": "/clocks/0" - }, - { - "backend_support": "not-evaluated", - "backend_vocabulary_occurrences": [], - "classification": "missing", - "completeness_disposition": "documented-gap", - "concept_id": "federated-object-event-exchange", - "rationale": "The federated cyber object/event exchange carrier was not exercised by this preregistered matrix. Runtime event internals are not treated as equivalent evidence.", - "stage_results": [ - { - "artifact_path": "docs/explain/sdl/limitations.md", - "diagnostic_codes": [], - "note": "The missing coverage-carrier test is recorded explicitly, without inferring an ecosystem-wide capability absence.", - "outcome": "not_run", - "pointer": null, - "stage_id": "contract", - "validation_strength": "not-applicable" - } - ], - "typed_pointer": null - } - ], - "deviations": [ - { - "artifact_path": "examples/scenarios/enterprise-participant-evidence-loop.sdl.yaml", - "baseline_sha256": "54ba1a60220e27a55da9cd2a407d7d3ab836fa54460d0b0c6cad87c2e744ddbb", - "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", - "retest_sha256": "f7a8897beec243e188ee081975006fad32725f469f267db6e75a1e1cf5727032" - }, - { - "artifact_path": "examples/scenarios/port-authority-surge-response.sdl.yaml", - "baseline_sha256": "a27c7a64e0c5c618fadaccafdf1a4e71600170a8b77b983190822b5141f00dec", - "rationale": "Migrate participant affiliations and explicit objective assignment, retaining organizational intent and portable action-contract declarations without granting execution authority.", - "retest_sha256": "0d5497ec946b863e6985284ec487dde7d7f6bf710a985be51401ac0e5e79dc4f" - }, - { - "artifact_path": "contracts/fixtures/experiment-core/experiment-task-v1/valid/reference.json", - "baseline_sha256": "21952a752f4e8581a9fc3b872e4bc308150548170d38bcfc83dbbe35ff5e0b9f", - "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", - "retest_sha256": "f3edf713ac6af26bad609136851c6dd434bfb87ce919a2d8c4414c1035deeafc" - }, - { - "artifact_path": "contracts/fixtures/experiment-core/experiment-apparatus-context-v1/valid/reference.json", - "baseline_sha256": "9536d897a09cbc6920e667e4f8f9371e51307aa0b3b5ff3c7de682dd783420ab", - "rationale": "Replay the retained preregistered artifact against the current evidence-provenance validation implementation.", - "retest_sha256": "e6fa559c5e961f0aab448d0f70dead24aa74fa8ba5f20e1b72f88e11473c9299" - }, - { - "artifact_path": "docs/explain/sdl/limitations.md", - "baseline_sha256": "129cf17810aad4c51988bc872e28fe43ae95019a80053c42d800ff7e2b9cc93e", - "rationale": "Correct historical mandatory-profile guidance after issue #1207; retain the preregistered missing-concept classifications and coverage limits.", - "retest_sha256": "489eeab3ce682627682311581eb98af9abb9ff42a437145af266eefb71dc7fc4" - } - ], - "execution_status": "complete", - "implementation_surfaces": [ - { - "content_sha256": "634b1dafb497e37709b0e8b7901be6ddaeec585e7ce71fd7248ece05afaf8c74", - "path": "implementations/python/packages/raes_contracts", - "surface_id": "contract-models" - }, - { - "content_sha256": "b7322e897c1141071f5f78f6f6acd590c675f00ab0410bb5e1ef2d17a70c997c", - "path": "implementations/python/packages/raes_processor", - "surface_id": "processor-pipeline" - }, - { - "content_sha256": "9ecd780448b054693503bab246120a1a2bb49a43016d0b9c27c5284ba609833f", - "path": "implementations/python/packages/raes", - "surface_id": "sdl-pipeline" - } - ], - "limitations": [ - "The execution validates the pinned reference implementation and published contracts, not an independent backend.", - "Repository-owned examples are exact execution artifacts but are not themselves the literature-derived request corpus; the protocol's requests and concepts are.", - "No live range, participant, simulator federation, or provider provisioning engine was executed.", - "Missing concepts remain frozen in this snapshot and require separately scoped product work before a later rerun.", - "This capture replays the retained protocol after EXP-732 run, apparatus, measurement-channel, and augmentation-producer provenance validation; it adds no independent backend or universal provenance assurance claim.", - "Materialization attestation is covered by its dedicated regression suite, not a new claim in this preregistered matrix.", - "This capture refreshes the corrected runtime limitations prose for issue #959; the protocol, coverage classifications and implementation source are unchanged.", - "This capture replays open-by-default augmentation scope integrated with the EXP-731 evidence refinements after composition type refinement; it does not evaluate native backend scope enforcement or broaden the preregistered coverage claims.", - "This capture replays the retained protocol after merging ACT-612 participant relationships with open-by-default augmentation scope; it adds no claim of realized participant relationships or native backend scope enforcement.", - "This capture replays issue #1299 partial listener descriptions on the integrated source state; endpoint completeness and backend admission remain outside this protocol's claims.", - "This capture also binds authoring-adapter semantic conformance to the integrated source; adapter transport behavior remains outside this protocol's claims.", - "Reviewed OCI mirror and pre-seed admission is covered by its own regression suites and the development artifact policy gate, not a new claim in this preregistered matrix.", - "This capture binds issue #1297 service-manager identity, native-name, and explicitly selected systemd-state contract changes to the integrated source. It exercises no live service manager and adds no backend-execution claim.", - "This capture replays the retained specification-coverage protocol after API-404 startup reconciliation added an operational recovery-observation contract. It does not evaluate crash recovery, classify provider effects, or broaden EXP-715 experiment-observation claims.", - "This capture binds API-404 single-owner store admission and immutable target/run scope to the integrated source. The retained offline protocol does not exercise process leases, SQLite lifecycle ordering, or crash recovery.", - "This capture binds issue #1015 deterministic mixed and staged trial admission to the integrated source. The retained offline language corpus does not execute mixed runtimes, phase transitions, backend handoff, or scheduler-driven realization.", - "This replay binds issue #1186 offline control-plane maintenance, readiness, and bounded audit code to the integrated source. The retained language corpus does not execute store recovery, HTTP health behavior, or audit redaction.", - "Issue #1187 control-plane crash/profile conformance and HTTP security changes are covered by their dedicated regression suite, not promoted to new claims by this retained corpus.", - "Issue #1189 control-plane profile declarations are covered by their dedicated runtime suite, not promoted to new claims by the retained language corpus.", - "Issue #1016 mixed-runtime coordination is covered by its dedicated runtime suite. The retained language corpus does not execute mixed providers or establish backend-native realization, multi-controller coordination, IFC, or equivalence.", - "Issue #610's reconciliation demonstration harness is covered by its dedicated processor and CLI suite, not promoted to new claims by the retained language corpus.", - "Participant identity, organization ownership, and participant assignment are separated by issue #1338. This retained offline corpus does not establish participant autonomy, execution authority, live backend fidelity, or causal attribution." - ], - "protocol_revision": "1.0.0", - "protocol_sha256": "e97a19e643e94c9e589dca823a63c6ce49d3329fe2a3cb888ab630838ed93125", - "raes_revision": "6cae755852f1f7826ba30f49a74efcc91ea32dc8", - "snapshot_id": "issue-1361-specification-coverage-v55", - "snapshot_revision": "55.0.0", - "source_state": { - "base_revision": "6cae755852f1f7826ba30f49a74efcc91ea32dc8", - "checkout_state": "modified", - "implementation_digest": "5aae891d544955fec78e2fc552abc57eb909d4e83dd88aa07cc09f5adc2898bd", - "profile": "python-reference-source/v2" - } -} diff --git a/docs/research/specification-coverage/index.md b/docs/research/specification-coverage/index.md index 8abff9429..af9bd738b 100644 --- a/docs/research/specification-coverage/index.md +++ b/docs/research/specification-coverage/index.md @@ -292,7 +292,7 @@ the port scenario. Historical captures and archived example bytes are retained. The matrix classifications and untested concepts are unchanged; no execution authority, successful action, or live backend fidelity is inferred. -Current validation requires release 55.0.0 and rejects duplicate or unsupported +Current validation requires release 54.0.0 and rejects duplicate or unsupported future revisions. It executes current artifacts, requires exact source and package hashes, and checks all passing stage pointers. `source_state` discloses the base Git commit, modified checkout state, and exact implementation digest; @@ -443,13 +443,3 @@ and claim limits remain unchanged; participant delivery timing is verified by its dedicated compiler tests in [`execution-snapshot-v54.json`](execution-snapshot-v54.json) and [`analysis-v54.json`](analysis-v54.json). - -## Trial execution-authority admission source replay - -Release 55.0.0 replays the retained protocol on the source that adds issue -#1361 trial execution-authority admission, in -[`execution-snapshot-v55.json`](execution-snapshot-v55.json) and -[`analysis-v55.json`](analysis-v55.json). Classifications and claim limits are -unchanged. The derived backend guarantees and their admission have dedicated -contract and compiler tests; this capture makes no live backend recovery claim. -Earlier captures retain their source identities. diff --git a/implementations/python/packages/raes_backend_protocols/backend_manifest.py b/implementations/python/packages/raes_backend_protocols/backend_manifest.py index be40060ae..d827b14f9 100644 --- a/implementations/python/packages/raes_backend_protocols/backend_manifest.py +++ b/implementations/python/packages/raes_backend_protocols/backend_manifest.py @@ -9,14 +9,12 @@ from raes_contracts.apparatus import ApparatusIdentity, ConceptBinding, RealizationSupportDeclaration from raes_contracts.manifest_authority import validate_backend_supported_contract_versions from raes_contracts.realization_envelope import BackendRealizationEnvelopeModel -from raes_contracts.versions import BACKEND_OPERATION_CONTRACT_IDS from .capabilities import ( BackendCapabilitySet, CleanupCapabilities, EvaluatorCapabilities, ObservationCapabilities, - OperationSupervisionCapabilities, OrchestratorCapabilities, ParticipantRuntimeCapabilities, ProvisionerCapabilities, @@ -57,7 +55,6 @@ class _BackendManifestOptions(TypedDict, total=False): cleanup: CleanupCapabilities | None time: TimeCapabilities | None recovery_observation: RecoveryObservationCapabilities | None - operation_supervision: OperationSupervisionCapabilities | None realization_envelope: BackendRealizationEnvelopeModel | None domain_profile_context_digest: str | None @@ -84,7 +81,6 @@ def __init__(self, **options: Unpack[_BackendManifestOptions]) -> None: supported_contract_versions = _validate_supported_contract_versions(options) _validate_cleanup_capability_contracts(supported_contract_versions, capabilities.cleanup) _validate_time_capability_contracts(supported_contract_versions, capabilities.time) - _validate_operation_supervision_contracts(supported_contract_versions, capabilities.operation_supervision) _validate_coordinated_reset_capabilities(capabilities) realization_envelope = options.get("realization_envelope") _validate_realization_envelope_contract(supported_contract_versions, realization_envelope) @@ -150,10 +146,6 @@ def time(self) -> TimeCapabilities | None: def recovery_observation(self) -> RecoveryObservationCapabilities | None: return self.capabilities.recovery_observation - @property - def operation_supervision(self) -> OperationSupervisionCapabilities | None: - return self.capabilities.operation_supervision - @property def has_orchestrator(self) -> bool: return self.orchestrator is not None @@ -231,7 +223,6 @@ def _resolve_capabilities(options: _BackendManifestOptions) -> BackendCapability cleanup=options.get("cleanup"), time=options.get("time"), recovery_observation=options.get("recovery_observation"), - operation_supervision=options.get("operation_supervision"), ) @@ -256,17 +247,6 @@ def _validate_realization_envelope_contract( raise ValueError("realization-envelope-v1 support requires realization_envelope") -def _validate_operation_supervision_contracts( - supported_contract_versions: frozenset[str], - operation_supervision: OperationSupervisionCapabilities | None, -) -> None: - if ( - operation_supervision is not None - and not frozenset(BACKEND_OPERATION_CONTRACT_IDS) <= supported_contract_versions - ): - raise ValueError("operation supervision capabilities require the backend operation contract family") - - def _validate_cleanup_capability_contracts( supported_contract_versions: frozenset[str], cleanup: CleanupCapabilities | None, diff --git a/implementations/python/packages/raes_backend_protocols/capabilities.py b/implementations/python/packages/raes_backend_protocols/capabilities.py index f94d29667..8352a168b 100644 --- a/implementations/python/packages/raes_backend_protocols/capabilities.py +++ b/implementations/python/packages/raes_backend_protocols/capabilities.py @@ -2,9 +2,7 @@ from collections.abc import Collection from dataclasses import dataclass, field -from typing import get_args -from raes_contracts.contracts.backend_operation import OperationGuarantee from raes_contracts.controlled_vocabularies import validate_controlled_vocabulary_scope_values from raes_contracts.manifest_authority import validate_backend_supported_contract_versions from raes_contracts.operation_lifecycle import OperationKind @@ -34,7 +32,6 @@ TIME_CAPABILITY_REQUIRED_CONTRACTS = _time_capabilities.TIME_CAPABILITY_REQUIRED_CONTRACTS TimeCapabilities = _time_capabilities.TimeCapabilities -OPERATION_GUARANTEES: frozenset[str] = frozenset(get_args(OperationGuarantee)) OBSERVATION_CAPABILITY_CAPTURE_KIND_SCOPE = "capabilities.observation.supported_capture_kinds" OBSERVATION_CAPABILITY_CHANNEL_KIND_SCOPE = "capabilities.observation.supported_channel_kinds" OBSERVATION_CAPABILITY_SEALING_MODE_SCOPE = "capabilities.observation.supported_sealing_modes" @@ -286,23 +283,6 @@ def __post_init__(self) -> None: raise ValueError("administrative resolution is not a recoverable backend effect") -@dataclass(frozen=True) -class OperationSupervisionCapabilities: - """Declared backend operation guarantees; not willingness or evidence.""" - - name: str - guarantees: frozenset[str] - - def __post_init__(self) -> None: - if not self.name.strip(): - raise ValueError("OperationSupervisionCapabilities.name must be non-empty") - if not self.guarantees: - raise ValueError("OperationSupervisionCapabilities.guarantees must not be empty") - unknown = self.guarantees - OPERATION_GUARANTEES - if unknown: - raise ValueError("OperationSupervisionCapabilities.guarantees contains unknown guarantees") - - @dataclass(frozen=True) class BackendCapabilitySet: """Backend-specific nested capability blocks.""" @@ -315,7 +295,6 @@ class BackendCapabilitySet: cleanup: CleanupCapabilities | None = None time: TimeCapabilities | None = None recovery_observation: RecoveryObservationCapabilities | None = None - operation_supervision: OperationSupervisionCapabilities | None = None def __getattr__(name: str) -> object: @@ -331,6 +310,7 @@ def __getattr__(name: str) -> object: "participant_feature_support_gaps", "participant_runtime_capability_contract_gaps", "resolve_participant_feature_support", + "require_cleanup_plan_capability", "require_time_model_capability", "time_capability_contract_gaps", "time_model_capability_gaps", @@ -338,8 +318,4 @@ def __getattr__(name: str) -> object: from . import capability_admission return getattr(capability_admission, name) - if name in {"require_cleanup_plan_capability", "require_execution_authority_capability"}: - from . import cleanup_admission - - return getattr(cleanup_admission, name) raise AttributeError(name) diff --git a/implementations/python/packages/raes_backend_protocols/capability_admission.py b/implementations/python/packages/raes_backend_protocols/capability_admission.py index a71cad610..7c4e78b74 100644 --- a/implementations/python/packages/raes_backend_protocols/capability_admission.py +++ b/implementations/python/packages/raes_backend_protocols/capability_admission.py @@ -23,6 +23,7 @@ if TYPE_CHECKING: from raes_contracts.contracts.time_model import TimeModelDeclarationModel + from raes_contracts.contracts.trial_cleanup import TrialCleanupPlanModel from .backend_manifest import BackendManifest from .capabilities import ParticipantRuntimeCapabilities, TimeCapabilities @@ -440,6 +441,50 @@ def require_time_model_capability( raise ValueError("; ".join(gaps)) +def _required_cleanup_actions(plan: TrialCleanupPlanModel) -> set[str]: + return { + obligation.action_kind + for obligation in plan.cleanup_obligations.values() + if obligation.requirement == "required" + } + + +def _required_cleanup_probe_methods(plan: TrialCleanupPlanModel) -> set[str]: + probe_refs = set(plan.clean_state.verification_probe_refs) + probe_refs.update( + probe_ref + for obligation in plan.cleanup_obligations.values() + if obligation.requirement == "required" + for probe_ref in obligation.verification_probe_refs + ) + return {probe_ref.partition(":")[0] for probe_ref in probe_refs} + + +def _require_supported_cleanup_values(label: str, required: set[str], supported: frozenset[str]) -> None: + unsupported = sorted(required - supported) + if unsupported: + raise ValueError(f"unsupported cleanup {label}: {', '.join(unsupported)}") + + +def require_cleanup_plan_capability(manifest: BackendManifest, plan: TrialCleanupPlanModel) -> None: + """Fail admission when a backend cannot satisfy a portable cleanup plan.""" + + cleanup = manifest.cleanup + if cleanup is None: + raise ValueError("backend does not declare cleanup capabilities") + + _require_supported_cleanup_values("action kinds", _required_cleanup_actions(plan), cleanup.supported_action_kinds) + _require_supported_cleanup_values( + "verification methods", _required_cleanup_probe_methods(plan), cleanup.supported_verification_methods + ) + + if plan.clean_state.mode == "declared-reusable" and not cleanup.supports_reusable_state: + raise ValueError("backend does not support declared reusable state") + required_cleanup = any(obligation.requirement == "required" for obligation in plan.cleanup_obligations.values()) + if required_cleanup and not cleanup.supports_residual_state_disclosure: + raise ValueError("required cleanup needs backend residual-state disclosure") + + __all__ = [ "participant_feature_support_gaps", "resolve_participant_feature_support", diff --git a/implementations/python/packages/raes_backend_protocols/cleanup_admission.py b/implementations/python/packages/raes_backend_protocols/cleanup_admission.py deleted file mode 100644 index 4b3052920..000000000 --- a/implementations/python/packages/raes_backend_protocols/cleanup_admission.py +++ /dev/null @@ -1,82 +0,0 @@ -"""Admission of trial cleanup plans and authored execution choices against backend capability.""" - -from __future__ import annotations - -from collections.abc import Iterable -from typing import TYPE_CHECKING - -if TYPE_CHECKING: - from raes_contracts.contracts.trial_cleanup import TrialCleanupPlanModel - - from .backend_manifest import BackendManifest - - -def _required_cleanup_actions(plan: TrialCleanupPlanModel) -> set[str]: - return { - obligation.action_kind - for obligation in plan.cleanup_obligations.values() - if obligation.requirement == "required" - } - - -def _required_cleanup_probe_methods(plan: TrialCleanupPlanModel) -> set[str]: - probe_refs = set(plan.clean_state.verification_probe_refs) - probe_refs.update( - probe_ref - for obligation in plan.cleanup_obligations.values() - if obligation.requirement == "required" - for probe_ref in obligation.verification_probe_refs - ) - return {probe_ref.partition(":")[0] for probe_ref in probe_refs} - - -def _require_supported_cleanup_values(label: str, required: set[str], supported: frozenset[str]) -> None: - unsupported = sorted(required - supported) - if unsupported: - raise ValueError(f"unsupported cleanup {label}: {', '.join(unsupported)}") - - -def require_cleanup_plan_capability(manifest: BackendManifest, plan: TrialCleanupPlanModel) -> None: - """Fail admission when a backend cannot satisfy a portable cleanup plan.""" - - cleanup = manifest.cleanup - if cleanup is None: - raise ValueError("backend does not declare cleanup capabilities") - - _require_supported_cleanup_values("action kinds", _required_cleanup_actions(plan), cleanup.supported_action_kinds) - _require_supported_cleanup_values( - "verification methods", _required_cleanup_probe_methods(plan), cleanup.supported_verification_methods - ) - - if plan.clean_state.mode == "declared-reusable" and not cleanup.supports_reusable_state: - raise ValueError("backend does not support declared reusable state") - required_cleanup = any(obligation.requirement == "required" for obligation in plan.cleanup_obligations.values()) - if required_cleanup and not cleanup.supports_residual_state_disclosure: - raise ValueError("required cleanup needs backend residual-state disclosure") - - -def require_execution_authority_capability( - manifest: BackendManifest, - *, - cleanup_plan: TrialCleanupPlanModel, - required_guarantees: Iterable[str], -) -> None: - """Fail admission when a backend cannot honour a trial's authored execution choices. - - The cleanup plan must be supported, and every operation guarantee derived - from the choices must be declared. A missing declaration is refusal, never - best effort. Runtime admission still rechecks the installed provider. - """ - - require_cleanup_plan_capability(manifest, cleanup_plan) - required = set(required_guarantees) - if not required: - return - supervision = manifest.operation_supervision - declared = supervision.guarantees if supervision is not None else frozenset() - missing = sorted(required - declared) - if missing: - raise ValueError(f"unsupported operation guarantees: {', '.join(missing)}") - - -__all__ = ["require_cleanup_plan_capability", "require_execution_authority_capability"] diff --git a/implementations/python/packages/raes_backend_protocols/manifest.py b/implementations/python/packages/raes_backend_protocols/manifest.py index c7d838748..12bd97773 100644 --- a/implementations/python/packages/raes_backend_protocols/manifest.py +++ b/implementations/python/packages/raes_backend_protocols/manifest.py @@ -15,6 +15,7 @@ BackendCapabilitiesV2Model, BackendCompatibilityModel, BackendManifestV2Model, + CleanupCapabilitiesModel, ConceptBindingEntryModel, EvaluatorCapabilitiesModel, OrchestratorCapabilitiesModel, @@ -22,6 +23,8 @@ ParticipantRuntimeCapabilitiesModel, RealizationObservationCapabilityModel, RealizationSupportDeclarationModel, + RecoveryObservationCapabilitiesModel, + TimeCapabilitiesModel, ) from raes_contracts.manifest_authority import BACKEND_SUPPORTED_CONTRACT_IDS from raes_contracts.realization_envelope import BackendRealizationEnvelopeModel @@ -30,13 +33,15 @@ BackendCapabilitySet, BackendCompatibility, BackendManifest, + CleanupCapabilities, EvaluatorCapabilities, OrchestratorCapabilities, ParticipantFeatureSupport, ParticipantRuntimeCapabilities, + RecoveryObservationCapabilities, + TimeCapabilities, ) from .observation_manifest import observation_capability_payload, observation_from_model -from .operational_manifest import operational_capabilities_from_model, operational_capability_payloads from .participant_execution_manifest import ( participant_execution_capability_kwargs, participant_execution_capability_payload, @@ -199,7 +204,54 @@ def backend_manifest_v2_model(manifest: BackendManifest) -> BackendManifestV2Mod else None ), "observation": observation_capability_payload(manifest.observation), - **operational_capability_payloads(manifest), + "cleanup": ( + CleanupCapabilitiesModel( + name=manifest.cleanup.name, + supported_contract_versions=sorted(manifest.cleanup.supported_contract_versions), + supported_action_kinds=sorted(manifest.cleanup.supported_action_kinds), + supported_verification_methods=sorted(manifest.cleanup.supported_verification_methods), + supports_reusable_state=manifest.cleanup.supports_reusable_state, + supports_residual_state_disclosure=manifest.cleanup.supports_residual_state_disclosure, + ).model_dump(mode="json") + if manifest.cleanup is not None + else None + ), + "time": ( + TimeCapabilitiesModel( + name=manifest.time.name, + supported_contract_versions=sorted(manifest.time.supported_contract_versions), + supported_domain_kinds=sorted(manifest.time.supported_domain_kinds), + supported_authority_kinds=sorted(manifest.time.supported_authority_kinds), + supported_advancement_modes=sorted(manifest.time.supported_advancement_modes), + supported_synchronization_modes=sorted(manifest.time.supported_synchronization_modes), + supported_mapping_kinds=sorted(manifest.time.supported_mapping_kinds), + supported_constraint_kinds=sorted(manifest.time.supported_constraint_kinds), + supported_reset_behaviors=sorted(manifest.time.supported_reset_behaviors), + supported_replay_behaviors=sorted(manifest.time.supported_replay_behaviors), + max_time_domains=manifest.time.max_time_domains, + max_clocks=manifest.time.max_clocks, + supports_pause=manifest.time.supports_pause, + supports_jump=manifest.time.supports_jump, + supports_exact_rational_mappings=manifest.time.supports_exact_rational_mappings, + supports_append_only_history=manifest.time.supports_append_only_history, + supports_run_provenance=manifest.time.supports_run_provenance, + supports_coordinated_participant_reset=(manifest.time.supports_coordinated_participant_reset), + constraints=dict(manifest.time.constraints), + ).model_dump(mode="json") + if manifest.time is not None + else None + ), + "recovery_observation": ( + RecoveryObservationCapabilitiesModel( + name=manifest.recovery_observation.name, + supported_operation_kinds=sorted( + manifest.recovery_observation.supported_operation_kinds, + key=lambda kind: kind.value, + ), + ).model_dump(mode="json") + if manifest.recovery_observation is not None + else None + ), }, ) @@ -312,6 +364,56 @@ def _participant_runtime_from_model( ) +def _cleanup_from_model(model: CleanupCapabilitiesModel | None) -> CleanupCapabilities | None: + if model is None: + return None + return CleanupCapabilities( + name=model.name, + supported_contract_versions=frozenset(model.supported_contract_versions), + supported_action_kinds=frozenset(model.supported_action_kinds), + supported_verification_methods=frozenset(model.supported_verification_methods), + supports_reusable_state=model.supports_reusable_state, + supports_residual_state_disclosure=model.supports_residual_state_disclosure, + ) + + +def _time_from_model(model: TimeCapabilitiesModel | None) -> TimeCapabilities | None: + if model is None: + return None + return TimeCapabilities( + name=model.name, + supported_contract_versions=frozenset(model.supported_contract_versions), + supported_domain_kinds=frozenset(model.supported_domain_kinds), + supported_authority_kinds=frozenset(model.supported_authority_kinds), + supported_advancement_modes=frozenset(model.supported_advancement_modes), + supported_synchronization_modes=frozenset(model.supported_synchronization_modes), + supported_mapping_kinds=frozenset(model.supported_mapping_kinds), + supported_constraint_kinds=frozenset(model.supported_constraint_kinds), + supported_reset_behaviors=frozenset(model.supported_reset_behaviors), + supported_replay_behaviors=frozenset(model.supported_replay_behaviors), + max_time_domains=model.max_time_domains, + max_clocks=model.max_clocks, + supports_pause=model.supports_pause, + supports_jump=model.supports_jump, + supports_exact_rational_mappings=model.supports_exact_rational_mappings, + supports_append_only_history=model.supports_append_only_history, + supports_run_provenance=model.supports_run_provenance, + supports_coordinated_participant_reset=model.supports_coordinated_participant_reset, + constraints=dict(model.constraints), + ) + + +def _recovery_observation_from_model( + model: RecoveryObservationCapabilitiesModel | None, +) -> RecoveryObservationCapabilities | None: + if model is None: + return None + return RecoveryObservationCapabilities( + name=model.name, + supported_operation_kinds=frozenset(model.supported_operation_kinds), + ) + + def _capability_set_from_model(model: BackendCapabilitiesV2Model) -> BackendCapabilitySet: return BackendCapabilitySet( provisioner=provisioner_from_model(model.provisioner), @@ -319,7 +421,9 @@ def _capability_set_from_model(model: BackendCapabilitiesV2Model) -> BackendCapa evaluator=_evaluator_from_model(model.evaluator), participant_runtime=_participant_runtime_from_model(model.participant_runtime), observation=observation_from_model(model.observation), - **operational_capabilities_from_model(model), + cleanup=_cleanup_from_model(model.cleanup), + time=_time_from_model(model.time), + recovery_observation=_recovery_observation_from_model(model.recovery_observation), ) diff --git a/implementations/python/packages/raes_backend_protocols/operational_manifest.py b/implementations/python/packages/raes_backend_protocols/operational_manifest.py deleted file mode 100644 index d7eaa6ea6..000000000 --- a/implementations/python/packages/raes_backend_protocols/operational_manifest.py +++ /dev/null @@ -1,161 +0,0 @@ -"""Manifest payloads and conversions for operational capability blocks. - -Cleanup, time, crash-recovery observation and operation supervision are -declared independently of the provisioning, orchestration and evaluation -surfaces, and are rendered and reconstructed together here. -""" - -from __future__ import annotations - -from typing import Any - -from raes_contracts.contracts import ( - BackendCapabilitiesV2Model, - CleanupCapabilitiesModel, - OperationSupervisionCapabilitiesModel, - RecoveryObservationCapabilitiesModel, - TimeCapabilitiesModel, -) - -from .capabilities import ( - BackendManifest, - CleanupCapabilities, - OperationSupervisionCapabilities, - RecoveryObservationCapabilities, - TimeCapabilities, -) - - -def operational_capability_payloads(manifest: BackendManifest) -> dict[str, Any]: - """Render the operational capability blocks of a v2 manifest payload.""" - - return { - "cleanup": ( - CleanupCapabilitiesModel( - name=manifest.cleanup.name, - supported_contract_versions=sorted(manifest.cleanup.supported_contract_versions), - supported_action_kinds=sorted(manifest.cleanup.supported_action_kinds), - supported_verification_methods=sorted(manifest.cleanup.supported_verification_methods), - supports_reusable_state=manifest.cleanup.supports_reusable_state, - supports_residual_state_disclosure=manifest.cleanup.supports_residual_state_disclosure, - ).model_dump(mode="json") - if manifest.cleanup is not None - else None - ), - "time": ( - TimeCapabilitiesModel( - name=manifest.time.name, - supported_contract_versions=sorted(manifest.time.supported_contract_versions), - supported_domain_kinds=sorted(manifest.time.supported_domain_kinds), - supported_authority_kinds=sorted(manifest.time.supported_authority_kinds), - supported_advancement_modes=sorted(manifest.time.supported_advancement_modes), - supported_synchronization_modes=sorted(manifest.time.supported_synchronization_modes), - supported_mapping_kinds=sorted(manifest.time.supported_mapping_kinds), - supported_constraint_kinds=sorted(manifest.time.supported_constraint_kinds), - supported_reset_behaviors=sorted(manifest.time.supported_reset_behaviors), - supported_replay_behaviors=sorted(manifest.time.supported_replay_behaviors), - max_time_domains=manifest.time.max_time_domains, - max_clocks=manifest.time.max_clocks, - supports_pause=manifest.time.supports_pause, - supports_jump=manifest.time.supports_jump, - supports_exact_rational_mappings=manifest.time.supports_exact_rational_mappings, - supports_append_only_history=manifest.time.supports_append_only_history, - supports_run_provenance=manifest.time.supports_run_provenance, - supports_coordinated_participant_reset=(manifest.time.supports_coordinated_participant_reset), - constraints=dict(manifest.time.constraints), - ).model_dump(mode="json") - if manifest.time is not None - else None - ), - "recovery_observation": ( - RecoveryObservationCapabilitiesModel( - name=manifest.recovery_observation.name, - supported_operation_kinds=sorted( - manifest.recovery_observation.supported_operation_kinds, - key=lambda kind: kind.value, - ), - ).model_dump(mode="json") - if manifest.recovery_observation is not None - else None - ), - "operation_supervision": ( - OperationSupervisionCapabilitiesModel( - name=manifest.operation_supervision.name, - guarantees=sorted(manifest.operation_supervision.guarantees), - ).model_dump(mode="json") - if manifest.operation_supervision is not None - else None - ), - } - - -def _cleanup_from_model(model: CleanupCapabilitiesModel | None) -> CleanupCapabilities | None: - if model is None: - return None - return CleanupCapabilities( - name=model.name, - supported_contract_versions=frozenset(model.supported_contract_versions), - supported_action_kinds=frozenset(model.supported_action_kinds), - supported_verification_methods=frozenset(model.supported_verification_methods), - supports_reusable_state=model.supports_reusable_state, - supports_residual_state_disclosure=model.supports_residual_state_disclosure, - ) - - -def _time_from_model(model: TimeCapabilitiesModel | None) -> TimeCapabilities | None: - if model is None: - return None - return TimeCapabilities( - name=model.name, - supported_contract_versions=frozenset(model.supported_contract_versions), - supported_domain_kinds=frozenset(model.supported_domain_kinds), - supported_authority_kinds=frozenset(model.supported_authority_kinds), - supported_advancement_modes=frozenset(model.supported_advancement_modes), - supported_synchronization_modes=frozenset(model.supported_synchronization_modes), - supported_mapping_kinds=frozenset(model.supported_mapping_kinds), - supported_constraint_kinds=frozenset(model.supported_constraint_kinds), - supported_reset_behaviors=frozenset(model.supported_reset_behaviors), - supported_replay_behaviors=frozenset(model.supported_replay_behaviors), - max_time_domains=model.max_time_domains, - max_clocks=model.max_clocks, - supports_pause=model.supports_pause, - supports_jump=model.supports_jump, - supports_exact_rational_mappings=model.supports_exact_rational_mappings, - supports_append_only_history=model.supports_append_only_history, - supports_run_provenance=model.supports_run_provenance, - supports_coordinated_participant_reset=model.supports_coordinated_participant_reset, - constraints=dict(model.constraints), - ) - - -def _recovery_observation_from_model( - model: RecoveryObservationCapabilitiesModel | None, -) -> RecoveryObservationCapabilities | None: - if model is None: - return None - return RecoveryObservationCapabilities( - name=model.name, - supported_operation_kinds=frozenset(model.supported_operation_kinds), - ) - - -def _operation_supervision_from_model( - model: OperationSupervisionCapabilitiesModel | None, -) -> OperationSupervisionCapabilities | None: - if model is None: - return None - return OperationSupervisionCapabilities(name=model.name, guarantees=frozenset(model.guarantees)) - - -def operational_capabilities_from_model(model: BackendCapabilitiesV2Model) -> dict[str, Any]: - """Reconstruct the internal operational capability blocks from a v2 model.""" - - return { - "cleanup": _cleanup_from_model(model.cleanup), - "time": _time_from_model(model.time), - "recovery_observation": _recovery_observation_from_model(model.recovery_observation), - "operation_supervision": _operation_supervision_from_model(model.operation_supervision), - } - - -__all__ = ["operational_capabilities_from_model", "operational_capability_payloads"] diff --git a/implementations/python/packages/raes_contracts/contracts/__init__.py b/implementations/python/packages/raes_contracts/contracts/__init__.py index d5f4d3cd3..f8cc3222d 100644 --- a/implementations/python/packages/raes_contracts/contracts/__init__.py +++ b/implementations/python/packages/raes_contracts/contracts/__init__.py @@ -207,7 +207,6 @@ BackendCapabilitiesV2Model, ConceptBindingEntryModel, ObservationCapabilitiesModel, - OperationSupervisionCapabilitiesModel, ParticipantFeatureSupportModel, ParticipantRuntimeCapabilitiesModel, ProcessorCapabilitiesV2Model, diff --git a/implementations/python/packages/raes_contracts/contracts/_backend_operation_exports.py b/implementations/python/packages/raes_contracts/contracts/_backend_operation_exports.py index ddf3c70ed..21f73b900 100644 --- a/implementations/python/packages/raes_contracts/contracts/_backend_operation_exports.py +++ b/implementations/python/packages/raes_contracts/contracts/_backend_operation_exports.py @@ -35,7 +35,6 @@ validate_backend_operation_history, validate_backend_operation_response, ) -from .execution_requirements import required_operation_guarantees from .operation_carriers import OperationReceiptModel, OperationStatusModel __all__ = [ @@ -60,7 +59,6 @@ "require_backend_operation_admission", "validate_backend_operation_history", "validate_backend_operation_response", - "required_operation_guarantees", "BACKEND_OPERATION_REQUEST_SCHEMA_VERSION", "BACKEND_OPERATION_CAPABILITIES_SCHEMA_VERSION", "BACKEND_OPERATION_CONTROL_SCHEMA_VERSION", diff --git a/implementations/python/packages/raes_contracts/contracts/_exports.py b/implementations/python/packages/raes_contracts/contracts/_exports.py index 79829da74..2499c8b14 100644 --- a/implementations/python/packages/raes_contracts/contracts/_exports.py +++ b/implementations/python/packages/raes_contracts/contracts/_exports.py @@ -60,7 +60,6 @@ "BackendManifestV2Model", "BackendCapabilitiesV2Model", "RecoveryObservationCapabilitiesModel", - "OperationSupervisionCapabilitiesModel", "BehavioralClaimBindingModel", "BEHAVIORAL_RELATION_PROFILE_SCHEMA_VERSION", "BehavioralRelationId", diff --git a/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan.py b/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan.py index 9ef8b1de8..6d57d1ae3 100644 --- a/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan.py +++ b/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan.py @@ -56,7 +56,6 @@ SelectionPolicyKind, ) from .base import ContractModel, NonEmptyString, PrefixedDigestString -from .execution_requirements import required_operation_guarantees from .experiment_apparatus import ExperimentStochasticControlModel from .random_stream import RandomStreamDrawRecordModel, TrialCoordinateModel from .schema_invariants import _add_raes_invariant @@ -321,11 +320,6 @@ def _validate_cleanup_joins(self) -> None: raise ValueError(f"entry cleanup_plan_ref {cleanup_ref!r} does not resolve to a plan cleanup block") if cleanup_plan.plan_entry_id != entry.plan_entry_id or cleanup_plan.run_id != entry.run_id: raise ValueError("referenced cleanup plan must bind the same plan_entry_id and run_id as the entry") - controls = entry.execution_controls - if controls.required_guarantees != required_operation_guarantees( - controls.on_timeout, cleanup_plan.retry_policy - ): - raise ValueError("entry required_guarantees must equal those derived from its execution controls") referenced_cleanup.add(cleanup_ref) self._validate_entry_draws(entry) orphan_cleanup = sorted(set(self.cleanup_plans) - referenced_cleanup) @@ -374,9 +368,7 @@ def __get_pydantic_json_schema__(cls, core_schema: CoreSchema, handler: GetJsonS "An admitted trial plan keeps map keys equal to embedded ids, keeps plan/entry/run identities distinct, " "gives every entry a unique logical coordinate and archival run_id, resolves cleanup and " "stochastic-control joins (with each draw addressed to its entry coordinate), exact mixed-composition " - "profile inputs, and isolation-proof entries within the sealed plan, requires each entry's required " - "backend guarantees to equal the canonical set derived from its execution controls and cleanup retry " - "policy, requires values duplicated from " + "profile inputs, and isolation-proof entries within the sealed plan, requires values duplicated from " "incumbent authorities (random-stream profile, " "binding condition/family) to agree, forbids bounded-parallel entries from sharing resources, matches " "admission cardinality, and binds the complete plan with a recomputed plan_digest over the entry set.", diff --git a/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan_components.py b/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan_components.py index 025b81c5c..930d1b0eb 100644 --- a/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan_components.py +++ b/implementations/python/packages/raes_contracts/contracts/admitted_trial_plan_components.py @@ -16,7 +16,6 @@ from raes.identifiers import PortableIdentifier from ..diagnostics import DiagnosticModel -from .backend_operation import OperationGuarantee from .base import ContractModel, NonEmptyString, PositiveInteger, PrefixedDigestString from .experiment_bindings import ExperimentBindingDescriptorModel from .experiment_manifest_references import ExperimentManifestReferenceModel @@ -268,31 +267,17 @@ class AdmittedExecutionControlModel(ContractModel): """Minimal schedule-independent attempt policy. Carries only whole-trial attempt timeout, the required cancellation/timeout - disposition, the cleanup-plan reference, and the backend guarantees those - choices require. The reset/compensation retry policy is owned by the - referenced ``TrialCleanupPlanModel.retry_policy`` and is not duplicated here; - ``required_guarantees`` is derived from it and ``on_timeout`` and is checked - against both by the plan, so a sealed plan cannot hold contradicting - requirements. It never carries worker, queue, placement, host, lease, or - mutable status data. + disposition, and the cleanup-plan reference. The reset/compensation retry + policy is owned by the referenced ``TrialCleanupPlanModel.retry_policy`` and + is not duplicated here, so a sealed plan cannot hold two contradicting retry + policies. It never carries worker, queue, placement, host, lease, or mutable + status data. """ attempt_timeout_seconds: PositiveInteger on_timeout: Literal["cancel", "abort", "cleanup-and-fail"] on_cancellation: Literal["abort", "cleanup-and-fail"] cleanup_plan_ref: NonEmptyString - required_guarantees: tuple[OperationGuarantee, ...] = Field( - default=(), - max_length=5, - exclude_if=lambda value: not value, - json_schema_extra={"uniqueItems": True}, - ) - - @model_validator(mode="after") - def _validate_required_guarantees(self) -> AdmittedExecutionControlModel: - if list(self.required_guarantees) != sorted(set(self.required_guarantees)): - raise ValueError("required_guarantees must be unique and sorted") - return self class AdmittedInstantiationProvenanceModel(ContractModel): diff --git a/implementations/python/packages/raes_contracts/contracts/execution_requirements.py b/implementations/python/packages/raes_contracts/contracts/execution_requirements.py deleted file mode 100644 index 53d10eb83..000000000 --- a/implementations/python/packages/raes_contracts/contracts/execution_requirements.py +++ /dev/null @@ -1,39 +0,0 @@ -"""Backend guarantees required by authored trial execution choices (#1361). - -RAE, not the author or the backend, derives these from choices the author has -already made. Absent choices require nothing: a single attempt that is not -cancelled on timeout places no supervision obligation on any backend. -""" - -from __future__ import annotations - -from .backend_operation import OperationGuarantee -from .trial_cleanup import ExecutionRetryPolicyModel - - -def required_operation_guarantees( - on_timeout: str, - retry_policy: ExecutionRetryPolicyModel, -) -> tuple[OperationGuarantee, ...]: - """Return the canonical guarantee set a backend must provide for these choices. - - - Cancelling on timeout needs backend cancellation. - - Another attempt must not overlap the previous one, so it needs evidence that - the previous attempt's effects ceased. - - A retry that forbids repeating after effects must also establish that no - effect occurred. - - Reset and compensation obligations stay with the cleanup-capability gate. - """ - - required: set[OperationGuarantee] = set() - if on_timeout == "cancel": - required.add("cancellation") - if retry_policy.max_attempts > 1: - required.add("cessation-evidence") - if retry_policy.after_effect_policy == "disallow": - required.add("effect-observation") - return tuple(sorted(required)) - - -__all__ = ["required_operation_guarantees"] diff --git a/implementations/python/packages/raes_contracts/contracts/manifests.py b/implementations/python/packages/raes_contracts/contracts/manifests.py index 70752cedb..e67f6d576 100644 --- a/implementations/python/packages/raes_contracts/contracts/manifests.py +++ b/implementations/python/packages/raes_contracts/contracts/manifests.py @@ -17,6 +17,7 @@ validate_processor_supported_contract_versions, validate_processor_supported_sdl_versions, ) +from ..operation_lifecycle import OperationKind from ..versions import PROCESSOR_MANIFEST_V2_SCHEMA_VERSION from ..vocabulary import ConceptFamilyId, ParticipantFeatureSupportLevel, ProcessorFeature from .base import _PROCESSOR_CONCEPT_BINDING_SCOPES, ContractModel, NonEmptyString @@ -30,14 +31,10 @@ from .experiment_bindings import ConfigurationTargetRegistryModel from .feature_support import ParticipantFeatureSupportModel from .observation_capture import ObservationCaptureOfferModel -from .operational_manifest_capabilities import ( - CleanupCapabilitiesModel, - OperationSupervisionCapabilitiesModel, - RecoveryObservationCapabilitiesModel, -) from .participant_execution import ParticipantExecutionBindingModel from .participant_resource_budgets import ParticipantResourceBudgetCapabilitiesModel from .time_manifest_capabilities import TimeCapabilitiesModel +from .trial_cleanup import CleanupActionKind from .validators import ( _validate_canonical_concept_bindings, _validate_controlled_vocabulary_terms, @@ -389,6 +386,50 @@ def _validate_observation_capability(self) -> ObservationCapabilitiesModel: return self +class CleanupCapabilitiesModel(ContractModel): + """Backend support for the portable SCE-007 cleanup contract family.""" + + name: NonEmptyString + supported_contract_versions: list[NonEmptyString] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) + supported_action_kinds: list[CleanupActionKind] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) + supported_verification_methods: list[NonEmptyString] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) + supports_reusable_state: bool = False + supports_residual_state_disclosure: bool = False + + @model_validator(mode="after") + def _validate_cleanup_capability(self) -> CleanupCapabilitiesModel: + _validate_unique_string_values("cleanup supported_contract_versions", self.supported_contract_versions) + _validate_unique_string_values("cleanup supported_action_kinds", self.supported_action_kinds) + _validate_unique_string_values("cleanup supported_verification_methods", self.supported_verification_methods) + required = {"trial-cleanup-plan-v1", "trial-cleanup-receipt-v1"} + if set(self.supported_contract_versions) != required: + raise ValueError( + "cleanup capabilities require contract versions trial-cleanup-plan-v1 and trial-cleanup-receipt-v1" + ) + validate_backend_supported_contract_versions(self.supported_contract_versions) + if self.supports_reusable_state and not self.supports_residual_state_disclosure: + raise ValueError("reusable-state support requires residual-state disclosure") + return self + + +class RecoveryObservationCapabilitiesModel(ContractModel): + """Operational crash-recovery observation support declaration.""" + + name: NonEmptyString + supported_operation_kinds: list[OperationKind] = Field( + min_length=1, + json_schema_extra={"uniqueItems": True}, + ) + + @model_validator(mode="after") + def _validate_supported_kinds(self) -> RecoveryObservationCapabilitiesModel: + if len(self.supported_operation_kinds) != len(set(self.supported_operation_kinds)): + raise ValueError("recovery supported_operation_kinds must be unique") + if OperationKind.INDETERMINATE_RESOLUTION in self.supported_operation_kinds: + raise ValueError("administrative resolution is not a recoverable backend effect") + return self + + class BackendCapabilitiesV2Model(ContractModel): provisioner: ProvisionerCapabilitiesModel orchestrator: OrchestratorCapabilitiesModel | None = None @@ -401,10 +442,6 @@ class BackendCapabilitiesV2Model(ContractModel): default=None, exclude_if=lambda value: value is None, ) - operation_supervision: OperationSupervisionCapabilitiesModel | None = Field( - default=None, - exclude_if=lambda value: value is None, - ) class ProcessorManifestV2Model(ContractModel): diff --git a/implementations/python/packages/raes_contracts/contracts/operational_manifest_capabilities.py b/implementations/python/packages/raes_contracts/contracts/operational_manifest_capabilities.py deleted file mode 100644 index 00115fddf..000000000 --- a/implementations/python/packages/raes_contracts/contracts/operational_manifest_capabilities.py +++ /dev/null @@ -1,80 +0,0 @@ -"""Backend manifest declarations for operational capabilities outside the realization domains.""" - -from __future__ import annotations - -from pydantic import Field, model_validator - -from ..manifest_authority import validate_backend_supported_contract_versions -from ..operation_lifecycle import OperationKind -from .backend_operation import OperationGuarantee -from .base import ContractModel, NonEmptyString -from .trial_cleanup import CleanupActionKind -from .validators import _validate_unique_string_values - - -class CleanupCapabilitiesModel(ContractModel): - """Backend support for the portable SCE-007 cleanup contract family.""" - - name: NonEmptyString - supported_contract_versions: list[NonEmptyString] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) - supported_action_kinds: list[CleanupActionKind] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) - supported_verification_methods: list[NonEmptyString] = Field(min_length=1, json_schema_extra={"uniqueItems": True}) - supports_reusable_state: bool = False - supports_residual_state_disclosure: bool = False - - @model_validator(mode="after") - def _validate_cleanup_capability(self) -> CleanupCapabilitiesModel: - _validate_unique_string_values("cleanup supported_contract_versions", self.supported_contract_versions) - _validate_unique_string_values("cleanup supported_action_kinds", self.supported_action_kinds) - _validate_unique_string_values("cleanup supported_verification_methods", self.supported_verification_methods) - required = {"trial-cleanup-plan-v1", "trial-cleanup-receipt-v1"} - if set(self.supported_contract_versions) != required: - raise ValueError( - "cleanup capabilities require contract versions trial-cleanup-plan-v1 and trial-cleanup-receipt-v1" - ) - validate_backend_supported_contract_versions(self.supported_contract_versions) - if self.supports_reusable_state and not self.supports_residual_state_disclosure: - raise ValueError("reusable-state support requires residual-state disclosure") - return self - - -class RecoveryObservationCapabilitiesModel(ContractModel): - """Operational crash-recovery observation support declaration.""" - - name: NonEmptyString - supported_operation_kinds: list[OperationKind] = Field( - min_length=1, - json_schema_extra={"uniqueItems": True}, - ) - - @model_validator(mode="after") - def _validate_supported_kinds(self) -> RecoveryObservationCapabilitiesModel: - if len(self.supported_operation_kinds) != len(set(self.supported_operation_kinds)): - raise ValueError("recovery supported_operation_kinds must be unique") - if OperationKind.INDETERMINATE_RESOLUTION in self.supported_operation_kinds: - raise ValueError("administrative resolution is not a recoverable backend effect") - return self - - -class OperationSupervisionCapabilitiesModel(ContractModel): - """Static declaration of the backend operation guarantees a backend provides. - - Planning compares authored execution choices with this declaration. It is - neither contextual willingness nor evidence: runtime admission still checks - the installed provider's capabilities and willingness before each dispatch. - """ - - name: NonEmptyString - guarantees: list[OperationGuarantee] = Field(min_length=1, max_length=5, json_schema_extra={"uniqueItems": True}) - - @model_validator(mode="after") - def _validate_guarantees(self) -> OperationSupervisionCapabilitiesModel: - _validate_unique_string_values("operation supervision guarantees", self.guarantees) - return self - - -__all__ = [ - "CleanupCapabilitiesModel", - "OperationSupervisionCapabilitiesModel", - "RecoveryObservationCapabilitiesModel", -] diff --git a/implementations/python/packages/raes_contracts/contracts/participant_manifests.py b/implementations/python/packages/raes_contracts/contracts/participant_manifests.py index d6de0b99d..3889294a3 100644 --- a/implementations/python/packages/raes_contracts/contracts/participant_manifests.py +++ b/implementations/python/packages/raes_contracts/contracts/participant_manifests.py @@ -20,7 +20,6 @@ ) from ..versions import ( BACKEND_MANIFEST_V2_SCHEMA_VERSION, - BACKEND_OPERATION_CONTRACT_IDS, PARTICIPANT_IMPLEMENTATION_MANIFEST_V1_SCHEMA_VERSION, PARTICIPANT_IMPLEMENTATION_PROVENANCE_V1_SCHEMA_VERSION, ) @@ -71,7 +70,6 @@ def _validate_unique_binding_scopes(self) -> BackendManifestV2Model: self._validate_realization_envelope_contract() self._validate_cleanup_contracts() self._validate_time_contracts() - self._validate_operation_supervision_contracts() self._validate_observation_capture_offers() self._validate_participant_policy_contracts() self._validate_concept_bindings() @@ -126,12 +124,6 @@ def _validate_cleanup_contracts(self) -> None: if declared_cleanup_contracts and self.capabilities.cleanup is None: raise ValueError("cleanup contract support requires capabilities.cleanup") - def _validate_operation_supervision_contracts(self) -> None: - if self.capabilities.operation_supervision is not None and not set(BACKEND_OPERATION_CONTRACT_IDS) <= set( - self.supported_contract_versions - ): - raise ValueError("operation supervision capabilities require the backend operation contract family") - def _validate_time_contracts(self) -> None: time_contracts = { "time-model-v1", @@ -221,27 +213,6 @@ def __get_pydantic_json_schema__( "properties": {"capabilities": {"required": ["time"]}}, }, }, - { - "if": { - "properties": { - "capabilities": { - "properties": {"operation_supervision": {"not": {"type": "null"}}}, - "required": ["operation_supervision"], - } - }, - "required": ["capabilities"], - }, - "then": { - "properties": { - "supported_contract_versions": { - "allOf": [ - {"contains": {"const": contract_id}} - for contract_id in BACKEND_OPERATION_CONTRACT_IDS - ] - } - } - }, - }, ] ) return json_schema diff --git a/implementations/python/packages/raes_processor/trial_compiler/compiler.py b/implementations/python/packages/raes_processor/trial_compiler/compiler.py index 755f4343b..0555414fe 100644 --- a/implementations/python/packages/raes_processor/trial_compiler/compiler.py +++ b/implementations/python/packages/raes_processor/trial_compiler/compiler.py @@ -8,7 +8,7 @@ ExpandedScenarioBindingTargetResolver, validate_experiment_selection_against_family, ) -from raes_backend_protocols.backend_manifest import BackendManifest +from raes_backend_protocols.capabilities import ObservationCapabilities from raes_backend_protocols.manifest import backend_manifest_from_v2_model_with_envelope from raes_contracts.canonical import canonical_json_bytes from raes_contracts.contracts import ( @@ -27,7 +27,6 @@ ParticipantImplementationManifestModel, TrialCleanupPlanModel, TrialCoordinateModel, - required_operation_guarantees, seal_admitted_trial_entry, seal_admitted_trial_plan, ) @@ -40,6 +39,8 @@ ) from ..capture_admission import ( + CaptureDemand, + capture_admission_diagnostics, compile_scoped_evidence_requirement_demands, ) from . import models as compiler_models @@ -47,7 +48,6 @@ validate_selected_apparatus, validate_selected_participant_manifests, ) -from .entry_admission import CaptureAdmissionFailure, require_capture_admission, require_execution_authority from .inputs import ( canonical_input_refs, canonical_realization_binding, @@ -70,6 +70,12 @@ _validate_selected_scenario = validate_selected_scenario +class _CaptureAdmissionFailure(Exception): + def __init__(self, diagnostics: tuple[Diagnostic, ...]) -> None: + super().__init__("required capture is not supported by the admitted apparatus") + self.diagnostics = diagnostics + + def _fail(code: str, address: str, message: str) -> CompilationFailure: return CompilationFailure(code, address, message) @@ -194,13 +200,24 @@ def _selection_records(row: CoordinateSelections) -> list[AdmittedSelectionRecor ] +def _require_capture_admission( + demands: tuple[CaptureDemand, ...], + observations: tuple[ObservationCapabilities | None, ...], +) -> None: + diagnostics = [ + diagnostic for observation in observations for diagnostic in capture_admission_diagnostics(demands, observation) + ] + if diagnostics: + raise _CaptureAdmissionFailure(tuple(diagnostics)) + + def _compile_entry( request: TrialCompilationRequest, plan_id: str, row: CoordinateSelections, coordinate: TrialCoordinateModel, descriptors: Mapping[str, ExperimentBindingDescriptorModel], - backends: tuple[BackendManifest, ...], + observations: tuple[ObservationCapabilities | None, ...], ) -> tuple[str, AdmittedTrialEntryModel, str, TrialCleanupPlanModel]: realization = request.realization_assignments.get(realization_assignment_key(coordinate)) selected = _validate_selected_scenario(request, row, coordinate) @@ -210,14 +227,14 @@ def _compile_entry( *request.task.evidence_requirement_relations, *request.experiment.run_plan.evidence_requirement_relations, ) - require_capture_admission( + _require_capture_admission( compile_scoped_evidence_requirement_demands( selected, tuple(request.capture_specs.values()), relations, relation_scenario=request.family, ), - tuple(backend.observation for backend in backends), + observations, ) identity_projection = { "plan_id": plan_id, @@ -241,8 +258,6 @@ def _compile_entry( plan_entry_id=entry_id, run_id=run_id, ) - required_guarantees = required_operation_guarantees(request.execution_authority.on_timeout, cleanup.retry_policy) - require_execution_authority(backends, cleanup, required_guarantees) bindings = _entry_bindings(request, row, coordinate, descriptors) if len(row.draws) > request.limits.max_draws_per_entry: raise _fail( @@ -263,7 +278,6 @@ def _compile_entry( on_timeout=request.execution_authority.on_timeout, on_cancellation=request.execution_authority.on_cancellation, cleanup_plan_ref=cleanup_id, - required_guarantees=required_guarantees, ), instantiation_provenance=AdmittedInstantiationProvenanceModel( plan_id=plan_id, @@ -302,7 +316,7 @@ def _compile_coordinate( row, coordinate, descriptors, - authority.backends_by_profile[profile_id], + authority.observations_by_profile[profile_id], ) @@ -324,7 +338,7 @@ def _compile_entries( row = rows[coordinate_index] try: entry_id, entry, cleanup_id, cleanup = _compile_coordinate(request, plan_id, coordinate, row, authority) - except CaptureAdmissionFailure as failure: + except _CaptureAdmissionFailure as failure: capture_failures.update( { (diagnostic.address, diagnostic.code, diagnostic.message): diagnostic @@ -349,7 +363,7 @@ def _compile_entries( if canonical_failure is None or _failure_key(candidate_failure) < _failure_key(canonical_failure): canonical_failure = candidate_failure if capture_failures: - raise CaptureAdmissionFailure(tuple(capture_failures[key] for key in sorted(capture_failures))) + raise _CaptureAdmissionFailure(tuple(capture_failures[key] for key in sorted(capture_failures))) if canonical_failure is not None: raise canonical_failure return entries, cleanup_plans, used_control_ids @@ -375,12 +389,12 @@ def _compile( authority = validate_mixed_authority(request) apparatus_manifests_by_profile = authority.apparatus_manifests_by_root participant_manifests = authority.participant_manifests - backends_by_profile = { + observations_by_profile = { profile_id: tuple( backend_manifest_from_v2_model_with_envelope( manifest, request.mixed_realization_envelopes[manifest.realization_envelope.envelope_id], - ) + ).observation for manifest in manifests ) for profile_id, manifests in authority.backend_manifests_by_root.items() @@ -389,9 +403,9 @@ def _compile( apparatus_manifests = validate_selected_apparatus(request) apparatus_manifests_by_profile = {"": apparatus_manifests} participant_manifests = validate_selected_participant_manifests(request) - backends_by_profile = { + observations_by_profile = { "": tuple( - backend_manifest_from_v2_model_with_envelope(backend, request.realization_envelope) + backend_manifest_from_v2_model_with_envelope(backend, request.realization_envelope).observation for backend in sorted( ( manifest @@ -423,7 +437,7 @@ def _compile( traversal, compiler_models._EntryCompilationAuthority( descriptors=descriptors, - backends_by_profile=backends_by_profile, + observations_by_profile=observations_by_profile, apparatus_manifests_by_profile=apparatus_manifests_by_profile, participant_manifests=participant_manifests, ), @@ -463,7 +477,7 @@ def compile_admitted_trial_plan( try: plan = _compile(request, coordinate_partitions) - except CaptureAdmissionFailure as failure: + except _CaptureAdmissionFailure as failure: result = TrialCompilationResult(plan=None, diagnostics=failure.diagnostics) except CompilationFailure as failure: result = TrialCompilationResult(plan=None, diagnostics=(_diagnostic(failure),)) diff --git a/implementations/python/packages/raes_processor/trial_compiler/entry_admission.py b/implementations/python/packages/raes_processor/trial_compiler/entry_admission.py deleted file mode 100644 index e8afc91bd..000000000 --- a/implementations/python/packages/raes_processor/trial_compiler/entry_admission.py +++ /dev/null @@ -1,66 +0,0 @@ -"""Per-entry apparatus admission gates for trial compilation.""" - -from __future__ import annotations - -from raes_backend_protocols.backend_manifest import BackendManifest -from raes_backend_protocols.capabilities import ObservationCapabilities -from raes_backend_protocols.cleanup_admission import require_execution_authority_capability -from raes_contracts.contracts import TrialCleanupPlanModel -from raes_contracts.diagnostics import Diagnostic - -from ..capture_admission import CaptureDemand, capture_admission_diagnostics -from .models import CompilationFailure - - -class CaptureAdmissionFailure(Exception): - def __init__(self, diagnostics: tuple[Diagnostic, ...]) -> None: - super().__init__("required capture is not supported by the admitted apparatus") - self.diagnostics = diagnostics - - -def _fail(code: str, address: str, message: str) -> CompilationFailure: - return CompilationFailure(code, address, message) - - -def require_capture_admission( - demands: tuple[CaptureDemand, ...], - observations: tuple[ObservationCapabilities | None, ...], -) -> None: - diagnostics = [ - diagnostic for observation in observations for diagnostic in capture_admission_diagnostics(demands, observation) - ] - if diagnostics: - raise CaptureAdmissionFailure(tuple(diagnostics)) - - -def require_execution_authority( - backends: tuple[BackendManifest, ...], - cleanup: TrialCleanupPlanModel, - required_guarantees: tuple[str, ...], -) -> None: - """Every selected backend must honour the authored timeout, cleanup and retry choices. - - An entry that selects no backend has nothing that could honour them, so it is - refused rather than admitted vacuously. - """ - - if not backends: - raise _fail( - "execution-authority-unsupported", - "/execution_authority", - "a selected backend cannot honour the admitted execution authority", - ) - for backend in backends: - try: - require_execution_authority_capability( - backend, cleanup_plan=cleanup, required_guarantees=required_guarantees - ) - except ValueError as exc: - raise _fail( - "execution-authority-unsupported", - "/execution_authority", - "a selected backend cannot honour the admitted execution authority", - ) from exc - - -__all__ = ["CaptureAdmissionFailure", "require_capture_admission", "require_execution_authority"] diff --git a/implementations/python/packages/raes_processor/trial_compiler/models.py b/implementations/python/packages/raes_processor/trial_compiler/models.py index 30f72a274..28e2e8281 100644 --- a/implementations/python/packages/raes_processor/trial_compiler/models.py +++ b/implementations/python/packages/raes_processor/trial_compiler/models.py @@ -7,7 +7,7 @@ from raes.canonical import canonical_sdl_digest from raes.scenario import ExpandedScenario -from raes_backend_protocols.backend_manifest import BackendManifest +from raes_backend_protocols.capabilities import ObservationCapabilities from raes_contracts.canonical import canonical_json_digest from raes_contracts.contracts import ( AdmittedApparatusBindingModel, @@ -41,7 +41,7 @@ class _EntryCompilationAuthority: """Per-entry authorities selected once for a compiler invocation.""" descriptors: Mapping[str, ExperimentBindingDescriptorModel] | None - backends_by_profile: Mapping[str, tuple[BackendManifest, ...]] + observations_by_profile: Mapping[str, tuple[ObservationCapabilities | None, ...]] apparatus_manifests_by_profile: Mapping[str, Mapping[ApparatusManifestKey, ApparatusManifest]] participant_manifests: Mapping[ParticipantManifestKey, ParticipantImplementationManifestModel] diff --git a/implementations/python/tests/test_formal_semantic_validation.py b/implementations/python/tests/test_formal_semantic_validation.py index 9866d6dad..812bf74be 100644 --- a/implementations/python/tests/test_formal_semantic_validation.py +++ b/implementations/python/tests/test_formal_semantic_validation.py @@ -134,7 +134,6 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: "53.0.0", "54.0.0", "55.0.0", - "56.0.0", ] assert all(validate_release_bundle(REPO_ROOT, release) == [] for release in releases) @@ -143,10 +142,10 @@ def test_atomic_release_index_validates_every_historical_bundle() -> None: def test_current_retest_bundle_is_coherent_and_clean() -> None: release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, REPO_ROOT) - assert release.manifest["revision"] == "56.0.0" + assert release.manifest["revision"] == "55.0.0" assert protocol["revision"] == "2.0.0" assert corpus["revision"] == "4.0.0" - assert snapshot["baseline"]["release_revision"] == "55.0.0" + assert snapshot["baseline"]["release_revision"] == "54.0.0" assert snapshot["deviations"] == [] assert validate_retest_bundle(REPO_ROOT, release, protocol, corpus, snapshot, analysis) == [] diff --git a/implementations/python/tests/test_issue_1361_execution_requirements.py b/implementations/python/tests/test_issue_1361_execution_requirements.py deleted file mode 100644 index 5a6a5ca2a..000000000 --- a/implementations/python/tests/test_issue_1361_execution_requirements.py +++ /dev/null @@ -1,303 +0,0 @@ -"""Authored trial execution choices reach backend admission (issue #1361).""" - -from __future__ import annotations - -from dataclasses import replace - -import pytest -from paths import REPO_ROOT -from pydantic import ValidationError -from raes import canonical_instantiated_sdl_digest, select_scenario_family -from raes_backend_protocols.capabilities import OperationSupervisionCapabilities -from raes_backend_protocols.cleanup_admission import require_execution_authority_capability -from raes_backend_protocols.manifest import backend_manifest_from_v2_model, backend_manifest_v2_model -from raes_contracts.canonical import canonical_json_digest -from raes_contracts.contracts import ( - AdmittedExecutionControlModel, - AdmittedMixedCompositionBindingModel, - BackendManifestV2Model, - ExecutionRetryPolicyModel, - ExperimentManifestReferenceModel, - ExperimentProcessorReferenceModel, - ExperimentReferenceModel, - OperationSupervisionCapabilitiesModel, - ProcessorManifestV2Model, - TrialExecutionAuthorityModel, - required_operation_guarantees, - seal_admitted_trial_entry, - seal_admitted_trial_plan, - seal_mixed_composition_profile, -) -from raes_contracts.versions import BACKEND_OPERATION_CONTRACT_IDS -from raes_processor.trial_compiler import TrialCompilationRequest, compile_admitted_trial_plan -from raes_processor.trial_compiler.profiles import realization_assignment_key -from test_issue_1014_mixed_composition_contracts import _alternative_profile -from test_issue_1015_mixed_staged_trial_admission import _mixed_request, _profile_context -from test_sce_002_trial_compiler import _request - -_BACKEND_KEY = ("backend", "backend-a", "1", "backend-manifest/v2") -_PROCESSOR_MANIFEST_FIXTURE = ( - REPO_ROOT / "contracts" / "fixtures" / "processor-manifest" / "processor-manifest-v2" / "valid" / "reference.json" -) - - -def _authority( - request: TrialCompilationRequest, - *, - on_timeout: str = "cleanup-and-fail", - max_attempts: int = 1, - after_effect_policy: str = "disallow", -) -> TrialExecutionAuthorityModel: - authority = request.execution_authority - cleanup = authority.cleanup.model_copy( - update={ - "retry_policy": ExecutionRetryPolicyModel( - max_attempts=max_attempts, after_effect_policy=after_effect_policy - ) - } - ) - return authority.model_copy(update={"on_timeout": on_timeout, "cleanup": cleanup}) - - -def _with_guarantees(request: TrialCompilationRequest, guarantees: list[str]) -> TrialCompilationRequest: - payload = request.apparatus_manifests[_BACKEND_KEY].model_dump(mode="json") - payload["supported_contract_versions"] = sorted( - {*payload["supported_contract_versions"], *BACKEND_OPERATION_CONTRACT_IDS} - ) - payload["capabilities"]["operation_supervision"] = {"name": "fixture-supervision", "guarantees": guarantees} - manifest = BackendManifestV2Model.model_validate(payload) - manifest_ref = request.apparatus.manifest_refs[0].model_copy( - update={"ref_digest": canonical_json_digest(manifest.model_dump(mode="json"))} - ) - apparatus = request.apparatus.model_copy(update={"manifest_refs": [manifest_ref]}) - return replace(request, apparatus=apparatus, apparatus_manifests={_BACKEND_KEY: manifest}) - - -@pytest.mark.parametrize( - ("on_timeout", "max_attempts", "after_effect_policy", "expected"), - [ - ("cleanup-and-fail", 1, "disallow", ()), - ("abort", 1, "idempotent", ()), - ("cancel", 1, "disallow", ("cancellation",)), - ("abort", 2, "disallow", ("cessation-evidence", "effect-observation")), - ("abort", 3, "idempotent", ("cessation-evidence",)), - ("cancel", 2, "disallow", ("cancellation", "cessation-evidence", "effect-observation")), - ], -) -def test_guarantees_are_derived_from_authored_choices_only( - on_timeout: str, max_attempts: int, after_effect_policy: str, expected: tuple[str, ...] -) -> None: - policy = ExecutionRetryPolicyModel(max_attempts=max_attempts, after_effect_policy=after_effect_policy) - - assert required_operation_guarantees(on_timeout, policy) == expected - - -def test_default_choices_compile_without_guarantees_or_serialized_field() -> None: - result = compile_admitted_trial_plan(_request()) - - assert result.plan is not None - for entry in result.plan.entries.values(): - assert entry.execution_controls.required_guarantees == () - assert "required_guarantees" not in entry.execution_controls.model_dump(mode="json") - - -def test_backend_without_declared_guarantee_is_rejected_before_any_plan() -> None: - request = _request() - request = replace(request, execution_authority=_authority(request, on_timeout="cancel")) - - result = compile_admitted_trial_plan(request) - - assert result.plan is None - assert [diagnostic.code for diagnostic in result.diagnostics] == ["trial-compiler.execution-authority-unsupported"] - assert result.diagnostics[0].address == "/execution_authority" - - -def test_backend_missing_one_of_several_guarantees_is_rejected() -> None: - request = _with_guarantees(_request(), ["cessation-evidence"]) - request = replace(request, execution_authority=_authority(request, max_attempts=2)) - - result = compile_admitted_trial_plan(request) - - assert result.plan is None - assert result.diagnostics[0].code == "trial-compiler.execution-authority-unsupported" - - -def test_supporting_backend_admits_and_the_plan_carries_the_compiled_requirement() -> None: - request = _with_guarantees(_request(), ["cancellation", "cessation-evidence", "effect-observation"]) - request = replace(request, execution_authority=_authority(request, on_timeout="cancel", max_attempts=2)) - - result = compile_admitted_trial_plan(request) - - assert result.plan is not None - for entry in result.plan.entries.values(): - assert entry.execution_controls.required_guarantees == ( - "cancellation", - "cessation-evidence", - "effect-observation", - ) - - -def test_every_mixed_composition_backend_must_honour_the_choices() -> None: - mixed = _mixed_request() - rejected = replace(mixed, execution_authority=_authority(mixed, on_timeout="cancel")) - - result = compile_admitted_trial_plan(rejected) - - assert result.plan is None - assert result.diagnostics[0].code == "trial-compiler.execution-authority-unsupported" - - supported = _mixed_request(base_request=_with_guarantees(_request(run_count=2), ["cancellation"])) - admitted = compile_admitted_trial_plan( - replace(supported, execution_authority=_authority(supported, on_timeout="cancel")) - ) - - assert admitted.plan is not None - assert {entry.execution_controls.required_guarantees for entry in admitted.plan.entries.values()} == { - ("cancellation",) - } - - -def _processor_only_mixed_request() -> TrialCompilationRequest: - """A mixed realization whose every component is a processor, so no backend is selected.""" - - request = _request() - request = request.with_experiment(request.experiment.model_copy(update={"apparatus_intent": None})) - pure = compile_admitted_trial_plan(request).plan - assert pure is not None - processor = ProcessorManifestV2Model.model_validate_json(_PROCESSOR_MANIFEST_FIXTURE.read_text(encoding="utf-8")) - processor_ref = ExperimentManifestReferenceModel( - ref_kind="manifest", - ref_id=processor.identity.name, - ref_version=processor.schema_version, - ref_digest=canonical_json_digest(processor.model_dump(mode="json")), - subject_ref=ExperimentProcessorReferenceModel( - ref_kind="processor", ref_id=processor.identity.name, ref_version=processor.identity.version - ), - ) - assignments, profiles, contexts, profile_refs = {}, {}, {}, [] - for entry in pure.entries.values(): - outcomes = {selection.variation_point_id: selection.outcome for selection in entry.selections} - fields = _alternative_profile().model_dump(mode="python", exclude={"profile_digest"}) - fields["profile_id"] = f"profile:{entry.coordinate.condition_id}:{entry.coordinate.replicate_id}" - for component_id, component in fields["components"].items(): - component["apparatus_identity_ref"] = f"apparatus:{component_id}" - component["manifest_ref"] = processor_ref.model_dump(mode="python") - component["realization_envelope"] = request.realization_envelope.identity.model_dump(mode="python") - fields["scenario_snapshot_ref"] = ExperimentReferenceModel( - ref_kind="scenario-snapshot", - ref_id=f"snapshot:compiler-family:{entry.coordinate.replicate_id}", - ref_version="instantiated-scenario-snapshot/v1", - ref_digest=canonical_instantiated_sdl_digest(select_scenario_family(request.family, outcomes)).value, - ) - profile = seal_mixed_composition_profile(**fields) - profile_ref = ExperimentReferenceModel( - ref_kind="profile", - ref_id=profile.profile_id, - ref_version=profile.profile_revision, - ref_digest=profile.profile_digest, - ) - assignments[realization_assignment_key(entry.coordinate)] = AdmittedMixedCompositionBindingModel( - profile_ref=profile_ref - ) - profiles[profile.profile_id] = profile - contexts[profile.profile_id] = _profile_context(profile) - profile_refs.append(profile_ref) - processor_key = ("processor", processor.identity.name, processor.identity.version, processor.schema_version) - return replace( - request, - input_refs=request.input_refs.model_copy(update={"mixed_composition_profile_refs": profile_refs}), - realization_assignments=assignments, - mixed_profiles=profiles, - mixed_profile_contexts=contexts, - mixed_realization_envelopes={request.realization_envelope.identity.envelope_id: request.realization_envelope}, - apparatus_manifests={**request.apparatus_manifests, processor_key: processor}, - ) - - -def test_realization_without_any_selected_backend_is_refused() -> None: - result = compile_admitted_trial_plan(_processor_only_mixed_request()) - - assert result.plan is None - assert [diagnostic.code for diagnostic in result.diagnostics] == ["trial-compiler.execution-authority-unsupported"] - - -def test_sealed_plan_rejects_guarantees_that_contradict_its_choices() -> None: - plan = compile_admitted_trial_plan(_request()).plan - assert plan is not None - entry = next(iter(plan.entries.values())) - entry_fields = {name: getattr(entry, name) for name in type(entry).model_fields if name != "entry_digest"} - entry_fields["execution_controls"] = entry.execution_controls.model_copy( - update={"required_guarantees": ("cancellation",)} - ) - resealed = seal_admitted_trial_entry(**entry_fields) - plan_fields = {name: getattr(plan, name) for name in type(plan).model_fields if name != "plan_digest"} - plan_fields["entries"] = {**plan.entries, resealed.plan_entry_id: resealed} - - with pytest.raises(ValidationError, match="required_guarantees must equal"): - seal_admitted_trial_plan(**plan_fields) - - -def test_required_guarantees_are_canonical() -> None: - plan = compile_admitted_trial_plan(_request()).plan - assert plan is not None - controls = next(iter(plan.entries.values())).execution_controls - unsorted = {**controls.model_dump(mode="json"), "required_guarantees": ["effect-observation", "cancellation"]} - - with pytest.raises(ValidationError, match="unique and sorted"): - AdmittedExecutionControlModel.model_validate(unsorted) - - -def test_manifest_declaration_requires_the_operation_contract_family() -> None: - payload = _request().apparatus_manifests[_BACKEND_KEY].model_dump(mode="json") - payload["capabilities"]["operation_supervision"] = {"name": "fixture", "guarantees": ["cancellation"]} - - with pytest.raises(ValidationError, match="backend operation contract family"): - BackendManifestV2Model.model_validate(payload) - - -@pytest.mark.parametrize("guarantees", [[], ["cancellation", "cancellation"], ["rollback"]]) -def test_manifest_declaration_is_closed_and_non_empty(guarantees: list[str]) -> None: - with pytest.raises(ValidationError): - OperationSupervisionCapabilitiesModel(name="fixture", guarantees=guarantees) - - -def test_manifest_declaration_round_trips_through_the_internal_manifest() -> None: - request = _with_guarantees(_request(), ["effect-observation", "cancellation"]) - model = request.apparatus_manifests[_BACKEND_KEY].model_copy(update={"realization_envelope": None}) - model = BackendManifestV2Model.model_validate( - { - **model.model_dump(mode="json", exclude={"realization_envelope"}), - "supported_contract_versions": [ - contract for contract in model.supported_contract_versions if contract != "realization-envelope-v1" - ], - } - ) - - manifest = backend_manifest_from_v2_model(model) - - assert manifest.operation_supervision == OperationSupervisionCapabilities( - name="fixture-supervision", guarantees=frozenset({"cancellation", "effect-observation"}) - ) - assert backend_manifest_v2_model(manifest).capabilities.operation_supervision == ( - model.capabilities.operation_supervision.model_copy( - update={"guarantees": ["cancellation", "effect-observation"]} - ) - ) - - -def test_admission_also_enforces_the_cleanup_plan_capability() -> None: - request = _request() - plan = compile_admitted_trial_plan(request).plan - assert plan is not None - cleanup = next(iter(plan.cleanup_plans.values())) - payload = request.apparatus_manifests[_BACKEND_KEY].model_dump(mode="json", exclude={"realization_envelope"}) - payload["supported_contract_versions"] = [ - contract - for contract in payload["supported_contract_versions"] - if contract not in {"trial-cleanup-plan-v1", "trial-cleanup-receipt-v1", "realization-envelope-v1"} - ] - payload["capabilities"]["cleanup"] = None - manifest = backend_manifest_from_v2_model(BackendManifestV2Model.model_validate(payload)) - - with pytest.raises(ValueError, match="cleanup capabilities"): - require_execution_authority_capability(manifest, cleanup_plan=cleanup, required_guarantees=()) diff --git a/implementations/python/tests/test_issue_989_versioned_evidence.py b/implementations/python/tests/test_issue_989_versioned_evidence.py index 42f4f2753..707f08176 100644 --- a/implementations/python/tests/test_issue_989_versioned_evidence.py +++ b/implementations/python/tests/test_issue_989_versioned_evidence.py @@ -230,7 +230,7 @@ def test_latest_current_release_is_versioned_and_strict(monkeypatch): from tools.formal_semantic_validation._releases import validate_retest_bundle release, protocol, corpus, snapshot, analysis = copy_bundle(load_retest_bundle, ROOT) - assert release.manifest["revision"] == "56.0.0" + assert release.manifest["revision"] == "55.0.0" original = _retest.replay_case def changed_result(root, case): @@ -283,7 +283,7 @@ def test_specification_current_capture_does_not_accept_old_artifact_digest(artif from tools.check_specification_coverage import load_bundle, validate_bundle manifest, protocol, snapshot, analysis = copy_bundle(load_bundle, ROOT) - assert manifest["revision"] == "55.0.0" + assert manifest["revision"] == "54.0.0" snapshot = deepcopy(snapshot) artifact = next(a for a in snapshot["artifacts"] if a["artifact_id"] == artifact_id) artifact["sha256"] = old_digest @@ -507,7 +507,6 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "53.0.0", "54.0.0", "55.0.0", - "56.0.0", ] if family == "formal" else [ @@ -566,7 +565,6 @@ def test_no_capture_can_be_silently_dropped(monkeypatch, family, removed): "52.0.0", "53.0.0", "54.0.0", - "55.0.0", ] ) revisions.pop(-1 if removed == "current" else 0) diff --git a/implementations/python/tests/test_specification_coverage.py b/implementations/python/tests/test_specification_coverage.py index 85fb6425e..cb3d4c9fc 100644 --- a/implementations/python/tests/test_specification_coverage.py +++ b/implementations/python/tests/test_specification_coverage.py @@ -53,7 +53,7 @@ def test_immutable_bundle_index_preserves_concurrent_captures() -> None: bundles = copy_bundle(load_bundles, REPO_ROOT) assert {manifest["revision"] for manifest, *_rest in bundles} >= {"1.0.0", "1.1.0", "19.0.0"} manifest, *_rest = copy_bundle(load_bundle, REPO_ROOT) - assert manifest["revision"] == "55.0.0" + assert manifest["revision"] == "54.0.0" def test_historical_failures_name_the_revision_specific_documents() -> None: diff --git a/specs/formal/scenario-variation-trial-realization/cleanup-contracts.md b/specs/formal/scenario-variation-trial-realization/cleanup-contracts.md index f3b326036..89de6c517 100644 --- a/specs/formal/scenario-variation-trial-realization/cleanup-contracts.md +++ b/specs/formal/scenario-variation-trial-realization/cleanup-contracts.md @@ -132,38 +132,6 @@ rejects a plan when the backend omits cleanup capability, lacks a required action or verification method, cannot support declared reusable state, or cannot disclose residual state for required cleanup. -## Execution Choices At Backend Admission - -The authored timeout and retry choices also require backend operation -guarantees (issue #1361). RAE derives them with -`required_operation_guarantees()`; neither the author nor the backend supplies -them: - -| Authored choice | Required operation guarantee | -| --- | --- | -| `on_timeout: cancel` | `cancellation` | -| `retry_policy.max_attempts > 1` | `cessation-evidence`, because attempts are sequential and the previous attempt must be proven stopped | -| the same, with `after_effect_policy: disallow` | also `effect-observation`, because absence of effects must be established | - -A single attempt that is not cancelled on timeout requires nothing. - -The admitted trial entry records the derived set in -`execution_controls.required_guarantees`, which is omitted when empty. The -plan rejects a set that differs from the one derived from the entry's controls -and cleanup retry policy. - -Trial compilation calls `require_execution_authority_capability()` for every -backend selected for an entry, including every mixed-composition backend. The -helper applies `require_cleanup_plan_capability()` and requires every derived -guarantee in the manifest's `capabilities.operation_supervision` declaration. -An entry whose realization selects no backend, such as a processor-only mixed -composition, has nothing that could honour these choices and is refused. -Failure yields the input-free diagnostic -`trial-compiler.execution-authority-unsupported`, and no plan is produced. An -unsupported authored choice is refused, never downgraded to best effort. At -dispatch, the runtime still rechecks the installed provider and its contextual -willingness with the backend operation contracts. - ## Scheduler Isolation `SchedulerIsolationProofModel.requested_parallelism` defaults to one. Serial diff --git a/tools/check_specification_coverage.py b/tools/check_specification_coverage.py index f9370fe6a..39cdc899c 100644 --- a/tools/check_specification_coverage.py +++ b/tools/check_specification_coverage.py @@ -157,12 +157,12 @@ def _load_bundle_index(repo_root: Path) -> list[tuple[str, dict[str, object]]]: "51.0.0", "52.0.0", "53.0.0", - } | {"54.0.0", "55.0.0"} + } | {"54.0.0"} if ( - dict(records)[current_path].get("revision") != "55.0.0" + dict(records)[current_path].get("revision") != "54.0.0" or {record.get("revision") for _, record in records} != supported_revisions ): - raise ValueError("coverage evidence requires the explicit current 55.0.0 release and supported history") + raise ValueError("coverage evidence requires the explicit current 54.0.0 release and supported history") return records diff --git a/tools/formal_semantic_validation/_baseline.py b/tools/formal_semantic_validation/_baseline.py index 540c7751b..a7b4b7840 100644 --- a/tools/formal_semantic_validation/_baseline.py +++ b/tools/formal_semantic_validation/_baseline.py @@ -190,7 +190,6 @@ def _selected_baseline_manifest( "52.0.0", "53.0.0", "54.0.0", - "55.0.0", }: expected_corpus_path = "docs/research/formal-semantic-validation/corpus/manifest-v4.json" elif baseline_revision in _V3_CORPUS_REVISIONS: diff --git a/tools/formal_semantic_validation/_loading.py b/tools/formal_semantic_validation/_loading.py index c56b5f44b..c7b8ba558 100644 --- a/tools/formal_semantic_validation/_loading.py +++ b/tools/formal_semantic_validation/_loading.py @@ -75,6 +75,6 @@ def load_retest_bundle( if not releases: raise ValueError("the formal semantic-validation index selects no v2 retest release") release = max(releases, key=lambda item: revision_key(item.manifest.get("revision"))) - if release.manifest.get("revision") != "56.0.0" or release.protocol.get("revision") != "2.0.0": - raise ValueError("the current formal evidence release must be the explicit 56.0.0 retest") + if release.manifest.get("revision") != "55.0.0" or release.protocol.get("revision") != "2.0.0": + raise ValueError("the current formal evidence release must be the explicit 55.0.0 retest") return release, release.protocol, release.corpus, release.snapshot, release.analysis diff --git a/tools/formal_semantic_validation/_release_revisions.py b/tools/formal_semantic_validation/_release_revisions.py index b1a838b0d..b818c373b 100644 --- a/tools/formal_semantic_validation/_release_revisions.py +++ b/tools/formal_semantic_validation/_release_revisions.py @@ -53,7 +53,7 @@ "51.0.0", "52.0.0", } -) | {"53.0.0", "54.0.0", "55.0.0"} +) | {"53.0.0", "54.0.0"} -_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"56.0.0"} +_SUPPORTED_RETEST_REVISIONS = _HISTORICAL_RETEST_REVISIONS | {"55.0.0"} _SOURCE_BOUND_RETEST_REVISIONS = _SUPPORTED_RETEST_REVISIONS - {"3.0.0"} diff --git a/tools/formal_semantic_validation/_releases.py b/tools/formal_semantic_validation/_releases.py index e3e6be083..aa4a05987 100644 --- a/tools/formal_semantic_validation/_releases.py +++ b/tools/formal_semantic_validation/_releases.py @@ -159,7 +159,7 @@ def validate_release_bundle(repo_root: Path, release: EvidenceRelease) -> list[P release.corpus, release.snapshot, release.analysis, - replay_current=manifest.get("revision") == "56.0.0", + replay_current=manifest.get("revision") == "55.0.0", ) ) else: @@ -272,7 +272,6 @@ def _expected_corpus_revision(release_revision: object) -> str: "53.0.0", "54.0.0", "55.0.0", - "56.0.0", }: expected_corpus_revision = "4.0.0" return expected_corpus_revision @@ -428,7 +427,6 @@ def _current_retest_source_failures( "53.0.0": "52.0.0", "54.0.0": "53.0.0", "55.0.0": "54.0.0", - "56.0.0": "55.0.0", }[release_revision] if not isinstance(baseline, Mapping) or baseline.get("release_revision") != expected_baseline: failures.append( diff --git a/tools/formal_semantic_validation/_retest.py b/tools/formal_semantic_validation/_retest.py index 6e6c95161..cbe06846f 100644 --- a/tools/formal_semantic_validation/_retest.py +++ b/tools/formal_semantic_validation/_retest.py @@ -37,7 +37,7 @@ ) from tools.policy.common import PolicyFailure -_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 57)) +_SOURCE_STATE_REVISIONS = frozenset(f"{revision}.0.0" for revision in range(4, 56)) @dataclasses.dataclass(frozen=True)