Skip to content

Gate A U1f: growth exponent for the child-usage linearity checks (validate-macos flaked on the per-doubling ratio) - #556

Merged
seathatflowsinourveins merged 2 commits into
mainfrom
claude/pra-u1f-scaling-fit-6d-20260930
Sep 30, 2026
Merged

seathatflowsinourveins merged 2 commits into
mainfrom
claude/pra-u1f-scaling-fit-6d-20260930

Conversation

@seathatflowsinourveins

Copy link
Copy Markdown
Owner

Scope

SOTA sources

Evidence-class table

Claim Evidence class Command / receipt
The old check failed linear scanners on macOS: quoted words [9, 16, 48, 104] and [7, 17, 47, 84] ms, run strings [55, 103, 203, 519] ms at n = 8000 to 64000 native_proven (actual CI runs) actions runs 36745793168 and 36751526079, full-suite-macos.log
All 36 recorded macOS samples have an exponent of 1.19 or less (worst 1.188, recomputed by the independent review); the pre-repair scan continued quadratically is 2.09 local_integration (recomputed from the recorded CI output) the four rejected or borderline samples and the pre-repair scan are controls in the suite
Anything the old check accepts, the new one accepts (t64 <= 6.25 * t16 + 17.5 implies t64 < 8 * t16 + 35), so no linear scan can newly fail source_review (algebra; a random search of 2,000,000 samples found no counterexample in the independent review) review of this diff
Detection is weaker for small quadratics: a pure quadratic passes while its time at 16,000 is under 4.4 ms (under 70 ms at 64,000; the old ratio failed it above 13 ms); the 150 ms bound for (( and the 1.5 s bound of the other shapes are the guard there source_review (stated in the test comment and the README) the same review
The modified suite passes on Linux and the harness refuses a scan that is quadratic by construction ([6, 24, 103, 436] ms, exponent 1.97) native_proven (local run) commands below
macOS passes the new criterion not run yet; this PR's own validate-macos is the first macOS run of it CI of this PR

Local commands run

$ TMPDIR=/var/tmp/gate-a-u1f-tests node examples/claude-native/workflows/test-child-usage.mjs
SUMMARY passed=219 failed=0 total=219
$ node examples/claude-native/workflows/test-envelope.mjs        SUMMARY passed=254 failed=0 total=254
$ node examples/claude-native/workflows/test-contract-mutations.mjs   SUMMARY passed=74 failed=0 total=74
$ TMPDIR=/var/tmp/gate-a-u1f-tests python3 -B -m unittest tests.test_child_usage_suite tests.test_context_mode_practice_docs tests.test_install_claude_profile tests.test_record_verdicts tests.test_token_e2e_preregistration
Ran 238 tests in 43.626s  OK (skipped=3)
$ TMPDIR=/var/tmp/gate-a-u1f-tests python3 -B scripts/validate.py
{"components": 69, "hashed_files": 8545, "profiles": 4, "receipts": 176, "status": "passed"}
$ (cd examples/claude-native/workflows && sha256sum -c SHA256SUMS)   all OK
$ git diff --check origin/main..HEAD   (exit 0)

An independent Opus review (read-only, with code execution for the arithmetic) found no high-severity defect and recomputed the numbers above; its medium and low findings (the comment misdescribed the upstream method, the dropped per-doubling rule and its README sentence, a control label, the quadratic control's margin) are applied.

Decision record

No new record: a test-robustness change to an existing check. The overturn condition is in the test comment: the criterion is replaced again if validate-macos fails it on a linear scanner (exponent of 1.5 or more), or if a scan that is quadratic by construction passes it.

Host evidence

Not applicable: no file under evidence/hosts/ changes.

Checklist

  • New/changed GitHub Actions are pinned to a full commit SHA with a version comment (no floating tags): none changed.
  • New/changed workflows declare top-level permissions: contents: read: none changed.
  • No secrets are printed, logged or committed; no new required secret was added.
  • No new paid hosting, subscription or billing surface was introduced.
  • Peer-owned untracked files and worktrees were preserved (not deleted, moved or overwritten).

🤖 Generated with Claude Code

Scout and others added 2 commits September 30, 2026 14:41
validate-macos failed tests.test_child_usage_suite on #548 (two attempts) and #552: the per-doubling check (each size at most 2.5 times the last plus
5 ms) rejected linear scanners at steps of 2.56 to 3.0 times on the macOS runner (actions runs 36745793168 and 36751526079). The criterion is now the
growth exponent from 16000 to 64000, ln((t64 + 5 ms) / (t16 + 5 ms)) / ln 4, under 1.5 (1 is linear, 2 is quadratic); the best-of-five timing, the
3-round retry, the 150 ms bound for unclosed "((" and the 1.5 s bound of the other shapes stay. All 36 macOS samples of those runs have an exponent of
1.19 or less; the scan measured before the D8 repair, continued quadratically, is 2.09. Detection is weaker for small quadratics (a pure quadratic
under 70 ms at 64,000 passes the exponent; the absolute bounds are the guard), which the test comment and the workflows README now say. Three
controls are added: the recorded macOS samples pass, the pre-repair scan fails, and a scan that is quadratic by construction is refused by the same
harness. An independent Opus review found no high-severity defect; its comment, label and README findings are applied.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…and SHA256SUMS in manifests/evidence.json

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@seathatflowsinourveins seathatflowsinourveins added the lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers label Sep 30, 2026
@seathatflowsinourveins
seathatflowsinourveins merged commit 7d7dcd0 into main Sep 30, 2026
25 checks passed
@seathatflowsinourveins
seathatflowsinourveins deleted the claude/pra-u1f-scaling-fit-6d-20260930 branch September 30, 2026 19:53
seathatflowsinourveins pushed a commit that referenced this pull request Oct 1, 2026
…ds (the #556 criterion)

test_k4_timing judged each helper by one CPU-time sample per size with "100k under 8 times 25k"; PR #567's hosted
validate failed it on two linear helpers at margins of 1 to 6 % (k4_shell_literals 0.1058 against 0.0998,
k4_store_text 0.1408 against 0.1397). It now uses the criterion of examples/claude-native/workflows/
test-child-usage.mjs (#556): the growth exponent ln((t100k + 5 ms) / (t25k + 5 ms)) / ln 4 under 1.5, over the
elementwise minimum of up to three rounds, with K4_LINEAR_SECONDS kept as the absolute bound. Measured with the
minimum of three rounds on the workstation, all 67 helpers fit exponents of 0.975 or less. A new test pins the
criterion: the two failing CI samples pass and a helper quadratic by construction fails from 4.5 ms at 25k up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 1, 2026
…ds (the #556 criterion)

test_k4_timing judged each helper by one CPU-time sample per size with "100k under 8 times 25k"; PR #567's hosted
validate failed it on two linear helpers at margins of 1 to 6 % (k4_shell_literals 0.1058 against 0.0998,
k4_store_text 0.1408 against 0.1397). It now uses the criterion of examples/claude-native/workflows/
test-child-usage.mjs (#556): the growth exponent ln((t100k + 5 ms) / (t25k + 5 ms)) / ln 4 under 1.5, over the
elementwise minimum of up to three rounds, with K4_LINEAR_SECONDS kept as the absolute bound. Measured with the
minimum of three rounds on the workstation, all 67 helpers fit exponents of 0.975 or less. A new test pins the
criterion: the two failing CI samples pass and a helper quadratic by construction fails from 4.5 ms at 25k up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins added a commit that referenced this pull request Oct 1, 2026
…agement routes (#567)

* Inventory: injectable claude-oauth-token entry, CLAUDE_CODE_OAUTH_TOKEN in must_not_be_set

Adds the optional private_env_file entry `claude-oauth-token`
(${XDG_CONFIG_HOME:-$HOME/.config}/native-agent-stack/claude-oauth-token.env,
sole variable CLAUDE_CODE_OAUTH_TOKEN, no public or pointer variables) per
K4 contract-v2 section 6.5 and amendments A3/A13, and lists
CLAUDE_CODE_OAUTH_TOKEN in must_not_be_set: exported in a shell it would
override every Claude Code session's native sign-in, so it is injected per
command only through tools/credentials/credential_run.py. The entry is
injectable, so tests/test_credential_run.py's INJECTABLE_IDS gains it
(A3 authorizes that line only).

Peer input (A13): the class provider_api_key, the credential_run.py loader
line, the Harbor 0.23.0 claude-code consumer
(src/harbor/agents/installed/claude_code.py:1709-1736) and the rotation
wording that revokes the old token come from the sota-memory-foundation
session's unlanded patch (from-34-claude-oauth.patch); the id and file name
stay claude-oauth-token to match the kernel keyring id already in use.

Edits made by the GPT-6 runtime worker in the k4-build clone before its
deadline; committed unchanged by the continuing Claude session.

Co-Authored-By: GPT-6 Codex runtime worker (gpt-6-astra-max via OmniRoute, effort max) <noreply@openai.com>

* Settings template: Read denies for both OmniRoute data trees

Adds the four Read denies of K4 contract-v2 section 6.5 in the template's
existing convention: Read(~/.local/share/omniroute/**),
Read(**/.local/share/omniroute/**), Read(~/.local/share/omniroute-fw/**)
and Read(**/.local/share/omniroute-fw/**). Metadata only; no host setting
changes. (As left by the worker, the new lines and the preceding
.config/omniroute twin are indented with four spaces instead of six; the
next commit restores the template's indentation.)

Edits made by the GPT-6 runtime worker in the k4-build clone before its
deadline; committed unchanged by the continuing Claude session.

Co-Authored-By: GPT-6 Codex runtime worker (gpt-6-astra-max via OmniRoute, effort max) <noreply@openai.com>

* Guard K4 draft: runner, gateway, manager, store, ps, canary, F and CODE rules with their tests

The GPT-6 runtime worker's uncommitted K4 implementation as it stood at its
deadline (contract-v2 plus amendments A1-A13), committed unchanged so that
its authorship stays separate from the repairs that follow:

- a second, K4 reading (module flag _baseline) beside the dc33b48 reading
  B(T), which keeps B's string-tuple segment identity, its names and its
  stores; the K4 reading adds descriptor metadata to segment identity
  (D-ID), CLAUDE_CODE_OAUTH_TOKEN and CLAUDE_CODE_MESSAGING_TOKEN, both
  OmniRoute data trees, runner starts and the shell -c/eval reading before
  a keyring or runner unwrap;
- RUN (start, environment, usage, mentions), GW (the frozen matrix, curl,
  wget, httpie/xh, requests/httpx, urllib, fetch, the omniroute CLI),
  MANAGER, STORE-LITERAL, PS-SELECTOR and CANARY rules and their hints;
- form F recognition, interpreter here-document regions with a Python/JS
  lexer, SHELL-LITERAL, SHELL-OUT, WHOLE-ENV, INLINE-ENV and TAIL-READ;
- K4GuardTests (22 of the contract's 28 named tests) and an independent
  reference_form_f.

State at this commit (python3 -B -m unittest tests.test_secret_path_guard:
68 tests, 12 failures, 1 error): the K4 reading re-reads every command and
charges many whole-text passes, so seven existing budget and timing rows
fail (command_too_complex or over the 0.5 s CPU gate); the two authorized
verdict changes (a safe form F body, the inline whole-environment print)
are not yet reflected in the existing tests; adoption/hooks/claude/SHA256SUMS
is not recomputed; and test_host_profile_copy_is_verbatim fails as
tolerated. The following commits repair these and complete the contract.

Co-Authored-By: GPT-6 Codex runtime worker (gpt-6-astra-max via OmniRoute, effort max) <noreply@openai.com>

* Settings template: restore the deny list indentation

The previous commit indented the four new OmniRoute data-tree Read denies
and the existing Read(**/.config/omniroute/**) line with four spaces;
the template uses six. Whitespace only: against dc33b48 the template now
differs by exactly the four added deny lines (contract-v2 section 2).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4: B(T) first, then anchored tightenings in the contract's tier order

Repairs the draft's reading structure (contract-v2 sections 1 and 3,
amendments A4 and A5). read_command() now computes B(T) exactly as
dc33b48 does (whole-text rules with its names, then this version's and
the prior word readings, string-tuple identity) and returns B's reason
for every command B refuses. Only for a command B allows does
k4_tightenings() run, in the order (a) added names and stores, (b) runner
keyring-equivalent rules and existing rules on what only the K4 walk
reads, (c) runner usage and mentions, (d) gateway, (e) manager, (f)
literal stores, (g) ps selectors, (h) canary, (i) SHELL-LITERAL,
SHELL-OUT, WHOLE-ENV, (j) tails.

Why: the draft read every command twice (a second full base reading
with _baseline False) and charged many whole-text passes, so a command
near the budget that B allows became command_too_complex and the
0.5 s CPU gate failed (seven existing rows). Now:

- one charged scan of the unquoted text finds the K4 anchors (a runner,
  keyring or canary basename, a gateway port, a selector or new secret
  name, a data-tree name, a manager verb, `<<`, an environment source);
  a rule whose literal is absent does no work, so an ordinary command
  pays one pass;
- a K4 walk (metadata identity, runner starts, shell strings read
  before a keyring or runner unwrap) runs only when a runner or keyring
  start exists or when B's own deduplication dropped a string duplicate
  with other descriptors (note_identity_collision, D-ID);
- the added names and trees are checked as deltas over both readings'
  segments; B's functions keep BASE_* names and stores;
- form F is recognized on its own (k4_form_f); regions follow logical
  lines and the bash delimiter word; TAIL-READ reads the text after each
  exact quoted terminator in the context bash resumes in
  (k4_resume_contexts), piece by piece with equal pieces read once, so
  4,000 commit-message here-documents cost two reads instead of 4,000
  suffixes;
- SHELL-LITERAL reads a double-quoted literal's substitution bodies (as
  the base does), not the whole literal as a command; SHELL-OUT also
  reads exec/spawn argv without the program path; WHOLE-ENV fails closed
  on reflective or aliased sources (getattr(x, 'environ'), o.environ,
  a bare process, require('process')), NFKC-normalizes Python code and
  treats a JS method call on process.env as no single key; the JS lexer
  knows regular-expression literals and flags identifier escapes;
- inline code: the installed Python 3.13.15 and Node 24.21.0 option
  tables (value options, -p/--print, here-strings to an interpreter),
  with an uncertain command line failing closed on a visible source;
- curl: more ordinary options, --globoff, URL glob expansion (bounded);
  percent escapes cannot hide an /api path;
- the two authorized verdict changes are recorded in the existing
  tables (the harmless F body moved out of BLOCKED; the inline
  whole-environment print moved from EXPECTED_PASS_THROUGH to BLOCKED).

python3 -B -m unittest tests.test_secret_path_guard: 68 tests, 1
failure (test_host_profile_copy_is_verbatim, tolerated until the
coordinator installs after window W). The checksum line is recomputed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4: complete the contract's fixtures and named tests; repairs they found

Tests (tests/test_secret_path_guard.py), all inert strings for check():

- every example of contract-v2 sections 3 to 7 not already listed,
  expanded without ellipses (1,514 K4_CASES fixtures across the 20 case
  groups), plus the review witnesses of this repair round;
- K4_F_LABELED: 111 manually labelled form F boundaries (every grammar
  token and option, both quotes, the PY'2/JS'1 suffix blockers, CR/tab/
  trailing-space terminators, ANSI-C and backslash delimiters, leading
  lines, several operators, launchers, options and tails), checked
  against the independent reference_form_f and the guard's k4_form_f
  with their body spans;
- K4_BASE_REFUSED: the measured base outcome of every fixture the pinned
  base refuses (88; amendment A10, a recorded local measurement against
  dc33b48, sha256 a70a056f...), and test_k4_base_reason_precedence
  holds the guard to those reasons outside form F;
- the five named tests the draft lacked: test_k4_prior_only_heredoc_controls
  (current reading None, prior reading dotenv_read, as measured at the
  base), test_k4_original_review_controls (the eighteen historical
  fixtures; B5 command_too_large in the real hook),
  test_k4_helper_failures_and_budget_charges (every new helper reached,
  then raising inside main() and in a child process; own charge per
  scanning helper; one shared budget), test_k4_timing (48 section 9.6
  rows in fresh children, median CPU under 0.5 s, per-helper 25k/50k/100k
  generators) and test_k4_hook_process_and_hints (the real hook, every
  new reason, allowed controls, the size cap, hint concepts, no command
  text or sentinel in the output).

Guard repairs found by these tests:

- the gateway rules also run when curl runs (its URL globbing can spell
  a port: 2012[8-9]); a covered URL inside an interpreter command line
  whose options could not all be read is found by K4_GW_FIND;
- a keyring exec's started command is reread through k4_join in the K4
  walk (a touching descriptor stays touching: D-ID);
- the K4 walk reruns only where it can differ (k4_needs_walk: a runner
  start, a descriptor collision, or a keyring start with descriptors or
  inside a shell or eval segment);
- STORE-LITERAL walks only stages and texts that name the keyring script;
- the runner and interpreter-operand questions are memoized per word
  list (k4_memo), so the tiers do not charge the same scan repeatedly.

python3 -B -m unittest tests.test_secret_path_guard: 73 tests, 1 failure
(test_host_profile_copy_is_verbatim, tolerated). The credential_status,
credential_boot_receipt, install_claude_profile, credential_run and
credential_tools suites pass. Checksum line recomputed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4: finish the contract's gates: OmniRoute option repair, checksum, documentation, sanitized fixtures

The continuation a GPT-6 runtime worker completed after the Opus builder stopped at a usage limit: the preserved OmniRoute
option repair and its SHA256SUMS line, the guard documentation within the contract's allowed regions, the credential
runner's docstring lines, and three inert fixture home paths sanitized. The worker's sandbox mounts .git read-only, so the
coordinator commits its working tree unchanged. Its handoff records the gates: guard suite 73 tests (only the host-copy
test fails, by design), oracle, probes, replay and differential families exit 0, timing and real hook processes pass;
still open: five mutation survivors, 163 tightenings without an attribution label, and the whole repository suite, which
the sandbox could not finish.

Co-Authored-By: GPT-6 Codex runtime worker (gpt-6-astra-max via OmniRoute, effort max) <noreply@openai.com>

* Guard K4: the one repair round against the GPT-6 verification and the Opus review

A GPT-6 runtime worker (gpt-6-astra, effort max, native login) repaired every finding of both reviews; the coordinator
commits its working tree unchanged (the worker's sandbox mounts .git read-only):
- the two hook-timeout inputs: charged indexes replace repeated assignment-suffix scans and failed regex lookahead,
  and the real hook answers the review's generators within one second;
- the runner path no longer expands a command twice; K4's named timing rows keep the contract's 0.5 s CPU bound;
- the eleven missed tightenings (empty URL userinfo, HTTPie/xh operands, urllib's positional method, attribute
  reassignment, commands started through credential_run, CR/CRLF/U+2028/U+2029 comment endings, environment-copy
  aliases with secret keys, the SHELL-OUT argv prefix, os.spawn* modes, STORE-LITERAL through builtin/command and
  ANSI-C feeds, the canary triggers through executing python -m modules), each with BLOCKED and control rows;
- the urlopen(timeout=) false refusal and the low findings;
- the mutation gate counts only failures of the named permanent tests: every decisive witness now lives in
  tests/test_secret_path_guard.py, and the budget mutants use limits derived from single-stage measurements;
  461 of 461 mutants killed;
- the runner parser-vocabulary test against credential_run.parse_args;
- the guard documentation states which reasons change for form F.

Co-Authored-By: GPT-6 Codex runtime worker (gpt-6-astra, native, effort max) <noreply@openai.com>

* Guard K4 docs: the five residuals the read-only re-check of the repair round found

The re-check (GPT-6, read-only) confirmed every finding of both reviews fixed and found no command K3 refuses
that K4 allows outside form F. It found two gateway forms both guards allow (keyword-ordered urlopen of a
Request, augmented full_url assignment), two false refusals K4 introduced (an incomplete computed argv item,
command -v lookup read as an assignment) and one generated 193,560-character urllib command that takes about
1.9 s in the real hook. The documented-command replay stays at 0 newly blocked, 0 loosened, 0 reason changed
against both K3 and the installed guard, so they are recorded as residuals for the next guard change.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register the K4 guard changes and its verification receipt (hot-file commit, last)

evidence/receipts/guard-k4-verification-20261001.json records the coordinator's gates on the final K4 head
(documented-command replay against K3 and against the installed guard, the acceptance oracle, the tracked-file
scan, the gitleaks ancestry scan and the targeted suites), the repair worker's mutation gate, the reviews and
the five residuals. manifests/evidence.json re-registers the eight changed files and adds the receipt;
scripts/validate.py passes with 179 receipts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Runner tests: synthetic values drawn from letters outside the hex alphabet (flaky echo check)

assert_never_echoed refuses any six-character piece of a test value in the output, and the reports print hex
SHA-256 digests; with hex values a piece matched a digest by chance in about 0.07% of runs (a simulation of
test_parser_never_expands' own value shapes: 138 of 200,000), which failed PR #544's validate job on
"['abe471']". Values now map each hex digit to one of the letters g-v, which no digest contains.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4 timing: growth exponent over the minimum of up to three rounds (the #556 criterion)

test_k4_timing judged each helper by one CPU-time sample per size with "100k under 8 times 25k"; PR #567's hosted
validate failed it on two linear helpers at margins of 1 to 6 % (k4_shell_literals 0.1058 against 0.0998,
k4_store_text 0.1408 against 0.1397). It now uses the criterion of examples/claude-native/workflows/
test-child-usage.mjs (#556): the growth exponent ln((t100k + 5 ms) / (t25k + 5 ms)) / ln 4 under 1.5, over the
elementwise minimum of up to three rounds, with K4_LINEAR_SECONDS kept as the absolute bound. Measured with the
minimum of three rounds on the workstation, all 67 helpers fit exponents of 0.975 or less. A new test pins the
criterion: the two failing CI samples pass and a helper quadratic by construction fails from 4.5 ms at 25k up.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4 timing: processor-time bounds scaled by host speed (the hosted macOS runner is about 2.8 times slower)

PR #567's validate-macos failed K4's fixed 0.5 s processor-time bound on linear work: row T-STORE-PRINTF took
0.550 s and k4_runner_commands' whole check 0.562 s on the hosted macOS runner, where this workstation measures the
row at 0.197 s. The bound now scales by k4_host_factor(): this host's time for a guard-independent reference (the
standard library's pure-Python shlex lexer over a fixed text, minimum of five runs) relative to the workstation's
0.0355 s, never below 1, a reference-machine ratio as SPEC CPU reports speed. On the workstation the bound stays the
contract's 0.5 s; a quadratic regression still grows 16 times per 4 times input and fails on any host. The controls
test pins the scale (1 on a faster host, proportional on a slower one). docs/secret-storage.md states both criteria.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4 timing: the host-speed reference also lexes one long quoted word

The second hosted macOS run of PR #567 measured row T-STORE-PRINTF at 0.522 s against a scaled bound of 0.515 s:
the short-word shlex reference ran at 1.03 times the workstation there, while the row, whose time is mostly the
standard library's shlex building one 120,000-character quoted token by repeated string concatenation (a cost that
follows the platform's allocator), ran at 2.6 times. The reference text now holds short words and that long quoted
word (0.188 s here, minimum of five runs), so the factor follows both costs; the docs say so.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Guard K4: curl -0 and pypy3 here-documents (the two review threads on PR #567)

Two false refusals the Codex review bot reported on #567 (P2):
- `curl -0` selects HTTP/1.0 like `--http1.0` (curl(1): "-0, --http1.0  Use HTTP 1.0"), but the short-flag table
  lacked it, so `curl -0 http://127.0.0.1:20128/api/health` was refused as gateway_credential_route; `0` is now a
  recognized short flag, and routes and bodies are judged as before (`-0` with /api/settings or with -d still refused).
- form F's interpreter expression accepted `pypy` but not `pypy3`, while K4_PYTHON and the contract's form-F grammar
  (PY := ... "pypy" [ "3" ]) accept both; `pypy3 - <<'PY'` now qualifies, and its bodies are read as Python
  (`set()` allowed, `print(os.environ)` refused as environment_dump). The test file's independent form-F reference
  and the docs' PYNAME rule follow.
Guard sha256 33a11fc01ee35dc4b157b04eee4a8524460bb3fe74375ee32485bc3b2530782f (275,624 bytes); SHA256SUMS updated.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

* Register the K4 guard changes and its verification receipt on main (hot-file commit, last)

manifests/evidence.json from main b72c588 with the changed files re-registered and the receipt entry added. The
receipt now names guard sha256 33a11fc0... (the two review-thread fixes) and the coordinator's gates on it: replay
against K3 and the installed guard, oracle, tracked-file scan, growth exponents and targeted suites (409 tests, the
host copy failing by design). scripts/validate.py passes with 181 receipts.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

---------

Co-authored-by: Scout <scout@local>
Co-authored-by: GPT-6 Codex runtime worker (gpt-6-astra-max via OmniRoute, effort max) <noreply@openai.com>
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
seathatflowsinourveins pushed a commit that referenced this pull request Oct 3, 2026
…ect the status section

- publication-checks.json: the failed lookup's recorded command now names the
  repository owner as <user>, the whole-token form scripts/host_receipts.py
  sanitize() writes for the user name. Exit 1, the 404 output and the
  correction fields are unchanged. No convergence record pins this file.
- Status at landing: drop the #600 attribution from the #556 timing bullet
  (#600 changed the Bash secret-path guard's K4 timing test, not the
  child-usage linearity check); state #626 as a dated read without a landing
  instruction; link the program's independent-review section (lines 480-484)
  beside the ownership split (line 178); reword the repository-variable
  observation without a "correction"; add a dated note for the redaction.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lane:foundation Foundation lane: Claude/Codex setup, hosts, memory, RAG, research, workers

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant