Close the exact-source to installed-artifact evidence chain - #227
Conversation
…-replay-20260912 # Conflicts: # README.md
…-final-20260912 # Conflicts: # README.md
# Conflicts: # docs/work-graphs/repository-plan-report.json
# Conflicts: # docs/work-graphs/repository-plan-report.json # uv.lock
# Conflicts: # docs/work-graphs/repository-plan-report.json
…/clean-install-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json
…/clean-install-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json
…/clean-install-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json # uv.lock
…/clean-install-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json
…/clean-install-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json
…-final-20260912 # Conflicts: # MANIFEST.in # docs/work-graphs/repository-plan-report.json # tools/run_skill_lib_boundaries.py # tools/verify_distributions.py
…-final-20260912 # Conflicts: # docs/work-graphs/repository-plan-report.json
# Conflicts: # docs/work-graphs/repository-plan-report.json
# Conflicts: # docs/work-graphs/repository-plan-report.json
# Conflicts: # docs/work-graphs/repository-plan-report.json
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
@codex review Please review exact head The current archives pass build, Twine and exact input validation. All five selected checks pass from the actual source archive with unchanged source and no snapshot errors. The final matrix is running. Each retained bundle will be checked independently against this exact Git tree, dependency export, archive bytes, all installed package files, actual 156-case XML outcomes, and the source receipt/helper identities before merge. Actions status alone does not establish acceptance, freshness, publication, or geometry standing. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 5048ca51da
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Please review exact head |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea3ec4e955
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: ea3ec4e955
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
|
@codex review Please review exact head |
|
Codex Review: Didn't find any major issues. You're on a roll. Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
UCNS now carries a complete source-to-installed-artifact evidence chain across Python 3.10, 3.11, and 3.12. Each job checks exact source, builds wheel/sdist artifacts, runs all 159 tests against each clean installation with locked dependencies, and retains the artifacts, source identity, XML outcomes, and replay receipts for independent acceptance.
The replay checks the complete extracted source before and after each full suite, keeps pytest caches outside evidence inputs, and rejects persistent source changes. Installed inventories cover package payloads, distribution metadata, validated uv installer/build metadata, and RECORD entries; all immutable bytes must match the candidate wheel. The exact-input receipt separately executes the archived source with unchanged-input and non-transfer checks. Archive checksum paths remain usable after downloading the CI bundle, and receipt assembly uses the selected verification interpreter.
Three executable CHECKS cover source mutation and real clean wheel/sdist installations with altered, missing, and unexpected metadata or package files. Shell declarations now enter the no-exec contract graph. The source-install fixture verifies uv_build.json explicitly; fixture inspection removes inherited checkout paths while the surrounding CHECK remains bound to its source.
The execution chain rejects optimized Python, uses hash-locked fixture backends and a version/digest-bound uv installer, and rechecks installer identity after replay. CI requires a clean checkout at the exact event-selected commit, builds from a fresh Git archive of that commit, and rechecks source identity before emitting provenance.
Validation at
6eea1828a34ed8ec99879f8090ea5d48352d8c2d: CI https://github.com/The-Interdependency/ucns/actions/runs/34689159193 passed source tests plus all six clean wheel/sdist installations on Python 3.10, 3.11, and 3.12, with 159 tests per installation and no skips. Downloaded artifacts, complete source/installed inventories, locked dependencies, XML outcomes, and exact-input receipts independently match the owning Git source. The acceptance receipt SHA-256 is850de6492db30d33eb43f385cad14edcd4ba1d48e8a741545e03162db9ece389. The final commit received a clean review: #227 (comment). All live review findings are resolved.Geometry ratification, unresolved Public Gonol operations, recursive-gonol research, theorem/proof standing, and expensive historical certificate recomputation remain outside this maintenance change. No publication or downstream semantic authority is transferred.