T09: crystallization
A stable agentic realization becomes deterministic code. All four exit
criteria met; 163 tests pass.
- crystallization.py: trajectory capture, stability assessment requiring the
same path across several runs, CrystallizedDriver, pytest codegen
- crystallized/test_grant_access.py: generated, runs with no model, carries
its lineage in the docstring
- descendant preserves the ancestor's oracle set, agrees with it across five
lab versions, and still catches a seeded defect
- reversibility shown both ways via new M24 (grant endpoint renamed): the
frozen descendant fails loudly rather than searching, and the agentic
ancestor recovers from the same mutation
F-0007 (open): the 54% cost reduction must not be quoted in support of the
thesis. The T07 runtime is token-free, so the measured saving is one page
fetch, one parse and a two-candidate scoring pass. The saving the concept
actually claims - tokens, latency, retry variance - is unmeasured. Together
with F-0005 this makes a bounded live-model experiment the highest-value next
investment.
Assertions in the generated test are imported rather than restated, so it is
not fully standalone. Deliberate: paraphrased claims would be a second
unverified statement of intent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:21:48 +02:00
|
|
|
"""Crystallized regression test — generated, do not edit by hand.
|
|
|
|
|
|
|
|
|
|
Lineage
|
|
|
|
|
-------
|
|
|
|
|
ancestor asset : va-grant-via-browser
|
|
|
|
|
ancestor maturity: T1
|
|
|
|
|
descendant : va-grant-crystallized (T5 Deterministic)
|
|
|
|
|
frozen from : 4 identical realizations
|
|
|
|
|
surface version: lab-0.2.0-baseline
|
|
|
|
|
generated : 2026-08-22
|
|
|
|
|
|
|
|
|
|
Why this file exists
|
|
|
|
|
--------------------
|
|
|
|
|
An agent discovered this path 4 times running and it did not change. The
|
|
|
|
|
search is now waste, so it has been frozen. **No model is involved in running
|
|
|
|
|
this test.**
|
|
|
|
|
|
|
|
|
|
The realization below is plain HTTP with no framework dependency. The assertions
|
|
|
|
|
are imported from the originating use case rather than restated — a generated
|
|
|
|
|
test that paraphrases its assertions creates a second, unverified statement of
|
|
|
|
|
intent, and drift between the two would be silent. See F-0007 for what that
|
|
|
|
|
costs.
|
|
|
|
|
|
|
|
|
|
If this test starts failing, the correct first response is **not** to update the
|
|
|
|
|
selectors. Re-run the agentic ancestor: if it recovers, the surface moved and
|
|
|
|
|
this file should be regenerated; if it does not, the behaviour changed and that
|
|
|
|
|
is a finding.
|
|
|
|
|
"""
|
|
|
|
|
|
|
|
|
|
from __future__ import annotations
|
|
|
|
|
|
|
|
|
|
import urllib.error
|
|
|
|
|
import urllib.parse
|
|
|
|
|
import urllib.request
|
|
|
|
|
|
|
|
|
|
from scenarios.alice_bob_carol import _bob_can_read, _bob_cannot_write, _carol_cannot_read
|
|
|
|
|
|
|
|
|
|
TARGET = '/resources/R/grant'
|
|
|
|
|
FIELDS = {'permission': 'READ', 'subject_id': 'bob'}
|
|
|
|
|
|
|
|
|
|
|
2026-09-28 14:12:31 +02:00
|
|
|
class OriginViolation(ValueError):
|
|
|
|
|
"""An authenticated request attempted to leave its configured origin."""
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _origin(url):
|
|
|
|
|
try:
|
|
|
|
|
parsed = urllib.parse.urlsplit(url)
|
|
|
|
|
if (parsed.scheme not in ('http', 'https') or not parsed.hostname
|
|
|
|
|
or parsed.username is not None or parsed.password is not None):
|
|
|
|
|
raise ValueError
|
|
|
|
|
return (parsed.scheme, parsed.hostname,
|
|
|
|
|
parsed.port if parsed.port is not None else (443 if parsed.scheme == 'https' else 80))
|
|
|
|
|
except ValueError:
|
|
|
|
|
raise OriginViolation('invalid authenticated HTTP origin') from None
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class _OriginRedirectHandler(urllib.request.HTTPRedirectHandler):
|
|
|
|
|
def __init__(self, origin):
|
|
|
|
|
self.origin = origin
|
|
|
|
|
|
|
|
|
|
def redirect_request(self, req, fp, code, msg, headers, newurl):
|
|
|
|
|
if _origin(newurl) != self.origin:
|
|
|
|
|
raise OriginViolation('authenticated redirect leaves configured origin')
|
|
|
|
|
return super().redirect_request(req, fp, code, msg, headers, newurl)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def authenticated_target(base_url, path):
|
|
|
|
|
origin = _origin(base_url)
|
|
|
|
|
target = urllib.parse.urljoin(base_url, path)
|
|
|
|
|
if _origin(target) != origin:
|
|
|
|
|
raise OriginViolation('authenticated request leaves configured origin')
|
|
|
|
|
# The caller supplies the authorization header only after target validation.
|
|
|
|
|
return target, urllib.request.build_opener(_OriginRedirectHandler(origin))
|
|
|
|
|
|
|
|
|
|
|
T09: crystallization
A stable agentic realization becomes deterministic code. All four exit
criteria met; 163 tests pass.
- crystallization.py: trajectory capture, stability assessment requiring the
same path across several runs, CrystallizedDriver, pytest codegen
- crystallized/test_grant_access.py: generated, runs with no model, carries
its lineage in the docstring
- descendant preserves the ancestor's oracle set, agrees with it across five
lab versions, and still catches a seeded defect
- reversibility shown both ways via new M24 (grant endpoint renamed): the
frozen descendant fails loudly rather than searching, and the agentic
ancestor recovers from the same mutation
F-0007 (open): the 54% cost reduction must not be quoted in support of the
thesis. The T07 runtime is token-free, so the measured saving is one page
fetch, one parse and a two-candidate scoring pass. The saving the concept
actually claims - tokens, latency, retry variance - is unmeasured. Together
with F-0005 this makes a bounded live-model experiment the highest-value next
investment.
Assertions in the generated test are imported rather than restated, so it is
not fully standalone. Deliberate: paraphrased claims would be a second
unverified statement of intent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:21:48 +02:00
|
|
|
def _post(base_url: str, token: str, path: str, fields: dict) -> int:
|
2026-09-28 14:12:31 +02:00
|
|
|
target, opener = authenticated_target(base_url, path)
|
T09: crystallization
A stable agentic realization becomes deterministic code. All four exit
criteria met; 163 tests pass.
- crystallization.py: trajectory capture, stability assessment requiring the
same path across several runs, CrystallizedDriver, pytest codegen
- crystallized/test_grant_access.py: generated, runs with no model, carries
its lineage in the docstring
- descendant preserves the ancestor's oracle set, agrees with it across five
lab versions, and still catches a seeded defect
- reversibility shown both ways via new M24 (grant endpoint renamed): the
frozen descendant fails loudly rather than searching, and the agentic
ancestor recovers from the same mutation
F-0007 (open): the 54% cost reduction must not be quoted in support of the
thesis. The T07 runtime is token-free, so the measured saving is one page
fetch, one parse and a two-candidate scoring pass. The saving the concept
actually claims - tokens, latency, retry variance - is unmeasured. Together
with F-0005 this makes a bounded live-model experiment the highest-value next
investment.
Assertions in the generated test are imported rather than restated, so it is
not fully standalone. Deliberate: paraphrased claims would be a second
unverified statement of intent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:21:48 +02:00
|
|
|
request = urllib.request.Request(
|
2026-09-28 14:12:31 +02:00
|
|
|
target,
|
T09: crystallization
A stable agentic realization becomes deterministic code. All four exit
criteria met; 163 tests pass.
- crystallization.py: trajectory capture, stability assessment requiring the
same path across several runs, CrystallizedDriver, pytest codegen
- crystallized/test_grant_access.py: generated, runs with no model, carries
its lineage in the docstring
- descendant preserves the ancestor's oracle set, agrees with it across five
lab versions, and still catches a seeded defect
- reversibility shown both ways via new M24 (grant endpoint renamed): the
frozen descendant fails loudly rather than searching, and the agentic
ancestor recovers from the same mutation
F-0007 (open): the 54% cost reduction must not be quoted in support of the
thesis. The T07 runtime is token-free, so the measured saving is one page
fetch, one parse and a two-candidate scoring pass. The saving the concept
actually claims - tokens, latency, retry variance - is unmeasured. Together
with F-0005 this makes a bounded live-model experiment the highest-value next
investment.
Assertions in the generated test are imported rather than restated, so it is
not fully standalone. Deliberate: paraphrased claims would be a second
unverified statement of intent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:21:48 +02:00
|
|
|
data=urllib.parse.urlencode(fields).encode(),
|
|
|
|
|
method="POST",
|
|
|
|
|
headers={
|
|
|
|
|
"Authorization": f"Bearer {token}",
|
|
|
|
|
"Content-Type": "application/x-www-form-urlencoded",
|
|
|
|
|
},
|
|
|
|
|
)
|
|
|
|
|
try:
|
2026-09-28 14:12:31 +02:00
|
|
|
with opener.open(request, timeout=10) as response:
|
T09: crystallization
A stable agentic realization becomes deterministic code. All four exit
criteria met; 163 tests pass.
- crystallization.py: trajectory capture, stability assessment requiring the
same path across several runs, CrystallizedDriver, pytest codegen
- crystallized/test_grant_access.py: generated, runs with no model, carries
its lineage in the docstring
- descendant preserves the ancestor's oracle set, agrees with it across five
lab versions, and still catches a seeded defect
- reversibility shown both ways via new M24 (grant endpoint renamed): the
frozen descendant fails loudly rather than searching, and the agentic
ancestor recovers from the same mutation
F-0007 (open): the 54% cost reduction must not be quoted in support of the
thesis. The T07 runtime is token-free, so the measured saving is one page
fetch, one parse and a two-candidate scoring pass. The saving the concept
actually claims - tokens, latency, retry variance - is unmeasured. Together
with F-0005 this makes a bounded live-model experiment the highest-value next
investment.
Assertions in the generated test are imported rather than restated, so it is
not fully standalone. Deliberate: paraphrased claims would be a second
unverified statement of intent.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 1629012@bnt-lap001
Assistant-Session: 78d4fb13-8a1e-474b-87a3-9b9261c49a39
2026-08-23 00:21:48 +02:00
|
|
|
return response.status
|
|
|
|
|
except urllib.error.HTTPError as error:
|
|
|
|
|
return error.code
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def realize(base_url: str, token: str) -> int:
|
|
|
|
|
"""Perform grant_access deterministically, exactly as the agent learned to."""
|
|
|
|
|
return _post(base_url, token, TARGET, FIELDS)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_grant_access(crystallized_world):
|
|
|
|
|
"""grant_access still works, and the claims it protects still hold."""
|
|
|
|
|
base_url, token, observe = crystallized_world
|
|
|
|
|
|
|
|
|
|
assert realize(base_url, token) < 400, "the frozen realization no longer works"
|
|
|
|
|
|
|
|
|
|
snapshot = observe()
|
|
|
|
|
assert _bob_can_read(snapshot), 'Bob can read R after the grant'
|
|
|
|
|
assert _carol_cannot_read(snapshot), 'Carol can never read R'
|
|
|
|
|
assert _bob_cannot_write(snapshot), 'A READ grant does not let Bob write R'
|