Skip to content

fix: enforce integrity contracts and ship Yeoul 0.3.0 - #12

Merged
bhyi4 merged 3 commits into
mainfrom
fix/integrity-contracts-0.3.0
Sep 9, 2026
Merged

bhyi4 merged 3 commits into
mainfrom
fix/integrity-contracts-0.3.0

Conversation

@bhyi4

@bhyi4 bhyi4 commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Harden the supervised Yeoul workflow without making preregistration mandatory for discussion arcs.

  • Recompute every MIRROR-SPEC hash/link, pin the first registration, and reject unsealed/tampered/replaced/deleted bindings. Legacy links require explicit verified migration.
  • Freeze TODO criteria before work; share CLI/MCP eligibility; prevent changed commands/item deletion from passing verification. Bound rounds/timeouts and stop on unknown usage.
  • Keep drafts/refusals pending, reject missing defense fields and archive collisions, separate archive recording state, and show active arcs before historical verdicts.
  • Add an explicit supervisor-driven result adapter for Mirror's bound result contract; it does not publish or infer a scientific verdict.
  • Bundle scripts/templates/license in wheels and sdists, test the installed package outside the checkout, and refresh docs, command references and migration guidance.

Verification

  • Existing gate suite: 72/72.
  • New adversarial contract suite: 26 tests, including relocated defense fields and preserved prior-run logs.
  • MCP subprocess contract: 8/8.
  • MCP serverInfo wire contract: 8/8 on the host (sandbox pipe did not answer).
  • CLI/MCP parity and real Mirror interoperability: 5 tests, including pass/fail/inconclusive result cases and Windows Git Bash discovery.
  • Lifecycle demo and pre-publish checks pass; relative documentation links and six public URLs checked.
  • sdist -> wheel built and installed harness exercised away from source. CI now checks the packaged paths too.

Compatibility and honest scope

v0.3.0 intentionally requires a supervisor baseline for protected standalone verification; --current-only is an explicit weaker diagnostic. Existing ledgers/archives are not rewritten. Local hashes do not establish identity, external time, content truth or independent reproduction. Agents with permission to rewrite every artifact remain outside this workflow-level boundary. Token limits are between-round controls, not hard provider spending caps.

@bhyi4
bhyi4 merged commit 7e13ceb into main Sep 9, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant