Skip to content

Fix bare-Potato material identity and preserve mapping-refresh provenance - #1239

Merged
realmarcin merged 4 commits into
masterfrom
fix/mediadive-potato-scope-1236
Sep 29, 2026
Merged

realmarcin merged 4 commits into
masterfrom
fix/mediadive-potato-scope-1236

Conversation

@realmarcin

@realmarcin realmarcin commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Scope

Addresses #1236 and #1237. This does not close the broader #286 CAS-curation or
#650 MicrobeDecoder work, and it does not certify a production KG release.

Bare Potato does not establish the extract-specific identity represented by
cas:93348-51-7. Apply the narrow reviewed name/target exclusion across unified,
strict/hydrate, embedded-CAS and nested solution-name routes. Preserve the recipe
observations and their source-local ingredient identity; do not infer another
chemical, registry or botanical target. Explicit extract names, direct registry
queries and distinct preparations such as Potato flour are not blanket-excluded.

The MediaDive producer retains original mapping claims separately in a mandatory,
producer-bound material-scope audit. It preserves full claim rows, source recipe
JSON, input hashes and record locators, distinguishing explicit starting-material
form from insufficient specificity. Finalization/admission verify the audit and
its actual consumed inputs; they do not invent a registry assertion in the recipe.

Mapping candidate and provenance

  • The identity-only unified refresh removes exactly one complete historical
    Potato lexical row. All other mapping row bytes and order remain unchanged.
  • The reviewed candidate is
    09c44642ab13b234e89ce113f7510aa9efb56969e4b539cb7843b43dcb425ba7:
    591,949 rows, 120,183 targets, 336,050 exact matches and 255,899 close matches.
  • The supported MIM product and immutable release pin remain byte-identical;
    this is not a new upstream MIM release or export.
  • Fix the identity-only writer's metadata: truthful tool/version, semantic YAML
    description preservation, one policy fingerprint, and fail-closed malformed
    metadata handling. Unrelated metadata stays byte-identical. Original
    reconstruction provenance remains bound to the saved baseline review.
  • A second refresh produces exactly the same compressed bytes with zero further
    removals/relabelings. Fresh lookup checks reject the reviewed bare-Potato
    variants and retain four CAS controls plus Potato flour.

The accepted candidate is staged only in the isolated worktree. The production
checkout has not been promoted by this change. See
docs/reviews/mediadive-potato-scope-20260929/PROMOTION.md for exact hashes,
retained evidence and the remaining gates.

Review and validation

  • Independent policy/runtime/metadata review and finite candidate review are
    complete; review findings Identity-only SSSOM refresh corrupts writer provenance and YAML description metadata #1237 were addressed before regenerating the accepted
    candidate.
  • Metadata-focused verification: 49 authored and 18 independent cases, plus five
    existing focused checks, passed.
  • Native mapping-pair and legacy predicate-semantics modules: 19 passed, including
    an independent rerun. Historical invalid-CAS/native-category controls and their
    immutable fixtures remain intact. Ruff and git diff --check passed for these
    updates.
  • Independent source-comparator review: 33 authored plus eight independent tests
    passed. This is helper verification, not acceptance of an actual replay.
  • The completed baseline is retained byte-for-byte. The current baseline cohort
    was rediscovered from its exact raw recipe witnesses, not assumed from a
    historical count.

Actual isolated MediaDive replay and its full-row comparison have now passed.
The real producer exited zero, native finalization/fingerprint checks passed,
and all protected inputs/outputs remained unchanged. Both versions contain
32,134 nodes and 113,926 edges. Exactly nine raw-bound Potato assertions change
only their object to the source-local ingredient; all 113,917 unrelated edges
are identical. Eighteen complete strict/hydrate mapping claims remain in the
producer/finalizer-bound audit. Explicit review accepted the sole node
replacement as source-local material retention, without invented equivalence.

Execution receipt SHA-256:
ee9c6861e6c7523441fd538bc0b2d0d54977523345a02253743e6034784388b5.
Full comparison SHA-256:
a190d364ced27310741cef657b5d5c0edf81f86dd2011af325b900c7d61485f5.
Evidence is under
data/issue1224-quarantine-20260929.xjuS9H/issue1236-review/, summarized in
ACTUAL-REPLAY-ACCEPTANCE.md. These checks prove the finite source change, not
universal scientific correctness or merged-KG acceptance.

Full CI at reviewed head 99a35c93c1b5155a6584a5b7823630b5999efae8 exposed
a test-fixture integration omission, tracked as #1240: three inert MediaDive
fixture setups omit the new mandatory producer audit. Python 3.10 and 3.12
pytest logs each report 17 failures and 13 errors with that same cause. The
already-failing local full suite was deliberately interrupted before editing;
it is not a passing gate. The fixture-only repair at
df7fb08a95a8724a6fe5aa791bf4d117bc183aa4 now exercises the real audit writer
without weakening runtime admission. All 174 focused cases pass; independent
review passed 81 selected cases and separate missing/unrecorded/tampered-audit
rejection probes. Only three test files changed; the production runtime,
mapping pair, pin and actual replay outputs are unchanged. This addresses
#1240 but does not turn the earlier failed run into a passing one.

CI passed on all three versions at df7fb08a95a8724a6fe5aa791bf4d117bc183aa4.
Its local full pytest nevertheless exposed a second test-isolation defect,
#1244: two category tests constructed MediaDive using unrelated default bulk
inputs when local production ontology files existed; CI had skipped them.
That local result was two failed, 4,926 passed and 15 skipped, not acceptance.

The test-only repair at 03dd4bc918566ceffd43692ef1ed865419a441aa exercises
the real BacDive/MediaDive category loaders on an immutable three-node fixture,
with unrelated defaults both absent and populated. Constructors, unrelated I/O
and network calls are guarded; there are no production-existence skips. All
34 authored tests and four independent adversarial probes pass. Runtime,
mapping/pin and accepted actual replay files remain unchanged.

Fresh full repository gates and all three CI versions are now running at
03dd4bc918566ceffd43692ef1ed865419a441aa (QC run 36561435972).
Do not merge before those checks pass. Fresh production
transforms, merge admission and KG model/path/release checks remain separate
after integration.

@realmarcin

Copy link
Copy Markdown
Collaborator Author

Independent adversarial review approved exact head 99a35c93c1b5155a6584a5b7823630b5999efae8 (tree 6c6b120491dff31b318ea0dfd833c64df43fa8fa) for the bounded source/mapping change. No new actionable blocker was found. The review checked the complete 14-file integration, native finalization/admission binding, fallback claims after removal of the unified row, metadata atomicity, and narrow material scope.

Executed on this head: 35 focused offline tests passed. The separate 19 native-pair/predicate tests passed against the byte-identical committed candidate. The actual mapping refresh and second cycle agree on SHA-256 09c44642ab13b234e89ce113f7510aa9efb56969e4b539cb7843b43dcb425ba7.

Review evidence: data/issue1224-quarantine-20260929.xjuS9H/issue1236-review/final-head-review.md, SHA-256 3dc79dc17cb4c71098fcbda0f10ba88c7bab39155b1c4a25a93372eee3a58fe7.

This is independent source/mapping review, not completed release acceptance. The actual isolated replay/comparison, full repository gates and CI are still pending; a fresh all-source production rebuild and candidate KG review remain subsequent work. No umbrella issue closure or publication is implied.

@realmarcin

Copy link
Copy Markdown
Collaborator Author

All required local gates now pass at exact PR head
03dd4bc918566ceffd43692ef1ed865419a441aa:

  • poetry run pytest: 4,952 passed, 15 skipped.
  • poetry run tox: all six environments passed; its full pytest again reports
    4,952 passed, 15 skipped.
  • poetry check --lock: passed.
  • python scripts/generate_merge_configs.py --check: passed.

The original full-pytest receipt is preserved at
repository-gates-bzgy3l1i/results.json, SHA-256
899964aeb5f4c578fb935038ec33ad0c88568a096adb5d7d08821520f4ff221d.
That attempt's later tox collection failure is not relabeled as a success.
#1251 was diagnosed as missing dependencies in the local tox environment plus
inherited Conda selection. After an independently reviewed isolated locked
dependency setup, the remaining default tox/lock/config commands passed at the
unchanged clean source head. No tests were selected away or disabled.

Terminal retry receipt: remaining-gates-tiiaqg7v/results.json, SHA-256
f62091753146d394885f70fd8d68636ffc1c7428320485f6bfd27bb579ca3777.
Full tox log SHA-256:
457a6a753ac7ad155ee6e9bbadb55f8f4f3302fba5ec07f3094d2ee0a57a3b43.
The pre-existing approved .venv link is untracked; tracked files are unchanged.

Independent source/mapping review and actual isolated MediaDive replay passed
for the byte-identical runtime. The subsequent #1240/#1244 changes are separately
reviewed test-only repairs. Exact-head QC run 36561435972 passed on Python
3.10/3.11/3.12. These satisfy the user's condition for an admin approval bypass.

This is bounded PR acceptance, not the final combined materials correction,
all-15 production rebuild, merged graph acceptance, publication or release.
Evidence root: data/issue1224-quarantine-20260929.xjuS9H/issue1236-review/.

@realmarcin
realmarcin merged commit c7dae95 into master Sep 29, 2026
3 checks passed
@realmarcin
realmarcin deleted the fix/mediadive-potato-scope-1236 branch September 29, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant