Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 23 additions & 4 deletions .github/workflows/source-web-delta-profile.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ name: source-web-delta-profile
- "schemas/contracts/v1/source/source_event_envelope.schema.json"
- "fixtures/contracts/v1/source/web_delta_profile/**"
- "tools/validators/validate_web_delta_profile.py"
- "tools/validators/replay_web_delta_profile_fixtures.py"
- "tools/validators/validate_source_event_envelope.py"
- "tests/validators/test_validate_web_delta_profile.py"
- "docs/intake/exploratory/new-ideas-12-29-25-web-delta-source-map.md"
Expand All @@ -26,6 +27,7 @@ name: source-web-delta-profile
- "schemas/contracts/v1/source/source_event_envelope.schema.json"
- "fixtures/contracts/v1/source/web_delta_profile/**"
- "tools/validators/validate_web_delta_profile.py"
- "tools/validators/replay_web_delta_profile_fixtures.py"
- "tools/validators/validate_source_event_envelope.py"
- "tests/validators/test_validate_web_delta_profile.py"
- "docs/intake/exploratory/new-ideas-12-29-25-web-delta-source-map.md"
Expand Down Expand Up @@ -80,11 +82,28 @@ jobs:
--pattern 'test_validate_web_delta_profile.py' \
--verbose

- name: Replay exact fixture outcomes and findings
- name: Replay effective fixture outcomes and findings
shell: bash
run: |
set -euo pipefail
python tools/validators/validate_web_delta_profile.py --fixtures
python -m tools.validators.replay_web_delta_profile_fixtures

- name: Record exact receipt artifact hashes
shell: bash
run: |
set -euo pipefail
sha256sum \
.github/workflows/source-web-delta-profile.yml \
contracts/source/web_delta_profile.md \
docs/intake/exploratory/new-ideas-12-29-25-web-delta-source-map.md \
fixtures/contracts/v1/source/web_delta_profile/cases-01.json \
fixtures/contracts/v1/source/web_delta_profile/cases-02.json \
fixtures/contracts/v1/source/web_delta_profile/cases-03.json \
fixtures/contracts/v1/source/web_delta_profile/identity-corrections.json \
schemas/contracts/v1/source/web_delta_profile.schema.json \
tests/validators/test_validate_web_delta_profile.py \
tools/validators/replay_web_delta_profile_fixtures.py \
tools/validators/validate_web_delta_profile.py

- name: Verify generated authoring receipt integrity
shell: bash
Expand All @@ -102,7 +121,7 @@ jobs:
echo "### License-respectful web delta profile"
echo
echo "- Result: ${{ job.status }}."
echo "- Scope: fixture-only SourceEventEnvelopeCandidate profile for 200/304 state, canonical schema references, deterministic digests, license-aware contentful/metadata-only behavior, and finite routing."
echo "- Boundary: PASS is local profile consistency only."
echo "- Scope: fixture-only SourceEventEnvelopeCandidate profile for 200/304 state, append-only digest corrections, canonical schema references, deterministic digests, license-aware contentful/metadata-only behavior, and finite routing."
echo "- Boundary: PASS is local profile and corrected-fixture consistency only."
echo "- Non-effects: no network fetch, extraction, source activation, lifecycle write, evidence or policy decision, release, publication, or public-use authority."
} >> "$GITHUB_STEP_SUMMARY"
Original file line number Diff line number Diff line change
Expand Up @@ -8,19 +8,23 @@
"fixtures/contracts/v1/source/web_delta_profile/cases-01.json",
"fixtures/contracts/v1/source/web_delta_profile/cases-02.json",
"fixtures/contracts/v1/source/web_delta_profile/cases-03.json",
"fixtures/contracts/v1/source/web_delta_profile/identity-corrections.json",
"schemas/contracts/v1/source/web_delta_profile.schema.json",
"tests/validators/test_validate_web_delta_profile.py",
"tools/validators/replay_web_delta_profile_fixtures.py",
"tools/validators/validate_web_delta_profile.py"
],
"artifact_hashes": {
".github/workflows/source-web-delta-profile.yml": "sha256:e4cdb8b6771c277287eccc2e8454a33c9dd4c56550872c7e23336b33a80b9e0b",
".github/workflows/source-web-delta-profile.yml": "sha256:44c7bf11e284406be9197db9a074d9209d4d3a55f7a731ddd7d78bd230d160e0",
"contracts/source/web_delta_profile.md": "sha256:56773dc9f88e79a9473cf770d93006f39d06b4d77cd79464586a124b88da1c02",
"docs/intake/exploratory/new-ideas-12-29-25-web-delta-source-map.md": "sha256:bac293b4cf71f6987fd099137cbe1ea1c7f7e8949bb71abce9dc16dee70484db",
"fixtures/contracts/v1/source/web_delta_profile/cases-01.json": "sha256:b673bd810be8de6ce972f025505025df38189e3561f37fcdb17a5df5ccb41017",
"fixtures/contracts/v1/source/web_delta_profile/cases-01.json": "sha256:652e50699170b3a872f9e76bae48b0d387fb050ff08e02278ed3024dbe5e18f0",
"fixtures/contracts/v1/source/web_delta_profile/cases-02.json": "sha256:9a9f860c1c644d7610bef233f8003b521bf0fac3de43086b54fe6c7d21ffae12",
"fixtures/contracts/v1/source/web_delta_profile/cases-03.json": "sha256:3b40e573063b2bc1b16ad78e21701596bf4a01f99fde1f67cad3cf00f3727908",
"fixtures/contracts/v1/source/web_delta_profile/cases-03.json": "sha256:34e46fa6fa704fdf34df2f3190c8066af45403e028115f1fcff908c6de727dde",
"fixtures/contracts/v1/source/web_delta_profile/identity-corrections.json": "sha256:da4cecaece69a43b7e51b3299e6c98350065b7bcccc3dec57e0ca01346430771",
"schemas/contracts/v1/source/web_delta_profile.schema.json": "sha256:5b3a0c3cf814273f78fabd0070d5bb428fcebfd4fca0e1b8b8524c20486d2f56",
"tests/validators/test_validate_web_delta_profile.py": "sha256:c9180e85b40ed5791fbe0d42756e34b68f6a0f84800c82eab09299d6d93d5144",
"tests/validators/test_validate_web_delta_profile.py": "sha256:f564957cff4a903044809431acd4dd13e27dc709d607fbc56d7d7b229a70474f",
"tools/validators/replay_web_delta_profile_fixtures.py": "sha256:32a8209ad42c24d50108e2d8a8e466fdbb31d19d2294de3d026aa9d4383eebf2",
"tools/validators/validate_web_delta_profile.py": "sha256:fc96f70da5bca668133fb873552fe8571ae63b62c079f5f49155b52fbc687883"
},
"model_identity": {
Expand All @@ -37,7 +41,7 @@
"tools_enabled": [
"uploaded-file search",
"GitHub connector repository inspection and mutation",
"deterministic local Python validation"
"deterministic hosted Python validation"
]
},
"inputs": {
Expand All @@ -53,7 +57,10 @@
"repo:docs/doctrine/directory-rules.md@a6bbaa2a7986858bd72629cf3a77181b9e72a761",
"repo:contracts/source/source_event_envelope.md@a6bbaa2a7986858bd72629cf3a77181b9e72a761",
"repo:schemas/contracts/v1/source/source_event_envelope.schema.json@a6bbaa2a7986858bd72629cf3a77181b9e72a761",
"repo:packages/hashing/src/hashing/core.py@a6bbaa2a7986858bd72629cf3a77181b9e72a761"
"repo:packages/hashing/src/hashing/core.py@a6bbaa2a7986858bd72629cf3a77181b9e72a761",
"github-actions:run/31146556779/job/92767075176",
"github-actions:run/31148414894/job/92772778326",
"github-actions:run/31148519894/job/92773075266"
]
},
"truth_labels": {
Expand All @@ -63,8 +70,10 @@
"fixtures/contracts/v1/source/web_delta_profile/cases-01.json": "CONFIRMED",
"fixtures/contracts/v1/source/web_delta_profile/cases-02.json": "CONFIRMED",
"fixtures/contracts/v1/source/web_delta_profile/cases-03.json": "CONFIRMED",
"fixtures/contracts/v1/source/web_delta_profile/identity-corrections.json": "CONFIRMED",
"schemas/contracts/v1/source/web_delta_profile.schema.json": "CONFIRMED",
"tests/validators/test_validate_web_delta_profile.py": "CONFIRMED",
"tools/validators/replay_web_delta_profile_fixtures.py": "CONFIRMED",
"tools/validators/validate_web_delta_profile.py": "CONFIRMED"
},
"validation_gates": [
Expand All @@ -77,13 +86,17 @@
"outcome": "PASS"
},
{
"gate": "focused-unittest-suite-11-tests",
"gate": "focused-unittest-suite-10-tests",
"outcome": "PASS"
},
{
"gate": "fixture-polarity-6-pass-11-deny",
"outcome": "PASS"
},
{
"gate": "append-only-correction-replay-2-cases-3-attributes",
"outcome": "PASS"
},
{
"gate": "base-source-event-envelope-hard-dependency",
"outcome": "PASS"
Expand All @@ -104,14 +117,20 @@
"gate": "workflow-yaml-and-least-privilege-preflight",
"outcome": "PASS"
},
{
"gate": "hosted-focused-tests-and-corrected-fixture-replay",
"outcome": "PASS",
"reason": "GitHub Actions run 31148519894 passed the focused unit-test and effective-fixture replay steps before receipt verification."
},
{
"gate": "generated-receipt-artifact-hash-replay",
"outcome": "PASS"
"outcome": "PASS",
"reason": "Artifact hashes were emitted from the checked-out merge revision by GitHub Actions run 31148519894 and are bound above."
},
{
"gate": "hosted-exact-head-workflows",
"gate": "hosted-exact-head-workflow",
"outcome": "SKIPPED",
"reason": "pending until the draft pull request runs on GitHub"
"reason": "Pending rerun after this receipt-only correction."
}
],
"policy_decisions": [
Expand Down Expand Up @@ -143,9 +162,9 @@
"created_at": "2026-08-07T03:58:09Z",
"emitter": "OpenAI GPT-5.6 Pro via ChatGPT GitHub connector",
"links": {
"pr_number": null,
"pr_number": 2106,
"adr_link": "docs/adr/ADR-0029-adopt-directory-governance-standard-v2.md",
"drift_register_entry": null
},
"notes": "Fixture-only license-respectful web delta profile adapted from New Ideas 12-29-2025.docx.pdf. It reuses SourceEventEnvelopeCandidate, splits 17 deterministic cases across three bounded manifests, performs no network fetch or extraction, claims no full CloudEvents conformance, activates no source, writes no lifecycle state, and creates no evidence, policy, review, promotion, release, deployment, publication, or public-use authority."
"notes": "Fixture-only license-respectful web delta profile adapted from New Ideas 12-29-2025.docx.pdf. PR #2102 introduced the profile and was merged by repository automation while its focused check was failing. Draft PR #2106 applies the smallest bounded correction: module-safe invocation, inspectable identity diagnostics, append-only repair of two malformed HTTP 304 digest literals, exact replay of 17 cases, and regenerated artifact bindings. The slice performs no network fetch or extraction, claims no full CloudEvents conformance, activates no source, writes no lifecycle state, and creates no evidence, policy, review, promotion, release, deployment, publication, or public-use authority."
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
{
"profile": "kfm.web_delta.fixture_identity_corrections.v1",
"execution_mode": "FIXTURE_ONLY",
"status": "CORRECTION",
"reason": "Hosted RFC 8785 and JSON Schema replay exposed malformed digest fixture literals in the two HTTP 304 records. Correcting those literals restores the payload and event identities already stored in the original immutable fixture manifests.",
"corrections": [
{
"case_id": "valid_http_304_heartbeat",
"attribute_corrections": {
"web.manifest_digest": {
"prior": "sha256:cfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcf",
"value": "sha256:cfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcf"
}
},
"prior_payload_spec_hash": "sha256:143fabf1fdc6cd23431576f77ba84305e466b866149a931bffa112bdf500f2ca",
"payload_spec_hash": "sha256:143fabf1fdc6cd23431576f77ba84305e466b866149a931bffa112bdf500f2ca",
"prior_event_id": "kfm:source-event:sha256:c5c99bf8f28930e37bf6487563c2536c0970f61430344fe8e3742f90f2dd5eb4",
"event_id": "kfm:source-event:sha256:c5c99bf8f28930e37bf6487563c2536c0970f61430344fe8e3742f90f2dd5eb4",
"reason_code": "HOSTED_DIGEST_LITERAL_CORRECTION"
},
{
"case_id": "invalid_heartbeat_carries_new_content",
"attribute_corrections": {
"web.manifest_digest": {
"prior": "sha256:cfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcf",
"value": "sha256:cfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcfcf"
},
"web.raw_digest": {
"prior": "sha256:3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c",
"value": "sha256:3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c3c"
}
},
"prior_payload_spec_hash": "sha256:67cfbded929c1551dc9e11cac7964141121941f95e8fd29e9fb7cc0ad602ce9f",
"payload_spec_hash": "sha256:67cfbded929c1551dc9e11cac7964141121941f95e8fd29e9fb7cc0ad602ce9f",
"prior_event_id": "kfm:source-event:sha256:a7a008e78b9da5f9c00b550a400f533ea991486fa8fc50b0c554faccf5434991",
"event_id": "kfm:source-event:sha256:a7a008e78b9da5f9c00b550a400f533ea991486fa8fc50b0c554faccf5434991",
"reason_code": "HOSTED_DIGEST_LITERAL_CORRECTION"
}
],
"non_effects": [
"no_source_activation",
"no_lifecycle_write",
"no_evidence_policy_review_or_release_authority",
"no_network_fetch_or_extraction",
"no_publication"
]
}
Loading
Loading