Skip to content

fix: publish P4 completion after verified cleanup and enrichment - #21

Draft
echoomegaprime wants to merge 1 commit into
mainfrom
agent/p4-acceptance-contract-20260922
Draft

echoomegaprime wants to merge 1 commit into
mainfrom
agent/p4-acceptance-contract-20260922

Conversation

@echoomegaprime

@echoomegaprime echoomegaprime commented Sep 22, 2026 •

Copy link
Copy Markdown
Owner

Objective

Successful P4 hostile acceptance reports omit completed_phase_gate, so the master collector rejects them as incomplete. Publish the required P4 marker only after all core checks and cleanup succeed. The exact wrapper keeps intermediate output pending until evidence enrichment returns; verifier failure, malformed capture, interruption and nonzero exit remain blocked.

The master consumer, signature and exact-source requirements, historical reports and release verdicts are unchanged. Completion of this phase remains distinct from whole-product readiness.

Evidence

  • Exact source revision: a725d2e72b8b80f8a5e28a69422ffa3129ccd1e8 (remote branch readback matched).
  • Local focused and adjacent checks: 24 passed, including actual producer serialization, exact-wrapper orchestration and unchanged master consumer.
  • Full local suite: 637 passed, 2 skipped, 1 failed because Windows denied symbolic-link creation (WinError 1314) in the existing test_workspace_owner_marker_and_symlink_detection test. No test was weakened or skipped to conceal that result.
  • P1 acceptance: exit 0, all 3 scenarios passed against an identical source copy, with output isolated from historical repository reports.
  • Negative paths: failed or empty checks, incomplete outcome, failed cleanup, absent verifier, malformed capture, interruption before enrichment and nonzero core exit.
  • Hosted CI: PR run and exact-candidate dispatch both succeeded. The dispatch checkout log verifies a725d2e72b8b80f8a5e28a69422ffa3129ccd1e8; its Linux suite passed all 640 tests. Artifact 10680649225, named for the same SHA, has digest sha256:45fcb31937469843f3f3797b9172c2075e13bd795b963db11d6007dfc44ae3f3. The PR-only run tested temporary merge 456e0f09f4dc7b7de391fe25cb5d3a279f801d36 and is not used as exact-head proof.
  • CertForge and Certification Forge GitHub App certification: not established. This draft is not ready for Commander release review.

Security and release impact

  • No secrets, private evidence, customer data, or personal information are included.
  • Verdict behavior remains deterministic and fail closed.
  • Public contract compatibility is covered by producer-to-consumer regression tests; no consumer contract is relaxed.
  • Deployment and rollback implications are documented: no deployment is part of this PR. Revert the focused commit to restore prior producer behavior; staged deployment requires its own exact-SHA checks and dual certification.
  • Unrelated repository history and license boundaries are preserved.

Live service readiness additionally requires fresh source-bound P4 artifacts, valid image attestations, the expected public verification material, exact-tested CI evidence and the genuine signed whole-product report. This source fix does not claim those operational gates have passed.

Successful hostile acceptance reports omitted the completed_phase_gate field
required by the master collector. Publish P4 only after every core check and
cleanup succeeds, and keep exact-wrapper reports pending until enrichment
returns. Failed verification, malformed capture, interruption and nonzero
exit cannot leave a newly completed report for the master consumer.

Keep master validation, exact-source and signing rules, release verdicts and
historical acceptance reports unchanged. Add producer/wrapper/consumer
integration coverage including pending publication and failure paths.

Validation: 24 focused and adjacent tests pass; full suite 637 pass, 2 skip,
1 existing symlink test blocked by Windows privilege 1314. P1 acceptance
passes all 3 scenarios using a byte-identical source copy outside historical
artifacts. Hosted CI, dual certification and deployment remain pending.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants