Skip to content

Resolve legacy observation self-review eligibility consistently #387

Description

@samovers

PR #388 keeps valid legacy observations captured while blocking new acceptance until typed semantics are approved. Current head 4ffe7bb, base/policy eea1601. The completed separate prerequisite PR #391 is merged and Delivery #390 closed. The observation diff is unchanged by integration. Zero Blockers and zero new findings; no PR #388 merge authorization exists.

Parent: #180. This Delivery implements only the observation eligibility limit from #179. Reporting Follow-up #389 remains separate; earlier Delivery #385 / PR #386 remains complete.

Capability and primary boundary

The primary trust boundary is observation acceptance eligibility before new accepted-force emission. All new direct and queued observation acceptance is disabled, including independent-reviewer acceptance and correction successors. Valid direct requests retain one immutable pending assertion and return RETAIN_DRAFT. Earlier refusals and ordinary diagnostics retain precedence; explicit acceptance reaching the guard receives HIGH_CONSEQUENCE_BLOCKED / Observation acceptance disabled. Existing temporal warnings remain in direct results and logs.

This explicitly narrows only observation acceptance/correction availability from prior correction decision v2 C03/C10. An old disputed observation may remain unresolved by correction. Historical accepted bytes, matching replay, reads and CONTEST remain; pending claims retain lawful rejection. Other assertion families keep their decided paths. No new grant, typed semantics, transaction/authority owner, canonical contract, signing/custody behavior, publication policy or production activation. No audit restart.

Approved acceptance criteria — unchanged

ID Required result
O01 Valid fresh confirmed direct observations with reviewer omitted/null/self/distinct all retain one pending assertion and emit zero accepted reviews/consequences/retirements. The unmodified base positively reproduces direct acceptance for omitted/null/self; the candidate refuses that capability. Check direct-call and real HTTP paths.
O02 Omitted and literal-false confirmation retain capture-only behavior and ordinary diagnostics, irrespective of reviewer hint; true cannot accept. Malformed confirmation still gets pre-transaction 422 and actor mismatch retains 403 precedence. Raw body and digest stay unchanged. Do not substitute another class's confirmation controls for observation coverage.
O03 Continue the same captured observation: self and distinct queued acceptance cannot consume it; both leave zero REVIEW edges and accepted outputs. A distinct authorized rejection still appends exactly one REJECTED decision/edge, changes derived disposition without editing claimState, and rejects duplicate review. Self-rejection remains refused.
O04 Missing/invalid evidence, authority, requested target, subject, scope, rationale, bundle and already-decided target retain the earlier governing refusals and create no accepted truth. Valid observation creation without REVIEW_ACCEPT still permits inert capture; granting REVIEW_ACCEPT cannot bypass O01/O03.
O05 Valid observation correction, direct or previously queued, never emits successor/accepted review/retirement or changes the old accepted/disputed predecessor. Earlier provenance/compatibility refusals remain meaningful. Operation, bounded structure and independently reviewed compliance keep their acceptance/contest/correction positive controls.
O06 In one retained disposable database, unmodified base HTTP creates fictional direct and queued accepted observations, pending observation/correction targets and history. Candidate matching historical keys reuse exact old references with no new accepted objects/edges; fresh keys cannot accept. Old accepted observations remain readable/contestable, old pending targets cannot newly accept, and old raw record bytes remain unchanged.
O07 No new authority, state, contract, transaction owner or production route. All emitted records remain reachable; refusal/rollback/replay preserve atomicity and accepted-state non-effects. Production closure, mandatory package/architecture checks, pinned full inventory, fresh exact-head review, two hosted baselines and publication receipt are required implementation evidence.

Complete implementation and current evidence

The PR owns nine paths, 1,354 additions / 38 deletions, including 28 runtime lines: the shared promotion gate; observation suite and genuine historical fixture; shared fixture registration; correction and review-fix tests; active review documentation; decision RFC; and full test inventory. The 42-case observation suite uses authentic base HTTP history before candidate execution in the same owned disposable database. No accepted rows are fabricated or safeguards disabled.

The entire observation diff is byte-identical before and after integration, SHA256 ed10014d36ceb7f8504e0deed08f6947548fb8045fedd871847b96af84691de4. The inherited audit test equals merged main and remains outside PR #388's owned delta. The historical fixture remains fixed to original base 9d7541d96bc708e9270b986927d7f4b8a035454f, tree 63d532112ed7c705997d0d71f5f6d0fec12928f7. O01–O07, the 4,525-case inventory and the approved boundary remain unchanged.

  • Fresh observation module: 42 passed, one expected Starlette warning, 31.43 seconds. Fictional fixtures, CPython 3.12.13, owned disposable PostgreSQL 17.10; owned resources removed and unrelated services preserved.
  • Mandatory package/architecture/temporal: PASS, zero failures, 10.101 seconds. Ruff, whitespace and lightweight 34872628959 passed.
  • Bounded integration/O07 review: zero Blockers, zero new Follow-ups, zero new Preferences, sealed in the PR body, SHA256 4db90eb21a123b726d42a6beb235f1ab79574b2e46d48bd496eb3732a83e3dd1. It preserves earlier content findings without restarting review or the audit.
  • Fresh admission 5667766907; source 34873076525, attempt 1, SUCCESS: both baselines, equivalence and both native architectures succeeded. Publisher 34876824763, attempt 1, SUCCESS.
  • Read-only publication verification: PASS at 2026-09-14T17:52:07.604030Z. Each baseline has 4,525 passed, zero failures/errors/skips/deselections and one exact inventoried Starlette collection warning. Pinned hosted environment, inventory, equivalence and source/published receipt bindings verified. Inventory raw SHA256: 93a897ac0a42ceaddc558dde3a1aeea2339b3b6c76ffc5e1b178ecc1db6c74ff.
  • Receipt artifact 10360884861, ZIP SHA256 9e399077240981ae60a3931261ca0d254f3ae07a807003479d5dfbf6703327bc, JSON SHA256 3e963ce504bb819f47eb3d8fd125dcd22c4c90452ba13b40615f78d5e81e5801. Verification-report SHA256: b50a60c397397fe8a6227b7cc5de9fe5ac974cbe73af7f48e930d0ada4d28737.

Native archives were not downloaded or independently re-executed locally; their IDs/digests, receipt bindings and index claims were checked. Verification records the capture interval; the final live state and evidence consistency recheck also passed.

Historical results and carried findings

Earlier source 34828888000 remains failed: baseline 1 passed 4,525; baseline 2 passed 4,524 and failed the audit overflow test's stale-time expectation; equivalence and publication handoff were skipped. PR #391 separately corrected that test and completed its own approval, review, evidence and merge gates. Its receipt does not transfer to PR #388.

The earlier combined local run remains 187 passed / 1 failed. Calibration reproduced the unchanged H1 operation-history clock-axis failure on prior and candidate bytes; read-only database-clock/current-state controls passed. No timing or source changes concealed it. Those results and all withdrawn packets remain historical.

Temporal-warning B1 is closed. Two non-blocking Preferences remain unchanged: P1, history-scenario selection by test-name substring; P2, explicit base/candidate RuntimeBundle digest equality. Follow-up #389 owns separate evidence-sufficiency/final-acceptance reporting. No new capability or process gate was added during integration.

Original authority and final stop

Decision OFARM2-LEGACY-OBSERVATION-ELIGIBILITY-001 version 1 applies to this Delivery and PR #388 in task 01a07cc8-4157-7b33-a0ca-becb772e0e8b. Original card msg_0d813f8071772f9a016aa6ef908cdc87d2b3edbcf339956013, line 11819, 2026-09-13T18:46:59.909Z; later exact approval msg_01a09c78-89b3-75b3-91fa-c8e6d25863b8, line 12080, 2026-09-13T20:32:20.403Z: I approve OFARM2 decision OFARM2-LEGACY-OBSERVATION-ELIGIBILITY-001 version 1. Both originals were directly retrieved again in order. This issue supplies navigation, not approval authority.

Scope stayed inside the observation eligibility boundary. Merge and deployment are not authorized by semantic approval or technical evidence. Final live recheck PASS: open/non-draft, MERGEABLE/CLEAN, unchanged full head/base/scope, no new findings, revocation or close/reopen. Report SHA256 1336de257460fdeacde41b637800ec9907bd041a37e30c821229c72ea948c905. Next: present the replacement complete exact-head packet and end unmerged for later same-task exact-head authorization before native merge and Delivery closure.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions