Skip to content

P2: Gate Python claims and publish on the exact proven candidate #275

Description

@tomdps

Parent

Tracking parent #251; epic #243. This is one vertical delivery slice. Do not close or bypass the parent tracker from this child.

Goal

Authorize public wording and release only from same-commit matrix, package, platform, provenance, and real-repository evidence.

Dependency contract

Required behavior

  1. Freeze the candidate SHA and require it to equal every child artifact source SHA, checkout HEAD, workflow_run head SHA, aggregate SHA, and prerequisite receipt SHA; bind tree ID, workflow run/attempt, matrix/audit digests, tarball integrity, installed files, descriptors, ASP manifest, and managed artifacts by checksum.
  2. Make publish consume the retained CI-tested tarball or prove byte identity; repacking unbound bytes is forbidden. Store authoritative candidate receipts as immutable CI/release artifacts keyed by SHA.
  3. Render/audit README, quickstart, concepts, examples, demo, agent integration, package copy, CLI help/JSON manifests, descriptors, release notes, and roadmap wording against proven capability IDs/states.
  4. Reject unqualified Python parity/full-support or positive Windows claims without matching cells; preserve experimental/degraded-honest and Windows-unsupported wording unless separate evidence and explicit policy change it.
  5. Run package/provenance/cutover/claim/fallback gates and retain no ASP-standard, old-tool replacement, security/SAST, all-stack, AI-authorship, automatic-fix, or blended-score claim.
  6. Maintainer/subagent-owned. Do not launch Zeroshot unless the user explicitly re-delegates this slice after its JIT review.

Acceptance criteria

  • Every child receipt and published/retained artifact has the same exact source/package identity; stale SHA, changed bytes, missing platform row, forged command, undeclared network/install, or provenance drift fails.
  • Every public/runtime surface agrees with the ledger and representative-repo audit; unsupported cells remain visible.
  • All release gates and local CI-equivalent proof pass; P2 — Ship honest Python readiness, setup, receipts, and cross-platform cutover #251 closes only after the evidence index links every prerequisite/child.

Observable outcomes

  • Clean success carries positive execution/provenance evidence; zero diagnostics alone is never proof.
  • Findings and every unavailable/invalid/timeout/crash/resource/stale/unsupported state are machine-readable and fail or degrade exactly as the capability contract says.
  • No implicit fallback, partial result, or skipped execution is reported as a pass.
  • Target source, configuration, lockfiles, environments, and caches remain unchanged except where this issue explicitly owns a validation-gated atomic edit; every temporary resource/process is cleaned.

Non-goals

  • fixing functional defects discovered here
  • docs-first readiness
  • old-tool retirement
  • automatic release announcement

Verification

Run focused behavior first, then the configured repository proof only after the acceptance matrix works:

  • npm run build
  • npm run lint
  • npm run pack:check
  • npm run release-receipt:check
  • npm run cutover:check
  • npm run provenance:check
  • bash ./scripts/ci/run-local-ci-equivalent.sh
  • all platform/audit/claim validators
  • Attach exact real-tool/artifact versions, argv/config/cwd/source, normalized result examples, before/after cleanliness evidence, and packed-install proof where the slice changes public package behavior.

Execution rule

Implement only after a just-in-time review against current dev. Keep exactly one implementation run active. PR base is dev; require green checks, clean scoped diff, merged PR, closed child, parent checklist update, focused reproductions, and opcore-ci proof before starting the next child. Do not claim Python readiness/parity, ASP authority, old-tool replacement, security/SAST, all-stack support, automatic fixes, or a blended score.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestrelease-blockerBlocks the 0.1.0-alpha.0 release

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions