diff --git a/docs/semantic-parity.md b/docs/semantic-parity.md index 70ad8bf..360cf3b 100644 --- a/docs/semantic-parity.md +++ b/docs/semantic-parity.md @@ -76,7 +76,7 @@ blockers remain. The detailed bootstrap audit is in | Inspect/version command surfaces | **partial** | `version`, sealed `inspect-segment`, active inspection, and representative `inspect-all` reports have fixtures and golden comparisons. | Inspection does not compensate for missing online status tabs, and the current audit did not rerun every golden against the current commit. | | Differential oracle | **blocked as an admission proof** | It provides useful event-log, final-state, restart, repair, and public-client coverage against a pinned upstream simulator. Focused production-boundary tests now prove per-repository writer-gated completion and same-disk reopen with a sibling held incomplete. | The oracle still needs an invariant-based process-kill world that scales this beyond a two-repository fixture; its old four-account `after_repo_complete` schedule could not detect a dispatch-scale replay defect. | | Strict power-loss oracle | **partial** | It exercises acknowledged-write reconstruction at named write/fsync/rename boundaries. Focused tests separately inject Store read failures for lifecycle phase, relay cursor, compaction watermark, and merge cursor; the merge restart guard also distinguishes source absence from filesystem failure. The completion reopen test proves completed-versus-interrupted repository classification around an unchanged listRepos cursor. | It does not yet inject missing manifest files during replay, long listRepos cursors, or storage loss specifically between archive fsync and the completion metadata commit. | -| Exact artifact admission | **partial** | `scripts/admit` implements the procedure: `run` requires a clean worktree, runs every suite, builds the exact linux/amd64 image and writes one receipt recording the Stream/Zig/upstream-Jetstream/dependency revisions and dashboard checksum; `publish` pins that receipt to the pushed registry digest and refuses if the local image drifted; `verify` is the deployment gate. A receipt covers a digest, never a tag; a `skipped` suite blocks admission exactly like a failure, so a partial run cannot read as a full one. `tests/admission_contract.py` pins the refusals — unknown digest, unpublished receipt, another artifact's digest, skipped suite, failed suite. | The publish path has not been exercised end to end: no image has been pushed and no receipt carries a real registry digest yet, because publishing is an outward-facing action awaiting an actual promotion. Deployment tooling must also be wired to call `verify` before rollout; today the gate exists but nothing on the deploy side is forced through it. | +| Exact artifact admission | **partial** | `scripts/admit` implements the procedure: `run` requires a clean worktree, runs every suite, builds the exact linux/amd64 image and writes one receipt recording the Stream/Zig/upstream-Jetstream/dependency revisions and dashboard checksum; `publish` pins that receipt to the pushed registry digest and refuses if the local image drifted; `verify` is the deployment gate. A receipt covers a digest, never a tag; a `skipped` suite blocks admission exactly like a failure, so a partial run cannot read as a full one. `tests/admission_contract.py` pins the refusals — unknown digest, unpublished receipt, another artifact's digest, skipped suite, failed suite. | The experiment harness `deploy.sh` now reads the image's registry digest and refuses to deploy unless `admit verify` admits it; checked against the real artifact, it rejects `sha256:adc276257fd8bc0cd8c0c94341afe220b50690cbef79539fe1ce3f7e6bcbd9fe`, the `e1926f3` image that failed the July experiment. Remaining: the publish path has not been exercised end to end — no image has been pushed and no receipt carries a real registry digest yet, because publishing is outward-facing and awaits an actual promotion. Until one receipt is published and a full `admit run` completes on the promotion commit, this row stays partial. | ## Evidence that must not be overread