Skip to content

Finalize criterion completion and bind release evidence to the updater - #150

Merged
pcvantol merged 3 commits into
mainfrom
codex/criterion-completion-finalization
Sep 18, 2026
Merged

pcvantol merged 3 commits into
mainfrom
codex/criterion-completion-finalization

Conversation

@pcvantol

@pcvantol pcvantol commented Sep 18, 2026

Copy link
Copy Markdown
Owner

The criterion completion implementation is protected-merged in #149. Before publication, independent updater review found that the new release workflow retains installed-composition summaries but the updater still rejected those fields. This finalization corrects that exact producer/consumer join: both qualification and registry-readback summaries must bind the 2.7.25 wheel and contain the eight qualifying scenario outcomes. Older release shapes stay unchanged; actual published receipts are never edited.

Captured installed-summary fixtures and negative cases cover missing, duplicate, malformed, source-only, mismatched and failed evidence. The separate source finalization records the implementation and assurance evidence with bootstrap navigation. It leaves publication, downloaded-byte qualification, safe activation and final completion open within the same assignment, and preserves #148's negative Mission-3 acceptance. Runtime modules and the selected version remain unchanged.

Validation: focused updater suite29 tests,1 existing opt-in skip; complete applicable validation and new independent Quality/Security review of the corrected exact candidate are recorded on this PR before merge. The initial doc-only reviews remain historical; they do not approve the later controller correction. Required hosted checks remain enforced.

@pcvantol

Copy link
Copy Markdown
Owner Author

Exact finalization candidate: 1a4f2ce261aa0b145ff86b06bced78d880e27a32.

  • Independent Quality: PASS, no open findings; verified documentary scope, navigation, sanitation, exact artifact identities and implementation-to-merge tree equivalence.
  • Separate independent Security: PASS, no open findings; verified the two documentation changes, merge/check claims, artifact identities and qualification boundaries.
  • Full applicable validation:817 tests passed,1 existing opt-in artifact test skipped; compile, version policy, offline projection, JSON and whitespace checks passed.
  • No product source or version changed after the reviewed implementation. Publication and installed activation remain explicitly pending. Required hosted checks must pass before merge.

These are actual separate agent review results, recorded as source assurance rather than fabricated GitHub approval records or Mission grants.

@pcvantol pcvantol changed the title Finalize criterion completion source delivery Finalize criterion completion and bind release evidence to the updater Sep 18, 2026
@pcvantol

Copy link
Copy Markdown
Owner Author

Final corrected candidate: ef08f1dc47b1ff1a26dae9252b11c2db108bb1dc.

Independent Quality PASS and separate independent Security PASS, both no open findings on this exact head. Quality independently ran57 tests with1 existing opt-in skip; Security independently ran29 updater tests with1 skip and reproduced rejection of its original false-positive case. Both reviewers are distinct from the implementation author.

Owning full validation:818 tests completed successfully with1 existing opt-in skip; compilation, version policy, offline projection, JSON and whitespace checks passed. Runtime modules remain byte-identical to the reviewed implementation in #149.

Finalization review retained and corrected two findings before any release publication:

  1. The release workflow's new composition summaries did not match the updater's strict receipt keys. Version2.7.25 now requires and validates both exact-wheel summaries while historical release shapes remain unchanged.
  2. A generic blocked outcome could mask the regression scenario's wrong criterion result. Each scenario now requires its exact K1/K2 status, criterion reason, action/planner/submission/assessment count, blocking reason, closed shape and preservation/reopen flags.24 negative receipt mutations cover both lifecycle stages.

Actual published-byte updater qualification and production activation remain later gates in this same assignment. No receipt has been stripped, synthesized or rewritten to bypass validation, and no production Mission/reset was started. Earlier candidate reviews remain historical evidence, not approvals of subsequent changes.

@pcvantol
pcvantol merged commit 61e0289 into main Sep 18, 2026
5 checks passed
@pcvantol
pcvantol deleted the codex/criterion-completion-finalization branch September 18, 2026 11:01
@pcvantol

Copy link
Copy Markdown
Owner Author

Normal release and exact published-artifact qualification are complete; production activation is still pending the scoped coordination window.

  • Protected release/controller source: 61e02899277d4ee557696bb24a051916e8c961c2.
  • Normal release run35337571211: all five jobs PASS, terminal RELEASE_COMPLETE.
  • Public Forge2.7.25 release, normal PyPI publication, no overwritten version or artifact.
  • Wheel SHA-256: e0ea58bf6ce242d4eca66801ef4c764c7104b90df5503141a8ebf0006c1aa7b8.
  • sdist SHA-256: 918db200a3970f75b6e0e6e338583cfab3784e648bf34ad613bbd0029efdab7b.
  • Terminal public release receipt SHA-256: bd33740bff86ba54dcf8f756ead2192e4029adfe40c303c7bc50361d7e44b783.
  • Protected updater file SHA-256: 0871d864056d1c7594d0a9eb8f36df1fb9abb30454a076abe4ff27bb71af3a6e.

Fresh local registry downloads match both immutable qualification/publication artifact digests. The noneditable downloaded wheel passed all eight normal composition scenarios again. The workflow independently ran those scenarios before publication and on downloaded PyPI bytes, with summaries retained in the actual release receipts.

The real owning updater then passed four fresh isolated synthetic installations using this exact wheel, terminal receipt and protected controller: normal, controlled interruption before database swap, after database swap, and during activation. Each reached COMPLETE, preserved all nonmetadata contents/identity/authority, migrated38→39 and accepted unchanged COMPLETE replay. Recovery reused the same durable request; after migration, failure fenced the old route. These are controlled exception interruptions, not a claim of abrupt process-kill testing. Baseline provenance is the actual published2.7.24 wheel; no production data or credential was copied into fixtures.

A concrete private production request now binds these exact artifacts and the existing selected installation. Fresh owning read-only target/quiescence/process checks PASS. That preparation has not invoked the production updater, reset, Mission intake/planning or Host submission. Actual safe activation and read-only production verification remain required before the final completion claim.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant