Skip to content

fix: bind staged portfolio truth to manifest receipt identity - #276

Merged
saagpatel merged 2 commits into
mainfrom
fix/truth-manifest-identity-20261011
Oct 11, 2026
Merged

saagpatel merged 2 commits into
mainfrom
fix/truth-manifest-identity-20261011

Conversation

@saagpatel

@saagpatel saagpatel commented Oct 11, 2026 •

Copy link
Copy Markdown
Owner

What

New portfolio generation publication checks the security receipt ID and content SHA in the staged truth artifact against the admitted manifest binding before making the release visible.

Why

A valid receipt pair could replace A with B before publisher admission. The publisher then accepted and selected a bundle whose truth named A while its manifest named B, even though every artifact hash matched. The new check refuses that disagreement, missing or malformed identities, and incompatible truth contracts.

Review Of What Was Built

The gate validates the bytes in the staged generation. Correct publication is exercised with the actual upstream truth builder and strict canonical validator. Companion digest files are explicitly synthetic opaque artifacts; decision-digest semantics remain in their own tests. The CLI tests cover unchanged A, B before admission, B after admission, and a mismatched receipt/terminal pair. Existing history remains readable through new publication, rollback, and roll-forward.

Cleanup Review

The manifest and pointer schemas, historical verifier, public function signatures, and later live receipt guard remain unchanged. This is a publication identity repair; full truth validation stays with the upstream producer.

Verification Summary

  • Focused publisher and valid canonical truth CLI regressions: 17 passed.
  • Locked fixture suite excluding the optional semantic-index module: 3,665 passed, 2 skipped, 50 deselected; 56 subtests passed.
  • Ruff across source and tests, diff whitespace, and portable consumer fixture check: passed.
  • Whole-source mypy: 294 diagnostics in both original and repaired source, with equal diagnostic multisets after normalizing shifted line numbers; no new diagnostics.
  • Independent review and replay verified artifact hashes, input identities, pointer/history preservation, late guard refusal, retained unselected candidates, and legacy history compatibility.
  • The original publisher also reproduced the mismatch using these strictly valid truth fixtures, so the regression does not rely on the earlier demo timestamp limitation.

Shipped Summary

A new generation cannot be selected with truth and manifest disagreeing on the admitted security receipt identity. Correct identity remains publishable. These are source and offline fixture results; scheduled runtime activation is not part of this change.

Next Phase

Controlled activation under the operator release contract is a separate deployment task. It should preserve existing receipt and generation history and verify the activated producer revision before any scheduled-run claim.

Remaining Roadmap

No additional implementation is required for this bounded repair.

Comment thread tests/test_portfolio_generation_identity.py Fixed
Comment thread tests/test_portfolio_generation.py Fixed
@saagpatel
saagpatel merged commit fbda19b into main Oct 11, 2026
4 checks passed
@saagpatel
saagpatel deleted the fix/truth-manifest-identity-20261011 branch October 11, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants