Roadmap item 4: Add inactive deterministic verifier payload - #222
Conversation
# Conflicts: # README.md # RESTORE.md # ci/required-files.txt
# Conflicts: # README.md # RESTORE.md # ci/required-files.txt
|
Construction safety-scope approval needed The exact #222 candidate deterministically fails the closed schema-import guard. The verifier intentionally consumes the canonical public core schema; replacing it with copied local validators would create schema drift. Requested exact authorization:
A scan of already-prepared Roadmap units found three more intentional canonical importers. To avoid repeated approval prompts, authorize these exact paths when their own bounded PRs are finalized:
No wildcard, no other importer, no generation-ID activation path, and no weakening of existing rejection logic. Each addition lands only with its own unit and must pass exact CI plus fresh independent review. Current #222 branch remains clean and unchanged at |
|
Operator authorization recorded The operator explicitly approved the five exact named canonical-schema importer paths in the current construction session. No wildcard is authorized. This PR will add only:
to the closed |
Deploying ystack with
|
| Latest commit: |
5c9f070
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://79fea466.fabrica-6yx.pages.dev |
| Branch Preview URL: | https://codex-default-deterministic.fabrica-6yx.pages.dev |
Codex reviewer (cross-vendor, read-only)Reviewed-head: 466d658 Final review: not clean. Important — incident-mismatched execution can carry passed verifier evidenceThe selected core v2 relation intentionally preserves mismatched or unclassified execution facts for failed, cancelled, and completed-inconclusive incidents, but it does not enforce the accepted rule that a wrong performer or capability may carry only non-passing evidence. A fully rehashed completed-inconclusive result using a CI actor and unclassified GitHub Actions capability was accepted with passed deterministic and behavioral verifier evidence. The adapter then emitted the selected verifier identity while omitting those mismatched execution facts. The root cause belongs in the immutable core result relation. Do not add a duplicated adapter-local guard. Fix the core so any execution mismatch forces all evidence verdicts to be non-passing, then add fully rehashed completed-inconclusive, failed, and cancelled regressions before this PR resumes. The exact six-path diff and its two authorized schema-import allowlist entries are otherwise clean. Required CI succeeded on the reviewed head, but this Important blocks publication. |
|
Construction root-cause adoption The current operator-authorized construction session adopts the Important finding in review comment 5517940810 as a Roadmap implementation correction. Exact concern: Parent selected generation: Required behavior:
Delivery is two bounded PRs:
PR #222 remains paused and unchanged until both land. |
…fault-deterministic-verifier-adapter-v1
Codex reviewer (cross-vendor, read-only)Reviewed-head: 5c9f070 Posted verbatim by The normalizer consistently validates the verifier request, profile, manifest, snapshot, result, attempt identity, and timestamp relationships before emitting an inactive, authority-free observation. The accompanying tests and restore manifest updates align with the implementation, and no actionable correctness issue was identified. |
Summary
Scope
Tracks ROADMAP item 4 without closing an intake issue.
This is one payload-only unit. It changes exactly README, RESTORE, the verifier normalizer, the required-file manifest, its focused test, and the portable-core schema import guard. The guard adds only the two exact importer paths for this unit; it adds no wildcard and changes no core rule. This PR intentionally ships no adapter manifest or default-profile binding. A later assembly PR must bind the normalizer from its durable squash-main identity.
This payload normalizes an already-supplied verifier result. It does not execute candidate code or claim that a sandbox or verifier implementation is qualified. A runnable verifier still needs a separately qualified sandbox launcher and fixed implementation.
Safety
The payload is inactive, offline, and unqualified. It does not run a command or tool, read proof bytes, use a credential or network, write evidence or target state, grant authority or qualification, or activate a profile. It accepts no provider metadata and emits no effects.
Exact tuple
5868e889ec5ea800ad0e36b99fe583b36b93ec85466d658cb7ab8caf160b1c7cc7bc3bfa589f5bc9Proof
scripts/test/default-deterministic-verifier-adapter.test.sh: 46/46 checks passed with pinned jq 1.6.scripts/test/portable-core-schema.test.sh: all 47 owned rules, 141 direct cases, 13 private routes, 8 registry cases, 39 activation guards, 8 numeric boundaries, 8 review findings, and 44 legacy assertions passed; zero failures.bash -n: passed.-x -S style: passed.The branch merged current main normally. It was not rebased or force-pushed.