Skip to content

Iteration 41: stage fail-closed SimNow certification workspaces - #28

Merged
cloudQuant merged 28 commits into
devfrom
codex/iteration41-simnow-real-certification
Sep 28, 2026
Merged

cloudQuant merged 28 commits into
devfrom
codex/iteration41-simnow-real-certification

Conversation

@cloudQuant

@cloudQuant cloudQuant commented Sep 28, 2026 •

Copy link
Copy Markdown
Owner

Scope

Stage the Iteration 41 config-first, fail-closed SimNow certification workspaces and offline runtime contracts. Each of the 33 managed cases has its own config.yaml, strategy module, and run.py. The protected suite-root CTP config remains Git-ignored. The managed registry requires all 33 case IDs, including five historically optional IDs, while preserving their legacy report metadata.

The latest commit adds unregistered, read-only G1 request-protocol and SQLite journal contracts. They use one fixed ctp_readonly_preflight operation, a service-owned 300-second request budget, durable acceptance and readback, duplicate-ID fencing, and terminal UNKNOWN handling for restarts/late results. A protected prestarted service, terminal journal wiring, OS-authenticated transport, and native Job/CTP runner are not implemented or registered.

Verification

  • Clean checkout: 438 passed in tests/unit/live_certification after the required-scope test was added; 332 passed in the earlier tests/unit/runtime focus.
  • Latest G1 offline focus: 39 passed; targeted Ruff, Black, and staged diff checks passed. Pytest requires disabling an incompatible environment pytest-asyncio plugin and reports one existing configuration warning.
  • A new credential-free TCP check of both protected 007 and 013_3 configurations found indexes 0–3 reachable at MD and TD (3/3 each), while index 4 was unreachable (0/3). The two checks selected indexes 2 and 0 respectively based on the bounded pair score. No SDK import, login, subscription, credential resolution, or write occurred. The redacted result is recorded in the staging acceptance note.
  • Windows CI on the previous head was red at the existing owner-only permissions assertion; an isolated handle-bound ACL candidate is under independent review and has not been integrated. Other earlier CI failures include PyPI download timeouts. Do not treat this draft as CI-green.

Acceptance state

0/33 real SimNow PASS. Every managed case runner remains BLOCKED; no real MD/TD login, tick, order, cancel, or provider reconciliation was accepted. Some cases require zero writes by design. The owner has removed the 0.8-second whole-CLI hard-limit requirement, but the replacement prestarted-guardian request path remains incomplete and G1 is still NO_GO. G4 installed native SDK provenance and the trusted account-wide writer/ActionRef/settlement gates remain open. No managed CTP write or live route is registered.

Next gates

Complete and independently accept the protected Windows service and request lifecycle, exact native SDK artifact and callback provenance, single-account owner/writer fence, settlement/risk checks, then run each case against the real SimNow counter with provider callbacks and baseline/final query evidence. Offline contract success never upgrades a certification case to PASS.

@cloudQuant
cloudQuant merged commit bf746c2 into dev Sep 28, 2026
33 checks passed
@cloudQuant
cloudQuant deleted the codex/iteration41-simnow-real-certification branch September 28, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants