sots-re/campaign/rollout/formal-verifier.md

2.4 KiB

Independent controls verifier — bounded formal acceptance task

Model openai/gpt-5.6-terra; role verifier; actor controls-independent-verifier. No implementation/source/document edits, no delegates/commits/lab actions. Own only your canonical runtime checkpoint/verdict for controls-bootstrap, plus campaign/rollout/formal-verifier-state.md. Read canonical AGENTS, contract and current evidence. Do not rely on lead summary. Inspect recorded tests/raw stderr/source bindings and reproduce the complete control suite (now 37 tests after R8). Challenge old-checkpoint recovery, same-HEAD source drift and final integrated-verifier launch guards specifically. Read independent Astra review, noting it is distinct from this formal source-bound verdict.

Source-bound test package is already attached to controls-bootstrap, state verification. R8 is now formally resolved by Astra (d-6239404c8f40351310c8abf0); the one-line role/status fix and added guarded integration regression require refreshed source-bound verification. Validate ALL evidence/inputs/binaries/source_binding through campaign API/CLI, independently run the appropriate local unit suite, inspect the actual normal-launch record campaign/runtime/runs/run-df1472c13f31db3a4d5361f0.json and its JSON events/checkpoint to confirm real session/stop/no source mutation. Do not mistake fake-process tests for that real launch.

If running in integration: source/package revalidate the final integrated evidence; no repeat suite is needed if hashes match your just-reproduced verification package. New verdict must bind the changed integrated evidence digest. If contract criterion holds and no new blocker, record a passing verdict with campaign CLI: --actor controls-independent-verifier --role verifier --model openai/gpt-5.6-terra --session controls-independent- --verdict pass --explanation scoped to actual controls tests. If not, record fail with precise evidence. Never widen this to whole-engine/full-assets/research acceptance.

Write a checkpoint with your actual actor/model/role/session, immutable evidence artifact(s), test outcomes and exact next action. Lead will then promote same package to integration and ask for final source/package revalidation; no redundant tests needed if all source/input hashes are identical, but changed integrated evidence digest needs a new independent verdict. At completion stop. Checkpoint before 40-step quantum limit. No alias model substitution.