Complete the #757 deferrals: the exclusion pass, the measured U8 lever, the release-cut certification, and the re-armed thresholds - #793
Conversation
|
Pre-merge sweep (2026-08-27): exercised the release-cut preflight's two ledger compile-parity gates against the pinned chronicle feed — the one live path this PR's runner had not yet executed — and both failed on register rot accumulated since the June fixtures froze: 13 stale entries (live compilation now matches the fixture: the scotgov council-tax stock bands, SCP spending, three SLC recipient rows) and 13 SLC entries whose kind moved 🤖 Posted with Claude Code |
…ster The 42 dispositions of microcosm#757 issue comment 5427936411 (adjudicated 2026-08-26) land as schema-2 windowed exclusions: 11 top-income 1m+ channel cells, 3 SLC channels, 16 UC payment-distribution cells, the OBR welfare-cap pair, 3 ONS composition cells pending the relationship-to-head column (microcosm#791, filed with this change), 6 sparse HMRC band cells, and obr.fuel_duties. The six UC caseload/two-child-limit cells stay bound for the would_claim_uc lever run; couple_no_children and the marginal state_pension 40-50k cell stay bound to ride the re-run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The seven UC caseload/two-child-limit targets get their adjudicated lever run (uk-data#452): the take-up contract carries a dated 2024 value of 0.85 over the 2015 incumbent-parity 0.55, with the support-arithmetic derivation recorded in the entry. The contract digest moves with the resource; the parity divergence on the rebuilt candidate is signed from its measured extraction in the licensed phase. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…the certification --release-candidate and canonical release ids are refused on the calibration driver (the seam's 6-entry scoped battery can never sign a shippability claim, per the 5413502559 audit); the release_candidate parameter leaves the seam runtime whole, and the build record's hand-written shippable literal is replaced by a pointer to the release-cut certification artifact. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…tification The release-cut battery runs scoped (preflight+terminal) at release-candidate strictness over the calibrated candidate, with evidence adapted from persisted artifacts - the spine sidecar now persists fit-weight records so the weights audit survives the process boundary. The multi-part certification composes the spine, seam, and release-cut reports: union with no gap and no overlap beyond the declared shared id, signed parts over the committed spec's scoped digests, full phase coverage, and a closed identity join down to the candidate bytes. The nine verifier refusal points of the 5413502559 audit move from per-report to per-certification. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
…n in the notes top_k 100 stays the grid anchor; max_top_share re-mints at the exact measured checked-surface maximum (0.9994670564654868, hmrc_spi_other_social_security_income, 104 carriers on spine-a); min_nonzero_records at the thinnest measured column above the anchor (104). The three saturated sub-anchor columns go thin visibly on every run. Gate policy/manifest/fingerprint digests re-cut from the live producer payload; contract threshold mirrors move in lockstep. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The nine refusal points the 5413502559 audit measured against a scoped report resolve at the certification: microcosm-data verifies the composed document - mirrored part scopes, scoped-manifest digest pins, full-manifest spec pins, the union partition, recomputed shippability, the diagnostics join, and the release-key signature - with build-shard sync tests holding every mirror in lockstep. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The pre-registered would_claim_uc raise to 0.85 was built (spine-h, 14/14 signed RC battery), calibrated, and measured against the 0.55 counterfactual on the same exclusion register: every failing UC caseload cell is unchanged (dwp.uc.households -44.9% at both rates, the capital test caps the support gain at +22%) while the raise destroys the legacy housing-benefit surface (obr.housing_benefit -0.0% at 0.55 vs -52.4% at 0.85: claimants move off legacy benefits) and perturbs the QRF predictor surface through engine-computed household_net_income. The contract entry records the run and stays frozen at 0.55; receipts live in the 757-swap acceptance evidence. The binding constraint on UC caseload is capital-test support (microcosm#750), not take-up support. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
spine-i rebuilds the candidate at the follow-up tip: payload-identical to spine-g, battery 14/14 signed at release-candidate strictness, ladder and strict parity green. The Phase-3 seam attempt on it binds 361 targets at loss 0.031 with five of six gates green and blocks, correctly, at uk_target_fit on 13 characterized cells; the certification therefore waits on the UC-family adjudication (microcosm#750 is the real lever) and the exclusion-set-dependence defect (microcosm#792). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
… ships Exercising the release-cut preflight against the pinned chronicle feed found both ledger compile-parity gates failing on register rot: 13 stale entries (live now matches the fixture) and 13 SLC entries whose kind moved when the SLC chronicle waves completed after the June fixtures froze. Regenerated from the feed with the packaged tool - zero entries added, so no unsigned difference was absorbed - and re-verified: both gates pass. The producer's first real preflight will not open on a known-stale register. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
771a6c2 to
58979b7
Compare
The sixteen UC payment-distribution exclusion entries tracked uk-data#452 under the retired package's full name; the live-tree guard (test_no_incumbent_data_package_references_in_live_tree) refused it on the first real CI run, exactly as designed. The sanctioned citation form is uk-data#452 - the same wording ruling #787 applied at 8ff3ff0. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Automated review pass (Claude Code, high effort, diff only — no build or test execution). Four findings, and all four are the same class this lane has been closing all week: a check that reports success without having tested what it names. Given the PR's own framing — "a candidate's shippability verdict comes only from the certification" — that class matters more here than anywhere. 1.
|
…edupe the scoped-battery seams All four findings confirmed in substance and fixed: national-line artifacts without a certification refuse (content-keyed until the canonical national release-id exists), the score cross-pin reads artifacts.candidate.sha256 exactly, malformed fit-weight blocks raise as corruption while empty ones still fail the audit, and the name@period parity grain is enforced loudly (it was already correct - diagnostics label rows name@period - now it is self-evident). The restructure the round invited: one scope-filtering helper with a source parameter, one graft-and-resign helper for every scoped report, public names for the shared seam helpers, digest properties on GateBatteryRun, and the dead zero-caller spine-manifest variant deleted. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Review dispositions (all four findings confirmed in substance; fixed at 1. Certification not required — confirmed, fixed content-keyed. A release directory shipping any national-line gate artifact ( 2. Parity grain — confirmed working as built, now self-evident. The diagnostics writer labels rows at 3. Rehydration — half-confirmed, the real half fixed. The empty-tuple path was deliberate and is not vacuous: the UK weights-audit binding refuses an empty record set ( 4. Score cross-pin — confirmed, fixed exactly as proposed. The check now reads The duplication sweep (María's ask, same commit): one scope-filtering implementation — 🤖 Posted with Claude Code |
…ion required for it microcosm-uk-2024-25-national (ruling 2026-08-27): the id stays fixed across cuts because the Logbook and versioning carry run identity; the vintage segment follows uk-data naming and -national stays disjoint from the exact-k -k<N> shape. The seam refuses the shippable name, the contract requires the certification for it (finding 1's id-keyed layer), and a lockstep test holds the data-shard mirror to the build-shard constant. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Naming ruled and landed ( 🤖 Posted with Claude Code |
vahid-ahmadi
left a comment
There was a problem hiding this comment.
Approving. All four findings fixed at 58829b62 (with the naming ruling at cebc9f50), 23/23 checks green. I checked each fix against the diff rather than the dispositions.
4 — score cross-pin. _verify_score_receipt now reads artifacts.candidate.sha256 and refuses anything else, with the failure message naming both the scored digest and the candidate under certification. This is the one I cared most about: the substring form would have accepted a receipt scored on a different artifact whenever the candidate digest appeared anywhere in the payload, and the check now reads the field that records what was actually measured. The fixture change in test_uk_release_certification.py is the tell — the old green fixture was {"candidate": {"sha256": ...}, "verdict": "scored"}, which the new check correctly rejects, so the test had been passing on a shape the gate could not really authenticate.
1 — certification required. The content-keyed refusal is the right call over the required_release_files() entry I proposed, and for the reason you gave: that rule needs a release-id family to key on, and inventing one mid-PR to satisfy a review comment would have been the worse trade. Refusing any directory that ships release_cut_gates.json, or a terminal_gates.json whose posture is calibration_seam, without the certification covers every directory that carries part of the story today, and the comment records why the id-keyed form is deferred rather than leaving a reader to wonder.
2 — parity grain. My finding was wrong; the fix is still worth having. The diagnostics writer does label rows at name@period, so the sets intersected and the gate compared for real — I read the two key expressions and inferred a mismatch without checking what the writer emits. What you have added is the better outcome anyway: an implicit convention shared across two modules is now a loud refusal, with the message explaining why a bare-name row would fall out of the comparison. That is a real invariant that was previously only a comment on a retired runner.
3 — rehydration. Splitting corruption from emptiness is exactly the right distinction, and I had the two conflated. A non-list stage value or a record missing fit_name / weight_kind now raises UKReleaseCertificationError as corruption, while a genuinely empty per-stage list still returns () so _missing_fit_weight_evidence_gate can fail the audit. Worth restating your framing since it is the part I got wrong: a fitting stage that recorded nothing must fail, not go evidence_absent, and the empty tuple is how that refusal is reached rather than a way around it.
On the duplication sweep. Promoting _scoped_gate_manifest / _resign_gate_report / _aggregate_admin_totals to public names and having one finalize_uk_scoped_gate_report serve both the seam and the release cut is the structural version of the property the old comment only asserted — that the two reports cannot drift apart in shape. Same for GateBatteryRun exposing the digests as properties instead of derivation round-tripping through a signed payload.
Scope of the approval, as before: I reviewed the diff and confirmed CI is green. I did not run the battery, the release cut, or the certification compose, so the digest-identical-by-construction claim is one I have read the reasoning for rather than reproduced.
Completes the deferred pieces of #757 per the follow-up contract (issue comment 5427936411); originally stacked on #787, now rebased onto its merge commit and targeting main. Nine commits, each independently verified (ruff +
ci_test_groups.py --verify+ uk + shared-spec groups; US groups not run — no US file touched).What lands
1. The
uk_target_fitexclusion pass (adjudicated 2026-08-26)42 windowed schema-2 exclusions on the calibration measure-exclusion register (approver +
2026-08-26 → 2026-11-26window, apply-time enforced): the 11 £1m+ top-income channel cells, 3 SLC channels, 16 UC payment-distribution cells, the OBR welfare-cap pair, 3 ONS composition cells pending a relationship-to-head frame column (#791, filed with this PR), 6 sparse HMRC band cells, andobr.fuel_duties(universe scope; the ledger retarget stays chronicle-side, your queue). The register census test pins the class counts and the deliberate non-exclusions.Measured effect (seam on the same spine, 1500 epochs /
family_equal): loss 0.1362 → 0.0309, ESS 5022 → 5916,uk_weight_ratiofails → passes (1546.7 → inside the reviewed 1151.3),couple_no_children+34.2% → +0.03%,unrelated_adult's absorbermulti_familyunbound. Five of the six seam gates green.2. The
would_claim_uclever run — measured, and re-frozen at 0.55The pre-registered U8 lever ran as adjudicated: contract raised to 0.85, full spine rebuild (
spine-h, 14/14 signed RC battery), strict parity signed (one new register entry + 15 bounds re-minted), seam re-run — then reverted on the receipts, which now live in the contract entry itself:dwp.uc.householdsobr.housing_benefitThe raise moves claimants off legacy benefits (HB initial £2.08bn → £0.75bn — unreachable under the 10× weight cap), pollutes the QRF predictor surface through engine-computed
household_net_income(the flip is payload-non-local: WAS/LCFS/ETB draws moved on ~1,700 households), and buys the UC cells nothing. The binding constraint on UC caseload is capital-test support (uk-data#452 mechanism 2 → microcosm#750), not take-up support. U8 stays frozen at 0.55 with the run recorded in the contract's source block.3. B5 — the seam refuses shippability claims
--release-candidateand canonical release ids are refused on the calibration driver (the 5413502559 audit): the seam's 6-entry scoped battery can never sign a shippability claim. Therelease_candidateparameter leaves the seam runtime; the hand-written build-recordshippableliteral is replaced by a pointer to the certification artifact.4. B5 — the release-cut certification producer
The 16 declared national preflight/terminal gates get their executable home back:
tools/certify_uk_release_cut.pyoveruk_runtime/release_certification.py, a scoped release-candidate-strict battery over the calibrated candidate, evidence reconstructed from persisted artifacts — the spine sidecar (which now persists each fitting stage'sFitWeightRecords: 38 records across 5 stages on the licensed build), the seam's diagnostics/build record, the recompiled register, and the per-run licensed input-mass reference.The multi-part certification composes over the spine, seam, and release-cut reports: union to the full 35-entry declared set, no gap, no overlap beyond
uk_aggregate_admin, per-part signatures and committed-spec scoped digests, full phase coverage, a closed identity join (spine report → sidecar → build record → diagnostics → candidate bytes), the doctrine and its receipted overrides recorded verbatim, and the rule-1 score receipt cross-pinned (the audit's third carried defect). Shippability exists only here. 14 hermetic tests: a green compose plus one refusal per audit point.5. B5 — the contract side
microcosm-dataverifiesrelease_certification.json: exact field set, mirrored part scopes and scoped-manifest digest pins, full-manifest spec pins, the union partition, recomputed shippability (never read off the flag), the diagnostics join, and the release-key signature. The nine refusal points move from per-report to per-certification;test_gate_battery_contract_pinsholds every new mirror in lockstep with the live producer.6. B4 —
uk_qrf_tail_concentrationre-armed from the #686 L3 baselinestop_k100 (grid anchor),max_top_share0.9994670564654868 (the exact measured checked-surface maximum:hmrc_spi_other_social_security_income, 104 carriers on spine-a),min_nonzero_records104 (the thinnest measured column above the anchor). The three saturated sub-anchor columns (12/22/24 carriers, top-100 share 1.0) go thin-visibly on every run. The gate notes record the measuring run — baselines file digest, measured artifact, defining column per threshold. Gate policy/manifest/fingerprint digests re-cut from the live producer payload. The 12 household-surface grids are measured but not armed (declared follow-up).Phase 3 — where the first certified cut stands
The candidate-of-record moves to spine-i (rebuilt at this tip, payload-identical to spine-g — the entire increment is payload-inert at 0.55): 14/14 battery at RC strictness with a signed report, fit-weight sidecar, identity ladder e4–e8 green, strict parity
signed_parity/ 0 unsigned. The committed acceptance receipt + binder now describe it.The Phase-3 seam attempt (
uk-757-first-certified-cut) binds 361 targets at loss 0.0309 and blocks, correctly, atuk_target_fiton 13 characterized cells:self_employment40–50k +128%, count 300–500k +40%,state_pension40–50k +118%,private_pension_count70–100k +66%)dividend_income_count500k–1m −36.7%; its amount sibling is excluded)So the certification, the
uk_input_mass_parityflip to the cut line, the descriptor retirement (B4/C4 completion), and the #731 scorecard probe wait on those dispositions — exactly the fail-closed behaviour the machinery is for. Everything is staged: once the UC family has a disposition, the cut is a seam run +certify_uk_release_cut.pyinvocation away.#792 — measure materialization is exclusion-set-dependent (found by this pass, controlled, filed)
Three seam runs on the same spine, same doctrine, differing only in the register: with the old 5-entry register all 403 initial estimates reproduce the rebind exactly (also proving this PR's seam changes measure-inert); with the 47-entry register 12 of 361 shared measures move, up to +858% (7 HMRC band cells, 5 UC payment-dist cells; the other 349 are bit-stable). Engine-side stochastic variables are materialized in register-dependent order. This must be fenced before any certified line binds on the surface — details and fix directions in #792.
Adjudication queue
dividend_income_count_500k–1m: 7th sparse-class exclusion, or ride Band edges derive from the exclusion-pruned register, silently widening surviving banded targets #792's fix?epochs 1500/family_equalas receipted overrides (your 2026-08-24 ruling keepsuniformthe default); the certification records them verbatim. Promote to doctrine, or certify with receipted overrides?Deferred, by construction — tracked in #796
Every remaining spine deferral now lives on the WS-E spine-deferrals tracker #796 (sub-issue of #145, the spine counterpart of #736): the B4 completion / C4 retirement (
uk_input_mass_parityflip to the first certified line +efrs-post-calibrationdescriptor retirement — cannot precede the cut, US #327 doctrine), the W8 certified-identity registry entry, the #731 scorecard probe and rule-1 scorer seal, the household-surface QRF tail gate,macro_realism, and the carried dates (owned_landexclusion expires 2026-09-26; measure-exclusion windows 2026-11-25/26). The calibration-side remainder — the 8 UC cells, the sparse sibling, #792's fix direction, the doctrine posture, the fuel-duties retarget — is checklisted on #736.Verification
ci_test_groups.py --verify, full uk + shared-spec groups green at the tip (US groups not run — no US file touched).data/ukds/acceptance/757-swap/): spine-h + spine-i builds under the armed battery (signed, RC-strict, 14/14); payload receipts (g↔h isolates the lever, g↔i proves the increment payload-inert); identity ladders; strict parity receipts; the four seam runs (lever, counterfactual, RNG control, Phase-3) with signed gate reports; logbook rows for every attempt.Closes #623, closes #686, closes #757.
With #787 merged, this PR completes what those three issues still owned: #623's seam gains its full gate story and doctrine-governed exclusion mechanics; #686's L3 baselines arm the thresholds they were measured for; #757's B4/B5 items land and its A-lane gaps carry adjudicated dispositions. The first certified cut — the epic bar — is staged and blocked only on the adjudications above; it is tracked as the capstone of #796 rather than holding these issues open. #791 and #792 were filed as successors with this PR.
🤖 Generated with Claude Code