Repository navigation
Add country-neutral Orrery execution evidence and UK contracts - #1144
Conversation
Measured against Orrery 0.6.1 with the maintained UK dense declaration
(76 operations, 5,355 presentation nodes) and recorded synthetic runs,
the first export landed badly in the viewer: cards hid gate verdicts
behind execution and cache badges, every replay phase relabelled
computed operations as cache hits, each column file became its own
artifact reference, the compiler schema was embedded twice, and the UK
substring grouping put 65 of 76 operations in "enrichment".
Shared exporter
- Contain each field node in the operation that provides it, so folding
an operation or group folds its versioned fields; describe fields by
population version and provider; label declared reads.
- Lead gate kernels with the gate badge and omit it elsewhere; summarise
the cache state across every supplied phase ("Computed: numerical ·
reused 2×", "Reused: 3 cache hits; computation not in supplied
phases") instead of reporting the last replay.
- Emit one artifact reference per content-store object with its byte
digest when it is a single file; keep per-file digests in the phase
record; attach native run files to activities only.
- Name the executing kernel as each activity's agent and record the
kernel role per phase.
- Put the presentation scope into the document id and default title.
- Replace the embedded compiler schema with a digest-bound summary.
- Add shared helpers: save_graph_schema (copies and relinks checkpoint
bytes), checkpoint_references (links only verifiable files, names
absent ones with their digest), publish_run_evidence (flat publication
merged across attempts, refusing files that no longer verify).
UK contracts
- Replace substring grouping with an explicit roster and group
descriptions; unrostered operations land in "other" and the maintained
declarations are tested to have none.
- Summarise spine, full and national gate reports per gate through the
summary registry, and record the spine's execution evidence index as
a checkpoint reference.
- Wire the spine driver to the UK summary providers and the drivers to
the shared helpers.
The contract check asserts badge policy, containment, agents and
aggregated artifacts rather than a badge count.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Automated review pass (Claude Code, high effort) — round 1 at
|
- Update the UK spine export test to the digest-bound schema summary (the engine-free lane stopped there). - Make evidence capture inside a build diagnostic: a summary provider that raises is recorded as provider_failed with its error beside the artifact binding and the build continues. The explicit export command still runs providers strictly. - Record the spine checkpoint's graph, manifest, schema and evidence links relative to the sidecar, so a checkpoint moved with its evidence directory keeps resolvable links and no machine-local path is stored. - Shape-check composite metadata in the presentation contract. - Write copied checkpoint bytes and published evidence files atomically. - Drop the unreferenced spine.graph-declaration.json write. - Document that execution exports from licensed runs need the same output clearance as the diagnostics they summarise, say that the serialized string bound applies to every string, and reword the weight-summary docstring. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Append the wall time and peak RSS of each phase's evidence capture to evidence-capture-timing.jsonl beside the build (and the spine checkpoint), so a real rung reports what the summary providers cost. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The two pre-Alembic spool tests stored rows dated 2 October 2026; once the retention prune's cutoff passed that date, adoption deleted the rows and has_pending() was False. Stamp the rows one hour before the test runs. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Automated review pass (Claude Code, high effort) — round 2 at
|
| # | Item | Status |
|---|---|---|
| 1 | test_uk_graph.py expected the full schema |
Fixed: it now checks the digest-bound summary. |
| 2 | Evidence capture could fail a good build | Fixed for providers: in-build capture records provider_failed with the error and carries on, while the explicit export stays strict (evidence.py _summaries(strict=False)). Tested. Non-provider failures in capture, such as the 32 MiB evidence cap or publish verification, can still abort a build; that's fine as is. |
| 3 | Absolute paths in the spine sidecar | Fixed: graph, manifest, schema and evidence links are relative to the sidecar (spine_build.py _checkpoint_link). The tests resolve them from the sidecar's folder. |
| 4 | Disclosure guidance and the weights docstring | Fixed: docs/orrery-adapter.md says licensed-run exports need output clearance before anything public, and the docstring now says the extremes and quantiles are individual weight values. |
| 5 | String limit applies to every string | Documented. |
| 6 | Composite records not shape-checked | Fixed, with tests (presentation.py). |
| 7 | Orphaned spine.graph-declaration.json |
Removed; the sidecar now points at the declaration inside the evidence bundle. |
| 8 | Non-atomic writes | Fixed: checkpoint bytes and published evidence go through _atomic_bytes. |
New
- Should: the capture-cost numbers are in the wrong unit on Linux, and don't measure capture (
full_build_cli.py_record_capture_cost,spine_build.py:~1912-1942).ru_maxrssis kilobytes on Linux and bytes on macOS. The fields are named*_bytesand the log divides by 2**30, so on a Linux build host a 10 GiB peak prints as about 0.01 GiB.- It's also the process's lifetime peak, so after a solve the "before" and "after" values will usually be identical, and the record won't show what capture itself costs.
- Fix: normalise the unit by platform (multiply by 1024 on Linux), and record a measure that reflects capture. For example, take the current RSS before and after (psutil, or
/proc/self/statm), or usetracemallocpeak during capture. - Smaller point: the jsonl append isn't guarded, so a write error there would fail the build, even though the docstring calls it "a measurement, not a gate". Wrapping it in
try/except OSErrorwith a warning would match the intent.
- Nit: provider error text goes into the export unbounded (
evidence.pyrecord["error"] = f"{type(error).__name__}: {error}"). An exception message can carry values from the frame. Truncating it, say to 500 characters, and keeping the type name keeps record-level values out of an export. - Nit: an errored summary is cached and reused for later phases without a retry. That's probably intended, but worth a line in the docstring.
CI
Lint, wheels, select-countries, both engine-uk lanes and integration-uk pass. engine-free and engine-us were still running. 5fa47f42 restamps the two spool adoption tests relative to now, so the date-dependent failure that also hits main shouldn't recur here. Main still needs the same fix until this merges.
UK graph exports currently show the declared graph without enough evidence to explain a recorded build or connect it to upstream checkpoints. This builds on #888 by adding country-neutral presentation and execution contracts, then supplying UK metadata and aggregate artifact providers through adapters.
Changes
--evidenceand--storeinputs. Orrery JSON and HTML remain explicit exports; builds save native evidence, not automatic viewer snapshots.Country details enter through presentation metadata and registered artifact-summary providers; the shared schema and execution code do not dispatch on UK-specific names. Detailed value lineage (#865), new visualizer features, and published demonstrations remain separate work.
Validation
Production declaration export through both spine/full gate batteries, holdout and export preparation: 77 operations, 5,156 presentation nodes, 19,593 edges, accepted by Orrery 0.6.1. The actual 65,971-character full gate contract now round-trips; focused schema, Orrery and UK presentation tests: 45 passed. CI for
e0ba98ais pending.Prior 10 GitHub Actions checks passed on
383fe76: engine-free, UK, and US suites on Python 3.13 and 3.14; UK integration; lint; wheel packaging; and country-test selection. Each engine-free suite reports 14,892 passed, 140 skipped.Registered engine-free suite: 14,888 passed, 142 skipped, with Hugging Face offline mode. Final focused checks after the last changes: executor/evidence 111 passed, dense driver 44 passed, and UK calibration/national evidence 56 passed.
Ruff, test-plan registration, graph acceptance registry, and diff checks pass. Frozen graph declarations and kernel interfaces are unchanged.
Orrery 0.6.1 public parser and browser checks cover groups, Record, Sources, Activity, and independent status badges. A synthetic export retains all 22,053 calibration targets; maintained UK dense and size graphs remain within exporter limits.
A separate online run reproduces an existing live-loader mismatch:
uk-2025-nationalexpects amicrocosm-uk-2025-release, while the current pointer resolves tomicrocosm-uk-2024-25-national. The loader and its test are unchanged.UK staging smoke integration: 2 passed, including export of the saved native evidence with the full gate declarations. Country-engine suites and a licensed population build were not run locally; UK driver tests use synthetic fixtures.
Closes #1079
Closes #1080