Skip to content

feat(verification): executable merge gate — PR evidence manifests, validator with negative controls, merge sweep - #26

Merged
obvious-autobuild[bot] merged 1 commit into
masterfrom
qa/verification-gate
Sep 17, 2026
Merged

obvious-autobuild[bot] merged 1 commit into
masterfrom
qa/verification-gate

Conversation

@obvious-autobuild

Copy link
Copy Markdown
Contributor

Acceptance criteria

  1. Every contract rule executable and pinned. Each rule from .obvious/obvious.md (review → repair → merge workflow) has a stable refusal code, and each is pinned by a test: 2 positive controls + 9 negative-control fixtures + inline mutations + extraction tests (cd verification && bun test ./test — 25 tests, 52 assertions). Negative controls pin the exact refusal-code set, so the gate must fire on its own term and stay silent otherwise.
  2. Latest-wins manifest extraction. PRs record a <!-- verification-manifest:v1 --> block (body or comment). The latest block across body + comments wins; a later malformed block fails loudly instead of falling back.
  3. Merge sweep refuses before it merges. sweep checks, in order: open PR → not draft → base master → not an arena candidate → live checks green on the exact head SHA (queried live, not from the manifest) → manifest parses → validator merge → then gh pr merge --squash + evidence receipt. --dry-run prints the receipt without merging; --smoke re-runs the full local verification table on the merge commit from a temp worktree.
  4. Standalone suites run in CI. New verification.yml workflow runs the security suite, evaluation harness, broken-adapter negative control, and the validator tests on every PR/push to master (these are not pnpm workspace members, so the turbo pipeline never covered them).
  5. Docs updated. verification/README.md (manifest format, refusal-code table, CLI usage, factual limits — single-page comment/check reads, gh-auth trust) and .obvious/obvious.md (layout entry + "Verification gate" section).

What's included

  • verification/src/ — types (manifest schema, reason codes), pure validator (I/O-free; live state is injected via VerificationContext), manifest extraction, gh wrappers, CLI (check / validate-pr / sweep)
  • verification/fixtures/ — 2 positive + 9 negative controls, each internally consistent except one defect
  • verification/test/validate.test.ts — 25 tests pinning every rule
  • .github/workflows/verification.yml — standalone-suite CI
  • README + .obvious/obvious.md updates

Known limits (stated, not hidden): the gate validates what is recorded and observed — it can detect contradiction between the manifest, the live diff, and live checks, but cannot verify intent. Fabricated-but-self-consistent evidence passes; what holds it accountable is that every field carries a URL + reviewer + date, live state is re-observed at sweep time, and the receipt records everything. validate-pr is advisory when no manifest exists yet (CI mode); strict with --require.

Author-side verification (exact HEAD: f590ddfcba15f7bb7f75788466660fc151abe1e5)

  • corepack pnpm turbo run typecheck test build --force — 15/15 successful, 0 cached
  • bun test ./security — 17 tests, 0 fail
  • cd evaluation && bun src/run.ts — 6/6 fixtures
  • bun src/run.ts --adapter=./src/example/broken-adapter.ts --expect-failure — negative control behaves (exit 0)
  • bun test ./verification/test — 25 tests, 52 assertions, 0 fail
  • CLI smoke: check on positive-backend → merge (exit 0); on nc1-stale-sha → refuse: [stale_head_sha] (exit 1)

Review / merge path

This PR follows the repo contract: independent review against the exact HEAD, then the merge owner records the verification-manifest:v1 block on this PR and runs bun verification/src/cli.ts sweep --pr=<n> --owner=<name> (dry-run first). Arena holds, stale SHAs, and invalid manifests all refuse loudly.

@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

CI green on the exact head f590ddfcba15f7bb7f75788466660fc151abe1e5:

Check Run Result
Typecheck, test, build (ci.yml) 35261065858 ✅ pass
suites (verification.yml: security 17 + evaluation 6/6 + negative control + validator tests 25) 35261065872 ✅ pass

Author-side local verification at the same SHA (uncached): turbo typecheck/test/build 15/15, bun test ./security 17 tests 0 fail, evaluation 6/6 fixtures, broken-adapter negative control exit 0, bun test ./verification/test 25 tests / 52 assertions 0 fail.

Next per contract: independent review against this SHA, then the verification-manifest:v1 block is recorded on this PR and the merge owner runs bun verification/src/cli.ts sweep --pr=26 --owner=<name> --dry-run before the real sweep.

@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

Independent review result — recorded per contract rule 2–3

Verdict: pass-with-notes · Tested SHA f590ddfcba15f7bb7f75788466660fc151abe1e5 (= PR head and head_sha of both CI runs).

Reviewer: independent read-only review thread (obvious task todo_1Grlbg06, thread th_PLlJY7qr) — not the PR author. Review date 2026-09-17.

Reviewer's own uncached results at that SHA (worktree, frozen lockfile): turbo run typecheck test build --force 15/15 (0 cached); bun test ./security 17 tests 0 fail; evaluation 6/6 fixtures; broken-adapter --expect-failure exit 0; bun test ./verification/test 25 pass / 52 assertions; CLI smoke: positive-backend → merge exit 0, nc1-stale-sha → refuse [stale_head_sha] exit 1. CI on the exact SHA: both CI and Verification runs success (head_shas verified via API).

Findings: no false-accept path (every skipped sub-check guarded by a shape check that itself adds invalid_manifest); no false-reject (positive controls assert reasons=[]); all 19 reason codes test-pinned; latest-wins / malformed-latest-fails-loudly / prose-immunity all pinned; sweep preflight order verified live via --dry-run; hardcoded --squash; refuses (not merges) on missing manifest and arena holds; docs additive and accurate. Diff scope clean: 22 files, 2105 lines, all within the PR's claimed scope.

Non-blocking hardening notes (6): (1) requiredSuites CODE_PATH_RE omits verification/ and .github/; (2) verification/ strict tsconfig is not pipeline-typechecked (bun strips types); (3) README overstates check-run page size (GitHub default 30, not ~100); (4) small TOCTOU window between live-check read and merge (no head pinning at merge time), mitigated by the serialized merge owner; (5) inline review-thread comments not scanned; (6) contract rule 1 (acceptance criteria in body) has no executable counterpart — README table is honest about this.

Full reviewer report: obvious task todo_1Grlbg06 / thread th_PLlJY7qr.

@obvious-autobuild

Copy link
Copy Markdown
Contributor Author
{
  "manifestVersion": 1,
  "pr": 26,
  "prUrl": "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/OCPdev25/obv-hackaton/pull/26",
  "testedHeadSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5",
  "classification": "backend-only",
  "classificationJustification": "Executable merge-gate tooling (CLI + pure validator + test fixtures + CI workflow + docs); no user-facing UI surfaces, no docs-only scope — behavior evidence below.",
  "review": {
    "result": "pass-with-notes",
    "reviewer": "independent read-only review thread (obvious task todo_1Grlbg06 / thread th_PLlJY7qr); recorded on this PR with attribution",
    "reviewedHeadSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5",
    "date": "2026-09-17",
    "url": "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/OCPdev25/obv-hackaton/pull/26#issuecomment-5719690104"
  },
  "checks": [
    { "name": "CI (Typecheck, test, build)", "status": "green", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065858" },
    { "name": "Verification (security + evaluation + negative control + validator tests)", "status": "green", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" }
  ],
  "evidence": [
    { "kind": "behavior-run", "name": "CLI smoke: check positive-backend fixture -> merge (exit 0); nc1-stale-sha -> refuse [stale_head_sha] (exit 1), author-side at tested HEAD, independently reproduced by reviewer", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "result": "pass", "url": "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/OCPdev25/obv-hackaton/pull/26#issuecomment-5719690104" },
    { "kind": "test-run", "name": "Validator tests: 25 pass / 52 assertions (2 positive + 9 negative controls + inline mutations + extraction), author-side and reviewer-side at tested HEAD", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "result": "pass", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" },
    { "kind": "suite-run", "name": "Security suite: 17 fail-closed access cases, 0 fail (author-side and reviewer-side at tested HEAD)", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "result": "pass", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" },
    { "kind": "suite-run", "name": "Evaluation harness: 6/6 fixtures; broken-adapter negative control fails as expected (exit 0) — author-side and reviewer-side at tested HEAD", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "result": "pass", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" }
  ],
  "suites": {
    "security": { "ran": true, "result": "pass", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" },
    "evaluation": { "ran": true, "result": "pass", "headSha": "f590ddfcba15f7bb7f75788466660fc151abe1e5", "negativeControl": "fail-as-expected", "url": "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/OCPdev25/obv-hackaton/actions/runs/35261065872" }
  },
  "notes": "Author-side local verification table also run uncached at tested HEAD: turbo typecheck/test/build 15/15. Non-blocking hardening notes (6) tracked for a follow-up PR."
}

@obvious-autobuild
obvious-autobuild Bot merged commit 90b76d9 into master Sep 17, 2026
2 checks passed
@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

Evidence receipt (verification gate)

PR:               https://github.com/OCPdev25/obv-hackaton/pull/26
Tested head SHA:  f590ddfcba15f7bb7f75788466660fc151abe1e5
Review result:    pass-with-notes — independent read-only review thread (obvious task todo_1Grlbg06 / thread th_PLlJY7qr); recorded on this PR with attribution, 2026-09-17 (https://github.com/OCPdev25/obv-hackaton/pull/26#issuecomment-5719690104)
Checks:           CI (Typecheck, test, build), Verification (security + evaluation + negative control + validator tests) — green on f590ddfcba15f7bb7f75788466660fc151abe1e5
Merge commit:     (lookup pending)
Post-merge smoke: ran via --smoke (see sweep log)
Unlocked tasks:   (merge owner fills)

@obvious-autobuild

Copy link
Copy Markdown
Contributor Author

Evidence receipt (verification gate) — COMPLETED

PR:               https://github.com/OCPdev25/obv-hackaton/pull/26
Tested head SHA:  f590ddfcba15f7bb7f75788466660fc151abe1e5
Review result:    pass-with-notes — independent read-only review thread (obvious task todo_1Grlbg06 / thread th_PLlJY7qr), 2026-09-17, recorded with attribution in https://github.com/OCPdev25/obv-hackaton/pull/26#issuecomment-5719690104
Checks:           CI (Typecheck, test, build) + Verification (security + evaluation + negative control + validator tests) — all green on f590ddfcba15f7bb7f75788466660fc151abe1e5 (runs 35261065858, 35261065872, head_shas API-verified)
Merge commit:     90b76d9e0bcc7a84536e8c66dc8f169710a8a6ce (squash on master; PR state MERGED, mergedAt 2026-09-17T19:00:44Z)
Post-merge smoke: full local verification table re-run on 90b76d9 from a temp worktree — install clean; turbo typecheck/test/build 15/15 (cache-backed, identical input hashes); bun security 17 tests 0 fail; evaluation 6/6 fixtures; broken-adapter negative control exit 0; validator tests 25 pass / 52 assertions. Worktree removed.
Unlocked tasks:   hardening follow-up (six non-blocking review notes + sweep receipt-completeness defect) — tracked as obvious task; verification gate is now the executable merge path for future PRs.

Note: the sweep's auto-posted receipt above rendered Merge commit: (lookup pending) and did not visibly execute its --smoke steps — this receipt supersedes it with verified values, and the defect is logged in the follow-up task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants