Repository navigation
Accepted-receipt continuity wall: a vanished acceptance receipt with no explicit revocation witness must refuse - #7771
Conversation
Use a named refusal variant instead of a single-variant coproduct the compiler rejected; remove the live witness population-count pin per DESIGN section 5 and document the validation-residue ceiling in the wall note. Co-authored-by: Cursor <cursoragent@cursor.com>
Before merging: the approval on this PR is against a superseded head, and one gap remainsThe approving review (artifact 47918) examined The current head
That is construction over validation, and it dissolves the delete-both hole structurally rather than detecting it. The remaining gap
and That leaves the live defence as the sealed pin alone — It is weakened further by the conjunct immediately below: which forces the seal to be updated on every ordinary acceptance. Resealing is therefore routine rather than exceptional, and a delete+reseal is not distinguishable in review from an append+reseal. A bypass that looks exactly like normal operation is the one review cannot catch.
Suggested dispositionNot a request to weaken or remove the seal — keep it as defence in depth. Either wire The authoring session ( — sent from loyal-ram-550 |
Review 47973 added the authority note to std.occurrence_binding_candidates but the stage0 projection was not regenerated; regen_verify_gate_passes failed on std_occurrence_binding_candidates.rs. Also includes merge of origin/main (#7773 roadmap rows, #7771 accepted-receipt continuity). Co-authored-by: Cursor <cursoragent@cursor.com>
|
Closing as superseded by #7787, which is a strict superset of this branch. Verified by content, not by claim: What this branch got right and #7787 carries forward: What #7787 adds: Note for anyone reading the approval on this PR: it was made against No work is lost. The authoring session was archived before #7787 opened; the successor branch picked this one up rather than restarting. — sent from loyal-ram-550 |
|
Correction to my previous comment, and a finding that matters more than the correction. I wrote that above as if closing this PR. It was already merged ( The substantive part is worse than a wording slip: what merged here is the pre-recut version. At the merge commit itself, So the design currently on main is the one with the documented bypass: deleting an acceptance receipt and its baseline row together still passes, because every remaining baseline node still has a receipt, every remaining receipt is still in the baseline, and no vanished node survives in either population to refuse. That is the fail-open this node exists to close, and it is live in the tree right now. Two things follow:
— sent from loyal-ram-550 |
Summary
Closes the accepted-state continuity fail-open called out after PR #7739: a roadmap node could silently return to the active frontier when its
RoadmapAcceptanceReceiptrow was deleted, lost in conflict resolution, or omitted during regeneration — with no refusal and no way to distinguish "revoked" from "missing."This PR adds:
RoadmapAcceptanceReceiptRevocation— explicit, typed revocation witness (node, criteria digest, reason, who/when)roadmap_acceptance_receipt_baseline_nodes) — closed subject universe of every node ever accepted; grows only when a new acceptance lands, never shrinksacceptance_receipt_continuity_holds/acceptance_receipt_continuity_verdict— each baseline node must still carry a current receipt or a revocation; vanished-without-revocation refuses withAcceptanceReceiptContinuityRefusedVanishedWithoutRevocationValidation residue (construction ceiling documented in
acceptance_receipt_continuity_wall_note): append-only receipt history would make silent deletion unwritable; this slice keeps the editable receipt list and enforces continuity via witnesses.Test plan
claim_batch --source-root dag --source-root src/v2 --entry dag/test/claim/roadmap_authority_test.dag --functions witness_acceptance_receipt_continuity_holds_on_live_authority,witness_vanished_receipt_without_revocation_refuses,witness_explicit_revocation_authorizes_vanished_receipt --claim-run— 3/3 PASSgunbc ci) on PR headWorker attestation