Repository navigation
Conversation
… must be green on the tag (PMAT-4687) publish_strict.sh accepted any non-empty cleanroom-run-id file. It now reads the recorded run back and judges it with the cascade's own clean_room_gate, pinned to that one run: a missing, empty, non-numeric, unreadable, red or other-commit run id stops the cascade before any upload. --plan is unchanged. clean_room_gate gains an optional third argument, a recorded run id. Pinned mode reads exactly that run through the runs API, refuses a run of another workflow, and never lists runs, so a green run elsewhere cannot stand in for a red recorded one. Falsifier: scripts/check_publish_strict_cleanroom.sh runs the real publish_strict.sh against a fixture tag checkout and stub gh/cargo. On origin/main 645dc34 it fails 8 of 9 checks; here 9 of 9 hold. check_cascade_clean_room_gate.sh gains 10 pinned rows. Contract: PW-DOOR-005 + FALSIFY-PUB-008 (pv validate: 0 errors). Agent: aprender-cd Refs: #4687 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
§13.11 rung 1 — quorum shadow verdict Shadow mode: this records a verdict and merges nothing. A refusal |
…d wiring, roadmap aggregate (PMAT-4687) - PW-DOOR-005's formal: line now uses symbols the ontology declares (⇒ ≠ ∅ ∧), so formal_prose stays at the 1464 baseline instead of rising to 1465 (PV-ONT-004, shrink-only). - check_publish_strict_cleanroom.sh carried a bare cargo token in a comment, so the textual classifier filed it as a cargo guard that no workflow runs. The comment is reworded; the guard invokes no build tool and now runs in guard-tree (check_guards_are_wired.sh: PASS, unwired stays 3). - docs/roadmaps/roadmap.yaml regenerated from the new fragment. Agent: aprender-cd Refs: #4687 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
publish_strict.shis the one door tocargo publish. It used to accept any non-emptycleanroom-run-idfile. It now reads the recorded run back and judges it with the cascade's ownclean_room_gate, pinned to that one run. A run id that is missing, empty, non-numeric, unreadable, red, from another workflow, or green on another commit stops the cascade before any upload.--planis unchanged.clean_room_gategains an optional third argument, a recorded run id. In pinned mode it reads exactly that run through the runs API and never lists runs, so a green run elsewhere cannot stand in for a red recorded one.Proof
scripts/check_publish_strict_cleanroom.sh(runs the realpublish_strict.shwith stubgh/cargo)scripts/check_cascade_clean_room_gate.shpv validate contracts/publish-workspace-v1.yamlThe green row passes the clean-room door and then stops on the next precondition, so no row reaches an upload; the stub
cargofails the table if it is ever called.A planted review round on 1b52a42 returned YES; both lanes caught the plant. 56a84f3 adds only CI follow-ups (ontology glyphs in the new
formal:line, a comment reworded so the new guard runs in guard-tree, the regenerated roadmap), and the round is re-run on it. This is a gate change, so it needs two non-author reviews before merge.Refs #4687
keep-open: #4687 is a multi-row issue and this PR delivers only its row T10; the issue closes when its remaining rows land.
🤖 Generated with Claude Code