Skip to content

Commit 51ccd8a

Browse files
committed
fix: close reviewed campaign terminalization gaps
Close the cohesive Branch 11 ANDON 153-159 repair wave. ANDONs 153 and 154 exposed completed adapter outcomes and atomic attempt claims that could lose replayable projection custody. ANDON 155 found divergent phase, classification, and incident-failure derivation for mixed projection outcomes. ANDON 156 found a pre-submit authorization drift mislabeled after the failure phase advanced too early. ANDON 159 found canonical consumed claim sets stranded when a foreign or missing legacy projection stopped recovery before terminal publication. ANDONs 157 and 158 remain bounded qualification-wrapper and review-transport events with no source repair claim. Reconstruct completed result and provider-receipt projections only from retained adapter state and original execution custody. Consume attempt claims atomically, use one closed phase/classification/failure-class contract, keep both final live rechecks pre-dispatch, and enter provider execution only immediately before first submit. Treat the immutable claim set as canonical; inspect every legacy projection as EXACT, COLLISION, or MISSING; preserve foreign bytes; terminalize through the governed no-dispatch path; and revalidate the same state on replay. The focused reviewed-campaign contract passes 110/110, including initial producer, retry, and cold-review collision/missing canaries plus replay-substitution checks. Fresh exact-tree qualification passes no-model preflight 25/25, local CI 179/179 from command 1 with strict PowerShell and zero timeouts, and generated/package 7/7. Independent exact-freeze whole-branch review accepts with Critical 0, Important 0, and Minor 0. This commit does not claim exact-SHA GitHub CI, an exact-commit source receipt, candidate readiness, campaign authority, reservations, provider invocation, paid usage, human assessment, merge, release, or owner acceptance. Paid execution remains 0/5.
1 parent 8247857 commit 51ccd8a

4 files changed

Lines changed: 1804 additions & 118 deletions

File tree

docs/audits/v0.4.6.0-wip-andon-closure-ledger.json

Lines changed: 25 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4410,10 +4410,10 @@
44104410
},
44114411
{
44124412
"kind": "file_sha256",
4413-
"source_ref": "Task 11bi rejected predecessor repair tree 2e6d34ebfee35d0c0cb15052666966f2fcd95eb0; Task 11bj owner report sha256 ce6cb5f9e3a96da211be5915802edcfb91191e066fca17cb591f16ef4f5a8da8 and Task 11bk independent APPROVE sha256 9d5c056a0a57e8de23af58f06c5934c51c729f921eb663b3ec288a00a8ec61eb bind exact repaired strict-JSON, mixed-terminal replay, execution-tooling, predispatch, and timeout contracts; Task 11cg ANDON 150 current-byte repair preserves the governed provider-cost-unavailable aggregate during live post-observation failure terminalization",
4413+
"source_ref": "Task 11bi rejected predecessor repair tree 2e6d34ebfee35d0c0cb15052666966f2fcd95eb0; Task 11bj owner report sha256 ce6cb5f9e3a96da211be5915802edcfb91191e066fca17cb591f16ef4f5a8da8 and Task 11bk independent APPROVE sha256 9d5c056a0a57e8de23af58f06c5934c51c729f921eb663b3ec288a00a8ec61eb bind strict-JSON, mixed-terminal replay, execution-tooling, predispatch, and timeout contracts; Task 11cg ANDON 150 preserves governed provider-cost-unavailable settlement; Task 11cl ANDON 153/154 current bytes reconstruct exact completed receipts and terminal projections from retained adapter results plus original execution custody after projection failure and consume attempt authority through one atomic recoverable claim set; Task 11cn ANDON 155 makes publication and replay share one exact phase/classification/failure-class contract for mixed projection failures; Task 11cp ANDON 156 keeps pre-dispatch classification through the final live authorization and tooling rechecks and crosses into provider execution only immediately before the first submit; Task 11cu/11cv ANDON 159 current bytes treat the immutable attempt claim set as canonical after projection collision or persistent absence, retain ordered EXACT/COLLISION/MISSING projection states, preserve foreign bytes, terminalize without dispatch, and revalidate exact replay",
44144414
"commit_sha1": null,
44154415
"blob_sha1": null,
4416-
"sha256": "3b872484bb9d1b91d471492aaf0365cead5178ffce9c6bbf4f6858195a4c6a6e",
4416+
"sha256": "d643fe9fa7f729bb0e7f85b7d84ceede98ee0a5716e8a909e3991cd1cfc9c5b5",
44174417
"command": null,
44184418
"exit_code": null,
44194419
"retained_artifact": "tools/reviewed_campaign_orchestrator.py",
@@ -4463,6 +4463,28 @@
44634463
"retained_artifact": null,
44644464
"unretained_reason": "raw stdout and stderr and the ignored Task 11cg owner record are not tracked repository artifacts; bounded focused acceptance does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure"
44654465
},
4466+
{
4467+
"kind": "command_result",
4468+
"source_ref": "Tasks 11cl/11cn/11cp current ANDON 153-156 test-first repair; reviewed-campaign orchestrator sha256 e89c40983a4a5c98b0e67040bff059230d379bb73712f668ef893e70ea456b7d and permanent test sha256 577ce028ccc791356ecc7ebd5a3ffe121754b55d07bf62165fa5ac12abb6f2f2; all ten all-completed live result/provider-receipt publication positions close five completed paid attempts without replacing foreign bytes, initial and retry claim projection failures terminalize from one atomic attempt claim set, interrupted exact claim sets recover without redispatch, the cold-review shared boundary is directly covered, mixed four-completed/one-outcome-unknown result and receipt projection failures settle exactly and replay without redispatch through one shared failure-state contract, and a fourth-load final pre-submit authorization drift proves five not-dispatched calls with zero host starts and exact replay; full reviewed-campaign contract is 106/106 GREEN",
4469+
"commit_sha1": null,
4470+
"blob_sha1": null,
4471+
"sha256": null,
4472+
"command": "python -B tests/reviewed-campaign-orchestration/test_contract.py",
4473+
"exit_code": 0,
4474+
"retained_artifact": null,
4475+
"unretained_reason": "raw stdout and stderr and the ignored Task 11cl/11cn/11cp owner records are not tracked repository artifacts; focused GREEN does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure"
4476+
},
4477+
{
4478+
"kind": "command_result",
4479+
"source_ref": "Task 11cw current ANDON 159 test-first repair; reviewed-campaign orchestrator sha256 d643fe9fa7f729bb0e7f85b7d84ceede98ee0a5716e8a909e3991cd1cfc9c5b5 and permanent test sha256 9d244d75e3f0d121db6009a93e9a973bf66c11922d7f3ebe3dd2f5359e2ca8a7; six initial/retry/cold-review foreign or persistently missing claim-projection subcases terminalize from the exact immutable claim set with ordered EXACT/COLLISION/MISSING states, preserve foreign bytes, retain no-dispatch evidence, and replay without redispatch; direct canaries are 4/4 GREEN, ten claim-set/projection/replay neighbors are 10/10 GREEN, and the full reviewed-campaign contract is 110/110 GREEN",
4480+
"commit_sha1": null,
4481+
"blob_sha1": null,
4482+
"sha256": null,
4483+
"command": "python -B tests/reviewed-campaign-orchestration/test_contract.py",
4484+
"exit_code": 0,
4485+
"retained_artifact": null,
4486+
"unretained_reason": "raw stdout and stderr and the ignored Task 11cw owner record are not tracked repository artifacts; focused GREEN does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure"
4487+
},
44664488
{
44674489
"kind": "command_result",
44684490
"source_ref": "Task 11bj owner verification after Task 11bk acceptance; current tooling-bound capture schema sha256 e0616acb1ff645c31e21a766b99f9671c6c3e652150926ef1acc37901b48a859, bridge sha256 6f5416c4170f5c0e9b848a70895d50d2549a5668d88892e589d4bf1de3c400af, and permanent test sha256 66513599523fc762f8e079c4f3330ef5e65b2f1115338935409fad54815483db; 2/2 GREEN including valid execution-tooling manifest fixture custody and exact result/captured-output/provider-subject identity",
@@ -4825,7 +4847,7 @@
48254847
"remaining_risk": [
48264848
"deterministic closure is not model, WIP, merge, release, or regression proof"
48274849
],
4828-
"next_action": "Keep A16 PARTIAL and terminal OPEN; regenerate the Branch 11 deterministic cohort on the final repaired tree, freeze and independently review that tree, require successor exact-SHA CI and a fresh mature candidate, then execute only the authorized governed campaign before final owner acceptance.",
4850+
"next_action": "Keep A16 PARTIAL and terminal OPEN; independently review the bounded ANDON 159 claim-projection terminalization/replay repair, then regenerate the Branch 11 deterministic cohort on the accepted exact tree and obtain a fresh whole-branch review; require successor exact-SHA CI and a fresh mature candidate before executing only the authorized governed campaign.",
48294851
"terminal_status": {
48304852
"required_status": "CLOSED_OWNER_ACCEPTED",
48314853
"owner_acceptance_required": true,

docs/audits/v0.4.6.0-wip-andon-closure-ledger.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,7 +36,7 @@
3636
| `A13` | `P0` | `OPEN` | `CURRENT` | `True` | `True` | `True` | `True` | A10, A12 | Preserve the current adapter-bound package-harness parity bytes and permanent path/hash canaries while completing final deterministic suites, whole-branch review, successor exact-SHA CI, terminal dependencies, and owner acceptance; keep A13 terminal OPEN. |
3737
| `A14` | `P0` | `OPEN` | `CURRENT` | `True` | `True` | `True` | `True` | A01, A10, A11, A12, A13, A15 | Preserve the current envelope/finalizer and campaign-control bytes while completing final deterministic suites, whole-branch review, successor exact-SHA CI, a fresh mature Branch 11 candidate, the separately authorized reviewed campaign, and owner acceptance; keep A14 terminal OPEN. |
3838
| `A15` | `P0` | `OPEN` | `CURRENT` | `True` | `True` | `True` | `True` | A02, A03, A04, A05, A07, A08, A09, A10, A12, A13 | Preserve bounded A15 acceptance while the independently accepted R3 repair set is frozen as a new exact tree and receives fresh deterministic/whole-branch review evidence; then require successor exact-SHA CI, terminal dependencies, and owner acceptance; keep A15 terminal OPEN. |
39-
| `A16` | `P0` | `OPEN` | `PARTIAL` | `True` | `True` | `True` | `True` | none | Keep A16 PARTIAL and terminal OPEN; regenerate the Branch 11 deterministic cohort on the final repaired tree, freeze and independently review that tree, require successor exact-SHA CI and a fresh mature candidate, then execute only the authorized governed campaign before final owner acceptance. |
39+
| `A16` | `P0` | `OPEN` | `PARTIAL` | `True` | `True` | `True` | `True` | none | Keep A16 PARTIAL and terminal OPEN; independently review the bounded ANDON 159 claim-projection terminalization/replay repair, then regenerate the Branch 11 deterministic cohort on the accepted exact tree and obtain a fresh whole-branch review; require successor exact-SHA CI and a fresh mature candidate before executing only the authorized governed campaign. |
4040

4141
## Milestones
4242

@@ -597,11 +597,13 @@ Evidence references:
597597
- kind=file_sha256; source=Whole-branch review R4 rejected prospective tree 3b022b9507a303def93c24ff8d06d44575de5c70 with 0 Critical, 5 Important, and 0 Minor findings; its complete deterministic PASS cohort remains historical and non-promotable; sha256=5dd5ffb155c247068e8d51c460354ef9abf8284794a8a5ea90d19fc979504fb8; retained=docs/audits/evidence/v0.4.6.0-b10/task7-independent-whole-branch-review-r4.md
598598
- kind=file_sha256; source=Owner closeout of the five concrete R4 repairs; no new deterministic whole-branch evidence or terminal claim; sha256=3fb5885c19d28536165f30b9331d43908b93495f22c8cbf1d02b95de4b0071bb; retained=docs/audits/evidence/v0.4.6.0-b10/task7-whole-branch-r4-repair-owner-report.md
599599
- kind=file_sha256; source=Independent bounded acceptance of all five R4 repairs; not a whole-branch review of the later final tree; sha256=339dc781749e5de9f2adf29c0ec3a5138ec18e3ec21937699d93cf43a9018a6e; retained=docs/audits/evidence/v0.4.6.0-b10/task7-whole-branch-r4-repair-independent-closeout.md
600-
- kind=file_sha256; source=Task 11bi rejected predecessor repair tree 2e6d34ebfee35d0c0cb15052666966f2fcd95eb0; Task 11bj owner report sha256 ce6cb5f9e3a96da211be5915802edcfb91191e066fca17cb591f16ef4f5a8da8 and Task 11bk independent APPROVE sha256 9d5c056a0a57e8de23af58f06c5934c51c729f921eb663b3ec288a00a8ec61eb bind exact repaired strict-JSON, mixed-terminal replay, execution-tooling, predispatch, and timeout contracts; Task 11cg ANDON 150 current-byte repair preserves the governed provider-cost-unavailable aggregate during live post-observation failure terminalization; sha256=3b872484bb9d1b91d471492aaf0365cead5178ffce9c6bbf4f6858195a4c6a6e; retained=tools/reviewed_campaign_orchestrator.py
600+
- kind=file_sha256; source=Task 11bi rejected predecessor repair tree 2e6d34ebfee35d0c0cb15052666966f2fcd95eb0; Task 11bj owner report sha256 ce6cb5f9e3a96da211be5915802edcfb91191e066fca17cb591f16ef4f5a8da8 and Task 11bk independent APPROVE sha256 9d5c056a0a57e8de23af58f06c5934c51c729f921eb663b3ec288a00a8ec61eb bind strict-JSON, mixed-terminal replay, execution-tooling, predispatch, and timeout contracts; Task 11cg ANDON 150 preserves governed provider-cost-unavailable settlement; Task 11cl ANDON 153/154 current bytes reconstruct exact completed receipts and terminal projections from retained adapter results plus original execution custody after projection failure and consume attempt authority through one atomic recoverable claim set; Task 11cn ANDON 155 makes publication and replay share one exact phase/classification/failure-class contract for mixed projection failures; Task 11cp ANDON 156 keeps pre-dispatch classification through the final live authorization and tooling rechecks and crosses into provider execution only immediately before the first submit; Task 11cu/11cv ANDON 159 current bytes treat the immutable attempt claim set as canonical after projection collision or persistent absence, retain ordered EXACT/COLLISION/MISSING projection states, preserve foreign bytes, terminalize without dispatch, and revalidate exact replay; sha256=d643fe9fa7f729bb0e7f85b7d84ceede98ee0a5716e8a909e3991cd1cfc9c5b5; retained=tools/reviewed_campaign_orchestrator.py
601601
- kind=file_sha256; source=Task 11bk independently accepted predecessor live-adapter sha256 0d357768608eae2e6bc0b3c73d1af5846bba7abce855347daf79ab1f2fdad2af; Task 11bv current ANDON 145/146 owner repair preserves those joins while making capability metadata-only and secret-free and binding destructive directory cleanup to an immutable create-once ownership witness; this row binds exact current bytes only and does not claim provider invocation, independent successor acceptance, exact-SHA CI, candidate maturity, or terminal closure; sha256=d92a131195201b634682baca8d2d6b9d4795c1bd569c863284be7605ef11843d; retained=tools/codex_live_producer_adapter.py
602602
- kind=file_sha256; source=Task 11bk reconfirmed the inherited exact Windows suspended-launch Job Object custody, stable-handle membership verification, governed timeout teardown, and zero-active-member readback bytes; no PID-ancestry or taskkill fallback; sha256=f769d96653aefc8b7e6e89fffc55979f57e9a0b1610000aaebf3abb6e90a2461; retained=tools/run_local_ci.py
603603
- kind=command_result; source=Task 11bv current ANDON 145/146 owner verification; exact current live adapter sha256 3a099b84c09443eaa214bafc6f0f3c149cc9e79c69c794ed4e7c048ef1a85d68, unchanged orchestrator sha256 d86aba11c685aacd48002ea5dc4904fa3bf5b49cc61bd82576a5e7112d21eea9, and reviewed-campaign test sha256 6535adfe42e0242430d8f496be2ef6aa5e8176bd40fdc9e52cce4bb01e807fde; full reviewed-campaign suite is 91/91 GREEN including metadata-only secret-free capability, deferred credential acquisition after authority and reservation, immutable directory-witness replacement custody, strict non-finite admission/rederivation, exact mixed-receipt replay, five-way barrier, and zero-dispatch replay; command=python -B tests/reviewed-campaign-orchestration/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the local durable Task 11bv owner record are not tracked repository artifacts; bounded deterministic acceptance does not imply independent successor acceptance, provider execution, final whole-branch acceptance, or terminal closure
604604
- kind=command_result; source=Task 11cg current ANDON 150 test-first repair; reviewed-campaign orchestrator sha256 3b872484bb9d1b91d471492aaf0365cead5178ffce9c6bbf4f6858195a4c6a6e and permanent test sha256 5995e364efb462c7dd9b0463080fdcbc8ea6a8b33a73ac79cceaa9cb0f8c3a66; the production-shaped live post-observation fault now preserves the governed provider-cost-unavailable aggregate, closes all five exact reservation members, and publishes the incident and terminal finalizer without weakening fake zero-cost behavior; full reviewed-campaign contract is 96/96 GREEN; command=python -B tests/reviewed-campaign-orchestration/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the ignored Task 11cg owner record are not tracked repository artifacts; bounded focused acceptance does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure
605+
- kind=command_result; source=Tasks 11cl/11cn/11cp current ANDON 153-156 test-first repair; reviewed-campaign orchestrator sha256 e89c40983a4a5c98b0e67040bff059230d379bb73712f668ef893e70ea456b7d and permanent test sha256 577ce028ccc791356ecc7ebd5a3ffe121754b55d07bf62165fa5ac12abb6f2f2; all ten all-completed live result/provider-receipt publication positions close five completed paid attempts without replacing foreign bytes, initial and retry claim projection failures terminalize from one atomic attempt claim set, interrupted exact claim sets recover without redispatch, the cold-review shared boundary is directly covered, mixed four-completed/one-outcome-unknown result and receipt projection failures settle exactly and replay without redispatch through one shared failure-state contract, and a fourth-load final pre-submit authorization drift proves five not-dispatched calls with zero host starts and exact replay; full reviewed-campaign contract is 106/106 GREEN; command=python -B tests/reviewed-campaign-orchestration/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the ignored Task 11cl/11cn/11cp owner records are not tracked repository artifacts; focused GREEN does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure
606+
- kind=command_result; source=Task 11cw current ANDON 159 test-first repair; reviewed-campaign orchestrator sha256 d643fe9fa7f729bb0e7f85b7d84ceede98ee0a5716e8a909e3991cd1cfc9c5b5 and permanent test sha256 9d244d75e3f0d121db6009a93e9a973bf66c11922d7f3ebe3dd2f5359e2ca8a7; six initial/retry/cold-review foreign or persistently missing claim-projection subcases terminalize from the exact immutable claim set with ordered EXACT/COLLISION/MISSING states, preserve foreign bytes, retain no-dispatch evidence, and replay without redispatch; direct canaries are 4/4 GREEN, ten claim-set/projection/replay neighbors are 10/10 GREEN, and the full reviewed-campaign contract is 110/110 GREEN; command=python -B tests/reviewed-campaign-orchestration/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the ignored Task 11cw owner record are not tracked repository artifacts; focused GREEN does not imply independent repair acceptance, exact-tree deterministic closure, exact-SHA CI, candidate maturity, provider execution, or terminal closure
605607
- kind=command_result; source=Task 11bj owner verification after Task 11bk acceptance; current tooling-bound capture schema sha256 e0616acb1ff645c31e21a766b99f9671c6c3e652150926ef1acc37901b48a859, bridge sha256 6f5416c4170f5c0e9b848a70895d50d2549a5668d88892e589d4bf1de3c400af, and permanent test sha256 66513599523fc762f8e079c4f3330ef5e65b2f1115338935409fad54815483db; 2/2 GREEN including valid execution-tooling manifest fixture custody and exact result/captured-output/provider-subject identity; command=python -B tests/producer-capture-finalization/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the local durable owner record are not tracked repository artifacts; exact-current per-case bridge bytes remain within A16 PARTIAL pending fresh deterministic and whole-branch review
606608
- kind=command_result; source=Task 11br ANDON 144 owner verification after bounded independent acceptance; current aggregate schema sha256 7940b0c37441e79d8e55bca92662b9045ca333e6b34a46bff05e6cd78311c732, tooling-bound promoter sha256 579715d8417af03e2f8adcafa495911dcab204dc7a25631efa5d1663e76b4339, and permanent test sha256 079f3f0346978f6b75322f065d195e8352a080ca4cc696e076cdbf017c12783f; registered producer-structural suite is 17/17 GREEN including Linux same-inode rollback custody, tooling canaries, scripted/test finalizer barrier, and shallow-fabrication rejection; command=python -B tests/producer-structural-completion/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and local durable review records are not tracked repository artifacts; bounded structural acceptance is not campaign, candidate, release, or terminal closure
607609
- kind=command_result; source=Task 11v Branch 11 Task 7 namespace owner report sha256 3cd7e18d25625ea0090bd5b7c687ad6e01c51190634c820199f68432d55c5628; schema sha256 4f578bbdbd2a71b978e4508b344b500c4710cffe24d14eda88d7345862ed008e, checker sha256 5d324874cdeb5d1d6ef9ab95881def50adb3f3cc7264c278aebc85e13220d311, and test sha256 7858272da46ac5e49d6298cf782ed2af2136124f29e1f50a9a92ba381b835e17; versioned Branch 10 and Branch 11 namespaces are disjoint and independently 14/14 GREEN; command=python -B tests/task7-deterministic-evidence-namespace/test_contract.py; exit=0; unretained_reason=raw stdout and stderr and the local durable owner report are not tracked repository artifacts; final generated Branch 11 cohort remains pending the final source freeze

0 commit comments

Comments
 (0)