Conversation
Parked mid-implementation at the user's request. NOT functional yet: build-orchestrator.mjs references a `runVerify` helper that is not yet defined, and buildProject is not wired to pass callVerify/verifyTeamFor. No tests added or run. Done so far: - schemas.mjs: VERDICT_SCHEMA + SCHEMAS.verdict - teamPrompts.mjs: promptForVerify / verifyPrompt / parseVerdict / makeLiveCallVerify - teams.mjs: verifyTeamForNode - build-orchestrator.mjs: readArtifactFiles + verify stage in makeTeamDispatch (pending: define runVerify, wire buildProject, tests) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01RcL28Z3rdYsTdCQiLAoBdu
dsmcewan
added a commit
that referenced
this pull request
Sep 23, 2026
Section 9 traces the GitHub side: the PR series that produced the current main (security sweep #155-#161, signed-by-default #186, marketplace rename #191, workflow oracle #188), the 12 open PRs including the parked per-node verify stage in #192, the 14 open issues mapped to the sections of this document, and the Claude Code Review workflow's failure pattern (29 of the last 40 runs, clustered in bursts, failing before any model call). Adds F14: connectors/meta-ads-mcp has no package.json, tests, CI job, manifest entry, or PACKAGE_ROOTS classification. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JSb8WNmvor3GNapDqUbc4T
5 tasks
Completes the WIP parked in 24200b3. The verify stage now runs end to end: - runVerify (build-orchestrator.mjs): resolves the node's verify team, reads the built artifact from disk, calls the verify team, and blocks on two fail-closed-safe sources — (1) fact-grounding: the verdict's declarative file_exists/file_contains checks are re-run against disk via reverifyRecord, so a model that says ok:true while its own declared evidence is absent is blocked; (2) an explicit verifier stop (ok:false / blockers). It never settles anything — Rule 3 (defaultVerifyNode) remains the sole settle authority; a verify verdict can only stop a node. - buildProject wiring: routes each node to its verify team (verifyTeamForNode) and threads callVerify/requireVerify into makeTeamDispatch. The stage is inert unless a callVerify is supplied, so absent it behavior is byte-identical. Advisory by default (a broken/keyless verifier cannot wedge the build); requireVerify (or dossier.require_verify) makes an un-runnable verify hard-fail the node. - scripts/test-verify-stage.mjs: 6 keyless cases — pass-settles, block on a failing grounded check (no bluffing ok), block on ok:false/blockers, advisory skip on an un-runnable verify, requireVerify hard-fail, and absent-callVerify backward compatibility. Wired into the build-gate check + test scripts. build-gate npm test (incl. breakout) passes. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HxkFCG3ehwNmqhTJHnFxqd
Owner
Author
|
Closing as superseded by #195. This branch ( Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Finishes the parked WIP: a per-node verify stage for the autonomous builder. After a team builds a node and its own test passes, an independent verify team adversarially re-checks the built artifact. The verdict can only block — Rule 3 (
defaultVerifyNode) stays the sole thing that settles the signed ledger. A verify verdict never settles anything.What it does (
build-gate/build-orchestrator.mjs)runVerify(now defined): resolves the node's verify team (verifyTeamForNode), reads the built artifact from disk (confined underbaseDir), calls the verify team, and blocks on two fail-closed-safe sources:file_exists/file_containschecks are re-run against disk viareverifyRecord. A check the verifier itself declared that does not hold blocks the node, so a model that saysok: truewhile its own evidence is absent cannot bluff past disk truth.ok: falseor raisingblockers. Blocking is always safe (it can only stop a node, never approve one).buildProjectwiring: routes each node to its verify team and threadscallVerify/requireVerifyintomakeTeamDispatch. The stage is inert unless acallVerifyis supplied, so absent it behavior is byte-identical. Advisory by default (a broken or keyless verifier cannot wedge the build);requireVerify(ordossier.require_verify) makes an un-runnable verify hard-fail the node.The schema/prompt/team primitives (
schemas.mjsVERDICT_SCHEMA,teamPrompts.mjspromptForVerify/verifyPrompt/parseVerdict/makeLiveCallVerify,teams.mjsverifyTeamForNode) were in the WIP commit; this commit makes them load-bearing.Tests
build-gate/scripts/test-verify-stage.mjs— 6 keyless cases: pass→settle, block on a failing grounded check (no bluffingok), block onok:false/blockers, advisory skip on an un-runnable verify,requireVerifyhard-fail, and absent-callVerifybackward compatibility. Wired into thebuild-gatecheck+testscripts.cd build-gate && npm test(which also runsbreakout) passes.Note
This branch forked well before current
main(itsbuild-gatecopies are stale), so it will need a rebase ontomainbefore it can merge cleanly — the verify stage itself is complete and self-contained.🤖 Generated with Claude Code