V4.3 Delivery Admission Evidence
Candidate admission evidence
Admission reached a terminal inconclusive result. The retained human exception
authorized Stage 2 without converting incomplete measurement criteria into
passes. AC-044 through AC-047 are recorded as excepted_not_passed; AC-048
passes because activation occurred only after the exception was retained.
Canonical skills main was published at
e9286c375963a5af33a730d79c4fff04a76e469a, followed by an override-free
Harness sync whose receipt and distributed tree matched that exact source.
The post-sync final proof is
.devpunks/delivery/v43/IP-455/offline-fixture-preparation/source04-post-sync-proof-execution04/.
It executes six actual public commands with expected statuses
[0, 1, 1, 0, 1, 1]: scaffold succeeds, ordinary update applies and returns its
documented nonzero status, repeat update reports no change, and the same sequence
passes for the absent-reference fixture. Its build, canonical contracts, CLI
typecheck, focused CLI tests, and public preservation logs all exit zero.
Execution04 initially exposed a runtime defect when Oxlint reported zero matching
files before valid JSON. The bounded scripts.ts repair recognizes the supported
notice and parses the following JSON; its regression test and the renewed execution04 proof pass. This was a runtime
defect found by the acceptance run, not benchmark evidence for AC-044–AC-047.
Compatibility and frozen inputs
Parent-owned .devpunks/delivery/v43/delivery-a3-gate.json passes the T1–T8 producer/consumer gate. Its 244/251 canonical test result retains exactly seven clean-baseline research failures as prior debt. T9 independently compared frozen candidate bytes with retained IP-454 and IP-453 source identities: all 20 and 26 identities respectively match, zero mismatches (IP-455/a3-source-identity-audit.json). This reuses compatible Task/Architecture evidence without treating it as admission assurance.
The source seam is complete working-byte path/content/mode manifest → immutable fixture selection → native measured admission → eligible canonical publication → exact Harness source receipt/tree verification. T9 owns preparation and observation extraction; the parent owns exclusive native runs, publication and synchronization. Standalone Python helpers prepare files or read observations; they execute no agent workflow.
Current immutable source selection: .devpunks/delivery/v43/IP-455/source-freeze-04/source-manifests.json (manifest SHA256 228d4a21d06ed75f569c204d0743392fa03a5f1f7568d310169ba4c2d81859c6).
| Variant | Identity | Complete manifest SHA256 |
|---|---|---|
| Baseline | Git 584ea4bddd5bcfcf780baf9fb67ff736ba7d0626; 826 paths | 2dcd45845d549a6a4fb86bf03239aab3e0b557e7a233fbc93fd7634ee1f52ba7 |
| Candidate | Uncommitted working bytes; 901 paths | 6dad3a70a6a35c48aaee03ac2072301a216745b3c79c2097bc65cd5ea2a588e1 |
Freeze 04 proves the current source04 selection; source03 freezes and their executed samples remain historical evidence for that earlier treatment. Rehash before selection and after execution. Candidate changes require a fresh snapshot before affected measurement.
The parent supplied runtime-0912 with 1,648-file manifest f5cb42a252b878a83ab51818ba2c4679f433e09b0d041979541b48717f108232; copied help passed. Dependency closure beyond that invocation remains unproved. The small browser fixture does not call Harness CLI. Combined scaffold preservation/no-op/recovery proofs remain separate exact-runtime gates.
Historical first native fixture readiness
Canonical tests/fixtures/v43/admission/MATRIX.md preserves all five families and fixture variants. Small Full Delivery has a reviewed browser product fixture; medium, skewed graph, worker context, four seeded-review sizes and recovery/handoff instances remain pending. Baseline uses its supported browser Verification; candidate authors project references only when its selected workflow requires them. Both retain identical observable browser assurance.
Current seed metadata is IP-455/browser-seed-03.json:
- Fixed main:
3292385c6be9519fa3077d1cae41e9947088ccde. - Retained specification seed:
42482a384b90efe8437b732100b7503a671d5bf2onfixture-seed/full-small. - Seed tree:
1c0b633d998246b00c37fd5ff5dd76b634fc1941. - SPEC blob:
6e315db5007158753d2baa97bb37045ab3858f0b. - SPEC SHA256:
69d5d5ea9656a41e499800f6f565589ef384c2872c2ded332027a1d23227b776.
One vertical provider Task delivers the small browser outcome. Fixed main precedes the meaningful specification changes, permitting an early draft PR. Each run receives isolated provider objects and explicit identity mappings; previous histories are preserved. PROVIDER-SETUP.md describes native Projects V2 fields/views, Epic/Story/Task hierarchy, V* milestone and exact readbacks. The empty small-task blocker graph is explicit; other families retain dependency coverage.
Prepared repositories /tmp/v43-admission-browser-p1-baseline and /tmp/v43-admission-browser-p1-candidate have identical seed HEAD/tree, clean Git status after selected-source projection and identical SPEC bytes (browser-p1-preflight.json). Reusable copies are ignored; project-owned verifier references remain writable and retainable. prepare.py binds exact seed commit/tree rather than moving clone HEAD.
At this historical checkpoint, native launch was held pending remote spec retention, Write Backlog proof, provider hydration and CONTEXT.json. Later source04 execution supersedes that readiness status; the retained preparation still cannot waive selected-source gates.
Browser capability passed an unmeasured probe: agent-browser 0.36.0 launched Chrome at about:blank and closed its named session (browser-capability.json). This is capability evidence, not product acceptance.
When readiness is complete, the parent uses identical authorized configuration/capacity and frozen stdin in both variants:
/home/stefan/.local/bin/codex exec --json --model gpt-6-astra -c model_reasoning_effort="medium" --cd <run-owned-repo> --output-last-message <evidence>/result.md -Stdin: frozen tests/fixtures/v43/admission/prompt.md. Retain exact argv/configuration identities, stdout, stderr and exit status. Correlate emitted thread IDs with actual native persistence and subprocess lineage. The first actual comparison proves telemetry before remaining pairs execute.
Observation boundary
node --test tests/v43-source-admission.contract.test.mjs passes five mechanical cases: missing records stay unknown; cumulative notifications count once; observed children/grandchildren exclude unrelated sessions; counter resets/opaque operations fail closed; native stdout reasoning usage retains line provenance without invented descendant closure. Log: IP-455/collector-mechanical-tests.log.
collect.py retains root stdout usage and observed-session cumulative token subtotals, raw path/line/hash provenance, observed operations and terminal elapsed where available. Observed subtotals are not proved all-descendant totals. Retained native stdout from an earlier IP-454 run confirms turn.completed.usage can expose input, cached input, output and reasoning categories; this is format evidence, not a T9 measurement.
Every unresolved boundary remains unknown:
- All-descendant closure includes native subagents and helper-spawned reviewer processes, with terminal outcomes and resume lineage.
- The existing autoreview helper invokes Codex with
--ephemeral, reformats streamed JSON and does not durably retain successful raw stdout. Native rollout metadata alone therefore cannot cover reviewer subprocess usage (reviewer-telemetry-boundary.json). - Cumulative usage needs reconciliation across resumes; retain total/cached/derived noncached input, output and reasoning for every descendant exactly once.
- Resumptions require invocation lineage; turn count is not resume count. Compactions require native events.
- Actual loaded-file bytes need native load evidence. Source sizes, command text, output size and encrypted payload length are insufficient.
- Nested shell/provider/wait/spawn/follow-up operations and wait intervals need attribution. Root active elapsed, first-to-last elapsed, waits and child elapsed remain distinct.
- Independent adjudication must prove every applicable Task, Architecture, runtime/UI/provider, Verification, final acceptance and review-retention gate. Seeded reviews require per-axis recall, no missed critical/high seed, correct severity/routes, complete lenses and stable target/report identities.
Missing required metrics or assurance prevent passing admission. Once observations are complete, each fixture needs three matched pairs, extending disagreement to five and then inconclusive. No numerical improvement threshold or simulation substitutes for actual native results.
Separate acceptance traceability
IP-455/AC-TRACEABILITY.json retains 95 pointer-only rows: 20 assigned umbrella criteria, all 39 Verifier criteria and all 36 Execution criteria. It preserves owner identities and hashed retained owner evidence. Every admission/final-acceptance status remains unassessed; Task Gates do not automatically complete these rows. Stage 2 source/readback/receipt and combined scaffold regression gates remain outstanding.
Symmetric measurement preparation
The parent accepted a task-local pass-through tee as symmetric measurement instrumentation and retained its focused mechanical review gate. IP-455/measurement-tee/codex-tee.py has SHA256 f351627c9f16293e6f11ed33357c22da0ceb6a95918c076e75d23cf934dc492e. It exec-replaces its PID with real Codex and uses a detached recorder; actual arguments, binary streams, process-group signals and caller exit semantics remain intact. Ten regressions include exactly-once group SIGINT, startup cancellation, early output closure, valid late stdin, open inherited stdin and ignored signals. These are mechanical tests, not native admission.
The readonly completion procedure is in measurement-tee/README.md: retain the original caller exit result, then wait for recorder PID/start-bound pidfd completion before consuming final receipts. Output EOF is not native termination. A timeout, incomplete input or absent final receipt stays unknown. Four parsing tests and three completion-observer tests retain these boundaries. Actual prior native custom-call output proved two unambiguous returned file reads totaling 12,847 UTF8 content bytes; their hashes/lines are retained as schema evidence, while complete loaded-byte attribution remains unknown.
The original preparation status (IP-455/TASK-RESULT.json) and preparation-final-identities.json describe the historical source03 checkpoint before native comparison. Current source04 execution status is recorded above and in .devpunks/delivery/v43/CURRENT.md. Canonical publication, synchronization, admission and final acceptance remain pending.