Repository navigation
fix: make the C0.4 corpus prove what its cases claim - #22
Merged
Merged
Conversation
This addresses the RKOI review of the golden corpus v2 (#20). GENESISRAG17-RECEIPTS now demonstrates each of its assertions: - Wrong-hash, forged-stage, other-tenant, mismatched-scope and wrong-role graph receipts run before any receipt exists, so each is refused by its own check, and the refusal message is annotated. - After acceptance, an identical graph receipt is idempotent and a different one is a conflict. - Publishing before the quality gate is refused. - After a Stage 15 failure, the worker receipt is refused because the execution is terminal, the gate fails and publication is refused. The public evidence export and the store both show stages 9-14 SUCCEEDED, 15 FAILED and 17 FAILED. Normalization is narrowed so it cannot hide a regression: - Instants are normalized only inside the run's wall-clock window. - Durations and hashes the request itself carried stay literal. Worker durations are distinctive values, and the runner rejects any request duration under 1000 ms. - The runner recomputes decision, graph, worker and publication hashes with the contract functions GKS uses. - --write refuses a labelled value that is identical in both of its runs. Other runner changes: - A graceful stop must exit cleanly, the store path must not leak, and --case requires an id. - The legacy default portfolio differs from every explicit scope. AUTH-DENIAL covers both a scope-less and an explicit-scope envelope. - The manifest records productSha and corpusSha separately. better-sqlite3 is declared as a root devDependency: the runner and 12 test files import it from the root. The baseline lock is re-locked. No product code changes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR follows up the RKOI architecture review of the C0.4 golden corpus v2 (Freshair129/Genesis-Knowledge-System#20), which was merged before the review finished. The first review returned REVISION_NEEDED, with 3 claim-honesty findings and 10 warnings. After this change, the re-review returned APPROVED, and its three residual suggestions are fixed here too.
No product code changes. Everything here is corpus fixtures, the runner, tests and docs, plus one root devDependency.
Claim honesty in GENESISRAG17-RECEIPTS (must-fix 1–3)
Denials came from the wrong check. The wrong-hash and forged-stage graph receipts used to run after the first receipt was accepted. So they were refused as "a different receipt", whichever check actually existed. They now run before any receipt exists, together with:
Each denial now names its message through a new
toolMessageannotation, because several different checks all answergks_conflict. The "different receipt after acceptance" conflict is now its own step."A failed stage blocks publication" was not shown. The gate verdict looked the same with or without the Stage 15 failure. The case now shows the failure itself blocking the chain:
FAIL;gks_pipeline_evidenceexport and directly in the store.Ordering was never exercised. Publishing before the gate is now tried, and it is refused.
Normalization cannot hide a regression
<server-time>duration_mswas replaceddecisionHash,graphReceiptHash,receiptHashandpublicationHashwith the contract functions GKS uses. A value the request carried is never labelled.--writerefuses a labelled value that is identical in both of its runs.Other warnings
c0-legacy-default, which differs from every explicit scope, so a server that ignored an explicit portfolio would fail. AUTH-DENIAL checks both the scope-less API-010 payload and an explicit-scope envelope.productSha(apps, packages, migrations, package files) andcorpusSha(fixtures and tooling, excluding the manifest itself).--caserequires an id.better-sqlite3is declared as a root devDependency. The runner and 12 test files import it from the root and previously resolved it only through workspace hoisting.hasInstallScript: truefrom its lock entry; I restored it by hand.npm install --package-lock-only.Golden diff
Three golden transcripts change. Each change follows from a change to the fixtures, not from a change in the server:
duration_msvalues are now literal (4301–4303) instead of<duration-ms>.c0-legacy-default, so its knowledge and entity refs are different. The explicit-scope steps and the final count of 2 promotions are new.The other 21 transcripts are unchanged.
Test plan
Mutation checks. Each mutation was applied to product code, the corpus was run, then the mutation was reverted:
receiptHashcomputed over a wrong objectpublicationHashcomputed over a wrong objectNew contract tests pin the three normalization rules: the time window, echoed durations and request-carried hashes.
npm test: vitest 292 passed, 2 skipped (the MSP suites needMSP_REPO_ROOT); security 12/12; unit 9/9.check:c0: PASS 24 / NOT_RUN 1.check:baselineholds.check:corpuspasses on every run, and--writeagrees across its runs.RKOI re-review: APPROVED.
CI on this PR
🤖 Generated with Claude Code