Reject lossy observations and validate schedules before execution

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e76f-be98-7ae3-965d-e0b31290a4c4
This commit is contained in:
tegwick 2026-09-28 14:50:27 +02:00
parent eaf5d348e4
commit 10077edb8c
8 changed files with 184 additions and 21 deletions

View file

@ -31,8 +31,13 @@ publication of the same run yields one winner and FileExistsError for others.
Directory fsync uses the local POSIX filesystem API. Storage failures propagate;
a caller must not report retained evidence if a write failed.
Serialization rejects unsupported values, non-string mapping keys and non-finite
numbers. Observations detach nested data when recorded, so later domain mutations
Observations must use JSON-native dictionaries with string keys, lists, strings,
integers, finite floats, booleans and null. Tuples and custom value/container types
are rejected rather than coerced. Runner checks and detaches the snapshot before
postconditions or oracles evaluate it; invalid evidence stops further actions,
records an evidence failure and makes pending judgments INCONCLUSIVE. Already
observed failures remain FAIL. Serialization also rejects unsupported values,
non-string mapping keys, cycles and non-finite numbers. Observations detach nested data when recorded, so later domain mutations
do not rewrite earlier snapshots. Receipts include the final run verdict and
asset id, parent, maturity, variant and adaptation history. Independent claim
revisions and scenario revisions bind evidence to the original run inputs.
@ -62,7 +67,9 @@ PY
```
`substitute(..., actor_id='other')` changes the scheduled actor; that actor must
exist in the execution world's cast. `arguments={...}` changes only existing
exist in the execution world's cast. Runner validates all scheduled actor
references, cast key/id agreement and nonempty unique step ids before any action;
invalid input raises ValueError with no execution or finalized receipt. `arguments={...}` changes only existing
argument keys and covers resource, tenant or privilege substitution without new
framework concepts. Mutable argument data is copied. Unknown/duplicate step ids,
unknown keys, empty actor ids and invalid variant ids are rejected. Callers choose
@ -83,3 +90,5 @@ scenario intent and can still qualify as mechanical adaptation.
This API deliberately does not generate new assertions, skip/reorder steps,
schedule races or infer required evidence from a successful implementation run.
Evidence/preflight decision: `aa6c3e31-614c-4030-990c-945acef08515`.