Repository navigation
Conversation
carloshvp
left a comment
There was a problem hiding this comment.
Reviewed 084571b in an isolated Python 3.12 checkout. Two items need correction before approval:
-
[P2] Enforce the complete comparison contract in integrations/alakris-authority-comparison/runner.py:59-73. validate_report validates only fields already present and supplies defaults for seven fields. It never requires authority, decision, dispatch, committed_effect, task_outcome, receipt, or policy_digest, despite comparison-contract.json declaring them required. Reproducer: generate the valid MintID testnet report, delete authority and decision from every case, then call validate_report(report). It returns successfully with no explicit missing-evidence states. This lets an incomplete adapter report pass while dropping the evidence gaps the contract is meant to preserve. Require every contract field (or explicitly populate missing fields with the appropriate state and reason), and add regression coverage for omitted core fields while retaining a valid control.
-
[P2] Fix the new code's existing CI lint gate. The workflow rule set (
ruff check integrations/alakris-authority-comparison --target-version py39 --select E4,E7,E9,F) reproduces 46 errors, including E701/E702, E741, and runner.py:130's unused trace variable. Please make the added files pass the repository's existing rule set; no broader style-rule expansion is requested.
Validation otherwise succeeded: hash-locked released dependencies installed; check_package.py --fetch passed; all 27 tests ran without skips; 12 TRACE Reference shapes validated; MintID publisher bytes passed; the known Proofable LF/CRLF checksum failure remained an explicit integrity FAIL. All 15 retained native-run collector hashes matched. I inspected the retained native artifacts but did not rerun vendor sandbox execution. The separation of author observations, synthetic effects, pointer shape, and native-run qualifications is appropriate; this review makes no Verified-tier or conformance claim.
imran-siddique
left a comment
There was a problem hiding this comment.
@wlad232 the repo-wide ruff gate fails on this package: 46 errors across create_references.py, runner.py and test_runner.py (E701/E702 one-line statements, E731 assigned lambdas, F841 an unused trace at runner.py:130). The rest of CI passes. To reproduce what CI runs:
ruff check integrations/alakris-authority-comparison --target-version py39 --select E4,E7,E9,F
Please push the fix; the package review follows once CI is green.
Proofable update: frozen packet repinned, independent reader PR open@wlad232 — Proofable's corrected Oct 8 package is frozen at This resolves the two blockers your review raised for Proofable:
On the binding-veto case, the machine-readable results and the signed authority receipt distinguish Independent code-based appraisal of this packet, from the ProbityAI reader, is open as a PR: If you repin the shared runner's Proofable adapter to The old Scope is unchanged: author-operated (SELF); independent code-based appraisal of published evidence, |
|
Proofable follow-up for the shared runner at The corrected frozen packet is The related reader now verifies all 11 envelopes and binds their qHashes to the trace and manifest. My current-head rerun results are recorded at probityai/agent-evidence-observer#88 (comment) (reader head Suggested bounded integration:
The initial pin/material-only patch has been exercised locally for checksum PASS, measured material presence, unperformed-signature state, and trace/envelope byte-tamper rejection; I have not run this shared runner's entire suite or changed this PR branch. Receipt verification remains unperformed in this shared adapter until the verifier is actually integrated and run. No change to SELF custody, independent-live-run status, target-side effect limitations, conformance claims or unmeasured revocation latency is warranted. |
|
Published the bounded Proofable follow-up for integration: dinakarjs#1 — now ready for review, with 12 changed files against this PR's unchanged head It repins the corrected Oct 8 packet, retains the historical Oct 6 checksum FAIL separately, vendors the reviewed offline verifier with license/attribution, and checks qHash/signature/DID/chain plus exact trace/manifest/envelope qHash-set binding. The lint follow-up fixes the shared-runner compound statements, assigned lambdas, ambiguous test variable and unused local while retaining JSONL parsing; the vendored verifier remains unchanged. Validation at the current head: all eight triggered GitHub workflows succeeded, including Lint and Alakris authority comparison evidence checks. Producer SELF custody and evidence boundaries remain unchanged: no independent live comparison, current-freshness, target-side effect-custody, conformance or measured revocation-latency claim. The connector could not open a direct PR against |
Closes #287.
Adds pinned public-evidence adapters for MintID and Proofable, an executable synthetic executor fixture, and released TRACE reference shape validation. Reports keep publisher observations, absent fields, unperformed appraisals and actual execution provenance distinct; external evidence does not become attestation or an independently verified effect.
Validation: Python 3.12.15, 27 tests including valid control, forged dispatch, action tampering, duplicate suppression, deadline closure, manifest coverage and missing-case rejection. MintID operator-record hashes pass. The pinned Proofable trace intentionally fails the strict publisher digest check; the diagnostic identifies LF/CRLF equivalence without altering expected hashes. Native client runs reproduced issuer/control and remaining revocation observations, but retain an initial HTTP 503 abort and a failed positive baseline in the bounded retry. Native reproduction scope and artifact hashes are recorded in RESULTS.md.
No Verified tier or conformance level is requested. Original vendor sources/evidence remain in their repositories. GitHub maintainer is the authenticated human submitting account
wlad232; the source/evidence and author-run limitations remain explicit.