Skip to content

[0.3.0 first half] L01 Evidence Core train — unstable → stable - #155

Open
mberrys wants to merge 56 commits into
stablefrom
unstable
Open

mberrys wants to merge 56 commits into
stablefrom
unstable

Conversation

@mberrys

@mberrys mberrys commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

[0.3.0 first half] L01 Evidence Core train — unstable → stable

This change promotes the first half of the 0.3.0 implementation, the first L01 Evidence Core train, from unstable to stable. Its architecture reflects version 0.3.0 of the alpha product. It adds the revision-bound Core inspection receipt (#16) and fences scheduled results by revision and request (#17). It qualifies hostile and production resource envelopes on hosted Linux and Windows runners (#19), and isolated PDF open/preflight now runs in a contained worker that speaks protocol v2 (#20). It also adds the tooling for exact-SHA Core qualification (#21) and separates live issue records from legacy ones (#111). The L01 milestone stays open: this release does not admit the Core module, and it closes only #16 and #19. The package version stays 0.2.1-alpha. docs/github-milestones/ has no file for L01, so the title names the train.

Scope: v0.2.1-alpha-248-g846e8694 (stable @ 846e8694) → 4388ca36 — 41 non-merge commits, 198 files changed (+8058 / −1994).
Canonical milestone text: none in docs/github-milestones/ for L01; GitHub milestone L01 - Evidence Core.

Added

  • L01-02 — Define complete inspection receipt #16: Core gains a typed inspection receipt bound to a revision. It has a stable identity for the same input and policy. Its verdicts fail closed: zero findings with missing required coverage is Incomplete, and unsupported, budget-limited, cancelled, or parser-error paths cannot coerce to PASS (b9caa53e).
  • L01-05 — Qualify hostile and production resource envelopes #19: PdfTool benchmark --profile adds a measured preflight phase, which is sampled for very large fixtures. A new resource-envelope qualification workflow generates a deterministic synthetic fixture bundle and runs the strict matrix. The matrix includes cancellation and reopen-after-cancel probes and a hostile budget-exhaustion lane. The workflow emits schema-2 evidence that carries the CI run id. Crashes, timeouts, and skipped workloads never count as a passing envelope. Failing records print per-record reasons, render errors, and stderr (be4edcd4, d7eeebb7, c9af5df2, f8b46038).
  • L01-05 — Qualify hostile and production resource envelopes #19: Evidence collection and colour inventory now honour cancellation. Rendering stops within one page slice of an interrupt, and Windows honours CTRL_BREAK (4d9d02f0).
  • docs/: Records two Quick canvas-editor gaps: the inert Select/Hand toolbar controls and the DragSession commit that is discarded. Each gap is recorded with the boundary and contract constraints that make it a decision rather than a patch (8362ae45).

Changed

  • L01-05 — Qualify hostile and production resource envelopes #19: Envelope budgets are pinned to measured runs. Three rasterizers are pinned to fit the raster-tile budget at 300 DPI. The active-model pool rises to 640 MiB and the 10k render cap to 600 s. The 500 MB fixture gets its own process RSS cap. The colour-inventory probe is capped, the cancel probe runs render-only, and each benchmark process gets 1800 s (648d160b, 04ead25a, 14264ad6, 8a789dd9, 0f10c873).

Fixed

  • L01-03 — Fence scheduled and worker results #17: Scheduled document work is fenced across close and reopen. Rendered results and Editor results are admitted only under their current request identities, so a worker success or a matching page number alone cannot publish a stale result (626ce488, d297f8e5).
  • Operation history: when history retention fails after an accepted rollback or repair, the restored revision stays open and the repair report is still written. Every preflight report's coverage claim again carries the general "no formal GWG conformance" statement (78934b17).
  • pdfrenderer.cpp: the renderer holds the rasterizer until its page image has been consumed (f6b48584).
  • L01-05 — Qualify hostile and production resource envelopes #19: The Linux VmHWM reader uses readAll, so peak-RSS readings no longer come back short (7d24c836).

Security

  • L01-06 — Audit untrusted PDF process isolation #20: Isolated PDF open/preflight requires Linux or Windows containment. Bounded protocol v2 worker responses are admitted only through Core inspection receipts. Worker faults and document content stay out of supervisor diagnostics. Protocol v1 peers are rejected (4bcd75de, 67ef0685, 173a156a).

Internal

  • L01-01 — Pin reset truth and evidence obligations #15: Pins the loop2 Evidence Core source SHA, the inherited contracts, catalog coverage, legacy gap dispositions, and proof limits for L01-01 (b6e5ff01).
  • L01-07 — Admit exact-SHA Core qualification #21: Adds an exact-SHA CI/package provenance checker with focused Linux and Windows script tests, plus an issue-dossier runbook (4978932b).
  • G00-01 — Re-home legacy issue provenance after the repository rename #111: Preflight catalog overlay records now carry repository, and legacy snapshots are keyed legacy#<n>. --verify-github reads each record back and rejects a missing issue, a pull request, or a changed title, state, or milestone. Sixteen backlog rows re-point to reset issues. 25 of 28 legacy links under docs/ become legacy #<n> text, and the convention is recorded in docs/LEGACY_ISSUE_PROVENANCE.md (54c174b5, 1e9118c0, 6aee33dd).
  • Tool tree: the standalone developer and qualification apps move under tools/, together with their CMake, source, evidence, and CI test paths (33a81a9f, 454dae64, 0f63fd7d, 57f7abc7).
  • Agent gate: scripts/agent/check-change.py runs mapped CTest with the Release configuration, so it works on multi-config builds (2bd7d2a9).
  • Promotion tracking: linked issue work is tracked through dev → unstable → stable in the organization's Promotion stage field. The legacy queue label and the stable-branch auto-close behaviour are retired (43f22c16, a7c9078a).
  • PR template: the "Anti-slop pass" section becomes "Quality pass", and the agent-policy handoff asks for a quality summary (86ef0ff4, d6238b43).

Closes

Each issue requires acceptance evidence, not just a merged implementation. An issue is closed below only if its acceptance-evidence comment, posted against 4388ca36, cites hosted runs for every criterion and failure case. stable is the default branch, so these keywords take effect when this PR merges.

Closes #16 — evidence: #16 (comment) (Release Gate run 36782669896).
Closes #19 — evidence: #19 (comment) (Resource envelope qualification run 36782669570). Remaining risk noted there: the measurements are not yet recorded under docs/evidence/issue-19-resource-envelope/.

Refs #15 — outstanding: docs/EVIDENCE_CORE_RESET_INVENTORY.md was pinned at 5c8366a3 and has no recorded review. At 4388ca36 it is stale: the backlog SHA-256 no longer matches, and 8 gaps it lists as "unfiled" now point to #113–#120.
Refs #17 — outstanding: no fault-injection test covers the verdict-publication identity checks added to LoopEditor/editorhost.cpp in 626ce488.
Refs #20 — outstanding: docs/PDF_WORKER_ISOLATION_AUDIT.md still lists 12 in-process routes as release blockers. Linux runtime qualification, Windows installed-product qualification, and dump-collector qualification are not done.
Refs #21 — outstanding: every required L01 lane passing on one selected SHA, with reviewer acceptance; final module admission stays pending.
Refs #111 — outstanding: 3 legacy links in docs/GOVERNED_EXECUTION.md and ADR-011, which wait for a change that carries the governed-execution proof lanes.

Verification

Checks on this PR at head 4388ca36 (gh pr checks 155): linux, windows, linux / build, windows / build, fuzz, fuzz_regression / fuzz, evidence, agent_contract, package_contract, supply_chain, source_integrity, policy, architecture-docs, documentation, release_ok, promote, CodeQL (actions, c-cpp, python), and Semgrep all report pass. agent-fast and the package-script workflow's linux/windows jobs report skipping. Merge state: CLEAN.

Breaking changes

#20 is a breaking change: the isolated worker rejects protocol v1 peers. A supervisor and its worker must ship together at protocol v2, and a mixed-version pair fails closed instead of falling back. #20 is the only fragment in this range marked Breaking-Change: yes.

🤖 Generated with Claude Code


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

mberrys and others added 30 commits September 22, 2026 14:46
…led-results

L01-03: fence scheduled and worker results
Two unimplemented Quick canvas-editor gaps, verified against origin/dev at
e995373:

- ShellToolBar's Select and Hand buttons are checkable but inert.
  InteractionController::m_activeTool is write-only, so wiring the existing
  setter would make dead controls look live without changing behavior.
- EditorHost::onDragCompleted discards the DragSession it is handed. Routing
  it needs a move/translate command that does not exist in the 107-ID action
  catalog, which is schema-validated and protected.

No production source is changed. Both gaps are tracked as #103 and #104.
A retention failure after an accepted rollback or repair no longer hides
the published result: the editor still opens the restored revision and
refreshes its rollback points, and repair writes its report and registers
its outputs before enforcing retention. The per-run preflight coverage
claim again states that Loop makes no formal GWG conformance claim for
every profile family, alongside the sheetfed-offset/packaging limit.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(history): keep accepted outputs reported when retention fails
docs: rename PR template anti-slop pass to quality pass
PdfTool benchmark gains a measured preflight phase (--profile), renders in cancellable slices, and handles SIGBREAK on Windows. A synthetic fixture generator, cancellation/recovery probes, a hostile corpus lane, schema-2 evidence, and a hosted Linux/Windows qualification workflow make the strict matrix runnable in CI.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
QFile::atEnd() is true immediately for procfs files, so
currentRssHighWaterBytes() always returned -1 on Linux. That left
preflight_high_water_bytes at -1, failing
benchmarkWithPreflightProfileIsComplete and flagging every Linux matrix
record as unmeasured.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
The job log only carried summary counts, so a failing hosted run could
not be diagnosed without downloading the matrix artifact.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
Exit code 5 (PartialOutput) alone does not say which page failed or why.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NT3L5ao8UyQuTPPKySRDcP
mberrys and others added 20 commits September 28, 2026 20:06
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…llation

PDFEvidenceCollectSettings and PDFColorInventorySettings gain an optional
operationControl. The colour inventory polls it per page and reports
cancelled; the evidence collector polls it per page and returns an
incomplete graph with incompleteReason "cancelled". PreflightEngine passes
its operation control through and reports errorCode "cancelled" instead of
evidence-incomplete, so an interrupt during the benchmark's preflight phase
stops within one page instead of after the whole document.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Preflight renders and walks every page it covers, about 0.5-0.7 s per page
on a hosted runner, so a full pass over the 10,000-page fixture cannot fit
any practical timeout. benchmark gains --preflight-page-last <n>, which
limits the preflight phase to pages 1..n while rendering still covers every
page. PDFEvidenceCollectSettings and PDFColorInventorySettings gain
pageIndices so the render and content walk skip pages the profile scope
already discards. run_matrix.py passes 256 for fixtures above 1,000 pages
and records it as profile.preflight_page_last.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…e render-only

The hostile raster-probe-pixel-budget case reached 15 GB RSS on both hosted
platforms: the colour inventory probes each page at 150 DPI with several float
bitmaps per pixel and no size limit. PDFColorInventorySettings gains
maxProbePixels (2.5 million); larger pages are probed at a proportionally
lower DPI.

The cancellation probe ran with the preflight profile, whose document-wide
setup does not poll for cancellation, so latency was 11-16 s against a 5 s
policy. The probe now interrupts a render-only run, like the recovery probe.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…der cap to 600 s

The 500 MB image-heavy fixture's document-model estimate exceeds the 256 MiB
active-document-model pool, so the benchmark rejects it before rendering.
The pool default becomes 640 MiB, still under the 768 MiB resident ceiling.

Three rasterizers on a hosted runner render the 10,000-page fixture in about
350 s (Linux) to 510 s (Windows), over the 120 s synthetic-image-heavy cap.
That workload's wall_time_ms becomes 600000; the DIV2K workload keeps 120000.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
image-heavy-500mb now renders all 60 pages (the active-model pool no longer
rejects it), but its process RSS peaks at about 1.7 GB in the preflight
phase on both platforms, against the 768 MiB resident limit. The reader
holds the whole file and its object model, so the peak scales with file
size. The fixture maps to a new large-document-500mb workload with a 2 GiB
RSS cap; the resident-limit check in run_fixture uses a workload's own RSS
cap when it declares one. Every other fixture keeps 768 MiB.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Resolves conflicts from unstable moving the tool executables under tools/:
scripts/ci/check_loop_identity.py takes unstable's tools/ entrypoint paths,
and docs/generated/phase5-widgets-inventory.json is regenerated with
scripts/generate_phase5_widgets_evidence.py --write.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
unstable moved CodeGenerator and ProductQuickAccessibilitySmoke under tools/;
two tests that dev carried still used the old root paths.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
agent-fast builds every changed target, and the tools/ move made the
CodeGenerator, JBIG2_Viewer and PdfExampleGenerator sources count as changed
while the distribution profile leaves those targets unconfigured. Fast mode
now turns them on; the full release-profile build is unchanged.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
The 10,000-page fixture renders within its 600 s cap but also runs a sampled
preflight phase and process start-up; the hosted Linux run exceeded the 900 s
process timeout on this merge. The 600 s render cap is unchanged.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Merge pull request #151 from studio-berry/docs-quick-canvas-editor-gaps
…tion

#20: Harden isolated PDF worker containment and receipt admission
@mberrys mberrys added enhancement New feature or request bug Something isn't working documentation Improvements or additions to documentation labels Oct 1, 2026
@mberrys mberrys added this to the L01 - Evidence Core milestone Oct 1, 2026
@mberrys mberrys changed the title Unstable [0.2.1-alpha] L01 Evidence Core train — unstable → stable Oct 1, 2026
@mberrys mberrys changed the title [0.2.1-alpha] L01 Evidence Core train — unstable → stable [0.3.0 first half] L01 Evidence Core train — unstable → stable Oct 1, 2026
buildPreflightInspectionReceipt left incompleteCoverage unset when the
evidence graph had no references, so a clean run produced a PASS receipt
with "not-recorded" fidelity that preflightInspectionReceiptFromJson
rejects. The builder now matches the parser and reports Incomplete.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working documentation Improvements or additions to documentation enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

L01-05 — Qualify hostile and production resource envelopes L01-02 — Define complete inspection receipt

2 participants