sots-re/campaign/rollout/gate-worker-state.md

76 lines
4.8 KiB
Markdown

# Gate worker checkpoint
Timestamp: 2026-09-09T22:05:00Z
Model/session: openai/gpt-5.6-terra, bounded Astra-followup implementation session.
## Contract and source identities
- Active repair contract: `campaign/rollout/gate-followup.md`; read the prior worker checkpoint,
`gate-worker.md`, `architecture-decision.md`, workflow, and reviewer checkpoint. No
`independent-review.md` exists in this checkout.
- RE source is `/home/alex/sots-re`; the worktree is already dirty with other lanes' changes.
Owned files remain `tools/{gate.sh,gate.py,evidence.py,standalone_report.py}`, `verify/tooling/`,
and this checkpoint. No staging, commits, or lab activity.
- Engine inspected at `/home/alex/sots-engine`, HEAD
`7741d42fc5e4e761e6449bdaf0e4a61d00036a23`, dirty from concurrent engine work. Its
`src/app/main.cpp` confirms `--roundtrip` verifies untouched serialization and then calls
`RunStrategicTurn`; it must remain part of the reporter invocation, not replace turn simulation.
- The required shim toolchain is the source-relative
`cmake/toolchain-mingw-i686.cmake`; its output target is `binkw32.dll`.
## Observations and decision
- Existing gate defects match the repair contract: source exclusion used `startswith("build")`,
copy integrity was not verified, source symlinks/modes/deletions were not represented,
inherited `SOTS_*` inputs were retained, JUnit completeness/corpus summaries were fail-open,
`--shim` took an unusable directory/toolchain path, and manifest success used unsafe generic
`all(checks.values())`.
- Existing reporter only checked gate schema/status and binary hash; it permitted unsafe engine
arguments and did not detect provenance/binary/input mutations after execution.
- This is ordinary implementation repair within the approved contract. Do not run an integrated
gate while the engine source is mutable.
## Implemented repair
- `tools/gate.py` now snapshots tracked and nonignored untracked engine files with complete
SHA-256 and mode records, rejects source/input symlinks, excludes only exact top-level known
build outputs, checks every copied file before the build, and detects additions/deletions/mode
and content changes after the run. RE tooling identity is an explicit immutable list rather
than mutable campaign runtime/publication state.
- The gate sanitizes inherited `SOTS_*`, accepts declared extra dependencies as repeatable
`--sots-input SOTS_NAME=PATH`, records roots, hashes full consumed file/directory inputs,
compiler/tool versions, commands, and actual environment. Input/output root overlap and
nonpositive jobs are rejected.
- `--shim` is now boolean. Host is always built; `--shim` also builds the source-relative
`cmake/toolchain-mingw-i686.cmake` configuration and hashes exactly one `binkw32.dll`. Full
requires `--data --shim`.
- JUnit records every testcase/system-out. Its executed identity multiset must be the expected
inventory with no missing/duplicate identity; statuses must cover every expected test without
failures or unexpected skips. Each of the four corpus tests must report exactly one positive
`N save(s)` count equal to the top-level corpus save manifest count.
- `tools/evidence.py` validates all passed-gate source, binary, test coverage and required-check
fields. `tools/standalone_report.py` binds binary/provenance/pair/engine file inputs before and
after execution, retains complete child stdout/stderr and differences, blocks output/metric/
roundtrip argument overrides, and records that `--roundtrip` verifies serialization before
`RunStrategicTurn`. Measurement remains scoped to selected workloads; `--accept` fails unless
all selected pairs match on file, inflated and state digests.
## Validation
- `python3 -m py_compile tools/gate.py tools/evidence.py tools/standalone_report.py verify/tooling/test_tooling.py`: pass.
- `python3 -m unittest verify/tooling/test_tooling.py -v`: pass, 15 tests. The expected argparse
diagnostics occur in rejection tests. Tests exercise build-named sources, pre-copy mutation,
symlink rejection, JUnit duplicate/positive counts, subprocess exception, incomplete/failed
provenance, binary mismatch, unsafe arguments, missing pair, wrong reference and pair failure.
- `git diff --check`: pass. `python3 tools/gate.py --help` and
`python3 tools/standalone_report.py --help`: pass.
- Per contract, no integrated gate, commits, staging, live lab operation, or architecture change
was performed.
## Blocker and exact next action
- The engine checkout remains dirty/concurrently owned, so any integrated measurement is still
invalid. This repair provides no acceptance result.
- Exact next action: lead coordinates a stable baseline-pinned engine identity, then a fresh
worker runs the documented gate CLI once in a new external output directory and independently
verifies the resulting evidence package.