Skip to content

Composition integration gate: five-lane composition - #296

Merged
mosesy5688-cell merged 7 commits into
mainfrom
composition/p0-five-lane-integration-attempt1
Sep 5, 2026
Merged

Composition integration gate: five-lane composition#296
mosesy5688-cell merged 7 commits into
mainfrom
composition/p0-five-lane-integration-attempt1

Conversation

@mosesy5688-cell

@mosesy5688-cell mosesy5688-cell commented Sep 4, 2026

Copy link
Copy Markdown
Owner

Composition integration gate -- five-lane composition

FOUNDER DISPOSITION -- this supersedes the pre-authorisation status below.

The DO NOT MERGE, DO NOT DEPLOY restriction and the
COMPOSITION DOES NOT QUALIFY status recorded further down were the state of
this PR before the Founder ruling. They are retained as the historical
record and are no longer the live status.

The blocking item -- tests/api/target.test.ts asserting the stale
x-sciweon-schema-minor value 0.6.0 against the frozen F-3 contract value
0.6.1 -- was ruled on by the Founder: the contract is correct and the test
was a stale oracle
. It was corrected in Correction 1
(f695a040… -> 81b9ea8c…), a single additive commit touching exactly five
files (15+ / 3-).

Approved by the Founder for SQUASH MERGE at the exact head
81b9ea8c333c103dfb4de5a7a8185c7e8705ffb3, and for the automatic
push-triggered Deploy only
. No manual Deploy dispatch, no Factory, no
R2 / cursor / latest-pointer / ingestion mutation, no governance append, no
mint. PRs #291-#295 remain OPEN and UNMERGED at their frozen heads and are
dispositioned separately.

Final verified state at 81b9ea8c…

Correction 1 did three things beyond clearing the stale oracle:

  1. Corrected the oracle without weakening it. tests/api/target.test.ts
    still calls the real handleTarget(...), still reads the real response
    header, and still asserts exact equality. Only the expected literal moved
    0.6.0 -> 0.6.1. It was not deleted, not loosened to a regex, and not
    converted to a source-text scan.

  2. Closed three REST runtime-probe gaps. Before this commit the only test
    asserting an emitted x-sciweon-schema-minor header was target's; the
    other REST bindings were pinned only by readFileSync source-text scans,
    which prove a literal is present in a file, not that it reaches the wire.
    All four REST bindings now have an exact runtime probe:

    binding value test
    target 0.6.1 tests/api/target.test.ts
    xrefs 1.2 tests/api/composition-surface-matrix.test.ts
    negative-evidence 1.3 tests/api/composition-surface-matrix.test.ts
    repurposing 1.1 tests/api/composition-containment-matrix.test.ts

    The two MCP bindings were already covered by real handleMcp() calls
    asserting the header, SERVER_INFO.version and the response body.

  3. Qualified the Tier-2 containment row. removed_key_count = 6 on
    compound Tier-2 is a wiring-capacity measurement taken after six claim
    containers were artificially injected into the fixture
    . It is not a
    property of current production PubChem Tier-2 data, whose shape does not
    carry these containers and where the filter is normally a no-op. The row
    proves the Tier-2 path is wired to the filter and would remove the
    containers if they appeared -- not that six are removed in production. The
    matrix table below should be read with that qualification.

Two stale source comments were also corrected (negative-evidence.ts
1.1 -> 1.2 became 1.2 -> 1.3; xrefs.ts 1.0 -> 1.1 became 1.1 -> 1.2).
Comment tokens only; no emitted value or code changed.

Gates at 81b9ea8c…: test, security-scan, schema-validate and
enforce-compliance all pass. CES passes locally. Byte-identity over the
single-lane files stands at 50, the sole departure from 51 being
tests/api/target.test.ts, which the gate now edits under Founder authority.
git ls-files --eol: 806 tracked, 806 w/lf, 0 w/crlf. Merge-ref parent
identity closes exactly: parents[0] = PR base = c88c1f52…,
parents[1] = 81b9ea8c….

The scripts/verify/rk15-v3c-surfaces.js citation recompute mandated for this
gate produced zero net change; all 21 worker.ts:NN citations were verified
correct against the composed router (61 negative-evidence, 69 repurposing,
77 bioactivities, 85 trials, 93 papers, 109 target, 117 mcp,
125 xrefs, 133 _health, span from 61).


Historical record (pre-authorisation, retained verbatim)

Composition integration gate -- five-lane composition (DO NOT MERGE, DO NOT DEPLOY)

Composes the five Founder-accepted lanes onto the frozen baseline. No merge,
no deploy, no Factory / R2 / ingest / cursor / latest-pointer movement.
The
five original PRs stay OPEN and UNMERGED.

BASE   c88c1f525d623f0b3a16715551d3a5983438e36a

STATUS: COMPOSITION DOES NOT QUALIFY -- one blocking contradiction

tests/api/target.test.ts:174 asserts x-sciweon-schema-minor === '0.6.0'.
The frozen F-3 binding list mandates target.ts move 0.6.0 -> 0.6.1. Both
cannot hold. That test file is lane #292's accepted content and one of the 50
files required to remain byte-identical, so the composition gate is not
authorised to change it
and did not. The mandated binding was applied and the
resulting failure is left visible for a founder ruling. See "Blocking item".

Replay

Five BASE..head diffs applied with git diff --binary | git apply --3way --index, in the frozen order, one commit per lane, gate content isolated in
commit 6.

1  #291  229e4e5  deployment identity        clean, exit 0
2  #292  390a6e4  public error contract      clean, exit 0 (worker.ts 3-way)
3  #293  c11e3b5  rights candidate registry  clean, exit 0
4  #294  73613b0  public claim containment   clean, exit 0 (5 api files 3-way)
5  #295  c49c1db  merge integrity            clean, exit 0

Zero conflicts. No manual conflict resolution was required anywhere, so no
semantic choice was made. scripts/factory/lib/aggregated-merger.js stands at
249 lines, byte-identical to #295's head; the gate added nothing to it.

Partition and byte identity

Independently derived and matching the pre-computed partition: 64 (file, lane)
rows, 58 distinct files, 6 multi-lane files, 52 single-lane, no file touched by
three or more lanes.

50 / 50 single-lane files are byte-identical to their own lane head, zero
mismatches
(git cat-file blob comparison). scripts/verify/rk15-v3c-surfaces.js
also came out byte-identical, so the true figure is 51 -- see deviations.

What this proves: those files were not altered by the replay. What it does NOT
prove: that the composed system behaves correctly. Two individually unaltered
files can still interact badly. Behaviour is covered by the suite, CES and the
CI gates, and containment separately by the matrix below.

F-3 version bindings (monotonic response-contract markers, NOT product SemVer)

These exist so a cached pre-composition body is distinguishable from a
post-composition one at the serving boundary. They assert nothing about feature
level, stability or API compatibility.

file binding before after
src/worker/api/negative-evidence.ts x-sciweon-schema-minor 1.2 1.3
src/worker/api/repurposing-evidence.ts x-sciweon-schema-minor 1.0 1.1
src/worker/api/target.ts x-sciweon-schema-minor 0.6.0 0.6.1
src/worker/api/xrefs.ts x-sciweon-schema-minor 1.1 1.2
src/worker/api/mcp.ts SERVER_INFO.version 0.6.0 0.6.1
src/worker/api/mcp.ts x-sciweon-mcp-version 0.6.0 0.6.1

PROTOCOL_VERSION (2025-03-26) is unchanged. x-sciweon-rights-filter
rc3a-v2 is lane #294's, verified not re-authored: 7 literals, all rc3a-v2,
zero rc3a-v1.

SERVER_INFO.version and x-sciweon-mcp-version are two distinct bindings that
happen to carry the same string; nothing in the source prevents them diverging.
A version-sync test now pins them together.

Per-surface containment matrix

Containment holds everywhere, but the mechanism differs by surface and the two
must not be written as one. Every row is measured, not inferred.

surface containers reach filter mechanism removed count marker test evidence
compound Tier-1 yes FILTER_REMOVAL 6 yes composition-surface-matrix.test.ts :: compound Tier-1
compound Tier-2 yes FILTER_REMOVAL 6 yes composition-surface-matrix.test.ts :: compound Tier-2
negative-evidence no UPSTREAM_PROJECTION 0 no composition-surface-matrix.test.ts :: negative-evidence
repurposing-evidence no UPSTREAM_PROJECTION 0 no composition-containment-matrix.test.ts :: CLASSIFICATION
target no UPSTREAM_PROJECTION 0 no composition-surface-matrix.test.ts :: target
xrefs no UPSTREAM_PROJECTION 0 no composition-surface-matrix.test.ts :: xrefs
MCP /api/mcp no UPSTREAM_PROJECTION 0 no composition-surface-matrix.test.ts :: MCP alias
MCP /api/v1/mcp no UPSTREAM_PROJECTION 0 no composition-surface-matrix.test.ts :: MCP alias

repurposing is classified UPSTREAM_PROJECTION, measured not assumed: the
aggregator returns a new literal object and summarizeNegative projects each
example to {id, evidence_type}, so containers never enter the payload.

Stated plainly: public six-container absence is ESTABLISHED. Active N > 0
filter removal is OBSERVED ON COMPOUND (both tiers). N = 0 after upstream
shaping is OBSERVED on the named shaped surfaces. Active removal on every
surface is NOT claimed.
Marker absence on a projection surface is correct and
is not evidence of removal.

CI identity step

One read-only step, id: composition_identity, in the existing test job.
No new job, no widened permissions (contents: read unchanged).
continue-on-error: true so a token or API failure cannot turn CI red -- but
the gate treats any absent or empty value as a qualification failure. gh api
is used because it is server-side: actions/checkout@v4 defaults to
fetch-depth: 1, so a local git log -1 --format=%P returns empty here.

Placed immediately after checkout so the identity record is emitted even when a
later step fails.

Verification

  • Full suite: 3238 passed, 4 failed, 13 skipped (272 files).
  • CES (python scripts/check_compliance.py): PASSED, exit 0.
  • Line-count audit (CES splitlines() semantics): no file exceeds 250. No
    gate-touched file is at the cap. The six binding edits are in-place value
    substitutions with zero line delta.
  • git ls-files --eol: 806 tracked, 806 w/lf, 0 w/crlf.
  • Composed diff is exactly 58 lane files + ci.yml + 3 gate test files = 62.
    Nothing unauthorised written; no lane file dropped.

The 4 failures, unsuppressed

  1. tests/api/target.test.ts -- the blocking F-3 contradiction above. New,
    caused by the mandated binding.

    2-4. tests/factory/dailymed-adapter-incremental.test.ts (3 timeouts) --
    pre-existing and environmental, not composition-caused. The test file
    and both its imports are byte-identical to BASE, no composed-diff file is in
    its import graph, and the adapter performs real network fetches that the
    local sandbox blocks. These may well pass on a GitHub runner, which has
    network.

Blocking item for founder ruling

Applying the mandated target.ts binding necessarily breaks a lane-owned test
assertion. The one-line fix is obvious ('0.6.0' -> '0.6.1' at
tests/api/target.test.ts:174) but it is outside this gate's authorisation on
two independent grounds: it edits an accepted lane's content, and it breaks the
50-file byte-identity invariant. No choice was made. The ruling is yours.

mosesy5688-cell and others added 7 commits September 4, 2026 21:35
Composition of the five Founder-accepted lanes (#291 #292 #293 #294 #295)
replayed from BASE c88c1f5 in the frozen order. This commit isolates
everything the composition gate itself authored.

F-3 response-contract bindings (MONOTONIC RESPONSE-CONTRACT MARKERS, not
product SemVer claims -- they exist so a cached pre-composition body is
distinguishable from a post-composition one at the serving boundary):
  negative-evidence.ts    x-sciweon-schema-minor  1.2   -> 1.3
  repurposing-evidence.ts x-sciweon-schema-minor  1.0   -> 1.1
  target.ts               x-sciweon-schema-minor  0.6.0 -> 0.6.1
  xrefs.ts                x-sciweon-schema-minor  1.1   -> 1.2
  mcp.ts                  SERVER_INFO.version     0.6.0 -> 0.6.1
  mcp.ts                  x-sciweon-mcp-version   0.6.0 -> 0.6.1
PROTOCOL_VERSION (2025-03-26) deliberately UNCHANGED.

CI: one read-only identity-recording step in the EXISTING test job. No new
job, no widened permissions. continue-on-error keeps a token/API failure
from turning CI red; the gate treats any absent value as a qualification
failure.

Tests: version-sync (SERVER_INFO.version and the x-sciweon-mcp-version
header are two distinct bindings; nothing else prevents them diverging),
plus the per-surface containment matrix including the repurposing
classification lane 3S did not individually verify.

KNOWN RED, NOT FIXED HERE: tests/api/target.test.ts:174 asserts
x-sciweon-schema-minor === '0.6.0' and now fails against the mandated
'0.6.1'. That file is lane #292's accepted content and is one of the 50
files required to stay byte-identical, so the composition gate is not
authorised to change it. Escalated for a founder ruling.
…e REST runtime probes

Bounded Correction 1 to the five-lane composition gate. Founder ruling: the
frozen F-3 contract target.ts = '0.6.1' is CORRECT; tests/api/target.test.ts
was a STALE ORACLE still expecting '0.6.0'. The oracle is corrected; the
contract is NOT rolled back.

The corrected assertion remains a real probe: it still calls handleTarget(),
still reads x-sciweon-schema-minor off the real Response, and still compares
by exact equality. Only the wrong expected literal changed.

Closes three REST runtime-coverage gaps. Before this commit the four REST
schema-minor bindings were pinned only by source-text scans in
tests/worker/composition-version-bindings.test.ts; now each is also asserted
against a live handler response:

  target            0.6.1  tests/api/target.test.ts
  negative-evidence 1.3    tests/api/composition-surface-matrix.test.ts
  xrefs             1.2    tests/api/composition-surface-matrix.test.ts
  repurposing       1.1    tests/api/composition-containment-matrix.test.ts

The two MCP bindings (SERVER_INFO.version, x-sciweon-mcp-version) already had
real handleMcp() runtime probes and are unchanged.

Qualifies the Tier-2 matrix row so removed_key_count = 6 reads as a
wiring-capacity measurement over an artificially injected fixture, not as a
property of production PubChem Tier-2 data.

Comment-only corrections to two stale bump annotations; no emitted value, no
rights-filter marker and no code changed:

  negative-evidence.ts  "bumped 1.1 -> 1.2"  ->  "bumped 1.2 -> 1.3"
  xrefs.ts              "bumped 1.0 -> 1.1"  ->  "bumped 1.1 -> 1.2"

Additive commit; five files; no lane content altered. PROTOCOL_VERSION
('2025-03-26') untouched. No merge, no deploy.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019c1bKNiDv8zfaPunCXUANq
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant