Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,13 @@ build recorded staging telemetry that never reached its repo
publishes without the flag. Never publish or promote artifacts as a side
effect of another task.

A US release or release-gate preflight that receives a multispine pool through
`--base-h5` must authenticate its sibling terminal manifest. A current stacked
pool whose terminal battery is red remains fail-closed unless the operator
passes `--allow-gate-failed-base-pool`; that opt-in carries the full red verdict
into `release_manifest.json` for a separate human publication decision. It does
not weaken the exact-k manifest arm or authorize publication by itself.

## Root journals are history, not state

The root `PROGRESS*.md`, `FINAL_REPORT.md`, `*_COVERAGE_PROGRESS.md`, and
Expand Down
128 changes: 77 additions & 51 deletions PROGRESS.md
Original file line number Diff line number Diff line change
@@ -1,63 +1,89 @@
# Progress: stacked-pool to release CD-vintage provenance
# Gate-failed base-pool release lane

## State

Implementation and validation are complete. The stacked
producer now authenticates and applies household geography after source
assembly, carries its authority through checkpoint and publication identities,
publishes verified CD-vintage H5 attributes, and reaches the unchanged release
guard through the shared fixed/table-aware reader
(`tools/build_us_multispine_pool.py:814-928,1300-1469,1857-1930,5290-5334`;
`packages/microcosm-build/src/microcosm/build/us_runtime/h5_io.py:1032-1193,1463-1699`;
`tools/build_us_fiscal_refresh_release.py:2565-2677`).

No pool/release build, push, guard weakening, operator-boundary weakening, or
`logbook-pending-chain.txt` access has occurred.
Complete on 2026-08-26. Containment, opt-in carriage, and preflight surfacing
are implemented and fully verified. The implementation rejects both redundant
green-pool waivers and any release-manifest receipt that does not exactly match
the pool authenticated by preflight; the preflight's historically required
base/selection inputs and exit semantics are unchanged. No pool or release was
built, no artifact was published, and nothing was pushed.

## Done

- Reconciled the worktree with salvage commit `ca26ea21`: its tracked tree was
already exactly present, so the best salvage was retained and audited rather
than reimplemented.
- Completed the required all-package US environment sync from the exact lock
using the writable offline uv cache after the managed sandbox refused the
default cache.
- Added the two required pinned geography authority pairs, the ledgered seeded
PUMA-overlap assignment, schema-12 checkpoint identity, assignment receipts,
schema-9 terminal manifest validation, and schema-3 H5 materializer binding.
- Added atomic nullable-H5 root-attribute write/verification and authenticated
manifest-to-H5 geography/clone-lineage validation.
- Made release preflight read root attributes and fixed household frames in one
`HDFStore` handle while retaining all existing SHA, target-vintage, and
positive-support checks.
- Added a real tiny stacked-pool publication to release-preflight integration
test plus negative attr, digest, missing-lineage, and divergent-clone tests
(`packages/microcosm-build/tests/test_us_multispine_pool_tool.py:2279-2335`;
`packages/microcosm-build/tests/test_us_multispine_pool_h5_io.py:1357-1440`).
- Regenerated and checked the US anti-rot chain: spec SHA
`5378bb9189aec96f50da22aac71e5bd2c3d919e9795f6ef2147e0bc9c739dd8e`,
42,120/42,120 configuration fields, 49 claims, and 41/41 inventory checks.
- Passed the complete accepted workspace suite: 7,241 passed, 77 skipped, and
0 failed. The two memory-bounded build partitions were 4,155 passed / 36
skipped and 2,177 passed / 3 skipped; calibrate, data, fit, and frame account
for the remaining 909 passed / 38 skipped.
- Passed repository-wide Ruff, bundle freshness, coverage freshness, smoke
script syntax, and `git diff --check`.
- Recorded the exact candidate Stage-1 path/SHA additions and the checkpoint
invalidation verdict in `_LANE-NOTES.md` and `FINAL_REPORT.md`.
- Confirmed the assigned branch and worktree.
- Recorded the v2 charter: close the legacy bare-H5 multispine bypass, add an
explicit release-build opt-in, carry the authenticated red verdict, and
surface it in publication preflight without making it an automatic
publication failure.
- Confirmed that no network, artifact builds, publishing, or pushes are in
scope.
- Traced the strict manifest loader, current stacked-only terminal-failure
exception, H5 identity stamp, pool sidecar naming, legacy release arm,
release manifests, and both preflight output modes.
- Reviewed the salvage branch's final source and test diff line by line. Its
shared classifier/path-binding/receipt approach closes the bypass without
changing either loader's contract and was retained with the subsequent
coherence corrections recorded below.
- Completed the `simulation_ready` / `gate_failed` / loader consumer audit.
Exact-k remains deliberately strict and head-to-head scoring remains the
existing authenticated evidence exception.
- Identified report-only downstream caveats: stacked producer metadata still
names only the k-ladder readiness consumer; red pool publication returns
status 1 and stops shell chains; ACS-local derivatives keep a donor revision
but do not project the nested red verdict; generic release consumers tolerate
and ignore the additive receipt.
- Added a release/preflight-specific authenticated pool loader over the shared
`require_simulation_ready` seam. The strict simulation-ready and existing
scoring-only loader contracts remain unchanged.
- Closed the bare-H5 path by detecting either the canonical sibling manifest
or the H5's stamped pool identity, requiring the sidecar, authenticating the
publication triple, and binding it to the exact requested H5 path.
- Added `--allow-gate-failed-base-pool` only to the legacy `--base-h5` arm.
It admits only a current authenticated stacked `gate_failed` pool, rejects a
green or non-pool use, and never affects the exact-k arm.
- Added the self-contained `base_pool` receipt to both manifests, including
status/readiness, immutable pool identities, flag use, gates JSON SHA-256,
failure count/list, and the complete terminal verdict.
- Kept the static preflight inputs mandatory, authenticated its base identically,
displayed red evidence prominently without changing its exit calculation,
and required optional release-manifest carriage to match the authenticated
receipt exactly.
- Hardened carried verdict normalization so nested pass/failure pairs and the
aggregate verdict must be coherent and a red battery cannot report zero
failures.
- Passed focused Ruff and the complete builder/H5/preflight test files after
the containment changes.
- Passed the broader exact-k, launcher, release-contract, and publish-guard
regression suites.
- Passed repository-wide Ruff and the CI test-group inventory verifier.
- Passed every pytest shard in its own process: build 6,545 passed / 45
skipped; calibrate 203 passed; data 318 passed / 2 skipped; fit 93 passed;
frame 295 passed / 36 skipped. Aggregate: 7,454 passed, 83 skipped.
- Confirmed `git diff --check` is clean and that no battery bounds,
tolerances, plans, or terminal gate logic changed.
- Wrote the complete handoff, consumer audit, manifest schema, verification
receipts, and commit inventory to `out.md`.

## Next

1. Candidate Stage 1 adds both authenticated geography authority pairs and
rebuilds under checkpoint materializer 12.
2. Candidate Stage 2 consumes the new schema-9 manifest/materializer-3 H5 and
passes the unchanged release preflight.
3. Do not reuse pre-fix Stage-1 checkpoints or pool publications; immutable
source artifacts remain reusable.
- Human review and merge of `release-from-gate-failed-pool`.
- Any later artifact operation remains separate: an operator must deliberately
choose the red-pool flag, then run publication preflight and make the human
publication decision. This lane performed none of those operations.

## Historical prior lane

The PolicyEngine-US 1.819.0 lock-bump journal previously in this file is
historical: that lane merged into `origin/main` at `7b90bb18` on 2026-08-24.
Its final state remains available at commit `05d254aa` and its detailed
receipts remain in the historical section of `_LANE-NOTES.md`.
The stacked-pool-to-release CD-vintage provenance lane previously maintained
this journal and completed before this work began. It authenticated and
applied household geography after source assembly, carried that authority
through checkpoint and publication identities, published verified CD-vintage
H5 attributes, and reached the unchanged release guard through the shared
fixed/table-aware reader. Its final verification was 7,241 passed, 77 skipped,
with repository-wide Ruff and anti-rot checks green. Full details remain at
commit `2263df36` (the parent of this lane's first journal commit).

The still-earlier PolicyEngine-US 1.819.0 lock-bump lane merged into
`origin/main` at `7b90bb18` on 2026-08-24; its final state remains at commit
`05d254aa` and its detailed receipts remain in the historical section of
`_LANE-NOTES.md`.
1 change: 1 addition & 0 deletions changelog.d/gate-failed-pool-release.fixed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Close the US fiscal release and release-gate preflight bypass that treated a bare multispine ``--base-h5`` as a generic H5 without authenticating its terminal manifest. ``--allow-gate-failed-base-pool`` now explicitly admits only an authenticated current stacked ``gate_failed`` pool, carries its full red battery receipt under ``build.base_pool``, and surfaces that evidence prominently for a separate human publication decision without changing other preflight exits.
Loading
Loading