diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index 9d2a7be..2044038 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -54,6 +54,9 @@ for a primary developer and returns one terminal result. Supporting boundaries: +- Affected Verification independently decides which verification checks are + defensible for a change; humans, CI, or Gearbox may execute the plan, and + Context Firewall may subsequently reduce the resulting evidence. - Gearbox admits deterministic versus cognitive work; Routing Policy selects an eligible cognitive route after admission. - Resource Claims establishes current concurrent ownership; Execution diff --git a/PROGRAM_STATUS.md b/PROGRAM_STATUS.md index bb9ba09..90ca65c 100644 --- a/PROGRAM_STATUS.md +++ b/PROGRAM_STATUS.md @@ -2,9 +2,9 @@ -**Coverage: 20/20 expected repositories; duplicates: 0.** +**Coverage: 21/21 expected repositories; duplicates: 0.** -Last verified: `2026-08-29T14:49:44Z`. HEADs are the verified default-branch revisions, not an assumption about later changes. +Last verified: `2026-08-31T01:29:54Z`. HEADs are the verified default-branch revisions, not an assumption about later changes. ## Portfolio totals @@ -12,7 +12,7 @@ Last verified: `2026-08-29T14:49:44Z`. HEADs are the verified default-branch rev |---|---:| | `THEORY` | 12 | | `SPECIFIED` | 0 | -| `PROTOTYPED` | 6 | +| `PROTOTYPED` | 7 | | `VERIFIED` | 2 | | `BENCHMARK_READY` | 0 | | `EXPERIMENTED` | 0 | @@ -20,7 +20,7 @@ Last verified: `2026-08-29T14:49:44Z`. HEADs are the verified default-branch rev | `DOCUMENTED` | 0 | | `COMPLETE` | 0 | -Program state totals: active 4; waiting 16; complete 0. +Program state totals: active 5; waiting 16; complete 0. ## Repository inventory @@ -43,13 +43,14 @@ Program state totals: active 4; waiting 16; complete 0. | 15 | [agent-recovery-policy](https://github.com/opsle/agent-recovery-policy) | concept | `1b733a111e26` | `THEORY` | [none; placeholder source directory only](https://github.com/opsle/agent-recovery-policy/blob/1b733a111e26e0a409fee3b96f627048531daefe/THEORY.md); placeholder only; no automated tests | No shared failure schema, attempt ledger, route evaluator, or comparative fixture set. | After decision evidence and route schemas stabilize, define same-failure convergence on synthetic failures. | `agent-routing-policy`, `agent-state-ledger`, `decision-evidence-protocol` | waiting | | 16 | [ephemeral-agent-workers](https://github.com/opsle/ephemeral-agent-workers) | concept | `ad96fcfdfac0` | `THEORY` | [none; placeholder source directory only](https://github.com/opsle/ephemeral-agent-workers/blob/ad96fcfdfac06d340b5e96d369634980cee78ef4/THEORY.md); placeholder only; no automated tests | Portable authority, claim, and handoff contracts are not ready; no safe synthetic containment harness exists. | Wait for prerequisite contracts, then define a fake worker adapter and destruction receipt without infrastructure changes. | `agent-execution-authorization`, `agent-resource-claims`, `verifiable-agent-handoff` | waiting | | 17 | [gearbox](https://github.com/opsle/gearbox) | concept | `f3fab9f292cf` | `PROTOTYPED` | [provider-free Python reference core with strict authority-policy admission, exact deterministic argv execution, content-addressed staged helper context, injected one-shot helper transport, passive process waiting, compact results, raw-artifact accounting, fail-closed budgets, and Visible Value receipts](https://github.com/opsle/gearbox/blob/f3fab9f292cf4eabd7200615d444f98881f57d55/src/opsle_gearbox/core.py); 19 of 19 provider-free automated tests passed locally, in PR #1 CI, and in final-main CI; ruff, shellcheck, actionlint, gitleaks, wheel build, receipt validation, and public raw-locator/hash checks passed | A production-quality bounded helper transport, independently verified isolation and termination, full Context Firewall integration, and a frozen comparative benchmark remain missing. | Freeze a provider-free deterministic-versus-direct baseline and helper-transport conformance corpus before considering any live model/provider run. | `context-firewall`, `decision-evidence-protocol`, `agent-trajectory-profiler`, `agent-routing-policy`, `agent-execution-authorization` | waiting | -| 18 | [research](https://github.com/opsle/research) | program infrastructure | `9ee43197880c` | `PROTOTYPED` | [authoritative 20-repository ledger, machine-readable 17-concept theory registry, canonical theory map, normative Visible Value controls, and provider-free EXP-001 benchmark, launch, one-block coordinator, external four-label LIVE_PROVIDER_RUN authorization, and current catalogue/pricing preflight artifacts with six content-addressed tasks, deterministic oracle, four arm contracts, sealed blinded allocation, exact subject configuration and adapter, exact authorization admission, private boundaries, receipts, mutation tests, and integrity CI](program/THEORY_MAP.md); 88 of 88 repository tests pass on the unreleased provider-free live-preflight branch, including 13 authorization validations and two byte-identical replays; PR #13 and exact main CI remain the released coordinator baseline | The exact live authorization set remains unconsumed and unreleased, account-specific API entitlement is unverified under the zero-provider-call policy, no immutable dated model snapshot is documented, and the program has no canonical measured concept experiment. | Independently review and release the provider-free live-authorization and catalogue/pricing preflight; do not consume authorization or launch a provider/model subject. | — | active | -| 19 | [site](https://github.com/opsle/site) | program infrastructure | `28ad65be4750` | `PROTOTYPED` | [React/Vinext source implementation with content routes](https://github.com/opsle/site/blob/28ad65be4750dc849976fbf5c9eae9501c6bbb25/README.md); automated build/render tests present; not rerun because this reconciliation kept other repositories read-only | Wait for validated registry data and measured research; deployment requires separate authorization. | After registry merge, add a read-only registry ingestion design without deploying the site. | `research` | waiting | -| 20 | [.github](https://github.com/opsle/.github) | program infrastructure | `01c38e726db7` | `THEORY` | [documentation-only organization profile](https://github.com/opsle/.github/blob/01c38e726db7c3e45059d25fccce55e071e35938/profile/README.md); not applicable to current single Markdown profile; consistency is unverified | No mechanical registry consistency check exists in this repository. | After registry merge, design a read-only consistency check for organization-profile repository links. | `research` | waiting | +| 18 | [affected-verification](https://github.com/opsle/affected-verification) | concept | `12076522c9b8` | `PROTOTYPED` | [dependency-free Node.js 20 deterministic planner with normalized change/impact evidence, reverse-dependency closure, explicit verification catalog and policy rules, selected and skipped check arguments, fail-closed escalation, canonical SHA-256 provenance, opsle.value-receipt.v1 output, and fixture-level shadow miss classification](https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/SPEC.md); 54 of 54 automated tests, 15 of 15 positive/boundary/negative/tampered conformance scenarios, and 5 of 5 determinism checks passed locally and in PR #1 CI; exact main CI, current Opsle value-receipt validation, actionlint, gitleaks, and clean local/remote parity passed | A frozen real public-repository full-verification baseline, complete catalog, production evidence adapter, relevance oracle, native-selector comparison, shadow observations, and independent review are missing. | Freeze one real public repository's full-verification baseline, catalog, adapter outputs, and relevance oracle, then run an OBSERVE/SHADOW comparison without replacing CI. | — | active | +| 19 | [research](https://github.com/opsle/research) | program infrastructure | `9ee43197880c` | `PROTOTYPED` | [authoritative 21-repository ledger, machine-readable 18-concept theory registry including Affected Verification, canonical theory map, normative Visible Value controls, and provider-free EXP-001 benchmark, launch, one-block coordinator, external four-label LIVE_PROVIDER_RUN authorization, and current catalogue/pricing preflight artifacts with six content-addressed tasks, deterministic oracle, four arm contracts, sealed blinded allocation, exact subject configuration and adapter, exact authorization admission, private boundaries, receipts, mutation tests, and integrity CI](program/THEORY_MAP.md); 88 of 88 repository tests pass locally after deliberate migration to the 21-repository, 18-concept anti-forgetting set, including 13 authorization validations and two byte-identical replays; generated status and registry validation pass | The exact live authorization set remains unconsumed and unreleased, account-specific API entitlement is unverified under the zero-provider-call policy, no immutable dated model snapshot is documented, and the program has no canonical measured concept experiment. | Independently review and release the provider-free live-authorization and catalogue/pricing preflight; do not consume authorization or launch a provider/model subject. | — | active | +| 20 | [site](https://github.com/opsle/site) | program infrastructure | `28ad65be4750` | `PROTOTYPED` | [React/Vinext source implementation with content routes](https://github.com/opsle/site/blob/28ad65be4750dc849976fbf5c9eae9501c6bbb25/README.md); automated build/render tests present; not rerun because this reconciliation kept other repositories read-only | Wait for validated registry data and measured research; deployment requires separate authorization. | After registry merge, add a read-only registry ingestion design without deploying the site. | `research` | waiting | +| 21 | [.github](https://github.com/opsle/.github) | program infrastructure | `01c38e726db7` | `THEORY` | [documentation-only organization profile](https://github.com/opsle/.github/blob/01c38e726db7c3e45059d25fccce55e071e35938/profile/README.md); not applicable to current single Markdown profile; consistency is unverified | No mechanical registry consistency check exists in this repository. | After registry merge, design a read-only consistency check for organization-profile repository links. | `research` | waiting | ## Theory reconciliation -Concept coverage: 17 canonical concepts; 17 current concept repositories mapped exactly once; Agent Gearbox maps to opsle/gearbox. +Concept coverage: 18 canonical concepts; 18 current concept repositories mapped exactly once; Agent Gearbox maps to opsle/gearbox. Canonical map: `program/THEORY_MAP.md`. Machine registry: `program/theory-registry.json`. diff --git a/program/PRIORITY.md b/program/PRIORITY.md index 7561545..30eab72 100644 --- a/program/PRIORITY.md +++ b/program/PRIORITY.md @@ -80,6 +80,15 @@ Agent Discovery Control should wait for a portable ledger and supervisor fixture so duplicate convergence and already-satisfied proofs are durable rather than conversation-local. +## Workstream 6: affected verification + +Affected Verification is independently prototyped for normalized synthetic +evidence and remains outside Gearbox. Its next evidence gate is not another +selector implementation: freeze one real public repository's full-verification +baseline, complete catalog, native-selector adapter output, and relevance oracle, +then run only in `OBSERVE`/`SHADOW` without replacing authoritative CI. Correctness +and relevant selection misses precede workload reduction. + ## Exact next execution In `opsle/research`, independently review and release the provider-free exact diff --git a/program/THEORY_MAP.md b/program/THEORY_MAP.md index d36dd4d..4711ca5 100644 --- a/program/THEORY_MAP.md +++ b/program/THEORY_MAP.md @@ -1,13 +1,13 @@ # Canonical Opsle theory map Status: authoritative conceptual reconciliation plus the 2026-08-29 public -Gearbox extraction. Consolidation and disposition operations remain -recommendations only. +Gearbox extraction and 2026-08-31 Affected Verification project creation. +Consolidation and disposition operations remain recommendations only. Machine source: [`theory-registry.json`](theory-registry.json). Theory registry canonical SHA-256: -`67b7529c195b501a810a3689f2074b1ed893541a15016ea4a8be83cb34437491`. +`d3a5f6e03f28d0ae8911763e6cb15c1a3f7306559f1801a2647219563159cb79`. This map corrects an extraction-boundary error. The original 16 concept repositories were useful hypotheses isolated from one production system, but @@ -38,6 +38,7 @@ OPSLE ├── Independent Opsle tools │ ├── Context Firewall │ ├── Agent Trajectory Profiler +│ ├── Affected Verification │ └── Semantic Edit Protocol ├── Cross-cutting protocols │ ├── Decision Evidence Protocol @@ -266,6 +267,7 @@ not an executed repository action. | Repository | Primary classification | Recommended disposition | Confidence | One-sentence rationale | |---|---|---|---|---| | `gearbox` | `GEARBOX_CORE` | `KEEP_STANDALONE` | `HIGH` | One bounded primary-developer transmission operation now has a narrow public home without absorbing durable orchestration or external policies and protocols. | +| `affected-verification` | `INDEPENDENT_OPSLE_TOOL` | `KEEP_STANDALONE` | `HIGH` | Minimum-defensible verification planning composes native impact evidence, catalogs, and risk policy without owning check execution or model-context reduction. | | `agent-trajectory-profiler` | `INDEPENDENT_OPSLE_TOOL` | `KEEP_STANDALONE` | `HIGH` | Reusable correctness-gated telemetry is external to both Gearbox and durable orchestration, although generic Visible Value scope needs ownership cleanup. | | `semantic-edit-protocol` | `INDEPENDENT_OPSLE_TOOL` | `KEEP_STANDALONE` | `HIGH` | Bounded structural editing is independently useful and can be selected as a deterministic Gearbox tool without becoming Gearbox core. | | `durable-supervisor` | `DURABLE_ORCHESTRATION` | `KEEP_AS_RESEARCH` | `HIGH` | Durable objective ownership and reconstruction form a distinct autonomous-orchestration hypothesis whose package boundary remains unproven. | @@ -354,6 +356,22 @@ profile, but it must not evolve into a competing reduction policy. Profiler must not become the normative owner of every receipt protocol merely because it aggregates them. +### Affected Verification versus selectors, Gearbox, and Context Firewall + +Native affected/related systems remain authoritative evidence providers for +their own graphs and test frameworks. Affected Verification composes that +evidence with a complete verification catalog and explicit risk policy to +produce selected checks, explained skips, and a sufficiency or uncertainty +state. It does not reimplement those selectors, execute CI, or claim global +mathematical minimality. + +Gearbox may consume a plan and choose an execution gear, but does not own the +verification theory or planner. After checks execute, Context Firewall decides +which results enter model context; Affected Verification decides only what +verification should execute. Decision Evidence may validate plan provenance, +and Agent Trajectory Profiler may measure planned versus actual or shadow work, +without initial package coupling. + ## Restored home and remaining gaps `opsle/gearbox` now coherently owns deterministic task admission, requested-gear @@ -390,6 +408,11 @@ repositories. - Verifiable Agent Handoff is prototyped only for HMAC manifest binding and caller-supplied destruction state; publication, transport, destruction proof, reconstruction, and independent verification are not implemented. +- Affected Verification is prototyped for normalized synthetic evidence, + deterministic catalog/policy planning, fail-closed escalation, skip reasons, + Visible Value receipts, and fixture-level shadow classification. No production + adapter, check execution, real-repository benchmark, or trusted selective + verification class exists. - The remaining theory repositories contain coherent falsifiable narratives, but their `SPEC.md` files are generic templates and their source/tests are placeholders. Their current lifecycle remains `THEORY`. @@ -482,6 +505,7 @@ Minimum requirements: ## Repository anti-forgetting invariant -The authoritative program registry tracks exactly 20 repositories: 17 concept -repositories, `research`, `site`, and `.github`. Agent Gearbox is mapped exactly -once to `opsle/gearbox`. Concept tracking does not replace repository tracking. +The authoritative program registry tracks exactly 21 repositories: 18 concept +repositories, `research`, `site`, and `.github`. Agent Gearbox and Affected +Verification are each mapped exactly once to their public repositories. Concept +tracking does not replace repository tracking. diff --git a/program/registry.json b/program/registry.json index d8d6f42..966575a 100644 --- a/program/registry.json +++ b/program/registry.json @@ -1,7 +1,7 @@ { "schema_version": 1, "program": "Opsle Research", - "authoritative_repository_count": 20, + "authoritative_repository_count": 21, "lifecycle_model": "program/LIFECYCLE.md", "experiment_registry": "program/experiments.json", "theory_registry": "program/theory-registry.json", @@ -38,7 +38,7 @@ }, "current_highest_priority_workstream": "Independently review and release the provider-free EXP-001 live-authorization and current catalogue/pricing preflight; do not consume authorization or launch any provider/model subject.", "recommended_next_execution": "In opsle/research, create and provider-free validate one exact four-label LIVE_PROVIDER_RUN authorization set plus a model catalogue/pricing preflight artifact; do not consume authorization or launch a provider/model subject.", - "last_verified_at": "2026-08-29T14:49:44Z", + "last_verified_at": "2026-08-31T01:29:54Z", "repositories": [ { "name": "agent-trajectory-profiler", @@ -550,6 +550,36 @@ "program_state": "waiting", "last_verified_at": "2026-08-29T02:53:08Z" }, + { + "name": "affected-verification", + "github_url": "https://github.com/opsle/affected-verification", + "default_branch": "main", + "last_verified_head_sha": "12076522c9b82501794d816f1fcc0b7775fad6e1", + "project_type": "concept", + "purpose": "Select the smallest verification workload whose sufficiency can be defended from available change-impact, dependency, coverage, policy, and risk evidence.", + "lifecycle_stage": "PROTOTYPED", + "implementation_status": "dependency-free Node.js 20 deterministic planner with normalized change/impact evidence, reverse-dependency closure, explicit verification catalog and policy rules, selected and skipped check arguments, fail-closed escalation, canonical SHA-256 provenance, opsle.value-receipt.v1 output, and fixture-level shadow miss classification", + "implementation_requirement": "A runnable deterministic planner, input validator, plan contract, conformance fixtures, and shadow classifier are sufficient for the prototype gate; real adapters and comparative evidence are later gates.", + "specification_status": "versioned input and opsle.affected-verification.plan.v1 contracts define catalog entries, evidence providers, policy matching, selection and skip reasons, provenance, explicit sufficiency/uncertainty/escalation states, failure behavior, Visible Value limits, and shadow observations", + "test_status": "54 of 54 automated tests, 15 of 15 positive/boundary/negative/tampered conformance scenarios, and 5 of 5 determinism checks passed locally and in PR #1 CI; exact main CI, current Opsle value-receipt validation, actionlint, gitleaks, and clean local/remote parity passed", + "benchmark_status": "twelve public-safe synthetic positive/boundary scenarios plus three explicit negative fixtures and fixture-level shadow classification; benchmark plan only, with no real-repository baseline, native-selector comparison, measured execution, or frozen correctness oracle", + "measured_experiment_status": "none; no real-project verification experiment and zero provider/model runs", + "reproducibility_status": "planner tests, conformance, determinism, canonical plan/value output, fail-closed cases, and shadow classification reproduce locally and in public CI at the verified HEAD; cross-project adapter behavior and comparative safety remain untested", + "documentation_status": "public canonical definition, normative specification, source-linked prior-art audit, architecture and independence boundaries, verification catalog and policy semantics, trust ramp, benchmark plan, limitations, usage, security, schema, and fixtures are present", + "site_publication_status": "GitHub documentation only; no evidence-backed site publication", + "known_limitations": ["The prototype trusts normalized component, catalog, and policy claims; has no production Git, graph, coverage, ownership, schema, or native-selector adapters; executes no checks; uses a synthetic corpus; and has no evidence of real-repository sufficiency, reduced undetected-regression risk, comparative computation benefit, or independent reproduction."], + "dependencies": [], + "dependents": [], + "active_experiment_ids": [], + "blockers": ["A frozen real public-repository full-verification baseline, complete catalog, production evidence adapter, relevance oracle, native-selector comparison, shadow observations, and independent review are missing."], + "next_task": "Freeze one real public repository's full-verification baseline, catalog, adapter outputs, and relevance oracle, then run an OBSERVE/SHADOW comparison without replacing CI.", + "evidence": ["https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/SPEC.md", "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/PRIOR_ART.md", "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/src/planner.js", "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/src/shadow.js", "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/tests/planner.test.js", "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/tests/value-shadow.test.js", "https://github.com/opsle/affected-verification/pull/1", "https://github.com/opsle/affected-verification/actions/runs/33347673715"], + "completion_criteria": ["Publish production evidence adapters and independently validate their completeness boundaries.", "Run correctness-first comparisons against full verification and native selectors with durable shadow miss evidence.", "Replicate bounded workload and safety claims on independent repositories or environments."], + "completion_evidence": [], + "completion_status": "INCOMPLETE", + "program_state": "active", + "last_verified_at": "2026-08-31T01:29:54Z" + }, { "name": "research", "github_url": "https://github.com/opsle/research", @@ -558,10 +588,10 @@ "project_type": "program infrastructure", "purpose": "Own public research methodology, portfolio reconciliation, experiment records, and the authoritative program ledger.", "lifecycle_stage": "PROTOTYPED", - "implementation_status": "authoritative 20-repository ledger, machine-readable 17-concept theory registry, canonical theory map, normative Visible Value controls, and provider-free EXP-001 benchmark, launch, one-block coordinator, external four-label LIVE_PROVIDER_RUN authorization, and current catalogue/pricing preflight artifacts with six content-addressed tasks, deterministic oracle, four arm contracts, sealed blinded allocation, exact subject configuration and adapter, exact authorization admission, private boundaries, receipts, mutation tests, and integrity CI", + "implementation_status": "authoritative 21-repository ledger, machine-readable 18-concept theory registry including Affected Verification, canonical theory map, normative Visible Value controls, and provider-free EXP-001 benchmark, launch, one-block coordinator, external four-label LIVE_PROVIDER_RUN authorization, and current catalogue/pricing preflight artifacts with six content-addressed tasks, deterministic oracle, four arm contracts, sealed blinded allocation, exact subject configuration and adapter, exact authorization admission, private boundaries, receipts, mutation tests, and integrity CI", "implementation_requirement": "Program infrastructure requires a validated registry, generated dashboard, experiment ledger, operating rules, and CI.", "specification_status": "canonical lifecycle, theory classifications and dispositions, Gearbox and Context Firewall definitions, Gearbox-versus-Durable boundary, Visible Value receipt and measurement classes, operator/model channels, observational corpus, shadow/replay attachment, operating, priority, registry, experiment, and generated-status controls are specified", - "test_status": "88 of 88 repository tests pass on the unreleased provider-free live-preflight branch, including 13 authorization validations and two byte-identical replays; PR #13 and exact main CI remain the released coordinator baseline", + "test_status": "88 of 88 repository tests pass locally after deliberate migration to the 21-repository, 18-concept anti-forgetting set, including 13 authorization validations and two byte-identical replays; generated status and registry validation pass", "benchmark_status": "the EXP-001 provider-free components are frozen at 04234a65bf36192d63f1dd173c440d45a6604d2b, launch controls are preregistered at 31848c3f25ff9371055932657e8e2f8ad54cc8c7, and the one-block coordinator is qualified at 9ee43197880c18d4e185cf7e29e02a151d22a12e; the unreleased branch adds one external exact four-label LIVE_PROVIDER_RUN set and current gpt-5.6-sol catalogue/pricing evidence with zero consumptions, provider/model launches, experiment runs, or results; no causal experiment", "measured_experiment_status": "one legacy integration observation; no canonical measured concept experiment", "reproducibility_status": "program and receipt validation, status generation, public dogfood artifacts, exact-revision EXP-001 offline qualification, public allocation checks, adapter self-test, structural preregistration verification, coordinator unit checks, and live-authorization reconstruction from frozen private inputs are reproducible; the live set replay is byte-identical twice, full secret-backed coordinator replay still requires the external seed, and no subject result exists", @@ -574,11 +604,11 @@ "blockers": ["The exact live authorization set remains unconsumed and unreleased, account-specific API entitlement is unverified under the zero-provider-call policy, no immutable dated model snapshot is documented, and the program has no canonical measured concept experiment."], "next_task": "Independently review and release the provider-free live-authorization and catalogue/pricing preflight; do not consume authorization or launch a provider/model subject.", "evidence": ["program/THEORY_MAP.md", "program/theory-registry.json", "program/evidence/gearbox-publication/README.md", "program/evidence/exp-001-offline-freeze/README.md", "program/evidence/exp-001-preregistration/README.md", "program/evidence/exp-001-block-coordinator/README.md", "program/evidence/exp-001-live-preflight/README.md", "program/evidence/exp-001-live-preflight/model-catalogue.json", "program/evidence/exp-001-live-preflight/pricing-preflight.json", "program/evidence/exp-001-live-preflight/qualification-report.json", "program/evidence/exp-001-live-preflight/value-receipt.json", "https://github.com/opsle/research/blob/04234a65bf36192d63f1dd173c440d45a6604d2b/experiments/exp-001/benchmark.json", "https://github.com/opsle/research/blob/04234a65bf36192d63f1dd173c440d45a6604d2b/program/evidence/exp-001-offline-freeze/qualification-report.json", "https://github.com/opsle/research/blob/31848c3f25ff9371055932657e8e2f8ad54cc8c7/experiments/exp-001/preregistration-v1/preregistration.json", "https://github.com/opsle/research/blob/31848c3f25ff9371055932657e8e2f8ad54cc8c7/program/evidence/exp-001-preregistration/verification-report.json", "https://github.com/opsle/research/blob/9ee43197880c18d4e185cf7e29e02a151d22a12e/experiments/exp-001/coordinator-v1/coordinator.py", "https://github.com/opsle/research/blob/9ee43197880c18d4e185cf7e29e02a151d22a12e/program/evidence/exp-001-block-coordinator/qualification-report.json", "https://github.com/opsle/research/blob/72f9e4a0326d68d3870e2e79ce4e351acb1d8ffa/program/VISIBLE_VALUE_CONTRACT.md", "https://github.com/opsle/research/pull/9", "https://github.com/opsle/research/pull/11", "https://github.com/opsle/research/pull/13"], - "completion_criteria": ["Keep the 20-repository ledger and dashboard mechanically consistent.", "Retain immutable experiment evidence and lifecycle promotion proof.", "Publish program documentation without stale or unsupported claims."], + "completion_criteria": ["Keep the 21-repository ledger and dashboard mechanically consistent.", "Retain immutable experiment evidence and lifecycle promotion proof.", "Publish program documentation without stale or unsupported claims."], "completion_evidence": [], "completion_status": "INCOMPLETE", "program_state": "active", - "last_verified_at": "2026-08-30T18:49:10Z" + "last_verified_at": "2026-08-31T01:29:54Z" }, { "name": "site", diff --git a/program/theory-registry.json b/program/theory-registry.json index e2b7f4d..8749d7b 100644 --- a/program/theory-registry.json +++ b/program/theory-registry.json @@ -1,20 +1,22 @@ { "schema_version": 1, "registry_id": "opsle.theory-registry.v1", - "verified_at": "2026-08-29T02:53:08Z", - "source_repository_count": 20, - "current_concept_repository_count": 17, + "verified_at": "2026-08-31T01:29:54Z", + "source_repository_count": 21, + "current_concept_repository_count": 18, "canonical_definitions": { "gearbox": "Agent Gearbox lets a powerful primary developer delegate routine operations and bounded work to deterministic software or less expensive models, then receive only the compact result needed to continue.", "context_firewall": "Context Firewall is a deterministic boundary that keeps operational noise out of an AI agent's context while preserving the compact evidence, provenance, and escalation path the agent needs to make correct decisions.", - "durable_orchestration": "Durable orchestration owns autonomous objective progress across durable state and multiple activations without requiring a continuously active primary developer." + "durable_orchestration": "Durable orchestration owns autonomous objective progress across durable state and multiple activations without requiring a continuously active primary developer.", + "affected_verification": "Affected Verification deterministically selects the smallest verification workload whose sufficiency can be defended from the available change-impact, dependency, coverage, policy, and risk evidence." }, "canonical_invariants": [ "Gearbox saves intelligence; Context Firewall saves context.", "Gearbox determines where bounded work executes; Context Firewall determines what information returns.", "Gearbox enhances a primary developer; durable orchestration owns progress across activations without that developer remaining continuously active.", "Research-hypothesis granularity does not imply repository granularity.", - "Repository tracking and concept tracking are independent anti-forgetting controls." + "Repository tracking and concept tracking are independent anti-forgetting controls.", + "Affected Verification decides what verification should execute; Context Firewall decides what resulting evidence enters model context." ], "concepts": [ { @@ -700,6 +702,46 @@ "What kernel and broker threat model is in scope?", "How much result sealing belongs solely to Verifiable Handoff?" ] + }, + { + "id": "affected-verification", + "canonical_concept_name": "Affected Verification", + "one_sentence_definition": "Affected Verification deterministically selects the smallest verification workload whose sufficiency can be defended from the available change-impact, dependency, coverage, policy, and risk evidence.", + "original_problem": "Existing affected-test and affected-target selectors do not by themselves establish which heterogeneous verification evidence is sufficient to accept a change, why every omitted check is irrelevant, or when uncertainty and policy must broaden the workload.", + "primary_classification": "INDEPENDENT_OPSLE_TOOL", + "current_repository": "affected-verification", + "recommended_disposition": "KEEP_STANDALONE", + "disposition_rationale": "Verification sufficiency, catalogs, risk policy, fail-closed escalation, and skip arguments are independently reusable by humans, agents, CI, Gearbox, and other developer tooling without belonging to an execution engine.", + "disposition_gain": "A standalone evidence-composition boundary can reuse native affected selectors while remaining verification-class-neutral and independently benchmarkable.", + "disposition_risk": "The project could duplicate mature test-impact systems, overclaim global minimality or safety, or drift into a CI scheduler unless adapters, claim ceilings, and execution boundaries remain explicit.", + "provenance_concerns": "The initial public prototype was created directly in opsle/affected-verification; preserve PR #1, exact revision 12076522c9b82501794d816f1fcc0b7775fad6e1, source-linked prior-art analysis, and synthetic-only evidence without retroactively claiming novelty or real-project safety.", + "relationship_to_gearbox": "Independent provider: Gearbox may request a minimum defensible verification plan and choose execution gears, but it does not own the verification theory, catalog, policy, or implementation.", + "relationship_to_context_firewall": "Complementary and sequential: Affected Verification decides what checks should execute; Context Firewall decides what check results should enter model context after execution.", + "dependencies": [], + "consumers": [ + "gearbox", + "decision-evidence-protocol", + "agent-trajectory-profiler" + ], + "current_implementation_fidelity": { + "status": "NARROW_PROTOTYPE", + "assessment": "The public dependency-free Node.js core validates normalized evidence/catalog/policy input, computes reverse impact, selects and explains checks, fails closed on uncertainty, emits canonical plans and Visible Value receipts, and classifies fixture-level shadow misses. It has no production adapter, check execution, real-repository benchmark, or trusted selective-verification evidence." + }, + "drift_status": "NEW_ALIGNED_PUBLIC_HOME", + "current_name_accuracy": "Accurate for the implemented verification-planning boundary and explicitly broader than affected-test selection.", + "evidence_references": [ + "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/SPEC.md", + "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/PRIOR_ART.md", + "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/src/planner.js", + "https://github.com/opsle/affected-verification/blob/12076522c9b82501794d816f1fcc0b7775fad6e1/tests/planner.test.js", + "https://github.com/opsle/affected-verification/pull/1" + ], + "confidence": "HIGH", + "unresolved_questions": [ + "Which real public repository has a complete enough verification catalog and full-run oracle for the first shadow comparison?", + "Which native selector should be the first evidence adapter without duplicating its impact logic?", + "Which evidence-based promotion criteria justify TRUSTED_BOUNDED authority for a narrowly defined change class?" + ] } ] } diff --git a/tests/test_validate_program.py b/tests/test_validate_program.py index 71f692f..b7d9ce4 100644 --- a/tests/test_validate_program.py +++ b/tests/test_validate_program.py @@ -29,8 +29,8 @@ def errors_for(self, registry=None, experiments=None): def test_authoritative_registries_are_valid(self): self.assertEqual(self.errors_for(), []) - def test_gearbox_is_the_twentieth_repository(self): - self.assertEqual(len(self.registry["repositories"]), 20) + def test_affected_verification_is_the_twenty_first_repository(self): + self.assertEqual(len(self.registry["repositories"]), 21) gearbox = next( item for item in self.registry["repositories"] if item["name"] == "gearbox" @@ -40,6 +40,15 @@ def test_gearbox_is_the_twentieth_repository(self): gearbox["last_verified_head_sha"], self.registry["gearbox_publication"]["final_main_sha"], ) + affected = next( + item for item in self.registry["repositories"] + if item["name"] == "affected-verification" + ) + self.assertEqual(affected["lifecycle_stage"], "PROTOTYPED") + self.assertEqual( + affected["last_verified_head_sha"], + "12076522c9b82501794d816f1fcc0b7775fad6e1", + ) def test_missing_expected_repository_fails(self): registry = copy.deepcopy(self.registry) diff --git a/tools/validate_program.py b/tools/validate_program.py index db2b521..f844ea2 100644 --- a/tools/validate_program.py +++ b/tools/validate_program.py @@ -37,6 +37,7 @@ "agent-recovery-policy", "ephemeral-agent-workers", "gearbox", + "affected-verification", "research", "site", ".github", @@ -883,8 +884,8 @@ def validate_theory( errors.append( f"theory.source_repository_count must be {len(EXPECTED_REPOSITORIES)}" ) - if theory.get("current_concept_repository_count") != 17: - errors.append("theory.current_concept_repository_count must be 17") + if theory.get("current_concept_repository_count") != 18: + errors.append("theory.current_concept_repository_count must be 18") if not _valid_timestamp(theory.get("verified_at")): errors.append("theory.verified_at must be an ISO-8601 UTC timestamp") @@ -909,10 +910,10 @@ def validate_theory( duplicate_ids = sorted(item for item, count in Counter(ids).items() if count > 1) if duplicate_ids: errors.append(f"duplicate theory concept IDs: {', '.join(duplicate_ids)}") - if len(concepts) != 17: - errors.append(f"expected 17 theory concepts, found {len(concepts)}") + if len(concepts) != 18: + errors.append(f"expected 18 theory concepts, found {len(concepts)}") - current_concept_repositories = set(EXPECTED_REPOSITORIES[:17]) + current_concept_repositories = set(EXPECTED_REPOSITORIES[:18]) current_mappings: list[str] = [] concept_ids = set(ids) concept_by_id = { @@ -1002,8 +1003,8 @@ def validate_theory( errors.append(f"duplicate current concept repository mappings: {', '.join(duplicate_mappings)}") if missing_mappings: errors.append(f"missing current concept repository mappings: {', '.join(missing_mappings)}") - if len(current_mappings) != 17: - errors.append(f"expected 17 current concept repository mappings, found {len(current_mappings)}") + if len(current_mappings) != 18: + errors.append(f"expected 18 current concept repository mappings, found {len(current_mappings)}") gearbox = concept_by_id.get("gearbox") if gearbox is None: @@ -1040,7 +1041,9 @@ def validate_theory( if isinstance(item, dict) and isinstance(item.get("name"), str) } if "gearbox" not in repo_names: - errors.append("the 20-repository registry must contain gearbox") + errors.append("the authoritative repository registry must contain gearbox") + if "affected-verification" not in repo_names: + errors.append("the authoritative repository registry must contain affected-verification") if registry.get("theory_registry") != "program/theory-registry.json": errors.append("registry.theory_registry path is invalid") if registry.get("theory_map") != "program/THEORY_MAP.md":