From fbbd706cbce5e6a30d7bffe106580ff1caaa4967 Mon Sep 17 00:00:00 2001 From: zzstoatzz Date: Sat, 25 Jul 2026 00:34:52 -0500 Subject: [PATCH] audit: the deploy path now calls the admission gate deploy.sh refuses any digest admit verify does not admit, proven against the e1926f3 digest that failed the July experiment. The row stays partial until a receipt is actually published on a promotion commit. Co-Authored-By: Claude Opus 5 (1M context) --- docs/semantic-parity.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/semantic-parity.md b/docs/semantic-parity.md index 70ad8bf..360cf3b 100644 --- a/docs/semantic-parity.md +++ b/docs/semantic-parity.md @@ -76,7 +76,7 @@ blockers remain. The detailed bootstrap audit is in | Inspect/version command surfaces | **partial** | `version`, sealed `inspect-segment`, active inspection, and representative `inspect-all` reports have fixtures and golden comparisons. | Inspection does not compensate for missing online status tabs, and the current audit did not rerun every golden against the current commit. | | Differential oracle | **blocked as an admission proof** | It provides useful event-log, final-state, restart, repair, and public-client coverage against a pinned upstream simulator. Focused production-boundary tests now prove per-repository writer-gated completion and same-disk reopen with a sibling held incomplete. | The oracle still needs an invariant-based process-kill world that scales this beyond a two-repository fixture; its old four-account `after_repo_complete` schedule could not detect a dispatch-scale replay defect. | | Strict power-loss oracle | **partial** | It exercises acknowledged-write reconstruction at named write/fsync/rename boundaries. Focused tests separately inject Store read failures for lifecycle phase, relay cursor, compaction watermark, and merge cursor; the merge restart guard also distinguishes source absence from filesystem failure. The completion reopen test proves completed-versus-interrupted repository classification around an unchanged listRepos cursor. | It does not yet inject missing manifest files during replay, long listRepos cursors, or storage loss specifically between archive fsync and the completion metadata commit. | -| Exact artifact admission | **partial** | `scripts/admit` implements the procedure: `run` requires a clean worktree, runs every suite, builds the exact linux/amd64 image and writes one receipt recording the Stream/Zig/upstream-Jetstream/dependency revisions and dashboard checksum; `publish` pins that receipt to the pushed registry digest and refuses if the local image drifted; `verify` is the deployment gate. A receipt covers a digest, never a tag; a `skipped` suite blocks admission exactly like a failure, so a partial run cannot read as a full one. `tests/admission_contract.py` pins the refusals — unknown digest, unpublished receipt, another artifact's digest, skipped suite, failed suite. | The publish path has not been exercised end to end: no image has been pushed and no receipt carries a real registry digest yet, because publishing is an outward-facing action awaiting an actual promotion. Deployment tooling must also be wired to call `verify` before rollout; today the gate exists but nothing on the deploy side is forced through it. | +| Exact artifact admission | **partial** | `scripts/admit` implements the procedure: `run` requires a clean worktree, runs every suite, builds the exact linux/amd64 image and writes one receipt recording the Stream/Zig/upstream-Jetstream/dependency revisions and dashboard checksum; `publish` pins that receipt to the pushed registry digest and refuses if the local image drifted; `verify` is the deployment gate. A receipt covers a digest, never a tag; a `skipped` suite blocks admission exactly like a failure, so a partial run cannot read as a full one. `tests/admission_contract.py` pins the refusals — unknown digest, unpublished receipt, another artifact's digest, skipped suite, failed suite. | The experiment harness `deploy.sh` now reads the image's registry digest and refuses to deploy unless `admit verify` admits it; checked against the real artifact, it rejects `sha256:adc276257fd8bc0cd8c0c94341afe220b50690cbef79539fe1ce3f7e6bcbd9fe`, the `e1926f3` image that failed the July experiment. Remaining: the publish path has not been exercised end to end — no image has been pushed and no receipt carries a real registry digest yet, because publishing is outward-facing and awaits an actual promotion. Until one receipt is published and a full `admit run` completes on the promotion commit, this row stays partial. | ## Evidence that must not be overread -- 2.51.2