sots-re/campaign/rollout/gate-worker-state.md

4.8 KiB

Gate worker checkpoint

Timestamp: 2026-09-09T22:05:00Z Model/session: openai/gpt-5.6-terra, bounded Astra-followup implementation session.

Contract and source identities

  • Active repair contract: campaign/rollout/gate-followup.md; read the prior worker checkpoint, gate-worker.md, architecture-decision.md, workflow, and reviewer checkpoint. No independent-review.md exists in this checkout.
  • RE source is /home/alex/sots-re; the worktree is already dirty with other lanes' changes. Owned files remain tools/{gate.sh,gate.py,evidence.py,standalone_report.py}, verify/tooling/, and this checkpoint. No staging, commits, or lab activity.
  • Engine inspected at /home/alex/sots-engine, HEAD 7741d42fc5e4e761e6449bdaf0e4a61d00036a23, dirty from concurrent engine work. Its src/app/main.cpp confirms --roundtrip verifies untouched serialization and then calls RunStrategicTurn; it must remain part of the reporter invocation, not replace turn simulation.
  • The required shim toolchain is the source-relative cmake/toolchain-mingw-i686.cmake; its output target is binkw32.dll.

Observations and decision

  • Existing gate defects match the repair contract: source exclusion used startswith("build"), copy integrity was not verified, source symlinks/modes/deletions were not represented, inherited SOTS_* inputs were retained, JUnit completeness/corpus summaries were fail-open, --shim took an unusable directory/toolchain path, and manifest success used unsafe generic all(checks.values()).
  • Existing reporter only checked gate schema/status and binary hash; it permitted unsafe engine arguments and did not detect provenance/binary/input mutations after execution.
  • This is ordinary implementation repair within the approved contract. Do not run an integrated gate while the engine source is mutable.

Implemented repair

  • tools/gate.py now snapshots tracked and nonignored untracked engine files with complete SHA-256 and mode records, rejects source/input symlinks, excludes only exact top-level known build outputs, checks every copied file before the build, and detects additions/deletions/mode and content changes after the run. RE tooling identity is an explicit immutable list rather than mutable campaign runtime/publication state.
  • The gate sanitizes inherited SOTS_*, accepts declared extra dependencies as repeatable --sots-input SOTS_NAME=PATH, records roots, hashes full consumed file/directory inputs, compiler/tool versions, commands, and actual environment. Input/output root overlap and nonpositive jobs are rejected.
  • --shim is now boolean. Host is always built; --shim also builds the source-relative cmake/toolchain-mingw-i686.cmake configuration and hashes exactly one binkw32.dll. Full requires --data --shim.
  • JUnit records every testcase/system-out. Its executed identity multiset must be the expected inventory with no missing/duplicate identity; statuses must cover every expected test without failures or unexpected skips. Each of the four corpus tests must report exactly one positive N save(s) count equal to the top-level corpus save manifest count.
  • tools/evidence.py validates all passed-gate source, binary, test coverage and required-check fields. tools/standalone_report.py binds binary/provenance/pair/engine file inputs before and after execution, retains complete child stdout/stderr and differences, blocks output/metric/ roundtrip argument overrides, and records that --roundtrip verifies serialization before RunStrategicTurn. Measurement remains scoped to selected workloads; --accept fails unless all selected pairs match on file, inflated and state digests.

Validation

  • python3 -m py_compile tools/gate.py tools/evidence.py tools/standalone_report.py verify/tooling/test_tooling.py: pass.
  • python3 -m unittest verify/tooling/test_tooling.py -v: pass, 15 tests. The expected argparse diagnostics occur in rejection tests. Tests exercise build-named sources, pre-copy mutation, symlink rejection, JUnit duplicate/positive counts, subprocess exception, incomplete/failed provenance, binary mismatch, unsafe arguments, missing pair, wrong reference and pair failure.
  • git diff --check: pass. python3 tools/gate.py --help and python3 tools/standalone_report.py --help: pass.
  • Per contract, no integrated gate, commits, staging, live lab operation, or architecture change was performed.

Blocker and exact next action

  • The engine checkout remains dirty/concurrently owned, so any integrated measurement is still invalid. This repair provides no acceptance result.
  • Exact next action: lead coordinates a stable baseline-pinned engine identity, then a fresh worker runs the documented gate CLI once in a new external output directory and independently verifies the resulting evidence package.