Skip to content

L04-06: revalidate exact published bytes with explicit state and impact scope (#38) - #216

Merged
mberrys merged 3 commits into
l04-05-execution-gatewayfrom
l04-06-published-bytes
Oct 5, 2026
Merged

mberrys merged 3 commits into
l04-05-execution-gatewayfrom
l04-06-published-bytes

Conversation

@mberrys

@mberrys mberrys commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Summary

L04-06 (#38), slice 6 of the L04 Governed Operation Engine stack (refs #5). Revalidation now reads the bytes that were actually published, names its outcome in explicit states, and can run an impact-driven targeted inspection instead of always running the full profile. The finding delta is computed on the published bytes and folded into the revalidation report digest, so sign-off sees a final-byte verdict.

Stack position

Slice 6 of 8. Base: l04-05-execution-gateway (#215). Children stack on this branch; land bottom-up.

Per-criterion: already satisfied vs built here

Acceptance criterion State Proof
Sign-off sees a final-byte verdict machinery already satisfied; state + delta built here PDFGovernedExecutionRevalidation gains state (complete/incomplete/error), reason_code, reason; isSignOffEligible requires complete; the finding delta + scope mode + baseline digest are folded into the report so reportSha256 covers them
Explicit incomplete/error states built here byte failures named (artifact-unreadable, artifact-digest-mismatch, artifact-reopen-failed); an empty expectedSha256 is refused (expected-digest-missing) instead of silently skipping the binding; surface statuses extended (repair report, action-list governed summary, PageMaster manifest)
Impact-driven vs full inspection built here PDFGovernedRevalidationScope (plan + impact + baseline); a targeted plan is honored only when the declared impact is complete and a baseline exists; undeclared/incomplete/document-wide/no-baseline fall back to full (fail-closed); targeted-vs-full equivalence fixture
Failure: in-memory candidate or pre-publication bytes cannot close the operation built here explicit slot; the Editor worker's temp-bytes path was already closed by #37's gateway routing (finalizes against the exact staged bytes) — verified on this base, no submitter change needed

Required proof

  • python scripts/agent/check-change.py --base e16a8cd4 --head cf015d5e --head-branch l04-06-published-bytes --build-dir <loop-build-l04> -> status: pass, 77/77 checks (LoopLibCore/PdfTool/loop-pdf-worker builds, mapped suites, clang-tidy, format, changelog, architecture contracts).
  • Provenance: the proof was recorded at the pre-rebase head 8ade7579. The stack rebase left this slice's own diff unchanged (patch-id verified) and the only later edit is a documentation-only fragment correction, so the proof carries for the code; CI re-runs the mapped lanes on the head above.
  • Focused: UnitTestsGovernedExecution (45/45 slots) / UnitTestsOperationImpact / UnitTestsPdfToolContract / UnitTestsPageMasterExport / UnitTestsActionList -> 5/5; 8 adjacent targets -> 8/8.
  • New slots: empty-digest refusal, tamper + restore re-read, incomplete state, targeted-vs-full equivalence + delta, undeclared-impact fallback, in-memory candidate cannot close.
  • Architecture: check-architecture.py, test_architecture_contracts.py, test_check_governed_parity.py -> green.
  • Pre-existing flake UnitTestsPdfWorkerIsolation supervisorFaults(cpu) is a razor-margin race against the 135s client timeout #211 can redden a mapped run; CI agent-fast is authoritative.

Notes

  • Closes #38.
  • Profile resolution mirrors PreflightEngine::run(QJsonObject) so the effective profile digest is unchanged for existing callers.
  • Breaking-change: no.

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@mberrys
mberrys force-pushed the l04-06-published-bytes branch from 276942c to cf015d5 Compare October 5, 2026 14:04
@mberrys
mberrys added this pull request to stack #220 October 5, 2026 21:52
@mberrys
mberrys merged commit bef8e06 into l04-02-save-impact-policy Oct 5, 2026
3 of 5 checks passed
@mberrys
mberrys deleted the l04-06-published-bytes branch October 5, 2026 22:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant