Skip to content

Commercial Research Beta release candidate#113

Draft
YuzeJ21 wants to merge 329 commits into
mainfrom
codex/personal-research-mode-mvp
Draft

Commercial Research Beta release candidate#113
YuzeJ21 wants to merge 329 commits into
mainfrom
codex/personal-research-mode-mvp

Conversation

@YuzeJ21

@YuzeJ21 YuzeJ21 commented Jul 18, 2026

Copy link
Copy Markdown
Owner

Current stage

Local Commercial Research Beta release candidate. Priority 4 remains frozen; the first provider-neutral Priority 6 workspace-authorization slice is implemented, hardened, reviewed, documented, and exact-head verified at 369da3a13cac2016300d4b8f08e2306d0f1bac7f.

PR #113 remains open and draft. Do not merge or deploy publicly. The product remains research-only and is not a hosted, calibrated, externally validated, production-operated, or investment-decision product.

Product workflow

  • Research Desk -> Discover -> Company Workbench -> Monitor
  • Research Decision Lab and append-only thesis/evidence/catalyst/outcome authoring
  • SEC quarterly actual lineage with explicit filed-Q4 and EPS split-basis boundaries
  • Earnings Nowcast readiness and five-company cohort board
  • Prospective point-in-time consensus contracts
  • Historical Valuation Regime, Research Outcome Review, Catalyst Evidence Timeline, Forward View, Scenario Lab, peer read-through, and source freshness
  • Independent readiness states for actuals, consensus, Revenue, EPS, valuation, catalysts, outcomes, backtesting, and calibration

Priority 6 workspace authorization slice

The approved design and test-first plan are:

  • docs/superpowers/specs/2026-07-26-provider-neutral-workspace-authorization-design.md
  • docs/superpowers/plans/2026-07-26-provider-neutral-workspace-authorization.md

Implementation lineage:

  • 9cdd8be024d543bc4f3bf3df67eed74a1d80533d — frozen trust-boundary types, exact structural validation, and fail-closed malformed-input behavior
  • 867556cd6cc196028f76400c675a746f8c5d309c — user-approved audit-field plan clarification
  • b6108a3629ee94f9c191f6488e76f7d6e7e9c015 — deterministic principal/workspace isolation, least-privilege policy matrix, append-only protection, and audit obligations
  • 3c5a2bc8fc47ac144290087e9dad513bb683252c — architecture, roadmap, continuation-contract, and public documentation evidence
  • 90b441d25e97655e887803d88f4730497e71e383 — final trust-boundary hardening for incomplete exact-type inputs, cumulative denial-order tests, mutation-proof assertions, and stronger hosted non-claim regressions
  • 369da3a13cac2016300d4b8f08e2306d0f1bac7f — final continuation-lineage reconciliation

The pure src.hosted_access_control.evaluate_workspace_access() contract now:

  • denies missing or malformed inputs by default;
  • requires authenticated principal, matching principal membership, active membership, and exact workspace match in deterministic order;
  • allows only explicit role/resource/action matrix entries;
  • prevents every role, including owner, from updating or deleting append-only research records;
  • returns stable privacy-safe reason codes and an immutable audit obligation for every allow or deny;
  • uses only the Python standard library and performs no file, environment, network, provider, dashboard, ledger, readiness, persistence, or generated-artifact operation.

This is local software evidence only. It does not implement or prove identity-provider authentication, deployed workspace isolation, hosted persistence, durable audit storage, retention/deletion execution, monitoring, health checks, backup, rollback, incident response, named operating capacity, external-user validation, market demand, or market readiness.

Verification at exact head

Local verification on the synchronized product tree:

  • focused authorization/private-beta/public-doc suite: 194 passed
  • complete suite: 4,209 passed, 1 environment-limited socket test skipped, 1 existing dateutil deprecation warning
  • commercial-beta contract: passed
  • Research route render: passed through the repository-native read-only render target
  • performance contract: passed without generating timing artifacts
  • public wording: passed, 48 files scanned
  • browser QA evidence: ready against existing committed assets
  • pilot readiness: truthfully blocked
  • diff hygiene and whitespace: passed
  • generated-artifact fingerprint remained unchanged

Exact-head GitHub Actions run 30191193745 completed successfully at 369da3a13cac2016300d4b8f08e2306d0f1bac7f:

  • full test suite: passed
  • dashboard startup: passed
  • Personal Research route render: passed
  • public wording: passed
  • PR-range generated-artifact hygiene: passed
  • whitespace: passed

Exact slice hygiene

The implementation range from a1379aa04d8ced420ceaab37eeb31235e53357b9 through 369da3a13cac2016300d4b8f08e2306d0f1bac7f contains exactly seven intentional paths:

  • ROADMAP.md
  • docs/PRIVATE_BETA_ARCHITECTURE.md
  • docs/internal/COMMERCIAL_RESEARCH_BETA_CONTINUATION_GOAL_PROMPT.md
  • docs/superpowers/plans/2026-07-26-provider-neutral-workspace-authorization.md
  • src/hosted_access_control.py
  • tests/test_hosted_access_control.py
  • tests/test_public_v1_release_docs.py

Generated CSV/JSON/report/sample-report/screenshot/timing paths in this range: 0.

Exactly 18 pre-existing local generated CSV/report differences remain excluded. Their unchanged diff fingerprint is:

a2c2f428b489dbb291dd54fd8a6e1e7f4ad9481414320ca248c54be89f4062b9

No readiness rebuild, provider fetch, broad refresh, generated report, screenshot capture, timing generation, merge, or deployment was performed.

Quant and investing boundary

The calculation and fail-closed layers support indicators, DCF/scenarios, benchmark-relative metrics, drawdown/volatility/beta/Sharpe/Sortino, deterministic nowcast modeling, walk-forward testing, and point-in-time universe validation. Real quantitative investing capability is not enabled:

  • real-company Nowcast remains blocked without compatible quarterly actuals and permitted point-in-time consensus;
  • numerical Beat/Miss probability remains withheld until at least 100 valid leakage-safe out-of-sample events exist;
  • no permitted independently reviewed real point-in-time universe package is on record;
  • no position sizing, allocation, stop-loss/take-profit, live holdings, broker integration, order routing, auto-trading, or direct buy/sell instructions.

Remaining maturity gates

  1. One bounded permitted point-in-time benchmark/universe package with exact-source rights and independent review
  2. One permitted point-in-time consensus source and one genuinely reviewed peer relationship
  3. An explicitly approved hosted identity, persistence, logging, monitoring, retention, rollback, and operating environment, followed by direct deployed verification
  4. Accessibility evidence beyond screenshots
  5. 10–20 independent workflow sessions measuring comprehension, trust, misuse risk, and repeat-use intent
  6. At least 100 valid out-of-sample events before probability exposure

Next safe lane

Keep the current authorization policy isolated. The next executable provider-neutral lane is a separately reviewed design for retention/deletion or append-only audit-event interfaces. Do not select a provider or create/change hosted accounts, use credentials, deploy, publish, merge, or claim hosted capability without explicit approval.

@YuzeJ21

YuzeJ21 commented Jul 18, 2026

Copy link
Copy Markdown
Owner Author

Verified implementation update — quarterly cash-generation evidence

Implemented the approved no-file design across four coherent commits:

  • 1089f58f8 adds the in-memory, fail-closed observation and derivation contract.
  • e11c698fa composes operating margin, free cash flow, and FCF margin independently from Revenue and EPS.
  • b6b8a3217 renders all five quarterly business-trend answers in Company Workbench while keeping source references and formulas under Advanced evidence.
  • 603985d5a updates methodology, provenance, Personal Research guidance, ROADMAP, and the persistent continuation goal.

Evidence and safety boundaries

  • Free cash flow preserves the reported capital-expenditure sign: cash from operations plus reported capital expenditures.
  • Q4 requires explicit filed-quarter evidence; annual-minus-nine-month derivation remains forbidden.
  • Ambiguous revisions and incompatible definitions block only the affected component.
  • Revenue, EPS, operating margin, free cash flow, FCF margin, valuation, consensus, catalysts, outcomes, backtesting, and calibration remain independent.
  • Production values remain withheld until a reviewed real-company quarterly source adapter exists. Synthetic observations remain test-only.
  • No supplemental CSV, JSON, data file, writer, template, report, sample report, screenshot, timing output, Make target, or generated artifact was added or staged.

Verification

  • Focused contract/workspace/docs tests: 77 passed.
  • Full suite: 2,746 passed; one existing dateutil deprecation warning.
  • Dashboard smoke: passed.
  • Research render smoke: Research Desk, Discover, Company Workbench, and Monitor passed.
  • Public wording and public checks: passed.
  • Commercial beta contract and release checks: passed.
  • Clean-tree pilot readiness: pilot-ready with manual gates.
  • Staged and diff hygiene: passed with zero generated-artifact candidates.
  • Branch is clean and aligned with origin/codex/personal-research-mode-mvp.

Product and market-maturity assessment

This is a meaningful methodology-maturity improvement: Company Workbench can now distinguish operating profitability from cash conversion, preserves source lineage, and gives a clearer answer-first research workflow. It improves reliability, extensibility, and reviewer trust.

It does not prove real-company coverage, licensed source operation, hosted reliability, reviewer adoption, commercial demand, calibration quality, product-market fit, or market validation. The product remains a local Commercial Research Beta release candidate.

Exact next executable step

Continue with a local one-company quarterly source-adapter acceptance contract using reviewed explicit inputs and no broad coverage refresh. Actual real-company activation remains external_source_and_review_required; point-in-time consensus remains external_data_required. Keep this PR draft.

@YuzeJ21

YuzeJ21 commented Jul 18, 2026

Copy link
Copy Markdown
Owner Author

Verified implementation update — quarterly cash-generation adapter acceptance

Implemented and pushed a one-company, in-memory acceptance harness for prospective quarterly cash-generation adapters.

What is now covered

  • Exact one-ticker and one-source identity checks
  • Commercial-use rights approval plus explicit rights for operating_income, cash_from_operations, and capital_expenditures
  • Existing cutoff, revision, component compatibility, Revenue compatibility, and explicit-Q4 evidence contracts
  • At least one complete period containing operating margin, free cash flow, and FCF margin
  • Deterministic fail-closed blockers and independent readiness state

Boundary preserved

  • Success means accepted_for_review, never production activation
  • Current checked-in SEC Company Facts rights evidence does not list all three required cash-generation fields, so that adapter remains blocked
  • No file, network, CLI, Make, broad-refresh, or generated-artifact surface was added
  • No CSV, JSON, report, or sample-report output is produced
  • Real activation remains external_source_and_review_required

Verification

  • python3 -m pytest tests -q: 2,764 passed, 1 existing deprecation warning
  • Dashboard smoke, four-route research render smoke, public wording, public check, commercial beta checks, release check, pilot readiness, diff hygiene, and git diff --check: passed
  • Pilot status: ready with explicit manual gates
  • Generated artifact churn: zero

Commits: 9a2d6b794, e9de1ca33.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified mobile Personal Research first-action density update:

  • Research Desk, Discover, Company Workbench, and Monitor now expose their primary phone task sooner.
  • All five profile facts remain visible in two phone rows.
  • Only duplicated route-card freshness is suppressed on phone.
  • Company Workbench keeps the complete review path available in a collapsed disclosure after Selected Company.
  • Desktop profile and route metadata remain unchanged.
  • Readiness, source dates, evidence, valuation, forecasts, catalysts, outcomes, backtesting, and calibration states are unchanged.
  • Fresh full suite: 2767 passed (one existing dateutil deprecation warning).
  • Dashboard smoke, all four Research render routes, public wording, public check, commercial-beta checks, release check, pilot readiness, whitespace, and hygiene gates passed.
  • Clean-tree pilot verdict: pilot-ready with manual gates.
  • No generated CSV, JSON, report, sample-report, screenshot, or timing churn was staged.
  • Commits: 2c4764e, edb86a0, 4bd071e, 8df949d, aec9ad2.

PR remains draft. This improves local usability maturity; it does not prove permitted source activation, hosted reliability, external reviewer demand, calibration quality, commercial demand, or product-market fit.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified reliability follow-up — declared-date readiness freshness:

  • Root cause: pilot/read-batch freshness used file mtimes only, while selected-profile and project status also compared declared source dates with the saved readiness build.
  • Shared freshness now fails closed when declared source dates are newer, even if checkout/restore mtimes appear current.
  • This alignment propagates through pilot packaging and every reviewed-batch consumer without rebuilding data.
  • Current truthful state: the saved readiness snapshot is stale; clean-tree pilot verdict is blocked on Readiness freshness.
  • I did not run make readiness because that would generate CSV/report churn outside this slice and conflict with the explicit no-new-CSV instruction.
  • Fresh focused regression set passed.
  • Fresh full suite: 2769 passed (one existing dateutil deprecation warning).
  • Dashboard smoke, all four Research render routes, public wording, public check, commercial-beta checks, release check, staged hygiene, whitespace, and diff hygiene passed.
  • Zero generated CSV, JSON, report, sample-report, screenshot, or timing artifacts were staged.
  • Commit: b28833626.

PR remains draft. The branch is safe for code review, but the pilot package must not be called ready until an intentional reviewed readiness rebuild is authorized and its generated diff is inspected.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified slice: no-write readiness impact preview

  • Added explicit no-write universe and readiness build modes while preserving existing write defaults.
  • Added make readiness-preview TOP_N=20. It compares stable saved-versus-proposed readiness states in memory, prints capped changes, disables bytecode writes, and creates no CSV, JSON, report, screenshot, timing, directory, or output artifact.
  • Stale pilot readiness remains blocked and now routes to the preview for inspection. The preview does not make saved readiness current and does not authorize the separate reviewed rebuild.
  • Live preview: 3,538 saved rows versus 3,541 proposed rows; 652 tickers have stable-field changes. Proposed fundamentals-ready and DCF-ready movement remains inspection evidence only, not current readiness or source-correctness proof.
  • Focused verification: 91 passed. Full suite: 2,777 passed with the existing dateutil warning. Dashboard smoke, all four Personal Research route renders, public wording, public-check, commercial-beta-check, commercial-beta-release-check, browser evidence, pilot gate, whitespace, and hygiene completed successfully.
  • Pilot readiness remains truthfully blocked by stale saved readiness. External consensus, hosting, reviewers, source/reviewer activation, calibration, and operated controls remain separately classified and incomplete.
  • Generated artifact hygiene: zero CSV, JSON, report, sample-report, screenshot, or timing changes committed. An accidental local generated rewrite during a shell-sensitive documentation search was immediately detected and exactly restored before verification; final hygiene was clean.

Commits through 3fd088f. Branch is pushed and aligned. PR remains draft; do not merge.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified implementation update — Personal Research evidence detour continuity

Current verified HEAD: 9403d8440

What changed

  • Company Workbench Advanced Evidence links now keep Data Health and Proof History inside mode=research instead of switching the researcher into Public or Operator mode.
  • Both evidence detours preserve the selected ticker, including URL encoding for symbols such as BRK/B.
  • Each research evidence view now shows a primary Return to Company Workbench action before existing evidence content; missing ticker context returns to Research Desk rather than inventing a company.
  • Public and Operator routes remain unchanged. The navigation does not change readiness, record evidence, refresh data, promote blocked inputs, or expose Operator commands.
  • ROADMAP, Personal Research documentation, dashboard QA evidence, the continuation goal prompt, and documentation contracts were updated.

Verification

  • focused slice tests: 77 passed
  • full repository suite: 2,780 passed with one existing dateutil deprecation warning
  • dashboard smoke: passed
  • public render smoke: Home, Stock Selector, Single-Stock Report, Data Health, Proof History passed
  • Personal Research render smoke: Research Desk, Discover, Company Workbench, Monitor, Research Data Health, Research Proof History passed
  • public wording, public check, commercial beta, commercial beta release, pilot-readiness, diff hygiene, staged hygiene, and whitespace gates passed as applicable
  • pilot-readiness remains truthfully blocked by stale saved readiness and external evidence gates; no make readiness run was performed

Artifact and evidence boundary

  • generated CSV, JSON, report, sample-report, screenshot, and timing churn: 0
  • no screenshot was created; this slice proves route and render continuity only, not visual spacing, focus order, contrast, assistive-technology behavior, hosted behavior, or accessibility compliance
  • real-company Earnings Nowcast remains blocked until permitted point-in-time consensus exists
  • numerical Beat/Miss probability remains withheld until calibration evidence exists
  • EPS split basis and explicit Q4 evidence boundaries remain unchanged

Product maturity effect

This improves workflow-continuity maturity: a researcher can inspect blocked inputs or proof and return to the selected company without losing context or changing workspaces. It does not prove market demand, hosted reliability, source rights, external reviewer adoption, calibrated prediction, or product-market fit.

Next executable external lane

After one permitted reviewed point-in-time consensus CSV or configured rights-appropriate provider exists, run one bounded preview:

make earnings-consensus-collection-preview INPUT=<reviewed.csv> AS_OF=<timestamp>

Do not perform broad collection, record snapshots, rebuild readiness, or generate evidence artifacts without the separate reviewed input and approval boundary. Overall continuation remains active; this draft PR must not be merged or publicly deployed.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified reliability update — stale-readiness continuation routing

Current verified HEAD: adc94651d

What changed

  • Added one shared fail-closed continuation gate for current, stale, mixed, and missing selected-profile readiness.
  • Project Status now exposes the gate in human and JSON output. When readiness is stale, it suppresses broad price, source-proof, and coverage next steps and routes only to make readiness-preview TOP_N=20.
  • Provider Setup and Coverage Frontier preserve provider classifications and ranked opportunities as planning context only.
  • Auto-Refresh Status, its runbook, and the Commercial Research Beta release path now use the same inspection-only routing instead of advertising SEC or coverage execution from stale counts.
  • make readiness remains a separate intentional reviewed write. This slice did not run it.

Verification

  • Focused continuation, status, provider, coverage, scheduler, and docs suites passed.
  • Full repository suite: 2,791 passed, with the existing dateutil deprecation warning.
  • Dashboard smoke passed.
  • Personal Research render smoke passed for Research Desk, Discover, Company Workbench, Monitor, Research Data Health, and Research Proof History.
  • Public wording, public check, commercial-beta check, commercial-beta release check, pilot-readiness check, staged hygiene, diff hygiene, and whitespace checks completed successfully.
  • Clean-tree pilot verdict remains blocked only because selected-profile source dates are newer than saved readiness.
  • Branch is clean and aligned with origin/codex/personal-research-mode-mvp.

Artifact and product boundary

  • Generated CSV, JSON, readiness-report, stock-report, sample-report, screenshot, and timing churn: 0.
  • Readiness counts were not refreshed and no source row, rights decision, provider availability, forecast, probability, event, peer, outcome, or recommendation was created.
  • This improves operating reliability and reviewer trust. It does not prove source correctness, hosted operation, reviewer adoption, calibration, commercial demand, market validation, or product-market fit.

Remaining gates

Point-in-time consensus remains external_data_required; hosted preview remains external_account_required; beta validation remains external_reviewers_required; trusted peers and quarterly cash-generation activation remain external_source_and_review_required; calibration remains external_evidence_required; operated controls remain external_account_and_operations_required.

After a permitted reviewed consensus file exists, the exact bounded resume command remains:

make earnings-consensus-collection-preview INPUT=<reviewed.csv> AS_OF=<timestamp>

PR remains draft. Do not merge or deploy.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Verified follow-up — complete stale-readiness operator routing

Current verified HEAD: 54f3977d7

This follow-up closes the remaining source-preflight and Advanced Data Health bypasses after the earlier continuation-gate update.

Additional changes

  • Session Source Preflight now overlays selected-profile continuation routing in readable and JSON output without changing raw source availability evidence.
  • Existing source-specific non-retry reasons are preserved, and the stale-readiness broad-refresh/source-proof/readiness-rebuild stop set is appended.
  • Advanced Data Health provider and scheduler cards now derive freshness directly from the selected profile, even when the cached preflight predates this gate.
  • The next scheduler card routes to make readiness-preview TOP_N=20 while stale; scheduled operations remain planning context only.
  • ROADMAP, Data Strategy, Dashboard QA, and the persistent continuation prompt now cover these surfaces.

Verification

  • Focused source-preflight and dashboard suites passed, including a 1,035-test dashboard/operator run and a 1,091-test cross-surface run.
  • Full repository suite: 2,792 passed, with the existing dateutil deprecation warning.
  • Dashboard boot and all six Personal Research render routes passed.
  • Public wording, public check, commercial-beta check, commercial-beta release check, pilot-readiness check, staged hygiene, diff hygiene, and whitespace checks exited successfully.
  • Clean-tree pilot readiness remains blocked only by stale selected-profile readiness.
  • Tracked generated CSV/JSON/report/sample-report/screenshot/timing churn: 0.

Local cache disclosure

During live validation, make session-source-preflight rewrote the existing ignored outputs/session_source_preflight.json cache because that Make target includes --write-output. The cache is excluded by Git policy and was not staged or committed. No CSV was generated. Future validation should use direct no-write rendering or fixtures when the continuation contract prohibits JSON cache rewrites.

The product remains a local Commercial Research Beta release candidate. This improves operating reliability; it does not satisfy source, hosted, reviewer, calibration, market-validation, or operated-platform gates.

PR remains open and draft. Do not merge or deploy.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Final verified state for this continuation run

Current HEAD: 300b5f336

The stale-readiness continuation gate now covers Project Status, Session Source Preflight, Provider Setup, Coverage Frontier, Auto-Refresh Status and runbook, Advanced Data Health cards, machine-readable output, and the commercial-beta release path.

Final verification:

  • full suite: 2,792 passed
  • dashboard boot: passed
  • six Personal Research render routes: passed
  • public wording, public check, commercial-beta check, commercial-beta release check, pilot-readiness, staged hygiene, diff hygiene, and whitespace: passed
  • no-write readiness preview artifact fingerprint: unchanged
  • preview result: 3,538 saved rows vs 3,541 proposed; 652 stable-field changes; fundamentals-ready 23→175; DCF-ready 23→169
  • those proposed counts remain inspection evidence only and are not current product claims
  • working tree clean; branch aligned 0/0

Tracked/staged generated artifact churn remains zero. The existing ignored session-source-preflight JSON cache rewrite is disclosed in the prior comment and remains untracked.

The exact next reviewed decision is whether to authorize a separate make readiness rebuild after source-provenance and generated-diff review. Until then, pilot readiness remains blocked by stale readiness. All external source, hosted, reviewer, calibration, peer/source-review, and operated-control gates remain independently incomplete.

PR remains open and draft. Do not merge or deploy.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Readiness promotion evidence review — verified local slice

This slice extends the existing no-write readiness preview with a separate fail-closed evidence review for proposed fundamentals and DCF promotions.

Verified inspection result:

  • 152 unique proposed fundamentals promotions; 146 also propose DCF.
  • 57 use an exact source identifier with approved commercial rights; 95 use unregistered exact source values.
  • 148 have source, as-of date, and durable-reference fields; 4 require provenance review.
  • 0 have complete registered source field scope for Revenue, free cash flow, FCF margin, and shares outstanding.
  • Complete DCF price-source provenance remains separately unproven.

Boundaries preserved:

  • These are proposed in-memory technical changes, not current readiness counts.
  • Composite source labels are not split or granted inferred rights.
  • The preview writes no CSV, JSON, report, sample report, screenshot, timing, cache, or readiness artifact.
  • Saved readiness remains stale. No make readiness run was performed or authorized.
  • PR Commercial Research Beta release candidate #113 remains draft; no merge or deployment was performed.

Verification:

  • Focused preview, readiness-engine, universe, source-rights, launcher, and documentation tests passed.
  • Full suite: 2,796 passed; one existing dateutil deprecation warning.
  • Dashboard boot smoke passed.
  • All six Personal Research route render smokes passed.
  • Public wording and public check passed.
  • Commercial beta and commercial beta release checks passed.
  • Pilot readiness executed and remains truthfully blocked by stale readiness.
  • Diff and staged hygiene passed with zero generated CSV/JSON/report candidates.
  • Byte fingerprint before and after the real readiness preview was identical.

Commits:

  • 9e1281b Design readiness promotion evidence review
  • e4174e2 Plan readiness promotion evidence review
  • 5e6e01d Audit readiness promotion evidence
  • 849800e Advance promotion evidence lineage

Next executable local lane: audit the remaining non-promotion readiness changes and the missing DCF price-source lineage without writing generated artifacts or editing source rights.

@YuzeJ21

YuzeJ21 commented Jul 19, 2026

Copy link
Copy Markdown
Owner Author

Readiness change-cause review — verified local slice

The same no-write readiness preview now explains major saved-versus-proposed transitions using named, tested method reasons.

Current in-memory transition evidence:

  • 3 ticker rows added; 0 removed.
  • Newly ready features: fundamentals 152; DCF 146.
  • Newly partial features: fundamentals 49; peer 3.
  • Newly excluded features: DCF 464; peer 2.
  • All 464 new DCF exclusions are explained: acquisition/SPAC 180, bank/bancorp 145, financial/insurance/mortgage 93, closed-end fund 30, capital corporation 6, nonpositive-revenue margin model 4, realty-trust/BDC 3, and REIT 3.
  • Unexplained new DCF exclusions: 0.

Boundaries:

  • Transition counts can overlap for one ticker and are not current readiness totals.
  • Exclusion reasons explain method fit; they are not company-quality judgments, rankings, or recommendations.
  • Existing exclusion behavior is unchanged and regression-tested.
  • The preview remains stdout-only and byte-preserving; no readiness rebuild or generated artifact was created.
  • Saved readiness remains stale; PR Commercial Research Beta release candidate #113 remains draft.

Verification:

  • Focused company-scope, readiness-preview, readiness-engine, docs, and launcher tests passed.
  • Full suite: 2,803 passed; one existing dateutil warning.
  • Dashboard boot and six Personal Research route render smokes passed.
  • Public wording, public check, commercial beta, commercial beta release, pilot readiness, diff hygiene, staged hygiene, and whitespace checks passed.
  • Pilot readiness remains truthfully blocked by stale readiness.
  • Generated CSV/JSON/report/sample-report/screenshot/timing candidates: 0.

Commits:

  • ffe9511 Design readiness change cause review
  • 8fd61e2 Explain readiness change causes
  • cf81319 Advance change cause lineage

Next executable local step: audit the DCF price-source lineage gap without writing or modifying canonical price/readiness artifacts.

@YuzeJ21

YuzeJ21 commented Jul 24, 2026

Copy link
Copy Markdown
Owner Author

Remediation 6 is complete and independently approved at exact head 92392642d with no remaining Critical, Important, or Minor findings in the slice review.

The second whole-branch review found and this slice closes four cross-slice issues:

  • source-rights inventory now uses exact verified raw evidence rows independently of technical parsing, including malformed/unknown/missing event scope;
  • walk-forward minimum history counts only distinct, otherwise-qualified evaluations strictly earlier than the current cutoff;
  • identity, membership, and event evidence now require publication at or before retrieval;
  • bounded snapshots use a same-descriptor regular-file reader, cap+1 total budget, stable-size equality, and complete short-read handling so a verified prefix cannot authorize a larger physical file.

Evidence:

  • RED: 15 initial expected failures, then 6 additional adversarial failures from independent review
  • focused: 387 passed
  • full: 3,706 passed (one existing dateutil warning)
  • public-check independently reran all 3,706 tests and passed route/render/browser/license/visitor gates
  • dashboard smoke, public wording, pilot readiness, Ruff, whitespace, diff and staged hygiene passed
  • original 18 generated CSV/report changes remain unstaged and unchanged; fingerprint a2c2f428b489dbb291dd54fd8a6e1e7f4ad9481414320ca248c54be89f4062b9

PR remains draft. No readiness rebuild, provider fetch, broad refresh, generated report/screenshot/timing command, merge, or deployment was performed. Priority 4 remains externally incomplete pending a permitted independently reviewed real dataset, direct source-rights evidence, and accepted expected membership count/digest. Next gates are exact-head CI and a third fresh whole-branch engineering review.

@YuzeJ21

YuzeJ21 commented Jul 24, 2026

Copy link
Copy Markdown
Owner Author

The third whole-branch review found one final Minor aggregate-resource issue; it is fixed and independently approved at exact head 59cade053.

The combined four-contract budget now constrains every descriptor read by both the per-file limit and the remaining aggregate allowance, with remaining+1 overflow detection. Exact aggregate boundaries pass; the next contract cannot be fully read or retained after the aggregate budget is exhausted. Per-file error precedence, legal short reads, same-descriptor metadata checks, race rejection, and immutable verified snapshots remain covered.

Verification at the reviewed head:

  • manifest: 51 passed
  • focused Priority 4/docs: 388 passed
  • full suite: 3,707 passed (one existing dateutil warning)
  • public-check independently reran 3,707 tests and all dashboard/render/browser/license/visitor gates
  • pilot readiness, public wording, Ruff, whitespace, diff and staged hygiene passed
  • original 18 generated CSV/report changes remain unstaged and unchanged; fingerprint a2c2f428b489dbb291dd54fd8a6e1e7f4ad9481414320ca248c54be89f4062b9

PR stays draft. No readiness/provider/generated report/screenshot/timing operation, merge, or deployment occurred. Next gates are exact-head CI and a fourth fresh whole-branch review. Priority 4 external real-data, direct-rights, expected-count/digest, hosted, and market-validation gates remain open.

@YuzeJ21

YuzeJ21 commented Jul 24, 2026

Copy link
Copy Markdown
Owner Author

The fourth whole-branch review found one structured-input Minor; it is now fixed and independently approved at exact head db9d1ea76.

Deeply nested but byte-bounded manifest JSON and hash-bound source-rights YAML now fail through stable manifest_unreadable / source_rights_registry_unreadable classifications. CLI and Make return readable nonzero results without traceback or writes. The exception scope is intentionally narrow: parser recursion/parse failures are translated, while unrelated reader/internal exceptions propagate and are not mislabeled as invalid input.

Verification:

  • targeted parser/CLI/Make/no-write regressions: passed
  • focused Priority 4/docs: 394 passed
  • full suite: 3,713 passed (one existing dateutil warning), independently rerun at stable HEAD
  • public-check reran 3,713 and dashboard/render/browser/license/visitor gates
  • standalone dashboard, wording, pilot, Ruff, whitespace, diff/staged hygiene passed
  • original 18 generated CSV/report changes remain unstaged and unchanged; fingerprint a2c2f428b489dbb291dd54fd8a6e1e7f4ad9481414320ca248c54be89f4062b9

PR remains draft. No readiness/provider/generated report/screenshot/timing operation, merge, or deployment occurred. Next gates: exact-head CI and a fifth fresh whole-branch review. External Priority 4 real-data, source-rights, expected-count/digest, hosted, and market-validation gates remain open.

@YuzeJ21

YuzeJ21 commented Jul 24, 2026

Copy link
Copy Markdown
Owner Author

Remediation 7 is complete and independently approved at exact head afe29386b with no remaining findings in the slice review.

This closes the V5 trust-boundary findings:

  • structural identifiers now reject C0/C1 and Unicode line/paragraph separator categories Zl/Zp, while ordinary Unicode remains deterministic;
  • renderers escape the same record-separator set as literal \\uXXXX, preventing forged status lines even in blocked packets;
  • newline-delimited member digest inputs are now delimiter-safe, closing the demonstrated equal-count/different-set ambiguity;
  • manifest_created_at must be at or after the observation cutoff and every timestamp in the exact bound evidence snapshots; impossible chronology receives exact physical-row temporal_evidence_after_manifest_creation classification independently of schema failures;
  • listing_state_after uses the shared structural validator before enum validation.

Verification:

  • remediation tests: 54 passed
  • focused Priority 4/docs: 448 passed
  • full suite: 3,767 passed (one existing dateutil warning)
  • public-check independently reran 3,767 and dashboard/render/browser/license/visitor gates
  • pilot, public wording, Ruff, whitespace, diff/staged hygiene passed
  • original 18 generated CSV/report changes remain unstaged and unchanged; fingerprint a2c2f428b489dbb291dd54fd8a6e1e7f4ad9481414320ca248c54be89f4062b9

PR remains draft. No readiness/provider/generated report/screenshot/timing operation, merge, or deployment occurred. Next gates are exact-head CI and a sixth fresh whole-branch review. External Priority 4 real-data, direct source-rights, expected-count/digest, hosted, and market-validation gates remain open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant