Conversation
…ease cell has a fresh Pass receipt; absence is a violation by construction Operator, 2026-09-21: "you need to improve our dogfood process and pv SHACL so leaks don't exist pre-release. this is clown town." Every 0.69.0 leak was absence read as conformance. - receipts.rs reads apr-model-ladder-receipt v1 AND v2 (#3712). Before this, the first committed v2 receipt would have turned `pv lint --gate shapes` exit 3 on every PR (a foreign schema is refused by name, and still is for v3). - extract:release-evidence (Σ entity type release-evidence), built ONLY under a release subject: Release, Host, Model, Verb, ContextRung, Cell, CellReceipt, RefusalCell, RungCoverage, TokenizerCell, KernelCell nodes. The universe is DERIVED (host inventory ∪ cuda ladder rungs × verbs × thinking_modes × context rungs up to the model's GGUF length; kernels from every host's dispatch path; one tokenizer cell per model), so a missing receipt is a missing edge. - the nine-shape release-readiness-v1 family; `--shape` arms it whatever armed_shapes says and reports release → host → context → model → coverage → tokenizer → kernel → refusal → cell. - `pv lint --gate shapes --shape release-readiness-v1 --release-version V --release-commit MC [--receipts-commit S] [--receipts D] [--kernel-receipts D] [--tokenizer-receipts D] --dogfood-receipt F`: 0 Pass · 1 Fail naming cells · 2 decline (no subject) · 3 caller error. `pv extract --release-* --out F` writes the release graph and never the tracked contracts.nt. - 34 red-turning CLI cases (a green base with every cell named, then one change each), 10 unit tests; skip-as-pass and always-fresh mutants each turn the table red. - evidence/release/proof-0.69.0: 0.69.0's own evidence, translated without inventing a measurement, is RED with 795 findings naming qwen3-8b lambda (verdict fail), qwen2.5-coder lambda and qwen3moe on both hosts (never identified), 752 of 768 cells absent, and the NO-GO dogfood receipt the train "inherited" a GO from. Receipt formats agreed on #3712 with aprender-62, -f0, -37, -eb; tokenizer parity on #3726. No waivers (cop ruling (c); the operator-only surface is #3722). Refs #3715, #3712, #3710, #3726 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
… reproduces; fixture rows one per line gate-summary.json carries the verdict, the counts, every non-cell finding verbatim and the cell findings aggregated per host/model; the README's command re-runs the full 795-finding report. Refs #3715 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false) {
"ticket": "PMAT-3715",
"head": "0e99993dc13eae20f6f49644f29041d2e23b4796",
"width": 3,
"executor": "agy",
"agreed": false,
"auto_merge": {
"checked": true,
"was_armed": false,
"disarmed": false,
"note": "auto-merge not armed"
},
"lanes": [
{
"lane": 1,
"verdict": "NO-VERDICT",
"findings": 0
},
{
"lane": 2,
"verdict": "NO-VERDICT",
"findings": 0
},
{
"lane": 3,
"verdict": "PASS",
"findings": 0
}
]
} |
…ith its URL Round 1 of the quorum judged against the ticket TITLE alone (`pmat work status` prints nothing else): both gemini lanes carried a scope FAIL for the kernel, thinking, tokenizer and dogfood cells that the issue's author added on the issue. The receipt is what the brief carries; it quotes each addition and the measurements. Refs #3715 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
quorum-review (AD-04): NOT agreed (auto_merge: checked=true was_armed=false disarmed=false) {
"ticket": "PMAT-3715",
"head": "ba9afe3d1cd8c6a900ade681ce17cc4d3b1cf4ba",
"width": 3,
"executor": "agy",
"agreed": false,
"auto_merge": {
"checked": true,
"was_armed": false,
"disarmed": false,
"note": "auto-merge not armed"
},
"lanes": [
{
"lane": 1,
"verdict": "NO-VERDICT",
"findings": 0
},
{
"lane": 2,
"verdict": "PASS",
"findings": 0
},
{
"lane": 3,
"verdict": "PASS",
"findings": 0
}
]
} |
…ease-evidence gets its own control The one real conflict (the extract import in shapes_gate.rs) is textual; the semantic one is #3706's every_implemented_entity_type_in_sigma_has_an_extract_control_and_it_fires: release-evidence was implemented in Σ with no pc_extract control, so the merged tree would have gone RED. release_evidence::positive_control(), drawn every gate run with no release subject and no file: a sample cell with one fresh Pass row and a planted cell with none go through the real build(); it fires iff the planted cell is still a release:Cell node with ZERO rows (absence materialized for minCount 1). extract() is now file reading plus a pure build(Inputs). Mutant measured: emit only cells that have rows -> pv lint --gate shapes exit 2, 'positive control pc_extract.release-evidence did not fire'. Also moves receipts.rs's strings() helper above the test module (clippy items_after_test_module). Refs #3715, #3704 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
§13.11 rung 1 — quorum shadow verdict Shadow mode: this records a verdict and merges nothing. A refusal |
Contributor
Author
|
quorum-review (AD-04): three PASS — agreed (auto_merge: checked=true was_armed=false disarmed=false) {
"ticket": "PMAT-3715",
"head": "84289cb7ba38adf96c0a1c5f836eb84ccb8d0646",
"width": 3,
"executor": "agy",
"agreed": true,
"auto_merge": {
"checked": true,
"was_armed": false,
"disarmed": false,
"note": "auto-merge not armed"
},
"lanes": [
{
"lane": 1,
"verdict": "PASS",
"findings": 0
},
{
"lane": 2,
"verdict": "PASS",
"findings": 0
},
{
"lane": 3,
"verdict": "PASS",
"findings": 0
}
]
} |
…emainder in the fragment The cop's landing conditions (1)-(2): the fragment names the hand-coded VERBS const as the known remainder, verbatim, so no reader takes it for the finished design; #3745 S2 deletes it. No code changes. Refs #3715, #3745 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PMAT-3715:
release-readiness-v1. The tag is refused unless every release cell has a fresh Pass receiptOperator, 2026-09-21, verbatim: "you need to improve our dogfood process and pv SHACL so leaks don't exist pre-release. this is clown town." Every 0.69.0 leak was absence read as conformance. Here every obligation of a release is a graph node derived from what was measured, so a missing receipt is a missing edge that
minCount 1rejects.What it does
receipts.rsreads v1 and v2 (P0 release-process: the train can publish with "most models working" — the model gate is a hand-picked ladder with OPTIONAL rungs, a skip reads as pass, and the dogfood can be inherited. Every Q4_K model × {lambda, gx10} × CUDA must be green or NOTHING ships #3712'sapr-model-ladder-receipt/v2). Until now, the first committed v2 receipt would have turnedpv lint --gate shapesinto exit 3 on every PR. A foreign schema such as v3 is still refused by name.extract:release-evidenceis a new Σ entity type and extractor. It builds the release graph only when a release subject is given; an ordinary PR has none, so it contributes 0 focus nodes there.Release,Host,Model,Verb,ContextRung,Cell/CellReceipt,RefusalCell,RungCoverage,TokenizerCell,KernelCell.thinking_modes× context rungs {4k, 8k, 20k, 60k, consumer-max (computed from the consumer records), declared (the GGUF's own length)}.long_rungs_for. Rungs above a model's length are not owed, and cells that don't fit the host's memory are owed as honest pre-load refusals.contracts/release-readiness-v1.yaml.--shapearms it whateverarmed_shapessays. Findings are reported release → host → context → model → coverage → tokenizer → kernel → refusal → cell.--gate shapes).pv extract --release-* --out Fwrites the release graph to F and never into the trackedcontracts.nt.Proof
crates/aprender-contracts-cli/tests/ont_release_readiness.rs, wired asci/explicit-test-commands.d/450. The green base passes 48/48 cells, each named, and then one thing changes per case:--receipts-commit; no subject → 2; caller errors → 3;pv extractwrites only to--out.cargo test -p aprender-contracts --lib: 1695 passed.cargo test -p aprender-contracts-cli: every target green. Theont4bshape ratchet was raised 9 → 18, naming the new shapes.pv lint contracts: PASS, 0 errors, and no new warnings from this contract.make ont-ratchetwas restamped. Clippy-D warningsis clean on both crates, lib and tests.evidence/release/proof-0.69.0/(done_when 5, first half): 0.69.0's own evidence, translated without inventing a measurement (the rules are intranslate.pyand the README), is RED with 795 findings. They name:verdict=fail;unmeasuredModel), with their failing sweep rowsunkeyedRow;Known remainder (cop ruling, verbatim)
release_evidence.rs
VERBSis a hand-coded list; #3745 S2 replaces it with the derived cell set viaInputs.cells. 0.69.1 does not tag while it exists.Quorum
Round 3 at
84289cb7ba38adf96c0a1c5f836eb84ccb8d0646is AGREED: gemini-3.1-pro-high PASS, gemini-3.1-pro-low PASS, gpt-oss-120b-medium PASS (author claude-opus-5;receipt-lint: complete). Artifact:docs/audits/quorum-PMAT-3715.json, diff_sha2569df958d287befbf36a6b50be55984468291262bf8a3cf2cf9507b584e2f5676b. Round 1 judged against the ticket title alone and was superseded by the implementation receipt; round 2 was 2 PASS + 1 NO-VERDICT. After the round-3 head, the only commit adds this artifact and the roadmap-fragment note below, and changes no code.Merged origin/main
#3706 (PMAT-3704) ties
pc_extractto Σ, sorelease-evidencegets its own control,release_evidence::positive_control(), drawn every gate run. Mutant measured: emitting only cells that have rows givespv lint --gate shapesexit 2, "positive control pc_extract.release-evidence did not fire".Not in this PR, so it carries
Refscheck_publish_preflight.shT-4 (aprender-f0, #3712 done_when 3 (child): the model-matrix gate runs at T-1 on BOTH hosts before any tag, receipts committed in the bump, re-read at T-4 by the same judge #3717 / autopilot's INHERITED dogfood GO writes no receipt that check_publish_preflight.sh R5 accepts — v0.69.0 stopped at the publish preflight 43 min after tagging #3708). This PR supplies the invocation they call.cells[], the memory arithmetic, kernel and tokenizer receipts) and the model fixes to land.release.cell_namesis what it will print.noahgift, so a comment-based waiver is forgeable. The operator-only surface is release-readiness waivers need a surface only the operator holds — a gh comment by noahgift is forgeable by every agent session #3722.Receipt formats were agreed on #3712 with aprender-62, -f0, -37 and -eb; tokenizer parity on #3726.
Refs #3715, #3712, #3710, #3726
🤖 Generated with Claude Code