Block isolation breaches and bind frozen replay to scheduled steps
Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e76f-be98-7ae3-965d-e0b31290a4c4
This commit is contained in:
parent
a8bb787d12
commit
9cdade2116
10 changed files with 229 additions and 14 deletions
|
|
@ -244,3 +244,30 @@ Validation for this follow-up: initial reproduction had 20 failures and two
|
|||
passing controls; full suite **327 passed**. The final dynamic-dependency and
|
||||
strict-postcondition additions passed **32 boundary checks**, including four
|
||||
new cases. These counts overlap; they are not separate independent samples.
|
||||
|
||||
## Isolation and repeated-action replay follow-up (2026-09-28)
|
||||
|
||||
Recorded actor isolation violations now stop the runner before further actions
|
||||
or judgments. Unreached scheduled assertions become INCONCLUSIVE; prior observed
|
||||
product failures remain FAIL. The framework finding remains separate S3 evidence,
|
||||
so it does not add or rewrite product claims. Isolation is examined at entry and
|
||||
after each action. Classification requires all these checks to be present, S3,
|
||||
and free of violations; crystallization inherits that gate. Older packs with
|
||||
only an entry check need rerunning before automatic acceptance. Canary checks
|
||||
remain a diagnostic at those boundaries, not proof against arbitrary memory
|
||||
access or transient leaks inside a driver.
|
||||
|
||||
Runner dispatch now passes step identity to drivers that expose `realize_step`.
|
||||
Composite drivers forward it while ordinary action-only drivers keep their
|
||||
existing interface. Frozen replay selects by step and verifies the action name;
|
||||
repeated names no longer overwrite different targets. Unknown/mismatched steps,
|
||||
duplicate frozen step ids and ambiguous action-only calls cannot send a request.
|
||||
Unambiguous action-only calls remain supported. Replay has no advancing cursor,
|
||||
so the same driver can run the schedule repeatedly.
|
||||
|
||||
Regression coverage includes entry/mid-run/final-action leaks, otherwise passing
|
||||
packs with invalid isolation evidence, distinct targets for repeated actions
|
||||
through direct and composite dispatch, driver reuse and invalid frozen lookup.
|
||||
Decision: `e8fabf6e-3e5e-424e-9a60-152bf3dec641`.
|
||||
|
||||
Validation: the complete suite passed **343 tests** (153.67 seconds).
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue