Skip to content

[E05] Ingest observed proof without promoting claims #403

Description

@TheAmericanMaker

Context and scope

Part of the incremental CodeCartographer engineering evolution. Planned, not shipped. Read the agent handoff, vision/decisions, record contract, and implementation plan. Documentation baseline PR #410 is merged at bbdf6b1a8b3bc348aa9e8f20a409c66df087af13. Follow this issue's prerequisite gates before starting.

Host-executed/framework-tracked; preserve analysis state ABI, both Pi analysis guards, and current synthesis confirmation gates. Ordinary in-place changes accept zero external references. No implicit source execution, provider spend, GitHub write, release/deployment, or private-data publication. E01 owns schema/API/authority decisions; dependent workers consume its merged contract rather than inventing another.

Tracking: #398

Blocked by: #400, #401. Prerequisites must be merged, not merely started.

Objective: retain actual check outcomes and provenance while refusing missing, malformed, or misbound evidence.

Depends on: E02, E03. Files: create core/engineering/proofs.ts, tests/engineering-proofs.test.mjs, proof fixtures; update engineering exports.

Steps:

  1. Write tests for passing/failing host-observed checks, CI-reported checks, manual observations, blocked environments, and agent-only claims.
  2. Write negative cases for absent output/exit metadata, wrong attempt/snapshot/scenario, incomplete capture, stale proof, duplicate ingestion, out-of-root artifact references, and private data in exported summaries; run RED.
  3. Implement normalization and create-only ingestion under the E01 schema. Preserve raw-local versus sanitized-export digest distinctions; ingestion does not execute commands or upload logs.
  4. Exercise meaningful RED/GREEN proof pairs using a small deterministic fixture executed by the test harness; the framework only consumes the resulting observations.
  5. Run GREEN/full gates and record the exact trust boundary.

Acceptance: a prose PASS cannot satisfy an observed proof obligation; failing or blocked checks cannot be promoted; a valid recorded observation retains snapshot/environment/provenance and safe artifact identity.

Out of scope: command runner, arbitrary filesystem importer, automatic secret-proof export, or claiming that a dishonest host cannot fabricate observations.

Required verification and handoff

  • Run the named RED/GREEN tests, npm run build, npm test, and git diff --check; record actual results, not historical counts.
  • Inspect current source and dependency PRs first. All new paths are proposed until their owning issue lands.
  • Get independent review on the exact candidate; stop on missing authority or unresolved security design.
  • Attach commit/PR, changed paths, observed proof, remaining limits, compatibility notes, and the next eligible issue.
  • Keep shared barrel/registration/invariant edits small and coordinate them; do not absorb unrelated work.
  • This issue does not authorize implementation of the later reuse/team/release backlog.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions