Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
47 commits
Select commit Hold shift + click to select a range
003f740
feat(lab): implement CL-03 bounded live-route probes
Wibias Aug 9, 2026
472a1ba
docs(lab): record CL-03 PR #1352 and validation state
Wibias Aug 9, 2026
09d2638
test(lab): cover CL-03 review blockers
Wibias Aug 9, 2026
38e7824
fix(lab): make CL-03 live evidence fail closed
Wibias Aug 9, 2026
422c168
fix(lab): reconcile CL-03 strict contracts
Wibias Aug 9, 2026
41c5c1d
fix(lab): gate live evidence on trusted execution
Wibias Aug 9, 2026
ffc9958
fix(lab): separate test execution from live evidence
Wibias Aug 9, 2026
e064e4c
fix(lab): make installation salt creation atomic
Wibias Aug 9, 2026
30f2df0
fix(lab): sanitize destination policy failures
Wibias Aug 9, 2026
25cc54b
fix(lab): close live result classification type
Wibias Aug 9, 2026
9b46613
fix(lab): enforce pinned connect timeout
Wibias Aug 9, 2026
735beb2
fix(lab): constrain live response metadata
Wibias Aug 9, 2026
98bfcf2
fix(lab): type live failure classification
Wibias Aug 9, 2026
836be56
fix(lab): bind trusted live results to execution receipts
Wibias Aug 9, 2026
c05df3c
fix(lab): require trusted receipt before live persistence
Wibias Aug 9, 2026
316eee6
fix(lab): enforce byte-identical live authority mirror
Wibias Aug 9, 2026
a175558
fix(lab): correct live manifest authority limits
Wibias Aug 9, 2026
73b1381
chore(lab): prepare authority mirror sync
Wibias Aug 9, 2026
69159b3
fix(lab): sync normative live authority bytes
Wibias Aug 9, 2026
6fd8d4a
fix(lab): fail closed on live projection applicability
Wibias Aug 9, 2026
6950e21
fix(lab): derive live applicability from ledger claims
Wibias Aug 9, 2026
83c72db
fix(lab): remove forgeable executor authority factory
Wibias Aug 9, 2026
6128f6f
fix(lab): issue live executor capabilities in host integration
Wibias Aug 9, 2026
b4e2798
test(lab): cover trusted live evidence boundaries
Wibias Aug 9, 2026
1b3ea04
test(lab): reject forged live executor authority
Wibias Aug 9, 2026
fdc2a69
fix(lab): close expected failure classification
Wibias Aug 9, 2026
b6ef4ed
fix(lab): bound destination resolution by connect timeout
Wibias Aug 9, 2026
62196b0
test(lab): cover destination timeout and canonicalization
Wibias Aug 9, 2026
ec89264
fix(lab): keep shared pinned connect timeout opt-in
Wibias Aug 9, 2026
562555c
docs(structure): record CL-03 trust boundaries
Wibias Aug 9, 2026
7eb76e6
fix(lab): classify destination connect timeout as blocker
Wibias Aug 9, 2026
ae590ec
fix(lab): publish installation salt after durable staging write
Wibias Aug 9, 2026
161048c
test(lab): cover multiprocess salt publication
Wibias Aug 9, 2026
8308c9f
docs(lab): correct CL-03 focused test totals
Wibias Aug 9, 2026
c6117a5
docs(lab): correct CL-03 implementation test totals
Wibias Aug 9, 2026
07b40fe
docs(lab): restore CL-03 implementation record and test totals
Wibias Aug 9, 2026
a80f79a
docs(lab): restore PR stack status and test totals
Wibias Aug 9, 2026
e0a07e2
fix(lab): harden salt publication durability
Wibias Aug 9, 2026
47ad32f
fix(lab): type pinned connect timeouts
Wibias Aug 9, 2026
c4e3ea9
fix(lab): preserve pinned connect timeout code
Wibias Aug 9, 2026
d53fde7
fix(lab): persist live retry policy
Wibias Aug 9, 2026
081c372
fix(lab): bind trusted receipt to result payload
Wibias Aug 9, 2026
5d2b494
test(lab): reject mutated trusted live results
Wibias Aug 9, 2026
4ee6cda
test(lab): use public IPv6 sandbox fixture
Wibias Aug 9, 2026
4446677
fix(lab): tolerate unsupported directory fsync
Wibias Aug 9, 2026
998de8a
fix(lab): seal exact failure retry policy
Wibias Aug 9, 2026
7db3e4b
fix(lab): persist sealed retry decision
Wibias Aug 9, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
37 changes: 35 additions & 2 deletions devlog/_plan/260807_compatibility_lab/001_pr_stack_status.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ independent review, blockers, and whether a later phase is authorized.
| CL-00 | `feat/cl-00-compatibility-contracts` | `3ad5bb6bd3f76f6879d84b78ea39edd3e01ec296` | `c014464237fd3c95bda08bc18bfab8ba8f532308` | [#1286](https://github.com/lidge-jun/opencodex/pull/1286) | ACCEPTED AFTER CODERABBIT REMEDIATION (merged to `dev` at `243c3f4905797aa11c62ba933bb03d6d721266fd`) |
| CL-01 | `feat/cl-01-conformance-harness` | `c2113ca47b8a05c5a5f90679e4eaa640ca2c6a66` | `22d608c82d82e2746c0cef9cd761db19a8e465ee` | [#1320](https://github.com/lidge-jun/opencodex/pull/1320) | MERGED TO `dev` at `4bb249b756abd468c675d2d92fffe4da95ad3e2a` |
| CL-02 | `feat/cl-02-evidence-ledger` | `4bb249b756abd468c675d2d92fffe4da95ad3e2a` | NOT RECORDED | [#1333](https://github.com/lidge-jun/opencodex/pull/1333) | MERGED TO `dev` at `025c37916225dd685d9217e5b40190600f06d278`; POST-MERGE HARDENING [#1343](https://github.com/lidge-jun/opencodex/pull/1343) MERGED at `eee2dab4d1bbacefce56057adad51d734f346702`; FINAL CLOSURE GATE [#1348](https://github.com/lidge-jun/opencodex/pull/1348) |
| CL-03 | | | | | NOT STARTED; AUTHORIZATION ACTIVATES ON #1348 MERGE AFTER GREEN CI/REVIEW |
| CL-03 | `feat/cl-03-live-route-probes` | `4f746d13799888ea0a8c7a111aa2ad61c2126ea0` | `003f7402f49bfe8dd710a7beba52f717051bfadf` | [#1352](https://github.com/lidge-jun/opencodex/pull/1352) | DRAFT PR OPEN (implementation; not accepted) |

The CL-01 starting SHA is the exact CL-00 tip recorded when CL-01 began. Its
moving base-ref name is not a substitute for that historical SHA.
Expand Down Expand Up @@ -156,4 +156,37 @@ Claims cannot produce `PROBED`/`VERIFIED`.
- CL-00: **ACCEPTED** (merged #1286).
- CL-01: **MERGED** via #1320 at `4bb249b756abd468c675d2d92fffe4da95ad3e2a`.
- CL-02: **MERGED** via #1333 at `025c37916225dd685d9217e5b40190600f06d278`; post-merge hardening #1343 is also **MERGED** at `eee2dab4d1bbacefce56057adad51d734f346702`; final closure is tracked in #1348.
- CL-03: **NOT STARTED**. Authorization is activated by merge of #1348 after green required CI and zero unresolved valid CodeRabbit findings.
- CL-03: **DRAFT PR OPEN** ([#1352](https://github.com/lidge-jun/opencodex/pull/1352)) on
`feat/cl-03-live-route-probes` from `4f746d13799888ea0a8c7a111aa2ad61c2126ea0`;
implementation head `003f7402f49bfe8dd710a7beba52f717051bfadf`. Not accepted.
- CL-04: **NOT STARTED** (blocked until CL-03 independent acceptance and review reconciliation).

## CL-03 implementation log (2026-08-09)

- **Branch:** `feat/cl-03-live-route-probes`
- **Starting/base SHA:** `4f746d13799888ea0a8c7a111aa2ad61c2126ea0` (#1348 merge on `dev`)
- **Implementation head:** `003f7402f49bfe8dd710a7beba52f717051bfadf`
- **PR:** [#1352](https://github.com/lidge-jun/opencodex/pull/1352) (DRAFT → `lidge-jun/opencodex:dev`)
- **Scope:** bounded live-route probes for `live_route_compatibility`; live manifest
authority; `RouteSubjectV1` builder; `LabDestinationV1` / credential lease sandbox;
inert tool/MCP stubs; live runner/executor; `observe/from-live` persistence;
projection applicability for route subjects.
- **Explicitly out of scope:** CL-04 CLI/API, CL-05 UI, CL-06 profile fields, Fabric,
shadow/automatic probing, production request-path probes.

### CL-03 validation (local, 2026-08-09)

- `bun x tsc --noEmit`: passed
- `bun test tests/lab-conformance-harness.test.ts`: 17/17 passed
- `bun test tests/lab-evidence-ledger.test.ts`: 37/41 passed (4 Windows SQLite `EPERM`
flakes in `wipeSqlite`; `rebuild.ts` unchanged vs `upstream/dev` — pre-existing)
- `bun test tests/lab-live-probe.test.ts`: 19/19 passed
- `bun test tests/lab-live-sandbox.test.ts`: 17/17 passed
- `bun run privacy:scan`: passed
- Cross-platform CI on #1352: pending at open time

### CL-03 blockers

- Independent acceptance review not performed
- Draft PR review findings not yet reconciled
- Full local ledger suite not green on Windows host (pre-existing SQLite EPERM)
Original file line number Diff line number Diff line change
@@ -0,0 +1,56 @@
# CL-03 live V1 manifest authority

This document closes the executable semantics for the initial
`live_route_compatibility` scenarios. It is normative for CL-03.

The machine-readable source of truth is
[`024_live_v1_cases.json`](./024_live_v1_cases.json). It contains 10 frozen
live-route scenarios with Lab-authored synthetic fixtures, literal expected
values, row-specific requirements, execution limits from the security contract,
artifact policy, failure rules, and domain-separated fixture digests.

## 1. Manifest expansion

For each entry in `cases`, CL-03 constructs `CompatibilityScenarioV1` using the
same `fixtureRef` contract as protocol V1, with authority
`024_live_v1_cases.json`. Defaults include:

- `evidenceLayer`: `live_route_compatibility`
- `executionMode`: `live`
- `freshness.maxAgeMs`: `604800000` (7 days)
- `failureRuleSet`: `live-v1-default`

Environmental blockers (`authentication_blocked`, `quota_blocked`,
`network_failure`, `provider_transient`, `region_blocked`, `timeout`,
`budget_exhausted`) map to `verdictEffect: none` and never produce compatibility
degradation.

## 2. Live suites

| Suite | Live scenario |
|---|---|
| `responses-core` | `responses-core.live.basic-turn` |
| `chat-core` | `chat-core.live.basic-turn` |
| `anthropic-core` | `anthropic-core.live.basic-turn` |
| `tools-core` | `tools-core.live.function-round-trip`, `tools-core.live.custom-freeform-round-trip` |
| `codex-core` | `codex-core.live.tool-turn`, `codex-core.live.custom-tool-turn` |
| `vision-core` | `vision-core.live.synthetic-ocr` |
| `reasoning-core` | `reasoning-core.live.replay` |
| `mcp-core` | `mcp-core.live.synthetic-tool` |

## 3. Route subject and sandbox

Live evidence uses `RouteSubjectV1` with opaque `endpointFingerprint` and
`providerInstanceFingerprint` derived via `localFingerprint()` from immutable
destination snapshots. Raw URLs, credentials, and DNS results are never
persisted.

The live sandbox rejects proxy environment variables, permits only
`TZ=UTC` and `NO_COLOR=1`, enforces security-contract resource ceilings, and
uses injectable transport in tests.

## 4. CL-03 boundary

CL-03 implements the live runner, sandbox, route subject builder, persistence
seam, and projection applicability for `live_route_compatibility`. It does not
implement CL-04 CLI/API.
Loading
Loading