Skip to content

Evaluate security cohort staleness as of the receipt time - #274

Merged
saagpatel merged 4 commits into
mainfrom
fix/security-cohort-as-of-receipt
Oct 11, 2026
Merged

saagpatel merged 4 commits into
mainfrom
fix/security-cohort-as-of-receipt

Conversation

@saagpatel

Copy link
Copy Markdown
Owner

Why

portfolio-maintenance kept failing closed at R3, which requires exact equality between the security receipt's cohort and freshly derived default attention. Root cause, confirmed by replaying the production functions: staleness uses a 31-day boundary against the wall clock. One repo crossed it at 1:59:40 AM PT, between the 1:31 AM receipt and the 2:00 AM run, so the two producers disagreed on the clock alone.

What

  • R3 now derives the comparison cohort as of the receipt's produced_at. Exact equality is still required, so changed inputs, reclassifications and genuine gaps still fail closed.
  • Clock-only arrivals (same inputs, different clock) are reported as pending security coverage. They appear in the truth summary, the portfolio report and the weekly digest, and the digest names them next to "all clear". Clock-only departures that the receipt already covered are recorded.
  • A missing, naive, unparseable or future produced_at fails closed.
  • Each R3 failure writes a metadata-only diagnostics artifact (both cohorts, plus each differing repo's activity inputs and classification), and the error points to it. A second, earlier failure in the opposite direction could not be explained because that run preserved nothing; the next one will.
  • R1, R2, R4 and declared-outgoing handling are unchanged.

Verification

  • Locked environment: 3,650 tests pass and ruff is clean. Whole-source mypy reports 340 errors, against 341 on origin/main, so no new errors.
  • Regression tests:
    • the observed clock crossing
    • a non-clock failure, which writes diagnostics
    • a covered clock departure
    • invalid receipt times, including one inside publication's 3-minute skew window
    • declared-outgoing still failing R4
    • the digest's pending line
  • An independent cross-model review found two gaps, both fixed here: the future receipt time and the weekly digest.

Follow-up (operator-scripts)

The pinned auditor ref must advance to this commit, and read_cohort_transition() should surface the new pending and clock-departure fields.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-11T10:54:52.003879Z d232f91 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@saagpatel
saagpatel merged commit ca7d666 into main Oct 11, 2026
4 checks passed
@saagpatel
saagpatel deleted the fix/security-cohort-as-of-receipt branch October 11, 2026 10:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant