Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
56 commits
Select commit Hold shift + click to select a range
7910d0c
chore: start F1 portable identity progress journal
MaxGhenis Sep 3, 2026
ec066ca
docs: record F1 identity implementation map
MaxGhenis Sep 3, 2026
6c96cb7
test: specify portable worker identity semantics
MaxGhenis Sep 3, 2026
8f14fde
test: specify legacy scoring identity attestation
MaxGhenis Sep 3, 2026
e764dbc
docs: record F1 fail-before evidence
MaxGhenis Sep 3, 2026
2bc201e
feat: authenticate portable primary worker identity
MaxGhenis Sep 3, 2026
acf5434
feat: gate portable identity compatibility scoring
MaxGhenis Sep 3, 2026
814d917
feat: mirror portable worker identity in US specs
MaxGhenis Sep 3, 2026
a549cb9
test: refresh portable worker identity pins
MaxGhenis Sep 3, 2026
d786374
docs: explain portable worker authentication
MaxGhenis Sep 3, 2026
ff3d255
fix: preserve worker identity in exact-k receipts
MaxGhenis Sep 3, 2026
90c3c57
fix: authenticate wheel-installed worker dependencies
MaxGhenis Sep 3, 2026
eed45be
test: retain nested release verdict coverage
MaxGhenis Sep 3, 2026
c90bc80
fix: normalize worker audit path aliases
MaxGhenis Sep 3, 2026
52e85a4
docs: state portable identity threat boundary
MaxGhenis Sep 3, 2026
921a8d5
Finish F1 verification: resolver bindings are not authored digests, t…
MaxGhenis Sep 4, 2026
5e6c895
Worker identity: accept byte-identical shadowed namespace roots and u…
MaxGhenis Sep 4, 2026
ee7906d
Re-pin the spec-engine identities for the rebased tree
MaxGhenis Sep 4, 2026
656dc88
Classify worker_identity.py as a reviewed non-registry runtime module…
MaxGhenis Sep 4, 2026
b26708a
Keep the worker execution binding out of the spec-engine inventory di…
MaxGhenis Sep 4, 2026
597cf72
Start Sol round-one progress journal
MaxGhenis Sep 4, 2026
71dbe29
Add fail-before regressions for Sol worker findings
MaxGhenis Sep 4, 2026
41e7aee
Require the complete schema-9 stacked envelope
MaxGhenis Sep 4, 2026
b8fd0eb
Disable and authenticate Torch backend autoload
MaxGhenis Sep 4, 2026
a0ec4f8
Bind the Python runtime and clean import closure
MaxGhenis Sep 4, 2026
62f1d3e
Cache the immutable worker identity test fixture
MaxGhenis Sep 4, 2026
3d5a1b9
Cache the canonical H5 worker fixture
MaxGhenis Sep 4, 2026
3cbb5a9
Reuse real worker bindings in pin checks
MaxGhenis Sep 4, 2026
32ce6f5
Move Torch autoload guard to worker bootstrap
MaxGhenis Sep 4, 2026
b0c5ab7
docs: initialize Astra worker identity fix journal
MaxGhenis Sep 4, 2026
4380745
test: reproduce worker startup and stale bytecode identity gaps
MaxGhenis Sep 4, 2026
b131afb
fix: disable Torch autoload before stacked worker startup
MaxGhenis Sep 4, 2026
4a575d7
fix: isolate probe and worker from existing bytecode caches
MaxGhenis Sep 4, 2026
aa2d6a7
test: reuse pristine worker identities in artifact validation fixtures
MaxGhenis Sep 4, 2026
f5042e8
test: reuse worker identity across tail control mutations
MaxGhenis Sep 4, 2026
59ce4d5
docs: record unchanged spec pins and completed verification suites
MaxGhenis Sep 4, 2026
61392cd
docs: finalize Astra worker identity verification report
MaxGhenis Sep 4, 2026
50c9232
fix(stacked-spine): report the retained sidecar's digest on checkpoin…
MaxGhenis Sep 5, 2026
e804f48
docs: start PR 871 CI crawl fix journal
MaxGhenis Sep 5, 2026
c48a220
docs: record slow worker identity baseline
MaxGhenis Sep 5, 2026
3399281
docs: record complete first-200 slow baseline
MaxGhenis Sep 5, 2026
3e18c9e
test: reproduce repeated worker identity computation
MaxGhenis Sep 5, 2026
c0cb126
perf: memoize worker attestations and prime real test identities
MaxGhenis Sep 5, 2026
5726d41
docs: record worker selector speedup and review
MaxGhenis Sep 5, 2026
c8b831c
docs: keep verification journal current
MaxGhenis Sep 5, 2026
eaf1058
docs: record complete stacked-spine verification
MaxGhenis Sep 5, 2026
2927d87
docs: record indirect bundle identity caller
MaxGhenis Sep 5, 2026
94d52a2
docs: record initial us-qs build verification
MaxGhenis Sep 5, 2026
964581c
docs: record us-qs frame verification
MaxGhenis Sep 5, 2026
635135d
docs: record us-am build verification
MaxGhenis Sep 5, 2026
8952df0
docs: record successful initial CI process groups
MaxGhenis Sep 5, 2026
a42ed4c
test: expose unprimed spec-bundle worker identity
MaxGhenis Sep 5, 2026
7ea6a25
test: prime worker identity before cached bundle generation
MaxGhenis Sep 5, 2026
08010cf
docs: record final bundle verification progress
MaxGhenis Sep 5, 2026
fc4f8a4
docs: record final us-qs build verification
MaxGhenis Sep 5, 2026
d653c07
docs: complete worker identity performance fix report
MaxGhenis Sep 5, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
274 changes: 273 additions & 1 deletion PROGRESS.md

Large diffs are not rendered by default.

1 change: 1 addition & 0 deletions changelog.d/f1-portable-worker-identity.fixed.md
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Authenticate primary-QRF workers with a versioned semantic identity covering launcher and loaded-Python-runtime bytes, imported stdlib source/extensions, canonical virtual-environment fields, the static and clean-import-observed Microcosm closure, the exact lock and installed RECORD environment, disabled and authenticated Torch backend autoloading, canonical arguments, and fit controls, while retaining absolute launcher paths only as audit aliases so byte-identical worktrees can relocate safely. Legacy schema-9 gate-failed artifacts may relocate only through the scoring-only loader after the complete stacked manifest envelope validates and with an explicit plan-authorized attestation binding the sealed artifacts, published `b8819b3f` campaign token, environment/code identity, and exact two-field alias mismatch; simulation-ready and release loaders remain closed, and the candidate-26 deny-list remains independently enforced. Manifests and downstream receipts now surface the worker schemas, semantic digest, audit aliases, and attestation digest and purpose when applicable.
24 changes: 12 additions & 12 deletions docs/evidence/spec-engine/us-f0-coverage.json
Original file line number Diff line number Diff line change
Expand Up @@ -1321,7 +1321,7 @@
"expected": "complete execution-row and transition-authority object",
"failures": [],
"observed": {
"sha256": "503428f6e9d98f19ed3a6ada5bc9883ae44c1b5dc27f09e60b7ac98895a99bc0"
"sha256": "9a09b49855b3dc4c37ac86c3b91293b6944a50f4448354701b18db8f659ae121"
},
"status": "covered"
},
Expand All @@ -1338,12 +1338,12 @@
],
"expected": {
"nodes": 38,
"sha256": "271a7bb8d0b3f97ff344e0b7e68184fa74738a6585c24fc8781793db669f388b"
"sha256": "40cd51ffdfe2e9d9d08d48c08e8ded9de1e4b134783bab05c4abc6ad5c72ca1e"
},
"failures": [],
"observed": {
"nodes": 38,
"sha256": "271a7bb8d0b3f97ff344e0b7e68184fa74738a6585c24fc8781793db669f388b"
"sha256": "40cd51ffdfe2e9d9d08d48c08e8ded9de1e4b134783bab05c4abc6ad5c72ca1e"
},
"status": "covered"
},
Expand All @@ -1361,12 +1361,12 @@
],
"expected": {
"producer_count": 38,
"sha256": "afebb6725373abf5b8dd4fdb77bf2814cb6fcc569cb606c0c30963a8f65c0bab"
"sha256": "b2b7dbd64db211088e85c94ad6ca1b942cb5e45683eb8c34ba9b664b5de64624"
},
"failures": [],
"observed": {
"producer_count": 38,
"sha256": "afebb6725373abf5b8dd4fdb77bf2814cb6fcc569cb606c0c30963a8f65c0bab"
"sha256": "b2b7dbd64db211088e85c94ad6ca1b942cb5e45683eb8c34ba9b664b5de64624"
},
"status": "covered"
},
Expand Down Expand Up @@ -1840,11 +1840,11 @@
"legacy_adapter.stacked_checkpoint_static_components"
],
"expected": {
"sha256": "e660a8ce42b69a39d29c5f0ec37264bc69d61b03f27adc386336ec8889531bb2"
"sha256": "9d4a9672a0f03039b1fe874b9fe21ed575be0d29f14afc396d03cdf5c809bdd2"
},
"failures": [],
"observed": {
"sha256": "e660a8ce42b69a39d29c5f0ec37264bc69d61b03f27adc386336ec8889531bb2"
"sha256": "9d4a9672a0f03039b1fe874b9fe21ed575be0d29f14afc396d03cdf5c809bdd2"
},
"status": "covered"
},
Expand Down Expand Up @@ -1887,7 +1887,7 @@
"alpha",
"zeta"
],
"sha256": "b88f2d9c0f6f92c6cd81eb14d6b126afe59577b8bb392b394b2c6fbbafd195c5"
"sha256": "7176664c34039def5f43281a7735f792fe43de4ef0a6e7ca18f53d812b412d15"
},
"failures": [],
"observed": {
Expand All @@ -1911,7 +1911,7 @@
"alpha",
"zeta"
],
"sha256": "b88f2d9c0f6f92c6cd81eb14d6b126afe59577b8bb392b394b2c6fbbafd195c5"
"sha256": "7176664c34039def5f43281a7735f792fe43de4ef0a6e7ca18f53d812b412d15"
},
"status": "covered"
},
Expand Down Expand Up @@ -1975,7 +1975,7 @@
"take_up_contract",
"us_qbi_reconciliation_contract"
],
"sha256": "04899daa491e8f089899c9df64cdb2ed44d61d11da2b4c733db6f20f38a1668a"
"sha256": "f22487c266bd24aba91ed526eed29d612875e4e78f7b4bdd93e10c9888801ecf"
},
"status": "covered"
},
Expand Down Expand Up @@ -2599,7 +2599,7 @@
"country": "us",
"schema_id": "country_spec",
"schema_version": 1,
"spec_sha256": "a6bc79878eb6f64637b9f3eceeea6cc2b050c0e5b8f9aca446179258940c44f2"
"spec_sha256": "9db29b4d33424fbb21a83c63927c7de55ba9a333d631f6323935f67a496eee46"
}
},
"report_schema_version": 3,
Expand All @@ -2609,7 +2609,7 @@
"country": "us",
"schema_id": "country_spec",
"schema_version": 1,
"spec_sha256": "a6bc79878eb6f64637b9f3eceeea6cc2b050c0e5b8f9aca446179258940c44f2"
"spec_sha256": "9db29b4d33424fbb21a83c63927c7de55ba9a333d631f6323935f67a496eee46"
},
"status": "pass"
}
111 changes: 111 additions & 0 deletions docs/f1-portable-worker-identity/PROGRESS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,111 @@
# F1 portable worker identity progress

## State

The portable worker identity, authenticated H5/scoring boundary, typed
specification mirrors, and downstream identity pins are implemented and
focused green; documentation and full verification are in progress on
`f1-portable-worker-identity` from base
`09abf2ad78e9af3c5314a4b303d42a75e30d49c4`.

## Done

- Read `CLAUDE.md`, the reproduced refusal in `_inputs/STOP.md`, and the F1
specification in `_inputs/FIX-PLAN.md`.
- Confirmed that runner-owned root journals and task inputs will remain
untouched.
- Traced both authenticated late-DAG validations, every public scoring and
release loader, the deny-list layers, generated-spec mirrors, and downstream
release/scoring receipt propagation.
- Specified fail-before coverage for portable semantic equality, semantic
tamper refusal, the sealed STOP alias mismatch, and the explicit legacy
scoring-only attestation boundary. The focused portable-identity nodes fail
against the base implementation with two missing semantic identities and one
missing legacy mismatch helper (3 failed).
- Mapped the required version cascade: worker identity 1, primary config 5,
primary-QRF sidecar 2, resource semantics 2, registry 17, producer receipt
4, transition authority 2, stacked authority 12, checkpoint materializer 13,
and pool manifest 10.
- Added a closed, versioned worker identity that binds interpreter bytes,
implementation/version/ABI/cache tag, canonical semantic `pyvenv.cfg`, the
exact approved lock, transitive source imports, verified installed RECORD
contents, canonical argv, and fit/predict controls. Absolute executable,
prefix, and raw argv aliases are retained separately for audit.
- Switched current primary-QRF resource authentication and checkpoint-resume
comparison to semantic projections while preserving full audit aliases in
receipts. Bumped the primary config, checkpoint sidecar, late registry,
producer receipt, transition authority, and stacked authority sources.
- Green evidence: Ruff passed for the three implementation files and the three
committed portable-identity regressions passed (`3 passed`).
- Added the explicit schema-9, gate-failed, scoring-only compatibility path.
Its plan-bound attestation seals the manifest and H5 digests, the exact
plan-published campaign identifier and campaign lock, the installed
transitive environment/code identity, recorded worker, semantic worker, and
the exact two legacy alias mismatches. Neither readiness/release loader has
an attestation parameter.
- Threaded the authenticated legacy context through both late-DAG validation
passes and reconstructed the frozen schema-4/config, registry-16,
receipt-3, transition-1, and authority-11 identities without weakening the
current validators.
- Published current worker-authentication evidence in manifests, diagnostics,
authenticated H5 capabilities, release receipts, and head-to-head scorer
identity/loader receipts. Added the candidate-only scorer CLI attestation
argument and direct propagation coverage.
- Kept deny-list refusal intact and made compatibility provenance impossible
to release-launder: schema 9, private legacy provenance, scoring-only receipt
fields, a changed returned manifest payload, and mismatched current receipts
each fail closed.
- Hardened the semantic identity implementation so source discovery follows
the worker module actually resolved by the interpreter, every source and
installed RECORD byte is re-read at authentication time, direct external
imports must resolve into the hashed RECORD, package initializers are part of
the transitive closure, and worker-startup package resources are hashed.
- Extended the regression surface with the 18-field semantic matrix, every
post-`argv[0]` position, exact legacy attestation/mismatch matrices,
release-laundering cases, scorer propagation/receipts, and the exact
non-mutating 12-household origin battery.
- Latest green evidence: four source/resource/scorer unit cases passed; four
end-to-end current/legacy H5 authentication and release cases passed; the
12-case legacy attestation/laundering subset passed. Ruff check passed on the
edited Python boundary files.
- Replaced both constants-era worker templates with the closed portable
resolver algebra, made the typed projector resolve the alias-free semantic
receipt, and retained semantic worker fields in inventory identity while
excluding only `audit_aliases`.
- Updated the imputation and spine JSON schemas and checked-in US YAML mirrors
to primary config 5, registry/schedule 17, producer receipt 4, transition
authority 2, resource semantics 2, stacked authority 12, and checkpoint
materializer 13. JSON parsing, Ruff, bundle loading, and all four imputation
projector tests pass.
- Refreshed the schedule, stacked-authority, resource-semantics, checkpoint,
graph, and country-spec identity pins, plus their exact version assertions.
Regenerated coverage evidence is green at `42154/42154` configuration fields
and `41/41` inventory checks; its deterministic `--check` is also green.
- Green evidence for the refreshed spec identity contracts: `18 passed, 21
skipped`, exit 0. The constants-era bundle generator was also attempted with
both `--check` and `--check --skip-validation`; each exits 1 before byte
comparison because this environment lacks the optional `policyengine-us`
distribution metadata.
- Documented the semantic/audit identity split, the explicit plan-authorized
schema-9 scoring exception, receipt fields, version cascade, independent
release deny-list, and the exact limits of the plan-defined authorization
tuple. Added the F1 changelog fragment.
- Closed the exact-k release-receipt propagation gap found in adversarial
review: the authenticated pool's worker schema/digest/audit receipt is now
required in `exact_k_ladder.pool` and therefore survives into both build and
release manifests.
- Corrected installed-wheel source discovery so only the `microcosm` namespace
roots are treated as internal code; neighboring site-packages remain in the
installed RECORD closure. The source and external-import closure now come
from one read rather than two potentially different filesystem snapshots.
- Preserved the nested release-verdict regression beneath the new authenticated
manifest-payload guard by rebinding only its synthetic capability; both
parameterized cases pass while real mutated manifests still fail earlier.
- Enforced absolute `sys_executable` and `sys_prefix` audit aliases while
retaining the unmodified raw `argv_template[0]` audit value.
- Recorded the F1 threat-model boundary: inherited Python startup/path hooks
remain trusted and are not added to the two specified semantic fit controls.

## Next

- Run focused, CI-group, and required repository checks.
Loading
Loading