Skip to content

feat(reviewer): bind external evidence receipts to exact claims and runs #555

Description

@seonghobae

Problem

Central ContextualWisdomLab/.github#1641 has an exact hosted false-negative reproducer for unreceipted external tool-behavior claims. Consumer RED head b8c986e2406beb37d254acd4c5df6389038b55f2, run 34073137064, job 101594104816, failed only the original two provenance regressions: 2 failed, 2974 passed, 1 skipped, 21 subtests passed, with DID NOT RAISE NoemaModelOutputError.

Noema owns reviewer evidence admission and exact revision/run identity. Central .github is the consumer. Provider/model routing remains owned by contextual-orchestrator; source, execution and research receipts are distinct authority classes. Quarantine/security/outbound verdicts remain with their canonical owners.

Current implementation / stack authority — 2026-09-08 KST

Protected Noema is GitHub-verified main@099d7d89a51bca4a2cf7c6b285b50ffadd08d001 after normal #540 integration.

Implementation owner is PR #556 exact fecb03d9c632f90f290f921c1d6e90ce86ca5305, still Draft on feature base fix/noema-orchestrator-free-routing-alias. Its live prerequisite #535 has advanced non-force to exact 2ab3fb4da9433701f1c806b8339054f581e8278f. That #535 commit is an ordinary two-parent convergence [099d7d89..., e996b509...]; fresh compare is ahead-only, behind_by=0, with merge-base exactly protected main. It carries the 31 non-overlapping gateway/reviewer owner-contract paths while preserving the six protected hourly-workflow overlap paths. The remaining orchestrator/free source-pin and proposer-timeout mismatch is therefore deterministic source RED rather than stale ancestry RED. Fresh #535 CI/reviewer/Security/image runs are new and non-authorizing until terminal success after the causal overlap repair.

#547 remains the independent sole writer for docs/product-technical-gap-baseline.md and its documentation-authority contracts. Current exact is 30b7e7e5cdab8de65715834a16f994b2047eafa6; application CI, reviewer-ci and required Security are terminal success, while patch-validator-image 34165467851 remains in progress at the exact image-build lane. Its baseline blob must not be carried through #556.

Integration order

  1. docs: reconcile protected runtime and commercial gap authority #547 may normally integrate only after unchanged exact 30b7e7e... obtains terminal-success image evidence, fresh behind_by=0, and clean review authority.
  2. Finish fix: pin NOEMA_LLM_MODEL routing alias to orchestrator/free #535's six-path protected-first causal repair: preserve fix(toolchain): replace Wrangler/Miniflare GPL-family path #540 work-conserving/central-dispatch behavior, pin NOEMA_LLM_MODEL: orchestrator/free, remove the repository-authored proposer wall-clock timeout, and align the operations/executable authority contracts. Require wholly fresh exact-head CI, reviewer-ci, required Security and patch-validator-image GREEN; normal merge only.
  3. Re-read protected main and live feat(reviewer): bind evidence receipts to exact claims #556. Restack/retarget feat(reviewer): bind evidence receipts to exact claims #556 non-force from protected source, carry only its valid evidence-receipt delta, and drop the historical docs: reconcile protected runtime and commercial gap authority #547-owned baseline delta.
  4. Require wholly fresh exact-head CI/reviewer/required Security/patch-validator-image terminal success and clean review authority; normal merge only.
  5. Publish and verify one immutable Noema SemVer release bound to exact protected source/tag/package/SBOM/provenance/reproducibility/rollback evidence.
  6. Bump central .github#1641 to that released Noema contract and rerun the unchanged original Concept35 corpus RED→GREEN. Mutable or unreleased dependency consumption is forbidden.

Hosted stale-stack RED retained as evidence

#556 run 34089768682, job 101640717018, checked out exact fecb03d9c632f90f290f921c1d6e90ce86ca5305, passed checkout/toolchain setup, then failed the live-base guard before lockfile control. Reviewer-ci 34089768665 and patch-validator-image 34089768733 succeeded on that stale exact head; no Security Scan exists. Under current AGENTS, absent required Security is non-passing. Do not rerun this invalid stack merely to manufacture another check.

Implemented #556 source contract retained for later semantic restack

The candidate binds trusted producer evidence to exact claims through canonical receipt ID/evidence kind, exact repository/head/workflow/run/attempt, claim/evidence digests, evidence-kind separation, trusted manifest/index admission and model-visible [receipt:<id>] references before deterministic gates/publication. Source receipts cannot authorize execution or research facts.

A public trusted sandboxed_verify execution adapter is exported on the candidate. It accepts only reviewed immutable central helper revision c9052e607e5f3cc76e73207e7786b21500721b79, validates the marker schema with extra=forbid, requires exact captured stdout/stderr separately, and rejects unreviewed helper revisions, non-empty allowed_env, malformed markers, empty commands and false sandbox markers.

Remaining product boundary: the central sandboxed_verify.py marker still does not contain exact stdout/stderr bytes, so a released consumer must capture those streams out of band and pass them to the versioned Noema adapter; trusted research retrieval still needs a content-addressed revision/excerpt/retrieval-policy producer; malformed/stale/wrong-head/wrong-run/wrong-claim/wrong-kind/digest-mismatched receipts remain fail closed; immutable release and consumer GREEN cannot be inferred from candidate source.

Keep this issue open. #547 image evidence, #535 overlap repair/exact-head gates, #556 restack/Security, immutable release and released-consumer verification remain incomplete.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions