Skip to content

P2: Gate Python claims and publish on the exact proven candidate #275

Description

@tomdps

Parent

Tracking parent #251; epic #243. This is one vertical delivery slice. Do not close or bypass the parent tracker from this child.

Goal

Authorize public wording and release only from same-commit matrix, package, platform, provenance, and real-repository evidence.

Dependency contract

Required behavior

  1. Freeze the candidate SHA and require it to equal every child artifact source SHA, checkout HEAD, workflow_run head SHA, aggregate SHA, and prerequisite receipt SHA; bind tree ID, workflow run/attempt, matrix/audit digests, tarball integrity, installed files, descriptors, ASP manifest, and managed artifacts by checksum.
  2. Make publish consume the retained CI-tested tarball or prove byte identity; repacking unbound bytes is forbidden. Store authoritative candidate receipts as immutable CI/release artifacts keyed by SHA.
  3. Render/audit README, quickstart, concepts, examples, demo, agent integration, package copy, CLI help/JSON manifests, descriptors, release notes, and roadmap wording against proven capability IDs/states.
  4. Reject unqualified Python parity/full-support or positive Windows claims without matching cells; preserve experimental/degraded-honest and Windows-unsupported wording unless separate evidence and explicit policy change it.
  5. Run package/provenance/cutover/claim/fallback gates and retain no ASP-standard, old-tool replacement, security/SAST, all-stack, AI-authorship, automatic-fix, or blended-score claim.
  6. Maintainer/subagent-owned. Do not launch Zeroshot unless the user explicitly re-delegates this slice after its JIT review.

Acceptance criteria

  • Every child receipt and published/retained artifact has the same exact source/package identity; stale SHA, changed bytes, missing platform row, forged command, undeclared network/install, or provenance drift fails.
  • Every public/runtime surface agrees with the ledger and representative-repo audit; unsupported cells remain visible.
  • All release gates and local CI-equivalent proof pass; P2 — Ship honest Python readiness, setup, receipts, and cross-platform cutover #251 closes only after the evidence index links every prerequisite/child.

Observable outcomes

  • Clean success carries positive execution/provenance evidence; zero diagnostics alone is never proof.
  • Findings and every unavailable/invalid/timeout/crash/resource/stale/unsupported state are machine-readable and fail or degrade exactly as the capability contract says.
  • No implicit fallback, partial result, or skipped execution is reported as a pass.
  • Target source, configuration, lockfiles, environments, and caches remain unchanged except where this issue explicitly owns a validation-gated atomic edit; every temporary resource/process is cleaned.

Non-goals

  • fixing functional defects discovered here
  • docs-first readiness
  • old-tool retirement
  • automatic release announcement

Verification

Run focused behavior first, then the configured repository proof only after the acceptance matrix works:

  • npm run build
  • npm run lint
  • npm run pack:check
  • npm run release-receipt:check
  • npm run cutover:check
  • npm run provenance:check
  • bash ./scripts/ci/run-local-ci-equivalent.sh
  • all platform/audit/claim validators
  • Attach exact real-tool/artifact versions, argv/config/cwd/source, normalized result examples, before/after cleanliness evidence, and packed-install proof where the slice changes public package behavior.

Execution rule

Implement only after a just-in-time review against current dev. Keep exactly one implementation run active. PR base is dev; require green checks, clean scoped diff, merged PR, closed child, parent checklist update, focused reproductions, and opcore-ci proof before starting the next child. Do not claim Python readiness/parity, ASP authority, old-tool replacement, security/SAST, all-stack support, automatic fixes, or a blended score.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestrelease-blockerBlocks the 0.1.0-alpha.0 release

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions