sots-re/campaign/rollout/RESULT.md

5.2 KiB

Rollout result — 2026-09-09

Architecture/planning/resolutions: GPT-6 Astra. Three additional Astra architecture/review executions supported the lead. Bounded implementation/verifier workers used GPT-5.6 Terra; final Windows operations used GPT-5.5. No source-repository commit, push or deployment of a new game shim was performed. The Windows housekeeping changes were explicitly authorized.

Delivered

  • Versioned role prompts/model routing, AGENTS entry points, 40-step worker quanta, auto-compaction, regular durable checkpoints, no silent fallback and no nested worker delegation.
  • Canonical RE contracts, guarded lifecycle, independent source-bound evidence/verdicts, surprise/Astra decision records, atomic leases and source-isolated launch controls.
  • Replaced old board/coverage/Forgejo/displacement workflow and removed global Claude re-* agents. Current projections come from contracts and explicit content-addressed evidence selection.
  • Fresh snapshot gate with actual source/input/binary hashes, expected test inventory, positive corpus execution, explicit skips and full output capture; no reused remote overlay/build.
  • Separate file/inflated/state comparisons, retained output saves, measured-only reporter and optional equality requirement. Campaign acceptance is not inferred from equal hashes alone.
  • Fixed RNG draw accounting across twists/rejections, duplicate nested-player accounting, lost replay writes, empty/malformed corpus false-skips, and snapshot clean-room scanning.
  • Concrete proposed research write-set replacement pilot with archived workload, prerequisites, complete effect boundary, controls and remaining implementation dependencies.

Validation

  • Python: 71 unique tests passed (37 campaign controls, 19 tooling, 8 publishing, 7 config/scanner).
  • Actual OpenCode loader/model availability checks passed. Real normal launcher runs completed for Astra architecture-review and Terra verifier roles, with actual session IDs, successful stop events, fresh canonical checkpoints and source identity records. Model request is explicit; emitted provider model metadata is unavailable and is not fabricated.
  • Fresh engine host build and MinGW shim cross-build passed. 59 CTest identities: 52 passed, 7 explicit permitted asset/trace skips, 0 failed. Four corpus suites each exercised 43 saves.
  • Independent Astra review rehashed 524 engine + 10 RE execution-tool files, both binaries, all corpus inputs and the saved replay; all matched retained manifests.
  • Canonical turn remains 62 state differences from the oracle. It is measured, not accepted.
  • controls-bootstrap reached accepted through independent verification and integrated source-bound verdict after R4/R6/R8 and handoff issues were resolved by Astra. Acceptance scope is the declared control-plane criterion, not engine/game fidelity.

Current selected gate: campaign/evidence/8e14e00ee3ce7478ddfdef8de12183451e858c52d78dc28cffbdee47f5d087d8-gate.json. Current selected replay: campaign/evidence/87f92c2b54625ecbca1f3c0a37e57c43d03a4aff488edf4ea8a09a842cd6279d-replay.json. Build/source/tool snapshots retained at /home/alex/.local/share/sots-runs/rollout-host-20260909-c. Actual replay output retained at /home/alex/.local/share/sots-runs/rollout-replay-20260909. Final independent controls verdict: campaign/runtime/verdicts/controls-bootstrap.json. Final integrated verifier run: campaign/runtime/runs/run-97066391080a3d06dce27a80.json.

Five Windows guests

VM Verified IP Cleanup/profile Login evidence
140 192.168.10.139 compliant existing console preserved; autologon config + key SSH verified
141 192.168.10.143 compliant reboot → automatic re console; key SSH recovered
144 192.168.10.144 compliant reboot → automatic re console; key SSH recovered
145 192.168.10.145 compliant reboot → automatic re console; key SSH recovered
146 192.168.10.146 compliant reboot → automatic re console; key SSH recovered

Lead independently queried all five after completion: re console active; sshd Running/Automatic. Policy/task/consumer cleanup and per-VM result JSON are under verify/results/housekeeping/. The existing provisioned credential was located in the documented installation ISO and streamed privately into protected LSA autologon storage. No password reset or plaintext-registry password. Temporary ISO mount absent after cleanup; all VM/credential leases released.

Windows re-enabled a scheduled scan/OneDrive after login during verification. The repeatable Apply/Verify profile is therefore a required preflight after reboot and before each new oracle capture; old compliant JSON is not proof of current guest state. See the housekeeping guide.

Next action

Review uncommitted rollout changes; prepare the research replacement pilot from the reviewed integration snapshot. Use source-identical verifier handoffs (baseline HEAD alone omits these uncommitted changes). Full asset/trace gate and live completion-bearing research replacement remain separate, unclaimed milestones. Restart OpenCode to load project configuration/agents; existing sessions retain their previously loaded configuration.