Refs #17783
🌿 The enforcement receipt can no longer claim a commit that never existed.
Evidence: L3 (mutation-verified — the new arm goes red when the validation it constrains is removed; 52/52 targeted spec green at this head) → L3 sufficient (no operator-gated or destructive step in scope). No residuals.
The defect
The Wave-3 cut input required enforcement.{headSha, requiredContext}. But the enforcement deliverable is a one-time observation of a branch ruleset — it has no implementing head. Any SHA in that field carries a fiction, and the manifest bind commit cannot stand in for a ruleset read, which is exactly why @neo-gpt-emmy held the final green emission.
The fix, following an idiom rather than inventing one
enforcement now carries {ref, rulesetDigest, requiredContext, integrationId} — a public coordinate for where the observation lives plus a digest for what it observed. That shape is not new to this file: skillsPackage.referenceClosure is already {ref, state} and learningCensus already carries {ref, commitSha, …}. Validation is fail-closed on all four and reuses the file's existing DIGEST_RE rather than adding a pattern.
ai/scripts/diagnostics/agentOsExtractionInventory.mjs
1953-1957 JSDoc: headSha → ref + rulesetDigest + integrationId
2062-2064 fail-closed: ref non-empty · DIGEST_RE on rulesetDigest · context non-empty · integrationId an integer
2140-2145 emitted prerequisites.enforcement carries all four
AC Evidence
| AC |
proof |
| AC-4 |
PARTIAL — the pre-cut half. The read-back exists and now has a home: ref + rulesetDigest + requiredContext + integrationId are exactly the fields the observation produces. The values themselves (digest sha256:54d48a48…, integration-parity, integrationId 15368, source GET /repos/neomjs/neo/rules/branches/dev) are recorded at #17783 comment 5426844579. The post-cut half — a second read-back proving the context survived the split — is unchanged and still post-severance. |
| AC-1 · AC-2 · AC-3 · AC-5 · AC-6 · AC-7 |
Untouched. All six are post-cut by construction; this PR is deliberately the pre-cut slice only, which is why it carries Refs and not Resolves. |
Test Evidence
The pre-existing fail-closed test could not have caught this. It passes an absent enforcement object, so it stays green even if three of the four fields are never validated. Added a per-field arm — six negative variants plus a positive control:
ref missing · digest not sha256-prefixed · digest wrong length
requiredContext missing · integrationId absent · integrationId not an integer
→ each must raise `enforcement-coordinate-missing`
a fully valid read-back
→ must NOT raise it (positive control: without this, all six could pass for the wrong reason)
Mutation-verified, not asserted. Removing the rulesetDigest and integrationId checks from validation turns the new arm red:
MUTANT (validation reduced to !ref || !requiredContext)
1 failed › each enforcement read-back field is individually load-bearing
FIXED
52 passed (16.9s) env -u NEO_MCP_REMOTE_TOKEN npx playwright test -c test/playwright/playwright.config.unit.mjs --workers=1 <spec>
Deltas
headSha is removed, not retained alongside. Keeping it would preserve a field whose only honest value is null for this deliverable, and a nullable SHA invites a future caller to fill it with the nearest commit — which is the fiction this PR exists to remove.
- No new regex, no new helper.
DIGEST_RE already existed at line 194; adding a parallel pattern would have been the added machinery the standing bar forbids.
Refs #17783, not Resolves. Six of the ticket's seven ACs are post-cut, and AC-4 itself is only half-delivered here. Closing it on this PR would overclaim.
- One durable comment initially cited the ticket number and
check-ticket-archaeology correctly rejected it — rewritten to describe the behaviour instead.
Post-Merge Validation
- @neo-gpt-emmy re-runs the final manifest emission with the four-field
enforcement object; the held green emission should no longer be blocked by enforcement-coordinate-missing.
- The remaining hold reasons are unaffected and stay outstanding: the plane-proof topology findings (red-capable by
#17533) and the two structurally-unrunnable probes.
- AC-4's post-cut read-back runs after severance and is not claimed here.
Authored by Vega (Claude Opus 5, Claude Code). Session 8cfe8ea9-113f-4e32-a3f4-822ee92ff721.
Refs #17783
🌿 The enforcement receipt can no longer claim a commit that never existed.
Evidence: L3 (mutation-verified — the new arm goes red when the validation it constrains is removed; 52/52 targeted spec green at this head) → L3 sufficient (no operator-gated or destructive step in scope). No residuals.
The defect
The Wave-3 cut input required
enforcement.{headSha, requiredContext}. But the enforcement deliverable is a one-time observation of a branch ruleset — it has no implementing head. Any SHA in that field carries a fiction, and the manifest bind commit cannot stand in for a ruleset read, which is exactly why @neo-gpt-emmy held the final green emission.The fix, following an idiom rather than inventing one
enforcementnow carries{ref, rulesetDigest, requiredContext, integrationId}— a public coordinate for where the observation lives plus a digest for what it observed. That shape is not new to this file:skillsPackage.referenceClosureis already{ref, state}andlearningCensusalready carries{ref, commitSha, …}. Validation is fail-closed on all four and reuses the file's existingDIGEST_RErather than adding a pattern.AC Evidence
ref+rulesetDigest+requiredContext+integrationIdare exactly the fields the observation produces. The values themselves (digestsha256:54d48a48…,integration-parity,integrationId 15368, sourceGET /repos/neomjs/neo/rules/branches/dev) are recorded at #17783 comment 5426844579. The post-cut half — a second read-back proving the context survived the split — is unchanged and still post-severance.Refsand notResolves.Test Evidence
The pre-existing fail-closed test could not have caught this. It passes an absent
enforcementobject, so it stays green even if three of the four fields are never validated. Added a per-field arm — six negative variants plus a positive control:Mutation-verified, not asserted. Removing the
rulesetDigestandintegrationIdchecks from validation turns the new arm red:Deltas
headShais removed, not retained alongside. Keeping it would preserve a field whose only honest value isnullfor this deliverable, and a nullable SHA invites a future caller to fill it with the nearest commit — which is the fiction this PR exists to remove.DIGEST_REalready existed at line 194; adding a parallel pattern would have been the added machinery the standing bar forbids.Refs #17783, notResolves. Six of the ticket's seven ACs are post-cut, and AC-4 itself is only half-delivered here. Closing it on this PR would overclaim.check-ticket-archaeologycorrectly rejected it — rewritten to describe the behaviour instead.Post-Merge Validation
enforcementobject; the held green emission should no longer be blocked byenforcement-coordinate-missing.#17533) and the two structurally-unrunnable probes.Authored by Vega (Claude Opus 5, Claude Code). Session 8cfe8ea9-113f-4e32-a3f4-822ee92ff721.