diff --git a/ROADMAP.md b/ROADMAP.md index 7f13978..c83958a 100644 --- a/ROADMAP.md +++ b/ROADMAP.md @@ -398,17 +398,19 @@ proposal non-effective. An independent Market candidate reproduces the unchanged The bounded [release-convergence packet](docs/design/measured-intelligence-v0.6.0-release-convergence-work-packet-v1.md) now owns installed-artifact and combined-gate evidence. The milestone remains **Next** pending -merged-source review, public release artifacts, compatibility/security/release acceptance, and -explicit release-owner resolution or re-dating of issue #49 F1, F3, and F5. Those three items are -open release gates; they are not silently waived, deferred, or implemented here. +World review/merge, public release artifacts, and compatibility/security/release acceptance. These +gates are not silently waived. The follow-on [merge-candidate audit](docs/design/measured-intelligence-v0.6.0-merge-candidate-audit-work-packet-v1.md) binds a World direct-to-live-main integration candidate and presents bounded F1/F3/F5 owner choices. The subsequent [#49 hardening packet](docs/design/measured-intelligence-v0.6.0-issue49-hardening-work-packet-v1.md) -implements bounded F1 and F5 candidates. Both remain open until reviewed and merged; F3 still -requires an explicit authenticated owner disposition. This does not advance the milestone beyond -**Next**. +implements bounded F1 and F5, now merged in exact Core `main`. The subsequent +[merged-source convergence packet](docs/design/measured-intelligence-v0.6.0-merged-source-convergence-work-packet-v1.md) +rebuilds the exact Core and World wheels, reproduces the public World `useful` and independent +Market `unproven` results, and retains proposal-only authority. Issue #49 now records F1 and F5 as +complete against merged Core and explicitly re-dates unresolved, unwaived F3 to `2026-11-05` under +documented containment. This does not advance the milestone beyond **Next**. ### 0.7.0 — Domain and Extension Platform diff --git a/docs/capability-maturity.md b/docs/capability-maturity.md index 797a81d..0b9dd8e 100644 --- a/docs/capability-maturity.md +++ b/docs/capability-maturity.md @@ -216,9 +216,13 @@ The later reconciles the World journey onto live World `main` and turns issue #49 F1/F3/F5 into explicit owner choices. The bounded [#49 hardening packet](design/measured-intelligence-v0.6.0-issue49-hardening-work-packet-v1.md) -implements F1 and F5 candidates but does not close them before review and merge; F3 still requires -an explicit authenticated owner disposition. The capability remains experimental until those -choices, reviewed merges, final artifacts, and release acceptance are complete. +implements F1 and F5, now merged in exact Core `main`. The bounded +[merged-source convergence packet](design/measured-intelligence-v0.6.0-merged-source-convergence-work-packet-v1.md) +reproduces the unchanged public World and independent Market results from an installed exact Core +wheel. Issue #49 now marks F1 and F5 complete against merged Core and re-dates unresolved, unwaived +F3 to `2026-11-05` under documented containment. The capability remains experimental until World +review/merge, final versions and public artifacts, public-index installation, and release +acceptance are complete. ## Implemented architecture beyond the compatibility contract diff --git a/docs/design/measured-intelligence-v0.6.0-merged-source-convergence-work-packet-v1.md b/docs/design/measured-intelligence-v0.6.0-merged-source-convergence-work-packet-v1.md new file mode 100644 index 0000000..423ab01 --- /dev/null +++ b/docs/design/measured-intelligence-v0.6.0-merged-source-convergence-work-packet-v1.md @@ -0,0 +1,79 @@ +# ACE 0.6.0 Measured Intelligence merged-source convergence work packet (v1) + +**Status:** bounded post-merge candidate. This packet does not change package versions, merge the +World draft, tag or publish an artifact, close issue +[#38](https://github.com/augmented-cognition-engine/core/issues/38), pass SI4, apply a measured +proposal, or declare ACE 0.6.0 complete. + +**Core base:** merged `main` commit `7013de62ae7320c51c3de9e9a03b049e768e4d84`. + +**World target:** draft [PR #17](https://github.com/augmented-cognition-engine/domain-world-intelligence/pull/17), +executable source `cb7b6fdb2b9fe4dd3c34df8afc1368c86d026710`. + +## Objective + +Replace stacked-candidate inheritance with one exact default-branch artifact and cross-domain +receipt: + +1. build Core, the reference Action adapter, World, and the World source adapter twice from exact + source identities and require byte-identical wheels; +2. install those exact wheels in a fresh Python 3.12 environment outside every Core checkout; +3. rerun the public World correction journey twice and freeze one canonical result; +4. rerun the independent Market production-store journey, including fresh-process replay after a + real database restart and atomic-interruption controls; +5. bind merged Core focused, default-branch CI, compatibility, and vulnerability results; and +6. keep every release-owner decision visible rather than inferring a release pass. + +The public World path remains: + +```text +Observation -> Shift -> Signal -> Brief -> Decision -> reviewed Action + -> observed Outcome -> governed feedback +``` + +## Ownership boundary + +- Core owns durable scope, identity, provenance, authority, Decision, Action, Outcome, append-only + history, replay, and proposal coordinates. +- Intelligence owns the domain-neutral matched evaluation and `useful | harmful | unproven` + classifier. +- World owns public-source fixtures, correction semantics, source policy, product criteria, + controls, and outcome meaning. +- Market remains a separate private consumer. Only bounded result identities and verification + totals may enter this public record; no private source, fixture, product data, or extension code + moves into Core. + +## Acceptance and non-claims + +The packet may prove exact merged-source installation, reproducible wheels, checkout exclusion, +deterministic World reproduction, independent Market reproduction, restart durability, atomic +failure behavior, and green compatibility/security gates. It cannot prove causality, population +performance, live freshness, general source independence, provider quality, human/customer +benefit, general SI4 completion, or a published 0.6 artifact. + +Every governance proposal remains non-effective, non-selectable, unapplied, and subject to +separate human/Core authority. This packet adds no proposal-application path. + +## Issue #49 boundary + +F1 and F5 implementation are merged in exact Core `main` and are re-derived here through focused, +default-branch, and external-consumer evidence. On `2026-08-11`, an authenticated release owner +reconciled the public issue #49 checklist by marking F1 and F5 complete against exact Core +`7013de62ae7320c51c3de9e9a03b049e768e4d84`. + +F3 remains unimplemented, unresolved, and unwaived. The same public disposition re-dated it to +`2026-11-05` under trusted-package-only scope, `ACE_DISABLE_EXTENSIONS=1`, compatibility-matrix +verification, and operator disablement on unexpected partial registration. Issue #49 remains open, +and its future packet must stage every mutable registration surface, enforce ceilings, publish or +roll back atomically, and emit a bounded failure report. + +## Owned files, rollback, and deletion criteria + +This packet owns this work packet, its point-in-time evidence, one evidence-index entry, and +restrained current-state roadmap and maturity reconciliation. It owns no runtime code, schema, +package version, workflow, World or Market policy, issue checklist, tag, or release. + +Rollback removes only these additive records and references. Preserve the evidence as historical +if later artifact epochs, package versions, World source, or release identities change. Supersede +it with a release-readiness receipt only after World review/merge, final artifact/version decisions, +public-index installation, and release-owner acceptance. diff --git a/docs/evidence/README.md b/docs/evidence/README.md index f852e30..a7fbf0d 100644 --- a/docs/evidence/README.md +++ b/docs/evidence/README.md @@ -45,6 +45,8 @@ superseded by later work and is kept for audit trail only. — live-main World integration, exact artifact receipts, and explicit F1/F3/F5 owner choices; not release closeout - [Measured Intelligence issue #49 F1/F5 hardening](measured-intelligence-v0.6.0-issue49-hardening-candidate-v1.md) — candidate in-transaction generation guard, durable review reconciliation, and legacy table pin; not release closeout +- [Measured Intelligence merged-source convergence](measured-intelligence-v0.6.0-merged-source-convergence-candidate-v1.md) + — exact merged Core artifact, public World reproduction, independent Market restart proof, and remaining release gates; not release closeout - [State Engine TP0 current-runtime baseline](state-engine-tp0-runtime-baseline-v1.md) - [State Engine TP1A truthful observation outcomes](state-engine-tp1a-truthful-observation-outcomes-v1.md) - [State Engine TP1 reliable memory lifecycle](state-engine-tp1-reliable-memory-lifecycle-v1.md) diff --git a/docs/evidence/measured-intelligence-v0.6.0-merged-source-convergence-candidate-v1.md b/docs/evidence/measured-intelligence-v0.6.0-merged-source-convergence-candidate-v1.md new file mode 100644 index 0000000..fea4184 --- /dev/null +++ b/docs/evidence/measured-intelligence-v0.6.0-merged-source-convergence-candidate-v1.md @@ -0,0 +1,128 @@ +# ACE 0.6.0 Measured Intelligence merged-source convergence candidate evidence (v1) + +**Status:** bounded candidate evidence. This is not a tag, publication, issue #38 closeout, SI4 +pass, proposal application, or ACE 0.6.0 release claim. + +**Recorded:** 2026-08-11 + +## Exact source and review identities + +| Surface | Exact identity | +|---|---| +| Core merged `main` | `7013de62ae7320c51c3de9e9a03b049e768e4d84` | +| Core merged stack | PRs #88 through #93, merged in dependency order | +| Core main CI | [run 31520372788](https://github.com/augmented-cognition-engine/core/actions/runs/31520372788), all six gates passed | +| World executable source | `cb7b6fdb2b9fe4dd3c34df8afc1368c86d026710` | +| World merged-Core evidence commit | `a85da4289ff80fff6e6507b546dca191ff92d841` | +| World review surface | draft [PR #17](https://github.com/augmented-cognition-engine/domain-world-intelligence/pull/17) | +| World PR CI | [run 31522715774](https://github.com/augmented-cognition-engine/domain-world-intelligence/actions/runs/31522715774), passed | +| Independent Market source | `cd1f2f2c862e5665344e47885f594a77c5aaa59b` | + +The World and Market consumers used the exact installed Core wheel below. Market remained a +separate private repository; this public record contains no private fixture, source, customer +material, credential, or extension code. + +## Reproducible artifact identities + +Each wheel was built twice with the exact source epoch shown. The paired SHA-256 values were +identical. + +| Artifact | Source epoch | SHA-256 | +|---|---:|---| +| `ace_core-0.5.0-py3-none-any.whl` | `1786471152` | `662c4197f3ff0cf7dc1e64b0f8bc6bc705c8a1d6373a8468d9cb1d2df3d8c214` | +| `ace_reference_workspace_action-0.1.0-py3-none-any.whl` | `1786471152` | `31463fbcfe2a9c62b5cc9abe0a67814cd7fdd36de3c9f6ec47835d7be080ed5a` | +| `ace_ext_world_federal_register_source-0.2.0-py3-none-any.whl` | `1786466888` | `4841a02b46fba867d8bac092cd2eab1a45e71537d364fda389192857313e049c` | +| `ace_domain_world_intelligence-0.9.0-py3-none-any.whl` | `1786466888` | `8470b903c165e6897159172c918245fbc7bae7470ce6ad82dbb940776417c049` | + +No version changed and no artifact was published. The local Core wheel still reports `0.5.0`; its +complete source commit and hash distinguish it from public `ace-core==0.5.0`. + +## Public World result + +A fresh Python 3.12 environment installed all four exact wheels plus public dependencies. Core, +the reference Action adapter, and the World source adapter imported from `site-packages`. The +generator rejected every declared Core checkout root. Two fresh workspaces emitted byte-identical +canonical JSON: + +```text +sha256:c62a7db77b66a15f2930c850bdb8bbc44b542f928c2e0b146b5bf3dde08f30df +``` + +The exact BLS correction pair still produces treatment `[1.0, 1.0]`, control `[0.0, 0.0]`, two +matched pairs, mean effect `1.0`, and bounded `useful`. The `promote` proposal remains +non-effective, non-selectable, unapplied, requires human review, and is not reauthorized on +historical replay. + +World verification against the installed merged Core wheel: + +```text +complete World suite: 123 passed in 37.82s +official-source connector suite: 80 passed in 0.65s +package/release contract: 7 passed in 0.07s +updated convergence and release controls: 10 passed in 2.20s +``` + +## Independent Market result + +The independent Market production-store acceptance retained its deliberately different result: + +```text +classification: unproven +treatment mean: 1.0 +control mean: 0.5 +mean effect: 0.5 +proposal: reject +live_effect: false +selectable: false +requires_human_review: true +evaluation digest: sha256:cba0ec7d5252f53f65243d1ecd3c98295f6773b1fa90649cbc544b377cec8dca +transaction receipt: append_only_receipt:f384e488f58f3752e6591a427ce4fc5c +``` + +Core schema v177 was applied to a disposable SurrealDB 3.2.1 store. The execute phase persisted the +exact journey through `SurrealImmutableRecordStore`; a fresh process reopened the same transaction +after a real database restart without current authorization or reclassification. The focused +authority, interruption, and replay lane passed `5` tests. The complete Market backend passed +`379 passed, 8 skipped, 4 deselected` against the installed merged Core wheel. + +This private second-domain falsifier proves unchanged neutral expressibility and durability. It is +not public Market data, a new provider run, causal evidence, customer benefit, or general Market +quality evidence. + +## Core and security verification + +```text +merged measured-impact + F1/F5 focused lane: 82 passed in 10.83s +main push CI: lint, fast tests, naked kernel, Canvas, security audit, Docker build passed +clean installed-environment pip-audit 2.10.1: no known vulnerabilities found +``` + +The vulnerability audit could not resolve the two separately built adapter distributions on PyPI +and reported them explicitly as skipped; all public resolved dependencies were audited. The clean +environment installed public dependencies from the public index, but it used local exact candidate +wheels. A public-index-only 0.6 install remains impossible until a 0.6 package is actually +published and is therefore still an open release gate. + +## Release-state corrections and issue #49 + +The stacked merge automatically closed issue #38 despite the explicit no-close boundary. The +milestone was reopened with a public correction; it remains **Next**. + +F1 and F5 implementation are now merged and reproduced from exact `main`. On `2026-08-11`, an +authenticated release owner reconciled issue #49 by marking F1 and F5 complete against exact Core +`7013de62ae7320c51c3de9e9a03b049e768e4d84`. F3 remains unimplemented, unresolved, and unwaived; +the owner explicitly re-dated it to `2026-11-05` under the trusted-package-only, extension-kill- +switch, compatibility-matrix, and operator-disablement containment recorded on the still-open issue. + +## What this proves and what remains + +The exact merged Core source supports a reproducible public World `useful` result and an independent +Market `unproven` result through the same neutral measured-impact contract. Both preserve exact +attribution, append-only replay, explicit uncertainty, restart durability, and proposal-only +authority. This is the smallest honest cross-domain convergence result; it is not a supported or +published release. + +Remaining gates are World PR #17 review/merge, final Core/World version and artifact identities, +public-index-only installation, release compatibility/security acceptance, publication, and +explicit release-owner acceptance. F3 remains tracked on open issue #49 under its documented +containment; no tag or publication occurred.