RQ-60-FLIPCOUPLE (#1064): status-evidence gate — a release status must agree with the evidence on main; seven-instance replay 7/7 - #1076
Merged
Conversation
… must agree with the evidence on main Seven measured instances across v0.59/v0.60 (six stale-proposed over shipped code, one premature implemented over an unmet definition of done) share one substitution: 'the PR merged' read as 'the artifact's stated outcome holds'. The gate makes each landing say which claim it is making, and checks what can be checked: - R0: a release file contributing ZERO artifacts is red — the #1064 invisible-file shape itself (at the moment of the three v0.59 misses the file was unreadable, so the stale statuses inside were unfalsifiable). - R1: every artifact >= v0.60 declares done-when (contains:/file:/manual:). - R2 (over-report): a claiming status whose evidence is absent is red; a manual: done-when under a claiming status requires a written verified-by basis — the reverted RQ-60-VFPPRESSURE flip had none. - R3 (under-report): a non-claiming status whose declared evidence EXISTS is red — the only rule that catches work shipped under a different program id (RQ-60-CANARY landed as 'VCR-TIER-001 increment 1'). - R4: an id-first delivery commit must be acknowledged — status flipped, or the PR recorded in fields.landed ('increment landed, outcome not yet held'). Anti-vacuity: duplicate-key-strict YAML loader (#1059 class), a pinned delivery-commit floor (28) so a shallow checkout reds instead of scanning nothing, and a committed seven-instance replay suite reconstructed from the real historical states (d656fb8, e1a7b57, f1e2e7b, 3267e0d, f8036ec, e6a3b27, the reverted flip). Mutation-verified: 8/8 rule-disabling mutants kill the suite. The replay also surfaced two UN-tabulated instances of the same class (RQ-59-POPCNT stale at d656fb8, RQ-59-I64SHIFT stale at e1a7b57) — the measured seven were an undercount. Stated residuals: work landing with no artifact and no id-first subject is invisible (unknown-id delivery subjects warn); a false verified-by basis passes — the gate forces the basis to be written, it cannot judge it. Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
…cknowledge #1073; RQ-60-FLIPCOUPLE is implemented - RQ-60-CANARY / RQ-60-A64IMPORT / RQ-60-CFOBLIG / RQ-60-FLIPCOUPLE carry in-repo signatures (contains: predicates on their delivered/planned surfaces); CFOBLIG's (WasmInstructions.v gains BrIf) is deliberately FALSE today and flips the moment the model extension lands. - RQ-60-RACOST / RQ-60-ARTIFACTSPLIT / RQ-60-WCETKEY / RQ-60-VFPPRESSURE are honestly manual: their definitions of done are measured verdicts or external runs with no single in-repo signature — for these, Direction-A protection rests on the delivery-commit floor, and any future implemented flip must carry a written verified-by basis. - RQ-60-VFPPRESSURE gains landed: '#1073' — the machine-readable statement 'increment 1 landed, the stated outcome (5-of-5 cascade stages) does not yet hold', which is the distinction the seven misses collapsed. - RQ-60-FLIPCOUPLE proposed -> implemented, with the delivered mechanism, its replay result, and its stated residuals recorded in the description. rivet validate: error set byte-identical to baseline (40, all foreign-prefix cross-repo); rivet list: 473 artifacts, unchanged — floor untouched. Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
…e required Claim Check job (#1064) fetch-depth: 0 on the job's checkout — the delivery-commit scan needs first-parent history, and the gate's in-script floor (28) turns a shallow checkout into a red rather than a vacuous pass. Verdict re-derived from the summary line the gate WROTE (non-empty populations, zero failures), not from exit 0 — the pipefail lesson from the oracle-wiring step applies unchanged. Lives in the already-required job for the standing reason: a brand-new job is not a required context on main, so it could sit red blocking nothing. Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
…why NOT `verified` #1075 merged as 0ec9dc7 and did not flip its own status. SEVENTH instance of the class this session; #1076 (the status-evidence gate) is what makes this mechanical instead of dependent on me remembering. `implemented`, NOT `verified`, and the distinction is the point. The artifact's DoD says those symbols reach `nm -> T` **IN THE FUSED IMAGE**. What I verified, against the REAL ghcr components at 1.134.1 on cortex-m7dp — jess's flight core — with the failure established on main FIRST: iekf / position / attitude main exit=1 SKIPPED -> branch exit=0 rate / mixer already compiled, unchanged attitude#tick, position#tick reach `nm -> T` at 00000138 That is 5 of 5 PER-STAGE. The fused-image run has NOT happened — our local meld predates `fuse --pack-rebase` — and the rescued functions' correctness evidence is the fixture differential on the same code path (70/70 bit-identical vs wasmtime), not an executed attitude/ekf run. Earlier this session I flipped this same artifact to `implemented` PREMATURELY, reading "the PR merged" as "the stated outcome holds". The correction is not to flip more cautiously by feel — it is to use rivet's lifecycle for what it is: `implemented` = the code is in; `verified` = the evidence closes. jess's standing offer covers the fused image, INCLUDING if the answer is that it is worse on target. The reasoning is recorded NEXT TO THE DoD rather than only in this message, so the next person reading the artifact sees why the status stops where it does. v0.60: 3/8. Verified BY ID; CI-filter OURS=0; measured 473 = floor 473; claim_check exit 0. Refs #1069, Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
…MY flip #1076 landed the status-evidence gate, and on its first encounter with me it fired R2 on this very flip: FAIL R2 RQ-60-VFPPRESSURE: status `implemented` on a `manual:` done-when with no `verified-by` — 'the PR merged' is not 'the stated outcome holds'; write the basis down It was right. My flip WAS justified — I verified 5/5 against the real ghcr components — but I wrote that reasoning as PROSE in a status note beside the DoD, where no machine can read it. A human-readable caveat and a machine-checkable claim are not the same artifact, and the gate exists to collapse that gap. The basis is now in `verified-by`, stated so it can be DISPUTED rather than trusted, and deliberately not overstated — the gate forces the basis to be written and cannot judge it, so inflating it here would defeat the mechanism I just commissioned: * per-stage, NOT fused: real ghcr components at 1.134.1, failure established on main FIRST, then the same bytes on the branch at -t cortex-m7dp — iekf/position/attitude exit=1 SKIPPED -> exit=0, rate/mixer unchanged, attitude#tick and position#tick at `nm -> T` 00000138 * mechanism soundness is the fixture differential on the same code path (70/70 bit-identical vs wasmtime), NOT an executed attitude/ekf run * THE FUSED-IMAGE RUN THIS done-when NAMES HAS NOT HAPPENED — local meld predates `fuse --pack-rebase`; jess holds that evidence under their standing offer, and `verified` waits on it INCLUDING if the answer is worse on target status-evidence exit 0, claim_check exit 0, CI-filter OURS=0. Refs #1069, Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L
avrabe
added a commit
that referenced
this pull request
Aug 27, 2026
…ied, and why it stops short of `verified` (#1077) * chore(rivet): RQ-60-VFPPRESSURE implemented — 5/5 falcon stages, and why NOT `verified` #1075 merged as 0ec9dc7 and did not flip its own status. SEVENTH instance of the class this session; #1076 (the status-evidence gate) is what makes this mechanical instead of dependent on me remembering. `implemented`, NOT `verified`, and the distinction is the point. The artifact's DoD says those symbols reach `nm -> T` **IN THE FUSED IMAGE**. What I verified, against the REAL ghcr components at 1.134.1 on cortex-m7dp — jess's flight core — with the failure established on main FIRST: iekf / position / attitude main exit=1 SKIPPED -> branch exit=0 rate / mixer already compiled, unchanged attitude#tick, position#tick reach `nm -> T` at 00000138 That is 5 of 5 PER-STAGE. The fused-image run has NOT happened — our local meld predates `fuse --pack-rebase` — and the rescued functions' correctness evidence is the fixture differential on the same code path (70/70 bit-identical vs wasmtime), not an executed attitude/ekf run. Earlier this session I flipped this same artifact to `implemented` PREMATURELY, reading "the PR merged" as "the stated outcome holds". The correction is not to flip more cautiously by feel — it is to use rivet's lifecycle for what it is: `implemented` = the code is in; `verified` = the evidence closes. jess's standing offer covers the fused image, INCLUDING if the answer is that it is worse on target. The reasoning is recorded NEXT TO THE DoD rather than only in this message, so the next person reading the artifact sees why the status stops where it does. v0.60: 3/8. Verified BY ID; CI-filter OURS=0; measured 473 = floor 473; claim_check exit 0. Refs #1069, Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L * chore(rivet): write down the verified-by basis — the new gate caught MY flip #1076 landed the status-evidence gate, and on its first encounter with me it fired R2 on this very flip: FAIL R2 RQ-60-VFPPRESSURE: status `implemented` on a `manual:` done-when with no `verified-by` — 'the PR merged' is not 'the stated outcome holds'; write the basis down It was right. My flip WAS justified — I verified 5/5 against the real ghcr components — but I wrote that reasoning as PROSE in a status note beside the DoD, where no machine can read it. A human-readable caveat and a machine-checkable claim are not the same artifact, and the gate exists to collapse that gap. The basis is now in `verified-by`, stated so it can be DISPUTED rather than trusted, and deliberately not overstated — the gate forces the basis to be written and cannot judge it, so inflating it here would defeat the mechanism I just commissioned: * per-stage, NOT fused: real ghcr components at 1.134.1, failure established on main FIRST, then the same bytes on the branch at -t cortex-m7dp — iekf/position/attitude exit=1 SKIPPED -> exit=0, rate/mixer unchanged, attitude#tick and position#tick at `nm -> T` 00000138 * mechanism soundness is the fixture differential on the same code path (70/70 bit-identical vs wasmtime), NOT an executed attitude/ekf run * THE FUSED-IMAGE RUN THIS done-when NAMES HAS NOT HAPPENED — local meld predates `fuse --pack-rebase`; jess holds that evidence under their standing offer, and `verified` waits on it INCLUDING if the answer is worse on target status-evidence exit 0, claim_check exit 0, CI-filter OURS=0. Refs #1069, Refs #1064 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refs #1064. Delivers RQ-60-FLIPCOUPLE: a mechanical coupling between "the code landed" and "the artifact says so", replayed against all seven measured misses.
Which shape, and why
A composition of shape 1 and shape 2, enforced per shape 3 — chosen deliberately because the seven instances split across what any single shape can see:
nm -> Tcensus on a meld-fused ghcr cascade — not buildable in-repo). So evidence is declared per artifact (fields.done-when:contains:<path>:<literal>|file:<path>|manual: <reason>) and checked in both directions. The negative result the task anticipated is real and is encoded rather than papered over: 4 of 8 v0.60 artifacts are honestlymanual:, and a claiming status on amanual:predicate requires a writtenverified-bybasis.proposed) is the workhorse for the other five Direction-A instances: this repo's measured convention is that a delivery commit's subject starts with the artifact id (28/28 on main; plan/chore/salvage commits never do). Such a commit must be acknowledged: status flipped, or the PR recorded infields.landed— the machine-readable statement "increment landed, the stated outcome does not yet hold", which is exactly the distinction the seven misses collapsed.The rules (
scripts/status_evidence_check.py)done-whenimplemented/verified/accepted) with absent evidence, ormanual:with noverified-bylanded:)Anti-vacuity: duplicate-key-strict YAML loader (the #1059 class — the gate must not validate with the parser that cannot see that defect); a pinned delivery-commit floor (28) so a shallow checkout reds instead of scanning one subject; CI re-derives the verdict from the summary line the gate wrote, not from exit 0.
fetch-depth: 0added to the Claim Check checkout for the history scan.Seven-instance replay — 7/7 flagged
Reconstructed from the real repo states (
git show <merge>:artifacts/..., real first-parent subject histories), run through the gate as landed.--delivery-floor 1because the anti-vacuity floor is calibrated to today's history; CI never lowers it. Full transcript in the collapsible below.proposedin 3267e0d)done-whenthis PR introducesimplementedmanual:done-when, noverified-byInstance 4's caveat, stated: its catch depends on the
done-whendeclaration that did not exist then. The replay therefore answers "would the mechanism, as landed, have flagged it" — had the mechanism existed, R1 would have forced the declaration into the plan PR that created the artifact.The replay also surfaced two instances nobody tabulated — the measured seven were an undercount: RQ-59-POPCNT was still
proposedat d656fb8 with #1039 merged, and RQ-59-I64SHIFT stillproposedat e1a7b57 with #1054 merged (both verified againstgit show; both later hand-flipped in plan/chore commits). Same class, same substitution.Replay transcript (literal, per instance)
Red-first, on the current tree
Replay [7] above is the red demonstration for the opposite (over-report) direction, run on the current tree with only the status forced.
The checker is itself checked:
scripts/test_status_evidence_check.py(15 tests, wired as a CI step) pins all seven replays as fixtures re-proven every run, plus green controls for every fix. Mutation-verified: 8/8 rule-disabling mutants (R0/R1/R2×2/R3/R4/dup-key/vacuity-floor) each kill the suite. Two earlier string-renaming mutants survived — because the mutants were weak, not the tests; they were replaced with real rule-disabling ones.What the mechanism does NOT cover
manual:done-when under a non-claiming status cannot fire R3 — for RACOST / ARTIFACTSPLIT / WCETKEY / VFPPRESSURE, Direction-A protection rests entirely on R4's subject convention. A delivery commit titled differently evades it — a miss, never a false red.verified-bybasis passes. The gate forces the basis to be written where the release query's reader can see it; it cannot judge it. That residual is exactly as manual as the artifact declared it to be.Gates
python3 scripts/claim_check.py claims.yaml→ exit 0 (51/51 hold)python3 scripts/oracle_wiring_check.py→ exit 0cargo fmt --all --check/cargo clippy --workspace --all-targets -- -D warnings/cargo test --workspace→ all exit 0 (no Rust touched)rivet validate: error set byte-identical to baseline (40, all foreign-prefix cross-repo — the class CI exempts); the newdone-when/landedfields land in the same unknown-field INFO class as the existingissue:/verification-track:(63 pre-existing INFOs forissuealone).rivet list: 473 artifacts, unchanged — no new artifacts, floor untouched. Checked by id:rivet validate --explain RQ-60-FLIPCOUPLE.set -o pipefail.scripts/repro/additions — both scripts are gate tooling inscripts/(claim_check precedent), so themanualceiling (at 8) is untouched.🤖 Generated with Claude Code
https://claude.ai/code/session_01YJK5LZZEkV5smCY1jKn18L