RQ1+RQ2 start-line: live per-cell condition assembler + guarded launcher + Holm ratification

Wire the live per-cell condition assembler (cmd_chat/sor/assembler.py): compose
the existing R1/R4/R5/R6 pieces into a condition-encoding CircuitSpec per frozen
§2 cell, so a cell_id maps to a genuinely distinct, ForwarderPlan-gated
(engine != local) isolated circuit rather than the plain 3-hop control:
  - RQ1 bridge-on / on+padding insert a live bridge hop (+ R1 PADDING stream);
  - RQ2 bridge-/directory-federated genuinely span >= 2 houses
    (federation.select_federated_path, split-knowledge).
Plans only: opens no socket, moves no traffic, stands up no engine.

battery.assembler_dry_check validates on FIXTURES (6/6 cells distinct
fingerprints, all isolation-gated, same (cell,seed) reproduces, RQ1 bridge +
padding arms live, RQ2 federation >= 2 houses); write-once, kept out of any
confirmatory data dir. confirmatory_run preflight now runs it; the --operator-go
path no longer refuses cells as "not wired" — triple-lock + green preflight HOLD
on grid completion, then surface the operator's immutable data-run gate. No
confirmatory cell is ever fabricated.

Start-line instrument-validation gate (cmd_chat/sor/gate.py), grid + containment
pin (grid.py), and the guarded launcher (confirmatory_run.py) land alongside.

Holm: hold family_size = 7, report the 4 RQ1/RQ2 tests -> multipliers 7,6,5,4.
This is the pre-registration, not a deviation (prereg §6 [APPROVAL] size-7 family
+ D6 disclosure in the lead paper); docs/stage-05-holm-clarification.md marked
RATIFIED. RQ3-fold and alpha-split declined.

Containment intact; prereg untouched (SHA f22331a72e...); worktree-only. output/
gitignored (runtime artifacts, never source). Full SOR suite 156 passed. No
confirmatory data collected — the live data run remains the human gate.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
leetcrypt
2026-07-19 20:49:12 -07:00
parent 72a6c7b519
commit 6d61c53152
11 changed files with 1228 additions and 0 deletions
+43
View File
@@ -0,0 +1,43 @@
"""Instrument-validation gate re-confirmation — offline items (2-6).
Item 1 (live 3-hop e2e) needs a docker daemon + sor-hop image, so it is exercised
separately by the forwarder e2e test; here we drive the gate with ``allow_live=
False`` and assert every *offline* item is green and the report is write-once.
"""
import json
from cmd_chat.sor import gate
def test_offline_gate_items_all_green(tmp_path):
report = gate.run_gate(tmp_path, allow_live=False)
assert report["offline_items_green"] is True
by_n = {it["n"]: it for it in report["items"]}
for n in (2, 3, 4, 5, 6):
assert by_n[n]["status"] == "green", (n, by_n[n])
# With live disabled, item 1 is 'unavailable' (not a red failure).
assert by_n[1]["status"] == "unavailable"
assert report["all_green"] is False # item 1 not confirmed in this offline run
def test_gate_report_is_write_once(tmp_path):
gate.run_gate(tmp_path, allow_live=False)
path = tmp_path / "gate-report.json"
first = path.read_text()
gate.run_gate(tmp_path, allow_live=False) # second call must not overwrite
assert path.read_text() == first
doc = json.loads(first)
assert doc["schema"] == "sor-gate-report/1"
def test_item5_isolation_refuses_local_accepts_docker(tmp_path):
report = gate.run_gate(tmp_path, allow_live=False)
ev = next(it["evidence"] for it in report["items"] if it["n"] == 5)
assert ev["refused_local"] and ev["refused_unknown"] and ev["accepts_docker"]
def test_item4_entropy_is_exact_log2n(tmp_path):
report = gate.run_gate(tmp_path, allow_live=False)
ev = next(it["evidence"] for it in report["items"] if it["n"] == 4)
assert all(c["exact"] for c in ev["checks"])