Skip to content

docs/plans: graph-port Plan A revision 5 (folds the third gate's round-2 findings) - #424

Merged
MaxGhenis merged 7 commits into
masterfrom
plan-a-rev5
Sep 5, 2026
Merged

docs/plans: graph-port Plan A revision 5 (folds the third gate's round-2 findings)#424
MaxGhenis merged 7 commits into
masterfrom
plan-a-rev5

Conversation

@MaxGhenis

Copy link
Copy Markdown
Contributor

Revision 5 of the shadow-only graph-port plan (docs/plans/graph-port-A-shadow-2026-09-03.md), folding both findings of the third gate 20260905-154850-plan-5cfd8532 (Fable main + Astra peer), round 2:

  1. TCB completeness for the hermetic-image alternative (A2, A2a): the complete image identity (image and loaded-layer digests) and the resolved semantic-environment values are TCB components; any change rejects the populated old namespace before any cache read; two images or environment resolutions can never share a namespace.
  2. Latency population per event class (§4, H2 stopping rule): harvest events keep harvest-to-shadow-complete; seal, void, repair, supersession and replication events use event-to-shadow-complete with an explicit commit-pinned timestamp source; classes are reported separately and never pooled.

No scope change: shadow-only, NONAUTHORITY, no touch of #405, e20-amend20, docs/design/, the registry, gates or runs. Docs only. Merge after the gate agrees on this revision's fingerprint (sha256 e02292da…).

🤖 Generated with Claude Code

…round 2: image identity and environment values in the TCB; latency per event class)

Third gate 20260905-154850-plan-5cfd8532 (Fable main + Astra peer) on revision 4 requested two changes. This revision folds both: the hermetic-image alternative binds the complete image identity and the resolved semantic-environment values into the TCB with old-namespace rejection before any cache read (A2, A2a), and the H2 latency population is defined per event class with an explicit timestamp source, harvest-to-shadow-complete kept separately for harvest events (§4). No scope change; shadow-only and nonauthority as before.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@vercel

vercel Bot commented Sep 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
social-security-model Ready Ready Preview Sep 5, 2026 8:51pm UTC

Request Review

…nt-type applicability map and explicit absence semantics for the legacy comparison)

Round 3 of gate 20260905-154850-plan-5cfd8532 found that the universal legacy comparison demanded a canonical report and T bytes for every event although voided attempts may never have produced either. Revision 6 adds a frozen applicability map per event class, an ABSENT-BY-DISPOSITION marker that satisfies A-2 and counts toward EVIDENCE-COMPLETE where the map permits it, a MISSING REQUIRED EVIDENCE failure where it does not, and fixtures for both cases. No scope change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…bility per report-derived and T-derived axis; report-bearing void fixture)

Round 4 of gate 20260905-154850-plan-5cfd8532 found the revision-6 applicability map all-or-nothing: an attempt voided after its canonical report but before its T had no rule preserving the report comparison. Revision 7 partitions the legacy fields into report-derived and T-derived axes, declares applicability per axis from the authoritative disposition, keeps the report comparison for report-bearing voids, and adds the fixtures. No scope change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…3f; consume the core's store/codec/artifact facilities; string gate outcomes)

Revision 7 was agreed by gate 20260905-154850-plan-5cfd8532. Revision 8 amends the A2 TCB pin from 6022e4f5 (which lacks register_bytes, raw-bytes-v1 and the typed ArtifactType/ArtifactInput/ArtifactOutput edges) to the commit the Microcosm US session froze for its interface check, b55a583f (memo SHA 485ea3d3…, receipt SHA 8d780c99…), recorded as a new TCB with its publication state; binds A-1 to the core's facilities instead of reimplementing them; and adds the string-outcome rule for gate kernels. Submitted to a fresh gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…round 1: all-string gate outputs, requires_decisions as a decision-name contract, per-fixture expected states)

Three runtime-contract findings against the pinned executor at b55a583f: the exception path rejects any non-string owned output (executor.py:130); requires_decisions is matched against supplied decision names, not gate ancestry (executor.py:219-249); a missing required source is refused before any kernel executes (executor.py:1922-1924). Revision 9 requires all-string owned outputs on gate kernels with a mixed-output fixture, freezes and validates the decision tuple and the gate set independently with warm-replay checks, and scopes A-2's execute/hit assertions to each fixture's frozen expected state (executed, refused, unreached).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
…-routed A-1/A-2 lane when Claude is capped, under ceremony precedence)

Requested by the Microcosm US session under Max's steering to maximise parallel work. A5 and the matching §5 do-not now permit the isolated A-1/A-2 engineering lane to route upward to Astra on a Codex home when every Claude lane is capped by return code, subject to ceremony precedence on that home (no build while an Amendment-20 ceremony step runs there), a recorded window state and routing decision at dispatch, and the Claude path as the default whenever it frees first. No scientific, authority or scope change.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
… round 1: blocking artifact edges, executed-failed vs unreached, both dependency-type fixtures)

At the pinned executor a failed string verdict does not block downstream execution; only an unavailable typed artifact or an unreached ancestor does (_blocked_by). Revision 11 requires every gate that must stop execution to emit a typed artifact its dependents consume (transport gate -> reconstruct_T and seal gate; seal gate -> RELEASE), distinguishes EXECUTED-FAILED from UNREACHED in the frozen expected states, forbids a RELEASE that executes after a seal-gate failure, and requires cold/warm fixtures for both dependency types. The revision-10 capacity amendment drew no finding and is unchanged.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant